2016-05-30

Tau-Chain - a programmer's perspective

EDIT:

After speaking to Ohad Asor, the creator of Tau, about the below piece, it's apparently "blatant obvious nonsense about things [I] don't understand" and "the contradictions are all around. just like eth". The Tau presale was apparently also meant for "only well informed buyers", "i have morals. im not ethereum!".

So yeah, the Tau project is not for mere mortals like myself, and the spam and promotional videos are meant for intellectual elites that will then buy the exclusive tokens. The project looks much better suited for some high-end computer science academia really, but no, token presale is the way to go.

Remember - the Tau is not for you, stupid.

END OF EDIT

Living in the Bitcoin land, you never know what you might come across next. It could be as benign as someone issuing a currency backed by pre-1965 silver US dimes, as geeky as someone creating a blockchain to mine for prime numbers, or it could be as convoluted as BitShares with the many iterations it had over the years (as someone put it - "BitSharesX - An Alt Coin That Is Impossible To Understand"). Over the last few months, I've been seeing a lot of spam about Tau-Chain, along with its many extravagant claims, and figured it might be interesting to try to understand it.

Disclaimer - the project appears to be delving really deep into the theoretical computer science that almost borders on philosophy. While I do have a masters degree in computer science, I can't claim I fully understand some of the topics Tau-Chain touches on or their implications. I will instead focus on more practical aspect of Tau and how it presents itself as a piece of software with practical use.

What is Tau-Chain?


So, what is Tau-Chain? Well, it's quite simple, just look at this graph from the founder of Tau:

A simple explanation of Tau-Chain...

Okay, it's not simple at all. This graph represents what sort of confusing things we're dealing with here...

From what I gathered looking at the project's website, its whitepaper, roadmap, some articles on it, listening to a LTB interview, viewing some other resources and talking briefly to the founder of Tau-Chain, I think we are dealing with two components here - Tau and Tau-Chain. Unfortunately, it seems the people involved in the project like to use those terms interchangeably and confuse everyone further.

Tau appears to be a new programming language, apparently similar to Idris. Unlike most traditional languages most programmers deal with on a daily basis, it is not turing-complete. Instead, it is a decidable programming language. What this means is that it avoids the halting problem, while still being able to do anything a finite turing machine can do. Since in practice we don't have infinite turing machines, from what I understand it should be able to do anything a turing-complete language could do. Apparently, this approach might be more secure. On top of that, Tau "has built-in P2P and blockchain".

Tau-Chain on the other hand, appears to be a sidechain-enabled blockchain that can run the Tau language. It seems to be similar to Ethereum with its contracts - both have a growing library of code embedded in it that anyone can call upon to build their code on. As I understand however, Ethereum's code can be more risky to use as you might not always be able to predict what the contract might do without its source code at hand, while Tau the language is more predictable in its execution?

The project also appears to have another component to it - the Agoras. As far as I can tell, they seem to be smart oracles that can execute various contracts and other Tau code. They appear to be able to interact with the Tau-Chain, as well as with one another directly. All in all, they remind me a lot of Codius, especially if you consider that that project aimed to be able to prove what code is being executed and so on. Not a bad feature, but there doesn't appear to be much new to talk about there.

What Tau-Chain promises


While initially researching Tau-Chain, one will stumble upon their promotional video:

Tau-Chain, solving all of your software development problems apparently...

Which lists a few outlandish claims about what Tau / Tau-Chain can deliver:

  • Software that always does what it is supposed to
  • No more bugs
  • Automatic requirement validation by the Tau client
  • It is impossible to write code that doesn't work
  • Thanks to Tau, the client doesn't need to trust the coder and vice versa
  • The payment for developing code is automatically paid when the code is verified by the Tau network
  • The Tau blockchain stores social norms, scientific theories, "whatever is based on facts and rules" (one example flashing in the video is "Once you start to eat you should never leave spoon, fork or knife on the table. Their place is on the plate.")
  • Tau-Chain code is reusable
  • Tau is a database of provably working code snippets
  • You can use the Tau-Chain to build search engines, social networks, market places
  • You can develop provable smart contracts on the Tau-Chain

As a software developer, I would take all of that with a huge grain of salt. Then again, it might be my turing-complete attitude talking and things might be different in the decidable language space. If this video was talking about traditional software languages, I would put my money on the video being about test-driven development - an approach to software development that starts with test cases (what the code should and should not do), and then developing the code to fulfil those tests. In theory this could mean that the software has no more bugs, it does what it is supposed to and can be verified automatically when new code is checked in. So while it would fulfil most of the listed requirements, in practice I would not expect it to be *the* solution to all problems - writing good test cases can be as hard and time consuming as writing good code, and I doubt 99% of the clients purchasing software would be able to use that. If the test cases aren't sufficiently complex, we might run into the problem of software being built just to tick the checkboxes and not much else. After all, any program operating on a sufficiently small domain could be replaced by a lookup table...

I am also very sceptical of how the software will decide what are the stored facts and how those will be handled and proven. Even more so when we're talking about "facts" about the real world and social norms. How do you prove you should not put used forks on the table, from a software perspective? How do you handle a problem having multiple contradictory answers (an infinite sum of (1-1+1-1...) can be proven to equal 0, 1, 0.5, -0.5, etc...)?

Some other claims I stumbled upon from other sources (1, 2, 3):
  • Tau client's behaviour is dictated on-chain, with the chain being able to hard-fork itself
  • Tau (-Chain?) has no rules at all, its users will set its behaviour
  • Tau does not need a coin, but it has a token presale anyway
  • "Tau network will be able to download virtually the whole internet, practically giving everyone the same information Google has, and more: data can be queried and processed more meaningfully and collaboratively, so you could perform queries as you like."

