6 ms·
This project is simultaneously a great example of the democratizing effect of Ethereum while also being truly terrifying. A Stanford '17 grad with a few interns
by buckie 9y ago
This project is simultaneously a great example of the democratizing effect of Ethereum while also being truly terrifying. A Stanford '17 grad with a few internships worth of industry experience is able to create and deploy a peer-to-peer loan infrastructure. This isn't meant to be demeaning in any way, I'm just remarking on how incredible of an accomplishment it is for both you and Ethereum that the previous sentence isn't fantasy.
Now, I'm someone with ~10yrs experience in finance/production engineering/regulation. That doesn't mean I'm right, just that I've been in the trenches for far longer and seen this type of domain from a number of sides over the course of many years. I need to at least mention that, well, this project is probably a bomb and you should be really careful with it. I, at least, wouldn't want to be the next DAO dev (e.g. project takes off quickly, unseen exploit exists, I lose some 10's of millions of other people's money) at mostly a personal (I'd feel guilty) and career trajectory level.
The Parity multi-sig bug occurred in a solidity shop that was founded by the father of the language itself. It got past a serious audit and had the best eng process known (for solidity) enforced. The odds that your code -- currently unaudited correct? -- doesn't have an exploit are, while impossible to accurately calculate, quite remote. Even an audit, as shown by Parity, is no guarantee. And while yes, we're all human so there is always the chance for a bug, your system could be the next ITO market and thus could gain a huge amount of attention (from both regular folks, regulators, and hackers).
I'm not saying you shouldn't do it (I wouldn't but you do you) or that you must have more exp to do it. I'm just recommending to be careful. Have fun and good luck!
- nahollander 9y agoI think the problems you're alluding to are problems with the blockchain ecosystem in general, and I don't purport to have a silver bullet to solve the inherent issues with immutable software deployments, particularly in financial applications. But, after all, a dark horse 20 year old college dropout spearheaded the development of Ethereum, and the technology now secures nearly 20B worth of value. Maybe it's impossible to truly build processes for secure software deployment auditing in this space -- in which case, it's unlikely blockchain tech will succeed as a technology in general -- but I hold an optimistic view that, as formal verification techniques for smart contracts get fleshed out and easier to use, best practices will emerge and it will become easier to build secure contracts on blockchains. Hopefully, until that point in time, Dharma won't get caught on the wrong side of history. Forgive my youth and naïveté :)
- ThePhysicist 9y agoCool project, congrats! As you speak of the "20B worth of value" I have a question: I always ask myself what the total monetary value stored in ETH actually is, as the 20B $ is the market capitalization (as far as I understand), which in my opinion is NOT the value. Drawing on my Economics classes (from a long time ago), my thinking goes like this: Let's assume I create 100 million items of a new cryptocurrency. At first, my coins have no value whatsoever. Now, you offer to buy 1 cryptocoin for 200 $ from me. This would instantly give my currency a market capitalization of 200 $ * 100 MN = 20 BN $! But is my currency now worth 20 BN $? I would say no, as there is probably no way for me to sell the remaining 99.999.999 coins for the same price for which I sold the first coin. And even after distributing a large amount of coins (say 50 % of the total), I would probably not be able to sell my remaining coins for their market value, as my offer volume would rapidly drive down the price of the coins by creating an oversupply (depending on the transaction volume of the currency of course). Following this logic I always thought that speaking of 20 BN $ of value stored in ETH as misleading, as the real monetary value of the currency (as determined by how much value you could actually extract when liquidating it entirely) is probably much less than that. And given that most people invest in ETH purely for speculation, I would even wager that a single seller who puts a large number of ETH on the market (as compared to the average daily volume) could cause a massive price drop, since there is no "fundamental" value in ETH (contrary to an asset-backed currency or a company stock).
- ruok0101 9y agoHow is this different than securities sold on public stock markets? If you hold a large position in a nasdaq 100 stock and drop a large sell order on the ECN's, you are surely going to see a similar (albeit not as dramatic) phenomenon. Does that mean the market cap of stocks shouldn't be used to assess value?
