This is as good a place as any to ask this question.
Do we actually know how many large mining groups we need to make up 51% of the processing power of the block chain (hopefully that make sense, from my understanding of bitcoin).
There has been a number of changes to the bitcoin protocol, which have been made in a short amount of time and unanimously, from what I can see. That implies to me that bitcoin is in practice much more centralised than we are sometimes lead to believe, and that moving to bitcoin is just switching from one shadowy control group to another.
I would be happy to hear evidence that I am vastly overestimating this problem.
GHash.io had actually been acting maliciously according to some users on Bitcointalk, but the operator claims that was a rogue actor inside that has been dealt with. Double spends against betting sites in particular were involved with this one.
We need digital currencies that can only ever be mined efficiently with a CPU, and there need to be many more blocks with lower rewards so that people don't need to join pools if they don't want to. They need to be able to earn "something" (not zero) even with a low-end CPU or when the difficulty gets too great, and close to the point of reaching the maximum number of coins. I think there weren't even 10 percent Bitcoins on the market, and CPU's already became obsolete.
Yes, I know about the scrypt-based ones, but unfortunately they can still be mined 10x faster with a GPU, and I don't think that's much more preferable either. It needs to be CPU-only, because most people get as fast CPU's as they can, usually, but they don't really care about the GPU performance, other than needing it to support HD playback, which is a very low standard for a GPU these days.
I'm not sure how it can be done, but some of the ones that claim to be CPU-only are using multiple hashing algorithms and ciphers at once, presumably to ensure that the task is too complex for anything less "general purpose" than a CPU (at least until they start making chips with accelerators for each and every one of those hashing algorithms?! Maybe something to prevent that could be built-in).
The point is to make mining as decentralized as possible. I realize the danger of botnets, too, but I think the trade-off is worth it. I'd rather have that, than a few groups of people or governments owning a ton of ASIC's, or perhaps a few very expensive quantum computers in the future, that they can use to manipulate the currencies. At least if it's CPU only, everyone can have a say in it, in aggregate, which is really the whole point of decentralization, and empowering the individual in the Internet world.
A cryptocurrency based on CPUs is just fodder for Botnet herders, like Bitcoin was for quite a period. Amusingly, that was Litecoins original call to action, "GPUs are too centralised, we can only be CPU mined!", except that they implemented scrypt very badly.
> I'd rather have that, than a few groups of people or governments owning a ton of ASIC's, or perhaps a few very expensive quantum computers in the future, that they can use to manipulate the currencies.
Any government worth it's salt has server farms with more CPUs and a bigger budget than you can imagine. It's not really a defence at all. Back when it was profitable, the operators at CERN used to mine to keep the cost of their servers down to a minimum, filling the spare cycles between computations. I imagine their systems are nothing compared with that of someone like the NSA.
> I'm not sure how it can be done, but some of the ones that claim to be CPU-only are using multiple hashing algorithms and ciphers at one, presumably to ensure that the task is too complex for anything less "general purpose" than a CPU (at least until they start making chips with accelerators for each and every one of those hashing algorithms?!).
Won't stop them being GPU or FPGA accelerated. I doubt anybody will ever care enough to do a custom silicon chip for any of the "altcoins".
Yes, I realize everyone with huge datacenters are a huge threat, too, but I still don't think it's as big of a threat as the alternative. Can the NSA own more than half of the world's CPU performance? I don't think so. Could they own 10-100 quantum computers that can mine at say 1 PH/s each? Definitely. It would be much more cost-effective for them, while prohibitively expensive for everyone else (a D-WAVE goes for $10 million a pop right now)
Granted, that's not actually viable yet, but if the world is going to move to a digital currency like Bitcoin, that implies it will be here for decades or centuries, and I think such a threat needs to be considered before it replaces most of the world's financial systems.
Even with ASIC's they could easily buy 1-10 million of them. It would only be a fraction of their annual budget, which will no doubt increase in the future, if nothing is done to rein in on their power. Normal people aren't going to buy ASIC's just to keep NSA in check.
Also, botnets would be there with or without Bitcoins. If they mine, at least they aren't doing something even more dangerous with the botnets, and keep them busy mining. Plus, it should be relatively easy to figure out you have a virus in your computer if your CPU is 100 percent 24/7 and the fans are spinning like crazy.
