Live data from Hacker News

Critical Update on DAO Vulnerability

blog.ethereum.org

81–90 of 629 posts

Re: Critical Update on DAO Vulnerability

#81

Earlier quoted context omitted.

Presumably the attacker will stop short of doing anything that would completely destroy the currency, since they now own a lot of it

I think they could also be shorting ETH, in dollars/euros/rubles/yuans, in which case destroying the currency would be excellent business for them, even if they can't extract what they stole.

Any (presumably buoyant) entity actually offering that possibility?

Re: Critical Update on DAO Vulnerability

#82
post #53

Earlier quoted context omitted.

What grey/black market sites accept eth. Pretty sure most of them historically have been Bitcoin based.

eth is traded to and from bitcoin on various exchanges, so it's a parallel.

>eth is traded to and from bitcoin on various exchanges, so it's a parallel.

eth is also traded to and from USD on various exchanges, so that's a parallel, too?

Listen, I'm no ethereum fanboy here, but logic, let's use it.

Re: Critical Update on DAO Vulnerability

#83
post #53

Earlier quoted context omitted.

What grey/black market sites accept eth. Pretty sure most of them historically have been Bitcoin based.

eth is traded to and from bitcoin on various exchanges, so it's a parallel.

So is the USD and a bunch of other currencies, what's your point? You can also trade ETH for USD on most big exchanges.

Re: Critical Update on DAO Vulnerability

#84

I always though that Etherium had a huge attack surface. Each script has to be security audited, etc. That's the thing about Bitcoin. It's as simple as possible while still being secure and useful and has been beat up and audited by the best security pros in the world. Distributed Systems are not easy. Secure distributed systems with Byzantine fault tolerance are even harder. Etherium is just trying to do too much.

Doesn't this show an issue with the Distributed Systems on Ethereum, with every script that has to be audited individually, and not with the platform itself?

I'm with you on the fact that proper auditing is an absolute must, as this DAO fiasco shows, but I don't think this event exposes any flaws in the Ethereum platform itself.

Re: Critical Update on DAO Vulnerability

#85

Is this related to https://www.ethereum.org/ ? "Ethereum is a decentralized platform for applications that run exactly as programmed without any chance of fraud, censorship or third-party interference." Right ...

Oh, it is absolutely right (as far as we know). But "exactly as programmed" doesn't mean "exactly as intended" it means "exactly as programmed", with bugs and vulnerabilities and all.

' “This is the land where dreams–dreams, do you understand–come to life, come real. Not daydreams: dreams.” There was about half a minute’s silence, and then with a great clatter of armor, the whole crew were tumbling down the main hatch as quick as they could and flinging themselves on the oars to row as they had never rowed before. . . . For it had taken everyone just that half-minute to remember certain dreams they had had–dreams that make you afraid of going to sleep again–and to realize what it would mean to land on a country where dreams come true. ' - C. S. Lewis’s Voyage of the Dawn Treader

Re: Critical Update on DAO Vulnerability

#86

Just remember, when the developers inevitably appear with suggestions about how to stop the hack, roll back the blockchain, or come up with other schemes to block the hackers, they are showing everyone that all the talk of blockchains being decentralised, or being beyond the control of governments or other powers... is a complete lie. If this hack can be stopped, then it demonstrates that the currency can be manipula…

Also remember that this isn't the first time this idea of 'lets rollback a blockchain due to a hack/attack' has been floated or even tried. The first major blockchain rollback almost completely destroyed the cryptocurrency [1]. Since then, some major hacks have happened and the community/developers rejected the idea of a rollback [2][3]. That was a hard lesson, and hopefully the current developers will learn from the…

One could argue that at this point in its history it stands to benefit more from that efficiency than it would from more robust decentralization.

When adoption is low it stands to reason centralization would be high, and so it enables them to move faster to increase adoption, and hence lower centralization as other players and stakeholders enter the game.

However it does also stand the risk of allowing the current influential parties (the developers or miners) to influence the system in their favor. So far though, I don't think this has been the case, but we'll see how this situation plays out.

Re: Critical Update on DAO Vulnerability

#87
post #81

Earlier quoted context omitted.

I think they could also be shorting ETH, in dollars/euros/rubles/yuans, in which case destroying the currency would be excellent business for them, even if they can't extract what they stole.

Any (presumably buoyant) entity actually offering that possibility?

[deleted]
Post reply on HN