Is Bitcoin Broken?
bitcoinfoundation.org
bitcoinfoundation.org
The Bitcoin paper at least presented a thorough argument. Andresen, who did not seem (in his Bitcoin Reddit post) to have grasped that argument, is obviously unhappy that "Bitcoin" didn't get a preprint or approve its presentation to the press. But the authors of the paper signed their name to it; the lead author is a lecturer at a serious university.
Instead of rebutting any technical point the paper makes, Andresen casts aspersions, alludes to a "peer review" process that would not have prevented the paper's publication, and then suggests the paper is flawed technically. Well, how?
Here, instead, is a vastly superior critical response by Ed Felten:
https://freedom-to-tinker.com/blog/felten/bitcoin-isnt-so-br...
Let me lay out the argument from our post in a more technical way: the biggest problem with the Eyal/Sirer paper is that they don't think about the problem as an equilibrium problem, but rather argue about what's best from the perspective of a particular player. This leads them to propose a strategy which is not even optimal for any player (we prefer to think of Bitcoin as a kind of consensus game, in the game theoretic sense. See our earlier paper on the topic [1]).
They argue that Bitcoin is not incentive-compatible by virtue of the strategy they demonstrate. I think this question needs to be the crux of any Bitcoin research paper. I'll define "incentive compatible" to mean one of two things
(1) (weakly incentive compatible) If people follow their incentives, rather than the rules of Bitcoin as written down and understood by the community, then there exists an equilibrium in which all players follow the rules.
(2) (strongly incentive compatible) The above equilibrium is the only equilibrium in Bitcoin.
The question of whether the current Bitcoin ruleset is incentive compatible strikes me as the most important Bitcoin research question: it answers whether Bitcoin, as a system, will continue to be stable over the long term. A secondary question is to ask "what rule sets could exist which would be incentive compatible?" Obviously, if the answer to the first question is "no" then the second question is more important.
I also agree that the Eyal/Sirer paper seems naive about markets.
--
PS. This thread should be at the top of this page. (Currently, another thread I started is at the top; I hope this thread shoots up past it.)
Is a Democratic Republic incentive compatible over the long term?
But my assessment of his post is descriptive, not normative. When you respond to a detailed technical report by criticizing the way it was presented to the press, then suggest technical flaws without actually explaining what those flaws are, that is innuendo.
Maybe you feel innuendo is warranted. Whether the mining game in Bitcoin is or isn't tenable over the long term doesn't much matter to me, because I'm one of those people who feel Bitcoin has no intrinsic value, and has a spot price today that represents in part irrational excitement about Bitcoin and in part a cynical scalping of that excitement by speculators. Bitcoin could be the most solid imaginable distributed cryptosystem and I'd still have problems with it.
I was motivated to comment about Andresen's post because I was also struck by his Reddit comment on the ES paper, where it seemed that random laypeople on Reddit were better prepared to discuss the technical implications of the paper than he was.
In the ES paper, and in your responses, the assumption is a colluding group of miners. I find myself agreeing with you there; it looks like the colluders have more incentive to break ranks. But suppose a single individual controlled 33%. Couldn't they use this same strategy to benefit more than we previously thought they could?
Yes, I think they could. I'm currently trying to model what happens in mining pools where the pool master attempts to keep the pool's state a secret from the pool members to deter the kind of hopping behavior necessary for fair weather mining.
Still, I would have liked to see a more technical rebuttal from Mr. Felten, so I hope he posts more in the near future. I don't see how being a fairweather miner like he describes is an issue. Pools already employ strong protections that prevent pool-hoppers from gaining anything.
I started implementing a simulation of the attack last night in an attempt to reproduce their results.
[1] http://www.reddit.com/r/Bitcoin/comments/1q22kg/a_start_to_r...
http://www.reddit.com/r/Bitcoin/comments/1puk1a/arxiv_paper_...
You can't know ahead of time which pool to bet on, unless you know that the ES pool is ahead. There's nothing guaranteeing that pool miners are decentralized, in fact by design they would have to be centralized to keep completed blocks private.
