A-Ads

Showing posts with label cryptography. Show all posts
Showing posts with label cryptography. Show all posts

Sunday, July 13, 2014

Why "Capitalism" Fails and how Bitcoin saves it




Many of the critics of capitalism love to point to those parts of the world where newly-freed markets have encountered major problems as "proof" that capitalism doesn't work.

Without hesitation, big-government advocates will talk about large global corporations that were deemed "too big to fail", and had to be bailed out at the expense of the taxpayers and little guys.  With similar logic, they point to former Soviet bloc countries which have seen violent opposition to capitalist reforms and little benefit from them.

Like many controversies, much of the problem lies in the differing definitions of words.  To a Free-Market Capitalism, free market means zero regulation.  To pro-government socialists, "free market" usually means "not regulated the right way" or "not regulated enough".

The truth is that the big banks, auto manufacturers, and investment firms that received the bailouts from the U.S. government operate in the some of the most highly-regulated industries on earth.
For example, the auto industry is regulated by thousands and thousands of laws and regulations; everything from those pertaining to import/export restrictions, safety, fuel economy to labor relations, and emissions standards - not to mention the SEC regulations controlling the issuing and sales of company stocks and their financial businesses like GMAC.  Each of these regulations presents a barrier of entry to new players in the market.  This is how government protects the cartel, by discouraging competitors from entering and competing against their existing political contributors and allies.  This stifles innovation.


Then there are those who bring up the failure of "free markets" in other countries.  There is a very long list of countries which were once socialist or communist, but then either peaceably or through violent revolt gained some level of personal and/or economic freedom, only to find that the transition didn't go as smoothly as free market advocates had hoped for.  

Hernando deSoto makes a great observation in his book The Mystery of Capital where he explains the foundation of all capital in being the establishment of undisputed claims to property.  The thing that makes capitalism work is that the foundation of all capitalism lies in proving that a particular piece of property actually belongs to a particular person or entity.  

He also argues that capitalism has been successful in the west precisely because of the establishment of records of ownership via titles.  In the west, when a person purchases a piece of property, there is a record of the transfer of ownership that is recorded in a public registry which can be accessed by anyone.  

Still, accusations of collusion, forgery, corruption, and conspiracy would occasionally bring challenges
to this system, which would be resolved by a system of courts.  In countries where distrust of government institutions, courts, and wealthy landowners is embedded in the minds of the populace (such as in former communist countries), this system is even more limited.  Trust in the institutions that witness and record these transactions is absolutely necessary for the entire system to function. That trust often does not exist in other countries and cultures.

What made the limited form of capitalism that the U.S. enjoyed a success was the system of public record-keeping of property ownership that was somewhat accurate and the court system that was in place for resolving disputes.  When buying a house, for example, a lawyer or title company could do a simple search through public records to find if the seller has the legitimate legal right to sell the house to the buyer and transfer that ownership and file the transfer with the local government office in order to list it in the public record.

Today, we are seeing a very strong erosion of that trust in the system which is needed in order to facilitate the peaceful exchange of goods due to the exposure of the corruption that is (and probably has been) in the system.  The massive amounts of foreclosures going on with the current and on-going housing crisis is exposing the fact that many people are being defrauded out of their homes through either corrupt lawyers, banks, and title companies, environmental regulations, and/or through lazy and sloppy filings.

The failure of these centralized systems is that they require a level of trust in the system.

Enter the Blockchain

The backbone of the phenomenon that is crypto-currency, the most famous of which is Bitcoin, is the Blockchain.  The Blockchain is a public record of ownership of currency which is anonymous, fully-distributed, decentralized, and publicly viewable from any computer.  The computer code behind the Blockchain is open-source so anyone can view it to make sure it is on the up and up.

Bitcoin transactions work by simply updating records in this public ledger which is stored on multiple computers all over the world, and agreed upon by all of them.  The entry of transactions appear in the order decided by the network itself and not by any person or group of persons.  For every transaction the ownership of the coins being used as currency is traced all they way back through the Blockchain to the time the coins first went into circulation or all the way back to the Genesis Block. Best of all, the entire thing is encrypted, secure, and anonymous.  While this system is what is used for the transfer of currency, the uses for the Blockchain idea are nearly endless.

The beauty of the Blockchain system is that it requires zero trust in anyone.  In fact, it operates on the assumption that everyone is a crook.

Here are some of the other potential uses for blockchains:

Title transfers of real estate.  The use of a blockchain for real estate is the next most-logical step.  This would eliminate the need for lawyers and title companies along with their outrageous fees.  

The existence of a public ledger that is free from political corruption would work miracles in places where land disputes often escalate into violent wars.  This is one of the primary roles for many or perhaps most country governments, almost eliminating the need for a county government altogether.


Sales of automobiles.  Imagine no more involvement of the local or state DMV in selling or buying
cars.  No more standing in their lines, paying whatever fees they demand, and no more annual registration fees.

The need for license plates also goes away - which won't make law-enforcement happy, but it's your right not to be identified while traveling, and you've given up that right by putting a license plate on your car.













