Furthermore, it's implemented and running. You could argue that someone in particular has made a poor or incomplete explanation of how it works but not that they way it works is unfathomable or being patched as your speak. It's already implemented, go look at the code if you don't want to believe what anyone says.
And there are over 5 interoperable, independent and open source implementations of said specification:
- https://github.com/sigp/lighthouse/
- https://github.com/ChainSafe/lodestar
- https://github.com/status-im/nimbus-eth2
- https://github.com/prysmaticlabs/prysm
- https://github.com/ConsenSys/teku
- https://github.com/sifraitech/grandine
...
Do you believe the same about cryptography? Since you can't understand it, and few really understand the full system, algorithms and functions, it must be "review resistant" rather than actually safe to use?
The implementations are also very close to formally verified if not fully formally verified.
Nothing is perfect but cryptographic code has to be pretty bulletproof or a lot of systems would get owned. The descriptions of how to verify cryptographic systems are academically and professionally rigorous especially compared to eth.
Caveat: sometimes the underlying systems that cryptographic implementations utilize change degrading their guarantees. There have been times where the compiler will get updated and cause what was a branchless process to branch which could lead to information leaks against a dedicated attacker. Thankfully such examples are rare in the literature.
So is Eth2, see "Formal Verification of the Ethereum 2.0 Beacon Chain" by Franck Cassez, Joanne Fuller, Aditya Asgaonkar, paper (https://arxiv.org/abs/2110.12909) and source code (https://github.com/ConsenSys/eth2.0-dafny). More efforts to formally verify Eth2 is ongoing as well, by different entities.
> Nothing is perfect but cryptographic code has to be pretty bulletproof or a lot of systems would get owned
Same with Ethereum. The chance of having a major impact with a vulnerability is even higher I'd argue, as you can easily extract currency you can trade for USD, and the entire network is inter-connected, so finding targets to exploit becomes even easier.
Point still stands that cryptography goes over a lot of peoples head, but you don't hear those people complaining that because they don't understand it, no one does.
This is kinda where I’ve gotten to on this: consensus is pretty much safe. Smart contracting is very hard to do safely.
This is not unlike the guarantees in general computation. The metal is pretty safe. The further you get away from the metal, the more layers of abstraction you’re relying on functioning predictably.
To be clear, I’m not arguing with you and appreciate your point about formal verification of eth.
Proving systems to be correct in computer science is far from settled matter.
If the hardware is in-scope for the system, you're generally out of luck at having provable guarantees unless you're willing to operate a foundry and courier your own products.
I think it comes down to threat modeling. You have some threshold where it's unreasonable for someone to attack a system for less than $X spend. Right now on iOS I think that's on the order of $500k-$1m usd.
I wager Ethereum would be much the same if a researcher came around to say "This is actually wrong." It would be happily ignored by the authors.
That is you try to implement a standard complaint new Eth2 implementation from scratch ( and possible record yourself while doing so.
[1] https://eth2book.info/altair/part2/building_blocks/randomnes...
[2] https://eth2.incessant.ink/book/06__building-blocks/02__rand...
If you really want to know how it works, go read the code.