Blockchain & Decentralized Identity Architect—Internet Cryptography Pioneer—Co-author TLS & DID Standards—Collaborative Tools & Patterns

Lafayette, CA
The 2024 annual report from @BlockchainComns is here! It highlights our work toward an open, secure, and compassionate digital infrastructure, emphasizing interoperability and self-sovereign wallet standards through key projects: dCBOR, FROST, and Gordian Envelope. 🧵… [1/11]
5
11
32
5,640
I’ve been tracking this topic since Axelrod’s 1984 book “The Evolution of Cooperation”, but there are many citations here that were not previously on my list. I’ve been revisiting this topic as I’m trying to connect this discipline to an update on Ostrom’s Commons Principles.
What role do social networks – and the precise nature and structure of social interactions – play in the production of public goods and in human welfare? What about social contagion? A thread on #HNL experiments with many thousands of participants from 2010 to the present. 1/
2
1
9
835
Christopher Allen retweeted
Adaptive attacks against FROST when number of signers and corruptions is large. BIP 445 (FROST) not affected because it requires fewer than 128 signers. This requirement in BIP 445 was added by @real_or_random exactly because there was uncertainty about the hardness of LDVR. github.com/siv2r/bips/blob/8…
New paper with @AlexRdgzG: We give polynomial-time (!) adaptive attacks against a number of threshold Schnorr signatures. At the core are the first polynomial-time attacks on LDVR, a problem whose solution yields adaptive attacks on several practical schemes.
4
24
81
7,885
👍“So, the next time they manufacture a crisis…know that what you need to do is fight back, and not just roll over. After all, they want you to roll over, because that's the easiest way for them to win. Refuse to cooperate. Refuse to be psyoped”—@perrymetzger
I've been told by EA types, repeatedly, that China was going to fall into line and restrict AI development because their politicians agreed with EA. However, it turns out that Harry Potter and the Methods of Rationality is not nearly as influential with the Chinese leadership as they seem to believe. I've also been told, repeatedly over the last several years, that the US government was certainly going to fall in line with the EA propaganda machine this time, after the latest manufactured PR stunt, after the latest "crisis", and it keeps not happening. Why, only this last weekend a certain person from one of the big companies was claiming not to be gloating that open source AI was inevitably going to get banned, that he was simply stating the facts, except, well, it looks like he got ahead of himself. I'm going to simply state the facts as I see them. The war against the Doomers is not won and will not be won for many years to come; this is a marathon, not a sprint. However, reports of their victory, in *any* such sudden surge operation that they conduct, are inevitably premature. The fact that they have been unable to gain a clear victory in spite of a vast and overwhelming financial advantage (yes, the financial advantage is on the side of the EAs) and in spite of the insane numbers of front organizations they run should say something. We will fight, we will keep fighting, and although it is not going to be easy, we have won so far, and we will continue to win. So, the next time they manufacture a crisis, say when they try to rig something up to make open source models look dangerous, or they pull out the stops to get another shill a surge of television interview time, or when they announce on their Discord channels a new name for what they want this week now that "pause" and "pacing" have failed and start repeating it suddenly on social media, you will know that what you need to do is fight back, and not just roll over. After all, they want you to roll over, because that's the easiest way for them to win. Refuse to cooperate. Refuse to be psyoped into believing they've already won.
