HN user

legutierr

3,059 karma
Posts9
Comments761
View on HN

The article talks about being “receipt free” as a required feature of any electronic voting system.

Fine. But by that standard, in a world where someone can bring their phone or AI glasses into the voting booth to record the whole voting process, how can any voting system be deemed secure? Anyone can show anyone else how they voted.

Event better is his response to the comment.

I was looking for a job during working on this and absolutely got some disappointing rejections, and one was because of my lack of skillset on things like this in a big tech company's interview. I literally failed the technical screening. Oh well.

I don’t think you have deferred resolving the dilemma—you have firmly decided the question in favor of your product and the LLMs you are using!

Not sure how one can design a system robust to these two threats.

The US at various time has had a system robust to these threats. A prerequisite has been an educated and well-informed electorate with at least a large majority committed to a shared set of national values.

If we move all crypto to purpose-made hardware, someone could just start trying to target the messages to/from the crypto system.

This is one of the technical advantages of a blockchain-based system. As long as the keys are protected and signatures are generated in a secure environment, then the content of the message doesn't need to be secret to be secure.

It's not a solution to situations where privacy is desired, but if the reason for secrecy is simply to ensure that transactions are properly authorized (by avoiding the leakage of passwords and session information) then keeping the signature process secure should be sufficient even where general secrecy cannot be maintained.

Where possible try utilizing HSMs, yubikeys, secure enclaves - any specialized hardware that has been hardened to protect key material.

Are there any circumstances where this hardware is accessible in the browser? As I understand, it is not generally available (if at all) for any cryptography you might want to do in the browser.

In general, this usually results in front-end logic being very tightly coupled with back-end logic. In some of the examples given, you even have database access in the same line that is generating the HTML document.

https://github.com/paveldedik/ludic/blob/main/examples/click...

It's the kind of thing that looks very cool and concise in small examples, but tends to become a nightmare when you are working on larger projects.

In 1980 packet switching had existed for 20 years already. The public Internet wouldn’t emerge for more than a decade after that—and it would take yet another 20 years for the true power of packet-switched networks to be realized, in the form of mobile Internet.

In 2000 neural networks had existed for more than 50 years. More than 20 years later their full potential is finally being realized, and many would say it is still early days.

It’s naive to think that you can predict the future course of a technology simply based on the fact that it has already existed for a certain amount of time.

Did you read the document you linked to?

"...the Court concludes that Ripple’s Programmatic Sales of XRP did not constitute the offer and sale of investment contracts"

It is not only third party sales that were deemed not to be investment contracts—it was all programmatic sales. As I said, the federal court found that exchange-traded Ripple XRP tokens are not securities.

Also, you should know that the SEC has dropped the remaining charges that were to be tried in April. The next step in the litigation is an appeal of the summary judgement.

The SEC's public mission also includes maintaining fair, orderly, and efficient markets, and facilitating capital formation. Both would be well served by an explanation as to how the SEC distinguishes between security tokens and non-security tokens.

When do facts stop being novel? There are hundreds of millions of crypto users worldwide, and more than a trillion dollars in value at stake. Cryptocurrencies have been around for more than a decade, and only in the past few years has the SEC begun to assert broad authority across the whole category.

Whether or not the crypto industry is victimized or not has nothing to do with my point, which is simply that the SEC has avoided clarifying the difference between security tokens and non-security tokens, while at the same time undertaking aggressive enforcement actions that depend entirely on where that line is drawn. I imagine that you and I agree on this?

That’s actually not exactly what the decision in the Ripple case says: it says that certain types of transactions are not securities transactions, but some are.

Thank you for pointing that out. I added the qualifier exchange traded when referring to XRP in an attempt to highlight that distinction, but my terminology was imprecise.

As you note, the court identified the transaction as the proper level of analysis, and found that whether or not participants entered into an investment contract depended on the nature of the transaction, not the token.

Implicit in this mode of analysis is that the XRP token is never itself a security; rather, securities laws are implicated when the XRP token is part of an investment contract, where the investment contract is itself a security, but the underlying asset is not.

By answering in the form of a question you seem to be implying that the answer is obvious.

But the judge in the SEC v. Ripple case found that exchange-traded XRP tokens are not securities; even if you think she is wrong, the fact that she disagrees with the SEC (and with you) is evidence that the answer is in fact not obvious.

