Poly Network hacker returns $258M after stealing $600M
forbes.com
forbes.com
If someone had physically or electronically broken into systems and illicitly copied private keys that would be a different story. Here someone executed permissible actions on chain that people didn't like, wah wah.
You have to be an absolute tool to use the poly network for anything serious ever again.
This is a great point. One name for it is 'Chesterton's Fence' [0]
I deposited 100 BTC to test it out.
First thing I did was to try to withdraw negative 100 BTC.
It sent me 100 BTC, but instead of a zero balance in the exchange, it said I now had 200 BTC.
So then I withdrew a negative 200 BTC, and it sent me 200 BTC and increased my exchange balance to 400 BTC.
I contacted the owner and returned the funds and he sent me a 100 BTC bug bounty.
Was entering a negative number in a web form "hacking"? Should that be illegal?
Many hacking laws were drafted in the 80s and are exceptionally broad. What you did was almost certainly illegal hacking, as the laws define it.
Of course, whether the victims would care to complain; and whether they could get the police to take them seriously; and whether they can find you; and whether you and they are in the same jurisdiction; are other matters. I certainly wouldn't recommend you rely on the CFAA to protect you from ransomware gangs.
of course, this is not quite the same as misunderstanding some subtleties in an explicit contract. for example, the mere fact that I did not understand an auto-renewal clause in a lease does not get me off the hook for payment. although I might have some recourse if the lease stipulates something absurd (eg, notice to vacate must be hand-delivered to office in antarctica).
crypto does not necessarily mean you get to do a complete end run around the laws of sovereign nations. what it might mean, if designed well, is that you don't have to depend on those nations enforcing things.
They need to go back and wrap all this stuff in actual legal boiler plate to have a meeting of the minds limiting what any individual digital contract can mean, if anything, rather than pretending this is orthogonal when it clearly is not.
To your original question, entering a negative amount in a web form should not be illegal. That's silly. But you're responsible for the effects and what you do after noticing the odd behavior. If an ATM machine vends me an extra $20 because the bills were stuck together, I should return the extra $20.
https://www.joelonsoftware.com/2000/04/06/things-you-should-...
> In the matter of reforming things, as distinct from deforming them, there is one plain and simple principle; a principle which will probably be called a paradox. There exists in such a case a certain institution or law; let us say, for the sake of simplicity, a fence or gate erected across a road. The more modern type of reformer goes gaily up to it and says, “I don’t see the use of this; let us clear it away.” To which the more intelligent type of reformer will do well to answer: “If you don’t see the use of it, I certainly won’t let you clear it away. Go away and think. Then, when you can come back and tell me that you do see the use of it, I may allow you to destroy it. [0]
[0] https://en.wikipedia.org/wiki/Wikipedia:Chesterton's_fence
"Do not carelessly denigrate social institutions or creative achievement."
Strike a "we", replace by "rich elites". "Small government" means in practice that most of what governments are doing now with taxpayer money at no-profit will be done by private for-profit companies, at a worse service level, or that regulations/regulatory agencies will be torn down.
For the first, just look at private prisons - make a lot of profit for their owners, while the level of care for the prisoners (access to healthcare, drug withdrawal treatment or education is often spotty, human rights abuse claims the norm).
For the second, look at how e.g. environment regulations were "relaxed" during the 45th.
It's all about the grifting opportunities.
I don't agree. My 'poor' leftie friends are all about tearing shit down, while most 'rich' people I know are pretty happy with the way things are, wanting only to make small tweaks here and there.
Maybe you didn't mean for your position to lead to private prisons. But it does, anyway, and that is all that matters.
The US is also not the only place where prisons are private[2], there's the southern hemisphere's Sweden a.k.a. big government paradise, and it has a private prison.
To say either "public" or "private" and ascribe some sort of good or bad to them without providing any reasoning is presumptuous in the least, but to then tell someone what their actual position is - in your view - after making such a presumption would only be to compound an error.
I know what I meant, try to focus on what you mean and fixing that before mischaracterising my views again, thank you.
[1] https://www.motherjones.com/politics/2016/06/history-of-amer...
[2] https://www.brennancenter.org/our-work/analysis-opinion/crit...
We do have private prisons. As you note, they started under Reagan, in response to Reagan's "anti-crime" policies. Reagan is notorious for claiming to support small government and balanced budgets while actually spending us deep into deficit in order to purchase boondoggles. How are your preferences different than Reagan's?
What’s the average length of a post on HN and where does that post stand?
> How are your preferences different than Reagan's?
You just stated that he acted contrary to his claims, if your position is that I say I’m for small government but wish to spend, spend, spend, then I can see why you’re confused. Try dropping the assumption I’m lying, the principle of charity is a wonderful thing.
More to the point, as you are confused by sarcasm in the service of proof by contradiction, I’ll rephrase:
Would you claim that the government was historically small in 1983?
Is today’s government smaller or bigger?
How do both of your answers correlate with the increasing number of private prisons?
Finally, since your answers should be no, bigger, and bigger government correlates with more private prisons, what on Earth are you on about?
And yet you're going to avoid defending it, or even looking at, nor answering any of my questions and then accuse me of such matters. Ironic.
> This is an awful lot of words to avoid the question
What is it with those who support big government ascribing mendacity to their opponents? I'm not avoiding anything (except fallacies like ad hominem and false dilemmas).
