And that one too was quite poorly done; from the text, it actually seemed like they thought that "the blockchain" is a file stored on blockchain.info. Disappointing from the inventor of Shamir's Secret Sharing and differential cryptanalysis.
And that one too was quite poorly done; from the text, it actually seemed like they thought that "the blockchain" is a file stored on blockchain.info. Disappointing from the inventor of Shamir's Secret Sharing and differential cryptanalysis.
We acquired the complete state of the Bitcoin transaction system [...]
This required downloading 180,001 separate but linked HTML files [...]
following the links backwards to the zeroth block [...]
Each file was parsed in order to extract all the multisender/multireceiver transactions in it, and then the collection of transactions was encoded as a standard database on our local machine.
This is definitely a very strange way of retrieving the blockchain for research purposes. Couldn't they have simply issued RPC calls to the regular bitcoind client after downloading the blockchain via the built-in peer-to-peer mechanism?It's a lot easier to just get it from blockchain.info.
People seem to confuse that a lot. It's a badly named service at the best of times. I wonder how many legal requests the site will get from people believing they run Bitcoin.
"This site allows you to navigate the bitcoin blockchain (a database which holds information about all transactions)."
That really does make it sound like they are storing the centralized database for bitcoin.
Edit: changed "storing a" to "storing the" to clarify my point per gojomo's reply.
(They have some earned authority, by a record of useful service.)
Bitcoin isn't the simplest concept around. Unless you are in the business of packaging up bitcoin for non-technical consumers, I think it is reasonable to expect your users to bring some knowledge about bitcoin to the table.
Indeed, as I was reading the post I thought to myself "it couldn't be that Shamir, could it?" Oh.
The New World is built on the results of that generation of cryptographers, but they can't keep up.
Yeah, I'm more than a little bitter about the technologically illiterate being allowed to judge complex technology.
Meanwhile these guys are merely riding on the huge waves which that 'poorly researched' paper left in its wake, trying to catch some press-coverage-by-association with their shoddy research. I'm failing to see the irony here, this is apples and oranges stuff. Really seems like you just wanted to sneer at 'Bitcoin supporters'.
I mean that it was poorly researched. There was no definition of security, no mention of the vast body of related work in digital cash or secure multiparty computation, a weak security analysis, no mention of the fact that polynomial time attacks are usually considered to indicate that a system is not secure (one would think that a different security model would require at least some justification), and so forth. That is not the mark of a solid research paper; the fact that Bitcoin has become so famous or that people are making money with it has no bearing on the quality of Satoshi's own research.
The Bitcoin whitepaper does what it says on the tin, you're the one inventing criteria for it that it doesn't meet. The white paper is also remarkably readable, which is something you can't say for most academic works.
I don't think there is any way to get him to stop saying that bitcoin isn't an achievement and that it is a priori invalid because it doens't have a "formal security model."
1. It is irrelevant to this thread, because I was only talking about Satoshi's paper.
2. It is not the sort of security people demand out of other cryptosystems. There is a reason nobody uses this:
That is because no falsifiable claims were made.
(Edit: Strictly speaking, this is not true. Falsifiable claims were made; this, for example:
An attacker can only try to change one of his own transactions to take back money he recently spent.
This claim has already been falsified: an attacker who can control the block chain can also selectively deny transaction verifications and prevent miners from receiving the mining reward.)
"you're the one inventing criteria for it that it doesn't meet"
No, I am just stating the criteria that determine how well-researched a paper is. If a paper does not cite the relevant previous work, it is poorly researched -- that is the standard that every other paper is held to. If a cryptography paper does not have a well-formed or clearly articulated security definition, it is poorly researched -- that is the standard other cryptography papers are held to. If a security paper breaks from widely accepted notions of security but never bothers to justify that, it is poorly researched. These are not unheard-of criteria, these are standard fare.
"The white paper is also remarkably readable"
What is your point? Readability is orthogonal to how well-researched a paper is.
This is elevating form above substance. Ron & Shamir's work has the proper form, the proper names, and yet the material it contains is rubbish. It cites "relevant previous work", so long as you think that none of the work in industry is relevant.
The gold standard should not be if a work follows a set of practices, advisable as they may be, it should be if a work advances the understanding of mankind. One of these papers did, the other does not.
G. H. Hardy said that his most important contribution to the study of mathematics was the discovery of Ramanujan. One could easily make the mistake of thinking this contribution could have been easily replicated by someone else, but its entirely likely that never would have happened at all because Ramanujan was not aware of much of the contemporary work that he blitzed past.
Block ciphers do have security definitions; what AES lacks is a rigorous proof that it satisfies the definition of security for a block cipher. There are different definitions for different notions of security, but that does not mean there is no security definition. It is also untrue to suggest that security parameters are fixed in practice; this is certainly false for public-key cryptography, but Rijndael was designed to support arbitrary parameters, as are many other practical block ciphers and hash functions.
"Coming up with a good security definition is hard, the 2013 Turing award was given for one."
Not one definition, but several definitions and an entire paradigm for definitions. The work also set the groundwork for proving that cryptosystems and cryptographic constructions meet such definitions.
Really, the importance of having a security definition cannot be understated. Without a security definition, you cannot have any falsifiable claims about security. If I claim a system without a definition is insecure, you can always refute me by claiming that the system was never designed to defend against my attack -- which is technically correct, because without a definition the system cannot be said to be designed to defend against any attacks.
Also, note that I did not say that Satoshi failed to give a good security definition for Bitcoin. What I said is that Satoshi failed to give any security definition. If Satoshi had given an unrealistic or otherwise bad security definition, then we could have a productive conversation about the definition and about whether or not Bitcoin satisfies it.
"I think it will take a long time before we get a realistic security definition for Bitcoin."
The thing is that we do have realisitic security definitions for digital cash -- the definitions just happen to rely on the existence of a central authority that issues the currency, which is a deal-breaker for the Bitcoin community.