{"type":"rich","version":"1.0","author_name":"npub1qf6k0f8p0h89d43l0vnx2xp5yrfgjyl8tg3hkg8jtyudrllgw2usdlfn9a","author_url":"https://nostr.ae/npub1qf6k0f8p0h89d43l0vnx2xp5yrfgjyl8tg3hkg8jtyudrllgw2usdlfn9a","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-06-19\n📝 Original message:-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA512\n\nOn 2015-06-19 15:37, Eric Lombrozo wrote:\n\u003e OK, a few things here:\n\u003e \n\u003e The Bitcoin network was designed (or should be designed) with the\n\u003e requirement that it can withstand deliberate double-spend attacks that\n\u003e can come from anywhere at any time…and relaxing this assumption\n\u003e without adequately assessing the risk (i.e. I’ve never been hacked\n\u003e before so I can assume it’s safe) is extremely dangerous at best and\n\u003e just horrid security practice at worst. Your users might not thank you\n\u003e for not getting hacked - but they surely will not like it when you DO\n\u003e get hacked…and lack a proper recovery plan.\n\u003e \n\u003e Furthermore, the protocol itself makes no assumptions regarding the\n\u003e intentions behind someone signing two conflicting transactions. There\n\u003e are many potential use cases where doing so could make a lot of sense.\n\u003e Had the protocol been designed along the lines of, say,\n\u003e tendermint…where signing multiple conflicting blocks results in loss\n\u003e of one’s funds…then the protocol itself disincentivizes the behavior\n\u003e without requiring any sort of altruistic, moralistic assumptions. That\n\u003e would also mean we’d need a different mechanism for the use cases that\n\u003e things like RBF address.\n\u003e \n\u003e Thirdly, taken to the extreme, the viewpoint of “signing a conflicting\n\u003e transaction is fraud and vandalism” means that if for whatever reason\n\u003e you attempt to propagate a transaction and nobody mines it for a very\n\u003e long time, you’re not entitled to immediately reclaim those funds…they\n\u003e must remain in limbo forever.\n\nI'm not talking about changing the protocol - I'm talking about the \nbusiness relationships between users of Bitcoin.\n\nI would expect a payment processor to inform the merchants of relevant \ndouble spends that it observes on the network, even if the payment is \nactually successful, so that the merchant can decide for themselves \nwhether or not to pursue it out of band.\n\nMining is a kind of technical fallback that allows the network to \nresolve human misbehavior without human intervention. If nobody ever \nattempted to make a fraudulent payment, we wouldn't need mining at all \nbecause the signed transaction itself is proof of intention to pay. That \nit exists doesn't suddenly make fraud less fraudulent and mean that \nusers who are in a position to pursue out of band recourse shouldn't do \nso.\n\nI agree that there are valid reasons for replacing transactions in the \nmempool, I just think they should be implemented in a way that doesn't \nfacilitate fraud.\n\nI'd also like to note that \"prima facie\" doesn't mean \"always\", it means \nthat \"the default assumption, unless proven otherwise.\"\n\n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v2\n\niQIcBAEBCgAGBQJVhDqcAAoJECpf2nDq2eYjX/UP/RlVIGqzwvdKftFW8kRW1+Dk\n3befE2vEIEWFAShNt0pk7/Isqk7prRWQDKP+VNZSJfaoyE3akOe7s3OPWuevVRqM\nY1N658hYnG6NPebkyp5zUQkjT3mXVxOo9Fw9k7JyHgkWaDcwx330z2n6yztleodq\n7hlKdW6sZrgqHw+DoF0Zal3QPN0WYm0XAno3uy71RXOs5cAoUxViuVzWHY0oReTQ\nuggTggT1A5acmyOM7v65h9Cb2AKcLvHKfSEIwVQbHxYMOT+3GIJOXPKAluh8MjB3\noWg8ERy5dEEHu5kF/MLPQMg5yVQACuQmO2dlmtRoOs3mUQQj+q7dEil/dZMIp0f+\nunDKIwLhXMa0sZ+63123UOgaKGZkF7afed3ueniJWQM80VS0WoZvZYhQadT/sCED\nNtfxifi1ZqCiKFeshyN9z7jDC8QEJ3N176Kr/wX76h/vvnPYicMEcfRgSE8EGd10\n+oRQQpYzb69WPSFRhhrR3yG9Dev1JfzNPEaIKKYerDk9Vo3OnQ3VaaqBNZwBDo46\n4r3O5orFES/ZxMdzWE1cWp99n4T4L6KxdZXmfQSYHehUJBnt62vKuEk9X/Li2ZWo\ni3dr3yxx8xhKGGjsSjG03arz70bkXE7SvrICPOs9OEAdGlJI2liLrSWzYU9BbTle\neWvElyVQJsJHgAU8ygvn\n=77NP\n-----END PGP SIGNATURE-----"}
