3 ms·
My understanding is that if one entity controls 51% of the network, they can push arbitrary modifications into the block chain. In effect, they can do whatever
by krig 13y ago
My understanding is that if one entity controls 51% of the network, they can push arbitrary modifications into the block chain. In effect, they can do whatever they want.
- rlpb 13y ago> ...they can push arbitrary modifications into the block chain. In effect, they can do whatever they want. No, since who holds what coin is defined by consensus, which has to stretch out of the mining pool. If they arbitrarily gave themselves coin, for example, then no other client would accept that they hold that. See smtddr's reply for details of what they can and cannot do.
- andyjohnson0 13y ago"If they arbitrarily gave themselves coin, for example, then no other client would accept that they hold that." Would this be detectable in practice?
- VMG 13y agoyes, ever other Bitcoin client would refuse the blocks because they don't follow the transaction spec The purpose of Bitcoin mining is to establish an ordered sequence of transactions
- guard-of-terra 13y agoThis will cause block chain to split into two (we've already observed that a year ago due to sqlite glitch between versions) and the offender (ghash, 51%) will get exactly 0% in the block chain that every other client will be using.
- yebyen 13y agoThat is not correct, the consequences are still very bad. What can you do with 51%? You can (theoretically) revert a transaction that has been confirmed, by mining blocks attached to a prior point in the blockchain and getting a longer chain than the rest of the network. What can't you do? You can't spend someone's coins when you never had their private key to begin with. Making a transaction is an act of "signing" and public-private key cryptography is not dependent on the block chain style technique for sending messages, only for making sure that they got through and maintaining them as a ledger. You can probably single out arbitrary transactions and make sure that those are the ones that are reversed -- your transactions, so the evidence would point back to you, and whomever accepted your bitcoins as payment for something, would potentially know it was you who wronged them. You could also decline to single out a transaction, just reversing all transactions after a given block and starting a "new life" for all the people who spent their coins after that. When you refused to re-sign the transactions that you made, you would then out yourself. All of this is fairly academic since the person in charge of 51% of the hash power (GHash.io owner/operator) is a known actor, the hordes have not trusted him/them anonymously, and it turns out that miners have the least incentive to perform this kind of attack, since you lose an amount of revenue equal to the contents of the number of (your) solved blocks that you reversed. They would be more likely in my opinion to accept hashes and proof of work, but then renege and refuse payment to their miners, since this is really a less sophisticated attack and either way you should lose all of your credibility as a pool operator when you are discovered.
- makomk 13y agoThe thing you're not taking into account is that, even if GHash.io are trustworthy, this still makes them a single point of failure - any attacker who compromises their systems can carry out double spends, or they can even do it themselves and then blame it on an outsider. What's more, this has already happened with GHash.io and it hasn't damaged their reputation in the slightest. (Back when they were a smaller portion of the network, someone spotted malicious double spends of coins obviously linked to GHash.io that were equally obviously done using the miners they controlled. They blamed it on rogue insiders and everyone carried on using them.)
- yebyen 13y agoI mine with slush, at mining.bitcoin.cz I am not at all disputing that 51% attack is one of the known attacks and that 51% of hash power concentrated in the hands of any one actor is something to be prevented. I also dabble in alt-chains, and the Terracoin chain has often had 51-60% of the hash power in the Coinotron pool. It happened to GHash.io before, yes. I think they made it right. It's up to the rest of us to take our miners somewhere else to minimize the possibility of a rogue actor at GHash.io causing problems. As Coinotron once told me, a pool operator just runs a pool, can't control the users. There is no fair way to turn away hash power or "self-police" as a pool operator. I think if I read the graph correctly, the CDF provides a logarithmic probabilistic dis-incentive to be >50% of the hash power and also act fairly (in other words, to work on any broadcasted solved blocks that don't contain rewards belonging to you), so it will be interesting to see what happens next.