1
00:00:00,200 --> 00:00:01,700
The first thing to look at,

2
00:00:01,700 --> 00:00:05,820
though, is what are the different
routes to block chain integration?

3
00:00:05,820 --> 00:00:08,910
So a lot of different routes to block
chain integration have been proposed.

4
00:00:08,910 --> 00:00:10,360
And in the Bitcoin community,

5
00:00:10,360 --> 00:00:13,760
you'll find people who are quite
partial to one way or another.

6
00:00:13,760 --> 00:00:17,310
So let's look at four different avenues,
and let's get a quick look at

7
00:00:17,310 --> 00:00:19,870
what some of the advantages and
disadvantages of these routes are.

8
00:00:21,170 --> 00:00:23,430
The first one,
sort of the obvious default one,

9
00:00:23,430 --> 00:00:26,870
is to directly use the Bitcoin
block chain itself.

10
00:00:26,870 --> 00:00:29,840
And this is the one that we saw
in the smart property example

11
00:00:29,840 --> 00:00:31,000
as we walked through the steps.

12
00:00:32,080 --> 00:00:35,600
The advantage, of course, is that it's
easy to deploy, the block chain is here.

13
00:00:35,600 --> 00:00:38,820
It has all this miner power behind it so
we know that it's something that's

14
00:00:38,820 --> 00:00:43,090
very secure, the consensus process
cannot be easily disrupted.

15
00:00:43,090 --> 00:00:47,043
On the other hand, even though we were
able to use some hacks, in this example,

16
00:00:47,043 --> 00:00:50,586
to achieve representation and
atomicity, it's not always the case.

17
00:00:50,586 --> 00:00:55,222
There's no fundamental reason to believe
that if you have some arbitrarily complex

18
00:00:55,222 --> 00:00:59,596
contract between different parties,
that it can be represented adequately on

19
00:00:59,596 --> 00:01:02,683
the block chain and
that you can execute it atomically.

20
00:01:02,683 --> 00:01:06,186
So, to get a better idea of
what this might look like and

21
00:01:06,186 --> 00:01:10,462
what some of the challenges to
atomicity and representation are.

22
00:01:10,462 --> 00:01:14,596
Let's look at a couple more examples in
how you might try to decentralize them

23
00:01:14,596 --> 00:01:16,197
directly on the block chain.

24
00:01:16,197 --> 00:01:19,784
So, the next one we'll look at
is the notion of crowdfunding.

25
00:01:19,784 --> 00:01:21,820
Kickstarter style, for example, but

26
00:01:21,820 --> 00:01:25,299
without actually having a centralized
intermediary like Kickstarter.

27
00:01:26,890 --> 00:01:30,990
So in other words, here is what we want to
happen, we want a completely decentralized

28
00:01:30,990 --> 00:01:36,770
system where some entrepreneur can ask for
donations or contributions.

29
00:01:36,770 --> 00:01:41,275
But, we should be technologically assured,
without the existence of an intermediary,

30
00:01:41,275 --> 00:01:45,260
that that entrepreneur is
only able to spend that money

31
00:01:45,260 --> 00:01:48,694
if they collect enough of it to reach
a certain prespecified threshold.

32
00:01:49,920 --> 00:01:55,236
So here's how we can accomplish that
technically, just using Bitcoin.

33
00:01:55,236 --> 00:01:59,836
What the entrepreneur will do is create
a single transaction with an arbitrary

34
00:01:59,836 --> 00:02:03,390
number of inputs that can vary
as the process continues, and

35
00:02:03,390 --> 00:02:06,753
a single output for,
let's say, value of 1,000.

36
00:02:06,753 --> 00:02:10,934
And they'll send this around and try to
collect contributions and so, of course,

37
00:02:10,934 --> 00:02:14,936
any Bitcoin transaction has the property
that it's spendable only if the sum of

38
00:02:14,936 --> 00:02:19,082
the inputs is greater than the sum of the
outputs, or a single output in this case.

39
00:02:19,082 --> 00:02:23,336
And what'll happen is that this
transaction will gradually accrue

40
00:02:23,336 --> 00:02:27,815
signatures, from people contributing
different amounts of money and

41
00:02:27,815 --> 00:02:32,660
each of the parties will only sign
her own input and the overall output.

42
00:02:32,660 --> 00:02:38,310
And this uses some little used features
of Bitcoin in order to achieve

43
00:02:38,310 --> 00:02:42,409
a transaction where you can produce
only this limited form of signature.

44
00:02:43,930 --> 00:02:47,590
So the entrepreneur will go collecting
these signatures, but the Bitcoin

45
00:02:47,590 --> 00:02:52,740
transaction will only be spendable if
the sum of the inputs eventually reaches

46
00:02:52,740 --> 00:02:56,675
greater than or equal to the output
value that's been prespecified.

47
00:02:56,675 --> 00:02:59,855
So this is something that you can
actually achieve today on Bitcoin, but

48
00:02:59,855 --> 00:03:04,755
already we see that it starts to get into
some little known corners of Bitcoin.

49
00:03:04,755 --> 00:03:07,435
It's not the everyday type
of Bitcoin transaction.

50
00:03:08,655 --> 00:03:13,930
But now let's look at another example
which starts to get even more confusing.

51
00:03:13,930 --> 00:03:17,790
And here's what I'm talking about, this is
something called paying for a proof and

52
00:03:17,790 --> 00:03:19,450
let me explain it in this way.

53
00:03:19,450 --> 00:03:25,500
Let's say that there is a hash function,
H, and Alice claims to know some input,

54
00:03:25,500 --> 00:03:30,150
x, such that hashing x
results in some constant, c,

55
00:03:30,150 --> 00:03:35,320
that's known to everybody, in other words,
she knows the hash preimage of some value.

56
00:03:35,320 --> 00:03:40,848
And now Bob would like to pay Alice in
exchange for knowing this value of x.

57
00:03:40,848 --> 00:03:45,660
Maybe this number x is the solution
to some very valuable proof of

58
00:03:45,660 --> 00:03:46,430
work computation.

