Bitcoin security guarantee shattered by anonymous miner with 51% network power
arstechnica.com
arstechnica.com
If a greedy attacker is able to assemble more CPU power than
all the honest nodes, he would have to choose between using it
to defraud people by stealing back his payments, or using it to generate
new coins. He ought to find it more profitable to play by the rules, such
rules that favour him with more new coins than everyone else combined, than
to undermine the system and the validity of his own wealth.Ideally one would think "it's all about happiness" would be the goal, not a measure of asset worth, but rather contentedness perhaps? It doesn't take much thinking to imagine why we can't function in that way, however.
All models are wrong, but some are useful. What is the chance that there is an irrational player that spends a lot of money only to destroy bitcoin? This kind of player has to be politically motivated, not just simply irrational.
> Besides, there are plenty of profitable avenues if you control 51%
Like what? Basically you can do a few things:
1) Mine all the current coins
2) Double-spend
3) Not confirm any transactions
All of them are harmful to the network. However, given that it is not an actual single entity that controls 51%, I wouldn't be worried much about anything except 1)
Etc, etc.
The game theorists assume at the outset that everyone involved's primary financial interest is in a valid working Bitcoin network. However, banks and Western Union would not desire competitors for international currency transfer. Governments may not want currencies they can't control. The Russian mafia may want to exploit it for short-term gain or launder money. And now that there's a single pool with >51% of the CPU power, the difficulty of a hostile takeover just went way, way down.
Before, a group would have to set up a massive amount of computing power in order to take it over, but now, taking over or disrupting Bitcoin is within the reach of non-technical entities like criminal organizations and the CIA. E.g., all the CIA has to do is threaten a few people and say "Insert this code so we can freeze the transactions of $VILLAIN_OF_THE_MONTH at any time." There's many more possibilities now.
Then game theory is pretty useful model. Players are rational, after all. Thats what's game theory is about.
> Governments may not want currencies they can't control.
Makes perfect sense. But we're discussing 51% attack. Would a miner with 51% of hashrate willingly help a government(and why would he)?
Or, would a government simply try to legislate bitcoin out of existence? I would say that the latter is more likely than the former.
> And now that there's a single pool with >51% of the CPU power, the difficulty of a hostile takeover just went way, way down.
Remember, it is not a single entity. It is a pool. And, in fact, ghash.io share is down to 39%.
> all the CIA has to do is threaten a few people and say
I do agree with this point. One of the strongest points of bitcoin is decentralization. We should keep bitcoin as decentralized as possible. But I would say ghash.io having 51% is a minor obstacle.
Bitcoin players aren't rational. Karpeles stood to earn way more by not manipulating the market. He did so anyway and bankrupted his own company.
Game theory assumes all players are smart.
Sorry, I wasn't clear enough. My argument is that the people citing game theory as a reason Bitcoin players had an incentive to avoid a 51%+ scenario kept assuming that all players wanted Bitcoin to succeed.
(However, as a former cognitive neuroscientist, I think it's mistaken to assume that people always act rationally. Check out the literature on the ultimatum game or anchoring effects in prospect theory (for which Kahneman got the Nobel prize) to see examples of people acting irrationally in a sytematic, biased way.)
> Would a miner with 51% of hashrate willingly help a government(and why would he)?
Who said anything about being willing? My example suggested threats, which is way more likely than cooperation.
> Remember, it is not a single entity. It is a pool. And, in fact, ghash.io share is down to 39%.
Yes, but the people running the pool have the keys to the kingdom as long the pool members don't know. So, more subtle perversion has a good chance of lasting a while, while gross manipulation is more likely to cause pool members to switch.
Irrational in this context (game theory) means self-defeating, but only in the confines of Bitcoin. It doesn't mean insane in the common sense.
So you can very well be "politically motivated" and irrational in this regard.
https://bitcointalk.org/index.php?topic=393815.0
https://bitcointalk.org/index.php?topic=399313.0
"...if every bank vault in the world had a vulnerability that you (and only you) could exploit, possibly without detection (or at least with a degree of deniability)... what would you do?"
Most people wouldn't immediately do the (irrational) thing and abuse that power on a large scale because obviously, the global instability/problems would outweigh the rewards.
"Sooner or later, if given the opportunity to take unfair advantage of the system day after day, month after month, I think a lot of otherwise "trustworthy" people/organizations will end up giving in, albeit in subtle ways at first. Most people left to their own devices wouldn't flip a switch (for a reward) to immediately contaminate all of the world's fresh water at once, but if given a million switches each of which contaminates just 1 millionth of the world's fresh water for a substantial reward... I think there'd be some serious switch-flipping going on."
The problem with Bitcoin (as described in the original Bitcoin paper) is that Satoshi apparently didn't account for the very real likelihood of pools gaining substantial amounts of power.
