5 ms·
> Another decision he made when he had no idea of the bug shows how quirky and unforgiving code can be. “If the capital ‘T’ in line 666 had been a small ‘t,’ th
by kator 9y ago
> Another decision he made when he had no idea of the bug shows how quirky and unforgiving code can be. “If the capital ‘T’ in line 666 had been a small ‘t,’ that would also have prevented the hack,” he says.
Can someone familiar with this explain how something financially based can have a capitalization flaw? I would expect a smart contract language to have very strict type and variable linking. Humans make many mistakes in coding but most of the time it doesn't cost $55m. A transaction language should be very strict so either the smart contract language is flawed or the author of this article is overstating something for dramatic effect.
EDIT: Found this: https://github.com/slockit/DAO/blob/v1.0/DAO.sol#L666 https://github.com/slockit/DAO/blob/v1.0/DAO.sol#L666
on a deeper dive: http://hackingdistributed.com/2016/06/18/analysis-of-the-dao-exploit/ http://hackingdistributed.com/2016/06/18/analysis-of-the-dao...
- kefka 9y agoThat's primarily because Ethereum is pure amateur hour. When Bitcoin had built in checksums on addresses, Eth Dev's just said "watch where you send money". They ended up having to later add in a capitalization scheme to serve as a hash. I have no clue how they managed to fool so many people with poor and shoddy work. But they have so far. And they've fooled everyone that this is a 'hack' even after saying time and again "The code is the contract, and the contract is the code"... Unless lead devs lose money.
- pmorici 9y agoTheir greatest skill is marketing.
- NicolaiS 9y agoThe 't' vs 'T' has _nothing_ to do with checksums. `Transfer` and `transfer` are two different functions, one creating an "event" (think a signal on the blockchain) and the other actually transfering tokens. The true flaw lies in the reentrant attack on `.send()`
- Laaas 9y agojesus christ, who the fuck would make two identical symbols differentiated by only capitalisation? (Other than these guys obviously)
- lproven 9y agoWhat, you mean apart from every Unix ever? (All right, all right, excluding Mac OS X. But it's weird.)
- kbody 9y agoThere's a big difference between being and actually making use of such anti-patterns. Especially on such a scale.
- jchw 9y agoThat's filesystems, not the OS. There are some extremely good reasons to treat filenames as bags of bytes, which is why Apple got rid of case folding in APFS. Think performance, locale issues, etc. (And before someone says it, yes, of course performance matters for filenames. Every single stat shouldn't need to worry about case folding.)
- deleted 9y ago[deleted]
- 0x0 9y agoYou can have macOS use case sensitive filesystems (like case sensitive HFS+), and you can have linux use a case insensitive file system (like FAT32)
- pjc50 9y agoIt's surprising that most languages will happily let you do this. Lots of C programs have 'FOO' and 'foo'; not so many will have 'Foo' as well but it's probably more common than you think.
- runeks 9y ago> When Bitcoin had built in checksums on addresses [..] There are no address checksums in the Bitcoin blockchain; all contracts/scripts on the blockchain reference raw hashes. Only at the application level -- e.g. sending an address to a friend in an email -- does Bitcoin make use of checksums, since blockchain space is fairly precious/expensive.
- pjc50 9y agoActually, could someone post a link to the source so we can all see?