0:00 Okay, so Ricardo asked me to give this talk, and he's like, yeah, come to this blockchain 0:08 panel, and I was like, I don't know about that, and he's like, no, it's beyond the hype. 0:13 It's beyond the hype. 0:14 It's blockchain beyond the hype. 0:15 And I was like, oh, okay, that sounds fun, I think I can do that. 0:18 So I'm going to talk about this problem and why it's so much harder here, and the subtitle 0:22 here, I'm going to read it to you, is Honest Reporting in Peer-to-Peer Networks When Everyone 0:26 Has an Incentive to Lie, and You Don't Even Know How Many People There Really Are. 0:30 So it's a really hard problem to solve, and it's a really important problem. 0:35 But what I thought I would do to go beyond the hype is try to contrast how easy this 0:40 problem would be if you just didn't have to use a blockchain. 0:43 It would be very easy. 0:45 But instead, we have something that's really, really hard. 0:48 And so the goal is really to draw the contrast as clearly as possible, and I have this little 0:54 paper airplane ship thing going because I'm going to try to talk about maybe aerospace 1:00 engineering in some sense, and maybe people will be able to follow it, maybe they won't. 1:05 But the point is just to draw as much of a contrast as possible between the two modes 1:09 so that it's really clear how different blockchain is from other things, because it's very, very, 1:14 very different in my point of view. 1:17 And so the overview here is that I'm going to try and give you the thesis straight off, 1:22 then I'm going to introduce what this problem is in some detail, and then I'm going to talk 1:26 about kind of the history of trying to solve this problem and how people have failed in 1:30 very complicated ways that did not involve a lot of computer science, and that instead 1:34 involved things like economics. 1:38 So here are kind of the takeaways that I'm hoping that people will get, which is that 1:42 blockchain means that you, it doesn't mean that there is less trust, but the security 1:46 model in blockchain is that everyone is a threat and you cannot trust anyone, which 1:50 is like a high bar. 1:52 So that means everything is way more difficult here than it would normally be. 1:57 And the second thing is something that I really liked, Peter Todd emphasized it in his talk, 2:01 and even I think Elaine and a couple other people mentioned it, which is that there's 2:07 a developer or someone who wants to write software for people, usually wants to enable 2:11 the user to do more things. 2:14 And Peter Todd gave the example of Photoshop, and he's like, you add new layers or colors 2:18 or something and that's a new thing you want your user to be able to do. 2:21 But contracts are about allowing people to like opt into a contract and then the contract 2:26 constrains them so they can do less. 2:28 So if you sign a contract with your employer, instead of being able to do whatever he wants 2:31 with his money, he has to give some of it to you every month or every hour or whatever. 2:35 And so contracts are about making things impossible, which is very opposite and quite different. 2:41 And in particular, the Oracle is going to, I'm going to point out these examples where 2:44 the Oracle fails for things that the user, actions that the user are allowed to take. 2:51 And I'm going to say that in the blockchain world, code is built on a foundation of incentives. 2:56 But before we can talk about that, we have to talk about what this problem is. 2:59 And it has nothing to do with the Oracle Corporation. 3:02 It is this issue of the blockchain not inherently knowing any information about the real world. 3:08 It only knows what people bring to it and submit in to the blockchain system. 3:13 So I have an unhappy Bitcoin there and it's thinking about what it's own exchange rate is. 3:18 But it doesn't know anything about that because it doesn't inherently know anything about 3:21 US dollars or in this case, British pounds. 3:25 And we know that it's around 1,000 British pounds for Bitcoin today, but there's no way 3:30 that the blockchain itself can know this problem. 3:33 And because in general, the more abstract something is in this space, the more dishonest 3:39 its contributors tend to be, I'm going to try to make this very concrete and not abstract 3:44 at all. 3:45 And I'm going to say that we're going to use this one example almost the entire time, which 3:48 is that two people are going to bet or at least some number of people are going to be 3:53 betting on Brexit. 3:54 And much earlier in the past, before Brexit happens, we're going to have Arthur and Beatrix 3:59 who disagree over what will happen in the future. 4:04 And Arthur says that Britain is going to remain and Beatrix says leave and Arthur offers 4:10 to bet 500 and Beatrix says fine. 4:14 And so in the real world, they would just kind of maybe settle up in human or something 4:18 like they would just, they know each other personally and their reputation would suffer 4:21 or something like that. 4:22 But the issue here is that we want to automate this process with a computer and replace it 4:26 and make it so that it doesn't depend on individual people knowing each other and people can just 4:31 meet on the internet and do this. 4:33 So now, later on in the present, we know that the outcome was leave. 4:38 And in order to automate this process, we're going to have them put some money in a box 4:41 and then that box is going to have to open. 4:43 To be very, very, very concrete about this, the Oracle problem is that we want to be able 4:48 to guarantee that the box is worth whatever under condition A and whatever other thing, 4:55 so Y, X and Y, under different conditions. 