Bitcoin withdrawal processing suspended
bitstamp.net
bitstamp.net
Quite how you manage to link it to be a result of a "truly free market" is beyond me.
With Bitcoin the entity holding your assets and operating the trading mechanisms are generally the same company. This leaves a customer in a weaker position and could allow the exchange/brokerage/bank to get away with shadier practices. They can do things like delay the execution of a transaction until it better benefits them. Or they can unillaterally suspend the ability to withdraw funds with no advance notice, just as what is happening here.
Edit: You of course do not get the funds in the case they are credited back to the original person at the end of the 3-5 days, you do probably get a fee for trying to deposit a bad check though!
At the end of the day I don't have access to my money, or I have to call their "customer support" and spend hours explaining the problem that they created.
If the bank goes down completely (as in: goes bankrupt), my deposits are only guaranteed by the state up to a certain limit, which isn't that high.
Regulation and "liability" buy me very little in real terms.
Large banks do have bugs, and sometimes even admit it. [0][1]
The fractional reserve system basically means if there is a problem, you need to be the first at the counter. If you are not, you will only get a certain amount of money back.
[0] http://www.telegraph.co.uk/finance/2737388/Bug-crunches-Hali...
[1] http://www.independent.co.uk/news/uk/home-news/lloyds-bankin...
Edit to add: (But not quite the same as the one above)
http://www.dailymail.co.uk/news/article-2426519/Gang-arreste...
http://article.wn.com/view/2012/06/26/Lloyds_TSB_computer_gl...
In any system with deposit or investor insurance, e.g. the United States, you will get back the full insured amount (up to $250 000 for bank deposits, $500 000 for investor funds). Beyond that you will be treated as the senior creditor that, as a depositor or investor, you are. If you want more certainty as to the return of your capital, buy Treasuries.
I probably should have mentioned I am in the UK. You get back up to £170k here ($280k) but I guess my point still stands :-)
Edit: (Oh, that's for a married couple by the way. £85k if you're single.)
Stop, you're killing me here.
I suggest playing with Dogecoins. It is beginning to become serious, and their community prefers to stay out of this political nonsense.
Dogecoins took some practical things and made them better. No ASICs exist yet for Dogecoin, so its still possible to mine them on normal computers. 1-minute block times means they're much faster than Bitcoins, and its refreshingly silly that people are sending each other thousands of DOGE at a time. (current exchange: $10 == 5,680 DOGE)
So it is ridiculously easy to get yourself thousands of DOGEs to play with.
Q
Remember, SHA256 was designed for speed... and easily made into a hardware implementation. SCRYPT however, was designed to be slow and explicitly designed to be difficult to implement on ASICs (its possible of course, just harder).
-------------
As for the 1 minute box, if you want security, just wait for 10 confirmations in DOGE. If you want speed, you can wait for 1 confirmation. Faster confirmations are strictly more flexible than slower confirmations.
https://alpha-t.net/product/scrypt-asic-miner/
In comparison, your typical R9 290X is hitting 0.8 Litecoin MH/s in 300 Watts.
Your typical Litecoin ASIC Miner is ~26x more power efficient than a GPU.
The 290x hits ~850 MH/s with Bitcoin at 300 Watts. But ASICs will soon hit 600,000 MH/s at 300 Watts. http://www.butterflylabs.com/monarch/
Basically, BTC ASICs are 700x more efficient than GPUs. LTC (and other SCrypt ASICs) are expected to only be ~20x more efficient.
By making ASICs less efficient, it keeps more of the control of network in the hands of the individuals. SCrypt is the better hashing algorithm for ANY self-proclaimed libertarian, who wishes to remove power from the ASICs that have taken over the BTC network.
So we've got a system that allows for greater ease by having the potential for a 1-minute confirmation, vs a system that FORCES you to always wait 10-minutes.
The system with 1-minute confirmations can always wait for multiple confirmations to increase security. But the system with 10-minute confirmations is forced. Instead, you have tons of sites that wait for 0-confirmations!!
One system is more flexible than the other and solves a pressing need in the core system. Whether you like it or not, DOGE has learned from BTC's mistakes and is improving upon the status quo.
I don't think DOGE is perfect quite yet though, maybe a few more "fun" currencies will come and go before we stick with a winner. But it is clear to me that BTC has too many core issues at hand for it to be the cryptocoin of the future.
The thing with bitcoin is that it is a software protocol, you don't have to apply politics to it. That is like saying TCP/I has a leftwing bias.
Anyone who has studied ethics understands that technology can have political leanings. Robert Moses's Bridges for example, were designed so that African American's would be unlikely to enter certain parts of New York City.
A Bridge in of itself is not pro-segregation or anti-segregation. But when Robert Moses used bridges to block bus traffic to certain areas of New York City, they were being used as pro-segregationist tools.
Technology is NOT politically agnostic. Only the naive or uneducated can believe that.
-------------
DOGECOIN's politics have been explicitly stated. It wants to be a fun and easy coin for people to get into. It is unlikely to last very long (the 100 Billion DOGE soft-cap will be hit rather quickly), but they hope to learn a lot about coins in the meantime.
Bitcoin's politics have been decided as well. Libertarians are beginning to wield BTC as a way to push their values.
I'm simply stating that one of these communities is much funner to work with. Keeping coins "fun" and "easy" resonates with me a lot more than the typical libertarian I hear about BTC.
I agree that would certainly be nonsense.
But any technology project most definitely can implement the ideological beliefs of its creators, if it's designed to do so and succeeds in achieving that design objective.
