3 ms·
How do I verify that the host is executing my application correctly? They talk about smart contracts[1] but there is a huge difference between a single host ex
by silviaotar 8y ago
How do I verify that the host is executing my application correctly?
They talk about smart contracts[1] but there is a huge difference between a single host executing an app and having the whole Ethereum network reaching consensus on the execution of a smart contract.
[1]: https://codius.org/docs/overview/for-contracts https://codius.org/docs/overview/for-contracts
- tgtweak 8y agoTechnically proof of output could be used by running it on multiple nodes and comparing output, but for anything but idempotent reads this will be difficult. Also for anything that needs any privacy this is fraught since unless you're running hardware obfuscation (sgx or similar) every workload is possibly observable by the 3rd party who is running the workload, including the client who is connecting. Ssl? Keys are on the host... Then there's the risk to the host, which could be side channeled in the best case scenario where isolation is sound, and completely owned in the worst case where containers are... containers. Lofty idea but extremely difficult without making it a tiny domain. There are multiple billion-dollar crypto projects aiming to do trusted distributed compute and so far none have shown anything but the most basic use cases.
- silviaotar 8y agoAFAIK Codius doesn't provide any tool to compare outputs from different hosts. Even if the outputs from different hosts is the same, you don't have a proof that the output is correct. For me the point is: why would I use a machine managed by an anonymous person/organization, with no guarantees on execution (and QoS in general) while I can run stuff on AWS EC2, where at least I have a contract with Amazon. > Codius billing is resource-driven, you should see a very strong correlation between the load on your servers (and the number of servers required) and the amount of money earned. from https://codius.org/docs/running-a-host/why https://codius.org/docs/running-a-host/why Codius incentive system is weird to me. I am incentivized to be a "host" and run a codius node so I can make money when people use it, and I am incentivized in maximizing my profit by faking the amount of resources used by the apps I host. I am not incentivized to be a "guest": how can I verify that the billing is correct? How can I verify that the host is running my application correctly?
- justmoon2 8y ago> AFAIK Codius doesn't provide any tool to compare outputs from different hosts. I'd love to see somebody make a browser extension that does just that! There are a bunch of important ecosystem pieces missing from Codius still. Keep in mind that this current release of it just came out a month ago. If I had a magic wand, the next things I'd introduce would be a Codius namespace system (have the design in my head but haven't had time to write it down) which can securely resolve an identifier like "alicescontract" to a JSON document like {"hosts":[...],"manifestHash":"...","hostPublicKeys":[...],"threshold":5} (For the blockchain geeks in the audience: Note you wouldn't need consensus for that because names are not fungible, so some weak form of consistency would be fine.) Then I would add a feature to Codiusd which allows a host to look up that identifier and then depending on the JSON become a proxy to that contract. What that would mean is that you could go to alicescontract.[any-codius-host] in your browser and that host would do the work of collecting responses from all the other hosts and respond once it has `threshold` matching replies. You could use whatever host you trust most as your proxy or, for the super-paranoid, you could run your own host and use that. There are further optimizations of course but I'll stop here.
- justmoon2 8y agoWell, the "whole Ethereum network" doesn't really matter. What matters are the handful of Ethereum nodes run by pools that currently represent a majority of mining power. Sure everyone else runs the code to verify the output but that's trivial. You can do that for any deterministic application you have the source code to. The important thing for most applications is ordering the inputs which boils down to: Which nodes did you select and how does your application come to consensus? With Ethereum, your selection is made for you: around 10 nodes have more than 1% hashing power and even among those, they are very unevenly weighted - three of them have a majority. With Codius, host selection is up to you, so you can select 10 nodes with even weighting or 100 nodes or whatever you're willing to pay for. As for the consensus algorithm: proof-of-work has some terrible characteristics (need to wait for multiple blocks, random block intervals, expensive, subject to front-running.) You can get a much better performing system using a BFT consensus protocol like Honeybadger. Edit: Sorry, this reply sounds a bit harsh / dismissive of Ethereum. That's not what I intended. After eight years in blockchain I just get frustrated when people assume that just because they don't know who they are actually trusting that that means the system is "trustless". It's not, no consensus system is. In fact, I would argue that any system where people aren't aware of who they are trusting is going to be worse in the long run because nobody is paying attention to the governance of that system.