@trailofbits How did you let these guys pass an audit without any automated tests? I could not find the audit report. Would it make sense for all the projects to have automated public test suite - even if you need to write it for them yourself?https://github.com/hegic/hegic-contracts-v1 …
-
-
Replying to @moo9000 @trailofbits
Where do you see that
@trailofbits said they "passed" anything? That audit report describes a dozen critically severe bugs that were found with relatively low effort.1 reply 0 retweets 0 likes -
Replying to @dguido @trailofbits
Mikko Ohtamaa Retweeted Mikko Ohtamaa
Here is my line of thought https://twitter.com/moo9000/status/1254086433356361728?s=19 … Why did the project go ahead despite the audit? Was there a failure to communicate somewhere? It is bad for you as the project clearly associates Trail of Bits with it by publishing the report.
Mikko Ohtamaa added,
1 reply 0 retweets 0 likes -
If the developer is young or hired why did he or she was not stopped by you guys if you see it needs more work?
2 replies 0 retweets 0 likes -
Replying to @moo9000 @trailofbits
That's not our job. Here's our job: We reviewed the code, found a dozen critically severe issues in a short period of time, and made recommendations to further improve the system. Here's what we told them directly:pic.twitter.com/Pao9wWiYck
1 reply 0 retweets 1 like -
Replying to @dguido @trailofbits
It might be not your job, but it should be your moral responsibility as a Ethereum community member and as a fellow developer.
1 reply 0 retweets 0 likes
I reported what we found in a public report (lots of bugs, an indication that more are present), and I privately advised the project avoid launching without further review and tests. I can't control what they do, or what you do with that information.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.