NSA Backdoors and Bitcoin (2013)
chrispacia.wordpress.com
chrispacia.wordpress.com
I think the important fact is not whether secp256r1 has a backdoor, but the decision of selecting secp256k1 by Satoshi Nakamoto for the use in Bitcoin. At the time, secp256k1 was the only widely-implemented non-P curve in various crypto libraries, and almost nobody used it at the time. It seems the entire decision of using secp256k1 was made to avoid secp256r1. This is another piece of evidence that Satoshi Nakamoto must have beee active in the 1990-2000 cypherpunk community, so that he was well-aware of those discussions. This should shed some light on his possible identity.
--
[0] DJB's paper how to manipulate curve standards [2] is DJB's attempt of creating the strongest argument for this claim. But even in his analysis, overall it's not too plausible, there's little evidence that such a class of secret curves exists and it required huge computation (2^80), it's on the edge of what was possible, but the pseudorandom parameter selection is certainly technically unfavorable as he demonstrated.
I was well aware of all that, at the time and now, without being active in the cypherpunk community. Granted, I was in college for a CS and math degree, but the cypherpunk community was pretty loud if you were listening at all.
Ok I think it's our civic duty to follow pg_is_a_butt around and upvote his comments :D pg_is_a_butt 10k karma or bust!
I dont think so .... that's just noise. He might have just asked around and received advise from friends/colleagues or random stranger what should be avoided. You are reading too much into this. This sheds no light on possible identity. Only identity it sheds light on is how your mind works with tiny information and how you confuse noise for signal.
I'm not sure why you would take such a strong position that amounts to 'nope just noise'.
When I claimed that Satoshi was active in the cypherpunk group, I didn't say that I was also thinking about the citations in the original Bitcoin paper, specifically, Wei Dai's "b-money" or Adam Back's "Hashcash", both came from the infosec community of the late 90s, and they are something that a member of the cypherpunk group should be intimately familiar with. An additional piece of information about his avoidance of using secp256r1 curve fits into the narrative well, and they can be circumstantial evidence if you buy into it. Also, I wasn't being serious at all, I mentioned it simply because it's just an interesting idea related to the original article and other readers may find the idea interesting as well, and I used the phrase "shed some lights", which, according to Merriam-Webster, is a phrase that means, "to make it possible to understand or know more about something", not a bad choice. Unfortunately, I misused the word "evidence", a pretty strong word. I should have used "circumstantial evidence" or "hints". while I was typing the original comment, I was also thinking about the possibility that Satoshi wasn't an active cypherpunk in the 2000s but simply a follower who had read the mailing list archive after the group became inactive, but I didn't mention either. I was not writing a background check for Satoshi, there's enough good articles on the Web.
When nonefromabove was replying my comment, nonefromabove, who was being unaware of anything of the above, must have deduced that I was fallen into the "connecting-the-dots" fallacy, or having a somewhat conspiracy theorist's attitude on Satoshi's identity, and I was being completely serious about it. Meanwhile, I was well-aware of the cognitive bias of overfitting data, and I was a fan of Nate Silver's The Signal and the Noise when his book came out. Nevertheless, I was told that I was "reading too much into this", and how "my mind works with tiny information and how I confuse noise for signal".
Perhaps, to avoid misunderstanding like this, we may use a "confidence" label, inc. "almost certain, likely, possible, unlikely", and a "tone" label, inc. "joke, casual, argument, serious", and so on.
If you wouldn't mind reading https://news.ycombinator.com/newsguidelines.html and participating in the spirit of this site, we'd be grateful. Your comment would be fine without the last sentence.
In a purported email [2] (reasonably well attested to) from Satoshi Nakamato, he claimed
> I didn't find anything to recommend a curve type so I just... picked one.
[1] https://web.archive.org/web/20140621062515/http://archive.wi...
You don't need curve magic to see the problem with Dual_EC; it's an RNG that works by transforming its state with a public key encryption primitive, which begs the obvious question "who holds the private key?". Dual_EC was so obviously problematic (and so slow) that many people, Schneier included, questioned whether it actually was a backdoor at all (full disclosure: I'm one of those people).
To believe the NIST curves generated from random numbers are backdoored, you essentially have to believe that there is a class of curves susceptible to some hitherto unknown attack that is large enough that NSA could find it by brute forcing hashes, but not so large that any other researcher got any inkling that the vulnerability existed. In particular: unlike Dual_EC, which is straightforwardly a backdoor, with its own special key, for NIST curves to be "backdoored" there has to be some underlying vulnerability in a particular curve structure to exploit. This isn't my argument, by the way; it's shoplifted from Koblitz and Menezes.
You shouldn't use the NIST curves! They're hard to implement securely. Curve25519 has better ergonomics and is much safer out of the box. But conspiracy-theoretic stuff linking Dual_EC to NIST curves is always painful to read.
Also the problem with Dual_EC wasn't just the bad design, but that they had (reportedly) paid RSA corporation to use it.
Until I started talking about this stuff on HN, it never would have occurred to me that anyone would think NSA had this benevolent reputation. Based on the timing, I suspect that's not because I'm encountering people with different priors about NSA, but rather that I'm talking to people with no priors about NSA.
Odd the article doesn't mention the obvious conclusion; that Bitcoin was designed by NSA, or folks with intimate knowledge of NSA's back doors. I've long maintained that a US government agency is the most likely developer of Bitcoin (mostly because no one else could sit on that kind of $$$ forever). NSA is the most obvious agency. The question is.. why? I can speculate on lots of reasons.
