Ethereum 2.0 Security Audit by Least Authority Reveals Two Major Shortcomings

2020-3-26 15:47

The upcoming Ethereum 2.0 Audit report was recently released by Least Authority who had been tasked with this function. This firm looked into Ethereum’s 2.0 codebase and framework at the foundation’s request. Results from the audit highlighted that despite a good design, Ethereum 2.0 has two major shortcomings stemming from its Block proposer and P2P messaging systems.

The audit process began back in January and both entities have been working together to realize this review. According to the report by Least Authority, ETH 2.0 is infrastructure is comprehensive and well thought out. However, the firm could not be very conclusive given the limited applications of the Proof-of-Stake (PoS) consensus;

“It is one of the first Proof of Stake (PoS)/sharded protocol projects planned for production,” the report further reads, “The long-term stability of PoS blockchains is an area of active research that will need to be monitored over time as they are used in production.”

It is also noteworthy that the report found Ethereum’s P2P and ENR as underrepresented. This basically means that not enough documentation on these systems has been done as per phase 0 of Ethereum 2.0. The report goes on to suggest that the significance of these two functions makes it important to elaborate on them from the beginning.

Block Proposer Information Leak Threat

As mentioned earlier, this function poses a threat to ETH 2.0 prospective clients’ information. Ethereum’s transition from a Proof of Work (PoW) to Proof of Stake (PoS) network ultimately pushed the foundation to integrate a block proposer within its ecosystem. The main purpose of this feature is to pick the next block to go into the chain. This process, in turn, exposes the Ethereum network to possible information leaks.

The report proposes a Single Secret Leader Election (SSLE) approach in order to hide the selection mechanism;

“With the information leak patched, the block proposer remains as protected as it would be in PoW chains, but without the computational overhead,”

Ethereum’s 2.0 team agreed with this shortcoming and the proposed solution. They particularly noted that the active research in SSLE is something Ethereum 2.0 Devs are looking at in preparation for better versions of the coming phases.

Spam Messaging on Ethereum’s 2.0 P2P

Another major shortcoming is a spam problem with the scheduled Ethereum upgrade’s P2P messaging system. The report by Least Authority mentioned that lack of a central authority to check on the nodes’ activity could expose the network to dishonest participants. This means that one can spam the network with old messages at the cost of the most recent ones; they can do so without the fear of being heavily penalized. In addition, ETH 2.0 nodes can easily cause traffic on the network by sending out unlimited messages for slashing.

The security research team Least Authority recommended the integration of a BAR-resilient gossip protocol that can fully prevent malicious interactions with Ethereum 2.0. As it stands, this tech is being analyzed by Protocol Labs.

Ethereum (ETH) Live Price 1 ETH/USD =$134.9384 change ~ -0.19%

Coin Market Cap

$14.88 Billion

24 Hour Volume

$2.3 Billion

24 Hour VWAP

$136

24 Hour Change

$-0.2526 var single_widget_subscription = single_widget_subscription || []; single_widget_subscription.push("5~CCCAGG~ETH~USD");

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Well (WELL) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 WELL

authority least audit review together out realize

authority least → Результатов: 28


Спецификации эфириума 2.0 прошли аудит безопасности

Спецификации эфириума 2. 0 прошли аудит безопасности. Аудиторы берлинской компании Least Authority заключили, что спецификации хорошо разработаны и порекомендовали внести несколько незначительных изменений.

2020-3-25 16:31


UK’s FCA Seeks Blockchain, Crypto Expert With Knowledge Of 5AMLD’s Digital Assets Regulations

The major financial authority in the UK, known as the Financial Conduct Authority (FCA), wants to hire a cryptocurrency specialist. More specifically, the FCA wishes to work with someone who has crypto expertise in order to know how to address digital assets according to the EU’s 5th Anti-Money Laundering Directive (AMLD5). At least this is […]

2020-2-6 20:57


Фото:

Tether and Bitfinex Ask New York Attorney General for Fund Accessibility

Attorneys for Tether and Bitfinex are hoping to get the former access to its reserves amid a legal dispute with New York Office of the Attorney General (NYOAG). In a letter sent to the New York County Supreme Court, attorneys representing iFinex (the parent organization of Bitfinex) and Tether took issue with the restrictions that had been placed on Tether's transactions with related parties as part of an ongoing case against them, stating that the NYOAG had no basis for disallowing tether (USDT) holders and other affiliated entities from redeeming their tokens.

2019-5-16 18:51


Почему обновление Ethereum ProgPoW всё ещё оспаривается в сообществе

Это долго обсуждалось. Было опрошено сообщество. Вчера сообщество эфириума узнало, что спорное обновление, известное как ProgPoW, будет проходить полную проверку своего кода у компании Least Authority из Берлина, которая будет анализировать ProgPoW в качестве независимого аудитора.

2019-3-29 21:25


Ожидая аудита: Почему обновление эфириума ProgPoW всё ещё оспаривается в сообществе

Автор — Адриана Хамахер. Оригинал опубликован на Decryptmedia. Это долго обсуждалось. Было опрошено сообщество. Вчера сообщество эфириума узнало, что спорное обновление, известное как ProgPoW, будет проходить полную проверку своего кода у компании Least Authority из Берлина, которая будет анализировать ProgPoW в качестве независимого аудитора.

2019-3-26 14:05


Фото:

Spain: Financial Watchdog Intensifies Efforts to Make Cryptocurrency Holders Pay Tax

It may soon no longer be business as usual for bitcoin (BTC) and altcoins investors in Spain as the nation’s tax authority, the Agencia Estatal de Administracion Tributaria (AEAT), has reportedly identified at least 15,000 distributed ledger technology (DLT) based virtual currency holders and is now set to make them pay taxes, reported Finance Magnates on November 20, 2018.

2018-11-22 01:00