4 ms·
Put a non-trivial amount of btc in a wallet with a moderately secure password. Oh you'd rather not? It will be swept up almost instantly by any of a myriad of w
by canoebuilder 9y ago
Put a non-trivial amount of btc in a wallet with a moderately secure password. Oh you'd rather not? It will be swept up almost instantly by any of a myriad of wallet cracking programs running 24/7 for just that purpose.
I think nodesocket's point was that to expect the run of the mill computer user, who barely understands what a browser is, to have the security chops to withstand constant attacks from people who not only know what a browser is, but have also devoted substantial time to understanding as many exploits to the crypto-currency systems as they can and who have monetary incentive to continue refining that understanding in pursuit of most likely consequence free(apart from their soul) illicit monetary gains, to look at the dynamics at play here, it is not a stretch to assume that expecting widespread adoption in any form is likely to be a losing proposition.
What does "decentralizing security" mean? Everyone with any currency to protect will have to implement the digital equivalent of 36 inch fortified walls? Why would they want to do that when most people are satisfied with outsourcing this to service providers who specialize in such things?
For some scenarios there is a case to be made for "user defined security" or some-such, possibly even a few legitimate ones that aren't socially hostile. But it's hard to make any convincing case(without using any "semantic sugar," "empty calorie" buzzword-laden phrases like "decentralizing security") against nodesocket's point that the lay of the land of crypto-currency seems hopelessly tilted towards those who would like to exploit it in these ways.
- benchaney 9y ago> Put a non-trivial amount of btc in a wallet with a moderately secure password. Oh you'd rather not? It will be swept up almost instantly by any of a myriad of wallet cracking programs running 24/7 for just that purpose. Most people refuse to invest in Bitcoin because of the possibility of a crash, so this is a completely pointless challenge.
- canoebuilder 9y agoNot sure the point your meaning to make. I was simply explaining that many crypto-currency systems are demonstrably more adversarial and user-hostile environments than most other currencies. Not only are they more adversarial, they are more adversarial in a way that most computer users aren't equipped to comprehend.
- sowbug 9y agoAre "hostile" and "adversarial" the right words for the point you're trying to make? Cryptocurrencies are powerful, and they offer no recourse in case of user error. You might say the same of a chainsaw or a nail gun, but nobody would call them "hostile" or "adversarial."
- canoebuilder 9y agoYeah but when you're using a chainsaw there is no one who is attempting to weight the machine in a certain direction potentially putting you in danger. And there is no one with an incentive to do so.
- mrb 9y ago«the run of the mill computer user, who barely understands what a browser is, to have the security chops to withstand constant attacks from people» That's why we invented hardware wallets, which physically separate coins from the computer. You don't need to be tech savvy to use one. And to date, there hasn't been a single case of bitcoins stolen from a hardware wallet.
- bm1362 9y agoIs there a good overview of the types of wallets, their architecture and evolution? As someone trying to get into blockchain stuff, this is kinda wild. Also, what exactly is a wallet? If the coins are really just outputs in a hashed block how do you 'access' them?
- klipt 9y agoRoughly, a wallet is a public/private key pair. You use the public key to receive money, and the private key to send money. If anyone hacks your private key, they can take all your money.
- nikcub 9y ago> Is there a good overview of the types of wallets, their architecture and evolution? A wallet is a userland abstraction where it groups together all of your keypairs. With each keypair (ECDSA) you have a public and private key. The address is derived from a hash and encoding of the public key. The private key is used to sign a script that unlocks the transaction outputs you have access to. For this reason, your balance is also a userland abstraction. A balance is the sum of all the outputs you have the ability to unlock by signing the input. Whats important to understand about transactions is that you need to spend the entire input. If you have 10 coin sitting in an output and want to send 7 to someone, you need to structure the transaction so that the 3 change goes back to you as well The way fees work is that the miner picks up any difference between the outputs and the input, for ex. 10 input => output 1 = 7btc to address1 (recipient) => output 2 = 2.9btc to address2 (change) => diff 0.1 btc transaction fee You now have a balance of 0 in your input address, and you're left with 2.9btc in your change address which will become the input on your next transaction There is no reason why the change address cannot be the same as the input, but it means a loss of privacy since you can then see the 2.9 btc was change, thus output1 was the recipient, and you link the future transaction back to yourself as well. If you then want to send 11 coin to someone, you can combine other inputs: 2.9btc input => output 1 = 11btc to address3 (recipient) 10btc input => output 2 = 1.89btc to address4 (change) => diff 0.1 btc transaction fee This is how wallet identification works as described in the OP - you can assume that any inputs shared in a transaction are from the same owner since they were signed together. If you parse the blockchain and continue grouping common inputs like that you end up with a graph of wallets. Sometimes it only requires a single transaction to group together entire clusters - especially if you're using wallet software that selects inputs to use in sequence, doesn't create change correctly, or if you sweep all your smaller and smaller inputs into an aggregate address What the original wallets did, and what OP explains, is they would pre-generate the next 100 keypairs and add them to the end of the list, and with each transaction that requires change it would move the pointer for next change address up one All of your addresses start as either receive addresses, or as change addresses, and