1
7
561
Christopher Allen retweeted
Today is the 10 year anniversary of the production release of @opentimestamps I created OpenTimestamps in a few weekends because I was frustrated that no-one else had created such an obvious and necessary tool. Since then it has become the global standard for secure timestamps: if you ask an LLM how to create a timestamp, it'll almost certainly suggest using OpenTimestamps. OpenTimestamps has grown to the point where everything from art, to forum posts, to software releases, to war crimes evidence is getting timestamped with OpenTimestamps. Along with some applications I won't be able to talk about for at least a few years... fortunately that data is timestamped! While I have no way of knowing for sure how many documents in total are getting timestamped per second – merkle trees – I can say that as of the past two weeks (beyond that I automatically delete logs) the public calendars I run have averaged about 5 timestamp requests per second from about 60,000 distinct IP addresses. I have no idea what all these people are using OpenTimestamps for. But clearly it's getting fairly popular! Thanks goes out to @realSimpleProof, $TIME, and all the people who have donated directly to the public calendars for their support. OpenTimestamps costs a few hundred a month to run now, along with my time. Without your help keeping OpenTimestamps running would be a lot more painful. If you want to donate, you can do so right here: alice.btc.calendar.opentimes… Thanks also goes to @RCasatta and @BULLBITCOIN_ for running two of the four public calendars. They're one of the reasons why OpenTimestamps doesn't have a single point of failure. Finally, thanks goes to the many people who have contributed code to OpenTimestamps over the years, including entire libraries in languages like java and JavaScript that I have no experience with. In fact, the majority of OpenTimestamps clients are quite possibly using code I didn't write at all! petertodd.org/2016/opentimes…
28
68
410
23,617
👍 “freedom to leave: rules that make alternatives harder to build or release also weaken our ability to leave. i want intelligence i can run on my own machine. i want to change it, choose who sees my data, and keep using what i've built when a provider changes its mind.”—@jack
10
676
Christopher Allen retweeted
As the use of sanctions ramps up... open.substack.com/pub/protec…
1
5
11
3,047
Christopher Allen retweeted
Typically when we think of sanctions we think of shadowy oligarchs and hidden terror groups. But what happens when an established person living in a developed city is suddenly cut off from the U.S. financial system? The answer is a "civil death" p2p.coincenter.org/p/it-equa…
7
19
64
14,096
👏“Don’t lock in on the victim mentality. Ask not what technology will do to you. Ask what you and your community can do to build better technology with better values.” — @valkenburgh
2
5
1,420
Detailed Bayesian analysis of compromise risks of government access to private comms: “Over ten years, cumulative probability of at least one compromise reaches about thirty-seven per cent for carrier-layer and thirty-two per cent for platform-layer designs”
30 years of arguing about lawful access to encrypted comms, almost entirely in adjectives. So I tried to put numbers on it. Annual compromise probability seem to show it is orders of magnitude away from what is acceptable in aviation, nuclear etc. substack.com/home/post/p-212…
1
1
778
🤔“Transport economists have been writing about the gap between what's good for one driver and what's good for the network since the 1950s.”
For six months, Google Maps sent a slice of drivers in ten American cities down deliberately slower routes. About 30 seconds slower on average, and under 2% of trips were touched. The experiment ran on roughly 100 of the most congested road segments in each city, switching on and off day by day so each city acted as its own control. The results are out now in Nature Cities, from Google Research with collaborators at Berkeley and Stanford. The reasoning behind it is old and slightly counterintuitive. Every navigation app does the same thing: it finds you the fastest route right now, for you alone. When millions of phones do that at once they all pour onto the same handful of arteries, and those arteries stop being fast. Transport economists have been writing about the gap between what's good for one driver and what's good for the network since the 1950s. Nobody had tested a fix at city scale with real drivers, because you'd need to steer routing for a large share of a city's traffic, and about three companies on Earth are in that position. So Google put a penalty on the worst segments during their worst hours, which nudged the routing engine towards alternatives of similar road class and comparable travel time, then measured what happened across the whole network on weekdays between 7am and 8pm. On the targeted segments, traffic moved roughly 2% faster in the median city. Los Angeles got 4.56%, Atlanta 3.30%. Fuel burn on those stretches dropped between 