Oracles, or why smart contracts still haven’t changed the world
blog.smartdec.net
blog.smartdec.net
Presumably because paper contracts don't scale; nor do they arbitrate machine:machine interactions without human proxies on both sides.
What does this mean?
Without any middleman, this doesn't work, because the parties are in a prisoner's dilemma, rather than an iterated prisoner's dilemma—nobody can effectively punish the other party in a future transaction, so there's no incentive to not screw the other party over.
Without smart contracts, what you need here is a "marketplace owner"—a legal agent where both sides have a legal agreement with them. This changes the situation so both sides are playing an iterated prisoner's dilemma with the marketplace owner, who can punish a user on either side for what they did to a user on the other side in a previous one-off transaction.
But this marketplace-owner role is also known as a "middle man." Their role in punishing defection is valuable enough that the market doesn't disappear if they extract rent from both sides—and so they usually do. Ideally, we would have an alternative where everything still works out, but where rent cannot be extracted.
With smart contracts, the marketplace-owner role is performed by, essentially, the buyers and sellers all automatically voting on whether a given transaction was legitimate. The smart contract is just the specification both sides have agreed to, in a given case, for judging the legitimacy of a transaction; and the blockchain is just a database which all parties doing this auditing synchronize amongst themselves, containing copies of both 1. those specifications, and 2. all the data required to validate any new transaction against them (which, in the case of a ledger-like transaction, is usually "all the valid transactions executed so far").
There still needs to be a human-level legal recourse for disputes—but those disputes would only ever be disputes about the specification of transactional legitimacy being wrongly specified, which are much rarer than disputes of the form of "he defected!"/"no I didn't!", to the point that the service of arbitrating such disputes would not be seen, at a human level, as valuable enough to justify rent-extraction.
Don’t we already have this? Street markets and retail shops and one off websites and millions of other agents making up modern markets? It seems to work fine.
In cities with police forces. Purchases at street-markets don't devolve into robbery because police forces disincentivize that. The municipality taxes you for that service, and so is effectively a middleman and rent extractor for these transactions.
Also, in cases where you've decided to trade using cash rather than to barter, you're being protected from your counterparty paying with counterfeit currency, by the state coming down rather harshly on counterfeiters, keeping counterfeit currency out of the market. That's a service they provide in exchange for state-level taxes. So, another middleman and rent extractor in your transaction.
> one off websites
When this works, it's because the payment processor (Stripe, PayPal) is acting as the middleman and rent-extractor.
Even without a payment processor, you can usually seek redress from your credit card company (another middleman and rent-extractor.)
Also, a search engine probably acted as a matchmaking agent to lead you to reputable services (and so is also acting as a rent-extractor in a round-about way, with sponsored ads and such.)
Without these parties in play, the Internet is not a safe place to transact. 99.99% of credit card input forms on the internet (by volume) are those of phishing domains. That's what a non-iterated prisoner's dilemma looks like.
The state, or any actor for that matter, can fill multiple roles in a transaction. Intermediating all transactions is a bad role for any actor to be in (from every other actor's perspective), because it's one prone to rent-extraction. Any time you hand money over to a second party through a third party, humans have enshrined the logic that the third party—if it's big and powerful enough—can demand a cut of that transaction.
In all the cases I mentioned, the rent that is being extracted is a cut of all regular transactions. Sales tax / VAT is rent; credit card fees are rent; payment-processor fees are rent; and all of these are percentages. That is why states, credit card companies, and payment processors all have billion- (or trillion-)dollar budgets.
Imagine we eliminate that intermediation. Transactions flow directly between buyer to seller, with nobody able to take a percentile cut of them. No rent is extracted from the original transaction.
Now, in the case where a transaction doesn't go well, we do still want some actor to arbitrate disputes over a transaction. But, given the way legal systems work, it's entirely possible to do that arbitration after the fact. That is the whole idea of civil court, after all.
Such arbitrations usually result in the need for a recompensatory transaction (i.e. a lien); and such transactions need to be intermediated (i.e. supervised) by a third-party, since the two parties have already proven that they aren't mutually trustworthy. So there is a transaction here from which you probably can't stop rent from being extracted.
But that's okay! Disputes happen very rarely, while regular transactions happen all the time. The total cut of small-claims court, probate court, etc. fees, is way smaller than the total revenue of sales tax. The total amount paid to retain an arbitration service, is way smaller than the total amount earned by operating an escrow service. Etc.
The state is essential! It just doesn't belong between two people. It belongs waiting behind two people, acting as the exception-handler which one or both parties run to to report the transaction as having failed from their perspective. Then the state can step in. Much less work for the state; but also, much less rent to extract.
But one nice thing about contracts (the objects of civil law) is that the state doesn't actually get involved in them except in the breach. You can create as many contracts as you like, as often as you like, with whomever you like, without any sort of filing cost or delay, and they will require no resources to maintain until someone on one side or the other thinks the contract has been violated.
I can't imagine the same being true if all contracts essentially worked like deeds, having to be notarized and filed at a government office (even if electronically) to have force, and needing to pay upkeep fees to keep them filed there lest their force lapse.
