5 ms·
The bigger flaw is that there is lack of economic incentive to continue to donate computing power to keep the network running. At the current exchange rates and
by dmk23 15y ago
The bigger flaw is that there is lack of economic incentive to continue to donate computing power to keep the network running. At the current exchange rates and bitcoin mining yield it cannot even pay for the energy cost.
As it stands today just around $300K worth of hardware (I cannot quite recall the reference off top of my head) is needed to be able to "out-compute" the existing network and introduce a corrupted / compromised version of the block that everyone will accept as real.
That's not to mention that the transactions are not anonymous and just pseudonymous, which means if your identity is somehow disclosed (anytime in the future) all your bitcoin dealings are going to be completely public for anyone to see and use against you.
Distributed crypto-currencies may have a future, but it would require a lot of work to make them viable.
- narcissus 15y ago"All your bitcoin dealings are going to be public" is really only true if someone gets a hold of your wallet, or if you are using the same Bitcoin address for each transaction. By default, every time you send or receive you are given a new 'default' address. If you don't use that, then yeah, a group of transactions can be linked to you. Otherwise your identity would have to be 'disclosed' for each different address separately. Unless of course someone gets your wallet, but then as far as I'm concerned, you've got bigger things to worry about it.
- coderrr 15y ago"Otherwise your identity would have to be 'disclosed' for each different address separately." Actually, it's a lot worse than that. Most people will have a majority of their addresses linked without knowing it. http://coderrr.wordpress.com/2011/06/30/patching-the-bitcoin-client-to-make-it-more-anonymous/ http://coderrr.wordpress.com/2011/06/30/patching-the-bitcoin...
- feral 15y agoI've done some work on this (http://arxiv.org/abs/1107.4524 http://arxiv.org/abs/1107.4524) and the phenomenon that coderr describes is very widespread in practice (we can examine this passively, from the transaction history) and its linking identities we can be pretty sure the users didn't intend to have linked. I'd say that anyone concerned about anonymity should be using a client with the functionality that coderr's patch provides, and be incredibly careful using Bitcoin in general.
- narcissus 15y agoThanks for the link: that's really interesting. I guess that's more a problem with the official client more than the protocol itself, though, right? If you were to create a new address and have all of those 'trackable' addresses send their balances to that new address, haven't you essentially removed this problem? I mean, all the people that sent to you in the first place can see where you sent the coins to, but they can't prove that you are holding that new account. Or is there something I'm missing here? For what it's worth, I completely see how this is a problem. However, I don't see it as a particularly hard problem to solve (even 'programatically'). EDIT: and it was until I read the other reply here that I realised that that is actually your blog post. Nice work!
- coderrr 15y agoYea if you send coins to a new address no one can prove you own that address. You have to be careful though. If you send 100% of your known linked addresses to a new address it's pretty obvious that you own the new address too and have just moved your coins to it. It's a pretty complicated area to reason about. I expect there will be a lot more research on it in the coming years.
- weavejester 15y agoBitcoin mining difficulty is automatically adjusted based on the capacity of the network. If the cost outstrips the gains, then either people are content to lose money on the network, or people will leave until the difficulty becomes low enough to make mining profitable again. You're probably correct that you'd only need $300K to purchase enough hardware to double-spend, but any profit you could make off double-spending would be offset by the cost of electricity. Also, an alternative compromised blockchain would be really obvious, so you'd only have a limited window in which to scam people. Maybe you could do something if you had a botnet (and thus didn't need to pay for the hardware or electricity), but I can't help thinking that you could probably be doing far more profitable things with that amount of hardware.
- patrickyeon 15y agoI don't think the root problem would be the money you directly scam from other users. I think it would be the huge loss in trust in the network once it's been seen to happen.