The Royal Canadian Mint just announced a new alternative to BitCoin
developer.mintchipchallenge.com
developer.mintchipchallenge.com
Every MintChip has an ID, and every transaction is logged on both the sending and receiving device with the ID of the other device. This means that if someone takes your chip, they get a complete record of every transaction you've ever made. In other words, it's not anonymous at all. That's problem two. Bitcoin solves this by encouraging users to generate a new address/private key for every incoming transaction, so that matching up addresses to people is hard.
It's tied to single physical devices which can be lost or damaged. This makes them unsuitable for storing savings. Bitcoin wallets, on the other hand, can be backed up securely.
Both MintChip and Bitcoin can be stolen if the attached device is compromised. Bitcoin is designed in a way that makes it possible to fix that, and developers are working on a fix: multi-signature transactions (so you have several computers, or a computer and a phone, and all of them must agree to any outgoing transaction). MintChip, however, cannot solve this problem in any way except with chargebacks, and the documentation given so far indicates that they aren't supporting that.
So, in theory, the Mint might be OK with trading off security for convenience/affordability, as long as that level is below what they currently experience with cash. It's difficult to know.
That would be fine, except the compromises in MintChip give up what is essential to cash. It's more like a replacement for debit cards for small purchases.
Quick was a small chip on a smart card that allowed you to store a monetary amount and to pay with this chip at certain terminals. This worked essentially like real money: You had to regularly top-up your chip and if you lost it your money was gone.
This is all nice from theoretical aspects, but in practice it didn't provide any advantages to users. Why use your "Quick" card, when you can use your plain old debit card instead? With the debit card you earn interest, get a new card if you lose it, don't have to regularly top it up.
The same is true for this Canadian Mint thing: (As a regular user) why should I be interested? I can use my credit card to pay online and offline. I can use my online banking account to transfer money to friends. Where's the advantage?
The advantage this system has over debit is that the terminal does not need to have a network connection. So individuals can make small purchases at coffee machines, parking meters, etc. You do need to "top up" your card at an ATM-like station (Pin # required), but you don't have to enter your pin when you make a transaction.
If you loose your card, or your card breaks, you're screwed, which is why I don't like the system very much.
In a couple of years even your underwear is going to be online, so this is really a non-feature.
http://en.wikipedia.org/wiki/Mondex
I agree about your point about debit cards - I use a debit card for all day to day purchases (lunch, taxis, bars, cinema). Pretty much the only cash transaction I make is when I get my hair cut.
PS: Banking websites have their own issues. But because they tend to use multitiple forms of authentication the are significantly harder to break into on the client side.
For example, Bitcoins could be stored on a smartcard having a flexible e-paper display, flexible built-in keypad, and flexible LiPo battery [1]. Withdrawing coins from the card could require a user typing in an amount and a pin code, and then using a smartphone to scan a QR code shown on the e-paper display (or sliding the card in the merchant's payment terminal, which would scan the QR code). The QR code would represent a signed Bitcoin transaction to a pre-programmed address whose private key sits on some online server, which is only used as an intermediary step before forwarding the coins to the final merchant. The smartcard would effectively never connect to an online device during its entire life, making it un-hackable without having physical access to it. Smartcards could also be manufactured in pairs, or triplets, etc, to have clones of them in order to have redundant backups of the Bitcoins in case of a loss of one of the cards. If you know about the Bitcoin blockchain, you might ask how the smartcard can sign transactions without access to the current blockchain. Well it is mathematically possible, because a transaction just consists of ECC-signing a few bytes representing the destination addresses.
Don't discard a technology because you are unable to comprehend it enough to think of solutions to address some of its flaws. (I do agree that addressing the security of Bitcoin wallets is of utmost importance.)
[1] The technology for this already exists. I own one of those: http://gallery.drfaulken.com/d/8752-1/IMG_1466.JPG
Not sure what you mean. By 'device' I didn't mean some special hardware developed by some special company, where the government can then regulate that industry. I just meant any computer. I'm saying that signing a transaction can be done offline on devices that are never connected to the Internet, such as an old laptop, or yes even a special device. There's no fundamental requirement to have the keys on your virus-ridden home PC at any time. This doesn't remove any of Bitcoin's advantages from what I can see.
