I don't think so. What if my friend and I both create 2 accounts and both trust both of each other's accounts? We get twice as much money as everyone else who plays by the rules?
I don't think so. What if my friend and I both create 2 accounts and both trust both of each other's accounts? We get twice as much money as everyone else who plays by the rules?
However, since this is basically a currency based on web of trust, at a large scale you could probably dupe enough people into trusting your fake account. Or introduce both currencies into separate social networks. One here with the technical social circle, another with your in real life community, for instance.
Maybe I'm too cynical but I would expect the scammers to win.
I explained this more in this comment: https://news.ycombinator.com/item?id=15898504
For the latter, what I mean is that it’s probably prohibitively difficult to maintain two significant in-person social graphs that have no overlapping members. Sure, people can get away with it for things like romantic affairs, but the incentive there is very different than money exchange, not to mention that romantic affairs often get discovered.
(This is certainly not confidence that it wont work, just lack of confidence that it will, pending further reading/experimentation/analysis...)
(This is like the only response I seem to be contributing, no one seems to have read the full thing, so people keep asking questions like this that are answered by the source, so there is no interesting conversation).
You won't pay me with dpark-fake because I don't trust it, instead you'll pay me with pg because I've trusted him and he's trusted you.
However, this gets to the fundamental problem of the web of trust: It's really hard to do. Physical key signing parties are impractical to scale. You need systems like keybase which correlate your keys/accounts with each other if we aren't able to meet and communicate in person (which also requires trust, I wouldn't trust you after a single meeting, but would readily trust my friends who I know well but are physically remote from me).
Quoting from the paper:
This example demonstrates that Bob can only ever
receive money that he trusts, and Alice can only ever
spend money that other users trust in turn. Even if
Alice makes 100 fake accounts and has them all trust
each other, she will never be able to spend more than
the amount of AliceCoins she has, since that’s the only
account that other users will trust. This is why it is
crucial that users take direct peer-to-peer trust
relationships seriously.Eve won’t try to establish trust with Bob directly. She’ll establish trust with Bob’s grandmother who doesn’t know any better. She’ll essentially phish her way into the trust network. After convincing Grandma to accept a single EveCoin, Grandma will perform any currency exchange for Eve and let Eve buy whatever she wants with BobCoins.
When your premise is that “it is crucial that users take direct peer-to-peer trust relationships seriously”, you are doomed to fail. You cannot expect security to derive from the average person being extremely diligent.
And at the end of the day, it’s unclear why you wouldn’t want my FakeAccount coins. Once I’m in your web of trust, you can spend my coins like any other trusted currency.
The authors seem to believe it’s the users’ responsibility to somehow police this when the users in this case just want a medium of exchange and derive little to no value from excluding my fake coins.