August 2017 Journal

121 minute read

WORDS is a monthly journal of Bitcoin commentary. This issue collects the August 2017 writing in the WORDS archive. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. That’s why we made this journal, to preserve and further the understanding of Bitcoin.

Subscribe


A Hundred Years of Crypto Anarchy

By Elaine Ou

Posted August 3, 2017

This is an excerpt from a presentation I gave at last week’s Blockstack Summit.

This is Tim May. Tim recently gave a talk called “Thirty Years of Crypto Anarchy.”

I like that title so I’m ripping it off, but we’ll add 70 years because this talk is aspirational as well.

Crypto Anarchy has gotten a bad rap. Something about the whole idea of anarchy. We’re not trying to overthrow the establishment and collapse the nation-state here. You can if you want to, but please do that on your own time.

The government actually has a pretty important job. It creates and enforces rules that make civilization possible. Without rules we’d be a bunch of little tribes fighting each other, and life would be nasty brutish and short.

In the absence of a central authority, we can use technology to enforce rules. That’s all crypto anarchy is: Create self-enforcing rules without involving the government. They should thank us for easing their workload.

Property rights, for example.

Back in the days of the wild wild west, there was no good way to control land rights. Cattle ranchers couldn’t keep their cattle from straying, farmers couldn’t grow crops without getting trampled by cows.

Barbed wire was a big deal because it let settlers take control of their land and improve it.

Barbed wire is not a perfect solution. For instance, it’s no match against a set of wire cutters. In physical conflict, it’s cheaper to attack than defend.

This is Ft. Knox. There’s something like $200B worth of gold stored here. A game theorist might reckon that it’s economically rational to spend up to $199B to break into the vault and steal the gold.

Except that we have a $600 billion defense budget. In the physical world, whoever has the biggest weapons gets to make the rules.

This isn’t true for the digital world. Encryption is cheap to defend and expensive to attack. To brute force a 128-bit RSA key would take a million billion years with a supercomputer.

Threats of violence are useless here.

Without coercive threats, we can interact and transact as we choose.

This is Attorney General Jeff Sessions. He sucks. I don’t know if he’ll be Attorney General for very much longer. He led a campaign to take down the biggest darknet markets.

Jeff Sessions likes to point out that people have OD’ed and died from drugs they bought off darknet markets, but look – people aren’t going to stop doing drugs. Narcotics is one of Mexico’s biggest exports.

Street drugs involve a lot of violence and extortion because they don’t have a central authority to keep things in order. Darknet markets provide a way for adversaries to compete without murdering each other.

Technology doesn’t change what people want in the world, it just removes the use of violence to get there.

Every time a market shuts down, three new ones spring up in its place. For the past few years, the biggest hidden market was AlphaBay. The day after Alphabay disappeared, vendors were posting signed messages on Reddit to prove that they were still available, and to announce that they had moved to the next market.

Public Key cryptography isn’t just for encrypting private messages. It also provides proof that the sender is who they say they are. When buyers and sellers conduct transactions, they sign messages with their private keys. The signatures become digital identifiers.

So here’s the thing with darknet markets. The platforms don’t matter. Users expect sites to eventually disappear, because no market admins have lasted 3 years without an exit scam or a raid. What matters is the users.

Even if a site goes down, the reputation and relationships remain.

For most of existence, identities were local. People could selectively reveal information depending on where they were.

Now that we have all these big data companies, there’s a stupid idea that people should have only one identity that follows them everywhere.

This is the visa application for entering the US. It asks for every email address you’ve used for the last five years, and a list of all your social media accounts. Cripes.

True Names is a sci-fi novel from the 80s, where online hackers go to great lengths to keep their legal identities secret. If the government finds their true identities, it might kill them.

This is where we’re headed. Not the killing part, but the part about separate digital and legal identities.

Keypairs aren’t social security numbers. We can have more than one digital identity.

Before we invented corporations, business owners were personally liable for any losses the business incurred. This meant that if your company sold a bum product, you could be sued and enslaved by creditors.

In the 1800s, we created the idea of limited liability companies that were legally independent of their founders. By separating the corporation from its owners, entrepreneurs could take on new business ventures, or multiple ventures, without liability from one company affecting another.

A lot of people are doing ICOs and lawyers are spazzing about whether tokens are securities. Who cares. Don’t do an ICO under your real name, duh.

ICOs have raised over $1.3 billion this year. How many investors even know who the founders are? Here’s one anonymous ICO for a decentralized name server and token exchange. The founder is trading on nothing more than a Github repository and Reddit karma.

Reputation is collateral. No one knows who darknet market admins are, but they’re entrusted as escrow. If the amount of money in custody exceeds the operator’s expected future revenue, they will exit scam. Evolution was the most highly-rated market until it exited with $12M in escrow. Don’t trust anyone with more money than their reputation is worth.

True names are a barbarous relic. The most valuable blockchain to date was created under a pseudonym.

When Tim May wrote The Crypto Anarchist Manifesto, it wasn’t a call to action or instigation of sorts. It was simply an observation. We now have the technology to create and enforce our own rules, and this knowledge cannot be stopped. We can either rail against the inevitable, or use these tools to build the world we want.


Descendants with modifications: Bitcoin’s new and possibly beneficial evolutionary test

By Konrad S. Graf

Posted August 5, 2017

POST HEADER

POST BODY

Source: Charles Darwin. 1845. “Journal of researches into the geology and natural history of the various countries visited by H.M.S. Beagle.”

The BTC/BCH chain split of 1 August 2017 could add value for holders of the former bitcoin during any period in which the summed value of each coin exceeds the value that the former single coin would have had. Holders of BTC before the split came to hold equal amounts of BTC and BCH after the split, prior to any subsequent individual trading.

Zero “new bitcoins” have been created from a monetary-inflation standpoint. Control of any existing bitcoin unit before the split gave rise to corresponding control of one BTC and one BCH unit after the split. Since this reflected the precise and complete pre-existing constellation of unit control with no alternation for each and all former holders of the single-chain BTC, no redistributive Cantillon effects follow.

This split looks like a better-case scenario, at least “less bad,” than several of the other fork types proposed and discussed over the past months.

At this early phase, bitcoin cash (BCH) trading remains nascent, as exchanges and wallet services work to serve customers in a post-split environment. Potential traders remain limited because many exchanges do not yet offer BCH account crediting or have temporarily disabled relevant withdrawal and deposit options.

Various partisans have already claimed that as soon as normalized trading is achieved the BCH price will either collapse or rally, or some sequence of both. Pre-split futures and post-split exchange data (such as it is) have thus far shown an approximately $250–500 range for BCH. The bitcoin (BTC) price hardly reacted from its recent pre-split range of approximately $2,600–2,800. Either way, relatively wide changes to the BCH price are likely to be the rule until at least some time after normalized trading options come on line and hashrates and difficulty levels settle out to a greater degree.

The summed prices of BTC and BCH have mostly exceeded the former BTC all-time high, hinting at possible net value added from the split. This could be illusory due to the poor trading environment, but this sum could also have been lower instead, particularly if viewed as a network, mining, and trading disruption: the BCH price range could have started lower than it did, the BTC price could have fallen unmistakably, which it did not—or both.

Looking ahead, hash rates and difficulty adjustments are other key points to watch. Although the BCH chain protocol revisions did add certain more flexible mining difficulty adjustment methods, it remains to be seen if this will be sufficient to prevent very long block times over the coming weeks, which, amid price declines, could further reduce mining profitability on the BCH chain for some time. The future allocation of hash power, pace of difficulty adjustment, and price all remain to be seen.

Separate from these temporary and news-oriented issues, in the balance of this article, I will interpret the chain split in more fundamental terms.

Potential net value added from innovation and experience effects

If a net value gain from the split is actually present and does persist, such an outcome would not be entirely mysterious. Innovation proceeds through action far more than talk. SegWit activation (BTC chain) and a substantial block size limit increase (BCH chain), respectively, both promise to partially replace months and years of talk with action and experience, which is, in general, bullish for innovation.

In contrast to action, speculation and modeling are far more subject to partiality, bias, and social and financial pressures in the selection, construction, and interpretation of models. Action can supplement or partly displace hot air. What will happen with SegWit? Watch and learn. What will happen on a live network with a higher protocol block size limit? Watch and learn. This opportunity for the addition of progressive sequences of reality checks on the respective chains might be positive in itself. The “test” this represents is highly imperfect, as discussed below, but is still probably better than unmitigated talk.

The misleading conventional understanding of innovation is that practice follows theory; that “basic science” comes first and then begets technological innovation. The historically far more common process of innovation has very often followed the opposite pattern. Some fundamental innovation attempts occasionally succeed (mostly they fail). After the rare successes, new theory and research come along to try to explain and formalize what entrepreneurs and tinkerers had already done (after the best pontifical efforts of old theory to prove that what had been done could not have been).

Descendants with modifications

The minimum requirement for a process to be called evolutionary is descent with modification. Thus far, Bitcoin has gradually evolved as a single chain with modifications to its software. This split, in contrast, is Bitcoin’s first speciation event. Both BTC and BCH build on and carry forward the Bitcoin chain in a valid unbroken lineage of blocks tracing back to the genesis block.

The best chain in Bitcoin is defined as a chain of valid blocks with the greatest accumulated proof-of-work difficulty. In this model, the validity test comes first, followed by the total difficulty assessment. The software variants behind each chain have recently implemented certain substantial rule changes that are not now recognized as valid on the other chain. The BTC chain, for example, does not recognize the BCH chain’s modified block size limit, and the BCH chain omits SegWit, which recently activated on the BTC chain. Bitcoin block history diverged after block #478558, which is the last “common ancestor” that the two chains share.

The term “altcoins” has been used to denote cryptocurrencies that are not Bitcoin. Both of these chains, however, are valid Bitcoin chains as defined above. From this standpoint, the commonly expressed opinion that BCH is a new altcoin may be viewed as a use of language for rhetorical and emotional, rather than cognitive and elucidative, functions. Sharing almost all specifications and over eight years of transaction history, each is far more Bitcoin than either is altcoin. Some new term may be required. For example, in a public draft article, Daniel Krawisz, a long-time altcoin critic, has quite recently suggested the term “bitcoin child” to specify any chain that traces its history back all the way to the Bitcoin genesis block, a category that now includes BTC and BCH, but no others.

Proponents of each chain will naturally want to claim the banner of “true” succession, much as most religious sub-sects story themselves alone as the one truest representative of the ancient founder’s original teachings (rarely acknowledging the odd coincidence that all of the other sub-sects likewise tell just such a story about themselves). Regarding coin names, it is sufficient if the tradable units of the two chains are named in such a way that those using them now or in the future do not encounter any practical confusion. Bitcoin (BTC) and Bitcoin Cash (BCH) appear sufficient for this. For continuity, Bitcoin dominance indices might choose to sum the valuation estimates for the two post-split Bitcoin chains, perhaps after trading normalizes and if it appears that both will persist for some time.

Of most practical relevance now is the quality and prospects of the existing chains, as they have actually come to exist, moving from the present into the future. Practical measures of their prospects center on hash rate and unit price trends.

Rather than relying primarily on such ever-shifting market criteria, however, I prefer to begin by examining what defines the respective chains themselves. If we are talking about mining, mining what? If we are talking about price, the price of what? Identification properly precedes evaluation. In this case, a comparative identification is natural given the context of descent with modification, in which common features far outnumber differentiators.

Which chain is the “truer” successor is, in principle, not especially important in direct analytical terms. It might be useful as sociological research into the study of the development and spread of beliefs, or somewhat more useful than that as a source of hints for investors as to likely relative popularity based on belief frequencies in relevant user populations (meme frequency).

Nevertheless, BCH’s critics have taken to consistently labeling it an altcoin (which it is not), and moreover asserting that it is impossibly distant from being any true and proper successor of the one real bitcoin, which they believe the BTC chain unquestionably is. In this context, it should at least be noted in counterpoint that from a strictly content standpoint—rather than a popularity standpoint—BCH is arguably a nearer successor to 2009–2015-6 BTC than a post-SegWit BTC.

First, the BCH chain block size limit functions for the time being as a high upper-end traffic-burst defense, which matches the originally stated role and years-long practical function of this limit. This is more consistent in economic terms with the former BTC throughout the majority of its historical development until relatively recent times. In contrast, it was a significant new development when the particular height of the block size limit began to function for extended periods as an economic output ceiling on the industrywide production of Bitcoin transaction-inclusion services. Regardless of one’s opinion on whether this new economic effect is desirable, it remains that it was a significant departure from most of Bitcoin’s past viewed in functional economic terms.

Second, BCH does not implement SegWit. Again, regardless of one’s particular opinion on the net desirability of SegWit, it will in fact**arrive on the BTC chain—but not on the BCH chain—as a significant data-structural departure from the organization of the former Bitcoin’s blocks.

Both BTC (with the new SegWit and some other recent changes) and BCH (with its revised block size limit and some other recent changes) are direct successors of the Bitcoin that came before them and each differs in some substantive way from that former Bitcoin. Against a backdrop of continuous Bitcoin software modification and innovation over the years, this stands out as the first time protocol choice options have elicited sufficient sustained disagreement among participants that a chain split has in fact resulted. For the lower block-size limit camp, the key factor was the limit change being unacceptable to them; for the higher block-size limit camp, it was the failure to revise the limit, and for some SegWit activation as well, being unacceptable to them.

Some observers have expressed concern that this first Bitcoin chain split could set a precedent for additional splits in the future. This seems possible, but somewhat doubtful to me. First, it is unclear the extent to which this first split will prosper, and if it does quite poorly, this might discourage future attempts rather than encourage them. Second, months and years of debate, effort, proposals, and campaigns, all primarily centering around the block size limit issue, preceded this first chain split. This suggests this step has by no means come about lightly. Most importantly, I view the block size limit as quite unique and distinctive among Bitcoin protocol issues and think it unlikely that other issues are likely to rise to the level of sustained disagreement that would be required for another similar split. [That said, the 2MB hard fork already planned for November could lead to another split, but that plan predated the current split and some believe this split might even reduce the probability of the other one rather than enhance it.]

