Ethereum fixes serious “eclipse” flaw
arstechnica.com
arstechnica.com
I imagine that if people could take short or long positions* in programming languages and technologies, it would be difficult to find the current quality of reviews and discussion around those topics.
I’ve been a fan of futarchy and prediction markets, but this phenomenon gives me pause.
* I’m aware that investing time, effort or credibility in a technology is taking a long position in it, but direct financial positions seem to incentivize a different class of behavior (EDIT: probably because they require an investment only of money, rather than of these other resources that produce commitment or knowledge).
It might be because of the intersection of different disciplines. For example, a math genius won't necessarily understand law, politics and/or economic policy.
The others probably won't understand math.
A marketing / CEO type might understand the business angle.
Don't even get me started with 'journalists' who have to report on any of these areas. It's hard.
There's some sort of Peter Principle effect where people from the various fields present themselves (perhaps sometimes accidentally) as experts in the other areas. Sorry, but knowing advanced cryptographic algorithms doesn't give you the authority such that I'm going to believe your predictions about law or politics. If you're an MBA/marketing type, hearing you talk about asymmetric encryption sometimes leads me to cringe.
Meanwhile, the people who actually COMMENT on cryptocurrency news are the worst. They range from "there's nobody home in the head" types that type in all-caps comments that look more like wishes about 'the moon', or perhaps some attack against the FED and money-printing that they repeat; to baby boomers who scream about tulips and that you can't touch the digital assets.
It's a disaster of information overload. The best you can do is observe, place your bets (if you're the betting type) and watch passively.
Reputation systems such as HN itself are another approach. These might not scale; or they might require an eigentrust-like system to scale; or scaling via eigentrust might create and reinforce the same kind of filter bubbles we see on social media. Who decides who’s a climate expert?
Steemit is an attempt at a blockchain-based reputation system. Whenever I’ve looked, it’s been dominated by low-quality content, mostly about crypto itself. Maybe this is growing pains, or maybe a reputation system needs a different go-to-market (that bootstraps from an existing platform or community), or maybe wedding reputation to crypto — or at least to crypto that pays out — just isn’t a good idea. (You didn’t exactly suggest that, either; I just riffed my way over to it.)
sometimes it'll be simple arithmatic, other times multi-variable calculus.
By all accounts Citizendium failed pretty spectacularly.
People often criticize 'crypto' on the basis of technology, but are wrong about the market because the market is driven by psychology, and often disregards the tech.
Like, people might say "oh, so-and-so is vaporware because it's literally just a whitepaper and an empty github repo", and then people go "pfft, whatever you don't understand their vision" - and the value goes up 50x over two weeks.
There are great resources, although the are commonly rather vertical, then horizontal by topic. E.g. there is a lot of great technical information out around Bitcoin, how it works, wiki pages that discuss the code and algorithms in details - really useful stuff, e.g: https://bitcoin.org/en/developer-guide
Its rare though to find a more "cross-disciple" assessment/analysis of crypto currencies (political, economic impcat, society changes,...). If anyone has good resources, please share.
But on the Internet, which is really to say in written form, there's more room for attention span and dissection of arguments. In person, in conversation, you have attention span issues, you have failure to break down definitions and thus people arguing sideways against one another, etc.
It's harder to cheat in the written word.
Uh oh. This reasoning is unreasonably self-contradictory.
Here's the partial-implementation of Countermeasure 2 in geth: https://github.com/ethereum/go-ethereum/pull/16069
Of note, this fix is still susceptible to attacks, though still an improvement:
> Since geth v1.8.0 still allows the attacker to freely craft node IDs that land in specific buckets, the partial implementation of Countermeasure 2 in geth v1.8.0 means that for a given victim’s table, there can be at most 10 attacker node IDs associated with each attacker IP address. While this improves on the situation prior to geth v1.8.0 (where we could eclipse our victim using just one or two IP addresses), it does not raise the bar for attackers quite as high as we had hoped.
Still making my way through the paper and the PR to identify other things fixed. Here's the entire 1.8 release: https://github.com/ethereum/go-ethereum/releases/tag/v1.8.0
This statement from ethereum/geth developer Felix Lange even hedges on how completely the vulnerability has been mitigated, which may not bode well for ethereum in general:
>We have done our best to mitigate the attacks within the limits of the protocol. The paper is concerned with 'low-resource' eclipse attacks. As far as we know, the bar has been raised high enough that eclipse attacks are not feasible without more substantial resources...
He did go on to mention his belief alternative ethereum client Parity isn't vulnerable, so there's that at least.
When people majorly botch x509 cert validation because the spec is so monstrously complex that's still a problem with x509.
It seems to me that the most reliable defense against eclipse attacks is to just compare the block rate of the longest chain we know about to the historical average. If the block rate is roughly normal, then either we're seeing the real longest chain, or an attacker has acquired nearly 50% of hash power, which is unlikely.
The same idea works with proof of stake -- if the participation rate drops substantially below the historical average, we're probably not seeing the main chain, and we shouldn't consider anything final until the participation rate return to normal.
If an attacker has access to the cable outside your home they have already won, it's game over.
>It seems to me that the most reliable defense against eclipse attacks is to just compare the block rate of the longest chain we know about to the historical average. If the block rate is roughly normal, then either we're seeing the real longest chain, or an attacker has acquired nearly 50% of hash power, which is unlikely.
Block creation have high variance. Over short periods of time, say a few hours no blocks being announced is fairly common. Over long periods of time how do you know the mining power has not decreased or increased at a slow rate than your person prediction.
>The same idea works with proof of stake -- if the participation rate drops substantially below the historical average, we're probably not seeing the main chain, and we shouldn't consider anything final until the participation rate return to normal.
