Live data from Hacker News

Facebook Libra Is Architecturally Unsound

stephendiehl.com

211–220 of 347 posts

Re: Facebook Libra Is Architecturally Unsound

#211
post #16

Typical blockchain and Libra hatchet job, except this time under the veneer of someone with software skills. I will make some counterpoints. > Byzantine fault tolerance is a fairly niche area of distributed systems research that concerns the ability of a networked system to endure arbitrary failures of its components while taking corrective actions critical to the system’s operation. Networks that are byzantine toler…

> Libra is supposed to be a decentralized blockchain payment system, similar to Bitcoin

There's a very big difference between Libra and Bitcoin. In Bitcoin miners can come and go as they please, and they don't have to be known or trusted. Bitcoin's innovation with POW was to make this possible at all.

In Libra the consensus nodes are known, making POW unnecessary.

Re: Facebook Libra Is Architecturally Unsound

#212
post #188

Earlier quoted context omitted.

Blockchains are just a datastructure and proof of work is not a strict requirement. I believe the rising popularity of Proof of Stake blockchains will make that evident.

> Blockchains are just a datastructure Again, wrong. > proof of work is not a strict requirement. I believe the rising popularity of Proof of Stake blockchains will make that evident. I thought for a second whether I should include PoS and other schemes, but decided (wrongly) that nobody would try to squeeze imaginary internet points out of being willfully misunderstanding. But so be it: proof of stake is a different…

My comment had nothing to do with imaginary internet points. You just said being wasteful was part of the definition of a blockchain which is a common argument people like to make when promoting the false idea that blockchains are inherently bad for the environment. It felt important to point out that there are non-wasteful ways of accomplishing the same thing as PoW.

Re: Facebook Libra Is Architecturally Unsound

#213
post #204

I don't disagree with the article per se, but I think many technologists are missing the forest for the trees when it comes to the motivations here. Or perhaps they're being charitable and are evaluating Libra on purely on its stated motivations rather than the ulterior motive that Libra can't name out loud. For example, take this quote: "The possibility that a Libra node run by Mastercard or Andressen Horrowitz woul…

There was this story from a month ago: https://news.ycombinator.com/item?id=21120956 A street vendor in canada was selling cuban coffee. They used "square canada" as a payment processor. Square canada, in turn, used the US bank JPMorgan as a back end. JPMorgan is required to enforce an embargo on money going into cuba. The seller and all the buyers were in canada, but because the money passed through a US bank, they…

Havinga bunch of US corporations run the global payment system won't solve this problem.

Re: Facebook Libra Is Architecturally Unsound

#214
post #203
post #146

Earlier quoted context omitted.

I think you've misread my comment. Also, of course theory could be used to make judgment given all the necessary context, but the context, in this case, is much harder to obtain than the theory. If we knew whether a language's type system being sound is greatly positive (for some metric), slightly positive, neutral, slightly negative or greatly negative, then the knowledge that a certain language is sound or not coul…

I’m new to this space so I’m not sure how PLT is distinct from formal verification, but my view of it is that formal methods are another form of testing. Unit testing also does not guarantee that you’re testing the right things, but it’s a good way to catch issues post-compile but pre-release. Formal verification moves that so that you catch issues as part of the compilation step, which is just another tool in the ge…

Formal methods are a large set of methods that allow you to analyze a program in ways that can verify it satisfies certain (correctness) properties. Most formal methods don't generate tests (although some do), but the term "compile-time" is not often used, as most formal methods are not part of the compiler.

There is some overlap between PLT and formal methods, as that some concepts studied in PLT -- most notably type systems -- can be used for formal verification, but the main thrust of formal methods uses other techniques. Both disciplines heavily rely on formal logic.

Re: Facebook Libra Is Architecturally Unsound

#215
post #107
post #65

Earlier quoted context omitted.

If you may spare a minute, I'd like to know your opinion on mission-critical software in dangerous-prone contexts (such as avionics, life support, even just economically for permanently-written "ROM" software, etc). Formal methods seem required in such projects, but your final paragraph seems to imply the formalism isn't key to end quality? (my agenda, for transparency: I want to send SOC's in space on tiny RISC-V sa…

Beware of bugs in the above code; I have only proved it correct, not tried it. --Donald Knuth On the one hand we have the management mantra: if you can't measure it you can't improve it. On the other hand we have Goodhart's law. And so 'correctness', 'safety', 'quality' (or absence thereof) are fluid concepts that can never be formalised precisely. Language/logic sucks, but it's all we've got.

> Language/logic sucks, but it's all we've got.

Perhaps, but PLT is not the main discipline studying software correctness -- those would be formal methods and software engineering -- although it has some overlap with those disciplines. PLT is not the general name for all study of programs; it is the name for a particular perspective, and a particular component of that study.