And multi-signature transactions will allow for multi-factor authentication at a protocol level.
PS: Your also describing an adhock solution. As soon as you want to mass produce them to allow significant and convenient adoption you get into regulation issues. And by 'device' I am including just the software to manage your account from a cheap netbook.
Things like the BitcoinArmory client [1] + upcoming multi-sig transactions should make it secure enough relative to traditional currencies. Use a a *nix instead of Windows (much easier for the mainstream these days with OS X/iOS/Android) + secure wallet.dat backup like SpiderOak or Tarsnap and you're in good shape security-wise.
And ubuntu...
To secure your 'real' bank account, you need your computer that you do your online banking to be secure, your need the computer in the card reader at the store to be secure, you need the computer in the POS to be secure, you need the stores back office system to be secure, you need the computers at the credit card processing company to be secure (yes you VISA) and you need your bank to be secure.
To secure bitcoin all you need is your bitcoin wallet to be on a USB key in your pocket.
Now, plug in that bit-coin wallet into a unsecured computer and within 5 seconds your account could be drained and there is no way for you to ever recover your money. Your PC and wallet might be secure, but you have literally no way of knowing that. Worse yet as soon as large numbers of people start having a few thousand $ worth of bitcoins zero day attacks are going to take on a hole new meaning.
PS: I don't do online banking or use a debit card, the entire system is horribly and fundamentally insecure. But, I only need to pay off my CC every month and suddenly I have near total safety. Or, I can walk up to any ATM and suddenly have total anonymity at the cost of some risk.
PS: I still think Bitcoins are an interesting idea. I am just describing why their adoption has been so slow. There is simply no compelling reason for significant legal transactions to use Bitcoins, which covers for their inherent risks.
This is a baseless statement.
I, for one, don't want my bank controlling my money supply or telling me how I can and can't spend it.
And my claim is hardly "baseless". You can reject the orthodox views but please don't claim to be in the majority -- whether we use the polite term "heterodox" or the less polite "crank" the fringe nature of such views is apparent.
You could have a bank account where the bank claims no liability if your debit account was emptied by a hacked chip+pin reader - they just wouldn't have many customers!
Similarly a bank could decide to offer a bitcoin account where it will offer you the option of a chargeback. It will simply charge a commission on the transaction to cover itself.
Merchants would have never come up with that on their own. It was forced on them with credit cards by consumer protection laws. Debit cards don't have that legal requirement, but consumers have come to expect it.
PS: I am not going to sue if some random website fails to ship a 200$ graphics card. So reputation becomes even more important, but only because fraud will also become far easier.
Edit -- to clarify, a mint could purchase one coin, and peg the value of .00000001 of that coin to $1. Only transactions originating from this official coin would be treated as official currency.
That said, if MintCoin gains momentum I'm sure there will be plenty of MC-BTC exchanges popping up.
Problems:
1) No mention on the Royal Mint website that I can see. News releases seem to normally be on http://www.mint.ca/store/mint/about-the-mint/news-releases-7...
2) Whois should probably point to Royal Mint, not this person's house, and not to a hotmail address.
Administrative Contact: Zaykova, Vessela vessyz@hotmail.com
Address: 131 Camelia Ave, Ottawa, Ontario, K1K 2X5 This is a suburb. Streetview: http://bit.ly/HMFiMB
3) Domain is registered through GoDaddy, which IMHO is a bad sign... like having a hotmail address ;)
4) Site T&C say the site is operated by ChallengePost.
ChallengePost has been listed on techcrunch: http://www.crunchbase.com/company/challengepost
ChallengePost.com has their domain registered through GoDaddy though, so perhaps I'm wrong about that signal :)
5) No mention on the ChallengePost blog at http://blog.challengepost.com/
6) Vessela Zaykova does apparently work for the Royal mint though, according to http://ca.linkedin.com/in/vessela
So - very interesting news, an inadvertent early leak, or very elaborate hoax?
Oskar
Note how excited we are that the winners receive gold bars. -Brandon
The Mint will be issuing a press release momentarily.
Government bodies move slow as all hell. Even when a specific department of the Mint authorises something, it'll have to pass through about six other departments before a blog post is signed off.
