<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub138d0km3t8jujy9duwng26dh79fwuxqhw0xmxjdw2h2t2dgwzwpxsk9dl95.rss" />
  <link href="https://nostr.ae/npub138d0km3t8jujy9duwng26dh79fwuxqhw0xmxjdw2h2t2dgwzwpxsk9dl95" />
  <id>https://nostr.ae/npub138d0km3t8jujy9duwng26dh79fwuxqhw0xmxjdw2h2t2dgwzwpxsk9dl95</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqs87ahupgjksyfx740x8agjssnq9qlwwxapje45fuac2qg6yqy2c8szyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6lmamcg</id>
    
      <title type="html">📅 Original date posted:2013-07-08 📝 Original message:Java ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs87ahupgjksyfx740x8agjssnq9qlwwxapje45fuac2qg6yqy2c8szyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6lmamcg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspntkqxg66nsa2xgx8l6q9j36qvr4zjgtd9rtt0z9aczqtczp6mjqtyv0m0&#39;&gt;nevent1q…v0m0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-07-08&lt;br/&gt;📝 Original message:Java (Applet) security is indeed abysmal but lets compare apples to apples.&lt;br/&gt;With an applet some random guy with a website makes up some Java code and&lt;br/&gt;your browser automatically executes it.&lt;br/&gt;With Multibit you&amp;#39;re only executing highly trusted code (so trusted that it&lt;br/&gt;handles your money).&lt;br/&gt;There has almost never been a Java exploit against secure trusted code.&lt;br/&gt;&lt;br/&gt;The idea of discouraging use of java apps just because people would be&lt;br/&gt;tricked into activating the browser plugin when installing the JVM is&lt;br/&gt;probably valid but Multibit is the only reasonably complete client outside&lt;br/&gt;of bitcoinqt and I think client diversity is more important than stamping&lt;br/&gt;out java.&lt;br/&gt;&lt;br/&gt;Thanks,&lt;br/&gt;Caleb&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;On 07/08/2013 08:22 PM, Robert Backhaus wrote:&lt;br/&gt;&amp;gt; But... Multibit is Java. Java&amp;#39;s security problems has made it an instant uninstall item on windows PCs for about a year now. Java exploits are a dime a dozen.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Yes, you can reduce some of the problems by manually disabling the browser plugin, but how many users will do that?&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Recommending a fast SPV client as a first wallet - yes, of course. Recommending users open such a huge attack interface on their computers by installing Java - No go. Until Multibit is provided as a compiled binary without a Java dependency, it is DOA.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; On 1 July 2013 02:39, Gary Rowe &amp;lt;g.rowe at froot.co.uk &amp;lt;mailto:g.rowe at froot.co.uk&amp;gt;&amp;gt; wrote:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;     I&amp;#39;ve beefed up the supporting documentation for the website to make it more accessible for developers who wish to contribute. It&amp;#39;s a Java application serving HTML.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;     It can be found here: &lt;a href=&#34;https://github.com/jim618/multibit-website&#34;&gt;https://github.com/jim618/multibit-website&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;     On 30 June 2013 16:19, Jim &amp;lt;jim618 at fastmail.co.uk &amp;lt;mailto:jim618 at fastmail.co.uk&amp;gt;&amp;gt; wrote:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;         Yeah &amp;#34;email jim&amp;#39; was never going to work so I have&lt;br/&gt;&amp;gt;         bumped up MultiBit support (a bit) by:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;         &#43; having a dedicated Support page on the website&lt;br/&gt;&amp;gt;            &lt;a href=&#34;https://multibit.org/support.html&#34;&gt;https://multibit.org/support.html&lt;/a&gt;&lt;br/&gt;&amp;gt;            It has fixes and support notes for the most common gotchas.&lt;br/&gt;&amp;gt;         &#43; the in-app help also now has a &amp;#39;Support&amp;#39; section with&lt;br/&gt;&amp;gt;            &amp;#34;Troubleshooting&amp;#39; and the commonest gotchas.&lt;br/&gt;&amp;gt;            I&amp;#39;ve also written more help to cover as much as possible.&lt;br/&gt;&amp;gt;         &#43; Failing that people are directed first to bitcoin.stackchange.com &amp;lt;&lt;a href=&#34;http://bitcoin.stackchange.com&amp;gt&#34;&gt;http://bitcoin.stackchange.com&amp;gt&lt;/a&gt;;&lt;br/&gt;&amp;gt;            (I have a notification set up for the &amp;#39;multibit&amp;#39; keyword.