The DAO, the Hack, the Soft Fork and the Hard Fork
cryptocompare.com
cryptocompare.com
Even today, the reason contracts today haven't been written in symbolic logic and enforced rigidly isn't because we lack the capability or some legal hurdle. It's because, often, the result of negotiation on a specific point is very deliberately "let's worry about this later" (IE in court). It allows agreement on the major things while putting off the improbable events to a time when they actually happen, and gives a resolution mechanism when that occurs.
1. The ability to execute code automatically. 2. The ability to decentralize.
There are lots of places where these things are of value, which is why some people are willing to accept code as law as a tradeoff to get them.
But I don't mind if Code is Law with respect to paying out suppliers for my bakery today.
Especially if, when things go sideways, I can choose to use different Code tomorrow.
I wouldn't trust Ethereum with the cash balance of my business, or all its assets, but I might trust it with the daily float.
> Lastly, if they'll fork for one bad contract, why not fork for all bad contracts?
It's not easy to a HF of this nature, there was a lot of discussion for a consensus to come about. In that case the funds were also effectively locked for a time in a single address so it was much easier to do a change to return those funds. the % of eth at the time was also enormous (around 15% of the supply) and arguably enough to cause problems later with future updates like proof of stake.
If you're saying that they have failed at that goal I'd agree. The contract language they implemented is too error-prone for writing secure contracts, and the only solution they have is to break every contract in the system except the one large enough to perform a 51% attack on the blockchain.
But if we call these programs or code instead of contracts, are they useful for anything? Why would we invest our wealth in programs that lose that value if the code isn't unrealistically bulletproof and the largest program in the system? Calling it a program instead of a contract doesn't make it any less useless.
Regarding the programming language, please note there is VM and Solidity is but one language (although by far the most popular currently) that compiles to bytecode for this VM. Much more restrictive/secure programming languages can be created for this VM and we'll likely see more work towards this as development continues, it's likely in the future developers will use different languages depending on the usecase they are trying to implement on the blockchain. Also in regards to the code deployed (the contracts) they can be decentralized, but contrary to popular belief they can also be as centralized as one wants in order to be possible to an update if something goes wrong. However in either case the Infrastructure remains distributed and decentralized.
Regarding the other comments: "if you somehow manage to write it correctly, the DAO might reverse your code by hard forking" and "the only solution they have is to break every contract in the system except the one large enough to perform a 51% attack on the blockchain."
In one sentence it sounds like you're saying the DAO contract somehow reverses 3rd party correct code, and in the other that every contract gets broken (?) except one contract because it's large? and the contract (?) performs a 51% attack on the blockchain (?)
Honestly I don't understand those sentences which is why I didn't address them, I mean you no offense.
> In one sentence it sounds like you're saying the DAO contract somehow reverses 3rd party correct code, and in the other that every contract gets broken (?) except one contract because it's large? and the contract (?) performs a 51% attack on the blockchain (?)
Yes. When the DAO broke, the Ethereum community banded together and performed a 51% attack on the Ethereum block chain, potentially breaking every other contract in the entire system, even correctly coded ones.
For the DAO HF: The DAO contract was replaced by a withdrawal one, that was the only change, No other contract broke because of the fork.
I'm pretty sure you wouldn't just say "It's their own fault for living there and it's also the construction company's fault for not carrying out safety tests. Let them burn because intervening now will only let the construction company & tenants off the hook - they all should have known better."
A more apt comparison would be: Someone found a flaw in my distributed MMORPG and now the game isn't interesting / useful anymore to some people. Should we collectively change the rules, even though we previously committed to not doing so? And before you say "Ethereum is no game", consider how serious some people take their gaming worlds and how much resources (time and money) they invest.
Conceptually, they would, it's just that DAO was an exceptional case.
a) The amount was really large. b) Ethereum ecosystem wasn't mature enough (and yesterday's event proved that they can take a hit like that and survive). c) DAO had a 30 day lockdown of the hacker's fund, this is something which allowed for a hard fork to be possible.
The last is really important. Once hacker gets your money out of the hacked contract, no hard fork is feasible. The DAO essentially created a situation where it was impossible for hacker to get the money, nor for the white hat hackers to get the money. Both could have created a script, where hacker would move his funds to a new child contract, and the WHG would follow him to the child contract (thus essentially rendering him unable to get his money out).
Why wouldn't it be feasible? Have all users update to a version of the client which artificially corrects for the balances of the hacked wallets. Isn't anything possible with a hard fork?
