Showing posts with label Ethereum. Show all posts
Showing posts with label Ethereum. Show all posts

Monday, August 1, 2016

Contentious Bitcoin fork WILL create a split

Contentious Bitcoin fork WILL create a split

The Bitcoin community has debated a potential hardfork to Bitcoin for over a year now. There have been various solutions proposed to change the hard cap on block size and increase the amount of transactions that can go into any single block.

Leaving aside the discussion as to which approach would be the best for Bitcoin in the long run, we can agree that there is a disagreement on the issue and any hard fork that may happen will not be as unanimous as the previous forks were. Looking at some recent examples, we can expect that any contentious Bitcoin fork will create a split in the network.

Big players can trump forks - Elacoin


Last year Steve Sokolowski shared his thoughts on a Bitcoin hard fork proposal in a forum post. Other than discussing the actual solution, Steve also shared a story of Elacoin's attempted hard fork. Apparently, it was some unremarkable Proof of Work altcoin which activity has died off after awhile. A new developer came in and decided to breathe new life into the coin by creating a Proof-of-Stake fork. A lot of people got excited for the update and the trading volume and price rose back up.

When the fork was scheduled to take place, despite the backing of the community, the developers and stakers, the fork failed since Cryptsy continued to trade the coin without upgrading their daemon. Eventually the hard fork was deemed a failure while the old coins were still being traded.

This brings to mind the famous experiments with five monkeys, a ladder and a banana. People would trade a coin in anticipation of the fork, then ignore the fork and continue trading the coin due to its increased price and volume, completely forgetting why they were trading it in the first place. Classical altcoin speculators.

This only goes to show that big players, even if they are in a minority, can trump developer forks. While a story like this is rather unlikely to happen in Bitcoin, since the coin itself has many different markets and a vast community, we could experience a different problem when a hard fork happens...

New Coke vs Coke Classic - Ethereum


Not so long ago, Ethereum has experienced The DAO debacle, wherein a large quantity of ethers were drained from a high-profile smart contract. This prompted the Ethereum developers to create a hard fork that invalidated the attack. For a few days everything seemed to go smoothly - the majority of the network supported the fork, everyone transitioned just fine and it looked like the network could put the kerfuffle behind them. Then came Ethereum Classic...

Ethereum Classic is, I suppose, an "un-fork" of Ethereum - a codebase designed to ignore the DAO hard fork and continue the network as if it never happened. Whether the developers believe that they are supporting the community that disagrees with the fork, or they just want to make a quick buck, the fact is that the classic ethers (ETC) started being traded on Poloniex, probably one of the biggest altcoin exchanges currently, and now are being actively traded on a number of other exchanges with a current market cap of $200M and 24h trade volume of $65k - forth market cap after Bitcoin, Ethereum and Ripple, and having double the trading volume of Ethereum, second only to Bitcoin...

From a perspective of any Bitcoin core developer wanting to fork Bitcoin, this is probably the worst thing that could have happened in the given situation. Exchanges supporting both sides of a fork can set a precedent of what will happen when Bitcoin is forked in any fashion short of full unanimity. Even if the unforked version of Bitcoin has 1% of its market cap, that's $94M market waiting for an exchange to take their money - it would be the 7th largest coin market, around the halfway point between Litecoin and Dash.

As an Ethereum Developer pointed out in an Ethereum Foundation Skype Chat leak - ignoring Ethereum Classic means there is no money to be made, while embracing it allows you to tap into some "vestigial value remaining from the shared chain history".

Even if any potential fork has all of the support from all of the developers and miners, there isn't much one can do to stop the un-fork, perhaps short of a Coiledcoin-esque 51% attack. Even if networks like Ethereum implemented "the bomb" (a special smart contract that prints tokens out of thin air, intended to kill an un-forked network), a developer could just create another hard fork to disable that code pretty much like the DAO was disabled...

Kill it with fire


So when all is said and done, it looks like the only way to ensure only one version of Bitcoin is around, one would need to reach an overwhelming consensus with the developers, the miners and the exchanges to support only one part of the fork. Anything short of that will create a split network with duplicate tokens being created on both tines of the fork.

To ensure the rest of the network follows suit, someone should put aside some funds and mining power to be able to execute 51% attacks on any un-fork that would start being traded at an exchange. While a 51% attack in normal cases might be in the legal murky territory, perhaps using it to enforce a hard fork might not be seen as an attack on the currency, but as a part of the upgrade process. The law might not catch up to this conundrum for years still.

Conclusions


Anything short of an unanimous hard fork to Bitcoin will most likely result in a network split where both sides of the fork. The split will most likely be motivated by short-term profit to extract some remaining value from the alt-chain. A good way to ensure no such split happens would be to divert some resources to performing 51% attacks on the minority chain and thus causing whatever exchange that tries to trade them to lose money.

Related discussions:


Monday, July 18, 2016

Transactional currencies - Entry Credits and Gas

Transactional currencies - Entry Credits and Gas

DISCLAIMER:
While I work for Factom, the opinions expressed in this piece are, as always, my own.

