Tuesday, August 11, 2015

Bitcoin and Beyond - a presentation

Bitcoin and Beyond - a presentation

Recently, I was invited to be a speaker for the 2015 Annual Gathering of Mensa Canada. Instead of doing the usual "What is Bitcoin" talk and walking people through the basics of how Bitcoin work from a technical standpoint, I decided to do things a bit differently. Instead, I decided to briefly talk about a lot of diverse topics and projects surrounding Bitcoin to hopefully spark some interests and inspire people to research further.

Here is my presentation - Bitcoin and Beyond

It was aimed to be a 40 minute presentation with 20+ minutes to spare for questions and conversation. Some of the projects covered I'm personally not a fan on (I'm looking at you in particular, BTCJam), some are mainly place holders for more general ideas (like ProTip), but I think overall I managed to cover a wide variety of interesting topics.

The presentation itself went fairly smoothly. We had some discussions on the topic of sending money over email (some people weren't aware only some banks can do it through a proprietary technology of Interac and it's not an international service), the question of who do you really buy domains from on Namecoin, etc.

I hope you enjoy the presentation slides and perhaps they inspire you to give a similar presentation yourself in the future ;).

If you'd like me to give a talk at your conference however big or small, let me know and we can figure out the details.

Saturday, July 25, 2015

Fighting Bitcoin theft - law enforcement block explorer

Fighting Bitcoin theft - law enforcement block explorer

Recently I had a chat about what would be some good features for a block explorer to have. One thing I don't really see implemented too well is a tool for helping fight the theft of bitcoins. The idea isn't anything new really - I discussed something similar back in 2013 - a block explorer focused on tracking officially reported thefts of coins and providing a tools for exchanges to cross-reference their inputs with the database. Here is how it could work...

The stolen coin tracker


The tracker would essentially be a block explorer focused on tracking coin taint - nothing ground breaking there. However, if you pair that with allowing law enforcement from around the world submit exactly which coins they want tracked, it can become a quality tool for figuring out whether some coins are "tainted" or not.

However, the taint shouldn't be permanent. If the stolen coins are recovered, or they end up very diluted in a legitimate place of business, the outputs might need to be whitelisted as "clean" to stop the tracking. This way, the coins could go back into circulation without triggering any more flags in the future. This whitelisting process should also be carried out on request of the law enforcement.

The reason why we would focus on law enforcement is to limit the amount of false claims of thefts. If someone really lost their coins, rather than only claim to have lost them, they wouldn't mind filing a report and being liable in case they lied. Similarly, when tainted inputs are reported but they are deemed too diluted by whoever is responsible for the local AML enforcement, they would be the ones responsible for that decision.

Knowing which outputs to track, the rest is trivial - follow the coins each time they are spent, keep a track of how the taint might be diluted down the line and record everything for later reference.

Who is going to use this?


Any company that is required to follow AML regulations, like any Bitcoin exchange, would want to start using the service to make sure they are not liable down the line. The exchanges would either want to ask the tracker about every deposit they receive to check its taint, or if they are very privacy conscientious, they might just want to poll for any recent movements of tainted coins and do the cross-referencing themselves.

Any transaction that contains tainted coins could be reported to the authorities, or there could be a threshold of the minimal taint for reporting (say, above 10%). Depending on the regulations, the coins would either need to be frozen by the exchange, or if the taint is small, the authorities could whitelist the transaction on the tracker.

The implications


As with many things Bitcoin, the solution is not clearly good or bad. On the positives, this can discourage people from stealing bitcoins as they would have much harder time spending or converting them (who knew infinitely traceable currency can be so hard on criminals?). As for the negatives:

  • We would be dealing with many jurisdictions with different laws, making the blacklisting and whitelisting process complicated
  • This idea may lead to the Bitcoin redlists, where all coins would be considered tainted unless they were whitelisted - clearly not a desirable path for Bitcoin to be heading
  • The tracker would only be useful if a lot of international Bitcoin exchanges would choose to use it. Having a few big exchanges ignore it completely would just mean everyone with tainted coins would just visit them instead circumventing the tool
  • This tool would negatively impact Bitcoin fungibility, which makes the system less desirable overall
  • A lot of independent vendors and casual users accepting bitcoins wouldn't be able to effectively report all suspicious activities, possibly forcing them to switch over to using big payment processors instead, going against the Bitcoin idea of being one's own bank

Conclusions


All in all, do the benefits outweigh the drawbacks? Possibly. Then again, if someone that understands Bitcoin won't create a tool like this and run it responsibly, we might end up with someone from outside that doesn't know how the Bitcoin ecosystem work come in and force something worse upon us...

