The only real difference is that academic systems call for an authority or group of authorities that issue the currency.
That's quite a difference, and one of the main features of Bitcoin. See the message in the genesis block.
It is hard to even say that Bitcoin has no central authority at this point; the developers of popular Bitcoin software have tremendous power over Bitcoin (e.g. they can trigger block chain forks).
"That's quite a difference, and one of the main features of Bitcoin. See the message in the genesis block."
That is a political statement not a technical statement, and this gets to the heart of the problem with Bitcoin and with its lack of a security definition. Bitcoin is popular, particularly among those who distrust the banking system, because there is no requirement for a central authority; that is certainly true but only in a pedantic sense. Without a security definition it is hard to even talk about what Bitcoin requires.
What we have therefore is a situation where no amount of technical criticism can matter with Bitcoin. Polynomial time attacks are irrelevant, because there is no requirement that Bitcoin resist polynomial time attacks. There is similarly no particular scalability requirement, and so there can be no real criticism of Bitcoin's scalability. "True believers" in Bitcoin can easily shoot down criticism because critics cannot actually point to any requirement that Bitcoin fails to fulfill: there are no clear requirements to point to.
To illustrate this point, consider this statement: There is a polynomial time attack on Bitcoin, and the whitepaper itself describes it. Now, is this a problem? Well, the answer I consistently get from Bitcoin devotees is no, that is not a problem because that is how Bitcoin works. With logic like that, who can argue?
So while you call the lack of an authority a feature, I call it a logical gap until a rigorous security definition is presented. Otherwise you have a solution in search of a problem, coupled with a community of people who all have their own vague notions of what they want Bitcoin to do for them.
That is a political statement not a technical statement
Just because it doesn't have the particular kind of specification that you are looking for, it doesn't mean that it's not technical. Being distributed is very much a technical feature, no matter how you look at it.
I much rather have a working solution that might or might not be broken in the future (if it was too damn insecure, someone would have broken it already), than be stuck forever with the old banking system just because we don't know how to create the mathematical/cryptological model that you are used to and would grant 100% theoretical security. That would be like not building a website or shutting down a project mid development just because some component is found to be difficult to unit-test.
"I much rather have a working solution that might or might not be broken in the future"
What does it mean for Bitcoin to be "broken?" That is my entire point here: if we do not have a clearly stated definition of what security means, then we cannot even talk about whether or not a system is broken. To put it another way, I would call any cryptosystem that can be attacked in polynomial time "broken," yet in the case of Bitcoin there is the 51% attack which apparently does not bother you -- and like I said, despite the fact that I call it broken, I cannot actually point to anything that would have required Bitcoin to be secure against such an attack.
To put things in scientific terms, we are talking about falsifiable hypotheses. As an example, here is a commonly assumed hypothesis: the block cipher AES is a pseudorandom permutation. This is a claim that could be disproved i.e. we can falsify the claim by presenting an algorithm that efficiently distinguishes AES input/output pairs (with a secret key that the algorithm does not receive as input) from the input/output pairs of a random permutation. Consequently we can speak about the security of AES in a meaningful way, even though have no theoretical proof that it meets its security definition (only heuristic evidence and a lack of known attacks).
My point about Bitcoin is that we do not have such a hypothesis, so we cannot even be sure that we mean the same thing when we say, "Bitcoin is secure" or "Bitcoin is broken." That is the point of having a security definition. Without such definitions, you can always make the claim that Bitcoin is secure, not matter what sort of attacks are carried out, because you can always just say that Bitcoin is not supposed to defend against those attacks.
It's pretty intuitive and I'm sure you know it: People being able to break the rules. Eg: create coins out of nowhere, move coins that weren't theirs, slow down transactions, unstabilize the market, etc.
To say that it's not falsifiable is a bit of a stretch. It is falsifiable, we just don't know how to create the model you are looking for. Maybe it can't be done [with crypto]. Maybe it wasn't a competence of Cryptography to begin with, and we need an entirely new field (I know cryptographers have tried in the past, but to me this seems different). Don't you agree that Bitcoin involves too many disciplines to try to simplify it into a cryptographic formula? Something that breaks Bitcoin could even simply come from Economics, and your crypto model (if you ever find one) would be useless.
Or, there is a cryptographic model, has been proven secure, and we just don't know it because its creator[s] wanted it to stay secret.
Let's try with an analogy (you can attack it or say why it's bad). Your ship is sinking for some reason, there are no emergency boats, but you find out something that might be used to stay afloat. You hesitate, because you don't have physical proof of it like you did with the ship (an expert created the drawings, calculated the forces involved, etc.). But then you see a lot of people using it and it's working fine. The more time it passes, the more certain you are that it works. That's empirical evidence, and it drives a big part of scientific advancements.
So maybe once each field is validated individually as thoroughly as possible (crypto components are being used correctly, the correct distributed computing techniques are used for scaling to the moon, the economic variables are chosen correctly -Satoshi wanted Bitcoin to mimic gold-, the right incentives are given to miners and hindrances to attackers -Game Theory-), only empirical evidence can be used to finish the test.
If by breaking Bitcoin you can silently steal millions and safely cash out (one hell of an incentive in my book), yet no one does it, I say it's secure enough. Not in a cryptographic or <individual traditional field> way, but in a pragmatic way. It just works.
"It's pretty intuitive and I'm sure you know it: People being able to break the rules. Eg: create coins out of nowhere..."
Ah, but therein lies the problem. If there is no authority that issues the money, then any party must be able to create money from nothing (or there would be no money in the system), and must be able to do so efficiently. This is where the first vague notion of security in Bitcoin arises: the idea that you can generate the money efficiently, but not "too efficiently." Unfortunately there is no well-understood security model that allows for efficient-but-not-too-efficient attacks.
"Don't you agree that Bitcoin involves too many disciplines to try to simplify it into a cryptographic formula?"
Two disciplines, as far as I can tell: economics and cryptography. One discipline motivates the other here. Theoretical understandings of money and money creation come from economics; whatever that understanding is, the security definition needs to capture it. The involvement of another discipline does more to motivate the demand for a security definition than to make it irrelevant.
Suppose you could identify or develop an economic theory for money that has no intrinsic value and no central authority. You would still have to have some security definition that captures that theory to make a convincing case (or at least a meaningful statement) that the money in Bitcoin meets the requirements of that theory. If you cannot identify an economic theory that supports a system like Bitcoin, you are no better off than if you cannot state a rigorous security definition.
"Something that breaks Bitcoin could even simply come from Economics, and your crypto model (if you ever find one) would be useless."
Whatever hypothetical security definition you had would not be useless in that case. Rather, it would be that systems that satisfy that definition do not make economic sense, and hence that entire category of systems has no practical use. I would say that in that case, Bitcoin would be solving the wrong problem, rather than that Bitcoin was "broken" (which I take to mean that it does not solve the problem it is supposed to solve).
"Let's try with an analogy (you can attack it or say why it's bad). Your ship is sinking for some reason, there are no emergency boats, but you find out something that might be used to stay afloat."
Are you suggesting that Bitcoin is a system that people desperately cling to when they believe that well-designed systems are failing? I think this might be the wrong analogy, at least if you are trying to defend Bitcoin.
A better analogy might be this: you are standing on a ship. You do not like the captain and his decisions, so you grab some hunks of wood, styrofoam, tires, and a barrel full of fuel oil, lash it together with some rope, and set sail.
Which would you rather be standing on -- a well-engineered ship that might sink if the captain makes bad choices or if the crew fails to maintain it properly, or something that some guy assembled from stuff he found that seemed relevant to ship-building and which seems to float, seems to have no captain to make bad decisions (but might be split in half if the crew cannot agree on a heading), and which has not yet sunk under the weight of its passengers?
"If by breaking Bitcoin you can silently steal millions and safely cash out (one hell of an incentive in my book), yet no one does it, I say it's secure enough. Not in a cryptographic or <individual traditional field> way, but in a pragmatic way. It just works."
What if the attacker does not want to steal money, but just wants to disrupt the system? Imagine a hypothetical "Satoshiland" where Bitcoin is a major economic force; now imagine that another, more powerful country is about to go to war with Satoshiland, and that their goal is to destroy everything. If the invader can block transactions, create transactions then reverse them, and kill the mining bonus, they can cause vast economic harm -- without firing a single gunshot.
Or (slightly) more realistically, what if the US government wanted to block payments to Wikileaks. What if that is worth more than whatever it costs to do so (ie a "51% attack"), and more than whatever hypothetical mining payoff could be had by just devoting the hardware to mining?
I would not assume that the adversary's goal is your personal goal.
LOL, great counter analogy. Well, let's hope you are wrong. Either way, it will be something interesting to watch. If Bitcoin dies overnight, we are going to see a lot of people jumping off the buildings. And if it succeeds, you know, we will become a type I civilization and all that...
Comments
That's quite a difference, and one of the main features of Bitcoin. See the message in the genesis block.
I agree with you on that.
"That's quite a difference, and one of the main features of Bitcoin. See the message in the genesis block."
That is a political statement not a technical statement, and this gets to the heart of the problem with Bitcoin and with its lack of a security definition. Bitcoin is popular, particularly among those who distrust the banking system, because there is no requirement for a central authority; that is certainly true but only in a pedantic sense. Without a security definition it is hard to even talk about what Bitcoin requires.
What we have therefore is a situation where no amount of technical criticism can matter with Bitcoin. Polynomial time attacks are irrelevant, because there is no requirement that Bitcoin resist polynomial time attacks. There is similarly no particular scalability requirement, and so there can be no real criticism of Bitcoin's scalability. "True believers" in Bitcoin can easily shoot down criticism because critics cannot actually point to any requirement that Bitcoin fails to fulfill: there are no clear requirements to point to.
To illustrate this point, consider this statement: There is a polynomial time attack on Bitcoin, and the whitepaper itself describes it. Now, is this a problem? Well, the answer I consistently get from Bitcoin devotees is no, that is not a problem because that is how Bitcoin works. With logic like that, who can argue?
So while you call the lack of an authority a feature, I call it a logical gap until a rigorous security definition is presented. Otherwise you have a solution in search of a problem, coupled with a community of people who all have their own vague notions of what they want Bitcoin to do for them.
Just because it doesn't have the particular kind of specification that you are looking for, it doesn't mean that it's not technical. Being distributed is very much a technical feature, no matter how you look at it.
I much rather have a working solution that might or might not be broken in the future (if it was too damn insecure, someone would have broken it already), than be stuck forever with the old banking system just because we don't know how to create the mathematical/cryptological model that you are used to and would grant 100% theoretical security. That would be like not building a website or shutting down a project mid development just because some component is found to be difficult to unit-test.
"I much rather have a working solution that might or might not be broken in the future"
What does it mean for Bitcoin to be "broken?" That is my entire point here: if we do not have a clearly stated definition of what security means, then we cannot even talk about whether or not a system is broken. To put it another way, I would call any cryptosystem that can be attacked in polynomial time "broken," yet in the case of Bitcoin there is the 51% attack which apparently does not bother you -- and like I said, despite the fact that I call it broken, I cannot actually point to anything that would have required Bitcoin to be secure against such an attack.
To put things in scientific terms, we are talking about falsifiable hypotheses. As an example, here is a commonly assumed hypothesis: the block cipher AES is a pseudorandom permutation. This is a claim that could be disproved i.e. we can falsify the claim by presenting an algorithm that efficiently distinguishes AES input/output pairs (with a secret key that the algorithm does not receive as input) from the input/output pairs of a random permutation. Consequently we can speak about the security of AES in a meaningful way, even though have no theoretical proof that it meets its security definition (only heuristic evidence and a lack of known attacks).
My point about Bitcoin is that we do not have such a hypothesis, so we cannot even be sure that we mean the same thing when we say, "Bitcoin is secure" or "Bitcoin is broken." That is the point of having a security definition. Without such definitions, you can always make the claim that Bitcoin is secure, not matter what sort of attacks are carried out, because you can always just say that Bitcoin is not supposed to defend against those attacks.
It's pretty intuitive and I'm sure you know it: People being able to break the rules. Eg: create coins out of nowhere, move coins that weren't theirs, slow down transactions, unstabilize the market, etc.
To say that it's not falsifiable is a bit of a stretch. It is falsifiable, we just don't know how to create the model you are looking for. Maybe it can't be done [with crypto]. Maybe it wasn't a competence of Cryptography to begin with, and we need an entirely new field (I know cryptographers have tried in the past, but to me this seems different). Don't you agree that Bitcoin involves too many disciplines to try to simplify it into a cryptographic formula? Something that breaks Bitcoin could even simply come from Economics, and your crypto model (if you ever find one) would be useless.
Or, there is a cryptographic model, has been proven secure, and we just don't know it because its creator[s] wanted it to stay secret.
