// COMPLETE THREAD

e$: e-cash underwriting

5 expanded posts ยท every known parent and child

NODE ba665d0de$: e-cash underwriting
At  4:53 PM 8/20/94 -0400, L. Todd Masco wrote:

>The problem here, and the one that's of interest to Cypherpunks, is
> how to change this system, using credit cards and all the loss of
> privacy they entail, into one using anonymous digital cash.  HKS
> certainly has a commitment (though in word only at this point, since
> it's vaporware) to support digital cash, but as I've noted before
> it a very difficult bootstrap problem.
>
>There has to be some reason people would use digital cash over credit
> cards and frankly, I don't see it happening in the near future except
> by some large power (like banks) decided to support it.

Forgive me, I'm beginning to think that the power doesn't have to be that
large at all.

I'm beginning to have an attack of "I've got a barn, let's have a show".
It's okay, it'll pass if I sit down...

While I think the technical mechanics are simple (you all seem to, anyway),
I'd like to see what regulatory and legal roadblocks have been identified.
The only way to find out about the *market* for the product is to test it.

By the way, I think the problem of double spending is a risk that can be
managed, like the risk that a bank takes when a check is bounced...  The
culprit is identified, and it becomes a matter between the bouncee (however
removed from the criminal transaction), the law, and the bouncer.  Of
course this might require some pretty vicious personal ID on the part of
users of digital cash, like no nyms allowed, but you still get privacy if
nobody bounces the cash. I'm also sure other administrative methods will
evolve which will allow almost total privacy and no double spending in
practice.

Tim refers to voluminous study and many man-years of effort put into
figuring how to do e-cash underwriting from a regulatory standpoint. I
prefer the word "underwriting" to banking, because there are no accounts of
deposit held at an e-cash exchange (where underwriting happens). There
seems to be a problem with the word "bank" here, like there seems to be a
problem with the word "bond". ;-)

Are there any non-proprietary, public sources of information on these legal
and regulatory research efforts?  Are there archives of the c'punks traffic
on this subject that I can look at?

Thanks,
Bob Hettinga

-----------------
Robert Hettinga  (rah@shipwright.com) "There is no difference between someone
Shipwright Development Corporation     who eats too little and sees Heaven and
44 Farquhar Street                       someone who drinks too much and sees
Boston, MA 02331 USA                       snakes." -- Bertrand Russell
(617) 323-7923
NODE db2e4504e$: e-cash underwriting
By the way, I think the problem of double spending is a risk that can be
   managed, like the risk that a bank takes when a check is bounced.

Exactly.  There is some cost incurred by attempts to double-spend, no
matter what the outcome.  The costs are either direct, e.g. redemption
of duplicated notes, or indirect.  Indirect costs include the
implementation of systems to get rid of double spending and the cost
of dealing with rejected transactions when challenged.  In any case,
double spending creates costs.

   The culprit is identified, and it becomes a matter between the
   bouncee (however removed from the criminal transaction), the law,
   and the bouncer.

Why does everyone think that the law must immediately be invoked when
double spending is detected?

Double spending is an informational property of digital cash systems.
Need we find malicious intent in a formal property?  The obvious
moralism about the law and double spenders is inappropriate.  It
evokes images of revenge and retribution, which are stupid, not to
mention of negative economic value.

What is needed are techniques to prevent the possibility of double
spending from taking down the system.  These might include law, and
hence also identity, but need not.  What is the point of an anonymous
system if identity is needed to make it stable?  The contradiction
here is enormous.  The offline cash protocols suffer from this fatal
design flaw, namely, anonymity for "good people" and identity for "bad
people".  Why invoke identity at all if you can do without it?

Having a database of "spent money" is the primary technique for
prevent direct costs from being a problem.  So what is left are
attempts to redeem multiple times the same note.  They won't actually
get redeemed, but if there's a negligible marginal cost for trying,
well, then, some folks will try.

One solution is clear and direct: charge for each redemption attempt.
In that situation, multiple attempts get rejected, and the issuer is
recompensed for the attempt.  No morality need be invoked.

There remains an issue as to the size of this redemption fee, which
would have to be small.  In order to optimize the transaction costs of
charging this fee, a bank might be willing to accept identity in
escrow for the transaction and to remove the fee for good
transactions.  Identity might be a pseudonym revealed after 10 bad
attempts, say.  This system removes the requirement for identity and
substitutes it for an economic optimization based on identity.

An anonymous depositor, however, can still use the system with zero
risk to identity.

   Are there any non-proprietary, public sources of information on these legal
   and regulatory research efforts?  Are there archives of the c'punks traffic
   on this subject that I can look at?

The research efforts are basically my own, Hal's, and Perry's.  There
is no reference other than back traffic, which others can provide.

Eric
NODE 5c567d8cRe: e$: e-cash underwriting
hughes@ah.com (Eric Hughes) writes:

>Why does everyone think that the law must immediately be invoked when
>double spending is detected?

>Double spending is an informational property of digital cash systems.
>Need we find malicious intent in a formal property?  The obvious
>moralism about the law and double spenders is inappropriate.  It
>evokes images of revenge and retribution, which are stupid, not to
>mention of negative economic value.

It was nice to finally meet Eric and other CP's at the Crypto conference.

To me, double-spending is analogous to passing bad checks.  I don't think
people will be satisfied to simply view it as a formal property, any more
than they are in the case of checks.  In either case you are getting an
explicit or implicit assurance from the payor that the instrument is
good.  Intentionally cheating would be viewed as fraud.  I think this
approach would increase the likelihood of digital cash being accepted.

>What is needed are techniques to prevent the possibility of double
>spending from taking down the system.  These might include law, and
>hence also identity, but need not.  What is the point of an anonymous
>system if identity is needed to make it stable?  The contradiction
>here is enormous.  The offline cash protocols suffer from this fatal
>design flaw, namely, anonymity for "good people" and identity for "bad
>people".  Why invoke identity at all if you can do without it?

That's a big "if".  I don't follow the proposed solution below.

In any case, discussions about the role of identity are purely
speculative.  I think what we want is a system where people are free to
use these technologies as they wish.  If one bank offers certain
advantages to people who are willing to authenticate their identity (as I
think some will), that is fine.  If a person chooses not to take
advantage of those opportunities because he doesn't want to divulge his
identity, that is fine, too.  The real question is the degree to which
adding identity authentication increases the likely range of situations
that can be covered in a privacy-protecting way, and the degree to which
it may lower costs.

>Having a database of "spent money" is the primary technique for
>prevent direct costs from being a problem.  So what is left are
>attempts to redeem multiple times the same note.  They won't actually
>get redeemed, but if there's a negligible marginal cost for trying,
>well, then, some folks will try.

>One solution is clear and direct: charge for each redemption attempt.
>In that situation, multiple attempts get rejected, and the issuer is
>recompensed for the attempt.  No morality need be invoked.

The problem is, the fraud doesn't occur (typically) when the note is
redeemed at the bank, it occurs when the note is exchanged at the
market.  Is this proposing to charge the merchant when he in good faith
turns in the cash which was given to him by the customer, and it turns
out bad?  What cruel irony!  Here he is already cheated once, and the
bank will charge him an extra fee as additional punishment?

I must be misunderstanding.  This seems not to deter double-spenders at
all.

>There remains an issue as to the size of this redemption fee, which
>would have to be small.  In order to optimize the transaction costs of
>charging this fee, a bank might be willing to accept identity in
>escrow for the transaction and to remove the fee for good
>transactions.  Identity might be a pseudonym revealed after 10 bad
>attempts, say.  This system removes the requirement for identity and
>substitutes it for an economic optimization based on identity.

Here I am lost completely.  Whose identity is in escrow?  The person to
whom the coin is given in the first place?  But I thought we were
referring to a double-spending protocol in which users revealed their
identity to the bank.  Apparently not?  Is the idea here that the bank
doesn't know the user's identity, but some other escrow holder does, and
it gets revealed only if the user double-spends 10 times?  But that would
still be identity-based, just with different rules about when it gets
exposed.  I really don't follow this at all.

