Tribler / tribler

Privacy enhanced BitTorrent client with P2P content discovery
GNU General Public License v3.0
4.74k stars 445 forks source link

msc placeholder: daos, scams, FROST, message drop, something #7074

Open synctext opened 1 year ago

synctext commented 1 year ago
rahimklaber commented 1 year ago

This is a short draft of my idea: Are_Daos_A_Scam_draft.pdf Bassically, I want to give an overview of what DAOs are and the issues they have.

I've also read some papers, but most of the interesting things are found outside of papers on blogs or articles. Some of the stuff I found interesting:

synctext commented 1 year ago

This angle is difficult to bring in the science. DAO now reads as engineering and financial shenanigans. More scientific example are going into these type of algorithms to generate trust or another wild angle is technology is becoming political; see Susskind book. Or especially wild: "why we never produced a global brain". Example Your survey needs more scientific citations, besides blogs. Note the DAO survey with [46] papers cited. Do something more practical: like crawl a DAO (forum) and analyse. The exhaustive list of DAOs and their exact governance rules.

rahimklaber commented 1 year ago

lit survey

this is what I currently have lit_survey_current.pdf. I combined what I was doing previously with researching DAOs' governance procedures. I couldn't really find a scientific angle + my writing is still not that good ☹


Do we really need to use FROST? Depending on what improvements FROST made over its predecessors, it might be worth it to use older schemes as they already have mature implementations. I found a go library that allows creating threshold signatures for ECDSA and EdDSA. Then we could use go mobile to call it from android.

synctext commented 1 year ago

Solid idea! Somehow I failed to read more, after seeing FROST. I just wanted it after reading. :smile:

rahimklaber commented 1 year ago

current version of survey I think it is a bit better now, but I think there is still a bit of work to be done. The angle I'm going with now is that It is hard to fully understand DAOs since there isn't any good documentation and you have to gather information from many different sources.

synctext commented 1 year ago

Master thesis thinking:

rahimklaber commented 1 year ago


lit survey.pdf

What I’m planning to do next sprint

synctext commented 1 year ago
rahimklaber commented 1 year ago

small update

rahimklaber commented 1 year ago


possible directions

synctext commented 1 year ago
kayabaNerve commented 1 year ago

While quite late, I'd like to contribute FROST is far simpler than any threshold ECDSA protocol, relying on far fewer assumptions. It also has extensive security review in:

Threshold ECDSA also has review, yet provides a much larger surface taking several rounds to complete, and relying on far more assumptions to be proven. Part of this can be cited back to ECDSA being a convoluted attempt at avoiding a patent, leading itself to not have a security proof given the discrete log problem.

Practically, FROST is 2-rounds, only one requiring knowledge of the message. The lowest thresold ECDSA protocol is 4 rounds to sign, when the famed GG20 is 7. Binance's tss-lib has been forked to GG20 by THORChain, and their fork has since had several security issues with it, from Alpha-Rays to the ability to cause honest parties to be blamed to leaking key shares. Despite this, THORChain's library was prior audited (though the quality of this audit now must be called into question) and is likely the better choice than the tss-lib it comes from (as I assume it has had far more scrutiny, yet I may just be unaware of the review on Binance's lib. Their one published audit is years old, prior to Alpha-Rays).

As for Binance's EdDSA impl, they appear to use a 3-round threshold signature protocol (not FROST, yet not vulnerable to Drijver's application of Wagner's algorithm thanks to a hashed commitment round). I'm unsure what actual protocol it implements, yet I can note FROST achieves a 2-round protocol with the same raw bandwidth for their messages. It didn't include any horrendously expensive proof to achieve the reduced complexity.

I also believe, regarding performance, no threshold ECDSA is linear to amount of signers. GG20 is quadratic, which is why THORChain takes tens of seconds to sign for their 20 participants. FROST is linear, and I've benchmarked <0.7s per-signer for a 333-500 group.

I do believe this is months late, and y'all are using FROST (specifically my lib, currently under audit :D ), yet I still wanted to chime in as I can :) At least this should be helpful by providing plenty of references to refer to?

rahimklaber commented 1 year ago

@kayabaNerve Thanks. This is great and It'll be helpful when writing my thesis.

rahimklaber commented 1 year ago


synctext commented 1 year ago

Please document the possible final goals of your master thesis, brainstorm:

rahimklaber commented 1 year ago

apk demo video in case apk doesn't work

Arxiv still has the survey on hold. 🤔

I think I will work on making these things work and then maybe add extra stuff:

Thesis paper brainstorm:

synctext commented 1 year ago
rahimklaber commented 1 year ago

I didn't do much this time.