59
00:03:48,460 --> 00:03:50,380
But it doesn't need to be a hash function,

60
00:03:50,380 --> 00:03:54,890
it doesn't need to be an input to a hash
function that Bob is paying Alice for,

61
00:03:54,890 --> 00:03:58,880
it could be the solution to
any pure function, really.

62
00:03:58,880 --> 00:04:02,560
There is some arbitrary function F,
Alice claims to know some input x,

63
00:04:02,560 --> 00:04:07,090
such that F of x equals some known value,
and Bob would like to pay her for

64
00:04:07,090 --> 00:04:07,930
knowledge of this value.

65
00:04:09,030 --> 00:04:12,550
But, of course, once again, security is
a problem this transaction happens over

66
00:04:12,550 --> 00:04:17,460
the Internet, we want to make
sure that if Bob does pay Alice,

67
00:04:17,460 --> 00:04:21,750
then Alice is necessarily forced
to transfer knowledge of x to Bob.

68
00:04:21,750 --> 00:04:25,950
And one way in which we can achieve that
is we can atomically couple Bob's payment

69
00:04:25,950 --> 00:04:28,869
with Alice's publication of
x side of the block chain.

70
00:04:28,869 --> 00:04:32,232
So here, she's not secretly sending x,
specifically to Bob, but

71
00:04:32,232 --> 00:04:36,717
instead she's publishing it onto the block
chain, but maybe that's acceptable to Bob.

72
00:04:36,717 --> 00:04:41,646
So this is also something that
can be accomplished, but,

73
00:04:41,646 --> 00:04:46,284
it starts to get quite
unwieldy with regular Bitcoin.

74
00:04:46,284 --> 00:04:49,969
All right, so now let's move
to the second possible route,

75
00:04:49,969 --> 00:04:53,667
which I am going to call embedding,
and is also quite popular.

76
00:04:53,667 --> 00:04:59,263
And what embedding is all about is it
still uses the actual Bitcoin block chain.

77
00:04:59,263 --> 00:05:03,644
But instead,
it comes up with some sort of arbitrary,

78
00:05:03,644 --> 00:05:07,458
maybe quite complex
representation scheme for

79
00:05:07,458 --> 00:05:13,287
encoding different real world semantics
into the Bitcoin block chain.

80
00:05:13,287 --> 00:05:17,327
So, one example of this is colored coins,
which you saw in Lecture 9.

81
00:05:17,327 --> 00:05:22,230
Colored coins are sort of similar to
the representation of car ownership and

82
00:05:22,230 --> 00:05:25,980
transfer that we saw in
the smart property example.

83
00:05:25,980 --> 00:05:30,032
But it's a little bit more elaborate,
in that, in the car ownership example,

84
00:05:30,032 --> 00:05:33,492
the car doesn't need to scan
the entire history of the block chain.

85
00:05:33,492 --> 00:05:37,472
It just comes hard coded with a particular
transaction out of the factory, and

86
00:05:37,472 --> 00:05:41,526
then it merely watches each block to see
if that transaction gets transferred.

87
00:05:41,526 --> 00:05:47,106
Colored coins are a little bit more than
that, the color of a coin, as it were,

88
00:05:47,106 --> 00:05:51,859
is defined by its entire history and
where its genesis comes from.

89
00:05:51,859 --> 00:05:55,460
And so, colored coins are a little bit
more sophisticated to implement, but,

90
00:05:55,460 --> 00:05:57,733
at the same time,
it perhaps gives you a bit more.

91
00:05:57,733 --> 00:06:01,933
In particular, one interesting thing that
it gives you is that everybody can agree

92
00:06:01,933 --> 00:06:05,720
upon what sort of transaction corresponds
to transfer of a car ownership.

93
00:06:05,720 --> 00:06:09,533
And there could be something else for
ownership of some other type of objects,

94
00:06:09,533 --> 00:06:12,152
and you can define as many
of these colors as you want.

95
00:06:12,152 --> 00:06:15,569
So, everybody can look at the block chain
and know that a car sale has happened and

96
00:06:15,569 --> 00:06:16,633
how much was paid for it.

97
00:06:16,633 --> 00:06:20,865
But, of course, they don't necessarily
know the participant identities,

98
00:06:20,865 --> 00:06:24,017
this could be regarded as an advantage or
a disadvantage.

99
00:06:24,017 --> 00:06:27,361
And then there's also Mastercoin,
which is also an example of embedding.

100
00:06:27,361 --> 00:06:31,620
It turns out there are a variety of
creative ways in which you can embed

101
00:06:31,620 --> 00:06:34,510
arbitrary data into
the Bitcoin block chain.

102
00:06:34,510 --> 00:06:36,620
Bitcoin has something called op return,

103
00:06:36,620 --> 00:06:40,780
which is a type of script that allows
40 bytes of arbitrary to be encoded.

104
00:06:40,780 --> 00:06:45,444
You can also use fake transactions
with non-existent addresses,

105
00:06:45,444 --> 00:06:48,809
you can exploit multi-signature, etc, etc.

106
00:06:48,809 --> 00:06:52,822
So these are all possible ways in which
you can encode data into the block chain

107
00:06:52,822 --> 00:06:57,098
and thus embed your arbitrary transactions
into the Bitcoin block chain itself.

108
00:06:57,098 --> 00:06:59,925
Again, it has some advantages and
disadvantages,

109
00:06:59,925 --> 00:07:02,439
more complex representations, obviously.

110
00:07:02,439 --> 00:07:06,297
But, normally, one might think that for
getting more complex representations,

111
00:07:06,297 --> 00:07:07,729
you'd have to use an altcoin,

112
00:07:07,729 --> 00:07:11,332
an entirely separate chain altogether
that allows those representations.

113
00:07:11,332 --> 00:07:16,302
But instead, what embedding allows you to
do is combine the idea of getting complex

114
00:07:16,302 --> 00:07:20,917
representations with utilizing the
security of the Bitcoin block chain with

115
00:07:20,917 --> 00:07:23,127
all the mining hash power behind it.