Ownership and Structure of Corporations.  Already, the blockchain model is being to theoretically create corporations where the ownership is fully-distributed and shares are traded like currency on a Blockchain instead of on a central trading floor through
a brokerage.

Intellectual Property Rights.  While most advocates of decentralized networks are opposed to the idea of Intellectual Property in general, there is no reason that a Blockchain could not be used for this purpose.  This would eliminate the central bureaucratic powers that run the U.S. Patent and Trademark Office and their foreign counterparts.  Enforcement of these "rights" would be a different subject altogether, though a voluntary system could be implemented and the Blockchain could be used for the management of royalty payments and licensing fees, etc.  

Registration of Internet Domain Names.  Currently Domain Names are registered by a single corporation that holds a monopoly on this service (ICANN).  The oversight of a world-wide distributed network like the Internet by a corporate monopoly makes little sense.  Complaints against ICANN abound, and they are often slowly and poorly handled (as you would expect from a monopoly).   Replacing ICANN with a group of fully-distributed networks could handle all their functions and totally replace the organization.   

Namecoin is already in the process of making much of this happen.


Much of the "under the hood' stuff of the World Wide Web systems could be better managed by distributing these tasks through the network of a blockchain.  A lot of the stuff most of us never see like the management of TLS/SSL certificates and that sort of thing.  

There are literally hundreds of current uses for the Blockchain architecture.  All of them are designed to take power out of the hands of the few large corporate monopolies, oligopolies, and government-protected cartels and put them in the hands of the individual - thus fully-distributing their powers.  The Blockchain is a threat to all things centralized, be it banks, insurance cartels, oil & gas cartels, unions, trading floors, etc. For this reason, it is the key to crushing government oppression by starving it of the labor, resources, and power that it acquires through centralization.


The reason capitalism has failed to take hold or flourish in many 3rd world countries is taken away by the Blockchain.  A trustworty, anonmymous, private, encrypted, secure, and efficient system that records ownership records is here.  It will liberate the entire world by crushing cartels like the Federal Reserve, the International Monetary Fund, the World Bank, OPEC, the New York Stock Exchange, the regional energy utilities, Internet Service Providers, currency exchanges (FOREX), NASDAQ, as well as the drug cartels, not by outright destruction, but by making them irrelevant and obsolete.  Bitcoin can and will liberate the world... peacefully.    

This is just the beginning.  




Monday, September 9, 2013

Building a PGP web of trust that people will actually use

http://bitcoinism.blogspot.com/2013/09/building-pgp-web-of-trust-that-people.html?m=1

Sunday, September 8, 2013


Building a PGP web of trust that people will actually use

Back in the early 1990s, PGP introduced the concept of web of trust (WoT)- a means by which users of personal encryption can know whether or not the key they are using actually belongs to the person they want to communicate with. Without some mechanism for verifying the connection between a cryptographic key and an identity encryption is mostly useless. All an attacker needs to do is insert themselves between the sender and recipient and trick each party into using the attacker's key for encryption instead of the intended recipient. This is the man in the middle attack, and based on the actual state of personal encryption as it is currently deployed, is still an unsolved problem 22 years after PGP was introduced.

There are two basic ways to solve the problem - first, all users can register with a central authority who vouches for their identity. This is the model used by SSL certificates, and it's worse than useless. Despite the illusion of security they provide, certificate authorities are routinely subverted by governments and other types of criminals, and there is little that a user can do to avoid this weakness inherent to a centralized model.

The web of trust concept is based on the idea of decentralized trust and social networks. Instead of trusting Verisign to validate identities, you validate the identities of the people you know and export this information to a public database. Then you rely on you friends to vouch for the people they know, and those friends to vouch still more people, and so on until you can create a trust chain between any two arbitrary identities.

This approach avoids the inherent problems of central authorities, but in practice virtually nobody uses it outside the open source software community, and even there it is hit or miss. The rest of this articles is going to discuss two reasons for the failure to deploy this technology, and how to solve them. First, the problems:

  1. The software tools are hard to use, even for experts. As as result, even people who understand how important it is usually don't bother.
    • Usability failures of privacy software should be regarded as possessing the same degree of severity as algorithmic or code failures, because there is no difference in practice between a message that is sent in cleartext because encryption was too hard and one that was decrypted by an adversary due to an implementation flaw.
  2. Even among the tiny minority of users who bother to sign keys, within the tiny minority of users who bother to encrypt at all, almost nobody agrees what it actually means to sign a key.
    • The definition of "identity" in a cryptographic sense does not directly map to how our brains naturally process it, and this impedance mismatch has never been addressed successfully.
    • Most users of personal encryption can't explain what they are actually verifying when they sign another person's public key.

What is Identity?

The stereotypical way that PGP users build out the WoT is via a key signing party. A group of people who meet in person, typically at a software conference, and exchange public keys. They they sign the public keys they collect and (hopefully) remember to upload those signatures to key servers where they can be used by others. The amount of identity verification that is applied is highly inconsistent. Some people might verify the government-issued ID card of the person handing them a key (or a key fingerprint), others might just blindly sign anything that gets handed to them. Most frequently of all, however, is that the key signing party never happens at all.

If we assume the purpose of a WoT is to unambiguously and unimpeachably map public keys to human beings, there are two ways in which the typical key signing party fails.

  1. The mere presentation of a public key or a key fingerprint does not prove the person delivering it actually controls the associated private key. The only way to such ownership may be proved is if the person can sign data on the spot which could not have been predicted ahead of time.
  2. Government issued ID cards are useless when it comes to what we actually mean when we talk about about identity. For example, I could meet someone at a key signing party with a valid government-issued ID card containing the name "Linus Torvalds". In principle, I could meet an arbitrarily high number of unique people all sharing that same name. They won't all be the Linus Torvalds, though.
Identity, as we humans understand it, is a set of shared experiences. We don't know our friends by a set of characters printed on a piece of plastic; we know our friends by the past interactions (direct or otherwise) we've had with them.

If I want to send an encrypted email to Linus Torvalds, and if I want to use some kind of public database to help me make sure I'm using the right key for encryption, the actual question I want the database to answer is not, "Does the owner of this public key posses an ID card containing the name Linux Torvalds?" The actual question I want answered is, "Is the owner of this public key the inventor of the Linux kernel?"

The signatures that form the basis of the existing WoT are thus useless because they don't certify the right data - the data that forms the basis for how we actually understand identity. Before we can have an effective WoT, one that normal people are willing to use, we first need a well-defined method of representing identity that matches our intuitive understanding.

Getting Identity Right

A successful WoT must be built very much like a social networking site, because that's how we obtain the shared experience information for certification, and that's the model that hundreds of millions of people all over the world are already comfortable using.

We also need to take advantage of mobile computing technology. Secure key exchange has to occur through tamperproof channels, and there's no way to achieve that in practice except in person. 22 years ago nobody had a smartphone and not many had laptops, but now enough people own smartphones that our key exchange protocols can rely on their capabilities.

The rest of this proposal assumes that we can trust the hardware we own. This is a known-false assumption, and an urgent problem, but solving it is something that will have to be handled via other efforts.

Given a more through understanding of the nature of identity, and with the understanding that the protocol must prioritize usability at least as much as cryptographic integrity, let's approach the problem by building an enjoyable social networking game that just happens to build a secure WoT as a side effect.

Imagine a social networking site called "iMet". The way it works is that users register on this account, and fill out facts about themselves. The facts could be serious like the kind you'd put on LinkedIn, or frivolous like most Facebook posts. Users "friend" other users by meeting them in person and using a smartphone app to certify. They are then presented with a list of facts about the person they just met which can be answered as true, false, or unsure. Their scores go up based on the number of people they met, and the accuracy of their answers. Users can also compete with their friends for obtaining the shortest path to famous or otherwise noteworthy people. Properly implemented, this application sufficiently fun and compelling such that people would participate for its own sake, without needing to care about cryptography.

Behind the scenes, however, these interactions can be leveraged to build a secure WoT.  When users "iMeet" with their smartphones they are actually performing a secure key exchange over NFC or camera/QR code, whichever is available and most convenient.

The specific facts are represented as text strings. When users answer questions about other users, their clients sign a (key id, string, ACK/NACK, date) tuple. These tuples are publicly searchable and can be used by PGP clients for WoT calculations.

Usability details

Anyone who has ever tried to put user-supplied information into a database knows that regular people are terrible at structuring data. This protocol allows for user-supplied arbitrary text strings, but an actual implementation should go to great lengths to sanitize their inputs first. For example, the UI should ask for common facts, such as birth date, and format them in an agreed-upon way.

Another problem is that most people don't understand the difference between time-variant and time-invariant facts. My date of birth is time-invariant. Most of the other facts which form my identity are not. The text strings should be formatted in a way that time-variant facts can be sanely represented and verified. The UI should not accept a "street address" fact without an associated date range. When I certify my friend's street address, by default my signature should be interpreted to mean "true as of the date of the signature", unless I specify otherwise. Clients who are parsing the public database must be able to intelligently handle the time element of truth.

Unsolved problems

  • Cheating by manually creating signatures without actually meeting in person: is this an actual problem, and if so, how could it be fixed?
  • Distribution of data: Will there be just one site handling all this data, or will it be distributed somehow?
    • If there are multiple providers, how to you make sure data is globally available?
    • If there is a single provider, how do you prevent the CA failure mode?

What do we do with it?


Successfully building a secure, decentralized WoT is just the first step to building a large number of other secure services. Once secure cryptographic identities exist and are available the WoT forms a foundation that can be used by other projects:

  • Encrypted communications
  • Personal clouds
  • Website logins
Really the sky is the limit once the WoT exists, we don't yet know what is ultimately possible once it exists because so far we've never got to the point of building one that works for a critical mass of the population. Given recent events, there's never been a better time to to do it than now.