"If a greedy attacker is able to assemble more CPU power than all the honest nodes..." sounds like a very remote possibility in the context of a world where every miner operates independently, and if pools didn't exist, it probably would be very unlikely. If every miner truly controlled his or her own mining power, I doubt we'd ever run into this problem.
I think this completely ignores the fact that messing with the block chain would seriously screw over all the miners that are choosing this network for monetary reasons. Your analogy is flawed. Basically, it's more like "if every bank vault in the world had a vulnerability that you (and only you) could exploit, and you spent tons of money to get that vulnerability, and exploiting it would make all your money worthless, what would you do?" That's more like the actual situation here.
Also, the pool operators (who have the ability to exploit this power) have not really spent large sums of money themselves. They have power because ignorant minors are essentially handing over their vote to the pool operators in exchange for convenience and low variance.
Tragedy of the commons averted, for now.
Which means it didn't happen. It would be blatantly obvious to watch whenever GHash was mining on the 'wrong' chain to try to make it win. Even if GHash had 80% of the mining power, about one in 25 blocks would see non-GHash miners win twice in a row and unarguably expose this behavior as GHash ignored them.
I don't think people will like their financial system unfairly tampered with.
People say, "Why would Ghash do that? They profit from the system they'd be manipulating." Well, so did Mt. Gox, and it didn't stop them from manipulating it anyway.
But to answer when, I'd say probably after getting at least 60 percent of the network to control it comfortably without instability and slowdowns.
Also even if another pool won twice in a row it wouldn't matter. Over the next few blocks ghash's blockchain would become longer and all bitcoin clients would accept it.
What I'm saying with the double-win is that it blatantly exposes GHash's ignoring of blocks they don't like, not that they would actually lose over time.
Why is GHash so popular to miners?
But please, don't stop here. What the most powerful political leader in your country could do bad ? What the most powerful economical leader in your country could do bad ?
"Power" as a concept is something that would need deeper inspection by everyone, and should probably be dissolved as much as possible (that's the point of democracy). If 51% attack scares you, push your reasoning to its ultimate point.
That seems to be one of the fundamental paradoxes in the anarchistic ideal of Bitcoin - that implicitly, collective action to centralize and exploit the system is a perfectly legitimate act within its framework, if you can get away with it.
I'd say it's more a libertarian ideal. You'd have the same idea in an actual anarchy of course, except that rolling up all the communes by force wouldn't be considered legitimate just because you're able to do it.
Someone on reddit went and did a Monte Carlo simulation to show them that that really wasn't true so long as the pool had at least a few percent of over all hashing power and that any risk to the BTC price from the negative perception of a 51% attack was far costlier than the couple tenths of a percent you might get by going with the largest pool.
http://bitcoinswitzerland.wordpress.com/2014/06/15/miners-lu...
The pool addresses seem like they would be reasonably easy to come by, but I'm not sure about estimating the mining power of the various pools.
Woah, can someone please explain why this is?
A chain losing consensus can happen retroactively (and by design does, frequently), but shouldn't after about 6+ confirmations (~1 hour of work by the network) unless you control a lot of power and are willing to secretly build a competing chain starting from a point in the past and build past the existing consensus chain. If you are willing and capable of outrunning the network for sustained periods of time, you can rollback the history believed by the network and replace it with a history which includes only those transactions which you think should have happened.
For example: did you pay your rent an hour ago? Did your landlord accept your payment after an hour and send it to Bitstamp, thereby getting money? Did Bitstamp then allow people to withdraw it? Psych. You remember that happening, but the Bitcoin consensus now says that the Bitcoin half of all those transactions never happened.
You could, for example, announce "Apropos of nothing: we find that transactions with 1% fees [paid to the miner of the block] are pleasing to the Bitcoin gods and are only willing to include them in our blocks. BTW, we will also rollback history periodically for the hell of it. If you want your transactions to survive rollbacks, take note."
The new development seems to be that one player is verifiably controlling 51% of the market. This doesn't mean that two pools who each had 30% couldn't have colluded outside of the network to control it beforehand. I've seen people trying to persuade people not to join the most popular pool but this seems like a more fundamental problem.
I see no particular reason why bitcoin addresses should remain anonymous in the future, making the impact of this power less, but still a fix to the protocol or a lot more miners will be preferable.
I would love to know if this is because the GHash pool has grown (through presumably investing 2012/13-bitcoin profits into hardware) or if it's because others stopped hashing.
It has grown, but not because of Bitcoin profits. cex.io is probably the easiest on-ramp to mining, and all miners are pointed at GHash.
The most complete and accurate statement on the entire thread.
So basically any government or any wealthy individual (or maybe even anyone with a botnet) could easily muster enough computing power to destroy Bitcoin?
I thought by this point the amount of computing power required to do that was supposed to be ungodly...
It would be less depressing if these real issues were novel; but they were written about by authors as far back in time as Hobbes.
Edit: so many people are upvoting this that we'll unbury it.