Live data from Hacker News

Internal FBI risk assessment of Bitcoin network [pdf]

wired.com

131–140 of 152 posts

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#131
post #105

Unless I misunderstand Bitcoin more than I think I do, this is flat-out wrong (~1/3 of the way through the document): (U) What Users Can Do To Increase Anonymity ... • (U) Combine the balance of old Bitcoin addresses into a new address to make new payments. Combining balances just means you have a bunch of disparate nodes in the network which may not be related, and you are intentionally connecting them. So if you co…

Actually, I think the suggestion in the report is correct.

I think that what they are getting at here, is the following scenario:

Imagine that you have several addresses, with different balances, in the same wallet. If you do a payment using the normal client, which requires the total balance from all those addresses, this will create a transaction with all those addresses as inputs. In the Bitcoin protocol this provides unambiguous proof that the input addresses are all controlled by the same user. (With some provisos: obviously wallet services overlaid on the network complicate this; as do some other more sophisticated uses of the protocol; but in general, at a protocol level, this is true).

So, that then shows any passively listening third party that all those addresses were under control of a single user. This knowledge can then be applied transitively, to consolidate ownership of large quantities of accounts. (We tried explain this in our paper: http://arxiv.org/pdf/1107.4524v2.pdf Fig 1.6)

What the report is probably getting at, is that an alternative thing to do, would be to instead send all the payments to a new account, in separate transactions. This would introduce a lot more ambiguity for a passive attacker - passive ownership assumptions become a lot less clearcut. You can still try make deductions, but its going to be much larger to do at large scale, and require more statistical assumptions.

Its not completely obvious that this is what the paper is suggesting, but thats my reading of it, and I think that makes sense.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#132
post #131
post #105

Unless I misunderstand Bitcoin more than I think I do, this is flat-out wrong (~1/3 of the way through the document): (U) What Users Can Do To Increase Anonymity ... • (U) Combine the balance of old Bitcoin addresses into a new address to make new payments. Combining balances just means you have a bunch of disparate nodes in the network which may not be related, and you are intentionally connecting them. So if you co…

Actually, I think the suggestion in the report is correct. I think that what they are getting at here, is the following scenario: Imagine that you have several addresses, with different balances, in the same wallet . If you do a payment using the normal client, which requires the total balance from all those addresses, this will create a transaction with all those addresses as inputs. In the Bitcoin protocol this pro…

Yeah, it's not a clear-cut connection if you do it in multiple steps. Hence the caveat that there are ways to make it (more) true. But what improvement in anonymity does it provide over leaving them separate? If they can't infer that X belongs to you, then if you don't send it to account Y (linked to you) you certainly don't leak that X belongs to you. If you do, it's not proof, but it certainly doesn't improve matters.

Don't take it to extremes - this can clearly be stretched to include running the whole process through mixers and back to a single address while improving anonymity. It doesn't say that. In principle, is combining addresses better for anonymity than not?

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#133

Given that Bitcoin records all transactions for posterity, and given the ongoing rise of "big data" analytics, I'd say Bitcoin is likely to be harder , in the long run, to use for shenanigans. A government currency has forms in which transactions create no paper trail. Bitcoin does not. Really the big disruption Bitcoin could cause if it becomes well established, is to act as a stable reference frame against which th…

Really the big disruption Bitcoin could cause if it becomes well established, is to act as a stable reference frame against which the other currencies can be compared What would make it any more (or less) stable than the traditional reference currencies of gold, ammo, and canned baked beans?

Bitcoin prices will be no more stable than conventional currencies, because money supply is a rate (BTC / sec) rather than a total volume (BTC). As commerce using BTC slows down so the money supply decreases. As commerce speeds up so the money supply increases. The exact relationship between the money supply and inflation complicated and somewhat controversial (see Wikipedia for more info), but there is no doubt that if, for instance, all the people currently holding Bitcoins as an investment were to sell them then the value of Bitcoins would drop, because the money supply would increase.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#134

Given that Bitcoin records all transactions for posterity, and given the ongoing rise of "big data" analytics, I'd say Bitcoin is likely to be harder , in the long run, to use for shenanigans. A government currency has forms in which transactions create no paper trail. Bitcoin does not. Really the big disruption Bitcoin could cause if it becomes well established, is to act as a stable reference frame against which th…

> It cannot be used as an instrument of fiscal policy, ...

Other than reserve requirements for lending bitcoins, accounting regulations for considering earned bitcoins as either cash income or accrued income, underwriting requirements for bitcoin-denominated loans, excise taxes on bitcoin transactions, and so forth.

Issuing currency is not the goverment's major control on the money supply.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#135
post #35

Earlier quoted context omitted.

Governments are cracking down on the use of cash in ways that will only help the promotion of Bitcoin. http://www.forbes.com/sites/jonmatonis/2012/10/17/large-cash...

While I am ignorant of the situation in Spain, it is interesting to note that the two other governments detailed in the linked Forbes article have extreme organized crime problems. I am sure this says something about the role of the rule of law in the bootstrapping of trust. Integrating licit and illicit revenue streams will always be a foundational issue for any illegal enterprise. I have not looked deeply into the…

At present there isn't much you can buy with BTC. If the day came when EBay, Amazon and your local shops accepted BTC then that would change, especially if the local shops didn't require ID when you bought something.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#136
post #19
post #5

Nice document. It shows well the way of thinking of our governments. "detecting suspicious activity, identifying users, and obtaining transaction records is problematic for law enforcement." - That must deeply hurts FBI people :) "Despite the virtual nature of Bitcoin, users value the currency for many of the same reasons people trust Federal Reserve notes: they believe they can exchange the currency for goods, servi…

People do not trust "Federal Reserve notes" (or any other official currency) - they are forced to use it, since they must pay taxes in it. That doesn't explain why people continue to accept official currency in excess of their anticipated tax bill, or why criminals who aren't expecting to pay tax at all still deal in official currency.

> That doesn't explain why people continue to accept official currency in excess of their anticipated tax bill, ...

It is legal tender for debts. Offering currency to a creditor extinguishes the debt, whether or not they accept it.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#137
post #130
post #125

Earlier quoted context omitted.

You mean, connected to a constant stream of new addresses. And wouldn't finding such a cluster be NP-complete?

Finding clusters in graphs is a big research interest in the research group I'm part of. When we started looking at Bitcoin we thought that we would have to use such sophisticated algorithms to uncover interesting structure, but it turned out to be much easier than we expected to find structure and meaning, so we never got too sophisticated. There's a very active field of research on these cluster finding algorithms…

Thanks for the explanation!

I think the benefit of this cycling, though, is in the size, not the obscurity. That is, if 60% of the users (and 99% of the addresses) are cycling money to obscure connection to a person, then either:

- You have to accept that "Joe spent a bitcoin that was once in a crime" is insufficient evidence Joe had any connection whatsoever to it, since "most users have touched that bitcoin too"; or

- You have to make it a crime to be a part of such a cycler altogether, which would effectively require an outright ban on Bitcoin.

These conclusions follow no matter how much structure to the trades you can detect.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#138
post #132
post #131

Earlier quoted context omitted.

Actually, I think the suggestion in the report is correct. I think that what they are getting at here, is the following scenario: Imagine that you have several addresses, with different balances, in the same wallet . If you do a payment using the normal client, which requires the total balance from all those addresses, this will create a transaction with all those addresses as inputs. In the Bitcoin protocol this pro…

Yeah, it's not a clear-cut connection if you do it in multiple steps. Hence the caveat that there are ways to make it (more) true. But what improvement in anonymity does it provide over leaving them separate? If they can't infer that X belongs to you, then if you don't send it to account Y (linked to you) you certainly don't leak that X belongs to you. If you do , it's not proof, but it certainly doesn't improve matt…

I think what you're looking at is something more like, if someone employs this tactic, they can't identify that addresses X, Y, and Z belong to the same person, whether or not they know who that person is.

Linking together abstract pieces like that can be one of the first steps to figuring out a very anonymous network.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#139
post #7

> FBI assesses with high confidence that [...] malicious actors can [...] use botnets to generate bitcoins. As far as I understand bitcoin (which isn't too far, admittedly), the generation of bitcoins is actually encouraged, and only possible within some well-defined boundaries which basically just ensures that bitcoins are put into circulation up until it hits the fixed limit. Maybe someone could clear that up for m…

It's malicious in the sense that infected machine resources are being used to directly turn a profit for the controller. Other ways of profiting off botnets include renting out DDoS and spam capabilities.

Not just turn a profit for the controller, but incur a cost for the victim. I measured my computer the other day; when I start mining, my power draw jumps 160 watts, and I have a fairly efficient machine.

Re: Internal FBI risk assessment of Bitcoin network [pdf]

#140
post #19

Earlier quoted context omitted.

People do not trust "Federal Reserve notes" (or any other official currency) - they are forced to use it, since they must pay taxes in it. That doesn't explain why people continue to accept official currency in excess of their anticipated tax bill, or why criminals who aren't expecting to pay tax at all still deal in official currency.

> That doesn't explain why people continue to accept official currency in excess of their anticipated tax bill, ... It is legal tender for debts. Offering currency to a creditor extinguishes the debt, whether or not they accept it.

Exactly. We trust USD to be accepted as legal tender for debts.
Post reply on HN