7 msΒ·
The flip side of that is any smart contract that stood the test of time should be rock solid. For example, there are huge incentives to go ahead and hack a big
by rawtxapp 5y ago
The flip side of that is any smart contract that stood the test of time should be rock solid. For example, there are huge incentives to go ahead and hack a big contract like maker, compound, uniswap or aave, so you can bet that there's highly qualified people out there trying to hack them as we speak, yet after all this time, they are still working as intended.
I have a lot more trust in that kind of product than in a product where contracts are subject to interpretations by humans which may or may not be reliable. It's one of the reasons why people incorporate their companies in Delaware, there are well known case law, so you know in advance what to expect from the justice system. Predictability is an important part of a contract, I trust a well inspected and battle tested smart contract much more than a human enforced contract. That said, not everything is suited to smart contracts, but many financial applications are.
- lisper 5y agoThat's no guarantee. Someone might have a zero-day stashed away somewhere.
- rawtxapp 5y agoThe game theory comes into play, if you found a bug that could empty maker's vaults for example, you better do it right now, otherwise, someone else will before you and you wasted all your time/energy.
- theli0nheart 5y agoExactly. This is precisely why there aren't (or at least, in a rational world, should not be) any undisclosed zero-days in crypto. If you're aware of an exploit, you're just going to exploit it immediately unless you're willing to let someone else exploit it in your place. There is a large amount of money at stake with these exploits and it doesn't make economic sense to let one sit around.
- Retric 5y agoHow many major bugs in software and especially cryptosystems went undisclosed for decades? The core issue is the inherent asymmetry where 1 person finding 1 bug can destabilize giant systems. Even if these systems where hundreds of years old that doesnβt actually mean much.
- zionic 5y agoBy this logic most e-commerce is a mistake as well, since a serious flaw in the linux kernel could take down most web servers.
- arcticbull 5y agoNah, that's governed by contracts, law and enforced by the police. That money tends to be traceable and recoverable.
- Retric 5y agoCredit card transactions are reversible, that means such flaws can be considered a cost of doing business rather than permanently destroying anything.
- threeseed 5y agoWith ecommerce the worst you can do as a seller is take out as much money as the credit limit on the card. Which for most people is in the low thousands. With smart contracts the liability upside is orders of magnitude higher.
- rawtxapp 5y agoHow many bugs had a direct financial return in the same way? If you found a bug in maker (or any of the other big contracts) today, you can walk away with billions of dollars worth of coins, that's a huge sum.
- Retric 5y agoMajor bugs in smart contracts can cause the system to stop working rather than handing anyone billions. As such people can discover such issues without disclosing them in much the way infrastructure can be vulnerable without people damaging it.
- solomonb 5y agoThis sounds like a fallacy of the inverse. Those contracts not being hacked yet is no proof that they are resistant to hacks.
- theli0nheart 5y agoIt's not clear what fallacy you're thinking about because the fallacy of the inverse is not it. From https://en.wikipedia.org/wiki/Confusion_of_the_inverse https://en.wikipedia.org/wiki/Confusion_of_the_inverse: > Confusion of the inverse, also called the conditional probability fallacy or the inverse fallacy, is a logical fallacy whereupon a conditional probability is equated with its inverse; that is, given two events A and B, the probability of A happening given that B has happened is assumed to be about the same as the probability of B given A, when there is actually no evidence for this assumption.[1][2] More formally, P(A|B) is assumed to be approximately equal to P(B|A).
- Closi 5y agoThe inverse of "any contract that has been hacked was insecure" is "any contract that hasn't been hacked must be secure". I think this is what OP meant. If something has been around for a long time it does probably mean it's less likely there is a really obvious security flaw, but it doesn't necessarily mean it is 'rock-solid' as plenty of things that have been seen to be 'rock-solid' in the past have turned out to be insecure.
- solomonb 5y agoyes this is what I was implying. I am curious how else the previous commenter would interpret my statement.
