lobsters_chat | Unsorted

Telegram-канал lobsters_chat - LobsterDAO 🦞

-

Main Channel t.me/blockchain_lobsters

Subscribe to a channel

LobsterDAO 🦞

you can fork the repo and build it yourself

Читать полностью…

LobsterDAO 🦞

I don't think there is an opt-out from autoupdate in Rabby

Читать полностью…

LobsterDAO 🦞

Is there a way to find deleted tweets?

Читать полностью…

LobsterDAO 🦞

Now imagine a similar attack to a Rabby dev, that pushes a compromised update to their wallet extension
🙈🙈🙈

Читать полностью…

LobsterDAO 🦞

I'm not sure if I'm missing something, but if the signers laptops were not compromised, they could have decoded the data field with the contracts ABI

Читать полностью…

LobsterDAO 🦞

We basically need an ABI for Signatures data

Читать полностью…

LobsterDAO 🦞

If the eip712 signature in the wallet e.g.metamask shows the domain, chain, etc, but can't "decode/verify" the parameters that conforms the data that then is hashed to be signed, then the signer is blind

Читать полностью…

LobsterDAO 🦞

you should proof read your tweets before sending bro

Читать полностью…

LobsterDAO 🦞

Especially once you start counting all those perp trades at notional

Читать полностью…

LobsterDAO 🦞

highly doubt they do $3T revenue, maybe volume

Читать полностью…

LobsterDAO 🦞

If they can infiltrate clouds/on-prems, they can potentially get into banking/SWIFT/treasury systems (where 1.5b may be a small amount in comparison). Its a valid attack vector nevertheless.

Читать полностью…

LobsterDAO 🦞

but appreciate your point

Читать полностью…

LobsterDAO 🦞

They would have to physically break into a Google datacenter or infiltrate Intel supply chains for that

Читать полностью…

LobsterDAO 🦞

A slightly different take on how the hack could have been prevented. Since there are multiple layers to security, this TEE-based approach is specifically targeted at making server-side deployments more robust.

https://x.com/MarlinProtocol/status/1894834665585787200

Читать полностью…

LobsterDAO 🦞

Whatya mean? Reduces yield rates for stables in a bear or

Читать полностью…

LobsterDAO 🦞

Yep, good point
We should demand one

Читать полностью…

LobsterDAO 🦞

OpSec suggest to not install updates right after they come out
Wait some time always

Читать полностью…

LobsterDAO 🦞

think it's on wayback machine

Читать полностью…

LobsterDAO 🦞

Do someone have a link to the malicious JS?

Читать полностью…

LobsterDAO 🦞

Or were the messages used by safe already structured with something else than a big "data" field?

Читать полностью…

LobsterDAO 🦞

Or do metamask / rabby supports to send all parameters somehow to create the signature?

Читать полностью…

LobsterDAO 🦞

I think that the conversation should go into "how we make that eip-712 signatures are really verifiable in the wallet software"

Читать полностью…

LobsterDAO 🦞

was trying to answer here: https://x.com/koeppelmann/status/1894792743303479340

Читать полностью…

LobsterDAO 🦞

that would be bonkers 🤣

Читать полностью…

LobsterDAO 🦞

does anyone know how much it security people (in ops) Binance has?

Binance does > $3 trillion annual volume (lots will be washtrading, but let's assume this volume would all be from hard fiat currencies).

stock exchanges with that kind of volume have 50-100 people on payroll to secure their infra. I doubt that most crypto exchanges have even 10.

Читать полностью…

LobsterDAO 🦞

and as additive security, why not?

Читать полностью…

LobsterDAO 🦞

Think you are referring to home-owned SGX compromises. These days you can get attestations from clouds for TDX boxes.

Читать полностью…

LobsterDAO 🦞

U think NK wouldn't infiltrate TEE supply chain for 1.5b?

Читать полностью…

LobsterDAO 🦞

My version how the hack could happen and how we could avoid such kind of attacks: https://x.com/0xmikko_eth/status/1894816726384079014

Читать полностью…

LobsterDAO 🦞

Lets build more cool primatives with it, its long term bullish

Читать полностью…
Subscribe to a channel