Author

Topic: [ANN] Ethereum: Welcome to the Beginning - page 1270. (Read 2006044 times)

newbie
Activity: 46
Merit: 0
January 29, 2014, 08:56:06 PM
Has anyone addressed the security of having a Turing complete foundation? Turing complete means that Ethereum contracts will likely be absolutely loaded with common and proprietary viruses, keyloggers, malware, adware, and a slew of other bad things. I am willing to bet my bank account that in a few short months people will be crying about how they got all their wallets/currency stolen, or their computers are now running slow, or how they blue screen every few minutes after a reboot.

If you want an example of how Turing complete works, load up a peer to peer sharing program and download a bunch of .MOV files and run them. I GUARANTEE that you will get a virus. That's because Quicktime movie files are Turing complete. This is why mkv, mpeg, mpg and avi, while not impervious, are much much safer to download. If you want to invest, mine, and run contracts at the risk of losing everything then go ahead. We will never know for sure how secure Ether is going to be until post release, so asking for money without proof of security is another red flag.


I too would like to know this. Turing complete is dangerous and highly insecure.

You are calling every turing complete programming language out there dangerous and highly insecure. You do not seem to know what you are talking about.

No I am not, I am talking within the context of a currency backed by people's hard earned money. Do not put words in my mouth. Hackers are already willing to inject malicious software into non monetary applications, I can only imagine what they would come up with if they found an application that is Turing complete, is used to handle millions of dollars, and thanks to the anonymity of crypto, have no chance of being caught. You are diffusing a valid question with irrelevant and illogical retorts. I'd like a short summary of the methods used to prevent people from doing this. What systems are in place to increase security for the end user?

So far as I can tell the security is based on the blockchain and the POW that will be used in roughly the same way bitcoin does this. The big difference is that ethereum scripts are more powerful. I dont see a reason why this introduces new security considerations, but it is certainly a valid point to consider. And still I say this based on my understanding of the model of ethereum and not on the implementation.
hero member
Activity: 672
Merit: 500
January 29, 2014, 08:52:55 PM
Ethanolium,
a bunch of programmers got drunk of premining greed ;-)
newbie
Activity: 28
Merit: 0
January 29, 2014, 08:33:01 PM
Has anyone addressed the security of having a Turing complete foundation? Turing complete means that Ethereum contracts will likely be absolutely loaded with common and proprietary viruses, keyloggers, malware, adware, and a slew of other bad things. I am willing to bet my bank account that in a few short months people will be crying about how they got all their wallets/currency stolen, or their computers are now running slow, or how they blue screen every few minutes after a reboot.

If you want an example of how Turing complete works, load up a peer to peer sharing program and download a bunch of .MOV files and run them. I GUARANTEE that you will get a virus. That's because Quicktime movie files are Turing complete. This is why mkv, mpeg, mpg and avi, while not impervious, are much much safer to download. If you want to invest, mine, and run contracts at the risk of losing everything then go ahead. We will never know for sure how secure Ether is going to be until post release, so asking for money without proof of security is another red flag.


I too would like to know this. Turing complete is dangerous and highly insecure.

You are calling every turing complete programming language out there dangerous and highly insecure. You do not seem to know what you are talking about.

No I am not, I am talking within the context of a currency backed by people's hard earned money. Do not put words in my mouth. Hackers are already willing to inject malicious software into non monetary applications, I can only imagine what they would come up with if they found an application that is Turing complete, is used to handle millions of dollars, and thanks to the anonymity of crypto, have no chance of being caught. You are diffusing a valid question with irrelevant and illogical retorts. I'd like a short summary of the methods used to prevent people from doing this. What systems are in place to increase security for the end user?
full member
Activity: 221
Merit: 100
January 29, 2014, 08:29:03 PM
For those disillusioned or turned off by the IPO but who are still interested in getting involved, I would recommend mining and developing.  Mining a new coin at launch is always a fun experience, especially for folks who haven't done it before.  Also, once high-level abstractions have been made (ruby gem, python port, etc.) hacking around with some easy code would be a worthwhile evaluation.

I'll be curious to see how the IPO goes once it arrives.  Someone should start a betting pool on what the final amount BTC raised will be (or the size of the initial Ether pool).