&lt;br/&gt;&amp;gt;         &#43; Then finally users are directed to the github issues to search&lt;br/&gt;&amp;gt;            existing or raise a new issue. Gary and Tim often chip in on there to&lt;br/&gt;&amp;gt;            close&lt;br/&gt;&amp;gt;            issues down as well as me.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;         On Sun, Jun 30, 2013, at 12:42 PM, Mike Hearn wrote:&lt;br/&gt;&amp;gt;         &amp;gt; Sounds like we have consensus, Saivann, shall we do it?&lt;br/&gt;&amp;gt;         &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; I&amp;#39;m also going to ask Theymos again to relax the newbie restrictions&lt;br/&gt;&amp;gt;         &amp;gt; for the alt client forums. It&amp;#39;s probably too hard to get support at&lt;br/&gt;&amp;gt;         &amp;gt; the moment and &amp;#34;email jim&amp;#34; doesn&amp;#39;t scale at all.&lt;br/&gt;&amp;gt;         &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; On Fri, Jun 28, 2013 at 4:24 PM, Gavin Andresen &amp;lt;gavinandresen at gmail.com &amp;lt;mailto:gavinandresen at gmail.com&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; wrote:&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; I vote &amp;#34;yes&amp;#34; to have MultiBit replace Bitcoin-Qt as the recommended&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; desktop wallet app. I think most users will be happier with it.&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; If I&amp;#39;m wrong, it is easy to change back.&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; This SF.net email is sponsored by Windows:&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; Build for Windows Store.&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; &lt;a href=&#34;http://p.sf.net/sfu/windows-dev2dev&#34;&gt;http://p.sf.net/sfu/windows-dev2dev&lt;/a&gt;&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; _______________________________________________&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; Bitcoin-development at lists.sourceforge.net &amp;lt;mailto:Bitcoin-development at lists.sourceforge.net&amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; &amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;         &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;         &amp;gt; This SF.net email is sponsored by Windows:&lt;br/&gt;&amp;gt;         &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; Build for Windows Store.&lt;br/&gt;&amp;gt;         &amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; &lt;a href=&#34;http://p.sf.net/sfu/windows-dev2dev&#34;&gt;http://p.sf.net/sfu/windows-dev2dev&lt;/a&gt;&lt;br/&gt;&amp;gt;         &amp;gt; _______________________________________________&lt;br/&gt;&amp;gt;         &amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt;         &amp;gt; Bitcoin-development at lists.sourceforge.net &amp;lt;mailto:Bitcoin-development at lists.sourceforge.net&amp;gt;&lt;br/&gt;&amp;gt;         &amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;         --&lt;br/&gt;&amp;gt;         &lt;a href=&#34;https://multibit.org&#34;&gt;https://multibit.org&lt;/a&gt;    Money, reinvented&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;         ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;         This SF.net email is sponsored by Windows:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;         Build for Windows Store.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;         &lt;a href=&#34;http://p.sf.net/sfu/windows-dev2dev&#34;&gt;http://p.sf.net/sfu/windows-dev2dev&lt;/a&gt;&lt;br/&gt;&amp;gt;         _______________________________________________&lt;br/&gt;&amp;gt;         Bitcoin-development mailing list&lt;br/&gt;&amp;gt;         Bitcoin-development at lists.sourceforge.net &amp;lt;mailto:Bitcoin-development at lists.sourceforge.net&amp;gt;&lt;br/&gt;&amp;gt;         &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;     ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;     This SF.net email is sponsored by Windows:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;     Build for Windows Store.