
yourQuantGuy
1.9K posts

yourQuantGuy
@yourQuantGuy
hedge fund → fintech → crypto (defi farmer → perp dex grinder) tg社群: https://t.co/GCSeWltJX3






To all systematic traders, market makers, and integrators: We are constantly shipping improvements to our APIs to improve your quality of life. Please join our Telegram announcements channel for the latest information. Link in the replies below!

360安全龙虾一点都不安全 😂 360安全龙虾的安装包里直接带着SSL私钥,相当于把整个网站的主密码公开,证书居然还有效到2027年。360已经回应并表示已经把该证书吊销。 我觉得其实这都是小事,国内排队安装龙虾这件事本身才可怕。 他们真的知道他们排队装了个啥吗? 国内和银行有关的事都搞得特别麻烦,因为“防止诈骗”等原因,但真不怕你们的龙虾被一锅端了吗? 连我妈都来问我她需不需要“养龙虾”,还好小城市里没有装龙虾服务,不然哪天在网上看到我小时候穿开裆裤的照片我也不会觉得惊讶照片是从哪来的。

China's biggest cybersecurity company apparently just shipped an AI assistant with its own SSL private key sitting inside the installer. Qihoo 360, think Norton or McAfee, but dominant across the entire Chinese market It appears that their new AI product, 360安全龙虾 (Security Claw) bundles a wrapper on @OpenClaw. Inside the installer package - accessible to anyone who downloaded it - was a private SSL certificate key for the domain *.myclaw.360.cn. An SSL private key is essentially the master password to a website's encrypted connection. With it, an attacker can impersonate 360's servers, silently intercept user traffic, forge a login page that looks completely legitimate, or possibly take over the AI agent altogether. The cert is valid until April 2027 and covers every subdomain on the platform. It's now public. The founder launched the product with a promise it would "never leak passwords". It did that during release? 461 million users, a $10B valuation, and nobody checked the zip file before shipping. The cert expires April 2027.


















