HN user

cottenio

190 karma

[ my public key: https://keybase.io/cottenio; my proof: https://keybase.io/cottenio/sigs/FHkhO8bJqBOvI8sFnWQKQdswBumbSC916lTBEsoYOEE ]

Posts26
Comments37
View on HN
finance.yahoo.com 4y ago

Scrypted Named as Integration Partner for Cryptoart's Forthcoming NFT Project

cottenio
1pts0
blog.cotten.io 5y ago

Tracing the Twitter Hacked Bitcoins

cottenio
1pts0
blog.cotten.io 6y ago

Fixing SEM Campaigns with Python

cottenio
2pts0
blog.cotten.io 6y ago

Apple News Shows “Brown *****” on Front Page – Thanks BuzzFeed

cottenio
1pts0
www.trinsicoin.com 6y ago

Bitcoin energy cost is $4,313 while market value drops to $5,900 in panic sale

cottenio
1pts0
blog.cotten.io 6y ago

How to Eat Gas in Ethereum – Consuming 99.9% of the Gas Limit

cottenio
2pts0
blog.cotten.io 6y ago

Greedy ‘Connect 4’ for Fun and Profit – Kaggle's New Simulations Contest

cottenio
2pts0
blog.cotten.io 6y ago

“Here's my private key, try stealing my Ether!” – blockd's marketing stunt

cottenio
1pts1
blog.cotten.io 6y ago

Have Google and Bing Gotten Better at Answering Questions? Zedah's Test Queries

cottenio
1pts0
blog.cotten.io 6y ago

Delaying the Inevitable: Muir Glacier and the Ethereum Difficulty Bomb

cottenio
90pts70
blog.cotten.io 7y ago

Deploying the Libra Core Blockchain on Amazon EC2

cottenio
1pts0
blog.cotten.io 7y ago

DeFi: Deposit Account Tutorial in Solidity

cottenio
1pts0
blog.cotten.io 7y ago

Russia's Bitcoin Hacking Funds: How the Mueller Investigation Ties It Together

cottenio
7pts0
blog.cotten.io 7y ago

Decentralizing a Certificate of Deposit

cottenio
3pts0
blog.cotten.io 7y ago

Wash Trading: How Crypto Exchanges Are Faking 67% of Trade Volume

cottenio
2pts1
blog.cotten.io 7y ago

An Overview of Bitcoin Transaction Types and Methods of Laundering

cottenio
2pts0
blog.cotten.io 7y ago

Congress on Market Manipulation and Crypto Regulation

cottenio
2pts0
blog.cotten.io 7y ago

Bitcoin Isn't Dying, but Another Big Crash Is Coming

cottenio
3pts0
blog.cotten.io 7y ago

Another Bitcoin Price Crash Imminent?

cottenio
3pts0
blog.cotten.io 7y ago

A Very Sleepy MySQL Attack

cottenio
70pts43
blog.cotten.io 7y ago

Hacking Node.js “May I Have This Repo?” – The Danger of Upstream Dependencies

cottenio
2pts0
blog.cotten.io 7y ago

Bitcoin Crashes Below Energy Cost

cottenio
4pts0
blog.cotten.io 7y ago

Bitcoin Cash Fork – SV is burning $1,500 an hour trying to keep up

cottenio
3pts0
blog.cotten.io 7y ago

Gmail Vulnerability Allows Anonymous Emails

cottenio
2pts0
blog.cotten.io 7y ago

Ghost Emails: Hacking Gmail's UX to Hide the Sender

cottenio
7pts1
blog.cotten.io 7y ago

Hacking Gmail’s UX with 'From' Fields – Another Phishing Vector

cottenio
114pts34

This is one of the first articles I’ve read with a decent attack on reverse engineering the black boxes of neural networks. I particularly appreciate the use of corrupted prompts for isolating behaviors.

[dead] 3 years ago

People try to sell Bitcoin on the idea that’s it’s deflationary when it’s not.

Hi, fellow MUD/MMO person here with an additional background in blockchain.

Can you walk us through where you think a language like Verse really shines with transactionality versus the current server authoritative models we see implemented in [language here] using [framework/pattern] here (like C++ and ECS)?

I've done my fair share of FP (got into Haskell years ago) so I see value here, but I'm not sure I'm grokking your level of excitement and would like to understand better.

You know, your comment made me rethink a few things.

I don't know if they have the wrong end of the stick. I'm afraid they might, because based on their presentations so far the Metaverse bit seems more tacked on than intrinsic. However, these are credentialed people well known in the field - it's hard to tell how much is exuberance re: Metaverse usage.

Regarding my comment on AI, I think it's relevant. It's not that AI will "solve all our problems", but that AI-aided design and code implementation will make learning a language like this obsolete. Transpilation will be seamless and backgroundy. So now there's a cost/benefit factor to learning a new language that was used to write a distributed execution layer for the Metaverse in a transaction-first manner, versus using tools that just "do it for us" and interact with the "product" created with Verse.

As far as Fortnite having a dominant market position once they do stuff with it, I'm not sure of that. I mean, StateScript being awesome doesn't make a dominant market position for it because of its use in Overwatch. I recognize the fundamental difference because the latter is closed and proprietary, sure, but I'm just not sure about the level of separation between Language and Product here when they're talking about the Metaverse. I look forward to learning more.

There comes a point in any massively scaling networking project, and here I speak with some experience, when you realize that your goal, while admirable, has no bearing on the lessons learned over the last few decades of MMO development.

I fear this is a handwave.

What I mean by that is that its addressing the wrong problem for the Metaverse. Being able to implement an ECS model, for instance, where different platforms have common system requirements but because they're both built on Verse they can easily glom/reduce/map components and functions so entities in one ruleset can interact in the other... that's neat, but not a technology problem.

