51 ms·
Facebook Libra Is Architecturally Unsound
- basicplus2 7y ago<Reading through the publications released, it is clear there is a fundamental deception in the stated goal and implementation of the project. Put concisely, this project will not empower anyone. It is a pivot from a company whose advertising business is so embroiled in scandal and corruption that it has no choice but to try to diversify into payments and credit scoring to survive. The clear long term goal is to act as a data broker and mediate consumers access to credit based on their private social media data. This is such an utterly terrifying and dystopian story that should cause more alarm than it does.> <The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case.> <Libra has no transaction privacy> <The system is designed to be a very large way of replicating transactions to a number of external parties who under existing European and US bank secrecy laws should not be privy to the economic details.> <Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail.> <Libra’s Move language is not sound.> <Libra’s cryptography engineering is unsound.> <Libra has no capacity for consumer protection mechanisms.>
- eecc 7y agoSo it’s basically the Chinese Social Credit System, only privatized and reframed as the traditional consumer credit score in use since decades. Creepy as hell... but it’s good that the excesses of online tracking have brought this whole “dark entanglement” into public scrutiny.
- antisemiotic 7y agoI used to think that Libra is just an attempt to combine the transaction speed of blockchain with the trustlessness of fiat, I didn't expect the rabbit hole to go so deep.
- Jamwinner 7y agoThis is downvoted, but hits the nail on the head. Will downvoters post to explian where op is mistaken?
- chrisweekly 7y ago> " It is a pivot from a company whose advertising business is so embroiled in scandal and corruption that it has no choice but to try to diversify into payments and credit scoring to survive. The clear long term goal is to act as a data broker and mediate consumers access to credit based on their private social media data. This is such an utterly terrifying and dystopian story that should cause more alarm than it does." ^ This. The rest is moot.
- argo_ 7y agoBitcoin is the only meaningful digital currency and sound money.
- Finch2192 7y agoDo you believe that bitcoin is useful as an actual currency? As far as I can tell, its only use is to buy drugs and other illegal things online.
- stronglikedan 7y agoI buy legal things online and use Bitcoin occasionally. Especially on sites that give a discount for using it.
- hombre_fatal 7y ago"Digital cash" is really the best way to explain the uses of it. Cash is still useful as well. And, equally, don't fall into the cashless utopia "why would anyone want to use cash except criminals?!" trap either.
- elcomet 7y agoall transactions are public, so to me it looks more like the opposite of cash..
- nighthawk24 7y agoBitcoin Cash adoption is growing around the world for restaurants https://map.bitcoin.com/ https://map.bitcoin.com/
- littlestymaar 7y agoI've always been puzzled when I heard about shops accepting bitcoin: how to they deal with double spending?
- 7y ago
- jsjolen 7y agoAn alternative company which actually seems to do good work w.r.t. safe languages is Alacris/LegiLogic. Though I haven't found the operational semantics of the language there is a public compiler that can be found here: https://alacrity-lang.org/codeeditor https://alacrity-lang.org/codeeditor
- snarf21 7y agoThere have been a lot of posts and responses about Libra. The core of it is that FB wants to be an unregulated bank. That is all this whole thing is about. Given the current (and post 2020 political realities?), it is no wonder all the established payment companies tapped out. This effort will be delayed until their is a government structure willing to look the other way. It will also be really interesting to see how this gets rolled out against GDPR and other European laws.
- no1youknowz 7y agoAs time goes on, it's increasingly looking likely that it won't be rolled out in Europe[0]. > "Libra is not welcome on European soil," French Economy Minister Bruno Le Maire told reporters the sidelines of the annual meetings of the World Bank and International Monetary Fund > "Do we want to put monetary policy in the hands of a private company like Facebook? My answer is clearly no," he said [0]: https://www.business-standard.com/article/pti-stories/paris-rome-berlin-preparing-to-block-facebook-s-libra-in-europe-french-minister-119101801388_1.html https://www.business-standard.com/article/pti-stories/paris-...
- K0SM0S 7y agoWorth noting however that Facebook could register some entity as a bank and operate the Libra service from there (even sharing offices with Fb, that's not illegal afaik). They would fall under all possible kinds and manners of banking regulation, but it's viable; many companies originally outside of the fin sector are offering financial services now (notably Orange, the French leading and historical ISP, formerly a state-owned public company). This would likely result in some tiny fee when crossing in/out of the traditional banking sector (from/to Libra and some regular account or merchant paying system), and maybe when entering/leaving Europe, but would remain largely free for Libra transactions within the EU. Which, as I see it, is the purpose of said regulation: to protect EU citizens (account insurance up to €100K, rights to certain features like free inter-bank transfers within the EU, etc). Libra unregulated would basically fall to Facebook's unilateral rules for protection and features, and that just isn't acceptable to the EU.
- drtillberg 7y ago>The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means. Refusing to rely on legal means of enforcement suggests the project views itself supreme over all national policies, laws and regulations. On the one hand, such a concept is usually the domain of autocrats, despots, and organized crime-- odd for a tech startup. On the other hand, it would suggest a system more secure from outside legal interference than, say, MasterCard. This detail tends to add a datapoint explaining the lack of support from global ministers of finance....
- deleted 7y ago[deleted]
- pearjuice 7y agoFacebook and a variation of "libre" in the same sentence makes so little sense to me that by definition I would refuse to use this product if it would ever reach market. Companies which main purpose is aggregation and selling of data to advertisers should simply not be trusted with financial transactions because in the end, this data will be used to make your financial transactions greater and more tailored to the advertiser paying the most for your data.
