-
bemore
I don't understand why people are getting suddenly worked up over transparency when they haven't bothered to ask in the first place. These channels are active and responsive.
-
selsta
A lot of people asked for core team transparency.
-
selsta
The first report is a step in the right reaction.
-
bemore
oh, well nevermind me if they have :P
-
rbrunner
Supercop was merged? Where can I see that? Was not able to find the PR / commit.
-
rbrunner
Ah, never mind, found it:
monero-project/supercop #3 It's not the master branch, but the monero branch there
-
selsta
-
rbrunner
Alright, thanks. Just because somebody today on Reddit was crying out for good news about Monero :)
-
selsta
though compiling the monero-wallet-crypto-bench bin requires some cmake magic
-
rbrunner
Uh, with "cmake magic" I am sure not to apply
-
selsta
I can explain it if you want to test it on your system
-
ErCiccione[m]
About yesterday's discussion. I would like to have some info from the core team about their plan to avoid the general fund to get drained in a year or so. The suggestion from luigi1111 to move rehrar's job to a ccs system + core filling the shortcoming sounds like a good short term solution to me.
-
ErCiccione[m]
I'm aware my tone can often sounds harder than it actually is, so i rephrase the first part from "i would like some info" to "i would like a conversation to be started about it"
-
ErCiccione[m]
If that makes sense :D
-
bemore
ErCiccione[m] I don't participate much here, but in my experience with places that have a diffusion of responsibility, conversation topics need to be directed at individuals rather than an open room. I don't know how the core team operates, but I bet if one of them felt responsible for this specific issue, he would help coordinate discussion in a positive way.
-
ErCiccione[m]
I see your point, but i'm confident they are aware of the issue after yesterday's discussion and will discussec the feedbacks received yesterday. I'm merely making some pressure, because i forsee problems if the issue is left to collect dust.
-
gingeropolous
nonsense, monero's goin to the effin moon. all our prollems solved. mo money, no problems, thats how the song goes
-
bemore
well, you can be confident or be certain :P
-
sgp_
ErCiccione[m]: we will definitely discuss it to some extent tomorrow during the Coffee Chat
-
sgp_
But it's meant to be a casual discussion, not for formal decisions lol
-
Inge-
Looks like malicious code allowed someone to print an extra 300M rvn
-
sech1
yeap
-
hyc
-
dsc_
> A community code submission caused a bug that has been exploited. Law enforcement has been notified and is working with us.
-
dsc_
;')
-
selsta
a wallet bug can mint coins?
-
hyc
with an incompetent enough dev team, anything's possible :P
-
sech1
what does law enforcement has to do with it? I'm not a lawyer, but I can't see any law that was broken
-
sech1
Code reviewed and checked in? Then it's a new consensus.
-
hyc
yeah that sounds like a stretch
-
sech1
attacker played by the rules
-
sech1
it's like Ethereum DAO hack
-
midipoet
unless there was a responsible disclosure agreement that was breached? would that be illegal?
-
hyc
agreement between which parties?
-
fluffypony
I don't know if the code submission was malicious
-
fluffypony
or they're trying to say that it's not "core devs" that caused it
-
hyc
core or not, nobody caught it in reviews
-
hyc
but since they know the offending commit, they should have some idea of the type of person who wrote it
-
derpy_bridge_
<[discord] Kayla#5718>: it was malicious but since the bug abuse been done from unknown party then that's just the perfect scam
-
derpy_bridge_
<[discord] Kayla#5718>: on one end code been pushed (that dev could just be like they didnt see that coming) and on the other end there's the other party (which could be the same but cant prove it) that did use that fuck up to go brrrrrr
-
hyc
yeah, hard to believe the bug was accidental and an unrelated party discovered it and exploited it
-
sech1
Are the details published yet? I'd like to see that sneaky code
-
fluffypony
no not yet
-
fluffypony
they released closed-source bins to fix it
-
hyc
talk about flawed processes
-
hyc
... if this happened to us, would we also release closed-source binaries to fix?
-
hyc
"this" meaning a bug discovered long after the fact
-
sech1
last time we had an inflation bug, the fix was public but not announced
-
sech1
until deployed
-
hyc
sech1 yes but nobody had exploited it
-
fluffypony
hyc: no, we wouldn't
-
fluffypony
if it's REALLY bad we would discretely give mining pools and exchanges a patch
-
fluffypony
and have them build from source
-
fluffypony
and then once enough of them they confirmed they'd updated with it we'd make the patch public
-
hyc
makes sense
-
fluffypony
we've done that once before iirc
-
Inge-
300M RVN is a nice $5M.
-
tevador
that was an expensive audit
-
midipoet
lol
-
hyc
$5M is only scratching the surface. the reputation cost will be more
-
hyc
there are thousands of projects. why invest in one with a proven loss?
-
needmoney90
because historically most projects that had that happen dumped, and the performance after the aftermath was actually decent (from memory) 👀
-
needmoney90
weak hands leaving and all
-
needmoney90
I've never tried to play that game tho
-
niocbrrrrrr
bytecoin inflation bug was exploited and when announced it pumped
-
hyc
talk about stupid money
-
niocbrrrrrr
it may have been added to an exchange or two afterwards as well
-
hyc
even knowing the devs are dishonest
-
niocbrrrrrr
ofc everything pumped at that time
-
sgp_
Weigh that against us all talking about RVN here. Free marketing
-
derpy_bridge_
<[discord] Kayla#5718>: bad press is good press eh 😛
-
derpy_bridge_
<[discord] Kayla#5718>: it still getting the word out, to communities that didnt know aobut it then it still brings some more people that start googling about it [...]
-
derpy_bridge_
<[discord] Kayla#5718>: batman (bruce) pinging fullypony on twatter, monero irc channels now talking about it
-
derpy_bridge_
<[discord] Kayla#5718>: i think it would only be fair if the word of monero being brought over their communities too, just sayin uwu
-
derpy_bridge_
<[discord] Kayla#5718>: gotta brainstorm on how to get bad press on monero since that's the way to go
-
shillo
when will xmr get its emoji?
-
shillo
even tron has one
-
shillo
-
dsc_
.soon
-
monerobux
Two weeks™
-
derpy_bridge_
<[discord] Kayla#5718>: :xmr_monero:
-
derpy_bridge_
<[keybase] kaylasu>: :xmr_monero:
-
derpy_bridge_
<[discord] Kayla#5718>: @shillo that's some not very subtle shill u be doing right there tho 😛
-
needmoney90
thats about as subtle as a brick through a window
-
needmoney90
ban
-
derpy_bridge_
<[keybase] kaylasu>: oof, rude x)