Rendered at 08:09:18 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
simonw 12 hours ago [-]
Crypto's greatest weakness has always been security. Even if the algorithms themselves hold, humans need to keep their keys safe. We have decades of experience now showing that humans can't do that.
I wouldn't be worrying about the algorithms so much as I'd worry about all of the end-users who are going to get their keys stolen and their wallets drained thanks to the deluge of new vulnerabilities in operating systems, browsers, wallets, personal agents and other software.
It turns out irreversible transactions have repercussions.
int32_64 11 hours ago [-]
The guy that made the 'bunker mode' tweet is an Ethereum guy, the chain that they reorganized when the wrong people lost money in the DAO hack.
What good are strong cryptography primitives for cryptocurrency if your "CEO" can successfully make calls to reorganize the chain?
kinakomochidayo 4 hours ago [-]
The chain wasn’t “reorganized”. It was an unusual state change in a smart contract, agreed by node operators.
Let’s also not forget that Satoshi actually rolled back the chain in 2010 after a hacker printed 184 billion BTC.
pants2 10 hours ago [-]
That was over 10 years ago now, when the chain was less than a year old. Things have changed. Can we drop it already?
tzs 7 hours ago [-]
I haven't followed this subject. What's changed?
pants2 4 hours ago [-]
Basically everything. DeFi wasn't even really a thing back then - Ethereum had zero TVL when the rollback happened. Smart contracts were a brand new concept. Competing SC chains like Solana weren't even in the idea stage yet. It also had only one client. Now there is $50B+ in TVL and nine clients and a rollback is just not going to happen.
It's ancient history. It's like still criticizing Apple for how they handled Copland OS.
kayamon 10 hours ago [-]
We won't drop it. Ethereum was built on insecure management from day one. Satoshi proved that honest mining nodes follow the longest proof-of-work chain. Ethereum chose to start their own management and now continue to suffer the consequences.
kinakomochidayo 4 hours ago [-]
Satoshi literally rolled back the chain in 2010 after the value overflow bug. Hilarious.
Ethereum only did a surgical state change on a smart contract. It wasn’t a rollback like Satoshi.
pants2 4 hours ago [-]
What "consequences" are you referring to? Anything that has happened in the last 10 years?
whattheheckheck 11 hours ago [-]
When it makes sense. Eth classic was a psy op from cardano guy.
gumby 11 hours ago [-]
I'm a bit concerned about starting a flame war, but I barely follow any cryptocurrency news at all. So I am curious: would there actually be any negative macro consequence if this were to happen?
I know, at the micro level some people would lose their money, but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)? And I'd be sad for some of those people. but would it have any impact that I would notice? My money is in broad, boring index funds.
Interesting use case. Not formally legitimate but even the US would prefer it not be stopped as even small exports exert a large impact on the price of oil.
But a good example of a macro impact on the global economy.
gucci-on-fleek 10 hours ago [-]
> but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)?
I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies, but my understanding is that nearly all of these users are immediately converting it to the local currency, so the only money at risk would be that which is in active transit. It would definitely be unfortunate to lose any money being transferred, but remittance recipients don't tend to have any savings at all, so I don't think that it would have any broader economic effects (in the context of this specific example).
It could also potentially mess with electricity prices in some areas, since Bitcoin mining uses quite a bit of power, but I suspect that some AI datacenter would step in and buy up all the excess power, so this probably wouldn't be much of an issue either.
(And I don't know enough to comment about how this could affect other sectors of the economy)
dumberquestions 9 hours ago [-]
> I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies
I can confirm that this aspect is absolutely massive and often underestimated by those living in the West.
It's happening all over Africa, Middle East and LATAM, since stablecoin transactions are cheaper and require no access to financial infrastructure that could be locally unavailable, but as you mentioned it's only used as an intermediate link before converting to local currency.
gumby 3 hours ago [-]
Interesting!
I just looked up the world bank’s estimates which say remittances are around $850B (including direct co-party islamic cash transfers, illegal in many countries). The amount using crypto is about $26B, so about 3%, hardly material at a macro scale (might be a big deal for a small country) so losing this would not be noticeable to the global economy.
logicalmind 8 hours ago [-]
There are two layers of value on chains that are not bitcoin. There is the native currency and then various forms of tokens that can be transacted. Tokens are things like NFT's or Stablecoins. In order to trade tokens you need to pay gas in the native currency of the chain. For example, ETH on the Ethereum network.
