19 ms·
A from-scratch tour of Bitcoin in Python
- ubi3921 5y ago> We don’t just get to share code, we get to share a running computer, and anyone anywhere can use it in an open and permissionless manner Can someone explain what this means? Its not explained anywhere in the post.
- counternotions 5y agoPresumably a reference to blockchain as a distributed ledger.
- legutierr 5y agoHe is probably referring to Ethereum, which was conceived as a "global computer", operating in an open and permissionless manner.
- jazzyjackson 5y agoEthereum extends the concept, but Bitcoin transactions are programs running on the global blockchain (well, the op codes are executed by a single node, but the result is published and verified by the network, if I understand it right) But just wanted to make the point that Bitcoin is a global computer as much as ethereum is, Solidity is just Turing complete while (Bitcoin’s) Script is intentionally limited to a few instructions.
- isoprophlex 5y agoHe links committing transactions to the blockchain to storing state in a distributed data structure... which is of course, in the case of Bitcoin, implemented in arguably the most wasteful, ham-fisted, environmentally disastrous way possible. There's also the ethereum VM which is a slow decentralized state machine capable of executing code...
- plebianRube 5y agoCheck yourself.All progress was 'wasteful' with resources at one time. And yes, bitcoin is progress.
- tsimionescu 5y agoAll progress was 'wasteful' at some point, but all 'progress' is wasteful. And yes, bitcoin is 'progress'. I suppose Bitcoin is better than gold. Unfortunately, for BTC, we already have much more advanced financial technology.
- plebianRube 5y agoPermissioned legacy technology is not advanced. The stronger, harder money wins. Good luck with your guess.
- tsimionescu 5y agoI am specifically thinking of fiat money, based on burrowing and fractional reserve banking. This has addressed many historical problems with fixed money/value supply that Bitcoin would have if it ever caught on.
- aazaa 5y agoYou can think of the Bitcoin block chain as the state of a globally-accessible machine. The state is updated through the publication of valid blocks, each of which builds on a previous block. A block is composed of transactions, each of which incrementally advances the machine's state. Each transaction contains a small program "script" that defines the conditions for the state transition it causes. There's this persistent misconception out there that only Ethereum works this way. It's a testament to marketing. Bitcoin has been doing "smart contracts" long before Ethereum was even a gleam in Vitalik's eye.
- spinny 5y agoBitcoin's script language is very restricted, claiming that Bitcoin has been doing "smart contracts" is disingenuous to me. I wouldn't call a bitcoin script as "smart". Ethereum was born because of this
- aazaa 5y agoScript is restricted, but it permits everything outlined by Nick Szabo's definition. As Wikipedia notes: > Smart contracts were first proposed in the early 1990s by Nick Szabo, who coined the term, using it to refer to "a set of promises, specified in digital form, including protocols within which the parties perform on these promises". https://en.wikipedia.org/wiki/Smart_contract https://en.wikipedia.org/wiki/Smart_contract We don't get to decide what smart contracts are. Nick Szabo decided long ago. Marketing vs reality has been a big problem in this space.
- olalonde 5y agoBitcoin transactions, or more precisely transaction outputs, are little scripts that are executed in a VM. To spend a transaction output, you have to "solve it" by providing it an input which makes it return true. The most common transaction script checks that you possess a private key through a signature check, but it's possible to make more complex scripts like the "Pay To Multisig" script. Of course, Bitcoin scripts are quite limited and, unlike Ethereum smart contracts, they are non-Turing-complete and can't store state. Permissionless just means anyone can create transactions because there's essentially no way to block someone from doing so, unlike say a transaction on PayPal.
- adamnemecek 5y agoKind of surprised Andrej has time to work on anything besides self-driving cars
- dswalter 5y agoIt's maybe an ... interesting sign that someone with substantial liquidity from tesla shares at this point in history is apparently finding cryptocurrency an enjoyable diversion/investment vehicle?
- js4 5y agoI was thinking the same thing.
- yumraj 5y agoMaybe he is losing faith in self driving cars and is looking for an alternate field.
- malux85 5y agoDiversification of interests accelerates creativity due to axiomatic discovery and reinforcement, idea plasticity and abstraction practice. Other interests are not just important, they are necessary.
