However, the rest of us are also perfectly free to adopt a fork if we wish.
However, the rest of us are also perfectly free to adopt a fork if we wish.
I get why everybody is upset, but this was pretty much bound to happen. Security of this kind is an all-or-nothing item, you have to get it 100% right or it might just as well not happen at all. So all this backpedaling and fixing does absolutely nothing in my view to strengthen the concept.
The only way forward would be to declare this version a total loss and to do a reboot with a better core and then to see how long that one will stand up.
Rinse and repeat until one really stands (by then confidence will likely be quite low) and accept that it could still go down at any point in the future.
A bit like the Monty Python sketch about the castle built on swampland.
Anything less will not do, either the contract is all there is or it is pointless.
I beg to differ. If those events come to pass, the DAO will be far from dead!
On which side of such a lawsuit you are is not important, the fact that the DAO can not be trusted to be complete and that there is a possibility that contracts once executed can be rolled back makes it un-viable in this incarnation.
Personally I think it was oversold, this lesson could have been learned a lot cheaper but that's easy to say after the fact. As bug bounties come this was a pretty good one, and I'd be highly surprised if it was the only flaw in the present implementation.
The attacker tried to exploit a flaw in TheDAO's code to steal its ether, not because it was designed to allow that or because that was the intent of its designers, but because he could.
Well, the Ethereum community can also do something that was neither intended nor planned for. You say that doing so would be a breach of contract. I say: Well, go ahead and sue me.
> Well, the Ethereum community can also do something that was neither intended nor planned for.
Of course they can. And that will make the whole concept moot.
> You say that doing so would be a breach of contract. I say: Well, go ahead and sue me.
No-one will. But then also: no-one will ever trust the concept. It either works or it does not, you can't say it works and if it doesn't we'll fork. That's simply institutionalizing unreliability.
The attacker has - very elegantly - pointed out a major flaw in the whole thing in a way that not much else could have: in the end we all have to either trust some higher power to interpret the context in which a contract was drawn up or we will have to live by the letter of the contracts. You can't have it both ways.
I think they will. In time, one of us will be proven right.
Philosophically I wonder about this "the exact code defines the semantics of the DAO" clause because, well, nobody's suggesting to change the code; the fork proposals would just change how the code is interpreted.
Kind of like "this exact Java code defines the terms of the contract" but then a new version of Java makes that code behave differently...
So the clause depends not only on the Solidity code but also on the Ethereum virtual machine's interpretation of that code, and the question now is whether that interpretation is constant or mutable.
And, like, what's even the legal status of the https://daohub.org/explainer.html document? It has a list of things to which anyone who interacts with "The DAO" supposedly agrees, which seems like a typical groundless EULA and anyone who "invested" could just say "uh, I didn't agree to any of that stuff".
I'm not really making an argument, I just find it bewildering to even imagine how any of this stuff would be interpreted by lawyers.
Agreed, and that's essentially what we're seeing here, some kind of rough equivalent between lawywers hacking human language and programmers hacking code. A 'smart' lawyer is equivalent to a hacker, finding a loophole in the law to enforce some novel interpretation of the letter rather than the intent of the law.
Trying to do an end-run around a whole bunch of established systems all to end up with re-inventing the exact problems of those systems that you were trying to get away from in the first place, it's kind of funny.
"The terms of The DAO Creation are set forth in the smart contract code existing on the Ethereum blockchain at 0xbb9bc244d798123fde783fcc1c72d3bb8c189413. Nothing in this explanation of terms or in any other document or communication may modify or add any additional obligations or guarantees beyond those set forth in The DAO’s code. Any and all explanatory terms or descriptions are merely offered for educational purposes and do not supercede or modify the express terms of The DAO’s code set forth on the blockchain; to the extent you believe there to be any conflict or discrepancy between the descriptions offered here and the functionality of The DAO’s code at 0xbb9bc244d798123fde783fcc1c72d3bb8c189413, The DAO’s code controls and sets forth all terms of The DAO Creation."
Emphasis mine.
from:
https://daohub.org/explainer.html
So yes, I'd interpret that as forks being 'right out'. It's either 'all terms' or it isn't.
This is the primer to the how it is supposed to work: https://blog.slock.it/a-primer-to-the-decentralized-autonomo...
Here is how it was attacked: http://vessenes.com/deconstructing-thedao-attack-a-brief-cod...
Also, strictly speaking it's not all the same people who might be bound by the contract as those who would do the forking.
DAO -> DOA either way.
That's what makes this attack so elegant, it strikes at the heart of the problem rather than 'just' take some money.
An even worse attack would have been to do this slowly over a longer period of time, which would make it even harder to roll back (but would have increased the chance of discovery before the damage was this large).
That must have been a tough decision on the part of the attacker.
As far as I see, that means there's no guarantee that Ether will be accepted by other parties, and no obligations on Ethereum miners, a de facto counterparty to the contract, not to agree to modify their own code. Of course, third parties [some of them with conflicts of interest] forking Ethereum is against the spirit of the "contract", but so was exploiting a recursion bug.
Which just goes to show that you still need to trust those with voting rights not to collude against you in a supposedly trustless system.