- ThePhysicist 9y agoThe public stock market is highly regulated, which makes price manipulation and insider trading more difficult as it is illegal and suspicious trades will be investigated. The ETH market is completely unregulated, hence the risk of manipulation is much higher. Also, NASDAQ stocks represent the underlying value (as well as future revenue expectations) of a real-world company, hence short-selling your stock to manipulate the price (usually) doesn't make much sense if the fundamentals of the underlying company are good, as investors that are optimistic about the future of the company will happily buy the stock that you sell. Of course there are situations where large funds speculate against companies or even governments, but this is (usually) only possible if there is a fundamental issue in the underlying asset such as a nation in a deep recession or debt crisis. For ETH there is currently no underlying asset that would have a value in the real world and which could serve as an "anchor of trust" for an investor. It should therefore be much easier to manipulate and speculate against ETH as there is little external information beyond the exchange rate that other investors have as a basis for their valuation. Also, as of now there is no large economic process that depends on the existence and functioning of ETH, hence there would be very little external pressure to keep the currency alive if people started speculating against it. For most cryptocurrencies, the initial developers / creators are similar to the founders of a publicly traded company in the sense that they possess a large fraction of the shares of the company / number of coins. What's different is that there is little for the "crypto-shareholders" to hold on to their coins in case of a sharp price drop, as there is no underlying asset that their coins represent. Economically, they are highly incentivized to "cash out" as soon as they think that the price has reached its maximum value (and this is what I expect will happen with many crypto-currencies as soon as the market cools down). With shares this is different as ownership of the share allows you to continuously extract value from the underlying company in the form of dividends, hence the incentive for selling your shares is much smaller even if you think that the share price has reached its maximum. I would therefore be very cautious about long-term investments in ETH, as there is no safety net and no guarantor behind the value. And while this is great for gambling, it does not provide a viable platform to build real world applications on top of (in my opinion).
- bjl 9y ago> I'm not saying you shouldn't do it (I wouldn't but you do you) or that you must have more exp to do it. I'm just recommending to be careful. Have fun and good luck! OP should also definitely consult a lawyer before making this public. Eth advocates love to parrot the 'code is the contract' slogan, but the actual law could very well disagree.
- Jabanga 9y ago>I need to at least mention that, well, this project is probably a bomb and you should be really careful with it. I, at least, wouldn't want to be the next DAO dev (e.g. project takes off quickly, unseen exploit exists, I lose some 10's of millions of other people's money) at mostly a personal (I'd feel guilty) and career trajectory level. >The Parity multi-sig bug occurred in a solidity shop that was founded by the father of the language itself. It got past a serious audit and had the best eng process known (for solidity) enforced. The odds that your code -- currently unaudited correct? -- doesn't have an exploit are, while impossible to accurately calculate, quite remote. I think this is very inaccurate. There have been devastating bugs in Ethereum, namely the bug in the DAO and the one in the Parity multisig contract. But there are numerous smart contracts that have not been found to be vulnerable. You cannot extrapolate what happened to two contracts to the entire ecosystem. It's inaccurate to claim that the probability that the loan contract he's working on will not have critical bugs once it's live is "remote", and a red herring to point out that it is unlikely to be bug free now, when it is still in development.
- buckie 9y agoI had a long discussion about this topic here: https://news.ycombinator.com/item?id=14807779 https://news.ycombinator.com/item?id=14807779 > I think this is very inaccurate. Perhaps, though keep in mind I did say that it is "[the odds that this code has a serious bug are] impossible to calculate accurately" and there's a reason for that. I'd argue that it wasn't an imprecise statement. Gavin was the father of solidity, put in the process at Parity, had an audit team, and the $200M multi-sig bug still got through. If the top-tier team and process failed, it's not imprecise to say that a more complex code base that didn't follow the best approach available likely has a bug. This is invariant on the phase of development. Moreover, I was cautioning OP to be careful. One valid response to that is what he's already going to do (get an audit). This makes a bug less likely. The next phase would be a Bankor-style pilot+bounty. After that... well we just don't know. > But there are numerous smart contracts that have not been found to be vulnerable. Sorry, but unexploited is not unexploitable. Many/most of these contracts are probably unexploitable, but the problem is that we can't be sure. To me, smart contract construction on the EVM/Solidity is closer to a "rolling your own crypto" grade problem, which is something that after years of massive exploits we've all agreed that you do not ever do it, vs building a webapp. Long term as tooling + approaches + standards + the language itself mature, it'll come closer to "backend programming at a hedge fund/bank" where it's doable but you need to be responsible.