Kaal claims by topic: consensus-and-security

441 atomic, individually citable claims from the published work of Wulf A. Kaal tagged consensus-and-security.

  1. If US law requires disclosure of information that another country's law prohibits from being disclosed, whether for privacy or other reasons, there could be a true conflict of law and a credible case that the United States is in breach of international law. 2010
  2. If a market evolves in which contingent capital designs appear to provide sufficient protection against systemic risk and contagion, decision makers may come to rely on the design of those securities and neglect their own role as monitors. 2012
  3. Investment adviser status under the IAA requires that the advice concern a security; without a security in the dealings between adviser and client the statutory definition does not apply. 2013
  4. Despite wide-ranging criticism of N/DPAs on authority, fairness, and expertise grounds, scholars agree that N/DPAs do influence corporate governance. 2015
  5. Blockchain removes fraudulent transactions primarily through completely decentralized network connectivity via the Internet, rather than through digital signatures alone, which only establish the identity and authenticity of the parties. 2017
  6. Blockchain's distributed consensus model, in which network nodes verify and validate chain transactions before execution, makes it extremely rare for a fraudulent transaction to be recorded in the blockchain. 2017
  7. Cryptographic hashing makes blockchain manipulation immediately detectable because the hash incorporates all previous transactions, so that even a single digit change produces a different hash value. 2017
  8. Blockchain technology lowers transaction costs by eliminating intermediaries, and it substitutes immutability and cryptography for the trust that intermediaries previously supplied. 2017
  9. Blockchain creates a data protection paradox: the technology itself offers strong privacy protection, yet storing blockchain data across a global network of nodes will often violate specific consumer protection rules and directives in individual jurisdictions. 2017
  10. The immutability and permanent recording built into blockchain technology may be the root of legal difficulties in European countries that recognize a right to be forgotten or comparable privacy rights. 2017
  11. In the decentralized DLT model, distributed consensus replaces the trusted central validation system, substituting cryptographic solutions and economic incentives for a central validator. 2017
  12. Complex smart contracts involving several parties can only work if they rest on a verifiable and unhackable system, which is what blockchain technology supplies. 2017
  13. Because network nodes verify and validate chain transactions before execution under a distributed consensus model, recording a fraudulent transaction on the blockchain is extremely rare. 2017
  14. Because each new block's hash value is generated from all previous transactions, the smallest change to the blockchain produces a different hash value, which makes any form of manipulation immediately detectable. 2017
  15. Although blockchain technology itself offers genuine data and privacy protection, storing blockchain data across a global network of nodes often will not comply with specific consumer protection rules, directives, and guidelines. 2017
  16. Equality is a natural byproduct of the blockchain-driven evolution of the crypto economy, because the trust enhancing consensus model, smart contracting in anonymous networks, and DAOs together allow a more equal society to evolve. 2017
  17. Proof of work mining carries significant externalities: the authors estimate that the total energy cost of running the global network of computers solving proof of work puzzles was around 700 million US dollars per year before publication. 2017
  18. Anonymity survives the blockchain's permanent public record because a new private key can be created for each transaction, so although public key addresses are stored eternally, each transaction allows an entirely new cryptographically secured private identity. 2017
  19. A government cannot control a blockchain by pressuring individuals within its territory; it would need complete control of 51 percent of the anonymous global users before it could change any part of the code. 2017
  20. Even if courts were given authority to order changes to smart contract code, a programmer coerced by a court could not override the will of the majority of anonymous international blockchain users to make an effective change. 2017
  21. Blockchain's distributed consensus model permits node verification of transactions without compromising the privacy of the parties, which makes it arguably safer than a traditional model requiring third party intermediary validation. 2017
  22. Smart contract arrangements involving several parties and greater complexity require the verifiable and unhackable system that blockchain technology supplies. 2017
  23. Although blockchain technology itself offers unprecedented data and privacy protection, storing blockchain data across a global network of nodes often will not comply with the consumer protection rules, directives, and guidelines of particular jurisdictions. 2017
  24. Contemporary corporate governance reforms are unlikely to work as policymakers and regulators intend, because experts agree improvement is needed but disagree widely on what good corporate governance is or how to achieve it. 2017
  25. Reputation value in any decentralized reputational system can be corrupted through three channels: direct purchase of reputation, automated worthless work, and degeneration of the system into a majority of inexpert opinions. 2018
  26. The problems of corruption, Sybil attacks, and tyranny of the majority have plagued every previous autonomous decentralized reputation platform, so they are the design constraints any new architecture must meet. 2018