For the next weeks:

synctext commented 1 year ago
rahimklaber commented 1 year ago


For the next weeks

Before choosing to do just acks for reliability I spend time looking into other ways. I think a future project could be adding quic to ipv8. I know you said its too heavy, but you could have quic for peers you interact with often and then have normal udp for other peers/ messages. There is a java quic lib aswell I played around with it and it worked.

synctext commented 1 year ago
rahimklaber commented 1 year ago

For comparison I ran FROST keygen with and without ipv8. Keygen with IPV8 vs Keygen without IPv8

synctext commented 1 year ago
rahimklaber commented 1 year ago


Can we have next meeting in two weeks?

synctext commented 1 year ago
rahimklaber commented 1 year ago

Can start setting up a date for the defense? thesis.pdf apk

synctext commented 1 year ago
rahimklaber commented 1 year ago

I probably won't be able to show the app while I'm in Curacao so I made a recording.

I still need to add/fix a bunch of stuff, but its way nicer than before. I do the following in the video:

synctext commented 1 year ago
synctext commented 1 year ago

Harvard Kennedy School on DAO.

Hubbard, Sarah, Connor Spelliscy, Nathan Schneider and Samuel Vance-Law. “Toward Equitable Ownership and Governance in the Digital Public Sphere.” , June 8, 2023. This paper explores how newly developed DAO tooling could help co-ops compete in the online economy. Specifically, we outline how DAO tooling could provide co-ops with:

rahimklaber commented 1 year ago

Is this enough to start the defense process? I got a job which starts in September, so I'd like to finish before then.

I spent this sprint writing: FROSTDAO__Collective_Ownership_of_wealth_using_FROST.pdf

The writing still isn't that good, but I think it is much better than before. The figures need to be tweaked and a bunch of them are placeholders. I'm also missing references.

What do you think of the plots? I used scatter plots because you can quickly see the variability and because the graphs have a lot of values on the x-axis, so box plots did not look nice.

You mentioned that the problem description sounds more like requirements than a problem. I tried to change it, but I'm not sure how good it is. This is the old problem description:

The internet has revolutionized the way individuals collaborate and work towards a common goal, even across borders. 
However, despite this, there remains a significant challenge when it comes to the collective management of wealth.
Establishing a company or making joint investments can be complicated and cumbersome, particularly when the individuals involved are from different countries.
Existing financial services do not address this issue, highlighting the need for a novel solution.

We aim to solve this problem by creating a peer-2-peer leaderless decentralized system.
This system will allow groups of individuals to form decentralized autonomous organizations (DAOs)~\cite{DAO} that enable them to collectively and democratically manage their wealth.
The key principle guiding our approach is decentralization, ensuring that every aspect of the system operates without reliance on any central authority or intermediary. 

To achieve this, we envision a fully open-source system and transparent system that allows participants to examine and verify every operation.
There is no central authority, therefore transparency is crucial to be able to identify potential bad actors. Building an open-source system allows anyone to contribute and ensures that the system can evolve based on the users.

Our system should be accessible to anyone, regardless of their background or technical expertise.
To ensure this, we aim to create the entire system using only mobile devices, therefore maximizing the number of potential users.
To support many users, our system should scale to millions without reducing security or performance.

By constructing this decentralized peer-to-peer leaderless system, we aim to address the existing limitations of traditional financial services and provide a robust and easy-to-use solution for decentralized collaborative wealth management. 
synctext commented 1 year ago
rahimklaber commented 12 months ago


Aside from the abstract, I think the writing of the first chapters is decent.

I spent a bit of time looking into EVA. The main problem is that it does not support concurrent transfers to the same peer + there seems to be a 20 second duration before this is reset. Key gen only needs to use EVA once per peer, so I don't think this is a problem in practice. But in my experiments, I do key gen from 2 to 50 members sequentially.

This is from image

I optimized the serialized of the message, so EVA is not needed so early, and I played around with the EVA code: image

synctext commented 12 months ago
synctext commented 11 months ago

Delft literature survey, 20 DAO participants is the tipping point for sustainability.

rahimklaber commented 10 months ago


synctext commented 10 months ago
rahimklaber commented 10 months ago


synctext commented 10 months ago

Review of draft master thesis presentation:

Collective money, FROSTDAO learnings

Approach properties
Multisig: Bitcoin scripting requires all public keys and signature of entire group. Bad scalability
FROST threshold signature single shared wallet, cubic growth of complexity for key generation.
Random lottery function loosely binding of goodness and income. Only converges to equality with infinite runtime