5 ms·
A few months ago as a newcomer to Ethereum, I looked into Solidity and concluded that due to the poor design of the language, large-scale problems like this wou
by pixelperfect 9y ago
A few months ago as a newcomer to Ethereum, I looked into Solidity and concluded that due to the poor design of the language, large-scale problems like this would be inevitable. I decided not to invest in ETH. In my opinion, smart contracts are a good idea, but smart contracts written in Solidity are a bad idea.
- DennisP 9y agoThe issue in this case isn't so much Solidity, as Parity getting too fancy with their code. If you look at the wallet stub contract it's half assembly. They did a good job optimizing the contract to use minimal gas upon deployment, but maybe that's not the best thing to optimize for contracts that will hold millions of dollars. They also don't appear to have gotten fresh external audits when they made changes. Incidentally, there are other Ethereum languages in development that are better suited for formal verification, including Viper and Bamboo.
- bitcoinmoney 9y agoIf I do a git clone of the parity github and deploy the multisig wallet, how much will it cost versus just using the stub/delegatecall architecture that's being used by everyone? We talking about >100$ here?
- DennisP 9y agoI haven't checked but these contracts aren't huge and gas prices are low if you don't mind waiting a couple minutes. I think you could post it for a couple bucks. (I also think you'd be better off using a different wallet entirely; Parity's isn't the most popular anyway, especially lately.)
- sjbase 9y agoWould you mind elaborating on which aspects of the language reflect poor design? And what was done well for that matter? I have no strong opinions on Solidity, btw - just generally interested in people's views on developer experience.
- slimshady94 9y agoThis comment after the previous hack is pretty detailed https://news.ycombinator.com/item?id=14691212 https://news.ycombinator.com/item?id=14691212
- DennisP 9y agoSome of those points are good, others are nonsense. In particular: 1) There's no need for a garbage collector, because there's very limited computation within each transaction, and complete cleanup of non-permanent storage after each one. 2) The author doesn't appear to realize that the list of mis-compilation bugs is a list of fixed bugs. The list is only available in json because its purpose is just to let tools display warnings for obsolete compilers. 3) I have a hard time dreaming up an application that would need a string library in Solidity, because storage on chain is very expensive, and you only need to compute things on chain that require global consensus. Strings on chain are usually very short and static; for longer stuff we just store their hashes on chain and use client code to manipulate the strings.
- root_axis 9y agoCan you offer some examples of smart contracts that are good ideas?
- tom_mellior 9y agoNot the OP, but you could replace Kickstarter with a smart contract. The smart contract would refund you if the project is not funded by the deadline. What the smart contract can't do is ensure that the funded project actually delivers on its promises. But neither can Kickstarter...
- root_axis 9y agoThat seems like it'd work, but I'm not sure what is gained by replacing Kickstarter with a smart contract (as opposed to replacing Kickstarter with a centralized alternative)
- tom_mellior 9y agoDo you mean a decentralized alternative? The advantage would be avoiding the 5% Kickstarter fee + (according to Wikipedia) 3% to 9% payment processor fees. The computation fees charged by the blockchain are presumably well below that. [On the other hand, maybe they aren't. Calling this suicide function on the Parity multi-sig wallet apparently cost 27 cents. If the crowdfunding contract is more complex, and submitting a payment costs, say, a dollar, then the average contribution would have to be on the order of 10 dollars to break even vs. Kickstarter.]
- fjsolwmv 9y agoYou can save the cost of Kickstarter by removing the value Kick-start adds. You get a smart contract that can't be executed because no one decides if the project delivered properly. How is that an improvement?
- tom_mellior 9y ago
- wskinner 9y agoMe too. That was back when Ether was at $2-3. Either the market is very irrational, or it just doesn't matter that much, and people are willing to take the risk of stuff like this happening again and again.
- draw_down 9y ago> I looked into Solidity and concluded that due to the poor design of the language, large-scale problems like this would be inevitable.... In my opinion, smart contracts are a good idea, but smart contracts written in Solidity are a bad idea. Yes, and it's sad that they continue to try to patch around and nibble at the problem. The foundation is borked, start over.