{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-04-23\n📝 Original message:On Wed, Apr 23, 2014 at 12:19 PM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\u003e That's the definition of a Finney attack, right?\n\nA finney attack is where you attempt to mine a block with a\ntransaction paying you, and as soon as you are successful you quickly\nmake a transaction spending that coin to someone else, then release\nthe block after they've taken an irreversible action. If everything is\nautomated it should have something like a 99% success rate, though it\nhas a cost of some small increase in the number of orphan blocks you\nexperience.\n\n\u003e I mean, I hope that's the definition of a Finney attack, given that I coined\n\u003e the term :)\n\nYou might have coined the term, but I don't think the attack you're\ndescribing is the attack Hal described:\nhttps://bitcointalk.org/index.php?topic=3441.msg48384#msg48384\n\nWhat you're talking about is just disagreement about the content of\nthe memory pool, but we have no consensus mechanism there (the\nblockchain _is_ the consensus mechanism).  Mempools are sometimes\ninconsistent all on their own, without any attacker being involved.\n\n\u003e These sorts of proposals are all just ways of saying block chains kind of\n\u003e suck and we should go back to using trusted third parties.\n\nI think thats an unsophisticated view.\n\nConsider this protocol.\n\nI take some of my funds and assign them to a 2 of 2 multisig with\nmyself and Oscar. I do not announce this transaction until I get Oscar\nto sign a timelocked anyonecanpay refund to send the coin back to me\n(say in 3 months).  Oscar gives me my refund and I announce the\ntransaction.\n\nLater I can make instant payments with oscar signing up until the\nrefund time comes clue to anyone who trusts Oscar to never double\nspend.  For the receiver this is purely additive with regular\nblockchain security: in that even with Oscar's help I cannot double\nspend except where I would have been successful absent Oscar. On the\nsender side, Oscar cannot up and steal my funds and he can't try to\nextort me (except by creating a delay up to the refund time).\n\nOscar himself can be implemented as a majority M parties to further\nincrease confidence, though if you're talking about using this for low\nvalue retail transactions— the fact that any cheating by oscar is\ncryptographically provable (just show them the double signatures)\nmaybe be strong enough alone. (Though there is a multitude of other\nproposals to provide more evidence of Oscar's honesty). There are also\nways to blind Oscar so he can't reliably identify which transactions\nare ones he signed for.\n\nI don't think this is at all a \"return to trusted third parties\"— that\nit's a shrug and an admission of defeat. Its a very narrowly scoped\ntrust, filling in precisely where large scale decentralized consensus\nis fundamentally weak... the result is something which combines\nadvantages from both classes and is stronger than either trust or\nblockchains alone.  (I'm also not trying to say that an implementation\nof this is _simple_ by any means, working out all the details is\nhard.)\n\nBy contrast, I think proposals which overly depend on colluding miners\nto behave in very specific ways are themselves just a way of saying\nblock chains suck unless we turn the miners themselves into a trusted\nthird party. I'm much more in favor of adding a little bit of\nmastercard to transactions where mastercard is really what people\nwant, than turning mining— and thus bitcoin itself— into mastercard,\nespecially since miners— self selecting as they are— are a pretty poor\nset of parties to act as trusted agents. :)\n\n\u003e\u003e Doubly so because a 'nasty' party with non-trivial hash-power can\n\u003e\u003e doublespend their own transactions\n\u003e If a miner is vertically integrated and defrauding merchants themselves,\n\u003e with no service component, pretty quickly people would talk to each other,\n\u003e notice this pattern and stop trading with them, making their coins rather\n\u003e useless. Also if their real identity is ever revealed they could be liable\n\u003e and there'd be a lot of people wanting to sue them.\n\nWe have an existence proof that it isn't so— you can say that it\nwasn't consistent enough, but what is? There wasn't any major doubt\nthat they were actually doing it. They're the largest identifiable\npool as we speak.\n\nI think, instead, that strong zero-conf security isn't a part of what\nmany people think of when they think of Bitcoin's characteristics.\nZero conf is risky, and I think for a lot of people thats okay.  If it\nisn't there are ways to improve it that don't involve asking miners to\nparticipate in a majority vote to take away funds from people."}
