<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-23&#xA;📝 Original message:On Wed, Apr 23, 2014 at 12:59 PM, Mike Hearn &lt;mike at plan99.net&gt; wrote:&#xA;&gt;&gt; What you&#39;re talking about is just disagreement about the content of&#xA;&gt;&gt; the memory pool&#xA;&gt; That&#39;s the same thing. Whilst you&#39;re mining your double spend tx, it&#39;s in&#xA;&gt; your mempool but you don&#39;t broadcast it as per normal. Then when you find&#xA;&gt; the block you broadcast it to override everyone elses mempool. So yours and&#xA;&gt; theirs were inconsistent.&#xA;&#xA;The difference is when you transact.  In the attack Hal described you&#xA;transact with your victim only after finding a block but before&#xA;announcing it.&#xA;&#xA;&gt; don&#39;t know if they inform you when they found a block (probably not), so you&#xA;&gt; have to do the purchase and then hope BitUndo finds the next block.&#xA;&#xA;Right, this works in the Bitcoin network today absent any collusion by&#xA;the miners. You give one miner a transaction and you give every other&#xA;node you can reach another transaction.  You then hope your selected&#xA;miner finds the next block and &#39;undoes&#39; the transaction you gave the&#xA;rest of the network.&#xA;&#xA;&gt; This just brings us back to square one. Who are these parties and what if I&#xA;&gt; pay them to be corrupt? What if they offer to be corrupt as a service?&#xA;&gt;&#xA;&gt; Let&#39;s say I succeed in finding some parties who are incorruptible no matter&#xA;&gt; how large of a percentage I offer them. At this point, why bother with&#xA;&gt; miners at all? Why pay for double spend protection twice, once to a group of&#xA;&gt; Oscar&#39;s who are trustworthy and once to a group of miners who are not?&#xA;&gt;&#xA;&gt; The point of the broadcast network and mining is so there can be lots of&#xA;&gt; Oscar&#39;s and I don&#39;t have to know who they are or sign up with them or put&#xA;&gt; any effort into evaluating their reputation.&#xA;&#xA;But it isn&#39;t at all the same thing.  Miners select themselves based on&#xA;controlling hash-power. You can distrust a miner all you like but all&#xA;your distrust does not prevent him from participating in the&#xA;consensus, potentially to your detriment.  Moreover, the set of miners&#xA;has to be the same for everyone or otherwise the network doesn&#39;t&#xA;converge. There are miners I _know_ to be scoundrels, but there is&#xA;nothing I can do about it.&#xA;&#xA;Someone you ask to not double spend is an entirely separate matter.&#xA;They aren&#39;t self-selecting: you select who you trust to not make&#xA;double spends and there is no need for this trust to be globally&#xA;consistent. If they behave in an untrustworthy way you can instantly&#xA;stop honoring them because the bad action is provable beyond any doubt&#xA;and never trust them again (unlike mempool consistency)... and you can&#xA;do this even if everyone else is too foolish to do so for some reason.&#xA;&#xA;The trustworthness of oscars needs only be limited and is different in&#xA;kind from the kind of &#39;trust&#39; we need over the history— they&#xA;arbitrating over the ordering of some subset of transactions right at&#xA;the tip of the chain, and only those transaction of people who have&#xA;specifically chosen to use them, of lower value transactions where you&#xA;need instant settlement.  Why pay twice? Because you&#39;re actually&#xA;getting a different part of your security from each, and the result is&#xA;additive.&#xA;&#xA;There is no such thing as an uncorruptable party, invoking that is a&#xA;useless strawman. Instead we can consider how difficult the corruption&#xA;is and what can happen if they&#39;re corrupted and hope to balance the&#xA;risks and the controls for those risks.  Any self-selectingness as&#xA;anonymity (in the not-previously-enumerated sense) of mining is&#xA;important for censorship security but it&#39;s terrible for other things&#xA;like getting reliable mempool behavior.&#xA;&#xA;&gt; But as you point out, cheating my GHash.io did not result in any obvious&#xA;&gt; negative consequence to them, despite that preventing double spending is&#xA;&gt; their sole task. Why would Oscar be different to GHash.io?&#xA;&#xA;Because you can choose to stop trusting an oscar while you—&#xA;individually— can&#39;t choose anything about ghash.io.  To stop GHash.io&#xA;we would have to take away their hardware or change the Bitcoin&#xA;protocol to make their hardware useless, and in the latter case we&#39;d&#xA;_all_ have to agree to do this not just some (perhaps quite large)&#xA;subset of us who doesn&#39;t want to trust them, and even though it is&#xA;quite apparent what they did there is still some room to claim doubt.&#xA;&#xA;&gt; Trying to solve the problem of dishonest miners is effectively trying to&#xA;&gt; solve the &#34;automatically find trusted third parties&#34; problem at scale.&#xA;&#xA;Mining is universal— everyone must use the same miners, trust seldom&#xA;is seldom universal and shouldn&#39;t be. The trust we have in mining is&#xA;exceptionally limited, I think any effort to increase it is doomed to&#xA;fail— both because trust heavy systems stink, because mining is a bad&#xA;fit for trust, and because increasing the requirements create other&#xA;exposures and vulnerabilities.</html></oembed>