7 ms·
Bitcoin security guarantee shattered by anonymous miner with 51% network power
- dang 12y agoDiscussed at length recently: https://news.ycombinator.com/item?id=7890215 https://news.ycombinator.com/item?id=7890215. Unless the present article adds something of substance, I think we have to call it a dupe. Edit: so many people are upvoting this that we'll unbury it.
- bdcravens 12y agoIt's worth noting that for much of yesterday the parent of Ghash, cex.io, was DDoS'ed. Is this a good thing? Maybe it makes Bitcoin seem more self-policing, or maybe it makes it the currency of scary hackers.
- JacobEdelman 12y agoI can't really think of a scenario when DDOSing would be responsible policing. If that kind of tactic becomes common it can set up the exact type of aggressive struggle we don't want a 51%er in.
- A_COMPUTER 12y agoThis could be argued is a side-effect of the anarchic, decentralized nature of Bitcoin. If you have a problem with another operator, you may not have any legal, civilized means of achieving redress, so (virtual) "violence" may be your only practical recourse. There may be a moral in here about the nature of voluntaryism. I'm a bitcoin booster but these are real issues that need to be thought about.
- mpyne 12y ago> If you have a problem with another operator, you may not have any legal, civilized means of achieving redress, so (virtual) "violence" may be your only practical recourse. It would be less depressing if these real issues were novel; but they were written about by authors as far back in time as Hobbes.
- Dylan16807 12y ago>There's no evidence the anonymous operators of GHash exercised any of those abilities. Which means it didn't happen. It would be blatantly obvious to watch whenever GHash was mining on the 'wrong' chain to try to make it win. Even if GHash had 80% of the mining power, about one in 25 blocks would see non-GHash miners win twice in a row and unarguably expose this behavior as GHash ignored them.
- sillysaurus3 12y agoAnd when it does happen? (It's a when, not an if.) I don't think people will like their financial system unfairly tampered with. People say, "Why would Ghash do that? They profit from the system they'd be manipulating." Well, so did Mt. Gox, and it didn't stop them from manipulating it anyway.
- Dylan16807 12y agoWhy is it a when, not an if? It would hurt their ongoing profits so much to do it. But to answer when, I'd say probably after getting at least 60 percent of the network to control it comfortably without instability and slowdowns.
- gnopgnip 12y agoghash has been caught before abusing 0 confirmation betting with double spend. https://bitcointalk.org/index.php?topic=327767.0 https://bitcointalk.org/index.php?topic=327767.0 Also even if another pool won twice in a row it wouldn't matter. Over the next few blocks ghash's blockchain would become longer and all bitcoin clients would accept it.
- Dylan16807 12y agoOh well 0 confirmation has a lot of issues. But thanks for the info. What I'm saying with the double-win is that it blatantly exposes GHash's ignoring of blocks they don't like, not that they would actually lose over time.
- lifeisstillgood 12y agoDistributed trust systems ought to work because we love the idea, but there is always the chance we shall find that anonymity is not such a good thing for trust. I see no particular reason why bitcoin addresses should remain anonymous in the future, making the impact of this power less, but still a fix to the protocol or a lot more miners will be preferable. I would love to know if this is because the GHash pool has grown (through presumably investing 2012/13-bitcoin profits into hardware) or if it's because others stopped hashing.
- bdcravens 12y agoif this is because the GHash pool has grown (through presumably investing 2012/13-bitcoin profits into hardware) It has grown, but not because of Bitcoin profits. cex.io is probably the easiest on-ramp to mining, and all miners are pointed at GHash.
- xkarga00 12y agoGHash.IO hasn't 51% of total network power anymore https://blockchain.info/pools?timespan=24hrs https://blockchain.info/pools?timespan=24hrs
- StavrosK 12y agoHow did that happen?
- tlrobinson 12y agoSame as always, miners realized GHash had 51% and some subset of them moved to a different mining pool. Tragedy of the commons averted, for now.
- scotty79 12y agoWhy people won't change the pool to some other pool that doesn't take fees?
- pmorici 12y agoSome people believe, wrongly, that being with the bigger pool reduces their earnings variance and increases their earnings. Someone on reddit went and did a Monte Carlo simulation to show them that that really wasn't true so long as the pool had at least a few percent of over all hashing power and that any risk to the BTC price from the negative perception of a 51% attack was far costlier than the couple tenths of a percent you might get by going with the largest pool. http://bitcoinswitzerland.wordpress.com/2014/06/15/miners-luck-smoothing-excuse-does-not-hold-up-to-scrutiny/ http://bitcoinswitzerland.wordpress.com/2014/06/15/miners-lu...