A poorly designed experiment, but all we get

The emergence of these two daughter variants of the former Bitcoin, which diverged from a common ancestor block on 1 August 2017, enables a certain evolutionary test in that both represent descent with modification following a speciation event. However, it is by no means a “clean” experiment, able to test the effect of changing a single variable. Alas, real-life evolutionary tests are usually “dirty,” reflecting the net effects of a complex interplay of context and interdependence. Even a single genetic change in an organism that does have some practical effect seldom has a simple, singular effect, but instead results in a certain cascade of effects, interactions, and adjustments.

As an experiment in the scientific sense, then, this chain split is badly confounded due to the many major variables differentiating the two chains. This includes, at least: the block size limit height difference, the presence/absence of SegWit, the respective quality levels and reputations of software development teams and software testing processes, differences in user traffic, and the extent and stability of relative hashing power. Most of these variables can impact both general user confidence (subjective) and bug probabilities (more objective). A good experiment, in contrast, would seek to change one variable at a time. This development does not do this—not even close.

A reasonable case can be made that the BTC/BCH split, such as it is, may be a net positive for holders of the previous “single bitcoin.” Bitcoin’s evolution continues for the time being along paths that have diverged into two chains differing across a set of multiple variables. This may well bring a certain marginal shift toward more practical experience opportunities and away from talk and modeling, which could in itself represent net value added from the event. Relative hashing power, unit prices, development efforts, and software quality levels are all likely to shift over time to various extents and directions not easy to predict (though always easy to “predict” afterwards). The complex sequence of outcomes to ensue must now be seen in practice and over time.

[Update: The original version used BCC for Bitcoin Cash, but this code was already in use by another cryptocurrency. Since that time the Bitcoin Cash community has clearly shifted to BCH.]

POST FOOTER

/post

/content-wrapper


Keepers — Workers that Maintain Blockchain Networks

By Ryan Zurrer

Posted August 5, 2017

Cryptographic tokens, which can represent digital scarcity in various forms, are an amazing use-case of blockchain technology. Tokens can be used to incentivize desired behaviours in decentralized networks. When designed correctly, tokens can act like rocket-fuel for driving network effects. One early example is Bitcoin’s block reward, which has incentivized an astonishing amount of computational resources to be spent securing its blockchain, to the point where now Bitcoin is more than 100 times more powerful than Google (arguments regarding the marginal benefit to security aside).

source: blockchain.info

Keepers

Bitcoin’s mining wasn’t intended to be useful beyond securing the network. However, now we are seeing “work” done by network actors, which not only secures the network, but also add intrinsic value for the network. The utility layer of a blockchain network — which is a group of self-interested actors that maintain stability— seems to be naturally positioned to be compensated for their work in the native token and also a logical choice to have a significant voice in governance over the development of the given network. I call these network participants “Keepers” as a catchall term for the different utility players in distributed networks that maintain stability and perform crucial jobs in the crypto-economic model. You may notice this term from the Maker White Paper but below is a list of some examples of Keepers, including a) their function on each blockchain network and b) their governance role:

Governance Layer

On-chain governance mechanisms are mostly still under research and development as noted above. This is because on-chain governance is very difficult to solve securely (see The DAO) and thus many projects are utilizing simulated governance in the initial stages of network release. For example, Maker uses a participatory process whereby all of the major token holders are heard by the core team in weekly governance meetings. While final decisions currently rest with the core team, controversial issues are thoroughly debated before implementation and consensus is sought. This will change over time an eventually MKR holders will have direct voting rights. Alternatively, Tezos and subsequently Dfinity are large-scale implementations of on-chain governance whereby token holders will vote directly on upgrades to the protocol immediately from the Genesis block. Both are incredibly ambitious endeavours and we are excited to see the lessons learned, including whether distributed governance allows for dramatically faster technical evolution of the protocol, as proposed by these respective projects.

Remuneration Layer

By remunerating Keepers in a native token, a network is able to dramatically reduce the cost to users of that network, thereby accelerating network effects. Keepers are well positioned to be paid for their work in the native token. Since Keepers are naturally interested in the long-term stability and health of the network they operate on, they are more likely to be cautioned, long-term token holders, thus adding further stability to the network’s economics.

Categories of Keepers

As the idea of Keepers evolves, I suspect there will be a broad taxonomy of specifically defined categories of Keepers. Initially, I would cautiously propose 3 general classes (but invite feedback on categorization).

1- Gatekeepers of Trust — these are trusted nodes that may validate transactions or actions of other network actors, often by having a stake in the network itself. Validators in Cosmos or Miners in PoS systems such as Tezos would fit this category. Often, these Keepers don’t need to expend extraordinary resources, they just need to be aligned with ensuring trust of the network.

2- Arbitrage Keepers — these are actors that scan the network looking for imbalances and profiting from opportunities, thereby keeping the network stable and/or operational. Keepers in Maker, Challengers in Truebit or Fisherman in Polkadot would fall into this category.

3- Resource-Transactional Keepers — these may be open architecture miners that trade one desired resource for another on a network such as file-storage for Filecoin or computation for bitcoin, ensuring a Nash-equilibrium between network actors and providing users with some valuable service.

Implications and Further Considerations

Checks and balances: If the remuneration layer allows Keepers to consolidate the vast majority of the native token over time and the token has a governance function, it could be very dangerous for a network to be totally dominated by a single Keeper layer. For example, one could argue that miner domination in Bitcoin has detracted from the evolution of the protocol. Keepers may not act in the long-term interest of the network as a whole and may tend to favour their own ideas and desires over end-users, which could prove myopic. Thus, when possible, there should probably be more than one type of Keeper i.e. more than one layer of utility-actors so there is balance in the decision-making and operation of the network. It will be interesting to observe the dynamic that evolves between competing Keepers in some of the projects listed above. Another option would be remuneration of software developers directly. Promoting a robust developer community that earns tokens for their important contribution and maintains a healthy ‘voting bloc’ seems appropriate in nearly all cases.

Governance is valuable in and of itself: I hypothesize that if a token only served as a governance mechanism and had absolutely no other utility function, it could still have some value measured as a fraction of the total value of the network. Such a hypothetical token (that I am not recommending) may not have the considerable value that a token with a specific utility function would have. However, a governance-token could still potentially be quite important and valuable to network participants.

Massive market opportunity: Because tokenized incentivization acts like rocket-fuel for propelling network-effects, I believe we will see highly efficient and professional Keepers on blockchain networks very quickly. In a similar exponential function to the Bitcoin hash-rate graph above, we will see the deployment of massive capital pools behind extremely sophisticated algorithms seeking arbitrage, routing transactions, providing resources and driving security in decentralized networks. This implies that small-scale operations that intend to operate as Keepers will have a short life-span and entrepreneurs should be thinking about scaling bigger, faster. Many of the networks cited herein will spawn tremendous opportunity for sophisticated investors with deep technical skills.

It’s an incredibly exciting time as we move from the ideas that began with Gavin Wood’s vision for Web3 into implementing a number of compelling distributed networks that will reorganize intelligence (both human and machine) and capital in totally new ways. I am very grateful to be able to work with such amazing technologists and entrepreneurs on their crypto-economic models and I am constantly amazed with the innovative ideas being proposed by communities and academic researchers. I can’t wait to see how Keepers evolve and invite constructive feedback on the ideas shared herein.

Kind regards,

-Ryan


How SegWit makes security better

By Oleg Andreev

Posted August 8, 2017

UPDATE (Aug 9, 2019): the described proposal has some significant flaws. A more secure proposal is discussed here:

Some people on the internet underappreciate how important a “malleability” aspect of Bitcoin is which is one of the things that Segregated Witness upgrade is going to fix.

Let’s take a look at Bitcoin Covenants paper from 2016 that introduces a “Vault” feature. I will briefly explain how Vaults work and how would you implement them in today’s Bitcoin without SegWit (today) and with SegWit (in two weeks).

First of all, what is a Vault? A slightly simplified version looks like this: you move funds to a special address V (“Vault”) from which you can only move them into address W (“initiate a withdrawal process”) and no other addresses. There are two paths from W. Path 1 allows moving funds from W anywhere after a 24 hour delay since the initiation of a withdrawal (that is, since the transaction V->W was published) using only an active key A. Path 2 allows moving funds anywhere without a delay, but requires both the active key A and a recovery key R (or multiple recovery keys).

Here’s a diagram:

initial deposit: $ -------> V

initiate withdrawal: V -------> W, using key A

unlock after delay: W --(a)--> *, using key A & 24h delay

recover funds: W --(b)--> *, using keys A & R, no delay

The theory behind Vault is that regular keys are convenient to use (they are always ready), but since they are more vulnerable, we require a publication of a “withdrawal attempt” with a grace period. If the withdrawal was legitimate, user would simply have to wait for the payment to go through. If it was not, the user has time to notice the attempt and will have to dig up the recovery keys: maybe ask friends to co-sign a transaction, or get a printed copy from a deep hole in their backyard. The time delay could be proportional to the amount of funds in question. Small amounts won’t use any vault, medium amounts would use 24 hour delay, long-term savings would use 72-hour delay and a multisig recovery setup with trusted friends/family.

Today Bitcoin does not have a CheckOutputVerify function suggested in the Covenants paper. To simulate it for the Vault case we can use a temporary key V for the Vault address and a pre-signed transaction V->W. Key V is destroyed after the address V is funded. Then, withdrawal can only be initiated by publishing the transaction V->W. Address W can use an already existing feature CheckSequenceVerify that enforces relative timelock (e.g. “24 hours since publication”), plus If/Else branches to allow a recovery path without a delay.

If we did not have transaction malleability, we would simply do the following:

  1. Create a temporary key V.
  2. Create and pre-sign transaction T1 that pays to V.
  3. Create and pre-sign transaction T2 that pays from V to W.
  4. Delete key V.
  5. Publish transaction T1.
  6. Store transaction T2 encrypted with an active key A.
  7. To make a withdrawal: publish transaction T2, pre-sign a delayed spending from transaction T2 into a given address, publish later when timelock is over.

If we do have to deal with transaction malleability, we cannot do steps 1-6 at once. We would have to store the temporary key V for a much longer time, persisted on disk (instead of in RAM for a millisecond), until transaction T1 is well-confirmed and the risk of chain reorganization that has a mutated version of it is very low.

What’s worse: we would introduce a new vulnerability. For regular payments, reorgs may cancel the payment, which can be retried by the sender. If you send to yourself, this is not a problem. But if you erase a temporary key and the pre-signed transaction (T2) is the only way to recover your funds, a reorg can lock you out forever. So you have to wait a significantly long time for your non-trivial amount of bitcoins to be securely locked by transaction T1.

While you wait, your key V has to be stored and backed up. If it is backed up, you need to protect it with a very strong password, but the whole premise of the scheme is to allow storing active key A with a mediocre password because strong passwords do not really exist. So if your key V is leaked while you wait, you lose all protections: attacker will not have to use your specially-crafted transaction T2, but would simply sign anything with key V directly.

So you need to store V stronger than you’d store A. You can achieve it with the same multisig setup you’d use for the recovery key(s) R: ask your friends to act as a collective additional key to your temporary V to pre-sign transaction T2 (using my blind signature scheme to maintain privacy). But now you no longer ask your friends to be only your recovery mechanism (which you may never have to use), but you have to ask them every time you move money into a vault.

As a result, your wallet has to be much more complicated, with a lot of moving parts, more user interactivity, and additional security assumptions instead of doing one obvious thing with one push of a button.

Segregated witness fixes transaction malleability and makes highly desireable security schemes possible. This is much more important than a minor increase in transaction throughput, because Bitcoin is stored most of the time and only occasionally changes hands.


An Inquiry Into John Nash’s Proposal For Ideal Money

By Juice

Posted August 9, 2017

This writing explores a special essay and lecture series by John Nash entitled Ideal Money. John Nash is already well known for redefining our understand of economics through various game theory related work. The Nash Equilibrium is one of the most widely cited solutions ever put forth yet Nash didn’t receive wide recognition for the significance of this contribution until nearly 40 years later. Our initial lack of understanding however did not deter Nash from continuing to provide many valuable solutions to incredibly difficult to solve problems while he waited for the rest of the world to realize the value of his insight. This essay argues that Nash’s proposal is on a level of significance far above his early work and is in fact the totality of the entire insight Nash had in the 60’s at the time he wrote his earliest groundbreaking work.

20 Years of Lectures and Writing on the Subject of Ideal Money

Ideal Money has many different versions of the argument Nash put forth almost none of which are well known to anyone including academic professors studied in the field of economics. Many of these versions can be found on Nash’s homepage hardly hidden among different folders that are available for public view. Each lecture or writing uses different metaphors and examples that use different economic events of our history or recent times to explain the concept of Ideal Money in different ways. One such paper was published in the Southern Economic Journal and this paper varies drastically with the other papers and lectures that are available. Nash presented the subject in a way that would be difficult to grasp with out the collective context of most or all the works.

The Origins of the Concept of Ideal Money

Nash said in an interview that the basic concept for Ideal Money came to him in the 60’s when he fled to Europe. His biography suggests that at this time he was having delusional episodes. One such “delusion” from this time had him running around suggesting that governments, communist and anti-communist alike, were colluding against the people and that he was going to be our “savior”. On the one hand such behavior would obviously be seen as extremely narcissistic and paranoid, on the other this writing will show not only did Nash never abandon this view but it was quite a logical observation to make. It also the conclusion of Ideal Money:

The Keynesian implicitly always have the argument that some good managers can do things of beneficial value, operating with the treasury and the central bank, and that it is not needed or appropriate for the citizenry or the “customers” of the currency supplied by the state to actually understand what the managers are managing, what exactly they are doing and how it will affect the “pocket book” circumstances of these “customers.”

I see this as analogous to how the “Bolshevik communists” were claiming to provide something much better than the “bourgeois democracy” that they could not deny existed in some other counties. But in the end the “dictatorship of the proletariat” seemed to become rather exposed as simply the dictatorship of the regime. So there may be an analogy to this as regards those called “the Keynesians” in that while they have claimed to be operating for high and noble objectives of general welfare what is clearly true is that they have made it easier for governments to “print money”.