> whether the small-government philosophy you personally subscribe to, whatever it may be
Here you admit that there is more than one possible outlook, yet you go on to produce this:
> If you prefer contracts, stop arguing, if you don't, explain why you think the operation of prisons is a proper function of a small government. It's not hard.
A false dilemma. Make your mind up, are there many types or only one?
Perhaps if my questions were answered I might feel more in the mood to answer those from people who accuse me of avoiding theirs.
> would prefer that government contract out prison services, or run them itself
My answer is either, it's irrelevant. The government is regulator and enforcer. It should promote (high) standards which it then enforces regardless of whom is running a service. Problems may arise when:
a) the one running the service is also the regulator, a clear conflict of interest and though in some cases permissible, it's not one for incredibly powerful entities like government.
b) the ones providing the service are also over-represented in government i.e. they have more than a vote, they have lobbying power (or straight up corruption) which in this case would lead to criminalising essentially non-criminal behaviours to produce whatever positive outcome for them and not for the populace they're supposed to serve. How many people are in gaol for marijuana possession?[1]
More criminals means more prisons, more tax money, more staff and budget (hence more power), more cheap labour… how does that sound anything like small government?
This[2] will come in handy for you.
[1] https://www.drugtestpanels.com/blogs/articles/jail-time-for-...
i think the bit where you talked about Sweden being in the southern hemisphere places it in the top tier of 'confusing' for me...
there's the southern hemisphere's Sweden a.k.a. New Zealand, the big government paradise
I can't edit now but thanks for pointing out something in a reasonable way.
A program that does not implement its intention is buggy.
This is still starting from scratch. The design may be conventional, but you're benefiting from a modern approach to processes and design from the beginning.
I mean this is the best way possible, the Falcon 1 didn’t reinvent the wheel. They basically said what’s the simplest useful rocket for getting stuff to orbit copying as much of the design as they could, and built that.
I'd say that if you are gluing together a bunch of known-good components into a specific configuration that isn't a full copy of something else, you're building from scratch.
Take say all those identical looking highway overpasses. Even if one of those projects started with a blank file, applying standard solutions to standard problems isn’t starting from scratch.
You alright?
Inefficiency implies that we can fathom a way to navigate the same space more efficiently. Do we? Or do we, for this mental gymnastics to work, actually have to change the space, to one where people are kind and the whole complicated system is less so?
Certainly having lawyers in big business must be efficient enough that they beat not having lawyers or else the market would adjust around that, no?
Lynching/mob justice is much more efficient than lawyers and courts, and that is what comes to mind seeing how the crypto reacts.
My point here is that it happens time and time again - people do revolution, be it real bloody one like French or Russian or just a tech one like crypto, and from the very beginning dispense with the old mature system and replace it with what they see as a very efficient new one - like the "emergency committee" system of Russian revolution which was able to quickly execute millions of "counter-revolutionaries" - yet with time the system again matures into what is perceived as a very inefficient one.
In what way specifically ?
The implementation can be formally written and verified, but the specification itself cannot be automatically verified.
That's effectively what a contract is anyway - it's a specification for a 'legal agreement' which is this sort of invisible obligation that is created after it is signed (for instance, the time spent in contract negotiations is usually spent debating what should happen in edge-cases).
It turns out some of the inefficiency is necessary for everything to function, and ultimate efficiency is a dumb idea. Who knew?
A formally verified X is just a reliable X.
If X is wrong, then you just have something that will reliably do the wrong thing.
i.e. just because analogs exist, don't expect their performance characteristics to be invariant
Tech people tend to think of technology as computerized things, but all those things you listed are also technologies that solve real problems that people encountered in the past.
IMHO, crypto is like a new car with the revolutionary new feature of not having seat belt technology. Maybe the inventor has some dumb idiosyncratic or ideological hatred of seat belts, and maybe some people buy into it... Then the new cars get popular, people start crashing them in numbers, and we realize, "hey maybe seat-belts weren't so dumb after all."
Of course, when that happens someone in that community will call it a seat-strap and claim it's a revolutionary new invention.
Crypto is like that new car that can have a seat belt but you don't need to. The fact that it still doesn't have that seat belt doesn't means much, just that you need to be aware of it.
For sure any new paradigms will takes time to solve every indirect issues that comes with it, Rome wasn't build in one day.
> Of course, when that happens someone in that community will call it a seat-strap and claim its a revolutionary new invention.
Oh seems like you acknowledge that... but twist it like a bad thing? For sure it will be a great thing to add to cryptos, you just said it yourself that it's something lacking in cryptos...
What's amazing about crypto is the flexibility, the openness, the accessibility. Anyone can join theses networks, thus it can be done anywhere too, and because of the financial incentive, it's gonna happen anywhere. You'll probably say, but there's Western Union, Paypal, Visa, banks, etc... for all that... but check the Chikaordery story from Pleasant Green (as a Canadian I often laugh when the list include Venmo, or any US exclusive service, that just show how so many forget that the US isn't the world).
So yeah, some people will makes mistakes from time to time in their smart contract, it will happens, but we will get better each time to avoid that, when it's needed, just like we did with the previous ways of doing things. We will accept the risk when it can't be done, and that will be it (never heard of fraud using credit card, or bouncing checks? We are just used to them and accept the risks.)
> Crypto is like that new car that can have a seat belt but you don't need to. The fact that it still doesn't have that seat belt doesn't means much, just that you need to be aware of it.
