Another successful DAO attack recursive split
reddit.com
reddit.com
The price of Etherium has fallen about 35% since this started. The Etherium market cap has dropped from $1.5bn to under $1bn. Volume hit an all time high, and the price is still in a screaming dive as people try to get out.[1]
I wouldn't be surprised if the person behind the exploit turns out to be an insider. That would be in keeping with cryptocurrency tradition. In the Bitcoin world, most of the major "hacks" turned out to be insider theft.
(It actually works on all instances of the DAO's code address, not just the famous ~$150M instance.)
https://github.com/ethereum/go-ethereum/pull/2715
> There's simply the notion of --illegal-code-hashes that takes a list of hashes that are placed in "ignore-mode".
Indeed, isn't it arguable that said insider(s) (and I agree it's probably an inseder) should identify themselves and challenge the leadership who are damaging their own credibility and that of ethereum generally? All these rollbacks -> they are the ones which are arguably illegal as they override the code. In my view, the so-called thieves have a legitimate claim on the ETH they have made and the investors in the DAO should respect the old caveat-emptor idea which is axiomatic to all investments, both inside and outside the blockchain world. They invested in a dog, and they should lose all their money. This is efficient markets at work.
The correct analogy is that the exploiters shorted the investment after performing thorough due diligence, and made a profit doing so, at the expense of more ignorant investors. That those more ignorant investors included the founders of ethereum and the authors of the code, is deliciously ironic especially considering (perhaps even because of) their own self-importance[1], but it is ultimately immaterial.
question 2: those worth less than 1m USD -> who do they sue? The "thieves" who were acting according to the terms and conditions? Or the DAO itself?
I don’t know why they didn’t reduce the computing power, so it becomes much easier to reason and automate the reasoning about contracts.
Do they really need Turing completeness?
This could be one of the better things about Bitcoin's blockchain: it's simpler and easier to reason about.
Of course not, this is why Bitcoin only supports a handful of transaction types which closely mimic things you might do w/ paper checks or cash.
About the Turing completeness, is there any limit to what you can calculate? What's to stop me from doing a contract that eats up an unreasonable number of calculations? That could easily be something that works fine when n is small but explodes when a bunch of different people are involved. Something that might be hard to check beforehand.
As for being hard to check beforehand, you're absolutely right. You can read about the consequence of this in one case on this reddit thread: https://www.reddit.com/r/ethereum/comments/4ghzhv/government...
This model should work in the long term. Just make sure not to invest too much on too complicated contracts that do not re-use smaller proven contracts.
This assumes that compositions of unexploitable contracts are themselves not exploitable, which isn't true in general.
I'm not saying that there will not be flaws, but this dynamic where there is an incentive to exploit the contracts (be it composed or not) makes contracts which stood longer more interesting.
This is one way to get a free code review /s
There was an issue raised on their repo to make exploitable bugs private [4]. So far it doesn't appear to have gained traction but I wonder, what will it say about decentralized communities, and the focus on the sanctity of their code as a contract, if it's accepted.
[1] https://news.ycombinator.com/item?id=11928936
[2] https://github.com/slockit/DAO
The most recent bugs that appear to have been fixed are still present in the running instance of the DAO.
(Prompted by your post, I have since edited my previous post to clarify the intended wording.)
Could such a possibility not be used to change smart contracts post-facto?
If this is even possible, what prevents the holders of The DAO's account keys from deploying a new "Send all outstanding balance to this wizard" version of the code?
If it's not possible to change the running version of a smart contract, how does the community plan to deal with these sorts of problems?
Out-of-band would be something like m-of-n control of a secret 'update' key where any properly signed update-to-script-X message is accepted. You'd vote by providing your segment of the key, or not.
In-band would be something like the DAO but where there was a special "update self" proposal with some set of quorum and rules all enforced in-script.
Both have their place. In-band is more transparent, and can have a lot of complexity modeling the intended domain. (Classes of shares with more voting power, auditors with vetoes, etc.) Out-of-band is more likely to work in cases where the script has major bugs.
Unless there's a provision to allow for that, it isn't possible.
If there is such a provision it would likely be for the old contract to forward funds to a new contract and simply "step aside". Everyone would use the new contract but refer to it with the same name.
It seems easy to screw up. To end up breaking the new contract too, or have funds still pile up at the old one that it was no-longer capable of forwarding, etc. Even if there is a provision it may not actually be useful.
> If this is even possible, what prevents the holders [...]
