4 ms·
So how would someone go about gaining more than 45k USD in profit from a single case of using the chosen-prefix collision? Not being candid here, I am honestly
by jVinc 7y ago
So how would someone go about gaining more than 45k USD in profit from a single case of using the chosen-prefix collision?
Not being candid here, I am honestly curious here. I'd guess that even in situations where you somehow get a signed e-mail sent off spoofing a CEO saying "Please pay these guys 50k$" the actual payout seems unlikely and that puts the attacker 45k in the red. But maybe there are some obvious avenues of abuse that I'm missing, or is this more a case of "In a decade it will become economical to abuse this for profit"?
- racingmars 7y agoI'm familiar with an organization that lost about $750,000 because someone spoofed an email from the CEO to the CFO asking to wire money to an account. The CFO fell for it. AFAIK, the money was never recovered (nor was the CFO fired... it was all just chalked up to 'the cost of doing business'). That was with NO crypto/signature spoofing involved... if the CFO has now been trained to not act on large dollar amount requests from the CEO without at least checking a digital signature... perhaps the CFO would be more likely to fall for it now since he has been "trained" that cryptographic signatures are a sign of authenticity?
- jVinc 7y ago$750,000 is a lot of money, but seeing as some people will act on emails without signature, and that you would effectively have to invest that amount up front in order to attempt this attack on 15 individuals, and then hope that at least one falls for it just to make it even, I can't really see this being a viable attack vector. Maybe if the cost goes down significantly to the $100-$1000 range it might be something you would see in the wild.
- biggestdecision 7y agoAt the current time this is much more likely to be abused for political/intelligence reasons, than for profitable criminal reasons. Sneaking a malicious commit with the same signature into a git repository for example.
- DaiPlusPlus 7y agoBitcoin uses SHA-256, but I wouldn’t put it past some of the devs of some of the Altcoins and Shitcoins to use SHA-1 for either - or both of - their Proof-of-Work or Blockchain integrity hashing algorithms. So if I understand today’s news correctly, you could use this to break blockchain integrity and offer-up alternative “valid” historical blocks (but not cheat at proof-of-work). You would still need to convince a quorum of network nodes to use your fake historical blocks - I imagine this might be doable on lesser-used coins that still have some trades - you could probably combine this with a few pump-and-dump trades too (without costing you anything as the coins you pump would be stolen).