  27. The hidden voting scheme depends on the choice of symmetric encryption protocol: a poorly chosen protocol exposes the platform to a birthday problem attack in which malicious voters submit an encrypted key that can be decrypted in two different ways, letting them retroactively choose their vote. 2018
  28. A newcomer cannot buy reputation with money because the 50/50 staking of newly minted tokens leaves incumbent experts with complete power to decide whether the newcomer's contribution was positive; a losing applicant forfeits all reputation in the expertise. 2018
  29. The chosen expert is deliberately not paid directly out of the fee but only indirectly in newly minted tokens, because the architecture secures itself by making reputation more valuable than any one time payment. 2018
  30. Enforcing a protocol in which all work fees are shared with the expertise produces a positive feedback loop: more fees raise the worth of reputation, which makes sem tokens more desirable than one time fees, which makes vested experts police the system carefully, which makes the system more secure. 2018
  31. The platform is Sybil attack resistant because all power is weighted by reputation rather than by account: an owner of a single account holding 1000 tokens has the same or more power than an owner of 1000 accounts holding one token each. 2018
  32. The tragedy of the commons arises in any system lacking a well designed incentive structure; in blockchain proof of stake design this is the nothing at stake problem, where unregulated systems lead pseudonymous users to abuse the system. 2018
  33. A 51 percent collusion that votes against common sense is visible in an open system, which erodes trust, reduces use and fees, and lowers the value of the attackers' own reputational salary, so the tactic can destroy an expertise tag but cannot enrich the attackers. 2018
  34. The author concedes an arbitrage attack is feasible when experts fail to police their expertise and a significant share of the technically fungible tokens is offered on an exchange, since a malicious actor can then buy 51 percent of the tokens, vote against common sense, and sell before the tokens lose value. 2018
  35. Healthy expertise tags are secure not because attack is impossible but because it is easier to profit from them by improving them than by harming them. 2018
  36. In the absolute worst case, with no safeguards at all, the price of corrupting the platform from within is a minimum of twice the total historical fees added to the system, and instituting any obvious protection raises that price steeply. 2018
  37. Even a successful takeover yields the attacker only a fraction of one transaction's fee before the expertise tag topples, so as long as any single fee is smaller than the total reputation there is no incentive to game the system for fees. 2018
  38. Acquiring 51 percent of the tokens by paying fees and winning betting pools costs roughly six times the value of the entire quantity of sem tokens in a healthy expertise, even when the bench makes no effort at all to police the incoming fees. 2018
  39. If good faith experts counter invest at least as fast as the malicious group, that is at a constant fraction c greater than or equal to one of the malicious investment, the malicious group can never gain more than 50 percent of the power. 2018
  40. The token economy is inflationary at equilibrium, and this inflation is a feature rather than a defect because it improves security and discourages rent seeking holding of reputation. 2018
  41. In the proof of stake application, a block is accepted by the network only if it carries proof of success in a betting pool, and that stamp constitutes the entire cryptographic security of the chain at far lower energy cost than proof of work mining. 2018
  42. A proof of stake lottery on this architecture is vulnerable because the seed of the pseudorandom generator that names the next block author is partly controlled by the current block author, which lets an attacker capture all block creation by routing authorship to their own Sybil accounts; the proposed remedy is to derive the seed from a hash of the previous block's validation information. 2018
  43. The author contests Houy's claim that killing a proof of stake currency costs nothing: on this platform the token's value is calculably predictable rather than merely a function of public opinion, and signaling an intention to buy tokens usually raises the price rather than triggering a race to the bottom. 2018
  44. Faking a reputable expertise tag is nearly costless: a successful tag's open record can be copied and reposted under a new name for the price of the anti denial of service fees, and the capital used to mimic fees paid into the sham tag is mostly recovered by the sham owners through the salaries they control. 2018
  45. If 51 percent of users collude to enrich themselves maliciously, nothing in the design can prevent them; the only check is the openness of the system, which would quickly detect such an attack. 2018
  46. Proof of Work remains the most popular consensus protocol type among the top 100 tokens, and the Other category alone comprises thirty-four tokens. 2018
  47. Attempts to increase throughput and scale in consensus protocols concentrate on proof of stake, and the data are consistent with anecdotal evidence that proof of stake may be the most dominant attempt at scaling. 2018
  48. To date no blockchain coherently and comprehensively combines scale, security, and decentralization, the three objectives of the blockchain trilemma, although continued experimentation with consensus algorithms can help overcome it over time. 2018
  49. Tokens experimenting with alternative consensus protocols typically change the transfer process in an effort to become more efficient. 2018
  50. Tokens launched before 2015 were overwhelmingly developed on a hardfork governance mechanism or a combination of hardfork and one other governance type. 2018
  51. To offset human limitations, requesters in centralized micro task structures assign the same task to teams of up to fifteen workers to form a consensus. 2018
