{"type":"rich","version":"1.0","author_name":"npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt","author_url":"https://nostr.ae/npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-02-12\n📝 Original message:Den 12 feb 2015 14:44 skrev \"Mike Hearn\" \u003cmike at plan99.net\u003e:\n\u003e\u003e\n\u003e\u003e You can prove a doublespend instantly by showing two conflicting\ntransactions both signed by thar party. This pair can be distributed as a\nproof of malice globally in seconds via a push messaging mechanism.\n\u003e\n\u003e There have been lots of e-cash schemes proposed in the academic\nliterature that work like this, or variants of it. Schemes where\nparticipants are anonymous until they double spend are popular.\n\u003e\n\u003e Let's re-write your proposal but substituting the word notary for miner:\n\u003e\n\u003e\u003e To profit, the miner would have to be sure the payout from agreeing on\ncollusion (or to perform the doublespend themselves) would pay out better\nthan acting honestly for a given amount of time info the future. This means\ntransactions for small sums are secure.\n\u003e\n\u003e That's the exact argument we're having. The assertion is that a\n\"rational\" notary would kill his own business to increase his profits in\nthe next few hours. So you're just arguing that a notary is different to a\nminer, without spelling out exactly why.\n\u003e\n\u003e Does the notary have to make a big up front investment? If so, why is\nthat different to mining investment?\n\nMiners are transient. You don't depend on any given subset of them.\nCentralized e-currency give you no choice but to trust one set of notaries.\n\nThe notary don't have any large maintenance costs. The initial investment\nis small, they don't need more than a few servers and maybe a HSM and some\noffice. In the non-collateral version, they're a centralized entity. Note\nthat in the fully centralized model, if the notary goes bad you're screwed.\nYour tokens are useless or maybe gone.\n\nEssentially you can't know if you're up for the long con or not.\n\nAnybody can set up a miner with capital investments. No individual miner\nhas a large impact on the system as a whole.\n\nIn Bitcoin, you aren't dependent on any one multisignature notary. One\ngoing gown only represents a small loss and done temporarily locked funds.\nAnybody can set up a multisignature notary, but people won't trust you\nunless you show you're trustable - you need to market yourself to get to\nthe point where a malicious doublespend can be profitable.\n\nYou can't really replicate the collateralized multisignature notary model\nin centralized systems. Because having the e-currency bank be the notary\nmeans they have the same powers a 51% miner would have - they can block the\ntransaction claiming the collateral, they can censor any other transactions\nat will, and all your funds depend on them and the market's trust in them.\n\n\u003e Is the notary non-anonymous and afraid of being charged with payment\nfraud? If so, note that big miners do lots of non-anonymous things too,\nlike renting warehouses and importing specialised equipment.\n\nAs notaries can be small operations, they can perform the doublespend as\nthey escape across the border.\n\n\u003e Is it because of the big up front collateral they're meant to have lying\naround? If so, how do you ensure a fluid market for notaries?\n\nWith collateralized multisignature notaries, my assumption is that\norganizations that are related to Bitcoin transactions that has sufficient\nsums of unallocated funds would use them for collateral in a scheme like\nthis (almost every large organization in the world have some unallocated\nfunds somewhere).\n\nAs sellers have almost no risk of losing money to them, any notary backed\nby somebody they know and trust would be good enough\n\nAs buyers also have no risk, they'd use them when they want to make quick\npayments.\n\n-----\n\nYou seem to be making a lot of arguments from the status quo. I don't care\nwhat people have been doing, preserving every habit isn't a sacred goal. I\ncare about stable incentives and long term predictability regarding what\nbehavior is safe. Behavior that becomes unsafe if incentives change is bad\nand shouldn't be relied on.\n\nAlso, Bitcoin is the concensus mechanism. As mentioned, trying to provide a\nguarantee for what will end up in the blocks without servers involved is to\nreinvent Bitcoin within Bitcoin. I can go Xzibit on you all day long if you\nlike!  What you consider an attack is irrelevant. You assume a certain\nbehavior is desired without first making sure it is reliable.\n\nDepending on that which isn't guaranteed is baaaad, and breaking other\npeople's assumptions is by itself NOT an attack if there never was a\nguarantee or even as little as an implicit understanding it is safe.\n\nYour also assume people will expect the Bitcoin network to keep zero-conf\nsafe forever and that Bitcoin valuation is tied to that. Given the options\navailable and current state of things, I'm assuming that's wrong.\n\nBesides, zero-conf will never be secure if you don't add external\ncontextual information as a requirement when validating blocks. Otherwise\ndefecting miners will frequently doublespend against you. And adding such\ninformation is messy and probably not secure in itself, as it opens up for\ngaming the system through network level attacks.\n\nAnd your remarks against game theory seems unwarranted.\n\nThe game theorists that are wrong are typically wrong for one of the\nfollowing reasons;\n\n* Their model is wrong. The system, the actors and/or the options available\nare misunderstood.\n* The actors don't understand the avaliable incentives and go for trial and\nerror (the most optimal choices for attack and defense are found at random\nor not at all, and not always adopted until it has stood the test of time).\n* That option is on the to-do list, just wait.\n* There's easier and/or more profitable attacks (a variant of #1 if the\ngame theorist said it is certain to happen).\n\nYou should NOT EVER rely on security-through-opportunity-cost for the\nattacker or assume you can always keep doing what you always did. Once the\nbigger targets are gone, you're next.\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150212/2ad0cc1c/attachment.html\u003e"}