4:57 So given conditions A has to be worth X, given conditions B has to be worth Y and the crucial 5:03 thing is we want to make that guarantee at all times but particularly when they're putting 5:08 the money in. 5:09 So we don't want to like, you know, the guarantee has to be something that they can rely on 5:15 when they're putting the money in the box. 5:16 So we need some kind of magical box that only opens and gives the money to Arthur in one 5:20 case and only opens and gives the money to Beatrix in a different case and doesn't do 5:24 anything else and we can't expect to do anything else. 5:27 So I'm going to talk a little, one slide about why we should solve this problem and this 5:31 is a screenshot from Gavin Andreessen who when he wrote this blog post was the chief 5:35 scientist of the Bitcoin Foundation and he is talking about something kind of complicated 5:42 but I'm just going to read to you this highlighted part which is that he says, all the really 5:45 interesting complex contracts I can think of require data from outside the blockchain 5:50 like the Bitcoin US dollar exchange rate on some future date for blockchain enforced futures 5:54 contracts and that data from outside, that is the Oracle problem that I'm referring to 6:00 and I want to be totally clear about exactly what this problem is so you get a better idea 6:05 of kind of what we're talking about here. 6:09 And as was mentioned, we don't want to like bother courts or any kind of humans with this. 6:15 We want to the extent that humans are involved at all, we want to be able to expect them 6:19 to be as lazy and selfish and anonymous as possible and so ideally, they wouldn't be 6:24 involved one bit but they're going to have to be involved a little bit. 6:28 But why solve this problem? 6:29 I mean, we're talking like lots of applications in finance, insurance, even Internet of Things, 6:34 you want to like, if a car is supposed to pick you up, the blockchain needs to know 6:37 somehow if the car actually did come or if anything actually did happen. 6:42 So this world of information is very important. 6:44 And in the non-blockchain world, it would be very, very, very easy because you would 6:47 just dial out to some place and ask them. 6:51 And this is some random thing I found on Google Images but apparently, this is some free service 6:55 that OCRs images and gives you JSON of whatever the text is in those images. 7:01 And that's not really relevant, you know, just in an abstract sense, you could dial 7:05 out to Google and ask them about the result for Brexit or you could compare search results 7:10 or something like that and you could ask someone, you could compare Twitter amounts or any kind 7:16 of metric that you could use by just dialing out to someone else. 7:21 But we're not going to be able to do that in the blockchain world and I'm going to explain 7:23 why, which is that the blockchain has features that prevent that from happening. 7:29 So the good thing about the blockchain is that it's very automatic and it's immune to 7:33 tampering and it's very resistant to censorship. 7:36 It's the miners who control which messages get in usually don't have any context about 7:42 those messages at all. 7:44 They only know the fee that they're getting paid and like the kilobytes of the message 7:47 so they have a very clear incentive to just include whatever. 7:51 They only remove messages that are spam basically. 7:57 And that's very good for our guarantee because it's so simple and ironclad that it's easy 8:02 to, this is the only system in which you could even make such a guarantee. 8:06 But the bad news is that there are no inherent identities on the blockchain, there's certainly 8:09 none that are programmed in from the beginning. 8:12 And every user must be able to validate the entire history, it's like an engineering requirement, 8:17 it's just difficult. 8:19 And everyone participating needs to be able to have some way of coming to total consensus 8:23 and a unique valid history down to the very last byte. 8:26 It has to be exactly the same, they have to get identical hash function results. 8:32 So the reason we cannot just dial out to someone else is that it's possible for you to dial 8:40 out today and understand what's happening today but it's not possible for you to do 8:44 that yesterday. 8:45 So I'm going to go into a little bit of detail on this point, which is that this is from 8:50 Satoshi's white paper and I'm just going to read some parts, which are that the longest 8:54 chain not only serves as proof of the sequence of events witnessed. 8:58 So what the blockchain is doing is proving a sequence of events that have been witnessed. 9:02 And if you're going to download the blockchain for yourself, you are going to need to re-download 9:07 everything and yourself verify that you have the same sequence of events as everyone else. 9:13 But not only do you need the same sequence as everyone else, there can't be any messages 9:19 in the sequence that break the rules. 9:22 And I'm going to go into that in like two minutes but let me read this next part, which 9:27 is that the longest proof of work chain has proof of what happened while they were gone. 9:32 So people are going to be leaving and joining this network, they're not going to be totally 9:34 synchronized. 9:35 They may need to leave their computer for some reason or their computer could catch 9:39 on fire or something and they need to redo some of this. 9:42 It won't be very synchronized and we're going to need to have proof of everything that happened. 9:48 And I think I explained this a little bit better on this other slide. 9:50 So you need to have the, you need to be able to verify the entire history at all times. 9:54 So not just when the history is being written. 9:57 So you can prove what Google said today. 