  52. Consensus by redundancy fails economically: multiplying the same work across many workers significantly increases the cost of micro task work. 2018
  53. Paying proportionally, up to fifteen times, for the same project output is waste, and the necessity of multiplying work also pushes micro task workers into lower rates with no pay increases. 2018
  54. Signup and approval processes in centralized micro task systems are invasive, privacy challenging, time consuming, and unclear, and they function as market entry barriers for micro task workers. 2018
  55. Unlike its decentralized competitors, the Semada Protocol is claimed to be resistant to both Sybil attacks and Tyranny of the Majority attacks. 2018
  56. The protocol architecture together with its incentive structure is what produces enhanced 51 percent attack resistance, which the author claims exceeds prior reputation verification attempts in both decentralized and centralized networks. 2018
  57. Rather than repeating the same task across many workers to reach quality, the architecture verifies quality directly by examining and validating individual worker task performance through reputation verification. 2018
  58. Staking creates disincentives for malicious actors, and it is this disincentive structure that makes the network both more efficient and attack resistant. 2018
  59. Once participants are vested through reputation, they police the system themselves, which raises security, which in turn attracts more public fees and closes the loop. 2018
  60. The gamification design borrows the foundational proof of work principle that verifying a game was played properly is far easier than playing it properly, which is why bench validators can check task performance almost fully automatically. 2018
  61. Attack resistance should be designed to increase as the platform grows, in contrast to designs like GEMS that detect and ban malicious actors, because a self enforcement mechanism lets the incentive system steer users away from bad actors once the system matures. 2018
  62. Because blockchain network nodes verify, validate and audit transactions both before and after execution, the model is safer than a traditional one in which transactions can only be accomplished through third party intermediaries such as a bank, judiciary or notary. 2018
  63. Cryptographic hashing makes tampering with blockchain records extremely difficult because even a minuscule change produces a different hash value, rendering manipulation instantly and readily detectable. 2018
  64. Cybersecurity should not be addressed by introducing more law in books; law students should instead look for technology based solutions and at minimum acquire the knowledge needed to evaluate such solutions against the alternatives. 2018
  65. Existing blockchains and DAOs still lack genuine decentralization, and there are currently no true DAOs: Bitcoin's proof of work protocol has produced mining pools because of economies of scale and unbalanced reward structures. 2018
  66. Anonymity in blockchain organizations makes them prone to Sybil attacks and 51 percent attacks, and anonymity combined with autonomy has led to many hacks. 2018
  67. The real design challenge for consensus protocols is to find a proof of stake protocol that offers both trust and security without unintentionally creating just another centralized validation system. 2018
  68. Today's internet is designed for hierarchical societal structures on an underlying authoritative trust model, and that traditional hierarchical trust model carries many inefficiencies including serious cyber security vulnerabilities. 2018
  69. The centralized version of the internet cannot scale to the thirty to fifty billion connected devices that experts expect by 2020, which is why decentralized authentication solutions for internet of things devices are needed. 2018
  70. Every centralized reputation score can be sybil attacked, because fake internet accounts or fictitious ratings disrupt true reputation scoring. 2018
  71. Nobody has yet created a reputation engine that is genuinely resistant to Sybil attack and that cannot be corrupted regardless of the economics at stake, despite the many platforms that capture reputation. 2018
  72. Meaningful and secure reputation tokens supply the incentives needed for secure proof of stake consensus in block production, which eliminates the unsustainable inefficiencies of proof of work based blockchains. 2018
  73. Semada replaces fungible currency staking with reputation staking for block propagation, a consensus algorithm the authors call Semada Proof of Reputation. 2018
  74. The fungibility of the staked currency is the main point of attack against proof of stake and leads inevitably to centralization. 2018
  75. Because Semada's Anchor Protocol uses reputation scores as a non fungible currency to qualify for block propagation, the resulting proof of reputation consensus is attack resistant, fully decentralized, scalable, and open to evolutionary protocol upgrades. 2018
  76. A Web of Trust reputation system can be gamed with sockpuppet accounts, because an attacker can behave well for a while and then transact with himself repeatedly and rate himself high to raise his reputation arbitrarily. 2018
  77. In an economic network where real money is at stake, historical good behavior cannot be assumed to prove future good behavior, because sockpuppet accounts allow participants to game the system automatedly, create valuable reputation falsely, and leach value out of the system. 2018
  78. Semada's voting algorithm is designed so that gaming the system is not economically feasible without contributing genuinely valuable improvements, because value is proven through the fees added to the system and every fee is subject to a fair validation pool. 2018
  79. The Sockpuppet Protocol breaks the incentive for Sybil attacks because all power derives from validation pools in relation to what members stake and all fungible currency rewards are shared with the group in proportion to individual reputation. 2018
