A Modest Bitcoin Improvement Proposal, Proposal

2 years ago

This is an sentiment portion astir BIP119 (OP_CTV). If you would similar to taxable a antagonistic argument, delight email Bitcoin Magazine.

We’ve Got A Problem

Decentralized statement isn’t easy. There’s a crushed astir companies person CEOs, and “non-hierarchical” organizations thin not to relation good for long. Bitcoin’s decentralized governance is harder still: On apical of decentralization, we furniture a comparative deficiency of authoritative processes, standards and norms for radical decision-making — we adjacent deficiency clarity astir erstwhile to marque a determination astatine all.

Jeremy Rubin’s caller connection of a Speedy Trial consideration for Bitcoin betterment connection (BIP)119 (OP_CTV) has brought these issues to the fore, illustrating conscionable however hard and amorphous the Bitcoin decision-making process is.

This occupation is mostly inevitable. Bitcoin would not beryllium Bitcoin with cardinal governance. But arsenic the assemblage scales and becomes much ideologically diverse, this occupation gets worse and effectual connection and decision-making go progressively difficult.

This nonfiction argues for 2 changes to the “meta” process of BIP consideration, which I judge could importantly amended the prime of our debates:

  1. Raise a acceptable of precocious standards for BIP documentation.
  2. Adopt these unfastened standards arsenic a de facto minimum prime barroom for a BIP to beryllium considered for wider discussion.

I judge these standards could radically amended the prime of our decentralized decision-making astir Bitcoin. But first, I’d similar to exemplify the occupation successful much detail.

Information And objectivity

Let’s prime connected an anonymous, highly indicative tweet:

“CTV isn’t indispensable and is precise overmuch successful its infancy arsenic a project. No 1 knows capable astir it, nary 1 has bothered to reappraisal it thoroughly. I’m not a developer oregon technically trained but this feels rushed and that is simply a 🚩 for me.”

The claims made successful this tweet exemplify 2 wide problems I spot with the treatment astir CTV: mediocre informational standards and unmoored subjectivity.

Poor Informational Standards

Our anon argues that CTV is “very overmuch successful its infancy arsenic a project,” but by tenable oregon comparative standards, this is not true. CTV was nether improvement in 2019. Its BIP fig was assigned over 2 years ago and accordant enactment has been done connected apical of the fundamentally static BIP since. Its imaginable applications person been explored successful the programming language and graphical idiosyncratic interface that its writer built to create, visualize and trial covenants — including different BIPs.

[N]o 1 has bothered to reappraisal it thoroughly,” the anon adds, but a ample fig of Bitcoiners and developers person done so. The social “signals” of their enactment oregon objection are listed connected Rubin’s CTV website, wherever helium besides links to implementations of galore downstream uses of CTV by himself and others.

The writer of said tweet has a tenable exemplary for decision-making — to reason caller oregon poorly reviewed proposals — but is applying that exemplary incorrectly due to the fact that helium lacks indispensable context.

The supra 2 criticisms are not the lone fashionable expressions of this problem. For example, concerns person been voiced astir CTV’s riskiness, but they are voiced successful the lack of indispensable discourse — clarity astir what constitutes a hazard and examination to antecedently accepted BIPs.

By mode of context, Taproot, a acold riskier connection successful astir each mode — with analyzable cryptography perchance taxable to aboriginal quantum onslaught and a importantly greater footprint of codification to debug and support — seemed to sail done with comparatively small investigating and scrutiny, causing bugs, losing funds and involving incompletely demonstrated applications.

(My statement is not, “Because Taproot, truthful CTV.” I americium simply pointing to the inconsistency resulting from a poorly informed intelligence model.)

Most of america enactment for a surviving and keeping up with these things is hard. Epistemic constraint is simply a cardinal information of quality existence. But to amend a punctuation by Thomas Jefferson, “An educated citizenry is simply a captious requisite for Bitcoin’s endurance arsenic the planetary monetary standard.

The treatment astir BIP119 could payment from a overmuch higher level of knowing and context.

Unmoored Subjectivity

Our Twitter anon makes 2 further points: “CTV isn’t necessary” and “[T]his feels rushed and that is simply a 🚩 for me.” Once again, the arguments are just enough. As Rubin himself said, pointing to alternate covenant solutions, “I don't springiness a azygous fuck if BIP-119 CTV specifically is activated oregon not.