For example, the World Wide Web was developed to facilitate sharing, exchange and collaboration.[1]. You might say Tim Berners-Lee did have certain belief system and that he did implement those in his design.
[1]: https://en.wikipedia.org/wiki/History_of_the_World_Wide_Web#...
Who would disdain to subscribe under this flowing banner?
Instead of greedy speculators who are willing to pump and dump or crash the economy to make money off of the ignorant?
Sometimes, the market does not figure it out... especially with a populace that is imperfectly educated (and not "perfectly logical, perfectly rational" beings in most theoretical economics)
But even with perfectly logical and perfectly rational beings however, there still are market failures. And it is up to the population to create Governments to deal with these market failures. (Usually through deregulation or regulation)
Case in point: LEXG, a 2010 stock that is widely considered "pump and dump". Despite all the regulations, and centuries of knowledge of pump and dump... it still happened.
BTC itself has a growing volume of trade... but a lot of smaller cryptocurrenies are simply pump-and-dump schemes.
Do you think we'll always have an "imperfectly educated" populace? Do you consider yourself part of that sector of society?
Its well known that economic models of "free markets" fail instantly on the first assumption. We are not perfectly rational beings with perfect knowledge.
And yet, a number of "free market" arguments are based upon this fact.
That's not really an if, it's a simple fact that has and probably will always be true.
> why let them elect representatives
Because millions of idiots turns out to be better than kings and dictators for the average quality of life.
Any form of "removing idiots" from the voting pool will give comparisons to the Literacy Test, and you will be literally compared to a slave-driver. http://en.wikipedia.org/wiki/Literacy_test
False dichotomies are the bread and butter of politics. Perhaps if you knew the history of this country, you'd know that you aren't gonna get very far on this subject.
I welcome you to try, but from a political / historical point of view, there is too much bad blood in this discussion for people to discuss it sanely.
But the point we're trying to make here is philosophical, not practical: If people are too uneducated to participate in a free market economy, why do we allow them to vote?
An organization who controls who and what votes is far scarier than letting idiots vote. We in America have destroyed any organization (government led, or whatever) that attempts to limit the number of voters.
Mind you, who should decide who can and can't vote? The free market? The Government?
The answer is no one. The right to vote is considered sacred and that is a good thing. No one can or should deny others the ability to vote.
EDIT: I'm surprised that I have to lecture you on this. I thought you were a libertarian? Aren't you all for personal rights and liberty? The freedom to vote is absolutely essential, and a holy right regardless of your political background.
But it is THAT much more important if you're a self-proclaimed libertarian. Personal freedom is the king of the Libertarian philosophy.
That isn't a natural right. That is born out of the system of governance that we've decided is best. There is no natural right to vote — not in the same way we have a natural right to speech or defense or anything else of that manner.
Democracy is dangerous. Our founding fathers despised true democracies, which is why they founded this country as a Constitutional Republic, and notably one that not everyone could vote. Many call them racist and sexist, and no doubt that was part of it, but they also understood that having a bunch of uneducated people voting could be disastrous. NO ONE should be allowed to vote your natural rights away, yet you see this in democracies all the time. You're right, though, the trick is figuring out an acceptable way to proof voting privileges.
Even the word "democracy" didn't come into popular use until the progressive era.
So yes, when we follow true Constitutionalism, voting is important because we should be selecting our leaders to uphold that limited government. But in our current system, we've given government so much power that we allow people to elect leaders that are going to give them the most, all whilst selling off the power they have taken from us to companies that want to protect their business model.
And once again, you really need to stop doing the whole, "I'm surprised you aren't smarter" bit.
Your own argument against voting defeats your own statement. You don't even trust your fellow citizen the right to vote, and yet you believe that citizens are smart enough to "route around damages" being done to the economy.
Listen here. I'm the one bringing up anti-market and pro-communist points against you. The fact that YOU are the one who wishes to limit voting is deeply ironic.
Democracies are anathema to anarcho-capitalist societies, because NO ONE should be able to vote to force you to do something you choose not to. Again, this is the pure governance/political theory I'm using to explain why I'm not being ironic in my thinking.
I never said I had thought of a good way to test voting. I only said that I thought it strange that we were attacked for suggesting that we even think about it — particularly when this "right" to vote is actually only a privilege granted by our various constitutions, and not a true, natural right.
Either you have an answer or you don't. The history of the U.S. is completely irrelevant to this question. I don't live in time when blacks couldn't vote or women couldn't vote, it's irrelevant to the conversation what the U.S. used to be or used to do.
Perhaps your panties are in a bunch because you think I think you're advocating a return to monarchy; I don't think that, so let it go. I think you're advocating for a return to the 1800's view of the constitution because you think it was a golden age of freedom before the federal government got so powerful. This is a typical anarcho-capitalist view and one I also disagree with.
However, trying to prevent people from voting is authoritarian whether it's from a king or from a congress and I won't support it under any circumstance. The people would certainly never vote to remove their right to vote.
FYI, you're making a logical fallacy, an Argument from Ignorance.
Ignoring your second part. (But I'm guessing you'll focus on this rather than my first sentence.)
-- Declaration of Independence 1776
The words "Natural Law" and "Natural Rights" only makes sense in the philosophies of John Lock, which inspired the Declaration of Independence.
The ability to alter and change governments has been declared as a Natural Right in the declaration of independence.
