6 ms·
So far, we have a long way to go to build higher quality code. There's a few reasons: 1. Blockchain smart contracts are often unchangeable, so you can't fix bu
by nemild 8y ago
So far, we have a long way to go to build higher quality code. There's a few reasons:
1. Blockchain smart contracts are often unchangeable, so you can't fix bugs
2. The language is being built as people write code, with some bad design choices that encourage mistakes (slowly being fixed)
3. Libraries are still being developed
4. Tooling is still limited (even basic linting)
5. People are not taking the time to have a beta process.
6. People prematurely optimize gas, at the cost of readability
(For non-Ethereum devs, here's a short tutorial for how the language works: https://learnxinyminutes.com/docs/solidity/ https://learnxinyminutes.com/docs/solidity/ )
My own view is that you have to code expecting that things go wrong, and ensure that your logic survives inevitable mistakes ('resiliency').
There's a lot of great resources on security, for people interested in this space:
Ethereum Safety: https://github.com/ethereum/wiki/wiki/Safety https://github.com/ethereum/wiki/wiki/Safety
Decentralized Application Security Project: https://dasp.co/ https://dasp.co/
Consensys Smart Contract Best Practice Guide (I helped coauthor this back in 2016 after the DAO):
https://consensys.github.io/smart-contract-best-practices/ https://consensys.github.io/smart-contract-best-practices/
Hacking Distributed is a great blog for blockchain security:
http://hackingdistributed.com/ http://hackingdistributed.com/
Emin and Phil Daian are great to follow on Twitter:
https://twitter.com/phildaian https://twitter.com/phildaian
https://twitter.com/el33th4xor https://twitter.com/el33th4xor
Audit Checklist (written by my team): https://github.com/cryptofinlabs/audit-checklist https://github.com/cryptofinlabs/audit-checklist
(Disclosure: Our team does audits for a few projects: http://audit.cryptofin.io/index.html http://audit.cryptofin.io/index.html )
Feel free to add other resources to this thread. Imagine it'll be useful for everyone.
- vec 8y ago> Blockchain smart contracts are often unchangeable, so you can't fix bugs This is the fatal flaw with smart contracts as a concept. If they can be changed by the author then they don't provide the security guarantees that make the system worth using, but if they aren't changeable by the author then a huge fraction of smart contracts will ultimately end up doing something unintended because of any of the million reasons we don't normally expect first releases of alpha software to work perfectly in all circumstances. In a perfect world Etherium would work great, but we don't live in a perfect world. People make mistakes. Any system which expects human input but isn't designed to gracefully handle human error (including the humans who programmed the system) is probably not going to end well.
- darawk 8y agoChanged arbitrarily by the author and immutable are pretty clearly not the only two options. Ethereum lets you design whatever governance scheme you want. You can build a system in which people vote on upgrades, for instance. You can structure that scheme however you want. It's just plain lazy thinking to say "welp code imperfect, therefore we can never use it for important stuff".
- pavel_lishin 8y agoSure hope that system is bug-free.
- darawk 8y agoYep, it'll take time to converge on high assurance implementations of these schemes. But we will. It is possible to write bug free code, particularly for relatively well defined, small areas.
- this_user 8y agoThe whole idea behind smart contracts that code can be law is fatally flawed, because it is a bet on our ability to write bug-free code. We know from experience that this is virtually impossible, especially at large scale, even for the best people and organisations in the world. This means this ultimately require some form of human arbiter to decide in cases like that, but this ultimately defeats the entire purpose of smart contracts.
- hardlianotion 8y agoQuite. This is a live topic for me. Wiser heads pointed me toward https://medium.com/@jimmysong/the-truth-about-smart-contracts-ae825271811f https://medium.com/@jimmysong/the-truth-about-smart-contract... when I had my own blockchain moment. I think that immutability and lack of human judgement limit the usefulness of these things. And of course, not everything needs decentralised.
- vec 8y agoIt's worse than that because immutability and lack of human judgement is also the killer feature that smart contracts offer over good old fashioned paper contracts and binding arbitration agreements. Any attempt to make maintaining smart contracts manageable is almost by definition going to undercut one of the main rationales for wanting to use them in the first place.
- darawk 8y ago> The whole idea behind smart contracts that code can be law is fatally flawed, because it is a bet on our ability to write bug-free code. We know from experience that this is virtually impossible, especially at large scale, even for the best people and organisations in the world. You mean, except for the cases where we do exactly that? Like mars rovers, space shuttles, medical devices, IOT, etc...
- wglb 8y agoDo you see blockchain developers doing the diligence that any random part of the space program does as a reflex?