With regards to whether Ethereum is a security, even the SEC is unsure. When asked under oath before Congress, the SEC Chair has repeatedly refused to give a direct answer. The commission has also avoided naming Ethereum as a security in any of its crypto exchange lawsuits, while it does name direct Ethereum competitors. If it were obviously a security, why would they name other tokens but not Ethereum?

And what about Bitcoin? The SEC has said unequivocally that it is not a security, but they refuse to say what specifically distinguishes Bitcoin from other tokens. Bitcoin cannot be one-of-a-kind in this regard—what would it take for another token to fall in the same category as Bitcoin?

Clearly, some tokens are not securities! If you cannot specify clear criteria to distinguish between security tokens and non-security tokens, you don't have a valid definition.

Here you go: "A security is a fungible, negotiable financial instrument that represents some type of financial value"

Is that your own definition? Luckily, the SEC is constrained by laws passed by Congress and by Supreme Court precedent—both of which run counter to your definition—and doesn't have the same flexibility that ordinary citizens do when articulating policy.

The SEC's position is simple: the same rules apply to crypto as to other financial products.

If you only reference the SEC's own press releases, you are going to miss the nuance here.

The SEC on its own doesn't get to decide when and how existing securities law applies to cryptocurrencies. Absent a settlement, any action undertaken by the SEC must be decided by a federal court.

Importantly, the SEC has been losing in court. For instance, the SEC, which had been blocking a spot Bitcoin ETF, was told in unequivocal terms by the DC Court of Appeals that its reasons for not allowing the ETF to issue were completely unsound. More pertinent to the question of enforcement: another federal court recently found that exchange-traded Ripple XRP tokens are not securities, with the implication that the SEC does not have jurisdiction to regulate the trading of Ripple XRP tokens on exchanges. If you extrapolate this finding to other cryptocurrencies, the SEC cases against Kraken and Coinbase are on shaky ground.

The fact that the SEC can list so many victories on its website is more a function of how costly it is to fight the SEC in court, rather than being a function of whether the SEC is right in all of its assertions.

There have been too many cases of fraud in the crypto industry, and it's good that the SEC has pursued enforcement against them. There are cases, however, where SEC has gone too far, and continues to go too far—especially in light of the fact that the SEC refuses to set forth clear criteria as to which crypto tokens it considers securities, and which crypto tokens it does not consider securities.

Now that the SEC is going after larger players, we are starting so see more cases actually go to court. If the trend continues, one or more of these cases will end up before the Supreme Court, and we will find out what the actual law is in the United States with regards to which crypto tokens are securities and which ones are not, and whether the SEC does in fact have any jurisdiction at all over the crypto exchanges.

You should not be surprised if after everything is said and done—after we have a Supreme Court opinion—crypto is in fact a special case under US securities law, at least with regards to some tokens.

You should also not be surprised if some of the cases in the list that you reference lose their legal support once the law is clarified by the Supreme Court. In hindsight, some of these SEC enforcement actions may be seen as unfair and unjust.

How many other money transmitters (that are not registered securities exchanges or banks) have 'tokens for sale' like Kraken?

Quite a few. In fact, all of the major centralized exchanges operating in the US are authorized to do so because they are licensed money transmitters (with the exception of some that might be operating under the NYS "Trust" licensing scheme), and none of them are broker-dealers regulated by the SEC, because until very recently the SEC has taken the position that broker-dealers are not allowed to sell crypto assets.

For years the money transmitter licensing scheme was understood to be the correct (and sufficient) licensing scheme under which a crypto exchange could legally operate in the United States. It is only since the beginning of the Biden administration that the SEC has taken the position that crypto exchanges have an obligation to register with the SEC. The Ripple lawsuit was filed at the tail end of the Trump administration (after the election), but it was not targeted at exchanges. It's also worth noting that the judge in the Ripple case found that exchange-traded XRP tokens are not securities. In other words, the SEC's assertion of authority over exchange-traded Ripple tokens was explicitly denied.

There is good reason to believe that SEC will be unsuccessful in asserting even broader authority over all tokens that are available on Kraken.

You seem to be conflating “segregating customer funds” and “having enough assets to cover customer obligations.”

Both banks and money transmitters (including Kraken) need to maintain sufficient assets to cover customer obligations. The difference is that for money transmitters those assets have to be liquid, while for banks they do not have to be liquid (which is why SVB got into trouble).

On the other hand, neither banks nor money transmitters need to designate specific assets as being held on behalf of customers, specifically, separate and apart from their own capital or operating accounts. Designating specific accounts or balances as being held on behalf of customers is typically what is meant by “segregating customer funds”.