2:30 I also belong to IOB Labs, which is the organization that supports my research, and within IOB Labs, I'm part of their research and innovation team. 2:40 This is an awesome team, 10 people that we work in state-of-the-art research on Bitcoin, RSK, and things blockchain in general. 2:53 So what is Rustok? Rustok was the first Bitcoin sidechain. It was launched on January 2018. 3:02 The native currency of RSK is, of course, Bitcoin, and currently there are about 113,000 accounts in RSK. 3:14 It has fast log times, around 32 seconds, and it runs EVM contracts. So basically you can take an Ethereum application and port it to RSK and run it with a Bitcoin as the native currency. 3:29 Currently there are 15,000 contracts deployed on RSK. It is merged mining with Bitcoin with approximately currently 57% of Bitcoin hash rate merged mining RSK. 3:46 Generally this goes from 50% to 80% of the Bitcoin hash rate. And it has a two-way peg with Bitcoin that is HSM-enforced, and this is an SPB bridge. 4:01 Currently there are 3,000 BTC locked in the RSK peg. And the blockchain is used by thousands of people. There are about 70,000 monthly active users in RSK. 4:18 So there are a lot of Rustokers using RSK for DeFi, also for remittances, for savings in stablecoins, and all kinds of very interesting applications. 4:30 So the first question that I'm interested in talking today is what is a sidechain? So this is my definition of a sidechain. 4:41 A Bitcoin sidechain is an independent blockchain that can securely transfer Bitcoins internally and from to the Bitcoin network without an ability to support a money token different from Bitcoin. 4:56 This is my own definition of what a sidechain is. But it seems like this is cheating, right? Because maybe I choose the definition of sidechain to match RSK. 5:08 Well, this is not the case because I'm basing my definition on the original sidechain definition from 2012 that was posted on Bitcoin Talk that defines a sidechain not by its technology but by the future it should have. 5:28 So basically this user said that a sidechain does not require separate currencies, so there is no other native money, does not need full or significant adoption by the Bitcoin network, so it's isolated, does not mirror the Bitcoin blockchain block by block, so this is a separate blockchain, it's not an overlay protocol, and it uses and is dependent on Bitcoin. 5:53 So probably this could be that it is two-way bridge or it is merge mine with Bitcoin. 6:01 So if we take a look at my definition and we compare it with the original definition of the sidechain, basically what I did is simply put all these properties into a single sentence that you can easily remember. 6:15 So this is a very straightforward definition for a sidechain. 6:22 But you probably think, OK, but what about decentralization? 6:27 The definition does not say anything about decentralization. 6:30 Well, the bad news is that with the extremely limited tools that Bitcoin has today, which is basically multi-sig, time locks, and taproot, we cannot achieve the desired level of decentralization. 6:46 But with this limitation, Rusto has reached a very high level of decentralization. 6:52 And I will show you in this talk all the properties that RSK has to be able to become really decentralized. 7:02 So the properties are basically that it must be run, it should be able to run in a laptop, you should be able to run a full node in a laptop. 7:13 You should have like clients, so nobody needs to depend on a centralized infrastructure. 7:20 It is a merge mine. 7:22 It has a PoPeg, which is a very, very interesting type of peg with Bitcoin that I will talk a little bit more about. 7:32 It should be self-sufficiency. 7:34 So if it grows, then it should be able to pay for its own growth. 7:41 It should not grow in an unbounded way where people are left out of the network because they cannot run a full node. 7:49 And, of course, it needs to have a community-driven procedure to create network upgrades. 7:56 So let's go and see each one of these items one by one and what happens in RSK. 8:04 So the technical features that enable decentralization relate to that full nodes should be able to be run on a laptop. 8:15 So one of the properties of RSK is that it is using a very, very efficient data structure to store the state. 8:26 So basically each account in RSK consumes only 12 bytes. 8:30 So we can put millions of accounts and store all this data structure in memory and provide very, very efficient management of this data structure. 8:45 Second, we developed a specific database engine, a key value database engine, to store this data structure that is very efficient. 8:57 Its performance is about 20 times faster than LevelDB, for example. 9:04 And writing speed is twice as fast as LevelDB. 9:07 So this is the data structure that we plan to use in the future for storing the state when the state grows. 9:13 And we have a proposal to do compact block propagation that is already there in the proposal repository. 9:23 And, of course, there's still a lot of room to optimize blockchain synchronization. 9:27 We think we can do better, but this is very promising. 9:32 So we will always be able to run a full node in a standard laptop. 9:39 So the other interesting aspect of RSK is how it relates to merge mining. 9:45 So currently between 50 and 60 percent of the Bitcoin hash rate is mining RSK. 9:51 So it is very secure. 9:53 But, of course, if you know all the details about merge mining, the security of merge mining is only assured if there is a high incentive alignment between Bitcoiners and the sidechain community. 10:08 And this is true for RSK. 10:11 For instance, we have support from Bitcoin maxi pools such as RAINS. 10:16 And we have also open source plugins to connect to different pools. 10:22 One of the properties of RSK is that it is protected from fee snipping by using a smooth revenue. 10:30 So basically each block does not pay the full amount to the miner of that block, but it pays a percentage of the fees collected. 10:38 And the rest is postponed and is paid for the following miners. 10:44 And one system that we put in place in RSK is called the universal merge mining subsystem. 10:51 And the idea of this system is to provide Blind Merged Mining for other sidechains. 10:57 Currently there are no other sidechains, so this system is not being used. 11:00 But we thought, how can we use RSK to facilitate the creation of new sidechains? 11:08 So we put this system in RSK. 11:11 Another interesting thing that needs to be very good decentralized is the POPEG, or in case of other sidechains, the federation. 11:21 So the federation or the POPEG in RSK is based on a 7 out of 13 multisig. 11:27 But the main difference between RSK and other kind of federations is that the private keys are stored in portable HSM devices that are based on ledger wallet technology. 11:40 So the POHSM validates the RSK chain in SPB node. 11:47 So essentially each one of these devices is validating certain rules of the consensus of RSK. 11:57 So the devices themselves are able to control the release of BTC, the pegout process. 12:07 So each pegout command requires 4000 RSK confirmation blocks, which is about, in comparing cumulative difficulty, it's about 100 Bitcoin blocks of hash rate, right? 12:21 So if you want to cheat one device, even if you steal one of these devices, you will not be able to command any pegout on the device. 12:30 So this is very important because if you think that, you know, in the future states around the world can try to censor the pegins or censor the pegouts, 12:42 it's very important that the pegnatory, the one, the functionaries holding one of these devices, 12:48 it's very important that they can be and they can move to any part of the world. 12:52 And with a single laptop and with the HSM devices, they can provide the services for approving or for signing the pegouts. 13:04 And finally, the POPEC nodes can be securely run on laptops anywhere on earth. 13:13 They could in the future even connect to RSK over Tor. 13:17 And it is very, very important that POPEC nodes remain secure, even when you run them on laptops, 13:27 because one of the most important centralization forces in any blockchain that is not decentralized enough is that to run one validator, 13:37 you need so much resources that people end up running these validators on the cloud or on data centers, 13:46 so they are prone to censorship by governments. 13:50 The POHSMs are based on the ST33 tamper-resistant secure element, 13:57 but if you have some doubts about these secure elements that are not open source, 14:05 then we are ready to port the firmware to the TropicSquare open source secure element whenever it is ready. 14:12 So probably it will be on a second layer multisig so that both multisig need to approve a pegout, 14:20 one multisig using the POHSM devices and the new multisig using probably something like the TropicSquare open source secure element. 14:31 So we are trying to make this as open source as possible. 14:37 The firmware of the POHSM will be soon open source, probably next week, I think. 14:44 And we have a very interesting community proposal to move to threshold signatures to be able to add more pegnatories in the future while keeping the pegout cost low. 14:56 And we added in two Firefox ago, we added a 3.0 to 4.0 backup multisig that is time locked for one year. 15:10 So because these hardware devices have full control of the private keys, there is no way to tamper with them, 15:17 we needed to provide some safeguard in case the devices have some malfunction. 15:25 So essentially, if for one year the devices are unable to process pegout, 15:30 then there is a backup federation that will take care of these funds and redistribute them or put them back in the peg. 15:39 So one of the important things about RSK is that we plan to be self-sufficient in the future. 15:47 So we plan to use payment channels to pay for infrastructure for like client services. 15:53 We develop a technology which is called proof of unique blockchain storage to incentivize decentralized storage of historical blockchain data. 16:01 Pegnotories are already incentivized with a percent change on transaction fees, so we think this is a sustained level in the network. 16:11 And we implemented, and this is going to be activated in the following half work, 16:16 we implemented a storage rent to keep the state under control so that it can fit in RAM, 16:23 so you will be always able to run your node on laptop, on a personal computer. 16:29 Well, I'm getting run out of time, so this is about like clients. 16:36 We also provided or are developing technologies to allow like clients. 16:41 And finally, we have a very interesting process of upgrading the Rootstock platform 16:50 because Rootstock development is much less politicized than Bitcoin development 16:55 or than Ethereum development or than mostly any other chain development 17:01 because basically we cannot change Bitcoin's money supply function. 17:05 So anything you do on RSK is basically a technological change, 17:11 something to optimize the way the resources are used, 17:15 and there is no proposal you can create to alter something that, 17:21 you know, alter decentralization or alter to change Bitcoin's supply function, 17:28 which will be very, very controversial, right? 17:31 So our Bitcoin community has a very strong stance to put decentralization before scalability, 17:39 so no change in the node will happen that affects decentralization. 17:44 And we have more than 300 improvement proposals in our repository. 17:47 Obviously, the core developers are trying to code them 17:53 and to include them for community analysis as fast as they can, 17:59 but this is a lot of proposals for improvement platform. 18:03 And we perform approximately one upgrade per year. 18:08 Okay, what about the decentralization of the two-way peg in the future? 18:14 Well, I created the HashRay DeskCrow proposal, which is BIP-11, 18:22 that uses a new opcode called opcode-axe to provide HashRay DeskCrow functionality to Bitcoin. 18:30 I hope that in the future I can present this proposal again when the time comes, 18:36 when the community is ready to evaluate different alternatives to create sidechains. 18:44 Also, we could switch to BIP300 if this is what the Bitcoin community prefers, 18:50 or maybe there's a new technology, zero-knowledge peg or whatever you want to call it, 18:57 zero-knowledge rollups, and RSK could switch to this technology. 19:00 We are working on very cool features that we'll be activating in the following hard fork. 19:06 One is, I mentioned before, Storage Rent. 19:09 We have a prototype ready for parallel transaction processing 19:13 to improve the transaction processing capabilities. 19:16 And we have a protocol which is called Flyover protocol, 19:20 which is a trustless peg-in and peg-out protocol. 