1
00:00:00,420 --> 00:00:04,200
So the last topic in this lecture about
mining will be mining incentives and

2
00:00:04,200 --> 00:00:04,920
strategies.

3
00:00:05,920 --> 00:00:07,980
So what do I mean by mining strategies?

4
00:00:09,350 --> 00:00:11,990
I've spent most of this
lecture talking about how

5
00:00:11,990 --> 00:00:15,830
the main challenge of being a miner
is to get some good hardware,

6
00:00:15,830 --> 00:00:20,419
get some cheap electricity, run as fast
as you can and hope for some good luck.

7
00:00:22,240 --> 00:00:25,380
But it turns out there's also some
interesting strategic considerations

8
00:00:25,380 --> 00:00:30,260
that every miner has to make,
before they pick which blocks to work on.

9
00:00:31,940 --> 00:00:33,070
So in particular,

10
00:00:33,070 --> 00:00:37,310
miners get to choose which transactions
they want to include in a block.

11
00:00:37,310 --> 00:00:40,890
The default strategy is to
include any transaction that

12
00:00:40,890 --> 00:00:43,510
includes higher than some
minimum transaction fee.

13
00:00:44,610 --> 00:00:48,440
Miners get to decide which block
they want to mine on top of.

14
00:00:48,440 --> 00:00:51,980
And the default behavior there is
to choose whatever the longest

15
00:00:51,980 --> 00:00:55,190
current chain is that's been announced.

16
00:00:55,190 --> 00:00:58,430
Miners have to choose how to decide
between two colliding blocks

17
00:00:58,430 --> 00:00:59,230
when they get announced.

18
00:00:59,230 --> 00:01:04,120
So if two people find blocks around
the same time, miners have to decide

19
00:01:04,120 --> 00:01:09,090
which block to extend, because both
will be the longest chain in history.

20
00:01:10,330 --> 00:01:12,880
And miners have to decide
when to announce new blocks.

21
00:01:12,880 --> 00:01:16,559
They can choose to find a block and wait
before actually announcing it to others.

22
00:01:18,590 --> 00:01:22,600
So in each case there's a default strategy
which is what most miners are currently

23
00:01:22,600 --> 00:01:25,490
doing because they won
the default Bitcoin client.

24
00:01:25,490 --> 00:01:28,650
Remember it's about 90% of
fully validating nodes around

25
00:01:28,650 --> 00:01:29,980
the default client.

26
00:01:29,980 --> 00:01:33,500
It's not clear what proportion
of mining power that represents,

27
00:01:33,500 --> 00:01:35,829
but it's safe to assume that
it's probably a majority.

28
00:01:36,860 --> 00:01:39,290
So most miners are doing
this default strategy.

29
00:01:40,320 --> 00:01:42,510
So what if you want to change
some of those decisions?

30
00:01:43,780 --> 00:01:47,520
Can you make more money as a miner if you
implement some other strategy besides

31
00:01:47,520 --> 00:01:48,270
the default one?

32
00:01:50,520 --> 00:01:54,250
Well, it's all going to depend on how
much mining power you actually have.

33
00:01:54,250 --> 00:01:57,950
And we'll express that with the parameter
alpha from zero to one, which is

34
00:01:57,950 --> 00:02:03,030
the proportion of all the mining capacity
in the world that you actually control.

35
00:02:04,810 --> 00:02:07,960
It turns out for some alpha, yes,

36
00:02:07,960 --> 00:02:11,270
you can make more money by
implementing a non-default strategy.

37
00:02:12,490 --> 00:02:14,790
Although the analysis is still ongoing, so

38
00:02:14,790 --> 00:02:17,570
this is very much new
under development stuff.

39
00:02:19,610 --> 00:02:22,490
So the simplest attack
is a forking attack.

40
00:02:24,460 --> 00:02:28,790
And the idea here is to
perform a double-spend.

41
00:02:28,790 --> 00:02:31,480
So we have a valid state of
the block chain here, and

42
00:02:31,480 --> 00:02:34,660
the miner will send money to some victim,
Bob.

43
00:02:36,800 --> 00:02:40,210
So it may look as if that transaction,
sending money to Bob,

44
00:02:40,210 --> 00:02:41,730
is in the valid longest chain.

45
00:02:43,140 --> 00:02:48,080
Now this forking miner is going to
then work on an earlier block.

46
00:02:48,080 --> 00:02:51,820
And to do this in practice it would need
to be about six blocks earlier based on

47
00:02:51,820 --> 00:02:55,010
the standard number of confirmations
that people usually wait before

48
00:02:55,010 --> 00:02:56,566
accepting that a payment is final.

