Showing posts with label mining. Show all posts
Showing posts with label mining. Show all posts

Monday, December 7, 2015

Irrational Bitcoin mining

Irrational Bitcoin mining

Last week we discussed the economics of P2Pool mining with low-powered miners. One of the more interesting comments I came across while doing some research for the topic talked about the possibility of companies like 21 Inc creating a scenario where the Bitcoin mining becomes completely unprofitable for anyone that has to pay their electricity bills. Lets examine how this scenario might impact Bitcoin.

Creating irrational miners


In game theory, one generally assumes that every player in the scenario behaves rationally, that is to say - they are motivated by maximizing their own profits. In the Bitcoin mining world, every large-scale miner is rational - they care about their bottom line and profits. If it is profitable to mine, they mine, if not, they either switch to more efficient hardware (CPU->GPU->FPGA->ASIC->better ASICs), don't turn on their miners (minimizing losses), or outright buy bitcoins from the market (if they aim to accumulate bitcoins).

Since the Bitcoin difficulty is self-correcting, eventually the market weeds out the most inefficient miners until mining becomes profitable again. All in all, it's a strange mix between the tragedy of commons and an arms race that makes Bitcoin more and more resilient to attacks (a potential attacker would have to incest more money into the attack than everyone else combined).

However, earning money from mining is only one motivator a potential miner might have. Just like Google indirectly benefits from laying down Google Fiber that gets more people onto the Internet where Google can monetize them with ads, Bitcoin companies might devote some of their resources to mining even at a loss. For example, SatoshiDice might want to have its own mining pool to push through all of its pending transactions that some other pools might consider to be spam. Big exchanges would similarly want to make sure all of their deposits and withdrawals are processed faster than its competitors, etc. Lastly, companies might want to mine just to make sure the Bitcoin network is more decentralized.

And now, with companies like 21 Inc pushing for inclusion of their mining chips into various devices, we might see an emergence of essentially botnets of low-powered miners contributing their hashing power to their creators.

Botnet mining


Botnet mining bitcoins isn't really all that new. We had some mining viruses bundled with torrents, esports server code, or even embedded in websites through WebGL. However, since nowadays mining with anything short of a dedicated ASIC chip is worth less than the coding time required to run it. However, if we start embedding small ASIC chips into devices, things might get more interesting...

It would be possible for hardware manufacturers to include physical bundleware / crapware into their products similar to how phones nowadays come with pre-installed bloatware. Like 21 Inc's investor slides suggest, those mining chips would probably come with pre-defined address they will be always mining a portion of their income to, creating a revenue stream for the chip or phone manufacturers, or perhaps network operators or the like. I would also suspect that for some amount of time most of those chips would be locked in to a specific pool (similar to carrier-locking), which means most of the value of the chip will probably be extracted in a controlled fashion.

All in all, what would this boil down to? Most likely, the people that purchase the device with a bundled miner that would mine for a specified pool say, when the device is plugged in or charged. Maybe if we're lucky, those devices would mine on something like P2Pool, but that has its own problems. The customers might not notice their devices eat up a few extra dollars of electricity and could break down faster after the warranty is over. They would get some dust balances to use in the Internet of Things, but that wouldn't matter much in comparison to some other implications.

The Bitcoin difficulty could be pushed up over time, accelerating its already fast growth. Traditional for-profit miners would have harder and harder time competing in the market against the botnet. If the miners would really be pushed into every device, they would probably be unable to compete shy of plugging new chips in straight from the factory for mining before consumer electronics devices would go through the process of production-shipping-sale-mining. ASIC manufacturers would probably start offering their own mining chips and compete to build their own botnets of devices with bundled miners. Perhaps there would be some market for second-hand mining chips - the manufacturers would first mine with a fresh batch of chips to get in on the lower initial difficulty (possibly under the pretext of "stress testing"), then when it becomes unprofitable, the chips would be sold to consumers, a bit like what Butterfly Labs was doing, only on a bigger scale.

At that point, we would probably see traditional Bitcoin mining pools be replaced with pools owned by chip / hardware manufacturers or network operators. While the talk of "redecentralizing Bitcoin" is all well and good, when push comes to shove I doubt final consumers would be mining through P2Pool if the profits could instead be directed through some big corporation's pocket. Providing the cost of running such a pool would be small, you could still squeeze in a bit of money out of your consumers by making them pay for the electricity used in mining.