While there are more claims, lets just limit ourselves to those few (a lot more can be found in the LTB interview).

The Tau / Tau-Chain's feature of embedding how the network operates in the blocks themselves is rather unique feature as far as blockchains go, but at the same time it can be one of the more dangerous thing out there. It certainly offers the network more apparent freedom from Bitcoin-like hardfork stalemate, although in reality Bitcoin's hardfork problems are never about the code being hard to change, but about the people you need to convince. It might also impair some thin clients if they are applicable to the chain (how can you just run the chain from a given length if you don't know what the rules are from all of the previous blocks?). The definition of who the "users" in the system are (one-vote-per-person / machine / CPU?), as well as what the rules for hard-forks will be will probably shape the network very drastically early on. I wonder whether anyone will try to change the code of how the blocks are executed to "stop execution, return 0"...

The token presale doesn't appear to be anything new in the crypto world - it's the paradox of presales all over again. Tau the language and network doesn't need a new coin, it would probably operate better without it, but the developers need money to develop the language / network, so they sell tokens to speculators. Looks to me like another Bob Surplus-esque coin looking for a problem.

As for the last claim, and a few similar marketing blurbs, I think they deserve a section all of their own...

False equivalence, false dichotomy, eating your own dog food


The quote about basically being able to replace Google appears to be a false equivalence fallacy. There are many problems with trying to say you can basically be like Google:
  • I very much doubt the network could handle about 10 exabytes of data
  • Being able to efficiently categorize all of that data requires very smart algorithms and a lot of data. You can't even begin figuring some of the things out without having efficient access to enormous data sets. For example, how would you figure out a search for "high contrast pictures of fruit floating threateningly in the night" (thanks Reddit)?
  • Google is as much about the data (what the websites contain), as much as it is about the metadata (what the people are searching for and what they are clicking). Having just one part of that might not give you the full picture
  • Without having most of the data at hand, it is impossible to know if you returned most of the searched data. While you might be able to make queries based on the data you do know, you can never know how much you don't know
  • It is also impossible to prove that real-world data is correct. Since Tau-Chain is focused on storing "whatever is based on facts and rules", how would you be able to know, say, what is the weather outside right now? Sure, you can have a lot of data points, but you can't prove they are true or made up

All in all, statements like that are just red flags if someone also asks you for money. At best, they are marketing superlatives. So while sure, if we're talking about Tau the language, someone might use it to implement a Google-like service with it and so on, but the same could be said about computers based on cogs and wheels (after all, any turing machine is equivalent to another). All in all - false equivalence - your software is not even comparable to Google.

Now, lets finish this discussion with a subtle false dichotomy. I stumbled upon this marketing blurb about Tau from some of the spam I see pasted in a few chats I visit:


It compares how Tau-Chain is different from Ethereum, and links to a blog post by Peter Vessenes criticising how buggy some of the Ethereum smart contracts can be. He makes a lot of valid points - since you can't upgrade and fix the contract code post-launch, you either need a good failsafe, or write perfect code not to lose people's money. However, what I take slight annoyance with, is how this sort of marketing might misrepresent the situation - "Tau is different from Ethereum, here are a few reasons why. Here is someone criticising Ethereum (while not talking about Tau)", implying that since Tau was not criticised and it is presented as Ethereum's competitor, it somehow doesn't have those flaws. No Tau, criticism of your competitor does not mean you don't / won't have those problems yourself.

Lastly, I find it really amusing that Tau apparently doesn't like the taste of its own dog food - for all of its criticism of turing-complete languages, saying how Tau is a much better language and all of that, in the end they develop their code in C++. I did bring this point up to Tau's creator and he made valid points as to why that is - they want to develop the software in an efficient language to make it operate efficiently and in the future they might implement Tau-Chain in Tau. Understandably, software development takes a lot of resources and time, and you want to release early, release often, but this somehow doesn't fill me with confidence that Tau will be usable for any commercial-grade software any time soon...

Conclusions


While Tau appears to be an interesting development of a new programming language and its creator certainly sounds very knowledgeable in his field, Tau-Chain looks like a project looking for a problem. Bootstrapping a new token to run a blockchain to use a new programming language for smart contracts that don't halt seems like a very complicated way of reinventing everything just because you want to change a few things. I am highly sceptical of how the network will handle everything it promises, especially when it comes to dealing with things in the real world. It could be as mundane as a different flavour of Ethereum with a non-turing complete language, some smart oracles, etc., or something potentially new - only time will tell. Until Tau-Chain is released, I remain unconvinced.

Amusingly enough, the Tau-Chain video contains an Escher-like perpetual motion water mill at 1:40. I wonder if this is telling that the project is trying to invent something impossible?

2016-05-24

Bitcoin rivals

Recently I came by a tweet by Andreas Antonopoulos stating:

Stop calling ethereum "the bitcoin rival". No one in ethereum or bitcoin believes it is a rival. Post-national currencies are not zero-sum

Which got me thinking - can Ethereum or any other cryptocurrency be seen as a Bitcoin rival?

Bitcoin vs fiat


First, lets look at how Bitcoin competes with fiat.

Looking at the definition, a rival is defined as "A competitor with the same goal as another, or striving to attain the same thing. Defeating a rival may be a primary or necessary goal of a competitor." and "Someone or something with similar claims of quality or distinction as another.".

