3 ms·
>If they used a library instead of a contract, this wouldn't have been possible. It's actually the opposite, using a library allowed this to break all the wall
by TD-Linux 9y ago
>If they used a library instead of a contract, this wouldn't have been possible.
It's actually the opposite, using a library allowed this to break all the wallets using it. However, an Ethereum "library" isn't what you'd expect a software "library" to be - it's an executable contract that just is never supposed to be executed directly. But oops, nothing prevented that from happening.
The concept of everyone using a common, well-audited contract makes sense though. Virtually all Bitcoin multisignature transactions use the same script construction and it has never been hacked, despite being much older.
- sciyoshi 9y agoFor something as important as contract code, there should still have been more failsafes. Even just having a kill() on the main contract that doesn't delegate out to the library would have protected against this.
- deleted 9y ago[deleted]
- bhaak 9y ago> The concept of everyone using a common, well-audited contract makes sense though. Just Parity's contract was neither common nor well audited. > Virtually all Bitcoin multisignature transactions use the same script construction and it has never been hacked, despite being much older. The only multi-sig issue that I'm aware of in Bitcoin was the Bitfinex hack but I don't know in what relation BitGo's multi-sig implementation is to the standard multi-sig. The EF multi-sig implementation has been audited and AFAIK there has also never been an issue with it.
- TD-Linux 9y agoThe Bitfinex hack was due to getting enough parties of the multiparty signature to sign it (e.g. by stealing 2 out of 3 keys, or taking advantage of insufficiently secure automatic signing systems), not an issue with the contract itself.