Live data from Hacker News

A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

medium.freecodecamp.org

191–200 of 440 posts

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#191
post #46

Earlier quoted context omitted.

Those are not sufficient conditions for a one-time pad. The entire pad, not just some "seed" has to be random. The pad cannot ever be reused even with a different plaintext. Breaking a one-time pad that's been used twice is not very hard. It's equivalent to recovering two texts which have been XORed together, which is not hard for English. One time pad systems are used regularly for high-security embassy-to-State Dep…

I don't understand how this is practical. If you have a highly secure mechanism for distributing the ultimate secret - one-time-pads - why not just distribute the messages in this way? Is it just the fact that it would take two trips for the courier? Or that someone would need to intercept both communications (pad, ciphertext)?

A big benefit is that you can time-shift the distribution of the secret - you can distribute the one-time pad when it's convenient (e.g. when your submarine is at a home port) and be able to send secure messages over insecure channels at any future time.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#193
post #13
post #11

Earlier quoted context omitted.

> Isn't "unbreakable" a bit of a dirty word in the security community "Dirty" is one way to put it, yes. I'd personally use something like "false god" or "blasphemy" :). "Unbreakable" is a naive way of describing cryptographic algorithms, because it preempts conversations about intractability assertions or complexity analysis...modern cryptography accepts as a premise that "unbreakable" is not a reasonable goal, whic…

One thing I've never understood about the one-time pad: How do you guarantee the third condition? Wouldn't you eventually run into the birthday problem if you sent enough messages?

One-time pad means that you have a limit to how much data you can exchange before the pad is spent - if you send enough messages, then you can't send any more securely until you exchange another one-time pad.

You're not likely to get a collision ever because of the typical sizes of one-time pads - birthday paradox matters if the key length is measured in bytes, but not if it's measured in gigabytes, there isn't enough space/time in our universe to expect a collision.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#194

Earlier quoted context omitted.

> something is very wrong with your system To be clear, neither of the two situations is "more moral" than the other. In the end however, the question remains: who you trust. Governments have resolved the question long ago (by enforcing trust), cryptocurrencies are just now starting to face the same question. You are correct however that who you Trust remains the greatest issue behind creating a currency.

Look, no. One hundred times, no. Governments in the west are quite accountable, voted for and with a system of checks and balances that has evolved over time, through wars and revolutions. Some random benevolents overlords (white-hat hackers) that save you just because they are magnanimous was the only option only in the most primive societies. Thankfully we moved on from those times, don't you agree?

Again, the question is who you trust, and that remains a moral choice, not an objective, empirical choice. Some people don't trust a government elected by only half the population, for example. Some others may prefer to trust an elite of "enlightened hackers" than hordes of plebs.

You might be right that governments are more evolved and have more history but that doesn't make them universally better.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#195

Earlier quoted context omitted.

Look, no. One hundred times, no. Governments in the west are quite accountable, voted for and with a system of checks and balances that has evolved over time, through wars and revolutions. Some random benevolents overlords (white-hat hackers) that save you just because they are magnanimous was the only option only in the most primive societies. Thankfully we moved on from those times, don't you agree?

Your Whig history of an ever progressing political system is not accurate in my opinion. I've written this comment before, and I'll repeat it as it's relevant to your comment: Societies have gradually grown more unfair as the political system has strained under their growing complexity. According to political scientists, the average voter has an extremely limited understanding of what their government is doing. The t…

Societies have gradually grown more unfair as the political system has strained under their growing complexity.

Is this not a revisionist view of history? Modern republics are pretty new things. There were serfs (and absolute autocracy) in Russia as of 1860, slaves in the US until the 1860s, voting tied to gender until the 1920s, colonial empires without fair representation until 1950, laws against interracial and homosexual marriage until the 1980s and 2014 respectively, state-sponsored inquisitions and pogroms until recently, etc.

People have so much more power than they had as little as decades ago in almost every single society and that seems to me hard to argue. Try being a Spartan helot (you can't because slavery is the exception rather than the rule) and tell me your life is better than any US citizen today. The issues you state - ignorant citizens and special interests have always existed, at least today even the worst governments try and educate their people.

Things can and should get better but to deny progress doesn't seem fair to history. Or is there something else you are seeing?

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#196

Earlier quoted context omitted.

Look, no. One hundred times, no. Governments in the west are quite accountable, voted for and with a system of checks and balances that has evolved over time, through wars and revolutions. Some random benevolents overlords (white-hat hackers) that save you just because they are magnanimous was the only option only in the most primive societies. Thankfully we moved on from those times, don't you agree?

Your Whig history of an ever progressing political system is not accurate in my opinion. I've written this comment before, and I'll repeat it as it's relevant to your comment: Societies have gradually grown more unfair as the political system has strained under their growing complexity. According to political scientists, the average voter has an extremely limited understanding of what their government is doing. The t…

I fully agree with your analysis. But cryptocurrencies are just the latest tool that will serve well the interests of the demagogues. Technocracy will not improve affairs that we don't resolve as a society in the first place. More powerful tools means just more power to those who can afford the longest lever. Any other interpretation is just a blatant neglect on the history of technology.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#197

Earlier quoted context omitted.

As long as real people can be hauled before a real court, judges and lawyers--but more importantly, the law --will be highly relevant.

You really just simply do not get it. Just like the law can not define Pi to be 3 the law should not be able to influence the outcome of a smart contract if smart contracts work at all because that is how it is intended to work, smart contracts are supposed to be the entirety of the agreement, no outside interpretation should make a difference nor could it make a difference. This is where the Ethereum crowd has - in…

> the law should not be able to influence the outcome of a smart contract

You don't seem to understand how the law works. The problem isn't a judge trying to interfere with any of the technical features of the contract. A judge would rule on the legality of the contract as the law sees it[1]. You will be able to argue that the code is the final authority. You will probably also have to show why the other party knew and understood that risk. Depending on the situation, the judge, how each side argues their case, etc, the judge might even agree and dismiss the case.

However, a judge could, for example, rule that an important part of the contract is unconscionable, illegal, etc, and order YOU - not the contract, not the blockchain, not the software - to return the other party's money, or release the other party from their contractual obligations, or to change any particular detail of the contract's terms. The judge won't rule against the contract, they will rule against you, and it's up to you to figure out how to follow the judges order=. If the judge decides to throw the book at you for some reason, the judge isn't going to be interested in why you think about immutable contracts, or what you think the contract means. They could simply throw you in jail (or fine you $1000/day) for contempt until you follow the judge's orders.

It's generally a very bad idea to ignore a judge's orders. IN some situations, this can make immutability a serious liability.

[1] What was the offer? Was there a deliberately misleading or unconscionable clause in the contract? Were the terms understood and accepted? Did each party uphold their obligations under the contract? etc (this type of question will be asked regardless of how the contract is implemented)

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#198
post #23

Earlier quoted context omitted.

You can't. Or, well, you can , but it's redundant. One-time pads make sense in the Cold War, Vernam Square era of cryptography. But now that we have the internet and public key cryptography, a one-time pad implemented in Ethereum would be inane and frivolous. Take Alice and Bob, who want to communicate confidentially. Alice doesn't know Bob personally, so she can't securely communicate the one-time pad to Bob in pers…

My question was more: how do you ensure a system that has true secrecy for its one time pad data when all the source is open?

The code will inevitably need to use a source of true randomness, which will be external to your source code, by definition it can't be a deterministic formula, it needs to use external input from physical devices.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#199

Earlier quoted context omitted.

It is, but it turns out exchanges don't actually care. Bitcoins from the Bitfinex hack are slowly being dumped on exchanges, for example. It's like someone rocked up to a bank with a big duffelbag full of dye-stained notes known to have been stolen from another bank, and went "no worries lol".

Well, it's unlikely the coins when straight from the hack accounts to the exchange accounts (they might have, i'm not sure in this case) The coins just have to go through a single intermediate account for there to be doubt that the hacker still owns them

yeah. Cryptocurrencies are prosecution futures, but only if law enforcement actually cares to do the considerable tedious legwork.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#200
post #197

Earlier quoted context omitted.

You really just simply do not get it. Just like the law can not define Pi to be 3 the law should not be able to influence the outcome of a smart contract if smart contracts work at all because that is how it is intended to work, smart contracts are supposed to be the entirety of the agreement, no outside interpretation should make a difference nor could it make a difference. This is where the Ethereum crowd has - in…

> the law should not be able to influence the outcome of a smart contract You don't seem to understand how the law works. The problem isn't a judge trying to interfere with any of the technical features of the contract. A judge would rule on the legality of the contract as the law sees it[1]. You will be able to argue that the code is the final authority. You will probably also have to show why the other party knew a…

This all assumes that you know your counterparty, which isn't necessarily the case.

You could simply reduce your argument to 'in situations where you use a smart contract where a normal contract would suffice a judge has their usual powers'.

But that wasn't the point I was making. Smart contracts will most likely be used in all kinds of situations where a judge does not have their normal powers, hence the reliance on a smart contract to begin with.

If you can rely on the courts you don't need a smart contract.

Post reply on HN