Live data from Hacker News

Bitcoin is "Worse is Better"

gwern.net

21–30 of 36 posts

Re: Bitcoin is "Worse is Better"

#21
post #17
post #16

Earlier quoted context omitted.

This is an application of Bitcoin. It says, "well, people want something that promises what Bitcoin promises; therefore, Bitcoin must be intrinsically valuable". But it's obvious why that isn't true. Flitcoin promises precisely the same things.

i'm not really worried about the intrinsic value of bitcoin, it goes up, it goes down, it doesn't matter. You don't have to store your wealth in bitcoin, USD goes in USD goes out when you want it to at usually 0.5% transaction cost ( or less some places ). And there's no reason Flitcoin can't succeed in the same places. I'm not sure why that would have anything to do with intrinsic value or why intrinsic value is of…

In other words, you're content to ride out the "greater fool" theory, confident that you'll be able to jump out before the market spirals down to zero. And that's fine, but it doesn't address the question that roots this thread.

Re: Bitcoin is "Worse is Better"

#22
post #20
post #19

Earlier quoted context omitted.

As long as we're talking about Bitcoin, mind clarifying your criticisms? it almost totally fails to achieve its security objectives, that it exploits a misperception about anonymity to handwave away the fact that for most users it is not anonymous Are these the same -- both referring to the mere pseudonymity of addresses? it is reliant on centralized infrastructure How so? My understanding is that anyone can generate…

The dollar isn't a currency simply by convention. Neither is gold. It only seems that way in the frictionless vacuum of message board arguments.

Agreed, and I didn't say they were.

Re: Bitcoin is "Worse is Better"

#23
post #8
post #6

Earlier quoted context omitted.

- meaningless as currency: I am actually not sure how elegance plays into that at all, so I have no cute analogy to rpg's Unix/ITS system calls. The wasted computing power is inherent to the system of avoiding double-spending (I also spent some time discussing this), but that's not related to Bitcoin being worthless or not as a currency. Any damn thing can be currency, after all; currencies are as currencies do. It w…

In this comment I would like to propose "Flitcoin". Flitcoin is nearly identical to bitcoin, with exactly one difference. In Flitcoin, instead of brute forcing a nonce through SHA-256(x) to find hashes with a suitable prefix of 0's, Flitcoin brute forces a nonce through HMAC-SHA256("bananas", x) to find hashes with a suitable suffix of 1's. Please explain to me why my Flitcoin is inferior to your Bitcoin. As you do s…

Bitcoin has a long hash chain already in existence and a large amount of computing power currently lengthening it. Bitcoin may or may not be valuable, but the amount of total CPU time invested into it and the current rate of CPU use are criteria one can use to decide if one proof of work network is superior to another.

Re: Bitcoin is "Worse is Better"

#24
post #12

Earlier quoted context omitted.

Bitcoin already has users and Flitcoin doesn't?

So, marketing? Ok! I'll just run a 2-for-1 sale on Flitcoin. Less snarkily: why are people using Bitcoin? What's the intrinsic value they see in Bitcoin? Based on what evidence can they predict that Bitcoins purchased today will be convertible to gold, dollars, or even toenails at any valuation? You've begged the question.

Why are people using BitCoin?

Language-seeking behavior, maybe.

Conceptually understandable and highly desirable.

BitCoin is in mind as word is bond|currency|techlogically valuable. An alternative value.

People beg and question $, and given alternative, goldmind rush wins.

Alternative values are worth risks.

A bit of sense.

Re: Bitcoin is "Worse is Better"

#25
post #7
post #4

Earlier quoted context omitted.

Thanks for reading; your summary is pretty decent. But obviously I differ about the elegance and following. Elegance is not optional; elegance is useful; elegance has important practical consequences. Go back to rpg's original paper and one of his examples - the difference between ITS and Unix in system calls was not one of mere aesthetic elegance, but a case where Unix programs were incorrect and could, and did, fai…

The point Ben is making is not simply that Bitcoin is wasteful, although it is. The point is that a $101 certificate for the smoke from $100 in burnt five dollar bills isn't worth $101. Or $100. Or $5. Or $0.01. You can declare by fiat that as a proof of effort, the smoke certificate is worth something. You can try to convince people that certificates representing smoke function as a medium of exchange. But as a medi…

> Here the nerdly Bitcoin advocate handwaves around the fact that we actually have notions of what it means to be a "good" or "bad" currency.

Like we had notions of what it means to be a "good" or "bad" encyclopedia before Wikipedia came out. Saying that Bitcoin is bad as a traditional currency does not prove that it is useless.

Re: Bitcoin is "Worse is Better"

#26
post #9
post #5

Earlier quoted context omitted.

> As someone who has spend some time hacking the bitcoin code, I would say I have little confidence. There are a lot of differing opinions on this. I quoted Kaminsky at length as someone with major security credentials who is saying the opposite of you.

You are citing as an authority on code quality someone who says Bitcoin should use Bcrypt instead of SHA-256 because Bcrypt is less amenable to hardware optimization. I hope to make the starburst of applicable points that follow from this by implication instead of explicit argument.

I'm afraid you're going to have to be explicit, because the idea of using Bcrypt for that reason makes perfect sense to me - the logic that makes Bcrypt better than SHA-256 for passwords seems to apply nicely to Bitcoin. Hardware optimization privileges the few who can invest in the hardware over the many who are able to run more commodity hardware, and is exactly contrary to the P2P Bitcoin ethos.

(A similar point applies to time-lock puzzles: http://www.gwern.net/Self-decrypting%20files Why were Rivest/Shamir/Wagner unhappy with brute-force decrypting? Because it's so amenable to hardware optimization. Why were subsequent researchers unhappy with successive squaring and looked for memory-bound hashes? Because squaring is still implementable in hardware.)

