<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-23&#xA;📝 Original message:On Wed, Apr 23, 2014 at 12:19 PM, Mike Hearn &lt;mike at plan99.net&gt; wrote:&#xA;&gt; That&#39;s the definition of a Finney attack, right?&#xA;&#xA;A finney attack is where you attempt to mine a block with a&#xA;transaction paying you, and as soon as you are successful you quickly&#xA;make a transaction spending that coin to someone else, then release&#xA;the block after they&#39;ve taken an irreversible action. If everything is&#xA;automated it should have something like a 99% success rate, though it&#xA;has a cost of some small increase in the number of orphan blocks you&#xA;experience.&#xA;&#xA;&gt; I mean, I hope that&#39;s the definition of a Finney attack, given that I coined&#xA;&gt; the term :)&#xA;&#xA;You might have coined the term, but I don&#39;t think the attack you&#39;re&#xA;describing is the attack Hal described:&#xA;https://bitcointalk.org/index.php?topic=3441.msg48384#msg48384&#xA;&#xA;What you&#39;re talking about is just disagreement about the content of&#xA;the memory pool, but we have no consensus mechanism there (the&#xA;blockchain _is_ the consensus mechanism).  Mempools are sometimes&#xA;inconsistent all on their own, without any attacker being involved.&#xA;&#xA;&gt; These sorts of proposals are all just ways of saying block chains kind of&#xA;&gt; suck and we should go back to using trusted third parties.&#xA;&#xA;I think thats an unsophisticated view.&#xA;&#xA;Consider this protocol.&#xA;&#xA;I take some of my funds and assign them to a 2 of 2 multisig with&#xA;myself and Oscar. I do not announce this transaction until I get Oscar&#xA;to sign a timelocked anyonecanpay refund to send the coin back to me&#xA;(say in 3 months).  Oscar gives me my refund and I announce the&#xA;transaction.&#xA;&#xA;Later I can make instant payments with oscar signing up until the&#xA;refund time comes clue to anyone who trusts Oscar to never double&#xA;spend.  For the receiver this is purely additive with regular&#xA;blockchain security: in that even with Oscar&#39;s help I cannot double&#xA;spend except where I would have been successful absent Oscar. On the&#xA;sender side, Oscar cannot up and steal my funds and he can&#39;t try to&#xA;extort me (except by creating a delay up to the refund time).&#xA;&#xA;Oscar himself can be implemented as a majority M parties to further&#xA;increase confidence, though if you&#39;re talking about using this for low&#xA;value retail transactions— the fact that any cheating by oscar is&#xA;cryptographically provable (just show them the double signatures)&#xA;maybe be strong enough alone. (Though there is a multitude of other&#xA;proposals to provide more evidence of Oscar&#39;s honesty). There are also&#xA;ways to blind Oscar so he can&#39;t reliably identify which transactions&#xA;are ones he signed for.&#xA;&#xA;I don&#39;t think this is at all a &#34;return to trusted third parties&#34;— that&#xA;it&#39;s a shrug and an admission of defeat. Its a very narrowly scoped&#xA;trust, filling in precisely where large scale decentralized consensus&#xA;is fundamentally weak... the result is something which combines&#xA;advantages from both classes and is stronger than either trust or&#xA;blockchains alone.  (I&#39;m also not trying to say that an implementation&#xA;of this is _simple_ by any means, working out all the details is&#xA;hard.)&#xA;&#xA;By contrast, I think proposals which overly depend on colluding miners&#xA;to behave in very specific ways are themselves just a way of saying&#xA;block chains suck unless we turn the miners themselves into a trusted&#xA;third party. I&#39;m much more in favor of adding a little bit of&#xA;mastercard to transactions where mastercard is really what people&#xA;want, than turning mining— and thus bitcoin itself— into mastercard,&#xA;especially since miners— self selecting as they are— are a pretty poor&#xA;set of parties to act as trusted agents. :)&#xA;&#xA;&gt;&gt; Doubly so because a &#39;nasty&#39; party with non-trivial hash-power can&#xA;&gt;&gt; doublespend their own transactions&#xA;&gt; If a miner is vertically integrated and defrauding merchants themselves,&#xA;&gt; with no service component, pretty quickly people would talk to each other,&#xA;&gt; notice this pattern and stop trading with them, making their coins rather&#xA;&gt; useless. Also if their real identity is ever revealed they could be liable&#xA;&gt; and there&#39;d be a lot of people wanting to sue them.&#xA;&#xA;We have an existence proof that it isn&#39;t so— you can say that it&#xA;wasn&#39;t consistent enough, but what is? There wasn&#39;t any major doubt&#xA;that they were actually doing it. They&#39;re the largest identifiable&#xA;pool as we speak.&#xA;&#xA;I think, instead, that strong zero-conf security isn&#39;t a part of what&#xA;many people think of when they think of Bitcoin&#39;s characteristics.&#xA;Zero conf is risky, and I think for a lot of people thats okay.  If it&#xA;isn&#39;t there are ways to improve it that don&#39;t involve asking miners to&#xA;participate in a majority vote to take away funds from people.</html></oembed>