<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2013-05-06&#xA;📝 Original message:On Mon, May 6, 2013 at 3:51 PM, Adam Back &lt;adam at cypherspace.org&gt; wrote:&#xA;&gt; Maybe I could hack a pool to co-opt it into my netsplit and do the work for&#xA;&gt; me, or segment enough of the network to have some miners in it, and they do&#xA;&gt; the work.&#xA;&#xA;Or you can just let it mine honestly and take the Bitcoins. This is&#xA;fast (doesn&#39;t require weeks of them somehow not noticing that they&#39;re&#xA;isolated), and yields the values I listed as &#39;costs&#39; if you would have&#xA;otherwise been able to use it to mine the difficulty down to 1.  Cost&#xA;is just as much foregone income from the alternative attack you could&#xA;have done instead.&#xA;&#xA;&gt; nor even topological, nor even&#xA;&gt; particularly long-lived.&#xA;&#xA;At least for attacks that drive the difficulty down it does.&#xA;&#xA;If you want to talk about abusing a pool or creating a partition in&#xA;order to create short reorgs— I agree, those don&#39;t have to be long&#xA;lived and you can find many messages where I&#39;ve written on that&#xA;subject.&#xA;&#xA;It&#39;s inconsiderate to propose one attack and when I respond to it&#xA;changing the attack out from under me. :(  I would have responded&#xA;entirely differently if you&#39;d proposed people segmenting the network&#xA;and creating short reorgs instead of mining the difficulty down.&#xA;&#xA;&gt; Do you know if there is any downwards limit on difficulty?  I know it takes&#xA;&gt; going slow for a long and noticeable time, but I am just curious on the&#xA;&gt; theoretical limit.&#xA;&#xA;Every 2016 blocks can at most lower the difficulty by a factor of 4,&#xA;thats where the log4 (number of 2016 groups needed) and 4^n (factor in&#xA;cost reduction for each group) come from in the formulas I gave&#xA;previously.&#xA;&#xA;&gt; I dont see the signatures.&#xA;&#xA;http://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.8.1/SHA256SUMS.asc/download&#xA;&#xA;The signatures can&#39;t be inside the tarball because they sign the tarball.&#xA;&#xA;Seems like the website redesign managed to hide the signatures pretty&#xA;good. They&#39;re in the release announcements in any case, but that&#xA;should be fixed.  Even when they were prominently placed, practically&#xA;no one checked them. As a result they are mostly security theater in&#xA;practice :(, — so— unfortunately, is SSL: there are many CA&#39;s who will&#xA;give anyone a cert with your name on it who can give them a couple&#xA;hundred bucks and MITM HTTP (not HTTPS!) between the CA&#39;s&#xA;authentication server and your webserver. Bitcoin.org is hosted by&#xA;github, even if it had SSL and even if the CA infrastructure weren&#39;t a&#xA;joke, the number of ways to compromise that hosting enviroment would&#xA;IMO make SSL mostly a false sense of security.&#xA;&#xA;The gpg signatures and gitian downloader signatures provide good&#xA;security if actually used, solving the &#34;getting people to use them&#34;&#xA;problem is an open question.&#xA;&#xA;And I agree, this stuff is a bigger issue than many other things like&#xA;mining the difficulty down.</html></oembed>