Tiffany young

1.7K posts

Tiffany young banner
Tiffany young

Tiffany young

@X_8964

普通的安全研究者 | 非常普通的开发者 | 酷爱屏蔽引流蓝标 | Speaker of BlackHat2024

Singapore เข้าร่วม Aralık 2018
382 กำลังติดตาม2K ผู้ติดตาม
ทวีตที่ปักหมุด
Tiffany young
Tiffany young@X_8964·
@HubertX13 @ResolvLabs Hi, I'm also a big vault curator on morpho market, who have listed and invested in RLP market. Can we keep in touch regarding the upcoming effects on the RLP morpho market.
English
1
0
0
33
Hubirb 🐘👀
Hubirb 🐘👀@HubertX13·
After gathering thoughts from various parties at ETHCC, here is my take on the options available to @ResolvLabs regarding their recent $USR hack. For me it’s very clear, there are two paths going forward: 1/ Resolv reduces $RLP value by the loss in collateral pool and uses treasury funds to partially compensate Fluid and Gauntlet for their USR bad debt. In this case, pretty much no end user will loose anything since fluid has repaid already, and anyway both gauntlet and fluid committed to repay right after the hack so it’s their word on the line. After that, new USR token and Resolv is back in business. 2/ Resolv repays fluid’s and gauntlet’s USR bad debts. RLP takes a significant hit, this creates an additional few millions of bad debt increasing even more the whole. Fluid is happy as they can replenish their treasury. Gauntlet is half happy half rekt because of the RLP bad debt generated. Tons of end users get rekt. Resolv then shut down as nobody will ever allocate funds to RLP again. Probably possible to get an exit door at Fluid. As an investor in Resolv, I would very much prefer if the team would decide to go the option 1 route (which is btw the most solid one from a legal standpoint). Hopefully there is a path towards rebuilding a successful Resolv.
English
4
6
21
3.9K
Kamoulox
Kamoulox@Lylo69·
@HubertX13 @ResolvLabs The collateral for RLP is intact and the terms are not clear about an issue related to offchain hack. Resolv risks litigations if they misuse the RLP collateral.
English
2
0
2
77
Tiffany young
Tiffany young@X_8964·
@Elmidou Hi, I'm also a big vault curator on morpho market, who have listed and invested in RLP market. Can we keep in touch regarding the upcoming effects on the RLP morpho market.
English
0
0
0
7
Mid
Mid@Elmidou·
Update: Resolv investor wants Resolv Labs to misappropriate RLP assets for the benefit of Fluid and Gauntlet. The intrigue thickens. x.com/hubertx13/stat…
Hubirb 🐘👀@HubertX13

After gathering thoughts from various parties at ETHCC, here is my take on the options available to @ResolvLabs regarding their recent $USR hack. For me it’s very clear, there are two paths going forward: 1/ Resolv reduces $RLP value by the loss in collateral pool and uses treasury funds to partially compensate Fluid and Gauntlet for their USR bad debt. In this case, pretty much no end user will loose anything since fluid has repaid already, and anyway both gauntlet and fluid committed to repay right after the hack so it’s their word on the line. After that, new USR token and Resolv is back in business. 2/ Resolv repays fluid’s and gauntlet’s USR bad debts. RLP takes a significant hit, this creates an additional few millions of bad debt increasing even more the whole. Fluid is happy as they can replenish their treasury. Gauntlet is half happy half rekt because of the RLP bad debt generated. Tons of end users get rekt. Resolv then shut down as nobody will ever allocate funds to RLP again. Probably possible to get an exit door at Fluid. As an investor in Resolv, I would very much prefer if the team would decide to go the option 1 route (which is btw the most solid one from a legal standpoint). Hopefully there is a path towards rebuilding a successful Resolv.

English
1
0
4
467
Colin Wu
Colin Wu@colinwu·
Gemini 幻觉太严重了,让 Grok 总结了一篇今天 X 上关于被盗事件的综述,然后让 Gemini 做真实性确认,结果。。。
Colin Wu tweet media
中文
39
0
30
20.6K
𝙋𝙖𝙨𝙨𝙡𝙪𝙤
爱玛,我是说怎么有人喷我直接复制别人推文,你们嗅觉也太灵敏了 😅
𝙋𝙖𝙨𝙨𝙡𝙪𝙤 tweet media𝙋𝙖𝙨𝙨𝙡𝙪𝙤 tweet media
中文
19
3
80
162K
Tiffany young รีทวีตแล้ว
砍砍.ᐟ
砍砍.ᐟ@Lakr233·
我们把 Xcode 打包进你的浏览器了 免费账号就能签名安装 无需下载任何软件 光速替代 Cydia Impactor 欢迎来玩~
溴化锂@0x88FFA357

