<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Julian</title>
        <link>https://paragraph.com/@julian-6</link>
        <description>undefined</description>
        <lastBuildDate>Thu, 13 Aug 2026 13:02:56 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[MakerDAO will not Dai]]></title>
            <link>https://paragraph.com/@julian-6/makerdao-will-not-dai</link>
            <guid>GZkZTO3Syll4SMtrCVwm</guid>
            <pubDate>Thu, 02 Jun 2022 16:18:36 GMT</pubDate>
            <description><![CDATA[Okay, the title is a little dramatic. I won’t be covering why MakerDAO won’t die (dai), or why Dai is better than the others. I’ll just be giving a shallow dive into MakerDAO. Before we start, watch this video on Vitalik Buterin, Co-founder of Ethereum, saying that he&apos;s “definitely impressed by MakerDAO”. If that doesn’t warrant your interest, I don’t know what will. Okay, let’s get started.A brief history of MakerDAOLet’s turn back to 7 years ago to a reddit post by Rune Christensen thr...]]></description>
            <content:encoded><![CDATA[<p>Okay, the title is a little dramatic. I won’t be covering why MakerDAO won’t die (dai), or why Dai is better than the others. I’ll just be giving a shallow dive into MakerDAO.</p><p>Before we start, watch <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.youtube.com/watch?v=XlYyj0WFi9Y&amp;ab_channel=RandomVideos">this video</a> on Vitalik Buterin, Co-founder of Ethereum, saying that he&apos;s “definitely impressed by MakerDAO”. If that doesn’t warrant your interest, I don’t know what will. Okay, let’s get started.</p><h3 id="h-a-brief-history-of-makerdao" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A brief history of MakerDAO</h3><p>Let’s turn back to 7 years ago to a <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.reddit.com/r/ethereum/comments/30f98i/introducing_edollar_the_ultimate_stablecoin_built/">reddit post by Rune Christensen</a> throwing out the idea of the &apos;ultimate stablecoin built on Ethereum&apos;, originally termed as &apos;eDollar&apos;. What Rune wrote in that reddit post, at its core, is essentially what MakerDAO does with Dai right now as well (which we&apos;ll dive into later!).</p><p>He made it into a reality, and MakerDAO has definitely garnered a lot of attention. They were the first investment of <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bitcoinmagazine.com/business/a16z-puts-16-million-behind-stablecoin-platform-makerdao">a16z&apos;s</a> crypto fund, pouring $15 million to buy up 6% of its token supply, on top of a $12 million round done in 2017. In 2019, they received another $27.5 million from <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblockcrypto.com/post/51059/makerdao-receives-27-5m-from-dragonfly-and-paradigm-to-expand-into-asia">Dragonfly and Paradigm</a> to help them break into the USDT dominated Asia market.</p><p>In Dec 2017, MakerDAO introduced the original Dai (now Sai), that (only) accepted Ethereum (ETH) as a collateral to generate the stablecoin. By <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coindesk.com/markets/2019/10/09/makerdaos-multi-collateral-dai-token-is-launching-nov-18/">Nov 2019</a>, MakerDAO started accepting various Ethereum-based asset types to be used as collaterals. That’s the Dai that we know (and use) today.</p><p>So, that’s a super brief history. If you want to look back and understand their journey, this <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.makerdao.com/makerdao-has-come-full-circle/">article here</a> is a good overview! I want to spend a little more time on the key elements of MakerDAO instead.</p><h3 id="h-what-makes-makerdao-makerdao" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">What makes MakerDAO, MakerDAO?</h3><h3 id="h-1-dai" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">1. DAI</h3><p>Dai is basically a stablecoin that is decentralised, unbiased, collateral-backed, and soft-pegged to the US Dollar. At day of writing, Dai is the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coingecko.com/en/categories/stablecoins">fourth largest stablecoin</a>, behind USDT, USDC, and BUSD. All of them serves the same purpose (1 stablecoin = 1 USD), but are slightly different.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/48840a53118d7e10004b4a549f4afcfbc6d91173a22a6e3d0ba38a455671dc19.