Live data from Hacker News

Critical Update on DAO Vulnerability

blog.ethereum.org

531–540 of 629 posts

Re: Critical Update on DAO Vulnerability

#531
post #185

It's not as bad as it seems. The hackers have their ETH locked in a Child DAO, so they will not be able to get the ETH out for a long time,by which a fix will be issued. The entire Ethereum Ecosystem is collaborating on a solution. 0. https://www.reddit.com/r/ethereum/comments/4oiib4/dao_is_saf...

Does the child DAO inherit the parent's code? If so, the money could be drained right back.

I think you have to own at least a little bit of the child DAO to drain it, and presumably only the attacker owns any.

Re: Critical Update on DAO Vulnerability

#532
post #280

Earlier quoted context omitted.

Unlike traditional contracts, the idea was that smart contracts were going to eliminate the need for enforcement or dispute resolution. So that law is enshrined in code. But this incident has set a precedent, at least within Ethereum, that the project leadership will intervene to enforce the spirit of a smart contract. So what now are the benefits of Ethereum smart contracts over the traditional legal system? The way…

Agreed. If this soft and hard fork idea really goes through, it seems that now you are in fact getting the worst of both worlds: For your contract, you have to write code that apparently is very hard to get right and bug-free[1], while at the same time you are at the whim of a "community" -- whose decisions (sorry, "suggestions") can apparently be announced by one guy in a blog post -- not to deem what you are doing…

> Agreed. If this soft and hard fork idea really goes through, it seems that now you are in fact getting the worst of both worlds: For your contract, you have to write code that apparently is very hard to get right and bug-free[1], while at the same time you are at the whim of a "community" -- whose decisions (sorry, "suggestions") can apparently be announced by one guy in a blog post -- not to deem what you are doing an "attack".

That's not really fair. His decree does not make it so. It still must be accepted by a majority of the miners, and this is and always has been a known property of the system. The collective will of the miners ultimately trumps the contract system. However, consensus there is purposely extremely difficult to achieve, and likely only possible in extreme cases like this.

Since this was a known property of the system, and since the agreement is inherently democratic, I don't see how this is a problem. Hard forks are simply another behavior of the network. Nothing more, nothing less.

Re: Critical Update on DAO Vulnerability

#533

Earlier quoted context omitted.

Keep in mind Ethereum is less than a year old, the DAO is even younger. It's still new, risky, and fraught with problems that need to be solved. If you're not familiar with anarcho-capitalist theory, there's a concept called a DRO -- dispute resolution organization [1] -- that can perform arbitration functions in a decentralized manner, i.e. without a monopoly on judicial services like the state. In the future, as th…

What's crazy to me about the whole thing isn't the bug in the DAO nor the fact that it's being taken advantage of. As you say, it's all very early stuff, and there's no surprise that it hasn't been fully worked out yet. What does surprise me is that people poured the equivalent of tens of millions of dollars into this new, unproven thing. To me, this says that while Ethereum itself may be technologically fine, the co…

Isn't pouring millions of dollars into new, unproven things the entire premise of venture capitalism? Great risk for great reward.

The outrageous investment in Ethereum/DAO does seem to highlight a desire for governance models outside of the corporatist status quo we live under today, though. Personally, I don't think it's bonkers to yearn for something better. But it's a hope that needs to be tempered with vigilance if people are going to avoid being duped.

Re: Critical Update on DAO Vulnerability

#534
post #347

Earlier quoted context omitted.

1. You just make an agreement with someone who would like to buy your tokens for some national currency. If you ever played an MMORPG or Diablo 2 or something, you know that "imaginary" digital items can be traded for "real" money. There are many exchanges where you can do this conveniently. 2. For one example, consider how tedious it is to open a new bank account; with cryptocurrency, you just make a new keypair. Sm…

>> consider how tedious it is to open a new bank account You make it sound like a person needs to open a separate bank account for every transaction, which is clearly not how people manage their finances. I'm in the same eli5 boat. I can't fathom why anybody would put real cash into such a system. It comes across as "because I'm rich as fuck and can gamble away my money on a stupid tech system that is not realistical…

> I can't fathom why anybody would put real cash into such a system.

They take the risk for hopes of future profit; it's an investment.

> Just... why would anyone use this?

Because they want to see the world change, it's a protest against the current financial system.

Re: Critical Update on DAO Vulnerability

#535
post #532
post #280

Earlier quoted context omitted.

Agreed. If this soft and hard fork idea really goes through, it seems that now you are in fact getting the worst of both worlds: For your contract, you have to write code that apparently is very hard to get right and bug-free[1], while at the same time you are at the whim of a "community" -- whose decisions (sorry, "suggestions") can apparently be announced by one guy in a blog post -- not to deem what you are doing…

> Agreed. If this soft and hard fork idea really goes through, it seems that now you are in fact getting the worst of both worlds: For your contract, you have to write code that apparently is very hard to get right and bug-free[1], while at the same time you are at the whim of a "community" -- whose decisions (sorry, "suggestions") can apparently be announced by one guy in a blog post -- not to deem what you are doin…

The troubling issue with the system that this highlights is that a majority of users can agree to implement a fork which invalidates an existing contract.

As you say, that's a known property of the system. And it might be one of those things that's only viable in practice when the network is young. But can a CFO be considered to have satisfied their fiduciary duty if they write a contract which can be subverted in this way?

