Crypto

Credible Neutrality As A Guiding Principle

Vitalik Buterin speaking on stage

Consider the following examples:

People sometimes object when governments spend 5% of GDP supporting particular public initiatives or selected industries. Yet those same people often express little concern when the very same government produces much larger shifts in capital allocation through the enforcement of property rights.

People sometimes criticize blockchain projects for directly assigning, or “premining”, a large number of coins to recipients personally selected by the developers. Yet those same critics may have no objection to major blockchains such as Bitcoin and Ethereum issuing billions of dollars in value to proof of work miners.

People sometimes become angry when social media platforms censor or reduce the visibility of content associated with certain politically unpopular ideologies, including ideologies that the critics themselves oppose. Yet those same people may not object when ride-sharing platforms remove drivers whose ratings fall below a required level.

One possible response to these examples is to shout “gotcha!”, enjoy the apparent contradiction, and declare that a hypocrite has been exposed. In some cases, this reaction is entirely justified.

In my view, it is genuinely mistaken to describe carbon taxes as an act of statist interference while regarding government enforcement of property rights as nothing more than the protection of natural law. It is also genuinely mistaken to treat miners securing a blockchain as workers performing Real Thermodynamic Work that deserves compensation, while describing any attempt to compensate developers who improve the blockchain’s code as an act of “printing free money”.

However, even when attempts to organize our intuitions into a consistent system fail, strong moral intuitions of this kind are rarely completely meaningless. In this case, I would argue that an important principle lies beneath these reactions. This principle is likely to become increasingly central to discussions about how we should construct institutions that are effective, freedom-preserving, fair, and inclusive, while allowing them to influence and govern different areas of our lives.

The principle is the following: when we design mechanisms that determine high-stakes outcomes, it is extremely important that those mechanisms be credibly neutral.

Mechanisms are algorithms plus incentives

First, what exactly is a mechanism?

I use the word in roughly the same sense in which it appears in the game theory literature on mechanism design. A mechanism is, in essence, an algorithm combined with incentives.

A mechanism receives inputs from multiple participants and uses those inputs to learn something about their preferences or values. It then uses that information to make a decision that matters to the people involved.

In a mechanism that functions well, the resulting decision should be efficient. In other words, given the preferences of the participants, the mechanism should produce the best available outcome.

It should also be incentive-compatible. This means that participants should have a reason to engage with the mechanism “honestly”, rather than gaining an advantage by misrepresenting their preferences or behaving in ways that undermine the system.

Examples of mechanisms are not difficult to find. Here are several:

Private property and trade. The “inputs” consist of people’s ability to transfer ownership through trade or donation. The “output” is a database, sometimes formally recorded and sometimes only implicitly recognized, that determines who has the authority to decide how each physical object may be used. The purpose is to encourage the production of useful physical goods and place them in the hands of those who can use them most effectively.

Auctions. The inputs are the bids submitted by participants. The output determines who receives the item being sold and how much the winning buyer must pay.

Democracy. The inputs are votes. The output determines who gains control of each government position or legislative seat included in the election.

Upvotes, downvotes, likes, and retweets on social media. The inputs are users’ upvotes, downvotes, likes, and retweets. The output determines which people are shown which content. A game theory purist might argue that this qualifies only as an algorithm rather than a mechanism because it does not contain explicit built-in incentives. However, future versions may include such incentives, and earlier systems already experimented with similar ideas; see Slashdot meta-moderation.

Blockchain rewards based on proof of work or proof of stake. The inputs are the blocks and other messages created by participants. The output determines which chain the network recognizes as canonical. Rewards are then used to encourage participants to behave “correctly”.

We are moving into a highly networked, heavily intermediated, and rapidly changing information age. At the same time, public confidence in centralized institutions is declining, and people are increasingly searching for alternatives.

As a result, different kinds of mechanisms are likely to become more important in shaping how we interact. They offer ways to intelligently aggregate the wisdom of crowds while also separating that wisdom from the crowd’s equally persistent capacity for error.

What is credible neutrality?

We can now turn to the central idea: “credible neutrality”.

In simple terms, a mechanism is credibly neutral when a person can examine its design and easily recognize that it does not discriminate in favor of or against particular individuals.

Such a mechanism treats people fairly, at least to the extent that fairness is possible in a world where people differ greatly in their abilities, circumstances, and needs.

“Anyone who mines a block receives 2 ETH” is credibly neutral.

“Bob receives 1,000 coins because we know that he has written a large amount of code and believe that he deserves a reward” is not.

“Any post flagged as harmful by five people is no longer displayed” is credibly neutral.

“Any post that our moderation team concludes is prejudiced against people with blue eyes is no longer displayed” is not.

“The government grants a limited 20-year monopoly to any qualifying invention” is credibly neutral, although major difficulties remain at the boundaries when deciding which inventions qualify.

“The government determines that curing cancer is important and appoints a committee to distribute $1 billion among people working on cancer treatments” is not credibly neutral.

Naturally, no mechanism is completely neutral.

Block rewards favor people with the connections and resources needed to obtain specialized hardware and inexpensive electricity.

Capitalism favors wealthy participants and concentrated interests while disadvantaging poorer people and those who depend heavily on public goods.

Political discussion disadvantages ideas that fall on the wrong side of social desirability bias.

Any mechanism intended to correct coordination failures must make assumptions about what those failures are. It will therefore disadvantage people whose coordination problems are underestimated by the mechanism.

None of this changes the fact that some mechanisms are considerably more neutral than others.

This helps explain why private property works as effectively as it does. Its effectiveness does not come from being a right directly granted by God. It comes from the fact that private property is a credibly neutral mechanism capable of solving many social problems. It certainly does not solve all of them, but it solves a substantial number.

This also explains why filtering content according to popularity is generally considered more acceptable than filtering it according to political ideology.

It is easier for a diverse group of people to agree that a neutral popularity-based process treats everyone reasonably fairly than it is to persuade that same group that a particular blacklist of forbidden political opinions is correct.

The same reasoning explains why onchain rewards for developers are often viewed with greater suspicion than onchain rewards for miners.

It is easier to verify that someone is a miner than it is to verify that someone is a developer. In practice, most attempts to decide who should qualify as a developer can quickly become vulnerable to accusations of favoritism.

It is important to emphasize that neutrality alone is not sufficient. What matters is credible neutrality.

A mechanism must do more than avoid intentionally favoring particular people or outcomes. It must also be able to convince a large and diverse population that it is making a genuine effort to remain fair.

Blockchains, political institutions, and social media systems are all intended to support cooperation among large and diverse groups of people.

For a mechanism to function as a shared foundation for this type of cooperation, every participant must be able to see that the mechanism is fair.

In addition, every participant must be able to see that other participants can also recognize the mechanism as fair.

This matters because each participant wants confidence that everyone else will not abandon the mechanism the following day.

What is needed, therefore, resembles the game-theoretic concept of common knowledge. In less mathematical language, it is a broadly shared understanding of legitimacy.

To create this kind of common knowledge around neutrality, the mechanism’s neutrality must be extremely easy to recognize.

It should be so visible that even a person without extensive education can understand it, including in the presence of an aggressive propaganda campaign intended to portray the mechanism as biased and untrustworthy.

Building credibly neutral mechanisms

There are four main rules for constructing a credibly neutral mechanism:

  1. Do not include specific people or predetermined outcomes in the mechanism.
  2. Make the mechanism open source and its execution publicly verifiable.
  3. Keep the mechanism simple.
  4. Avoid changing the mechanism too frequently.

Rule (1) is straightforward.

Returning to the earlier examples, “Anyone who mines a block receives 2 ETH” is credibly neutral, while “Bob receives 1,000 coins” is not.

“Downvotes cause a post to be displayed less frequently” is credibly neutral.

“Prejudice against people with blue eyes causes a post to be displayed less frequently” is not.

“Bob” refers to a particular person.

“Prejudice against people with blue eyes” refers to a particular desired outcome.

Of course, Bob may truly be an excellent developer whose work was essential to the success of a blockchain project, and he may genuinely deserve compensation.

Likewise, prejudice against blue-eyed people is certainly not an idea that I, and hopefully you, would want to see become influential.

But the objective of credibly neutral mechanism design is to avoid writing those preferred results directly into the mechanism.

Instead, the mechanism should allow desirable outcomes to emerge from the actions of its participants.

In a free market, the fact that Charlie’s widgets are not useful while David’s widgets are useful is discovered through the price mechanism.

Eventually, consumers stop purchasing Charlie’s widgets, causing his business to fail.

David, meanwhile, earns a profit and gains the ability to expand production and manufacture even more widgets.

Most of the information contained in the output of a mechanism should come from participant inputs rather than from rules that have been hard-coded into the system itself.

Rule (2) is also relatively easy to understand.

The mechanism’s rules should be public, and members of the public should be able to verify that those rules are being executed correctly.

It is worth noting that in many circumstances, the inputs or outputs themselves should not be public.

This article explains why a very strong form of privacy, in which a person cannot prove how they participated even if they wish to do so, is often beneficial.

Fortunately, privacy and verifiability can be achieved at the same time through a combination of blockchains and zero-knowledge proofs; see here for further details.

Rule (3), the requirement of simplicity, is ironically the least simple of the four.

This post on “central planning as overfitting” develops many of the relevant arguments in greater depth, but the core idea can be summarized.

The simpler a mechanism is, and the fewer parameters it contains, the less opportunity there is to introduce hidden advantages or disadvantages for a selected group.

When a mechanism includes fifty parameters that interact in complicated ways, it is likely that parameters can be found to produce almost any desired result.

When a mechanism includes only one or two parameters, accomplishing this becomes much more difficult.

It may still be possible to favor broad categories such as “demagogues” or “the rich”, but it becomes harder to target a small and specific group of people.

The ability to target particular outcomes decreases further over time.

As more time passes, a stronger “veil of ignorance” develops between the designers at time A, when the mechanism is created, and the beneficiaries at time B, when the mechanism operates under specific conditions that may allow them to gain a disproportionate advantage.

This brings us to rule (4): the mechanism should not be changed too often.

Changing a mechanism is itself a form of complexity.

It also “resets the clock” on the veil of ignorance.

A change gives the designers another opportunity to adjust the mechanism in ways that benefit their current friends or harm their current enemies.

They can do so using the most recent information about the unique positions of those groups and about how different modifications would affect them.

Not just neutrality: efficacy also matters

A common error found in more extreme versions of the ideologies mentioned at the beginning of this post is a form of neutrality maximalism.

The argument can be summarized as follows: if something cannot be done with complete neutrality, it should not be done at all.

The problem is that this position achieves neutrality in a narrow sense by sacrificing neutrality in a broader sense.

For example, a system can guarantee that every miner is treated in the same way as every other miner, with each receiving 12.5 BTC or 2 ETH for every block.

It can also guarantee that every developer is treated in the same way as every other developer, with none receiving compensation beyond gratitude for performing a public service.

However, the result is that software development becomes dramatically under-incentivized relative to mining.

It is unlikely that the final 20% of miners contributes more to the success of a blockchain than its developers do.

Nevertheless, existing reward structures often appear to assume exactly that.

More broadly, societies need to produce many different categories of things.

These include private goods, public goods, accurate information, effective governance decisions, and goods that are not valued today but will become valuable in the future.

The list could continue much further.

Some of these things are easier to support through credibly neutral mechanisms than others.

If we adopt an uncompromising form of narrow neutrality purism and accept only mechanisms that are extremely credibly neutral, then only the problems for which such mechanisms are easy to design will be addressed.

The community’s remaining needs will receive no systematic support.

As a result, neutrality in the broader sense will suffer.

The principle of credible neutrality must therefore be supplemented by another principle: efficacy.

A good mechanism must actually solve the problem that matters to us.

This often means that even the designers of mechanisms that are clearly credibly neutral should remain open to criticism.

A mechanism can be both credibly neutral and extremely poor.

Patents, for example, are often claimed to fall into this category.

In some cases, this also means that when no credibly neutral mechanism has yet been discovered for solving an important problem, a mechanism with imperfect neutrality may need to be adopted temporarily.

Premines and development rewards that exist for a limited period in blockchain systems are one example.

Another example is the use of centralized methods to identify accounts representing unique humans and exclude others when decentralized methods are not yet available.

Even so, it remains important to recognize credible neutrality as something highly valuable and to continue moving toward that ideal over time.

When there is serious concern that an imperfectly neutral mechanism may lead to declining trust or political capture, it can be implemented using a “fail-safe” approach.

For example, developer funding can come from transaction fees rather than new issuance.

This creates a “Schelling fence” that limits the total amount of funding available.

A time limit can be introduced.

Alternatively, the mechanism may contain an “ice age” in which rewards gradually decline and must be explicitly renewed.

The mechanism may also be implemented within a “layer 2” system, such as a rollup or an eth2 execution environment.

Such a system may benefit from a degree of network-effect lock-in, while still allowing participants to abandon it through coordinated effort if the mechanism begins to behave badly.

When we anticipate that voice within a system may fail, we can reduce the associated danger by strengthening the freedom to exit.

Credibly neutral mechanisms capable of addressing many different problems already exist in theory, but they still need to be developed and improved in practice.

Examples include:

Prediction markets, such as electionbettingodds.com, which can serve as a “credibly neutral” source of probabilities regarding the likely winners of upcoming elections; see also Scott Alexander’s discussion of this topic.

Quadratic voting and quadratic funding as methods for reaching agreement on questions involving governance and public goods.

Harberger taxes as a potentially more efficient alternative to pure property rights for allocating non-fungible and illiquid assets; for example, see the thread on capped Harberger taxes for domain names.

Peer prediction, which provides a much more formal version of the “meta-moderation” system mentioned earlier.

Reputation systems based on transitive trust graphs.

We do not yet know which versions of these ideas, or which completely new ideas, will function effectively.

Many rounds of experimentation will be needed before we understand what kinds of rules produce good results in different environments.

A particularly important challenge will be keeping the mechanism’s rules open while also making the system resistant to attack.

Cryptographic developments that make it possible to combine open rules, verifiable execution, and verifiable outputs with private inputs may make some of these problems significantly easier.

In principle, we already know that robust systems of rules can be created.

As mentioned earlier, we have effectively succeeded in doing so in many cases.

However, as we become increasingly dependent on software-mediated marketplaces and platforms of many different forms, it becomes more important to ensure that these systems do not concentrate power in the hands of a small group.

That group could consist of the platform operators themselves, or it could consist of even more powerful actors that eventually capture those operators.

Instead, we should aim to construct credible systems of rules that everyone can reasonably support.

About the author

Vitalik Buterin conceived and co-founded Ethereum and wrote its original white paper.