Sorting out who should get their money returned and who gets to keep it would be infeasible.
I would go even further and suggest that the user (not "attacker") of this ethereum contract proudly stand up and identify themselves - without fear of retribution.
This individual played their game by their rules.
They are not an attacker, this was not a hack, and nothing was stolen.
"Your program just computes a different function than you expected and I supplied legal inputs" can be used as a defense of literally all software exploitation.
Isn't this the exact definition of a bailout? Specifically it's bailing out the investors in the DAO.
Even then, the hacker didn't lose anything. He might have a legal argument that he has been unjustly deprived of his wealth, but the legal system isn't generally available to criminals. Also, there's an alternative timeline where ETH fails because of this breach of trust, ETC takes off, and the hacker gets rich. But since the value creating developers supported to forked chain, that's where the value went.
[1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
"I have put one million dollars in this safe. The combination is one of the factors of this very large number."
Man factors number, opens safe, and takes one million dollars
"Woah hold on there, I didn't think anyone could do that! The money is still mine! Give it back!"
No.
I'll stick to real money, thanks.
If you want to watch anything, watch what happens with Bitcoin between now and August 1st. It's a make or break time for whether that trend of slowly increasing value keeps going or blows up horribly.
[1] """The User Activated Hard Fork (UAHF) is a proposal to increase the Bitcoin block size scheduled to activate on August 1. The UAHF is incompatible with the current Bitcoin ruleset and will create a separate blockchain. Should UAHF activate on August 1, Coinbase will not support the new blockchain or its associated coin.
The User Activated Soft Fork (UASF) is a proposal to adopt Segregated Witness on the Bitcoin blockchain and could result in network instability. It is scheduled to activate at the same time as the UAHF."""
Have we even seen a single cycle yet? Bitcoin hit the mainstream, what, five years ago? The value certainly hasn't "crept up"; it's growing exponentially like every bubble in history.
I mean, just look at the data. Yes, there have been -- without any doubt! -- at least 3 cycles that I recall. And by cycle I mean Bitcoin losing at least 50% of its market capitalization suddenly (bust!) and then slowing crawling back up, then quickly shooting up (boom!). No one, not even Bitcoin's biggest detractors, doubts that it's been through numerous boom and bust cycles (and that's not even a good thing, for a store of value).
The main issue to be aware of with cryptocurrency at the moment is quite a bit more volatile than the most major currencies. For now, at least, I would classify cryptocurrency investment as "speculative". EG: I wouldn't recommend anyone put their life savings into a cryptocurrency, at the moment.
By "real" money, you mean more established and widely used, correct?
IMO this means that we are reaching peak interest among techies. It happened with node, with angular, with react and now with crypto... it'd be fun to see some data graphs with info from algolia or the HN dataset from GCloud...
https://cloud.google.com/bigquery/public-data/hacker-news
Regarding the post: I opposed the fork, but now I think it was the best way to go. When there are irreconcilable views/goals in a community, the best thing to do is to separate ways. It happened with linux distros, with dev frameworks, etc and cryptos are not different, it's just software.
I think HN plays a vital role and these opinions by very intelligent people are very helpful to me.
Your comment also made me wonder about a sentiment analysis of HN comments. Something like:
"What does HN Think about It?" App
I actually see lots of parallels to companies like StackMob, Parse, and Firebase, which launched incredibly insecure "serverless" database products that didn't even support any notion of security and even as they added security would almost encourage "anyone can read and even write all of your data" in the documentation as even mentioning security in a tutorial made the product look hard to use.
But the result, of course, was that there were even companies offering dating apps that even claimed in their marketing "we are actually secure, unlike others", which were listed as featured users on the StackMob website, where you could just dump their entire database--including both offline Facebook access tokens for all the supposedly-anonymous users as well as the entire database of what they were saying to each other in their supposedly-private messages--as it was all public.
The market is fundamentally incapable of optimizing for secure products in the same way it is incapable of optimizing for open products. Both of these properties of a product are too complex for users to analyze and the benefits often come in some difficult to measure effect that happens on some difficult to predict timescale. We need to work on this problem before the "Internet of things" becomes too popular and we hit truly dystopian levels of insecure centrally-controlled products.
I first heard about bitcoin right here, when it hit $3 per coin for the first time. That was a huge event.
I had my own reservations about investing in bitcoin, but reading the comments here prejudiced my view.
