Earlier quoted context omitted.
Do you believe that bitcoin is useful as an actual currency? As far as I can tell, its only use is to buy drugs and other illegal things online.
Bitcoin Cash adoption is growing around the world for restaurants https://map.bitcoin.com/
Facebook Libra Is Architecturally Unsound
231–240 of 347 posts
Re: Facebook Libra Is Architecturally Unsound
#232> The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means.
> The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case.
> ... the model as proposed is hundreds of person-years away from being able to handle global transaction throughput and would likely have to be completely redesigned from first principles.
> Enterprise software consultants generally thrive on ambiguity and smart contracts are the apotheosis of enterprise obscurantism because they can be defined to mean literally anything.
> It should be assumed this entire crypto stack is vulnerable to a variety of attacks until proven otherwise. The “move fast and break things” model should not apply to cryptographic tools handling consumer financial data.
> The final conclusion one must take away after doing technical due diligence on this project is this simply that it would not pass muster in any respected journal on distributed systems research or financial engineering. Before trying to disrupt global monetary policy there is a massive amount of a technical work needed to build a reliable network the public and regulators could trust to securely handle user data.
> I see no reason to believe that Facebook has done the technical work needed to overcome these technical issues in their project, not does it have any technical advantage over existing infrastructure that already works. Claiming one’s company needs regulatory flexibility to explore innovation is not an excuse for not doing it in the first place.
Re: Facebook Libra Is Architecturally Unsound
#233> The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means. Hmm, I'm not sure I'm convinced. While "Mastercard as an entity turns into a malicious actor" doesn't seem like an important threat model, it seems to me…
The author didn't say that we should trust MasterCard but he was saying that this trust issue can be solved much more efficiently via the legal system. And in practice the current system already works as billions entrust their financial transactions in these institutions. Some people have the tendency to think that technology could solve anything and should be allowed to solve everything. This Libra thing is no bette…
For example, governments, in the past, have tried to prevent bank transactions from being sent to wiki leaks, even though they were never charged with any crimes.
The credit card transactions failed to go through, but the crypto transactions DID succeed.
Crypto currencies seem to have done a pretty good job so far, of preventing this attack vector.
I can think of no examples where a government has taken over a crypto currency yet.
Re: Facebook Libra Is Architecturally Unsound
#234Earlier quoted context omitted.
Right, here in Argentina our currency has lost more than half its value this year, and the US dollar has lost 96% of its value since the end of the gold standard in 1973. I carry a Zimbabwe 100 trillion dollar bill in my wallet to remind people what real hyperinflation is. I don't think that's the main threat Bitcoin is designed to defend against, though; I think there's a whole spectrum of confiscation threats, rang…
> the US dollar has lost 96% of its value since the end of the gold standard in 1973 It is more like 80-85%, not 96%. $1 in 1972 is $6-$6.5 in 2019. A 96% loss of value would mean $1 in 1972 is more like $25 in 2019, which is not the case. Also to phrase it in context you should probably say "the US dollar has had an average annual inflation rate of 4% per year over the last 5 decades". Also for additional context yo…
I agree that "an average annual inflation rate of 7.1%" (or, using your US$6 number, 3.9%) sounds much milder than "lost 96% of its value since 1973" (or 83%). Where I differ is on whether the milder presentation or the more dramatic presentation is more informative. I think that, except to financial traders, "3.9%" or even "7.1%" is a misleadingly insignificant number.
Consider that throughout the 1600s, 1700s, and 1800s, there were families that lived on the interest income from government bonds, both in the US and in England. Even throughout the 20th century, people would buy "savings bonds" as presents for children or as a means to save up for college or retirement; the bonds would reach maturity decades in the future, providing a healthy reward for the prudent and patriotic purchase. Since the end of Bretton Woods, that 3.9% or 7.1% has made nonsense of such ideas. Despite what you might think, this hasn't eliminated plutocracy or increased social mobility — rather the opposite has happened in the post-Bretton-Woods years, in fact. I think it's hard to obtain the historical perspective necessary to appreciate the importance of this radical experiment. But it is, I assure you, a worthwhile effort. I recommend it.