Aside from that, "Natural Rights" don't exist. They are a concept created by our founding fathers to attempt to unite the nation. If you disagree with the founding father's definition of "Natural Rights", then the concept is dead and there is no point continuing to talk about the matter.
After all, like everything else that has been created by humans, these concepts are all imagination and fiction. Natural Rights do not exist in the real world, they are merely a concept created by people hundreds of years ago to attempt to unify this country.
Basically, a "Natural Right" is simply the rights that the United States of America were founded upon, the foundation of our Constitution, the foundation of our Revolution, and the foundation of the philosophies that created this country.
These rights are not shared with other countries, these concepts do not exist in other hypothetical governments. "Natural Rights" are simply the rights our founding fathers believed in. Nothing more, nothing less.
You're leaving out entire swaths of the DoI that explain where natural rights come from. But I find it interesting you pick part of the document to argue for what you want, and then try to lecture me about your own philosophy of where the rights come from.
-- Declaration of Independence 1776
I do believe that the Declaration of Independence ALSO leaves its explanation out. It declares the truths to be self-evident, and fails to elaborate upon those facts.
The term 'natural right' is nothing more than a glorified circular argument, embodied within the founding papers of our Government.
So you can either hold those truths to be self-evident and agree upon our founding fathers, or you can disagree. If you disagree, we will be unable to proceed with this debate however...
Just finish off that tid-bit of quote you pulled, and you'll find they specify exactly where they come from — a Creator. Whether or not you believe in a Creator might determine whether you reject natural rights, but for those of us that aren't so quick to reject God, then there's a sound basis for believing in them.
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness."
All philosophies have their pros and cons. Learning to pick which philosophy is an art. Personally speaking, I keep Capitalist AND Communist arguments in my brain. I'm ready to use either philosophy to prove whatever point whenever I want.
For example, if you were a Communist, I'd deride the "free market" by talking about Bourgeois and the working classes. (But that wouldn't work on you, because you'd instantly think that I'd be creating a "class war").
All of these philosophies are theoretical anyway. The real purpose of them is to give us the ability to understand what other people are talking about. Furthermore, it has been proven that ALL pure systems are imperfect.
Free Markets have their market failures (Monopolies). Communists fail to allocate resources effectively.
The solution therefore, is to pick and choose the philosophy that works in the right situation. Be a more educated man, and open to different ways of thought.
I'm really curious where and when this 100% free market system existed that was proven unworkable. Because from my understanding of history, we've only ever had government.
ZERO monopolies have become what they are/were without help from the government.
Perfectly theoretical free markets, with perfectly educated populations with 100% perfectly rational beings will be unable to solve the externality problem. http://en.wikipedia.org/wiki/Externality
It is known and proven. Do not give me a "Well, we'll figure it out later" bull... tell me how a free market is supposed to resolve an externality (which by its very definition is unresolvable by free markets).
Perfectly rational and greedy actors will always offload their costs onto unwilling parties. It is the job of the government to ensure that costs align up with the actors who create those costs.
If that is too theoretical for you, imagine two cities. "City Upstream" and "City Downstream" both are on the same river. City Upstream begins flushing their sewage into the river, and so City Downstream is no longer able to drink the water.
Solve this issue using only rational actors in the free market. The "Government" solution, is to have the Federal Government create Water Treatment plants, and then force "City Upstream" to use them. Afterwards, you tax both cities to pay for the treatment plants.
Your turn. Come up with a free market solution without the use of a central government or centralized 3rd party. Assume both cities are perfectly rational and perfectly selfish, as is common in these economic problems.
Good luck coming up with a solution. But if you're like any other libertarian who I've issued this challenge to, you'll probably run away.
What happens without a government? City Downstream chips in for a bunch of guys to go up there and beat the shit out of the owners of that factory. Let's assume a scenario in which all citizens of City Upstream work for that factory, so they all want to keep their jobs and so they all chip in for a bunch of guys to protect them (or a company hires those guys on their behalf). Now, those guys meet up. Are they going to fight? Highly unlikely, because it is in their personal self interest to resolve this conflict peacefully AND collect the money from the people who hired them. What are they gonna do? They're gonna compare the balance of power. If it's equal then they're gonna settle for the solution that satisfies both equally. If City Downstream, which obviously is concerned with its health more than City Upstream workers are concerned with keeping their job, hires more tough guys, the balance of power would be in its favor and thus you can expect more drastic measures to be agreed upon. Then remember, we talked about an edge case, when all citizens of City Upstream work at a factory. However, that is very unlikely. Thus it may turn out to be that one factory would be up against the whole city.
Of course in reality, no one would actually hire tough guys, but rather such conflicts would be resolved through more civilized private protection agencies and courts. The central question is who outbids whom and to what degree. And the answer is that if the majority of people want something enough to pay for it, it will always outbid the minority, however rich this minority is.
You don't need no government to solve externality problems. All you need is to stop thinking that some magical entity, simply because you can vote for it, is able to resolve issues that are truly complicated.
FYI, a little global perspective. What happens in "the real world" is that your country loses its rivers and millions die to sewage born illnesses.
http://www.spiegel.de/international/world/dead-rivers-and-ra...
Go fantasize about private protection agencies and courts that don't exist and preach it to the 3rd world. Neither exist in India and millions die to this very problem I've been describing.
Perhaps if you stopped believing in pure theoretical fairy tales (wtf? Private Protection Agencies? They don't even exist.) and looked at real world problems, you'd know.
The Ganges river has 2 Million people ritually bathing in it every day due to Hindu tradition. It has over 400 Million living by it as a potential source of drinking water... and it carries some 80% of the Indian untreated sewage.
