October 2015 Journal
WORDS is a monthly journal of Bitcoin commentary. This issue collects the October 2015 writing in the WORDS archive. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. Thatâs why we made this journal, to preserve and further the understanding of Bitcoin.
Estimating and minimizing consumer worry
By Nick Szabo
Posted October 8, 2015
The process of selling in general, and web commerce in particular, is often described or charted as a funnel. Prospective customers are poured in at one end, and a fewer number of paying customers come out at the other. The other prospects spill out through other holes or over the side of the funnel and donât bring you any revenue. The fraction of customers left, converted from prospects to customers, is called the conversion rate. As prospects proceed from initial interest to final sale, from initial entry page to clicking the final âI Agreeâ button, more and more of them become discouraged by various worries which beset the consumer. They drop out. The remaining prospects, those who have not dropped off, have been converted into customers or into an audience for your advertisers.
There are a variety of factors that cause drop-off, which vary from business to business. A common cause is forms. Simplifying forms often greatly increases conversion rates. For example, in one
study
cutting the number of lines on a form in half increase conversions by a third. As one web designer
- put it
-
â[i]s every field youâre asking the visitor to submit absolutely necessary? Can you trim the fat and make the process simpler?â
Besides the sheer tediousness and time consumed in filling out forms, rational consumers also worry about the potentials for privacy violation and identity theft from the information most e-commerce sites currently require them to divulge: physical and e-mail addresses, phone numbers used for cross-site behavioral tracking, insecure credit card numbers, and more.

The tinfoil-wallet crowd is now mainstream
Instances of regret that one has filled out a form, only to have oneâs
trust violated
â or
pride
among the sophisticated that they refused to fill out such a form â are on the rise.
The worst worry culprit is usually the step you most want your customers to complete â paying you. â[T]he credit card form likely has the highest abandonment rate of any other part of the sign-up process.â [
Source
].
If you donât require payments, you are probably funding your service through advertisements. Those also cause worries. Ads typically distract and delay from the content users are after, provide a low quality of entertainment or information, and are too often offensive. And sophisticated users are worried about the tracking that tends to go with ads. Ad blocking
grew
nearly tenfold between 2009 and 2014.
Replacing ads and identity-based payments with payments that donât require identity, such as bitcoin, can greatly reduce these worries, lowering the barriers and hesitations that currently prevent consumers from paying for your service.
But there remains a big worry that no payment system can reduce. Consumers worry about whether they are getting their moneyâs worth â the
mental transaction cost
problem (see also
this paper
). If e-commerce were as worry-free as some of it could be, your customers would neither have to fill out forms, nor be bothered by ads, nor have to worry about repeated charges for content or services of variable value. They would be able to just insert a few digital coins into your online vending machine and then not have to worry about losing your service for another year. Eliminate forms
and
eliminate repeated payments â both are key to worry-minimized e-commerce.
Many bitcoin startups are making the grave mistake of replacing one set of worries with another. The ability of cryptocurrency systems to facilitate small payments tempts many companies to nickel-and-dime their customers with pay-per-click micropayments and other such excruciating schemes. Donât follow the many lemmings who have already jumped off that cliff. Stick to long-term subscriptions for content (or other services of variable value) and pay-per-unit for fungible units of consistent value (as in phone minutes). That way customers arenât saddled with having to constantly re-evaluate the amount and worthiness of recurring charges. The costs to your customers of having to finance a yearsâ worth of low-cost subscription to a reputable brand is almost always far less than the mental transaction costs of recurring charges for content or services of variable value. The ideal worry-free commerce is to âstick the coin into the machineâ once, and then never have to pay again for an entire year. A vending machine for subscriptions. Reduce your customersâ worries across the board: eliminate forms
and
eliminate recurring charges.
Ideal worry-minimization can only be closely approached in some purely online forms of commerce, such as video streaming, remote storage, privacy services, and the like. The more physical and offline contract performances are â a common example being physical delivery â the more location, various kinds of identity (legal, social network, etc.) may need to come into play, adding, often greatly and necessarily, to the worry overhead, the mental transaction costs, of your relationship with your consumers.
I have previously called this worry-minimized commerce by a narrower label, âform-minimized commerce.â The complexity of the forms you make your users fill is indicative of the worries you are causing them, and thus the barriers you are putting up between your prospects and their decisions to purchase your services.
When you are a consumer, the tediousness of the forms you are filling out is not only a direct cost of your time, and your ability to enjoy that time, it is on top of that a decent proxy measure of the odds of your identity being stolen and of your privacy otherwise being violated. The fewer forms you fill out, the more the tediousness, worries, and risks in your life caused by interacting with the worldâs institutions will drop in proportion.
While such a proxy measure does not account in particular for the wide variety of information that can be disclosed, nor that some kinds of information (social security numbers) are more risky to divulge than others (throw-away email addresses), nor for the wide variety of risks in identity theft and privacy violation that are consequent, nevertheless consumers necessarily must bring to bear such sweeping rules-of-thumb in order to satisfactorily navigate the bizarre complexities of the digital world. And when your users are using, whether consciously or implicitly, such estimates, you the service provider and the product designer must use them too.
Add to the forms your customers must fill out the repeated charges you make your customers make, and we get a rough proxy measure of the worry that you are causing your consumers:
Index of worry = number of lines of forms + number of repeated charges for content or services of variable value
If you are funded through ads rather than consumer payments, you can substitute for the repeated charges the proportion of screen space covered by your ads, or any other reasonable estimate of the delay and distraction the ads on your pages cause.
The index of worry allows you to estimate and minimize the worries you are causing your users, and as a result to minimize the drop-off in your sales funnel and maximize the number of users coming back for more â and willing to view your ads or pay for the privilege.
Measuring Decentralization
By Paul Sztorc
Posted October 9, 2015
Bitcoinâs Decentralization increases as a full node becomes cheaper.
Agenda
- Break down âDecentralizationâ, and âMoneyâ, to determine, from the ground up, when âDecentralization of Moneyâ increases or decreases.
- Defend that measure against its major competitors.
- Evaluate the measure against scalability comments made by Satoshi.
- âHow to (Safely) Increase Decentralizationâ
Defining Decentralized Money
The process of âmoneyâ is âknowing youâve been paidâ. A process has greater âdecentralizationâ as it âoccurs more locallyâ. Thus âdecentralized moneyâ is the local cost of knowing youâve been paid: the cost of running a full node.
Letâs break the concepts down, before building them back up.
âCentralizedâ and âDecentralizedâ are words which describe the layout of the relationships between agents. Let us start with what these relationships are (in our âmoneyâ case) before we assess any of their other qualities (âdecentralizationâ).
Money
Money is like a big record of who has done favors for whom, but a very abstract record which works without knowing the specific identity or favor. Thatâs how you can trade money with someone youâve never met (or will never meet again): it makes private value-knowledge common.
Thatâs what it does. How can we make something do that? How can we build a âpayment networkâ?
It seems there are two simple requirements: [1] to know when youâve been paid (for the favor you gave), and [2] to be able to show your trading partner that theyâve been paid (for their favor to you).
The two requirements are mirrors: if âsomethingâ can do the first, for everyone, it can likewise do the second. Thereâs no reason to double-count it.
Money is âknowing youâve been paidâ (by someone, with finality).
Decentralization
Now lets see how a money-relationship varies in its centralization-quality.
Basics
Some existing academic literature might help us with the general concept of âmeasuring decentralizationâ, but itâs nothing we couldnât have figured out on our own (that âthe process takes place closer to each agentâ).
This figure spells it out for us:

The decentralized system is more local: the lines (pairwise-connections, or ârelationshipsâ) are shorter. It also involves less âinteractionâ (path-overlap) and hence, less âpermissionâ: on the left all node-paths must share the single central node, but on the right it is possible for some pairs to âgroup upâ in ways that avoid the center node.
Now we must discuss Satoshiâs use of the word âdecentralizedâ.
A âPeer to Peerâ Electronic Cash System
Satoshi clearly intended âthe Bitcoin Networkâ NOT to be âmore decentralized than usualâ, but, instead to be 100% decentralized. In other words, the one on the right:

After all, the âDecentralizedâ process above (middle) still has a center, which is a superior authority (non-peer) to the surrounding subordinates.
And, such a âhaving a centerâ contradicts this statement from Bitcoinâs Creator:

Notice the phrase âpure P2Pâ. Bitcoinâs whitepaper never uses the word âdecentralizedâ, instead favoring the term âpeer-to-peerâ (which is very easy to measure: âIs every pair of nodes âtwo peersâ?â and/or âDoes any node have a privileged status?â).
The phrase âcutting of the head(s)â is a clue to the underlying principle: âWhy is Bitcoin P2P?â (Might we achieve this goal another [non-P2P] way?)
Clearly, the âDecentralizedâ image still has a âheadâ that can be âcut offâ. In fact (worse than that), if I reorder/relabel the images, the âdecentralizedâ option is the most-headed of all!

