Live data from Hacker News

Cryptocurrency in the 2020s

blog.coinbase.com

261–270 of 278 posts

Re: Cryptocurrency in the 2020s

#261

Earlier quoted context omitted.

> (He also didn't say anything about "lightning network transactions".) Correct. I'm not going by what Satoshi said, but by what development the bitcoin core team is aiming to create now. > If blocks had been 10 times bigger, the blockchain would still be less than 3 TB Correct. The aim of the project is to keep it as small as possible. 3 TB may not seem prohibitive today, but that's because there's hardly been any u…

So you admit that increasing the block size by 10x would solve the current congestion/fees problem without needing the complexity and changed incentive structure of the Lightning network, and that bitcoin doesn't compete with Visa/Mastercard yet so it doesn't need a 30 TB blockchain (which would fit on two hard drives, which many consumers have). To give an analogy, it's like saying that there should be a law limitin…

>It doesn't matter what the size of the blockchain is now (as long as it's within say 1TB that the average consumer can access).

Why does it have to fit on a laptop? Only miners influence which tx get into a block, not people on laptops.

>The problem that won't exist of billions of transactions?

Visa does 1 trillion tx/yr. Bitcoin tx is ~500 bytes That's just 500 TB/year. Miners with today's hardware can store that easily. A pruned observer node could run with just a few hundred dollars of hard drives even at Visa scale!

The bottom line is that Satoshi and others thought about this and no one saw it as a problem until Blockstream and other VC funded startups began pushing sidechains that they could profit from.

Re: Cryptocurrency in the 2020s

#262
post #256

Earlier quoted context omitted.

> I'm sure plenty of states would be happy to let you transact in crypto as long as you're willing to pay taxes. What is the point of cryptocurrency if your freedom can be impinged upon by being compelled to pay taxes? What's the point of it isn't the primary medium of exchange? If it's not that, then it's just a deflationary store of value, functioning like gold, which nobody uses for daily transactions, therefore o…

What's the point if it's not the primary medium? I just gave you an example, taking my money elsewhere. Bank accounts can be frozen. I think you're moving the goalpost from "crypto grants me more financial freedom" to "crypto makes me literally untouchable by governments". Nobody here is claiming the latter. I have no idea where you even got the tax evasion angle from anything I said.

> I just gave you an example, taking my money elsewhere.

Why do you think that the state that accepts you would give you anything like the market exchange rate for the cryptocurrency to their currency?

The only way would be if they had a competitive internal market for purchase of cryptocurrency, but it's not at all clear that would be the case, since in this situation, you would need asylum (a service they would be providing to you) more than they need your cryptocurrency. That would come at a price.

You could try to play these countries off one another to get the best possible exchange rate, but really, you'd have to be stupendously wealthy in crypto before those countries would begin to care enough to offer you any kind of deal.

Re: Cryptocurrency in the 2020s

#263
post #260

Earlier quoted context omitted.

It's complicated, and I'm not sold on the Lightning Network as the future, but > Which can be be reneged on if one party is malicious, meaning they'll only occur between trusted parties? This is not correct. My understanding is essentially each party is tying up Bitcoin as being between them on the blockchain, then trading cryptographically verifiable assertions of each other off-chain about what the latest status of…

> My understanding is... That's how two finserv companies would transact off-chain with each other, but when I go to buy a cup of coffee with a bitcoin, I'm not opening up a payment channel with them for one transaction, that would defeat the whole point. The coffee shop will use a payment processor, who isn't going to deal with me off-chain unless I'm the KYC'd customer of them or some other finserv they trust. (ple…

In the case of purchasing coffee, your payment can make multiple hops (through multiple channels) to the coffee shop. This means you only need a channel open with 1 participant in order to be able to transact, and none of you need to trust each other.

Re: Cryptocurrency in the 2020s

#264
post #260

Earlier quoted context omitted.

It's complicated, and I'm not sold on the Lightning Network as the future, but > Which can be be reneged on if one party is malicious, meaning they'll only occur between trusted parties? This is not correct. My understanding is essentially each party is tying up Bitcoin as being between them on the blockchain, then trading cryptographically verifiable assertions of each other off-chain about what the latest status of…

> My understanding is... That's how two finserv companies would transact off-chain with each other, but when I go to buy a cup of coffee with a bitcoin, I'm not opening up a payment channel with them for one transaction, that would defeat the whole point. The coffee shop will use a payment processor, who isn't going to deal with me off-chain unless I'm the KYC'd customer of them or some other finserv they trust. (ple…

I think you're correct in that this will be the inevitable result. It just won't really be for trust reasons.

