Showing posts with label analysis. Show all posts
Showing posts with label analysis. Show all posts

Monday, July 4, 2016

The Bitcoin Bullshit List

The Bitcoin Bullshit List

If you hand around the Bitcoin space for awhile, you will inadvertently come across a few or a few hundred copycoins, scamcoins, scams, ponzi schemes and what have you. Whether it's a large scam like Paycoin, small scale pump and dumps like Quarkcoin, or something that might look like an earnest project that got too big for its own good like The DAO, after awhile you start seeing the same pattern and red flags repeat themselves over and over again.

Being inspired by the ever timely SpamSolutions.txt (a quick checklist of "why your idea to solve the problem of spam won't work"), awhile back I started compiling "The Bitcoin Bullshit List" (also available at http://tiny.cc/Bullshit). It should be expansive enough to cover most of the common scenarios, but if you think it's missing something, let me know and I'll add it in the future revisions.

So, how does the Bitcoin Bullshit List work? You simply read up on or listen to a project pitch and start filling in the checkboxes in the "Your Crypto Idea Will Not Work" section. Once you're done, you can summarise your thoughts and give the project a short "Bitcoin Bullshit Tier".

Let's go through an example to show how this might work in practice (and cutting out the unnecessary parts of the lists).

Example - The DAO


Your post advocates a new:
(x) Altcoin
(x) Investment scheme

Your idea will not work.  Here is why it won't work.

(x) Your target audience is too small to support the project
(x) The proposed security model is (x) flawed / ( ) not enough / ( ) completely wrong and therefore you will be (x) scammed / (x) hacked / (x) stolen from / ( ) ________ quickly
(x) You promise unreasonable return on investment without a clear business model of where the money is coming from
(x) Your project cannot be run legally at your jurisdiction
(x) Your project will not be compliant with the current (x) KYC / (x) AML / ( ) gambling / (x) securities regulations
(x) The solution would work better as a (x) centralised / (x) decentralised / ( ) distributed solution
(x) Your product is poorly implemented
(x) Your presale tokens have no economic value
(x) Your adoption goals are unrealistic

Specifically, your plan fails to account for:
(x) The existing regulations
(x) The required Money Services Business license
(x) The anonymous nature of cryptography
(x) Public reluctance to accept weird new forms of money
(x) The human factor

and the following philosophical objections may also apply:
(x) Ideas similar to yours are easy to come up with, yet none have ever been shown practical

Furthermore, this is what I think about you:
(x) Sorry dude, but I don't think it would work.


Bitcoin Bullshit Tier
You are advertising a new Bitcoin / crypto related project. Based on the information provided, you have reached the Bullshit Tier of 4 for the following reasons:

Bitcoin Bullshit Tier 1 - marketing babble, technology misunderstanding
(x) Dropping names of crypto celebrities to bolster one’s credibility


Bitcoin Bullshit Tier 2 - willful misinformation, bait and switch
(x) Claiming your project can accomplish something hard without a clear explanation of how to do so

Bitcoin Bullshit Tier 3 - Many red flags
(x) Assuring your product is legal
(x) Speaking about profits / return on investment
(x) Presale
(x) Token IPO
(x) Providing no company contact information


Bitcoin Bullshit Tier 4 - Outright scams
(x) Describing a financial security and claiming it’s not a security



Well, that was pretty straightforward. Now, let's compare that to something that is generally not considered a scam and see how well it fares.


Example - Litecoin


Your post advocates a new:
(x) Altcoin

Your idea will not work.  Here is why it won't work.

(x) There is already a product on the market that does exactly what you’re doing, but ( ) faster / ( ) cheaper / (x) better / (x) is more established / ( ) ______________ You are proposing exuberant fees for the use of your product that are unsustainable in the long run


Specifically, your plan fails to account for:
(x) Public reluctance to accept weird new forms of money
(x) Huge existing software and hardware investment in Bitcoin

and the following philosophical objections may also apply:


Furthermore, this is what I think about you:
(x) Sorry dude, but I don't think it would work.



Bitcoin Bullshit Tier
You are advertising a new Bitcoin / crypto related project. Based on the information provided, you have reached the Bullshit Tier of 1 for the following reasons:

Bitcoin Bullshit Tier 1 - marketing babble, technology misunderstanding
(x) “As good as / better than Bitcoin”



Generally, not that bad - some tick boxes will apply to even the most benign and well meaning projects, and that's fine.