49
00:02:56,566 --> 00:03:00,450
And then the miner will
insert an alternate payment

50
00:03:00,450 --> 00:03:03,829
where they keep the money for themself by
transferring it to a different address.

51
00:03:05,390 --> 00:03:10,230
Now at this point that block won't be
valid since it builds on an earlier point.

52
00:03:10,230 --> 00:03:14,190
In the block chain, it doesn't represent
the longest possible chain of blocks.

53
00:03:15,390 --> 00:03:22,010
But, if you have a majority of hash power,
if alpha is greater that .5, eventually

54
00:03:23,400 --> 00:03:27,400
your alternate chain will be longer than
what was previously the longest chain.

55
00:03:27,400 --> 00:03:32,150
And at this point, your longest chain
now becomes the valid block chain.

56
00:03:33,330 --> 00:03:35,040
So you've rewritten history.

57
00:03:35,040 --> 00:03:39,600
You've removed that payment that you made
to Bob, and you've now kept that money for

58
00:03:39,600 --> 00:03:40,150
yourself.

59
00:03:42,210 --> 00:03:44,600
And if your target had given
you something in exchange for

60
00:03:44,600 --> 00:03:48,730
those bitcoins, preferably real currency
or some kind of goods in the real world

61
00:03:48,730 --> 00:03:52,900
that they can't easily take back,
then you've swindled them.

62
00:03:52,900 --> 00:03:55,530
And this is a way that you can

63
00:03:55,530 --> 00:03:58,400
profit if you have a majority
of power in the network.

64
00:04:01,060 --> 00:04:04,930
So like I said, this attack is certainly
possible if alpha is greater than 0.5.

65
00:04:04,930 --> 00:04:09,500
If you have the majority of the mining
power, it might be possible in practice

66
00:04:09,500 --> 00:04:13,960
with a little bit less, because of things
like network overhead and the fact that as

67
00:04:13,960 --> 00:04:17,740
one mining pool you shouldn't be working
on colliding box on your alternate chain.

68
00:04:19,570 --> 00:04:23,110
So sometimes people talk about
a 51% attacker in Bitcoin,

69
00:04:23,110 --> 00:04:26,550
but it's a mistake to think that that's
a magical threshold where as soon as

70
00:04:26,550 --> 00:04:30,420
you cross it, all of a sudden,
you can do this attack.

71
00:04:30,420 --> 00:04:30,940
In reality,

72
00:04:30,940 --> 00:04:35,539
it's more of a gradient where the attack
gets easier, the further over 50% you go.

73
00:04:37,140 --> 00:04:41,447
It's important to realize that this attack
is detectable, and it's possible that if

74
00:04:41,447 --> 00:04:45,282
you were doing it on a large scale that
the community would decide to reverse it

75
00:04:45,282 --> 00:04:48,650
by refusing to accept your alternate
chain, even if it was longer.

76
00:04:50,360 --> 00:04:52,919
So it's not clear in practice
that this would actually work.

77
00:04:53,920 --> 00:04:57,850
It is also possible that doing this
would completely crash the exchange rate

78
00:04:57,850 --> 00:04:58,430
of Bitcoin.

79
00:04:59,730 --> 00:05:03,970
So it might be that once a miner started
trying to do this it would lose so

80
00:05:03,970 --> 00:05:07,600
much confidence in the system that
they would not want to buy into it and

81
00:05:07,600 --> 00:05:12,360
the amount of dollars that Bitcoins
were worth would go way down.

82
00:05:13,500 --> 00:05:16,490
In fact, if this was done on a large
scale, it's possible it could destroy

83
00:05:16,490 --> 00:05:21,340
the currency completely by
a dramatic loss of confidence.

84
00:05:22,420 --> 00:05:23,910
So, who would want to do this?

85
00:05:26,600 --> 00:05:30,360
The conceivable scenario where people
are worried about an attack like this,

86
00:05:30,360 --> 00:05:32,419
has been referred to as
a Goldfinger attack.

87
00:05:33,460 --> 00:05:37,070
Named after the famous villain in
the James Bond movie, of course,

88
00:05:37,070 --> 00:05:41,340
whose goal in the movie was to
irradiate all of the gold that the U.S.

89
00:05:41,340 --> 00:05:43,980
government held at Fort Knox
to make it valueless.

90
00:05:45,110 --> 00:05:47,330
So if your goal is to destroy Bitcoin,

91
00:05:48,690 --> 00:05:51,840
then you might be willing
to do this forking attack.

