Live data from Hacker News

Bitcoin Exchanges Under ‘Massive and Concerted Attack’

coindesk.com

81–90 of 218 posts

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#81

Earlier quoted context omitted.

In what way is that different from fiat money? You can keep fiat money in your mattress and spend it anywhere that accepts them. If you have $100 in a mattress (offline) then you would still have it tomorrow. The problem is that the moneys value may change tomorrow, especially if we are talking about bitcoin.

You can't secure cash under your mattress with a password, for one thing. That makes cash (and paper wallets) venerable to physical attack, even by vermin: http://metro.co.uk/2007/03/27/mouse-eats-cash-machine-makes-... There is no problem with value changing tomorrow as this is a potential problem with any new payment methodologies. Adoption does not appear magically overnight. The US Dollar is velocity stable due t…

If someone is going to physically break into your house and access your money what's to stop them from physically assaulting you until you give them the password? Or just taking the computer that stores the "offline" wallet?

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#82

What was the intent of including something like transaction malleability in the Sotahsi client?

It's a bug. Signatures have multiple equivalent forms, and the clients don't require that representations are canonical.

>The first form of malleability is in the signatures themselves. Each signature has exactly one DER-encoded ASN.1 octet representation, but openssl does not enforce this, and as long as a signature isn't horribly malformed, it will be accepted. In addition for every ECDSA signature (r,s), the signature (r, -s (mod N)) is a valid signature of the same message.

https://en.bitcoin.it/wiki/Transaction_Malleability

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#83
post #62
post #40

Earlier quoted context omitted.

I can't find the article now, but there have been several good articles explaining the lack of gravity on bitcoin in general. Basically, the price goes up quickly when new people are attracted to bitcoin and rush to buy. When the price dips however, because so much is bought for long term speculation, the price doesn't really dip much, as no one is incentivised to sell and hold out for when it gets better. At some po…

Also worth noting: you can't buy bitcoins on margin. So no margin calls to suddenly detonate the market.

You can p2p lend and borrow btc here: https://www.bitbond.net/

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#84
post #4

It's interesting to watch actually, submit a transaction to the network at the moment and there's a rogue node that will mess with the padding of the signatures and rebroadcast it faster than the original. It confuses the reference client into duplicate display, which is what Gox is relying on for the failed/success display. That they're winning races over the normal related transactions isn't that unnatural as the t…

There's also a story here about responsible disclosure. People are making the case (and I tend to agree) that Gox should have contacted the other exchanges in private to discuss this problem before going public with it. There's a very good chance this widespread attack is a direct result of Gox's announcement.

The attack started prior to the disclosure.

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#85

Earlier quoted context omitted.

No, even if you successfully achieve a 51% attack, you can't spend coins from arbitrary wallets.

Well, you could control the blockchain, wouldn't that include spending coins from any wallet?

No. Transactions have to be signed by a private key matching the from address.

The double spend attack works by convincing the other party that the transaction has completed (so they release whatever escrow is in place) and then replacing the blockchain.

(But a botnet infection could watch for wallets on a computer and cause the coins in the wallet to be spent)

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#86
post #40
post #10

Earlier quoted context omitted.

Also worth noting is the fact that the Bitcoin Price Index has been massively resilient to all the bad "news" thats been pouring in this month. It has been consistently hovering around the 670-700 mark.

I can't find the article now, but there have been several good articles explaining the lack of gravity on bitcoin in general. Basically, the price goes up quickly when new people are attracted to bitcoin and rush to buy. When the price dips however, because so much is bought for long term speculation, the price doesn't really dip much, as no one is incentivised to sell and hold out for when it gets better. At some po…

This sounds like a general analysis of most bubbles in history - nothing very specific to BTC.

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#87

Earlier quoted context omitted.

No, even if you successfully achieve a 51% attack, you can't spend coins from arbitrary wallets.

Well, you could control the blockchain, wouldn't that include spending coins from any wallet?

No. The wallets are protected with public/private key cryptography. Controlling the block-chain simply lets you control whose transactions get processed, and hence potentially allow someone to attempt to double spend their money. You could also prevent other people from spending their money entirely.

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#88

Earlier quoted context omitted.

No, even if you successfully achieve a 51% attack, you can't spend coins from arbitrary wallets.

Well, you could control the blockchain, wouldn't that include spending coins from any wallet?

You don't "control" the blockchain in the strict sense. To generate a transaction from one address to another, you must know the private key corresponding to the sender's address. Without that, the transaction is invalid, and no sane node will accept block containing such transaction.

When you have 51% of mining power, you can do a lot of nasty things(like stopping confirming transaction at all), but not spend someone else's bitcoins.

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#89
post #40

Earlier quoted context omitted.

I can't find the article now, but there have been several good articles explaining the lack of gravity on bitcoin in general. Basically, the price goes up quickly when new people are attracted to bitcoin and rush to buy. When the price dips however, because so much is bought for long term speculation, the price doesn't really dip much, as no one is incentivised to sell and hold out for when it gets better. At some po…

Wow this makes a lot of sense. I personally believe that this is yet again another one of BTC's large dips that will eventually recover onto it's upwards path. But then if people panic and see how hard it is to get back into fiat from BTC won't they just go into relatively stable altcoins instead? For example DOGE is skyrocketing as we speak and it's USD price was totally unaffected by BTC's recent plummet. http://co…

Is doge inmmune to this multiple hash malleability feature?

EDIT: "If" -> "Is".

Re: Bitcoin Exchanges Under ‘Massive and Concerted Attack’

#90

I've not bought in to Bitcoin yet. It just seems like a massive, world-wide scam to me. I'm not saying that it is a scam, I'm just saying that Bitcoin is something that I don't really understand, and so I don't entirely trust it. That said, this event is extremely encouraging. Not only is the security and the viability of the currency being tested. But more importantly, the communication and cooperation between the m…

>That said, this event is extremely encouraging. Not only is the security and the viability of the currency being tested. But more importantly, the communication and cooperation between the major players in the Bitcoin ecosystem is being tested. And so far, the community is kicking ass.

If this was two major banks and they said they had to stop withdrawals for 1-3 days to fix a software bug that's been exposed through a concerted attack, one they already knew about and could have prevented, I don't think you would be saying the same thing ...

Ultimately this might prove a footnote in the Bitcoin story, or it might be the harbinger of more trouble, who knows. But I do think it takes quite a bit of spin to think of this as somehow being encouraging or a net positive. I think if this had maybe stopped at Mt. Gox, an exchange that was universally considered a bad player, you could think of it has good overall (ignoring the fact many people would have still been screwed over). But it seems clear it's gone beyond them.

Post reply on HN