You are assuming Satoshi is sitting on money. Satoshi took care to hide it’s identity, and thus would have switched mining to different addresses very early in bitcoins history.
It would have been obvious to Satoshi that spending from a known address would blow it’s identity, so only did so for testing.
Satoshi may well be a billionaire and spending bitcoin every day.
People seem to take comfort in this idea that bitcoin was created by a government... because bitcoin seems radical when you first learn about it. However the attempts to create it date back a couple decades before it was created. Satoshi combined existing inventions with just the new element of his time chain.
But even if the NSA were behind it, what could they do? Anything they could do could also be done by someone with a math breakthrough. So whether the attacker is the NSA or not bitcoin has to be robust against it.
So where is bitcoin vulnerable?
It’s easy to imagine vulnerabilities in the cryptography, but hard to produce them.
Further, if you did, it doesn’t necessarily affect bitcoin. This is bitcoin’s genius. It’s not software, it’s a set of incentives. Show an error in the software, it will be patched and bitcoin will carry on. Worst case is a hard fork.
Insiders at the NSA (or any other TLA, foreign or domestic) also fit this description. The strongest position is to know both the truth, and the most compelling misconceptions.
Freedom and human rights need financial backing, and bitcoin does that.
They are simply incapable of valuing any other human being, let alone comprehending that such human being might have superior knowledge in any area.
After all, the narcissist is the supreme being. At least in their reality.
To be fair, “Unabashedly elitist” was a confession — if one were wise enough to recognize it.
Either way there’s no way a single person holds on to a wallet that size. It’s also less likely someone/some group in China or Russia could hold on to wallet that size without it being pilfered.
And the solution is easy: Satoshi mined initially to bootstrap bitcoin. He was the only one mining in the early days.
But then once there were enough other miners, all he had to do was destroy his private key.
If he’s greedy he just waited until he had enough bitcoin mined in other addresses that were never associated with him, before doing so.
Zero temptation. And hard to feel much regret... because he had opportunity to mine a great deal in those early years.
This is untrue-- we know other people who mined in the first days.
The way the initial released software worked, it wouldn't mine unless another peer was connected. So it's possible that there has never been a moment when there was only one party mining.
1) At some point during development he would have absolutely been the only one mining because the code only existed on his machine. 2) Requiring that another peer be available doesn’t mean that both peers couldn’t be run by the same person, even if they were run with different sets of keys. A peer in this case is a software construct, not a physical one.
Block 1 was created about 7 after the software was publicly released.
Whatever he did in development was thrown away, block 0 is an unspendable placeholder.
It the early 2010s it was billed as the Next Big Thing that was going to change the world. I’d argue Facebook has changed the world more than bitcoin, for better or worse.
Frankly, your response shows how revolutionary bitcoin is- it’s been ten years and you haven’t learned enough about it to understand it. That’s fine, most people haven’t, and bitcoin isn’t ready for the world to adopt it.
But not meeting your timeline expectations is not it’s fault. It doesn’t care.
If there were a backdoor and it leaked (or the math behind it was independently rediscovered!) the result could be catastrophic. Snowden showed that the NSA is absolutely vulnerable to leaks.
And decrypting cryptocoins is too obscure. For maximum effect, make the key able to break all encryption.
When someone puts some effort into making an indirect reference like that, they appreciate their work having been noticed. That's the role my comment was performing.
It doesn't completely preclude having a purposefully weak curve based on some publicly unknown weakness. ... but at the same time it also doesn't preclude the the curves having been selected to be stronger against some publicly unknown weakness (as was done with DES).
[Not that I'd recommend them.]
My comment was pointing out that those NIST curves like P-256 and P-224 can't have a trapdoor-- meaning a hidden secret key that allows the NSA and only the NSA to compromise the use-- in the curve themselves.
Some application of the curve could have its own trapdoor, as dualECdrbg did.
But when the space of potential attacks is an unknown-unknown, can we really constrain with confidence what attacks might exist? Maybe the prime group was chosen to have some relationship to a composite group for which the NSA knows the prime factors? I know this doesn't jive with our current understanding of number theory, but the point is it is hard to speculate about unknown-unknowns. Can we be certain that every crazy thing we think of is ruled out by our proven, not conjectured understanding of number theory?
[As an, aside, the NIST curves do not use random primes, E.g. P-256 is 2^256 - 2^224 + 2^192 + 2^96 - 1, which is a solinas prime with a pretty obvious performance driven structure. As is the case for all the other NIST P-whatever curves. Using primes chosen for field performance is pretty common, e.g. curve 25519 uses a crandall prime]
For really sensitive flows, perhaps dark fiber + non standard ciphers + encrypting the payload with application layer encryption using non standard or custom ciphers. I mean, why not, if it's your own B2B flows. Take an existing cipher / protocol and make a few subtle changes. It's just math.
For end-user encryption, that would take some more thought and would probably get into layers of turtles.
Ages ago, I used to change up a rubix-cube for a friend. The more I changed it, the quicker he could solve it. If I made just a very subtle change, it would take him up to an extra 7 seconds to solve it.
This has nothing; and I do mean nothing to do with your Rubik’s cube analogy. One small tweak and the whole thing may be utterly worthless. It’s like if you were tweaking the starting position of the Rubik’s cube with a nuclear warhead.