Well, nothing. (Do you have their home addresses?)
That's why there often isn't a provision for it, it's a catch-all such as "or any terms that may be added at a later date."
You wouldn't sign that contract, would you?
Why is this even controversial? Lots of projects embargo dangerous vulnerabilities.
My libertarian-leaning friends were not so amused.
It's just too bad that the experiment was orders of magnitude larger than it needed to be. But if most of that was speculation and greed, then little value has been lost.
This is hard-tech sitcom.
"oops, just a practice!"
i don't think it's any coincidence that's how it works in the 'real world' either, with big banks and governments.
at the end of the day, it's about people. money isn't real.
If they rolled the whole system back and said, "Ok lesson learned. Let's not fuck this up again." I could get behind that. People who get ahead by doing some black-hat stuff would be pissed, but to bad for them. Maybe they'll decide to stay away.
If they give DAO a hard-fork refund, they're going to need to convince the community that this wont happen again, or explain the rules about when it might happen again. Otherwise, no one is going to trust the system.
That's just not very wise.
I don't know if I buy it, but there it is.
The bitcoin world now has "consensus" meetings which from an outsiders' perspective look a lot like the kind of meetings at Davos that bitcoin was supposed to be against, only without regulation, consumer protection and any recourse against bad actors within the upper spheres of influence.
In future of ethereum there'll have to be "arbitration committees" which will look a lot like courts. Self-appointed, unregulated courts of course.
I am in full control of which currency I use when transacting.
Ethereum is a bad idea and people are too embarrassed to admit it. I get it. However, turning around and shoehorning that sentiment into "They don't understand central banking" is just foolish and highlights the sort of headstrong obliviousness that has essentially springboarded DAO into the spotlight to begin with.
Smart contracts aren't good for stupid users. Someone outsmarted a big group, now they're having a fit because all of their money is going to leave, and rather than walk away from the poker table with their head hung low, they've decided to just rob the dealer and try for heisting the vault while they're at it.
And then they have the gall to say "Oh, you just dont understand the purpose of central banking" as they oppose a system that they put in place to benefit themselves, by themselves.
I am long on cryptocurrencies but the community at large needs a reality check to see where they currently fit.
Watching this rapid evolution towards traditional legal systems reminds me of an oddball scifi story about life on the surface of a neutron star. Everything moves so quickly that, by our perspective orbiting the star, civilizations may rise and fall within days.
Not a great idea for a currency.
You could equally say that the threat of collapse of the US government dilutes the utility, marketplace and value of the US dollar. Sure, it's true, but it's irrelevant.
You're... kind of agreeing with me here.
The reason a threat of a fork works is because it had the results I mentioned.
Basically what is the point you're trying to make?
With Bitcoin, most issues were a result of private organizations misappropriating money or security. But the entire foundation of Ethereum is now considered completely unreliable.
Considered by who? The bugs are in the smart contract, not Ethereum itself.
Like a certain programming language's features, it may happen to be easier than not.
You can in addition implement these safety checks to be executed during runtime, but that costs money.
The door lock company is the funniest part of the whole thing. It makes this meltdown so much less surprising tbh.
Somewhat related: the lock in my apartment is actually based on cryptography too. It uses SHA-1, which is somewhat scary, because it's not considered "safe" anymore. The algorithm was probably chosen because it uses less energy compared to safer ones, as the lock gets the energy from the turning of the key.
The EVM may be reliable, but the humans that use it are completely unreliable, and it's the humans that form the foundation of any distributed system.
(Another big problem with Bitcoin at scale is that you can't count it without access to the keys that let you spend it. This makes outside auditing very difficult and helped to enable the Mt. Gox scam. Etherium doesn't address that. Some multi-signature scheme where external parties could determine that an account has funds without the key needed to take them would be useful for a cryptocurrency. But, as Etherium shows, adding complexity adds exploitable bugs.)
Correct me if I misunderstand, but checking that an account has funds is trivial. It's in the blockchain. Multi-signature transactions are also standard.
That's not remotely true, I'm not sure what gave you that idea. Bitcoin at its core is based around asymmetric encryption, which allows only 1 party to send money but everyone to verify it. By sharing a public key (a bitcoin address) you can see the funds, but can not spend it. In fact, right from the start bitcoin client even included the ability to sign and verify messages from addresses to prove ownership. Right now I could give you the bip44 (public key) of my wallet and you could see every transaction I have received, sent (and all future ones, from that wallet). But you'll have no ability to spend my money. Although I'm not going to do that for the same reason most people won't: privacy.
