6 ms·
Due to the pseudo anonymitiy of cryptocurrencies, a whole range of perfect crimes is possible. Say you've got a some bitcoins (as little as 3 BTC makes you attr
by codeshaman 12y ago
Due to the pseudo anonymitiy of cryptocurrencies, a whole range of perfect crimes is possible.
Say you've got a some bitcoins (as little as 3 BTC makes you attractive, but let's say you've got 100BTC ) and you order a pizza with bitcoins from that wallet.
The pizza guy fires up blockchain.info and notices that your address has a hefty balance, then picks up the phone and tips Oleg and Boris, giving them your home address.
Oleg and Boris mean business: they have a hammer, clippers, a soldering iron and an AK-47 in the trunk. Their target: your Bitcoins.
They wait patiently for your to exit your apartment or they follow you around or they just come knocking at your door.
They are ready to patiently torture you until you transfer all your bitcoins to their address. They will enjoy the process, you .. not so much.
After you finally give in and transfer them your bitcoins, they leave and disappear.
Now you've got absolutely nothing to show to the police: You cannot prove that those were your bitcoins and you cannot prove that the address you've transferred your balance to isn't yours. And you have no idea that it was the pizza place that tipped the bad guys.
For Oleg and Boris, it's the perfect crime: They just made $30k in 20 minutes and they didn't even have to kill anyone, a finger here, a finger there and they are rich!
This, in my opinion, is a great risk for cryptocurrency owners, because it offers potentially great returns for the bad guys and the risk is pretty small, plus it's very hard to prove that the theft/extorsion did happen.
- xorcist 12y agoCash survived thousands of years with this weakness. I'm sure cryptocurrencies would, too. In fact, it would be easier to make the case that this was you money, thanks to the transparency of the block chain (and the fact that you have the keys).
- codeshaman 12y agoTrue, the only difference is that cash (or any physical store of value, like gold) becomes cumbersome in large amounts. And random people having large amounts of cash or gold in their apartment is pretty rare. 1000 BTC on the other hand have no physical form so it's much more convenient.
- icebraining 12y agoSimple: keep multiple addresses (all clients are built for this) and diversify your balance among them. Keeping them all on a single address makes even less sense than keeping large savings in a checking account. It shouldn't be very hard to design the UI to make it hard to fall into this trap, either. Easy way: when doing a small payment from an address with a large balance, the client can automatically add intermediate transfers to avoid the direct link.
- codeshaman 12y agoOf course, everybody should do that. But since we live in an imperfect world, not everybody will do it. As you're saying, this should be implemented in the BTC clients themselves and they should not let you make large transfers without first warning of the dangers. But what if you're buying a boat or a car or a house ? I've lived in the ex Soviet Union in the 90's and extorsion through torture was a common thing back then. But now we might see the 21st century version of those guys, probably a bit more gentle - no need to shoot or kill people, just force them to press Enter and you're done.
- icebraining 12y agoIf you're buying a boat or a car, you'll have to do a big transfer. But how is that any different than buying something expensive using a bank account? It's not a new problem with cryptocurrencies.
- mehwoot 12y agothan buying something expensive using a bank account Because a robber can't demand you transfer money from your bank account and expect not to be traced, that's why.
- throwaway84356 12y agoYour bank wire doesn't leak the balance of your account to the recipient. It is a new and unique problem with some cryptocurrencies. Of course, we have already proposed solutions to problem this with ring signatures, stealth addresses, 'coinjoin', 'zerocash', 'TITAN', etc.
- onli 12y agoThat is not the definition of a perfect crime I know. There are traces, Oleg and Boris for example, or the injuries. A perfect crime would have no realistic way to trace to the mastermind. Also, shouldn't there be ways to indicate ownership with the private key?
- icebraining 12y agoAlso, shouldn't there be ways to indicate ownership with the private key? Well, it's possible to prove control of the address (simply transfer something to an address of the choosing of the person who you're trying to convince). "Ownership" is more difficult to prove.
- vog 12y agoStill, that's a strong connection between you and the address, which is a whole different story than "leaving no traces", and pretty far away from a perfect crime.
- higherpurpose 12y agoIf your cash was stolen from your wallet, how would you prove the cash was yours? Besides, I think most "mainstream Bitcoin users" have their wallets on sites such as Bitstamp, Coinbase and so on. So they can prove the Bitcoin was theirs.
- vog 12y agoOr, as onli suggested, you can provide the private keys for the emptied account(s).
- throwaway84356 12y agoNo, you don't want to give away the priv keys, as someone may transmit a future transaction you could claim with it. Simply signing a message would be sufficient. Don't reuse the 'k' value with your ecdsa sig!
- vog 12y agoOf course, you just have to prove that you know the private key. Handing it out is unnecessary. My bad. BTW, instead of signing a message, you could also move around some money through that account. This may be easier to achieve for non-tech people, as it can be done with any Bitcoin client.
- notahacker 12y agoOleg and Boris don't need Bitcoin or tipoffs to bash people over the head for their jewllery in rich neighbourhoods, and don't need named bank accounts and audit trails to get caught doing it. The pseudoanonymity is perfect for phishing and ponzi schemes though...
- Cyther606 12y agoRight idea, but: 1. Satoshi is likely carrying $300M in his head, today. Imagine what it will be in 10 years. You can't carry $1,000,000,000 in cash in your head for example. 2. Allowing criminals to steal BTC from you by force or extortion sets up horrible incentives. First, the criminals must voluntarily relinquish control of the BTC if you are to get it back, so there's little the State can do to help you even if they wanted to. Are you willing to use equal or greater force to compel hardened criminals to get your money back? The police probably aren't, and your government is almost assuredly corrupt regardless of where you live. Ponzi schemes are the least of your worries in a world where Bitcoin is truly ubiquitous.
- venomsnake 12y agoYou know committing crimes in the real world leave a lot of traces? And even the most corrupt regimes think of torture as state only prerogative? As the Silk Road proceedings showed - getting someone for wet work even with a lot of money is hard.
- hluska 12y agoI think wet work could be the worst (or, at least most ghastly) euphemism of them all! I had never heard it before now...:)
- celticninja 12y ago"enhanced interrogation" was my favourite but it has been recently superseded by "incorrect evidence"[0] [0]http://www.bbc.co.uk/news/business-30175983 http://www.bbc.co.uk/news/business-30175983
- gregorias 12y agoIsn't it possible to trace history of transfers in Bitcoin? I thought the blockchains contained information about transfer from and to account, and that's de facto the way to check account's value - by tracing it's entire history.
- throwaway84356 12y agoYes but you will soon give up once that value hits a mixer/laundry, or an exchange hot wallet. No shortage of either.
- celticninja 12y agobut you never know at which point the coins came into the current owners posession. You could go back 1 step or 100 steps and trace the coins linegae from their creation until today but without knowing who owns all the intermediary addresses youy dont really know anything other than how much was sent when.
- IkmoIkmo 12y agoIt's a fair point, but it's much less simple than you say. Firstly, this problem exists in current society too. I don't think anyone has any problem picking out rich people, and anyone in a city will be able to tell you where the rich neighborhood is. Bitcoin doesn't make this any easier. In fact, best (and common) practice is to never reuse addresses, and use bitcoin inputs from various addresses. (e.g. to pay $5 for a pizza, you could theoretically, if you wanted, use inputs from millions of addresses each having only tiny fractions of a penny). Despite the public ledger, bitcoin offers a lot of financial privacy. As such the first premise of your story I think is flawed: that it's easier to find out who is bitcoin-rich. Second, extortion, kidnapping, stealing, these are all things that on paper are pretty easy to do now, but to say it leaves no trace or that it's in any way easy (regardless of what token you steal, whether it's platinum bars or World of Warcraft gold) is clearly not true. Regardless of what is being extorted, this is really hard. For example, ideas can be extorted, too, passwords, keys to nuclear launch facilities etc. But it doesn't really happen too often, even though the tools to 'trace' a stolen idea or a stolen digital file are (and can be) limited. But let's imagine it does happen? Let's compare it to a debit card. They kidnap you, take you to an ATM and force you to use it or give them the code. It happens every now and then, but the amount stolen is usually very limited, a few hundred bucks as that's the limit for most ATMs per day. Bitcoin has similar options. You can have more than 1 key, and you can give such a key to say a friend, a bank, a server. Technically it's easy to set up a system where you have $1m, and to send $1m requires you and multiple other keys to sign, the key at the bank (stored behind armed guards), your notary or your friends. You can keep it simple or super complicated depending on your risk profile and the amount of money. In a small village as an unknown rich entrepreneur, keep it simple. As a known billionaire in guadalajara? Probably require lots of keys for any amount over $10k or something. Just making something up. Point is, technically you can set it up any way you'd want. So they'd extort you and you'd say 'just like my ATM, I only possess a key that allows $500 to be transferred per day. For more I need more keys which I don't possess, I own them but I don't have them with me. I'd need to go to a bank' or whatever. Now there are a lot of caveats to this. The whole notion of keeping all your money in your brain carries physical risks, and keeping keys with a third party (as opposed to 100% autonomy over your money) is sort of contrary to the spirit of bitcoin. But you can keep keys at multiple parties, neither of which individually have enough keys to control your money, while providing security benefits. In short, there are lots of possible solutions to the horror story you wrote (of an easy & perfect crime) that should be arriving in fully consumer-friendly ways over the next few years for sure.
- hluska 12y agoThankfully, this wouldn't be a perfect crime - there are several weaknesses that each (thankfully) provide many opportunities for police to collect evidence. For example, Boris and Oleg would need to conduct the exercise (for lack of a better euphemism) somewhere they control yet that cannot be tied back to them. They would need to keep the scene extraordinarily clean since the types of people who would torture are often the types of people with DNA samples in databases. They would have to avoid each other's names. And, faced with the prospect of serious jail time (this crime would receive a life sentence in many parts of the world), each party to the offense would have to stay solid. The curse of intelligent criminals is all powerful. Intelligent criminals have to get lucky every single day for the rest of their lives. The police only need to get lucky once!! :) That was a fun thought exercise and I hope your deserved upvotes rain in.
- codeshaman 12y agoUpdate: You are right, It's not the perfect crime. That's why I write code for a living :) It's just a crime, but the rewards can be well worth the risks. You expect returns comparable to robbing a bank, but the criminal method is much safer for the robbers, they can even avoid violence altogether. In the real world, badass shellshocked war veterans who've done time in a russian prison would meet very little resistance from a bitcoin-rich geek. They don't need AK-47s to extort most of us, they just have to say something really scary, like 'All your bitcoins are belong to us. Now!' and pretty much all the geeks I know would shit their pants and hand over their private keys or make the transfer. It's also certainly possible to prove that you did own the funds. That is, if the police is not in on it. And when we're talking big money, impossible things become possible, especially in corrupt countries. Bitcoin is used all over the world. Maybe it's hard to imagine such crimes in US or Europe, but I wouldn't vouch for the rest of the world. Much much shittier things are happening every day. Multi-sigs and address shuffling makes sense to us, but some random investor who's storing part of his wealth in cryptocurrency may have no idea.