Devreal

Bridging the gap between untrusting devs and trust-seeking users

Event: Blockchain: Rethink Trust

Rethink Trust 2018: Yonatan Sompolinsky, Bridging the gap: untrusting devs and trust seeking users

Recording: Rethink Trust 2018: Yonatan Sompolinsky, Bridging the gap: untrusting devs and trust seeking users

okay so thank you for the intro a bit background about myself and my project I'm not sure okay so I'm a PhD student in the computer science in Hebrew University my research was focused for the last six years I guess replacing working and improving satoshis proof of work paradigm and protocols it began with ghost Protocol which were presented in around 2013-14 aetherium implemented a version of this to some extent inclusive Spectre which represented in scaling between Hong Kong and recently phantom which represented in in Stanford B pace so we kind of let me give you just the gist of what these protocols are about so this won't be a technical talk it's just to get the flavor of what what's going on here so as most of you know the operation of Bitcoin is a block chain a chain of blocks and when a miner gets a block it extends the tip of the chain so you have this nice chain of blocks but in the block back pad I'm instead of extending a single chain of blocks this new block on the right on your right so it's time time flows from the left to the right this is the genisis block this is a new block the miner mines instead of extending the longest chain of blocks it extends the entire graph of blocks it observes so this is the block that / time what's interesting about it is that it helps you scale up so there's this parameter K which sort of represents how how intense is the mining in the dag so you see a block chain on the top on the top left a block chain is sort of a trivial block dag just a slow grab four blocks but you can increase the scalability of the system and then you have this smaller graph over there which grows actually faster and just imagine here ten blocks per second in the network this is what you'll see so again one block let's say one block for ten minutes this is a chain of blocks but ten blocks per second this roughly will look like this why different miners in the network will receive different versions of the other blockchain so we have to have to merge everything into the same graph so this is towards this is aimed at scaling up the blockchain okay so so this may or may not look cool but this is not the main challenge the main challenge of a block dag is to recover consistency so in this large graph there may be many conflicts many double spans and you have to have some protocol that recovers consistency and says okay there are double spans but what's so what's what version of the transactions remain and what are rejected okay so to that end we devised protocols in the Hebrew University it's a joint work with several people in the Hebrew University myself my advisor of Zohar another colleague Yad Laurinburg and these are Specter and phantom protocols which again represented in several venues and this won't be the topic of today's talk so this will be the last technical slide for today ok so in the remaining time let me outline what I want to take home key messages I want to talk about today block sharing versus change allows databases what's the value proposition of trust lessness the fact that trust exists sorry in the Bitcoin ecosystem as well and some conclusions about the two-layer approach okay so this this is sort of a trivial slide that is hard to convince people it's sort of paradoxical so anyone who knows blockchain internally acknowledges that it is in and of itself a technology a database technology that is inferior to any centralized database now there are many talks in the community how to scale up the system but we must acknowledge that any scaling technology will forever lose to visa technology and we'll get to it shortly why but and it is not a prediction about adoption this is a prediction about this is a statement about the technology itself and and the reason is that because we are trying to build a trust list system this trustless implies lots of scalability limitations which visa doesn't have so any feature that visa will that blockchain will have visa will probably copy scalability wise so today the it's ten thousand transactions the capability of visa at least bitcoin is not near that so whenever someone says you know we have a blockchain is more secure it's not more secure per se it's not more private person and it's slower but still it's very valuable so the main value proposition is that we can achieve many properties of databases some emphasize more the financial aspect in a trustless manner and as computer scientists we prefer to define what trustless means so some loose define definition here if at least in order to disrupt the operation an attacker needs to control a large portion of the resources in proof-of-work this is the computational resources in proof-of-work needs to control a large large portion of the stake in delegated proofs take it's more it's more refined it's more subtle so this is trustless this is a trustless agenda and why why it is good so first maybe why why is it bad it's very expensive to be trustless so if you're paranoid if you want to verify every single bit of the system this causes the main stability limitations okay so for instance in in Bitcoin every node verifies everything so this is one limitation and moreover every node at least originally stores all the data all the historical data for the sole reason that if you let's say join in 2018 so the Bitcoin network the assumption is we have to prove to you the validity of the entire history so imagine this is a very radical and strict paradigm someone missed out Bitcoin for ten years that's ok maybe he was young maybe who's conservative and then 10 years later he joins the network and then he asks everyone to send to prove the entire history was correct and this assumption implies that in these 10 years between 2009 and today we all stored everything just to accommodate this new this new node to help him to help it on board so this is part of the trustless you know scalability imitations of course people understand that it's not sustainable so there's pruning pruning for nodes and there's charting where not everyone verifies everything but all of these are are relaxing the trustless agenda right so any solution to scalability in this manner is essentially saying okay you have to trust something in order to play the game for instance if you're a new node you have to trust that everything is okay so far we'll get to it maybe later so I thought maybe to share with you some tweets