1
00:00:00,740 --> 00:00:05,290
In this portion of the lecture, we'll
look at where e-cash gets its value from.

2
00:00:05,290 --> 00:00:07,860
We didn't cover this in the previous
portion when we talked about

3
00:00:07,860 --> 00:00:09,850
different e-cash systems.

4
00:00:09,850 --> 00:00:13,150
And the reality is that there's
a bunch of different proposals for

5
00:00:13,150 --> 00:00:16,100
how you do this and
different companies do it differently.

6
00:00:16,100 --> 00:00:20,280
In the very early portion of this lecture
we looked at credit card based systems,

7
00:00:20,280 --> 00:00:24,000
and so in this case it's obvious that
the user's credit card is getting billed

8
00:00:24,000 --> 00:00:26,030
every time they conduct a transaction.

9
00:00:26,030 --> 00:00:30,910
In the case of DigiCash we have
these digital cash objects,

10
00:00:30,910 --> 00:00:35,140
and they might be worth $100, but
what makes them actually worth $100?

11
00:00:35,140 --> 00:00:39,280
The answer is that in order to be
issued DigiCash that's worth $100,

12
00:00:39,280 --> 00:00:42,480
you would have to take $100
out of you bank account and

13
00:00:42,480 --> 00:00:45,540
give it to the bank that was
issuing you the DigiCash.

14
00:00:46,630 --> 00:00:49,550
Some other,
maybe more far fetched ideas was,

15
00:00:49,550 --> 00:00:53,690
what if the government actually
authorized services to mint money?

16
00:00:53,690 --> 00:00:57,030
They were actually authorized by
the mint of a particular country

17
00:00:57,030 --> 00:00:59,380
in order to create new
cash out of thin air.

18
00:00:59,380 --> 00:01:01,672
That was the idea behind NetCash.

19
00:01:01,672 --> 00:01:05,639
Another proposal thought that what
if we took a pile of gold, and

20
00:01:05,639 --> 00:01:08,944
we put it in a vault, and
we only issued digital cash,

21
00:01:08,944 --> 00:01:12,550
that was of the same value of
the gold that was in the vault?

22
00:01:12,550 --> 00:01:14,090
So e-Gold used this.

23
00:01:14,090 --> 00:01:16,020
There was another company,
called Digigold,

24
00:01:16,020 --> 00:01:19,410
they weren't fully backed by gold, but
they at least had partial reserves for

25
00:01:19,410 --> 00:01:22,389
the amount of digital cash that they
issued that was backed by gold.

26
00:01:23,400 --> 00:01:28,100
So in a digital realm, how do you create
something that has value out of thin air?

27
00:01:28,100 --> 00:01:31,680
Especially when digital bits
can be copied and pasted?

28
00:01:31,680 --> 00:01:35,230
The idea is to create
something that's scarce.

29
00:01:35,230 --> 00:01:39,410
Scarcity is one of the features of all,
not just cash,

30
00:01:39,410 --> 00:01:42,640
but other things that have been
used like gold or diamonds.

31
00:01:42,640 --> 00:01:44,110
As substitutes for cash.

32
00:01:45,140 --> 00:01:50,210
One way to achieve scarcity in
cryptography is to look at the solutions

33
00:01:50,210 --> 00:01:55,040
to a moderately hard puzzle or
the output of a moderately hard function.

34
00:01:55,040 --> 00:01:58,630
So, a moderately hard function is
a function that takes some amount of time,

35
00:01:58,630 --> 00:02:03,800
computational resources, maybe memory,
in order to compute the output of.

36
00:02:03,800 --> 00:02:08,380
In this case by moderate,
we mean it might take you know for

37
00:02:08,380 --> 00:02:12,905
example, in BitCoin you know that in the
entire peer to peer network it takes them

38
00:02:12,905 --> 00:02:16,620
about 10 minutes to solve a block, that's
the idea of a moderately hard function.

39
00:02:16,620 --> 00:02:20,720
It takes a significant amount of time but
it's not also completely infeasible,

40
00:02:20,720 --> 00:02:24,420
as would be the case if you were trying
to recover someone's private key

41
00:02:24,420 --> 00:02:27,369
from their public key in the signature
scheme that BitCoin uses.

