Live data from Hacker News

The Web3 Fraud

usenix.org

261–270 of 377 posts

Re: The Web3 Fraud

#261

Earlier quoted context omitted.

There are easy mitigations for those things though. My self hosted apps run on immutable infrastructure and are replicated and load balanced. Still stupid cheap and easy.

> My self hosted apps run on immutable infrastructure and are replicated and load balanced What? Assuming you live in the US, the government can swoop in at any time (provided they have a legal reason to do so) and demand that AWS or whoever's hosting your servers shuts them down. If you're hosting them yourself, they can raid the physical locations where you host them. If you're not in the US, I'm sure your country…

> Good luck raiding every single Ethereum node in the world to take down a smart contract.

They won't have to. It's like putting absurd security on your door yet leaving the windows as open as always.

If you ever want to move value out of your virtual economy and into the real, they can and will be there waiting for you, with all their unreasonable demands.

Re: The Web3 Fraud

#262

Earlier quoted context omitted.

> Even Ethereum smart contracts do not actually guarantee the compiled byte code matches the supposed source of the contract What? You don't have to publish your smart contract code for the public to verify, but you absolutely can. And once you do, the public can absolutely verify that the smart contract code you provided does in fact compile to the byte code deployed to the blockchain. > and then we’re right back wh…

Given that you can deploy smart contracts as binaries (without source) and you can design the contracts to be upgradeable if needed, I don’t see any advantages of this system. Sure, the contract can be immutable but the only advantage is for the archivist who now has a permanent record of the software history. Other than a public change log, this doesn’t have much utility.

It's up to you to decide how much control over your smart contract and it's assets you want to put into who's hands. It reasonable that the EVM would want to account for a wide range of use-cases.

The point is simply to be able to make certain immutability guarantees, if you do want them. The utility is very evident in that something like a Uniswap pool a) works and b) cannot be stopped, so people who do find a Uniswap pool useful, are able to rely on the guarantees made by the smart contract, including of course any potential bugs.

Re: The Web3 Fraud

#263

Earlier quoted context omitted.

Okay, can you give me an example of some staple Web3 sites that exist today?

- Uniswap and Sushiswap allows you to trade different cryptos for one another. If you want to trade gold for some reason in a decentralized manner, you could do that by making trades between gold-pegged crypto and stablecoins - Aave allows you to lend and borrow different crypto assets. If you wish to short a crypto, or if you wish to borrow against your portfolio so that you're spending fiat rather than your portfol…

So you can

- Trade blockchain tokens for other blockchain tokens. Or trade blockchain tokens for tokens that claim (with dubious, temporary and totally non-cryptographic evidence) to be backed by something else.

- Lend and borrow blockchain tokens.

- Try to launder your blockchain tokens. They have to be really dirty for it to be worth it, since obscuring how you got hold of something valuable is already a crime in itself.

- Give your blockchain tokens to blockchain casino owners.

Re: The Web3 Fraud

#264
post #240

Earlier quoted context omitted.

If you just want to store and host files like a website, there's a few projects in that vein that I know of - Arweave ( https://www.arweave.org/ ), IPFS ( https://ipfs.io/ ), and Filecoin ( https://filecoin.io/ ). IMO these projects are aiming at a new form of sovereignty on the internet that doesn't/can't exist currently - the ability to have your data be permanently stored and accessible on the web. Google can deci…

But it's not on the internet permanently, it will disappear eventually at an unknown point in the future, like a dead torrent due to the lack of seeders.

Eventually everything will disappear, so this is. It quite a valid counter argument. On the other hand, there is a real chance that these protocols have a shot on enabling preservation of data for a significant amount of time - literally hundreds of years, sensorship-free, which is kind of cool.

Re: The Web3 Fraud

#265
post #247
post #75

Earlier quoted context omitted.

> Dapps running on the blockchain are immutable and highly resistant to being shutdown. Yeah, and that's why we have Ethereum Classic , a remnant of its own shameful history. Dapps are still man-made, so can be faulty, but Ethereum doesn't have any recovery scenario for faulty dapps other than forking out. No one can save you from your own deadly mistakes. This simply can't scale.

The eth classic fork was because of the first high profile hack of a smart contract leading to massive loss of funds (way way back in 2016 - https://en.wikipedia.org/wiki/The_DAO_(organization) ). The Ethereum community back then was a fraction of a fraction of a percent of what it is compared to the size today, and that early on in the network I don't think it was a detrimental thing to do like it would be today. >…

> Alternatively, "You really really have to give a shit about your own security". Imagine if banks had some skin in the game in terms of their security story. Why was I able to have 2 factor on my world of warcraft account many years before my bank account?

It’s telling that you don’t know how wrong this is, but feel qualified to redesign a mature industry anyway. Banks are highly regulated and spend billions on security — that’s why the major breaches which are routine in the cryptocurrency world don’t have an analog in the real financial system.

They know that there would be significant penalties if they lose customer resources or grant access to your account improperly, but they don’t spend it on the same things. For example, MFA doesn’t solve every problem — if I phish you or compromise your device, your cryptocurrency life savings are gone but trying to send a wire transfer from your bank for an amount that large will require out of band confirmation, especially if it’s to a random third party or out of the country.

That irrecoverable failure mode is one of the core design flaws of cryptocurrency which makes it unappealing to most people. Most people do not want the risk or constant maintenance work of being their own bank, and mitigating that by reinventing the banking sector except more expensive is a tough sell.

