Live data from Hacker News

PeopleDAO “exploited” by Google Docs edit

twitter.com

31–40 of 87 posts

Re: PeopleDAO “exploited” by Google Docs edit

#31
post #4

I know this is a low value way of saying this, so, apologies up front but: Fucking lol at their bookkeeping and payout system just being a spreadsheet with no other comparison of truth before submission. We're on course for DAOs to rediscover the basic principles of our existing financial system within the decade.

This feels like the financial version of, “front end feels too complicated. Let’s make it simple.” And then they re-discover all the hard fought lessons one by one until their framework is complicated too.

Re: PeopleDAO “exploited” by Google Docs edit

#32
post #20

Earlier quoted context omitted.

Imagine the number of people who have ownership of business-critical documents in the cloud. Now imagine a venn diagram with the number of people who don't realize that granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity.

> granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity. That's like saying passwords are "security through obscurity" because they're also "obscure" random strings, just like URLs. To try and make my point more clear: Basic auth password url: https://username:randomSecurePassword@webpage.com Google docs edit url: https://docs.google.com/randomLongString/edit How are…

This is about Google docs. In Google docs access control means not just knowing password and username combo, it also means having the device to receive a time limited 2FA code etc. Plus the ability to revoke access. Very much not just obscurity.

Re: PeopleDAO “exploited” by Google Docs edit

#33
post #20

Earlier quoted context omitted.

Imagine the number of people who have ownership of business-critical documents in the cloud. Now imagine a venn diagram with the number of people who don't realize that granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity.

> granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity. That's like saying passwords are "security through obscurity" because they're also "obscure" random strings, just like URLs. To try and make my point more clear: Basic auth password url: https://username:randomSecurePassword@webpage.com Google docs edit url: https://docs.google.com/randomLongString/edit How are…

If people are sharing the links including the basic auth embedded, not much. However it splits the problem into two halves. One part deals with auth, one part deals with the identity of the resource. So you can have different auth, or change the auth, without changing the URL.

In practice, the most important difference between those is about what gets copied when someone shares a link. If the only possible option is to share it with the authentication embedded, you're kind of screwed. I don't think browsers expose the basic auth when you copy and paste from your url bar though.

Re: PeopleDAO “exploited” by Google Docs edit

#35
post #26

So people want to be progressive and use cryptocurrency that is not tied to a government. But when things go wrong they run to the FBI and FTC both run by the government.

If you use google sheets and discord to run your org then it's pretty clear you are not in it for the decentralization. Is it money? Or is it the cool mystique of these emerging technologies? I don't know.

It’s for the people! It says so right in the name!

Re: PeopleDAO “exploited” by Google Docs edit

#36

Hilarious. DAO stands for "decentralized autonomous organization." This thing appears to collect transactions via a centralized google form and then complete those transactions if 5 of 9 people vote to perform them. Neither decentralized nor autonomous. You go through all this effort to establish something fancy using whatever hot defi thing exists but situate it on top of a google form and a spreadsheet just owned b…

I agree that the lessons learned is weak. The solution to a systemic failure like this can not be that everyone involved should try harder and be more careful. A solution is needed that addresses the weakness of the system.

How about a solution where the approvers need to forfeit a significant amount into escrow accounts to cover losses and receive a portion of the payout for their efforts and investment. Any payout would be systemically limited to the total amount held in escrow.

Writing this I realize that this perfectly describes a traditional financial institution. Not such a radically new idea.

Re: PeopleDAO “exploited” by Google Docs edit

#37
post #4

I know this is a low value way of saying this, so, apologies up front but: Fucking lol at their bookkeeping and payout system just being a spreadsheet with no other comparison of truth before submission. We're on course for DAOs to rediscover the basic principles of our existing financial system within the decade.

And if you take the process to its conclusion people will say we’re tired of doing all this accounting all the time, let’s hire a specialized person to do that - and you’ll end up with a company accountant. After that they’ll say he we should standardize the accounting process over different organizations and end up where we are now

And then add an organization to double check the accounting numbers to validate if they are correct.

Re: PeopleDAO “exploited” by Google Docs edit

#40
post #4

I know this is a low value way of saying this, so, apologies up front but: Fucking lol at their bookkeeping and payout system just being a spreadsheet with no other comparison of truth before submission. We're on course for DAOs to rediscover the basic principles of our existing financial system within the decade.

This feels like the financial version of, “front end feels too complicated. Let’s make it simple.” And then they re-discover all the hard fought lessons one by one until their framework is complicated too.

Exactly. Or young people coming out of college having this adorably naïve, idealistic world view where everything fits nearly into their world view. Then they live some, experience things that don't fit so neatly, and begin to acknowledge the complexity of the world, becoming more pragmatist politically.

At least that was my experience of 20->30. I can't even think of a long sentence that encapsulates my world view anymore, let alone a single word like "conservative", "anarchist" or whatever.

When I was 20 I could have easily done so.

Post reply on HN