Rendered at 23:39:32 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
simonw 3 hours ago [-]
Crypto's greatest weakness has always been security. Even if the algorithms themselves hold, humans need to keep their keys safe. We have decades of experience now showing that humans can't do that.
I wouldn't be worrying about the algorithms so much as I'd worry about all of the end-users who are going to get their keys stolen and their wallets drained thanks to the deluge of new vulnerabilities in operating systems, browsers, wallets, personal agents and other software.
It turns out irreversible transactions have repercussions.
gumby 2 hours ago [-]
I'm a bit concerned about starting a flame war, but I barely follow any cryptocurrency news at all. So I am curious: would there actually be any negative macro consequence if this were to happen?
I know, at the micro level some people would lose their money, but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)? And I'd be sad for some of those people. but would it have any impact that I would notice? My money is in broad, boring index funds.
Interesting use case. Not formally legitimate but even the US would prefer it not be stopped as even small exports exert a large impact on the price of oil.
But a good example of a macro impact on the global economy.
gucci-on-fleek 2 hours ago [-]
> but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)?
I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies, but my understanding is that nearly all of these users are immediately converting it to the local currency, so the only money at risk would be that which is in active transit. It would definitely be unfortunate to lose any money being transferred, but remittance recipients don't tend to have any savings at all, so I don't think that it would have any broader economic effects (in the context of this specific example).
It could also potentially mess with electricity prices in some areas, since Bitcoin mining uses quite a bit of power, but I suspect that some AI datacenter would step in and buy up all the excess power, so this probably wouldn't be much of an issue either.
(And I don't know enough to comment about how this could affect other sectors of the economy)
dumberquestions 48 minutes ago [-]
> I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies
I can confirm that this aspect is absolutely massive and often underestimated by those living in the West.
It's happening all over Africa, Middle East and LATAM, since stablecoin transactions are cheaper and require no access to financial infrastructure that could be locally unavailable, but as you mentioned it's only used as an intermediate link before converting to local currency.
mceleri 53 minutes ago [-]
Well... Elliptic curve cryptography is also used in many other systems and connections, so yes, we would all notice if a mathematical trick broke it.
int32_64 3 hours ago [-]
The guy that made the 'bunker mode' tweet is an Ethereum guy, the chain that they reorganized when the wrong people lost money in the DAO hack.
What good are strong cryptography primitives for cryptocurrency if your "CEO" can successfully make calls to reorganize the chain?
pants2 2 hours ago [-]
That was over 10 years ago now, when the chain was less than a year old. Things have changed. Can we drop it already?
kayamon 1 hours ago [-]
We won't drop it. Ethereum was built on insecure management from day one. Satoshi proved that honest mining nodes follow the longest proof-of-work chain. Ethereum chose to start their own management and now continue to suffer the consequences.
whattheheckheck 2 hours ago [-]
When it makes sense. Eth classic was a psy op from cardano guy.
notnullorvoid 3 hours ago [-]
My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.
MattPalmer1086 3 hours ago [-]
The point is they have less algebraic structure than things like elliptic curves. If you want "math resistant" properties, this is a good thing.
palmotea 3 hours ago [-]
> My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.
Aren't hashes far less reliant on math tricks?
My understanding is the problem with public-key crypto is it extremely reliant on a single math trick (e.g. the factoring problem), so if it turns out that trick was weaker than was assumed, the whole thing crumbles.
tptacek 3 hours ago [-]
Yes. Symmetric cryptography doesn't generally rely on the existence of "trap doors", so there's no direct relationship in any sense between the inputs and the outputs. Huge portions of the cryptographic attack surface are foreclosed in these constructions.
jMyles 3 hours ago [-]
That's the opposite of what my gut is telling me.
Hashes are so simple. There's no place for these crazy math attacks, which rely on rethinking long-standing and otherwise reasonable assumptions, to hide.
