geodude

26 posts

geodude

geodude

@geooooodude

engineering @code4rena

Katılım Kasım 2023
108 Takip Edilen12 Takipçiler
geodude retweetledi
Paul Graham
Paul Graham@paulg·
The prospect that AI will eventually write most code isn't a sign that you shouldn't learn to program. If anything it's a sign you should. If big waves are coming, it will be better to surf on them than to be hit on the back of the head by them.
English
50
115
1.4K
91.6K
geodude retweetledi
CloudEllie
CloudEllie@CloudEllie1·
It feels emotional tbh, seeing all of these incredible auditors whose careers have been boosted by C4 in this lineup. One of my favorite things about C4 is how we've built -- and are continuing to build -- a platform where talented people get opportunities based on performance.
English
6
4
60
3.4K
geodude retweetledi
Sock
Sock@sockdrawermoney·
Seriously @0xtotem is a gem. It’s been a blast working with him and seeing all the great ideas he has come to light at @code4rena. - AI deduplication - audit docs bot - what’s next?
sorryNotsorry@0xSorryNotSorry

@code4rena Shout out to the team and especially @0xtotem 👏🎉🤘

English
2
3
35
4.5K
geodude retweetledi
Sock
Sock@sockdrawermoney·
This is 100% why @code4rena didn’t drop lows even after competitors created marketing narrative that they only focus on serious issues. Not allowing low-severity issues in a competitive audit is a convenience to the platform, NOT an improvement of security outcomes for customers
StErMi@StErMi

Sunday reflection: contest that won't pay for low/info findings and why I think they shouldn't do that. Context: I'm participating in a contest that follows this rule. Unfortunately, I discovered it only once I had already submitted some of them (totally my fault to not have paid enough attention to that). Now that I know it, I feel like I've wasted my time and I have no more incentives into investing into it. Why do I think that they should allow low/info findings? First, because from low reports, you could discover med/high findings by combining them. Second, because low/info reports are usually a treasure trove for the protocols to understand how to improve the design, architecture and codebase. Yes, probably from a security prospective they are not as valuable as a high, but they for the protocol they could be as valuable if not even more if you think about the long term. Having strong foundations should be your priority, if you build on top of a weak one, you are most likely going to regret it. Finally, I think that the main problem is that when a contest follows this rule, it creates a wrong mental model for the security researcher. You start not looking with accuracy at all the code because you are just rushing to find med/high findings and there's a good probability that some of them will be missed directly or indirectly. I understand that a lot of low/info reports can create much more work for the judge and the client, but I think that's worth reserving a small piece of the overall pot for them, you never know the outcome.

