In other words, if you allow an organisation to change things like refund you, then they might as well just manage their own leger like they do at the minute.
In other words, if you allow an organisation to change things like refund you, then they might as well just manage their own leger like they do at the minute.
USDC exists with reversibility but not all users in the network are forced to use it. There are other protocols like DAI that have different features and considerations. And in many cases these are open source protocols that can be forked as desired.
Probably the closest thing we have like this is the web, which is more or less a decentralized protocol, atop which we have built a lot of centralized platforms.
They don't seem to be ready yet but they look somewhat promising.
I can look at the USDC contracts and see that privileged users have the ability to freeze the USDC in my account.
I can look at the DAI contracts and see that they do not.
Good luck getting visibility into the back-end processes of web2 applications. Even if they publish the source on github, there's no way to verify what they're running
"Smart" "contract" are as invisible to the average user as the backends of web2 applications (or any other applications for that matter). The authors of these "contracts" routinely create buggy contracts because the code is complex [1]
But sure. You can definitely look at impenetrable code written in an esoteric language for an equally esoteric VM and see exactly what it does.
[1] just an example, https://web3isgoinggreat.com/?id=akudreams-earns-34-million-...
But think about where faith is being placed in traditional software vs. decentralized software: with traditional software, you rely on a whistleblower inside the company, or a government agency to expose corruption, malpractice, maliciousness, noncompliance, or incompetence.
In a dapp, there are also knowledgeable watchdogs who are incentivized to expose scams/fraud, or report bugs (I'd wager there are more responsible disclosures in crypto than exploits by bad actors).
Knowledgable researchers keep casual users informed of developments, and give layperson explanations of how dapp works (and Cunningham's law dictates that they're likely to be called out if their explanation is incorrect).
Either way, people are placing their trust somewhere. Traditional applications basically rely a lot on "security by obscurity" which doesn't make them truly secure. And many users enjoy truly transparent applications.
The biggest problem with crypto for the average person is that it's incredibly hard to assess risk in order to develop risk-appropriate strategies and expectations for interacting with crypto. And it can also be hard to get a straight answer when discussing risks (good signals are surrounded by lots of noise). That's why I think that rather than writing off the industry as a whole, those of us who have more insight into the technology (and the risks) should be advising less technical participants to be incredibly cautious, not to approach crypto outside of the top two as an investment without incredible diligence etc. (though, like the author, I'm very much opposed to bitcoin due to proof of work)
Indeed.
> In a dapp, there are also knowledgeable watchdogs who are incentivized to expose scams/fraud, or report bugs
Indeed. Moreover, they are incentivised to actively seek out and exploit those bugs because there are literally no avenues of recourse.
> Traditional applications basically rely a lot on "security by obscurity"
No. No they don't.
> The biggest problem with crypto for the average person is that it's incredibly hard to assess risk in order to develop risk-appropriate strategies and expectations for interacting with crypto.
Indeed. Whereas with "traditional applications" you have anything from regulations to courts in case something goes wrong.
> those of us who have more insight into the technology (and the risks) should be advising less technical participants to be incredibly cautious
Yeah. Yeah. Those who actually have insight into technology clearly and openly call that almost all crypto projects are scams. And that "smart" "contracts" are neither smart nor contracts and run obscure code whose authors often don't know how it works.
The people who pretend to be knowledgable and advising post things like "I can look at the contracts and see <various things>" perpetuating the myth that this is true.