VC's say it's not the losses that get to you, it's the companies you miss out on that scar you.
Not investing in Bitcoin at $3-5 was the single worst strategic decision of my life.
It was something that could have saved me years of toil, it was an easy ticket into the Big Game. A massive influx of economic energy, a fantastic counterstrike to entropy was right there, and it was easy. So easy to buy, granted it would have been not easy to hold through the dark times, the dips, the panic.
Oh, but if one did!
None of the hard work of starting a company, finding product-market fit, hiring a team, raising funds, fighting off the inevitable bandits that will come for their extortion money in the form of frivolous patent lawsuits...
None of that. Just easy, huge, beautiful, juicy investment capital right at my fingertips.
Oh the land that could have been bought! The development deals that would have flowed and the opportunities that could have been pursued. Instant entrance to Ruling Class, a ticket to the best club on earth.
'The most important men in town would come to fawn on me! They would ask me to advise them, Like a Solomon the Wise. "If you please, Reb Tevye..." "Pardon me, Reb Tevye..." Posing problems that would cross a rabbi's eyes! And it won't make one bit of difference if i answer right or wrong. When you're rich, they think you really know!"'
- If I Were A Rich Man, Fiddler on the Roof
And it's that emotion thats fueling crypto asset valuations right now, along with actual riches created by people who didn't give in to the negativity, the doubt, the fear.
The thing has value. People like this thing. They like it all over the world. There are infinite uses for something like money + code + global computer networks.
And a thing doesn't have to be perfect or solve every problem to have value.
The standard that commenters here hold crypto to is not the same standard they hold startup companies to.
With companies if they do something some people like enough to use, they say wow what a success, look they are a real company with profits!
I mean even if the only use for crypto currency is regulatory/legal arbitrage, that's insanely valuable and would have merited an investment.
There's a lot of activity lately so it makes sense that there's more news on this lately. IMO it's relevant to HN. If I see stuff that I'm not interested in on HN (of which there is plenty) I just move on to the other stories.
Some sort of A/B test where there were two versions of Ethereum, one with the fork and another one without the fork. That way we could have known for sure if forking was a good idea or not.
Technically, no transactions were undone, but the fork agreed to a new state set in the future. The users of the new version also had a choice if they wanted to support the fork or not, the majority went with the fork. It's not like anyone was forced to fork. Actually, you could even run both, and I did for a time until it was clear who was the winner.
This is a screenshot of the choice everyone was asked when starting up their wallet: https://upload.wikimedia.org/wikipedia/commons/thumb/d/d7/Et...
Semantic games aside, this is a classic illegal maneuver in corporate law -- I think the term is "freezeout merger."
It works like this: Alex, Beth, and Casey each own 1/3 of FooCo. So Alex and Beth get together and, by a 66% vote, agree to sell the assets of FooCo to BarCo for $1. BarCo just happens to be owned by Alex and Beth without Casey.
It's a nice move for Alex and Beth, right? They just each increased their net worth by 50% with a simple legal formality. In fact, if you think about it, this maneuver is always a rational transaction for the majority shareholders in any corporation. Which is why it's illegal -- otherwise it breaks the game.
So, what do you think Alex and Beth say in this scenario if they're called on it? They say exactly what you said here: Casey didn't lose anything! She still has 1/3 ownership of FooCo, plus she got her 1/3 of the $1 paid from BarCo, fair and square. No harm, no foul.
(No kidding, I've actually had the lawyer for a company that did this to my client try to make this argument across a conference table. Then the lawyer tries to pretend no one has ever had that idea before. Like this wasn't thought of and dealt with about 5 minutes after the first minority shareholder existed.)
A court, and the rest of the world, will find this argument ridiculous. The obvious intention and impact of Alex and Beth's action was to take net worth (in real world terms) from Casey and award it to themselves. They can't avoid that by playing clever games with the labels.
Likewise, the obvious intention and impact of the Ethereum shareholders' actions was to take net worth (in real world terms) from the DAO hacker and award it to themselves.
Play all the games you want with the words, that's what happened. And that's the takeaway: in the law, the minority has protection from the majority. In Ethereum, the majority shareholders rule, and if they decide you don't deserve to have ownership, they can vote to take it for themselves.
It's potentially rational to decide you like your chances better with the majority-shareholder-vote-is-law system than the legal system in your jurisdiction. (If you live in the US or a similar jurisdiction then I disagree, but it's an interesting argument anyway.) But trying to pretend no one lost anything from the hard fork just doesn't fly.
