15 ms·
Blockchain Demo [video]
- mthoms 10y agoThis is extraordinarily well done and begs to be shared widely. Once blockchain tech is understood by the masses, the sky (moon?) is truly the limit. As this video demonstrates, it's not actually that complicated. It could be made better (perhaps) by clearly establishing at the begining what problem the blockchain attempts to solve. Otherwise, this is a phenominal "blockchain for idiots" introduction that even your grandmother would understand. That's not easy.
- eecks 10y agoTwo things stood out for me: How is a signature picked? (he says four 0s at the start). He also says Bob can't give Alice 4 dollars out of thin air right after giving Anders 100 dollars out of thin air.
- POiNTx 10y agoThis is my understanding of it. How is a signature picked: This is arbitrary but should be a fixed sequence that you define before hand. It could start with 'abcd' as long as you decide on that sequence. In the example (and for bitcoin also) it is decided that the hashes should start with a specific number of zero's. He also says Bob can't give Alice 4 dollars out of thin air right after giving Anders 100 dollars out of thin air: Anders gets 100 dollars out of thin air because he mined (calculated the hash with the specific starting sequence). This is the reward Anders gets. Looking for a specific hash such as a hash starting with a certain number of 0's is very computational intensive work. That's why he gets the reward. Hashing is fast for a computer to calculate one way (go from a piece of data -> a hash) but very difficult and as such slow for a computer to calculate it in reverse (go from a hash to the original piece of data for which the hash was generated).
- Taek 10y agoThese come down to the specific rules of the Bitcoin blockchain. Today in Bitcoin, if you mine a block, you get 12.5 bitcoins out of thin air. The network allows you to have this money as a reward for finding the block. That is the only way to get money out of thin air. And because blocks are hard to create, money is hard to create. All other money comes from people sending it to eachother. For the signature question, we need to differentiate between two types of signatures. The first is the block signature, which is defined by having a bunch of leading zeroes. The second is an ECDSA signature, which is your more traditional cryptographic signature with a public key and a private key. When coins are mined out of nowhere, they get assigned to a public key. I'm oversimplifying a little bit, but this is sufficient to understand. To spend coins from that public key, you need to sign a transaction saying something like "I send X coins to person A". This message is signed with the secret key that corresponds to the public key that owns the coins. The really important part about the blockchain is that it prevents you from spending the same coins twice. So, if you only have 12.5 bitcoins, you can't sent 12.5 to Alice and then send the same 12.5 to Bob. You can create signed messages that claim both. Without a blockchain, it's impossible to tell which one is valid, because it's impossible to know which one came first. But that's the magic of the blockchain. It's a history of transactions. If you try to spend the same money twice in the blockchain, we can very easily see that you've spend it twice. We also know which one is the valid original one, because it will be first in the blockchain. So we know to accept the transaction that's first in the blockchain, and to ignore the second one. (note, in Bitcoin, it's actually illegal to have two conflicting transactions in the same blockchain. The second transaction will never be included into a block at all). And, as described early in the video, this history is very hard to re-write. If you decide one day later in Bitcoin that you want to actually undo your spend to Bob and instead spend that money back to yourself, you will have to outcompete all of the mining that happened over the past 24 hours to re-write the blockchain. Given that 'all of the mining' is hundreds of millions of dollars of hardware working non-stop, you will not be able to re-write the blockchain.
- samlewis 10y agoSo, all the miners race to mine the block but only the winner gets the 12.5 btc reward? Does that mean if you're a Joe Bloggs Bitcoin enthusiast, you'll never be able to get any reward if you only ever mine on your low key laptop setup?
- jacobwg 10y agoYes, and that's why there are mining pools, where Joe Bloggs connects his computer to a pool of other similarly underpowered computers to perform the complex calculations required to mine a block in a distributed fashion. Then when a block is mined, the pool owner acquires the 12.5 btc reward and distributes it to all the pool participants based on how much computation power/time each participant contributed to the overall pool, keeping a small bit for themselves for the overhead of managing the pool. Obviously you have to trust your pool operator. Also at this point in the BTC world, the difficulty has become so high that Joe Bloggs will never acquire any meaningful amount of BTC, even in a pool. There are specialized arrays of GPUs that can perform calculations at rates much higher than any standard PC or laptop. The same principles apply to any other bitcoin-like blockchain currency though.