----

Working at Factom I came across an idea that seems seldom explored in the cryptocurrency space - a transactional currency called entry credits. They operate alongside the main currency of the network, factoids, but while factoids are a fully functional cryptocurrency that can freely circulate in the network, entry credits have a number of restrictions on them:

  • Entry credits are created out of factoids (by burning them) at an exchange rate dictated by the system, but they can't be turned back into factoids
  • Entry credits can be created ahead of time to lock in their factoid-entry credit exchange rate, and used later down the line
  • The exchange rate is tweaked by the system to stabilise the price of entry credits, while still allowing factoids to be a free-floating currency
  • Entry credits can only be spent (burned) to store entries into Factom - they can't be spent elsewhere
  • Entry credits are not transferable - they can only be spent by the account that received them during the factoid->entry credit conversion
These restrictions create a few interesting features for the system that I don't see explored much in other cryptocurrencies:
  • It is possible to put a large amount of entry credit tokens on a hot wallet without worrying much about theft - any would-be hacker wouldn't be able to cash out the stored value, only spend it. This makes production servers much less of a target for attacks.
  • Being able to lock in the price of the tokens ahead of time means companies can budget ahead of time and don't have to worry about token volatility
  • Having the exact amount of tokens in an account, one always knows how many transactions they can perform in the system before running out

Other tokens


While I haven't heard of another currency having the same features, there are some that function similarly.

Most cryptocurrencies adjust their transaction fees on a regular basis to keep up with the price of their coins. This can function as a way to keep the transaction cost stable without trying to control the price of a currency.

Ethereum uses a more formal approach to this with their gas currency. It is separate from their ethers, but you can't purchase gas ahead of time. The gas is used to pay for transactions and operations in smart contracts, but the final cost calculations are more complicated - one can get gas rebates for freeing up memory as far as I heard.

Conclusions


The Factom project might be one of the first projects to implement a fully transactional currency - entry credits. While being a confusing feature for some, it is an interesting approach of stabilising the transaction cost of production blockchain application, as well as limiting the attractiveness of an attack on the production servers.

Monday, June 20, 2016

Perfection or bust - the rise and fall of The DAO

Full disclosure - I own some ether and I have put some of it into The DAO presale. I don't think it coloured my view of the situation, but I feel it's better to be open about such things.

The DAO has made a lot of waves recently. First - last month when it became the largest crowdfunding project in history, at one point surpassing Star Citizen's 116M USD (although it might be partially due to ETH exchange rate fluctuations). Second time - earlier this week when the DAO was hacked. So lets start from the beginning and have a look at the rise and fall of The DAO.

DAOs, in general


DAO, or Decentralised Autonomous Organisations have been a fairly nebulous concept in the crypto space for awhile. They basically are computer programs that run as an organisation, using its code as law. They can hold digital assets and money that can be spend on various projects, services and other digital assets.

Some have proposed to use DAOs to create a rudimentary self-sustaining decentralised organisations. Such programs would actually use their resources to hire people to improve them. I've heard this concept described first during the 2013's Money2020 Ripple conference, and I would consider BitShares to be one of the first self-sustaining DAOs.

Of course, with the current level of cryptocurrency technology, the DAOs are very limited in scope. They can't be as sophisticated as modern AI running on supercomputers, and since code isn't lawfully binding - the various DAOs have to rely on humans to interface with the outside world.

In theory, DAOs could create a lot new jobs. As @aantonop put it though:

TheDAO will create many jobs. First for people like me who have to explain what the hell it is.

The DAO


The DAO (holding a very generic "temporary name", which it probably won't escape from), created by Christoph Jentzsch, the founder of Slock.it, was set out to be one of such self-sustaining DAOs. It was set up to be a quasi-venture-capitalist-fund. As with many token crowdsales, it was skirting the borders of the law - allowing anyone to invest, not doing any KYC, promising "benefits to the DAO Token Holders", without outright selling securities.

The project had support from a number of high-profile members of the Ethereum Foundation

The DAO started operations by selling its tokens for ETH. The promise was that later the ETH would be used to fund various projects and try to extract value from those projects to the DAO itself. The DAO also had a mechanism to upgrade itself to newer versions of the code. The entire process of both spending money and code upgrade would be governed by the token holders voting. Every vote would be proportional to the amount of tokens held.

By the end of the crowdsale, The DAO has raised 8.26M ETH, more than 10% of the total coin supply.

In theory, The DAO could've been a very strong player in the crypto space. Even if it would spend 10% of its funds just funding early stages companies, it could give out 100k USD to 100 different companies and probably have great ROI by the end.

However, there was a bug in the code...

The exploit


Around 2016-06-17, news broke that The DAO's balance was being drained. Quickly there was a call to all exchanges to stop trading the tokens and Ethers while the situation is being resolved.

As it turns out, The DAO had a small bug in it (discussion, technical overview). They managed to make a recursive call to a function and use that exploit to start draining The DAO of its ETH. Before the attack stopped, 3.6M ETH was extracted, worth about 50M USD give or take 20M due to wild price fluctuations.

The attack stopped around the time Vitalik released a blog post about how Ethereum will be handling the exploit. In the end it was decided that Ethereum will not roll back, instead creating a soft fork preventing the drained ETHs from being spent. The coins would also apparently be reimbursed and everyone that put their money into The DAO would be getting it back.

The following day, we actually got a statement from "The Attacker" about the issue, claiming that the draining of ETH was legal and in accordance to The DAO's rules ("code is law", therefore any execution of the code is always as intended). The Attacker also threatens legal action against any attempt to freeze the drained ETH. If such a case ever made it into a court, it would probably be the most important precedent for the future of decentralised organisations as a whole. Only time will tell where the story goes.

