5 ms·
> So split any cryptocurrency network into small segements, then add your machine to that network with a false history, design the network to be small enough, a
by null0pointer 3y ago
> So split any cryptocurrency network into small segements, then add your machine to that network with a false history, design the network to be small enough, and your machine will out-hash the rest, and so it's history will win. Rinse-and-repeat.
You cannot forge history, even with 100% of the hash power. Firstly, each transaction is cryptographically signed with the keys of the sender address. Secondly, each full node within the segmented network will have the full history.
The only thing you can do is publish different blocks to the segmented network than the blocks the outside network has. You cannot create arbitrary transactions. You can only censor others’ transactions within the segmented network. Since the mining difficulty will not adjust instantaneously your segmented network will fall behind the outside network in block height unless you control more hashing power than everyone else mining Bitcoin on either network combined. So as soon as anyone in your segmented network re-establishes connection with the outside network (and they will, they could receive a physical hard drive with the blockchain on it and rebroadcast to segmented nodes) all your work is for nothing.
You might say “yeah well I’ll publish an entire fake history that is MUCH longer than the outside network with lower difficulty so I can stay ahead”. Well, actually you can’t, because if you wanted vastly more blocks between Bitcoins inception and the present then the difficulty will necessarily be much higher because that’s how difficulty gets set, by how quickly blocks are produced. You would have to change the difficulty adjustment algorithm, creating a fork between your own malicious node(s) and the other nodes in your segmented network. Oh and by the way, you _still_ can’t create arbitrary transactions.
> The global bitcoin system is well within rearch of a hostile state 51%'ing it
I’ll believe it when I see it. They honestly have a better chance outlawing it and imprisoning anyone who’s ever used it.
- mjburgess 3y agoAll this depends on how many assumptions are in operation about what the state is doing to these networks, and the machines on them. In the end, it can turn all btc traffic off -- and there's no btc at all. Or it could take over the miners within its borders, which are heavily centralised, and run a different protocol. If you own the machines and own the network you can do anything you want. Anything at all. As far as assuming that the state hasnt taken control of the miners (unlikely, this is the easiest thing to do), by dropping communication, delaying it, observing it, etc. much can be done following the protocol, including replaying transactions etc. -- the future can be forged. There are so many assumptions about the realworld, that do not hold up, behind cryto protocols, they're laughable. Assuming that the system will follow the protocol is itself disconnected from reality, quite literally. The initial paper's realworld assumptions was that mining would be an at-home affair, ie., decentralised; everyone would run their own. And that networks were not own or controlled by centralised actors. Neither is true. Mininig is incredibly centralised, as is network control. This makes it trivial for a state to pull an off switch. Even talking about sophisticated denials of service, transaction replays, forging future transactions... all this takes place in a silly imagined scenario in which the state wants to hide what it's doing. If it didnt care, bang goes the whole thing.
- rspeele 3y ago> The global bitcoin system is well within rearch of a hostile state 51%'ing it > I’ll believe it when I see it. They honestly have a better chance outlawing it and imprisoning anyone who’s ever used it. First of all I don't think any state is currently motivated to do this. However, if I were a state agency trying to attack Bitcoin, I would start by creating my own mining pool, which of course would purport to be privately run. I would be the most efficient mining pool in the business, offering miners a slightly better cut than other mining pools since while most pool operators are trying to extract a low-margin profit, I'm willing to break even or, if necessary, run at a small loss. It would be ideally to gradually create several sock-puppet pools that appear to be in competition with one another, while in fact I control all of them. Even with competitive payouts, it may take several years to build up my pools reputation and gain a significant share of miners. And when I start having my pools mine blocks that I'm not actually submitting to the chain (to support my double spend), pretty soon miners will notice and switch. But I only need a couple hours to cause chaos, and I may benefit from miners confusedly switching to other pools that are also under my control. If I look at the regions where I have the most miners and time to the attack to occur overnight in those areas, I may succeed. And unlike trying to 51% the network myself by throwing hardware at the problem, I won't be left with worthless SHA256 hashing machines at the end of the attempt, nor will I have to pay for power. And I don't have to outmine the entire network -- I've enlisted half of it to be on my side. The only cost is the minimal pool operating expenses (not mining, just issuing work to miners, checking their work and arranging payouts), spread over how ever many years it takes me to gain dominance.
- rcxdude 3y agoOr, skip the trouble of building such a pool and rubber-hose those who control the existing pools into doing what you want.