publications
rocketpool
publications | rocketpool | |
---|---|---|
51 | 104 | |
1,318 | 866 | |
1.4% | -0.1% | |
8.7 | 1.5 | |
12 days ago | 1 day ago | |
Python | JavaScript | |
Creative Commons Attribution Share Alike 4.0 | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
publications
-
Skiff: Various Privacy Failures
Disagree, their reputation is tied to their audit quality.
But I'm pretty sure in this case the scope was bad. Like they coukd have had audits on "Do I use OpenSSL well?" and then misrepresent that all their privacy claims were audited.
Now it seems like Skiff conveniently didn't allow Trail of Bits to publish their reports, they are usually here: https://github.com/trailofbits/publications/tree/master/revi...
Disclaimer, I have used Trail of Bits service in the past (and 2 other auditors for an security campaign on a blockchain, cryptography + networking product).
- The Lisk v4.0 security audit 🔐
-
PyPI has completed its first security audit
Link to the report: https://github.com/trailofbits/publications/blob/master/revi...
They seem to not have analysed client-side of PIP itself, but I suppose there isn't anything you could say that isn't already obvious to everyone.
- SimpleX Chat security assessment by Trail of Bits [pdf]
-
Thoughts on Skiff? What do you like? What would you want to see improve?
Audits are mentioned on the Trail of Bits website https://github.com/trailofbits/publications and the Skiff one https://skiff.com/transparency. Skiff has been externally audited 4 times.
-
SimpleX Chat: private and secure messenger without any user IDs (not even random)
Here's the URL https://github.com/trailofbits/publications/blob/master/reviews/SimpleXChat.pdf It was in the article I have already linked.
-
Solidity digest fortnightly / 17-30 apr 2023
MYSO Finance Security Assesment by Trail of Bits
-
Audit Firms Ranking
Trail of Bits
-
Transparency at Skiff
Hi! I'm Skiff's CEO. We've had 3 security audits, including 2 from Trail of Bits - one of the best security auditing firms in the world https://github.com/trailofbits/publications. Skiff Mail is also open-source: https://github.com/skiff-org/skiff-mail as is our whitepaper https://skiff.com/whitepaper We've also been in the news quite a bit: https://www.theverge.com/2022/5/17/23075804/skiff-mail-email-privacy, https://www.wsj.com/articles/encryption-bans-what-is-this-russia-hacking-online-privacy-security-data-signal-whatsapp-emails-protection-11675436242 (I wrote this with our team!), https://techcrunch.com/2023/01/30/russia-skiff-block/, and more, even though we're only a year old. We collect no personally identifying information - not even IP addresses used - no backup emails, phones, etc. - no advertising, and we end-to-end encrypt BOTH email subject + body and don't have any metadata (time sent/received an exception). What can we do to share more of this with more people? We're a younger company but it's so important this is made public.
-
Skiff Apps
Hi! I'm Skiff's CEO. We've had 3 security audits, including 2 from Trail of Bits - likely the best security auditing firm in the world https://github.com/trailofbits/publications. Skiff Mail is also open-source: https://github.com/skiff-org/skiff-mail as is our whitepaper https://skiff.com/whitepaper
rocketpool
-
about rETH
And yes, you can swap your rETH back with the protocol directly on www.rocketpool.net
- Staking rewards?
-
Daily General Discussion - October 29, 2022
Discord is a must for anything Rocketpool related. There is a link on the website at www.rocketpool.net
-
Can someone ELI5 the value of rETH?
You can check the official rEth to Eth ratio at www.rocketpool.net
-
how do you stake while maintaining custody and control over your eth without needing to run a node?
The source code of the contract can be revised here: github repo
-
Daily General Discussion - March 20, 2022
when deciding to take part in a staking pool that allows them to run a Validator with just 16Eth instead of 32 for sharing their staking rewards 50/50 + commission as displayed on www.rocketpool.net for years now.
-
Bi-Weekly Development Update - February 14/15, 2022
The Merge - finished initial contract changes for The Merge based on this research: https://github.com/rocket-pool/rocketpool-research/blob/master/Post%20Merge/Merge%20Implementation%20Research.md For those who are interested, here is the branch: https://github.com/rocket-pool/rocketpool/tree/merge-ready Please note that it is under code review, requires further testing, and is unaudited at this stage.
-
How Much Staking Passive Income Do You Need To Retire? I Did The Math
All Rocket Pool code has been open source over more than 4 years, longer than any other major ETH project.
-
XT Will List JBX,RPL
Website: https://www.rocketpool.net/
-
Now, you don't have to be a validator with 32 ETH or give custody of your coins to a centralized staking pool or exchange to participate in ETH2.0 staking.
Review their smart contract code, but since that’s complicated, research their auditors and audit reports.
What are some alternatives?
slither - Static Analyzer for Solidity and Vyper
lido-dao - Lido DAO smart contracts
manticore - Symbolic execution tool
rotki - A portfolio tracking, analytics, accounting and management application that protects your privacy
echidna - Ethereum smart contract fuzzer
token-allowance-checker - Control ERC20 token approvals
verified-smart-contra
MyEtherWallet - MyEtherWallet (our friends call us MEW) is a free, client-side interface helping you interact with the Ethereum blockchain.
codeql - CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
EIPs - The Ethereum Improvement Proposal repository
security - Materials related to security: docs, checklists, processes, etc...
ethereum-org-website - Ethereum.org is a primary online resource for the Ethereum community.