Skip to content
Cosmopediaby Unity Nodes
DiscussionsConversationWhy would amulet publish an informal security report with notionals name on it?Forum ↗

Why would amulet publish an informal security report with notionals name on it?

Conversation5 posts523 views3 likesLast activity Jan 2024
JA
jacobgadikianOP
Jan 2024 1

@catdotfish - yes of course the former post went out of scope because it was an insanely unprofessional act on the part of @Jessysaurusrex .; I explicitly asked their team for pre-publication review. You are not the first person to say they’re going to contact them to get my company’s name off of it. I assume that all 5 people I asked, did as I requested. So why isn’t Notional’s name removed from Informal’s report? It has not happened. The only thing I can think is that they were deliberately leaving it there, attempting to attribute to Notional a “low severity” rating on an issue that can stop any chain. This is why it is decent, and common courtesy to get permission before putting someone (or their company’s) name on stuff. Please consider the following scenario: • I write an article talking about how the world is ruled by mutant aliens. • I then give you attribution for that information @catdotfish you shouldn’t close that thread, until it is changed. I deserve the right to speak out and say the following facts: • The interchain foundation funds teams that misattribute reports • The interchain foundation funds a security team that doesn’t even give…

Excerpt (1195 of 2296 characters). Read the whole post on the forum ↗

JA
jacobgadikian
Jan 2024 2

Just in with a report from @catdotfish

Thing is I believe that My original email made it extremely clear that I did not feel that amulet actually understood the issue, and that I wanted to see anything pre-publication.

Additionally it sucks that I need to document this stuff publicly.

The reason I need to is that my repeated requests have been ignored.

JA
jacobgadikian
Jan 2024

JA
jacobgadikian
Jan 2024

JA
jacobgadikian
Jan 2024

tell ya what is bogus though: Slapping someone’s company’s name on a report they didn’t write, without consent, knowing the other firm disagrees: • https://forum.cosmos.network/t/amulet-security-advisory-for-cometbft-asa-2023-002/11604/29 • Why would amulet publish an informal security report with notionals name on it? - #3 by jacobgadikian So is informal bogus? idk (note direct relevance to this PR) Actual and legit p2p storms reports here: • https://docs.google.com/document/d/1q6C1xGdbFaTwJQkzevAHxFsqyUyL_vzJvunp5XESo60/edit#heading=h.gcda2ww838dk • https://docs.google.com/document/d/1oCjsVYMaV77etxOEbDxh58vkAQaXf7RAkhXvF_8GYis/edit?usp=sharing • https://docs.google.com/document/d/1HNSF75A2K8CgFIAagoF2b3MCbZ_BS-7v5l4b9romPW4/edit Again, no personal attacks, the whatever that is on the fourm, isn’t what I reported and I don’t want association with it. Probably like how informal wouldn’t want those links in a repo they maintain. I’ve let the foundation know I hold them responsible for the actual gross misrepresentation and harassment. repo including all correspondance on the matter, and proof of sploit: • https://github.com/notional-labs/spammy…

Excerpt (1199 of 2705 characters). Read the whole post on the forum ↗

← Back to Discussions