42
00:02:28,880 --> 00:02:34,510
So, the idea of applying moderately
hard puzzles to solving cash like

43
00:02:34,510 --> 00:02:39,830
systems, cash like problems was
first proposed by Dwork and

44
00:02:39,830 --> 00:02:42,480
Naor, and they looked at email spam.

45
00:02:42,480 --> 00:02:45,920
And so their idea was what if
every time you spend an email,

46
00:02:45,920 --> 00:02:49,430
you would have to compute the solution
to some moderately hard puzzle?

47
00:02:49,430 --> 00:02:54,150
For the average user it wouldn't be
that much of a barrier to sending

48
00:02:54,150 --> 00:02:56,750
emails because you're not sending
emails very frequently, but

49
00:02:56,750 --> 00:02:58,790
if you're a spammer and
you're trying to send out thousands or

50
00:02:58,790 --> 00:03:02,440
millions of emails all at once then that
cost would become prohibitive once you

51
00:03:02,440 --> 00:03:07,810
multiply it by the thousand or
million emails that you're trying to send.

52
00:03:07,810 --> 00:03:11,120
This idea was later
actually implemented and

53
00:03:11,120 --> 00:03:15,660
sort of independently discovered by
Adam Back in a proposal called Hashcash.

54
00:03:15,660 --> 00:03:18,820
Now, proof of work or
moderately hard puzzles,

55
00:03:18,820 --> 00:03:22,490
they also can be used
just to slow things down.

56
00:03:22,490 --> 00:03:26,530
So if you have some function and you want
to delay the amount of time that it takes,

57
00:03:26,530 --> 00:03:29,780
think about the creation of blocks
in the block chain in Bitcoin,

58
00:03:29,780 --> 00:03:33,210
you can also apply it to
this problem as well.

59
00:03:35,020 --> 00:03:38,070
So Hashcash as mentioned was
proposed by Back in '97 and

60
00:03:38,070 --> 00:03:43,310
it was the same idea which is
that if you're a emailer or you

61
00:03:43,310 --> 00:03:49,110
can think of it as a more general level,
if you are the consumer of some resource.

62
00:03:49,110 --> 00:03:51,660
Then in order to consume that resource or
send an email,

63
00:03:51,660 --> 00:03:55,230
you would have to generate the solution
to one of these moderately hard puzzles,

64
00:03:55,230 --> 00:03:58,390
or they're also known as
proof of work protocols.

65
00:03:58,390 --> 00:04:02,910
So the specific puzzle that Hashcash uses,
which will look familiar to you,

66
00:04:02,910 --> 00:04:08,070
having looked at BitCoin, what happens
is you're given a hash function,

67
00:04:08,070 --> 00:04:12,290
and your'e giving some string, we will
talk about what's in this string, but

68
00:04:12,290 --> 00:04:16,530
the idea is you have a nonce value and
you can choose any value you want.

69
00:04:16,530 --> 00:04:19,930
So the easiest thing would be to set
it equal to 0 like a counter then

70
00:04:19,930 --> 00:04:21,070
step through.

71
00:04:21,070 --> 00:04:24,950
So what you would do is you would hash
this string together with your chosen

72
00:04:24,950 --> 00:04:27,593
nonce, say 0, and
you would look at the output.

73
00:04:27,593 --> 00:04:30,807
Now the output would be random looking.

74
00:04:30,807 --> 00:04:33,556
And just by chance it will have
a certain number of leading zeroes.

75
00:04:33,556 --> 00:04:34,900
Maybe it has none.

76
00:04:34,900 --> 00:04:37,450
The output happens to start with a 1.

77
00:04:37,450 --> 00:04:40,000
Maybe you get two or
three leading zeroes, and

78
00:04:40,000 --> 00:04:42,930
the idea is that you would
change this nonce value.