Anyway, there's been proof of solvency schemes for a long times, it's just most exchanges and services (with a few notable exceptions) haven't seen a business case in implementing it.
So yeah, an exchange like Mt Gox can not prove they own the USD they should own, but can prove they own the bitcoin they claim to own. How is this a problem or limitation of bitcoin again?
I'm not an expert, but I'm pretty sure one could use the private key, without revealing it, to sign a message, for example "%date I, %owner, own the bitcoin in $account".
Then anyone else could check the signature against the public key on the blockchain.
Would that not be enough?
"Commerce on the Internet has come to rely almost exclusively on financial institutions serving as trusted third parties to process electronic payments. While the system works well enough for most transactions, it still suffers from the inherent weaknesses of the trust based model. Completely non-reversible transactions are not really possible, since financial institutions cannot avoid mediating disputes. The cost of mediation increases transaction costs, limiting the minimum practical transaction size and cutting off the possibility for small casual transactions, and there is a broader cost in the loss of ability to make non-reversible payments for nonreversible services. With the possibility of reversal, the need for trust spreads. Merchants must be wary of their customers, hassling them for more information than they would otherwise need. A certain percentage of fraud is accepted as unavoidable. These costs and payment uncertainties can be avoided in person by using physical currency, but no mechanism exists to make payments over a communications channel without a trusted party."
The problem with [a trusted central authority] is that the fate of the entire money system depends on the company running the mint, with every transaction having to go through them, just like a bank.
Sure, it's hard to say exactly what Bitcoin is for or against, given that it's a multi-faceted community with many different goals. But to deny that decentralization and lack of central planning is a huge motivation / driver / goal of both the original inception of Bitcoin, and also the community that developed around Bitcoin, is pretty hard to believe.
The original poster insinuated Bitcoin needed all-powerful policy planners ("Davos meetings"), which is false. All that is taking place is community discussions about scaling (block size increase), but it would be absolutely incorrect to compare this to "Davos meetings".
If we're going to blow so much computer power on raw calculations, we could use it for Folding@home, SETI@home, or any number of other great causes. But this is just a waste.
So, beware of status quo bias.
After spending 4 years in bitcoin and having watched all the copy+pastecoins fail similarly to alternative internets I can say that any new blockchain isn't revolutionary or innovative in the way most people shallowly believe in the hopes of finding "the next bitcoin". It's already here just accept it.
Or it will just die once users have to pay the real transaction costs and it becomes really obvious how expensive that system is.
Bitcoin by contrast is "inconvertible digital money made legal tender by no-one because it's not legal tender".
So.. it's fiat in the sense that "by fiat" sense - which is where fiat money as a term comes from, but not in the strict "fiat money" sense of the phrase.
Oh really? Please do explain why a government would ever allow bitcoin to challenge its currency.
So governments & financial institutions will certainly embrace blockchain tech as a potential way to possibly reduce transaction paperwork (read eliminate backoffice jobs) but anonymity which underlies bitcoin is unlikely to be supported by governments.
It's quite another thing for paavokoya to make the bold claim that bitcoin will replace government fiat currencies. That won't happen. Government currencies like USA dollars and Euros are backed by courts and police. Bitcoin doesn't have that. Bitcoin usage beyond the trivial can always be suppressed by the government. All it takes is for the government to pass a law that says, "property purchased with bitcoin is null and void".
Any non-government crypto-currency exists at the pleasure and amusement of the government.
Government has the ultimate power and infuses that power into the fiat currency. That power is spread across tax collectors, courts, and law enforcement. On the other hand, bitcoin can't create its own "Bitcoin Sovereign Island" with its own sympathetic government. Alt-coin enthusiasts overestimate the ability of bitcoin to overthrow government sponsored money.
USA dollars are not "backed by courts and police" (what does that even mean?).
Property cannot be null or void, so a government decree as such would be meaningless.
>Government has the ultimate power
Maybe under some theories, but again, not in the US. In the US, government power is derived exclusively from the people, by the people.
>Property cannot be null or void, so a government decree as such would be meaningless.
Sorry for writing in shorthand and not making the meaning clearer. It's not the property that's nullified but the transaction of that property.
Ok, you agree to buy a car or domain name from a seller for 100 bitcoins. After you pay the 100, the seller keeps the keys/title/domain. You go to court to help recover your "money" -- aka bitcoins, because it was a fraudulent transaction. The court doesn't recognize the transaction because it doesn't recognize bitcoin as legal consideration. Case closed. You then try to go to the police/sheriff to seize "your" property. The police ask for the court order. You don't have one.
