Etherium's fundamental premise -- "code is law" -- presupposes a general solution to the formal verification of program correctness. This is an unsolved problem (and is likely unsolvable in the complete case). Put simply, all code has bugs. How can Etherium ever work in practice at scale?
Attempt to Reverse a $55 Million Ether Heist
111–120 of 194 posts
Re: Attempt to Reverse a $55 Million Ether Heist
#112Earlier quoted context omitted.
That's primarily because Ethereum is pure amateur hour. When Bitcoin had built in checksums on addresses, Eth Dev's just said "watch where you send money". They ended up having to later add in a capitalization scheme to serve as a hash. I have no clue how they managed to fool so many people with poor and shoddy work. But they have so far. And they've fooled everyone that this is a 'hack' even after saying time and ag…
The 't' vs 'T' has _nothing_ to do with checksums. `Transfer` and `transfer` are two different functions, one creating an "event" (think a signal on the blockchain) and the other actually transfering tokens. The true flaw lies in the reentrant attack on `.send()`
Re: Attempt to Reverse a $55 Million Ether Heist
#113This case feels so closely to the very interesting case of Aviva France[1], where a not "well-futureproofed" life insurance contract is making a person very rich by the day. Unfortunately for Aviva, their contracts are actually law in contrast to Ethereum where if the devs feel like it, they can do/revert anything. [1]: https://ftalphaville.ft.com/2015/02/27/2120422/meet-the-man-...
here's a link not behind a signup wall: http://www.independent.co.uk/news/business/news/max-herve-ge...
Re: Attempt to Reverse a $55 Million Ether Heist
#114This story really needs an ELI5
A guy came up with an idea of digital money that doesn't require contracts using "smart contracts", where the code is the law. The guy went to a bunch of people with the idea and they liked it. The people talked about it a lot and many more people joined in. They all pooled their money together to launch this cool money. Some other guy came over, saw all of this, looked at the code, and used the code to transfer $55M…
Re: Attempt to Reverse a $55 Million Ether Heist
#115Earlier quoted context omitted.
isn't it a bit disingenuous to say it was just the position of Ethereum founders? People wanted their money back. It's almost as if some recourse for actions done in bad faith is a useful tool to have as a society...
That's not what says https://www.ethereum.org/ > Ethereum is a decentralized platform that runs smart contracts: applications that run exactly as programmed without any possibility of downtime, censorship, fraud or third party interference.
"Without any possibility" - You'd think that'd raise a few red flags.
The probability that Ethereum will be subject to downtime, censorship, fraud, and third party interference is 1.
How can they have that on their landing page and keep a straight face?
Re: Attempt to Reverse a $55 Million Ether Heist
#116Thief? He strictly followed the terms of a contract by people who were very clear that "code is law" and who did not want institutions were the result is decided by human judgement.
Can we do an experiment and use 'she' for anonymous players in these stories? Would be kinda cool. The article uses 'he' throughout, and only acknowledges the possibility of it being either/or/group in the final paragraphs.
Re: Attempt to Reverse a $55 Million Ether Heist
#117Thief? He strictly followed the terms of a contract by people who were very clear that "code is law" and who did not want institutions were the result is decided by human judgement.
Can we do an experiment and use 'she' for anonymous players in these stories? Would be kinda cool. The article uses 'he' throughout, and only acknowledges the possibility of it being either/or/group in the final paragraphs.
Re: Attempt to Reverse a $55 Million Ether Heist
#118Earlier quoted context omitted.
The 't' vs 'T' has _nothing_ to do with checksums. `Transfer` and `transfer` are two different functions, one creating an "event" (think a signal on the blockchain) and the other actually transfering tokens. The true flaw lies in the reentrant attack on `.send()`
jesus christ, who the fuck would make two identical symbols differentiated by only capitalisation? (Other than these guys obviously)
Re: Attempt to Reverse a $55 Million Ether Heist
#119Etherium's fundamental premise -- "code is law" -- presupposes a general solution to the formal verification of program correctness. This is an unsolved problem (and is likely unsolvable in the complete case). Put simply, all code has bugs. How can Etherium ever work in practice at scale?
Aren't there a to of Bitcoin organizations with hundreds of millions of dollars flowing through them? If these companies found a way to operate safely with manageable risk, through things like cold storage and encryption schemes, than how is it much different from Ethereum?
It's fun to say things like "code is law" and imagine everything happens within this self-contained bubble but this stuff still operates in the real world and there are risks and consequences for actions as well as real world security mechanisms regardless.
Re: Attempt to Reverse a $55 Million Ether Heist
#120> ". Over email, he said, “We might be up the creek ;).” Later, when Gün pointed to the error in line 666, Daian replied, “Don’t think so.” well, isn't the financial law against this kind of incompetence in the first place? I don't think the thieves would be guiltier than the team behind DAO. ps: and line 666??? who the hell keeps a single source-code file that big? no wonder bugs are around...
Blockchain currency advocates like to claim that the law doesn't apply to them. Line 666 is an entertaining coincidence but that is really not that large a file for most languages.
Example? Or do you just mean like every financial organization ever (even beyond Wall St) that pushes back on regulatory oversight?
Attempting to regulate Ethereum with human gatekeepers sounds ridiculous to me, especially at this point, and entirely defeats the purpose of the whole system.
These people who put money into that DAO fully knew the risks of what they were doing. And none of them are calling for centralized oversight from the US gov as a result. So I'm not sure who this would be protecting or helping.