Tell me, how long will it take for a "Private Protection Agency" and "Court System" to stand up automatically in those Indian villages? People don't even understand the concept of pollution. The reality is, "City Downstream" may not even know that "City Upstream" is the cause of their problems.
India's government isn't powerful enough to create a solution. The current situation, is as "free market" as it gets. Lets see how long before someone comes up with a solution, or for your fairy tail "private courts" to be set up.
Yes, NGRBA was set up in 2009 to fix the problem. The "Free Market" had over 20 years to solve this pollution problem. Guess what? Externalities can't be solved by the free market. At very least, not before the 20+ years it takes to convince a government bureaucracy that there is a problem.
I'm not saying there aren't externalities to free markets, I think there are. I just don't think government is any better at dealing with them than markets. Friedman always says it better:
http://www.law.cornell.edu/uscode/text/33/652
http://en.wikipedia.org/wiki/Mississippi_National_River_and_...
Your solution is really called "internalizing the externality", and a near hundred-year-old analysis can be found in Coase's Theorem. http://en.wikipedia.org/wiki/Coase_theorem
Your solution requires "some entity" to create the concept of ownership, and then sell pieces of the shared resource to other people. You ensure that an owner exists for every part of the river, and then you get an economically optimal solution.
But WHO declares ownership? WHO enforces this ownership? If you believe in "private protection agencies" and "private courts", it is obvious that ownership of "The River" should be settled in the "private courts".
Eventually, you start building an entity functions exactly like the current US Government (except you use Libertarian friendly words to describe it). So please, describe to me a technique that isn't currently being used by the US Government to solve the problem of Externalities. Otherwise, you end up just describing our current Governing philosophy.
I guess if there's no convincing you, then your open-mindedness claim dies with this discussion.
Toodle-oo.
You're calling me close minded, when YOU are the one walking away from this conversation. As I said, you gave a valid solution, but this solution you're talking about requires a Government.
But if you don't feel like discussing it... sure, c ya later. I will say that this is the first time someone has called me "close minded" for calling their solution analogous to one of the most economically stable solutions known.
Now, I have NOT said that I subscribe to a full-on anarcho-capitalist system; I mainly understand the theory behind it, and think that it makes the best theory ON WHICH TO BASE A PRACTICAL SYSTEM OF GOVERNMENT. I do think government is needed for some things. I'm a huge fan of our original form of government in the US, namely federalism — though I'd have some cuts I'd make there too.
And I mainly felt like leaving this conversation because you seemingly try to insist that I don't know what I'm talking about. I do know what I'm talking about. Just because you don't agree with me, or you feel you've thought about this more than me doesn't make it so.
Did you even watch the video of Milton Friedman on market failures? He left it open at the end to say there are times where government might be best, but you cannot immediately and automatically say that government is better — which is exactly what the progressive movement in this country tends to claim.
This subthread started because someone disagreed with the following words: "Furthermore, it has been proven that ALL pure systems are imperfect."
I hold no qualms against Anarcho-capitalism, especially today as deregulation laws are beginning to show promise (New Jersey has some deregulation laws that seem to improve upon utilities like power and gas). It is when a purist comes up, and claims that it is the solution to all problems that I become a bit antsy.
Sometimes, Deregualtion is the key to solving problems. Other times, we need regulation. Pick and choose the philosophy for the situation, there is no silver bullet.
What about my distinction in your definition of government? You seemed so adamant about the fact that a private owner and our current government are the same, effectively. I thought I gave a reasonable response to that claim. You didn't continue that line of debate in your response, though.
http://en.wikipedia.org/wiki/East_India_Company
Companies can become Governments rather quickly. The difference between Companies and Governments is that there is none. The US Government is simply one of the largest companies created on this land.
The US Government has also claimed monopoly privileges on armies and police force. Within the lands that the US Government owns, no other groups of people can organize an army. Basically, Companies and Governments are all the same thing. They are a collection of people, attempting to work together for some abstract purpose.
Besides, the US Government has adopted anarcho-capitalism before. Calvin Coolidge's quote: "Perhaps one of the most important accomplishments of my administration has been minding my own business."
I'd say, Calvin Coolidge probably did more for the Anarcho-capitalist cause than any thought experiment revolving around an Anarcho-capitalist utopia. A heavy pusher of deregulation and a "Hands Off" approach to governing.
Certainly, Calvin Coolidge was less oppresive to the American population than the East India Trading Company was to the Indians.
I have yet to understand where you're going with this. If companies inevitably become so powerful that they become governments, then letting the sitting government regulate them is inconsequential; takeover is inevitable! Let's just all eat worms and die!
No. I think the original thinking during the age of reason makes more sense to me. I think that the people truly hold the power, and as long as we don't give up our inalienable rights to governments (in whatever form they exist), and be sure to always question and hold suspect the people we put into the collective positions of power, then we'll be ok.
Don't forget that the limited liability that we give corporations is a government-granted right. That's one of the major reasons we have issues with large companies.
(I'm not going to get into a debate about Coolidge. I think he was a great President, truly the last of his kind — though even he had his moments of growing government.)
No matter what bugs, attacks, malware or whatever happens, the US Government will pay you back your deposited money, to the fullest extent that it can.
If you don't see why this is useful, maybe you need a sanity check.
That's the key.
But I agree 100% that the idea that a cash account at a random bitcoin exchange is somehow as reliable as an FDIC insured bank is a completely batshit crazy notion.
