Live data from Hacker News

Critical Update on DAO Vulnerability

blog.ethereum.org

511–520 of 629 posts

Re: Critical Update on DAO Vulnerability

#511
post #255

Earlier quoted context omitted.

I see a different problem here: Ethereum and the DAO were not in a mature state to handle this amount of money. For example, there is a limited support for upgrading contracts in Ethereum and the DAO was not reviewed enough to handle hundreds of million dollars. Also, there are methods to make the software ultra secure using formal models.

Formal verification is the right approach. Do you know of any specifics for this goal that exist for ETH now?

Vlad Zamfir, Greg Meredith, and Emin Gun Sirer are working on this for Ethereum's next consensus algo, Casper. Not aware that they've published anything on it yet though.

Re: Critical Update on DAO Vulnerability

#513

"They say 'there are no atheists in foxholes.' Perhaps, then, there are also no libertarians in crises." [1] [1] https://www.hks.harvard.edu/fs/jfrankel/CatoRespCrisesJun07+...

(Not to take this post too serious, but I'll take the bait)

I'd argue that the solution proposed by Ethereum in this blog post is not antithetical to mainstream Libertarianism. It actually fits perfectly well into the role the majority of libertarians believe a state should take.

To begin with, from my understanding they merely proposed a solution which the community has to agree to implement. Just like modifying the bitcoin codebase.

It's still ultimately an additional layer of decentralization in between. Taken as a whole - even if Ethereum takes action against the attacker - what DAO represents would still be very very far from the representative democracy style system that libertarians take issue with.

Importantly, libertarians are not all anarchists (or 'crypto-anarchists' or 'anarcho-capitalists' to be more accurate) who believe in total decentralized control structures. Mainstream libertarians wish for a minimal state or "night-watchman" state, a not the total absence of a state.

This the most prevalent myth about libertarianism and the faulty premise of most attacks against it.

Even many hardcore anarcho-capitalists are against the idea of decentralized judicial and law enforcement systems - as they see it as unworkable.

In the book "Anarchy, State, and Utopia" [1] popular libertarian thinker Robert Nozick argues that

    [..] only a minimal state "limited to the narrow functions of protection against force, theft, fraud, enforcement of contracts, and so on" could be justified without violating people's rights. 
Therefore supporting the solution Ethereum proposed does not make you less of a libertarian. But it does make you less of a crypto-anarchist.

[1] https://www.amazon.com/Anarchy-State-Utopia-Robert-Nozick/dp...

Re: Critical Update on DAO Vulnerability

#514

This is what concerns me about contract programming. With human contract law, if there's a minor typo or loophole, participants can generally see the spirit and intent, and at worst go to a judge who will usually enforce the intent. But with software contracts, only the characters matter and there's no intent anywhere: either you get paid or you don't. ETH is advising, "Contract authors should ... be very careful abo…

Unlike traditional contracts, the idea was that smart contracts were going to eliminate the need for enforcement or dispute resolution. So that law is enshrined in code. But this incident has set a precedent, at least within Ethereum, that the project leadership will intervene to enforce the spirit of a smart contract. So what now are the benefits of Ethereum smart contracts over the traditional legal system? The way…

The miners have always been the arbiters. That's implicit in verifying transactions via their consensus.

Re: Critical Update on DAO Vulnerability

#515

Earlier quoted context omitted.

Commenting on your second thought: I hoped that people behind DAO (and Ethereum?) will stick to the terms they themselves proposed but it seems they will push hard for forking the chain (see: Ethereum blog).

Maybe someone can write an insurance contract that future DAO authors can hire, as an alternative to interventions. It would have to be bug free.

Step 1: Write an insurance contract against the malicious use of Ethereum

Step 2: Find someone foolish enough to accept the other side of the insurance contract, in a world where "insurance fraud" is no excuse

Step 3: Use Ethereum maliciously, stealing your own Ether under another identity

Step 4: Collect insurance

Step 5: Profit (in Ether)

Step 6: Good luck turning your Ether into actual money when people figure out how broken everything about it is

Re: Critical Update on DAO Vulnerability

#517
post #495

Earlier quoted context omitted.