Re: Critical Update on DAO Vulnerability

#536

Looks like security agencies are placing extra guards at important national security sites like the statue of liberty, NSA, and Best Buy: http://i.imgur.com/5c9H6DO.gif

Please don't. We detached this comment from https://news.ycombinator.com/item?id=11922131 and marked it off-topic.

Re: Critical Update on DAO Vulnerability

#537
post #532

Earlier quoted context omitted.

> Agreed. If this soft and hard fork idea really goes through, it seems that now you are in fact getting the worst of both worlds: For your contract, you have to write code that apparently is very hard to get right and bug-free[1], while at the same time you are at the whim of a "community" -- whose decisions (sorry, "suggestions") can apparently be announced by one guy in a blog post -- not to deem what you are doin…

The troubling issue with the system that this highlights is that a majority of users can agree to implement a fork which invalidates an existing contract. As you say, that's a known property of the system. And it might be one of those things that's only viable in practice when the network is young. But can a CFO be considered to have satisfied their fiduciary duty if they write a contract which can be subverted in th…

Ya, it's a tricky issue to be sure. But the miners are strongly incentivized to act in a way that minimizes harm to the currency itself. If they start accepting hard forks left and right then ether will lose all its value extremely rapidly. So i'm not really sure the slippery slope argument applies here.

I think this really can be considered a 'one time thing'. It isn't like miners can be pressured by a government to halt contracts for terrorists or other things. They have to be convinced and agree with the argument being made. There isn't a sole individual to whom pressure can be applied here. Granted, Vitalik may wield some influence, but if he started advocating things that were clearly not in the best interest of Ethereum, people simply wouldn't take on his suggested upgrades.

EDIT: I'd also add that for the record, as a DAO token holder, my personal opinion on what should be done is this: A soft fork to prevent ether from moving out of the child DAO, and then nothing. Just burn that ether forever. This avoids the moral hazard problem while minimizing harm to the overall ecosystem. People like me who made the mistake of investing still feel the pain, but Ethereum itself moves forward.

Re: Critical Update on DAO Vulnerability

#538

Just remember, when the developers inevitably appear with suggestions about how to stop the hack, roll back the blockchain, or come up with other schemes to block the hackers, they are showing everyone that all the talk of blockchains being decentralised, or being beyond the control of governments or other powers... is a complete lie. If this hack can be stopped, then it demonstrates that the currency can be manipula…

The developers appear to be treating this as a dev environment - "We were starting a new team (welcome @hiddentao, @evertonfraga and @luclu) and I was pushing for weekly releases, without proper testing. Meanwhile the DAO happened, and we wanted to make a release that had support for events subscription without realizing the performance impact it would have..."

https://github.com/ethereum/mist/releases/tag/0.7.5

I realize this is the wallet development but they are absolutely related and shows the culture of this software is not as professional or thought out as it should be.

Re: Critical Update on DAO Vulnerability

#539
post #507

"The "hacker" simply used the DAO as it was meant to be used ... and deserves the funds." Exactly. DAO is CoreWar meets Nomic. https://en.wikipedia.org/wiki/Core_War https://en.wikipedia.org/wiki/Nomic Designers of rulesets (laws, board games, markets, control systems) ignoring Gödel's incompleteness theorems should themselves be ignored. Just like we ignore inventors of perpetual motion machines who ignore the laws…

Not sure where you're saying Gödel's incompleteness theorems come in, but I agree that DAO is a game of Nomic. Now... the ability to hard-fork is kind of in the rules as well. So it's a Nomic with a complicated endgame. Some guy just won the Nomic, but now he's finding that not only do you want to win, you want to win subtly , or else a majority can vote to undo your win. But anyone who still thinks DAO is an investm…

"Not sure where you're saying Gödel's incompleteness theorems come in, but I agree that DAO is a game of Nomic."

I know what he means - he's suggesting that you can't ever get a bulletproof or watertight set of rules or guidelines for a system because ... blah blah ... Gödel's incompleteness theorem.

This is a very tempting idea and I myself have given it a lot of thought over the years.

The problem is, Gödel's incompleteness theorem applies to a system that contains the complexity of the set of all real numbers. But there are plenty of systems that do not have that much complexity and there are plenty of rulesets we could create and implement that would also not have anywhere near that amount of complexity.

So the analogy sort of falls apart there. It's still worth thinking about, though - the more complex your system of rules/laws/regulations/etc. becomes, the closer you are to a system that is mathematically guaranteed not to be airtight.

Good luck explaining that to lawmakers.

EDIT: YES, CORRECT, SORRY - I did mean to say the set of natural numbers, not the set of real numbers. Mea culpa.

Re: Critical Update on DAO Vulnerability

#540
post #537

Earlier quoted context omitted.

The troubling issue with the system that this highlights is that a majority of users can agree to implement a fork which invalidates an existing contract. As you say, that's a known property of the system. And it might be one of those things that's only viable in practice when the network is young. But can a CFO be considered to have satisfied their fiduciary duty if they write a contract which can be subverted in th…

Ya, it's a tricky issue to be sure. But the miners are strongly incentivized to act in a way that minimizes harm to the currency itself. If they start accepting hard forks left and right then ether will lose all its value extremely rapidly. So i'm not really sure the slippery slope argument applies here. I think this really can be considered a 'one time thing'. It isn't like miners can be pressured by a government to…

I respect that position, the moral hazard question is quite significant, particularly this early in the lifecycle of this network.
Post reply on HN