- seibelj 7y agoTypical blockchain and Libra hatchet job, except this time under the veneer of someone with software skills. I will make some counterpoints. > Byzantine fault tolerance is a fairly niche area of distributed systems research that concerns the ability of a networked system to endure arbitrary failures of its components while taking corrective actions critical to the system’s operation. Networks that are byzantine tolerant must resist several types of attacks including restarts, crashes, malicious payloads, and malicious voting in leader elections. This design decision is central to Libra and it makes zero sense. BFT consensus is standard in blockchain. Libra is building a protocol and reference implementation but anyone can build their own implementation, just as Bitcoin and Ethereum have several clients written independently as separate open source projects. As Facebook intends to be just one member of the Libra consortium, and anyone (member or not) can write software to the protocol spec, BFT is the logical choice. If Libra was trying to be a centralized entity owned by Facebook, then BFT consensus would make no sense. But it's not - Libra is supposed to be a decentralized blockchain payment system, similar to Bitcoin, so BFT is the logical (and standard!) choice. > Libra has no transaction privacy. By the admission of the whitepaper the system is designed to be pseudonymous meaning the addresses used at the protocol are derived from elliptic curve public keys and contain no metadata about the accounts. This means the same level of anonymity as provided by Bitcoin. Post-transaction analysis may identify the owners of keys by cross-referencing known addresses, but onchain it is unknown. Again, very standard in blockchain. There are various techniques to improve privacy, such as how SiaCoin generates new addresses for every transaction by default, but again I want to emphasize that the shrill language used by the author is coming from someone who doesn't understand the technology. I agree with him that Facebook could (and probably will) improve on Bitcoin's pseudo-anonymity, but claiming outright that this is some sort of grand oversight is just plain wrong. > Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail... There is no technical reason that cross border payments could also not settle instantly, except for the differences in rules and requirements across the jurisdictions involved. This is more about the philosophy of our payments infrastructure. Let's assume Facebook solves scaling, which is a problem many blockchains have solved (or are solving) in various ways. For example, Bitcoin's lightning network moves small transactions off-chain to settle later in one transaction that batches them. I'm not saying that's a good solution, either for Bitcoin or for Libra, I'm just saying the scaling problem can be solved even if the consensus algorithm is limiting. On the question of "why use blockchain for payments at all", this is more philosophical. You have monopoly-controlled payment systems that tightly control who can integrate with them and improvements to the core level take years / decades (see ACH in the USA). Blockchain is one major way that software is eating finance - companies and individuals will be able to hack away at the system and build novel innovations with much less friction. Whether you think this is a good thing is a matter of philosophy. > Libra’s Move language is not sound... In the public blockchains, smart contracts refer to logic deployed on public networks which allows escrowing, laundering money, and the issuance of extralegal securities and gambling products. These are typically done in a shockingly badly designed language called Solidity, which from an academic PL perspective, makes PHP look like a work of genius. Clearly biased, Solidity has its warts but it is successfully being used for billions of dollars in real-world transactions per day. The author is something of a compiler hacker according to his Github so I assume he feels qualified and passionate to speak on this. But Move has not been battle-tested yet so I would at least let it get finished and deployed before claiming it's dead-on-arrival. > Libra’s cryptography engineering is unsound. Facebook, like many other companies, can pay for audits and formal verification of crypto libraries. As Libra will not be production-ready for years (it isn't live today!), I think we can give Facebook the benefit of the doubt on this. They are a massive company with near-limitless resources. I want to conclude by saying that blockchain and cryptocurrency are knee-jerk hated by Hacker News, and have been so for years. You typically won't find positive (or even neutral) opinions on it, nor casual HN comments discussing the minutiae of the underlying tech the way you would for (say) Rust. People who are deep into this scene are posting on other websites that aren't as negative on the subject. There are indeed highly technical and competent people who work in this space. However it remains quite niche given its outsized mindshare in society. I encourage people to keep an open mind, there are very interesting problems to be solved if you can avoid the overwhelming criticism.
- magnamerc 7y agoAs soon as blockchain is even mentioned on HN, everyone loses their freaking minds. For some people that tout themselves as intellectuals, they just seem to parrot that 'blockchains are useless' without even taking a cursory look into the technology. It seems to me that a lot of people here fall into the category of ultracrepidarianism.
- rimliu 7y agoI'd argue that the usefulness of something is defined by what it can do, not the technologies used to implement it.
- briatx 7y agoOr maybe after much research and some testing they conclude (correctly) that "blockchain is useless."
- magnamerc 7y agoIf that were true, then they would come to a different conclusion. There are several examples of useful applications that are live today that would be otherwise impossible without a public programmable blockchain.
- forgotmyhnacc 7y agoI'm confused about this article. I've read it, and it's skeptical of libra (which is fine) but makes handwavy and non concrete arguments about it's soundness. Can anyone tell me why it's so popular, besides just bashing Facebook?
- rudolph9 7y agoBecause, facebook. He make a good point about privacy but even that was kinda handwavy.
- woah 7y agoIt's bashing both Facebook AND blockchains using handwavy faux-intellectual arguments, and is thus in the exact sweet spot of Hacker News upvotability.
- leshow 7y agoIt appears in the case of the Move language it doesn't actually contain a 'linear type system'. > The claim of the Move language to use of linear types appears to be unsubstantiated by a dive into the compiler as it reveals no such typechecker logic. As far as one can tell the whitepaper cites the canonical literature from Girard and Pierce and does nothing of the sort in the actual implementation.
- amluto 7y agoI have only studied Move by reading the whitepaper, but there's a gaping architectural hole that I found in five minutes: public withdraw_from_sender(amount:u64): Coin { let transaction_sender_address: address = GetTxnSenderAddress(); ... } Checking the global txn sender address is not a sound way to authorize a transaction in a smart contract language. Consider that a buggy or malicious function in a different smart contract could call withdraw(). Linear type theory might prevent the resulting stolen coins from being duplicated, but they're still stolen. I don't know if there is a clean theoretically sound way to do this, but here's an idea based on linear types: The main function in a transaction is given a Sender object as one of its arguments. The Sender has a method that generates an assertion (an object) that the transaction intends to perform a specific action, e.g. withdraw 10 coins of type A. The withdraw() function takes an assertion as a parameter and calls a method that consumes the assertion before withdrawing the coins.
