<oembed><type>rich</type><version>1.0</version><author_name>npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_name><author_url>https://nostr.ae/npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-08-21&#xA;📝 Original message:On Fri, Aug 21, 2015 at 05:55:58PM +0000, Matt Corallo wrote:&#xA;&gt; Revised copy follows. re: mentioning the HTTP seeding stuff, I&#39;m not&#xA;&gt; sure we want to encourage more people aside from bitcoinj to use&#xA;&gt; that...I thought about adding a DNS seed section to this bip, but&#xA;&gt; decided against it...still, I think we should add the option to select&#xA;&gt; service bits to DNS seeds ASAP.&#xA;&#xA;Well, in general relying on seeds every time you start your node is a&#xA;really bad idea; doing so much be carefully weighed against the&#xA;downsides and should be used only as a last resort. Nodes should be&#xA;doing caching and proper gossip protocol participation whenever&#xA;possible. (note how bitcoinj nodes *do* rely on centralized servers,&#xA;implemented with an unauthenticated, unencrypted, protocol - the worst&#xA;of all possible solutions with many possible MITM vectors and privacy&#xA;security holes)&#xA;&#xA;To that end, I&#39;d be inclined to leave the DNS seed protocol as it is and&#xA;let others solve the centralized server use-case, for which Cartographer&#xA;isn&#39;t all that bad of a load balancing mechanism. Also as gmaxwell noted&#xA;on IRC, adding flag bits does have privacy implications.&#xA;&#xA;&gt; Re: need to &#34;shard&#34; the blockchain: not sure what you&#39;re referring to&#xA;&gt; here. The bloom filter stuff requires you to download the chain&#xA;&gt; in-order, sure, but you have to do that for headers anyway, and&#xA;&gt; hopefully your total data isnt too much more than headers alone.&#xA;&#xA;Any protocol change that would split blocks themselves into multiples.&#xA;Not an easy problem to solve, but given the inherent O(n^2) scaling of&#xA;global consensus blockchains, it&#39;s the only kind of solution that could&#xA;in the future make the blockchain itself have reasonable scalability.&#xA;&#xA;&gt; Anyone have the best reference for the DoS issues?&#xA;&#xA;Well actually, we can reference the DoS attacks that Bitcoin XT nodes&#xA;are undergoing right now - part of the attack is repeated Bloom filter&#xA;requests to soak up disk IO bandwidth. I&#39;ve CC&#39;d Gavin and Mike - as far&#xA;as I know they haven&#39;t published details of those attacks - a write-up&#xA;would be very helpful.&#xA;&#xA;While so far those are being directed only at XT nodes, obviously this&#xA;is a potential issue for Core nodes as well. Like I mentioned last time&#xA;around, it&#39;s critical that miners aren&#39;t affected by these attacks -&#xA;nodes simply serving SPV wallet clients are much less latency sensitive,&#xA;so a good DoS attack mitigation strategy would be to have the two&#xA;classes of nodes out there &#34;in the wild&#34;&#xA;&#xA;&gt; BIP: ?&#xA;&gt; Title: NODE_BLOOM service bit&#xA;&gt; Author: Matt Corallo &lt;bip at bluematt.me&gt;, Peter Todd &lt;pete at petertodd.org&gt;&#xA;&gt; Type: Standards Track (draft)&#xA;&gt; Created: 20-08-2015&#xA;&gt; &#xA;&gt; Abstract&#xA;&gt; ========&#xA;&gt; &#xA;&gt; This BIP extends BIP 37, Connection Bloom filtering, by defining a&#xA;&gt; service bit to allow peers to advertise that they support bloom filters&#xA;&gt; explicitly. It also bumps the protocol version to allow peers to&#xA;&gt; identify old nodes which allow bloom filtering of the connection despite&#xA;&gt; lacking the new service bit.&#xA;&gt; &#xA;&gt; &#xA;&gt; Motivation&#xA;&gt; ==========&#xA;&gt; &#xA;&gt; BIP 37 did not specify a service bit for the bloom filter service, thus&#xA;&gt; implicitly assuming that all nodes that serve peers data support it.