Show HN: Kong – Physical Cryptocurrency
kong.cash
kong.cash
Kong is based on two primary observations; (1) it’s really difficult to use and secure cryptocurrency for most people and (2) cryptocurrency has been useful as a means of speculation, but poor for actually buying goods and services. It’s our hypothesis that by making cryptocurrency more like cash it may be possible that people ultimately use it as a means of exchange.
Our background is in secure embedded hardware (Lockitron, YC S09); over the past year we did a deep dive to really consider how cryptocurrency key material is handled today. We found that cryptocurrency has a unique challenge and corresponding opportunity; unlike IoT products where the cost of a breach might be difficult to quantify, breaking a hardware wallet can yield clear rewards to the hacker.
We developed Kong around the notion that security should be isolated to the smallest possible footprint — in the case of Kong, to an individual single purpose secure element chip. Doing so removes additional layers of firmware and software in order to limit the attack surface (it also broadly questions how good are our existing secure chips today).
To date we’ve handed out close to 2,500 Kong notes; we’re now exploring more ways to distribute physical crypto. Take a look at https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks... for an in-depth technical overview.
So how does a transaction work? Do I exchange a 500 kong note for a 10 kong item and 490 kong worth of notes?
So if you use a 500 Kong note to someone for a 10 Kong item, they will have to make 490 Kong in change. 4x 100 Kong notes, 1x 50 Kong note and 2x 20 Kong notes...etc.
Cash has an inherent agreement as to locality. When I'm in Australia, I use Australian dollars, when in the US, they have US dollars.
Though you may be solving this problem, I can use Kong everywhere, you need to somehow seed the market. How do you see that happening?
As you state, crypto is mostly a store of value atm. The benefit of not having physical crypto is that, in theory, I can trade my crypto for goods anywhere in the world. How will having a physical currency solve for this?
I went to my corner store at about 10:30 a few weeks ago to pick up a late dinner. I took out cash to pay, and the guy behind the register had already entered my purchase into his FPOS (credit card) machine. He looked at me and said "wow...old school. First time I've seen cash all day". You clearly feel that you are not fighting against a dying mode of payment, what makes you believe that? Or is there a piece I am missing?
It is more or less instant. Common in .au, .nz at least.
I'm actually noticing some cultural changes as a result of this, cash is starting to seem "dirty" since you often have to touch other people's hands to exchange it.
Pay with cash at a bar now and everyone will sigh as the barman counts it up, puts it in the till etc etc. Contactless is so fast, the barman will be pouring the next drinks while you're tapping the machine.
Also anecdotally, many London cafes/restaurants are entirely card payments now. They just don't do cash.
The legal tender laws just mean that if you offer a sufficient quantity of legal tender in settlement of debt, your debt is discharged and they can't sue you for non-payment. This ensures cash has value, and means that most shops will take most forms of cash, even if it means queueing up for counter service because the kiosks are card only
For instance, if you are at the bar and they pour you 3 drinks then ask for payment, they have to take your cash.
On the other hand if you are at the bar and, ask for a drink, and they say that'll be $10, they are not required to take your cash (the debt has yet to be incurred) and are also of course not required to provide you that drink if you pull out a $10 bill.
Only last year I always carried cash. I like cash. Now, I have a $10 note in my wallet and I can't even remember where it came from. I've stopped actually carrying my wallet, thanks to Apple Pay on my watch.
(I live in a major metropolitan area. It might be different elsewhere.)
I just spent a few months in the US and didn't use cash once (LA, SF, NYC).
I went to many places that no longer accepted cash in the US, maybe we're just in different areas.
What am I missing? How is this not fatally flawed?
We start to explore how someone could participate in printing Kong freely, without our influence, in section 5.1 but there are massive unsolved challenges to tackle here.
There is a significant distinction between verifying a note electronically and conducting an electronic transaction. The former can be done in an offline fashion; the latter cannot and, in the case of credit card networks, Ethereum and, Bitcoin, incurs a fee.
After reading the paper, I’m still not exactly sure how the lockdrop works. Could you elaborate on it?
As for verifying transactions offline, I’m skeptical of how useful that is. If you can lock down printing, the supply of fake or duplicate Kong should be low anyway. If you decentralize printing (or a lot of counterfeit/duplicate Kong gets introduced into the market some other way) then offline verification seems insufficient. What’s to stop me from printing and spending two copies of a note if I know the other parties won’t veriify the transaction online until much later?
We likely will need to have another document detailing how the lock drop works. The short version is that you lock up Ethereum in a smart contract for between 30 and 365 days; when you prove that fact to a given Kong lock drop contract instance you receive Kong token (at the end of the period).
> If you decentralize printing (or a lot of counterfeit/duplicate Kong gets introduced into the market some other way) then offline verification seems insufficient. What’s to stop me from printing and spending two copies of a note if I know the other parties won’t certify the transaction online until much later?
Here's how I see offline verification working:
(1) I sync up directly with an Ethereum node and cache all the Kong note smart contracts (ideally my own would be the most trustworthy). Most importantly this contains the public key for each Kong note known at the time and the token associated with that note (2) I accept any notes that I can electronically verify from that cache. That's done by challenging the note to sign a message and verifying the response. (3) I don't accept any notes not in my cache. The downside is that I can't accept very new notes, but we suspect that if we continue to produce Kong that we'll do so in large batches infrequently.
This isn't strictly true; you can buy notes from people.
> We likely will need to have another document detailing how the lock drop works. The short version is that you lock up Ethereum in a smart contract for between 30 and 365 days; when you prove that fact to a given Kong lock drop contract instance you receive Kong token (at the end of the period).
It sounds like the basic idea is that you "preorder" Kong with Ethereum, and then you visit a physical location (the "contract instance") to receive your cash ("Kong token"). If my understanding is correct, then this isn't outside of your control at all — you (or the "contract instance") can simply refuse to issue the cash.
Re: verification, here's my issue:
> Most importantly this contains the public key for each Kong note known at the time and the token associated with that note
What if someone counterfeits Kong not by wholesale faking currency, but by duplicating valid notes in circulation? The public key would be the same, so they would both pass offline verification.
Haha, sure.