The colorful stars represent âprivilegeâ in the network. A decapitateur could take out the Capitol Star in either the 2-H or 1-H, but his control over 2-H is even more fine-tuned. Instead of all-or-nothing, he can selectively disable the network for enemies only.
This âdecapitation-controlâ brings me to my next point:
It is an Engineering Requirement that Bitcoin be âAbove the Lawâ
Obviously, people prefer not to talk openly about breaking the law, but if we donât acknowledge true things, our conclusions will be wrong.

What is the difference between the following columns:
Computing
Legal
A
user
goes to a nearby terminal and
logs in
to a given mainframe. The user attempts to use his
e-credits
to purchase
heroin
at the
e-store
, but the mainframe rejects these instructions (as ânot permittedâ). With some effort, the user cleverly
circumvents
the
programmed limitation
. However,
the administrators
of the mainframe later use
the mainframeâs logs
to track this activity down. New limits are imposed and
the offending user is banned
, losing access to
all of his digital resources
.
A
citizen
wakes up
within the borders of a given country. The citizen attempts to use his
Bitcoin
to purchase
heroin
at a
nearby pharmacy
, but under current law this is ânot permittedâ. After some effort, the user manages to
break
the
law
by transacting with a street dealer. However,
the local police
begin to
carefully patrol the area
to track this activity down. After studying the local black market,
the drug offender is jailed
, losing access to
his freedoms
completely.
A
user
goes to a nearby terminal and
logs in
to a given mainframe. He has been running
UserBank
, which lets him and his friends keep track of who still owes who money (for beer and whatnot). This user recently discovered cryptography and wants
to take his banking software global
. When
the administrator learns of this
, he decides he does not like it (for whatever reason), and sends the user a notice that it will not be allowed. Not wanting to do anything that might upset the administrator, the user takes UserBank back to pencil-and-paper.
A
citizen
wakes up
within the borders of a given country. He and his immediate social network have been
bartering
favors (repair, electrical, painting, babysitting), which is cheaper and more fun than filling out tax forms. New, untrusted people want to participate, and they are willing to
use an accounting ledger
to keep track of who owes what. As the barter-network grows, the government
finds out about it
and audits these individuals for tax evasion, imprisoning the ledger-keeper for money laundering. Next year itâs back to âfriends onlyâ.
The
system administrator
can determine what
commands
are
allowed
on the computer network.
The
legislators
determine what
actions
are
legal
within the borders of their country.
Only things that can break the law are truly P2P, ie truly 100% decentralized. Compliance with the law is the acknowledgment of a âprivileged non-peerâ. If the process is subordinate to the law, it is âownedâ by the law exclusively, undermining the benevolent force of competition (for better or for worse).
You can spin it however you like (âthe first software application to self-maintain its subordinate OSI layersâ), but it is what it is: above the law.
Combining the Two: âDecentralized Paymentsâ
Setup
Money is âknowing youâve been paidâ. When does âthat knowingâ occur more locally?
Experience vs. Persuasion
To learn anything, you can either [1] check for yourself, or [2] trust the judgment of someone else. Trusting someone else implies a loss of local-ness. It definitely implies that P2P is lost: you are a subordinate taking the information from an authority. To preserve P2P, youâll have to check everything yourself: run a full node.
The requirement to run an entire full node may seem like a high bar, but the height is appropriate. With money, other peopleâs actions (counterfeiting) affect you. The only way for you to know youâve been paid, is to make sure that every piece of data has followed every rule, and you canât do that unless you have all of the data, and all of the rules, in front of you. Thatâs a full node.
It is also reasonable to require that this node start from scratch, for the very same reasons: to learn something, you either validate it yourself or trust an authority. Authorities are not âpeersâ.
âDonât Make Me Call My Full Nodeâ
Of course, one need not actually go through with the actual running of the node. That would imply that Some Guy in the remote African wilderness, far away from any internet connection, could declare âI refuse to run a full nodeâ and somehow decrease the decentralization of âBitcoinâ. Only the cost of running the node matters, not the number of people who choose to pay that cost.
And, technically, the centralization measure is the cost of the option to create a new full node, because in strategy/anything-reasonable only Options matter. Of course, the cost of âcreating a node at time=tâ is roughly the same as the cost of âcreating a node at time=(t-X) + running 1 node for X timeâ. However, this helpful detail does imply that some unconsumed electricity is âfree decentralizationâ (people can avoid running the node, unless Something Bad is currently happening), and it does perfectly tie up the edge-case where the full node count drops to zero (and new full-node creation is infinitely expensive), because option valuation includes uncertainty surrounding future costs.
So my metric of centralization is the cost of the option to create a new full node.
Testing the Definition (Applications and Alternatives)
The definition mirrors our observations. It flags âsuspicious servicesâ (Ripple, checkpointers, âŠ) as centralized, and is more fundamental than rival considerations (mining and development).
For this section, the cost of the option to create a full node will be referred to as the âcost of node-optionâ or âCONOPâ.
Applications
Extreme Points
What if the CONOP were free (ie $0.00)? That would imply perfect decentralization (centralization of zero). Is that right?
I think so: anyone, anywhere, would be able to make sure that they had gotten paid, without trusting a third party, or doing any other work whatsoever. And this option would be available to every human on the planet, no matter how oppressed/disadvantaged (and the only way for a government to âcut off the headâ of the network would be to kill every human being on the planet).
On the other hand, what if the CONOP were expensive, such that only one agent in the entire world could run a full node (say, the United State Government)? This agent would control the network completely: perfect centralization. If someone âcut off its headâ, this network would disintegrate.
In fact, the logic works perfectly, in reverse, to explain existing monetary systems: the cost of creating âa full US Dollar nodeâ is more than anyone could afford, by deliberate design. If, by magic, all of the USAâs banks / federal reserve / treasury buildings and equipment suddenly vanished, how many people would be able to replace them? Only one. Despite the fact that many, many people could, in principle, start a bank from their garage (and try to satisfy this unmet banking demand), we all know that they would be unable to do so. It would be illegal.
Ripple
A popular view is that the supposedly P2P Ripple is actually completely centralized. Does CONOP lead us to the same answer?
( Currently it is unambiguously centralized. And CONOP catches this: Ripple only allows one full node [theirs]. Adding a [second] node is infinitely expensive. )
But what of its eventual steady state?
Well, while anyone can become a Ripple ânodeâ, not all nodes are equal âpeersâ. Extra-special nodes make the âdefault Unique Node List (UNL)â, which requires the approval of Ripple. The future âcostâ of this approval is highly uncertain. Just as an option price converges to todayâs spot price as volatility increases, you canât guarantee youâll be able to join the future Ripple club unless youâve already joined today.
Actually, even that wonât work: the Ripple scheme allows you to be âthrown outâ of the UNL club. In this way, Ripple doesnât really have full nodes at all.
But lets run with it: To âknow youâve been paidâ, you need to join the club, and stay in until your payment(s) go through. So the application of CONOP actually requires, that, to know youâve been paid, you need to be âlong a call option to join Rippleâ + âlong a put option that youâll be thrown out before you can use Rippleâ.
The second term (the put), acts as a kind of insurance that fully compensates you if you are kicked out of the club. However, because [1] âfull compensationâ is âthem knowing theyâve been paidâ (impossible to provide, by circular reasoning), and [2] because the likelihood of being kicked out is highly subjective (âvolatileâ), the cost of the option is infinite for everyone except the 1 person who controls the UNL: Ripple Labs. If RL were destroyed, the gatekeepers would then be âa coalition of 80% of the club membersâ.
Only they really âknowâ if anyone has been paid. Not you.
âAsk A Friendâ / Weak Subjectivity
Summary
âAsk a Friendâ is a scheme where one decides if a chain (âtransaction historyâ) is valid by asking a friend, and taking their word for it. (Obviously the Friend has a superior non-peer status, so this is an outright rejection of âpure P2Pâ). If two friends disagree, (presumably) one asks a third friend, making it pseudo-democratic. This implies that democracyâs trademark effort-saving info-strategy will emerge: political parties. Specifically, the formation of alternating major/minor status groups (who âteam upâ to be realistic about winning), and fringe groups (who refuse to compromise on their principles, and always lose) resulting ultimately in a Status Game.
A high-status individual with âname recognitionâ (such as Gavin Andresen), can completely overpower even a group of honest/well-informed friends. This is because name recognition is common, and allows for âfree coordinationâ, whereas private or even mutual* knowledge do not allow for such coordination.
- There is a definition-mismatch in the video, Pinkerâs âmutualâ knowledge is wikipediaâs âcommonâ knowledge.
CONOP
Whatâs the cost of âknowing youâve been paidâ? Well, with âask a friendâ, you cannot (by yourself) learn whether or not you have been paid. You are asking a friend! The cost is infinite unless you join the set of âthose who are askedâ.
So this scheme is essentially a version of Rippleâs UNL, but with no âdefault leaderâ. The paramount question âHow do I join The Group?â is answered with âThe Group decides if you can. We also decide if you can stay.â
If âjoining the groupâ is cheap, this is fine. However, the âcostâ of membership is public name-recognition, yet this is incompatible with anonymity, and hence incompatible with coercion-resistance. Only one agent, the sovereign government, can âaffordâ to maintain the monopoly on violence it takes to remain in this set (âcan afford to run a full nodeâ).