Literally hundreds of banks have failed in the last several years.
There are multiple exchanges all around the world that compete for the business of customers and innovating in a break-neck speed, none of which would even exist if there was government regulation. Bugs are fixed and problems are addressed faster than the average legislator can spell "malleability".
It would work even better if there was less regulation and investors could fund exchanges in the US without having to buy a bank, so that development could actually happen everywhere and not only in Japan and Slovenia.
Lack of regulation means that others learn from their misfortune.
Straw man alert; no one claims bank regulation is perfect or will stop all bank failures.
Regulation can work, however it should not absolve users of responsibility for vetting their investments or financial service providers.
The time between a bad actor starting to fleece people and the market or regulation wiping them out can still be fairly lucrative for the bad actor and fairly damaging for the public.
Just goes to show, there's no use looking at a website (when that site is effectively a black-box) and judging its competency from a general vibe.
Also, it appears that the Bitcoin network is under global attack by some large entity, so blame for the current exchange issues lie ultimately at the hands of some attacker who doesn't like Bitcoin, or wishes to plunge the price.
On the other hand Bitstamp identified a problem within 24 hours of it starting to happen says they know how to fix it and will have everything back to normal shortly.
Personally I'd rather have my money with the latter.
Any reading material on the subject (for a newbie) would be greatly appreciated.
http://en.wikipedia.org/wiki/Bank_run
EDIT: See this for a more thorough description of what I mean: http://www.dailytech.com/Mt+Gox+Bitcoin+Bank+Run+Intensifies...
A bank run is where the bank does not hold enough money to cover everyones deposits. Bitstamp have enough BTC to cover everyones deposits they just are delaying withdrawals for 72 hours. Think of it like you rbank telling you you need to wait 3 days for a transaction to go through, not that unlikely and in fact quite common in traditional banking. It seems longer in bitcoin though because of the usually quick transactions.
Moreover, with banks you have this every weekend.
Also iDeal, a very popular online dutch payment system that integrates with almost all banks, has only like 95% uptime.
Some reading:
http://qz.com/175565/why-nobody-can-withdraw-bitcoins-from-o...
>In the meantime, users of the reference implementation do not need to be concerned. Transactions are always tracked properly by the Bitcoin-Qt/bitcoind software.
http://www.reddit.com/r/Bitcoin/comments/1xm49o/due_to_activ...
Edit: The concern with the Bitstamp appears to be confusion due to transaction malleability and NOT actual double spend or cancellation issues. However the BTC reference client is not perfect at handling malleability and only gets it right eventually.
I imagine that the more recent versions of the satoshi client don't have this bug, it may have a few years ago when bitstamp and mtgox may have been looking to draw inspiration from it.
"Not that Bitcoin-QT handles Malleability fantastically— but because it tracks inputs it will still detect the mutant transactions."
http://sourceforge.net/mailarchive/message.php?msg_id=319565...
A user on an exchange requests to withdraw btc. MtGox creates a transaction with a tx hash of abc1234cdf... and sends it to the blockchain, polling for the status of tx hash "abc1234cdf...".
Due to tx malleability, the tx hash can change by changing some of the tx data (in insignificant ways), which doesn't invalidate the tx signatures.
A malicious user could wait for MtGox to create a tx, flip a bit and resubmit the tx and try to get it confirmed under a different hash, invalidating Gox's tx as a double spend.
Which leaves Gox polling for the status of tx hash "abc1234cdf...", which will never confirm.
A user then submits a support request and says their tx is "Stuck". MtGox then creates a new tx, Which doesn't respend the same coins, and thus, the user is paid 2x.
This is why many sites are having issues. It is in fact a problem with the reference client.
As I understand it, this is not correct, the new tx must be functionally identical to the old one (same inputs and outputs), just with a different txid.
Someone correct me if I'm wrong
Both exchanges use the JSON/RPC interface to the Satoshi bitcoin client. That is the One True Way to use Bitcoin to develop Bitcoin-consuming applications. To do otherwise is madness. (I've seen explanations that Mt. Gox was using a custom client, but I believe they mean "Mt. Gox was using a custom system which took care of bookkeeping for itself, because the Satoshi client cannot operate thousand of wallets in any sane fashion, but used the Satoshi client for interacting with the Bitcoin network.")
The Bitcoin RPC interface exposes many methods. I don't have intimate knowledge of which one these exchanges were using, but since they all have similar issues, let's assume they used sendtoaddress.
The message signature of sendtoaddress is (pseudo-code):
#returns transaction_id
sendtoaddress(from_account, to_bitcoin_address, amount, optional_message)
The mistake which both exchanges made is they assumed transaction_id is the same transaction_id used for gettransaction(transaction_id). It is. If you send a transaction, wait an hour, and then get it by ID, that will work.But it isn't. Transaction ID means absolutely nothing. It can be changed by any party, worldwide, for up to one hour after the invocation of sendtoaddress. If you use gettransaction(transaction_id) and it returns nil, that does not prove that the transaction you previously created did not succeed correctly. You should not attempt to retry the transaction until first verifying that you have all the coins you started with and that the recipient does not have some of your coins. You can conveniently do this with an O(n) scan over all Bitcoin transactions ever. (Someone pointed out to me on twitter that it isn't O(n) if you have your database indices set properly. Well, yeah, true.)
You'll need to know what addresses you actually sent from, which is obscured by the sentoaddress API described above, for that scan to succeed, so essentially you're going to reimpliment much of the Satoshi Bitcoin client, particularly around the area of wallet management. Don't reimpliment everything, though -- down that path lies madness. Also, try not to make any bugs anywhere, particularly not the kind which only show up when someone tries to steal from you.