Maybe someone can write an insurance contract that future DAO authors can hire, as an alternative to interventions. It would have to be bug free.

This is a smart response. The insurance company could also review the contract code in order to provide cover -- this would give investors extra confidence.

Suppose that I want to make a medical device, and I want to get liability insurance for when a bug in its code administers a lethal dose of radiation to a patient.

Is there any extant insurance company that would want to review my code in exchange for a lower premium?

If not, why would one be willing to do this for a flash-in-the-pan cryptocurrency, but not a useful, real-world device?

Re: Critical Update on DAO Vulnerability

#518

Earlier quoted context omitted.

Keep in mind Ethereum is less than a year old, the DAO is even younger. It's still new, risky, and fraught with problems that need to be solved. If you're not familiar with anarcho-capitalist theory, there's a concept called a DRO -- dispute resolution organization [1] -- that can perform arbitration functions in a decentralized manner, i.e. without a monopoly on judicial services like the state. In the future, as th…

This is fascinating. How do ancaps propose that DRO's will enforce their judgments? With violence? What's to stop the losing party from just gathering a bigger militia and shooting back to prevent collection?

The most effective way is likely ostracism, or some other penalty based on reputation. If someone doesn't pay their debts, people just stop trading with them. I'd posit that most people are interested in restitution, rather than punitive measures, which would be the primary goal of a DRO -- making the victim whole again. This is why DROs would likely function similar to an insurance agency.

The non-aggression principle is a central tenet in ancap philosophy which would preclude violence in most cases, however, it is permitted in self defense of ones person or property. Still, most people who subscribe for a DRO probably aren't going to want to pay the high costs for a standing militia. Would you voluntarily pay taxes for the War on Terror, or the numerous other military boondoggles across the globe, if you had a choice and knew the actual costs?

This ventures into the territory of private defense agencies, which decentralize security services, and is a deeper subject. If you want to dive in, I'd suggest Michael Huemer's book "The Problem of Political Authority: An Examination of the Right to Coerce and the Duty to Obey" in which he debunks the Hobbesian war of all against all scenario. "Practical Anarchy" by Stefan Molyneaux is also a decent (and free to read) overview of how ancap voluntarism could work, but Huemer's arguments are more comprehensive.

Re: Critical Update on DAO Vulnerability

#519

Earlier quoted context omitted.

This is FUD, broadly speaking. The devs have put out a patch for miners which allows them to decide whether or not they wish to fork over these transactions. Centralization is not required for this decision, instead, distributed consensus. The counterpoint to your statements is simply that consumers need safety with their money. It is no badge of honor to let unsophisticated technical people lose money for some extre…

I agree with your points. But the miners who actually have a say, if I am not mistaken, are the big ones and the pool owners. These are just a small fraction of all people running mining software. A soft fork will undeniably require distributed consensus. It is the number of people with the actual right to vote that may be worrisome. Perhaps the pool owners should extend their voting rights to their pool contributors…

Or, pool owners could announce their position, and you could switch pools. This has happened in Bitcoin, albeit very occasionally.

Re: Critical Update on DAO Vulnerability

#520

I wrote this attack up last week -- a solidity dev initially noticed this bug, but seemed to think it wasn't a big deal. http://vessenes.com/more-ethereum-attacks-race-to-empty-is-t... The comments here are generally spot on; it's a combination of problems -- upgradability is designed to be hard because other people's money shouldn't be easy to steal, programmers are not used to making whole programs reentrant, exist…

> That said, there just aren't enough people looking at these contracts right now I hope this doesn't kill the project. Having programs that give you money when you find bugs in them could be a very powerful incentive to develop new tools to write correct code.

I've been thinking the same thing!
Post reply on HN