Re: Facebook Libra Is Architecturally Unsound

#216
This post is nonsense. 1) FB claims they want to eventually make it a public network. Therefore, they'll need BFT sooner or later. 2) No blockchain can match a centralized system (WeChat, Visa, et al). 3) Very few languages have a formal semantics written in Coq. 4) So what if the crypto lib has additional functions? Algorand has VRF code in their repo. Is the whole project doomed now? And it would take a huge effort to verify a crypto lib ala Everest. Even cryptographers don't do it. 5) In the US many banks are in a consortium called Zelle which allows retail customers to send money around. It has finality; can't be reversed.

I don't give 2 shits about Libra. Gov'ts will clobber it anyway. But these criticisms are mostly "why didn't Libra do the latest bleeding edge researchy thing that no-one else does?" Because they had to ship this century, that's why.

Re: Facebook Libra Is Architecturally Unsound

#217

Earlier quoted context omitted.

Yeah, for now it's all we have, so I guess the juice is worth the squeeze. But in a world where our cryptocurrencies are a bit more mature I think we can stop being reactive by reversing transactions and start being preventative by using their structure to build chains and webs of trust that make fraud harder to commit up front, rather than just making it harder to get away with.

The amounts to giving the advantage to fraudsters until something that doesn't exist is invented. Blockchains are irrevocable and unalterable, which removes two useful tools (reversing and changing transactions), and replaces them with nothing workable.

> Blockchains are irrevocable and unalterable

But so are events in the real world. When you think about "reversing or changing a transaction" what you really mean is creating a new transaction that brings an equivalent amount back to the person that paid it.

This is done in the real world by knowing the identity of the receiver person or entity and threatening them with consequences if the money is not returned. It seems to me more a problem of being able to identify the parties in a transaction rather than of mutability of the ledger.

Re: Facebook Libra Is Architecturally Unsound

#218
post #166

Earlier quoted context omitted.

Blockchain gives the impression that the primary threat it is designed to defend against, is a government deciding (like Germany between world wars) to inflate their currency for whatever reason. So, not surprisingly, in order to defend a currency against being decreased in value by a central authority, it is vulnerable to all of the threats that a central monetary authority might help you with. Which of these threat…

Right, here in Argentina our currency has lost more than half its value this year, and the US dollar has lost 96% of its value since the end of the gold standard in 1973. I carry a Zimbabwe 100 trillion dollar bill in my wallet to remind people what real hyperinflation is. I don't think that's the main threat Bitcoin is designed to defend against, though; I think there's a whole spectrum of confiscation threats, rang…

I see your point, but I think there are plenty of examples of people losing their Bitcoins through analogous nefarious activities (e.g. MtGox). For an expert in cybersecurity perhaps Bitcoin is safer, but for the average non-technical person (in the U.S.) it is probably _more_ likely to get your money taken by a thief than if you had it in fiat currency in a bank, though of course either one is possible.

Again, this could vary depending upon your nation's government and crime situation.

Re: Facebook Libra Is Architecturally Unsound

#219

Earlier quoted context omitted.

Yeah, for now it's all we have, so I guess the juice is worth the squeeze. But in a world where our cryptocurrencies are a bit more mature I think we can stop being reactive by reversing transactions and start being preventative by using their structure to build chains and webs of trust that make fraud harder to commit up front, rather than just making it harder to get away with.

The amounts to giving the advantage to fraudsters until something that doesn't exist is invented. Blockchains are irrevocable and unalterable, which removes two useful tools (reversing and changing transactions), and replaces them with nothing workable.

The faults that people are attributing to blockchain are also applicable to cash, if you go the market and buy some magic beans from dodgy Dave with cash you won't be getting your money back. If you buy something from a reputable supplier with cash/blockchain then you would probably get a refund if you had some form of receipt.

Re: Facebook Libra Is Architecturally Unsound

#220

Earlier quoted context omitted.

Your understanding of inflation is misguided. Inflation as we have it under central banking today is theft. A GSE creates money from nothing. Large banks are allowed to have this money at near-zero cost, and lend it to others and a higher cost. It's a free profit for large banks. It's 100% organized theft. This is the scenario that create the 'too big to fail banks' that we had to give even more money to keep the sys…

Ok round 2. > “inflation is theft” I think you didn’t read anything I wrote because my core focus is that inflation is 100% avoidable through investment which is the behavior explicitly being incentivized via, to your point, a stick and not a carrot approach. It’s theft like taxation is theft: it’s not. > a GSE creates money from nothing Yes that’s the point. The economy gets bigger and more people are born and the m…

> It’s theft like taxation is theft: it’s not.

Taxation is also theft.

> If you don’t believe the value of existing money should go up then you agree the money supply must expand to match economic growth and population growth.

The unit of exchange (money/currency) should remain relatively constant. That's the point. Maybe it will go up some, maybe it will go down some, but having it manipulated for the profit of large banks is theft.

It's a complete perversion of free market banking and benefits the few over the many.

> 100% avoidable through investment

Not true, unless you're talking about investing in financial instruments. Investing in almost anything else subjects you to property taxes almost everywhere.

Post reply on HN