back

by padolsey·4y ago·view on hn ↗
People keep saying 'trustless', without realizing the upsetting and very real truth that no mechanism is trustless. Even if you can, if well informed, verify the cryptographic integrity of any communication or data, you are also relying on and trusting the device, UI, and OS that you're using (+myriad stacks, libs, protocols). You are relying on every single medium between you and whatever it is that's verifiable. Let's not kid ourselves. There is no 'trustless'. We just end up assigning the burden of trust to other things. Unless you've built every element from transister upwards, then you're assigning trust. If we implemented, e.g., blockchain based democracy you can bet your bottom dollar that vulnerabilities will be found and utilized.
5 comments
I guess when people say `trustless`, it means that they don't have to trust every single elements of the chain between you and your target: if any steps of the chain acting untruthfully, it would be detected by other steps thanks to the protocol they're using.

Of course, with enough failures in the link, anything can be compromised.

But how do you know who is holding the phone/keyboard? If my phone is stolen and someone then sells my house and drains my bank accounts, how can I prove it was not me?

The whole thing is built on sand.

Suggesting that it is all verifiable etc is fine and dandy, but that is risky as the onus of proof falls to the victim. It is a bit like when Chip+Pin first came in for the UK way back when - there was this suggestion by the banks that fraud was now impossible, and the only possible way for the card to be used was by you the account holder as you are the only person that knows your pin is 1234.

Obviously that was bullshit and they have softened their line since, but I worry that we'd just go through this all over again "You are the only person who has your private key! It must have been you that sold your house to someone in Nigeria for $1! It is in the blockchain now - it is irreversible there is nothing we can do. Case closed!" ... ignoring all of the possible ways we can imagine in just 30 seconds for how someone could access your computer/phone without your permission.

Hasty conclusion, but I am glad you put a traditional banking system to the same standard.

Beneath all incumbent banking processes and redundancies, money and value is a bearer instrument. If someone takes it, it is their's (with some extra steps for reintegration back into the economy necessary, sometimes). Redundancies have been built on top of it to improve that user experience.

Crypto assets have accomplished the bearer level. The commodity raw resource that people then built value transfer on top of, and then credit-velocity based money, and then banking systems compatible with that. In the crypto-asset sector, additional private businesses and sector wide redundancies will be built to improve that user experience. They have been built and many compete directly with each other, if you find them laughably inadequate then congratulations, you've identified a market need. Obviously the conclusion that it is fundamentally and irreconcilably flawed and 'built on sand' won't necessarily motivate you to fulfill the market need, but others are motivated by it.

And it will. Imagine a world where, let’s say 20% of all online payments are via blockchains.

With enough meet in the bone, bad actors will show up.

How can anyone claim that it will not be vulnerabilities is beyond me.

Just wondering: is it objectively better to rely on a complex technical cryptographic chain rather than a person or entity with representatives someone who you can drag over a counter if necessary?
Yes, hence why we have the law, instead of religious judges making judgments ad hoc and at will
Maybe it's a bit of a marketing sleight-of-hand, but the difference is the nature of what you trust. Authority, tradition, laws, that kind of everyday thing, or math, cryptography, algorithms?

I won't get into the weeds of whether you can actually trust math, just pointing out that this is what crypto proponents seem to mean when they say trustless.

Isn't the first question we should answer more whether math, cryptography and algorithms can actually replace authority, tradition and laws? I personally have my doubts.
In order to answer that we need to know what math, cryptography and algorithms can do and the cryptocurrency movement is doing a great job of exploring that space.
Totally.

Also, since we're in the weeds, you can ask yourself why you believe in math. Did someone tell you that Public Key cryptography works, or did you verify it yourself? I've read through a lot of crypto code, and in the end I can't say I really understand the details. I can point at the readings, but really, do I actually get what a pairing group is? Chances are I'm relying on authority.

They have to trust that the power utilities and ISP's don't shut down their trustless distributed system.
Not trying to prove or disprove an argument. This project seems to be trying to address what you mentioned. I hope you find it interesting :)

https://www.helium.com/

yeah, trustless is a marketing term.

I don't see people here getting riled up about the fact that many founders call their product "intuitive" either.

Neither can there be pre-born intuition for a tech product as anything human-made must be entirely non-natural.