<oembed><type>rich</type><version>1.0</version><author_name>npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_name><author_url>https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-08-22&#xA;📝 Original message:&gt; The initial message I replied to stated:&#xA;&#xA;Yes, 3 years is silly.  But coin expiration and quantum resistance is&#xA;something I&#39;ve been thinking about for a while, so I tried to steer the&#xA;conversation away from stealing old money for no reason ;).   Plus I like&#xA;the idea of making Bitcoin &#34;2000 year proof&#34;.&#xA;&#xA;- I cannot imagine either SHA256 or any of our existing wallet formats&#xA;surviving 200 years, if we expect both moores law and quantum computing to&#xA;be a thing.   I would expect the PoW to be rendered obsolete before the&#xA;Bitcoin addresses.&#xA;&#xA; - A PoW change using Keccak and a flexible number of bits can be designed&#xA;as a &#34;future hard fork&#34;.  That is:  the existing POW can be automatically&#xA;rendered obsolete... but only in the event that difficulty rises to the&#xA;level of obsolescence.   Then the code for a new algorithm with a flexible&#xA;number of bits and a difficulty that can scale for thousands of years can&#xA;then automatically kick in.&#xA;&#xA; - A new addresses format and signing protocols that use a flexible number&#xA;of bits can be introduced.   The maximum number of supported bits can be&#xA;configurable, and trivially changed.   These can be made immediately&#xA;available but completely optional.&#xA;&#xA; - The POW difficulty can be used to inform the expiration of any addresses&#xA;that can be compromised within 5 years assuming this power was somehow used&#xA;to compromise them.   Some mechanism for translating global hashpower to&#xA;brute force attack power can be researched, and consesrvative estimates&#xA;made.   Right now, it&#39;s like &#34;heat death of the universe&#34; amount of time to&#xA;crack with every machine on the planet.   But hey... things change and 2000&#xA;years is a long time.   This information can be used to inform the&#xA;expiration and reclamation of old, compromised public addresses.&#xA;&#xA;- Planning a hard fork 100 to 1000 years out is a fun exercise&#xA;&#xA;&#xA;&#xA;&#xA;On Tue, Aug 22, 2017 at 2:55 PM, Chris Riley &lt;criley at gmail.com&gt; wrote:&#xA;&#xA;&gt; The initial message I replied to stated in part, &#34;Okay so I quite like&#xA;&gt; this idea. If we start removing at height 630000 or 840000 (gives us 4-8&#xA;&gt; years to develop this solution), it stays nice and neat with the halving&#xA;&gt; interval....&#34;&#xA;&gt;&#xA;&gt; That is less than 3 years or less than 7 years  away. Much sooner than it&#xA;&gt; is believed QC or Moore&#39;s law could impact bitcoin.  Changing bitcoin so as&#xA;&gt; to require that early coins start getting &#34;scavenged&#34; at that date seems&#xA;&gt; unneeded and irresponsible.  Besides, your ECDSA is only revealed when you&#xA;&gt; spend the coins which does provide some quantum resistance.  Hal was just&#xA;&gt; an example of people putting their coins away expecting them to be there at&#xA;&gt; X years in the future, whether it is for himself or for his kids and wife.&#xA;&gt;&#xA;&gt; :-)&#xA;&gt;&#xA;&gt;&#xA;&gt;&#xA;&gt; On Tue, Aug 22, 2017 at 1:33 PM, Matthew Beton &lt;matthew.beton at gmail.com&gt;&#xA;&gt; wrote:&#xA;&gt;&#xA;&gt;&gt; Very true, if Moore&#39;s law is still functional in 200 years, computers&#xA;&gt;&gt; will be 2^100 times faster (possibly more if quantum computing becomes&#xA;&gt;&gt; commonplace), and so old wallets may be easily cracked.&#xA;&gt;&gt;&#xA;&gt;&gt; We will need a way to force people to use newer, higher security wallets,&#xA;&gt;&gt; and turning coins to mining rewards is better solution than them just being&#xA;&gt;&gt; hacked.&#xA;&gt;&gt;&#xA;&gt;&gt; On Tue, 22 Aug 2017, 7:24 pm Thomas Guyot-Sionnest &lt;dermoth at aei.ca&gt;&#xA;&gt;&gt; wrote:&#xA;&gt;&gt;&#xA;&gt;&gt;&gt; In any case when Hal Finney do not wake up from his 200years&#xA;&gt;&gt;&gt; cryo-preservation (because unfortunately for him 200 years earlier they did&#xA;&gt;&gt;&gt; not know how to preserve a body well enough to resurrect it) he would find&#xA;&gt;&gt;&gt; that advance in computer technology made it trivial for anyone to steal his&#xA;&gt;&gt;&gt; coins using the long-obsolete secp256k1 ec curve (which was done long&#xA;&gt;&gt;&gt; before, as soon as it became profitable to crack down the huge stash of&#xA;&gt;&gt;&gt; coins stale in the early blocks)&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt; I just don&#39;t get that argument that you can&#39;t be &#34;your own bank&#34;. The&#xA;&gt;&gt;&gt; only requirement coming from this would be to move your coins about once&#xA;&gt;&gt;&gt; every 10 years or so, which you should be able to do if you have your&#xA;&gt;&gt;&gt; private keys (you should!). You say it may be something to consider when&#xA;&gt;&gt;&gt; computer breakthroughs makes old outputs vulnerable, but I say it&#39;s not&#xA;&gt;&gt;&gt; &#34;if&#34; but &#34;when&#34; it happens, and by telling firsthand people that their&#xA;&gt;&gt;&gt; coins requires moving every once in a long while you ensure they won&#39;t do&#xA;&gt;&gt;&gt; stupid things or come back 50 years from now and complain their addresses&#xA;&gt;&gt;&gt; have been scavenged.