Let's try with an analogy (you can attack it or say why it's bad). Your ship is sinking for some reason, there are no emergency boats, but you find out something that might be used to stay afloat. You hesitate, because you don't have physical proof of it like you did with the ship (an expert created the drawings, calculated the forces involved, etc.). But then you see a lot of people using it and it's working fine. The more time it passes, the more certain you are that it works. That's empirical evidence, and it drives a big part of scientific advancements.
So maybe once each field is validated individually as thoroughly as possible (crypto components are being used correctly, the correct distributed computing techniques are used for scaling to the moon, the economic variables are chosen correctly -Satoshi wanted Bitcoin to mimic gold-, the right incentives are given to miners and hindrances to attackers -Game Theory-), only empirical evidence can be used to finish the test.
If by breaking Bitcoin you can silently steal millions and safely cash out (one hell of an incentive in my book), yet no one does it, I say it's secure enough. Not in a cryptographic or <individual traditional field> way, but in a pragmatic way. It just works.
"It's pretty intuitive and I'm sure you know it: People being able to break the rules. Eg: create coins out of nowhere..."
Ah, but therein lies the problem. If there is no authority that issues the money, then any party must be able to create money from nothing (or there would be no money in the system), and must be able to do so efficiently. This is where the first vague notion of security in Bitcoin arises: the idea that you can generate the money efficiently, but not "too efficiently." Unfortunately there is no well-understood security model that allows for efficient-but-not-too-efficient attacks.
"Don't you agree that Bitcoin involves too many disciplines to try to simplify it into a cryptographic formula?"
Two disciplines, as far as I can tell: economics and cryptography. One discipline motivates the other here. Theoretical understandings of money and money creation come from economics; whatever that understanding is, the security definition needs to capture it. The involvement of another discipline does more to motivate the demand for a security definition than to make it irrelevant.
Suppose you could identify or develop an economic theory for money that has no intrinsic value and no central authority. You would still have to have some security definition that captures that theory to make a convincing case (or at least a meaningful statement) that the money in Bitcoin meets the requirements of that theory. If you cannot identify an economic theory that supports a system like Bitcoin, you are no better off than if you cannot state a rigorous security definition.
"Something that breaks Bitcoin could even simply come from Economics, and your crypto model (if you ever find one) would be useless."
Whatever hypothetical security definition you had would not be useless in that case. Rather, it would be that systems that satisfy that definition do not make economic sense, and hence that entire category of systems has no practical use. I would say that in that case, Bitcoin would be solving the wrong problem, rather than that Bitcoin was "broken" (which I take to mean that it does not solve the problem it is supposed to solve).
"Let's try with an analogy (you can attack it or say why it's bad). Your ship is sinking for some reason, there are no emergency boats, but you find out something that might be used to stay afloat."
Are you suggesting that Bitcoin is a system that people desperately cling to when they believe that well-designed systems are failing? I think this might be the wrong analogy, at least if you are trying to defend Bitcoin.
A better analogy might be this: you are standing on a ship. You do not like the captain and his decisions, so you grab some hunks of wood, styrofoam, tires, and a barrel full of fuel oil, lash it together with some rope, and set sail.
Which would you rather be standing on -- a well-engineered ship that might sink if the captain makes bad choices or if the crew fails to maintain it properly, or something that some guy assembled from stuff he found that seemed relevant to ship-building and which seems to float, seems to have no captain to make bad decisions (but might be split in half if the crew cannot agree on a heading), and which has not yet sunk under the weight of its passengers?
"If by breaking Bitcoin you can silently steal millions and safely cash out (one hell of an incentive in my book), yet no one does it, I say it's secure enough. Not in a cryptographic or <individual traditional field> way, but in a pragmatic way. It just works."
What if the attacker does not want to steal money, but just wants to disrupt the system? Imagine a hypothetical "Satoshiland" where Bitcoin is a major economic force; now imagine that another, more powerful country is about to go to war with Satoshiland, and that their goal is to destroy everything. If the invader can block transactions, create transactions then reverse them, and kill the mining bonus, they can cause vast economic harm -- without firing a single gunshot.
Or (slightly) more realistically, what if the US government wanted to block payments to Wikileaks. What if that is worth more than whatever it costs to do so (ie a "51% attack"), and more than whatever hypothetical mining payoff could be had by just devoting the hardware to mining?
I would not assume that the adversary's goal is your personal goal.
LOL, great counter analogy. Well, let's hope you are wrong. Either way, it will be something interesting to watch. If Bitcoin dies overnight, we are going to see a lot of people jumping off the buildings. And if it succeeds, you know, we will become a type I civilization and all that...