In contrast, Bitcoinâs proof of work is easily verifiable (âcommonâ information, implying âfree coordinationâ), and the Work would live on even if the miners who provided that work were killed. Reputation doesnât work that way: someone needs [1] to be a reliable reporter of info, and [2] to be known as a reliable reporter of infoâŠthis is exactly the super-linearity that Bitcoin explicitly avoids!

Figure: the economics of degenerating (non-common) information (a zero-variable cost good): why settle for less than the best?
Checkpointers
This is perhaps the clearest victory for CONOP. Entirely by construction, only one person âdecidesâ who has been paid and who hasnât. Perfect centralization.
Now that the definition is viable, letâs see if it holds up to its competitors.
Alternative Definitions of Centralization (Have We Missed Anything?)
A Big List
Hereâs a (well-meaning) list on this topic written by someone who isnât me.
Letâs boil it down:
- Many members of the list (node, wallet, block explorer, payment processor, remittance service) are merely cosmetic layers on top of a Full Node. Certainly, they add convenience (and value) to Bitcoin, but the protocol itself isnât even aware of them. Instead of repeat âFull Nodeâ five times, weâll just keep it once (although I will discuss âcostâ vs âother attributesâ).
- Mining: while originally also a âpluginâ of Bitcoin Core, mining has since specialized to a degree where the representative full-node-user is completely divorced from the mining process. So thatâs a distinct #2.
- Some items (community, wealth) canât themselves affect the software (or its use) at all. Ignore.
- Exchanges: a Bitcoin Full Node inherently supports âexchangeâ for everything (currency included), and could have a âLocalBitcoins Pluginâ. Moreover the âprofessional exchangesâ are half-fiat, and can be altered -in quantity and quality- by factors which are entirely non-technical (laws/subsidies). So they are simultaneously irrelevant and immutable.
- Software development: clearly a solid #3.
So I have to justify âcostâ of a full node, and defend it against 2 challengers.
Counting Full Nodes Is Irrelevant
Itâs popular to reference the quantity of full nodes (another attempt at measuring decentralization focuses obsessively on counting things up and taking their log_2(Quantity) ).