Getting your bitcoins for cheap / free might be undesirable, if you subscribe to the labour theory of value (a good is worth about as much as it costs to produce it). While a mining pool today might be more careful with its hard earned coins - selling them for as much as possible, waiting to sell if the price dips, etc. - a botnet mining pool might not care as much. They might also not care as much about various Bitcoin issues - they might not vote on various BIPs, not care if their software provider creates a pool that censors some transactions, create empty blocks, be easier to sell their mining power to "double-spend-as-a-service" pools, etc. If the mining is forced onto the users, they can't vote with their feet unless they are willing to unplug their electronics completely.

Conclusions


While the current state of largely centralized mining pools might be a potential Sword of Damocles hanging over the Bitcoin network, they have a strong incentive not to attack the network:

If a greedy attacker is able to assemble more CPU power than all the honest nodes, he would have to choose between using it to defraud people by stealing back his payments, or using it to generate new coins. He ought to find it more profitable to play by the rules, such rules that favour him with more new coins than everyone else combined, than to undermine the system and the validity of his own wealth.

Giving the mining power to everyone through a P2Pool-like solution might be seen as similar to low information voters - a lot of them would not know what to do.

If embedded mining chips become more widespread, we could see them disrupting the current mining status-quo, but I ultimately doubt the new mining pools would be much more decentralized than the current ones. They would also have less incentives to care about the Bitcoin network - it's not their main business.

Only time will tell how this will play out.

Tuesday, December 1, 2015

P2Pool and low power miners

Recently, we got a new insight into 21 Inc's plans for its mining computer / chips - allowing the device to connect and mine on any pool, and ultimately - mining on a P2Pool-like network to further "redecentralize Bitcoin". This got me thinking about whether P2Pool would actually be compatible with a potential large swarms of low-power devices mining together. Lets see how it might work.

What is P2Pool?


P2Pool is an interesting idea that came about around 2011 to address the growing centralization of Bitcoin mining in mining pools. Instead of connecting to a centralized pool, a miner would instead join the P2Pool decentralized network and start mining there. The block reward would be split between peers based on how many "shares" they contributed to the decentralized network - essentially creating a decentralized "Pay Per Last N Shares" mining pool.

What is very interesting about P2Pool is that it allows for the decentralization of mining - anyone can join the network and contribute, you are free to mine for any valid block as long as you respect the mining reward distribution and all in all it once again allowed smaller miners to mine for Bitcoin blocks without relying (or giving power to) any centralized third party.

However, P2Pool is not without its disadvantages.

It is reportedly underperforming / being "unlucky", indicating that it might be experiencing a higher rate of orphaned blocks. This could be due to traditional mining pools optimizing their new block discovery time (I heard someone mentioning a dedicated communication network for the mining pools, but I can't find a source for that claim currently), while P2Pool might be reliant on the Bitcoin network itself, which can take a few extra seconds to populate.

P2Pool coinbase transactions are pretty big in comparison to the traditional mining pools' transactions. This means the blocks themselves can process a few fewer transactions, and there is a practical limit to how many outputs one can reasonably fit into a transaction to pay for the last N mining shares.

Mining at a traditional pool uses about 20MB per day, or 600MB per month. In comparison, P2Pool puts a much higher burden on the data transfers at about 38GB per month before we start taking the resources used up by BitcoinQT which you also have to run.

All in all, if you are mining on a computer with a good internet connection, a reasonably powerful set of miners attached and you don't mind earning a few percent less than you otherwise could, then P2Pool is not a bad choice.

However, what if you are dealing with mobile devices equipped with low-power mining chips?

21 Bitcoin Computer with P2Pool


Looking at the limitations of P2Pool and what 21 Inc is aiming to do with their mining computer, there are a few problems that stand out.

Currently, P2Pool pays its miners directly in the block coinbase, while 21 Inc prefers to buffer the balances at its shared wallet before letting you withdraw the mined dust to a wallet. If the 21 Bitcoin Computer was instead to be paid directly with the coinbase, you might quickly run out of block space. Looking at some sample P2Pool coinbases (1, 2), we can see about 200-250 outputs being included on average, taking up about 8kB of space. This roughly puts an upper cap of 32'000 outputs on a transaction before a whole block is filled with only the coinbase. Equally divided, every output would receive about 78125 satoshis, worth about 27 cents (at  current 356 USD/BTC exchange rate). This would represent about two days of mining for one of the 21 Bitcoin Computers.

32k computers mining a block every two days is fairly incompatible with 21 Inc's vision of "buffered pool mining" (quick way of mining coins to use for transaction) and putting a mining chip into every gadget.

