3 ms·
Each Ripple server does validate all the data completely and cannot be tricked. Ripple uses consensus to establish transaction ordering. Ripple does have only
by SJoelKatz 13y ago
Each Ripple server does validate all the data completely and cannot be tricked. Ripple uses consensus to establish transaction ordering.
Ripple does have only a small number of server nodes today, but that should be growing over time. A node cannot freely set balances. Each node signs each ledger and any change to a ledger entry (such as a balance) must be accompanied by a signed transaction justifying that change or other nodes will reject it.
Nodes are in fact called "validators" and they validate each ledger to ensure that any changes are justified by transactions. They sign these ledgers every few seconds.
As for the peering needing to be centrally controlled, I assume you're referring to each node's set of validators. While that does need to be sanely managed, it doesn't need to be centrally controlled. A number of organizations can publish lists of validators they believe to be reliable. The algorithm is very tolerant of things like minimal overlap or bad apples. Every honest node wants to agree with every other honest node, and dishonesty is impossible to hide, so the problem is not that difficult.
(I'm one of the architects of the Ripple network.)
- rxl 13y agoFirst, let me quote http://ripplescam.org/ http://ripplescam.org/: But wait – you can become your own validator! [...] The consensus system ensures there is only one ledger – the most accepted one. If you run your own validator, you must connect with OpenCoin Inc servers, or you will be building a different ledger. In practice, it is not possible to “dethrone” OpenCoin Inc as you have to co-operate with OpenCoin Inc. Second, I'll point out that while minimizing the number of validators may be attractive, it also makes the currency much more vulnerable to top-down control, via governments, corporations, etc. Last, if you're reading this, I'd suggest that you read up a bit about Ripple on Bitcoin Forum before you make conclusions about the currency - there are a lot of interesting discussions about its viability (like this one: https://bitcointalk.org/index.php?topic=146964.0 https://bitcointalk.org/index.php?topic=146964.0).
- SJoelKatz 13y agoThe quote from ripplescam.org just says what we all know, we all have to agree on a blockchain (in the case of Bitcoin) or a ledger (in the case of Ripple) or the system breaks. Part of it is false though, you can connect to servers not run by us. So long as they're also trying to agree with us (or those who are trying to agree with us), it will work. Ripple uses a distributed agreement protocol to order transactions. You have to try to agree with other people who are trying to agree. The group of people trying to agree that includes us defines the dominant transaction ordering (at the moment). But this is equally true of anyone else in the group we are in. It's the group that matters. I don't see why minimizing the number of validators is attractive. We want as many as possible precisely because that ensures that administrative control can't be seized. It's just like mining in Bitcoin -- you want it distributed into the hands of as many people as possible as evenly as possible. We are working on making this happen now. Obviously, open sourcing the server was a necessary stop to broadening the validators.
- makomk 13y agoNo, it isn't in any way similar to Bitcoin's blockchain consensus - that's is designed to have blockchain disagreements which are resolved eventually by some of the nodes rolling back their blockchain and moving to the consensus one. As I understand it Ripple doesn't do that - once nodes have agreed on a ledger version they won't roll it back, and even if they did the OpenCoin Inc-controlled nodes don't care what non-OpenCoin-approved nodes think when forming their consensus. So the net result is that, since everyone - including the exchanges - trusts the OpenCoin-run nodes, the only safe thing to do is wait for OpenCoin's servers to come to a consensus amongst themselves and then accept their ledger updates in their entirety. There is no way for anyone outside of OpenCoin Inc to influence what gets included in the ledger except if you allow it.
- SJoelKatz 13y agoAll the servers are agreeing with each other. You could just as well wait for any other reliable servers to come to a consensus amongst themselves and it would work just as well. It is true that today we control the majority of validators that other important servers trust. We're working now on increasing the number of validators because that will improve the reliability and robustness of the network. We absolutely do not want people to have to trust us, or even think they have to trust us, so this is a real priority for us. Open sourcing the server was, obviously, a step in this direction.
- nullc 13y ago> (I'm one of the architects of the Ripple network.) Please see the thread linked to above. There were several trust topologies given than are obviously non-convergent in your model and you appeared to have no answer for them. Effectively you have ripple servers which must have central selection/control (or the system is not guaranteed to converge), and they can set balances to whatever they want. ... and then clients that simply believe the majority of the servers they are pointed at.
- SJoelKatz 13y agoThey can't set balances to whatever they want. They have to justify each switch from ledger to ledger with signed transactions. (Just like miners in Bitcoin can choose the transactions to include in their blocks but can't just create Bitcoins out of thin air or teleport them from one account to another.)
- mrb 13y agoThe way I see it --correct me if I am wrong-- is that Ripple has zero defenses against an attacker controlling many public IPv4 or IPv6 addresses and broadcasting his transactions to effectively control what the consensus is. IOW, attacker-controlled Ripple nodes can outnumber legitimate Ripple nodes, therefore legit Ripple nodes are forced to accept transactions broadcasted by attacker-controlled nodes.
- kylebrown 13y agoTransactions are accepted if they are signed by private keys, it doesn't matter who broadcasts them. But the reason for fees is to prevent DoS attackers overloading the consensus process with spam transactions. Also, just running a node on an IP address doesn't give you any amount of control. That IP address also has to be other validators' UNL (unique node list).
- mrb 13y agoMy point is that if an attacker controls consensus (by having many IP addresses), he can double spend by signing transactions to send coins to an address, then by spaming the network to change the consensus and re-send the same coins to another address.
- SJoelKatz 13y agoNot so for two reasons. First, the number of IP addresses you have is irrelevant. Trust is weighted by the number of signatures made with keys that a server has chosen to trust. Second, you can't "change the consensus". Once a consensus is reached on a given ledger, it's irrevocable. Every validator that witnesses the consensus signs the resulting ledger providing cryptographic proof that they agreed to that particular consensus. A transaction is not considered confirmed until the server possesses that cryptographic proof.