Live data from Hacker News

Critical Update on DAO Vulnerability

blog.ethereum.org

541–550 of 629 posts

Re: Critical Update on DAO Vulnerability

#541
post #539
post #507

Earlier quoted context omitted.

Not sure where you're saying Gödel's incompleteness theorems come in, but I agree that DAO is a game of Nomic. Now... the ability to hard-fork is kind of in the rules as well. So it's a Nomic with a complicated endgame. Some guy just won the Nomic, but now he's finding that not only do you want to win, you want to win subtly , or else a majority can vote to undo your win. But anyone who still thinks DAO is an investm…

"Not sure where you're saying Gödel's incompleteness theorems come in, but I agree that DAO is a game of Nomic." I know what he means - he's suggesting that you can't ever get a bulletproof or watertight set of rules or guidelines for a system because ... blah blah ... Gödel's incompleteness theorem. This is a very tempting idea and I myself have given it a lot of thought over the years. The problem is, Gödel's incom…

The law isn't a formal system so I'm pretty sure incompleteness doesn't apply in a straightforward way.

Re: Critical Update on DAO Vulnerability

#542

Earlier quoted context omitted.

Commenting on your second thought: I hoped that people behind DAO (and Ethereum?) will stick to the terms they themselves proposed but it seems they will push hard for forking the chain (see: Ethereum blog).

It might also be a question of survival. If $36 million+ is drained from the DAO itself unintentionally at such an early stage, can they continue, and how confident can anyone be that their implementation will be successful if the reference implementation itself is not?

If the DAO is not ready for survival now, then no amount of protecting it will make it ready for survival. What will make the DAO survive is code that only contains bugs that are too difficult to find relative to the value of finding them.

Re: Critical Update on DAO Vulnerability

#543

Earlier quoted context omitted.

This is fascinating. How do ancaps propose that DRO's will enforce their judgments? With violence? What's to stop the losing party from just gathering a bigger militia and shooting back to prevent collection?

The most effective way is likely ostracism, or some other penalty based on reputation. If someone doesn't pay their debts, people just stop trading with them. I'd posit that most people are interested in restitution, rather than punitive measures, which would be the primary goal of a DRO -- making the victim whole again. This is why DROs would likely function similar to an insurance agency. The non-aggression princip…

"If someone doesn't pay their debts, people just stop trading with them."

... Unless that impacts their bottom line. In reality, this is unsolvable - if it were, boycotts, divestments, and employer blacklists would be far more effective. You can always find scabs that will compromise on principle in order to put food on their table.

Re: Critical Update on DAO Vulnerability

#544

Earlier quoted context omitted.

Indeed, but you have bug-safety law around the world which incorporates something like : "If there is a typo, error, fraud, crime etc. a contract is considered invalid or the part of the contract that is flawed" With software bugs you have something similar : > NO WARRANTY. THE SOFTWARE IS PROVIDED TO YOU “AS IS” AND “WITH ALL FAULTS.”

Who decides what a typo is? "Oh, that contact for 1000 dollars is really 10 dollars because they 'missed' a decimal place. You still have to uphold your part though." Corruption of judges can be a problem in that space and that is in part what this is attempting to solve. A lofty goal, maybe even impossible, but certainly worth the time to try.

I UPvoted your comment.

Aside from everything. In writing a contract, it's very common to write price with numbers and letters in brackets next to them. E.g. 1000$ ( one thousand dollars ), exactly because typos happen.

The decision what a typo is is made by the parties, in case of dispute then by several courts ( based on the evaluation of the contract ). That's at least in continental law system.

There's a way to specify a 3rd party court ( non-corrupted one, called arbitrage ) which can solve disputes for that contract.

Corruption of judges problem is being fixed also in several ways. Usually decisions in high courts are decided by 3 judges ( again continental law ) and sometimes a jury ( prevailing in anglo-saxon law system ). Also there is a way to appeal the decision of the court to a higher court(s).

Re: Critical Update on DAO Vulnerability

#545

Earlier quoted context omitted.

So that means if you are against majority thought you are shit out of luck. Just think of any time when majority consensus hasn't been the optimal solution.

If you believe that there is a better way to find a consensus in a distributed system than majority you are free to implement a system based on it. I consider it as quite plausible that such a system exists, but cannot even imagine how it might look like.

There is a better way but it unfortunately requires the system to have an understanding of what the decision is about - in other words, no longer decoupling the mechanics of the decision from the meaning of the decision.