You're missing the point. To put it slightly differently: crypto is like the overconfident kid who thinks seat belts are stupid because he doesn't truly realize he can get into an accident, let alone die. He actually does need a seat belt, he's just not wise enough to realize it. When he gets in an accident and files out his windshield, then he'll discover he wants to use one.
>> Of course, when that happens someone in that community will call it a seat-strap and claim its a revolutionary new invention.
> Oh seems like you acknowledge that... but twist it like a bad thing?
Reinventing the wheel when everyone else around you is riding in cars and on bicycles is not actually inventing anything, let alone anything revolutionary. Then, if you'd previously spent the previous few years mocking wheels as stupid and useless, there's the angle of refusing to acknowledge that you were wrong.
God didn't come down and give us governments.
We started without order and survival based on individual output.
And every single living thing beyond a threshold of intelligence agreed that it sucked.
If you assume that adding more government always makes things better, then why not go all the way to complete totalitarianism?
If you agree that totalitarianism is too far, then I don't see why reasonable people can't disagree on which direction (more government or less government) is an improvement on the status quo.
any anarchy is just one step away from despotism. when power lies on the ground, it doesn't take much for anyone to pick it up and wield it. you really need a strong government to preserve anarchy.
"Liberty" is a wonderful lag measure, but a terrible lead measure.
The only thing you can really do to immediately create more liberty is deregulating. But in a world without laws, the only law is that of the jungle.
In which case we have a might makes right tyranny.
But as a lag measure you can do things like legislate worker rights, minimum wages, term limits, etc. With the long-term effect of more "liberty and freedom"
“Why would anyone need light bulbs? There are gas lamps and oil everywhere that do the same thing.”
“Why would anyone need email? There are post offices that do the same thing.”
Reading this a hash collision was exploited:
https://rekt.news/polynetwork-rekt/
> Well... here's the actual sighash of the target function:
> http://ethers.utils.id ('putCurEpochConPubKeyBytes(bytes)').slice(0, 10)
> '0x41973cd9'
> And the sighash that the attacker crafted...
> http://ethers.utils.id ('f1121318093(bytes,bytes,uint64)').slice(0, 10)
> '0x41973cd9'
> Fantastic. No private key compromise required! Just craft the right data and boom... the contract will just hack itself!
So yes. As the main point of digital contracts seems to be that they are self-enforcing, then it seems to follow that there can be no complaining about the results of using them.
I believe if you lied in the game that would constitute a written/verbal contract and what you did is fraud. Some games enforce written agreements, others say it's the wild west so too bad, this is role playing by a character, not the person. I'm not sure if either has ever been tested in court.
For the hacking thing I don't really agree that all hacking is 'allowed', phishing is of course a type of fraud, your access is unauthorised even with the correct credentials - authority to enter a building does not derive from stealing a key from someone. Likewise a buffer overflow is 'allowed' much the same way a window allows itself to be broken by a brick.
Actually...
https://www.gwern.net/docs/rotten.com/library/bio/crime/crim...
>Patrick had an interesting mating ritual: Apparently the task of convincing a girl to meet you involves sending her a digital photograph of your wang, as Naughton did on several occasions. He described his flights of fantasy as role-playing as himself, pretending to be a successful, rich executive with everything going his way. When he bragged about running a company and owning a boat in chat sessions, he was telling the truth, unlike so many chatters before him. [...]
>If Mickey cried a little that night then certainly Michael Eisner had a bad day after learning that his young Vice-President in charge of E-mail and Chat Rooms had been arrested for, well, very un-Disneylike behavior. [...]
>Despite all of the evidence and the decades of prison time hanging over him, Naughton would eventually walk free. The jury in his trial deadlocked over the more serious charge and to avoid a retrial, he plead out to lesser charges.
https://www.latimes.com/archives/la-xpm-1999-dec-10-fi-42422...
Former Internet Exec Says Online Pursuit of Girl Was Role-Playing
DEC. 10, 1999 12 AM PT
>Taking the stand in his own defense, former Internet executive Patrick Naughton testified Thursday that he never intended to have sex with a minor and that his steamy online encounters with an undercover FBI agent posing as a teenage girl were part of a fantasy life he pursued to escape emotional problems and mounting pressures at work. [...]
>Naughton’s unexpected appearance represented a bold move by a defense team that is pursuing what many consider a risky and unprecedented legal strategy. Their central argument is that Naughton’s statements online and subsequent actions aren’t incriminating because they were grounded in an online fantasy world. [...]
>While claiming that role-playing is rampant online, Naughton admitted that he always provided accurate information about himself during online chats, even pointing his supposed 13-year-old correspondent--actually an agent--to one Web site that had a news article about him and another that had a picture of his exposed genitals.
