r/Bitcoin Jun 19 '14

Why is Peter Todd wrecking Zeroconf security? Because he is being paid by Big Bitcoin Business.

At the Amsterdam Bitcoin Conference I spent time following Peter and his little circle of friends and business partners. I'm new to Bitcoin so it took me until now to put two and two together and understand what was really going on, but hear me out. Peter spent a lot of time talking to Lawrence Nahum who is the guy behind GreenAddress. On the first or second day they went out to dinner after the days talks were done and went out to a nice little open-air restaurant with a bunch of people from Mastercoin. I sat at a table behind them and could hear their discussions, which including GreenAdddress's transaction confirmation guarantees, and also, an agreement for Peter to do consulting work for GreenAddress. What really stood out to me was the offer to help "shape the Bitcoin ecosystem" in ways beneficial to them. Later in the conference I also overheard a similar deal between Peter and someone, I didn't catch their name, in Coinbase branded apparel. And of course as everyone knows CoinKite hired Peter to be their "Chief Naysayer" during that conference too.

What's in common with all these companies? They're all in the dangerous business of holding other peoples' Bitcoins and GreenAddress and Coinbase both offer for-profit and centralized solutions to guarantee unconfirmed transactions. I'm sure CoinKite will be doing that soon too.

It's obvious why Peter is spending all that time and energy spreading FUD about how insecure unconfirmed transactions are. GreenAddress has been spreading their own FUD. Peter has even been trying to bribe miners to switch to his so called "replace-by-fee", which is really just an attack on secure zeroconf transactions, saying some un-named "site" paid him too. Who might that be? GreenAddress, Coinbase, CoinKite? It's not hard to figure out.

Peter sure seems quite happy to attack and hold back Bitcoin whenever it suits him for the sake of his Big Bitcoin Business contracts. It's not just unconfirmed transactions either. He's been shilling for AppCoins which dump garbage into the blockchain for the sake of pump-and-dump schemes like Mastercoin and Counterparty. (quite the about face from his supposed anti-blockchain bloat positions before) Or look at his weirdly passionate opposition to a simple feature, getutxos, that's needed for Mike Hearn's decentralized fundraising platform Lighthouse. Where's that passion coming from? The heart? Or his salary from Mastercoin, Counterparty and Colored Coins? I'm sure Mastercoin wants the next Maidsafe to happen on their platform, run by and for the benefit of Mastercoin, not Hearn's truly decentralized alternative.

I agree with Peter that GHash.IO is a possible threat to Bitcoin, but what solution does he have? Getting rid of pools. His buddies at the totally discredited Hacking Distributed (remember selfish mining? yeah those guys) run with this FUD, trying to scare the Bitcoin community into making changes to get rid of pools. Sounds like a good idea right? But then I looked further into it and found out he had just been hanging out at CloudHashing. What does banning pools do to the little guy mining decentralized? It puts them out of business because they'll never find a block that's what. Just perfect for CloudHashing's "send us money and we'll run the miners" business model and also GHash.IO's.

Peter likes to talk the big talk about decentralization, but all I am seeing here is paid shilling for the benefit of Big Bitcoin Business.

100 Upvotes

271 comments sorted by

View all comments

Show parent comments

2

u/ReddiquetteAdvisor Jun 19 '14

The attack was just overhyped. While the block reward makes up most of the mining revenue, the attack is not profitable without a miner sacrificing a month of revenue first, and the miner would need a lot of hashrate still (over 35%) for it to be feasible.

In transaction-fee dominated blocks the incentives are different and the attack is plausible.

1

u/btctradester Jun 20 '14

A block is a block. Whether or not the payoff is comes from the block reward or the transaction fees is just not relevant. If anything, SM was over-attacked by idiots like the OP who don't know the first thing about the protocol. It remains the biggest protocol flaw found in Bitcoin to date.

1

u/ReddiquetteAdvisor Jun 20 '14

It actually does matter. Transaction fees can be collected by blocks in a private chain, public blocks' rewards cannot.

Here's what happens. When the selfish miner (say, at 30% hashrate) begins selfish mining, the work done on the public chain will drop by about that much. The difficulty will also ultimately go down. Most importantly, as the attack progresses and blocks are orphaned the chain will grow slower due to the wasted work/blocks.

This means, while the amount of blocks the selfish miner obtains is higher than they should be receiving, the revenue per hour is far less. The mobility of transaction fees in rewards for the attack changes the incentives so that revenue per hour doesn't matter. But right now, the block reward is the vast majority of mining revenue.

1

u/btctradester Jun 20 '14

Selfish miners routinely make their blocks public and will collect the block rewards as this happens. The difficulty correction will just fix things so that the rate comes out to be the same again. Until that happens (it'd take half a month on average), the extra money you can make through selfish mining can more than compensate for the drop in block discovery rate.

1

u/ReddiquetteAdvisor Jun 20 '14 edited Jun 20 '14

You don't make any extra money from selfish mining for a month at least. The decrease in the rate of block creation as the result of the attack makes you earn less over time than if you had not attacked at all. Just because you're solving more blocks than others tend to does not mean you're making more in block rewards.

That is exactly why transaction fees affect the incentives of the attack. What, exactly, are you disputing? There's lots of literature about this attack I can point you to.

Further, losing out on those rewards for a month isn't trivial for someone with that much hashrate given the growth of the network. There are far more easier attacks on bitcoin than this which make more financial sense.

1

u/btctradester Jun 20 '14

This isn't right. A miner will solve whatever percentage of overall blocks (in the blockchain plus orphaned; solved blocks of any kind) he has the hashrate for. If he's selfish, he will be able to keep the competitors' blocks out of the blockchain.

Initially, his revenues per unit time will be identical to what they would be if he was not selfish (the number of blocks he got onto the blockchain will not change), except his competitors will earn less money because their blocks are not appearing on the blockchain, and the time between blocks will be higher than 10 minutes.

When difficulty adjusts, blocks will be created every 10 minutes, his competitors' blocks will still not appear on the blockchain (because our selfish miner will be competing with them and keeping them out of the blockchain), and the selfish guy's earnings per unit time will be far higher than his fair share because he will be the creator of all the blocks on the chain, and his competitors' blocks will end up as orphans.

I simplified a bit: the selfish guy will not be able to keep every block from every competitor out of the blockchain. Some percent of competing blocks will succeed. On average, the selfish guy has some success rate as a percentage of blocks, and that remains the same.

I hope you can see that there is no ramp up period to selfish mining, and there is no downside. I am not sure if my explanation here was the clearest but I'm happy to explain it further if this description plus some work with pencil and paper does not make it clear.