Letting the hacker walk away with millions at that point would have been silly. It was enough Ether to give the hacker the funds to DOS the system to death for years to come if he wanted to.
Letting the hacker walk away with millions at that point would have been silly. It was enough Ether to give the hacker the funds to DOS the system to death for years to come if he wanted to.
The issue is, the person wasn't a 'hacker' in any meaningful sense of the word.
Etherium claims to be "a decentralized platform that runs smart contracts: applications that run exactly as programmed without any possibility of downtime, censorship, fraud or third party interference" (from etherium.org). That is, an Etherium program doesn't implement a written contract, it is the contract.
Despite this lofty goal, the core team saw fit to hard-fork the chain because they didn't like how a particular program was executing. The claim that the 'hacker' had 'stolen' funds from theDAO is ridiculous - you can only steal what doesn't belong to you, and ownership of theDAO's Ether is defined by the program itself!
More broadly, the hard-fork seems to imply that an Etherium contract is really made up of two contracts. One contract is the program itself, which explicitly spells out what is and not allowed. The other contract is an implicit understanding of what the program 'should' do, and exists only in the minds of the creators of the contract. The issue arises when this implicit 'contract' is used to override the real contract - flying in the face of how Etherium claims to work.
A much better solution would have been to try to address the underlying issues in Solidity - perhaps requiring future contracts to explicitly allow recursion? I personally question the decision to use a Turing-complete language to express contracts in the first place.
There is a new decidable language that compiles to EVM bytecode: https://github.com/ethereum/viper Visually it looks similar to Python. The language is not turing complete, and one of the advantages of this is it's easier write bug free code and easier to verify that the code is doing what you think it's doing.
The reason why the entire EVM is turing complete (and not more limited) is because making it decidable instead is harder than making it Turing complete and would have made the protocol more complex: https://github.com/ethereum/wiki/wiki/White-Paper#computatio...
A Turing-complete language is base layer: you can build any paradigm you want on top.
Since the hack, various small improvements have been made to Solidity, the Foundation hired someone to work full-time on formal verification, there's the new Viper language which is easier to verify, and the community has gotten a lot more serious about coding standards and security audits.
TheDAO very explicitly states that you can't do this: "Your use of the Software does not, in and of itself, create a legally binding contract in any jurisdiction and does not establish a lawyer-client relationship. Your communication with a non-lawyer will not be subject to the attorney-client privilege and (depending on your jurisdiction) may not be entitled to protection as confidential communication."
Honestly, though, I have absolutely no idea what would happen in a legal case involving 'smart contracts', as I don't think there's any precedent involving treating computer programs as contracts.
It would be an interesting case, for sure.
It turns out the code of a smart contract doesn't override the legal system.
Smart contracts aren't legal contracts, though they may be evidence of the existence and content of one.
Of course, strictly speaking that's true of the written documentation of a contract, too.
It also concerned me that it sure seemed like nearly everyone who was in favor of the hard fork had invested in the DAO and nearly everyone who was against it had not.
https://aeon.co/essays/trust-the-inside-story-of-the-rise-an...
Has it undermined their motto "All the news that's fit to print"? Keep in mind, the old NYT still exists with 5% of original capacity.
in The DAO's case, there was a consensus failure in the population but the majority decided to go along with a recovery. There were good reasons to go either way but most people decided this was an experiment, it's early stage, and a move to PoS would be more difficult with a wealthy attacker. I invested but did not want to fork because I was willing to take on the risks. I lost out but I still stick with the main chain because what matters is where we're going with this not where we are. It was a valuable lesson for the community, devs have heavily stepped up investment in security and stability, I doubt anything like it will happen again as even those who were in favor now understand the damaging effects it can have.
still, if you look at the effects it's pretty interesting. You now have ETC and ETH and the market caps for each have waved to reflect the interest in the two competing ideologies. this means blockchains resolve failure through replication and the social effects that happen after can retroactively decide who the winner is or, as it is in this case, you now have two compatible technologies going different directions. ETC is staying PoW, ETH is moving to PoS, both have different governance attitudes and the split has been mostly amicable. not too bad.
edit- I should note this is also true of Bitcoin. the only reason it hasn't split is because its miner and user culture strictly adhere to immutability. if the population decided immutability didn't matter, it wouldn't. there are points of resistance to push back on the way people are but ultimately these things don't run themselves. they depend heavily on incentives.