- GeorgeTirebiter 5y agoRight. All really smart people 'play'. Famously, Feynman was spinning plates in the Caltech cafeteria on his fingertip, which gave him the ideas that ended up winning him a Nobel prize. Play is important for children of all ages.
- karpathy 5y agoSurely You're Joking is one of my all time favorite books, for sure.
- karpathy 5y ago
- torcete 5y agoI wonder how strong would Elliptic Curve Cryptography be compared to other methods if there is a major breakthrough in quantum computing.
- IncRnd 5y agoShor's algorithm, which runs partially on a classical computer and a portion on a quantum computer, breaks elliptic-curve cryptography.
- plebianRube 5y agoYes, with major caveats - knowing the public key and having 100s of messages signed by corresponding private key. Nowadays people only expose their public key one time per transaction, and never reuse their address. So to steal coins, not only do you have only ~10 mins between blocks to find the private key, currently Shor's algorithm is unfeasible with only 1 signed message.
- tromp 5y agoNot only do many people still reuse keys, but there is also still a huge amount of bitcoin in P2PK outputs, i.e. with exposed public keys.
- deleted 5y ago[deleted]
- erostrate 5y agoSorry if that's a naive question but why do you need several signed messages? If you have a quantum computer and a quantum period finding function don't you get immediately the discrete log? Assuming you have one public key (not hashed) doesn't that give you the private key immediately?
- plebianRube 5y agoBroadly speaking, more signed messages can get you more points on the curve you're trying to guess. https://www.cs.umd.edu/~amchilds/teaching/w08/l03.pdf https://www.cs.umd.edu/~amchilds/teaching/w08/l03.pdf May help if you're actually interested. Edit: More signed transactions help with the classical and not the quantum part of schor. Edit2: Schor has not yet even been able to factor the integer 35 with current quantum hardware, too much interference.
- hermitsings 5y agoThis dude writes stuff hitting the sweet spot!
- 21eleven 5y agoLooks like the exercise left to the reader has been completed: https://www.blockchain.com/btc-testnet/tx/182bf9202649ded3a668d48a57b774614181479f7c2e9a9bcd160afaa3179bec https://www.blockchain.com/btc-testnet/tx/182bf9202649ded3a6...
- noxer 5y ago0.00090000 BTC moved 0.00005000 BTC Fees Thats 5.55% On the test net! On the real net it would be like 20% or more in fees.
- bogota 5y agoFees are dictated by the user and the time they have for the transaction to take place. The fee could have been much lower. I think we are well past the point of debating if bitcoin layer one will be used for day to day transactions however. A custodial service or lighting will have to be used for that. Additionally most people treat bitcoin closer to gold than a dollar currently.
- noxer 5y agoI disagree but wont bother explain why because I know you dont care.
- AlexAndScripts 5y agoThen why bother writing that useless comment?
- noxer 5y agoWhy ask that useless question?
- read_if_gay_ 5y agoPointing out that something is useless isn't useless in itself. You can take it down a nihilistic path by claiming that it is in fact useless, but that argument just spins in circles forever because it applies to itself.
- kozak 5y agoI'm amazed that he has time for this kind of hobby work.
- yellow_lead 5y agoFor others: Andrej Karpathy is the director of artificial intelligence and Autopilot Vision at Tesla. Was on front page yesterday for a presentation on Tesla's Autopilot / Autonomous features: https://www.youtube.com/watch?v=NSDTZQdo6H8 https://www.youtube.com/watch?v=NSDTZQdo6H8
- mlcrypto 5y agoMaybe most of his job is hype & marketing without delivering much
- ketamine__ 5y agoFSD rollout has been delayed many times. He's underperforming.
- nexuist 5y agoThis is a very cynical way of looking at development progress. Did the iPhone team underperform by shipping in 2007 instead of 2005?
- animex 5y agoOr Elon is over-performing.
- throwkeep 5y agoHe's almost certainly a 100x engineer.
- ketamine__ 5y agoHas he saved 100x lives with FSD?