> It sounds like the basic idea is that you "preorder" Kong with Ethereum, and then you visit a physical location (the "contract instance") to receive your cash ("Kong token"). If my understanding is correct, then this isn't outside of your control at all — you (or the "contract instance") can simply refuse to issue the cash.
Nope, it's in a smart contract that can be deployed into perpetuity.
> What if someone counterfeits Kong not by wholesale faking currency, but by duplicating valid notes in circulation? The public key would be the same, so they would both pass offline verification.
Section 2 in the paper explains how difficult this would be do. You need to duplicate the private key from a secure chip designed not to reveal the private key.
But I would be receiving a physical object, correct? Which means one of the following must happen:
- you give me notes in a manner that is not controlled by you (e.g. in the mail) assuming I'll fulfill the contract in good faith
- you give me notes in a manner that is controlled by you (e.g. at a bank-like location) to prevent theft
- we introduce an oracle (i.e. centralization in a third party)
> You need to duplicate the private key from a secure chip designed not to reveal the private key.
Yeah, this is an example of a problem that becomes much more likely if you share "printing rights".
Ultimately, I remain unconvinced — this is as proposed today a centralized currency that is almost strictly worse than a government currency, with the possibility of new drawbacks were printing ever to become decentralized.
Incorrect. The lockdrop is for completely virtual Kong token.
> Yeah, this is an example of a problem that becomes much more likely if you share "printing rights".
Correct, as elucidated above. Likewise each Kong self generates its own private key by design, as outlined in section 2 of the paper. By design, the key is non-extractable.
> Ultimately, I remain unconvinced — this is as proposed today a centralized currency that is almost strictly worse than a government currency
We can't inflate Kong infinitely unlike every other paper fiat currency. We can only print Kong for four years. After that the only digital Kong produced is via lockdrop.
So what? As soon as you share printing rights the other party can. So can anyone else who has the private key. Not even by minting new Kong but by physically duplicating existing Kong. That's a much bigger problem than a well controlled 2% rate of inflation.
Rarely do users of cash care about the property of it being payable on demand by the issuer (conventionally a central bank), only the property that it be practical for physical commerce.
1. the relevant private key is known to only a Kong note's secure element. this is (hopefully) enforced by the secure element's, uh, security, and by the issuer.
2. the relevant private key is known to the secure element on the specific physical Kong note the user has been given.
2 is unenforced in your current design, from what I can see. A crafted note can relay all communication to the secure element of another note (e.g. over low-power RF from a single-use battery or small ultracapacitor).
better, a "dead" Kong note which performs no NFC communication can be given to a merchant; then, a high-power NFC transceiver can be used to pretend to be the note wirelessly (from a handful of meters away, but in a lot of situations that's more than enough). Of course, this one only works if the verifier is using NFC, but... This one is particularly nasty because it's relatively straightforwards to "weaponise" - imagine buying a "kit" off AliExpress which contains fifty dead notes, a ProxMark, and an amplified antenna. Then, in any situation where you're close enough to the person who'll be verifying your notes... just give them a dead one and relay communications. Verification passes, but what the merchant ends up putting in their cash drawer is worthless.
For 2) I get the part about relaying communication but regardless of that, what makes you think any sort of communication will cause it to output the private key? As far as high powered NFC, I am not sure that would work to begin with (someone who knows radio explained it to me but I cannot recall) but even if it did how is it different than existing mobile phone NFC payment?
You also gotta keep in mind,this is in-person. If someone defrauds you, they face several risks including law enforcement,legal,phsyical altercation(violence) and more.
Better would be nice but I can live with "as good as cash" or "as good as mobile nfc payment" when it comes to security.
Perhaps by having the secure element "lock" and "unlock" each time the note changes hands, so that an attacker who uses a a relay will still have his note locked in a way that makes it useless unless he gives it to the recipient to unlock?
I love this. I have been wanting something like this for a while. Personally, I desired a coin instead of a bill. 2-3CM thick coin made with material good for radio security and longevity would be neat. A phsyical 'coin'. Any plans for something like that? Any reasoning against it?
Are you in a non extradition treaty country? This could be a relevant question for you soon enough
Sure, it can be used as money (assuming what authors say is correct). Virtually any physical items that are hard to fake can be used as money, as long as people believe it's worth something. And if we are okay with complicated and rather expensive manufacturing process (since Kong isn't something you find in the forest), it really is a non-problem to create a new "government-independent currency", print it and sell it. Nobody really gives a fuck about that, because money is worthless unless you can spend it. And as long as Costco doesn't accept Kong (or any other made-up currency), it would be hard for you to spend it on anything other than unique hand-crafted chairs or cocaine. And it would be hard for them to start accepting Kong notes, while being a government-compliant entity that pays taxes, as every physical bill they get must be accounted for and put into a cashier machine.
And, by the way, since every Kong bill is unique, it isn't any more anonymous than dollar bills: i.e. pretty much anonymous as long as they change hands without touching real cashier machines or ATMs, which, as it happens, is not so long, because people don't generally exchange unique hand-crafted chairs for cocaine, they buy/sell it, then go to Costco to get some more conventional goods or services.
Tokens loaded onto Kong Cash instruments and exchanged ephemerally in person between party A and party B are more anonymous than tokens sent directly from party A to party B electronically which will be recorded for everyone to see forever.
It's programmable money. It's cooler than non-programmable money. We're putting it out there as a toy.
The exit to real currency will always reveal Kong transactions at some point. Real cash is more anonymous because it's seamlessly transacted everywhere.
Seems more convoluted than connecting a gaming pc to a network (please don’t say bitcoin can’t do that now, you could initially)
I do agree that people can’t picture or visualize in their mind a “bitcoin”, and so this solves that part. But then you’re left with the, how do people print this tangible pretty currency part.
Cryptocurrencies are turning out to be really important but lack a physical cash instrument.
Kong marries the two.
Kong accomplishes that by minimizing trust down to the chip level - as opposed to the firmware or application level - so we can make these things trustlessly and cost effectively. Something like a Trezor is too expensive and dear to be treated like physical cash.
Couldn’t you imagine a world where this starts trending cheaper and cheaper and soon becomes a commodity ?
Further, I'd suggest you read up on NFC and tokenization, it's not true that the companies in question actually do get access to that information unless they have separate-from-the-technology arrangements with payment processors.
In either case I'd rather be tracked than bankrupt.
