6 ms·
Bitcoin Network Speed Breaks 1 Petahash per Second
- ctz 13y agoSo 10^15 H/s is about 2^50 H/s, or 2^71 H/Y. Assuming you could rededicate the whole network to attacking SHA-1 (which you practically couldn't, the ASICs would need replacing) you could break 2^10 intermediate SHA-1 signed CA certs per year, and compromise the whole current deployment of HTTPS.
- ISL 13y agoAssuming that the hashes are equivalent difficulty (I don't know if they are): Given that the market cap of Bitcoin is ~$1B, imagine what you could do if you had ~$1-200M and wanted to crack some certificates...
- antocv 13y agoAnd now we know how NSA "breaks the internet encryption", it is not through RDRAND, its by good old force. Its much more cost-effective to do things by force than trying to predict the future uses of some hardware with some special software.
- p1mrx 13y agoYour math suggests that you can break a certificate with 2^61 hash operations, but this page says 2^61 operations will only give you a collision: https://code.google.com/p/hashclash/ https://code.google.com/p/hashclash/ With the ability to generate collisions, it becomes easier to trick a CA into signing an evil certificate, but collisions don't help if you want to break someone else's certificate.
- mrb 13y agoBy "break", ctz meant "create 2^10 certificates". Creating arbitrary intermediate CAs would indeed compromise the safety of HTTPS.
- mrb 13y ago1 bitcoin hash (2 SHA-256 hashes) is approximately equivalent to 3 SHA-1 hashes in terms of number of 32-bit operations, so you are off by a factor 3. But your point remains valid :)
- agl 13y agop1mrx is correct - creating plain SHA-1 collisions shouldn't break the CA system. Even though it's believed that one can create an identical-prefix collision with that amount of work, after the MD5 Industries demo all CAs now inject at least 64 bits of randomness into the signed certificate. Thus the certificate that they actually sign isn't predictable and doesn't have an identical prefix. Technically what one needs to break is the target-collision-resistance of SHA-1, and that's standing up much better. For things like git, however, an identical-prefix SHA-1 collision would be a problem.
- o_s_m 13y agoIt would be nice if all that electricity could be used to help the less fortunate on this planet.
- ISL 13y agoIf it means frictionless commerce with anyone worldwide, perhaps it will?
- broostoryco 13y agoExactly, its the price we pay for the currency network, which is incidentally much less than what we pay now to commercial banks for using their payment network (spoiler: that money does not help the less fortunate of the world either)
- eterm 13y agoNothing about bitcoin is tending towards frictionless commerce. That is an argument people make to excuse the huge waste of power (by extension generating a large amont of pollution) that goes into bitcoin. The reality is that all the forces that slow down electronic dollars also slow down other electronic currencies.
- pjc50 13y agoWhat forces are those?
- drcross 13y agoThe energy required to obtain gold from the earth, when you compare it to bitcoin, makes your comment farcical
- eterm 13y agoCurrencies aren't backed by gold. They're backed by governments. The united states dollar is just as much a "virtual currency" as bitcoin.
- fpgaminer 13y agoWhatever you may think about Bitcoin itself, the _story_ of Bitcoin is impressive. Bitcoin started as a small, open source hacker project by an anonymous fellow on the internet. Somehow, this has snowballed to the point where an entire datacenter's worth of custom computing power is being thrown at it. That's inspiring and amazing no matter how you slice it. Amidst the on-going onslaught against our digital world, it's refreshing to see what people can accomplish using open source ideals.