github.com/lbr77/SideImpa… 开源了,感谢砍砍@Lakr233 进行的超绝前端优化 欢迎star/contribution

中文
19
62
538
77.7K
Tiffany young รีทวีตแล้ว
yetone
yetone@yetone·
现在再听「龙虾」、「养虾」这些词儿就有一种听「奥利给」、「真给力」这种过时网络用语一样尴尬羞耻了
中文
96
24
860
102.9K
Tiffany young
Tiffany young@X_8964·
不是,哥们儿,tradingview忘换证书了?还是我的dns给他什么api干了
Tiffany young tweet media
中文
0
0
2
325
Tiffany young
Tiffany young@X_8964·
@lipeng0820 神奇,理论上skip proxy就会回退到普通siri(圆球),我也是港版
中文
1
0
0
26
SimbaLee
SimbaLee@lipeng0820·
@X_8964 明白,我再让他想想可以怎么优化。不过我此刻的Apple intelligent是正常状态,不知道是不是跟港行有关
中文
1
0
0
89
SimbaLee
SimbaLee@lipeng0820·
Antigravity的妙用+1 : 用来魔改梯子的分流规则 哪里不爽改哪里,之前的规则在 iOS 端访问 AppStore 会导致报“无法连接,无法载入页面,请重试。” 且无法绕过公司的内网环境,这下好了,统统搞定👌 轻松打造属于自己的专属分流规则
SimbaLee tweet media
中文
12
6
65
25.4K
Tiffany young
Tiffany young@X_8964·
@lipeng0820 感谢解答,1 ipv6可以可以试试,2 skip proxy会导致apple intelligent用不了,3 如果proxy再走国内dns解析反而可能绕路
中文
1
0
0
84
SimbaLee
SimbaLee@lipeng0820·
你也遇到这个问题了么?让 AI 总结了一下他之前的操作 1. 禁用 IPv6 (杀手锏) 在 Shadowrocket 和 Clash 的配置中,强行关闭 IPv6 开关。 # Shadowrocket 配置ipv6 = falseprefer-ipv6 = false 原因:强制系统回归 IPv4。IPv4 的链路成熟度更高,在大规模分流规则下极其稳定,能解决 90% 的“无法载入页面”问题。 2. 内核级绕过 (skip-proxy / Bypass) 不要仅仅在 [Rule] 区域写 DIRECT。我们直接将 Apple 的基建域名加入 skip-proxy(绕过代理)名单。 # Shadowrocket 配置skip-proxy = 192.168.0.0/16, *.apple.com, *.icloud.com, *.mzstatic.com, *.itunes.apple.com 原因:这能让 Apple 的流量完全不进入 VPN 隧道。对于系统而言,这部分流量就像没开 VPN 一样透明传输,完美避开了苹果的所有隧道检测。 3. DNS 阵列加固 指定苹果域名永远由国内(AliDNS/TencentDNS)进行原生解析。 yaml# Clash Meta 配置nameserver-policy:"apple.com": "223.5.5.5""icloud.com": "119.29.29.29" 原因:确保解析出的 IP 永远是离你最近、最快的苹果 CDN 节点,杜绝因 DNS 污染导致的连接重置。
中文
1
0
3
781
Oasis Feng
Oasis Feng@oasisfeng·
在国行 iPhone 17e 上,把国内运营商的号码写入手机的 eSIM,然后用实体卡槽插 eUICC 卡用来保存和使用其它 eSIM。 不知这个方案靠谱吗?有没有啥坑?
中文
18
3
36
25.3K
外汇交易员
外汇交易员@fxtrader·
#观察 小米红米的命名有点反直觉,“至尊版(Ultra)”的定位居然会比“Max”更低。
外汇交易员 tweet media
中文
7
0
68
39.9K
陈橘墨
陈橘墨@Randark_JMT·
@pypi Dear PyPI security team, during this period of frequent supply chain poisoning incidents, you're still relying solely on the inspector service for code security checks. Does this mean if attackers use .pyd or .so files to deliver payloads, you won't detect it?😅
English
2
0
3
213
luolei
luolei@luoleiorg·
给家里网络拓扑,又做了亿点点小小优化,现在所有落地的 IP ,不再暴露家宽或者服务器 IP,全部又套了一层 Cloudflare WARP。🤡
luolei tweet medialuolei tweet media
中文
36
17
321
135.9K
Resolv Labs
Resolv Labs@ResolvLabs·
Ivan, co-founder of Resolv, has shared an update on the protocol security incident and recovery process. Some of the questions covered: → Why were whitelisted USR users redeemed first? Verified wallets allowed the team to act within 24 hours manually to limit further impact on the broader market. 98% of those redemptions are complete. → What can non-whitelisted pre-exploit USR holders expect? The same 1:1 commitment. The team is finalising the technical solution for redemptions. → Was this an insider incident? The investigation with @Mandiant and @zeroshadow_io is ongoing. No evidence of insider involvement has been found at this stage. → What about post-exploit USR holders, LPs and RLP holders? The remaining steps involve legal, technical, and ecosystem coordination across many counterparties. There is no single obvious solution — only a set of trade-offs. The goal is to find the most balanced outcome. → How long will the full recovery plan take? We are moving as quickly as the process responsibly allows. Watch the full video below:
IvanKo@Iv4n_Ko

Sharing a bit broader highlight of the Resolv security incident

English
26
9
83
27.9K