Large financial institutions are already doing work using stablecoins. In order to turn stablecoins back into fiat, you have to take them back to the issuer for exchange. Countries with unstable currencies can hold USD by purchasing stablecoins. And financial institutions can do settlement between each other using stablecoins.
gumby 3 hours ago [-]
Federal reserve (Kansas) says in ‘25 these transactions were about $390B (there are qild estimates of $35T but these seem to be typos or deliberate misreadings of a prediction for 2035 from a crypto enthusiast). At forex scale or the scale of global GDP, 400B is invisible.
It could grow, of course, though the use case appears to be weak and unstable countries, which are by definition distant participants of global exchange, and unlikely to have any visible effect on the overall macro economy.
mceleri 9 hours ago [-]
Well... Elliptic curve cryptography is also used in many other systems and connections, so yes, we would all notice if a mathematical trick broke it.
gumby 3 hours ago [-]
Very much so! Though I was looking at the use case of the OP.
notnullorvoid 12 hours ago [-]
My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.
MattPalmer1086 12 hours ago [-]
The point is they have less algebraic structure than things like elliptic curves. If you want "math resistant" properties, this is a good thing.
palmotea 12 hours ago [-]
> My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.
Aren't hashes far less reliant on math tricks?
My understanding is the problem with public-key crypto is it extremely reliant on a single math trick (e.g. the factoring problem), so if it turns out that trick was weaker than was assumed, the whole thing crumbles.
tptacek 12 hours ago [-]
Yes. Symmetric cryptography doesn't generally rely on the existence of "trap doors", so there's no direct relationship in any sense between the inputs and the outputs. Huge portions of the cryptographic attack surface are foreclosed in these constructions.
jMyles 12 hours ago [-]
That's the opposite of what my gut is telling me.
Hashes are so simple. There's no place for these crazy math attacks, which rely on rethinking long-standing and otherwise reasonable assumptions, to hide.
Surely we can all agree that there's no way to reverse a modulus.
notnullorvoid 7 hours ago [-]
The risk isn't about reversing the hash, it's about finding a hash collision. If the hash is the only reference to your public key on chain, one does not need to reverse the hash, they just need produce a key pair who's public hash collides.
Currently that's a large brute force problem. But my gut is telling me is that finding a forward pass method of restraining private key generation such that we know what kind of public key hash to expect at the end, should be easier than cracking elliptic curves.
I guess depending on your outlook some might view that as "reversing" a hash, but it's not like you are getting the original input which is a impossible problem (unless there is a bunch of info you already know about the input).
tptacek 11 hours ago [-]
I think I agree with you in spirit but I don't think "there's no way to reverse a modulus" is the right way to say this. Like that's in a sense what Coppersmith does? (Several attacks on RSA can be thought of as in some way "reversing a modulus").
jMyles 11 hours ago [-]
> I think I agree with you in spirit
holy heck, the planets have aligned, HN
;-)
tptacek 10 hours ago [-]
We both work in security, right? That shouldn't surprise you so much.
jMyles 9 hours ago [-]
Actually man, I've transitioned pretty much full-time to playing bluegrass. Given that my life has been spend watching and helping the internet grow, most of my songs are about what it has felt like to live amidst that: https://justinholmes.bandcamp.com/
I still hack every day (current project: pickipedia.xyz), but I'm not doing security anymore except for my own projects.
And yes, I was more making light of what seem to me to largely be political disagreements; of course I respect your work at the same time.
It seems clearer and clearer to me that nationa-states cannot possibly withstand the evolution of the internet in any dignified way, and I pray for peaceful, simple deprecation of them. It seems to me to be the sensible stance, both in terms of security and in terms of joy.