end up becoming your balance addresses until they are spent To backup these wallets you had to backup every key pair, which is why most modern wallets use deterministic keys usually derived from a mneumonic. HD wallets use a master key pair, where the private key is usually derived from a mneumonic. That key pair is then used to generate the key chains that are used as receive and change addresses. It means you only need to backup your master keypair or your master mnemonic and can then generate and check all the key chains The new wallet format is defined in bip32 [0] while the mnemonic to generate seeds is defined in bip39[1] - which you can test using a browser client app[2] (don't store coin using these - generate them securely) Most wallets now support these deterministic wallets, including bitcoin core The three main wallet types are full node, thin node (SPV) or web wallet You can run a full node with Bitcoin Core[3] or Bcoin[4] (a Javascript implementation) - both support pruning the blockchain at a specified block height The most popular SPV clients are Electrum[5] cross-platform, breadwallet for ios/android[6]. SPV uses block headers and peer queries (sometimes using bloom filters for privacy) to query your unspent transaction outputs and to verify transactions (there are variations of the architecture). The bcoin project also allows you to run an SPV client in the browser or via node (i'm really starting to like this project - they were the first to implement p2p authentication and encryption which is specified in bip150/bip151) Electrum supports Trezor and hardware wallets, multisig wallets, 2FA wallets and have their own mnumonic and deterministic wallet format (but it also just involves saving a seed for the master key) Web wallets store your wallet (usually) encrypted on their server and then unpack and decrypt in your browser client, then making HTTP API queries to verify transactions, get your unspents, broadcast transactions etc. The most popular are Blockchain.info[7] (disclaimer: I worked for them) and GreenAddress[8] - you can use blockchain.info via a tor hidden service at blockchainbdgpzk.onion Good ways of getting started if you're more interested in the tech is Electrum (web wallets tend to obfusacte a lot of what is going on to make them easy to use), a full node with Bitcoin Core or running bcoin - and running them on testnet so you can build and broadcast your own transactions without fear of losing funds (the scripting language has also evolved a lot). The other Javascript lib you can use to create transactions is bitcoinjs-lib[9] - there are libs available for deterministic wallets and some good transaction/script abstractions. [0] https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki https://github.com/bitcoin/bips/blob/master/bip-0032.mediawi... [1] https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki https://github.com/bitcoin/bips/blob/master/bip-0039.mediawi... [2] https://iancoleman.github.io/bip39/ https://iancoleman.github.io/bip39/ [3] https://bitcoincore.org/ https://bitcoincore.org/ [4] https://github.com/bcoin-org/bcoin https://github.com/bcoin-org/bcoin [5] https://electrum.org/ https://electrum.org/ [6] https://breadwallet.com/ https://breadwallet.com/ [7] https://blockchain.info/wallet/#/home https://blockchain.info/wallet/#/home [8] https://greenaddress.it/en/ https://greenaddress.it/en/ [9] https://github.com/bitcoinjs/bitcoinjs-lib https://github.com/bitcoinjs/bitcoinjs-lib
- sowbug 9y agoUnless you're exaggerating to make a point, you should qualify your challenge to indicate that you're talking about old-school "brain wallets" that nobody uses anymore. Every modern wallet app uses BIP32/BIP44/BIP39 standards that guarantee a minimum of 128 bits of good entropy. Yes, people will still refuse to back up their wallets by writing down the 12- or 24-word seed phrase, and others will get phished. They'll lose their funds, just as they already do with their Steam and eBay accounts. Your point is valid that Bitcoin allows a tremendous amount of control that many people will use first and foremost to shoot off their own limbs. But brain-wallet crackers are no longer a threat.
- canoebuilder 9y agoGood info, thanks.
- knocte 9y agoYour answer to my comment also seems to forget what cold storage is. With cold storage, you can forget about zero-days and whatnot. It's the way to go for mass adoption (we just need to make it more user friendly).
- wu-ikkyu 9y ago>Yes, people will still refuse to back up their wallets by writing down the 12- or 24-word seed phrase Stupid question here, but what is wrong with doing that?
- sowbug 9y agoThat seed phrase is the entire secret key making up a deterministic wallet (HD wallets, BIP32, are pretty much the only kind of consumer Bitcoin wallet today). If you don't write it down, and your phone dies or you lose it, then all your money is gone forever. In case that's an insufficient answer, here's the mechanism: Bitcoin addresses are (usually) based on ECDSA public keys. When you send Bitcoin to someone, you're saying "send this to whoever can sign for the following public key [XYZ]. Signed, [ABC]." You had private key [abc] for [ABC], and you got the bitcoin you sent from someone else who said "send this to whoever can sign for the following public key [ABC]. Signed, [MNO]." ("said" means published to the global blockchain ledger.) Back in the bad old days, the Bitcoin app would generate a new private/public key pair for every address. This meant that if you didn't back up wallet.dat frequently, you were screwed because your old backup might have only the old keys in it, not the new ones since the last backup. The BIP32 scheme works kind of like this (simplified): 24 words -> 256-bit secret, called [defghi]. To generate a new address, take [defghi] and add a path to it, like "44/0/0/1" and then do a cryptographic hash on it, creating a new secret: [defghi-44/0/0/1] -> [jklm] Then [jklm] becomes one of the private keys in your wallet. Next time you need another key, use "44/0/0/2," "44/0/0/3," etc. So what's nice about this is that the 24 words are the only thing you need to reconstruct your whole wallet. You no longer have to keep on backing up your Bitcoin wallet except for the very very very first time when you first create it. But if you don't write down that list of words, and something happens to your phone/PC, goodbye bitcoin.