Trust: the inside story of the rise and fall of Ethereum
aeon.co
aeon.co
The reality is that Ethereum as a platform has gained strength, credibility and market traction over the last six months. There have been 3 hard forks and 1 soft fork, partly in response to the system being under almost continuous attack (mostly denial of service). The effective response by Vitalik and company has increased trust, not decreased it. As the saying goes: "What does not kill you, makes you stronger."
More and more developers building applications on top of this platform. The MelonPort token sale ICO (on the Ethereum platform) sold out in 2.5 minutes yesterday.
It's not just independent Ramen-fueled startups, but "enterprise Ethereum" has become a thing. JP Morgan, Santander, Microsoft, Redhat, Cisco, Accenture, etc -- for better or worse -- are joining the Ethereum bandwagon.
I think it is still way early to call a winner in the blockchain platform wars. There are dozens of well-funded competitors trying to gain dominance over established platforms like the Bitcoin technology stack and the Ethereum platform -- including IBM-led Hyperledger Fabric and the bluechip banking consortium led by R3CEV.
But if there is one dog at the top of the blockchain platform heap right now, it is Ethereum.
See:
http://www.coindesk.com/jp-morgan-santander-said-join-enterp...
https://media.consensys.net/the-birth-of-enterprise-ethereum...
https://www.reddit.com/r/ethereum/comments/5u6uhb/melonport_...
- the price is pretty stable relative to early Bitcoin.
- Vitalik and the other devs are still building out economic/game theory models. And Ethereum has successfully made a hard fork. That suggests the organization has some leeway to skate where the puck is going, so to speak.
- it's very early days in terms of building out the "standard library". Lots of people working on this, collectively and privately. It's a little like the railroad tracks have been laid but they are still building the trains, not to mention stations.
- Ethereum has the benefit of being overshadowed by Bitcoin, which insulates it a bit from speculators and scammers. This is only a temporary effect, but I think obscurity helps Ethereum grow smart and slow right now.
- the forums are all about things being built with Ethereum. Bitcoin has a chicken and egg problem, where retailers need to get on board for consumers to care. But nerds can sit down and make something useful on Ethereum today.
I would put one check on this endorsement, though. Ethereum is uniquely useful in situations where you can't trust anyone. It shines in that environment.
Mostly though, we do trust the people around us. I think once the Ethereum community starts releasing big trustless e-institutions, it will be clear that most of them could run just fine with Venmo, WebRTC, and a little JavaScript.
So I think Ethereum will always have a more back-office feel, and I don't quite see it being on The Today Show any time soon.
But Vitalik Buterin is very smart and I wouldn't bet against him.
Now it's established that there's a chance a contract can be "too big to fail".
I think it would have built more trust if they had let the money go. To paraphrase a saying, they would have spent 15% of ETH on training everyone to build safe contracts, and to vet contracts properly before "investing" in one.
If you hold this view you're going to be very unhappy with the many innovations we'll see in the blockchain space in the coming years: Almost every technology in the future is going to put the desires of the community ahead of any specific piece of code- Computer code is a tool, not the final decision maker.
Yeah, especially in systems where the fundamental model is code is law
The whole pitch of ethereum was that it was supposed to be an objective platform, free of human bias, to execute contracts. "The code is the law", they said.
Of course, that was a big fat lie; someone made a shitty contract with a loophole in it. When someone took advantage of that loophole, the devs said "uh, just kidding" and reversed the whole thing.
If I wanted a contract system where humans were able to void contracts, I would use the traditional legal contract system. Ethereum no longer has any advantage.
And the law can change if the community deems it wise.
> nor really how Ethereum was advertised
This meme is kind of silly to me: Would it be false advertising for BMW to say "Pushing the gas pedal makes the car go forward" after a single BMW had to be taken to the shop because of a broken gas pedal?
(I'm talking about advertising for ethereum in general, not for the DAO itself. I agree the DAO advertising was totally inexcusable for many reasons. I wish I had had the guts to say so more publicly at the time.)