Based on the amount of unique entities you want on the Bitcoin network, we can start extrapolating how often they could get paid on average. Sticking with the 32k outputs per block, we would have 4'608'000 daily outputs. If we looked at the sales of only iPhones in Q4 2015 (48.05M), we would require over 10 days worth of blocks to credit each of those devices individually. This is all before those transactions are again spent, before taking into account all the other smartphones, quarters and every other potential device one could think of in the Internet of Things world. All in all, Bitcoin couldn't handle this level of spam even if the blocks were increased.

Looking at the mobile data plans of a company like AT&T, 40GB/month would cost one about $300, or about $10 per day. The data price for P2Pool alone is 37 times more than the 21 Bitcoin Computer would earn. Mining at a pool would cost somewhere between $20-$30 worth of a data plan, making the data only twice more expensive than the bits one would earn before taking electricity costs into consideration.

Optimizing for your needs


All in all, it would appear that with mining, like with project management, you have three variables:

  • Centralization vs decentralization
  • Low vs high variance
  • Whether small devices can efficiently mine or not
But we can only pick two of them. Decentralized low variance mining but not good for small miners? That's P2Pool. Centralized low variance mining for any device? Centralized pools. Decentralized mining for any device but with high variance? Solo mining.


Possible solutions?


While with the current technology it might be rather impossible to achieve what 21 Inc is aiming to achieve in full, there are some ways one could compromise while still achieving some of the desired outcomes.

First of all, one could try creating an intermediate solution between a fully decentralized P2Pool and a completely centralized mining pool. Perhaps we could see a lot of new, smaller mining pools popping up based on carrier, manufacturer, geography, etc. that the devices could connect to and contribute the mining power to instead. This would allow the balances to be stored on shared wallets and used accordingly, perhaps aggregated into bigger payments or some off-chain settlement between those nodes (and oh god, we're coming back to the tired 2013-era block size debate and ways of settling without bloating the blockchain...).

We could focus on creating bigger mining devices that would power our mobile wallets. This device could stay at home and mine coins using the standard P2Pool protocol, rather than having a miner in every device. This would probably just get us back to the buy vs mine debate once more though. We could even do without all the physical mining and purchase some virtual mining contracts instead... Moreover, the situation is no different than what one can currently do with the existing mining hardware and since we don't seem to be doing that en masse suggest we wouldn't do it in the future either.

Lastly, we could just ignore the variance and mining profitability altogether and just starting to waste money for the benefit of the Bitcoin network. While this might sound crazy, it might not be that far-fetched of a plan. Chip manufacturers would probably make more money than the chips could ever mine, so they could just fork over some money to pay the mining rewards in a Pay-Per-Share scheme. Mining would still go to secure the network, perhaps in an inefficient way, and we might just end up with the entire Bitcoin mining ecosystem being generally unprofitable to mine in. Since the cost of mining would be distributed between potentially many millions of people, the individual burden might be small in comparison. However, this entire idea would best be suited to an entirely separate post I might do at some other time.

Conclusions


All in all, P2Pool currently is rather incompatible with low-power miners, especially if data bandwidth and profitability is an issue. If there is some way to solve the the underlying problems with how P2Pool operates to address those issues, I would love to hear more, but I doubt we'll see any concrete informations on the subject any time soon.

Thursday, November 19, 2015

21 Bitcoin Computer - the Macintosh of Bitcoin

It looks like the 21 Bitcoin Computer has began shipping recently for $400 apiece. Moreover, we also got a few extra bits of information from the 21.co website about some features and solutions of the machine and the ecosystem in general. Since guessing the business model of 21 Inc seems to be everyone's favourite activity for about half a year now, lets not waste any more time and dig right in.

The hardware


First of all, we've got some photos of the actual machine. The packaging looks good, the mining component of the device looks sleek and elegant, while the actual computer is a standard Raspberry Pi 2 (according to the FAQ). Strange it doesn't come in a case, especially given that even their setup steps seem to be aware that this might cause some problems:



The 21 Computer's mining chip appears to have the following specs:

  • 0.16 Joules per Gigahash
  • 50 Gigahashes per second
At the moment there don't appear to be any upgrade / swap options for the machine.

This seems to put it in the same category as Antminer U3 Batch 2 - currently selling for $20 and clocking in at 63GH/s. The energy efficiency is rather odd - comparing it to existing solutions, it would be at roughly 6250 MHash/J, while the top performer, AntMiner S7 performs at 4000 MHash/J. This would seem to suggest the chip is underclocked to be more efficient.

