Live data from Hacker News

Critical Update on DAO Vulnerability

blog.ethereum.org

151–160 of 629 posts

Re: Critical Update on DAO Vulnerability

#151
post #96

Earlier quoted context omitted.

Doesn't this show an issue with the Distributed Systems on Ethereum, with every script that has to be audited individually, and not with the platform itself? I'm with you on the fact that proper auditing is an absolute must, as this DAO fiasco shows, but I don't think this event exposes any flaws in the Ethereum platform itself.

Agreed - this is a problem with the DAO, not with the ethereum network itself.

It seems that we need formal verification for smart contracts and maybe a more restricted language that makes it easier to reason about correctness.

Obviously it's not enough to just say "some guys did a security audit and everything looks fine."

Re: Critical Update on DAO Vulnerability

#153
I see a lot of confusion mixed with the good old HN hate for crypto which is justifiable but just to be clear, the breach was with a single piece of software written on the Ethereum network (the DAO). Not a vulnerability with Ethereum. The eth that is locked is the funds that were paid to that contract (TheDAO), not the network's funds.

Re: Critical Update on DAO Vulnerability

#154

I started archiving the slock.it #general slack channel when this attack began. This is where most of the discussion has been taking place. Here's up until a few minutes ago: http://pastebin.com/DykumjLs

Fantastic entertainment right there, thanks for creating this..

So much self importance mixed with faux understanding of technology and a dash of desperate desire to belong to a special group.

On a more positive note, my bitcoin wallet is rapidly approaching steak dinner territory as of last month. It's the little things in life!

Re: Critical Update on DAO Vulnerability

#155
post #142

Earlier quoted context omitted.

Huh? What does halting trading has to do with compromising decentralization? You do know what "decentralization" mean right?

They're now talking about essentially blacklisting the hacker's ETH address, how is that decentralised? Halting trading is a show of force too, if they believed a single thing of what they preach they'd let the free market continue its course with the hacker walking away with the money. Looking at your comment history it seems clear you have an agenda here, so I'll ignore the ad hominem.

Decentralization doesn't mean complete lack of central control, or anarchy, it means that balance of power is in the periphery with the broader organization largely controlled by protocol and policy. Issuing an edict in a crisis doesn't necessarily imply centralization if the member nodes can ignore the edict.

In the history of organization structures, for example, Peter Drucker in 1946 wrote the "Concept of the Corporation", a study on General Motors, which was arguably one of the early detailed studies of Decentralized governance in an organization.

Re: Critical Update on DAO Vulnerability

#157
post #115

Well, that was kind of inevitable. Building a financial system out of pure code with no humans in the loop and no legal structure is building a self-distributing bug bounty piñata. It's decentralised, so there's nobody who can throw a breaker and shout "stop!"; cryptocurrency transactions are irreversible, so thefts are permanent; and it's somewhat anonymous, so thefts are hard to trace. It also demonstrates that bei…

Exactly what I was thinking.

If they had some sort of fraud-related authorized structure, which was able to "reverse" the result of an obvious software bug, I would say that it should've been much more stable financial system.

Re: Critical Update on DAO Vulnerability

#158
post #138

Earlier quoted context omitted.

So can random people who agree with each other completely control everything that happens with the currency? So if there is a company who they dislike can they just decide that they have no money?

Majority of ethereum holders would want to rollback. That is consensus. If they don't hard fork they can keep running an old node. What is the problem?

Majority is consensus?

Re: Critical Update on DAO Vulnerability

#159

developer asks token holders to spam the network to delay the attack o.O griff [10:05 AM] @channel The DAO is being attacked. It has been going on for 3-4 hours, it is draining ETH at a rapid rate. This is not a drill. You can help: If anyone knows who has the split proposals Congo Split, Beer Split and FUN-SPLT-42, please DM me We need their help! If you want to help, you can vote yes on those aforementioned split p…

Quick! Create a GUI interface using Visual Basic. See if I can track an IP address.

Re: Critical Update on DAO Vulnerability

#160

Earlier quoted context omitted.

If there is network consensus to do the rollback, then the blockchain stays decentralised.

What is 'network consensus'? It certainly isn't giving everyone a vote as to whether they think the rollback is a good idea or not. Instead, it's connected people wielding influence.

Connected people always have influence in any human system, because, you know, emotions.
Post reply on HN