3 ms·
I know it’s sortof a dirty word, but this to me is one of the things that a blockchain solves. You cannot steal an address on the blockchain. I mean my god, i
by blhack 7y ago
I know it’s sortof a dirty word, but this to me is one of the things that a blockchain solves.
You cannot steal an address on the blockchain.
I mean my god, imagine if somebody rewrote bitcoin, except there were no private keys, and the public keys were only 9 digits long.
- harryh 7y agoYou cannot steal an address on the blockchain. People have their private keys stolen all the time. Blockchain makes this problem worth because after a theft there is no central authority capable of repairing the damage.
- blhack 7y agoPrivate keys and addresses are not the same thing. In the current model, if you get my social security number, checking account number, or credit card number, you have it. I have to trust you not to use it for something bad. At least in BTC, if you have my public key, it doesn’t matter. You can’t do anything with it. But in the current system, we are expected to give away this sensitive information all the time. In the BTC model, you (practically) NEVER share you private key with anybody. The BTC equivalent would be giving your private key to everybody who you have even any sort of relationship with, and just hoping they don’t do anything you don’t want them to. It’s absolutely insane how we treat this stuff right now.
- harryh 7y agoYes, public/private key authentication would be great when it comes to this sort of thing. But that really has very little to do with the blockchain. It would be quite possible for the government or a consortium of banks to implement improve authorization schemes that have all of the upsides of public/private keys and none of the downsides of the blockchain.
- blhack 7y agoHow can you see that this has little to do with the blockchain? This is like a basic application of that technology. Yes of course the government could implement the same thing, but many people already have.
- mattnewton 7y agoI think, while there may be a technical solution, the bigger problems are with the business and legal incentives around the credit industry today. Many of the things that make our credit system a nightmare for security, also lower friction for opening new accounts and engaging with the banking system. In my view, the banks are effectively offloading the security costs to law enforcement and unrelated third party individuals, in order to reap the benefits of less friction with signup. If you want a blockchain credit system, you need to solve that convenience problem, as well as a bunch of other kinds of support problems (what happens when you lose your key? Are you just screwed, and if not, what happens when the recovery mechanism is compromised?), and the banks currently have no incentive to do so (see chip and pin for a similar but smaller case study with the credit industry). Barring large legislation that shifts liabilities onto financial institutions from individuals and law enforcement, we won't see them invest in solving this either.
- ghaff 7y agoWhile there are better practices and worse practices, there's also just a tradeoff between convenience and how thoroughly identity is vetted. Imagine you forgot your 15 digit randomized password to Google and their response was either a shrug or a requirement to come to an office in Mountain View with multiple forms of government ID between the hours of 9-5 weekdays. (And 2FA doesn't change the basic equation because smartphones, keys, and one-time pads can all be lost.) That's a somewhat nonsensical extreme example obviously but using physical mail to addresses of record and things like that have often been used to enhance security for certain types of reactions. You're a digital nomad, are just traveling, just moved and didn't update records, or are actually homeless? Too bad. And this is in a country where pretty much any sort of Voter ID law is controversial because they do disenfranchise many voters.
- patio11 7y agoYou cannot steal an address on the blockchain. You can, trivially, so trivially that the community has a phrase for shaming people when it happens: "Not your keys, not your coins." One of the thorniest problems in credit history management in the US is that credentials are given to people who have apparent and actual authority to transact on behalf of other people at the time of the credentials being given but who do not have it at the time of credentials being used. The paradigmatic example is parents using their childrens' SSNs/etc to open accounts, which is routine, legal, and must be a supported use case and, btw, is also an enormous fraud vector. Related vectors include commingled finances of married couples needing to be extricated post divorce and elder abuse. Blockchains do not solve for these issues, and the community's insistence that they do does not do it credit.