Other criticism


If The DAO has not been taken down by this exploit, it is entirely possible we might've seen a lot of other problems crop up in the future. Here are just some of the possible issues and other ideas that would need to be considered.

Setting a precedent for Ethereum. The way Ethereum handles this exploit may affect how similar future problems would have to be addressed. If they go through with the blacklisting, they might be required by law or asked by the community to do the same in the future for a lot of other things. This can open up a big can of worms. However, if they don't, then they might scare off any other similar projects from using the platform, along with some of their users. Damned if you do, damned if you don't.

Voter apathy. If The DAO would have a large amount of users sitting idly on their tokens rather than voting with their money, the software might have problems reaching the needed quorum to do anything. Apparently in Bitshares, only about 10% of stakeholders participate in voting. Perhaps switching to a Delegated Voting model might help alleviate the issue.

Unexplored legal area. The DAO seems to have aimed to exist in an unexplored legal area. It operates like a security or a venture fund without doing the due diligence. It technically cannot be sued, but people that put money into it might face legal repercussions. All in all, it probably would give any lawyer and government official a headache to try framing it in the existing rule of law.

Lack of KYC. While a lot of people in the crypto community want the government and regulations as far from their projects as possible, some oversight might deter attackers. If every investor in The DAO would be vetted by KYC first, and if only vetted individuals could hold the tokens, anyone attacking The DAO would have to be prepared to get sued and criminally charged for their actions. Right now the best we've got is to try tracing the ETHs they owned back to an exchange and possibly investigate some Ethreum / DAO short calls someone might have set up before the attack (similarly to the idea of "terrorist insider trading").

Rushed deployment. After The DAO has been released, there have been some concerns from people that the code should've been tested and vetted more to iron out any bugs. A code that holds so much money is a gold-filled pinata for any and every hacker that might try to break it 24/7. Some attack vectors have been published before the attack (description and mitigation). Since the contract is vulnerable right after it's released, rushing a release is not wise.

Any bug needs to be fixed immediately. With a smart contract running on a decentralised network, it is vulnerable to exploits all the time. Any new bug that is found needs to be fixed right away, especially if it is described publicly. With more centralised software, you can at least shut everything down until the bug is fixed, but such luxury would be harder to implement in a DAO.

One mistake and your money is gone. While this one applies to most cryptocurrencies, it also bears mentioning - any bug in the code that breaks the smart contract that holds actual money (in this case, ETH) can cost you everything. If you deploy such a piece of code and send money to it, it is gone and you won't be able to get it back.

There are no rollbacks with real coins. While any contract that issues and deals only in its own tokens can be rolled back to any point in time with a patched contract, the matter is not as simple when we're dealing with actual coins (in this case, ETH). As the native coins exist outside of the contract's controls, using such contracts to manage the coins is more dangerous than just dealing in tokens.

Putting all eggs in one basket. A contract holding over 100M USD is a disaster waiting to happen. At the very least some of that money should've been put in some deep cold storage until it is needed. Enter into some legally binding contract with 50 people if you need to to provide some multisig and keep the funds safe. It's like putting all of your coins into a hot wallet - you shouldn't do that.

Paradox of presales. Even if The DAO would function correctly, it might be a hard value proposition, similar to most other ITOs (Initial Token Offering). Unless you are an actual security / fund and building projects that funnel their earnings into the organisation, the projects that benefit The DAO holders rather than Ethereum as a whole might be inferior to the general use case. There is a lot that the Ethereum platform and anything on it could benefit from, but tying them into one smart contract might defeat the purpose. Since many DAOs want to avoid being labelled as a security, we might just get some weird projects in the end.

Relation to other projects


A few people have started comparing this bug to a few other things in the cryptocurrency space. Perhaps it is important to have a look at them and figure out how similar they are.

In the early days of Bitcoin, in mid-2010, someone found a way to create 184'467'440'737.09551616 BTC (almost 10k times more coins than would ever exist) out of thin air in a so called "Value overflow incident". The bug was fixed and the network was rolled back. The bug is similar - use an unexpected way the code works to get access to more tokens than one should be able to. However, this situation is different as it breaks the core functionality of the entire network, rather than a sub-part of it that is not governed by the protocol. Rolling back the network to before the bug was introduced is entirely justified - it is something that shouldn't have happened. With The DAO, the situation is a bit different - the core network functioned as intended, it is the final product that was at fault.

Another incident similar to this was the fall of MtGox allegedly caused by Transaction Malleability, and the attack on JustCoin with Ripple's Partial Payment Flag. In both cases, the software creators did not anticipate an obscure network behaviour that lead to their downfall. In neither cases did the network got rolled back - it functioned as intended, and to my knowledge neither of those companies got bailed out for the bugs in their code. This would probably be the closest analogy.

The decision to bail the contract out and refund the drained ETH might be either seen as the Ethereum Foundation trying to mitigate the damage to the network's reputation, or it might be due to many of the Foundation members lending their credibility to the project itself. One way or the other, I doubt we would see many similar DAOs in the future with such lineup of big name supporters to mitigate any similar damage in the future.

