Vampire Attack Twitter
geohot.github.io
geohot.github.io
The smaller problem is in those details—the scheme described is highly vulnerable to attacks like the following: I create a network of private bot accounts who post high-frequency generated content, and a follower account who follows them all and installs the browser extension. Whenever I want I can print money (well, Twitcoin) by uploading these fake hornet tweets to the new platform. I can think of ways to defeat this specific attack relatively easily, but I’m not sure it’s easy to defeat all such attacks.
Interaction with the real-world (outside the blockchain) is where the vast majority of these bullshitchain projects fall apart.
For TLS 1.1 (and supposedly "TLS 1.2+" since https://github.com/tlsnotary/PageSigner/commit/4e12573): https://tlsnotary.org/pagesigner
For TLS 1.3 there's also TLS-N from https://eprint.iacr.org/2017/578.pdf but it requires a cooperating server:
"TLS-N generates non-interactive proofs about the content of a TLS session that can be efficiently verified by third parties and blockchain based smart contracts. As such, TLS-N increases the accountability for content provided on the web and enables a practical and decentralized blockchain oracle for web content. TLS-N is compatible with TLS 1.3 and adds a minor overhead to a typical TLS session. When a proof is generated, parts of the TLS session (e.g., passwords, cookies) can be hidden for privacy reasons, while the remaining content can be verified."
Probably not. If it does start to matter it should start becoming an issue for twitter too and they'd probably have to deal with it.
Ironically the fact that they are paying 10x for original "tweets" posted through their interface makes it so that nobody who can think would try fake scraping. You are 10x better of just blasting your crap directly at their interface as "original" "content". :)
Doesn't the same apply to many blockchain applications ?
- if you provide an essentially identical service
- you make it seamless to switch
- and you incentivize users to switch
Then you may be able to aggressively siphon users from your target.
OP’s example is using a blockchain as the distribution mechanism for the incentives.
Lot of startups do this but have pretty high CaC. In the Sushi/Uniswap case, users were already crypto-native. In the twitter case, the majority of users are not. There's just going to be a bigger barrier than in the former case. Sure, I think if you spend money some people will switch, but it's much less clear to me how much money you'd need.
Basically this strategy is "steal Twitter and fund the effort with another crypto Ponzi".
It would be ridiculous to use a blockchain to authenticate posts, upvotes, friend connections, etc, since these should all be done with digital signatures alone
The ostensible scheme can't possibly actually work (it requires Twitter to not do anything to stop it -- of course, Twitter would work to stop it to the extent it ever actually threatens them).
What can work, though, is the narrative of the scheme. What you need is a mechanism to incentivize people to promote the narrative of the scheme.
That's where the crypto comes in. It's a viral mechanism to franchise selling the scheme. Anyone can buy in, promote the narrative, and get others to buy in. It doesn't really matter how many of the people have a deep belief in the original narrative or not. Get people's attention, get them to believe there is more money in it if they put in a little money, and once the money starts moving around, there will be opportunities to grab some, or perhaps a lot of it.
the crypto bros don't want to perform for an audience that's only other crypto bros, they want to reach the people who aren't part of their circle, and twitter provides that. same for the right-wingers - if they can't reach the suburban wine moms, there's no point in posting.
This is a great definition of cryptocurrency. It nicely frames how they become pyramidal.
This could be said about 99.9% of all blockchain products and companies.
Another is that Twitter is 6000 transactions per second, whereas Ethereum only manages about 15tps - 1/400th as much - and BTC 7tps.
You could add the crypto layer to Mastodon, and by the time scale becomes an issue, you haven't irretrievably crippled yourself and you build it from there. Plus federation and so on.
I would think scraping Twitter would come with legal hassle, so a lawsuit could be worse than any technicalities.
Yeah, uh, definitely.
> Tons of creators would migrate for the FREE MONEY! ... Even lurkers will use TWITCHAIN front end because it doesn’t have ads and fake “trending” topics.
