Hal Finney’s proposal for optimizing Bitcoin to be enabled in Bitcoin Core
btctimes.com
btctimes.com
Hopefully anyone with the time to care about this will read one of his last comments on the subject dictated through eye-movement software from a wheelchair:
https://bitcointalk.org/index.php?topic=155054.0
Vale Hal.
That's my honest opinion and you are entitled to yours, fairly sure no one will ever know for certain. There's a journalist that went deep diving on this and came out with the same conclusion, from timelines to stylometric analysis, it doesn't add up to being Hal. He's just that guy who actually listened on the mailing list rather than be the snarky one where everyone else nods in agreement congratulating themselves how smart they are.
In the last years of his abled life, the man was getting involved in whatever cutting edge technology he could find, most of this is documented, nearly all of them failed, except for twitter and bitcoin. He's now cryopreserved, something that has virtually no chance of ever succeeding in the next 1000 years, yet...
Luckily, there is not that much that points towards him being Satoshi:
https://davidgerard.co.uk/blockchain/2018/12/16/no-nick-szab...
You can be right libertarian without being a xenophobe or an outright racist.
He was not a socialist, he was a Marxist. It's like expecting that Windows and Linux are Operating-systems and by that completely the same.
It mystifies me how /pol ideology gets called libertarian. I remember when words meant things.
What does liberty mean to you? That's all libertarianism actually is, and that has always plagued the movement.
If forcibly implemented marxism means liberty or freedom to you, good enough, you can call yourself a libertarian now if you see fit. The Hayek wing will always disagree with that, however their disagreement is also entirely irrelevant as they don't have much control over the term or the movement.
You wish he was more like you?
This is a good reason why he hid his identity. Any real person would be more disappointing then the legend constructed in imagination.
But it in this case, the legend was a rather nice person. Getting this aspect of his personality destroyed would be a shame.
I just don't understand why everyone needs to be a PR polished suit. These people work on computers, not administer public policy. We can appreciate their contributions and ignore their quirks or the fact they don't have all the popular opinions.
Putting people on a podest and excusing untolerable behavior is plain toxic.
It is not wanting that everyone needs to be a PR polished suit, just wanting that people are decent human beings.
Precisely what I am saying. We can applaud Nick for contributions to cryptography without importing his views of other things. We don't have to weigh his political opinions at all.
> just wanting that people are decent human beings.
This sounds to me like "having views I like, because only undecent people would think otherwise". Do you have an instance of Nick being nasty or indecent?
Yeah, that's a sentiment you hear a lot in political discourse these days. But if you follow cryptocurrencies, you wouldn't get far with this attitude. The combination of technological, financial, and political issues that make up this field draw a lot of different people to it. Including a lot of wackos, often even with a cult following. So you need to have a good filter to find the interesting stuff.
But I followed him long enough to notice that there is no interesting stuff anymore and some of his content was showing uncomfortable character traits to me, so I unfollowed.
> Do you have an instance of Nick being nasty or indecent?
This Twitter thread by somebody else is a good start.
> so I unfollowed.
I completely encourage that.
I'm not asking for his political views to be platformed, just that we treat them separately. In other words, it's not in bad taste to respect Nick for a Bitcoin opinion, even if what else he has going on we believe or even know to be incorrect.
I just glanced at it and it looks innocuously right wing. In the context of being contender for the creator of a decentralized currency I was expecting a "far-right" libertarian type.
It’s not that the marginal probability of using a known name is high, it’s that for a fact the name used IS a known name that makes it suspect.
[1] He was a senior engineer at APh working on Intellivison and Atari VCS games [2], when I was a fresh out of college junior engineer there. (And he was amazing at it [3]).
[2] http://gdri.smspower.org/wiki/index.php/APh_Technological_Co...
[3] One of the big projects while I was there was the next generation Intellivision. It would have a significantly more powerful graphics processing chip than its predecessor. The prototypes for the new chip implemented via discrete logic on big wire wrapped card in a big card cage. We were all working hard to get some games working on the prototype, which was going to be shown in some closed demos at CES.
This was made difficult for most of us programmers because the hardware guys were still fiddling with the design. We'd work very late until we could not stay awake anymore, and go to sleep for a few hours. Then we'd wake up and head back to work...and many times we would then find a note on our development system that the hardware guys had made a revision, and replaced some of the boards with updated ones.
Those updates would often do things like change the function of control registers, or the number of sprites, or the way color worked. That sent most of us into at least a couple hours of changing our code to work with the new hardware. (This was all hand written assembly).
