Live data from Hacker News

Simple Contracts are Better Contracts: the Meltdown of the DAO

blog.blockstack.org

51–60 of 105 posts

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#51

How many of the TheDAO Curator members are lawyers? Contracts are agreements that are meant to be legally enforceable. The enforcer has always been the King, a local governmental authority and a third party. The very concept of a contract assumes the neutral third party. That third party is to interpret the contract, identify potential scoundrels, nullify illegal contracts and generally make sure everyone isn't playi…

Typos rarely matter in real contracts. Intent can trump language where appropriate. But in smart contracts typos are everything. Good luck with that too. The City of Cleveland and Frank McCourt would like to have a word with you about your novel theory. In real contracts, typos--like an errant comma--can be significant and completely change the meaning of the language. Cleveland lost the original Browns because of a…

In those cases the court found the intent manifest in the language. These were sophisticated parties with legal advice. Even if they court didn't see intent, it is within the courts' power to force such persons to follow the language if for nothing else than to serve as example to other negligent contract drafters.

A court will only grant that which is asked for. So for a typo to matter, one of the two parties before the court must be claiming that is isn't a typo.

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#52
Can code both embody and replace law for the exact function for which it is set up?

DAO strives to execute through code an idealized pooled investment system by which contract issues are resolved entirely by code and wholly apart from any external societal legal or enforcement mechanisms.

All well and good but, where people are involved, code simply cannot define all the relations needed to capture what the law does (and, indeed, and in spite of its flaws, does very well indeed).

Consider the argument that the exploit here is not a flaw at all but just another variation on what the code does, with the result that investors who suddenly are $50M lighter in their wallets have not been harmed at all and should have no recourse to any remedy to restore their funds to them. The idea here is that the code is the contract and, if that is what the code does, well, that is what you bargained for, whether this is good or bad from any particular moral perspective. Right at the entry point of the system is a prominent disclaimer that says this in exact words. So a contract is a contract. If you don't like the result, tough.

The participants here are wealthy and presumably sophisticated investors. What if they aren't? What if this were marketed to a lot of gullible small investors who were induced to part with their money through various representations stating that their funds were entirely safe, subject only to normal investment risks relating to the underlying companies they funded? What does society do when people like this lose their life savings when some newly discovered "feature" of the code allows a sharpie to walk away with their funds? Are they to have no legal recourse because a "contract is a contract," especially if it embodied in code?

And what happens if a system is set up and the person or persons who find the new "feature" enabling them to walk away with other people's funds are the very people who organized the fund? Does law from the broader world step in to provide a remedy to those who lost their money? Or does the "contract is a contract, especially in code" logic work to deny any remedy to the participants here as well?

And, setting aside any of the more extreme examples, what if it is simply the case that those who did participate had reasonable expectations that any code that would define and limit their rights would do all that was expected in terms of defining their investments but would include safeguards that would prevent anyone from simply coming in to remove their funds altogether (dare I say "steal")? What if they were misled into having such expectations by promoters of the venture who said or implied that such safeguards existed? Is it enough to say that none of this matters because of some disclaimer buried in fine print? Is all of this simply irrelevant just because a "contract is a contract, especially in code"?

Contracts are part of any system of law that includes private property, and a very important part at that.

But contracts can never define the totality of the law that applies to a given situation, even if the parties swear up and down that that is their intent.

That is why securities laws exist, to help investors who get swindled by sharpies with well-honed contracts.

That is why the laws relating to fraud exist, to help those who are misled by others to their financial detriment.

Indeed, that is why a sophisticated body of laws exists relating to contracts themselves, to cover cases where the intent of the parties is sometimes so frustrated by one thing or another as to make it inequitable to enforce a contract.

Law is and always has existed in multiple layers. Legislatures pass statutes but courts exist to interpret them to cover specific cases as disputes arise. The same with administrative regulations promulgated by agencies. Even within the courts themselves, common law courts would declare legal "rules" only to have courts of equity intervene to correct things where the "rules" led to harsh or inequitable results.

Basically, all of this is another way of saying that human relations are complex and any system of laws and justice needs to be able to handle such complexity if it is to be worthy of being a system of justice.

Perhaps in narrow cases, things such as DAO can be set up to create a rich guy's playground of sorts in which, for the overwhelming number of cases, outside laws play no part within the self-contained system. Perhaps there is even an ideal of some type to be realized here (get rid of lawyers, etc.).

But no such system can ever be utterly divorced from the rules of the broader society. Ideal or no ideal, this is just not how the law works. Apart perhaps from some survivalist society or other, people simply cannot exempt themselves from the general rules of law no matter how much they desire to do so. They can limit the application of such broader laws to a degree but, when key bounds are transgressed, the law will apply in its full force regardless of their intentions.

So, I would say that the curators here probably had no choice. It was either do what they did or watch as lawsuits followed, probably in abundance. This may have violated some ideal in play here but it was a pragmatic necessity given how law in reality works (and always will work).

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#53

"Simple Contracts are Better Contracts" has always been the mantra of the Ethereum and DAO team. Most times when a security question was raised, "simple contracts" was their defacto answer [1]. This exploit suggests that the most competent developers in this space, who always preached simple contracts, are not yet able to consistently write secure contracts. Also, the OP states the importance of being able to update…

"Most competent developers"? There are probably thousands of better informed developers/researchers who would not attempt to set up such a company before they have stronger formal guarantees . Of course, if you want to be first-to-market, none of that seems to matter.

Strong formal guarantees are complicated see? and we run around telling ourselves that simple is better, so we keep writing shit code.

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#54
post #50

If the contract code can be upgraded by the majority of involved parties, it would be simple to buy 51% of the voting power and change the code to pay out everything else. Each takeover would double your wallet. Am I missing something here?