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>How are they different though? Generally, there are three kinds of stablecoins:</p><ol><li><p>Fiat backed (USDC, USDT) - stablecoins are <strong>backed by actual fiat</strong> in the form of cash, bonds, commodities, US treasuries. More stability, but centralised and requires regulatory oversight</p></li><li><p>Algorithmic (UST) - relies on one stablecoin and another cryptocurrency that backs the stablecoin (e.g. UST and LUNA), with a <strong>smart contract that regulates the relationship</strong> between the two. Does not require collateralisation and is decentralised, but <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coindesk.com/learn/algorithmic-stablecoins-what-they-are-and-how-they-can-go-terribly-wrong/">risk depegging</a> with large-volume withdrawals</p></li><li><p>Collateral backed - Basically <strong>requires another asset to back it</strong>. This is the core of what Dai is. Let&apos;s dig slightly deeper below.</p></li></ol><p>As a user, to generate Dai, you would have to deposit collateral assets (think ETH, WBTC, LINK, MATIC etc). What you&apos;re essentially doing is <strong>borrowing Dai</strong>, similar to how you can only borrow money from a bank if you put your house as a collateral.</p><p>The Dai you have right now can be used just like any currency and any other stablecoin out there. And similar to your savings account, you can <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://makerdao.world/en/learn/Dai/dsr/">earn interest</a> on your Dai.</p><h3 id="h-2-maker-vault" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">2. Maker Vault</h3><p>Think of Maker Vault like any other vault out there - it keeps your money. But Maker Vault does more than that.</p><p>Enter <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://oasis.app/">Oasis</a>. Oasis allows you to create the vault to generate the Dai you need!</p><p>Here&apos;s a few things that you need to take note of though.</p><ul><li><p>Collateralisation Ratio: You <strong>need to be within the Collateralisation Ratio</strong> [Calculation = (Deposit in USD value / Dai)*100%]. So assuming the collateralisation ratio is 150% and you deposit $1000 worth of ETH into the vault, you can take (read: borrow) up to 666 Dai tokens ($666).</p></li><li><p>Liquidation Price and Ratio: If the value of your collateral or the collateral to Dai ratio <strong>falls below a liquidation price or ratio</strong>, you will be <strong>subject to liquidation</strong>. This means that your collateral will be sold and you&apos;ll have to pay a Liquidation Penalty. To prevent this, you can either pay back the Dai you&apos;ve borrowed, or deposit more collateral.</p></li><li><p>Stability Fee: This is basically the <strong>interest rate</strong> that you would need to pay at the end, similar to what a traditional bank would charge you.</p></li><li><p>Closing the vault: If you do decide to close your position, you can either <strong>payback</strong> all the Dai you&apos;ve borrowed or <strong>sell</strong> your collateral right there and then. You definitely can’t do that with a traditional house. I mean you can’t just sell your house back to the bank to repay your loan.</p></li><li><p>And it’s super flexible: Unlike banks, there’s no repayment schedule or timelines involved. You just need to maintain a healthy collateral ratio!</p></li></ul><p>Note that Oasis does more than just this. Do check out the app for more details!</p><h3 id="h-3-the-mkr-token" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">3. The MKR Token</h3><p>MKR is mainly used to two things - governance and recapitalisation.</p><p><strong>As a governance token:</strong></p><p>MKR <strong>allows its holders to vote</strong> on a variety of items, such Risk Parameters of Maker Vault and other non-technical aspects, among other things</p><ul><li><p>Risk Parameters of each vault - e.g. Debt Ceiling, Stability Fee, Dai Savings Fee</p></li><li><p>Other non-technical aspects - e.g. Asset priority lists, governance processes etc</p></li><li><p>See the other items you can vote on <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://vote.makerdao.com/">here</a> as well!</p></li></ul><p><strong>As a recapitalisation source</strong></p><p>This happens when the Maker Protocol runs at a deficit. If the collateral portfolio becomes undercollateralised and show threat of insolvency, such as when the price of the collateral drops drastically and does not cover the Dai issued, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://medium.com/@MakerDAO/what-is-mkr-e6915d5ca1b3">automatic recapitalisation</a> is triggered.