A distributed system can easily make a majority decision that is unwise, like if the votes are based off of bad information. But if the different options of the decision could be formalized and checked/proven as part of the decision making process, based off of axioms and values that participants all agree on, then perhaps the most rational decision could be selected even if it's not what the majority was initially in favor of.

Re: Critical Update on DAO Vulnerability

#546
post #280

Earlier quoted context omitted.

Unlike traditional contracts, the idea was that smart contracts were going to eliminate the need for enforcement or dispute resolution. So that law is enshrined in code. But this incident has set a precedent, at least within Ethereum, that the project leadership will intervene to enforce the spirit of a smart contract. So what now are the benefits of Ethereum smart contracts over the traditional legal system? The way…

Agreed. If this soft and hard fork idea really goes through, it seems that now you are in fact getting the worst of both worlds: For your contract, you have to write code that apparently is very hard to get right and bug-free[1], while at the same time you are at the whim of a "community" -- whose decisions (sorry, "suggestions") can apparently be announced by one guy in a blog post -- not to deem what you are doing…

I think this comment on the original blog post says it very well:

"To be clear, if this happened due to an exploit in the software, then I can accept a hard fork fixing the issue. However, if the DAO team made a mistake in the way they designed their smart contract, as an issue of principle, they should not be "bailed out" by the Ethereum team because they are "to big to fail." Hard lessons like these teach the cryptocurrency community at large to do their homework and to be excessively (and obsessively) diligent with their security."

I agree with this.

Re: Critical Update on DAO Vulnerability

#547
I currently don't own any etherium. I'd like to point out that those who are saying that this mean there's a "too big to fail" concept within etherium are missing the key point that when the US (and other places) did too big to fail bailouts it was a concerted effort between unelected central bankers and government officials who are percieved to not necessarily have the best interests of the people in mind. At least if etherium makes a decision that the DAO is too big to fail, it will have done so via consensus, and parties that don't like it can take their assets and leave.

Re: Critical Update on DAO Vulnerability

#548
post #513

"They say 'there are no atheists in foxholes.' Perhaps, then, there are also no libertarians in crises." [1] [1] https://www.hks.harvard.edu/fs/jfrankel/CatoRespCrisesJun07+...

(Not to take this post too serious, but I'll take the bait) I'd argue that the solution proposed by Ethereum in this blog post is not antithetical to mainstream Libertarianism. It actually fits perfectly well into the role the majority of libertarians believe a state should take. To begin with, from my understanding they merely proposed a solution which the community has to agree to implement. Just like modifying the…

Doesn't necessarily make you less of an anarchist either. Anarchy isn't an absence of rules or decisions, it's having decision making mechanisms that are non-hierarchical (now, the preferred size of those decision making structures and how to keep them from becoming psuedo (or real) States in their own right is a whole different discussion). In this case, one could argue that miners are making a decision collectively through a very imperfect mechanism (subject to possible hijacking, attacks, and tyranny of the majority), but still a non-hierarchical one.

Re: Critical Update on DAO Vulnerability

#549
post #67
post #22

Earlier quoted context omitted.

Is this a weakness on Ethereum or the DAO?

The fact that many scripts written suffers similar vulnerabilities unless extensive (and, seemingly failure prone) mitigations are applied, suggests that the root cause is a known design flaw in the ethereum smart contract architecture. Doubly so when the latest reviewers of this systems and custodians of the DAO include the system's creators. When building systems that provide irreversible transaction processing, sa…

Ethereum is a general purpose system: it has sharp edges. We can use the same reasoning to condemn C/++'s pointers (people trip over themselves all the time, even serious audits occasionally miss big bugs), but we still survive with C code running much of our lives. If there's issues with implementing in ethereum code directly, there are many ways of addressing it and only some of them view the issue here as a 'flaw' rather than a 'hard to use feature'.

Ethereum just has to work. It doesn't have to be pretty. It doesn't have to be easy. Being pretty will help it work, but there's enough money on the table, and TheDAO demonstrates this, that it will advance on alternative institutions if it works.

TheDAO may never be 'safe' or 'perfect'. It only has to be safe right now, from the threats that real, interested parties are capable of implementing. This list of threats is quite large at 250,000,000$, and will be larger when/if TheDAO/its descendants hit 250,000,000,000$+.

Post reply on HN