Live data from Hacker News

It's Time For a Hard Bitcoin Fork

hackingdistributed.com

51–60 of 154 posts

Re: It's Time For a Hard Bitcoin Fork

#51
post #49
post #29

Earlier quoted context omitted.

From the bitcoin wiki: An attacker that controls more than 50% of the network's computing power can, for the time that he is in control, exclude and modify the ordering of transactions. This allows him to: Reverse transactions that he sends while he's in control. This has the potential to double-spend transactions that previously had already been seen in the block chain. Prevent some or all transactions from gaining…

You could theoretically mine your own chain from the genesis block right?

That won't work due to checkpoints and even if it did work it would be the equivalent of nuking the entire Bitcoin ecosystem.

It would be more profitable to do something like extending the current blockchain but charge 1% transaction fees.

Re: It's Time For a Hard Bitcoin Fork

#52
post #24

I was under the impression that the mining percentage would give you the same percentage chance to cook the books. 51% means you are more likely to succeed than fail in an attempt. Much like buying 51 percent of lottery tickets gives you a slightly better than even chance of winning the big prize. in that respect, wouldn't 51% be only marginally different to 49%. Both would be a bit of a concern, but neither would be…

No, 51% is vastly more powerful than 49%. With 51%, you essentially control the entire Blockchain because you can always create a new Blockchain that would be accepted by the network, given enough time. Always. With 49%, you can only get away with it a few times, and it's less likely you will mine the next 6 blocks. Essentially, as time progresses, with 49% you lose out, with 51%, you keep winning.

I think I understand now. That would still be a bit of a tricky position because it isn't so much 51% when you commit the fraud that is important it is the period following the fraud.

How detectable would such an action be? Wouldn't other systems be able look at the block and say "it's verified, but it don't look right to me"

Re: It's Time For a Hard Bitcoin Fork

#53
post #25

A hash pool at 51% is big news. If this isn't corrected soon, BTC is doomed to fail.

You're assuming that someone with a significant investment in the space would act dishonestly. That's the only reason BTC fails as the result of something like this. Seem like MAD to me, if they were to act dishonestly they would destroy their own investment and profit potential.

"Seem like MAD to me, if they were to act dishonestly they would destroy their own investment and profit potential."

There's more than a few entities with an incentive to seeing a decentralized network capable of replacing established methods of conducting financial transactions go away.

Re: It's Time For a Hard Bitcoin Fork

#54

Their Bitcoin is broken argument doesn't really seem to work. I agree that something needs to be done to stop huge amounts of pooling but this seems to be too alarmist. The initial Bitcoin is Broken post is at http://hackingdistributed.com/2013/11/04/bitcoin-is-broken/ and a counterpoint is at https://freedom-to-tinker.com/blog/felten/bitcoin-isnt-so-br... .

The argument in that counterpoint seems to be as follows:

1. Assume that selfish mining doesn't work.

2. Because selfish mining doesn't work there will be fair weather miners who will only mine on whichever chain is furthest ahead, defaulting to the public chain in the case of a tie.

3. Since the selfish mining pool won't be ahead all the time nobody will mine for it.

4. Therefore selfish mining doesn't work.

It's not what I'd term a strong rebuttal.

Re: It's Time For a Hard Bitcoin Fork

#55

You can't stop pool mining, even with a hard fork. Let's say you implement a restriction like "5 blocks in a row max for a given pool". GHash can split into GhashA and GhashB, and keep going.

That's not the kind of restriction that stops pool mining. The trick is to enable the pool members to steal the blocks they discover. Andrew Miller, a grad student at UMD, has an ingenious scheme for doing this. I am pretty sure I put the link in the article, under the first bullet in the "What to Do Now" section.

Wouldn't pool participants that use this extension to steal rewards be exposed to the pool simply due to their work being consistently challenged and thus lost?

i.e: The pool would notice that certain participants contributions are conflicting with other discoveries, and ban such participants?

Re: It's Time For a Hard Bitcoin Fork

#56
post #48
post #43

Earlier quoted context omitted.

The bitcoin protocol defines the longest chain as the correct/canonical chain. At 51% you have more hashing power than the rest of the network combined, so you can start mining blocks on your own and create your own chain with the knowledge that eventually your chain will be longer than the 49% chain everyone else is working on. When that happens, the 49% will abandon their chain and start working on yours.

What kind of chain length differential is enough to cause people to switch. Is it a single block?

Yes.

