0:00 So yeah, I just like have some examples of that. 0:08 I talked about this Futarki in 2018, the top center there. 0:15 And that went on to become like now Polymarket is very big, and this is very big in Solana, 0:19 where they have this Futarki DAO, it's like $75 million, and Polymarket did $1.5 billion 0:25 in trading. 0:27 And then I talked about this MEV type of topic in 2019. 0:32 I called it sidechain leeching back then. 0:35 And now we just had a whole thing about that. 0:37 But I did actually completely solve that problem back in January 2017. 0:43 And even earlier, in fact. 0:45 But I guess some people are still unconvinced. 0:48 And then I did talk about Drivechain at TabConf in 2021. 0:52 And then I did the debate with Peter Todd last year. 0:57 Now, there are a lot of altcoin versions of that that were very bad, or they just became 1:02 some kind of scam or something. 1:04 But there is a decent one in Ethereum called Eigenlayer, and it just raised $100 million 1:11 from A16z. 1:13 So with all that in mind, I'm going to today talk about soft forks. 1:16 And this is going to build off of some very much earlier work that I did in the past, 1:21 and the talk I did at MIT last year. 1:27 And so here's the agenda, which is that the intro. 1:29 We're done with that. 1:30 I kind of really like that Q&A. 1:31 So I think maybe one of these 10-minute ones, I'll cut way short, and then maybe there'll 1:35 be 20 minutes of Q&A at the end. 1:37 But then I'm going to talk about some basics and some more advanced things, a lot about 1:41 the history of the soft fork. 1:43 And then I will talk about this thing, CUSF, the Core Untouched Soft Fork, which is like 1:49 a new kind of a new thing, and then Q&A. 1:53 So before that, though, I have this one slide about me. 1:56 And I'm the author of BIP300/301. 1:59 Those are collectively known as Drivechain. 2:01 I run a technical Bitcoin blog called Truthcoin.info. 2:06 And I'm also the founder and CEO of LayerTwo Labs. 2:09 And I did not ask them to put the sign here, but here it is. 2:12 It's very nice looking. 2:14 So that was created December 2022. 2:17 But we have already produced the following pieces of software. 2:21 We have our own test net. 2:22 We have the CUSF enforcer for not only BIP300, 301, but also for OP_CAT, in case anyone 2:29 cares. 2:30 Oops, sorry about that. 2:31 Changed the style. 2:32 And we have a sidechain L2 that emulates Zcash, which is like a million times better than 2:37 CoinJoin for privacy. 2:40 We have an L2 that emulates Ethereum called EthSide, basically just Ethereum on Bitcoin. 2:45 That would be Matt Corral's worst nightmare, except that it has Blind Merged Mining. 2:48 So the L1 miners would never even see it. 2:51 They'd just see that they're getting more money, and they don't really care why. 2:56 We have a version of Namecoin on Bitcoin called BitNames, and we have L2 for token and token 3:01 trading called BitAssets. 3:03 And then we have a set of large block sidechains that could scale to 8 billion users tomorrow 3:08 that I call Thunder as a kind of joke. 3:11 And I also have a new GUI for Bitcoin Core, because I really don't like the existing GUI. 3:15 So that's the intro. 3:19 And I do have a lot of strong opinions. 3:21 I'm well known for this. 3:22 I'm always pulled onto the unpopular opinions panel for things. 3:25 But I do think that all these things on the right are basically a distraction and a waste 3:28 of time distracting from Bitcoin's mission to take over the world. 3:33 And Lightning, Ardcoin, CoinJoin, DLCs, Bitcoin Core itself, I think that they are a waste 3:38 of time. 3:39 Sorry about that. 3:40 OK. 3:41 So now I'm going to review some basics of the soft fork. 3:46 I don't know why the lights keep moving up and down. 3:48 It seems very ominous. 3:53 This is how powerful the soft fork is. 3:54 It can bend light in hue and color. 4:00 OK. 4:02 So yeah, these are some basics. 4:03 You probably already know this. 4:05 But actually what's up here is not perfectly accurate, as we will see. 4:08 But it is the conventional wisdom, so it is a great starting point. 4:13 The conventional wisdom is that the soft fork tightens the rules, and the hard fork loosens 4:18 the rules. 4:19 But that is not completely true. 4:22 Guys, what are you doing over there? 4:25 I would seriously like to know. 4:36 Yeah. 4:39 OK. 4:42 All right, great. 4:45 OK. 4:48 Yeah, so that's the conventional wisdom. 4:49 But you see there's a second competing definition, which 4:52 is that there's an optional discretionary upgrade 4:55 versus an immediate and mandatory upgrade. 5:00 And those two are kind of in conflict with each other, 5:02 actually, as we'll see. 5:05 So these are some famous soft forks. 5:06 So in August 2010, Satoshi took a bunch 5:09 of messages that you could previously broadcast in Bitcoin. 5:12 And he banned all these so that they would no longer 5:14 be acceptable in the blockchain. 5:16 And that tightened the rules, as you can see. 5:21 And it's also the case that regular users who 5:23 didn't upgrade could just upgrade later 5:24 whenever they wanted to. 5:25 So it satisfies both bullet points. 5:30 And then September 2010, Satoshi added the infamous block size 5:34 limit of one megabyte. 5:36 He's shrinking the block size, tightens the rules. 5:41 That would be a soft fork, and then 5:44 increasing the block size of the hard fork, 5:47 loosening the rules. 5:48 I have these examples at the bottom, 5:53 which are the infamous attempted hard forks, all of which 5:56 failed. 6:00 The block size limit increased. 