Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets
bitcoinmagazine.com
bitcoinmagazine.com
--
edit: tl;dr of it all is:
1) addresses are hashes of public keys, not public keys themselves, so you can't really figure out the private key even with magic / quantum computing.
2) 21 million BTC * 100 million divisions = 2.1 quadrillion < maximum integer uniquely representable by a (double-precision) float (~2^50.9 < 2^53), handy for simpler programming.
3) elliptic curve chosen wasn't one of the dubious NIST ones.
The article is pretty well written, IMO, and does a reasonable job explaining why these are issues in the first place, and how it avoids them. Probably worth a read unless you grok it all from the tl;dr, and even then since it might help you explain things to others.
Not the ones that go for the "proven" way "because NIST said so" or the "internet specialists" that cry wolf more often than not (and miss or even suggest security holes)
Bitcoin's ECDSA curve was chosen because it was one of the faster ones, not because of any NIST connection (a "real" cryptographer of the day would have probably advised against the secp256k1 curve used in bitcoin in favor of one of the NIST curves, or DJB's curve which is superior in just about every way.
Turns out, the NSA is a shadow of its former self. But you'd have to have had non-public insider information to have known that with confidence in 2009.
I say "common case" because it only really is a win if _both_ quantum computers are in use _and_ you've never spent from the wallet and never will (except possibly to cash out entirely).
This comment seems to offer many clues: https://news.ycombinator.com/item?id=5547590
There are two groups that are on the suspects list for having engendered bitcoin, one group centers around Trinity College, another is a bunch of loosely affiliated international collaborators. Both groups are on the record with precursors to bitcoin (papers, software), neither has admitted openly that they were the ones.
Along with https://news.ycombinator.com/item?id=5548093
Investigations into the real identity of Satoshi Nakamoto have been attempted by The New Yorker and Fast Company. Fast Company's investigation brought up circumstantial evidence that indicated a link between an encryption patent application filed by Neal King, Vladimir Oksman and Charles Bry on 15 August 2008, and the bitcoin.org domain name which was registered 72 hours later. The patent application (#20100042841) contained networking and encryption technologies similar to bitcoin's. After textual analysis, the phrase "...computationally impractical to reverse" was found in both the patent application and bitcoin's whitepaper. All three inventors explicitly denied being Satoshi Nakamoto.
Anyone care to speculate whether it's more likely the creators were based in Trinity College rather than being international collaborators?
It's interesting that the controller of the Satoshi persona managed to stay anonymous for so long. I wonder if they were careful to only write forum posts via Tor? Otherwise their IP address might've been logged. An IP address would be enough for an ISP to unmask them (or at least narrow down the suspect list quite a lot). Satoshi also made a lot of source code commits, which seems like another way their IP address could leak.
Obviously if the inventor was not a single person, but the result of a group effort, one could truthfully reply that they were not the inventor.
That's the first time I have heard that one. If there are no other textbooks / papers / patents were this phrase is used, this seems like a pretty strong indicator to me. A search on Google Scholar for that exact phrase gives (at the time) the two expected results. http://scholar.google.com/scholar?hl=en&q=%22computationally...
Alternative hypothesis: (a) Nakamoto paid close attention to research, read the patent and liked the phrase. (b) The phrase is common lingo, but Google Scholar doesn't index it. For example, it could be used in a private mailing list. Both (a) and (b) seems like they could quite easily be investigated by someone with domain knowledge together with some knowledge of how patents are distributed.
This seems like too simplistic a reasoning. Anyone care to explain what I am missing?
EDIT: The exact phrase "computationally impractical" seems to be very common, with thousands of citations before 2008 http://scholar.google.com/scholar?q=%22computationally+impra... It seems to me that reversibility might simple have been a "theme" in crypto circles around that time, which could explain the coincidence that two different groups independently glued the phrases together.
When you hit a jackpot like this, remaining silent and denying everything is one of the most sensible courses of action.
I'm starting to add more tin foil to my hat these days and this sort of thing worries me.
Every single time I read something about what 'Satoshi Nakamoto' did in designing, implementing and securing Bitcoin, I grow more skeptical that one person, or even a small group of people, created Bitcoin. It is very difficult to believe that something this sophisticated was developed by anyone other than a well financed, possibly nation-state backed organisation.
