Hospitals could encrypt this information inside the blockchain, but then they would need to contact each other for the keys, which defeats the entire point of the blockchain. At that point they might as well contact each other for the data, after all.
Using blockchain technology also means you cannot abide by GDPR's right to forget. That means storing any personal information in a blockchain is a legal liability, at least in the EU, which limits its potential use cases even further.
Yes indeed, blockchains aren't suitable for storing personal data. No public decentralised network is. IPFS wouldn't be either for instance. By nature such networks assume no one peer can be trusted. Not the sort of thing you want to trust with confidential information.
This openness is often sold as a feature, for example running your supply chain through a blockchain means there is a publicly auditable ledger of every step, so a company claiming to have an ethical supply chain could theoretically point to that blockchain as proof. This is potentially interesting imo.
Most enterprise blockchain solutions I've seen are hybrid ones. A business can store personal data in a regular database and have non-sensitive data on a blockchain (as per the example above). The advantage of this (outside of the above use case) being that you can run SQL queries on large data sets much faster if that data is stored on a distributed ledger.
(Note: this is what the companies selling those solutions claim. I don't have first hand experience with blockchains in an enterprise context so I couldn't tell you if this is true - I imagine it'd depend on the database and blockchain in question.)
Final point though, these aren't necessarily proprietary blockchain solutions as such. They're more like SDKs businesses can use to build their own blockchains, code their own smart contracts, etc.
Whether this is actually useful for enterprise... I honestly couldn't tell you. I do think the supply chain stuff is interesting. I also think using it as a system to detect counterfeit items is another good use case for businesses. In the past, companies have created apps where you can scan a QR code and it confirms the legitimacy of the product, but counterfeiters just made QR codes that tricked the app. If each unit is tracked on a public blockchain, it should be possible to verify legitimacy with near 100% certainty.
No. A company can point at an entry that claims to be from an ethical supply chain. It's not proof that that entry actually represents reality.
Same for every other entry in the supply chain.
> you. I do think the supply chain stuff is interesting.
It's not. For the reason above.
> If each unit is tracked on a public blockchain, it should be possible to verify legitimacy with near 100% certainty.
Because a publicly available hash on a publicly available blockchain is different from a QR code and cannot be spoofed... how?
It can not be spoofed due to having been signed by a verified key (a signature could of course be encoded in a QR code as well!)
It can not be redacted, or retroactively inserted at a later point in time. The link/hash can of course also be encoded in a QR code.
Let's say I have a Rolex watch. This "item" has an entry in a publicly available blockchain available to everyone. Who's to stop anyone from producing a "Rolex" watch pointing to the exact same entry on the blockchain?
> The link/hash can of course also be encoded in a QR code.
Indeed. So how exactly does blockchain protect against counterfeit goods?
No one. But only one is signed by Rolex's keys, and therefore considered legitimate.
> Indeed. So how exactly does blockchain protect against counterfeit goods?
It depends on who you are if it does or not. It can 1) prevent inconsistencies in different databases in different orgs, 2) prevent companies trying to hide their tracks or muddy the waters, 3) provide near-instantaneous settlement and coordination
Let me ask you this; if you buy a Rolex watch on eBay that includes a QR code as proof of authenticity, how can you be confident that the same QR code has not been included with 100 other duplicate watches otherwise?
(I had this happen with fake Bose headphones, BTW. A correct blockchain implementation would have allowed me to spot that within minutes of receiving the package as well as irrefutable proof to present to eBay/law enforcement, as opposed to months later when they failed and vague evidence)
How do you sign a physical watch with keys?
> Let me ask you this; if you buy a Rolex watch on eBay that includes a QR code as proof of authenticity, how can you be confident that the same QR code has not been included with 100 other duplicate watches otherwise?
I can't be confident. So, once again, how does blockchain help?
> A correct blockchain implementation would have allowed me to spot that within minutes of receiving the package as well as irrefutable proof to present to eBay/law enforcement
- What's a "correct blockchain" and who implements it?
- How would it help if both watches/headphones/whatnot point to the same record in the ledger?
- more in two comments to this: https://news.ycombinator.com/item?id=27435785
The watch has an ID/serial number. The record on the ledger is transferred to the new owner. If both new owners check the ledger, only one of them will have been assigned the watch with the corresponding SN.
the payment could even be done atomically with the assignment of the (authentic) watch. As long as the buyer validates it, the only one who could forge watches would be Rolex.
This. How does this magical transfer happen? The moment you say "authorised resellers", please read comments to this: https://news.ycombinator.com/item?id=27435785
> the payment could even be done atomically with the assignment
What's to stop an automatic payment with the assignment of the counterfeit watch?
> As long as the buyer validates it, the only one who could forge watches would be Rolex.
Why?
Using your example of a Rolex, the code can be scanned by the authorised dealer and buyer. Those events are then stored in the blockchain next to the cryptographic hashes of both entities.
Any authorised dealer who buys one for resale would scan the QR code so ownership can be transferred in the same way on a public ledger.
If there's a public record that this Rolex has been purchased already and you scan it, this record would show up. It could even show exactly where and when it was purchased.
Clearly, for someone to put a real cryptographic key on a fake Rolex, they need to have taken it from a real one.
So if someone tries to sell you a "Rolex" and you scan it, you'll have the history of the watch right there. If they try to claim it's new, you'll know that's a lie. If they try to sell it to an authorised dealer, they'll get caught.
This could still leave space for fake Rolexes to be sold as used on eBay or something of course, but then if you buy a "Rolex" on eBay from a random seller (not an AD) you kind of know what you're getting already don't you?
(Although even in those situations, knowing exactly when and where the real watch was last purchased makes it easy to just make a phone call and get a better idea of legitimacy. Currently, even ADs send the watches to Rolex for verification because the fakes are so good.)
