Baidu now accepts Bitcoin
bitcointalk.org
bitcointalk.org
"As a cutting-edge IT guy and a professional webmaster, what else can showcase our difference? The answer is that we have Bitcoin!
Bitcoin, as a new electronic and digital currency, is being accepted internationally. It's also used in daily lives. You can use Bitcoin buy a cup of coffee, or easily convert it to cash. But in China, Bitcoin is still a fairly new thing. Today, we have a good news: from today, we are starting to officially accept Bitcoin as a payment method. You can use Bitcoin to buy all Baidu Jiasule services. Baidu Jiasule as an innovator in the Internet industry, is now the first cloud service provider to accept Bitcoin and give everyone a better payment method and experience."
I couldn't imagine any big company in China will officially accept Bitcoin in the future at all.
What do you base this belief on?
The Internet is an example. The GFW (http://en.wikipedia.org/wiki/Golden_Shield_Project) surveillance all connections in China like NSA but since 10 years ago and people are used to it.
Even large payment companies in China (like Alipay) could do litter about economic innovation, they have to obey the rules set by the government and bank.
Any big company in China could challenge these rules by using a method which independent of any central authority in the future? I don't think so.
You can see Chinese bitcoin trade volumes at this site: http://btckan.com/price (Google translate, also don't forget the 0-fee promotions). I hear that a one or two of them have shady reputations, but the majority don't. Volume has been increasing, and is rivaling dollar trade volumes. So the government isn't too overbearing in this regard, it seems. The state media also ran a detailed bitcoin TV special several months back.
Strange, I always hear quite the opposite. That everything is simply too big at this point and although there is the appearance of a big controlling force, there really isn't one anymore.
* traditional Chinese culture would have the children care for their parents and grandparents in their old age
* one-child policy means that each child has two parents and four grandparents to care for exclusively, so that's not going to work out so well, therefore:
* everyone saves like crazy
* the state-run banks pay negative real interest rates (less than inflation)
* the state-run banks loan to big state-owned firms at negative real interest rates (and you can do amazing things when paying for capital at negative interest rates)
* the people in charge of the state-owned firms live lavish lifestyles off the profits and provide political support for the regime
* from time to time the government has to work to suppress riots over high food prices and other consequences of inflation
This breaks down if the ordinary people can get hold of a currency that isn't full of inflation. So, capital controls limit how many dollars people can get a hold of.
Of course, Bitcoin in the mix could be interesting. Or rendered illegal. Or both.
Also, there is no practical limit to how much dollar you can get with yuan, it's called the grey market.
It's pretty astounding to me how Americans can still have such simplistic and misplaced views of how things works in other countries.
http://www.news.com.au/travel/travel-ideas/inside-china8217s...
Some on-the-ground experience with China would indicate that the one-child policy has basically no effect on the number of children per couple. As would the international fertility stats.
Most recently, I asked a group of chinese software developers about the policy. They went around the table admitting they weren't only children.
I wonder what the explanation could be for our radically different experiences. Mine is all around Beijing, is yours perhaps out somewhere less urbanized?
Potentially it's an SES thing, but note that the fertility statistics show very low fertility for China, so a lot of only children isn't unusual overall. The conclusion that the one-child policy isn't having any effect comes from the fact that Japan and Korea have the same ultra-low fertility rate, but no one-child policy.
Perhaps the best comparison would be India, and the disparity in birth rates there is stark, but there are massive other differences as well.
They're more into passive spying and subtle manipulation/influencing, instead of active restriction and arresting of dissidents.
Why do you believe this? There's a very long chinese tradition of vesting control in the social hierarchy. "Authoritarian control-monger" may be dirty language in the US, but not everywhere.
I know that Reddit, after months of enabling Bitcoin as a payment option, still only got 3% of their entire revenue in Bitcoin [2]. I like the concept of bitcoin but as of now, it seems like many of these initiatives are launched by businesses to get "tech people" interested and to make news about their business. That's not a terribly bad thing though for bitcoin because businesses are still adopting it. It just would be nice to see Bitcoin used more than 2.5% of the time.