6:01 That was a big drama. 6:02 SegWit2x, and then BCH, which became its own community. 6:07 So this is the basics. 6:10 And now I'm going to bring up four things that I think 6:12 are really not widely known. 6:14 And they get to the heart of what the soft fork is. 6:16 And this is a very important issue, 6:18 because I've got a couple of slides in where this is a very, 6:21 I'll come back to this in a second. 6:22 But this is a hotly debated issue. 6:24 It's like, what is a soft fork? 6:25 Both people disagree on whether or not something 6:27 counts as a soft fork or not. 6:29 But they also disagree as the core essence. 6:31 So this is Adam Back and Luke Dashjr. disagreeing. 6:35 But I'll get back to that in a second. 6:37 So yeah, so Gavin called these, for those of you 6:42 who don't know, Gavin sort of, Satoshi kind of handed 6:45 the reins to Gavin, kind of. 6:48 And he was like the sort of leader for a little while 6:51 in 2010. 6:52 And Gavin wrote this in 2012. 6:56 He used the word changes. 6:57 So he said, there are soft rule changes 6:59 and there are hard rule changes. 7:01 And the point of this is that he says, when he says, 7:07 at this point, he's saying something like, 7:09 at this point, it is much more difficult or impossible 7:11 to roll out hard changes. 7:13 And when he says, at this point, he's 7:15 talking about June 29, 2012. 7:19 And so that was quite a long time ago. 7:23 And ironically, Gavin would later attempt himself 7:26 to do the hard fork block size increase change. 7:30 And he would fail exactly the way 7:31 that he predicted that he would. 7:34 So that was ironic. 7:35 But what I want to convey here is 7:37 that something is forbidden on the grounds of impracticality. 7:40 It's almost like the software can't do it, 7:42 the laws of physics don't permit it, or whatever. 7:44 So money has these network effects 7:45 and people don't want to split. 7:47 So this is going to be a very important idea. 7:49 Now, first I have this. 7:52 This is the second of the four things 7:53 that people don't really consider, 7:55 which is that when people say hard and soft fork, 7:59 we actually aren't really referring to a visual fork 8:02 at all, which is very strange. 8:03 These are normal culinary fork, tuning fork, fork in the road. 8:08 But actually, when there's a soft fork, 8:11 there really is no split. 8:13 It's just like the purple just becomes blue or whatever 8:15 and there is no red part. 8:17 And even when the community upgrades via hard fork, 8:21 they abandon the old network 8:22 and so there isn't a fork in that sense either. 8:25 So this is something of a puzzle in the sense of like, 8:29 why does it have the word fork? 8:33 Given that there is no visual fork 8:35 and that is what I'm going to explain. 8:37 I have actually tracked it down. 8:39 There's a very satisfying answer to that question. 8:41 You would think, what is going on? 8:43 But this is the first ever usage of the term soft fork 8:47 that I could find. 8:48 I looked really hard. 8:50 And this is five months after Gavin's remark 8:52 about hard and soft changes. 8:55 So this is, where did the word fork come from? 8:57 This person gave a whole, like a giant post 9:01 on all these terms. 9:03 And this is where hard and soft fork are in. 9:05 And so I'll just read this at you. 9:09 But it's quite interesting. 9:12 But again, I forgot I've had this slide in here about, 9:15 this is something where people really disagree. 9:18 So maybe in the Q&A, people will come forward and say, 9:22 that's not what a soft fork is or whatever. 9:23 But these are the original, 9:26 the definitions I'm about to give you are the earliest. 9:29 They are the only ones that are logically consistent 9:31 in my point of view. 9:32 But more important than either of those two things, 9:36 I'm going to explain what problem it is 9:38 these words were invented to solve. 9:41 And so in that way, they are fundamental. 9:46 And so here we go. 9:47 I'm just gonna read these, but you know. 9:49 Okay, quote, when there are a sufficient number 9:52 of Bitcoin clients on the network that disagree 9:55 on the rules about how blocks are created 9:57 and recorded in the blockchain, 9:58 it leads to a split in the chain. 10:01 One set of clients falls one branch 10:02 and another set falls the other 10:06 This is the important part. 10:07 To fix hard fork, some action must be taken by us. 10:12 And then I got orphan blocks in here, it's important. 10:14 When a soft fork or a hard fork occurs, 10:17 the blockchain is split into two paths. 10:21 One of these paths will eventually be considered 10:23 the valid one and the other will be invalid chain. 10:28 Blocks that are an invalid chain are called orphan blocks. 10:32 And then soft fork, you see at the end, it says, 10:36 these kinds of forks will solve themselves 10:38 without any intervention from us. 10:40 So this is actually the heart and soul of the matter 10:43 that when the network splits, 10:44 this is not like a benign feature or even intended feature 10:48 like with a fork in the road, fork splits, 10:51 that was the whole point all along. 10:53 But when the blockchain splits, 10:55 this is a problem to be solved. 10:56 This is an undesirable state and it must be addressed. 11:01 So we want the network to be tightly synchronized. 11:03 We don't want any orphan blocks. 11:05 We want zero orphan blocks basically. 11:08 So the forking is a problem. 11:12 The hard fork and the soft fork, 11:13 they are both problems to be solved. 