Live data from Hacker News

The Web3 Fraud

usenix.org

331–340 of 377 posts

Re: The Web3 Fraud

#331

Earlier quoted context omitted.

Given that you can deploy smart contracts as binaries (without source) and you can design the contracts to be upgradeable if needed, I don’t see any advantages of this system. Sure, the contract can be immutable but the only advantage is for the archivist who now has a permanent record of the software history. Other than a public change log, this doesn’t have much utility.

It's up to you to decide how much control over your smart contract and it's assets you want to put into who's hands. It reasonable that the EVM would want to account for a wide range of use-cases. The point is simply to be able to make certain immutability guarantees, if you do want them. The utility is very evident in that something like a Uniswap pool a) works and b) cannot be stopped, so people who do find a Unisw…

It seems you’re talking from the developer’s point of view, the person who writes and deploys smart contracts. I am coming from the end user’s point of view, who has very little to gain from the immutability guarantees.

For Uniswap pools, you’re referring to smart contracts that allow people to take out or provide funding for loans, right? So the immutability of the contract may be appealing in terms of interest rates or loan duration/terms/etc. But this option already exists outside of DeFi (fixed rate loans). It is cool that we can offer these in a decentralized manner, but the possibility of a bug affecting my mortgage or another sizable loan is a huge, huge deterrent and I am also sure that, if DeFi “takes off,” there will be solutions implemented that completely remove all immutability guarantees.

Re: The Web3 Fraud

#332

Earlier quoted context omitted.

The point I am making is every smart contract is Schrodinger’s contract where the user has no idea what is inside and no way to know. Say you have a game called, I don’t know, Crypto Run. To purchase in game assets, the developers of Crypto Run deployed a smart contract that lets players do this. You have to use the smart contract from the developers and even if alternatives exist, people want to use the official con…

> The point I am making is every smart contract is Schrodinger’s contract where the user has no idea what is inside and no way to know. I literally explained a few comments ago how that's not the case. Did you forget what you read already? https://news.ycombinator.com/item?id=29588550

The contract developer releasing the code is the problem, not verifying that is what is running. When a company open sources some code, we assume and trust they are not keeping a separate, evil branch running in production unbeknownst to us. If Facebook “open-sourced” their entire platform and infrastructure tomorrow, the hard part is not verifying that this code is what is running. The hard part would be getting Facebook to do this in the first place. Your use case (of the developer open sourcing their code already) is not the hard part.

Re: The Web3 Fraud

#333
post #13

Many criticisms of blockchain apps, comparing their use cases to conventional technologies (databases, conventional separation of services such as that described in the article, etc) all seem to miss a major point: Dapps running on the blockchain are immutable and highly resistant to being shutdown. Immutability is important because it's guaranteed that no matter how many times you interact with a contract address, y…

Unless there is a killer feature it enables, it's an implementation detail and I don't care. And I will gladly compare other solutions against blockchain despite not having the same implementation detail you claim puts it above comparison. And so will everyone else that isn't blinded by fanaticism.

It's an implementation detail, right. But in most cases, it's implemented as immutable. With some exceptions, but developers are very upfront about that in those cases.

But even if developers implemented their contract with the possibility of updating, the most important detail here is that only those developers can do that.

Not AWS, not Apple, not Google, etc.

Re: The Web3 Fraud

#334

Earlier quoted context omitted.

> Trade blockchain tokens for other blockchain tokens. Or trade blockchain tokens for tokens that claim (with dubious, temporary and totally non-cryptographic evidence) to be backed by something else. The Perth Mint is "dubious" and "temporary" to you? If you dislike examples of assets backed by centralized entities, then look at decentralized algorithmic stablecoins. > - Lend and borrow blockchain tokens. Yes, inclu…

Yes, it's temporary, in the sense that even tokens backed today might not necessarily be backed tomorrow. And yes, it is actually a surprisingly dubious organization (that corporations fully owned by a state and performing some minor official service for it, can still be extremely dodgy, should not come as a surprise). They seem to be profiting off the assumption that from the name, they would be as tightly controlle…

> They seem to be profiting off the assumption that from the name, they would be as tightly controlled as a central bank. But it's very clear from dodgy stuff they've already been involved in, that they're absolutely not.

Alright, then don't trade in their token. Or short it, if you think it's going to collapse in value anytime soon.

> But of course, I wasn't first and foremost talking about them, I was talking about the 800 dollar gorilla, Tether. They're now where Mt Gox was ca. mid-2013, with "everyone" knowing they're extremely dodgy and likely to collapse, but hoping to make money off those who haven't realized it yet.

Well yes, the whole point of a decentralized ecosystem is that it gives people the freedom to do things without government stepping in and telling them no, for better or for worse. Tether is free to print as much Tether as they want, and everyone else is free to hold or not hold USDT if they want. Caveat emptor.

> As to "tracking" real world assets, that mechanism of tracking is a weak point, rendering all the other "guarantees" moot.

Sure, that is still a centralized point of failure. But the other decentralized benefits still hold. No government sanctions can prevent you from buying this gold-backed crypto, if you so wish. Or if you have it already, from selling it for something else. Nobody to enforce pattern day trading rules on you. For better or for worse, it still gives you all the benefits that decentralization entails.

> So is other fraud. Doesn't mean it isn't money out the window.

It's money circulating through a different part of the economy than it would've otherwise. It's valuable to the people participating in it. Not to you, obviously. To other people.

> For that matter, you don't know how much of the economic activity is real.