What is also worth noting is that because of Bitcoin's success, a lot of the cryptocurrency projects may "suffer" from an accelerated growth. There have been many incidents in the earlier days of Bitcoin of people losing their money and it wasn't that big of a deal - the coins were worth only so much. However, with networks such as Ethereum being worth a billion dollars less than a year after release, you have similar high profile bugs, but the coins themselves are worth a lot more a lot quicker. Perhaps we should try stalling the gold rush until a project has been vetted by early adopters hammering out all of the kinks and best practices? It's probably not going to happen unfortunately...

Lastly, if the Tau developers want to brag about how their platform is / will be much better than Ethereum since such bugs can't happen there, it is your time to prove yourself - deliver us your implementation of The DAO in a language of your choice so we can pick it apart and see if it breaks.

Conclusions


The DAO has been an interesting ride. It allowed the ETH to double in value and crash back down. A project of this scope if executed correctly would certainly be a game changer for any cryptocurrency network. Unfortunately, as many have made this joke before, it seems The DAO was DOA (dead on arrival). With DAOs, it's perfection or bust.

Spells of Genesis card for The DAO, reading
"Holding so much energy, the Colossus is able to withstand all threats"...

How Bitcoiners see the situation

Monday, May 30, 2016

Tau-Chain - a programmer's perspective

EDIT:

After speaking to Ohad Asor, the creator of Tau, about the below piece, it's apparently "blatant obvious nonsense about things [I] don't understand" and "the contradictions are all around. just like eth". The Tau presale was apparently also meant for "only well informed buyers", "i have morals. im not ethereum!".

So yeah, the Tau project is not for mere mortals like myself, and the spam and promotional videos are meant for intellectual elites that will then buy the exclusive tokens. The project looks much better suited for some high-end computer science academia really, but no, token presale is the way to go.

Remember - the Tau is not for you, stupid.

END OF EDIT

Living in the Bitcoin land, you never know what you might come across next. It could be as benign as someone issuing a currency backed by pre-1965 silver US dimes, as geeky as someone creating a blockchain to mine for prime numbers, or it could be as convoluted as BitShares with the many iterations it had over the years (as someone put it - "BitSharesX - An Alt Coin That Is Impossible To Understand"). Over the last few months, I've been seeing a lot of spam about Tau-Chain, along with its many extravagant claims, and figured it might be interesting to try to understand it.

Disclaimer - the project appears to be delving really deep into the theoretical computer science that almost borders on philosophy. While I do have a masters degree in computer science, I can't claim I fully understand some of the topics Tau-Chain touches on or their implications. I will instead focus on more practical aspect of Tau and how it presents itself as a piece of software with practical use.

What is Tau-Chain?


So, what is Tau-Chain? Well, it's quite simple, just look at this graph from the founder of Tau:

A simple explanation of Tau-Chain...

Okay, it's not simple at all. This graph represents what sort of confusing things we're dealing with here...

From what I gathered looking at the project's website, its whitepaper, roadmap, some articles on it, listening to a LTB interview, viewing some other resources and talking briefly to the founder of Tau-Chain, I think we are dealing with two components here - Tau and Tau-Chain. Unfortunately, it seems the people involved in the project like to use those terms interchangeably and confuse everyone further.

Tau appears to be a new programming language, apparently similar to Idris. Unlike most traditional languages most programmers deal with on a daily basis, it is not turing-complete. Instead, it is a decidable programming language. What this means is that it avoids the halting problem, while still being able to do anything a finite turing machine can do. Since in practice we don't have infinite turing machines, from what I understand it should be able to do anything a turing-complete language could do. Apparently, this approach might be more secure. On top of that, Tau "has built-in P2P and blockchain".

Tau-Chain on the other hand, appears to be a sidechain-enabled blockchain that can run the Tau language. It seems to be similar to Ethereum with its contracts - both have a growing library of code embedded in it that anyone can call upon to build their code on. As I understand however, Ethereum's code can be more risky to use as you might not always be able to predict what the contract might do without its source code at hand, while Tau the language is more predictable in its execution?

The project also appears to have another component to it - the Agoras. As far as I can tell, they seem to be smart oracles that can execute various contracts and other Tau code. They appear to be able to interact with the Tau-Chain, as well as with one another directly. All in all, they remind me a lot of Codius, especially if you consider that that project aimed to be able to prove what code is being executed and so on. Not a bad feature, but there doesn't appear to be much new to talk about there.

What Tau-Chain promises


While initially researching Tau-Chain, one will stumble upon their promotional video:

Tau-Chain, solving all of your software development problems apparently...

Which lists a few outlandish claims about what Tau / Tau-Chain can deliver:

  • Software that always does what it is supposed to
  • No more bugs
  • Automatic requirement validation by the Tau client
  • It is impossible to write code that doesn't work
  • Thanks to Tau, the client doesn't need to trust the coder and vice versa
  • The payment for developing code is automatically paid when the code is verified by the Tau network
  • The Tau blockchain stores social norms, scientific theories, "whatever is based on facts and rules" (one example flashing in the video is "Once you start to eat you should never leave spoon, fork or knife on the table. Their place is on the plate.")
  • Tau-Chain code is reusable
  • Tau is a database of provably working code snippets
  • You can use the Tau-Chain to build search engines, social networks, market places
  • You can develop provable smart contracts on the Tau-Chain

As a software developer, I would take all of that with a huge grain of salt. Then again, it might be my turing-complete attitude talking and things might be different in the decidable language space. If this video was talking about traditional software languages, I would put my money on the video being about test-driven development - an approach to software development that starts with test cases (what the code should and should not do), and then developing the code to fulfil those tests. In theory this could mean that the software has no more bugs, it does what it is supposed to and can be verified automatically when new code is checked in. So while it would fulfil most of the listed requirements, in practice I would not expect it to be *the* solution to all problems - writing good test cases can be as hard and time consuming as writing good code, and I doubt 99% of the clients purchasing software would be able to use that. If the test cases aren't sufficiently complex, we might run into the problem of software being built just to tick the checkboxes and not much else. After all, any program operating on a sufficiently small domain could be replaced by a lookup table...

