Live data from Hacker News

'Minting' electronic cash (1999)

spectrum.ieee.org

51–60 of 90 posts

Re: 'Minting' electronic cash (1999)

#51
post #23
post #9

Earlier quoted context omitted.

Believe it or not but there are people who think that "Bitcoin is a battery" because it can turn energy into money (and "money is easily converted to energy again", Umm... STEM education, we need to have a word because it looks like you are not doing your job properly... ). Here is an example: https://twitter.com/balajis/status/1351214402167578626

These people will justify bitcoin in such insane ways. I see one guy doesn't agree that it's a battery but still thinks mining is a good thing > Bitcoin let’s anyone with excess energy manufacture sound money. This is a better option than wasting the energy. There are times where the grid is producing more energy than is being demanded but it's not like it's that difference that's being used to mine. I also don't get…

> There are times where the grid is producing more energy than is being demanded

That never happens. The production and demand in the electric grid must always be matched. When they are not, the voltage and frequency increase (excess production) or decrease (excess demand), and control mechanisms on all generators in the grid regulate the production so that it matches the demand again; if that's not possible (because the production and demand are too mismatched), safety mechanisms disconnect parts of the grid (and power off the generators) to avoid costly damage.

Re: 'Minting' electronic cash (1999)

#52

Earlier quoted context omitted.

How do you figure?

In short, the suggested method by Chaum requires a trusted 3rd party (bank). The topmost invention of Bitcoin is that it requires no trusted 3rd party.

...and to achieve that, Bitcoin has a backwards approach to security where the honest parties must work harder than the attackers, which ultimately means that nobody can confidently say that the system is secure unless a majority of energy produced on Earth is being devoted to honest parties mining Bitcoin.

It is also wrong to suggest that the bank in Chaum's system is a "trusted third party," as if the bank can unilaterally break any security property of the system. In fact the bank in an ecash system is very much constrained. The bank cannot violate a user's privacy (in the sense of linking a user's transactions) unless the user attempts to spend the same coin twice. The bank's ability to claim that a user was trying to conduct some kind of double-spending attack is also constrained (the no-frame-ups property) so that a user must actually attempt to double spend a coin for the bank to produce evidence of such a crime. It is also possible to create a distributed trust model where several parties must jointly issue the coins (threshold blind signatures).

Unlike Bitcoin, the security model of ecash is well-defined and follows the basic philosophy of cryptographic security: the computational difficult of attacking the system grows exponentially with the computational work performed by honest parties. Put another way, the energy expended in an ecash system will grow linearly with the number of transactions being performed in the system, and the incentive is to reduce the energy consumption by finding more efficient ways to process transactions. If the cost of a well-defined, rigorous security model, a system that incentivizes minimizing energy consumption, and features that Bitcoin can never actually support (e.g. direct peer-to-peer payments that do not require an Internet connection or any communication with any third parties), is to have a central bank or consortium of banks that issues the coins, you can count me in.

Re: 'Minting' electronic cash (1999)

#53
post #16

Ooh, the original Chaum paper! Chaum "coins" behave a lot more like bearer instruments or "free banking" notes; they're IOUs issued by a bank that can be traded. The advantage over a database is that there's some ability to do offline transactions, although the double-spend prevention is done through the originating bank. The advantage over bitcoin is that is uses a tiny fraction of the energy. It's also naturally a…

Actually the bank does more than just issue coins and detect double spending. The bank is the ultimate authority on whether any coin is valid (just like with paper money), in the sense that the bank can refuse to accept a deposit. This is crucial to the security definition of ecash -- crucial because the security definition of any cryptosystem that is trying to achieve "electronic money" must in some way define "money."

