Live data from Hacker News

Facebook Libra Is Architecturally Unsound

stephendiehl.com

171–180 of 347 posts

Re: Facebook Libra Is Architecturally Unsound

#171

Earlier quoted context omitted.

The initial question was whether cryptocurrencies have the capacity for consumer protection measures, not whether those measures are ready for prime time. I'm just arguing that when they're ready, they'll be more efficient than what we have, so we should encourage their development in the meantime (though maybe not in Libra's particular case). Also, there are limits on how old a transaction can be when a bank goes an…

Out of that entire list, the one thing that exists now is the Ethereum blockchain fix, and that basically required global agreement to respond to a single theft. That's not particularly scalable. The rest of the things on the list aren't in significant use at the moment, and might never be. Measures that are not ready for prime-time are as good as nonexistent. We're talking about money here!

> Measures that are not ready for prime-time are as good as nonexistent

That's not how technology works. To become fruitful it requires patience and investment. Nobody is saying you have to be an early adopter of these currencies.

> We're talking about money here!

...and particularly whether it's current feature set is amenable to fraud prevention. I work at a traditional payments company and the waste is infuriating--there has to be a better way.

Re: Facebook Libra Is Architecturally Unsound

#172

Earlier quoted context omitted.

Regarding your claim that blockchain has almost no good use cases, I see news every week which disagrees. Here is the first article I could find from just today which shows a great use case. Coca Cola is expanding their blockchain trial project to a $21 billion-a-year supply chain because they found very significant savings. https://www.coindesk.com/coca-cola-supply-chain-firm-to-expa...

Why would Coca-Cola need to use a block chain? They can run their own code on their own servers.

I'm sure they have plenty of cloud, Internet of Things, and AI. They might even have IoT AI in the cloud. Gotta stay buzzword compliant.

Re: Facebook Libra Is Architecturally Unsound

#173
post #37

The answer to the question implied in the article -- why does Libra make such unjustified design decisions -- is simple. Some people have become enamored with blockchain despite it having almost no good use cases, and this certainly isn't one. It seems like a classic example of focusing on the technology rather than on the problem. -- Regardless of the other, far more important sections of this article, I find the se…

The NIST has a helpful decision tree to determine whether a blockchain architecture is appropriate for your use case.

https://www.nist.gov/publications/blockchain-technology-over... (page 42)

Re: Facebook Libra Is Architecturally Unsound

#174
> The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means.

Hmm, I'm not sure I'm convinced. While "Mastercard as an entity turns into a malicious actor" doesn't seem like an important threat model, it seems to me maybe guarding against mailicious actors within (eg) Mastercard, as well as external attacks on Mastercard is? And justifies this stuff?

The possibliity that a node run by Mastercard would suddenly start running malcicious code doesn't seem that bizarre a scenario to me, if we remember it can happen not just cause the CEO of Mastercard directs it to, but because of criminal activities from hackers as well as employees for their own gain.

Am I wrong?

Re: Facebook Libra Is Architecturally Unsound

#175
post #134

Earlier quoted context omitted.

Why would Coca-Cola need to use a block chain? They can run their own code on their own servers.

Because while the core innovation of blockchain is a trusted database a context without trust, the core benefit of blockchain is reduced transaction costs. A blockchain is a singleton global computer of program code and data. It turns out this is sufficient to represent capital (money) on that computer. In practice this results in dramatically reduced transaction costs. For example you can transfer money with an API…

> In practice this results in dramatically reduced transaction costs. For example you can transfer money with an API call.

Just as a relational database with a web frontend would.

Re: Facebook Libra Is Architecturally Unsound

#176
post #65
post #37

The answer to the question implied in the article -- why does Libra make such unjustified design decisions -- is simple. Some people have become enamored with blockchain despite it having almost no good use cases, and this certainly isn't one. It seems like a classic example of focusing on the technology rather than on the problem. -- Regardless of the other, far more important sections of this article, I find the se…

If you may spare a minute, I'd like to know your opinion on mission-critical software in dangerous-prone contexts (such as avionics, life support, even just economically for permanently-written "ROM" software, etc). Formal methods seem required in such projects, but your final paragraph seems to imply the formalism isn't key to end quality? (my agenda, for transparency: I want to send SOC's in space on tiny RISC-V sa…

> my agenda, for transparency: I want to send SOC's in space on tiny RISC-V satellites

I've seen your posts in multiple threads K0SM0S, and I generally enjoy reading your thoughts and opinions. When I meet people I find interesting, I like to ask what they plan on doing with their lives. I understand completely if you don't want to share further details, but I for one would be interested in an off-topic detour into your intentions with these microsatellites. One application I always toy with in my head is a time+location verification service, but I don't think satellites are strictly necessary for that one unless you're trying to work around region-specific laws that would regulate towers.

