<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-23&#xA;📝 Original message:On Wed, Apr 23, 2014 at 12:55 AM, Mike Hearn &lt;mike at plan99.net&gt; wrote:&#xA;&gt; Lately someone launched Finney attacks as a service (BitUndo). As a reminder&#xA;&gt; for newcomers, Finney attacks are where a miner secretly works on a block&#xA;&gt; containing a double spend.&#xA;&#xA;Hm? I didn&#39;t think this is at all what they did.  What they claim to&#xA;do is to prioritize transactions in their mempool from people who pay&#xA;them, potentially over and above other transactions which they may or&#xA;may not have received first.&#xA;&#xA;This may still be bad news for someone taking an irreversible action&#xA;in response to an unconfirmed payment and it may or may not be really&#xA;ill advised in general, but I think it&#39;s less sinister than it sounds&#xA;in your posts.  Is there some reason to believe it isn&#39;t what it&#xA;claims to be?&#xA;&#xA;I think we have very clear evidence that the Bitcoin community doesn&#39;t&#xA;care if miners reorder transactions in their mempool to profitable&#xA;ends: In https://bitcointalk.org/index.php?topic=327767.0 it&#39;s&#xA;demonstrated that GHash.IO, currently the largest publicly identified&#xA;pool was used to rip off Betcoin dice via double-spends.&#xA;&#xA;&gt; first started using Bitcoin, nowadays most of my purchases with it are for&#xA;&gt; food and drink. If Bitcoin could not support such purchases, I would use it&#xA;&gt; much less.&#xA;&#xA;Accepting zero-conf inherently has some risk (well, so does all&#xA;business, but there is substantially more in a zero-conf payment).&#xA;Even in a spherical-cow Bitcoin absent anything like Bitundo someone&#xA;can just give a double spend to a large miner and currently give the&#xA;whole rest of the network the one paying the merchant.  They will,&#xA;with high success rate be successful.   Worse, it may _appear_ to the&#xA;network that the miner was a &#34;bitundo&#34; but they really were not.   The&#xA;blockchain exists to establish consensus ordering, prior to the&#xA;blockchain there is no order, and so it is not easy to really say&#xA;which transaction came first in any meaningful sense.&#xA;&#xA;But in business we balance risks and the risk that sometimes a&#xA;transaction will be reversed exists in every electronic payment system&#xA;available today, in most of them the risk persists for _months_ rather&#xA;than minutes.  Businesses can still operate in the face of these&#xA;risks.&#xA;&#xA;More importantly, it&#39;s possible to deploy technological approaches to&#xA;make zero-conf very secure against reversal: Things like performing&#xA;multi-sig with a anti-double-spending system, or using an external&#xA;federated payment network... but this stuff requires substantial&#xA;development work— though it&#39;s not work thats likely to happen if&#xA;people are still confused about the level of security that zero-conf&#xA;has.&#xA;&#xA;&gt; Miners can vote to reallocate the coinbase value of bad blocks before they&#xA;&gt; mature.&#xA;&#xA;I think miners &#39;voting&#39; to reallocate coins, even if they&#39;re&#xA;thoroughly convinced that the owner of the coins is a nasty party, is&#xA;a much greater violation of the Bitcoin social contract than some&#xA;twiddling with the unspecified unconfirmed transaction ordering.&#xA;&#xA;Doubly so because a &#39;nasty&#39; party with non-trivial hash-power can&#xA;doublespend their own transactions with a pretty good success rate (as&#xA;was the case for the GHash.io betcoin spends) including not-just&#xA;zero-conf (though with obviously reduced effectiveness), and all of&#xA;your reliable detection depends on it being a public service.&#xA;&#xA;A much better defense is having the control of hash power very well&#xA;distributed and so there isn&#39;t any central point that excerts enough&#xA;influence to change the risk statistics much.  Giving miners the&#xA;ability to steal each others payments is, if anything, a force away&#xA;from that decentralization.</html></oembed>