  80. Semada's biometric onboarding technology uses zero knowledge proofs so that users retain continuing anonymity once they are onboarded. 2018
  81. No single, fixed, entirely algorithmic policing solution can completely prevent independent nodes in a distributed system from gaming block production to advantage some parties over others. Any consensus protocol that relies on a permanently fixed rule set will therefore be gamed as conditions change. 2018
  82. A successful proof of stake protocol must be flexible enough to continually police new attack strategies, because changing market forces and network performance keep creating new opportunities to profit at the expense of the majority. 2018
  83. A secure proof of stake protocol requires an incentive structure that perpetually motivates users to do three things at once: produce valuable blocks, police blocks that violate protocol, and improve the production protocols in response to gaming. Incentivizing only block production is insufficient. 2018
  84. Because all block creation fees are shared with the whole group as a reputation weighted salary, SPoS removes the direct monetary reward for forming mining pools or block production cartels, which the authors identify as a decentralization threat that raises the likelihood of 51% attacks. 2018
  85. Because the stakes in SPoS are reputation tokens that are far less fungible than cryptocurrency stakes, long term probity is incentivized and many short term arbitrage opportunities are eliminated. Fungibility of the staked asset is what makes short horizon attacks profitable in other proof of stake systems. 2018
  86. Because at least half of the sem tokens minted when a user buys in with a fee are shared with the community that polices the application, the ability to purchase tokens does not open a profitable 51% attack; the authors claim a mathematical proof that this feature alone eliminates the incentive. 2018
  87. Given that Byzantine faults are inevitable in a distributed system, the known impossibility results force any consensus protocol to hedge: it can promise only a probability of finality and security, and that probability is inversely proportional to liveness and speed. 2018
  88. Even though proof of stake mitigates the economy of scale advantage, block production cartels can still arise in PoS systems through lotteries, through built in voting delegations, or because the stakes required to be a block producer can simply be bought. 2018
  89. If block producers' identities are revealed, the supranational independence and security of the blockchain are threatened, because local jurisdictions can then exert legal power over block production. This threat is most acute in delegated proof of stake, where delegates must win popularity contests. 2018
  90. No consensus protocol can guard against Byzantine faults when a single transaction is worth more than the promise of all future fees for the entire platform, because in that case a party can profitably bribe the whole node set to destroy the chain's own integrity. 2018
  91. Altruism cannot be relied on in a decentralized anonymous system, so fees are ultimately crucial; the authors conclude that several blockchains with different fee structures must exist so that different transaction values can be given correspondingly different security. 2018
  92. Because almost all other blockchains distribute perfectly fungible currency tokens through initial sales or mining, there is a clear, computable answer to how much it would cost to corrupt or destroy a chain running a proof of stake protocol on cryptocurrency stakes. 2018
  93. The long range attack is a fundamental problem every proof of stake protocol must address: because no energetic outlay is required to build blocks, a malicious producer can fabricate a long chain forked from an earlier valid block, and a newly joining node lacking proof of work hashes cannot objectively tell which chain is genuine. 2018
  94. SPoS prevents the long range attack without token locking, because a false chain cannot be manufactured with more total validation than the real chain: votes are transactions moving validators' sem tokens under their public keys, so upvotes cannot be forged from existing tokens. 2018
  95. Any blockchain whose soft forks are decided through private communication between famous token holding whales is ultimately less secure than legacy centralized systems, which at least address centralized security risks deliberately. 2018
  96. The current dominance of altruists in the crypto space will not persist: once the crypto economy matures, an influx of hedgers and rent seekers can be anticipated with certainty, and they will exploit any weakness in the system for profit. 2018
  97. Successful proof of stake experiments running today cannot be used to infer that their protocols are truly secure, because the current participant population is atypically altruistic; confidence must instead come from sound reasoning about incentives. 2018
  98. A healthy expertise will have near unanimous consensus on every evidence of work validation pool, and that very unanimity creates an impediment to development, because honest members risk their stakes by voting for untested changes. 2018
  99. In SPoS, validators download the most recently upvoted validation algorithm and faithfully running it unedited automatically produces the winning vote, so honest validators are rewarded; this holds on the assumption that users controlling 51% of sem token power act honestly. 2018
  100. Forcing validation pools to close in finite time, which practical demand for swift resolution requires, opens the possibility of network partition and of a lack of genuine consensus, and therefore of forks. Complete finality would require unbounded validation time. 2018
  101. When a fork skips valid blocks, fees previously distributed to the bench from those blocks lose their valid histories and ownership reverts to the transaction authors, which creates a direct disincentive for validators to endorse such forks. 2018
