9 ms·
The problem isn't that they wrote the blockchain in JavaScript, it's that the language they chose for user-written contracts and dapps (out of all the languages
by flunhat 9y ago
The problem isn't that they wrote the blockchain in JavaScript, it's that the language they chose for user-written contracts and dapps (out of all the languages in the world, mind you) was JavaScript. Meaning that in the future, if this project really takes off (suspend disbelief here), an entire generation of blockchain apps that transfer money back and forth will be built on JavaScript when they didn't have to be. If they chose C as the language for smart contracts/dapps/whatever I would be ragging on them just the same. They had options, and choose the one of the worst ones.
- qaq 9y agoPaypal, Walmart are doing just fine handling huge amounts of transactions in JS. Majority of security breaches are via targeted emails with attachments and have very little to do with language services are written in.
- qaq 9y agoNot sure what is making everyone upset Paypal is doing 1.7 billion transaction per quarter (100 billion + in volume). 80%+ of breaches at companies are via email as a vector.
- yorwba 9y agoAre Paypal and Walmart actually handling their transactions in JS or is that just the front end? In either case, when they transfer money, they hopefully use a sane database transaction mechanism. AFAIK, that would have prevented the DAO hack.
- qaq 9y agoweb layer is Node so yes they are actually handling transactions in JS up to a point.
- azag0 9y agoYes, but Paypal nor Walmart don’t handle irreversible transactions. Nor are they platforms on which apps and custom transactions can be implemented. So I don’t think this is a good analogy.
- sealthedeal 9y agoWhy does "irreversible transaction" or "custom transactions" matter at all when talking about writing something in javascript?
- purerandomness 9y agoNone of those companies handles actual monetary transactions in JavaScript. That would be insane.
- qaq 9y agoDefine handling transactions, they have Node services which are touching cardholder data and are subject to PCI DSS compliance. The web layer is Node.
- KirinDave 9y agoSo you prefer the state of affairs with a language with arguably less safety than C _and_ many more amateurish implementation errors? I wish Etherium had chosen Javascript. It'd have started from a better place.
- flunhat 9y agoI totally agree with you about Solidity. If you're interested in developing a better language for smart contracts, check out Viper (https://github.com/ethereum/viper https://github.com/ethereum/viper). Although development is kind of slow right now because Vitalik is the only one who merges pull requests.
- KirinDave 9y agoI'm not sure I trust that team at all. Quite frankly, I think Etherium is a shameless powergrab by a bunch of folks who's sole positive contribution to the medium is growing it. It's a tribute to the essentially unskilled & uninformed investors and inventors in many parts of the blockchain ecosystem that Eth has been allowed to grow at all. It's a great idea for the owners of Eth and a terrible idea for everyone, everyone, EVERYONE else (except maybe certain classes of miners). I've got 0 interest in contributing my time to a system that will only be used to extract wealth from other people's good ideas while simultaneously welding them to a release calendar that keeps them at the back of the pack of blockchain software. If I wanted to pitch in with that, zcash is way more competent anyways. You don't standardize to a platform at the beginning of a boom. You standardize to protocols. And that is, by the way, exactly what every competent programmer is doing; standardizing on the protocols laid out by bitcoin as they develop their own chains and experiment with new, cheaper ways to sustain a digital currency.
- chrisco255 9y agoMaybe it's one of the best ones because it is one of the most accessible programming languages on the planet.
- danmaz74 9y ago* Most accessible language in the planet -> any script kiddie can write dapps right away without even bothering to study what the risks are and what is happening under the hood * dapps manage real money in real time * end users aren't able to evaluate the quality of the dapps they entrust their money to * what could possibly go wrong?
- deleted 9y ago[deleted]
- johnhenry 9y agoI think you may have inverted the responsibility. > any script kiddie can write dapps right away without even bothering to study what the risks are and what is happening under the hood It's not the contract author's responsibility to guarantee that the contract works properly -- they aren't forcing anyone to use it. Any script kiddie SHOULD be able to write a dapp. Most people don't [understand that they don't] understand the complexities our our modern financial system, but we don't require that one has a PhD in order to spend a dollar. A low barrier to entry when dealing with financial transactions is desirable. > end users aren't able to evaluate the quality of the dapps they entrust their money to This is entirely not true. Because dapps are publicly audit-able, an end user can evaluate whether or not he/she wishes to participate in a contract based on his/her understanding of the code. Granted, it might take a lot of time to properly learn the language used to build a contract, but this would be true of any language. Even so, if a user does not understand a contract, he/she can choose not to use it.
- KMag 9y ago> A low barrier to entry when dealing with financial transactions is desirable. Writing a dapp is much closer to issuing an exotic cross-asset derivative than it is to spending a dollar.