{"type":"rich","version":"1.0","author_name":"npub1ac86vemj7ce5z8jyxt39rna3tvwql6xd30ha3vxcd6esysp23d9qrlswfj","author_url":"https://nostr.ae/npub1ac86vemj7ce5z8jyxt39rna3tvwql6xd30ha3vxcd6esysp23d9qrlswfj","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2013-05-06\n📝 Original message:On Mon, May 06, 2013 at 11:25:50AM -0700, Gregory Maxwell wrote:\n\u003eOn Mon, May 6, 2013 at 11:04 AM, Adam Back \u003cadam at cypherspace.org\u003e wrote:\n\u003e\u003e bitcoins primaryvulnerability IMO (so far) is network attacks to induce\n\u003e\u003e network splits, local lower difficulty to a point that a local and\n\u003e\u003e artificially isolated area of the network can be fooled into accepting an\n\u003e\u003e orphan branch as the one-true block chain,\n\u003e\n\u003eIt currently costs about 2016*25*$120 = six million dollars to\n\u003ereduce the difficulty in your isolated fork by a factor of 4.\n\nWell I take your point that you have to produce 2016 blocks, but at a lower\nrate.  But that doesnt directly translate into my cost, I am thinking pure\nnetwork hacking.\n\nMaybe I could hack a pool to co-opt it into my netsplit and do the work for\nme, or segment enough of the network to have some miners in it, and they do\nthe work.\n\nI am just thinking $500k/day worth of relatively perfect crime reward is a\nlot of motivation for hacking networks.  Many routers home and even carrier\nare vulnerable to people armed with cisco source code \u0026 0-days.  The\nnetsplit doesnt have to be geographical, nor even topological, nor even\nparticularly long-lived.\n\nIf you control enough people's network routing at a low enough level, you\ndont even have to stop transactions, nor do any mining work, just stop\nblocks from the netsplit crossing over, and hold that position for say a day\n(if your netsplit has 1/24 of network hash rate in it, so the split gets 6\nconfirmations to reassure the victims) and let the miners do the work.  Do\nenough transactions to do a big cash out (spend differently on the two\nnetsplits).  Obviously a big and human inattentive pool, dark-miner etc is\nthe ideal target to put into the netsplit to increase the power while\ncontrolling less nodes.\n\nMalware could do the same thing for clients, dont forget most are running\nwindows.  Malware could also start a miner if none present.\n\n\u003e\u003e maybe even from node first install time.\n\u003e\n\u003eProtecting against that— making sure any such attack has to start from\n\u003ea high difficulty— is, in my opinion, the biggest continued\n\u003ejustification for checkpoints.\n\nDo you know if there is any downwards limit on difficulty?  I know it takes\ngoing slow for a long and noticeable time, but I am just curious on the\ntheoretical limit.\n\n\u003e\u003e (btw I notice most of the binaries and tar balls are not signed, nor served\n\u003e\u003e from SSL - at least for linux).\n\u003e\n\u003eThey are signed.\n\nI dont see the signatures.\n\nhttp://bitcoin.org/en/download\n\nI see no signatures for linux and none in the tarball.  There are some\npublic keys inside the tarball, thats it.  Also no SSL.  sourceforge support\nSSL so you can download that.  But bitcoin.org doesnt even answer 443, and\nthe source forge link is HTTP.  But even if the sourceforge link was SSL one\nshould not serve an SSL download link from an HTTP page, any more than type\na password into an HTTPS form action on an HTTP page.  The attacker can just\nredirect and the user doesnt know what is legitimate.\n\nConsequently even if there is code signing on the windows exe, the user\ndoesnt know that, nor who they should be signed by, and as they are served\nvia HTTP, its bypassable.\n\nI guess by far the easiest way to attack right now (at least linux users) is\njust to change the binaries to create a user operated netsplit, or just have\nall their wallets empty to you via a mix once the amount gets interesting.\n\n(All attacks hypothetical of course - I'm actually a white-hat type of\nperson).\n\nAdam"}