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;     &lt;a href=&#34;http://p.sf.net/sfu/windows-dev2dev&#34;&gt;http://p.sf.net/sfu/windows-dev2dev&lt;/a&gt;&lt;br/&gt;&amp;gt;     _______________________________________________&lt;br/&gt;&amp;gt;     Bitcoin-development mailing list&lt;br/&gt;&amp;gt;     Bitcoin-development at lists.sourceforge.net &amp;lt;mailto:Bitcoin-development at lists.sourceforge.net&amp;gt;&lt;br/&gt;&amp;gt;     &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; See everything from the browser to the database with AppDynamics&lt;br/&gt;&amp;gt; Get end-to-end visibility with application monitoring from AppDynamics&lt;br/&gt;&amp;gt; Isolate bottlenecks and diagnose root cause in seconds.&lt;br/&gt;&amp;gt; Start your free trial of AppDynamics Pro today!&lt;br/&gt;&amp;gt; &lt;a href=&#34;http://pubads.g.doubleclick.net/gampad/clk?id=48808831&amp;amp;iu=/4140/ostg.clktrk&#34;&gt;http://pubads.g.doubleclick.net/gampad/clk?id=48808831&amp;amp;iu=/4140/ostg.clktrk&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:04:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsthxn5frqj40a8th3lp2ckuaswxlwt3fzw784xgnva8wlskwpz2qczyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6a6mv2g</id>
    
      <title type="html">📅 Original date posted:2013-05-15 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsthxn5frqj40a8th3lp2ckuaswxlwt3fzw784xgnva8wlskwpz2qczyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6a6mv2g" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrqe5a4q29hq2gwtvjduekmg0d7t5pjfjcwx3v8y93h4e5j9nrdnsrygt7k&#39;&gt;nevent1q…gt7k&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-05-15&lt;br/&gt;📝 Original message:On 05/15/2013 12:21 PM, Adam Back wrote:&lt;br/&gt;&amp;gt; On Wed, May 15, 2013 at 08:40:59AM -0400, Caleb James DeLisle wrote:&lt;br/&gt;&amp;gt;&amp;gt; If the commitment is opaque at the time of inclusion in the block then&lt;br/&gt;&amp;gt;&amp;gt; I will create multiple commitments and then after revealing the&lt;br/&gt;&amp;gt;&amp;gt; commitment and spend to you I will reveal the earlier commitment which&lt;br/&gt;&amp;gt;&amp;gt; commits the coins to an address I control.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Bit-commitments are based on deterministic one-way functions eg like SHA1(&lt;br/&gt;&amp;gt; SHA256( public key ) ) Obviously it has to be a different one-way function&lt;br/&gt;&amp;gt; to the coin address calculation which is RIPEMD( SHA256( public key ) ) as&lt;br/&gt;&amp;gt; that is already public.  Alternatively it can be a different serialization&lt;br/&gt;&amp;gt; using the same hash eg RIPEMD( SHA256( 1 || public key ) ).&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Ahh thanks for clearing that up, although it would limit the possibilities&lt;br/&gt;of scripting it is silly of me not to think of it.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; There is only one commitment possible per public key - so you can only&lt;br/&gt;&amp;gt; create one commitment that would validate to a receiver, or to the network. The network checks that there are no non-blind double spends of committed&lt;br/&gt;&amp;gt; coins which it can do as spends require disclosure of the public key, which&lt;br/&gt;&amp;gt; allows existing commitments to be verified, and it similarly qchecks that&lt;br/&gt;&amp;gt; there are no blind double-commitments.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Each committed coin would be:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; one-spend-commit = Com( spender pub ), Com( transaction )&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; where Com is implemented as the above hash.  The network just places the&lt;br/&gt;&amp;gt; commitments in order as with conventional transactions.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; The committed coins are not linkable to your non-blind coin because you did&lt;br/&gt;&amp;gt; not reveal your public key in the (largely passive) act of receiving to a&lt;br/&gt;&amp;gt; coin address.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;&amp;gt; On the topic of reversibility, I suspect in the long term the lack of&lt;br/&gt;&amp;gt;&amp;gt; chargebacks will create issues as criminals learn that for the first&lt;br/&gt;&amp;gt;&amp;gt; time in history, kidnap &amp;amp; ransom is effective. &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; The temporary unlinkability (until commitment reveal) is a necessary side&lt;br/&gt;&amp;gt; effect, not a cryptographic anonymity feature like zerocoin.  