Live data from Hacker News

Critical Update on DAO Vulnerability

blog.ethereum.org

481–490 of 629 posts

Re: Critical Update on DAO Vulnerability

#481
post #242

This is what concerns me about contract programming. With human contract law, if there's a minor typo or loophole, participants can generally see the spirit and intent, and at worst go to a judge who will usually enforce the intent. But with software contracts, only the characters matter and there's no intent anywhere: either you get paid or you don't. ETH is advising, "Contract authors should ... be very careful abo…

100% agreed and anyone who expects these types of smart contracts to replace typical contracts is overlooking this. The real void smart contracts fill is the type of contracts that cannot be trusted to be enforced by the current court systems. For example, consider prediction markets. Just about any economist or rational person will tell you these are a huge boon to the world, but the CFTC shut down InTrade just a fe…

Prediction markets already widely exist and have been around for ages, just not in America. You can bet on all kinds of real world events, not just sports, in many countries.

Adding a prediction market to ethereum or some other crypto coin isn't going to revolutionise anything.

Re: Critical Update on DAO Vulnerability

#482
post #476

Wow, theDAO has a shockingly cavalier attitude to security ( https://github.com/slockit/DAO/wiki/The-DAO-v1.0-Code ): > At the time of deployment, it was discovered that the solidity compiler is not deterministic. AST nodes are identified by their raw pointers. So if we iterate over data structures, different raw pointers might result in a different iteration order. > We originally wanted to let the community deploy…

"Move fast and break things."

In all seriousness though, when it comes to cryptography, cryptocurrency, and smart contracts, people are playing with fire, and they don't realize it. You can't fix a smart contract the same way you can fix a website. The fact that it's function is not good enough to push it out to the public.

Most software projects don't have that problem. Most software projects, it is okay to push buggy beta code out to the public. Because most software projects don't steward large amounts of money in an irreversible payment system.

Re: Critical Update on DAO Vulnerability

#484
post #349

It seems to me that the DAO is a large enough player in the Ethereum community that this plan is likely to succeed. If it does, it will be the first example I know of where a 51% attack was successfully executed against a popular blockchain. Whether or not this is a desirable thing depends on your goals. From the perspective of the Ethereum community, which is heavily invested in the DAO, it makes a lot of sense. Eve…

> On August 15 2010, it was discovered that block 74638 contained a transaction that created over 184 billion bitcoins for two different addresses. This was possible because the code used for checking transactions before including them in a block didn't account for the case of outputs so large that they overflowed when summed. A new version was published within a few hours of the discovery. The block chain had to be…

While this does demonstrate a 51% attack, I think there's a key difference here. With the 2010 Bitcoin fork, the problem was a bug in the core infrastructure which was broken. The 51% attack broke the core infrastructure, but that core infrastructure was already broken. In that case it was a matter of choosing which way the core infrastructure breaks.

In the current Ethereum situation, the core Ethereum infrastructure isn't broken. The problem is with the contracts in the DAO. So creating an intentional fork is breaking the core infrastructure--which isn't broken--to fix the problem of a single majority stakeholder.

I don't mean to indicate the Bitcoin fork wasn't a problem--the fact that bugs can break core infrastructure also concerns me. But it's a very different problem from the one the DAO is creating here.

Re: Critical Update on DAO Vulnerability

#485

I started archiving the slock.it #general slack channel when this attack began. This is where most of the discussion has been taking place. Here's up until a few minutes ago: http://pastebin.com/DykumjLs

@channel EMERGENCY ALERT! IF YOU HAVE A SPLIT OPEN PLEASE DM @griff ASAP!!! azzo [2:22 PM] what's DM

azzo [2:23 PM] What DM !!!!!!!!!!!!!!!

Re: Critical Update on DAO Vulnerability

#486

Earlier quoted context omitted.

Very interesting! Looking at the papers and going to read them. Any specific papers you'd recommend?

"Tiling agents" would be the most arguably relevant. Provably correct agents that approve the construction of other probably correct agents obeying similar invariants.

Thanks! Looks very interesting!

Re: Critical Update on DAO Vulnerability

#487

This is what concerns me about contract programming. With human contract law, if there's a minor typo or loophole, participants can generally see the spirit and intent, and at worst go to a judge who will usually enforce the intent. But with software contracts, only the characters matter and there's no intent anywhere: either you get paid or you don't. ETH is advising, "Contract authors should ... be very careful abo…

Attempting to enforce the spirit of the law is a problem in its own right though. The flexibility of written law is repeatedly abused. Whether it's politicians taking land from their constituents, or drug laws being used to drive racism, we really shouldn't be looking at the flexibility of written law as a good thing. Or at the very least, we should be acknowledging that it's a double edged sword.

