본문으로 건너뛰기

제14장 – 에이식부스트

한글

책 The Blocksize War의 14장을 아래에 게재합니다. 전체 책은 Amazon에서 구할 수 있습니다. 참고로 종이책 판매로 얻는 수익의 50%는 분쟁, 전염병, 재난 또는 의료 서비스에서의 배제로 영향을 받는 사람들에게 의료 지원을 제공하는 자선 단체인 Médecins Sans Frontières에 기부됩니다.*

* 참고: i. 저자의 사망과 ii. 2031년 1월 중 더 이른 시점까지의 판매에 적용됩니다.

2017년 4월 5일 수요일, 이번에는 작은 블록 지지자들이 또 하나의 폭탄을 터뜨렸습니다. 그레고리 맥스웰이 비트코인 개발자 메일링 리스트에 보낸 이메일 형태였습니다. 매우 기술적인 내용이라 여기서는 세부 사항을 깊이 다루지 않겠습니다. 그레고리의 주장이 핵심적으로 말하는 바는 Bitmain과 Jihan이 세그윗에 반대한다고 밝힌 이유가 사실은 거짓말이라는 것이었습니다. Bitmain은 비밀 의제를 가지고 있었다고 합니다. 그 회사가 비밀 채굴 최적화 방법, 즉 블록에 세그윗 트랜잭션이 포함되면 작동하지 않는 작업 증명 지름길을 발견했다는 것입니다. 따라서 세그윗에 반대하는 이유는 복잡성 때문이라거나 하드포크를 얻기 위한 지렛대를 유지하기 위해서라는 표면적인 이유가 아니라 Bitmain의 수익성을 지키기 위한 금전적 이유였다는 것입니다. Bitmain이 이 정도로 부정직했다는 것이 사실이라면, 비트코인 프로토콜과 관련해서는 Bitmain이 악의적인 행위자였다고 주장할 수 있습니다.

그레고리의 이메일은 아래에 싣습니다.

한 달 전에 저는 ASICBOOST가 악용하는 비트코인의 SHA2 hashcash에 대한 공격과, 그것이 문제가 될 경우 네트워크에서 그것을 차단하는 데 사용할 수 있는 여러 단계를 설명하고 있었습니다.

ASICBOOST에 대한 논의는 대부분 그것을 구현하는 공개적인 방법에 초점을 맞추었지만, 그것을 사용하는 은밀한 방법도 존재합니다.

은밀한 ASICBOOST를 억제하기 위한 접근 방법 중 하나를 설명하면서 저는 제 말이 세그윗 커밋먼트 구조를 설명하는 것과 거의 같다는 것을 깨달았습니다.

세그윗 제안의 저자들은 어떤 채굴 시스템과도 호환되지 않게 되지 않도록 특별히 노력했고, 특히 강제 지급 주소를 가진 채굴 칩을 수용하기 위해 어느 시점에 설계를 변경했습니다.

이 공격이 악용되고 있다는 인식이 있었다면 호환성 문제를 피하려는 노력이 이루어졌을 것입니다. 단순히 관심사를 분리하기 위해서입니다. 그러나 은밀한 공격을 구현하는 가장 좋은 방법들은 비트코인의 트랜잭션 기능을 확장하는 사실상 모든 방법과 상당히 호환되지 않습니다. 주목할 만한 예외는 익스텐션 블록입니다(그 자체의 문제들을 안고 있습니다).

이러한 호환성 문제는 채굴 생태계의 일부 관계자들이 보인 설명하기 어려운 행동 중 일부를 설명하는 데 크게 기여할 것이므로 저는 이를 뒷받침하는 근거를 찾기 시작했습니다.

특정 채굴 칩에 대한 역공학 분석은 ASICBOOST가 하드웨어에 구현되었다는 것을 결정적으로 입증했습니다.

이에 근거하여 논의를 위해 다음과 같은 BIP 초안을 제안합니다. 이 제안은 일반적으로 공격을 막지 않으며, 비트코인 프로토콜의 개선과 호환되지 않는 은밀한 형태의 공격만을 억제합니다.

ASICBOOST가 완전히 차단되기를 강력히 바라는 저희 중에서도, 프로토콜 개선을 잠재적으로 막는 은밀한 사용을 억제함으로써 관심사를 분리하는 보호 조치를 지지하기 위해 함께할 수 있기를 바랍니다.

ASICBoost는 비트코인의 작업 증명(PoW)을 위한 해싱 시도에서 채굴자가 해야 하는 작업량을 줄이는 방법입니다. 비트코인의 PoW에 사용되는 해싱 알고리즘인 SHA256은 계산이 이루어지기 전에 블록 헤더를 64바이트 청크로 나눕니다. 비트코인 블록 헤더의 크기는 80바이트이므로 두 개의 청크, 즉 청크 1과 청크 2로 나뉩니다. ASICBoost는 여러 해싱 시도에 걸쳐 두 청크 중 하나의 값을 동일하게 유지합니다. 따라서 채굴자는 여러 해싱 시도에서 이 청크에 대해 부분적인 작업만을 하면 되어, 아마도 20퍼센트 정도의 상당한 효율 향상을 얻습니다. 이 시스템을 설명한 논문은 2016년 3월에 Timo Hanke가 처음 발표했습니다.

이를 달성하는 방법은 두 가지였습니다. 비트코인 블록 헤더의 청크 1에 있는 버전 비트 영역을 조정하여 엔트로피를 만들고 청크 2를 여러 해싱 시도 동안 고정시키는 공개적인 방법과, 은밀한 방법이었습니다. 은밀한 ASICBoost는 훨씬 더 복잡하며, 트랜잭션들의 Merkle root에서 마지막 4바이트의 충돌을 찾기 위해 비트코인 트랜잭션을 조정하는 과정을 포함합니다. Merkle root는 두 청크에 걸쳐 나뉘며, 마지막 4바이트는 청크 2에 있습니다. 따라서 이 은밀한 방법 역시 여러 해싱 시도 동안 청크 2를 고정시킵니다. 이러한 은밀한 조작은 블록 안의 트랜잭션 순서를 조정함으로써 일어날 수 있습니다. 세그윗 업그레이드는 채굴자가 블록의 다른 위치에서 트랜잭션 구조를 커밋하도록 요구하므로 이러한 유형의 조작을 거의 불가능하게 만듭니다. 따라서 세그윗은 의도하지 않게 은밀한 ASICBoost를 막습니다.

그레고리의 주장, 즉 “특정 채굴 칩에 대한 역공학 분석은 ASICBOOST가 하드웨어에 구현되었다는 것을 결정적으로 입증했다”는 주장에 대해서는 여전히 상당한 불확실성이 있었습니다. 대부분의 작은 블록 지지자들은 이 주장을 믿는 듯했지만, 저에게는 그 주장을 뒷받침할 충분한 근거가 있는지 분명하지 않았습니다. 아마도 작은 블록 지지자들은 세그윗이 좋은 생각이며 Bitmain이 반대할 타당한 이유가 없다고 너무 확신한 나머지, Bitmain의 의도가 따라서 악의적임에 틀림없다고 부적절하게 결론 내렸을 것입니다. 이 주장은 Bitmain의 행동을 설명하면서 그 서사에 매우 잘 들어맞았고, 그래서 대부분의 작은 블록 지지자들은 이를 믿는 듯했습니다. 물론 Jihan의 행동에 대한 다른 설명도 가능해 보이며, 그 역시 상당히 가능해 보이는 설명인데, 그가 극단적인 큰 블록 지지자로서 큰 블록 지지자 측의 서사에 노출되었다는 것입니다. 이 역시 세그윗에 대한 그의 반대를 설명하는 타당한 설명이었습니다.

주장이 제기된 지 이틀 뒤, Bitmain은 길고 두서없는 부인을 내놓았습니다:

Bitmain은 테스트넷에서 ASICBOOST를 시험했지만 Gregory Maxwell의 제안이 암시하는 것처럼 메인넷에서는 ASICBOOST를 사용한 적이 없습니다. 이러한 근거 없는 주장은 비트코인 분야에 해로우므로 이것이 사실이 아니라고 주장하는 분에게는 결정적인 증거를 요구합니다.

Bitmain은 중국에서 ASICBOOST 특허를 보유하고 있습니다. 저희는 중국에 있는 저희의 채굴장에서 그것을 사용해 수익을 얻고 클라우드 채굴 계약을 대중에게 판매하는 것을 법적으로 할 수 있습니다.

