October 2015 Journal

60 minute read

WORDS is a monthly journal of Bitcoin commentary. This issue collects the October 2015 writing in the WORDS archive. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. That’s why we made this journal, to preserve and further the understanding of Bitcoin.

Subscribe


Estimating and minimizing consumer worry

By Nick Szabo

Posted October 8, 2015

The process of selling in general, and web commerce in particular, is often described or charted as a funnel. Prospective customers are poured in at one end, and a fewer number of paying customers come out at the other. The other prospects spill out through other holes or over the side of the funnel and don’t bring you any revenue. The fraction of customers left, converted from prospects to customers, is called the conversion rate. As prospects proceed from initial interest to final sale, from initial entry page to clicking the final “I Agree” button, more and more of them become discouraged by various worries which beset the consumer. They drop out. The remaining prospects, those who have not dropped off, have been converted into customers or into an audience for your advertisers.

There are a variety of factors that cause drop-off, which vary from business to business. A common cause is forms. Simplifying forms often greatly increases conversion rates. For example, in one

study

cutting the number of lines on a form in half increase conversions by a third. As one web designer

put it

“[i]s every field you’re asking the visitor to submit absolutely necessary? Can you trim the fat and make the process simpler?”

Besides the sheer tediousness and time consumed in filling out forms, rational consumers also worry about the potentials for privacy violation and identity theft from the information most e-commerce sites currently require them to divulge: physical and e-mail addresses, phone numbers used for cross-site behavioral tracking, insecure credit card numbers, and more.

The tinfoil-wallet crowd is now mainstream

Instances of regret that one has filled out a form, only to have one’s

trust violated

– or

pride

among the sophisticated that they refused to fill out such a form – are on the rise.

The worst worry culprit is usually the step you most want your customers to complete – paying you. “[T]he credit card form likely has the highest abandonment rate of any other part of the sign-up process.” [

Source

].

If you don’t require payments, you are probably funding your service through advertisements. Those also cause worries. Ads typically distract and delay from the content users are after, provide a low quality of entertainment or information, and are too often offensive. And sophisticated users are worried about the tracking that tends to go with ads. Ad blocking

grew

nearly tenfold between 2009 and 2014.

Replacing ads and identity-based payments with payments that don’t require identity, such as bitcoin, can greatly reduce these worries, lowering the barriers and hesitations that currently prevent consumers from paying for your service.

But there remains a big worry that no payment system can reduce. Consumers worry about whether they are getting their money’s worth – the

mental transaction cost

problem (see also

this paper

). If e-commerce were as worry-free as some of it could be, your customers would neither have to fill out forms, nor be bothered by ads, nor have to worry about repeated charges for content or services of variable value. They would be able to just insert a few digital coins into your online vending machine and then not have to worry about losing your service for another year. Eliminate forms

and

eliminate repeated payments – both are key to worry-minimized e-commerce.

Many bitcoin startups are making the grave mistake of replacing one set of worries with another. The ability of cryptocurrency systems to facilitate small payments tempts many companies to nickel-and-dime their customers with pay-per-click micropayments and other such excruciating schemes. Don’t follow the many lemmings who have already jumped off that cliff. Stick to long-term subscriptions for content (or other services of variable value) and pay-per-unit for fungible units of consistent value (as in phone minutes). That way customers aren’t saddled with having to constantly re-evaluate the amount and worthiness of recurring charges. The costs to your customers of having to finance a years’ worth of low-cost subscription to a reputable brand is almost always far less than the mental transaction costs of recurring charges for content or services of variable value. The ideal worry-free commerce is to “stick the coin into the machine” once, and then never have to pay again for an entire year. A vending machine for subscriptions. Reduce your customers’ worries across the board: eliminate forms

and

eliminate recurring charges.

Ideal worry-minimization can only be closely approached in some purely online forms of commerce, such as video streaming, remote storage, privacy services, and the like. The more physical and offline contract performances are – a common example being physical delivery – the more location, various kinds of identity (legal, social network, etc.) may need to come into play, adding, often greatly and necessarily, to the worry overhead, the mental transaction costs, of your relationship with your consumers.

I have previously called this worry-minimized commerce by a narrower label, “form-minimized commerce.” The complexity of the forms you make your users fill is indicative of the worries you are causing them, and thus the barriers you are putting up between your prospects and their decisions to purchase your services.

When you are a consumer, the tediousness of the forms you are filling out is not only a direct cost of your time, and your ability to enjoy that time, it is on top of that a decent proxy measure of the odds of your identity being stolen and of your privacy otherwise being violated. The fewer forms you fill out, the more the tediousness, worries, and risks in your life caused by interacting with the world’s institutions will drop in proportion.

While such a proxy measure does not account in particular for the wide variety of information that can be disclosed, nor that some kinds of information (social security numbers) are more risky to divulge than others (throw-away email addresses), nor for the wide variety of risks in identity theft and privacy violation that are consequent, nevertheless consumers necessarily must bring to bear such sweeping rules-of-thumb in order to satisfactorily navigate the bizarre complexities of the digital world. And when your users are using, whether consciously or implicitly, such estimates, you the service provider and the product designer must use them too.

Add to the forms your customers must fill out the repeated charges you make your customers make, and we get a rough proxy measure of the worry that you are causing your consumers:

Index of worry = number of lines of forms + number of repeated charges for content or services of variable value

If you are funded through ads rather than consumer payments, you can substitute for the repeated charges the proportion of screen space covered by your ads, or any other reasonable estimate of the delay and distraction the ads on your pages cause.

The index of worry allows you to estimate and minimize the worries you are causing your users, and as a result to minimize the drop-off in your sales funnel and maximize the number of users coming back for more – and willing to view your ads or pay for the privilege.


Measuring Decentralization

By Paul Sztorc

Posted October 9, 2015

Bitcoin’s Decentralization increases as a full node becomes cheaper.

Agenda

  1. Break down “Decentralization”, and “Money”, to determine, from the ground up, when “Decentralization of Money” increases or decreases.
  2. Defend that measure against its major competitors.
  3. Evaluate the measure against scalability comments made by Satoshi.
  4. “How to (Safely) Increase Decentralization”

Defining Decentralized Money

The process of “money” is “knowing you’ve been paid”. A process has greater “decentralization” as it “occurs more locally”. Thus “decentralized money” is the local cost of knowing you’ve been paid: the cost of running a full node.

Let’s break the concepts down, before building them back up.

“Centralized” and “Decentralized” are words which describe the layout of the relationships between agents. Let us start with what these relationships are (in our “money” case) before we assess any of their other qualities (“decentralization”).

Money

Money is like a big record of who has done favors for whom, but a very abstract record which works without knowing the specific identity or favor. That’s how you can trade money with someone you’ve never met (or will never meet again): it makes private value-knowledge common.

That’s what it does. How can we make something do that? How can we build a “payment network”?

It seems there are two simple requirements: [1] to know when you’ve been paid (for the favor you gave), and [2] to be able to show your trading partner that they’ve been paid (for their favor to you).

The two requirements are mirrors: if “something” can do the first, for everyone, it can likewise do the second. There’s no reason to double-count it.

Money is “knowing you’ve been paid” (by someone, with finality).

Decentralization

Now lets see how a money-relationship varies in its centralization-quality.

Basics

Some existing academic literature might help us with the general concept of “measuring decentralization”, but it’s nothing we couldn’t have figured out on our own (that “the process takes place closer to each agent”).

This figure spells it out for us:

The decentralized system is more local: the lines (pairwise-connections, or “relationships”) are shorter. It also involves less “interaction” (path-overlap) and hence, less “permission”: on the left all node-paths must share the single central node, but on the right it is possible for some pairs to ‘group up’ in ways that avoid the center node.

