8 ms·
With this "blockchain revolution" hype, I've been waiting for these 51% attacks. Maybe people will realize that this is not a foolproof solution and that it can
by bleuarff 10y ago
With this "blockchain revolution" hype, I've been waiting for these 51% attacks. Maybe people will realize that this is not a foolproof solution and that it can "easily" (you only need computing power, a.k.a money) be beaten.
- heliumcraft 10y agogood luck getting the computer power to do a 51% on Bitcoin or Ethereum. The hashpower used in Bitcoin is mind-boggling.
- iopq 10y agoThis is why Bitcoin is going to win - it is good enough for a lot of use cases and getting better. At the same time, it's the most widely accepted and the most secure. The network effect is too strong to overcome unless you offer something Bitcoin cannot.
- bleuarff 10y agoThis has happened in the past, see http://arstechnica.com/security/2014/06/after-reaching-51-network-power-bitcoin-mining-pool-says-trust-us/ http://arstechnica.com/security/2014/06/after-reaching-51-ne... . I agree the required power must have grown since 2014. But not knowing by which factor, one can only assume it's still feasible. I can't find any source for it, but I remember reading not so long ago that 2 or 3 mining pools were responsible for 2/3 of the total bitcoin mining power. That's not something in favor of trusting the blockain as infallible.
- heliumcraft 10y agoit has increased by a factor of ~153x https://blockchain.info/charts/hash-rate?timespan=all https://blockchain.info/charts/hash-rate?timespan=all 2014 -> 10,436 TH/s 2016 -> 1,536,337 TH/s
- bleuarff 10y agoThe attack was in june, when it was ~ 100K TH/s rather than 10K. The factor becomes ~15x instead of 150x. But I must admit I don't know if that makes such an attack still feasible.
- tveita 10y agoYou only need to spend as much as the miners already are doing. With proof of work, if it is feasible to run, it is feasible to attack. And vice versa, if it is not feasible to attack, it is probably not cost effective to run. Bitcoin may be wasting enough electricity to put it out of reach of small-time attackers, but a nation adversary could outspend it for as long as necessary.
- smokeyj 10y agoBut what does the attack get you? Sure you could mine empty blocks and double spend, but that would hardly be worth the investment. Besides, if payment processors detect the hashing rate doubling overnight they can simply require more confirmations. If a nation state invested in permanently disabling bitcoin that would require a big investment in ASIC's, at which point I imagine a bitcoin fork would be introduced with a slightly different PoW, but that's just speculation.
- tveita 10y ago> a bitcoin fork would be introduced with a slightly different PoW And then what? Either you're falling back to mining on CPUs or GPUs, which the attacker would presumably have a large amount of, or you're manufacturing a new batch of ASICs, which is just as expensive for you as for an attacker. The point remains that an attacker can win by spending only slightly more money than the defender. Whether that's "worth the investment" is up to each individual actor, apparently it hasn't been yet.
- jerf 10y ago"The point remains that an attacker can win by spending only slightly more money than the defender." It's actually only slightly more than the sum of the defenders (assuming as we are for the sake of argument that everyone is buying efficiently). If what you said was true BitCoin wouldn't even have gotten to where it is now.
- CoryG89 10y agoThis is not a real concern once the hashing power of the network reaches a sufficiently high level. > Maybe people will realize that this is not a foolproof solution and that it can "easily" (you only need computing power, a.k.a money) be beaten. This same argument can be leveled against just about any form of cryptography. With enough computing power you can decrypt anything. No cryptography is perfect, it can only be strong.
- Nursie 10y agoEh, no. Enough computing power in this case (even in the case of bitcoin) is significantly less than the amount of computing power that exists today. For a lot of crypto the amount is magnitudes larger, and working for thousands (or millions) of years to break it. I agree that the 51% attack is unlikely on BTC now, but it doesn't bear comparison to (for instance) brute forcing an AES-GCM message...
- CoryG89 10y agoI agree that currently it may not be the same as brute forcing something like an AES-GCM, but that isn't my point. My point is just that, if you have a blockchain with sufficiently high (and distributed) hash power (relative to the amount of computing power any individual actor/group can obtain), then in theory, you start being able to make strong guarantees about consensus.
- bleuarff 10y agoI agree in principles, but there's a difference. A system able to break a strong encryption could cost more than the world GDP and is not reallistically feasible, while owning 51% of bitcoin power is possible - not cheap, but possible.
- CoryG89 10y agoRight, I agree. The theory is sound though. Theoretically, there could be a quantum computing breakthrough (however unlikely) which would break some traditional crypto which was previously deemed impossible. It is the same with blockchains. It is just that there isn't one that exists (yet) which has enough distributed hash power where it's infeasible for any actor/group to ever get 51%. Bitcoin is just the best example so far, some might argue it's still in its early stages, or that another blockchains will surpass it.