This is a little ironic coming from a company that wants to put mining chips into mobile devices - if you're worried about the power efficiency of a device that runs straight from a power adapter, and yet you want to include extra power hungry hardware in devices that run off battery power...

At any rate, this puts the value of the whole package at under $100 (with the Rapsberry Pi 2 along with all the extras selling for about $70 at the moment). But, the hardware isn't everything, so lets look at what else we get with the 21 Computer.

The Software


It looks like the 21Inc's software is quite packed with features. The CLI looks exhaustive, you can run a full Bitcoin node, you have your wallet, etc. We have some reports of people running things like the Open Bazaar project on the device just fine.

All in all, it looks like the software is the meat of the package. I've seen a number of people being interested in the software component more so than the whole package itself. Luckily, it seems that one can get the whole open source software without having to buy the 21 Computer:

> curl https://install.21.co/bitcoin-computer/install.sh | sudo bash

Beyond that, I personally don't have much else to say about the software in general. It looks to be delivering on what it's promising in one neat package.

The Rest


Beyond the hardware and software, it looks like (at least for now during the launch week) 21Inc has some responsive consumer service, which is great to know. If some people get into Bitcoin because of this computer, this can be a very valuable service to make sure they stay interested in the service.

The 21 website has a few interesting tutorials on what could be done with the software. Moreover, with the $200 tutorial bounty, we can expect to see more articles popping up over time.

Beyond that, we come into some more interesting nuggets of what could either be something really insignificant in the future, or perhaps will end up as a starting point for something more insidious...

The Quirky


Wallets

It seemed that from the very beginning, 21Inc was aiming to sell everyone on the idea of combining Bitcoin mining with Internet of Things. However, as I discussed almost half a year ago exactly, this makes no economic sense whatsoever. Mining dust wouldn't even cover for the transaction fees, much less amount to anything useful.

However, in their tutorial on micropayments, we can see that probably the encouraged method of transferring money between individuals won't be the Bitcoin network itself, but the so called "BitTransfers", which looks like a fancy way of saying "shared ewallet transfers". In other words, 21Inc is building itself up to be something like CoinBase for the IoT world - settling peer-to-peer transactions using its centralized database.

Mining

Now, to load the wallet, one would of course mine the coins using the 21 Computer. Even in this area could be spruced up with some marketing talk, as we go into the mining tutorial and "buffered pool mining". 

We start with a time lesson talking about transitioning between CPU mining into pool mining when one couldn't realistically mine a block by themselves. Pooled mining allowed one to reduce the reward variance (without the pool, you either got a whole block and 50BTC, or no block and no reward, while pooled mining allowed you to get a fraction of the reward, but at a more regular pace). 

Afterwards, we seem to get a vision of what 21Inc wants to sell as the vision for its computers - "redecentralizing Bitcoin" by the use of "millions of mining chips worldwide each generate a small stream of bitcoin" as they believe the ASIC chip development will start following the Moore's law in the near future.

However, since the default way (and possibly the only way without modifying the software) to mine on the 21 Computer is to connect to the 21Inc's pool and receive the dust rewards in your 21 shared ewallet, it's not really a decentralization of mining as it is adding another central server to the equation.

Perhaps if we would instead see P2Pool on the device we could call it an effort in the right direction, but then you wouldn't be able to solve the mining variance problem very well, nor would you lock people into your walled garden of an ecosystem.

In the next section we get another new buzzword - "Buffered Pool Mining". You see, 21Inc believes that if you're mining in a pool, you will have to wait:
  • For the pool to mine a block before you get paid
  • To mine enough coins to reach the minimum withdrawal threshold
  • For the block to mature over 100 confirmations before you can get paid
  • To earn bitcoins before you can spend them again if you run out

Instead, 21Inc essentially combines its shared ewallet with the circa 2011 BitPenny's idea of Pay-per-share. As described in the Bitcoin Wiki:

The Pay-per-Share (PPS) approach, first described by BitPenny, is to offer an instant flat payout for each share that is solved. The payout is offered from the pool's existing balance and can therefore be withdrawn immediately, without waiting for a block to be solved or confirmed. The possibility of cheating the miners by the pool operator and by timing attacks is thus completely eliminated. 
This method results in the least possible variance for miners while transferring all risk to the pool operator. The resulting possibility of loss for the server is offset by setting a payout lower than the full expected value.

I wonder how hardened is the 21 mining pool against what an attacker with a state-of-the-art mining rig could throw at it...

