Jay Freeman (saurik)Verified account

@saurik

I developed Cydia for jailbroken iOS devices and am now (theoretically) in charge of technology for ; I am also a local politician in California.

Isla Vista, CA
Joined May 2007

Tweets

You blocked @saurik

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @saurik

  1. Mar 10

    As an interesting contrast, released their official postmortem of the bug this morning, along with their understanding of the cause (which I will note is very different from the engineering methodology and process issue I focus on in my talk).

    Show this thread
    Undo
  2. Mar 10

    Note: the audience for that recording was the final day of an Intro to CS class, and so it is somewhat a culmination of our earlier discussion; in particular, I view my talk on Unbridled Optimism as an update to this other lecture I often give on security.

    Show this thread
    Undo
  3. Mar 10

    I had tech issues at that affected my talk on Unbridled Optimism (the Ethereum L2 bug I reported last month); but, last night, I gave a much more complete version at a UCSB course I co-facilitate! ...though (sorry) the audio quality is poor.

    Show this thread
    Undo
  4. Mar 10

    As an interesting contrast, released their official postmortem of the bug this morning, along with their understanding of the cause (which I will note is very different from the engineering methodology and process issue I focus on in my talk).

    Show this thread
    Undo
  5. Mar 10

    Note: the audience for that recording was the final day of an Intro to CS class, and so it is somewhat a culmination of our earlier discussion; in particular, I view my talk on Unbridled Optimism as an update to this other lecture I often give on security.

    Show this thread
    Undo
  6. Mar 10

    I had tech issues at that affected my talk on Unbridled Optimism (the Ethereum L2 bug I reported last month); but, last night, I gave a much more complete version at a UCSB course I co-facilitate! ...though (sorry) the audio quality is poor.

    Show this thread
    Undo
  7. Feb 13

    I'd missed the confirmation of this on Thursday, but had decided to additionally extend to me their (maximum) $100k bug bounty payout, making the total reward for my Ethereum L2 bug--"Unbridled Optimism"--$2,100,042! (...I think this might actually set a new record?)

    Show this thread
    Undo
  8. Feb 10

    I will be giving a talk about the bug at , Friday, February 18th: 9:40am MST on the Infinity Stage. My talk will be live-streamed, presumably to the YouTube channel: Look out for "Attacking an Ethereum L2 with Unbridled Optimism"!

    Show this thread
    Undo
  9. Feb 10

    Last week, I discovered (and reported) a critical bug (which has been fully patched) in (a "layer 2 scaling solution" for Ethereum) that would have allowed an attacker to print arbitrary quantity of tokens, for which I won a $2,000,042 bounty.

    Show this thread
    Undo
  10. Amazingly, the bugs continue: after I gave up and went to sleep, the two transfers I then had "PENDING" were both "CANCELLED" at the same time with the reason "The transaction fee has expired."... but these failed transfers are still counting against my daily withdrawal limit :/.

    Show this thread
    Undo
  11. (Before I decided to tweet, one of my transactions ended up failing after *10 hours*, with an extremely low-level looking e-mail that had the error message "Pro/Prime send money failed!". Attempting to retry the transaction put it in the same state again.)

    Show this thread
    Undo
  12. FWIW, this apparently has happened to many other users on the subreddit and most of them report the same SNAFU of your customer support providing incorrect responses in a loop, so this seems to be a systemic issue. Maybe a postmortem is in order?

    Show this thread
    Undo
  13. Does anyone else find it strange that both Apple and Google not only allow but in fact require privacy policies for apps to be hosted on external websites, meaning that to view an app's privacy policy you must connect to their server and already subject yourself to their logging?

    Undo
  14. In 2016, I ran for 3rd District County Supervisor in Santa Barbara (and lost). I've been told (after) that, had I run for California State Assembly District 37, I might've had institutional support! Some days, I dream about the bills I could've floated ;P.

    Undo
  15. For more detail, I'll highly recommend reading our complaint: "This lawsuit seeks to open the markets for iOS app distribution and iOS app payment processing to those who wish to compete fairly with Apple, and to recover the enormous damages Apple caused."

    Show this thread
    Undo
  16. Cydia just joined the legal battle against Apple: "A new lawsuit brought by one of Apple's oldest foes seeks to force the iPhone maker to allow alternatives to the App Store, the latest in a growing number of cases that aim to curb the tech giant's power."

    Show this thread
    Undo
  17. Regardless, in early September of 2020, I was able to get Facebook to reinstate the Cydia app... though they made it sound tenuous enough that I waited until now--when I'm finally feeling confident-ish--to reactivate the button, in case anyone still has reason to log in to Cydia.

    Show this thread
    Undo
  18. In June of 2019, Facebook suspended my Cydia app, removing its access to Facebook login and locking users out of their Cydia accounts, which required a slow (on both sides: Facebook and I each were taking months to respond to the other ;P) back and forth of interrogations to fix.

    Show this thread
    Undo
  19. So yeah: I don't know if anyone else will agree with me that security events should not allow companies using USC Section 1201--or similar laws around the world: the US got this included in a WIPO treaty--to speak at their events, but if so: poke a conference organizer for me? ;P

    Show this thread
    Undo
  20. Companies which wish to speak at security events should be required to sign a non-action pledge on USC Section 1201--which isn't even about infringement: it is a potentially-unconstitutional law about "circumventing" controls and "trafficking" in tools--in order to submit a talk.

    Show this thread
    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·