Surely we can all agree that there's no way to reverse a modulus.
tptacek 2 hours ago [-]
I think I agree with you in spirit but I don't think "there's no way to reverse a modulus" is the right way to say this. Like that's in a sense what Coppersmith does? (Several attacks on RSA can be thought of as in some way "reversing a modulus").
jMyles 2 hours ago [-]
> I think I agree with you in spirit
holy heck, the planets have aligned, HN
;-)
tptacek 2 hours ago [-]
We both work in security, right? That shouldn't surprise you so much.
jMyles 13 minutes ago [-]
Actually man, I've transitioned pretty much full-time to playing bluegrass. Given that my life has been spend watching and helping the internet grow, most of my songs are about what it has felt like to live amidst that: https://justinholmes.bandcamp.com/
I still hack every day (current project: pickipedia.xyz), but I'm not doing security anymore except for my own projects.
And yes, I was more making light of what seem to me to largely be political disagreements; of course I respect your work at the same time.
It seems clearer and clearer to me that nationa-states cannot possibly withstand the evolution of the internet in any dignified way, and I pray for peaceful, simple deprecation of them. It seems to me to be the sensible stance, both in terms of security and in terms of joy.
My repeated sense - right honed or wrongly - is that you defend these structures (nation-states generally, and intelligence operations / state secret brokers in particular) in ways that I find hard to reconcile, even upon extended reflection.
dist-epoch 3 hours ago [-]
Isn't it more secure mostly because of the mixing than the modulus.
search_facility 4 hours ago [-]
May be Ethereum should fund 10000 agents to pursue new crypto math with provable strongness/hardness
Lerc 3 hours ago [-]
I think much of the the doomer propaganda is paid for by by the half billion or so that Vitalik Butering gave to the Future of Life institute. It sounds like he wanted it spent on research more than advocacy and is now distancing himself from them.
j2kun 3 hours ago [-]
FWIW, there has already been a lot of effort thrown at AI attacking lattice problems underlying PQC without anything to show for it. I'm not sure why Vitalik is suddenly worried about lattice problems in particular, unless he has some insider knowledge.
dist-epoch 3 hours ago [-]
The AI unit distance conjecture proof used high-dimensional lattices and algebraic number fields, adjacent to the kind of stuff used in lattice PQC. It shows skill in that area.
what 3 hours ago [-]
Why should we believe that LLMs are going to break ECC?
tptacek 3 hours ago [-]
LLMs probably won't break curve cryptography. Cryptography researchers armed with LLMs are a different story.
what 3 hours ago [-]
Okay and why should we believe that?
tptacek 2 hours ago [-]
It depends a lot on your priors. I think making existing cryptography researchers hyperefficient and much more mathematically capable is likely to generate some disruptive results, but you may disagree.
contingencies 3 hours ago [-]
Don't forget LLMs can now design efficient high speed hardware systems, a traditional slow-down for many attackers which represents a significant barrier to scalable next-gen attacks falling. Unfortunately memory prices are through the roof, but that isn't always significant.
plesiv 3 hours ago [-]
Your probability distribution should be flatter at least.
nextaccountic 3 hours ago [-]
It's a risk
cidd 3 hours ago [-]
You don't
EA-3167 3 hours ago [-]
It’s always tragic when the new hype train runs over the old one. It pains my soul to imagine those gentle folks with millions in crypto being subjected to the incredibly foreseeable consequences of their limitless greed.
lopsotronic 1 hours ago [-]
Isn't it fascinating how multiple successive hype trains have had the same functional command of "Build Me More Teraflops, Human"?
I sometimes wonder if the AGI wasn't here all along . . .
We never did find out who "Satoshi Nakamoto" actually was.
I'm not seriously suggesting that an AGI has been in the wild since circa 2010s, but . . stranger things have happened. All through the aughts, then the teens, GWoT had been funneling an absolutely bananas amount of money into compute. What if, in those years, something horrifying happened, and it's already taken over. That would explain so much weirdness.
EA-3167 48 minutes ago [-]
That’s a wonderfully creative idea and I’d read a short story along those lines.
spottedmarley 4 hours ago [-]
It may be a plausible concern at some point in the future but, once it's possible, it would manifest as an extremely expensive and time consuming attack against a targeted address, it would require an enormous amount of compute. So, I suppose the first line of defense would be to never keep more funds locked under one key than it would cost an attacker to decrypt it.