Right. So on top of a blockchain there's some software that inputs something on the blockchain.
What's to stop me from creating software that won't create those events, but will still check the key?
> Any authorised dealer
> so ownership can be transferred in the same way
Curioser and curioser. So now there are centralised dealers that can transfer ownership. So only selected few can create events on the great decentralised blockchain. Tangential question: if I want to give the watch as a gift, do I have to have Rolex's blessed authorised software to do that?
Also, if "authorised dealers" have the power to do this, it means they have the cryptographic keys. This also means that the rest of the world has them.
> So if someone tries to sell you a "Rolex" and you scan it, you'll have the history of the watch right there.
Indeed. So, the counterfeit watch comes up with a real history. Rolex produces almost a million watches a year. It will be ridiculously easy to pick up numbers for the counterfeit watches that are new.
Those that are not "new" can be sold at second hand markets.
> but then if you buy a "Rolex" on eBay from a random seller (not an AD) you kind of know what you're getting already don't you?
Ah. And here it is: "blockchain can help verify authenticity with near 100% certainty" devolves into "you know what you're getting into" in the span of three comments.
Sure, simply writing metadata that says "we promise we did this" into a blockchain doesn't automatically make it proof.
But that's not what anyone talks about when they discuss this.
The point is each company down the supply chain is recorded on the blockchain. The companies used to provide raw metals to the companies that run the factories to the distributors, all cryptographically sign the blockchain throughout production.
What you get at the end of that is cryptographic assurance that each party is who they claim to be and they publicise their practices.
If a someone in the supply chain is found to be using unethical practices, and the company using this approach makes a public statement promising they will use a more ethical supplier, this would be verifiable by any member of the public.
And of course all the actual software backing this would be in smart contracts meaning the source code of the actively running software on the blockchain can also be verified by anyone. This is like having reproducible open source builds but for real life objects.
TL;DR: Quite obviously, a blockchain doesn't magically turn everything ethical, but it is a tool that could well be used for that purpose if utilised correctly and combined with other public knowledge such as public audits of factories and mines and increasing regulations enforcing supply chain transparency reports etc.
It's a piece of the larger puzzle that means when a company claims to be ethical you can see for yourself instead of taking their word for it.
> Because a publicly available hash on a publicly available blockchain is different from a QR code and cannot be spoofed... how?
If the entire supply chain and the code managing it is on a public ledger, so is a log of every unit produced. Blockchains carry cryptographic proofs, so a business can use a cryptographic signature to allow a buyer to verify an item's authenticity. The signature could still be on a QR code to make it easy for the end user, but it'd be a lot lot harder to fake if backed by tried and trusted cryptography.
And then you immediately go and say exactly this:
> If a someone in the supply chain is found to be using unethical practices, and the company using this approach makes a public statement promising they will use a more ethical supplier, this would be verifiable by any member of the public.
What you're basically saying is: "If a company somehow records their PR stunt on the blockchain, they are immediately bound by it because public record, and blockchain, and smart contracts".
> And of course all the actual software backing this would be in smart contracts meaning the source code of the actively running software on the blockchain can also be verified by anyone.
And how would software running inside some other software would actually verify that a company is ethical? Or that it properly labels its products? Or that it adheres to standards? Or...
> combined with other public knowledge such as public audits of factories and mines and increasing regulations enforcing supply chain transparency reports etc.
All this is already being done, and without blockchain. What exactly does blockchain bring into the equation?
I mean, TIR has been around since 1975, to give just one example [1]
> If the entire supply chain and the code managing it is on a public ledger, so is a log of every unit produced.
1. Almost everyone already logs every unit produced. Even now you can probably trace an random individual apple from a supermarket to where it was produced. What does blockchain add to this?
2. As all logs, it doesn't log "every unit produced". It logs whatever is input into the log. If someone inputs "eco bananas", but instead ships radioactive slime, what good is blockchain?
Oh, and before you start with "audits" and all that. The supply chain isn't "producer -> consumer". It's "producer -> dozens of intermediaries -> consumer". And everything depends on what those intermediaries input. And there are already laws, practices and audits in place that ensure that you get your eco bananas instead of radioactive slime.
Or, lets use a more realistic example: 20% of seafood in restaurants is mislabeled, https://www.rd.com/article/restaurants-serve-fraudulent-fish... Every single item there can already be traced to origin, passes multiple inspections etc. How does blockchain help?
How is that not solved by a layer of permissions?
At a higher level, if you’re willing to do business with someone, and you’re providing or accepting fiat, goods, or services, there is a baseline level of trust between parties and an understanding that any breakdowns in trust will be resolved by contract law and courts.
Apple has coincidently released functionality as part of iOS 15 for verifiable health records data. Note the use of digital signature crypto primitives.
> Find out how you can securely request access to someone's verifiable health records and incorporate that data safely into your app. The Health app helps people download, view, and share their health records, including their COVID-19 immunization and test results — and iOS 15 brings support for the Smart Health Card, a verifiable health record that incorporates the FHIR health data standard. We'll show you how your app can go about requesting access to this record and how you can verify the signature of the file using CryptoKit and the issuer's public key.
Certainly there is a huge financial incentive to run a 51% attack on Bitcoin or Ethereum but thus far no one has managed it.
It's easy to get lost in the hype, but peer to peer applications always serve valid use cases. A peer to peer database is no different even if it's enamored by cryptobros and scammers.
"Blockchain" aka a Git repository is only useful when multiple trusted parties are trying to coordinate a central source of truth without inadvertently removing each others changes.
At which point we can dispense with anything that sounds like cryptocurrency because it's all just signed commits.