>Asked why he furnished such information if fantasy was his real objective, Naughton replied: “The role I was playing was a character of me. If you ask my psychiatrist, I have a lot of self-image and ego problems. I was looking for approval.”
https://en.wikipedia.org/wiki/Patrick_Naughton#Novel_defense
>His line of defense was that he claimed he was persuaded to participate online in a ritualized sexual role-playing exercise, dealing with a mature woman acting as a girl.[14] His then-novel defense, became known as the fantasy defense for pedophiles.[2]
https://en.wikipedia.org/wiki/Fantasy_defense
>The fantasy defense is where a defendant accused of attempting a crime (enticing minors into sexual activity, for example) claims that they never intended to complete the crime. Instead, they claim they were engaged in a fantasy and, in the case of luring a minor, believed they were dealing with an adult.[1]
>The fantasy defense was developed by Donald B. Marks, the attorney for Patrick Naughton,[2] the Disney executive who eventually pleaded guilty to traveling in interstate commerce with the intent to have sex with a minor, in violation of 18 U.S.C. § 2423(b).[3][4][5] The "fantasy defense" used in the Naughton case was novel; however, since the closely watched Naughton fantasy defense was successful, defense lawyers were expected to use it to help other clients.[4]
https://digitalcommons.law.scu.edu/lawreview/vol41/iss2/6/
>Donald S. Yamagami, Comment, Prosecuting Cyber-Pedophiles: How Can Intent Be Shown in a Virtual World in Light of the Fantasy Defense?, 41 Santa Clara L. Rev. 547 (2000).
This is all about the level of abstraction
The ‘laws of physics’ in a game may allow you to do unintended things, it’s a complex system. Doesn’t mean that it’s OK at a higher abstraction.
I know what we did constituted a violation of terms of service, and we were subject to bans at any time. However, I was reasonably confident there was little Jagex could do to pursue legal action against us. Generally, we were relatively small fish compared to things like the Mod Jed scandal.
I am not sure the courts would find this to be in any way illegal. But I find it very interesting.
KempQ on YouTube does a lot of videos on modern luring methods. There's also a guy on YouTube called Hermano, a former Venezuelan gold farmer, who has some interesting insights into the real world value of osrs gold and why Venezuelans do it.
Is that wrong? Is it part of the game? Obviously there would be something wrong if you sold people your digital tokens and then took them away from players - you agreed to give them digital tokens and then took them away. But if an in-game character is making false representations as part of the game, that seems different.
agreed
> A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it
I kind of disagree in philosophy here. If there's a bug in a bank API that lets me transfer funds to my account, I'm still "hacking", even if I'm doing exactly what the API lets me do, because I know very well that I'm not supposed to.
Then again, as you say, the whole spiel of digital contracts is that theyre far too clever to need silly courts and judges and common sense and all that, so... meh
You are likely also violating the terms of usage of the API and various other legally enforceable contracts by breaching the API.
If a smart contract included a terms of use however, it would be interesting to see whether this could be considered enforceable.
There is no one physical server. I think this is misleading.
From a moral standpoint, it's like, if you accidentally leave behind your wallet with cash on a park bench with a lot of passer-by, then it's your fault for leaving it there and whoever finds it deserves to keep it. I'm sure you're familiar with the "finders keepers, losers weepers" saying... After all, it's in public, similar to how public blockchains work, right?
However, different people may come to different conclusions about this. In some countries in the world, the overwhelming consensus would be to return the wallet to the owner, even if it's found in public. I guess it's because it doesn't matter if you had to break through the window, or simply reach out and grab it from the bench; the property does not belong to you.
A lost wallet is accidentally left there. The context of it being available to be taken by anyone is not intended. There is no declaration of rules by which you may take it by the owner.
You can't just expect people not to take free money laying out on a park bench with their name on it...
The debate being had is whether the sign was sufficiently well written ("It's the code's fault") vs. whether the sign system is just a terrible idea regardless of sign quality and you should use normal societal systems to transfer the wallet.
• As a device to programmatically ensure the “owner” of some resource is the one who controls it; or
• As a system that decides who controls a resource, whomsoever controls the resource has a right to it, there can only be one.
The sensible interpretation (imo) is the first one, unless we're doing away with our conception of property rights. (Which would be an interesting experiment, but given the philosophical background of a lot of this cryptocurrency stuff I don't think that's what's intended.)
Blockchain are just databases. But they still run due to consensus and the consensus is made up by humans and it is humans who uphold it.
For example, humans came to a consensus that there will there will only ever be 21 million Bitcoin. However, we cannot guarantee that one day there may be more than 21. They also came to a consensus that that this shall never change. However, all that is protecting this consensus is a meme. The source code can be changed should everyone agree, especially if the future humans find that such a cap does not work.
The benefits of decentralization is that the consensus is hard to change by individuals or centralized organisations... Consensus must be reached by all of the participants of the network.
Previous relevant comment of mine on the matter of "Code is law": https://news.ycombinator.com/item?id=28132994
https://en.wikipedia.org/wiki/The_DAO_(organization)
>In June 2016, users exploited a vulnerability in The DAO code to enable them to siphon off one-third of The DAO's funds to a subsidiary account. On 20 July 2016 01:20:40 PM +UTC at Block 1920000, the Ethereum community decided to hard-fork the Ethereum blockchain to restore virtually all funds to the original contract.[10] This was controversial, and led to a fork in Ethereum, where the original unforked blockchain was maintained as Ethereum Classic, thus splitting the Ethereum blockchain into two branches, each with its own cryptocurrency.
I think its an important point to be made.
Such an intention doesn't cause laws and courts to stop existing or make things so courts won't interpret certain actions as theft. But it complicates things.
Anything outside the that was exploiting bad implementations and therefore a hack.
Some here might think the the code is a contract because that's the name. But that had never really been the case: public human statements supercede code.
Arguably things like this should make the future a bit more secure, from what gets learnt. In the same way other code industries learn from found bugs or exploits.
Where do we put a border?
But that’s antithetical to the value prop of smart contracts.
Such a weak take. I guess we are also tools for using Ethereum after The DAO.
