3 ms·
100% of users have to trust the code used to generate random numbers for private keys they care about isn't backdoored. Only a subset of users will be able to d
by photon12 4y ago
100% of users have to trust the code used to generate random numbers for private keys they care about isn't backdoored. Only a subset of users will be able to do this successfully. There is no safety net or recourse for people who will lose their money to backdoored refurbished hardware wallets. Because poor people won't be able to afford newer wallets and will be scammed. There is no good solution to this problem that is actually usable by all classes of people who need financial services.
I recently left a company that pivoted hard to building blockchain infrastructure because I couldn't find any way I could ever recommend my friends or family interact with the services the company was building. A lot of people are holding out for technical vaporware to solve these problems. I can't hold out anymore.
- EGreg 4y agoWell, this is the Trusted Computing Base. You trust Apple and Google every day with the devices, OS, browsers etc. They can impersonate you, and sure, you can say that for this reason we cannot have finalized transactions (because they can always be disputed). But you’d be wrong. First of all, each participant can control a small portion of the overall value (eg one vote in an election, or one student paying one teacher). Even if their keys are hacked, the real value is for the network itself to be secured. And the business logic to be followed no matter what! No corruption of the database, ever! For example, UniSwap is a smart contract factory and you trust every instance that comes out of it to be an battle tested and heavily audited piece of code you can trust. As of right now we are forced to trust the value and control of YOUR ENTIRE NETWORK to a big tech company that has all the infrastructure. That’s the best we have today, like how we trusted the Post Office to deliver mail and not tamper with it, until SMTP got adopted over the Internet. For more info, click here: https://community.intercoin.app/t/web3-moxie-signal-telegram-and-why-decentralization-matters/ https://community.intercoin.app/t/web3-moxie-signal-telegram...
- photon12 4y agoThere were MPC experts at the company I was at. We talked a lot about account abstraction design for our stack we were building. I'm not unfamiliar with anything you are suggesting. I'm saying there are classes of users for which there are no good solutions. Different people have different threat models.
- EGreg 4y agoWhat do you mean by MPC? Sure different people have different threat models. Perhaps some classes of users don’t have good solutions, but we are building apps for the mainstream.
- tromp 4y agohttps://en.wikipedia.org/wiki/Secure_multi-party_computation https://en.wikipedia.org/wiki/Secure_multi-party_computation