Ethereum even now advertises itself on its homepage as
>Ethereum is a decentralized platform that runs smart contracts: applications that run exactly as programmed without any possibility of downtime, censorship, fraud or third party interference.
But clearly, we had a program that very specifically ran exactly as programmed, and its operation was interfered by a third party (the community hard-fork). Ethereum offers a guarantee that is not held; this is false advertising.
If it is a guarantee that cannot be held, it is still false advertising.
But even more so, Ethereum imagines itself to have no established authority; to be decentralized. But obviously, it is not. The final say clearly remains with the Ethereum developers, even if the community has the option to secede. (You can renounce your citizenship from the US, everyone can wholesale, but this does not mean the US has no centralized authority.) Bitcoin, of course, offers the same situation; the difference being that bitcoin's authorities do not collude, and by community happenstance, it is unlikely that they will. Such a fork is unimaginable in that universe.
Ethereum (and its many users) imagines itself to be of Bitcoin's equivalence, a large enough and stable enough network that offers little ability and incentive for its authorities to collude. But, of course, this is false. It remains small enough that a hard-fork is viable; proven by the act of a hard-fork.
This is false advertising, in the sense that it misrepresents fundamental components of the system. It might support decentralization given a sufficiently large network, but it does not (yet) have sufficiently large network. But either it pretends its network is sufficiently large, or it pretends that requirement does not exist.
Most of the issues with currencies(and most everything) is trust and the motivations of other people. Technology might help democratize a world currency, but those who corner the market first will have major influence over it, which in turn will quickly result in the same imbalance in power which was trying to be avoided.
In other words, the code isn't the law, which is exactly what I said.
So I'm not sure that it's really all that distinct from legislative majorities in traditional legal system (and clearly less of a genuine majority than in legislative systems where the public retains, whether or not it chooses to frequently exercise them, powers of initiative and referendum.)
In this system, no transaction is actually final, because it can always be rollbacked because the reversal of a law can traverse time and space. The only gaurantee is once you've got it converted to cash (exited the network) because the network may simply enter a parallel universe where the law never existed (and unlike a hostile government invading another, with all the repurcussions of it, this is a manuever taken by the existing government, and likely it remains the government in the new universe).
This isn't a law then, its simply a communally accepted rule; if the ratchet turns, and community decides slavery is no longer acceptable, then it'll be applied retroactively and you'll be rendered an illegal actor for operating legally at the time of operation, despite operating legally now (no longer dealing in slaves).
It's a pillar of modern democracies that the effects of some law, can only be applied to future events not to past ones.
What ETH did, was create new laws and then proceed to apply them to previous actions. Very untrustworthy indeed.
In the ETH case, you are creating a law to REVERT a previous deal. Democracies don't do that.
So yes, it's possible your transactions will get reversed, but only if you've done something so horrendous that you've pissed off a large majority of the entire community, and in that case you'll likely still have your valid transaction on a working chain, it's just that a lot of people will have gone elsewhere.
A large economic majority of the community, you mean. Which gets to the heart of my largest misgiving about these networks: They are so transparently libertarian in striving to embody the Golden Rule ("He who has the gold makes the rules"). If a big actor makes a mistake that benefits 1,000 small actors, the little guys still get fucked.
If the US operated like this, Bill Gates would have ~500,000 more votes than the average American. You could argue that wealthy actors already exert outsize influence on our meatspace contract system, but I'd argue it's to a much lesser extent, and anyway, I don't see Ethereum offering much of an alternative. They don't even pretend to try to strike a balance between individual and community justice.
Economic majority is a copout, and it looks an awful lot like feudalism. As a little guy, I'm hesitant to hitch my wagon to that particular star.
The main point of the article isn't that people are losing trust in Ethereum. It's that there's no platform that truly avoids the need to trust other human beings (as some apparently believe). That code is not absolute law because the community can choose to change it and affect pre-existing contracts. I don't think he bashes Ethereum at all, but is just making the case that, if you believe you can rely on a platform like this to avoid the need to trust in human decisions, you're fooling yourself.
These days publications are continually A/B testing headlines.
