Reviewing the Bitcoin Piñata
mirage.io
mirage.io
HN discussion when the Pinata was released: https://news.ycombinator.com/item?id=9027743
(some general background to the Pinata is at: http://amirchaudhry.com/bitcoin-pinata/)
8.2 MB is pretty small, but I wonder if it can be even smaller without losing any functionality. OpenSSL, for example, is ~3 MB. Does that unikernel include symbols and other debugging info? Is there any way to get a breakdown of the object code size for each major component?
Having said that, yes there are ways to make it even smaller. We're working on getting the pieces right first.
- Native code compilation still includes symbols. Stripping that reduces the size at the obvious cost of debugging ease.
- When an OCaml module is touched for a single function, the entire module is included at present. OCaml 4.02.0 included module aliases to make it easier to break down module hierarchies into less monolithic chunks. They work by exposing module equivalence in the signature, and reduced the size of Unix binaries in Jane Street Core by 90% in some cases; https://blogs.janestreet.com/better-namespaces-through-modul...
- Bytecode (while less performant) can be compressed more easily than native code. We've had DNS and OpenFlow servers that are less than a megabyte in size quite easily when compiled with bytecode.
- Dead code elimination requires some whole program optimisation, and currently only works with bytecode via the OCamlClean tool: http://www.algo-prog.info/ocaml_for_pic/web/index.php?id=oca... . Porting this to native code is on the TODO list, but needs some fiddling with frame pointers in the generated binaries to do a good job.
So the overall answer is that reducing the deployed binary size is now a compiler problem, since the unikernel architecture lets us provide it with much more information (configuration files and OS libraries as well as the application logic).
The amount in the pinata should probably double every X days. In this situation, if two people know the secret, it is advantageous for one of them to act immediately.
Right now, unikernels aren't in major production use, so there's little to gain by holding on to an exploit (one would assume).
Correct, but there's also very little to gain by developing it in the first place. Right now, the pinata's value is approximately $2500, or less than two straightforward XSS bugs on Google properties, which are waaaay easier to find. There's just not anywhere near the motivation required to get (mostly well-paid) security people on this. It's interesting, but that's about it.
We didn't really expect the money to be the main motivator. Just a hook to draw attention.