The&lt;br/&gt;&amp;gt; transactions are identical to bitcoins once revealed.  How long the&lt;br/&gt;&amp;gt; committed transaction chains can be between reveals is an implementation&lt;br/&gt;&amp;gt; choice could be 1 hop, or as long as you like.  (Actually it appears to be&lt;br/&gt;&amp;gt; up to the individual users how long the maximum chain they accept is - the&lt;br/&gt;&amp;gt; network itself, though ordering the committed spends (if there are multiple&lt;br/&gt;&amp;gt; spends on the same key) cant even tell how long the commitment payment&lt;br/&gt;&amp;gt; chains are).&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Obviously the first coins in the network ordered committed coins on the same&lt;br/&gt;&amp;gt; key up to the coin value are spends as verified by the recipient, the rest&lt;br/&gt;&amp;gt; are double-spend and ignored.  If someone wants to waste fees by sending&lt;br/&gt;&amp;gt; more spends than there inputs thats up to them.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Probably the typical user doesnt care about long committed chains  other&lt;br/&gt;&amp;gt; than their wallet will bloat if the chains are too long, so probably they&lt;br/&gt;&amp;gt; would periodically compact it by revealing the long chains.  Committed coins&lt;br/&gt;&amp;gt; are probably a bit less SPV client friendly, though with correct formatting&lt;br/&gt;&amp;gt; in the merkle trees between blocks, probably a committed coin holder can&lt;br/&gt;&amp;gt; provide enough proof to an SPV client to verify even multi-spend committed&lt;br/&gt;&amp;gt; coins directly (without a network feed).&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; About privacy, up to the entire commitment chain can be opened at any time&lt;br/&gt;&amp;gt; (to other people or to the bitcoin network in general) with the cooperation&lt;br/&gt;&amp;gt; of any user on the chain (up to the point they saw it), so while the blind&lt;br/&gt;&amp;gt; commitment protocol is not vulnerable to a &amp;gt; 50% power quorum unilaterally&lt;br/&gt;&amp;gt; imposed policy (without even needing client updates), it is fully dependent&lt;br/&gt;&amp;gt; on the good will of the recipients for its temporary unlinkability.  Thats&lt;br/&gt;&amp;gt; the point: it puts policy control in the users hands not in the &amp;gt; 50% power&lt;br/&gt;&amp;gt; quorum.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;That is indeed interesting. If I understand this properly Alice commits coins&lt;br/&gt;to pay to Bob and gives Bob the transaction, Bob then commits to pay to Charlie&lt;br/&gt;and gives him the related transaction. If Charlie wants to collect the bitcoin&lt;br/&gt;he then reveals Alice&amp;#39;s transaction and Bob&amp;#39;s.&lt;br/&gt;&lt;br/&gt;I think what you&amp;#39;re trying to do is *almost* possible now (ab)using BIP-0016&lt;br/&gt;In the output of the previous tx you put:&lt;br/&gt;&lt;br/&gt;OP_HASH160 [20-byte-hash-value] OP_EQUAL&lt;br/&gt;&lt;br/&gt;and in the next tx you use a new type of input which specifies it&amp;#39;s value but&lt;br/&gt;not the output which is spent. In the input script you place:&lt;br/&gt;&lt;br/&gt;OP_DUP OP_1ADD OP_HASH160 [20-byte-hash-value] OP_EQUALVERIFY&lt;br/&gt;&lt;br/&gt;Then a serialized script containing the normal stuff as well as the last&lt;br/&gt;transaction hash and output index would be passed around out of band and the&lt;br/&gt;validating nodes would execute each script with a shared stack, beginning with&lt;br/&gt;the out of band one, then the input one (the OP_EQUALVERIFY) then the output.&lt;br/&gt;When the serialized sigscript reaches the bottom of the stack, having been&lt;br/&gt;verified twice, it will now be evaluated as per the rules of P2SH.&lt;br/&gt;&lt;br/&gt;None of this probably works in the real world since I&amp;#39;m not familiar with the&lt;br/&gt;actual implementation of P2SH and it probably has quite a number of things&lt;br/&gt;which will break if used this way but it is interesting to see that in theory&lt;br/&gt;it is possible with little change to the protocol (just a new input format).&lt;br/&gt;&lt;br/&gt;Thanks,&lt;br/&gt;Caleb&lt;br/&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; If you want cryptographic anonymity its better to look to zerocoin.  