비트코인 채굴 장비는 빠르게 감가상각됩니다. Bitmain은 모두를 위해 더 새롭고 더 효율적인 채굴기 모델을 계속 내놓아 왔습니다. 따라서 20%의 전력 효율 차이를 가져올 수 있는 ASICBOOST의 도입이 Bitmain의 사업 모델에 부정적인 일이라는 주장은 거짓입니다.

홍콩 합의에서 분명히 밝힌 조건들이 충족되지 않았기 때문에 세그윗은 실제 운영 환경에서 실행되고 있지 않습니다

Gregory Maxwell의 최근 제안은 ASICBOOST를 더 어렵게 만들기 위해 2^32 충돌을 2^64 충돌로 바꾸자고 제안합니다. 그 결과는 특허권자와 비트코인 프로토콜 모두에게 손실이 될 것입니다. 특허권자는 아무것도 얻지 못하고 비트코인 프로토콜은 더 복잡해질 것입니다.

Maxwell이 Gavin Andresen에 대한 쿠데타를 이끌고(sic) 그의 Github 커밋 권한을 제거했을 때 비트코인 커뮤니티는 심각한 불행을 겪었습니다. 이제 커뮤니티로서 비트코인의 대형 투자자(Ver), 대형 거래소 중 하나(Coinbase), 그리고 최대 채굴 장비 공급업체(Bitmain)를 공격하는 데 몰두하지 않는 새로운 핵심 개발자 그룹을 어떻게 찾을지 고민하는 것은 저희에게 달려 있습니다.

가장 먼저 주목할 점은, 부인에도 불구하고 Bitmain이 테스트넷에서 추정컨대 은밀한 ASICBoost를 사용했음을 인정한 듯하고 따라서 그것이 자사 하드웨어에 구현되어 있었을 가능성이 크다는 것입니다. 이 부인이 나오기 전에는 저는 주장의 정확성을 확신하지 못했습니다. 역설적으로 제 생각에는 부인의 성격 때문에 그 주장이 사실일 가능성이 크게 높아졌습니다. Bitmain은 이어서 중국에서 ASICBOOST 특허를 보유하고 있으며 원한다면 법적으로 사용할 수 있다고 주장한 뒤, Bitmain이 그것을 사용하고 있다는 가정적 상황에서 ASICBoost를 정당한 채굴 최적화 방법으로 옹호했습니다. Bitmain이 그것을 사용하고 있다는 가정적 상황에서 ASICBoost를 옹호하기보다는 단순하고 분명한 부인이 훨씬 더 효과적인 소통 방침이었을 것입니다. 따라서 그 부인은 Bitmain의 입장을 약화시켰고 작은 블록 지지자들은 이를 악의적인 행동의 증거로 인용했습니다. Bitmain이 현재 은밀한 ASICBoost를 사용하고 있지 않더라도 사용할 의도가 있었을 수 있으며, 따라서 그레고리의 비난의 취지는 어느 정도 정확해 보였습니다. Bitmain은 세그윗에 대한 반대에서 부정직했다는 것입니다. 모든 것이 돈에 관한 일이었을 수 있습니다.

그러나 더 단순한 설명도 가능합니다. 아마도 Bitmain은 영어 소통에 서툴렀을 뿐이며, 그래서 부인이 그토록 미약했던 것일 수 있습니다. 이 전쟁에는 모든 쟁점을 다투는 호전적인 논쟁 문화도 있습니다. 아마도 Bitmain의 요점은 은밀한 ASICBoost를 하고 있지 않지만, 설령 하고 있더라도 그것이 무슨 문제냐는 것이었을 수 있습니다. 회사가 ASICBoost를 하고 있지 않더라도 Bitmain이 이러한 요점을 말하고 싶었을 가능성은 없지 않습니다. 그 부인은 또한 홍콩 합의의 조건이 충족되지 않았으므로 세그윗을 실행하지 않겠다는 블록 크기 전쟁에서의 Bitmain의 입장을 다시 밝혔습니다. 물론 작은 블록 지지자들에게 그것은 주고받기 조건으로 의도된 적이 없었습니다.

놀랍게도 Gavin은 회사가 은밀한 ASICBoost를 하고 있다는 가정에 근거하여 Bitmain을 옹호하기까지 했으며, 그것이 비트코인 소프트웨어를 이용한 정당한 채굴 최적화라고 주장했습니다.

