8 ms·
> For one, Ethereum is unable to access real time data from outside the blockchain. Developers need to rely on trusted third party data providers, called oracle
by goodroot 9y ago
> For one, Ethereum is unable to access real time data from outside the blockchain. Developers need to rely on trusted third party data providers, called oracles, to provide smart contracts with outside information like weather, random numbers, or currency values.
I feel like this is more of a feature than a bug. If you're weaving applications into the blockchain, would it really be wise to have that chain communicate with abstract data off of the chain itself? Seems an unnecessary burden for the chain to bare!
Great article. I've recently gotten into Ethereum Dev and Solidity. It's really fun, fun stuff. This isn't directly addressed in the Ethereum portion of the article, but it's good to keep in mind that these things are all works in progress. Limitations today are non-such tomorrow; we don't quite know where the train is headed.
You, Developer, can help it get to wherever you feel it needs to go. Remember that before deciding not to contribute. :)
- sf_rob 9y agoI took this as a point of explaining what Oracles are/do. Too often Ethereum proponents skip talking about Oracles when it comes to discussing attack vectors on Eth smart contracts.
- Jasper_ 9y agoWhat I don't understand is how Ethereum can describe their dapps as "trustless" when all the trust is still centralized in an oracle. This can even happen accidentally, such as with the Mayweather/McGregor smart contract breakage. [0] But now imagine if BoxRec had intentionally reported false results from their website in order to make a lot of money on the bet. People would lose their money, and there would be no recourse. [0] https://www.reddit.com/r/ethtrader/comments/6w5wcn/important_update_mayweathermcgregor_smart_contract/ https://www.reddit.com/r/ethtrader/comments/6w5wcn/important...
- albertgoeswoof 9y agoYou can solve this by using multiple oracles and a stake-based consensus algorithm to de-incentivize malicious reporting.
- Jasper_ 9y agoI am unable to find anything about using multiple oracles in Ethereum. Do you have any information about this?
- cslarson 9y agoChainlink is a project to enable a network of decentralised oracles.
- manderson2080 9y agoHere's some good background on ChainLink: https://medium.com/@signal_capital/https-medium-com-signal-capital-our-investment-in-chainlink-15ab90ee9c02 https://medium.com/@signal_capital/https-medium-com-signal-c...
- Jasper_ 9y agoReading up on ChainLink: > Several data providers respond to this service agreement with a bid in the form of a data reply — when enough data providers have responded, the majority response is taken (or average depending on the request), outliers are removed, and data is fed into the contract. What's to stop me from setting up 10,000 different data providers that initially provide good data to get a good reputation score, but then slowly corrupt them over time? It doesn't matter how many data providers you average if I can set up millions of them in seconds. I don't see any way to solve Sybil attacks here.
- goldenkey 9y agoBingo. Most cryptocurrencies/contracts/anything in the field/realm -- they don't attack the problem of "person" vs address/wallet/account. ChainLink might think they are clever but like you said..when accounts in your network are free, then don't expect any kind of consensus to work. Accounts or rather, more abstractly, entry into your network -- needs to cost something that can't be easily done to gain majority. Another way to attack the issue is to do antes..so accounts dont cost anything unless the account holder is caught doing something bad -- ie. every entry requires a refundable collateral.
- JorgeGT 9y agoPlus, it's not like bribing oracles is unheard of. Herodotus, who lived 2500 years ago, already reports instances of bribery affecting the predictions of the Oracle at Delphi: https://archive.org/stream/jstor-3287085/3287085_djvu.txt https://archive.org/stream/jstor-3287085/3287085_djvu.txt
- dahdum 9y agoA lot of dapps don't need oracles to run. Anything that does is still more trustless than a centralized solution would be, reducing the counterparty risk to the oracle alone. As mentioned elsewhere, a lot of work is also being done on decentralizing the oracles. Like PoW / PoS protection, this raises the cost of an oracle attack high enough to reduce the risk to acceptable levels for more sensitive applications.