You may&lt;br/&gt;&amp;gt; have noticed zero coin talked about optional fraud tracing.  Its usually&lt;br/&gt;&amp;gt; trivial to add tracing to an otherwise privay preserving protocol.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; The blind commitment if implemented as described (and its not obvious how to&lt;br/&gt;&amp;gt; get more privacy from it) offers somewhat like community policing.  Users on&lt;br/&gt;&amp;gt; the chain can still themselves do fraud tracing, or any policy they choose,&lt;br/&gt;&amp;gt; on any blind committed coins that they receive.  If they dont like the&lt;br/&gt;&amp;gt; colour of them they can refund them.  The point is to enforce that this is a&lt;br/&gt;&amp;gt; free uncoerced community choice, by individual end users, not a &amp;gt; 50% cpu&lt;br/&gt;&amp;gt; power quorum choice surreptitiously imposed.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Adam&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:01:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstwdrkt2la743z6536j80kvlw7lxs5945kn709ce0j7qzqe7vxwtczyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6muamd3</id>
    
      <title type="html">📅 Original date posted:2013-05-15 📝 Original message:I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstwdrkt2la743z6536j80kvlw7lxs5945kn709ce0j7qzqe7vxwtczyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6muamd3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq885k6ksmtchx89tzxsghuge6gl0m4swftea3r4p0w8dvyarrszc29nr3u&#39;&gt;nevent1q…nr3u&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-05-15&lt;br/&gt;📝 Original message:I can&amp;#39;t see this working, if 51% of the mining power doesn&amp;#39;t like your&lt;br/&gt;coins, when you create the commitment they will reject it.&lt;br/&gt;If the commitment is opaque at the time of inclusion in the block then&lt;br/&gt;I will create multiple commitments and then after revealing the&lt;br/&gt;commitment and spend to you I will reveal the earlier commitment which&lt;br/&gt;commits the coins to an address I control.&lt;br/&gt;&lt;br/&gt;On the topic of reversibility, I suspect in the long term the lack of&lt;br/&gt;chargebacks will create issues as criminals learn that for the first&lt;br/&gt;time in history, kidnap &amp;amp; ransom is effective. Suffice to say after the&lt;br/&gt;first &amp;gt;= $10mn kidnapping-for-bitcoin heist, governments will be forced&lt;br/&gt;to decide how they view the system. It will likely fall somewhere between&lt;br/&gt;&amp;#34;arrest/question anyone identified holding tainted coins&amp;#34; to something&lt;br/&gt;nonsensical and reactionary like &amp;#34;blocking&amp;#34; bitcoin as Iran does TOR.&lt;br/&gt;&lt;br/&gt;Thanks,&lt;br/&gt;Caleb&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;On 05/15/2013 07:49 AM, Adam Back wrote:&lt;br/&gt;&amp;gt; On Wed, May 15, 2013 at 07:19:06AM -0400, Peter Todd wrote:&lt;br/&gt;&amp;gt;&amp;gt; Protocols aren&amp;#39;t set in stone - any attacker that controls enough&lt;br/&gt;&amp;gt;&amp;gt; hashing power to pose a 51% attack can simply demand that you use a&lt;br/&gt;&amp;gt;&amp;gt; Bitcoin client modified [to facilitate evaluation of his policy]&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Protocol voting is a vote per user policy preference, not a CPU vote, which&lt;br/&gt;&amp;gt; is the point.  Current bitcoin protocol is vulnerable to hard to prove&lt;br/&gt;&amp;gt; arbitrary policies being imposable by a quorum of &amp;gt; 50% miners.  The blind&lt;br/&gt;&amp;gt; commitment proposal fixes that, so even an 99% quorum cant easily impose&lt;br/&gt;&amp;gt; policies, which leaves the weaker protocol vote attack as the remaining&lt;br/&gt;&amp;gt; avenue of attack.  That is a significant qualitative improvement.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; The feasibility of protocol voting attacks is an open question, but you&lt;br/&gt;&amp;gt; might want to consider the seeming unstoppability of p2p protocols for a&lt;br/&gt;&amp;gt; hint.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Adam&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; AlienVault Unified Security Management (USM) platform delivers complete&lt;br/&gt;&amp;gt; security visibility with the essential security capabilities. Easily and&lt;br/&gt;&amp;gt; efficiently configure, manage, and operate all of your security controls&lt;br/&gt;&amp;gt; from a single console and one unified framework. Download a free trial.&lt;br/&gt;&amp;gt; &lt;a href=&#34;http://p.sf.net/sfu/alienvault_d2d&#34;&gt;http://p.sf.net/sfu/alienvault_d2d&lt;/a&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:01:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrmqawh25vplt0cvpa4gl3r3tc52u254zdasr5e32n2lxwu5xllygzyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6egh9mq</id>
    
