Four Questions About the Orchard Vulnerability

(In the unlikely case) What if the exploiters are “good” and simply leave the coins in Orchard? No similar than behavior in Sprout ( from what I can see )

Anything could happen but to me, as in the most likely case where there was no exploitation of the vulnerability, in that case there is nothing meaningful to discuss and I am not addressing that case. If there are no losses then there is nothing that needs to be done to solve the problem of losses.

I’m specifically addressing the unlikely but possible case of sophisticated black hat exploitation where the motive is to effectively steal value from holders of legitimate ZEC.

The network isn’t congested. If you’re genuinely concerned, you can exit the Orchard pool right now. Unshield your coins, touch grass, enjoy the summer, and wait for Ironwood.

Almost nobody with actual skin in the game seems worried about this. If they were, they would have already done exactly what I’m suggesting you do.

5 Likes

Couldn’t agree more :slight_smile:

This small blip is folks trying to scare.

3 Likes

Exactly. In crypto, individuals should assume their choices and the consequences.

For those looking for moral hazards, bailouts and a confirmed inflation bug, I’m sure the fiat system will welcome you with open arms :rofl:

I don’t intend to migrate in the next few years. I would like to know if there will be a deadline for the discontinuation of the orchard.

I don’t intend to migrate in the next few years. I would like to know if there will be a deadline for the discontinuation of the orchard.

I haven’t yet heard any discussion of that.

In my humble opinion, which a lot of other Zcashers strongly disagree with, the social expectation should be that you have to open your wallet at least once every year or so and connect it to the blockchain if you want your coins to remain first-class. If you don’t then the rest of us should start refusing to accept your coins at face value, and instead accept them only at a discount, ie a fee that you pay to the network to pay for the costs to everyone else of maintaining your old, unmaintained coins.

Here was a recent discussion about this: NU7 Sentiment Polling: Questions for Community Review & Coinholder Voting via Zodl - #33 by zooko

3 Likes

If my wallet is the lite version and not a full node, does connecting the wallet to the internet, even though it’s a lite version, make any difference, even if it’s not a full node? In my view, the benefit of connecting the wallet to the internet is linked to the full node.

Yes, a lite wallet would be able to do the steps that keep your coins in the first first-class category, such as migrating them to a current pool or a long-term storage pool. To be clear, this is all hypothetical. This is my preference and imagination, which a lot of other Zcashers don’t share, and in practice Zcashers have still not figured out how to shutdown the oldest pool (Sprout) which launched almost ten years ago. So even if something like this idea does eventually win out, you’ll probably have plenty of time and notifications. But I thought it was right to let you know about the possibility now, since you’re thinking about how you intend to maintain your coins (which are currently in the Orchard pool) in the long term. :slight_smile:

1 Like

Textbook definition of an avant garde idea.

Dude, what’s the deep meaning behind keeping coins in orchard for whole years after it basically stops working? Or is this just another disimulational post? :face_with_monocle:

Okay, so let’s say this crazy thing happens - someone hacks Binance and steals 100M to Ironwood. And we can see the money isn’t being moved anywhere.
Binance is pissed off and thinking about delisting ZEC.
Would it make sense to simply delete all notes created after the theft event from the Ironwood tree and recalculate the root, in order to prevent ZEC holders from experiencing negative consequences of Binance’s unfriendly actions?

I don’t think those situations are analogous.The Binance hack changes who owns ZEC. Counterfeiting changes the monetary properties of the protocol by increasing the supply.

My view is that the protocol should continue enforcing its rules in both cases. It should not rewrite the ledger to reverse the theft, and it should not accept an inflated supply after counterfeiting.

The protocol is that with a valid zec note, you can reliably perform known actions. With the Ironwood fork, it appears the protocol is continuing to “enforce some rules” while not enforcing others. That is, for some properties of zcash ecosystem, we can change part of the protocol. There’s certainly a difference from my example, but I don’t think it’s as big as it seems at first glance.

Yes, Ironwood changes the consensus rules. Almost every network upgrade does. It seals the Orchard pool so that no new funds can enter it and funds can only leave through the existing turnstile accounting rules. The question isn’t whether the rules change. The question here is which properties those new rules preserve, and Ironwood preserves the integrity of 21 million coin cap.

Rewriting the ledger to reverse stolen funds is different. That would be changing history to undo a particular outcome.

Ethics put aside, if we turn off the turnstile and accept any amount of orchard coins in the future, it means the current supply of ZEC is unknown/unbounded. I don’t think many people would find this acceptable for a coin.

LOL.

Seriously, “ethics put aside” every wrong thing you can imagine anyone doing is fine. I won’t start enumerating all the evil stuff that people do that is just fine if you “put ethics aside” because I know that some people around here are sensitive, but really, “ethics put aside”?

In the unlikely event that counterfeiting took place, because there would be no way to know which coins were “real” and which were “counterfeit”, then the actual reality would be exactly that the current supply of ZEC is unknown/unbounded. If counterfeiting happened, that is exactly what happened.

What you are saying translates into this: whether it’s the right or the wrong thing to do ethically, I’m in favor of making it look like (i.e. pretending) there was no counterfeiting even if there was and imposing all the loss of value that counterfeiting would result in on whoever happens to try to exit the turnstile after the “correct” qty of ZEC have exited the turnstile.

I didn’t mention anything about my opinion on the matter. I am merely pointing out the logical implication of accepting unlimited funds coming out of the Orchard pool, now and forever.

Sorry, you’re right. I agree I was assuming that you were expressing an opinion.

I meant it as: “I won’t get into an ethical argument. Here’s an argument that doesn’t depend on it”.