If the government wants to pass a law stating that bitcoin transactions are not recognized, it can do so. It doesn't have to pass such a law at the moment, because bitcoin transaction volume is trivial.
>In the US, government power is derived exclusively from the people, by the people.
Did the "power of the people" stop FDR from confiscating gold?[1] Gold was even more entrenched than bitcoin is today. Did the "power of the people" direct the government to take their 1980 dollars and reduce its purchasing power to 1/3rd in 2016?[2]
There's a difference between repeating the ideals of "government of the people, by the people, for the people" from Lincoln's Gettysburg Address and the reality of how government actually exercises its power _against_ the people.
If Bitcoin activity got so large that it threatened the USA government's power to manipulate its Federal Reserve Notes to pay debt obligations (at least in nominal terms) or inflate the money supply to pay for Social Security & Medicare, it will make all bitcoin transactions null and void by decree.
Therefore, I disagree with paavokoya that Bitcoin will make fiat currencies like US Dollars and Euros "obsolete". Bitcoin doesn't have that power because Bitcoin doesn't come with its own courts, police, aircraft carriers, etc -- a.k.a. all the apparatus of government. It's the backing of government that enabled the US Dollar to become a global reserve currency.
[1]https://en.wikipedia.org/wiki/Executive_Order_6102
[2]http://data.bls.gov/cgi-bin/cpicalc.pl?cost1=1000&year1=1980...
I don't understand what this means. Courts don't only consider cases where you pay ordinary money for an exhcange of goods. Contracts exist for purely material exchanges, so I don't see "give me bitcoin for X" wouldn't count.
Eventually, I believe one of the two things would happen:
(1) Bitcoin becomes part of the "system", like Paypal, Amazon, and Visa. It remains one of the handful of convenient methods of transaction for some situations. Some of its early adopters publicly denounce it as corrupted by the government and mega-corporations, and move on to greener pasture.
(2) Bitcoin loses its initial lure and dies off.
I think it's safe to say that governments will not allow things that will seriously threaten their fiscal policy. For all the wonders of cryptocurrencies, they have to intersect with the real world in order to be useful.
The 'decentralized' attribute is a big lie, and it's good illustration how big lies successfully operate today as they did in the past centuries. They just need repetition.
The reason that Ethereum is particularly silly, is because there are no underserved code execute'rs. (Go to Alphabay or Bovada if you doubt this)
Who exactly falls into this category?
I would also not be a huge fan of spending tens of millions of Dollars every year on electricity and hardware to heat the planet and process an amount of transactions that could easily be processed by a single centralized server for a fraction of the costs.
What an incredibly rude thing to even say. While it is 100% the fault of the people who "invested"(if you can call it that) in this. At the end of the day its someone else's hard earned money, perhaps stupid at spending, but hard earned money.
I honestly feel really bad for the people who are loosing so much of their money, it should not happen to anyone. Its a horrible horrible situation for the people involved.
http://bitcoincharts.com/markets/bitfinexUSD.html
Looks up close to 100% in two months.
I'm not sure why you'd find this satisfying, unless you hate innovation.
Also, I agree that the same Dapps can be run with Bitcoin, so it's not like everyone needs to switch to Ethereum. It does have some advantages over Bitcoin, though that might not be enough given the huge adoption Bitcoin has already.
"I am disappointed by those who are characterizing the use of this intentional feature as "theft". I am making use of this explicitly coded feature as per the smart contract terms and my law firm has advised me that my action is fully compliant with United States criminal and tort law."
There's much argument over whether this is a hoax.
There's a good writeup in American Banker.[2] They question whether the rules should be changed.
Patrick Murck, a lawyer and researcher at Harvard University's Berkman Center:
"The contract is the code, it's unstoppable code, it's unbreakable, it's self-executing and autonomous — right up until everything goes wrong. And then, 'No no no no, that's theft!' Which is some social norm that we've attached to it that's not based in the code, and then we're going to stop the whole system and basically bail it out," he said. "Is this something we're going to do every time a smart contract fails? Or is this just because there are a lot of [Ethereum] insiders in the DAO?"
[1] http://pastebin.com/CcGUBgDG [2] http://www.americanbanker.com/news/bank-technology/what-the-...
[1]: https://www.reddit.com/r/ethereum/comments/4oo1io/an_open_le...