10:00 You just Google it yourself today and you check that what you got matches whatever someone 10:06 else says that the answer is. 10:08 And so then you can verify that that is the case. 10:10 But what you can't do is prove what Google said yesterday because you'd have to time 10:14 travel to yesterday in order to Google it then and verify it back then. 10:18 So if we're talking something that is like going to be operating for many, a long time 10:25 in the future, people will join the network in the future and they will need to verify 10:31 everything that's been happening over the time since the network began, since they joined 10:36 it and they can't do any of those things. 10:40 And there are some other issues with just kind of trusting Google for this which are 10:43 that some people, depending on where they are located in the world or what time of day 10:46 or if they're signed in or something, they may not get exactly the same results which 10:52 we have to get down to the exact byte. 10:54 They have to be exactly the same. 10:57 And I have kind of asked yous up here the, I'm going to, I think so on this next slide 11:02 I'm going to point out that Satoshi planned the Bitcoin network to be unalterable for 11:09 like a hundred years. 11:10 So I have this quote from Satoshi which didn't fit so I broke it into two but I'm going to 11:15 read just the first sentence of it to you which is that, the nature of Bitcoin is such 11:18 that once version 0.1 was released, the core design was set in stone for the rest of its 11:23 lifetime. 11:25 And on the right I have when he actually announced version 0.1, so I have exactly what he was 11:29 talking about. 11:30 So on the right is the thing that he's talking about that cannot be changed and is set in 11:34 stone for the rest of its lifetime. 11:36 And he announces a number of things there but one of the things he announces in particular 11:39 is the circulation of the coins which will be distributed to network nodes when they 11:44 make blocks with the amount cut in half every four years and the final year of this plan 11:49 is the year 2140. 11:51 So this post does explain how Bitcoin can be extended and improved over time and indeed 11:57 it has been upgraded a lot since June 17th, 2010. 12:02 But the core design is set in stone and this is a big contrast to something like anything. 12:09 I mean like we're talking like Corda, Hyperledger or even modern day things that are relatively 12:14 blockchain like such as Ethereum which hard for and even Monero, Ricardo who introduced 12:20 me his project, they will, they plan to reset the network every six months like manually 12:26 but that's not what Satoshi did. 12:28 He turned it, when he turned it on January 1st, excuse me, January 9th, 2009, it actually 12:35 has not been substantially changed since then. 12:38 There has been one change that was snuck through as the, it's a quirk but that was snuck through 12:43 a long time ago and it's not very relevant at all. 12:45 In fact, you don't actually need to upgrade for that change to protect you. 12:50 But the point is that this network is very, it's designed to be resistant so that you 12:56 can make guarantees of this kind with the box because we want people to be maybe betting 13:01 on something that might happen a long time in the future and if the network is going 13:05 to be changed sometime between now and then, there's no principle on which to base an assertion 13:11 that we won't change what opens the box when we change everything else. 13:15 So the only good change is no change. 13:18 And so that's the Oracle problem which is that you want to guarantee that this box opens 13:21 the right way, pays out the money to the right people. 13:24 And that's what I'm going to try to limit this to for maximum clarity and minimal abstraction. 13:30 And now I'm going to talk about people who tried to solve this problem and really didn't 13:33 succeed at all. 13:35 So as I hinted at before, the entire network history of all the messages received or sent 13:41 by anyone that was going to be in this consensus set, it must be totally self-contained. 13:48 So you can't dial out to someone else that's kind of cheating or just kind of punting the 13:51 problem away. 13:52 But in addition to being, it's kind of a cheating thing, there's no way for people to verify 13:56 that you did it the right way themselves. 13:58 So everything has to be self-contained and we'll need people to report in on how they 14:02 did this. 14:04 And people have tried or they conjectured a number of different ways of kind of doing 14:08 this. 14:10 And the first way is that there's something called multi-signature where you have one 14:14 third party who can be like a, sort of like a lawyer or do like a kind of an escrow arrangement 14:19 where you and your counterparty will, like Arthur and Beatrix will meet with someone 14:25 and they'll say, okay, we're going to settle this up ourselves. 14:29 And if you have any two people agreeing, then it's fine. 14:32 So if Arthur decides that he lost or he won, I don't even remember how I set the example 14:38 up but it doesn't matter if they, Alex and Arthur and Beatrix decide that they won, they 14:43 can each sign and that's two of the required three. 14:46 But if they get into some kind of dispute and the winner says I won and the loser says 14:49 no you didn't win, they can go to a third person and the third person will be the tie-breaking 14:53 vote. 14:54 And I'll talk about that in the next slide. 14:56 But people then, that kind of wasn't working at all, no one was using that for anything 15:00 interesting. 