  102. If a Byzantine producer equivocates during a network partition and wins validation pools in separate subnets, the fork is not permanent: once connectivity is restored the next honest producer points to a previous block, and with 51% honest producers the Byzantine fork is eventually orphaned because honest producers outproduce it. 2018
  103. Running the reputation platform on the very blockchain it validates destabilizes the system because it increases the likelihood of forks: every validation pool result is itself a transaction that must be included in a future block requiring its own validation, without end. The authors judge this destabilization non catastrophic for most imagined uses. 2018
  104. SPoS is far more computationally efficient than proof of work implementations because nodes no longer hash mine; the only computation added beyond the block validity checking every blockchain performs is one validation pool per block, in which each node sends a single up or down vote transaction. 2018
  105. Finality in SPoS is measurable because forking away from a given block would cost the community all sem tokens created on the chain after it, and that quantity equals half of all fees sent since the block was produced. 2018
  106. Because each sem token carries a different value depending on the post that minted it and on its position in the reference graph, the total value is difficult to determine, which makes it almost impossible to execute a 51% attack by purchasing tokens on an exchange. 2018
  107. An attacker who buys sem tokens directly from the platform by sending fees must spend at least twice, and more likely six times, the entire historical value of the platform, so the griefing factor is a minimum of 2 with an average of 6. 2018
  108. Under the worst case model with no admission safeguards and no other users paying fees, a malicious group must invest at minimum twice the total sem tokens of the system to reach 50% voting power in the validation pool, because half of every fee it pays mints tokens for the existing good faith experts. 2018
  109. The sem token economy is inflationary at equilibrium, and the authors argue this is a feature: inflation improves security and discourages rent seeking by penalizing holders who do not use their tokens to evaluate posts. 2018
  110. A malicious party using Sybil accounts cannot be prevented from cloning the structure of a successful proof of stake blockchain at far lower cost than cloning a proof of work chain, leaving a new user unable to distinguish the truly decentralized chain from a clone that has manufactured even more tokens. The authors answer that this is resolved off chain, by a trusted user interface, as with cloned web pages. 2018
  111. Peer-to-peer transactions are possible because a distributed consensus model has network nodes verify, validate and audit transactions before and after execution, and this is often safer than routing transactions through a single trusted third-party intermediary. 2018
  112. Cryptographic hashing makes tampering detectable because even a minuscule change to the blockchain produces a different hash value, which other participants can observe instantly. 2018
  113. Most current blockchain applications lack complete decentralization: proof of work style validation has produced mining pools because of economies of scale and unbalanced reward structures. 2018
  114. Anonymity in blockchain organizations makes them prone to Sybil attacks and 51 percent attacks, and anonymity combined with autonomy has already produced hacks. 2018
  115. The claim that blockchain is secure by design cannot yet be relied on, because the technology has not been adopted widely enough to be severely tested, and hacking attacks on digital currencies underscore the concern. 2018
  116. Personal happiness, freedom and expression can thrive better in a decentralized world only on the condition that the decentralized world provides a secure environment, which is why blockchain platforms attract people. 2018
  117. Forking a chain is an insufficient governance mechanism, and even attempts to create socially optimal chain forking rules cannot suffice as a substitute for evolutionary blockchain governance protocols. 2019
  118. Decentralized systems become more attack resistant and grow quickly because their information flow is optimized through dynamic feedback effects, which lets them mutate and change very easily. 2019
  119. In delegated proof of stake protocols the significant block validation power of elected nodes leads to corruption, because those nodes are incentivized to bribe voters to be elected as delegates in exchange for some of the newly inflated tokens. 2019
  120. Hard forks can reintroduce the double spend problem, because wallets, merchants, and users running the previous code deem the new code invalid and cannot detect spending on it, so coins spent in a new block could be spent again on an old block. 2019
  121. If a community cannot agree after a hard fork on which chain is the true chain, the result can be two blockchains competing in perpetuity, and the only viable remedy is abandoning one branch, which causes some miners to lose re-allocated transactions. 2019
  122. Reform of agency relationships in decentralized systems is possible only if and when a truly decentralized public blockchain emerges that is scalable and fully secure; without it, information asymmetries, censorship, agent opportunism, and system corruption may persist. 2019
  123. Optimized DAO governance should pay members only indirectly, through fungible salary tokens issued in proportion to non fungible merit tokens, because the indirect economic effects remove corruptive elements and make the design more attack resistant and stable in the long run. 2019
  124. On chain governance is a necessity for most public blockchains because all existing blockchains need to calibrate soft forks for protocol upgrades. 2019
  125. Reputation based metrics were ineffective in centralized governance systems because before blockchain, reputation could not be stored autonomously, anonymously, and transparently, so it was not a reliable predictor of actors' future actions. 2019
  126. The double spending problem has not been eradicated in theory: a group or syndicate obtaining 51 percent control of a network could reverse transactions and create a private chain that the market could only limitedly discern as not real. 2019
  127. Blockchain based offerings introduce technology risks from code design and functioning and from third party intrusions that are generally absent in traditional offerings, and these risks cannot really be quantified. 2019
  128. The Overstock structure fails to deliver investor privacy, because all existing broker-dealer customer agreements contain provisions allowing the broker-dealer to share the customer's identity, whereas ideally the individual's privacy would be contained. 2019
  129. Applying blockchain to corporate governance requires the relevant authorities, who most likely understand the governance use case but not the technology, to reach consensus on how and when to implement it. 2019
  130. The immutability of the blockchain and its cryptographic security systems provide transactional guarantees that create trust between principals and agents in the integrity of their contractual relationship, and ensure that no participant can circumvent the rules embedded in blockchain code. 2019
  131. A blockchain guarantee means that a contract between principal and agent executes only if and when all contract parameters have been fulfilled by both parties and verified by a majority of miners or nodes in the system. 2019
  132. The distributed consensus model, in which network nodes verify and validate transactions before execution, makes it extremely rare for a fraudulent transaction to be recorded in the blockchain, and it does so without compromising the privacy of the parties. 2019
  133. Cryptographic hashes increase blockchain security and remove the trust barriers in agency relationships that otherwise require monitoring of agents and generate agency costs. 2019
  134. The core issues that afflict centralized governance solutions, including information asymmetries, censorship, opportunism of agents, breaches of fiduciary duties, and fraud, can only be truly removed if and when a truly decentralized public blockchain emerges that is scalable and fully secure. 2019
  135. Blockchain-based corporate governance solutions in DAOs require evolutionary blockchain governance protocols, and socially optimal hard-forking rules cannot suffice. 2019
  136. Because information flow in decentralized systems is optimized through dynamic feedback effects, such systems mutate and change easily, which makes them more attack resistant and allows them to grow very quickly. 2019
  137. Because cryptocurrencies embody a transferable store of value, the exercise of power over that value inevitably leads back to centralization through economies of scale, creating core points of attack that undermine the very nature of decentralization. 2019
  138. For any static set of rules in an infinitely repeated game using reputation stakes there is a way to subvert the rules for individual profit at the expense of the group, a result the author attributes to the Folk Theorems of game theory. 2019
  139. A dynamic, changing set of governance rules can address the problem that any static rule set is gameable, and can establish the incentives necessary to stop such abuses. 2019
  140. Decentralized systems mutate and change easily because their information flow is optimized through dynamic feedback effects, and this capacity to mutate is what makes them more attack resistant on multiple levels. 2019
  141. The data mining that produces scarcity in existing blockchains also slows creation, so high speed transactions cannot be achieved for the foreseeable future without a different consensus design. 2019
  142. Because cryptocurrencies embody a transferable store of value, the exercise of power over that value inevitably leads to centralization through economies of scale, which creates core points of attack and undermines the very nature of decentralization. 2019
  143. It is immaterial whether security incidents occur on centralized exchanges, on centralized systems appended to decentralized structures, or in the decentralized systems themselves, because the public perceives the resulting security concerns as a technology risk across all of these technologies. 2019
  144. For any static set of rules in an infinitely repeated game using reputation stakes, there is a way to subvert the rules for an individual's profit at the expense of the group, which is why static decentralized governance rules can always be gamed and only dynamic, changing rules can address the problem. 2019
  145. Narrowly construed, a digital asset is instantiated through computer code and depends on consensus computer algorithms to trigger and validate any transaction in that asset; broadly construed, digital assets extend to items such as video game goods that have no validating consensus algorithm and no comparable security. 2019
  146. The transferability of the stores of value entailed in cryptocurrencies creates core points of attack and undermines the very nature of decentralization. 2019
  147. A fiat backed stable cryptocurrency that is not fully collateralized is exposed to arbitrage trade attacks of the kind George Soros used against the pound sterling; full collateralization is therefore a necessary defense. 2019
  148. Fiat currency collateralization is expensive and inefficient because the entire backing value must be held liquid; anything less opens arbitrage opportunities of the Soros type. 2019
  149. The interoperability deficit in cryptocurrency markets is partly intrinsic to blockchain technology itself, because the consensus mechanism that allows block propagation on one chain in some ways negates interoperability with other chains and their consensus. 2019
  150. Fiat currency collateralization is expensive and inefficient because the entire backing value must be held liquid; anything less opens arbitrage attacks of the kind Soros used against the Bank of England. 2019
  151. Contesting the standard reading, the authors argue Soros broke the Bank of England not because the pound lacked full foreign reserve backing but because the pound was pegged at an inauthentic value. 2019
  152. Misestimating the hot money ratio fails in both directions: overestimation makes the currency more costly to use, and underestimation leaves it insecure, so efficiency and security are in direct tension. 2019
  153. Transparency is not an unqualified good for monetary policy: a currency only partially backed by reserves can be arbitraged by a Soros-style shorting strategy much more easily when the quantity of reserves is public. 2019
  154. Power in a blockchain system is exercised through the consensus protocol, which places control of data with multiple networked parties and thereby creates checks and balances that prevent any single vested interest from controlling the system. 2020
  155. Because individual network nodes verify and validate transactions before execution under the distributed consensus model, recording a fraudulent transaction on the blockchain is extremely rare. 2020
  156. The immutability of blockchain ledgers is itself a vulnerability, because once a DAO is in operation its essential construction is very difficult to alter should a bug in the code appear. 2020
  157. Bifurcation of nodes in a decentralized network through forking can cause significant economic loss, errors, confusion and bugs, including reemergence of the double spend problem that the pre fork network had already solved. 2020
  158. Paying DevDAO salaries in fungible stable tokens in proportion to members' non fungible reputation scores makes the economic benefit indirect, which removes corruptive elements and makes the governance design more attack resistant and stable over the long run. 2020
  159. Reputation weighted salary distribution defeats sock puppet attacks, because a member who creates ten accounts holding one reputation token each ends up in the same position as one account holding ten reputation tokens. 2020
  160. Cyber security incidents contribute to the volatility of the digital asset market through a specific channel: consumers instantaneously withdraw their assets from an exchange affected by an incident. 2020
  161. In the early 2020s the DeFi technology infrastructure was insufficiently developed to support DeFi growth estimates and growth potential, and fulfilling that potential requires significant tradeoffs between scaling, security, and levels of decentralization. 2020
  162. The tradeoff between transaction approval speed and immutability has the potential to undermine the DeFi infrastructure in the long run. 2020
  163. Consensus in decentralized systems presents a two sided cost problem: creating consensus raises the costs of prepping, processing, and storing information, while reducing the number of computational checks increases the risk of collusion attacks that could change the record. 2020
  164. The Bank of Canada's year long Jasper trial revealed a tradeoff rather than a solution: Ethereum would make the wholesale payment system more resilient but was costly and raised privacy issues, while Corda addressed cost and privacy but made the system less resilient, and the Bank concluded in May 2017 that blockchain was not mature enough to run a national interbank payment system. 2020
  165. Reputation based staking removes the corruptive elements of fungible tokens because third parties are less likely able to take over a non fungible asset such as reputation that is organically grown and maintained through actual expertise in the relevant subject matter. 2021
  166. Paying members indirectly, through a fungible stable salary proportional to non fungible reputation, removes corruptive elements and makes the governance design more attack resistant and more stable over the long run. 2021
  167. Member reputation is inflationary by design, so non staking of reputation tokens or non voting leads to value depreciation, which incentivizes action and makes liveness faults less likely. 2021
  168. Reputation weighted salary distribution solves the sockpuppet attack, because a member who creates ten accounts holding one reputation token each ends up in the same position as one account holding ten reputation tokens. 2021
  169. Any set process or set of rules that can ever be designed will ultimately fail to secure a network for all time, so no static rule set can serve as the permanent foundation of a DAO. 2021
  170. Because a group sometimes genuinely has no consensus to be discovered, network forking is at times inevitable rather than a governance failure that better rules could prevent. 2021
  171. Across all the alternative polling methods explored in the literature, changes both help and hurt: new approaches solve old problems while creating new opportunities for manipulation, a pattern the authors identify with increasing the attack surface. 2021
  172. Marketing a consensus algorithm as correct by construction is false advertising, because such proofs establish resistance only to the attacks the theorists considered reasonable at the time, not to all possible attacks. 2021
  173. Finding a correct by construction algorithm that incorporates all possible or even all practical assumptions about network status is not possible, because for any set of assumptions about network behavior an actor can break those assumptions by valuing some other result. 2021
  174. Since no algorithm can be perfectly secure in all circumstances, protocol developers should redirect effort from proving algorithms correct to building a governance process that updates the algorithm as network circumstances change, rewarding protocol improvement with meaningful reputation instead of leaving attack as the profitable option. 2021
  175. The authors hold that the Bitcoin proof of work algorithm is ultimately flawed, that every consensus algorithm is flawed, and that it is not possible to create an algorithm that is not flawed. 2021