I am also very sceptical of how the software will decide what are the stored facts and how those will be handled and proven. Even more so when we're talking about "facts" about the real world and social norms. How do you prove you should not put used forks on the table, from a software perspective? How do you handle a problem having multiple contradictory answers (an infinite sum of (1-1+1-1...) can be proven to equal 0, 1, 0.5, -0.5, etc...)?

Some other claims I stumbled upon from other sources (1, 2, 3):
  • Tau client's behaviour is dictated on-chain, with the chain being able to hard-fork itself
  • Tau (-Chain?) has no rules at all, its users will set its behaviour
  • Tau does not need a coin, but it has a token presale anyway
  • "Tau network will be able to download virtually the whole internet, practically giving everyone the same information Google has, and more: data can be queried and processed more meaningfully and collaboratively, so you could perform queries as you like."

While there are more claims, lets just limit ourselves to those few (a lot more can be found in the LTB interview).

The Tau / Tau-Chain's feature of embedding how the network operates in the blocks themselves is rather unique feature as far as blockchains go, but at the same time it can be one of the more dangerous thing out there. It certainly offers the network more apparent freedom from Bitcoin-like hardfork stalemate, although in reality Bitcoin's hardfork problems are never about the code being hard to change, but about the people you need to convince. It might also impair some thin clients if they are applicable to the chain (how can you just run the chain from a given length if you don't know what the rules are from all of the previous blocks?). The definition of who the "users" in the system are (one-vote-per-person / machine / CPU?), as well as what the rules for hard-forks will be will probably shape the network very drastically early on. I wonder whether anyone will try to change the code of how the blocks are executed to "stop execution, return 0"...

The token presale doesn't appear to be anything new in the crypto world - it's the paradox of presales all over again. Tau the language and network doesn't need a new coin, it would probably operate better without it, but the developers need money to develop the language / network, so they sell tokens to speculators. Looks to me like another Bob Surplus-esque coin looking for a problem.

As for the last claim, and a few similar marketing blurbs, I think they deserve a section all of their own...

False equivalence, false dichotomy, eating your own dog food


The quote about basically being able to replace Google appears to be a false equivalence fallacy. There are many problems with trying to say you can basically be like Google:
  • I very much doubt the network could handle about 10 exabytes of data
  • Being able to efficiently categorize all of that data requires very smart algorithms and a lot of data. You can't even begin figuring some of the things out without having efficient access to enormous data sets. For example, how would you figure out a search for "high contrast pictures of fruit floating threateningly in the night" (thanks Reddit)?
  • Google is as much about the data (what the websites contain), as much as it is about the metadata (what the people are searching for and what they are clicking). Having just one part of that might not give you the full picture
  • Without having most of the data at hand, it is impossible to know if you returned most of the searched data. While you might be able to make queries based on the data you do know, you can never know how much you don't know
  • It is also impossible to prove that real-world data is correct. Since Tau-Chain is focused on storing "whatever is based on facts and rules", how would you be able to know, say, what is the weather outside right now? Sure, you can have a lot of data points, but you can't prove they are true or made up

All in all, statements like that are just red flags if someone also asks you for money. At best, they are marketing superlatives. So while sure, if we're talking about Tau the language, someone might use it to implement a Google-like service with it and so on, but the same could be said about computers based on cogs and wheels (after all, any turing machine is equivalent to another). All in all - false equivalence - your software is not even comparable to Google.

Now, lets finish this discussion with a subtle false dichotomy. I stumbled upon this marketing blurb about Tau from some of the spam I see pasted in a few chats I visit:


It compares how Tau-Chain is different from Ethereum, and links to a blog post by Peter Vessenes criticising how buggy some of the Ethereum smart contracts can be. He makes a lot of valid points - since you can't upgrade and fix the contract code post-launch, you either need a good failsafe, or write perfect code not to lose people's money. However, what I take slight annoyance with, is how this sort of marketing might misrepresent the situation - "Tau is different from Ethereum, here are a few reasons why. Here is someone criticising Ethereum (while not talking about Tau)", implying that since Tau was not criticised and it is presented as Ethereum's competitor, it somehow doesn't have those flaws. No Tau, criticism of your competitor does not mean you don't / won't have those problems yourself.

Lastly, I find it really amusing that Tau apparently doesn't like the taste of its own dog food - for all of its criticism of turing-complete languages, saying how Tau is a much better language and all of that, in the end they develop their code in C++. I did bring this point up to Tau's creator and he made valid points as to why that is - they want to develop the software in an efficient language to make it operate efficiently and in the future they might implement Tau-Chain in Tau. Understandably, software development takes a lot of resources and time, and you want to release early, release often, but this somehow doesn't fill me with confidence that Tau will be usable for any commercial-grade software any time soon...

