Oh, nobody saw that coming. Completely unforeseeable. What other mature, ready-for-primetime autonomous altcoin networks can I dump my savings into for no apparent reason? Edit: "DAO token holders and ethereum users should sit tight and remain calm. Exchanges should feel safe in resuming trading ETH." No they shouldn't. They should running screaming for the exit doors. Less than two months after the launch of this my…
WTF. There is the equivalent of millions of dollars in this blockchain? How?! Who willingly puts real cash up front for this kind of thing? Just... what?!
Critical Update on DAO Vulnerability
601–610 of 629 posts
Re: Critical Update on DAO Vulnerability
#602"The "hacker" simply used the DAO as it was meant to be used ... and deserves the funds." Exactly. DAO is CoreWar meets Nomic. https://en.wikipedia.org/wiki/Core_War https://en.wikipedia.org/wiki/Nomic Designers of rulesets (laws, board games, markets, control systems) ignoring Gödel's incompleteness theorems should themselves be ignored. Just like we ignore inventors of perpetual motion machines who ignore the laws…
Re: Critical Update on DAO Vulnerability
#603Earlier quoted context omitted.
Keep in mind Ethereum is less than a year old, the DAO is even younger. It's still new, risky, and fraught with problems that need to be solved. If you're not familiar with anarcho-capitalist theory, there's a concept called a DRO -- dispute resolution organization [1] -- that can perform arbitration functions in a decentralized manner, i.e. without a monopoly on judicial services like the state. In the future, as th…
What's crazy to me about the whole thing isn't the bug in the DAO nor the fact that it's being taken advantage of. As you say, it's all very early stuff, and there's no surprise that it hasn't been fully worked out yet. What does surprise me is that people poured the equivalent of tens of millions of dollars into this new, unproven thing. To me, this says that while Ethereum itself may be technologically fine, the co…
Re: Critical Update on DAO Vulnerability
#604Earlier quoted context omitted.
> I have a (maybe naive) question: why is the person draining ETH from DAO called "attacker"? George Soros wasn't (afaik) breaking any law or contract when he drained a billion dollars from the Bank of England in 1992. I think most people in the UK would be OK with describing that as an attack.
I like this analogy, but no one tried to reengineer finance or the law to prevent Soros from spending his earnings.
Re: Critical Update on DAO Vulnerability
#605Well, that was kind of inevitable. Building a financial system out of pure code with no humans in the loop and no legal structure is building a self-distributing bug bounty piñata. It's decentralised, so there's nobody who can throw a breaker and shout "stop!"; cryptocurrency transactions are irreversible, so thefts are permanent; and it's somewhat anonymous, so thefts are hard to trace. It also demonstrates that bei…
I find it endlessly amusing that people are willing to bet their cold hard cash on "this code has no bugs". When widespread old and tested code like OpenSSL has massive security bugs, what chance does something as new and in-development as Bitcoin/Ethereum have? An in the case of Ethereum, the contracts themselves?
It's not "this code has no bugs" it's "this code has less visible bugs than the lower hanging fruit". If it's harder to find than any bug in any system with bitcoin (or other ethereum) in it, then people will find that stuff first. Bitcoin gave us out here in the IT world, for the first time in history, a realistic way to measure the large-scale security of various kinds of systems. Microsoft, for example, has not had the bitcoin from any of their wallets stolen. With every flaw that's found, we get the chance of learning how not to fail in the future.
Furthermore you have to invest in something. And it's remarkably hard to invest these days. Just try buying a house with ethereum, see how frustrating it is.
Re: Critical Update on DAO Vulnerability
#606Earlier quoted context omitted.
Not sure where you're saying Gödel's incompleteness theorems come in, but I agree that DAO is a game of Nomic. Now... the ability to hard-fork is kind of in the rules as well. So it's a Nomic with a complicated endgame. Some guy just won the Nomic, but now he's finding that not only do you want to win, you want to win subtly , or else a majority can vote to undo your win. But anyone who still thinks DAO is an investm…
"Not sure where you're saying Gödel's incompleteness theorems come in, but I agree that DAO is a game of Nomic." I know what he means - he's suggesting that you can't ever get a bulletproof or watertight set of rules or guidelines for a system because ... blah blah ... Gödel's incompleteness theorem. This is a very tempting idea and I myself have given it a lot of thought over the years. The problem is, Gödel's incom…
As others have corrected that this should be naturals, I'll just also note that you can derive incompleteness just from addition and multiplication over naturals. So while you're correct that plenty of systems don't need full multiplication, you run into limitations quickly. Then you need proper theorem proving to recover the missing verification power.
Re: Critical Update on DAO Vulnerability
#607Seems like I was right.
Re: Critical Update on DAO Vulnerability
#608Re: Critical Update on DAO Vulnerability
#609I have no axe to grind against Eth vis-a-vis Bitcoin. Infact support both. But, try to look at parts of the former skeptically which I think are over sold, without being looked at critically.
[1] https://news.ycombinator.com/item?id=11772397
edit: minor rephrase
Re: Critical Update on DAO Vulnerability
#610Earlier quoted context omitted.
I see a different problem here: Ethereum and the DAO were not in a mature state to handle this amount of money. For example, there is a limited support for upgrading contracts in Ethereum and the DAO was not reviewed enough to handle hundreds of million dollars. Also, there are methods to make the software ultra secure using formal models.
I always wondered why there was such a rush to launch the DAO. As opposed to what Ethereum itself did: develop a proof of concept for over a year, then release a beta version and provide bounties for security bugs, all the while collaborating with testers and security researchers to stress the software.