11:16 The hard fork is a hard problem 11:17 because we have to do something about it. 11:19 The soft fork actually is not a big problem. 11:21 We don't have to do anything about it. 11:23 It will actually work itself out automatically. 11:27 So that's why fork is kind of a good word. 11:29 After all, if you keep in mind that fork equals problem. 11:34 And now, I'm gonna, the very next slide has an example. 11:37 So if this is too abstract, 11:38 I will have a very concrete example soon. 11:40 But this is the logic, is that soft fork resolves itself. 11:47 And so when you upgrade via soft fork, 11:49 you either, the whole blockchain, 100% of it, 11:52 no orphan blocks, whatever, 11:53 the whole thing will collapse either in the direction 11:55 where everyone can safely use the new feature, 12:00 or it will collapse the other way, 12:02 where the new feature is just broken for everyone 12:04 and the soft fork never activates. 12:06 But no matter what happens, there will not be any splitting. 12:10 So the soft fork means that it won't, 12:12 the split, any splitting will solve itself automatically. 12:16 And ideally, like immediately, 12:17 so there will only ever be like maybe one candidate block 12:21 and it will never actually be a real split. 12:24 And hence the heart and soul of the soft fork, 12:26 which is that, as before with Gavin's comment 12:30 about the changes in 2012, 12:31 it's too difficult to get everyone to upgrade. 12:33 But if we just have a few people 12:35 plus 50% of hash rate to upgrade, 12:38 then we can deploy the feature 12:40 in like an optional consensual way. 12:43 So the feature goes from being 0% safe to 100% safe 12:47 as soon as 51% of miners upgrade. 12:51 And on top of that, with hash rate signaling, 12:55 anyone can learn the exact date that a feature activates 12:58 so they know when it has become safe. 13:00 So this is very, very useful, 13:02 especially when paired with the op-nops that Satoshi put in. 13:04 And so this is my example. 13:07 The example is check-lock-time-verify. 13:11 I did the debate with Peter last year. 13:15 And of course, I have a lot of disagreements with Peter, 13:17 but I do have to give it to him. 13:18 He wrote this BIP and the text is, 13:20 this is so short and clear that this is great. 13:23 And you can ignore the bullet points. 13:24 They're not important, but I'm gonna explain. 13:27 Check-lock-time-verify redefines op-nop2 or nop2. 13:32 When executed, if any of these conditions are true, 13:36 the script interpreter will terminate with an error. 13:40 Blah, blah, blah, forget about that. 13:42 And then otherwise, script execution will continue 13:44 as if a nop had been executed. 13:46 So for these nops, 13:47 the default behavior is to allow the transaction. 13:50 The transaction was always allowed. 13:52 It was always valid. 13:53 Even years before check-lock-time-verify was thought up, 13:57 the op-nop2 is always valid. 13:59 And what happens is you add new conditions 14:02 that trigger suddenly being invalid, invalidating the block. 14:06 And so this is maybe a little counterintuitive, 14:08 but hopefully that explains some of it a little bit. 14:12 So those are a little bit more. 14:14 This is a part that I think I might cut short 14:15 because I think the questions may be, 14:17 I had so much fun asking the questions last time. 14:20 But I'll just try to go through this. 14:22 Softworks are intimately related 14:24 to how the protocol evolves over time. 14:25 So I had some slides about this from the MIT talk, 14:28 so I just kept them in here. 14:30 This is like, what does governance mean? 14:32 I think no one knows. 14:33 But my point is that the existing definition 14:37 definitely doesn't work 14:38 because Bitcoin doesn't have governed people. 14:40 Everyone's peer-to-peer in Bitcoin. 14:43 So I say this definition sucks. 14:46 And then I say that actually, 14:48 the only thing that makes sense in Bitcoin 14:50 is how do I find out what the node software is? 14:55 And then it's actually a peer-to-peer definition again, 14:58 because now we're all trying to figure out 15:00 how do I get the Bitcoin node software 15:02 and how do we tell Bitcoin nodes from non-nodes? 15:05 Of course, a lot of the stuff with the block size 15:07 were kind of hinged on this, 15:08 like is this the real Bitcoin 15:09 or does this count as Bitcoin even though such and such? 15:13 So this is this definition I came up with 15:16 and I call it node constructor theory. 15:18 And I think it's quite an interesting question. 15:21 And I do, this is something that I think I'll still explain, 15:24 which is that there are three different, 15:27 mostly three different strategies about this. 15:31 Luke Dashjr. and also Mike Kern, 15:34 who was coincidentally mentioned before. 15:36 I didn't plan on that. 15:37 But as well as Satoshi at first, 15:41 they thought you must be a participant in the community 15:44 and you must run the latest version. 15:47 Although everyone started to, 15:48 except for Luke Dashjr., 15:50 who still really believes in this. 15:52 But a lot of other people have abandoned this. 15:53 And in particular, Satoshi removed this thing op-ver, 15:57 which is very neat. 15:58 So Mike Kern just thinks like you, 16:01 here's this line, you're the decider, 16:05 from this very interesting post 16:06 that he wrote back in the day. 16:10 The op-ver thing pushed the version number to the stack. 