Monday, February 29, 2016

An Ethical AdBlocker - a Bitcoin killer app?

An Ethical AdBlocker - a Bitcoin killer app?

Ads suck. TV ads suck, internet ads suck, pretty much all ads suck (well, perhaps except for some Super Bowl ads and a few rare gems). Moreover, ads don't work as well as they used to, so they have to get more aggressive. We hate ads, so we create software to block ads, and the software creators then charge a toll to let companies display us ads anyway.

A lot of content creators need ads to support their work, they appeal to their viewers not to use adblocks, and some websites make half-assed attempts at getting us to pay instead of viewing ads.

If you don't use adblocker, your viewing experience on most sites is abysmal, and the loading times, especially on mobile, are abysmal. If you use adblock, you feel bad for not supporting the content creators. Perhaps instead you decide to use "ethical adblocks" and only view websites that are not ad supported?

All in all, the current ad industry is a struggle between ad creators that want you to see their ads, content creators that don't want to show you the ads but have to to earn a living, and the viewers that don't want to watch the ads but still want to support the content creators.

Perhaps there is a way to support the content creators AND not have to rely on ads? There have been many approaches to this in the past, so lets see what we can learn from them and what can be improved...

Tip-based support


One of the first ideas that come to mind when one thinks how to support a creator is tipping. The idea is not new - companies like Flattr have been around for many years.

The problem with tipping, is that quite often you have to set a tipping jar up first and hope your users will be using the same platform. Without critical mass, you don't have much. This seemed to be the reason Flattr failed - it hasn't reached a critical mass, so it fizzled out mostly.

A better idea came around with BitcoinTip and later ChangeTip - tipping solutions where you could tip anyone, even if they haven't set up an account with the company. Combining that with being able to tip anyone on various social websites like Reddit, Twitter, Twitch, etc. Now suddenly you were able to even tip famous people, such as Garry Kasparov, and know they would receive their bits.

However, tip-based support also has a downside - you can't make a predictable living with them. They are by their very nature a flash in the pan. Moreover, just like upvotes on Reddit, short, witty jokes and memes might get content creators more tips / upvotes than large submissions of substance. We need something better that encourages creation of "wholesome" content, not just pictures of cats.

Patronage


An alternative to tip-based support is patronage, made especially easy through such platforms as Patreon or SatoshiVote. This form of support is suitable for a much broader set of work - from hobbyist book reviews up to high-quality educational videos.

This models fosters consistently high-quality work. Creators get paid more the more people enjoy their work on a regular basis. One-hit wonders don't translate directly into money as it would with ads on a highly-popular video, but the extra exposure can translate into a bigger stream of money down the line.

While this model is good for continuous series, it might not be ideal for infrequent releases that get a lot of views over time (say, the song "Friday" by Rebecca Black is getting a good amount of searches every week on Friday), or frequent but very minor releases (such as most of the top contributors to Reddit).

Subscription model


Similar to the patronage model, in the subscription model every user pays a certain amount per month to view a website (usually, but not always ad-free). While this model can work pretty well if the user consumes a lot of content from the same website, it doesn't work well if someone visits a page only a few times per month. Since one can only pay for so many subscriptions per month, it tends to promote only the biggest, most established content hosts (similarly to subscription-based MMOs being replaced by free-to-play ones).

A tipping adblocker


A possible solution to most of those problems could be a combination of a few of the above technologies.

The starting point for the solution would be an ad blocker - not necessarily designed to sell your data nor to take bribes to get ads through, but focusing on being the best ad blocker out there - no compromises, user experience comes first.

From there, the software would start tracking which pages its users visit and for how long. All of the time would be divided based on the content consumed - length of the video watched, which submissions on Reddit were upvoted, etc.

Once the data is aggregated, the users would be able to donate a certain amount of money per month. Like on Flattr, the donations would be divided up between the content consumed, but without the extra hassle of having to click on special buttons and so on. Some portion of the money could go to the company maintaining the whole software product.

The content creators would receive the aggregated donations of everyone from the system. If they provide a Bitcoin address - the money can be sent automatically. For websites that support it, the money could be deposited to user's account like through ChangeTip. Other websites could embed payment details directly into the html code, which can be easily scoured like ProTip appears to be doing. If a website doesn't have a payment setup yet, the donations could be stored for the time being. Websites hosting content could divide the revenue up - YouTube could get a cut of the tip, while the video creator could get the rest.

Everything could be optimized through some Interledger-like cross-currency payment protocols if someone doesn't like Bitcoin. Users could also add weight to various sites they are tipping - perhaps prioritizing blog posts over Reddit and so on.

