{"type":"rich","version":"1.0","author_name":"npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw","author_url":"https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2011-09-13\n🗒️ Summary of this message: Bitcoin's \"timejacking\" vulnerability allows miners to manipulate block timestamps, leading to difficulty adjustment issues. Fixing it requires addressing the \"what time is it\" code.\n📝 Original message:Background:\n\nTimejacking:\n  http://culubas.blogspot.com/2011/05/timejacking-bitcoin_802.html\n\nAnd a recent related exploit launched against the low-difficulty\nalternative chains:\n  https://bitcointalk.org/index.php?topic=43692.msg521772#msg521772\n\n\nSeems to me there are two fundamental problems:\n\n1) Bitcoin should be overlapping the ranges of block timestamps that\nit uses to calculate difficulty adjustments.\n\n2) Bitcoin's \"what time is it\" code is kind of a hack.\n\n\nFixing (1) would mean a potential block-chain split; before\nconsidering doing that I'd like to consider second-best solutions.\n\nFixing (2) is easier; incorporating a ntp library and/or simply\nremoving the bitcoin mining code from the client but requiring pools\nand miners to have accurate-to-within-a-minute system clocks (or their\nblocks will be \"discouraged\") seems reasonable to me. If you want to\nproduce blocks that the rest of the network will accept, run ntp on\nyour system.\n\nI THINK that fixing (2) will make (1) a non-issue-- if miners can't\nmess around with block times very much then it will be very difficult\nfor them to manipulate the difficulty for their benefit.\n\n-- \n--\nGavin Andresen"}
