Earlier quoted context omitted.
You still don't get it. The law will not have anything to say about smart contracts because the law will not be able to enforce a contract one way or another depending on some judge but it will simply execute and that's the end of that . This so that some guy in China or India and some guy in the United States can agree on terms without having to haggle over whose legal jurisdiction will kick in if and when there is…
If you try to argue this to a judge you will most likely end up doing some time for contempt of court. I am not a lawyer and not your lawyer.
A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
141–150 of 440 posts
Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#142Earlier quoted context omitted.
> However a smart contract between you or me may execute, a court can still order me to give you money, Just like that judge that ordered the DAO hack to be reversed? > or order me to enter into a different smart contract. No, a judge will never order anybody to enter into a different smart contract just like they don't order people into regular contracts today. > And if I don't comply, they will eventually hold me i…
> The world is larger than just your own country. Not too much larger, considering that every major company and country has large amounts of assets and other financial interests that are subject to US jurisdiction. The government of Argentina recently learned that the hard way when American courts forced them to honor their sovereign debt, or have their US-based assets seized to pay them. The same applies if you want…
Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#143Nothing was stolen. All I see is a programmer abiding by the contracts.
In legal terms you'd need to make the argument that the programmer abided by the letter of the contract rather than the spirit of the contract. That might well be a reasonable defence in the case of smart contracts, but it'd need to be tested in a court.
Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#144Earlier quoted context omitted.
> This isn't a normal loss by the way, where you can prosecute someone or sue somebody. No, this is the instant, digital theft of the entire value of the contract, to an anonymous digital address where it will be quickly blended in with hundreds of millions of dollars of similar thefts a month. Also worth pointing out that a non-trivial number of people would say that no theft at all has occurred, as the smart contra…
Well, what's the point of having a smart contract if it's not the final authority? We already have contracts that require highly paid humans to judge whether they've been broken or not. To me at least Etherium was dead the moment they chose to fork because they felt a contract was "hacked".
I think this is a common misunderstanding of Ethereum and blockchains in general. The current Ethereum blockchain is authoritative only as long as a majority of it users consider it to be authoritative. The same applies to Bitcoin. No single person decided to fork Ethereum after the DAO was hacked, it was decided by a quorum of Ethereum users. The original fork still exists as Ethereum Classic and if you believe that the "contract is king" then you are still free to continue using that fork along with everyone else who shares that view.
You say "To me at least Ethereum was dead the moment they chose to fork" and that is probably the view of many Ethereum users. I'm certain many Ethereum holders chose to divest their positions and move their assets elsewhere. That is a big loss for the currency but obviously enough people still believe it to be worth something and so it survives.
Because of their distributed nature, cryptocurrencies can be thought of more as living organisms fed by the collective computing power of their users. They don't need to be perfect to survive, only to be slightly fitter than their competitors.
Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#145Earlier quoted context omitted.
> I know I'm this situation the dev made a simple mistake, but I wonder if Ethereum is safe as a system assuming developers will make many mistakes, and those mistakes will happen more often as more complicated contracts are written. This will probably come off as being assholish, but I honestly don't mean it to be: you should read the rest of the article. It actually covers this topic in depth and has good thoughts…
The rest of the article amounts to a few points: - Humans make mistakes, the tools should have been better - The technology to make Ethereum safe doesn't really exist - We should work to make that technology exist - We should be happy this happened since it raises awareness about the problem > In the end, attacks like this are good for the community. They call you to your senses and force you to keep your eyes open.…
There seems to be a lot of hype and demand around blockchain tech at the moment, and hence a lot of demand for developers to pick up the tech. For the skilled and experienced developers who work with blockchain tech these kinds of events will make them think more about what they're doing and probably take more care. For those of us with lots of programming experience but no knowledge of blockchain tech, they serve as a warning that there are serious issues with the platform that need deep experience (and hence time investment) to address properly.
That leaves a tranche of less experienced developers who maybe don't realise that these issues mean they should take more care (or use better tooling, or whatever other panacea is called for to make development 'safe'). The platform may finish up with a small number of experienced developers writing 'safe' code and a larger number of inexperienced developers writing 'unsafe' code, with the result that the platform as a whole finishes up being unsafe. As the article says:
> Most of the programmers who are getting into this space, myself included, come from a web development background, and the blockchain toolchain is designed to be familiar for web developers. [...] In a way, this may end up being its downfall.
> The problem is, blockchain programming is fundamentally different from web development.
Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#146Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#147I think the fundamental problem here is an economic one. Make three assumptions: 1) most contracts worth implementing in Ethereum are fairly complex 2) even given great developers, bugs are inevitable in complex code 3) the budget of the contract-makers' security team MUST be smaller than that of the hackers You quickly see that if the chance of a bug is nonzero, "smart contracts" don't make economic sense. If you ha…
Some things that are at stake on the lawyers side are their competence (can they actually make sure the contract is "secure" ?), their reputation (track record of competence established over time) and some insurance mechanism (if things go wrong can you get something back from their insurance).
All of the above seem to be missing in the case of "smart-contracts".
Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#148Writing provable, secure software is difficult, and highly unlikely if your environment doesn't force the correct mindset. Solidity (poorly named) was made with the primary goal of being easy for JavaScript / Node hackers to use.
The cost of this is now illustrated through the repeat 'hacks' of bad 'smart contracts'.
Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#149Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
#150Earlier quoted context omitted.
Your logic doesn't add up. Attackers are only willing spend $90k if there's a 90 percent chance they can exploit a bug in the contract to extract the entire $100k value. Clearly if TWO hackers both spend $90k and only one extracts the value, the other one has lost their entire $90k - unless there's a way to be sure you are the one who will win that, your expected return on the $90k is only $50k if there are two parti…
> But a loss of unmarked cash is similarly instant. True, there isn't a global list of where every bank note is. I've already lost a tiny amount of BTC just by testing a bit with short keys. Can you imagine what the world would be like if every time you left your wallet for 10 seconds, it vanished?
testing a bit with short keys.
He's put some bitcoin into wallets with keys/passwords that don't meet very high security standards.
I've already lost a tiny amount of BTC
He's then lost that bitcoin because there are programs running running around the clock to programatically empty any wallets with passwords that don't meet very high standards of security.
Thus,
Can you imagine what the world would be like if every time you left your wallet for 10 seconds, it vanished?
But this is the "trustless" world you signed up for right?