51% attacks are a known issue. A sustained 51% attack is pretty much an existential threat to any blockchain. So I doubt the issue gets any better when dealing with individual contracts. https://blog.ethereum.org/2014/05/15/long-range-attacks-the-... http://ethereum.stackexchange.com/a/544

Thank you for your valuable input. The problem I see is not in having 51% of the whole capacity of the blockchain, but of the smaller entities/organizations/contract codes. With the proposed simple contracts, the little 'start-up' contract codes with little voting power will easily get acquired by bigger ones, which then vote for a code change to pay out the remaining shares. This is much more realistic that the traditional 51% attacks. Letting the majority of a small DAO-like organization vote for code change (which translates to law-change) will not only be used to fix bugs, but to change the contract to the majorities advantage. This may eventually result in one single big contract code that incorporates every new organization on the horizon.

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#55

Earlier quoted context omitted.

For example: either party to this contract submit a signed request for arbitration within the escrow period of this contacts then 1) a panel of 3 arbiters from the New Atlantis Common Law Arbitration Group will be selected at random. 2) 50-ETH will be set aside for court fees. 3) The panel can execute any 1 of 5 events by submitting 2 of 3 signed tokens. If the panel cannot arrive at a consensus, one token will execu…

If the panel cannot arrive at a consensus, one token will execute at random. Hang on, this isn't the casino. Contracts don't usually have a 'random outcome' clause, do they? I think we better take this to the courts.

Whether the random number is pulled before the hearing (picking just 1 judge instead of 3) or after (by picking one vote token at random) seems the same to me.

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#56
There are two fundamental problems with Etherium contracts.

1. They're executable programs. They could have been a set of declarative rules listed in priority order, but no, the designers went overboard and made them general programs with loops and recursion. There are straightforward ways to analyze sets of rules; they're usually amenable to case analysis. It's hard to analyze programs.

Writing a declarative contract language is a challenge. But doing so forces the designers to think through what they want the system to be able to do, and what they don't want it to do. Doing contracts as executable programs is punting on the problem. It says "we don't know how to do this, so we'll dump the problem on the users."

2. The stack overflow problem is idiotic. The system should have been designed so that if a program aborts, anything it did is rolled back. That's the design flaw this attack exploits.

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#57
post #8
post #5

Earlier quoted context omitted.

It's not like honoring contracts is unsolved. Bookies have been doing it forever with questionable effectiveness. PayPal offers arbitration on stranger to stranger sales. Again with questionable fairness in tough cases. Kickstarter et al are doing a pretty good job as arbitrators and collecting money and issuing refunds more or less fairly.

I do see room for improvement in efficiency. Kickstarter and PayPal surely have large teams working on arbitration, review and fraud that could be delegated back to the involved parties vote with some rules. And law suits can be very inefficient. This absolutely could be solved without a block chain.

How can code on a blockchain decide whether an eBay listing was fraudulent without paying humans to make the determination? Unless you have a general AI up your sleeve!

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#58
post #50

Earlier quoted context omitted.

51% attacks are a known issue. A sustained 51% attack is pretty much an existential threat to any blockchain. So I doubt the issue gets any better when dealing with individual contracts. https://blog.ethereum.org/2014/05/15/long-range-attacks-the-... http://ethereum.stackexchange.com/a/544

Thank you for your valuable input. The problem I see is not in having 51% of the whole capacity of the blockchain, but of the smaller entities/organizations/contract codes. With the proposed simple contracts, the little 'start-up' contract codes with little voting power will easily get acquired by bigger ones, which then vote for a code change to pay out the remaining shares. This is much more realistic that the trad…

It should be possible to define that you need e.g. 90% of the shareholders to approve a change to the contract. The 90% could still steal money from the 10%.

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#59

Earlier quoted context omitted.

>>... to include common law arbitration protocols. That's a great example of the sort of ambiguity that an arbitrator must deal with. Do you mean to refer to "the common law" as in the body of law descending from the brits, or do you mean the common law principals of precedent and authority? Or do you mean only the concept of precedent by which past decisions under similar fact patterns are used to inform decisions r…

I mean a "concept of precedent by which past decisions under similar fact patterns are used to inform decisions regarding new fact patterns." Without the need for territorial jurisdiction there will be many competing (but still distinct) common law groups. Signatories would pick a lineage at signing (npm install JAMS). We'll start with human only arbiters, (panel of three from JAMS for example) then moved to mixed pa…

I cannot wait until I can do UNIDROIT[0]-compatible contracts in Rust using Parity[1]. building an implementation of UNCITRAL Model Law[2] would be the biggest market disruption I could think of. Imagine being able to do ex aequo et bono (think Judge Judy/small claims rules) arbitration; even with human (flawed/biased) arbitral tribunals, this would be amazing.

ROSS is killing the need for lawyers, and this is the path to killing the need for judges. Software is eating the world, and i couldn't be happier.

0. http://www.unidroit.org/english/principles/contracts/princip...

1. https://ethcore.io/parity.html

2. http://www.uncitral.org/uncitral/en/uncitral_texts/arbitrati...

Re: Simple Contracts are Better Contracts: the Meltdown of the DAO

#60
post #56

There are two fundamental problems with Etherium contracts. 1. They're executable programs. They could have been a set of declarative rules listed in priority order, but no, the designers went overboard and made them general programs with loops and recursion. There are straightforward ways to analyze sets of rules; they're usually amenable to case analysis. It's hard to analyze programs. Writing a declarative contrac…

To be fair, ethereum has bytecode at its base- almost certainly someone will wrote a more declarative language on top of it now to help minimize the chance that unexpected calling trees can lead to unexpected behavior.

Also, the existing solidity language is pretty well designed, it's just a hard problem and an even better design may be needed.

Post reply on HN