So the whole gimmick here is that supposedly you're going to get ordinary users to switch (i.e. install your extension that puts them on a duplicate site)? Actually, if you succeed at anything at all you're going to run into the issue that the people who want to use your site are, for the lack of a better word, cringe. Most people are like me and won't use it exactly because of the sort of audience this kind of supposed "Twitter alternative" would draw. That's if they even care, and most people don't.
(I realize describing people as "cringe" is judgmental sounding, but there's really not a better word here from the point of view of the people who I'd call "normies".)
What kind of blockchain would actually be able to deal with the expected transaction count? According to [1] Ethereum peaks out at 15 transactions per second, but [2] claims around 6.000 tweets per second on average.
A difference of 2–3 orders of magnitude is not something a team of 5 engineers can simply solve in 6 months.
[1]: https://blog.coinbase.com/scaling-ethereum-crypto-for-a-bill...
Good luck storing those on blockchain :D
[1] http://highscalability.com/blog/2016/4/20/how-twitter-handle...
> Good luck storing those on blockchain :D
I'll admit that a normal blockchain would be impossible to store that level of transactional data. Of course that doesn't mean that it isn't possible to store it in a decentralized manner: It does, however, require different methodologies to make it work.
Currently, the best attempt at this comes from both Filecoin & Arweave, but they're both coming at the problem at different angles [1]: Filecoin tries to solve the storage problem as a "Pay for X storage for Y time" problem, whereas Arweave is trying to solve it as a "Pay to store X storage forever" problem.
Going by Arweave's current stats [2][3], it is possible that the network could be able to handle that level of content generation with a high enough node count. In fact, a stress test of sorts is currently underway, as there's an attempt to try and store the Russia-Ukraine conflict on the network [4].
[1] https://coinmarketcap.com/alexandria/article/the-decentraliz... [2] https://viewblock.io/arweave/blocks [3] https://viewblock.io/arweave/stat/cumulativeWeaveSizeHistory [4] https://www.forbes.com/sites/stevenehrlich/2022/02/25/a-bloc...
Translation: blockchain a) doesn't solve this problem, and b) isn't required for this
> Translation: blockchain a) doesn't solve this problem, and b) isn't required for this
Clarification: The data structure of a typical blockchain that is regularly talked about (single-chain, no shard/web) definitely cannot store that level of data. In order to reach that level of data throughput, better data structures are required to do so.
Single-chain blockchains are great in terms of determining transaction finality, but are poor in terms of data storage. This doesn't mean that research into decentralized & computationally-assured data storage techniques shouldn't be pursued.
No, it doesn't, for one simple reason: blockchains is not the only such tech, and "computational assuredness" probably isn't really a requirement for this.
> No, it doesn't, for one simple reason: blockchains is not the only such tech
Again, reiteration must be applied here: The standard single-shard reference-to-previous-block data structure that is the initial blockchain structure is non-conducive towards decentralized data storage. As stated beforehand:
> > The data structure of a typical blockchain that is regularly talked about (single-chain, no shard/web) definitely cannot store that level of data. In order to reach that level of data throughput, better data structures are required to do so.
> , and "computational assuredness" probably isn't really a requirement for this.
Towards the latter half of your statement, if computational assurance is not required, then standard trust-based storage solutions can be implemented instead.
HOWEVER (and it should be stressed with extreme emphasis on the word), in that scenario, concerns about the centralized nature of such a storage solution CANNOT be launched by critics: It was their criticism of decentralized storage solutions that caused the shift towards standard trust-based storage solutions, and thus they cannot criticize the move towards the latter. Otherwise, their criticism is not out of technical concern, but out of personal opinion.
This sounds like a rant devoid of meaning.
Yes, there are centralized solutions. Yes, there are decentralized solutions. Yes, critics have full right to criticize both, because both have their failings.
This has literally nothing to do with whatever ideological angle you're trying to force.
> This sounds like a rant devoid of meaning.
> Yes, there are centralized solutions. Yes, there are decentralized solutions. Yes, critics have full right to criticize both, because both have their failings.
> This has literally nothing to do with whatever ideological angle you're trying to force.