FYI for those who don't happen to know the early Facebook ownership story... Mark Z attempted a variation of this.[1][2]
FooCo would be the Facebook (Florida) LLC created April 2004.
BarCo would be the Facebook (Delaware) Inc created July 2004.
Alex & Beth would be Mark Zuckerberg & Dustin Moskovitz & Sean Parker & et al except for Eduardo Saverin. Casey would be Eduardo Saverin.
>A court, and the rest of the world, will find this argument ridiculous.
Yes, the real world confirms that. After Eduardo Saverin figured out that he was diluted via trickery, he sued Mark. Mark lost and owed Eduardo additional stock (worth billions).
[1] http://www.businessinsider.com/how-mark-zuckerberg-booted-hi...
It's rather inconsistent to on the one hand claim that "that's just how Ethereum contracts work; the hackers should be allowed to keep those funds" even though those hacks would clearly be illegal under US law, then on the other hand turn around and say "forking the currency like this is wrong because it'd be illegal if this was a company operating under US law".
The "attacker" is seen as the "bad guy" so everyone decides to screw him?
The software IS law in the world of Etherium. There is a reason they are called "Smart Contracts", instead of "methods" or "functions". They are designed to be binding.
The DAO having a faulty smart contract is akin to someone agreeing to a bad deal. They feel cheated, but there is nothing legally that they can do.
Personally, I believe there should never have been a hard fork. The people that invested in the DAO were stupid to do so.
The token holders of theDao did not approve running of the attacker's contract, since they did not agree to the attacker's contract. At least that's how I interpret it.
Also, the word "contract" is not the same as a contract in law, it's more of a buzzword. They are just programs. So I don't think a program can have legal meaning by itself because it also depends of the semantics of the machine & how it interprets the programs. What happens if the code is correct, but something in the machine is broken?
The rules of the Ethereum virtual machine were altered later. I think the 'fallback function' now has a limit of 23k gas, correct me if I'm wrong, so attacks like these are more difficult, if even possible.
That's not my argument. My argument is that there's a reason it's illegal under US law (and presumably in other functioning legal systems): because it has to be illegal for the game theory of vote-per-share corporations to work. Otherwise entering a corporation as a minority shareholder is irrational.
If you abandon the legal system's protection for minority shareholders, you're assuming that you don't need those protections -- that somehow cryptocurrency game theory works differently than the game theory of legal corporations. I suspect that's wrong. But either way, we have to at least be clear about the practical impact of Ethereum's hard fork in order to have the debate.
> agree to sell the assets of FooCo to BarCo for $1
This is where your analogy breaks. The classic chain was not sold to the forked chain.
It would be more comparable to Alex & Beth getting together and creating new company, copying all the books & records from the old company (that were public domain), minus Casey's balance. Without buying the old company. Customers of the two companies could go to any company at any time they wish, except for Casey, who is not a customer of the new company. That would be legal in US?
There are a few other issues with your interpretation:
- Coins do not represent shares of a company. There's no stock.
- There's no voting: At most, the miners probably have voting power with their hashrate, however as the linked article stated, a soft-fork was impossible to do, so even the miners could not vote.
- Hardfork was not a vote. Even if you said "Yes" to the hardfork config option, you could still go back and say "No" to play with the classic chain at any point in time. (Refer to the screenshot in my OP)
In my analogy, Casey owned 1/3 of X (a corporation), where X is some social construct with real-world market value in terms of dollars or bitcoin or gold or whatever. The other owners of X worked to transfer real-world market value from X to a new social construct, Y, in order to capture Casey's share of the value. Under the US-law ruleset this is a violation of their fiduciary duty to Casey as a minority shareholder.
In the Ethereum example, the DAO hacker owned 1/20th (or so?) of X, where X (ether) is some social construct with real-world market value in terms of dollars or bitcoin or gold or whatever. The other owners of X worked to transfer real-world market value from X to a new social construct, Y, in order to capture the DAO hacker's share of the value. Under the Ethereum ruleset this is OK.
So we have two different rulesets with different protection for minority stakeholders. It's an interesting question whether (despite this example) Ethereum could end up being more favorable for minority stakeholders overall. But it's not at all interesting to spend time arguing about whether a minority stakeholder was injured by the Ethereum split -- that was the entire, explicit, point of the split, and if you focus on real-world exchange value there's no way to disguise it.
