We wrote a paper [0] in 2015 performing eclipse attacks against Bitcoin. You can watch me talk about it here [1]. At the time it required an attacker with 400 IP addresses. Many of our countermeasures were adopted by Bitcoin-core raising the difficulty of the attack even further. In fact at this very moment I am still working on adding some of our countermeasures to Bitcoin-core [2].
In our attack on Ethereum, only 2 IP addreses were required. We discuss this in our paper:
>"We present new eclipse attacks showing that, prior to the disclosure of this work in January 2018, Ethereum’s peer-to-peer network was significantly less secure than that of Bitcoin. Our eclipse attackers need only control two machines, each with only a single IP address. [..] By contrast, the best known off-path eclipse attacks on Bitcoin [23] require the attacker to control hundreds of host machines, each with a distinct IP address. For most Internet users, it is far from trivial to obtain hundreds (or thousands) of IP addresses. This is why the Bitcoin eclipse attacker envisioned by [23] was a full-fledged botnet or Internet Service Provider, while the BGP-hijacker Bitcoin eclipse attacker envisioned by [17] needed access to a BGP-speaking core Internet router. By contrast, our attacks can be run by any kid with a machine and a script."
-Low-Resource Eclipse Attacks on Ethereum's Peer-to-Peer Network [3]
[0]: https://eprint.iacr.org/2015/263.pdf
[1]: https://www.usenix.org/node/190891
This applies to "Solidity", the most commonly used language to write smart contracts for Ethereum. The VM itself is not so bad but also simpler.
- The main ledger and smart contracts should be separated, everyone smart contract is public, why??
the smart contracts should be run on several specific sidechains. Why if I buy a crypto kittie everyone as to know and store the transaction for all eternity.
Wait sharding is coming, yes but will reduce the security guarantees.
However engineering decisions 'on genesis' was over 3-4 years ago and at that time doing a blockchain with smart contracts was already challenge on itself. It's not really fair to take the knowledge and lessons from the present day and claim those in the past without that knowledge made horrible decisions. It's a bit like blaming google for not starting angular 1 with the functionality of angular 4, or saying that John Resig should have created Babel and ES7 features instead of creating jQuery.
Sorry when I heard about Ethereum plans 4 years ago, I tough it as a terribly bad idea then (I didn't invest because of this, I should have invested stupid me) in 2013 the increase size of blockchain was already an ongoing problem, I simply tought if a decentelized ledger is already problematic to store, let's put a lot of more information on it, it's madness..
You might find Blockstack interesting.
(I don’t have a connection. I’ve just started to explore this space, and have some of those same questions.)
[2] Jude, “What is the difference between blockstack and Ethereum?”, Blockstack forum, March ‘17. https://forum.blockstack.org/t/what-is-the-difference-betwee...
[3] Alid Castano, “What is the difference between Blockstack and Ethereum?”, Sept. 13 ‘17. https://www.quora.com/What-is-the-difference-between-Blockst...
[4] Alid Castano, “Why I’m betting on Blockstack to save the decentralized internet”, Sept. 12 ‘17. https://medium.com/@alidcastano/why-im-betting-on-blockstack...
I didn't know this project I normally hate ICO's (including the original Ethereum ICO) from what I have read on the information you so kindly shared it looks like a much more sensible approach to the distributed permissionless application problem, let's see how it goes.
that loses your funds, that is the bad part.