5 ms·
Please read http://hackingdistributed.com/2016/06/17/thoughts-on-the-dao-hack/ http://hackingdistributed.com/2016/06/17/thoughts-on-the-dao.... Solidity langua
by amaks 10y ago
Please read http://hackingdistributed.com/2016/06/17/thoughts-on-the-dao-hack/ http://hackingdistributed.com/2016/06/17/thoughts-on-the-dao....
Solidity language makes very hard to write safe code:
Is Ethereum/Solidity Suitable for Secure Smart Contracts?
It's clear that writing a robust, secure smart contract requires extreme amounts of diligence. It's more similar to writing code for a nuclear power reactor, than to writing loose web code.
Yet the current Solidity language and underlying EVM seems designed more for the latter. Some misfeatures are:
A good language for writing state machines would ensure that there are no states from which it is impossible to recover.
A good language for writing state machines would make it painfully clear when state transitions can and cannot happen.
A good language for maintaining state machines would provide features for upgrading the security of a live contract.
A good language for writing secure code would make it clear that there are no implicit actions, that code executes plainly, as read.
The current language does not fulfill any of these commandments, and in fact, the last one, involving implicit recursive calls, is what did The Dao in.
The SlockIt team even had the designer and implementor of Solidity perform a review of their code. If he cannot get something like The DAO to be secure, no one can.