Live data from Hacker News

153k Ether Stolen in Parity Multi-Sig Attack

etherscan.io

311–320 of 754 posts

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#311

Earlier quoted context omitted.

Right, so I guess I was asking: If you cash out everything as quickly as possible, no one from the government will ask where your millions came from?

Sure they will ask. And you can say something like "I was an early bitcoin investor". Or "I trade cryotcurrencies". It is perfectly reasonable to be a cryto trade that never withdraws to USD, and just makes money by transferring between crypto currencies and ICOs or something. I am sure there are a whole lot of people out there who spent a thousand dollars or so back in 2009, and now they have 10 mill in the bank. It…

I guess I'm skeptical of the idea that they won't ask for proof of your trades, which would lead to discovering you were a thief. But I suppose that's highly unlikely.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#312

Earlier quoted context omitted.

Again, you haven't made any case for not using open source third party software. The other other example you've come up with was a close source proprietary internet service. Very few people, for instance, use the official Bitcoin Core wallet.

I believe there have been scam wallet implementations for BTC in the past, though I don't have any info. They're your coins. Throw them off a bridge if you want. Meanwhile, people who stick with core tech have been burned zero times. Why does the obsession with shiny new convenient thing outweigh people's good sense not to risk thousands or hundreds of thousands of dollars? If that amount of money were printed out in…

So you use the Bitcoin Core wallet do you?

You've veered away from your original statement towards one that I don't disagree with. Of course you shouldn't just trust any software you find on the internet. That's not the same as "only trust Ethereum core". Slandering "third party" as if that has any meaning is silly. You should treat everything on its individual merits, including the Ethereum reference wallet.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#313
post #11

I've posted this before [0], but it's still apropos regarding the foolishness that is Ethereum. [Ethereum] only makes sense if all of the following obtain: (a) the code is 100% bug-free (b/c accidents cannot be rewound) (b) all code-writers are 100% honest (their code does what they say) (c) all contract participants are 100% perfect code readers (so as to not enter into fraudulent contracts) (Strictly speaking, only…

Can't you say the same thing about software that uses encryption in general? For example your browser, yet you still trust it. Also, what you said applies to critical software in airplanes, and cars like Tesla, yet you still somehow trust it without reading the code. Maybe you should replace the word "Ethereum" with "sotware". "Software in general makes sense is all the following are true"

Safety-critical software, for flight in particular, is required to meet rigorous certification standards and processes specified by law that include independent engineering review. You can't just slap in something from github, write some tests and call it a day.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#314

Earlier quoted context omitted.

I believe there have been scam wallet implementations for BTC in the past, though I don't have any info. They're your coins. Throw them off a bridge if you want. Meanwhile, people who stick with core tech have been burned zero times. Why does the obsession with shiny new convenient thing outweigh people's good sense not to risk thousands or hundreds of thousands of dollars? If that amount of money were printed out in…

So you use the Bitcoin Core wallet do you? You've veered away from your original statement towards one that I don't disagree with. Of course you shouldn't just trust any software you find on the internet. That's not the same as "only trust Ethereum core". Slandering "third party" as if that has any meaning is silly. You should treat everything on its individual merits, including the Ethereum reference wallet.

My argument has remained the same. The Ethereum reference wallet is by far the most vetted wallet. Use that. (And yes, I use the Bitcoin Core wallet.)

If you used Parity because it has 1,700 stars on Github and was written in Rust, you're doing it wrong. Stop. You can't assess merit based on what everyone else is doing. The only hope in a situation where you don't know what you don't know is to stick with fundamentals. And even then you could still get burned. But that hasn't happened yet, which is why it's the least risky move.

It will take at least a decade for the cryptocurrency ecosystem to stabilize. Why risk anything when you don't have to? Arguing "I don't use the Bitcoin Core wallet because it's less convenient" is exactly that: an unnecessary risk. If you're set on jumping into this world, at least do it safely.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#315

Earlier quoted context omitted.

Whether it's an online service or a local wallet with an embedded buggy smart contract, your coins are just as gone. If you're perfectly happy to use it, you're perfectly happy to lose everything. How many millions need to be lost before this lesson is learned?

Are you saying everyone needs to write their wallet from scratch?

re: sillysaurus3, the "core" wallet is possibly even worse than parity. Why wouldn't you be as safe using the most popular one with the most eyeballs?

If someone steals your coins from the "core" wallet, they're just as gone, correct?

The real moral, as always, is don't keep wealth in a crypto-currency. You'll lose it and have no recourse.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#316
post #229

Earlier quoted context omitted.

Parent is referring to the transaction mechanism of the CC providers, not consumer credit. Fraud is a function of humans not the currency. The reason large systems to protect from fraud are baked in, is because there are a lot of humans that commit fraud. The blockchain would only provide a well documented account of the fraud, with no tooling to remove the assets from the fraudster. Chargebacks are a blessing when y…

> Chargebacks are a blessing when you need them and a curse when you receive them, but something that the economy has deemed a necessary evil mostly because there are a lot of fraudsters in the world This is an excellent point, and I think it's an example of how an institutional mechanism evolved to help address fraud. There's absolutely no reason to think chargebacks would not come to exist if commerce were dominate…

I don't think anyone doubts that smart contracts can be written that allow for a trusted third party to effectively reverse a payment, especially not in Turing-complete languages. I think the point is that if mutability and trusted third party oversight is actually usually a necessary and desired fraud prevention feature in a payments system, there's probably not huge demand to replicate all that using blockchains whose most-touted virtue is immutability and trustlessness and brand new institutional infrastructure (it's not like we don't already have ways for algorithms to execute trades subject to contract conditions being met using old-fashioned dollars and yen)

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#317
post #160

Earlier quoted context omitted.