Also, if I change my level of abstraction to think about the problem as you say, it would appear that the attacker was trying to injure the project, opposite to your Casey example, where she was the victim. Those that had 'skin in the game' did what they had to do, to protect themselves from the attacker. I don't think the attacker was naive, they would have known that such a move would inflict a loss of value for the project.
I also think that the hardfork was the best outcome for both parties: Classic represents the value of Ethereum should it have chosen to keep on going with the attacker, and Ethereum Fork is the value representing the attacker absent. Everybody wins, the thief would be pretty happy with their loot regardless (if it's legally theirs, maybe it's not). In your Casey example, she was left with nothing, so it's another important distinction to make.
Btw, thanks for replying and for the debate. It's been a pleasure.
Also in the law, a suitable majority of voters and/or their delegates can change the law concerning the return of stolen property. They can even change the definition of theft if they want, or even change the Constitution. They're the (super-)majority after all. No amount of code or technology can ultimately stop them from having their will. Even the protections you mentioned only exist because some group of people who are more numerous than Alex and Beth have decided that they don't like freezeout mergers.
At the time, not hard-forking would have made the very concept of programmable blockchain a no-go area, never mind the damage to the project and the initial investors with some 10% of the whole token supply being drained because of a software bug.
In a way, the decision to hard-fork proves the Ethereum Foundation and community are truly committed to creating a new internet and we will do whatever it takes to make it a success.
That said, contracts also tend to have many "fail safe" and conditional provisions to handle unanticipated events and edge cases.
It sounds to me (without much understanding of how exactly contracts are programmed) like there ought to be some kind of hard-coded "laws" restricting for controlling what contracts can do. Is there anything like a legal system in Ethereum?
Wasn't it 89% of those who voted? What was the voter participation rate?
In particular, blacklisting DAO operations means that one can broadcast transactions that perform huge computations but just before running out of gas, perform a DAO operation. This huge waste of resources by miners cannot be compensated if the transaction cannot be included...
This I see as a wonderful property of blockchain currencies, everyone can get what they want in an entirely democratic way, except the haters who just want to see other people's fun ruined.
When the slaves from the southern US started escaping north and towards Canada, many northerners who aided them were put on trial because technically they broke a law because slaves were considered property.
The jury would acquit them because they did not believe in the spirit of the law.
Some people believe jury nullification is required for a truly democratic justice system.
Also in this scenario, the fork is essentially the majority's way of saying "we don't believe in the spirit of this contract, it wasn't meant to behave that way." Obviously, that brings up many complications. But the majority believed that a fork is essential to save the platform and worth the potential split in the community.
Either the code is the contract or it isn't.
Btw -- what has the DAO even accomplished after they 'saved' it?
It has warned a lot of people to stay the hell away from this kind of construct because it can't be trusted. That's a pretty good accomplishment.
Seems a little strange to stand by your prediction now when we have the benefit of hindsight and can see pretty clearly that you were wrong.
No Other Coins Before Me
Thou Shalt Not Attempt To Mutate The Blockchain
The blockchain has always been about consensus first and foremost. If a clear majority of the economic power decides to change something then that thing will change. There's nothing magical in the blockchain to prevent that. You can always decide that it's wrong and remain on the "classic" version, but if you don't convince anybody else to follow you there won't be any value.
More generally, I don't see how any coder would take the "code is law" thing seriously. All code has its share of bugs. Even if you formally verify it you may still have a bug in your verification code or your assumptions. The tiniest mistake can lead to catastrophe, as we've seen lately.
Code isn't law, law itself isn't law, it's how humans apply the law that's law. Removing the human factor from it isn't a feature, it's a terrifying totalitarian dystopia.
"Hello sir, the algorithm detected that $10 was missing from your utility bill 12 years ago, with the late fine, processing fees and interests you now owe us $1298.51. Please pay within a week."
"I can't pay this and I need to take care of my family. I'll have to mortgage the house!"
"I'm sorry sir, code is law. Beep boop."
Judge Dredd: blockchain edition.
Except then they hard forked, proving that political consensus still rules. The benefits of crypto-secured mathematical consensus are still subject to politics and messy human institutions. "Code is law" is a lie.
The funny thing is, this is a corner they painted themselves into. If they'd planted their flag only on decentralization, automation and trustlessness, and ignored "code is law", they wouldn't be having this problem today. Ethereum would be a technological advance on what we already accept: human economics.