Live data from Hacker News

A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

medium.freecodecamp.org

121–130 of 440 posts

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#121

Earlier quoted context omitted.

You really just simply do not get it. Just like the law can not define Pi to be 3 the law should not be able to influence the outcome of a smart contract if smart contracts work at all because that is how it is intended to work, smart contracts are supposed to be the entirety of the agreement, no outside interpretation should make a difference nor could it make a difference. This is where the Ethereum crowd has - in…

I do get it. I just don't think that's realistic. What smart contracts should be according to you is mostly irrelevant to how the law will treat them.

It sounds like you're both in agreement that it doesn't seem realistic. What jacquesm is explaining is that the intention of "smart contracts" is to work entirely outside the existing legal system. There is no need for adjudication of any contract by a court because the contract is the law and the court.

Put in X out comes Y,every time. No room for interpretation, just pure beautiful math. That was the idea anyway, for some reason it seems they decided to implement some of these contracts in a not particularly rigorous way.

Jacques is talking about the theory and premise behind the smart contracts, and you Marco are talking about the people interacting with the smart contracts. People who of course are existing under the scope of our present legal systems.

As long as real people can be hauled before a real court

I think this is the crux of the misunderstanding. Because actions can be taken in these crypto-systems more or less anonymously, it is not obvious that you can "haul some one before a real court" should they wrong you in some way, and in those cases when you have parties interacting in these systems anonymously, the laws of the crypto-systems are the extent of the laws they are operating under. Provided extensive investigative effort isn't undertaken to unmask anyone operating anonymously.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#122
post #89
post #82

Earlier quoted context omitted.

Once code is developed that proves to be bug free, it can be used over and over with no bugs! Doesn't seem to quite work like that in real life.

quicksort? cat? ls? I mean some of these things have bugs still, but generally when you have something of fixed scope then there are less bugs over time. Especially if you're restricting your scope to something simple

> I mean some of these things have bugs still, but generally when you have something of fixed scope then there are less bugs over time. Especially if you're restricting your scope to something simple

I'm guessing that smart contracts tend to be relatively short and simple? I mean I would never bet on an entire web/mobile app being bug free because the surface to attack is enormous but e.g. a sorting algorithm or something small in scope can be formally verified to be bug free as long as your specification is accurate.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#123

Earlier quoted context omitted.

However a smart contract between you and me may execute, a court can still order me to give you money, or order me to enter into a different smart contract. And if I don't comply, they will eventually hold me in contempt and at some point seize my property by force and throw me in jail if I resist. The authority of the state ultimately rests on its ability to resort to violence to enforce its will. No smart contract…

> However a smart contract between you or me may execute, a court can still order me to give you money, Just like that judge that ordered the DAO hack to be reversed? > or order me to enter into a different smart contract. No, a judge will never order anybody to enter into a different smart contract just like they don't order people into regular contracts today. > And if I don't comply, they will eventually hold me i…

>The world is larger than just your own country.

Not too much larger, considering that every major company and country has large amounts of assets and other financial interests that are subject to US jurisdiction. The government of Argentina recently learned that the hard way when American courts forced them to honor their sovereign debt, or have their US-based assets seized to pay them. The same applies if you want to do business in India, China, or Europe. Submit to their judgments or see your assets and interests in their jurisdiction confiscated or destroyed. Another recent example of this is French courts applying the "right to be forgotten" extraterritorially.

>No, a judge will never order anybody to enter into a different smart contract just like they don't order people into regular contracts today.

They certainly do, in effect. A court judgment very often creates new obligations between the parties. And if entering a new smart contract is the only way to right some legal wrong, then they can order that too. An American court, at least, can order just about anything it needs to in order to enforce its judgments.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#124

Earlier quoted context omitted.

You still don't get it. The law will not have anything to say about smart contracts because the law will not be able to enforce a contract one way or another depending on some judge but it will simply execute and that's the end of that . This so that some guy in China or India and some guy in the United States can agree on terms without having to haggle over whose legal jurisdiction will kick in if and when there is…

However a smart contract between you and me may execute, a court can still order me to give you money, or order me to enter into a different smart contract. And if I don't comply, they will eventually hold me in contempt and at some point seize my property by force and throw me in jail if I resist. The authority of the state ultimately rests on its ability to resort to violence to enforce its will. No smart contract…

Assuming you live in a certain subset of countries, sure that could happen (take a look at what happens when an American sues a Chinese citizen). But it defeats the purpose of a smart contract.

If everyone agrees that smart contracts will pay out when they are fufilled. But only if they are fufilled in the specific way each party believes they should be (as opposed to what the code actually says)--then there is no point in smart contracts.

A potential solution is some form of very explicit disclaimer that states you are agreeing X should be paid when the code in contract Y executes, not when the condition you believe the code in contract Y tests for is met.

Of course a court could still ignore the disclaimer.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#125

Earlier quoted context omitted.

I do get it. I just don't think that's realistic. What smart contracts should be according to you is mostly irrelevant to how the law will treat them.