Of course, that's the whole point. But you can still make educated guessing. Looking at the size of various illicit businesses, money laundering is obviously a billion dollar global industry. Why? Because a lot of people find it valuable. Not you, obviously. Other people.

Re: The Web3 Fraud

#335
post #221

Earlier quoted context omitted.

BitTorrent is a terrible file distribution mechanism. I can't think of a single instance where I have had better performance downloading a torrent than a simple FTP/HTTP transfer or video stream from a web server or CDN.

Resilio Sync for Business worked way better for us than Dropbox and OneDrive with their CDN.

Were your use cases intra- or inter-organizational?

Re: The Web3 Fraud

#336

Earlier quoted context omitted.

As my post was one of the first in this these threads, the topic had not yet gotten divisive. Moreover, my comment about moderation did not regard my comment but regarded the parent comment, which I felt made a substantive contribution and got downvoted for it for, I am guessing, ideological reasons.

Thanks, anyways. Ironic that they effectively "censored" my comment rather than engage with it. Prompts a few thoughts for me: (1) coming to HN is like time-traveling ~10 years back, (2) HN today reminds of the late stages of after slashdot, digg, etc. peaked, and (3) decentralized projects have real incentives with "points" that mean something, so losing some silly HN points to moderation seems more meaningless than…

Your comment (assuming you mean https://news.ycombinator.com/item?id=29587769) has in no way been "censored".

Re: The Web3 Fraud

#337
post #274
post #240

Earlier quoted context omitted.

If you just want to store and host files like a website, there's a few projects in that vein that I know of - Arweave ( https://www.arweave.org/ ), IPFS ( https://ipfs.io/ ), and Filecoin ( https://filecoin.io/ ). IMO these projects are aiming at a new form of sovereignty on the internet that doesn't/can't exist currently - the ability to have your data be permanently stored and accessible on the web. Google can deci…

Resources like storage and bandwidth aren’t free. People won’t pay to host strangers content for free forever, especially with the personal legal risk that entails, so you’re going to need to pay regularly to host content which isn’t both very popular and under an open license, which is the content which is most reliably replicated now at much lower cost. Similarly, there’s a lot of mythology about content not being…

Sure, I generally think of these projects as experiments to try to make this “store something permanently” vision happen in reality. Just because the vision has hurdles to overcome doesn’t mean it’s not worth trying. Arguably GitHub’s Arctic Code Vault aimed to do the same thing in a different way https://archiveprogram.github.com/. I agree that the tail end support of bandwidth and storage costs for X years are obstacles for this vision but blockchains in their current form already incentivize keeping this data around and hosting the data as part of normal network operations. These projects are just trying to separate out the storage layer from the computation layer (which may be a folly, or may prove viable). The point is that there’s groups of people trying to apply these new tools in novel ways to try to give humanity better tools in some capacity, and I think that’s a fine use of resources and effort.

Have you heard of the uncensorable library project? https://www.uncensoredlibrary.com/en it aims to make some data permanent and available even in the face of Chinese censorship. Is it a panacea that’s going to scale for all data forever? Of course not, but it’s a novel approach and an interesting experiment (and look ma, no blockchain!).

Re: The Web3 Fraud

#338

Earlier quoted context omitted.

> The point I am making is every smart contract is Schrodinger’s contract where the user has no idea what is inside and no way to know. I literally explained a few comments ago how that's not the case. Did you forget what you read already? https://news.ycombinator.com/item?id=29588550

The contract developer releasing the code is the problem, not verifying that is what is running. When a company open sources some code, we assume and trust they are not keeping a separate, evil branch running in production unbeknownst to us. If Facebook “open-sourced” their entire platform and infrastructure tomorrow, the hard part is not verifying that this code is what is running. The hard part would be getting Fac…

[deleted]

Re: The Web3 Fraud

#339

Earlier quoted context omitted.

> The point I am making is every smart contract is Schrodinger’s contract where the user has no idea what is inside and no way to know. I literally explained a few comments ago how that's not the case. Did you forget what you read already? https://news.ycombinator.com/item?id=29588550

The contract developer releasing the code is the problem, not verifying that is what is running. When a company open sources some code, we assume and trust they are not keeping a separate, evil branch running in production unbeknownst to us. If Facebook “open-sourced” their entire platform and infrastructure tomorrow, the hard part is not verifying that this code is what is running. The hard part would be getting Fac…

> The contract developer releasing the code is the problem, not verifying that is what is running.

In a trustless environment like defi, why would anyone other than the most gullible put their money in any smart contract that doesn't have open sourced code?

> When a company open sources some code, we assume and trust they are not keeping a separate, evil branch running in production unbeknownst to us.

We assume and trust because we have to. With crypto, you can trust and verify, as the Russians say.

Re: The Web3 Fraud

#340

Earlier quoted context omitted.

> Any solution for a given use case can and should get compared with other solutions for that use case. And the current use cases are sufficiently different that it's like comparing apples and oranges. > I'm really sorry that it doesn't seem (judging by this thread) to compare particularly well for most developers, but that doesn't invalidate the comparison. Again, do you think the same of Tor? It doesn't compare par…

"And the current use cases are sufficiently different that it's like comparing apples and oranges." Uh, what? This whole thread and post is about the argument that replacing existing apps with dapps will be better (or worse).

No, this particular thread started by v64 is precisely that comparing existing apps on the regular web to dapps is comparing apples and oranges. The use cases and guarantees are pretty darn different.
Post reply on HN