19:22 This is very interesting. It's already activated in the network. 19:26 Okay, this is all. 19:27 Thank you very much for this remote invitation. 19:32 If you want to research more about RSK, you can go to the research forum 19:36 or the developer site or their Discord 19:39 or many other communication channels set up by the community. 19:43 So, I invite you to go there, download your RSK full node, and have fun. 19:52 Thank you. 19:58 All right, we've got the next one coming up. 20:05 This one is about unpopular opinions. 20:08 I don't know if everyone's got them. 20:10 Altcoins, LARPing, tail emissions. 20:15 Let's have it out. 20:17 We're going to have a panel. 20:19 Marty's going to host it. 20:21 We've got a few great panelists. 20:23 We've got Peter Todd, Eric Voskil, Paul Sztorc. 20:28 Giacomo, and I think that's it. 20:32 Welcome them up. 20:34 Marty's going to introduce everyone. 20:36 Thank you so much. 20:39 All right, we're audibling. 20:42 We're still doing unpopular opinions, but we only have 30 minutes for this time slot. 20:46 Matt couldn't be here for our HR. 20:48 He sends his love from across the pond. 20:51 So, we're just going to extend this topic for the next hour 20:54 because there's a lot of unpopular opinions. 20:59 I mean, I don't want to shit on the dude who just presented, 21:04 but Rootstock seems to be pretty unpopular with people. 21:07 Why is that? 21:10 I think a lot of people don't know what Rootstock does. 21:13 He did a great job in that talk of listing a lot of things, 21:16 but he never actually explained that it was supposed to be like an Ethereum. 21:19 He never actually explained a basic feature of it. 21:23 Well, you can explain why it's so unpopular, 21:25 because it's for the same reason why your own ideas are so unpopular. 21:28 This is starting, like, very good. 21:32 Well, you could say we need the neutral zone. 21:36 I was expecting a slower introduction. 21:38 I actually have a real reason why RSK probably is not that popular, 21:44 which is because Ethereum has its own token that you can buy, 21:48 so it's not good enough. 21:49 Even if RSK tied for features with Ethereum, 21:53 people would still say, 21:55 well, if I believe in these features, 21:57 why would I go for the multi-sig, 22:00 sort of crippled version on BTC 22:03 when I could just invest in ETH, join the ETH community. 22:06 And so even if it tied for features, it would lose to ETH, 22:10 but it doesn't even tie because Sergio likes to invent 22:14 a lot of weird things and plug them into RSK. 22:16 Sergio likes to stay out of jail, 22:17 and because of that, RSK will never moon. 22:20 Peter, you just had a couple choice tweets about HSMs, 22:24 riffing on that. 22:26 Yeah, you pro-HSM now, right? 22:28 Well, I mean, 22:30 HSMs have their place, 22:32 but to go on the same slide, 22:34 say decentralization and HSM is crazy. 22:37 Yeah, I think the HSMs are a little bit of a cop-out, 22:40 so I agree with Peter on that one. 22:42 Why is it crazy? 22:44 Well, first of all, I've got to explain what is an HSM. 22:46 And HSM stands for Hardware Security Module, 22:49 and the idea there is you have this piece of hardware 22:52 that's a security module that does something trusted 22:56 in a way where even the person in physical possession of the HSM 23:01 can't violate what it's doing. 23:03 And, you know, of course, like Liquid uses these, 23:05 like Blockstream Liquid, they use HSMs for the signers, 23:08 but they use HSMs because people in possession of the signers 23:12 really do not want the ability to go steal all that money. 23:15 Well, at least most of them probably. 23:17 Most of them don't. 23:19 Because, you know, it creates risks. 23:21 Like if you're in possession of someone else's money, 23:23 you really don't want to be the guy who screws up 23:25 and loses it all, so you build HSMs 23:27 that are a little piece of hardware, they're secure, 23:29 they have the anti-tamper effects, whatever. 23:31 But the fact of the matter is, 23:33 HSMs, you're trusting the manufacturer. 23:35 And that's often better than just trusting the guy 23:38 who's writing the computer. 23:40 But that's still not decentralized. 23:41 That, by the way, was also the way that 23:45 Hal Finney was imagining reusable proof-of-work, 23:48 because Hal Finney could not solve 23:50 the double-spelling problem in a decentralized context, 23:52 so he proposed to use trusted computing, 23:54 which is basically HSMs. 23:56 But it was like a second best to a decentralized solution, 23:59 and then Satoshi Nakamoto invented. 24:01 So as many other things, 24:03 things proposed in Bitcoin right now, 24:05 they are just marketing rediscoveries 24:07 of things already proposed before, 24:08 like the way that I proposed proof-of-stake, 24:10 basically, with the second b-money. 24:12 It was broken. 24:14 People noticed it was broken. 24:16 And so in 2014, 24:18 shit-coiners rediscovered it 24:20 and re-marketed it, 24:22 just like everything else, 24:24 like DAG chains or whatever. 24:26 I mean, proof-of-stake in particular is hilarious, 24:28 because in the early days 24:30 of people trying to invent Bitcoin, 24:32 it was sort of an obvious idea. 24:34 Of course, you could have people with coins 24:36 who sign it, but obviously that wouldn't work. 24:38 How would you ever get consensus 24:40 when you just go rewrite history at will? 24:42 Well, it turns out if you go publish the consensus 24:44 on Twitter or something, I guess that's enough. 24:46 Yeah. Eric, we were talking about proof-of-stake, 24:48 I believe it was yesterday or the day before, 24:50 I think, the way you describe it. 24:52 How would you say he who owns the history 24:54 owns the future? 24:56 Is that how you...? 24:58 Yeah. 25:00 I've never heard it framed that way. 25:03 I don't think it's an uncommon viewpoint. 25:07 It's certainly not an opinion. 25:09 I don't know if it qualifies for this panel. This is factual. 25:12 Sorry, Eric is offended because his are never opinions, just facts, 25:16 so you put him in a couple of opinions. 25:18 A man who knows everything. 25:19 I think I've been on this panel every year, and I don't know why. 25:22 I understand Giacomo, but even Peter. 25:28 Even Paul over here, I don't understand. 25:33 I generalize as much as I can, just about everything I can, 25:36 and I look at stake versus work. 25:39 People might imagine there's all these different kinds of proof, 25:42 and it gets really confusing and everything, and it is, right? 25:44 But when it comes right down to it, there's two kinds of proof, 25:47 and I call it internal and external. 25:49 There's what's internal to the chain, the history, 25:52 and there's what's external. 25:53 It has nothing to do with history. 25:55 Work is just a name for what's external, 25:58 and stake is a word for what's internal, 26:00 and even if you combine them, one is going to dominate. 26:03 What was it? Decred? 26:05 Decred. 26:06 Yeah, so I did some analysis on Decred, 26:07 and I was like, you know, stake dominates, 26:08 so it's proof of stake coin. 26:09 It doesn't matter how much work you do. 26:11 So if you want to simplify things, 26:13 that's what this world divides into, 26:15 and stake means that the history controls the future, 26:19 and given that you don't have censorship resistance 26:23 because once somebody controls the history, 26:26 there's no way you can remove them. 26:29 Yeah, they can buy old keys, 26:31 and they can also just make millions of fake versions of history. 26:37 So I don't know how many people here, 26:38 hopefully we're in a room full of very smart people 26:41 who are very skeptical of proof of stake 26:43 and do not believe that it is a significant improvement 26:47 over proof of work at all. 26:49 I mean, I think, who here is, 26:52 can we ask people to raise their hand 26:53 if they think that proof of stake, 26:54 they're open-minded to proof of stake? 26:55 If you raise your hand, you come on stage 26:57 because that's unpopular here. 26:59 That's locally unpopular. 27:02 Special room for you out back. 27:04 The main selling point is environmentalism, 27:07 and Paul's blog had a great article 27:10 because you have to know that Paul's articles 27:12 before it became anti-Maximilians were very good, 27:14 and there's an article called 27:16 There's Nothing Cheaper Than Proof of Work, 27:18 which explains to you that you don't even get 27:20 any environmentalist advantage. 27:22 It's not just circular and broken. 27:24 It's also mostly useless. 27:26 Yeah, I think if you put an enormous amount of R&D 27:30 into proof of stake, you could probably make it 27:32 like very much basically equal to proof of work 27:34 as far as in every respect, 27:36 but I don't think that I'm very skeptical. 27:38 For years, I thought we would do this joke 27:41 about it being three months away, 27:42 and we have that great Twitter thread about that, 27:47 and so that joke went on and on and on forever, 27:50 back in 2015, they would be like, 27:53 Ethereum was going to switch to proof of stake, 27:55 and now it seems like they may finally actually do it, 27:59 which I think there's that metaphor 28:01 of when the dog's chasing the car, 28:02 and then the dog finally catches the car, 28:04 and the dog doesn't know what to do, 28:05 and it's like, I don't know what will happen 28:07 if they actually turn it on. 28:08 No one will be more interested than I 28:10 if they actually switch to it 28:12 because I just kind of thought 28:13 they would just kind of never switch to it, 28:15 but we'll see what happens. 28:16 Well, it's fascinating that right now, 28:18 hashing power on Ethereum is actually going up. 28:22 It's not like they're jumping ship, 28:23 thinking, oh, this is all going to end. 28:24 For whatever reason, they're jumping onto Ethereum, 28:27 thinking, well, either we can make some money 28:29 or we're going to plot something. 28:31 Sorry, but we are all agreeing right now. 28:33 Yeah, this is very popular. 28:35 Let's talk about this inflation attacker. 28:38 Yeah, Giacomo, I was wondering 28:40 about what you were going to say 28:42 about the Peter Tau's inflation thing 28:44 because normally I feel like the two of you always agree, 28:46 and that was my first thought when I read this thing 28:48 because Giacomo's like the biggest anti-never 28:52 at any violation of the 21 million coins, 28:55 and then I was like, oh my gosh, 28:56 this is finally the divorce between the marriage 28:59 of Giacomo and Peter Tau. 29:01 Just one Satoshi. 29:02 She's going to. 29:04 All right, yeah, so for this topic, Peter, 29:07 obviously you wrote to the mailing list 29:09 about your basically belief that there will need to be. 29:12 We're calling it tail coin now. 29:14 Tail coin. 29:15 Tail coin is going to need to be created. 29:18 Why do you believe that is so? 29:19 Remember, it's not just tail coin, 29:20 it's continuous tail coin. 29:22 I like more emission coin 29:23 because like a fart is an emission of some gas. 29:28 It's TLC for those who want to look it up. 29:31 So why do we need tail emissions? 29:34 Well, I mean, tail emissions is just one way. 29:37 I think the bigger issue is Satoshi designed Bitcoin 29:42 so that the inflationary reward that you get 29:46 in every block would eventually disappear. 29:48 And that means that Bitcoin has a state change. 29:50 You start off in one state 29:52 where every block will go make you money guaranteed, 29:56 maybe not very much in the very beginning, 29:57 but certainly like after the first year 29:58 or two bootstrapping, 30:00 you mine a block, you're going to make money. 30:02 Thus, your incentive is keep mining the blockchain forward. 30:05 And then in the future, it changes this thing 30:07 where now it's all about transaction fees. 30:09 And there is no coin in the world 30:11 that's proof of work that relies just on transaction fees. 30:15 Like nobody's done this. 30:16 Nobody's proven it to work. 30:18 And it's just from that point alone, 30:19 I would say this is crazy. 30:21 Going from this thing that is working 30:23 to this thing that is completely untested. 30:27 Why would you ever go do that 30:29 for the sake of having, you know, 0.1% less inflation? 30:32 Why going from PayPal to Bitcoin, right? 30:35 Nobody did that before. 30:38 But why would you do two novel things in once 30:42 when you only have to do one? 30:43 Well, I think there's an important point here. 30:46 Like the addition of tail emissions, 30:51 the amount of emissions is arbitrary to begin with. 30:53 So you open a Pandora's box of arbitrariness 30:56 that if you do it once, it's like, oh, we did 0.1. 30:59 There's a lot of arbitrary decisions we go make. 31:02 And certainly, I mean, I think the easier, 31:04 or I should say the more popular viewpoint 31:08 is that Satoshi should have done this at the beginning. 31:10 It should have been like one Bitcoin per block forever. 31:12 I mean, the exact number, of course, doesn't matter. 