overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ)
3K posts

overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ)
@AnalyserOver
Crypto enthusiast focused on Ethereum and @INDEXcoop, https://t.co/P5RySHewKz
DeFi UTC ๊ฐ์
์ผ Aฤustos 2020
1.2K ํ๋ก์1.5K ํ๋ก์
๊ณ ์ ๋ ํธ์
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

@SetProtocol Twitter has been hacked. Do not claim the $SET airdrop, you will get drained.
English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

๐จ Security Alert ๐จ
@SetProtocol X account is compromised and is started to promote $SET token airdrop
โ ๏ธ DO NOT click on any links until further clarifications from their team โ ๏ธ

English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

โ๏ธNow that the worse is behind us but while everyone's attention is still on the mattter I am writing a bit of a longer post on this industry's architecture and security practises.
@Ledger messed up badly. Having practically no opsec, no proper credential management, and not revoking former employees access and credentials. Amateur hour, and extremely embarassing for a company their size whose entire focus is supposed to be on security. Really bad.
But surprisingly they are the least to blame for this failure.
This industry has a serious problem. It preaches one thing and does another. Preaches decentralization, and nobody runs their own node. Preaches user being in control and don't trust verify, but everyone uses SaaS and centralized frontends.
What you people call "dapps" is a joke. A farce. Centralized SaaS frontends that can monitor you or worse. Apps that are hosted by someone else and can change at any point under your feet. That's not what a decentralized app is. It's a travesty to even use this terms for the apps this industry has available right now.
๐ฆ I have devoted the last 5 years of my career trying to bring local apps and local-first software back into play. I am a strong believer in self-sovereignty, data ownership and decentralization and this is embodied in @rotkiapp.
I want us all to start becoming more aware of what we use and how we interact with web3, otherwirse before you know it web3 will vanish, and this dream of self-sovereignty and the user being back in control will go away with it.
To the users: Question every single tool you use. See what it does with your data, where it stores it, how it manages its dependencies, what its security practises are etc. Check the track record of its team. Do your due dilligence. If the tool is anywhere close to your funds, addresses or any private info be extra dilligent. You may not be able to do your due dilligence. Find someone who can! This is not something to just brush off in the name of convenience. Today you see what happens when you do so.
To the devs:
- Whatever you do, pin all your dependencies. Never ever just yolo pull the latest dependency. Freeze all of them all the way up to the smallest transient dependencies. If you are in JS and are pulling from a CDN then pin the hash too in case the CDN itself is compromised. Otherwise just serve/bundle your dependencies. Today's tragedy was preventable by this simple thing.
- Build local-first. Respect your users, give them choices on how to consume your app. This is web3 damn it. Let them save their data locally, let them use their own node, let them self-host the app, let them inspect the code, be opensource!
- Avoid centralized points of failure. Using a common library's latest version unpinned from a CDN is one such point of failure. But there is a lot more. Using only infura and/or alchemy. Using centralized indexers (especially if their number == 1). Hosting your app in a single server without any self-hosting capabilities. And so many more ways to fail ...
This can probaly get a lot longer but I will stop here. Again I want to re-iterate. Ledger is definitely to blame here but the lion's share of the blame is on our industry and its software engineering practises.
Let's stop regressing back to web2 and build the true vision of web3. A world where the user is self-sovereign, owns their data and is free. Freedom is what all this is about.




English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

Hello everyone
We're starting our search for someone to engage in heated, self-sustaining arguments with me about direction and functionality as the Head of Product at Wildcat
I will pay you to tell me I'm wrong
Application below, more info in thread
jobs.lever.co/wintermute-traโฆ
English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

Our Diversified Staked ETH Index (dsETH) just got more diversified ๐ข
Today, we're excited to announce the addition of @fraxfinance's sfrxETH in dsETH's first rebalance

English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

#AllYouCanEarn looks interesting for GBP interest.
Higher rates than most Defi, but centralised...
Nexo@Nexo
Your wealthโs sweetest dreams are made of this โ up to 15% annually on GBP stablecoin. Start earning now and win yourself a prize of 1,000 in GBP stablecoin by following us and quote retweeting this with the #AllYouCanEarn hashtag. ๐งต link.nexo.com/3i1R
English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

Fuck you @AtomicWallet
Fuck you @gladkos
Fuck you @Changelly_team
Your security posture sucks, you refuse to listen to people, you aggressively silence people, and your products and services facilitate theft on a daily basis and have for years.
web.archive.org/web/2022021015โฆ
English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ

$DPI Rebalance Update
The DeFi Pulse Index (DPI) is a capitalization-weighted index that tracks the performance of some of the largest protocols in the decentralized finance (DeFi) space.
Meet the newest tokens in the DeFi Pulse Index. pic.twitter.com/MiTrf1IoNI
English
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ
overanlyser.eth ๐ฆ๐ (๐ฆ,๐ฆ)๐ช (๐ธ, ๐ฟ) ๋ฆฌํธ์ํจ