All in all, this setup would improve the user experience by eliminating ads, replacing the revenue stream content creators and hosts lose from the removed ads by essentially donate-per-view (which could be more than a few cents an active user is generating per month). This means a user doesn't have to commit to a subscription if they don't visit a site frequently, they reward the content creator whenever they view the media, not "once-per-video" like Patreon would, and adding an extra tip every now and then would be seamlessly integrated into software (since it already tips everyone anyway, might as well make it easy to tip a bit extra).

Conclusions


Nobody wants to watch ads, thus adblockers are popular. If the adblockers would incorporate some universal tipping solution to replace the revenue stream from ads to support the content creators, it could be a win for both the creators and the users (although not so much for companies that need to advertise). Bitcoin could allow for anyone to receive tips, but different payment solutions could be introduced as well.

Tuesday, February 16, 2016

Breaking dollar's fungibility

Breaking dollar's fungibility

In the modern world we rarely make a distinction between the money in our banks, the currency in our pocket, or our balance in a digital wallet like PayPal - a dollar is a dollar, pretty much fungible. However, that's not really the case - money deposited in a bank means the bank owes that money to you (it's not "your cash"), digital wallets also own your money and can easily freeze your balance. Transferring money from one bank to another is always done at par, even if that bank in question might be Lehman Brothers about to go down back in 2008. Perhaps it is time we break the dollar's fungibility and start putting a price tag on the credibility of banks?

Private notes


Over 150 years ago in the "free banking era", any bank could issue its own banknotes. You would see a number of different notes in circulation - you could have $2 from The Bank of Chattanooga, The County of Polk, or The Lawrenceburg Bank of Tennesee. Same in Canada. While it created a lot of hassle for anyone wanting to use the currency, especially if they would travel beyond where those notes would be redeemable, it also allowed for a market to form and put a real value on the currency based on how credible the issuing bank was - good notes would be valued at par, bad ones - at a discount.

While banking nowadays is certainly simpler and safer with uniform currency issued by one entity per country, FDIC deposit insurance to prevent people losing money in case a bank goes bust, etc. However, this means we also lost the ability to evaluate bank's trustworthiness, usability, etc. and arbitrage it.

Bank arbitrage


In the Bitcoin world, it is fairly straightforward to judge the health of an exchange by looking at its exchange rate. Back when MtGox was going bust, its rates deviated from its competitors by 15+% even early on. When withdrawals out of the exchange became impossible, there was even a secondary market that traded MtGox BTC for real BTC by using MtGox's inter-account transfer capabilities. You can track arbitrage metrics today.

How would this apply to banks? Well, you could start with the currency issued by the government as the base - one dollar here would be redeemable to one dollar in banknotes (this is what MintChip aimed to do for example). Banks would use that as their reserves for fractional-reserve banking and issue their own debt-based currency. All of it could be tracked on a shared "bankchain" to allow market for various bank debt to form. The price difference of the debt could stem from various factors - how stable the bank is (FDIC insurance is all well and good, but nobody wants to go through the stress of having your saving locked up for who knows how long), how cheap and easy it is to transact to and from a bank (say, USD-demoniated bank account in Europe might be valued less due to the extra cost of transferring money overseas), how accessible is the bank (branch opening hours and how common they are), as well as how their customers share the banks values (banking for millennials, sharia-compliant finance, etc.).

Setting up such simple metric for each bank would allow anyone to easily compare various banks and put that metric on everyone's mind. If one day your money would go down to 95 cents on the dollar, perhaps you would ask your bank "what is going on?" and find out that HSBC enabled Mexican drug cartels to launder money. Maybe it would enable some people to demand all of their deposits to be covered 100% by the government-issued currency, rather than allow for fractional reserve banking? Or perhaps it would allow some people to move their money to their local credit union to support the grassroot company and earn 1-2% on the conversion rate.

Conclusions


Banking in the modern world is pretty homogeneous - currency dictated by the government, fungible money no matter where you go. Perhaps it might be useful to bring the market back into the equation and allow us to see see the bank's worth by checking the value of their dollars?


Related links:


Monday, February 8, 2016

The Dark Wiki

The Dark Wiki

This blog post is inspired by some "what if" videos made by Tom Scott, in which he explores a theoretical futures when Google forgot to check passwords, the dystopian view of the singularity ruined by lawyers or what happens when privacy dies. Here is my take on what might be built in the future on top of the existing blockchain technology.

Any names or examples used in this story are meant for purely illustrative purposes only and are not meant to condone or condemn any actions, companies, governments, technologies or the like.

----

Knowledge is power, and a lot of money can buy you a lot of information...

The years is 2025, there are almost 20 million bitcoins in circulation and they are valued at $5'000 per coin. While not as fast a growth as many would've predicted, it still puts Bitcoin as the world's 8th biggest currency in circulation, ahead of Canada's dollar, but behind the United Kingdom's pound. For all intents and purposes, Bitcoin and crypto have succeeded - they are used by a lot of people in all walks of life.

The biggest story of the year's first quarter turned out to be the busting of a US-based criminal organization creating superbills - high quality replicas of the "counterfeit-proof" polymer banknotes. What stood out about those bills is not that they were good, but that they were perfect replicas of the banknotes, down to the microprint, security ribbons and the colorshifting ink.

While not an unheard of story (North Korea is said to have done something similar in the past), over the following days of media attention a surprising finding has caught everyone's attention - the criminals got all of the information they needed to make the superbills from "The Dark Wiki" - a Wikipedia-like website residing on the Dark Web, created with the sole purpose of "cataloguing the world's forbidden knowledge".

The Dark Wiki contained detailed articles on many subjects that would land anyone in jail - recipes for narcotics, 3D printer files for military-grade weapons, interrogation manuals from a number of international agencies, copies of standard keys used in "back doors", the complete smallpox genome, or "how-to's" on accessing military GPS signals or the aforementioned printing process of superbills, from 3D prints of various master hubs, etc.

The website was not only dealing with standard articles, but also featured a prominent section on "kickstarting" / requesting information, with the bounties anywhere between a few thousand dollars for creating some malicious scripts to break into some computers, through a few hundred thousand dollars for pharmaceutical recipes of some major drugs, up to a few million dollars for schematics of nuclear weapons.

While the website seemed to lack a single owner, there were a number of prominent "experts" on the website serving as third party escrows on a number of bounties to verify if the information delivered was accurate and precise. They also curated one of the more bizarre part of the website - a scientific journal on "the dark sciences".

While a number of traditional scientific papers have been written on criminals and their illegal activities (such as Steven Levitt and Sudhir Venkatesh studying the economics of crack dealing), the Dark Wiki's journal was focused more on scientific research that was itself illegal or borderline illegal - designer drugs, human cloning, synthetic organisms, or experimenting on humans and infants. While so far only the first category had any traction, going so far as having some research grants, the other categories were open for submissions.

With a little help from the Streisand effect, hundreds of millions of people have heard of the website and it became the most searched for topic of the moment. Among the wave of new users that came across the website for the first time then, was a disgruntled 30-something NSA software engineer. Stuck in a dead-end job working on some machination that would further make the agency's reputation worse if it ever was revealed.

What he saw in that website struck a chord with him. When he was a teenager, Wikileaks broke the news. In his early 20s, Snowden's revelations shook the world. This year, he would make both history, and a lot of money for himself.

A month later, the Dark Wiki broke into the news again. A high six-figure bounty was awarded for delivering the information required to access NSA backdoors embedded in billions of devices world-wide. That day would later be known as "the day the Internet broke". The massive-scale hacking that occurred with that information was an order of magnitude higher than the 2014 Heartbleed bug, and it brought down a number of key servers around the world for a few hours before some of the vulnerabilities could be patched and the Internet reconnected.

The following days the governments were dealing with a few major issues. First, any US-based manufacturer was distrusted overnight, with many world governments revving up production on their non-backdoored hardware. But due to the nature of how hardware is manufactured, it would take years for the industry to adjust.

Second major issue was figuring out who leaked the information. The bounty was paid in bitcoin, but since the 2019 halvening hard fork introduced confidential transactions to the network, it became impossible to figure out which address received the funds. An internal investigation was under way at various government agencies to see if some leads could be found...

Lastly, the Dark Wiki had to be shut down - it attracted too much unwanted attention and could cause global security concerns if it was used by large criminal organizations or corrupt governments. With some busy work and exploiting some weaknesses of the Tor network, the website was finally traced to a server sitting in some country with abundant legal loopholes and lax prosecution laws for hosting illegal content. However, the biggest surprise came when it turned out there were only two notable pieces of software on the server - a small wrapper serving the website's frontend and an Ethereum client...

As it turns out, the website was running as a smart contract on the Ethereum platform. All the required information and logic was stored in the distributed ledger, with payments being handled through a sidechain connection onto the Bitcoin network. Editing rights were only given to users that created a high enough proof-of-burn pledges (by donating the coins to the contract itself) and the little governance there was was mostly handled through anonymous users building their reputation by contributing to the website and being recognized by the community. Anonymous donations from people benefiting from the wiki as well as the pledges and other fees allowed for the contract to become a self-sustaining DAO.

After the website was shut down, multiple other mirrors cropped up along with the source code required to access the data locally. Attempts to shut the network down only strengthen it due to the antifragile nature of crypto.

On the 10th anniversary of its genesis block creation Ethereum was no longer seen as a quirky distributed state machine, but as an avatar of unstoppable quest for knowledge in all of its forms paired with the cold machinations of cryptographically untouchable capitalism.

If the Dark Wiki has taught us anything in its following years of operations is that security through obscurity is a joke and that we can't rely on any secrets to keep us safe. In the end, backdoors had to be closed, strong cryptography became the default and the attitude towards cryptocurrencies has changed. Just like you cannot kill an idea, neither can you stop a decentralized network or currency.

----

What I have described above could be implemented today, at least technology-wise. It would probably still take some time before the technology becomes popular enough for people to start using it as described, but we have some kernels of that already in the form of the assassination market or the now-defunct Silk Road. In due time perhaps we would see some dark web information market develop and turn into some wiki for people to use. Pair cryptocurrencies with the sort of money drug lords or a small government can amass and you might have to be keeping a closer eye on disgruntled or low-paid employees with access to secret information...

I used Ethereum as an example of a platform to host the Dark Wiki, but the same project could be hosten on any platform that supports smart contracts. Please don't read it as condemnation of Ethereum either - I see it as one of the more innovative crypto projects and see it being useful for a number of good projects in the near and far future.

Monday, January 25, 2016

Cryptocurrencies as protection from the government

Cryptocurrencies as protection from the government

Recently, International Monetary Fund released a report on Virtual Currencies. Overall, it's not a bad report - it discusses whether virtual currencies such as Bitcoin should be considered money, what the regulatory approach should be and what are some of the challenges related to dealing with cryptocurrencies. It has its share of misconceptions (for example: "VC schemes are difficult to monitor. Their opaque nature makes it difficult to gather information, including statistical data, or to monitor their operation." - yeah, no, that's the current banking system you are describing there), and overall it paints a cautionary picture of virtual currencies. However, I think the report is missing one important feature of cryptocurrencies that a lot of people might find interesting - they are a protection from the government. Let me explain what I mean...

Government power over money


When you stop and think about it, a lot of governments have nearly orwellian power over money. The monetary policy is not something that is often discussed by a lot of people, and often we are not equipped with the vocabulary to talk about it (like trying to form complex thoughts in newspeak). They get to decide whether savers or borrowers have it easier by controlling the rate of inflation. They get to determine how much your labour is worth by engaging in currency wars and a "beggar thy neighbour" race to devalue its currency the most. Then we have the incompetent governments that let their currency devalue in hyperinflation like Venezuela (reaching about 100+% in 2015). The fiscal and monetary policies are thrust upon us.

In short, the governments can effect our savings, future income, as well as many other factors just by controlling how money is created and spent.

Lack of trust in the government


For those and other reasons, some people resort to moving away from the government-issued currencies and adopt new forms of payments. Whether they take the form of local currencies, gold or something else, they can be an expression of lack of trust in the government.

However, there are limitations to a lot of those currencies in the modern world. Local currencies are often low-tech and they are not usable globally. Physical currencies can be seized by force (like in 1933 in USA, by the Executive Order 6102).

At the moment it would appear that only native cryptocurrencies such as Bitcoin can be a viable protection from the government in the modern world.

Protection from the government


While some people would jump to thinking that "protection from the government" necessarily means breaking the rule of law and engaging in illegal activities, that's not what I'm talking about here. What I'm discussing is withdrawing at least partially from the fiat-fuelled economy and moving into the cryptocurrency economy. One can and should still pay taxes, obey the law and so on, but that doesn't mean one has to keep one's wealth in the potential house of cards that various banks and government currencies are (look no further than the 2013 Cyprus crisis and the related bank bail-ins).

I am a saver, not a borrower. I wish for my money to at least keep its value, or be worth more. I want my wage to be stable no matter which government I work under. I don't want the currency I use to be created as debt by the banks, or even let the banks take any part in the money creation process. As such, I know of no fiat currency in the world today that satisfies my preferences, hence why I choose Bitcoin over fiat.

Conclusions


Native cryptocurrencies like Bitcoin offer a way for people to de-leverage the power governments hold over the currency and shape a new economy for themselves.

The IMF and similar organizations need to understand that asking "should the government regulate cryptocurrencies?" might be less important than "if cryptos will succeed, why would anyone continue to use fiat?". Probably for the first time ever, fiat currencies have a worthy competitor in the global Internet economy. They can either focus on becoming the best currencies they can be to compete (akin to Steam trumping free torrents), or go the way of the Kodak.

Related topics:

Sunday, January 17, 2016

Stanford University and its native advertising of 21.co

About two weeks ago there was a post on /r/Bitcoin advertising a new course on Bitcoin Engineering from Stanford University. It sounded good enough - there is a lot one can develop with Bitcoin and teaching it at a university would be a perfect way for new people to get exposed into Bitcoin. However, reading some of the topics to be covered, such as "Bitcoin Dropbox" or "Bitcoin WordPress", made me think of some company I covered before on this blog. Reading further down, yup, one of the instructors for the course was Balaji Srinivasan, the CEO of 21.co. "Oh boy!" I thought, "I wonder how much of this course will focus on using the 21 Computer rather than pure Bitcoin...". Today I came back to the website and I got my answer...

It's not often that I get to write multiple pieces on this blog that fit together into a neat narrative, but it seems that 21.co will have the privilege (previous entries - 1, 2).

Course content so far


At the moment, it looks like the course is two weeks in and we have 3 out of 12 rows of documents available publicly:


While it is possible the course becomes more generalized in the future, I have my doubts.

Reading the entire course page, we can see the course is about "Bitcoin and Bitcoin-enabled computing", where the students will be "build[ing] Bitcoin-powered versions of several popular Internet services". No mention of "Bitcoin Computer" or "21 Bitcoin Computer", so one would think you would be building something with perhaps Bitcoin Core, or some other open APIs...



"Pick up your 21 Bitcoin Computer up front". Makes me REALLY excited for the possible upcoming MOOC version of the course (signup form available). Thanks Balaji.

Lab 1, instructions on setting up 21 Bitcoin Computer, followed by some okay explanation of what Bitcoin is, basics of how it works, etc. This is then followed by some hands-on exploration of data in Bitcoin on the 21 Computer, explanation of what mining is and "How to rapidly mine bitcoin with a Bitcoin Computer" (after all, "The 21 Bitcoin Computer includes a fast and convenient way to get bitcoin for programming purposes" - who needs TestNet, right?). After that we learn about the all important "21.co balance and your blockchain balance"...

Guys, there is a reason mining is downplayed in most introductions to Bitcoin (including the version 2 of the famous "What is Bitcoin?" video) - it is a specialized industry doing some of the most boring things around Bitcoin. A vast majority of Bitcoin businesses never touch it, nor care about it. Sure, by all means, explain how it works and what it is, but devoting 11+ out of 54 pages to it in the first lab is an overkill. TestNet exists for a reason - you can get some coins to play around for free and its way less complicated.

After that, we get a document on "Remotely login to your Bitcoin Computer" (I think what you meant  to say was "Remotely logging into"). As expected, more 21 Computer. Finally, we get some document to schedule 'Genius Bar' appointments (Apple much?).

Upwards and onwards to week 1. We get out Lab 0, which is the course overview, how to set up 21 Computer (with a special slide on how to "Mount the 21 hard-drive as a volume on your Mac"...). Not much else to see here.

It looks like the first proper presentation for this course is "Bitcoin: An Overview", which does a decent job explaining what is Bitcoin about, a number of things surrounding Bitcoin. It looks like a decent presentation without plugging 21 Computer too much. I guess that might be because a good chunk of it was presented by Belaji back in May last year at Sunnyvale's Bitcoin Job Fair when 21.co was still in semi-secrecy mode...

After that, we get linked to Lab 1 again, and we also see the first Self Test, including such important questions as:
  • "When you ran `21 status` to create your wallet and 21 account, what username did you select? (If you don't remember, you can run the following command at any time: 21 status)"
  • "How many satoshis do you get each time you run 21 mine? (If you don't remember, run the command again.)"
  • "Fill in your Stanford email and run the following command (if you get an error about your balance, run `21 mine` and try again): 21 buy sms +14084383755 'YOUR_EMAIL@stanford.edu'"
    • For which the only thing to check is " I sent the SMS message using the 21 CLI"

We're now at week two. Lab 2 - after a brief introduction to "Bitcoin Computing", we get a few step process of how to mine some bitcoins, buy and sell digital goods for bitcoin, and learn how to work with the bitcoin library (of course, all with the use of the 21 Computer). [Side note - we get have both the uppercase and lowercase "bitcoin" used to refer to the currency ("buy digital goods with bitcoin", "sell digital goods for Bitcoin") - keep it consistent, please.] Afterwards, we get some example of how to use the 21.co's library on how to develop some software-as-a-service.

After Lab 2, we get our Self Test 2, with the important questions of:
  • "Which of these is the main advantage of using off-chain transactions?"
    • After all, this wouldn't be a course on Bitcoin if we didn't focus on transactions happening outside of the Bitcoin network...
  • "What API calls can be outsourced using micropayments?"
    • With the answers being "Any remote API call", "Only calls that have a high per-use cost", "Only calls that depend on complicated technology, like Google Maps", "Only calls that use cloud services" and "Only calls that require registering for an API key before using"
    • None of the answers are particularly correct, and the question itself doesn't make sense - outsourcing API calls in the context of software development would be more focused on putting the API calling logic in some separate library, rather than as an external product...
  • "After you joined the market with "21 join", what was your IP address for the zt0 interface? (Instructions to get this are in the lab 2 document.)"
  • "Were you able to get someone on the Slack channel to buy your endpoint?"

And that would be it when it comes to what is available for public viewing so far.

Course critique


As someone who has written a Master Thesis on Bitcoin almost 4 years ago, I have mixed feelings about the course. My major gripe is that the course looks like some HEAVY native advertising in disguise. The course website makes you believe you would be working with Bitcoin, but in reality, you are working with 21 Computer and their proprietary libraries. This would be like wanting to take a course on the C programming language, but ending up with a course being on developing Windows Phone apps in ASP.NET as presented by Steve Ballmer. Sure, you would learn some similar fundamentals, but one would be a good basis for learning other C-based languages, a staple in the current industry, while the other would make you a Windows Phone app developer - not something many people aspire to really.

Similarly, since the course requires heavy use of the proprietary $400 device, I doubt many students not physically present at the university would be able to participate. If 21 decided to release some "student version" of their software that can be used on any device - it wouldn't be a problem, but I somehow doubt that would be the case...

That being said, as I stated before, the software itself seems to be quite feature-rich and the examples presented with the lecture wouldn't probably be possible to implement in a short time frame without them. Speaking from experience, one week is about enough to implement a web wallet from scratch if you're using Bitcoin Core for the first time - hardly as impressive as digital content delivery.

The strong emphasis put on mining and the use of off-chain transactions is a bit misleading if you want to learn about programming on Bitcoin. It is yet again 21 pushing its narrative of having mining available on every device and all of them being connected to their proprietary mining pool / shared wallet. It isn't representative of how Bitcoin works in its core, although it may be used as a good example perhaps later down the line of some alternative ways of handling bitcoins.

Lastly, when we're considering that two weeks of this 11 week course are focused on small hackathons, where the "Best projects get written up in Bitcoin Magazine" (from Lab 0), one might start to think that this whole lab exists not for the students to learn about Bitcoin, but for 21.co to get exposure, teach a number of students how to be completely reliant on its software for anything Bitcoin-ralated and possibly get some ideas / examples of what can be built with their hardware and software.

Conclusions


The Stanford Bitcoin Engineering course is a series of labs and lectures on how to use the 21 Computer, as presented by the CEO of 21.co. The majority of learning materials so far are reliant on proprietary software and hardware making it useless for anyone without the device. 

All in all, if the instructors of the course were more up-front about what they are trying to teach in this course I probably wouldn't be bothered by this so much, but as it stands, I can see it as nothing more than Stanford doing some native advertising of 21.co. I'm sure any student that essentially paid $1k+ to take the course will be grateful...

Monday, January 11, 2016

Full Proof of Solvency - pondering Tether

Full Proof of Solvency - pondering Tether

Tether (currently in beta) is a fiat gateway allowing its users to transact in USD IOUs on Omni and internally in Tether's shared wallet. One of the core features the platform advertises is its 100% backing of the issued assets, coupled with frequent solvency reports. This used to be a big issue in the Bitcoin world a few years back, when MtGox, once biggest Bitcoin exchange in the world, became insolvent and shut down. After that incident, a few exchanges (1, 2, 3) started looking into creating proof of solvency to bolster consumer confidence in their platforms. Today I would like to talk about what constitutes a full proof of solvency, how Tether approaches it in a multi-platform system, as well as some potential pitfalls one might face while designing proof of solvency.

Proof of Solvency


A quick recap of what is a Proof of Solvency. In simple terms, its a way for exchanges and other companies holding their customer funds to prove their liabilities to their customers never exceed their cash and crypto reserves. It stands in stark contrast to fractional reserve banking, where by definition, there isn't enough cash or precious metals to cover all of the outstanding deposits. Historically, this is an important concept for Bitcoin - the Genesis Block created by Satoshi quotes a newspaper headline talking about a bank bailout.

Since we're dealing with cryptocurrencies, the modus operandi is always "trust but verify" - claiming that you have a certain amount of money but not having a strong, verifiable and falsifiable proof usually raises red flags.

Proof of Solvency can be broken down into two parts - Proof of Liabilities, wherein the company proves how much they owe their customers, and Proof of Reserves, where they prove how much liquid fiat and crypto they have to cover those deposits.

Proof of Reserves


Proof of Reserves is usually quite tricky for the Bitcoin exchanges as it often involves interacting with "the old financial world" - banks and their banking system. To prove they are solvent, an exchange would publish statements from their banks indicating how much money they have in a segregated account. As banks usually don't focus on creating cryptographically authenticated documents or balances, this is usually the hardest part of the proof to verify outside of a full audit.

However, when we get into the cryptographic world, things get a lot easier. An exchange needs only to state which addresses they own, what is their current balance, and sign the message with those stated addresses. This proves they have access to those addresses, and anyone can go onto the blockchain and verify how much money is really in them at all times.

The last part can also be very important - being able to verify the reserve balance at all times, or at least very frequently, is a lot more reassuring than one-off statements. After all, one could borrow the money for a day to create the proof, therefore misleading everyone.

In the Bitcoin world, one might try to similarly falsify the reserves by asking someone else with deep pockets to sign the proof of reserves statements, creating a false belief that those coins form the reserves. However, this problem can be mitigated with Voting Pools.

All in all, Proof of Reserves is fairly straightforward, at least when it comes to cryptocurrencies. Banks still need to catch up.

Proof of Liabilities


Proof of Liabilities can be tricky for the Bitcoin companies as it often touches on their customer records and databases.

If we're dealing with cryptographic IOUs, things are fairly simple - one only needs to point to the issuing address, count the total number of outstanding liabilities, and sign the statement. Anyone can verify it in real time, just like in the Proof of Reserves for cryptocurrencies.

When it comes to shared wallets and private databases, as is usually the case for many exchanges, the things get a bit more complicated. The companies usually don't want to reveal the balances of every individual account, and the dumps could get quite sizeable (back in 2011, MtGox's database leak was said to contain 61'016 user accounts).

There are a few ways of compressing the data, but the most popular one appears to be creating a merkle tree consisting of account IDs and balances. A single account-balance pair would be a tree leaf. One would then combine the two balances together and pair that with a hash combination of the IDs to form a node higher up the tree. This would continue until we would get one hash and one balance at the very end.

This merkle tree would be hard to fully verify without access to the full account list, but it would also be combined with another interesting trick - every user would be able to request an SPV-like balance branch connecting their account to the merkle root of the tree. If the exchange would fail to provide the branch, the balances would not add up, there would be some negative balances or the branch would not match the latest published root - one would have a cryptographic evidence of foul-play. Now if we only had something like this for the banks...

All in all, Proof of Liabilities is a bit harder than Proof of Reserves, unless we're dealing with pure cryptos once more. Combined with Proof of Reserves, we create a Full Proof of Solvency - the company in question is completely liquid, at least for the time being. Now, lets take a look at how Tether does this...

Tether


A good chunk of this discussion is based on a few conversations I had with the company last year. Since the product is in beta and some time has passed since I spoke with them last, this description might not be indicative of the final product if and when it launches. I bring this example up mainly because it raises some insights into a few important design choices for gateway design.

Tether at the moment is a gateway focused on issuing USD-backed IOUs. Those IOUs can be transferred both on the Omni network, as well as from inside of the Tether shared wallet. In the future, it would be possible to see Tether issuing similar assets on other Crypto 2.0 networks, such as Ripple or Ethereum.

We can see their outstanding balances on their transparency page. Here we come to the first design question - what does this number represent? Is it the balance on Omni, in the shared wallet, a sum of both or something else?

In case of Tether, the number corresponds to the assets issued on Omni. Their shared wallet balance is then a subset of that amount, and as I understand, balances on any other network like Ethereum would also have their own separate balances on the Omni network.

Since we're dealing with multiple networks, the Full Proof of Solvency would be dependent on all of them. In case of Tether, we would start with Proof of Reserves to figure out how much the company has in deposits. The number would be compared with Proof of Liabilities from the Omni network. If that passes, our job is still not done. Now we would use the Omni balance of the shared wallet as a PoR to compare against the PoL of that wallet, and use similar methods for any other connected networks.

The Proofs are valid top-down. If any part is invalid, anything relying on those Proofs are also invalid (which might be more relevant for bigger constructs, like exchanges relying on Tether).

Another interesting issue to consider would be the transaction lag when moving between the different networks. As Tether's top-level settlement network is Omni, which in turn is sitting on Bitcoin, the transactions that move assets between network would have to go over one of the slowest cryptocurrency network (at least in comparison to things like Ethereum or Ripple), which might not be ideal. Since Tether as a company already needs to provide Proofs for all of the network as well as its own wallet, it would make the most sense to make the fastest element be the top level, which in this case would be the wallet.

