Live data from Hacker News

Smart Contract Security Field Guide

scsfg.io

131–140 of 156 posts

Re: Smart Contract Security Field Guide

#131

Smart contracts are fundamentally a business technology where money is hosted & manipulated natively on the platform. This is pretty awesome & could be very dirsuptive. The problem is at least in ecosystems such as Ethereum you have a single line of defense, your smart contract code. And that code is written in a poor language with very little security features. Worst if something go wrong you can maybe pause, suicid…

It's a misunderstanding that smart contracts are just about money. What you have in essence is decentralized verifiable computation, which can and often is used for finance stuff, but isn't limited to that at all.

> decentralized verifiable computation

Wasn't Ethereum centralized after switching to Proof-of-Stake?

Re: Smart Contract Security Field Guide

#132

Earlier quoted context omitted.

Who is providing the finance and under what terms? How does rhat actually differ from banks or one of the many microfinance services predating crypto? Now, the real kicker, what is the effective cost when _all_ fees are included, because someone has to pay for it and when combining the interest of non-traditional lenders and such fees I highly doubt it'll be cheaper.

These are collateralized loans that are automated with "smart" contracts. Programmable money. Who? Anyone who wants to provide liquidity. Is this different from existing solutions? Yes and no, the difference is that there is no human intervention here... you don't have to ask for permission. You're also dealing with a global pool of funds using open source technology, instead of just a single bank or service. The onl…

Who proves the collateral exists and is unfettered by existing contracts, specifically those provided through other platforms/existing mechanisms?

You see there is still a whole bunch of steps left out.

Re: Smart Contract Security Field Guide

#133
post #99
post #42

Earlier quoted context omitted.

Well, for the internet you could say “it allows stores to show pages with their products, and people can choose what they want to order, give their address and pay it with credit card , all without leaving their home” That’s a pretty obvious killer feature of the internet

Worth noting this wasn’t allowed on the early precursors to the internet. Also the credit card company and processor both take a fat cut and maybe deposit the money a few days later if they feel like it.

And eth fees are tiny?

And they'll get smaller as demand increases?

Don't worry I already know the answer to both is "No".

Ffs....

Re: Smart Contract Security Field Guide

#134
post #79

Earlier quoted context omitted.

Can you give examples of things which are "simply are complex and to say otherwise is to over-simplify them" and that are not either blockchain or snake oil? Note that internal operation does not really matter, only applications do; I might have no idea how CRISP/CAS works, but I can totally understand some of its applications and why people call it revolutionary.

Neuropsychopharmacology Medicine Higher level mathematics Material science Chemical engineering ... There are specialized journals for blockchain tech now. Maybe 'diverse' would be a better word than 'complex' for blockchain tech because projects aren't all financial. The OP made the claim that he couldn't think of use-cases for smart contracts. The problem isn't that there are no use-cases but that there are too man…

Every single one of those listed has a simple description of its use case.

Every, single, one.

Re: Smart Contract Security Field Guide

#135

Earlier quoted context omitted.

These are collateralized loans that are automated with "smart" contracts. Programmable money. Who? Anyone who wants to provide liquidity. Is this different from existing solutions? Yes and no, the difference is that there is no human intervention here... you don't have to ask for permission. You're also dealing with a global pool of funds using open source technology, instead of just a single bank or service. The onl…

Who proves the collateral exists and is unfettered by existing contracts, specifically those provided through other platforms/existing mechanisms? You see there is still a whole bunch of steps left out.

It is baked into the contracts and the way that the networks and protocols work. The general idea isn't super complicated though.

You have tokens, they sit in a wallet that you control. Let's say you own 10 ETH. Then that is in your wallet. Those ETH are mathematically provable to be in your wallet.

In the case of AAVE, you send your tokens to their contract, they give you back a receipt token which represents how much they owe you. Once your tokens are in their contract, you are free to borrow against the value that is locked up. If you get liquidated due to not maintaining your loan ratio, AAVE just keeps your tokens and your receipt tokens are then invalid.

There aren't any steps left out. It is really on you to read the documentation and bring some understanding around how all this works. I'll point you here: https://docs.aave.com/hub/

I googled and found another good article for you: https://www.leewayhertz.com/how-defi-lending-works/

Re: Smart Contract Security Field Guide

#136

Earlier quoted context omitted.