&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt; --&#xA;&gt;&gt;&gt; Thomas&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt; On 22/08/17 10:29 AM, Erik Aronesty via bitcoin-dev wrote:&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt; I agree, it is only a good idea in the event of a quantum computing&#xA;&gt;&gt;&gt; threat to the security of Bitcoin.&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt; On Tue, Aug 22, 2017 at 9:45 AM, Chris Riley via bitcoin-dev &lt;&#xA;&gt;&gt;&gt; bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt; This seems to be drifting off into alt-coin discussion.  The idea that&#xA;&gt;&gt;&gt;&gt; we can change the rules and steal coins at a later date because they are&#xA;&gt;&gt;&gt;&gt; &#34;stale&#34; or someone is &#34;hoarding&#34; is antithetical to one of the points of&#xA;&gt;&gt;&gt;&gt; bitcoin in that you can no longer control your own money (&#34;be your own&#xA;&gt;&gt;&gt;&gt; bank&#34;) because someone can at a later date take your coins for some reason&#xA;&gt;&gt;&gt;&gt; that is outside your control and solely based on some rationalization by a&#xA;&gt;&gt;&gt;&gt; third party.  Once the rule is established that there are valid reasons why&#xA;&gt;&gt;&gt;&gt; someone should not have control of their own bitcoins, what other reasons&#xA;&gt;&gt;&gt;&gt; will then be determined to be valid?&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt; I can imagine Hal Finney being revived (he was cryo-preserved at Alcor&#xA;&gt;&gt;&gt;&gt; if you aren&#39;t aware) after 100 or 200 years expecting his coins to be there&#xA;&gt;&gt;&gt;&gt; only to find out that his coins were deemed &#34;stale&#34; so were &#34;reclaimed&#34; (in&#xA;&gt;&gt;&gt;&gt; the current doublespeak - e.g. stolen or confiscated).  Or perhaps he&#xA;&gt;&gt;&gt;&gt; locked some for his children and they are found to be &#34;stale&#34; before they&#xA;&gt;&gt;&gt;&gt; are available.  He said in March 2013, &#34;I think they&#39;re safe enough&#34; stored&#xA;&gt;&gt;&gt;&gt; in a paper wallet.  Perhaps any remaining coins are no longer &#34;safe enough.&#34;&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt; Again, this seems (a) more about an alt-coin/bitcoin fork or (b) better&#xA;&gt;&gt;&gt;&gt; in bitcoin-discuss at best vs bitcoin-dev. I&#39;ve seen it discussed many&#xA;&gt;&gt;&gt;&gt; times since 2010 and still do not agree with the rational that embracing&#xA;&gt;&gt;&gt;&gt; allowing someone to steal someone else&#39;s coins for any reason is a useful&#xA;&gt;&gt;&gt;&gt; change to bitcoin.&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt; On Tue, Aug 22, 2017 at 4:19 AM, Matthew Beton via bitcoin-dev &lt;&#xA;&gt;&gt;&gt;&gt; bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt;&gt; Okay so I quite like this idea. If we start removing at height 630000&#xA;&gt;&gt;&gt;&gt;&gt; or 840000 (gives us 4-8 years to develop this solution), it stays nice and&#xA;&gt;&gt;&gt;&gt;&gt; neat with the halving interval. We can look at this like so:&#xA;&gt;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt;&gt; B - the current block number&#xA;&gt;&gt;&gt;&gt;&gt; P - how many blocks behind current the coin burning block is. (630000,&#xA;&gt;&gt;&gt;&gt;&gt; 840000, or otherwise.)&#xA;&gt;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt;&gt; Every time we mine a new block, we go to block (B-P), and check for&#xA;&gt;&gt;&gt;&gt;&gt; stale coins. These coins get burnt up and pooled into block B&#39;s miner fees.&#xA;&gt;&gt;&gt;&gt;&gt; This keeps the mining rewards up in the long term, people are less likely&#xA;&gt;&gt;&gt;&gt;&gt; to stop mining due to too low fees. It also encourages people to keep&#xA;&gt;&gt;&gt;&gt;&gt; moving their money around the enconomy instead of just hording and leaving&#xA;&gt;&gt;&gt;&gt;&gt; it.&#xA;&gt;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&gt;&#xA;&gt;&gt;&gt;&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20170822/7866f6f9/attachment.html&gt;</html></oembed>