Conclusions


Full Proof of Solvency is an interesting concept that came out of the Bitcoin world in reaction to shoddy business practices of using fractional reserves at an exchange. It can be tricky to implement when dealing with non-cryptocurrency systems, but becomes trivial on publicly auditable blockchains. It would be interesting to see something similar implemented in a traditional bank...

Monday, January 4, 2016

Positive and negative proofs in blockchain audits

Positive and negative proofs in blockchain audits

As the old logical fallacy goes - you can't prove a negative, and absence of evidence is not evidence of absence. While for a long time this might've been true in various financial audits - you could only prove that some invoice existed, not that there were no invoices you missed - thanks to the blockchain technology things might change in the near future.

Positive vs negative proof


In general, we use positive proofs a lot in our everyday lives and in business. To create a positive proof, we only need to show that something exist - show an invoice of a transaction, a recording of a conversation, etc. Even in the Bitcoin Genesis Block Satoshi used a positive proof - a quote from The Times to prove that the Block could not have been created before 2009-01-03.

Negative proofs, while applicable in mathematics and some other cases, are often used in logical fallacies. If your goal is to prove for example, that there are no mice in the attic. You can easily disprove that theory with a positive proof if you find a single mouse there. However, searching the attic and not finding anything only proved that you have no evidence there are mice there, not that you had a proof there were no mice there. A subtle, but important difference.

Proofs on the blockchain


As in most cases, it is easy to create a positive proof on a blockchain. Point to a transaction paying for a particular invoice, if it is included in a block with 6+ confirmations, it's all you need.

Now, what if instead we are being audited and we have to produce an exhaustive list of all transactions we sent and received? It is possible, but we would have to do some preparations beforehand.

Cryptographic audit on the blockchain


First of all, we need to establish some way of uniquely declaring some data, saying "I am X and this is a message coming from me: ...". If we had something like government-issued unique digital signatures, that would be good enough. Alternatively, we could rely on some less infallible methods - notarized letters, tweets from some official handles, posting information on our website for everyone to see, perhaps sending the information to our competitors (if we try to lie about something, they would benefit from calling us out). Once we can prove that we as the person or a corporation were the authors of any given message, we can use cryptographic digests to prove any piece of data is coming from us, and coupled with embedding messages into the Bitcoin blockchain for timestamping (directly, or through Factom for example), we can create tight time bounds on when the data was created.

Why do we need all of this? Well, depending on how we use the blockchain, we will need to be able to create timestamped commits / anchors that we have to prove came from us.

If we only use one address on a public blockchain for all of our transactions, we have to commit to that address early on through the above scheme - "I am X, and I will be using the address 1PiachuEVn6sh52Ez7o6Fymvw54qvQ4RBm".

If we use multiple addresses on a public blockchain, it would be best if all of those addresses were derived from a single address in some predictable fashion. For example, we could use split-key address generation, multiplying the base private key by a sequential list of integers. This way, we can easily disclose the public key of the seed and allow any auditor to derive all of the other public keys, while still keeping our private keys safe. This way we only need to declare one address early on to create a full proof for the audit.

If the blockchain we are using is private, whether it is used only by us internally or by multiple parties, it would need to be anchored into the Bitcoin blockchain periodically to prove it wasn't altered in any way (Factom does this for example). Once we have that, we would also need a complete copy of the blockchain (or at least the relevant slice between two anchors) as part of the audit. If it is our internal blockchain, it would be analysed in whole, if it is shared - we would need to indicate which parts we used just like in the public blockchain scenarios.

Having gone through all of that effort, we can finally create our final data compilation for our audit, consisting of:

  • The entire block history in the slice of time we are analysing (say, all of 2010)
  • Whatever else is needed to prove the block history was unaltered. This can come in block header chain up to the newest Bitcoin block, simplified-payment-verification-esque branches of anchor transactions included in blocks, etc
  • Our original commits to the addresses we would use (if applicable), along with the necessary proofs that we committed to them at the appropriate time
  • Any relevant metadata we wish to submit (descriptions of which transaction was for what, etc.)


Finally, we would have not only a cryptographically verifiable proof that all of the transactions took place, but also have irrefutable proof of the time frame they took place in (we couldn't forge a few extra transactions from last year after the fact) and be able to prove that we didn't omit any piece of data - creating a negative proof.

The last one is possible because the records we are dealing with are cryptographically sealed (we can't alter the blockchain without invalidating its future, which would be evident), but also public and finite (we CAN iterate over every block and every transaction and check whether it is relevant to the audit or not). This way we not only provide every relevant transaction, but prove there are no relevant transactions we didn't provide.

Conclusions


Thanks to the advent of cryptography and blockchain technology with atomic, countable transactions, it is now possible to create an undeniable cryptographic provable complete audits. Hopefully this will help us avoid more audit fraud cases in the future...