4 ms·
Hypothetical 1: Contract security is taken very, very seriously, and discussed in section 2.2 of the whitepaper. The short answer is that colonies will have a
by thiagodelgado 9y ago
Hypothetical 1:
Contract security is taken very, very seriously, and discussed in section 2.2 of the whitepaper. The short answer is that colonies will have a 'recovery mode' whereby whitelisted addresses have the ability to alter some state of the colony contract directly. This should, in principle, prevent the circumstances enabling such an exploit from ever happening. In that sense, the hypothetical is moot.
The situation you really are getting at is one in which the Common Colony is mature enough that the 'recovery mode' features have been disabled and the contract is in full community control (a reasonable assumption if the Common Colony is pulling down $10M a year as you suggested). In this case, it also seems reasonable that some of that $10M a year will be spent by the Common Colony on bug bounties and internal security, paid to experts who have the highest reputation scores. If somehow there was still some brilliant exploit by a hacker who was both skilled enough to outsmart many, many world-class developers all working together, malicious enough to forgo the generous bounty awarded for disclosing the exploit to the Common Colony security domain, and downright detestable enough to willingly crash an enormously successful DAO... well, the answer is simply ¯\_(ツ)_/¯
Hypothetical 2:
This is where the reputation system gets interesting. If you really wanted to try to gum up a colony's inner workings by 'objecting to everything' or somehow interfering with the normal day-to-day workflows, you yourself would need some reputation score to do that. With each objection, you would be required to stake your own tokens and reputation on the outcome of the dispute. If the other members of the colony don't approve of what you're doing (I don't see why they would if you're trying to push the colony into the ground), they will vote against you and you will lose tokens and reputation. So with each unsuccessful attempt to interfere with the colony you hate, your own ability to influence that colony will diminish substantially.
Section 9 in the whitepaper describes these mechanisms in detail.
- stefano 9y ago> well, the answer is simply ¯\_(ツ)_/¯ That's not a great answer to a very realistic case.
- mgkabar 9y agoI think the many sentences that come before the shrug emoji illustrate that the case is not very realistic. You're taking the final, sarcastic closing comment out of context.
- popcorncowboy 9y agoOn the contrary. This is a core project team member saying that in the event a dedicated agent IS sufficiently motivated and DOES manage to compromise a Colony, "well, the answer is simply ¯\_(ツ)_/¯" The many sentences that come before the shrug do nothing to address the very realistic scenario of a breach. The "sarcastic closing comment" was in fact the final truth of it.
- mgkabar 9y agoIt really seems like the most appropriate response to this is indeed ¯\_(ツ)_/¯ You're assuming quite a lot of this hypothetical hacker - the response above clearly addresses the hypothetical by stating "here are the relevant reasons why this hypothetical is impossible or at least unlikely, and here are the relevant sections in the whitepaper for more verbose information". >The many sentences that come before the shrug do nothing to address the very realistic scenario of a breach. If you're assuming blackhat success for any conceivable project/company/database regardless of security measures taken to prevent it, what would an appropriate response even look like? What kind of answer would satisfy you?
- stefano 9y ago> What kind of answer would satisfy you? In the real world, with an actual registered company/cooperative, you can call the police or sue people in court as a last resort. This is not possible in a distributed world, so a new kind of recourse needs to be invented, if that's even possible.
- pookeh 9y agoNot if they are large sophisticated state sponsored attacks. I think we have to forego the stereotype of lone wolf havker (or at least not treat as the only hacker stereotype) when considering having a large population put their valuables into a single pot.