31:14 But, you know, some amount per block forever 31:16 would have been simple and would have worked. 31:18 Some, if you want to argue about it, 31:20 maybe some amount increasing 31:21 so it actually is inflationary. 31:24 But like the point is just don't do something 31:26 where it has a state change from, 31:28 yeah, there's always incentive 31:29 to move the blockchain forward 31:30 to actually there probably isn't in a whole lot of scenarios. 31:34 Yeah, there are two different discussions here. 31:35 One is would telemissions or stable emission 31:39 be better or worse? 31:40 And we can discuss that. 31:41 And the other is should we change Bitcoin now 31:44 to achieve that? 31:45 And I think on the second part, 31:46 we are really ready to punch each other 31:48 because that's, I mean, that's the no-go. 31:50 The first part is- 31:51 Sometimes sneaky ways around this 31:52 where you don't have to go and, you know, 31:55 get into that argument. 31:56 Exactly. 31:57 Yeah, but as the, if it's a fixed amount of coins per block, 32:01 eventually it will be such a small percentage 32:03 that it will have no effect anyway, right? 32:05 So it won't even be able to pay for- 32:06 Which is exactly why I wrote telemission. 32:08 And funny enough, it's non-inflationary 32:10 because it isn't- 32:11 But doesn't that mean also that the idea 32:12 serves no purpose? 32:13 Well, the thing is, no, no. 32:14 The point is, the point of that article 32:16 is to show that rather than it converging towards zero, 32:19 like you would expect if the coin supply increased forever, 32:22 in reality, it doesn't converge towards zero 32:24 because people inevitably lose coins. 32:26 You know, what it actually converges towards 32:28 is a rate of lost coins, 32:30 which is, you know, going to be small 32:33 because we're not all losing all our money in boat accidents 32:36 as much as we say we are. 32:38 But it's not going to be zero 32:40 because some of us actually do lose our money 32:41 in boating accidents or other accidents. 32:43 Even if it was zero, your proof still holds 32:45 because it just infinitely increases the supply of money 32:48 and then at time equals infinity, then finally- 32:50 But the supply of money is not infinite in reality 32:52 because people lose their coins. 32:53 Well, of course, I'm just saying that your math 32:56 holds even in that case when it's zero. 32:59 Well, I mean, all right. 33:00 So in that case, we're so far off in the future, 33:02 who really cares? 33:03 We're all dead. 33:04 This whole article is kind of silly anyway 33:06 because it's just saying that eventually 33:09 the coins added will be a very small portion. 33:12 Yeah, don't you want to build a system 33:13 that isn't going to just arbitrarily stop? 33:15 The article is really important 33:16 because everyone needs to know 33:17 that Peter Todd understands differential equations. 33:21 That's- 33:22 No, I don't. 33:23 I used Wolfram Alpha to solve them, just like you. 33:26 Why would you ever solve them yourself? 33:28 Wolfram Alpha is brilliant. 33:29 If you saw his presentation earlier today- 33:31 Unpopular opinion. 33:32 Don't learn math. 33:33 Just use Wolfram Alpha. 33:34 I use Wolfram Alpha to be clear. 33:36 I don't solve differential equations. 33:38 If you understand math, 33:39 you definitely want to use Wolfram Alpha. 33:40 Sometimes I ask someone else to use Wolfram Alpha for me. 33:46 Anyway, sorry. 33:48 No, I was going to say, 33:49 the way you phrased it or framed it, Peter, 33:52 was it's insane to depend on the security of a chain 33:58 on transaction fees alone 33:59 because we've never seen anybody do it? 34:01 Does that mean that you believe it cannot be done? 34:05 Is there a possibility in your mind 34:06 that a fee market could develop and it could sustain? 34:09 I don't know. 34:10 And I don't think it's a good idea to risk, 34:13 especially in the future, 34:14 a multi-trillion dollar asset on this crazy idea 34:18 just to go save a few billion dollars. 34:20 Is it that crazy, though? 34:21 Yeah, I think it is. 34:22 And also, there's technical reasons why this is dubious. 34:26 One reason is, with transaction fees, 34:30 if that's the significant source of revenue, 34:33 if someone goes in, has more transaction fees 34:35 than average in one period, 34:36 it can make sense to reorg blocks. 34:38 So, I have a bunch of fees here, 34:40 further back in the chain, there's less fees. 34:42 Well, it can be worthwhile to re-mine these blocks out of order. 34:47 So now I get those transaction fees 34:49 rather than some other miner. 34:50 And one issue why this, of course, is bad 34:53 is because it's very disruptive. 34:54 The more subtle issue is because only big miners can do this. 34:58 If I have 1% hashing power, 34:59 I don't have enough hashing power to reorg. 35:01 But if I have 30%, it might be profitable. 35:04 Just to clarify, this fee sniping, 35:06 since it's been hyped a lot by the Stanford guys that discovered, 35:10 this goes to equilibrium anyway, 35:12 because if you have a fee sniping, 35:14 eventually, in the main pool, 35:15 you build up transactions that want to enter and cannot, 35:18 and then you build up enough fee to just evolve the chain. 35:21 But it makes mining less reality. 35:24 But again, I'm not so worried about the fee sniping itself. 35:27 That would kind of suck. 35:28 But the real issue is that bigger miners make more money on this. 35:32 That's the dangerous thing. 35:33 Reorgs make mining more centralized. 35:36 So the more incentives to reorgs you have. 35:39 But the other point is that Eric has very good explanations. 35:42 The first I read about that, about the attack of censorship. 35:45 So you may have a fee sniping, 35:47 but the second big attack you can have is 35:50 governments paying miners in order to produce anti-blocks. 35:53 In this case, an inflation subsidy will do nothing to prevent it. 35:58 It will just diminish the cost of the attack. 36:00 And the only answer to this is fees. 36:03 So if we assume that nobody is going to pay for block space, 36:07 the block space market is going to suck anyway. 36:10 We cannot invent money. 36:11 We cannot print usage. 36:13 We cannot print demand. 36:15 We can just print supply, 36:16 but we cannot bring demand in artificially. 36:19 We just have to accept that nobody cares for block space. 36:22 And if nobody does, why do we really have to provide block space? 36:25 See, I don't think that really works out because... 36:30 Alright, in your realistic scenario where some government wants to spend money to go screw over Bitcoin, 36:35 what's more likely to happen is either 36:38 their budget is enough money that they're not trying to go and earn a bit of return 36:42 by getting some subsidy in the process. 36:44 They're saying, alright, we have a budget for like 10 billion dollars. 36:47 Is that enough to go screw over Bitcoin? Yes or no? 36:50 Oh, it is? Okay, good. 36:51 Let's go build a bunch of mining equipment or buy a bunch or steal a bunch or whatever. 36:55 But what's more important to defeat that is ensuring that 36:59 there's a lot of revenue going to miners, period, 37:02 that are already out there existing doing something really boring like Bitcoin mining. 37:07 And it's really boring because there aren't shenanigans to go on. 37:09 You just go mine things, you get some transaction fees, you get a subsidy, 37:13 and it's a very boring process that anyone, you know, 37:17 with a bunch of electricity and somewhere to go put all the heat can do. 37:20 Like, you want mining to be boring. You don't want it to be interesting. 37:23 You don't want rootstock on top of all this stuff, too. 37:25 I don't want to have to go install 10 different MergeMine clients for all this. 37:29 I want to do one thing, very simple, install Bitcoin Core, hit go, run my mining pool or whatever. 37:34 Oh, but you know that BlindMerge Mining is designed to make it so that the miners don't have to run any other clients 37:40 and they just do what they're doing now, which is include the highest fee-paying transactions 37:44 and then everything else just kind of happens behind the scenes. 37:46 And they can make more money by being clever. 37:48 So to clarify, before it was me and Paul and Eric against... 37:52 No, me and Paul against Eric and Peter, I guess, because you're a little bit... 37:56 I don't take sides, man. 37:58 You literally haven't taken sides. 38:01 I really try not to make opinions and somehow... 38:04 We did the whole talk about it. 38:06 That is very unpopular. 38:08 Maybe that is. 38:09 It frustrates people. 38:10 But boring or otherwise, when it comes right down to it, if there's a 51% attacker, 38:17 there's the only economically rational way they are challenged is by some difference 38:25 between the reward to mine, you know, illicit blocks versus others, right? 38:33 And that difference can't come from subsidy, right? 38:37 So the subsidy doesn't contribute to that. 38:38 It's a kind of an orthogonal question. 38:40 I view these as independent issues. 38:42 Do you think a 51% attacker will be economically rational? 38:46 Or have an incentive that's entirely outside of our economic model? 38:51 I think both those can be true. 38:53 It can be completely rational and outside of our economic model. 38:56 That's basically the state, right? 38:58 So a state wants to preserve the revenue it gets from its own money, which is significant. 39:03 And if they don't do something about Bitcoin, etc., then they will give that up. 39:09 And there's a huge, presumably, financial incentive to prevent that from happening. 39:14 So whatever budget they allocate, the only thing that challenges that budget 39:19 is some difference between these fee levels. 39:21 I mean, first we might presume they'll just ban certain types of transactions. 39:24 You can see it's already kind of creeping its way along with KYC requirements on big miners, etc. 39:28 But at some point, somebody's got to pay the miners to take the risk to mine the illicit transactions. 39:35 Subsidy or no subsidy? 39:36 This is kind of an independent question, which I find is interesting 39:38 because it doesn't really challenge this tail coin thing. 39:42 Some people think that a fee market doesn't develop as long as we have a big subsidy. 39:46 I find this a really interesting perspective. 39:49 But we have a big subsidy and a fee market has developed on a fee market. 39:52 Well, why wouldn't it, right? 39:53 People are paying for block space. 39:55 The amount of block space is not affected by the subsidy. 39:58 And you're competing to get in. 40:00 It has nothing to do with the subsidy. 40:02 And the amount of the subsidy or the reward, the combined subsidy and fee level, 40:06 has nothing to do with miner profitability. 40:09 It's a competitive market. 40:10 It's a competitive market. 40:11 They're going to make the interest rate, the cost of capital, period. 40:14 It doesn't matter what the reward level is. 40:16 So these are completely unrelated issues. 40:18 The question of whether fees will rise to the point where they become significant 40:23 in proportion to reward is a question of how much demand there is for block space, 40:27 which means demand to transact. 40:31 That's it. 40:31 That's the only thing that's going to cause fees to rise to some level. 40:35 Now, if it happens, doesn't happen, that is going to have an effect, right, 40:38 if subsidy drops off on the total hash rate, but not on miner profitability. 40:42 That's not going to be affected. 40:44 But let me remember, though, we don't actually care about miner profitability 40:48 in a lot of these tax centers. 40:49 What we actually care about is how much money does it cost to do an attack. 40:53 Right. 40:53 And that is set by fees. 40:56 It's nothing to do with the profitability. 40:58 It's the difference between the censored fee level, 41:01 the going fee rate for censored fee transactions, 41:04 and what people are willing to pay above that 41:06 to incent miners to take those transactions. 41:08 That fee differential is the only thing that will pay miners to take the risk. 41:13 But, well, so one thing I want to unpack is, first of all, 41:17 there's a huge difference between 95% of miners refuse to go mine your transaction 41:24 and 51% or 100%, of course, if they do an attack, 41:29 like, sorry, 100% or 51% if they do an attack of miners refusing. 41:33 And the difference there is that, 41:35 if miners simply aren't interested in my transaction, 41:39 but I can go pay that remaining 5% to go and include it, 41:42 and those other miners will build on top of those blocks. 41:46 So this is the budget. 41:49 Point is, pretty quickly, my transaction will get mined. 41:52 And this is just a minor inconvenience. 41:54 You know, I pay a little bit more fee, maybe I have to wait a little longer. 41:58 But especially with things like Lightning, it doesn't really matter that much. 42:01 You know, my transaction will get confirmed, 42:03 and my Lightning channel will open, I'll be able to do what I want. 42:05 Yeah, the real attack we're talking about is actually reorging 42:08 when your transaction, when your illicit transaction is inside one previous block. 42:12 As well as attackers who just want to say, 42:14 all right, Bitcoin is now AML KYC. 42:16 And I don't think that attack is going to be one driven by profit. 42:19 I think that attack is going to be one driven by, 42:21 well, we are going to force you. 42:22 And, you know, either they can go do that in ways 42:26 where mining revenue can't help you at all, 42:28 or they do that in ways where they're... 42:31 We're talking about this. 42:33 So what do you guys think the probability of an actual 51% attack is? 42:37 Has that probability gone up or down over the last three years? 42:41 Well, it is a function of the cost of doing so, right? 42:44 So that right now, it's very, very expensive to do such a thing. 42:48 Like the spiteful, there's like the spiteful attack 42:51 where someone just wants to shut the Bitcoin network off for a while. 42:55 And they don't care about, 42:57 they don't care if they're just spending money and losing it. 43:00 That is a very sort of spiteful thing. 43:01 That would depend on how expensive it is. 43:04 Do you think that probability would go up or down 43:07 if we cut the overall mining reward by say, you know, like 10 times? 43:14 Oh, slightly down, irrelevantly down. 43:16 There is just a little bit of money. 43:18 It costs a little bit more to perform the attack. 43:20 What about a hundred times? 43:22 What about a thousand times? 43:23 Like where's the threshold where this amount of money going into mining 43:26 is low enough that people will do it? 43:28 Because they have a bit of budget left over, 43:29 and you know, the CIA's budget for the end of the year. 43:32 There's no cost to achieving 51%. 43:34 Mining's profitable. 43:35 The bigger you are, the more profitable it is. 43:37 No, but he's saying the 51% attack. 43:39 So once you're not building on somebody else's blocks 43:42 and you've got 51%, what's the cost to you? 43:45 Now, you could presume price goes down. 43:47 So you're going to lose some capital costs. 43:49 But we might see price go up in the face of a 51% attack. 43:52 Okay, to be clear, you're saying that there's a capital cost to the 51% attack. 43:56 No, I'm saying mining is profitable, 43:59 and mining at 51% will be especially profitable. 44:02 Well, why can't I do a 51% attack? 44:04 You can. 44:05 Me, right now? 44:07 Just raise the capital. 44:08 Ah, okay, but I've got to raise the capital. 44:10 Capital is not... 44:11 And it has to be at risk. 44:12 That's not zero cost. 44:13 If you raise the capital, you'll recoup your capital costs 44:17 because mining is profitable. 44:19 So, for example, the primary threat, the state, 44:21 can easily raise the capital and mine profitably. 44:26 Otherwise, Bitcoin's still alive. 44:28 It's not fair that me and you are not fighting, 44:30 so let's do Samurai Wallet, please. 44:33 I mean, people have in mind the 51% attack 44:35 that would reduce the value of Bitcoin to zero, I think. 44:37 That's like the... 44:38 The only entity that has the incentive financially 44:41 to execute a 51% attack is the state 44:44 because it's competing with state money. 44:46 Are they competent enough? 44:48 Wait, wait. 44:49 Well, you say yes, but we have an example last year 44:52 of China literally kicked out the whole mining industry, 44:55 had an opportune time to seize the mining equipment at the border, 44:59 and China arguably has the highest incentive to destroy Bitcoin, 45:03 and they didn't do it. 45:04 These things will evolve, presumably, over time. 45:06 If China doesn't want people using Bitcoin, 45:08 they can just ban Bitcoin, 45:09 they can get rid of most of the use, right? 45:11 But if it continues to get used... 45:14 So, the easiest thing for the state to do, 45:16 the cheapest thing is pass a law, ban it. 45:17 Most of the white... 45:18 All the white market disappears overnight. 45:20 Gone. 45:21 Right, Coinbase, everybody, all the big miners, 45:23 they're just gone. 45:24 So, China did that. 45:26 But as Bitcoin evolves 45:28 as a more distributed black market money, 45:31 the next phase will... 45:32 If it's taking enough revenue away from state monies, 45:35 the next step, logical step, 45:37 is to attack the entire network from a single point on the earth, 45:40 which is a 51% attack. 45:41 Do you think Bitcoin's stronger or weaker than it was 45:44 before China kicked it out? 45:45 I don't have a way to measure that. 45:46 I don't know. 45:48 I don't like opinions. 45:49 That's an opinion, and I'm not going to... 45:50 You don't like opinions. 45:51 But I can... 45:52 Presumably, if you act on economic rationality, 45:55 you have to look at the rationality of the state 45:58 is not in making money, double spending. 46:00 It's not in even shutting down the network. 46:03 It's preserving the signage and transparency 46:06 of its own money as tax revenue. 46:09 And if they don't do it, what's going to happen? 46:12 That will go away. 46:13 It literally will go away. 46:14 The state won't have state money anymore, 46:16 and we'll have our Bitcoin paradise. 46:18 But we have to assume that they might want to protect it. 46:21 Hang on. 46:22 So you seem to be talking about the state being financially rational. 46:26 Remind me again. 46:27 How is it financially rational to go shut down the economy 46:30 for two years to go combat the flu? 46:33 These things may not look rational to you, 46:35 but you're not the state. 46:37 I'm pretty sure there's more than just financial rationality 46:40 going on here. 46:41 I think there are political considerations. 46:43 We should build a system that's resilient to crazy people. 46:47 Because then they could spend even more money than they would ever create. 46:51 Yeah, they could. 46:52 They could do a suicide attack. 46:53 Absolutely. 46:54 We have to consider irrational attacks as well, of course, by the state. 46:57 I'll just bring back the point that it can be done. 46:59 It's possible. 47:00 We can't reject that. 47:02 The security model of Bitcoin has to be based on, 47:05 probable or not, dealing with it. 47:08 And the way, the only way it's dealt with 47:11 is by paying people to mine transactions when it's not allowed. 47:14 So we need lots of security budget and lots of fees being paid. 47:17 It doesn't come from security. 47:19 It doesn't come from block subsidy, 47:22 and it doesn't come from the kind of prevailing fee rate. 47:24 It comes from the amount that people are willing to pay 47:27 above the prevailing fee rate to get unapproved transactions approved. 47:31 That delta is it. 47:33 It's the only additional amount that you're paying to miners 47:36 to take those transactions. 47:37 So discussion will go to how to increase that delta by, for example, 47:40 aggregated demand. 47:42 We may have many black market users 47:44 that individually cannot go to that threshold. 47:47 So we want to aggregate with stuff like multi-party channels. 47:50 No, no, we should get rid of Lightning. 47:52 No, no, we should get rid of Lightning. 47:54 Lightning is the thing that's preventing all these fees 47:56 from going on to the main chain. 47:58 Far more fees would get paid to the main chain 48:00 if we got rid of Lightning. 48:01 You know what's unpopular? 48:02 It's very popular to say that Bitcoin is going to fail 48:04 because nobody will have the block space to open Lightning channels 48:07 because it would be too expensive. 48:09 But also, there would be fees so low 48:11 that nobody would pay for miners. 48:13 So these things are popular. 48:14 What's unpopular is just, we'll be fine, guys. 48:17 We have seen something really interesting happen. 48:22 If you go look at fees, they did go up a lot 48:25 to the point where transactions on average 48:28 would frequently cost, I mean, even $10, $20. 48:32 But how much of that can be applied to that spam attack 48:34 that happened during that period? 48:37 But hang on. 48:38 But on top of that, people were willing to go pay these big fees. 48:41 And suddenly, of course, Lightning gets better and better 48:44 and more and more stuff happens on Lightning 48:46 and the fees go drop like crazy. 48:48 It's really not clear how does this play out. 48:52 I think that just in general, 48:54 I think it's not clear at all 48:56 that people will pay the high fees in a sustainable way. 48:59 They sometimes will in the short term. 49:02 They very often will when the price of Bitcoin 49:05 is surging upwards. 49:08 Also, we have very clever things we can do 49:11 to make opening Lightning channels 49:13 even cheaper than it is right now. 49:15 For one UTXO for an arbitrary number of channel openings. 49:18 Well, Eric, this is something you and I talked about last night 49:21 and something I've been putting out there as a theory. 49:24 Actually, Pierre Rochard, I think, was the first one 49:26 to bring this idea to me. 49:28 It's the fact that you can apply Jevin's paradox 49:30 to a Bitcoin UTXO. 49:32 UTXO gets more efficient. 49:34 You can do more things with it. 49:35 Will that drive demand in the long run 49:37 which will then drive a thriving fee market? 49:40 Is this an unpopular opinion or just a dumb opinion? 49:43 Well, I think there may be some of that 49:47 but the main point here is that 49:49 these economic effects will not go high enough 49:51 to sustain a market where nobody needs block space. 49:54 I think that the main point is 49:56 is there demand for censorship resistance 49:59 using a non-double spending blockchain mechanism? 50:03 If the answer is yes... 50:05 If the answer is yes, then the market will figure it out. 50:07 If the answer is no, there is no trick we can play or economical paradox we can hope for. 50:12 The point is that do we think that people will need Bitcoin censorship resistance? 50:18 If yes, great. If not, that means that it's not useful to them. 50:23 I can't agree with that. I think part of the issue here is that the amount of money that will naturally get paid there 50:30 in how people actually use the system could easily be much less than an amount of money 50:35 you could easily tolerate with a security tax. 50:37 Because right now, the security tax on Bitcoin is approximately like 2%. 50:42 That's what the inflationary reward works out to be. 50:45 It will spend security, not censorship resistance. 50:47 No, I disagree with you on how that works. 50:51 But the tax we are paying that goes to pay miners works out to be about 2% of the entire value of all Bitcoins per year. 51:00 At the same time, I suspect an amount of say 0.1% would be more than enough to go and pay for security against pretty much any realistic attacker. 51:11 Maybe 0.01%. 51:12 Not the one we are talking about. It's just a security against fee sniping, but not the one we are talking about. 51:17 The point is, that's the amount of money that's paying to protect against these types of attacks. 51:22 It would be very easy for something like Lightning to come out where individually, 51:25 there's no reason for me to go pay more fees than I have to. 51:28 And my individual payments could be effectively zero of my total value of my Bitcoin. 51:32 And in that scenario, we would be underpaying for security because everyone can just go pay the lowest amount. 51:38 But not just Lightning, even a hodler. A hodler doesn't need fast confirmation. 51:42 Exactly. That is exactly why the amounts we may end up paying due to fees may be much less than something that would be tolerated. 51:49 Communist. You want to tax capitalists in order to subsidize... 51:52 There's nothing wrong with taxing people for security. 51:55 How about the greater good? 51:57 I have an unpopular fact. I want to state an unpopular fact. 52:01 What's that? 52:02 What Peter is referring to as a tax is not a tax. And we talked about this last night. 52:07 I think there's a chance where I'm coming from. 52:10 Mining Bitcoin is not a tax on other people who own Bitcoin. 52:14 Bitcoin miners pay the full price of every Bitcoin they buy. 52:18 They don't get it at a discount like the Fed getting $100 bills for $0.20. 52:23 Like a power company. And the power company doesn't give them Bitcoin back. 52:26 When a miner mines gold, they pay the power companies, truck drivers, employees. 52:30 They pay all these people to produce the gold. 52:32 Miners in Bitcoin are paying their own money to produce the Bitcoin at the price that everybody else is currently paying. 52:39 Which is not like any other thing in the world. 52:41 When the price of something rises, like gold, just a canonical example, the cost of producing it has not risen. 52:50 Those are not related. 