But we also get one more interesting feature, which is essentially Bitcoin, lets say, nanolending:

Finally, you do not need to send N hashes to the server before getting N hashes worth of mined bitcoin. That is, by invoking 21 mine your 21 Bitcoin Computer can receive bitcoin in advance of future mining at the expense of a small asymptotic slowdown in the rate of bitcoin streamed to your device.

Which considering the price tag of the machine is still rather amusing.

We conclude the tutorial with:

The basic idea is that buffered pool mining is a new way of getting bitcoin: not by buying huge quantities slowly for investment purposes on an exchange, but by mining tiny quantities rapidly for programming purposes at the command line, rate-limited by a mining chip.

I guess someone forgot the middle-ground of being able to buy a small amount of BTC, for example by phone, getting small amounts of coins for free (through facets or by signing up to various wallets), or if you're really a developer, using TestNet Bitcoins.

Anything else?


As someone that frequents the Bitcoin-related subreddits, I noticed a large amount of submissions about the device recently. That's to be expected when a new, big product launches and everyone gets their hands on it. However, some of the submissions and discussion appears to be somewhat astroturfed. Submissions titled "Whoa" that aren't some Shiba Inu memes generally don't do very well on a crypto subreddit. Cynical quips usually stick better, you rarely see people talking in bold (1, 2), and hardware is rarely inspirationally compared to some major milestones in commercial computing. Even the self-post appear a bit defensive (1, 2). My money would be on at least some of the sentiment being not entirely as grassroots as it might appear in the first place...

Conclusions


Coming back to the title of my post - 21 Bitcoin Computer to me looks like a Macintosh Computer for Bitcoin - an overpriced, underpowered piece of hardware coupled with some decent software. It appears to be building the roots of a walled garden of closed-loop wallets and related ecosystems. If you're a developer, you can do better, both in terms of mining performance, computing speed and price for a throwaway machine for testing. Their software and related articles appear to be the main piece of value added.

For $400, even for a "dev kit" as it's sometimes advertised, I would still rather buy some BTC (by "buying huge quantities slowly for investment purposes on an exchange" - which would still be a smaller investment than the machine) instead of committing to mining. But perhaps it's like some random comment said on Reddit - "the investment will get you to commit to using it".

Related discussions:



Thursday, May 28, 2015

Mining versus Consensus algorithms in Crypto 2.0 systems

Mining versus Consensus algorithms in Crypto 2.0 systems

Recently, I had the pleasure of talking with David Schwartz, Chief Cryptographer at Ripple Labs about a topic that I haven't heard covered before - the implications of using a Consensus algorithm for ledger creation rather than a Mining approach, such as the one used in Bitcoin. This seemingly insignificant difference can affect the long-term viability of a Crypto 2.0 system as it turns out. But first, some theory...

Mining algorithms


As pretty much everyone knows, new Bitcoin blocks are created through a process called mining. Every miner on the network competes to produce the next Bitcoin block by the use of Proof of Work algorithm. If you find the solution first, you have successfully created the next block and thus get the block reward plus fees for included transactions - pretty simple.

There have been a lot of tweaks made to this simple algorithm in many altcoins out there. A number of different coins use different hashing functions for their Proof of Work, some networks introduce Proof of Stake or Distributed Proof of Stake and so on. What all of those algorithms have in common is that every block is created by a single entity - it might be a lone miner, or perhaps a mining pool aggregating a number of workers, but there is still a singular authority that dictates how a block looks.

Consensus algorithms


The Consensus algorithm as popularized by Ripple and also used in Stellar works on a different principle (some videos on this subject - 1, 2). Instead of performing any mining, a number of validators agree on which transactions should be included in the next ledger. Based on that agreement, every validator creates the same ledger.

While the way the validators are chosen can be a a difficult and important design decision, the result is similar - there is no single entity that creates the next ledger.

Malicious miners - what can they do?


While most people have heard about the dangers of a 51% attack and some are also aware of the Finney attack, today we would be talking about more benign things every miner can do to every block they create.

Any miner that creates a block can:

  • Control which transactions are part of the block, if any
    • They can prevent certain transactions from appearing in the block they mine
    • They can include any number of valid transactions into the block. Even if fees are forced for any such transactions, the miner will earn those fees back
    • If there are multiple conflicting transactions, the miners get to pick which are included in the block, thus invalidating their double-spend counterparts
  • Control the order the transactions are included in the block
  • Decide whether to release the block they created at all
  • Set the various block parameters within some limits (they control the nonce and timestamp)


In the Bitcoin world, pretty much all of those things don't really affect the network performance all that much. Sure, the miners can censor some transactions for a block, but provided the network as a whole is not compromised, those transactions should eventually make it into someone's block. They can also spam the block with any number of their own transactions for free, but in the grand scheme of things it's just an extra megabyte of data that needs to be stored. All in all, due to Bitcoin's straightforward transaction nature and the fact that we're dealing with only one currency, a malicious miner can't really do much.

Now, lets consider the same scenario on a more sophisticated Crypto 2.0 platform, such as Ripple, BitShares, Ethereum, Omni or the like. The network not only handles their native currency, but also offers a lot of other features - derivative contracts, decentralized exchanges, smart contracts and so on. Suddenly, whether a transaction is included in a given block or a block after can start to matter a lot more.

If a malicious miner sees a big buy order coming into the market that would move the price significantly, they can engage in front running - the buy order could be pushed to the back of the queue or even left out until the next block, while the miner buys up all of the current stock and re-lists it at a higher price to turn a profit. Alternatively, when they see there is a high market pressure coming in, especially in systems that are inefficient by design, they can buy the orders up one by one by using their power to include any number of their own transactions into a block for free, and similarly re-list them for people to buy up.

When we enter into the smart contract world, we have a few more exploits.

Perhaps the system in question is relying on the miners to be smart oracles and report some price data. The miners can misrepresent the price in their favour - perhaps not so blatantly as to report different orders of magnitude, but one could use data that is a bit stale or fudged on the second or third significant digit without it looking too suspicious.

The miners could also try to influence some time-sensitive contracts - maybe someone tried to make a bet on some lottery during the last possible minute, or some contract deadline is about to come up and the miner stalls the transaction by one block? That could change the outcome of the contract.

Lastly, if some smart contracts implement gambling on the blockchain with the random number generator being influenced by the mined blocks, the miners could cheat that system by only releasing blocks favourable to their bets. Say, if we have a virtual coin flip that is heads if the block hash is even and tails if the hash is odd, if the miner stands to gain more by winning the bet rather than creating the next block, they can withhold the blocks that aren't favourable to them. Provided their computing power share in the network is greater than the house edge in the game, the miners would turn a profit in the long run.

All in all, there is a lot more a malicious miner can skew in their favour in a Crypto 2.0 system than they could do in a traditional system like Bitcoin.

Validators


In comparison to the miner-based approach, the consensus model based on validators solves the listed issues in most cases. Provided the validators are not colluding with each other to overtake the network, most of the above listed attacks are reduced if not eliminated altogether.

While a malicious validator might try to do some front-running, their transactions aren't more likely to be included into the next ledger than the transactions anyone else submits. Having multiple validators act as smart oracles could allow one to average out the answer and limit the influence of one malicious report. Time-sensitive contracts could be slightly influenced by trying to stall the consensus mechanism or vote against some transactions being included in a ledger, but since the system is designed to be fault-tolerant, one malicious entity shouldn't be able to do much.

Influencing the ledger hash is possible to some degree - the validator can try predicting what the next ledger will look like and adding which transaction could influence that hash in their favour, but everyone else can do the same. Since all parties are just as likely to influence the ledger hash, the result of this influence could make the outcome just as random as it ought to be, or at least make it very hard to predict whose influence will win in the end.

All in all, a validator-based approach to ledger generation reduces the number of exploits that can be performed in a Crypto 2.0 system.

Conclusions


One could compare the mining approach to block generation to a short-term dictatorship, while the validator approach is more akin to democracy. While both systems can be exploited or used for good (the Roman Republic elected their dictators in times of need, while democracy can spiral into mob rule), the democracy of validators requires more parties to be malicious before the system becomes compromised.

While in the Crypto 1.0 world a malicious miner can't do much to harm the system, in a Crypto 2.0 world there are a lot more exploits that need to be addressed.

As this is a topic I haven't seen properly discussed before, I would love to hear the input from the developers of various Crypto 2.0 systems - Omni, Ethereum, Counterparty, NXT, BitShares and so on as to how they view this issue potentially affecting their networks.

Thursday, May 21, 2015

Much ado about nothing - pondering 21Inc

Much ado about nothing - pondering 21Inc

In the last few months a lot of people have been talking about the "mysterious 21 Inc" - a Bitcoin startup that raised $116M in recent funding to work on their secret technology. Everyone was speculating on what it could be based on the little information that we had from their job offers looking for ASIC engineers. People were guessing they could be making space heaters that earn money, or perhaps an ASIC-powered toaster. Well, the wait is over and we finally know that their big plan was... to put Bitcoin miners into phones...

