{"type":"rich","version":"1.0","author_name":"npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","author_url":"https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2017-08-22\n📝 Original message:\u003e The initial message I replied to stated:\n\nYes, 3 years is silly.  But coin expiration and quantum resistance is\nsomething I've been thinking about for a while, so I tried to steer the\nconversation away from stealing old money for no reason ;).   Plus I like\nthe idea of making Bitcoin \"2000 year proof\".\n\n- I cannot imagine either SHA256 or any of our existing wallet formats\nsurviving 200 years, if we expect both moores law and quantum computing to\nbe a thing.   I would expect the PoW to be rendered obsolete before the\nBitcoin addresses.\n\n - A PoW change using Keccak and a flexible number of bits can be designed\nas a \"future hard fork\".  That is:  the existing POW can be automatically\nrendered obsolete... but only in the event that difficulty rises to the\nlevel of obsolescence.   Then the code for a new algorithm with a flexible\nnumber of bits and a difficulty that can scale for thousands of years can\nthen automatically kick in.\n\n - A new addresses format and signing protocols that use a flexible number\nof bits can be introduced.   The maximum number of supported bits can be\nconfigurable, and trivially changed.   These can be made immediately\navailable but completely optional.\n\n - The POW difficulty can be used to inform the expiration of any addresses\nthat can be compromised within 5 years assuming this power was somehow used\nto compromise them.   Some mechanism for translating global hashpower to\nbrute force attack power can be researched, and consesrvative estimates\nmade.   Right now, it's like \"heat death of the universe\" amount of time to\ncrack with every machine on the planet.   But hey... things change and 2000\nyears is a long time.   This information can be used to inform the\nexpiration and reclamation of old, compromised public addresses.\n\n- Planning a hard fork 100 to 1000 years out is a fun exercise\n\n\n\n\nOn Tue, Aug 22, 2017 at 2:55 PM, Chris Riley \u003ccriley at gmail.com\u003e wrote:\n\n\u003e The initial message I replied to stated in part, \"Okay so I quite like\n\u003e this idea. If we start removing at height 630000 or 840000 (gives us 4-8\n\u003e years to develop this solution), it stays nice and neat with the halving\n\u003e interval....\"\n\u003e\n\u003e That is less than 3 years or less than 7 years  away. Much sooner than it\n\u003e is believed QC or Moore's law could impact bitcoin.  Changing bitcoin so as\n\u003e to require that early coins start getting \"scavenged\" at that date seems\n\u003e unneeded and irresponsible.  Besides, your ECDSA is only revealed when you\n\u003e spend the coins which does provide some quantum resistance.  Hal was just\n\u003e an example of people putting their coins away expecting them to be there at\n\u003e X years in the future, whether it is for himself or for his kids and wife.\n\u003e\n\u003e :-)\n\u003e\n\u003e\n\u003e\n\u003e On Tue, Aug 22, 2017 at 1:33 PM, Matthew Beton \u003cmatthew.beton at gmail.com\u003e\n\u003e wrote:\n\u003e\n\u003e\u003e Very true, if Moore's law is still functional in 200 years, computers\n\u003e\u003e will be 2^100 times faster (possibly more if quantum computing becomes\n\u003e\u003e commonplace), and so old wallets may be easily cracked.\n\u003e\u003e\n\u003e\u003e We will need a way to force people to use newer, higher security wallets,\n\u003e\u003e and turning coins to mining rewards is better solution than them just being\n\u003e\u003e hacked.\n\u003e\u003e\n\u003e\u003e On Tue, 22 Aug 2017, 7:24 pm Thomas Guyot-Sionnest \u003cdermoth at aei.ca\u003e\n\u003e\u003e wrote:\n\u003e\u003e\n\u003e\u003e\u003e In any case when Hal Finney do not wake up from his 200years\n\u003e\u003e\u003e cryo-preservation (because unfortunately for him 200 years earlier they did\n\u003e\u003e\u003e not know how to preserve a body well enough to resurrect it) he would find\n\u003e\u003e\u003e that advance in computer technology made it trivial for anyone to steal his\n\u003e\u003e\u003e coins using the long-obsolete secp256k1 ec curve (which was done long\n\u003e\u003e\u003e before, as soon as it became profitable to crack down the huge stash of\n\u003e\u003e\u003e coins stale in the early blocks)\n\u003e\u003e\u003e\n\u003e\u003e\u003e I just don't get that argument that you can't be \"your own bank\". The\n\u003e\u003e\u003e only requirement coming from this would be to move your coins about once\n\u003e\u003e\u003e every 10 years or so, which you should be able to do if you have your\n\u003e\u003e\u003e private keys (you should!). You say it may be something to consider when\n\u003e\u003e\u003e computer breakthroughs makes old outputs vulnerable, but I say it's not\n\u003e\u003e\u003e \"if\" but \"when\" it happens, and by telling firsthand people that their\n\u003e\u003e\u003e coins requires moving every once in a long while you ensure they won't do\n\u003e\u003e\u003e stupid things or come back 50 years from now and complain their addresses\n\u003e\u003e\u003e have been scavenged.