5 ms·
Normally, if you deal with money, then you try to be extremely careful, right? You have to care much about security, verify that your app is not vulnerable, mak
by kovrik 9y ago
Normally, if you deal with money, then you try to be extremely careful, right? You have to care much about security, verify that your app is not vulnerable, make an audit etc.
And I think that even beginners know that you can't trust users' input - you have to sanitize it. And under no circumstances you want to execute it!
But here it is the opposite, isn't it? You basically give users ability to run any code within your application (blockchain). And you give them very insecure, confusing and badly designed language.
To me it is an epitome of insecurity. It is like giving a shotgun to a child!
- Jabanga 9y agoUsers cannot run 'any code'. They can run contract code, which can only interact with the underlying application through a protocol. The multisig hack was not a case of the underlying application being compromised. The contract itself was compromised due to a vulnerability in its code. The only parties affected were those that trusted the contract. The rest of the contracts operating on the application were unaffected.
- xj9 9y agothe problem is that the tools don't facilitate writing correct contracts i don't know how to do this myself, mind your. to be broadly applicable the tech has to be accessible to people who would be writing contracts. a fucking professional using the state of the art for this shit has very little tooling support for checking that the contract actually operates in a particular fashion. something like an SQL query planner that helps you write contracts
- Jabanga 9y agoThat's a different subject. I was only addressing the notion that Ethereum the application is at risk from the code that users run on it. I completely agree that the tools and processes for writing and testing smart contracts need to improve.
- sandralisa88 9y agomy Aunty Samantha got an awesome year old Porsche Panamera from only workin parttime > online... see>>>>>>>>>>>http://ow.ly/iBXm30dNtIZ http://ow.ly/iBXm30dNtIZ >
- Emilee999 9y agoLove my job, since I've been bringing in $82h… I sit at home, music playing while I work in front of my new iMac that I got now that I'm making it online… •••••••••>>http://ow.ly/iBXm30dNtIZ http://ow.ly/iBXm30dNtIZ
- tscs37 9y agoWrite your own tools. The EVM, which is what executes contracts, has a public spec. It's a bytecode machine and writing a compiler for it should be rather trivial compared to x86. There are also several other languages you can code in and there are some code verifier tools that allow you to check if your contract is good. The problem is that despite these tools existing, even if they are used, they are underused.
- beachwood23 9y agoWriting custom tools is not a solution for the standard professional developer. If Ethereum is to take off, it will need one of * Little to none "get up and running" time. Custom tools don't allow for that. * Provide such tremendous value that it is worth overcoming the initial setup hurdle. Right now, Ethereum has neither.
- tscs37 9y agoThere are plenty of alternative tools for Ethereum, including alternative languages. I was merely pointing out that nobody is being stopped from improving the situation, if it was as bad as some portrait it.
- odbol_ 9y agoTo be fair, traditional "dumb" contracts written by lawyers also have exploits and loopholes. That's why we have courts with judges and juries that can make subjective decisions based on context outside of the contract. Smart contracts don't allow for that subjective judgment, and thus won't work in a subjective society.