4 ms·
> I assume this is a technical limitation rather than a business decision to sell more notes. But I do wonder (as someone who doesn't quite understand cryptogra
by ccamrobertson 4y ago
> I assume this is a technical limitation rather than a business decision to sell more notes. But I do wonder (as someone who doesn't quite understand cryptography and multisig beyond the basics of how Bitcoin works), barring a protocol update, is it technically impossible to have reusable notes or was this a trade-off/design decision? If it is possible, is the trade-off it requiring an on-chain transaction to update the multisig every time the note change hands?
This is a trade-off; we could issue notes that never expire and do not require cutting to claim (and could be reloaded), however, this would require perpetual trust that we remain in existence without a fallback. Creating an expiration date mirrors how real money wears out after use. Our intent here isn't to sell more notes; in a medium-confidence scenario our hope is that after a long life in circulation the final holder of the notes re-keys them and puts them in a safe place until 2029 at which point they claim without cutting the notes (and retain them as collectable artifacts with no Bitcoin value thereafter). Our goal is not to sell more notes because they are cut/expired, but rather because we have new designs and denominations.
> This looks like a cool gift, but the necessity of destroying the note to move it, or otherwise trust the giver didn't copy the key, makes it a bad currency (I understand that cold-storage is the aimed use-case, not currency). My first thought on the landing page was that the keys were inaccessible to the holder without destroying the note for moving it to a known address (which would be somewhat alike trading in US dollars for gold, back in the day). I.e., that you could trust the note holds it's denomination as long as it is not cut. That would make it a proper offline and trustless currency. Is there a future where such notes will exist and does it require a major protocol update?
If there is anything beyond zero trust that we exist in some form into the future, the goal is that the recipient can re-key a note from an untrusted giver without cutting the note. In a medium trust world you can assume that a note hold value without scanning it so long as the expiration date is not past. But this requires several things -- (1) trusting that we will continue to exist and facilitate key rotation and (2) that the previous holder carried out some validation and is somewhat trustworthy -- e.g. potentially a bank or large retailer. For low value notes this doesn't seem completely unreasonable, but I appreciate why no one would treat the notes that way without some track record. Given a theoretical new chip which doesn't exist there are some additional possibilities here.