14 ms·
Chasing the DAO Attacker’s Wake – A second exploit
- Animats 10y agoSo one contract can call a function in another contract, in the middle of their transaction: if (_recipient.call.value(_amount)()) { // vulnerable That's inherently a scary feature, and it was exploited. Etherium's "Solidity" suffers from the desire to have it be a general-purpose computer. It should have been if-then rules, or a logic tree, or a decision logic table - a finite representation of business logic subject to exhaustive case analysis. Contract executions should have been atomic transactions - either everything commits, or everything gets rolled back. Stack overflow and running-out-of-gas terminations are inherently trouble. Etherium needs to go back into the shop for a redesign. At least we found out early that this isn't going to work.
- alfiedotwtf 10y ago> At least we found out early that this isn't going to work. $US150M later isn't early
- reustle 10y agoMaybe that just means the $150M was early too
- jacquesm 10y agoThat's called a bug bounty.
- cloudjacker 10y agoThis guy
- pjc50 10y agoI came up with "self-distributing bug bounty piñata" in the last DAO-failure discussion https://news.ycombinator.com/item?id=11921677 https://news.ycombinator.com/item?id=11921677
- jacquesm 10y agoHehe, that's even better. But it is the essence of the matter. If you put $100M in a bucket you've just incentivized the worlds bad guys to audit your production in order to figure out how to open the bucket to get to the loot. And this goes for all of commerce, which is an important realization: security is not an all-or-nothing proposition, it is an economic affair. Whatever you wish to secure, you can expect to expend a reasonably constant fraction of that on the act of securing it. So if you wish to secure $100M you will have to do a much better job than if you wish to secure $10M or $1M, just like you're going to spend more money on the lock for a $1k bike than a $25 junker. When DOA ended up being over-subscribed they should have immediately yanked the emergency brake because whatever plans they had would end up being moot by virtue of storing more money in the bucket than they originally planned. Their security measures would by definition not have been up to the task because they had planned to secure a much smaller amount. Either that or they were ridiculously over-confident.
- drcode 10y agoMeh, the money is going to likely be routed back to the original owners via a fork.
- pjc50 10y agoThe problem with a redesign is that the only way you're going to get a reliable design involves a lot of formal verification, which is a rare skill and time-consuming to perform. Whereas the cryptocurrency space is a startup environment: there's huge pressure to launch first so that you can get the money that people are begging to throw into untested speculative finance systems. And the refusal to countenance human control or any of the normal forms of accountability - these things are designed out of the system deliberately - means that there's going to be a long, slow, expensive period of designing them back in.
- deleted 10y ago[deleted]
- leesalminen 10y ago> there's huge pressure to launch first so that you can get the money that people are begging to throw into untested speculative finance systems. I got a good chuckle out of that one.
- htns 10y agoI'd be interested in knowing how this has been dealt with (or not) before. Was the problem recognized when designing E?
- mbrock 10y agoI don't understand "you can't assume anything about the state of the contract." Surely the contract's state is only modified by the contract's own code, which means you can assume that the state is not altered arbitrarily but only according to the rules set up by the contract. Yes, you need to be careful about external calls that make altering calls to you.
- nugget 10y agoWell in theory couldn't any obscure exploit in the underlying framework (Solidity or related) be used to exploit contracts based on it? I think a comment from yesterday nailed it - that a system like this may be perfect for processing a repetitive, high volume of relatively low value contracts, wheres high value contracts may be better served by traditional systems wherein the Courts provide dispute resolution as needed. Broadly it would seem like Ethereum needs to isolate the potential for loss due to zero day exploits such that it is less than the savings realized from operational efficiency.
