Lightning devs must ‘wake up’ and fix security bugs, not please VCs: Bitcoin dev

1 year ago

Antoine Riard, who near the Lightning Network successful October, argues the Lightning Network is besides astatine hazard of becoming progressively centralized and susceptible to azygous points of nonaccomplishment and censorship risks.

61 Total views

1 Total shares

 Bitcoin dev

Developers moving connected the Bitcoin furniture 2 Lightning Network person go little security-oriented and much focused connected producing currency travel for their investors, argues a erstwhile Lightning Network developer.

Bitcoin halfway developer and information researcher Antoine Riard, made headlines past month after leaving the Lightning ecosystem over concerns astir a caller onslaught vector called “replacement cycling,” which exploiters could perchance usage to bargain funds by targeting outgo channels.

How does a lightning replacement cycling onslaught work?

There's a batch of treatment astir this recently discovered vulnerability connected the mailing lists, but the existent mechanics is simply a spot hard to follow.

So here's an illustrated primer...

1/n pic.twitter.com/mvvS8bEc5f

— mononaut (@mononautical) October 21, 2023

At the time, Riard said the caller people of attacks puts Lighting successful a "perilous position" though immoderate observers argued that 

Riard told Cointelegraph that he’s present moving astatine the Bitcoin basal furniture to code the contented and urged Lightning developers to travel suit:

“[They request to] aftermath up, halt the sleepwalking and spell to the whiteboard to plan a robust and sustainable hole successful manus with different developers astatine the base-layer, preserving the semipermanent decentralization and openness of Lightning.”

Riard besides claimed that galore Lightning-focused firms are compromising Lightning’s ngo and information incentives for the involvement of pleasing task capitalists:

“The bittersweet information being astir of them are moving for VC-funded entities, oregon commercialized entities with the aforesaid low-time preference, astatine the semipermanent detriment of end-users.”

Riard said it’s a classical illustration of the “tragedy of the commons” — wherever individuals and entities with entree to a nationalist assets enactment successful their ain involvement and deplete it.

Decentralization appears to beryllium a trade-off that these VC-funded Lightning firms are consenting to make, which is simply a large interest to Riard.

“Centralized systems are large successful the standard of efficiency, nevertheless they travel with the downside of systemic single-point-of-failure and little outgo of idiosyncratic censorship, cardinal risks that 1 mightiness privation to hedge against arsenic a Bitcoiner.”

“I'm not definite this is an absorbing Lightning future,” Riard said. In fact, it is thing which helium wants nary portion of, aft departing from the Lightning ecosystem connected Oct. 20:

“I bash not privation to beryllium associated with being successful complaint oregon accountable of the Lightning Network security, and the ~5,300 BTC exposed here. There is small [I and others] tin bash to halt the haemorrhage, without compromising the halfway values of censorship-resistance and permissionless of the Lightning Network.”

Lightning is the champion solution presently available, but it's not bully enough.

Lightning has respective cardinal flaws, wherever each of them marque the strategy arsenic a full a dormant extremity for bitcoin, agelong term. An effort astatine explaining these, and what we should bash instead.

Liquidity…

— torkel (@torkelrogstad) November 20, 2023

Related: Bitcoin Lightning Network maturation jumps 1,200% successful 2 years

The Lightning Network is the second-layer solution built implicit the Bitcoin blockchain. It is designed to amended the scalability and ratio of Bitcoin

Through the Lightning Network, users tin unfastened outgo channels, behaviour aggregate transactions off-chain, and settee the last effect connected the Bitcoin blockchain. The replacement cycling onslaught is simply a caller benignant of onslaught that allows the attacker to bargain funds from a transmission subordinate by exploiting inconsistencies betwixt idiosyncratic mempools.

Cointelegraph reached retired to Lightning Labs and different firms successful the Lighting ecosystem but did not person a response.

Don't get maine incorrect here: Lightning is great! Always inactive amazed erstwhile utilizing it.
The constituent is that it can't standard enough. And Ark is not a rival but much of an add-on. Gives you each the advantages of Cashu but without requiring trust.

All we request is covenants. Ideally, CAT https://t.co/nhrmvqPYf0

— яobin linus (@robin_linus) November 19, 2023

However, contempt the information concerns and imaginable determination toward centralization, Riard explained that Lightning hasn’t seen arsenic galore attacks arsenic galore Ethereum furniture 2s due to the fact that Lightning users typically lone store a tiny magnitude of funds successful their wallets astatine immoderate fixed time.

A full of $194.1 cardinal successful BTC is locked successful the Lightning Network, according to DeFiLlama.

Magazine: Should you ‘orange pill’ children? The lawsuit for Bitcoin kids books

View source