      <title type="html">📅 Original date posted:2013-04-09 📝 Original message:An ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrmqawh25vplt0cvpa4gl3r3tc52u254zdasr5e32n2lxwu5xllygzyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy6egh9mq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsz4ng2ct0vg2ngazskqlvxw69hwq7rrz7deygeyr7ssvk483es8fcwdh67n&#39;&gt;nevent1q…h67n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-04-09&lt;br/&gt;📝 Original message:An approach which I see as workable in the long term is to keep the block&lt;br/&gt;header and an array of bitfields representing each transaction&amp;#39;s spent&lt;br/&gt;and unspent outputs. When someone wants to spend money you ask them for the&lt;br/&gt;transaction and ideally you ask them for the transaction and the merkle branch&lt;br/&gt;from that transaction to the header. If they want to spend the money they have&lt;br/&gt;to carry around the data.&lt;br/&gt;&lt;br/&gt;Agreed on the legality aspect but another case which is worth considering is&lt;br/&gt;what anti-virus software might do when certain streams of bytes are sent across&lt;br/&gt;the tcp socket or persisted to disk. Perhaps worth contacting an AV company and&lt;br/&gt;asking what is the smallest data they have a signature on.&lt;br/&gt;&lt;br/&gt;Thanks,&lt;br/&gt;Caleb&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;On 04/09/2013 06:42 AM, Mike Hearn wrote:&lt;br/&gt;&amp;gt; OK, as the start of that conversation is now on the list, I might as well post the other thoughts we had. Or at least that I had :)&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; It&amp;#39;s tempting to see this kind of abuse through the lens of fees, because we only have a few hammers and so everything looks like a kind of nail. The problem is the moment you try to define &amp;#34;abuse&amp;#34; economically you end up excluding legitimate and beneficial uses as well. Maybe Peters patch for uneconomical outputs is different because of how it works. But mostly it&amp;#39;s true. In this case, fees would never work - Peter said the guy who uploaded Wikileaks paid something like $500 to do it. I guess&lt;br/&gt;&amp;gt; by now it&amp;#39;s more like $600-$700. It&amp;#39;s hard for regular end users to compete with that kind of wild-eyed dedication to &amp;#34;the cause&amp;#34;.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; The root problem here is people believe the block chain is a data structure that will live forever and be served by everyone for free, in perpetuity, and is thus the perfect place for &amp;#34;uncensorable&amp;#34; stuff. That&amp;#39;s a reasonable assumption given how Bitcoin works today. But there&amp;#39;s no reason it will be true in the long run (I know this can be an unpopular viewpoint).&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Firstly, legal issues - I think it&amp;#39;s very unlikely any sane court would care about illegal stuff in the block chain given you need special tools to extract it (mens rea). Besides, I guess most end users will end up on SPV clients as they mature. So these users already don&amp;#39;t have a copy of the entire block chain. I don&amp;#39;t worry too much about this.