[1]: http://blockchain.info/address/1NtbQKVFxAPc8mmBoWwRzhg7o3EMC...
[2]: http://www.reddit.com/r/Bitcoin/comments/1dkbix/bitcoin_usag...
Reddit getting 3% from Bitcoin actually sounds like quite a bit. I know there's a lot of stories about BTC, but I still think of it as a fairly obscure thing.
I think it is perfectly safe to have a single address and for someone to say "Hey, I just sent 66.32 btc to your payment address."
In the one-in-a-thousand chance that someone else claims to have sent that money as well, you can just ask the sender to sign a message with the source address' private key.
Still, I agree long term you'd save yourself extra work by setting up separate payment addresses.
Meanwhile, in the world of cryptography research, we have known how to make secure digital cash, with rigorous security definitions, without the need for such vast energy or computing resources, with support for offline transactions, etc., for decades. The only real difference is that academic systems call for an authority or group of authorities that issue the currency, though that is not as bad as it might sound if you consider the problem of actually defining security without such an authority (Bitcoin's solution, as I mentioned, is to simply not bother with such a definition). It is hard to even say that Bitcoin has no central authority at this point; the developers of popular Bitcoin software have tremendous power over Bitcoin (e.g. they can trigger block chain forks).
That's quite a difference, and one of the main features of Bitcoin. See the message in the genesis block.
> It is hard to even say that Bitcoin has no central authority at this point; the developers of popular Bitcoin software have tremendous power over Bitcoin (e.g. they can trigger block chain forks).
I agree with you on that.
That is a political statement not a technical statement, and this gets to the heart of the problem with Bitcoin and with its lack of a security definition. Bitcoin is popular, particularly among those who distrust the banking system, because there is no requirement for a central authority; that is certainly true but only in a pedantic sense. Without a security definition it is hard to even talk about what Bitcoin requires.
What we have therefore is a situation where no amount of technical criticism can matter with Bitcoin. Polynomial time attacks are irrelevant, because there is no requirement that Bitcoin resist polynomial time attacks. There is similarly no particular scalability requirement, and so there can be no real criticism of Bitcoin's scalability. "True believers" in Bitcoin can easily shoot down criticism because critics cannot actually point to any requirement that Bitcoin fails to fulfill: there are no clear requirements to point to.
To illustrate this point, consider this statement: There is a polynomial time attack on Bitcoin, and the whitepaper itself describes it. Now, is this a problem? Well, the answer I consistently get from Bitcoin devotees is no, that is not a problem because that is how Bitcoin works. With logic like that, who can argue?
So while you call the lack of an authority a feature, I call it a logical gap until a rigorous security definition is presented. Otherwise you have a solution in search of a problem, coupled with a community of people who all have their own vague notions of what they want Bitcoin to do for them.
Just because it doesn't have the particular kind of specification that you are looking for, it doesn't mean that it's not technical. Being distributed is very much a technical feature, no matter how you look at it.
I much rather have a working solution that might or might not be broken in the future (if it was too damn insecure, someone would have broken it already), than be stuck forever with the old banking system just because we don't know how to create the mathematical/cryptological model that you are used to and would grant 100% theoretical security. That would be like not building a website or shutting down a project mid development just because some component is found to be difficult to unit-test.
What does it mean for Bitcoin to be "broken?" That is my entire point here: if we do not have a clearly stated definition of what security means, then we cannot even talk about whether or not a system is broken. To put it another way, I would call any cryptosystem that can be attacked in polynomial time "broken," yet in the case of Bitcoin there is the 51% attack which apparently does not bother you -- and like I said, despite the fact that I call it broken, I cannot actually point to anything that would have required Bitcoin to be secure against such an attack.
