Facebook Libra Is Architecturally Unsound
stephendiehl.com
stephendiehl.com
--
Regardless of the other, far more important sections of this article, I find the section about the programming language misleading. Programming language theory does not study the quality of programming languages or their suitability to certain tasks. It is simply outside the purview of the discipline. PLT does not have any tools whatsoever to determine which language is more or less suitable and it is not interested in that question. The theory studies the properties of formal systems and the internal implications of their design. Much like mathematics can deduce from the Peano axioms that 10 > 5, but it says absolutely nothing about whether 10 is "better" than 5 because the answer to that depends on context (are we talking cookies or tumors?) that is simply outside the purview of mathematics. Similarly, PLT can say whether a certain formal system is sound or not, but it says nothing whatsoever about whether soundness is "good", "bad" or neutral, and certainly not how good or bad it is. Of course, programming language theorists have opinions on the matter, but those opinions are not supported by the theory.
Also, given the other glaring flaws, there is nothing to suggest that a formal definition of the programming language would improve matters in any perceptible way. After all, we do entrust the world's monetary system, and sometimes even our lives, to software written in programming languages that don't have a formal definition. As someone who studies the issue of software correctness, a formal definition of a programming language is certainly of interest to theorists, but it has not been shown to be a particularly worthwhile means of increasing correctness.
(my agenda, for transparency: I want to send SOC's in space on tiny RISC-V satellites, and the lowest layers of those should be 100% error-free because there's no going physically there to reboot a working shell, remote is all we have.)
Regarding 'love' for blockchain, I think it's the basic proposition of "100% accurate data that cannot be controlled by anyone" that seduces. The 'cost' of that in performance becomes a nagging second concern. It gives people a feeling of safety if no other party, not their bank nor family nor employer nor anyone can alter their data, their transactions (whatever the kind, financial is but one use).
Whether blockchain is the only way to achieve that is another matter, but (afaik?) so far it's the only working implementation of the concept of perfectly secured data. I think that's what drove people nuts. I also think Bitcoin or currency in general is but one use case and a very impractical one in the current financial environment, i.e. Earth circa 2019. I'd wager there are much better avenues to explore, eminently non-financial in nature, such as peer-to-peer 'free' communication, or formal (law, contracts) codification (anything official and 'forever' until 'revoked'). No coin, no market, no whatever but the benefits of a slow but 100% truthful database, for small data (text fits quite well).
That's not what I said. I said that merely creating a verified formal specification of a language is not in itself a good path to increasing correctness, and I wouldn't focus on that as a significant cause for concern given all others. But even when you use formal methods in the development of your software -- and I'm certainly a proponent -- there are many formal methods with widely different guarantees and costs, and some of them don't require a formal specification of the programming language. Moreover, no system can be 100% error free, regardless of verification method used. Systems rely on hardware whose actual behavior can never be "proven" correct, and, at best, only probabilistically matches the spec.
I personally believe that some formal methods can greatly improve correctness, and do so affordably, but the question of which formal methods are worthwhile when and by how much each of them improves correctness is very much an open question.
> it's the only working implementation of the concept of perfectly secured data.
I strongly disagree. There is no such thing as "perfectly secure." Security is defined with respect to certain threats (e.g. a hazmat suit can protect you from poisonous gas but gives you no defense from bullets, whereas a bullet-proof vest is the opposite), and blockchain is rarely the most secure with respect to the most relevant threats in a monetary system.
Wow, this is a great way to frame this! What do you see as the largest threats to the effective operation of a monetary system?
Which of these threats you think is the more salient is, of course, a matter on which people may disagree. I personally find the risk of a central monetary authority devaluing my money, to be not one of my top concerns, but I could understand why others might think differently (especially if they were in a different country, that used a different currency).
I don't think that's the main threat Bitcoin is designed to defend against, though; I think there's a whole spectrum of confiscation threats, ranging from thieves tunneling into bank vaults (I know a woman here who lost her savings that way), to immigration authorities confiscating jewelry, to pirates, to trumped-up "money laundering" charges. And of course if we're mentioning Germany and World Wars, we must not forget the confiscation of Holocaust victims' entire possessions, including jewelry and fillings after the gas chambers. Bitcoin can't make genocide impossible but maybe at least it can make it unprofitable.
Again, this could vary depending upon your nation's government and crime situation.
It seems like some sort of confusion to blame the Mt. Gox heist on Bitcoin. Mt. Gox's depositors gave their Bitcoins to Mt. Gox; Mt. Gox didn't give them back and claims that an unknown party absconded with them. If you lent your car to a random French PHP programmer in Japan and he came back without the car, you wouldn't blame that on cars in general being an "unsafe" investment.
If the Mt. Gox depositors had kept their Bitcoins in a paper wallet in a Bank of America safe deposit box rather than in Mt. Gox, they'd still have their money. (In fact they'd have enormously more money, but that's sort of random; it demonstrates the fickleness of markets rather than any kind of fundamental security of Bitcoin.) Conversely, the investors and banks who invested or lent dollars and yen to Mt. Gox lost as much or more as the Bitcoin depositors.
Probably a BofA Bitcoin account would be better, but that's a matter of convincing BofA to offer Bitcoin or similarly secure currencies, instead of or in addition to dollar-denominated accounts. And that's where Libra comes from.
Fiat currency is secure in US banks because there is vast institutional protection for banks such as FDIC insurance and extremely strict laws against bank theft, the Federal Reserve, and so on. There are no such institutional protections for Bitcoin and there never really can be, by design.
> If you lent your car to a random French PHP programmer in Japan and he came back without the car, you wouldn't blame that on cars in general being an "unsafe" investment.
Sure I would - if lending a car to strangers was an effective necessity to use one in the same way using an exchange is an effective necessity to use Bitcoin, and there were "alternative cars" (aka fiat currency) that required no such lending to strangers.
> There are no such institutional protections for Bitcoin and there never really can be, by design.
This is nonsense. Bitcoin's design permits all the same institutional protections available for dollar bills or precious-metal coins, and additionally permits others that are enormously more secure than the mere incentive structures we must rely on in the case of dollar-based institutions. For example, a bank holding gold or dollars cannot produce a mathematical proof of its reserves as a Bitcoin bank can, and there is no dollar equivalent of multisig wallets.
So, in both cases, you are incorrectly imputing advantages to fiat currencies that in reality belong to Bitcoin in this comparison.
Yes. However there is also cash which allows for instant anonymous transactions in the physical world which is sufficiently widely accepted to be used to the exclusion of banks, if you so choose.
> you can engage in instant electronic transactions with Bitcoin you hold in your own wallet
Isn't the fact that transactions are not instant widely perceived in the Bitcoin community as one of, if not the, greatest barrier to adoption? If not, why all the investment in the Lightning network?
> Bitcoin's design permits all the same institutional protections available for dollar bills or precious-metal coins, and additionally permits others that are enormously more secure than the mere incentive structures we must rely on in the case of dollar-based institutions. For example, a bank holding gold or dollars cannot produce a mathematical proof of its reserves as a Bitcoin bank can, and there is no dollar equivalent of multisig wallets.
You're saying these words but not addressing the substance of what I said. There is no FDIC equivalent for Bitcoin - unless there's an exchange that guarantees replacement of lost/stolen Bitcoins? Replacing Bitcoin seems a difficult proposition when fiat currency can just be created out of thin air but Bitcoin cannot - once it's lost, it's lost, and can only be replaced in a zero-sum way.
I didn't realize you were laboring under the misconception that the FDIC has the authority to mint money, like a central bank. That's why I didn't address it. Now I can. It doesn't. The FDIC is funded by premiums paid by its member institutions, not by creating currency out of thin air; an insurance scheme for Bitcoin depositors in a bank that provided fractional-reserve Bitcoin accounts could be funded in the same way. It could even be provided by the FDIC, which already provides deposit insurance for deposits denominated in foreign currencies.
> Isn't the fact that transactions are not instant widely perceived in the Bitcoin community as one of, if not the, greatest barrier to adoption?
Bitcoin transactions are instant; they reach everywhere in the mempool in a matter of seconds. It's just that until they're a few blocks deep in the blockchain, they might be reversed, like bank transactions can be for several months. This usually takes half an hour or so, and that's a hassle for some kinds of transactions. However, I think bigger barriers to adoption include the network effect of existing currencies, a sketchy reputation, and the fact that Bitcoin exchanges are now illegal in China.
> there is also cash which allows for instant anonymous transactions in the physical world which is sufficiently widely accepted to be used to the exclusion of banks, if you so choose
Cash limits you to transacting with people you can meet in person, which condemns you to poverty unless you are very lucky indeed.
It is more like 80-85%, not 96%. $1 in 1972 is $6-$6.5 in 2019. A 96% loss of value would mean $1 in 1972 is more like $25 in 2019, which is not the case.
Also to phrase it in context you should probably say "the US dollar has had an average annual inflation rate of 4% per year over the last 5 decades". Also for additional context you should point out that bonds slightly exceeded, and that $1 of stock in 1972 in the US market became ~$104 in 2019.
Context matters a lot here.
I agree that "an average annual inflation rate of 7.1%" (or, using your US$6 number, 3.9%) sounds much milder than "lost 96% of its value since 1973" (or 83%). Where I differ is on whether the milder presentation or the more dramatic presentation is more informative. I think that, except to financial traders, "3.9%" or even "7.1%" is a misleadingly insignificant number.
Consider that throughout the 1600s, 1700s, and 1800s, there were families that lived on the interest income from government bonds, both in the US and in England. Even throughout the 20th century, people would buy "savings bonds" as presents for children or as a means to save up for college or retirement; the bonds would reach maturity decades in the future, providing a healthy reward for the prudent and patriotic purchase. Since the end of Bretton Woods, that 3.9% or 7.1% has made nonsense of such ideas. Despite what you might think, this hasn't eliminated plutocracy or increased social mobility — rather the opposite has happened in the post-Bretton-Woods years, in fact. I think it's hard to obtain the historical perspective necessary to appreciate the importance of this radical experiment. But it is, I assure you, a worthwhile effort. I recommend it.
Perhaps inflationary monetary policy is a necessary instrument for avoiding financial panics; it's a plausible idea. But the evidence against it — particularly the 1970s stagflation in the US — suggests that, though plausible, it isn't such a clearly open-and-shut conclusion that we should deny everyone access to alternative, non-inflationary currencies. Moreover, in most scenarios, attempting to institute such a policy would only deny such access to everyone but the well-connected and influential.
Oil now is 3x more expensive even after a more average inflation of ~4% compared to the bottom of 1973 (though in the mid 90s it wasn't so bad). Energy as a whole though, is not 3x more expensive. Petrol is only about a third of energy consumption. Consumer electricity prices for instance are relatively constant from the 70s through now. Slight increase in the 80s, slight decrease in the 00s, but within say <5% of prices.
I'm not making assertions about the change to bond markets (which I agree are historically fascinating, and will continue to be so in the future too).
If we want to be skeptical of carefully tailored metrics with thousands of parameters produced by political appointees, what standard should we use to measure the value of the dollar? Precious metals have been the standard against which currencies have been measured for several thousand years — the gold standard for measuring the value of currencies, you could say — and by that standard the dollar's loss of value since 1973 is about a factor of 25. This compares to about a factor of 2 over the previous 40 years, since 1933, and a factor of about 1.1 over the previous 140 or so years since the dollar was introduced.
I suspect that if you compare other goods which are, like gold and crude oil, verifiably produced to the same standard of quality in 1973 and today, you will find a similar factor of 16–32 in their dollar prices. I'm thinking of the most common grades of steel, aluminum, brass, portland cement, window glass, industrial electric motors, and so on. There will definitely be some exceptions — ±1% resistors are much cheaper now, to the point where you can't even get the ±20% kind that were the norm in 1973, and I imagine the same is true of specialty steels, synthetic sapphire, and a number of other things that were barely feasible at the time; and presumably photographic film has become more expensive, as it has ceased to be a mass-market item. If you're right about the cost of electricity "staying the same" — by which I assume you mean that, in the US, it increases in line with the BLS CPI? — this suggests that my hypothesis won't be true of coal. Do you have any other ideas?
Let's take anthracite, because it's the purest grade of coal, so it should be less vulnerable to variation in value from drift in grading standards. https://www.eia.gov/totalenergy/data/annual/showtext.php?t=p... suggests that nominal anthracite coal prices have risen from US$13.65 per short ton in 1973 to US$70.99 in 2011; https://www.eia.gov/energyexplained/coal/prices-and-outlook.... says that in 2017 they were US$93.17 per short ton, FOB the mine. That's a factor of 6.8, which is a lot closer to 6 than to 25.
Yes I meant real price, not nominal.
US electricity is somewhere around a third from coal.
I would be interested in a study showing a 15-30x increase in similar-quality construction materials.
The fixation on gold makes no sense to me. It's just a commodity, not a super useful one either. Gold's price floats wildly based on people's fears. It's not like everything became 4x more expensive between 2000 and 2015.