Conclusions


While Tau appears to be an interesting development of a new programming language and its creator certainly sounds very knowledgeable in his field, Tau-Chain looks like a project looking for a problem. Bootstrapping a new token to run a blockchain to use a new programming language for smart contracts that don't halt seems like a very complicated way of reinventing everything just because you want to change a few things. I am highly sceptical of how the network will handle everything it promises, especially when it comes to dealing with things in the real world. It could be as mundane as a different flavour of Ethereum with a non-turing complete language, some smart oracles, etc., or something potentially new - only time will tell. Until Tau-Chain is released, I remain unconvinced.

Amusingly enough, the Tau-Chain video contains an Escher-like perpetual motion water mill at 1:40. I wonder if this is telling that the project is trying to invent something impossible?

Tuesday, May 24, 2016

Bitcoin rivals

Bitcoin rivals

Recently I came by a tweet by Andreas Antonopoulos stating:

Stop calling ethereum "the bitcoin rival". No one in ethereum or bitcoin believes it is a rival. Post-national currencies are not zero-sum

Which got me thinking - can Ethereum or any other cryptocurrency be seen as a Bitcoin rival?

Bitcoin vs fiat


First, lets look at how Bitcoin competes with fiat.

Looking at the definition, a rival is defined as "A competitor with the same goal as another, or striving to attain the same thing. Defeating a rival may be a primary or necessary goal of a competitor." and "Someone or something with similar claims of quality or distinction as another.".

When talking about most fiat currencies like USD, Euro, GBP, etc., or hard assets like Gold or Silver, it might be hard to call Bitcoin a rival to those, at least so far. A lot of national and international currencies exist to facilitate trade, government programs, taxes, etc. on a scale where Bitcoin doesn't register yet. Previous metals are similarly used for some trade, as well as store of value, speculation, etc.

While Bitcoin can fulfil similar niches as those currencies, the currency would first need to rise in value a few orders of magnitude to be able to compete on the same scene. In the future, Bitcoin may be seen as a competitor to USD or Gold, but it will probably take awhile. That, however, doesn't stop it from filling in some other niches.

Bitcoin in various applications


While Bitcoin might not compete against Gold or USD, it can still catch the attention of some gold bugs, internet sellers, or the unbankables. Bitcoin might be too small to compete in the primary markets of companies like PayPal or Western Union, but it seems to be catching up in the more fringe markets.

Bitcoin vs altcoins


Bitcoin's most direct rivals would be the various altcoins.

Looking at the current cryptocurrency market, we have Bitcoin at $6.9B market cap, Ethereum at $1B, Ripple at $206M and Litecoin at $181M, with every other coin having substantially less than $100M.

Bitcoin's most direct competitor feature-wise would be Litecoin, sitting at 1/38th of the market cap. While it might be a notable currency for speculation, there doesn't seem to be as much adoption and development push from within and without the Litecoin community to say that LTC is competing with BTC. As such, it doesn't look like a potential rival for Bitcoin.

Ripple, due to the centralized control of its XRP tokens, can never hope to compete with Bitcoin. Similar to Omni and Counterparty, it might be better suited to be a Bitcoin compliment - dealing with user-created currencies, while leaving Bitcoin to be the decentralized currency.

This leaves us with the main topic - Ethereum...

Bitcoin vs Ethereum


Ethereum is a bit of a mixed bag. Its genesis block started with ~72M ETH being created for the presale (~60M ETH), the developers, and the Ethereum foundation (~12M ETH). With the current supply of 80M ETH, that presale constitutes a large chunk of the total ethers in circulation. Some might see that as premining, while others, like myself, don't see similar presales as such.

Ethers also aren't always viewed as currency, but rather as a token for executing code on Ethereum. While that might be true and some core developers might say that for legal reasons (to protect themselves from any legal fallout from the token presale), it hasn't stopped people from speculating on the value and bringing the value up more than 10 fold in the last year.

Lastly, Ethereum does a lot more with its scripting language than what Bitcoin can. Until we get something like sidechains up and running, Bitcoin will probably not be Ethereum's rival anytime soon.

However, the opposite might not be true. Ethereum has 1/7th the market supply of Bitcoin, a large community around the world, and is starting to get high-profile projects like The DAO. As such, Ethereum is shaping up to be a rival to Bitcoin.

The rivalry


With all of that being said, Ethereum and Bitcoin filling the same niche of decentralized internet currency might not be too bad. Both of the currencies still have bigger opponents to overcome on their way up - fiats, precious metals, centralized payment processors taking big cuts, etc. Success of one might not mean the loss of other. As long as both communities remain on good terms, developers, exchanges, and other crypto businesses are open to accepting both currencies, and we keep our eyes on the same target of overcoming the old way of banking, there is no reason why this rivalry couldn't be a friendly coopetition.

Conclusions


Bitcoin is not yet a rival to the big fiats or precious metals, as it is too small to register. Most altcoins aren't big enough to compete with Bitcoin. Ethereum is a potential rival to Bitcoin, but there is no reason for competing directly with one another when there are old currencies and use cases to take on first.

