NIST Randomness Beacon
nist.gov
nist.gov
They use signed contracts combined with a novel mixing fee mechanism based on public randomness to ensure honest behavior by rational Bitcoin mixes. If you're interested in Bitcoin the full paper is worth a read.
[^1]: http://www.nist.gov/itl/csd/ct/beacon-secure-multi-party-com...
Selfish mining requires strategically withholding blocks, the NIST random beacon gives you unforgeable timestamps, thus during block races you can prefer blocks that have newer unforgeable timestamps. Those older withheld blocks will lose blockraces punishing selfish miners.
Unforgeable except by anyone who's able to order or trick NIST into doing something.
If NIST is unimpeachable, why not just have them run the anti-double-spending database and dispense with this inefficient blockchain stuff? :)
> prefer blocks that that have newer unforgeable timestamps
This general class of solutions often runs into problems with creating incentives for large miners to continue to mine at your current height and ignore a third party block, because you know you'll beat it in a race even though you announced late.
Because even if NIST helps someone cheat, the cheaters only get a minor advantage and NIST runs a huge risk. Having an additional security measure which doesn't endanger the entire system if it is broken is not that same as trusting NIST.
Furthermore you can also compose the NIST beacon with other random beacons so that they would all have to collude for any party to cheat.
Imagine tomorrow, we find out a small (<33%) pool is selfish mining, what is a fix we can roll out in a few hours that will stop them while we examine longer term solutions (a long term solution might be asking every pool above 33% to provide a beacon and then having miners compose these beacons).
>This general class of solutions often runs into problems with creating incentives for large miners to continue to mine at your current height and ignore a third party block, because you know you'll beat it in a race even though you announced late.
Yes, we run into these problems at 33% of mining power. That being said, a 33% attack is better than the 0.5% attack.
I also have no trouble conceiving of a scenario in which the US government may want to make an invalid scientific paper appear valid.
WARNING:
DO NOT USE BEACON GENERATED
VALUES AS SECRET
CRYPTOGRAPHIC KEYS.
Can you point to where exactly do they advocate what you say?Am I the only one who read the entire page? There are three links prominently featured on the page under the "Uses" header:
http://www.nist.gov/itl/csd/ct/beacon-unpredict-sampling.cfm
http://www.nist.gov/itl/csd/ct/beacon-new-secure-auth-mechan...
http://www.nist.gov/itl/csd/ct/beacon-secure-multi-party-com...
Which the page clearly notes: "WARNING: DO NOT USE BEACON GENERATED VALUES AS SECRET CRYPTOGRAPHIC KEYS."
I mean, people weren't going to trust NIST on this anyways but if you're going to warn about crypto then it should probably be more prominent.
After reading your comment I had another peek... I think the background colour is inappropriate considering the surroundings, I had some trouble reading it well.
If there is a NSL gag order in effect for the work recognized by the 2012 Physics Nobel how did the committee hear about the work? You think the scientific community just took Haroche and Wineland's word and never looked into their results?
These data points have absolutely nothing to do with practical, trustworthy crypto standard processes or confidence in their ability to due-diligence systems.
To recap; you started this thread with "Who in their right mind would trust anything NIST offers." I responded by pointing out that there is a very talented group of people working on metrology at NIST and that some of these individuals have been awarded Nobels. What is the connection between trustworthy crypto standards and metrology?
Nobel snobels, still has nothing to do with crypto.
Thank you for arguing my original position for me.
Further, weights and crypto are night and day. I'm sure they have the best clocks and reference weights, but everything that comes out of that shop is tainted.
WARNING:
DO NOT USE BEACON GENERATED
VALUES AS SECRET
CRYPTOGRAPHIC KEYS.Do you work for NIST or NSA? Just curious.
A public source of random numbers is useful in almost all the fields mentioned in [1].
What's wrong with any hardware RNG that produces 0's and 1's straight from physics, if these also pass the relevant statistical tests?
What's wrong with any hardware RNG that produces 0's and 1's straight from observing natural phenomena like "thermal noise, the photoelectric effect, and other quantum phenomena", as wikipedia puts it[1].
How can they do better than that; specifically, what do they mean with "demonstrably unpredictable values"?
[1] http://en.wikipedia.org/wiki/Hardware_random_number_generato...
ASCII:
entropy sources -> entropy pool -> CSPRNG -> ...Given that you'd probably want to avoid using for any crypto use (not just secret parameters) unless you can be sure that using this randomness for a public parameter doesn't break the cryptosystem (or USG isn't in your threat model). Given that few of us are experts in cryptology it would seem like the safe thing to do is to avoid for crypto use at all.