Perhaps inflationary monetary policy is a necessary instrument for avoiding financial panics; it's a plausible idea. But the evidence against it — particularly the 1970s stagflation in the US — suggests that, though plausible, it isn't such a clearly open-and-shut conclusion that we should deny everyone access to alternative, non-inflationary currencies. Moreover, in most scenarios, attempting to institute such a policy would only deny such access to everyone but the well-connected and influential.
Re: Facebook Libra Is Architecturally Unsound
#235Libra’s byzantine tolerance on a permissioned network is an incoherent design.
The criticism here is that byzantine tolerance is not needed, when every participant is a regulated multinational company. But it certainly isn't a bad thing to have byzantine tolerance. Maybe a set of the regulated multinational companies will have backdoors put in place by a malicious entity - that has certainly happened before.
The downside of byzantine tolerance is the computational overhead. Yes, there is going to be a cost in throughput. But it just doesn't make sense for Libra to optimize for transactions-per-second at this point. If they run into scaling problems, then they can optimize. Right now they are quite far away from having scaling problems.
Libra has no transaction privacy.
It's the same privacy level as Bitcoin. Transactions are public, endpoint identities are trackable but don't have real identities attached. You can say it isn't a good set of tradeoffs for a cryptocurrency to be pseudo-anonymous. But it doesn't make the system "architecturally unsound".
Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail.
Again, it doesn't make sense to criticize Libra at this point for not being able to achieve tens of thousands of transactions per second. If they start running into scaling problems, they can work on all sorts of extensions and improvements then.
Libra’s Move language is not sound.
The criticisms here really boil down to "Move needs more work". It isn't fundamentally unsound, it just needs more work.
The claims seem to reduce to nothing more than handwaving and marketing rather than actual proof. This is an alarming position for a language engineering project which expects the public to trust it to handle billions of dollars.
Okay, well don't go putting a billion dollars in a Move smart contract tomorrow. Programming languages, and especially programming language documentation, can be improved a lot over time.
...
There's more in the article, but really, it reads like a rant, where the author is so biased by their hatred of Facebook that they think every little thing that Libra does is wrong.
IMO, the core mistake behind Libra is assuming that regulators would be okay with it, because it isn't very different from other permissioned cryptocurrencies, like Stellar. Instead, regulators have been quite opposed to it because Facebook is behind it, even when technologically it isn't very unique. It is certainly not "architecturally unsound".
Re: Facebook Libra Is Architecturally Unsound
#236I'm confused about this article. I've read it, and it's skeptical of libra (which is fine) but makes handwavy and non concrete arguments about it's soundness. Can anyone tell me why it's so popular, besides just bashing Facebook?
> The claim of the Move language to use of linear types appears to be unsubstantiated by a dive into the compiler as it reveals no such typechecker logic. As far as one can tell the whitepaper cites the canonical literature from Girard and Pierce and does nothing of the sort in the actual implementation.
Re: Facebook Libra Is Architecturally Unsound
#237Earlier quoted context omitted.
If you may spare a minute, I'd like to know your opinion on mission-critical software in dangerous-prone contexts (such as avionics, life support, even just economically for permanently-written "ROM" software, etc). Formal methods seem required in such projects, but your final paragraph seems to imply the formalism isn't key to end quality? (my agenda, for transparency: I want to send SOC's in space on tiny RISC-V sa…
> (my agenda, for transparency: I want to send SOC's in space on tiny RISC-V satellites, and the lowest layers of those should be 100% error-free because there's no going physically there to reboot a working shell, remote is all we have.) Speaking from a bit of experience at Satellogic as well as folklore, trying to make the lowest levels 100% error-free isn't a good strategy. A better strategy is to make the lowest…
> Think in terms of how to prevent inevitable unreliability from snowballing, how to make the satellite resilient against inevitable damage and malfunctions, as well as reducing that bottom-level unreliability to an absolute minimum.