This article suggests that Bitcoin was made difficult or impossible to fork by-design, which implies that the creator doesn't want to allow anyone to seize control of Bitcoin.
Paradoxically, the more you learn about Bitcoin, the more mysterious it becomes. Who would go through all that trouble to create it? What can they gain from Bitcoin's existence?
"This article suggests that Bitcoin was made difficult or impossible to fork by-design, which implies that the creator doesn't want to allow anyone to seize control of Bitcoin."
Well, source code is easy to change and fork. But because this would create a fork in the block chain, you would end up with a different Bitcoin network that does not recognize transactions of the original Bitcoin network.
"Who would go through all that trouble to create it?"
Version 0.1.0 is only 13k lines of code.
"What can they gain from Bitcoin's existence?"
Someone wanted to experiment with his ideas about a revolutionary peer-to-peer currency/payment network, and maybe hoped to inspire others with his creation? Some people enjoy experimenting with cool ideas just for the heck of it. What was Linus Torvalds thinking he would gain from writing the first version of Linux? Anyway, the success of Bitcoin so far is probably beyond what Satoshi envisioned as probable (although he may have seen it as possible).
Not that nobody else has found him out (definitely possible/plausible, and some people claim to have successfully used web tracking bugs to get an IP).
Satoshi Nakamoto:
1. never publicly claimed any credit for the idea of bitcoin... think about it, he doesn't claim he invented the idea, he just put it forward and kind of said, what if... ?
2. never spent or moved his massive holdings of BTC which are easy to identify because they are some of the oldest blocks in the blockchain
3. never exercised his power to shape bitcoin, especially after the end of 2011 - aside from code contributions and that doesn't count since everyone involved can think about it and decide to accept it or not - each code contribution is a potential fork so don't underestimate the care taken on the official bitcoin client
4. never slipped up and revealed his identity or even his _timezone_ !
That's a preponderance of evidence to me. I'll understand if you're not convinced but this is the kind of PR management that a single person just can't pull off!
What can they gain from Bitcoin's existence? Only all the economic benefits from a _viable_ digital currency. All previous attempts at digital currency are weak in comparison. And currency market manipulation is by far the most profitable game, like that even needed to be said.
Who would go through all that trouble? In a world where a US Agency (NSA) has successfully tapped almost the entire internet, maybe it's time to accept that this kind of advanced planning is within reach.
It helps to point out some common misconceptions about Bitcoin. Bitcoin does not guarantee anonymity, despite the p2p elements of the protocol - far from it. Bitcoin is much more flexible than you think, for example the "1" prefix on all addresses currently. Bitcoin does not have to succeed or last forever, the idea has been planted and isn't going away.
All markets are a mix of manipulation and organic behavior. Factor that into your plans and Bitcoin makes a lot more sense.
- posted anonymously
The more persons would be behind the Satoshi identity, the more chances there would be for mistakes or leaks: one of them spending/stealing the BTC, one of them boasting about the secret Bitcoin project, or revealing it while intoxicated at a party, etc.
This doesn't have to be some crazy story. There's the means, the motive, and the opportunity to create Bitcoin. Why would a lone actor be so motivated to keep their identity a secret?
We obviously disagree.
There are 2 simple reasons why Satoshi would want to remain anonymous:
#1 He is estimated to own ~1 million BTC ($200 million); many thieves would capture/torture/murder someone for the chance to steal that amount!
#2 Sometimes people just want anonymity by default, like you who posts anonymously for no apparent reason ;)
Bitcoin will not be outlawed by the US or Europe. China seems like the only remaining threat as far as outlawing Bitcoin.
Hilarious. A "well financed, nation-state backed organisation" just gave us the Obamacare website.
It doesn't all have to be ACA websites.
But this same large military organization did come "dramatically close", as "only one low-voltage switch" prevented what would have been an atomic explosion in North Carolina in 1961:
http://www.theguardian.com/world/2013/sep/20/usaf-atomic-bom...