This is that trust can never really be fully automated, it is ultimately a human phenomenon. And that is just what happened, the Ethereum community decided, on the basis of the sorts of reasons that human beings normally use, that the whole project and the people running it are trustworthy, and so has charged ahead.
As for "The DAO", the biggest question on their forum is "How do I get out?"[1] Apparently the DAO is dead, but they seem to have kept the money.
It's true some employees at the ethereum foundation had personal money invested in the DAO. Vitalik himself had a small amount invested as well. However, the Ethereum Foundation was not involved with the DAO.
> If it had been anybody else, they would have lost the money
This is idle speculation, and I personally don't think that's true.
> Apparently the DAO is dead, but they seem to have kept the money.
I don't know who you mean by "They" but neither the creators of the DAO, nor the Ethereum foundation has kept any money that was lost in this unfortunate incident. If you're going to accuse people of things please provide citations with evidence.
[1] https://medium.com/curator-multisig-phf-official-channel/dao...
The Foundation itself may not have been invested, but many of the members and core contributors were (Gavin Wood, core contributor of the Rust implementation, was rumored to have over $100k in DAO tokens).
> neither the creators of the DAO, nor the Ethereum foundation has kept any money that was lost in this unfortunate incident.
The hard fork, by definition, allowed everyone to keep what would have been lost.
And it wasn't an "unfortunate incident", it was a publicly stated inevitability, advertised not only by the platform (with the words "unstoppable code" on the home page) but by the authors of the DAO themselves ("Any and all explanatory terms or descriptions are merely offered for educational purposes and do not supercede or modify the express terms of The DAO’s code set forth on the blockchain;").
I didn't agree with the fork, and I choose to follow the majority of miners anyway because I still believe in Ethereum, but quit trying to rewrite history.
The hard fork had a lot more to do with the fact the overall community didn't thought the system would survive the eventual switch to proof of stake if 15% of all ether was in the hands of malicious actor. There was also the moral matter that something could indeed be done to actually return the stolen money to their original owners, there was consensus to do the fork and so the fork happened.
The author of Casper, Vlad Zamfir, clearly stated on numerous occasions on Reddit that there was no risk to PoS b/c of the hack.
> There was also the moral matter that something could indeed be done to actually return the stolen money to their original owners
That's a really nice way of phrasing "we have a moral right to help gamblers recoup their losses."
That's a bit cynical to call the token holder gamblers, sure many of them "invested" thinking they would get some return back, but a lot of people were genuily curious in participating in this decentralized democracy experiment that never came to be. Regardless even if these people were 'gamblers' stealing is still stealing and returning stolen money is the right thing to do.
This was a lot less decentralized than the PR indicated.
That's incorrect, He was previously in the Ethereum Foundation but left (due to disagreements with Vitalik) long before the DAO was created.
I wasn't that interested in it, but the idea of programmable contracts was intriguing. The main issue is that they should be declarative/logical in nature, as that's what most contracts are, instead the primary language was imperative and had a weak type system (inexpressive). Has this situation improved or are all contracts written in it still destined to have many bugs due to the poor language design?
EDIT: Had to look it up, forgot the name, it's Solidity.
http://www.stephendiehl.com/posts/smart_contracts.html :
> "Solidity, while being an interesting proof of concept, is dangerously under-contained and very difficult to analyze statically."
Solidity docs are here: http://solidity.readthedocs.io/en/develop/solidity-in-depth....
No referential transparency, no purity, no algebraic data types . . . it's scary stuff for writing contracts.
It sounds like the core team has realized what a hole they're in and are taking it seriously, which is great. But I think a lot of the Etherium-related businesses still have no idea what a sandy foundation they're building on. It's going to be ugly.
A few developers I know use Serpent because it is simple and stable (meaning it has not been changed or updated for a while, unlike Solidity which they say is continually being tweaked in a manner that can be aggravating).
Interestingly, Vitalik's preferred language (say for prototyping Casper algorithms) is Python. He created Serpent and is now working on Viper, which sounds like a next-generation Serpent. Viper is being implemented in Python3.