- nileshtrivedi 10y agoNot unlike setting up a gold mine to "create" money.
- Taek 10y agoLaptops are useless for mining, yes. You'd need to spend something like $1000 on electricity for every $1 of Bitcoins earned on a laptop. Not to mention machine wear and failure. If you want to mine Bitcoins, you need a bunch of advantages. Special hardware, cheap space, low electricity cost, bulk manufacturing deals. Otherwise you probably aren't going to be breaking even, let alone profiting.
- TD-Linux 10y agoMining is not a race - in fact, the mining being progress-free is a really important part of PoW. If you have a low power setup, you have a very small chance of winning the reward, but it's proportional to your power over the total network power. There's unfortunately some things that make it a bit of a race - network latency and block verification time. That's why there's so much work spent on shrinking these (the FIBRE network, libsecp256k1)
- grey-area 10y agoThis is extraordinarily well done and begs to be shared widely. Agreed, this is a wonderful demonstration of the interesting principles behind the idea of a blockchain (or a distributed merkle tree). Definitely worth playing with for anyone interested in this, and the video is a nice overview as well. As far as the moon being the limit, unfortunately we still inhabit the corrupted sublunary sphere, and blockchain technology (at least as implemented in Bitcoin) has some limitations which make it unsuitable as a currency or log of transactions between untrusted parties. On your last point, I'm not really sure people know what problems blockchain solves, because there are no problems which directly map to this solution, and there are plenty of problems it half-solves. Problems it purports to solve but fails at: Anonymity - good enough to protect criminals, not good enough to protect citizens against a state Trustless consensus - 51% attack makes this unreliable, esp. with semi-anonymous actors Trustless transactions - POW as in bitcoin makes this impractical due to energy use and delays People want centralised trust in many cases for verified identity, transaction rollback, legal constraints on transactions, so in an important sense it is solving the wrong problems (pseudo-anonymity, fungible cash, sort-of trustless consensus) while leaving important problems untouched. Still, the video and website are an excellent demonstration of the ideas behind a blockchain or Bitcoin.
- colordrops 10y agoI'm not sure what you mean in your explanation that it fails at trustless transactions. Also, you are ignoring the main driving force for the development of bitcoin, that being the removal of the middleman/governments from the transaction.
- grey-area 10y agoBitcoin has failed to keep govs out of transactions between individuals because governments impose their will by force.
- colordrops 10y agoIf you are not trying to exchange currency, they can't really impose anything by force. You are taking about a failure of the exchange system, not bitcoin.
- JohnKacz 10y ago> It could be made better (perhaps) by clearly establishing at the begining what problem the blockchain attempts to solve. What would you say that is? Real question.
- bshanks 10y agoThe purpose of the blockchain is to be a shared append-only data structure. There are a number of nodes who have copies of what is supposed to be exactly the same data (but see below). The nodes are all constantly telling each other what they believe to be the most up-to-date version of the data. The purpose of the blockchain is to support a consensus-finding algorithm by which the nodes may start out disagreeing on the contents of the most recent few blocks in the log, but eventually converge to a consensus, at least for relatively old blocks. This convergence occurs even if some of the nodes are evil or faulty or out-of-touch, provided that these bad nodes control less than 50% of the total computing power of all of the nodes.
- nileshtrivedi 10y agoIt doesn't explain either how the money is created in the first place or how actual resolution happens when coming across a block which differs from others' copies. Do I need to ping all the peers?