It's a combinatoric problem. And a game design problem.

By the time Verse is built up enough and has enough market penetration to try to take on this sort of role as a bedrock foundation layer for the Metaverse I think we're going to see two major shifts that make it obsolete:

1. The rise of AI-aided design and programming (think ChatGPT on steroids) that makes it pointless to worry about having One Great Solution when the AIs can just interop/translate and all the platforms (even competing corporate interests) can be "Metaversy" with their entities/players.

2. Either the combinatoric problem gets solved or it doesn't. Game designers have strong opinions on NFTs, for instance. The majority recognize them as incapable of solving the item portability problem (or as Raph Koster says, is it even desired?). Either novel ways emerge to do so and it's solvable, or they don't. I suspect either way the heavy lifting is not a programming technology problem, but a contractual/API one.

I think mathematicians are going to love Verse.

I'm concerned about hoping "millions" of Metaverse devs will use Verse when, right now, the biggest problems with Metaverse are more about frameworks/netcode than the underlying language.

An open framework for handling interpolation, client & server space simulation (w/ physics), forecasting/prediction for events, and handling at least 30 ticks/s for a connection target with <150ms latency, <10% packet loss, while being able to handle thousands of connections + tens of thousands of entities PER instance (and also seamlessly mirror data across instances to enable large maps without zoning): that's a huge need for large-scale MMORPG-style Metaverse design.

I'm not at all certain we need a new language to do that.

I know it's hard to compare the usage percentage of various programming paradigms because many languages are multi-paradigm, but FP represents a much smaller piece of the pie (especially in games/networking) and, honestly, we have several generations of existing engineers who don't do FP.

Still, it's nice to see that Sweeney hasn't given up on making FP more useful to the mainstream! =)

I just want to mention that the C++ code running UO was incredibly fast at what it did, and it even wrapped a custom scripting language called Wombat that ran all the gameplay logic.

Pretty sure Jason Spangler, genius, made a JIT compiler in LLVM for Wombat just to see how much code we could execute in each 250ms tick.

During one of my live events I got 500 people on-screen (in what, an 800x600 pixel screen?) thanks to how efficient the networking, gameplay, and client rendering code had become.

Well. Then the telestorming began because I forgot to disable it…

Not really “changed hands.”

Stages:

1. EA with original Origin devs 2. EA post-Origin 3. EA, integrated into Online group (with Westwood) 4. EA Mythic (UO & DAOC) 5. Broadsword (owned by the former GM of EA Mythic under a licensing deal)

I think that’s fairly accurate. Older devs correct me if I’m wrong.

No, stacks are stacks. They’re an object id with a quantity counter. Each stack, however, was capable of holding its own separate script and objvars; there were event triggers to handle special cases like “onStackAdd” and such.

I just want to note that I only started paying attention to cryptography after I left UO and got into Bitcoin, which sounds like an NFT-grifting MMO supervillain origin story - I know - but I sure did learn a lot about merkle trees and solving interesting social problems.

As a huge fan and experienced implementer of merkle trees in my modern work I really wish I had known what they were at the time :)

Merkle trees don’t solve the forgeability issue, just the unbroken chain of what you currently have. So, if you have control over the server you can just create a set of events with your “+5 billion gold” event injected in it, recalculate the tree and root and voila: forgery.

PoW doesn’t prevent this, it just adds computational time provably spent between the events so that if you DID try to inject a false record a year ago you’d have to spend that same amount of time calculating the resulting merkle tree.

Merkle trees all the way down!

Oh, and a good aside: thanks to player exploits the nodes themselves weren’t necessarily trustworthy (such as duping exploits across shards, not just areaservs).

Like I said, not saying we “needed blockchain”, but when AWS released QLDB I was like “ohhhh, that would’ve been useful” since, you know, forging log files is a thing.

Consider the sheer scale: people sell 200 million UO gold for $10. Can you imagine every gold piece having a unique UUID? Even if you didn’t use 256 bit hashes, even at 64 bits you’d be talking about 1.6gb per $10 worth of UO gold.

UXTO would’ve been a neat technology to have to experiment with at least.

Memory was at enough of a premium that even in the tagging system we made in the article it was just for the rarest items.

Yeah, my point was that an internal PoW ledger (not decentralized but still technically a blockchain) would’ve been useful because: A) stack tracking per stackable type is trivial with UXTO, and B) adding a few seconds of PoW makes the resulting chain so hard to forge for crime-of-opportunity style attacks (preventing internal employees from making untraceable gold) that it could’ve prevented a few firings/calls to the authorities during my time. Oh, and C) it might’ve resolved the duping issues with cross-server character transfer exploits (a different beast than areaservs), and D) heh, maybe conned an engineer into making a block explorer dashboard so we could see the global state of currency/stackable amounts

Like you said: most of these except B) could’ve been done with traditional techniques and relational databases, but I maintain A) might’ve been easier than the message passing code required to synchronize and emulate it.

One suggestion is to allow further segregation of permissions for functions like SLEEP, BENCHMARK, etc. A front-end request has no need for it.

It’s the exposition of things that “act” on lax query permission sets that “appear” read-only (but in fact have interrupt style executions) that leads to trivialization of abuse.

Yes, thank you - since the most "secure" method of generating UI/UX while still depending on a database at least requires SELECT permission, even if INSERT/DROP/DELETE are enabled, having SLEEP() not require special permissions makes it trivial to use in vulnerability enumeration.

These are valid points, but don't necessarily reflect the reality of a production web environment whose user ONLY has SELECT access to read caches and view data from the database.

Being able to enumerate vulnerable spots or exfiltrate data can arguably be more devastating than performing a DROP that's noticed immediately and the LKG table from backup is imported to fix it.