A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution. Digital signatures provide part of the solution, but the main benefits are lost if a trusted third party is still required to prevent double-spending. We propose a solution to the double-spending problem using a peer-to-peer network. The network timestamps transactions by hashing them into an ongoing chain of hash-based proof-of-work, forming a record that cannot be changed without redoing the proof-of-work. The longest chain not only serves as proof of the sequence of events witnessed, but proof that it came from the largest pool of CPU power. As long as a majority of CPU power is controlled by nodes that are not cooperating to attack the network, they'll generate the longest chain and outpace attackers.
A digital currency requires arbitrary tokens as a medium of exchange.
It does not require peer-to-peer creation and verification of tokens. It does not require mining, it does not require pseudo-anonymous transactions and a distributed public ledger of all past transactions. Those are all properties of Bitcoin but not of currencies in general.
Bitcoin has some interesting ideas, but it's hardly the only type of digital currency which can exist and mining is a concept particular to Bitcoin (and spin-offs) - it has the effect of enriching the devs and early adopters and transforming it into an appreciating asset rather than a currency.
Mining is not just for distribution of tokens. I would argue the more important use is for maintaining the proof-of-work blockchain. There have been some experimental attempts at maintaining a distributed ledger using a proof-of-stake/proof-of-work hybrid, but I don't know of any successful attempts to do it without a proof-of-work component.
If you have an idea of how it could be done, you may have a shot at dethroning Bitcoin.
Ripple achieves ledger consensus without proof-of-work. Absence of proof-of-work is how it gets a new ledger (analogous to the block) every few seconds. The XRP fee destruction deflationary scheme is effectively similar to a proof-of-stake inflationary scheme, because as the total supply of XRP decreases, it benefits all XRP holders in proportion to their holdings.
The scrypt hardness parameters are related to both processor and cache. Once hardness gets big enough,GPU mining won't make sense, because each GPU core has relatively little cache vs cpu.
Right now the largest pool is 29%. And you actually only need 33% to trigger the 51% problem if the controlling pool withholds blocks for a couple seconds after solving them to give themselves a headstart on the next block. So in theory the currency is only days or weeks away from collapsing.
I do think bitcoin solves a legitimate problem. But I don't think bitcoin itself will become the winner. Litecoin is vastly better than bitcoin because it solves the 51% problem and several other issues, but odds are litecoin will eventually be replaced by something better also.
Litecoin does not solve any problem, just the proof of work algorithm is changed. The block time has nothing to do with it really, it just makes people believe one confirmation is as strong as any other (Litecoin's are actually just 4 times weaker).
4 times weaker? When you're talking about statistical attacks that depends on getting a very small number of random events ahead of your opponent, I would expect quadrupling the numbers to provide significant additional security in the medium term of 10 to 100 minutes.
Clearly a litecoin confirmation is weaker than a bitcoin confirmation, but 4 or 12 litecoin confirmations should be much stronger than 1 or 3 bitcoin confirmations.
Confirmations are just a measure of computing power essentially. By saying a transaction needs 3 confirmations you are saying that you require 30 minutes of network hashing time before you call a transaction secure. For the same 30 minutes you'd need 12 Litecoin confirmations.
The chance of me solving 4 litecoim blocks is the same as me solving 1 bit coin block, assuming the same hash power and difficulty. In reality Litecoin is quite low in both, so is substantially easier to abuse in the real world.
No, confirmations are not just a measure of computing power. The difficulty of carrying out attacks with a sub-50% proportion of the total hash power increases exponentially with the number of confirmations, whereas requiring more work per confirmation only gives a linear increase. Satoshi's original whitepaper explains this.
The chance of solving 4 litecoin blocks is the same as solving 1 bitcoin block, sure.
But look at it this way. If bitcoin blocks were once a day, then if you had a few percent of the network power you would get 1 day = 1 confirmation ahead of your opponent all the time. But with bitcoin blocks every few minutes, you have an infinitessimal chance of getting 1 day = hundreds of confirmations ahead.
The distribution of timings is much wilder when you're only taking a couple samples. The longest confirmations in the world won't make 2-confirmation transactions completely safe, but 20 confirmations is pretty secure with any length.
Do we actually know how many large mining groups we need to make up 51% of the processing power of the block chain (hopefully that make sense, from my understanding of bitcoin).
There has been a number of changes to the bitcoin protocol, which have been made in a short amount of time and unanimously, from what I can see. That implies to me that bitcoin is in practice much more centralised than we are sometimes lead to believe, and that moving to bitcoin is just switching from one shadowy control group to another.
I would be happy to hear evidence that I am vastly overestimating this problem.