So I see the Keynesians as in a weak sense comparable to the “Bolsheviks” because of the support of both parties for a certain “lack of transparency” relating to the function of government as seen by the citizenry.

How Can We Define (A Stable) Metric For Value

Understanding value is not easy which is really a symptom of not having a stable metric for it. This is something we can begin to understand by thinking about how we evaluate money and commodities on markets that give us price signals for them. Put another way we might ask how we can objectively evaluate government issued fiat of any given nation. If, for example, we are to compare the Euro to the US dollar we might observe at some period of time that the exchange rate for Euro is falling. This might be an indication in a loss of value, however, if the price of the Euro is rising in relation to the Venezuelan Bolivar this might suggest not that the Euro is necessarily losing value but that both the US dollar and the Euro are increasing in value and that the US dollar is simply increasing more or faster than the Euro.

Because each of the currencies have floating exchange rates in comparison to each other, and each central bank that issues these currencies has their own policy and control over inflation, no currency really functions as a long term stable comparison for value.

However, if we measure a given currency versus a basket of currency prices this would be a more objective valuation than the comparison to just one currency. This is a comparable observation to how central banks measure and target inflation:


its was the observation of a new “line”
for “central banking” functions relating to national currencies that gave us the idea for the study of “asymptotically ideal” money.

The idea seems paradoxical, but by speaking of “inflation targeting” these responsible official are effectively CONFESSING
that it is indeed after all possible to control inflation by controlling the supply of money (as if by limiting the amount of individual “prints” that could be made of a work of art being produced as “prints).

How would they do this? The means for measuring inflation that they would naturally use would be a “cost of living” index relation to domestic prices within the territory of the state.

On a domestic level an aggregate of different prices helps provide a reasonably objective measure for comparing the inflation of a respective money. The argument Nash paints is based around a comparable concept he calls an ICPI. The ICPI would be an optimally chosen basket of international prices which would provide an international basis for value comparison.

Isn’t Gold Stable In Value?

Historically at times gold has provided a reasonably stable basis for value although it is said we were never truly on a gold standard. At the end of WWII much of the world moved on to a de facto gold standard in which the US pegged their currency to gold in what is known as the Bretton Woods Agreement. This standard lasted until the 70’s when the US abruptly abandoned the standard and the world was forced to follow suit and move to the floating exchange system we have today

Some economic philosophers suggest we strive to achieve such a gold standard, however, as noted in Ideal Money this might not be optimal:

Nowadays, however, few would propose a return to the actual use of simply the metal gold as a standard, for the following reasons:

The cost of mining gold effectively does depend on the technology. Recent cyanide leaching techniques have made it possible again to profitability mind gold at formerly abandoned sites in the U.S. so that it is now a big producer. However, the unpredictability of the cost is a negative factor.

The location of potential gold-mining locations may not be “politically appealing.” so it would seem undesirable to make a political choice to enhance the economic importance of those particular areas.

There is some negative psychology about gold such that even if it were the most logical choice after all, the unpopularity of the idea could be very obstructive.

Nonetheless one would expect gold to be a component of Nash’s ICPI

The Misrepresentation of Nash’s Theoretical ICPI

The ultimately launched concept of “ideal Money” become possible when I conceived of a practical basis of a standardization of the comparison of the value of the currency with an appropriate standard of ideal.

Not many people have been exposed to the bulk of Nash’s argument and often people mistakenly believe that Nash suggested we should peg our money to a politically constructed ICPI. Although the ICPI is the basis for the special insight it is not itself a solution as Nash’s points out because it would be need to be adjusted over time which introduces the possibility for political pressure:

We can see that times could change, especially if a “miracle energy source” were found, and thus if a good ICPI is constructed, it should not be expected to be valid as initially defined for all eternity. It would instead be appropriate for it to be regularly readjusted depending on how the patterns of international trade would actually evolve.

Here, evidently, politicians in control of the authority behind standards could corrupt the continuity of a good standard.

However, pegging money to an ICPI was NOT Nash’s proposal:

It seems possible and not unlikely, however, that if two states evolve towards having currencies of more stable value as measured locally by national CPI indices that then also these distinct currencies would tend to evolve towards more stable comparative relations of value.

Then the limiting or “asymptotic” result of such an evolutionary trend would be in effect “ideal money” but this as a result achieved without the adoption of anything like an ICPI index as a basis for the standard of value.

Understanding the Purpose of Defining a Theoretical ICPI

Nash’s ground breaking solutions and papers are well known for having a very special flare. He solves problems from angles his peers admit they would never have thought to think from and his solutions often have what initially seems to be leaps of logic. Often years later when we fully understand his work we can work through the logic to see that it’s all there but rather it was just so paradigm shifting it seemed like there could be no bridging explanation.

Ideal Money works like this. It is basically mathematical induction. It’s like building a form for a bridge and then once the final keystones are in place the bridge holds on its own no longer needing the form.

Nash’s argument in a nutshell is that, although, we cannot design a money that is perfectly stable in value, we could see that money that does approach stable value can necessarily be said to approach a limit that WOULD BE comparable to an optimally chosen basket of commodity prices.

This observation in itself might not seems like a special or valuable insight, but it is what set Nash over the edge when the idea come to him. It’s also his life’s work and something he spent the last 20 years of his life giving lectures on.

What is the Significance of Nash’s Insight?

The ultimately launched concept of “Ideal Money” became possible when I conceived of a practical basis for a standardization of the comparison of the value of the currency with an appropriate standard ideal.

The significance of this idea is what you can extrapolate from it-not the idea itself. From this viewpoint of observing that if money were put on a stage of competition in which it must compete to survive we can begin to ask what is needed to create this phenomenon.

The below is a lengthy and wordy paragraph but incredibly revealing and further shows the genius of John Nash’s proposal:

I think there is a good analogy to mathematical theories like, for example, “class field theory”. In mathematics a set of axioms can be taken as a foundation and then an area for theoretical study is brought into being. For example, if one set of axioms is specified and accepted we have the theory of rings while if another set of axioms is the foundation we have the theory of Moufang loops.

So, from a critical point of view, the theory of macro-economics of the Keynesians is like the theory of plane geometry without the axiom of Euclid that was classically called the “parallel postulate”. (It is an interesting fact in the history of science that there was a time, before the nineteenth century, when mathematicians were speculating that this axiom or postulate was not necessary, that it should be derivable from the others.)

So I feel that the macroeconomics of the Keynesians is comparable to a scientific study of a mathematical area which is carried out with an insufficient set of axioms. And the result is analogous to the situation in plane geometry, the plane does not need to be really flat and the area within a circle can expand hyperbolically as a function of the radius rather than merely with the square of the radius. (This picture suggests the pattern of inflation that can result in a country, over extended time periods, when there is continually a certain amount of gradual inflation.)

The special axiom is again not necessarily novel until we begin to flip the perspective. Nash highlights it here:

The missing axiom is simply an accepted axiom that the money being put into circulation by the central authorities should be so handled as to maintain, over long terms of time, a stable value.

The Problem With Central Banking

Central banks aren’t evil. Most people that suggest banks are immoral don’t understand the purpose of central banking. Central banks adjust the money supply via inflation rate policies in order to reflect economic growth (or decline of growth). Central banks usually favor slight inflation, however, this attitude can change depending on political and economic circumstances.

Stability of value is the general goal but a predictable rate is sometimes favored over perfect instability in order to serve exports and imports needs. If the value of a currency begins to rise especially in relation to other relevant currencies then export number suffer. If exports are expected to fall and the economy will suffer central banks will often devalue their currency in order to make exports cheaper for foreign buyers.

The contrasting views between the search for an internationally stable metric of value and the want to increase inflation to spur economic growth somewhat highlights what is known as the triffin dilemma:

The Triffin dilemma or Triffin paradox is the conflict of economic interests that arises between short-term domestic and long-term international objectives for countries whose currencies serve as global reserve currencies.

The currencies in the world don’t really compete in a way that makes them strong over time, rather, different respective nations are sometimes and often in a race to devalue. In contrast devaluing a reserve currency (such as the US dollar is sometimes said to be) has its own ramifications. So there is pressure both ways to not seek stability of value even if in the long run it would be optimal for all nations and their respective citizens.

The Importance of a Stable Metric For Value

We tend to think of currency as a medium of exchange for value. But this function can be viewed a side product of our want for effective value comparison. When the value changes, however, money no longer serves this purpose.

Nash explains the importance of a stable unit of value with this example:

Consider a society where the money in use is subject to a rapid and unpredictable rate of inflation so that money with 100 now might be worth 50 to 10 by a year from now. Who would want to lend money for the term of a year?

From a short term individual view the the importance of money seems to be to serve everyday transactions but the real problem we face as a global economy is how to get onto the same incorruptible value standard.

Bitcoin as the Premise of Nash’s Proposal

From the perspective of Nash’s insight we can extrapolate every aspect of bitcoin as a catalyst for the evolution of our money systems towards what would be comparable in stability to an optimally chosen basket of commodity prices (ICPI). What is needed is the introduction of an internationally traded currency or commodity that is as good or better than other alternatives available. This is exactly what Nash calls for:

I think of the possibility that a good sort of international currency might evolve before the time when an official establishment might occur.

Here I am thinking of a politically neutral form of a technological utility.

To be quite respectable, in a Gresham-advised sense, money needs only to be AS GOOD as other material commodities that might be hoarded.

Bitcoin is slowly becoming understood to function as a form of value storage for much of the same reason that gold has historically played this role. Not necessarily the scarcity of supply but the relation of the supply to the cost of mining which bitcoin effectively mimics. Bitcoin provides a fairly stable (but not perfect!) and predictable measure of value which the markets can rely on as an inflation hedge. Nash even perfectly predicts bitcoin’s inflation schedule which decreases by half every 4 years:

Now the possible area for evolution is that if, say, an inflation rate of between 1% and 3% is now considered desirable and appropriate in Sweden, then, if it is really controllable, why shouldn’t a rate between 1/2 % and 3/2 % be even more desirable?

As bitcoin becomes more relevant and traded for more currencies across more exchanges central banks will find themselves competing with bitcoin for relevance. As customers of fiat the citizens will naturally put pressure on central banks to print money of a higher quality in regard to stability of value just as Nash predicted 20 years ago:

The currencies being compared, like now the euro, the dollar, the yen, the pound, the swiss franc, the swedish kronor, etc. can be viewed with critical eyes by their users and by those who maybe have the option of whether or not or how to use one of them. This can lead to pressure for good quality and consequently for a lessened rate of inflationary depreciation in value.

The ultimate result of this phenomenon is that our money systems will hit the ceiling of ideal-ness that Nash describes as being comparable to an ICPI (again without ever implementing an ICPI). This allows us to return to his original claim that otherwise competing governments and their respective central banks effectively collude against the people’s best interests. Nash’s claim that he would solve this problem is actually rational:


this standard, as a basis for the standardization of the value of the international money unit, would remove the political roles of the “grand pardoner’s,”


This insight is what causes Nash to declare:


a process of political evolution might lead to the expectation on the part of citizens in the “great democracies” that they should be better situated to be able to understand whatever will be the monetary policies which, indeed, are typically of great importance to citizens who may have alternative options for where to place their “savings”.

On The Difficulty of Traversing Nash’s Argument

Much of Nash’s work is difficult to understand. He is well known for unapologetically putting forth solutions with seemingly little explanation. Ideal Money however was an insight Nash felt would not go over particularly well with those that traditionally held the monopoly on money printing:

The script or plan for my talk linking the “ideal money” with the choices and actions of “thrift” or “savings” by persons or by “economic agents” was influenced by concerns that it would be wise not to speak too incautionsly of “the Keynesians” when the times are such that massive public opinions maybe supporting actions by which a state administration can act without going through the parliamentary processes to write new legislation.

So in the rush of political campaigns and elections (for example in the USA) it is difficult to sell a national monetary policy which, if followed consistently on a “long run” level, would result in the specific nation state existing as if on a higher level of economic civilization.

(For example, Sweden and Argentina might be usable, over a long time comparison, to represent comparable “economic civilizations”.)

Therefore, I had arranged for 2012 to talk more cautiously in relation to whatever would impact with “the Keynesians” and with the political interest relating also to the scholarly factions allied with (or forming) “the Keynesians”.

And this caution carries over naturally to 2013 also.

I am speaking about a research project that is not fully complete since I have not yet written up and submitted for publication any paper or papers describing the work. Also the details of what axioms to use and how to select the basic set theory underlying the hierarchical extension to be constructed are not fully crystallized. I have also a great fear of possible error in studying topics in this area. It is not rare, historically, for systems to be proposed that are either inconsistent or that have unexpected weaknesses. So I feel that I must be cautious and proceed without rushing to a goal. And this psychology of fear has also inhibited me from consulting other persons expert in logic before I could feel that I had gotten my own ideas into good shape.

Conclusion

The conclusion has already basically been expounded on but there is a relevant point to be made in regard to bitcoin. The community of early bitcoin adopters is said to be in a civil war with itself. On the one hand there is a faction of people that are basically ignorant to the concept of central banking practices and their purpose who are arguing for “hyperbitcoinization” which is the idea that bitcoin will eventually usurp all central banks and cause hyperinflation of all fiat.

This is simply the conclusion of someone that doesn’t properly view the role of central banks:

The idea seems paradoxical, but by speaking of “inflation targeting” these responsible official are effectively CONFESSING
that it is indeed after all possible to control inflation by controlling the supply of money (as if by limiting the amount of individual “prints” that could be made of a work of art being produced as “prints).

The proper outlook for bitcoin when we consider how central banks actually work is for it to be a catalyst that improves central banking practices and the quality of money central banks issue in regard to stability of value. This is explained in a congressional research report on bitcoin:

Regarding the velocity of money, if the increase in the use of Bitcoin leads to a decrease in need for holding dollars, it would increase the dollar’s velocity of circulation and tend to increase the money supply associated with any given amount of base money (currency in circulation plus bank reserves held with the Fed).

In this case, for the Fed to maintain the same degree of monetary accommodation, it would need to undertake a compensating tightening of monetary policy.

