{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-04-23\n📝 Original message:On Wed, Apr 23, 2014 at 12:59 PM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\u003e\u003e What you're talking about is just disagreement about the content of\n\u003e\u003e the memory pool\n\u003e That's the same thing. Whilst you're mining your double spend tx, it's in\n\u003e your mempool but you don't broadcast it as per normal. Then when you find\n\u003e the block you broadcast it to override everyone elses mempool. So yours and\n\u003e theirs were inconsistent.\n\nThe difference is when you transact.  In the attack Hal described you\ntransact with your victim only after finding a block but before\nannouncing it.\n\n\u003e don't know if they inform you when they found a block (probably not), so you\n\u003e have to do the purchase and then hope BitUndo finds the next block.\n\nRight, this works in the Bitcoin network today absent any collusion by\nthe miners. You give one miner a transaction and you give every other\nnode you can reach another transaction.  You then hope your selected\nminer finds the next block and 'undoes' the transaction you gave the\nrest of the network.\n\n\u003e This just brings us back to square one. Who are these parties and what if I\n\u003e pay them to be corrupt? What if they offer to be corrupt as a service?\n\u003e\n\u003e Let's say I succeed in finding some parties who are incorruptible no matter\n\u003e how large of a percentage I offer them. At this point, why bother with\n\u003e miners at all? Why pay for double spend protection twice, once to a group of\n\u003e Oscar's who are trustworthy and once to a group of miners who are not?\n\u003e\n\u003e The point of the broadcast network and mining is so there can be lots of\n\u003e Oscar's and I don't have to know who they are or sign up with them or put\n\u003e any effort into evaluating their reputation.\n\nBut it isn't at all the same thing.  Miners select themselves based on\ncontrolling hash-power. You can distrust a miner all you like but all\nyour distrust does not prevent him from participating in the\nconsensus, potentially to your detriment.  Moreover, the set of miners\nhas to be the same for everyone or otherwise the network doesn't\nconverge. There are miners I _know_ to be scoundrels, but there is\nnothing I can do about it.\n\nSomeone you ask to not double spend is an entirely separate matter.\nThey aren't self-selecting: you select who you trust to not make\ndouble spends and there is no need for this trust to be globally\nconsistent. If they behave in an untrustworthy way you can instantly\nstop honoring them because the bad action is provable beyond any doubt\nand never trust them again (unlike mempool consistency)... and you can\ndo this even if everyone else is too foolish to do so for some reason.\n\nThe trustworthness of oscars needs only be limited and is different in\nkind from the kind of 'trust' we need over the history— they\narbitrating over the ordering of some subset of transactions right at\nthe tip of the chain, and only those transaction of people who have\nspecifically chosen to use them, of lower value transactions where you\nneed instant settlement.  Why pay twice? Because you're actually\ngetting a different part of your security from each, and the result is\nadditive.\n\nThere is no such thing as an uncorruptable party, invoking that is a\nuseless strawman. Instead we can consider how difficult the corruption\nis and what can happen if they're corrupted and hope to balance the\nrisks and the controls for those risks.  Any self-selectingness as\nanonymity (in the not-previously-enumerated sense) of mining is\nimportant for censorship security but it's terrible for other things\nlike getting reliable mempool behavior.\n\n\u003e But as you point out, cheating my GHash.io did not result in any obvious\n\u003e negative consequence to them, despite that preventing double spending is\n\u003e their sole task. Why would Oscar be different to GHash.io?\n\nBecause you can choose to stop trusting an oscar while you—\nindividually— can't choose anything about ghash.io.  To stop GHash.io\nwe would have to take away their hardware or change the Bitcoin\nprotocol to make their hardware useless, and in the latter case we'd\n_all_ have to agree to do this not just some (perhaps quite large)\nsubset of us who doesn't want to trust them, and even though it is\nquite apparent what they did there is still some room to claim doubt.\n\n\u003e Trying to solve the problem of dishonest miners is effectively trying to\n\u003e solve the \"automatically find trusted third parties\" problem at scale.\n\nMining is universal— everyone must use the same miners, trust seldom\nis seldom universal and shouldn't be. The trust we have in mining is\nexceptionally limited, I think any effort to increase it is doomed to\nfail— both because trust heavy systems stink, because mining is a bad\nfit for trust, and because increasing the requirements create other\nexposures and vulnerabilities."}
