6 ms·
There may be some unstated assumptions here that I'm missing, but as presented this does not appear to be a useful idea. The meat of the idea, as I understand
by kwantam 6y ago
There may be some unstated assumptions here that I'm missing, but as presented this does not appear to be a useful idea.
The meat of the idea, as I understand it, is: passports can be easily validated (because they contain a secret key signed by a government's Document Signing Certificate), but they cannot be cloned (because that secret key is in tamper-resistant hardware). So let's prove work by generating preimages of signatures under these keys.
Trusting this purported PoW system requires that you trust the government not to issue fake certificates. Otherwise, they can just use their signing key to generate lots of new certificates and massively parallelize the "proof of work". Moreover, at the point that you trust the government to behave honestly, there's no need for proof of work! Since you're trusting that a passport key is uniquely tied to an individual, you can (for example) just vote---the required assumption already implies that there cannot be any Sybils. (Or use any other mechanism that requires Sybil-free PKI, since that's what the assumption implies.)
(As another practical matter, there does not appear to be any reason to believe that each individual only has one physical passport. Some countries allow people to have multiple passports.)
- tromp 6y agoEven if the consensus rules accept any passport public key certified by a government, how would this cope with revoked passports? Or worse yet, with a revoked government certificate signing key? This idea goes against the decentralized, trustless and permissionless nature of cryptocurrencies.
- janmo 6y agoRevoked government certificates are published on the website of the ICAO, so it isn't very difficult to get this information. For revoked passports there is no solution as of now.
- tromp 6y agoConsensus rules must be verified using on-chain data only and cannot depend on website access.
- DennisP 6y agoTrue, but if the website provides an API and signed data, it can be possible to verify the signature on chain in a smart contract.
- espoir666 6y agoI think this is his future direction, providing an API that can be verified
- comex 6y agoI’m nitpicking, but there’s no rule that a blockchain node can’t check a website before deciding whether a block is valid or not. It’s usually a bad idea, since if the page changes between different nodes’ requests, those nodes would end up disagreeing on validity. And it’s not necessary for this scenario. But it’s possible. It does imply trusting the owner of the website, whereas most cryptocurrencies aim to be trustless, but in this case the premise already involves trusting the government.
- janmo 6y agoOne solution that I have thought of is to have a mining difficulty by country and another one by passport. If the passports of a certain country mine a lot of blocks the difficulty for this country would increase. In this scenario it would take 51% of the countries to go rogue in order to perform a 51% attack. Another thing to implement as well is to increase the difficulty for a passport to find a new block once it has already found a block. This way even if someone extracts the private key of a passport he will only be able to take a very limited advantage out of it because the difficulty for him would skyrocket, as a consequence the reward of doing this should be lower than the costs of doing the hardware hacking.
- londons_explore 6y agoThis sounds like the UN... Representatives from each country are voted in by the people, and those representatives vote... (for now assume all countries have perfect democracies and the UN does away with its veto system) Overall, it works, but I suspect we wouldn't see the explosion of "Blockchain 2.0" companies if instead they were "UN Governance 2.0" companies...
- centimeter 6y agoYou're describing a blockchain with nation-level votes instead of proof of work. I don't see any valuable properties in such a system compared to a normal bank. If the member nations get to control the contents of the blockchain anyway (because they can locally decide to to sybil attacks or whatever), why would I bother using such a system instead of just having an account at Barclays or whatever?
- icebraining 6y agoBarclays doesn't require the consensus of 51% of countries to do shenanigans. Plus their shenanigans are easy to keep hidden for years, whereas this attack would be quite obvious as it was performed. Yes, both require some level of trust in governments, but that doesn't mean they are the same.
- gruez 6y ago>One solution that I have thought of is to have a mining difficulty by country and another one by passport. If the passports of a certain country mine a lot of blocks the difficulty for this country would increase. But countries are a completely arbitrary distinction. Should Liechtenstein mining 100 blocks raise its difficulty as China mining 100 blocks? If not, how should we weigh each country? By population? By GDP? What's stopping countries from gaming their statistics to get more votes?
- smsm42 6y ago> that you trust the government not to issue fake certificates But we know it's not true - the government does issue fake passports, e.g. for spies, maybe for other purposes too. > each individual only has one physical passport Passports can be lost. In that case, the government keeps the database of revoked passports (IIRC in cases I've seen they actually track when the latest one was issued and will reject ones with earlier issue date). However, if you don't have access to that database, I don't think you have any way to distinguish between passports issued to the same person. At that would be true for pretty much every country I imagine - I don't think any country would not allow their citizens to replace a lost passport.
- cguess 6y agoPeople also get multiple passports for things such as traveling to countries where having a visa from one in your passport would preclude you from entering the other. Military service or diplomatic service often means you get a "black" diplomatic passport, which would have the same chip in it as any other e-passport. You can be sending one passport in to receive a visa (Russia, for instance, can take over a month), but you still need to travel so you're issued a secondary temporary passport. I'm sure there's dozens of other exceptions on why assuming every user has only one passport doesn't work out. (This is aside from the fact North Korea or China can just issue 10,000's of fake passports to hack this anyways)
- ubiubi18 6y agopeople get multiple mining machines. Somw even multiple thousands. It is not necessarily about more democracy where one person has only one vote, but it is about more true decentralisation of control - as i understand it.
- DennisP 6y agoI agree there's no real need to use PoW this way. But this could be interesting as a sybil-resistant voting mechanism. It could be helpful for experiments in quadratic voting, liquid democracy, etc. As you point out it's not perfect, which is why I used the word "experiment," but it's a step forward at least.