- joosters 9y agoIf your code doesn't reach out beyond the blockchain, then there's very little it can actually do. You are limited to twiddling balances of coins. This turns out to be great for making casinos and ponzi schemes, but little else. To do anything more meaningful, code needs to interact with the real world. And this is generally the point at which blockchain apps lose all of their purported benefits, like decentralization, immutability, reliability and so on.
- eyezick 9y ago> If your code doesn't reach out beyond the blockchain, then there's very little it can actually do. Asset issuance, voting, wills, identity/reputation systems, land registries. Fundamentally, a blockchain is just public, transparent immutable data history. Of the above sample cases, all it takes is for the powers to be to recognize the data as a reflection of the real world; which is a barrier outside of the technology. And sidenote, decentralized oracles will literally tie outside world to the blockchain.
- joosters 9y agoAsset issuance, voting, wills, identity/reputation systems, land registries. All of which reach beyond the blockchain. No-one is going to care that a 'smart contract' says that Alice owns a plot of land when Bob holds the real-world deeds. The real world and the blockchain can only be linked when, as you say, 'the powers that be' decide to recognise the data. But then you've lost all of the advantages that the blockchain was claimed to possess. For example, if we need an entity to recognise that the land registry smart contract is valid, there's no more decentralization, and we might as well let that entity store the land registry in their own simple database. The blockchain becomes pointless and wasteful.
- vincentschen 9y agoYes, the lack of outside access isn't necessarily a bug, but it can be a development hurdle!
- eyezick 9y ago> Developers need to rely on trusted third party data providers, called oracles It's ironic that they mention Augur by name in the article, but are apparently unaware its main innovation is the decentralized oracle that just so happens to have a prediction market built on top of it. > I feel like this is more of a feature than a bug. That is indeed 100% by design. All smart contract code in Ethereum has to be deterministic to guarantee computational consensus, and of course this can only be done by having a closed EVM.
- hyperion2010 9y agoVerifiable oracles are extremely hard to create. In fact I think that the creation of verifiable oracles is the single biggest challenge facing science and engineering. Full disclosure, I am quite biased about this since part of my PhD work is to create a language to specify measurement processes. How do you know whether the numbers you are getting reflect something about the real world? How do you know that your data hasn't been tampered with intentionally or unintentionally? Data provenance is extremely difficult, and that is only half the problem. The other half of the problem is determining whether you have actually measured what you think you have measured. (Note: there may be some additional halves lurking around as well.) To give some concrete examples. You find a picture of a CEO groping someone, how do you know whether it is real? Does it matter if you want to short the stock of the company, given that you know that other people will not verify it? What if the photographer's camera automatically pushed a stream of hashes of sensor contents and GPS locations to a source with a verifiable timestamp? How about the equivalent for a microscope sensor to ensure that the raw data from the sensor was verifiable, and that all transformations of that data needed to be published in a form that would allow anyone to verify that the raw data could be transformed to the final data? How about a contract that specifies that if a freezer temperature rises above X degrees C for more than 3 minutes then the freezer owner must pay Y dollars to the owners of the contents of the freezer. What does it take to build sensors that the owner of the freezer would trust enough to enter into such a contract? tl;dr Verifiability of data from oracles is extremely difficult, and much a bigger challenge than building a blockchain that could make use of it. GIGO will be a big stumbling block.
- pmontra 9y agoMaybe I'm just dumb, but is this a bigger problem than it is offchain? Data is forged all the time, we have fake news, people lie, people are jailed with false accusations. If the owner of the fridge in your example eventually discovers that the sensor has been tampered with, s/he can get the money back using the judicial system offchain, maybe reflected in some inchain contract. Answering to my own initial question, the speed of the system could make a difference. An automated way to scam people with an oracle could make it easier to get the money and disappear. Are there any other major differences?