Good luck!
http://www.coindesk.com/massive-concerted-attack-launched-bi...
What they should have done was waited an hour then done an O(n) scan of all transactions globally in history to find the transaction by inspecting for parameters which exactly matched the ones they provided. That is, the Bitcoin developers now say, the correct use of the create transaction API.
Let me use an example programmers may be familiar with. Twilio lets you do SMS messages with three parameters: from_number, to_number, message. You are given back an SMS ID, which you can query to see the results of the SMS message (like, say, was it delivered successfully or did it fail with an error like "that telephone number did not exist").
Here's a discussion with Twilio in the bizarro world where it's like Bitcoin.
Me: "Hey Twilio I created an SMS message but when I try to query it for the results it 404s."
Them: "Are you sure you created the message?"
Me: "Yep pretty sure."
Them: "Are you sure you are looking for the right message ID in /messages/:id?"
Me: "Yep, I'm using the one that I got back when I created it."
Them: "Maybe it changed."
Me: "... What?"
Them: "Message IDs can change."
Me: "They don't usually change."
Them: "Of course, they don't usually change. Why have an ID if they usually changed? They only change some of the time."
Me: "What determines if a message ID changes?"
Them: "Oh, anyone globally can change your message IDs."
Me: "That sounds a bit insecure for a system which is, by its nature, deployed in a hostile environment."
Them: "Don't worry, they can't change after about an hour. Well, probably. It would be pretty expensive for an attacker to change them after an hour. Don't worry though, you'll never need an ID."
Me: "I find IDs useful for querying things. Like, say, messages. Which I have to do. To see whether the message was successful or not."
Them: "Well you're already downloading every message ever. Just scan through for one which matches the same from number, to number, and message contents."
Me: "... You're serious."
Them: "Don't worry though: they can't touch the from number, to number, or the message contents."
Me: "... Does this sound a little problematic to anyone else?"
Them: "It's on our wiki, noob!"
[Edit: Maybe somebody thinks I'm joking. Let me point you to one of the dangerous functions.
https://en.bitcoin.it/wiki/Original_Bitcoin_client/API_calls...
Name: sendtoaddress
Parameters: <bitcoinaddress> <amount> [comment] [comment-to]
Comments: <amount> is a real and is rounded to 8 decimal places. Returns the transaction ID <txid> if successful.
You should naturally, upon reading this documentation, figure "I should immediately discard that transaction ID, because it could be changed instantaneously after this message call. If I instead rely on that transaction ID, I will allow malicious users to break the software I am building."]
It wasn't twilio, but it turned out that when we submitted a SMS message of over 160 characters, the provider split it into 160 chunks and sent out as multiple SMS.
So far, so normal. But what happened when the first chunk sent successfully and the second chunk failed?
We got back a notification to say "MessageID: 4ACB-etc Result: OK" but the customer never got the message, and scanning the report on the provider's site showed the customer number, time and message as having failed.
But then the representative agreed it was a problem and set out to fix it rather than blaming our dependence on the ID!
There seem to be two prevailing extremes of opinion which appear a lot on Hacker News and many other places, as extremes are wont to do while those in the middle don't feel strongly enough to contribute. Those are 1) BitCoin will replace government control of money and fix freedom, dude! and 2) What fucking morons, can't wait until you crash and burn.
I love this whole thing. It's fascinating, it's an interesting solution to a problem, and watching DogeCoin take off is fun to watch. In my opinion, BitCoin is kind of like when a naïve programmer decides to rewrite an existing library themselves, and comes up against the brutal reality that led the original developers to the compromises and apparently necessary hacks to get the thing working. The analogy here being regulation, insurance, all that jazz. It's educational, and I haven't been this interested in a technology for a while.
I'm picking on your reply here because it is one of many that exemplifies a "haha told you so" rather than really digging into the interesting technical and sociological aspects.
* Message IDs from one API do not equate to IDs from the other, so your example is a bit flawed; there's no way to check with Twilio except the ID.
* Is "ID" even the term used? I don't know for sure, but "Tx Hash" seems to be more widely spread. [Edit: patio11 edited his comment while I was typing mine; I withdraw this point!]
* "It's on our wiki noob" - someone running the 3rd largest exchange should hardly be a "noob"
* "O(n) scan of all transactions globally" - that's not particularly hard, nor is it necessary (why scan all transactions from all time?), nor is it unexpected (the entire thing requires everyone to have the complete ledger, so you have the data anyway)
There are valid points to be made that the BitCoin protocol needs improvements, and these are even acknowledged by the core devs. This whole situation is a bit ludicrous. But I wish we were talking about "what have we learned", not "told you so".
When it comes to BitCoin, the conversation seems to be full of radicals and optimists when success happens, and gloaters when it doesn't. I don't feel either add to the conversation, we could be talking about how to improve this as a currency or (as I believe the long term actual application to be) how this can influence distributed trust, especially important in the current climate.
People often deploy the word FUD to describe arguments about technology which have no basis in technical fact. Can you identify statements which I've made about Bitcoin which have no basis in technical fact?
As for the second, FUD was then incorrect. You points were factual. I believe they ignored certain other facts for the convenience of argument (like, most exchanges seemed to know about it). But FUD was the incorrect term.
