5 ms·
What does this mean? (Not all of us know a whole lot about how crypto works or why this is good or bad and what it means for our investments)
by aetherspawn 8y ago
What does this mean?
(Not all of us know a whole lot about how crypto works or why this is good or bad and what it means for our investments)
- analyst74 8y ago51% attack means someone (or a group of people) has successfully taken over the said blockchain.
- bonyt 8y agoIn this kind of blockchain network, the longest chain of blocks is considered to be the valid one. However, someone that has 51% of the hashing power (i.e. more hashing power than everyone else combined) can create a chain that grows faster than the chain used by everyone else. This means that they could tamper with their chain, potentially rewriting history on it, and because it is the longest chain, it will be accepted as the valid chain, and their version of events looks like it has been accepted.
- orblivion 8y agoBeing only somewhat familiar, I wonder this: Why don't clients have a simple rule against accepting changes to history that are more than one or two blocks old?
- wmf 8y agoThose rules can cause breakage under normal usage because the probability of an N-deep reorganization is low but nonzero. They also don't help nodes that are syncing the chain from scratch.
- leevlad 8y agoBecause it's an eventually consistent system. If what you proposed was implemented, you could end up with a fork that would never get reconciled.
- makomk 8y agoIn short, because they don't know that the chain they saw first is the chain that other nodes saw first (especially if they weren't online at the time). At least in theory, an attacker can exploit this to permanently fork the chain.
- orblivion 8y agoHmm. The humans at the exchanges seem to be able to tell the difference. I wonder if it could be encoded.
- AgentME 8y agoThe "legitimate" fork can only be identified if you were online when the 51% attack started. Users who have started up their ETC client after the attack started will just see two forks and will pick the one with more blocks (which will be the 51% attacker's fork). No one wants a permanent fork, so the clients that were online the whole time disregard their knowledge of the previous "legitimate" fork and adopt the attacker's fork because it has more work and because that's the one everyone else is using. Also, if you have clients follow the rule "never switch forks" to protect against 51% attacks, then any network partitions will cause a permanent fork.
- leevlad 8y agoI don't think that's feasible, to be honest. I'd imagine that you would want to look for evidence of a double spend as that's the most likely goal of a 51% attack. But then the blockchain must have up-to-date knowledge of likely double spend targets (such as exchanges, OTC desks, etc), and be able to algorithmically and deterministically prove malicious intent with high certainty. Only then will you be able to maintain consensus and prevent unnecessary or accidental forks. But since this is all open-source anyway, it would only be a matter of time before a slightly more sophisticated attacker read through the updated consensus algorithm and figured out how to game it. And so the cycle continues. In truth, the only real strategy for mitigating attacks in PoW blockchains is hash power. It has proven to be very effective if you have enough of it (see BTC), and looking for other 51% resistance measures isn't really that productive unless you start from the ground up and rebuild the consensus mechanism on a different paradigm (e.g. PoS, which is still unproven afaik).
- CydeWeys 8y agoBecause then a simple accidental network partition could cause a permanent fork in the cryptocurrency.
- pryce 8y agoOther people have answered this from a more technical perspective. Philosophically, what the distributed blockchain is, is an agreement for adjudicating whose record (eg list of transactions) should be agreed on as "the valid one". If you already have a different, reliable external way of deciding this question, that is (arguably) conceding that you didn't need a distributed blockchain in the first place. EDIT: I've realised my comment could be misinterpreted as endorsing the blockchain 'movement'. I am among those who are quite skeptical of these many blockchain projects.
- orblivion 8y agoWhat I described would be part of the rules of system (or at least certain players). It just says "no changing history after X point". If anything, relying on an outside source is what we're doing now. Coinbase and others are telling us that they detected something and I haven't heard anybody question them. (And I'm assuming they're not lying). Though that's not to say the blockchain will be changed by this information.