Kong is a toy implementation of this idea, but I think it's a very powerful idea.
It already has all the benefits of physical crypto with less headache.
Not really. There's a couple northern european economies that are almost entirely cashless.
Both the UK and the Netherlands for instance have issue reports[1][2] to ensure cash does not go away as it serves a vital purpose for protected classes.
[1] https://www.accesstocash.org.uk/media/1087/final-report-fina... - from the UK report "17% of the population would struggle in a cashless society"
[2]https://www.dnb.nl/en/binaries/DNB%20Payments%20Strategy%202... - from the DNB report "While we support the retailers’ and banks’ wish to encourage electronic payments, we do not seek to achieve a cashless society..."
I just don't see why people would switch to something to ensure 100% real bills and lose all the other benefits of cash. How is there going to be a cambrian explosion with an issue that affects almost no one?
Secondarily, it demonstrates how we can move validation from physical properties of cash instruments (such as fine printing and exotic inks) to cryptographic properties.
We believe the latter to be superior and a path to ratchet down the cost overheads that go into securing cash issuance and payment channels.
Then a company like Coinbase shows up and uses their resources to dominate the market as the de-facto app change. Centralised again.
Crypto is just as abstract as the currency we currently use so only functions as legit currency because people are willing to buy and sell it from one side of the world to the other. Bitcoin for example has a single valuation, despite being decentralised.
If you want true decentralisation then you’re looking at the pre-currency barter economy.
Not that Kong isn’t centralised. It’s just that it’s controlled by unknown nobodies, rather than the most powerful entity in the world.
Maybe kind of a valid point, but... I don't know, maybe that varies from place to place a lot, but fake money doesn't feel like a huge problem around here. I mean, unless I am a tax-paying entity with a cashier machine, I don't even really care if a bill is fake or not: it is not fake, if somebody else accepts it. And I'm pretty sure somebody will, if I accepted it after looking at it. It doesn't only concern how bill was actually printed: it happened more than once that I had to worry about a bill because of its condition (tears, dirt, etc.)
> more anonymous than tokens sent directly
Yeah, as much as dollar bills are. That's why Monero is better than Ethereum, BTW.
> It's cooler
... Oh, come on.
Are we not entertained?
Programmable colors.
Programmable taste.
We already do this with genetically modifying food, why not do it with code?!
And that right there is the honesty that the rest of this thread is missing.
We've made a physical product, we'll sell it to cover the costs of doing so.
But I'm wondering what made you decide to go with the generic greek bust heads? Missed opportunity to depict some cryptography and computer pioneers imo.
One design pattern among currencies is "person on front, place on back" - we didn't want Kong to be too geographically local so we picked the planets (Mercury, Venus, Mars, Luna, etc) for the places and the associated Roman pantheon. Romans used currency while Greeks famously didn't. (Lydians aside.)
I’m so curious why people think (and it’s certainly not just you, I see this attitude all over) that it is possible to run a business without providing value to customers.
As far as this specific project. The creators will probably need to show some physical notes, how they work and so on.
This appears to be an early-stage project idea so cut them some slack here.
And yea it is cool, this overriding principle defies any predefined business model or use case. Novel things come from new things not incremental improvements like “Apple Pay”. Which those are explicable money making scams and schemes to control people’s banking info and insert yet another middle man to profit off the mere act of transacting.
The innovation of Bitcoin was money as a purely digital artifact that cannot be double spent. As a merchant accepting Kong bucks, I have no idea how many duplicates of a particular Kong note there could be out there. I could find myself in a race between many other people to move the Ether out of that private key. To rely on embedded chips and watermarks to prevent counterfeiting and double-spending seems like a huge step backward, like you're trying to make a better $100 Benjamin instead of a better cryptocurrency.
I get the idea of quick, zero-fee transactions. But there needs to be some finality or pseudo-finality. The Lightning Network uses a similar model as yours, but it has collateral. Analogously, in the way Lightning solved this problem, the merchant has 5 actual Ether on file for a customer that the customer sacrifices if they ever double spend a Kong buck at the store.
The innovation of Bitcoin was decentralized electronic peer-to-peer cash. Kong does not remove any of those elements and makes the overhead of the peer-to-peer bit easier.
Physical cash is still the dominant form of payment. The advancement here is figuring out how to issue physical cash without needing a central entity.
I like Bitcoin but it is anti-privacy by specification. For small transactions I prefer cash. I would like the best of both.
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
However, a gold coin will remain valid if dropped into water or fire.
(of course there are empirical methods for proving gold is gold, but being able to do it with NFC is neat)
Then what problem is it solving?
>Physical cash is still the dominant form of payment. The advancement here is figuring out how to issue physical cash without needing a central entity.
It has to be physically manufactured. You're now the entity.
Section 4.1 goes into how to manufacture these so we're not the sole entity. Manufacturers of mining equipment set an...ok...precedent here. I think we can do better in this space which is why we're trying to minimize trust in these black boxes and move to open silicon with ARX - section 5.1. [1]
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
In what way is cash failing that it needs to be replaced by your type of cash?
The "it's decentralized and doesn't rely on a state level actor" argument has been thoroughly lost at this point.
Point is it being not tied to a state level actor is only useful if you can use it to get out from underneath the control of an oppressive regime by not being beholden to it's financial system.
So far we haven't seen a crypto succeed at that. So... so what if it has that property? Doesn't seem to be useful in practice. In theory yes, but not in practice.
The point is that there is a use-case for decentralized assets.
> Point is it being not tied to a state level actor is only useful if you can use it to get out from underneath the control of an oppressive regime by not being beholden to it's financial system.
Or if you don't want the value of your money inflated away by central bank policy.
> So far we haven't seen a crypto succeed at that. So... so what if it has that property? Doesn't seem to be useful in practice. In theory yes, but not in practice.
Yes, that's true. Although you could argue Bitcoin has succeeded, just not as a currency. It has succeeded as an asset class. But the question of why crypto hasn't succeeded as a currency is what Kong appears to be attempting to solve. Their answer to that question is that it doesn't have some of the nice properties of physical cash, so they made one that does.
I'm not sure I think that this will change much, but I don't think the fact that cryptos haven't displaced national currencies yet is evidence that they don't solve any problems. They do solve important problems, they just create other ones, and those things don't yet balance in their favor.