An error like this in the contract stack should have been caught by the auditor, Certik. It's not a fundamental flaw in PolyNet's system, just a very unfortunate oversight.
In reality, parts of the crypto community moved quickly to block transactions involving the funds and some security researchers claimed they had solid leads on tracking down the hacker’s identity. I think the hacker realized that if their identity was compromised then the legal system wouldn’t look kindly on someone stealing hundreds of millions of dollars.
Returning the funds and trying to portray the hack as a noble operation to identify flaws in the system is one way to try to re-spin the events as a positive. It appears they’re hoping to collect donations or some sort of reward as a sort of clean money takeaway.
It must have been a wild emotional roller coaster to go from securing $600 million dollars for yourself to realizing that you made a mistake that tied your real identity to the heist.
The other piece is a reaction to the pro crypto crowd who are making claims about how amazing crypto is and why it is the future. Most of these people have a large financial interest in moving the price of various coins up. The use cases so far 10 years into this are buying drugs and ransomware and the price going up.
Another example "Smart Contracts" are supposed to be this amazing technology for changing the world, but as you see here they have some significant downsides that the pro crypto people seem to either ignore or not understand.
It isn't just HN folks who feel this way. One of the smartest and most accomplished AI engineers alive today had this to say. https://twitter.com/karpathy/status/1401267972044328961
PS Mined some BTC in 2011 and some LTC in 2012-2013.
The original promise (per Satoshi) was that it could be used as electronic money. That goalpost was moved onto other currencies and sidechains and regular public acceptance has been low.
Most of crypto activity is related to other crypto(see Ethereum, see DeFi). All of the "cool" stuff happening in crypto seems to be dealing with other crypto...
It is useless to non-crypto people.
The only somewhat useful moral use case are remittances to unstable countries.
The rest of crypto is just bad bad stuff: scams, ransomware, large scale capital transfers by bad actors(tax evaders being the least evil).
I am in a business(high rate of CC fraud) where I would really benefit from an easy onramp for non crypto users.
PSS Last not least, POW and the horrible incentives going along with it is a serious issue as well. POS remains unproven in the field.
It’s ironic you’re asking this question in a thread about news proving how stupid crypto is to begin with.
maybe they dont just understand it at all, too. and its a lot, wrapping your head around all the defi fiasco alone is mentally challenging as hell, haha.
That's not what post modernism is
Of course that doesn't apply to everyone, and perhaps not even them majority, but certainly at least the majority that shows up in crypto threads. HN members tend to be very smart, very technical, and very confident, all of which combine into this ugly blind spot to creative/unusual forms of technical innovation. Crypto in particular is good at sitting right in the center of that blind spot.
This explanation has made more sense to me than anything else I've seen, you'll have to decide for yourself if you agree with it.
Crypto has been around for quite a few years already. How is everyone still close minded? Maybe the issue is that crypto has several problems that are consistently ignored by the community and crypto products keep on underdelivering on their promises.
In the end, it all boils down to one fact: the differentiating feature of blockchain is decentralization. That's mainly it. However, the crypto community keeps on promising changes and improvements in areas that don't have anything to do with decentralization without any actual arguments, ignoring what is the reality of those issues.
The other side of that coin – excessive open-mindedness – however, leads to being susceptible to cults, snake oil salesmen, and hyped up technologies. Crypto currencies, in particular, frequently tick all three boxes. Skepticism is generally a good thing, and so far crypto currency proponents have failed to refute the arguments of sceptics.
Cryptocurrency offers new primitives that are unavailable in any other system known to man. It takes time to build up a backbone of technology that can take these new primitives and get them to the point where they can compete with established trillion dollar industries, but it is happening, and it's starting to happen very rapidly.
It's certainly true that crypto is full of snake oil salesmen, overhyped technologies, and culty communities. But the presence of those things doesn't change the fact that the technology is real, and that it can do things at a fundamental level that no other technology can do.
Short answer: Crypto has been touted as a primarily technological advancement (blockchain!) while the primary use case for most crypto proponents is simply getting rich (flipping coins or spreading "HODL" encouragement).
Imagine if Venmo had launched with the requirement that all Venmo transactions had to be performed with VENMOCOIN instead of dollars. To transact on the Venmo platform, you had to buy some of this VENMOCOIN from the founders or early adopters, funneling your real money to them in exchange for tokens you could use on the Venmo platform. The VENMOCOIN early adopters really, really want you to use Venmo so the price of their VENMOCOIN goes up, so every online discussion gets filled with people talking about how amazing Venmo is and how it's the way of the future and everyone should buy as much VENMOCOIN as possible.
Sound ridiculous, right? That's more or less what the crypto discussions have become: People pretend to talk about technology but it's really about getting rich by flipping coins and pumping their value.
Not to to mention anything dealing with money that isn’t reversible or doesn’t have a clear method for recourse is not something I want to put my money into.
It’s really no different than a wealthy old man hating crypto. He has no need for it, he doesn’t want others to use it to get past him. He sees no problem with the current wealth inequality because he is at the top.
The 100 richest ETH wallets own 25% of mined ETH. Many of those wallets are probably owned by the same person/organization. Switching to PoS will make inequality even worse.
Some critics are definitely jelly about not hitting the crypto-lottery...but crypto is not a solution for wealth inequality.
Another reason is that most people on HN don't realize that there are roughly two sets of people in crypto. There are bitcoiners and then there are all the shitcoiners and scammers (who talk about use cases, ICOs, NFTs etc.). It's ok to hate all the scammers, but bitcoiners should be left out of it, because they're totally different set of people.