Ethereum's smart contract language is not one which makes it easy to write secure smart contracts. There are dragons everywhere, and the DAO is far and away not the only smart contract to incur their wrath.

In general I am in favor of moving to programatic, unforgiving law. But we need to do so at a pace that matches our technological progress. Today, the technology is not there to make advanced contracts. Simple ideas like 'this coin is owned by this person until a signature from this key transfers ownership to someone else' are pretty easily enforceable. Bitcoin has a scripting system with a variety of safe scripts in widespread use.

But as soon as you start aiming at things like 'this investment fund is owned by this group of people and is able to make investments under conditions X, Y, Z, and can split... etc.', you've outpaced what we currently know how to do safely.

Re: Critical Update on DAO Vulnerability

#488
post #347
post #338

Earlier quoted context omitted.

Now there are a couple things I still do not understand. 1. How do I exchange this cryptocurrency for something that I can go and buy a sandwich with at the Deli? 2. Why is there a need for this instead of using traditional methods with contracts, banks, etc? Money as is, is a collective illusion we all subscribe to anyway, and these things aren't any more different from that. What is the purpose of this cryptocurren…

1. You just make an agreement with someone who would like to buy your tokens for some national currency. If you ever played an MMORPG or Diablo 2 or something, you know that "imaginary" digital items can be traded for "real" money. There are many exchanges where you can do this conveniently. 2. For one example, consider how tedious it is to open a new bank account; with cryptocurrency, you just make a new keypair. Sm…

In the country of my current residence, there are government plans running that provide additional benefits beyond simple salaries. These are food-tickets, leisure and vacation credit that are allocated on plastic cards. I loathe these. They are a way of faking actual payment. These credits and tickets are not accepted everywhere, unlike the currency of the country is. They carry second-class monetary value, and the system is set up in a way so that these leisure credits time-out after 2 years of allocation. Imagine your dollars or euros disappearing due to expiration. Nonsense.

Beyond their inconvenient use, they are not valid outside of the country either. In essence, they have created a closed ecosystem, making sure that you can only spend this 'money' within their own system. You cannot transfer these funds outside of walled gardens, in this case the country's legislative boarders. I see cryptocurrency the same way. If everyone starts using it, it will have universal value. However, to use it, everyone would need to have access to internet and mobile devices. I do not see that happening anytime soon. And please don't reference the number of mobile devices. Internet infrastructure is much more expensive to build than to supplement everyone with cheap phones. [1]

I cannot really relate to your vending machine example either. In case of a vending machine example you are quoting that 'anybody with coins can participate in an exchange with the vendor.' This only works if the universally agreed currency is the one expected by the vendor. Your vending machine would not accept my Eastern European Monopoly Money whereas the expected input is in Euro. Same for cryptos: where the expected input is that of a currency backed by financial institutions trading in the same currency, I will laugh at you when you attempt to pay in bitcoin, dogecoin, ether (literally the primordial Greek deity of pure air), whatever.

With point three you suggest that the real value of these systems are for people who got into the Pyramid Scheme early. Again, I think these institutions are frauds, and I would not be surprised if it surfaced that the creators of this blockchain system planned to pull off such a scam in the first place.

[1] http://paiwandgah.af/personal-data-leaked-from-smartphones-n...

Re: Critical Update on DAO Vulnerability

#489

Earlier quoted context omitted.

Even if we agree that Ethereum is still in its early stages we have to ask whether this response is setting a good or bad precedent going forward. Will the project leadership offer a soft- and/or hard-fork every time a poorly-implemented smart contract is exploited in a manner that is not intended by the contract creators? If every smart contract is going to be "guaranteed" in this way, then this introduces significa…

In this particular case the contract holds 15% of all ether. The fork won't be enacted unless a majority of the community agrees to run its code. That's not likely to happen except in extreme cases, like this one.

In other words, this contract is too big to fail?

Re: Critical Update on DAO Vulnerability

#490

Earlier quoted context omitted.

Very interesting! Looking at the papers and going to read them. Any specific papers you'd recommend?

"Tiling agents" would be the most arguably relevant. Provably correct agents that approve the construction of other probably correct agents obeying similar invariants.

Is "probably" there meant to be "provably"? I assume so, but I'm not sure.
Post reply on HN