Live data from Hacker News

'Minting' electronic cash (1999)

spectrum.ieee.org

61–70 of 90 posts

Re: 'Minting' electronic cash (1999)

#61

Earlier quoted context omitted.

What do you mean? It's not like PayPal because the sender is actually anonymous (assuming that exact amounts are hidden by always withdrawing fixed size coins).

Bitcoin isn't quite anonymous, as a variety of criminals have found out. Cash is anonymous: there is no unique identifier associated either with the transaction or the parties to the transaction. Bitcoin on the other hand is, at best, pseudonymous. This is particularly problematic because it gives information about true identities when the owner of coins wants to spend it in any way on anything where bitcoin is not a…

I wasn't talking about bitcoin, I agree on all those points. I was talking about Chaum's digital cash

Re: 'Minting' electronic cash (1999)

#62
Ah yes, the Chaum paper. The "Hey here is a cool thing you could do and solve a billion problems. Oh by the way we've patented the shit out of it and our royalty rates are pretty extreme. Ha ha ha!"

I think the last of the patents expire in 2023 which allow for an end to end zero knowledge based local transaction ledger system. That will be useful.

Re: 'Minting' electronic cash (1999)

#64

Earlier quoted context omitted.

Bitcoin isn't quite anonymous, as a variety of criminals have found out. Cash is anonymous: there is no unique identifier associated either with the transaction or the parties to the transaction. Bitcoin on the other hand is, at best, pseudonymous. This is particularly problematic because it gives information about true identities when the owner of coins wants to spend it in any way on anything where bitcoin is not a…

I wasn't talking about bitcoin, I agree on all those points. I was talking about Chaum's digital cash

got it, I appreciate the clarification.

Re: 'Minting' electronic cash (1999)

#65

Earlier quoted context omitted.

Actually the bank does more than just issue coins and detect double spending. The bank is the ultimate authority on whether any coin is valid (just like with paper money), in the sense that the bank can refuse to accept a deposit. This is crucial to the security definition of ecash -- crucial because the security definition of any cryptosystem that is trying to achieve "electronic money" must in some way define "mone…

> This is a nice property because it allows the bank to issue blacklists of cheating users That property consequently allows a bank to black list any user, not just cheating users. There are many situations where that can be not so nice. In bitcoin, cheating isn't even feasible. It's better to prevent cheating entirely than to black list cheaters after the fact.

Did you actually read what I wrote? The full tracing property means that when double spending is detected, the bank can identify all coins that the cheating user spent. Honest users remain anonymous, which is the basic security property of ecash (and a property that Bitcoin does not achieve).

Also, this may seem pedantic, but cheating is entirely feasible in Bitcoin. In Bitcoin the honest users must perform more computation than the attackers, but that means that an attack must be feasible (as the effort of honest users must be feasible for anyone to use the system).

Re: 'Minting' electronic cash (1999)

#66

Earlier quoted context omitted.

...and to achieve that, Bitcoin has a backwards approach to security where the honest parties must work harder than the attackers, which ultimately means that nobody can confidently say that the system is secure unless a majority of energy produced on Earth is being devoted to honest parties mining Bitcoin. It is also wrong to suggest that the bank in Chaum's system is a "trusted third party," as if the bank can unil…

> unless a majority of energy produced on Earth is being devoted to honest parties mining Bitcoin. Nope, try again

How do you know when enough computational effort / energy has been devoted to mining i.e. how do you know that there is no attacker out there who is working harder than all the honest users combined?

Re: 'Minting' electronic cash (1999)

#67
post #24

Earlier quoted context omitted.

In short, the suggested method by Chaum requires a trusted 3rd party (bank). The topmost invention of Bitcoin is that it requires no trusted 3rd party.

> it requires no trusted 3rd party Or, at least not the same 3rd parties. Instead, it requires trusting a much larger host of other 3rd parties, many of which are anonymous, and likely none of which will provide recourse if you lose your bitcoin due to their failure or malicious intent.[1] Bitcoin represents a shifting of trust; not an elimination of trust. That's not to say there is no value. It's just that there ar…

You don’t have to trust a “host of third parties” - you merely have to predict that a majority of third parties will not economically sabotage themselves.

Re: 'Minting' electronic cash (1999)

#68
post #30

Earlier quoted context omitted.

I don't believe this is accurate. As trust is spread across the network to an increasing number of people running nodes, the trust assigned to any individual participant approaches zero. This can be observed in the resilience of the network, as it self-heals against any attacker or alternative fork from the consensus. Bitcoin has democratically ossified into a store-of-value with absolute scarcity, deterministic mone…

> As trust is spread across the network to an increasing number of people running nodes, the trust assigned to any individual participant approaches zero. If only we knew this was true. An increase in the number of people running nodes does not guarantee that the maximum trust assigned to any individual participant approaches zero. What is the size of the largest Bitcoin whale? What is the size of the largest Bitcoin…

> What prevents China from deciding to eliminate the Bitcoin threat to its control by taking over the Chinese miners and launching a 51% attack?

China isn’t stupid.

If they 51% attacked Bitcoin (completely contrary to their self interest), everyone would switch to a different hash algorithm and now China has burned tens of billions of capital, hurt their reputation, and achieved nothing.

Re: 'Minting' electronic cash (1999)

#69

Earlier quoted context omitted.

I don't believe this is accurate. As trust is spread across the network to an increasing number of people running nodes, the trust assigned to any individual participant approaches zero. This can be observed in the resilience of the network, as it self-heals against any attacker or alternative fork from the consensus. Bitcoin has democratically ossified into a store-of-value with absolute scarcity, deterministic mone…

Trust approaches, but never reaches, zero. In practice though, so few people run full nodes relative to the whole that trust is still not nearly as decentralized as it might appear. A few rough estimates from simple searches indicates that only 10% of about 1 million miners actually run a full node. Further, while this article is about 2 years old, it indicates that many miners use outdated software that may have vul…

> A solid store of value should not fluctuate in value by 5%, 10%, 15% on a fairly regular basis.

What do you think it should look like when an asset monetizes from nothing to one of the world’s largest assets in under 15 years? A nice smooth geometric curve?

Re: 'Minting' electronic cash (1999)

#70
post #68
post #30

Earlier quoted context omitted.

> As trust is spread across the network to an increasing number of people running nodes, the trust assigned to any individual participant approaches zero. If only we knew this was true. An increase in the number of people running nodes does not guarantee that the maximum trust assigned to any individual participant approaches zero. What is the size of the largest Bitcoin whale? What is the size of the largest Bitcoin…

> What prevents China from deciding to eliminate the Bitcoin threat to its control by taking over the Chinese miners and launching a 51% attack? China isn’t stupid. If they 51% attacked Bitcoin (completely contrary to their self interest), everyone would switch to a different hash algorithm and now China has burned tens of billions of capital, hurt their reputation, and achieved nothing.

You trust China to not attack Bitcoin because you consider it against their self interest.

China just launched its own digital currency.[1]

“In order to protect our currency sovereignty and legal currency status, we have to plan ahead,” said Mu Changchun, who is shepherding the project at the People’s Bank of China.

China isn’t the only major power that needs to monitor transactions and maintain control of its money supply. There are plenty of capable parties that could launch a 51% attack and they’re unlikely to take responsibility for it afterwards, so reputation is hardly a factor. The fact that another hash algorithm could be used later doesn’t matter. A government doesn’t stop defending its interests just because threats change.

Certainly, there may never be a 51% attack, but it will not be surprising if it happens.

[1] https://www.wsj.com/articles/china-creates-its-own-digital-c...

Post reply on HN