51,637 karma · joined December 4, 2010
https://bpier.re
github.com/bpierre
twitter.com/bpierre
warpcast.com/bpierre
Posted by Vitalik Buterin on June 17th, 2016.
An attack has been found and exploited in the DAO, and the attacker is currently in the process of draining the ether contained in the DAO into a child DAO. The attack is a recursive calling vulnerability, where an attacker called the “split” function, and then calls the split function recursively inside of the split, thereby collecting ether many times over in a single transaction.
The leaked ether is in a child DAO at https://etherchain.org/account/0x304a554a310c7e546dfe434669c...; even if no action is taken, the attacker will not be able to withdraw any ether at least for another ~27 days (the creation window for the child DAO). This is an issue that affects the DAO specifically; Ethereum itself is perfectly safe.
The development community is proposing a soft fork, (with NO ROLLBACK; no transactions or blocks will be “reversed”) which will make any transactions that make any calls/callcodes/delegatecalls that execute code with code hash 0x7278d050619a624f84f51987149ddb439cdaadfba5966f7cfaea7ad44340a4ba (ie. the DAO and children) lead to the transaction (not just the call, the transaction) being invalid, starting from block 1760000 (precise block number subject to change up until the point the code is released), preventing the ether from being withdrawn by the attacker past the 27-day window. This will later be followed up by a hard fork which will give token holders the ability to recover their ether.
Miners and mining pools should resume allowing transactions as normal, wait for the soft fork code and stand ready to download and run it if they agree with this path forward for the Ethereum ecosystem. DAO token holders and ethereum users should sit tight and remain calm. Exchanges should feel safe in resuming trading ETH.
Contract authors should take care to (1) be very careful about recursive call bugs, and listen to advice from the Ethereum contract programming community that will likely be forthcoming in the next week on mitigating such bugs, and (2) avoid creating contracts that contain more than ~$10m worth of value, with the exception of sub-token contracts and other systems whose value is itself defined by social consensus outside of the Ethereum platform, and which can be easily “hard forked” via community consensus if a bug emerges (eg. MKR), at least until the community gains more experience with bug mitigation and/or better tools are developed.
Developers, cryptographers and computer scientists should note that any high-level tools (including IDEs, formal verification, debuggers, symbolic execution) that make it easy to write safe smart contracts on Ethereum are prime candidates for DevGrants, Blockchain Labs grants and String’s autonomous finance grants.
https://translate.google.com/translate?sl=fr&tl=en&js=y&prev...
I was about to pay for the new logic board, and the person confirmed to me that in case of a recall happening in the future, I would be refunded by Apple. Nice surprise when he asked me where I bought it: since I ordered it on the Apple website, even if it was on the french Apple Store website, they proposed me to replace it using the UK warranty, which is 6 years (!) instead of 1 year in France [2] (I didn’t take the Apple Care).
A few hours after having my computer back, the exact same graphic issues started again. I went back to the Apple Store, and they changed it again. Everything was working fine…
Until two months later, when the sound chip just died: no errors in OS X, but no sound at all (from speakers, microphone or jack plug). I went back to the Apple Store, and they changed the logic board again (it wasn’t a problem because all replacements are covered by warranty).
A few days later, the graphic issues started again. I went back to the Apple Store. Since they changed the logic board three times already, they proposed me to replace the MBP by a brand new one: the latest and high-end model (since they have to replace it with an equivalent), and I even received an external drive since the new models don’t have one, and despite having said that I don’t need it.
I think I have been really lucky: I just wanted to repair it so I could sell it and buy a new model. I ended up with the latest model without paying anything except a few hours spent at the Apple Store.
Lessons learned:
- Buy your Apple computer from Apple if you can.
- You have a 6 years warranty in the UK.
[2] http://www.apple.com/uk/legal/statutory-warranty/
Edit: the legal warranty is 2 years in France, not 1 year.