도난을 되돌리기 위해 Ethereum이 규칙을 바꾸는 것은 괜찮지 않지만, 최적화를 막기 위해 비트코인이 규칙을 바꾸는 것은 괜찮습니까?

그러나 Gavin은 요점을 놓치고 있는 듯했습니다. 쟁점은 은밀한 ASICBoost가 부당한 것이냐가 아니라, Bitmain의 세그윗 반대가 부정직에 근거했다는 것과 블록 크기 전쟁에서 주요 당사자 중 하나가 부정직한 의도에 따라 움직였다는 것이었습니다. Bitmain이 솔직하게 털어놓고 이러한 이유로 세그윗에 공개적으로 반대했더라면 이야기는 달랐을 것입니다.

ASICBoost 논란과 비슷한 시기에 여러 큰 블록 지지자들은 세그윗의 대안 아이디어로 익스텐션 블록을 제안하고 있었습니다. 소프트포크로 블록 크기 제한을 높이는 방법이었습니다. 이 제안은 큰 블록 진영과 관련된 회사인 Purse.io의 블로그에서 Andrew Lee가 했습니다. 이 계획은 Roger Ver의 지지도 받았고 Bitmain도 이를 지지하는 듯했습니다. 익스텐션 블록은 원래 2013년에 세그윗 공동 저자인 Johnson Lau가 제안했지만, 익스텐션 블록에서 메인 체인으로 코인을 보내는 경험이 매끄럽지 않아 대체로 폐기되었습니다. 반면 세그윗에서는 이 과정이 간단했습니다.

여기서 놀라운 점은 큰 블록 지지자들이 세그윗의 단점이라고 주장되던 많은 점을 가진 제안에 동의한 듯했다는 것입니다. 매우 복잡하고 단순한 블록 크기 제한 인상이 아니라는 점에서 그러했습니다. 그러나 그들에게 중요해 보였던 것은 이 아이디어가 Bitcoin Core에 의해 개발된 것이 아니라는 점이었습니다. 이 시점에서 그들 자신의 아이디어를 개발하고 Bitcoin Core로부터 자유롭다고 느끼는 것이 큰 블록 지지자들에게 가장 중요한 문제로 보였으며, 블록 크기 제한 인상 자체가 아니었습니다.

익스텐션 블록은 소프트포크로 블록 크기 제한을 인상하면서 은밀한 ASICBoost를 할 수 있는 능력을 유지하는 방법이었습니다. 따라서 작은 블록 지지자들에게 이 제안은 Bitmain의 유죄에 대한 추가 증거였습니다. 작은 블록 지지자들은 또한 Bitmain이 최근의 익스텐션 블록 추진에 자금을 댔다고 비난했으며, 이 역시 ASICBoost에 대한 Bitmain의 유죄 증거였습니다. 큰 블록 지지자들이 Bitcoin Core가 구현한 것은 무엇이든 받아들이려 하지 않았던 것처럼, 작은 블록 지지자들도 비슷한 편향을 가진 듯했으며, 이 익스텐션 블록 제안이 Bitmain에 의해 홍보되고 자금 지원을 받았다는 사실 때문에 그들은 이를 반대했습니다.

ASICBoost 특허는 비트코인에 대한 중대한 위협으로 여겨졌습니다. 하나의 채굴 주체가 특허를 취득해 그 기술에 대한 독점적 사용권을 주장한 뒤, 그 기술이 줄 수 있는 이점 덕분에 채굴 산업을 장악할 가능성이 있었습니다. 이러한 우려를 덜기 위해 여러 비트코인 관계자들이 꽤 높은 가격에 그 특허를 매입한 뒤 2018년 3월에 그 특허를 방어적 특허 풀에 넣어서, 다른 특허에 대항해 방어하는 경우를 제외하고는 그 특허를 결코 사용할 수 없게 했다고 합니다. 2018년 4월 무렵부터 비트코인 전체장부상의 블록들은 공개적인 ASICBoost의 사용을 표시하기 시작했습니다. 공개적인 ASICBoost는 은밀한 방식보다 훨씬 더 단순하고 효율적이며, 세그윗과 호환되지 않는 문제도 피합니다. 2018년 11월에 Bitmain은 자사 펌웨어에 공개적인 ASICBoost를 도입했으며, 현재 기준으로 70퍼센트가 넘는 비트코인 블록이 공개적인 ASICBoost를 이용해 채굴됩니다. 특허와 관련해서는 누가 정확히 그 특허를 매입했는지 명확하지 않았고, 발명자로부터 방어적 특허 서약에 그 특허를 넣었다는 당사자로의 소유권도 쉽게 추적할 수 없었습니다. 따라서 여기서 실제로 일어난 일은 다소 불분명했습니다.

오늘날에도 저는 Bitmain이 메인넷에서 은밀한 ASICBoost를 사용했는지 확신하지 못합니다. 이 문제에 대한 전문가들의 의견은 엇갈립니다. 확률은 50:50 정도라고 생각합니다.

ASICBoost 비난은 큰 블록 지지자 커뮤니티에 거의 영향을 주지 않은 듯했습니다. 일반적으로 그들은 비난을 이해하지 못했고 더 많은 Bitcoin Core의 선전과 거짓말로 치부했습니다. 그 비난은 주장의 복잡성 때문에 더 많은 사람을 작은 블록 진영으로 끌어들이는 데도 거의 영향을 주지 않았습니다. 그러나 그것은 많은 작은 블록 지지자들의 견해를 굳히는 데에는 분명히 매우 중요한 영향을 주었으며, 그들은 이제 상황을 훨씬 더 긴급하다고 여겼습니다. 여기서 ASICBoost 논란은 분쟁에서 중요하고 기념비적인 역할을 했습니다. 작은 블록 지지자들은 이제 행동에 나서기로 결심한 듯했습니다.

영문 — Chapter 14 – ASICBoost

Chapter 14 of the book The Blocksize War is published below. The full book is available on Amazon. As a reminder, 50% of any profits from physical book sales will be donated to Médecins Sans Frontières, a charity that provides medical assistance to people affected by conflict, epidemics, disasters, or exclusion from healthcare.*

* Note: Applies to sales up until the earlier of i. the death of the author and ii. January 2031

On Wednesday April 5, 2017, another bombshell was set off, this time by the small blockers. It was in the form of an email to the Bitcoin developer mailing list from Gregory Maxwell. We won’t go too much into the details here, as it’s highly technical. The main thrust behind Gregory’s allegation was that Bitmain and Jihan’s stated reasons for opposing SegWit were, in fact, lies. Bitmain supposedly had a secret agenda: the company had discovered a secret mining optimisation, a proof-of-work shortcut, that would not work if blocks contained SegWit transactions. The reason for the opposition to SegWit was therefore financial, to protect Bitmain’s profitability, rather than the stated reasons of complexity or to retain leverage to get a hardfork. If it was true that Bitmain had been dishonest to this extent, it could be argued that Bitmain were malicious actors when it came to the Bitcoin protocol.

Gregory’s email is provided below.

A month ago I was explaining the attack on Bitcoin’s SHA2 hashcash which is exploited by ASICBOOST and the various steps which could be used to block it in the network if it became a problem.

While most discussion of ASICBOOST has focused on the overt method of implementing it, there also exists a covert method for using it.

As I explained one of the approaches to inhibit covert ASICBOOST I realized that my words were pretty much also describing the SegWit commitment structure.

The authors of the SegWit proposal made a specific effort to not be incompatible with any mining system and, in particular, changed the design at one point to accommodate mining chips with forced payout addresses.

Had there been awareness of exploitation of this attack an effort would have been made to avoid incompatibility — simply to separate concerns. But the best methods of implementing the covert attack are significantly incompatible with virtually any method of extending Bitcoin’s transaction capabilities; with the notable exception of extension blocks (which have their own problems).

An incompatibility would go a long way to explain some of the more inexplicable behavior from some parties in the mining ecosystem so I began looking for supporting evidence.

Reverse engineering of a particular mining chip has demonstrated conclusively that ASICBOOST has been implemented in hardware.

On that basis, I offer the following BIP draft for discussion. This proposal does not prevent the attack in general, but only inhibits covert forms of it which are incompatible with improvements to the Bitcoin protocol.

I hope that even those of us who would strongly prefer that ASICBOOST be blocked completely can come together to support a protective measure that separates concerns by inhibiting the covert use of it that potentially blocks protocol improvements.

ASICBoost is a way to reduce the amount of work a miner is required to do when making a hashing attempt for Bitcoin’s proof of work (PoW). SHA256, which is the hashing algorithm used for Bitcoin’s PoW, splits the block header into 64-byte chunks before the computations occur. The Bitcoin block header is 80 bytes in size and therefore it is split between two chunks — chunk 1 and chunk 2. ASICBoost keeps the value of one of the chunks the same over multiple hashing attempts. Therefore, the miner is required to do only partial work for this chunk, for multiple hashing attempts, resulting in significant efficiency gains of perhaps around 20 percent. A paper describing this system was first published in March 2016 by Timo Hanke.

There were two ways of achieving this: overtly, by tinkering with the version bits area in the Bitcoin block header in chunk 1 to create entropy as chunk 2 remained static for multiple hashing attempts; or covertly. Covert ASICBoost is far more complex, and involves tinkering with Bitcoin transactions, to find a collision in the last four bytes in the Merkle root of the transactions. The Merkle root is split across both chunks, with the last four bytes in chunk 2. Therefore this covert method also keeps chunk 2 static for multiple hashing attempts. This covert manipulation can occur by tinkering with the order of the transactions in the block. The SegWit upgrade requires miners to commit to the transaction structure elsewhere in the block, making this type of manipulation almost impossible. SegWit therefore inadvertently prevents covert ASICBoost.

There was still considerable uncertainty with respect to Gregory’s claim that “reverse engineering of a particular mining chip has demonstrated conclusively that ASICBoost has been implemented in hardware”. While most small blockers appeared to believe the allegation, it was not clear to me that there was enough evidence to support the allegation. Perhaps small blockers were so convinced that SegWit was a good idea, and that there was no good reasons for Bitmain to oppose it, that they had inappropriately concluded that Bitmain’s intentions must therefore be nefarious. This allegation fit very well into that narrative, explaining Bitmain’s behaviour, and for that reason most small blockers seemed to believe it. Of course, an alternative explanation for Jihan’s behaviour, which also seems quite possible, was that he was an extreme large blocker, exposed to the narrative of the large blocker side. This was also a valid explanation for his opposition to SegWit.

Two days after the allegation was made, Bitmain put out a long and rambling denial:

Bitmain has tested ASICBOOST on the Testnet but has never used ASICBOOST on the mainnet as implied in Gregory Maxwell’s proposal. We ask conclusive proof from whoever claims this to be false because such baseless claims are toxic for the Bitcoin space.

Bitmain holds the ASICBOOST patent in China. We can legally use it in our own mining farms in China to profit from it and sell the cloud mining contracts to the public.

Bitcoin mining equipment depreciates rapidly. Bitmain has constantly been introducing newer more efficient miner models for all. As such the statement that the deployment of ASICBOOST, which can lead to a 20% difference in power efficiency, is some kind of negative development for Bitmain’s business model is false.

SegWit is not running in production because the conditions made clear in the Hong Kong agreement have not been met

Gregory Maxwell’s recent proposal suggests changing 2^32 collision to 2^64 collision to make ASICBOOST more difficult. The result of this would be a loss for the patent owners and the Bitcoin protocol. The patent owners will get nothing and Bitcoin protocol will become more complicated.

The Bitcoin community suffered a grave misfortune when Maxwell lead (sic) the coup against Gavin Andresen and removed his Github commit access. It is now incumbent upon us as a community to figure out how to find a new core developer group that does not busy itself with attacking one of Bitcoin’s largest investors (Ver), one of its largest exchanges (Coinbase), and its largest mining equipment provider (Bitmain).

The first thing to note is that, despite the denial, Bitmain did appear to admit to using what was presumably covert ASICBoost on the testnet and therefore it was probably implemented in their hardware. Prior to this denial, I was unsure of the accuracy of the allegations. Ironically, in my mind, the nature of the denial greatly increased the probability that the allegation was true. Bitmain even went on to claim that they owned the ASICBoost patent in China and could legally use it if they wanted to, before going on to defend the technology as a legitimate mining optimisation. A far more effective communication policy would have been a simple, clear denial, rather than defending ASICBoost in the hypothetical scenario that Bitmain was using it. The denial therefore weakened Bitmain’s position and was cited by small blockers as evidence of the nefarious behavior. Even if Bitmain was not currently using covert ASICBoost, they potentially intended to and therefore the spirit of Gregory’s accusation appeared somewhat accurate: Bitmain were dishonest in their opposition to SegWit. It may have been all about the money.