I mean yeah you could roll this out to places that perhaps didn't understand this and/or fucked up real bad like Zimbabwe, but otherwise who cares?
If you can't trust your government so bad that your cash no longer works, you've got bigger problems and whatever system you build via the Internet is probably going to also be blocked and/or the infrastructure will be in tatters.
I guess if your government is a royal family taxing you to line their own pockets that would seem like theft, but otherwise seems hard to believe it could be true, but people will believe anything. The world is complex, the economy is complex, and stopping a country's economy from tumbling out of control with all the internal and external variables is non-trivial.
When I accept a physical note, do bits move on the Ethereum blockchain? If not, how do I know that it's really mine?
This reminds me of when people sold Bitcoin private keys ("paper wallets") on eBay. I've heard some people do OTC trades by swapping private keys when they don't want the transaction recorded, but I assume these people know each other well. You save money on miner fees and gain some privacy, but you sacrifice trustlessness.
Token is stored in an escrow contract. The self-generated, non-extractable key stored on the note is the only key that can be used to claim funds out of that escrow contract when it matures.
This is basically a smart-contract implementation of how promissory notes issued by goldsmiths (the predecessors to modern cash) worked in the 1600's. A big difference is that every note has its own contract. It's possibly more correct to say every bill owns itself and people transfer those bills.
Section 3 of the whitepaper[1] expands on this.
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
Another simple flaw of Kong is that when I receive a Kong note, someone could have intentionally fried it with, for example, high voltage on the I2C contacts to damage the secure element without leaving any visible defects. So I need to verify each Kong note I receive by reading them over NFC using a smartphone. Not great for usability.
That would "fry" the secure element chip entirely, thus destroying it precluding anyone from accessing the token in the future (NFC would fail as well).
People don’t pass off counterfeit currency as real all the time either, that’s a false lead. Currently 0.01% of currency is fake and it’s actively sought out and removed from circulation [1]. That’s almost guaranteed way less than Kong bills that will become damaged and destroyed in the most ordinary of ways. We’re extending SFYL to IRL.
[1] https://www.google.com/amp/s/www.frbsf.org/education/publica...
Whereas Kong requires verification because literally anything could have happened to the note that you can't determine through mere visual inspection (all the things I noted). That forces you through the awkward and painful flow of verifying each Kong note via NFC.
That's not because non-obvious counterfeits are not possible. It's just that not many of them are generated. The same could apply to non-obviously sabotaged Kong: theoretically it's possible to do, but in practice uncommon.
Kong would have the added benefit of not financially rewarding the sabateur the way counterfeiting rewards a counterfeiter.
It's far more likely your Kong bill just break taking its value with it into the aether than you receiving a counterfeit USD bill.
Counterfeiting a bill requires special technology and evading the police. Breaking a Kong bill requires putting it into a wallet with too aggressive a fold.
Neither would Kong in most cases. Why would you assume that counterfeiting will be anymore common with Kong than it would for cash?
> Whereas Kong requires verification because literally anything could have happened to the note that you can't determine through mere visual inspection (all the things I noted). That forces you through the awkward and painful flow of verifying each Kong note via NFC.
I don't see why verification via NFC would be any more difficult than using one of those counterfeit detector pens.
No, I assume that the risk of a counterfeit bill is much much lower than the risk of the IC on a kong bill failing taking the value of the bill with it forever. There's so many more failure modes for a Kong bill than the plastic it's embedded in.
The bills themselves, aside from being counterfeit, cannot fail. Kong bills can be counterfeit too, and also have tens of new failure modes.
And if your physical banknotes do somehow get damaged e.g. by fire or by being chewed by a pet, there is a decent chance you'll still be able to get them exchanged, because there are government-backed institutions there to help you such as the Bank of England[0] or the US Dept of Treasury Bureau of Engraving and Printing[1].
In the absence of a Central Bank of Kong to perform this function, the Kong people could make their new physical currency more robust by putting their fancy chips and whatnot inside some discs made of a metal that was resistant to corrosion and oxidation and had a very high melting point. Perhaps also using a rare metal with high economic value, preferably with a standardized weight and purity, so it could also better act as a store of value and be more difficult to counterfeit. At that point you could also take out the fancy chips and whatnot in order to improve reliablility, usability etc.
[0] https://www.bankofengland.co.uk/banknotes/damaged-and-contam...
That depends entirely on how good your fake is. And it is most certainly not 'mostly a non-issue'. Counterfeiting happens all the time.
> Who prints Kong? I imagine prevalence of counterfeiting is more or less directly proportional to the ease of printing.
Nobody. Kong is printed algorithmically, like any other cryptocurrency.
How often have you had any real-life issues with counterfeit money? How often has anyone you know? How often have you even heard of it happening, relative to how often you see and hear of cash being used? A sibling comment provided a source that said that only 1% of 1% of cash is counterfeit.
> Nobody. Kong is printed algorithmically, like any other cryptocurrency.
What? Notes and coins are a human-made physical items. They’re manufactured by someone.
Stores have issues with it all the time. That's why they don't often take large bills. I and my personal acquaintances don't accept a lot of cash in exchange for goods and services.
You think 1% of cash being counterfeit is not a problem? That sounds like a huge problem to me.
> What? Notes and coins are a human-made physical items. They’re manufactured by someone.
Sure, the physical objects are made by someone. But the digital tokens to which they refer are produced algorithmically, and the digital tokens are the source of truth here.
> Sure, the physical objects are made by someone. But the digital tokens to which they refer are produced algorithmically, and the digital tokens are the source of truth here.
In what sense? The whole idea here is that I can exchange a physical note to transact with someone.
So refuse large Kong notes. Why would you assume the economy finds workarounds for cash but not this?
> In what sense? The whole idea here is that I can exchange a physical note to transact with someone.
Ya, and for most transactions you will. If you're suspicious, you can validate the physical devices using your phone. But for simple transactions with a moderate level of trust, you can accept cash. The same way you accept a $20 from a friend without buying a counterfeit detector pen to check it.
That makes this, at best not better, and at worst, well, worse, because it introduces a myriad new failure modes.
Re: finding workarounds, we’re talking about money — we shouldn’t be “testing in production”, so to speak. IMO the government should come down hard on this.
I don't. I assume that, exactly like cash, only large notes will be worth falsifying.
Now your bills cost over 30X what a traditional bill costs. Since counterfeiting is only 0.01% of US bills, to stop that, you're proposing we pay a 30X premium on the manufacture of those bills?
The treasury prints 38M notes per year, totaling $541M dollars. That's a material cost of $3.9M. If 0.01% of that $541M is counterfeit, that's an additional cost of just $54,000, bringing our total just under $4M. Even if you chose to include "2% inflation" as a cost (and to be clear, you shouldn't) that's still just $10.82M.
To print the same 38M notes in Kong we'd be paying $106M. That means to eliminate $4M in printing and counterfeiting costs we'd have to pay $106M. You're proposing we pay 10-27X as much per year to manage our currency. [2] Not to mention the sheer electricity cost of creating and locking up the value on the Ethereum blockchain. Then, mechanical stress/strain and failure of the secure elements over time takes value out of both the Kong real-world supply and also out of Ethereum, which is already subject to massive breakage.
This is basically why we don't verify signatures on checks. It's cheaper to eat the fraud cost.
[1] https://www.investopedia.com/news/fed-will-print-more-50-bil...
[2] https://www.factmonster.com/math/money/facts-about-us-money
There's a chicken-and-egg problem that I think goes missed or unmentioned by all these crypto startups trying to piecemeal a "solution" to the centralized banking problem: in the monetary system, individuals have absolutely no power, because we're at the bottom of the hierarchy of spending.
Joe Schmoe's dollar has value because he can buy a soda at the diner with it. The diner takes the dollar because they can use it to pay their staff and buy more supplies. The supplier takes the dollar because they can pay their staff and and buy raw materials. And in between every layer, the banks store the excess operating capital and profits.
Decentralized currency can only work if it can occupy every layer at once, across the world. Anything less is just straight out worse than regular money from a usability standpoint, and that's before you mention that now we're all responsible for our own money security.
Yes, people out there have been wronged by the current system, but the average modern human's relationship with money can be essentially summed up as follows:
1. Perform labor
2. Receive paycheck
3. Deposit in bank
4. Purchase food, shelter, and netflix
So what is this kind of pseudo-money-computer-chip-paper for? No matter the fancy technology thats woven into its fibers, if I pay the Kong people for 10 Kongs, how do I, Joe Schmoe, turn 10 Kongs into a pizza? How do I, Jane Pizza-Maker, find a supplier that will sell me tomatoes and flour for 10 Kongs? How do I, Rachel Dough-Maker, find a wheat farm that will accept Kongs?
All of this has to happen simultaneously, because business owners are busy and don't have the time or the energy to incrementally work space money into their cash flow.
Yeah sure, centralized banking has issues. But a bottom-up approach is doomed to failure because we don't live in barter-based villages anymore. Every transaction is part of a hierarchy of money-transfers that extend from the local diner through dozens of entities across the planet and back again. Are you making enough Kongs for all of them?
But its hard to get funding or user buy-in if you say that.
I might suggest an alternate definition: Money is a transferable record of debt valid for a period of time and amongst a network of peers.
Generally we think of money as local to a country and its government. However, one could imagine a 'minimum viable money' that could work in a space as small as a table and with only a handful of people - and for the purposes of a game like Monopoly, while the game is ongoing the money in the game serves a real purpose. From there things get pretty blurry as any World of Warcraft or Eve player will tell you.
And that's why you generally can't pay for your eggs & bacon at the diner in Wisconsin using British pounds.
The difference here is that you can trivially go to your bank and exchange those pounds for US dollars. Good luck getting them to exchange your Kong.
I suspect most people (especially in the USA, given how relatively few people even leave the country compared to other western countries) don't consider foreign currency to be real.
Heck, try spending Scottish Pounds in London (UK) and see what responses you get.
The Monopoly example is interesting, because there's enough currency in the box to pick up the entire system and operate it. In that context, the money isn't the point, it's just a tool to operate the Monopoly game-system. Similarly, for us money isn't the point, it's just a tool that powers the human society-system.
I think it's better to frame it in terms of the minimum viable society. Figure out how much system it takes for an arbitrary group of humans to operate a society that is indistinguishable from any given slice of modern life, and then derive how much new money you'll need to make and distribute to make it possible to switch all at once.
Privately owned or rented homes, food purchased from a store, utilities, transportation, entertainment; all the things that being a human in society entails. All of it needs to be present and purchasable with the new money, or else the new money will have to be converted back to traditional fiat, which as many have said defeats the purpose and introduces a boat of security problems.
I like where you all are taking the concept of money, I like the Kong experiment, and I wish there was One Weird Trick to get past the adoption phase and into usefulness, but idk it just seems like all we have are ten thousand interesting experiments.
Why should anyone buy a crypto currency you can barely use anywhere in physical form if I can just use regular cash?
What you are missing is that I need to pay my bills in practice, not in theory. I measure the value of cryptocurrency against what it delivers in practice, not on the white paper of the people who are going to benefit from its adoption.
There are many attacks to consider. The most obvious is to obtain the private key. If you did so, you could give the note to someone else in an environment lacking network access. This would enable double-spending - the main problem Bitcoin solves.
The attack can range in complexity from breaking into the secure element to physically separating the element from the note. The latter approach was used way back to pull private keys from Casascius coins by dissolving the adhesive on the security sticker.
I suspect not all of these kinds of attacks have been considered by the creators.
If it becomes necessary to verify Kong with a network connection, the main value proposition disappears. That can be done already without a physical note.
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
So say the key was extracted, you would not be aware until the "maturity" or whatever time you can claim the real value?
How would one then know and trust that the note I'm holding on to won't be claimed by someone else at the period of claim? As far as I see it my best option would be to try and offload any Kong in my possession as soon as possible for real goods or other currency.
Wouldn't this mean that if the notes are destroyed the value of the other notes would increase?
A dedicated "Kong scanner" could do this very quickly.
"An additional 7,340,032 Kong was issued to the Kong project for discretionary Kong noteprinting and distribution. The upper bound for Kong token created after five years (the point at which only the recurring lockdrop rewards remain) is roughly 72,700,000 Kong."
So, the promoters of this skimmed off 10% before launch. Or, more like 20% of the first year's production.
Now, if this was set up so that it's denominated in something they don't control, like Etherium or Bitcoin or dollars or euros or yuan, it would be more interesting.
