<oembed><type>rich</type><version>1.0</version><author_name>npub1vjzmc45k8dgujppapp2ue20h3l9apnsntgv4c0ukncvv549q64gsz4x8dd</author_name><author_url>https://nostr.ae/npub1vjzmc45k8dgujppapp2ue20h3l9apnsntgv4c0ukncvv549q64gsz4x8dd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2021-04-23&#xA;📝 Original message:&#xA;Hi,&#xA;&#xA;During the lastest years, tx-relay and mempool acceptances rules of the&#xA;base layer have been sources of major security and operational concerns for&#xA;Lightning and other Bitcoin second-layers [0]. I think those areas require&#xA;significant improvements to ease design and deployment of higher Bitcoin&#xA;layers and I believe this opinion is shared among the L2 dev community. In&#xA;order to make advancements, it has been discussed a few times in the last&#xA;months to organize in-person workshops to discuss those issues with the&#xA;presence of both L1/L2 devs to make exchange fruitful.&#xA;&#xA;Unfortunately, I don&#39;t think we&#39;ll be able to organize such in-person&#xA;workshops this year (because you know travel is hard those days...) As a&#xA;substitution, I&#39;m proposing a series of one or more irc meetings. That&#xA;said, this substitution has the happy benefit to gather far more folks&#xA;interested by those issues that you can fit in a room.&#xA;&#xA;# Scope&#xA;&#xA;I would like to propose the following 4 items as topics of discussion.&#xA;&#xA;1) Package relay design or another generic L2 fee-bumping primitive like&#xA;sponsorship [0]. IMHO, this primitive should at least solve mempools spikes&#xA;making obsolete propagation of transactions with pre-signed feerate, solve&#xA;pinning attacks compromising Lightning/multi-party contract protocol&#xA;safety, offer an usable and stable API to L2 software stack, stay&#xA;compatible with miner and full-node operators incentives and obviously&#xA;minimize CPU/memory DoS vectors.&#xA;&#xA;2) Deprecation of opt-in RBF toward full-rbf. Opt-in RBF makes it trivial&#xA;for an attacker to partition network mempools in divergent subsets and from&#xA;then launch advanced security or privacy attacks against a Lightning node.&#xA;Note, it might also be a concern for bandwidth bleeding attacks against L1&#xA;nodes.&#xA;&#xA;3) Guidelines about coordinated cross-layers security disclosures.&#xA;Mitigating a security issue around tx-relay or the mempool in Core might&#xA;have harmful implications for downstream projects. Ideally, L2 projects&#xA;maintainers should be ready to upgrade their protocols in emergency in&#xA;coordination with base layers developers.&#xA;&#xA;4) Guidelines about L2 protocols onchain security design. Currently&#xA;deployed like Lightning are making a bunch of assumptions on tx-relay and&#xA;mempool acceptances rules. Those rules are non-normative, non-reliable and&#xA;lack documentation. Further, they&#39;re devoid of tooling to enforce them at&#xA;runtime [2]. IMHO, it could be preferable to identify a subset of them on&#xA;which second-layers protocols can do assumptions without encroaching too&#xA;much on nodes&#39;s policy realm or making the base layer development in those&#xA;areas too cumbersome.&#xA;&#xA;I&#39;m aware that some folks are interested in other topics such as extension&#xA;of Core&#39;s mempools package limits or better pricing of RBF replacement. So&#xA;l propose a 2-week concertation period to submit other topics related to&#xA;tx-relay or mempools improvements towards L2s before to propose a finalized&#xA;scope and agenda.&#xA;&#xA;# Goals&#xA;&#xA;1) Reaching technical consensus.&#xA;2) Reaching technical consensus, before seeking community consensus as it&#xA;likely has ecosystem-wide implications.&#xA;3) Establishing a security incident response policy which can be applied by&#xA;dev teams in the future.&#xA;4) Establishing a philosophy design and associated documentations (BIPs,&#xA;best practices, ...)&#xA;&#xA;# Timeline&#xA;&#xA;2021-04-23: Start of concertation period&#xA;2021-05-07: End of concertation period&#xA;2021-05-10: Proposition of workshop agenda and schedule&#xA;late 2021-05/2021-06: IRC meetings&#xA;&#xA;As the problem space is savagely wide, I&#39;ve started a collection of&#xA;documents to assist this workshop : https://github.com/ariard/L2-zoology&#xA;Still wip, but I&#39;ll have them in a good shape at agenda publication, with&#xA;reading suggestions and open questions to structure discussions.&#xA;Also working on transaction pinning and mempool partitions attacks&#xA;simulations.&#xA;&#xA;If L2s security/p2p/mempool is your jam, feel free to get involved :)&#xA;&#xA;Cheers,&#xA;Antoine&#xA;&#xA;[0] For e.g see optech section on transaction pinning attacks :&#xA;https://bitcoinops.org/en/topics/transaction-pinning/&#xA;[1]&#xA;https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2020-September/018168.html&#xA;[2] Lack of reference tooling make it easier to have bug slip in like&#xA;https://lists.linuxfoundation.org/pipermail/lightning-dev/2020-October/002858.html&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/lightning-dev/attachments/20210423/98e1f2cc/attachment.html&gt;</html></oembed>