92
00:05:51,840 --> 00:05:56,410
In order specifically to tank the market,
make bitcoins worthless and

93
00:05:56,410 --> 00:05:59,730
possibly profit because you
will do a shorted Bitcoin or

94
00:05:59,730 --> 00:06:02,580
because you had significant holdings
in some competing currency.

95
00:06:04,670 --> 00:06:09,001
So beyond that threat model, it's not
clear in which scenarios we would have to

96
00:06:09,001 --> 00:06:11,344
worry about a large scale forking attack.

97
00:06:14,058 --> 00:06:19,046
Although it's possible that the attack
is easier than achieving that

98
00:06:19,046 --> 00:06:23,790
alpha greater than .5,
all that hash power by simply buying it.

99
00:06:23,790 --> 00:06:28,030
Whereas, it would be really expensive to
buy enough mining capacity to have more

100
00:06:28,030 --> 00:06:32,550
than everybody else in the world, it might
be possible to just bribe the people who

101
00:06:32,550 --> 00:06:35,430
do control that capacity
to work on behalf of you.

102
00:06:37,450 --> 00:06:39,750
So there's a couple of ways you
could pay the bribe to them.

103
00:06:39,750 --> 00:06:41,580
You could try to do it out of band.

104
00:06:41,580 --> 00:06:44,940
You could hand them
an envelope full of cash, say.

105
00:06:44,940 --> 00:06:48,320
You could declare yourself to be a new
mining pool and run it at a loss.

106
00:06:48,320 --> 00:06:53,110
You could say I'll pay out 1.01, or
something that clearly wasn't sustainable

107
00:06:53,110 --> 00:06:57,250
but enough to get miners to join your
pool at the expense of all other pools.

108
00:06:57,250 --> 00:06:59,010
Maybe that would push you over 50 percent.

109
00:06:59,010 --> 00:07:03,250
And there's some other subtle ways you
could try to get people to work on your

110
00:07:03,250 --> 00:07:06,670
alternate chain, say by leaving
big tips on the block chain.

111
00:07:08,090 --> 00:07:11,710
But the idea is that instead of actually
acquiring all the mining capacity

112
00:07:11,710 --> 00:07:16,580
yourself, you just pay the people who
already have it to work on your fork.

113
00:07:18,770 --> 00:07:22,480
Now it might be a bad idea for
those miners to actually participate.

114
00:07:22,480 --> 00:07:26,100
Because by doing so they would be hurting
the currency that they've invested so

115
00:07:26,100 --> 00:07:29,190
much money and mining equipment
hoping will stay sustainable.

116
00:07:30,460 --> 00:07:33,680
So why would anybody be
subject to such bribery?

117
00:07:33,680 --> 00:07:36,360
Well, it would be an incentive problem.

118
00:07:36,360 --> 00:07:40,512
All of the miners together have an
incentive in keeping the Bitcoin currency

119
00:07:40,512 --> 00:07:45,390
solvent, but individual miners would
have the incentive to defect and

120
00:07:45,390 --> 00:07:48,380
accept a bribe if they thought they
could make more money in the short term.

121
00:07:49,490 --> 00:07:55,635
So this would be a classic tragedy of
the commons from an economic perspective.

122
00:07:55,635 --> 00:07:59,674
Now this hasn't happened,
this is pure speculation, but

123
00:07:59,674 --> 00:08:04,947
it's an open problem if a bribery attack
like this could actually be viable.

124
00:08:04,947 --> 00:08:11,720
So one defense that does exist in BitCoin
against forking attacks is checkpointing.

125
00:08:11,720 --> 00:08:16,250
So since 2010, each version of the default

126
00:08:16,250 --> 00:08:21,600
BitCoin client ships with a specific
checkpoint, and will refuse to accept

127
00:08:21,600 --> 00:08:25,110
versions of the block chain that
don't date back to that version.

128
00:08:27,200 --> 00:08:31,049
And it's usually several hundred blocks
before whatever the current longest

129
00:08:31,049 --> 00:08:31,642
chain is.

130
00:08:31,642 --> 00:08:36,950
So there's some questions about
the implications for this in terms of how

131
00:08:36,950 --> 00:08:41,350
decentralized this is, because this now
means that essentially a central party,

132
00:08:41,350 --> 00:08:43,990
the developers who maintain
the core BitCoin client,

133
00:08:43,990 --> 00:08:47,810
are deciding something about
the value of the valid block chain.

134
00:08:48,870 --> 00:08:53,112
But this does serve as a good practical
mitigation against the risk of a deep fork

135
00:08:53,112 --> 00:08:57,921
in the block chain Another

136
00:08:57,921 --> 00:09:02,730
type of attack that's quite interesting
is a block-withholding attack.

137
00:09:02,730 --> 00:09:05,330
So the idea here is that you don't want to

138
00:09:05,330 --> 00:09:08,500
announce your blocks right
away as soon as you find them.

139
00:09:08,500 --> 00:09:10,810
Instead you're going to want to try and
get ahead.

140
00:09:10,810 --> 00:09:13,830
What do I mean by get ahead?

141
00:09:13,830 --> 00:09:16,880
Well, you want to do
a little bit of mining, and

142
00:09:16,880 --> 00:09:22,850
hopefully find two blocks in a row, before
the rest of the network finds even one.

143
00:09:22,850 --> 00:09:25,340
And you keep these blocks
to yourself as a secret.

144
00:09:26,790 --> 00:09:27,720
Now, why would you want to do that?

145
00:09:27,720 --> 00:09:29,740
What would you gain from
keeping blocks secret?

146
00:09:31,140 --> 00:09:35,040
Well, as long as you have those two
blocks that are being held secret in your

147
00:09:35,040 --> 00:09:39,940
back pocket, the rest of the network
is going to be trying to extend

148
00:09:39,940 --> 00:09:43,520
what they think is the current
longest block chain.

149
00:09:43,520 --> 00:09:45,890
And all that effort is going
to be a waste for them.

150
00:09:46,930 --> 00:09:48,820
So while you're ahead by two blocks,

151
00:09:48,820 --> 00:09:51,760
all of the mining that you're
doing is essentially unopposed.

152
00:09:53,070 --> 00:09:56,150
And the reason is that as soon
as the rest of the network

153
00:09:56,150 --> 00:10:00,480
actually found a valid block, they would
publish it and everybody would accept it.

154
00:10:00,480 --> 00:10:06,580
But then immediately, boom, you can drop
the two blocks that you had in reserve.

155
00:10:06,580 --> 00:10:10,310
And now it instantly needed
a new longest valid block chain.

156
00:10:10,310 --> 00:10:12,953
And that block that the rest of
the network worked so hard to find,

157
00:10:12,953 --> 00:10:15,663
would immediately be orphaned and
cut off from the longest chain.

158
00:10:19,414 --> 00:10:23,665
So this approach has been called selfish
mining, which I think is a little bit of

159
00:10:23,665 --> 00:10:26,720
a misnomer,
because all mining is inherently selfish.

160
00:10:27,810 --> 00:10:31,400
At least at this point, now that the
hobbyist interest in mining has largely

161
00:10:31,400 --> 00:10:35,970
died down, mining is a business, and
people are in it to try and make money.

162
00:10:35,970 --> 00:10:38,539
So we should say that it's all in
the game for miners to do this,

163
00:10:38,539 --> 00:10:40,445
if they think that
they'll make more profit.

164
00:10:43,195 --> 00:10:46,868
So what happens if you're trying
this block withholding strategy, and

165
00:10:46,868 --> 00:10:50,430
you're ahead by one when the rest of
the network finds the next block?

166
00:10:51,560 --> 00:10:53,230
So instead of being two blocks ahead,

167
00:10:53,230 --> 00:10:55,920
you just have one secret block
held in your back pocket.

168
00:10:55,920 --> 00:11:01,210
And then the rest of the network announces
what they think will be the next

169
00:11:01,210 --> 00:11:02,370
valid block.

170
00:11:02,370 --> 00:11:03,990
Well, if this happens,

171
00:11:03,990 --> 00:11:07,380
you're going to want to immediately
push your secret block out the door.

172
00:11:09,090 --> 00:11:13,480
And now there's two versions of
potentially the longest chain.

173
00:11:13,480 --> 00:11:18,580
And every other miner is going to have to
decide which version they want to work on,

174
00:11:18,580 --> 00:11:19,880
and we're in that race condition.

175
00:11:21,040 --> 00:11:24,910
So you basically have to race as soon as
you hear somebody else finding a valid

176
00:11:24,910 --> 00:11:28,220
block, to get your secret
block out the door and

177
00:11:28,220 --> 00:11:30,960
hopefully get more minors to
hear about your block first.

178
00:11:32,600 --> 00:11:36,610
So the viability of this block-withholding
approach is going to depend

179
00:11:36,610 --> 00:11:38,919
really heavily on your
ability to win these races.

180
00:11:43,290 --> 00:11:45,640
So, when is it a good idea to
do a block-withholding attack?