(the goats thing is a timeline of currency, seems relatively self-explanatory to me)
http://www.techvibes.com/blog/royal-canadian-mint-developing...
"...will be formally unveiled on April 17 by Chief Financial Officer Marc Brulé in a keynote at The Canadian Institute's Forum on Canadian Payment Innovations.
The digital payments space has been booming recently. Canadian-born companies like PayFirma and NetSecure are already active in the mobile payments industry, not to mention American counterparts such as Square, as well as some failed ideas such as the Bitcoin."
Doesn't necessarily mean it is real but it does seem to be.
[1] Average price from https://www.cavirtex.com/home
It could also be a ploy by Square or Payfirma for recruiting employees among the contest applicants.
This strikes me as an attempt by the Royal Canadian Mint to disintermediate credit card companies by offering a new, low-cost, "irrevocable," centrally-controlled payment system.
This seems to be exactly what they're doing. From the Developer Guide, Background page: "The emerging digital economy must be able to accommodate small-value transactions, such as micro transactions (under $10) and nano-transactions (under $1). The Mint hopes that software developers and entrepreneurs will use MintChip to ignite trade and commerce for these very-low-value markets."
The title of this post equates MintChip to BitCoin, but the two appear to have significantly different goals. MintChip may end up being the digital equivalent of pocket change.
http://en.wikipedia.org/wiki/Proton_(bank_card)
Having used this myself, the problems were numerous. First of all, it's effectively a new currency, so you have to explicitly convert your cash money into this form. This sucks. But because it's meant for small purchases, you'll only ever have pocket change on there, which means your balance runs out all the time. The card doesn't display its value, so you risk looking like an idiot and pissing off every customer behind you when they see you tried to pay the 'fancy way' and failed.
Of course, today things are different, and the web is hugely important, and most of us carry smartphones. But do you really want your ability to use money to be tied to your phone's flakey battery?
I think the real goal is that it offers offline digital user-to-user transactions.
From a 2-minute introduction this looks like it's based on trusted computing in offline situations, since you don't need cloud acceptance of a transacation ala bitcoin.
If that's the case, there's nothing making this unhackable.
I wonder what's the timeframe before we see a illicit "client" that creates value transactions without deducting from the user's balance. There will certainly be a huge effort to create such a thing.
update as I read more: It's optionally an SD card or a USB stick. clever way to interface to most every existing phone/laptop!
With the backing of a bank, it's possible to be anonymous, offline, and prevent double spends with standard user-trustable computation - really, I kid you not.
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.46.4...
It relies on having a third party that's trusted to be a reliable provider for value and knowing customers identities to punish double spenders (a Bank). (You can give up this requirement if you want to give up one of the other qualities I mentioned above, but those are different papers ;)
1. An account holder looking to spend creates a coin through a mutual process with the bank, which debits their account. The bank is unaware of the identity of the coin, but knows that it conforms to certain properties.
2. The coin is comprised of multiple parts P_1 - P_n, each of which has two pieces, P_i_1 and P_i_2. The account identity is encoded in the coin such that it is recoverable if and only if one has both P_i_1 and P_i_2 for any i.
3. To spend, for all i, a merchant requests either P_i_1 or P_i_2. (most likely based on the merchant's identity).
4. The merchant eventually turns these coin parts over to the bank, which credits their account. If the bank sees multiple spends of the same coin, only then can it put two corresponding pieces together and deduce the account holder's identity.
There are of course many details that force the parties to behave honestly at every step. The paper is somewhat old and I have no idea of further work (I'm not especially interested in protocols that require a bank or user identities). Main point being that if you do have a bank, designing protocols becomes much easier (Simple blind-signature tokens, for instance. These are anonymous but require online transactions).
Now I'm interested in how step 1 is accomplished, but that's probably too involved for a comment - I have the paper, I'll see if I can figure it out.
Thanks! That was very helpful. A quick skim of the paper backs up what I could find, so it looks like you remembered well enough :)
I think setting n = log_2(maximumNumberOfMerchants) and hardcoding which merchants ask for which pieces is a straightforward way of preventing all unpunished double spends while keeping n relatively small. BTW, with general progress of zero-knowledge techniques I'd be surprised if there weren't a more modern and concise paper in the same vein.
So current hardware solutions like visa and debit are secure because they use a trusted 3rd party. And not anonymous.
Bitcoin traded trusted 3rd party for trusted cloud (its p2p nature) and so was still not really anon if you put in any effort.
This is supposed to be 3rd party-less, fully anon. So thats a lot of trust in the hardware. It does seem uniquely vulnerable in ways we haven't before seen with visa and debit or bitcoin.
Not saying the potential for a hardware exploit resulting in a money tree isn't there...
My guess is that us foreigners could register a company in Delaware etc, and compete.
But in all seriousness, if MintChip is for real and doesn't get hacked, and if I can finally say good bye to the penny (which I have already been getting rid of for over 2 years) then I'll have to admit that the Mint is probably more innovative than any other government entity up here. :)
http://www.bankofcanada.ca/banknotes/bank-note-series/polyme...
/**
* Creates a new demo.
* @param o The object to demo
*/
public Demo(Object o) {
this.o = o;
String s = CONSTANT;
int i = 1;
}
That aside, this is basically a good idea with laughably poor execution. Other comments have addressed that it’s centralised and non-anonymous, can be double-spent, is not fault-tolerant, and (perhaps worst of all) is a fiat currency without fixed supply. There could indeed be a superior alternative to Bitcoin, just waiting to make the leap into the mainstream—but this is not it.Pretty much everything after that java snippet is incorrect in your post.
I wish there were a middle ground - institutionally backed bitcoin. I suppose there will be, once all the mining is done and ownership becomes consolidated.
[1]http://developer.mintchipchallenge.com/devguide/ecosystem.ht...
You could realistically do something almost as good as that without any reliance on either bitcoin or trusted computing, if you have a central authority. It actually seems pretty simple: You create a website where people can put in a credit card numbers and exchange money for secret (1000+ bit) numbers. The server keeps track of how much money is associated with each number. If you have a secret number, you can then go back and trade it back for money, or you can (anonymously) trade it for a different secret number -- which permanently invalidates the old one and assigns its value to the new one.
This way when you want to spend money, you just disclose a secret number worth the value of the transaction in question to the payee, who immediately exchanges it for a new number that the payer doesn't know, and is thereby the only one who can subsequently trade it back in for government currency. (Of course, in the common case they just re-spend it in the same way as digital cash rather than redeeming it for government currency.) Make it so that you can specify values (i.e. trade in a $5 number for a $4.50 number and a $.50 number) and you create a situation where anyone can sell anything and receive a number as payment, and then buy something else and spend the number as currency, all while neither of the other parties or the payment processor have any idea who you are.
Add to this the availability of VPN accounts that assign all users to a single public IP, so that users can route their SSL-encrypted transactions through an IP shared by thousands of others who do the same and thereby prevent the transaction processing server from associating transactions with IP addresses, and you have digital anonymous cash.
The main disadvantage is that the secret numbers are exactly like cash, i.e. if someone gets hold of them then they've stolen your money, it's gone, and there is nothing you can do. But that's how cash works. And I kind of wish someone would implement something like this -- I mean think about all the money you could make just by holding the currency people pay you for the numbers in low risk securities between when someone pays for one and when (if ever) it eventually gets redeemed for government currency.
+1. Not just something to think about; I feel this was a Satoshi-worthy comment.
The only two meaningful categories of currency are "large" and "small". Large currency is cash, coins. It can be manipulated with the hand, verified by the eye. "Small currency" is expressed as microscopic state, and requires complex tools to observe, verify, etc. Both bitcoin and mintchip are microscopic currency. Computers function, then, first and foremost, as a kind of microscope.
My theory is that small currency is only as secure as the microscope used. And 'microscopes' expressed on computers are themselves expressed 'in the small', requiring other microscopes to verify, which can in turn be subverted. It's subvertable microscopes all the way down.
What is the solution then? You need a cheap, 'trusted' microscope/small wallet from a single source. It needs to be cheap so that it can be replaced frequently (lost or stolen). It needs to be from a single source because if trust is ever broken you need to get it from a different trusted source.