We were debating precisely which data series is best for computing the "real price" from the nominal prices. But it seems you take me for a fool and beg the question.
And Bitcoin lost over 90% of its value in just under 2 years. Where are you going with this, council?
When do you mean? Right now Bitcoin is US$9400, which is almost exactly half of its all-time high value of US$19891 (in 2017). There are several times it has lost more than half of its value, but I don't remember a time when it has lost 90% of its value.
The reason the dollar inflates and never deflates is that it's designed to inflate. On purpose. The underlying Keynesian monetary theory is a radical experiment in stimulating economic activity by maintaining the proper level of unemployment — when unemployment is "too low", central banks raise interest rates (in effect, printing less money), while dropping them when unemployment is "too high". Of course, deliberate inflation of coins by governments has a much longer history than Keynesian monetary theory or fiat currencies — not only did Song China experience it when it introduced paper "representative money", but it's also a well-attested phenomenon in Roman commodity money and later coinages (there known as "debasement", in a technical sense different from its metaphorical use in literary English to describe degradation.) But Keynesian monetary theory, which might be correct, provides a theoretical justification for believing that inflation is good under some circumstances and bad under others, and since 1973 we are all, for better or worse, participating in a radical large-scale experiment to test this hypothesis.
Bitcoin is, in significant part, a dissident response from a group of eccentric intellectuals looking for a way to opt out of that radical experiment. Consequently it is designed to make inflation (of Bitcoin) infeasibly difficult — the existing Bitcoin supply increases asymptotically toward a fixed quantity, known in advance. So, although Bitcoin's value will fluctuate, sometimes wildly, it doesn't have the secular inflation trend designed into the dollar's governance mechanism.
Looks like I overstated it slightly. It lost 85% of its value between its all time high December 17th 2017 ($19,891) and December 16th 2018 ($3,159).
The rest of your response, in my opinion, is immaterial. I can't imagine a soul who'd prefer their money to "fluctuate wildly"—to the tune of -85% in a year—vs slowly losing 1-3% per year. Especially when there are very accessible financial instruments (e.g., TIPS) to avoid even that.
In short, if any soul you could imagine had won the lottery in 1973, they'd be poor again by now because of not knowing how to manage their money, incorrectly believing that a currency is not a kind of investment.
People invest in things, generally understanding the risk. Risk is not all equal. BTC is far riskier (more volatile) than virtually all publicly traded stocks or commodities. See again the very recent 85% drop in 1 year.
And let's be clear: BTC is not comparable to a stock. Company stock is valuable because it gives you ownership (and therefore a stake in) the company's profits. Gold is a much more reasonable comparison, but even that has real practical value (e.g., use in electronics, jewelry, dental work, etc.) And funny enough, Gold is worth less today than it was in 1979. So... it's not a great investment. It's just volatile, and "investment" in it is basically a 0-sum game. Just like Bitcoin.
In 1979 the price range of gold was $226 to $512 per troy ounce, a slightly higher level of volatility than the Bitcoin level you describe with a bit of exaggeration as "far riskier than virtually all…commodities." The gold price today is $1485 per troy ounce.
I'd like to caution the people who have downvoted your other comment that there is a plausible reading that is sufficiently charitable to make your new comment not actually false. Namely, although if you measure it in dollars, it's "worth" 3 to 6 times more, even over the timespan you cherry-picked, the dollar has lost more than a factor of 6 since 1979, so gold really is worth less today than it was then. The attraction of gold — just as with Bitcoin — is precisely that it doesn't have a secular decline in value built in, so it's a good vehicle for preserving wealth through periods of instability, even though it doesn't generate a return in the way that stocks and bonds do.
Well if you have a suitably sound and accurate economic model that you’ve been secreting away, let us know and save us the time. Additionally, it’s not like it’s been exclusively Keynesian economics since the 70’s: there’s been a huge amount of neoliberal economics going around-do you not remember the popularity of austerity measures during the 2008 GFC?
To me, bitcoin and co’s dogged insistence on the evils of inflation feels more like someone along the way had some personal issue with inflation alone and designed something to counteract it, plausibly at the expense of numerous other economic factors.
You cannot mean this seriously. Every example you write is worse for bitcoins. If your coins are stolen, that's it, you can pretty much kiss them goodbye. If the government wants to confiscate someone's bitcoins, they will beat the private key out of the holder with a $5 wrench. If WW3 breaks out and the world order collapses, a wholly digital asset that relies on a large network of high upkeep, high-tech infrastructure is surely not a particularly safe bet. You can bet that datacenters will be among the first casualties in such an event, whether outright government confiscation or a denial of service attack by the enemy.
If a bank gets robbed, for most cases it won't impact account holders at all. Even if the bank goes bankrupt, there are various government schemes that will cover account holders up to some limit (e.g. $250k currently for the US). There is none of this for bitcoins. There could be of course, but then the argument is: what do cryptocurrencies actually offer beyond what is already possible with normal currencies?
To the best of my knowledge, the only practical benefit of cryptos is that they completely sidestep KYC/AML regulations and therefore one can easily move money between regions that draw regulatory scrutiny. Countries with at least semi-modern banking infrastructure already have instant transfers so let's not bring that argument up. In any case, that's not a feature uniquely enabled by cryptocurrencies.
The fact that bitcoins are deflationary I consider a bug, not a feature. Perhaps history will prove me wrong, but in my opinion money is not supposed to be an investment asset. People should not hold cash expecting it will appreciate. It should be reinvested as much as possible.
If our banking system had used something like bitcoin to implement online transactions, odds are that e-business would have had much less successs and much higher barrier to entry.
The other alternative, of course, is someone taking on full legal liability for transactions that can't be secured technically. If Facebook would offer Libra to consumers in e.g. UK, then all that "transactions are technically irreversible" means is that Facebook would be required to "reverse" the transaction to customer while being unable to recover the funds from the beneficiary - and if they can afford to do that, that's their choice to make.
The main problem is simply the novelty of it all. Once reasonable and customary structures to handle disputes are in common use asking people to bypass those structures without a very good reason will be just as much of a red flag as it is under the current system.
Facebook is not a party to a transaction between any other two Libra users and should have no liability in the event of a dispute over payments beyond maintaining accurate records and providing a fair and above all neutral platform to conduct business.
The original article mentions UK Consumer Credit Act which IMHO is not appropriate (its scope is limited to credit relations, and the protections of that act generally exclude both debit cards and most e-money systems including Libra), so the scope for potential payment service provider involvement in disputes between buyer and seller is narrower than that - and probably closer to your "should" statement than the arguments of the original article.
However, it can't be a fully neutral platform distancing itself from all liability. It is illegal to "simply" offer payment services without incurring any liability for misuse of them, breaching AML/KYC regulations, etc. Facebook has not yet (as far as I know) stated what exact legal structure they'll use for compliance with the legal requirements, so I can't comment on that, but they did make statements that Libracoin will comply with the EU regulations so I presume that some legal entity regarding Libracoin (possibly co-owned by the consortium members, or possibly multiple entities) will (have to) be a licensed payment service provider in EU, and similarly (it's usually done with separate legal entities) in other major jurisdictions.
Technical structures that "just happen" such as Bitcoin can ignore regulations but any person or organization that wants to offer services using these technical structures is fully liable for meeting all the legal requirements - and if the technical structure makes impossible to do something, they're still fully responsible for any consequences of not achieving the impossible thing; if they don't want the liability, they're free to not use that technical structure and not use/offer/advertise anything with it.
Personally I find it much more interesting and productive to debate what the law ought to be rather than what it is, but as a practical matter Facebook will obviously need to take the various injustices of the jurisdictions in which they intend to operate into account—and the centralized design of Libra doesn't seem very well suited to deal with that reality.
The only known solution to this threat is not have a single supplier of money (i.e. a lot of independent miners digging metal out of the ground, or the block chain equivalent)
I reckon the only way to error-free is redundancy, i.e. 'out of the box' we just put two boxes, or actually three for "high availability"; the underlying controller being just a dead man's switch — if A's life signal dies, failover to B; set up C as new failover; reboot A.
> I personally believe that some formal methods can greatly improve correctness, and do so affordably, but the question of which formal methods are worthwhile when and by how much each of them improves correctness is very much an open question.
Oh I can see that.
In general terms, I think cost should be focused on the most critical components; like we don't need to test every single bit of code before production. You just crash gracefully and resume state when the loss (if any) is acceptable. When it's not, then it's not a choice to front the cost, it's an imperative, part of your 'spec' as a business/product/service/free thing. Tor is slower than normal browsing, but that's the tradeoff. Fast forward 10 years and costly workloads have become either accelerated by hardware or simply benefit from general improvements, like encryption is now fundamentally cost-free for usual things like TLS (AES-based things), or increasingly AI workloads.
> blockchain is rarely the most secure with respect to the most relevant threats in a monetary system.
I very much agree. Key words being "in a monetary system", and indeed it's about economics more than tech (what I alluded to in saying 'Earth circa 2019', i.e. globalized monetary system, central-bank driven, mostly insured for most customers, etc).
Hence why I advocate that blockchain proponents explore other domains. I know businesses are, but it has more to do with topics like compliance (internal, legal).
You can have a lot of this automatically with "lockstep" chips, such as TI Hercules: http://www.ti.com/en/download/mcu/SPRB204.pdf?DCMP=hercules&...
This seems to be poorly considered. Isn't it easier for an OS and a language to be verified once even at great cost than hoping future billions of lines of developer code already produced at lesser cost per line are actually correct?
https://microkerneldude.wordpress.com/2016/06/16/verified-so...
Focusing on a formal language spec is like saying that a good way to make your software more correct is to work hard to ensure your compiler doesn't have bugs. I'm sure you'll agree there are more important things. As to use by program proofs, often an approximate ad-hoc specification is good enough.
BTW, the article you linked to is about one particular formal method -- deductive proof. There are many others, with varying costs and benefits.
On the one hand we have the management mantra: if you can't measure it you can't improve it. On the other hand we have Goodhart's law.
And so 'correctness', 'safety', 'quality' (or absence thereof) are fluid concepts that can never be formalised precisely.
Language/logic sucks, but it's all we've got.
Perhaps, but PLT is not the main discipline studying software correctness -- those would be formal methods and software engineering -- although it has some overlap with those disciplines. PLT is not the general name for all study of programs; it is the name for a particular perspective, and a particular component of that study.
Speaking from a bit of experience at Satellogic as well as folklore, trying to make the lowest levels 100% error-free isn't a good strategy. A better strategy is to make the lowest levels capable of recovering from the errors that will occur most frequently. Radiation is going to flip bits; processors are going to fail and sometimes hang; batteries are going to go low; temperatures are going to exceed specifications. If your system is built on the assumption that the lowest layers are going to be 100% error-free, you won't give sufficient attention to handling those errors when your assumption inevitably turns out to be wrong.
One suggestion: include a remotely-triggerable reset sequence in a hardware state machine. A 4-bit state machine driven by 4-bit symbols will work reliably if your channel error rate is small compared to one error per 16 symbols, and it has a false positive trigger rate of 5.4 × 10⁻²⁰. (This is of course vulnerable to malicious DoS attacks if a malicious party learns the 64-bit reset code, but in practice those have historically been an enormously smaller concern than satellites failing randomly in ways that a reset switch can correct.)
It's worth thinking through the fault tree of that reset mechanism. It needs to use omnidirectional antennas, for example, because otherwise it's dependent on attitude control. It needs to be on all the time, not just when you're passing over ground stations, because otherwise it depends on the clock and whatever kind of navigational system you have. It needs to be unencrypted, because otherwise it depends on your encryption protocol, which typically also involves clocks. It unavoidably depends on some kind of power source, but you can connect it directly to the solar panels and/or batteries, rather than through a switch. You probably want to use logic that can tolerate a fair bit of uncontrolled variation of the power supply voltage, not, say, TTL. But then you need like 4 flip-flops and a couple dozen gates. It can fail, but it's simple enough that you can make it highly reliable, unlike a RISC-V.
So, don't think in terms of making the bottom level 100% reliable. You won't get there. Think in terms of how to prevent inevitable unreliability from snowballing, how to make the satellite resilient against inevitable damage and malfunctions, as well as reducing that bottom-level unreliability to an absolute minimum.
As for blockchains, I think they're a very pragmatic solution to serious problems that are otherwise unsolvable: how can I send money to a friend in Venezuela? How can refugees carry their money safely without it being confiscated by pirates, corrupt police, or immigration authorities? How can people pay for illegal drugs without meeting in person with the vendors? How can we fund Wikileaks so they have the resources to transport Ed Snowden to safety? How can we fund Sci-Hub so that knowledge is available to everyone and not lost? Even international remittances to family members work enormously better with Bitcoin than with Western Union or SWIFT, particularly between countries with some degree of unfriendly relations.