If Kong develops a market of its own (???) then having some token for the project to fund the very real costs of making more Kong is helpful.
Have you considered licensing the tech to governments to make counterfeit-proof bills?
Some people might not remember the Liberty Dollar[0] from 10-20 years ago. The depository was raided after a few years, the company issuing the currency was shut down, and the owner/proprietor was convicted of illegally minting coins. Kong couldn't be shut down the exact same way - these aren't coins - but I'd be shocked if a similar thing didn't happen were Kong to become as popular as ALD (which, come on, it won't).
[0]: https://en.wikipedia.org/wiki/Liberty_dollar_(private_curren...
Things get complicated real fast once you move from peddling virtual to physical currencies. I fail to see how the US wont use the same laws to shut them down the way they did to the liberty dollar.
I trust math, science and verified algorithms rather than people or governments.
Since this is always going to be true, I am probably going to go with the best bets based on track record... I will use the currencies that have held pretty consistent value over the last 100 years.
Is there an equivalent to a starch pen like a suspicious cashier might use on a $100 bill today? Or is the process more painful? Does it require the internet? Remembering that many cash transactions happen person-to-person, in places with low or inconvenient connectivity.
Validation can be performed with any smartphone. Notes are issued in blocks so technically if you downloaded the 2019 Kong Registry contract you would not need connectivity to validate a note. Purpose built hardware can also be built or existing android based POS systems updated to support kong-like validation. Other anti-counterfeiting techniques have been explored but it the only thing that really matters is securing the root of trust.
Technically with Swiss Francs, the notes have no value after their "expiration date", with Kong the escrow contract unlocks and the token can be claimed off the notes but the precedent made us comfortable enough with this tradeoff.
Alternative implementation 1) notes are not escrowed and funds can be claimed off the bills immediately - this is effectively how paper wallets, java smart card wallets, and trezors work. This is a gift card instrument not a cash instrument.
Alternative implementation 2) funds are locked up into perpetuity - all tokens are eventually lost to breakage.
Our back of the envelope expectancy was 10 years for these notes. We wanted the majority to be reclaimable well before their anticipated breakage so we set a claim date relatively soon in the future.
No it's not.
- https://en.bitcoin.it/wiki/Casascius_physical_bitcoins
It looks like Kong might be the first crypto-cash with an issuer that hasn't seen its private keys. And that's cool, but it'd be good not to exaggerate what this is.
Oh yeah, because then the founders can't get rich in the ICO. Yuck.
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
You're converting me into a fan.
Dollars aren't strictly physical. They also exist digitally. And they are cash.
The taxation difficulty is the single biggest reason why I stopped making small transactions with Bitcoin. The paperwork, come April, was awful.
If you bought the stock for $100, and now it’s worth $200, and you sell $10 worth to buy a sandwich, you have $5 of income to be reported.
> To reduce the number of currency conversions required, the tax code uses the standard of FAS 52, which is the Financial Accounting Standards Board standard for foreign currency conversions. This allows the business to record most of its transactions in terms of its functional currency (FC), which is the currency that is generally used by businesses in the locale of the foreign unit or entity. Generally, under FAS 52, fluctuations in currency rates do not have to be accounted for unless the fluctuations change the cash flow for the business. In most transactions of a foreign business unit in a foreign country, cash flows are not affected by currency fluctuations. However, transactions between the parent company and its foreign subsidiary will result in a change of cash flow. As a consequence, gain or loss on the currency exchange will have to be included when calculating net income.
https://thismatter.com/money/tax/foreign-currency-transactio...
> do not have to be accounted for unless the fluctuations change the cash flow for the business
If there is a change in value then it needs to be reported. It's the same concept as if you were forex trading.
However, this is one of those things where the government isn't going to come knocking your door down for since it's petty cash.
https://www.irs.gov/businesses/small-businesses-self-employe...
The usability problems are also a feature -- if Kong is burned, stolen or otherwise destroyed, the value is lost forever. Billions of people understand that's how cash functions and they take measures to secure it.
Looks like they're also trying to structure this as 'reward cost for key extraction vs cost of mounting attacks' showing they have a plan in place for attacks. I'd argue the notes still have a tx cost though because the only way to know if a note has a valid private key is to challenge it with a unique, large, random number - which takes time and effort. Users of the notes will need an app for that and have to check every note against an on-chain 'smart contract' before accepting them? NFC might make some of that easier but there are still usability issues there.
Putting (very) public bounties at various reward tiers lets one establish something like a demand curve but for security.
Specifically, Kong notes use a secure element which 1) self-generates a key pair 2) can attest the key pair was self-generated and 3) does not leak the private portion of that key pair. Section 2 of the paper (specifically 2.2) goes into more detail[1].
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
This of course holds true for all hardware. When someone creates or stores a Bitcoin key on a laptop, they are at the mercy of the laptop manufacturer.
One of the biggest issues plaguing cryptocurrency as a transactional currency is the volatility of decentralized assets.
What problem is Kong fixing? “We made a physical crypto asset” isn’t connecting the dots for me.
I'm phrasing the question facetiously but the underlying intent is there: how is there more anonymity, usability, etc.?
What is a lovely property of Kong is the only digital breadcrumb is leaves is when notes are loaded at creation and unloaded at de-circulation. Every person to person transaction of the instrument leaves no digital record or footprint. Usability is superior for new users - everyone understands how cash works.
That's true of cash as well, but that doesn't mean it's totally untraceable, as bills still have serial numbers. I think what GP is getting at is, Kong notes must completely lack any sort of persistent unique identifier in order to be an improvement over cash in anonymity. Can Kong make this claim?
What problem does that solve for me though? What benefit does that afford me? Why does that matter to me?
Potentially more people will accept it. But I doubt it.
That seems painful for small transactions, but without it you lose absolutely all the security benefits of crypto, right? (e.g. vulnerable to good old fashioned counterfeiting)
Unless the price is listed in this particular crypto people will have to do a live conversion to even know what this space cash is even worth.
Also, very funny (and accurate) about the $2
Steve Wozniak used to keep uncut sheets of $2 bills that he perforated and would tear off to give tips to people. He has a great story about secret service agents detaining him and accepting his fake ID ("Laser Safety Officer" - it showed him with an eyepatch on) and generally having no idea $2 existed.
I have a few in my wallet most of the time, like to use them for tips when I eat out.
The email 'request access' thing doesn't work
If you want a physical currency that can’t be printed, use gold bullion.
Make a currency exchanger that exchanges bits with a scan of your device, instantaneously, and you’ll have my attention.
Correct, this is the primary challenge of creating sound cryptocurrency and indeed why we go into length about the hardware we use in section 2 of the paper.
> Make a currency exchanger that exchanges bits with a scan of your device, instantaneously, and you’ll have my attention.
Can you elaborate?
(I could be wrong but from skimming their technical spec it doesn't seem to be redeemable for anything other than digital Kong tokens)
We looked at existing hardware wallets like trezor and ledger and realized we could create something like this for 1/20th the price. Once we realized the numbers we were playing with we ran with it. Conceptually, I prefer validating something with a cryptographic signing operations rather than looking at some watermarks.
Kong is a proof of concept but we could always print these for other governments.
It's utterly impossible to sustain, it's highly likely that the physical cost could be higher than the face value
In addition, the paper cites the cost of decapping and side channel equipment as part of what makes double spends impractical. Given that they're fixed costs that undoubtedly many governments and labs already own, it still seems like it could be worth it for some people to extract Kong keys.
This is perhaps the most important question. In short, yes. We use an off the shelf secure element; if it's shown to be broken/backdoored it will influence a vast number of embedded and IoT applications.
> In addition, the paper cites the cost of decapping and side channel equipment as part of what makes double spends impractical. Given that they're fixed costs that undoubtedly many governments and labs already own, it still seems like it could be worth it for some people to extract Kong keys.
We cite fixed costs in hardware, but not in time. Certain extraction techniques would still take hours of time per chip. The secure element we're using has no published attacks thus far (which is not to of course imply that it won't be, simply that it isn't trivial).
The scenario I'm imagining is one in which someone manufactures a note that looks and behaves exactly like a Kong but has known key material (i.e. a "fake" secure element). You can't verify that the secure element is real without expensive hardware.
And what is the vision for who can mint Kongs? If only the Kong developers can, then it's no better than USD. If anyone can do it, how will you guarantee consistent chips, construction, design, etc. between manufacturers?
Yes, that's counterfeiting in the case of Kong. The counterfeiter would need to first extract that key material from a previously issued Kong note by breaking the secure element.
> And what is the vision for who can mint Kongs? If only the Kong developers can, then it's no better than USD.
Only the Kong project for now; whether it's better or worse is definitely subjective. There is a ceiling for the amount of Kong that can be issued. Also, as something more akin to an art project than a fully functioning economy, there is no place to spend Kong today. It's ambiguous, but the fact that the Kong project is the only issuer of the physical notes doesn't undermine the cryptocurrency rules upon which it's based.
> If anyone can do it, how will you guarantee consistent chips, construction, design, etc. between manufacturers?
Section 5.1 touches on this; in short there is no solution today, but this in an immensely important challenge. Flipping this on its head -- if we don't have these guarantees today, how can we trust any of the places we store key material (smartphones, laptops, IoT). It's impossible to guarantee a perfect chip, but it is feasible to create economic incentives that deter broken chips. We'll probably write more on this topic in the future.
Cash is the dominant form of consumer payments (77% world wide!) and the move to ban cash in various places disproportionately affects the underserved and marginalized members of society - ostensibly the audience cryptocurrency is trying to serve first. This is an effort to meet others with terms and technology they are comfortable and familiar with.
Even so, we're unaware of any value to the Kong token independent from Kong notes and we are not taking steps to list it on exchanges. If Kong was to become a means of exchange somewhere then it might need to be declared as a monetary instrument depending on the jurisdiction.
We have considered more robust variants that would fully seal all the components, but this is a v2 problem.
I should add that even a corroded chip should ultimately still be accessible; you might have to pull it off of the bill and decap it.
How do you plan to tackle this mentality, where there is such hostility to anything in the slightest bit unusual?
Also, while I do sometimes have problems with them abroad too, it's 50/50 - I've had them accepted in all sorts of places, including India, Nepal and China
Literally every bank in the UK will accept Scottish bank notes - if that's not a defacto legal tender, I don't know what is.
https://en.wikipedia.org/wiki/Banknotes_of_the_pound_sterlin...
But in the real world, they are absolutely defacto legal tender - as above, every bank in the UK (and even many beyond) accepts them.
However, the old Swedish notes had not lost their value because they could still be redeemed.
In a formal legal tender situation, you could to some extent require a private party (within the relevant jurisdiction) to accept the notes in payment of a pre-existing debt. You could contrast this with "having value", "being redeemable", "being in circulation", and "being widely accepted", maybe.
Less cheekily, I think Kong like instruments when properly adapted could capture the best parts of local currencies (like the Bristol Pound), the messy parts of multi-governmental currencies (like the Scottish Pound), and the nice bits of computer validation.
In your example specifically, the Royal Bank of Scotland can still mint Scottish Pounds but back them on chain by UK pounds.
I'm of course hand-waiving the problems here - we've made a programmable monetary instrument. One can program things well or badly to support this kind of interoperability.
Why not? Each of you can have Bitcoin wallets on your phones. I'm sure coke heads can figure out something to talk about for 10 minutes waiting for 1 confirmation.
Also what do you mean by "after a period of several years"?
Paper Wallet were 1st gen - one couldn't guarantee the person giving you a paper wallet didn't have two copies or kept a copy of the private key for themselves. Probably ok for personal use assuming you trust your printer firmware.
Hardware Wallets were 2nd gen - seed phrases made recovering from device loss nice but again, seed phrases were designed to be exported and cant be used as cash. They are very useful for other applications.
Java smart cards were 3rd gen - meant to be used as pre-paid gift cards but again these were designed for banks who wanted to handle the key material in software and have dangerous APIs for doing such[1].
Kong - uses a specific kind of secure element which allows for key generation but not extraction. On chain contracts convert the R1 keys used by the chip to K1 used by most cryptocurrencies today.
The paper goes in depth on this in section 2.3 [2]
[1] https://docs.oracle.com/javacard/3.0.5/api/javacard/security...
[2] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
In other words, just like almost every other smartcard (including EMV).