The forums on their site are pretty sparse at the moment http://forum.ethereum.org/ but meetups have already started to be organized so I would expect this to change rapidly.
newbie
Activity: 46
Merit: 0
January 29, 2014, 08:26:11 PM
Has anyone addressed the security of having a Turing complete foundation? Turing complete means that Ethereum contracts will likely be absolutely loaded with common and proprietary viruses, keyloggers, malware, adware, and a slew of other bad things. I am willing to bet my bank account that in a few short months people will be crying about how they got all their wallets/currency stolen, or their computers are now running slow, or how they blue screen every few minutes after a reboot.

If you want an example of how Turing complete works, load up a peer to peer sharing program and download a bunch of .MOV files and run them. I GUARANTEE that you will get a virus. That's because Quicktime movie files are Turing complete. This is why mkv, mpeg, mpg and avi, while not impervious, are much much safer to download. If you want to invest, mine, and run contracts at the risk of losing everything then go ahead. We will never know for sure how secure Ether is going to be until post release, so asking for money without proof of security is another red flag.


I too would like to know this. Turing complete is dangerous and highly insecure.

You are calling every turing complete programming language out there dangerous and highly insecure. You do not seem to know what you are talking about.
newbie
Activity: 28
Merit: 0
January 29, 2014, 08:19:21 PM
Has anyone addressed the security of having a Turing complete foundation? Turing complete means that Ethereum contracts will likely be absolutely loaded with common and proprietary viruses, keyloggers, malware, adware, and a slew of other bad things. I am willing to bet my bank account that in a few short months people will be crying about how they got all their wallets/currency stolen, or their computers are now running slow, or how they blue screen every few minutes after a reboot.

If you want an example of how Turing complete works, load up a peer to peer sharing program and download a bunch of .MOV files and run them. I GUARANTEE that you will get a virus. That's because Quicktime movie files are Turing complete. This is why mkv, mpeg, mpg and avi, while not impervious, are much much safer to download. If you want to invest, mine, and run contracts at the risk of losing everything then go ahead. We will never know for sure how secure Ether is going to be until post release, so asking for money without proof of security is another red flag.


I too would like to know this. Turing complete is dangerous and highly insecure.
sr. member
Activity: 294
Merit: 250
January 29, 2014, 08:10:23 PM


The dilution potential is huge. Set the cap at 5000 BTC and implement a max investment cap to allow many small investors.

+1

+1

At the moment it makes no sense. The risk is way too high. Besides, there are many ways they can make money once they launch, such as with their own exchange or other software.

A 5000-10000 BTC limit with 50 BTC limit per person (at least for the first month) is more sensible. Assuming BTC doesn't collapse, that's $4-8m even at current prices. In six months there is a fair chance that will have doubled. Appreciate that 'a person' is imprecise but it's a start. This way everyone knows what they are getting. This also allows people to share the coin pre-mine which I think is better pr and better for the market post launch. If month 1 goes by and the limit is not reached, then remove the coin limit for month 2.

To flip it round, any investor has to assume a 30,000 BTC valuation, making it already a valuable coin. The upside is immediately limited to the coin being a major success. Anything else and the money is lost. Factor in the minting model and the clones that will appear immediately, which may be a better gamble for those so inclined, and the investment is too high risk.

Note: The 50% pre-mine is not for the coin creators. That's for the coin investors, i.e. Potentially us. The rest is split between year 1 miners (not enough I would say), creators, and funding for dev. Correct me if I am wrong.

I want to support this and like some of those involved, but the fund raising model is wrong. That doesn't mean they won't manage to raise it, but it's raising too many eyebrows amongst investors I work with and it's a poor start to a good concept.

Which is why they've delayed the IPO. They've obviously got the pulse of the community and decided to make adjustments.

When they'll be out with this project, others like Mastercoin or Next will be well underway and have first adopter advantage which can be huge advantage.

In this crypto world 1 month = 1 year. Too little, too late.
sr. member
Activity: 364
Merit: 250
January 29, 2014, 08:03:38 PM


The dilution potential is huge. Set the cap at 5000 BTC and implement a max investment cap to allow many small investors.

+1

+1

At the moment it makes no sense. The risk is way too high. Besides, there are many ways they can make money once they launch, such as with their own exchange or other software.

A 5000-10000 BTC limit with 50 BTC limit per person (at least for the first month) is more sensible. Assuming BTC doesn't collapse, that's $4-8m even at current prices. In six months there is a fair chance that will have doubled. Appreciate that 'a person' is imprecise but it's a start. This way everyone knows what they are getting. This also allows people to share the coin pre-mine which I think is better pr and better for the market post launch. If month 1 goes by and the limit is not reached, then remove the coin limit for month 2.

To flip it round, any investor has to assume a 30,000 BTC valuation, making it already a valuable coin. The upside is immediately limited to the coin being a major success. Anything else and the money is lost. Factor in the minting model and the clones that will appear immediately, which may be a better gamble for those so inclined, and the investment is too high risk.

Note: The 50% pre-mine is not for the coin creators. That's for the coin investors, i.e. Potentially us. The rest is split between year 1 miners (not enough I would say), creators, and funding for dev. Correct me if I am wrong.

I want to support this and like some of those involved, but the fund raising model is wrong. That doesn't mean they won't manage to raise it, but it's raising too many eyebrows amongst investors I work with and it's a poor start to a good concept.
hero member
Activity: 644
Merit: 500
January 29, 2014, 07:46:12 PM
I can compare only Nxt and Ethereum:

1. Nxt is simple (for casual programmers), Ethereum is hardcore (for hardcore programmers). I think most of coders will choose Nxt if noone creates a simple Ethereum Contract Creation Kit.
2. Nxt can process 1000s transactions per second (coz of absence of scripts and Transparent Forging), Ethereum can't process too many transactions but they r much richer. I think these platforms would go on par if Nxt didn't have Transparent Forging. With TF Nxt will win.
3. Nxt has fixed supply of coins, Ethereum will be inflationary for a long period of time. Ordinary people prefer non-inflationary currencies.
4. Nxt is 100% PoS, Ethereum is PoW + PoS, so the latter is not so "green".

These r just a few points that came to my mind.

Please stop trying to talk up Nxt at every opportunity in this thread. You forgot to mention Nxt is vulnerable to nothing-at-stake attacks, poorly implemented in Java (known for security!), you can't store anything in an offline wallet, and the currency is owned by 71 people who sell it to everyone else. Just get real if you want to talk things up.


There is nothing wrong with Java as programing language. Don't confuse programing language with Java Applet that is a web browser plugin

It's much easier to write secure software in Java than C and C++
newbie
Activity: 9
Merit: 0
legendary
Activity: 1176
Merit: 1134
January 29, 2014, 07:37:28 PM
alot of posts being deleted on this thread this post wont last long....eutherium!!!
You are not kidding!
Used to be 80 pages, now 45
That is why they didnt bother to respond
legendary
Activity: 1176
Merit: 1134
January 29, 2014, 07:36:26 PM
I have heard that etherium might already have received investments. If this is true, What sort of preferential terms did they get? If it is not true, can you please confirm that there are no preexisting investors

The tech vision seems to be quite ambitious, does testnet release support all of what will be in the final release? If not, when will everything be completed? Is source code available?

Inflation concerns abound, ignoring preferential tems for early investors, wouldnt someone have to continue buying 40 percent more per year to maintain their stake?

Many more questions, but if the final product is many months away, or if preexisting investors get lions share of gains or if dilution cannot be avoided, then i am leery of ipo

James
hero member
Activity: 714
Merit: 502
January 29, 2014, 07:34:41 PM
alot of posts being deleted on this thread this post wont last long....eutherium!!!
legendary
Activity: 1134
Merit: 1008
CEO of IOHK
January 29, 2014, 06:50:39 PM
Quote
Has anyone addressed the security of having a Turing complete foundation? Turing complete means that Ethereum contracts will likely be absolutely loaded with common and proprietary viruses, keyloggers, malware, adware, and a slew of other bad things. I am willing to bet my bank account that in a few short months people will be crying about how they got all their wallets/currency stolen, or their computers are now running slow, or how they blue screen every few minutes after a reboot.