Re: The Web3 Fraud

#266

Earlier quoted context omitted.

They didn't address the points - they tried to say nobody gets to compare other things unless they do . Which is wrong.

They said it's an apples to oranges comparison unless both things do . Which is absolutely correct. You could compare apples to oranges if you wanted to... but usually there's no point in doing so.

As I said to OP, no, it's not apples to oranges, you are absolutely wrong. It's comparisons of different points in the app architecture space, and that's normal, and not pointless as you claim.

You can't wave away the serious issues by saying "there's no point in comparing them"

Lots of things offer different functionality and tradeoffs. If you want to play in the space of "web app", you can and should be compared to things that are solutions for producing "web apps". We compare codeless web apps to code ones, etc.

The same way people compare gas and electric vehicles. Or minivans and suvs and trucks. Or, well, everything in a solution space.

Any solution for a given use case can and should get compared with other solutions for that use case.

I'm really sorry that it doesn't seem (judging by this thread) to compare particularly well for most developers, but that doesn't invalidate the comparison.

Re: The Web3 Fraud

#267

Earlier quoted context omitted.

> I just want to host a random site. Then just do that. You're neither the kind of user nor the kind of developer who would want to use web3. > What is the "killer app" for the average user who isn't obsessed with crypto/blockchain? What's the "killer app" of Tor for the average user who isn't obsessed with privacy? Nothing. The whole point is privacy. If you're okay with clearnet tracking, then just use the clearnet…

Honestly you couldnt explain at all what could be interesting usecase and resulted to saying "its not for you". Whats killer app of TOR? Well its TOR - its pretty clear proposition even to mainstream users it will be instantly obvious - the privacy is the feature.

> Honestly you couldnt explain at all what could be interesting usecase and resulted to saying "its not for you".

I've explained again and again in other comments. As did the parent comment of this whole thread. It's really not that hard to understand, but there's nothing I can do if you don't want to understand.

> Well its TOR - its pretty clear proposition even to mainstream users it will be instantly obvious - the privacy is the feature.

Really? Have you ever met a non-technical user who said they wanted to use Tor for anything?

Regardless, that's entirely besides the point. So what if a mainstream user doesn't understand why version control would be useful for their Excel sheets? The rest of us carry on using version control just fine.

Re: The Web3 Fraud

#268

Earlier quoted context omitted.

> Even Ethereum smart contracts do not actually guarantee the compiled byte code matches the supposed source of the contract What? You don't have to publish your smart contract code for the public to verify, but you absolutely can. And once you do, the public can absolutely verify that the smart contract code you provided does in fact compile to the byte code deployed to the blockchain. > and then we’re right back wh…

Given that you can deploy smart contracts as binaries (without source) and you can design the contracts to be upgradeable if needed, I don’t see any advantages of this system. Sure, the contract can be immutable but the only advantage is for the archivist who now has a permanent record of the software history. Other than a public change log, this doesn’t have much utility.

> Given that you can deploy smart contracts as binaries (without source) and you can design the contracts to be upgradeable if needed

You can do all that, but then who but the most gullible will use your smart contracts?

Re: The Web3 Fraud

#269

Earlier quoted context omitted.

Then that'll be the day proof of stake cryptos rise to the occasion. Also, just use a friggin VPN.

How would proof of stake mitigate ISP blocks? These still communicate with other nodes over TCP/IP.

Given the comment I was responding to, I was assuming that only a ban would be attempted on the environmentally unfriendly cryptos.

How would you propose to ban all cryptos? We haven't even been able to ban torrents.

Re: The Web3 Fraud

#270

Earlier quoted context omitted.

- Uniswap and Sushiswap allows you to trade different cryptos for one another. If you want to trade gold for some reason in a decentralized manner, you could do that by making trades between gold-pegged crypto and stablecoins - Aave allows you to lend and borrow different crypto assets. If you wish to short a crypto, or if you wish to borrow against your portfolio so that you're spending fiat rather than your portfol…

So you can - Trade blockchain tokens for other blockchain tokens. Or trade blockchain tokens for tokens that claim (with dubious, temporary and totally non-cryptographic evidence) to be backed by something else. - Lend and borrow blockchain tokens. - Try to launder your blockchain tokens. They have to be really dirty for it to be worth it, since obscuring how you got hold of something valuable is already a crime in i…

> Trade blockchain tokens for other blockchain tokens. Or trade blockchain tokens for tokens that claim (with dubious, temporary and totally non-cryptographic evidence) to be backed by something else.

The Perth Mint is "dubious" and "temporary" to you?

If you dislike examples of assets backed by centralized entities, then look at decentralized algorithmic stablecoins.

> - Lend and borrow blockchain tokens.

Yes, including tokens that track "real world" assets. Lending and borrowing is afater all an integral part of the modern economy. This bulletpoint stands by itself.

> - Try to launder your blockchain tokens. They have to be really dirty for it to be worth it, since obscuring how you got hold of something valuable is already a crime in itself.

Just because you don't see any value in money laundering doesn't mean others don't. It's a billion dollar industry.

> - Give your blockchain tokens to blockchain casino owners.

If you want to, yes, you should absolutely have the freedom to do that. Alas, some jurisdictions in real life prevent their people from doing just that.

Post reply on HN