Is this measure actually useful? Or is quantity an effect following the underlying cause.
You Are Indifferent to Other Peopleâs Nodes
I, personally, first heard it from Peter Todd: âThe only full node that matters is yours.â This is the point I raised above: to know anything, you either [1] check for yourself or [2] take someone elseâs word for it.
( Of course, [as I also mentioned], they are [slightly] related: if the node count falls to zero, you will be unable to start a node. )
After all, a single entity (of any type) can run and control many full nodes. The (centralized) Federal Reserve system likely has 100âs of redundant copies of its âknowledgeâ (payments data, research, web site, operating infrastructure, âŠ). In parallel, nothing stops a Bitcoin user from spinning up 100,000 new nodes that only he controls (and then halving them). So whatâs to be gained by counting them up? If you run a node (or can run one at any time), then it doesnât matter if the full node count falls even to one! Youâll always know the status of your payments.
Cost is King
An explanation based on cost makes the most sense: if creating a full, up to date node is nearly free (takes 10-20 seconds on a smart phone), we see that this network will have the desired âheadlessâ property, and be completely local (even if the average number of nodes in existence is some âlowâ number like 5). Conversely, if the a node is so expensive that only 10 or 20 people can afford to run one, it can be easily disabled (via the âclose e-goldâ routine, 20x in parallel), or coerced/harassed.
Donât Worry About Mining
Mining âFeelsâ Important; Disregard the Feeling
Money already mesmerizes people. Mining goes even further: it takes the âgenerationâ of ancient mysticism (making something valuable appear from ânothingâ), and adds modern computing technology and elitist tech-expertise, a round measure of esoteric h4x0r jargon, and finishes it off with a dash of âf**k the man!â.
Small wonder, that mining draws the attention of the audience.
Even freedom-loving, tech-literate Edward Snowden remarked: âweaknessesâŠmake [Bitcoin] vulnerable to people who are trying to own 50 percent of the networkâŠâ which implies (incorrectly) that the miners âownâ the network.
The Final Gear in a Vast Machine
There is a rampant misconception that mining is somehow important to Bitcoin.
Firstly, the true function of mining is not to provide security to the network, but instead to slow the distribution of coins, such that interested parties would join Bitcoin instead of cloning it into a competing system. Mining will fulfill that function, in a fully-P2P way, regardless of who is-or-is-not mining.
When Satoshi/Bitcoin-Experts use the phrase âsecure the networkâ, they are using a somewhat different version of the word âsecureâ. If I say that my bank is âsecureâ, what I usually mean is that âno one is going to steal my moneyâ. But Miners already canât steal anyoneâs Bitcoin.
It goes straight down to the tech tools used in Bitcoinâs design. Bitcoin is a ledger, answering the question âWho owns what, when?â. The entire first half (âwho owns whatâ, aka âmost of the actual âbankâ partâ) of that question is solved using asymmetric key cryptography, and even the second half (âwhenâ) is mostly solved with very clever structuring of data (into blocks, headers, hash chain etc) and creative use of cryptographic hash functions. Neither of those things have anything to do with mining; 0%.
Mining was brought in at the last minute to solve the P2P problem: âIf X makes a transaction, and Group A hears about it, but Group B doesnât hear about it, (and A and B are equal peers,) how do they decide if it âhappenedâ or not?â. Most of the Bitcoin whitepaper focused on this yet-unsolved problem, because Satoshi was a good writer, who knew that it would waste the readerâs time to go over those much-more-important problems that were already 100% solved.
If Bitcoin were a bank, Mining would be the clock on the wall.
Itâs the crypto that does all the heavy-lifting.
The 51% âAttackâ
Iâm sure you heard from your friend that, like, miners can âreverseâ transactions or whatever.
No Motivation
Most transactions are totally foreign to the miner; the sender, receiver, even the amount, are more or less unknown. The miner has nothing to gain whatsoever by reversing them.
Admittedly, reversal might be a problem for transactions that the miner makes himself. He may buy something in a store, and later want to reverse this transaction so he doesnât have to pay.
Or, an irate government might roll in with some tanks, take over the mining facilities, and reverse transactions (or âpauseâ the clock, by mining only empty blocks), purely to create mayhem.
That certainly wouldnât be cheap: troops have to eat, and anyone in possession of mining hardware (even via theft) who fails to use it for ROI-maximization incurs an opportunity cost.
But say they did it anyway.
Itâs not very effectiveâŠ
Ok, if the attacker also owns Bitcoins, he can double-spend these Bitcoins.
Once.
Assuming he doesnât âget caughtâ.
Where âcaughtâ is defined as âpeople come to understand that this 6+ block reorg was specifically unrepresentative of the distributed consensus processâ, and manually flag your chain as invalid. If this (highly likely) event happens, nothing will be reversed.
Not only is the userâs money safe, but the attackerâs money is at risk! It is relatively uncomplicated to have nodes (or the honest 49%) censor all further transactions âfromâ this address. This would result in the attacker not only failing, but also having his Bitcoin âblacklistedâ and essentially destroyed (increasing the value of all other BTC).
Whereas âask a friendâ was centralized, this isnât, because the conditions under which it would take place can be agreed upon in advance (even coded into the protocol) and donât change. No new judgment is required, only the protocol rules (and these rules are, you guessed it, common information, and they can therefore support âfree/leaderless coordinationâ).
Peer-to-Peer Blacklisting
Although âblacklistingâ coins is overwhelmingly considered to be objectionable, in this case I think an exception might be made.
Whatâs different here? Typically, âblacklistingâ would violate two core principles of Bitcoin: [1] âreproduce the qualities of moneyâ, and [2] âremain peer-to-peerâ. Blacklisting [1] implies that some Bitcoins are different than others, a direct contradiction to the monetary feature of Fungibility, and [2] allows a list-manager to achieve a âhigher-than-Peerâ status.
However, â51%-attack-blacklistingâ actually excels on both counts. First, it actually maximizes [1] Bitcoinâs reproduction of money-qualities, because, in my view, this loss of fungibility is more than offset by a large gain in transaction finality (a much more important feature of money). Second, if the blacklist-conditions are publicly discussed and agreed-to in advance, there is no need for a âlist-managerâ to coordinate the blacklisting, and no one has a âhigher-than-Peerâ status.
So, the 51% âattackâ requires a huge expenditure, to probably not achieve anything.
Mining isnât Bitcoin
By no means should we ignore mining. However, try to keep in mind that a âcentralizedâ mining network doesnât really mean that Bitcoin is significantly centralized. Mining isnât Bitcoin, itâs just something that Bitcoin does.
Now for a more complex topic:
Development: 100% Decentralized, Unless we Hard Fork

Soft and Hard Forks
A soft fork is a change to the Bitcoin protocol to make it more restrictive. A hard fork, in contrast, is a change to the Bitcoin protocol which makes it more permissive.
Game
Soft
Hard
Chess
Neither player can castle after move 10.
Any Queen can move three times in a row if her King is in check.
American Football
A team can only score a field goal if they have not yet thrown an interception.
Any team up by 20 points or more can declare themselves the immediate victor.
What is the effect of each fork-type?
Well, players are immune to soft forks. After all, there likely have been many chess games where neither player castled, and many football games where neither team ever attempted a field goal. Everyone can observe, or play in, soft-forked games with complete indifference (although they may become increasingly confused by a playerâs seemingly bizarre moves).
Hard forks, of course, have a theoretically unlimited effect on the game. It depends on the details: in the football example, a team up by 20 will probably (not necessarily) win anyway. The chief motivation in football is to earn more points; it doesnât change under the new rule. In contrast, the chess hard fork transforms the game substantially. Whereas, originally, checking your opponentâs king was highly desirable, now it is outright dangerous. Moreover, no one will sacrifice or risk the loss of their queen, and players might march the king out into the middle of the field, to trigger check (and the additional queen moves it grants).

Free to Choose
Un-upgraded software will, by definition, already be compatible with all future soft forks (and incompatible with all future hard forks).
For a given protocol, the user is free to choose among any soft-forks he wishes. The resulting competition is entirely centralization-proof: no authority can disable your version.
All versions are compatible, so, even if all the devs were kidnapped (and forced to write Evil Bitcoin Soft Fork), no one needs to upgrade. If you accidentally do upgrade, you can merely switch back. To âknow youâve been paidâ you can run any version of the software you like, including the very first version!
Your version might be slower, uglier, etc, but it will let you âknow if youâve been paidâ. It wonât allow YOU to be paid in a ânewâ (ie, âupdate-dependentâ) way, and it wonât know if other people have been paid in a ânewâ way (because it necessarily doesnât know why the coach chose to avoid a âpost-interception field goalâ: Was it to comply with some ânewâ rule, or just because he doesnât want to?).
But all of your own money is protected by the âold rulesâ, no matter what fancy other rules other people play by.

Figure: Mike Hearnâs bizarre obsession with money that doesnât belong to him.
Hard Forks Threaten Bitcoinâs Accumulated Security
With soft forks, there are no surprises. Your money is protected by the âold rulesâ.
Because a system is only as secure as the adversarial environment it has historically survived, we can translate â..protected by the old rulesâ as â..safeâ (for 6-year-old Bitcoin, anyway).
With hard forks, your money is subject to a new system. In principle, âa hard forkâ could mean anything: stealing money, printing money, freezing the network permanently, itâs all on the table.
Therefore, the critical question is: âAre these new rules any good?â
Cost of Node-Option
To âknow youâve been paidâ (ie âP2P moneyâ) you need to know that the software wonât lose your money. After all, the definition of âpaidâ implies that the money now belongs to you and is controlled by you exclusively. Whether you lose your BTC to theft, or you lose them because the entire network collapsed, âyouâ have been âunpaidâ (and you instead âknow that youâve not be paidâ).
On top of that, if âthe networkâ (users, merchants, service providers, âŠ) switches, you have no choice but to switch. If you refuse to switch, and stay on the minority network, your money will be useless and you will be âunpaidâ!
So the cost of âknowing youâve been paidâ (the cost of âthe option to run a full Bitcoin nodeâ), necessarily now includes maintenance items, which YOU must pay if YOU are to KNOW youâve been paid: [1] the cost of âvalidatingâ any new set of rules and [2] the cost of preventing other people from being deceived into accepting unproven rules.
Because you can only know youâll be paid if the network uses rules that allow you to spend your future income.