- CydeWeys 10y agoUnfortunately it didn't explain this correctly, and this is the most important part of Bitcoin, as well as its biggest innovation. The longest chain always wins. And since valid block hashes are very hard to find, the longest chain is the one that has the most mining effort behind it. This is why mining is essential to securing the blockchain. In order to make a fake chain of any appreciable length, you would need to have >50% of the total hashing power of the blockchain. And if you have that much power, then whatever you say is the right chain is the right chain, because you can mine more blocks than anyone else and so yours is right by virtue of being longest. The video incorrectly implies that there is some sort of voting mechanism going on wherein the version of the chain with the most copies is correct, but this is incorrect, and would be horribly broken. The P2P network exists only to communicate transactions and blocks; it does not factor in to which version of a chain is considered valid (the longest one always wins). If the P2P network were used for this, then it would be trivial to take over Bitcoin using a Sybil attack, by e.g. hiring a botnet to run millions of fake nodes with your preferred version of the chain. With mining and validity determination by longest length, that doesn't even put a dent in Bitcoin, as even a million general purpose commodity computers can't get anywhere close to matching a small percentage of the overall hashing power of the miners.
- Natanael_L 10y agoActually length doesn't decide, but rather total accumulated hashing power. This is because Bitcoin changes the difficulty per block over time to keep the time between blocks close to 10 minutes. This means that two chains can be equally long but have different amounts of accumulated difficulty. It even means that long blockchains can have low amounts of accumulated difficulty. But for short periods of time, less than ~2 weeks as it is for Bitcoin, the difficulty will not yet have changed and thus length = total difficulty for SHORT forks.
- SkyMarshal 10y ago>Once blockchain tech is understood by the masses, the sky (moon?) is truly the limit. Not really. Security via economic incentives is still shaky. Bitcoin community is split, and Ethereum is still working out the kinks and has a high-risk move to PoS coming up soon. The tech is not remotely mature yet, and blockchain being better understood by the masses will have zero effect on that.
- _coldfire 10y ago>Bitcoin community is split Yet not even the advent of quantum computing with todays algorithms could undo a few hours of the Bitcoin blockchain. A bit too much credence is given to people arguing on the internet rather than the raw state of things. The sheer computing power of bitcoin is a marvel of the modern world. For all its problems I would say it has a long way to go yet unless the world solves the reality of a borderless economy.
- SkyMarshal 10y agoTrue, Bitcoin's historical ledger is pretty durable. The community split is more about its future. And I'm not referring to people arguing on internet forums, but about the split between Bitcoin's core developers and its biggest miner. One day such discord may actually be a good thing, but right now it is hindering basic fixes from being implemented.
- martinkallstrom 10y agoVery nice explanation. Not oversimplifying and not too detailed. Could anyone care to explain smart contracts in the same balanced fashion? I always struggle to convey my understanding.
- antocv 10y agoIn bitcoin you can have a transaction which requires 2 or more people to sign it before the transaction can happen/is considered valid at all. Smart contracts, is specifying conditions which can be checked in the blockchain, like existence of certain data you expect to be posted in the OP_RETURN (comment-like field) by other transactions. When your conditions are met the "smart-contract" makes/signs and publishes its own transaction, and other contracts can depend on this output of your contract.
- DennisP 10y agoIn Ethereum and similar systems, a smart contract is a script which can hold funds and various other data. It has functions that can be called by users, which can update data and move money around. The script can also act like a user and call other scripts.
- baby 10y agoFor Ethereum, IIRC, inside a transaction you can host a program (contract). A peer who runs your program will use your transaction money to run it (it's called gas) and display the result of the program as part of the new receiving transaction. Everyone who verifies the contract needs to run the program as well, for free, that's why you can't have big programs. You can then send new transactions to continue using the program, to interact with it, etc... If you don't send enough gas, they can't run the program though. (Each functions in a program cost some amount of gas to run.)
- starik36 10y agoPretty cool. This is the first time I looked at the blockchain and his explanation was immediately understandable. Having said that, he mentioned that everyone has a copy of the blockchain. So, is that really true? Wouldn't "everyone" be overwhelmed by the number of blocks? Is there a specific example where blockchain is used, other than bitcoin?
- antocv 10y agoNot everyone, just people who like to run a full node, the others run "light clients" or other variants of light clients, like Electrum, but eventually, if nobody run full nodes it wouldnt work at all. The bitcoin database size is more than 100GB now in 2017. Blockchain is used by all altcoins and Namecoin for distributed DNS like system.
- chrisseaton 10y agoWhy does the number have to be a nonce? If you can find a number that gives a block the correct number of zeros, but it has been previously used to give a totally different block the correct number of zeros, what is wrong with using it?