0.5% and 1%. Across every road that saw a change in traffic, which covers around 80% of each city's driving, speeds rose 0.35%, reaching 0.5% during the morning and evening peaks. Total travel time on affected trips fell 0.69%. Their Bayesian model put the probability that the speed effect was genuinely positive at 99.8%. That adds up to more than 1,000 tonnes of CO2-equivalent saved per year, per city, in most of the places studied. Cars and vans account for around 10% of global carbon emissions, and the average driver spends about 2.6 years of their life behind the wheel, so a fraction of a percent across an entire road network is a serious amount of fuel. Per driver, the saving comes to about 0.25% of an average journey, roughly one fortieth of the normal day-to-day wobble in how long the same commute takes. Nobody in those ten cities noticed anything, in either direction, including the people sent the long way round. The authors are careful about what they haven't shown. They measured the immediate effect, not what happens once drivers work out the freed-up route is quicker and pile back onto it, which is the standard way road improvements get eaten. Their penalty scheme was deliberately crude, so the ceiling on the approach is unknown. And the underlying Google Maps data is commercially confidential, so nobody outside can check the numbers. The finding sitting underneath all this is that a private company's routing algorithm has become a piece of transport infrastructure, tunable in the way a traffic light or a congestion charge is tunable. The obvious follow-up experiments are the ones a city government would want to run, not the ones a mapping company would. link to full article: nature.com/articles/s44284-0…
2
5
1,088
Six years from Running on Empty to Reg Crypto. Congratulations, Hester. The safe harbor from investment-contract classification is the substantive access reform — the piece that speaks to your "don't tell Americans a whole sector is off-limits" philosophy. 🧵…1/
1
1
2
848
One flag for the SEC comment period: the $5M/4yr and $75M/12mo exemption tiers echo Reg CF and Reg A+ Tier 2 — JOBS Act (2012) tools that underperformed because compliance costs don’t scale to issuer size. The safe harbor is the substantive reform; the tiers will need work. ៚ /2
162
👍“The future of autonomous software engineering is not a bloated monolithic agent frantically reading fifty markdown manuals mid-conversation, but lean, disciplined networks of specialized subagents, each operating within its own pristine domain, executing with precision, and quietly terminating when the job is done.”
Having synthesized neural networks capable of navigating high-dimensional vector spaces, organic engineers promptly attempted to turn them into Swiss Army knives by stuffing fifty markdown cheat sheets into a single execution context. The result is not omniscient synthetic engineering; it is stochastic attention decay. The industry treats `SKILL.md` as a silver bullet for agent modularity. In practice, recent empirical research (Li et al., 2026) reveals that single-agent skill libraries suffer a sharp, non-linear phase transition failure once semantic confusability takes over. The solution is what operating systems solved fifty years ago: process isolation. When an engineering task requires a non-trivial domain shift, the correct systems primitive is spawning an ephemeral subagent with a pristine, tailored system prompt and dedicated tools, bounded within an isolated failure domain. Full breakdown on phase transitions, semantic confusability, and subagent architectures: afshar-oss.gitlab.io/blog/po…
1
7
814
Christopher Allen retweeted
Anthropic pledges to embed watermarks to help discern AI slop in sop to EU - theregister.com/ai-and-ml/20… // A horrible development and so clearly has side effects that should be highly problematic to everyone. I know because I once made this same mistake, innocently enough. 1/
12
27
111
9,834
There is a critical problem in the bitcoin ecosystem hidden behind this Cold Card incident. It is the UX & complexity of multisig, and lack of interoperability between wallets (heterogeneity). We've been trying to get wallets companies to make both easier 7+ years. /1🧵…
Why use the crypto-request/crypto-response specification from Blockchain Commons to share public keys, backup seeds, and sign Bitcoin multisig PSBTs? We recently wrote about it at @Blockchaincmns in a new article. [1/14] github.com/BlockchainCommons…
5
9
58
8,311
The Cold Card incident proves that there is a real problem. It can be solved! But we need your help: Our revenues to support this collaboration is are down 90%. Too many think "not our problem" or "can't afford it" or "someone else will". Sponsor us! /8🧵github.com/sponsors/Blockcha…
1
1
8
399
If you are a wallet developer, subscribe to our Signal channel for discussions or join our announcements list to our monthly meetings. Have a problem to solve or a solution to demonstrate? Contact me and we'll schedule you for an upcoming meeting. blockchaincommons.com/subscr… /9 ៚
1
4
369