8 ms·
Bitcoin is not decentralized
- wccrawford 15y agoNo, Bitcoin is decentralized. One possible path in the future might be to centralize it for a time, then decentralize again. The author claims that only the original creators could do this, but that's not necessarily true, either. He brings up a valid concern, but the linkbait title doesn't do it any justice because everyone will be focused on the technical aspects where he's talking about socio-economic problems.
- ezyang 15y agoI make a stronger claim then that, which is that Bitcoin must perform a transfer in the future, and that if this transfer is to be non-disruptive, it must be done in a centralized fashion. I will admit I debated over the title for some time, but I decided I wanted to emphasize Bitcoin as a succession of protocols, not the current one, which is a hopelessly myopic perspective.
- berkes 15y agoHe actually points out that one of the two options as successor, is decentralized. The title is therefore slightly misleading.
- rrrazdan 15y agoBut then he points out the problem in the decentralized approach?
- lukeschlather 15y agoYes, I think the point is that the decentralized approach could have horrible consequences for people with significant savings in bitcoins.
- agentultra 15y agoThe author also "risks" constructing strawmen and then proceeds happily to do so. I was wary at first, but once the speculation started flying the article lost credibility IMO. It's a neat trick but I was less than impressed. What will happen to bitcoin with the hashing algorithm it uses becomes obsolete? Who knows. It may not be the only game in town at that point anyway.
- rwmj 15y ago"Who knows"? Deciding what may happen in the future is why people write papers. If there's a particular thing wrong with the paper then why not answer that?
- kiba 15y agoI am told that the cryptosystem can be swapped out and replaced.
- tptacek 15y agoHuh? No it can't.
- ezyang 15y agoWould it help if I linked to various Bitcoin forum posts where I found descriptions of these proposed transition plans? I don't have a very good feel for the reputability within the Bitcoin community, and I feel that simple technical reasons will limit the range of possible proposals.
- agentultra 15y agoIt's a good article, to be sure. Links to the threads would be nice. The speculation is what did it in for me. You say: At the risk of constructing strawmen, I would like to now present my perception of the two most popularly voiced plans. At which point I was expecting to read an unbiased over view of the popular proposals from the community and perhaps some links to the discussion threads. And after presenting the "decentralized" version and colouring it with an analogy to chinese black markets, you say: Is this a transition? Yes. Is it disruptive? Definitely yes. It is certainly not what you want a currency you’re using for every day transactions to be doing. Which essentially tells me you only presented the decentralized argument to me so that you could burn it down for all to see. I won't go so far to argue whether your position is wrong. As a reader I just felt the article to be another Internet soap box. Links would be nice and saving the speculation until the end would have helped, IMO.
- dholowiski 15y agoStupid title, of course bitcoin is decentralized, but it brings up some interesting ideas - what happens when a currency becomes obsolete?
- grimen 15y agoWell, isn't that happening to some currencies around the world with the current system anyways?
- michael_dorfman 15y agoTraditionally, you offer a limited time where the old currency can be exchanged for the new currency, and after that date, anyone holding the old currency is shit-out-of-luck. Note that the same scenario may apply (in some places) when new banknotes or coins are rolled out. Here in Norway, they periodically redesign the coins (and give them new sizes), and you have a certain amount of time to exchange your old ones before they are no longer considered legal tender.
- ezyang 15y agoNote that such an exchange is necessarily centralized.
- iwwr 15y agoYou can have several competing specifications, recognizing the old BTC balance and offering a new balance in a new spec. People (who can be) separate from the spec proposers may implement clients that connect both to the Bitcoin network and the alternates. Eventually, one (or maybe more) new protocols win out and trade move to the stronger protocols. BTC would be left as legacy and eventual discontinuation.
- po 15y agoMy main fear with something like bitcoin is this: imagine a virus or worm that infects machines and then transfers all bitcoin found on that machine to an anonymous address. There is absolutely no recourse. Hell, it could be a bitcoin "client" that continues to display the correct amounts to the user without them realizing they're being fleeced.
- thorax 15y agoThis has also concerned me as well (and lots of others), and on Reddit we had some thoughtful discussion here: http://www.reddit.com/r/Bitcoin/comments/hid2r/how_will_you_lose_your_bitcoin_wallet_ill_tell_you/ http://www.reddit.com/r/Bitcoin/comments/hid2r/how_will_you_... One of the best suggestions in there is simply to separate your checking and savings accounts so that a compromise of your spending money doesn't leave you without any coins. There's also a link in there that says the upcoming clients will store the wallet locally encrypted and only decrypt in memory for transactions-- there are weaknesses to this (i.e. the bitcoin client trojan you mention), but it's better than what is done today to secure the file on disk.