- detaro 10y agoIt's called that for whatever reason in bitcoin, but yes, there is no reason why it couldn't be reused in a different block. Maybe the name was used since it is similar to a cryptographic nonce in that it is choosen independently of the actual "payload" data?
- sowbug 10y agoIt doesn't, and there would be nothing wrong with using it. I haven't read TFA but it's probably using "nonce" in the more colloquial sense of a random number that is in a range so large that repetition is extremely unlikely. Finding that a single number solved two blocks would be very similar to finding a SHA-256 collision (Bitcoin uses a double-SHA scheme that I think was designed to address a length-extension concern).
- fabianfabian 10y agoits just named that way, probably as in you don't try the same number twice for finding the hash of one block. The same number can be used for other blocks or even the same block if you change something else in it (like add more transactions).
- DiThi 10y agoYou can start counting from zero or you can start with any of the previous numbers, but in the end the probability that it is the correct number is exactly the same. The header is always different than other headers (even if it's just for the block number, or "height"), that guarantees the probability is random.
- mthoms 10y agoBy design, the chance of a previous nonce being re-usable are virtually nill. http://preshing.com/20110504/hash-collision-probabilities/ http://preshing.com/20110504/hash-collision-probabilities/ The Bitcoin "nonce" is actually a much bigger number than shown in the video. 32 bits I believe.
- eecks 10y agoHow are updates propagated to all different copies of the blockchain?
- myroon5 10y agoReddit thread on this: https://www.reddit.com/r/Bitcoin/comments/2wjgpd/can_someone_please_explain_to_me_how_bitcoin_gets/ https://www.reddit.com/r/Bitcoin/comments/2wjgpd/can_someone...
- Taek 10y agoAnother commenter linked to a discussion about updating the Bitcoin software, but are you talking about updates to the Bitcoin blockchain? An 'update' would be a new block or transaction. The Bitcoin network shares new blocks and transaction over a flood network where every node is peered with 8+ other nodes, and will tell all of them when it sees a new block or transaction.
- dmux 10y agoOne of his last comments -- the one about having an immutable, agreed upon history -- seems like a great tool for recording facts in our "alternate-facts" world.
- moxious 10y agoBlock chain has always seemed technically excellent but of limited practical value to me. It clearly excels in a world where the participants are anonymous and can't trust each other. The trouble is that doesn't describe most business transactions worldwide. Humanity has a couple thousand years of business experience that generally always bent towards parties identifying one another, building trust, and using courts when those previous methods failed. So there seems a big mismatch here...block chain seems really excellent at solving a problem that doesn't exist in most places. Bitcoin is a good counter example. And crypto libertarians who would prefer anonymity will clearly always be attracted, but society would have a lot of cultural habits to undo before this would seem attractive in the mainstream.
- Taek 10y ago> generally always bent towards parties identifying one another, building trust, and using courts when those previous methods failed That costs a lot of money. It makes it hard to get started if you are untrusted, and it means you have to have a court system, you have to do legal stuff, you have to constantly be wary of the potentially changing trustworthiness of your counterparty. Blockchains eliminate all of this overhead. It doesn't matter if you are dealing with a highly regulated bank or if you are dealing with Bob the hobo, the blockchain guarantees that you can't be stabbed in the back (... err, when used correctly. Used incorrectly it will not provide any security at all). I think this is something a lot of people fail to grasp. The true power of the blockchain is its ability to bring trust to places where it's currently inaccessible. Banks that don't trust eachother can do buisness directly. Countries that don't trust eachother can do business directly. A person with no name, no reputation, and no tether to a court system can also be transacted with safely, because the courts, names, and reputations are made strictly unnecessary. And the proposal is that doing things this way is much cheaper than doing things the traditional way, especially when you consider all of the innovation that could never happen simply because the innovator was unknown or untrusted. All of the energy and money that goes into mining Bitcoin, in my opinion, is more than made up for by the value-add here.
- Xophmeister 10y agoMaybe this is off-topic, as Bitcoin is an implementation of a blockchain, but I'm interested in how the reward and consensus system works. This video implies that, while expensive, it's not that expensive to calculate a correct nonce. Why, therefore, is mining now only viable to huge ASIC farms? My presumption is that it must be to do to with either speed (i.e., the farms get there first), or influence (i.e., the farms have more peers, so can sway the vote in their favour).