I'm a bit sad to see my main argument derailed by semantic failures. I guess I need to learn a lot about debating on the internet.
sendtoaddress didn't always return a transaction id. It was changed to do that to facilitate bookkeeping. Sort of ironic.
I find it quite ridiculous that people are trying to lay the blame on not reading an obscure wiki page. I remember reading much of the bitcoin wiki myself and never seeing ANYTHING about not relying on transaction IDs. The API list doesn't even warn you about it.
Why bother returning a transaction ID if it is spoofable? That is simply misleading.
I guess it shows you how how biased all the bitcoin backers are.
> Don't worry, they can't change after about an hour. Well, probably. It would be pretty expensive for an attacker to change them after an hour.
You use the term "pretty expensive" here without qualifying it. Changing a transaction encoded in the blockchain would require outpacing the current hashrate of the bitcoin network. That would require a significant hardware investment, on the order of tens of millions of dollars.
> Well you're already downloading every message ever. Just scan through for one which matches the same from number, to number, and message contents.
You make it sound as if you wouldn't have to do this if you had the transaction hash. You still need to iterate through the transactions regardless. It's just a question of whether you use the transaction hash, or derive your own from the parts of the transaction that are immutable.
Let's make your example a touch more realistic:
Me: "Hey Twilio I created an SMS message but when I try to query it for the results it 404s."
Them: "Has the message been delivered?"
Me: "I don't think so. I'm querying it shortly after I create it."
Them: "How are you querying it?"
Me: "With the message hash."
Them: "Ah, that explains it, then. A pending message may be changed before its delivered, altering the hash. This makes the hash unsuitable for identifying pending messages."
Me: "So how do I identify messages?"
Them: "Ideally you wait until they're delivered, but if you really need to check for pending messages, you can search through them looking for a message that matches on to, from and content."
Me: "That kinda sucks."
Them: "We know, but it's a difficult issue to fix. It's documented in our wiki."
Me: "What if I don't read your wiki, or follow your mailing list?"
Them: "Then should you really be running an exchange handling millions of dollars of transactions?"
Me: "... Good point."
You'd think they'd have at least one guy dedicated to nothing but breaking their software. They make my salary every day with transaction fees (well, maybe until recently) so you can't say they're unable to afford it.
Edit: Rereading this, it sounds more accusatory than I intended. I think your clarification was perfect, but at the same time that MtGox is at fault.
However, the hash over the malleable part is still protocol-significant: which exact incarnation of the isomorphic transaction is being passed around or cemented into blocks. So this new stable ID would be in addition to the older one, and might not even be necessarily expressed inside the protocol: it might just be a convention, and could vary across independent implementations.
The MTGox statement was a plea for the community to converge on such an consensus identifier before MtGox commits to a local fix. But that's not strictly technically necessary, so their stance looks like a strategy for blame-shifting and further delay. The Bitcoin core people don't like to rush into things.
So what happens to people who aren't running an exchange handling millions of dollars of transactions? It doesn't matter if they get screwed by this flaw?
I read much of the wiki and never encountered any reference to transactional malleability.
Lol.
The point of bitcoin is being able to do it yourself and not rely on centralized institutions.
The bitcoin reference client seems to get confused by this. It seems to allow additional spending of the unconfirmed change addresses and forms a chain of double spent transactions. The bitcoin balance as reported by 'getbalance' also becomes unreliable as it computes the balance incorrectly. Eventually the wallet stops working.
You don't have to scan all transactions: only those from a firm reference-point of available-funds state, essentially the same point that was used to compose the outbound transaction.
Robust software already has to examine all incoming confirmed-in-block transactions for whether those transactions have consumed prior funds. If they have, even if the local software had as its design goal exclusive control of those funds, the local software must adapt to the new information. (Given the possibility of backups/virtualization-clones/private-key-exports, software must always be open to the possibility another node elsewhere has spent pending funds first.)
So safety against this particular mischief is possible with the same practice that's necessary for other reasons: it's not involved extra work.
Also, it's not "an hour" that lets a node know when it can rely on transaction-state, but block-confirmations, a precise and observable transition. One block is almost always enough, but each additional block adds more certainty. Still, all Bitcoin software already needs to handle occasional orphaned blocks and short forks, so being sensitive to periods of uncertainty is a essential part of all implementations, not extra work because of this one gotcha.
A better analogy than Twilio would be commercial payment systems: there you need to systems that are checking for weeks or months for chargebacks or reversals.
But an even better analogy than proprietary pay-per-use payment systems is SMTP or BitTorrent. The system is an emergent mess anyone can plug into. There are a lot of sharp edges, and even with great care, you're going to hit some painful and costly bugs. Those building billion-dollar businesses on such systems need to be experts, and will still take some arrows, but each incident that doesn't kill the software/business stacks only leaves them stronger.
Oh, you mean the scanning they have to do already, to verify "all transactions globally in history"? Inspecting all parameters on all transactions since the genesis, like you'd already have to do to verify they are not stealing or creating money from nothing? The inspection you have to do just to locate even the same transaction you submitted to the network yourself, to verify it was accepted? And you have to spend like 10 whole seconds of CPU time doing this, per ~10 minutes that a new block comes out, verifying the transactions from the last 10 minutes? Golly, that is sooooo much more onerous than just running the blockchain securely! /sarcasm
I'll agree that it's embarrassing, misleading, not documented well, and not gracefully handled by the community now that everyone points their fingers at each other. But you are deliberately making it sound worse by re-describing standard parts of the bitcoin protocol, as if they are new requirements in order to get a sane ID. Anyone writing financial software should be more than capable of quickly adding a few function hooks into the existing process to get a deterministic normalized ID, and the amount of extra computing resources is negligible compared to what you already have to do, just to use bitcoin safely.