- deleted 5y ago[deleted]
- msgilligan 5y agoThis is reminds me of Ken Shirriff's 2014 "Bitcoins the Hard Way" blog post that also used Python to build a Bitcoin transaction from scratch: http://www.righto.com/2014/02/bitcoins-hard-way-using-raw-bitcoin.html http://www.righto.com/2014/02/bitcoins-hard-way-using-raw-bi... (The subtitle of the blog is "Computer history, restoring vintage computers, IC reverse engineering, and whatever" and it is full of fascinating articles, several of which have been featured here on HN)
- animex 5y agoNo, the hardest way is using pencil and paper to mine a block :) https://gizmodo.com/mining-bitcoin-with-pencil-and-paper-1640353309 https://gizmodo.com/mining-bitcoin-with-pencil-and-paper-164...
- rantwasp 5y agotechnically it said “the hard way” not “the hardest way”. also, computing a hash != mining. mining needs forming the block and computing the hash
- alpb 5y agoThat's basically just a SHA256 hashing on pen and paper, doesn't have much to do with how bitcoin works.
- jazzyjackson 5y agoTo be fair, performing sha256 hashing is kind of the only work that Bitcoin is doing, from a kilowatt hour’s perspective.
- Saig6 5y agoSame guy, Ken Shirriff
- samlewis 5y agoShameless self-promotion but there's also this post I wrote in 2017 if anyone interested in a slightly different take (but a very similar write up to the OP): https://www.samlewis.me/2017/06/a-peek-under-bitcoins-hood/ https://www.samlewis.me/2017/06/a-peek-under-bitcoins-hood/ Cool that this article implements the cryptography primitives, though! e: Funnily, like the article, I also stored some BTC in a wallet and challenged people to (manually) take/steal it. At the time it was worth $10 USD.. now it's worth $123 USD!
- noxer 5y ago"...Bitcoin is a living, breathing, developing code base that is moving forward with new features to continue to scale..." There is exactly zero progress to make it scale in the last 10+ years.
- wyager 5y ago> There is exactly zero progress to make it scale in the last 10+ years. Lol, literally this week: https://taproot.watch/ https://taproot.watch/
- noxer 5y agoTaproot doesn't make bitcoin scale its mainly to increase privacy.
- wyager 5y agoTaproot decreases the size of multisig and other complex transactions significantly, in the happy path of a cooperative signature. It also enables Schnorr, which produces smaller signatures than ECDSA. It also contains features to further improve the efficiency of Lightning, which is a shockingly effective scaling mechanism.
- simias 5y agoLightning doesn't work because it either leads to a chaos of routing that doesn't scale or it ends up centralized and you lose the point of bitcoin in the first step. And don't bother coming up with hand wavy explanations of how it could work, some day. People have been talking about Lightning for years, literally billions of dollars have been poured into the "tech", the fact that even bitcoin enthusiasts barely ever use it is all the proof I need. I wonder how many more years of empty promises we'll have to suffer through before people accept that cryptocurrencies are a very good pyramid scheme with a thick layer of technobabble around it.
- nednar 5y ago
- toxik 5y agoIf you, like me, were curious about what the secret key 1 is on the mainnet, then here you are: 1 1BgGZ9tcN4rm9KBzDn7KprQz87SZ26SAMH https://www.blockchain.com/btc/address/1BgGZ9tcN4rm9KBzDn7KprQz87SZ26SAMH Some others: 2 1cMh228HTCiwS8ZsaakH8A8wze1JR5ZsP https://www.blockchain.com/btc/address/1cMh228HTCiwS8ZsaakH8A8wze1JR5ZsP 3 1CUNEBjYrCn2y1SdiUMohaKUi4wpP326Lb https://www.blockchain.com/btc/address/1CUNEBjYrCn2y1SdiUMohaKUi4wpP326Lb 42 1EMxdcJsfN5jwtZRVRvztDns1LgquGUTwi https://www.blockchain.com/btc/address/1EMxdcJsfN5jwtZRVRvztDns1LgquGUTwi 1337 1DN76uuAUDY1DLxABD3JAyunhhAreJbCjT https://www.blockchain.com/btc/address/1DN76uuAUDY1DLxABD3JAyunhhAreJbCjT
- delaaxe 5y agoThanks, I was wondering the same but too lazy to figure out the addresses!