To put things in scientific terms, we are talking about falsifiable hypotheses. As an example, here is a commonly assumed hypothesis: the block cipher AES is a pseudorandom permutation. This is a claim that could be disproved i.e. we can falsify the claim by presenting an algorithm that efficiently distinguishes AES input/output pairs (with a secret key that the algorithm does not receive as input) from the input/output pairs of a random permutation. Consequently we can speak about the security of AES in a meaningful way, even though have no theoretical proof that it meets its security definition (only heuristic evidence and a lack of known attacks).
My point about Bitcoin is that we do not have such a hypothesis, so we cannot even be sure that we mean the same thing when we say, "Bitcoin is secure" or "Bitcoin is broken." That is the point of having a security definition. Without such definitions, you can always make the claim that Bitcoin is secure, not matter what sort of attacks are carried out, because you can always just say that Bitcoin is not supposed to defend against those attacks.
It's pretty intuitive and I'm sure you know it: People being able to break the rules. Eg: create coins out of nowhere, move coins that weren't theirs, slow down transactions, unstabilize the market, etc.
To say that it's not falsifiable is a bit of a stretch. It is falsifiable, we just don't know how to create the model you are looking for. Maybe it can't be done [with crypto]. Maybe it wasn't a competence of Cryptography to begin with, and we need an entirely new field (I know cryptographers have tried in the past, but to me this seems different). Don't you agree that Bitcoin involves too many disciplines to try to simplify it into a cryptographic formula? Something that breaks Bitcoin could even simply come from Economics, and your crypto model (if you ever find one) would be useless.
Or, there is a cryptographic model, has been proven secure, and we just don't know it because its creator[s] wanted it to stay secret.
Let's try with an analogy (you can attack it or say why it's bad). Your ship is sinking for some reason, there are no emergency boats, but you find out something that might be used to stay afloat. You hesitate, because you don't have physical proof of it like you did with the ship (an expert created the drawings, calculated the forces involved, etc.). But then you see a lot of people using it and it's working fine. The more time it passes, the more certain you are that it works. That's empirical evidence, and it drives a big part of scientific advancements.
So maybe once each field is validated individually as thoroughly as possible (crypto components are being used correctly, the correct distributed computing techniques are used for scaling to the moon, the economic variables are chosen correctly -Satoshi wanted Bitcoin to mimic gold-, the right incentives are given to miners and hindrances to attackers -Game Theory-), only empirical evidence can be used to finish the test.
If by breaking Bitcoin you can silently steal millions and safely cash out (one hell of an incentive in my book), yet no one does it, I say it's secure enough. Not in a cryptographic or <individual traditional field> way, but in a pragmatic way. It just works.
Ah, but therein lies the problem. If there is no authority that issues the money, then any party must be able to create money from nothing (or there would be no money in the system), and must be able to do so efficiently. This is where the first vague notion of security in Bitcoin arises: the idea that you can generate the money efficiently, but not "too efficiently." Unfortunately there is no well-understood security model that allows for efficient-but-not-too-efficient attacks.
"Don't you agree that Bitcoin involves too many disciplines to try to simplify it into a cryptographic formula?"
Two disciplines, as far as I can tell: economics and cryptography. One discipline motivates the other here. Theoretical understandings of money and money creation come from economics; whatever that understanding is, the security definition needs to capture it. The involvement of another discipline does more to motivate the demand for a security definition than to make it irrelevant.
Suppose you could identify or develop an economic theory for money that has no intrinsic value and no central authority. You would still have to have some security definition that captures that theory to make a convincing case (or at least a meaningful statement) that the money in Bitcoin meets the requirements of that theory. If you cannot identify an economic theory that supports a system like Bitcoin, you are no better off than if you cannot state a rigorous security definition.
"Something that breaks Bitcoin could even simply come from Economics, and your crypto model (if you ever find one) would be useless."
Whatever hypothetical security definition you had would not be useless in that case. Rather, it would be that systems that satisfy that definition do not make economic sense, and hence that entire category of systems has no practical use. I would say that in that case, Bitcoin would be solving the wrong problem, rather than that Bitcoin was "broken" (which I take to mean that it does not solve the problem it is supposed to solve).
"Let's try with an analogy (you can attack it or say why it's bad). Your ship is sinking for some reason, there are no emergency boats, but you find out something that might be used to stay afloat."
Are you suggesting that Bitcoin is a system that people desperately cling to when they believe that well-designed systems are failing? I think this might be the wrong analogy, at least if you are trying to defend Bitcoin.
A better analogy might be this: you are standing on a ship. You do not like the captain and his decisions, so you grab some hunks of wood, styrofoam, tires, and a barrel full of fuel oil, lash it together with some rope, and set sail.
Which would you rather be standing on -- a well-engineered ship that might sink if the captain makes bad choices or if the crew fails to maintain it properly, or something that some guy assembled from stuff he found that seemed relevant to ship-building and which seems to float, seems to have no captain to make bad decisions (but might be split in half if the crew cannot agree on a heading), and which has not yet sunk under the weight of its passengers?
"If by breaking Bitcoin you can silently steal millions and safely cash out (one hell of an incentive in my book), yet no one does it, I say it's secure enough. Not in a cryptographic or <individual traditional field> way, but in a pragmatic way. It just works."
What if the attacker does not want to steal money, but just wants to disrupt the system? Imagine a hypothetical "Satoshiland" where Bitcoin is a major economic force; now imagine that another, more powerful country is about to go to war with Satoshiland, and that their goal is to destroy everything. If the invader can block transactions, create transactions then reverse them, and kill the mining bonus, they can cause vast economic harm -- without firing a single gunshot.
Or (slightly) more realistically, what if the US government wanted to block payments to Wikileaks. What if that is worth more than whatever it costs to do so (ie a "51% attack"), and more than whatever hypothetical mining payoff could be had by just devoting the hardware to mining?
I would not assume that the adversary's goal is your personal goal.
If Bitcoin developers do something that miners don't like, they lose their base. Developers are as invested as miners are and don't want to risk a drop in the value of their bitcoins.
The balance is that developers are accountable to miners and users, unlike central banks that aren't accountable to us.
How is that any different from what happened with Chaum's startup (digicash)? Bad management resulted in a failed business.
"The balance is that developers are accountable to miners and users, unlike central banks that aren't accountable to us."
Central banks are accountable to their customers insofar as the management of a currency is concerned. If a currency is poorly managed, it will fail, which leaves the bank without any authority. Sure, the bankers might remain wealthy if they happened to hold assets other than the currency -- but the same is true of Bitcoin developers, who might simply sell their BTC on some exchange and thus protect themselves from a Bitcoin failure.
But to the subject of the thread: Baidu should be using a Hierarchical Deterministic pub/priv key tree. [1] Increases their financial privacy 10-fold.
I'm not sure if he also meant it, because the attack described by betterunix isn't quite what a 51% attack is about.
That sounds like a 51% attack, although the 'half of all computing resources' is off the mark. The OP is right here, it is a very feasible attack at the moment, which is why some are concerned that SHA256 is too specializable (ASICs) which means that a dedicated adversary with access to chip manufacturing could print a few wafers and own the network at low cost.
There aren't many attacks on the network that require that kind of computational power. I could see the NSA running a large portion of nodes to de-anonymize users, but beyond that I don't know what else it could be. A double spend attack wouldn't require much effort (right now at least, that will change) [1].
[1]http://www.tik.ee.ethz.ch/file/848064fa2e80f88a57aef43d7d595...
[1a]http://www.tik.ee.ethz.ch/file/49318d3f56c1d525aabf7fda78b23...
[1b] We will see some of these changes in bitcoind .9 (so says Gavin)
I suppose that I could have stated it somewhat better by saying this: half the energy output of the planet needs to be devoted to the most energy-efficient Bitcoin mining hardware possible to guarantee that no attack is occurring, and only if that hardware is being used by honest miners and not an attacker. Of course, in practice no attacker will amass anything close to that (it would leave no power left for anything other than Bitcoin), but in practice the world will never devote anything close to half its energy resources to Bitcoin. Even generous estimates of what the world's energy economy could devote to Bitcoin leave an awful lot of room for an attack, and while the attack might not make economic sense in terms of the market value of Bitcoin or the mining payoff, it might be part of some broader plot (perhaps a war against a country where Bitcoin is popular and widely relied on).
"I could see the NSA running a large portion of nodes to de-anonymize users"
Why would they bother? Bitcoin transactions are broadcast to the entire Bitcoin network anyway. All the NSA would need is a handful of desktops and some auxiliary information about which wallets belong to which users (perhaps gather by watching Bitcoin exchanges). Bitcoin makes no anonymity guarantees at all.
I won't refute this, because you are right. I was just speaking in more manageable/realistic terms.
>Why would they bother? Bitcoin transactions are broadcast to the entire Bitcoin network anyway. All the NSA would need is a handful of desktops and some auxiliary information about which wallets belong to which users (perhaps gather by watching Bitcoin exchanges). Bitcoin makes no anonymity guarantees at all.
Bitcoin is not anonymous, correct. That doesn't mean that it is easy to break the barrier from pseudonymous - > known identity.
Let's say there is a clever participant in the network, Satoshi, who is under investigation by the NSA. The NSA knows they will be sending 10btc to their cohort at address xyz. Satoshi is smart, he is not going to use an exchange to get his coins. Maybe he mined them. Maybe he got them in a f2f transaction.
This leaves few options to find out information about Satoshi. However, if the NSA ran a sufficient number of nodes, they could easily determine the first node to propagate a transaction. This would be Satoshi's IP address. That is why they would do this.
I suspect that there would be easier ways. Even just the time when the transaction occurs would reveal a data point (e.g. when the sender is awake). It also would not help much to avoid using exchanges; if the target mined their Bitcoins, then you can at least narrow them down to the people who could mine enough for the transaction (which becomes easier as transactions become larger). If the target was given the Bitcoins by someone else, you now have another transaction that can reveal some data points (e.g. when that transaction occurred, who sent the money, etc.).
Like I said, auxiliary information is key here. Sure, transactions in isolation might be hard to associate with a person, but transactions do not occur in a vacuum. If you want to speak rigorously about anonymity, you need to somehow include the notion that an attacker might have access to some information beyond the observations they make of the system; the point is that the system should not expand the attacker's knowledge (except by some negligible amount). This is the intuition behind concepts like "unlinkability" in academic work on digital cash: it should be computationally difficult to identify transactions that originated from the same spender (even better is the notion of transferable cash, which allows for "fully" offline payments; however, this has the drawback of causing the representation of the money to grow in the number of parties that have received it, and so it scales poorly [1]).
So, imagine a system where a party being watched by the NSA uses an offline protocol to pay another party e.g. they meet out in a field somewhere and do the transaction without any Internet connection. A system with divisibility and unlinkability [2] would make it hard for the NSA to track the target from the transaction, as the target could withdraw more money from the bank than he spends, and the receiver's deposit does not reveal which user sent the receiver the money (at least beyond what would be revealed by things like the timing of the withdrawals and deposits and the amount of money being deposited; the point is that the transaction protocol itself does not add any additional information). A system that supports transferable cash would take this even further: a party might receive the cash from one friend, then send it to another, both using offline transactions, and the NSA would not be able to identify "middle" party (or the "first" party that made the withdrawal).
Of course, these definitions cannot be applied to Bitcoin, for an obvious reason: these definitions call for a bank in the system, which acts as an authority on the validity of the money (sound familiar?) and which identifies "cheaters" e.g. double-spenders. On the other hand, there seems to be no good security definition for digital cash that does not involve such an authority; I suspect this has something to do with the lack of an economic theory for money with no intrinsic value and with no such authority.
No doubt there are better ways. If there were no useful data points (e.g. stolen then mixed via CoinJoin, traded atomically to another chain with less traceability then back again) then maybe it would be helpful. But then again, if it was a sophisticated user they probably wouldn't propagate the tx from their own IP. I brought it up only because it would be slightly more expensive then some other attacks.
Regardless, you are right. Absolute anonymity is not possible in Bitcoin at the moment. If offline transactions become more adept, then perhaps. But for now... not quite.
And I'm not sure I understand what you mean by "weird timing attacks".
You should be treating addresses more like single-use, disposable accounts than longstanding pseudonyms.
Actually you can. Vendors who do this require payers to use a built-in functionality in most Bitcoin wallet apps to cryptographically sign a message identifying them.
However this is not very user-friendly, does not work when sending from a hosted wallet (no access to the private keys), and reduces anonymity for the vendor since everybody knows his main payment address.
The rationale behind creating a new BTC recipient address for every transaction is that it doesn't matter who the sender is.
First and foremost is simplicity for the recipient: if wallet X contains the desired number of bitcoins, the sender paid. Unambiguously. Otherwise it's difficult to tell who sent what, since you might be sending any number of pieces of coins that all make up "your" transaction, which is complex / nigh-impossible to solve without other ways of verifying (such as including a message in the transaction). This is made even more complex if you receive many transactions from many people with a single address.
Second is anonymity. If you reuse "your" wallet and it's ever connected to you, so is every transaction out of it, forever. If you value the anonymity side of Bitcoin, it's very important, but not sufficient. If you don't care about anonymity, the only other downside is that someone who gets your private key can wait until your wallet is bigger before stealing the bitcoins. If you constantly change addresses, the old private key is essentially worthless as soon as you make any transaction. Honestly that's pretty unlikely, and if they have your private key it's game over anyway, they can steal it all at any time they want.
To see the price increase, you can look at any of the charts at http://bitcoincharts.com. But since the exchanges strongly influence each other because of arbitrage, price charts won't tell you anything about the role of Chinese exchanges in the increase.
It certainly sounded like that was what you intended. A transaction volume increase is interesting, but on Reddit I have read comments stating that the exchanges in some cases have started charging no fees - which sounds like it's possible that the increases are entirely spurious and due to, say, bots going nuts.
Take a look at the services list in that article - they are like Google, Wikipedia, and Yahoo all rolled into one, and dominate the Chinese market.
Some details here: http://en.wikipedia.org/wiki/Renminbi#Managed_float
The CCTV spot wasn't state sponsored per se, but I know what you mean.
>the large number of Chinese bitcoin miners
Oh?
Here's to hoping. I'd love it to be real.
Correct me please.
Right but that is life. Make back ups when you have something critical like that.
"two, how is tax going work?"
The same way it works with anything else. The government will come in, assert that you own X in taxes on your Bitcoin income, and you will pay it or go to jail. You will probably need to pay with something other than Bitcoin, of course, which adds in transaction fees (but you just pass that cost on to your customers, right?).
"Third, bitcoin price goes up and down so rapidly"
By extension, your prices change daily. You'll probably charge a fixed fee in your local currency (Yuan?) and adjust your Bitcoin prices according to the market value.
2) Taxes would work just like how you make money today from other sources, you have to declare them. Plus, wouldn't it be better if people wanted to pay taxes based on the marvelous "services" they get from the government, rather than having part of the money being taken away from them by force, and then the government spending it however it wishes, with little benefit for the tax payer? Seems to me that if the government had to convince people to pay up, instead of forcing them, they'd be a lot more efficient with that money spending, and a lot of waste would be reduced.
3) I think the more used Bitcoin gets, the volatility decreases. Right now if someone buys $1 million worth of Bitcoin, that could still have a pretty significant impact on the Bitcoin market. In the future, if the transactions are worth trillions of dollars, someone trading $1 million of them won't mean much.
2) People have been bartering for centuries and taxation of barter is already well defined by government. Bitcoin transactions get handled the exact same way.
3) You're witnessing the birth of a new currency, price fluctuation can't be avoided. However, bitcoin prices will stabilize over time. Plus, there's services that immediately convert you BTC into fiat currency to avoid this problem.