The ideological angle in this case is: "N solutions have a mixture of good & bad, but at least one of them is required for system S to function. Critics that criticize N-1 of N solutions cannot criticize the usage of the Nth solution when that is the only other solution left, after catering to their desires for (1...N-1) of N solutions to not be used."
Admittedly, the only way to be able to achieve that level of throughput would be to require zk proofs for assured transaction finality, on top of being a Layer 2 scaling solution.
Currently, that level of throughput can be obtained by using a specialized ZK-rollup network like StarkNet [3] if it needs to be deployed right now. Otherwise, zkSync 2.0 [4], an EVM-compatible general ZK-rollup, is currently in its testnet stages & is currently the desired goal for scaling Ethereum's TPS up to the desired amount.
The technology is currently still in it early stages, as demonstrated by zkSync & StarkNet, the capability to reach that level of throughput is possible.
[3] https://starkware.co/starknet/ [4] https://v2-docs.zksync.io/dev/
If will take mostly an hour, if not minutes, for someone to hook into Twitter API and mimic the browser extension's requests to mine TWITCOIN by constantly feeding new tweets. Scale this to many developers out there and you've just invented Proof-of-well, ...bandwidth? ...API access? ...processing power (aka Work)? that gives you coin in return.
No one will use the extension, and because of the nature of it, it will be totally open to Sybil attacks anyway.
If you can't verify that the tweets are real, what is the incentive for anyone to post real tweets, instead of just streaming random garbage into your system in exchange for coins?
Twitter has 200M "monetizable" DAUs. The poster suggests that spending $1B would move those users and those users traffic over. That implies that $5 in some shitcoin would be enough to make people switch to this app. That does not seem plausible at all. If acquiring and retaining users was that easy and cheap, there would be a lot more major social networks around.
Twitter in 2014 had 500M tweets per day. How long a time period will the $1B be distributed over? The poster doesn't say, but let's assume a year. That'd be about 5 cents per tweet. No real users would care about that. If anything they'd be insulted. But botnets posting spam would have a field day with it. It would of course be botnets that the company would have no way to fight, since with this distributed scraping idea they'd struggle to collect any kind of abuse signals related to the actual tweets/likes/other monetizable events.
This would never work.
I don't get it. But I don't get the point of most blockchain bs.
That's where the 1B in buy-orders backing the coin is meant to come in, allowing people to exchange those coins for real currency.
But neither is the GPT-3 to verify if the GPT-3 is GPT-3.
Crypto is exactly about strengthening copyright.
What, this?
https://support.opensea.io/hc/en-us/articles/4412092785043-W...
Art gets stolen from Deviant Art etc every day, as it has been for decades. The NFT ecosystem makes it super easy for people to look at listed art and ensure that the proper artist is getting paid. If they fail to do their due diligence, then the NFT they paid for is worthless. The system seems to be working just fine.
NFTs don't prevent theft of IP, nothing does. What it does do is prevent people from effectively profiting off IP theft.
How so? Let's say you made an NFT of your art, how does that prevent someone else printing it on a t-shirt and selling it?
How so? Walk us through the steps that ensure the proper artist is getting paid
> If they fail to do their due diligence, then the NFT they paid for is worthless
So:
- the person who paid for stolen art was scammed out of their money
- the original artists weren't paid
- the scammer got the money
I see, NFT is working as intended
> What it does do is prevent people from effectively profiting off IP theft.
How come people are profiting off IP theft on NFTs right now?
Totally wrong. Utterly wrong.
Suppose Alice has an NFT of an image, whereas Bob has legal ownership of that image.
Charlie makes a series of T-shirts with the image. Bob can sue Charlie and win. Alice has no rights, not even legal standing to sue.
NFTs have zero legal value.
A lot of the art is stolen. NFTs do nothing to prevent that.
No, your plan of giving away money and giving away bandwidth and making money... through magic? is not going to fly.
Ask anyone here, the blockchain/crypto part adds no value to this. Better ways to do this. There are banks and credit card companies and they would have zero issues being intermediaries in a scheme like this. They're neutral actors after all.
Which bank or cc company is going to jump on the opportunity of platforming an alternative to twitter that almost definitely going to include content that the institutions already voted wouldn't be platformed.