What has happened is Nash has given the proper logical and founded argument for the optimal use-case for bitcoin. While many people new to bitcoin and uneducated in economics are rallying behind a movement to scale bitcoin to be an everyday coffee money that anyone in the world can use for a low fee bitcoin is slowly showing itself to be resilient towards this movement and instead is slowly starting to be heralded for its gold like qualities as an inflation hedge.

At the same time actual experts in the field are noting that bitcoin can’t necessarily scale to serve the entire population of the world so soon in its infancy. As a matter of fact that the transaction capacity cannot scale on the base layer may in fact lend to the predictable nature of bitcoin’s value proposition further solidifying its role as a new digital gold.

As bitcoin’s fees rise the average user that doesn’t understand the macro-economic implications of bitcoin starts to get frustrated. But as the currency’s inflation rate continues to decline bitcoin will eventually be effectively scarcer in supply than gold. As the network effect continues to drive the price the fees increase. This cannot be seen as a fatal flaw since the high fees are in fact an indicator that there is such a demand for the limited transaction space. As this demand for a stable store of wealth increases the price of bitcoin in respective fiat money increases which allows higher and higher value players to enter the market. Eventually we should expect large hedge funds and even central banks to hold substantial positions in bitcoin.

At this point bitcoin as a settlement system will serve as the perfect catalyst John Nash described that will “asymptotically” take the power from central banks to arbitrarily print money against the ultimate good of the people.

It’s been suggested Nash might be the mastermind behind bitcoin, but whether he had something to do with the project or not does not take away from the specialness of the proposal Ideal Money. Nash’s Ideal Money is clearly premised on bitcoin, whether he knew about it or not, and more importantly Nash left us the logical founded argument for how bitcoin should be scaled well before the technology existed.

As more and more academic and economic professors learn about bitcoin and Nash’s argument a new revolution of people will lend support to this theory. At this point bitcoin nature as a digital gold will be preserved by knowledge economic experts and professors around the world. Nash’s proposal will be the foundation for such a movement.


Is Bitcoin Money?

By Beautyon

Posted August 9, 2017

It doesn’t matter if Bitcoin is money or not. What matters is its utility, not its definition. It’s like asking whether or not emails are “letters” or webpages are “newspapers”. It is of no consequence at all in either case. This is a line by line rebuttal of an article by Jim Rickards, notorious nocoiner.

At various times in history, feathers have been money. Shells have been money. Dollars and euros are money. Gold and silver are certainly money. Bitcoin and other cryptocurrencies can also be money.

This is not relevant, and arguments over what money is and is not are also not relevant and have been going on for years with reference to Bitcoin. The only thing that matters is what you can do with Bitcoin, not any definition of it. It doesn’t matter that you call email “letters”, as long as email works. The same is true with Bitcoin. If you can use it as you use money, then you can use it. What economists and other think is not relevant to the big picture, and is a distraction.

People say some forms of money, such as Bitcoin or U.S. dollars, are not backed by anything.But that’s not true.They are backed by one thing: confidence.

This is an incorrect use of the word “backing”. Federal Reserve Notes used to be backed by gold. That means you could redeem them for physical gold. “Backing” in this context means “redeemable”. When you redeem you dollars with the government, what do they give you in return? They don’t store “confidence” at Fort Knox or the New York Fed, and the Germans wanted their gold returned to them, not “confidence”.

You can’t just change the meaning of words to make an argument, and have the argument remain sound. Confidence is meaningless as a measure of integrity in the money context, and we can see this is true in fiat. All fiat currencies have gone to hyperinflation without exception, and yet all the governments that issued them had the full confidence of the public.

If you and I have confidence that something is money and we agree that it’s money, then it’s money. I can call something money, but if nobody else in the world wants it, then it’s not money. The same applies to gold, dollars and cryptocurrencies.

This is absolutely false. People in the USA will not take Euros for purchases not because they have no “confidence” that the Euro is money, but because they can’t spend it locally. And putting up the standard that no one else in the world wants it excluding it as money is absurd. Once again, this is a total distraction to the important issues swirling around Bitcoin, and failing to grasp this is what makes people fail to understand exactly what Bitcoin is offering.

Governments have an edge here, because they make you pay taxes in their money. Put another way, governments essentially create an artificial use case for their own forms of paper money by threatening people with punishment if they do not pay taxes denominated in the government’s own fiat currency.

By this argument, pieces of wood, like the Tally Stick are money. This does not require collusion of many people, just force. So is money the result of compulsion or collective delusion?

And the dollar has a monopoly as legal tender for the payment of U.S. taxes. According to John Maynard Keynes and many other economists, it is that ability of state power to coerce tax payments in a specified currency that gives a currency its intrinsic value. This theory of money boils down to saying we value dollars only because we must use them to pay our taxes — otherwise, we go to jail.

Citing Keynes
unbelievable. The ability to force someone to do something can’t turn an object into money. If that were true, literally anything could be money, including kidnapped people, and not even Keynesians would claim that “people are money”.

So-called cryptocurrencies such as Bitcoin have two main features in common. The first is that they are not issued or regulated by any central bank or single regulatory authority. They are created in accordance with certain computer algorithms and are issued and transferred through a distributed processing network using open source code.

This is a very poor description of how Bitcoin works, but it doesn’t matter that no one understands the workings underneath it. People make posts on Blogs like this one, which is behind SSL, and have no idea about any of the complex software that powers their writing. Trying to explain Bitcoin’s workings is a fools errand for computer illiterates, who must try and find some other means of addressing and explaining how it works. They invariably fail.

The second feature in common is encryption, which gives rise to the “crypto” part of the name. It is possible to observe transactions taking place in the so-called block chain, which is a master register of all currency units and transactions.

Once again, this shows that Rickard’s understanding of how Bitcoin works is not complete. It would be much better for him to actually use it himself and then talk about his user experience, rather than trying to delve into the low level details. I’m sure he could explain how to write a blog; he wouldn’t add how SSL works as part of his description. How SSL (or Apache or Browsers) work under the hood is immaterial to blogging.

But the identity of the transacting parties is hidden behind what is believed to be an unbreakable code. Only the transacting parties have the keys needed to decode the information in the block chain in such a way as to obtain use and possession of the currency.

This is nonsense, and it is not how Bitcoin works at all. Not even close. You never posses or receive Bitcoin in a transaction. It’s hard to believe, but that is in fact an accurate description.

This does not mean that cryptocurrencies are fail-safe. But on the whole, the system works reasonably well and is growing rapidly for both legitimate and illegitimate transactions_._

This is not true. The system works perfectly and has an unrivalled uptime record. There are no illegitimate transactions on Bitcoin. All transactions are simple messages sent and received by software clients, and that is all. Any attribute you place on them is purely one of your own incorrect perspective, and not of fact. Its like saying there are “illegitimate phone calls”. No one in their right mind thinks that, and Bitcoin is no different to a phone call or a text message, save in the way the message is handled. Its just data, from end to end, all the time, without exception.

It’s worth pointing out that the U.S. dollar is also a digital cryptocurrency for all intents and purposes. It’s just that dollars are issued by a central bank, the Federal Reserve, while Bitcoin is issued privately. While we may keep a few paper dollars in our wallets from time to time, the vast majority of dollar-denominated transactions, whether in currency or securities form, are conducted digitally.

This is false. The dollar is in no way shape or form a “digital cryptocurrency”. Anyone who thinks this clearly doesn’t understand what Bitcoin is and why it is special. Bitcoin is fundamentally different to the dollar at every level, and this is why it’s so interesting. If you don’t understand why the dollar is not a cryptocurrency, then you will not be able to understand why Bitcoin is so important and why it is so revolutionary.

We pay bills online, pay for purchases via credit card and receive direct deposits to our bank accounts all digitally. These transactions are all encrypted using the same coding techniques as Bitcoin.

This is not true. The same software is used to do many things, but in the unique arrangement that is Bitcoin, it stands completely alone. Its like saying, “ink is used to print different newspapers, so newspapers are like paper dollars because both use ink and paper”.

The difference is that ownership of our digital dollars is known to certain trusted counterparties such as our banks, brokers and credit card companies, whereas ownership of Bitcoin is known only to the user and is hidden behind the block chain code.

The difference is way, WAY beyond a simple knowledge of ownership. In Bitcoin, there are no trusted counterparties; it is peer to peer. The ownership of Bitcoin is known to everyone on Earth. All you need to do is look on the block chain to see who controls what Bitcoin. And there is no such thing as “block chain code”.

Bitcoin and other cryptocurrencies present certain challenges to the existing system. One problem is that the value of a bitcoin is not constant in terms of U.S. dollars. In fact, that value has been quite volatile, fluctuating between $100 and its present high above $3,400 over the past few years. It’s currently around $3,467.

The fact that Bitcoin’s price goes up and down is not a challenge to the existing system. It is a result of an immature on ramp and price discovery system that is getting better every day. A chart of the volatility of Bitcoin shows a steady downward trend. Bitcoin’s volatility is one of the many arguments against it we have read over and over for years now. It is not novel, interesting or insightful.

One potential solution to the Bitcoin volatility problem I find interesting is to link Bitcoin to gold at a fixed rate. This would require consensus in the Bitcoin community and a sponsor willing to make a market in physical gold at the agreed value in Bitcoin. This kind of gold-backed Bitcoin might even give the dollar a run for its money as a reserve currency, especially if it supported by gold powers such as Russia and China.

The idea of linking Bitcoin to gold is an old one, and some companies have tried it and failed. There is no reason to link Bitcoin to gold; it offers no extra utility or security or value, and in fact, introduces friction and risk. Bitcoin backed by gold will never happen. It is a bad idea that has been rejected by the market. Bitcoin alone is enough to change the entire world exactly as it is. Backing Bitcoin by gold is like saying, “Email will be more useful and acceptable if it is used to scan hand written letters that are then sent to the recipient”. Totally ridiculous, obviously, but that is what is being suggested here.

Clearly Rickard’s has not had any real exposure to Bitcoin, and yet, he persists in writing about it in a way that exposes this. The question is, “Why?”. Why does he not ask someone to help him understand Bitcoin , rather than double down every time he get pulled up on the matter?

His experience in business, currencies and markets could be invaluable to the Bitcoin community, but it will be lost if he stubbornly refuses to accept the facts and embrace Bitcoin. I’m sure someone out there would be more than willing to help Jim!

While the price is low and the fees are cheap, send Bitcoin here, so we can eat!


Traditional Asset Tokenization

By Stephen McKeon

Posted August 11, 2017

Tokenization of traditional assets in the coming years will have an impact on liquidity across multiple asset classes. The implications of this statement are relevant to all investors, including both traditional and crypto, for reasons I detail in this post.

I. Liquidity: The driving force behind traditional asset tokenization

Let’s start by defining liquidity. Liquidity is not binary, it is a continuum. Illiquid does not necessarily mean “unable to trade,” it means “costly to trade.” Liquidity is related to trading volume and can be measured using price impact from trading, or by observing the bid-ask spread.

An example: When I was a kid I found a Darryl Strawberry rookie card in a pack of Topps. By the late 1980’s, Beckett Monthly listed the value at something like $50.

Upon opening my Beckett Monthly, I thought: “That’s 100 Snickers bars!” I was ten years old so 100 Snickers bars had a lot of utility value to me back then. I wanted to trade.

I marched over to my local card shop, presented the card to Calvin, the owner, and requested $50. Calvin offered me $10. Sadly, that was the only card shop within walking distance, and I had binding transportation constraints since I was only 10. Calvin represented the only market participant. I accepted $10. This is the “bid” in financial jargon. Calvin then put it on the shelf with a $50 price tag (the “ask”). This is an example of a very large bid-ask spread, therefore, the Darryl Strawberry rookie card is considered a relatively illiquid asset.

The advent of sites like eBay made life a lot better for baseball card traders because it opened up competitive markets with more participants and volume, and assets could be bought and sold with smaller spreads and less price impact. All things equal, additional liquidity increases the expected value from trade.

This post is not about baseball cards, so let’s extend this framework to think about other assets like equity in private companies. A share of stock that’s traded on an exchange is of higher value than a share of stock in an identical private company because there are less frictions to trade the public stock. Less frictions often mean more market participants, more volume, smaller spreads, and less price impact. We think of the difference in value between the public company and identical private company as an “illiquidity discount,” or analogously a “liquidity premium.”

How big is the illiquidity discount? Financial economists have attempted to measure the illiquidity discount in a variety of ways. A common rule of thumb is 20–30%. This represents a huge amount of value and therein lies great promise. Tokenizing relatively illiquid assets and creating a market in which to trade these tokens can reduce the illiquidity discount substantially by reducing frictions to trade. Traditional assets will tokenize because they will lose the liquidity premium if they don’t.

II. Traditional asset token use cases

This tweet by @naval is profound and extends well beyond traditional asset tokenization. However, it certainly applies to all the assets currently characterized by low liquidity that will get tokenized in the future. Let’s briefly unpack a couple of these.

Blockchain Capital as an example of traditional asset tokenization. Typically, investors in venture capital (VC) funds, known as limited partners (LPs), are locked up for 10 years, and for good reason: VC funds invest in illiquid securities and cannot fulfill redemption requests in the interim. In so doing, the liquidity premium is a component of VC returns.

There are often fund-level restrictions that prevent LP investors from trading their positions and VCs have historically not gone out of their way to facilitate trade for their LPs. Blockchain Capital has demonstrated that this model can be disrupted. They executed a portion of the fundraising for their recent VC fund by issuing a blockchain token (BCAP). In doing so, the fund receives the capital they need to invest in illiquid securities, yet investors can exit prior to 10 years selling the token to another investor. Importantly, this liquidity does not require a redemption on the part of the fund. Furthermore, since tokens are highly divisible, it eliminates the need for minimum investments. Blockchain facilitates trade in the secondary market.

Consider commercial real estate. Publicly listed Real Estate Investment Trusts (REITs) provide some liquidity, but they are expensive to set up and typically hold a basket of properties rather than a single building. Furthermore, REITs are typically buy and hold vehicles, so most investors are shut out of development projects entirely unless they can meet minimums which are often on the order of $25k and higher. One day you might be able to buy $10 of a single commercial real estate asset like the Empire State Building, or invest $100 in the development of a LEED-certified housing project. Real estate focused token exchanges will increase liquidity for asset owners. Real estate appraisers will become more like equity analysts, because the market value of any building will be readily apparent if the token is trading. Tokenization will make IRS 1031 exchanges easy.

Consider residential real estate. Perhaps funding models will emerge where you can tokenize your house instead of taking out a traditional mortgage. Instead of making mortgage payments, you will make payments to the network of token holders. I will not pretend to know exactly what this might look like, but I think we will see some version of this in the coming years.

Fine art will be tokenized. Perhaps small donors will collectively acquire a Picasso for their local museum through a token sale even though none of them possess the resources to acquire the painting individually. The difference between this and current crowdfunding models is that the token holders can retain fractional ownership. Charitable donations will evolve towards charitable investments. Token governance mechanisms will evolve to enable granting usage rights rather than cash flows.

These and many other assets that are costly to trade will be tokenized and become more liquid. Vacation timeshares come to mind. The lines between token exchanges and traditional exchanges will blur. Most electronic exchanges will trade tokens because most assets will be tokenized.

III. Challenges for traditional asset tokenization

Regulatory: Although there are early efforts in progress (e.g. digix for gold and rex for real estate), mass adoption of traditional asset tokenization is going to take years, and possibly decades, to fully develop. Technology evolves quickly, but regulation does not. Traditional asset tokenization represents one of the greatest opportunities, and greatest challenges, that the SEC and other global regulatory agencies will face over the next decade.

Governance: If one entity owns a building they have the incentive to monitor things like maintenance and timely lease payments. If 10,000 people own the same building then it may be the case that no owner has the incentive to monitor, because the cost of monitoring exceeds the value of their investment. Solutions will need to come to market that enable governance of widely held tokenized assets. Financial economists have spent a lot of time thinking about the separation of ownership and control and will be able to help design these solutions.

Thinly traded tokens: Let’s be very clear about this one: the mere act of token generation to represent ownership claims on a traditional asset does not impact liquidity in and of itself. If a token is thinly traded it is still relatively illiquid. Improvement in liquidity comes from increases in market depth, meaning more participants and more trade. The reason tokenization improves liquidity is because it enables deeper markets. Since tokens are highly divisible and global, the potential number of market participants is substantially higher than what we see today in markets for illiquid assets.

Status Quo: Tokenization of traditional assets will cause disruption to the status quo. Some systems that are in place today may not work the same way in the blockchain world (e.g. equity securities lending). That doesn’t mean the blockchain world isn’t coming, it means the current systems will have to evolve. The challenge is that there are stakeholders that benefit from the status quo. These constituencies have incentives to resist change, and they will do what they can to slow down adoption. I view this as a speed bump rather than a barrier.

IV. Impact of traditional asset tokenization on protocol tokens

As Nick Tomaino mentioned in a recent post, traditional asset tokens are less common and perhaps less interesting than protocol tokens. I agree with this sentiment. However, traditional assets currently represent aggregate market value that is orders of magnitude greater than cryptoassets. As they tokenize I believe that there will be crossover effects that are relevant to protocol tokens.

Consider the market sizes of low liquidity assets. Global real estate value was recently estimated at $217trillion. Roughly 25% of that total, $54 trillion, is commercial. For arguments sake, let’s say a 10% liquidity premium would be applied to these assets if they were tokenized and could be traded freely. That’s over $5 trillion, or put another way, the illiquidity discount on global commercial real estate is about 40–50x the aggregate value of all cryptoassets as of this writing. These are big markets. Will tokens eat the whole market? Of course not, but they will eat some, and as time goes on the bites will get bigger and bigger. These tokens will become embedded within the larger ecosystem of cryptoassets. Traditional asset tokenization is going to impact protocol valuation because they will become intertwined.

If traditional asset tokenization occurs on top of an existing crypto protocol (e.g. ERC20 tokens), this will influence value of the underlying blockchain network. Further, traditional asset tokenization enables protocol tokens to be used as a method of payment in both directions. For example, perhaps dividends/lease payments/coupon payments are paid out in ETH or BTC. This will drive demand for the protocol tokens and influence valuation. Finally, there will be a demand for governance protocols within traditional asset tokens, giving rise to new platforms. Crypto investors would be wise to watch these developments, even if they don’t intend to invest directly in this asset class.

It will be fascinating to watch this develop. As the world’s assets become increasingly liquid, the concept of ownership will evolve in ways we cannot yet imagine.


Visions of How Banking Will Be Disrupted

By Beautyon

Posted August 15, 2017

One of our acquaintances is a gold bug. That means they store their wealth not in fiat, but in gold bullion. They recounted the following story to me over drinks, that I must share with you right now. It is a story of how banks are going to be completely disrupted by Bitcoin.

My acquaintance wanted to sell a single Krugerrand. She found a mobile gold buyer, who agreed to the trade. When the trader arrived, the deal got under way. He does this every day as a regular part of his business.

Chip and Pin Two Factor Authentication devices.

The trader had three devices; an iPad for internet access, an iPhone to do the fiat payment from the company bank account to my acquaintance’s bank account, and a bank issued Two Factor Authentication device with a slot in the top for his “Chip and Pin” bank card.

The trader had the iPad on his lap, the iPhone in his left hand, and the 2FA device in his right hand. Once the iPad found a wireless signal, the buyer set up a local wi-fi network on the iPad and connected the iPhone to it. Then he opened his Bank account app, and logged in. He opened up a gold price checking iPhone app (I didn’t glimpse which one) and got the spot price.

He then typed out the account name, account number, sort code and bank of the gold seller into the iPhone app. Then he put the iPhone down, switched the 2FA device to his left hand, pulled his wallet out of his right back pocket with his right hand, and took out his bank card, which he slotted into his 2FA device. He typed his PIN Code into the 2FA device, and retrieved a token to log into the iPhone App with. He was authenticated



.then he made the transfer.

Now compare this Heath Robinson juggling process, with the payment process had the exchange been made for Bitcoin instead of a transfer of fiat from bank account to bank account. After checking the gold price:

  1. The gold buyer Opens Samurai Wallet on his phone.
  2. The seller shows his QR code on his phone.
  3. The gold buyer scans the QR code.
  4. Types in an amount of BTC.
  5. Presses send.

Not only does this transfer require a maximum of only two devices (you can pay to a QR Code on a piece of paper as seen below) and not three

devices plus a “Chip and Pin” card, there is no third party involved in the payment of Bitcoin, and its still totally secure by default.

Which one do you think is more efficient? Using Bitcoin, or doing a fiat bank transfer? Bitcoin is quicker, more efficient, more private. It is better than bank accounts by orders of magnitude, and of course, that Bitcoin could be transferred to another address anywhere on Earth, in seconds, once again, without logging in or any other Robinsonesqe nonsense.

Experiences like this make it crystal clear that Bitcoin is the future. Banks have no way of competing with it in any way, from the form of the money to their insanely complex Security Theatrics, to Bitcoin’s global access and extraordinary utility.

100% GAME OVER.

You can’t tip dollars to this QR Code from your bank account
LOL! ↯


“JekyllCoin” the US Government’s Doomed Attempt to Kill Bitcoin.

By Beautyon

Posted August 20, 2017

Jekyll Island Club where the secrete meeting to destroy the dollar took place in 1910. Two years later the Federal Reserve Act was passed.

The Daily Caller, run by Fox News presenter Tucker Carlson, has published an astonishing article claiming that the US Congress is working on legislation to “legitimise” Bitcoin. We always expected the state to attack Bitcoin, but the undemocratic way in which this attack is being formed is apalling and shocking. In the information vacuum, all sorts of conspiracy theories rush to fill in the details. Lets examine a conspiracy theory now.

https://twitter.com/dantwany/status/899281189713969153

Anyone familiar with Bitcoin knows that the word “legitimacy” was widely used when referring to Bitcoin for years as a necessary step to boost acceptance and adoption. This word was dropped for other memes and now it seems it is back. As ususal, the State is twenty steps behind (this is a good thing) but this time, there is a twist to the push for “Bitcoin Legitimacy”. It isn’t a matter of making Bitcoin legitimate this time, it is a push to replace it with something else.

If you know the recent history of money you’ll be familiar with the story of how the Federal Reserve was founded. The Federal Reserve is a private bank tasked with the management of the money of the United States. A secret meeting of cigar smoking fat men was held at a place called Jekyll Island, where the details where thrashed out. What this Daily Caller article is claiming is that there has been a “Jekyll Island 2.0” where soy drinking characters have planned in secret to replace Bitcoin with a totally crippled system stripped of privacy and economic soundness.

You might think that this comparison is totally wrong, and that in the 21st century of Open Source thinking, democracy, Wikileaks and inclusiveness, secret meetings are a thing of the past. If you believe that, you are naĂŻve.

From the article:

The three offices looking at the issue asked not to be identified for this story because of the sensitivity of the issue and the complexity of the solution.

The three “offices” mentioned here are part of the United States Government. They are working on behalf of the people under oath, in a government of and by the people. It is totally unacceptable that legislation that will violate the First Amendment should be drafted in secret without consultation from any stakeholders in society; but this is exactly what they are doing, just as the Jekyll Island meeting was held behind closed doors and in secret.

When they say “sensitivity of the issue” this is not a legal pretext for refusing to draft this legislation in the open and under consultation. There are times where the State must keep secrets, and these circumstances are explicily laid out in law. If this proposed law is a matter of National Security, then they need to say that it is a matter of National Security, and cite the law they are using to keep this secret, otherwise, what they are doing is not correct, is extra legal and profoundly un-American.

Three Members of Congress are working on legislation to protect certain digital currencies from government interference

Only an insane person could characterise this as a Bill to, “Protect Cryptocurrencies from Government Interference”. You have to be a fully indoctrinated member of Orwell’s DoubleThink Newspeak team to characterise this story in those terms.

There are already laws in the USA to protect cryptocurrencies from government interference; The First Amendment of the Constitution.

The “Bitlicense” is a bad idea that must die_Some say that Bitcoin is money. Others say that it is not money. It doesn’t matter. No one should be licensed to use or
_hackernoon.com

Cryptocurrencies are text, and text is protected speech. This is established law, and any new legislation that tries to undermine this will be struck down if the system is working correctly. When we say Bitcoin is a profoundly disrupting tool, we actually mean it. Because it is text and protected speech and it mimics good money perfectly, it sits in a special place between two worlds where, in the USA that has guaranteed rights, it cannot be touched.

This story, if it is even true, is an account of a blatant attempt to subvert The Constitution and to stifle Bitcoin and render it useless. If the bill’s purpose is

to prevent them from being used by those engaged in illegal business practices like drug traffickers and terrorists

it can never ever succeed. That goal is impossible on top of being unreasonable, hysterical, computer illiterate and unrealistic. These people should be honest. The scourge of drug taking and other unpleasant things is not the problem they are addressing. The real problem this legislation addresses is the existence of Bitcoin, which has now been recognised as a real threat to fiat currencies. The IMF has stated this clearly in a recent report, where they talk of, “Dealing with Bitcoin by other measures”, a thinly veiled threat to use violence as a resort to destroy Bitcoin.

Now for the heart of the conspiracy theory. Who would the US Government turn to to create its own version of Bitcoin, “JekyllCoin”? They don’t have the skill to create their own version of Bitcoin, and would have to find developers to create one from scratch, which is impossible, in terms of competent software developers and the prohibitive cost of building of a huge network to support it’s hash requirements and climbing the mountain of first mover advantage Bitcoin has. The best way to do it would be to take the existing Bitcoin network and replace the reference client with a client that had a small change that seemed reasonable, then once Bitcoin Core are denied access to changing the source, change Bitcoin into JekyllCoin.

BTC1 is the is the obvious candidate.

Why BTC1? Once again, developing a bespoke system from scratch is bound to fail. The Canadian Mint Chip is an example and that failed before Bitcoin was as big as it is. The only possible candidate here is BTC1. It has vocal industry support from incumbents and it is not Chinese. Think about who is behind BTC1. Jeff Garzik already owns a Blockchain Surveillance Company that services Interpol and others, so he is “on side”. He has the minimum skills required to fork Bitcoin. Do not be overly shocked by a surprise return to Bitcoin of Mike Hearn, who will join Gavin Andressen and Jeff Garzick on JeckyllCoin as developers. Hearn will eat this dish of vengeance with ice.

Barry Silbert and his “Digital Currency Group” are rallying companies with large numbers of users behind BTC1, and so they will have an off the shelf user base in the millions, running on a version of Bitcoin which is indistinguishable from Bitcoin at this point.

When Congress anoints BTC1 as the official Bitcoin, the price will increase dramatically. Bitcoin will finally be “legitimised”. Banks will offer Bitcoin companies accounts and the ecosystem will burn white hot.


but there is a catch.

What these people are offering is a classic fraudulent “Bait and Switch”

They will offer both legitimacy and a slightly higher capacity at first, and whopping great profit for Bitcoin holders, only later to inject lethal poison into Bitcoin, utterly destroying and wrecking its fundamental proposition.

There will be an increase in the total supply of Bitcoin beyond 21,000,000, Address Blacklists, KYC/AML, reversible transactions and everything else characters like Mike Hearn, half wit economists like Paul Krugman, un-American Police Men like Preet Baharaha and Federal Reserve central bankers think are necessary. Remember also, that the block size increase of BTC1 is just the first of many, making the private operation of a Bitcoin full node impossible, cutting off access to all but the most thoroughly vetted and incumbents from the legacy financial system.

It will be the death of Bitcoin. Using actual Bitcoin would need to be illegal the moment this law is passed. Starting an alt coin with the correct characteristics would need to be made illegal. Even if they were not made illegal, it would be very difficult to replace or even compete with a government anointed JekyllCoin.

Game Over for Bitcoin.

First, there is a new entity that is considering issuing a brand new digital currency that is compliant with anti-money laundering laws unlike any other in circulation.”

There is “A New Entity” what does this mean? If they do not mean BTC1, then they are talking about a new alt-Coin and they have absolutely no hope of succeeding against Bitcoin. The Bitcoin infrastructure is too big, too international, has first mover advantage and can never be stopped. The logical move is to use BTC1 as the Trojan Horse.

CoinCenter and DCG probably advised on this corruption of Bitcoin. Jerry Brito has been pushing this sort of anti-bitcoin nonsense for a long time, appearing before legislators and spreading the disease of FUD and KYC/AML across America, by misinforming everyone who would listen, all paid for by some very misguided and unethical VCs. He also has access to deep state insiders at the infamous Council on Foreign Relations where he has appeared as a guest of Foreign Affairs magazine. BTC1 is a dream come true for these bad people; a Bitcoin that is gelded, tamed, and put under their control.

There is a problem however.

A free and technically superior Bitcoin cannot co-exist with a crippled JekyllCoin; the market will always choose the superior option, especially on a global basis. No one in any country will accept JekyllCoin. This is their one chance to break away from US Dollar hegemony and make a fortune at the same time. Businesses outside the USA have no incentive to root for it either. Any businessman who has had the pleasure of filling out dozens of US government forms to transfer even a tiny amount of money knows what is at stake. Banks globally are rejecting American customers to get away from the US Governments insane regulations. There is no way they will accept JekyllCoin over Bitcoin; in fact, it will only serve to highlight Bitcoin’s superiority and increase its adoption.

Lets go through some important countries and see whether or not they would want to adopt JekyllCoin over Bitcoin.

The Japanese. Answer: “NO”Bitcoin is already huge in Japan, and their exchanges are set for domination. Why should they make themselves subservient to the USA again?

The Russians. Answer : â€œĐœĐ”Ń‚â€Mother Russia is in a long term conflict with the west. Are they really going to accept a subverted cryptocurrency that will dominate them and the entire globe? Do you not think they will at the very least, support real Bitcoin or start their own “RuCoin”? They may not be able beat the USA by themselves, but they can join with every other country on earth to adopt Bitcoin, which is politically neutral. This happened before with the GSM mobile phone standard, and America lost.

The Nigerians. Answer: “A’ah?! NO!”No citizen of any African country should want to be dominated by foreigners ever again. Bitcoin is culturally neutral, and all people living on the African continent should be predisposed to adopting it. Anything else is de facto subservience to the old Colonial Master, and is utterly undignified.

The Chinese. Answer: “LOL”The Chinese already dominate in several areas; Bitcoin mining, software and services, and custom Bitcoin mining hardware, that is exported globally. They are the world leaders in Bitcoin, and are so powerful they can threaten Bitcoin itself. Only a totally idiotic, parochial, ugly-American, myopic Congressman thinks the Chinese are going to accept US domination of Bitcoin because they pass a law. LOL!

Once again, American domination of the global cryptocurrency standard will give back door access to the world’s money and economy in a way that is unprecedented. It will be far worse than the Federal Reserve controlling the form and supply of the world’s reserve currency. The US Government would be able to block the transfer of money to or from anyone in any country. It could even block entire countries from being able to use money both inside and outside of their country. This is a nightmare too terrifying to imagine, and yet it is absolutely achievable with a future version of BTC1.

Big blocks are the least of the problems with BTC1, obviously. KYC/AML is nothing more than a pretext for the creation of a global financial surveillance system that can watch literally every single human on Earth.

Members of Congress are working on legislation that would provide protections to currencies if they meet certain minimum conditions on preventing the currencies from being used by terrorists, drug traffickers, and others engaged in unlawful business practices.

MSM sock puppets sometimes repeat that Bitcoin must be brought “out of the shadows”. Obviously, Bitcoin is not “in the shadows” at all, and it is totally transparent. Furthermore it is not possible to prevent people from using any tool for a bad purpose. If the congressmen believed that what they were planning will be effective, they would pass a law requiring all kitchen knives to be registered. Knives kill more people than rifles in the USA. Why will Congress not ACT?!

There is no way to control Bitcoin once it moves from the wallet of the first purchase; that means that KYC/AML is totally pointless. The only way KYC/AML would make sense is if the entire structure of Bitcoin was changed, so that it was not permissionless. It would also mean all wallet software would need to be compliant. It would mean making sure that JekyllCoin was not interoperable with other Bitcoin variants, as Olaoluwa Osuntokun as shown is doable. It would mean making a private network.

You can see now, why this shabby, scabrous un-American plan is doomed.

They continued that “the law needs to be changed to protect digital currencies from federal government harassment to make sure that a complaint currency can be backed by value, the currency cannot be treated like a security or investment, and that transfers are protected against taxation. The bottom line is that Congress needs to remove all the obstacles to a vibrant digital currency that has voluntarily taken the initiative to keep the bad guys from using it.”

Congress
IS THE OBSTACLE. There is no need for a change in the law; the First Amendment already covers crypto currencies; they are speech. This line sounds like a Mafia threat. “We need to protect you from our own harassment — capish?” You can protect Bitcoin from taxation by issuing a decree that, “We do not tax Bitcoin”. It’s as simple as that. Federal government harassment can be stopped by simply issuing instructions that The Constitution must be followed. The problem is when you have foreigners who come from a different culture at the levers of government, their fundamental and irrevocably held perspective of the role of government is not American; it comes from their home lands. No real American is for any law that effectively nullifies the First Amendment.

When they say, “Can be backed by value” this is meaningless. What Bitcoin is or how it works is not within the gift of government to define. It was created outside of the government, and has nothing to do with them at all. The bottom line is that if the US Government wants Bitcoin to thrive, it needs to get out of the way and stop trying to help. If they don’t, and try to launch JekyllCoin, the rest of the world will be induced to join Bitcoin, as it will be clear that the Americans are trying to control the world with fraudulent “Super Money” a second time. It will be GSM vs CDMA all over again, and America will lose.

In the meantime, this project can be killed before it starts. It does not require you to do anything, in fact all that is required is that you do nothing. Do not run BTC1 or any version of Bitcoin other than Bitcoin Core. No matter what anyone says, no matter what happens. If no one is running their software, their project dies. They can scream all they like, just like the MPAA/RIAA screamed about BitTorrent for years to zero effect. There are too many BitTorrent users to ever take that system down, and if there are enough Bitcoin users, Bitcoin can never ever be stopped. And do not think that this will put you in the cross hairs of the Government. Two courts, one in Florida and the other in New York have both found two men did nothign wrong by exchanging Bitcoin for money, and that Bitcoin is not money, and is therefore not subject to money laundering regulations.

All States world-wide should take the advice we submitted to the British government. If you value your sovereignty, your dignity, peace and prosperity of the citizens of you your nation, you will adopt Bitcoin now, and start taking it in payment of taxes. Legislators in other countries are starting to wake up to this and so should you.

Of course, in this analysis I could be completely wrong.

Even if Garzik, CoinCenter, Silbert and his DCG have absolutely nothing to do with any of this, and it is as much a surprise to them as it is to the Ethical Bitcoin community, the nature of the proposal remains absolutely unchanged. It is pure anti-Bitcoin and should roundly condemned and rejected by all market actors on a global basis. As I mention above there are precedents for such rejections, from the doomed CLIPPER chip, to the ill fated Canadian Mint Chip; the market cannot be forced to accept anything, and the State is not powerful enough to force it. Remember; what they would have to make illegal is the running of a computer programme — just like the ones that run the BitTorrent protocol. And we all know how well trying to ban that turned out.

We knew this was coming. We are still going to win. They have no arguments, no software, the antipathy of the international community and math itself against them. They don’t even get marks for effort, because their thinking is so slipshod and shabby.

Their best way out is to embrace Americanism. This legislation, no matter what it says, should be totally rejected on principle. Secretly drafted legislation and unaccountable public servants are anathema to democracy.

If you like the content and feel so obliged to send some love via BTC donations you can do so at the address below:↮


Liquidity is about market depth, not magic

By Stephen McKeon

Posted August 21, 2017

As I was scrolling through my twitter feed yesterday I saw that Emin GĂŒn Sirer, a thoughtful scholar whom I respect, had retweeted a piece on token liquidity by Preston Byrne. I read it immediately. As it turns out, the post references some of my statements from Traditional Asset Tokenization in a context that might be considered critical. Preston’s blog contains some valuable insights, so this post is a brief response to reconcile the two articles.

As an academic, I welcome critical feedback. Working through divergent views is how we learn. It’s a sign of a healthy ecosystem and exactly what we should be doing. As I detail below, Preston and I are in more agreement than may be obvious. For example, take the last sentence of his post (bold italics are quotes from his article):


if you have the right business case and find the right lawyers to advise you, tokens and securities can mix quite nicely.

Agree.

I was assuming legal securitization as given. I’m a finance professor, it should come as no surprise that I believe people need to comply with security laws. Preston’s post addresses what happens under conditions of willful non-compliance.

There is nothing magic about liquidity. It is a function of market depth, as measured by bid-ask spreads and price impact from trade. As I mentioned in my post, the act of tokenization does not impact liquidity unless it impacts market depth. The interesting thought experiment is to consider how and why tokenization might increase market depth.

Representing a fractional ownership claim on an asset is securitization, a concept that has been around for hundreds of years. The difference with blockchain tokens is divisibility, low cost global transfers of ownership, and an immutable record of the ownership claims. My argument is that these differences will lead to increased depth in the secondary market for the securities because they reduce frictions to trade, no magic required.

A careful reading of my article reveals that I intentionally stayed away from startup liquidity problems. Tokens representing early-stage corporate equity have their own set of complications that I will address in a future post.

“Liquidity becomes available by taking the illiquid asset (bricks and mortar) and pooling it with many others like it so you can get a more easily tradable asset (e.g. a AAA-rated note) which allows a bank in, say, Japan to get exposure to some mortgages in southern Florida. Which makes mortgage loans, as a class, more liquid than they were before, because you can get them off your balance sheet before they mature.”

When one pools a group of assets, say mortgages, and then splits up the claims on the pool into a hierarchy, new securities with different levels of risk and return can be created. This is a totally different animal compared to the idea of securitizing/tokenizing a single asset. In the pooling case, additional liquidity is achieved by tweaking the risk and return profile of the securities. It is the alteration of the risk profile that generates demand and increases the depth of the secondary market.

Pooling will continue occur when more assets are securitized with tokens, but focusing on pooling is missing the point. The big picture in traditional asset tokenization is about relaxing frictions to trade, not pooling and tranching. The liquidity gains I describe in my article are not conditional on changing the risk profile of the assets.

“Where I’m left is that everyone is repeating the “tokens make X easier” mantra ad nauseam but nobody can actually explain why.”

I stated that IRS 1031 exchanges would be easier if the underlying assets were tokenized. Here’s why: 1031 exchanges allow the seller of an investment real estate asset to defer paying capital gains taxes if the proceeds from the sale are invested into a like-kind asset (another real estate asset). If real estate assets were tokenized, the degree of divisibility allows a buyer to tailor the amount of investment to precisely match the proceeds from the sale. A larger and deeper market of real estate asset tokens would reduce search cost for the buyer to find a suitable replacement asset. Further, if real estate tokens can be directly traded for each other, this is even closer to the spirit of a simultaneous exchange of like-kind assets. The notion of direct exchange of assets without translation through a currency is really interesting to me and I’ll surely be writing more on this in the future. However, before we get too carried away, let me state that I’m not a tax attorney and cannot predict how the IRS will treat tokens representing real estate assets. Perhaps they’ll rule that they are not eligible for 1031 exchanges. This is a regulatory issue, which is one of the challenges I mentioned in my original post.

“When we hear people say they want to “tokenize an asset,” most people are talking about avoiding the expense and bother of securitization while achieving the same effect.”

I cannot speak for others, but this is absolutely not what I’m talking about. I wholeheartedly agree that tokenization needs to be done within the context of regulation. That means complying with security laws like Blockchain Capital, not ignoring them like The DAO.

To be clear, traditional asset tokenization is not about cutting corners. Registration is a slow expensive process and cost cutting on registration is not where the gains in liquidity reside. The gains flow from increasing the depth of the secondary market, where liquidity is enhanced by compliance, not hindered by it. There are lots of investors (i.e. institutions) with fiduciary responsibilities that are rightfully wary of unregulated securities. These investors represent a lot of capital and they will add depth to markets. Adhering to regulation is a necessary condition for expanded institutional participation.

In sum, the main takeaway is that Preston and I are talking about different aspects of tokenizing traditional assets. His post is focused on the cost of securitizing at the time of issuance and the importance of conforming to legal regulations. My post is about secondary market liquidity effects when an asset can be traded with reduced frictions. These are not mutually exclusive and both are important.

I commend Preston for drawing a bright red line around the topic of securities regulation and tokens. It is a topic that we’ll be discussing a lot more as time goes on.


Blockchains don’t scale. Not today, at least. But there’s hope.

By Preethi Kasireddy

Posted August 23, 2017

Your browser does not support the audio element.

The first Bitcoin paper was first released in 2008. My excitement about the potential of blockchain technology has been building ever since. Decentralized digital currency, once just a far-fetched goal, is finally making inroads into the mainstream. While that’s exciting on its own merit, I’m personally most excited about the potential for decentralized applications. Financial exchanges, prediction markets, and asset management platforms all carry enormous potential. The trustless systems supporting them are no less intriguing; identity verification systems, smart property, censorship resistant social platforms, and autonomous structures and governance models like DAOs. The most disruptive use cases probably haven’t even been dreamt up yet. But this dream still remains a dream for the foreseeable future — while a few early enthusiasts and entrepreneurs are experimenting with building such applications, there’s still a big missing piece that prevents us from seeing these applications come to fruition_:_ scalability. Blockchains, as it stands today, are limited in their ability to scale. That’s not to say that this will be the case forever, but it’s definitely true today. In fact, I’d argue it’s one of the biggest technological barriers we face with blockchain technology today. It’s quickly become a very active area of research among researchers in the community and cryptocurrency in general.

Why isn’t the blockchain scalable?

Currently, all blockchain consensus protocols (eg. Bitcoin, Ethereum, Ripple, Tendermint) have a challenging limitation: every fully participating node in the network must process every transaction. Recall that blockchains have one inherent critical characteristic — “decentralization” — which means that every single node on the network processes every transaction and maintains a copy of the entire state. While a decentralization consensus mechanism offers some critical benefits, such as fault tolerance, a strong guarantee of security, political neutrality, and authenticity, it comes at the cost of scalability. The number of transactions the blockchain can process can never exceed that of a single node that is participating in the network. In fact, the blockchain actually gets weaker as more nodes are added to its network because of the inter-node latency that logarithmically increases with every additional node. In a traditional database system, the solution to scalability is to add more servers (i.e. compute power) to handle the added transactions. In the decentralized blockchain world where every node needs to process and validate every transaction, it would require us to add more compute to every node for the network to get faster. Having no control over every public node in the network leaves us in a pickle. As a result, all public blockchain consensus protocols that operate in such a decentralized manner make the tradeoff between low transaction throughput and high degree of centralization. In other words, as the size of the blockchain grows, the requirements for storage, bandwidth, and compute power required by fully participating in the network increases. At some point, it becomes unwieldy enough that it’s only feasible for a few nodes to process a block — leading to the risk of centralization. In order to scale, the blockchain protocol must figure out a mechanism to limit the number of participating nodes needed to validate each transaction, without losing the network’s trust that each transaction is valid. It might sound simple in words, but is technologically very difficult. Why?

  1. Since every node is not allowed to validate every transaction, we somehow need nodes to have a statistical and economic means to ensure that other blocks (which they are not personally validating) are secure.
  2. There must be some way to guarantee data availability. In other words, even if a block looks valid from the perspective of a node not directly validating that block, making the data for that block unavailable leads to a situation where no other validator in the network can validate transactions or produce new blocks, and we end up stuck in the current state. (There are several reasons a node might go offline, including malicious attack and power loss.)
  3. Transactions need to be processed by different nodes in parallel in order to achieve scalability. However, transitioning state on the blockchain also has several non-parallelizable (serial) parts, so we’re faced with some restrictions on how we can transition state on the blockchain while balancing both parallelizability and utility.

Gimme the numbers

So what do the scalability numbers actually look like? Let’s take a look. An Ethereum node’s maximum theoretical transaction processing capacity is over 1,000 transactions per second [1]. Unfortunately, this is not the actual throughput due to Ethereum’s “gas limit”, which is currently around 6.7 million gas on average for each block [2].

Source: etherscan.io

Quick “gas” primer in case the measurement is new to you: in Ethereum, gas is a measure of computational effort, and each operation is assigned a fixed amount of gas (for example, getting the balance of an account costs 400 gas, creating a contract costs 32,000 gas, sending a transaction costs 21,000 gas, etc.). Transactions have a gas limit field to specify the maximum amount of gas the sender is willing to buy. Hence, the “gas limit” for each block determines how many transactions will fit in a block based on the gas limit specified by each transaction in the block.

Ethereum’s gas limit is somewhat similar to Bitcoin’s 1 MB limit on the size of each block, with the difference being that Ethereum’s gas limit is dynamically set by miners while Bitcoin’s block size limit is hard-coded into the protocol. This gas limit for Ethereum imposes a soft cap on the network’s computational power per block: with the current 6.7 million gas limit and the current average gas used per standard transaction of approximately 21K, we get approximately 300 standard transactions every block. The current average block time is 20 seconds which equates to roughly 15 transactions per second (300 / 20 = 15) at best [4]. This gets much lower with more complex transactions (e.g. median gas used by smart contract calls is 50K [3], which means roughly ~7 transactions per second).

Combined with the fact that the number of transactions on the Ethereum network is growing at a significant pace, you can see how this would become a problem. Daily transactions increased from approximately 40K to 240K from Q2 2016 to Q2 2017 [4], which represents a 500% year-over-year growth. Moreover, just in the past month it reached a peak of over 440K transactions per day! If we do some back of the envelope calculations, that’s an average of 5 transactions per second.

Uh oh.

Similarly, Bitcoin, despite having a theoretical limit of 4,000 transactions per second, currently has a hard cap of about 7 transactions per second for small transactions and 3 per second for more complex transactions.

Note that these limitations don’t exist for private blockchains. Private blockchains can, in fact, achieve over 1,000 transactions per second on Ethereum or Bitcoin. Why? Because if you’re running a private blockchain, you have the ability to ensure that every node on the network is a high-quality computer with high bandwidth internet connection. Scaling the blockchain currently would require us to add more compute to every node for the network to get faster. Since privately managed networks have control over every node in the network, they can do this. Moreover, since you’re on a private network, you can handle some actions that would otherwise happen on the blockchain off the blockchain, such as making sure that each node that is participating is running a real node.

I’ve been architecting and implementing a new protocol on Ethereum, and have first-handly been confronted with future-proofing the issue of scalability. Personally, I’ve been fascinated by the amount of research, discussion and most importantly, experimentation happening to solve this problem. In the rest of the post, I’ll describe some of the proposed solutions being discussed in the community to solve scalability. Each comes with unique strengths and tradeoffs.

The truth of the matter is that unfortunately, none of the solutions provide the silver bullet answer to scalability. In reality, each one of these solutions will help improve scalability incrementally. Combined together, there’s a promising outlook for the future of blockchain scalability.

Please note that the goal of this post is not to explore all the technical intricacies or to debate the merits of each proposed solution. Instead, my goal is to give you a 10,000 foot overview of some of the proposed solutions that I am aware of. If readers are interested, I can dive into some of the specific solutions in more depth in later posts. This post also assumes that you have a basic understanding of how the blockchain works. (If not, you can check out my last post “Bitcoin, Ethereum, Blockchain, Tokens, ICOs: Why should anyone care?” for a refresher.)

Let’s dig in.

Solutions

Scaling the blockchain is a known challenge and has been an active area of research for several years. Specifically, if you’ve been following the multi-year debacle in the Bitcoin community, you may have heard of two Bitcoin-specific scaling solutions known as SegWit and the 2 megabyte (MB) block size increase.

Both of these solutions aim to solve the Bitcoin-specific issue where the Bitcoin-blockchain has a built-in hard limit of 1 megabyte (MB) per block, which caps the number of transactions that can be added to a block. As a result, Bitcoin has been facing delays (sometimes hours and even days) in processing and confirming transactions for a while now. Similarly, as we saw in the previous section, Ethereum also faces limitations in its ability to scale.

Until we figure out how to scale the blockchain, we’re limited to how fast and wide the use cases can actually grow. So let’s take a look at some solutions on the table.

Proposed solution #1: SegWit (Bitcoin-only)

Every Bitcoin transaction contains:

Input

  • Sender’s previous transaction details
  • Sender’s unique private key (i.e. scriptSig) which verifies that the sender has the right amount (based on their previous transactions) to make the transaction

Output

  • Amount to send
  • Recipient’s public address (i.e. ScriptPubKey)

Out of these elements, the digital signature (scriptSig) is the largest in terms of size, accounting for ~60–70% of the transaction. Still, signatures are only needed at validation time.

Segregated witness (also commonly known as Segwit) is solution to separate (i.e. “segregate” ) transaction signatures (i.e. “witnesses”) from the rest of the transaction data. The signature is stripped off from within the input and moved to a structure towards the end of a transaction.

Moreover, with SegWit, the witnesses are moved to a new “witness” field in the transaction data, which allows for us to change the way block sizes are calculated. The block size limit is no longer measured in bytes. Instead, blocks and transactions are given a new metric called “weight” that correspond to the demand they place on node resources. Specifically, each byte of a segregated witness is given a weight of 1, each other byte in a block is given a weight of 4, and the maximum allowed weight of a block is 4 million, which allows a block containing SegWit transactions to hold more data than allowed by the current maximum block size. This would effectively increase the limit from 1 MB limit to a little under 4 MB, giving us a ~70% increase in transactions.

SegWit also solves other issues besides scalability, such as transaction malleability and increased security (which I won’t go into here since it’s not related to scalability.)

Proposed solution #2: 2 MB Block size (Bitcoin-only)

While one side of the Bitcoin community (the users) strongly support SegWit, the other side of the community (the miners) prefers a hard fork that would change the 1 MB block size limit to 2 MB (Keep in mind that the 1 MB limit cannot be modified without a hard fork). The basic idea is simple: by increasing the block size, it would allow for more transactions to fit in each block, allowing the network to handle more transactions per second.

Plans of this block size increase have long been a subject of heated debate in the Bitcoin community, and have gained increasing attention since the beginning of 2015, when the size of blocks started to approach the current hard limit of 1 MB.

Proposed solution #3: Off-chain state channels

State channels are essentially a mechanism by which blockchain interactions that could and would normally occur on the blockchain instead get conducted off of the blockchain. This is done in a cryptographically secure way without increasing the risk of any participant, while providing significant improvements in cost and speed. I personally believe state channels will be a critical part of scaling blockchain technologies to support higher levels of use. A state channel works as follows:

  1. Part of the blockchain state is locked via multi-signature or some sort of smart contract, where the only way to update it is if a specific set of participants agree completely.
  2. Participants make updates amongst themselves by constructing and cryptographically signing transactions without submitting it to the blockchain. Each new update overrides previous updates.
  3. At some later point, participants submit the state back to the blockchain, which closes the state channel and unlocks the state again.

Steps 1 and 3 involve blockchain operations which are published to the network, pay fees and wait for confirmations. However, Step 2 does not involve the blockchain at all. It can contain an unlimited number of updates and can remain open indefinitely. In this sense, the blockchain is used purely as a settlement layer to process the final transaction of a series of interactions for the final settlement, which helps lifts the burden from the underlying blockchain.

At any point during the process, any participant can send a transaction into the contract to close the channel and start a settlement procedure. This starts a time limit within which participants can submit transactions, and the transaction with the highest sequence number is processed. If one of the participants leaves or tries to cheat, another one can at any time publish the latest transaction to the blockchain to finalize the state, assuming all the participants completely agree on the state.

Not only is transactional capacity increased with state channels, but they also provide two other very important benefits: increased speed and lower fees. Because a majority of the transactions are happening off-chain, payments can be handled instantaneously since updates between two parties that happen off-blockchain don’t require the extra time to be processed and verified by the network. Secondly, payments also incur lower fees because only a small number of on-chain transactions are needed to secure the settlement state channels, while a majority of the transactions are happening off-chain without fees.

There are several different implementations of this. For example, Lightning Network is a decentralized network that uses state channels via smart contracts to enable instant and scalable payments across a network of participants. Initially, Lightning Network was created for Bitcoin, but it seems now that they allow for transactions across blockchains as well.

Raiden Network is the Ethereum analogy of the Lightning network. Raiden Network also leverages off-chain state networks to extend Ethereum with scalable and instant transactions.

Proposed solution #4: Sharding

Sharding in the blockchain world is similar to database sharding in traditional software systems. With traditional databases, a shard is a horizontal partition of the data in a database, where each shard is stored on a separate database server instance. This helps spread the load across different servers.

Similarly, with blockchain sharding, the overall state of the blockchain is separated into different shards, and each part of the state would be stored by different nodes in the network.

A single shard

Top level diagram of blockchain sharding [6]

Transactions that occur on the network are directed to different nodes depending on which shards they affect. Each shard only processes a small part of the state and does so in parallel. In order to communicate between shards, there needs to be some message-passing mechanism.

There are various ways to implement message-passing. In Ethereum’s case, the approach they are taking is a “receipt” paradigm: when a transaction within a shard executes, it can change the state of its own local shard, while also generating “receipts”, which are stored in some sort of distributed shared memory that can later be viewed (but not modified) by other shards.

Ethereum’s receipt paradigm [1]

Ethereum’s receipt paradigm [6]

Overall, sharding the blockchain requires us to create a network where every node only processes a small portion of all transactions, while still maintaining high security
 A difficult challenge to say the least.

Why?

Well, for one, the blockchain protocol assumes that all nodes in the network don’t trust each other. Still, the transactions need to agree on a common state despite being processed on different computers. Since each node does not trust one other, it is not enough for a node processing transactions on shard A to simply say to the nodes processing transactions on shard B that a transaction occurred; rather, it would need to prove it to them somehow.

Additionally, since the goal of sharding is to not have every node validating every transaction, we need to figure out a mechanism that determines which nodes validate which shard in a secure way, without creating opportunities for an attacker who might have a lot of power in the system to disrupt the network.

Another reason it’s difficult to implement sharding is because a transaction executed on the blockchain can depend on any part of the previous state in the blockchain, which makes it challenging to do things in parallel. Moreover, with parallelization, you now need a fool proof way to mitigate with race conditions and the like.

There’s a lot more technical goodies to how sharding will be implemented in Ethereum — in particular, how to use “cryptoeconomic incentives” to drive actors in a system to not cheat (in this case, ensuring that nodes are passing on valid information to other nodes) — which I hope to explore in a future post.

Proposed solution #5: Plasma

Plasma was very recently introduced and is among the more promising proposed solutions to scalable computation on the blockchain.

Plasma is essentially a series of contracts that run on top of a root blockchain (i.e. the main Ethereum blockchain). The root blockchain enforces the validity of the state in the Plasma chains using something called “fraud proofs”. (Note: Fraud proofs are a mechanism by which nodes can determine if a block is invalid using mathematical proofs).

Source: Plasma Whitepaper

The blockchains are composed into a tree hierarchy, and each branch is treated as a blockchain that has its own blockchain history and computations that are map-reducable. We call the child chains “Plasma blockchains”, each of which are a chain within a blockchain.

Source: Plasma Whitepaper

The Plasma blockchain does not disclose the contents of the blockchain on the root chain (e.g. Ethereum). Instead, only the blockheader hashes are submitted on the root chain, which is enough to determine validity of the block. If there is proof of fraud submitted on the root chain, then the block is rolled back and the block creator is penalized. In other words, we only submit data to root chain in Byzantine conditions.

As a result, the root blockchain processes only a tiny amount of commitments from child blockchains, which in turn decreases the amount of data passed onto the root blockchain and allows for a much larger number of computations.

