<oembed><type>rich</type><version>1.0</version><author_name>npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt</author_name><author_url>https://nostr.ae/npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-02-12&#xA;📝 Original message:Den 12 feb 2015 14:44 skrev &#34;Mike Hearn&#34; &lt;mike at plan99.net&gt;:&#xA;&gt;&gt;&#xA;&gt;&gt; You can prove a doublespend instantly by showing two conflicting&#xA;transactions both signed by thar party. This pair can be distributed as a&#xA;proof of malice globally in seconds via a push messaging mechanism.&#xA;&gt;&#xA;&gt; There have been lots of e-cash schemes proposed in the academic&#xA;literature that work like this, or variants of it. Schemes where&#xA;participants are anonymous until they double spend are popular.&#xA;&gt;&#xA;&gt; Let&#39;s re-write your proposal but substituting the word notary for miner:&#xA;&gt;&#xA;&gt;&gt; To profit, the miner would have to be sure the payout from agreeing on&#xA;collusion (or to perform the doublespend themselves) would pay out better&#xA;than acting honestly for a given amount of time info the future. This means&#xA;transactions for small sums are secure.&#xA;&gt;&#xA;&gt; That&#39;s the exact argument we&#39;re having. The assertion is that a&#xA;&#34;rational&#34; notary would kill his own business to increase his profits in&#xA;the next few hours. So you&#39;re just arguing that a notary is different to a&#xA;miner, without spelling out exactly why.&#xA;&gt;&#xA;&gt; Does the notary have to make a big up front investment? If so, why is&#xA;that different to mining investment?&#xA;&#xA;Miners are transient. You don&#39;t depend on any given subset of them.&#xA;Centralized e-currency give you no choice but to trust one set of notaries.&#xA;&#xA;The notary don&#39;t have any large maintenance costs. The initial investment&#xA;is small, they don&#39;t need more than a few servers and maybe a HSM and some&#xA;office. In the non-collateral version, they&#39;re a centralized entity. Note&#xA;that in the fully centralized model, if the notary goes bad you&#39;re screwed.&#xA;Your tokens are useless or maybe gone.&#xA;&#xA;Essentially you can&#39;t know if you&#39;re up for the long con or not.&#xA;&#xA;Anybody can set up a miner with capital investments. No individual miner&#xA;has a large impact on the system as a whole.&#xA;&#xA;In Bitcoin, you aren&#39;t dependent on any one multisignature notary. One&#xA;going gown only represents a small loss and done temporarily locked funds.&#xA;Anybody can set up a multisignature notary, but people won&#39;t trust you&#xA;unless you show you&#39;re trustable - you need to market yourself to get to&#xA;the point where a malicious doublespend can be profitable.&#xA;&#xA;You can&#39;t really replicate the collateralized multisignature notary model&#xA;in centralized systems. Because having the e-currency bank be the notary&#xA;means they have the same powers a 51% miner would have - they can block the&#xA;transaction claiming the collateral, they can censor any other transactions&#xA;at will, and all your funds depend on them and the market&#39;s trust in them.&#xA;&#xA;&gt; Is the notary non-anonymous and afraid of being charged with payment&#xA;fraud? If so, note that big miners do lots of non-anonymous things too,&#xA;like renting warehouses and importing specialised equipment.&#xA;&#xA;As notaries can be small operations, they can perform the doublespend as&#xA;they escape across the border.&#xA;&#xA;&gt; Is it because of the big up front collateral they&#39;re meant to have lying&#xA;around? If so, how do you ensure a fluid market for notaries?&#xA;&#xA;With collateralized multisignature notaries, my assumption is that&#xA;organizations that are related to Bitcoin transactions that has sufficient&#xA;sums of unallocated funds would use them for collateral in a scheme like&#xA;this (almost every large organization in the world have some unallocated&#xA;funds somewhere).&#xA;&#xA;As sellers have almost no risk of losing money to them, any notary backed&#xA;by somebody they know and trust would be good enough&#xA;&#xA;As buyers also have no risk, they&#39;d use them when they want to make quick&#xA;payments.&#xA;&#xA;-----&#xA;&#xA;You seem to be making a lot of arguments from the status quo. I don&#39;t care&#xA;what people have been doing, preserving every habit isn&#39;t a sacred goal. I&#xA;care about stable incentives and long term predictability regarding what&#xA;behavior is safe. Behavior that becomes unsafe if incentives change is bad&#xA;and shouldn&#39;t be relied on.&#xA;&#xA;Also, Bitcoin is the concensus mechanism. As mentioned, trying to provide a&#xA;guarantee for what will end up in the blocks without servers involved is to&#xA;reinvent Bitcoin within Bitcoin. I can go Xzibit on you all day long if you&#xA;like!  What you consider an attack is irrelevant. You assume a certain&#xA;behavior is desired without first making sure it is reliable.&#xA;&#xA;Depending on that which isn&#39;t guaranteed is baaaad, and breaking other&#xA;people&#39;s assumptions is by itself NOT an attack if there never was a&#xA;guarantee or even as little as an implicit understanding it is safe.&#xA;&#xA;Your also assume people will expect the Bitcoin network to keep zero-conf&#xA;safe forever and that Bitcoin valuation is tied to that. Given the options&#xA;available and current state of things, I&#39;m assuming that&#39;s wrong.&#xA;&#xA;Besides, zero-conf will never be secure if you don&#39;t add external&#xA;contextual information as a requirement when validating blocks. Otherwise&#xA;defecting miners will frequently doublespend against you. And adding such&#xA;information is messy and probably not secure in itself, as it opens up for&#xA;gaming the system through network level attacks.&#xA;&#xA;And your remarks against game theory seems unwarranted.&#xA;&#xA;The game theorists that are wrong are typically wrong for one of the&#xA;following reasons;&#xA;&#xA;* Their model is wrong. The system, the actors and/or the options available&#xA;are misunderstood.&#xA;* The actors don&#39;t understand the avaliable incentives and go for trial and&#xA;error (the most optimal choices for attack and defense are found at random&#xA;or not at all, and not always adopted until it has stood the test of time).&#xA;* That option is on the to-do list, just wait.&#xA;* There&#39;s easier and/or more profitable attacks (a variant of #1 if the&#xA;game theorist said it is certain to happen).&#xA;&#xA;You should NOT EVER rely on security-through-opportunity-cost for the&#xA;attacker or assume you can always keep doing what you always did. Once the&#xA;bigger targets are gone, you&#39;re next.&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150212/2ad0cc1c/attachment.html&gt;</html></oembed>