181
00:11:46,910 --> 00:11:51,270
Well, if you assume that you can win every
race, every time there's competition for

182
00:11:51,270 --> 00:11:52,530
the next valid block,

183
00:11:52,530 --> 00:11:56,690
the rest of the network is going to
accept yours then no matter what alpha,

184
00:11:56,690 --> 00:12:00,580
no matter how much mining capacity you
have, it's better to try selfish mining.

185
00:12:02,510 --> 00:12:03,310
By selfish mining,

186
00:12:03,310 --> 00:12:05,920
I mean this block withholding
strategy that I've just described.

187
00:12:05,920 --> 00:12:09,621
So how would you try to win every race?

188
00:12:09,621 --> 00:12:12,742
Well you could just fight really hard
to have a good network position.

189
00:12:12,742 --> 00:12:15,375
You could try to appear with every node,
so

190
00:12:15,375 --> 00:12:20,580
that you'll announce some more nodes ahead
of the legitimate flooding algorithm.

191
00:12:22,000 --> 00:12:24,130
Or you could try bribing people.

192
00:12:24,130 --> 00:12:27,819
And again, you could bribe by including
small tips in your blocks, so

193
00:12:27,819 --> 00:12:29,695
that it makes it more attractive for

194
00:12:29,695 --> 00:12:32,903
people to mine on top of you
rather than the competing block.

195
00:12:35,377 --> 00:12:39,915
So if you assumed that you only have
a 50% chance of winning these races,.

196
00:12:39,915 --> 00:12:46,719
Which is about what the natural chances
would be, if you're competing fairly,.

197
00:12:46,719 --> 00:12:54,998
Then this block withholding strategy is an
improvement if alpha is greater than 0.25.

198
00:12:54,998 --> 00:12:58,414
And again, this is a theoretical attack,
which is very interesting, but

199
00:12:58,414 --> 00:13:00,814
it hasn't actually been observed yet
in practice.

200
00:13:00,814 --> 00:13:04,561
And it should be something that you'd be
able to tell by monitoring the block chain

201
00:13:04,561 --> 00:13:06,590
and when miners are announcing new blocks.

202
00:13:07,750 --> 00:13:10,480
But even though it hasn't
been observed in practice,

203
00:13:10,480 --> 00:13:12,560
it's very surprising
that this is possible.

204
00:13:12,560 --> 00:13:15,600
And it's contrary to
the original idea of BitCoin,

205
00:13:15,600 --> 00:13:20,450
that without alpha over 0.5,
without a majority of the network,

206
00:13:20,450 --> 00:13:23,870
there was no better mining
strategy than the default.

207
00:13:23,870 --> 00:13:28,676
So the very existence of this attack
shows that it's not safe to assume that

208
00:13:28,676 --> 00:13:32,033
a minor who doesn't control
50% of the network,

209
00:13:32,033 --> 00:13:36,633
doesn't have anything to gain by
switching to an alternate strategy.

210
00:13:41,323 --> 00:13:44,960
Another interesting case is if
miners want to do punitive forking.

211
00:13:46,030 --> 00:13:49,610
So specifically, if miners want to
blacklist transactions from a specific

212
00:13:49,610 --> 00:13:54,720
address, which would freeze the money
held by that address forever.

213
00:13:54,720 --> 00:13:59,560
They could announce that they'll refuse
to mine on any chain with a transaction

214
00:13:59,560 --> 00:14:01,210
originating from address X.

215
00:14:03,360 --> 00:14:05,817
So the reason this is an extreme strategy,

216
00:14:05,817 --> 00:14:09,092
is that if you have less than
a majority of the network, by

217
00:14:09,092 --> 00:14:13,959
announcing that you'll refuse to mine on
any chain that has the transaction from X.

218
00:14:13,959 --> 00:14:17,879
As soon as a chain exists that a majority
of the network accepts that has

219
00:14:17,879 --> 00:14:19,341
that transaction from X,

220
00:14:19,341 --> 00:14:23,141
then you will have cut yourself off
from the longest chain forever.

221
00:14:23,141 --> 00:14:25,870
And all of the mining that you're
doing is essentially wasted.

222
00:14:27,680 --> 00:14:29,170
So you could do this strategy, but

223
00:14:29,170 --> 00:14:32,070
very quickly you would just be
mining on an orphaned fork.

224
00:14:32,070 --> 00:14:35,550
And it would be a waste of all
of your time and electricity.

225
00:14:38,150 --> 00:14:42,130
But there's a much more clever
way to do punitive forking,

226
00:14:42,130 --> 00:14:43,600
which is called feather forking.

227
00:14:45,140 --> 00:14:48,650
And the idea here is, instead of
announcing that you're going to fork

228
00:14:48,650 --> 00:14:52,349
forever, as soon as you see a block
that has a transaction from address X.

229
00:14:53,550 --> 00:14:56,280
You announce very publicly
that you're going to fork,

230
00:14:56,280 --> 00:14:59,620
you're going to try to mine
an alternate longest chain,

231
00:14:59,620 --> 00:15:03,100
if you see a block that has
a transaction from address X.

232
00:15:04,230 --> 00:15:06,560
But, you will give up after a while.

233
00:15:06,560 --> 00:15:11,760
Typically after one or two blocks
confirm the transaction from address X,

234
00:15:11,760 --> 00:15:13,230
you'll go back to the longest chain.

235
00:15:14,790 --> 00:15:19,120
So your chance of actually
pruning that block,

236
00:15:20,380 --> 00:15:23,760
or orphaning that block,
that has the transaction from address X,

237
00:15:25,270 --> 00:15:30,010
if you give up after one confirmation,
is alpha squared.

238
00:15:30,010 --> 00:15:32,929
And the reason is because you ought
to find two consecutive blocks

239
00:15:34,200 --> 00:15:37,930
to get rid of the block with
the transaction from address

240
00:15:37,930 --> 00:15:41,460
X before the rest of the network
can find the next valid block.

241
00:15:44,180 --> 00:15:46,750
So alpha squared might not be very good.

242
00:15:46,750 --> 00:15:51,871
Say you're a 20% minor,
alpha squared is going to be quite low.

243
00:15:51,871 --> 00:15:56,237
It's only going to be only a 4% chance
of actually getting rid of that

244
00:15:56,237 --> 00:15:59,873
transaction that you don't
want to see in the blockchain.

245
00:15:59,873 --> 00:16:03,971
But you might motivate
other miners to join you.

246
00:16:03,971 --> 00:16:05,712
Now why is that?

247
00:16:05,712 --> 00:16:08,534
As long as you've been
very public about this,

248
00:16:08,534 --> 00:16:12,626
other miners know that if they
include a transaction from address X,

249
00:16:12,626 --> 00:16:17,283
they have an alpha squared chance that
the block that they find will end up being

250
00:16:17,283 --> 00:16:20,349
orphaned because of your
feather forking attack.

251
00:16:21,750 --> 00:16:24,430
And if they don't have any strong
motivation to include that

252
00:16:24,430 --> 00:16:28,880
transaction from address accident
only has a very low transaction fee.

253
00:16:28,880 --> 00:16:32,060
That alpha squared chance of
losing their mining reward,

254
00:16:32,060 --> 00:16:34,980
might be a much bigger incentive
than including the transaction.

255
00:16:36,950 --> 00:16:41,670
So, those other miners might rationally
say, we have this person, this miner,

256
00:16:41,670 --> 00:16:42,830
doing feather forking.

257
00:16:43,840 --> 00:16:46,200
It's in our interest to join them, and

258
00:16:46,200 --> 00:16:50,070
just do the blacklist that they're
demanding, rather than run the risk

259
00:16:50,070 --> 00:16:53,010
that they'll feather fork away from
the new block that we've just found.

260
00:16:54,520 --> 00:16:58,600
And the cool thing is that you can now
enforce a blacklist, even if alpha

261
00:16:58,600 --> 00:17:03,164
is less than 0.5, if you have less than
the majority of the mining capacity.

262
00:17:06,519 --> 00:17:10,179
And your success in doing this is going to
depend really heavily on how convincing

263
00:17:10,179 --> 00:17:14,030
you are to the other miners that
you're definitely going to fork.

264
00:17:14,030 --> 00:17:19,060
So ideally what you would want to do
it say, I've burned this into hardware.

265
00:17:19,060 --> 00:17:20,530
I have no choice.

266
00:17:20,530 --> 00:17:24,390
I have to do this, so no matter what
you do I'm going to be feather forking.

267
00:17:24,390 --> 00:17:28,600
In which case the minors would say, well,
this minor really is going to go through

268
00:17:28,600 --> 00:17:31,630
with it so maybe we should just give them
what they want to do this black list.

269
00:17:34,710 --> 00:17:37,420
So why would you want
to have a black list?

270
00:17:37,420 --> 00:17:41,790
Well, like I said, there's the ability to
freeze money held by an individual and

271
00:17:41,790 --> 00:17:44,470
if you are black listing successfully
you can keep them from ever

272
00:17:44,470 --> 00:17:46,130
spending that many will money.

273
00:17:46,130 --> 00:17:50,950
So maybe you could profit off
this by some sort of ransom or

274
00:17:50,950 --> 00:17:54,810
extortion, demanding that the person
you're blacklisting pay you

275
00:17:54,810 --> 00:17:57,100
in order to be taken
off of your blacklist.

276
00:17:58,290 --> 00:18:02,410
It also might be something that you
might want to do for legal reasons.

277
00:18:02,410 --> 00:18:07,300
Maybe certain addresses are designated
by law enforcement as being bad.

278
00:18:07,300 --> 00:18:12,560
Those assets are demanded to be frozen,
in which case some proportion of miners,

279
00:18:12,560 --> 00:18:16,440
say those operating in the jurisdiction
where the asset freezing has

280
00:18:16,440 --> 00:18:20,270
legal authority, will say well,
we really have to enforce this blacklist.

281
00:18:20,270 --> 00:18:22,590
We're being demanded to by the government,

282
00:18:22,590 --> 00:18:25,330
therefore maybe we should feather
fork to try to make it happen.

283
00:18:27,200 --> 00:18:31,290
But a much more interesting case is if
miners do this to try to enforce a minimum

284
00:18:31,290 --> 00:18:32,130
transaction fee.

285
00:18:34,320 --> 00:18:37,580
So instead of a blacklist
against a specific address,

286
00:18:37,580 --> 00:18:41,730
you want to blacklist against any
transaction that doesn't include some

287
00:18:41,730 --> 00:18:46,029
minimum transaction fee that you think is
fair to you as a miner for your hard work.

288
00:18:47,830 --> 00:18:51,160
So we haven't talked a lot about
transaction fees in practice yet.

289
00:18:51,160 --> 00:18:54,730
We've said that they exist, and we've said
that there's the capacity in Bitcoin to

290
00:18:54,730 --> 00:18:58,640
pay transaction fees, but
what are transaction fees?

291
00:19:00,170 --> 00:19:01,890
So this is the default policy for

292
00:19:01,890 --> 00:19:06,430
transaction fees, taken essentially
right out of the Bitcoin code.

293
00:19:08,360 --> 00:19:14,230
Transactions are assigned a priority
which sums over all the inputs,

294
00:19:14,230 --> 00:19:19,770
the value of that input times how
old the transaction is, how long

295
00:19:19,770 --> 00:19:25,600
ago that input was put on the block chain,
divided by the size of the transaction.

296
00:19:25,600 --> 00:19:28,310
So this basically means,
transactions that are larger,

297
00:19:28,310 --> 00:19:33,700
transactions that are spending older coins
that haven't been moved in awhile and

298
00:19:33,700 --> 00:19:36,160
transactions that are smaller
have higher priority.

299
00:19:37,880 --> 00:19:40,820
And by smaller,
I mean smaller in size of the transaction,

300
00:19:40,820 --> 00:19:43,170
which means they don't have a long,
complicated script.

301
00:19:43,170 --> 00:19:48,340
So the idea is to prioritize
large transactions,

302
00:19:48,340 --> 00:19:52,220
people who don't move their coins very
often, and who do it in a simple way.

303
00:19:52,220 --> 00:19:54,200
Whereas if you want to move money quickly.

304
00:19:54,200 --> 00:19:59,060
If you want to move small amounts or
if you want to do complicated scripts,

305
00:19:59,060 --> 00:20:00,780
you have to pay a higher transaction fee.

306
00:20:02,360 --> 00:20:06,080
Currently, by default,
there is a magic number,

307
00:20:06,080 --> 00:20:11,880
where minors accept with no transaction
fee if the priority is higher than 0.576.

308
00:20:13,140 --> 00:20:15,440
And if you're sitting there
thinking that seems pretty random,

309
00:20:15,440 --> 00:20:18,570
where did that number come from,
I'd say you're right.

310
00:20:18,570 --> 00:20:22,540
It's a very arbitrary choice but
it's in the default client so

311
00:20:22,540 --> 00:20:25,630
that's basically what you need to
pay if you want to move Bitcoin.

312
00:20:28,760 --> 00:20:32,030
So currently transaction fees
don't matter that much and

313
00:20:32,030 --> 00:20:37,050
the reason is that block rewards provide
the vast majority well over 99% of

314
00:20:37,050 --> 00:20:39,010
all the revenue that miners are making.

315
00:20:40,370 --> 00:20:45,780
But keep in mind,
we mentioned earlier that the size

316
00:20:45,780 --> 00:20:50,070
of mining rewards is going
down constantly over time.

317
00:20:50,070 --> 00:20:53,020
So every four years, it's [COUGH] halving.

318
00:20:54,800 --> 00:20:58,900
So eventually in the distant future,
the mining rewards,

319
00:20:58,900 --> 00:21:03,430
the fixed rewards by creating new coins,
are going to be much lower.

320
00:21:03,430 --> 00:21:06,290
And transaction fees are going to
be the main game for miners.

321
00:21:06,290 --> 00:21:08,010
going to be where they're
making all of their revenue.

322
00:21:10,200 --> 00:21:14,280
So it's an open question in that new world
where transaction fees are everything for

323
00:21:14,280 --> 00:21:15,080
the miners.

324
00:21:15,080 --> 00:21:17,870
They really depend on transaction fees for
their revenue.

325
00:21:17,870 --> 00:21:22,870
Are miners going to be more aggressive
about enforcing minimum transaction fees,

326
00:21:22,870 --> 00:21:24,870
and how are they going to enforce that?

327
00:21:24,870 --> 00:21:28,940
Well, they need to form a cartel to
enforce minimum transaction fees.

328
00:21:28,940 --> 00:21:31,990
Is that something that market
concentration provided by mining pools

329
00:21:31,990 --> 00:21:33,110
will make easier to happen?

330
00:21:34,790 --> 00:21:37,730
These are really interesting
long-term open questions about

331
00:21:37,730 --> 00:21:38,960
how Bitcoin will evolve.

332
00:21:41,450 --> 00:21:45,640
So in summary, miners are free to
implement any strategy that they want,

333
00:21:45,640 --> 00:21:49,370
although in practice in the wild we've
seen very little behavior of anything but

334
00:21:49,370 --> 00:21:50,910
implementing the default strategy.

335
00:21:50,910 --> 00:21:55,610
And I should stress that
there's no complete model for

336
00:21:55,610 --> 00:21:59,170
miner behavior that says that
the default strategy is optimal.

337
00:21:59,170 --> 00:22:03,640
We've seen that in a world where most
miners do choose the default strategy,

338
00:22:03,640 --> 00:22:06,330
Bitcoin seems to work fairly well.

339
00:22:06,330 --> 00:22:08,680
So it seems to work
fairly well in practice,

340
00:22:08,680 --> 00:22:10,340
we're not sure if it works in theory yet.

341
00:22:11,970 --> 00:22:13,820
But even though it works in practice so

342
00:22:13,820 --> 00:22:18,490
far, the facts on the ground
are going to change for Bitcoin.

343
00:22:18,490 --> 00:22:22,510
They're changing slowly because
of more network hashing capacity,

344
00:22:22,510 --> 00:22:24,480
the miners are getting better and better.

345
00:22:24,480 --> 00:22:28,700
There's more centralization and
professionalization of the miners.

346
00:22:28,700 --> 00:22:31,910
But even beyond those trends, they'd have
to change in the long run because of

347
00:22:31,910 --> 00:22:35,660
transition from fixed mining
rewards to transaction fees.

348
00:22:37,890 --> 00:22:40,950
So, overall, I'd say you should
stay tuned to this space.

349
00:22:40,950 --> 00:22:44,150
Things might be about to get a lot
more interesting for Bitcoin mining,

350
00:22:44,150 --> 00:22:47,170
and currently it's a very interesting
research project to try to

351
00:22:47,170 --> 00:22:49,720
play out using what we
know from game theory.

352
00:22:49,720 --> 00:22:54,560
How is this going to
evolve in the long-term?

353
00:22:54,560 --> 00:22:56,840
So that's all on Bitcoin mining for now.

354
00:22:56,840 --> 00:23:00,430
A few lectures from now we'll have
another lecture about mining, but

355
00:23:00,430 --> 00:23:02,270
about alternative models for mining.

356
00:23:02,270 --> 00:23:06,390
How could we redesign Bitcoin mining
to have different properties.

357
00:23:06,390 --> 00:23:09,690
But before we get to that,
in the immediate next lecture,

358
00:23:09,690 --> 00:23:12,300
we're going to look at anonymity and
Bitcoin.

359
00:23:12,300 --> 00:23:14,840
How much anonymity does Bitcoin provide?

360
00:23:14,840 --> 00:23:16,010
If I use Bitcoin,

361
00:23:16,010 --> 00:23:19,360
will people be able to link my
Bitcoin transactions to my real name?

362
00:23:20,680 --> 00:23:25,630
And what technologies are there to try to
either strengthen anonymity in Bitcoin, or

363
00:23:25,630 --> 00:23:28,770
design an alternate currency
with more anonymity?

364
00:23:28,770 --> 00:23:30,671
That's all coming your
way in the next lecture.