_ink_ 4 hours ago [-]
Which leaves Bitcoin between a rock and a hard place. The Satoshi funds are probably worth an attack. At the same time they cannot move to post quantum cryptography, because that would also require to move funds.
3 hours ago [-]
spottedmarley 3 hours ago [-]
Yeah the Satoshi treasure would be a prime target. Maybe we see those funds get mysteriously split up at some point? But we wouldn't know if they were hacked or protected..
tzone 3 hours ago [-]
There are exchanges, custodians, etc that hold insane amounts of BTC or ETH in a single address.
We are talking billion dollars+ worth in a single address. So if either chainskey security is compromised in a way that it is conceivable to brute force it, there will definitely be plenty of targets.
dist-epoch 3 hours ago [-]
Stealing a billion dollar address is kind of worthless. Try cashing it out. Even if you are NK.
spottedmarley 3 hours ago [-]
Yes, it would require those exchanges to move their funds around. I'm pretty sure they can manage it.
warkdarrior 4 hours ago [-]
Cost of running an attack is super cheap if one buys botted computers (it is/used to be $25/1000 machines).
I wouldn't be worrying about the algorithms so much as I'd worry about all of the end-users who are going to get their keys stolen and their wallets drained thanks to the deluge of new vulnerabilities in operating systems, browsers, wallets, personal agents and other software.
https://www.bbc.com/news/articles/c6eq84eygz0qo
I know, at the micro level some people would lose their money, but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)? And I'd be sad for some of those people. but would it have any impact that I would notice? My money is in broad, boring index funds.
But a good example of a macro impact on the global economy.
I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies, but my understanding is that nearly all of these users are immediately converting it to the local currency, so the only money at risk would be that which is in active transit. It would definitely be unfortunate to lose any money being transferred, but remittance recipients don't tend to have any savings at all, so I don't think that it would have any broader economic effects (in the context of this specific example).
It could also potentially mess with electricity prices in some areas, since Bitcoin mining uses quite a bit of power, but I suspect that some AI datacenter would step in and buy up all the excess power, so this probably wouldn't be much of an issue either.
(And I don't know enough to comment about how this could affect other sectors of the economy)
I can confirm that this aspect is absolutely massive and often underestimated by those living in the West.
It's happening all over Africa, Middle East and LATAM, since stablecoin transactions are cheaper and require no access to financial infrastructure that could be locally unavailable, but as you mentioned it's only used as an intermediate link before converting to local currency.
What good are strong cryptography primitives for cryptocurrency if your "CEO" can successfully make calls to reorganize the chain?
Aren't hashes far less reliant on math tricks?
My understanding is the problem with public-key crypto is it extremely reliant on a single math trick (e.g. the factoring problem), so if it turns out that trick was weaker than was assumed, the whole thing crumbles.
Hashes are so simple. There's no place for these crazy math attacks, which rely on rethinking long-standing and otherwise reasonable assumptions, to hide.
Surely we can all agree that there's no way to reverse a modulus.
holy heck, the planets have aligned, HN
;-)
I still hack every day (current project: pickipedia.xyz), but I'm not doing security anymore except for my own projects.
And yes, I was more making light of what seem to me to largely be political disagreements; of course I respect your work at the same time.
It seems clearer and clearer to me that nationa-states cannot possibly withstand the evolution of the internet in any dignified way, and I pray for peaceful, simple deprecation of them. It seems to me to be the sensible stance, both in terms of security and in terms of joy.
My repeated sense - right honed or wrongly - is that you defend these structures (nation-states generally, and intelligence operations / state secret brokers in particular) in ways that I find hard to reconcile, even upon extended reflection.
I sometimes wonder if the AGI wasn't here all along . . .
We never did find out who "Satoshi Nakamoto" actually was.
I'm not seriously suggesting that an AGI has been in the wild since circa 2010s, but . . stranger things have happened. All through the aughts, then the teens, GWoT had been funneling an absolutely bananas amount of money into compute. What if, in those years, something horrifying happened, and it's already taken over. That would explain so much weirdness.
We are talking billion dollars+ worth in a single address. So if either chainskey security is compromised in a way that it is conceivable to brute force it, there will definitely be plenty of targets.