- zikduruqe 5y agoIf you are really curious, all the secrets are out there. https://keys.lol/bitcoin/224868539337681284334442086789769487062499115521269460747326812921128882966 https://keys.lol/bitcoin/22486853933768128433444208678976948... Finding one with a balance is the hard part.
- delaaxe 5y agoI was wondering if monitoring those starter addresses could be lucrative... They've transacted quite a lot
- blocked_again 5y agoThat's a lot of upvotes. Do you folks really spend hours going through the whole blog post? I for one can never go through the whole blog post. My brain would be shouting at me the whole time to work on something that can generate passive recurring revenue instead.
- DrNuke 5y agoThat’s neat, as a case study for implementation at the very least. Thanks!
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- jaycroft 5y agoOne little nitpick: the checksum error probability should be more like 9 nines. The checksum contains 4 bytes, not 4 bits, and so the false positive rate should be about 1 in 2^32, not 1 in 2^4. "The raw 25 bytes of our address though contain 1 byte for a Version (the Bitcoin “main net” is b'\x00', while the Bitcoin “test net” uses b'\x6f'), then the 20 bytes from the hash digest, and finally 4 bytes for a checksum so we can throw an error with 1 - 1/2*4 = 93.75% probability in case a user messes up typing in their Bitcoin address into some textbox."
- sethgecko 5y agoI’ve made something similar in order to learn how everything works and made it into a python library. Everything is in pure python with no dependencies, only std lib. I’ve implemented all the crypto stuff, address generation including HD, transaction serialization and even the bitcoin script. https://github.com/mcdallas/cryptotools https://github.com/mcdallas/cryptotools
- mountainboy 5y agorespect.
- RyanGoosling 5y agoBitcoin is taking up all the water
- runbathtime 5y agoIn Step 1, he explains how to create a cryptographic identity- the private public key pair. I came across an argument that a number cannot be property or owned because you can't legally own a number. If this is true then you can't own UTXOs associated with a private key or a cryptographic identity. I do think that bitcoin is fundamentally too complicated to understand, mathematically, for most people- myself included. I would argue everyone needs to do this exercise, from scratch, and also understand what they are doing (the math), to have confidence in bitcoin payment network. Anyone who thinks you don't need to get it is most likely in it for speculation alone. With something so abstract like bitcoin, it has a much larger uphill battle for understanding than a physical commodity like Gold, the precursor of paper dollars.
- modeless 5y agoYou don't own the number that is your private key, just as you don't own the number that is your bank account PIN or balance. What you own is space on the blockchain. And just as you don't need to tour the mint to have confidence in the dollar, or implement Diffie-Hellman to have confidence in your TLS connection to Amazon, you don't need to understand elliptic curve cryptography to have faith in Bitcoin.
- runbathtime 5y agoA bank account balance is representative value of dollars that bank owes you. If someone tries to steal it by pretending to be you even if they just steal your PIN, they are committing fraud. If someone steals a private key by committing another crime like stealing a laptop, that is a crime because you own the laptop. If they learn of your private key without committing a crime, that is not theft. You don't own 'space on the blockchain.' I have no idea what that even means. You do need to understand elliptic curve cryptography to have confidence (not faith) in bitcoin because you make the transactions in bitcoin. You are responsible, not some third party. People understand the dollar because it is physical and you can get them on demand and they originally got their value from Gold, not some abstraction like proof of spent energy one time awhile back.
- plondon514 5y agoTaking this opportunity to promote my side project codeamigo and a tutorial I wrote for building your own Bitcoin wallet https://codeamigo.dev/lessons/start/53 https://codeamigo.dev/lessons/start/53
- Cantinflas 5y ago"NIST publishes recommendations on which ones to use, but people prefer to use other curves (like secp256k1) that are less likely to have backdoors built into them" Does this make any sense? How is a curve going to have backdoors on it? Or he means a specific implementation? Or is this a joke? I'm confused
- stcredzero 5y agoThere's been a history of mathematical information used in cryptography produced by the NSA, for which it's later revealed, they had pre-developed an attack. Example: the s-boxes of DES.
- foo92691 5y agoExcept NSA strengthened DES against this not-yet-known-to-the-public attack (differential cryptanalysis). https://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA's_involvement_in_the_design https://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA's... https://en.wikipedia.org/wiki/Differential_cryptanalysis#History https://en.wikipedia.org/wiki/Differential_cryptanalysis#His...