Node Option = Hardware Costs + Privacy Costs + Maintenance Costs
âŠitâs really getting expensive!
Hard Forks Destroy Decentralization
If one avoids hard forks, we donât need to ask âAre these new rules any good?â at all, and so maintenance costs will be zero. Developers will never have any privilege, and there will be no centralization.
Unfortunately, of course, this limits our ability to improve the software!
Instead we might try to only propose hard forks where as little as possible has changed, so that âAre these new rules any good?â is likely to be easy to answer.
Then, with [1] enough experts involved, and [2] enough time for them all to voice their concerns, the user could eventually be as confident that âthe rules are goodâ as the net confidence of the experts.
Unfortunately, our experts just arenât smart enough. No one is.
Prediction in Complex Systems
We will probably never know âif the rules are goodâ, which means that maintaining decentralized access to oneâs money will be impossible under a hard fork.
The Ideal Conditions (Arenât Good Enough)
While it is claimed that NASAâs shuttle program achieves a 0 bug rate (per 500,000 lines of code), that is actually not true. Even getting as far as 1 per 440,000 apparently requires 260 full-time experts (Bitcoin has barely a handful) working under âthreat of deathâ, in an execution environment where they control 100% of the hardware and software, and there is no adversarial activity whatsoever, and no user input of any kind.
Ask them about it! Hereâs Appendix D (âFlight Software Complexityâ) of their report on getting it right:
The very first sentences quote sociologist Charles Perrow: ââŠabout the causes of failure in highly complex systems, concluding that they were virtually inevitable.â He continues: ââŠwhen seemingly unrelated parts of a larger system fail in some unforeseen combination, dependencies can become apparent that could not have been accounted for in the original design.â
Of course, a space shuttle is really complex, right? Instead, why donât we take something that has been operating continuously, without any problems, for like 10 years. Then, weâll take the elite NASA programming team and have them change just a single parameter.
It does not get any better than that.
But, in the end, the Black Swan always gets his man:

Figure: this perfectly-healthy robot wound up entirely disabled after The Experts updated a single parameter.
Sound familiar?
Bitcoin is the Opposite of Ideal
Mankind will have perfected space travel long before we remotely understand software systems.
Just ask Greg Maxwell or Gavin Andresen. Or Mike Hearn.
Someone attempted to count up Bitcoinâs lines of code, and concluded that there were a little over 12,000. In order to reasonably predict that a hard fork is safe, someone must evaluate each change against every existing line of code.
But no, the fun only begins once youâve done that. You now need to forecast, with perfect accuracy, the effect of the softwareâs new allowances on all real world attributes of the Bitcoinâs wider economic system, as well as all psycho-social responses (rational or otherwise), and all new opportunities (whether change-based or uncertainty-based) given to motivated adversaries.
No human being has the research capacity to actually do this.
So, you see, the average citizen is far more beholden to the developer who writes his software, than he is to the politician who writes his laws. Breaking the developerâs (more numerous) rules is literally impossible, and thereâs no recourse (socially, politically, practically, âŠ).
An Actual Example
Hereâs a best-case scenario for a hard fork, because it is actually describable in advance:
- An 8 MB blocksize creates an incentive to selfish mine, such that miners must force all blocks to be 8 MB.
- The dramatic explosion in required bandwidth makes it impossible to run a full node anonymously.
- Because most presidents / current presidential candidates plan to use payments as a foreign policy negotiation tool, the âUS Freedom America #1 Anti-Terrorist-Financing Emergency Powers / âFlags for Orphansâ Orderâ is âhappenedâ.
- Anyone who runs a full node in the US is jailed, anyone who runs a full node in a non-US is flagged as a terrorist.
- Although some try to keep the node count afloat, the skills and resources required to do this are rare. These few are harassed, coerced, arrested, or outright assassinated.
- The Bitcoin project collapses.
Just think: with all the unknown unknowns, the true possibilities are unfathomably worse. One thing to point out is that a hard fork can be undone via soft fork. Since miners are the driving force behind soft forks (and since mining is capture-able), any hard fork which grants extra influence to miners would likely increase strategic complexity to a degree that could only be described as âunwiseâ.
But, protected by soft forks, you will never need to worry about all those things you didnât understand until moments ago.
Contentious Hard Forks Obliterate Decentralization
I could go on (perhaps in a new post), but letâs wrap this up.
Grandma User does know that: âBitcoin Core has been running for 6 years, it seems fine so farâ.
Grandma User can not know that her money will be safe under the new rules of âBitcoin Core II Duoâ. She doesnât have what it takes (150+ IQ points, technical inclination / CS PhD, a network of experts, and 100+ hours of free time), so, she must trust an authority. A hard fork elevates those who are Technical, Persuasive, or Endorsed, to ânon-peerâ status.
From there, the problem gets worse. Say x is the probability of hard-fork disaster, and f(x) is the probability that the âgreatest expertâ [1] catches the error, [2] is known (as an âerror catcherâ) to the audience (impossible to scale past 1-5 known experts) and [3] articulates his/her point clearly. As f is applied multiple times (as the info spreads to multiple people) the resulting f( f( f(x) ) ) will quickly degenerate to zero. Knowing this, individuals will minimize the number of f()âs and trust the Main Expert directly.

As with the very Federal Reserve System that Bitcoin aims to replace, these elite ânon-peersâ will [1] Team Up for greater collective clout per non-expert info-processed, [2] import credibility from top credential-ers, [3] entwine themselves with existing players, [4] formally entrench themselves to prevent the âwrongâ people from making changes to Bitcoin.
In the extreme, an environment of frequent hard forks would eventually obviate the need for validation rules at all, and the people in charge would just be doing whatever they wanted.
The initial esoteric âtechnical and (subjectively) meritocraticâ would collapse into a formal power structure. The minority who understood âoriginal Bitcoinâ will be powerless to prevent ânew Bitcoinâ from morphing slowly away from the principles that originally made it distinctive.
Conclusion: Remove the Contention
Iâm not saying that we should never hard fork, only that doing so does tremendous damage to decentralization and is extraordinarily risky in general.
The decentralization of Hard-Forking can be increased as the âcontentionâ decreases. I am aware of only one way to transform subjective judgments into objective information, as such a method must be itself P2P (ânon-capture-ableâ, ie, allows anyone to express their [anonymous] judgment, without permission), incentive compatible, and produces a non-degradable signal (âcommonâ knowledge supporting âfree coordinationâ).
Decentralization increases if contentious forks are met with hostility: forked coins could immediately be sold, businesses who transact in them could be ostracized, individuals who support them should be discredited. A social norm of hostility would decrease the risk that a Bad Hard Fork will accidentally âunpayâ everyone (ie, makes it cheaper for everyone to maintain their full node), but it would also make it harder to âupgradeâ the software. It is a tradeoff, like anything else.
Bring on the Big Server Farms
Is an obsession with âcheap full nodesâ consistent with Satoshiâs vision and statements?
Satoshi seemingly contradicts himself here:

In that he proposes something with two tiers (not âpure P2Pâ), such that, if everyone in the upper tier is destroyed, the network fails. Iâm interpreting his analogy as something like:

Resolving the Contradiction
My interpretation is that Satoshiâs use of the word ânodeâ is, in this case, overly liberal (ie, âincorrectâ).
First, clearly these claims are true: [1] the intended configuration wonât scale, [2] it is impractical to have everyone validate everything, and [3] some users will lack the ability to run a full node, and thatâs not a catastrophe (and able users are completely indifferent to it).
The Usenet analogy, furthermore, seems perfectly descriptive. However, Satoshi clearly intends all (or âenoughâ) of these âbig server farmsâ to be safe, and these âNNTP serversâ will be anything but.
Usenet isnât Good Enough
Iâm hardly an expert in this area (or, rather, this âeraâ).
But, what happened to Usenet? It became overloaded with spam, child pornography, and pirated software, and two non-peers (the government and ISPs) eventually pulled the plug (which is why 99% of the people reading this probably have no idea what the Usenet is). Once, the âChurchâ of Scientology used legal pressure to close down the (at the time) most popular anonymous remailer (a kind of Usenet âgatewayâ). Not exactly âheadlessâ.
We donât need to wonder âwhat would happen if Bitcoin were like Usenetâ? It would overflow with spam and be killed by law enforcement.
Toying with Indifference
Of course, Usenet survives today as a paid service (and not a cheap one), but my feeling is that, if law enforcement knew or cared, theyâd go back and finish the job. Today, Usenet is an enclave of the technical elite: itâs relatively complex to set up and use, its users are smart enough to not talk about it [sorry, guysâŠSatoshi brought it upâŠ], and most regular people have no idea how the internet works at all (watch these people mis-describe a web browser as basically âa librarian they ask for helpâ, and these and this, and why not this) let alone Usenet. Usenet is, to borrow a phrase from Greg Maxwell, secured by âindifferenceâ.
After all, you canât care about something if you arenât aware of it.