- theli0nheart 5y agoLet's formalize this to make it easier to discuss. π(π) = π(contract has been hacked) π(Β¬π) = π(contract has not been hacked) π(π) = π(contract is hack resistant) Relevant conditional probabilities: π(π|Β¬π) = π(contract is hack-resistant given that it has not been hacked) π(Β¬π|π) = π(contract has not been hacked given that it is hack-resistant) The fallacy of the inverse would be assuming that: > The probability that a contract is hack-resistant, given that it has not been hacked, is approximately equal to the probability that it has not been hacked, given that it's hack resistant. More succinctly: π(π|Β¬π) β π(Β¬π|π) In https://news.ycombinator.com/item?id=27666484 https://news.ycombinator.com/item?id=27666484, the fallacy of the inverse was presented as "those contracts not being hacked yet is no proof that they are resistant to hacks" or "NOT (NOT A implies B)", i.e.: Β¬(Β¬π β π) In summary: π(π|Β¬π) β π(Β¬π|π) => the fallacy of the inverse and Β¬(Β¬π β π) => statement in comment These two statements are fundamentally different. Note that the first statement is a comparison of probabilities, and the second is not. They're not the same. There might be another fallacy at play here, but it's not the fallacy of the inverse.
- uncomputation 5y agoConsidering there are still new bugs found in chip designs, operating systems, and compilers that have been around 4 times as long as any cryptocurrency I have literally no idea why you would feel safe in βsmart contracts.β At least if my bank account is hacked, I have a solid legal standing for compensation and I have good reason to believe centralized financial institutions will keep extensive documentation and logs. With decentralized finance, all I have is some Medium dot com post on the βForward Planβ and an ominous message that βSAFEDOLLAR IS UNDER ATTACK.β
- rawtxapp 5y agoThe bugs found in smart contracts equal large sums of money right away unlike 0-days in OSes or other systems where the link is much more indirect. For example, if you find a 0-day on Windows, sure you might sell it for 7-8 figures on the black market, if you found a bug on maker (or any of the big contracts), you could walk away with billions of dollars in a practically untraceable way.
- doesnotexist 5y agohttps://en.wikipedia.org/wiki/Market_for_zero-day_exploits#Marketplace https://en.wikipedia.org/wiki/Market_for_zero-day_exploits#M... The wikipedia entry on this is a bit misleading or misinformed. As there are multiple above ground buyers for 0-days that have no interest in making it difficult for people to sell to them.
- reidjs 5y agoThere's still a middle-man to deal with in that process. In this case, you extract a decent amount of 'money' directly. Would you rather win $100 and have to make a phone call to claim it, or find a $100 bill on the street?
- hanniabu 5y ago> Considering there are still new bugs found in chip designs, operating systems, and compilers that have been around 4 times as long Not quite the same. Those codebases are much larger, often include legacy spaghetti code, or are closed source. This makes it more difficult to find exploits, not to mention there's not as clear of path of financial incentive.
- snewman 5y agoI'm not sure this follows. It's a fair point that any easy-to-find bugs in large, time-tested contracts will have been found. Any medium- or hard-to-find bugs also will probably have been found. But there might still be a very-hard-to-find bug lurking; and given the value of finding such a bug, people might look hard enough to find it. In other words, the same scale that ensures there is no low-hanging fruit, also provides the incentive to pick high-hanging fruit. > I have a lot more trust in that kind of product than in a product where contracts are subject to interpretations by humans which may or may not be reliable. This is a valid concern, but it's also extremely well-understood at this point; we have centuries of global-scale experience with traditional financial and legal systems. They're certainly not flawless, but it's rare for gigantic new flaws to emerge. An important point is the existence of mechanisms for rolling back bad transactions and challenging / appealing flawed decisions.
- jwblackwell 5y ago> it's rare for gigantic new flaws to emerge There are countless instances of rouge traders, high level financial crime and corruption. Wirecard is one recent example costing billions. The Libor scandal another that comes to mind.
- NicoJuicy 5y agoWho were the victims with wirecard? They faked the numbers, but they didn't manage people's money.
- rawtxapp 5y agoI can't tell if you're sarcastic or not. In case you're serious, you don't see how a company with a market cap of 28B$ going belly up causes damage to investors, the markets, their partners, clients and employees?
- NicoJuicy 5y agoThe stock going belly up is the consequence of the fraud, but not the actual fraud. Just like the other people you've mentioned. Eg. Their clients switched payment processor. When a btc exchange frauds or a coin hacked or a smart contract is bugged, they get away with all your money. Which is the actual fraud. In some cases they post a postmortem on medium and call it a day. I don't think wirecard's fraud is comparable with all the crap in crypto town.
- donio 5y ago> The flip side of that is any smart contract that stood the test of time should be rock solid. They all are until they aren't.
- EGreg 5y agoI would trust things with formal proofs a lot more