3 ms·
Wouldn't it be possible to fool this by forking the blockchain immediately after the first difficulty adjustment after the last remembered block, and then forgi
by bdonlan 12y ago
Wouldn't it be possible to fool this by forking the blockchain immediately after the first difficulty adjustment after the last remembered block, and then forging timestamps to force the difficulty to go down? You'd need a pretty substantial amount of hashing power to generate the next 2016 blocks, but it doesn't need to be a 51% attack. Over a long enough time scale it ought to be feasible to fool this.
Of course, if you're syncing back up on a reasonably regular basis this won't be practical. But for 'time capsule' applications this ought to work.
- hackcasual 12y agoI sort of touch on that in the slides. If the smart card didn't take difficulty into account, you could bypass it simply by generating a bunch of low level difficulty transactions, with minimal effort. You would need to also model how much difficulty each proof of work should have. It's a risk, as some major bitcoin collapse could leave you effectively with no ability to decrypt your saved package. The closer you're able to accurately model how much difficulty there will be over the time period, the more secure the system will be. The more lenient, the less power an attacker would need. Even 5% of the bitcoin block network's hashing power for the duration of the life of the secret would represent a substantial amount of computing power.