HN user

usmannk

2,553 karma

hn@usmannkhan.com

Posts6
Comments273
View on HN

dont you find all the string parsing and manipulation to be quite painful in Swift? I tried to do AoC in Swift before and that put me off a lot. I liked doing little functional one liners but a week from now the parsing burden will be too high.

1. This is really hard to enumerate. I basically am always doing recon and don't do it 1 target at a time either. I'd been looking at Sei's V2 upgrade code on and off for months, and made my report when they merged the v2 branch to master (this action put the code in-scope for a bounty). I'd found a handful of other critical bugs on the way but they were fixed eventually either in the course of normal development or audits. I definitely spent upwards of 40 very focused hrs in total investigating this codebase along with its dependencies Cosmos/Tendermint. Probably much more time less focused. Cosmos&TM are quite big. But those dependencies are used in many other projects too, so it can't be purely accounted towards time on Sei.

2. I am a very experienced security researcher/pentester/whatever we want to call it, specifically in the blockchain niche. I'm OK at the other stuff (reversing, cryptography, web, mobile, etc). Networking probably alright? I'm comfortable saying I have a good mind for security and a wide knowledge of the basics in many fields, then a very deep knowledge of a select few areas.

3. Idk, a lot! Upwards of 20 for sure.

The answer to this question is out there, but the reports are not published yet.

I caution readers to not make rash judgements on their skill like this though. These bugs are really hard to find, and it was a minor miracle that I noticed these ones at all. I actually had a whole list of critical bugs in this codebase ready to report before the V2 upgrade was merged to master (which would put it in scope for a bounty). However the auditors managed to find every single bug on my list. I only noticed the ones that eventually made it here later, by a stroke of luck, and after I had already spent a ton of time looking at this codebase without noticing them.

Typically networking. I spent some time working at a reputable firm in this space as well.

One way to do this is to show some chops on the competition sites and then move to one of the organized freelance firms like Spearbit or yAudit. In doing all of these things you'll inevitably meet more people, build a specialty, get some reputation, etc.

Projects are free to change their terms and the page you link has been updated since I submitted my reports. The maximum was lowered to $1M and payment currency changed from USDC to SEI.

Wire fraud, at minimum. This would constitute direct theft. Very similar cases have been tried and convicted several times now.

Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...

It was advertised in advance, but the real gamble is on if they'll pay. If you go to my other blogpost linked in OP, you can see a case where I was owed 500k and paid 60k.

You're right though that it's a lot of risk. It's not something that most of the leaderboard works full time on, though some of us do. The immunefi homepage has a list of all the bounties on offer.

Technologists describe their systems as having “uptime” and measure it in “nines”, such as “We have five nines of uptime”, which means that a system has 99.999% uptime or, equivalently, about five minutes of downtime per year. Five nines is admirable in many circumstances and would be considered _disastrously_ below expectations for e.g. Google Search.

This seems wrong? 5 9s is probably a reasonable benchmark or even unattained goal for Google Search, right?

I have on several occasions seen firetrucks and police cars nearly kill bikers in this bike lane. The vehicles abruptly turn _into_ the center bike lane without warning, and use it instead of the car lane. Bikers then literally fall over trying to get out of the way in time.

For some reason the majority of the businesses on valencia have put up the sfsbcoalition posters against the bike lane. I still don't understand it though, it doesn't seem like many or even any parking spots were removed from valencia. Do they mean people were parking in the old side bike lanes?

I used to work on cloud infra at an org that spent many millions on GCP (I'm certain ~everyone reading this comment would recognize it by name) and was working on adding more zeros to that number. We spent years working on this and still ended up switching to AWS in the end, largely because of support but also GCP's anti-customer business practices in general. We had weekly meetings with our account reps in person at our office but even they weren't able to get things done internally. No fault of their own though!