15:01 And so they moved on to this idea of competing reporters and I'm going to talk about that. 15:06 And that also didn't really work and I kind of foresaw that it wouldn't work. 15:10 And at around the same time, I proposed something which is my project, the Bitcoin Hivemind, 15:16 which is sort of like this much more complicated version but it's basically a pseudo-corporation 15:21 that slowly resolves these outcomes. 15:24 But I also inspired a kind of Ethereum-based version of this which doesn't work for reasons 15:32 that are very complicated. 15:33 So I'm going to try to get through those reasons because I think they really speak to the nature 15:37 of failure in blockchain which is supposed to be all about. 15:41 Which is exactly what I'm going to be talking about in this half of the talk. 15:43 So as I explained on the previous slide, this first example is this multi-signature idea 15:48 where there's, you need two or three keys to open this lock and Charles will break the 15:53 tie. 15:55 And there's like all kinds of unspoken stuff about like Charles will always resolve correctly 16:00 therefore we won't, there won't be any disputes and we'll never need to borrow Charles and 16:04 therefore this will scale a lot and stuff like that. 16:06 So there's all kinds of unspoken stuff that goes with all of these claims that people 16:10 have made in the past. 16:12 And right off the bat there's a severe problem which is that we don't actually know, Charles 16:17 really can't prove a negative that he is not actually Arthur in disguise and then this 16:22 whole scheme is foolish because as soon as two people put money into this box, Arthur 16:26 will just sign twice to take the money out. 16:29 But the real problem is economic which is that Arthur can actually offer Charles a bribe 16:36 of not only 500 but up to 1,000 because he's losing 500. 16:43 As the outcome is reported honestly, Arthur loses his 500 and it goes to Beatrix. 16:51 Beatrix not only gets her 500 back but she wins Arthur's 500. 16:56 So the, so Arthur's down a net 1,000. 17:00 He can bid up to 1,000 if he bids 999 for this bribe to Charles then Charles will throw 17:07 it in his favor and then he'll get 1,000 out of this box and he's still up one from against 17:13 where he would have been if he had lost honestly. 17:16 And this is like really dark because this foreshadows the entire sequence of problems 17:20 that the Oracle thing experiences. 17:25 In particular, the critical issue is that Charles, he right now he's getting nothing. 17:31 So any bribe at all is higher than what he's getting which is like he's charitably kind 17:35 of agreed to do this. 17:37 Right now his payoff is zero. 17:38 So any bribe he should take because his bribe would cause him to get a higher payoff. 17:44 And a really annoying thing is that the only thing Beatrix can do is counter bribe and 17:49 this is really unfair because she won the bet fair and square. 17:54 Her like maximum bribe is really 500 if we're being serious because she could have just 17:59 not put any money into this box at all, she would have been stuck at zero. 18:04 So in order for this to be worth it for the person who wins, they actually have a less 18:10 recourse than the person who loses. 18:12 And this is sort of like a general problem which is that Charles, the decision to steal 18:17 is worth 1,000 in this case. 18:20 It doesn't always have to be 1,000 but there is always going to be some cost that is inherent 18:25 to the oracle problem which I'm going to call the opportunity cost of theft. 18:29 And it's going to be equal at least to the amount of money controlled by the oracle because 18:33 whoever this oracle is, in this case, Charlie, he can throw the thing in some other way and 18:42 make himself a party to that transfer. 18:46 And so this is very dire situation right here. 18:49 And the multi-signature solution in this case to reinterpret it through this lens is 18:54 to just transfer that burden from Arthur where it originates. 18:57 And it originates with Arthur because he lost the bet. 19:00 So he loses the 500 and so there's an inherent cost of honesty that he must honestly lose 19:06 his 500. 19:08 And the solution here in quotes is to transfer that burden from Arthur to Charlie and simply 19:13 hope that they cannot coordinate. 19:15 But that's not very clever because they can easily coordinate. 19:19 So this got more sophisticated in 2014 particularly with Counterparty but with a number of other 19:28 people especially I think including BitShares and some other projects that were kind of 19:33 had a weird take on this. 19:34 But they said, okay, we're going to give up on identity which is smart because it's a 19:39 lost cause. 19:40 And they say, well, abstract the identities into roles, right? 19:43 And we'll say there's users who are would be the people who are Arthur and Beatrix and 19:47 they'll be reporters. 19:48 And we don't care if they are the same people potentially or we don't know who they are 19:53 and we're just going to forget about that. 19:54 So already we've like given up on a lot of concrete things. 19:58 And then it's pretty simple kind of business type model where the reporters are going to 20:01 collect fees on an ongoing basis. 20:03 It might be per report, it might be per minute, it might be per whatever. 20:08 But whatever it is, since the users can choose their reporter when they make the, when they 20:13 put the money in the box so to speak or when they want to initiate a bet of some kind in 20:18 this very concrete example, there is an incentive for the reporters to get and keep a good reputation 20:26 which is that if you have a bad reputation, you won't be chosen and you will lose this 20:30 stream of ongoing fees. 20:33 But no one really use this either because it has a lot of problems. 20:37 So I'm going to walk you through this slide which is basically the decision calculus of 20:43 this guy, the reporters over here, these judges so to speak. 