I agree the required power must have grown since 2014. But not knowing by which factor, one can only assume it's still feasible.
I can't find any source for it, but I remember reading not so long ago that 2 or 3 mining pools were responsible for 2/3 of the total bitcoin mining power. That's not something in favor of trusting the blockain as infallible.
https://blockchain.info/charts/hash-rate?timespan=all
2014 -> 10,436 TH/s 2016 -> 1,536,337 TH/s
Bitcoin may be wasting enough electricity to put it out of reach of small-time attackers, but a nation adversary could outspend it for as long as necessary.
If a nation state invested in permanently disabling bitcoin that would require a big investment in ASIC's, at which point I imagine a bitcoin fork would be introduced with a slightly different PoW, but that's just speculation.
And then what? Either you're falling back to mining on CPUs or GPUs, which the attacker would presumably have a large amount of, or you're manufacturing a new batch of ASICs, which is just as expensive for you as for an attacker. The point remains that an attacker can win by spending only slightly more money than the defender.
Whether that's "worth the investment" is up to each individual actor, apparently it hasn't been yet.
It's actually only slightly more than the sum of the defenders (assuming as we are for the sake of argument that everyone is buying efficiently). If what you said was true BitCoin wouldn't even have gotten to where it is now.
> Maybe people will realize that this is not a foolproof solution and that it can "easily" (you only need computing power, a.k.a money) be beaten.
This same argument can be leveled against just about any form of cryptography. With enough computing power you can decrypt anything. No cryptography is perfect, it can only be strong.
For a lot of crypto the amount is magnitudes larger, and working for thousands (or millions) of years to break it.
I agree that the 51% attack is unlikely on BTC now, but it doesn't bear comparison to (for instance) brute forcing an AES-GCM message...
My point is just that, if you have a blockchain with sufficiently high (and distributed) hash power (relative to the amount of computing power any individual actor/group can obtain), then in theory, you start being able to make strong guarantees about consensus.
It is the same with blockchains. It is just that there isn't one that exists (yet) which has enough distributed hash power where it's infeasible for any actor/group to ever get 51%. Bitcoin is just the best example so far, some might argue it's still in its early stages, or that another blockchains will surpass it.