Too Late to Learn Web3 Security

Поделиться
HTML-код
  • Опубликовано: 28 июл 2022
  • Is it still worth it to learn web3 security now? Are the bounty rewards still good? My thoughts around whether it is still worth participating in audit contests on code4rena, and my future plans.

Комментарии • 58

  • @lacag-lacag
    @lacag-lacag Год назад +4

    Thanks keep the update man.

  • @jaym4697
    @jaym4697 Год назад +7

    Great content. Keep it up!

  • @soaphornseuo8630
    @soaphornseuo8630 Год назад +5

    Thank brother 😀

  • @linuxinside6188
    @linuxinside6188 Год назад +1

    Great content andy 👌, thank you.

  • @luce36
    @luce36 Год назад

    This channel is amazing!

    • @andyli
      @andyli  Год назад

      Thanks! 😃

  • @cowsecurity
    @cowsecurity Год назад +2

    Great work buddy, also thanks for accepting my request on linkedin!

    • @andyli
      @andyli  Год назад

      Thanks, good to connect!

  • @fuffsec
    @fuffsec Год назад

    Great content. Thank you so much

  • @rokinot5523
    @rokinot5523 Год назад +5

    I think the reason why that high vuln payout was so low was because it was a low hanging fruit finding, almost 30 ppl found it and it was a very simple mistake to spot, which is why the rewards were so diluted. Some recent high vuln findings, if unique, were paying >5k for some contests, so there's still a chance to make some good amount

    • @andyli
      @andyli  Год назад +1

      True, we need to find uniques to get paid well now. Not easy though, I have not gotten a unique finding yet!

  • @tangjunnz
    @tangjunnz Год назад +2

    Thanks

  • @mujtabaaltayib7417
    @mujtabaaltayib7417 Год назад +1

    I'm still confused on it but thanks for the guidance for the beginners like me

    • @andyli
      @andyli  Год назад +1

      No problem, feel free to ask any questions

  • @devabdee
    @devabdee Год назад +1

    TY. Sir

  • @arslanelahmer2729
    @arslanelahmer2729 8 месяцев назад +3

    what's the situation one year on?

  • @qu4ku
    @qu4ku 18 дней назад

    the rewards are huge precisely because there is no competition (talent is scarce), when the talent is not scarce there is commoditization = even highs are worth $50/$500 (it's not different than thousands of indians available to make you an website).

  • @tomj1883
    @tomj1883 Год назад +1

    yea I feel this too but I will definitely continue participating in code4rena because Im there to learn, not the money :) Thanks for the great content!

    • @andyli
      @andyli  Год назад +3

      yep 100%, money is just a bonus

  • @serousetrick
    @serousetrick Год назад +1

    Any advice on what can be profitable but still less competitive area of web3, like what smart contract auditing was a year or two ago?

    • @andyli
      @andyli  Год назад +9

      No easy profits now since we are in a crypto bear market. Learning to become a dev/auditor in web3 is still going to pay off long term.

  • @HelloWorld-sy4yc
    @HelloWorld-sy4yc Год назад +1

    Ohh, u get it. It's cuz of your videos, dude...

    • @andyli
      @andyli  Год назад

      It can't *all* be because of my videos lol

  • @digitalchinmay263
    @digitalchinmay263 Год назад +1

    Hey do you know any other platforms other than code4rena, like one that accepts gas opt etc. ? I'm asking about permissionless open platforms.

    • @andyli
      @andyli  Год назад

      I don't know of any others that accepts QA and gas ops.

    • @digitalchinmay263
      @digitalchinmay263 Год назад

      @@andyli And other audit platforms ? Like code4rena and immunefi ?

  • @aftabkhan2677
    @aftabkhan2677 Год назад +3

    Hi Andy, I am 19 just starting into web3. I am no previous experience in coding I am noob in coding, should I learn java script first or solidity ? In the article you mentioned in the road map of web3 security. its tolded to learn java first.

    • @andyli
      @andyli  Год назад +4

      I would say Solidity first, go through the 32 hour solidity tutorial on youtube

    • @aftabkhan2677
      @aftabkhan2677 Год назад

      Thank you will do that.

  • @zerocool2765
    @zerocool2765 Год назад +1

    Should I start my journey in web 3 bug bounty or traditional bug bounty?

    • @andyli
      @andyli  Год назад

      web3 has bigger long term upside I think

  • @devone7702
    @devone7702 8 месяцев назад

    I'm a proframmer, who is starting his journey in traditional bug bounty. Do you think it's better to learn web3 bug bounty instead ?

    • @andyli
      @andyli  8 месяцев назад

      try some CTFs and see if you enjoy web3

  • @eugenionull9758
    @eugenionull9758 Год назад

    same feeling here... it's over

  • @emmanuelochubili
    @emmanuelochubili Год назад

    @Andy please what are the requirements .. if i am a begginer in bug bounty

    • @andyli
      @andyli  Год назад +1

      Start with doing Ethernaut CTF, I made a video on beginner road map

    • @emmanuelochubili
      @emmanuelochubili Год назад

      @@andyli thanks man.. will look for the link

  • @ashhadali7592
    @ashhadali7592 Год назад

    So i start it or not whats ur advise? i already do web 2 bug bounties intrested to learn web 3 your advise save mu time

    • @andyli
      @andyli  Год назад +2

      Depends on if you are doing this full time and how much you are currently earning in web2 bounties.
      It is still possible to make $500-$1000 per month doing this part time, and of course the long term upside is huge

    • @ashhadali7592
      @ashhadali7592 Год назад +3

      @@andyli no part time
      In web 2 mar earning is 1000-2000$
      2) part time 1000$ is good so u mean i start it
      Thank you Very much
      u help me alot

  • @farena.human_
    @farena.human_ Год назад

    Is it right time to learn web3 security? I mean now days

  • @goodboy9758
    @goodboy9758 Год назад +1

    psyops

  • @haanrey
    @haanrey Год назад +4

    Don't take advice from everyone. I had found a $$$$$ bug in one of the oldest programs in bugcrowd . The bug was 5 years old .

    • @andyli
      @andyli  Год назад +1

      damn, congrats

    • @haanrey
      @haanrey 6 месяцев назад

      @@andyli coming here after a year , I am sorry for being rude while commenting . I wish you more success .

    • @priyanshujaswal2210
      @priyanshujaswal2210 29 дней назад

      ​@@haanreyAt least you learnt brother. And doing this after a few months shows that you are a good person 😊