10 ms·
This is a concerning aspect of Ethereum's strategy to push scaling to layer-2 networks: Ethereum is a heavily audited and tested protocol that runs an extremely
by iskander 5y ago
This is a concerning aspect of Ethereum's strategy to push scaling to layer-2 networks: Ethereum is a heavily audited and tested protocol that runs an extremely decentralized network of diverse clients. L2s can be...an AWS instance running arbitrary buggy code. Much of the confidence in the "base layer" that people using Ethereum currently experience will be significantly undermined if mundane transactions wend in and out of different L2s.
- sschueller 5y agoIsn't the whole lightning network for bitcoin also L2?
- vmception 5y agohm okay, room for nuance, there are at about a dozen L2 technologies in deployment right now, each with multiple competitors using a specific technology.
- rawtxapp 5y agoIt's L2, but you can have different types of L2s. With lightning network, you're opening and closing channels with a counterparty using on-chain transactions, so each channel can be tied back to an on-chain transaction. Before someone points out that it would require tons of on-chain transactions to onboard everyone onto it, you can batch thousands of channel open/closes into a single transaction with new protocol upgrades.
- idiotsecant 5y agoThat's not even the most fundamental issue with LN though, it's not a fully thought out system. As LN node count increases the routing complexity increases exponentially, which is the classic problem of routing issues on large graphs that literally every networked system has. The internet solves this with some degree of human intervention to tip the scales to particular routes, which is something that the LN inherently can't (and shouldn't) do. There is some amount of optimization that could take place using common graph routing algorithms like OLSR or others but those represent foundational changes to the protocol which historically LN is allergic to for whatever reason and wouldn't entirely solve the problem in any case. Simply put - it can't scale to that kind of throughput for a combination of cultural and technical reasons.
- rawtxapp 5y agoMost end-users won't be acting as payment gateways, they'll all have private channels, so they won't appear in the routing graphs. The number of routing nodes would be many magnitude smaller than total number of LN users. It's working fine for now with growing adoption (1ml.com) and I believe it'll only get better with time.
- idiotsecant 5y agoSure, but in order to accommodate more users you need more routing nodes. Exponential scaling is a funny thing- systems work perfectly right up until they catastrophically fail. That's why it's important to understand these kinds of problems ahead of time, which LN is determined not to do.
- jksmith 5y ago>> which LN is determined not to do. What's the source of your opinion?
- rawtxapp 5y agoLook at it this way, if x = number of total users, routing nodes will grow O(log x), not O(c^x). The users can grow exponentially, the routing nodes won't because the marginal cost of processing an extra transaction from an end-user is very close to 0.
- jimmydorry 5y agoI thought the routing node was putting up some amount of Bitcoin per channel. Each channel would therefore have a non-zero cost (and each user requires a channel). I would need to go back and refresh my understand as it's been quite a while since I read the LN whitepaper, much less kept abreast of developments in that space.
- rawtxapp 5y agoWhen you fund a channel, the Bitcoin is still yours, you're not giving it away. With batched channel open/closes, it'll be super cheap to open and close channels. The only cost you'd pay is the opportunity cost if your counterparty isn't sending transactions, so you're not collecting routing fees. If that's the case, you can just close the channel if you need to fund another channel and don't have spare Bitcoin for it, but that's about it.
- HashBasher 5y agoExactly, CashApp/RobinHood/Coinbase/Kraken are all bitcoin L2. Centralized and trusted, but L2 nonetheless.
- stale2002 5y agoIt is yes, and even though the lightning network is considered one of the more secure/safe L2 networks, even it has had bugs (now solved) that potentially could have caused everyone to lose all their money, if those bugs had been taken advantage of.
- gillesjacobs 5y agoThat's an issue with all cryptocurrency infrastructure though: projects need to be proven to demonstrate robust value and it's probably one of the most adversarial spaces in software. History has shown that hacks and exploits of projects hurt the price of the native taken but do not really damage the long-term earned trust.
- rawtxapp 5y agoExactly this, it's a very adversarial environment with huge stakes for those that can exploit it. Even projects that have been around for months, years can get exploited which is why I'd recommend waiting a long time before putting non-trivial amounts into any smart contract or crypto related projects. That's also a big plus for Bitcoin, because it's been around the longest and because it's so much simpler than more complex chains like eth, it's as secure as it gets.