</p><p>The Maker system does this by creating new MKR tokens and selling them on the market, which will allow them to raise the necessary funds to bring it back from insolvency. As more MKR tokens are issued, the value per token drops since there are more in circulation. That&apos;s why <strong>MKR holders are incentivised to govern the system well</strong> to prevent dilution on their part. This whole process is called a <strong>Debt Auction</strong>. Get a preview of it in <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cointelegraph.com/news/2-million-of-makerdao-debt-to-be-wiped-as-auction-reaches-final-stages">this article</a> or this <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://forum.makerdao.com/t/black-thursday-response-thread/1433">thread here</a>!</p><p>There will also be cases where MKR will appreciate in value too! One way that the system does this is via <strong>surplus auction</strong>, which is the opposite of debt auction. Here&apos;s how it works: when you get Dai as a user, you&apos;ll need to pay an interest rate (&quot;stability fee&quot;). This stability fee (in Dai) is kept in a safe place, which is termed as &quot;<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://makerdao.world/en/learn/governance/param-system-surplus-buffer/">surplus buffer</a>&quot;.</p><p>If the surplus buffer gets too large, the system will use the Dai in the surplus to purchase MKR and burn it . As a result, there&apos;s less tokens in circulation, value per MKR token increases! This also incentivises MKR token holders to govern the system well too!</p><h3 id="h-and-thats-it" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">And that’s it!</h3><p>This is by no means a complete guide, but hope this gives you a quick overview of MakerDAO and Dai. See you in the next one!</p>]]></content:encoded>
            <author>julian-6@newsletter.paragraph.com (Julian)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/82756ab5385d4a18856d212968978134730192cd14c74ef6d0e750d5794bc17b.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Why I know Web3 will make it]]></title>
            <link>https://paragraph.com/@julian-6/why-i-know-web3-will-make-it</link>
            <guid>8ztl3XUmNTimgmPJprPw</guid>
            <pubDate>Mon, 02 May 2022 17:26:43 GMT</pubDate>
            <description><![CDATA[We often hear these three keywords about blockchain: Trustless (no middlemen), Permissionless (everyone can participate), and Open/Transparent (open-source). If you’re like me a few months back, I’ll be like: Okay…… That’s nice. But really, I think the most important thing about these three characteristics is that they will push forward innovation like we’ve never seen before. Enter the world of PERMISSIONLESS INNOVATION Let’s talk about that today. But before that, let’s enter the web2 world...]]></description>
            <content:encoded><![CDATA[<p>We often hear these three keywords about blockchain: Trustless (no middlemen), Permissionless (everyone can participate), and Open/Transparent (open-source).</p><p>If you’re like me a few months back, I’ll be like: Okay…… That’s nice. But really, I think the most important thing about these three characteristics is that they will push forward innovation like we’ve never seen before.</p><p>Enter the world of <strong><em>PERMISSIONLESS INNOVATION</em></strong></p><p>Let’s talk about that today. But before that, let’s enter the web2 world to draw some parallels.</p><p>To be fair, even right now, we do see permissionless innovation happening all around us. Entrepreneurs are able to push their ideas forward because generally, innovation is not treated as a threat from the start. For the more regulated spaces, such as financial services sector, there are <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.bnm.gov.my/sandbox">sandboxes</a>!</p><p>I’d like to believe the first wave of permissionless innovation came after the commercialisation of the internet, with the Clinton administration advocating for the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://clintonwhitehouse4.archives.gov/WH/New/Commerce/summary.html">private sector to lead</a> the market.</p><p>Listen to this short clip of Naval Ravikant, founder of Angelist, talk about permissionless innovation <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.facebook.com/watch/?v=1678509135515894">here</a>. In this <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://open.spotify.com/episode/4gEKzuCAnR9JcomNcZHpQk?si=fd32a635606c4c30">podcast</a> that features Naval too, he says that</p><blockquote><p><em>“Almost all innovation that we rely on in the last 50-100 years, especially in information technology, happens because it is permissionless. I don’t need anyone’s permission to take a computer, write some code, start a website etc. So moving towards permissionless networks, opens up innovation, opens up participation, and opens up ingenuity.”</em></p></blockquote><p><strong>But all is not well.</strong></p><h3 id="h-areas-stifling-innovation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">AREAS STIFLING INNOVATION</h3><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.discoursemagazine.com/culture-and-society/2021/01/06/the-future-of-innovation-is-this-the-end-of-permissionless-innovation/"><strong>Regulation</strong></a> by the government can still stagnate growth, with Europe being the biggest example. In the past decade, Europe has stifled innovation with <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.politico.eu/sponsored-content/europe-innovate-or-stagnate/">regulatory barriers</a>, with them leaning on <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://app.croneri.co.uk/feature-articles/innovation-and-precautionary-principle-risk-or-opportunity">precautionary principles</a> and <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.weforum.org/agenda/2021/03/europe-learn-from-asia-stop-falling-behind-tech/">overregulating its startup ecosystem</a>. A <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www2.deloitte.com/uk/en/pages/technology-media-and-telecommunications/articles/future-of-tech-in-europe/a-tech-wasteland.html">fiction piece by Deloitte</a> even predict that Europe will be a tech wasteland by 2030 due to regulation. <strong><em>They need permission before innovating, and that slows things down</em></strong>. Though, it’s probably good to keep in mind that <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thenextweb.com/news/how-regulation-brought-innovation-back-to-european-tech">regulations may be getting better</a> to drive innovation in Europe.</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://komodoplatform.com/en/blog/permissionless-innovation/"><strong>Closed systems</strong></a> are also a problem. As companies get larger, they start closing their doors. Many things become proprietary, information gets transferred less, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.wired.com/insights/2014/06/enterprises-keep-external-apis-public-restricted/">API access is restricted</a>, all in the name of ‘being competitive’ and ‘building a moat’. As they establish dominance, they (and their employees) have less incentive to innovate.</p><p><strong>Intermediaries</strong> are relied too heavily upon for coordination. Think of Airbnb, Grab, Shopee, and our banking systems - we have become overly dependent on this platforms. These big players will eventually move from ‘attracting users’ towards <em>‘extracting value from users’</em>. On a whim, these big players can change the rules of the game that can make you and I suffer (e.g. higher fees, platform risk (removing your business)). Just think about how easily iOS/Google app store can remove apps, or how Grab fees are absurdly high nowadays. Users have less incentives to participate, and this definitely stifles innovation.</p><h3 id="h-two-areas-that-will-drive-permissionless-innovation-in-web3" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">TWO AREAS THAT WILL DRIVE PERMISSIONLESS INNOVATION IN WEB3</h3><p><strong>Open source</strong> - users can create and share information with each other freely. Being open source and driving innovation isn’t new (think Wikipedia). When people are allowed onto a technology, further applications will proliferate and the technology will spread. Don’t believe me? Even Elon Musk and Tesla made their <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.tesla.com/blog/all-our-patent-are-belong-you">patents open</a> to the general public to advance electric vehicles. Many blockchains like <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://ethereum.org/en/contributing/">Ethereum</a> are open source, allowing anyone to contribute through a number of ways, like working on open issues, adding community articles, creating decentralised apps and so on, <em>without the need of anybody’s permission</em>.</p><p><strong>Aligned Incentives</strong> - with native tokens, stakeholders (developers, entrepreneurs, investors and users) will be <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.innopay.com/en/publications/web-30-how-decentralisation-and-incentives-will-create-alignment-internet">aligned on a common goal</a> from the start till the end, which is to grow the network and increase the token’s value. Participation, whether in the form of coding, providing feedback, or voting, from all parties will be rewarded as the protocol (or dApp) grows. Same as above, <em>everybody can participate without permission</em>. I can’t describe this better than <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://onezero.medium.com/why-decentralization-matters-5e3f79f7638e">Chris Dixon</a>:</p><blockquote><p><em>“Decentralized systems start out half-baked but, under the right conditions, grow exponentially as they attract new contributors….There are multiple, compounding feedback loops involving developers of the core protocol, developers of complementary cryptonetworks, developers of 3rd party applications, and service providers who operate the network. These feedback loops are further amplified by the incentives of the associated token, which — as we’ve seen with Bitcoin and Ethereum — can supercharge the rate at which crypto communities develop.”</em></p></blockquote><h3 id="h-closing-notes" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">CLOSING NOTES</h3><p>I’ll end this article by a quote from our very own Malaysian founder from CoinGecko:</p><blockquote><p><strong><em>&quot;Nobody has to give you permission to do anything. When there is permissionless innovation, things move at a very rapid pace.&quot;</em></strong></p></blockquote>]]></content:encoded>
            <author>julian-6@newsletter.paragraph.com (Julian)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/ca1056c1d4c7b87dc0348ec811643f3cda42581cbbf3789267907222cfea7e05.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[The Foundation of Bitcoin - SHA256 (Web3 Analogies)]]></title>
            <link>https://paragraph.com/@julian-6/the-foundation-of-bitcoin-sha256-web3-analogies</link>
            <guid>gHwC2P2pp9wagf9uLD9b</guid>
            <pubDate>Mon, 18 Apr 2022 10:18:24 GMT</pubDate>
            <description><![CDATA[Bitcoin is nothing without SHA-256. In fact, we’re pretty much screwed if SHA did not exist. Let’s talk about how SHA-256 is used in bitcoin and why it’s so important. But before that, let’s go over a few key concepts, some history, and some existing examples of how SHA is used.KEY CONCEPTSIt’s a one way function This basically means that once I get a hash from a particular set of data, an outsider will not be able to decipher the message from the hash by itself. E.g. Inputting ‘Web3’ into th...]]></description>
            <content:encoded><![CDATA[<p>Bitcoin is nothing without SHA-256.</p><p>In fact, we’re pretty much screwed if SHA did not exist. Let’s talk about how SHA-256 is used in bitcoin and why it’s so important. But before that, let’s go over a few key concepts, some history, and some existing examples of how SHA is used.</p><h3 id="h-key-concepts" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">KEY CONCEPTS</h3><ul><li><p><strong>It’s a one way function</strong></p><p>This basically means that once I get a hash from a particular set of data, an outsider will not be able to decipher the message from the hash by itself. E.g. Inputting ‘<em>Web3</em>’ into this <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://xorbin.com/tools/sha256-hash-calculator">calculator</a> will yield hash ‘<em>20db…4358</em>’. If I just give you ‘<em>20db…4358</em>’, you most likely won’t be able to find out what data I inputted.</p></li><li><p><strong>You’ll die trying</strong></p><p>A say ‘most likely’ in the previous point because it’s not impossible. But it’ll probably take a few lifetimes, even with your fancy computers. If I gave you the hash function of ‘<em>20db…4358</em>’, you’ll need 2^256 attempts to generate the initial data. I can’t even brain the scale of this. But I hope this YouTube video would:</p></li></ul><div data-type="youtube" videoId="S9JGmA5_unY">
      <div class="youtube-player" data-id="S9JGmA5_unY" style="background-image: url('https://i.ytimg.com/vi/S9JGmA5_unY/hqdefault.jpg'); background-size: cover; background-position: center">
        <a href="https://www.youtube.com/watch?v=S9JGmA5_unY">
          <img src="{{DOMAIN}}/editor/youtube/play.png" class="play"/>
        </a>
      </div></div><ul><li><p><strong>No two messages have the same hash</strong></p><p>This is pretty straightforward. But what’s worth pointing out is that even a small change will yield huge changes. ‘<em>Web3</em>’ will generate ‘<em>20db…4358</em>’, while ‘<em>Web2</em>’ will generate ‘<em>f980…b45a</em>’. This is important and we’ll see why under the next section.</p></li></ul><h3 id="h-sha-2s-predecessor" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">SHA-2’s PREDECESSOR</h3><p>There are four groups of Secure Hash Algorithms (SHA) - SHA-0, SHA-1, SHA-2, SHA-3. But let’s just talk about a few notable ones (sorry SHA-0), and some use cases</p><p>SHA-1 was published in 1995 by the United States National Security Agency after finding a flaw in SHA-0. One of the use cases of SHA-1 is to verify a file. This is done by producing a <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.lifewire.com/what-does-checksum-mean-2625825">checksum</a> (or hash), a number that is generated by a file. This way, you can verify a file sent by me by cross-referencing the checksum that you and I have. If it’s the same then you can go ahead and download knowing that your copy is genuine. After downloading, you can even <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.lifewire.com/how-to-verify-file-integrity-in-windows-with-fciv-2625186">verify the document</a>.</p><p>However, they found a weakness in SHA-1. This ties in to my third point of no two messages (or documents) should have the same hash. <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html">Google</a> actually found two distinct pieces of data that produced the same hash.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/0253b63b3b48a13ec58a33f015d432b6fe4ff2383b49c66f1814f27e14ea7c8f.png" alt="Cryptographic hash collision" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Cryptographic hash collision</figcaption></figure><p>This is called a <strong>hash collision</strong>. Same way both ‘2+2’ &amp; ‘2x2’ produces 4. This is bad, because what if I wanted to send you a document containing ‘2+2’, but in the process has been tampered to ‘2x2’? There’s no way for you to determine that the document is genuine because the checksum is the same before downloading. This will be a security issue (think malware, virus etc).</p><p>SHA-1 was not considered secure since 2005 and governments and organisations have mostly transitioned to SHA-2 (which SHA-256 is part of) and SHA-3.</p><h3 id="h-the-broad-use-cases-of-hashing" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">THE BROAD USE CASES OF HASHING</h3><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://auth0.com/blog/hashing-passwords-one-way-road-to-security/">Passwords</a>: How do you think your bank stores passwords? Rest assured, they do not store your password in <em>plaintext</em> (aka what you can read). It’s actually hashed. So when you log in, you enter your password, your password get hashed, hashed password matches the stored hash, you enter your account.</p><p>Your bank technically don’t know your password (they hash it and forget about it), and hackers won’t be able to find out since hashing is, as mentioned, one way.</p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://en.wikipedia.org/wiki/Digital_signature">Digital Signatures</a>: This is used to verify the authenticity of the documents (or info sent), giving the recipient the confidence that the document has not been altered. The document is hashed, then encrypted by the user. There’s more to this, but basically if the document has been altered, it give rise to a different hash value, and the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://stackoverflow.com/questions/18257185/how-does-a-public-key-verify-a-signature">digital signature will not be valid</a>.</p></li></ul><h3 id="h-sha-256-in-bitcoin" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">SHA-256 IN BITCOIN</h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b23723238a648e7cf07ca564abc6f3651e4234d3bbc266d162307dcd60f5e487.png" alt="Bitcoin whitepaper" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Bitcoin whitepaper</figcaption></figure><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://medium.com/fluree/immutability-and-the-enterprise-an-immense-value-proposition-98cd3bf900b1"><strong>Immutability</strong></a> - unalterable, irreversible, permanent. That’s basically what it means. We can’t go back and change the block. And that’s because of SHA-256.</p><p>Take a look at the picture above and you can see that every block has its own hash. One of the key components of hash (output) is from the data from the previous block (input). If you have a chain of blocks that are already established, say block 1, block 2 and block 3. Any small changes in block 1 will break the entire chain (or rather, block 2 &amp; 3 will reject the modification). This is because of point 3 under key concepts - any changes in the input will lead to large changes in the output.</p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://bitcoinmagazine.com/technical/bitcoin-is-a-one-way-hash-function"><strong>Proof of work</strong></a> - this <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.youtube.com/watch?v=f9EbD6iY9zI&amp;t=275s&amp;ab_channel=learnmeabitcoin">YouTube video</a> gives the best explanation of mining by far (2.22 - 5.00). Translating that video into writing, to mine, you need to get the transactions, previous block, merkle roots etc, and the <strong>nonce</strong> (number only used once).