From a 100% real survey. Keep in mind that 50% of people will correctly answer a True-False question that they personally know nothing about.
Compare that to this:

âOn day one in the Oval Office I would make two phone calls. The first one would be to my good friend Bibi Netanyahu, to assure him that we will stand with the State of Israel. The second will be to the Supreme Leader of Iran. He might not take my phone call, but he would get the message, and the message is this: Until you open every Nuclear and every Military facility to full, open, anytime, anywhere, for real, inspections, we are going to make it as difficult as possible for you to move money around the global financial system. I hope congress says no to [the Iran deal], but, realistically, even if they do, the money is flowingâŠwe have to stop the money flow.â (emphasis added)
-Carly Fiorina, Widely-Regarded âWinnerâ of the Fox News 5 PM Debate for 2016 Presidential Candidate, beginning 39:50.
Conclusion (Usenet Analogy)
Usenet never prevented a US President from executing on their Iran âAnti-Nukeâ Foreign Policy. Such a difference is too excessive (to sustain the analogy), and removes the (required) expectation of full-node-safety.
Which is interesting, because the NNTP analogy is almost perfect.
In fact, it more reminds me ofâŠ
The Lightning Network
You see, it would really be something like this:

Thereâs cheap nodes, run by everyone, and no central authority. There is a two-class hierarchy.
An Authority on what?
The âupper classâ in the Lightning Network is a little bit like a limited government: it exists to serve the public, and there are strict rules on what it can and canât do.
It Canât
The hubs canât prevent you from becoming a hub yourself:

And they canât prevent you from circumventing the hubs:

It Can
During the custodial period (about a week) The Hubs do get to determine if you will, or will not, be able to make a cheap transaction with the money you deposited with them. If they ban you from making any transactions (or, their computers get shut down by the government, or catch fire), your money is stuck there for the duration of the custodial period. However, it is only temporarily trapped: your money canât be lost or stolen.
Basically, itâs a bank that canât steal your money. Revolutionary!
Since anyone can become one, the resulting competition will result in maximal uptime and minimal fees for everyone.
Servers that compete on uptime? âŠjust as is done today withâŠgaspâŠâbig server farmsâ.
Reinterpretation
As Satoshi said, the current configuration is indeed not appropriate for large scale payments, that would indeed place an excessive burden on each user, âthe design supports letting users just be usersâ, and a few ânodesâ can be large server farms.
However, the Lightning Network configuration is much more rational, specialized, and efficient. To our point, it increases decentralization by making a full node cheaper: by allowing many transactions to take place off-chain, fewer happen on-chain, and fewer burden each full-node-user. This is true even if you refuse to use any off-chain transactions.
Increasing Decentralization
To improve Decentralization, make full nodes cheaper. One overlooked way to do this is with a âTor supply curveâ (which Bitcoin can provide)!
The Last Discontinuity
Given our conclusion, the easier it is to start up a new full node, the more decentralized Bitcoin will be. How can we make full nodes cheaper?
Iâd ignore mundane expenses like hardware and power. Instead, recall that, if a full node cannot be run anonymously, âthe networkâ (full node entry) is effectively controlled by law enforcement, a central entity. Therefore, my view is that the current largest âcostâ (and current bottleneck to Bitcoin scalability) is therefore the threat of persecution.
It is a shame to have come so far, only have one tiny subjective abstraction interfere with my presentation of an actual number.
Intermediate-Good Bitcoin
One way to address this bottleneck (and make decentralization easily measurable at the same time) would be to increase the supply of âTor-Bandwidthâ (or equivalent âinternet anonymityâ). However, Tor-Bandwidth currently has a big problem: the anonymity prevents anyone from paying for it. This means that it cannot be bought or sold, its price is fixed at zero, and we will only have what is volunteered.

Moreover, âavailable at no costâ also means âit can be attacked at no costâ. This is highly problematic, as the price cannot even react to the attack (âreact to changes in scarcityâ), and the lack of price prevents capital investments from efficiently increasing long-run supply. (After all, our internet service providers built the current internet to purposefully have limited consumer upstream bandwidth because thatâs what the market told them we [could prove we] wanted).
Anyone looking to improve Bitcoinâs decentralization might look at integrating Bitcoin payment channels with Tor nodes (or metering bandwidth in VPNs, or in general). Keep in mind that more decentralization is not always better, but, as decentralization improves, we can be more comfortable âtrading offâ some for other things weâd like to have (ie, bigger blocks, and cheaper/more-numerous transactions).
Conclusion
To increase decentralization, focus on making a full node cheaper. âDecentralizersâ include the Lightning Network, Tor, and metered bandwidth services.
I will be in Montreal to discuss this and related issues.
Add Disqus comments.
comments powered by
Disqus
The Hashing Heart Attack
By Paul Sztorc
Posted October 28, 2015
Special thanks to Marshall Long, Greg Maxwell, Mark Freidenbach, and Adam Back for related discussion.
The Problem
This issue is one which might disable Bitcoin completely, requiring a (simple) hard fork to get it âunstuckâ. This issue becomes more dangerous over the next 20-30 years (likely most dangerous in 2020-2028), but then quickly declines.
Iâll break it into two subproblems:
SubProblem 1: The blockreward halving instantly cuts miner revenues by a huge fraction.
Of course, this assumes [1] that transaction fees are negligible and [2] the Bitcoin exchange rate never increases in response to the difficulty halving.
Transaction fees are currently around 1% of miner-revenues, and no one expects this proportion to significantly increase anytime soon. Even if transaction fees were 50% of revenues (wildly optimistic), the reward-halving would still cut total revenues by (1/4), a sizable proportion.
The Bitcoin exchange rate (important to miners) shouldnât change in response to the difficulty halving, at all. By Weak Efficient Markets, anyone who believes that âthe USD/BTC price will imminently doubleâ, should be buying immediately (and bidding up the price). Iâve previously written that, because of âsaturationâ, Bitcoin might have some immunity to the EMH, but (like all EMH-resistance) this immunity is constantly hard at work, canceling itself out.

Figure. On the left, the reward-halving dominates the block-reward; on the right, transaction-fee variance dominates.
SubProblem 2: The difficulty adjustment process causes miner homogeneity.
Every two weeks, the total costs of mining (namely, the difficulty) reset such that the average miner achieves an expected economic profit of zero. Those in the bottom half can no longer afford to operate, and they (eventually) switch their miners off and drop out of the system.
Of course, this is an academic simplification of actual mining. It ignores [1] uncertainty (in all factors) and [2] âpermanent advantagesâ (âfreeâ power, geographic distribution of energy sources, ASIC engineering secrets), but those artifacts merely slow the inevitable: this is an ever-present, fundamentally underlying process of filtration.
As the lower-quality miners get filtered out, the filter reacts to the increase in quality by becoming more intense. Eventually, only a few top quality miners will remain. These miners might follow different best-practices (all the solar-power miners might have a different set of best practices than the hydro-power miners), but all miners should eventually have tiny, and equal economic profit margins.

Because an average is just a single number, it necessarily contains less total information than the distribution from whence it came.
Combined
The problem is when these two effects happen at the same time.