- baby 7y agoThere's no other ways to get the sender address, this is a built-in.
- _nhynes 7y agoIt sounds like what you're describing is passing a capability to withdraw balance (which is implicitly captured in an erc20's internal state via `approve` [0]). Of course, cap handling is probably a bit unwieldy for a snippet in a whitepaper, so they're likely making the assumption of "don't call untrusted code." I don't see a construction for sender delegation, so at least it reduces the TCB to the immediate callee. [0] https://eips.ethereum.org/EIPS/eip-20 https://eips.ethereum.org/EIPS/eip-20
- bitxbit 7y agoZuckerberg sees shiny things and wants his name behind it. VR and now Crypto.
- jrochkind1 7y ago> The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means. Hmm, I'm not sure I'm convinced. While "Mastercard as an entity turns into a malicious actor" doesn't seem like an important threat model, it seems to me maybe guarding against mailicious actors within (eg) Mastercard, as well as external attacks on Mastercard is? And justifies this stuff? The possibliity that a node run by Mastercard would suddenly start running malcicious code doesn't seem that bizarre a scenario to me, if we remember it can happen not just cause the CEO of Mastercard directs it to, but because of criminal activities from hackers as well as employees for their own gain. Am I wrong?
- pckhoi 7y agoThe author didn't say that we should trust MasterCard but he was saying that this trust issue can be solved much more efficiently via the legal system. And in practice the current system already works as billions entrust their financial transactions in these institutions. Some people have the tendency to think that technology could solve anything and should be allowed to solve everything. This Libra thing is no better than the crypto-currencies.
- stale2002 7y agoOk, now what if the legal system is the one trying to get them to run the malicious code? For example, governments, in the past, have tried to prevent bank transactions from being sent to wiki leaks, even though they were never charged with any crimes. The credit card transactions failed to go through, but the crypto transactions DID succeed. Crypto currencies seem to have done a pretty good job so far, of preventing this attack vector. I can think of no examples where a government has taken over a crypto currency yet.
- ummonk 7y ago>For a system that is designed to be run in a consortia of highly regulated multinational corporates, all running Facebook signed code and access controlled by Facebook it simply makes no sense to deal with malicious actors at the consensus level. Why is this system designed to be byzantine tolerant at all rather than just maintaining a consistent audit log for compliance checks. The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means. Eh, I'm not so sure about that. It seems like a good feature that hackers successfully targeting a single node don't take down the whole system. >In congressional testimony the product was stated as a challenger to emerging international payment protocols such as WeChat, Alipay and M-Pesa. Yet none of these systems are designed to run on byzantine tolerant pools of validators. They are simply designed in the traditional high-throughput bus that orders ledger transactions according to a fixed set of rules. This is the natural approach to designing a payment system. Preventing double-spends and forks is simply not an issue that a properly designed payment rails should ever have to deal with by design. I would assume these systems are each run by a single company though, no? Which makes them fundamentally different from what Libra seems to be aiming at. >The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case. On the contrary, running byzantine fault tolerant consensus on a small number of node partners (which each submit aggregations of transactions from their clients) seems like exactly the kind of system that blockchain technology is best suited for. Not the kind of highly distributed consensus we see in e.g. bitcoin. >A defining feature of a payment rail is the ability to reverse transaction in case payments need to be undone by legal action or if they result in accidental or system malfunction. The Libra system is designed to have “total finality” and does not include a transaction type to reverse a payment. I don't know that this is necessary? A transaction can of course be reversed simply by making the inverse transfer. I don't know what kinds of annotations / metadata they would be storing in the ledger for audit trails, but it doesn't seem to me like a reverse transaction should be treated extra special. Disclosure: I work for Facebook in a totally unrelated initiative (Facebook Connectivity) but have only cursorily followed Libra news in news media. I'm generally highly skeptical of cryptocurrencies, but less skeptical of distributed byzantine fault tolerant ledgers as a general technology for some niches. My comments are completely my own personal views.
- bsenftner 7y agoJust ignore this Facebook Libra pollution; failure from inception, as the producer cannot be trusted for shit, which is prerequisite #1 for this type of endeavor.
- wiremine 7y ago> Not many people who work on financial infrastructure speak publicly about their work... This was a bit of a throw away line, but I found it insightful. As someone who isn't in this space, my question is: why is this? Is it contractual, or is that just not part of the space's ethos? Feels like we need to overcome this some how to achieve progress?
- sokamyung 7y agoI am not sure you would consider me directly in that space, even though the vast and distributed nature of that "space" seems unlikely to produce someone that can be considered equal part high level broadly knowledgeable enough, technical enough to make a statement about the work, in addition to muck around here to provide an answer. I think your answer is lost in the crevices of the nebula of dissimilar characteristics. That being said though, take or leave by following boiled down opinion on the matter that it is essentially just a form of greed that drives this ethos you highlight. It's both negative greed of people not wanting to discuss their secret sauce that does or could make them rich and wealthy, especially if and when it comes as the expense of others (regardless of whether it is only their sub-conscience that acknowledges it), not wanting to expose things like the spaghetti code that makes up the core of a multi-trillion dollar enterprise of maybe even the literal fraud being perpetrated to achieve riches, some self-delusion that obfuscation quals security that hopefully will prevent nefarious actors gaining insights. The very nature of the financial industry, a store of value, worth, and a huge closet of misdeeds and fraud that is chocked full and bursting at the seams to reveal the putrid innards; makes it a massively sensitive matter and domain. The behaviors and actions or ethos of the financial industry is not at all dissimilar to when you interact with other dishonest and nefarious and secretive types who have dirty secrets to hide and ill gotten gains to obscure and squirrel away. But there is also a layer of honesty that must be maintained. The notion of "disrupting" the financial sector with the trademark wonton recklessness of the Silicon Valley mentality gives me shivers, because when, e.g., the WeWork fraud One may as well have asked why African government officials don't publicly speak about how their government work or ask the CCP how China really works. But one could also even ask that question closer to home like how massively lossy Silicone Valley unicorns can exist or one may also ask for an audit of the DoD (which, interestingly, the recent attempt to audit the Marines led to the Auditor refusing to sign the audit) or the Federal Reserve (a set of private bankers that control the money supply without any accountability, oversight, let alone limits or balance of powers). Those are ALL equally sketchy and nefarious deceptive and manipulative smoke and mirrors slight of hand operations that one could ask the same question of why does not one speak publicly about their work. You may be one of those that realizes that there is a thread that runs between all of the above.