To me, there is no problem with revealing identity in certain situations
as long as it is unlinkable to my other activities..  And I will be much
more willing to lend credit or other forms of trust to pseudonyms if I
know that they are willing to pay the ultimate price of punishment to
their own very physical bodies if they cheat me.  What more assurance
could I want?  And yet, as long as all parties are honest, we have no
fear of our identities being revealed against our will.

This is no more a contradiction than is the existance of one-way functions.
Both are manifestations of control over information flow.  If this
control is possible, why not make use of it?

Hal
NODE 94245c08e$: e-cash underwriting
To me, double-spending is analogous to passing bad checks.  

Legally, it's one form of conversion.  Conversion includes forgery,
for example.

   In either case you are getting an
   explicit or implicit assurance from the payor that the instrument is
   good.

That's the case with checks right now.  The assurance you mention is,
in law, called an "implied warranty", and there are several kinds of
them.  Implied warranties are creations of law, and need not exist in
a newly designed system.

The system in which the issuer charges for a deposit attempt needs no
implied warranty of validity.  A deposit attempt is made, the fee is
paid which covers equipment and communication costs, and everyone is
happy.

   The problem is, the fraud doesn't occur (typically) when the note is
   redeemed at the bank, it occurs when the note is exchanged at the
   market.  Is this proposing to charge the merchant when he in good faith
   turns in the cash which was given to him by the customer, and it turns
   out bad?  What cruel irony!  Here he is already cheated once, and the
   bank will charge him an extra fee as additional punishment?

Fairness is overrated.

In the commercial paper world, there is the concept of the "holder in
due course", which is a legally protected holder.  In certain
situations there are parties who have to pay off both the holder in
due course as well as having already paid for the note, or in other
words, there are parties who incur a dead loss.

There is a public policy decision implicit in this doctrine that a
protected market in commercial paper is more important than fairness
at each stage in the transaction.

This is a profound principle.  Overall economic benefit was the goal,
not individual economic benefit.

Now, I should add that if the issuer charges a deposit attempt fee,
that a reasonable merchant would pass that fee right along to an
anonymous customer.  If the merchant wishes to extend credit in the
size of the transaction or in the size of the deposit fee, that's
their business.

So the question of intermediates is really not relevant.  An
intermediary, the merchant in this case, can derive some source of
income by being an intermediary, and either passes the deposit fee
along or averages it with other income.  The market will decide.  Any
merchant who must pay deposit attempt fees and who neither passes that
cost on nor makes any attempt to otherwise stochastically recover that
cost is, well, stupid.

From the issuer's perspective, the system is stable because database
queries, that is, deposit attempts, are being directly paid for.  From
a potential multiple spender's perspective, double spending gets them
nothing, and they have to pay for getting nothing.  They might be able
to convince some merchant to try the transaction for them, but it
won't succeed and the only difference is that someone else pays the
bank.

   But I thought we were
   referring to a double-spending protocol in which users revealed their
   identity to the bank.

I'm talking about an online system.

The idea of charging per attempt might also work in an offline system,
if only to get the merchant to pass the fee on to their customers.

Eric
NODE 04edd09bRe: e$: e-cash underwriting
rah@shipwright.com (Robert Hettinga) writes:
>While I think the technical mechanics are simple (you all seem to, anyway),
>I'd like to see what regulatory and legal roadblocks have been identified.

Come on, Bob, we've talked about a lot of problems in the last few weeks: the
prohibitions on most forms of bearer bonds; the prohibitions on banks
issuing their own currency; the stringent regulations for private scrip
circulation.  Our people who know securities law can probably list a few
more.

>The only way to find out about the *market* for the product is to test it.

OK, but also one way to find out whether it is legal or not is to test it.
If you end up in jail, I guess it wasn't legal.  Maybe that's not the
best strategy, though?

Send mail to netbank-info@agents.com for info on their non-anonymous (I
think) cash-like system.  I wonder whether they have worried about these
issues or whether they are trying out the strategy above.

Hal