[1] https://github.com/creationix/js-git
- Everything is programmable, including the UI and the appearance of your modul
- A modul can send and receive messages with the moduls around it
- You start with a predefined and ready to use modul
- Offline support: your modul continues to live on the server when you are not connected
There is no game mechanics at all though, our goal is to create everything using moduls (games, entities composed of multiple moduls, tools…).
Planned features:
- A REST API to do everything remotely
- Code sharing using library packs
I can't wait to see how Screeps work!
Original: http://www.gamasutra.com/view/feature/132517/the_rise_and_fa...
Awesome tool!
A Markdown Community Group [2] has been created on w3.org, and people have started to push some effort in it [3][4][5], but it has been totally ignored since the beginning, despite the communication attempts.
Maybe I don’t have all the informations, but it looks like a waste to me, and I find it disrespectful for the people who worked on the project. All of this could have easily been avoided with a simple communication about the status of the project.
[1] http://blog.codinghorror.com/the-future-of-markdown/
[2] http://www.w3.org/community/markdown/
[3] http://www.w3.org/community/markdown/wiki/Main_Page
[4] http://lists.w3.org/Archives/Public/public-markdown/2014Mar/...
[5] http://lists.w3.org/Archives/Public/public-markdown/2014Jul/...
Browserify [1]. You have all the npm packages available, and your modules are compatible with Node. This allows you to easily test your modules, or reuse some of your modules in the browser, the CLI and a webserver for example.
Stylus [2] is great. Compared to Sass, I think it’s easier, more or equally powerful, and more future-proof. It’s basically a programming language on top of CSS, while Sass looks more like another language that produces CSS. It’s also written in JS, so you can easily write your own plugins (as npm modules).
Browserify and Stylus are also quite nice if your code is component-oriented.
This is how you import a component in Browserify:
require('my-component')
And in Stylus: @require 'my-component'
For the build step, I always use Make because it’s everywhere except Windows, and I switch on gulp [3] if things get complicated or if I need Windows compatibility.I’m using tape [4] and testling [5] (locally) for tests. Simple.
jspage [6] (I’m the author) is a simple tool I often use to transform some JS into a page. Useful for quick tests if you work in the CLI.
Services:
Cloudup [7] is nice for quick screenshot sharing. On OS X, I just use the built-in tool to make a screenshot, and an URL is immediately copied to the clipboard, I just have to paste it to someone. The delay between the moment when you take the screenshot and the moment when the other person loads the page is usually enough for the screenshot to be uploaded and displayed.
scri.ch [8] (I wrote this tool) is a simple drawing tool I’m using to share visual ideas, especially in GitHub issues (just add .png to an URL to get the image). I also use it to make quick interface elements that I can integrate into a web mockup.
[1] http://browserify.org/
[2] http://learnboost.github.io/stylus/
[3] http://gulpjs.com/
[4] https://github.com/substack/tape
[5] https://ci.testling.com/
[6] https://github.com/bpierre/jspage
[7] https://cloudup.com/
[8] http://scri.ch/That being said, I’m almost certain that video formats performs better than gif (e.g. WebM), but the gif format is still the easiest to work with at the moment:
<img src="http://gif.gg/xyz.gif">I may be biased since I wrote it and I’m using Vue.js everyday, but I think it is really comprehensive compared to others.
Edit: if you want to know more about Vue.js [2], especially how the data binding works (hint: no dirty checking, no ES6), the FAQ [3] is a good read.
It's going to be an awful lot of work, with the result that not all
systems will be supported, new bugs introduced and what's the gain
for the end user exactly?
Total refactoring is not a solution. It's much better to improve what
we have. Perhaps with some small refactorings specifically aimed at
making Vim work better for users.
[1] https://groups.google.com/d/msg/vim_dev/x0BF9Y0Uby8/94tmiaBv...[1] https://github.com/mozilla/servo
[2] https://en.wikipedia.org/wiki/Rust_%28programming_language%2...
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
I think the only solution to respect the copyright for this kind of content (amateur content with no identified author) would be to stop publishing it: you can’t sue Tumblr, Facebook, Twitter etc.
Just to be sure: are we talking about the original authors, or the websites who add their watermarks on it?