- dan-robertson 5y agoAre the stakes that huge for potential exploiters? It seems that exploits can write off a bunch of value from the exploited but, at least for big and quickly noticed exploits, it is hard to launder the gains into the ‘legitimate’ part of the ecosystem with big exchanges and suchlike.
- rawtxapp 5y agoI think last year alone had more than a billion dollars worth of crypto hacked on defi, there's some trackers out there [1]. On one hand, you have amateurs that leave their private keys on cloud services and try to cash out while living in a place like NYC, on the other hand, you have people who know what they are doing or perhaps live in places that actively encourage those activities [2]. 1: https://cryptosec.info/defi-hacks/ https://cryptosec.info/defi-hacks/ 2: https://www.bbc.com/news/business-59990477 https://www.bbc.com/news/business-59990477
- jkhdigital 5y ago> That's also a big plus for Bitcoin, because it's been around the longest and because it's so much simpler than more complex chains I’ve always understood this on a basic level, but reading an entire exploit debrief with intricate technical details really hammered this point home for me.
- soco 5y agoCorrect me if I'm wrong, but with those L2 tricks the plusvalue of Ethereum gets kinda diluted... and there's already a heavy discussion on the "why should I use it at all".
- serverholic 5y agoYou're going to have to explain. L2 heavily rely on the Ethereum base layer.
- suikadayo 5y agoMost L2s will require users to pay transaction fees in ETH. Some will have fee abstraction where people can pay with tokens, but the rollup themselves will still end up paying ETH on L1. Ethereum will essentially be a settlement layer for rollups, and everyone will be doing their DeFi, NFTs, etc on the rollups which are almost treated like their own chains.
- k__ 5y agoTheir proof ends up on L1 and they get cheaper the more people use them.
- serverholic 5y agoEthereum didn't start that way, it had to build trust over time just like any other project. Eventually L2s will get there too.
- SubiculumCode 5y agoSame with Polygon their Ethereum L2+Sidechaining scaling solutions. Polygon is quickly building a reputation for solid secure code, mostly because their team kicks ass and is proactive.
- jeffalbertson 5y agoI mean they just disclosed a 1.6mil hack 40days ago. I like polygon and unfortunately feel like hacks/stolen funds are part of the maturing process for blockchain projects but im not yet ready to say they are building a reputation for solid secure code.
- 8note 5y agoI think it's worth noting that that was an exploit as opposed to a hack or a scam. In this case, the code securely gave the money to people in a way the owners didn't expect
- deleted 5y ago[deleted]
- SilasX 5y agoYes! I got burned by Optimism in another way. They tell you to point your applications at etherscan.io for transaction data/history, but then, on November 11 last year, the pushed an update that deletes all transaction history up to that point, which you need for taxes! They swore they'd have the history restored on Etherscan by Nov 18th, but they still haven't. Only recently they pushed a workaround that lets you download the transactions as a CSV, but that lacks the critical data from your transfers of non-ETH tokens. And then, an alternative source does have that data, but only as a binary blob you have to run through a decoder and parse out yourself. The crypto tax software, of course, doesn't know what to do with it. (Even if your local client cached the transactions, most, like MetaMask, left out the critical data above.) 68 days till the filing deadline in the US! I asked the maintainers how they planned to do their own taxes, and one of them claimed that he was separately recording all sales in a spreadsheet. I had to inform them that the taxable events include more than just sales, and, even under the most aggressive interpretation of tax law, you need the other data to figure cost basis.
- leppr 5y agoIf the history is completely gone, your government won't be able to find it either, so you can just fill in whatever you want to explain how balance A became balance B.
- AlexCoventry 5y agoOf course it's not completely gone. Chain analysis companies, which tax authorities consult, will have backup copies.
- 3np 5y agoLet this be a lesson: Maintain local self-hosted copies of any necessary data, don’t rely on third-parties maintaining it and keeping it available. Should be standard practice for anyone doing anything serious with cryptocurrencies but unfortunately users seem complacent enough that easily accessible tooling is still lacking in many places and you may have to DIY scripts for some parts. Your situation is unfortunate but it sounds like no fault on Optimism or Etherscan here. (BTW just to be clear: you’re talking about off-chain data that was never part of on-chain txes, and this binary blob comes from some Optimism operator? If it’s on-chain data its just a matter of doing the right queries)
- DennisP 5y agoWith zkrollups, you get an on-chain proof that the off-chain infrastructure did everything correctly. A contract can even verify that proof before updating the data on chain.