16:13 So it actually resulted in the network forking 16:16 every time a new version of the software came out, 16:18 but it was never used. 16:20 But Satoshi, what I want to bring up is that 16:23 Satoshi put it in and then he quietly removed it, 16:25 because I think he realized that this was a terrible idea. 16:29 And then this second one has a very interesting story. 16:32 The second thing is like, 16:33 you just run the old version of the software. 16:37 And you just say the old version works. 16:39 If it's not broke, don't fix it. 16:41 So never upgrade. 16:43 And this is very, very old. 16:45 There's this guy, Mircea Popescu, who ran this place. 16:49 He possibly is dead, he possibly faked his own death. 16:51 He's definitely qualified to fake his own death. 16:54 So we'll never know. 16:56 He is one of the most interesting people in the whole world, 16:59 and also completely crazy. 17:00 But they ran this version of Bitcoin, 0.5.4, 17:03 and they told everyone else to run it as well, 17:05 and he had a great sense of humor. 17:07 Copyright, whatever, you do not have, 17:09 nor can you ever acquire the right 17:11 to use, copy, or distribute this software. 17:14 Should you use this software for any purpose, 17:16 you are breaking the laws of blah, blah, blah. 17:17 So he's quite a character. 17:19 But this is actually sort of the Michael Saylor view today. 17:22 So this has actually come full circle. 17:24 And this is even the complaint about Mev view, 17:26 and the hall monitor view, 17:28 that we have to be very, very, very conservative. 17:31 Meanwhile, everyone around us is making whatever, 17:34 that's not gonna hold back any altcoin community. 17:36 They're gonna push whatever version of the software 17:38 they think is best. 17:39 But we will have to go really, really, really slowly, 17:44 and be very deferential to the old version. 17:47 This third point of view was really my point of view, 17:49 and I really thought it was most people's point of view. 17:52 I may have been mistaken about that. 17:54 But definitely after 2017, and after the block size war, 17:57 it has fallen relatively, 18:00 and the second one gained a lot of ground. 18:02 But the third one is this idea that, 18:06 as long as you have a line of compatible protocols, 18:08 it kind of doesn't matter which one you use, 18:10 and so you can just use whichever one you like. 18:12 And this emphasizes consent of people. 18:17 Now I had a big thing about the relative 18:20 costs and benefits of this, 18:21 but I think that it's actually not as important 18:23 as the next stuff that I wanna talk about. 18:25 And so I'll come back to it if there are no questions. 18:28 But you can see, I'll just go to where the table 18:30 is completely filled out. 18:33 And so they have some advantages and disadvantages. 18:39 The second one, for better or worse, 18:41 is currently in vogue, 18:42 and that one has the disadvantage 18:44 that it does not easily allow for innovation. 18:48 And so if we don't innovate and other people do, 18:50 then we would be losing ground, 18:53 potentially being replaced at some point. 18:57 Oh, one thing that I should point out, though, 18:58 is that it's not super great. 19:02 The third one isn't perfect, 19:03 because if two people try to soft fork at the same time 19:08 with different little incompatible soft forks, 19:11 then that actually does become a hard fork, 19:13 and so that is not great. 19:14 But there is a way of improving on that, 19:16 which is to do all these things 19:17 on the sidechains themselves, 19:19 or in layers, or using this Qsift thing 19:21 that I will talk about at the end of the talk. 19:23 And this gives you the best of all the different worlds. 19:26 You can do any kind of innovation you want, 19:28 and everything is separated, 19:30 so that if one thing doesn't work, 19:33 then that's not a big deal, 19:36 so then we have rapid experimentation, 19:38 and so that promotes error correction. 19:40 But then since nothing is, 19:42 in the stack of layers, nothing is mandatory. 19:45 So you can just stay on whatever layers you've been using, 19:48 and just wait to trust them more. 19:51 Now I'm gonna skip, yeah, I'll skip ahead to this part, 19:53 which is good. 19:54 So this is soft forks over time. 19:56 I took this list from BitMEX. 19:58 I would make my own, but it's inherently, 20:00 as I've tried to explain, 20:02 it's actually quite a controversial subject. 20:04 So I have decided to take BitMEX's table, 20:08 and then I have re-tabled it like this. 20:11 And here I have put the first eight years 20:15 of Bitcoin's history on the top row, 20:17 and then the next eight years, 20:20 closing out in 2024 there, at the bottom. 20:27 So as you can see, in the past, 20:30 it's kind of hard to tell, 20:31 but this is BitMEX's list. 20:33 So I just took it from them. 20:35 We averaged about two soft forks a year, 20:38 and we never really went more than 12 months 20:41 without doing at least one. 20:43 But in the second, the lower period, 20:45 we have only done two total. 20:48 And I've also taken, as you can see, 20:50 I took the liberty of tracking down 20:51 when each was coded, first announced, 20:53 coded, and then activated. 20:56 And as you can see, SegWit took 20 months 20:59 from when it was first announced at scaling two. 21:01 Oh, is this a beeping sound? 21:03 Oh, sorry. 21:04 Okay, great. 21:07 Yeah, so that took 20 months, 21:08 and then Taproot took 46 months. 21:10 So it's been slowing down, 21:13 and if you extrapolate, 21:14 then the next one will have taken nine years 21:16 from when it was first announced 21:18 to when it actually activates. 21:20 So then the question is, 21:22 what's the problem, or is there a problem? 