3 ms·
> - Signed Transactions (TLS based authentication trades security & audibility for speed) I think you meant "auditability". How are "Signed Transactions" an u
by m3ta 10y ago
> - Signed Transactions (TLS based authentication trades security & audibility for speed)
I think you meant "auditability".
How are "Signed Transactions" an upgrade from TLS 1.2? How is TLS trading security for speed?
- buckie 10y agoI did, though I can't edit it now sadly. And it's not that TLS isn't secure but about what features TLS gives the system. The gist of this is that TLS doesn't give one a durable/persistable form of security vs ppk-sig's ability to verify that x signed y at any time. TLS is much faster than verifying the sig with every transaction on every node but after, say, a cluster restart the question of "who sent x" is answered via consensus and not cryptography. There are a couple other issues too. Using ppk-sigs means that the mail clerk and the CEO use different keys to sign transactions vs TLS where you'd either have a logical "from:" field or a different connection for different users. Both of the TLS solutions have rather obvious flaws. Finally, a TLS based approach puts an attacker 1 server away from impersonating, potentially, an entire organization because the system using TLS cares only that it came via the correct pipe. Overall I'd describe systems using TLS as not being paranoid enough about who authored a transaction, as PBFT/SmartBFT are by default very trusting of a client's transactions vs Bitcoin's model where everything is to be questioned/require independently verifiable cryptographic proof. Hence the tradeoff.