Here’s who probably did that $150 million Bitcoin transaction
washingtonpost.com
washingtonpost.com
Edit: got curious and found an answer: http://bitcoin.stackexchange.com/questions/2847/how-long-wou...
If I understand correctly, it's still not viable even if you tried your brute-forced keys on all addresses in the network.
This is constantly suggested, and it's always useless. If you could attack keys like this the system would be broken.
The ECDSA keys used in Bitcoin are much stronger than RSA keys at the same size, and they seem quite safe, but don't make the mistake of looking at the time needed to brute force e.g. a 128-bit AES key and assume that applies to asymmetric algorithms too.
However, in cases where the private key is generated from a hash of a passphrase, like brainwallets, then it is far more feasible. There are people running bruteforcers constantly looking for private keys corresponding to brainwallet passphrases; that's their form of "mining".
To test it, if you make a brainwallet with a password of "password" and then send 0.01 BTC into your account, you'll see it vanish in a few minutes (or a few seconds).
Brainwallet inputs -> public keys are deterministic. It's true that the method of creating the key pair is as much of a password as the password, it's easy to select the most common methods (sha-256 hashes, bitaddress.org's method, etc.)
I cracked thousands of passwords for the https://keybase.io/warp competition (I lost by a few minutes... the answer to the top one is Je).
Once you have those public, private key pairs you can simply make an index of them and watch the blockchain for any of them to show up.
Deleted comment
You'd need a time machine, and if you had one I can think of better uses.
Actually even a time machine wouldn't help since bitcoin showed up long after the RNG was fixed.
Plus you have to balance "my own fuckup" risk against "someone attacked me" risk, right. Wallets depend on your backup habits, and you backup provider's security. Going through the fora, I'd say "oops. I lot my wallet.dat" is a much more serious threat to your bitcoins, on average, than someone got a hold of your password. Both of those, for most people (including me) are ... lacking. Brainwallets depend on my memory for passwords. A hardware brainwallet would guarantee you're 100% not exposed.
As for ECSDA attacks. It's true that the algorithm itself is near-unhackable. However, make one single transaction on a computer which chooses a non-random k value, and you're exposed. So the risks don't end just because
It's incredible to see such misinformation on HN. I suggest you read this: https://dl.dropboxusercontent.com/u/315/articles/A%20Large-S...
This is a 2007 study on web password habits. In it, they reveal the fact that fewer than 1% of passwords have bitstrength >= 90 bits: http://i.imgur.com/8vSrx2E.png
Achieving 128 bits of protection with a user selectable and memorable password is statistically unlikely (to put it mildly).
The fact that a brainwallet password is memorable means a computer can bruteforce it in far fewer operations, too. I.e. the bitstrength is mostly meaningless. Just ask the guy who runs http://www.cloudcracker.com
A memorable user-selectable password is incredibly unlikely to be as strong as 128 random bits.
Passphrases aren't limited by length, and your brainwallet can be derived from your memory and publicly available information, so you can construct very strong memorable passphrases, e.x. the 3rd sentence of the 8th chapter of your favorite book concatenated with a moderately strong but memorable password.
Key stretching with PBKDF or scrypt helps a lot as well. Do you care if it takes 1 minute to compute your keys from the passphrase? Probably not, and it will make cracking much more difficult.
"I am the administrator of MtGox, I need you to send us a copy of your private key..."
You only need the internet connection to do something with the coins.
For those who don't recognize the reference: http://en.wikipedia.org/wiki/Tulip_mania
In all seriousness, this is going to come across as a conspiracy theory, but why else would major government organisations be thinking that bitcoin is actually a good thing? Surveillance by design neatly negates all the current NSA privacy issues! It is also a figurative goldmine for economics researchers, who get to study every transaction in an economy for once, with full information on how the funds are following.
There's quite a few of us who have been concerned for a while about the issue of who controls the bitchain, as the only real thing stopping a single entity from doing this is cost. Yet the advantages are so very high. There's also the very real possibility that you don't actually need 51% of miners to do this for specific purposes, either. Just look at some of the TOR monitoring research.
EDIT: I should also add that we need to be talking about these issues, rather than dismissing them. If the cryptocurrency movement is to survive, then these are the challenges ahead.
And one has to ask, if this is not the sole means of accepted currency, are these issues actually a concern? What would count as appropriate mitigation? Can multiple forms of cryptocurrency co-exist and serve different purposes?
If you're interested in that than you should look at the economy for Eve Online. It's definitely the closest thing ever created to a real economy which astounding amounts of information available to study. I'll provide some links that talk about Eve's market from economic standpoints, but these really only scratch the surface of what type of analysis is possible.
[NOTE: I am not an author of any of these posts, and I claim no ownership over them]
http://justinandrewjohnson.com/gaming/eve-online-best-game-e...
http://justinandrewjohnson.com/gaming/The-EVE-Online-Monopol...