- westoque 7y ago> Libra has no capacity for consumer protection mechanisms. You can replace Libra quote above with your favorite cryptocurrency and that pretty much sums up what I feel on the crypto space.
- wongarsu 7y agoIn general the answer for consumer protection is to use any escrow service. Multi-signature schemes can even prevent you from a bad escrow, as long as no two parties are colluding. In general the need for consumer protection mechanisms is of course already a failing of the justice system. Virtually every case where consumer protection is useful is covered by existing laws and shouldn't require anything from the payment facilitator.
- leeoniya 7y ago> Virtually every case where consumer protection is useful is covered by existing laws and shouldn't require anything... ...except a lawyer, more money and a non-trivial part of your life.
- derefr 7y agoYes, that’s the failing. Ideally, justice should be cheaper in both time and monetary costs. I don’t know of any state that has ever tried to optimize for a low-overhead justice system “in the small” (e.g. many, more efficient, more convenient small-claims courts; or the introduction of another triage layer of “medium-claims” courts, where most all civil contractual disputes would land) which is an interesting fact all by itself. Speedy+cheap justice goes somewhat hand-in-hand with things like red-tape reduction, in that both are attempts to “oil the wheels” of the state apparatus—yet you’d never hear the same people (e.g. libertarians) espouse both.
- waqf 7y agoAren't small-claims courts precisely an attempt to optimize for a low-overhead justice system in the small? Doubtless you feel they don't succeed or don't go far enough, but it seems odd to claim that nobody's tried.
- HashThis 7y agoI wouldn't worry as much about Libra’s byzantine tolerance architecture. Sure it is O(n^2) now, but it can be replaced. That can be optimized away, if the economics cause companies to push it into the market and make it have mass adoption. Bitcoin, Ethereum and EOS have optimized away the exponential problem of O(n^2) byzantine tolerance. I'd be careful that that is just a short-term artifact of getting an early version running.
- HashThis 7y agoBitcoin launched with crypto that was replaced later. Yes, the algorithm, key length and similar things need to be right at the start (or back compat is harder). But the cypher and cryptography library implementation can be wholesale replaced, without a problem. Just as you pointed out, Microsoft did with a new TLS library.
- HashThis 7y agoNot being able to reserve payments is a FEATURE and not a BUG. That inherintly breaks a currency that is fast and removed of human transaction approvals. My thesis is that refunds will need to operate at a business level at a higher level. Their KYC and AML can be effective at backing that up.
- simiones 7y agoIt is a mis-feature - it is done intentionally, but it is a bad idea. Having to go through the legal system to reverse a fraudulent transaction is a huge hurdle compared to the current state of affairs, and it will significantly impact the use of Libra for internet payments.
- Jamwinner 7y agoIts a feature for avoiding facebook holding the bag when it is invaribly used for fraud. Let the little guy eat the risk.
- crb002 7y agoThe point of Libra is to create a consumer small purchase transaction medium with low friction. Businesses using it only care if it has enough Swiss backing so they can get a week’s business or two turned into real currency. It only has to be sound enough for those goals. As it is used more it will get hardened. The killer use is being able to pay overseas contractors without friction. Since there is no privacy, government on the other end will levy instant income tax withholding with glee.
- HashThis 7y agoThis ignores the big problems in Facebook's Libra: 1) It charges ECONOMIC RENTS. The ethical asset backed and currency backed stable coin needs to pass profits from revenue generating assets to the currency holder. The member companies should only take a tiny slice of the profits. This is the MASSIVE problem. 2) Libra is designed that ECONOMIC RENTS will be sharecropped and sent to the member companies. This will be the economic incentives for them to force it on their customer base and create incredibly fast adoption. This is a good thing, except it turns evil by the economic rents from #1.
- jyu 7y agoEconomic rents is an issue, but how else would you incentivize member companies to join into Libra in the first place? The proven business models are "evil" to some population: 1. Charge fees (like paypal, stripe, bank ach / wires), 2. Collect interest via economic rents, or 3. Capture and monetize user data ala Facebook. Can you think of a better way to jumpstart a new monetary network?
- hocuspocus 7y agoLaws and regulations in Europe have managed to make wire transfers and card payments cheap and efficient for both consumers and businesses.
- gridlockd 7y agoIt's not that cheap: https://en.wikipedia.org/wiki/Electronic_cash#Costs https://en.wikipedia.org/wiki/Electronic_cash#Costs You may think 0.3% isn't much, but with razor-thin profit margins (e.g. groceries) it does make a difference.
- hocuspocus 7y agoHandling cash isn't necessarily cheap either.
- 7y ago
- dharma1 7y agoAside from perhaps lack of developers / competency, I wonder why central banks don't issue digital currencies themselves? Mark Carney (current Bank of England governor) has been warming up to the idea - https://www.theguardian.com/business/2019/jun/20/mark-carney-bank-of-england-lend-digital-business-sme-cryptocurrency https://www.theguardian.com/business/2019/jun/20/mark-carney... Not sure if that because he is setting himself up for a new job at Libra after his BoE gig finishes in 2 months, or is there merit to the idea and appetite from central bankers?
- robjan 7y agoAren't all currencies digital these days? When I receive my salary it's just an entry in a digital ledger and when I buy something it's just another entry.