Monday, April 25, 2016

Nobody needs Counterparty - a discussion on needs and wants

Nobody needs Counterparty - a discussion on needs and wants

About a month ago, I had a comment exchange on /r/Bitcoin with /u/brighton36, the community director of Counterparty. A lot of different points were discussed, but the general argument was that /u/brighton36 believed that there isn't a convincing argument for the use of smart contracts and turing complete language in general, thus making Ethereum an unnecessary project. However, just like that logic could be used to claim "nobody needs Ethereum", similar logic could be used to make a statement that "nobody needs Counterparty". Lets explore whether any of this holds water...

Nobody needs Counterparty


Counterparty was launched around the start of 2014 and is one of the Crypto 2.0 platforms that runs on top of Bitcoin. Their notable feature that sets them apart from most other Crypto 2.0 platforms is their reliance of Proof-of-Burn to issue their currency. The platform offers decentralized exchange between XCP, BTC, and user created assets, although no direct asset-asset exchange, as well as some financial contracts. Their most notable and active assets include LTBCoin, Gemz and BitCrystals, which seem rather negligible in comparison to other platforms.

All in all, Counterparty is a decentralized asset issuing platform for centralized assets - loyalty points, presale currencies, etc. Since it relies on the Bitcoin network, the transactions are slower than the competition, there are no real gateways on the network offering fiat currencies. The network doesn't support asset-asset trading, making it pretty useless for direct FX trading. While Counterparty tried to woo Overstock into using its platform, but that didn't work out too well. The most notable proponent of Counterparty appears to be Adam Levine with his Tokenly project, but hearing what he aims to accomplish with it during a Decentral Vancouver meetup, both myself and other listeners said "you're reinventing Ripple!".

So in general, nobody needs Counterparty - you can issue the same currencies on faster, more established platforms, you can issue them privately on a centralized platform, on semi-centralized Open Assets, partner with some exchanges, etc. There are many other, better ways you can accomplish the same result without using Counterparty. So all in all, you don't need Counterparty, right?

Nobody needs Ethereum


In similar vein, one could criticise Ethereum's smart contracts. They offer unambiguous code execution, you know the code will not be changed during execution, and you can run long-running pieces of software that can use persistent storage on the blockchain. As /u/brighton36 pointed out:

"Unambiguous code execution is already in ubiquitous use today. Package management systems use code signing to detect whether the code being executed is asserted as valid by the issuing party. Open source scripts are in abundance. "

Beyond that, Counterparty has recreated Ethereum on its platform (and Ethereum responded in kind by recreating Counterparty in 340 lines of code). So all in all, you don't need Ethereum, right?

It's not about the need, but the want


When you think about it really, focusing on whether you need something or not because you can accomplish the same task with something else is a silly argument. That's like saying "you don't need Goland, you've got C++", or "nobody needs a screw, you can use nails". So no, nobody needs Counterparty and nobody needs Ethereum, but they are both useful tools in their own right. As long as they are functioning as intended and fulfil a need people have, not necessarily optimally, they are useful. I might prefer to use Ethereum to say, publish my blog because I can / feel like it / it's cool to do that, or Counterparty to issue my local currency because it's convenient / good enough / I like the project. Sure, you can do better in both cases, and in time you might optimize and choose a better platform, but that doesn't mean those projects aren't useful in one way or the other.

The only obvious caveat here are pumps, scams and similar attempts at getting people's money illicitly. While PayCoin might be as useful to transfer money as Tether, it wouldn't be advisable to give money to the former over the latter.

Good projects can flourish if people want to use them, or die if people don't care. Bad projects will most likely burn themselves out eventually. If Ethereum, Counterparty or whatever other project is out there is used by people, even if you can accomplish the same things with something else, let them use it. Claiming a project is "full retard" won't get you very far.

Conclusions


Claiming that "nobody needs project X" because you can accomplish the same task with some other tool or technology doesn't make the project itself useless. People might have many reasons to use the various alternatives, and as long as you can accomplish what you set out to do, that might be good enough for a lot of people.

EDIT:

- It looks like Counterparty has started supporting asset-asset exchange since the last time http://tiny.cc/Crypto was updated.
- As some have pointed out, Counterparty is also used by Storj and Spells of Genesis trading cards, although they haven't been trading much recently, hence why they weren't mentioned

More discussion on the topic can be found here:

Monday, February 8, 2016

The Dark Wiki

The Dark Wiki

This blog post is inspired by some "what if" videos made by Tom Scott, in which he explores a theoretical futures when Google forgot to check passwords, the dystopian view of the singularity ruined by lawyers or what happens when privacy dies. Here is my take on what might be built in the future on top of the existing blockchain technology.

Any names or examples used in this story are meant for purely illustrative purposes only and are not meant to condone or condemn any actions, companies, governments, technologies or the like.

----

Knowledge is power, and a lot of money can buy you a lot of information...

The years is 2025, there are almost 20 million bitcoins in circulation and they are valued at $5'000 per coin. While not as fast a growth as many would've predicted, it still puts Bitcoin as the world's 8th biggest currency in circulation, ahead of Canada's dollar, but behind the United Kingdom's pound. For all intents and purposes, Bitcoin and crypto have succeeded - they are used by a lot of people in all walks of life.

The biggest story of the year's first quarter turned out to be the busting of a US-based criminal organization creating superbills - high quality replicas of the "counterfeit-proof" polymer banknotes. What stood out about those bills is not that they were good, but that they were perfect replicas of the banknotes, down to the microprint, security ribbons and the colorshifting ink.