Now we must discuss Satoshi’s use of the word “decentralized”.

A “Peer to Peer” Electronic Cash System

Satoshi clearly intended “the Bitcoin Network” NOT to be “more decentralized than usual”, but, instead to be 100% decentralized. In other words, the one on the right:

After all, the “Decentralized” process above (middle) still has a center, which is a superior authority (non-peer) to the surrounding subordinates.

And, such a “having a center” contradicts this statement from Bitcoin’s Creator:

Notice the phrase “pure P2P”. Bitcoin’s whitepaper never uses the word “decentralized”, instead favoring the term “peer-to-peer” (which is very easy to measure: “Is every pair of nodes ‘two peers’?” and/or “Does any node have a privileged status?”).

The phrase “cutting of the head(s)” is a clue to the underlying principle: “Why is Bitcoin P2P?” (Might we achieve this goal another [non-P2P] way?)

Clearly, the “Decentralized” image still has a “head” that can be “cut off”. In fact (worse than that), if I reorder/relabel the images, the “decentralized” option is the most-headed of all!

The colorful stars represent “privilege” in the network. A decapitateur could take out the Capitol Star in either the 2-H or 1-H, but his control over 2-H is even more fine-tuned. Instead of all-or-nothing, he can selectively disable the network for enemies only.

This “decapitation-control” brings me to my next point:

It is an Engineering Requirement that Bitcoin be “Above the Law”

Obviously, people prefer not to talk openly about breaking the law, but if we don’t acknowledge true things, our conclusions will be wrong.

What is the difference between the following columns:

Computing

Legal

A

user

goes to a nearby terminal and

logs in

to a given mainframe. The user attempts to use his

e-credits

to purchase

heroin

at the

e-store

, but the mainframe rejects these instructions (as “not permitted”). With some effort, the user cleverly

circumvents

the

programmed limitation

. However,

the administrators

of the mainframe later use

the mainframe’s logs

to track this activity down. New limits are imposed and

the offending user is banned

, losing access to

all of his digital resources

.

A

citizen

wakes up

within the borders of a given country. The citizen attempts to use his

Bitcoin

to purchase

heroin

at a

nearby pharmacy

, but under current law this is “not permitted”. After some effort, the user manages to

break

the

law

by transacting with a street dealer. However,

the local police

begin to

carefully patrol the area

to track this activity down. After studying the local black market,

the drug offender is jailed

, losing access to

his freedoms

completely.

A

user

goes to a nearby terminal and

logs in

to a given mainframe. He has been running

UserBank

, which lets him and his friends keep track of who still owes who money (for beer and whatnot). This user recently discovered cryptography and wants

to take his banking software global

. When

the administrator learns of this

, he decides he does not like it (for whatever reason), and sends the user a notice that it will not be allowed. Not wanting to do anything that might upset the administrator, the user takes UserBank back to pencil-and-paper.

A

citizen

wakes up

within the borders of a given country. He and his immediate social network have been

bartering

favors (repair, electrical, painting, babysitting), which is cheaper and more fun than filling out tax forms. New, untrusted people want to participate, and they are willing to

use an accounting ledger

to keep track of who owes what. As the barter-network grows, the government

finds out about it

and audits these individuals for tax evasion, imprisoning the ledger-keeper for money laundering. Next year it’s back to “friends only”.

The

system administrator

can determine what

commands

are

allowed

on the computer network.

The

legislators

determine what

actions

are

legal

within the borders of their country.

Only things that can break the law are truly P2P, ie truly 100% decentralized. Compliance with the law is the acknowledgment of a “privileged non-peer”. If the process is subordinate to the law, it is “owned” by the law exclusively, undermining the benevolent force of competition (for better or for worse).

You can spin it however you like (“the first software application to self-maintain its subordinate OSI layers”), but it is what it is: above the law.

Combining the Two: “Decentralized Payments”

Setup

Money is “knowing you’ve been paid”. When does “that knowing” occur more locally?

Experience vs. Persuasion

To learn anything, you can either [1] check for yourself, or [2] trust the judgment of someone else. Trusting someone else implies a loss of local-ness. It definitely implies that P2P is lost: you are a subordinate taking the information from an authority. To preserve P2P, you’ll have to check everything yourself: run a full node.

The requirement to run an entire full node may seem like a high bar, but the height is appropriate. With money, other people’s actions (counterfeiting) affect you. The only way for you to know you’ve been paid, is to make sure that every piece of data has followed every rule, and you can’t do that unless you have all of the data, and all of the rules, in front of you. That’s a full node.

It is also reasonable to require that this node start from scratch, for the very same reasons: to learn something, you either validate it yourself or trust an authority. Authorities are not “peers”.

“Don’t Make Me Call My Full Node”

Of course, one need not actually go through with the actual running of the node. That would imply that Some Guy in the remote African wilderness, far away from any internet connection, could declare “I refuse to run a full node” and somehow decrease the decentralization of “Bitcoin”. Only the cost of running the node matters, not the number of people who choose to pay that cost.

And, technically, the centralization measure is the cost of the option to create a new full node, because in strategy/anything-reasonable only Options matter. Of course, the cost of “creating a node at time=t” is roughly the same as the cost of “creating a node at time=(t-X) + running 1 node for X time”. However, this helpful detail does imply that some unconsumed electricity is “free decentralization” (people can avoid running the node, unless Something Bad is currently happening), and it does perfectly tie up the edge-case where the full node count drops to zero (and new full-node creation is infinitely expensive), because option valuation includes uncertainty surrounding future costs.

So my metric of centralization is the cost of the option to create a new full node.

Testing the Definition (Applications and Alternatives)

The definition mirrors our observations. It flags “suspicious services” (Ripple, checkpointers, 
) as centralized, and is more fundamental than rival considerations (mining and development).

For this section, the cost of the option to create a full node will be referred to as the “cost of node-option” or “CONOP”.

Applications

Extreme Points

What if the CONOP were free (ie $0.00)? That would imply perfect decentralization (centralization of zero). Is that right?

I think so: anyone, anywhere, would be able to make sure that they had gotten paid, without trusting a third party, or doing any other work whatsoever. And this option would be available to every human on the planet, no matter how oppressed/disadvantaged (and the only way for a government to “cut off the head” of the network would be to kill every human being on the planet).

On the other hand, what if the CONOP were expensive, such that only one agent in the entire world could run a full node (say, the United State Government)? This agent would control the network completely: perfect centralization. If someone “cut off its head”, this network would disintegrate.

In fact, the logic works perfectly, in reverse, to explain existing monetary systems: the cost of creating “a full US Dollar node” is more than anyone could afford, by deliberate design. If, by magic, all of the USA’s banks / federal reserve / treasury buildings and equipment suddenly vanished, how many people would be able to replace them? Only one. Despite the fact that many, many people could, in principle, start a bank from their garage (and try to satisfy this unmet banking demand), we all know that they would be unable to do so. It would be illegal.

Ripple

A popular view is that the supposedly P2P Ripple is actually completely centralized. Does CONOP lead us to the same answer?

( Currently it is unambiguously centralized. And CONOP catches this: Ripple only allows one full node [theirs]. Adding a [second] node is infinitely expensive. )

But what of its eventual steady state?

Well, while anyone can become a Ripple “node”, not all nodes are equal “peers”. Extra-special nodes make the “default Unique Node List (UNL)”, which requires the approval of Ripple. The future “cost” of this approval is highly uncertain. Just as an option price converges to today’s spot price as volatility increases, you can’t guarantee you’ll be able to join the future Ripple club unless you’ve already joined today.

