4 ms·
Also, Electrum wallet and friends don't do proof of work validation, they merely check which is the longest chain.
by sysk 11y ago
Also, Electrum wallet and friends don't do proof of work validation, they merely check which is the longest chain.
- Buge 11y agoWhat do you mean by "don't do proof of work validation". They don't verify the has in the header is the hash of the previous block's header? They don't that the hash is sufficiently small? They don't calculate the difficulty correctly?
- sysk 11y ago> They don't calculate the difficulty correctly? Yes. It's possible to create a long chain at low difficulty and the original bitcoin client protects against that by computing the total "work" that has gone in a chain. However, Electrum just assumes that the longest chain will be the one which has most "work" in it which is wrong.
- zaroth 11y agoThat would be a pretty lame bug! It's the difference between "chainLength++;" and "chainLength+=pow;"
- wcoenen 11y agoI don't think so. These wallets implement Simplified Payment Verification as described by Satoshi in section 8 of the original bitcoin paper[1]. They do validate the block headers, which contain the proof of work. [1] https://bitcoin.org/bitcoin.pdf https://bitcoin.org/bitcoin.pdf
- sysk 11y agoThe issue is not with SPV itself but with Electrum's implementation (by "and friends" I really meant Electrum forks, not all SPV clients). Electrum does validate block headers but it doesn't handle re-orgs correctly. It just assumes the longest chain has the most PoW in it which is wrong and makes it vulnerable to attacks by malicious Electrum servers. Block headers do not contain the cumulative work that has gone into the chain (only the difficulty of the current block). A chain's total work must be calculated and stored locally by clients. https://github.com/spesmilo/electrum/blob/master/lib/blockchain.py#L56 https://github.com/spesmilo/electrum/blob/master/lib/blockch...
- lappa 11y agoSurely they verify the PoW, otherwise it would be trivial to create a long chain and attack them.
- sysk 11y agoIndeed. I was also surprised to find this out given how popular Electrum is. The code is here: https://github.com/spesmilo/electrum/blob/master/lib/blockchain.py#L56 https://github.com/spesmilo/electrum/blob/master/lib/blockch... and https://github.com/spesmilo/electrum/blob/master/lib/blockchain.py#L88 https://github.com/spesmilo/electrum/blob/master/lib/blockch... One could run a modified Electrum server that sends a long chain at low difficulty and double spend Electrum users.
- Pr0methean 11y agoI read that generating that chain would be really cheap and simple too -- you just run a non-pool miner disconnected from the Internet and with an accelerated clock.