11 ms·
> How do I verify that the host is executing my application correctly? You can't verify what an individual host does. So you can either upload your application
by justmoon2 8y ago
> How do I verify that the host is executing my application correctly?
You can't verify what an individual host does. So you can either upload your application to a single host that you trust to run it (like everyone has been doing happily for decades) or you can write your application to be Byzantine fault-tolerant and upload it to multiple hosts.
The key things that Codius provides that make this possible are:
- Host provides the hash of the manifest which shows exactly what it's running down to the container image hashes. -> This removes trust from the uploader. So I can upload a BFT application to 10 hosts and you can convince yourself to trust it if you can convince yourself that the code is legit and too many of those hosts won't collude. That's not possible with traditional hosting because the uploader generally gets admin rights at ALL hosts they upload to.
- Standardization, so you can upload to many hosts without speaking a dozen different APIs.
> How do I make sure that a host is billing me the right amount of money?
You pay when you upload and your client is enforcing a certain max rate. The host could turn off your contract before the agreed-upon time so if you're worried about that you could only pay for e.g. two hours at a time using some cron job.
In practice, a lot of this will come down to host selection. If a host has been legit, reliable, etc. for years, it's unlikely to suddenly decide to screw you out of $10. That's why we think host trackers like codiushosts.com will play an important role. We're working on building our own host tracker as well.
Edit: Fixed typo.
- silviaotar 8y ago> You can't verify what an individual host does. So you can either upload your application to a single host that you trust to run it (like everyone has been doing happily for decades) or you can write your application to by Byzantine fault-tolerant and upload it to multiple hosts. There is a difference between trusting someone and have a contract with someone. If I use EC2, I'm using AWS, and they have policies and laws they have to comply with (data privacy is one of the first one that pops up in my mind). Technically, nothing stops a AWS engineer to put their hands in my application; Legally, they cannot do it, so they are liable if I find it out. I'm not saying that AWS is the best. I'm saying that compared to AWS, Codius gives me less guarantees. > [...] That's not possible with traditional hosting because the uploader generally gets admin rights at ALL hosts they upload to. A Sybil attack seems to be quite cheap on Codius. I can have 10 hosts managed with 10 different identities and make people think the app is legit. > Standardization, so you can upload to many hosts without speaking a dozen different APIs. I don't mind having more tools to achieve that, but Docker/Kubernetes standardized the way devops deploy apps, you can use them on different cloud providers (or on your own machine[s]). > You pay when you upload and your client is enforcing a certain max rate. The host could turn off your contract before the agreed-upon time so if you're worried about that you could only pay for e.g. two hours at a time using some cron job. There is still no proof that the host charged me the correct amount of money. Even if I cap the money I put in the system, a host can still charge me much more than it should be. > In practice, a lot of this will come down to host selection. If a host has been legit, reliable, etc. for years, it's unlikely to suddenly decide to screw you out of $10. That's why we think host trackers like codiushosts.com will play an important role. We're working on building our own host tracker as well. Maybe I'm thinking too much about "blockchain" when I think about Codius, but reading "Decentralized apps" and "Smart contracts/programs" in the homepage doesn't help, I'd remove it.
- justmoon2 8y ago> I'm not saying that AWS is the best. I'm saying that compared to AWS, Codius gives me less guarantees. Codius isn't supposed to give you any guarantees but Codius hosts might. Imagine you're a Codius host. You make money when people upload contracts. If you think you can make more money by legally agreeing not to screw with your users' uploads, you may just do that. IANAL, so I'm not sure exactly how you would do it but I imagine you could have the CLI print a tabulated summary of the hosts' terms and conditions that you could agree to and thereby enter into a binding contract. Whether this is a good idea and whether people will actually do this, I don't know but there are definitely hosting companies who are interested in running Codius hosts. So as an uploader you'll be able to choose to upload to reputable hosting companies or to whoever you want. There are pros and cons to either option. > A Sybil attack seems to be quite cheap on Codius. I can have 10 hosts managed with 10 different identities and make people think the app is legit. Point taken. I remember a few years ago there was a story going around about some botnet you could rent with 400000 hosts. So this isn't anything new. If people abuse Codius, we'll think about ways to make that less attractive. But I think it's not so unprecedented to have distributed networks you can run arbitrary code on that we have to worry about breaking the Internet. I hope. > Maybe I'm thinking too much about "blockchain" when I think about Codius, but reading "Decentralized apps" and "Smart contracts/programs" in the homepage doesn't help, I'd remove it. Totally fair point. I think the main thing is that when we created the website there was a lot less "blockchain fatigue" than there is no, so the next redesign will definitely emphasize more of the pragmatism and less of the blockchain magic.