- lm28469 7y ago> Aside from the perhaps lack of developers / competency, I wonder why central banks don't issue digital currencies themselves? Why would they though ? I can transfer money worldwide in a few hours for very little fees already. Normal currencies are good for 99.99% of use cases. Aren't most currencies already mostly digital, they're literally integers in databases around the world, most of it isn't backed by any physical currency. Facebook wants its own currency because it would allow granular tracking and profiling like never before. What would banks gain from it ?
- dharma1 7y agoI can think of a few reasons 1) Geopolitical - if there was a widely accepted, regulated global currency that is relatively non-volatile, pegged on a basket of assets, I think many countries would gladly do cross-border trade in that rather than USD. I don't think Libra will be it, because it's perceived as being Facebook coin. But an effort from central banks could be it. 2) mainstream programmable money doesn't really exist, neither do microtransactions, or access to the financial system for many of the world's poor
- sschueller 7y agoThe Swiss National Bank is hiring blockchain people. They may be planning a stable coin.
- pron 7y agoThe answer to the question implied in the article -- why does Libra make such unjustified design decisions -- is simple. Some people have become enamored with blockchain despite it having almost no good use cases, and this certainly isn't one. It seems like a classic example of focusing on the technology rather than on the problem. -- Regardless of the other, far more important sections of this article, I find the section about the programming language misleading. Programming language theory does not study the quality of programming languages or their suitability to certain tasks. It is simply outside the purview of the discipline. PLT does not have any tools whatsoever to determine which language is more or less suitable and it is not interested in that question. The theory studies the properties of formal systems and the internal implications of their design. Much like mathematics can deduce from the Peano axioms that 10 > 5, but it says absolutely nothing about whether 10 is "better" than 5 because the answer to that depends on context (are we talking cookies or tumors?) that is simply outside the purview of mathematics. Similarly, PLT can say whether a certain formal system is sound or not, but it says nothing whatsoever about whether soundness is "good", "bad" or neutral, and certainly not how good or bad it is. Of course, programming language theorists have opinions on the matter, but those opinions are not supported by the theory. Also, given the other glaring flaws, there is nothing to suggest that a formal definition of the programming language would improve matters in any perceptible way. After all, we do entrust the world's monetary system, and sometimes even our lives, to software written in programming languages that don't have a formal definition. As someone who studies the issue of software correctness, a formal definition of a programming language is certainly of interest to theorists, but it has not been shown to be a particularly worthwhile means of increasing correctness.
- nradov 7y agoThe NIST has a helpful decision tree to determine whether a blockchain architecture is appropriate for your use case. https://www.nist.gov/publications/blockchain-technology-overview https://www.nist.gov/publications/blockchain-technology-over... (page 42)
- brokensegue 7y agoand someone turned it into a website http://doyouneedablockchain.com/#/1/0 http://doyouneedablockchain.com/#/1/0
- matthewdgreen 7y agoI don't disagree with the article per se, but I think many technologists are missing the forest for the trees when it comes to the motivations here. Or perhaps they're being charitable and are evaluating Libra on purely on its stated motivations rather than the ulterior motive that Libra can't name out loud. For example, take this quote: "The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means." It goes without saying that Libra isn't concerned about any sort of security event at Mastercard or a16z. The purpose here is simply to evade and arbitrage different regulatory regimes. The plan is to build a ledger that no single party (or coalition of parties in a single legal jurisdiction) has the capacity to edit or alter, and to make such alterations so technically challenging that it's beyond the capacity of any single court or legislature to do so. Once this chain is up and running, it becomes a "fact of nature" that courts and policymakers will simply have to deal with. It's a brilliant strategy from that perspective. It's going to be alternately fascinating and horrifying to see if it works.
- nokcha 7y ago>"The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means." In regards to that, I don't think it's any more bizarre than a SCADA system in an Iranian nuclear enrichment plant suddenly running malicious code. Cyberattacks against financial systems are a very real worry. In the history of computing, there have been countless times when people casually dismissed a security concern only for it to bite them years later. And oftentimes, trying to add security after the fact is much less successful that designing it to be secure from the get-go. I'm not a fan of Facebook Libra, but I do think that it's misguided to criticize it for having a robust security model with properties that can be reasoned about mathematically.
- matthewdgreen 7y agoTo the best of my knowledge, no deployed banking system relies on immutable ledgers. They all rely on detection and revision of ledgers. Libra has chosen to do something fundamentally different, and the author is asking why.
- madrafi 7y agoWould like to point that the work done by the curve25519 team is solid, Henry is also behind the ristretto RFC. The reason Facebook used the BFT algorithm is for pure regulatory purposes (they needed a Blockchain therefore a solid consensus algorithm with failure tolerance). The cryptographic constructions used are quite solid unlike OP claims.
- Jamwinner 7y agoCan you elaborte? You sould like you may have a unique perspective.
- bascule 7y agoThe article also incorrectly claims that curve25519-dalek has never had security audits. It's had at least two by reputable cryptography auditing firms (Quarkslab and NCC), the former of which is public (the NCC audit was done at the request of my former employer and is private, but like the Quarkslab audit only found minor issues): https://blog.quarkslab.com/security-audit-of-dalek-libraries.html https://blog.quarkslab.com/security-audit-of-dalek-libraries...
- dathinab 7y agoI think the start problem of Libra was to go with the ideas that: 1. One globally _uniform_ payment system is needed/wanted/makes sense. (It doesn't make sense due to regulation, is not needed, as long as a non uniform system still can make cross area transactions reasonable fast. It is not wanted (by some) as it put consumers at additional risk wrt. data protection and international conflicts). 2. Blockchain makes sense and "fixes everything", somehow, magically Sure the current payment systems have a lot of problems. But many come from complicated regulations which makes building such systems harder not incompetent bank IT. I fear a single company can't do to much here. Especially because banking software has to be reliable from the get-to-go.
