<oembed><type>rich</type><version>1.0</version><author_name>npub1e46n428mcyfwznl7nlsf6d3s7rhlwm9x3cmkuqzt3emmdpadmkaqqjxmcu</author_name><author_url>https://nostr.ae/npub1e46n428mcyfwznl7nlsf6d3s7rhlwm9x3cmkuqzt3emmdpadmkaqqjxmcu</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-08-21&#xA;📝 Original message:BIP Editor: Can I get a BIP # for this?&#xA;&#xA;On 08/21/15 17:55, Matt Corallo via bitcoin-dev wrote:&#xA;&gt; Revised copy follows. re: mentioning the HTTP seeding stuff, I&#39;m not&#xA;&gt; sure we want to encourage more people aside from bitcoinj to use&#xA;&gt; that...I thought about adding a DNS seed section to this bip, but&#xA;&gt; decided against it...still, I think we should add the option to select&#xA;&gt; service bits to DNS seeds ASAP.&#xA;&gt; &#xA;&gt; Re: need to &#34;shard&#34; the blockchain: not sure what you&#39;re referring to&#xA;&gt; here. The bloom filter stuff requires you to download the chain&#xA;&gt; in-order, sure, but you have to do that for headers anyway, and&#xA;&gt; hopefully your total data isnt too much more than headers alone.&#xA;&gt; &#xA;&gt; Anyone have the best reference for the DoS issues?&#xA;&gt; &#xA;&gt; BIP: ?&#xA;&gt; Title: NODE_BLOOM service bit&#xA;&gt; Author: Matt Corallo &lt;bip at bluematt.me&gt;, Peter Todd &lt;pete at petertodd.org&gt;&#xA;&gt; Type: Standards Track (draft)&#xA;&gt; Created: 20-08-2015&#xA;&gt; &#xA;&gt; Abstract&#xA;&gt; ========&#xA;&gt; &#xA;&gt; This BIP extends BIP 37, Connection Bloom filtering, by defining a&#xA;&gt; service bit to allow peers to advertise that they support bloom filters&#xA;&gt; explicitly. It also bumps the protocol version to allow peers to&#xA;&gt; identify old nodes which allow bloom filtering of the connection despite&#xA;&gt; lacking the new service bit.&#xA;&gt; &#xA;&gt; &#xA;&gt; Motivation&#xA;&gt; ==========&#xA;&gt; &#xA;&gt; BIP 37 did not specify a service bit for the bloom filter service, thus&#xA;&gt; implicitly assuming that all nodes that serve peers data support it.&#xA;&gt; However, the connection filtering algorithm proposed in BIP 37, and&#xA;&gt; implemented in several clients today, has been shown to provide little&#xA;&gt; to no privacy[1], as well as being a large DoS risk on some nodes[2].&#xA;&gt; Thus, allowing node operators to disable connection bloom filtering is a&#xA;&gt; much-needed feature.&#xA;&gt; &#xA;&gt; &#xA;&gt; Specification&#xA;&gt; =============&#xA;&gt; &#xA;&gt; The following protocol bit is added:&#xA;&gt; &#xA;&gt;     NODE_BLOOM = (1 &lt;&lt; 2)&#xA;&gt; &#xA;&gt; Nodes which support bloom filters should set that protocol bit.&#xA;&gt; Otherwise it should remain unset. In addition the protocol version is&#xA;&gt; increased from 70002 to 70011 in the reference implementation. It is&#xA;&gt; often the case that nodes which have a protocol version smaller than&#xA;&gt; 70011, but larger than 70000 support bloom filtered connections without&#xA;&gt; the NODE_BLOOM bit set, however clients which require bloom filtered&#xA;&gt; connections should avoid making this assumption.&#xA;&gt; &#xA;&gt; NODE_BLOOM is distinct from NODE_NETWORK, and it is legal to advertise&#xA;&gt; NODE_BLOOM but not NODE_NETWORK (eg for nodes running in pruned mode&#xA;&gt; which, nonetheless, provide filtered access to the data which they do have).&#xA;&gt; &#xA;&gt; If a node does not support bloom filters but receives a &#34;filterload&#34;,&#xA;&gt; &#34;filteradd&#34;, or &#34;filterclear&#34; message from a peer the node should&#xA;&gt; disconnect that peer immediately. For backwards compatibility, in&#xA;&gt; initial implementations, nodes may choose to only disconnect nodes which&#xA;&gt; have the new protocol version set and attempt to send a filter command.