4 ms·
No but it certifies who has entered the info, right? That might be part of the solution here
by donmatito 9y ago
No but it certifies who has entered the info, right? That might be part of the solution here
- nkrisc 9y agoMaybe it just certifies a "company" headquartered in an empty office in some commercial park entered the info.
- s73v3r_ 9y agoAnd how do you know that's the actual person, or that such a person/entity exists?
- donmatito 9y agoIsn't that EXACTLY the problem solved by cryptography, ie I can reliably know that only supplier X could have signed the message with the public key of supplier X ?
- asynchrony 9y agoIt depends on the security of supplier X's private keys. I think there's a general conflation of the security of the cryptography with the security of the system overall.
- simias 9y agoCryptography lets you make signatures that can't be falsified by anybody not having your key but that's it. It doesn't mean much if you have no way to know who is actually behind the signature. I could generate a PGP key for Bill Gates right now, distribute it to the keyservers and sign a message saying that "I owe simias on hacker news one billion dollars". You could verify that the message was signed by my key beyond a doubt but so what? Bitcoin doesn't have this problem thanks to PoW, when a miner submits a newly mined block the network doesn't need to check the miner's credentials, the block itself proves (statistically) that the miner did a certain amount of work to come up with the block. That's all that matters and the coins/fees are credited to the miner's address. That works because all the data necessary to create the consensus are available "objectively" on the blockchain for all to see. It doesn't matter if the miner pretends to be Abraham Lincoln, that's not what the blockchain works with. Most problems don't have these properties, if I tell the blockchain "I have a brand new PS4 and I'm going to send it to X in exchange for n bitcoins" the blockchain has no objective way to track this transaction.
- donmatito 9y agoI know that, but I don't understand why it is seen as such a roadblock. A supplier would add its tag on thousands of parts each day, which would find their way into thousands of products and thousands of end-consumers each day. The suppliers would be well identified by their physical location and the physical products they produce. I think people raising these objections have not worked in a physical supply chain in the floor plant? I don't know, I have a difficulty to wrap my head around the objection. I am receiving a truckload of parts that I ordered - these parts have a barcode or a RFID identifier that tracks their provenance - the only change in the system would be that when I acknowledge the reception of the truckload, another block is appened to the blockchain-based history of the parts : Supplier + me the manufacturer. And so on across the supply chain. I don't understand, are we talking about a scenario where a rogue actor would send me for fere a truckload of parts I have not ordered or something like that ?
- simias 9y agoMore like a rogue actor sending you a truckload of parts that are not what they're supposed to be. Take for instance the blockchain De Beers (the diamond cartel) says it wants to create to track diamonds. Things like country of origin, quality etc... Tracking diamonds is especially important because you want to make sure that the diamonds you buy are not from a conflict zone, the so-called "blood diamonds". Now imagine that you have a completely trustless bitcoin-like blockchain to track this. What prevents an African warlord from pretending to be Canadian and create fake entries for its diamonds into the blockchain pretending that they were mined in America? Then he can trade them without issue. The blockchain is unable to detect that a user hasn't the right nationality, nor can it track the physical origin and location of a diamond without having to trust somebody to tell it. Ergo your trustless blockchain is no more valuable than a random file on pastebin.com. To solve this issue you'd need some trusted certification authority that would audit miners and grant them access to the blockchain once they've asserted that they are who they pretend to be. But if you do this then you have a trusted 3rd party and the blockchain can advantageously be replaced by any regular database of your choice managed by this 3rd party. You can apply this reasoning to any physical good, from organic produce (how do you make sure that the producer isn't lying about making organic oranges?) to paper rolls (how do you know the producer isn't lying about using sustainable foresting techniques?). You need trusted third parties certifying and controlling these things to weed out cheaters.
- twblalock 9y agoWhat if someone else gets their hands on supplier X's keys?
- zhoujianfu 9y agoI've thought about this some and one way to at least "sort of" map a private key to a single trusted real-world individual/entity is to require it always keep a balance of some "high" amount on it to be considered valid. So three banks start out signing some new "blockchain" ledger with their private keys, each with $100M on it, and they probably are going to be really careful with those keys from then on, and not let anybody who doesn't really represent the entity sign things with them?
- asynchrony 9y agoI think this is the idea behind proof-of-stake. I don't see how it mitigates the fact that while the cryptography may be secure, the humans handling the keys are less so.
- s73v3r_ 9y agoAnd how do I know that person actually exists? How would I track them down if they lied?
- nrhk 9y agoWhy does this need to be a public blockchain? Just make it a permissioned industry chain with access from each of its members. Someone lied, well they signed it, go talk to them, you have immutable proof now. Or smart contract style, someone lied? Send the items back and escrow won't release your money as proof of return it could be signed by the courier and the original sender.
- s73v3r_ 9y agoAnd how is any of that different than the way things work now?
- donmatito 9y agoBecause you have sent them a purchase order and they have sent you a truckload of parts that you ordered? I'm sorry I don't understand the objection here
- atomical 9y agoIs that part of the problem?
- deleted 9y ago[deleted]