Conclusions


With many new crypto projects cropping up and vying for your money, it's useful to step back once in awhile and see how many flags certain projects raise before buying into them. Whether it's for laughs or as a sanity check, the Bitcoin Bullshit List might be a useful tool to run through when looking at new Bitcoin and crypto-related projects:

Wednesday, October 14, 2015

Liquid - when sidechains say "fuck it"

Liquid - when sidechains say "fuck it"

We had big news in the Bitcoin world - Blockstream, the company that has been working on sidechains for awhile has announced they will be launching their first sidechain called Liquid. The announcement is all over CoinDesk, BitcoinMagazine, IHB and others. Unfortunately, when you look closer, what is being proposed is not really fulfilling the promise of sidechains...

What is Liquid?


Liquid is a settlement system for Bitcoin exchanges. It allows one to "[reduce] the time in which bitcoin-denominated funds can be transferred between accounts at these institutions" [1] and "allowing partner exchanges to move funds between order books without the need to transfer funds on the bitcoin blockchain" [1] for "an undisclosed monthly subscription fee" [1]. This will be accomplished by "[finding] partner exchanges transferring funds to a shared multi-signature wallet address, with a Byzantine round robin consensus protocol used to process transactions"[1]. The network will be run by known exchanges, essentially boiling down to a permissioned blockchain. The block signers will be running on proprietary hardware to prevent "tampering with the block signers when they are up and running [, further minimizing trust].".

What are sidechains?


Even more so than "blockchain", "sidechain" is a bit of a nebulous term. Blockstream, who are pretty much the main developers in this space have defined the term in their whitepaper as

"A sidechain is a blockchain that validates data from other blockchains"

This opens it up to interpretation as to what is and isn't a blockchain. Is Bitcoin a sidechain since it contains Factom blockchain data? Is Counterparty a sidechain since you can trade BTC on it? Is Ripple a sidechain since we have services like BitStamp and SnapSwap being Bitcoin gateways onto the system?

I personally expand the term to "a blockchain with a distributed two-way pegged currency from other blockchains" (a quick refresher on centralized, decentralized and distributed definitions). Generally, it should be a system that is not rely on a handful of centralized gateway / bridges to move value back and forth between the networks, but a more protocol-level way of achieving deposits and withdrawals.

Having a one-way peg is dead easy - we've done proof-of-burn years back. Two-way peg, unfortunately, requires a soft fork in the Bitcoin protocol, or an entirely new system to be built from grounds-up.

Liquid is not innovative


Looking at what has been said about Liquid - it's not an innovative technology. It can be boiled down to:
  • Funds are deposited in a multisig address controlled by multiple exchanges [2]
  • Transfers between the exchanges happen when multiple exchanges sign off on the transaction in a mechanism similar to green addresses [2]
  • Transfers require no confirmations because the network won't sign a double-spend against itself

The technology is nothing new - we've had multisig since 2012, and even frigging MtGox used a green address in 2011.

I'm also not yet sure whether Liquid provides some cryptographic receipts for deposits. If they don't - the network isn't entirely gox-proof. You may have proof-of-liquidity (balance in the multisig address), but you'd be lacking proof-of-liabilities - exchange clients or counterparties being able to prove who is owed how much in case the servers blow up due to incompetent PHP programming. Having a pile of bitcoins and a mob of people is not enough to know who is owed how much.

If Liquid has proof-of-liabilities or some other form of cryptographic receipts, that is great! It means they can be compared to Open TransactionsVoting Pools idea from 2014.

Now, to be fair - you don't need to be innovative to be useful, just be honest about it. What Liquid is, I wouldn't classify as a sidechain, but it can still bring a lot of value to their customers. That being said...

Liquid is not enough


Do I believe being able to speed up BTC transfers between exchanges is a useful thing? Yes. However, do you know what is the biggest pain point in Bitcoin exchanges and arbitrage? The fiat part. I'll be able to save an hour or two on my Bitcoin deposits to lock in a trade at a good exchange on another continent, but then I'll have to wait a few days for my fiat to move around so I can arbitrage in the other direction, great. Well, maybe pairing this with something like Tether would be good enough...

