9 ms·
Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has be
by doomroot 5y ago
Context on what I believe they mean by "fraudulent".
Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users account instantly for a better purchase UX.
Turns out anyone with some deeper understanding of bitcoin could construct another transaction spending the same bitcoin back to themselves before their original transaction was ever put in a block. The bitcoin community moved away from accepting '0 conf' transactions pretty much everywhere because of this reason.
In fact the high fee era (2016-2018) saw many wallets incorporating this "double spend" feature into their wallets. This is known as RBF, "replace by fee" and is really useful when you need to bump your transaction up the queue. You replace your old transaction, that is waiting to be mined, with a new one that offers a higher fee to incentivize miners to add it to a new block.
I think its rather unfortunate that 0 conf transactions were written off so quickly. There are many context where a 0conf tx makes sense, mostly IRL. But, if you are running a business online and you don't trust you customers you should wait 3-6 blocks after the transaction has been mined before delivering your goods.
- exitb 5y agoShouldn’t it make most sense in contexts exactly like Steam, where the merchant can take the goods back in case of a fraudulent transaction?
- gambiting 5y agoIt did, and they did. That's probably exactly why they allowed it like that in the first place - if the transaction is fraudulent then simply remove the user's entitlement, but offer instant access for better experience.
- agentofoblivion 5y ago“Fraud” and “simply” don’t belong in the same sentence. This is coming from someone who’s spent years working with many fraud departments in major companies. Wack-a-mole doesn’t work, they just scale their account creation.
- gambiting 5y agoWell then please explain what is difficult here. You initiate a purchase with bitcoin, valve instantly grants you access, then few hours later valve checks if the transaction has been confirmed in the blockchain or not. If it hasn't, then the entitlement is removed. What's not simple about it?
- srcreigh 5y agoWhat about people who do this 10x a day to play free games forever?
- ric2b 5y agoForce brand new accounts with no purchase history to wait for the transaction to confirm?
- Siira 5y agoThe UX sucks sufficiently that it shouldn't affect their bottom line.
- naniwaduni 5y agoHow much worse is this than people who do this 0.5x a day with 48-hour returns?
- gambiting 5y agoYou let the user do it twice then ban them from using bitcoin payments?
- SkittyDog 5y ago
- usrusr 5y agoThen the next question is this: why did those 50% even bother to try? Reselling for less btc (or fiat) keys that would soon be revoked? Has piracy decayed to the point where desperate consumers would really fall for something like that?
- judge2020 5y ago> keys that would soon be revoked The BTC acceptance didn't even vend keys, it was just access on the primary steam account.
- marcus_cemes 5y ago> There are many context where a 0conf tx makes sense, mostly IRL. I'm curious, like what? To me this is more like "someone wrote a cheque but there's no guarantee that they'll give it to you".
- deleted 5y ago[deleted]
- qvrjuec 5y agoI think more like "someone wrote a check and there's no guarantee it won't bounce". So really, it's quite analogous to how 0conf works in practice.
- tomc1985 5y agoThere are laws in place that specifically handle writing bad checks. While I'm sure double-spending Bitcoin transactiosn is illegal in some way, it is probably covered under a more nebulous fraud-type statute. I'd be curious to see the percentage likelihood on both, as well, as I suspect they are very different. Would businesses accept checks if half of them were bad?
- HWR_14 5y agoThe general fraud crimes you would get convicted of have a pretty nasty set of penalties. But good luck convincing a federal prosecutor to care about $20 worth of online goods that can be revoked.
- alickz 5y agoI only have a layman understanding of bitcoin, and I've never used a cheque in my life, but would it not be more like "someone wrote you a cheque and there's no guarantee it won't bounce when you try to cash it in"? Which, again maybe showing my complete lack of knowledge of cheques, is how I thought they worked in the first place.
- egberts1 5y ago
- aasasd 5y ago> and you don't trust you customers Seeing as “remember the password” does about nothing in the desktop app on my own machine near which only I ever come—Steam's attitude toward the users is crystal clear, and I'd say it's weird that they lived almost two years with that arrangement.
- sangnoir 5y agoConvenience and security are always in tension - and steam account takeovers are very common, as they can have tradable assets worth hundreds or thousand of dollars.
- delusional 5y agoIn the same era steam stored your password on disk if you used "remember my password".
- sidewndr46 5y ago> Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Why? Why would anyone ever accept this?
- philsquared_ 5y agoBecause I am pretty sure it isn't true. I am one of the few people who used bitcoin on steam during this time and I don't remember it ever being instant. I would like to see clarification to the top point because I don't think it is true... In my opinion when he says "fraudulent" he is probably talking about how people would use it to avoid bans. Steam would track banned users that remake accounts by checking their CC. They would also verify the people by making sure the address on the CC was close or the same to the address on the account. With Bitcoin you could avoid any tracking from remaking an account which leads to more 'bad actors' using Bitcoin. For reference you needed to spend something like $5 - $10 to enable trading on the platform. From their people would phish, scam, and break the TOS on the account.
- doomroot 5y agoI used bitcoin all the time on steam and there was a time when they were using 1 conf but the majority of the time they used 0 conf with bitpay. Couldn't find anything official with a quick goog but here is a reddit comment from 5years ago corroborating 0 confs on steam: https://www.reddit.com/r/Bitcoin/comments/6arpvq/comment/dhgv3dq/?utm_source=share&utm_medium=web2x&context=3 https://www.reddit.com/r/Bitcoin/comments/6arpvq/comment/dhg...
- philsquared_ 5y agoIt is possible I am incorrect then. I remember it always taking 5 - 10 minutes before any funds hit my account. I never actually counted the confirmations so it is very possible I am just wrong and they were doing 0 conf. At the same time I am surprised BitPay would have been structured this way and not experience a major attack...
