You're missing a word: "...flaw in cryptocurrency-centralization entities". Actually cryptocurrencies are achieving the opposite: they're decentralizing security.
Exchanges are just a bridge to that world.
You're missing a word: "...flaw in cryptocurrency-centralization entities". Actually cryptocurrencies are achieving the opposite: they're decentralizing security.
Exchanges are just a bridge to that world.
I think nodesocket's point was that to expect the run of the mill computer user, who barely understands what a browser is, to have the security chops to withstand constant attacks from people who not only know what a browser is, but have also devoted substantial time to understanding as many exploits to the crypto-currency systems as they can and who have monetary incentive to continue refining that understanding in pursuit of most likely consequence free(apart from their soul) illicit monetary gains, to look at the dynamics at play here, it is not a stretch to assume that expecting widespread adoption in any form is likely to be a losing proposition.
What does "decentralizing security" mean? Everyone with any currency to protect will have to implement the digital equivalent of 36 inch fortified walls? Why would they want to do that when most people are satisfied with outsourcing this to service providers who specialize in such things?
For some scenarios there is a case to be made for "user defined security" or some-such, possibly even a few legitimate ones that aren't socially hostile. But it's hard to make any convincing case(without using any "semantic sugar," "empty calorie" buzzword-laden phrases like "decentralizing security") against nodesocket's point that the lay of the land of crypto-currency seems hopelessly tilted towards those who would like to exploit it in these ways.
Most people refuse to invest in Bitcoin because of the possibility of a crash, so this is a completely pointless challenge.
I was simply explaining that many crypto-currency systems are demonstrably more adversarial and user-hostile environments than most other currencies. Not only are they more adversarial, they are more adversarial in a way that most computer users aren't equipped to comprehend.
That's why we invented hardware wallets, which physically separate coins from the computer. You don't need to be tech savvy to use one. And to date, there hasn't been a single case of bitcoins stolen from a hardware wallet.
As someone trying to get into blockchain stuff, this is kinda wild.
Also, what exactly is a wallet? If the coins are really just outputs in a hashed block how do you 'access' them?
A wallet is a userland abstraction where it groups together all of your keypairs.
With each keypair (ECDSA) you have a public and private key. The address is derived from a hash and encoding of the public key. The private key is used to sign a script that unlocks the transaction outputs you have access to.
For this reason, your balance is also a userland abstraction. A balance is the sum of all the outputs you have the ability to unlock by signing the input.
Whats important to understand about transactions is that you need to spend the entire input. If you have 10 coin sitting in an output and want to send 7 to someone, you need to structure the transaction so that the 3 change goes back to you as well
The way fees work is that the miner picks up any difference between the outputs and the input, for ex.
10 input => output 1 = 7btc to address1 (recipient)
=> output 2 = 2.9btc to address2 (change)
=> diff 0.1 btc transaction fee
You now have a balance of 0 in your input address, and you're left with 2.9btc in your change address which will become the input on your next transactionThere is no reason why the change address cannot be the same as the input, but it means a loss of privacy since you can then see the 2.9 btc was change, thus output1 was the recipient, and you link the future transaction back to yourself as well.
If you then want to send 11 coin to someone, you can combine other inputs:
2.9btc input => output 1 = 11btc to address3 (recipient)
10btc input => output 2 = 1.89btc to address4 (change)
=> diff 0.1 btc transaction fee
This is how wallet identification works as described in the OP - you can assume that any inputs shared in a transaction are from the same owner since they were signed together. If you parse the blockchain and continue grouping common inputs like that you end up with a graph of wallets. Sometimes it only requires a single transaction to group together entire clusters - especially if you're using wallet software that selects inputs to use in sequence, doesn't create change correctly, or if you sweep all your smaller and smaller inputs into an aggregate addressWhat the original wallets did, and what OP explains, is they would pre-generate the next 100 keypairs and add them to the end of the list, and with each transaction that requires change it would move the pointer for next change address up one
All of your addresses start as either receive addresses, or as change addresses, and end up becoming your balance addresses until they are spent
To backup these wallets you had to backup every key pair, which is why most modern wallets use deterministic keys usually derived from a mneumonic. HD wallets use a master key pair, where the private key is usually derived from a mneumonic. That key pair is then used to generate the key chains that are used as receive and change addresses. It means you only need to backup your master keypair or your master mnemonic and can then generate and check all the key chains
The new wallet format is defined in bip32 [0] while the mnemonic to generate seeds is defined in bip39[1] - which you can test using a browser client app[2] (don't store coin using these - generate them securely)
Most wallets now support these deterministic wallets, including bitcoin core
The three main wallet types are full node, thin node (SPV) or web wallet
You can run a full node with Bitcoin Core[3] or Bcoin[4] (a Javascript implementation) - both support pruning the blockchain at a specified block height
The most popular SPV clients are Electrum[5] cross-platform, breadwallet for ios/android[6]. SPV uses block headers and peer queries (sometimes using bloom filters for privacy) to query your unspent transaction outputs and to verify transactions (there are variations of the architecture). The bcoin project also allows you to run an SPV client in the browser or via node (i'm really starting to like this project - they were the first to implement p2p authentication and encryption which is specified in bip150/bip151)
Electrum supports Trezor and hardware wallets, multisig wallets, 2FA wallets and have their own mnumonic and deterministic wallet format (but it also just involves saving a seed for the master key)
Web wallets store your wallet (usually) encrypted on their server and then unpack and decrypt in your browser client, then making HTTP API queries to verify transactions, get your unspents, broadcast transactions etc. The most popular are Blockchain.info[7] (disclaimer: I worked for them) and GreenAddress[8] - you can use blockchain.info via a tor hidden service at blockchainbdgpzk.onion
Good ways of getting started if you're more interested in the tech is Electrum (web wallets tend to obfusacte a lot of what is going on to make them easy to use), a full node with Bitcoin Core or running bcoin - and running them on testnet so you can build and broadcast your own transactions without fear of losing funds (the scripting language has also evolved a lot).
The other Javascript lib you can use to create transactions is bitcoinjs-lib[9] - there are libs available for deterministic wallets and some good transaction/script abstractions.
[0] https://github.com/bitcoin/bips/blob/master/bip-0032.mediawi...
[1] https://github.com/bitcoin/bips/blob/master/bip-0039.mediawi...
[2] https://iancoleman.github.io/bip39/
[4] https://github.com/bcoin-org/bcoin
[7] https://blockchain.info/wallet/#/home
Yes, people will still refuse to back up their wallets by writing down the 12- or 24-word seed phrase, and others will get phished. They'll lose their funds, just as they already do with their Steam and eBay accounts. Your point is valid that Bitcoin allows a tremendous amount of control that many people will use first and foremost to shoot off their own limbs. But brain-wallet crackers are no longer a threat.
Stupid question here, but what is wrong with doing that?
Bitcoin addresses are (usually) based on ECDSA public keys. When you send Bitcoin to someone, you're saying "send this to whoever can sign for the following public key [XYZ]. Signed, [ABC]." You had private key [abc] for [ABC], and you got the bitcoin you sent from someone else who said "send this to whoever can sign for the following public key [ABC]. Signed, [MNO]." ("said" means published to the global blockchain ledger.)
Back in the bad old days, the Bitcoin app would generate a new private/public key pair for every address. This meant that if you didn't back up wallet.dat frequently, you were screwed because your old backup might have only the old keys in it, not the new ones since the last backup.
The BIP32 scheme works kind of like this (simplified):
24 words -> 256-bit secret, called [defghi].
To generate a new address, take [defghi] and add a path to it, like "44/0/0/1" and then do a cryptographic hash on it, creating a new secret: [defghi-44/0/0/1] -> [jklm]
Then [jklm] becomes one of the private keys in your wallet. Next time you need another key, use "44/0/0/2," "44/0/0/3," etc.So what's nice about this is that the 24 words are the only thing you need to reconstruct your whole wallet. You no longer have to keep on backing up your Bitcoin wallet except for the very very very first time when you first create it.
But if you don't write down that list of words, and something happens to your phone/PC, goodbye bitcoin.
Or are you talking about other cybercurrencies that use different schemes to maintain consensus?
For centuries, banks have partnered with the state to monopolize their rents and profits at the expense of competitors. The ultimate example of this is central banking cartels.
> small group of miners
There is a small group of mining pools that together can block certain upgrades to the system. A couple of those pools combine to more than 50% of the hashpower. But they are pools, and pools are made up of lots of contributing miners, who may leave for another pool at any moment.
> small group of developers that choose what to implement
Relative to the total number of Bitcoin miners, company employees, or wallet users, the number of developers is the smallest group. Developers choose what code they wish to write, unless someone is paying them to write certain things. But developers cannot force anyone to run their code. Hence, the ultimate power of consensus is with the node operators of the system.
But all of this is beside the point that parent comments were making about the danger of centralized bank-like services such as exchanges. The decentralized, trustless nature of Bitcoin is such that you can download the client and verify your funds from the Genesis block until today, without needing to trust anyone.