In short, we will reach a day when all miners have small profit margins, and then a blockreward-halving will slash their revenues in half. The result will be that not half, but all miners will shut off their mining rigs.
You see, the difficulty wonât re-adjust (decrease) until (on average) 1008 blocks later. (In fact, we always know exactly the number of blocks.) So, even miners who plan to turn their mining rigs back on, post-difficulty-decrease, would have them off for this brief unprofitable period.
The problem is that it might not be brief. The difficulty adjustment period, which would normally last two weeks, is counted in blocks, not human-time. So it could actually last forever.
(Or, until someone manually hard-forked the network [to something with 60% difficulty], thus giving the stalled engine a jump.)
But thatâs not all: even if most of the miners stayed on, the resulting uncertainty (or merely the increase in confirmation times) might cause a Bitcoin currency crisis. Abnormal tx-fee and exchange-rate volatility would increase Bitcoinâs risk premium, harming Bitcoinâs value-proposition as money. One example: were the USD/BTC price to fall by half, the blockreward-halving would have an effect more-resembling a blockreward-quartering. A falling USD/BTC price widens the gulf between mining costs and revenues, and makes the problem even worse, potentially resulting in a death spiral.
In the near term, miners are different enough (and the exchange rate is already volatile enough) such that most will survive the halving, and in the long term, Bitcoin might be sufficiently important such that transaction fees simply increase (in step with the higher confirmation times) to offset the problem. However, in the medium term, namely the year 2020, it is potentially disastrous.
Solution
What Wonât Work
Do Nothing
We might hope that miners, out of the kindness of their hearts, would simply keep mining (at a loss) to prevent Bitcoin from dying (and prevent their specialized hardware from depreciating to zero).
This isnât acceptable to me - in equilibrium, miners consume all of their BTC revenues (which are all spent on operating or capital costs), and it is easy to imagine miners who plan their capital investments to align with the 4 year Bitcoin halving cycle (âweâre going to run these into the ground until the reward halves, and then replan from thereâ). Mining hardware itself rarely lasts longer than 2 years, anyway.
The cost of altruistic mining can be roughly estimated. Currently, miners collectively earn 201625300 = over $15 million dollars in revenue each difficulty cycle. These inputs might all change, of course, but, if they didnât, the 2016 halving would slash this revenue by over $7,000,000. If miners were already running at cost, this 7M figure is the cost of keeping 10 minute blocks. Worse still, such altruism would prevent the subsequent difficulty adjustment from being representative; miners would only keep themselves trapped in Altruism Prison, losing money the whole time.
Moreover, âweâ are increasingly unable to âhelpâ the minersâŠongoing professional hardware-specialization makes our âcivilian hardwareâ (home PCs, phones) overwhelmingly irrelevant.
Upon Each Blockreward Halving, Also Halve the Difficulty
Clearly the intent was to cut profits in half, not revenues. Unfortunately, thereâs no clear way for the protocol to learn about minerâs profit margins.
One (hard fork) idea is to simultaneously halve the difficulty (with the reward); this might work, but instead it might simply delay the problem for 2016 blocks (which might all mined in one week, instead of two), at which point the difficulty would doubleâŠlanding us right back where we started. If âhalving the difficultyâ perfectly halved the total costs of mining (including overhead and labor), and the blockreward perfectly halved the revenues (ie, transactions fees were nonexistent and the exchange rate never changed), then it might work, but difficulty has a stronger relationship with time than it does with cost (and revenues are driven mostly by Bitcoinâs exchange rate).

It seems that thereâs only one way to guarantee that the problem be removed.
Smooth the Disinflation Out
The only ironclad solution is to replace the sudden halving of the Bitcoin coinbase with a continuous, gradual decrease.
Something like this:

Where r refers to the quantity of BTC released per block, t refers to the block number (ie, âtimeâ), and lambda is some parameter. (Little t is used to index on r, but big T refers to the actual number itself).
Fork Types
This can be done either with a hard fork or with a soft fork.
While any hard fork can replace one issuance policy with another, a soft fork must obey the original issuance rules. This can be done by storing coins in a kind of âsoftfork reserve accountâ, with special rules allowing only future block-finders to withdraw. Because the bank can never have a negative balance under soft fork, such a change would involve some sacrifice on the part of the miners (theyâd be losing coins that theyâd otherwise be able to keep). A hard fork, freed from the original rules, can reduce this problem.
Details
I did some preliminary Excel math to take a first look at the potential issuance schedule and its effect on miners. This analysis is oversimplified (a year spans just a single row, instead of 624365 = 52,560 rows), and I would (obviously) improve it before making a formal proposal. The specific numbers are, of course, irrelevant; only the concepts are relevant.
.
Original
Hard Fork
Soft Fork
Lambda (Annual)
N/A
.012
371160
.012
166134
PV Impact (BTC, at 5%)*
N/A
-81,442.1
-119,080.3
BTC in Year 2168
21,038,400.0**
21,038,399.7
20,973,054.6
*Obviously, I used math to minimize this value in each case. **This value is not 21 million, because of leap years (and other simplifications, which are consistent across scenarios). So, âHard Forkâ is accurately recreating âOriginalâ (and not a second error).