Lets ponder for awhile how feasible this approach could be.

What are the current rates?


As with all analysis related to Bitcoin mining and profitability, everything is in the state of flux. So here are some current numbers we will be using for those of you who might be reading this in the future.


Based on that, we can do some calculations. That chip is currently mining about 0.000037BTC per day, earning about 0.013540 BTC or $3.17 per year if you run it at no cost. If you take the cheapest electricity cost of say, India or China at $0.08 / kWh, your annual profit is about $1.28, so you break even for the cost of a single $1.5 chip after 428.5 days of mining.


The current standard transaction fee in Bitcoin is about 0.1mBTC per 1000 bytes. The chip could make this much in about half a week.

Currently the difficulty on the Bitcoin network has slowed down its growth. It currently is about 48B, 5 months ago at the start of the year it was 40B, it was 23B in September of last year, and 13B in July of last year. So the difficulty has grown by roughly a factor of 4 since last year, but currently it looks like it slowed down to under a factor of 3 annually.

Estimating how much bandwidth a Bitcoin miner takes can be a bit tricky. Some people have reported it using about 20MB per day.

The difficulty approach, versus the simple approach


Looking at all those numbers, it looks like the mining doesn't scale all too well. In order to mine a dollar of bitcoins using a single chip it would take a phone non-stop 4 months of work. During that time, the phone would need to be connected to the Internet, powered up and heating up from the mining. Subtract from that the cost of electricity, mobile data and so on, and you might be operating at a loss in most situations. This is not to mention the decreased battery life from higher heat exposure and so on.

All in all, ASICs operate the best with economics of scale in mind - producing chips in bulk, cramming them into well-ventilated chassis, putting those in a data warehouse and so on. Perhaps instead of cramming a cellphone with an ASIC chip, it could come with some cloud mining subscription for life where a given datacenter would mine for BTC in the device's name and send those coins to the address bound to the phone over the years?

Alternatively, do away with mining and just buy some coins up front. Add $5-$10 to the phone's price up-front, but BTC with that money and trickle the coins into the device say, once a week or whenever the balance is getting low. Heck, if you notice a device's balance is still positive, you can always keep the coins for longer and perhaps even cash the coins after a year of inactivity of a potentially dead phone. This solution is much simpler and elegant. Best of all, since all Bitcoin balance data is public, you can top people's phones up without checking with them - you will know when their balance is running low.

Conclusions


Sometimes the first solutions might be the most obvious, but there are more elegant solution to solving the same problem. Cramming Bitcoin mining into devices in a way that detracts from their primary usage doesn't make sense. If you want a device augmented with Bitcoin mining, make sure its primary function is generating heat - this way even if the toaster or the space heater doesn't earn any money, it will still be a useful source of heat, rather than a hotplate for a phone that just eats your bandwidth.

Saturday, December 7, 2013

Why fast maturing altcoins are doomed to fail, or why $30 dollars a day is not enough to secure Quarkcoin

Why fast maturing altcoins are doomed to fail, or why $30 dollars a day is not enough to secure Quarkcoin

Recently I came across Quarkcoin, a Bitcoin-based altcoin with a very fast maturation. The blocks start with 2048QRK reward and halve every 60480 blocks. Each block is set to take about 30 seconds, so this give us roughly 3 weeks of blocks between each halving event. Minimum block reward is 1QRK, and will be reached after 11 halving events, or about 6 months.

A lot of people consider Quarkcoin to be a pump-and-dump premined scamcoin. In some sense, they are right, but in some sense, we are stretching the definition a bit here. QC has been promoted by the likes of Bill Still and Max Keiser, driving its price up a lot. While not falling strictly under the definition of a premined currency (one in which all coins are created in genesis block and subsequent mining reward is insignificant if present at all), it certainly is reminiscent of such schemes.

Looking at the market price of QRK (at the time of writing, each coin is work about a cent, giving the entire market of about 250 million coins the value of $2.5M), a lot of people from the Bitcoin community will recognize it as a pump-and-dump scheme. The currency exists without much of a market - it appears to be traded on 3 small exchanges, there is a lack of tools or documentation for developers, and it appears to be accepted through one obscure payment processor, mainly by shops that will accept any currency. All in all, there is nothing that warrants the current price, asides some key individuals driving its popularity.