Because they realized it would be impossible to fight it and, more importantly, because they probably invested in it themselves. Bitcoin being non-anonymous is a problem that can be solved and is being currently solved.
Also we already had a case of ransomware. How about ransomware that attacks a nuclear facility, flight control tower, hydroelectric plant or whatever else, and threatens to immediately cause damage if a ransom isn't paid. You really want that to be totally 100% off of any ledger anywhere - and not even include a delivery of a briefcase full of cash? Nor any way to follow any of that money at any point whatsoever?
I think btc pseudonymity is a fine compromise.
https://news.ycombinator.com/item?id=4404362 - "Hackers Steal, Encrypt Health Records and Hold Data for Ransom".
and recently https://news.ycombinator.com/item?id=6567735 - "You’re infected—if you want to see your data again, pay us $300 in Bitcoins"
A top comment on that article said: It actually made my skin crawl reading about it. Never had that reaction to such a story before. Interesting...
You might think this might have been a speculative work of fiction. It wasn't - this is a story that happened.
As for your run of the mill kidnappings for ransom, blackmail, extortion and other things normal people turn to the FBI with, (that you would too, if you got certain very specific threatening letters for example), I think if you come back after 5 minutes of googling the subject you would not consider the general situation to be speculative. We are talking about sources of blackmail, kidnapping and ransom becoming literally completely untraceable, without even a network effect of where the money is going afterward (what pseudonymous addresses).
As for the infrastructural, nuclear and so forth examples, you will observe that placing or turning moles and spies already occurs historically, which shows that the process is possible. You are talking about lowering the barrier to entry and risk profile.
Literally anyone who is in a position to do something, and understands that they could instantly anonymously receive a the digital equivalent of a briefcase full of cash, without it ever showing up anywhere, without needing to hide it as they spend it (except regarding the effect it would have on their visible lifestyle -- hell, they could anonymously transfer it to some fake lottery that pretends they just won it...nothing would ever connect the two, the lottery could be a complete front and seem 100% legitimate. Or even actually be 99% legitimate, with a single person adding another payout while collecting funds for it from the person being paid and making sure the lotteries ledger's add up... you get the idea.)
It would be a disaster to have absolutely zero leads whatsoever in all such cases. Money has a profound effect on the world and a modicum of possible pseudonymous oversight over its movements is quite a bit more than minimally responsible.
Ask yourself, for hte data ransoming story I linked: would you prefer for the btc address to be totally and completely a black box, or the present state of affairs?
Really, the current implementation is an absolute minimum for 'keeping people honest'. It has a very high level of barrier to de-anonymizing users (as far as I understand it), yet given sufficient resources certain leads can at least be put together.
Run of the mill kidnappings are parents violating custody agreements.
Infrastructure needs to be resilient in any case.
I don't mind that bitcoin has a public ledger, but you haven't convinced me it is particularly important.
A lot of us are investing with the expectation true anonymous transactions eventually happen, because when they do Bitcoin will become even more valuable.
That's... pretty stupid.
Calling it "privacy scaremongering" would be reasonable if it were simply wrong. But if it's completely correct, and the only reason you disagree is because you're pretty sure it'll eventually be solved, that's crazy.
Not true. There are many, many schemes that can be built into the protocol or on top of it to make transactions anonymous. Rather than hastily choosing one, it's probably better to wait for a really good scheme to surface.
Until then, it's opt-in, a hassle, with a small pool of anonymity. But "impossible" isn't the word I'd use to describe the scenario.
So as it stands truly anonymous transactions are impossible. The possibility to make that not true doesn't negate the fact that today bitcoin is in no way a private way of transferring money.
Something doesn't have to be private to be anonymous. So if you're happy with anonymous and public it's possible, but hard.
In the case of the article, the reason it's suspected, not even confirmed, is simply because the number of wallets coins were coming from were identified as the same source.
It's definitely more anonymous than wire transfers, or credit card transactions. The way to avoid detection would be to keep many, relatively small wallets... and disperse money from different sources fairly evently.
Call it what it is, money laundering.
To quote Wikipedia:
It is defined as knowingly engaging in a financial transaction with the proceeds of a crime for the purpose of concealing or disguising the illicit origin of the property from governments.[1]
More specifically, money laundering is defined in Article 6.1.a.i and 6.1.a.ii of the United Nations Convention against Transnational Organized Crime[2]. The PDF won't let me copy & paste the text, but it uses the language "proceeds of crime" in both subsections.
Some jurisdictions may have monetary reporting laws which are broken during transferring BTCs, but it isn't money laundering (under international law anyway).
[1] http://en.wikipedia.org/wiki/Money_laundering#Criminalizing_...
[2] http://www.unodc.org/documents/treaties/UNTOC/Publications/T...
There are very few legitimate reasons to be concealing where you money came from or is going from the IRS, and they well aware of the intent behind the actions.
Come up with a way for the IRS to investigate (not just get it handed to them on a platter, but something that mathematically requires a level of effort to prevent fishing expeditions by IRS employees) while simultaneously keeping all transactions private from everyone else and then we'll have a solution.
Nice circular reasoning. Because everything that the IRS would disapprove of is illegitimate? When did the IRS get ultimate moral authority?
Spending on sex toys is not special, unless the national security apparatus (or more likely your competitor in the private sector) already has a reason to try to discredit you. Which is a valid concern for activists, but not most people.
Investigations and enforcement actions by the IRS have nothing to do with the morality of your checking account statement and everything to do with tax evasion.
The largest threat to your financial privacy is private enterprise. Underwriters, prospective employers, and others with a financial stake in your "good behavior" are the most interested in judging the moral acceptability/health/prudence of your financial choices.
Amazing.
Translation: "Rights are essential for small group of people, because everyone else is not exercising them anyway. So lets just take the rights away".
2) I'm a person. I have to pay taxes. Top500 corps - not so much, in practice. What do you say about that?
3) Where the fuck did you get that I'm a tax evader? I was addressing your point about people's rights and your evaluation of their need of having those rights.
That's irrelevant. I don't need a reason for concealing where my money comes from.
Oh sure, the IRS may disagree, but I have a really hard time giving a shit about what the IRS thinks.
The same logic applies to encryption. People have a right to privacy.
People don't have an absolute right of privacy - the laws can and do restrict that.
The flippant and universalizing way several of the commenters here are referring to money laundering as "concealing where the money came from" cast far too wide a net.
The definition you're using here would include concealing where $500 came from that was donated by anonymous friends to give to another friend in need. Suddenly, by your metric, if any of the friends suspected of donating the cash to help someone don't fess up to the source of the cash, they're laundering money.
Yeah, that's ridiculous. But it fits your description. Money laundering requires the currency be earnings from criminal activity.
Pretty much the only way to do so 'properly' would require you to make the coins anonymous to the public, but ID all of your customers and keep records on who actually gets which coins in the end.
If you're right and I'm wrong, it'll be a lucrative business and you'll probably quickly dominate the mixer industry, as it'd be very easy for you to get press and build name recognition. You could do it as a very part-time job.
If I'm right and you're wrong, you'll be in prison.
I do think in the mid to long term Zerocoin or something similar should be added to Bitcoin to at least allow people the option to be anonymous if they want to be.
However, I'm also unsure if this should be done right now as governments are trying to decide what to do with Bitcoin. Perhaps it would be better to wait a couple more years, get Bitcoin more established into the mainstream, and adopted by banks and more companies, and then enable something like Zerocoin in the protocol, when it would be too late to stop Bitcoin. Although I'm not sure what the government's reaction towards Zerocoin would be then.
On the other hand, Bitcoin may be even harder to kill than file-sharing/torrenting, in which case maybe it won't matter if it's done now, as the government's action against it could be irrelevant.
You might well get rich from speculating in bitcoin, but if if doesn't pan out then your assets could end up having no value whatsoever - you won't even be able to burn them to keep warm during the zombie apocalypse ;)
I'm not trying to comment on the viability of BTC here, just pointing out that it not the same as many other asset classes.
It's trivial to work against them - simply forbid any legal business offering goods, services or bitcoin-currency transactions to accept such coins. In essence, the same way that they're fighting right now against laundered cash - you can do it, but not on large scale, and it's not accepted for most of assets you want to buy.
Unless you take extreme precautions tracking down the individual behind a wallet would be trivial for a government.
http://www.nytimes.com/2006/08/09/technology/09aol.html?page...
Anonymity is not privacy.
* Spend 100 million for supercomputers to compute this address's wallet in one day.
* Acquire said wallet.
* Reimburse my 100 million debt.
* Enjoy my 50 millions.
Anybody got supercomputers?
From: http://bitcoin.stackexchange.com/questions/22/is-it-possible...
In order to spend money sent to a Bitcoin address, you just need to find a ECDSA public key that hashes to the same 160 bit value. That will take, on average, 2 ^ 160 key generations.
Supposing you could generate a billion (2 ^ 30) per second, you need 2 ^ 130 seconds.
Doing this in parallel using a billion machines requires only 2 ^ 100 seconds.
Getting a billion of your richest friends to join you gets it down to only 2 ^ 70 seconds.
There are about 2 ^ 25 seconds per year, so you need 2 ^ 45 years.
The age of the Universe is about 2 ^ 34 years so far—better get cracking!
Edit: Found it, http://bkeychain.com/buy.html ($12??)