52:51 So as the price rises, competition comes in and undercuts each other until that price is brought back down to the production cost. 52:57 Which means instead of your price of gold continuing to stay high, 53:01 it's brought back down through increased people willing to let it go at the cost price. 53:07 Whereas with Bitcoin, a miner pays the current price. 53:11 He's not going to let it go at half that price because that was his cost. 53:15 He has the same demand as existed when he mined it that everybody else had. 53:19 Hang on, let's be clear. 53:20 Government contractors, when they go get my taxpayer dollar, they go and spend all the taxpayer dollar of me, 53:27 of things like their power, their ranch, etc, etc, etc. 53:30 All that money, that's not a tax. 53:32 Those government contractors are paying full value for all that return. 53:36 For me, I should think good that it's not actually a tax. 53:39 The real difference is that if you don't pay mining fees, your transaction is not included, but you're not going to jail, basically. 53:45 In my value, my Bitcoin is still getting diluted. 53:48 Look, I love how I've managed to go get someone like you to go say that inflation isn't actually a tax. 53:54 It's absolutely a tax. It's a tax on savings. 53:56 Monetary inflation with dollars is a tax because the dollars are produced at 20 cents per hundred, 5 cents per one. 54:06 If they were produced at cost, producing them would not be a tax. 54:09 Just like producing cars is not a tax on people who own cars. 54:12 It doesn't matter how much it costs to go and do the accounting thing. 54:16 What matters is the fact that my holdings are now worthless. 54:19 I don't care whether or not the government went and siphoned off the money or didn't. 54:23 If you've ever worked with stock ownership, you realize that creating new stock, that you can create new stock that is non-dilutive. 54:32 That's what we're talking about. 54:34 So you're basically saying that even if it cost $100 to print a $100 bill, you could still print trillions of them and then there would definitely be the people who… 54:42 There would be more of them. 54:43 People who had money under the mattress would be very upset about that and they would have less purchasing power. 54:48 No, that's… 54:49 Because the cost is taken out of my ability to buy things. 54:51 That's the fact that I'm trying to… that is the idea that I'm trying to correct. 54:56 People have conflated supply with the amount in existence. 55:02 And they're not… in economics, they are not the same thing and they… the amount in existence is not what is referred to when we talk about supply and demand. 55:10 Supply is the other… is another demand of another person. 55:14 It's willingness… 55:15 That one sounds unpopular. 55:16 No. 55:17 Yeah. 55:18 This is very unpopular. 55:19 This is very unpopular. 55:20 This is not unpopular. 55:21 Just nerdish. 55:22 Let's get back to popular. 55:23 This is not an opinion. 55:24 I stated what is in every economics textbook. 55:25 Supply is not the amount in existence. 55:28 Karl Menger who developed these ideas. 55:30 Supply and demand are not mentioned in his work. 55:33 There's two demanders. 55:34 It wasn't until Marshall comes along years later and talks about this and then people start conflating a demand function with an amount in existence. 55:43 Look, I don't care what a bunch of economics and ivory towers would ever say. 55:47 The fact of the matter is I have one bitcoin and you are diluting my bitcoin. 55:52 It might go to power but… 55:53 The fact that you're using the term diluting means you are referring to these economic concepts which you just claim to not care about. 56:00 Dilution of that kind does not exist when you issue new stock at a higher price. 56:05 But from a practical point of view, I know the fact that my bitcoin will now go buy less because there's more of them out there. 56:11 I don't care whether… 56:12 That's an assumption which is incorrect. 56:14 I don't think we'll get through this one. 56:17 I mean we've been talking about this for like two days. 56:21 But I do think that is a very interesting thing that I never thought about when people conflate supply with units. 56:28 It's unique to bitcoin which is why people have a hard time getting their heads around it. 56:31 And supply is actually a verb. 56:32 You're supplying something. 56:33 It's not the amount of that thing. 56:36 I think that definitely made me think. 56:38 Matthew Mazincus is aggressively texting me from the crowd. 56:42 He wants me to let everybody know there's $30 trillion in base money. 56:47 You subtract $2 trillion in gold reserves. 56:49 So that's $28 trillion worth of scenery on top of the gold reserves. 56:53 So this equals the cost to the state to attack divided by the attack cost. 56:59 So he's trying to provide us with an equation to try to calculate this cost. 57:04 He's saying that's how much money they'd be willing to spend? 57:06 Yes. 57:07 Well, I think there's some truth to that. 57:09 I think there's some truth to that that it is about the revenues they would lose because of bitcoin's existence. 57:16 So I think that… 57:18 If you do nothing, it goes away. 57:20 We're probably not going to settle any of these. 57:22 Next unpopular opinion. 57:24 Alternative implementations. 57:26 Crazy. 57:28 What do you mean? 57:29 Like bitcoin knots? 57:30 What are we talking about? 57:31 Bitcoin knots. 57:32 Bitcoin first version, second version, third version, fourth version? 57:35 People think we just need one team building. 57:39 There's a new one that comes out every six months or so, right? 57:42 Yeah. 57:43 Well, Satoshi had a well-known opinion that it was not a good idea. 57:46 Second implementation would be a menace to the network, he said. 57:49 But I think we do have new versions. 57:51 The idea of the soft fork was that they would all be mutually compatible with each other. 57:55 But they haven't been. 57:56 To the extent that that is true remains to be 100% proven, but it's sort of working so far. 58:01 It is a necessary evil that we ever release new versions of Bitcoin Core. 58:06 And by releasing code that comes from a completely different code base, you're just making that into an unnecessary evil. 58:14 But there have been, I think the people behind Bitcoin have argued, which is my way of saying I don't want to really defend this too much. 58:22 But I think they said something like when they redid Bitcoin in JavaScript, they found something. 58:27 They fucked up multiple times. 58:28 Yeah, but didn't they find something that was useful to someone else at some point? 58:31 Well, the thing is, so hang on. 58:33 Now we're dealing in opinions. 58:35 Multiple implementations are a good thing. 58:39 Using multiple implementations is a terrible idea. 58:42 And that's the distinction. 58:43 I personally have written an alternative implementation of the Bitcoin Core scripting. 58:48 And in the process I learned a bunch about it. 58:50 That code base at the very top says you are fucking crazy if you ever actually use this. 58:54 Because there's no way it will ever agree with what Bitcoin Core does. 58:58 It's just not going to happen. 59:00 And I know that because I found so many issues with it trying to go develop it. 59:04 Computer science isn't ready for consensus systems where you have two separate code bases and want them to agree. 59:12 We're not going to get there. 59:13 Most of the core guys would say that. 59:15 Unpopular applause. 59:18 But brave. I respect that. 59:21 I mean it should be unpopular. 59:22 It's a failure of computer science. 59:24 But that's just the reality. 59:25 We're much better off having one code base and trying to change as little as possible. 59:29 You can't go wrong in this room because if you're popular, you're popular. 59:31 If you're unpopular, then you nailed it. 59:34 So anything goes, I guess. 59:36 So your point would be that different versions of Bitcoin Core upgrades are different implementations but only slightly diverging. 59:44 So it's less likely to have consensus failure. 59:47 Exactly. 59:48 I've made this argument myself in pull request view. 59:53 Such and such, why are you changing this? 59:55 This is risky for very little gain. 59:57 And changing the entire code base is really risky for very little gain. 1:00:03 But keep in mind where this really matters is what miners use. 1:00:07 Because miners are the ones who go produce blocks and miners are the ones who can go fork the chain. 1:00:11 Now if it's only, say, you're a merchant and you're running your own copy of Bitcoin Core that you modified a bunch of ways. 1:00:19 And it's behind a more stock copy of Bitcoin Core, that's fine. 1:00:23 All that matters is you might go down a bit. 1:00:25 That's really not a big deal. 1:00:27 Are you referring to the July 2015? 1:00:29 What did you say when you said miners fork the chain? 1:00:32 Is that what you mean? 1:00:33 If miners fork the chain, they just lose money. 1:00:36 No, they screw over all of us. 1:00:38 No, the block just gets rejected by everybody and they lost money. 1:00:41 Yeah, but see this is the thing. 1:00:43 But that's not how this works in practice. 1:00:44 No, but you said this before, Peter, because you're like everyone has to run their own node and your full node only protects you and doesn't protect anyone else. 1:00:52 And then the July 2015 thing happened and then you're like, oh, this is so bad. 1:00:57 But really it didn't affect anyone running their own full node in the slightest. 1:01:01 Well, that's not true, though. 1:01:02 Hang on, hang on. 1:01:03 That's not true, though. 1:01:04 So then I was like, eh, I was kind of looking at that. 1:01:06 That is not true. 1:01:07 People who are running a full node making the same type of mistake that miners did to get the chain to fork, they were equally as screwed. 1:01:16 But that's not miners being most important. 1:01:18 That's everybody else being most important. 1:01:20 Miners are just going to lose money if they run some random broken node. 1:01:24 So there's a nuance here. 1:01:25 If only miners are the ones crazy enough to run an alternate implementation, then yes, it doesn't really matter. 1:01:31 But that's not how the world works. 1:01:32 The way the world really works is both miners and users will go make this mistake. 1:01:37 And then that becomes very dangerous. 1:01:39 And we would like users to be able to make this mistake. 1:01:42 So is an insulated Libitcoin possible? 1:01:46 So a consensus library possible? 1:01:48 Is that possible? 1:01:49 Sure. 1:01:50 Yeah. 1:01:51 It's doable. 1:01:52 It's kind of annoying and hard to do. 1:01:53 And also, like, why bother? 1:01:54 Why not just run Bitcoin Core and then put something behind it? 1:01:57 It works fine. 1:01:59 There's so much engineering effort going into this concept. 1:02:03 The difference of performance between Eric's implementation and Core are staggering, right? 1:02:08 The things you tried in the sub-other were, the metrics were... 1:02:12 You've got to understand that most of the node and all the stuff that goes around it, which you can't, the node does nothing of its own. 1:02:18 You need a communication mechanism to the store and all that stuff. 1:02:21 That has nothing to do with consensus, right? 1:02:24 P2P protocol has nothing to do with consensus. 1:02:27 Well, P2P protocol is consensus related. 1:02:29 The querying interface... 1:02:30 2015 beta was a... 1:02:32 You can use carrier pigeons to deliver transactions. 1:02:35 They can take any form you want. 1:02:36 It has nothing to do with consensus. 1:02:38 Consensus is much smaller than the node. 1:02:43 Peer-to-peer, in reality, ends up being consensus because... 1:02:47 Yes, it does. 1:02:48 Because what happens is if you can't get the consensus related data to the other peers, consensus will fail anyway. 1:02:54 But what's strange with the peer-to-peer code is that, unlike the Core consensus, you can layer it. 1:03:00 Say, for example, we have two completely different networking protocols in Bitcoin. 1:03:04 If one of the two fails, nothing happens. 1:03:07 I would argue we've got hundreds of different networking protocols in Bitcoin. 1:03:10 There are a lot of different things out there. 1:03:12 I look at the P2P traffic and there's not one. 1:03:15 But, again, this is why there's a nuance there where P2P is related to consensus, but in an additive way, unlike the Core consensus. 1:03:24 In other words, not consensus critical, which can easily be seen on the network. 1:03:28 No, no. The wallet is not consensus critical because nothing the wallet does is ever going to affect consensus. 1:03:32 So the vast majority of what's in a node is not consensus critical code. 1:03:35 There is very identifiable specific code that's consensus critical, which goes beyond script, which is the lib consensus subset of Core, which is isolated to just script. 1:03:47 There are other checks that happen at the transaction block and chain level, but they can be identified, can be well-documented, can be well-tested. 1:03:55 The database is consensus critical, too. 1:03:58 Sorry? 1:03:59 Remember, the database is consensus critical, too. 1:04:02 If your database does not faithfully reproduce what you put in it, you have a consensus bug. 1:04:10 And when that actually did happen with Core, they fixed the database. 1:04:14 They did not accept the consensus criticality of that error. 1:04:18 They fixed it so that it faithfully reproduced the data that went into it. 1:04:22 Yes, they did. They took several stages and hard forks to get it fixed, but it got fixed. 1:04:28 That did happen. 1:04:30 It did happen. 1:04:31 But at first they went back, though, and they said, we do accept this as a… 1:04:36 We artificially put a constraint on the number of hashes that could exist in a block so that they wouldn't trigger the database limit, and then they went and fixed the database limit, and then they went and removed that restriction. 1:04:47 In the end, the database was fixed. 1:04:49 It did not keep the consensus that actually existed up to that point. 1:04:54 How much time do we have? Because I want to see the cage about Drivechain between Peter and Paul. 1:04:58 I'll do that any time. 1:04:59 I was thinking, why don't we do something about lightning? 1:05:02 Well, I was going to say, we have at least 15 minutes. We have plenty of time. 1:05:07 Peter and I were talking about an uncomfortable truth that people really don't like to acknowledge. 1:05:12 We can do that. 1:05:16 We need to hard fork Bitcoin at one point because of this Unix timestamping bug. 1:05:21 Nobody likes to talk about it. 1:05:22 2032, right? 1:05:24 2032 bug, but… 1:05:25 No, no, no, not 2032. It's much later. 1:05:27 Assigned or unsigned? 1:05:28 The bug is called 2032. 1:05:30 There's a signed and unsigned variant of this bug. 1:05:32 Well, yeah, but so the code, the Bitcoin core code base, so it has a 32-bit unsigned integer in the block header, and that is used for time, and that will roll over in 2106, and at that point, Bitcoin will cease to exist. 1:05:46 There are a couple of that, right? There is a block height, which may have… 1:05:50 But block height is thousands of years in the future. 1:05:53 If it's treated as signed, it rolls over sooner. There's another bit there if it's treated as unsigned. 1:05:58 So I think the unsigned bug is 21-something. 1:06:01 There is one which is closer. 1:06:02 And I'm not sure… 1:06:03 No, there isn't one that's closer. 1:06:04 I don't remember whether the code actually… 1:06:05 Nothing that will stop Bitcoin from operating. 1:06:09 I just don't remember whether the code treats it as signed. 1:06:12 Satoshi used an awful lot of signed integers where they shouldn't have been signed integers. 1:06:16 But the one that actually will make consensus stop is 2106, or whatever the heck the… 1:06:20 That's the later one. 1:06:21 Yeah, but there is an earlier one that will make consensus stop. 1:06:24 So that would be the signed… That would have to be the signed one, which is 2032. 1:06:28 But the consensus doesn't use it as signed integer. 1:06:30 Now, Bitcoiners are mocking us because we don't know about critical consensus bugs. 1:06:34 We are joking. We know what we're talking about. 1:06:37 This is not limited to Bitcoin. This is like a Y2K bug. 1:06:40 It's very much like a Y2K bug, and it exists because the Unix timestamp is limited, and that's it, right? 1:06:47 And we've been fixing this Y2K bug since well before Bitcoin ever existed. 1:06:51 Satoshi doing this was just a complete fuck-up. 1:06:53 Like, there's no reason this should have ever been done this way. 1:06:56 But he saved 32 bits. Otherwise, it would have lasted for the next 10 million years. 1:07:00 I mean, on top of this, the fact the header is hashed directly in the proof-of-work is also crazy. 1:07:05 Why do you say that? 1:07:06 Well, it's crazy because it enables very clever optimization, so we don't want that. 1:07:11 The ASICs boost attack. 1:07:15 You know, Bapu likes miners, so he doesn't consider it an attack. 1:07:19 Yes, I have a very—my view, I've learned, is very different than a lot of people's. 1:07:23 So maybe it's an unpopular view, but I have this very like Nietzschean kind of view towards mining, 1:07:27 that the strong will win and will be protected by the champions of history. 1:07:33 That's crazy. The strong are centralized. 1:07:36 Some people have this thing where it's like we have to make sure that the weakest miners are still in the pool. 1:07:43 Yes, we want all miners to be equal. 1:07:45 Well, what do you define as a strong miner? 1:07:48 We say the strong are centralized. 1:07:50 If they go against the Nietzschean mining thing, then it's got to be against clever mining ideas like reusing natural gas. 1:07:57 I think of my upstream data hash that's mining off-grid on natural gas on a farm that nobody can ever find as the strongest miner in the world. 1:08:05 But hang on a minute. But is that strongest in terms of profitability? 1:08:09 See, the problem we have is, first of all, energy and cooling is inherently decentralized. 1:08:16 The way that physics works, especially with cooling— 1:08:20 But I have to stop you to point out that you're using the word decentralized in a completely different way. 1:08:24 It may also be valid, but it's a completely different way than the way that Satoshi used the concept of Bitcoin as being peer-to-peer, 1:08:31 where each software node has equal status. 1:08:33 Who cares what crazy ideas he had in 2009? 1:08:35 Because he's using this word, and— 1:08:38 But I'm just talking about the fact that you are— 1:08:41 What you mean is that in Euclidean space, the thermodynamics is distributed— 1:08:45 Yes, I mean physically decentralized. 1:08:47 But I'm just pointing out that this is like sometimes— 1:08:49 Because this is sometimes like a trick that people do. 1:08:51 But peer-to-peer— 1:08:52 Hang on. 1:08:53 Peer-to-peer being decentralized. 1:08:55 There are economies of scale in physical mining, not economies of scale. 1:08:58 We were kicking around ASIC boost, and I just want to make a comment about this. 1:09:01 And it kind of, I think, leans towards what Paul was saying. 1:09:04 Somebody's smart enough to figure out some faster way to hash, using the existing rules, by the way, and then patents it. 1:09:10 Why does Bitcoin care about patents? 1:09:13 The whole point is you do what you want. 1:09:15 This is not kowtowing to monopoly controls, which is what patents are. 1:09:20 Bitcoin cares about patents because it's hardware, and that itself is its own form of centralization. 1:09:25 Again, if you want to mine efficiently and it requires you to violate a patent, just like mining illegal transactions, that's what you do. 1:09:32 And you become the strong, and you survive. 1:09:34 But that's very nice, but the world doesn't work that way. 1:09:37 It's not an attack to use the most efficient legal—you know, there's no illegality in Bitcoin. 1:09:41 It's not an attack to use the most efficient— 1:09:43 Yes, it is an attack. 1:09:44 It's an attack against— 1:09:45 To use the most efficient algorithm you can find. 1:09:47 I agree. 1:09:48 And I also have something else to say about ASIC boost that I think is very unpopular, or at least something that I've never been able to understand myself, which is that I thought— 1:09:55 The way it was explained to me was that there was a conflict between SegWit and ASIC boost, and that activating SegWit would turn ASIC boost on. 1:10:02 Well, covert ASIC boost, because overt one was possible without SegWit. 1:10:06 But I don't understand exactly why it was the fact that when SegWit actually activated, nothing happened to the difficulty immediately afterwards. 1:10:14 It's because the covert— 1:10:15 It seems to prove that it had no impact. 1:10:17 But the covert ASIC boost, so the way that worked was the people doing this in secret could go and get money from their mining that they weren't telling other people they could go do, which comes down like commercial contracts between those— 1:10:30 Yeah, but who the heck was making ASIC boost? 1:10:33 And, you know, the people they were selling hashing equipment to. 1:10:36 And, of course, the reason why this didn't change was, if I remember correctly, that they had switched to non-covert ASIC boost at that point. 1:10:46 Yeah, the overt one is still going on in blocks right now. 1:10:49 The covert one was impossible without it. 1:10:51 Why is there such a big controversy about it, you know? 1:10:54 Well, it was controversial because in secret they had an incentive to go screw up SegWit. 1:10:58 They were stealing hash. 1:11:00 They could just switch it from the SegWit screwing up version to the non-SegWit. 1:11:04 When I make my really fast mining code, I'm going to keep it a secret and mine the crap out of it until everybody else figures it out. That's good business. 1:11:10 Yeah, we don't want that. In general, in Bitcoin, we do not want people to be clever. 1:11:13 Bitcoin does not want that, but that's how it works. 1:11:16 Who cares how it works? I want to have a good system. 1:11:18 But we have to establish – we actually want to have this conversation because this is a very – this is a good conversation, but it's liable to go off on many different tangents or whatever. 1:11:26 If you're not going to use the criterion of just the most profitable miner is the healthiest miner and, therefore, we're actually raising the difficulty to its highest value and we're making the 51% attack as expensive as possible. 1:11:40 If you're not using that as your criterion, you should also explain what exactly you're saying that it should – 1:11:47 And if code is not law, right? 1:11:49 Right. 1:11:50 The code allows this. 1:11:51 He's saying something like it has to be in a different continent or something. 1:11:54 Let's do a thought experiment. Let's suppose ASIC boost, rather than being like a 30 or 50 or whatever the heck the percentage was, let's suppose it was a 10 million percent difference. 1:12:04 Quantum mining with Grover algorithms, which is quadratic, quadratic. 1:12:08 Sure, but you know perfectly well that the difficulty would reset and then – 1:12:11 Let's suppose it was some very, very clever thing that cut difficulty by like 10 million. 1:12:16 That would imply some consensus rule that allowed that. 1:12:19 Yeah, but afterwards – 1:12:20 But again, listen, from the point of view of Bitcoiners, would we want to have a system which had a secret 10 million advantage? 1:12:28 We want symmetry. So, every asymmetry in mining is not illegal or immoral. It's just dangerous for the future of attacks. 1:12:35 So, we want to – if we can, we want to minimize asymmetries between miners. 1:12:40 So, I mean, I don't think we're really disagreeing here. We would all like to see people mining on an equal footing. 1:12:46 We would like to see the strong survive for various reasons, but the fact that the code allows these things and people take advantage of them does not make them evil people. 1:12:55 Who cares who are evil? I just don't want them to exist. 1:12:59 Probably we have to distinguish between something which is bad for Bitcoin functionally and something which is morally bad. 1:13:05 I mean, I think we can agree that we would fix this issue, like SegWit took care of the ASIC boost, essentially, and that's a good thing. 1:13:12 But people taking advantage of what the code allows them to do, what the rules allow them to do, is not somebody being evil or keeping it a secret. 1:13:19 It's not somebody being evil, right? That's just good business. 1:13:22 That's a very huge discussion, like Satoshi Dice bloating the chain. Is that evil? 1:13:27 I mean, you are damaging the experience for everybody else, but if somebody can do it, then you can do it. 1:13:32 Or the DAO hacker. Was he a hacker? No, he was just a lawyer because the code is low and the code allows him to take money. 1:13:39 He was a good Samaritan. 1:13:40 He was a good lawyer. 1:13:41 He was a good Samaritan. 1:13:43 I mean, I historically have argued quite strongly things like Satoshi Dice. 1:13:47 We should stop caring about whether or not spamming and think about how do we design a system where this doesn't matter. 1:13:52 But at the same time, we should be clear that we do want mining to be a level playing field. 1:13:58 This is good for Bitcoin because it means mining is more decentralized and there's fewer people that we can go and do things to, to go and make mining... 1:14:07 Yeah, but I don't think this is actually... I think this is not conceived the right way. 1:14:13 I think it's overgeneralization. You want the node to be very easy for everyone to run, and I don't think anyone disagrees with that. 1:14:21 That is the cost of joining the network. That is the cost of getting the view into the... So everyone agrees about that. 1:14:28 But then this view is often reapplied that it should be very, very easy to join the mining world. 