&#xA;&gt; However, the connection filtering algorithm proposed in BIP 37, and&#xA;&gt; implemented in several clients today, has been shown to provide little&#xA;&gt; to no privacy[1], as well as being a large DoS risk on some nodes[2].&#xA;&gt; Thus, allowing node operators to disable connection bloom filtering is a&#xA;&gt; much-needed feature.&#xA;&gt; &#xA;&gt; &#xA;&gt; Specification&#xA;&gt; =============&#xA;&gt; &#xA;&gt; The following protocol bit is added:&#xA;&gt; &#xA;&gt;     NODE_BLOOM = (1 &lt;&lt; 2)&#xA;&gt; &#xA;&gt; Nodes which support bloom filters should set that protocol bit.&#xA;&gt; Otherwise it should remain unset. In addition the protocol version is&#xA;&gt; increased from 70002 to 70011 in the reference implementation. It is&#xA;&gt; often the case that nodes which have a protocol version smaller than&#xA;&gt; 70011, but larger than 70000 support bloom filtered connections without&#xA;&gt; the NODE_BLOOM bit set, however clients which require bloom filtered&#xA;&gt; connections should avoid making this assumption.&#xA;&gt; &#xA;&gt; NODE_BLOOM is distinct from NODE_NETWORK, and it is legal to advertise&#xA;&gt; NODE_BLOOM but not NODE_NETWORK (eg for nodes running in pruned mode&#xA;&gt; which, nonetheless, provide filtered access to the data which they do have).&#xA;&gt; &#xA;&gt; If a node does not support bloom filters but receives a &#34;filterload&#34;,&#xA;&gt; &#34;filteradd&#34;, or &#34;filterclear&#34; message from a peer the node should&#xA;&gt; disconnect that peer immediately. For backwards compatibility, in&#xA;&gt; initial implementations, nodes may choose to only disconnect nodes which&#xA;&gt; have the new protocol version set and attempt to send a filter command.&#xA;&gt; &#xA;&gt; While outside the scope of this BIP it is suggested that DNS seeds and&#xA;&gt; other peer discovery mechanisms support the ability to specify the&#xA;&gt; services required; current implementations simply check only that&#xA;&gt; NODE_NETWORK is set.&#xA;&gt; &#xA;&gt; &#xA;&gt; Design rational&#xA;&gt; ===============&#xA;&gt; &#xA;&gt; A service bit was chosen as applying a bloom filter is a service.&#xA;&gt; &#xA;&gt; The increase in protocol version is for backwards compatibility. In&#xA;&gt; initial implementations, old nodes which are not yet aware of NODE_BLOOM&#xA;&gt; and use a protocol version &lt; 70011 may still send filter* messages to a&#xA;&gt; node without NODE_BLOOM. This feature may be removed after there are&#xA;&gt; sufficient NODE_BLOOM nodes available and SPV clients have upgraded,&#xA;&gt; allowing node operators to fully close the bloom-related DoS vectors.&#xA;&gt; &#xA;&gt; &#xA;&gt; Reference Implementation&#xA;&gt; ========================&#xA;&gt; &#xA;&gt; https://github.com/bitcoin/bitcoin/pull/6579&#xA;&gt; &#xA;&gt; &#xA;&gt; Copyright&#xA;&gt; =========&#xA;&gt; &#xA;&gt; This document is placed in the public domain.&#xA;&gt; &#xA;&gt; &#xA;&gt; References&#xA;&gt; ==========&#xA;&gt; &#xA;&gt; [1] http://eprint.iacr.org/2014/763&#xA;&gt; [2] ???? is one example where the issues were found, though others&#xA;&gt; independently discovered issues as well. Sample DoS exploit code&#xA;&gt; available at https://github.com/petertodd/bloom-io-attack.&#xA;&#xA;-- &#xA;&#39;peter&#39;[:-1]@petertodd.org&#xA;00000000000000000402fe6fb9ad613c93e12bddfc6ec02a2bd92f002050594d&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: signature.asc&#xA;Type: application/pgp-signature&#xA;Size: 650 bytes&#xA;Desc: Digital signature&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150821/206f9582/attachment.sig&gt;</html></oembed>