21:25 I think certainly there is a problem. 21:27 For me, it actually skips, 21:29 I mean, a lot of people don't think this is a problem, 21:31 and they think this is great. 21:32 They say, we don't want Bitcoin to change. 21:34 But you see, this quite misunderstands 21:36 why the soft fork was invented in the first place, 21:38 which is that the old protocol 21:40 does not have to change at all. 21:42 So soft forks are not a mandatory change, 21:44 since the old software works in the original conception. 21:48 So let's just skip to the third bullet point, 21:51 which is, since that's the case, 21:53 since it's a voluntary consensual update 21:55 that people do in their own time, 21:57 there really can't be any costs to the soft fork, 22:01 since it is optional. 22:04 On top of that, they're actually reversible. 22:06 So although it's bad if two different people 22:09 use opnop6 for different things, 22:12 what you could do is have someone claim opnop6, 22:16 use it for something, 22:17 then we all decide as a community this is terrible, 22:20 and then have, just as Satoshi did originally 22:22 at the beginning of the talk, 22:23 you can just ban opnop6, 22:25 and now you have deleted, 22:26 you've created something via soft fork, 22:28 and then via a second soft fork you have deleted it. 22:32 But the third sub-bullet point here I have 22:34 is that they are inevitable, 22:35 because if the soft fork makes money for miners, 22:39 they can just unilaterally activate the soft fork. 22:42 I don't know how, if people will trust 22:43 that they really will stick to the soft fork, 22:46 but one would think that if this actually 22:50 is something that makes money for miners, 22:52 they will just do it, 22:55 and then there's nothing that people can do about it. 22:56 I think some people have some extremely interesting, 22:58 suspicious views about if you can resist a soft fork 23:04 that is done by miners, 23:05 but if all of those types of things 23:08 rely on an end user voluntarily rejecting 23:11 the heaviest valid chain rule, 23:12 and so actually all of those things are, 23:14 paradoxically, those things are hard forks, 23:16 those people will hard fork off 23:18 onto a network that has less hash rates, 23:21 so they will be the only ones on their network, 23:23 and anyone who does nothing will be on the, 23:26 which is exactly the point. 23:29 So I do think that the soft fork is a good thing, 23:31 and I also think it is inevitable, 23:32 so we should kind of, I don't know, 23:34 make our peace with it or something, 23:35 or learn how to do it the right way. 23:38 As was alluded to earlier today numerous times, 23:41 the second bullet point, 23:42 we have the potential for enormous benefits 23:44 via the soft fork. 23:46 So they, we want, I think this is something 23:49 that one gentleman made about, 23:52 we want the software to improve. 23:53 The more the software improves, 23:56 the better Bitcoin is, the more competitive it is, 23:58 more users, more happiness. 24:02 Things that we like today, Multisig and Lightning, 24:04 they were created by soft fork. 24:07 OpVault, I would love OpVault, 24:09 because OpVault is like, if you have a ton of money, 24:12 a ton of Bitcoin, and people come to your house 24:14 and they want to torture you 24:17 and get you to give up your private key, 24:20 I don't want to be tortured. 24:21 So I like OpVault, because OpVault is like, 24:24 you can only, you can set it up 24:25 so that you can only take a small amount of money 24:27 at a time, and this is a deterrent, you know. 24:30 This is a deterrent from, if you can't. 24:33 So we don't, what we really don't want 24:35 is a situation where thieves steal, 24:37 they torture people and they get a lot of money. 24:39 Then they're gonna be thinking, 24:40 oh, we should make a list of people, 24:41 we should keep this going and keep torturing people. 24:43 So we don't want that, so why can't we get OpVault? 24:45 I don't know. 24:47 Okay, finally, this is my new thing. 24:49 I have this this year. 24:51 This is a Core Untouched Soft Fork. 24:55 You could also call it the ordinalization of soft forks 24:57 or the sidechainization of soft forks. 25:01 I have this little paper about it on this little site, BIP300CUSF.com, so you can read the paper if you want, but basically the idea is to leave Bitcoin Core untouched. 25:13 The key is, what problem does CUSF solve? Well, actually, the Bitcoin Core merge process is the source of the slowdown, where something like ordinals just launches. 25:24 So the idea is, actually, you can do that with soft forks. You have a second piece of software. It takes blocks from Bitcoin Core and just gives them a second pass, and if it finds any rule breaking, it's exactly like, okay, I'll come to this in a second, but if it finds any rule breaking, it just has Bitcoin Core call and validate block on that block, and then it achieves the same thing. 25:47 So if you can remember back to the black slide where I had check-lock-time-verify from Peter Todd, and you had the op-nop-2, and the script interpreter will throw an error if any of these conditions are met, that would be like the red thing, which is the old ways at the top there. 26:03 The old way is the red thing, the script interpreter, will fail the block if soft fork rules are broken, and the new way is that you have the orange rectangles are the same. 26:17 It's just the same thing, but you add a red thing, a new server, a new software daemon or whatever, and that thing will just call, well, that will ask your local version of Bitcoin Core to call and validate block if it detects any. 26:34 So it has the exact same effect. 26:35 It's kind of a neat way of teaching people what the soft fork is anyway. 26:38 It's just invalidate block if something happens. 26:42 It's very inefficient from the computer's point of view because it's twice as much work. 26:46 You have to scan through the whole block twice, but it actually is better at the human level because these things are all separable now, and now everyone can just do whatever they want, and even though this is almost exactly like what was happening before, this is much easier to do. 27:02 It has a long list of advantages, so I think. 27:05 I would just kind of blur through them quickly, but I'm not really. 27:09 I'll just give this one this part here, which is that. 27:13 Well, I think maybe it's better if people just read. Hopefully, people can tell, like the one simple one is that the new soft fork activator thing can be written in any programming language, and it can have any style, and it can be in any idiosyncratic way, so some one random guy can just do that in an independent way. 27:35 So there's no need to talk to other people or have the pull request get merged. 27:41 And then one thing I wanted to mention is that the bottom of this one here, the lowest row. 27:47 The principle of the whether or not miners activate is just whether or not they make more money, so then this becomes sort of this is sort of almost the way the inverse of the MEV talk where I'm saying the miners will write software and then run it in order to get more money, and this is not only inevitable, but perfectly safe because they will eventually. 28:07 There's no way that you can have something that's a blockchain unless it's like open source node software, so anyway, that's just like there's kind of a little bit more to it than that, but I did want to try to. This is all exists already, and you can download this if you go to the site. 28:21 Bit300accusives.com you can download this. We have it for OP_CAT and for BIP300, 301. 28:30 And I think this is easy way of restoring the soft fork to its former glory that it lost. 28:37 As a result of just pointless drama during the scaling war so. 28:42 OK, I got I got like maybe slightly faster than I thought so. 28:48 All good questions Paul so want to give a big round of applause for Paul. 28:53 Thank you. 28:56 Alright, here's our first question. 28:58 So yes, invalidate block prevents any other blocks from being mined on top of it so. 29:05 If someone invalidates one block and the miners go on then they may be on the situation where no miners are building on the chain that they believe exists. 29:16 Yes, it must be done. It must be the case that no one invalidates any blocks until 51 majority hash rate is is running the activator thing. 29:26 So otherwise it will not work, and in fact it may just cause miners to lose money, but they'll just invalidate their own. I'll shoot their own block in the head and then that for no reason so that will not work so if I understand the invalidate logic also includes coordination logic with other people running the activator. 29:45 That's that's the part I missed. 29:48 Yes, and in fact I didn't I don't think I haven't written that into the code yet so, but that is that must be a part of it. 29:56 Yes. 29:57 That's right. 29:59 You cannot just it would be very what would be very interesting is if you could just if we were in a situation where like someone with 5% of the hash rate could like. 30:07 Only activate soft fork and get the benefits from it kind of like a privatized improvement, but then we wouldn't have any problems at all because nothing would be everything would just be privatized raise your hand if you have a question and I will bring you the mic. 30:22 Yeah, hey Paul thanks for the talk. 30:25 One of just maybe pushing back on one thing you said it there was a slide where you mentioned that if. 30:32 That it's technically a hard fork if somebody tries to reject a soft fork, but I would I would say that it's not it's it's more like the situation that we just described where somebody is trying to do a soft fork, but there aren't enough miners. 30:51 To you know kind of build on them, so they end up just kind of halting there's a fork there's a chain split, but there's not it's not a hard fork my point of view is that the software doesn't really start until 51% of miners are in. 31:06 So I have like maybe I don't know everyone has their own definitions or something, but to me what I'm referring to in this bullet point the second one in the little set. 31:17 I'm referring to a case where there is 51% of the hash rate upgrades and then some people say I will never allow anything that uses up not five I reject that blockchain. 31:29 Yes, people will they have added a rule they have this is the paradox of the soft fork they have tightened the rules from their point of view. 31:38 But in practice. 31:40 They will be on they have the same effect as if they were running Bitcoin cash or something because they will only be on the same network with other people. So this is the paradox. I think it maybe does go in a circle if you it is a chain split. It's just it's not a hard fork. I would say I don't have no miners at all, then there would never be more blocks. Hypothetically. Yeah, it does depend on sort of nuanced. I think yeah. 32:05 Um, I also had a question about your 32:10 One of your last slides where you're saying that the accuser software. It requires validating the block twice. And I wonder if you think that this would slow down mining to any material degree such that you know miners would be hesitant to run the software because they don't want to be slower than other miners weren't validating blocks twice. 