scrobble.life
#steem

Fact: Steemit Sybil Attacked the Steem Blockchain

I've been having a number of Twitter conversations today about the Tron/Steemit/Steem drama. There are a lot of people very concerned about this situation and rightfully so. On February 15th, I tweeted this:

image.png

If you've been paying attention the last few weeks, things have gotten really interesting, bringing a lot of media attention such as:

People are emotionally connected to this story because it may impact the way their blockchain property is defined and secured. For a really interesting discussion on property (and this whole Steem debate), check out this conversation:

The second part of the conversation was really interesting because it challenged some of my perspetives on property, mainly that if it's not rivalrous, is it really property? I also appreciated the distinction between value and property. Many, I think, are more concerned with their value being negatively impacted than they are about their property.

There are many sides to the current discussion. Some see the actions of the community consensus witnesses as "theft" because they (temporarily) froze tokens they did not own according to non-blockchain legal frameworks. They did so with support of token holders as demonstrated on chain by the one witness who ran v0.22.3 (which also disabled voting rights, but didn't hinder transfers) being voted out of consensus. They responded here. Some argue there is a legal case to be made about the expectations set on that property and there may even be a fraud cause in the future between Ned and Justin for selling something without full disclosure about the commitments associated with that stake.

I personally think this won't go anywhere because, as has been pointed out on Twitter, the Steemit about page contradicts whatever things Ned said publicly about the Steemit stake (and, in a sense, even the 2017 roadmap statements).

image.png

But then there's also this... so... yeah.

image.png

We can go back and forth on this, but ultimately it comes down to the rules on a blockchain are defined by the consensus algorithm of that blockchain. If those rules are followed and those in consensus control are asked to take action to protect the chain, that's in line with the rules. Not everyone may agree, but the rules are still the rules.

The valid chain is based off DPoS consensus. The ninja-mined stake has a complicated past (witnesses were asked by some to fork it off the chain last year, something I will not support). v22.2 temporarily froze the issuer tokens (it was a difficult decision), hoping to communicate with the new owner who had not talked to the community yet (but did make statements, some saw as threats, about the future of their token and blockchain). The response from the new owner was immediate and positive, saying a community town hall would take place. Unfortunately that meeting was pushed far enough into the future to coordinate with exchanges to vote with customer stake to take over and centralize the chain with 20 sock puppets.

Exchanges voting with customer funds was always a theoretical threat to DPoS (HF14 on Steem introduced decline_voting_rights as a way to help with these things, but that's back when the power down was two years, now it's 13 weeks). Now it's a historical reality.

The rules (currently, until they are updated to remove this threat) also allow custodial holdings to vote without the intentions of the "owners" (I use quotes because not your key, not your token) taken into account.

What really happened here and what concerns me most is a Sybil Attack.

In a Sybil attack, the attacker subverts the reputation system of a network service by creating a large number of pseudonymous identities and uses them to gain a disproportionately large influence. It is named after the subject of the book Sybil, a case study of a woman diagnosed with dissociative identity disorder.

If you're not familiar with Sybil attacks and why they are so dangerous to Byzantine Fault Tolerant systems like blockchains, I suggest being less vocal on Twitter until you do.

Steem was Sybil attacked.

Steemit and Justin Sun did it.

Are you okay with that?


(P.S. We have friends staying with us this weekend who planned their trip months in advance. I will not neglect their friendship. I may not be super available this weekend.)

Comments · 20

  • @sarariflo(25)· 2361d

    I don´t understand why people are upset, when exchanges use customers stake for voting. Everyone in the crypto-community knows the drill: NOT YOUR KEY = NOT YOUR COINS. So why would anyone who cares about votings in the commuity leave their stack on an exchange. And the people who did leave it on an exchange DID their vote. They voted for not really taking care what happens with their stake. Anyone should simply stop whining.

  • @arcange(79)· 2361d

    Congratulations @lukestokes! Your post was mentioned in the Steem Hit Parade in the following categories:

    • Comments - Ranked 10 with 50 comments
    • Pending payout - Ranked 5 with $ 66,03
  • @alexs1320(72)· 2361d

    Who is more stupid:

    A girl with Dawn Syndrome or Extreme Communists who don't understand basic economy?

    image.png

    P.S. PARTY COMMISARS, DO FLAG YOURSELVES

  • @ammonite(73)· 2361d

    Whatever happens we really need to find a way to stop this kind of thing happening again. Nobody should be able to come in and buy the network. My stake is quite small but my social stake is quite large having been here for nearly three years. I would love to see a way that this is taken into account in the Witness votes. Something like a REP system that works and a way to use that to multiply my vote strength. A new account, a week or two old should not be able to have such power when they don't have social skin in the game. I wrote more about this in my latest post but it fell down the back of the Steem sofa. (I already made this comment on another post but I think is also belongs here)

  • @gorans(38)· 2361d

    Cool

  • @cloudspyder(60)· 2361d

    The attack came from the inside out. Using the community fund to attacked the community core. However, the community managed to hold the ground.