You still don't get it. The law will not have anything to say about smart contracts because the law will not be able to enforce a contract one way or another depending on some judge but it will simply execute and that's the end of that . This so that some guy in China or India and some guy in the United States can agree on terms without having to haggle over whose legal jurisdiction will kick in if and when there is…

>This so that some guy in China or India and some guy in the United States can agree on terms without having to haggle over whose legal jurisdiction will kick in

>there is no way around a smart contract environment that actually works.

What about the present system where people develop trusting relationships in business and elsewhere and deal with the occasional anomalies and breaches of trust as they arise, but in the big picture they're not really a deal breaker because they are relatively rare and we humans are wired for socially harmonious behaviour and mutually beneficial actions. Is that a way around it? It seems to have been working decently well thus far in terms of facilitating extensive commercial networks around the world.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#126
post #96

Earlier quoted context omitted.

>I wonder how do you ride your plane then? When I was in physics undergrad, I remember talking to engineering students taking statics. In general physics, we were allowed to make simple numerical errors, the emphasis then was on figuring out the solution and understanding the physics. My friends on the other hand complained how they, after acing gen. physics, would get mercilessly docked off points for minor arithmet…

That means there is an entrepreneurial prospect for you to enter the space with a team that has a more serious background, right? Eventually people will generally understand that contracts require serious correct engineering, and you'll be able to capitalize on expertise. Smart contracts have only been generally available for like a couple of years. Most people are clueless about how to do them properly. That means i…

>Eventually people will generally understand that contracts require serious correct engineering, and you'll be able to capitalize on expertise.

No one gets paid for exploiting a minor hole in a bridge, causing it to collapse. They will by finding holes in smart contracts, as evidenced.

Bug bounty programs do not exist to provide alternative means of financial remuneration for black hat hackers. They exist to provide white/grey hat hackers an opportunity to get paid for doing the right thing. And yet black hat hackers still sell zero-days to rogue governments and operatives.

Why do you think this bug bounty model of securing smart contracts will be any different? Capitalizing on expertise against smart contracts has its own reward with a shorter feedback cycle than selling zero-days: You directly profit from finding security breaches and stealing money.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#127
post #17

Stories like this make me consider whether programmers that engage in commerce should be forced (yes, by law) into guilds that have rigid journeyman and apprenticeship stages before the programmer gets to touch the production environment. Specialized, official, bonded developer roles need to be established. Our community cannot continue operating in the hacker mode wherever money is involved.

It is a very interesting thought. Any Germans care to comment? They have the closest systems, I would think.

What do you mean? I've been working as a developer in Germany for 5 years now, and I'm only now getting a CS degree. There is a vocational training for software developers, bit it's nowhere near required.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#128
post #49

Earlier quoted context omitted.

The rest of the article amounts to a few points: - Humans make mistakes, the tools should have been better - The technology to make Ethereum safe doesn't really exist - We should work to make that technology exist - We should be happy this happened since it raises awareness about the problem > In the end, attacks like this are good for the community. They call you to your senses and force you to keep your eyes open.…

> We're not even close to a world where tools can offer amazing protection. I wonder how do you ride your plane then? > The tools that will save us from this madness don't exist. These tools do exist(not with ethereum ofc). They are harder to work with, which should be a non-issue for writing contracts.

>I wonder how do you ride your plane then?

I don't fly air superiority missions, so I don't generally consider it. Your point is probably valid for Air Force and Navy pilots, I guess.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#129

Earlier quoted context omitted.

The rest of the article amounts to a few points: - Humans make mistakes, the tools should have been better - The technology to make Ethereum safe doesn't really exist - We should work to make that technology exist - We should be happy this happened since it raises awareness about the problem > In the end, attacks like this are good for the community. They call you to your senses and force you to keep your eyes open.…

> We're not even close to a world where tools can offer amazing protection. Actually, we're reasonably close--the tools aren't quite there yet for mass consumption (many are still feel quite researchy), but given that the trend of (research -> industry) usually takes 10-25 years, I'd expect that more and more critical systems will be formally verified in 10 years. Even now, companies like Amazon are using some formal…

I think the problem is that the language for smart contracts that backs Ether hasn't been written with formal verification in mind. You could apply formal methods to anything after the fact but it doesn't look like they've made this easy here. You could claim that a C program could be made bug free eventually by applying formal methods for example but it would require a huge amount of work.

Is there a good reason they didn't use a battle tested pure functional language with a strong and expressive type system?

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#130
> Having sounded the alarm bells, a group of benevolent white-hat hackers from the Ethereum community rapidly organized. They analyzed the attack and realized that there was no way to reverse the thefts, yet many more wallets were vulnerable. Time was of the essence, so they saw only one available option: hack the remaining wallets before the attacker did.

> By exploiting the same vulnerability, the white-hats hacked all of the remaining at-risk wallets and drained their accounts, effectively preventing the attacker from reaching any of the remaining $77,000,000.

> To prevent the hacker from robbing any more banks, the white-hats wrote software to rob all of the remaining banks in the world. [...]

One argument I keep hearing in favor of cryptocurrencies is that they are beyond the control of individual governments and their regulation through legislation and law enforcement.

Next time, I'm going to use this case as a counterexample, because when the solution to the problem of "hackers robbing banks" is "vigilantes robbing the remaining banks", something is very wrong with your system, and it is certainly not something for the general public.

Post reply on HN