6 ms·
Not off topic in the slightest! In fact, all too topical, given the past few weeks. For what it's worth -- I'm a former engineer at Coinbase / Google and rece
by nahollander 9y ago
Not off topic in the slightest! In fact, all too topical, given the past few weeks.
For what it's worth -- I'm a former engineer at Coinbase / Google and recently graduated from Stanford. Though I didn't touch Solidity as part of my work at Coinbase, I've been following Ethereum extremely closely since its beginnings, and any mainnet release I'd push forward would certainly undergo rigorous third-party auditing at the smart contract level. I've also been iterating on this protocol for the better part of the past 9 months, so this is by no means a weekend project.
- sigstoat 9y agohave you attempted to apply any formal methods (coq, isabelle, tla, whatever) to your code? or will you be content with mere auditing?
- nahollander 9y agoNot as of yet, but I'd definitely be interested in exploring the possibility. If you know of any good resources or primers on those, please do send them my way.
- sigstoat 9y agoshrug, the reference books for all those things are the standard resources. i think they've shown up on hacker news a couple times each. if i were aware of any material on formalizing solidity or the EVM, honestly i'd keep it to myself and use it to identity vulnerabilities in your contracts. in that hypothetical world, my question was a means to check and see if you were a good target. good luck. :)
- buckie 9y agoThis project is simultaneously a great example of the democratizing effect of Ethereum while also being truly terrifying. A Stanford '17 grad with a few internships worth of industry experience is able to create and deploy a peer-to-peer loan infrastructure. This isn't meant to be demeaning in any way, I'm just remarking on how incredible of an accomplishment it is for both you and Ethereum that the previous sentence isn't fantasy. Now, I'm someone with ~10yrs experience in finance/production engineering/regulation. That doesn't mean I'm right, just that I've been in the trenches for far longer and seen this type of domain from a number of sides over the course of many years. I need to at least mention that, well, this project is probably a bomb and you should be really careful with it. I, at least, wouldn't want to be the next DAO dev (e.g. project takes off quickly, unseen exploit exists, I lose some 10's of millions of other people's money) at mostly a personal (I'd feel guilty) and career trajectory level. The Parity multi-sig bug occurred in a solidity shop that was founded by the father of the language itself. It got past a serious audit and had the best eng process known (for solidity) enforced. The odds that your code -- currently unaudited correct? -- doesn't have an exploit are, while impossible to accurately calculate, quite remote. Even an audit, as shown by Parity, is no guarantee. And while yes, we're all human so there is always the chance for a bug, your system could be the next ITO market and thus could gain a huge amount of attention (from both regular folks, regulators, and hackers). I'm not saying you shouldn't do it (I wouldn't but you do you) or that you must have more exp to do it. I'm just recommending to be careful. Have fun and good luck!
- nahollander 9y agoI think the problems you're alluding to are problems with the blockchain ecosystem in general, and I don't purport to have a silver bullet to solve the inherent issues with immutable software deployments, particularly in financial applications. But, after all, a dark horse 20 year old college dropout spearheaded the development of Ethereum, and the technology now secures nearly 20B worth of value. Maybe it's impossible to truly build processes for secure software deployment auditing in this space -- in which case, it's unlikely blockchain tech will succeed as a technology in general -- but I hold an optimistic view that, as formal verification techniques for smart contracts get fleshed out and easier to use, best practices will emerge and it will become easier to build secure contracts on blockchains. Hopefully, until that point in time, Dharma won't get caught on the wrong side of history. Forgive my youth and naïveté :)
- ThePhysicist 9y agoCool project, congrats! As you speak of the "20B worth of value" I have a question: I always ask myself what the total monetary value stored in ETH actually is, as the 20B $ is the market capitalization (as far as I understand), which in my opinion is NOT the value. Drawing on my Economics classes (from a long time ago), my thinking goes like this: Let's assume I create 100 million items of a new cryptocurrency. At first, my coins have no value whatsoever. Now, you offer to buy 1 cryptocoin for 200 $ from me. This would instantly give my currency a market capitalization of 200 $ * 100 MN = 20 BN $! But is my currency now worth 20 BN $? I would say no, as there is probably no way for me to sell the remaining 99.999.999 coins for the same price for which I sold the first coin. And even after distributing a large amount of coins (say 50 % of the total), I would probably not be able to sell my remaining coins for their market value, as my offer volume would rapidly drive down the price of the coins by creating an oversupply (depending on the transaction volume of the currency of course). Following this logic I always thought that speaking of 20 BN $ of value stored in ETH as misleading, as the real monetary value of the currency (as determined by how much value you could actually extract when liquidating it entirely) is probably much less than that. And given that most people invest in ETH purely for speculation, I would even wager that a single seller who puts a large number of ETH on the market (as compared to the average daily volume) could cause a massive price drop, since there is no "fundamental" value in ETH (contrary to an asset-backed currency or a company stock).