Actually, even that won’t work: the Ripple scheme allows you to be “thrown out” of the UNL club. In this way, Ripple doesn’t really have full nodes at all.

But lets run with it: To “know you’ve been paid”, you need to join the club, and stay in until your payment(s) go through. So the application of CONOP actually requires, that, to know you’ve been paid, you need to be “long a call option to join Ripple” + “long a put option that you’ll be thrown out before you can use Ripple”.

The second term (the put), acts as a kind of insurance that fully compensates you if you are kicked out of the club. However, because [1] “full compensation” is “them knowing they’ve been paid” (impossible to provide, by circular reasoning), and [2] because the likelihood of being kicked out is highly subjective (“volatile”), the cost of the option is infinite for everyone except the 1 person who controls the UNL: Ripple Labs. If RL were destroyed, the gatekeepers would then be “a coalition of 80% of the club members”.

Only they really “know” if anyone has been paid. Not you.

“Ask A Friend” / Weak Subjectivity
Summary

“Ask a Friend” is a scheme where one decides if a chain (“transaction history”) is valid by asking a friend, and taking their word for it. (Obviously the Friend has a superior non-peer status, so this is an outright rejection of “pure P2P”). If two friends disagree, (presumably) one asks a third friend, making it pseudo-democratic. This implies that democracy’s trademark effort-saving info-strategy will emerge: political parties. Specifically, the formation of alternating major/minor status groups (who “team up” to be realistic about winning), and fringe groups (who refuse to compromise on their principles, and always lose) resulting ultimately in a Status Game.

A high-status individual with “name recognition” (such as Gavin Andresen), can completely overpower even a group of honest/well-informed friends. This is because name recognition is common, and allows for “free coordination”, whereas private or even mutual* knowledge do not allow for such coordination.

  • There is a definition-mismatch in the video, Pinker’s “mutual” knowledge is wikipedia’s “common” knowledge.
CONOP

What’s the cost of “knowing you’ve been paid”? Well, with “ask a friend”, you cannot (by yourself) learn whether or not you have been paid. You are asking a friend! The cost is infinite unless you join the set of “those who are asked”.

So this scheme is essentially a version of Ripple’s UNL, but with no “default leader”. The paramount question “How do I join The Group?” is answered with “The Group decides if you can. We also decide if you can stay.”

If “joining the group” is cheap, this is fine. However, the “cost” of membership is public name-recognition, yet this is incompatible with anonymity, and hence incompatible with coercion-resistance. Only one agent, the sovereign government, can “afford” to maintain the monopoly on violence it takes to remain in this set (“can afford to run a full node”).

In contrast, Bitcoin’s proof of work is easily verifiable (“common” information, implying “free coordination”), and the Work would live on even if the miners who provided that work were killed. Reputation doesn’t work that way: someone needs [1] to be a reliable reporter of info, and [2] to be known as a reliable reporter of info
this is exactly the super-linearity that Bitcoin explicitly avoids!

Figure: the economics of degenerating (non-common) information (a zero-variable cost good): why settle for less than the best?

Checkpointers

This is perhaps the clearest victory for CONOP. Entirely by construction, only one person “decides” who has been paid and who hasn’t. Perfect centralization.

Now that the definition is viable, let’s see if it holds up to its competitors.

Alternative Definitions of Centralization (Have We Missed Anything?)

A Big List

Here’s a (well-meaning) list on this topic written by someone who isn’t me.

Let’s boil it down:

  1. Many members of the list (node, wallet, block explorer, payment processor, remittance service) are merely cosmetic layers on top of a Full Node. Certainly, they add convenience (and value) to Bitcoin, but the protocol itself isn’t even aware of them. Instead of repeat “Full Node” five times, we’ll just keep it once (although I will discuss ‘cost’ vs ‘other attributes’).
  2. Mining: while originally also a “plugin” of Bitcoin Core, mining has since specialized to a degree where the representative full-node-user is completely divorced from the mining process. So that’s a distinct #2.
  3. Some items (community, wealth) can’t themselves affect the software (or its use) at all. Ignore.
  4. Exchanges: a Bitcoin Full Node inherently supports “exchange” for everything (currency included), and could have a “LocalBitcoins Plugin”. Moreover the “professional exchanges” are half-fiat, and can be altered -in quantity and quality- by factors which are entirely non-technical (laws/subsidies). So they are simultaneously irrelevant and immutable.
  5. Software development: clearly a solid #3.

So I have to justify “cost” of a full node, and defend it against 2 challengers.

Counting Full Nodes Is Irrelevant

It’s popular to reference the quantity of full nodes (another attempt at measuring decentralization focuses obsessively on counting things up and taking their log_2(Quantity) ).

Is this measure actually useful? Or is quantity an effect following the underlying cause.

You Are Indifferent to Other People’s Nodes

I, personally, first heard it from Peter Todd: “The only full node that matters is yours.” This is the point I raised above: to know anything, you either [1] check for yourself or [2] take someone else’s word for it.

( Of course, [as I also mentioned], they are [slightly] related: if the node count falls to zero, you will be unable to start a node. )

After all, a single entity (of any type) can run and control many full nodes. The (centralized) Federal Reserve system likely has 100’s of redundant copies of its “knowledge” (payments data, research, web site, operating infrastructure, 
). In parallel, nothing stops a Bitcoin user from spinning up 100,000 new nodes that only he controls (and then halving them). So what’s to be gained by counting them up? If you run a node (or can run one at any time), then it doesn’t matter if the full node count falls even to one! You’ll always know the status of your payments.

Cost is King

An explanation based on cost makes the most sense: if creating a full, up to date node is nearly free (takes 10-20 seconds on a smart phone), we see that this network will have the desired “headless” property, and be completely local (even if the average number of nodes in existence is some “low” number like 5). Conversely, if the a node is so expensive that only 10 or 20 people can afford to run one, it can be easily disabled (via the “close e-gold” routine, 20x in parallel), or coerced/harassed.

Don’t Worry About Mining

Mining “Feels” Important; Disregard the Feeling

Money already mesmerizes people. Mining goes even further: it takes the “generation” of ancient mysticism (making something valuable appear from “nothing”), and adds modern computing technology and elitist tech-expertise, a round measure of esoteric h4x0r jargon, and finishes it off with a dash of “f**k the man!”.

Small wonder, that mining draws the attention of the audience.

Even freedom-loving, tech-literate Edward Snowden remarked: “weaknesses
make [Bitcoin] vulnerable to people who are trying to own 50 percent of the network
” which implies (incorrectly) that the miners “own” the network.

The Final Gear in a Vast Machine

There is a rampant misconception that mining is somehow important to Bitcoin.

Firstly, the true function of mining is not to provide security to the network, but instead to slow the distribution of coins, such that interested parties would join Bitcoin instead of cloning it into a competing system. Mining will fulfill that function, in a fully-P2P way, regardless of who is-or-is-not mining.

When Satoshi/Bitcoin-Experts use the phrase “secure the network”, they are using a somewhat different version of the word “secure”. If I say that my bank is ‘secure’, what I usually mean is that “no one is going to steal my money”. But Miners already can’t steal anyone’s Bitcoin.

It goes straight down to the tech tools used in Bitcoin’s design. Bitcoin is a ledger, answering the question “Who owns what, when?”. The entire first half (“who owns what”, aka “most of the actual ‘bank’ part”) of that question is solved using asymmetric key cryptography, and even the second half (“when”) is mostly solved with very clever structuring of data (into blocks, headers, hash chain etc) and creative use of cryptographic hash functions. Neither of those things have anything to do with mining; 0%.