  176. Bitcoin's proof of work has produced no protocol violation in more than a decade, meaning no rule breaking message has been incorporated into the finalized blockchain, even though anyone can run a hacked version of the algorithm anonymously at any time. 2021
  177. Charging admission to a DAO disincentivizes defection because the sunk cost of joining makes cheating expensive when rejoining would require paying again, a mechanism the authors identify as costly signaling that works better the more cheaters the surrounding environment contains. 2021
  178. A DAO permitting anonymous membership is exposed to a sockpuppet attack in which one account behaves honestly while another cheats, and if the cheating account can funnel its gains to the honest account without detection or punishment the system is set up for failure. 2021
  179. Paying contributors in reputation tokens rather than fees, and then distributing all fees as a periodic reputation weighted salary, defeats the sockpuppet attack because splitting a holding across many accounts yields exactly the same share of fees. 2021
  180. The goal of the Web3 movement is to foster radical bureaucratic transparency through open source design, to advance individual autonomy and privacy through cryptography, and to level access to information and computing resources through decentralized networks. 2021
  181. Bitcoin proved that a decentralized peer to peer network can manage valuable assets without a central authority, but the centralizing force of competition concentrated power anyway, as economies of scale produced large mining farms in place of millions of individual members maintaining the ledger. 2021
  182. Hash functions let a leaderless network reach consensus on identity and ordering, because every node independently hashes a transaction's data and deterministically arrives at the same unique identifier that everyone recognizes. 2021
  183. A blockchain is immutable because any attempt to edit an old block changes the hash of that information and is immediately rejected by the network that follows the protocol. 2021
  184. Proof of work consensus is energetically wasteful because the entire global network redundantly computes wrong nonces, with the Bitcoin network consuming as much energy as the country of the Czech Republic. 2021
  185. Proof of stake carries an unresolved failure mode: if anyone devises a clever algorithm for hijacking the block producer selection process, the network would fail. 2021
  186. Blockchain transactions will always be expensive whether or not proof of stake is solved, because full participation requires downloading the entire transaction history to verify validity, an extreme redundancy that cannot be removed. 2021
  187. Hot storage buys easy access and quick transferability of digital assets at the cost of exposure to cyber attacks and to the difficulty of keeping private keys safe. 2021
  188. Because a wallet provider or exchange that has custody of a digital asset gains full control over transactions, hacking a digital asset exchange is equivalent to robbing a bank: the attacker obtains valuable cryptocurrency that can be cashed out. 2021
  189. Between 2011 and 2018 there were 56 cyberattacks on cryptocurrency exchanges, initial coin offerings and other digital currency platforms worldwide, totaling $1.63 billion in hacking related losses. 2021
  190. Cold storage custody solutions are much more secure and resistant to cyber attacks than hot storage because the digital assets and associated private keys are held in wallets that are not connected to the Internet. 2021
  191. Information security infrastructure and controls to mitigate hacking, theft, and fraud must be enhanced when maintaining custody of digital assets, because digital assets have unique technical characteristics. 2021
  192. Custodial service providers spend proportionally less on IT security than non custodial ones: custodians spend between 6 and 10 percent of resources on IT security while non custodial service providers spend between 11 and 20 percent. 2021
  193. Every risk in a digital custody operation should carry both a preventative and a detective control, layered so that if some controls fail others remain to reduce the risk. 2021
  194. Specialized digital custody audit procedures for verifying that a bank maintains access controls over a cryptographic key differ from the audit procedures used for physical assets, so some risk management processes must be tailored for digital custody. 2021
  195. Because the instruments of scientific development and research are themselves centralized, the scientific consensus they produce is naturally centralized as well. 2021
  196. Because social media can move knowledge and views from the edges of society into the mainstream very quickly, this transfer can remove existing societal consensus, social cohesion among established groups, and order in the process. 2021
  197. Proof of Work block rewards structurally reintroduce centralization: the economic nature of mining rewards incentivizes degrees of centralization through collective action of nodes that share rewards as a group, that is, mining pools. 2021
  198. Early stage consensus designs such as PoW, PoS and DPoS create a community belief system in certain foundational technology features that in effect inhibits higher degrees of decentralization, so suboptimal early decentralization becomes self perpetuating. 2021
  199. Decentralized networks depend on dynamic governance because evolving blockchain protocols require updates, and the practice of hardforking that remained prevalent in the early 2020s created significant economic loss for such blockchains. 2021
  200. Forking bifurcates network nodes and can reintroduce the double spend problem the network had already solved, because users running pre fork code treat post fork code as invalid and cannot detect spending on it, so coins spent in a post fork block can be spent again on a pre fork block. 2021