- imaginenore 10y agoBitcoin has Difficulty, a measure of how many zeroes you must have in your hash. https://en.bitcoin.it/wiki/Difficulty https://en.bitcoin.it/wiki/Difficulty https://en.bitcoin.it/wiki/Target https://en.bitcoin.it/wiki/Target Basically, every 2016 blocks (around 11-14 days) new difficulty is calculated based on the time it took to find the previous 2016 blocks. Whenever someone gets new fast hardware, blocks get solved quicker, but then the difficulty gets adjusted after 2016 blocks, and it becomes hard again (but even harder for the people with worse hardware).
- deleted 10y ago[deleted]
- Taek 10y agoWith Bitcoin today, instead of needing 4 leading zeroes you need something like 17 leading zeroes (in hex, or ~1 in 2^68 chance of finding a block). Every 2016 blocks, the difficulty adjusts. This is supposed to take 20,160 minutes, but if the timestamps indicate that it took less than that, the difficulty will increase, requiring more leading zeroes. If it takes more time than 20,160 minutes, the difficulty will decrease, essentially requiring less leading zeroes. Also worth pointing out that the hash can be evaluated as an integer. Instead of requiring an exact number of leading zeroes, you require the hash to have an integer representation than is lower than a certain value. There's actually a lot of work that has gone into Bitcoin to make sure that having higher hashrate and higher influence does not make it more likely so that you can find a block. Ideally, if you have 0.01% of the hashrate, you have a 0.01% chance of finding each block, and if you have 33% hashrate, you have a 33% chance of finding each block. In reality, Bitcoin is not quite this perfect, but it's pretty close. The 33% hashrate miner may have a 34% or 35% of actually finding each block.
- zutronics 10y agoI saw Anders give this overview live at a Hubweek presentation at the Boston Fed a few months back. Excellent overview. Not sure if he's still working at Circle, but their recent pivot away from Bitcoin is a bummer - but I'm told they're still utilizing the Blockchain as an underlying technology for their systems.
- anders94 10y agoThanks for the comment - I am still with Circle, and indeed we still use the bitcoin blockchain behind the scenes. We're also working on a smart contract platform called Spark. More to come on that in a bit.
- pcmaffey 10y agoSo absolute truth on the blockchain is held by majority rule?
- c0achmcguirk 10y agoYes, in a sense. The longest blockchain is the "truth." But with independently acting miners and mining pools there isn't a "majority" in the sense of a group of actors bullying the minority. The 51% problem describes this but it probably won't happen. The miners don't want to be a part of a pool that achieves over 50% hashing power because it would undermine bitcoin and sabotage their efforts. Currently the biggest mining pool is either AntPool or F2Pool. They both have about 15% of the total hashing power [1]. - [1] https://blockchain.info/pools https://blockchain.info/pools
- Taek 10y agoNot quite. Bitcoin has very specific rules that transactions must follow. For example, there is a very strict way that you can create new money. Existing money can only be spent by the owner, etc. So, if the longest chain violates one of the core rules, that chain is ignored. You only ever follow the longest chain that also follows all of the rules.
- runeks 10y agoIt's not the longest chain (most blocks) that is preferred, it's the chain with the most cumulative work. Ie. the valid chain whose sum of block difficulties is the greatest.
- bshanks 10y agoYes, if you imagine that the number of "votes" that each computer gets is proportional to its computational power ("hashing power" or hashpower). (if instead, each node got one vote, then it would be too easy for someone to create a million fake nodes to game the vote) Also as Taek points out, the protocol also contains some rules that constrain the content of the chain. No honest node will accept a chain violating these rules even if a majority of the hashpower supports such a chain. Note that this describes a "proof-of-work" chain. There are other forms of blockchains, such as "proof-of-stake", in which the number of "votes" is proportional to something other than computational power.
- fidz 10y agoGreat explanation. Thank you very much. However, it raises question for me: - So "Hash" it combination of Block Number, Nonce, and the Data? - If "mining" means computing the Nonce, what is the actual data to be hashed? - For Coinbase case, is it the data is the miner's Coinbase Account? So that if mining successful, the miner will get the "money"? If so, how do the first miner advertise the result so that the other peer can trust that the first miner actually get the money?
- Canada 10y agoIt's an expression containing a public key controlled by the miner. The way you give value to someone else is by saying, "whoever can make this expression evaluate true can move the funds" https://en.bitcoin.it/wiki/Script https://en.bitcoin.it/wiki/Script
- Natanael_L 10y agoCoinbase the company is unrelated to the Bitcoin protocol, other then that they use it like everybody else. The hash covers the Bitcoin block header. The header includes a Merkle Tree Hash of all transaction, including the transaction that is the base for creating new coins = coinbase. You pay to public keys. Payments have to be signed by the private key holder for the public key that a given set of coins have been assigned to. Publishing the block itself that you mined is how your announce it. Others then have to accept your block and continue building on it as a part of the blockchain.
- avenoir 10y agoI'm more than sure I misunderstand something. Is the purpose of mining to introduce cost to recalculating a chain? So basically if someone changes a block in the chain mining makes it impractical to extend the change upstream? If so how did this impact the security of blockchains in the early days when mining complexity was very low and attainable on a single CPU. By the way, amazing find. Immensely thankful to the OP for sharing.
- arglebarnacle 10y agoSo in a blockchain, it's straightforward to verify whether a block contains only valid transactions or not (in the sense of an address only being allowed to spend coins it really has for example). Any node running the reference implementation will reject any block that is invalid regardless of mining. The issue with one actor controlling over 50% of mining power is that they can spend their money, then go back in time to before the spend to create an alternative chain. Since they control the majority of hashpower, their alternative chain catches up and ultimately becomes the reference chain in the view of the nodes in the peer to peer network. The bad actor is then free to spend the coins from their original transaction again, despite presumably having already received the goods or services from the original transaction. The real innovation of the blockchain is that it solves the Byzantine Generals problem in the case where less than 50% of the hashpower in the network belongs to coordinating bad actors. In the absence of that level of centralization and collusion, you can be sure that nobody is cheating.
- mthoms 10y agoYou've definitely got the right idea. It's not mentioned in the video, but mining is also how new currency is generated - Miners are rewarded for finding blocks (thus there is incentive to mine). And to answer your question - In the early days, miners were hobyists and simply operated at a loss. The value of coins grew roughly along with the "hash power" of the collective network (as you might expect). And at the same time, the reward for finding new blocks is constantly shrinking.
- bshanks 10y agoYes, you are correct. Proof-of-work blockchains are vulnerable to an adversary who has more computing power than the sum of the computing power of all of the honest miners. This is called a "51% attack". So baby blockchains are quite vulnerable.
- gamapuna 10y agoThis was posted before , but IMO is very well written:- https://www.igvita.com/2014/05/05/minimum-viable-block-chain/ https://www.igvita.com/2014/05/05/minimum-viable-block-chain...
- quwert95 10y agoI really like this demo; it makes sense and was stepped through beautifully. I would love to see a 'weaknesses' explanations about blockchains though, like how 'truthiness' is generated and speed of verification and distribution. Well done.
- Natanael_L 10y agoIf the blockchain follows the rules in the code / protocol and it is part of the blockchain fork currently known to have the greatest amount of accumulated proof of work, it is considered canonical / real.
- arc_of_descent 10y agoReally nice. Clear and concise.
- nul_byte 10y agoSo I guess where he talks about the consensus of the peers 11.10seconds, this is a good way to understand a 51% attack?
- baby 10y agoYup, this is it. What I'm wondering is how many blockchains are you verifying as a peer. When you download the blockchain software, you start verifying the entire blockchain, do you keep getting blockchain hashes from other peers and keep comparing them to see what's the consensus?
- Natanael_L 10y agoYou ask for blocks from everybody, starting with the genesis block (block #1). You verify that they're all valid, and the blockchain with the greatest accumulated difficulty (correlated with chain length) is assumed to be the valid one used by the whole network. Whenever you get new blocks you first verify validity, and then you check if they make up for a conflicting blockchain longer than yours (if so, you switch), shorter than yours (ignore), or if it extends the blockchain you have (then you add them). Number of peers don't matter in Bitcoin.