- z3t4 7y agoWhen you make a oversea money transaction the banks take up to 20%. For every electronic transaction a bunch of middle-men takes a percentage. Maybe there need to be a payout for those that keep the system running? Like in Bitcoin mining ... But the thing is, transactions can be highly automated, with almost zero marginal cost (the cost of making yet a transaction when you already process millions per second). So the transaction fees for the middle-men is almost pure profit after a certain level. So there will be efforts to make sure any joint solution fails.
- gerikson 7y ago> When you make a oversea money transaction the banks take up to 20%. You need to comparison-shop the price of remittance: https://www.saveonsend.com/blog/welcome/#more-1 https://www.saveonsend.com/blog/welcome/#more-1
- robbya 7y agoWhat's the profit potential for Facebook here, especially above using an existing cryptocurrency for payments on their platforms? Having low friction payments on Facebook makes sense, it build value into the platform and Facebook can capture some of that. But can't they do that with an existing cryptocurrency? It doesn't seem like Facebook will maintain full control of the currency due to the consensus algorithm. There is power and control if Facebook continues to control the fork of the code base that everyone uses, but presumably nodes could choose to switch away from Facebook's fork. So I'm not seeing "control a currency" as a long term benefit. It makes sense that anyone running a Libra node would make money, but anyone else running a node would make similar profit. The article mentions that a long term goal could be "act as a data broker and mediate consumers access to credit", although again, doesn't the decentralized nature permit any node from taking those steps? That doesn't seem to uniquely advantage Facebook. As others mention, once a cryptocurrency is "too big to fail", regulators are locked out. Is Libra really an easier approach to getting a cryptocurrency to that point, versus adopting and accelerating the growth of an existing coin (like Bitcoin)? Does Facebook just think they can build a better cryptocurrency? I don't doubt that they can hire good engineers, but with all the politics and marketing focus on the code now, development is probably getting stressful and chaotic.
- gerikson 7y ago> What's the profit potential for Facebook here In a world where "everyone" uses Libra, they need a FB account to access their wallet, and FB will see every consumer decision at its most valuable - the point of exchanging money for goods and services. This is immensely valuable for an ad company.
- m12k 7y agoI've been thinking and it actually makes a lot of sense for new ways to be created to transfer money and pay for things (though I'm highly skeptical of having it operated by Facebook and of the ad-hoc pump-and-dump-prone and whitewashing-and-tax-avoidance-friendly properties of cryptocurrencies). But when you think about it, it's insane that transferring money is something credit cards and payment processors can regularly charge a fee of 1.5-3.0% on. In order to change some numbers in a couple databases... The marginal cost of this ought to be less than pennies. The only reason they can even partially justify this is because of fraud and credit, and the costs associated with dealing with that. But what if we had a way to transfer money between entities that mandated two factor authentication to prevent fraud, and sidestepped the whole credit thing by only working if you had the money? (or required that you took the loan elsewhere, so the account that actually transfers the money does not have to deal with credit at all). Verify that the person is who they claim to be, and that they have the money needed, then do the transaction - no more, no less. No chargebacks, no credit checks, no fraud checks. Why isn't this a thing?
- Slartie 7y agoThe actual cost of processing payment is far less than 1.5-3% - especially with debit cards (which actually implement most of what you think "is not a thing") but even when dealing with credit cards and the necessity to include some overhead for countering card fraud and chargeback costs and whatnot, the total cost is far lower, below 1%. How can I know this? Well, how do all these credit cards that offer cashback bonuses in the realm of typically 1-2% make this unbelievable feat of paying you for paying stuff happen? They pay for it out of the 2-3% that they get for the transaction. Let's take 2.5% as a middle ground and deduce 2% cashback, that leaves us with 0.5% from which the actual costs of doing the payment have to be covered - and the profits to be paid to shareholders, of course. Also, Europe has this nice regulation in place limiting credit and debit card interchange fees to 0.3% for credit and 0.2% for debit cards. This regulation has been in effect for a few years already, and the only thing that disappeared were these 2%-cashback-on-every-payment cards (or similar offerings, like granting airplane miles of about the same value). Debit and credit card issuers seem to be entirely able to operate under these conditions, which means that their actual costs of doing business must be under these fractions of a percent.
- gok 7y ago> smart contracts refer to logic deployed on public networks which allows escrowing, laundering money, and the issuance of extralegal securities and gambling products I'm a blockchain skeptic but come on
- baby 7y agoThis is a well-written post, although obviously carrying some confirmation bias against the idea of a cryptocurrency. I'm also obviously biased, but if people are interested in my opinion (and only my own) here it goes. > Libra’s byzantine tolerance on a permissioned network is an incoherent design. There are two aspects here that the author seems to forget: * The next best system, that a consortium of very different companies (think from different countries) would agree to run together is probably a protocol like Certificate Transparency which would be too slow and would have no mechanism to prevent double spending. If you're not doing this, then you're probably using a protocol that doesn't tolerate faults and the first time you have a fault your protocol collapses. There's probably a reason that Venmo cannot talk to Paypal which cannot talk to Square. * Libra will eventually move to a permissionless setting, which means it has to be designed from scratch to support this evolutionary change. You can agree or not with this, but this is the way it was planned. > Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail. Two things again: * The number of people in the world who uses GBP vs the number of people who will use Libra at launch is probably not comparable. This means that Libra will be perfectly fine to carry the load for a number of years. * Current research has shown that the largest throughput improvements are hidden in layer 2. If you don't know what layer 2 is: basically you do transactions off-chain, with whatever protocol you have, and only sometimes do you confirm the current state on the chain. > Libra’s Move language is not sound. I believe the type checking (and other checks) are done by the VM, (but that's not my domain so I might be wrong). Indeed, why would you trust the compiler to do the right thing? > Libra’s cryptography engineering is unsound. There are two things in this section that are completely wrong: * No, dalek is not the "wild west” and is actually written by some of the few people who you could trust to write such a library. Yet, audits are planned. Also: we do actually use formally verified code! We have integrated fiat-crypto (a formally verified library, not a cryptocurrency :D) into dalek in order to use formally verified field operations. * Neither do we use VRFs, bilinear pairings, and threshold signatures (they are just experimentations at this point) nor are these new tools or techniques. I don't have to say much at this point but I would take the author "It should be assumed this entire crypto stack is vulnerable to a variety of attacks" with a huge grain of salt. > Libra has no capacity for consumer protection mechanisms. Of course, it is a financial backbone, not a financial service.