You won't want to open up a payment channel to them, but you don't need to. You just need an already open payment channel to someone who is, or (more importantly) there is some route of payment channels between you and them through any number of intermediaries.

There won't be a way to enforce KYC on the network itself, and you don't need trust for this to work.

But because of the inherent cost / time / complexity reduction benefits of just maintaining big channels between large entities, normal people and businesses will inevitably be incentivized to just work through banks to do this. The banks can just hold all their money and handle keeping the channels between themselves open and funded.

And that's where I think you're correct. It leads to a world where KYC can be required easily because the vast majority of legitimate use cases will be through centralized endpoints.

Re: Cryptocurrency in the 2020s

#265

Earlier quoted context omitted.

So you admit that increasing the block size by 10x would solve the current congestion/fees problem without needing the complexity and changed incentive structure of the Lightning network, and that bitcoin doesn't compete with Visa/Mastercard yet so it doesn't need a 30 TB blockchain (which would fit on two hard drives, which many consumers have). To give an analogy, it's like saying that there should be a law limitin…

>It doesn't matter what the size of the blockchain is now (as long as it's within say 1TB that the average consumer can access). Why does it have to fit on a laptop? Only miners influence which tx get into a block, not people on laptops. >The problem that won't exist of billions of transactions? Visa does 1 trillion tx/yr. Bitcoin tx is ~500 bytes That's just 500 TB/year. Miners with today's hardware can store that e…

> A pruned observer node could run with just a few hundred dollars of hard drives even at Visa scale!

Each node would need to download 1.4 TB of data per day (500TB / 365) to keep up, and the UTXO set would presumably expand dramatically with a volume increase of that magnitude, making it impracticable to store even a pruned state on a consumer hard drive.

Re: Cryptocurrency in the 2020s

#266
post #252

Earlier quoted context omitted.

It’s a complex socio-economic-technical system, which probably can’t be perfectly quantified. Same as with the weather or the larger economy. We can understand it to some degree, but lack of perfectly predictive models does not invalidate these concerns, as you imply. “Everyone must run a full node” is aspirational but not realistic. It’s nevertheless extremely valuable to continue working on ways of reducing the exp…

> It’s nevertheless extremely valuable to continue working on ways of reducing the expense of running full nodes. And nobody will claim otherwise. But there's always a trade-off, and focusing only on reducing the expense is severely misguided. > Throwing caution to wind so Bitcoin can have fast payments Now at the expense of failing at sound money later is short-sighted and irresponsible. The funny thing is, the inac…

>And nobody will claim otherwise. But there's always a trade-off, and focusing only on reducing the expense is severely misguided.

That's conventional wisdom and applicable in lots of other places, but not in cryptosystem design. People have to accept that cryptosystems in general and cryptocurrency in particular are different domain from most other software engineering they're used to.

Any single error or bug can result in the complete compromise and failure of the entire system. The old rules of calculating acceptability of risk and errors based on whether they enable more value creation than they put at risk, no longer apply, because any/every error can result in total loss.

I believe different world views on this issue is one of the root causes of the schism in Bitcoin.

>The funny thing is, the inaction of the Bitcoin devs have made it fail at one of the core features of money. You cannot consider it to be acceptable, as fees are so expensive they price out a lot of people. Money should be easy to move around, and you should be able to buy large and small things with it.

That's a "nice to have" for sure, but not at the risk of a Global Financial Crisis style event happening to Bitcoin itself. The prudence of the Bitcoin devs has made it succeed at avoiding that so far.

>Yet this is somehow preferable, because doing otherwise would make Bitcoin "fail at sound money", whatever that means.

There's no need to be confused about that term, it has a simple, clear and easy to understand meaning. Sound money is money whose supply and value is both transparent and un-manipulatable.

When you choose to store savings in that currency, you know how it works, and you know it can't be changed in the future (to either your detriment or benefit). Sound money is a social contract that can't be broken or reneged.

By way of counter-example, in the GFC, the US Fed pumped up the money supply to prevent the failure of the banking system, risking devaluation of dollar-based savings and hyperinflation to the detriment of everyone else.

