5 ms·
> Am I missing something about how cutting notes works, or am I correct in saying that cutting notes relies on a centralized single-company-controlled server be
by ccamrobertson 4y ago
> Am I missing something about how cutting notes works, or am I correct in saying that cutting notes relies on a centralized single-company-controlled server being both online and releasing a decryption key?
That's correct.
> Even ignoring the centralization angle, all of the verification advice I'm seeing boils down to "scan each note and cut it when you receive it." And if everyone is going to do that, what's the point of using a physical note instead of an app? The promo images and descriptions clearly expect that this is going to be used like cash so that technical burdens are lessened for people who aren't good with more traditional cryptocurrency transaction methods.
Not quite; rather than cutting the note you could re-key it and store it. Or, if you are planning to use the note immediately or near term in commerce, you might have sufficient confidence that our re-key service won't shut down (but yes, this obviously implies some trust if you hold notes without re-keying of claiming).
> But if non-technical users use it like cash, they're not going to scan anything. And if you think you can teach them to scan every bill in their wallet with a phone, then... why not just teach them to use the phone?
Because with a phone alone they need to store their keys locally. With re-keyed notes (or notes from family members who have re-keyed them), they can immediately store notes in a safe place without the problem of phone hacks or loss.
- danShumway 4y ago> Or, if you are planning to use the note immediately or near term in commerce, you might have sufficient confidence that our re-key service won't shut down (but yes, this obviously implies some trust if you hold notes without re-keying of claiming). Does this mean that your private servers have the ability to re-key notes? What prevents someone from scanning the chip or storing the user key that they generated, handing the note to someone else, and then walking around the corner and immediately using the scanned information to re-key it? Without understanding more about the technical details, this feels like unless a user is using an app to re-key immediately at the time of transfer that it's significantly less secure than normal cash. I guess I'm not completely clear on what you're doing with user keys. --- > Because with a phone alone they need to store their keys locally. But they have to do that here too, or is the assertion that they don't need to back up the user key necessarily and that it's not secret? Is the user key just plain-text readable? If the user key is accessible from the chip just via scanning (not cutting), and isn't a user-defined secret that only they know (which seems like would require some form of backup), then does that mean an attacker can just walk past my wallet with a reasonably powerful RFID reader and then rekey every single one of my bills?
- ccamrobertson 4y ago> Without understanding more about the technical details, this feels like unless a user is using an app to re-key immediately at the time of transfer that it's significantly less secure than normal cash. We will have a security overview doc up soon, we ran out of time to have it ready today. Long story short, there are pending key rotation states and the latest holder can always re-key the note again. But it is indeed distinct from cash; we can't just state a note has value like governments do, by fiat. We have to provide users with sufficient information to assess the veracity of that claim relative to the functions of Bitcoin and the information we provide on the note. > But they have to do that here too, or is the assertion that they don't need to back up the user key necessarily? Not necessarily; in the condition where a user is confident they are the only ones that can claim, they can place the notes in a safe the same way they might printed Bitcoin keys or Opendimes (I would recommend a fireproof safe).
- throwaway92394 4y ago> We will have a security overview doc up soon, we ran out of time to have it ready today. I mean this respectfully - why would you release a cryptographic method of transferring money - without going into detail of how it actually works? That's kinda the entire point of cryptocurrency, that we have a way to be mathematically confident the money is safe - but you didn't tell us the math. Especially on HN were a lot of the audience is technical enough to want to and be able to verify it to some degree. I see you have patent US10896412B2, which honestly I have to ask how this is any different from any other hardware wallet? > A physical cryptocurrency may comprise a physical medium and an attached processor. I read some of the details (admittedly not all) and I'm still unsure how this is different from any other hardware wallet. AFAIK this is just a hardware wallet that exposes it's public key, then exposes it's private key when you cut the wire? Then we still need your signature to transfer the crypto, which is so double spend is prevented? Also, if your servers go down or you're hacked or rm -rf dir/ * happens, will all the notes become unusable? Are we relying on you to maintain servers indefinitely?
- ccamrobertson 4y ago
- barkingcat 4y agoDoes "cutting" a note mean taking scissors to cut it physically? Can you cut it in the corner or it has to be "across" a sensor boundary somehow breaking connectivity? Can you tear the note apart and have it work too, if you don't have scissors on hand for example? Maybe you can sell a kit that comes with the notes and a special cutter, like a cigar cutter with a box
- ccamrobertson 4y agoThe synthetic paper we use is laughably difficult to tear -- it more readily deforms and stretches instead. You need to cut across a trace. I like the idea of a note "humidor" with included cutter -- instead it's fireproof and includes EMF shielding.
- BbzzbB 4y agoMeaning the cutting part is literal and the notes are basically single-use?
- ccamrobertson 4y agoYes, literal cutting -- if not cut, the notes can be re-keyed and recirculated until the expiration date in 2029.
- noduerme 4y agoWhat happens after the expiration date?
- ccamrobertson 4y agoAt that point in time the note downgrades to a 1-of-2 multisig where only the user key on the note is needed to create a transaction. Cutting the note isn't required/is irrelevant as the second encrypted key has no function at that time.
- 4y ago
- jacobsenscott 4y ago> That's correct Doesn't sound very "self-custodial" to me.
- ccamrobertson 4y agoWe can't transfer the funds under any circumstance. Custody always reverts to the user key on the note.
- bozhark 4y ago> Because with a phone alone they need to store their keys locally. With re-keyed notes (or notes from family members who have re-keyed them), they can immediately store notes in a safe place without the problem of phone hacks or loss. In a safe place, like a wallet? This seems dramatic unnecessary. You can lose cash. And it’s measurable how much easier it is to lose paper money compared to a phone. Hard cash went electronic. Why would electronic cash go hard?
- ccamrobertson 4y agoOr a safe. Because it's easier to understand and safely custody than private keys for the billions of people who know how to use cash but haven't encountered Bitcoin yet.
- patrickthebold 4y agoCan you explain re-keying? Does that happen on-chain? If so, who pays for the transaction fees?
- ccamrobertson 4y agoYes; you are effectively requesting sending from the original 2-of-2 multisig to a new 2-of-2 multisig in the re-key procedure. The user broadcasts the transactions and pays the fees. For all transfers we're recommending using the lowest fee tier possible as given the fact that the notes are intended to be long-lived, rushing to load or re-key them doesn't make a ton of sense.
- tommica 4y agoThe re-keying seems like a hassle to get grandparents to do - wouldn't it be better if the cash value is linked to a generated wallet that is locked behind a very strong key? That way the cash becomes the physical representation of X amount if BTC with "real" backing?