- jerf 10y agoThe problem pointed out in this article isn't that it is impossible to write correct contracts. The problem is that it means that it is superhumanly difficult to write correct contracts, using the current feature set and infrastructure. This is especially true in what is theoretically an actively hostile environment, which the DAO hack proves is also actually an actively hostile environment. It is theoretically possible to call out to another contract that has the ability to make further calls safely... but how can you be sure you've done it safely? This isn't a unique problem. It arises in imperative-based programming all the time. But what in Javascript may be a bit of a coding error that means the next page of search results didn't load this time, in Solidity it means you may lose your shirt. Also, I'd suggest that after-the-fact "static analysis" tools don't help. It's basically the same situation that real-world computer security is in, and right now, that world is massively advantage attacker, with generally far less direct incentive to attack than a blockchain functioning directly as money does. If the static analysis tool is open enough for "everyone" to use, the attackers get to use it too, and they can use it on all contracts at once because they're all open, and they have all the motivation to do so before the proper contract owners have time to fix their contracts. Every time the static analysis tools release a new check, it's an advantage-attacker race between exploiting the new check and fixing the contracts. The attackers are going to win big, repeatedly. A Turing-complete blockchain needs to come out of the gate nearly 100% correct on this front, just as it needs to come out of the gate nearly 100% correct on the encryption security.
- refulgentis 10y agoWhat if the DAO invested in short-selling Ethereum? 🤔🤑
- andrewfromx 10y agoas long as eveyone agrees :)
- curiousgal 10y agoThere was a 3K BTC worth short position right before the attack.
- pigeons 10y agoNo, there were 3K BTC worth of short ~positions~ right before the attack.
- TazeTSchnitzel 10y agoHow did you manage to post emoji? I thought HN stripped those (somewhat overzealously…)
- refulgentis 10y agoWhy I used them: I was a little punch-drunk waking up, and the DAO stuff the last couple days has been a great representation of the worst basic instincts we share. I was surprised to see an informal snarky response stay positively scored. I was even more surprised to see that the emoji weren't stripped. As for the question you actually asked, how did I? Emoji keyboard from iOS 10b1 on an iPhone 6s Plus in Safari.
- lostmsu 10y agoPotential vector of attack to look for, not an exploit. Thus, flagged.
- goldenkey 10y agoI guess you own some Ethereum and have no shame.
- mbrock 10y agoI'd love if we could keep HN free of these boring accusations of shilling. It makes the Reddit cryptocurrency forums really tedious to follow.
- goldenkey 10y agoI guess the shills are out in full force this morning. Unfortunately when 40 million is on the line, people tend to greenfield and ruin the nuetral bias of social websites.
- freedaemon 10y agoIt's an exploit because you can do this live on the DAO (and potentially other deployed contracts) today. Vector of attack for future contracts but already impacts the DAO.
- Karunamon 10y agoAt best, the headline is^H^H was inaccurate then.
- bouk 10y agoSeems like this is what mutexes were invented for
- JulianMorrison 10y agoWith a mutex, an A -> B -> A call would deadlock if the mutex is the stop-and-wait or spin-and-retry sort. It would have to be a succeed-or-exception mutex, which is not a common design.
- vessenes 10y agoThe typical solidity dev is "but mutexes cost so much gas!" There's an optimization problem not yet sorted out here. If I were king of ethereum, (happily I'm not), I'd make a very cheap mutex support part of the eth vm and encourage solidity and serpent devs to use it as needed.
- drcode 10y agoI suspect we'll see something like mutexes in the next ethereum EVM revision.
- vessenes 10y agoYes, that would be a kind and fine thing to do, or at least change the cost of a specially designated bool argument to something cheap. You get one per contract, kind of thing. Or you pay on deployment.
- woah 10y agoNone of these "exploits" really sound much more dramatic than using a database without transactions
- goldenkey 10y agoActually it's much worse, it's the equivalent of calling a function that ends up doing something totally different than you thought it would. Very reminiscent of a web bug that has since been blocked by newer browsers: parsing JSON data that ends up using a constructor redefinition exploit to execute arbitrary JS. Pretty much this: http://www.thespanner.co.uk/2011/05/30/json-hijacking/ http://www.thespanner.co.uk/2011/05/30/json-hijacking/
- heliumcraft 10y ago"This impacts all contracts on Ethereum, not just the DAO. This is an issue with Ethereum’s JavaScript-like programming language (Solidity)." No it doesn't, no it's not. It affects contracts that use this functionality with arbitrary untrusted contracts (which is a bad idea), and most contracts just don't use this functionality at all.
- drcode 10y agoYeah, all this shadenfreude from people who (wrongly) predicted ethereum would never work, and who want to feel vindicated, is predictable but frustrating.
- curiousgal 10y agoHonestly, I was in awe by r/bitcoin's reaction to this whole DAO debacle. I thought that the whole Mt Gox "incident" has taught them some empathy to people losing money but I was very wrong.
- vertex-four 10y agoEmpathy? Bitcoiners? A large chunk of them are anarcho-capitalists who measure a person's right to survive by how much money they can make, and most of the rest are in it to make themselves rich. There's a fair few who are mostly in it just because it's cool tech, but they avoid Bitcoin forums now due to the former two groups. Note that this covers most other cryptocurrencies as well.
- 099812891 10y agoSure, ephemerum works in the same manner as Windows 98, Adobe Flash and sendmail.
- etherial 10y agoSo hugely popular beyond anything you or anyone you know has ever made?
- AJ007 10y agoNearly a year ago I made the comment -- "Who are these people[1] and what credentials do they have to build and run a cryptocurrency platform?" [1] https://angel.co/ethereum-1 https://angel.co/ethereum-1 Today, not a single cryptographer, mathematician, or anyone with software security experience is listed on the Ethereum Foundation member list[2]. I am not attacking any individuals by themselves, but as a group this says a lot. For the record, what I see listed online today is a: consultant, magazine founder, a programmer, and a lawyer. On the advisory board a sales person, a psychologist, a leveraged debt consultant. On the "special advisors" list, which I have no idea what this means, maybe someone who answered a phone call a few times, one person with a bunch of business credentials, something "fintech" related with little explanation, and a tech CEO. Maybe the Ethereum Foundation doesn't need anyone with deep experience in cryptography and security? [2] https://www.ethereum.org/foundation https://www.ethereum.org/foundation
- heliumcraft 10y agoyou are looking at a page listing boards and advisors, of course those wouldn't be the technical people. Look at the core teams behind the different tools (too many to list here quickly), as well as the devs working in companies in the ecosystem such as consensys and ethcore, they are all quite qualified and smart people. Two examples come to mind are vlad zamfir and Dr. Christian Reitwiessner.
- djcapelis 10y agoI'm not really familiar with either of them so maybe there's ton of security experience that they have that I'm not aware of... but I sure wasn't able to find any when I looked up the history of either of those two people. If you wanted to make the case that they had programming experience, sure, totally. But software security experts? How do you figure either of them being one of those?
- jsprogrammer 10y agoWhy would boards and advisors of course not be technical?
- 10y ago
- niftich 10y agoThis reads a little sensational. The original source [1] referred to in the article looks at the issue in more detail. [1] http://pdaian.com/blog/chasing-the-dao-attackers-wake/ http://pdaian.com/blog/chasing-the-dao-attackers-wake/
- freedaemon 10y agoAgreed the original article does a great job. However, without the "sensational" title and simpler explanation people were not paying proper attention to this. The original article discussed a bunch of other things as well -- everyone should read it to understand the details.
- curiousgal 10y agoBy people you mean traders. This sensationalism is utterly unnecessary since the non-traders involved with Ethereum read the original article and are capable of understanding it.
- dang 10y agoOk, we changed the url to that from https://blog.blockstack.org/solar-storm-a-serious-security-exploit-with-ethereum-not-just-the-dao-a03d797d98fa#.rre7cp9zc https://blog.blockstack.org/solar-storm-a-serious-security-e..., and added the subtitle (of that post) to make the point clearer. We also merged the comments from https://news.ycombinator.com/item?id=11934472 https://news.ycombinator.com/item?id=11934472 here, since there weren't that many of them and they were about the same post.
- JulianMorrison 10y agoIsn't this just a normal data race with stateful actors? Something modified the data while A is calling B (doesn't have to be B, could be any X) in between a call and its response. The answer to this is that mutation needs to be kept under control. Immutable data structures in mutable buckets. Locking around the data that mustn't change. Deep copy all state before calling out. And so forth. This is basically an understood problem and I'm a bit appalled that Ethereum didn't build protection against it into their design.
- mbrock 10y agoUnfortunately, worse is better.
