Ron McKown

124 posts

Ron McKown

Ron McKown

@ronmckown

California, USA Katılım Mayıs 2008
132 Takip Edilen961 Takipçiler
Ron McKown
Ron McKown@ronmckown·
@j4hangir @EowynChen @TrustWallet Even if they were using this feature, it's only as good as the security of the signing private key. Perhaps that was compromised as well. Either their key management is weak or they have an insider threat problem.
English
1
0
4
886
ʝㄐ🔆 🇮🇷
ʝㄐ🔆 🇮🇷@j4hangir·
Your statement implies that you lack multisig for binary uploads. Otherwise, regardless of the number of leaked API keys, the binary simply couldn't have been signed to be deployed. You should've implemented an internal multisig process or, ideally, adopted Google's from over six months ago. This clearly shows security-the one thing that you must prioritize over all-is not your first and foremost concern. Honestly, embarrassing; and highly concerning. developer.chrome.com/blog/verified-…
English
3
4
35
5.9K
Eowyn
Eowyn@EowynChen·
I want to share a transparent update on the @TrustWallet Browser Extension v2.68 security incident, and what we know so far ~24 hours of the attack. This is an ongoing investigation, so I’ll focus on confirmed facts and updates, highly likely hypothesis, and what we’re doing to stop loss for users.
English
80
76
397
116.8K
Nostalgia Nerd
Nostalgia Nerd@nostalnerd·
Name a better logo. I'll wait.
Nostalgia Nerd tweet media
English
90
26
580
22.9K
Ross Ulbricht
Ross Ulbricht@RealRossU·
Oops...the first thing I try to do on X and I screw it up! I accidentally deleted my last post about taking over the account: 6.5 years ago my wife created this X account to give me my voice back. All this time, she relayed my messages to you word for word. Starting now, MY fingertips are on the keyboard! Here we are, one week after my release, our prayers finally answered.
Ross Ulbricht tweet mediaRoss Ulbricht tweet media
English
5.8K
5.8K
103.7K
5.4M
Ron McKown
Ron McKown@ronmckown·
👋🏼 Ron here, Head of Security @phantom. First of all, I want to reassure everyone that security is our top priority at Phantom and that there is no vulnerability that puts user funds at risk. The issue @CloakdDev is referring to involves being able to freeze a user’s Phantom app by sending it thousands of tokens. This issue has been never been exploited and is now completely remediated, but at various points this was the case for both fungible and non-fungible tokens. In the case of non-fungible tokens, it was possible to crash the collectibles tab, but not affect the rest of the app, and certainly not affect user private keys or secret recovery phrases. In the case of fungible tokens, it was possible to crash the app, and make it difficult for users to access their wallet without the help of Phantom support. Both these issues were promptly remediated and never exploited. At no point were funds at risk of being compromised. @CloakdDev had been in touch with our security team, and other members of the Phantom team, claiming that it had been possible to wipe private keys and secret recovery phrases from user devices using similar methods. Despite multiple outreaches from our team, he was not able to provide reproducible steps, and we have also not been able to reproduce this despite our best efforts. Based on this, the finding was triaged to score CVSS 3.7, rated Low, and valued at $3,000. @CloakdDev if you can provide reproducible steps to your claims, we are happy to work with you and increase the size of the bounty offered.
English
42
38
376
431.1K
Cloakd ⌛
Cloakd ⌛@CloakdDev·
I've been waiting for over 28 days for a large vulnerability to be fixed in one of the largest apps on SOL At this point, it's becoming a joke - I can't even get a response from their security team at this point in terms of update.
English
118
83
2K
496.6K
Ron McKown
Ron McKown@ronmckown·
@lopp The word "kindly" is always a giveaway.
English
0
0
1
346
Jameson Lopp
Jameson Lopp@lopp·
Social engineering prevention 101: 1. Never trust ANY unsolicited incoming communications be it via email, phone, chat, social media, etc. 2. Any message you receive that conveys FEAR and a sense of URGENCY should be regarded as highly suspicious. 3. No crypto exchange, hardware, or software provider is going to call you out of the blue and ask you to make changes to your security setup. 4. Never install software, especially remote desktop software like AnyDesk or TeamViewer, at the instruction of an unsolicited message. 5. Slow down, take a breath, and reach out to someone you trust to provide a second opinion if you find yourself in a weird situation.
English
36
252
976
64.8K
Ron McKown
Ron McKown@ronmckown·
@lopp Always verify calls to action out of band.
English
0
0
1
309
Petter Solberg
Petter Solberg@Petter_Solberg·
That young man on the left couldn't even imagine turning 50, but here we are...! 😂🎈 Big thanks to everyone for all the birthday wishes, and to my family for the lovely gifts and excellent day so far! 👌🥊
Petter Solberg tweet mediaPetter Solberg tweet media
English
26
52
638
64.1K
Magic Eden 🪄
Magic Eden 🪄@MagicEden·
If Bitcoin hits $70k, Solana hits $170 and ETH hits $2,700 this week, we’re following everyone who replies to this.
English
5.6K
823
7.2K
745K
Ron McKown
Ron McKown@ronmckown·
@mikealfred Beware of people with wrenches, saying something like this makes you an easy target.
English
0
0
2
79
Ron McKown
Ron McKown@ronmckown·
I just received some new toys!
Ron McKown tweet mediaRon McKown tweet mediaRon McKown tweet media
English
4
0
20
3.3K
FreeBSD Frau
FreeBSD Frau@freebsdfrau·
I didn't want to write this, but I felt like I had to. Put this in your .bash_profile and get notifications whenever someone impersonates you, hijacks your credentials, or nefariously attaches to your forwarded ssh-agent to gain access to machines they cannot without your user
FreeBSD Frau tweet media
English
28
170
1.9K
357.9K
Ron McKown
Ron McKown@ronmckown·
@BitcoinMagazine We needed someone like Linus Torvalds. We got Gavin. The rest is history.
English
0
0
0
89
Bitcoin Magazine
Bitcoin Magazine@BitcoinMagazine·
FUN FACT: 13 years ago today, Satoshi Nakamoto announced he "moved on to other things", stepping away from #Bitcoin
Bitcoin Magazine tweet media
English
190
354
2.3K
382.9K
Ron McKown
Ron McKown@ronmckown·
@ndgoHODL It should be required reading in high school.
English
0
0
0
47
Ron McKown
Ron McKown@ronmckown·
@cybersecmeg Since 100% prevention is impossible, detection is paramount.
English
0
0
0
36
meg west
meg west@cybersecmeg·
is it better to detect the breach, or to prevent the breach?
English
225
26
373
124K
Ron McKown
Ron McKown@ronmckown·
Taken in my backyard with a phone
Ron McKown tweet media
English
5
1
12
3K
Ron McKown
Ron McKown@ronmckown·
@lopp @RealRossU Eagle scout, Masters degree and clean record - his punishment is much too severe.
English
0
0
1
98
Jameson Lopp
Jameson Lopp@lopp·
Wishing as happy a 40th birthday as possible, given the circumstances, to @RealRossU. A decade in prison for facilitating free trade is unconscionable.
English
14
56
415
23.7K
mason
mason@masonic_tweets·
I'm telling you - Satoshi talks like he was born, raised and worked in Mountain View, CA.
mason tweet media
English
3
0
7
822
Ron McKown
Ron McKown@ronmckown·
@DaDrunkDragon This did nothing to stop piracy, it only inconvenienced people who actually bought the game.
English
0
0
0
38
80s Kidz
80s Kidz@80s_Kidz·
What's the first game you can think of when see this? Turricain for me.
80s Kidz tweet media
English
542
26
609
195.7K