I think the overly trashy environment of the crypto space made it an acceptable target for behaviour that's otherwise seen as childish and unacceptable when it comes to other subjects.
Lack of methods to handle fraud and abuse is the one hilighted in this thread.
My impression is that most of the pro-crypto communities are rather new; most people involved just haven't been disillusioned yet.
e.g. why is a pixelated horse worth $10k? the least worrisome conclusion is that it's a tax optimization thing.
I think it has to do with a misconception about how much effort you have to put in to have a good understanding on crypto. If we are speaking about topics like high mathematics, most people realise that their knowledge is not enough to have a meaningful opinion on the cutting-edge. For some reason people on HN treat crypto like politics: almost everyone has a strong opinion without much knowledge. Crypto is a much deeper subject than how it is treated on HN. You need to have not just technical knowledge (like understanding why a proof-of-stake algorithm has no vulnerability is VERY hard), but also very deep knowledge of the philosophy of value/money/trust. For example any substantial interview with Vitalik Buterin discusses the topics in a much deeper way than it is treated on HN.
TL;DR: People are reasonably smart here but extremely uneducated on crypto, and for some reason they think that they are informed enough to have a strong opinion.
As the other commenter said, "censor resistant" is impossible to achieve. It's society the one that gives value to things, and society can decide to censor you and stop you from storing/getting value from that network. Not to mention that most blockchains are traceable, so it's not that difficult to know how money is flowing.
> potentially the best store-of-value known to mankind so far
Why? This always happens in crypto: somehow it's going to fix a lot of issues even if the features that differentiate it from existing solutions don't have anything to do with those issues.
Are you a gold investor? I am. There are lots of problems with gold: 2-3% inflation, hard to store, hard to transfer, hard to divide, hard to examine whether it is really gold. BTC has some advantages (and some disadvantages). Proof of stake ETH have even more advantages (but also some more disadvantages). It is meaningful to research this, experiment with this, and not treat it as complete bullshit.
Most people don't deal with those problems because they use banks and official currency. If the target of the blockchain is to replace gold, then I don't know why people insist on regular people using it.
> It is meaningful to research this, experiment with this, and not treat it as complete bullshit.
Of course it is. But it's also meaningful to not treat it as the revolution as the crypto community does, or say that the people who don't think crypto is great is just uneducated.
In fact, it has happened to the first two, at least temporarily. Someone who bought gold in 1980, say, is probably not particularly happy with it as a store of value today (adjusted for inflation, they _may_ just about be breaking even now assuming that they paid no transactional or storage fees); the same goes for someone who bought bitcoin in May. Or, er, an hour ago.
Picasso's time will presumably come, too.
First, I am very crypto skeptical, but I don't have any problem with "research continuing". However, that's not what I am experiencing. If crypto enthusiasts were off in a lab trying to figure out how to make it solve a real problem then great! Instead, I am the "tech expert" for many of my friends and family, and frequently have them reach out to me as they are on the verge of putting a non trivial amount of money into crypto that they can't afford to lose. Most of these people can barely keep their passwords safe, so I have to spend a lot of time talking them out of it because I care about them. A similar thing happens at work. Some random business exec has a great idea to "use blockchain" for some thing that frankly would be better solved with a regular database. I've had to spend a lot of time convincing business people to not use crypto or NFTs yet.
Second, what you're doing, and many crypto people do this, is identify real problems that would be great if we could solve them. And then you go, "and isn't crypto great because it hasn't solved these problems, but maybe it could". Yeah, maybe, but it hasn't yet. Crypto reminds me of the semantic web people in a lot of ways. They said, "wouldn't it be great if semantic information were embeded in data and APIs could be machine understandable". Sounds a lot like smart contracts doesn't it? Yes, it would be great if we solved that problem, but we never did. The most we got from the semantic web was the semi-useful json-ld you seen in HTML headers for SEO optimization. Here's the thing, the vast vast majority of new ideas don't pan out. It's a lot easier to identify legit problems than it is to solve them. Crypto people get super excited because it would be amazing to solve those problems, BUT there's no good reason to believe it's likely that it will. I say this as someone who spent years trying to get teh semantic web to work. It never did.
Neither of those things are true about Bitcoin (it will not become deflationary until 2140, and "censor-resistant" requires a lot of extra elaboration). But then what's the economic basis for that being a good store of value?
I'm mostly upset with crypto because it hasn't delivered on any promise, while still causing untold ecological damage, and has tilted the price of computing equipment so already rich industrialists can earn even more. Up until recently that was just GPUs, but the latest invention in the space is they made a cryptocurrency based around using up hard drives. The joy.
but every once in a while great discussions pop up here, vitalik buterin himself even posts here sometimes, also that guy from coinbase etc
Actually, I was flagged over $6000 deposit over the sale of a car.
The IRS gives rewards to bank employees if they report (successful conviction) any suspicious behavior.
I still don't know why I was flaggged. Probally because I had long hair at the time?
I had a bunch of sleepless nights over that incident, and a bunch of emails back and forth.
Internet file sharing is older than you think. Together with remote terminal access (TELNET), file transfer (FTP) is one of the oldest Internet protocols. When file transfer over the Internet first started, that is, when the Internet itself started, it was not "illegal".
Biggest eyeroll in history.
