Developer posts secret key on GitHub, loses $40K in 2 minutes
cointelegraph.com
cointelegraph.com
Ah, schadenfreude.
So when competitors, like hardhat and foundry, popped up what did they do? Used default shared accounts and keys. We reached out to let them know that users will lose funds, but all they did was add a warning in the CLI output and in docs. Devs still regularly lose funds: https://etherscan.io/address/0xf39fd6e51aad88f6f4ce6ab882727...
This repo should have had all types of static analysis running automatically.
Hell, GitHub has built in secret scanning. Apparently it was only set as the default for all new repos in March 2024[].
[] https://docs.github.com/en/code-security/secret-scanning/con...
How does the monetary value matters? A prototype is a prototype, a quick project to test some concept. If you wanna test some concept around large transfers, does that mean it's suddenly not a prototype?
> This repo should have had all types of static analysis running automatically.
Would that actually prevent this issue? So lets say they make the repository public, the static analysis tool begins screaming at the repo owner. Now, he has 2 minutes to transfer those funds somewhere (manually), before the thief automatically makes that transfer for them, to their own wallets.
Sounds like the guy just needed a hardware wallet instead of whatever they were doing. Who stores unencrypted wallet details containing $40K on disk?! Committed to git?!
Totally agree wallets with any real amount of money should probably not be on disk
Of course, an escape hatch (like adding some "I know what I am doing" tag to the commit) would be necessary but that's trivial to setup.
The public events API is delayed by 5 minutes[1]. Unless someone was actively scraping his profile rather than doing large scans on GitHub, this is not possible.
[1] https://docs.github.com/en/rest/activity/events?apiVersion=2...
GitHub even lets you find them easily: https://github.com/search?q=language%3ASolidity&type=users
Also, I expect anyone working on high-value systems to be under more targeted scraping.
Edit: and what’s the best practice here? Is it using a key management system of some sort? (I’m thinking of scenarios where you might need to deploy your code + secrets on a remote server, say to authenticate with a third party API)
@your edit: you can use environment variables for example, just don't commit your dotfile or just don't store in the same folder as the repo if you don't know what a dotfile is.
There are other services that manage securely saving/storing these keys rather than just hosting it on the server itself (e.g. AWS Secrets Manager)
For example most/all VPS provider allow you to give extra data to the machine; this could be the secrets directly or maybe a connection url to a local* redis server with the configs.
Or you can copy paste a file vis ssh.
*AWS-like providers allow you to also deploy private networks so that only approved services vps can access a db
When you deal with high value amount of cryptocurrencies, you have a hardware wallet so things like these are not even possible in the first place, as the keys are safely stored in the hardware. Storing anything on disk (unencrypted at that) that corresponds to $40K is basically begging to be stolen from you.
Besides that, when you open source something that even has a chance of containing something you don't want to make public, you read through every single file before hitting publish.
> I’m thinking of scenarios where you might need to deploy your code + secrets on a remote server, say to authenticate with a third party API
Commonly you use environment variables for this. So the code references `process.env.MY_SECRET_VAR` or equivalent, and then you set that variable inside your server. That's the simplest way, then there are more complex/"secure" ways too, quick search for "secrets management" in your favorite search engine will tell you more.
Protecting high-value cryptocurrencies is particularly hard, and as much as crypto people like to say "not your keys, not your coins", the reality is far more nuanced, and the average person is much better off using a well-known platform like Coinbase. Even hardware wallets are not as simple as people thing to use safely.
(If you're building cryptocurrency apps, never upload wallet private keys to cloud KMSs. Instead, generate wallet keys using the KMS itself, and use those wallets for small "in-transit" funds only. Think of them like bank branches, when you manually transfer small amounts of funds securely from a set of central wallets.)
There are a variety of options, depending on what type of software you're developing, how much you're willing to be locked into third party tools, and things like that.
The simplest is to just save the credentials somewhere like the user's home directory, outside of the git repo. This is what a lot of command line tools do.
Environment variables are also a popular option - most CI build systems will let you store 'secrets' that are passed into the build process as environment variables.
Larger scale projects will often end up with a configuration management mechanism, enabling 'configuration as code'. When doing this it will often be interlinked with credential management. After all, why not store the hostname of the database alongside the username and password?
If you're in a cloud environment, they will have 'instance metadata' that can (with configuration) pass cloud provider credentials into your instance. They will often provide a secret store service you can access using those credentials, and will let you authenticate to databases and blob stores and whatnot using those credentials so long as you stay within their cloud ecosystem.
Large corporations like 'credential rotation' where secrets get revoked and re-issued on a regular basis. The cloud environment can do this between your instance and their provided services - or you can do it yourself in an ad-hoc way.
All the major PC operating systems provide a secret storage function or 'keyring' although it's debatable whether it's all that different to just saving a file on disk. It used to be, back before the rise of full disk encryption though.
And of course if you're writing a mobile app, the operating system is a lot more locked down. So there you can store credentials in the system keyring and other applications can't access them.
Not even then and this is why
https://git-scm.com/docs/gitignore
And I see most professional senior devs training juniors to be more helpful... It is always a blessing to see that perpetual look of terror subside when people finally understand what they should be doing.
A company attrition rate is a reflection of hiring, training, and project management skills. If you have an IT culture problem, than it will manifest in the high-stress areas first. i.e. you are likely not going to survive as a business beyond 3 years.
Happy investing, and I hope someone returns his gambling chips. =)
So you can still offer any random shitcoin and make money with it. Seriously, I've got the wrong job.
If I may, I would posit all crypto is not a safe store of value to begin with. An EMP taking out the entire world power grid would render crypto pretty useless almost immediately, while gold will just sit there. Even paper money is resistant to decentralized unwindings as they are physical and people are conditioned from birth to accept their value.
I think it doesn't do this as we have seen the value of gold shift so much over time.
If we look at Roman Empire during Augustus, your average denarius penny in the empire was worth about 10 hours of minimum wage. A denarius was about 1/10 of a troy ounce of silver, and you needed 25 of these to get an 8 gram gold coin, the aureus.
Going by today's standards, your typical 8 gram coin is worth $604.96 USD
If we go by the average minimum wage in the United states, 25 days at $72.5 USD/day for 10 hours of minimum wage, in order to compare to the Roman Empire during Augustus, pre-tax, the same coin was worth $1812.50 USD.
So to briefly summarize:
1 denarius penny = 1/10oz Silver = 10hrs minimum wage, 4 hours minimum wage today nets 10 times the Silver it did 2000 years ago. You can quickly see that if anything, on the basis of Silver alone, that our currency is worth about 23.7 times more than the currency of Rome ever was if we ignore taxes.
3-5% tax rate on total wealth was murder and why riots happened to begin with.
Then we look at the cost of a average small villa in that time period- 200,000 denarii.
You figure this means 200,000 days for your average agricultural worker at 1 denarii/day, but actually it's way more than that because there's the 3-5% wealth tax on them, plus the tax collector wages came from whatever they could extort on top of that.
200,000/365 = 548 years of payments only to a house at 1 denarii/day.
200,000/30 years= 6666.66 denarii/year
6666.66/270 (because I'm nice and assume we get days off in this time period (today)) = 24.69 denarii/day, or about 98.8% of an aureus per day, would be required to own a small villa on a 30 year mortgage during the Emperor Augustus roman empire, (excluding the extreme 3-5% annual total wealth tax).
I figure most people here would agree that even at minimum wage, a personal villa is much more accessible today. Even a $1,000,000 home on minimum wage with zero other expenses or taxes, working 10 hour days, 5 days a week, would basically pay it off on a 51 year mortgage at 1631.25/month.
I think that's why so many people here feel ripped off. Homes would be much more affordable if the loan terms were slightly longer, but there's a bunch of old people out there trying to min/max their investment based income before they die.
I don't see anything wrong with them wanting to do that, but I think it would be wise if consumers began to push for longer mortgages because as a function over time, while the dollar is still worth quite a bit, it is nonetheless losing value. Keeping your mortgage going means the bank gets less value out of the loan over time, assuming inflation remains static.
I know you didn't expect this reply but I enjoyed learning and making it. If you end up going back over it and have any corrections you'd like to make I'm all ears, but I'd agree. Crypto is a crappy place to have a store of value right now and arguably you'd be a fool to not have it invested in the stock market targeted index fund because that's simply how the world of finance works today.
It's not about what we can do in a day, it's about how we can leverage the income to get more done in a day, even if it's not being done by us directly. That's why investing in the stock market, in stocks you trust as a consumer, is so important to the success of capitalism long term.
Gold is a great form of money thanks to its unique chemistry:
Its colour and lustre is unique - it's fairly easy to tell something is gold-ish by eye and weight. This is why gold was chosen by our low-tech forebears.
Its lower melting temp makes it easier to purify than say Platinum or even Aluminium.
Its inertness (thanks in part to the relativistic contraction of the 6s orbitals) mean that you can leave it in a safe for 1000 years and it'll basically be the same. You literally need conc HNO3 and H2SO4 aka aqua Regis to dissolve it.
People who think gold is a pet rock and is useless fail to appreciate that even if all stores of value are pointless and arbitrary, we still gravitate around particular stores for a reason.
I'd be fairly happy to hang onto some gold in a post Apocalyptic world if it looks like society may eventually recover.
Even stuff like coffee and oil would be useless in any size because they have a shelf life. And cash at scale can literally rot or get eaten by mice. Gold can be buried and it'll be there forever basically
It is in fact not a given(I for one do not trust the value of bitcoin or other cryptos, and I know more people who don't believe crypto has any value than those who do), and your comment is an example of attempting to coerce public opinions and beliefs in such a way as to promote crypto.
Oh, and please don't try to argue about the value of gold coming from its physical properties
I understand why you would want to discount from the conversation the very things that make gold valuable; but I don't have to let you move the goalposts. Gold has properties of corrosion resistance (store of value), rarity, and desirable qualities(such as its color and weight, using it in jewelery to attract mates) which allows it to be a medium of exchange, and the fact that it is easily separated from other metals by its low melting point, not to mention its luster is different from other base metals used for currency, makes it easy to use it as a unit of accord for payment of taxes and such. These properties are unmatched by other more common, natural materials-- that humans have long recognized it as unique and rare on Earth merely raises its intrinsic value to human society. Ya can't eat gold as a person, after all.
(lest you think me a gold bug, I don't have any gold and actively recommend that humans not possess it except where they actually need the properties in question. I do the same for fiat currency too. They're all just tools for getting by in life)
And most of the gold owned in the world is not in someone's basement, but as a line in a database; so you can wave goodbye to that as well.
We’re still doing that?
0 - https://topenddevs.com/podcasts/javascript-jabber/episodes/w...
Yes. All the web3 influencers are on AI now.
Assuming we have an ice age because let's be real that's the best way to make sure everything plastic or nonmetal stays preserved.... Ice age for most things, but we leave the technology buried near an area with high probability of pyroclastic flow.
That, or we get real and we begin leaving time capsules with mathematical proofs and scientific discoveries, maps, etc, on the moon and other planets.
Nope! It's going great[1]!
Fees are for inclusion of a transaction in a block. And some pretty clever game theory was implemented as part of eip1559 in Ethereum to make fees efficient and fair.
Some semi-centralized infrastructure and development is needed and costs money to run, but the questions unique to each circumstance are: "What do revenue and EBITA look like?" and "How efficiently are CapEx and OpEx used?"
OTOH, if a social venture nonprofit ran a coin with survival in mind rather than get-rich-quick fintech profiteering, it could make a promise to keep overhead low and any sort of profit margins for reinvestment in robustness, stability, features, and auditing controls to a small, fixed %.
Cryptobros telling you never to use an exchange due to FTX and other examples, also its super easy to use...
What stupidity
You referring to your comments?
(now we wait for dang to delete these comments)