It was more than just security experts who understood this about @HegicOptions. It was obvious that further work was needed to non-experts too. “It's OK we have no tests because the auditors will catch all the bugs” said no one ever
https://twitter.com/BlockEnthusiast/status/1254132916675907584 …https://twitter.com/hitchcott/status/1253982497446166528 …
-
Show this thread
-
Dan Guido Retweeted Dr Heidy Khlaaf (هايدي خلاف)
We know there are roadblocks to interpreting our results by non-experts. For example, we purposefully avoid subjective opinions in our reports, preferring objective facts to maintain our integrity and independence.https://twitter.com/HeidyKhlaaf/status/1254121886902083584 …
Dan Guido added,
Dr Heidy Khlaaf (هايدي خلاف) @HeidyKhlaafReplying to @dguido @defiprime and 5 othersThese criticism lack any realism in how auditing works. Working in Safety, where government auditors are also involved, independent auditors have their hand tied and can seldomly make "human readable" recommendations. We provide objective technical observations. That's it.1 reply 0 retweets 21 likesShow this thread -
Dan Guido Retweeted Jordan Spence
Further, it's possible for clients to simply ignore what we document in reports.
@trailofbits does not have any authority over our clients, we simply provide them advice. https://twitter.com/HeidyKhlaaf/status/1254122500407152640 …https://twitter.com/spencecoin/status/1254116602720608258 …Dan Guido added,
Jordan SpenceVerified account @spencecoinReplying to @Rewkang @defiprime and 4 others^^^^ THIS Security audits are an audit of the security. They are purely objective. They provided ALL the information and unfortunately can't control what happens after that information is given. Dan and trailofbits performed exactly as they should have.1 reply 0 retweets 20 likesShow this thread -
How will we improve after this incident? 1st, we will no longer work with
@HegicOptions. Their behavior has been deeply irresponsible. They ignored our advice and recklessly put user funds at risk. This hurts the entire DeFi community.2 replies 7 retweets 52 likesShow this thread -
2nd, we will keep services from
@trailofbits accessible for those with lower or limited financial resources. Security assistance is essential for smaller projects, and we'll continue to help those that need it with shorter project sizes.3 replies 2 retweets 48 likesShow this thread -
3rd, we'll add structure to our summary reports to help readers better evaluate the current state and maturity of the project while remaining objective. It's unfortunate so few people look beyond our reports so we'll provide stats and info about the code in them.
2 replies 3 retweets 49 likesShow this thread -
cc
@defiprime@lalleclausen@tzhen@drVillo@preston_vanloon@hitchcott@intocryptoast@quentinc137@Fiskantes@ck_SNARKs@nicksdjohnson@ChainLinkGod@hosseeb@IamNomad@JTremback Thanks for your earlier comments! We're open to hearing your opinions about how we can improve.7 replies 0 retweets 36 likesShow this thread -
Replying to @dguido @defiprime and
scott lewis 🌾 Retweeted scott lewis 🌾
hi dan, could you add a standardized outgoing confidence to your audits? I have read many of your audtis and trail of bits has a very good standards for the 1 & 2. /https://twitter.com/scott_lew_is/status/1254089620037480450?s=20 …
scott lewis 🌾 added,
scott lewis 🌾 @scott_lew_isfor every custodial contract audit i would like to see: 1. engineer hours spent on audit. 2. bug distribution: (crit/high/medium/low/info) 3. auditors outgoing confidence level on the safety of contract going forward: (inadequate/adequate/acceptable/excellent) we need all 3.1 reply 0 retweets 3 likes -
Replying to @scott_lew_is @dguido and
second, does trail of bits ever "unpublish" public audits? I have been unable to locate the Compound V1 audit. was it ever public? if we are trying to determine how much value an audit adds to the safety of a project, the less selection bias in the data set, the better.
1 reply 0 retweets 1 like -
Replying to @scott_lew_is @defiprime and
Thanks for the Qs. 1) We need to stick to objectivity. No subjective opinions about "confidence" (varies by person, impossible to measure, etc). Instead, we'll make it easier to understand the current level of risk and recommended actions going forward.
2 replies 0 retweets 1 like
2) We don't publish all of our reports, particularly ones that involve corporate, internal, or cloud security, which were areas of focus for our first Compound review. This IT infrastructure is not available outside the company, therefore the review of it is not either.
-
-
Replying to @dguido @defiprime and
ahhhhhh. that explains it. i think i assumed it was the audit of the public code, but i guess i need to keep looking. dang.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Replying to @dguido @scott_lew_is and
This is interesting, thanks for sharing
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.