It's a similar approach to that with satellites: we know there are bad actors in the financial system, and we want to engage in transactions with them, without giving them the opportunity to sell our credit card numbers to the Russian Mafia or take all our money. We want to prevent the small amounts of inevitable unreliability from snowballing and destroying the entire civilization. Also, we want to minimize the number of attempted ripoffs, so that our defenses against them can be less costly. It turns out that thieves, unlike cosmic rays, respond to incentives, so by making thefts more difficult to pull off, we can also decrease the number of attempted thefts.
Obviously I don't trust Facebook to design the world financial system, though. They elected Trump.
> Think in terms of how to prevent inevitable unreliability from snowballing, how to make the satellite resilient against inevitable damage and malfunctions, as well as reducing that bottom-level unreliability to an absolute minimum.
High-availability of components seems like a given to me (e.g. have 2, 3, 4 batteries as distant from each other as possible, to mitigate loss if one gets shot by some collision or outright fails; rinse and repeat for every critical component, starting at circuit design). In another comment, user "pjc50" suggests to me “"lockstep" chips, such as TI Hercules”, and yet my intuition would be to put two redundant ones on each satellite, just for good measure.
But the ultimate economics of the project can be made to work, imho, because I envision a swarm of such tiny satellites actually, wherein you can afford to lose a few nodes now and then, if that makes all of them orders of magnitude cheaper — and thus you can send orders of magnitude more, overall. Brute-force the reliability issue by making them expendable to a reasonable degree. No human life means they can die for all we care, if it makes sense cost-wise. Hence why in that perspective, a discussion on the cost versus benefit of formal methods is of great interest.
Needless to say, any advanced draft of the project would inevitably have to be vetted by, actually co-developed with field experts like you. To each contributor their domain. I hope it will be a given too, since I'm thinking of a 100% open-source project (both software and hardware ideally). The more eyeballs...
____
I see your points about blockchain, and they make a lot of sense; the problem I see with current 'cryptos' in general (including the big one) is that they simply aren't welcomed by most decisive institutions, including those who combat on principle the problems you mention. Like, you see the EFF et. al defending e.g. E2E encryption, but none of that drive to promote bitcoin.
Thus that 'respectable' cryptocurrencies exist to solve these problems, sure, please, yesterday! — but that they reform the financial system by their very existence? There doesn't seem to be much appeal in the mainstream. I think it's a matter of time, how much each generation weighs demographically in the global opinion / decision power. For now, it's boomers, and they're not in that place.
Satellogic's CubeBug design did use a TI Hercules TMS570 Cortex-R, and I think it's safe to say our experiences with chips like that were good — for the relatively restricted tasks they can perform. The automotive industry has a lot of lockstep chips available for it, because it's a mass market that demands reliability under harsh conditions.
I'd like to point out that what you're describing is pretty similar to Satellogic's original business plan.
Edit: skimming through the paper, really really solid material. Much appreciated.
I've seen your posts in multiple threads K0SM0S, and I generally enjoy reading your thoughts and opinions. When I meet people I find interesting, I like to ask what they plan on doing with their lives. I understand completely if you don't want to share further details, but I for one would be interested in an off-topic detour into your intentions with these microsatellites. One application I always toy with in my head is a time+location verification service, but I don't think satellites are strictly necessary for that one unless you're trying to work around region-specific laws that would regulate towers.
I'm not sure if you'll get this late reply.
First of all, thank you so much for your kind words, they mean the world to me, and for your interest — which is now reciprocal, I want to hear about you as well!..
I must admit I've spent way too much time trying to answer your questions in a 'concise' manner —HN's norm— but, as usual with this topic, it proved unusually hard fo me. It's rather complex, several independent yet synergistic 'moving parts' — too much repetition and cognitive bloat for a mere comment.
Thus I'm drafting something to share and discuss the concepts, if time permits it'll be up on some website (maybe reddit, maybe a forum, maybe some blog, idk...) by month's end. I'll keep you updated, if you so wish. You can reach me by email `cosmos// a t //vcx.cx` ;-)
The gist of it, FYI:
- the satellite thing is a personal research project (in very tangible ways, the experiment is to actually do it and launch). But the endgame (think 2030-2040) is a massive swarm of ~8 billion devices or more, if you catch my drift.
- However, it's an extension to a ground network which essentially aims at being an alternative infrastructure to internet. Formally it's something along the lines of a distributed, decentralized ("peer-to-peer") mesh network, fully encrypted yadi yada.
- This network is but an "optional" medium for my original idea (in ~2010) which was, in dumb terms, a communication network (which people would call 'social network' I guess, but it's not against such existing services, it's more of a global standard / spec whose primary goals are security/freedom/privacy, interoperability (like email), and to be 'unstoppable' (in the event of war, catastrophe, etc). Going back to first principles, this 'network' is not even an application but a formal protocol I suppose. It's the kind of thing that would ideally exist as an RFC 'standard' by the IETF.
This is more generally motivated by some of my philosophical values, notably freedom, empowering individuals (in the name of progress, civilization, but also happiness, self-growth).
My biggest question is how to handle payments. Bitcoin can't realistically handle the micropayments for this purpose -- I'm not waiting for a block to hash before my website loads, nor do I want to pay miner fees for every request. The best proposal I'm aware of is that nodes keep track of balances to neighboring nodes, and when you want to establish a new connection with an unknown node you need to send them an up-front payment for X amount of data in advance. (The price of data wouldn't really be per byte of course, it's bytes multiplied by the arbitrary node-selected edge-costs all the way to the actual source and back through the cheapest/fastest path as selected by the end user.) Then when you're approaching the limit you pay more in advance, aggregating the micropayments. This means the inital connection still has to wait for a block to be hashed, and it's annoying from the perspective of a user trying to find valid peers once it's profitable enough to launch malicious fake nodes that eat up-front payments and refuse to forward packets. The initial connection time issue might be mitigated by allowing a Zahavian signal worth of coins to be sent to a burn pile, like an address that is just all zeroes, since a user who was willing to burn a pile of coins covering X+Y data Z hours ago probably isn't trying to rip you off for X data now even if they haven't successfully made a payment to your specific node yet. I'd like to believe that something like IOTA could probabalistically work well enough for micropayments that we don't have to worry about that, but I'm not convinced. Ideally a connection could be established quickly enough that vehicles passing along highways/oceans could route traffic as they go, breaking apart and reforming as necessary.
IPFS is worth googling too, if you haven't seen it already.
I'll send you an email before the end of the month!
I need to research more into that. Great pointer, thanks!
> IPFS
Yup, definitely, it's on the radar. It's still not production ready though, I'm unsure whether it will/can (I mean this particular project/implementation, not the concept).
> payments
You've definitely thought this through, maybe developed already on e.g. blockchain?
Note that my initial idea, for a neutral human communication medium/protocol, dates back before bitcoin, blockchain, etc. My "system" was designed thus works without those. The inspiration was another 'bit' network: bittorrent.
Later on when I found out about bitcoin etc., I researched the tech. While I ignore the 'currency' aspect of blockchain for this project (because 'currency' is an application; and I'm merely concerned with the protocol beneath all applications), I did find interesting ways to integrate the blockchain paradigm itself (the idea of a database that can't be tempered with, and may be distributed).
My system remains independent of its database implementation though, it should work with simple txt files, or more typically some postgres.
The naive architecture is simpler than you might think, it relies on tried-and-true enterprise-inspired models and implementations. Simple things. Where we do the magic is precisely in the execution, to make it extremely efficient (eg target the lowest viable solution space; have a "concurrency-driven design" for scaling, modularity, distribution). And as of 2019, we have incredible computing resources in the hands of half the population, so 'efficient' is 'enough'.
So there's no payment at this level. It's a protocol, a language we agree to use, and one application may be human communication, but I may be wrong about that part. The protocol stands nonetheless. We are fundamentally not far from XMPP conceptually, although we integrate much deeper (XMPP could probably be a high-level API of a node in this system).
However there's this simple equality rule: "for every bit you ask the network to process n times, you too must process n bits for the network in return". Take some, give back some.
So nodes come a la "BYOR" (Bring Your Own Resources: CPU, RAM, storage, GPU, sensors, whatever), and each node is both server / client; like bittorrent or Tor you simply receive and serve continuously.
This puts the burden of scaling entirely on users individually (remember, it's decentralized: there's no central anything, no 'final' or 'higher' authority) and you'd expect the biggest traffic producers to also be those who make a business out of it (and I'm sure there would exist many applications on this system to let users charge/pay e.g. content or merch etc). Note that "sharing" should probably mean you are willing to 'seed' said shared content, thus fairly distributing load in viral cases.
Note that the network should guarantee anonymity of all accounts (each of your chosen 'persona' is derived but your core account is never exposed and can't be compromised by misuse, only theft in-real-life).
> mesh
It's a hard problem though, I'm aware of that. The MVP may definitely 'cheat' by using regular internet to bridge the gaps (it will be necessary anyway between cities). But one primary goal is that whenever possible (i.e. within range), two devices should never communicate but through an ad hoc LAN between them. Why go to Google's server when I just need to serve a file that's locally cached in the next room, or maybe just next house?
Baby steps...
All a blockchain is, is a Merkle tree with a third party that ensures there is only one “main line”. That’s the use case.
All the other stuff — such as having all computers in the network watch every transaction — that’s the wasteful part. There are other ways to have a set of third party validators, that is a subset of the network watching a given merkle tree, simply says which branch is correct. SAFE network uses a Kademlia DHT with various mechanisms to ensure the validators have no say in what they watch and they need to “earn” their way into having any say about anything over time.
There are tons of useful properties, some of which are used in Merkle trees like git:
Immutability
Quick verification of tree membership using Merkle branch
Ability to download different parts from different actors (Bittorent)
Consensus and rule enforcement (eg chess game or any other evolving document)
Smart contracts and autonomous code execution
And much much more. The main problem is when people think of blockchain they think of a giant monolithic chain of blocks each of which contains ALL TRANSACTIONS IN THE NETWORK. This is wasteful.
What’s even more wasteful is when you have divisibility of the tokens, leading to an exponential growth of UTXOs and unlimited storage requirements. And each full node needs to verify the entire history of every transaction because then they get intertwined. That’s the ridiculous part.
And proof of work is the most wasteful thing of all. People need to get off of that!
No. The "wasteful part" is also part of the definition of the blockchain.
Just because the word "blockchain" seems to describe only the data structure, doesn't mean that's the case.
The innovation was to couple a Merkle tree with a proof-of-work system. Both existed before in standalone forms. The Merkle tree in many, many applications, the proof-of-work for example in Hashcash to combat email spam.
Only the combination of both reached a level of novelty that deserved a new name.
(That we still haven't found a single compelling use case is another matter.)
What you mean is indeed succinctly and correctly named "Merkle tree" or "hash tree". It would have been wasteful to coin another word for it.
Again, wrong.
> proof of work is not a strict requirement. I believe the rising popularity of Proof of Stake blockchains will make that evident.
I thought for a second whether I should include PoS and other schemes, but decided (wrongly) that nobody would try to squeeze imaginary internet points out of being willfully misunderstanding.
But so be it: proof of stake is a different mechanism that fulfills the same role as proof of work in blockchains.
Here is the first article I could find from just today which shows a great use case.
Coca Cola is expanding their blockchain trial project to a $21 billion-a-year supply chain because they found very significant savings.
https://www.coindesk.com/coca-cola-supply-chain-firm-to-expa...
A blockchain is a singleton global computer of program code and data. It turns out this is sufficient to represent capital (money) on that computer.
In practice this results in dramatically reduced transaction costs. For example you can transfer money with an API call.
Another example is that an API can be "implemented with money". The https://uniswap.io/ API allows you to exchange currencies without any API keys or middlemen. But, the Uniswap API only works because there's a large amount of liquidity deposited by 3rd parties into its system, much like an inventory of food in a grocery store that shoppers can then access.
"What's the big deal?", you might say. "Uniswap sounds just like a bank. Who cares?". Well as I understand it Uniswap was built by a dude in a basement over a few months, not a multi-million dollar bank project. And you can integrate your app with Uniswap in an afternoon. If you don't think that's going to change the world then you might consider spending a few dozen hours reading https://weekinethereumnews.com/ and see if your opinion is stable :)
No, this is not true. It might incidentally currently be the case with, say, Bitcoin vs. $US, but there's nothing technical that inherently makes it so. In fact, as this article and countless others reiterate, from a technical perspective blockchain is almost always more costly.
It's the same reason why AirBnB is often cheaper: hosts don't pay business fees and don't follow other regulatory requirements like safety inspections.
But, it's important to understand that Ethereum is not a replacement for or opponent of KYC, AML, or checking if transactions are legal. Ethereum is a starting point, a base layer. It is necessary to rebuild all kinds of monetary controls into Ethereum's app layer. I support this development. Within 5-10 years all of the traditional controls will become available on various parts of Ethereum -- KYC, ability for government to freeze accounts, etc.
Example of reduced monetary transaction costs:
The current Ethereum gas price for a token transfer is $0.04 (https://ethgasstation.info/). Operations on Ethereum are relatively inexpensive and will become much cheaper with Ethereum v2 in a couple of years. The cost of Ethereum operations is orthogonal to the value of the money being manipulated. You can transfer $100M for $0.04.
Example of reduced non-monetary transaction costs:
Say you wanted to launch an eBay-type app with a single market for a dozen countries. Some customers may bring Euros, others Swiss Francs, some USD. Each market auction selects a currency from a whitelist. All bids for that auction must be in its selected currency. On Ethereum you can bid Swiss Francs which will be dynamically exchanged for USD. Unlike using your VISA for forex, this currency exchange is at the same price that whales and banks get; you pay no spread fee for being an end consumer. The non-monetary transaction cost part is that this Ethereum-based currency exchange API can be permissionlessly integrated in an afternoon.
2nd example of reduced non-monetary transaction costs:
https://www.pooltogether.us/ is a no-loss, audited, provably fair lottery built on Ethereum. The way the lottery works is -- you always get your money back, but your money bears interest during the lottery period, and all the interest goes to a single lottery winner. So the cost of the lottery is the time value of your money. PoolTogether is built on other Ethereum projects, that's why the lottery proceeds earn interest. The non-monetary transaction cost part is that PoolTogether is able to access interest-bearing deposits as easily as you can use jQuery. Also anyone in the world can participate - reduced cost of being in another country.
Just as a relational database with a web frontend would.
What blockchain ostensibly allows you to do is create that system without having to trust anyone to run the central database. But why would Coca-Cola ever need to do this? There will always be a trusted central party who can maintain the Coca-Cola bottle production database: the Coca-Cola company itself.
Blockchain (ie. Ethereum) excels when a heterogenous network of 3rd and 4th parties come together in a commons and interact permissionlessly based on a set of rules enforced by the system.
Ethereum is basically the World Wide Web with hyperlinks except with programs in general and money can live inside those programs.
An Ethereum-based supply chain system could do a lot of things. Not sure if these are valuable because I'm not a supply chain expert. But I can speculate.
Coca-Cola's Ethereum-based supply chain system could...
1. associate an eBay-style reputation with each supply chain participant. These reputations could then be used by more parties (eg. Pepsi) than if they were locked in a centralized system. Coca-Cola might retain the option to override any reputation.
2. provide a global audit trail of supply tracking. Similar to FedEx's "track my shipment", except you could transfer payment for supplies in the same blockchain transaction that updated their status. And those updates could automatically feed into the reputation system.
3. pay for supplies with a security. For example, Coca-Cola could tokenize a portion of its common stock and pay suppliers tokens of common stock in the same transaction that pays them currency. Or Coca-Cola could automatically distribute a pro rata stock grant to the entire supply chain each quarter. This could better align a global, heterogenous supply chain with the long term interests of Coca-Cola.
4. integrate with other Ethereum-based systems. For example supply payments held in escrow could automatically earn interest in https://compound.finance/. Payments crossing international borders could automatically exchange currencies at a very competitive, no-fee rate (eg. https://dex.ag/).
Should Coca-Cola embrace an Ethereum-based supply chain? I have no idea. But after spending hundreds of hours studying Ethereum I feel very confident that there is something very special going on here.
So for the purposes of supply tracking, different Coca-Cola facilities and shipments are 'individuals' which might report mistaken or dishonest results to the central server. And once somebody screws up, that trusted authority becomes a problem for others facilities to work around. For sufficiently large and restrictive systems (like US military supplies), correcting an error can become functionally impossible. At that point, you start resorting to awful two-wrongs-make-a-right solutions like entering fictional shipments which "move" a misdirected item from the listed location to the real one, or even redoing needless part replacements to match reality to documentation.
Obviously you can track supplies without a blockchain, and I'm sure a lot of Coke's actual gains came from tearing out a bad system and replacing it, but a blockchain does at least encourage good tracking design (one authoritative record per item, transactions are assessed by peers rather than immediately accepted by an authority). And if the goods in question have individual identifiers, "proof of work" is actually a great addition. It doesn't have to be computationally hard if you trust all the users, but you still get a system where "I am holding this and hitting it with an RFID scanner" is allowed to overrule any number of past errors regarding that object.
(Did Coke get all those gains? No idea. They probably just scrapped some legacy nonsense for a not-too-stupidly designed system.)
There are more details in this BI article mentioned in the coindesk one. I would have linked to it directly, but they have a paywall. https://www.businessinsider.com/coca-cola-bottlers-sap-scali...
As the article explains, they're expanding their test because it's demonstrated that they could reduce order-reconciliation duration from 50 days to just a few days. That's a big deal for a $21 billion-a-year supply chain.
So, for those of you who are so sure that blockchain is pointless end-of-story, it seems like you're not taking into account how messy and expensive it is to manage data and legal contracts with many small business entities throughout supply chains. But I'll read more into the links you sent with your arguments, thanks for that.
Programming language theory does not, in fact, make value judgments, but it does make statements upon which value judgments can be built given context, which contradicts your first statement.
Don't get me wrong -- I think that PLT is a valuable theory, but people are often confused about what it actually studies. PLT most certainly cannot tell us whether certain language designs are desirable or not as that is not what the theory studies. It can't even tell us if certain language designs lead to more correct programs or programs that are easier to read. It does tell us that if certain typing rules are used, then, say, all types in the language can be inferred, or that a system with certain typing rules is sound.
There is some overlap between PLT and formal methods, as that some concepts studied in PLT -- most notably type systems -- can be used for formal verification, but the main thrust of formal methods uses other techniques. Both disciplines heavily rely on formal logic.
https://www.nist.gov/publications/blockchain-technology-over... (page 42)
You are slightly off here. Look at [1], it views over a metric which correlates with language utility and provides 1) result of the metric applied to various languages and 2) reason why some languages can be more of utility (less errors, for example).
"The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means."
It goes without saying that Libra isn't concerned about any sort of security event at Mastercard or a16z. The purpose here is simply to evade and arbitrage different regulatory regimes. The plan is to build a ledger that no single party (or coalition of parties in a single legal jurisdiction) has the capacity to edit or alter, and to make such alterations so technically challenging that it's beyond the capacity of any single court or legislature to do so. Once this chain is up and running, it becomes a "fact of nature" that courts and policymakers will simply have to deal with.
It's a brilliant strategy from that perspective. It's going to be alternately fascinating and horrifying to see if it works.
It would not be impossible for someone to change the observations of the blockchain, manipulate its inputs and outputs, or even change how it operates, as software and hardware are imperfect, along with how we use them. Furthermore, even if the system were technically perfect, political and economic systems do not have to abide by their rules. An oppressive state can simply decide not to deal with them, as the world is in no way bound to being purely rational at all times.
It's like trying to "fix" a painting by using philosophy. One is a series of logical arguments, and the other is paint on canvas; certainly they can influence each other, but they can't solve each other's problems.
I'm not seeing why they need a new cryptocurrency for this. If you grow Bitcoin (or any other existing cryptocurrency) to be "too big to fail", it would also have all these properties. Is starting from scratch with zero users easier?
And that the proposed "solutions", such as the Lightning Network, to this are nowhere near completed (and have indeed suffered from doomsday "someone can steal all my money" type bugs as of recently)
It doesn't seem like a bizarre scenario at all. Consider:
- Real-time control system nodes in Iran's nuclear energy project suddenly started running malicious code, destroying a large number of their centrifuges.
- Crypto AG cipher machines sold to embassies around the world were always running malicious code (or perhaps malicious circuits), giving the US a major advantage in 20th-century diplomacy.
- Google's and Facebook's data centers suddenly started running malicious code as part of the PRISM attack carried out by the NSA.
- Municipalities regularly pay ransomware ransoms because their computers have suddenly started running malicious code.
- Numerous nonprofits organizing conferences have discovered to their dismay that the code running on Paypal's servers is malicious to them, opportunistically freezing their accounts because they have recently received a lot of payments.
- We saw an article last week about how WeChat runs malicious code in their chat application to censor politically controversial images.
- What was the name of that popular NPM package for building pipelines that suddenly started running malicious code on everybody's servers looking for Bitcoin wallets? Was that this year or last year?
I don't think it's at all far-fetched to suggest that if Mastercard or Andreessen Horowitz is in a position to decide how much of other people's money they're entitled to, they might decide that the answer is "all of it". Paypal and Google do this on a regular basis. Here in Argentina, the banking system decided that the answer was "75% of it" in 2001, with respect to dollars; in the US, the Federal Government did precisely the same thing in 1933 with gold.
"Regulators" and "courts" and "legislatures" are indeed among the parties that might decide to confiscate the holdings of participants in some kind of financial system, using various rationalizations. (And that's why "simply enforcing protocol integrity…through legal means" is a less effective solution, as you say.) But they are far from the only ones.
Still, it seems like if that's Fecebutt's motivation, it would just back Bitcoin.
The consensus model of blockchain would at least require Mastercard, Andreessen Horowitz and other validator nodes to be in agreement about stealing / being entitled to the money, which seems less likely. That said, this is one of the flaws of having only a few nodes validating transactions. Libra went this route instead of Bitcoin's proof of work consensus model. With Bitcoin's proof of work consensus, 51% of the miners in the world would have to collude in order to steal funds.
All of the comments I see that say blockchain has no use case, seem to miss another point you raise, in that Bitcoin can not be seized, even by government (like the US government did with Gold), unless they had miner control and the public didn't continue to operate and spin up new miner nodes. This seems unlikely considering that the miners could lose their funds, if they did not prevent a counterparty having 51% control of the network. This is a protection that Bitcoin has, that Libra does not. The government could go to corporations in the Libra association and tell them to do what they want.
In terms of other use cases, I think having an immutable ledger, that can't be changed by one party, or even a few parties with DB access, also seems like a compelling use case for blockchain / cryptocurrency. Libra isn't really a cryptocurrency by this standard though, although Bitcoin is.
Also, just to put it out there, Mastercard, PayPal, Stripe, Visa and a few others already have left the Libra association.
Right, I think you, I, and Libra's developers are in agreement about this being a significant risk and one that using a blockchain effectively mitigates, in precisely the way you say, but Diehl and Green aren't.
+ Since Libra uses a HotStuff variant, you need to control 2/3+ of the voting power to violate safety, i.e., double-spend. In exchange, however, you only need to control 1/3+ to halt progress (liveness).
Edit: Its also pretty ironic that the crypto currency is banking on "too big to fail."
In regards to that, I don't think it's any more bizarre than a SCADA system in an Iranian nuclear enrichment plant suddenly running malicious code. Cyberattacks against financial systems are a very real worry.
In the history of computing, there have been countless times when people casually dismissed a security concern only for it to bite them years later. And oftentimes, trying to add security after the fact is much less successful that designing it to be secure from the get-go. I'm not a fan of Facebook Libra, but I do think that it's misguided to criticize it for having a robust security model with properties that can be reasoned about mathematically.
If they respond to a legal demand saying “Our software won't let us comply”, do you really think that the answer will be “oh well, guess the law doesn't apply to you” and not “halt operations until you are in compliance with the law”?
https://news.ycombinator.com/item?id=21120956
A street vendor in canada was selling cuban coffee. They used "square canada" as a payment processor. Square canada, in turn, used the US bank JPMorgan as a back end. JPMorgan is required to enforce an embargo on money going into cuba. The seller and all the buyers were in canada, but because the money passed through a US bank, they vendor was locked out of thousands of dollars.
We live in a more globally connected world. That should not mean that everyone is (potentially) subject to every nation's laws. It also should not mean that no one is subject to any nation's laws. But enforcing the laws at boundaries seems a whole lot better than enforcing it at every checkpoint along the way. I will not, for example, get out of paying taxes because I received all my money over a blockchain. The sky won't fall.
Well said and paints a clear lack of understanding from OP on the value this provides.
You can replace Libra quote above with your favorite cryptocurrency and that pretty much sums up what I feel on the crypto space.
In general the need for consumer protection mechanisms is of course already a failing of the justice system. Virtually every case where consumer protection is useful is covered by existing laws and shouldn't require anything from the payment facilitator.
...except a lawyer, more money and a non-trivial part of your life.
I don’t know of any state that has ever tried to optimize for a low-overhead justice system “in the small” (e.g. many, more efficient, more convenient small-claims courts; or the introduction of another triage layer of “medium-claims” courts, where most all civil contractual disputes would land) which is an interesting fact all by itself. Speedy+cheap justice goes somewhat hand-in-hand with things like red-tape reduction, in that both are attempts to “oil the wheels” of the state apparatus—yet you’d never hear the same people (e.g. libertarians) espouse both.
Both small-claims courts themselves and rules giving effect to binding arbitration agreements are attempts to do that, as are many specialized, domain-specific administrative forums.
But sure, other than all those things.
A lot of money and research has gone into this, and the tech is being tightened up all the time.
> which increases the risk profile, and thus cost.
Except the cost isn't actually higher.
> You can do this in traditional approaches because you just pass on these costs and there's no need to improve beyond what people are willing to pay.
In the US perhaps, not in places where these costs are regulated.
> Crypto represents...
A much more expensive and more risky way to do basically anything, because you have neither solved security nor trust problems, you've just moved them.
Yeah, but it's not being deployed at consumer level, nor are the savings being passed on.
> A much more expensive and more risky way to do basically anything
Risky, yeah. Like any new technology. But transaction cost is cheaper.
Sorry, I didn't mean to get involved in some holy war. I can see there's people with a lot vested in both sides of the debate. I'm neither. Just pointing out the obvious.
It absolutely is, not sure where you're getting your ideas from here.
> Risky, yeah. Like any new technology. But transaction cost is cheaper.
It's not risky because it's new technology, it's risky because you've passed all the risk to the end user and their opsec. The cost per transaction of something like the VISA network is utterly tiny compared to most cryptocurrency transactions, particularly if you factor in the externalities (mining) and it's a pretty small cost to the merchant as well in places where regulation has been put in place (i.e. not the US). To the consumer it's free. See also bank transfers in most advanced economies.
> Just pointing out the obvious.
You're not pointing out anything that's actually true though.
This was exactly my point. With pervasive crypto end users can assume this to a greater degree, whether you believe that appropriate or not.
Visa e.g. requires specialist terminal equipment, complicated issuer and acquirer and banking relationships and is heavily dependent on legal enforcement wherever you use it. Try using mastercard or visa in a third world country.
For “actual” money transfer, compare with western union where toure talking about ~10% fee.
> ... nothing that’s actually true
Oh you’re a rude one. But I’m sure to somebody you’re very special. Good boy.
It's not a point you made before this, you just said it was "more secure" and "cheaper" without qualification. Now you're just trotting out 'coiner memes about the third world and Western Union.
(You can use Visa in 200 countries by the way)
Have a nice evening, I'm done here.
No, it's not, because the problem being addressed with consumer protection is power imbalance in the marketplace; mutually voluntary mechanisms cannot be the answer to it.
Also, escrow notionally solves exactly the same problem as cryptocurrency: providing the ability to rely on a transaction with an untrusted counterparty. If you need escrow for anything with cryptocurrency, the cryptocurrency is not doing the one thing that is it's defining purpose. So, why cryptocurrency at all?
It's basically the same how a business would recover money from a bad supplier. With small claims court it's even somewhat efficient for small sums, but of course still orders of magnitude more work than a credit card dispute.
Pick your favorite consumer protection mechanism, and I'll pick my favorite cryptocurrency and let's compare:
A) the up front implemention cost of the protection mechanism in fiat currency
B) the up front implemention cost of the protection mechanism in the crypto
C) the year-over-year cost in fiat
D) the year over year cost in crypto
I bet A and C are going to be in the hundreds of millions, if not billions, while B is going to be in the tens of millions and D is going to be in the thousands of dollars.
Here's an example of the kind of thing I'm talking about:
https://www.ccn.com/cardano-to-help-ethiopia-grow-coffee-usi...
Consider the recent news regarding contaminated black market vape cartridges--that's going to be insanely expensive to fix, because there's nothing about high schoolers passing around dollars after school that gives those students any insight into the supply chain of the cartridges they're buying. But if some vape company did with their supply chain what Cardano is trying to do with coffee, they could provide consumers (and authorities) a way to trace their products back to their origins, a capability that already would have saved several lives.
It's not surprising that Libra is a dumpster fire, but let's not throw the baby out with the bathwater.
Blockchains are irrevocable and unalterable, which removes two useful tools (reversing and changing transactions), and replaces them with nothing workable.
Also, there are limits on how old a transaction can be when a bank goes and rewrites history. In my experience the limit is about six months. Transactions older than than are considered settled.
If this is a feature that people want in a cryptocurrency, it shouldn't be hard to achieve with smart contracts. The problem right now is just that you need a solid settlement layer before you work on features supporting the politics of rejiggering unsettled transactions.
Also, provided there is community consensus (this differs based on whether your currency is proof of work or proof is stake) blockchains can be altered after-the-fact to undo a threat. It happens: https://spectrum.ieee.org/tech-talk/telecom/internet/ethereu...
It's just that for most currencies, it's currently a political affair that occurs at a risk to the stability of the overall system. But there are (what appear to be) good technical solutions to that (decred, for example, has a neat approach to post-fork-attempt stability https://medium.com/decred/detailed-analysis-of-decred-fork-r...).
As far as deciding whether a transaction ought to be settled in the first place, people are experimenting with some really interesting approaches (https://particl.wiki/learn/market/mad-escrow for instance).
It's probably not time to forget your bank password and switch to crypto, but if we want to eventually have good solutions to our fraud problems then we should be working to shape crypto into the system we want, not dismissing it as inflexible.
The rest of the things on the list aren't in significant use at the moment, and might never be. Measures that are not ready for prime-time are as good as nonexistent. We're talking about money here!
That's not how technology works. To become fruitful it requires patience and investment. Nobody is saying you have to be an early adopter of these currencies.
> We're talking about money here!
...and particularly whether it's current feature set is amenable to fraud prevention. I work at a traditional payments company and the waste is infuriating--there has to be a better way.
This here is probably the source of our disagreement. As far as I can tell, tons of people actually are saying "get in now", which means we're no longer in the patience and investment stage, and any deficiencies in the cryptocurrency ecosystem have real consequences.
I'm interested in the tech and I want to work on it--so I'm just arguing that we shouldn't dismiss it.
If you have the interest, now might be a good time to diversify in that direction, but it's nowhere near ready to compete with fiat currency in terms of usage by the masses.
But so are events in the real world. When you think about "reversing or changing a transaction" what you really mean is creating a new transaction that brings an equivalent amount back to the person that paid it.
This is done in the real world by knowing the identity of the receiver person or entity and threatening them with consequences if the money is not returned. It seems to me more a problem of being able to identify the parties in a transaction rather than of mutability of the ledger.
1. A scammer cheating someone out of their life savings through social engineering
2. A central bank "unjustly" inflating currency and giving the newly printed money to specific industry/people etc
3. A person paying for merchandise with a stolen credit card or refusing payment after services/good is delivered.
Fiat solves 1 and 3 (recovery) does not think 2 is a problem.
Crypto solves 2 and 3. People say it is meant for solving 1.
Credit card fraud is regulated such that the consumer is protected after a manageable amount of theft, $50 in the US last I looked. If you use a bank you receive some protections but at that point the implantation is abstracted and not that relevant.
IMO Cryrto is significantly worse in case 3.
You can set a withdrawal limit of say, $50 and you can set a few recovery addresses (of friends, family or other personal wallets).
So if I have $10,000 in my ethereum wallet and I post my private key in every forum and every chatroom on the internet then the most I lose is $50. Before 24 hours pass I send my remaining $9,950 to a pre-defined recovery address which is excluded from the withdrawal limit.
Consumer protections are actually pretty good. The trouble is getting these tools in the hands of users.
So, this is strictly worse than using a credit card.
I don't think I ever spend that much in a single day though. The limit will differ from person to person.
>The independent ability to send all your money to a recovery address is a new security risk.
It's not new and it's not a risk. You could always send all your money to another address. And the recovery addresses are meant to be trusted. I could send my money to a secondary wallet sitting in a safe or to a trusted family member. That isn't a risk.
>Further, you need to notice the issue which means you could be our far more than 50$ unless you happen to be checking how much is in the wallet constantly.
Your balance is printed in big letters whenever you open the wallet. It's hard to not notice really. There's also these things called automatic notifications, not difficult to set up.
>So, this is strictly worse than using a credit card.
But this is supposed to replace cash not credit cards. It is objectively better than cash in terms of consumer protections.
> objectively better than cash
Many people don’t use cash just credit cards. They might keep 50$ or less in their wallets, but that’s about it.
Further, Billions of people can hack my PC, only those I come into contact with can take my cash.
>Many people don’t use cash just credit cards. They might keep 50$ or less in their wallets, but that’s about it.
Because they value convenience over privacy and freedom.
>Further, Billions of people can hack my PC, only those I come into contact with can take my cash.
Even if someone managed to gain access to your wallet they would still have to decrypt your private key. So, it isn't an issue if you use a strong password.
It's difficult to argue that low and predictable rates of USD inflation has had more of an adverse impact on holders of USD over the last few years than crypto fraud on holders of crypto.
Indeed, given that most cryptoassets have actually lost significant amounts of value against the USD since the end of 2017, it's difficult even to argue that the crypto world has adequately solved 2
A reputable supplier of vape cartridges gains nothing from having a verified supply chain - people trust them anyway and they maintain a supply of good cartridges to protect that reputation.
A non-reputable supplier of vape cartridges doesn't care, and only sells to people who don't care what they're buying. Their lack of good reputation doesn't matter, and their lack of a verifiable supply chain won't matter either.
If the customer wants a dodgy black market vape cartridge, that's what they'll buy. If they want a quality one from a reputable source, they can already do this.
But still, the perpetrators here are not technically capable of pulling off a convincing forgery, so if the kids were sensitive to this issue in the first place then I guess there would indeed be no reason to insert a blockchain into the situation.
So let's take a scenario where the middle men are indeed capable of convincing forgeries: sneakers. Cardano is working on a supply chain integration there too:
https://beincrypto.com/new-balance-to-use-cardano-technology...
And my wife's students (she's a teacher) are really into their sneakers. They're also largely unaware that chain/web of trust type measures exist at all for validation of product authenticity--but if Nike started doing this, they'd become experts overnight. And then, after school, when offered a sketchy vape product, they might think twice.
Maybe that's a weak argument too. Still, I like the ability to use the same channels you money would flow through to determine if your upcoming purchase came from where you think it did, and I think that that's a capability that's going to be hard for fiat currency to mimic.
Why would blockchain be required for that? In case of drugs and food there recalls are being done using batch number of day of production.
> Joe runs the factory and gave this cartridge to Bob. Bob have it to Mary.
The assumption is that if you buy it then the site will then say:
> And Mary gave it to aiCeivi9
What reason do you have to believe that the website contents are accurate or that people accepting vape cartridges from Joe Bob and Mary are still alive?
In the blockchain case, you can see that Joe Bob and Mary have sold thousands of these and that very few of the transactions are in dispute over authenticity. Also, rather than trusting some faceless 4.6 star rating you can see which of the people that supplied the rating are ones that you know, and which of those are ones that you trust. You can also see if you trust people who trust Joe Bob and Mary. This let's you make a more informed decision about the quality of the thing you're buying.
Bitcoin is incredibly wasteful. If we're talking about digital transactions we already have credit cards and digital transfers. A block chain isn't required for those benefits.
Supply chain tracking is interesting but literally no one is talking about that. Its also an even harder problem. Its really not verifiable at all because you're now relying on data from outside the chain, ie how many widgets were created, whether the label on the real life widget is unique or forged, etc.
Also, what kind of consumer protections would you want to see in a currency? It seems to me that ensuring that you actually got what you paid for pretty much sums it up but I'm probably overlooking something.
As a parent of children, consumer protections are overall a "good thing" to help prevent bad actors from doing harm. It goes for any space that can do harm to you or your family in any way.
It's why you have exchanges like Gemini in place that seek to be the "most regulated" crypto exchange - to instill trust in the service and market... and your investment.
That being said there is still a ways to go... it will be interesting to see if the market can solve some of these issues through natural growth and competition.
Personally, I want orphans (as defined as minors with no living parents) to be well-cared for regardless, either by relatives or by an outside agency ("orphanage" or foster home).
Even when everyone's an adult, consumer protections can be very important -- e.g. to prevent things like lending crises.
Invoking family to make an ethical point is something I see often, in many different circumstances.
1. Inflation eats 2-4% of everyone's purchasing power each year, disproportionately affecting the poor. This inflation is desired by the central planners.
2. The American system of banking regulations introduces systemic risk into the financial sector.
Sure, if you can prove that your transaction was fraudulent, you can get a couple thousand bucks back into your savings account. But you'll have to gamble your money in the market to beat inflation just to break even. And then, every so often, the entire system will collapse and destroy trillions of dollars of wealth.
As an aside, you also get the bonus of having political control of banking relationships, so you can conveniently freeze and take the money of those who find the political winds aren't blowing their way.
Edit: PLEASE don't take this is an argument for Libra (sorry I wasn't clear), merely an argument for sound monetary policy and decentralization.
Inflation is an incentive to invest. If you invest in literally anything other than cash under your mattress inflation stops mattering completely to you, and all you have to think about is constant dollar returns. That’s why we have it. So long as your wages track inflation (broadly they do) you benefit from implicit depreciation in your debt obligations. It costs you nothing if you don’t hold cash like you’re supposed to, and it costs you effectively nothing if you hold money in a savings account as many offer 1.8% interest these days, matching inflation.
What nobody arguing for a deflationary currency can tell me is why they think money should be worth more later solely by virtue of them having gotten it first. A risk-free guaranteed return at the expense of the next generation! It makes no sense.
This is basic ECON 101. High school level home ec probably. Not some big conspiracy perpetrated by the central banking cabal.
As I mentioned before a dollar today should be worth more than a dollar next year since, if you are smart, you can make that dollar work for you for a whole year.
Hence the inflation.
You have not explained why; you've explained why you think we should have inflation. And why someone thinks something should be is a long way from explaining why something is.
The same amount will be worth less in the future! That's really all there is to it. A certain amount of money is not value, money is a number that has a value associated with it, that value will continuously change depending on what you can do with it.
Inflation (deflation) simply reflect the change in value for doing something today versus tomorrow. When the economy works well you have inflation, when the economy works badly it becomes deflation.
This is backward, actually. If the economy is working well then withholding consumption (i.e. saving) means that more goods are available for others to either consume or invest. The portion that ends up invested should result in higher future productivity and, in the absence of currency supply manipulation, decreasing prices (deflation), a natural reward for producing more than one consumes.
Only in an economy which is consuming capital—investing so little that productivity is actually decreasing—should prices increase over time. In that case we need more investment to bump up production—the investments don't need to be all that good to be better than the status quo, and anything with a positive return is superior to just waiting for prices to increase further. In the deflationary case, however, we should be more selective about where we invest. It's better for the economy to simply hold our funds in reserve rather than actively compete against more competent investors to expend resources—not just money, but the labor and material it represents—on ventures that will provide lower-than-average returns.
If we expand the currency supply to manufacture inflation and thus make it look like we need more investment when we actually don't then the net result is malinvestment, wasted resources, and a lower average rate of return. It's not good for the economy or the average citizen, but the extra transactions and higher nominal prices directly benefit the bankers and tax collectors with influence over monetary policy.
Low inflation is a good thing - it is a sign of a properly functioning economy. A dollar today should be worth more than a dollar tomorrow.
Too much inflation is not a good thing is usually sign of systemic failures of trust in a system.
The two stages are usually conflated in many discussions.
But as you say, inflation is a tool; it motivates investment. Expropriation is a tool; I don't see how eliminating it is appealing at all to the billions of people with no savings at all. They may want to take money from the wealthy at some point.
If there's ever a point where "the masses" really understand bitcoin, and how a few HODLers possess most of it's value, they're not going to want it.
I don't know where you live but I doubt it's western Europe. In the Netherlands for example, the highest interest rate available [1] is a lousy 0.2%.
Because it is my choice? If you want to use an inflationary currency, go ahead. But other people should have the option of opting out, and using a different currency, with different properties
My justification is freedom of choice. Or, in other words, the reason is "because I want it to, and I am justified in making my own free decisions".
I believe it is people's right to choose which money system that they want, and you should not have the right to prevent other people's voluntary choice to use a different money system.
I am justifying why people should be allowed to make their own decisions about what money system that they use.
Freedom of choice is a valuable principle in and of itself.
You cannot just dismiss this important concept of freedom of choice. It applies to all parts of society.
The only justification I need, is that I do not want people's freedoms to be infrindged upon.
You're intentionally not answering my question which is: explain to me what benefit to society could potentially arise from money being worth more over time?
I'm not saying you can't do it I'm asking you why. It seems you and everyone else can't point to anything other than making yourselves wealthy.
Long version: https://news.ycombinator.com/item?id=21457114
Freedom is something that many people care about and value.
The benefit is also that different people want different things in their own money system, and a diversity of things and monetary systems is good, merely because of the money systems being different.
There is value in having differing money systems with different properties (merely because they are different!), and letting the market decide which one is best.
So a direct answer to your question is "because it is different from what we have now", and more diversity in monetary properties is a good thing.
One can use the desired amount of third parties for fund protection.
The new thing about cryptocurrencies, is that some of these third-party services can be made non-custodial, so the third-party never has access to your funds. They arbiter, but not transmit.
I don't give 2 shits about Libra. Gov'ts will clobber it anyway. But these criticisms are mostly "why didn't Libra do the latest bleeding edge researchy thing that no-one else does?" Because they had to ship this century, that's why.
It's amazing to me that nearly every single expert that weighs in on this topic completely misses the intention behind Libra. Facebook wants to make money off of it's massive user gains in the developing world (like hundreds of millions of users massive), but many of those people don't have digital money right now. Libra wants to be their digital money so Facebook can sell more expensive ads.
It's really as simple as that. Move on from the "why" and talk about the rest of it which is the actually problematic part.
> The claim of the Move language to use of linear types appears to be unsubstantiated by a dive into the compiler as it reveals no such typechecker logic. As far as one can tell the whitepaper cites the canonical literature from Girard and Pierce and does nothing of the sort in the actual implementation.
How can I know this? Well, how do all these credit cards that offer cashback bonuses in the realm of typically 1-2% make this unbelievable feat of paying you for paying stuff happen? They pay for it out of the 2-3% that they get for the transaction. Let's take 2.5% as a middle ground and deduce 2% cashback, that leaves us with 0.5% from which the actual costs of doing the payment have to be covered - and the profits to be paid to shareholders, of course.
Also, Europe has this nice regulation in place limiting credit and debit card interchange fees to 0.3% for credit and 0.2% for debit cards. This regulation has been in effect for a few years already, and the only thing that disappeared were these 2%-cashback-on-every-payment cards (or similar offerings, like granting airplane miles of about the same value). Debit and credit card issuers seem to be entirely able to operate under these conditions, which means that their actual costs of doing business must be under these fractions of a percent.
Refusing to rely on legal means of enforcement suggests the project views itself supreme over all national policies, laws and regulations. On the one hand, such a concept is usually the domain of autocrats, despots, and organized crime-- odd for a tech startup. On the other hand, it would suggest a system more secure from outside legal interference than, say, MasterCard. This detail tends to add a datapoint explaining the lack of support from global ministers of finance....
https://blog.quarkslab.com/security-audit-of-dalek-libraries...
Sure the current payment systems have a lot of problems. But many come from complicated regulations which makes building such systems harder not incompetent bank IT. I fear a single company can't do to much here. Especially because banking software has to be reliable from the get-to-go.
However, use of a BFT consensus algorithm, newish crypto libraries, and missing but promised features in an unlaunched product are not reasonable criticisms.
BFT algorithms that scale well (Libra's will, that's one thing Facebook is good at) are great for public financial networks. All large companies end up implementing their own crypto libraries and for some (Google, Facebook) this ends up a net positive for the open source community.
Consumer protection will be there, Facebook is not going to knowingly violate local regulations in such an obvious way.
When in fact there has been a review, and probably more internal audits that haven't been published: https://blog.quarkslab.com/security-audit-of-dalek-libraries...
I'm a blockchain skeptic but come on
1) It charges ECONOMIC RENTS. The ethical asset backed and currency backed stable coin needs to pass profits from revenue generating assets to the currency holder. The member companies should only take a tiny slice of the profits. This is the MASSIVE problem.
2) Libra is designed that ECONOMIC RENTS will be sharecropped and sent to the member companies. This will be the economic incentives for them to force it on their customer base and create incredibly fast adoption. This is a good thing, except it turns evil by the economic rents from #1.
The proven business models are "evil" to some population: 1. Charge fees (like paypal, stripe, bank ach / wires), 2. Collect interest via economic rents, or 3. Capture and monetize user data ala Facebook.
Can you think of a better way to jumpstart a new monetary network?
https://en.wikipedia.org/wiki/Electronic_cash#Costs
You may think 0.3% isn't much, but with razor-thin profit margins (e.g. groceries) it does make a difference.
Also, in order to use EC, you need a bank account, so it doesn't help the unbanked, which do exist even in Europe.
Transaction fees are a real thing, but essentially that covers keeping fraud out of the system. In cryptocurrency that's your problem, and many of the "solutions" are riskier and in the end more expensive.
There's a decent argument to be had that they make products cheaper.
What, you didn't think it was free to handle cash, did you? It takes time and effort to do that. So much time and effort that a lot of smaller places are going card-only here in the UK so they don't have to deal with cash.
In particular, you should consider the ludicrous fees that the unbanked are paying for basic services.
More competition is only going to drive that rent down further towards marginal cost.
Having low friction payments on Facebook makes sense, it build value into the platform and Facebook can capture some of that. But can't they do that with an existing cryptocurrency?
It doesn't seem like Facebook will maintain full control of the currency due to the consensus algorithm. There is power and control if Facebook continues to control the fork of the code base that everyone uses, but presumably nodes could choose to switch away from Facebook's fork. So I'm not seeing "control a currency" as a long term benefit.
It makes sense that anyone running a Libra node would make money, but anyone else running a node would make similar profit.
The article mentions that a long term goal could be "act as a data broker and mediate consumers access to credit", although again, doesn't the decentralized nature permit any node from taking those steps? That doesn't seem to uniquely advantage Facebook.
As others mention, once a cryptocurrency is "too big to fail", regulators are locked out. Is Libra really an easier approach to getting a cryptocurrency to that point, versus adopting and accelerating the growth of an existing coin (like Bitcoin)?
Does Facebook just think they can build a better cryptocurrency? I don't doubt that they can hire good engineers, but with all the politics and marketing focus on the code now, development is probably getting stressful and chaotic.
In a world where "everyone" uses Libra, they need a FB account to access their wallet, and FB will see every consumer decision at its most valuable - the point of exchanging money for goods and services. This is immensely valuable for an ad company.
This was a bit of a throw away line, but I found it insightful. As someone who isn't in this space, my question is: why is this? Is it contractual, or is that just not part of the space's ethos?
Feels like we need to overcome this some how to achieve progress?
That being said though, take or leave by following boiled down opinion on the matter that it is essentially just a form of greed that drives this ethos you highlight. It's both negative greed of people not wanting to discuss their secret sauce that does or could make them rich and wealthy, especially if and when it comes as the expense of others (regardless of whether it is only their sub-conscience that acknowledges it), not wanting to expose things like the spaghetti code that makes up the core of a multi-trillion dollar enterprise of maybe even the literal fraud being perpetrated to achieve riches, some self-delusion that obfuscation quals security that hopefully will prevent nefarious actors gaining insights.
The very nature of the financial industry, a store of value, worth, and a huge closet of misdeeds and fraud that is chocked full and bursting at the seams to reveal the putrid innards; makes it a massively sensitive matter and domain. The behaviors and actions or ethos of the financial industry is not at all dissimilar to when you interact with other dishonest and nefarious and secretive types who have dirty secrets to hide and ill gotten gains to obscure and squirrel away. But there is also a layer of honesty that must be maintained. The notion of "disrupting" the financial sector with the trademark wonton recklessness of the Silicon Valley mentality gives me shivers, because when, e.g., the WeWork fraud
One may as well have asked why African government officials don't publicly speak about how their government work or ask the CCP how China really works. But one could also even ask that question closer to home like how massively lossy Silicone Valley unicorns can exist or one may also ask for an audit of the DoD (which, interestingly, the recent attempt to audit the Marines led to the Auditor refusing to sign the audit) or the Federal Reserve (a set of private bankers that control the money supply without any accountability, oversight, let alone limits or balance of powers). Those are ALL equally sketchy and nefarious deceptive and manipulative smoke and mirrors slight of hand operations that one could ask the same question of why does not one speak publicly about their work.
You may be one of those that realizes that there is a thread that runs between all of the above.
What pieces of financial infrastructure do you want to know about?
Mastercard and Visa (for example) publish a lot of information about their technology and standards, and certainly people aren't prohibited from talking about implementing them or interfacing with them.
The financial sector is many things, it's a lubricant of the economy, it is a prediction machine, it's a fascilitator of markets, but not least important it is setup as a game, where every player tries to outsmart the others. Why would you talk about how you are playing and give your opponents a chance to outplay you?
(Fun fact: Statistics was invented many times throughout history. Minus the last time, it was always hidden to make someone money.)
Even when you've got awesome secrets, you've still got other parts of the business. Open research moves faster. Libraries of books have been written about investment, or running a business, or writing software, or other profitable things. Granted, some of that comes from people teaching without acting -- but a lot of it too comes from actors with serious skin in the game.
I build financial market infrastructure and in the last twelve months I've seen companies in my industry presenting at AWS and Splunk conferences, and a Cassandra meetup.
There are lots of great technologists in the space that are just like the rest of us and love sharing ideas. There are definitely NDAs in place, but "financial infrastructure" generally refers to processing systems, not trading systems. The former is increasingly utilized, while the latter generates alpha (i.e. where you actually make money).
People like sharing ideas about processing infrastructure because everyone benefits when the rest of the market gets better at it also. Your efficiency is only as good as your counterparties' efficiency. If their system breaks, you still have a broken trade that costs you operational time and money no matter how good your infrastructure is.
There is a lot more wrong with what this author wrote, but in the interest of time I'll keep my answer to the question asked.
1) it's complex and relies on a bunch of concepts that are niche/uncommon in tech field, so it's really hard to make a short answer that makes your point understandable without adding an essay-length explanation about why some assertion of fact is actually true, or how some aspect of the financial system works slightly differently than the common understanding and has serious implications that usually doesn't matter only because the system is carefully engineered to ensure that this never happens, but for a different system it would matter.
2) you can't have a purely technical discussion because pretty much every factor of infrastructure is part technical, part legal, part financial, and you can't really separate these aspects because they put serious constraints on each other.
3) it's a bit emotionally unpleasant because multiple important, relevant aspects have political connotations and invite passionate debate about things that I'd like to assume as axiomatic and offtopic to the main point. For example if we want to debate why technical payment systems are the way they are and what other technical payment systems are plausible in the short-term, aspects like the need for reversibility are pretty much an undisputable unavoidable constraint from the legal/economic side to the technical part; IMHO any productive technical debate is possible only about how to best design systems within these non-technical constraints (and what exactly are the actual constraints), but a lot of the discussion here is centered whether these constraints "should" be there - which is interesting but a completely different topic, to note the "is-vs-ought" distinction, debating whether reversibility (or, say, KYC/AML) ought to be a requirement has absolutely no relevance to the debate whether and when it is a requirement. But it's hard to make a technical description of how/why something works without getting sidetracked into a political discussion of whether some must-have requirement should have a right to exist.
There's not really an ethos of secrecy (at least for the main infrastructure side), all the technical and legal (but not financial) details are generally available to whoever is interested but they are large and details matter, and key details differ between countries. Seriously, when getting started in the industry when I had spent months reading on various details of e.g. card issuing/acquiring process, I thought I had a reasonable understanding.... and now I know how a bunch of that understanding was slightly but dangerously wrong.
Hmm, I'm not sure I'm convinced. While "Mastercard as an entity turns into a malicious actor" doesn't seem like an important threat model, it seems to me maybe guarding against mailicious actors within (eg) Mastercard, as well as external attacks on Mastercard is? And justifies this stuff?
The possibliity that a node run by Mastercard would suddenly start running malcicious code doesn't seem that bizarre a scenario to me, if we remember it can happen not just cause the CEO of Mastercard directs it to, but because of criminal activities from hackers as well as employees for their own gain.
Am I wrong?
Some people have the tendency to think that technology could solve anything and should be allowed to solve everything. This Libra thing is no better than the crypto-currencies.
For example, governments, in the past, have tried to prevent bank transactions from being sent to wiki leaks, even though they were never charged with any crimes.
The credit card transactions failed to go through, but the crypto transactions DID succeed.
Crypto currencies seem to have done a pretty good job so far, of preventing this attack vector.
I can think of no examples where a government has taken over a crypto currency yet.
Some issues, however:
1. His argument against BFT is "legal systems are efficient" (lmao). Also, the whole point of HotStuff (vs. PBFT etc...) is linear O(N) communication complexity outside of cascading proposer failures...
2. He clearly didn't investigate move bytecode-verifier, which asserts linearity.
3. Strong disagree on the untested crypto-primitives argument. curve25519-dalek is audited (x2) and written in Rust; simple and minimal; not a bloated, unauditable mess like TLS.
4. Consumer protection can be built on top via the wallet providers.
<The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case.>
<Libra has no transaction privacy>
<The system is designed to be a very large way of replicating transactions to a number of external parties who under existing European and US bank secrecy laws should not be privy to the economic details.>
<Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail.>
<Libra’s Move language is not sound.>
<Libra’s cryptography engineering is unsound.>
<Libra has no capacity for consumer protection mechanisms.>
Creepy as hell... but it’s good that the excesses of online tracking have brought this whole “dark entanglement” into public scrutiny.
^ This. The rest is moot.
BFT is still useful in that scenario as part of a defense-in-depth against compromise of some of the validators/nodes, yes even ones run by Mastercard or A16Z.
It’s certainly more difficult for that to happen in these settings, but given the state of the world with nation states rampantly hacking each other in any way they can of varying levels of sophistication, from social engineering to stealing user databases to stuxnet, having an extra layer defenses against that in a global currency is not superflous.
And that’s what Libra is, a global currency, not a mere payment system.
So assuming the transactions are accessible to anyone (and even encrypted is somewhat worrisome), what are the implications? Well, for a while Whole Foods was accepting payment by Bitcoin. That means if you know Whole Foods' Bitcoin account number you could simply look up all transactions to Whole Foods to see how much money they were making through Bitcoin, how many unique accounts paid them as well was when and how much. Does every business want their detailed transaction history to be public?
And on a personal level, I remember when Netflix released anonymized data of movie ratings with ratings and date stamps. From this alone, some people were identified by looking at other personalizing data: https://www.wired.com/2007/12/why-anonymous-data-sometimes-i...
All it would take is one data harvesting company to pair your account to your transactions and then could track everything you do through it. I really hope this isn't how all of this works... and even if there are protections to prevent this, it seems like a viable attack vector to consider for any blockchain technology.
They wouldn't have just one "account number". Standard practice is to use a different address for each transaction, both for privacy and for increased security. (An attacker only has the public key hash to work from for any unspent transactions, not the full public key.) Now, these funds would probably be consolidated into a smaller number of holding accounts, and you might be able to deduce some other likely payments to Whole Foods by looking at which inputs were combined together in later transactions, but obtaining their complete ledger is nowhere near as simple as looking at one payment to Whole Foods and finding all the other transactions involving the same address.
Bitcoin, Ethereum and EOS have optimized away the exponential problem of O(n^2) byzantine tolerance. I'd be careful that that is just a short-term artifact of getting an early version running.
public withdraw_from_sender(amount:u64): Coin {
let transaction_sender_address: address = GetTxnSenderAddress();
...
}
Checking the global txn sender address is not a sound way to authorize a transaction in a smart contract language. Consider that a buggy or malicious function in a different smart contract could call withdraw(). Linear type theory might prevent the resulting stolen coins from being duplicated, but they're still stolen.I don't know if there is a clean theoretically sound way to do this, but here's an idea based on linear types:
The main function in a transaction is given a Sender object as one of its arguments. The Sender has a method that generates an assertion (an object) that the transaction intends to perform a specific action, e.g. withdraw 10 coins of type A. The withdraw() function takes an assertion as a parameter and calls a method that consumes the assertion before withdrawing the coins.
> Byzantine fault tolerance is a fairly niche area of distributed systems research that concerns the ability of a networked system to endure arbitrary failures of its components while taking corrective actions critical to the system’s operation. Networks that are byzantine tolerant must resist several types of attacks including restarts, crashes, malicious payloads, and malicious voting in leader elections. This design decision is central to Libra and it makes zero sense.
BFT consensus is standard in blockchain. Libra is building a protocol and reference implementation but anyone can build their own implementation, just as Bitcoin and Ethereum have several clients written independently as separate open source projects. As Facebook intends to be just one member of the Libra consortium, and anyone (member or not) can write software to the protocol spec, BFT is the logical choice.
If Libra was trying to be a centralized entity owned by Facebook, then BFT consensus would make no sense. But it's not - Libra is supposed to be a decentralized blockchain payment system, similar to Bitcoin, so BFT is the logical (and standard!) choice.
> Libra has no transaction privacy. By the admission of the whitepaper the system is designed to be pseudonymous meaning the addresses used at the protocol are derived from elliptic curve public keys and contain no metadata about the accounts.
This means the same level of anonymity as provided by Bitcoin. Post-transaction analysis may identify the owners of keys by cross-referencing known addresses, but onchain it is unknown. Again, very standard in blockchain. There are various techniques to improve privacy, such as how SiaCoin generates new addresses for every transaction by default, but again I want to emphasize that the shrill language used by the author is coming from someone who doesn't understand the technology. I agree with him that Facebook could (and probably will) improve on Bitcoin's pseudo-anonymity, but claiming outright that this is some sort of grand oversight is just plain wrong.
> Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail... There is no technical reason that cross border payments could also not settle instantly, except for the differences in rules and requirements across the jurisdictions involved.
This is more about the philosophy of our payments infrastructure. Let's assume Facebook solves scaling, which is a problem many blockchains have solved (or are solving) in various ways. For example, Bitcoin's lightning network moves small transactions off-chain to settle later in one transaction that batches them. I'm not saying that's a good solution, either for Bitcoin or for Libra, I'm just saying the scaling problem can be solved even if the consensus algorithm is limiting.
On the question of "why use blockchain for payments at all", this is more philosophical. You have monopoly-controlled payment systems that tightly control who can integrate with them and improvements to the core level take years / decades (see ACH in the USA). Blockchain is one major way that software is eating finance - companies and individuals will be able to hack away at the system and build novel innovations with much less friction. Whether you think this is a good thing is a matter of philosophy.
> Libra’s Move language is not sound... In the public blockchains, smart contracts refer to logic deployed on public networks which allows escrowing, laundering money, and the issuance of extralegal securities and gambling products. These are typically done in a shockingly badly designed language called Solidity, which from an academic PL perspective, makes PHP look like a work of genius.
Clearly biased, Solidity has its warts but it is successfully being used for billions of dollars in real-world transactions per day. The author is something of a compiler hacker according to his Github so I assume he feels qualified and passionate to speak on this. But Move has not been battle-tested yet so I would at least let it get finished and deployed before claiming it's dead-on-arrival.
> Libra’s cryptography engineering is unsound.
Facebook, like many other companies, can pay for audits and formal verification of crypto libraries. As Libra will not be production-ready for years (it isn't live today!), I think we can give Facebook the benefit of the doubt on this. They are a massive company with near-limitless resources.
I want to conclude by saying that blockchain and cryptocurrency are knee-jerk hated by Hacker News, and have been so for years. You typically won't find positive (or even neutral) opinions on it, nor casual HN comments discussing the minutiae of the underlying tech the way you would for (say) Rust.
People who are deep into this scene are posting on other websites that aren't as negative on the subject. There are indeed highly technical and competent people who work in this space. However it remains quite niche given its outsized mindshare in society. I encourage people to keep an open mind, there are very interesting problems to be solved if you can avoid the overwhelming criticism.
What other technical analyses of the Libra software are there? So far I've seen this and Elaine Ou - who I'm sure you would concede knows a thing or two about the space, even as she's a bitcoin maximalist - being shocked at how incomplete the code dump was: https://www.bloomberg.com/opinion/articles/2019-06-20/facebo...
That's a lot of benefit of the doubt! There are situations in which such generosity is warranted, but this is not one of them. "Move fast and break the financial system" is a philosophy we've seen play out before. It's bad.
(I find particularly strange the idea that we should give them the benefit of the doubt because they're a huge rich company.)
> > Libra has no transaction privacy. ... > This means the same level of anonymity as > provided by Bitcoin.
Diehls' point regarding privacy is not that pseudonimity is inherently bad. It seemed to be that pseudonymous networks (like Libra or Blockchain) do not satisfy US or EU legal requirements.
> I want to conclude by saying that blockchain and > cryptocurrency are knee-jerk hated by Hacker News,
Ad-hominem arguments are unhelpful.
There's a very big difference between Libra and Bitcoin. In Bitcoin miners can come and go as they please, and they don't have to be known or trusted. Bitcoin's innovation with POW was to make this possible at all.
In Libra the consensus nodes are known, making POW unnecessary.
Suppose that I'm working in the insurance industry and I want my company A to share the ownership of some code (and its execution) with company B. It's a redundant piece of code that would otherwise be implemented in both companies internally.
We may share a repository. That's simple and clear. But who is going to run this code? How do I know that the code running is the one shown in the shared repository?
When I see things like Hyperledger Fabric, I see a possible solution to this problem (although I don't know about the downsides of Fabric). I can ensure that, given the same inputs, all parties will produce the same outputs. This seems like a fair use for a permissioned blockchain and smart contracts.
But what else is out there? How would you approach this problem?
Mark Carney (current Bank of England governor) has been warming up to the idea - https://www.theguardian.com/business/2019/jun/20/mark-carney...
Not sure if that because he is setting himself up for a new job at Libra after his BoE gig finishes in 2 months, or is there merit to the idea and appetite from central bankers?
Why would they though ? I can transfer money worldwide in a few hours for very little fees already. Normal currencies are good for 99.99% of use cases. Aren't most currencies already mostly digital, they're literally integers in databases around the world, most of it isn't backed by any physical currency.
Facebook wants its own currency because it would allow granular tracking and profiling like never before. What would banks gain from it ?
1) Geopolitical - if there was a widely accepted, regulated global currency that is relatively non-volatile, pegged on a basket of assets, I think many countries would gladly do cross-border trade in that rather than USD. I don't think Libra will be it, because it's perceived as being Facebook coin. But an effort from central banks could be it.
2) mainstream programmable money doesn't really exist, neither do microtransactions, or access to the financial system for many of the world's poor
Because they already have one? And it comes with handy features such as being available in paper form, storable in a regular DB, relatively stable and manipulatable and easy for everyone to understand. And a whole host of other goodies gleaned out of 400 years of attempting to keep the gears moving while keeping economic implosion to the bare minimum.