Also, it would be smart to limit the amount on a single device to being less than or equal to the cost of physically defeating the device.
Mind you, the MintChip "microscope" is incomplete: it requires a host system to do user interaction. Which, in my view, will always be the primary weakness of any small currency. All you need to do is write a dummy program to fool a user into believing they received the money, and you've won. And that's trivially easy.
That would be correct.
>The only two meaningful categories of currency are "large" and "small". Large currency is cash, coins. It can be manipulated with the hand, verified by the eye. "Small currency" is expressed as microscopic state, and requires complex tools to observe, verify, etc. Both bitcoin and mintchip are microscopic currency. Computers function, then, first and foremost, as a kind of microscope.
What are you even saying? I saw where you were going and then you took a swerve left at the last second. How does storing state in a microscopic state turn a computer into a microscope? I assure you that no computer hardware works by looking at stored state with a lens and using computer vision algorithms to determine the state of the device.
>My theory is that small currency is only as secure as the microscope used. And 'microscopes' expressed on computers are themselves expressed 'in the small', requiring other microscopes to verify, which can in turn be subverted. It's subvertable microscopes all the way down.
A pet peeve of mine is calling such guesses "theories" at this point the proper term is "hypothesis". At any rate this is what cryptography is for. No amount of "subversion" is going to break checksums and hashes. (In a way that wouldn't set off serious red flags to users.) (Though turning them into a usable monetary system is left as an exercise for the reader.)
>What is the solution then? You need a cheap, 'trusted' microscope/small wallet from a single source. It needs to be cheap so that it can be replaced frequently (lost or stolen). It needs to be from a single source because if trust is ever broken you need to get it from a different trusted source.
It needs to not be from a single source you mean? If not then that sentence makes no sense. As it turns out; hardware bugs are actually harder to find than software ones. It would be better to use general hardware if only because you'd be less likely to find an intentional Trojan horse for bit-coin or similar in it.
>Also, it would be smart to limit the amount on a single device to being less than or equal to the cost of physically defeating the device.
So about the cost of a 5$ walmart screwdriver? A 50$ Blowtorch? It would end up being too low and you know it. It'd be better to just do an arbitrary limit like 500$ and call it done.
>Mind you, the MintChip "microscope" is incomplete: it requires a host system to do user interaction. Which, in my view, will always be the primary weakness of any small currency. All you need to do is write a dummy program to fool a user into believing they received the money, and you've won. And that's trivially easy.
Man in the middle attacks were something that certificates were supposed to solve; but didn't.
It'll be interesting to see how this all plays out.
Oh sorry. It's a somewhat strange concept I admit, but it's served me well. There are a couple of ways to motivate it. Let us say that a computer has 4G of memory (roughly 10^10 bits). That is a vast amount of data. If that were to be printed out into a sheet of paper, with each bit a dot about what the naked human eye can see (call it .1 mm square) then it would be a sheet about 10 square meters (10^5 * 10^-4m = 10m^2).
The actual size of a 4G RAM chip is more like 1mm^2. This is a reduction factor of 10,000.
Let us say that a physical screen operates at the density of our original printout . This implies that the software sitting between the display and main memory is essentially functioning as a microscope, making visible to the naked eye a sheet of paper that is 10,000x smaller than we can see.
But if we consider information rather than data, the magnification is an order-of-magnitude higher, at least. (A screenful of characters 10px on each side requires 100bits, whereas the codepoint takes around 8bits.) And of course if we consider hard-drives rather than main memory, realize that a TB is roughly 1000x main memory, or 1000 sheets of paper, each 10 meters square (about 310 square meters).
You know. I think I'm going to use that in the future. Thanks.
Thanks! I hope you can revisit what I said in the grandparent post with this in mind. :)
Though BitCoin is related, I don't see a a reason to inject it into this particular thread. BitCoin is its own beast with different goals... in fact... opposite goals (while using some similar technologies). BitCoin is happy as the backbone of an edge economy and not a competing system with centralised solutions like MintChip (which has decentralised aspects as well but not the core foundation).
MintChip = checking account, Bitcoin = savings account
The only differentiating factor here is the currency is "mintchips". How much more creative can you get with a checkout when we are only changing the "backing" of the numbers that are moving around?