You can see the work in progress at: https://github.com/ethereum/viper
I think there are some really cool ideas in Etherium. Proof-of-stake is great. Provably terminating functions are great! These ideas deserve to be paired with a higher level language worthy of them.
https://www.reddit.com/r/ethereum/comments/5u6uhb/melonport_...
Relatedly, from the Reddit thread:
> ICOs have nothing to do with ethereum. They can raise by any cryptocurrency existing or that will exist in the future. So far, they've mostly been used for scams, although I'm sure some legitimate projects will also be funded.
Is there a meaningful response to this? This is a serious question - how can I tell the difference between an ICO scam, and one that isn't? Are there any examples of sustainable businesses arising from ICOs, or are all of them pump-and-dump schemes?
If I get defrauded by a company putting out an ICO, will anyone go to jail?
I will attempt to debunk a few of the most important errors in this article.
In short, the author takes the position that the promise of blockchains is immutability; and that by hardforking, Ethereum proves that "immutability" requires trust:
> We aren’t actually trusting the blockchain technology; we are trusting the people that support the blockchain.
We should start by observing that un-mutated Ethereum - Ethereum Classic - still exists. You can mine its blockchain and run contracts on its virtual machine. So whatever point there was to be made about the untrustworthiness of "immutability" seems false, since the "immutable chain" is still there chugging along. The only problem is that nobody actually wants immutability, once they really think through its permutations.
---
I will posit that "immutability" is a red herring. While some people did promise immutability, this was a false promise made by some people. Other people have instead said for years that consensus blockchains like Bitcoin are not - and don't need to be - in fact shouldn't be - "immutable." I will further posit that this is in fact the majority view.
In fact there is a perfectly clear reason why a blockchain might "mutate" and fail to honor the contract as it is written in code: the contract sufficiently harms the economic majority of miners and holders.
And that is why such "mutability" is not bad, but in fact desirable. Otherwise, all that is needed is the invention of some sort of poison contract, and then the network would be unable to administer its own antidote.
This is in fact what happened when someone mined some 90M Bitcoin in 2010 while everyone else was running code that considered these to be valid coins. Obviously, there was a fork, and the perpetrator's 90M Bitcoin were taken out of the ledger. And a good thing, too: if "the code was really the law" then those would still be 90M valid Bitcoin and the whole project likely would have been dead some time ago as the malactor would own something like 90% of the money supply.
> The code was supposed to be the law. If you didn’t see the weakness in the software, that was your problem
Ironically, because this is in fact a true statement, the author's point is exactly wrong.
The code is the law - not just The DAO's code, but also Ethereum's code, on which The DAO depends. Ethereum code is not only also "law", but in this sense, it's the "highest law in the land" with respect to contracts executed on its virtual machine.
It should be patently obvious that Ethereum's code permits forks, "soft" and "hard." It should therefore be patently obvious that any promise of "unstoppable contracts" is simply overpromise. The Ethereum global VM came to consensus that The DAO was not just a failed contract (buggy Ethereum contracts happen all the time) but a failed contract so toxic as to be a threat to consensus.
So, by following one chain, a group of users may declare its will that The DAO contract be "held invalid." By following another chain, a different group may declare its will that the DAO contract be held "valid." Each group actually got its will.
---
Consensus blockchains like Ethereum and Bitcoin are not "immutable" and never were, in the sense that all it takes is someone to mine a fork, and the chain "mutates." This is the "permissionless innovation" aspect of blockchains: anyone can create a fork - though it takes a lot of hashpower to protect a fork from hashpower attack.
But on the other hand, consensus blockchains are immutable in the sense that nobody can compel you to follow a "mutated" chain and you are always free to continue to mine on the original chain. Moreover you can hold coins on either - or both - chains. This is the non-compulsory nature of blockchains: nobody is forced to hold coins on anyone's fork - though it takes a lot of money to protect the value of a forked coin.
Since anyone can create a fork, but it takes a lot of hashpower and coin holdings to sustain a fork, the system on the whole is highly resistant to - but fortunately not completely immune from - hardforks.
