5 ms·
And that 40% is still enough for lots of attacks.
by jdong 12y ago
And that 40% is still enough for lots of attacks.
- michaeltoth 12y agoNot really. For an attack to be possible, the attacker needs to generate an alternate blockchain faster than the honest blockchain. This problem can be thought of as a binomial distribution where the "success" is the honest blockchain mining a block and extending its lead by a block and the "failure" is the attacking chain being extended by one, reducing the gap by 1 block. p = probability of honest blockchain extension by 1 block q = 1 - p = probability the attacker extends by 1 block If p <= q, the probability of the attacker catching up at some point in time is 1. This is what makes a 51% attack possible. If p > q, the probability of the attacker catching up is (q/p)^z where z is the number of blocks behind at the beginning of the attack. There is a reasonable possibility for small values of z (small number of blocks behind), that 40% control would allow for the creation of an alternate blockchain longer than the honest chain, but this is mitigated by the fact that transactions require confirmations, which extends the number of blocks and makes the likelihood of an attack very unlikely.
- sp332 12y ago51% attack is not the only kind of attack. A "selfish mining" attack can break the system too. http://hackingdistributed.com/2013/11/04/bitcoin-is-broken/ http://hackingdistributed.com/2013/11/04/bitcoin-is-broken/ Here's the paper http://arxiv.org/abs/1311.0243 http://arxiv.org/abs/1311.0243
- michaeltoth 12y agoThanks for the articles. I recall reading about this last year when the paper was published, but I had since forgotten about this form of attack. This is definitely interesting.
- nullc 12y agoWhile the factual you said we're true, they aren't anywhere near as useful as just linking to a calculator— http://people.xiph.org/~greg/attack_success.html http://people.xiph.org/~greg/attack_success.html I don't agree with your conclusions though— at 40% a determined attacker reorgs 6 confirmations with a 50% success rate. Many users don't wait even six. Consider, even with 20%— thats analogous to having five parties 'signing' blocks— a result which is less decentralized than a fair amount of traditional financial systems. (The comparison is better than it would be with other pools because ghash primarily physically controls their own infrastructure). Even though this is all quite concerning, Bitcoin is very dynamic— the current state isn't something that will last, one way or another.
- deleted 12y ago[deleted]
- keyme 12y agoYep, obviously the incentive system of bitcoin is deeply flawed. It's interesting to see that the market price is completely decoupled from such problems coming into public attention... I'm holding on to my stash for now, but unless the network is hard-forked to solve this issue (and other major ones on the way), I don't see a real future for bitcoin anymore. The price could still hit $20k, but the coin would be tightly controlled by then if mining remains centralized.
- petertodd 12y ago> It's interesting to see that the market price is completely decoupled from such problems coming into public attention... It's seems "decoupled" because investors know that there is a fairly high chance that the problems will be fixed when it becomes apparent that it's posing a serious threat. Ultimately what Bitcoin is is a social consensus, and that social consensus has rapidly changed before in the face of exploits and will probably do so again. Secondly, at a technical level solving the flawed incentives can be done in a backwards compatible soft-fork upgrade - a hard-fork where everyone upgrades at once is not required, which makes agreeing to and deploying such a change significantly easier.
- baddox 12y ago> Yep, obviously the incentive system of bitcoin is deeply flawed. Then how do you explain that apparent lack (or at least, very low rate) of such attacks? It seems to me that what we observe is evidence against your description of the incentives.
- keyme 12y agoThey did occur, but yes, at a very low rate. The rate will increase once the people with guns realize the benefit of such attacks. This is not the case now, but it will be the case if the price continues to rise. Imagine that 2 court orders (one to GHash, one to the next largest pool) are enough to reverse a transaction, or to "freeze funds" by not allowing TXs from a certain key. If the incentive system encouraged independent mining, this would not be possible.