Re: Bitcoin is "Worse is Better"

#27
post #21
post #17

Earlier quoted context omitted.

i'm not really worried about the intrinsic value of bitcoin, it goes up, it goes down, it doesn't matter. You don't have to store your wealth in bitcoin, USD goes in USD goes out when you want it to at usually 0.5% transaction cost ( or less some places ). And there's no reason Flitcoin can't succeed in the same places. I'm not sure why that would have anything to do with intrinsic value or why intrinsic value is of…

In other words, you're content to ride out the "greater fool" theory, confident that you'll be able to jump out before the market spirals down to zero. And that's fine, but it doesn't address the question that roots this thread.

you can jump out whenever you get bitcoins. You don't have to hold onto bitcoins more than a few minutes after a transaction is confirmed. You can tie goods/service to the market rate and sell your bitcoins whenever you get them. It won't matter what the price is, $30 or $0.30. No fooling going on. And tell me again what the question is that roots this thread?

Re: Bitcoin is "Worse is Better"

#28
post #8
post #6

Earlier quoted context omitted.

- meaningless as currency: I am actually not sure how elegance plays into that at all, so I have no cute analogy to rpg's Unix/ITS system calls. The wasted computing power is inherent to the system of avoiding double-spending (I also spent some time discussing this), but that's not related to Bitcoin being worthless or not as a currency. Any damn thing can be currency, after all; currencies are as currencies do. It w…

In this comment I would like to propose "Flitcoin". Flitcoin is nearly identical to bitcoin, with exactly one difference. In Flitcoin, instead of brute forcing a nonce through SHA-256(x) to find hashes with a suitable prefix of 0's, Flitcoin brute forces a nonce through HMAC-SHA256("bananas", x) to find hashes with a suitable suffix of 1's. Please explain to me why my Flitcoin is inferior to your Bitcoin. As you do s…

In this comment I would like to propose "PTTH". PTTH is nearly identical to HTTP, except you replace all occurrences of "HTTP" in the protocol by "PTTH". Why is this inferior to HTTP? Why are people investing time and money to provide HTTP service and not PTTH service? You are right when you say that the artificially imposed scarcity on Bitcoins does not entail a scarcity on digital currencies in general, but, as it stands, your argument seems weird.

Actually, I believe that Bitcoin's (possibly short-lived) fame has created some sort of value in the sense that there would probably be, for quite some time, people interested in hoarding Bitcoins just as a kind of souvenir ("hey, remember, people used to get excited over this"); not so with Flitcoin. I am not saying that this is something reasonable to base a currency on, just that it is wrong to assume that Bitcoin and Flitcoin are strictly equivalent.

Re: Bitcoin is "Worse is Better"

#29
post #7
post #4

Earlier quoted context omitted.

Thanks for reading; your summary is pretty decent. But obviously I differ about the elegance and following. Elegance is not optional; elegance is useful; elegance has important practical consequences. Go back to rpg's original paper and one of his examples - the difference between ITS and Unix in system calls was not one of mere aesthetic elegance, but a case where Unix programs were incorrect and could, and did, fai…

The point Ben is making is not simply that Bitcoin is wasteful, although it is. The point is that a $101 certificate for the smoke from $100 in burnt five dollar bills isn't worth $101. Or $100. Or $5. Or $0.01. You can declare by fiat that as a proof of effort, the smoke certificate is worth something. You can try to convince people that certificates representing smoke function as a medium of exchange. But as a medi…

Your economic points seem to be just reiterating the claim 'currencies must have a backing!', which is something people can disagree on and not relevant to the essay. (If some random country adopted Bitcoin as its currency, would it suddenly cease to be Worse is Better and just be Better is Better? Or vice versa? If not, then the tough economics/philosophy question of whether a currency needs backing to be a 'currency' is not relevant.)

> To all that, add the critiques you sourced of Bitcoin; that while it has impressive virality, it largely fails at its security goal by making the cost to defend transaction integrity greater than the cost of attacking it; that it largely fails at its anonymity goal by requiring a complete audit log be made available to everyone simply in order to function; that it largely fails at its decentralization goal by requiring resources comparable to that of a Visa or a Mastercard just to scale.

It's true that the cost of defense is similar to attack, the audit log is public, and the scaling story is not good. But does it fail? That's the question, and so far it seems to bumble along, with all the major problems being in things surrounding Bitcoin (MtGox, MyBitcoin, that Polish exchange) but not actually Bitcoin. Bitcoin fails on a lot of properties, but it's still there. Unix failed at a lot of things too, but somehow it's still around.

That's kind of the essence of Worse is Better - maybe those security properties or software properties are not as important and valuable as people judging the elegance thought that they were.

Re: Bitcoin is "Worse is Better"

#30
post #26
post #9

Earlier quoted context omitted.

You are citing as an authority on code quality someone who says Bitcoin should use Bcrypt instead of SHA-256 because Bcrypt is less amenable to hardware optimization. I hope to make the starburst of applicable points that follow from this by implication instead of explicit argument.

I'm afraid you're going to have to be explicit, because the idea of using Bcrypt for that reason makes perfect sense to me - the logic that makes Bcrypt better than SHA-256 for passwords seems to apply nicely to Bitcoin. Hardware optimization privileges the few who can invest in the hardware over the many who are able to run more commodity hardware, and is exactly contrary to the P2P Bitcoin ethos. (A similar point a…

Bcrypt isn't specifically harder to compute on GPUs. It just has an adjustable amount of work it has to do which increases the load. Bitcoin effectively has the same thing with the difficulty.
Post reply on HN