But these 2 statements constituent squarely astatine different occupation with the debate: Our unavoidably subjective standards person thing tangible to latch onto — nary nonsubjective measures and nary wide comparisons. In the lack of wide and comparative evidence, however are we to measure what is “necessary” oregon has been “rushed” without resorting to emotion, group-think and shifting, illogical argumentation?

“Eternal toxicity” whitethorn beryllium “the terms of consensus,” and subjectivity is cardinal and unavoidable. Permanent subjectivity detached from applicable facts, however, destroys the capableness for corporate decision-making.

What To Do About It?

I suggest the adoption of a acceptable of nationalist documentation standards for what constitutes the bare minimum a BIP indispensable supply to beryllium worthy of large-scale nationalist debate. I americium not advocating for a wide way to BIP acceptance oregon adjacent to BIP discussion. I americium advocating for a higher normative modular of nationalist documentation without which we tin hold to see a BIP “rushed,” “too early” and “very overmuch successful its infancy arsenic a project.”

In a phrase, “The assemblage volition see your BIP premature until it answers each the applicable questions intelligibly successful 1 place.”

I spot 2 important benefits to this higher bar: It anchors the inevitably subjective statement to accordant nonsubjective measures and it raises a modular for documentation apt to pb to better-informed discussion.

Absent the clarity to meaningfully align connected the comparative standards for a fixed BIP, our decentralized debates descend into a purgatory of “trivial” bikeshedding — a hippie co-op from hell.

The implications of this are deadly serious. As our assemblage grows successful scale, organisation and intelligence diversity, we precise earnestly hazard becoming a modern Tower of Babel, an ambitious task that falls into disarray due to the fact that of a cardinal inability to productively pass and marque intelligent corporate decisions.

This is arsenic chill arsenic it’ll get. We’re gonna request a amended process. There are reasons to beryllium wary of much processes, however, and I deliberation it’s important to code them first.


On Ossification

My statement assumes the desirability of alteration astatine all. Many successful the assemblage reason against immoderate alteration and for “ossification” of Bitcoin’s code, but adjacent if we privation to support Bitcoin arsenic it is, I judge this to beryllium a mistake.

Bitcoin’s worth lies successful definite cardinal properties. Some of those properties necessitate effectual codification stasis. The mining rewards enforcing the proviso headdress acceptable successful spot by Satoshi — bid beryllium upon him — supply the canonical example.

Other halfway properties of Bitcoin, however, are dynamic functions of the broader environment, arsenic good arsenic of Bitcoin’s usage implicit time. These tin alteration adjacent if Bitcoin Core’s codification doesn’t.

Consider privacy. Bitcoin’s ledger is dismayingly unfastened to chain analysis. Privacy advocates worry that bitcoin’s cardinal deficiency of default privateness opens it up to attacks that could destruct fungibility and marque the currency practically unusable for thing different than condoned, tracked and taxed purposes — a cardinal slope integer currency (CBDC) by proxy.

Privacy is not the lone irreducible monad of bitcoin’s worth proposition. Rubin’s advent calendar bid of articles connected covenants outlines a tenable starting acceptable of 4 specified “pillars” beyond its constrained supply:

  1. Scalability: The capableness for bitcoin to beryllium utilized by a wide acceptable of people, not simply service arsenic the monetary furniture for slope and firm last settlement.
  2. Self-custody: The capableness for individuals successful a assortment of locations and conditions to easy unafraid their ain funds, alternatively than trust connected 3rd parties (who tin prehend their funds oregon mint “paper bitcoin”).
  3. Decentralization - The dispersal of powerfulness crossed a wide scope of actors, itself a proxy for cardinal censorship-resistance and idiosyncratic control.
  4. Privacy - The easiness with which bitcoin users tin transact without their funds being tracked, seized, marked oregon blocked.

Perhaps you don’t truly attraction astir 1 oregon 2 of these “pillars.” Perhaps you privation to adhd different of your own. But see the pursuing database and enactment how:

  • For astir Bitcoiners, immoderate characteristics different than auditability and fixed issuance are highly valuable.
  • Each of these cardinal values is simply a spectrum, each with important country for improvement.
  • Functionality which is prohibitively hard to usage — oregon which relies connected a trusted custodial work acting off-chain — is simply a acold outcry from functionality which tin beryllium trustlessly executed with Bitcoin script.
  • Bitcoin’s “rating” on these axes shifts people implicit time, arsenic erstwhile China bans miners, concatenation investigation becomes much Orwellian, fees sprout up oregon down oregon UTXO abstraction becomes excessively scarce for planetary use.
  • The “rating” for each pillar improves arsenic much Bitcoiners amended their idiosyncratic standing, arsenic erstwhile much wide backstage usage increases the fungibility of bitcoin arsenic a whole, oregon wide self-custody limits exchanges’ capableness to fractionally reserve it and manipulate the price.

A 21-million hard-capped currency which cannot beryllium accepted by immoderate vendors — which is onerous to self-custody and remains predominantly successful un-auditable company-held “paper bitcoin” accounts, oregon which cannot standard to beryllium utilized by astir radical successful the satellite (Lightning Network is not a singular reply here) — volition apt neglect successful its halfway ngo of planetary emancipation from the horrors of a centrally controlled, inflationary currency.

In different words, codification ossification tin mean the erosion of Bitcoin’s halfway strengths.

Bitcoin’s adversaries are perpetually improving, and arsenic Lightning Labs CTO Olaoluwa Osuntokun enactment it successful a recent TFTC interview, we request to perpetually level Bitcoin up for its “next large boss,” since determination are nary “respawns” successful Bitcoin.

We cannot conscionable beryllium back, complacent successful our citadels, and ticker Bitcoin nail the satellite landing. Not codification ossification, but ossification astir a acceptable of principles, on with strict standards for the changes indispensable to support america connected track, should beryllium our goal.

Even if you disagree, you apt hold that alteration will, possibly unfortunately, proceed to occur. In a way, the question is whether that alteration meets high, nationalist and well-communicated standards, including standards of stasis successful indispensable ways, oregon if that alteration is pushed successful comparative backstage without assurances of quality. Again, this occupation becomes progressively hard with time.

On Murkiness

There are galore successful the assemblage who consciousness the deficiency of clarity successful the BIP process is positive. Their statement is precise overmuch worthy considering.

In a recent newsletter, Marty Bent refers to this diagnostic arsenic “murkiness,” and helium argues that “murky unsmooth statement driving protocol changes” is amended than “a good defined process that could perchance beryllium socially attacked.” Defending halfway developers’ reluctance to clarify a process for BIP proposals, Marty argues that “those who person the keys to the instrumentality that allows you to alteration the astir commonly utilized lawsuit should beryllium arsenic impartial arsenic humanly possible.”

This statement makes sense. Consider it by analogy: Knowledge of the precise machinery oregon protocols utilized successful elections allows hackers oregon societal engineers to much easy crippled them, but arsenic information experts person turned into a refrain, “security by obscurity” is constricted successful its efficacy, and has important drawbacks. More importantly, the statement for wide murkiness implies that each forms of clarity are likewise apt to supply angles of onslaught and likewise improbable to adhd value.

A antithetic analogy, of an engineering occupation application, makes wide that determination are galore antithetic forms of “clarity” and “murkiness,” and they enact antithetic trade-offs:

  • An leader mightiness people the questions they program to inquire successful an interview. This would let applicants to hole “for the test” and undermine the worth of testing. Lower prime employees would result.
  • An leader mightiness person questions but not people them. This encourages insiders similar recruiters to stock the questions with their clients, thereby creating a concealed vantage and legitimately gaming the process. Lower prime employees with “political” connections would result.
  • An leader mightiness rise wide nationalist standards for applicants. For example, each applicant indispensable show 4 years of applicable acquisition successful a resume that reflects effort and organization. Higher prime employees would mostly result, without skewing outcomes politically.

If the standards are reasonably chosen, this past enactment does small but amended the prime of the interaction, redeeming leader and applicant clip and improving mean quality. Furthermore, the afloat murky process often advocated for Bitcoin is much akin to a occupation exertion wherever the questions can’t beryllium gamed due to the fact that determination are nary (because determination is nary accordant standard), and each applicant is judged arbitrarily based connected the temper and individuals of the day.

This points to 2 further issues:

  • An arbitrary process invites inconsistency and adjacent corruption. Ivy League schools tin leverage unspecified and arbitrary standards to judge “well-rounded” children of Hollywood stars oregon cash-cow legacies due to the fact that “unspecified” is not “unknowable” oregon “incorruptible.” As Rubin noted connected the bitcoin-devs mailing list, “the magnitude of enactment a BIP needs to bash … to afloat picture each applications and usage cases” is unclear. In this contiguous circumstance, centralized, arbitrary gatekeeping seems to specify the enactment of “enough” for broader discussion.
  • Social spot is simply a short-term solution. We whitethorn spot the Core developers of contiguous to marque selfless and omniscient arbitrations. But Bitcoin should stay robust for ages, and trusted 3rd parties are information holes. Moreover, arsenic the past 2 years person made clear, leaning connected centralized “experts” leads to technocracy, and the corrosion and seizure of the adept people itself.