- Mathnerd314 7y agoThe author seems to have done no actual research beyond skimming the code. E.g., "none of these libraries have had security audits" When in fact there has been a review, and probably more internal audits that haven't been published: https://blog.quarkslab.com/security-audit-of-dalek-libraries.html https://blog.quarkslab.com/security-audit-of-dalek-libraries...
- cloudhead 7y agoThe author correctly states that BFT algorithms are meant to handle arbitrary failures, but then explains how that is the wrong choice because one shouldn't handle malicious actors at the consensus level. Yet there are categories of faults that cannot be handled by basic FT systems, that BFT systems can handle, and are not due to malice. So all in all, BFT is the right choice.
- deleted 7y ago[deleted]
- carlosdp 7y ago> It is a pivot from a company whose advertising business is so embroiled in scandal and corruption that it has no choice but to try to diversify into payments and credit scoring to survive. It's amazing to me that nearly every single expert that weighs in on this topic completely misses the intention behind Libra. Facebook wants to make money off of it's massive user gains in the developing world (like hundreds of millions of users massive), but many of those people don't have digital money right now. Libra wants to be their digital money so Facebook can sell more expensive ads. It's really as simple as that. Move on from the "why" and talk about the rest of it which is the actually problematic part.
- macmichael01 7y agoCrypto in general still have a ton of security flaws. To call out a specific currency is silly. Lets acknowledge that there is still tons of security to fix with crypto in general.
- cimtrae 7y agoThis whole article sounded like he started with a conclusion and then found reasons to support it. It doesn't look objective. I am no supporter of Libra but increasingly media and influencers are about starting with a belief/conclusion based on their bias and then finding proofs for it. Perhaps that's how any human mind works!?
- silverlake 7y agoThis post is nonsense. 1) FB claims they want to eventually make it a public network. Therefore, they'll need BFT sooner or later. 2) No blockchain can match a centralized system (WeChat, Visa, et al). 3) Very few languages have a formal semantics written in Coq. 4) So what if the crypto lib has additional functions? Algorand has VRF code in their repo. Is the whole project doomed now? And it would take a huge effort to verify a crypto lib ala Everest. Even cryptographers don't do it. 5) In the US many banks are in a consortium called Zelle which allows retail customers to send money around. It has finality; can't be reversed. I don't give 2 shits about Libra. Gov'ts will clobber it anyway. But these criticisms are mostly "why didn't Libra do the latest bleeding edge researchy thing that no-one else does?" Because they had to ship this century, that's why.
- gwbas1c 7y agoFor the TLDR crowd, here are some juicy quotes: > The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means. > The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case. > ... the model as proposed is hundreds of person-years away from being able to handle global transaction throughput and would likely have to be completely redesigned from first principles. > Enterprise software consultants generally thrive on ambiguity and smart contracts are the apotheosis of enterprise obscurantism because they can be defined to mean literally anything. > It should be assumed this entire crypto stack is vulnerable to a variety of attacks until proven otherwise. The “move fast and break things” model should not apply to cryptographic tools handling consumer financial data. > The final conclusion one must take away after doing technical due diligence on this project is this simply that it would not pass muster in any respected journal on distributed systems research or financial engineering. Before trying to disrupt global monetary policy there is a massive amount of a technical work needed to build a reliable network the public and regulators could trust to securely handle user data. > I see no reason to believe that Facebook has done the technical work needed to overcome these technical issues in their project, not does it have any technical advantage over existing infrastructure that already works. Claiming one’s company needs regulatory flexibility to explore innovation is not an excuse for not doing it in the first place.
- lacker 7y agoI am not affiliated with Libra in any way, but I cannot agree with this article. Let me respond point by point. Libra’s byzantine tolerance on a permissioned network is an incoherent design. The criticism here is that byzantine tolerance is not needed, when every participant is a regulated multinational company. But it certainly isn't a bad thing to have byzantine tolerance. Maybe a set of the regulated multinational companies will have backdoors put in place by a malicious entity - that has certainly happened before. The downside of byzantine tolerance is the computational overhead. Yes, there is going to be a cost in throughput. But it just doesn't make sense for Libra to optimize for transactions-per-second at this point. If they run into scaling problems, then they can optimize. Right now they are quite far away from having scaling problems. Libra has no transaction privacy. It's the same privacy level as Bitcoin. Transactions are public, endpoint identities are trackable but don't have real identities attached. You can say it isn't a good set of tradeoffs for a cryptocurrency to be pseudo-anonymous. But it doesn't make the system "architecturally unsound". Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail. Again, it doesn't make sense to criticize Libra at this point for not being able to achieve tens of thousands of transactions per second. If they start running into scaling problems, they can work on all sorts of extensions and improvements then. Libra’s Move language is not sound. The criticisms here really boil down to "Move needs more work". It isn't fundamentally unsound, it just needs more work. The claims seem to reduce to nothing more than handwaving and marketing rather than actual proof. This is an alarming position for a language engineering project which expects the public to trust it to handle billions of dollars. Okay, well don't go putting a billion dollars in a Move smart contract tomorrow. Programming languages, and especially programming language documentation, can be improved a lot over time. ... There's more in the article, but really, it reads like a rant, where the author is so biased by their hatred of Facebook that they think every little thing that Libra does is wrong. IMO, the core mistake behind Libra is assuming that regulators would be okay with it, because it isn't very different from other permissioned cryptocurrencies, like Stellar. Instead, regulators have been quite opposed to it because Facebook is behind it, even when technologically it isn't very unique. It is certainly not "architecturally unsound".
