{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-04-23\n📝 Original message:On Wed, Apr 23, 2014 at 12:55 AM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\u003e Lately someone launched Finney attacks as a service (BitUndo). As a reminder\n\u003e for newcomers, Finney attacks are where a miner secretly works on a block\n\u003e containing a double spend.\n\nHm? I didn't think this is at all what they did.  What they claim to\ndo is to prioritize transactions in their mempool from people who pay\nthem, potentially over and above other transactions which they may or\nmay not have received first.\n\nThis may still be bad news for someone taking an irreversible action\nin response to an unconfirmed payment and it may or may not be really\nill advised in general, but I think it's less sinister than it sounds\nin your posts.  Is there some reason to believe it isn't what it\nclaims to be?\n\nI think we have very clear evidence that the Bitcoin community doesn't\ncare if miners reorder transactions in their mempool to profitable\nends: In https://bitcointalk.org/index.php?topic=327767.0 it's\ndemonstrated that GHash.IO, currently the largest publicly identified\npool was used to rip off Betcoin dice via double-spends.\n\n\u003e first started using Bitcoin, nowadays most of my purchases with it are for\n\u003e food and drink. If Bitcoin could not support such purchases, I would use it\n\u003e much less.\n\nAccepting zero-conf inherently has some risk (well, so does all\nbusiness, but there is substantially more in a zero-conf payment).\nEven in a spherical-cow Bitcoin absent anything like Bitundo someone\ncan just give a double spend to a large miner and currently give the\nwhole rest of the network the one paying the merchant.  They will,\nwith high success rate be successful.   Worse, it may _appear_ to the\nnetwork that the miner was a \"bitundo\" but they really were not.   The\nblockchain exists to establish consensus ordering, prior to the\nblockchain there is no order, and so it is not easy to really say\nwhich transaction came first in any meaningful sense.\n\nBut in business we balance risks and the risk that sometimes a\ntransaction will be reversed exists in every electronic payment system\navailable today, in most of them the risk persists for _months_ rather\nthan minutes.  Businesses can still operate in the face of these\nrisks.\n\nMore importantly, it's possible to deploy technological approaches to\nmake zero-conf very secure against reversal: Things like performing\nmulti-sig with a anti-double-spending system, or using an external\nfederated payment network... but this stuff requires substantial\ndevelopment work— though it's not work thats likely to happen if\npeople are still confused about the level of security that zero-conf\nhas.\n\n\u003e Miners can vote to reallocate the coinbase value of bad blocks before they\n\u003e mature.\n\nI think miners 'voting' to reallocate coins, even if they're\nthoroughly convinced that the owner of the coins is a nasty party, is\na much greater violation of the Bitcoin social contract than some\ntwiddling with the unspecified unconfirmed transaction ordering.\n\nDoubly so because a 'nasty' party with non-trivial hash-power can\ndoublespend their own transactions with a pretty good success rate (as\nwas the case for the GHash.io betcoin spends) including not-just\nzero-conf (though with obviously reduced effectiveness), and all of\nyour reliable detection depends on it being a public service.\n\nA much better defense is having the control of hash power very well\ndistributed and so there isn't any central point that excerts enough\ninfluence to change the risk statistics much.  Giving miners the\nability to steal each others payments is, if anything, a force away\nfrom that decentralization."}
