3 ms·
It's not clear to me that Felten's response you've linked to identifies a fatal flaw in the ES attack, because the ES attackers aren't limited to following just
by nimble 13y ago
It's not clear to me that Felten's response you've linked to identifies a fatal flaw in the ES attack, because the ES attackers aren't limited to following just the bitcoin protocol. The ES attackers could follow a protocol under which coalition members are required to prove to each other that they are working on the ES chain and not "fair weather mining". For example, coalition members could log cyptographic proof that they were working on certain chains, and then keep a certain number of bitcoins in virtual escrow that will be forfeit if fair weather mining is discovered.
- deepblueocean 13y agoHow would such a proof protocol work? I spent most of yesterday trying to answer that question and came up with nothing. Imagine that you and I are mining and we've agreed to use the ES "selfish" strategy. When I want to getWork, I have to choose which branch I'm targeting as the parent of whatever block I'm trying to mine (I have to choose which hash to put into my block). But how do I prove this to you? I could send you a commitment to the hash and you could promise to come beat me up after the fact if I lied, but that's outside the stated protocol. In fact, if your model is that you can coerce me to follow your protocol when it's better for me to do something else, then you may as well coerce me to give you all my bitcoins. Our argument is that the protocol, as stated, is not incentive compatible. That's ironic, because the protocol, as stated, is offered as an argument that Bitcoin is not incentive compatible.
- nimble 13y agoThinking about this more, I don't understand the importance of your fair-weather mining idea. If the parties collaborating on the ES attack are willing to betray each other, then isn't a much simpler form of betrayal to steal the block that someone else in the group found and claim it for yourself? Bitcoin attempts to create a protocol that doesn't require trust between parties, but needs to robust against large groups (e.g. blocks of Chinese) who trust each other. So I don't think it's ironic that the ES attack is not incentive compatible, nor do I think it's really a flaw.
- nullc 13y agoYou cannot "steal the block". You must commit to the full solution (including who it pays) before testing it. The reason this doesn't prevent defection is that while you can produce a provable commitment that you're mining with the ES miners in one moment, all other moments you can be defecting and sharing the ES state with your friends.