&#xA;&gt; &#xA;&gt; While outside the scope of this BIP it is suggested that DNS seeds and&#xA;&gt; other peer discovery mechanisms support the ability to specify the&#xA;&gt; services required; current implementations simply check only that&#xA;&gt; NODE_NETWORK is set.&#xA;&gt; &#xA;&gt; &#xA;&gt; Design rational&#xA;&gt; ===============&#xA;&gt; &#xA;&gt; A service bit was chosen as applying a bloom filter is a service.&#xA;&gt; &#xA;&gt; The increase in protocol version is for backwards compatibility. In&#xA;&gt; initial implementations, old nodes which are not yet aware of NODE_BLOOM&#xA;&gt; and use a protocol version &lt; 70011 may still send filter* messages to a&#xA;&gt; node without NODE_BLOOM. This feature may be removed after there are&#xA;&gt; sufficient NODE_BLOOM nodes available and SPV clients have upgraded,&#xA;&gt; allowing node operators to fully close the bloom-related DoS vectors.&#xA;&gt; &#xA;&gt; &#xA;&gt; Reference Implementation&#xA;&gt; ========================&#xA;&gt; &#xA;&gt; https://github.com/bitcoin/bitcoin/pull/6579&#xA;&gt; &#xA;&gt; &#xA;&gt; Copyright&#xA;&gt; =========&#xA;&gt; &#xA;&gt; This document is placed in the public domain.&#xA;&gt; &#xA;&gt; &#xA;&gt; References&#xA;&gt; ==========&#xA;&gt; &#xA;&gt; [1] http://eprint.iacr.org/2014/763&#xA;&gt; [2] ???? is one example where the issues were found, though others&#xA;&gt; independently discovered issues as well. Sample DoS exploit code&#xA;&gt; available at https://github.com/petertodd/bloom-io-attack.&#xA;&gt; &#xA;&gt; &#xA;&gt; &#xA;&gt; On 08/21/15 05:42, Peter Todd wrote:&#xA;&gt;&gt; On Thu, Aug 20, 2015 at 10:38:19PM -0700, Peter Todd via bitcoin-dev wrote:&#xA;&gt;&gt;&gt;&gt; Motivation&#xA;&gt;&gt;&gt;&gt; ==========&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt; BIP 37 did not specify a service bit for the bloom filter service, thus&#xA;&gt;&gt;&gt;&gt; implicitly assuming that all nodes that serve peers data support it.&#xA;&gt;&gt;&gt;&gt; However, the connection filtering algorithm proposed in BIP 37, and&#xA;&gt;&gt;&gt;&gt; implemented in several clients today, has been shown to provide little&#xA;&gt;&gt;&gt;&gt; to no privacy, as well as being a large DoS risk on some nodes. Thus,&#xA;&gt;&gt;&gt;&gt; allowing node operators to disable connection bloom filtering is a&#xA;&gt;&gt;&gt;&gt; much-needed feature.&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt; I&#39;d reference that paper on bloom filters re: the &#34;little to no privacy&#34;&#xA;&gt;&gt;&gt; issue. There&#39;s also a post in the bitcoinj mailing list somewhere IIRC&#xA;&gt;&gt;&gt; talking about the default settings, and how they don&#39;t provide any&#xA;&gt;&gt;&gt; privacy.&#xA;&gt;&gt;&#xA;&gt;&gt; Oh, and we should also point out that Bloom filters have scaling issues,&#xA;&gt;&gt; as each application of the filter has to scan the whole blockchain -&#xA;&gt;&gt; with future blocksize increases these issues increase, in some proposals&#xA;&gt;&gt; quite dramatically. The underlying idea also conflicts with some&#xA;&gt;&gt; proposals to &#34;shard&#34; the blockchain, again suggesting that we need a bit&#xA;&gt;&gt; to handle future upgrades to more scalable designs.&#xA;&gt;&gt;&#xA;&gt; _______________________________________________&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#xA;&gt;</html></oembed>