That's one my my main concerns - the hard fork has set an incredibly dangerous precedent. Etherium has shown that it's willing to jettison the idea of 'code as contract' whenever the code ends up doing something 'bad'. In the case of theDAO, 'bad' meant anything from "people losing a lot of money" to "we found a 'bug' in an experiment that still isn't ready".
>Also many people who supported the Dao fork, would be against the fork today, because there is no more excuse that "we are early and we don't know how to write secure contract code".
but what you really mean is, we've identified a single "attack vector" and now know to avoid it. And, in the process, we've set a precedent that the discovery of any sufficiently large-scale-affecting (or core developer-affecting?) "attack vector" can potentially result in the software contracts being overridden by human action, i.e. a rollback and hard fork. Thus, I personally see no reason to trust the Ethereum network, even though it's full of really cool ideas and technology.
That's probably true in general, but the idea of 'code as contract' is supposed to be one of the defining features of Etherium. If the project wants to move away from that, then it should stop pretending that smart contracts are "applications that run exactly as programmed without any possibility of downtime, censorship, fraud or third party interference."
https://aeon.co/essays/trust-the-inside-story-of-the-rise-an...
Substantial amounts of case law deals with exceptions and courts ruling on how to make things good in situations where there were disagreements between people over what the rules were meant to be, and most of them will not go away just because there's a computer program that can decisively tell us what the outcome of executing the rules exactly as written will be - a court can, and does, for example find that the rules contradict the law, or that the rules are so one sided that they imply there is no meeting of minds and therefore no valid contract.
Substantial amounts of literature lampoons the very idea of static rules to govern behaviour. E.g. Asimovs three laws of robotics represents not an ideal to strive to, but the backdrop that let him spend story after story showing how seemingly straight-forward rules and be circumvented, coopted, or hav unintentional side effects.
As societies we decide to make concessions and wave away rule breaches all the time when it seems like the right thing to do.
Systems that mindlessly apply rules in ways that are hard to reverse are going to have tough run-ins with societies where every enforcement mechanism includes expectations of being able to override rules.
This is my big problem with systems like Ethereum: Courts will eventually demand some transaction or other to be undone. If the other party can't be coerced into doing it, sooner or later they will issue decisions to e.g. some service provider or software developer to do it. When they can't do it, odds are bad decisions will get made. And eventually badly written contracts will create conditions where there is no way for contracts to get undone in ways that will satisfy the courts. It's going to take a long time to settle how to handle this in a sane way, and I'm willing to bet someone will eventually end up in prison in the meantime either because the courts fail to understand the technical limitations built into the system, or because they do understand them and decide someone is responsible for some transaction anyway if they chose to use such a system.
It's going to get messy.
Not meaning to be snarky, but does anyone seriously believe that? Sometimes I do think software-engineers should go and try to understand processes of non-techies a bit more.
Why would a nation ever adopt anything like this? Can you give me a scenario?
The inability to undo financial transactions based on ownership claims instead of hard currency flies in the face of centuries of expectations of modern society.
Evidence of past ability to undo transactions via hard-forks will create "interesting" legal conundrums for anyone trying to claim to a court it can't be done.
There are a lot of potential circumstances where people will need to find human workarounds for the supposed immutable nature of these blockchains because courts will simply say "this is how it is; make it happen". The above example is "simple": The company can worst case just pass a board resolution to replace the ledger and/or reissue it.
But it is a demonstration that the immutability of the ledger will often be irrelevant, in the face of a court that says "this is the truth now".
Was this fact communicated out to the people who invested $150 million in Ethereum? Attracting a hundred million dollars in investor money, then failing and saying "woops! that was just a test run.", I'm not surprised some people were bothered a bit.
The crux of the matter is that some people were way too confident about the viability of their product, and as a consequence a lot of investor money was lost. One or more programmers somewhere were too impressed with their own skills, without the ability/willingness to see the weaknesses.
https://aeon.co/essays/trust-the-inside-story-of-the-rise-an...