Live data from Hacker News

PeopleDAO “exploited” by Google Docs edit

twitter.com

61–70 of 87 posts

Re: PeopleDAO “exploited” by Google Docs edit

#61

I don’t browse much Twitter so maybe I’m just sheltered, but this is the first time I’ve scrolled down and seen extremely explicit pics (presumably spam to make people click). Is this normal or have twitters filters started to fail?

The first “recommended tweet” under the thread was some porn that I don’t even think is legal (hint: there was a dog involved). Posted 11 hours ago. I wonder what’s left of the content moderation team at Twitter.

Re: PeopleDAO “exploited” by Google Docs edit

#62

Earlier quoted context omitted.

I used to joke about how I was going to make my own shitcoin that was literally just that you could paypal me $10 and I'd add your name to a publicly viewable Google Sheet with your "coin" being that you'd own the row number. I did not realize that was actually how this operated.

Let people buy multiple cells and arbitrarily set the formatting and you basically have reinvented the million dollar homepage. https://en.wikipedia.org/wiki/The_Million_Dollar_Homepage Actually that would be a pretty neat NFT project. With each pixel having its RGB value and a link stored on chain, the entire image could be reconstructed without having to be hosted anywhere in specific.

You’re a couple years late on that idea: https://steemit.com/advertising/@shazow/the-million-dollar-h...

Re: PeopleDAO “exploited” by Google Docs edit

#63
post #4

I know this is a low value way of saying this, so, apologies up front but: Fucking lol at their bookkeeping and payout system just being a spreadsheet with no other comparison of truth before submission. We're on course for DAOs to rediscover the basic principles of our existing financial system within the decade.

Yeah, no, I agree with you. For other, less blatantly slipshod efforts, run by less blatant grifters, it might have been a faux pas to immediately point and laugh. Assume good-faith, and all that.

But for this? Cryptobros running bookkeeping over Google Docs and collaborating on their project via Discord? Crying to the FTC and FBI, the centralized arbiters their own model casts aside?

By all means, point and laugh. These people and their projects need crucified publicly. It's nothing personal. They were asking for it: this should be obvious, and it should be obvious why. If it's not, they need to find a new line of work.

Re: PeopleDAO “exploited” by Google Docs edit

#64
post #61

I don’t browse much Twitter so maybe I’m just sheltered, but this is the first time I’ve scrolled down and seen extremely explicit pics (presumably spam to make people click). Is this normal or have twitters filters started to fail?

The first “recommended tweet” under the thread was some porn that I don’t even think is legal (hint: there was a dog involved). Posted 11 hours ago. I wonder what’s left of the content moderation team at Twitter.

This is what I miss out on for running uBlock origin

Re: PeopleDAO “exploited” by Google Docs edit

#65
post #41

This is a beautiful example of the biggest current problem with DAOs and all (and I do mean ALL) crypto projects which aim to interface with the real world (i.e. all projects not doing with purely abstract stuff like DeFi-like tokens, and closed systems like "metaverses"): THEY CAN'T. They really cannot interface with the Real World, without leaking real-world problems into the "perfect" smart contract-driven crypto…

Hey, wait a minute.. those sound like really useful use cases for public transparency. So we just need folks to tag and shuttle these things into a blockchain, and present some kind of API to allow (data) mining it?

I don't understand why it should be a blockchain as opposed to some append-only log like the certificate transparency log?

Re: PeopleDAO “exploited” by Google Docs edit

#66

Earlier quoted context omitted.

Imagine the number of people who have ownership of business-critical documents in the cloud. Now imagine a venn diagram with the number of people who don't realize that granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity.

If the super long string on a Google doc is “security through obscurity”, so are passwords, 2FA codes, and ssh keys.

One persists in your browser history and is easy to copy/paste into the wrong place, the other is not (good luck copying a password field without technical workarounds such as changing the field type in the developer tools).

Re: PeopleDAO “exploited” by Google Docs edit

#68

Earlier quoted context omitted.

Hey, wait a minute.. those sound like really useful use cases for public transparency. So we just need folks to tag and shuttle these things into a blockchain, and present some kind of API to allow (data) mining it?

I don't understand why it should be a blockchain as opposed to some append-only log like the certificate transparency log?

Yes, admittedly it may just reduce to something that can be done with existing tech. Maybe it may not be implementation or execution, but adoption.

Re: PeopleDAO “exploited” by Google Docs edit

#70

What's a DAO?

The PeopleDAO is not a DAO, even though they claim themselves to be a DAO, because a DAO can't own title to property, and therefore can't own Ethereum that can be robbed. The PeopleDAO is a well-meaning club, not a DAO, that has a confusing and misleading name that owns title to property that is centralized, and therefore that property can be seized, and that property was seized.

An example of an actual DAO was last year's Genesis fractal experimental apparatus (links below). The PeopleDAO used an old-school spreadsheet accounting system (i.e. a Google spreadsheet), and there is nothing wrong with that. The Genesis fractal also used an old-school spreadsheet accounting system.

The same type of "theft" could have also happened to the Genesis fractal, i.e. stealing a password and editing an accounting spreadsheet. However, there was no Genesis property to steal. The Genesis fractal only had pure information stored in their spreadsheets and not title to property. The "theft error" would have been discovered eventually, just like the PeopleDAO discovered their "theft", but the Genesis fractal would simply need to re-edit their spreadsheet and not pursue the thief for the return of any property. This is a fundamental principle and feature of a DAO.

The PeopleDAO's fatal flaw was not understanding the principles of a DAO, meaning they did not understand the concept of decentralization and title to property.

The "PeopleDAO theft" is a wonderful case study for the benefits of a DAO and for the need for educational fractals like Genesis. Dan Larimer invented the concept of Decentralized Autonomous Organization and the word DAO, but it is poorly understood which is why we see heartbreaking theft stories like "the PeopleDAO theft" and the catastrophe surrounding Ethereum's "The DAO" (which was also not a DAO and suffered a similar fate as PeopleDAO). Ethereum's "The DAO" was a smart contract deployed to a "real" blockchain (i.e. it did not use a Google spreadsheet for accounting) but it still fell victim to an entirely predictable fate just like PeopleDAO - it held title to property.

The acid test of whether something is a DAO is determining whether the organization holds title to property. If the organization holds title to property, then it is not a DAO. There are many ways for an organization to use real property involving title (e.g. domain names, physical equipment like servers, land and equipment and anything other tangible, etc.)

If you know someone in the PeopleDAO, it would be well worth their while to read the following blog posts from Team fractally and to reach out to anyone on the Genesis fractal's leader board:

"What is a DAO?", February 20, 2022 https://fractally.com/blog/what-is-a-dao

"What is the Legal Standing of a DAO?", June 28, 2022 https://fractally.com/blog/what-is-the-legal-standing-of-a-d...

"Genesis Fractal Dashboard" https://share.streamlit.io/matt-langston/fractal_governance/...

Post reply on HN