However, a simpler explanation is also possible. Perhaps Bitmain were just bad at communicating in English, and this could be why the denial was so weak. There is also a combative culture of arguing every point in this war. Maybe Bitmain’s point was that they were not doing covert ASICBoost, but even if they were, so what? It is not impossible that Bitmain wanted to make this point, even if the company wasn’t conducting ASICBoost. The denial also went on to restate Bitmain’s position in the blocksize war, that they would not run SegWit as the conditions of the Hong Kong agreement had not been met. Of course, to the small blockers, it was never intended to be a quid pro quo.

Remarkably, Gavin even went on to defend Bitmain, based on the assumption that the company was conducting covert ASICBoost, arguing that it was a legitimate mining optimisation using the Bitcoin software.

It’s not ok for Ethereum to change their rules to undo a theft, but it is ok for Bitcoin to change the rules to prevent an optimization?

However, Gavin seemed to be missing the point. The issue was not that covert ASICBoost was illegitimate, but that Bitmain’s opposition to SegWit was based on dishonesty and that, in the blocksize war, one of the main parties was motivated by dishonest intentions. Had Bitmain come clean and openly opposed SegWit for this reason, it would have been a different story.

Around the same time as the ASICBoost scandal, several large blockers had been proposing extension blocks as an alternative idea to SegWit; a way to increase the blocksize limit via a softfork. This proposal was made by Andrew Lee on the Purse.io blog, a company associated with the large block camp. This plan was even supported by Roger Ver, and Bitmain also appeared to support the idea. Extension blocks were originally proposed by SegWit co-author Johnson Lau in 2013, however the idea was largely abandoned as the experience of sending coins from the extension block to the main chain was not seamless. In contrast, with SegWit, where this process was straightforward.

What was remarkable here was that the large blockers appeared to agree on a proposal that had many of the supposed shortcomings of SegWit, in that it was highly complex and not a simple blocksize limit increase. However, what appeared to be important to them was that this idea was not developed by Bitcoin Core. At this point, developing their own ideas and feeling free from Bitcoin Core appeared to be the most significant issue to the larger blockers, not a blocksize limit increase itself.

Extension blocks were a way to get a softfork blocksize limit increase and retain the ability to conduct covert ASICBoost. To the small blockers, this proposal was therefore further evidence of Bitmain’s guilt. Small blockers also accused Bitmain of financing this recent extension blocks push, again evidence of Bitmain’s guilt over ASICBoost. Just like the larger blockers didn’t want to adopt anything implemented by Bitcoin Core, the smaller blockers appeared to have a similar bias, and the fact that this extension block proposal was promoted and financed by Bitmain, ensured that they opposed it.

The ASICBoost patent was considered a significant threat to Bitcoin. It is possible one mining entity could acquire the patent, claim exclusive rights to use the technology and then dominate the mining industry due to the advantage the technology could provide. To help alleviate this concern, several Bitcoiners are said to have purchased the patent for quite a high price and then, in March 2018, placed the patent into a defensive patent pool, such that the patent could never be used except to defend against other patents. From around April 2018, blocks on the Bitcoin blockchain started indicating the use of overt ASICboost. Overt ASICBoost is far simpler and more efficient than the covert format and also avoids the issue of being incompatible with SegWit. In November 2018, Bitmain adopted overt ASICBoost in its firmware and, as of today, more than 70 percent of Bitcoin blocks are mined using overt ASICBoost. As for the patent, it was never clear exactly who purchased the patent, nor could one easily trace the ownership from the inventor to whomever supposedly put the patent into the defensive patent pledge. Therefore, what actually occurred here was a bit murky.

Even today, I am genuinely unsure of whether Bitmain was using covert ASICBoost on the mainnet or not. Opinion on this issue is mixed among the experts. I think the odds are somewhere around 50:50.

The ASICBoost accusation appeared to have a very little impact in the larger blocker community. In general, they did not understand the accusation and dismissed it as more Bitcoin Core propaganda and lies. The accusation also had very little impact on persuading more people to join the small block camp, largely due to the complexity of the allegation. However, it certainly did have a very significant impact in hardening the views of many of the small blockers, who now considered the situation as far more urgent. Here, the ASICBoost controversy played a significant and monumental role in the conflict. The small blockers now seemed determined to take action.

링크 복사하기X에 공유페이스북에 공유쓰레드에 공유