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
Instead of garbage paper tokens, here's a thing that already exists:
... can be used just like cash
... isn't limited to a particular denomination
... value can be added at any time
... fits in your butt
You even said it in your critique of ETH- “it's not a reliable store of value”
Currency is NOT intended to store value. It’s intended to facilitate the transfer of value. In that regard, etherium and bitcoin fail equally.
cash has been variously shells, giant stones, glass beads, shiny metal, complicated paper, etc...
fundamental to the hand-to-hand nature of this Kong nonsense, is the feasibility to be transferred offline.
whatever Kong is, it's primary function will be a way to rip people off.
and taywrobel: as a side note, i realize my statement may appear unbelievably ironic to you. just know that's your problem and not mine.
Since you have a brand new username, I’m going to give you the benefit of the doubt and assume that you’re just new here and not intentionally trolling, and explain why.
This community values neutral statements of fact, not vulgarities or arguments of passion. As such, while your opinion may have merit, your presentation of it is unlikely to get you far here.
Hope that helps you thrive in this community going forward.
- than
stick to your fiat bro, that's going to be the best store of whatever type of value you're creating.
View keys can be printed as a mnemonic seed (a set of meaningless English words).
Would printing of view keys mnemonic not be equivalent to this? With the added advantage that printing is not centralized?
this is full text of a View Key
A keypair specific to Monero. The public part of it makes up the 2nd half of monero address, and is used by the sender to generate a one-time stealth address to where the funds are actually sent. The owner of the wallet uses the private view key to scan the blockchain and find the funds sent to his address. At the protocol level, the sender performs an encryption with the recipient's public view key, and the recipient attempts to decrypt all the outputs on the blockchain to find the one belonging to him (where decryption was successful). For audit purposes, it could be shared with the auditor, along with the signed key images to prove the balance of a wallet. Sharing only the view key would enable the auditor only to see received transactions, but he wouldn't be able to tell if any funds were spent, so he couldn't know the actual balance.
In the trivial case that each kong is a wallet - a view key would actually show the balance.
> Need more Kong? Reach out and we'll see what we can do.
Yes everything about this reads like a scam. Uses the most basic scam tactics, make it seem urgent, and desirable and exclusive.
It is completely unlike other things that have come before because it only stores keys on the secure element and only stores code in the EVM.
We're putting this out there as proof of concept. We're selling a limited number as validation of the idea and because we believe in shipping product in a space notorious for shipping vaporware. There is no ICO. It is technology demonstration first and foremost.
[1] https://ipfs.io/ipfs/QmRNRCocj4PwKMXrd1jeUGw7ASQSuEk7BDJu5Ks...
Physical DAI or ETH would be most excellent.
I think most others here are simply jumping too far ahead of what is being done here. This is a proof of concept type project. It can certainly be improved going forward, I'm sure.
> They consist of a flexible circuit board, specialized secure element chips and an independent NFC interface capable of powering the secure element. Each secure element stores an internally-generated ECDSA key pair that is associated with a unique smart contract on the Ethereum blockchain
Who wants bills that cost $3 ea, and are not likely to survive a wash?
> flexible circuit board
FPC != "meant to be constantly flexed". Most are not designed for a certain (not small) bend radius and to be bent no more than a dozen times. They are more meant to be curved once into a particular shape than to be constantly bent.
> I2C, raspberry pi connector
That will do great with dry pockets and ESD
> raspberry pi connector
tiny holes, so your notes can catch on your keys and any other thin sharp object in your pocket
Americans are already used to this.
I would contend it's not "in search of a problem" but trying to solve one. Specifically the usability nightmare that is cryptocurrency. Cash has tradeoffs but it has great usability properties. The space needs rebalancing in that direction.
Linen notes last about 4,000 bends before breaking, FPC lasts about 6,000. The stuff thats critical to validation is not in the 'bendy bit' pathway.
Did some ESD testing but the NFC chip bears most of the brunt here and not the secure element. Likewise the tiny holes dont bug me so much as the QF Packaging. Want to go slimmer in our next revision.
yup. with you so far
> FPC lasts about 6,000
But, how tests are done differs from what bills face: Large curve radius, slow curving, nothing sharp poking at it in the middle. Basically the opposite of what is going on in tight pockets/purses.
> NFC chip bears most of the brunt here and not the secure element.
Unless the dielectric over your secure element is some previously unknown type, a few kilovolts will arc right through it and hit your secure element.
Our goal wasn't to make this thing indestructible, it was to figure out where the bar was for "good enough".
USD benchmarks are roughly:
4000 folds
2 years lifetime (low denomination)
8 years lifetime (high denomination)
30 transactions before decirculation
For Kong we aimed for: 6000 folds
10 years lifetime
unknown number of transactions before decirculation. (Unknowable)
Survives a wash
I think it's sufficient for what Kong is now but we have ideas for improvement and I would love here yours. Specifically anything we could do on the ESD side.We've met before years ago but if you would like to get some to play with please email me.
We considered various stablecoin constructions, but most of them effectively pin to fiat which (1) seems to defeat the original intent of cryptocurrencies (i.e. think back to 2009) as not subject to the whims of central banks and (2) seems to just duplicate fiat currencies in a more expensive format.
Likewise we are doubtful that most folks holding BTC/ETH/etc. would actually be willing to spend it on something, vs. just continue to hodl in a cooler format.
We're selling packs of Kong in a limited fashion to cover the costs of manufacturing the hardware. We have a limited number of units available so we're slowly opening up sales to our mailing list.
Take a look at sections 4.2 and 4.3 of the paper for information on our lockdrop; this is the only other way to get Kong token. Lockdrops are a novel means of distributing token based on opportunity cost rather than selling the token.
Bank notes are recognized as a financial instrument by the government, and have the accompanying legal repercussions to counterfeiting. I expect no such strictness being applied to a private digital token, what exactly de-incentivized someone from going crazy counterfeiting notes? Especially considering their transactions would be anonymous too?
Correct, there is no secret service that will remove counterfeit Kong which is why you should verify it yourself or only accept it from parties you trust and have attested to previously verifying it. Habits around verification would likely be governed by the prevalence of counterfeits in a local money supply. If I hear about a bunch of 1 Kong notes failing to verify as counterfeit, then I'll likely verify every 1 Kong note before acceptance.