<oembed><type>rich</type><version>1.0</version><author_name>npub1ac86vemj7ce5z8jyxt39rna3tvwql6xd30ha3vxcd6esysp23d9qrlswfj</author_name><author_url>https://nostr.ae/npub1ac86vemj7ce5z8jyxt39rna3tvwql6xd30ha3vxcd6esysp23d9qrlswfj</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2013-05-06&#xA;📝 Original message:On Mon, May 06, 2013 at 11:25:50AM -0700, Gregory Maxwell wrote:&#xA;&gt;On Mon, May 6, 2013 at 11:04 AM, Adam Back &lt;adam at cypherspace.org&gt; wrote:&#xA;&gt;&gt; bitcoins primaryvulnerability IMO (so far) is network attacks to induce&#xA;&gt;&gt; network splits, local lower difficulty to a point that a local and&#xA;&gt;&gt; artificially isolated area of the network can be fooled into accepting an&#xA;&gt;&gt; orphan branch as the one-true block chain,&#xA;&gt;&#xA;&gt;It currently costs about 2016*25*$120 = six million dollars to&#xA;&gt;reduce the difficulty in your isolated fork by a factor of 4.&#xA;&#xA;Well I take your point that you have to produce 2016 blocks, but at a lower&#xA;rate.  But that doesnt directly translate into my cost, I am thinking pure&#xA;network hacking.&#xA;&#xA;Maybe I could hack a pool to co-opt it into my netsplit and do the work for&#xA;me, or segment enough of the network to have some miners in it, and they do&#xA;the work.&#xA;&#xA;I am just thinking $500k/day worth of relatively perfect crime reward is a&#xA;lot of motivation for hacking networks.  Many routers home and even carrier&#xA;are vulnerable to people armed with cisco source code &amp; 0-days.  The&#xA;netsplit doesnt have to be geographical, nor even topological, nor even&#xA;particularly long-lived.&#xA;&#xA;If you control enough people&#39;s network routing at a low enough level, you&#xA;dont even have to stop transactions, nor do any mining work, just stop&#xA;blocks from the netsplit crossing over, and hold that position for say a day&#xA;(if your netsplit has 1/24 of network hash rate in it, so the split gets 6&#xA;confirmations to reassure the victims) and let the miners do the work.  Do&#xA;enough transactions to do a big cash out (spend differently on the two&#xA;netsplits).  Obviously a big and human inattentive pool, dark-miner etc is&#xA;the ideal target to put into the netsplit to increase the power while&#xA;controlling less nodes.&#xA;&#xA;Malware could do the same thing for clients, dont forget most are running&#xA;windows.  Malware could also start a miner if none present.&#xA;&#xA;&gt;&gt; maybe even from node first install time.&#xA;&gt;&#xA;&gt;Protecting against that— making sure any such attack has to start from&#xA;&gt;a high difficulty— is, in my opinion, the biggest continued&#xA;&gt;justification for checkpoints.&#xA;&#xA;Do you know if there is any downwards limit on difficulty?  I know it takes&#xA;going slow for a long and noticeable time, but I am just curious on the&#xA;theoretical limit.&#xA;&#xA;&gt;&gt; (btw I notice most of the binaries and tar balls are not signed, nor served&#xA;&gt;&gt; from SSL - at least for linux).&#xA;&gt;&#xA;&gt;They are signed.&#xA;&#xA;I dont see the signatures.&#xA;&#xA;http://bitcoin.org/en/download&#xA;&#xA;I see no signatures for linux and none in the tarball.  There are some&#xA;public keys inside the tarball, thats it.  Also no SSL.  sourceforge support&#xA;SSL so you can download that.  But bitcoin.org doesnt even answer 443, and&#xA;the source forge link is HTTP.  But even if the sourceforge link was SSL one&#xA;should not serve an SSL download link from an HTTP page, any more than type&#xA;a password into an HTTPS form action on an HTTP page.  The attacker can just&#xA;redirect and the user doesnt know what is legitimate.&#xA;&#xA;Consequently even if there is code signing on the windows exe, the user&#xA;doesnt know that, nor who they should be signed by, and as they are served&#xA;via HTTP, its bypassable.&#xA;&#xA;I guess by far the easiest way to attack right now (at least linux users) is&#xA;just to change the binaries to create a user operated netsplit, or just have&#xA;all their wallets empty to you via a mix once the amount gets interesting.&#xA;&#xA;(All attacks hypothetical of course - I&#39;m actually a white-hat type of&#xA;person).&#xA;&#xA;Adam</html></oembed>