<oembed><type>rich</type><version>1.0</version><author_name>npub10tqt6wdc2neye0cxwyphtre6n5uccgur94khtqjdry9wxhrvywlq6w9uu9</author_name><author_url>https://nostr.ae/npub10tqt6wdc2neye0cxwyphtre6n5uccgur94khtqjdry9wxhrvywlq6w9uu9</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-05-23&#xA;📝 Original message:On 5/23/2017 5:51 AM, Tier Nolan via bitcoin-dev wrote:&#xA;&gt; On Mon, May 22, 2017 at 9:00 PM, Paul Sztorc &lt;truthcoin at gmail.com&#xA;&gt; &lt;mailto:truthcoin at gmail.com&gt;&gt; wrote:&#xA;&gt; &#xA;&gt;     I would replace &#34;Bitcoins you manage to steal&#34; with &#34;Bitcoins you&#xA;&gt;     manage to double-spend&#34;. Then, it still seems the same to me.&#xA;&gt; &#xA;&gt; &#xA;&gt; With double spending, you can only get ownership of coins that you owned&#xA;&gt; at some point in the past.  Coins that are owned by someone else from&#xA;&gt; coinbase to their current owners cannot be stolen by a re-org (though&#xA;&gt; they can be moved around).&#xA;&#xA;I&#39;m not sure it makes much of a difference. First of all, in point of&#xA;fact, the miners themselves own the coins from the coinbase. But more&#xA;importantly, even if miners did not explicitly own the coins, they might&#xA;profit by being bribed -- these bribes would come from people who did&#xA;own the coins.&#xA;&#xA;The principle is that value &#34;v&#39; has been taken from A and given to B.&#xA;This is effectively coercive activity, and therefore itself has value&#xA;proportional to &#39;v&#39;.&#xA;&#xA;&gt; &#xA;&gt; With BMM, you can take the entire reserve.  Creating a group of double&#xA;&gt; spenders can help increase the reward.&#xA;&gt;  &#xA;&gt; &#xA;&gt; &#xA;&gt;     It may destroy great value if it shakes confidence in the sidechain&#xA;&gt;     infrastructure. Thus, the value of the stolen BTC may decrease, in&#xA;&gt;     addition to the lost future tx fee revenues of the attacked chain.&#xA;&gt; &#xA;&gt;     http://www.truthcoin.info/blog/drivechain/#drivechains-security&#xA;&gt;     &lt;http://www.truthcoin.info/blog/drivechain/#drivechains-security&gt;&#xA;&gt; &#xA;&gt; &#xA;&gt; That is a fair point.  If sidechains are how Bitcoin is scaled, then&#xA;&gt; shaking confidence in a side-chain would shake confidence in Bitcoin&#39;s&#xA;&gt; future.&#xA;&#xA;Yes. The more value _on_ the sidechain, the more abhorrent the malfeasance.&#xA;&#xA;&gt; &#xA;&gt; I wasn&#39;t thinking of a direct miner 51% attack.  It is enough to assume&#xA;&gt; that a majority of the miners go with the highest bidder each time.&#xA;&#xA;What do you think of my argument, that we already labor under such an&#xA;assumption? An attacker could pay fees today equal to greater than&#xA;sum(blockreward_(last N block)). According to you this would force a&#xA;reorg, even on mainchain (pre-sidechain) Bitcoin. Yet this has never&#xA;happened.&#xA;&#xA;It seems that this argument fully reduces to the &#34;what will happen when&#xA;the block subsidy falls to zero&#34; question.&#xA;&#xA;&gt; &#xA;&gt; If (average fees) * (timeout) is less than the total reserves, then it&#xA;&gt; is worth it for a 3rd party to just bid for his theft fork.  Miners&#xA;&gt; don&#39;t have to be assumed to be coordinating, they just have to be&#xA;&gt; assumed to take the highest bid.&#xA;&gt; &#xA;&gt;     Again, I don&#39;t really think it is that different. One could&#xA;&gt;     interchange &#34;recent txns&#34; (those which could be double-spent within&#xA;&gt;     2-3 weeks) with &#34;sidechain deposit tnxs&#34;.&#xA;&gt; &#xA;&gt; &#xA;&gt; It is not &#34;recent txns&#34;, it is recent txns that you (or your group) have&#xA;&gt; the key for.  No coordination is required to steal the entire reserve&#xA;&gt; from the sidechain.&#xA;&#xA;See above (?) for why I still feel they are comparable, if not identical.&#xA;&#xA;&gt; &#xA;&gt; Recent txns and money on the sidechain have the property that they are&#xA;&gt; riskier than money deep on the main chain.  This is the inherent point&#xA;&gt; about sidechains, so maybe not that big a deal. &#xA;&#xA;Yes. Sidechains have newer, more interesting features, and&#xA;simultaneously more risk.&#xA;&#xA;&#xA;&gt; &#xA;&gt; My concern is that you could have a situation where an attack is&#xA;&gt; possible and only need to assume that the miners are indifferent.&#xA;&#xA;Again, I think that we _already_ need to eliminate any assumption of&#xA;&#34;charitable miners&#34;.&#xA;&#xA;&gt; &#xA;&gt; If the first attacker who tries it fails (say after creating a fork that&#xA;&gt; is 90% of the length required, so losing a lot of money), then it would&#xA;&gt; discourage others.   If he succeeds, then it weakens sidechains as a&#xA;&gt; concept and that creates the incentive for miners to see that he fails.&#xA;&gt; &#xA;&gt; I wonder how the incentives work out.  If a group had 25% of the money&#xA;&gt; on the sidechain, they could try to outbid the attacker.&#xA;&#xA;Yes, we may see interesting behavior where people buy up these&#xA;liabilities using the LN. In my original post, I mention that miners&#xA;themselves may purchase these liabilities (at competitive rates, even if&#xA;these arent the idealized 1:1). At this point, miners would be paying&#xA;themselves and there would be no agency problem.&#xA;&#xA;&gt; &#xA;&gt; In fact, since the attacker, by definition, creates an illegal fork, the&#xA;&gt; effect is that he reduces the block rate for the side chain (possibly to&#xA;&gt; zero, if he wins every auction).  This means that there are more&#xA;&gt; transactions per block, if there is space, or more fees per transaction,&#xA;&gt; if the blocks are full. &#xA;&gt; &#xA;&gt; In both cases, this pushes up the total fees per block, so he has to pay&#xA;&gt; more per block, weakening his attack.  This is similar to where&#xA;&gt; transaction spam on Bitcoin is self-correcting by increasing the fees&#xA;&gt; required to keep the spam going.&#xA;&gt; &#xA;&gt; Is there a description of the actual implementation you decided to go&#xA;&gt; with, other than the code?&#xA;&#xA;If you haven&#39;t seen http://www.truthcoin.info/blog/drivechain/ , that is&#xA;probably the most human-readable description.&#xA;&#xA;Cheers,&#xA;Paul</html></oembed>