79
00:04:42,930 --> 00:04:47,020
And you would keep computing this hash
until you happen to find some nonce value

80
00:04:47,020 --> 00:04:50,800
that satisfies an output where
there's m leading zeroes,

81
00:04:50,800 --> 00:04:55,520
where m could be a number like 20 or 40.

82
00:04:55,520 --> 00:04:58,120
Now, what's inside the string
that you're hashing

83
00:04:58,120 --> 00:05:01,260
that ties it back into the email
system that we're trying to do?

84
00:05:01,260 --> 00:05:04,160
So the first thing is there's some
name that describes the service

85
00:05:04,160 --> 00:05:06,350
that you're going to use
this Hashcash to spend on.

86
00:05:06,350 --> 00:05:10,420
And what this does is it just means that
this cash can only be spent consuming that

87
00:05:10,420 --> 00:05:11,350
service, okay?

88
00:05:11,350 --> 00:05:16,248
So if you generate one coin,
you can't use it to both send email and,

89
00:05:16,248 --> 00:05:18,790
you know, download a file with it.

90
00:05:18,790 --> 00:05:20,690
Another thing is a validity period.

91
00:05:20,690 --> 00:05:25,300
So, Hashcash has the problem of double
spending, like all e-cash systems.

92
00:05:25,300 --> 00:05:27,570
And it solves it the same
way as everyone else does.

93
00:05:27,570 --> 00:05:30,760
Which is the person that's receiving
the Hashcash, they just keep a list of all

94
00:05:30,760 --> 00:05:35,420
the Hashcash they've seen, and they check
it to see if someone spends it twice.

95
00:05:35,420 --> 00:05:37,349
Okay.
Now, this list would get really long

96
00:05:37,349 --> 00:05:40,469
over time, and so if you put
a validity period into the Hashcash,

97
00:05:40,469 --> 00:05:44,466
say the Hashcash lasts three months, then
your list, you can at least shorten it.

98
00:05:44,466 --> 00:05:47,834
As soon as Gashcash that you've
seen that expired a month ago,

99
00:05:47,834 --> 00:05:51,470
you can purge it from your list and
you can end up with a shorter list.

100
00:05:54,490 --> 00:05:58,415
Another thing, another alternative if
you don't want to maintain a list,

101
00:05:58,415 --> 00:06:02,279
is if you have an interactive protocol
where the person that you're giving

102
00:06:02,279 --> 00:06:06,476
the Hashcash to is online when you're
ready to deliver or consume the resource.

103
00:06:06,476 --> 00:06:09,346
Then what that person can do is
they can send you a challenge.

104
00:06:09,346 --> 00:06:13,173
And if they send you a challenge you can
incorporate in your proof of work and

105
00:06:13,173 --> 00:06:16,601
now that proof of work or
that Hashcash is specific to that person.

106
00:06:16,601 --> 00:06:21,004
That person gave you the challenge, they
know that it's not a double spends because

107
00:06:21,004 --> 00:06:24,430
they choose random challenges
every time they ask for Hashcash.

108
00:06:26,570 --> 00:06:31,930
The final alternative is if you
are not in the interactive setting,

109
00:06:31,930 --> 00:06:34,560
if you're just generating
Hashcash yourself,

110
00:06:34,560 --> 00:06:39,200
it could be that a spammer still is able
to send a million emails just by spending

111
00:06:39,200 --> 00:06:43,880
a really long time computing Hashcash for
all the emails that they want to spend.

112
00:06:43,880 --> 00:06:48,150
And so one thing you can do is you can
prove that your Hashcash is fresh,

113
00:06:48,150 --> 00:06:49,550
that it was freshly generated.

114
00:06:49,550 --> 00:06:52,590
It wasn't generated before
some period in the past.

115
00:06:52,590 --> 00:06:55,370
And the way you can do
this is with a beacon.

116
00:06:55,370 --> 00:07:00,474
A beacon is just a fancy way of saying
some source of unpredictable randomness.

117
00:07:00,474 --> 00:07:03,260
So in the Hashcash proposal,
they thought about lottery tickets.

118
00:07:03,260 --> 00:07:06,170
You could use the lottery
numbers of a certain day, and

119
00:07:06,170 --> 00:07:09,640
if that was involved in the creation
of this Hashcash, you know that

120
00:07:09,640 --> 00:07:14,660
the person started computing the Hashcash
after those lottery numbers were released.

121
00:07:14,660 --> 00:07:18,960
You could also use stock market prices, or
you could use the cover of the Times of

122
00:07:18,960 --> 00:07:23,450
London, because no one could predict what
the story would be on a particular day.

123
00:07:23,450 --> 00:07:27,506
At least, not before say a day
before that newspaper was published.

124
00:07:27,506 --> 00:07:30,727
Now you might recognise
the Beacon from BitCoin,

125
00:07:30,727 --> 00:07:36,093
because in BitCoin what Satoshi did is in
the very first block, the Genesis block,

126
00:07:36,093 --> 00:07:41,155
he incorporated a newspaper article
that proved that he didn't start working

127
00:07:41,155 --> 00:07:46,013
on the block chain until after the date
that that newspaper was published.

128
00:07:46,013 --> 00:07:46,680
Okay?

129
00:07:46,680 --> 00:07:49,700
So this could prevent some
sort of farfetched attack, but

130
00:07:49,700 --> 00:07:52,110
maybe where he pre-computed
a huge block chain.

131
00:07:52,110 --> 00:07:54,754
And then as other people came
into the BitCoin network and

132
00:07:54,754 --> 00:07:56,970
started competing with
him to solving blocks.

133
00:07:56,970 --> 00:07:59,179
If someone else solved a block,
he could just drop two or

134
00:07:59,179 --> 00:08:01,966
three blocks because he had this long,
pre-computed chain, okay?

135
00:08:01,966 --> 00:08:06,658
So he proved that he didn't actually do
this attack by incorporating a beacon into

136
00:08:06,658 --> 00:08:07,820
the genesis block.

137
00:08:08,870 --> 00:08:11,590
Let's compare and
contrast Hashcash with Bitcoin.

138
00:08:12,790 --> 00:08:17,210
Now, the problem with Hashcash
is that the granularity of

139
00:08:17,210 --> 00:08:20,920
the proof of worker moderately
hard puzzle, is very course.

140
00:08:20,920 --> 00:08:23,830
Essentially all you can do is you
can increase the number of zeros

141
00:08:23,830 --> 00:08:27,350
that are required at the output of the
hash function or you can decrease them.

142
00:08:27,350 --> 00:08:30,590
What this effectively does is
double how hard the problem is.

143
00:08:30,590 --> 00:08:33,530
Or you can it scale it back and
have the problem as well.

144
00:08:33,530 --> 00:08:35,870
So, we know, from BitCoin,
that the block chain.

145
00:08:35,870 --> 00:08:37,686
You want to solve blocks, on average,

146
00:08:37,686 --> 00:08:40,711
the whole network wants to solve
them in a ten minute interval.

147
00:08:40,711 --> 00:08:44,088
So let's say that, for some reason,
the network got really fast, and

148
00:08:44,088 --> 00:08:48,053
they started solving blocks on average,
in eight minutes instead of ten minutes.

149
00:08:48,053 --> 00:08:50,920
And so you want to make
the problem a little more hard.

150
00:08:50,920 --> 00:08:56,720
Now, if BitCoin used Hashcash's, proof
of work, then they could only double it.

151
00:08:56,720 --> 00:09:00,820
So we go from eight minutes to 16 minutes,
and then that's way too long.

152
00:09:00,820 --> 00:09:04,580
And so what we want is a finer grade
precision where we can make it harder so

153
00:09:04,580 --> 00:09:08,310
that something that's taking eight
minutes can take exactly ten minutes.

154
00:09:08,310 --> 00:09:14,060
So Satochi observed that there's way of
thinking about the Hashcash proposal for

155
00:09:14,060 --> 00:09:18,270
proof of work that's equivalent but
looks at it slightly different.

156
00:09:18,270 --> 00:09:22,340
If you think about an output that has
a whole bunch of leading zeros, well any

157
00:09:22,340 --> 00:09:25,990
number with a huge number of leading
zeros is actually just a small number.

158
00:09:25,990 --> 00:09:27,390
That's another way of thinking about it.

159
00:09:27,390 --> 00:09:30,594
Small numbers are numbers that
have a lot of leading zeros.

160
00:09:30,594 --> 00:09:35,444
And so, what you can think of it as
equivalently is you're hashing this thing

161
00:09:35,444 --> 00:09:39,337
until you get a number that's
smaller than some upper bound.

162
00:09:39,337 --> 00:09:40,280
Okay?

163
00:09:40,280 --> 00:09:41,250
And in Hashcash,

164
00:09:41,250 --> 00:09:46,440
because they're selecting bits, that upper
bound has to be a perfect power of two.

165
00:09:46,440 --> 00:09:48,800
But there's no reason that it has
to be a perfect power of two.

166
00:09:48,800 --> 00:09:50,590
It could be any number that you want.

167
00:09:50,590 --> 00:09:54,480
You can just pick a number and say, keep
hashing until it's less than this number.

168
00:09:54,480 --> 00:10:00,330
And so with that tweak, Satoshi proposed
that, that number just be any integer.

169
00:10:00,330 --> 00:10:04,149
It's called the target and the proof of
work that Bitcoin uses is very similar to

170
00:10:04,149 --> 00:10:07,569
Hashcash but with this twist that
you're trying to generate a number,

171
00:10:07,569 --> 00:10:10,715
an output of your hash that's
less than this particular number.

172
00:10:12,672 --> 00:10:14,361
Now another proposal for

173
00:10:14,361 --> 00:10:19,540
how to mint coins using proof of work
comes from Rivest and Shamir in '97.

174
00:10:19,540 --> 00:10:24,175
These are the R and the S and
the RSA crypto system, respectively.

175
00:10:24,175 --> 00:10:29,151
And they observed that with Hashcash style
minting what happens is when you solve,

176
00:10:29,151 --> 00:10:30,643
say you create one coin,

177
00:10:30,643 --> 00:10:35,051
if you want to solve the proof of work
to create a second coin, a third coin,

178
00:10:35,051 --> 00:10:38,846
it takes you the same amount of
work every time you want to do it.

179
00:10:38,846 --> 00:10:41,457
Now for Rivest & Shamir,
unlike at Hashcash,

180
00:10:41,457 --> 00:10:45,966
where users themselves are generating
their own Hashcash, Rivest & Shamir were

181
00:10:45,966 --> 00:10:50,304
interested in what if a government decided
they wanted to mint money instead?

182
00:10:50,304 --> 00:10:54,250
And if you think about how
anti-counterfeiting works just in say

183
00:10:54,250 --> 00:10:58,920
paper currency, in order to counterfeit
a bill there is a huge initial cost.

184
00:10:58,920 --> 00:11:02,562
You have to acquire all the equipment to
mimic the security features that are on

185
00:11:02,562 --> 00:11:04,370
the bills.

186
00:11:04,370 --> 00:11:08,070
But, once you have all that equipment,
then it doesn't matter if you print one

187
00:11:08,070 --> 00:11:11,140
bill, or you print a hundred bills,
your costs go down.

188
00:11:11,140 --> 00:11:15,638
So, it has a huge fixed overhead cost,
but it has a low marginal cost.

189
00:11:15,638 --> 00:11:18,588
And so, they were interested in
whether you could do a proof of

190
00:11:18,588 --> 00:11:20,932
work scheme that would
mimic these properties.

191
00:11:20,932 --> 00:11:24,269
Where it would cost real lot
to mint that first coin, but

192
00:11:24,269 --> 00:11:28,319
once you have the computational
abilities to mint that first coin,

193
00:11:28,319 --> 00:11:32,850
then minting a second, third, and
forth coin became a lot cheaper.

194
00:11:32,850 --> 00:11:35,740
And so they had a proposal,
it was also based on hash functions.

195
00:11:35,740 --> 00:11:39,470
In this case it was based on finding
collisions as opposed to preimages.

196
00:11:39,470 --> 00:11:41,491
We won't go through
the details of their scheme but

197
00:11:41,491 --> 00:11:44,556
it was interesting at a high level the
problem that they were trying to solve.

198
00:11:46,637 --> 00:11:49,668
Another extension of Hashcash
comes from Hal Finney.

199
00:11:49,668 --> 00:11:55,760
And what Hal didn't like about Hashcash is
that once you create a unit of Hashcash,

200
00:11:55,760 --> 00:11:58,410
you spend some computational
resources creating it.

201
00:11:58,410 --> 00:11:59,225
You spend it.

202
00:11:59,225 --> 00:12:03,178
But then you have to retire that
coin to prevent double spending.

203
00:12:03,178 --> 00:12:06,420
You have to check that that
coin doesn't get spent again.

204
00:12:06,420 --> 00:12:09,383
There's no way that,
once you mint a piece of Hashcash,

205
00:12:09,383 --> 00:12:11,805
it can be passed around
from person to person.

206
00:12:11,805 --> 00:12:15,030
So he thought, well,
what if I set up a server?

207
00:12:15,030 --> 00:12:18,109
And every time you spend
a piece of Hashcash,

208
00:12:18,109 --> 00:12:23,310
you could send it to the server and
the server will sort of refresh that coin.

209
00:12:23,310 --> 00:12:27,150
It won't refresh it by computing a new
proof of work, it will just refresh it

210
00:12:27,150 --> 00:12:30,690
because you trust the server to only
refresh coins that it receives and

211
00:12:30,690 --> 00:12:31,837
not create new coins.

212
00:12:31,837 --> 00:12:32,810
Out of thin air.

213
00:12:32,810 --> 00:12:36,549
And then to provide a layer of security,
what he did is,

214
00:12:36,549 --> 00:12:40,910
he based this server using
a trusted platform module or a TPM.

215
00:12:40,910 --> 00:12:44,510
Which is a little chip where
you can create programs.

216
00:12:44,510 --> 00:12:47,093
And you can actually remotely,
over the Internet.

217
00:12:47,093 --> 00:12:47,642
Check and

218
00:12:47,642 --> 00:12:51,973
see that that computer is running
exactly the program that was specified.

219
00:12:51,973 --> 00:12:54,991
So he set up a server that used
this remote attestation, so

220
00:12:54,991 --> 00:12:59,134
you can check that this refreshing service
wasn't creating its own new coins.

221
00:12:59,134 --> 00:13:01,342
It was just refreshing existing hashcash.

222
00:13:03,888 --> 00:13:07,650
Now, let's think about the differences
between Hashcash and BitCoin.

223
00:13:07,650 --> 00:13:12,230
So, as we mentioned, Bitcoin effectively
uses Hashcash's proof of work but

224
00:13:12,230 --> 00:13:15,090
it modifies it slightly,
instead of shooting for

225
00:13:15,090 --> 00:13:17,960
a number that's smaller than a perfect
power of two, it's any number.

226
00:13:17,960 --> 00:13:19,500
But, that's just a slight modification.

227
00:13:20,520 --> 00:13:23,340
The more substantial difference
is a little more subtle.

228
00:13:23,340 --> 00:13:26,010
In Bitcoin,
the proof of work is being used for

229
00:13:26,010 --> 00:13:28,110
a different purpose than minting coins.

230
00:13:28,110 --> 00:13:31,610
You're not solving the proof of
work in order to mint coins.

231
00:13:31,610 --> 00:13:35,337
Now you might be saying, wait a minute,
that's not right, we have these miners.

232
00:13:35,337 --> 00:13:39,174
And we call them miners because
they're minting new coins.

233
00:13:39,174 --> 00:13:41,964
And all miners do is solve proof of work,
right?

234
00:13:41,964 --> 00:13:45,874
So obviously the proof of work is being
solved in order to mine new coins or

235
00:13:45,874 --> 00:13:47,200
mint new coins.

236
00:13:47,200 --> 00:13:50,420
However there is a subtle distinction
here that needs to be made.

237
00:13:50,420 --> 00:13:54,180
The best way to think about this is maybe
think about what happens to BitCoin

238
00:13:54,180 --> 00:13:56,810
after all 21 million BitCoins are created.

239
00:13:56,810 --> 00:14:00,690
What happens is the miners, the so called
miners, they continue solving the proof of

240
00:14:00,690 --> 00:14:03,540
work even though they are not
getting any new money.

241
00:14:03,540 --> 00:14:04,140
Okay?
So

242
00:14:04,140 --> 00:14:07,440
they're not actually solving the proof
of work to generate new money,

243
00:14:07,440 --> 00:14:10,140
they're doing something else
to solve the proof of work.

244
00:14:10,140 --> 00:14:14,447
Specifically what they're doing is they're
solving the proof of work to add blocks to

245
00:14:14,447 --> 00:14:15,339
the block chain.

246
00:14:15,339 --> 00:14:15,990
Okay?

247
00:14:15,990 --> 00:14:20,920
Now the mechanism for minting new
coins piggy backs on that system

248
00:14:20,920 --> 00:14:24,730
where if you create a new block will
also insert new coins into that block,

249
00:14:24,730 --> 00:14:28,765
at least for a certain time period
that the claim runs over, but

250
00:14:28,765 --> 00:14:33,960
it's not the idea of Hashcash where any
individual can fire up their computer and

251
00:14:33,960 --> 00:14:36,970
directly mint coins by solving
a proof of work system.

252
00:14:36,970 --> 00:14:40,200
BitCoin also differs from
Hashcash In the sense that

253
00:14:40,200 --> 00:14:43,340
Bitcoin has a lot more to
it than Hashcash does.

254
00:14:43,340 --> 00:14:45,670
In Hashcash, it's a simple
system where you mint a coin,

255
00:14:45,670 --> 00:14:47,200
you send it to someone else.

256
00:14:47,200 --> 00:14:49,940
In Bitcoin you have a distributed
peer-to-peer network,

257
00:14:49,940 --> 00:14:51,480
you have the blockchain with the ledger,

258
00:14:51,480 --> 00:14:55,840
you have transactions which have
very complicated transaction types.

259
00:14:55,840 --> 00:15:00,630
So I only belabor this point because
there is this notion that, for example,

260
00:15:00,630 --> 00:15:03,790
in the words of Adam Back
who invented Hashcash,

261
00:15:03,790 --> 00:15:07,188
he says that Bitcoin is hashcash
extended with inflation control.

262
00:15:07,188 --> 00:15:09,831
I think that's overreaching a bit,

263
00:15:09,831 --> 00:15:15,466
it's sort of like saying a Tesla is just
a battery that has transportability.

264
00:15:15,466 --> 00:15:18,878
So, why did Hashcash never catch on?

265
00:15:18,878 --> 00:15:23,080
Probably the issue is that spam just
wasn't a big enough problem to solve.

266
00:15:23,080 --> 00:15:25,530
For a lot of people,
they view spam as a nuisance, but

267
00:15:25,530 --> 00:15:30,570
it's not something they want to spend
their computing cycles on combatting.

268
00:15:30,570 --> 00:15:32,010
We have spam filters today, and

269
00:15:32,010 --> 00:15:35,270
they work pretty well at keeping
spam out of our inboxes.

270
00:15:35,270 --> 00:15:38,470
It's also possible that it wouldn't
actually prevent spammers.

271
00:15:38,470 --> 00:15:40,430
In particular, if spammers had a botnet,

272
00:15:40,430 --> 00:15:43,470
where they took control of a large
number of other people's computers,

273
00:15:43,470 --> 00:15:45,710
then they could use those
computers to harvest hashcash.

274
00:15:45,710 --> 00:15:47,120
And then they could continue spamming us.

275
00:15:48,500 --> 00:15:53,510
However, that said, the idea of using
proof of work to limit resources,

276
00:15:53,510 --> 00:15:55,110
it's still an idea that's kicking around.

277
00:15:55,110 --> 00:15:59,986
You can see it in some proposals for
replacing network protocols, for example,

278
00:15:59,986 --> 00:16:00,713
MinimaLT.

