{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2013-05-06\n📝 Original message:On Mon, May 6, 2013 at 3:51 PM, Adam Back \u003cadam at cypherspace.org\u003e wrote:\n\u003e Maybe I could hack a pool to co-opt it into my netsplit and do the work for\n\u003e me, or segment enough of the network to have some miners in it, and they do\n\u003e the work.\n\nOr you can just let it mine honestly and take the Bitcoins. This is\nfast (doesn't require weeks of them somehow not noticing that they're\nisolated), and yields the values I listed as 'costs' if you would have\notherwise been able to use it to mine the difficulty down to 1.  Cost\nis just as much foregone income from the alternative attack you could\nhave done instead.\n\n\u003e nor even topological, nor even\n\u003e particularly long-lived.\n\nAt least for attacks that drive the difficulty down it does.\n\nIf you want to talk about abusing a pool or creating a partition in\norder to create short reorgs— I agree, those don't have to be long\nlived and you can find many messages where I've written on that\nsubject.\n\nIt's inconsiderate to propose one attack and when I respond to it\nchanging the attack out from under me. :(  I would have responded\nentirely differently if you'd proposed people segmenting the network\nand creating short reorgs instead of mining the difficulty down.\n\n\u003e Do you know if there is any downwards limit on difficulty?  I know it takes\n\u003e going slow for a long and noticeable time, but I am just curious on the\n\u003e theoretical limit.\n\nEvery 2016 blocks can at most lower the difficulty by a factor of 4,\nthats where the log4 (number of 2016 groups needed) and 4^n (factor in\ncost reduction for each group) come from in the formulas I gave\npreviously.\n\n\u003e I dont see the signatures.\n\nhttp://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.8.1/SHA256SUMS.asc/download\n\nThe signatures can't be inside the tarball because they sign the tarball.\n\nSeems like the website redesign managed to hide the signatures pretty\ngood. They're in the release announcements in any case, but that\nshould be fixed.  Even when they were prominently placed, practically\nno one checked them. As a result they are mostly security theater in\npractice :(, — so— unfortunately, is SSL: there are many CA's who will\ngive anyone a cert with your name on it who can give them a couple\nhundred bucks and MITM HTTP (not HTTPS!) between the CA's\nauthentication server and your webserver. Bitcoin.org is hosted by\ngithub, even if it had SSL and even if the CA infrastructure weren't a\njoke, the number of ways to compromise that hosting enviroment would\nIMO make SSL mostly a false sense of security.\n\nThe gpg signatures and gitian downloader signatures provide good\nsecurity if actually used, solving the \"getting people to use them\"\nproblem is an open question.\n\nAnd I agree, this stuff is a bigger issue than many other things like\nmining the difficulty down."}