For another counter-example, the US Govt's inability to control its deficit and debt may one day result in it having to monetize the debt (print more dollars to pay for it), devaluing the dollar and dollar-based savings, and harming global confidence in the dollar as a reserve asset.

Cryptocurrency as sound money is a hedge against that, and that's the ultimate killer app. But if you lose enough decentralization, you lose this characteristic of it. Then its worthless, regardless how good of a payment system it makes.

And it will never be better than Paypal and other centralized payments services at merely transferring money quickly and cheaply, so if it has no other value proposition like sound money then its worthless.

Re: Cryptocurrency in the 2020s

#267
post #262

Earlier quoted context omitted.

What's the point if it's not the primary medium? I just gave you an example, taking my money elsewhere. Bank accounts can be frozen. I think you're moving the goalpost from "crypto grants me more financial freedom" to "crypto makes me literally untouchable by governments". Nobody here is claiming the latter. I have no idea where you even got the tax evasion angle from anything I said.

> I just gave you an example, taking my money elsewhere. Why do you think that the state that accepts you would give you anything like the market exchange rate for the cryptocurrency to their currency? The only way would be if they had a competitive internal market for purchase of cryptocurrency, but it's not at all clear that would be the case, since in this situation, you would need asylum (a service they would be…

This is just whattaboutism seeing as there's currently good crypto exchanges in every major currency, accessible from most countries. Does your argument hinge on this somehow changing everywhere?

Do you know what asylum is? I can permanently move to plenty of countries without asylum, I think you're getting a bit off track..

Re: Cryptocurrency in the 2020s

#268
post #153

Earlier quoted context omitted.

It's only a debt for the business who receives the loan. When a business receives a loan it shows up as an asset to them in the form of a bank deposit. The business then usually uses that demand deposit to purchase goods and services, so people who don't owe debt to the bank get those deposits in their accounts, and spend the deposits, etc., etc. So effectively, private banks create money.

You missed the part where the business gives the money for those goods and services back to the bank plus interest and the fact that the bank already had the money to give, nothing was created

The bank doesn't usually "have the money to give" when it makes a loan.

Let's say Bank A loans $1000 to a customer. It creates a $1000 bank deposit in that customer's account. On the balance sheet it looks like this:

Bank A:

(Asset) Loan to customer of $1000

(Liability) Bank deposit in account of customer $1000

Bank A created the $1000 at will out of thin air. This is how it happens most of the time.

Re: Cryptocurrency in the 2020s

#269

Earlier quoted context omitted.

Reusing the same attack would just result in a never-ending series of offshoots from the "western" chain. If anything that would guarantee that the uncensored chain stays dominant, as all of the forks would be quicky abandoned for the next

You can't expect people to fork every week to a new network. This is at best a one time deal, and if it doesn't work, that's it.

People wouldn't do it manually--the entire point is to automate it.

But you corrected your assumption in the other comment thread, so I'll continue the conversation there.

Re: Cryptocurrency in the 2020s

#270

Earlier quoted context omitted.

> Every fork is vulnerable to the same attack, which is why such a switch doesn't make sense. No, it wouldn't. I don't think you're understanding the solution I'm proposing. There isn't an amount of computing power that allows you to submit invalid blocks.

I assumed you meant manually. This method isn't possible to automate under PoW, because any such actions require global time, but PoW is what provides time itself, creating a contradiction. What this means in practice is network splits. >you know the transaction exists, and at some point (i.e. after a certain number of blocks), if the transaction isn't included in the chain, you can conclude with reasonable certainty…

EDIT: Everywhere I say that we wait 5 blocks/confirmations, that's just a number I picked. I think you could conservatively use fewer confirmations, but there's a bunch of network analysis you'd have to do to calculate what the probability of a transaction not being included in N sequential blocks simply due to network instability. I didn't do that network analysis, so you might need more or fewer confirmations to be reasonably sure that censorship is occurring and not just network instability.

> I assumed you meant manually. This method isn't possible to automate under PoW, because any such actions require global time, but PoW is what provides time itself, creating a contradiction. What this means in practice is network splits.

I don't think you need global time to do this. More on this later in this post.

> as what would happen is nodes that were online and observed the situation would follow one chain, but everyone else that joins later wouldn't be able to confirm that censorship actually happened, and follow another. If you have a solution that solves it, you solved the fundamental problem - absolute order - some other way and PoW becomes completely superfluous.

This situation resolves itself naturally via the mechanism I proposed.

