Live data from Hacker News

A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

medium.freecodecamp.org

181–190 of 440 posts

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#181

Earlier quoted context omitted.

> Next time, I'm going to use this case as a counterexample, because when the solution to the problem of "hackers robbing banks" is "vigilantes robbing the remaining banks", something is very wrong with your system I can see what you're saying, but I don't think that this is a problem with cryptocurrencies specifically , it's a problem with buggy software, yes, but it's something that is the case with every dangerous…

This is a problem that everybody seems to skip over with cryptocurrencies. Cryptocurrencies are being sold as eliminating trust and allow us to rely on the cold certainty of mathematics. Only trust hasn't been eliminated from the system, it's just been shifted from a central bank to the authors of the software client you're using. To the majority of the miners in the network. The awful politics, lies, greed, corrupti…

Much worse in fact, since the entities in power have no oversight, were not elected, and have no obligation to anything but increasing their own personal wealth.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#182

Earlier quoted context omitted.

> The world is larger than just your own country. Not too much larger, considering that every major company and country has large amounts of assets and other financial interests that are subject to US jurisdiction. The government of Argentina recently learned that the hard way when American courts forced them to honor their sovereign debt, or have their US-based assets seized to pay them. The same applies if you want…

Look, once more: I'm not saying smart contracts work at present. But if they work then judges would be without tools to do anything about it, that's a matter of definition, if you choose to define a smart contract in a way that does not agree with how the rest of the world views them then that's fine with me but it voids the discussion. Any contract that has all the outward aspects of being a smart contract but that…

so the scope of smart contract in your definition can only cover areas not already governed by traditional regulatory system / laws. Imho that doesn't cover a lot.

or laws will have to be adapted to grant values to them. But then it isn't much different from today's contracts.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#183
What's the fairest distribution of the recovered white-hat funds:

- return them exactly as they were, with the unlucky people completely losing funds

- distribute them back among everyone based on the % of total funds that were in their wallets

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#184
post #144

Earlier quoted context omitted.

> Well, what's the point of having a smart contract if it's not the final authority? I think this is a common misunderstanding of Ethereum and blockchains in general. The current Ethereum blockchain is authoritative only as long as a majority of it users consider it to be authoritative. The same applies to Bitcoin. No single person decided to fork Ethereum after the DAO was hacked, it was decided by a quorum of Ether…

You are making the argument that if, say, you've made a bunch of ethereum through means that the majority of miners don't like, they can just fork the currency and take your coins from you, and that's totally fine.

I don't know enough about Ethereum to know whether or not that is technically possible, but I believe it's technically possible with Bitcoin. I think the common misconception of these technologies is that trust is eliminated. It's not, it's simply distributed - you have to trust that the majority miners will find it in their own interests not to steal money from your wallet. I am not saying one way or another whether this state of affairs is 'fine', just pointing out the reality.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#185

Earlier quoted context omitted.

> something is very wrong with your system To be clear, neither of the two situations is "more moral" than the other. In the end however, the question remains: who you trust. Governments have resolved the question long ago (by enforcing trust), cryptocurrencies are just now starting to face the same question. You are correct however that who you Trust remains the greatest issue behind creating a currency.

Look, no. One hundred times, no. Governments in the west are quite accountable, voted for and with a system of checks and balances that has evolved over time, through wars and revolutions. Some random benevolents overlords (white-hat hackers) that save you just because they are magnanimous was the only option only in the most primive societies. Thankfully we moved on from those times, don't you agree?

[deleted]

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#186

> Having sounded the alarm bells, a group of benevolent white-hat hackers from the Ethereum community rapidly organized. They analyzed the attack and realized that there was no way to reverse the thefts, yet many more wallets were vulnerable. Time was of the essence, so they saw only one available option: hack the remaining wallets before the attacker did. > By exploiting the same vulnerability, the white-hats hacked…

You could say the same thing about home routers with that argument then, which are often under patched, and apparently require grey hats to act. http://www.computerworld.com/article/2988656/network-securit...

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#187
post #175

Earlier quoted context omitted.