I would be more inclined to believe that the majority of sites use the reference client and this is why issues are appearing.
It shouldn't surprise anyone that after months (years!) of BTC services absconding with millions of dollars worth of users money and now the exchanges starting to collapse in a similar fashion (users can't get money out) that the wider user base of bitcoin would begin to default toward not trusting services that purport to store coins 'securely'.
This is bad in the short term as the remaining exchanges prices show, but likely a positive progression in the safe use of crypto currencies going forward--
As a developer I think the correct mindset towards security is important to have day in and day out; Perhaps that's the real social engineering of the NSA leaks. Nothing could be better for the distributed security of our country than each and every individual developer being more acutely aware of security concerns at every keystroke.
Gambling exchanges have worked well for years, I wonder if the first serious competitor in the btc exchange space will be from one of those exchanges. (Unlike established financial exchanges they might be willing to risk a reputation hit for getting established in the space.)
Without many real places to deal with USD <-> BTC, then of course it will be hard to deal with the cryptocurrency (the passage is needed to allow for a transition period in currencies).
If you understood cryptocurrency you would understamd that their success is not measured in the price point. That is the most marketable aspect so that is what you know, the utility and use of the protocol is as good if not a better measure of their success. the relative speed with which issues are identified and resolved speaks to the success of the protocol not the daily/weekly highs and lows.
If you are payed in the currency that you spend...
We need exchanges that are also P2P like Bitcoin.
This is not going to kill any exchange (except perhaps mtgox, but that is due to an accumulation of poor performance rather than this minor issue).
What you want is an independent audit, not regulation.
Maybe even some regulation requiring such a thing?
Competition isn't a magic bullet. It amplifies perverse incentives just as easily as it amplifies legitimate incentives.
So it's important to remember - insurance and audit are great things. But combine them with government policing and force and you have a regulation, which only leads to restricting the choices consumers have.
Obviously it depends on the regulations, but a lot of regulations are about making sure that there's at least a minimum bound in the "quality" of products offered, because of the asymmetry at play here. If there is none, we can end up with "bad" products(that don't seem bad because we're uninformed) crowding out "good" ones, and having the entire market be worse off.
The 2007 crisis was a perfect example of asymmetry causing markets to crash: obviously there's the whole aspect of consumers being mislead on their mortgages, but there's the even greater aspects of banks misleading each other! Because of the opacity of the market of derivatives (nobody knew just how invested everyone was in on certain obligations) no bank could make informed decisions on what to do with their positions.
If we don't restrict some choices in the short term, then we can end up with no choices in the long term. In areas of extremely high uncertainty, regulation (notably concerning transparency) is necessary to make the market freer (in the actual definition, not from the common usage of free=no regulation).
Is it a chant or something? We can end up with no choices. Or maybe we will end up with more choices. Can you prove it logically without manipulating data and suggesting it to be evidence? Because the 2007 crash you mentioned can be explained from a different point of view, completely different from yours.
I can also say "everyone being able to own guns actually increases overall safety and if you don't allow people to own guns, we may end up with less safety". Do you realize this sounds exactly like your argument?
I'm not saying that every instance of markets should be regulated, I'm saying that some markets in their unregulated form are not free, and can end up imploding on itself. You might argue that a market in that form isn't worth saving, but if a small bit of regulation can push the market in the right direction you can end up with a healthy market.
You're going to have to explain your last statement, because I don't get it.
Every economic argument will reach the point of some guy saying "A" and another guy saying "not A" anyways though, so might as well just stop here.
True. And the "solution" of government financial regulation is to allow the people with more information to create compulsory regulations that benefit themselves.
https://en.wikipedia.org/wiki/Federal_Deposit_Insurance_Corp...
Auditors generally have no incentive to rock the boat, and might have a disincentive in the form of losing future business. And even if they're really thorough, most auditors are only in for a few days or weeks and don't have time to go through things anything like as thoroughly as people who work on them full time. And even if they're really thorough and have the time to go through everything with a fine-toothed comb, insider threats can be undetectable, like if the guy preparing the cold storage wallet to put in the safety deposit box makes himself a copy.
The only audit of an exchange worth a damn is the audit undertaken by reputable insurers who will guarantee my entire deposit.
http://www.reddit.com/r/CoinedUp/comments/1xkft8/why_are_bit...
Not even, since Coinbase is a webwallet not an exchange... People generally keep them there because its an easy way to manage/spend them (esp on a phone)
> I am lucky that about two months ago I moved over to Coinbase from both Mt Gox and BitStamp. I wonder now if Coinbase is going to start having issues.
You mean something like this? http://www.reddit.com/r/Bitcoin/comments/1wtbiu/how_i_stole_...'Someone' didn't ensure their trading engine did atomic writes to a database (by the way, that database doesn't do write isolation on multiple documents by default.. guess which database is that? Hint: it starts with the letter 'M'), which resulted in a potential race condition that could be exploited.
Coinbase uses that database, and apparently did not know that you need to ensure atomic write operations.
edit nwh links to Coinbase CEO's comment that it was not them. Ok, good to know. However, I still can't see how anyone would use said database in critical/production infrastructure, sorry. Maybe in a few+ years time it will be mature enough.
So... they didn't handle transaction processing correctly either. Are there any exchanges that are handling this properly?
I very much doubt it ;)