Introducing Stellar: a decentralized protocol for sending and receiving money
stellar.org
stellar.org
Ha ha ha. No.
The rest of it looks interesting, however.
Edit: This was the text below the token:
Keep this code SAFE. Anyone with this code and your username can gain access to your account. If you lose both your password and your recovery code, you will lose access to your funds so be safe!
I do have a few concerns, though. Some of them require a bit more digestion so I won't comment on those here, but one that I'm sure about: WTF is the reference client written in browser JS?? It doesn't make any sense, for all the same reasons as the last time someone dragged out that dead horse.
I understand that peer-to-peer is also a possible use case, but realistically the people who don't know how to mine aren't going to care about transferring cryptocurrencies... that's why the gateways are valuable in the first place.
I think we all would have preferred a route that didn't require creating a new currency, but this was the best approach they could find to moving forward on their vision. Certainly the long-term hope is that the stellar will mostly help provide liquidity between other currencies, rather than become something used primarily as a first-class currency itself.
The distribution strategy here is actually something that, as far as I know, has never been tried before. It's correspondingly very difficult to know exactly how it'll turn out. The underlying motivation is to distribute the stellar as fairly and as rapidly as possible, and this model (given lots of transparency and upfrontness) was the best they could think of. (If you come up with a better one, I'd certainly love to hear it — I'm gdb@stripe.com if you'd like to talk more.)
As soon as you're in-browser, you have a choice: do it server-side, which means you have access to people's funds (at least while they're logged in), or do it via client-side JS, in which case you don't. The choice there for Stellar ended up being pretty straightforward, though the simple implementation leads to some UX surprises such as: https://www.stellar.org/faq/#_Why_do_I_need_to_authenticate_....
Of course you do, it just takes a teeny bit more work--you swap the contents of crypto.js with the contents of malicious-crypto.js. The threat model is exactly the same (users either trust the server or they don't) but the browser crypto option adds a layer of (respectfully, because I know you're a very intelligent person who means well) bullshit.
I think the question of where your password by design will go is very important. If it's transiting the server, suddenly there's a lot more surface area to worry about. Logfiles, databases, and the like suddenly can be called into scope, and an attacker might be able to steal credentials even without being able to substitute out code.
In any case, the great thing about an open ecosystem is that, if you don't like the choices someone else has made, you are more than welcome to make your own implementation with choices you prefer!
* Google accounts
* Github accounts
* Twitter accounts
* bitcoin-otc accounts (probably with a minimum reputation)
* GPG keys with some minimum threshold of age and "signedness"
* S/MIME certificates from issuers that verify government ID.
I'm guessing the difficulty with supporting multiple methods is a desire to limit this to 5k/person. I'm not sure there's a good solution to this, though I will say that you may have just added some additional incentive to steal Facebook credentials.
Cool idea. The idea of a distributed exchange is interesting.
I've had my facebook account for something like 8 years. Oh well.
On another notice, this is one of the situations where it makes a lot of sense to register a simple username just in case, so I don't regret it later where the only available are longer ones :)
Decentralized as in bitcoin, where proofs of work confirm transactions? That is not news, since 6 years ago.
Decentralized as in any other electronic transfer system, where you trust a few nodes to confirm the transaction? "Each node in the network communicates with a set of other nodes that it believes will not collude (such as nodes run by universities, governments, and companies)" That is not news, it's from decades ago. (Some people even tried to put a patent on it, like 15 years ago: http://www.google.com/patents/US6173272)