I should add that as a bullet on my resume:
- Hasn't accidentally set off any nuclear bombs.Really, you think Bitcoin is that sophisticated? Can you even point to any clearly stated requirements, constraints, or security definition? The original Bitcoin paper did not even describe the system well enough for someone else to implement it; half the specification of the data formats was in the code itself. Nevermind the bad design; the original Bitcoin paper somehow failed to mention or even hint at (or even use the concepts from) the massive body of related work.
All the evidence points to Bitcoin being the work of an amateur, just one hobbyist who hacked together a system based on an idea he had. My guess is that it was a college student who was fascinated by cryptography and had read a few books. This is not necessarily bad -- the same is true of the Linux kernel, after all -- but to claim that Bitcoin is some kind of highly sophisticated system that must have been the work of a government team is just silly.
without having this post balloon in size, i'll leave you with an interesting scenario:
let's say you were a member of some shadowy group and you were tasked with moving funds around the world but you didn't want intelligence services to be able to watch those funds move, e.g. via the SWIFT system. your only alternative is to move funds some other way, using an alternate system. moving physical goods around always carries risks at customs checkpoints and it is slow. this leaves some kind of an electronic value-transfer system. since one of your own group members may be a spy or otherwise untrustworthy, the system must assume everyone is untrustworthy. the obvious way to deal with untrustworthy parties is cryptography. a classic way to pass messages semi-anonymously is to "write on a wall" somewhere that you tell your counterparty to look, but others do not know to check.
if you had such a private / closed-loop value transfer system, the only real caveat is settlements in fiat currency, which all "normal" ppl use to settle transactions. if you aggregate these fiat settlements episodically using a fixed exchange rate, it effectively decouples actual meaningful transactions from the fiat transfers, obfuscating the actual transactions.
In fact, being well-conceived and svelte is evidence that it was just a few very smart people, perhaps just one.
Further, the "smart" curve choice bitcoin made was simply not using the NIST P-curves. But lots of stuff chose not to use the NIST curves; that's why we have Certicom's curves and the Brainpool curves. Unfortunately, bitcoin didn't do that much better than the NIST P-curves; the Koblitz curves they use also have problems that researchers are exploring.
If there is a concept of "quantum-safe" (which I did not know until reading this article), why hasn't the broader internet (HTTPS) adopted them? Is there any plans for there adoption in the future?
My understanding is that schemes that would be resistant to quantum attacks are much less efficient, and have more negative tradeoffs, than the systems in use today. Speed is an important property for a most cryptography, so few people would adopt such a system until the threat seems more pressing.
The real problem is public key ciphers that rely on prime number factorization. Eliptic curves are one solution, but the only people who seem to have in-depth knowledge about them are in the NSA.
I haven't heard this expressed anywhere, but it could also be that the McEliece and Niederreiter algorithms have a bit of a feel to them like the Merkle-Hellman knapsack algorithm that was thought for a long time to be secure.
Though, if you're being paranoid and can spare the cycles, it wouldn't hurt to take Elliptic Curve Diffie-Hellman (or ECIES) exchange, encrypt that using RSA (or ElGamal), and then Encrypt that using Niederreiter (or McEliece), like a bunch of Russian dolls nested by key/message size. All three crypto systems would need to be broken in order to recover the key.
Uhm, no such thing? Every mined bitcoin is instantly sent to an address
Why wouldn't I feel tempted to use his fork?..
Strangely enough he talks about floating point rounding errors in one of the next paragraphs?
This is normally a very good rule to follow. The reason is that floating point is binary, whereas cash is decimal, so even an innocent number like 0.4 has no exact representation in binary (it's actually an infinite tail: 0.011001100110011...).
Here, however, I'm using floats NOT to store decimals; every single value that I store is an integer. There is absolutely no danger in using floating point numbers to store relatively small integers like 1253251126; the issue only arises in the context of very large numbers (specifically, those above 2^53) and decimals. If anyone can come up with a remotely realistic series of integer manipulations that will cause an inaccuracy in Javascript where all values always stay below 2^50.9, I will certainly abandon my choice of moving to integers at once; otherwise, I see no problem.
The first thing we did in the programming class at university was to learn how the IEEE floating point standard works...
Same thing with the IEEE standard, it's not hard, but it was presented in a dull way, all theory.
I'd trust a unique and fairly original monetary system run by good engineers. But most engineers are really not that good.