Live data from Hacker News

I Am Not Satoshi

blog.dustintrammell.com

171–179 of 179 posts

Re: I Am Not Satoshi

#171

Earlier quoted context omitted.

"Not sure what you mean by 'poorly researched'." I mean that it was poorly researched. There was no definition of security, no mention of the vast body of related work in digital cash or secure multiparty computation, a weak security analysis, no mention of the fact that polynomial time attacks are usually considered to indicate that a system is not secure (one would think that a different security model would requir…

Real-world cryptography often doesn't have security definitions, e.g. AES. In parts that is because security definitions tend to be asymptotic (which is a massive simplification), and real cryptography is working at a fixed parameter. Coming up with a good security definition is hard, the 2013 Turing award was given for one. I think it will take a long time before we get a realistic security definition for Bitcoin.

"Real-world cryptography often doesn't have security definitions, e.g. AES"

Block ciphers do have security definitions; what AES lacks is a rigorous proof that it satisfies the definition of security for a block cipher. There are different definitions for different notions of security, but that does not mean there is no security definition. It is also untrue to suggest that security parameters are fixed in practice; this is certainly false for public-key cryptography, but Rijndael was designed to support arbitrary parameters, as are many other practical block ciphers and hash functions.

"Coming up with a good security definition is hard, the 2013 Turing award was given for one."

Not one definition, but several definitions and an entire paradigm for definitions. The work also set the groundwork for proving that cryptosystems and cryptographic constructions meet such definitions.

Really, the importance of having a security definition cannot be understated. Without a security definition, you cannot have any falsifiable claims about security. If I claim a system without a definition is insecure, you can always refute me by claiming that the system was never designed to defend against my attack -- which is technically correct, because without a definition the system cannot be said to be designed to defend against any attacks.

Also, note that I did not say that Satoshi failed to give a good security definition for Bitcoin. What I said is that Satoshi failed to give any security definition. If Satoshi had given an unrealistic or otherwise bad security definition, then we could have a productive conversation about the definition and about whether or not Bitcoin satisfies it.

"I think it will take a long time before we get a realistic security definition for Bitcoin."

The thing is that we do have realisitic security definitions for digital cash -- the definitions just happen to rely on the existence of a central authority that issues the currency, which is a deal-breaker for the Bitcoin community.

Re: I Am Not Satoshi

#172
post #143
post #127

Earlier quoted context omitted.

Betterunix has been in this discussion many, many times. I don't think there is any way to get him to stop saying that bitcoin isn't an achievement and that it is a priori invalid because it doens't have a "formal security model."

Well he stopped saying there was no formal security analysis once someone linked him to one, I think. :)

I believe that I responded to that paper at least once. By my memory, the formalization of Bitcoin's security left room for a polynomial time attack on the system. That is a fine restatement of what we already know about Bitcoin, but:

1. It is irrelevant to this thread, because I was only talking about Satoshi's paper.

2. It is not the sort of security people demand out of other cryptosystems. There is a reason nobody uses this:

https://en.wikipedia.org/wiki/Merkle%27s_Puzzles

Re: I Am Not Satoshi

#173
post #143

Earlier quoted context omitted.

Well he stopped saying there was no formal security analysis once someone linked him to one, I think. :)

I believe that I responded to that paper at least once. By my memory, the formalization of Bitcoin's security left room for a polynomial time attack on the system. That is a fine restatement of what we already know about Bitcoin, but: 1. It is irrelevant to this thread, because I was only talking about Satoshi's paper. 2. It is not the sort of security people demand out of other cryptosystems. There is a reason nobod…

If someone could link me to the paper in question, I would really appreciate it.

Re: I Am Not Satoshi

#174
post #152

Earlier quoted context omitted.

Why does it really matter who Satoshi is? He didn't do anything illegal so why should anyone try to uncover his identity even though he's chosen anonymity for himself?

You could argue that it's in the public interest to know who created Bitcoin and why. What if Satoshi were a NSA stooge and the algorithm had currently-unknown weaknesses that would allow a selected group of in-the-know people to generate BC at rates much higher than regular miners? Cryptography does not lie, but we often don't know what (or how) to ask the right questions. Satoshi's identity could help shape those q…

As far as I know, everything is open source, and I'm sure that some cryptography experts already analyzed that.

And even if no one did, it is obvious that the person/organization that started the whole thing would have the highest profit by definition without the need of any backdoor.

Just look at how many Bitcoins Satoshi made at the start, when competition and mining difficulty was low.

But yes, I share your concerns, since it could be a pyramid scheme.

The one that starts it profits the most, everyone that enters the game later earns less but hopes that the value increases as long as more and more new players are joining.

And this currency is deflationary by design, which obviously helps driving profit expectations for everyone. (why the hell would you want deflation in a currency? Deflation reduces circulation which defeats the purpose of a currency)

Re: I Am Not Satoshi

#175

Earlier quoted context omitted.

That's a positive thing, because it only grows trust between members of community.

I don't think so; witch hunts didn't exactly grow trust between people in the middle ages. Witch hunts grow mob feelings between people against whoever happens to get crushed by their collective paranoia that day.

Pedant's note: Contrary to popular belief, witch hunts were rare in the Middle Ages. They took off in popularity during the Renaissance.

Re: I Am Not Satoshi

#176
post #169

Earlier quoted context omitted.

Looks like they posted a retraction: http://money.cnn.com/2013/11/27/technology/bitcoin-silk-road... I hope they also apologized.

So, they put forward a theory, it turned out to be wrong, they said "ok, we agree, we were wrong". I think this is how the science is supposed to work, not? Vast number of theories and ideas are put out and most of them prove to be wrong, some prove to be true. I think it is a very normal and healthy process and I wonder why so many people feel the need to attack the researchers personally just because one of their i…

Because their theory inculpated a person (Satoshi) with criminal activity and they were wrong. That is why an apology was appropriate. This isn't just a matter of scientific incorrectness - someone's reputation was attacked.

Re: I Am Not Satoshi

#177
post #173

Earlier quoted context omitted.

I believe that I responded to that paper at least once. By my memory, the formalization of Bitcoin's security left room for a polynomial time attack on the system. That is a fine restatement of what we already know about Bitcoin, but: 1. It is irrelevant to this thread, because I was only talking about Satoshi's paper. 2. It is not the sort of security people demand out of other cryptosystems. There is a reason nobod…

If someone could link me to the paper in question, I would really appreciate it.

A little late, but I believe this is the paper mentioned: https://socrates1024.s3.amazonaws.com/consensus.pdf

Re: I Am Not Satoshi

#178
post #83
post #5

If his statement is true the "research" by Dorit Ron and Adi Shamir seems more than just accidentally flawed, not to say even highly misleading.

Well, he said that the research was funded by Citi bank's 'philanthropic' foundation. Is he mentioning that to insinuate that a bank is trying to produce de-anonymizing scare research about Bitcoin, which need not be true so long as it shakes consumer confidence? I suspect it's just very easy to get funding for Bitcoin related research right now because it's a hot topic, but that would be a much more fun explanation.…

In theory I would like to assume that especially seasoned academics are more concerned about their reputation than a few thousand Citi bank dollars.

Re: I Am Not Satoshi

#179

Earlier quoted context omitted.

I don't think so; witch hunts didn't exactly grow trust between people in the middle ages. Witch hunts grow mob feelings between people against whoever happens to get crushed by their collective paranoia that day.

Pedant's note: Contrary to popular belief, witch hunts were rare in the Middle Ages. They took off in popularity during the Renaissance.

Annoying meta-pedant note: You presumably mean that witch hunts mainly occurred in puritanical areas, at a time in which the Renaissance was occurring elsewhere in the world.
Post reply on HN