I don't think what the government calls "drugs" should be illegal, but, selling and buying drugs with cryptocurrency is an oft advocated for activity that I've seen in these communities.
As for the legitimacy of the law itself, and the opinion of the 'crypto community' on it: the distinction you're missing is that some laws prohibit victimless crimes, by infringing upon the freedom of contract, and always in the name of some supposed greater good, whether that's 'limiting systemic risk', 'protecting retail investors' or 'preventing money laundering', while others prohibit genuinely victimful crimes, where one party violates the rights of another. It can be entirely morally consistent to oppose the former while supporting the latter.
In fact, we have already seen what happens when the financial industry is entirely deregulated multiple times worldwide.
https://www.theatlantic.com/politics/archive/2016/06/enforci...
When such laws are used to prohibit mutually voluntary interactions between consenting adults, I think it's a human rights violation, and it is an accurate adjective to use, whether it's the CCP doing it to "maintain social harmony and political stability", or the USG doing it to "limit systemic risks to the financial system".
>>In fact, we have already seen what happens when the financial industry is entirely deregulated multiple times worldwide.
That is a revisionist account put out by some of the most powerful special interests in the world, who benefit from rampant gatekeeping/centralization of private financial interaction.
His own explanation is the one I find the most truth in. https://sites.google.com/view/hackersconfession/home/hacker-...
I don't know about this but I agree that he doesn't seem to set out wanting to steal $600mio. Sounds like the typical "hacker" mentality where he's prodding around for security holes and just happened to find one.
It seems most people using crypto currencies now have basically no knowledge about it, so I guess this will happen more often in the future. Now, "everyone" is into cryptocurrencies, and most of them could probably not name a single algorithm used for cryptography.
It's so simple to stay anonymous online. If someone took your currency then it's unlikely you'll ever figure out who it was.
Speaking as a dumbass who noticed the news in 2013 about bitcoin reaching $ 1k or something, then realizing the key for a wallet with 52 BTC was on a drive I wiped some years prior to that.
Well played to whoever found a flaw, if that's what happened.
Edit: It should probably be designed as a contract which pays out only once a predetermined number of fake blocks have been mined, and the payout to the solvers will be proportional to the number of blocks they have in the final solution chain (wallet addresses of solvers should be encoded in the empty blocks they mine to prevent front-running, which will destroy the incentives). It should be possible to submit any solution to the contract so that everyone competes. This includes solutions that are mined by actual bitcoin miners, effectively pitting the miners mining real blocks against the miners mining empty blocks. Someone who is more skilled than me should design such a contract and put it on Ethereum, ready to receive Ether that someone "finds".
Edit: Recent block 695416 generates about 6.5 BTC to miners and has only 0.0748 BTC in total fees. Fees would have to increase by more than a factor of 64 to make up for the difference. https://live.blockcypher.com/btc/block/00000000000000000001c...
I think we're past trying to assume peoples identities based on writing styles, it's too easy to fake for the hackers, simply drop 1% of the words you're using and now suddenly people think you're no longer a native English speaker.
And not only is it easy to guess wrong or easy for the hacker to fake, it also adds absolutely nothing to the story/evidence/history by trying to guess the country they are from. If you're right, nothing has been gained. If you're wrong, you've just blamed the wrong nationality, again with no gain if you're right.
This is a bit of my point. If I'm from Uruguay (and not native English speaker) and I want to to be a anonymous user that wants to pretend to actually be Slavic, I can easily look up common mistakes (like missing `is`) in order to foster the image of me being from somewhere I'm not.
Typing in a way you don't usually type is a common way to mask more of your identity.
https://sites.google.com/view/hackersconfession/home/hacker-...
How about Vietnamese?
I love the idea of a digital native currency. But I also love financial protections that have grown up over thousands of years.
The mints of each country could solve that tomorrow (is there a FOSS blockchain already that does a "we know there are 1 trillion Euros in existence, here are the tokens, no need for mining"?)
Yeah, this is a contrast/friction that exists in the ecosystem. Some people just want something that is like a "digital native currency" that works kind of like banks today (with the same protections at least) but works across banks/applications and somehow also is at a fixed value.
Others want "decentralized cryptocurrencies" that works the same as described before, but without any centralized control or issuance and without the "protections" as the protections can also be used against people, not just for.
Neither is "right" or "correct", just two different views inhabiting the same ecosystem.
Why not drop both protection and regulations for that protection from the second group and not bothering anyone?
Nah - we have this nanny like state because there are millions and millions of people and despite what Libertarians say, they cant all pay that much attention all the time.
Honestly the only way most of us make it through a year is because all the shit we rely on just does as it is expected.
In short, if you can't trust one politician/bank/sewage plant it breaks faith in all politicians/banks/sewage plants - That's no good for anyone
Which is funny as for the longest time crypto's argument was that FIAT regulations/manipulation only protects the rich, not individuals. Well here we are talking about network that rolled back because some rich people lost money and another example of organizing one of the biggest manhunts in crypto history because of a code bug abuse. Yet average people who lose money are being told "code is law", should have watched your keys or made smarter investments fool!
Maybe medium is not the issue here...
Now what about things that are not really US dollars but convertible? There are a thousand weird instruments I barely have heard of. God knows if they should get a UUID?
And loans - look everyone loves to rag on fractional banking but we want the amount of currency in circulation to prety much match the value. Having banks create currency at the margin works pretty well as a distributed solution (we like those). Imagine the federal government assessing what your widget factory is worth every ten years.