When talking about most fiat currencies like USD, Euro, GBP, etc., or hard assets like Gold or Silver, it might be hard to call Bitcoin a rival to those, at least so far. A lot of national and international currencies exist to facilitate trade, government programs, taxes, etc. on a scale where Bitcoin doesn't register yet. Previous metals are similarly used for some trade, as well as store of value, speculation, etc.

While Bitcoin can fulfil similar niches as those currencies, the currency would first need to rise in value a few orders of magnitude to be able to compete on the same scene. In the future, Bitcoin may be seen as a competitor to USD or Gold, but it will probably take awhile. That, however, doesn't stop it from filling in some other niches.

Bitcoin in various applications


While Bitcoin might not compete against Gold or USD, it can still catch the attention of some gold bugs, internet sellers, or the unbankables. Bitcoin might be too small to compete in the primary markets of companies like PayPal or Western Union, but it seems to be catching up in the more fringe markets.

Bitcoin vs altcoins


Bitcoin's most direct rivals would be the various altcoins.

Looking at the current cryptocurrency market, we have Bitcoin at $6.9B market cap, Ethereum at $1B, Ripple at $206M and Litecoin at $181M, with every other coin having substantially less than $100M.

Bitcoin's most direct competitor feature-wise would be Litecoin, sitting at 1/38th of the market cap. While it might be a notable currency for speculation, there doesn't seem to be as much adoption and development push from within and without the Litecoin community to say that LTC is competing with BTC. As such, it doesn't look like a potential rival for Bitcoin.

Ripple, due to the centralized control of its XRP tokens, can never hope to compete with Bitcoin. Similar to Omni and Counterparty, it might be better suited to be a Bitcoin compliment - dealing with user-created currencies, while leaving Bitcoin to be the decentralized currency.

This leaves us with the main topic - Ethereum...

Bitcoin vs Ethereum


Ethereum is a bit of a mixed bag. Its genesis block started with ~72M ETH being created for the presale (~60M ETH), the developers, and the Ethereum foundation (~12M ETH). With the current supply of 80M ETH, that presale constitutes a large chunk of the total ethers in circulation. Some might see that as premining, while others, like myself, don't see similar presales as such.

Ethers also aren't always viewed as currency, but rather as a token for executing code on Ethereum. While that might be true and some core developers might say that for legal reasons (to protect themselves from any legal fallout from the token presale), it hasn't stopped people from speculating on the value and bringing the value up more than 10 fold in the last year.

Lastly, Ethereum does a lot more with its scripting language than what Bitcoin can. Until we get something like sidechains up and running, Bitcoin will probably not be Ethereum's rival anytime soon.

However, the opposite might not be true. Ethereum has 1/7th the market supply of Bitcoin, a large community around the world, and is starting to get high-profile projects like The DAO. As such, Ethereum is shaping up to be a rival to Bitcoin.

The rivalry


With all of that being said, Ethereum and Bitcoin filling the same niche of decentralized internet currency might not be too bad. Both of the currencies still have bigger opponents to overcome on their way up - fiats, precious metals, centralized payment processors taking big cuts, etc. Success of one might not mean the loss of other. As long as both communities remain on good terms, developers, exchanges, and other crypto businesses are open to accepting both currencies, and we keep our eyes on the same target of overcoming the old way of banking, there is no reason why this rivalry couldn't be a friendly coopetition.

Conclusions


Bitcoin is not yet a rival to the big fiats or precious metals, as it is too small to register. Most altcoins aren't big enough to compete with Bitcoin. Ethereum is a potential rival to Bitcoin, but there is no reason for competing directly with one another when there are old currencies and use cases to take on first.

2016-05-16

Deniable proof of Satoshi

About two weeks ago in the Bitcoin community we were dealing with a bit of drama surrounding dr. Craig Wright claiming to be Satoshi, convincing Gavin Andresen of the fact with a shady signature, and then proceeding to be thoroughly debunked when a public proof was released. After which, Craig continued with his claim for a little while, saying he would move some old coins to prove he is indeed Satoshi, before quitting the Internet because people are such meanies.

What Craig's "signature proof" essentially looked like


One of the reasons why this hoax gained any legitimacy, was because Craig was able to convince Gavin by providing a signature of some random phrase allegedly using Satoshi's private key. However, he didn't want anyone to release that proof, so everything was done in a controlled environment and nothing was allowed to leave the room to be analysed in more detail:

Gavin explaining how Craig convinced him,
and Vitalik Buterin explaining why it was very unlikely Craig was really Satoshi

While some people blame Gavin for being duped, I personally wouldn't hold any grudges - everyone makes mistakes, it's no big deal. However, lets look at how we could prepare ourselves for when the next bidder to the title of Satoshi comes along.

Deniable proof of Satoshi


One reason why Gavin was unable to debunk the claim early was due to Craig not letting Gavin perform deeper analysis on a signature of a random phrase. This was allegedly to ensure Gavin couldn't leak the proof before the big reveal was supposed to happen. A reasonable precaution a legitimate claimant might make. If you would skip all of the drama, all the proof you would need would look like:


However, if the claimant would still insist on a big reveal or otherwise keeping his identity rather secret, /u/emansipater came up with quite a clever way to create a deniable proof of being Satoshi. Simplified:


  1. Verifier creates a random phrase, number or whatever with sufficient enough entropy
  2. They encrypt the message with Satoshi's public key
  3. They send the encrypted message to the claimant
  4. The claimant then proceeds to decrypt the message and return it unencrypted

This proves that the claimant is indeed in the possession of the private key (otherwise they wouldn't be able to decrypt anything), but at the same time the proof is completely deniable as it relies on the negative - the claimant NOT knowing what the random phrase is. As you cannot at any point prove the secret was NOT shared with anyone before being decrypted, the proof only works for you - you know you haven't released the secret, but you can't prove that.