On the other hand, a fresh network of imaginary credits that perhaps might inherit some value requires no permission and can be setup by almost any entity.
I forgot to tout the banks' other well known qualities that perfectly demonstrate the vapidity of cryptocurrencies. Chief among them, their ability and willingness to facilitate high volume of transactions to a mass of semi-anonymous website users.
#MitochondrialFork. https://docs.google.com/document/d/1TIbvOjbaHbcwSqiEJzBBIcH1...
and that's where you should stop reading
> Step 1: Make a clone of Twitter on a blockchain with a native currency of TWITCOIN.
Sure.
Hubris of some people …
How does the chain "know" that the tweet you just provided is legitimate and not spam you just made up? Malicious actors can quickly exploit this to farm endless amounts of the coin as it is cheaper than searching for true tweets that haven't yet been seen.
Furthermore if your objective is just to pay people to join your site then I don't see the need for a bullshitchain.
Nevermind the insane electricity costs - how are you getting anyone to install the extension, when nobody values your fake coin?
But even a POS blockchain is a giant waste of electricity on what amounts to a casino backed by illegal securities
Note: since the $1 is fictional, this remains 100% vaporware
Distributed Denial of Service of the Legal system by violating copyright distributedly.
On the flip side, monetizing social interactions is a great way to suck the vitality and soul out of them, which would fastly reduce twitter's impact on the real world. So if you don't like twitter this isn't the worst proposal.
Or just making the Twitter clone and open api and the extension so it's a seamless experience to follow anyone across any of the clones. Users can just scrape their own feeds as needed.
Not enough hand wavy crypto magic in these ideas?
By cloning people's accounts without their permission and storing data in these "shadow accounts" (to borrow a phrase from Facebook's fuckups) it's probably going to run afoul of the GDPR, too. Data on the blockchain is immutable and undeletable, have fun complying with the GDPR's right to data erasure, for instance. Really any "let's make $service but ON THE BLOCKCHAIN" proposal runs up against that one, hard.
This plan also ignores the part where people who do not want to be part of your pyramid scheme would start sharing blocklists of people known to be running the browser extension. How long do you think it would take to make a bot that watches for people who have linked their Twitter accounts to Vampire Twitter accounts, and auto-block them for anyone who wants to subscribe to it? Autoblock extensions sprung up very quickly after the hexagonal NFT icons popped up on Twitter.
'it would totally work!'… uh-huh. Suuuure.
I don’t see why a blockchain needs to be involved though. Can’t we just work on mirroring Twitter onto mastodon?
The initially harmless Reddit alternative that got overrun with nazis. I actually started working on a Voat app for Android back when it seemed like it actually had a chance to be successful... but when I connected it to the site and saw racist garbage polluting my shiny new app, I decided to abandon ship.
> 100k people would install this
> Tons of creators would migrate for the FREE MONEY!
I’m surprised that the author thinks these are all /easy/.
Good luck to anyone trying to do the same.
The various right-wing twitter alternatives are already there with polished platforms providing the equivalent functionality, why don't they pay Twitter's users to switch over?
I can't tell if the author is serious or not. This seems like the most roundabout (and optimistic) way to solve this problem possible.
But more generally, Twitter is tweets, and tweets are written by people, and lots of folks think the promise of "free money" is a bad one. Your weird uncle switching does little to help this plan, you need Matt Levine and Popehat and all the other prolific posters to move. This plan, at its core, tries to attack Twitter the wrong way. It tries to replace the utility of Twitter (reading tweets by interesting people) with financial incentive.
Honestly a great way to waste a billion dollars.
Okay, so do it. Let's see how simple it is in reality.
Peoples extensions will just fake tweets. Or a single bot running through many IPs can just harvest them all.
This can be solved.
But Twitter is a incredibly complex database with a lot of the data and data structure unable to be seen.
This would take years of engineering work and would assumably break copyright or maybe IP or patents.
If it's enough to scare Twitter shareholders it might allow a cut price sale. But what a MVP would be is unknown off this article.