4 ms·
Some alternative cryptocurrencies were created using memory-hard hash functions. Litecoin uses scrypt, for example.
by championcake 10y ago
Some alternative cryptocurrencies were created using memory-hard hash functions. Litecoin uses scrypt, for example.
- cperciva 10y agoNo it doesn't. Litecoin uses a variant of scrypt which has been deliberately nerfed by limiting its memory usage.
- warbiscuit 10y agoI agree, but it's actually hard not to nerf scrypt, since it's time-cost and memory-cost are tied together. I'm not sure if they could have increased the memory cost sufficiently for their purposes, without making the time cost prohibitively high. That's one of the things argon2 (https://github.com/P-H-C/phc-winner-argon2 https://github.com/P-H-C/phc-winner-argon2) is trying to fix, though I don't think any cryptocurrencies are using it yet (which is reasonable, it's just too young)
- bqe 10y agoThis paper also describes an attack on Argon2, which lowers the amount of memory required by an attacker.
- tromp 10y agoInstead of "deliberately", you might as well say "necessarily". As I argue in [1], "in order to keep verification cheap, hash functions in Hashcash must restrict their resource usage as well. That’s why scrypt is configured to use only 128KB of memory." To achieve ASIC-resistance, one should avoid Hashcash in favor of asymmetric proof of work systems, where proof attempts can take huge amounts of memory even while verification is instant and memory less. [1] http://cryptorials.io/beyond-hashcash-proof-work-theres-mining-hashing/ http://cryptorials.io/beyond-hashcash-proof-work-theres-mini...
- cperciva 10y agoRight. Cryptocoins' need for cheap verification of proofs-of-work is precisely opposed to KDFs' need for expensive checking of candidate passwords.
- Dylan16807 10y agoI think they overcorrected. They want it to run on a phone, fine, but a phone app can easily dedicate 100MB of ram to verifying blocks.