Monday, July 13, 2015

Who stands to benefit from a spam attack on the Bitcoin network?

Who stands to benefit from a spam attack on the Bitcoin network?

As discussed earlier, the Bitcoin network has recently been flooded with a lot of spam transactions. While at least some of this was an honest stress test, it brought more attention to the fact that the Bitcoin network can be pushed to its limits with relatively low cost by anyone. While the network should be resilient against zero fee transaction spam attack, putting some money and effort into the attack can make it seem like a lot of honest transactions with relative ease.

Now, since we know how the Bitcoin network could be destabilized, let us ponder who might benefit from such actions.

DISCLAIMER: while I will be mentioning a lot of specific examples of peoples and projects that might benefit from such an attack, please treat them only as illustrative examples. I have no evidence of their involvement in the attacks, nor do I believe any of them would employ such a strategy.

The usuals


Since we're talking about an attack on Bitcoin, lets get the usuals out of the way - governments, big banks, PayPal, etc. wanting to bring Bitcoin down since it challenges "the old ways". There isn't much new to add to these speculations or motivations, so might as well skip this part of the debate for expediency's sake.

The direct competitors


Bitcoin has been copied so many times people lose count. There is never a shortage of copycoins out there. Since Bitcoin has a throughput issue of handling a lot of transactions, you can easily see someone creating an altcoin with higher block sizes and faster blocks to sell itself as the solution to Bitcoin. More ambitiously, you can look at coins that have added some improvements to the protocol to combat spam, like Litecoin for example. Sustain a spam attack on the Bitcoin network long enough to sell your story of being the savior of cryptocurrencies and you might just be able to push up the price of your coin high enough to turn a profit.

The speculators


Just like you can speculate on the price of altcoin alternatives going up, you can also try speculating on the price of Bitcoin being affected by the spam. Alternatively, you could try to cause something similar to "trade engine lag" on the Bitcoin network and try to game some exchanges while other traders would have trouble moving their coins onto the exchange to cash in.

The solution evangelists


Even if we don't look at the altcoin space, we can see a lot of people with an agenda of where the Bitcoin code should move towards. Whether they are doing it for profit or for personal satisfaction, there is a potential for those evangelist of their own solutions to attack the network and push their code onto others.

Below are some examples (again, only illustrative examples, read the disclaimer) of potential solution evangelists.

Sidechains is an interesting concept of how to move a lot of transactions off the Bitcoin blockchain while still having a currency tightly tied into the Bitcoin itself. As (to the best of my knowledge) sidechains are still impossible to fully implement into the Bitcoin network without a soft fork, using the spam attack as an opportunity to push for a fork would be beneficial to them and enable sidechains to come to the Bitcoin network.

The debate over Bitcoin block size increase has been a hot topic for a few months now. The topic has been pushed most notably by Gavin Andresen, with some people even speculating on "gavincoin" becoming a reality (read more here). More so than Sidechains, the concept is not possible without a hard fork to the Bitcoin protocol, thus pushing the block size increase amid the spam attack would make the core developers more urged to consider going through with the fork to solve the issue.

Finally, something that doesn't require a hard fork - transaction filtering. This approach relies on being able to identify which Bitcoin transactions are spam and which are legitimate use cases and prevent the spam from propagating through the network. If enough nodes in the network would stop spam transactions, the network as a whole could develop herd immunity against spam. However, the same mechanism could be used to deny some Bitcoin businesses' transactions from reaching the miners. Such transaction censorship has been tried to pass unnoticed in the past by Luke-Jr, and could possibly be tried again along with more honest spam filtering.