- baby 10y agoOK. So you get an arbitrary number of blockchains, you check which one is the longest, it wins. Doesn't matter if you have 50 against 1 that are shorter and on a different path?
- Natanael_L 10y agoOnly one thing matters - a validly formed blockchain with a total accumulated proof of work greater than that of any other individual chain. This typically also means that the longest individual blockchain wins.
- baby 10y agoWait what is the coinbase thing? EDIT: Oh, that's when you successfully mine a block. I'm guessing they chose the name "Coinbase" instead of "reward" to promote Coinbase.
- wcoenen 10y ago"coinbase" is a term from the bitcoin source code[1]. The company came later. [1] https://github.com/bitcoin/bitcoin/blob/master/src/coins.cpp https://github.com/bitcoin/bitcoin/blob/master/src/coins.cpp
- 2sk21 10y agoAnders Brownworth is the cohost of the Asymco podcast along with Horace Dediu. He mostly takes the back seat to Horace in that podcast so I'm amazed to see how talented he is at explaining things. He did in a podcast that he is working on blockchain related startup (apart from being a helicopter pilot!)
- deleted 10y ago[deleted]
- blinry 10y agoI'd like to start a Reddit community around interactive explanations like this – wanna join? https://www.reddit.com/r/explorables/ https://www.reddit.com/r/explorables/
- Curious42 10y agoYes please.
- stevehiehn 10y agoThere is something i don't understand: At the point a transaction is made there is only one copy. Does that not mean at that point its vulnerable to fraud before more copies are made?
- pizza 10y agohttps://en.bitcoin.it/wiki/Double-spending#Finney_attack https://en.bitcoin.it/wiki/Double-spending#Finney_attack The key is to wait for confirmations
- stevehiehn 10y agoAh! i get it now. I just watched a kahn academy video. When a transaction occurs between valid users (with public keys) the transaction is broadcast to the entire network.
- Curious42 10y agoThere's a nice analogy that can be drawn between linked lists and the way blockchains work.
- Curious42 10y agoWhat's the guarantee that every peer has the same number of blocks? Are they asynchronously updated through a global endpoint or something similar? And how do these peers communicate with each other?
- Natanael_L 10y agoAll full nodes propagates blocks they generate or receive to everybody else. The blockchain system aims for global concensus. The chain with the greatest amount of proof of work will propagate to the majority of the network and be accepted as valid by these nodes (assuming it also follows the protocol rules).
- kriro 10y agoVery interesting and well explained. I like the style with the code/tabs. Link to that code: https://github.com/anders94/blockchain-demo https://github.com/anders94/blockchain-demo
- pizza 10y ago(Are/Why aren't) encrypted wallet keys written to & referenced from the blockchain itself?
- Natanael_L 10y agoStoring the master keys where? Bitcoin already has brainwallets, password derived private keys.
- pizza 10y agoStoring the keys into the ledger itself, maybe via the OP_RETURN field. People have stored images in the blockchain, so I imagine you can use it as a persistent decentralized filesystem in theory. Wouldn't you just need a way to chunk your desired keys into 80-byte segments? The initial wallet used to create the transaction is simply for bootstrapping, after that as long as you know which transactions are necessary to fetch the encrypted keys, and you retain the means of decryption, you could reconstitute the blockchain-stored keys necessary to sign further transactions. At that point you could even dispose of the bootstrapping wallet. Kinda like if you kept a key in one of those banks that let you rent deposit boxes, and you stored another key there. Then you'd have a way to use the expected greater robustness of the bank (blockchain) compared to, say, keeping the key under your mattress.
- Natanael_L 10y agoWhy not just use the existing hierarchical wallets (BIP32) based on a secret you've got somewhere perhaps stored split up using Shamir's Secret Sharing Scheme?
- pizza 10y agoInteresting. The use-case I was envisioning is an always-accessible but still secure, trust-less cloud wallet.
- ianpurton 10y agoThey could be. But storing data on the blockchain is relatively expensive and a bit clunky.