This simple challenge would be enough to allow Gavin to have a strong proof of whether or not Craig was Satoshi, and it would allow Craig to be able to deny any leaks before doing a proper reveal. However, as his intent didn't appear to be to create a proof, but rather to deceive, obviously this wouldn't be the approach taken.

Conclusions


It is possible to create a deniable proof of owning a particular private key. Any future claims to someone being Satoshi or not should first pass through at least such a filter before they are given any credibility. Alternatively, you could just expect Satoshi to flat-out publish his proof for anyone to verify and possibly falsify without any drama.

Perhaps verifiers could also require some moderate BTC deposit (perhaps 50BTC?) before any claims are verified, to be returned if the claimant reveals themselves to be Satoshi within a certain amount of time. The deposit could either stay with the verifier, or be deposited at some Bitcoin charity.

EDIT:

The original wording of the article implied a personal attack on Gavin. It was not intentional. The sentence has been rephrased.

2016-04-25

Nobody needs Counterparty - a discussion on needs and wants

About a month ago, I had a comment exchange on /r/Bitcoin with /u/brighton36, the community director of Counterparty. A lot of different points were discussed, but the general argument was that /u/brighton36 believed that there isn't a convincing argument for the use of smart contracts and turing complete language in general, thus making Ethereum an unnecessary project. However, just like that logic could be used to claim "nobody needs Ethereum", similar logic could be used to make a statement that "nobody needs Counterparty". Lets explore whether any of this holds water...

Nobody needs Counterparty


Counterparty was launched around the start of 2014 and is one of the Crypto 2.0 platforms that runs on top of Bitcoin. Their notable feature that sets them apart from most other Crypto 2.0 platforms is their reliance of Proof-of-Burn to issue their currency. The platform offers decentralized exchange between XCP, BTC, and user created assets, although no direct asset-asset exchange, as well as some financial contracts. Their most notable and active assets include LTBCoin, Gemz and BitCrystals, which seem rather negligible in comparison to other platforms.

All in all, Counterparty is a decentralized asset issuing platform for centralized assets - loyalty points, presale currencies, etc. Since it relies on the Bitcoin network, the transactions are slower than the competition, there are no real gateways on the network offering fiat currencies. The network doesn't support asset-asset trading, making it pretty useless for direct FX trading. While Counterparty tried to woo Overstock into using its platform, but that didn't work out too well. The most notable proponent of Counterparty appears to be Adam Levine with his Tokenly project, but hearing what he aims to accomplish with it during a Decentral Vancouver meetup, both myself and other listeners said "you're reinventing Ripple!".

So in general, nobody needs Counterparty - you can issue the same currencies on faster, more established platforms, you can issue them privately on a centralized platform, on semi-centralized Open Assets, partner with some exchanges, etc. There are many other, better ways you can accomplish the same result without using Counterparty. So all in all, you don't need Counterparty, right?

Nobody needs Ethereum


In similar vein, one could criticise Ethereum's smart contracts. They offer unambiguous code execution, you know the code will not be changed during execution, and you can run long-running pieces of software that can use persistent storage on the blockchain. As /u/brighton36 pointed out:

"Unambiguous code execution is already in ubiquitous use today. Package management systems use code signing to detect whether the code being executed is asserted as valid by the issuing party. Open source scripts are in abundance. "

Beyond that, Counterparty has recreated Ethereum on its platform (and Ethereum responded in kind by recreating Counterparty in 340 lines of code). So all in all, you don't need Ethereum, right?

It's not about the need, but the want


When you think about it really, focusing on whether you need something or not because you can accomplish the same task with something else is a silly argument. That's like saying "you don't need Goland, you've got C++", or "nobody needs a screw, you can use nails". So no, nobody needs Counterparty and nobody needs Ethereum, but they are both useful tools in their own right. As long as they are functioning as intended and fulfil a need people have, not necessarily optimally, they are useful. I might prefer to use Ethereum to say, publish my blog because I can / feel like it / it's cool to do that, or Counterparty to issue my local currency because it's convenient / good enough / I like the project. Sure, you can do better in both cases, and in time you might optimize and choose a better platform, but that doesn't mean those projects aren't useful in one way or the other.

The only obvious caveat here are pumps, scams and similar attempts at getting people's money illicitly. While PayCoin might be as useful to transfer money as Tether, it wouldn't be advisable to give money to the former over the latter.

Good projects can flourish if people want to use them, or die if people don't care. Bad projects will most likely burn themselves out eventually. If Ethereum, Counterparty or whatever other project is out there is used by people, even if you can accomplish the same things with something else, let them use it. Claiming a project is "full retard" won't get you very far.

Conclusions


Claiming that "nobody needs project X" because you can accomplish the same task with some other tool or technology doesn't make the project itself useless. People might have many reasons to use the various alternatives, and as long as you can accomplish what you set out to do, that might be good enough for a lot of people.

EDIT:

- It looks like Counterparty has started supporting asset-asset exchange since the last time http://tiny.cc/Crypto was updated.
- As some have pointed out, Counterparty is also used by Storj and Spells of Genesis trading cards, although they haven't been trading much recently, hence why they weren't mentioned

More discussion on the topic can be found here:

2016-04-11

Uphold - a follow-up

Two weeks ago, I wrote a blog post about Uphold's proof of solvency. Since then, I was in contact with Rebecca Geller, a PR, and by her proxy, with Jorge Pereira, chief product & engineering officer at Uphold to discuss the recent concerns with their platform and the perceived insolvency. Having exchanged a few lengthy emails, I would like to present what I learned about the situation and give a more informed opinion on the matter.

Voxels


While Voxels appeared to be an important part of the insolvency claim early on, they don't seem to play an important part anymore. As they are currently held separate from the main currencies and not counted towards the solvency anymore, it should be impossible for them to be used as an asset to cover the liabilities of currencies other than itself.

It is very unfortunate there isn't much publicly available historical data to draw on in trying to evaluate whether the Voxel balance was consistently counted towards the solvency proof when other assets were not enough to cover the difference, or was 2016-02-14 an anomaly. While archive.org does have some records of that page from before February, it doesn't render correctly. Retrieval of the data would be possible, but would take a skilled web developer to decipher. Perhaps in the future, we could see the transparency data being regularly exported to say, Factom, where it could be used for analysis in the future (disclaimer - I work at Factom).

Beyond that, Uphold handling Voxels appears to be a simple deal - Voxelus paying Uphold to list and handle their currency, handle the currency conversion, etc. As long as the currency itself is handled separately from everything else, I personally see nothing wrong or shady in the arrangement.

$38k deficit into a $57k surplus


While the Voxels can be ignored, we are still left with probably the main problem that needs addressing - the $38k deficit turning into a $57k surplus.

On 2016-02-14, Uphold's total obligations to their members was $115M, and assets - $116M. Subtracting the value of Voxels ($109M, $110M), the totals were $5.7M and $5.6M, with a deficit of $38'145.29. On 2016-03-27 Uphold's total reserves were $5'359'978.76 in obligations and $5'417'435.54 in assets, with a surplus of $57'456.78.

In other words, $95k worth of assets appeared seemingly out of nowhere in a span of a month and a bit. This either meant that either:
  1. Voxels were indeed counted towards the solvency in February
  2. The transparency website misreported some numbers
  3. The balances were mismatched due to some recent trades or money movement
  4. The numbers were fabricated
Either one of the four outcomes would show the platform in an unfavourable light, but some would be more damning than the others. 

Uphold explained the issue with option number 3 - the money was in transit between bank accounts and exchanges, and thus wasn't taken into account by the automated system tallying everything and publishing the numbers onto the transparency page. When asked for a proof that the funds were indeed in transit at the time, instead I received an a reply of

"To some extent, that’s a fair request, but if you trust the data illustrating what is perceived as a shortage of $38k, it’d stand to reason you’d trust the same source presenting an additional explanation, particularly seeing as the issue resolved itself within hours. The explanation we have provided rests on the same logic and transparency as the data you believed that illustrated the shortage."

Shorting Bitcoin, speculating with customers' funds


Another important accusation levelled against Uphold was the issue of their Bitcoin balances being short in favour of fiat currencies.

On 2016-02-14 Uphold's BTC obligations were listed as 5'834.056BTC, and their assets as 4'594.390BTC, short 1'239.666BTC, or 21.25%. On 2016-03-27, their BTC obligations were listed at 4'944.479BTC and assets at 3'652.980BTC, short 1'291.499BTC or 26.12%.

This raises a few questions - why was this done in the first place, what was the contingency plan in case of a price swing (with their $57k surplus, a 44.5BTC/USD price swing would turn the website insolvent again) as well as whether the company is speculating using their customer funds.

The reasoning behind the short balance was stated as trading sideways to save on exchange fees. As Uphold doesn't charge a conversion fee, they focus on lowering their operational costs by not immediately covering their customers' trades. In a perfect system, the trades would be going back and forth, allowing Uphold to only correct a fraction of the total trade amount on an external exchange, thus lowering the fees they pay. However, when the trades are more one-sided, the balance discrepancy grows further and further apart and needs to be corrected eventually.

Second question had a fairly straightforward answer - stop-loss mechanism. When the price swings too wildly, automatic trades are executed to protect the reserves.

Lastly, the company stated it does not condone the practice of speculating with one's customers' funds without an explicit permission from them. As such, Uphold is claiming not to engage in such a practice, and does not aim to make a profit by being over-exposed to one currency or another.

All in all, we seem to be running into the main trade-off that might have been the cause of this BTC shortage - whether one should prioritize keeping the fees low, or the reserves rigid. Neither one is a wrong answer - they both have their merits and drawbacks, but they do send a message about the company's priorities and values.

Interestingly enough, between 2016-03-27 and 2016-04-01, during my email exchange with Uphold, their BTC reserves seem to have corrected themselves:

Uphold BTC balance, 2014-04-01

Whether this balance correction was coincidental after over a month of running on a BTC deficit, or it was a deliberate action by the company, it can be hard to prove. Despite asking about "What is the threshold before your company would consider itself over-exposed on Bitcoin?", no direct answer was provided. At least I can take comfort in Uphold's statement to consider their BTC reserves more closely:

"This is feedback we’ll incorporate, and in all likelihood will just result in us adding a bit more of our own funds to the reserve surplus on the asset side of Bitcoin, to ensure it’s always close to over-reserved. "

Proof vs claim


A few times during the email exchange the topic of proofs came up. As Uphold is focusing on providing "a public, real-time, traceable and verifiable proof of solvency", it is important to distinguish between what constitutes a proof, and what is just a claim.

A proof needs to be independently verifiable and falsifiable, while a claim does not. Whether you use a send-to-self transaction, use a set of addresses and balances, or do something else an independent third party (or better yet, the public) can verify and possibly disprove, that can constitute a proof. Self-reported balances as is the case with Uphold's current transparency page, do not constitute any proof, but are merely a claim of solvency.