Source: Plasma Whitepaper

In addition, data is only propagated to those who wish to validate a particular state. This makes contract executions more scalable by eliminating the need for every node to watch every chain. Instead, they only watch the ones they are economically impacted by in order to enforce correct behavior and penalize fraud. Fraud proofs allows any party to enforce invalid blocks and ensure that all state transitions are validated.

Additionally, if there is an attack on a particular chain, participants can rapidly and cheaply do a mass-exit from the corrupt child chain.

Source: Plasma Whitepaper

Source: Plasma Whitepaper

Plasma might seem similar to state channels implementations (e.g. Lightning Network) that handle transactions off chain. The main difference between state channels and Plasma is that with Plasma, not all participants need to be online to update state. Moreover, the participants do not need to submit data to the root blockchain in order to participate and confirm transactions.

The neat part about Plasma is that state channel type solutions like Lightning Network could be the main interface layer for rapid financial payments/contracts on top of Plasma, while Plasma maintains updates to the state with minimal root chain state commitments.

Source: Plasma Whitepaper

There’s a lot of intricate details to this solution that I hope to delve into a future post.

Proposed solution #6: Off-chain computations (e.g. TrueBit)

TrueBit is an example of a solution that uses off-chain computations to enable scalable transactions among Ethereum smart contracts. Essentially, just like state channels, TrueBit uses a layer outside the blockchain to do the heavy lifting. In other words, its a system that verifiably executes computations off-chain that would be otherwise prohibitively expensive to execute on-chain. It works like this:

Instead of every node participating, specific participants in the network, called “Solvers,” perform the computations made by smart contracts and submit a solution to the problem, along with a deposit. If the Solver is correct, then the solver is rewarded and the deposit returned. Otherwise, if the Solver cheated, the deposit is forfeited and any dispute is resolved on the blockchain using the “Verification Game”.

The Verification Games goes like this: You have a set of participants in the network called “Verifiers” who check the Solvers’ work off the blockchain. If no Verifier signals an error, then the system accepts the solution. If a Verifier does dispute the correctness of the Solver’s solution, the game proceeds in a series of rounds to settle the dispute on the blockchain, where “Judges” in the network with limited computational power adjudicate all disputes. The system is built to ensure that the work done by the Judges on the blockchain is small compared to the work required to perform the actual task off the blockchain.

At the end of this game, if the Solver was in fact cheating, it will be discovered and punished. If not, then the Challenger will pay for the resources consumed by the false alarm.

A very rough diagram of off-chain computations as proposed by TrueBit

Lastly, in order to convince Verifiers that bugs actually exist and that it’s worth their effort to try to find those bugs, TrueBit does something interesting where it occasionally forces Solvers to submit incorrect solutions, which reverses the normal system incentives: the Solver gets paid for submitting an incorrect solution and penalized for submitting a correct one. This ensures there’s always a reward in the system for Verifiers who are validating transactions.

In summary, the protocol allows anyone to post a computational task, and anyone else to receive a reward for completing it, while the system’s incentive structure guarantees the correctness of returned solutions. And by moving the computations and verification process off the Ethereum blockchain into a separate protocol, it can scale to large numbers of computations without being constrained by Ethereum’s gas limit.

Other proposed solutions to blockchain scalability.

There are a few other proposals floating around the crypto community that I find interesting. While the solutions are not directly aimed at solving scalability, they help indirectly address some scalability problems more easily.

Proof of stake

Similar to Proof-of-work, Proof-of-Stake is a consensus mechanism which underpins security of the blockchain by preventing doublespend.

In traditional Proof-of-Work based blockchains, miners maintain the integrity of the blockchain data by racing to solve computation-intensive, Proof-of-work mathematical puzzles in exchange for rewards. In this regard, they help validate transactions with their CPU power, and the more CPU power you have the proportionately larger your ability to influence the network is. In Proof-of-Stake, stakeholders vote with their “dollars” (in Ethereum’s case, ether) instead of compute power.

How does this work exactly?

The blockchain keeps track of certain validating nodes, called “validators”, who must place a security deposit (which is referred to as “bonding”) in order to take part in validating the blocks. If a validator produces anything that the protocol considers “invalid” in a crypto-graphically provable manner, their deposit AND the privilege of participating in the consensus process is forfeited. If they bet correctly, they earn their deposit back along with transaction fees.

Effectively, the validators make money by betting with the eventual consensus and lose money by betting against the consensus. An analogy can be made to Proof-of-work where each miner is betting with their hash power on which block will be accepted. If they bet wrong in order to cheat the system, then any block they produce will be orphaned, causing them to lose money.

There are several different kinds of Proof-of-stake consensus algorithms as well as different mechanisms for assigning rewards to validators, which I won’t go into in this post.

How does Proof-of-Stake help scalability?

One example is with sharding. Sharding with Proof-of-work is tricky to do securely. Recall that with sharding, we split up the validation responsibility among many nodes so that every node doesn’t have to process everything. However, Proof-of-work is implemented to be completely anonymous, which poses a problem because even if a single shard is secured by only a small portion of a miners hashpower, an attacker can direct all of their hashpower toward attacking this shard and disrupt the network. For example, let’s say we have two shards, A and B. A has 90% of the hashpower and B has 10%. A can attack B with only 5.1% of the total hashpower (by virtue of the majority 51% attack).

This changes with Ethereum’s current Proof-of-Stake proposal because it is designed such that validators have known identities (i.e. Ethereum addresses). Knowing their identities allows us to solve this type of targeted attack by randomly choosing a set of nodes from the entire set of validators to process any given set of transactions on a shard, which makes it impossible for an attacker to specifically target any particular shard.

Another reason Proof-of-stake helps scalability (specifically for Ethereum) is because unlike Proof-of-work which issues new tokens for miners who validate blocks, in Proof-of-Stake, validators will likely be earning only transaction fees. As a result, they have an incentive to increase the block “gas limit” (because it earns them more fee while also fitting more transactions in each block), if their validation server can handle the load. The caveat is that validators will only raise gas limit to a point that is tolerable by the other validators, because otherwise they get reduced returns from causing other, slower validators to fall out of sync.

Blockchain rent

Another Ethereum-specific solution is “Blockchain rent” [5]. Blockchain rent is a solution that aims to reduce the amount of data that is stored on the network in order to help speed up transaction times. With Ethereum, users pay for computational steps, memory, transaction logs, and permanent storage. While most of these are resources are paid for in a properly incentivized manner, the claim here is that storage is not.

In the current system, users only pay for bytes of storage. However, in reality, we can make the argument that storage is different from the other resources because it is stored forever permanently in the blocks. Instead, blockchain rent proposes to set the cost of storage to be bytes x time. This way, there’s an incentive built into the protocol to keep the network lighter and reduce transaction times.

Decentralized storage

Another solution for keeping the network lighter is using a decentralized storage service such as Swarm. Swarm is a peer-to-peer file sharing protocol for Ethereum that lets you store application code and data off the main blockchain in swarm nodes, which are connected to Ethereum blockchain, and later exchange this data on the blockchain .The basic premise here is that instead of nodes storing everything on the blockchain, they only store data that is more frequently requested locally and leave other data on the “cloud” via Swarm.

A very rough diagram of decentralized storage using Swarm

There’s more, but for the sake of brevity (this post is getting quite long!), I’ll leave those out for now :)

Conclusion

This topic is monstrously complex, but I hope this post was useful in giving you a big-picture idea of why scalability matters in blockchain, and how it might be solved.

This is not be a comprehensive list of by any means, and I’ll be following up on this topic as research progresses. I personally doubt that there’ll be a single silver bullet answer to scalability
 but I believe some combination of approaches will eventually solve the issue and allow blockchain applications to leap forward.

As always, don’t hesitate to correct any mistakes I’ve made, or start a (healthy) discussion in the comments. Happy blockchaining! ;)

References: [1] http://www.r3cev.com/blog/2016/6/2/ethereum-platform-review [2] https://etherscan.io/chart/gaslimit [3] http://ethgasstation.info/ [4] https://etherscan.io/chart/tx [5] https://github.com/ethereum/EIPs/issues/35

[6] https://docs.google.com/presentation/d/1CjD0W4l4-CwHKUvfF5Vlps76fKLEC6pIwu1a_kC_YRQ/edit#slide=id.gd284b9333_0_6


Funding the Evolution of Blockchains

By Fred Ehrsam

Posted August 24, 2017

Blockchains are digital organisms. As organisms evolve though changes in their DNA, blockchain protocols evolve through changes in their code. And like biological organisms, the most adaptive blockchains will be the ones that survive and thrive.

So what makes for a strong evolutionary process in a blockchain? Forking is an important mechanism that is becoming more common. Forks can speed evolution by allowing many different approaches to be tried in parallel. However, I feel there is another which is barely talked about: the economic incentives to contribute to a blockchain’s core protocols. These incentives are lacking in almost every major blockchain today and are an opportunity to supercharge their development.

The lack of incentives to work on core protocols is reflected in the large number of people working on Etheruem tokens vs. the small number working on Ethereum itself. Launching a new token has made many millionaires in the last 8 months, whether on paper or liquid. Meanwhile, if you contribute to the core Ethereum codebase at best you 1) own a bunch of ETH personally and the price of them goes up a bit or 2) need to join the Ethereum Foundation and get paid some amount that wouldn’t match the economics of a successful token launch. As a result, Ethereum is starting to suffer from a tragedy of the commons problem: while lots of people own ETH and would benefit from Ethereum improving, the economic reward for any single individual improving it is low.

So it’s not surprising these massively valuable blockchains don’t have many people working on them. Despite being worth over $30bn and $65bn, there are only 15 meaningful contributors to Ethereum and Bitcoin respectively, and the rate of contribution isn’t going up much with their rise in popularity.

Commit history of Ethereum’s main implementation

Commit history of Bitcoin’s main implementation

This is a shame. Improvements to these protocols would create massive amounts of value. For example, let’s say someone or a group of people implemented an Ethereum scaling solution like sharding or Plasma. Each of these improvements would likely increase the value of Ethereum by over 10%, creating roughly $3 billion in value at current Ether prices.

So how do we incent people to work on the common good of the core protocols?

Private funding was one of the first methods used when MIT funded Bitcoin core developers Gavin Andresen, Wladimir van der Laan, and Cory Fields in 2015. Some projects like Blockstack have funds of private individuals and VCs to invest in projects built on top of the protocol, but this is different because it is not focused on improving the core protocol directly.

Private funding can be a good first step because it is fast, decisive, and lightweight. However, the economics probably don’t work at some point. If a protocol upgrade like sharding in Ethereum could create $3bn in value, private funding is already unable to scale to be able to offer anything close to the value that could be created.

Public crowdfundinghasn’t been tried much in the blockchain space or nothing has worked enough to come to mind. A theoretical example of this would be the Ethereum Foundation announcing an open crowdfund for a feature bounty.

Public crowdfunding still suffers from a tragedy of the commons problem. Everyone will want the benefit of the crowdfunded efforts but is incentivized to sit on the sidelines and hope others chip in.

Inflation fundingis where things get interesting. It allows economic rewards that are otherwise unthinkable. Remember, if Ether holders believed an upgrade (ex: sharding) would make the price go up by >10%, they’d be happy to pay close to 10% of their tokens for it. That means Ethereum could crowdfund a $3bn feature bounty by inflating the number of ETH by 10% and pay the newly created tokens to the creator(s) of the upgrade. This is somewhat analogous to taxes: everyone in the community chips in to fund common infrastructure (ex: roads) which no one would build alone.

Funding protocol developments through inflation would also allow anyone in the world to contribute more easily. Not everyone wants to be employed by a foundation or reveal their identity: some of the largest advances in cryptocurrency likeBitcoin****itself**and**Mimblewimble**were anonymously airdropped.**

Finally, the funds in token sales set aside for future protocol development will eventually run out, and this feels like a good solution to that eventuality.

An example of how this would work: a developer submits a pull request to Ethereum with a working implementation of sharding. The community discusses and tests it. There is an on-chain vote of Ether holders to 1) determine if the upgrade should be merged and 2) if so, what the size of the bounty should be. The pull request increases the number of ETH outstanding and sends the new tokens to an address the developer includes. This would require a hard fork the first time, but may not in the future. The size of the bounty ends up being fair because Ether holders want to incentivize developers to keep submitting improvements like this in the future.

I find Tezos interesting because it proposes a version of this concept. Here’s an excerpt from their position paper:

“Funding Innovation”, from the Tezos position paper

Open feature bounties are a powerful way of accelerating change. The self-driving car revolution was kicked off by The DARPA Grand Challenge to make an autonomous car traverse 132mi of a desert. It offered a $2m feature bounty and drew over 40 teams from different universities and companies. Imagine how much competition there would be for multi-hundred million or billion dollar feature bounties. And the potential size of the bounties will grow as the value of the network grows.

A $2m feature bounty created this.

A protocol which provides strong incentives for people to improve it is likely to evolve faster than one that does not. So blockchains which fund innovation through token inflation would seem to have a superior evolutionary algorithm. And over the long run, rate of change is often more important than starting point.

There are some counterarguments. Contributors value things beyond money: the intellectual pursuit, the status and camaraderie it brings within their community, and the mission of a project. But I’d argue proper economic incentives can only add to this list and are also necessary for some people to be able to focus 100% of their time on a project. Also, as The Mythical Man Month**suggests, more people working on software doesn’t necessarily mean it will go faster or turn out better. However, adding more people to software projects usually fails when its components can’t be divided up, and there are a sufficient number of different scaling paths at this point where each can be pursued relatively independently. Finally, approving upgrades and bounties requires greater community coordination. Yet, looking at different attempts to upgrade protocols, it seems on-chain voting on upgrades is something that would reduce complexity, not add it.

So, perhaps the highest leverage thing protocol designers can do is think about how to engineer the evolutionary characteristics of their blockchains — specifically, the economic incentives for anyone to come along and improve them. The best engineered organisms can outpace others, even if they start smaller or later.

This can be the biggest step function change in the rate of innovation in the blockchain space if implemented well. By harnessing their decentralized nature they can evolve faster than a centralized organization ever could.

Thanks toDan Romero,Arthur Breitman,Brian Armstrong,Joseph Poon, andAlbert Wengerfor conversations which influenced this post.


Categories:

Updated: