2,082 karma · joined November 20, 2013
https://twitter.com/thebensams
https://github.com/bsamuels453
Blockchain clients tend to want to publish the report, but that isn't true for our business lines/projects/clients that are more interesting to HN's audience.
Another use case you might run in to as you talk with more clients is figuring out what developer IAM roles need to be. This was the far bigger problem for us as we had a ToS that restricted employees from viewing/accessing user data.
the crass bullshit that people on HN say astounds me every day. the victims here are literally the people who need protecting the most
Looking over all the old YC projects that ended up being wildly successful, but their HN threads were full of naysayers who are better at sounding smart on the internet than providing actual feedback. Learning to differentiate between that kind of poster and people who have genuine feedback that reflects what users actually want is invaluable.
If 99% of Tor's volume is helping laundering international drug trade money, distributing CSAM, etc, should it be demonized as well?
Using h1 isn't about bug bounties, it's about not having to spend a 1-2 of your team's full time engineers triaging security researcher reports.
RE the second point: highly recommend taking a look at the arweave white paper. They use an interesting pricing mechanism that tries to account for the cost of the next 200 years of storage (dunno where 1000 came from, the spec plans for 200).
Ethereum has the first, the second is wip.
I read it once when I was a junior engineer and didn't get much out of it, then again 6 years later and it was _excellent_.
memory has to stay as cool as possible or else the overclock will be unstable.
This is pretty well documented in the Cryptopians book; the DAO hard fork was driven almost exclusively by people outside the EF.
This is like the 10th algo stablecoin to eat shit. You would think by now, a risk person could adequately describe these existential risks.
Stablegains was a rent collecting middleman. The risks are not characterized adequately on this page, and there ought to be some level of liability.
Hashcat was proposed over 20 years ago. You really think out of all the tens of thousands of security engineers working on this problem, nobody has ever considered it? Get a grip.
I hate how this website incentivizes people to try to make posts that sound smart instead of posting stuff they're actually knowledgeable about.
Blocking individual IP addresses has never been a valid mitigation against professional attackers. Attackers will just pivot to renting a different botnet from different geographies/ip ranges.
If your service has any level of scale, there can be double digit percentages of users who are sharing an IP address with a hacked device. Blocking attacker IP addresses will block users of your service.