> The possibility that a Libra node run by Mastercard or Andressen Horrowitz would suddenly start running malicious code is such a bizarre scenario to plan for and is better solved by simply enforcing protocol integrity and through non-technical (i.e. legal) means.
> The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case.
> ... the model as proposed is hundreds of person-years away from being able to handle global transaction throughput and would likely have to be completely redesigned from first principles.
> Enterprise software consultants generally thrive on ambiguity and smart contracts are the apotheosis of enterprise obscurantism because they can be defined to mean literally anything.
> It should be assumed this entire crypto stack is vulnerable to a variety of attacks until proven otherwise. The “move fast and break things” model should not apply to cryptographic tools handling consumer financial data.
> The final conclusion one must take away after doing technical due diligence on this project is this simply that it would not pass muster in any respected journal on distributed systems research or financial engineering. Before trying to disrupt global monetary policy there is a massive amount of a technical work needed to build a reliable network the public and regulators could trust to securely handle user data.
> I see no reason to believe that Facebook has done the technical work needed to overcome these technical issues in their project, not does it have any technical advantage over existing infrastructure that already works. Claiming one’s company needs regulatory flexibility to explore innovation is not an excuse for not doing it in the first place.
I may be behind on Libra news, but my understanding was that the permissioned blockchain governance model would only exist during the bootstrapping phase to launch Libra and would eventually evolve into a public blockchain once it reaches some arbitrary point of stability. If that is still the case, then wouldn't Byzantine fault tolerance be required from the get-go, assuming Facebook wants to avoid a hard fork of Libra?
You need to comparison-shop the price of remittance: https://www.saveonsend.com/blog/welcome/#more-1
> "Libra is not welcome on European soil," French Economy Minister Bruno Le Maire told reporters the sidelines of the annual meetings of the World Bank and International Monetary Fund
> "Do we want to put monetary policy in the hands of a private company like Facebook? My answer is clearly no," he said
[0]: https://www.business-standard.com/article/pti-stories/paris-...
They would fall under all possible kinds and manners of banking regulation, but it's viable; many companies originally outside of the fin sector are offering financial services now (notably Orange, the French leading and historical ISP, formerly a state-owned public company).
This would likely result in some tiny fee when crossing in/out of the traditional banking sector (from/to Libra and some regular account or merchant paying system), and maybe when entering/leaving Europe, but would remain largely free for Libra transactions within the EU.
Which, as I see it, is the purpose of said regulation: to protect EU citizens (account insurance up to €100K, rights to certain features like free inter-bank transfers within the EU, etc). Libra unregulated would basically fall to Facebook's unilateral rules for protection and features, and that just isn't acceptable to the EU.
To me, it's increasingly looking like they're heading for Calibra as PayPal-but-it's-Facebook. This is a more sane and comprehensible business idea, at least.
Basically just a layer of abstraction like in-game currency in virtual worlds, only this one has some 2.2b 'players' so the in-world PayPal is one hell of an easy way to transfer money?
That's much less sexy from a technological and social standpoint, but it might just be the simplest way to both reach a solution and seduce just enough blockchain lovers for the 'buzz' (best fueled by Controvery®).
When you think about it, people use items as secondary currency to exchange real-world money since forever and a day. E.g casino chips (physical), in-game assets ("virtual" but really we just mean software i.e. codified text, like we'd write score cards in tabletop RPG, or... computer punched cards). Colibra, fundamentally, would be just that...
So much ado about nothing if it turns out to be such a custodial abstraction. Now I expect Colibra lootboxes and gift shops in WhatsApp and Instagram! — once you've seen people spend hundreds on pixels in games, cosmetic shaders to embellish their avatar, you know there's no limit to human commerce. Probably Facebook's endgame with Libra if you ask me.
Libra is several things, most of which will be hard/impossible to block without new laws and also blocking a large amount of currently legal things. So, blocking all of it is not a thing.
First it's an oss blockchain platform. It's similar in design to several other blockchain platforms; none of which are currently banned anywhere. Banning software is (mostly) not a thing.
Once it gets to a stable state, somebody will fire up some nodes and a Libra network comes into existence. If other blockchains are any indication, there's a good chance there will be multiple of these (e.g. testing and public). Blockchain networks don't get commonly blocked and you can legally connect to most blockchains out there from most countries. Blocking blockchain access is not a thing.
Then it is a legal entity based in Switzerland with representatives from lots of companies (though minus a few of course as of a few weeks ago). This too is nothing special. Doing business with, being a member of, or interacting with this legal entity is not subject to blocking either.
Then there are the countless financial products, tokens, etc. you can build on top of Libra, most of which are going to be similar to other stuff out there and many of which are not currently illegal or blocked in the EU or the US.
One of those things is the Libra coin. As such coins don't get blocked but the organizations that create them are subject to legislation. The controversial thing about Libra is related to how Facebook intends to implement mechanisms for controlling its value. These are in scope for legislative action.
Once all this is up and running, Facebook plans to integrate some kind of wallet type solution to do payments into their products. That would be similar to Paypal, Android Pay, WeChat, and other stuff in this space. Payment solutions as such are fine as well. Payment solutions using some kind of stable coin are also fine. Several fintech companies already do this, legally.
So, Facebook and the Libra foundation have quite a bit of wiggle room to make most of the above a reality. Yes there would be legal hurdles. The only thing that stands out is Facebook's intention to do market making (via the Libra Association) this is the bit that is controversial. When politicians say they want to ban Libra, what they are saying is that they want to ban all of it because of this market making. The reality is that they will likely try to create some legal hurdles for the market making. Facebook can then choose to work around those.
E.g., you could feasibly implement some alternate coins (simple euro and dollar stable coins like already exist on exchanges) and Facebook has already indicated that they are thinking of doing exactly that.
IMHO it is entirely likely that Facebook may give in to the political pressure to not do this given that they already are under pressure on other fronts. This would happen before they get blocked. But if they push through with this, it's very likely that the legal and political fights around this will be very lengthy. Legislation around this topic will be slow and translating the uninformed but widely spread sentiment "we don't like this" into concrete action is not likely to happen fast.
"no private entity can claim monetary power, which is inherent to the sovereignty of nations"
It's a legal move. Not a technical one.
Regarding privacy — it seemed obvious to me that privacy solutions for Libra would be build on top of Libra (the so-called "Layer 2") and not within the core protocol.
Stephen's critique here is bizarre and lacks context.
I'm also obviously biased, but if people are interested in my opinion (and only my own) here it goes.
> Libra’s byzantine tolerance on a permissioned network is an incoherent design.
There are two aspects here that the author seems to forget:
* The next best system, that a consortium of very different companies (think from different countries) would agree to run together is probably a protocol like Certificate Transparency which would be too slow and would have no mechanism to prevent double spending. If you're not doing this, then you're probably using a protocol that doesn't tolerate faults and the first time you have a fault your protocol collapses. There's probably a reason that Venmo cannot talk to Paypal which cannot talk to Square.
* Libra will eventually move to a permissionless setting, which means it has to be designed from scratch to support this evolutionary change. You can agree or not with this, but this is the way it was planned.
> Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail.
Two things again:
* The number of people in the world who uses GBP vs the number of people who will use Libra at launch is probably not comparable. This means that Libra will be perfectly fine to carry the load for a number of years.
* Current research has shown that the largest throughput improvements are hidden in layer 2. If you don't know what layer 2 is: basically you do transactions off-chain, with whatever protocol you have, and only sometimes do you confirm the current state on the chain.
> Libra’s Move language is not sound.
I believe the type checking (and other checks) are done by the VM, (but that's not my domain so I might be wrong). Indeed, why would you trust the compiler to do the right thing?
> Libra’s cryptography engineering is unsound.
There are two things in this section that are completely wrong:
* No, dalek is not the "wild west” and is actually written by some of the few people who you could trust to write such a library. Yet, audits are planned. Also: we do actually use formally verified code! We have integrated fiat-crypto (a formally verified library, not a cryptocurrency :D) into dalek in order to use formally verified field operations.
* Neither do we use VRFs, bilinear pairings, and threshold signatures (they are just experimentations at this point) nor are these new tools or techniques. I don't have to say much at this point but I would take the author "It should be assumed this entire crypto stack is vulnerable to a variety of attacks" with a huge grain of salt.
> Libra has no capacity for consumer protection mechanisms.
Of course, it is a financial backbone, not a financial service.
Eh, I'm not so sure about that. It seems like a good feature that hackers successfully targeting a single node don't take down the whole system.
>In congressional testimony the product was stated as a challenger to emerging international payment protocols such as WeChat, Alipay and M-Pesa. Yet none of these systems are designed to run on byzantine tolerant pools of validators. They are simply designed in the traditional high-throughput bus that orders ledger transactions according to a fixed set of rules. This is the natural approach to designing a payment system. Preventing double-spends and forks is simply not an issue that a properly designed payment rails should ever have to deal with by design.
I would assume these systems are each run by a single company though, no? Which makes them fundamentally different from what Libra seems to be aiming at.
>The overhead from the consensus algorithm serves no purpose and will only limit throughput of the whole system, and appears to be there here no reason other than apparently cargo culting public blockchain technology which is not designed for this use case.
On the contrary, running byzantine fault tolerant consensus on a small number of node partners (which each submit aggregations of transactions from their clients) seems like exactly the kind of system that blockchain technology is best suited for. Not the kind of highly distributed consensus we see in e.g. bitcoin.
>A defining feature of a payment rail is the ability to reverse transaction in case payments need to be undone by legal action or if they result in accidental or system malfunction. The Libra system is designed to have “total finality” and does not include a transaction type to reverse a payment.
I don't know that this is necessary? A transaction can of course be reversed simply by making the inverse transfer. I don't know what kinds of annotations / metadata they would be storing in the ledger for audit trails, but it doesn't seem to me like a reverse transaction should be treated extra special.
Disclosure: I work for Facebook in a totally unrelated initiative (Facebook Connectivity) but have only cursorily followed Libra news in news media. I'm generally highly skeptical of cryptocurrencies, but less skeptical of distributed byzantine fault tolerant ledgers as a general technology for some niches. My comments are completely my own personal views.
And when there's a good answer to that, the next question is what are the exact consequences to reversals (or attempted reversals) of money that's "not there anymore" - e.g. there's a valid transfer from A to B; followed by a transfer from B to C; followed by a need/decision to reverse the A to B transaction (which is a very, very common scenario in e.g. scam resolution). For systems that treat money as the conceptual equivalent of "stuff" (e.g. Bitcoin) that's a very hard question; most of our financial infrastructure (probably for millenia) treats money as the conceptual equivalent of "debt relationship" i.e. a metric of who owes whom how much, and then it's a bit easier but still not trivial.
Libra’s byzantine tolerance on a permissioned network is an incoherent design.
The criticism here is that byzantine tolerance is not needed, when every participant is a regulated multinational company. But it certainly isn't a bad thing to have byzantine tolerance. Maybe a set of the regulated multinational companies will have backdoors put in place by a malicious entity - that has certainly happened before.
The downside of byzantine tolerance is the computational overhead. Yes, there is going to be a cost in throughput. But it just doesn't make sense for Libra to optimize for transactions-per-second at this point. If they run into scaling problems, then they can optimize. Right now they are quite far away from having scaling problems.
Libra has no transaction privacy.
It's the same privacy level as Bitcoin. Transactions are public, endpoint identities are trackable but don't have real identities attached. You can say it isn't a good set of tradeoffs for a cryptocurrency to be pseudo-anonymous. But it doesn't make the system "architecturally unsound".
Libra HotStuff BFT is not capable of achieving the throughput necessary for a payment rail.
Again, it doesn't make sense to criticize Libra at this point for not being able to achieve tens of thousands of transactions per second. If they start running into scaling problems, they can work on all sorts of extensions and improvements then.
Libra’s Move language is not sound.
The criticisms here really boil down to "Move needs more work". It isn't fundamentally unsound, it just needs more work.
The claims seem to reduce to nothing more than handwaving and marketing rather than actual proof. This is an alarming position for a language engineering project which expects the public to trust it to handle billions of dollars.
Okay, well don't go putting a billion dollars in a Move smart contract tomorrow. Programming languages, and especially programming language documentation, can be improved a lot over time.
...
There's more in the article, but really, it reads like a rant, where the author is so biased by their hatred of Facebook that they think every little thing that Libra does is wrong.
IMO, the core mistake behind Libra is assuming that regulators would be okay with it, because it isn't very different from other permissioned cryptocurrencies, like Stellar. Instead, regulators have been quite opposed to it because Facebook is behind it, even when technologically it isn't very unique. It is certainly not "architecturally unsound".
It only has to be sound enough for those goals. As it is used more it will get hardened.
The killer use is being able to pay overseas contractors without friction. Since there is no privacy, government on the other end will levy instant income tax withholding with glee.