- LanceH 5y agoYou say wait 3-6 blocks -- which makes sense for large transactions, but are there cases where 1 blocks have been getting reversed? Is this happening now because some parts of the network are on stale or diverging info?
- doomroot 5y agoThese are called "orphan blocks" and they happen very regularly, like everyday. https://bitcoin.stackexchange.com/questions/2170/how-often-forks-occur https://bitcoin.stackexchange.com/questions/2170/how-often-f...
- freeAgent 5y agoThat’s not really a double spend issue, though. Usually the blocks are found within a very short time between them. Unless the double spender is coordinating with a miner, orphaned blocks are a non-issue. It’s 51% attacks that would be the real problem.
- LanceH 5y agoThis is the answer to what I was asking. Not sure who I offended to get downvoted. edit: I guess my point is that if you're selling coffee and making 100 $6 transaction, going 1 block deep probably isn't a big deal. If you're selling one car a month, you might not want to risk the small chance of an orphaned block -- but a one hour hold on title is a whole lot better than waiting for a check to clear.
- ezoe 5y agoYou don't even need to do anything on bitcoin side if you value the 0 confirmation. You offer the goods or services before you receive the payment. It's like a restaurant that serve the food first and receive payment later. The restaurant do that because they trust the customer to pay up.
- elcomet 5y agoThis doesn't work,people don't know the amount to pay before they finish their meal.
- hayd 5y agoYou pay up front in most cafeterias for example. More likely the reason this isn't done is to allow customers to buy more (drinks/dessert, do so in a single transaction, and tip post-service. Not because the amount is unknown.
- elcomet 5y agoYeah but they verify that you pay before giving you the food. That's exactly the opposite of what op was talking about.
- kadoban 5y agoDepending on what it is, 3-6 is a _lot_. For something like a Steam game, it seems like waiting for 1 should be more than enough. I say "more than enough" because can't they just revoke the key of whatever was purchased if it gets double-spent? Seems easy enough.
- doomroot 5y ago> it seems like waiting for 1 should be more than enough. Not in bitcoin land, orphaned blocks happen a few times a day: https://bitcoin.stackexchange.com/questions/2170/how-often-forks-occur https://bitcoin.stackexchange.com/questions/2170/how-often-f... If you're willing to tolerate this risk then by all means go for it. (I'm with you I think steam should be able to tolerate this risk.)
- bavell 5y agoFYI the answer in that link is from 2013, not sure how much it's changed since then but I doubt it's the same today.
- doomroot 5y agoA feature of bitcoin is it’s stubborn system stability and resistance to change :) One of the odd benefits of this is that old forum posts and discussions have a good chance of being relevant. Although I will say lots of progress has been made in p2p message propagation (since this isn’t directly a part of consensus) which could definitely prevent orphan blocks, so you may be on to something in this case.
- kadoban 5y agoYeah, the biggest effects on the number of orphaned blocks should be the number of distinct mining pools and the latency between them. I could see some of those numbers changing enough to matter since 2013, but I'm not all that sure.
- kevincox 5y ago
- donkarma 5y agoIt was my understanding that RBF does not work by double spending, but by making a transaction with a much higher fee that depends on the parent transaction which means you would need to mine both to get the higher fee.
- sparkie 5y agoThis is known as CPFP (Child pays for parent)
- freeAgent 5y agoBCH is trying to keep 0-conf alive by eliminating the artificial block space constraint, removing RBF (which is really dangerous when you have an RBF-flagged grandparent tx that maybe your wallet is t looking for), and implementing double spend proofs to warn tx recipients as soon as a double spend tx appears on the network. It’s obviously impossible for an unconfirmed Bitcoin tx to be guaranteed secure, but the risk can be minimized, which is nice for everyday, low value transactions.
- doomroot 5y agoWith no RBF how will you prevent TX's from getting stuck in a high fee environment? I know BCH thinks block space should be unlimited which means TX fees will never get high but i don't think the economics works out there.
- freeAgent 5y agoMiners can set their acceptable minimum fee levels and orphan the blocks of miners who accept transactions with fees that they think are too low. This is essentially cartel behavior with an incredibly strong enforcement mechanism. There should never be a “high fee environment” due to an artificially low block size cap.
- doomroot 5y agoAnd why can't miners do this on BCH?
- freeAgent 5y agoThat’s the point. They can. Are you reading this as me thinking the collusion on minimum fee levels between miners being a bad outcome? I think it’s going to become necessary as the block reward goes to zero, and therefore it’s necessary and good for the system. It’s nice that Bitcoin (including BCH in “Bitcoin”) has a the block orphaning mechanism for enforcing cooperation in this manner. It’s much stronger than enforcement mechanisms available to cartels such as OPEC.
- rmbyrro 5y agoAppreciate the explanation, thank you. I was imagining it was something on the line of drug cartels and human traffickers laundering money through trading game assets.
- mFixman 5y agoHow would you prevent the fraudulent transactions you just posted if you accept 0 conf proof?
- elevenoh 5y ago>Steam back in the day used to accept 0 confirmation bitcoin spends This is ridiculous. 1 block confirmation would've prevented near-all transactions from being retracted.
- kirso 5y agoCorrect, but why to deal with this at all considering the % of all BTC TXs compared to fiat.
- pinephoneguy 5y ago>SSH caused serious security problems >I don't know what "null cipher" means but it sounds very technical and is probably the best one. The whole UX excuse is a bit silly considering modern Steam games take an hour to download anyway.
- lawn 5y ago> The bitcoin community moved away from accepting '0 conf' transactions pretty much everywhere because of this reason. They moved away from 0 conf because of the high fees, making payments sometimes get stuck for days or weeks, making 0 conf much less trustworthy.