- pryce 8y ago> If anything, relying on an outside source is what we're doing now. You are correct of course. To me, problems like this recent attack highlight an inherent contradiction in the blockchain idea - that the "51%+ of hashing power determines the truth" rule is really either lip-service; techno-marketing vanity that doesn't actually translate to practice (if corrective action ensues), and in which case the adjudicator is clearly not the blockchain tech we were told, but instead a nebulous collection of companies and stakeholders OR - that "51% determines the truth" is indeed a strictly-held principle even though we have already demonstrated that there exist actors with enough resources and motivation to make attacks of this nature on some of the most prominent blockchain projects already - and we haven't even yet witnessed what a 51% attempt by an actor with the resources of a state would look like. This is one of the reasons I have become skeptical of blockchain projects.
- hinkley 8y ago> I am among those who are quite skeptical of these many blockchain projects. There's always dilution when an idea has been around long enough and I'm concerned about the copycats trying to use blockchain for other things. If Raft is democracy, then blockchain is Might Makes Right. The guy with the biggest stick always wins. There is no actual vote. Everybody is an accomplice. That doesn't sound like progress, that sounds like regression. A really big one.
- stale2002 8y agoSome clients do have this rule, actually! It is a pretty interesting solution, that seems to work out OK. For example, most Bitcoin cash clients don't accept reorgs longer than 10 blocks, as such a reorg is 100% an attack. This protects the network against large reorgs.
- eloisant 8y agoBecause crypto-currencies are validating transactions by having them validated by the network as a whole, a group who controls more than 50% of the computing power can do whatever they want: reject valid transaction, create (and validate) fake transactions...
- gus_massa 8y agoYou can't create fake transactions[1]. You can reject some valid transactions or reject all transactions freezing the network for some time, and also try to double spend your money. [1] The idea is that the miner just pick the last block and select a bunch of the current transactions and a random number and makes a hash of all of them. If the hash has enough zeros at the beginning then it is a new block and it is distributed to all the network. The other nodes of the network validate all the transactions and also that this bunch of transactions with this random number produce a hash that has enough zeros at the beginning. Any invalid transaction of a wrong random number make all the other nodes of the network ignore the fake block. Once the last block and the bunch of transactions are picked, the difficult part is selecting a random number that with them produces a has that has enough zeros at the beginning. So the mines must try, try, and retry with different random numbers until they are lucky (or someone else is lucky). They must try millions of millions of millions (gillons?) of times, because it's difficult to pick the correct one. This uses a lot of electricity to power the computer. The other people just validate with the lucky number, so it's much cheaper.
- wmf 8y agoThe attacker rewrote part of the blockchain which was supposed to be immutable. Generally this allows spending the same money twice.
- DyslexicAtheist 8y ago51% attack: https://www.investopedia.com/terms/1/51-attack.asp https://www.investopedia.com/terms/1/51-attack.asp I can't comment on investment. Note Ethereum has always been over-hyped which (imvho) makes it useless for any serious engineering. see https://news.ycombinator.com/item?id=18780489 https://news.ycombinator.com/item?id=18780489
- pietjepuk88 8y agoThe most typical way to profit from this, is to have quite a bit of ETC, and then sell it on an exchange or buy something expensive. This transaction would then end up on the block chain, and eventually be considered secure / part of history. Privately, you are building a chain where said transaction did _not_ occur. Because your hash rate is high enough, you are generating blocks at at least the pace of the public chain. You keep mining your chain (without your transaction) privately until the bank transfer from the exchange goes through, or you are sure whatever you bought is on its way. Then you broadcast your private chain as soon as it has at least one block more than the public chain and voila, you have your ETC back and the USD/EUR/crypto you sold it for (or the product you bought). You can have your cake and eat it too. This is because the rule of most cryptocurrencies is that the longest chain is the truth, and everyone mines on top of the longest chain. If a longer chain appears out of nowhere, all miners will jump on top of this one. There is no such thing as "finality" in most cryptocurrencies, where something becomes actually (read: much more) irreversible. Of course, doing this only makes sense if what you gain outweighs the costs of performing such an attack. Note that you typically _cannot_ steal coins from specific wallets, as you do not have the keys to those coins. You can however censor transactions that you may not want, but the above is a common way to benefit from a 51% attack.
- naveen99 8y agoso to be safe, an exchange should require more confirmations depending on size of deposit. Basically the number of confirmations you could finance an attack for with the deposit.
- Klathmon 8y agoYes, and most do. Many will semi-routinely increase the number of confirmations during times where it could be necessary (like chain splits or network upgrade events), or adjust the number of confirmations depending on the size of the currency and overall usage. Another mitigation is to shut down trading until the attack is over. Maintaining a 51% attack is expensive (assuming there is at least SOME usage of the coin), and if you just say "we won't be doing business for the next 24 hours", the attacker now has to maintain that attack for the next 24 hours, and if the company wants, they can just extend the time. Eventually (hopefully!) the attacker will run out of money, and the "correct" chain will take it over again.
- xbkingx 8y ago(This is a very basic run down of what I understand to occur. There are places where I omit steps and oversimplify, but I THINK it's pretty accurate. Someone please correct me if I'm wrong.) Mining is basically the way that everyone agrees a transaction is valid - you have a bunch of unrelated entities saying, "Yes, according to my copy of the ledger, the sending party has X dollars and wants to send Y dollars, and the two parties agreed." (It's much more nuanced, but this is the easiest way to summarize it.) If someone said, "I'm going to send AccountB 100ETC from AccountA," but AccountA only had 50ETC then a miner would see that and deny the transaction (wouldn't add it as a valid block to the blockchain). In reality, there are several places that the transaction should be thrown out, but there are obvious ways around those, and every transaction incurs a fee, so trying to just flood the network is costly. More importantly, several miners have to agree that the transaction is valid. When sending bitcoin, you'll see a number of "confirmations," which is the number of miners that marked the transaction as valid. You can see this when sending coins between two exchanges, you'll see that the receiving exchange won't allow you to use the coins for trading until you hit, say, 30 confirmations. The problem with this model for smaller projects is that those "confirmations" by unrelated miners can't be trusted if one person/group owns more than half the miners. I left out the idea of wallets/nodes to bring this up here. Every "full" wallet (or node) has a copy of the blockchain and does some cursory checks on transactions before broadcasting them to the network. Miners then package a bunch of transactions in a block and send this to the network - "Here is my version of block X. It should be added to the blockchain as block X for everyone." The miners then have to expend some effort to verify that the block is actually the block they think it is and contains valid transactions. When the miners confirm a block, it eventually propagates to all the miners and nodes, and competing blocks by other miners, which might have contained some of the same transactions are discarded. It doesn't mean the other blocks were fake, just that the chosen block reached "consensus" of the miners and can be trusted to be valid. (I realize this leaves lots of open questions, but I'm limiting the scope to OP's question.) Consensus is the big problem in 51% attacks. If someone controls more than half the mining power, they can reach consensus on blocks faster than legit miners and add whatever they want to the blockchain that is distributed to all the other miners and nodes. That means they can add/delete transactions or manipulate existing ones to, say, change the receiving address to their own, and everyone that receives those blocks will accept the outcome. This is why decentralization is so important to cryptocurrency. There's a level of necessary chaos that keeps the network honest. It is possible to roll back the blockchain to a previous version, but that also means that transactions in all blocks that followed must be rolled back as well. If the rogue party simply accumulated currency, that's not a big deal, since all other transactions would still be valid. But, if they immediately turned around and traded them for other coins, you start to see the problem. On top of that, if ETC was more "robust", the news would (and currently is) send the price into a nosedive, which creates an opportunity to legitimately buy it very low and profit from the recovery. That's not going to be the case here. All this being said, Ethereum Classic was kinda declared dead a month ago when the development group halted operations, so anyone with any significant amount of ETC should have sold off by now. This attack will probably be the final nail in the coffin. TL;DR - In the end, the state of the blockchain comes down to a simple majority of miners agreeing that a block (a group of transactions) is valid. At 51%, you can force everyone to see invalid transactions as valid. ETC development ceased around a month ago, so no one that follows it should be holding any now, but people blindly trading for profit will get a nasty surprise.