\n\u003e\u003e\u003e\n\u003e\u003e\u003e --\n\u003e\u003e\u003e Thomas\n\u003e\u003e\u003e\n\u003e\u003e\u003e\n\u003e\u003e\u003e On 22/08/17 10:29 AM, Erik Aronesty via bitcoin-dev wrote:\n\u003e\u003e\u003e\n\u003e\u003e\u003e I agree, it is only a good idea in the event of a quantum computing\n\u003e\u003e\u003e threat to the security of Bitcoin.\n\u003e\u003e\u003e\n\u003e\u003e\u003e On Tue, Aug 22, 2017 at 9:45 AM, Chris Riley via bitcoin-dev \u003c\n\u003e\u003e\u003e bitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e This seems to be drifting off into alt-coin discussion.  The idea that\n\u003e\u003e\u003e\u003e we can change the rules and steal coins at a later date because they are\n\u003e\u003e\u003e\u003e \"stale\" or someone is \"hoarding\" is antithetical to one of the points of\n\u003e\u003e\u003e\u003e bitcoin in that you can no longer control your own money (\"be your own\n\u003e\u003e\u003e\u003e bank\") because someone can at a later date take your coins for some reason\n\u003e\u003e\u003e\u003e that is outside your control and solely based on some rationalization by a\n\u003e\u003e\u003e\u003e third party.  Once the rule is established that there are valid reasons why\n\u003e\u003e\u003e\u003e someone should not have control of their own bitcoins, what other reasons\n\u003e\u003e\u003e\u003e will then be determined to be valid?\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e I can imagine Hal Finney being revived (he was cryo-preserved at Alcor\n\u003e\u003e\u003e\u003e if you aren't aware) after 100 or 200 years expecting his coins to be there\n\u003e\u003e\u003e\u003e only to find out that his coins were deemed \"stale\" so were \"reclaimed\" (in\n\u003e\u003e\u003e\u003e the current doublespeak - e.g. stolen or confiscated).  Or perhaps he\n\u003e\u003e\u003e\u003e locked some for his children and they are found to be \"stale\" before they\n\u003e\u003e\u003e\u003e are available.  He said in March 2013, \"I think they're safe enough\" stored\n\u003e\u003e\u003e\u003e in a paper wallet.  Perhaps any remaining coins are no longer \"safe enough.\"\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Again, this seems (a) more about an alt-coin/bitcoin fork or (b) better\n\u003e\u003e\u003e\u003e in bitcoin-discuss at best vs bitcoin-dev. I've seen it discussed many\n\u003e\u003e\u003e\u003e times since 2010 and still do not agree with the rational that embracing\n\u003e\u003e\u003e\u003e allowing someone to steal someone else's coins for any reason is a useful\n\u003e\u003e\u003e\u003e change to bitcoin.\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e On Tue, Aug 22, 2017 at 4:19 AM, Matthew Beton via bitcoin-dev \u003c\n\u003e\u003e\u003e\u003e bitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\u003e Okay so I quite like this idea. If we start removing at height 630000\n\u003e\u003e\u003e\u003e\u003e or 840000 (gives us 4-8 years to develop this solution), it stays nice and\n\u003e\u003e\u003e\u003e\u003e neat with the halving interval. We can look at this like so:\n\u003e\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\u003e B - the current block number\n\u003e\u003e\u003e\u003e\u003e P - how many blocks behind current the coin burning block is. (630000,\n\u003e\u003e\u003e\u003e\u003e 840000, or otherwise.)\n\u003e\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\u003e Every time we mine a new block, we go to block (B-P), and check for\n\u003e\u003e\u003e\u003e\u003e stale coins. These coins get burnt up and pooled into block B's miner fees.\n\u003e\u003e\u003e\u003e\u003e This keeps the mining rewards up in the long term, people are less likely\n\u003e\u003e\u003e\u003e\u003e to stop mining due to too low fees. It also encourages people to keep\n\u003e\u003e\u003e\u003e\u003e moving their money around the enconomy instead of just hording and leaving\n\u003e\u003e\u003e\u003e\u003e it.\n\u003e\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20170822/7866f6f9/attachment.html\u003e"}