Re: Facebook Libra Is Architecturally Unsound

#177

Earlier quoted context omitted.

Out of that entire list, the one thing that exists now is the Ethereum blockchain fix, and that basically required global agreement to respond to a single theft. That's not particularly scalable. The rest of the things on the list aren't in significant use at the moment, and might never be. Measures that are not ready for prime-time are as good as nonexistent. We're talking about money here!

> Measures that are not ready for prime-time are as good as nonexistent That's not how technology works. To become fruitful it requires patience and investment. Nobody is saying you have to be an early adopter of these currencies. > We're talking about money here! ...and particularly whether it's current feature set is amenable to fraud prevention. I work at a traditional payments company and the waste is infuriating…

> Nobody is saying you have to be an early adopter of these currencies.

This here is probably the source of our disagreement. As far as I can tell, tons of people actually are saying "get in now", which means we're no longer in the patience and investment stage, and any deficiencies in the cryptocurrency ecosystem have real consequences.

Re: Facebook Libra Is Architecturally Unsound

#178

Earlier quoted context omitted.

How does being an orphan make one care less about humanity? Personally, I want orphans (as defined as minors with no living parents) to be well-cared for regardless, either by relatives or by an outside agency ("orphanage" or foster home).

Absolutely, that's my point. We should care about people, period. Whether one has a family should be irrelevant to the question of how to engineer a society.

Thanks for clarifying. I agree 100%.

Re: Facebook Libra Is Architecturally Unsound

#179
>For a system that is designed to be run in a consortia of highly regulated multinational corporates, all running Facebook signed code and access controlled by Facebook it simply makes no sense to deal with malicious actors at the consensus level. Why is this system designed to be byzantine tolerant at all rather than just maintaining a consistent audit log for compliance checks. The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means.

Eh, I'm not so sure about that. It seems like a good feature that hackers successfully targeting a single node don't take down the whole system.

>In congressional testimony the product was stated as a challenger to emerging international payment protocols such as WeChat, Alipay and M-Pesa. Yet none of these systems are designed to run on byzantine tolerant pools of validators. They are simply designed in the traditional high-throughput bus that orders ledger transactions according to a fixed set of rules. This is the natural approach to designing a payment system. Preventing double-spends and forks is simply not an issue that a properly designed payment rails should ever have to deal with by design.

I would assume these systems are each run by a single company though, no? Which makes them fundamentally different from what Libra seems to be aiming at.

>The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case.

On the contrary, running byzantine fault tolerant consensus on a small number of node partners (which each submit aggregations of transactions from their clients) seems like exactly the kind of system that blockchain technology is best suited for. Not the kind of highly distributed consensus we see in e.g. bitcoin.

>A defining feature of a payment rail is the ability to reverse transaction in case payments need to be undone by legal action or if they result in accidental or system malfunction. The Libra system is designed to have “total finality” and does not include a transaction type to reverse a payment.

I don't know that this is necessary? A transaction can of course be reversed simply by making the inverse transfer. I don't know what kinds of annotations / metadata they would be storing in the ledger for audit trails, but it doesn't seem to me like a reverse transaction should be treated extra special.

Disclosure: I work for Facebook in a totally unrelated initiative (Facebook Connectivity) but have only cursorily followed Libra news in news media. I'm generally highly skeptical of cryptocurrencies, but less skeptical of distributed byzantine fault tolerant ledgers as a general technology for some niches. My comments are completely my own personal views.

Re: Facebook Libra Is Architecturally Unsound

#180
post #131
post #119

Earlier quoted context omitted.

Exactly what I needed to hear, thanks again. I reckon the only way to error-free is redundancy, i.e. 'out of the box' we just put two boxes, or actually three for "high availability"; the underlying controller being just a dead man's switch — if A's life signal dies, failover to B; set up C as new failover; reboot A. > I personally believe that some formal methods can greatly improve correctness, and do so affordably…

> I reckon the only way to error-free is redundancy, i.e. 'out of the box' we just put two boxes, or actually three for "high availability"; the underlying controller being just a dead man's switch — if A's life signal dies, failover to B; set up C as new failover; reboot A. You can have a lot of this automatically with "lockstep" chips, such as TI Hercules: http://www.ti.com/en/download/mcu/SPRB204.pdf?DCMP=hercules…

Very interesting! Duly noted, thanks for the pointer.
Post reply on HN