- teempai 5y agoEthereum actually has almost no client diversity. The vast majority of nodes run the geth client (go). Regarding the security aspects of L2s: they will of course not be anywhere near as robust as ethereum itself, but over time they’ll get better. However, they also don’t need to be as robust as ethereum given they effectively benchmark against the ethereum chain so while things could go wrong, the amount of damage will be very contained and as the ethereum mainchain scales the damage radius becomes ever more contained. Finally the bridges that are being implemented to move assets from ethereum to the L2s can implement emergency withdrawal mechanisms which allow users to get their assets out even if things go wrong. Not perfect, but the tradeoff seems reasonable to me given the performance enhancement and the diversity of functionality that can be offered via many different environments. Disclaimer: I’m quite possibly biased due to my company working on L2s.
- sophrocyne 5y agoFor those interested in data supporting diversity comment (~82% geth) - https://www.ethernodes.org/ https://www.ethernodes.org/ Re: GP comment - From a "trust" perspective, there is a distinct difference to call out between the integrity of data on the platform, and the trustworthiness of the platform itself (i.e., the ability for centralized control of all data) In an instance where an L2 is compromised, the potential impact is limited to the integrity of data that individual L2 was contributing to the overall platform. Those transactions which demand absolute integrity will naturally tend to occur on L1, for this reason. Risk mitigation strategies will develop for those operating on L2 + bridged chains.
- jrochkind1 5y agoWhat kinds of transactions do not demand absolute integrity, but still make sense to use a blockchain for? (I don't know much about these sorts of things, I'm actually asking for examples)
- mattdesl 5y agoSecurity of zk rollups may be sufficient for a lot of activity - trading, DeFi, games, art, DAO/access tokens, escrow, crowdfunds, all the web3 stuff. The L1 may eventually be a primary settlement layer for protocols like zkSync and StarkNet (and any other protocols and rollups built on Ethereum L1). At some point it may not be common for users to interact with L1—ie. users of Argent and Sequence wallets may only be holding assets on L2. zkSTARK/SNARKs has pretty dramatically changed the L2 landscape and new direction seems to be moving away from optimistic rollups like in the OP. This is just my understanding, somebody please correct me if I’m wrong.
- baxtr 5y agoSide note: that’s the first flame war free / nuanced thread on crypto that I have seen on HN so far. Thanks for starting it!
- kristofferR 5y agoThe discussion here used to be way more thoughtful, it's only been bad the last year or so. I think the degradation of crypto discourse here was mostly a knee-jerk reaction to NFTs. "NFTs are stupid, so all crypto is stupid, because NFTs are crypto" - that was likely the thought process behind all the toxicity seen here.
- rawtxapp 5y agoI would disagree, in my experience HN has been pretty anti-crypto for a long time, starting with Bitcoin's announcement thread [1]. Personally, I think people are just tired, as a proponent I'm tired of arguing the same stuff over and over again, I can imagine the other side of that too. At this point, time will decide who's right and wrong, I think that what anyone of us thinks doesn't really matter in the grand scheme of things. 1: https://news.ycombinator.com/item?id=599852 https://news.ycombinator.com/item?id=599852
- simias 5y agoYeah I'm an opponent and I feel the same. The talking points have been exhausted half a decade ago. On top of that as cryptocurrencies get more and more mainstream we have to deal with less sophisticated people who make it very hard to have a decent discussion in the first place, because you basically have to start by taking 20 minutes to explain to them what the basics even are. NFTs are really pushing this situation to the extreme. Between the NFT enthusiast who seem to think the technology is literal magic who can do anything you want it to and "haters" who will say stuff like "NFTs are just URLs of JPEG" which is absurd oversimplification and completely misses the point. That being said I would argue that the fact that the discussion is not advancing and that we're left with "monkey jpegs" is to be blamed entirely on the cryptopeople who clearly fail entirely to deliver anything new. The killer "crypto app" has been a couple of years away since 2015 at least. The tech keeps getting more complicated as an attempt to address the fundamentals shortcomings of the blockchain, but it still fails entirely at being anything more than a vehicle for wild speculation. The fundamental reality is that basically nobody would be using any of this if they didn't think it was going to make them rich. That was true five years ago, it's true now and I think it's going to remain true for the foreseeable future.