- getsat 15y agoI already wrote some proof of concept code that steals a user's balance if they're using the Windows client. You'd just have to distill it down to shellcode and include it as a payload in a 100% silent driveby browser exploit. POC code for Linux/BSD would be trivial, too. I'm not sure about Mac, but there's probably a way to do it via automator or regular message passing. As I've been saying for a while on the BTC forums, the wallets will be the main target, not the crypto.
- coderrr 15y agoCompletely agree. Although your code wouldn't help make a worm. Because even though you could get the Bitcoin client's peer addresses you couldn't remotely exploit them. I'm worried about the bitcoin client being in c++ rather than java because that seems to make a remote code execution vulnerability a lot more likely. And given a single remote code exec vuln it'd be easy to make a worm which destroys the entire network.
- drcode 15y agoThis post doesn't make sense to me. Why wouldn't the following be a solution: 1. Create a bitcoin client that includes a better cryptographic algorithm. 2. When this new client is asked to vote on the validity of bitcoins created with the old algorithm it votes "no", but allows it to be grandfathered in, as long as the new client is still in the minority. 3. Once the old clients are obsoleted, you can then no longer create bitcoins with the old hash method, but even the very last bitcoin created with the old method is considered 100% valid by all clients. Sorry, I'm not bitcoin or cryptographic expert, so I might be using the wrong language here, but I hope my basic point is clear: Accepting a bitcoin block as valid is not the same as voting as to whether a bitcoin block should be deemed valid... or am I missing something?
- alphamerik 15y agoThe problem is that if the cryptography is broken, in regards to #3, you have no idea if a token created with the 'old method' is real or counterfeit. In a decentralised service you would need to convert all old tokens into new tokens before the old cryptography was compromised, which requires work - you would be generating new coins, and would have an exchange rate. Or you could setup a centralised validation service for coins as the article suggests, before the cryptography was broken, to ensure people aren't creating fake money. I am not sure what you mean by accepting a bitcoin vs voting for a bitcoin, can you clarify? "Voting" doesn't look like a method they normally use for validation...
- ezyang 15y agoTo clarify this some more, if the hashing algorithm is sufficiently broken, then I can doctor an arbitrary transaction of bitcoins to where-ever I want. If the old bitcoins are that insecure, they will necessarily become worthless.
- illumin8 15y agoThis is very similar to the way the US Treasury handles physical currency updates. If I recall correctly, in the 1990s, Iraq still had a working money press that could print perfectly legitimate US dollars as fast as possible. PC printer technology had also advanced to the point where $20s and $100s were easily counterfeited. The US Treasury had to go through a transition period where new money with new security features were printed and the old money was taken out of circulation. I assume BTC will have to go through a similar digital verification. The way this would work in theory is that old BTC will be converted to new BTC on a 1 to 1 basis, but first each old BTC will need to be validated against the blockchain. You could just say that any BTC with over 1,000 confirmations is valid, since it is highly unlikely that so many confirmations could be falsified. Another way to convert from old-BTC to new-BTC would be to use the miners to validate each conversion. For example, if a sufficient number of miners verifies that yes, indeed a certain BTC appears in the blockchain, then that one is considered valid and is inserted into the new blockchain, and removed from the old blockchain. This algorithm could actually pay a new-BTC reward for validating old-BTC to the miners that validate each transaction, thus ensuring a sufficient amount of CPU power is dedicated to this process.
- DannoHung 15y agoCan someone explain to me how someone would be paid a salary in bitcoins?
- ColinWright 15y agoSomeone who has bitcoins and employs you, then transfers an agreed number of bitcoins to you in recompense. That seems obvious, so I'm sure I must have mis-understood, or not understood, your question.
- tptacek 15y agoIn what country is this arrangement lawful and enforceable?
- ColinWright 15y agoAh, now I see the point. In the UK I believe it's possible to agree a salary/payment at an amount of recognized currency, such as GBP or USD, and then you perform all your tax and related calculations based on that. How the payment is actually transferred is, potentially, up to the people involved. I believe that I can contract my services at, say, 100 GBP per hour, bill for one hour, and then accept payment in bitcoin, stating that there is an agreed rate of exchange. If the stated underlying rates are not regarded as "unusual" by the HMRC then most likely the arrangement would be permitted to stand. There are laws concerning "payment in kind" and I think this would fall under that. Note, I'm not an accountant or lawyer, but I've seen barter arrangements not dissimilar to this accepted as valid by HMRC.
- tptacek 15y agoIn the US, you can arrange payment "in kind" for lodging, food, and "other facilities", but they are accounted for in dollar-denominated values and their fair market value can be determined by the government --- and likely will be, as fair-market value for in-kind compensation is a hotbutton issue for people who want to e.g. screw their housekeepers out of wages. FLSA 3(m), also read the section in the FLSA handbook about "scrip" and "tokens" (which I understand bitcoin isn't --- scrip, which cannot lawfully be used as a wage substitute, only as an accounting mechanism for dollar-denominated wages) is at least backed by the full faith and credit of a company.
- aubergene 15y agoCouldn't the same argument be made of any protocol? Not all browser implement HTTP in the same way, IPv6 isn't compatible with IPv4, but all agree to switch, HTML is governed by a central body but a lot of the influence comes from the community.
- potatolicious 15y agoThe difference is that changing the HTTP protocol and moving to IPv6 won't wipe out people's savings and threaten the world economy...
- ezyang 15y agoRaise your hand if you like moon cakes. (To the down-voters: I wonder how many people managed to read to that segment of the article. I think the moon cake black market in China is independently interesting case of a currency with an expiration date.)
- weavejester 15y agoThe author doesn't appear to distinguish between a decentralised client and a decentralised specification. The authors of the official Bitcoin client have de-facto control over the specification, so the design of the Bitcoin protocol is effectively centralised. I don't think anyone sees this as a problem, because if people start disagreeing they can always fork the protocol. If a flaw is discovered in Bitcoin that requires a protocol change, I doubt we'll see any fragmentation. People fork projects over a wide range of reasons, but rarely over essential security patches.
- ezyang 15y agoThis misrepresents the tight interlock between client and specification. Suppose that there is a flaw discovered in Bitcoin that requires a protocol change. In a classic software system, the worst you'd have to worry about is a backwards incompatible protocol change; Bitcoin is designed with very little wriggle room in this respect. But furthermore, with Bitcoin, you have to worry about a change which existing Bitcoin clients will reject: for example, if you wanted to increase the reward given to miners. You can fork the protocol, but you can't fork the economy. This is true in normal projects, and doubly true for Bitcoin.
- weavejester 15y agoI'm not sure I understand your point. Yes, in order for a Bitcoin fork to succeed, you'd have to convince the majority of clients to use the new protocol. However, once you gained a majority, the Bitcoins generated by the old protocol would fall in value relative to the Bitcoins generated with the new protocol. If your Bitcoins are worth $100 using the new protocol, but only $50 using the old protocol, there's a strong financial incentive to start using the new client so you can sell your bitcoins at a higher rate and to a larger audience.
- ezyang 15y agoYes. I argue this "convincing" process is at the very least a centralized process, and at the worst deeply problematic.
- snorkel 15y agoThe actual Achilles Heel of Bitcoin is the sparse few exchanges that convert Bitcoin to hard cash. If these exchanges can not control price manipulation schemes among their traders then Bitcoin's value will quickly bubble and pop. What Bitcoin needs is to be accepted by an established trading exchange which would stabilize the real world price of Bitcoins.
- tptacek 15y agoBitcoin is an Achilles Centipede; that may be one of its many heels. Another: is its conflation of efficient transaction medium and store of value, as if the simple "scarcity" of cryptographic random numbers would allow it to hold value once people decide it's no longer a competitive way to conduct business. You see this in message board debates all the time, where bitcoin supporters, having been talked down from the notion that particularly idiosyncratic bit patterns in SHA256 hashes can ever have intrinsic value, resort to talking up bitcoin's utility as an cheap and anonymous Paypal; then, when confronted by bitcoin's manifest liabilities as a transaction media (for instance, the fact that it's so thinly traded that its price can jump double digit percentage points during the time it takes to clear a transaction), they revert back to the intrinsic value of mathematical scarcity compared to the oogie-boogie Federal Reserve.
- sneakycactus 15y ago"It is literally impossible to “change” the hashing algorithm in Bitcoin; any change would constitute a change in the protocol, and thus result in a completely new currency." This was something that came to my mind some time ago regarding Bitcoin, but I wasn't sure if it was possible, or at least practical. What's to stop other interested parties from changing the protocol/hash and creating myriad competing virtual currencies? Metacoin, Hashcash, Bitcoin++, Digidollars, Ameribits, Eurobits, Digigold, Ingots - you get the point. "Hi, my name is Fred, and this is my currency." We live in a world with a wide range of currencies and exchanges, so I suppose there could just as well be an exchange that supports as many digital currencies as could ever be conceived. But couldn't that also mean that Bitcoin could be devalued through confusion and obfuscation, its present reputation notwithstanding?