- jsmthrowaway 12y agoWait, it's wrong to correlate pool size with steady income, but the simulation correlated pool size with steady income? If you need a few percent to guarantee steady income the base assertion is not wrong.
- pmorici 12y agoPeople were trying to say that there was a big difference between mining with a large pool vs the largest pool and what that guy showed is that once a pool is big enough 3%+ any variance due to the size difference is negligible compared to other considerations.
- maxerickson 12y agoHow hard would it be to compile actual statistics? The pool addresses seem like they would be reasonably easy to come by, but I'm not sure about estimating the mining power of the various pools.
- pmorici 12y ago
- rlpb 12y agoSo what's an individual miner's incentive here to continue mining with a pool that has 51%? If he wants more security in his own mined bitcoins, then surely he has an incentive to switch to another pool? Why is GHash so popular to miners?
- pakitan 12y agoTragedy of the commons. It may be bad for bitcoin as a whole but it's beneficial for that single miner because bigger pool means less variation of miner's income.
- mpyne 12y agoIn addition there's also the less rosy issue that if G.Hash becomes more powerful than the other pools and starts doing small-scale theft or other activities, it's safer for your money to "pick the winning team".
- KingMob 12y agoThey offer a 0% mining fee.
- wcummings 12y agoPlenty of pools do, this isn't the issue
- deleted 12y ago[deleted]
- sktrdie 12y agoSatoshi wrote this in the original Bitcoin paper, which logic I think still holds today: If a greedy attacker is able to assemble more CPU power than all the honest nodes, he would have to choose between using it to defraud people by stealing back his payments, or using it to generate new coins. He ought to find it more profitable to play by the rules, such rules that favour him with more new coins than everyone else combined, than to undermine the system and the validity of his own wealth.
- kolev 12y agoLike most Americans, you think it's all about money.
- jsmthrowaway 12y agoAlthough this is the weirdest, most out-of-place comment I have seen in a while, my life has taught me that "it's all about money" is the safest position to take in almost any scenario. That is potentially a product of our cultural and economic structure, but I have observed it to be true worldwide; I don't think we are wrong in general.
- serf 12y agoI think that it's a correct position now, but probably temporary in some sense. We didn't start with a cash system, and we may not end up with one, but for this moment in time it's a useful way to measure value/wealth. Ideally one would think "it's all about happiness" would be the goal, not a measure of asset worth, but rather contentedness perhaps? It doesn't take much thinking to imagine why we can't function in that way, however.
- conectorx 12y agoJust because money seems to be the most tangible thing in life it does not apply to the world. Some people value more love, health or ideals than money. Those people are quite rare to find, but they exist either unknown or known (such as Jesus, Hitler or El Che).
- 12y ago
- Tycho 12y agoIs this really true? So basically any government or any wealthy individual (or maybe even anyone with a botnet) could easily muster enough computing power to destroy Bitcoin? I thought by this point the amount of computing power required to do that was supposed to be ungodly...
- alextingle 12y agoMerely godly.
- polemic 12y agoCompare the sort of user hardware that a botnet will typically control, vs the hardware that specialist miners run, and you'll see why botnets don't have much chance of upsetting the network. You might earn a few coins, but you'll never take 51%: https://en.bitcoin.it/wiki/Mining_hardware_comparison#Intel https://en.bitcoin.it/wiki/Mining_hardware_comparison#Intel
- jokoon 12y agothe more bitcoin news, the more I'll stay away from it.
- dperfect 12y agoThese discussions seem fairly relevant now: https://bitcointalk.org/index.php?topic=393815.0 https://bitcointalk.org/index.php?topic=393815.0 https://bitcointalk.org/index.php?topic=399313.0 https://bitcointalk.org/index.php?topic=399313.0 "...if every bank vault in the world had a vulnerability that you (and only you) could exploit, possibly without detection (or at least with a degree of deniability)... what would you do?" Most people wouldn't immediately do the (irrational) thing and abuse that power on a large scale because obviously, the global instability/problems would outweigh the rewards. "Sooner or later, if given the opportunity to take unfair advantage of the system day after day, month after month, I think a lot of otherwise "trustworthy" people/organizations will end up giving in, albeit in subtle ways at first. Most people left to their own devices wouldn't flip a switch (for a reward) to immediately contaminate all of the world's fresh water at once, but if given a million switches each of which contaminates just 1 millionth of the world's fresh water for a substantial reward... I think there'd be some serious switch-flipping going on." The problem with Bitcoin (as described in the original Bitcoin paper) is that Satoshi apparently didn't account for the very real likelihood of pools gaining substantial amounts of power. "If a greedy attacker is able to assemble more CPU power than all the honest nodes..." sounds like a very remote possibility in the context of a world where every miner operates independently, and if pools didn't exist, it probably would be very unlikely. If every miner truly controlled his or her own mining power, I doubt we'd ever run into this problem.
- chez17 12y ago"...if every bank vault in the world had a vulnerability that you (and only you) could exploit, possibly without detection (or at least with a degree of deniability)... what would you do?" I think this completely ignores the fact that messing with the block chain would seriously screw over all the miners that are choosing this network for monetary reasons. Your analogy is flawed. Basically, it's more like "if every bank vault in the world had a vulnerability that you (and only you) could exploit, and you spent tons of money to get that vulnerability, and exploiting it would make all your money worthless, what would you do?" That's more like the actual situation here.
- dperfect 12y ago
- oelmekki 12y agoWell, for the sake of theory, it's a good thing to think about what the most powerful person in the bitcoin ecosystem could do bad. But please, don't stop here. What the most powerful political leader in your country could do bad ? What the most powerful economical leader in your country could do bad ? "Power" as a concept is something that would need deeper inspection by everyone, and should probably be dissolved as much as possible (that's the point of democracy). If 51% attack scares you, push your reasoning to its ultimate point.
- krapp 12y agoI don't believe democracy is about decentralizing power, so much as decentralizing the means of potentially taking and exploiting power. Or maybe only in practice, versus theory. That seems to be one of the fundamental paradoxes in the anarchistic ideal of Bitcoin - that implicitly, collective action to centralize and exploit the system is a perfectly legitimate act within its framework, if you can get away with it.
- mpyne 12y ago> That seems to be one of the fundamental paradoxes in the anarchistic ideal of Bitcoin - that implicitly, collective action to centralize and exploit the system is a perfectly legitimate act within its framework, if you can get away with it. I'd say it's more a libertarian ideal. You'd have the same idea in an actual anarchy of course, except that rolling up all the communes by force wouldn't be considered legitimate just because you're able to do it.
- sciguy77 12y ago"So-called 51 per centers, for instance, have the ability to spend the same coins twice, reject competing miners' transactions, or extort higher fees from people with large holdings." Woah, can someone please explain why this is?
- patio11 12y agoThe blockchain with the most blocks in it becomes the consensus blockchain. If you build a blockchain higher than the existing blockchain without building off of it, the One True Bitcoin Client will anoint your chain as the true chain. Only the true chain happened, from the perspective of the bitcoin client. Non-consensus chains mean nothing. A chain losing consensus can happen retroactively (and by design does, frequently), but shouldn't after about 6+ confirmations (~1 hour of work by the network) unless you control a lot of power and are willing to secretly build a competing chain starting from a point in the past and build past the existing consensus chain. If you are willing and capable of outrunning the network for sustained periods of time, you can rollback the history believed by the network and replace it with a history which includes only those transactions which you think should have happened. For example: did you pay your rent an hour ago? Did your landlord accept your payment after an hour and send it to Bitstamp, thereby getting money? Did Bitstamp then allow people to withdraw it? Psych. You remember that happening, but the Bitcoin consensus now says that the Bitcoin half of all those transactions never happened. You could, for example, announce "Apropos of nothing: we find that transactions with 1% fees [paid to the miner of the block] are pleasing to the Bitcoin gods and are only willing to include them in our blocks. BTW, we will also rollback history periodically for the hell of it. If you want your transactions to survive rollbacks, take note."
- PhasmaFelis 12y agoThat's funny, I thought we are all told quite vehemently that 51% control was ridiculous and would never happen.
- ZenPro 12y agoThis ^ The most complete and accurate statement on the entire thread.
- m0llusk 12y agoBy who were you told this? The bitcoin community has been buzzing with the issue of pools exerting control for quite some time now. Putting up a straw man that is the opposite of what has actually been said isn't funny so much as tragic. Why did you bother to post this?
- po 12y agoThe thing that surprises me the most is that people were seemingly ok with a player having any large percentage of the network power. The new development seems to be that one player is verifiably controlling 51% of the market. This doesn't mean that two pools who each had 30% couldn't have colluded outside of the network to control it beforehand. I've seen people trying to persuade people not to join the most popular pool but this seems like a more fundamental problem.