Not Hal.
Hal would spend just a few minutes, and his code worked again. Oh, and his code was also better performing than the rest of ours, and made better use of memory.
Hal wrote a Basic interpreter to fit in 2K of ROM. To save bytes, it had only one error message:
EH?
Still my favorite error message.Of course, all of us at Aph were idiots. We had everything needed to make a killer consumer microcomputer, did not, and missed out on being billionaires!
That was when I found out Hal was not your average bear. Usually, he was just the friendly fellow who was always up for taking as many students as would fit into his VW bug to Tommy's at 3AM. I was small enough at the time to fit in the luggage slot behind the back seat.
Satoshi's discussions on BitcoinTalk were definitely not snarky, but fairly well measured and objective.
>But it doesn’t really matter in the end in my opinion. The whole point was to not have a godhead.
Of course; but it's not about that. It's about the mystery, the challenge, the thrill of the adventure.
It's one of the absolute strangest and most enigmatic events in internet history - when else has some open source software blown up to even 0.0001% of this level with a 100% anonymous creator who no one's come close to identifying (that we know of)?
Would I reveal who Satoshi was if I found out? Probably not. Their life would probably undeservedly become much harder and much worse. But I still sure as hell would be interested to know who made this thing.
Also, if we know who it is, then we know who it isn't. Rumors over certain people being Satoshi can be very irresponsible.
Nick Szabo
Satoshi Nakamoto
the writer in me looks at those two names and sees a kind of echo/mirror/rearrangement pattern, as if someone was either trying to give a clue as to their real identity, or, to mislead in a playful waynot decisive obviously. and might have been a coincidence. but if so its a weird one
Nick Szabo
Nakamoto Satoshihttps://www.thoughtco.com/szabo-last-name-meaning-and-origin...
Phil left the project and deleted all evidence in 2011, when the FBI was getting involved. Dave died in 2013, and in 2015 Craig started to proclaim that he is Satoshi. The problem is, Craig is the least technical and least stable of the trio, so almost no one believes him.
The source for this info is actually Phil, who comes back in 2017 to tell his story at http://vu.hn/bitcoin%20origins.html#bitcoin-origins
Of course there is no hard evidence for this, so almost no one believes him as well. But I like the story, and matches some of my priors, so I'm sticking with it.
There is also the ongoing lawsuit of the Kleiman estate vs Craig, for the Tulip Trust, a large cache of bitcoins they mined together. The jury trial is scheduled for October 13, so that might also expand on the story when it's concluded: https://coingeek.com/kleiman-v-wright-trial-delayed-until-oc...
If the above poster is Satoshi (which I suspect, it being a new account), I'd like to thank you for your contribution. Your writings are underrated but will be appreciated by future economists, developers, and historians.
The bit about having to finish the documentation was particularly noteworthy. Even when writing code laboriously through eye moment, Hal didn't lose focus of the importance of documentation.
Oh, and he was off-the-charts smart, too, though you had to get to know him for a while before discovering this.
(k1 + k2 x lambda) x Q = k1 x Q + k2 x (lambda x Q)
where k = k1 + k2 x lambda mod n, k1 and k2 are only 128-bit, and lambda has the special property that for some beta, lambda x Q = (beta x Qx mod p, Qy), i.e. at the cost of just a scalar multiplication, yielding a 25% speedup.
[1] https://bitcointalk.org/index.php?topic=3238.msg45565#msg455...
backslash star: \*
3 stars: *. - Works if it's not the last characters of the post.
So it doesn't really matter who can push code to what repo. It only matters who can organise the majority of computational power.
I'm not saying it's not vulnerable, but I am saying that investing in taking over btc in order to enrich yourself will by its nature backfire, and that it's not really vulnerable to code change in any way like a centralised system.
No, the economic majority[1] also matters. If the miners decided to hardfork bitcoin and double their mining rewards, and the non-mining users did not support this change, their fork would fail because nobody would accept their coins. This is exactly what happened to the segwit2x fork[2], which was arguably less contentious than doubling mining rewards.
Even if all of the miners made a change, if it doesn't align with the public perception, the value will vanish.
The economic majority is basically tied directly to this. It's not only the holders of btc that decide the value. The more it aligns with what the public wants from a parallel currency, the larger the want, and the larger the economic majority. If the miners disalign with the hodlers, it dies. If the miners and hodlers conspire, it still dies.