My repeated sense - right honed or wrongly - is that you defend these structures (nation-states generally, and intelligence operations / state secret brokers in particular) in ways that I find hard to reconcile, even upon extended reflection.
dist-epoch 11 hours ago [-]
Isn't it more secure mostly because of the mixing than the modulus.
search_facility 12 hours ago [-]
May be Ethereum should fund 10000 agents to pursue new crypto math with provable strongness/hardness
Lerc 12 hours ago [-]
I think much of the the doomer propaganda is paid for by by the half billion or so that Vitalik Butering gave to the Future of Life institute. It sounds like he wanted it spent on research more than advocacy and is now distancing himself from them.
j2kun 12 hours ago [-]
FWIW, there has already been a lot of effort thrown at AI attacking lattice problems underlying PQC without anything to show for it. I'm not sure why Vitalik is suddenly worried about lattice problems in particular, unless he has some insider knowledge.
dist-epoch 11 hours ago [-]
The AI unit distance conjecture proof used high-dimensional lattices and algebraic number fields, adjacent to the kind of stuff used in lattice PQC. It shows skill in that area.
j2kun 6 hours ago [-]
And if the same AI has tried and failed to break lattice problem security, wouldn't that suggest the problems are more secure, not less?
what 12 hours ago [-]
Why should we believe that LLMs are going to break ECC?
tptacek 12 hours ago [-]
LLMs probably won't break curve cryptography. Cryptography researchers armed with LLMs are a different story.
what 11 hours ago [-]
Okay and why should we believe that?
tptacek 11 hours ago [-]
It depends a lot on your priors. I think making existing cryptography researchers hyperefficient and much more mathematically capable is likely to generate some disruptive results, but you may disagree.
what 6 hours ago [-]
If this were a real possibility, it would be getting a lot more attention. Not just some crypto bros worried about losing magic beans.
contingencies 11 hours ago [-]
Don't forget LLMs can now design efficient high speed hardware systems, a traditional slow-down for many attackers which represents a significant barrier to scalable next-gen attacks falling. Unfortunately memory prices are through the roof, but that isn't always significant.
plesiv 12 hours ago [-]
Your probability distribution should be flatter at least.
nextaccountic 11 hours ago [-]
It's a risk
cidd 11 hours ago [-]
You don't
EA-3167 12 hours ago [-]
It’s always tragic when the new hype train runs over the old one. It pains my soul to imagine those gentle folks with millions in crypto being subjected to the incredibly foreseeable consequences of their limitless greed.
lopsotronic 10 hours ago [-]
Isn't it fascinating how multiple successive hype trains have had the same functional command of "Build Me More Teraflops, Human"?
I sometimes wonder if the AGI wasn't here all along . . .
We never did find out who "Satoshi Nakamoto" actually was.
I'm not seriously suggesting that an AGI has been in the wild since circa 2010s, but . . stranger things have happened. All through the aughts, then the teens, GWoT had been funneling an absolutely bananas amount of money into compute. What if, in those years, something horrifying happened, and it's already taken over. That would explain so much weirdness.
EA-3167 9 hours ago [-]
That’s a wonderfully creative idea and I’d read a short story along those lines.
It may be a plausible concern at some point in the future but, once it's possible, it would manifest as an extremely expensive and time consuming attack against a targeted address, it would require an enormous amount of compute. So, I suppose the first line of defense would be to never keep more funds locked under one key than it would cost an attacker to decrypt it.
_ink_ 12 hours ago [-]
Which leaves Bitcoin between a rock and a hard place. The Satoshi funds are probably worth an attack. At the same time they cannot move to post quantum cryptography, because that would also require to move funds.
12 hours ago [-]
spottedmarley 12 hours ago [-]
Yeah the Satoshi treasure would be a prime target. Maybe we see those funds get mysteriously split up at some point? But we wouldn't know if they were hacked or protected..
tzone 12 hours ago [-]
There are exchanges, custodians, etc that hold insane amounts of BTC or ETH in a single address.
We are talking billion dollars+ worth in a single address. So if either chainskey security is compromised in a way that it is conceivable to brute force it, there will definitely be plenty of targets.
dist-epoch 11 hours ago [-]
Stealing a billion dollar address is kind of worthless. Try cashing it out. Even if you are NK.
spottedmarley 12 hours ago [-]
Yes, it would require those exchanges to move their funds around. I'm pretty sure they can manage it.
warkdarrior 12 hours ago [-]
Cost of running an attack is super cheap if one buys botted computers (it is/used to be $25/1000 machines).