While not an unheard of story (North Korea is said to have done something similar in the past), over the following days of media attention a surprising finding has caught everyone's attention - the criminals got all of the information they needed to make the superbills from "The Dark Wiki" - a Wikipedia-like website residing on the Dark Web, created with the sole purpose of "cataloguing the world's forbidden knowledge".

The Dark Wiki contained detailed articles on many subjects that would land anyone in jail - recipes for narcotics, 3D printer files for military-grade weapons, interrogation manuals from a number of international agencies, copies of standard keys used in "back doors", the complete smallpox genome, or "how-to's" on accessing military GPS signals or the aforementioned printing process of superbills, from 3D prints of various master hubs, etc.

The website was not only dealing with standard articles, but also featured a prominent section on "kickstarting" / requesting information, with the bounties anywhere between a few thousand dollars for creating some malicious scripts to break into some computers, through a few hundred thousand dollars for pharmaceutical recipes of some major drugs, up to a few million dollars for schematics of nuclear weapons.

While the website seemed to lack a single owner, there were a number of prominent "experts" on the website serving as third party escrows on a number of bounties to verify if the information delivered was accurate and precise. They also curated one of the more bizarre part of the website - a scientific journal on "the dark sciences".

While a number of traditional scientific papers have been written on criminals and their illegal activities (such as Steven Levitt and Sudhir Venkatesh studying the economics of crack dealing), the Dark Wiki's journal was focused more on scientific research that was itself illegal or borderline illegal - designer drugs, human cloning, synthetic organisms, or experimenting on humans and infants. While so far only the first category had any traction, going so far as having some research grants, the other categories were open for submissions.

With a little help from the Streisand effect, hundreds of millions of people have heard of the website and it became the most searched for topic of the moment. Among the wave of new users that came across the website for the first time then, was a disgruntled 30-something NSA software engineer. Stuck in a dead-end job working on some machination that would further make the agency's reputation worse if it ever was revealed.

What he saw in that website struck a chord with him. When he was a teenager, Wikileaks broke the news. In his early 20s, Snowden's revelations shook the world. This year, he would make both history, and a lot of money for himself.

A month later, the Dark Wiki broke into the news again. A high six-figure bounty was awarded for delivering the information required to access NSA backdoors embedded in billions of devices world-wide. That day would later be known as "the day the Internet broke". The massive-scale hacking that occurred with that information was an order of magnitude higher than the 2014 Heartbleed bug, and it brought down a number of key servers around the world for a few hours before some of the vulnerabilities could be patched and the Internet reconnected.

The following days the governments were dealing with a few major issues. First, any US-based manufacturer was distrusted overnight, with many world governments revving up production on their non-backdoored hardware. But due to the nature of how hardware is manufactured, it would take years for the industry to adjust.

Second major issue was figuring out who leaked the information. The bounty was paid in bitcoin, but since the 2019 halvening hard fork introduced confidential transactions to the network, it became impossible to figure out which address received the funds. An internal investigation was under way at various government agencies to see if some leads could be found...

Lastly, the Dark Wiki had to be shut down - it attracted too much unwanted attention and could cause global security concerns if it was used by large criminal organizations or corrupt governments. With some busy work and exploiting some weaknesses of the Tor network, the website was finally traced to a server sitting in some country with abundant legal loopholes and lax prosecution laws for hosting illegal content. However, the biggest surprise came when it turned out there were only two notable pieces of software on the server - a small wrapper serving the website's frontend and an Ethereum client...

As it turns out, the website was running as a smart contract on the Ethereum platform. All the required information and logic was stored in the distributed ledger, with payments being handled through a sidechain connection onto the Bitcoin network. Editing rights were only given to users that created a high enough proof-of-burn pledges (by donating the coins to the contract itself) and the little governance there was was mostly handled through anonymous users building their reputation by contributing to the website and being recognized by the community. Anonymous donations from people benefiting from the wiki as well as the pledges and other fees allowed for the contract to become a self-sustaining DAO.

After the website was shut down, multiple other mirrors cropped up along with the source code required to access the data locally. Attempts to shut the network down only strengthen it due to the antifragile nature of crypto.

On the 10th anniversary of its genesis block creation Ethereum was no longer seen as a quirky distributed state machine, but as an avatar of unstoppable quest for knowledge in all of its forms paired with the cold machinations of cryptographically untouchable capitalism.

If the Dark Wiki has taught us anything in its following years of operations is that security through obscurity is a joke and that we can't rely on any secrets to keep us safe. In the end, backdoors had to be closed, strong cryptography became the default and the attitude towards cryptocurrencies has changed. Just like you cannot kill an idea, neither can you stop a decentralized network or currency.

----

What I have described above could be implemented today, at least technology-wise. It would probably still take some time before the technology becomes popular enough for people to start using it as described, but we have some kernels of that already in the form of the assassination market or the now-defunct Silk Road. In due time perhaps we would see some dark web information market develop and turn into some wiki for people to use. Pair cryptocurrencies with the sort of money drug lords or a small government can amass and you might have to be keeping a closer eye on disgruntled or low-paid employees with access to secret information...

I used Ethereum as an example of a platform to host the Dark Wiki, but the same project could be hosten on any platform that supports smart contracts. Please don't read it as condemnation of Ethereum either - I see it as one of the more innovative crypto projects and see it being useful for a number of good projects in the near and far future.