If you want an example of how Turing complete works, load up a peer to peer sharing program and download a bunch of .MOV files and run them. I GUARANTEE that you will get a virus. That's because Quicktime movie files are Turing complete. This is why mkv, mpeg, mpg and avi, while not impervious, are much much safer to download. If you want to invest, mine, and run contracts at the risk of losing everything then go ahead. We will never know for sure how secure Ether is going to be until post release, so asking for money without proof of security is another red flag.

Also please be aware that LeoC sent this message to me via a PM:

Quote
10 BTC and I'll remove my posts even though they are factual and won't make any more. 15 and I will change my tune and promote.

eMunie have already lost hundreds of BTC and were forced to cancel their IPO when I called them out here https://bitcointalksearch.org/topic/scam-alert-emunie-caution-advised-411366

I was going to create a similar thread regarding Ethereum, unless you send the above amounts.

I'd suggest you think long and hard about this. Which would you prefer to lose, 10 BTC or 1000, your choice.

1C7MPUTTWQjinfbRcQtW6HAc4ips7wMuiJ

Please ignore the FUD. We are going to make every attempt to address all concerns. In many cases, with Vitalik and Me directly.
legendary
Activity: 2674
Merit: 2965
Terminated.
January 29, 2014, 06:33:12 PM
I'll keep watching this with a chunk of doubt.
All those names sound too random.
Why not give an inside look to a senior or VIP from here?  Roll Eyes
newbie
Activity: 46
Merit: 0
January 29, 2014, 06:18:54 PM
Has anyone addressed the security of having a Turing complete foundation? Turing complete means that Ethereum contracts will likely be absolutely loaded with common and proprietary viruses, keyloggers, malware, adware, and a slew of other bad things. I am willing to bet my bank account that in a few short months people will be crying about how they got all their wallets/currency stolen, or their computers are now running slow, or how they blue screen every few minutes after a reboot.

It's horse shit to believe keyloggers or viruses will be loaded onto ethereum. The running of a contract does not affect the local system except for the ethereum node.
full member
Activity: 154
Merit: 100
January 29, 2014, 05:57:00 PM
Has anyone addressed the security of having a Turing complete foundation? Turing complete means that Ethereum contracts will likely be absolutely loaded with common and proprietary viruses, keyloggers, malware, adware, and a slew of other bad things. I am willing to bet my bank account that in a few short months people will be crying about how they got all their wallets/currency stolen, or their computers are now running slow, or how they blue screen every few minutes after a reboot.

If you want an example of how Turing complete works, load up a peer to peer sharing program and download a bunch of .MOV files and run them. I GUARANTEE that you will get a virus. That's because Quicktime movie files are Turing complete. This is why mkv, mpeg, mpg and avi, while not impervious, are much much safer to download. If you want to invest, mine, and run contracts at the risk of losing everything then go ahead. We will never know for sure how secure Ether is going to be until post release, so asking for money without proof of security is another red flag.
kvb
newbie
Activity: 21
Merit: 0
January 29, 2014, 05:49:14 PM
For the non-techie among us, would I be able to install alpha release of the testnet client on my Win 8? Some guidance would be helpful.  What does all this mean? "two official clients released at the same time, with one written in C++ and the other in Go; a Python client is also in the works. A compiler from the Ethereum CLL to Ethereum script will be released very soon."

see if this helps..
http://dr-pra.tumblr.com/post/73526554416/build-and-run-the-ethereum-go-client-on-windows
newbie
Activity: 17
Merit: 0
January 29, 2014, 05:37:01 PM
For the non-techie among us, would I be able to install alpha release of the testnet client on my Win 8? Some guidance would be helpful.  What does all this mean? "two official clients released at the same time, with one written in C++ and the other in Go; a Python client is also in the works. A compiler from the Ethereum CLL to Ethereum script will be released very soon."
full member
Activity: 221
Merit: 100
January 29, 2014, 05:10:23 PM
Does anyone know if there are official plans for things like a ruby gem or a python library?  Allowing contracts to easily integrate with existing web applications seems like the best way to encourage adoption.  The more developers who can understand/test/validate contract code the better.
Jump to: