Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Oracle is a fancy name for an API, right?


In cryptography an oracle is someone or something you can query that returns an answer that you cannot know from just the math.

It doesn't have to be an API. Side channel attacks can provide unintentional oracles. For example, if you have a password checking function that takes longer to return a false result for "close" inputs, then it leaks information that can be used to crack passwords (simple O(n) string comparison would be an example)

https://en.wikipedia.org/wiki/Oracle_attack


An oracle is not just an API, but specifically one that your system trusts unconditionally.


I've been wondering the same for a few weeks but can't be bothered checking.

My uneducated inference is that an oracle is a data source and you can hook into it from the smart contract. The oracle seems to live off-chain and live on a traditional server/DB.

Please correct me if the above is way off!


An oracle is a source of truth for information about the outside world to a smart contract. The smart contract doesn't actually call the oracle. This is because smart contracts don't self-execute and can't make external http calls. So a smart contract pauses, and waits for an oracle to trigger an update function. Because oracles have a lot of power over a smart contract (not all smart contracts need them, by the way), they have to be done in a secure way. The market leader in decentralized oracles is Chainlink. They power hundreds of DeFi applications.


At that point can they really be considered purely code contracts anymore? If their execution requires a trusted third party some of the rhetoric goes out the window.


They're sort of hybrid networks at that point, but Chainlink oracles are decentralized: each function is run by several nodes (31 for the BTC/USD or ETH/USD price feed, for example). The nodes have to come to consensus and individual nodes are slashed if they produce bad or late data. You can see an example of a LINK feed here: https://data.chain.link/ethereum/mainnet/crypto-usd/eth-usd

Decentralization is a spectrum. But I would argue this approach is far more secure than naive oracle implementations.

Not all applications need oracles. It depends on whether your smart contract needs information about the world outside of the blockchain.


Who owns those 31 nodes? Who gets to choose which nodes are part of the calculation?


I think they're just other smart contacts that use many data sources. Like if you wanted an oracle that returned the result of a baseball game, you'd have it check various newspaper websites and have it make sure the results were all the same. To attack it, you'd have to attack all the newspaper sources. It's still a weak point, but not quite a single point of failure.


Specifically for something that feeds data from an API (or really any other data source) into a blockchain so it is available from smart contracts.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: