<oembed><type>rich</type><version>1.0</version><author_name>npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_name><author_url>https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2011-09-13&#xA;🗒️ Summary of this message: Bitcoin&#39;s &#34;timejacking&#34; vulnerability allows miners to manipulate block timestamps, leading to difficulty adjustment issues. Fixing it requires addressing the &#34;what time is it&#34; code.&#xA;📝 Original message:Background:&#xA;&#xA;Timejacking:&#xA;  http://culubas.blogspot.com/2011/05/timejacking-bitcoin_802.html&#xA;&#xA;And a recent related exploit launched against the low-difficulty&#xA;alternative chains:&#xA;  https://bitcointalk.org/index.php?topic=43692.msg521772#msg521772&#xA;&#xA;&#xA;Seems to me there are two fundamental problems:&#xA;&#xA;1) Bitcoin should be overlapping the ranges of block timestamps that&#xA;it uses to calculate difficulty adjustments.&#xA;&#xA;2) Bitcoin&#39;s &#34;what time is it&#34; code is kind of a hack.&#xA;&#xA;&#xA;Fixing (1) would mean a potential block-chain split; before&#xA;considering doing that I&#39;d like to consider second-best solutions.&#xA;&#xA;Fixing (2) is easier; incorporating a ntp library and/or simply&#xA;removing the bitcoin mining code from the client but requiring pools&#xA;and miners to have accurate-to-within-a-minute system clocks (or their&#xA;blocks will be &#34;discouraged&#34;) seems reasonable to me. If you want to&#xA;produce blocks that the rest of the network will accept, run ntp on&#xA;your system.&#xA;&#xA;I THINK that fixing (2) will make (1) a non-issue-- if miners can&#39;t&#xA;mess around with block times very much then it will be very difficult&#xA;for them to manipulate the difficulty for their benefit.&#xA;&#xA;-- &#xA;--&#xA;Gavin Andresen</html></oembed>