Register and share your invite link to earn from video plays and referrals.

sudo rm -rf --no-preserve-root /
@pcaversaccio
๐–๐จ๐ซ๐ค๐ข๐ง๐  ๐จ๐ง ๐ฐ๐ก๐š๐ญ'๐ฌ ๐ง๐ž๐ฑ๐ญ. ๊ŸผG๊Ÿผ: 063E 966C 93AB 4356 492F E032 7C3B 4B4B 7725 111F
333 Following    33.5K Followers
i'm so fucking done with all of your fucktards using hot wallets, getting compromised and losing your life savings because you stored everything on a hot device. i don't have fucking mercy with you. it's all your fucking mistake. stop using fucking hot wallets. hot wallets are a fucking bug. today alone we have had +2m in losses at SEAL 911 due to hot wallet drains (via device compromises). use a fucking cold storage wallet.
Show more
0/ As AI systems become more powerful, formal verification โ€“ which is the discipline of using mathematics to prove computer programs correct โ€“ shows more and more promise. A guest thread by @big_tech_sux, lead developer of @vyperlang ๐Ÿงต
Show more
0
116
596
109
Forward to community
guys, ethereum wasn't created to fit into the existing system. it was created to _route around it_. somewhere along the way, we stopped trying to make the old world obsolete and started asking for its approval. fuck approval. wtf are we building today that makes the old world obsolete? not 10% cheaper. not 20% faster. _obsolete_.
Show more
too many folks think privacy is about removing names. well, it is _not_. it's about eliminating _uniqueness_. once your behaviour stands out, you've already identified yourself. it's all about maximising your anonset guys, whether on-chain or across every piece of metadata you leave behind (and you leave a lot of data behind dude). the fun fact is that many times the best privacy decision is simply sticking to the defaults because the crowd is your cover.
Show more
Very excited to welcome @pcaversaccio to join us at the EF board! What he brings isn't just security and privacy expertise. He's a living example of what 100% CROPS alignment looks like in practice. Looking forward to the perspective he'll bring, and to being pushed to think much harder about security and privacy๐Ÿ›ก๏ธ๐Ÿฅท
Show more
_unconditional_ privacy
Weโ€™re pleased to welcome @pcaversaccio to the EF Board. A longtime Ethereum contributor, co-founder of SEAL 911, Silviculture Society member, and privacy and security maximalist, pc has consistently championed the values at Ethereumโ€™s core. We look forward to working together to help steward Ethereumโ€™s long-term future. Read more:
Show more
0
100
724
54
Forward to community
i recommend anyone who travels to use grapheneos and set up a duress pin & pw (and rotate both before every trip). the chances of being forced to unlock your phone, whether at a border crossing or somewhere on the street, are only going up in this insane world. it's _your_ fucking phone, your data, and your private life. nobody except you has any right to access its contents. period.
Show more
the crazy thing is that the vulnerability has been live since _August 23 2019_:
this industry has spent more than a decade lying to itself about building the future while shipping systems that can't survive the people who built them. if your application fails the walk away test, you've fucking failed. period. i don't fucking care how many users, investors, or billions it has. sooner or later every company disappears, every foundation dissolves, and every multisig stops signing. the only things worth building are the ones that keep working after everyone walks away. build something that no longer needs you.
Show more
extremely important! Letโ€™s harden Tornado Cash even further. Pure immutable onchain infrastructure *mwah* And then letโ€™s use Tornado. A lot. Bc itโ€™s truly CROPS.
i've been one of the very few people consistently reviewing tornado cash dao proposals (and man, this is fucking time-consuming), and i've come to the conclusion that the recent proposals are either malicious or just bullshit quality (and simply adds unnecessary noise). along the lines i tweeted recently of "no governance is best governance," i've been working on a _terminal_ tornado cash governance proposal that permanently _disables_ tornado cash governance so that no future proposal (malicious or otherwise) can ever be submitted, voted on, or executed again. at the same time, it adds `unlockAll()` so previously locked torn, including the torn locked specifically to pass this proposal, is never trapped. any torn held directly by the governance contract itself (i.e. dao treasury funds not accounted for in the vault) is intentionally left _inaccessible_ and will remain permanently trapped forever once the governance is sealed. my ask: please review the proposal and share your feedback (i haven't done any security reviews so far as well as i'm running on little sleep, so any security comments appreciated as well): the proposal is not live yet. i'll only deploy it if i can get sufficient commitments from torn token holders to support and pass it. if executed, torn effectively becomes a meme token. tornado cash governance must die. long live tornado cash.
