Password cracking, mining, and GPUs
erratasec.blogspot.com
erratasec.blogspot.com
If the value didn't go up people would stop mining. If people stopped mining the difficulty level would go down.
So basically the value of bitcoins will always stabilize at the cost of electricity for the most efficient rig.
But the efficiency of rigs changes constantly, but that is offset by the difficulty changing. So I'm not quite sure how the balance will stay longterm.
But in the short term the value is pegged to the cost of energy.
PS: I would also feel somewhat guilty wasting that much energy for so little net gain.
On the flip side, if you have a friend with data center space, you can usually buy electrity around $0.09/kWh - http://www.pge.com/tariffs/tm2/pdf/ELEC_SCHEDS_E-20.pdf.
So, running a 42U Rack of mining gear out of your data center would cost you 500 Watts * 42 * 24*30 =15,120 kwH or $1512/electricity month. It would cost you $4500/month to do the same thing out of your home.
D = difficulty (HASH/BTC)
E = marginal efficiency (HASH/kWH)
V = value of bitcoins (USD/BTC)
C = cost of electricity (USD/kWH)
then in equlibrium, the difficulty will be equal such that the electricity you can purchase with a generated bitcoin will just balance out the electricity required to produce it (neglecting depreciation of equipment, time value of money etc..):
D ~= (E * V) / C
So this predicts that equilibrium difficulty will increase when marginal mining efficiency increases (ie. more power-efficient GPUs are available), when the value of bitcoins increases, and when the price of electricity decreases.
(Note that there is no guarantee that the system will reach equilibrium - the relatively long time lag taken for the difficulty to adjust in the protocol may mean it doesn't).
It is also notable that you can rearrange to solve for `V`, allowing you to determine an estimate of the underlying theoretical value of bitcoins based on the current difficulty level, the efficiency of the best GPU now available, and the price of electricity.
(As long as the number of students with unmetered power partipating is small compared to the number of miners, it shouldn't significantly affect the analysis. It's the marginal cost faced by a new entrant that's of interest - a relatively small number of students mining simply adds a background base level of difficulty).
http://ncix.com/products/index.php?minorcatid=1323&submi...
As for Bitcoin mining being profitable, the difficulty level is going up quite quickly so the days of quickly recouping your hardware costs seem to be waning.
As has been mentioned previously on HN, smart sysadmins use bcrypt making the entire password cracking exercise nearly impossible.
It is a bit old, but not so old that you can't determine what a good length is. More importantly, it is not always about the length, where something like "alpine fun" (two common words) may take a couple months, but just adding in "this is fun" (three common words) gains you thousands of years in time.
Before reading, I was under the impression that without a password manager, it has become impossible to secure passwords by memory as GPU's became more powerful. My impression was that "random", alpha-numeric, plus non-alpha-numeric characters, and, of great length would be needed.
This article leads me to believe otherwise, and that something like "this#is#my#password" should be sufficiently uncompromisable for some time to come. It is also highly rememberable to me.
There was a youtube video linked, I believe from HN, apx. 3 weeks ago, that showed a demo of GPU password cracking that was a bit more illustrative than this article, and more current. Unfortunately, I can't seem to locate it.
2 - also, using more words is, in the context of the article you linked to, related to dictionary attacks. and again your article is pretty poor since it's giving an example with very common words which implies that a very small dictionary would be needed. i would not call "this is fun" a safe password.
3 - the article you link to is again misleading in that it completely ignores password helpers and puts too much emphasis on local restrictions like reducing login rates. it seems like it was written before both the web (we are seeing lists of passwords being stolen - that makes "restricting retries" completely irrelevant) and gpus were common. i would not use it as a reliable source of advice.
Remember that the article is about today's state-of-the-art. Next year, cracking algorithms might be better, GPUs will certainly be better, EC2 spot instances might be cheaper, and dictionary guessing algorithms will be smarter. A 50-character random password loaded with symbols, digits, and letters is good in the face of that.
Also, the article failed to mention the risks of compromised password databases. Sure, the attacker could just gain access to the actual files he or she wants while bypassing the login step, but the list of username/email and password credentials are a major threat to users. Most users only have a handful of passwords, and an attacker could leverage the one they know to find the ones they don't. Password managers are necessary for this reason, to provide unique passwords to each protected site. If password managers become wide spread, then why not let them remember arbitrarily long and complex passwords. It can't hurt, right?
Bitcoin was created as a secret government project to inexpensively wage cyber warfare. Thousands of hopeful BTC prospectors invest in ever-increasingly efficient hash-cracking rigs, creating a sleeping botnet of cyber-soldiers. When the time comes, the government takes control of these machines (possibly silently). Instead of cracking bitcoin blocks, they are now all cracking nuclear launch codes of enemy states. That's a movie I would see.