Researchers Locate Flaw In Bitcoin Protocol
coderrr.wordpress.com
coderrr.wordpress.com
As it stands today just around $300K worth of hardware (I cannot quite recall the reference off top of my head) is needed to be able to "out-compute" the existing network and introduce a corrupted / compromised version of the block that everyone will accept as real.
That's not to mention that the transactions are not anonymous and just pseudonymous, which means if your identity is somehow disclosed (anytime in the future) all your bitcoin dealings are going to be completely public for anyone to see and use against you.
Distributed crypto-currencies may have a future, but it would require a lot of work to make them viable.
You're probably correct that you'd only need $300K to purchase enough hardware to double-spend, but any profit you could make off double-spending would be offset by the cost of electricity. Also, an alternative compromised blockchain would be really obvious, so you'd only have a limited window in which to scam people. Maybe you could do something if you had a botnet (and thus didn't need to pay for the hardware or electricity), but I can't help thinking that you could probably be doing far more profitable things with that amount of hardware.
By default, every time you send or receive you are given a new 'default' address. If you don't use that, then yeah, a group of transactions can be linked to you. Otherwise your identity would have to be 'disclosed' for each different address separately.
Unless of course someone gets your wallet, but then as far as I'm concerned, you've got bigger things to worry about it.
Actually, it's a lot worse than that. Most people will have a majority of their addresses linked without knowing it. http://coderrr.wordpress.com/2011/06/30/patching-the-bitcoin...
I'd say that anyone concerned about anonymity should be using a client with the functionality that coderr's patch provides, and be incredibly careful using Bitcoin in general.
I guess that's more a problem with the official client more than the protocol itself, though, right? If you were to create a new address and have all of those 'trackable' addresses send their balances to that new address, haven't you essentially removed this problem? I mean, all the people that sent to you in the first place can see where you sent the coins to, but they can't prove that you are holding that new account. Or is there something I'm missing here?
For what it's worth, I completely see how this is a problem. However, I don't see it as a particularly hard problem to solve (even 'programatically').
EDIT: and it was until I read the other reply here that I realised that that is actually your blog post. Nice work!
It's a pretty complicated area to reason about. I expect there will be a lot more research on it in the coming years.
I had them removed for a number of months as so many articles were upvoted indiscriminately, but then reintroduced about a week ago. Seems articles will still be upvoted by followers, but they are more discretionary this time around. Although, I might be placing too much importance on whether having them there makes a difference.