- HashBasher 5y ago> extremely decentralized network Can you provide source for this claim? I thought that infura was the dominant infrastructure provider for eth and if it gets taken down, a majority of the apps goes down too.
- nootropicat 5y agoInfura already went down several times and nothing happened. Metamask users can easily switch to other rpc providers (including their own nodes).
- iskander 5y agoInfura is a single RPC endpoint, the underlying network it talks with has 5k-6k clients: https://www.ethernodes.org/?synced=1 https://www.ethernodes.org/?synced=1 You can choose one of ~20 different free RPC endpoints: https://ethereumnodes.com/ https://ethereumnodes.com/ This doesn't include private or paid RPCs or just running your own.
- rvz 5y agoWell on the same site ethernodes.org, the majority of Ethereum nodes are running on AWS at 45% [0]. Due to this announcement from AWS [1], it is going to become even more centralized. So the claim of 'extremely decentralized network' is somewhat of a myth and a falsehood. [0] https://ethernodes.org/networkType/Hosting https://ethernodes.org/networkType/Hosting [1] https://aws.amazon.com/about-aws/whats-new/2021/03/announcing-general-availability-of-ethereum-on-amazon-managed-blockchain/ https://aws.amazon.com/about-aws/whats-new/2021/03/announcin...
- mattdesl 5y agoCorrection: according to your link, only 28% of Eth nodes are running on AWS (1579 of 5632 - click "Network Types"). However, many of these are not mining nodes that secure the network (and therefore security of the blockchain), but instead are nodes run by dApp/web3 developers to handle things like indexing NFTs and the current state inside a smart contract.[1] It is easy to spin up a geth node for a task like this—and by default mining is not enabled. I haven't seen any stats on the total number of mining nodes and their network types. I agree that too much of the traffic is going through AWS, and I suspect all of these stats will need to be re-examined after the PoS Merge. [1] https://www.reddit.com/r/ethereum/comments/ksdu11/how_can_ethereum_give_us_decentralized_internet/gifvhem/?utm_source=reddit&utm_medium=web2x&context=3 https://www.reddit.com/r/ethereum/comments/ksdu11/how_can_et...
- lhl 5y agoFor those interested in the specific risks of various L2s as they stand, L2Beat has the best overview: https://l2beat.com/?view=risk https://l2beat.com/?view=risk While the various L2s are all pretty bleeding edge, the current state/alternative [1] is that a majority of the TVL is being bridged to alternate L1s, where the bridges are also extreme weaknesses [2]. There was the recent $320M Wormhole hack [3], the last record white-hat payout ($2M bounty on $850M at risk with the Polygon Bridge) [4][5], and $2.2B sits on Avalanche's Bridge [6] which is an EOA that is secured by literally 4 SGX machines. [7] [1] https://defillama.com/chains https://defillama.com/chains [2] https://old.reddit.com/r/ethereum/comments/rwojtk/ama_we_are_the_efs_research_team_pt_7_07_january/hrngyk8/ https://old.reddit.com/r/ethereum/comments/rwojtk/ama_we_are... [3] https://wormholecrypto.medium.com/wormhole-incident-report-02-02-22-ad9b8f21eec6 https://wormholecrypto.medium.com/wormhole-incident-report-0... [4] https://medium.com/immunefi/polygon-double-spend-bug-fix-postmortem-2m-bounty-5a1db09db7f1 https://medium.com/immunefi/polygon-double-spend-bug-fix-pos... [5] https://gerhard-wagner.medium.com/double-spending-bug-in-polygons-plasma-bridge-2e0954ccadf1 https://gerhard-wagner.medium.com/double-spending-bug-in-pol... [6] https://app.uniwhales.io/avalanche/bridge-tracker https://app.uniwhales.io/avalanche/bridge-tracker [7] https://medium.com/avalancheavax/avalanche-bridge-secure-cross-chain-asset-transfers-using-intel-sgx-b04f5a4c7ad1 https://medium.com/avalancheavax/avalanche-bridge-secure-cro...