4 ms·
The donate page lists bitcoin destination addresses for donation but the page doesn't seem to be HTTPS.
by ArchD 13y ago
The donate page lists bitcoin destination addresses for donation but the page doesn't seem to be HTTPS.
- ISL 13y agoIt doesn't need to be. Their address isn't any different from any other public address, like 1600 Pennsylvania Avenue. With Bitcoin, you can just send money to it; no form required.
- betterunix 13y agoHow do you know Bitcoin is non-malleable i.e. how do you know that a man-in-the-middle attacker cannot modify your Bitcoin messages so that the money is deposited to his account instead of the receiver's? Without a proof of Bitcoin's security, or even a formal security definition, it is hard to say whether or not such a thing is possible. In fact, the Bitcoin community seems to be tangentially aware of such issues: https://en.bitcoin.it/wiki/Transaction_Malleability https://en.bitcoin.it/wiki/Transaction_Malleability This is one of the reasons I say it is a near-certainty that whoever designed Bitcoin is not a cryptography expert; this sort of issue is well-understood by cryptographers and has been the subject of much research. See e.g. non-malleability in other settings: http://www.cs.cornell.edu/~rafael/papers/CNMZK.pdf http://www.cs.cornell.edu/~rafael/papers/CNMZK.pdf http://people.csail.mit.edu/huijia/papers/concnmc-owf.pdf http://people.csail.mit.edu/huijia/papers/concnmc-owf.pdf
- nicpottier 13y agoYou do bring up a good point that a MITM attack could change the bitcoin address and trick people to donate there. This really doesn't have anything to do with bitcoin though. I don't really understand your point on malleability though. The source and destination addresses are very much part of the hash and what is signed into the blockchain, so although you could change trick people into sending bitcoins to the wrong address using a MITM, the receiver wouldn't be tricked, only the sender. (IE, they wouldn't see any transaction coming to their legitimate address) As to your point on Bitcoin not being 'expert enough', that seems like a troll. Given the monetary incentives that exist to break bitcoin, and the number of rather clever people who have given it a hard look, I think you are vastly underestimating just how solid it is. It may have weaknesses that have yet to be discovered, but they aren't trivial.
- betterunix 13y ago"You do bring up a good point that a MITM attack could change the bitcoin address and trick people to donate there. This really doesn't have anything to do with bitcoin though." That is not my point. My point was that a person might attempt to send money to the correct address, but that a MITM attacker might be able to compute a new, related transaction -- perhaps one that deposits money in the attacker's wallet. That is the point about malleability. Throwing hashes and signatures around does not necessarily imply non-malleability. As a simple example, imagine a malleable public key encryption system. Simply signing messages before encrypting them would not create a non-malleable system, because the attacker could potentially maul the message in a way that replaces the original signature with his own signature (on a related plaintext). Non-malleable PKE is not an easy problem to solve; it took a lot of work to create such systems (hashes are often involved in the solution, but it takes more than just a hash function to "get it right"). In the case of multiparty computation, non-malleability is even harder and carries numerous subtleties. The attacker might desynchronize messages between the parties as part of the attack. The attacker might be able to observe multiple simultaneous interactions among different parties, which can be used in the attack. Maybe a Bitcoin attacker needs to observe a hundred transactions all involving some target party before they can compute related messages. The fact that there is no known attack does not mean that no such attack is possible. It may not be a trivial attack, but non-trivial attacks are still problematic for a system that is supposed to protect enormous amounts of money (as Bitcoin is). "I think you are vastly underestimating just how solid it is" I think it is hard to even estimate Bitcoin's security, since there is no well-defined concept of "security" for Bitcoin. That aside, there is already a known polynomial-time attack on Bitcoin (the so-called "51% attack," though even with less computing power there is a high probability of success), so I think you are overestimating the security of Bitcoin. My point about who designed Bitcoin was not meant to be some kind of insult, it is just an observation I have made. People seem to obsess over who Satoshi might be, and for some reason people keep looking at experts in cryptography, math, or related fields. My point is that experts in those fields would almost certainly be aware of work that has been done in multiparty computation and would not have simply ignored things like malleability, the "51% attack," concurrent security, etc. It is possible for amateurs to design secure systems; I just do not think Bitcoin is really an example of that.