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Secondly, the need to host blocks forever. In future, many (most?) full nodes will be pruning, and won&amp;#39;t actually store old blocks at all. They&amp;#39;ll just have the utxo database, some undo blocks and some number of old blocks for serving, probably whatever fits in the amount of disk space the user is willing to allocate. But very old blocks will have been deleted. &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; This leads to the question of what incentives people have to not prune. The obvious incentive is money - charge for access to older parts of the chain. The fewer people that host it, the more you can charge. In the worst case scenario where, you know, only 10 different organizations store a copy of the chain, it might mean that bootstrapping a new node in a trust-less manner is expensive. But I really doubt it&amp;#39;d ever get so few. Serving large static datasets just isn&amp;#39;t that expensive. Also, you&lt;br/&gt;&amp;gt; don&amp;#39;t actually need to replay from the genesis block to bring up a new code, you can copy the UTXO database from somewhere else. By comparing the databases of lots of different nodes together, the chances of you being in a matrix-like sybil world can be reduced to &amp;#34;beyond reasonable doubt&amp;#34;. Maybe nodes would charge for copies of their database too, but ideally there are lots of nodes and so the charge for that should be so close to zero as makes no odds - you can trivially undercut someone by&lt;br/&gt;&amp;gt; buying access to the dataset and then reselling it for a bit less, so the price should converge on the actual cost of providing the service. Which will be very cheap.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; There was one last thought I had, which is that if there&amp;#39;s a shorter team need to discourage this kind of thing we can use a network/bandwith related hack by changing the protocol. Nodes can serve up blocks encrypted under a random key. You only get the key when you finish the download. A blacklist can apply to Bloom filtering such that transactions which are known to be &amp;#34;abusive&amp;#34; require you to fully download the block rather than select the transactions with a filter. This means that people&lt;br/&gt;&amp;gt; can still access the data in the chain, but the older it gets the slower and more bandwidth intensive it becomes. Stuffing Wikileaks into the chain sounds good when a 20 line Python script can extract it &amp;#34;instantly&amp;#34;. If someone who wants the files has to download gigabytes of padding around it first, suddenly hosting it on a Tor hidden service becomes more attractive.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Precog is a next-generation analytics platform capable of advanced&lt;br/&gt;&amp;gt; analytics on semi-structured data. The platform includes APIs for building&lt;br/&gt;&amp;gt; apps and a phenomenal toolset for data science. Developers can use&lt;br/&gt;&amp;gt; our toolset for easy data analysis &amp;amp; visualization. Get a free account!&lt;br/&gt;&amp;gt; &lt;a href=&#34;http://www2.precog.com/precogplatform/slashdotnewsletter&#34;&gt;http://www2.precog.com/precogplatform/slashdotnewsletter&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T11:45:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsffnh75cxzrpc0jchvssdxycchste6vl58xgwjw6zj2vvwva36skqzyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy65uyuvu</id>
    
      <title type="html">📅 Original date posted:2011-08-03 🗒️ Summary of this ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsffnh75cxzrpc0jchvssdxycchste6vl58xgwjw6zj2vvwva36skqzyzya47mw9v7tjgs4h36dptfklc49msczaeumv6f4e2afdf4pcfcy65uyuvu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszsaghy2al8qe4pugucglxs09vjxqqhprtx3vr50v9v8v52ejavhg6cgy07&#39;&gt;nevent1q…gy07&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2011-08-03&lt;br/&gt;🗒️ Summary of this message: Discussion on Bitcoin DNS seeds and the need for a custom DNS server that watches the network to find long-lived peers.&lt;br/&gt;📝 Original message:-----BEGIN PGP SIGNED MESSAGE-----&lt;br/&gt;Hash: SHA1&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;On 08/03/2011 07:38 AM, Matt Corallo wrote:&lt;br/&gt;&amp;gt; On Wed, 2011-08-03 at 12:04 &#43;0200, Mike Hearn wrote:&lt;br/&gt;&amp;gt;&amp;gt; This is expected to happen from time to time of course as it&amp;#39;s&lt;br/&gt;&amp;gt;&amp;gt; inherently racy, but there are a lot of bad nodes appearing in the DNS&lt;br/&gt;&amp;gt;&amp;gt; seeds.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;&amp;gt; $ nmap -oG /tmp/x -p 8333 `dig &#43;short bitseed.bitcoin.org.uk&lt;br/&gt;&amp;gt;&amp;gt; dnsseed.bluematt.me bitseed.xf2.org`&lt;br/&gt;&amp;gt;&amp;gt; ...