32:34 That's a good question. If it if I don't think so. First of all, but the second of all, I think that even if it did that would not fundamentally make it that's not that that's not that specific to this to the soft fork in general or any particular soft fork because like any other thing. It's just their business decision to make a cost benefit analysis and say we could make this much money or at this percent risk. So even like a sick boost was that you probably remember. 33:04 That was like much faster, but it had like something. I don't remember exactly like 12% of the time it would. It would make an erroneous block or something, but it was so much faster that I don't know the exact details, but it was something like that. There was a cost benefit. 33:17 Involved the reason why I definitely don't think it would is that imagine that you just if the when they refresh that if they refresh the template like every five seconds or something. They just they stick with a template that's that's perfectly good and then the new transactions stream in to the mining pool or whatever they assemble the block. They run the block through each first through Bitcoin core. They have the mempool that is in Bitcoin core and then the activator the activator. 33:47 Will flag the any invalid ones is requiring a fee of 21 million coins, which they will never have so so that's happening somewhere else. So it's just when they refresh the template. So they refresh the template every 10 seconds or something. It's very, very, very, very, very, very unlikely that that would be. 34:04 Paul, can you help me understand on this page that you've got up there? How does the CUSF actually make the transaction fail? 34:31 What was the question? How does it actually want well on your on your map or on your graph there? You've got the bit 119 activator. How does this actually make the transaction fail? 34:42 I didn't I didn't hear it quite again, but is it? How did it? How does the? 34:47 Oh, there is actually a there are actually many ways, but there is an RPC in Bitcoin. That's since been hidden, but it's still there called invalidate block that just you curse a block and it's as if it and it's actually very important one because during various times of crisis like in 2015. 35:04 2015 had to be used for some reason, but it is very you can just curse it, but even if that weren't there, you could do any. 35:17 The way of implementing CUSF doesn't it kind of doesn't matter what form it takes, but this is by far the most convenient form. There's already an RPC. You just do invalidate block and then the block hash and then it will. The software will treat that as if it broke a consensus rule. 35:31 So that has been in every version of Bitcoin for a very long time. 35:35 Although it is now hidden, it's one of the infamous hidden RPCs. You learn to hear first everyone. There are secret RPCs that are not. They don't show up and help, but they're still there. So look at them up there very interesting. 35:46 Could you talk a little bit about the history of activation methods for soft forks and do you have like a preferred activation method? Yes, OK, that's a very, very good question. And this is also a thing that people are like really, really, really. 36:00 Passionate about and they are very. 36:06 OK, yeah, alright. 36:10 So yeah, there were these things. Bip 9 was this old one. So historically there was an idea that. 36:17 OK, what I really need to stress is that historically there was no controversy about soft forks. 36:23 This started with SegWit because of the way SegWit activated and I can go into enormous detail on that. But basically, actually, it's probably worth reviewing because SegWit was there was this block size dispute. 36:38 And then in 2015 there was these two scaling conferences, scaling 1 and 2 and then scaling 3, which is where I was talking about with Matt Corral before. Scaling 3 was much, much longer time had elapsed. 36:47 So at the end of scaling 2 people had promised like lightning is the way to go and SegWit is the best way to get lightning. And then someone said that I don't know who this person was. 36:55 Someone said SegWit will be ready by April 1st or something, which you should never do in software. 36:59 And so it wasn't ready by April 1st at all, but then people started to get really stressed out in 2016. It was a very stressful year. 37:08 Scaling 3, SegWit still hadn't activated and so it had been coded. So people were very annoyed, or at least some of the people who had come to scaling 3 including some miners, some Chinese miners. 37:23 They thought that there would be more tangible progress or something on this. 37:32 So one of them went, they looked at the program, the schedule, and the whole first day didn't have anything. It only had one thing about scaling. It was about privacy or something. 37:42 So this one irate person flew back to China and switched. They had 9% of the hash rate, which they switched to mine this thing, Bitcoin Unlimited, which is a long story. 37:54 But the reason I bring this up is there used to be this 95% threshold limit. So people are constantly shipping new versions of Bitcoin Core, new versions coming out. 38:04 And it used to just be when 95% of the miners are running, when you upgrade to this, you put a little flag in the version bits and everyone can tell that you have updated. 