Also: a blockchain is nice because it allows people in different sovereign jurisdictions to create a contract. There's no legal contract I can make, as a US citizen, with e.g. a Cuban or Iranian citizen. But I can transact with them through a smart contract.
> already has it that a contract does not have to written down to exist so if you're pretty sure things are going to go well - say mowing the lawn, you can go ahead and just enter the contract with nothing written down
Yeah, but there's a reason people do write contracts down rather than... not doing that, when they want to actually have them be enforced in the breach.
Personally, I don't even really want smart contracts to "do" anything on their own; all they would need to be useful is to be predicates—executable code running on a distributed computer that automatically detects a breach of contract, so that legal measures can be taken. That, by itself, is much more useful than a regular two-party written contract that devolves into "burn down their office to get out of the contract", or the regular three-party (you, them, a lawyer) written contract that costs $500/hr to facilitate.
Replace 'hackers' with 'lawyers' or 'accountants' and that's already true in our present system.
“Technicalities” in general are a lot less of a thing than TV shows would lead you to believe
The common moniker to9 not take a contract verbatim is not codified in law as such, I guess. And if it were, it would be ironically self defeating. I don't know US Law precisely, but Germany has BGB § 242 Leistung nach Treu und Glauben - liability by trust and obligation (with respect to the customs of trade).
Translating this title shows how deep the connection runs. "The spirit of the law" as you imply strikes me as something coined at least in roman times if not koine or older. The law is actually very strongly exploiting misunderstandings. The ruling theme is still that vulgar language is wrong, the obligation to interpret code is on the subjects and it is satisfied by the availability and ability of lawyers. The exploitation is giving the judicial branch an advantage that is unfair to the point that lawyers are likened to devils. The downside is that it gives lawyers (including judges) a hard time as well.
The problem with smart contracts remains the same, that limit on expressiveness extends to computer code, that cannot express questions of morality any better.
Automated transactions may have useful applications, but seeking fairness is not one of them.
The way programmatic code can improve on it by automated tools is burdened with the same level of complexity, if not higher than Natural Language. But Smart Contracts are, as the name implies, intended to be used for small, manageable bits of code. Never mind codes that are too big to handle for a single person, bugs from a single typo for example could still happen. There's simply two sides to that. Either strict enforcement is thought to promote improvements in code quality. Or lenient apologies hope to promote amicable values, as far as trust is concerned, e.g. if due diligence also implies to inform whether a likely mistake was intended or not.
If the other party knew of the mistake that may be a "Versteckter Einigungsmangel" (covered up, hidden; Agreement; lack of, deficiency - hidden deficiency of agreement). In that sense no smart contract would be enforcable, because the conscious decision is deferred - post hoc ergo propter hoc.
The deciding difference is, if there's an automatic arbitrage bot for example, and it's not aware of the mistake, the creator has no liability to check for mistakes, I suppose. Whereas if exploits are targeted at buggy programs, that's a different matter.
The deciding factor would be the custom of the trade. Custom comes from costume. So if a foolish script kiddy exploits a huge bank they will suit up and claim higher right from custom. Vice versa, a kid exploited by automatic gambling bots e.g. will be blamed for wearing a suit to big for it's size. /s
Furthermore, some areas of law seem more open to "Technicalities" than others. It's hard to believe that tax structures like https://www.investopedia.com/terms/d/double-irish-with-a-dut... were part of the intent of the law, though they are compatible with the word of it. The difference between avoidance and evasion often rests on a technicality.
Finding ways to subvert the intent whilst remaining within the 'rules', is the very essence of hacking. No one said the username input couldn't contain an SQL statement?
Yes, someone will have a use case where this can't do (obscure thing) nobody really needs to do. The way to design this is to try to express common contract forms - buying, selling, lending, renting, betting, derivatives - and make sure you have the expressive power for that. Then stop.
A decision table would be an improvement over some current written contracts. A friend once asked me to read over a complex currency swap derivative contract, written in English and I found a clause that was the opposite of what it should have been.
(And no, layering another language layer on top of the byte code, and a proof system on top of that, is not the answer.)
probably not
Code is itself a compromise. Do this thing for me, and in exchange for not having to do the thing you lose flexibility.
Updating a smart contract should never happen because once you can update it, you can change its contents and its rules in a way that might benefit only one side. Even if you create rules to update the contract, finding 100% consensus (everything below 100% is unacceptable if you are explicitly using smart contracts to disallow cheating) to update the contract takes time in which more mistakes might happen and make the whole contract unusable.
No, it's an argument from programmers' common sense. Smart contracts are code, and we all know that any program more complex than hello world will contain bugs, due to both coding mistakes and errors in modeling the relevant aspects of reality. Given that, binding people with (immutable!) code seems like an extraordinarily bad idea.
Assume:
1. a distributed system where the consensus algorithm is state-dependent (in the sense that an SQL RDBMS that exposes the ability to insert rules/triggers has state-dependent consensus—different MVCC states will see different transactions as valid/invalid);
2. malicious machine-agents (bot oracles) supplying arbitrary input into the distributed system;
3. the distributed system being open-membership, such that malicious people are running auditing nodes (and so you can't really do Raft consensus);
4. the distributed system being large enough that you can't really do Paxos consensus in any efficient way.
Is there any other solution to this problem, than to use the consensus algorithm of:
1. have many nodes redundantly, eagerly audit a block of new inputs;
2. on each step, choose of those blocks essentially by lottery (specifically, a lottery no individual node on the distributed system can predict or cheaply craft an input to win);
3. allow anyone who wants to, to configure their node to fully verify past blocks, such that enough nodes doing this will create "herd immunity", diverging the system away from maliciously-crafted blocks.
Step 2 of the algorithm requires Proof-of-Work (so far as we know); step 3 of the algorithm requires an accessible chain of signed proofs to audit. Together, those spell "blockchain."
There's this adage[0], that "organizations which design systems ... are constrained to produce designs which are copies of the communication structures of these organizations". It's usually meant negatively, but in this case one can draw a positive conclusion - just like organizations don't need the blockchain to efficiently do their businesses, automated systems designed by those organizations may not need the blockchain either.
--
There is, in my mind, justification for there existing at least one distributed computation substrate where machine-agents can basically play a https://en.wikipedia.org/wiki/Nomic together, each asserting rules into the system, and then moving data (including data representing physical assets, and new rules) around according to the thusfar-established ruleset. Basically, an extensible distributed stock market where different negotiable synthesized instruments, each with their own rules, can be brought into being and traded, without needing to get buy-in from anybody, by just throwing them on there and seeing if anybody is interested.
(You know, the thing that there was enough pent-up demand for that the very first even-somewhat-viable distributed computation substrate, Ethereum, was forced into this shape despite not being very well-suited for the job, having been designed for entirely different kinds of computation.)
That's pretty much the only good case for a smart-contract blockchain as such that I know of, though.
In the Anglo-American legal sphere you usually settle for compensation, it's the only means at your disposal, whereas in continental Europe (Code civil or BGB) there are legal ways to compel performance as written. Price of strawberries went up, but someone bought strawberry futures cheaply? An American will settle for money, but a Frenchman or German will show up at the warehouse with the bailiff and seize the goods.
You'll find people who hate dealing with Americans. They squirm and won't perform if pressed, it's like nailing pudding to the wall! You have commitments yourself and don't want to scramble for strawberries, otherwise the bailiff will show up at your own offices.
You can say that Bitcoin is Anglo-American because they want Bitcoin to be independent of the real world, no law, just "smart contracts". No wonder that some people shake their heads.
Specific performance [0] does in fact exist in the U.S, so I'm not sure what you mean.
It's a problem, I can tell you. If you've been brought up in a world where people usually perform and you encounter an American who underperforms and then wants to haggle you are going to be angry. Right now I'm involved in a dispute with my former landlord who rented out substandard housing, and it looks as if my remedies are very limited. Moving is a great hassle and isn't cheap.
Start by imagining the exact system we have now: police, district attorneys, private attorneys, judges, appellate courts, senate, representatives, and executive... all of that in exactly the same configuration, except nothing is considered settled law until it is finalized by those people on the blockchain. No changes in law or consequences, just a replacement of the existing ad-how bookkeeping with blockchain-based bookkeeping.
That would seemingly function, given the current system functions, right? We would probably need some additional laws on how to deal with lost keys and such. But that would be resolved through existing structures. Someone starts impersonating a senator, the FBI investigates, there is a criminal trial, new keys are issued by the executive branch eventually.
Now imagine a slightly different setup, say... the same thing except no legislative branch. Non criminal law. Just the courts and the executive branch, and the executive branch is charged only with carrying out court orders that result from civil contract disputes.
Would that work? We don’t know. But in this blockchain world, people would be free to try that too.
Now imagine every possible variation between those two scenarios also being played out, in little communities who opt into them.
That’s the idea.
This seems like a really good idea. I wonder if someone has already done something like this on any of the systems out there i.e.\ a system where some nodes are designated as the Executive and have the power to change contracts in case of disputes.
The people aren't on the block chain, the "law is finalized (by those people) on the blockchain".
So, throughout the day as a judge is making rulings, their clerk is signing transactions on probably an Ethereum dapp.
It really is a shame that we've got so many people trying to do smart contracts "on the blockchain," when everything that they're attempting to offer was previously possible before Bitcoin because their solutions ultimately require a central entity or selected set of entities to work.
All blockchains are valuable to someone - the creator. They're cash cows. They start with the premise that they need a blockchain (so they can print money), and work backwards - what can we apply the blockchain to in order to convince people to buy our token. How many cycles of pump and dumps we can go through before people realize that it isn't going to work.
If everyone can and does print their own tokens, what are your tokens going to be worth?
I think it is worth to take a look to MakerDAO and how they handle external oracles to create the DAI stable coin.
Beyond this, before smart contracts change the world we need to cryptocurrencies be useful and change the world. That is the simplest smart contract case.
I feel exactly the same. However, SC are a very interesting technology. I prefer to study it now, to be ready when the humanity is OK with electronic money (cryptocurrencies) and come to electronic contracts.