10 ms·
> took a private key from KMS They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.
by WatchDog 7mo ago
> took a private key from KMS
They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.
- pants2 7mo ago^ this is a common security misconception in crypto. "We're using an HSM, they can't steal our private key." OK genius now you still have to secure the HSM. There's no shortcut to MPC/multisig with 3+ keyholders.
- Ferret7446 7mo agoIt's still significantly better, since access can be revoked, vs a leaked key where you're permanently fucked
- pants2 7mo agoNot much better because even a single signature can drain your whole wallet.
- WatchDog 7mo ago> you still have to secure the HSM Obviously. > There's no shortcut to MPC/multisig with 3+ keyholders. The whole concept of a stablecoin seems to be based on centralised trust. Ultimately there is some org that has the fiat bank account, that mints and redeems the coins.
- idiotsecant 7mo agoNope, that is the foundation of bad stablecoin. Trustless decentralized stablecoin like DAI exist. People just largely don't do their homework and prefer scams that lure them in with promises of 'yield'
- Hendrikto 7mo agoDAI and SKY are backed in large part by USDC, so they are not truly decentralized. It is possible in theory, but nobody has successfully done it so far.
- killerstorm 7mo agoIt's possible in practice: that's how DAI worked originally. It's just not very competitive where the main customer -- traders -- want a lot of liquidity and razor thin spread.
- idiotsecant 7mo agoDAI made some dumb decisions for market reasons recently but it was an actual stablecoin for a long time. It worked fine, they just decided to make it worse for some reason.
- heartlinmachado 6mo ago[dead]