I assume that what IBM did was centralizing mango grower info in a database instead having to go through complicated, manual processes. They did that through a Blockchain for some reason but I'm sure you could get similar result in some PostgreSQL DB. Of course I can't know for sure because the announcement is all fluff and hype and no substance.
The temper resistance is not god-given, it's a consequence of the miners racing to mine new blocks. If you want the same type of resistance for a custom blockchain then you need to convince a bunch of people to mine your chain. Why would I mine MangoCoin?
So instead immutability is achieved by making a "side-chain" that eventually links to a big and secure chain like Bitcoin or Ethereum. But then it's basically the equivalent of having a SQL database, computing a checksum every day and uploading it in a custom bitcoin transaction. Effectively you could achieve the same thing by computing the checksum, signing it with your PGP key and uploading it publicly on your website for all to see. This way anybody can make copies and if you attempt to modify an old entry in your DB it'll invalidate the checksum and anybody having a copy will be able to prove it.
So with this scheme your SQL database is immutable, verifiable and temper resistant. Unfortunately if you implement it that way your announcement won't make the rounds on social media and give you a lot of free PR and a boost to your stock, so better brand it "with real bits of revolutionary Blockchain(c)(tm) technology inside" instead.
>ie there’s nothing to hack
The Blockchain runs on computers, computers can be hacked. People can forge a bad transaction saying that some mangoes are organic when they're not. People can say mangoes have been stolen when in fact they've been sold to avoid paying taxes. The blockchain isn't harder to hack than any distributed database. The Blockchain isn't magic.
It's just not the same thing, completely different security profile.
The only way to forge transaction is to steal private key.
Nobody is saying that blockchain will force humans to not click "organic" checkbox for non-organic mangoes, this is absurd - but it can encode digital signature of somebody who checks it so it can be later traced back and allows to write logic that signature is required for the mango to go to the next step in the supply chain for example.
I think you don't realize (most people don't) how many problems this little thing solves.
It's not replacement for sql, big data or what not - it would be silly to say that - when designing blockchain systems you actually spend a lot of time on finding the most minimal thing that has to be stored on the chain for your contracts to enforce all required logic. It allows you to trust data in it without security ceremony/setup.
On the contrary. Let's say that you institute a blockchain to trace the chain of custody for evidence (not much different than tracing the chain of custody, cough supply chain cough, for mangoes). From the creation of a piece of evidence to transferring custody between different law enforcement officials, each block on the blockchain contains the private key signatures of law enforcement agents who have testified that they have taken custody of the evidence at a certain period of time. In theory, the benefit of a blockchain here is a publicly auditable record of custody which has clear value for the admissibility of evidence at public trial. Imagine that we wave away issues of latency for the sake of argument.
With cryptocurrency, actors are motivated not to share their private keys, because sharing their private key means risking irrevocably giving away all the currency in the wallet controlled by that key. What is the similar motivation here, for law enforcement agents not to share or otherwise compromise their private keys? If one cop tells another cop "hey I need you to do me a favor and sign custody of this evidence now while not actually taking it, so I can take it somewhere else and mess with it to make sure we can for sure put this guy away," or "hey do me a favor, I'm not going to sign custody on this now, but I'll do it later on" - what prevents this from happening?
Is it supposed to be the threat of perjury? Because the courts already have a problem with testimony which has been found to be false, where perjury cases are rarely subsequently prosecuted. Put it this way - just because something is auditable, who will audit it? And how do you police domain violations which are still valid blockchain transactions?
A blockchain where you have a publicly auditable, irrevocable record is meaningless if it doesn't really mean anything for blockchain actors to "act in their own interest". In this case, undermining the private keys is everything, because that's what undermines faith in the entire blockchain.
Police officer would issue a request to that 3rd party to sign this fact.
Blockchain doesn't magically make people honest, but it can encode claims that you can verify.
I think the point is, though, that you can trust someone to be honest whilst someone is watching them, but you can't necessarily trust them not to change their minds at some point in the future. If it's all on the blockchain you have an immutable historical record.
can you give examples? where all stakeholders have the same immutable "ledger"?
...and then you could group the ledger entries into "blocks" of merkle trees and signing using HMACs, you mean?
You've basically reinvented the "blockchain". The commercially available blockchains are essentially this - they don't use proof-of-work. The enterprise blockchains are not the same as the one that underpins bitcoin.
The current blockchain craze is supposed to find its root in the Bitcoin whitepaper which is about a decentralized distributed trustless immutable ledger. If you remove any of these attributes you end up with something absolutely mundane that definitely doesn't warrant the ridiculous amount of hype, resources and money being poured into it. There are only a very small number of problems that can be solved with a decentralized distributed trustless immutable ledger. That's exactly the point of TFA.
I think this is a very important point to make because many cryptocurrency zealots ofter argue that "the blockchain technology is here to stay, ergo cryptocurrencies is here to stay". Except it turns out that the term became almost meaningless because anything sort of qualifies as a "blockchain" these days, including many centralized systems like IOTA or Ripple or systems that are de-facto centrally managed and mutable (like Ethereum).
If people realize that Blockchain is 90% hype, 9% old technology and 1% actual innovation then maybe they'll think twice about whether having a ~$400 billion market cap for cryptocurrencies is sustainable in the long term.
This is what usually happens when marketing around a term gets too froth (see also, AI).
Why not have auditable mutability? The audit log is the thing that should be immutable.