116
00:07:23,127 --> 00:07:25,858
On the other hand, the scripting and

117
00:07:25,858 --> 00:07:29,744
atomicity are unlimited by
that of Bitcoin itself.

118
00:07:29,744 --> 00:07:33,761
But, the scripting could get even
more limited than just using Bitcoin.

119
00:07:33,761 --> 00:07:39,172
Because these new features that you have
defined, these new representations, might

120
00:07:39,172 --> 00:07:44,372
not interact well with Bitcoin's existing
atomicity and scripting properties.

121
00:07:44,372 --> 00:07:48,236
Another thing to think about is that
it results in unwanted transactions in

122
00:07:48,236 --> 00:07:51,609
the Bitcoin block chain, now,
unwanted is a contentious word,

123
00:07:51,609 --> 00:07:53,472
this is a controversial property.

124
00:07:53,472 --> 00:07:56,242
Some people say that this is just fine,
but some people say that

125
00:07:56,242 --> 00:07:59,280
you're using the Bitcoin block chain for
unintended purposes, for

126
00:07:59,280 --> 00:08:02,972
purposes other than currency, and so that
they try to discourage this kind of use.

127
00:08:02,972 --> 00:08:05,658
I'm not necessarily taking
a moral stance on this, but

128
00:08:05,658 --> 00:08:09,202
just pointing out that these are the
things that one wants to think about if

129
00:08:09,202 --> 00:08:12,190
you're using embedding as a vehicle for
decentralization.

130
00:08:13,940 --> 00:08:15,470
Now let's move to the third route,

131
00:08:15,470 --> 00:08:18,840
which is something called side
chains which you saw in Lecture 10.

132
00:08:18,840 --> 00:08:23,290
I'll just summarize what you
learned about in a single sentence.

133
00:08:23,290 --> 00:08:26,896
A side chain is a merge-mined
alternative chain, so

134
00:08:26,896 --> 00:08:31,310
it still utilizes some or
all of the mining power behind Bitcoin.

135
00:08:32,690 --> 00:08:35,970
And, the value of the currency
represented by the side chain is pegged

136
00:08:35,970 --> 00:08:36,917
in a 1-1 fashion.

137
00:08:37,930 --> 00:08:42,160
Because a proof of burden in
either chain allows you to redeem

138
00:08:42,160 --> 00:08:43,190
coins in the other chain.

139
00:08:44,260 --> 00:08:47,910
And the typical use that it's been
proposed for is Bitcoin testbed.

140
00:08:47,910 --> 00:08:52,050
People want to try out different
interesting modifications to Bitcoin, and

141
00:08:52,050 --> 00:08:55,060
they want to do that without messing
with the Bitcoin system itself, but

142
00:08:55,060 --> 00:08:58,690
still have interoperability of
currency between these two systems.

143
00:08:58,690 --> 00:09:03,370
But perhaps we can use side chains
with enhanced scripting properties,

144
00:09:03,370 --> 00:09:07,050
let's say, in order to achieve some
of these complex contracts and

145
00:09:07,050 --> 00:09:08,740
other things that one
wants to decentralize.

146
00:09:10,170 --> 00:09:12,230
The advantage, of course,
compared to embedding,

147
00:09:12,230 --> 00:09:15,820
which it's somewhat similar to, is that
you're not polluting the block chain.

148
00:09:17,750 --> 00:09:21,510
But the downside is that in order to
even support the notion of a side chain,

149
00:09:21,510 --> 00:09:23,553
Bitcoin modifications are necessary.

150
00:09:23,553 --> 00:09:26,085
So who knows if this is going to happen,
but if it does happen,

151
00:09:26,085 --> 00:09:28,439
it could provide another
interesting alternate route.

152
00:09:30,510 --> 00:09:35,270
So now let's get to the final route for
decentralization,

153
00:09:35,270 --> 00:09:37,570
which is having a totally
separate alternate chain.

154
00:09:38,800 --> 00:09:43,720
And the best example of this is Ethereum,
which is really intended, from the ground

155
00:09:43,720 --> 00:09:48,880
up as a platform, as a general framework
for this kind of ledger-based consensus,

156
00:09:48,880 --> 00:09:52,410
which you can use for all kinds of things,
even creating your own currencies.

157
00:09:54,100 --> 00:09:58,458
And what Ethereum does, the key feature
is that instead of Bitcoins limited stack

158
00:09:58,458 --> 00:10:02,200
based scripting language,
it provides turing-complete scripts.

159
00:10:03,760 --> 00:10:07,730
So this seems weird at first, because
it can lead to all kinds of problems.

160
00:10:07,730 --> 00:10:10,120
A mining node is trying
to execute a script and

161
00:10:10,120 --> 00:10:12,019
it could get stuck in an infinite loop,
for example.

162
00:10:13,300 --> 00:10:16,724
So Ethereum has a neat solution for
this problem,

163
00:10:16,724 --> 00:10:19,985
which is that miner
computation will be paid for

164
00:10:19,985 --> 00:10:24,892
using an internal currency called gas,
by entities within Ethereum.

165
00:10:24,892 --> 00:10:29,862
In particular, Ethereum has this notion of
a long lived contract, which is sort of

166
00:10:29,862 --> 00:10:34,940
a program with a minimal amount of state
that lives within the Ethereum blockchain.

167
00:10:34,940 --> 00:10:37,070
It gets activated when
a transaction is sent to it.

168
00:10:37,070 --> 00:10:40,180
It executes for a little bit on
the miner nodes and then it shuts down.

169
00:10:40,180 --> 00:10:43,945
So contracts are these long lived
things that have their own accounts and

170
00:10:43,945 --> 00:10:44,750
their balances and so on.

171
00:10:44,750 --> 00:10:49,325
And so they use that to pay for
computation from miners.

172
00:10:51,090 --> 00:10:53,870
Now if you can achieve
something like Ethereum,

173
00:10:53,870 --> 00:10:58,550
then it's pretty much a dream situation
for complex representations in atomicity.

174
00:10:58,550 --> 00:11:03,370
You can take arbitrarily complex contracts
and make sure you can represent them, and

175
00:11:03,370 --> 00:11:05,140
execute them in an atomic manner.

176
00:11:05,140 --> 00:11:08,490
But the concerns, the challenges,
are more practical.

177
00:11:08,490 --> 00:11:10,580
Is something like this even possible?

178
00:11:10,580 --> 00:11:14,250
And since it's an alternative chain, will
it ever have the sort of mining powers

179
00:11:14,250 --> 00:11:18,210
necessary to make it really secure,
at least in relation to using Bitcoin?

180
00:11:19,840 --> 00:11:22,800
And given that you're allowing
turing-complete scripts,

181
00:11:22,800 --> 00:11:26,910
what sort of unexpected security
problems does that open you up to?

182
00:11:26,910 --> 00:11:29,800
So those are the things to
think about when one is talking

183
00:11:29,800 --> 00:11:32,880
about a totally altcoin based
solution like Ethereum.

184
00:11:32,880 --> 00:11:37,490
I should point out that Ethereum mostly
exists in an idea stage at this point, so

185
00:11:37,490 --> 00:11:41,220
it remains to be seen to what extent it
will be realized as a practical system.

186
00:11:42,310 --> 00:11:44,970
But nevertheless,
at least as a thought experiment,

187
00:11:44,970 --> 00:11:49,950
Ethereum is fascinating in thinking
about what sorts of powerful contracts

188
00:11:49,950 --> 00:11:52,257
can be decentralized using
blockchain technologies?

189
00:11:53,590 --> 00:11:55,740
Coming back to the smart property though,

190
00:11:55,740 --> 00:11:58,930
let's think about which of
these approaches might be best.

191
00:11:58,930 --> 00:12:00,970
Well, from a conceptual point of view,

192
00:12:00,970 --> 00:12:05,290
any of these is powerful enough
to accomplish what we want to.

193
00:12:05,290 --> 00:12:08,980
But when you start to get to more powerful
contracts, then there are going to be

194
00:12:08,980 --> 00:12:10,980
a lot of differences between
the four approaches and

195
00:12:10,980 --> 00:12:12,890
the level of power and
flexibility that they offer.

196
00:12:14,330 --> 00:12:18,016
But another practical
consideration also to keep in mind,

197
00:12:18,016 --> 00:12:22,807
is that various things like SPV,
simplified payment verification proofs,

198
00:12:22,807 --> 00:12:27,617
are going to be more or less feasible in
some approaches compared to the others.

199
00:12:27,617 --> 00:12:30,903
All right, now let's go back
to the car sale example, and

200
00:12:30,903 --> 00:12:34,910
ask what happens if there is
a dispute about the sale of a car.

201
00:12:34,910 --> 00:12:37,750
Perhaps the seller sold
a lemon car to the buyer, and

202
00:12:37,750 --> 00:12:40,400
now they're not happy with it, and
they want to reverse the transaction.

203
00:12:41,950 --> 00:12:45,980
Recall from one of the early lectures that
we learned about escrow transactions,

204
00:12:45,980 --> 00:12:49,990
particularly 2-out-of-3 escrow,
where, in addition to the buyer and

205
00:12:49,990 --> 00:12:53,630
the seller, there is a judge or
a mediator who's involved.

206
00:12:53,630 --> 00:12:56,278
And how might an escrow payment look like?

207
00:12:56,278 --> 00:13:00,430
So the buyer is going
to transfer Bitcoins,

208
00:13:00,430 --> 00:13:05,050
not directly to the seller, but
instead to a 2-out-of-3 address,

209
00:13:05,050 --> 00:13:10,548
which is controlled jointly by the buyer,
the seller, and a mediator or a judge.

210
00:13:10,548 --> 00:13:17,250
And the 2-out-of-3 account has a property
that, if any two of them agree,

211
00:13:17,250 --> 00:13:23,200
then they can get the payment out of
this intermediate holding address and

212
00:13:23,200 --> 00:13:27,420
get it back to either the seller if
the transaction goes through smoothly, or

213
00:13:27,420 --> 00:13:31,460
back to the buyer if there is a dispute
and a transaction needs to be reversed.

214
00:13:31,460 --> 00:13:34,340
But in no case to mediator's account,
they can't steal the money.

215
00:13:35,540 --> 00:13:39,300
So that seems like a pretty good technical
solution that we can use to build

216
00:13:39,300 --> 00:13:41,720
some sort of dispute resolution
mechanism on top of it.

217
00:13:42,830 --> 00:13:45,944
But you might notice that
this seems to lose atomicity,

218
00:13:45,944 --> 00:13:49,133
this is a 2-out-of-3 escrow only for
the payments.

219
00:13:49,133 --> 00:13:52,500
But as we saw earlier, what we ideally
wanted was to couple the payment with

220
00:13:52,500 --> 00:13:54,850
the transfer of car ownership itself.

221
00:13:54,850 --> 00:13:56,740
That also can be accomplished, but

222
00:13:56,740 --> 00:13:59,600
it really starts to get a little
bit unwieldy at that point.

223
00:14:01,470 --> 00:14:06,320
Nevertheless, let's look at this sort
of escrow and dispute mediation, and

224
00:14:06,320 --> 00:14:11,530
compare that to the traditional real world
solution, and see what that gives us.

225
00:14:11,530 --> 00:14:14,420
So how would dispute mediation
happen in the physical world,

226
00:14:14,420 --> 00:14:17,210
with an actual dispute about a car sale?

227
00:14:17,210 --> 00:14:19,680
It would probably go
through the court system.

228
00:14:19,680 --> 00:14:25,370
The court system is again, a centralized
state-controlled mediation process.

229
00:14:25,370 --> 00:14:30,370
But what this gives you is
the freedom to choose the mediator.

230
00:14:30,370 --> 00:14:33,920
This is entirely a private contract
between these two parties and

231
00:14:33,920 --> 00:14:38,000
they can choose that mediator
to be whoever they want.

232
00:14:38,000 --> 00:14:41,110
And this could be a good
thing in some situations.

233
00:14:41,110 --> 00:14:46,375
In particular, you can argue that
this notion of an intermediary for

234
00:14:46,375 --> 00:14:51,366
a resolution, which is the court system,
has now been changed,

235
00:14:51,366 --> 00:14:56,943
from a single entity that everybody
must use mandatorily, to a market.

236
00:14:56,943 --> 00:14:59,309
A private market,
where different entities,

237
00:14:59,309 --> 00:15:03,686
different intermediaries can compete based
on the perceived fairness, for example,

238
00:15:03,686 --> 00:15:07,960
of their dispute mediation process as
well as efficiency, low costs, etc., etc.

239
00:15:09,520 --> 00:15:11,310
There are, of course, a lot of challenges.

240
00:15:11,310 --> 00:15:15,640
This sort of situation immediately gives
rise to huge conflicts of incentive

241
00:15:15,640 --> 00:15:18,390
between the mediator and
one of the participants.

242
00:15:18,390 --> 00:15:22,060
They could be bribed, for example,
so those are things to think about.

243
00:15:22,060 --> 00:15:25,830
But one key disadvantage I'll point
to is that, in the escrow process,

244
00:15:25,830 --> 00:15:29,010
forget about even how
the dispute mediation happens.

245
00:15:29,010 --> 00:15:32,900
In the escrow process that you must use
in Bitcoin to even enable the dispute

246
00:15:32,900 --> 00:15:37,350
mediation to take hold, you have
to tie up the funds for the period

247
00:15:37,350 --> 00:15:41,180
during which either of the parties is
allowed to dispute the transaction.

248
00:15:42,570 --> 00:15:43,680
And that's a little bit of a problem.

249
00:15:43,680 --> 00:15:46,150
It's not a problem that you
have in the traditional system.

250
00:15:46,150 --> 00:15:50,192
And the reason for that is that in the
court system, if there was a dispute, and

251
00:15:50,192 --> 00:15:53,510
one of the parties refuses to pay up,
you have law enforcement.

252
00:15:53,510 --> 00:15:56,068
You can go after them,
you have their identity, and

253
00:15:56,068 --> 00:15:59,382
that's something that's lacking in
this system as well as in any of

254
00:15:59,382 --> 00:16:03,570
the alternative routes That we've looked
at in order to achieve decentralization,

255
00:16:03,570 --> 00:16:05,510
and we'll return to this point again.

256
00:16:06,920 --> 00:16:10,710
But the broader point I wanted to
make here is that, while earlier

257
00:16:10,710 --> 00:16:14,560
we saw an example of decentralization
through disintermediation,

258
00:16:14,560 --> 00:16:16,580
completely getting rid of an intermediary.

259
00:16:16,580 --> 00:16:21,330
This is also a different form
of decentralization, but

260
00:16:21,330 --> 00:16:26,080
it's not disintermediation,
instead we've replaced a single mandatory

261
00:16:26,080 --> 00:16:29,210
intermediary with the freedom
to choose your own intermediary.

262
00:16:30,220 --> 00:16:32,540
And we've seen this before,
we've seen this in a different context,

263
00:16:33,810 --> 00:16:37,970
in a previous lecture you saw the notion
of decentralizing prediction markets.

264
00:16:37,970 --> 00:16:42,780
And when what we did in
that situation is also.

265
00:16:42,780 --> 00:16:47,410
We allowed, instead of a single party like
Intrade running everybody's prediction

266
00:16:47,410 --> 00:16:50,160
market, we said anybody
can now start a market.

267
00:16:51,400 --> 00:16:53,680
Let's really lower the barrier to entry.

268
00:16:53,680 --> 00:16:55,959
And if somebody wants to
run a prediction market for

269
00:16:55,959 --> 00:16:57,980
the next presidential election, go for it.

270
00:16:57,980 --> 00:17:00,710
Someone else wants to run a prediction
market for the Super Bowl,

271
00:17:00,710 --> 00:17:01,410
they're free to do so.

272
00:17:01,410 --> 00:17:05,370
In fact, multiple people can run different
prediction markets for the same event.

273
00:17:05,370 --> 00:17:09,130
There's nobody stopping them, so
you have this competitive market for

274
00:17:09,130 --> 00:17:10,880
intermediaries.

275
00:17:10,880 --> 00:17:13,661
So that's another sense of
the word decentralization.

276
00:17:15,982 --> 00:17:20,370
Okay, so
let's put what we've seen in a spectrum.

277
00:17:20,370 --> 00:17:23,800
On the one end,
in terms of the most centralized system,

278
00:17:23,800 --> 00:17:25,700
is the single mandatory intermediary.

279
00:17:25,700 --> 00:17:28,159
We also just looked at multiple
competing intermediaries.

280
00:17:29,540 --> 00:17:32,820
And there's one more intermediate
step which I'm calling a threshold

281
00:17:32,820 --> 00:17:33,620
of intermediaries.

282
00:17:33,620 --> 00:17:36,350
We haven't looked at that so far,
we'll see that near the end.

283
00:17:37,680 --> 00:17:41,710
But finally, what we started out
seeing with smart property is complete

284
00:17:41,710 --> 00:17:43,750
disintermediation, no intermediary.

285
00:17:43,750 --> 00:17:46,530
So I would put all of these on a spectrum.

286
00:17:46,530 --> 00:17:49,190
It's not completely distinct categories,
but

287
00:17:49,190 --> 00:17:51,620
it's useful conceptually to
sort of think of them that way.

288
00:17:54,520 --> 00:17:58,610
Now, let's think about another aspect of
all of the protocols that we've seen so

289
00:17:58,610 --> 00:18:00,760
far, which is security.

290
00:18:00,760 --> 00:18:05,020
We started out by saying atomicity is
a very important way to achieve security.

291
00:18:05,020 --> 00:18:05,620
It's not the only one.

292
00:18:05,620 --> 00:18:07,920
We said there were going
to be some alternatives.

293
00:18:07,920 --> 00:18:09,480
So, what are they?

294
00:18:09,480 --> 00:18:12,130
So here are some ways
of improving security.

295
00:18:13,160 --> 00:18:15,390
We've seen two of these,
the ones in the middle.

296
00:18:15,390 --> 00:18:18,950
Escrow with dispute mediation
as well as atomic exchange,

297
00:18:18,950 --> 00:18:21,600
which completely automates the process.

298
00:18:21,600 --> 00:18:22,750
But there are others.

299
00:18:22,750 --> 00:18:26,290
And, in fact, the most obvious one,
perhaps, is reputation, where you don't

300
00:18:26,290 --> 00:18:30,280
have any particular technological
security enhancing mechanism.

301
00:18:30,280 --> 00:18:32,210
But instead, these intermediaries, or

302
00:18:32,210 --> 00:18:34,800
whoever the parties that you
were interacting with, built

303
00:18:34,800 --> 00:18:39,660
up reputations over the long-term and
so they built some trust in that matter.

304
00:18:41,130 --> 00:18:46,000
Reputation is okay if, in the absence
of other security alternatives

305
00:18:46,000 --> 00:18:49,470
like atomic exchange, but
it has some problems.

306
00:18:49,470 --> 00:18:54,330
First of all, the entity has to build up
this reputation over the long run, right?

307
00:18:54,330 --> 00:18:57,140
If whoever's the entity you
are interacting with is

308
00:18:57,140 --> 00:19:00,910
completely pseudonymous or anonymous,
then reputation doesn't even apply.

309
00:19:00,910 --> 00:19:04,030
And we see this problem even with
real-world reputation systems, for

310
00:19:04,030 --> 00:19:05,410
example, restaurants or

311
00:19:05,410 --> 00:19:10,250
other businesses that obtain really bad
reviews on Yelp might close and reopen,

312
00:19:10,250 --> 00:19:14,662
maybe in a different location, maybe in
the same location, but simply rebranded.

313
00:19:14,662 --> 00:19:17,100
All right, so that's a problem in
general with reputation systems.

314
00:19:18,420 --> 00:19:23,600
Also, for the party to accrue positive or
negative reputation, there should be a way

315
00:19:23,600 --> 00:19:28,900
for establishing what they did, right or
wrong, that does beyond he-said-she-said.

316
00:19:28,900 --> 00:19:33,226
So looking at Yelp again, it does work on
a he said, she said model would sort of

317
00:19:33,226 --> 00:19:36,310
works okay because there
are real identities in Yelp and

318
00:19:36,310 --> 00:19:39,458
people sort of have to use
their real names and of course,

319
00:19:39,458 --> 00:19:42,311
businesses operate under
their real identities.

320
00:19:42,311 --> 00:19:46,691
But here we're talking about a universe in
which everybody wants to be pseudonymous,

321
00:19:46,691 --> 00:19:50,411
and so this sort of model where it's
one person's word against another,

322
00:19:50,411 --> 00:19:52,780
might end up really
becoming a non-starter.

323
00:19:52,780 --> 00:19:55,030
There are also problems with escrow and
dispute mediation.

324
00:19:55,030 --> 00:19:58,200
We saw a couple in the way that
escrow is done on Bitcoin,

325
00:19:58,200 --> 00:20:02,470
you have to actually tie up your funds and
they become unusable during the time

326
00:20:02,470 --> 00:20:06,810
when either party has even the ability
to challenge the transaction.

327
00:20:06,810 --> 00:20:10,120
And, of course, dispute mediation leads
to conflicts of interest and so forth.

328
00:20:11,320 --> 00:20:12,690
We have seen atomic exchange, and

329
00:20:12,690 --> 00:20:15,740
whenever it is technically feasible
then it's probably a good idea.

330
00:20:15,740 --> 00:20:19,070
And the last thing, another thing that's
been proposed is trusted hardware.

331
00:20:19,070 --> 00:20:21,580
It's not always applicable,
but in some cases.

332
00:20:21,580 --> 00:20:26,330
For example, it's applicable when
the service that you want to pay for

333
00:20:26,330 --> 00:20:29,670
is something that's entirely
a software program.

334
00:20:29,670 --> 00:20:32,390
And so what the developer can
do is publish the code and

335
00:20:32,390 --> 00:20:34,010
execute it on a trusted hardware module.

336
00:20:34,010 --> 00:20:37,130
And so the people who are subscribing
to that service, or paying for

337
00:20:37,130 --> 00:20:41,230
that service can be assured that the code,
that they can look at an audit as

338
00:20:41,230 --> 00:20:43,569
the same code that's executing and
providing them the service.

339
00:20:45,210 --> 00:20:48,610
But what is really common
to all of these ways for

340
00:20:48,610 --> 00:20:53,510
improving security in terms of the block
chain based decentralization paradigm,

341
00:20:53,510 --> 00:20:56,420
is that ultimately there is
no real world enforcement.

342
00:20:56,420 --> 00:20:57,920
There are no physical identities,

343
00:20:57,920 --> 00:21:00,480
there's no law enforcement,
there's no going after people.

344
00:21:00,480 --> 00:21:02,000
And so that means two things.

345
00:21:02,000 --> 00:21:03,460
One is, there can be no debt.

346
00:21:04,460 --> 00:21:07,830
If we want to do dispute mediation,
the lack of the ability for

347
00:21:07,830 --> 00:21:11,870
debt is the reason why you have
to put in sort of a deposit and

348
00:21:11,870 --> 00:21:16,480
lock up those funds during the period when
you want dispute mediation to be possible.

349
00:21:16,480 --> 00:21:19,550
Also, there are no punitive measures for
misbehavior, so

350
00:21:19,550 --> 00:21:22,030
this really limits the sort
of things you can do.

351
00:21:22,030 --> 00:21:23,830
So these are important
limitations to keep in mind.

352
00:21:25,300 --> 00:21:30,231
Okay, a little thing that I want to point
to is that in terms of the vocabulary of

353
00:21:30,231 --> 00:21:33,920
security, some people use
the word trust minimization.

354
00:21:35,060 --> 00:21:36,710
I don't like this term at all.

355
00:21:36,710 --> 00:21:40,300
I feel that there is often
a confusion between two things.

356
00:21:40,300 --> 00:21:45,057
One is the fact that cryptography is often
used in contexts where unfortunately

357
00:21:45,057 --> 00:21:47,968
there is not much trust between entities,
and so

358
00:21:47,968 --> 00:21:52,640
the lack of trust is a starting point,
and cryptography is the solution.

359
00:21:52,640 --> 00:21:57,020
This often becomes confused with, oh,
now we have this hammer of cryptography,

360
00:21:57,020 --> 00:22:01,720
let's try to use this to move to a world
where nobody has to trust anyone anymore.

361
00:22:01,720 --> 00:22:03,500
Trust minimization is not the goal.

362
00:22:05,130 --> 00:22:07,890
Lack of trust is not the model
that we're hoping to move to.

363
00:22:07,890 --> 00:22:10,590
It is, instead,
our unfortunate starting point.

364
00:22:10,590 --> 00:22:13,250
But really, trust is not really
the right lens to look at it.

365
00:22:13,250 --> 00:22:16,090
It's not whether you trust
the motives of some individual, but

366
00:22:16,090 --> 00:22:20,540
whether they're going to behave in
the manner that they have specified.

367
00:22:20,540 --> 00:22:24,302
And that could be not only because they're
untrusted but because they got hacked,

368
00:22:24,302 --> 00:22:25,410
etc., etc.

369
00:22:25,410 --> 00:22:28,760
So let's not really use the word trust and
instead talk about security.

370
00:22:30,350 --> 00:22:33,190
All right, so let's summarize
a lot of what we've seen so far.

371
00:22:33,190 --> 00:22:37,770
One of the things that we
want to talk about in terms of

372
00:22:37,770 --> 00:22:40,240
decentralization is what
is being decentralized.

373
00:22:40,240 --> 00:22:41,910
We've looked a couple of examples.

374
00:22:41,910 --> 00:22:44,790
Smart property, pay for proof and so on.

375
00:22:44,790 --> 00:22:45,980
But we're going to see a lot more.

376
00:22:45,980 --> 00:22:48,390
So we haven't really talked
about the first bullet.

377
00:22:48,390 --> 00:22:52,060
Instead, the three things that we have
talked about in this section are,

378
00:22:52,060 --> 00:22:54,000
what type of block chain integration.

379
00:22:54,000 --> 00:22:57,890
We saw four examples directly on
block chain embedding, side chains,

380
00:22:57,890 --> 00:23:00,647
and a totally different
alternative chain altogether.

381
00:23:02,020 --> 00:23:04,450
We talked about levels
of decentralization.

382
00:23:04,450 --> 00:23:08,550
Again, we talked about four
points on a spectrum ranging from

383
00:23:08,550 --> 00:23:11,190
completely disintermediated
to completely centralized.

384
00:23:12,210 --> 00:23:15,140
And finally, we talked about
different ways of enhancing security.

385
00:23:17,170 --> 00:23:20,470
So key points that I want to
make in this lecture and

386
00:23:20,470 --> 00:23:22,810
you'll see through
the next several slides.

387
00:23:22,810 --> 00:23:26,110
Is that asking these four
questions gives you a powerful and

388
00:23:26,110 --> 00:23:30,140
generic decentralization template
that can be used to understand and

389
00:23:30,140 --> 00:23:34,110
succinctly represent almost any of
the proposals that you see in the Bitcoin

390
00:23:34,110 --> 00:23:36,675
community for
block chain based decentralization.

391
00:23:38,415 --> 00:23:40,365
Let's go ahead and
see some examples of this.

392
00:23:40,365 --> 00:23:42,525
Let's go back to smart
property once again.

393
00:23:42,525 --> 00:23:44,105
So, what is smart property?

394
00:23:44,105 --> 00:23:48,210
It decentralizes the notion of
property ownership and trading,

395
00:23:48,210 --> 00:23:51,725
which are two related, but
somewhat distinct things.

396
00:23:51,725 --> 00:23:54,675
And it decentralizes in
the sense of disintermediation.

397
00:23:54,675 --> 00:23:58,585
You don't need an intermediary
anymore like the state or the DMV.

398
00:23:58,585 --> 00:24:02,103
And in the example that we saw,
it was achieved using the Bitcoin block

399
00:24:02,103 --> 00:24:06,940
chain itself, but you could achieve it
using any of the other three methods.

400
00:24:06,940 --> 00:24:11,100
And finally, the key security principle
that we used was atomicity in tying

401
00:24:11,100 --> 00:24:13,760
together the payment with
the transfer of the car ownership.

402
00:24:16,130 --> 00:24:19,480
Now let's look at another example, which
is also something we alluded to a bit

403
00:24:19,480 --> 00:24:21,840
earlier in the lecture,
which is prediction markets.

404
00:24:21,840 --> 00:24:25,270
So of course, it decentralizes
a centralized prediction market,

405
00:24:25,270 --> 00:24:25,920
like end trade.

406
00:24:27,530 --> 00:24:29,810
And it does so
in the sense of competition.

407
00:24:29,810 --> 00:24:33,300
It doesn't get rid of the need for some
entity to run a prediction market, but

408
00:24:33,300 --> 00:24:35,190
instead it allows anybody to do that.

409
00:24:35,190 --> 00:24:36,860
It lowers the barrier to entry, and

410
00:24:36,860 --> 00:24:38,769
different people can run
different prediction markets.

411
00:24:40,770 --> 00:24:42,720
And it was done using an Altcoin.

412
00:24:42,720 --> 00:24:47,036
And again the security property was
atomicity, in that the two parties to

413
00:24:47,036 --> 00:24:51,698
a trade of a share in a prediction market
are coupled together using those atomic

414
00:24:51,698 --> 00:24:56,656
property that ties together the transfer
of the share with the transfer of payment.

415
00:24:58,211 --> 00:25:00,370
Now let's look at a quite
different example.

416
00:25:00,370 --> 00:25:02,680
This is something that's called StorJ,

417
00:25:02,680 --> 00:25:06,370
proposed by Greg Maxwell, who claims
it should be proposed storage, but I'm

418
00:25:06,370 --> 00:25:10,270
going to ignore that because it's going to
be just confusing if I called it storage.

419
00:25:10,270 --> 00:25:13,970
So what this is, it's sort of
an agent that lives in the cloud.

420
00:25:13,970 --> 00:25:15,610
And what do I mean by agent?

421
00:25:15,610 --> 00:25:18,310
What, or
at least what Greg Maxwell means by agent,

422
00:25:18,310 --> 00:25:23,400
is that it has some level of
independent decision-making ability.

423
00:25:23,400 --> 00:25:26,960
It's not full-fledged AI, but
it decides some things for itself.

424
00:25:26,960 --> 00:25:30,920
What it's going to do is,
it's going to rent

425
00:25:30,920 --> 00:25:35,000
cloud computing services, and
it's going to use that to run itself.

426
00:25:35,000 --> 00:25:39,360
But the service it provides to consumers
is that you can pay this agent

427
00:25:39,360 --> 00:25:42,829
to store a file for
a certain period of time, say 24 hours.

428
00:25:44,310 --> 00:25:47,830
And when you do that, it's going to
receive payment in Bitcoins, store this

429
00:25:47,830 --> 00:25:52,920
file, keep it for 24 hours, and then
delete it unless you keep making payments.

430
00:25:52,920 --> 00:25:57,100
But it also has some other very
interesting aspects such as reproduction.

431
00:25:57,100 --> 00:26:00,760
It can take a copy of the code, spawn a
new instance, and try to make improvements

432
00:26:00,760 --> 00:26:04,830
to it, pay somebody to write new
improvements or modules and so on.

433
00:26:04,830 --> 00:26:09,090
But we'll ignore those aspects for now and
just talk about this aspect of it.

434
00:26:10,620 --> 00:26:14,408
So what is StorJ, and can we look at it
through the lens of decentralization?

435
00:26:14,408 --> 00:26:15,908
It turns out that we can't.

436
00:26:15,908 --> 00:26:19,210
So StorJ decentralizes
the notion of file storage and

437
00:26:19,210 --> 00:26:21,980
retrieval, which you can do today
through Dropbox, for example.

438
00:26:23,460 --> 00:26:25,281
It's decentralized in
the sense of competition.

439
00:26:25,281 --> 00:26:28,200
You still need an intermediary very much,
which is this agent.

440
00:26:29,450 --> 00:26:31,120
And the payment is done using Bitcoin.

441
00:26:32,580 --> 00:26:36,890
And finally, the security mechanism
that you have is just reputation.

442
00:26:36,890 --> 00:26:39,720
There is nothing in particular
in the StorJ proposal that, for

443
00:26:39,720 --> 00:26:43,070
example, atomically
couples your payment for

444
00:26:43,070 --> 00:26:46,400
storage with the actual act
of retrieving the file.

445
00:26:48,590 --> 00:26:52,060
So that's StorJ,
let's look at more examples.

446
00:26:52,060 --> 00:26:55,720
In fact, we can even consider Zerocoin,
for example,

447
00:26:55,720 --> 00:26:57,840
which we saw in a previous
lecture through this lens.

448
00:26:58,920 --> 00:27:02,580
So Zerocoin is a way to
decentralize the notion of mixing,

449
00:27:02,580 --> 00:27:06,810
instead of having a centralized mixing
service, where you put in your coins and

450
00:27:06,810 --> 00:27:08,390
just hope that you get it back.

451
00:27:08,390 --> 00:27:11,560
It's decentralized in the sense
of disintermediation.

452
00:27:11,560 --> 00:27:13,430
There's no mixing intermediary anymore.

453
00:27:14,540 --> 00:27:17,320
The mixing is accomplished
purely through cryptography,

454
00:27:17,320 --> 00:27:18,700
you don't need to trust anyone.

455
00:27:18,700 --> 00:27:20,599
It's enforced just by math and
by consensus.

456
00:27:22,150 --> 00:27:24,730
And it's done using an Altcoin.

457
00:27:24,730 --> 00:27:29,380
It's not quite compatible with Bitcoin
unless there is a fork to Bitcoin.

458
00:27:30,980 --> 00:27:32,660
And the security property is atomicity.

459
00:27:32,660 --> 00:27:34,310
What does this mean?

460
00:27:34,310 --> 00:27:39,490
The notion of burning a base coin in
Zerocoin and actually getting a Zerocoin

461
00:27:39,490 --> 00:27:43,540
in exchange for it are atomically
coupled through the same transaction.

462
00:27:43,540 --> 00:27:45,840
And the same goes for
later redeeming a Zerocoin.

463
00:27:45,840 --> 00:27:48,410
And that's where the security comes from.

464
00:27:48,410 --> 00:27:49,900
That's why you don't
need to trust anybody.

465
00:27:50,980 --> 00:27:54,300
And that is of course accomplished
through zero knowledge proofs.

466
00:27:54,300 --> 00:27:59,490
So we've seen this powerful template
that incorporates these four factors.

467
00:27:59,490 --> 00:28:03,590
And we've seen some examples of how
systems that we've already looked at

468
00:28:03,590 --> 00:28:06,740
fall into this pattern
of decentralization.

469
00:28:06,740 --> 00:28:08,110
In the next part of this lecture,

470
00:28:08,110 --> 00:28:12,010
we're going to look at a variety of new
examples of things that people have

471
00:28:12,010 --> 00:28:14,990
proposed can be decentralized
using block chain technology.

472
00:28:14,990 --> 00:28:17,398
And we're going to use this sort
of template to analyze them.

