﻿{"id":295,"date":"2021-05-25T22:28:19","date_gmt":"2021-05-25T22:28:19","guid":{"rendered":"https:\/\/gridnet.org\/wpp\/?p=295"},"modified":"2021-05-26T06:21:54","modified_gmt":"2021-05-26T06:21:54","slug":"dev-news-transactions-from-the-mobile-app-and-whats-being-worked-upon","status":"publish","type":"post","link":"https:\/\/mag.gridnet.org\/index.php\/2021\/05\/25\/dev-news-transactions-from-the-mobile-app-and-whats-being-worked-upon\/","title":{"rendered":"Transactions from the mobile app and what&#8217;s being worked upon"},"content":{"rendered":"<p data-pm-slice=\"1 1 []\">Folks,<\/p>\n<p>As you may know,\u00a0for around 24 hours we have been working on adding support of issuing transactions directly from the mobile app.<\/p>\n<p>We\u2019ve got bad.. and good news as well!\ud83d\ude01<\/p>\n<p>Let us start with the bad. We\u2019ve had boys\u2019 return results of their TLA+ simulations portraiting of what was to be and partially already has been implemented since the very morning.<\/p>\n<p>All in all,\u00a0it\u00a0turned out to be a little bigger subject than expected, with potential issues involving other areas of the system as well, were we to to leave things as they are or were to be.<\/p>\n<p><strong>Let\u2019s now jump straight to the gist of things:<\/strong>\u00a0In order to uphold strong security guarantees against malicious full-nodes\u00a0we will need to move the entire Grid Script Compiler to be available directly from the mobile app. In other words &#8211; large portions of the GRIDNET VM engine will need to be made available\u00a0from\u00a0the mobile app itself. Sounds complicated? It is\ud83d\ude06.<\/p>\n<p>That wasn\u2019t quite expected.<\/p>\n<p>Still, the simulations showed that a malicious full-node\u00a0<em>could<\/em>\u00a0 request a signature for arbitrary operations were things to be implemented like we initially envisioned. Now, of course, we need to be after security first. It needs to be first there&#8217;s no way around it.<\/p>\n<p>To sum up,\u00a0we need the mobile app to be able to:<\/p>\n<ol>\n<li>Compile GridScript on its own &#8211; we can\u2019t trust full-nodes to be compiling GridScript instructions for us as the resulting byte-code could be faked. We wouldn\u2019t know wasn\u2019t the mobile app be able to..<\/li>\n<li>Decompile the code generated at a full-node and be able to present results of decompilation to the user would he want to verify what\u2019s being committed.<\/li>\n<\/ol>\n<p>Now, if we allow for 1) &#8211; the mobile app would be able to compile a #GridScript transaction on its own sign it and problem solved. Then, in case of simple transactions that the mobile app formulated, there wouldn\u2019t be any need to user to verify source code and stuff\u00a0 as one may be 100% sure that code was generated and compiled by the mobile app itself.<\/p>\n<p>The second\u00a0point\u00a0would be\u00a0of particular importance when the to-be-committed transaction\u00a0resulted from\u00a0user actions made within the Web-UI, or for whatever other reason was the code compiled at a full-node. In short: we need to be able to see <em>within<\/em> the code <em>if it was generated at full node and compile at mobile app if we can<\/em>.<\/p>\n<p>There could be a hacky solution making the mobile app able to compose bytes of a simple transaction but that would be too short-sighted and since cryptographic signatures and variable length fields would need to be used anyway, even this wouldn&#8217;t be so simple. Thus we&#8217;re planning on porting the entire compiler.<\/p>\n<p>The good thing? While it\u2019s going to take\u00a0<em>little longer<\/em>\u00a0than expected, we\u2019ve\u00a0already planned\u00a0the\u00a0approach towards this matter and we could see some functional results\u00a0at the beginning of next week\ud83e\udd17<\/p>\n<p>Wizards.\ud83e\uddd9\u200d\u2640\ufe0f\ud83e\uddd9<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Folks, As you may know,\u00a0for around 24 hours we have been working on adding support of issuing transactions directly from the mobile&#8230;<\/p>\n","protected":false},"author":1,"featured_media":296,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,11,8,19],"tags":[],"class_list":["post-295","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-core","category-mobile-news","category-news","category-research"],"_links":{"self":[{"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/posts\/295","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/comments?post=295"}],"version-history":[{"count":5,"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/posts\/295\/revisions"}],"predecessor-version":[{"id":302,"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/posts\/295\/revisions\/302"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/media\/296"}],"wp:attachment":[{"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/media?parent=295"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/categories?post=295"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mag.gridnet.org\/index.php\/wp-json\/wp\/v2\/tags?post=295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}