Also, double-spending detection can be defined in several ways. My view is that the best definition includes the no-frame-up property and the "full tracing" property. A system that supports full tracing allows a cheating user to be blacklisted completely, since the double spending detection procedure produces a value that can be used to check if any coin was spent by the cheating user (basically, users have secret keys they use to spend; double-spending will reveal the secret key used for double spending). This is a nice property because it allows the bank to issue blacklists of cheating users, which are enforced by the bank's refusal to accept any coins that were spent by that user (even those not double spent), and thus no other party is willing to accept payments from blacklisted users since the coins are effectively worthless (as the bank will not accept them for deposit). In other words there is a meaningful way to punish a cheating user.

Finally, there is no reason these systems must naturally be "stablecoins." The bank need not peg the coin's value to anything, it can float freely like any other currency and the bank can choose any monetary policy, including one that results in significant volatility. The bank could even emulate Bitcoin by setting a fixed limit on coins in circulation (the different between the number of withdrawals and number of deposits) and periodically releasing more coins (maybe giving them in fixed amounts to randomly chosen users to simulate mining). If the coins did have stable values or were pegged to a currency with stable value, that would only be because the bank itself thought it was a good idea (perhaps in response to customer demand), not because there is something inherent in ecash that promotes stability.

Re: 'Minting' electronic cash (1999)

#54
post #16

Ooh, the original Chaum paper! Chaum "coins" behave a lot more like bearer instruments or "free banking" notes; they're IOUs issued by a bank that can be traded. The advantage over a database is that there's some ability to do offline transactions, although the double-spend prevention is done through the originating bank. The advantage over bitcoin is that is uses a tiny fraction of the energy. It's also naturally a…

Actually the bank does more than just issue coins and detect double spending. The bank is the ultimate authority on whether any coin is valid (just like with paper money), in the sense that the bank can refuse to accept a deposit. This is crucial to the security definition of ecash -- crucial because the security definition of any cryptosystem that is trying to achieve "electronic money" must in some way define "mone…

> This is a nice property because it allows the bank to issue blacklists of cheating users

That property consequently allows a bank to black list any user, not just cheating users. There are many situations where that can be not so nice. In bitcoin, cheating isn't even feasible. It's better to prevent cheating entirely than to black list cheaters after the fact.

Re: 'Minting' electronic cash (1999)

#55

Earlier quoted context omitted.

In short, the suggested method by Chaum requires a trusted 3rd party (bank). The topmost invention of Bitcoin is that it requires no trusted 3rd party.

...and to achieve that, Bitcoin has a backwards approach to security where the honest parties must work harder than the attackers, which ultimately means that nobody can confidently say that the system is secure unless a majority of energy produced on Earth is being devoted to honest parties mining Bitcoin. It is also wrong to suggest that the bank in Chaum's system is a "trusted third party," as if the bank can unil…

> unless a majority of energy produced on Earth is being devoted to honest parties mining Bitcoin.

Nope, try again

Re: 'Minting' electronic cash (1999)

#58
post #41

Earlier quoted context omitted.

As is commonly pointed out in these threads, that's likely only around 60% the usage of idle always-on electronics in the US. Isn't that a way more obvious low hanging fruit? Human activity uses energy, that's unavoidable.

> As is commonly pointed out in these threads, that's likely only around 60% the usage of idle always-on electronics in the US. Luckily Bitcoin mining is utterly centralized. In fact turning off a single mine in Xinjiang cut power consumption by 1/4-1/2. > Isn't that a way more obvious low hanging fruit? No. Is idle device power in the US rising? Some data shows one of the biggest sources of idle power is halogen bul…

Incidentally the last time [well, more like the 215th time ago, because this thing comes up like 10 times a day] this came up, I came up with a figure for US junk mail's CO2 footprint that was comparable to Bitcoin [US junk mail volume is something in the 6 million ton range, and the figures I got for paper were 3-10 pounds of CO2 / pound of paper].

I'm not bringing this up to dispute anything you just said, more that if you're looking to crusade against industries that generate a huge amount of waste to benefit a relative few, I think there's a strong argument for also killing junk mail along with PoW cryptocurrencies.

Post reply on HN