- yungcoder 7y ago> The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case. I may be behind on Libra news, but my understanding was that the permissioned blockchain governance model would only exist during the bootstrapping phase to launch Libra and would eventually evolve into a public blockchain once it reaches some arbitrary point of stability. If that is still the case, then wouldn't Byzantine fault tolerance be required from the get-go, assuming Facebook wants to avoid a hard fork of Libra?
- phlip9 7y agoI strongly agree with him on transaction privacy, though not for the reasons he lists. Some issues, however: 1. His argument against BFT is "legal systems are efficient" (lmao). Also, the whole point of HotStuff (vs. PBFT etc...) is linear O(N) communication complexity outside of cascading proposer failures... 2. He clearly didn't investigate move bytecode-verifier, which asserts linearity. 3. Strong disagree on the untested crypto-primitives argument. curve25519-dalek is audited (x2) and written in Rust; simple and minimal; not a bloated, unauditable mess like TLS. 4. Consumer protection can be built on top via the wallet providers.
- bascule 7y agoThis post is filled with a large number of factual inaccuracies, so numerous I wrote a blog post in response: https://tonyarcieri.com/factual-inaccuracies-of-facebook-libra-is-architecturally-unsound https://tonyarcieri.com/factual-inaccuracies-of-facebook-lib...
- buboard 7y agoYou should submit that
- haolez 7y agoGenuine question: how do I share code with other parties in the industry? Suppose that I'm working in the insurance industry and I want my company A to share the ownership of some code (and its execution) with company B. It's a redundant piece of code that would otherwise be implemented in both companies internally. We may share a repository. That's simple and clear. But who is going to run this code? How do I know that the code running is the one shown in the shared repository? When I see things like Hyperledger Fabric, I see a possible solution to this problem (although I don't know about the downsides of Fabric). I can ensure that, given the same inputs, all parties will produce the same outputs. This seems like a fair use for a permissioned blockchain and smart contracts. But what else is out there? How would you approach this problem?
- mgraczyk 7y agoThere are many valid criticisms of Libra, even if we restrict our view to the code. This article contains none of them. However, use of a BFT consensus algorithm, newish crypto libraries, and missing but promised features in an unlaunched product are not reasonable criticisms. BFT algorithms that scale well (Libra's will, that's one thing Facebook is good at) are great for public financial networks. All large companies end up implementing their own crypto libraries and for some (Google, Facebook) this ends up a net positive for the open source community. Consumer protection will be there, Facebook is not going to knowingly violate local regulations in such an obvious way.
- lubujackson 7y agoI am always amazed at the concept that blockchain is private at any level. The architecture is built specifically to share transactional data. It is useful for creating a digital entity that is unique and can be treated as currency, but the shared transactional nature is a huge, huge privacy flaw, as far as I understand blockchain (at least Bitcoin). Please correct me if I am wrong about the public nature of transactions - I haven't seen anything discussing the encryption of transactions but I am by no means an expert on this. So assuming the transactions are accessible to anyone (and even encrypted is somewhat worrisome), what are the implications? Well, for a while Whole Foods was accepting payment by Bitcoin. That means if you know Whole Foods' Bitcoin account number you could simply look up all transactions to Whole Foods to see how much money they were making through Bitcoin, how many unique accounts paid them as well was when and how much. Does every business want their detailed transaction history to be public? And on a personal level, I remember when Netflix released anonymized data of movie ratings with ratings and date stamps. From this alone, some people were identified by looking at other personalizing data: https://www.wired.com/2007/12/why-anonymous-data-sometimes-isnt/ https://www.wired.com/2007/12/why-anonymous-data-sometimes-i... All it would take is one data harvesting company to pair your account to your transactions and then could track everything you do through it. I really hope this isn't how all of this works... and even if there are protections to prevent this, it seems like a viable attack vector to consider for any blockchain technology.
- nybble41 7y ago> Well, for a while Whole Foods was accepting payment by Bitcoin. That means if you know Whole Foods' Bitcoin account number... They wouldn't have just one "account number". Standard practice is to use a different address for each transaction, both for privacy and for increased security. (An attacker only has the public key hash to work from for any unspent transactions, not the full public key.) Now, these funds would probably be consolidated into a smaller number of holding accounts, and you might be able to deduce some other likely payments to Whole Foods by looking at which inputs were combined together in later transactions, but obtaining their complete ledger is nowhere near as simple as looking at one payment to Whole Foods and finding all the other transactions involving the same address.
- lazzlazzlazz 7y agoThe article is so confused about the underlying reasons for choosing a decentralized (among Libra members) ledger that it boggles the mind. It's a legal move. Not a technical one. Regarding privacy — it seemed obvious to me that privacy solutions for Libra would be build on top of Libra (the so-called "Layer 2") and not within the core protocol. Stephen's critique here is bizarre and lacks context.
- SkyMarshal 7y ago>For a system that is designed to be run in a consortia of highly regulated multinational corporates, all running Facebook signed code and access controlled by Facebook it simply makes no sense to deal with malicious actors at the consensus level. Why is this system designed to be byzantine tolerant at all rather than just maintaining a consistent audit log for compliance checks. The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means. BFT is still useful in that scenario as part of a defense-in-depth against compromise of some of the validators/nodes, yes even ones run by Mastercard or A16Z. It’s certainly more difficult for that to happen in these settings, but given the state of the world with nation states rampantly hacking each other in any way they can of varying levels of sophistication, from social engineering to stealing user databases to stuxnet, having an extra layer defenses against that in a global currency is not superflous. And that’s what Libra is, a global currency, not a mere payment system.
- homakov 7y agoA long boring read lacking arguments.