Edit: Thanks to those who took the time to explain. Very interesting.
Edit: Thanks to those who took the time to explain. Very interesting.
It worries me that it's this hard to convince miners to leave a pool. If I wanted to kill Bitcoin and had a few million to spare, I'd open a pool with no fees PLUS a bonus of 1 or 2% from my own pocket. Good luck getting people to leave that pool.
It could be even worse than that however. Another post on BCT[2] talks about a "time warp attack", where at 51% node could effectively mine all remaining bitcoins in one fell swoop.
1. While a 51% pool operator could double spend, none of the participants can do that. The social incentives against a pool operator exploiting this power are very strong, however, because double spends are basically impossible to hide and would destroy the value Bitcoin - which is pretty much against the operator of a mining pool who is likely to hold significant amounts of Bitcoin herself.
2. There is a second possible exploit that is not so well known, which is that a >50% pool can capture all mining rewards. They can do so by never accepting a block mined by somebody else, and instead always mining on their private chain. This pool-specific chain will always ultimately become longer.
The loss of confidence associated with such an attack is probably smaller. So I would bet that if the pool operator has evil intentions, that would be the way to go for them.
See https://en.bitcoin.it/wiki/Weaknesses#Attacker_has_a_lot_of_...
Edit: According to the Wiki linked, these attacks are also possible with <50% mining rate, although with lower probability of success. So this is a problem even if Ghash.io does not crack the 51%.
No, since who holds what coin is defined by consensus, which has to stretch out of the mining pool. If they arbitrarily gave themselves coin, for example, then no other client would accept that they hold that.
See smtddr's reply for details of what they can and cannot do.
Would this be detectable in practice?
The purpose of Bitcoin mining is to establish an ordered sequence of transactions
What can you do with 51%? You can (theoretically) revert a transaction that has been confirmed, by mining blocks attached to a prior point in the blockchain and getting a longer chain than the rest of the network.
What can't you do? You can't spend someone's coins when you never had their private key to begin with. Making a transaction is an act of "signing" and public-private key cryptography is not dependent on the block chain style technique for sending messages, only for making sure that they got through and maintaining them as a ledger.
You can probably single out arbitrary transactions and make sure that those are the ones that are reversed -- your transactions, so the evidence would point back to you, and whomever accepted your bitcoins as payment for something, would potentially know it was you who wronged them.
You could also decline to single out a transaction, just reversing all transactions after a given block and starting a "new life" for all the people who spent their coins after that. When you refused to re-sign the transactions that you made, you would then out yourself.
All of this is fairly academic since the person in charge of 51% of the hash power (GHash.io owner/operator) is a known actor, the hordes have not trusted him/them anonymously, and it turns out that miners have the least incentive to perform this kind of attack, since you lose an amount of revenue equal to the contents of the number of (your) solved blocks that you reversed. They would be more likely in my opinion to accept hashes and proof of work, but then renege and refuse payment to their miners, since this is really a less sophisticated attack and either way you should lose all of your credibility as a pool operator when you are discovered.
I am not at all disputing that 51% attack is one of the known attacks and that 51% of hash power concentrated in the hands of any one actor is something to be prevented.
I also dabble in alt-chains, and the Terracoin chain has often had 51-60% of the hash power in the Coinotron pool.
It happened to GHash.io before, yes. I think they made it right. It's up to the rest of us to take our miners somewhere else to minimize the possibility of a rogue actor at GHash.io causing problems.
As Coinotron once told me, a pool operator just runs a pool, can't control the users. There is no fair way to turn away hash power or "self-police" as a pool operator. I think if I read the graph correctly, the CDF provides a logarithmic probabilistic dis-incentive to be >50% of the hash power and also act fairly (in other words, to work on any broadcasted solved blocks that don't contain rewards belonging to you), so it will be interesting to see what happens next.