While Uphold is claiming that their reserves are independently audited on a quarterly basis and are currently working on publishing those audits in the future, as of the time of writing, I have no evidence of this, despite Uphold being asked to provide "independent, verifiable, sources for the information" for this article. I would exercise caution until such proofs are provided, even if this might be erring on the side of overt caution.

All in all, in an ideal world, I would like to see the following proofs:
  • Proof of liabilities - allowing anyone to verify that their assets are counted in Uphold's total liabilities and that everything adds up
  • Proof of reserves - independently verifiable proof that Uphold does indeed own the stated currencies and assets, crypto or otherwise
  • Proof of existence / records - Ideally, the other proofs would be timestamped or published on a platform like Factom to prove they weren't altered in the future
  • Proof of exchange rate - while one is able to claim they are not charging an exchange fee, a crafty party could hide the fee in the exchange rate spread and charge it covertly. While I don't know of any company that incorporates such proof, shy of using an open ledger, it might be a mark of the highest standards of transparency

At the current time, one can only wait for the first two or three to be eventually published...

Everything else


During the email exchange, a few less important topics were discussed. Some of the statements make the company appear fragile to criticism:

When asked whether Uphold stands by their CEO's tweet labeling the first Reddit post about the company's possible insolvency as "ridiculous, untrue & libellous lies", I was reassured:

"Absolutely, and it’s unfortunate that people end up misinterpreting the information we make available in good faith, without offering us the chance to clarify it. I can understand the confusion regarding VOX, and I hope our updates  address that.
Our CEO Anthony Watson is an award winning social  advocate, who does a great deal of good in the world to support people's basic human rights. He’s got no interest engaging with an anonymous Reddit poster who set up an account up several hours before he made this post seemingly only to cast doubt upon Uphold, without making any effort to engage with us to clear up these questions. "

The middle part seems like an appeal to emotion. In their closing remark, another two quotes appear to be putting the company in a victim role:

"[...] while some people may see us as “just a corporation”, we instead see ourselves as a group of people on a mission. We want to do the right thing, and being so poorly perceived is damaging to the morale of those working hard to make Uphold a reality. "
 "[...] We’re building bridges, so we’re bound to find trolls, but we see no value in taking part of a conversation where the conclusion has been decided beforehand and there is no opportunity for open dialogue."

While I'm glad that despite that the company decided to address some of those criticism in their blog post as well as answer my doubts and questions on the matter, failing to address the criticism head on because they came from an anonymous user while taking that criticism to heart and letting it lower your morale might not be the healthiest approach to take on the Internet.

Conclusions


Having had the chance to discuss the insolvency accusations with Uphold, I remain cautiously optimistic for their platform and their customers.

While they failed to provide any verifiable proof of their platform's solvency or where the $95k of extra solvency came from between February and March, their promise of publishing audits in the future might address similar issues in the future. 

Uphold's changed commitment to maintaining a more rigid BTC balance should similarly keep that issue from cropping up again.

While the company might not wish to engage "trolls" raising criticisms of their platform, it is at least good to see them addressing the concerns raised and improving themselves based on that feedback. One could see it as either being wise enough to reconsider one's stance, or desperate enough to pander to critics however.

So here's for hoping we'll get our proof of solvency soon enough and Uphold will be a shining example of transparency, rather than turning into another cautionary tale in the Bitcoin world.

2016-04-04

Transaction data vs metadata - interpreting what has happened

With Bitcoin as well as most "Crypto 1.0" currencies, the transactions are simple and elegant. You specify which coins you're spending, what are the redemption requirements, and that's about it. A transaction either goes through, is included in a block and can be spent, or it never gets included and can be safely ignored. However, when we look at the more complex Crypto 2.0 systems, things start to get more complicated - there are many more states a transaction can be in, and we require additional metadata to figure out what really happened.

Transaction data vs metadata


The way Ripple handles its transactions is a good example of the data vs metadata. When submitting a transaction, we submit its data - our intent of what we want the transaction to do. For example:


{
"TransactionType" : "Payment",
"Account" : "rf1BiGeXwwQoi8Z2ueFYTEXSwuJYfV2Jpn",
"Destination" : "ra5nK24KXen9AHvsdFTKHSANinZseWnPcX",
"Amount" : {
  "currency" : "USD",
  "value" : "1",
  "issuer" : "rf1BiGeXwwQoi8Z2ueFYTEXSwuJYfV2Jpn"
},
"Fee": "10",
"Flags": 2147483648,
"Sequence": 2,
}

Indicates that we want to send 1USD from rf1... to ra5... and we pay the fee of 10. Now, when we submit the actual transaction, we also see its metadata:

{
  "id": 6,
  "status": "success",
  "type": "response",
  "result": {
    "Account": "rf1BiGeXwwQoi8Z2ueFYTEXSwuJYfV2Jpn",
    "Amount": {
      "currency": "USD",
      "issuer": "rf1BiGeXwwQoi8Z2ueFYTEXSwuJYfV2Jpn",
      "value": "1"
    },
    "Destination": "ra5nK24KXen9AHvsdFTKHSANinZseWnPcX",
    "Fee": "10",
    "Flags": 2147483648,
    "Sequence": 2,
    "SigningPubKey": "03AB40A0490F9B7ED8DF29D246BF2D6269820A0EE7742ACDD457BEA7C7D0931EDB",
    "TransactionType": "Payment",
    "TxnSignature": "3045022100D64A32A506B86E880480CCB846EFA3F9665C9B11FDCA35D7124F53C486CC1D0402206EC8663308D91C928D1FDA498C3A2F8DD105211B9D90F4ECFD75172BAE733340",
    "date": 455224610,
    "hash": "33EA42FC7A06F062A7B843AF4DC7C0AB00D6644DFDF4C5D354A87C035813D321",
    "inLedger": 7013674,
    "ledger_index": 7013674,
    "meta": {
      "AffectedNodes": [
        {
          "ModifiedNode": {
            "FinalFields": {
              "Account": "rf1BiGeXwwQoi8Z2ueFYTEXSwuJYfV2Jpn",
              "Balance": "99999980",
              "Flags": 0,
              "OwnerCount": 0,
              "Sequence": 3
            },
            "LedgerEntryType": "AccountRoot",
            "LedgerIndex": "13F1A95D7AAB7108D5CE7EEAF504B2894B8C674E6D68499076441C4837282BF8",
            "PreviousFields": {
              "Balance": "99999990",
              "Sequence": 2
            },
            "PreviousTxnID": "7BF105CFE4EFE78ADB63FE4E03A851440551FE189FD4B51CAAD9279C9F534F0E",
            "PreviousTxnLgrSeq": 6979192
          }
        },
        {
          "ModifiedNode": {
            "FinalFields": {
              "Balance": {
                "currency": "USD",
                "issuer": "rrrrrrrrrrrrrrrrrrrrBZbvji",
                "value": "2"
              },
              "Flags": 65536,
              "HighLimit": {
                "currency": "USD",
                "issuer": "rf1BiGeXwwQoi8Z2ueFYTEXSwuJYfV2Jpn",
                "value": "0"
              },
              "HighNode": "0000000000000000",
              "LowLimit": {
                "currency": "USD",
                "issuer": "ra5nK24KXen9AHvsdFTKHSANinZseWnPcX",
                "value": "100"
              },
              "LowNode": "0000000000000000"
            },
            "LedgerEntryType": "RippleState",
            "LedgerIndex": "96D2F43BA7AE7193EC59E5E7DDB26A9D786AB1F7C580E030E7D2FF5233DA01E9",
            "PreviousFields": {
              "Balance": {
                "currency": "USD",
                "issuer": "rrrrrrrrrrrrrrrrrrrrBZbvji",
                "value": "1"
              }
            },
            "PreviousTxnID": "7BF105CFE4EFE78ADB63FE4E03A851440551FE189FD4B51CAAD9279C9F534F0E",
            "PreviousTxnLgrSeq": 6979192
          }
        }
      ],
      "TransactionIndex": 0,
      "TransactionResult": "tesSUCCESS"
    },
    "validated": true
  }
}

Which specifies, among other things, AffectedNodes - the actual state change exacted on the system. It specifies the balance change of multiple addresses the transaction rippled through. This can be especially important when there are multiple paths a transaction could take, possibly even spanning many different currencies and entities.

How Ripple Works - Gateways and Pathways

All in all:
  • Transaction data specifies what we want the system to do
  • Transaction metadata specifies what did happen in the system

Lets look at a few examples of why this distinction is important.

Blockchain interpretation in Bitcoin 2.0


Some people use the term "Bitcoin 2.0" and "Crypto 2.0" interchangeably. I personally make the distinction of using the first term only when referring to systems built on top of Bitcoin itself - Mastercoin/Omni, Counterparty, Colored Coins, etc., while using the second term for all cryptocurrency systems allowing one to issue custom currencies (which includes Bitcoin 2.0s as well as systems like Ripple, Ethereum, etc.).

The distinction is important here because Bitcoin 2.0 systems inherently have no control over which of their transactions are included in the Bitcoin blockchain they are using. Unlike Bitcoin, two conflicting transactions can be included in the block and the system has to be able to interpret them correctly. Without transaction metadata, it is hard to tell at a glance whether a transaction is valid and spendable, or whether it is a double-spend and should be ignored.

A cautionary tale of the partial payment flag


In 2014 JustCoin, a Ripple gateway, got into a lot of trouble due to a small feature in Ripple very few people noticed before then - the partial payment flag. When a transaction is created with that flag, it signals to the network "I want to pay the person as much as I can up to the limit specified", rather than "I want to pay the person exactly this much". So for example if my transaction data specifies the amount I'm paying to be 1'000'000USD, but my balance is only 10USD, without the partial payment flag the transaction would fail, and with the flag it would succeed but only give a person 10USD.

The big problem JustCoin ran into was that the transaction data still would quote the big number, even if very little was sent, and only by examining the metadata would they be able to see how much money was actually sent. This meant their attackers could rack up bogus deposits and cash out of the gateway, leaving it short on funds.

Transaction successful, payment failed


While working on a Ripple gateway in the past, I got to explore a few different end states a transaction can end up in - a transaction can be not included in a block and be in an undefined state, it can be included in a block and be successfully applied, included in a block and partially applied (partial payment, open exchange), or it can be included in a block but still fail. In the context of Bitcoin, the last state would be unthinkable.

A scenario where a transaction is not applied to a block is similar to Bitcoin's unconfirmed transaction - it is in a state of limbo. However, with Bitcoin one can still spend other outputs without worrying about the transactions interfering with one another - each transaction output can be spent independently. For systems relying on address balances rather than transaction outputs, a dangling transaction can be a blocker. This is why professional transactions are sent with an expiration date (after which the transaction will definitely fail and not do anything), as well as sending a NOP transaction to overwrite the expired transactions to allow everything else to go through.

Successful transactions that applied fully are pretty straightforward - everything went through (or as much as could in case of partial payment flags).

