Live data from Hacker News

Smart Contract Security Field Guide

scsfg.io

71–80 of 156 posts

Re: Smart Contract Security Field Guide

#71
post #27

Can someone give me a good use case (even better if you're doing it yourself) for a smart contract? What is anyone doing with them that they find really handy? I've never been able to understand how it gets used / why you would use smart contracts. I've googled and read... still don't grok it. I've seen so many "benefits" listed, but none make sense to me as far as the process you go through and how it works out in t…

Typically I like to read HN comments for insightful discourse focused on details of the topic at hand by relevant experts. It is a terrible failing of HN that this useless comment is promoted to the top.

It is like if there were a detailed blog post about rusts type system and I was to comment “Why would anyone use rust when they could use X instead?”

Please stop upvoting this comment.

Re: Smart Contract Security Field Guide

#72

Earlier quoted context omitted.

How exactly does the Spanish bank get the USD that the American bank sent without trusting a third party?

They may be willing to accept trusting the dollar-backed token issuer. In the case of USDC, it's Circle. But there's nothing stopping JPMorgan, BoA, Wells Fargo, Western Union, etc implementing their own dollar backed tokens, and I suspect we'll see more and more of that as regulatory clarity settles. Maybe the Fed themselves will issue tokens in this way. It's also entirely possible to construct a permissioned, yet…

Your first and last sentence contradict to each other. If you already have a third party which both sender and receiver of money can trust, what's the point of blockchain?

Re: Smart Contract Security Field Guide

#73

Earlier quoted context omitted.

I find posts like this honestly infuriating because its like you don't know the first thing about an entire, specialized field, yet because its something taking place in tech you feel like you're qualified to write about it. Ask the same question about chemistry, biology, electrical engineering, or any STEM subject, and here's the actual answer: it's beyond the scope of a comment on hacker news to spoon feed you an e…

counterpoint: engineers building complicated things /and then looking for a problem they would solve/ is bad. if you are unable to easily explain it to a human who isn't your profession, it's snake oil. what's a tooth filling? it's a bio-safe, quick setting, similar plasticity to your teeth enamel. what's shipping logistics software? it's not wasting an idle or half empty truck. what's S3? durable object storage. wha…

All of your examples are trivial and deal with every day concepts. Blockchain technology intersects cryptography, computer science, government, politics, economics, finance, information security, probably even sociology and philosophy. It's multi-disciplinary.

The idea that something needs to be simple to be legitimate is not a good one. Some things simply are complex and to say otherwise is to over-simplify them. Or reductionist. Much of the ground work requires questioning assumptions that people are already familiar with and accepted as true. Like the trust assumption in banking.

I can tell you first hand that when I pitched my blockchain startup back in 2013 the very first stumbling block I had was even getting people to understand Bitcoin. So go ahead and tell me that a large, in-depth field must mean its invalid. I think that's a silly idea.

Re: Smart Contract Security Field Guide

#74
post #48

Earlier quoted context omitted.

Explanation: bankA -> bankB -> bankC. bankC creates a secret number, hashes it and sends it to bankA. bankA sends money to bankB locked to hash. bankB can't get money until they have that secret number. bankB sends money to bankC locked to hash. bankC reveals secret number to bankB to unlock that money. bankB does the same with bankA. Tada, we eliminated the risk of bankB running away with money. This is the lightnin…

> we eliminated the risk of bankB running away with money This isn't a real risk with correspondent banks. Instead, it's counterparty risk: bankB failing while it holds the funds in transfer. That risk can be mitigated with smart contracts, but it's not eliminated. (Correspondent banks also take a portion of the client bank's fraud and AML risk.)

I think the bank failing risk is eliminated, if it fails the forwarded payment is unlocked so bankA gets their money back.

Re: Smart Contract Security Field Guide

#75

Earlier quoted context omitted.

I genuinely cannot tell if this comment is veiled sarcasm or not. That or a question about concrete, practical examples of this tech and what unique advantages smart contacts bring to the table has hit a real nerve and set you off. If the latter is the case, that is of course a telling answer in itself.

It's not this specific question. It's the fact that any time anything about blockchain tech is posted on hacker news the first comment will be 'b-but where are the use-cases' with the second being something like 'lol scam.' It would be the equivalent of replying to every HN post with 'but why would anyone want to own a personal computer?' That's how irrelevant and uninformed these posts are.

Asking about practical applications of a relatively mature technology is an entirely, 100% legitimate question to ask. It is frequently asked about many other techs and advances, although it's also frequently omitted since the answer is obvious and readily available/forthcoming. Not so with pretty much anything blockchain. So yeah, if a technology is a solution in search of a problem for ten years, that's gonna come up a lot, and it's entirely fair. What else could be more relevant than that question, given all the hype?