38:17 And then when that gets to 95, then there's like a two-week grace period for any straggling miners to upgrade and then it's locked in. And then if you do not enforce the rule, you are kicked off the network. 38:30 And then Luke has a completely different point of view. His view is that to involve the miners at all is like giving them hostages or something. 38:38 Now, I want to crack open something a little new about this. I don't think a lot of people talk about this, this idea of toxic limbo, which I think is extremely important. 38:47 This is why, and this is a huge difference between, you might think, where am I going with this? 38:53 But, you know, America and the UK have this first-past-the-post voting system and the continental Europe has this proportional representation, which is these things are as different as chalk and cheese. 39:04 They are completely different. And one is better because it does not produce toxic limbo. 39:11 And what on earth am I talking about this? 39:14 Originally, it was 95 and then it was dropped to 90 for a speedy trial that happened recently. 39:21 Now, the problem with anything other than 51, there are multiple problems, actually. I don't even want to get into them all. 39:27 But there's one huge problem with, if the threshold is 51 percent, then you have a logical situation. 39:34 But if you have anything else, you have an illogical situation. 39:37 And so the problem with 90 percent is that two different coalitions of 11 percent can emerge. 39:43 And now the problem is totally unsolvable because maybe these two people want different things. 39:48 No one, there's no way of satisfying both. 39:52 And even the people who are now, whatever that would be, 88 or whatever, the 88, they know that it will never actually, excuse me, 78. 40:02 They know that it will never actually succeed. So they can just keep signaling. 40:06 So the whole thing is in gridlock and you don't know to whom your grievance should be addressed. 40:11 If it's 51, then everyone has to take a side. 40:14 And you know, some people, OK, we've only convinced 10 percent so far. 40:17 So we haven't convinced, and then 90 percent are unconvinced. 40:21 And so this is a terrible situation to be in. 40:27 And this is an issue, my view is that actually most of the problems in Bitcoin today were caused by this detail. 40:35 You think it's a tiny detail. 40:37 And I just have to stress that in the past, the soft fork was not controversial. 40:41 And that was why it had the 95 percent threshold, because it was just as a courtesy, we'll wait for everyone to upgrade. 40:51 But when it becomes like a governance thing, now it is a like a poker chip or something. 40:57 And now that one guy, I don't even think that person knew what they were doing. 41:01 They were just upset. And that one guy switched, diverted his 9 percent of his hash to something that wasn't Bitcoin Core. 41:06 At the same time that they were working on the hackathon after scaling three to ship SegWit. 41:11 So I think that this actually caused the whole scaling war. 41:14 The miners didn't even realize that they could veto soft forks. 41:17 They didn't even think of it. I don't even think that was on their mind. 41:19 So I think that most of the problems today that we have, because the software isn't as good as it could be, 41:25 supporting privacy, scalability, and these other things, more competition, more development, more focus on users. 41:31 I believe that actually a lot of those problems are caused by this 90 percent number. 41:37 So, but yeah, there is BIP-9 was the old thing, which is the miners will activate at some point. 41:43 Then there was this lock-in true or false things. I don't know. I hate to keep rambling on about this. 41:48 Okay, we'll have one last question over here. 41:52 Yeah, I can't really follow why the 51 percent would be better than the 90 percent. 41:58 Because you would still have a 94 percent chain that might be longer than the 51 percent chain for a long time, 42:09 which would lead to pretty deep forks potentially and can affect all users which have not upgraded to the new rules 42:17 and potentially lead to double spend attacks or just a lot of chaos. 42:21 Well, I think that type of premise in the question relies on like, okay, there's a lot of statistical. 42:28 If it was actually split 51-49, then there is some statistical noise in there. 42:33 And so it's not a guarantee that the 51 percent will be further. 42:38 So I completely agree with that. And in fact, in practice, 51 percent is not, because of the noise, it's not realistic. 42:45 And so I would actually accept that as a critique, that this is like a platonic ideal is 51 percent or 50.0001. 42:56 But I think that's only because of the noise, that is not because of the principle of the matter, 43:02 that actually there is no one to, you don't know what to do to solve the problem when the threshold is higher than 50 percent. 43:09 So I think it's really 50 percent plus a buffer, a margin of error to account for the noise. 43:17 I agree that actually firing the gun as soon as it's 50.0001 is actually not what you would want to do in practice 43:26 because you would not want to actually maybe mismeasure because there's a lot of luck involved. 43:31 You wouldn't want to mismeasure how much hashrate support something had and that would not be good. 43:35 So I would agree with that. 43:36 All right, thanks everyone. 43:39 Appreciate it. 43:41 Paul, a big round of applause for Paul. 43:43 Thank you guys.