The soft fork eventually starts accumulating larger-and-larger proportions of tinier-and-tinier blockrewards, such that ~65,000 BTC remain trapped in the bank forever.
Costs
Most of the damage (~ 81/119 ~= 68%) is done whether the fork is soft or hard.
This damage (the cost to miners, of loaning these coins to the bank without compensation) would be substantial: at a market price of $250/BTC, the 119K BTC are worth nearly $30,000,000 USD.
Of course, mining revenues are mostly driven by the exchange rate itself, so we have to weigh this cost against any BTC appreciation that might occur as a result of this change.
How the Soft Fork Might Work
As mentioned, the soft fork would still allow miners to âmineâ 25 BTC per 10 minutes. Some portion of these 25 would simply be âfrozenâ (metaphorically, they would be âplacedâ into a âminer-bankâ).
We might require the âbankâ to be an âANYONE-CAN-SPENDâ BTC address, yet with miners enforcing a pre-specified policy for spending from this address. Later, when someone mines a block that needs to âwithdrawâ from the bank (during the 2020-2038 years, where the smooth curves are above the blue jagged line) the refined protocol can simply agree to allow a certain number of BTC to be transferred from this address to anywhere (knowing that the winning miner will give it to him or herself).
This would be the first soft fork which is not obviously a Pareto improvement: it harms a subset of individuals (the miners) âif we neglect to consider that miners would also be harmed by Bitcoinâs collapse as a result of this unfixed problem. This is particularly interesting because miners are the very group which turn soft forks on and off. At around year 2020, the ANYONE-CAN-SPEND address will have accumulated over 450,000 BTC (today, worth over $120 million).
To prevent an interesting situation might emerge where miners attempt to raid those funds, possibly by bribing users to upgrade their software, or by lobbying in some other way, notice:
- Regular users would almost certainly have upgraded their software by then (making this a little more like a hard fork).
- An un-forked block is too valuable for its own good. Worth more than surrounding blocks by a factor of 72,000 ( = 450,000/6.25), The Block that rewards all these coins would be fought over endlessly (as new miners will most certainly jump online to mine this single block, and then refuse to participate in a chain that does not allow them to win). So, threats to start a fight arenât very credible.
How did this happen?
It seems strange to see a design flaw in Bitcoin, something which was otherwise so perfectly-crafted. Iâm inclined to think that the inherent fairness of the static â50 BTC per blockâ appealed to Satoshi; that he anticipated a great deal of criticism off the bat, and didnât want to be hearing âI donât want to join this! Youâve already started mining and got all the easiest blocks for yourself!â.
And, it certainly is easier to explain âyou get 50 of them with each block, but this number drops by half every four yearsâ than it is to say â âa formulaâ determines how many BTC you getâ.
Or, perhaps I have misunderstood? What do you think?
zzz The source of the flaw (and other âdifficulty oscillationâ) is really the clunky 2 week difficulty adjustment, which, by definition, can only forecast 2 weeks into the future, using data from 2 weeks in the past. the difficulty adjustment had to be a little clunky, because of the way that Satoshi measured âtimeâ.
Add Disqus comments.
comments powered by
Disqus
Itâs All About the Blockchain
By Erik Voorhees
Posted October 30, 2015
Blockchain is so hot right now.
2015 was the year the narrative changed. Bitcoin is out, blockchain is in. Attend any financial conference and youâll hear panels about the brilliance of private distributed ledgers. Private blockchain initiatives like R3 CEV have attracted over 25 of the worldâs top banks to participate. Airports everywhere are displaying Bloomberg Marketsâ recent cover story, featuring Wall St. tour-de-force Blythe Masters sitting elegantly behind a celebratory banner, âItâs All About the Blockchain.â Even investors who have long backed Bitcoin startups now make sure to convey in their promotional copy that theyâre involved with âexciting Blockchain ventures.â Whatâs your blockchain strategy? Bro, do you even blockchain?
The ascent of this term in the media and financial industry has been dizzying.
And âBitcoin,â as a thing somehow distinct from âblockchain,â has been left by the wayside, ignored like an embarrassing relative at a family gathering.
Some of us have been amused by this development, but many confounded. Why is everyone talking about the blockchain, and ignoring its central fuel, Bitcoin proper?
First, letâs understand why the change in narrative had to happen, why it was necessary and indeed inevitable.
Bitcoin, to many in the world who have casually heard about it, is an uncomfortable and cryptic creature, existing somewhere between Ponzi Scheme and âmoney used by bad people.â Didnât Bitcoin go bankrupt in Japan? Wasnât the CEO arrested? To others, itâs just downright weird and unnecessary. Visa works just fine, thank you.
More importantly, though, to professionals in the money realm â to bankers and investors and financial regulators â Bitcoin is an awkward and annoying development, a technology almost all of them dismissed as absurd and useless, and yet it keeps growing. Bitcoin promises a dangerous world without strict top-down financial control. Terrorism. Think of the children. Bitcoin made the term âfiatâ a thing, and when something has a name, it can be critiqued. Every day Bitcoin exists, it demonstrates the naive idea that money may be able to work without central planning. Worst of all, Bitcoin brings with it an obnoxious cult spouting proletariat nonsense like âfinancial privacy is a human right,â and âmoney should move faster than an anvil FedExâd to Singapore.â
What respectable banker wants to deal with that?
And while the technology brings with it vast promises of financial innovation, these cannot be discussed in terms of âBitcoin,â because this term brings with it all the aforementioned baggage. One cannot discuss Bitcoin in polite company, for the conversation may veer into one of monetary theory, human rights, massive sovereign theft and bank fraud⊠better stick with the weather.
But how do you convince your boss or shareholders that youâre keeping pace with innovation? They read the news, they know that disintermediation is a thing. At the edges of their mind, they have a sense that, perhaps, charging $45 to send a money transfer message is neither logical nor sustainable. As Jamie Dimon recently warned in his annual letter to shareholders, âSilicon Valley is coming.â
Enter âBlockchain.â
Ahhh, what a term! It encapsulates all the magic, all the technological brilliance, all the promise and the sparkle of true financial innovation. And it does it without devolving into a discussion of Silk Road or Jekyll Island.
Blockchains, as a concept, are not controversial. Bitcoin is highly controversial. That is why the narrative changed â because âBitcoinâ makes financial professionals uncomfortable. There was no conspiracy to change the subject, it just happened naturally; the path of least resistance.
But what is it, exactly, that they hope to achieve by advancing private, non-Bitcoin blockchains? Without Bitcoin, a blockchain is just a distributed database â not exactly a novel technology. What is R3 CEV but a sexier and more social MySQL database? Why did banks not build such distributed ledgers long ago? If they are the arbiters of transactions, there is no need for mining, and thus no need for a blockchain, per se.
Perhaps such a distributed database never happened before because the banks havenât felt the true competitive pressure to innovate. Banksâ biggest innovation in the last two decades was the Geithner Swap, in which loss due to excessive risk taking is swapped for taxpayer money. Banks arenât so much financial innovators as they are lobbying cartels. But can you blame them? When Government forces its way into bed with you, who do you imagine youâll wake up with?
It remains to be seen how long it takes for the financial industry to realize that the true valuable innovation is not the distributed ledger of the blockchain (which has existed in other forms prior), but rather the open platform of financial inclusion with no trusted party or cartel (which has never existed).
It is precisely Bitcoinâs openness which, like the internet before it, brings revolutionary change to how humans interact. Bitcoin wasnât revolutionary because it could move money faster, or more cheaply, than banks. Most of the banksâ delay isnât due to technology â theyâre just sending digital messages representing virtual money, after all â itâs due to regulation, bureaucracy, and habit.
Supporters who are âall about the blockchainâ may counter that the blockchain demonstrates truth, demonstrates finality, and thus as banks adopt this technology they will be made more efficient because the uncertainty of settlement will be resolved. Sure, blockchains can help with this, and banks can be more efficient for it. It seems clear that blockchain-based banking networks could settle payments in minutes, not days.
But thatâs missing the point. A marginal gain in efficiency isnât what weâre excited about, and indeed a centralized system like PayPal can always be faster than a blockchain, from a technical perspective.
This technology wasnât created as a way to make things a little faster, though certainly thatâs one of its benefits. The real purpose, the purpose which in hindsight will be hailed as the real innovation, is to remove censorship and central-control from money itself.
Is the internet remembered as the means by which Time Warner more quickly delivered its content to readers? Is the printing press remembered as the means by which the Church more aptly conveyed its prognostications to the devout?
It was the openness of these technologies â the fact that anyone, in any country, could access them, build with them, & experiment with them. One did not have to be 18 to sign up. One did not have to be on a government-approved list. One could write whatever she wished, communicate with whomever she felt relevant.
Blockchain technology, properly understood, is decentralized. It is an open platform. It does not pass judgement on human actions, it simply enables more action, more easily, to everyone. A blockchain strategy that doesnât appreciate this is doomed in the same way and for the same reason as AOL and CompuServe. Does industry really need that lesson again?
How many billions will be wasted by banks seeking their own private distributed ledger, before they realize that the service of âledgerâ is just one branch in the tree of broad human communication, and such communication tends to open over time, rather than close.
So industry â if you need to keep using the word âblockchainâ to feel socially comfortable when discussing the renaissance, thatâs fine. But for the sake of intellectual honesty, not to mention fiduciary duty to your shareholders, donât fall into the hallucination that siloed financial networks are innovative or lasting. If your blockchain strategy ends at the edge of another bank, youâre doing it wrong.
Moving from a permissioned financial network between banks, to a permissioned financial network among banks, is no great step for mankind.

Erik Voorhees http://www.ShapeShift.io Erik Voorhees, CEO of leading digital asset exchange ShapeShift.io, is among the top-recognized serial Bitcoin advocates and entrepreneurs, understanding Bitcoin as one of the most important inventions ever created by humanity. Erikâs former project, the groundbreaking gaming phenomenon SatoshiDICE, was, at its peak, responsible for more than half of all Bitcoin transactions on Earth and popularized the concept of âprovable fairness.â Having been a featured guest on Bloomberg, Fox Business, CNBC, BBC Radio, The Peter Schiff Show, and numerous Bitcoin and industry conferences, Erik humbly suggests that there is no such thing as a âfree marketâ when the institution of money itself is centrally planned and controlled. This blog is about the human struggle for the separation of money and state, and about Bitcoin as the instrument by which it will happen.
You can start editing here.