5 ms·
This is interesting, but I could see some possible issues. It would be fun to ask the Devs some questions. eg: if peers are able to select their arbitrators,
by Jaepa 9y ago
This is interesting, but I could see some possible issues.
It would be fun to ask the Devs some questions.
eg: if peers are able to select their arbitrators, how do you prevent a peer and & arbitrator from gaming the system. There is a secondary arbitrator but from the docs it looks like after the initial arbitration the funds are released.
Is there a way to protect against root DHT node hijack? Only refernce I see to this is a TODO: See how btc does this.
- oelmekki 9y ago> if peers are able to select their arbitrators, how do you prevent a peer and & arbitrator from gaming the system Actually, it doesn't even need a criminal association : what if arbitrator is malicious? FAQ answers both our questions : https://bisq.io/faq/#8 https://bisq.io/faq/#8 and https://bisq.io/faq/#10 https://bisq.io/faq/#10 The defense mechanism chosen is to make arbitrators pay a high registration fee, so that it would supposedly cost them more to trick the system than they would win (because of the 1btc trade limit). To be noted is that current arbitrators are handpicked by founders, but they want it to be fully decentralized ultimately. What is not addressed is this : if arbitrator management is fully decentralized, how will people be triggering their safety payment if they do something bad? Will there be some kind of a vote or something? How much time would it takes? (because if it's long enough, malicious arbitrator can steal money from several trades and outperform their safety deposit). It seems like the hardest part to decentralize, and I don't think it's addressed well enough yet.
- ManfredKarrer 9y agoGood questions: See the new concept for securing the arbitration system by the DAO tokens: https://docs.google.com/document/d/1DXEVEfk4x1qN6QgIcb2PjZwU4m7W6ib49wCdktMMjLw https://docs.google.com/document/d/1DXEVEfk4x1qN6QgIcb2PjZwU... In short: The arbitrator will have to lockup a high amount of BSQ (DAO tokens)and in case he would default that deposit can get confiscated by voting. He also is limited to do not more than 20 cases.
- ManfredKarrer 9y agoYes the trader can select his arbitrator. The arbitration system got a conceptual change with the upcoming DAO and will be secured by locked up security deposit of the arbitrator as well as an introduction of a mediator who will cover most cases and who has no key to the 2of3 MS. See: https://docs.google.com/document/d/1DXEVEfk4x1qN6QgIcb2PjZwU4m7W6ib49wCdktMMjLw https://docs.google.com/document/d/1DXEVEfk4x1qN6QgIcb2PjZwU... Most arbitration cases are customer care cases and there have been actually no real dispute at all where the traders delivered conflicting statements. We use PageSigner/TLSNotary (https://tlsnotary.org/ https://tlsnotary.org/) for the case that traders have a real dispute. With that we can get a tamper evident proof if the bank transfer took place. WE don't use a DHT but a custom P2P network based on a floodfill algorithm. All traffic is routed over Tor and each node is a hidden service.
- Jaepa 9y agoHuh. I thought I saw in the documentation there are references to securing the master DHT, though I did see references to something called TomP2P. I'm no in a place where I can go back through the documentation for this though. My original question I think still applies how every so I'll try and rephrase it: Is there a way to secure the Peer Discovery service in such a to secure against creating a secondary network of peers, then running a bookkeepers odds scheme. (Using the secondary marketplace as an options market for transactions on the first)
- ManfredKarrer 9y agoWhich doc are you referring? We used a DHT in early days but that was long before the launch. Maybe I oversaw to update at some place... There are 4 seed nodes to which you connect randomly at startup. They deliver you all known onion addresses in the network. From that list you select randomly peers until u have 8 connections. You also maintain your local peer list which will be used at follow up startups. I don't see a way how to partition the network. You get random incoming connections as well (e.g. if one takes your offer). The floodfill network architecture is very robust against eclipse attacks (dht problems) and partitioning. Thats why a floodfill architecture is used on Bitcoin as well.