English
2
5
62
15.5K
geodude retweetledi
Code4rena
Code4rena@code4rena·
The @zksync Era audit was historic, and helped turn some of the best Wardens into legends 🐐 We’re taking a look back on the Top 10 of this audit, starting with @xuwinniexu! 🥇 Rank: #1 (#3 All-Time) High-risk findings: 5 (4 Solo) Medium-risk findings: 2 (1 Solo)
Code4rena tweet media
English
4
13
103
12.3K
geodude retweetledi
Code4rena
Code4rena@code4rena·
For our latest Warden Spotlight, we sat down with the now legendary @xuwinniexu to learn more about how they prepared for the @zksync audit, and what advice they have for the up and coming Wardens out there 🗣️ Check out the full interview here: code4rena.co/warden-spotlig…
Code4rena tweet media
English
1
14
93
19.2K
geodude retweetledi
Code4rena
Code4rena@code4rena·
Awards have been announced for the $1.1m USDC @zksync Era audit 🎉 🎉 Top 5: 🥇 xuwinnie - $502,041.99 USDC 🥈 ChainLight - $157,696.85 USDC 🥉 Audittens - $140,480.81 USDC 🏅 minhtrng - $38,573.19 USDC 🏅 erebus - $25,342.88 USDC Read more at: code4rena.com/audits/2023-10…
English
23
35
381
226.1K
chrisdior
chrisdior@chrisdior777·
Seems like there aren't many bug bounty platforms specifically for Web3. The ones I know and are legit: Immunefi - total paid $85,000,000+ Hackenproof - total paid $7,358,983 Hats Finance - total paid $400,000+ Any other significant related platforms that I might have missed?
English
14
5
90
8.4K
@bytes032.xyz
@bytes032.xyz@bytes032·
the only goal you need for the next year, or the year after, is to show up daily. everything else is bs
English
7
30
222
11.3K
peakbolt
peakbolt@peak_bolt·
With the year ending, here's my C4 stats for 2023. Thanks @code4rena for the opportunity! It has been a rewarding experience while securing the web3 ecosystem. I am ready to achieve more for web3 security in 2024! #Code4renaWrapped
peakbolt tweet media
English
10
2
68
6.2K
geodude retweetledi
Sock
Sock@sockdrawermoney·
I don’t normally make personal asks of the @code4rena community, but I have a big one to make. I’ve really pushed the C4 team so hard this year and especially this quarter. It’s been a wild last couple months. There’s so much stuff happening behind the scenes to get ready for an amazing 2024 and it’s been an enormous amount of effort and some of it has required an exhausting and thankless slog by C4 staff. Normally on teams I’ve led, I’ve invested time and effort at end of each year to make sure everyone has a clear sense of how valuable they are and how much their work is appreciated. But due to a massive list of enormous projects we intended to complete by end of year, I wasn’t able to do that before the holidays. And, in fact, I pushed people on the team much harder than I wanted to. I am not above asking for help and I strongly believe the sentiment expressed by a paraphrase of Parker Palmer: “Community means trusting someone else will be there.” So I am indeed asking for your help. The Code4rena staff is enormously dedicated. They truly are passionate about improving security outcomes for sponsors, they really are rooting for the wins of each warden, they obsess over the security, scalability, and UX of the platform, they agonize over technical debt, they worry about making sure everyone who contributes to C4 feels appreciated and valued and treated fairly, and they are constantly driven to make things better. And they do it without any fanfare. I absolutely know the community appreciates their work and the results of their work much as I do, but them getting to hearing from you all would be incredibly meaningful. So: if you’ve benefited from Code4rena this year, I w community, but I have a big one s.fore 2023 runs out and drop a note in the C4 discord as-fives channel. I’d ask the same for appreciation of the amazing sponsors and wardens and lookouts and scouts and judges and bot racers. Doing this will actually be the best gift we can all give each other, in getting to experience the joy of celebrating what this community means to each of us spread throughout the world. Thank you all deeply and profoundly for the privilege of serving this community. I’m exhausted beyond belief, but with all my heart, I’m looking forward to everything we’re going to do together in 2024. Here’s to everyone who makes Code4rena what it is—starting with you.
English
5
11
138
10.3K
@bytes032.xyz
@bytes032.xyz@bytes032·
"Remember the name" > first team blue in c4 more about it soon stay tuned
@bytes032.xyz tweet media
English
17
7
163
14.3K
geodude retweetledi
Code4rena
Code4rena@code4rena·
What makes Code4rena Blue a better alternative to traditional bug bounties? 👇🧵
English
2
4
40
7K
geodude retweetledi
@bytes032.xyz
@bytes032.xyz@bytes032·
C4 just released: - Code4rena Blue - Competetive bounties - Blue teams - Team captains Happy to announce Renascence Labs is the first blue team in C4. More about Renascence soon. 📈
@bytes032.xyz tweet media
English
3
10
109
7.3K
geodude retweetledi
HollaDieWaldfee
HollaDieWaldfee@HollaWaldfee100·
In the bull market we will see a lot more auditors teaming up. As contest pots increase and maybe audit scopes and complexity as well, teams will be the more efficient way to earn money from audit contests.
English
8
3
49
5.3K
geodude
geodude@geooooodude·
🧢
ART
0
0
1
10