&lt;br/&gt;&amp;gt;&amp;gt; Nmap done: 48 IP addresses (25 hosts up) scanned in 9.80 seconds&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;&amp;gt; $ grep -c &amp;#39;closed&amp;#39; /tmp/x&lt;br/&gt;&amp;gt;&amp;gt; 6&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;&amp;gt; So of 48 IPs returned only 19 are actually usable. This is slowing&lt;br/&gt;&amp;gt;&amp;gt; down peer bringup for the Android apps, which don&amp;#39;t currently save the&lt;br/&gt;&amp;gt;&amp;gt; addresses of last-used peers (yes, I know we should fix this).&lt;br/&gt;&amp;gt; Its actually much, much less.  You forgot to grep for filtered, which&lt;br/&gt;&amp;gt; are also worthless and you didn&amp;#39;t make an actual connection to the node,&lt;br/&gt;&amp;gt; meaning there is no way to tell if the node has its connection slots&lt;br/&gt;&amp;gt; full (a node which has the maximum connection count will ack a syn, but&lt;br/&gt;&amp;gt; will drop the connection after the first message, so nmap thinks the&lt;br/&gt;&amp;gt; port is open).&lt;br/&gt;&amp;gt; I just tested and I show 0 accepting from bitseed.xf2.org and 0 from&lt;br/&gt;&amp;gt; bitcoin.bitcoin.co.uk.  dnsseed.bluematt.me rotates every 2 minutes to&lt;br/&gt;&amp;gt; the most recently checked so it tends to be pretty good if you get it&lt;br/&gt;&amp;gt; right after a rotate, if you wait to long, those slots fill up quick.&lt;br/&gt;&lt;br/&gt;Someone I know who runs a moderately large website told me that some ISPs cache DNS for as long as a week without regard to TTL.&lt;br/&gt;If your DNS seeds are not pointing to your own dedicated boxen then you might want to do a lookup on a random cookie as a subdomain.&lt;br/&gt;&lt;br/&gt;Caleb&lt;br/&gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; I was talking to a friend a few days ago about Bitcoin, he seemed&lt;br/&gt;&amp;gt;&amp;gt; interested. I&amp;#39;m hoping he might take on DNS seeding as a project. A&lt;br/&gt;&amp;gt;&amp;gt; custom DNS server that watches the network to find long-lived peers&lt;br/&gt;&amp;gt;&amp;gt; that run the latest version would be helpful for resolving this kind&lt;br/&gt;&amp;gt;&amp;gt; of thing.&lt;br/&gt;&amp;gt; Point him to &lt;a href=&#34;https://github.com/TheBlueMatt/dnsseed&#34;&gt;https://github.com/TheBlueMatt/dnsseed&lt;/a&gt; it could use a bit&lt;br/&gt;&amp;gt; of cleanup, but it works.&lt;br/&gt;&amp;gt; If a different DNS Server were used to could pull directly from the&lt;br/&gt;&amp;gt; database in a more dynamic way it would probably work better too (it was&lt;br/&gt;&amp;gt; originally set up on MySQL and PowerDNS, but that is quite a resource&lt;br/&gt;&amp;gt; hog compared to SQLite and BIND, but the original backend is still there&lt;br/&gt;&amp;gt; and could work if you have a beefy enough server).&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Matt&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; BlackBerry&amp;amp;reg; DevCon Americas, Oct. 18-20, San Francisco, CA&lt;br/&gt;&amp;gt; The must-attend event for mobile developers. Connect with experts. &lt;br/&gt;&amp;gt; Get tools for creating Super Apps. See the latest technologies.&lt;br/&gt;&amp;gt; Sessions, hands-on labs, demos &amp;amp; much more. Register early &amp;amp; save!&lt;br/&gt;&amp;gt; &lt;a href=&#34;http://p.sf.net/sfu/rim-blackberry-1&#34;&gt;http://p.sf.net/sfu/rim-blackberry-1&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;-----BEGIN PGP SIGNATURE-----&lt;br/&gt;Version: GnuPG v1.4.9 (GNU/Linux)&lt;br/&gt;&lt;br/&gt;iQIcBAEBAgAGBQJOOT64AAoJECYAmptlsgnWNNYP/3pk/61AOaTo8577XF2E3RWU&lt;br/&gt;hqPclOYMveBZveo7Hz0k/Vf3TMf5p7CFGtFllApVmmR5ck4hXwow&#43;tXwaYvBuf9b&lt;br/&gt;4QwDlNtBelZ&#43;7DqOdDTxRjaRzBo7PlsuiEp&#43;6B3&#43;oggfjKWnkWlIighfM/6LOtMO&lt;br/&gt;kv&#43;MsC9xulqCrX96FrQBERVknkvza8NWfVblAFCM0uxECC5Hd52W1Okx1cDqUsIj&lt;br/&gt;MAp6T6IDwy1u0WtYIZBbD3KR802tqTpx/gzElo2AAz4ZR8P9yATBbAjmd9vZDscB&lt;br/&gt;SRF5yg&#43;BIAzTQzz84c0cno8Q6hFyieRLTu9x0AWUqAZPTL3OgYV7hyl9WXMzcQGY&lt;br/&gt;LgnG9hP5N9qn2S&#43;rYJuNJwvTJhzaLgUwOdRgyisI8v86R5vEjOpAAPVStAgCtvw2&lt;br/&gt;6BJJvit3iZ74fK37kPb4iEljd11ibb8rOoiZzKSuS6LMJXkCplQQ06Uhy9MFd/Wn&lt;br/&gt;UZbSwbXqizJmQUPnHfCvvJc9fmoPFbj4SpYagxXFbUXtQsuB84h1e/jKAf5cvRed&lt;br/&gt;n0fLfKBZJuAfK1B/lV8&#43;R6&#43;oJj6F2OSGdCpdGzMlrxKX3JPcDJGK56/JmFzaqXyA&lt;br/&gt;ScaYja4yps83l80zt7H9Fadl642tNWXsdETniyDt2ADnqr1u/nWr9m&#43;aT7oskbZA&lt;br/&gt;SfO&#43;U22w9JC0CW8u5fAa&lt;br/&gt;=7WNK&lt;br/&gt;-----END PGP SIGNATURE-----
    </content>
    <updated>2023-06-07T02:10:44Z</updated>
  </entry>

</feed>