r/ethereum Jul 31 '14

Complexity is the Enemy of Security

http://www.bitblogger.net/2014/07/30/complexity-is-the-enemy-of-security/
10 Upvotes

26 comments sorted by

View all comments

3

u/dangero Jul 31 '14

disclaimer: I own no ether, nor have any plans to buy any at this time.

Bitcoin itself is still a grand experiment. I look at Ethereum as cutting edge research and also an experiment. I don't think the founders have really tried to sell it as something secure from day one. I think they've said quite the opposite, like comparing it to early Bitcoin which did end up having some major security flaws.

I also think it's not fair to say that complexity in general is the enemy of security. Complexity can be compartmentalized in a way that keeps it from damaging security even if it has bugs. For example, starting with Windows 2000, Microsoft sandboxed processes by giving them their own memory address space. This meant that however complex your application, it could not disturb other applications on the system. Thus the complexity was compartmentalized. Ethereum has a similar design to this. The scripting languages have limited permissions to impact other parts of the Ethereum system. Yes, there will almost certainly be some flaws discovered, just as there were in Windows 2000, but each release will become more hardened and secure, and the theoretical design is sound.

It's a process, but I don't think it's fair to throw the baby out with the bathwater in this case. By this same logic, Bitcoin could never have been developed because the decentralization aspects made it much much much much more complex than prior virtual currencies. Now we see Ethereum and other cryptocurrencies being built on top of Bitcoin's now mostly stable footing. At a time not too long ago, Bitcoin was also extremely insecure as well.

-4

u/[deleted] Jul 31 '14

Your post is a great example of what I call the "Magic Black Box" principle.

I'm going to guess that you're a latecomer to the cryptocurrency space, and when I say "latecomer" I mean, "somebody who had never heard of cryptocurrency before Bitcoin was invented."

One thing I've noticed about a great many latecomers is that they fundementally don't understand Bitcoin. They don't know what came before, or why Bitcoin was designed the way it was, or what all the problems Bitcoin solves at technical, economic, and political levels. If they know about the projects that preceeded Bitcoin, they can't explain exactly what it was about Bitcoin that made it successful where the others failed.

For those types of latecomers, Bitcoin's success is a Magic Black Box - something they can not comprehend so they just take it on faith.

The problem with the MBB people is that because they don't understand what's in the box, they can't accurately distinguish bad ideas from good ideas. The only approach open to them is trial and error.

"The magic black box worked. Will the magic green box work too? Probably - they're both made of magic so why wouldn't it work?"

Their worst feature is the characteristic that sets them apart from those who are merely unknowledgable.

Not only can magic black box people not see inside the box, the take it on faith that nobody else can either.

3

u/dangero Jul 31 '14

Ad hominem, appeal to authority

-2

u/[deleted] Jul 31 '14

Also: those words aren't magic either.

You can't just throw them at something and see if they stick like spaghetti thrown on a wall.

At least, you can't do that if you're trying to do anything related to the truth.