20:47 And there's three factors that go into their decision at least and this is like a basic 20:51 finance NPV calculation of like net present value for those of you who are familiar with 20:57 this. 20:58 But the attack payoff is how much money they can get by just stealing from everyone. 21:04 So, circumstances might be such that there ends up being like 50 million pounds more 21:13 or let's say 50 million pounds that Brexit will happen and that Brexit equals yes and 21:19 maybe 40 million pounds that Brexit equals no and so there's this extra 10 million there. 21:25 The attack is that the reporter will himself become a user or a trader. 21:31 Get against this outstanding 10 million pounds and then throw it, the switch the wrong way 21:35 and extract the 10 million pounds. 21:37 So this attack is all the money that they can get which is this opportunity cost of 21:41 theft and that's offset by these payoffs that are in the future. 21:44 So this table here, the horizontal axis represents time and you're going today, one day, two 21:49 day, three days into the future and they have all this stuff, these payoffs in the future 21:54 and then this third factor is a mapping that allows you to compare payments in the future 21:59 to payments today and so it's basically how much they care about the future. 22:02 And the assumption in order to make our guarantee which is our goal, our design goal is to make 22:06 this guarantee that the box will work which we absolutely cannot do in this case but in 22:14 order to make the guarantee, it has to be the case that it's always true that the payoffs 22:17 in the future outweigh the attack payoff today and I think it should be pretty obvious why 22:21 that's not the case but I'm going to explain some of it anyway which in there, there's 22:26 a triple uncertainty, each of the three factors can wander into a dangerous zone where it 22:32 guarantees the failure of the scheme and if any of the three factors fail, the entire 22:38 scheme fails and there's no, more importantly, there's no way to guarantee ahead of time 22:44 that it won't enter any of those zones. 22:47 So this is like a giant disaster but I'm going to walk through some of it. 22:49 The attack payoff today which we want to be low because we want the scales to tilt to 22:54 the right, there's nothing preventing that from skyrocketing if the market becomes unexpectedly 22:59 popular. 23:00 So you could have like something that just, some reason everyone wants to bet on something 23:06 with some reporter, there's no clear way to limit the popularity of like, you know, like 23:13 it's sort of like a little bit what David was saying where he was saying that sometimes 23:16 the service becomes too popular and the network has to like kind of rebalance slowly but in 23:21 this case, there is no rebalancing, it's too late. 23:24 So this thing can skyrocket. 23:25 The red payments that we want to be high, they can decrease for any number of reasons. 23:32 One is just that the reporter industry might become more competitive or there could just, 23:36 not only could there be news of that, it doesn't actually need to happen. 23:38 It could be a rumor, it could be false. 23:41 So this is very dire. 23:44 More people might join the industry or they might have different offerings in this case 23:47 so they would not be able to, they'd say, okay, I'm going to lose this stream of payments 23:53 but I'm going to lose it anyway so, of course, I'll just attack everything and steal the 23:56 money today. 23:57 The reporter's concern for the future, we want it to be high but there's nothing preventing 24:01 it from decreasing. 24:02 The person might decide there's enough money in here for them to retire, they don't care 24:06 about their future at all or they might get some terminal illness or they could pretend 24:09 to be hacked or they could really be hacked and then the hacker would not similarly care 24:13 about their reputation. 24:16 So this is totally doomed but I'm going to walk it back through the framework of before. 24:19 This is this opportunity cost of theft that's still here, it's equal to the amount of the 24:23 losing bet and that amount and it's potentially large if there are many users which in the 24:29 number of users can skyrocket unexpectedly. 24:32 And this fee that we can extract here is to offset that and it's based on the utility 24:37 of the service. 24:38 So this is much better. 24:39 This is an improvement over the terrible multisig world where we are compensated for honesty 24:43 this time. 24:44 And this is some new psychological parameter that's specific to this solution attempt and 24:48 it's unreliable. 24:49 But the overall result is that this is a small improvement but it's still nowhere near good 24:54 enough which is why people really did not use this service to do anything interesting 24:58 like the... 24:59 blockchain enforced futures contracts that Gavin mentioned. People really are not doing that. It's got to be really good to be useful for that and so I'm going to try to just walk you through a little bit of this and again this is sort of like the plane versus boat thing where I'm not going to be able to explain the plane in detail but just try to draw the contrasts as much as possible which is that this is part of kind of my thinking on the issue which is one thing 25:26 improvement that I made is that I'm going to make a reputation itself a 25:30 tradable resource in this finite and tradable resource in this system and so 25:35 there's some pseudo corporation that's kind of not really a corporation of 25:38 course but in an abstract sense it is behaves kind of with the it's a nexus of 25:43 stakeholders that have ownership so it exists to prove its consistency within 25:48 and across time and