Live data from Hacker News

Smart Contract Security Field Guide

scsfg.io

1–10 of 156 posts

Re: Smart Contract Security Field Guide

#5

[flagged]

From every lawyer I spoke to about this, this was not a win for Ripple but the SEC.

They were found guilty of unregistered offerings to institutional. There's no way that the jury/judge won't take that prior decision into account with the non-institutional tranche. Somehow this was spun as a good thing?

Re: Smart Contract Security Field Guide

#6
Every time I hear about another massive hack on Ethereum, I feel a little bit sad that I didn't specialize in software security. For many years there was huge amounts of free cash just sitting on a table waiting to be taken, a victimless crime (VCs and cryptobros are not victims, everyone is playing the same game).

I expect the low-hanging fruit has gone now. And setting up spearfishing attacks to scam teenagers out of their NFTs doesn't seem as noble (or as profitable).

Re: Smart Contract Security Field Guide

#7
I appreciate how organized the Consensys guide is laid out. It's pretty easy to read. Trail of Bits has a similar guide that is a little more in-the-weeds technically. It also covers, what we think is, essential background about certain automated analysis techniques like static analysis and how fuzzers work. Check it out!

https://secure-contracts.com/

Re: Smart Contract Security Field Guide

#9
post #6

Every time I hear about another massive hack on Ethereum, I feel a little bit sad that I didn't specialize in software security. For many years there was huge amounts of free cash just sitting on a table waiting to be taken, a victimless crime (VCs and cryptobros are not victims, everyone is playing the same game). I expect the low-hanging fruit has gone now. And setting up spearfishing attacks to scam teenagers out…

As a dark-hat in the space you'd have a pretty good chance of being caught by chainalysis eventually.

Meanwhile there are still hundreds of millions of dollars of bounties available for white-hats who responsibly disclose.

The dark-hat hackers who aren't held responsible are likely in either Russia or North Korea

Re: Smart Contract Security Field Guide

#10
post #5

[flagged]

From every lawyer I spoke to about this, this was not a win for Ripple but the SEC. They were found guilty of unregistered offerings to institutional. There's no way that the jury/judge won't take that prior decision into account with the non-institutional tranche. Somehow this was spun as a good thing?

I know a lawyer who happens to have a CS background who specializes in technology and cryptocurrency law. IIRC he was saying this was more of a win for Ripple/crypto, as it paved a path for crypto projects to not be classified as securities
Post reply on HN