or messages of community leaders why trustless is important so Zuko if you're not familiar he is he's a CEO and founder of Z cash and his nice statement is my position is we should reduce reliance on X is true for all X meaning this is like we don't want if we can't remove trust for up any sort we should remove it so this is Zuko's sort of one of his quotes I like and then there's another longer quote by Greg Maxwell former CTO of block stream and this is an interesting statement I've founded some Bitcoin dev lists and he says now that justifies justified trust is a bad thing but trust makes system brittle or pay can cost operate trust failures result in systemic collapses and naturally arising trust choke points can be abused to deny access of the process so this is a more holistic view that trust is may be justified can be justified can't be operate in a good manner but but it's very costly in and of itself so maybe Trust is is cheaper that's at least what's hinted here this is another argument so in the latest there's a latest scandal in blockchain industry some would say regarding iOS where some block producer had has been supposedly abused or harassed and inside here is that these in heels there's some committee that's votes about stuff I don't get it in detail but the fact that these their identities are not anonymous means that people can you know what's up you hey why didn't you vote like I did you know you can get an email someone can knock on your door it's not like proof-of-work proof-of-work you have this this bunch of minors you're not sure where they are where they're coming from some of they have explicitly covert covert setups so you don't know who they are you can't you can't approach them if they're not willing if they're not accepting that so it's it's another reason why trustless has value and another final argument is that everyone abuser trust things but we don't trust the same thing so in in in China WeChat pay and Alipay are extremely common but in the u.s. they're not in Europe I guess they are not so in short users trust but they don't trust the same things so that's one main reason why I want a trust was paradigm trust less platform interest interestingly there are trust points even in blockchain so there's an interesting lecture by a sociologist researcher from Durham University which goes to explain how Trust is actually how users actually when the user system need to rely on trust this is something that maybe devs don't understand as users understand for instance she highlights the fact that if there's a hack in Bitcoin the users perceive it as a hack devs perceive it as this wasn't a hack and the Bitcoin protocol was a hack and the way you used it but the user doesn't care about this distinction so this is an interesting gap between how devs view the system and how users view it I recommend following her work there are other ways to see that trust - to utilize trust in Bitcoin system the main idea is if you want to scale up the system as I said previously you have to give up and some assumptions the most common one which Satoshi himself already proposed it's the SPV node SPV node is a node so if you're let's say a home user and you're not interested in verifying everything but you're still somewhat paranoid and you want to verify that your transactions are included in the blockchain what you do is you open a node and you ask people to send you you ask peers to send you the blockchain you verify only that you've got the most updated version of the blockchain you don't verify everything and you verify that your own transactions are embedded in the blockchain so again you verify two things you're verified that you got the most recent blockchain version and you verify that your transaction is accepted but you're not verifying that that everything is correct and another interesting point is when you connect to the Bitcoin network how do you know how do you know who that you're getting the right Bitcoin so let's say we convince you to onboard and Bitcoin and then I send you some some assyrian blockchain so so the way you have to have some anchor of trust some external anchor of trust where you know you call your friend you say hey ice any connected to the Bitcoin network here's the hash of block number this is the block height here's its hash and Mike am i observing am i viewing the right network so this is this is something that you know it's another trust point in in Bitcoin and in any system so you can't totally eliminate trust I'll skip some some things there's a lot of talk in the Bitcoin community about layer 2 I'm sure you heard you heard of lighting network in lighting network there's it's a it's a huge boost to scalability on the other hand there's some limitations one limitation is that the user needs to be online after that for a certain line for a certain period of time after the transaction is after the channel or after operation transactions and the way you really do it is you ask someone else to watch for you to have your back for instance essentially so this is like Watchtower and lighting Network this is also a point of trust there are some in coin custody there are some protocols of trust where you ask the exchange to hold your your coins for you let me finish with the general framework of trust and some computer science point of view so in general there's two layers in Bitcoin there's the base layer the the hard core protocol and this needs to be trustless it needs to be trustless for the various reasons we mentioned and and more than trustless or in addition to tortoise nests it has to has another property and that is simplicity so I don't have the time to do the survey here but I'm sure many of you can explain or can can look at Wikipedia very shortly how Bitcoin the consensus protocol on Bitcoin works everyone creates everyone creates a block and there's a longest chain but new new protocols for scalability like proof of stake like other protocols are less less easy to to to convince I'm not sure how many people here understand proof of stake so it's when you don't understand it's it's harder to to build trust but from the user point of view user doesn't need to have trust in the program if the hedge was in the entire ecosystem okay so there's the the devs and the technical community which needs to trust the protocol and that the user which need to trust the entire ecosystem that operates correctly I don't have time for more details about this but in Dague labs we are implementing such paradigms of two layers and trying to tackle various scalability and to choose a good trade-off between total trust lessness and high scalability so thank you for your listening [Applause]