- DennisP 10y agoIt's not quite a data race, since there's nothing parallel at all. Transactions are put in a particular order and run one at a time. So it actually does have to be B that does the modification. One easy solution is to have just one external call per method, and always put it at the end of the method. Another is to use a single mutex for all public functions of the contract, so any callbacks fail.
- HoopleHead 10y agoEvery article I see on etherium mentions the DAO. Not one of them explains what it means. Gotta love unexplained acronyms!
- mtgx 10y agoIt means "Decentralized Autonomous Organization". It's usually used as a common term ("I'm creating a DAO"), but these guys called theirs "The DAO". This attacker exploited "The DAO".
- crispyambulance 10y agoOk, but you realize that merely listing the words in the acronym does nothing to explain what it actually is. The whole ethereum "ecosystem" is a radical and new construct that very few people are familiar with. Given that, I would even say that the name "Decentralized Autonomous Organization" is a deliberate, almost satirical, obfuscation.
- rspeer 10y agoWhen you say it's "usually used as a common term", that sounds like wishful thinking. It seems you want to take the term back and distance it from The DAO. But new efforts like this won't call themselves "a DAO" anymore than a new airship would be called "a hindenburg".
- JulianMorrison 10y agoDoubleclick drag rightclick search on Google. Here, I googled it for you https://daohub.org/ https://daohub.org/
- rfrey 10y agoThat's snarky and unnecessary. And your linked site actually doesn't define the term until the third page in, after using "DAO" many times. And even then it's not a definition, it's a sentence that happens to spell it out. I had to ctrl-F to find it.
- 10y ago
- DennisP 10y agoAs the article briefly suggests, this problem can be completely avoided if every method has no more than one external call and always puts it last. I'm messing around with contracts to do about a dozen different things, and it turns out to be easy to meet this restriction, as long as I'm willing to design the UI accordingly. (E.g. don't send money to lots of users in one step, just update their balances and make them call a withdraw function.)
- cheeze 10y agoIt seems like there are quite a few pitfalls to avoid just in writing these contracts, and they aren't obvious things in many cases. This seems incredibly dangerous, given what is at stake when a bug is included in a contract. Is there any form of auditing that contracts can go through to not have these pitfalls? I wonder how many of them are still undiscovered...
- bradenb 10y agoIt would be nice if you could dry-run each execution of the contract and verify it passes a series of tests. It seems to me that regardless of how these contracts are written, you should be able to verify the behavior.
- jcoffland 10y agoThat's what the test net is for.
- jarsin 10y ago> I wonder how many of them are still undiscovered... Yup. I find it interesting how everyone only thinks it's these couple of issues. I wouldn't do anything beyond experiments with it at this point.
- jsprogrammer 10y agoI have asked if there is a contract simulator and I got no response. Even though the coding experience seems pretty poor, it doesn't appear to be particularly dangerous as bad contracts can just be rolled back.
- thom_nic 10y agoInteresting Ethereum uses the term "function" however in programming we understand a pure function to be an operation that always returns the same result given the same inputs. I don't know anything about Ethereum, but if functions rely on external shared state then they aren't pure functions, are they?
- mbrock 10y agoEthereum (well, Solidity) calls them methods, not functions, and everybody agrees that methods are potentially state changing procedures. Moreover, there is a staggering amount of precedence for using "function" without implying purity, so even if Solidity did call them functions, that would be entirely normal terminology. And, well, the entire point of invoking a contract is to effect some change to the state of the blockchain, so it would be strange to expect that Solidity methods were pure functions.
- mst 10y agoWell, solidity is kinda javascript-style syntax and that's the keyword from javascript. On a pedantic level, you're absolutely correct, but real-world usage generally makes 'function' equivalent to 'subroutine', hence why we have the specific term pure function to disambiguate.
- lotsoflumens 10y agoNo - a pure function is a function that has no side-effect (other than heat loss). You are talking about referential transparency. Even functions that are not pure can be referentially transparent.
- nawitus 10y ago"that impacts all of Ethereum" Well, all of Ethereum smart contracts which are written in Solidity and which use a "call construct" in a certain way.
- cel1ne 10y agoSo what they should have implemented is communicating sequential processes / actors instead of arbitrary calls. The more I read about ethereum's technical details, the more it sounds like a joke to me.