collects money to power the mechanism so it provides this 25:52 service here the reason that making reputation itself tradable is important 25:56 is because it's a basic of finance that the stream of payments coming in which 26:01 is this red thing before we'll go back to it the stream of payments coming in 26:05 should actually be equal to the current market capitalization of the shares of 26:09 the corporation so if you want to buy up the this corporation your attack is so 26:15 your attack is not to be a reporter and then decide to do something wrong your 26:19 your attack is to buy up 51% or 75% or whatever it is of this corporation and 26:25 then force the entire group to make everything go haywire but the reason 26:31 that it's important to make reputation itself tradable is that it deletes that 26:34 third factor of time from the equation because theoretically the current market 26:39 capitalization of the company should be equal to the present value of all the 26:44 money coming in so similarly if the market becomes unexpectedly popular if 26:49 any market it was in this corporation or the entire system becomes unexpectedly 26:52 popular the it should the expected future fees should be going up or indeed 26:57 the present ones because the sort of dividends that are paid are a function 27:01 of the trades that are being made they happen later so they the money that's 27:06 coming in as the service gets more popular should directly translate to a 27:09 higher market capitalization immediately today so there's some stuff that's 27:14 offsetting this here and I do some other things as well which I don't really want 27:19 to explain this slide is from a different talk that I'm reusing but one 27:24 thing I do is I have everyone in the corporation submits a report on every 27:30 single thing that is resolved and I cross-reference those things against 27:34 each other for consistency but also to produce some information about who is 27:39 lying and what and there's sort of a kind of it's not really a cluster 27:43 analysis it's actually something else but more or less you can tell if some 27:46 people are being some people innocently got something wrong or some people are 27:50 just like out to reverse everything and steal all the money and it kind of very 27:54 makes it much more obvious like what people are kind of doing and one thing I 27:59 do want to emphasize the strategic use of time which is that it's easy in the 28:02 blockchain to lock money this is something that David was talking about a 28:06 little bit as well in his talk it's easy to lock money for a period of time but 28:11 as time goes on the kind of it's more easier to find truth and more easy to 28:16 kind of figure things out which is kind of one of the reasons why a court move 28:20 slowly slowly and that's not a bad thing so the net effect is that time 28:25 penalizes attackers only and so you have this money locked in it's locked in the 28:28 box that's not leaving but the box is gonna take a really long time to open 28:32 and the future contracts don't actually need to settle up again for a reason 28:36 that's totally financial and has nothing to do with computer science whatsoever 28:39 the futures price of this box the what the box is worth should track whatever 28:46 the whatever a real futures contract would be worth because if one is worth 28:50 different from the other you buy the cheaper one you short the higher one and 28:54 you extract money for free and since that would be if anyone who does that 29:00 will reharmonize and equalize those prices so I don't really want to explain 29:04 a lot of this but what I do want to explain is how this can break because it 29:08 is itself fragile so it's gonna break in a way that's totally itself bizarre 29:11 and yet is relies on a lot of simplicity so this slide there's two slides for 29:18 this the second one is where everything breaks but this is just a setup of some 29:23 very very simple things simple premises that you have to get admitted and one is 29:27 that this stuff is happening in a very specific order so first there are must 29:32 be multiple oracles because there's no way to stop people from you know copying 29:36 the service and creating it again and once someone chooses an oracle then you 29:43 have to wait for in order to evaluate so you choose first and then later on you 29:49 want to evaluate if that oracle was actually honest or not so in this case 29:53 you've chosen the blue oracle it's a thicker arrow there and then the blue 29:58 oracle is paired with some event in this case is this moon half crescent moon 30:03 event and then they have a report where they're gonna tell you this thing and 30:07 that's gonna this thing is gonna go into the blockchain and then stuff will 30:11 happen with it it will be referenced as a thing that everyone knows but it's 30:15 only after that phase two happens that you can actually check and see if 30:18 whether or not the oracle actually reported correctly because you need the 30:21 report and the event the report before the event happens maybe they could get 30:25 lucky or something but you need you need both in order to actually check to see 30:28 if they did it right and so since there's this degree of freedom here that 30:31 is not removable it must be possible it must be the case that they vary in 30:35 quality the oracles from 100% honest and the lower bound is actually 50% because 30:41 if they were a 0% honest that you would just flip everything and they would be 30:45 honest again but the point is a very simple one that if there are multiple 30:49 oracles they must have the freedom to vary in quality and it turns out that 30:52 simple premise destroys just about everything which is that the there's so 30:59 some are more honest than others