Open-ended transactions are initialized by one transaction, but end up being fulfilled by other transactions. This applies mostly to the decentralized exchange offers - it's similar to placing a bid on a market and waiting for one or more asks to fulfill it. The transaction only closes when it is fully fulfilled, or it becomes invalid due to low balance, etc.

Failed transactions being included in a block mostly apply to Bitcoin 2.0s and balance-based cryptocurrencies. Those transactions either are inevitable - any valid Bitcoin transaction can be included in a Bitcoin block, but it can be an invalid Omni transaction -, or they are there for simplicity's sake - to do nothing, consume a sequence number and allow next transactions to be committed.

Conclusions


Transaction data specifies what we want the system to do, while transaction metadata specifies what did happen in the system. While not as important to Bitcoin and other first generation cryptos, the transaction metadata becomes more and more important for more complex Crypto 2.0 systems.

2016-03-28

How not to do Proof of Reserves - a look at Uphold / BitReserve

Uphold, formerly known as BitReserve, recently came into some people's attention thanks to a Reddit user by the handle of askwhy10, who noticed the company might be somewhat insolvent according to their own Proof of Solvency. Anyone that has been around the Bitcoin world when MtGox has collapsed will know how important maintaining solvency is in our little corner of the world. But before we delve into that issue, lets have a retrospective on Uphold / BitReserve.

What is BitReserve?


BitReserve has been an interesting project for me to observe from a distance every now and then. Early on it was mostly a project about creating hedged accounts - you would deposit BTC, and then you could convert it over to USD or other currencies. In that sense it was similar to Locks from Coinapult or CoinJar's Hedged Accounts - BitReserve would dictate the exchange price, and it looks like you could only move money in and out of the system using BTC. One advantage it had over the other hedged accounts at the time was that one could transact directly in those hedged currencies, making it a bit more usable.

While lacking the free flow and exchange of money that systems like Ripple provided with their gateways, BitReserve still had a good idea to focus on the Proof of Reserves / Proof of Solvency to avoid insolvency:

"What people do with their money is their business,
what we do with people's money is everyone's business"

As BitReserve put it: "When you transfer your Bitcoin to your dollar card, we actually take your bitcoin and we sell it and we put those dollars in our reserve. And then, through our transparency system, we show that you are now actually holding dollars, not Bitcoin.", etc.

It is a very reasonable strategy for any financial service to take. In the Bitcoin world, you don't want to get caught in a swing holding the wrong currency and end up insolvent like MtGox. As long as you have 100+% reserves on all outstanding balances in all currencies, you can call yourself solvent. If you want to be strict about it, you combine Proof of Reserves with Proof of Liabilities, etc. So, how solvent is BitReserve / Uphold?

Uphold's solvency question


BitReserve, rebranded as Uphold in late 2015, seems to have shifted their focus away from Bitcoin and focus more on a PayPal-like model - allowing users to directly deposit and withdraw in fiat currencies as well as precious metals. They also seem to have expanded their trademarks to include such entries as bitdollar, bitgold, bitelectrum, reservechain, reserveledger, etc. and getting on the bad side of people like Andreas Antonopoulos. But lets go back to the issue of solvency.

Askwhy10 has made a post on 2016-02-15, in which he calculated that Uphold was insolvent at the time. It was short about $120k out of its expected balance of $5.6M (without Voxels, more on that later), so about 2% of total money was missing. But that was the total difference in balances. Looking at individual currencies, the company had only 4'594 out of 5'834 BTC (short 1'240BTC, 21%, or just shy of $500k). Missing 21% of your reserves in a currency that can swing by 10+% on a rough day is essentially gambling!

Uphold's BTC balance, 2016-02-14.
Columns: Currency, Obligations to our Members, Assets in Reserve, Exchange Rate.



Despite those glaring omissions, Uphold's transparency page on 2016-02-14 stated it had "101.0% Full reserve status". Most of that came in the form of Voxels, an "official coin of virtual reality".

Reading into this I am reminded of the timeless Bitcoin tale - "Story of Bob Surplus", wherein an altcoin pumper would create elaborate stories to attach to worthless currencies in order to pump them. Voxels looks like an altcoin looking for a problem - in this case, "wouldn't it make sense if Unity's Asset Store had it's own currency?", missing the point that you can just use Bitcoin...

Going back to our topic, with $350k worth of Voxels sold at the presale, Uphold evaluated that their share is worth, I kid you not, $110M. They hold 314 times the value of Voxels as were sold at the entire presale, with a surplus of $1.2M:

Uphold's Voxel balance, 2016-02-14

As the story went on, Uphold apparently became solvent again within a day of askwhy10's post, has removed Voxels from their transparency page, but they apparently are still going short on Bitcoin (holding 3'652 out of 4'944 BTC, 1'292 BTC or 26% short, worth $537k):

Uphold's BTC balance, 2016-03-27

While it may be understandable to hold some small imbalances between a few fiat currencies that won't swing more than a few percent per day in relation to one another, having such a short position on Bitcoin is a MtGox waiting to happen. At least Uphold is insignificant in the Bitcoin economy, but if I were someone holding Voxels...

Conclusions


Any company that doesn't hold at least 100% reserves on EVERY currency it operates in is gambling with their customer's money at least, and posing themselves to be the next MtGox at worst. Full Proof of Solvency is a requirement we should challenge all Bitcoin financial companies with and not accept any shortcomings or deficiencies. Lastly, if a company's CEO thinks Bitcoin won't exist in five years, especially if they are going short on BTC, they are not running a Bitcoin-friendly company and don't deserve your business.

Related discussions: