3 ms·
Responsible Professor here from Delft University, AMA. Note this is not a normal blockchain: its an offline-first blockchain [1]. Open source [2]. [1] https:/
by synctext 6y ago
Responsible Professor here from Delft University, AMA.
Note this is not a normal blockchain: its an offline-first blockchain [1]. Open source [2].
[1] https://tools.ietf.org/id/draft-pouwelse-trustchain-01.html https://tools.ietf.org/id/draft-pouwelse-trustchain-01.html
[2] https://github.com/Tribler/trustchain-superapp https://github.com/Tribler/trustchain-superapp
- elcomet 6y agoCould you give a high-level explanation of what's an offline-first blockchain here, and what's the difference between TrustChain and Bitcoin ? The draft seems very low-level and complex to read, and the article contains very few technical information.
- synctext 6y agoTrustchain is a ledger which is consensus-free. Forget anything you know about chains and ledgers. By using legally valid digital signatures it is possible to sign agreements which are irrefutable. If you have two parties which sign a contract, it become legally enforceable. Trustchain requires that any block is signed by multiple parties and thus become legally enforceable. Every transaction forms its own "micro-block". Mono-signature transactions are strictly not allowed (e.g. Bitcoin,Ethereum approach). Once signatures are added to a block its valid: instant finality. Weird... Yes, it's a strange approach, even older then Bitcoin :-) Perhaps its useful. See "bandwidth-as-a-currency" news item in BBC News, 1 Sep 2007, http://news.bbc.co.uk/2/hi/technology/6971904.stm http://news.bbc.co.uk/2/hi/technology/6971904.stm Edit: no native token or money creation. Its just fabric for recording transaction micro-blocks. Non-profit. So nothing like Bitcoin at all. So works very well with dApps, Distributed Apps, no smart contracts needed. Scientific publication about Euros, DAO, dApps, passport-grade identity deployment: https://dl.acm.org/doi/abs/10.1145/3428662.3429744 https://dl.acm.org/doi/abs/10.1145/3428662.3429744
- malikNF 6y agoWhat's a "legally valid digital signature" in the context?
- synctext 6y agoShort answer: nobody knows yet. Its taking shape. UK minister of Digital infrastructure only some weeks ago announce their vision, far away from running code and new laws [1]. Dutch secretary-of-state on same days also send his digital ID vision to parliament [2]. [1] https://www.gov.uk/government/publications/the-uk-digital-identity-and-attributes-trust-framework https://www.gov.uk/government/publications/the-uk-digital-id... [2] https://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2021Z02985&did=2021D06488 https://www.tweedekamer.nl/kamerstukken/brieven_regering/det...
- p_l 6y agoWell, in EU, there's existing digital signature law with (working) provisions for signing legally-binding contracts digitally... Maybe those are some new schemes under that framework?
- pqs 6y agoI'm Spaniard. My national ID has a chip and I use it daily to sign documents with a card reader and a password. You can change your password at police stations that issue ID cards. The signature is legally valid.
- littlestymaar 6y agoSo is there a reason to call it “blockchain” except for marketing reasons? (I'm currently working on a Paxos-based distributed system for an industrial application, and my client insist in calling that a “blockchain” in all internal communication because, you know “blockchain” sounds cool to them)
- synctext 6y agoDistributed ledger would be a better fit indeed. However, nobody then understands what it is. It offers tamper-proof micro-blocks, distributed validation, and leaderless governance. So this is more then idle marketing. But you're right, the name "Trustchain" is specifically tailored that government leaders and managers feel trustworthy and cool about it.
- johanneskanybal 6y agoI've dreamed of something like this too. I think it fills a good spot especially smaller transactions. I see parallels to the nordics bankid+swish, bank issued id/phone payment system. It's flawless in execution but both the id(!) and the payment part carries a cost picked up by the person accepting money (about $0.12 for each, very bank like). With your way of doing things none of the parts has to cost anything at the reasonable expense of potential double spending.
- DJBunnies 6y agoHow does one rotate keys, in the event of compromise?
- imtringued 6y agoIsn't this just a digital check? People can tamper with their app and their checks will bounce once reality catches up.
- synctext 6y agoYes, you need something against tampering. However, once you legally signed something, the contract/transaction is valid. Various mechanism can be used to ensure integrity. What we implemented specifically is that various witnesses can inspect your Trustchain blocks and co-sign your balance. So any node can act as a digital notary. You can also use a reputation or trust function. Here is a master thesis from Mathematics on distributed accounting systems. It contains numerous new mathematical proofs around integrity without strong identity assumption; .PDF "On the Sybil-Proofness of Accounting Mechanisms in P2P Networks", https://repository.tudelft.nl/islandora/object/uuid:6b4011c6-1668-4a1c-a49e-f86d226063b1 https://repository.tudelft.nl/islandora/object/uuid:6b4011c6...
- bluesign 6y agoProblem is you cannot have offline and privacy (or better anonymity) at the same time. Reputation and trust can be gamed. Also requiring reputation will slow down adaptation. I will read this paper in the evening but I don't think you can have Sybil-Proof Accounting on P2P without some tradeoffs.
- throwaway4good 6y agoIt would be wouldn't it? The double spend problem is not solved. And how could it be if it works offline. If I have a phone in some state s. Then I can just do the transaction and revert the phone's state back to s and spend the money again.
- fbn79 6y agoI think they solved by using a banner on the app that say "Don't do It bad boy! Or I'll say it to your mum".
- 6y ago
- nixpulvis 6y agoFirst of all, they clearly state the need for some amount of consensus here: https://tools.ietf.org/id/draft-pouwelse-trustchain-01.html#rfc.section.3.4 https://tools.ietf.org/id/draft-pouwelse-trustchain-01.html#... Second, if multiple parties are involved (I have to assume you mean more than just the needed 2 parties), wouldn't that mean you must be connected to a wider internet?
- CasperDern 6y ago> The customer scans the code, sees the amount to be debited, and presses OK. The amount then moves from one phone to another without the need for WiFi or another wireless network How does the business verify a transaction was successful? It seems like information only flows one way.
- rebuilder 6y agoCould you elaborate on double-spend protection a little? I skimmed the protocol draft and came away with the impression that the goal is not so much to prevent double spending directly as it is to flag users who do attempt it, so future payees know to refuse to do business with them. Did I understand correctly?
- synctext 6y agoExactly. Using protocols to prevent double spending hurts performance and scalability. Detect fraudsters and ignoring them is cheap. This is a fundamental issue I believe. If you have a stable legal ecosystem you can use the law of the land to ensure that double spending has real-world consequences. Preventing double spending is expensive. Guaranteed double spending _detection_ might also be sufficient and scales horizontally.
- michaelscott 6y agoI'm interested in your thoughts on the performance impact of double spend prevention. What algorithms have you looked at, working on this project?
- devos50 6y agowe are building upon our own lightweight, scalable distributed ledger which has been in development for many years now. This ledger is based on the swift detection of double-spend behavior. You can find details on the fraud detection algorithm in our peer-reviewed paper, see https://dicg2020.github.io/papers/devos.pdf https://dicg2020.github.io/papers/devos.pdf (an extended version is currently under review). We have also performed scalability experiments on our nation-wide compute cluster to estimate the throughput of our distributed ledger. These experiments hint that our ledger is easily capable of handling 100.000+ transactions/sec.
- tphyahoo2 6y agohttps://standardcrypto.wordpress.com/2021/03/10/the-your-papers-please-argument-for-cbdcs/ https://standardcrypto.wordpress.com/2021/03/10/the-your-pap... The "your papers please" argument. It's true. If you live in a world where you are compelled to present an identity for any financial transaction, then there is no need for bitcoin, to prevent double spending.
- wrnr 6y agoHow is this linked to an iban account. Is it a bit like a one off sepa? I've always been curious as to why iban is not used more, say I don't care for credit cards and just want to trust my customers.
- p_l 6y agoWell, IBAN is just universal account number. The actual transfer systems are more complex and differ heavily between EU countries. You have SWIFT, which is general correspondence-based system for international transfers, of which SEPA is essentially a special agreement on how certain setup of SWIFT transfers are to be handled (essentially if you select certain transfer parameters you fall under agreement rules, otherwise not). Intra-country transfer systems have more variability, unfortunately I can only speak about how UK and Poland did it, with UK having a very legacy numbering scheme where you only touch IBAN when you do international transfers (at least when I dealt with it last time in 2014), whereas in Poland all banking uses IBAN accounts (minus PL prefix) because that's what national interbank clearing system uses - and by extension paying for things by bank transfer are the norm, with widespread usage of the large "address space" of IBAN to create individual accounts even per contract (for example, if you take a loan, or pay for some service, you will usually pay to a bank account made just for that contract). Ultimately, the difference is that there's effectively no extra cost for handling bank transfers in Poland, the clearing happens fast enough (usually max 1 business day, there are multiple clearing batches per day and it essentially depends on whether your transfer enters the system before the last batch of the day is calculated - with UK, I encountered multi-day wait times). Since there are no cheques, you essentially have three options - cash, bank transfers, and cards - and accepting bank transfers is the simplest approach outside of "cash direct in hand". An ecosystem of utilities to make it even simpler had grown out of making common simple & fast way of doing electronic transfers.
- kmlx 6y ago> with UK, I encountered multi-day wait times with Faster Payments local transfers in the UK happen instantaneously. this has been the case for more than a decade. all banks participate and makes transferring funds in the UK a breeze. to give you an example as to how fast this payment system is: i press pay and the money is received on the other end before the “successful transfer” screen pops-up on my device :) for international payments i’ve noticed that it takes less time to receive money from the UK than it is for the receiving party to do a local transfer :) it’s mind boggling honestly. https://en.m.wikipedia.org/wiki/Faster_Payments_Service https://en.m.wikipedia.org/wiki/Faster_Payments_Service
- bluesign 6y agoThere doesn't seem any privacy references in the draft. Can you give a bit information about privacy side?
- synctext 6y agoThat is a lengthy story.. We basically forked the Tor protocol and decentralised it. This makes it Bittorrent friendly, offer end-2-end crypto, and would scale to Internet-wide usage. We're planning to port our deployed Python Tor-stack towards Kotlin for the Superapp and Trustchain. Specifications: https://github.com/Tribler/tribler/wiki/Hidden-Services-Specifications-for-anonymous-seeding https://github.com/Tribler/tribler/wiki/Hidden-Services-Spec...
- bluesign 6y agoThanks, my question was most inline with comments here about double spend. Detecting double spend is easy as you said, but I am curious about the consequences. Will this system will be somehow connected to real IDs? Who will in the network will have access to this data? If so what is the process hiding my real ID from my identifier? I did shopping at the market, what will prevent them to see my all spending history? If it is not connected to real ID somehow, what is preventing me to create a new identity?
- synctext 6y agoThat is the golden question. How anonymous will the upcoming digital Euro be? Politicians and European Central Bank will decide on this soon. Delft University has tested out technology which could offer equal privacy as cash money. Will this be legal?
- Proven 6y agoIf that's the case why does the government have to be involved? From the article: > In contrast, the digital euro is free. It's interest-free: it comes with a built in 2% (target) theft through inflation. It may have no transaction fee, but just owning it costs 2% per year, compared to major cryptos that bear interest and appreciate. Not a hard choice....
- riffraff 6y agohow does this compare to GNU Taler[0] ? [0] https://taler.net/en/ https://taler.net/en/
- synctext 6y agoIts different mostly in the methodology and requirements. GNU Taller is developed without input by governments or existing legal frameworks. Christian Grothoff has done pioneering work for years. Its ideology driven, not government driven. We're different. We are trying to ensure compliance with very complex eIDAS regulations, GDPR, KYC, and AML. In partnership with governments and Brussels are trying to discover what is possible and desired.
- kitkat_new 6y agoCould you be a little more specific how these aspects manifest themselves, please?
- sigio 6y agoPlease... don't name your protocol IPv[0-9] when it's not a RFC-based IP protocol.
- TeMPOraL 6y agoThat first link seems to claim it's an (expired?) IETF draft on its way to become a RFC.
- rahkiin 6y agoIs there a specific reason there are only Android apps in the repository? Is there a restriction in iOS that makes this app not portable, or were researchers only known with the Android ecosystem?