How is rolling back transactions that are clearly part of a robbery a bad thing?

Because people want to dream this is some anarchist system where nobody controls etherium the same way everyone thinks bitcoin-core isn't a centralized authority on the protocol. To dispute that de-facto centralization requires miners to collectively decide to abstain from updates to these primary clients en masse. That just won't happen, people don't organize or coordinate like that. The status quo has tremendous in…

> To dispute that de-facto centralization requires miners to collectively decide to abstain from updates to these primary clients en masse. That just won't happen, people don't organize or coordinate like that. The status quo has tremendous inertia beyond what can be reasonably expected of independent actors trying to act in their own self interest.

Yeah, tell that to Bitcoin on August 1st.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#318
post #299

Earlier quoted context omitted.

Actually, I think Solidity being designed to turn bad node.js coders into bad smart contract coders was key to Ethereum's success. I've written a book on this (hit upload five minutes ago! release Monday!) which hammers on this point (and all the stuff surrounding this issue). I think Solidity is actually designed with worse is better in mind, because Ethereum is the first smart contract platform that anyone actually…

I agree that it was a key to the success; but it will also be a key to it's failure. Because it's a financial system, and normal sane people don't want money that is demonstrably worse for nearly all the things that normal sane people do with money. Ethereum is a great political statement, and a fun toy... but when you recast the worse is better story into this context, you're just demonstrating that you don't really…

You appear to have misconstrued my words. I don't in any way think this is a good idea; just one that has the viral characteristics of "worse is better".

I spent about three thousand words on the smart contracts chapter, attempting to conclusively stab this bad idea in the face and supply a suitable rhetorical ammo dump for anyone faced with having to deal with these things to kill the idea stone dead. Absolutely everything about smart contracts is terrible and misconceived. I don't believe there is any way to do them right, because the idea is fundamentally wrong.

Here's (an older draft, need to update) what I actually say about Solidity and Ethereum smart contracts: https://davidgerard.co.uk/blockchain/ethereum-smart-contract...

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#319

Earlier quoted context omitted.

> Why not just use a traditional financial institution then? Insurance via smart contracts is still far simpler and more efficient to implement than in meatspace. Consider things like insurer solvency risk and the way that meatspace regulations make that hard to understand. With cryptocurrencies an insurer can easily offer proof of solvency based on all outstanding risks. Insurance emerges as a fundamental economic b…

This is nonsense. Ethereum is uninsurable. The turtles-all-the-way-down notion that you can wrap a bad "smart contract" in a bad "smart insurance contract" and buy Ethereum insurance from an Ethereum insurer and prove that there will be enough Ethereum there to make everyone whole economically should everything go to shit because a fundamental problem in Solidity lets anyone unilaterally blow the whole thing up... I…

> because a fundamental problem in Solidity

Problems in Solidity are a systemic risk faced by all contracts and are thus not something that can be hedged within the system.

Correspondingly, fixes to VM bugs are the sort of thing that the hard fork mechanism is good for. Hard forks that fix flaky VM behavior are uncontroversial.

While there are many applications of insurance products, the use case I am referring to above has to do with specifically insuring the expected behavior of a smart contract.

Suppose I write a smart contract that "rounds up" a user's transactions for a day and donates the rest to charity. I describe the contract verbally as "This contract lists all the transactions your account made that day, rounds to the nearest ETH, and donates the difference to account xyz which is associated with the American Red Cross fundraising division.

There are several aspects of this contract to verify. First, does the logic in the code do what the verbal description says it does. Are there any mathematical errors? Can it run more than once in given 24 hour period? Is the id associated with the Red Cross actually linked to that organization?

If a trusted third party vetted the contract and claimed that its claims were true and that 800 people had used it that day to donate, I'd likely consider it worthwhile to trust that contract.

Similarly, if a third party offered an insurance smart contract that would charge me a tiny amount of Ether to guarantee that the contract would behave as expected within a 10 year period, I might feel comfortable buying that contract. If that third party was unknown to me I might rely on recommendations from others, etc.

The point is that trust builds upon trust. One sort of vetting can help buttress other layers of vetting. This is no different than trust in meatspace, only the characteristics of the blockchain make some kinds of trust easier to realize.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#320
post #299

Earlier quoted context omitted.

Actually, I think Solidity being designed to turn bad node.js coders into bad smart contract coders was key to Ethereum's success. I've written a book on this (hit upload five minutes ago! release Monday!) which hammers on this point (and all the stuff surrounding this issue). I think Solidity is actually designed with worse is better in mind, because Ethereum is the first smart contract platform that anyone actually…

I agree that it was a key to the success; but it will also be a key to it's failure. Because it's a financial system, and normal sane people don't want money that is demonstrably worse for nearly all the things that normal sane people do with money. Ethereum is a great political statement, and a fun toy... but when you recast the worse is better story into this context, you're just demonstrating that you don't really…

I don't think your personal attacks lie within the standards set by this community. There are many ways of disagreeing, even vigorously, without being a jackass. It's discrediting to yourself.
Post reply on HN