The off-chain alternatives


Since moving transaction on the chain can be a problem, some people might propose solutions based on transactions being processed off-chain instead. Examples of such alternatives would include the Lightning Network, Ripple, Open Transactions or shared wallet providers such as Coinbase. If the off-chain solution can deliver bitcoins to people faster than the real network and some people don't know or don't care how they receive the coins, they might appear as a legitimate replacement for sending real Bitcoin transactions to some people. This might be also the case when Bitcoin transactions are too pricey to be included in the blockchain.

Crypto 2.0s eliminating competition


There are a lot of Crypto 2.0s out there. A good deal of them rely on the Bitcoin network to function - Colored Coins, Omni or Counterparty for example. There are also some emergent platforms that offer services tied to the Bitcoin blockchain, such as Factom. If the transactions for those networks can't make it into the Bitcoin blockchain, the network itself performs worse and suffers as a result. Their alternatives on the other hand stand to benefit from people potentially switching over. Ripple could benefit if Omni is not performing well, Ethereum stands to benefit from Counterparty being slow, etc. While being on the Bitcoin blockchain has been a selling point for a lot of companies, it can turn into a detriment if the Bitcoin network is overloaded.

Extra: bribing the miners for their compliance


As a side-note, it might be interesting to consider how some parties might want to even further push their agenda onto the network by essentially bribing the miners for their compliance.

Say, if someone wanted to eliminate some "spammy" transactions from the Bitcoin network, whether it's SatoshiDice's dust transactions or perhaps Omni transactions. They could easily set up an anonymous website claiming they will pay every miner X amount of bits for every block they create that complies with their spam filter. As long as they offer more than the miners stand to earn from the transaction fees, there is a benefit to them complying. With the excuse of excess spam, the miners can't be entirely held accountable for some transactions not making it into the block. Since the miners can be paid directly to their coinbase address, everything is transparent and nobody needs to agree to collude.

Conclusions


A stress test of the Bitcoin network can be all about preparing for the higher transaction volumes that are to come in the future, but it can also be a way for some people and organizations to further their agenda. While it might be still really early for such high-level politics to surface around Bitcoin, who knows what the future might hold?

Thursday, July 9, 2015

Fighting Bitcoin spam with Bitcoin Days Destroyed

Fighting Bitcoin spam with Bitcoin Days Destroyed

As many of you might've noticed, the Bitcoin network has recently been flooded with a lot of spam transactions. While the problem is nothing new, essentially a plain old DOS attack, the Bitcoin network doesn't appear to have much in a ways of contingency attack if the attack is sustained. I would like to propose a possible solution to at least mitigate the attack somewhat using Bitcoin Days Destroyed.

For those of you who might not be familiar with the concept, Bitcoin Days Destroyed is an interesting metric for transactions. For every input, you multiply the coin age (when the transaction was included in a block) by the amount of coins being spent. You add up all of the results for the whole transaction Nd you get your BDDs. So, spending 1BTC a day after it was received gives you 1BDD. A week after it was received - 7BDD. 0.1BTC after a year has 36.5BDD and so on.

Now, if the order transactions are priorities for inclusion in a block was dependent on their BDDs as well as fees and size, it could limit the effectiveness of the spam attack - since the spammer relies on sending a lot of transactions often, unless they have a lot of coins, their transactions will have a very low BDD score. Standard users should have higher scores by default, provided they don't cycle their coins all the time.

Of course, this method only works if the mining pools would follow the rules. Seeing how many pools still mine blocks that aren't full gives one little hope the situation will be resolved quickly.

Side note - this solution isn't all that new either. I did write it down broad strokes in my master thesis (pages 42-43) back in 2011-2012 ;).

Tuesday, July 7, 2015

Cryptos - the anti-euro

Cryptos - the anti-euro

In the light of recent banking problems in Greece, it might be interesting to revisit the ideas behind the Euro and how they hold up in the world of cryptocurrencies. While some might view Bitcoin as a possible solution to the problem, other take a more sober look and realize that we aren't dealing with a currency crisis as much as a banking crisis.

Benefits of Euro


There are many benefits to multiple countries using the same currency as opposed to everyone having their own. The currency itself can be more stable and reliable, there is an ease of money flow between the countries and the countries themselves become more interconnected in trade and therefore less likely to go to war.

All of these make sense if you consider both the longer history of Europe and how things operated around the turn of the millennium when Euro was introduced and adopted. Trading between different countries and currencies was an extra step adding complexity and delay considering how slow the banks can move.

Benefits of Crypto


Now, if we jump ahead by a decade and a bit to the present state of affairs. On one hand we have the euro debt crisis, but also the modern technologies like Bitcoin and Crypto 2.0s.

If we look at Bitcoin, it can be compared to Euro in some ways. It is a singular currency that was designed to possibly replace the national currencies of multiple countries. Understandably, Bitcoin is more similar to gold than Euro when it comes to how it is issued (mining versus central bank issuance), but that's not what we're focusing on today.

Now, if we look at an efficient Crypto 2.0 system, it can be compared to what we had before the Euro - multiple entities issuing their own currencies and being able to trade between them. Everyone is responsible for how well their own currency performs and the value of their currency reflects that.

What are the benefits of Crypto 2.0 over how things used to work? Since the system is open and all trades happen in real time, the flow of money is greatly improved. Even if we don't use a single currency to settle, we can go to the open market, perform atomic swaps between as many currencies as we need to perform the trade. The buyers are not bound by the currency the sellers accept and vice versa - everyone can hold and accept one currency, while being able to spend it with anyone else easily. In other words, we achieve one of the goals of Euro, facilitating easy international trade, without the need for a single currency.

Conclusions


While adopting a Crypto 2.0 system instead of Euro might not achieve all of the goals of Euro (such as strengthening the currency on a global scene or unifying the monetary policies of multiple countries), it creates an alternative to the Eurozone solution. It might be an approach worth considering if Greece abandons Euro, or perhaps as a way to connect multiple countries in some other region.

If we wish to have a singular currency, let it be Bitcoin, but if we can't have that - lets at least have an efficient way to trade between everything else.

Sunday, June 28, 2015

Bitcoin vs Blockchain

Bitcoin vs Blockchain

In the recent months there has been a lot of buzz in the financial world about the "blockchain technology". It seems that everyone from Overstock to NASDAQ are getting into the game, but the Bitcoin name is uttered less and less often. The consensus is that the blockchain technology is interesting, but Bitcoin is not. On the flip side, the Bitcoin community appears to detest the notion countering that the blockchain cannot exist without Bitcoin. Lets analyse this topic and figure out what is going on...

What is a blockchain?


There appears to be some confusion among some people as to what the blockchain is. The technology bears some resemblance to a database and git in particular. The general consensus appears to be that a blockchain:
  • Is a database consisting of atomic transaction records
  • It is write-only (barring a 51% attack)
  • It is immutable (transactions cannot be changed, again barring a 51% attack)
  • Commits to the blockchain come in a form of a block
  • Commits have an unambiguous sequence (every block refers to a previous block)
  • The blockchain protocol enforces some rules as to how each transaction is handled (through a protocol and smart contracts)
  • The blockchain protocol has a way of resolving forks in the chain (for example, longest chain)
  • At any time, the blockchain is in a predictable, unambiguous state (given by the current block)
Beyond those, there is some disagreement as to whether or not some features are needed:
  • Does a blockchain need a native currency?
  • Do blocks need to be mined?
  • Is a blockchain controlled by a single entity still a blockchain, or just a database?
Lets explore some of the disagreements and possible misconceptions in greater detail.

"You can't have a blockchain without Bitcoin"


If we're talking in a literal sense, that statement is obviously false - there is nothing in Bitcoin that imbues its blockchain with some special properties unobtainable by say, Litecoin or Dogecoin. However, if we're talking in a more broad sense about blockchains without native coins that provide an incentive for the miners to be creating more blocks, things get a bit more complicated.

In a traditional blockchain like Bitcoin, the native currency is not only used to incentivise the miners, but also to prevent spam. It is quite an elegant solution - anyone wishing to send a payment won't mind spending less than a penny to get their transaction included in a block, but someone flooding the network with spam transactions will feel the burden of the fees compounding on them.

A blockchain without an internal currency loses both the incentive for the miners to create new blocks and prevent spam through the use of fees. While this would probably cripple any decentralized blockchain, it might not be the case with more centralized blockchains (we'll discuss them in detail later on).

The miners can be subsidized in other fashion, or even ran for free by the businesses that rely on the network. This is the case with Ripple's validators - most of them are run by Ripple Labs, since they have a strong stake to keep the network running, but one could imagine a more decentralized network with validators being run by the various gateways on the network. Since the validators earn money in some other way (running gateways, providing other services, etc.), it makes sense to keep the servers running.

If we're talking about blockchains without fees, Hyperledger and Eris come to mind. While those solutions don't appear to be suitable for decentralized networks, they make sense if we're talking about a finite number of known servers communicating with one another. In this scenario, similar to a private network, you don't expect spam or DOS attacks to be an issue - all the parties are known and they have no motivation to attack the network. Moreover, if the users of the network are known, they can be punished if they try to break the network - either by having their access revoked, or possibly by some legal actions being taken against them. 

So all in all, it looks like decentralized networks do need a token to run their blockchain, while more centralized solutions can get by without them through other means.

"Centralized blockchain is just a database"


While in the previous section we touched on the economics of running a centralized blockchain, here we will be discussing what is the point of running a centralized blockchain in the first place.

There are many reasons to connect to a decentralized blockchain like Bitcoin - you can transact with anyone in the world, nobody can ban you from the network and all your transactions are forever stored and distributed among many computers all around the world. However, there are also some needs that can't be achieved in a public ledger - protection of private data, instant transaction speed, dealing with only known parties, etc. All of those are features needed by some companies - perhaps they need to follow strict KYC rules on all clients, or they are dealing with sensitive financial information that need to be kept private. One way or the other - there are some valid reasons to run a private blockchain.

Given all that, what advantages and disadvantages are there to using a blockchain over a database?

There are certainly many disadvantages - since the blockchain is a new technology, it might not be as optimized as a database. If we're talking about a distributed network, there is also a lot of delay when the data is transmitted, not to mention the block creation time itself.

There are also some advantages to a blockchain over a database:
  • The entire status of the system can be summarized in a single hash (latest blockchain hash)
  • Every full node in the system is synchronized with the rest of the network and will reach consistency with it
  • Every transaction is authorized by a private key, meaning every action and actor can be held accountable
  • Every block can be similarly authorized by a known entity / private key, meaning that any "51% attacks" can be traced and punished externally
  • There is certainty for whether or not a transaction committed successfully to the blockchain and what is its outcome (especially if we're talking about more complex systems like Ripple or Ethereum)
While there might be little use for a blockchain technology if it's used by a single entity, it certainly bring up a lot of benefits if we're considering multiple parties using the blockchain technology to conduct business:
  • All transactions on the network can be legally binding as per agreement (especially if we're talking about making business decisions using smart contracts or tracking debt using a Ripple-like ledger)
  • There is no confusion as to the current state of the network - everyone will be on the same page once fully synchronized
  • Given the block creators are trusted entities (in a model similar to BitShares or Eris), or everyone using the network is also a block creator (in an ideal consensus mechanism), there is a strong disincentive to attack the network through a 51%-esque attack (block creators can be legally liable for doing such a thing)
  • Audits of the network are unambiguous, since all transactions are public (provided the auditor has access to the full blockchain)

Centralized versus decentralized blockchains


While centralized blockchains have their uses, there are certainly some advantages to using a decentralized blockchain (Bitcoin or otherwise).

First of all, anything that happens on a large, decentralized blockchain such as Bitcoin can be verified to have happened at the given time. Centralized blockchains can be re-written or forged if all the involved parties collude, while a decentralized blockchain is much harder to corrupt. This is why we see companies like Factom using the Bitcoin blockchain for timestamping - the record is public and provably immutable. Any private blockchain wishing to prove their records were not altered would similarly have to use the Bitcoin blockchain and embed the block hashes into it to prove the data was not altered later down the line.

Secondly, it may be much easier for multiple companies to agree to use a decentralized network as a middleware, rather than them agreeing to use a proprietary blockchain. This is especially true if we would be talking about companies dealing with entities they don't know or don't trust. Using a decentralized network allows you to tap into its network effect - you're not only connected to a few parties, but to potentially everyone in the world.

Conclusions


All in all, there are advantages and disadvantages to both using centralized and decentralized blockchains. Every one of them is a tool of its own, and some might be more suitable for problems than others. While the Bitcoin network certainly has a lot of value on its own, it's not a silver bullet solution to all problems and use cases. Blockchain without Bitcoin is certainly possible, but even in the world filled with centralized blockchains, Bitcoin has a place of its own.

Wednesday, June 10, 2015

Handling bitcoins during a hard fork - pondering Bitcoin XT

Handling bitcoins during a hard fork - pondering Bitcoin XT

As everyone might've heard by now, there is a big debate in the Bitcoin community about whether or not we should increase the block size limit. Some core devs are pushing for the size increase with the Bitcoin XT version, and it looks like some people might be committed to the hard fork even if the community would be against it. This can be a potentially dangerous move that fragments the Bitcoin world to those that use Bitcoin QT and those that use Bitcoin XT. If this was to happen and both of the versions were to coexist, there is a lot more than just confusion to be had for anyone that holds funds on behalf of their customers.

Hard fork and the transactions


Initially, when the hard fork happens, all transactions will be interchangeable between the two blockchains - after all, they will be spending the same outputs using the same algorithms. You could broadcast the same transaction to both blockchains and they will be able to get into the blocks just fine. However, this also means that any withdrawal from shared wallet, like from an exchange or CoinBase, may siphon the funds out of both chains even if the service is using only one chain. If a service was to ever switch over to the other chain, their balances might be out of order.

Over time, the networks will start drifting apart. Any transaction that spends the coinbase transaction of a block minted post-fork won't be copyable to the other chain. Similarly, any conflicting transactions will only be valid on one chain.

Since Bitcoin network currently has a lot of unspent outputs (such as the ones tied in physical bitcoins), we will probably see transactions valid on both chains for years to come.

Confusion about addresses


After the fork happens, there can be a lot of confusion as to what network everyone is on. If the address structure remains identical, someone asking you "to send 1BTC to 1PiachuEVn6sh52Ez7o6Fymvw54qvQ4RBm" might be confused when you send that amount of money to the listed address, but on a different network.

Maybe the devs behind BitcoinXT will take some precautions to prevent such mistakes by altering the Base58 alphabet in a similar fashion to Ripple (yes, Ripple addresses are identical to Bitcoin with the difference of the final Base58 alphabet used). Perhaps BitcoinXT addresses would start with an X instead of 1 without changing the underlying mathematics behind address creation or net bytes?

Recommendations for exchanges and other services


Even if one side of the fork will be more likely to stick around than the other, it is still useful to be prepared to exist on both sides of the fork. My recommendation for any exchange or service relying on a shared wallet is to make a backup of all user balances on the day the fork occurs. Since those Bitcoin balances would be valid on both chains, if the service was to support both sides of the fork, users should receive the same balance in BitcoinQT and BitcoinXT.

After that, both the hot and cold wallet balances should be spent on both chains in a conflicting fashion (send all funds to A on BitcoinQT, and all funds to B on BitcoinXT). After both transactions are confirmed on the separate forks, there will be no chance of the same transaction being copied between the chains. The balance of whichever chain is not used should be safely stored for the time being along with the backup of user balances.

If an exchange was to support both of the chains, supporting them straight away would create the least amount of confusion. Users should receive the same balance on BitcoinXT as they currently have on BitcoinQT, with their fiat balance remaining intact. Afterwards, the users would be free to trade both coins like they would be separate altcoins.

Conclusions


A Bitcoin hard fork might be coming. Exchanges and hosted wallets should have a plan of action if both chains were to co-exist.