If they were public they could be neutered by one rouge agent in the pool that immediately publishes completed blocks. So you have no way of knowing how far ahead an ES mining pool is. So on what grounds could you decide which pool to help?
If you see it work on top of yet another block that is not published, it's probably two ahead, and so on.
You of course, can't just connect and immediately know, but if you watch the pool (as a miner) you can figure it out.
So I was wrong.
Our argument is that the protocol, as stated, is not incentive compatible. That's ironic, because the protocol, as stated, is offered as an argument that Bitcoin is not incentive compatible.
Bitcoin attempts to create a protocol that doesn't require trust between parties, but needs to robust against large groups (e.g. blocks of Chinese) who trust each other. So I don't think it's ironic that the ES attack is not incentive compatible, nor do I think it's really a flaw.
The reason this doesn't prevent defection is that while you can produce a provable commitment that you're mining with the ES miners in one moment, all other moments you can be defecting and sharing the ES state with your friends.
Translation: next time, please send us the paper in advance and get it peer reviewed before you start talking to reporters.
"I’m not going to write about the specific claims in the paper... However, it is good to note that in my initial review, I believe the paper’s assertion of a fundamental flaw is based on some over-simplified assumptions about how the bitcoin mining market works."
Translation: the paper's claims are probably wrong.
If he tore into them then other researchers may feel less inclined to look at the network/protocol and undertake their own research.
That said, the way this whole paper has been released smacks of sensationalism. I'll take the Eyal at his word that he's concerned with Bitcoin's future, but failing to adhere to the standards of responsible disclosure and entitling a blog post "Bitcoin is Broken" really make me wonder about what they're trying to do, other than self-promote.
Besides, this basic attack is something that has been discussed since 2010. There may be a few subtle differences in the paper, but based on my reading of the blog post, this is an attack that mining pools have even accused each other of doing a year or two ago. It's a potential problem, but definitely not a "Bitcoin is fundamentally broken" problem as the blog post claims.
In other words, the entire institution of science (computer science in this case) is better off if the individual researchers are careful about presenting things to the press and make sure to review things carefully before publishing.
But the incentive for individual researchers may not be aligned with this. An individual researcher might be able to advance their career by going to the press (particularly about a hot-in-the-news-right-now topic like Bitcoin) and by making sensational claims ("Bitcoin is 'Broken'!") even if the overall scientific enterprise suffers. After all, had you ever heard of Ittay Eyal or Emin Sirer before this? Given these skewed incentives, at least a few people will "cheat" the system by going to the press, and those people will profit by it.
Rather like Eyal and Sirer's claim for Bitcoin miners.
- - - - - - - - - -
To discuss the merits of the paper itself (rather than Gavin's response), if a mining pool were to utilize the strategy described in the paper it would result in that pool repeatedly releasing new chains that are longer than the existing blockchain but which fork one OR MORE of the previously released chains. While this is allowed under the Bitcoin protocol (this is the way that forks in the chain get "healed"), it is also rather obviously visible. So if certain miners were following this protocol then it would quickly become obvious that they were doing so. The community would then be able to take actions to redress the problem.
One could even imagine creating "poison pill" derivative instruments where someone agrees to sell a lot of BTC if some predicate over the blockchain becomes true (such as a predicate that's only true if ES-mining is happening).
That's fine and all. But not very newsworthy.
> However, it is good to note that in my initial review, I believe the paper’s assertion of a fundamental flaw is based on some over-simplified assumptions about how the bitcoin mining market works.
Not really. Most of the arguments are based on false premises, like the claim that the codebase is of high quality or has never had serious breaks. I've looked pretty deeply into Satoshi, and nothing makes me think it's not exactly what it looks like: one guy.
They might not have powerful enough machines to actually brute-force normal Internet encryption standards, but they are probably still attempting to develop them, and it shouldn't be surprising if they now have a SHA256 hashing network that can blow the entire world's bitcoin mining operations out of the water.
Alternatively, some other entity may have attempted to build a hashing network to crack online encryption, and they developed bitcoin as another way to try to use their network.
Conspiracy theories, yeah I know, but come on. Is it not at least plausible?