Interesting you can design PoS systems such that if not a quorum of stake is online, no new blocks are created. Algorand has some very neat properties in this regard.
Not if I'm looking at the block times or PoS participation rates. The attacker can feed me their own fork while preventing me from seeing the actual highest-difficulty chain, but their fork will be suspiciously weak, so I'll know not to trust it.
> Block creation have high variance. Over short periods of time, say a few hours no blocks being announced is fairly common. Over long periods of time how do you know the mining power has not decreased or increased at a slow rate than your person prediction.
Yeah; with Bitcoin you would need to wait several hours to get a good estimate of hash power. With more granular blockchains like Ethereum you could get a good estimate more quickly.
Would be really interested to read a paper that invents a confirmation sureness metric based on distances between block times which takes into account eclipse attacks.
Why exactly does Ethereum use Kademlia anyway?
Kademlia's main purpose is to find content distributed among a small percentage of nodes.
Ethereum doesn't need this, since the entire blockchain is stored on every node.
And does the attack also work against other applications that use Kademlia, such as IPFS and I2P?
One such principle which doesn't need many attacking nodes, rely on peers self-clustering themselves over time is the following :
You divide the peer network in 2 groups. Using a few number of attacking nodes, when a peer from one group ask you for a node you know, you answer with a peer from the same group. Then each peer from each group is more likely to recommend a peer from the same group. Over time bias accumulate, and cluster forms, with very few bridges between the two groups which you control.
Obviously it can be mitigated easily by adding some hard-coded "central" nodes or monitoring the network.
Afaik robust peer discovery in p2p network is still not solved.
Maybe it is the way the article is written, or how I've read it, but the original flaw involved just 2 nodes w/ 2 IP address. This fix sounds like you need 2 nodes w/ 2 IP addresses that don't have the same /24 octal? Is it that much more difficult?
> When even a single node presents users with a different version of the blockchain, they will be warned of an error that effectively defeats the attack.
Doesn't this just mean the attacker has to make sure to control all 13 connections before starting the attack?
We wrote a paper [0] in 2015 performing eclipse attacks against Bitcoin. You can watch me talk about it here [1]. At the time it required an attacker with 400 IP addresses. Many of our countermeasures were adopted by Bitcoin-core raising the difficulty of the attack even further. In fact at this very moment I am still working on adding some of our countermeasures to Bitcoin-core [2].
In our attack on Ethereum, only 2 IP addreses were required. We discuss this in our paper:
>"We present new eclipse attacks showing that, prior to the disclosure of this work in January 2018, Ethereum’s peer-to-peer network was significantly less secure than that of Bitcoin. Our eclipse attackers need only control two machines, each with only a single IP address. [..] By contrast, the best known off-path eclipse attacks on Bitcoin [23] require the attacker to control hundreds of host machines, each with a distinct IP address. For most Internet users, it is far from trivial to obtain hundreds (or thousands) of IP addresses. This is why the Bitcoin eclipse attacker envisioned by [23] was a full-fledged botnet or Internet Service Provider, while the BGP-hijacker Bitcoin eclipse attacker envisioned by [17] needed access to a BGP-speaking core Internet router. By contrast, our attacks can be run by any kid with a machine and a script."
-Low-Resource Eclipse Attacks on Ethereum's Peer-to-Peer Network [3]
[0]: https://eprint.iacr.org/2015/263.pdf
[1]: https://www.usenix.org/node/190891
- The main ledger and smart contracts should be separated, everyone smart contract is public, why??
the smart contracts should be run on several specific sidechains. Why if I buy a crypto kittie everyone as to know and store the transaction for all eternity.
Wait sharding is coming, yes but will reduce the security guarantees.
However engineering decisions 'on genesis' was over 3-4 years ago and at that time doing a blockchain with smart contracts was already challenge on itself. It's not really fair to take the knowledge and lessons from the present day and claim those in the past without that knowledge made horrible decisions. It's a bit like blaming google for not starting angular 1 with the functionality of angular 4, or saying that John Resig should have created Babel and ES7 features instead of creating jQuery.
Sorry when I heard about Ethereum plans 4 years ago, I tough it as a terribly bad idea then (I didn't invest because of this, I should have invested stupid me) in 2013 the increase size of blockchain was already an ongoing problem, I simply tought if a decentelized ledger is already problematic to store, let's put a lot of more information on it, it's madness..
You might find Blockstack interesting.
(I don’t have a connection. I’ve just started to explore this space, and have some of those same questions.)
[2] Jude, “What is the difference between blockstack and Ethereum?”, Blockstack forum, March ‘17. https://forum.blockstack.org/t/what-is-the-difference-betwee...
[3] Alid Castano, “What is the difference between Blockstack and Ethereum?”, Sept. 13 ‘17. https://www.quora.com/What-is-the-difference-between-Blockst...
[4] Alid Castano, “Why I’m betting on Blockstack to save the decentralized internet”, Sept. 12 ‘17. https://medium.com/@alidcastano/why-im-betting-on-blockstack...
I didn't know this project I normally hate ICO's (including the original Ethereum ICO) from what I have read on the information you so kindly shared it looks like a much more sensible approach to the distributed permissionless application problem, let's see how it goes.
This applies to "Solidity", the most commonly used language to write smart contracts for Ethereum. The VM itself is not so bad but also simpler.
that loses your funds, that is the bad part.
Of all the things anyone would trade for money Cryptokitties is really riding the line between smart and so dumb it devalues the concept of Ethereum, which might have been the point.
Ethereum is a weak attempt at money laundering.