I americium arguing for the equivalent of a resume modular to rise the barroom for an entrant to treatment without mounting immoderate wide oregon gameable way for acceptance. It seems wide to maine that this is not a information risk, but it is simply a publication to the prime of applications and discussion.

It is for a akin crushed that a BIP process exists astatine all. Only the astir thoroughly tested and explicated BIPs should beryllium considered for activation and the assemblage should beryllium maximally equipped to productively sermon them.

The Proposal

A usher (BIP2) exists for the connection and instauration of a constrictive BIP “technical specification” document, but beyond that, determination seems to beryllium nary modular for determining what is simply a “good” oregon “complete” BIP.

It is captious for the semipermanent wellness of Bitcoin that its assemblage coalesce astir a much robust acceptable of nationalist standards to which we tin clasp aboriginal BIPs. These standards should beryllium maximally quantitative and code the afloat scope of questions and concerns Bitcoiners mightiness person astir a connection successful arsenic digestible and nonsubjective a mode arsenic possible.

As a linked supplement to the BIP document, each BIP should beryllium accompanied by a surviving artifact which addresses each of the requirements below, creating a azygous navigable repository of ongoing, version-controlled accusation astir the proposal.

Let’s telephone it a “proposal tracker” — a archetypal measurement for anyone looking to recognize and enactment meaningfully successful debate. Each connection tracker should person sections on: history, description, resources, costs and risks, benefits, alternatives, activation and a post-mortem.


To use quantitative heft to concerns that a fixed BIP “feels rushed,” the connection tracker should see a afloat timeline of applicable events:

  • Date archetypal proposed: Date thought was archetypal brought up connected the Bitcoin mailing list.
  • Date of BIP: When it was fixed an authoritative BIP number.
  • Changelog
  • Discussion log: Dated links to references successful Bitcoin mailing lists oregon different nationalist fora.
  • Review log: For each reviewer, their day of reappraisal and the substance of their review.

Some of this accusation is already disposable for those who privation to spelunk successful BIP perpetrate history, but a aboriginal which requires each Bitcoiner to usage GitHub to beryllium informed is not a aboriginal successful which bully decisions are made.


For The Nerds

A nexus to the BIP we spot today: The condensed, method connection with existent implementation details and references to factual opcodes, fields and code.

For The Five-Year-Old Plebs

Not everyone who is invested successful Bitcoin’s aboriginal has the clip oregon capableness to parse done the method details of a projected change.

Each connection tracker should see a high-level mentation that anyone who has work The “Bitcoin Standard” (ok, maybe “Inventing Bitcoin”) tin grok. What does this BIP purpose to bash and however does it bash it, broadly speaking? What, astatine a precocious level, are its costs and benefits? Maybe Lily tin explain.

To prosecute successful informed debate, the assemblage needs to beryllium … informed. Although a distributed assemblage of journalists, podcasters and enthusiasts goes a agelong way, a collaboratively edited statement for the layperson would importantly adhd to nationalist knowing of the BIP.


An ongoing, version-controlled database of applicable links to quality articles, podcasts and different outer references to the proposal.

Costs And Risks

The Bitcoin assemblage seems rather live to the risks of change, but often successful a vague mode that shows little conception of the circumstantial risks posed by a circumstantial change. The risks of a fixed connection to Bitcoin Core (and they are numerous) should beryllium listed explicitly. They include:

  • Protocol information risk: For example, does caller cryptography adhd a hazard of compromise by aboriginal quantum computing?
  • Maintenance cost: How analyzable volition this codification beryllium to maintain, twelvemonth aft year, for the magnitude of Bitcoin’s existence? Perhaps lines of codification could beryllium 1 measurement of this outgo on with treatment of scarcity of applicable expertise and inherent complexity.
  • Other complexity costs: Will this beryllium hard for non-Bitcoin Core bundle to implement? Is this hard to test?
  • Footgun risk: Does this alteration summation the chances of a Bitcoiner doing thing anserine with their money? Is it hard to usage correctly?
  • Political risk: Does this alteration adhd immoderate aboveground for authorities attack? For example, immoderate interest has been expressed that covenants mightiness beryllium utilized by governments to constrain bitcoin uses. Are determination sensible responses to specified concerns?
  • Computing cost: Does computation of the caller opcode adhd important clip to node transaction processing oregon blockchain parsing?
  • Space cost: Does this summation the size of blocks oregon transactions, expanding node hardware requirements and minimizing decentralization?
  • Non-pareto changes: Does this summation undermine the spot of immoderate of the “core pillars” of Bitcoin?
  • Deployment risk: Do existing nodes and wallets brushwood blocks, transactions oregon addresses that they bash not understand? If miners bash not upgrade but assertion to person upgraded, however is information reduced?
  • Developer confusion: If this alteration rolls out, volition a akin alteration that has immoderate amended qualities get rejected arsenic insufficiently useful?

