xM

63 posts

xM

xM

@marcbcs

Mercenary management consultant

Katılım Temmuz 2022
135 Takip Edilen3 Takipçiler
xM retweetledi
xM retweetledi
Hasu⚡️🤖
Hasu⚡️🤖@hasufl·
Here are my highlights from Lido's second quarterly tokenholder update, which happened yesterday. 🧵
English
15
17
98
26.3K
xM retweetledi
Christian Catalini
Christian Catalini@ccatalini·
20/ It's the same fundamental economic truth we identified at MIT almost a decade ago: the only thing that truly separates crypto from the systems it aims to replace is that it's permissionless. Full stop.
Christian Catalini tweet media
English
9
49
349
65.1K
xM
xM@marcbcs·
@ameensol Have a weighted democracy where how much you paid last year in taxes determines your voting power. If taxes are too high, people that contribute the most have more power and can lower them. If taxes are too low, people that barely pay taxes can vote to increase them.
English
0
0
2
10
Ameen Soleimani
Ameen Soleimani@ameensol·
gm what is the general solution to 51% attacks against democracies? aka when the voters just decide to vote themselves the treasury, and basically win forever
Ameen Soleimani tweet media
English
54
7
111
21.1K
xM
xM@marcbcs·
@LidoFinance Hey marcbcs here, I haven’t received the invite yet
English
0
0
0
3
xM
xM@marcbcs·
@LidoFinance I haven’t received the speaker invite yet
English
0
0
0
2
xM
xM@marcbcs·
@pacmoon_ is eating other memecoins alive
GIF
English
0
0
0
3
xM retweetledi
Stephan Livera
Stephan Livera@stephanlivera·
"It's a great business to be in, Central Banking, where you print money and people believe it" - Adrian Orr, Governor Reserve Bank of NZ He says this while the state imposes legal tender laws, and myriad banking and AML laws. "Belief"? or coercion?
English
34
195
621
52.5K
xM
xM@marcbcs·
@Lomashuk How do you like just the first paragraph of the tweet?
English
0
0
0
3
xM
xM@marcbcs·
2)
Safety@Safety

We can confirm that the account @SECGov was compromised and we have completed a preliminary investigation. Based on our investigation, the compromise was not due to any breach of X’s systems, but rather due to an unidentified individual obtaining control over a phone number associated with the @SECGov account through a third party. We can also confirm that the account did not have two-factor authentication enabled at the time the account was compromised. We encourage all users to enable this extra layer of security. More information and tips on how to keep your account secure can be found in our Help Center: help.x.com/en/safety-and-…

QST
0
0
0
24
xM retweetledi
Lefteris Karapetsas
Lefteris Karapetsas@LefterisJP·
✍️Now that the worse is behind us but while everyone's attention is still on the mattter I am writing a bit of a longer post on this industry's architecture and security practises. @Ledger messed up badly. Having practically no opsec, no proper credential management, and not revoking former employees access and credentials. Amateur hour, and extremely embarassing for a company their size whose entire focus is supposed to be on security. Really bad. But surprisingly they are the least to blame for this failure. This industry has a serious problem. It preaches one thing and does another. Preaches decentralization, and nobody runs their own node. Preaches user being in control and don't trust verify, but everyone uses SaaS and centralized frontends. What you people call "dapps" is a joke. A farce. Centralized SaaS frontends that can monitor you or worse. Apps that are hosted by someone else and can change at any point under your feet. That's not what a decentralized app is. It's a travesty to even use this terms for the apps this industry has available right now. 🐦 I have devoted the last 5 years of my career trying to bring local apps and local-first software back into play. I am a strong believer in self-sovereignty, data ownership and decentralization and this is embodied in @rotkiapp. I want us all to start becoming more aware of what we use and how we interact with web3, otherwirse before you know it web3 will vanish, and this dream of self-sovereignty and the user being back in control will go away with it. To the users: Question every single tool you use. See what it does with your data, where it stores it, how it manages its dependencies, what its security practises are etc. Check the track record of its team. Do your due dilligence. If the tool is anywhere close to your funds, addresses or any private info be extra dilligent. You may not be able to do your due dilligence. Find someone who can! This is not something to just brush off in the name of convenience. Today you see what happens when you do so. To the devs: - Whatever you do, pin all your dependencies. Never ever just yolo pull the latest dependency. Freeze all of them all the way up to the smallest transient dependencies. If you are in JS and are pulling from a CDN then pin the hash too in case the CDN itself is compromised. Otherwise just serve/bundle your dependencies. Today's tragedy was preventable by this simple thing. - Build local-first. Respect your users, give them choices on how to consume your app. This is web3 damn it. Let them save their data locally, let them use their own node, let them self-host the app, let them inspect the code, be opensource! - Avoid centralized points of failure. Using a common library's latest version unpinned from a CDN is one such point of failure. But there is a lot more. Using only infura and/or alchemy. Using centralized indexers (especially if their number == 1). Hosting your app in a single server without any self-hosting capabilities. And so many more ways to fail ... This can probaly get a lot longer but I will stop here. Again I want to re-iterate. Ledger is definitely to blame here but the lion's share of the blame is on our industry and its software engineering practises. Let's stop regressing back to web2 and build the true vision of web3. A world where the user is self-sovereign, owns their data and is free. Freedom is what all this is about.
Lefteris Karapetsas tweet mediaLefteris Karapetsas tweet mediaLefteris Karapetsas tweet mediaLefteris Karapetsas tweet media
English
57
194
777
194.5K
xM retweetledi
Morgan Housel
Morgan Housel@morganhousel·
The Austrian 100-year bond issued in 2020 is now down 75%. Basically a meme stock.
English
58
144
1.4K
578.7K
xM retweetledi
찌 G 跻 じ MBA, CFA, FRM, CFP, NGMI, HFSP, HENTAI 🛡️
"rich people can easily fall into the trap of BUYING themselves more JOBS" property portfolio? congrats you're a real estate agent now big mansion, garage of cars? congrats you're facilities maintenance now outsource all that? congrats, you're the human resources manager now
찌 G 跻 じ MBA, CFA, FRM, CFP, NGMI, HFSP, HENTAI 🛡️ tweet media
찌 G 跻 じ MBA, CFA, FRM, CFP, NGMI, HFSP, HENTAI 🛡️@DegenSpartan

i will say tho, the point of money is NOT to hoard it and die with a lot of it spend it, be happy consider using money to blast away problems, instead of buying "stuff" that comes with extra work and problems, esp if it requires constant mental overheads dont let stuff own you

English
37
61
949
146.4K
xM retweetledi
Hasu⚡️🤖
Hasu⚡️🤖@hasufl·
PSA If you signed up to Twitter Blue, it automatically added your phone # to your Twitter profile. This phone # can be used to reset your account, whether you use it for 2FA or not. Every Blue account is sim swappable. Go to settings/profile to remove your phone # right now
FreddieRaynolds@FreddieRaynolds

Sounds like @VitalikButerin didn’t use phone number as 2FA, just having an associated number enough to lose @X account if sim-swapped

English
21
67
204
69.7K