Show more
i've been one of the very few people consistently reviewing tornado cash dao proposals (and man, this is fucking time-consuming), and i've come to the conclusion that the recent proposals are either malicious or just bullshit quality (and simply adds unnecessary noise). along the lines i tweeted recently of "no governance is best governance," i've been working on a _terminal_ tornado cash governance proposal that permanently _disables_ tornado cash governance so that no future proposal (malicious or otherwise) can ever be submitted, voted on, or executed again. at the same time, it adds `unlockAll()` so previously locked torn, including the torn locked specifically to pass this proposal, is never trapped. any torn held directly by the governance contract itself (i.e. dao treasury funds not accounted for in the vault) is intentionally left _inaccessible_ and will remain permanently trapped forever once the governance is sealed. my ask: please review the proposal and share your feedback (i haven't done any security reviews so far as well as i'm running on little sleep, so any security comments appreciated as well): the proposal is not live yet. i'll only deploy it if i can get sufficient commitments from torn token holders to support and pass it. if executed, torn effectively becomes a meme token. tornado cash governance must die. long live tornado cash.
Show more
it's pretty simple: my personal goal is to make Ethereum the leading privacy chain (unconditional native txs & private compute via confidential smart contracts). everything else is of second importance to me. and i don't fucking care if this is unpopular. i don't fucking care if most people disagree. i'm not fucking stopping until we get there.
Show more
look guys, it's actually pretty simple: on-chain governance is not a solution to a problem, it introduces another _failure mode_. full stop. if governance can approve arbitrary changes to mutable code, you're no longer trusting immutable code, you're trusting governance. no governance is best governance.
Show more
so i've been moving all of my actively maintained repos to require github actions pinned to _full-length commit shas_. on top of that, all jobs now use fine-grained perms, downloaded binaries are verified against hardcoded sha256 hashes, deps are pinned, and force-pushes to the `main`/`master` branch are disabled. there's really no good reason to risk dangling commits on your main branch. otherwise, anyone who gets compromised with write access could force-push an amended (and malicious) version of an old-looking commit. look, none of this will completely protect you from supply chain attacks, but it's one of many guardrails you can put in place. in the end, it's the combination of these measures that makes the difference hopefully. here my snekmate pr if you wanna check what i did:
Show more
the latest tornado cash proposal 67 is _malicious_: https://bafybeie5hxovqc4ifcnrnhvmjbefxgeix6oqvzaspyytdxiyscji22v5pu[.]ipfs[.]inbrowser[.]link/governance/67 decompilation of the proposal: the try to set the governance address to a vanity address that looks almost like the governance address: - spoofed version: `0x5EFDa50f22D34F272c7077689d6ABc42F15E285f` - real governance address: `0x5efda50f22d34F262c29268506C5Fa42cB56A1Ce` same for the staking governance proxy: - spoofed version `0x2fc93484614a34f7dbf98d7f7e997f6424e54a32` - real staking address: `0x2FC93484614a34f26F7970CBB94615bA109BB4bf` furthermore, worth mentioning the function `nullifyBalance` checks against the spoofed governance address above; so whoever controls that vanity address can zero out any relayer's balance at will. this is a governance attack on Tornado Cash and i ask all TORN tokenholders to reject this proposal
Show more
1/ A suspicious DAO proposal on Tornado Cash was created ~8hrs ago. Summoning @pcaversaccio (and everyone else curious) for an independent opinion! Details in the thread below๐Ÿ‘‡
Show more
probably only 5 people in the world care but on 2 may the tornado cash proposal 66 was accepted (i.e. on-chain executed), which means an update to the ui version (tornadocash[.]eth[.]limo and some other domains). today i finally found the time to carefully review the _two new commits_. i documented my findings in a gist. i would really appreciate an additional review from others, as i can always miss something but based on my analysis, all the changes are _legitimate_ (although the quality of the commits are shit imho). my analysis:
Show more
so four days ago a new proposal for Tornado Cash was accepted, which means an update to the UI version (tornadocash[.]eth[.]limo and some other domains). I haven't seen anyone doing a dee-dive on the diff yet so I have spent several hours carefully reviewing the changes, including a detailed check of each dep update reflected in the new `yarn.lock` file. I documented my findings in a gist (see comment section). tbh I would greatly appreciate additional review from others as I can always miss something but based on my analysis so far, the changes appear legitimate & I have found _no evidence_ suggesting a supply chain attack, despite some concerns raised by some.
Show more