15:49:21 we should have a meeting today to discuss the second BP+ audit 15:49:38 we have received 2 SoWs 15:52:51 https://github.com/monero-project/meta/issues/553 15:52:57 2 SoWs are in the issue 17:00:59 Monero Research Lab meeting time 17:01:59 ping ArticMine sarang knaccc DeanWeen Isthmus SerHack vtnerd xmrscott 17:02:26 I know this wasn't scheduled much in advance, but we need to make a decision on BP+ today 17:02:36 hey, I'm partially around 17:02:37 (ideally regarding the audit because we now have SoWs) 17:03:45 https://github.com/monero-project/meta/issues/553 17:03:55 first up, BP+ second audit 17:04:36 we have received 2 SoWs 17:05:04 TrailofBits may be submitting one, but it's been a few weeks and we don't have it yet. They are also not likely available in the short term 17:05:11 Quarkslab: https://github.com/monero-project/meta/files/6037184/PRO_Quarkslab_Monero_Bulletproof_RPS_security_assessment_public.pdf 17:05:19 JP: https://github.com/monero-project/meta/files/6037185/bpplus-review-sow.pdf 17:10:22 wow, silence lol 17:10:58 hey! 17:11:05 hey serhack :P 17:11:24 here's what's next for the audit to proceed 17:11:28 1. we need to pick one 17:11:47 im interested I just have no idea what's going on, so just observing 17:11:56 2. I need to confirm with MAGIC that we can open a campaign for this (likely) 17:11:59 +1 for JP, I chatted for a while with him and he seems really expert, I wonder about deadline 17:12:16 JP says he is available within the next 1-2 weeks 17:12:26 we can have an audit report in 3 weeks 17:12:29 woof that quarkslab 17:12:31 from today 17:12:35 I see 17:13:09 and what about quarkslab? 17:13:16 I think Quarkslab is a good choice, but I have a lot of confidence in JP and think he is a great choice personally 17:13:53 JP is also <1/3 the cost 17:13:56 who / what is JP? 17:14:20 gingeropolous: https://www.aumasson.jp/ 17:14:58 JP led this Monero bulletproofs audit https://research.kudelskisecurity.com/2018/07/23/audit-report-of-moneros-bulletproofs-integration/ 17:15:40 JP also audited CLSAG https://ostif.org/wp-content/uploads/2020/07/ostif-clsag-audit-final-public.pdf 17:18:00 * xmrscott[m]1 attempts to slide into meeting quietly 17:19:45 JP is a really good choice 17:20:16 imo, with his expertise and immediate availability, we jump on it 17:21:31 and we would do it through magic so we can send him a check in USD, and USD and XMR donations would be tax deductible 17:21:48 so that'll be 2 total audits so far? 17:21:59 if JP is selected? 17:22:02 the original plan was to do 2 17:22:21 yeah, JP's will build on the previous one which was quite extensive 17:24:10 ok. my general gut feeling is to not skimp on this, mainly because of all the "mOneRo prIntS iNfIniTe mOneY", but thats not really technical or scientifically based opinion. 17:24:21 I'd do JP, seems like a suitable candidate + availability 17:25:03 gingeropolous: I think a third is relatively excessive personally, but obviously security is important 17:25:41 first audit: https://suyash67.github.io/homepage/assets/pdfs/bulletproofs_plus_audit_report_v1.1.pdf 17:26:18 right. at what point is it just throwing money at a problem just because. i dunno. 17:28:08 is there anyone here that feels strongly that we need a third? 17:28:20 it's good that this is iterative though. can always assess after JP whether a third is warranted. 17:29:02 is there anyone against me opening the fundraising campaign for JP ASAP? 17:29:22 I'd go for assessing after JP, if the time frame allows it 17:29:50 but that's not something we want to rush anyway 17:32:18 Sounds like no one is against then 17:32:32 *against doing the JP campaign ASAP 17:33:06 okay, I will talk with MAGIC and open a fundraising campaign for JP's audit pending board approval 17:33:20 if MAGIC can't do it, I'll let you know ASAP and open a CCS 17:34:08 Thanks for coordinating this 17:34:33 ty to sarang also for sitting on some of the auditor calls with me :) 17:34:48 is ArticMine here to talk about the block size / fee penalty? 17:36:51 any other MRL topics for this meeting? 17:46:19 okay, meeting adjourned then :) 18:24:31 guys 18:24:47 how much is such an audit expected to cost, and how many manhours are put into it ? 18:25:54 CrimsonKing: the one from JP is for $12500 18:26:12 the one from Quarkslab is $41,250 18:26:32 appreciated. 20:20:52 Remember kids. If you call project coral reef for what it is - fluffypony embezzling half a mil usd from the monero fund for a website with smaller adoption than monero woo plugin, you will get excommunicated. Why do you think charities need Teslas? They don't and Elon won't support Monero 150k will sure buy a lot of party time for those that actually do get it.