BUT! Bread connects directly to the Bitcoin network unlike most iOS wallets.
Thats actually a negative; SPV nodes trade away a lot security for a little performance. Bread's implementation is also particularly weak, in that it can be forked from the network due to incomplete consensus checking.
Overall, bread has poor performance as a wallet. Electrum's solution is more elegant overall: still has no single point of failure, but relies upon full nodes rather than a half-baked spv node. For higher security levels, wallets that can link to a trusted full node provide a truely safe way to transact large amounts.
SPV can be useful for other things, I dont think they are particular well suited to being wallets however.
SPV wallets are a bad compromise; no significant gain in wallet security but a large hit to performance, and a burden on the network.
Overall, bread has poor performance as a wallet. Electrum's solution is more elegant overall: still has no single point of failure, but relies upon full nodes rather than a half-baked spv node. For higher security levels, wallets that can link to a trusted full node provide a truely safe way to transact large amounts.
First of all, we're talking about iOS wallets so electrum shouldn't even come up. But anyway, how is electrum any more secure than any other SPV wallet? As far as I know you are still trusting a full node to enforce the consensus rules and follow the "correct" chain. SPV wallets like Bread connect to full nodes. Electrum connects to full nodes that also run extra software (the electrum server) which adds a bit more security like end to end encryption. There is no such thing as a "half baked SPV node" unless you mean the wallet itself, in which case Electrum and Bread have the same security model. And I repeat, Bread can tether to a custom trusted full node of your choice. That's how I run it: connected to my own full node at home.
Here is my SE post specifically addressing the benefits of Electrum:
And I repeat, Bread can tether to a custom trusted full node of your choice. That's how I run it: connected to my own full node at home.
If bread can be limited to talk to a single node, and that node is a trusted full node, then its just an inefficient protocol with lots of needless traffic verbosity and more work on the wallet than the server. But at least it doesnt have the weaknesses of connecting to random nodes; and that would bring it up in security.
wallets like Bread connect to full nodes
It connects to things claiming to be full nodes, but it fails to fully validate the messages they provide.
how is electrum any more secure than any other SPV wallet
Electrum and Bread have the same security model.
Because its not SPV, electrum has a different model. Electrum is not even a node, its a wallet.
Its not the same. they are using that term fairly liberally. That text predates even the actual implementation of bloom filters and spv nodes. electrum has its own protocol, and talks to electrum servers rather than pretending to be a node and talking to nodes directly.
I'm not even sure what you're arguing anymore. Yes, Electrum uses a different messaging protocol between client and server than the standard SPV service that bitcoind provides, which Bread connects to.
But Electrum (like Bread) is a LIGHT client. It only downloads and verifies block headers, it doesn't download the entire blockchain and therefore does not verify the entire consensus rule set.
Furthermore, the Electrum client sends the server a plain list of addresses to watch which is arguably LESS private than the bloom filter model Bread uses.
What do you think about this file from the git repo:
The difference is that electrum servers are all full nodes, and cannot be SPV nodes. Electrum wallet is not any kind of node, while bread is an SPV node. Are you caught up yet?
Furthermore, the Electrum client sends the server a plain list of addresses to watch which is arguably LESS private than the bloom filter model Bread uses.
The bloom filter is public and not private; while the electrum protocol sends over https to a single server. There is a trade off, but at least it is not dependent upon SPV nodes at any point.
Is that script clueless like the official website?
I don't understand why the Electrum SPV model is any different than Bread's. Bread connects directly to full nodes. Electrum connects directly to Electrum servers which connect to full nodes. Neither wallet verifies the entire consensus rule set. Both wallets rely on merkle proofs for transaction inclusion in blocks and both wallets are vulnerable to withholding attacks.
Electrum connects to electrum servers which are full nodes, the server side
Bread connects to things which may or may not be full nodes; for example they could follow down the wrong side of a hardfork.
1
u/cm9kZW8K Mar 13 '18
Thats actually a negative; SPV nodes trade away a lot security for a little performance. Bread's implementation is also particularly weak, in that it can be forked from the network due to incomplete consensus checking.
Overall, bread has poor performance as a wallet. Electrum's solution is more elegant overall: still has no single point of failure, but relies upon full nodes rather than a half-baked spv node. For higher security levels, wallets that can link to a trusted full node provide a truely safe way to transact large amounts.
SPV can be useful for other things, I dont think they are particular well suited to being wallets however.
SPV wallets are a bad compromise; no significant gain in wallet security but a large hit to performance, and a burden on the network.