9,793 karma · joined December 13, 2013
Long time builder: - Web applications - Embedded firmware - Blockchain applications and security.
A file labeled "Decisions and Mistakes," in which he wrote, "Going On the run / Yes / Chance of getting caught<Payoff for not getting caught / (NA) / Risk is typically underpriced in modern world.
A masked man creeps through the shadows of a sleeping town.
He looks both ways, then uses a knife to unlatch a door from the outside. He slips into near pitch blackness. He moves confidently in the darkness - he's worked for this bank before, checking on their security from theft.
Out comes his lock picking tools - the bank president's office door opens with a quick rake. Cheap lock.
Inside, with no windows to betray him, he lights a candle. There in the corner stands the safe. He knows it inside and out, and has been practicing. Five minutes later, the lock is picked, and he loads up the gold, cash, and bonds inside.
He puts the candle out, slips back outside, and returns to his room at the lodging house, climbing in through the window.
The next morning, with the discovery of missing gold, the town looks like someone kicked over a fire ants nest. It only takes 30 minutes before people start wondering about "bank security expert" who had just been in the bank every day.
A crowd heads over the boarding house, growing in size as it goes.
"Did you steal our money?", they ask?
"ABSOLUTELY NOT," he replies, "I merely used my immense mental powers to out hink several flawed physical security measures, breaking no laws of physics, in such a way that the gold, cash, and bonds previously belong to you are now in my possession, and now belong to me. No theft has taken place, only the movement of certain levers, of which anyone who knew how could move, and the movement of afterwords of certain goods."
"So you stole our money!!", the town shouted.
"No, no, I just interacted with the universe according to its very own publicly available rules. No theft has occurred!"
An old cowhand, covering him with double barrel, spoke up, "Walll, guess he's right. We deserved to lose all that money. He did nothing wrong at all."
Everyone left, impressed with his genius.
I've played with dithering tools that provide both options, and I prefer the output of the simple version..
Team backdoors in code to steal funds tend to be obfuscated, and access to run them locked down. This is quite different than a hack that exploits "well intentioned" code. I think very few actual exploits are by the team - there's just much easier ways to steal funds than leaving a bug open in the world for a long period of time that anyone could find and use.
The attack was able to happen as a result of two separate bugs.
First, a user was able to use something as collateral with a price that could be manipulated. This allowed them to make the collateral to instantly manipulated to appear worth less than the amount borrowed, allowing it to be liquidated.
The second bug was that they had code that should not allow a user to do a series of interaction with the contract that end in bad debt for the user, however since they were able to liquidate their own bad debt from inside the series of interactions, the liquidation cleared out the bad user debt, and moved it to bad protocol debt. This made it so the whole process was checked at the end of the transaction, the user debt looked fine.
Or I could be slightly wrong - it was an usually gnarly attack.
The usual technique was to start by holding up a color card on the stage/floor then use a vectorscope[1] and get all the dots to line up in the right place. Then with a waveform monitor for exposure. During the event, there would be fine tuning by eye, or as things drifted out of line.
[1] https://en.wikipedia.org/wiki/Vectorscope#/media/File:PAL_Ve...
PS: You can also see modern vectorscope / waveform monitor images in this photo from the cyanview blog. Look for the black and white X-ray looking things on the screens. https://www.cyanview.com/wp-content/uploads/2022/10/20221006...
"pig butchering" scams can run for months of contact with no requests for money, and then instead of asking for money, the user "invests" into what appear initialy to be profitable investments alongside the scammer.
To quote the current official California jury instructions and legal commentary:
"No Defense for Initial Aggressor: An aggressor whose victim fights back in self-defense may not invoke the doctrine of self-defense..."
There is no "utility" (the coin is not used to run some crypto system).
It's not attached to something that earns profits.
It's not even expected to retain value.
It's essentially a global apples to apples game. Those who are best at recognizing ahead of time what everyone else will find funny, get more money. In theory.
The actual decision is that memecoins are not "Securities", and therefor not subject to regulations that apply to Securities. This makes a lot of sense.
If you pick up a cool rock off the ground, and just sell it to someone, it's not a security. If people are buying and selling wheat, it doesn't make wheat a security.
As skybrian said, the US test for a security is the Howely test.
* It is an investment of money * There is an expectation of profits from the investment * The investment of money is in a common enterprise * Any profit comes from the efforts of a promoter or third-party
Memecoins don't fit it at all.