Mining was brought in at the last minute to solve the P2P problem: “If X makes a transaction, and Group A hears about it, but Group B doesn’t hear about it, (and A and B are equal peers,) how do they decide if it ‘happened’ or not?”. Most of the Bitcoin whitepaper focused on this yet-unsolved problem, because Satoshi was a good writer, who knew that it would waste the reader’s time to go over those much-more-important problems that were already 100% solved.

If Bitcoin were a bank, Mining would be the clock on the wall.

It’s the crypto that does all the heavy-lifting.

The 51% “Attack”

I’m sure you heard from your friend that, like, miners can “reverse” transactions or whatever.

I doubt it.

No Motivation

Most transactions are totally foreign to the miner; the sender, receiver, even the amount, are more or less unknown. The miner has nothing to gain whatsoever by reversing them.

Admittedly, reversal might be a problem for transactions that the miner makes himself. He may buy something in a store, and later want to reverse this transaction so he doesn’t have to pay.

Or, an irate government might roll in with some tanks, take over the mining facilities, and reverse transactions (or “pause” the clock, by mining only empty blocks), purely to create mayhem.

That certainly wouldn’t be cheap: troops have to eat, and anyone in possession of mining hardware (even via theft) who fails to use it for ROI-maximization incurs an opportunity cost.

But say they did it anyway.

It’s not very effective


Ok, if the attacker also owns Bitcoins, he can double-spend these Bitcoins.

Once.

Assuming he doesn’t “get caught”.

Where “caught” is defined as “people come to understand that this 6+ block reorg was specifically unrepresentative of the distributed consensus process”, and manually flag your chain as invalid. If this (highly likely) event happens, nothing will be reversed.

Not only is the user’s money safe, but the attacker’s money is at risk! It is relatively uncomplicated to have nodes (or the honest 49%) censor all further transactions “from” this address. This would result in the attacker not only failing, but also having his Bitcoin “blacklisted” and essentially destroyed (increasing the value of all other BTC).

Whereas “ask a friend” was centralized, this isn’t, because the conditions under which it would take place can be agreed upon in advance (even coded into the protocol) and don’t change. No new judgment is required, only the protocol rules (and these rules are, you guessed it, common information, and they can therefore support “free/leaderless coordination”).

Peer-to-Peer Blacklisting

Although “blacklisting” coins is overwhelmingly considered to be objectionable, in this case I think an exception might be made.

What’s different here? Typically, “blacklisting” would violate two core principles of Bitcoin: [1] “reproduce the qualities of money”, and [2] “remain peer-to-peer”. Blacklisting [1] implies that some Bitcoins are different than others, a direct contradiction to the monetary feature of Fungibility, and [2] allows a list-manager to achieve a “higher-than-Peer” status.

However, “51%-attack-blacklisting” actually excels on both counts. First, it actually maximizes [1] Bitcoin’s reproduction of money-qualities, because, in my view, this loss of fungibility is more than offset by a large gain in transaction finality (a much more important feature of money). Second, if the blacklist-conditions are publicly discussed and agreed-to in advance, there is no need for a “list-manager” to coordinate the blacklisting, and no one has a “higher-than-Peer” status.

So, the 51% “attack” requires a huge expenditure, to probably not achieve anything.

Mining isn’t Bitcoin

By no means should we ignore mining. However, try to keep in mind that a “centralized” mining network doesn’t really mean that Bitcoin is significantly centralized. Mining isn’t Bitcoin, it’s just something that Bitcoin does.

Now for a more complex topic:

Development: 100% Decentralized, Unless we Hard Fork

Soft and Hard Forks

A soft fork is a change to the Bitcoin protocol to make it more restrictive. A hard fork, in contrast, is a change to the Bitcoin protocol which makes it more permissive.

Game

Soft

Hard

Chess

Neither player can castle after move 10.

Any Queen can move three times in a row if her King is in check.

American Football

A team can only score a field goal if they have not yet thrown an interception.

Any team up by 20 points or more can declare themselves the immediate victor.

What is the effect of each fork-type?

Well, players are immune to soft forks. After all, there likely have been many chess games where neither player castled, and many football games where neither team ever attempted a field goal. Everyone can observe, or play in, soft-forked games with complete indifference (although they may become increasingly confused by a player’s seemingly bizarre moves).

Hard forks, of course, have a theoretically unlimited effect on the game. It depends on the details: in the football example, a team up by 20 will probably (not necessarily) win anyway. The chief motivation in football is to earn more points; it doesn’t change under the new rule. In contrast, the chess hard fork transforms the game substantially. Whereas, originally, checking your opponent’s king was highly desirable, now it is outright dangerous. Moreover, no one will sacrifice or risk the loss of their queen, and players might march the king out into the middle of the field, to trigger check (and the additional queen moves it grants).

Free to Choose

Un-upgraded software will, by definition, already be compatible with all future soft forks (and incompatible with all future hard forks).

For a given protocol, the user is free to choose among any soft-forks he wishes. The resulting competition is entirely centralization-proof: no authority can disable your version.

All versions are compatible, so, even if all the devs were kidnapped (and forced to write Evil Bitcoin Soft Fork), no one needs to upgrade. If you accidentally do upgrade, you can merely switch back. To “know you’ve been paid” you can run any version of the software you like, including the very first version!

Your version might be slower, uglier, etc, but it will let you “know if you’ve been paid”. It won’t allow YOU to be paid in a “new” (ie, “update-dependent”) way, and it won’t know if other people have been paid in a “new” way (because it necessarily doesn’t know why the coach chose to avoid a “post-interception field goal”: Was it to comply with some “new” rule, or just because he doesn’t want to?).

But all of your own money is protected by the “old rules”, no matter what fancy other rules other people play by.

Figure: Mike Hearn’s bizarre obsession with money that doesn’t belong to him.

Hard Forks Threaten Bitcoin’s Accumulated Security

With soft forks, there are no surprises. Your money is protected by the “old rules”.

Because a system is only as secure as the adversarial environment it has historically survived, we can translate “..protected by the old rules” as “..safe” (for 6-year-old Bitcoin, anyway).

With hard forks, your money is subject to a new system. In principle, “a hard fork” could mean anything: stealing money, printing money, freezing the network permanently, it’s all on the table.

Therefore, the critical question is: “Are these new rules any good?”

Cost of Node-Option

To “know you’ve been paid” (ie “P2P money”) you need to know that the software won’t lose your money. After all, the definition of “paid” implies that the money now belongs to you and is controlled by you exclusively. Whether you lose your BTC to theft, or you lose them because the entire network collapsed, “you” have been “unpaid” (and you instead “know that you’ve not be paid”).

On top of that, if “the network” (users, merchants, service providers, 
) switches, you have no choice but to switch. If you refuse to switch, and stay on the minority network, your money will be useless and you will be “unpaid”!

So the cost of “knowing you’ve been paid” (the cost of “the option to run a full Bitcoin node”), necessarily now includes maintenance items, which YOU must pay if YOU are to KNOW you’ve been paid: [1] the cost of “validating” any new set of rules and [2] the cost of preventing other people from being deceived into accepting unproven rules.

Because you can only know you’ll be paid if the network uses rules that allow you to spend your future income.

Node Option = Hardware Costs + Privacy Costs + Maintenance Costs


it’s really getting expensive!

Hard Forks Destroy Decentralization

If one avoids hard forks, we don’t need to ask “Are these new rules any good?” at all, and so maintenance costs will be zero. Developers will never have any privilege, and there will be no centralization.

Unfortunately, of course, this limits our ability to improve the software!

Instead we might try to only propose hard forks where as little as possible has changed, so that “Are these new rules any good?” is likely to be easy to answer.

Then, with [1] enough experts involved, and [2] enough time for them all to voice their concerns, the user could eventually be as confident that “the rules are good” as the net confidence of the experts.

