6 ms·
Wow. It's just distributed signed ledgers.
by bmh_ca 9y ago
Wow. It's just distributed signed ledgers.
- andirk 9y agoI think the security an inability to double spend is pretty important too. The ledger is the proof but not the means.
- bmh_ca 9y agoIsn't a double (n+1) ledger the definition of the inability to double spend (presuming Atomicity or reconcilability)? That's a genuine question.
- bhaak 9y agoIt's distributed. You can't presume atomicity. The consensus rules ensures that everybody (eventually) stays on the same chain and the PoW mechanism ensures that (after a few confirmations) it would be too costly to change the blockchain for a double spend.
- DennisP 9y agoPlus smart contracts, in Ethereum's case. As a very rough analogy: Bitcoin is a massively replicated database with a single table having accountid and accountBalance, with a stored procedure that lets you transfer some of your own account's balance to any other user. Ethereum is a massively replicated database with that same table, but you also have developer rights. You can make your own tables and stored procedures, and other people can use them. (Some reasons that's just an analogy: they aren't actually SQL databases, Bitcoin uses UTXOs instead of accounts and has limited scripting, and Ethereum's "stored procedures" themselves have accountIds, with their own balances.)
- kochthesecond 9y agoThe post insinuates that the etherium scripting language is Turing complete. How can that be safe?
- geedy 9y agoYou will have to define "safe", but in general things like infinite loops are effectively bound by the amount of gas provided. Mistakes are still expensive, and it is easy to get the code wrong (the DAO hack and quadrigacx screw up this week are obvious examples), but the network itself is fairly stable, which is priority number one.
- pault 9y agoIs there an analysis/post-mortem on the QuadrigaCX snafu anywhere? I would be very interested in reading a detailed account of exactly what went wrong.
- DennisP 9y agoHere's their comment: https://www.reddit.com/r/ethereum/comments/6ettq5/statement_on_quadrigacx_ether_contract_error/ https://www.reddit.com/r/ethereum/comments/6ettq5/statement_... Also, it's normal practice for a contract to throw an exception if ETH is sent to any function that doesn't know how to deal with it. This includes the "fallback function," which is what runs if no other function in the contract is called. With recent versions of Solidity, this throw is built in, unless you mark a function "payable." But they were using an older contract, and there was no protection built into their fallback, and that's what made them vulnerable to this issue in the first place.
- DennisP 9y agoIndeed it is, aside from the fact that you pay a transaction fee for every step so at some point you run out of money. Some other things that run on Turing-complete code: passenger jets, medical equipment, self-driving cars, and nuclear reactors. I write and audit Ethereum scripts for a living. It takes a lot of care, but it's manageable because the scripts are typically under a thousand lines total, implementing simple business rules rather than complicated algorithms. It's feasible to make it very solid if you take your time, make the code as simple and clear as possible, write lots of unit tests, hire expert review, publish the code and maybe post a bounty. It's also good practice to build in something to handle emergencies, just in case. People are working on formal verification for Ethereum contracts, so down the road we should be able to actually prove their properties.
- fragsworth 9y agoIf it were that simple, we'd have had online currencies a long time ago.
- msutherl 9y agore: most other software: "Wow. It's just a relational database."