Live data from Hacker News

Zerocoin implementation bug

zcoin.io

141–142 of 142 posts

Re: Zerocoin implementation bug

#141
post #95

Earlier quoted context omitted.

In a way, they did actually prove that code is law - but they proved that "currently consensus-agreed-upon code is law." That old buggy code was law until the new code became law and changed the rules :). But of course its redundant to say "current code is law" because it's obvious by the logic of how consensus works. The confusion for people was their belief that code at one point in history would forever remain "th…

"code is law" and "currently consensus-agreed-upon code is law" are not the same though, not even close. One allows for human intervention and the other one doesn't. Moreover, consensus means that it's possible that >50% participants can one day to decide and take the money from the other participants. By declaring them hackers / evil / etc, for example. Which is basically what happened.

Yes, consensus does mean that the group "in power" can change the rules in ways that can harm those outside the consensus.

This is kind of scary, but on the other hand I think it won't be exercised in too strong a way - or at least in a way that harms a large number of people. The reason it won't happen is that aggressive moves that harm too many players threaten the whole game. So those in power have to consider whether their actions could ultimately undermine their own value, since the value is agreed upon by a larger market than just the people with consensus.

Now, if you have a pile of nerds with more interest in ego or "correctness" than in financial value, then wild changes can occur. I don't mean to suggest that's always a bad thing either. It's a bit like choosing when to evolve in a backward compatible way or when to make changes that are good for the long term but which annoy or frustrate some people in the short term.

For me, the takeaway of most interesting events in the blockchain world is that it's still quite young. There's a lot to learn, and it will take time to stabilize and become boring and reliable (or at least more predictable).

Re: Zerocoin implementation bug

#142

Earlier quoted context omitted.

Another major bug caused by copy+paste. I seem to remember a security researcher article months (years?) ago that identified this theme, showed a way to grep a codebase for likely c+p errors and found a load of bugs in real production code that had remained hidden for years. I think I landed there from HN, but my google-fu is failing me now, can anyone else remember it?

I want to know..

I went looking for this again today. It's not the article I was talking about, but you might find this interesting:

http://pages.cs.wisc.edu/~shanlu/paper/TSE-CPMiner.pdf

Post reply on HN