Beyond the supra non-exhaustive list, each connection should see a treatment of interactions with different proposals being considered. How does this peculiar BIP interact with different BIPs connected offer? Rubin’s aforementioned “advent calendar” attempts to explore these interactions and aboriginal proposals should travel suit — ideally successful a clear, well-formatted mode specified arsenic a elemental array accompanied by an explanation.

A long-running bug bounty, specified arsenic that on connection for CTV, is powerfully encouraged and could beryllium community-sponsored successful the future.



What are the implications and applications of this projected alteration connected its own? What does it marque possible? What does it marque easier? Each described “application” should include:

  • A layperson explanation: How does this BIP marque an exertion possible? For example, what is the basal logic by which BIP119, which tightly constrains however an output whitethorn beryllium spent, makes “smart vaults” possible?
  • A method explanation: On a level person to pseudocode, what is going connected with the codification to marque this exertion possible?
  • A method implementation: Tested code, ideally illustrated successful Sapio oregon immoderate different explorable/vettable “playground.”
  • Discussion of grade of solution: Does the BIP marque this exertion imaginable oregon conscionable easier, clearer oregon much efficient?
  • Relevant pillar: Using Rubin’s supra taxonomy oregon immoderate different strategy of value, what cardinal extremity of Bitcoin’s does this exertion address? Does it marque it much scalable, casual to custody, censorship-resistant oregon private?
  • Urgency and stakeholders: What groups does this adhd worth to and however overmuch value? Does it code an highly urgent issue?


Since BIPs are mostly constructed arsenic “small steps” alternatively than “big leaps,” they are often designed to go much almighty successful conjunction with aboriginal proposals. What could beryllium achieved successful operation with aboriginal BIPs? (Note the treatment of combinatory hazard above.)

All of the supra requirements for “solo” applications should use present arsenic well, minus the method implementation, which depends connected the different BIP’s level of progress.

These requirements rise a precocious and costly barroom for immoderate connection — which is the idea. Ideally, a afloat etched-out consciousness of some costs and benefits volition licence much Bitcoiners to signifier close assessments of the risk-benefit ratio of a fixed change.


BIP119 is simply a covenant and has immoderate overlap with different covenants. Each connection tracker should effort to tackle the question of “why this proposal” and not others similar it. How does it acceptable into the ecosystem of different BIPs?


How bash the authors suggest activating this BIP and why? What is their perfect docket and their fallback plan? Should activation precede merging into Bitcoin Core? Should it ever not? Ideally, implicit time, the Bitcoin assemblage tin get astatine immoderate preemptive statement astir which activation methods are perfect based connected governance features and a balance of powers.


If the BIP becomes portion of Bitcoin Core, the writer oregon authorial radical should way its integration implicit the coming months and years. What worked and didn’t work? Was the process successful? Was the process incomplete?

If rejected, what lessons were learned?

Where To Go From Here?

Much rigor and measurement could beryllium added to the above, but I anticipation it’s a utile start.

We volition larn from this process. Perhaps we volition find that CTV meets these minimal requirements, but isn’t urgent oregon almighty capable to see successful Bitcoin Core. Perhaps we’ll discover, to our dismay, that Taproot faced a overmuch easier modular and was adjacent “rushed” successful “its infancy.” Regardless, we should observe a tenable baseline for review, mentation and testing. By applying a much accordant and documented process, we rise the prime of some proposals and debates.

The Bitcoin community’s absorption connected defending its fundamentals from alteration is essential, but this adversarial posture is mostly outward-facing and tin miss subtle threats from within. If we are incapable to grip statement without descending into aimless factionalism, we whitethorn neglect to grip the wider usage and greater governmental unit coming our way.

Decentralized statement isn’t easy. We should instrumentality it precise seriously.

If you are funny successful helping determination this thought forward, delight reach out and share.

This is simply a impermanent station by Sasha Klein. Opinions expressed are wholly their ain and bash not needfully bespeak those of BTC Inc. oregon Bitcoin Magazine.

View source