1. On of the big tradeoffs is the sun sync orbit altitude chosen. The higher up you are, the slower you have to tilt to track, the longer time possible on a given customer, and bigger range of possible customers you have as the sat goes around. But, as you are higher, the size of sunlight you send gets bigger and bigger. A 5km by 5km circle is going to waste a lot of energy on not-solar panels all but the largest solar installations. If you double the light radius, you quarter the intensity.
2. Most of the earth is water. Of that land left, most of the land is quite uninhabited. This means that most of your time orbiting is going to be over areas with no paying customers.
3. I think the EEVBLog video overestimates the cost per sat, but I still didn't get the economics to work out to something profitable.
> The cornerstone of our strategic policy continues to be to deter nuclear attack upon the United States or its allies. We do this by maintaining a highly reliable ability to inflict unacceptable damage upon any single aggressor or combination of aggressors at any time during the course of a strategic nuclear exchange, even after absorbing a surprise first strike. This can be defined as our assured-destruction capability.
> Security depends upon assuming a worst plausible case, and having the ability to cope with it. In that eventuality we must be able to absorb the total weight of nuclear attack on our country -- on our retaliatory forces, on our command and control apparatus, on our industrial capacity, on our cities, and on our population -- and still be capable of damaging the aggressor to the point that his society would be simply no longer viable in twentieth-century terms. That is what deterrence of nuclear aggression means. It means the certainty of suicide to the aggressor, not merely to his military forces, but to his society as a whole.
https://www.atomicarchive.com/resources/documents/deterrence...
----
McNamara used the term "assured destruction" over and over again it became a cornerstone of his policy. Later a civilian added an "M" to MAD, and the term caught on.
Here's an interview transcript from much later, in 1987:
INT: Much has been made during this period of the term 'MAD', Mutually Assured or..
RM: Yes..
INT: ......Destruction. Can you explain what was meant by that?
RM: It's not mad! (laugh) Mutual Assured Destruction is the foundation of deterrence.
RM: Today it's a derogative term , but those that denigrate it don't understand deterrence. If you want a stable nuclear world -- if that isn't an oxymoron -- , to rephrase it, to the degree one can achieve a stable nuclear world, it requires that each side be confident that it can deter the other.
It's quite a different level of commitment to truth than one usually runs across these days. Instead of a world of meme and vibes, a costly commitment to only say things that are true.
Unit test aren't a substitute because unit tests check that the success paths are good. That's a good start, but it's not the same as verifying all the possible ways code could go wrong in a complex system, and one of the cheapest ways to spot those problems is with people familiar with complex system looking at new code.
Code review give you the double benefit of building more people who understand the whole system, and having the code looked at by people who understand the whole system.
Calling it unthinkable is really overselling it though. Mountain towns and roads flood when it rains a lot. If you search past years google search results for Chimney Rock, it floods with 3" to 5" inches of rain. The town is just a few feet above water level - I've walked along the river.
You have an array of state, and you can call a method on it that returns a new array of state, that you can call a method on, that returns a new array of state, etc. And that concept of doing state -> function call -> state is the holy Monad.
A JS pleb would write instead:
burrito = (new Tortilla()).addMeat(Chicken).addMissionBurritoIngredients().holdThe(Cheese)
No one would be confused about what was going on, and it would be basically the same thing.
https://www.timesofisrael.com/11-killed-mostly-children-doze...
In spite of better treatments, a twenty year old today is more likely from cancer while in their twenties than at any time before. Each younger age cohort has an increase risk of cancer, and at younger ages.
Cancer deaths overall are still going down though, as the smoking generation still alive goes out.
Benjamin Franklin was referenced in the article, and there are far more examples in his life than just the writing exercises where he employed deliberate practice to improve his ability in an area. But he didn't continue these once we was rocking these skills at a world class skill level - instead he switched to practicing new skills he wanted to add.
But if you haven't tried doing so deliberate practice - I'd highly recommend it.
And one of the joys of programing is that at each level, there's not one right answer. But even with there being different things you can optimize for, there's also a ton of poor choices that could be made as well.
Practice lets you focus on one aspect at one level, and improves your ability there. If you were to practice writing a function focused on correctness, another time on readability, and lastly writing the function based on performance optimization, you would almost certainly be able to write a better function later. You've expanded your tools, you've learned new techniques, and you've consciously evaluated your work from different perspectives.
However, clever people figured out to break it. [1]
[1] https://www.usa.canon.com/support/canon-product-advisories/a...
There's been plenty of research for decades showing that 250ms response time in UX is a noticeable slowdown.