Last Notes
https://delvingbitcoin.org/t/ec-ots-onchain-has-anyone-considered-it/2901
😂
So what was the outcome in the end ?
Oh. So, two things are in my head that made me write that 1/ inversion (that is division) is one of the most expensive and ugly operations you have to do (remember we're dividing mod p where p is an outlandishly huge prime number). They did a ton of work on it. But 2/ is what actually matters here: they're careful to only expose in the API what a user of the library actually needs, because that lets them have the ability to change underlying algos without breaking software that uses the library. Some libraries have different strategies for that, like naming parts of their API "unstable" or "experimental". Actually come to think of it libsecp did have that kind of thing too. But anyway I guess it's just too low level and they don't want to be responsible for maintaining a stable API for that operation.
Can you say more?
They don't approve of crypto that depends on inversion?
Or it can't be done in a way what's safe from timing attacks?
Or some other problem that I don't understand? 😂 (Yet)
Liquid hacker should have kept all the coins…
I read that the customer data leak was a while ago. But honestly I've forgotten 😄
Also I think I am not in the affected group anyway.
I just read somewhere that affected customers have been contacted by Revolut, so if you haven't been contacted you're probably(?) fine.
Why too late? Is there some cutoff date that's relevant here?
I also closed my account earlier this year, or maybe late last year.
Fair point that there are other dangers (e.g. surveillance) that we have much shorter and more concrete paths to, here, which might require very different responses.
What what what? I use revolut, did something happen?
Their api is the least shit out of those modern banky things
There was a customer data leak. It's been in the news last 2 days.
They really are. In my sec update yesterday, I saw the Germans were hacked with data being put up for sale for 30 btc, and IDScan in the US which collected loads of PII like drivers licenses and their *photos* and passport numbers
Yes they are, some come with lawsuits, some come with data leaks, some come with rug pulls. Pick your poison I guess.
Yes, bad outcomes definitely possible: they've happened with previous technologies, too. But extrapolating to super-intelligent machines has a long history: the real damage was elsewhere.
That's not a p2p tradfi app, reads like multiwallet.
Revolut is the worst of all these p2p apps.
And they're all bad.
My understanding of phoenix is that by using acinq's node, we lose a good part of the privacy that lightning would otherwise give us. Also, that if something happens to their node, the procedure to get our funds back is pretty complicated (for a non-dev). Would you say those are fair assessments?
Yep you trade privacy off for reliability. Only partly of course, but you do. Not a panacea but way better than custodial. That's how I see it. Re: complicated to get funds back, I don't think so, but I'm not sure, haven't tried it recently. There is a close channel option that presumably force closes as you'd expect.
Phoenix because it's reliable while self custodial.
In the last year or two I haven't even bothered to run my own LN node at home (or elsewhere). I used to, but I don't have the motivation or the organization to do it properly. Which is a shame, but shrug.
Also my case is not normal, I spent the last few years in El Salvador mostly.
I've used lightning for lots of things but my experience has been that to work, it had to be used either from a custodial app (ecash mints) or a wallet that used liquid on the backend. I can't count the number of failed routes I ran into with self-sovereign options (my own node).
Would you mind saying which lightning application you like/recommend for these buys?
In this particular case, I disagree.
Responsible disclosure to blockstream security could have resulted in a stop of liquid block production, and therefore not put any user's funds at risk.
If they did report it and Blockstream did nothing, then the right move is to take the money.
Holy shit... I mean it looks like it's not fully confirmed yet but that was one of the holy grails of mathematics O_o
This is wild.
...vibes.
https://cdn.nostrcheck.me/bc9b39f5ad03f37666b080cb36fb18b4bbcade14783a71b049cd960964427a4a.gif
I did. I have a vague impression that it's overblown. Very vague though. The thing is, how much difference does it really make, long term?
From what I read, the timing is suspicious, but you make a good point. If what they claim is true (and not outright stealing his insights directly), the model training on what users did just gets rolled up into future models I suppose.
I guess I'm all for it. I don't know the details of this specific problem, but it'll be interesting to see what categories of problems withstand this type of progress.
Did you catch the controversy around Navier Stokes? OpenAI apparently "stole" some intel from a mathematician who was using it to develop his proof. I didn't go deep into the details.
ethics and permission-less are orthogonal and difficult to hold at the same time. math and physics say what you can do, society what you should
it's a common category error to say that math or physics determine what you should do, just as it is to say society determines what you can. taking from someone is always wrong, even when you can do it easily, and doing what is right is sometimes impossible
my resolution is to see that it's okay for people to do things that are wrong, and also for society to punish them for it, if they can. the best we can do as technologists is to try to make what we feel to be right easier, and to be wrong harder
Yeah i qualified in reply. But this is nostr, so, understandable 😄
It's really something how many (respected) developers in the Bitcoin community used this ordeal as an opportunity to dunk on Monero and privacy tech.
It's such a lazy and unfortunate takeaway from this circumstance.
You earn respect that you didn't do that and approached all unfolding events with a proper critical eye.
*if you return the full amount
I wrote that before the 15%.
The other two points are good. Especially the first one; since they could take anything, it's a particularly good point.
The third one is not as clear cut, but definitely to be considered.
Good qualifications but I don't see how it equates to "No". I trust myself to keep a private key safe for a short period. And giving it back wasn't hard either, as has been demonstrated now.
They didn’t even bother to steal all the money, a huge amount was left vulnerable. Also, specifically to liquid, they have back doors to halt the system so reporting it to them can likely get the issue locked down faster than you can exploit it.
Finally, they kept 15%? That’s not even remotely white hat behavior. They just wanted to use the term “whitehat” to reduce risk of FBI.
I think this amount is above the whitehat threshold :-)
#nevent1q…znng
Taking 598 btc in exchange for finding the exploit isn't exactly "whitehat" behavior.
'Wrong' was oversimplified on my part, though I stand by it.
What I was thinking about more was the risk. Taking a big chunk (as apparently they now have done) unilaterally puts them firmly in the criminal category from a legal perspective. IANAL but I think they could have very reasonably and ethically argued that they did not steal, if they hadn't done that.. Now, they cannot. Of course if their opsec is tight, they may avoid the consequence, but that's another Q.
598 BTC is one hell of a bounty
They did it for a better bounty amount because bitcoin projects don't pay anything.
Yes, that's what's happening. They're finding a way to return that bitcoin safely to control of the 11/15 federation multisig (if they're honest). Which they could do immediately *if* the signatories didn't have infrastructure that automatically sends it out on any "valid" Liquid transaction that has a peg-out.
So yeah if Liquid is currently 100% shutdown then it'd be safe to send, even without a bugfix. Maybe that's your point.
I don't know if the blockchain is totally or partly shutdown right now.
Isn't this the bitcoin that is owned by Liquid as collateral? No need to deal with customers directly, just find a way to return the collateral safely so that peg outs can work again no?
To be fair, I don't really know how the sidechain works so this is really me probing to learn more.
Ah you're right. Sorry. I'm a bit retarded today
maybe law of salvage should be applied here in regards to the bounty
Yes, people should definitely be spooked! Not saying "definitely the guy has good intentions ".