Do we stop banks doing that? do they hand out UUIDs as well? Will there be two tier currencies (see Scottish banks).
It should be a simple solution, but nah.
- function and variable naming - social conventions around ownership - stated intent by code writers - common sense
By any reasonable standard, this was theft.
Is a door with a pickable lock always unlocked? No, that would be silly. What makes using a key on a lock different from using a lockpick. Social convention, intent of the creator, common sense, the fact that one thing is called a key, and the other a lockpick.
Now, it seems that the thief was afraid of legal reprecussions, but that is sort of outside the scope of ethereum. It happens purely 'off chain'.
The interesting exception to this story is the original DAO heist. Where an Eth hard-fork was made to reverse the heist. In this case there was an intervention. That intervention took broad consensus of miners and developers. So it takes a pretty big effort to get disputes "resolved" away from what the smart contract says. That is an interesting deviation from normal contracts before a court. Personally, I do think that Eth should not have forked the DAO heist away, but I understand why they did.
IMO, the answer is fundamentally that it expands the market (no more limitations like medallions, scales better than hiring dispatchers, etc.), and creates more demand overall (more people use these cars than would've used traditional taxis).
Of course, even the customer support gets automated away, until humans only need to deal with exceptions to the exceptions (that automated support was supposed to handle). So there can still be economies of scale and efficiency.
halting problem smart contract that's
both fraudulent and not at the same time
How would the halting problem help with that? With the halting problem, can't you just write code so that nobody knows if it will halt or not? I wouldn't say it halts and not halts at the same time. We just don't know if it will halt.How much would they offer to him?
Also it does look like they really did try to launder it:
> Tether froze more than $30 million in response to the hack, Tether Chief Technology Officer Paul Adroino tweeted.
> About an hour following Poly Network’s announcement of the hack, the perpetrator attempted to move stolen assets through the Ethereum address into Curve.fi, but the transaction was blocked. The hackers continued trying for about 20-30 minutes before an anonymous user sent the hackers a message on the blockchain that USD Tether had been blocked.
> The user told the hackers to try depositing the stolen tokens without Tether, which the hackers did successfully and they deposited all the addresses into Curve. The hackers then sent the anonymous user about $45,000 worth of ethereum for their help.
https://blockworks.co/hackers-steal-over-600m-biggest-in-def...
He bit off way more than he could chew it seems.
Unless he gives it all back, he is probably fucked if he is caught by American authorities, and even then it would not matter probably. Unlike France, no 5 years sentences in the good ol us of a for major fraud.
"Your honor, I returned half of it, so half the sentence"
"Yes, I will cut it from 150 +50 years to 75 +25"
Greed kills.
These are the type of arguments that reinforce my belief that crypto assets do not make any sense. Yet.
For all the libertarian bullshit about decentralising and no control and “you can’t shut it down” when someone actually makes off with a whole bunch of coin what does everyone do?
Relies on centralised control to shut the hacker down and cut them off.
SMFH.
It's a hot take, and a lot of people will write this off as pretentious and egocentric, but I believe him.
Big crypto as a whole has to stop.
The original intention of cryptocurrency was to be an experiment (!!!) with providing alternative peer-to-peer transactions that didn't rely on the value of a centralized economy. It didn't account for what would happen when a part of that load shifted to the network.
A lot of people have a hard time understanding the scale of the world's economy, but it's really something to behold. Each one of the world's 8-billion-some people need a handful of resources to survive, and to be conservative I'll estimate that the average human makes 2 transactions a day. That's 2 documented transfers, per person, per day. Those numbers add up very quickly, and if even a fraction of them start to pile onto a collapsing concept, there's no way it can sustain it. Hacks like this are an important step towards reminding people that "money" on the blockchain isn't actually money. You're purchasing a digital asset that now suffers the same issues that the stock market does, except the FCC can't do anything about it. And they shouldn't do anything about it, either. This smoking garbage pile is a great example of how such large, experimental networks can break down at every level.
I'll file it between "Exit Scamming" and "Hash Collision"
2) The amount of morale hazard we have allowed to build up since the great financial crisis is astronomical. No one has been held to account for that mess and the Too Big To Fail mindset has become deeply entrenched. The fact that no one backstops crypto is one of it's biggest features, we cannot continue to play the world's biggest janitor when the system breaks down, and regulation is not preventing these things.
3) Visa, Mastercard and other operators of the worlds biggest payment networks are expanding to crypto. They definitely have a perspective on scale and are embracing this 'experiment'.
People don’t actually want this. The problem in 2008 wasn’t bankers or any other boogieman. The problem is that people want housing to be affordable/accessible, but they also want it to be an investment/retirement plan.
If you subsidise housing to make it affordable (a market distortion in itself), and you encourage appreciation in said market (another distortion) you get bubbles. We stopped this bubble from popping so that boomers didn’t have to take a retirement hit. But Wall St’s role in all of this is insanely small. They played the role of the dealer at a card table. The players are the average Joes and the casino is the Fed.
This didn't happen. What happened was an extreme lowering of the barriers to entering into a mortgage contract, such as minuscule down payments (which are back), NINJAs, and floating the extremely high-interest rates on those mortgages to volatile and completely gamed numbers like LIBOR. After collecting these mortgages into a bundle, they paid someone to declare them as safe as US treasuries, and immediately sold them on/started borrowing against them.
You can absolutely do this with crypto, except it would be even easier.