Unfortunately, our experts just aren’t smart enough. No one is.

Prediction in Complex Systems

We will probably never know “if the rules are good”, which means that maintaining decentralized access to one’s money will be impossible under a hard fork.

The Ideal Conditions (Aren’t Good Enough)

While it is claimed that NASA’s shuttle program achieves a 0 bug rate (per 500,000 lines of code), that is actually not true. Even getting as far as 1 per 440,000 apparently requires 260 full-time experts (Bitcoin has barely a handful) working under “threat of death”, in an execution environment where they control 100% of the hardware and software, and there is no adversarial activity whatsoever, and no user input of any kind.

Ask them about it! Here’s Appendix D (“Flight Software Complexity”) of their report on getting it right:

The very first sentences quote sociologist Charles Perrow: “
about the causes of failure in highly complex systems, concluding that they were virtually inevitable.” He continues: “
when seemingly unrelated parts of a larger system fail in some unforeseen combination, dependencies can become apparent that could not have been accounted for in the original design.”

Of course, a space shuttle is really complex, right? Instead, why don’t we take something that has been operating continuously, without any problems, for like 10 years. Then, we’ll take the elite NASA programming team and have them change just a single parameter.

It does not get any better than that.

But, in the end, the Black Swan always gets his man:

Figure: this perfectly-healthy robot wound up entirely disabled after The Experts updated a single parameter.

Sound familiar?

Bitcoin is the Opposite of Ideal

Mankind will have perfected space travel long before we remotely understand software systems.

Just ask Greg Maxwell or Gavin Andresen. Or Mike Hearn.

Someone attempted to count up Bitcoin’s lines of code, and concluded that there were a little over 12,000. In order to reasonably predict that a hard fork is safe, someone must evaluate each change against every existing line of code.

But no, the fun only begins once you’ve done that. You now need to forecast, with perfect accuracy, the effect of the software’s new allowances on all real world attributes of the Bitcoin’s wider economic system, as well as all psycho-social responses (rational or otherwise), and all new opportunities (whether change-based or uncertainty-based) given to motivated adversaries.

No human being has the research capacity to actually do this.

So, you see, the average citizen is far more beholden to the developer who writes his software, than he is to the politician who writes his laws. Breaking the developer’s (more numerous) rules is literally impossible, and there’s no recourse (socially, politically, practically, 
).

An Actual Example

Here’s a best-case scenario for a hard fork, because it is actually describable in advance:

  1. An 8 MB blocksize creates an incentive to selfish mine, such that miners must force all blocks to be 8 MB.
  2. The dramatic explosion in required bandwidth makes it impossible to run a full node anonymously.
  3. Because most presidents / current presidential candidates plan to use payments as a foreign policy negotiation tool, the “US Freedom America #1 Anti-Terrorist-Financing Emergency Powers / ‘Flags for Orphans’ Order” is “happened”.
  4. Anyone who runs a full node in the US is jailed, anyone who runs a full node in a non-US is flagged as a terrorist.
  5. Although some try to keep the node count afloat, the skills and resources required to do this are rare. These few are harassed, coerced, arrested, or outright assassinated.
  6. The Bitcoin project collapses.

Just think: with all the unknown unknowns, the true possibilities are unfathomably worse. One thing to point out is that a hard fork can be undone via soft fork. Since miners are the driving force behind soft forks (and since mining is capture-able), any hard fork which grants extra influence to miners would likely increase strategic complexity to a degree that could only be described as “unwise”.

But, protected by soft forks, you will never need to worry about all those things you didn’t understand until moments ago.

Contentious Hard Forks Obliterate Decentralization

I could go on (perhaps in a new post), but let’s wrap this up.

Grandma User does know that: “Bitcoin Core has been running for 6 years, it seems fine so far”.

Grandma User can not know that her money will be safe under the new rules of “Bitcoin Core II Duo”. She doesn’t have what it takes (150+ IQ points, technical inclination / CS PhD, a network of experts, and 100+ hours of free time), so, she must trust an authority. A hard fork elevates those who are Technical, Persuasive, or Endorsed, to “non-peer” status.

From there, the problem gets worse. Say x is the probability of hard-fork disaster, and f(x) is the probability that the “greatest expert” [1] catches the error, [2] is known (as an “error catcher”) to the audience (impossible to scale past 1-5 known experts) and [3] articulates his/her point clearly. As f is applied multiple times (as the info spreads to multiple people) the resulting f( f( f(x) ) ) will quickly degenerate to zero. Knowing this, individuals will minimize the number of f()’s and trust the Main Expert directly.

As with the very Federal Reserve System that Bitcoin aims to replace, these elite “non-peers” will [1] Team Up for greater collective clout per non-expert info-processed, [2] import credibility from top credential-ers, [3] entwine themselves with existing players, [4] formally entrench themselves to prevent the “wrong” people from making changes to Bitcoin.

In the extreme, an environment of frequent hard forks would eventually obviate the need for validation rules at all, and the people in charge would just be doing whatever they wanted.

The initial esoteric –technical and (subjectively) meritocratic– would collapse into a formal power structure. The minority who understood “original Bitcoin” will be powerless to prevent “new Bitcoin” from morphing slowly away from the principles that originally made it distinctive.

Conclusion: Remove the Contention

I’m not saying that we should never hard fork, only that doing so does tremendous damage to decentralization and is extraordinarily risky in general.

The decentralization of Hard-Forking can be increased as the “contention” decreases. I am aware of only one way to transform subjective judgments into objective information, as such a method must be itself P2P (“non-capture-able”, ie, allows anyone to express their [anonymous] judgment, without permission), incentive compatible, and produces a non-degradable signal (“common” knowledge supporting “free coordination”).

Decentralization increases if contentious forks are met with hostility: forked coins could immediately be sold, businesses who transact in them could be ostracized, individuals who support them should be discredited. A social norm of hostility would decrease the risk that a Bad Hard Fork will accidentally “unpay” everyone (ie, makes it cheaper for everyone to maintain their full node), but it would also make it harder to “upgrade” the software. It is a tradeoff, like anything else.

Bring on the Big Server Farms

Is an obsession with “cheap full nodes” consistent with Satoshi’s vision and statements?

Satoshi seemingly contradicts himself here:

In that he proposes something with two tiers (not “pure P2P”), such that, if everyone in the upper tier is destroyed, the network fails. I’m interpreting his analogy as something like:

Resolving the Contradiction

My interpretation is that Satoshi’s use of the word “node” is, in this case, overly liberal (ie, “incorrect”).

First, clearly these claims are true: [1] the intended configuration won’t scale, [2] it is impractical to have everyone validate everything, and [3] some users will lack the ability to run a full node, and that’s not a catastrophe (and able users are completely indifferent to it).

The Usenet analogy, furthermore, seems perfectly descriptive. However, Satoshi clearly intends all (or “enough”) of these “big server farms” to be safe, and these “NNTP servers” will be anything but.

Usenet isn’t Good Enough

I’m hardly an expert in this area (or, rather, this “era”).

But, what happened to Usenet? It became overloaded with spam, child pornography, and pirated software, and two non-peers (the government and ISPs) eventually pulled the plug (which is why 99% of the people reading this probably have no idea what the Usenet is). Once, the “Church” of Scientology used legal pressure to close down the (at the time) most popular anonymous remailer (a kind of Usenet “gateway”). Not exactly “headless”.

We don’t need to wonder “what would happen if Bitcoin were like Usenet”? It would overflow with spam and be killed by law enforcement.

Toying with Indifference

Of course, Usenet survives today as a paid service (and not a cheap one), but my feeling is that, if law enforcement knew or cared, they’d go back and finish the job. Today, Usenet is an enclave of the technical elite: it’s relatively complex to set up and use, its users are smart enough to not talk about it [sorry, guys
Satoshi brought it up
], and most regular people have no idea how the internet works at all (watch these people mis-describe a web browser as basically “a librarian they ask for help”, and these and this, and why not this) let alone Usenet. Usenet is, to borrow a phrase from Greg Maxwell, secured by “indifference”.

After all, you can’t care about something if you aren’t aware of it.

From a 100% real survey. Keep in mind that 50% of people will correctly answer a True-False question that they personally know nothing about.

Compare that to this:

“On day one in the Oval Office I would make two phone calls. The first one would be to my good friend Bibi Netanyahu, to assure him that we will stand with the State of Israel. The second will be to the Supreme Leader of Iran. He might not take my phone call, but he would get the message, and the message is this: Until you open every Nuclear and every Military facility to full, open, anytime, anywhere, for real, inspections, we are going to make it as difficult as possible for you to move money around the global financial system. I hope congress says no to [the Iran deal], but, realistically, even if they do, the money is flowing
we have to stop the money flow.” (emphasis added)

-Carly Fiorina, Widely-Regarded “Winner” of the Fox News 5 PM Debate for 2016 Presidential Candidate, beginning 39:50.

Conclusion (Usenet Analogy)

Usenet never prevented a US President from executing on their Iran “Anti-Nuke” Foreign Policy. Such a difference is too excessive (to sustain the analogy), and removes the (required) expectation of full-node-safety.

Which is interesting, because the NNTP analogy is almost perfect.

In fact, it more reminds me of


The Lightning Network

You see, it would really be something like this:

There’s cheap nodes, run by everyone, and no central authority. There is a two-class hierarchy.

An Authority on what?

The “upper class” in the Lightning Network is a little bit like a limited government: it exists to serve the public, and there are strict rules on what it can and can’t do.

It Can’t

The hubs can’t prevent you from becoming a hub yourself:

And they can’t prevent you from circumventing the hubs:

It Can

During the custodial period (about a week) The Hubs do get to determine if you will, or will not, be able to make a cheap transaction with the money you deposited with them. If they ban you from making any transactions (or, their computers get shut down by the government, or catch fire), your money is stuck there for the duration of the custodial period. However, it is only temporarily trapped: your money can’t be lost or stolen.

Basically, it’s a bank that can’t steal your money. Revolutionary!

Since anyone can become one, the resulting competition will result in maximal uptime and minimal fees for everyone.

Servers that compete on uptime? 
just as is done today with
gasp
“big server farms”.

Reinterpretation

As Satoshi said, the current configuration is indeed not appropriate for large scale payments, that would indeed place an excessive burden on each user, “the design supports letting users just be users”, and a few “nodes” can be large server farms.

However, the Lightning Network configuration is much more rational, specialized, and efficient. To our point, it increases decentralization by making a full node cheaper: by allowing many transactions to take place off-chain, fewer happen on-chain, and fewer burden each full-node-user. This is true even if you refuse to use any off-chain transactions.

Increasing Decentralization

To improve Decentralization, make full nodes cheaper. One overlooked way to do this is with a “Tor supply curve” (which Bitcoin can provide)!

The Last Discontinuity

Given our conclusion, the easier it is to start up a new full node, the more decentralized Bitcoin will be. How can we make full nodes cheaper?

I’d ignore mundane expenses like hardware and power. Instead, recall that, if a full node cannot be run anonymously, “the network” (full node entry) is effectively controlled by law enforcement, a central entity. Therefore, my view is that the current largest “cost” (and current bottleneck to Bitcoin scalability) is therefore the threat of persecution.

It is a shame to have come so far, only have one tiny subjective abstraction interfere with my presentation of an actual number.

Intermediate-Good Bitcoin

One way to address this bottleneck (and make decentralization easily measurable at the same time) would be to increase the supply of “Tor-Bandwidth” (or equivalent “internet anonymity”). However, Tor-Bandwidth currently has a big problem: the anonymity prevents anyone from paying for it. This means that it cannot be bought or sold, its price is fixed at zero, and we will only have what is volunteered.

Moreover, “available at no cost” also means “it can be attacked at no cost”. This is highly problematic, as the price cannot even react to the attack (“react to changes in scarcity”), and the lack of price prevents capital investments from efficiently increasing long-run supply. (After all, our internet service providers built the current internet to purposefully have limited consumer upstream bandwidth because that’s what the market told them we [could prove we] wanted).

Anyone looking to improve Bitcoin’s decentralization might look at integrating Bitcoin payment channels with Tor nodes (or metering bandwidth in VPNs, or in general). Keep in mind that more decentralization is not always better, but, as decentralization improves, we can be more comfortable “trading off” some for other things we’d like to have (ie, bigger blocks, and cheaper/more-numerous transactions).

Conclusion

To increase decentralization, focus on making a full node cheaper. “Decentralizers” include the Lightning Network, Tor, and metered bandwidth services.

I will be in Montreal to discuss this and related issues.

Add Disqus comments.

comments powered by

Disqus


The Hashing Heart Attack

By Paul Sztorc

Posted October 28, 2015

Special thanks to Marshall Long, Greg Maxwell, Mark Freidenbach, and Adam Back for related discussion.

The Problem

This issue is one which might disable Bitcoin completely, requiring a (simple) hard fork to get it “unstuck”. This issue becomes more dangerous over the next 20-30 years (likely most dangerous in 2020-2028), but then quickly declines.

I’ll break it into two subproblems:

SubProblem 1: The blockreward halving instantly cuts miner revenues by a huge fraction.

Of course, this assumes [1] that transaction fees are negligible and [2] the Bitcoin exchange rate never increases in response to the difficulty halving.

Transaction fees are currently around 1% of miner-revenues, and no one expects this proportion to significantly increase anytime soon. Even if transaction fees were 50% of revenues (wildly optimistic), the reward-halving would still cut total revenues by (1/4), a sizable proportion.

The Bitcoin exchange rate (important to miners) shouldn’t change in response to the difficulty halving, at all. By Weak Efficient Markets, anyone who believes that “the USD/BTC price will imminently double”, should be buying immediately (and bidding up the price). I’ve previously written that, because of “saturation”, Bitcoin might have some immunity to the EMH, but (like all EMH-resistance) this immunity is constantly hard at work, canceling itself out.

Figure. On the left, the reward-halving dominates the block-reward; on the right, transaction-fee variance dominates.

SubProblem 2: The difficulty adjustment process causes miner homogeneity.

Every two weeks, the total costs of mining (namely, the difficulty) reset such that the average miner achieves an expected economic profit of zero. Those in the bottom half can no longer afford to operate, and they (eventually) switch their miners off and drop out of the system.

Of course, this is an academic simplification of actual mining. It ignores [1] uncertainty (in all factors) and [2] ‘permanent advantages’ (“free” power, geographic distribution of energy sources, ASIC engineering secrets), but those artifacts merely slow the inevitable: this is an ever-present, fundamentally underlying process of filtration.

As the lower-quality miners get filtered out, the filter reacts to the increase in quality by becoming more intense. Eventually, only a few top quality miners will remain. These miners might follow different best-practices (all the solar-power miners might have a different set of best practices than the hydro-power miners), but all miners should eventually have tiny, and equal economic profit margins.

Because an average is just a single number, it necessarily contains less total information than the distribution from whence it came.

Combined

The problem is when these two effects happen at the same time.

In short, we will reach a day when all miners have small profit margins, and then a blockreward-halving will slash their revenues in half. The result will be that not half, but all miners will shut off their mining rigs.

You see, the difficulty won’t re-adjust (decrease) until (on average) 1008 blocks later. (In fact, we always know exactly the number of blocks.) So, even miners who plan to turn their mining rigs back on, post-difficulty-decrease, would have them off for this brief unprofitable period.

The problem is that it might not be brief. The difficulty adjustment period, which would normally last two weeks, is counted in blocks, not human-time. So it could actually last forever.

(Or, until someone manually hard-forked the network [to something with 60% difficulty], thus giving the stalled engine a jump.)

But that’s not all: even if most of the miners stayed on, the resulting uncertainty (or merely the increase in confirmation times) might cause a Bitcoin currency crisis. Abnormal tx-fee and exchange-rate volatility would increase Bitcoin’s risk premium, harming Bitcoin’s value-proposition as money. One example: were the USD/BTC price to fall by half, the blockreward-halving would have an effect more-resembling a blockreward-quartering. A falling USD/BTC price widens the gulf between mining costs and revenues, and makes the problem even worse, potentially resulting in a death spiral.

In the near term, miners are different enough (and the exchange rate is already volatile enough) such that most will survive the halving, and in the long term, Bitcoin might be sufficiently important such that transaction fees simply increase (in step with the higher confirmation times) to offset the problem. However, in the medium term, namely the year 2020, it is potentially disastrous.

Solution

What Won’t Work

Do Nothing

We might hope that miners, out of the kindness of their hearts, would simply keep mining (at a loss) to prevent Bitcoin from dying (and prevent their specialized hardware from depreciating to zero).

This isn’t acceptable to me - in equilibrium, miners consume all of their BTC revenues (which are all spent on operating or capital costs), and it is easy to imagine miners who plan their capital investments to align with the 4 year Bitcoin halving cycle (“we’re going to run these into the ground until the reward halves, and then replan from there”). Mining hardware itself rarely lasts longer than 2 years, anyway.

The cost of altruistic mining can be roughly estimated. Currently, miners collectively earn 201625300 = over $15 million dollars in revenue each difficulty cycle. These inputs might all change, of course, but, if they didn’t, the 2016 halving would slash this revenue by over $7,000,000. If miners were already running at cost, this 7M figure is the cost of keeping 10 minute blocks. Worse still, such altruism would prevent the subsequent difficulty adjustment from being representative; miners would only keep themselves trapped in Altruism Prison, losing money the whole time.

Moreover, “we” are increasingly unable to “help” the miners
ongoing professional hardware-specialization makes our “civilian hardware” (home PCs, phones) overwhelmingly irrelevant.

Upon Each Blockreward Halving, Also Halve the Difficulty

Clearly the intent was to cut profits in half, not revenues. Unfortunately, there’s no clear way for the protocol to learn about miner’s profit margins.

One (hard fork) idea is to simultaneously halve the difficulty (with the reward); this might work, but instead it might simply delay the problem for 2016 blocks (which might all mined in one week, instead of two), at which point the difficulty would double
landing us right back where we started. If ‘halving the difficulty’ perfectly halved the total costs of mining (including overhead and labor), and the blockreward perfectly halved the revenues (ie, transactions fees were nonexistent and the exchange rate never changed), then it might work, but difficulty has a stronger relationship with time than it does with cost (and revenues are driven mostly by Bitcoin’s exchange rate).

It seems that there’s only one way to guarantee that the problem be removed.

Smooth the Disinflation Out

The only ironclad solution is to replace the sudden halving of the Bitcoin coinbase with a continuous, gradual decrease.

Something like this:

Where r refers to the quantity of BTC released per block, t refers to the block number (ie, “time”), and lambda is some parameter. (Little t is used to index on r, but big T refers to the actual number itself).

Fork Types

This can be done either with a hard fork or with a soft fork.

While any hard fork can replace one issuance policy with another, a soft fork must obey the original issuance rules. This can be done by storing coins in a kind of “softfork reserve account”, with special rules allowing only future block-finders to withdraw. Because the bank can never have a negative balance under soft fork, such a change would involve some sacrifice on the part of the miners (they’d be losing coins that they’d otherwise be able to keep). A hard fork, freed from the original rules, can reduce this problem.

Details

I did some preliminary Excel math to take a first look at the potential issuance schedule and its effect on miners. This analysis is oversimplified (a year spans just a single row, instead of 624365 = 52,560 rows), and I would (obviously) improve it before making a formal proposal. The specific numbers are, of course, irrelevant; only the concepts are relevant.

.

Original

Hard Fork

Soft Fork

Lambda (Annual)

N/A

.012

371160

.012

166134

PV Impact (BTC, at 5%)*

N/A

-81,442.1

-119,080.3

BTC in Year 2168

21,038,400.0**

21,038,399.7

20,973,054.6

*Obviously, I used math to minimize this value in each case. **This value is not 21 million, because of leap years (and other simplifications, which are consistent across scenarios). So, “Hard Fork” is accurately recreating “Original” (and not a second error).

The soft fork eventually starts accumulating larger-and-larger proportions of tinier-and-tinier blockrewards, such that ~65,000 BTC remain trapped in the bank forever.

Costs

Most of the damage (~ 81/119 ~= 68%) is done whether the fork is soft or hard.

This damage (the cost to miners, of loaning these coins to the bank without compensation) would be substantial: at a market price of $250/BTC, the 119K BTC are worth nearly $30,000,000 USD.

Of course, mining revenues are mostly driven by the exchange rate itself, so we have to weigh this cost against any BTC appreciation that might occur as a result of this change.

How the Soft Fork Might Work

As mentioned, the soft fork would still allow miners to “mine” 25 BTC per 10 minutes. Some portion of these 25 would simply be ‘frozen’ (metaphorically, they would be “placed” into a “miner-bank”).

We might require the “bank” to be an ‘ANYONE-CAN-SPEND’ BTC address, yet with miners enforcing a pre-specified policy for spending from this address. Later, when someone mines a block that needs to ‘withdraw’ from the bank (during the 2020-2038 years, where the smooth curves are above the blue jagged line) the refined protocol can simply agree to allow a certain number of BTC to be transferred from this address to anywhere (knowing that the winning miner will give it to him or herself).

This would be the first soft fork which is not obviously a Pareto improvement: it harms a subset of individuals (the miners) –if we neglect to consider that miners would also be harmed by Bitcoin’s collapse as a result of this unfixed problem. This is particularly interesting because miners are the very group which turn soft forks on and off. At around year 2020, the ANYONE-CAN-SPEND address will have accumulated over 450,000 BTC (today, worth over $120 million).

To prevent an interesting situation might emerge where miners attempt to raid those funds, possibly by bribing users to upgrade their software, or by lobbying in some other way, notice:

  1. Regular users would almost certainly have upgraded their software by then (making this a little more like a hard fork).
  2. An un-forked block is too valuable for its own good. Worth more than surrounding blocks by a factor of 72,000 ( = 450,000/6.25), The Block that rewards all these coins would be fought over endlessly (as new miners will most certainly jump online to mine this single block, and then refuse to participate in a chain that does not allow them to win). So, threats to start a fight aren’t very credible.

How did this happen?

It seems strange to see a design flaw in Bitcoin, something which was otherwise so perfectly-crafted. I’m inclined to think that the inherent fairness of the static “50 BTC per block” appealed to Satoshi; that he anticipated a great deal of criticism off the bat, and didn’t want to be hearing “I don’t want to join this! You’ve already started mining and got all the easiest blocks for yourself!”.

And, it certainly is easier to explain “you get 50 of them with each block, but this number drops by half every four years” than it is to say “ ‘a formula’ determines how many BTC you get”.