Let's follow the scenario you propose and see how it resolves. The following events happen in this order:

1. The Chinese government decides to censor transactions from a certain address, refusing to accept blocks which include transactions from that address.

2. A transaction from that address is broadcasted.

3. Chinese miners mine 5 blocks that don't contain the transaction. Nodes which have been on the network the whole time notice the censored transaction, and go to the next-longest chain, creating a fork.

4. A new node joins the network. From the new node's perspective, there are two chains, but the Chinese one is longer so you go with that. However, you still have the signed transactions from the shorter chain, and your node notices that the Chinese chain doesn't contain some of those transactions. At the time of joining, as far as you know, that transaction simply hasn't been included in the longest chain yet.

5. Chinese miners mine 5 more blocks that don't contain the transaction. The newly-added node now notices the censored transaction, rendering the current chain invalid, and goes to the longest valid chain, which is the one everyone else was on. Consistency achieved.

The implication of this solution is that when you join the network, you now have to wait for 5 confirmations to ensure none of the transactions you have are being censored in the longest chain (i.e. it takes 5 confirmations to know that the longest chain is valid). Which is certainly an important implication!

Note that absolute order doesn't matter here. We don't have to know the order of the transaction, only that it has existed for some number of blocks without being included in the chain.

> Then there's a problem of: what happens when there are contradictory transactions on two different chains at once? How do you decide which one is valid? This gets complex very fast.

The way you've worded it, that's not really all that complex--that's the same as a double spend, and it's resolved the same way any other contradictory transaction is resolved: follow the longest (valid) chain (where part of the definition is "valid" is "containing all transactions I've had for 5 confirmations").

However, I think you might have left out part of what you meant here, so I'll try to explain what I think you're hinting at. There's a sophisticated way for China to hide their attack. It works like this:

1. The Chinese government decides to censor transactions from a certain address, refusing to accept blocks which include transactions from that address.

2. A transaction from that address is broadcasted. We'll call this the censored transaction.

3. Non-Chinese miners mine a block that includes the censored transaction. This becomes the root of what we'll call the censored branch.

4. Chinese miners ignore the mined block that includes the censored transaction, and mine a block which doesn't contain the transaction. This block becomes the root of a branch we'll call the red herring branch. In that block, they include a transaction which they never broadcasted to the network. We'll call this the red herring transaction.

5. Due to superior Chinese mining capability, the red herring chain quickly becomes longer. However, after 5 confirmations, the network notices the censored transaction isn't being included in the red herring chain. So they invalidate the red herring chain and go to the longest valid chain, which is the censored chain.

6. 4 more blocks are mined on the censored chain.

7. A new node joins the network.

8. At this point, the censored branch doesn't include the red herring transaction, and the red herring branch doesn't include the censored transaction. So our previous resolution strategy doesn't work, because we don't know whether it's the red herring transaction or the censored transaction that's being censored.

First, I want to say, this is a really sophisticated attack and I want to congratulate you for coming up with it.

Second, I think this problem can be solved by sweeping up ALL the transactions in EVERY block you receive, even if they are in blocks which haven't been confirmed, and treat them as if they were broadcast to you on the network. This way, the red herring transaction gets included into the censored branch. This gives us a new resolution:

1. The Chinese government decides to censor transactions from a certain address, refusing to accept blocks which include transactions from that address.

2. A transaction from that address is broadcasted. We'll call this the censored transaction.

3. Non-Chinese miners mine a block that includes the censored transaction. This becomes the root of what we'll call the censored branch.

4. Chinese miners ignore the mined block that includes the censored transaction, and mine a block which doesn't contain the transaction. This block becomes the root of a branch we'll call the red herring branch. In that block, they include a transaction which they never broadcasted to the network. We'll call this the red herring transaction.

5. Due to superior Chinese mining capability, the red herring chain quickly becomes longer. However, after 5 confirmations, the network notices the censored transaction isn't being included in the red herring chain. So they invalidate the red herring chain and go to the longest valid chain, which is the censored chain.

6. A new block is mined on the censored chain. Since we've swept up all the transactions from the red herring chain, this block includes the red herring transaction.

7. A new node joins the network and assumes the red herring chain is the longest valid chain.

8. After 5 blocks, the new node sees the red herring chain does not contain the censored transaction, invalidates the red herring chain, and goes to the longest valid chain, which is the censored chain. Consistency achieved.

Post reply on HN