Validating Lightning Signer

772 posts

Validating Lightning Signer banner
Validating Lightning Signer

Validating Lightning Signer

@VLSProject

Non-custodial Lightning security for serious balances. Off-node keys + full validation = a compromised node can’t steal funds Open source Rust SDK. https://t.co/uyM2m1tBs7

Katılım Eylül 2020
51 Takip Edilen1.1K Takipçiler
Sabitlenmiş Tweet
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
“Non-custodial” is not a security model on Lightning. Because signing must be online, the real question is: If your node is compromised, what can the attacker do?
English
2
11
9
678
Validating Lightning Signer
The VLS signer holds keys, tracks channel state, and evaluates policy. It does not route, gossip, run plugins, or accept peer connections. Everything it does not do is attack surface it does not have.
English
0
0
0
82
Validating Lightning Signer
A Lightning channel is a running agreement, not a static balance. Old states get revoked, new ones replace them. VLS keeps its own record of that history and refuses to sign anything that contradicts it.
English
0
2
4
206
Validating Lightning Signer
Lightning signing happens fast and often. Routing, channel updates, closes. A validating signer that checks each request without slowing the protocol down is the design VLS targets.
English
0
2
5
106
Validating Lightning Signer
Per-payment amount limits in VLS bound the size of a single HTLC the signer will approve. A compromised node cannot exceed the cap by request, regardless of what the protocol would otherwise allow.
English
0
2
4
141
Validating Lightning Signer
Lightning balances large enough to matter for a payment network are larger than anyone wants to keep on a hot wallet. Moving keys off the node and enforcing policy independently is how balances become reasonable to hold at scale.
English
0
1
2
84
Validating Lightning Signer
Lightning is stateful. Same key, same channel, different commitment number, different valid signature. A signer without its own state cannot tell the difference between a current state and a revoked one. VLS tracks state for this reason.
English
0
4
5
250
Validating Lightning Signer
If Lightning is going to serve a large number of users, it needs merchants. Merchants need channel balances they are comfortable with. That comfort depends on the security of the setup. It is one of the key pieces that needs to be in place.
English
0
2
4
148
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
VLS treats node requests as untrusted input. The signer decides whether the request is allowed and produces a signature only if the answer is yes.
English
0
2
2
75
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Routing payments through high-fee adversarial nodes has been used to drain Lightning channels. VLS checks fees against policy and refuses signatures on outgoing HTLCs that exceed the configured ceiling.
English
0
3
6
176
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Self-custody on Bitcoin L1 is the user holding the key and approving each transaction. The equivalent on Lightning is the user controlling a signer that enforces policy on each request. VLS provides the signer piece.
English
0
1
2
36
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Channel state. Chain context. Revocation history. All are required to know whether a signing request is consistent with what has been signed before. VLS keeps them and uses them.
English
0
1
1
106
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Boring is the goal for signer architecture. Small codebase, narrow API, no gossip, no plugins, no peer traffic. The Lightning node can be exciting. The signer should be predictable.
English
0
1
6
224
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Open source security infrastructure does not depend on a single team's continued participation. The signer code is on GitLab, the license is Apache-2.0, and anything found by one team can be fixed for all.
English
0
3
4
163
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Lightning incident postmortems often end with the same observation. The compromise itself was routine. The blast radius was the problem. Architecture that limits blast radius is the missing piece in most setups.
English
0
1
5
105
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Greenlight runs Lightning nodes as a hosted service while users keep signing authority through VLS. Hosted convenience, user-side signing decisions, working in production.
English
1
1
4
236
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
Security shapes what you can build on top of it. With weak security, you cap your channel sizes, limit your customer base, and stay cautious. With strong security, those limits move. That is why it is worth the investment early.
English
0
1
4
248
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
After a breach, the sats are just the beginning. You shut down operations to investigate. You notify users who trusted you. Potential partners pull back. Rebuilding that trust takes months. It is always worse than the number on the screen.
English
0
1
4
113
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
When someone at a company asks "should we put real money on Lightning?" the conversation goes better if you can point to an independent signer with explicit policies, not just a hot node you hope does not get hacked.
English
0
3
4
234
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
A validating signer makes a node compromise survivable. Funds can still be at risk depending on the operator's policy, but the default outcome is no longer "it's all gone."
English
0
1
3
136
Validating Lightning Signer
Validating Lightning Signer@VLSProject·
A useful test for any Lightning deployment: name the smallest component an attacker would need to own to move funds. With keys on the node, the answer is the node and everything attached to it.
English
0
1
1
250