  • @farizal(64)· 2361d

    I resteemd/reblogged this post so more people can join the conversation and move forward with solutions. I can't comment more because the previous replies were so good. ☮️✌️

  • @joanstewart(75)· 2361d

    Above my "pay-grade", not a coder.

    Possible interesting reading on matter at hand: https://hackernoon.com/notes-on-blockchain-governance-ob65o3pod

  • @joeyarnoldvn(68)· 2361d

    The good news is that something like this brings us together to vote and to fight for a thing that we share a bond over, Steem.

  • @birdinc(60)· 2362d

    I wouldn't call it a true DDOS-style sybil attack. It's more a stake weighted-sybil attack.

  • @phgnomo(65)· 2362d

    Sorry @lukestokes but what is happening is a consequence of the witnessess actions.

    Yes, Justin Sun did a shitty move, and it was an attack.

    But this kind of attack was possible because you witnessess ignored the problem for a long time.

    And you can't say that this was never brought up. But witnessess attitude were "Nah... It's fine"

    Isn't it time for the witnessess to also be honest and own their own mistakes?

    You got the community (including me) backing you guys up in this situation, but after this crisis end, well....

  • @valued-customer(75)· 2362d

    I have engaged with you in the past about this specific threat. ~Two years ago you and other consensus witnesses did not act to prevent this threat when I came to understand and discuss it. The responses I received generally took the form 'We do not agree' I got from @timcliff (or @smooth. Maybe you. Memory fails me atm).

    Here we are. While that is in the past, I reckon it is important to acknowledge our failures and limitations in order to move forward based on real and factual data.

    I don't care about acknowledgment, and am not here to say 'I told you so', but I do want to pierce the veil of nescience regarding foreknowledge. The fact is that during the entire existence of Steem, the founder's stake has been a threat of Sybil attack, and if the threat of majority stake effecting a 51% attack is not utterly eliminated going forward, there is no possibility of Steem being secure from Sybil attacks.

    We (the Steem community) may or may not survive this attack. If we do, failing to prevent this vector for Sybil attacks will simply leave Steem as vulnerable to destruction as it has always been. The next thing I want from witnesses, while ongoing attempts to secure the chain continue, is specific proposals to eliminate this threat. You may find it useful to consider my recommendations from our prior discussions in order to reconsider their potential for success, or eliminate them from consideration as lacking potential to resolve the problem.

    The witnesses that have been continually in the consensus for these last several years have profited (insofar as witnessing is profitable) from the centralizing multiplication of stake weight the current witness voting mechanism employs. It is difficult to dismiss this fact considering the potential of witnesses to actually secure the blockchain going forward, but since it's an existential matter presently (as far as Steem is concerned) I expect it is necessary and possible.

    Starting with 1 Steem = 1 witness vote (or 100% VP depletion without recharge for witness votes), and executing code preventing exchanges from voting on witnesses, how do we secure Steem from this threat?

    Thanks!

  • @martie7(62)· 2362d

    Each user must decide for himself in what proportion he makes to divide the votes for witnesses. He can vote for only one or break own vote into 30 parts - that's his personal right. I think the current DPOS system is far from ideal and pretty unfair.

  • @skytrex(59)· 2362d

    I'll guess, what should be on the table is... Q: should exchanges have the ability to power up Steem or not?

  • @sgt-dan(66)· 2362d

    Thank you for taking the time to explain these things. Have a wonderful time with your friends that are visiting. I personally would love to be in Puerto Rico right now. It is cold up here in Pennsylvania!

  • @hotbit(59)· 2362d

    Steem is designed for an easy 1/3 + 1 attack. What is more, it's designed through the multivote rule to be 100% controlled by a very small number of top SP holders.

    I've asked in comments several witnesses about opinion. If I'm not mistaken, none did.

    @lukestokes Are you OK with the 30 for 1 centralization rule? https://steempeak.com/palnet/@hotbit/steem-blockchain-multivote-security-vulnerability

    Why no community witness had the courage to express his support or the lack of thereof for the centralization multivote rule?

  • @fitzgibbon(61)· 2362d

    Me, OK with Justin executing a coup d'état? No. But he doesn't listen to me.

    Is CZ ok with this attack by Justin?

  • @luca1777(69)· 2362d

    No, Sybil Attack ain't cool, but a clear situation/case is something else...

  • @torrey.blog(59)· 2362d

    No!!

    Steem was Sybil attacked. Steemit and Justin Sun did it.

    Are you okay with that?