Or, perhaps I have misunderstood? What do you think?

zzz The source of the flaw (and other “difficulty oscillation”) is really the clunky 2 week difficulty adjustment, which, by definition, can only forecast 2 weeks into the future, using data from 2 weeks in the past. the difficulty adjustment had to be a little clunky, because of the way that Satoshi measured “time”.

Add Disqus comments.

comments powered by

Disqus


It’s All About the Blockchain

By Erik Voorhees

Posted October 30, 2015

Blockchain is so hot right now.

2015 was the year the narrative changed. Bitcoin is out, blockchain is in. Attend any financial conference and you’ll hear panels about the brilliance of private distributed ledgers. Private blockchain initiatives like R3 CEV have attracted over 25 of the world’s top banks to participate. Airports everywhere are displaying Bloomberg Markets’ recent cover story, featuring Wall St. tour-de-force Blythe Masters sitting elegantly behind a celebratory banner, “It’s All About the Blockchain.” Even investors who have long backed Bitcoin startups now make sure to convey in their promotional copy that they’re involved with “exciting Blockchain ventures.” What’s your blockchain strategy? Bro, do you even blockchain?

The ascent of this term in the media and financial industry has been dizzying.

And “Bitcoin,” as a thing somehow distinct from “blockchain,” has been left by the wayside, ignored like an embarrassing relative at a family gathering.

Some of us have been amused by this development, but many confounded. Why is everyone talking about the blockchain, and ignoring its central fuel, Bitcoin proper?

First, let’s understand why the change in narrative had to happen, why it was necessary and indeed inevitable.

Bitcoin, to many in the world who have casually heard about it, is an uncomfortable and cryptic creature, existing somewhere between Ponzi Scheme and “money used by bad people.” Didn’t Bitcoin go bankrupt in Japan? Wasn’t the CEO arrested? To others, it’s just downright weird and unnecessary. Visa works just fine, thank you.

More importantly, though, to professionals in the money realm – to bankers and investors and financial regulators – Bitcoin is an awkward and annoying development, a technology almost all of them dismissed as absurd and useless, and yet it keeps growing. Bitcoin promises a dangerous world without strict top-down financial control. Terrorism. Think of the children. Bitcoin made the term “fiat” a thing, and when something has a name, it can be critiqued. Every day Bitcoin exists, it demonstrates the naive idea that money may be able to work without central planning. Worst of all, Bitcoin brings with it an obnoxious cult spouting proletariat nonsense like “financial privacy is a human right,” and “money should move faster than an anvil FedEx’d to Singapore.”

What respectable banker wants to deal with that?

And while the technology brings with it vast promises of financial innovation, these cannot be discussed in terms of “Bitcoin,” because this term brings with it all the aforementioned baggage. One cannot discuss Bitcoin in polite company, for the conversation may veer into one of monetary theory, human rights, massive sovereign theft and bank fraud
 better stick with the weather.

But how do you convince your boss or shareholders that you’re keeping pace with innovation? They read the news, they know that disintermediation is a thing. At the edges of their mind, they have a sense that, perhaps, charging $45 to send a money transfer message is neither logical nor sustainable. As Jamie Dimon recently warned in his annual letter to shareholders, “Silicon Valley is coming.”

Enter “Blockchain.”

Ahhh, what a term! It encapsulates all the magic, all the technological brilliance, all the promise and the sparkle of true financial innovation. And it does it without devolving into a discussion of Silk Road or Jekyll Island.

Blockchains, as a concept, are not controversial. Bitcoin is highly controversial. That is why the narrative changed – because “Bitcoin” makes financial professionals uncomfortable. There was no conspiracy to change the subject, it just happened naturally; the path of least resistance.

But what is it, exactly, that they hope to achieve by advancing private, non-Bitcoin blockchains? Without Bitcoin, a blockchain is just a distributed database – not exactly a novel technology. What is R3 CEV but a sexier and more social MySQL database? Why did banks not build such distributed ledgers long ago? If they are the arbiters of transactions, there is no need for mining, and thus no need for a blockchain, per se.

Perhaps such a distributed database never happened before because the banks haven’t felt the true competitive pressure to innovate. Banks’ biggest innovation in the last two decades was the Geithner Swap, in which loss due to excessive risk taking is swapped for taxpayer money. Banks aren’t so much financial innovators as they are lobbying cartels. But can you blame them? When Government forces its way into bed with you, who do you imagine you’ll wake up with?

It remains to be seen how long it takes for the financial industry to realize that the true valuable innovation is not the distributed ledger of the blockchain (which has existed in other forms prior), but rather the open platform of financial inclusion with no trusted party or cartel (which has never existed).

It is precisely Bitcoin’s openness which, like the internet before it, brings revolutionary change to how humans interact. Bitcoin wasn’t revolutionary because it could move money faster, or more cheaply, than banks. Most of the banks’ delay isn’t due to technology – they’re just sending digital messages representing virtual money, after all – it’s due to regulation, bureaucracy, and habit.

Supporters who are “all about the blockchain” may counter that the blockchain demonstrates truth, demonstrates finality, and thus as banks adopt this technology they will be made more efficient because the uncertainty of settlement will be resolved. Sure, blockchains can help with this, and banks can be more efficient for it. It seems clear that blockchain-based banking networks could settle payments in minutes, not days.

But that’s missing the point. A marginal gain in efficiency isn’t what we’re excited about, and indeed a centralized system like PayPal can always be faster than a blockchain, from a technical perspective.

This technology wasn’t created as a way to make things a little faster, though certainly that’s one of its benefits. The real purpose, the purpose which in hindsight will be hailed as the real innovation, is to remove censorship and central-control from money itself.

Is the internet remembered as the means by which Time Warner more quickly delivered its content to readers? Is the printing press remembered as the means by which the Church more aptly conveyed its prognostications to the devout?

It was the openness of these technologies – the fact that anyone, in any country, could access them, build with them, & experiment with them. One did not have to be 18 to sign up. One did not have to be on a government-approved list. One could write whatever she wished, communicate with whomever she felt relevant.

Blockchain technology, properly understood, is decentralized. It is an open platform. It does not pass judgement on human actions, it simply enables more action, more easily, to everyone. A blockchain strategy that doesn’t appreciate this is doomed in the same way and for the same reason as AOL and CompuServe. Does industry really need that lesson again?

How many billions will be wasted by banks seeking their own private distributed ledger, before they realize that the service of “ledger” is just one branch in the tree of broad human communication, and such communication tends to open over time, rather than close.

So industry – if you need to keep using the word “blockchain” to feel socially comfortable when discussing the renaissance, that’s fine. But for the sake of intellectual honesty, not to mention fiduciary duty to your shareholders, don’t fall into the hallucination that siloed financial networks are innovative or lasting. If your blockchain strategy ends at the edge of another bank, you’re doing it wrong.

Moving from a permissioned financial network between banks, to a permissioned financial network among banks, is no great step for mankind.

Erik Voorhees http://www.ShapeShift.io Erik Voorhees, CEO of leading digital asset exchange ShapeShift.io, is among the top-recognized serial Bitcoin advocates and entrepreneurs, understanding Bitcoin as one of the most important inventions ever created by humanity. Erik’s former project, the groundbreaking gaming phenomenon SatoshiDICE, was, at its peak, responsible for more than half of all Bitcoin transactions on Earth and popularized the concept of “provable fairness.” Having been a featured guest on Bloomberg, Fox Business, CNBC, BBC Radio, The Peter Schiff Show, and numerous Bitcoin and industry conferences, Erik humbly suggests that there is no such thing as a “free market” when the institution of money itself is centrally planned and controlled. This blog is about the human struggle for the separation of money and state, and about Bitcoin as the instrument by which it will happen.

You can start editing here.


Categories:

Updated: