Earlier quoted context omitted.
The flip side of that is any smart contract that stood the test of time should be rock solid. For example, there are huge incentives to go ahead and hack a big contract like maker, compound, uniswap or aave, so you can bet that there's highly qualified people out there trying to hack them as we speak, yet after all this time, they are still working as intended. I have a lot more trust in that kind of product than in…
How many major bugs in software and especially cryptosystems went undisclosed for decades? The core issue is the inherent asymmetry where 1 person finding 1 bug can destabilize giant systems. Even if these systems where hundreds of years old that doesn’t actually mean much.
SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
261–270 of 577 posts
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#262Earlier quoted context omitted.
Time for LawyerCoin (TM). The smart-contract is written in English (or other human language) and the oracles are powered by a bunch of lawyers who pinky swear to enforce them. I'm doing ICO next week, if anyone wants in.
We can do better than pinky swearing. Each lawyer gets mining fees when they enforce a contract fairly. "Fairly" is defined by consensus, where each lawyer is forced to predict the consensus before voting in a private ballot that is only revealed when the rewards are issued. Lawyers who predict the consensus get rewarded. If you start it off with people who are trying to be fair then predicting fairness will lead to…
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#263The fact that this is trending on HN shows how little hacker news knows about the cryptocurrency space. A relatively unknown, recently launched stablecoin collapsing is not big news in crypto. Now if dai, usdc or usdt had failed, that would be a big deal.
Meanwhile on boomer news
> A single web server caught fire somewhere in Bolivia, is social media over? (+20000 points)
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#264Earlier quoted context omitted.
The flip side of that is any smart contract that stood the test of time should be rock solid. For example, there are huge incentives to go ahead and hack a big contract like maker, compound, uniswap or aave, so you can bet that there's highly qualified people out there trying to hack them as we speak, yet after all this time, they are still working as intended. I have a lot more trust in that kind of product than in…
Considering there are still new bugs found in chip designs, operating systems, and compilers that have been around 4 times as long as any cryptocurrency I have literally no idea why you would feel safe in “smart contracts.” At least if my bank account is hacked, I have a solid legal standing for compensation and I have good reason to believe centralized financial institutions will keep extensive documentation and log…
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#265These incidents really illustrate the main flaw of smart contracts: a single bug in your code can lead to incredible losses. I simply don't think it's possible for human beings to write good enough software for smart contracts.
Human beings write software that flies people around the world and shuttles people between the Earth and space. Managing money is not more important than many things we use software for.
The incentives to break those other pieces of software are different.
Very few people are incentivized to hack planes to crash and kill people. Even fewer are incentivized to hack the space shuttle. Not to mention those pieces are rarely exposed on the public internet, or have connectivity at all.
But massive amounts of nigh-untraceable free money? Ton's of people are incentivized to go for that.
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#266These incidents really illustrate the main flaw of smart contracts: a single bug in your code can lead to incredible losses. I simply don't think it's possible for human beings to write good enough software for smart contracts.
The flip side of that is any smart contract that stood the test of time should be rock solid. For example, there are huge incentives to go ahead and hack a big contract like maker, compound, uniswap or aave, so you can bet that there's highly qualified people out there trying to hack them as we speak, yet after all this time, they are still working as intended. I have a lot more trust in that kind of product than in…
It's a fair point that any easy-to-find bugs in large, time-tested contracts will have been found. Any medium- or hard-to-find bugs also will probably have been found. But there might still be a very-hard-to-find bug lurking; and given the value of finding such a bug, people might look hard enough to find it.
In other words, the same scale that ensures there is no low-hanging fruit, also provides the incentive to pick high-hanging fruit.
> I have a lot more trust in that kind of product than in a product where contracts are subject to interpretations by humans which may or may not be reliable.
This is a valid concern, but it's also extremely well-understood at this point; we have centuries of global-scale experience with traditional financial and legal systems. They're certainly not flawless, but it's rare for gigantic new flaws to emerge. An important point is the existence of mechanisms for rolling back bad transactions and challenging / appealing flawed decisions.
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#267Earlier quoted context omitted.
> I simply don't think it's possible for human beings to write good enough software for smart contracts. I agree, but think it's fixable. I believe we have missed a natural platform in between binary notation and computer languages. I believe there is a 2-D dimensional binary. Simply using a grid (with an array of cells forming a line, and lines stacked on top of each other—a spreadsheet basically), we can drop *all*…
> I believe there is a 2-D dimensional binary. Simply using a grid (with an array of cells forming a line, and lines stacked on top of each other—a spreadsheet basically), we can drop all syntax characters. The only thing you have is your cells and your semantic words. I fail to see how this helps. The reason why bugs crop up all the time in software isn't because syntax is confusing. It's also not because semantics…
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#268Earlier quoted context omitted.
The flip side of that is any smart contract that stood the test of time should be rock solid. For example, there are huge incentives to go ahead and hack a big contract like maker, compound, uniswap or aave, so you can bet that there's highly qualified people out there trying to hack them as we speak, yet after all this time, they are still working as intended. I have a lot more trust in that kind of product than in…
This sounds like a fallacy of the inverse. Those contracts not being hacked yet is no proof that they are resistant to hacks.
From https://en.wikipedia.org/wiki/Confusion_of_the_inverse:
> Confusion of the inverse, also called the conditional probability fallacy or the inverse fallacy, is a logical fallacy whereupon a conditional probability is equated with its inverse; that is, given two events A and B, the probability of A happening given that B has happened is assumed to be about the same as the probability of B given A, when there is actually no evidence for this assumption.[1][2] More formally, P(A|B) is assumed to be approximately equal to P(B|A).
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#269Earlier quoted context omitted.
I dunno, it's not about wealth concentration, be rich, that's fine. It's about whether your wealth was gathered by contributing useful work, or by parasitizing it. I imagine a proof of work system where there's a community work queue, and "mining" is completing tasks in the queue, borderlands-style (though hopefully without the violence). The mined tokens can be resolved to nft's which stay attached to the wallet of…
The difficulty is that once you move from things like my joke solution to earnest attempts like yours you start involving the real world in your model, and you end up with something that is more like a social solution than a technological one. Once you start talking social solutions you start looking more like a business or a commune or a community and less like a technology. You don't just have algorithms and widget…
As for the botnet thing, I really like how CirclesUBI handles it. "Trust" is a pact to treat tokens minted for the other party as indistinguishable from tokens minted for yourself. So by all means, go simulate a small town doing "useful" work. Nobody is going to value the fruits of that labor unless they've seen them, and so your tokens will be worthless.
Once you have the base web of trust set up, you can layer other types of trust on top of it, like returns-borrowed-tools-undamaged trust and other things that lower the cost of doing business.
It's about using technology to take things that already work (cooperation) and make them work at scale (1000 people instead of 10). No need for global consistency, the resources are all local anyway.
As for being called a commune, that's fine. Communism allegedly doesn't work, so the idea that people might be doing this in tandem with traditional economics ought to be considered "not-a-threat" except in cases where traditional economics produces exceptionally troublesome outcomes.
Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
#270Earlier quoted context omitted.
I think the word „smart contract“ does not actually describe them very good. Of course, a piece of software can not replace a legal contract, really, because software is stupid and inflexible. Think of smart contracts rather as vending machines for financial transactions. For example: You enter some crypto coins, maybe select an option and the machine returns a receipt for redeeming your investment plus some interest…
In a very real way, those contracts are less smart than existing legal contracts. In the same way a "smart speaker" allows for interactive and sensitivity to its environment compared to a "dumb speaker", a "legal contract" allows for arguing and bugfixing and sensitivity to its environment compared to an block chain "contract". They should call them "strict contracts" or "inflexible contracts" or "software-enforced c…
It's more that they're just entirely separate things. Smart contracts are programmable money. Contracts are agreements between parties. The fact that you can use smart contracts to automatically take actions required by an actual contract is interesting and useful, but it's not enough to make the two comparable.