and they must charge this fee to offset all 31:04 of their costs and so if they can't do that then they're just out of business 31:08 and they won't exist it's unsustainable of course but one of the one of their 31:12 costs is this quality premium which is a really important point to emphasize 31:16 because I'm having the top here honesty is costly to the oracle everything every 31:23 time they're honest they are foregoing some opportunity to steal the money and 31:28 so every so in order to compensate them for that we they have to charge this is 31:33 a cost it's not like a profit or anything like that they need even though 31:36 it's an inherently abstract concept theoretical kind of concepts it they 31:41 must charge more for being higher quality than they would charge if they 31:46 were going to be low quality and this is in addition to other costs that they may 31:50 or may not have such as the labor of like you know the 30 seconds it would 31:54 spend to Google something they didn't already know and maybe something about 31:57 that setup so the problem here is that as I say in the title of this slide you 32:02 need something that's sort of like a pseudo copyright and it took a long time 32:05 to figure out for me to figure out exactly how this would be done and I'm 32:09 not gonna explain how it's done here but I'm just gonna say if you don't have it 32:12 why everything breaks so you by you don't mean like a literal copyright or 32:16 any kind of legal enforcement of anything like that but you do need 32:19 something that will censor someone who steals the information in order to 32:24 purchase quality if you can't do this and you can't purchase quality and all 32:28 the reporters will be low quality and there'll be this kind of collapse of 32:31 unraveling markets which is the term so this red guy he's making it kind of an 32:37 evil statement that he's gonna copy the blue guy what when he reports and he can 32:41 do that in any number of ways one is by just watching the blockchain to wait for 32:45 one of those two people to get paid and say if they get paid that triggers this 32:48 thing or they could program them to just simulate blue or just look it up or 32:52 anything there's any number of very easy ways of doing this now the thing is 32:57 once this guy's coded up he's always going to be cheaper it's unavoidable 33:02 that he will be he will be able to charge less for this exact same service 33:06 to the users but he will always be exactly as reliable I'm gonna walk 33:12 through that which is that blues report is on the blockchain and now it's a 33:16 public non-excludable resource that anyone can verify and we've kind of 33:20 flipped the tables on that which is that anyone can validate and verify this 33:23 that blue actually did report that and that's exactly what red is gonna 33:28 exploit red is going to take blues contract here and he's just gonna copy 33:34 it and he's not gonna do any effort on his own and the issue is not that he the 33:39 issue is not that he is saving on labor the issue is that he is always exactly 33:44 as reliable but he will has no reason to charge the quality premium and so since 33:49 he's always exactly as reliable and always cheaper there's really no logical 33:53 basis for any users to pick blue over red because they're the same they're 33:59 exactly the same things if one's cheaper so in short but even since everyone may 34:05 be foreseeing that or at least not willing not being willing to wait to 34:08 kind of investigate if this is worth it this kind of entire scheme will never 34:12 pick up momentum because it will just constantly be in a state of uncertainty 34:18 but long story short since the red guy is always as cheap or cheaper than the 34:23 blue guy so we all excuse me it's always cheaper the blue guy and always exactly 34:27 the same service the blue guy goes out of business and this scheme doesn't work 34:31 and the idea behind the corporation pseudo corporation idea is that you 34:37 successfully spread the opportunity cost of theft widely over many people and 34:41 over a long time period very infrequent reporting and you've minimized the total 34:45 amount of information that someone needs to assess when they're looking at 34:49 whether or not this thing is honest or broken but the problem in this case very 34:56 bizarre failure is that the maximum reward these people could get for their 35:00 efforts is zero and so in turn the shares by that same finance kind of 35:05 theory I was mentioning before the shares of the honest corporation will be 35:10 worth the net present value of a stream of zeros which will be zero which will 35:14 mean that it would be trivial to purchase the shares and attack which 35:17 means that no one has any reason to trust that the system will operate the 35:21 way it was designed and that's basically it so I'm just going to repeat the 35:25 takeaways which is that with blockchain there's less trust everything is harder 35:29 it would have been a lot easier to just have Google do this or have Google 35:32 publish some keys or something but in the blockchain threat model everyone is 35:36 a threat and so we're doomed and there is a difference between programmers and 35:42 contract authors specifically smart contract authors and so in particular 35:45 number one there well that was with a it was too easy for the user to assume two 35:49 identities or make some bribe and with two it was too easy for the service to 35:54 be too popular it was a victim of its own popularity and then in the third 36:00 one it was too easy for rivals to enter and steal the service and in my opinion 36:05 in the blockchain world code is built on a foundation of incentives so what I 36:12 hope I what I was hoping to do is just draw a severe contrast as