1,249 karma · joined January 25, 2013
Also, when parts of the government have attacked the security provided by Tor, it's been visible (and kind of hamhanded) [2].
[1] http://cryptome.org/2013/10/nsa-tor-stinks.pdf [2] https://freedom-to-tinker.com/blog/felten/why-were-cert-rese...
Also, the article states very clearly states: "If you use the same browser for your anonymous and normal Internet activities, for instance, websites can use “browser fingerprinting” techniques like cookies to identify you.", which is basically the point of this post.
The WIRED piece even goes further, offering the same solution as is offered in this piece: "[an expert] suggests that even when routing traffic over Tor with Anonabox, users should use the Tor Browser, a hardened browser that avoids those fingerprinting techniques."
So while I understand the gripe that a transparent Torifying proxy doesn't necessarily do what you think it should, I would also praise WIRED for doing a pretty good job of handling these difficult and subtle issues in their article about the Anonabox.
[1] http://www.wired.com/2014/10/tiny-box-can-anonymize-everythi...
If I submitted a piece to a major outlet such as this, I would do so in full faith that they would assign at least one person to read through it and copy-edit it before publication. Apparently, Time is not a sufficiently reputable institution of journalism to believe in doing this, or at least is unwilling to spend enough money to have it done by competent people.
EDIT: As for Janet's credibility, I can speak to it personally, having spent a year with her working down the hall from my office. Probably the coolest stuff she's done relates to how decisions are made in big teams of scientists (she studied the sociology of scientists running some Mars rover missions: http://janet.vertesi.com/projects/social-life-spacecraft).
I really can't see any substance here. The name is also sort of darkly humorous: they've clearly poured a lot of effort into (at least marketing) what they're doing, but have yet to realize that they're just tilting at windmills.
But the most important question about the dynamics of Bitcoin mining, which nobody has yet answered, is whether there is an equilibrium that can actually occur in which the Bitcoin economy can no longer function. This is the question that everyone would like to answer.
Indeed, the Cornell attack on Bitcoin mining claims to demonstrate that Bitcoin is not incentive compatible. This claim is demonstrably wrong. The burden of proof is on the original authors to rebut their (correct) detractors.
Yes, I think they could. I'm currently trying to model what happens in mining pools where the pool master attempts to keep the pool's state a secret from the pool members to deter the kind of hopping behavior necessary for fair weather mining.
One could even imagine creating "poison pill" derivative instruments where someone agrees to sell a lot of BTC if some predicate over the blockchain becomes true (such as a predicate that's only true if ES-mining is happening).
http://www.reddit.com/r/Bitcoin/comments/1puk1a/arxiv_paper_...
Our argument is that the protocol, as stated, is not incentive compatible. That's ironic, because the protocol, as stated, is offered as an argument that Bitcoin is not incentive compatible.
Let me lay out the argument from our post in a more technical way: the biggest problem with the Eyal/Sirer paper is that they don't think about the problem as an equilibrium problem, but rather argue about what's best from the perspective of a particular player. This leads them to propose a strategy which is not even optimal for any player (we prefer to think of Bitcoin as a kind of consensus game, in the game theoretic sense. See our earlier paper on the topic [1]).
They argue that Bitcoin is not incentive-compatible by virtue of the strategy they demonstrate. I think this question needs to be the crux of any Bitcoin research paper. I'll define "incentive compatible" to mean one of two things
(1) (weakly incentive compatible) If people follow their incentives, rather than the rules of Bitcoin as written down and understood by the community, then there exists an equilibrium in which all players follow the rules.
(2) (strongly incentive compatible) The above equilibrium is the only equilibrium in Bitcoin.
The question of whether the current Bitcoin ruleset is incentive compatible strikes me as the most important Bitcoin research question: it answers whether Bitcoin, as a system, will continue to be stable over the long term. A secondary question is to ask "what rule sets could exist which would be incentive compatible?" Obviously, if the answer to the first question is "no" then the second question is more important.
(Learn to read Korean in 15 minutes)
Some of the content in there is particularly golden for humor value (search "perfect 10"), but more importantly, it serves as a first step to quantifying how many of these letters get sent and how many of those are legitimate. Chilling Effects doesn't track what happens afterwards, but it's one step above anecdote, anyway.
Think of it like a poll. Would you make the claim that politicians are willing to write off people who respond to polls just because they all answer the same question or the question isn't somehow the "right" one? Probably not.
Of course, it's not a poll because people self-select. But even still, if the report to the representative says "this week, we had 37 letters about gun control and 43,742 about surveillance", well, it's clear what the politician wants to say that he or she is doing something about when he or she next sees a reporter.
In particular, the right test of openness is this: can I build an interoperable client that could participate in a Hangout as a first-class entity?
It's good to prevent the re-sharing of child pornography, but a lot of companies don't like to talk about the systems because they're very much the same systems that the same companies are busy telling the content industry that they can't build to enforce copyrights. So they're generally kept pretty hush-hush by a kind of gentleman's agreement.
I think general copyright is actually a thornier problem and this secrecy is unnecessary. CP is just something you can block if you see it. Tracking down exactly which uses of a copyrighted work are intended to be allowed and which are not is really much harder. And I think that's a legitimate argument, especially because it recasts the copyright debate in terms of compromises that make sense: if clearing a bunch of rights is confusing, maybe certain types of compulsory licenses are more attractive. But that debate is for another thread...
Also interesting is Steve Bellovin et al.'s excellent report on security implications of extending CALEA to VoIP: https://www.cs.columbia.edu/~smb/papers/CALEAVOIPreport.pdf Steve Bellovin is now the FTC's Chief Technologist and spends his days trying to bring technical sanity to the government in various ways.
Exercise for the reader: determine whether these sets are different in a meaningful way.