- mckoss 10y agoNice job. Nit - it would be nice not to use the term "signed" for a block that has a sufficiently small hash. The term "valid" is more commonly used for this attribute of a block, and less confusing with signed transactions.
- amadeuspzs 10y agoTerrific visual explanation. Would love to see this extended to explain permissions and smart contract aspects of hyperledger/ethereum.
- mnemotronic 10y agoAt about 8:50 he describes how changes to early blocks cause the chain to "resist change". I understand how a change to a previous block will require re-computation of subsequent blocks, but how is this "resisting change"? Just recompute the nonce for each of the remaining 2 or 3 blocks. No big deal. What am I missing?
- xxbondsxx 10y agoEven if it were computationally cheap to do so (despite a very long blockchain and new blocks arriving), it is a peer-driven system. So if you alter your blockchain, it will differ from the majority consensus from the rest of the crowd and your version of the truth will be rejected.
- cyberfart 10y agoIt doesn't "resist change" as much as it just makes it easy to tell that it was manipulated. Now you can go ahead and rehash the following blocks in the chain (if you can) but with only you having that chain and nobody else, it will be discarded in a distributed system.
- Natanael_L 10y agoYou also need to compete with all the miners in the network to accumulate more proof of work in your chain than what's already been added in the existing chain. Less proof of work = rejected blockchain fork.
- bshanks 10y agoThe blockchain is supposed to be used as an append-only data structure. There are a number of nodes who have copies of what is supposed to be (or at least, converge to) exactly the same data. The nodes are all constantly telling each other what they believe to be the most up-to-date version of the data. The purpose of the blockchain is to support a consensus-finding algorithm by which the nodes may start out disagreeing on the contents of the most recent few blocks in the log, but eventually converge to a consensus, at least for relatively old blocks. But some of the nodes are evil (or maybe just faulty, or maybe just out-of-touch), and want to try to change past data and get the other nodes to accept their fake history (the "fake chain"). When any node notices that some other nodes are saying different things (proposing different chains), it prefers to believe in whichever chain is longer (this is a slight simplification, actually it's accumulated difficulty). Many of the nodes are constantly accepting new data and 'mining' new blocks to append to the end of the real chain. They are doing this as fast as they can. The problem of finding a new hash for new blocks is embarrassingly parallel, so if there are 1000 nodes in the network they can mine about 1000x as fast as one node (however, the protocol is constantly adjusting the difficulty (the number of prefix zeros required in the hash) to ensure that on average the blockchain is getting longer at a fixed rate). If the evil nodes want to change something far back in history, they're going to have to try to mine a whole bunch of new blocks before the fake chain gets as long as the real chain. Recall that the other nodes will reject the fake chain as long as they are aware of another chain which is longer. But while the evil nodes are trying to catch up, the good nodes are also going to be trying to mine new blocks to append to the end of the real chain. Assuming there are more good nodes than evil ones (or rather, that the total computing power of the good nodes is greater than the total computing power of the evil ones), on average the speed that the evil nodes can mine new blocks is slower than the speed that the real chain is getting longer. Therefore the rule that the longest chain is the right one works. Now, through random chance it's always possible for the evil chain to get lucky and mine a block much faster than the good chain. But if it alters something deep in history, then in order to catch up, it would have to get lucky in this way many times in a row; the chance of that happening decreases geometrically with the number of blocks it is behind. Therefore, you can be very confident that a block deep in the chain won't be altered. To reiterate, the reason that it's important that the further back you change something, the more hashes you need to recompute, is that this leads to the following property: if there are two competing chains of different lengths, the probability that the shorter chain will eventually become the longest decreases geometrically with the initial difference in lengths. This property is why the algorithm converges to a consensus on the data in older blocks.
- luvz2code 10y agoVery nice demo and explanation of concepts. Thanks.
- mrfusion 10y agoCan sha asics be put to other uses? Is there value in finding these hashes quickly?
- runeks 10y agoNot really, no. As the name implies, these ASICs are highly specialized. They take in a half-calculated 512 bit SHA-256 block, and hash it twice. So unless you need to SHA256 hash something twice at a rate of trillions of hashes per second, there's really no alternative use. But, again, that's the purpose of ASICs: an increase in performance from a decrease in generality.