In a hard fork[0], blocks produced by the newer version will not be accepted as valid by the older version (e.g. increase of block sizes, changes in rewards or additions of new opcodes). This will result in a split of the blockchain, where old and new nodes operate on two concurrent diverging chains. You can think of it as a git fork. A hard fork essentially requires all nodes to upgrade.
Hard forks are generally activated by first adding the functionality without activating it but signalling for compatibility, only actually enabling the protocol change once a subset of nodes have signalled support.
In a soft fork[1], blocks produced by the older version can be deemed invalid by the newer version - otherwise the two are compatible. This means that users don't strictly need to upgrade to participate, only miners do.
So TL;DR, if BTC Core developers released a hard fork, it would only go into effect once it reached majority support among miners. In practice, users and other stakeholders (most notably exchanges) also have an important practical voice in which chain is deemed the canonical one, in case of a split.
No, this is the worst case scenario, the core developers of a technology like Bitcoin have the power to, arbitrarily, govern the project and change the code or protocol without the people noticing or caring about it. There are obviously limits that are not acceptable to the people (e.g. SegWit2x and Bitcoin Cash). The governance of a protocol is mostly centralized. Perfectly decentralized systems are decentralized systems that never change. If they change it is because there is governance that plays in the power context.
Everything I see, from Canaries to codesigning, to simple git mirrors make it easy to detect such fraud.
Also, there are many unofficial Bitcoin implementations. And with 'core' being the only 'spec', I know from personal experience that a lot of devs of those alternative implementations, make a lot of 'eyeballs'.
Because you cannot assume that node runners and miners are spending time in reviewing commits or entering in discussions except when there are issues that are highlighted and amplified by media such as SegWit2x.
I do feel you just don't understand this still, though: if the miners all upgrade and you don't it isn't like they can force anything down your throats as you didn't upgrade.
I feel like your mental model is somehow "if 51% of everyone does something invalid then the system is now invalid", but what that actually means is that those people are rejected from your consensus.
So, if all the miners decide to run a different software this is effectively just a different distributed system. Your computer, which is checking everything, rejects all of them and keeps playing with the people who are playing the same game.
You aren't trusting anyone or assuming anything: that wouldn't be decentralized at all really. Now, is any of this efficient? No. But that wasn't a goal ;P.
But there's still a question of "how many people actually review the changelog before updating?" It's a very small number, but that might be okay. If a bad actor pushes malicious code through, all you need is one person to raise the alarm.
In general, Bitcoin is very well reviewed. I don't think it would be easy for a bad actor (even a good actor who is being compelled in secret by a state actor) to push through malicious code. But it's hard to be certain exactly how robust Bitcoin is to this type of thing.
The culture of Bitcoin is highly resistant to changes in the core code. Even optimizations are increasingly scrutinized. Attempts to influence the core devs ("psyops") are also likely to fall flat, simply because the core devs have gone to great lengths to ensure that there is a lot of red tape to making changes, and that larger changes take years to get through with hundreds of eyes of review.
And some of those vulnerabilities may have been planted intentionally, we’d never know.
Not perfect, but overall I think that's a pretty decent track record.
It is commonly known that exchanges have to implement KYC/AML and so on, so the question isn't very interesting if we are talking about whether the government has some influence on a web-wallet like Coinbase.
The computation stack end to end has alarming risks. If the average user can’t read code, then anything they use is a form of delegated trust.
The users trust the wallet software that it’s doing the right thing. The average user does not even know what validation means.
Additionally what is known about computation is public knowledge. What secrets exist within state actors or even possible ET tech that could be used to influence truth with advanced computation?
There’s certainly no guarantee of security within Bitcoin or the network. It shifts the trust model at the most.
In another perspective, the amount of individuals who understand cryptography are quite low for the entire human population. Combine cryptography with hardware and software and that’s the small percentage of people who truly “get it” and are also specifically the ones entrusted as the leaders of all. The attack vectors are large.
In order to fix this we need to reduce complexity across the stack end to end. Every individual should know how to build their own computer without having to trust any hardware or software manufacturing.
I’d argue the stack is needlessly complicated end to end. Individuals add complexity by allowing the conceptual model of computation to remain complex within their tooling and then adding their own esoteric layer on top. It’s a house of cards.
Here’s a good post by Bruce Schneier https://www.schneier.com/blog/archives/2019/02/blockchain_an...
Would I keep a significant portion of net worth in bitcoin? No.
Would I use it to make a payment like PayPal? Yes.