Who proves the collateral exists and is unfettered by existing contracts, specifically those provided through other platforms/existing mechanisms? You see there is still a whole bunch of steps left out.

It is baked into the contracts and the way that the networks and protocols work. The general idea isn't super complicated though. You have tokens, they sit in a wallet that you control. Let's say you own 10 ETH. Then that is in your wallet. Those ETH are mathematically provable to be in your wallet. In the case of AAVE, you send your tokens to their contract, they give you back a receipt token which represents how mu…

Just ignored my questions to give the standard allusions rants....

"proves the collateral exists" means who validates the asset doesn't have a standard run of the mill contract/lien/etc?

Just answer that, and _actually_ answer it (the site sure doesn't in any reasonable nor concise manner) and we'll go from there.

Re: Smart Contract Security Field Guide

#137

Earlier quoted context omitted.

It is baked into the contracts and the way that the networks and protocols work. The general idea isn't super complicated though. You have tokens, they sit in a wallet that you control. Let's say you own 10 ETH. Then that is in your wallet. Those ETH are mathematically provable to be in your wallet. In the case of AAVE, you send your tokens to their contract, they give you back a receipt token which represents how mu…

Just ignored my questions to give the standard allusions rants.... "proves the collateral exists" means who validates the asset doesn't have a standard run of the mill contract/lien/etc? Just answer that, and _actually_ answer it (the site sure doesn't in any reasonable nor concise manner) and we'll go from there.

> standard allusions rants

Oh, I see, you just want a hostile battle and don't want to do any sort of actual conversation around knowledge you refuse to learn on your own.

> "proves the collateral exists" means who validates the asset doesn't have a standard run of the mill contract/lien/etc?

I don't understand this line at all.

Re: Smart Contract Security Field Guide

#138

Earlier quoted context omitted.

Just ignored my questions to give the standard allusions rants.... "proves the collateral exists" means who validates the asset doesn't have a standard run of the mill contract/lien/etc? Just answer that, and _actually_ answer it (the site sure doesn't in any reasonable nor concise manner) and we'll go from there.

> standard allusions rants Oh, I see, you just want a hostile battle and don't want to do any sort of actual conversation around knowledge you refuse to learn on your own. > "proves the collateral exists" means who validates the asset doesn't have a standard run of the mill contract/lien/etc? I don't understand this line at all.

Making a vague reference to something isn't an answer, nor is a random link and a "look here", especially when the link doesn't provide the answer.

And the fact you don't understand that line is the proof you don't know enough about traditional contracts to be able to compare them to smart contracts.

Seriously.... you've just done more to prove to me that you crypto folks are generally just ignorant of real world issues.

Re: Smart Contract Security Field Guide

#139

Earlier quoted context omitted.

> standard allusions rants Oh, I see, you just want a hostile battle and don't want to do any sort of actual conversation around knowledge you refuse to learn on your own. > "proves the collateral exists" means who validates the asset doesn't have a standard run of the mill contract/lien/etc? I don't understand this line at all.

Making a vague reference to something isn't an answer, nor is a random link and a "look here", especially when the link doesn't provide the answer. And the fact you don't understand that line is the proof you don't know enough about traditional contracts to be able to compare them to smart contracts. Seriously.... you've just done more to prove to me that you crypto folks are generally just ignorant of real world iss…

> you've just done more to prove to me that you crypto folks are generally just ignorant of real world issues.

I didn't know I was supposed to "prove" anything to you or handhold you on reading even the basics of the available documentation. All I have to say is your loss for not making the effort on your own and being so negative and combative. Good luck sir.

Re: Smart Contract Security Field Guide

#140

Earlier quoted context omitted.

Making a vague reference to something isn't an answer, nor is a random link and a "look here", especially when the link doesn't provide the answer. And the fact you don't understand that line is the proof you don't know enough about traditional contracts to be able to compare them to smart contracts. Seriously.... you've just done more to prove to me that you crypto folks are generally just ignorant of real world iss…

> you've just done more to prove to me that you crypto folks are generally just ignorant of real world issues. I didn't know I was supposed to "prove" anything to you or handhold you on reading even the basics of the available documentation. All I have to say is your loss for not making the effort on your own and being so negative and combative. Good luck sir.

Just more deflections and allusions.

https://www.lawinsider.com/dictionary/encumbrance

Educate yourself.

Post reply on HN