I suppose an app that allowed offline transactions would fit that bill, the only problem being that your app would be offline.
“Bitcoin offers currency from a decentralized source, whereas RCM's solution is from a centralized authority.”
Unburdened by the need for a proprietary network, MintChip offers a cost effective solution to consumers and merchants and enables easy person-to-person payments.
So, it looks like, this is the government's attempt to compete with Interac. The site claims it's a replacement for cash, but the last time I used cash was maybe two weeks ago to pay for a coffee. And I know some people who use a prepaid card to buy coffee.
[1] http://faircash.org/fileadmin/dateien/fairCASH_Patent_Applic...
They only make sense for transit (or other one-way systems, not peer to peer), and there, providing Internet at the point of sale is easy.
If the issuer claims to have backing for the currency then for each CAD issued on a MintChip there would be a CAD in a bank somewhere. Same for USDs.
Since the mint can buy BTCs to issue as well, no reason MintChips can't be used for Bitcoin commerce as well.
http://developer.mintchipchallenge.com/api/java/ca/mint/mint...
[google] this was us! http://www.mail-archive.com/cryptography@c2.net/msg00993.htm...
They do seem to be fixing one of my primary objections to BitCoin by providing it some real backing... or again, so they glibly claim without details.
If it is just "Hey, we'll store monetary values in the cloud" they're going out of their way to obscure that.
monetary value is stored on the hardware itself it seems, as you can do an offline transfer between two people.
bitcoin needs the cloud as an intermediary to transfer value (cloud acceptance of transactions)
as well bitcoin has traceability with unique identifiers and the text on this site suggests "no user data is transmitted with payment".
The 404 page is horrifying.
Deleted comment
MintChip value can be stored and moved quickly and
easily [...] by physically tapping devices together
Ugh.Here: http://developer.mintchipchallenge.com/devguide/developing/c...
Each transfer message has both the Sender and Receiver encoded within it. These are opaque but generated by your mintchip provider.
Looking here: http://developer.mintchipchallenge.com/devguide/ecosystem.ht...
Suggests that your provider ("trusted broker") creates your mintchip ids. It might be possible to associate many keys to your physical person but I believe all of them could be traced back with the co-operation of the providers.
The giant caveat is that the documentation online does not seem to indicate whether or not a transaction log is stored in the trusted hardware.
Basically, BitCoin for the time being is an interesting asset/investment, but not a very good cash replacement.
As long as the sender converts their money just prior to paying and the receiver converts back to local currency soon afterwards, there should be no problems.
I guess the big assumption here is both parties have access to a reliable exchange that can easily handle the volume of currency being transferred.
Compare that to the fees charged by Western Union or Money Bookers or credit card companies.. You're looking at $30 minimum + 6%-12%
Whether this is the natural market price or if there is manipulation going on is hard to tell.
Certainly bitcoin is more volatile than the dollar, pound or euro but those currencies fluctuate in value too.
Bitcoin will be volatile whilst new coins are being minted, it is in an inflationary phase and the only upwards pressure will come from demand outstripping the supply.
This is more like a credit card that we can use to pay one another directly, than a new monetary system.
Nothing on their website gives me confidence that any of those issues have been addressed, or will be. And in truth, the idea that a national government would open up an unmonitored currency for System-D sounds just-William-Gibson-enough to be plausible, and just too Neal Stephenson to not deserve a rimshot.
What's a lot more likely is that this is a big-ass trojan horse for the media to make sweet love to for the next few months while castigating Bitcoin for supposed flaws, and eventually deeming it "unsafe", followed by "illegal", for the general population. It's a PR stunt to compete with BTC in the eyes of a non-technical public. And it'll probably work - for a non-technical public.
But the flaws in a system like this will likely become apparent much more quickly than, say, the flaws in the Federal Reserve system did. Nothing with a backdoor, closed code or centralized "trusted distributors" stays safe for long these days. I really had to laugh when I saw their nifty graphic over here: http://developer.mintchipchallenge.com/devguide/ecosystem.ht...
But we're not biased. Hell, we'll start accepting the junk if it's as good as they say. Let the best currency win.