</p><p>All the information mentioned above is readily available, except for the nonce. <em>You</em> will need to determine the nonce, and the result you’re looking for in a hash value that starts with a certain number of zeroes at the front (as of now, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.blockchain.com/btc/block/00000000000000000007ae1d4325cba63479623cbcaaaa7694a6860518897bbb">19 zeroes</a>).</p><p>Think of it as linear equation that you’re trying to solve in high school. You got 13 + 10 + <em>x</em> = 100, you’re just trying to find <em>x</em> (your nonce) so that your answer is 100. Only this time, it’s way harder, you can’t reverse engineer it, and there are no formulas.</p></li></ul><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/450b00f1f618e0821b01c88af452a39d7cf073ad9e5a2e523f056027595f585d.png" alt="Merkle Root" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Merkle Root</figcaption></figure><ul><li><p>Use <strong>fewer resources</strong> via <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.mycryptopedia.com/merkle-tree-merkle-root-explained/">Merkle Root</a> - Pretty simple and straightforward concept. It’s used to summarise all the transaction data so it can be put into a block at only 32 bytes in size. This happens by hashing each transaction, then merging two hash values to be hashed again, until you reach the last hash value called the merkle root.</p><p>So instead of writing <em>1,2,3,4,5,6</em> on a paper, I just write <em>21</em> (simplistic, I know). And going back to my earlier point of immutability, if I change any transactions, the entire merkle root hash value will be different, and we’ll know if the transaction has been tampered with.</p></li></ul><h3 id="h-all-hail-sha-256" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">ALL HAIL SHA-256</h3><p>Yep, if there’s one key takeaway you take from this blog, is that you’ll most likely be getting scammed left and right if SHA did not exist,</p>]]></content:encoded>
            <author>julian-6@newsletter.paragraph.com (Julian)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/df1aa4e479dfeead6b42e9e8eb17cbec02d24434e3efc575592c369913f8d57a.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Crypto Wallet vs Your Other Stuff [Web3 Analogies]]]></title>
            <link>https://paragraph.com/@julian-6/crypto-wallet-vs-your-other-stuff-web3-analogies</link>
            <guid>SBdsB9KN0G62znaXeVJ5</guid>
            <pubDate>Mon, 04 Apr 2022 15:44:43 GMT</pubDate>
            <description><![CDATA[Let’s talk money. Or rather, a thing to keep your money in. If you’ve dipped your toes even slightly in the web3 space, you’ve probably heard the term ‘wallet’ floating around, maybe even heard about metamask. It’s most likely the very first thing you need if you’d like to participate in the DeFi space. But what is it really? What’s self-custody (non-custodial) anyway? As per the cambridge dictionary, ‘custody’ means the legal right or duty to care for someone or something. ‘Self’ basically m...]]></description>
            <content:encoded><![CDATA[<p>Let’s talk money.</p><p>Or rather, a thing to keep your money in.</p><p>If you’ve dipped your toes even slightly in the web3 space, you’ve probably heard the term ‘wallet’ floating around, maybe even heard about metamask. It’s most likely the very first thing you need if you’d like to participate in the DeFi space.</p><p>But what is it really? What’s self-custody (non-custodial) anyway?</p><p>As per the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://dictionary.cambridge.org/dictionary/english/custody">cambridge dictionary</a>, ‘custody’ means the legal right or duty to care for someone or something. ‘Self’ basically means you and I. So, self-custody wallets would mean <strong>a wallet that only us ourselves are responsible for.</strong></p><p>Okay… So? Let me answer the so what by drawing some parallels with how you currently keep your money (think: physical wallets, e-wallets, bank accounts, and maybe even hosted wallets), then pointing out some differences. Here goes!</p><p><strong>THE PARALLELS</strong></p><ul><li><p>Similar to our physical wallets, the <strong>money in a crypto wallet is really yours</strong>. Unless, we lose it, or in crypto’s case, lose our “private key” or “seed phrase”. (We’ll how this is important under differences)</p></li><li><p>We also <strong>control access to the money</strong> in our crypto wallet, just like our physical wallets. Technically, nobody would be able to steal money from our physical or crypto wallets, unless we give them permission to, or if they take it by force. <strong>We are responsible for our own wallet.</strong></p></li><li><p>We can <strong>send (buy) and receive money to and from other people or platforms</strong> just with our crypto’s wallet address, same as how we can scan duitnow QR codes with our e-wallets and transfer money using online banking.