- stcredzero 5y agoWhile keeping DES to 56 bits, to keep the attack within reach.
- inter_netuser 5y agoECC NIST curves were proposed by the NSA. They have some unusual hand-selected constants that nobody quite understands exactly why they were selected. https://miracl.com/blog/backdoors-in-nist-elliptic-curves/ https://miracl.com/blog/backdoors-in-nist-elliptic-curves/ “Working in collaboration with the NSA, NIST included three sets of recommended elliptic curves in FIPS 186-2 that were generated using the algorithms in the American National Standard (ANS) X9.62 standard and Institute of Electrical and Electronics Engineers (IEEE) P1363 standards.”: What exactly is NIST’s justification for making claims regarding the method that NSA used to generate these curves? The fact that a hash matches is publicly verifiable, but the distribution of “random” inputs is not. I have heard NSA employees claiming that the “random” inputs were actually generated as hashes of English text chosen (and later forgotten) by Jerry Solinas." https://csrc.nist.gov/CSRC/media/Publications/sp/800-186/draft/documents/sp800-186-draft-comments-received.pdf https://csrc.nist.gov/CSRC/media/Publications/sp/800-186/dra... It's all quite public.
- halotrope 5y agoImplementing things from scratch is probably the ultimate test of thorough understanding. Chapeau! On another note I am amused that Mr. Karphathys name describes exactly what he is doing in his day job.
- sombremesa 5y agoSometimes implementing things from scratch is the ultimate proof of thorough misunderstanding.
- delaaxe 5y agoThat's very true, I don't know why you're getting downvoted
- ijlx 5y agoAn excellent example of nominative determinism!
- yerwhat01010 5y agoI don't get it. What does the word "Karpathy" mean or sound like?
- aaronax 5y agoCar pathing, as in getting cars to drive along a path.
- davidhowlett 5y ago"car path ey" sounds like a thing connected to finding paths for cars.
- yerwhat01010 5y agoD'oh. I was trying to think of a connection between "Karpathy" and Bitcoin.
- colordrops 5y agoDoes this blog entry hang Brave on Android for anyone else? Happens on two phones for me.
- Thorentis 5y agoYep, just happened for me. Hangs and can't scroll.
- archon810 5y agoHangs Chrome for Android completely too.
- archon810 5y agoCreated a bug report https://bugs.chromium.org/p/chromium/issues/detail?id=1222833 https://bugs.chromium.org/p/chromium/issues/detail?id=122283....
- astroanax 5y agoDisabling js doesn't make it hang anymore for me.
- igravious 5y agoSuper interesting and informative, I learned lots that I didn't already know. Who are the cryptominers on the testnet btw?
- m00dy 5y agoHis implementation is missing Taproot :)
- anonporridge 5y agoTo be fair, taproot isn't live on mainnet yet.
- deleted 5y ago[deleted]
- headsupftw 5y agoTwo days in a row I see this Karpathy name on the front page of HN on two totally unrelated subjects. It almost feels like this is simulated world and something is wrong.
- shaklee3 5y agoHe's seni-famous even before working at Tesla
- fredfoobar 5y agoBitcoin is surprisingly easy, I'm currently working on a similar thing, but in Pharo/Smalltalk (I took it up as a project to learn Pharo). It's been pretty nice so far.
- akbirthko 5y agoAndrej is an excellent teacher. I got into ML because of his blogs and Stanford's CS231n course (which he also started).
- uyt 5y agoIn python 3.9 you don't need to implement extended euclidean and inv, you can just do `pow(x, -1, mod)`
- globular-toast 5y agoI wish people would put this much effort into learning git, which is actually useful. It's very similar.
- onebot 5y agoThis is great, love it.
- AzzieElbab 5y agoGreat post. One day someone will do Bitcoin from scratch in Scratch
- cf499 5y ago# secret_key = random.randrange(1, bitcoin_gen.n) # this is how you _would_ do it I know the article is mainly for learning purposes but someone should point out that the `random` module in python is not meant for cryptography. Please use the built-in `secrets` module or `os.urandom` instead.