{"type":"rich","version":"1.0","author_name":"npub10tqt6wdc2neye0cxwyphtre6n5uccgur94khtqjdry9wxhrvywlq6w9uu9","author_url":"https://nostr.ae/npub10tqt6wdc2neye0cxwyphtre6n5uccgur94khtqjdry9wxhrvywlq6w9uu9","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2017-05-23\n📝 Original message:On 5/23/2017 5:51 AM, Tier Nolan via bitcoin-dev wrote:\n\u003e On Mon, May 22, 2017 at 9:00 PM, Paul Sztorc \u003ctruthcoin at gmail.com\n\u003e \u003cmailto:truthcoin at gmail.com\u003e\u003e wrote:\n\u003e \n\u003e     I would replace \"Bitcoins you manage to steal\" with \"Bitcoins you\n\u003e     manage to double-spend\". Then, it still seems the same to me.\n\u003e \n\u003e \n\u003e With double spending, you can only get ownership of coins that you owned\n\u003e at some point in the past.  Coins that are owned by someone else from\n\u003e coinbase to their current owners cannot be stolen by a re-org (though\n\u003e they can be moved around).\n\nI'm not sure it makes much of a difference. First of all, in point of\nfact, the miners themselves own the coins from the coinbase. But more\nimportantly, even if miners did not explicitly own the coins, they might\nprofit by being bribed -- these bribes would come from people who did\nown the coins.\n\nThe principle is that value \"v' has been taken from A and given to B.\nThis is effectively coercive activity, and therefore itself has value\nproportional to 'v'.\n\n\u003e \n\u003e With BMM, you can take the entire reserve.  Creating a group of double\n\u003e spenders can help increase the reward.\n\u003e  \n\u003e \n\u003e \n\u003e     It may destroy great value if it shakes confidence in the sidechain\n\u003e     infrastructure. Thus, the value of the stolen BTC may decrease, in\n\u003e     addition to the lost future tx fee revenues of the attacked chain.\n\u003e \n\u003e     http://www.truthcoin.info/blog/drivechain/#drivechains-security\n\u003e     \u003chttp://www.truthcoin.info/blog/drivechain/#drivechains-security\u003e\n\u003e \n\u003e \n\u003e That is a fair point.  If sidechains are how Bitcoin is scaled, then\n\u003e shaking confidence in a side-chain would shake confidence in Bitcoin's\n\u003e future.\n\nYes. The more value _on_ the sidechain, the more abhorrent the malfeasance.\n\n\u003e \n\u003e I wasn't thinking of a direct miner 51% attack.  It is enough to assume\n\u003e that a majority of the miners go with the highest bidder each time.\n\nWhat do you think of my argument, that we already labor under such an\nassumption? An attacker could pay fees today equal to greater than\nsum(blockreward_(last N block)). According to you this would force a\nreorg, even on mainchain (pre-sidechain) Bitcoin. Yet this has never\nhappened.\n\nIt seems that this argument fully reduces to the \"what will happen when\nthe block subsidy falls to zero\" question.\n\n\u003e \n\u003e If (average fees) * (timeout) is less than the total reserves, then it\n\u003e is worth it for a 3rd party to just bid for his theft fork.  Miners\n\u003e don't have to be assumed to be coordinating, they just have to be\n\u003e assumed to take the highest bid.\n\u003e \n\u003e     Again, I don't really think it is that different. One could\n\u003e     interchange \"recent txns\" (those which could be double-spent within\n\u003e     2-3 weeks) with \"sidechain deposit tnxs\".\n\u003e \n\u003e \n\u003e It is not \"recent txns\", it is recent txns that you (or your group) have\n\u003e the key for.  No coordination is required to steal the entire reserve\n\u003e from the sidechain.\n\nSee above (?) for why I still feel they are comparable, if not identical.\n\n\u003e \n\u003e Recent txns and money on the sidechain have the property that they are\n\u003e riskier than money deep on the main chain.  This is the inherent point\n\u003e about sidechains, so maybe not that big a deal. \n\nYes. Sidechains have newer, more interesting features, and\nsimultaneously more risk.\n\n\n\u003e \n\u003e My concern is that you could have a situation where an attack is\n\u003e possible and only need to assume that the miners are indifferent.\n\nAgain, I think that we _already_ need to eliminate any assumption of\n\"charitable miners\".\n\n\u003e \n\u003e If the first attacker who tries it fails (say after creating a fork that\n\u003e is 90% of the length required, so losing a lot of money), then it would\n\u003e discourage others.   If he succeeds, then it weakens sidechains as a\n\u003e concept and that creates the incentive for miners to see that he fails.\n\u003e \n\u003e I wonder how the incentives work out.  If a group had 25% of the money\n\u003e on the sidechain, they could try to outbid the attacker.\n\nYes, we may see interesting behavior where people buy up these\nliabilities using the LN. In my original post, I mention that miners\nthemselves may purchase these liabilities (at competitive rates, even if\nthese arent the idealized 1:1). At this point, miners would be paying\nthemselves and there would be no agency problem.\n\n\u003e \n\u003e In fact, since the attacker, by definition, creates an illegal fork, the\n\u003e effect is that he reduces the block rate for the side chain (possibly to\n\u003e zero, if he wins every auction).  This means that there are more\n\u003e transactions per block, if there is space, or more fees per transaction,\n\u003e if the blocks are full. \n\u003e \n\u003e In both cases, this pushes up the total fees per block, so he has to pay\n\u003e more per block, weakening his attack.  This is similar to where\n\u003e transaction spam on Bitcoin is self-correcting by increasing the fees\n\u003e required to keep the spam going.\n\u003e \n\u003e Is there a description of the actual implementation you decided to go\n\u003e with, other than the code?\n\nIf you haven't seen http://www.truthcoin.info/blog/drivechain/ , that is\nprobably the most human-readable description.\n\nCheers,\nPaul"}