- heliumcraft 10y agoIt's a code mistake by who did the DAO code. (DAO != Ethereum) It's more the equivalent of using eval in your nodejs code to evaluate some parameter received from a user. It's a stupid code mistake, but you wouldn't say the internet is a bad idea because some website got hacked.
- cel1ne 10y agoI know that DAO != Ethereum. Letting programs call arbitrary function on each other is a fundamental design-flaw in every concurrent system.
- heliumcraft 10y agoI dont think I would consider Ethereum a "concurrent system" in the same sense. This functionality is there because it allows contracts to interact with each other. This allows a million different type of applications, e.g you could create a crowdfund using a gold token hold by a multisgn. The contracts are usually trusted and their addresses set from beginning, so this is never an issue (unlike what the article implies). The DAO however allowed an arbitrary address to be used as the contract to talk to. This is flexible because it allows contracts to be update themselves, or update who they talk to, but if the contract is malicious and there is a reentrancy, then that's the issue, but again, it's the contracts fault, not the whole platform.
- msbarnett 10y ago> This is flexible because it allows contracts to be update themselves, or update who they talk to, but if the contract is malicious and there is a reentrancy, then that's the issue, but again, it's the contracts fault, not the whole platform. The platform is being shown to be superhumanly difficult to write secure contracts for. That's a platform issue.
- IncRnd 10y agoSolidity is to Solid as Oracle is to Unbreakable. These really are solved problems.
- homogeneous 10y agoWith all this fuss over ethereum security flaws, can someone explain to me the practical use case for these smart contracts? I just don't understand where the benefit comes in. It seems like any type of contract that would be useful requires a human to qualify the meaning of the terms since these contracts cannot autonomously measure the state of the world. Even something as trivial as betting on sports requires deference to a trusted authority to say "this team won". What advantages does an ethereum smart contract provide over, say, some kind of trusted bitcoin escrow site?
- aakilfernandes 10y agoIn the scenario you gave, the trusted oracle never needs access to the funds. This is important for legal/regulatory reasons. This would not be possible without smart contracts. Yes, its not 100% trustless, but its far more trustless than the alternative.
- gomox 10y agoSome simple use cases: - a multisignature wallet, that requires more than one person to sign off on a transaction before it can happen. - payment schedules or any kind of transaction that does not function exactly like a one time, full size payment (payments, debt, etc). - more ambitious ideas, like the Slock.it ones, involve smart locks that hold funds while granting use to a resource, and only return them after access has been revoked In all of the above the inputs are contained in the blockchain and therefore have no need for trusted oracles.
- homogeneous 10y ago> a multisignature wallet, that requires more than one person to sign off on a transaction before it can happen. This is possible with bitcoin isn't it? What does the added complexity of ethereum bring to the table? > payment schedules or any kind of transaction that does not function exactly like a one time, full size payment This also seems possible with bitcoin, but it's also a problem that has already been solved better by the traditional payment system (e.g. netflix debits my credit card every month, why would I use a cryptocurrency solution instead?) > more ambitious ideas, like the Slock.it ones, involve smart locks that hold funds while granting use to a resource, and only return them after access has been revoked Can you go into specifics here? I'm not really understanding. It sounds like you're describing a kind of autonomous collateral system, but I can't really think of any practical examples where this would be useful (without bringing human judgement into the mix).
- unfortunateface 10y agoThe backers of the DAO selflessly created a $150 million bug bounty for Ethereum and their Smart Contract - Good for them.
- throwanem 10y agoYeah, but they seem to be awfully reluctant to pay out on it.
- saynsedit 10y agoAny code that calls arbitrary callbacks is prone to failure. The context in which a callback is called matters. Calling a callback at the end of a method avoids interfering with the caller's state but ignores the state of the caller's caller. An ethereum contract will only be tractably analyzable if it avoids dynamically invoking arbitrary callbacks.
- deegles 10y agoWill the attacker be able to spend any of the funds?
- int_19h 10y agoGiven that trust is the single most critical aspect of the entire platform, why doesn't it use languages (for both the platform, and the contracts), programs in which can be easily formally verified, and for which tools for such verification already exists?