Advanced
Sort:
In reply to @vitalik.eth
Paul Miller@paulm
3/11/2024

Foucault wrote a whole book on that, “Discipline and punish”. Mentioning schools, jobs, etc.

In reply to @anderselowsson
Paul Miller@paulm
2/8/2024

To minimize diffs for audit purposes.

dev
In reply to @awkweb
Paul Miller@paulm
2/7/2024

Wowow

dev
In reply to @lefteris.eth
Paul Miller@paulm
2/4/2024

I believe it is not just miscommunication. It’s malevolence. Hayden in the blog post never mentioned that what Micah did was right. E.g that they would still send copyright claim against these kinds of forks. “Uncensored uniswap” phrase is descriptive and discoverable and should not be banned.

dev
In reply to @haydenzadams
Paul Miller@paulm
2/4/2024

Serious question: What are jurisdictions of uni trademark? Does it affect Ukraine? What about EU? Oman? If it doesn’t affect some countries, does it mean one can use it for whatever and notices have no legal basis?

dev
In reply to @haydenzadams
Paul Miller@paulm
2/4/2024

My main emphasis is that if it hadn’t become viral on X, there would have been no “fix” from uniswap labs. Which is similar to how big corps are working. Some adjustments to legal process are warranted to prevent this.

dev
In reply to @cassie
Paul Miller@paulm
2/4/2024

Not suing yet, threatening hosters for “copyright violation”. Which is nonsense. Now that the matter got public they’re trying to fix it, of course. https://x.com/micahzoltu/status/1753416705983074668

dev
Paul Miller@paulm
1/18/2024

Ethereum ABI parsers are vulnerable to DoS. It’s also possible to inject information in transactions, hidden from parsers. This allows tracking users across different wallets and even stealing private data. Details in a new article. https://github.com/paulmillr/micro-eth-signer/discussions/20

dev
In reply to @grin
Paul Miller@paulm
12/20/2023

FC dms utilizing 3dh are superior, but they are not oss yet.

Paul Miller@paulm
12/20/2023

We’ve finalized and audited very simple end-to-end encrypted messaging scheme for nostr. Feel free to use it in your protocol. https://github.com/paulmillr/nip44 Wen OSS in farcaster dms @dwr.eth ?

In reply to @paulm
Paul Miller@paulm
10/10/2023

40B$ worth of eth is currently staked in Lido, which means a rug could severely damage eth.

Paul Miller@paulm
10/10/2023

Post on Lido risks from EF. tl;dr: “By having the ability to arbitrarily mint stETH, spend the treasury, overwrite the withdrawal contract, and cycle the node operators, the DAO could effectively destroy the Lido protocol in a “rug-style” manner” https://notes.ethereum.org/@mikeneuder/magnitude-and-direction

In reply to @paulm
Paul Miller@paulm
10/9/2023

5. Ideally: Stop all upgrades, freeze contracts and remove owners. When an upgrade is necessary, switch to a new version akin to Uniswap

In reply to @paulm
Paul Miller@paulm
10/9/2023

3. Document all moving parts, audit trail and supply chain risks. Who owns which contract, who can change it, which entities can affect change 4. Limit upgrades to 1 per year. Outsiders need to have at least 3 months to check what’s in the upgrade.

In reply to @paulm
Paul Miller@paulm
10/9/2023

5. Upgrades are regular. Any smart contract upgrade can bring critical bugs. That includes something as simple as changing Solidity version. What Lido needs to do: 1. Limit themselves to 22% of total eth stake 2. Re-distribute voting power transparently to entities who actually operate lido nodes

In reply to @paulm
Paul Miller@paulm
10/9/2023

3. Some other contracts are changed using DAO voting. However, they are being passed with only 5% of votes, no one bothers to vote https://vote.lido.fi 4. DAO voting is done using LDO token. We don’t know who holds it. Even if 90% voted instead of 5%, the 90% could have easily been just one entity, like Lido itself

Paul Miller@paulm
10/9/2023

Lido owns almost 1/3 of all staked ETH, around 40B$. Owning more will allow them to control ETH consensus. Lido is bad: 1. They have 100 contracts. Auditing is very complicated https://docs.lido.fi/deployed-contracts/ 2. Some of them are owned by EOA and multisig: they could be trivially upgraded by a person or a few

In reply to @dwr.eth
Paul Miller@paulm
9/29/2023

Not sure I understood. What is the protocol? A smart contract? But it’s permission-less? The platform would be paid-only?

In reply to @dwr.eth
Paul Miller@paulm
9/29/2023

How would you capture value?

In reply to @dwr.eth
Paul Miller@paulm
9/27/2023

Still vendor lock-in. Fine for spammy sites, but for ios it’s the same icloud hide my email, without OS integration.

Paul Miller@paulm
9/19/2023

Signal will switch to post-quantum algorithms in the near future. ETH is not protected against this threat right now. Neither are rollups. Staking is good, with eip2333. Would be great to restart the discussion. https://signal.org/blog/pqxdh/

Paul Miller@paulm
9/7/2023

Last month, we've collaborated with Starknet and released a new addition to "scure" family of audited libraries. The audit was done by Kudelski security. The package includes stark curve and poseidon / pedersen hashes. Check it out: https://github.com/paulmillr/scure-starknet

Paul Miller@paulm
8/23/2023

The Tornado cash founders have been charged with money laundering for operating a privacy-preserving mixer. https://www.justice.gov/usao-sdny/pr/tornado-cash-founders-charged-money-laundering-and-sanctions-violations

In reply to @ccarella.eth
Paul Miller@paulm
8/23/2023

Tried it for some time and can’t support the opinion. A lot of uncomfortable synthetics (plastics) that feels like crap. Winter jackets are not warm even in mild temp.