possible 36:16 between the way this would normally be done by anyone writing normal software 36:20 which is that they would just there'd be some reliable database for this that 36:24 you would just dial out to and the blockchain world and so I hope that 36:28 you've learned a little about the peer-to-peer Oracle why it's such a 36:31 difficult problem and in particular why it's much harder than just asking 36:35 someone else for the answer and then in turn you've learned more about 36:40 blockchain and so thank you very much for your attention 36:47 thank you Paul thanks we have time for a couple of questions if there's anyone 36:51 that wants to ask something or if there's anyone that understood most of 36:54 that talk it was it was in depth thank you any questions at the end of the day 37:02 oh hey Elaine does Olga have active markets going it doesn't matter to what 37:09 I was presenting here because it won't they don't work in equilibrium so it 37:19 still exists but it yeah but it would want though I mean it doesn't it hasn't 37:26 even launched in some sense depends on who you ask you ask them they say they 37:29 haven't launched yet so so I guess I would say no I don't know but they have 37:35 you know markets on you can look at but you know they're not they exist in the 37:40 sense that everything it's like only in like a testing kind of phase I guess I 37:47 would say well you know but I mean a lot of things that are literally test 38:01 nets have tokens that are traded on coin market cap you could trade Zcash 38:05 before launch on BitMEX yeah being having having a token traded on coin 38:12 market cap is actually a contra indicator of value I think it's like the 38:15 more valuable the coin is on coin market cap the less valuable the project 38:19 will ultimately be I think yeah they're going to be in the sole 38:24 exception the exception that proves the rule cool anything else it's you could 38:31 comment on that that oh did you have a question 38:45 I agree with you I'm not sure so that is one thing that so there's a separate 39:07 issue with that I think yeah so I think you're completely right if we had 39:10 something like where someone published a website and they said I'm gonna offer 39:13 this service and I will sign whatever the British pound to Bitcoin exchange 39:19 rate is and I will only do that once every you know a couple months and then 39:23 you can set up a bunch of stuff based on that and we'll reference that and they 39:26 their signature will go into the blockchain the problem with that is that 39:29 all of the money there is is reliant on that one person so even if they are 39:35 honest they could be like maybe hacked or something so it's like the Bitcoin 39:39 exchanges so I don't know if you're familiar everyone here is but every 39:42 Bitcoin exchange has basically been hacked at one point or another and 39:45 emptied of all of its money and there's like really no way to tell if it's like 39:49 an inside job or there's a legitimate security problem or if the founders just 39:55 absconded with the money and embezzled it or something to their friends or 39:58 there's like it's really really hard to tell so the the the kind of the ethos of 40:04 Bitcoin is that you control your own money and by putting it in the hands of 40:09 someone else you kind of are not operating in that world anymore hence 40:14 the focus on this box that you have this guarantee for you know this bearer token 40:19 that is worth some other amount of money but you you're right that that could 40:25 work it probably won't work at scale though because if something is worth 40:28 like 20 million dollars or 20 million pounds or something then that's a big 40:31 incentive to throw the switch the wrong way and even if you don't do it other 40:35 people will try to hack you for it and I'm not sure that that will scale I 40:40 don't think it will scale in monetary sense cool anything else yes 40:51 it was 40:55 new sources or I guess correct well it did it did work for a while but then it 41:06 didn't work you know and then it yeah then it had to comply with some laws and 41:11 the also the founder hiked Mount Everest and died and then some people it was 41:16 ambiguous like MF global situation where some people were like stealing money 41:19 from it or something they were using the money to make safe investments and they 41:24 were not allowed to do but yeah in trade is great it is not an example of 41:29 something where there's a guarantee because so that's the world of non 41:33 blockchain of like the legal world where it's not automated and you have 41:36 contracts with a person that has a brand and they have a mailing address and they 41:40 have something like that and you as a consequence it's a normal business and 41:45 not in the blockchain world it's not automated in trade had a number of 41:49 problems that I could maybe lists but they're not important because you could 41:54 if you ran into it a different way you would be able to fix those problems but 41:59 one thing that you couldn't fix is that it would not be this automated computer 42:02 system that would maybe be able to operate without any forms of censorship 42:07 or control and they would give this these financial tools to everyone in the 42:12 world and that is something that would not be the case for in trade you had in 42:17 order to like wire money to in trade it was expensive and cumbersome and slow 42:21 and that was a result purely of artificial regulatory and legal 42:26 requirements and it ended up not working for a lot of reasons but basically that 42:31 company went bankrupt and had some problems that we could list cool does 42:38 that answer your question cool all right any more questions 42:46 it's beer o'clock thank you very much for attending guys