RedZeroRay (🎭,🍫) retweetledi

I wasn't going to comment on the @THORChain situation, but given that I think TC is cool, and want the best for it, and no one benefits from hacks, there's a couple of things I wanted to voice an opinion on:
1) @jpthor is wrong to suggest that closed source TSS can help because great decompilation is trivial with better language models, so having a closed source TSS lib would not benefit the network by protecting the TSS lib from the validator set. Neither he nor @pluto_hbr are exactly wrong for considering this, but my understanding of next gen (and to some degree current gen) language models is that they render this "protection from validators" fairly ineffective since anyone with the binary and a great LLM could get an understanding.
2) Like Pluto, I think that the correct response is to go with the up to date version of tss-lib from binance instead of the more obscure DKLS lib from @silencelabs_sl . But it does occur to me that the team knows most about the hack and that the issues in gg20 could still be present in the latest TSS-lib.
3 (not security related))
Unlike a lot of commentators here I think Thor chain is great infrastructure and don't see it getting attacked as a form of karmic justice or whatever. This attack is like any other and demands we tighten up. The AI+decompilation threat seemed especially pressing, so in the end I decided to speak up.
English