>but why would anyone want to own a personal computer?

Both you and I can effortlessly come up with a dozen or two concrete answers (reality, not hypotheticals) to this question with no preparation whatsoever. Can you come up with just one single example for smart contracts? Reality, not hypotheticals. Heck, I'd settle for hypotheticals that are at least well on their way to reality.

Re: Smart Contract Security Field Guide

#76
post #27

Can someone give me a good use case (even better if you're doing it yourself) for a smart contract? What is anyone doing with them that they find really handy? I've never been able to understand how it gets used / why you would use smart contracts. I've googled and read... still don't grok it. I've seen so many "benefits" listed, but none make sense to me as far as the process you go through and how it works out in t…

I find posts like this honestly infuriating because its like you don't know the first thing about an entire, specialized field, yet because its something taking place in tech you feel like you're qualified to write about it. Ask the same question about chemistry, biology, electrical engineering, or any STEM subject, and here's the actual answer: it's beyond the scope of a comment on hacker news to spoon feed you an e…

Nah, supporters of most of the tech (chemistry, biology, EE, whatever) can easy explain applications to layman, as well as explain why one would use it over alternatives.

There are some exceptions of course -- one example is "memristors", an very specialized EE concept that claims to revolutionize computing for least 20 years and yet never does. And if you look at its HN discussions, you'll see mostly skepticism and negativity, kinda like for blockchains.

Re: Smart Contract Security Field Guide

#77

Earlier quoted context omitted.

OK, great example, so I'll explain why a smart contract couldn't work here at all. So, to start, going to be clear I'm using your specific example of "escrowing funds on purchase of a piece of real estate (and I mean actual, real, real estate)". Simple enough. But, at the end of the day, who is to say "the keys you gave me are really the keys to the house you said you sold me"? That is, there needs to be some way to…

More than just needing an oracle - the keys and the house are both physical items. There's not really any practical way for a contract on the blockchain to validate that a particular physical item is in fact the item that it purports to be. Are these ACTUALLY the keys to this house? Are they the only set? The original set? Were the locks changed, and this set in the contract is no longer valid? Then putting aside all…

Thinking of a real estate transaction as an exchange of physical things is already a mistake. Most people expect to take possession of a structure in most deals, but it is sort of beside the point. What you're trading is a legal filing where you go to the county recorder (most states) and just claim to own something. What are you really buying? The promise from the other guy that they won't claim to own it in the future. But, under our deeply stupid title system, there really isn't a guarantee that the seller "owns" it in the first place. All kinds of people could have claims on it.

In a legal system this vague, smart contracts simply do not have a niche.

Re: Smart Contract Security Field Guide

#79

Earlier quoted context omitted.

counterpoint: engineers building complicated things /and then looking for a problem they would solve/ is bad. if you are unable to easily explain it to a human who isn't your profession, it's snake oil. what's a tooth filling? it's a bio-safe, quick setting, similar plasticity to your teeth enamel. what's shipping logistics software? it's not wasting an idle or half empty truck. what's S3? durable object storage. wha…

All of your examples are trivial and deal with every day concepts. Blockchain technology intersects cryptography, computer science, government, politics, economics, finance, information security, probably even sociology and philosophy. It's multi-disciplinary. The idea that something needs to be simple to be legitimate is not a good one. Some things simply are complex and to say otherwise is to over-simplify them. Or…

Can you give examples of things which are "simply are complex and to say otherwise is to over-simplify them" and that are not either blockchain or snake oil?

Note that internal operation does not really matter, only applications do; I might have no idea how CRISP/CAS works, but I can totally understand some of its applications and why people call it revolutionary.

Re: Smart Contract Security Field Guide

#80
post #27

Can someone give me a good use case (even better if you're doing it yourself) for a smart contract? What is anyone doing with them that they find really handy? I've never been able to understand how it gets used / why you would use smart contracts. I've googled and read... still don't grok it. I've seen so many "benefits" listed, but none make sense to me as far as the process you go through and how it works out in t…

Governance of next-generation automated economies and societies.

It's one thing to make a promise to someone. It's another to marry your business procedures directly to immutable code which guarantees to users, employees and partners that the business operates in the intended and described way.

Most of these benefits require your company to be digital in nature, but many asset-based economic systems can benefit from it.

For example, automatic, trustless guarantee of both quality of transport and payment for shipping goods. Sensors in a transport vehicle continually update a decentralized semi-private blockchain, proving that an item never left a refrigeration state, or was not tampered with.

Automatic payment could be achieved by placing the item inside a locked stationary container at point of delivery and validating through this blockchain that all requirements were met.

A system like this could go even further to make guarantees to the end customer, who could verify at point of sale that their food item remained fresh.

Post reply on HN