Even "contentious" hardforks. Like the DAO rollback.
The beauty is that hardforks provide automatic market choice. One day there's only one Ethereum, and the DAO attacker who holds a not-insubstantial percentage of the entire money supply. Then there's a fork, and everyone who held Ethereum now holds coins on two chains - Ethereum and Ethereum Classic, and can signal to the market by holding coins on one chain and selling them on the other - or hedge by holding coins on both chains.
Do we really want true "immutability?" In the case of Ethereum, the market of Ethereum users was offered a choice of either "mutated Ethereum" and "non-mutated Ethereum." Since the split, the market has fairly consistently valued "mutated Ethereum" over "non-mutated Ethereum" roughly 10:1 - and as the article points out, even "non mutated" Ethereum Classic found itself facing a hardfork. Uh oh.
Forks are good, because they allow markets to place bets on which outcomes they prefer. It's also good that it's really, really hard to create economically-viable fork.
Getting back to the first paragraph of the article:
> on that day, after much deliberation and hand-wringing, in the aftermath of a multimillion-dollar swindle from his automated, algorithm-driven, supposedly foolproof corporation, Vitalik Buterin, then 22 years old, announced the ‘hard fork’ of the cryptocurrency Ethereum.
Vitalik is a respected developer. I think there's a valid argument to be made that certain high-profile devs carry more influence than is their due - but no developer controls any consensus blockchain - not Ethereum, not Bitcoin. Ethereum, like all consensus blockchains, is "controlled" by its ecosystem of miners and users.
"Devs propose, the market disposes." And we have seen - the market preferred the forked Ethereum.
> By making that announcement, Buterin shattered certain tightly held assumptions about the future of trust and the nature of many vital institutions that make modern life possible.
I hope by now we see that the only thing that Ethereum shattered is the overpromise and undesirability of "immutability."
---
I hold in each hand a cryptocurrency.
In the left hand, I offer a truly immutable cryptocurrency. The economic fundamentals of this currency cannot be changed by the will of man even if things start going wrong with the initial assumptions upon which the money was based.
In the right hand, I offer a self-improving consensus blockchain-based cryptocurrency. This currency cannot be easily forked, but when it does, two things will be true: the market must value the change quite badly to stimulate a fork, and you will be permitted to hold coins on either side of the fork as you see fit.
Take your pick.
[edits: a lot of stuff - I got onto a bit of a long topic and realized it needed some editing. It still does.]
Minor aside, unlike Bitcoin, Ethereum doesn't use hashpower (proof of work) as its voting currency, it uses proof of stake.
So in order to convince the network of a lie, you need to be willing to put up monetary bets against the truth, and then pay them.
This is very unlike Bitcoin, where you buy your mining rig, and then own it. If you pay to fork Ethereum, your real money is at stake.
And the financial incentive for people with even more money than you is to call your bluff and put up a bigger bet against your lie and get the cash and get your lie taken off the books.
Although they have the price structure set up so that calling a bluff is much cheaper than lying. So really even someone with a tenth of your budget can afford to call your bluff.
It downloaded 500MB on my SSD and I stopped it, I've read that it has to download about 15GB. Thats too much for me. Do the other projects download such big blockchains also ? I mean 15GB for each project ?
1. Geth/Mist now supports a "light client" mode that requires much less storage and maintains most of the strong crypto guarantees.
2. Most of the size problem is due to the complexity in efficiently optimizing the serialized data, this will improve in the near future.
3. Ethereum is on the forefront of research into scalable blockchain technology, which has the potential to resolve this problem.
In theory though, through the magic of Merkle trees, a superlight client could get away with needing only a few KB of storage, accounting for the paths through the Merkle tree that witness its spendable outputs. A discussion about such a setup for Bitcoin can be found for instance at
https://bitcointalk.org/index.php?topic=88208.msg1896213#msg...
I don't know of any crypto-currencies that have implemented these UTXO commitments that would allow for such wallets though...
Exactly once a week, a story like this pops up. Mostly written by someone who thinks that "blockchain is the new big-data of the cloud".