</p></li></ul><p>So at its core, crypto wallet seems to be able to do what a typical wallet can - store, send, and receive money.</p><p><strong>THE DIFFERENCES</strong></p><ul><li><p>Do we really have access to our own money? - Back to the first point, the possibility may be small, but if our banks go bankrupt/collapse/robbed, we can only get back up to RM250,000 per bank <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://asklegal.my/p/what-happens-if-a-malaysian-bank-gets-robbed-and-you-bank-with-them">thanks to PIDM</a> in Malaysia. And this was only implemented in 2011, so if you had your money in <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.afr.com/politics/malaysia-takes-over-2-finance-firms-to-prevent-collapse-19990105-k8k45">MBf Finance back in 1999</a>, you would probably be stressing out. Banks can also <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.ft.com/content/8fba7cac-83b3-4df3-a1a7-5b6869516085">freeze your account</a> without warning or explanation (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.freemalaysiatoday.com/category/nation/2022/04/08/650-customers-file-rm650mil-class-action-suit-against-cimb/">have fun unfreezing it!</a>), with the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.freemalaysiatoday.com/category/nation/2022/04/08/650-customers-file-rm650mil-class-action-suit-against-cimb/">latest debacle</a> being with our favourite red octopus - CIMB.</p><p>Having a <strong>hosted wallet</strong>, such as Luno, Binance, and Kucoin, is also largely <strong>similar to having a bank account.</strong></p><p>You’re probably asking, what if Metamask shuts down? Do they have control over your money? Short answer: no. <strong>Metamask is just a way for you to interact with your account,</strong> which lives on the Ethereum blockchain. Metamask is not your account, nor does it control it. If they do decide to shut down, there are ways you can regain your money! <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://finance.yahoo.com/news/metamask-stopped-working-country-223141615.html">(More info here)</a></p></li><li><p>Data data data - imagine the amount of data your e-wallet providers and banks are getting from you. They now not only know how much you spend, but how you spend it. <strong>They own our data.</strong> Our trust is on them to remain ethical and keep our data safe.</p><p>Crypto wallets <strong>do not control any of our personal or private data</strong>, or sell those data to third parties. They don’t even do e-KYCs. Though, do note that data such as transaction history and assets in the wallet are <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://newsletter.thedefiant.io/p/for-all-you-degens-farming-in-public?s=r">publicly available on the blockchain</a>. But it’s getting better! If you really want to be anonymous, explore solutions such as <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://tornado.cash/">Tornado Cash</a>, VPNs, and <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://brave.com/">Brave Browser</a>.</p></li><li><p>Borders no more - ever tried transferring money overseas or use an international platform? There’s just so many layers and processes. Try opening an <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.interactivebrokers.com/en/home.php">Interactive Brokers</a> account as a Malaysian to see what I mean.</p><p>With crypto wallets, you can send your money to any account and use any platform <strong>anywhere in the world</strong>! Sure, there may be high gas fees and relatively long processing time, but this depends on the chain and network you’re using. Plus, we’ll definitely see tremendous improvements in the coming months.</p></li></ul><p>That’s it! There are a few obvious reasons why crypto wallets may be better than what we have now. But this is not saying that we should transition fully into crypto wallets.</p><p>Sometimes, it’s just easier to leave it with a third party. Aside from the lack of crypto-readiness, with crypto wallets, you don’t get interest on your funds automatically debited into your account, there’s little to no support if you need help, and it won’t be a one-stop center for all your needs.</p><p>Ultimately, it depends on what you need or what you value more. But I hope this blog helped your understanding of ‘crypto wallets’!</p>]]></content:encoded>
            <author>julian-6@newsletter.paragraph.com (Julian)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/526e96ae522f39258e21c9b2c71f81c46a055ae54416056aa2f2d4668cb6e569.jpg" length="0" type="image/jpg"/>
        </item>
    </channel>
</rss>