High-availability of components seems like a given to me (e.g. have 2, 3, 4 batteries as distant from each other as possible, to mitigate loss if one gets shot by some collision or outright fails; rinse and repeat for every critical component, starting at circuit design). In another comment, user "pjc50" suggests to me “"lockstep" chips, such as TI Hercules”, and yet my intuition would be to put two redundant ones on each satellite, just for good measure.
But the ultimate economics of the project can be made to work, imho, because I envision a swarm of such tiny satellites actually, wherein you can afford to lose a few nodes now and then, if that makes all of them orders of magnitude cheaper — and thus you can send orders of magnitude more, overall. Brute-force the reliability issue by making them expendable to a reasonable degree. No human life means they can die for all we care, if it makes sense cost-wise. Hence why in that perspective, a discussion on the cost versus benefit of formal methods is of great interest.
Needless to say, any advanced draft of the project would inevitably have to be vetted by, actually co-developed with field experts like you. To each contributor their domain. I hope it will be a given too, since I'm thinking of a 100% open-source project (both software and hardware ideally). The more eyeballs...
____
I see your points about blockchain, and they make a lot of sense; the problem I see with current 'cryptos' in general (including the big one) is that they simply aren't welcomed by most decisive institutions, including those who combat on principle the problems you mention. Like, you see the EFF et. al defending e.g. E2E encryption, but none of that drive to promote bitcoin.
Thus that 'respectable' cryptocurrencies exist to solve these problems, sure, please, yesterday! — but that they reform the financial system by their very existence? There doesn't seem to be much appeal in the mainstream. I think it's a matter of time, how much each generation weighs demographically in the global opinion / decision power. For now, it's boomers, and they're not in that place.
Re: Facebook Libra Is Architecturally Unsound
#238Earlier quoted context omitted.
Your wallet can be stolen and when using crypto so it doesn't solve 3 very well. Credit card fraud is regulated such that the consumer is protected after a manageable amount of theft, $50 in the US last I looked. If you use a bank you receive some protections but at that point the implantation is abstracted and not that relevant. IMO Cryrto is significantly worse in case 3.
If you use a smart contract wallet you can actually protect yourself from losing all your money even if someone gets your private key. You can set a withdrawal limit of say, $50 and you can set a few recovery addresses (of friends, family or other personal wallets). So if I have $10,000 in my ethereum wallet and I post my private key in every forum and every chatroom on the internet then the most I lose is $50. Befor…
So, this is strictly worse than using a credit card.
Re: Facebook Libra Is Architecturally Unsound
#239Earlier quoted context omitted.
>"The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means." In regards to that, I don't think it's any more bizarre than a SCADA system in an Iranian nuclear enrichment plant suddenly running malicious code. Cyber…
To the best of my knowledge, no deployed banking system relies on immutable ledgers. They all rely on detection and revision of ledgers. Libra has chosen to do something fundamentally different, and the author is asking why.
Re: Facebook Libra Is Architecturally Unsound
#240Earlier quoted context omitted.
> (my agenda, for transparency: I want to send SOC's in space on tiny RISC-V satellites, and the lowest layers of those should be 100% error-free because there's no going physically there to reboot a working shell, remote is all we have.) Speaking from a bit of experience at Satellogic as well as folklore, trying to make the lowest levels 100% error-free isn't a good strategy. A better strategy is to make the lowest…
Thanks so much for all the food for thought and recommendations. I had a hunch for "capable of recovering", and now I have a clearer roadmap (some critical steps). I see your way of thinking. This in particular: > Think in terms of how to prevent inevitable unreliability from snowballing, how to make the satellite resilient against inevitable damage and malfunctions, as well as reducing that bottom-level unreliabilit…
Satellogic's CubeBug design did use a TI Hercules TMS570 Cortex-R, and I think it's safe to say our experiences with chips like that were good — for the relatively restricted tasks they can perform. The automotive industry has a lot of lockstep chips available for it, because it's a mass market that demands reliability under harsh conditions.
I'd like to point out that what you're describing is pretty similar to Satellogic's original business plan.