1:14:34 I don't know if that makes any sense. I think, first of all, if the miners are at different scales, that still doesn't necessarily mean that small people can't join. 1:14:41 They can just form a little corporation and become part of something. 1:14:44 I mean, what is the ultimate objective? We just want mining to be difficult to take over by the state, which is the whole point of Bitcoin. 1:14:50 Yes, if you want that, though, then every time you sacrifice the efficiency of mining, you're leaving money on the table. 1:14:58 You're just saying it's making the state easier to attack Bitcoin. 1:15:02 And you're doing that because, you know, you feel bad that some person feels left out of the mining or something. 1:15:06 And that just sounds like common sense to me. 1:15:09 Would any of us disagree that we would like reward to be proportional to work? I mean, assuming equal efficiency. 1:15:15 Well, but that's the thing, is people are constantly improving the efficiency. 1:15:19 Right, but aside from somebody's efficiency versus somebody else's because their operations or whatever, 1:15:25 we would like Bitcoin to produce a proportional reward given the amount of work, right? 1:15:31 Let me put it like this. 1:15:32 And it doesn't do that. 1:15:33 Can I put it like this? Like the state, when it attacks, it will choose the maximum efficiency. 1:15:37 Which means the largest mine possible, right? It's going to put it all in one place. 1:15:41 Largest mining is not most efficient. 1:15:43 Sorry? 1:15:44 The largest mining is not most efficient. 1:15:46 The set of mines that are closest together have an advantage. 1:15:48 No, it's not. The state will be the most efficient. 1:15:51 That's why we should also have the defense pick the most efficient. 1:15:55 So first of all, the statement that the largest miner is most efficient, it is not. 1:16:00 I think it's not necessarily. 1:16:01 It fundamentally is not because there are disincentives to scale in mining. 1:16:04 There are many disincentives. 1:16:05 Fundamental physics disincentives. 1:16:07 Largest as in a hash rate collusion, not largest as in the physical facility of a mining block. 1:16:13 Distance between seen blocks, right, makes a difference. 1:16:17 You see as a larger, meaning you're physically closer together. 1:16:21 All other efficiencies you may have versus somebody else's side. 1:16:24 If you're physically closer together, information takes time to travel. 1:16:28 You see your own... 1:16:29 But that's a very small... 1:16:30 Yeah, that's a very, very small... 1:16:32 The cooling disadvantages you get are... 1:16:33 I'm not arguing in orders of magnitude. 1:16:35 I'm just saying that if you're closer together, you see your own blocks before other people see them. 1:16:39 Therefore, you're mining on the new blocks faster. 1:16:41 I agree with that. 1:16:42 This is a well-established principle in Bitcoin. 1:16:43 It is, but I think they now do it... 1:16:45 But it's tiny because we have 10-minute block controls. 1:16:48 That's why it makes very little difference. 1:16:50 I agree with that. 1:16:51 They do the spy mining and SPV mining. 1:16:53 They've done that for many years, so they can find very quickly... 1:16:56 You're talking like less than one second into the 600 seconds... 1:16:59 But in a decentralized world where everybody's more spread out, right, it starts to make a bigger difference 1:17:05 when one miner can put them all together. 1:17:07 That's where it starts to matter. 1:17:09 We don't see it now because you basically have one big... 1:17:12 Everybody's spy mining. 1:17:13 Everybody else giant mines everywhere. 1:17:14 And people don't see orphans. 1:17:16 But when you spread this out and everybody's hiding and mining illegally, you will see a lot of orphans. 1:17:21 No, I don't think we will because they do the spy mining. 1:17:24 Yeah, we still won't because 10 minutes is very big. 1:17:26 Do we think the state is competent to do all this, though? 1:17:29 Well, they will hire people who are, and I wouldn't assume they can't. 1:17:33 I consider it a fatal flaw in anybody's security model to assume the enemy is stupid. 1:17:38 Also, if it's very, very cheap, then we could get any, you know, whatever. 1:17:43 Someone with a visa or someone could do it just to, you know, I don't know why they would... 1:17:47 Also, they don't need to be clever. 1:17:49 They can just outspend us. 1:17:51 Like, you know, if being clever means you're 10% more efficient or you just go and spend, you know, 50% more, 1:17:58 the 50% more guy will go win. 1:18:00 Well, governments around the world are throwing trillions of dollars at this energy crisis, 1:18:04 and it's not going to fix that anytime soon, so... 1:18:06 How much time do we still have? I'm just curious. 1:18:08 Oh, we have like 10 minutes. We should probably... or 5 minutes. 1:18:12 Why is not Carballo on the panel? I mean... 1:18:15 I have a question about how many people here think that the beliefs of the experts in the lightning network world 1:18:24 accurately match the ones, beliefs held by maybe let's call them influencers or the audience or the layperson. 1:18:31 To a certain extent, which is on a scale of 0% to negative 100% or a scale of 100% to whatever you like. 1:18:38 So, if the lightning network... 1:18:39 We're talking like blue mat versus like maybe random guy over there or something, you know. 1:18:44 So, if it was overhyped by experts? 1:18:47 I'm just saying if you think it's... No, I think the experts have a more sober view. 1:18:51 That's actually what I think is the case. 1:18:53 See, lightning is written in C. That's crazy. 1:18:56 Right there, there's a major disconnect between most programmers and like what those experts decided to go do. 1:19:03 Yeah, but that's not what I mean. I mean like, you know, like... 1:19:07 But C is faster than C++. 1:19:09 Rust. 1:19:11 C is faster than everything, isn't it? 1:19:15 What do you think, Giacomo? You got anything for that or no? 1:19:17 You think like everyone understands lightning? 1:19:19 So, I think that the scaling, the block size debate made clear some fundamental limitations of the blockchain design that was not clear for anybody. 1:19:30 It was clear for like Alphine in 2009 immediately, but for most people not until the war, basically. 1:19:36 So, blockchain sucks. They cannot scale. 1:19:39 And I think that this created a lot of awareness about the problem. 1:19:43 The solution, which is lightning, which is removing stuff for the global consensus as a theoretical solution, received a lot of hype and attention because it's the only reasonable solution. 1:19:54 And I think that that kind of hype was justified. 1:19:57 The actual implementation of the most popular off-chain protocol, which is lightning, received a little bit of overhype. 1:20:04 I remember people telling me, we will do one million transactions per second, which will be possible in theory, but it will not be possible for database management of the channel updates. 1:20:14 So, there has been overhype of lightning. 1:20:16 I think it's already self-corrected because we were thinking like lightning will destroy altcoins, lightning will make privacy perfect, lightning will scale. 1:20:27 We already have a self-correction of this over-expectation. 1:20:31 Now, I think the perception is realistic. 1:20:33 Lightning is great for some things, like fast payments, small payments, and network and chain privacy. 1:20:40 Lightning sucks for other things, which is basically large payments, security long-term, and network privacy because you're basically reusing your address all the time. 1:20:51 So, there are trade-offs, and having both is way better than having one. 1:20:55 So, experts were not so wrong in the idea, but we exaggerated with the hype. 1:21:02 We did it with Taproot as well. 1:21:04 I mean, some people were actually expecting something magical happening after Taproot adoption. 1:21:09 Literally nothing happened because it's something we need for the future. 1:21:13 So, there is a risk of overhyping stuff, yes. 1:21:18 Peter, you got anything on that or not? 1:21:20 I'm probably guilty of it sometimes. 1:21:21 Do we have time? 1:21:22 How much time do we have? 1:21:23 I don't know. Max, we have time. 1:21:27 So, Giacomo, the scaling strategy for sidechains is also, as I presented in your very presence in Milan, it has two aspects, one of which I presented in 2016. 1:21:39 It also involves, though, hiding transactions from people and getting them out of the global consensus. 1:21:45 So, I'm just wondering what everyone's giant problem with that is since it's this exact same thing as the Lightning Network. 1:21:50 Because I don't think it gets them out of the global consensus because miners will go find ways to make more money by taking advantage of that. 1:21:56 But, again, it has nothing to do with the miners. 1:21:58 The miners can maybe find an advantage by digging up natural gases. 1:22:02 But miners are the things that we need to be decentralized. 1:22:07 Like, yes, absolutely, it gets out of the global consensus. 1:22:09 But you could make the same argument about SPV. 1:22:11 SPV means all this blockchain stuff gets out of the global consensus. 1:22:14 You don't have to pay attention to it. 1:22:16 Yeah, but I don't agree that miners' costs have anything to do with really anything at all. 1:22:22 Because, first of all, if you care about miners' costs, then what you should do is you should get rid of all the upward difficulty adjustments. 1:22:27 Sorry, now we're talking mostly about blind. 1:22:30 No, this is where there's a big difference between marginal costs and overhead costs. 1:22:34 We're okay with marginal costs, but overhead costs are very dangerous. 1:22:37 Because it makes it much harder to go set up a new pool. 1:22:39 Yeah, but that doesn't make any sense either, Peter. 1:22:41 Because the overhead costs of running these nodes, these sidechain nodes, that theoretically they could have any cost. 1:22:47 But in practice, the network won't exist unless regular full-node people can run them. 1:22:52 Like a 0% miner can run them, basically. 1:22:55 And that means it's many, many orders of magnitude smaller than what it would even cost to set up a normal mining operation. 1:23:02 So let's move from merge mining to actually hashrate escrow, which is the main contention about Drivechains. 1:23:08 So I think that Drivechains are an example of off-chain evolution that I think is positive overall. 1:23:14 But the main concern people have about Drivechains is that miners right now have one kind of political power. 1:23:20 Which is censoring and colluding with double spends. 1:23:24 If you include a successful Drivechain in the model, now they have an additional political power. 1:23:29 And you cannot stop people from running Drivechain code. 1:23:33 But if I have to choose a world where they have an additional political power, I may be less concerned if they haven't. 1:23:38 But this is a case where the political power that they have is provisional and given to them by the user. 1:23:44 So it's no different than if the user sold their Bitcoin and bought Solana or something. 1:23:48 If you're not using any of the BIP300 sidechains, then the miners do not have any additional power whatsoever of any kind. 1:23:55 And if you do opt in, then that's a risk the user has chosen to take. 1:24:01 And it's no different than if they joined a blockchain. 1:24:03 I get screwed over because now being a miner is harder to go do. 1:24:07 And thus we're centralizing mining. 1:24:09 Just adding choices to mining makes it harder to go do. 1:24:12 Wait, I have a question I wanted to ask yesterday when you and John were up here talking about this. 1:24:16 Does this add an MEV aspect to mining? 1:24:20 No. 1:24:21 Does that perturb incentives? 1:24:23 It's possible to make any mistake you like on the sidechain. 1:24:27 So the sidechain could have MEV. 1:24:29 The way it's designed is that all the drama goes in one direction. 1:24:33 So if the mainchain reorgs, then everything above it would have to reorg. 1:24:37 But the reverse is not the case. 1:24:39 So if a sidechain has MEV and it's being reorged all the time because it's badly designed stuff up for grabs up there, 1:24:46 then someone who's just running Bitcoin Core today will not even notice. 1:24:51 So the answer is no. 1:24:53 Yeah, that's another unpopular opinion. 1:24:55 MEV is actually good for chain security. 1:24:58 Complexity is bad. 1:24:59 Complexity is very bad. 1:25:01 Ideally, in a hypothetical world where everything was perfect, 1:25:05 miners would not see transactions. 1:25:07 They would just see a bunch of encrypted data and they'd have no clue what it was, 1:25:10 they'd have no way to extract value out of it. 1:25:12 They would just magically get money, and that would be that. 1:25:14 Yeah, but I don't know why you say that, though. 