I wouldn't be worrying about the algorithms so much as I'd worry about all of the end-users who are going to get their keys stolen and their wallets drained thanks to the deluge of new vulnerabilities in operating systems, browsers, wallets, personal agents and other software.
https://www.bbc.com/news/articles/c6eq84eygz0qo
What good are strong cryptography primitives for cryptocurrency if your "CEO" can successfully make calls to reorganize the chain?
Let’s also not forget that Satoshi actually rolled back the chain in 2010 after a hacker printed 184 billion BTC.
It's ancient history. It's like still criticizing Apple for how they handled Copland OS.
Ethereum only did a surgical state change on a smart contract. It wasn’t a rollback like Satoshi.
I know, at the micro level some people would lose their money, but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)? And I'd be sad for some of those people. but would it have any impact that I would notice? My money is in broad, boring index funds.
But a good example of a macro impact on the global economy.
I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies, but my understanding is that nearly all of these users are immediately converting it to the local currency, so the only money at risk would be that which is in active transit. It would definitely be unfortunate to lose any money being transferred, but remittance recipients don't tend to have any savings at all, so I don't think that it would have any broader economic effects (in the context of this specific example).
It could also potentially mess with electricity prices in some areas, since Bitcoin mining uses quite a bit of power, but I suspect that some AI datacenter would step in and buy up all the excess power, so this probably wouldn't be much of an issue either.
(And I don't know enough to comment about how this could affect other sectors of the economy)
I can confirm that this aspect is absolutely massive and often underestimated by those living in the West.
It's happening all over Africa, Middle East and LATAM, since stablecoin transactions are cheaper and require no access to financial infrastructure that could be locally unavailable, but as you mentioned it's only used as an intermediate link before converting to local currency.
I just looked up the world bank’s estimates which say remittances are around $850B (including direct co-party islamic cash transfers, illegal in many countries). The amount using crypto is about $26B, so about 3%, hardly material at a macro scale (might be a big deal for a small country) so losing this would not be noticeable to the global economy.
Large financial institutions are already doing work using stablecoins. In order to turn stablecoins back into fiat, you have to take them back to the issuer for exchange. Countries with unstable currencies can hold USD by purchasing stablecoins. And financial institutions can do settlement between each other using stablecoins.
It could grow, of course, though the use case appears to be weak and unstable countries, which are by definition distant participants of global exchange, and unlikely to have any visible effect on the overall macro economy.
Aren't hashes far less reliant on math tricks?
My understanding is the problem with public-key crypto is it extremely reliant on a single math trick (e.g. the factoring problem), so if it turns out that trick was weaker than was assumed, the whole thing crumbles.
Hashes are so simple. There's no place for these crazy math attacks, which rely on rethinking long-standing and otherwise reasonable assumptions, to hide.
Surely we can all agree that there's no way to reverse a modulus.
Currently that's a large brute force problem. But my gut is telling me is that finding a forward pass method of restraining private key generation such that we know what kind of public key hash to expect at the end, should be easier than cracking elliptic curves.
I guess depending on your outlook some might view that as "reversing" a hash, but it's not like you are getting the original input which is a impossible problem (unless there is a bunch of info you already know about the input).
holy heck, the planets have aligned, HN
;-)
I still hack every day (current project: pickipedia.xyz), but I'm not doing security anymore except for my own projects.
And yes, I was more making light of what seem to me to largely be political disagreements; of course I respect your work at the same time.
It seems clearer and clearer to me that nationa-states cannot possibly withstand the evolution of the internet in any dignified way, and I pray for peaceful, simple deprecation of them. It seems to me to be the sensible stance, both in terms of security and in terms of joy.
My repeated sense - right honed or wrongly - is that you defend these structures (nation-states generally, and intelligence operations / state secret brokers in particular) in ways that I find hard to reconcile, even upon extended reflection.
I sometimes wonder if the AGI wasn't here all along . . .
We never did find out who "Satoshi Nakamoto" actually was.
I'm not seriously suggesting that an AGI has been in the wild since circa 2010s, but . . stranger things have happened. All through the aughts, then the teens, GWoT had been funneling an absolutely bananas amount of money into compute. What if, in those years, something horrifying happened, and it's already taken over. That would explain so much weirdness.
We are talking billion dollars+ worth in a single address. So if either chainskey security is compromised in a way that it is conceivable to brute force it, there will definitely be plenty of targets.