Other points


A few last points that don't fit anywhere before I wrap up:
  • Proprietary hardware requirement - if someone told me that to run some system that takes care of my coins I would have to use their proprietary hardware, that's where the conversation would end. I understand, you want the system to be hardened against attacks, but that's exactly why you need heterogeneous network - if everyone has the same hardware and software, you can take down the entire network with the same exploit. Not to mention, proprietary hardware doesn't fit well with "trust but verify" model of Bitcoin.
  • Obfuscated balances and trade data - cool feature, as long as it doesn't interfere with proof-of-liabilities

Conclusions


Liquid looks like a very interesting project, but it's not the sidechains we are looking for. I guess it's a fair compromise between not being able to do anything because one needs a soft fork to implement the full vision and launching a whole altcoin just to have sidechains properly implemented. I guess you can only wait so long for things to improve before you say "fuck it" and create something between where we're now and where you're aiming to be in the future.


[1] - http://www.coindesk.com/blockstream-commercial-sidechain-bitcoin-exchanges/
[2] - https://www.reddit.com/r/Bitcoin/comments/3ok8ga/blockstream_announces_liquid_bitcoins_first/cvydu7r

EDIT:


I heard rumours about the proprietary hardware used for Liquid being secured by thermite that would destroy the hardware if it was tampered with. Reportedly, the hardware would have to be picked up in person as well. While I can't find a reference for those statements, if they were true it would make the situation even weirder (perhaps making it quite problematic for companies to get a hold of those outside of the country they would be produced in - try bringing such highly flammable package onto a plane...).

Related discussions:



Saturday, July 25, 2015

Fighting Bitcoin theft - law enforcement block explorer

Fighting Bitcoin theft - law enforcement block explorer

Recently I had a chat about what would be some good features for a block explorer to have. One thing I don't really see implemented too well is a tool for helping fight the theft of bitcoins. The idea isn't anything new really - I discussed something similar back in 2013 - a block explorer focused on tracking officially reported thefts of coins and providing a tools for exchanges to cross-reference their inputs with the database. Here is how it could work...

The stolen coin tracker


The tracker would essentially be a block explorer focused on tracking coin taint - nothing ground breaking there. However, if you pair that with allowing law enforcement from around the world submit exactly which coins they want tracked, it can become a quality tool for figuring out whether some coins are "tainted" or not.

However, the taint shouldn't be permanent. If the stolen coins are recovered, or they end up very diluted in a legitimate place of business, the outputs might need to be whitelisted as "clean" to stop the tracking. This way, the coins could go back into circulation without triggering any more flags in the future. This whitelisting process should also be carried out on request of the law enforcement.

The reason why we would focus on law enforcement is to limit the amount of false claims of thefts. If someone really lost their coins, rather than only claim to have lost them, they wouldn't mind filing a report and being liable in case they lied. Similarly, when tainted inputs are reported but they are deemed too diluted by whoever is responsible for the local AML enforcement, they would be the ones responsible for that decision.

Knowing which outputs to track, the rest is trivial - follow the coins each time they are spent, keep a track of how the taint might be diluted down the line and record everything for later reference.

Who is going to use this?


Any company that is required to follow AML regulations, like any Bitcoin exchange, would want to start using the service to make sure they are not liable down the line. The exchanges would either want to ask the tracker about every deposit they receive to check its taint, or if they are very privacy conscientious, they might just want to poll for any recent movements of tainted coins and do the cross-referencing themselves.

Any transaction that contains tainted coins could be reported to the authorities, or there could be a threshold of the minimal taint for reporting (say, above 10%). Depending on the regulations, the coins would either need to be frozen by the exchange, or if the taint is small, the authorities could whitelist the transaction on the tracker.

The implications


As with many things Bitcoin, the solution is not clearly good or bad. On the positives, this can discourage people from stealing bitcoins as they would have much harder time spending or converting them (who knew infinitely traceable currency can be so hard on criminals?). As for the negatives:

  • We would be dealing with many jurisdictions with different laws, making the blacklisting and whitelisting process complicated
  • This idea may lead to the Bitcoin redlists, where all coins would be considered tainted unless they were whitelisted - clearly not a desirable path for Bitcoin to be heading
  • The tracker would only be useful if a lot of international Bitcoin exchanges would choose to use it. Having a few big exchanges ignore it completely would just mean everyone with tainted coins would just visit them instead circumventing the tool
  • This tool would negatively impact Bitcoin fungibility, which makes the system less desirable overall
  • A lot of independent vendors and casual users accepting bitcoins wouldn't be able to effectively report all suspicious activities, possibly forcing them to switch over to using big payment processors instead, going against the Bitcoin idea of being one's own bank

Conclusions


All in all, do the benefits outweigh the drawbacks? Possibly. Then again, if someone that understands Bitcoin won't create a tool like this and run it responsibly, we might end up with someone from outside that doesn't know how the Bitcoin ecosystem work come in and force something worse upon us...