However, at the same time Quarkcoin can be an amusing case study for fast maturing altcoins. Just think about it - once blocks will have 1QRK rewards, that will essentially be the baseline of how secure the network is. At the current price, this would equate to $30 per day.

Any mining-based altcoin can essentially be brought to a standstill by a 51% attack. This means that the total computing power of an attacker would equal to the computing power of the entire network. As long as the miners on the network are rational according to game theory (they mine the coins for profit and stop mining when they are not making a profit), the cost to mine the block should be roughly equal to the amount of money earned by mining the block. Since the block reward will level out at 1QRK per block, or 2880QRK per day, this is about as much it would cost to perform a 51% attack on the network in electricity costs.At the current exchange rate of 1 cent per QRK, this is a cost of $30. This is all that will stand between someone being to transact in Quarkcoin, and having their coins sit idly for a day not getting confirmed. Imagine what could happen in that time...

A malicious party could spin up a lot of Amazon EC2 instances, or otherwise rent some server farm time to be able to efficiently mine Quarkcoin without having to pay high upfront costs. It might cost them more than $30 per day, but even spending $1000 would be nothing in comparison to bringing down $2.5M market. They could buy up some QRKs beforehand and position them at online exchanges that do not require KYC verification and are not AML compliant. They start the 51% attack, sell all of their coins and announce what is happening - Quarkcoin is under 51% attack. The attack will persist as long as QRKs have value. No transactions will be confirmed, so nobody will be able to get their money into the exchanges and sell them until it is too late. All the big players that don't hold their money on the exchanges essentially lose all of their money. Panicked people do their best to dump their coins. The attack persists for an hour, a few hours, a day or more as needed. Those that were not convinced at the start change their mind sooner or later.

People holding a lot of money in Quarkcoin would probably do their best to fight against the attack - perhaps sending transactions with high fees to incentivise miners to mine, getting as much computing power as they can onto the network to counter the attack. The question is - how prepared would such people be for this situation in comparison to the attackers? One would have as much time as they need to prepare themselves and streamline the process, the others would have to catch up if they haven't done their lesson in advance. One could also go after the exchanges, performing DDOS attacks on them to bring them down and cause more panic - even if someone was able to get their money in, they might not be able to trade.

Of course, the network could be hardened against such attempts by the people with a lot to lose running their own miners beyond profitability and artificially increasing the difficulty. This would make a 51% attack harder, but at the same time it would destroy the healthy network of miners that would otherwise be interested in profiting from the currency.

All in all, what a lot of people that use fast maturing altcoins don't understand is that unless adoption is driven as fast as the reward is dropping, the currency will develop a big vulnerability to 51% attacks. High transaction volume with appropriate fees would solve this issue, but this requires people to start using the currency, not just buying it and holding it.

As it stands, it looks like Quarkcoin is headed in one of two directions - either it will be just another pump and dump coin and will end up in a number of people losing their money, or it will be destroyed in a more spectacular 51% attack on the network. Anyone holding a grudge against the coin or people that have a lot of their assets tied to the currency can be a potential attacker. A Bitcoin or Litecoin purist could wish to destroy it to prevent people from diverting their money from their currency of choice. Anonymous might do it for the lulz.

We'll have to wait and see whether Quarkcoin will go out with a bang or a fizzle, or perhaps persist against all odds. We will probably see in the following few months what the future will bring.

Sunday, December 18, 2011

How did it all start?

Where did my adventure with Bitcoins start? As far as I remember, it went like this:

At the time I was a student of first semester of MSc course in Artificial Intelligence and Software Engineering. I was taking a boring lab at the moment, Modelling and Analysis of Informatic Systems. I googled around for some info on the PSN hack, came across the LulzSec Twitter account, and I saw this message:



I thought that it was intriguing that there was some way to send such a small amount of money to someone, and then I started looking around for what those "BitCoins" are. Soon after I was hooked on the concept of creating your own money. The book of value of Bitcoins was only starting, so like many people I was doing my calculations and looking into getting some hardware. Did manage to mine and sell some part of a coin before the value stated going down, but at any rate, I didn't get rich;).

By that time I learned a bit more and knew that if I wanted to earn anything in the long run I had to get into making my own mining pool, rather than mining. The costs of getting a decent mining rig was too much for a student, and the ratios between how much it costs to mine coins and how much they are worth didn't calculate. I decided to incorporate it all into my master thesis, but since the summer break has already started, it was hard to get in contact with anyone form the university and ask them to be my supervisor...