Take the peer-to-peer traffic of the cryptocurrency network of any area, prevent it from getting outside that area (ie., just block it talking to IPs outside some range) -- then to that network, you can trivially control the total hashing power.
So split any cryptocurrency network into small segements, then add your machine to that network with a false history, design the network to be small enough, and your machine will out-hash the rest, and so it's history will win. Rinse-and-repeat.
It's trivial for any state to take down a cryptocurrency. There's nothing magic about it; it's an incredibly fragile system whose 'safety' relies on no one owning the network, and if that's the case, no one being able to russle-up huge amounts of electricity.
In both cases, this is false for states. So any state, if it wishes, can really do anything it likes.
The global bitcoin system is well within rearch of a hostile state 51%'ing it, even at the global level -- though the cost would be non-trivial. It would be trivial to do it in its own borders though.
As any state, of course will, if you can ever go into a shop and buy somehting with it. At that point you're imperilling a state's ability to use monetary policy to manage its economy, and that's an existential security threat. So bye bye your monopoly money tokens.
You cannot forge history, even with 100% of the hash power. Firstly, each transaction is cryptographically signed with the keys of the sender address. Secondly, each full node within the segmented network will have the full history.
The only thing you can do is publish different blocks to the segmented network than the blocks the outside network has. You cannot create arbitrary transactions. You can only censor others’ transactions within the segmented network. Since the mining difficulty will not adjust instantaneously your segmented network will fall behind the outside network in block height unless you control more hashing power than everyone else mining Bitcoin on either network combined. So as soon as anyone in your segmented network re-establishes connection with the outside network (and they will, they could receive a physical hard drive with the blockchain on it and rebroadcast to segmented nodes) all your work is for nothing.
You might say “yeah well I’ll publish an entire fake history that is MUCH longer than the outside network with lower difficulty so I can stay ahead”. Well, actually you can’t, because if you wanted vastly more blocks between Bitcoins inception and the present then the difficulty will necessarily be much higher because that’s how difficulty gets set, by how quickly blocks are produced. You would have to change the difficulty adjustment algorithm, creating a fork between your own malicious node(s) and the other nodes in your segmented network. Oh and by the way, you _still_ can’t create arbitrary transactions.
> The global bitcoin system is well within rearch of a hostile state 51%'ing it
I’ll believe it when I see it. They honestly have a better chance outlawing it and imprisoning anyone who’s ever used it.
If you own the machines and own the network you can do anything you want. Anything at all.
As far as assuming that the state hasnt taken control of the miners (unlikely, this is the easiest thing to do), by dropping communication, delaying it, observing it, etc. much can be done following the protocol, including replaying transactions etc. -- the future can be forged.
There are so many assumptions about the realworld, that do not hold up, behind cryto protocols, they're laughable. Assuming that the system will follow the protocol is itself disconnected from reality, quite literally.
The initial paper's realworld assumptions was that mining would be an at-home affair, ie., decentralised; everyone would run their own. And that networks were not own or controlled by centralised actors.
Neither is true. Mininig is incredibly centralised, as is network control. This makes it trivial for a state to pull an off switch.
Even talking about sophisticated denials of service, transaction replays, forging future transactions... all this takes place in a silly imagined scenario in which the state wants to hide what it's doing. If it didnt care, bang goes the whole thing.
> I’ll believe it when I see it. They honestly have a better chance outlawing it and imprisoning anyone who’s ever used it.
First of all I don't think any state is currently motivated to do this. However, if I were a state agency trying to attack Bitcoin, I would start by creating my own mining pool, which of course would purport to be privately run. I would be the most efficient mining pool in the business, offering miners a slightly better cut than other mining pools since while most pool operators are trying to extract a low-margin profit, I'm willing to break even or, if necessary, run at a small loss. It would be ideally to gradually create several sock-puppet pools that appear to be in competition with one another, while in fact I control all of them.
Even with competitive payouts, it may take several years to build up my pools reputation and gain a significant share of miners. And when I start having my pools mine blocks that I'm not actually submitting to the chain (to support my double spend), pretty soon miners will notice and switch. But I only need a couple hours to cause chaos, and I may benefit from miners confusedly switching to other pools that are also under my control. If I look at the regions where I have the most miners and time to the attack to occur overnight in those areas, I may succeed. And unlike trying to 51% the network myself by throwing hardware at the problem, I won't be left with worthless SHA256 hashing machines at the end of the attempt, nor will I have to pay for power. And I don't have to outmine the entire network -- I've enlisted half of it to be on my side. The only cost is the minimal pool operating expenses (not mining, just issuing work to miners, checking their work and arranging payouts), spread over how ever many years it takes me to gain dominance.
Countries have this neat tool called violence that tends to override all security whenever humans are a linchpin
That doesn’t work with distributed systems. No single country is able to shut the whole Internet down, for example.
Countries do this all the time , just yesterday we were talking about internet shutdown during elections and exams , then there are restricted countries like say North Korea.
(b) "seal the network in their borders" is much easier than that, lots of networks basically act like that already due to either voluntary compliance with local laws, or due to direct government interference with the networks
iii. the miners aren't really all that distributed, they group together for the same reason everyone else groups together instead of being free-range anarchists
[δ] all you need to do to shut down a currency within a country is arrest people using it, which is very easy and has a long history