Live data from Hacker News

153k Ether Stolen in Parity Multi-Sig Attack

etherscan.io

351–360 of 754 posts

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#351

Earlier quoted context omitted.

I think a big part of the complaint is about the implicit assumption that because people are smart, and have experience with cryptography, they necessarily have the experience to design a sane and safe programming language given their goals. They did put themselves way out there, and that takes ambition, but also hubris. I wish they were able to figure out which one was driving them at certain points a bit better, as…

Actually, I think Solidity being designed to turn bad node.js coders into bad smart contract coders was key to Ethereum's success. I've written a book on this (hit upload five minutes ago! release Monday!) which hammers on this point (and all the stuff surrounding this issue). I think Solidity is actually designed with worse is better in mind, because Ethereum is the first smart contract platform that anyone actually…

You've wet my appetite. Got a link to your book?

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#352
post #346

Earlier quoted context omitted.

These are good points. What if the default behavior of a contract was to reset the world to its previous state if the program does not terminate within 30 seconds? Arguably unclear termination semantics would be a good reason not to trust a contract. Ideally trust mechanisms would exist such that closed source contracts were trustable via a pure insurance-based mechanism.

> if the program does not terminate within 30 seconds? As I attempted to say in my previous comment, undecidability[1] isn't limited to deciding if a program will halt (or even the weaker question of if it will halt in a given finite time). Recursively enumerable[2] languages that require a Turing machine to automate have an intrinsic complexity (i.e. any Turing-complete language). This isn't a "work harder to solve…

Very Interesting. I will read those links.

What if Ethereum offered a non-turning-complete subset of Solidity (that included formal verification) which could optionally be used in smart contracts. Would this cause you to view the platform differently?

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#353

Earlier quoted context omitted.

You should ask yourself what the Bitcoin developers are doing while Ether takes their market share. The answer is the exact same thing, at https://elementsproject.org Now why hasn't there been as much publicity about this? Is it because Vitalik Buterin is a wunderkind genius who simply beat them to market? Nope, the Bitcoiners are simply being more responsible and making sure they get the formula right before rushing…

You sound very biased on this.

I am very biased because I know the people at Blockstream have been thinking about this problem longer than the developers of Ethereum.

Please see this article to get an idea of the personalities involved:

http://www.newsbtc.com/2016/08/17/gregory-maxwell-vitalik-bu...

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#354

Earlier quoted context omitted.

So you use the Bitcoin Core wallet do you? You've veered away from your original statement towards one that I don't disagree with. Of course you shouldn't just trust any software you find on the internet. That's not the same as "only trust Ethereum core". Slandering "third party" as if that has any meaning is silly. You should treat everything on its individual merits, including the Ethereum reference wallet.

My argument has remained the same. The Ethereum reference wallet is by far the most vetted wallet. Use that. (And yes, I use the Bitcoin Core wallet.) If you used Parity because it has 1,700 stars on Github and was written in Rust, you're doing it wrong . Stop. You can't assess merit based on what everyone else is doing. The only hope in a situation where you don't know what you don't know is to stick with fundamenta…

If being highly vetted is your main heuristic for safety, then isn't popularity (large number of github stars) directly correlated with that?

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#355
post #322

Earlier quoted context omitted.

Do you have examples of this, or just hearsay?

the story you are commenting on is a good example it should not be this easy to lose sixteen million dollars

I feel like we shouldn't be expressed in dollars, but in percentage of total funds. In this case 16 million is about 1% of the total. This would be a $16 billion case if the US banking system was the target and used this technology.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#356

Earlier quoted context omitted.

This is the central, glaring flaw in cryptocurrencies to me. Transferring "value" for goods and services is really more of a social problem than a scientific/engineering one. Money is a social technology that solves a social problem. Cryptocurrency is a engineering technology in search of a problem to solve.

> Transferring "value" for goods and services is really more of a social problem than a scientific/engineering one Do you mean on the margin where there is debate about the contract or whether the goods/services were rendered adequately? Cryptocurrencies don't attempt to solve this problem at all, they simply allow for efficient moving of currency between parties without the need for meatspace regulation/trust to do…

[deleted]

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#357

Earlier quoted context omitted.

Dear god, I've been thinking crypto is a bubble since 2010. At some point, we have to admit this is not just a bubble. It's a new unproven evolving technology

I actually think eth has a lot of potential, but I don't think he's saying crypto is a bubble. He's probably talking about the ICO "bubble", which isn't a controversial thing to claim. Eth has already halved in value in the last month which is mostly put down to the crazy value being pumped into ICO's slowing down.

I would argue ICO phenomenon is not a bubble Rather, some ICOs are scams But many are legitimate business ventures. Buying into an ICO is similar to buying deep out of the money options

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#358
post #322

Earlier quoted context omitted.

Do you have examples of this, or just hearsay?

the story you are commenting on is a good example it should not be this easy to lose sixteen million dollars

Yes. If a similar scale thing were to happen in the U.S. banking system, 1% would be 160 billion dollars, not 16.

I'm amazed that otherwise intelligence people really believe this is a better system than fiat currencies + banks.

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#359

A much more useful explanation: https://press.swarm.city/parity-multisig-wallet-exploit-hits...

> The Swarm City Core team is more committed than ever to the development of Swarm City. The real value of our token lies in the community, and the technology the developers are creating. Black hat hackers, vulnerabilities, and bugs will not stop us from creating the decentralized sharing economy our community and the world craves. What?!? That seems like a pretty relaxed response for someone who just lost 8m dollars…

Maybe they just acquired 8 million dollars for free?

Re: 153k Ether Stolen in Parity Multi-Sig Attack

#360

Earlier quoted context omitted.

Again, you haven't made any case for not using open source third party software. The other other example you've come up with was a close source proprietary internet service. Very few people, for instance, use the official Bitcoin Core wallet.

I believe there have been scam wallet implementations for BTC in the past, though I don't have any info. They're your coins. Throw them off a bridge if you want. Meanwhile, people who stick with core tech have been burned zero times. Why does the obsession with shiny new convenient thing outweigh people's good sense not to risk thousands or hundreds of thousands of dollars? If that amount of money were printed out in…

Just a couple months ago geth clients were crashing due to a memory overload, the fix? Use parity until geth was patched.

Using core implementations is no guaruntee that you won't get burned. The only difference between official software and third party open source software is the dev team behind it. The official devs can make mostakes just like anyone else.

Post reply on HN