1:25:17 Because part of what the blockchain is doing is purging the contradictory double spends. 1:25:23 But I'm saying in a perfect world where we could have the magical crypto to make this possible... 1:25:29 Yeah, but if I can do it, then the miners can also do it, right? 1:25:31 If I'm going to look into the blockchain and see if there's double spends there, 1:25:34 then the miners have to be able to do it. 1:25:36 I think I missed my point. 1:25:37 If we had the cryptography to encrypt transactions and somehow prevent double spends even there, 1:25:42 I'm not saying it's possible. 1:25:44 I'm just saying if we had that world, that would be categorically better than what we have right now, 1:25:49 which is where miners can go see what transactions do. 1:25:51 We do not want miners to have any influence in transactions other than, 1:25:54 yeah, I created a block, and I got a bit of money, and that was that. 1:25:57 In the client-side validation model, they will not see the content, 1:26:00 assuming they're not colluded with it. 1:26:02 So if I pass you off-chain the content of the transaction, they only see the single-use seals. 1:26:06 Yeah, yeah. 1:26:07 I mean, this is why I came up with stuff like single-use seals. 1:26:10 In RGV, they have no idea what they're doing. 1:26:12 You still need to pay the transaction fee to the miner in something that they understand. 1:26:15 That's the only thing. 1:26:16 You pay a fee to publish some data. 1:26:18 There's this idea that, again, if the user—like you believe, both of you over there, you two jokers over there, 1:26:24 you believe that people have the right to sell their Bitcoin for fiat if they choose, right? 1:26:29 And they can spend their Bitcoin on goods and services? 1:26:31 No, they're not allowed to sell their Bitcoin for fiat. 1:26:33 They're only allowed to hodl. 1:26:35 Okay. 1:26:36 But, you know, they're the owner. 1:26:38 So what I'm saying is they should be allowed to pay into this script 1:26:41 where they have an additional vulnerability, if that's true. 1:26:45 Nobody's arguing against any user doing anything with code. 1:26:49 They can use shitcoin, change Bitcoin. 1:26:52 The problem is what I hope will be widespread or not, 1:26:58 and how I can influence that by speaking up about one option and the other. 1:27:02 We will never initiate violence about shitcoiners or drive-chainers. 1:27:07 But you understand the point, though. 1:27:09 The analogy is that they can deposit coins into this BIP300 Drivechain or whatever you want to call it. 1:27:16 The user—they're the owner. 1:27:19 They can do whatever. 1:27:20 They can destroy the coin so they can do it. 1:27:22 Only the people who have opted in have this additional— 1:27:26 The other thing we have to point out is that this same vulnerability— 1:27:29 you could make the same argument about the Lightning Network. 1:27:31 You could say this gives miners an extra power. 1:27:33 Miners can— 1:27:34 But I would make that argument. 1:27:37 I think the fact that Lightning creates a system where miners could potentially go screw over 1:27:42 a huge number of users is dangerous. 1:27:44 I would love to see somehow for Lightning to get rid of that. 1:27:47 And it's also way different because it's local. 1:27:48 Miners have to collude with a single peer. 1:27:50 But I think it's much worse for that reason. 1:27:52 Don't you agree or no? 1:27:53 In a Drivechain, it's public, so they can just do something very visible. 1:27:57 In Lightning, they have to collude with one peer to screw up the other. 1:28:00 So it's way more localized. 1:28:01 Well, there's a little bit of prep, but the fact that it's localized, 1:28:04 it's kind of like, I don't know, maybe— 1:28:06 The fact that it's localized means that it's very difficult for anyone to get 1:28:10 some maybe what you might call sympathy. 1:28:12 Like you'd go to Twitter and you could say, 1:28:15 miners stole all the money out of my Lightning channel. 1:28:18 But people would be like, I don't know if they're telling the truth. 1:28:21 So you want something more like— 1:28:23 Remember the strength in numbers? 1:28:25 You want something more where it's like if you attack this thing, 1:28:29 it attacks the whole group. 1:28:31 In the case of miners screwed over my Lightning channel, 1:28:34 that's a relatively easy thing to go prove, 1:28:36 because you can go show that there was a transaction 1:28:38 that should have achieved some states in the Lightning channel 1:28:40 that never went through entirely. 1:28:41 But not necessarily, though, because you can show the transaction, 1:28:44 but you don't know when it was revealed in the past. 1:28:46 You have to ironically hash it a different way, timestamp it, 1:28:49 and then hope that people understand that. 1:28:51 Realistically, the fact that it showed up in a whole bunch of block explorers 1:28:54 and everyone could have seen it, and then finally the timeline gets reached 1:28:58 even though it wasn't mined, 1:28:59 that's more than enough evidence in practice. 1:29:01 But I don't know if it would be persuasive to a huge group of people. 1:29:05 If this happens, you will see it on Twitter in real time, 1:29:08 and millions of people will know this is happening as it's happening. 1:29:11 There will be plenty of people seeing this 1:29:14 and plenty of people angry that, oh shit, Bitcoin just broke. 1:29:17 This is our Bitcoin conversation. 1:29:19 We're arguing how to solve these problems over Twitter. 1:29:22 But I just want to make one observation in terms of privacy good. 1:29:28 No information being exposed to miners or others on the chain is good. 1:29:32 But keep in mind the threat is presumably able to compel transparency. 1:29:40 So if you want to regulate all your white market miners and demand 1:29:44 that they get KYC information for any transaction that's mined 1:29:49 or they go to jail, that's not hard to do. 1:29:52 And that's already kind of being done and will probably continue. 1:29:56 So you can't really use technology to solve that problem. 1:30:00 That's a great point. 1:30:02 You cannot fix blacklists fundamentally because you just turned them into whitelists. 1:30:06 Even if you use Monero and you say Monero has ring signatures 1:30:09 and confidential transactions still, 1:30:11 somebody could tell you that they're not allowed to accept your Monero transaction 1:30:17 unless you provide them off-band your membership in the ring signature or whatever. 1:30:22 I can't agree with that. 1:30:24 In practice, politics isn't that simple. 1:30:26 In theory, you can always just ban Bitcoin altogether. 1:30:30 In practice, politics isn't that simple. 1:30:32 Politics is a complex thing. 1:30:34 We're being able to do certain – a good example being, 1:30:37 in theory, governments would just go to the ASIC manufacturers of the world 1:30:41 and say, all right, no more Bitcoin mining equipment, end of story. 1:30:44 We will now do a 50% attack and we'll just kill Bitcoin, that's that. 1:30:48 Arguments that politics is hard is the status quo. 1:30:51 If politics could secure Bitcoin, we wouldn't need Bitcoin. 1:30:54 We'd just use the dollar. We'd vote for what we wanted. 1:30:56 We'd get what we wanted. 1:30:58 So Twitter-based arguments and politics is hard, 1:31:01 these are to me antithetical to Bitcoin. 1:31:05 When anybody argues Bitcoin is secure because it would be very hard for politicians to do this, 1:31:11 people would rise up. 1:31:13 I go, well, why didn't we rise up against the dollar and the euro? 1:31:15 We don't. 1:31:16 So Bitcoin is a way for individuals to – 1:31:18 But we do. We created Bitcoin. 1:31:20 We're rising up against the dollar and the euro. 1:31:22 Exactly. 1:31:23 And reverting Bitcoin's security model to, it's politically hard so they won't do it, 1:31:28 is a break in that design. 1:31:30 But that is what Bitcoin's security model is at some level. 1:31:34 Yes, because if you're in North Korea, 1:31:37 you're not allowed to stand in front of a computer without being arrested. 1:31:40 There is no cypherpunk ideal that can save you. 1:31:42 So some level of political evaluation, 1:31:46 political possibility evaluation is needed even in Bitcoin. 1:31:50 You can minimize it a lot. 1:31:52 I would call hiding from the state political. 1:31:55 In a different world, we wouldn't even have access to general purpose computing. 1:31:59 It would have been very easy for the evolution of computing to be that you could not get a compiler. 1:32:05 Let's say we should not count on the fact that politicians will not attack Bitcoin, 1:32:09 like my current policy. 1:32:11 Or that voters won't vote for it because we apparently have voted for the dollar that we have 1:32:15 or the euro that we have. 1:32:16 So there's some smaller group of people out there that don't want to rely on the political system 1:32:21 to secure their money because it hasn't worked yet. 1:32:23 And so Bitcoin is allowing those people to opt out if they have the ability to hide from it. 1:32:27 That's it. 1:32:28 And anytime there's an argument that reverts back to, 1:32:31 well, we need to vote for this, we need to stop this politically, 1:32:35 I'm like, why bother with that? 1:32:37 That is unrelated to Bitcoin. 1:32:39 This is like Satoshi's unpopular opinion. 1:32:41 When everybody was hyped about WikiLeaks accepting Bitcoin, 1:32:44 Satoshi went all unpopular and said, 1:32:46 no, please don't because you're kicking the hornet's nest, it's too soon. 1:32:49 So there is some level in which maybe you don't want political acceptance 1:32:54 as the ultimate security because it's not, 1:32:57 but you want it maybe temporarily in order to grow enough. 1:33:00 Take whatever you can get, but don't base your security model on it. 1:33:04 Yeah, sure. 1:33:05 Well, I mean, you would like not to base your security model on it, 1:33:07 but you don't necessarily have a choice. 1:33:09 And again, we do not have a choice to rely on 1:33:12 general purpose computing availability 1:33:14 and also currently with proof of work function ASICs. 1:33:17 And we have some ways to play games around this, 1:33:19 like if they went to the intels of the world and said, 1:33:22 all right, no more mining ASICs, 1:33:23 we'd probably fall back on the general purpose computing capability. 1:33:26 And these are the problems we work on. 1:33:28 In general, the stronger computing technology is 1:33:31 and the better bandwidth is around the world, 1:33:34 that's all better for us. 1:33:36 Gentlemen, we could keep going for hours, 1:33:39 but this has been fascinating. 1:33:40 So you know why? 1:33:41 Because we cannot block each other on stage, only on Twitter. 1:33:46 I'm blocked. 1:33:47 All right. 1:33:48 I mean, I'm sure we will continue this conversation after. 1:33:51 This is, I think, a rare occurrence. 1:33:53 I think this is the only time I've been on a panel 1:33:54 where somebody on the panel hasn't had me blocked. 1:33:58 I don't have you blocked. 1:34:00 I'm not blocked by any of you either, I don't think. 1:34:02 He blocked me and I blocked him back. 1:34:04 I don't even know why. 1:34:05 I was going to message you about Peter Todd's article 1:34:07 and then I was like, he blocked me, 1:34:08 and then I was like, I'm blocking him. 1:34:09 That's the second time I've blocked you. 1:34:10 Are we going to unblock each other after this or no? 1:34:12 I guess so. 1:34:13 Maybe, yes. 1:34:14 I mean, the panels are, we are sweet people at the end. 1:34:17 It's much better to have these conversations in person. 1:34:20 Much more. 1:34:21 I don't know if this was productive at all, 1:34:22 but it was definitely fun. 1:34:25 Guys, Max is going to come up here, 1:34:27 give some closing remarks. 1:34:28 Thank you for listening to our debate. 1:34:30 Thank you. 1:34:35 Thank you. 1:34:49 Guys, I wanted to thank all of you for being here 1:34:54 and I hope you enjoyed this year's Honey Badger. 1:34:58 I want to specifically thank our amazing MCs, 1:35:03 Bitcoin Stage. 1:35:10 And also Luna for Sat Stage. 1:35:13 There he is. 1:35:18 I want to thank all the speakers for coming here 1:35:22 and devoting their time, sharing ideas and thoughts. 1:35:25 I want to thank our security team, catering team, 1:35:30 video, sound team and venue team. 1:35:32 And of course, I want to thank hodl hodl team 1:35:34 and volunteers for doing this amazing weekend for you. 1:35:39 They deserve that, honestly. 1:35:46 And I actually would love to thank, 1:35:50 a huge thank for a person who actually did 99% of the job. 1:35:57 She hasn't been sleeping for a week, Anna. 1:36:02 Yeah, she's like, she's somewhere there, but yeah. 1:36:09 Basically, this year's Honey Badger happened because of her. 1:36:14 And one more time, please, applause for her. 1:36:17 Thank you. 1:36:24 Guys, thank you. 1:36:25 You've been amazing. 1:36:26 We did our best to match your expectations. 1:36:29 We're all Satoshi. 1:36:30 Thank you. 1:36:47 Thank you.