You still don't get it. The law will not have anything to say about smart contracts because the law will not be able to enforce a contract one way or another depending on some judge but it will simply execute and that's the end of that . This so that some guy in China or India and some guy in the United States can agree on terms without having to haggle over whose legal jurisdiction will kick in if and when there is…

The "contract execution" can't touch anything in the real world. People do that. Maybe a "smart contract" says Joe Hacker is entitled to reside in 168 Park Avenue. Maybe everyone on the Ethereum blockchain agrees that Joe is entitled to reside in 168 Park Avenue. If a judge rules that it's Bob's house and Joe has no right to be there, that's gonna trump all of that, if only because the judge has more people with guns…

The contract execution is only going to work if all parties bound by it agree that the execution is the full extent of their agreement.

For instance, if two people who have no business to reside in 168 Park Avenue make up a contract in 'the real world' that the other can go and occupy 168 Park Avenue then they will find - probably not to their surprise - that their agreement will not work, regardless of which medium it is conveyed on.

Smart contracts are a tool for those situations where you believe present day law is going to leave you stranded or in a situation that is legally ambiguous. I do not believe their strength lies in areas that are already properly governed by existing law.

Now you could argue that that is all of society as we know it right now, but in international commerce there are quite a few legally gray areas that are now patched over with mechanisms such as escrow and various other instruments. But those are only 'worth it' when the transaction amounts are larger than a certain minimum.

So, in short, you are absolutely right, if you use a smart contract in a situation where a regular contract would suffice it will not change anything. All the parties to the contract are known, the whole thing has immediately verifiable effects in the real world and 'might makes right'.

But in situations where the participants would like to remain anonymous, in situations where both parties would for reasons known to them rather avoid dealing with lawyers, the law and associated mechanisms smart contracts could become an enabling device.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#188
post #159
post #36

Earlier quoted context omitted.

"Is there really such a thing as "unbreakable cryptography"?" Yes. One time pads are unbreakable. "Even after the aliens from Andromeda land with their massive spaceships and undreamed-of computing power, they will not be able to read the Soviet spy messages encrypted with one-time pads (unless they can also go back in time and get the one-time pads)." (Bruce Schneier, Applied Cryptography)

Are these the same one time pads that have already been cracked by the NSA after the Soviets reused them?

If you reuse them, then it's not a one time pad any more, is it?

Yes, it's well known that two-time pads are very vulnerable in ways that one time pads are not.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#189

I think the fundamental problem here is an economic one. Make three assumptions: 1) most contracts worth implementing in Ethereum are fairly complex 2) even given great developers, bugs are inevitable in complex code 3) the budget of the contract-makers' security team MUST be smaller than that of the hackers You quickly see that if the chance of a bug is nonzero, "smart contracts" don't make economic sense. If you ha…

One way to help mitigate that is by tiering releases. Rather than deploying an app that can potentially accept millions of dollars on day 1, it can be purposely limited to lower amounts and slowly increased over time as the codebase is iterated and time-tested. Apps that have been around for decades with few changes are significantly safer than new apps. Of course this is not perfect (ie heartbleed) but I think this methodology will become standard in ethereum.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#190

Earlier quoted context omitted.

It's not about whether or not it should, I'd be happier living in a world where they can be, but since the whole goal is that it can't and there are people working really hard on trying to achieve that goal it would be more realistic to adjust to the eventuality that it will at some point be done. The biggest stick that governments have is that they could make it illegal for their constituents to engage in smart cont…

Smart contracts are not laws of nature, they are contracts. I totally agree you could come up with a few examples where enforceability would be a practical impossibility, but that's also the case with standard contracts. Just like the Arizona law I cited restricting use of smart contracts for "fire arm tracking", the law could restrict smart contracts in all sorts of ways to protect the public. Examples: -drafters of…

> Smart contracts are not laws of nature, they are contracts.

No, they are software. And the participants to such a contract have agreed that the execution of that software is the entirety of their transaction. If one of the parties changes their mind after the fact they will have to convince a judge first that even though they initially agreed that the execution of the contract was the entirety of the agreement that now this is no longer the case and that what they said was un-ambiguous before is now ambiguous and needs overriding.

So now you have a fairly complex situation:

- you will have to convince the judge that you entered into that contract and now wish to back out of the defining clause on something that is not classed as 'regret' (which is never a reason to annul a contract)

- you will have to find a way to communicate the judge what relief you feel will compensate you at a level that the judge will be able to enforce (this could be very difficult)

- and on top of that you will have all the usual issues you have to deal with in a lawsuit possibly complicated by your counterparty being anonymous and/or in an entirely different jurisdiction

States don't really matter here, smart contracts are software and are global, that changes their nature in a material way which will make it hard (possibly impossible) for a judge to enforce them one way or the other.

Post reply on HN