Re: It's Time For a Hard Bitcoin Fork

#57
post #52

Earlier quoted context omitted.

No, 51% is vastly more powerful than 49%. With 51%, you essentially control the entire Blockchain because you can always create a new Blockchain that would be accepted by the network, given enough time. Always. With 49%, you can only get away with it a few times, and it's less likely you will mine the next 6 blocks. Essentially, as time progresses, with 49% you lose out, with 51%, you keep winning.

I think I understand now. That would still be a bit of a tricky position because it isn't so much 51% when you commit the fraud that is important it is the period following the fraud. How detectable would such an action be? Wouldn't other systems be able look at the block and say "it's verified, but it don't look right to me"

Not really. There are always lots of 'versions' of the blockchain floating around. The network only keeps track of the longest chain (broadly speaking). This means the network with 51% can determine which transactions get into the blockchain. For example, if the pool owner doesn't like you, he can essentially 'blacklist' your account, which means your Bitcoins can become unspendable, basically. The longer they have the 51% power, the more damage they can do. GHash already performed what you describe as your '49% attack' against a gambling site that accepted 0 confirmation deposits. There has been no known instance of a 51% attack yet (e.g. double spend after 6 confirmations).

Re: It's Time For a Hard Bitcoin Fork

#58
post #25

Earlier quoted context omitted.

You're assuming that someone with a significant investment in the space would act dishonestly. That's the only reason BTC fails as the result of something like this. Seem like MAD to me, if they were to act dishonestly they would destroy their own investment and profit potential.

Then why are you using BTC in the first place? The US Fed and US Government has no reason to act dishonestly. The value of the dollar relies on us trusting the US Government / US Fed to protect it. If switching over to BTC means "trusting GHash.io"... then nothing has changed.

The difference is that if GHash.io launches an attack, miners have the choice to move to another pool. If the US government inflates the currency (yet again) there is nothing to do.

Re: It's Time For a Hard Bitcoin Fork

#59
post #32

This is the same panic-prone author (@el33th4xor) who, in early November 2013 with Bitcoin at about $220, wrote "@el33th4xor: You heard it here first: now is a good time to sell your Bitcoins" ( https://twitter.com/el33th4xor/status/397219415025934336 ) This was just before releasing some research that he thought would cause a confidence collapse. (That is, his prediction was almost self-consciously attempting market…

Nice ad hominems you've got there. >In fact, the paper just formalized some concerns discussed in the mining community for years. This is false. Discussed here: http://hackingdistributed.com/2013/11/09/no-you-dint/ >the "Bitcoin lunatic fringe" this author mocks has been right about the pool(s) having such power refraining from destructive (and self-bankrupting) next steps. No. The Bitcoin lunatic fringe was adamant…

I think your track record of alarmism and disrespect to non-academics is relevant, but even if you classify it 'ad hominem', you've earned it with your own prolific slurs of critics.

I've addressed your continued "no-you-dint" willful-blindness about earlier analysis elsewhere... including on your own blog at (http://hackingdistributed.com/2013/11/14/response-to-feedbac...). You failed to discover (and thus footnote) prior community work, from years earlier, that did everything except for your more-rigorous boundary formalizations. So again, nice write-up, but exaggerated novelty. The interested can follow the links and decide for themselves.

I'm sure someone said no pool would ever even try to get 51%. Others simply said a pool in such a position wouldn't self-destruct the entire ecosystem, against their own interests. (Instead, they behave like the 'stationary bandit' of Mancur Olson's political-economy. Not ideal, and not what Bitcoin intended, and worthy of attempted-fixes... but also not an instant and unsurvivable crisis.) It's this latter prediction, of stability even in the presence of explicit (or secret) 51% cartels, that is still, so far, outperforming your own. For now they have the same claim to "I told you so!" as you do.

Re: It's Time For a Hard Bitcoin Fork

#60
post #52

Earlier quoted context omitted.

No, 51% is vastly more powerful than 49%. With 51%, you essentially control the entire Blockchain because you can always create a new Blockchain that would be accepted by the network, given enough time. Always. With 49%, you can only get away with it a few times, and it's less likely you will mine the next 6 blocks. Essentially, as time progresses, with 49% you lose out, with 51%, you keep winning.

I think I understand now. That would still be a bit of a tricky position because it isn't so much 51% when you commit the fraud that is important it is the period following the fraud. How detectable would such an action be? Wouldn't other systems be able look at the block and say "it's verified, but it don't look right to me"

You'd see that every single block was mined by the same pool.
Post reply on HN