I do not trust anything with computation today. It is compromised end to end.
As long as the Internet depends on BGP and ISP’s there’s no true decentralization. We need ad-hoc mesh networking with deterministic address spacing. Doing so behind some type of one-time cryptographic address that maps to an IP would be interesting. A few projects are experimenting in this path. Yggdrasil looks promising as an algorithm. Ouroborus has an interesting novel stack based on recursion.
I mention all these things because it’s exactly the reason why bitcoin is not safe or to be trusted. The cult behind it doesn’t help the fact of the fragility of the situation. Much of the cult are increasing the risk of other individuals by preaching trustless models.
This is a false narrative peddled by BCash supporters. The bottom line is that the market had a chance to decide if they want to go the BCash route or the Bitcoin Core route, it chose the latter, now the supporters of the former are salty.
if you need me to elaborate on the ramifications/benefits of that let me know.
Two years ago the datacenter owners were contemplating whole new buildings. "We're going to run out of room next year, so we're planning another quarter million square feet down the road a bit." That expansion didn't happen. The space they opened up internally remains largely unused. One of the cages next to ours had a bunch of bitcoin mining racks, clearly at the DC's capacity for cooling . . . and they were unplugged because the customer hadn't paid their power bills. The DC wound up tossing the machines away after a few months. That parcel of land "down the road a bit" remains vacant.
I think the bitcoin "resource losses" go much, much deeper than an algorithmic tweak that would have been taken for granted a few months after introduction. [Okay, 25% is a good optimization, but it wouldn't have changed the basic game, nor the character of the companies involved]
Why would you need this to be the case? In my mind (im not an expert) I just imagine schnorrs batching signatures into one tx on the chain. And then its done. Why would you need to add years after?
In Bitcoin today we can do things like make a conditional signature in a multi signature. With three parties, one can pre-sign a transaction and lock it until a future date, then hand it to the other parties who can sign it at their leisure when that time is elapsed. This would not be possible with schnorr unless you also had the expectation that all parties would be online when the lock time expires.
Yes, to get the space/validation improvements you can get from schnorr you need interaction. But it's perfectly possible to use it in the same way as ECDSA, it only adds options, it doesn't remove them. For some applications the requiremetn that the participants isn't a big deal and they can enjoy those benefits, otherwise they don't.
It is like watching a state-capital system versus a free-er market compete.
People in the state-capital system have completely binary things to argue about, with dissidents being shunned while everyone is stuck in a quagmire of false dilemmas. Third and fourth and additional options are not considered.
Whereas in the free-er market, people are allowed to take risks and fail, fail with LOTS of money and value, and iterate en masse towards solutions that are most "useful" ideally, but also service a variety of use cases.
Until recently (or still) pretty much none of them had production usable implementations anywhere for any application, and most academic coverage has mostly been a glib "trivially you can do that"-- ignoring that naive "obvious" implementations end up being completely insecure.
It does not its irrelevant it chances nothing about bitcoin or its limits. Its a client side it does not speed up usage or something the CPU just useless less cycles and idles more.
If everyone is anonymous, you can probably ignore the patent. But if you want legitimate businesses to be able to use the software, you need to respect the laws in which those businesses operate.
Sure, somebody could anonymously push a patent-encumbered solution and make it available to the public, but there's a lot that could and would be done to prevent the public from using that solution if the patent owner (or whomever they sold the patent to) wanted. That would just create a "poisoned" version of the software that's taboo for every legitimate user because it opens them up to a cease&desist + requirement to pay fee+penalties for previous use.
For starters, if running a full node required to run patent-encumbered software then (no matter if that software was published on the internet) all the legitimate exchanges would be prohibited to use the software, and any US merchants would be unable to accept bitcoins, since they can't use the software anymore and any USA payment service providers who could handle the transactions for them would also be prohibited to use the software without licensing the patent.
Or is BTC too fundamentally tied to CPU-bound work?
Market forces fundamentally tie the energy consumption of the miners to the price of bitcoin.
This optimizing is for the users of the bitcoin network that must validate that the rules are being followed so they can reject any miners that do not follow the consensus rules
(I mean, if I wrote it it would probably take several hundred machines but I'm sure Satoshi or some other brilliant programmer could fit it on a single machine. It only processes what, 5 transactions per second? My first dumb cellphone might be able to do that many signatures per second if someone could figure out how to compile the relevant libraries to run on it.)
The mining is no longer (for 7 years or so) done by traditional CPUs. People use ASICs