Craig Wright will never sign a message with the original private keys or move the coins in a way that proves his involvement or ownership of the first mined coins. He is a fraud.
Craig Wright will never sign a message with the original private keys or move the coins in a way that proves his involvement or ownership of the first mined coins. He is a fraud.
Edit: I see. It's confusingly worded but that makes sense.
There is a better way: make the nonce a hash of the message signature and the private key. That way you don't need any randomness, and the entire algorithm is deterministic. It is guaranteed (assuming the hash is good, but you need a good hash algorithm to sign things anyway) that no two messages will be signed with the same nonce, and that the nonce cannot be guessed without already having the private key. This is what EdDSA does.
One could just as well implement something EdDSA compatible with insecure nonce generation and people have done so (for years the thing you got when you goggled for eddsa python was just such an implementation).
It's good that the eddsa paper specifies more of the system, as people have made bad choices and ruined the security-- but even it fails to completely specify the system: the exact input handling isn't specified, which has resulted in security problems.
It's not just about specifying more of the standard either. EdDSA is designed to be harder to screw up an implementation of, by construction.
While I not a FIPS certification expert by any means, it was intended that implementations could implement RFC6979 without breaking the standard by simply using a standard allowed DRBG in the right way.
> EdDSA is designed to be harder to screw up an implementation of, by construction.
That's the marketing claim at least. It's debatable. Some of its choices make it easier to screw up, and widespread implementations of it have also been wrong in the varrious ways it was intended to address. It's a good idea to try, at least, for sure.
I think nonce security in particular is not at all the best example since modern ECDSA implementations are secure against in that respect. I'm also aware of some systems which have had grave security flaws because they believed the EdDSA claim of a deterministic signature meant that it was a unique signature. The promotion of EdDSA itself as magic pixie dust creates vulnerabilities.
There is just no replacement for understanding. :)
You can, but you can also do a lot more than that. Thinking that this is the only attack is a common error, and precisely the one Wright was making in that recording.
Two signatures with different messages and the same key and message is just a special case of the fact that if you write out the signing equation as a linear system with privkey and nonce being unknown, and the message and signatures being the knows if the resulting matrix is exactly determined or over-determined, then you can solve for the unknown values.
It would also be the case that if you had two signatures with the same key and the nonces being any known multiple of each other that it's just as solvable.
There are other attack approaches, for example if you have a set of signatures where you know the leading bits of the nonce you can also recover the keys by solving a hidden number problem. (If you only know the single leading bit it'll take a few hundred signatures).
Cryptosystems are inherently fragile. The security assumptions of these schemes demand a uniformly random nonce. Deviation from the required property easily destroys security in practically exploitable ways.
The person Wright was arguing with was pointing out that if Wright had the private keys in question -- turns out he didn't-- it wouldn't be impossible that he obtained them after observing a single insecurely generated signature. Wright drove the discussion down a tangent with an argument that one couldn't recover a key with a single signature-- a false claim, but even if it were true it wouldn't really have supported his case.
That's what we did to get the PS3 signing keys. Accidentally became a bit of a citation in the ECDSA world for that one too; who knew Sony would unwittingly earn the title of "canonical example of how to screw up ECDSA in a consumer product"? :-)
It's also how lots of Bitcoin have been taken away when transactions are signed using broken random number generators. These days people are running bots to spot those keypairs and automatically take the bitcoin.
That's false.
Dr Nicolas Courtois - "Well, uhhhum that's the question."
Craig Wright told him that he used non-standard nonces, not predictable ones.
What is sad is that anyone is even talking about this guy. From the beginning people pointed out he is lying and yet he is still somehow able to be talk about.
Most obvious con-man that is still able to stay in public spotlight.
He could offer his services to various blockchain-focused startups in which he'll fit right in considering said startups' objective is often to get money off clueless VCs by throwing the "blockchain" buzzword around (there are very little legitimate use-cases for a blockchain that can't be served by a traditional database, and a truly decentralized blockchain can't easily be monetized to the level a VC would want).
You don't even have to believe him - you'd just have to believe (or see viable risk/reward) that he has a shot at a successful legal attack.
Wright claims to own around $50 billion dollars worth of cryptocurrency which he cannot access.
Let's say he manages to convince you that he has 1% chance of success at obtaining these funds-- something you could believe even if you know he's a fraud, you just have to have a low opinion of the courts and misunderstand how Bitcoin works (which many people do, see this discussion!).
If offers you a 10% stake in his victory, what would you pay for that? Well under the 1% assumption you might be willing to pay $25 million dollars (half the expected value).
The buyers error is just in flawed reasoning about the odds of success, but people are notoriously bad at reasoning about fringe events and a lot of people don't understand Bitcoin.
For Wright, the fact that his effort cannot be successful is actually a very good property: It means that he can safely sell more than 100% of his fictional fortune: He doesn't have to worry that he'll win and then have to pay out >100%. Instead, he'll lose and tell his investors "Sorry, gave it our best shot but you always knew this was a risky deal!". In that case his income from the scheme is only limited by how many suckers he can bring in... 100 people paying 25m for a '10%' stake would yield a 2.5 billion dollar windfall.
And if you don't think there are at least 100 suckers out there with 25 million to blow you haven't been paying attention to all the defi/ico/nft noise the last couple years.
Right now we know of one major self-claimed billionaire that Wright is exploiting, but there may be many others-- particularly in Asia where language barriers make it much easier for Wright to isolate victims from discrediting information.
May 2nd, 2016:
https://web.archive.org/web/20160502071722/http://www.drcrai...
May 7th, 2016:
https://web.archive.org/web/20160507165900/http://www.drcrai...
If he really were Satoshi, he could literally prove it in 4 seconds beyond any shadow of a doubt. Instead he obfuscates with things like Tulip Trusts that can't be touched until January 1, 2020 and then that date comes and goes (over 2 years ago now!) and nothing happens.
https://coingeek.com/what-is-the-tulip-trust/
Accused of forgery and perjury by at least one Judge:
https://cointelegraph.com/news/judge-slams-craig-wright-for-...
And then in 2017 he got the bright idea to start filing patent after patent on anything to do with Blockchain. Why did he wait 8 years after he "invented" it?
https://patents.justia.com/inventor/craig-steven-wright
There are like a hundred patents there from 2017 and after!
And he has two doctorate degrees (one in Theology!) with two more on the way and a dozen other degrees and certifications. The man is a wonder!
The effect is that the reporting is becoming worse. Two years ago it was common for articles to mention that Wright's supposed proof was completely discredited. Today it's common for articles to say that Wright's claims haven't been "conclusively proved yet".
There is a big difference between saying that it isn't yet totally conclusive and saying that he tried to provide proof but it was proven to be a fraud!
Unfortunately, Wright has shown that he's willing to use SLAPP lawsuits against parties that criticizes him, including journalists. So you have to have deep pockets and a huge tolerance for nonsense to risk publishing something truly critical -- at least if you have enough visibility that he'll care.
You mean ethically questionable? Because it is not impossible.
That isn't how Bitcoin works, however. The protocol is enforced autonomously by each participant all on their own. The only voting like property in Bitcoin is the consensus used to decide the order of transactions in order to reject double-spends. Wright doesn't want to change the order of transactions-- the coins he's attempting to steal haven't moved since 2011.
If someone creates a transactions that spends some coins without the required signantures it'll just be ignored by all participants. If some participants adopt backdoored software that allow bypassing the authentication they'll just be ignored by everyone else, it doesn't matter how many do-- all automatically. Even if everyone else adopts that backdoor your own computer will just ignore them and continue the Bitcoin network with other non-backdoored participants.
So inherently what he seeks is to replace Bitcoin with an incompatible alternative. The only way that's possible is if people choose to adopt the alternative, call it bitcoin, trade it for bitcoin-prices, etc.
He's attempted it already too, he created Bitcoin Satoshi Vision-- his fork that is distributed under a proprietary software license. His conspirators and their victims go around telling people that it's the real bitcoin and that Bitcoin is an imposter. This has been mostly unsuccessful.
Ironically, some of the funds that Wright is trying to demand a backdoor to access are ones that were indirectly stolen from the developers he's suing!
If we could have just wave a magic wand and magic those coins back into our possession, we would have!
Anyone at any time-- including you or wright or anyone else-- can go and make a modified version of Bitcoin with its own consensus rules that do whatever you want, print yourself a trillion coins from nothing. Wright even did this already a few years ago.
But your modified version doesn't do anything to anyone else, the only people it has an effect on are the people who choose to run it. Your version would form a separate currency (just as Wright's has) and you can compete in the market for adoption. If your version is distinguished by stealing a bunch of coins, I'd bet that it doesn't get much adoption particularly since the whole premise of Bitcoin advanced in it's initial announcement was giving people power against being overridden by that kind of capricious change.
https://p2pfoundation.ning.com/forum/topics/bitcoin-open-sou...
I understand the Craig Wright is violating the norms of public behavior. I think it would be more charitable to not assume that he’s necessarily in his right mind.
Terry built templeOS and spent years working on the project. No one questioned the authenticity of that project and anyone familiar with him or his illness would likely not compare him to Craig Wright. This analogy really falls flat and makes no sense.
There’s nothing to indicate he’s who he claims to be.
Beyond his ineptitude, Wright has repeatedly claimed he would provide proof, but then when his 'proof' is exposed to expert analysis it turns out to be a provable forgery. Not just once, but over and over again. Forged emails, forged pgp keys, forged digital signatures, forged invoices, forged whitepaper drafts. Not merely falsifiable but actually falsified.
It's certantly possible that Satoshi lost whatever keys he had-- but if so he isn't saying anything about it. The idea that Satoshi would lose keys and then make a clown out of himself is just not parsimonious.
What is parsimonious is that we know for a fact that Wright has been selling his "fortune" to suckers for a number of years now-- the setup of a classic Nigerian scam: I am a prince in exile but with a small advance from you I can access a vast fortune which I will gladly share with you. At first his excuse was that he couldn't touch the coins without risking the AU government seizing them (due to stealing millions from AU with fraudulent rebates), then his excuse was that the coins were secured by a "bonded courier" (think of the end of Back to the Future 2) and wouldn't be delivered until Jan 2020, and most recently he claims that in Feb 2020 hackers entered his home and hid a 'wifi pineapple' to penetrate his network and steal his coins (of course, the coins haven't moved on the blockchain)...
"Bitcoin 'inventor' will face forgery claims over his Satoshi Nakamoto proof, rules High Court" https://www.theregister.com/2022/01/06/craig_wright_satoshi_...