Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> However this source now will be the target for no end of attacks (both hacking and legal)

It's possible to build a decentralized fork detector that anyone can run. All you have to do is run a bunch of versions of bitcoin nodes, and run a cron job to check and see if they have differing opinions on which fork is currently valid.

If you discover a recent fork of length > x, you might want to hold off on verifying or making transactions for a bit until things clear up.

> The bitcoin industry/community seems incapable of writing secure software

Dan Kaminsky (http://en.wikipedia.org/wiki/Dan_Kaminsky) would probably disagree:

"When I first looked at the code, I was sure I was going to be able to break it, Kaminsky said, noting that the programming style was dense and inscrutable. The way the whole thing was formatted was insane. Only the most paranoid, painstaking coder in the world could avoid making mistakes.…He quickly identified nine ways to compromise the system…when he found the right spot, there was a message waiting for him. Attack Removed, it said. The same thing happened over and over, infuriating Kaminsky. I came up with beautiful bugs, he said. But every time I went after the code there was a line that addressed the problem.…I’ve never seen anything like it, Kaminsky said, still in awe…Either there’s a team of people who worked on this, Kaminsky said, or this guy is a genius."

Kaminsky was talking about Satoshi's code, but some of the current devs seem good. For example, there's Mike Hearn, a senior security engineer at Google. And Jeff Garzik, a linux kernel developer.



Hmm, having now read Kamisnky's thoughts on BTC, were I a BTC enthusiast I'd be less than happy to pointing to them.

His evaluation is that the crypto is sound, but that as transaction volume increases the cost of entry goes up massively and the whole system has to morph into a centralised, bank-based operation run by a few parties with masses of processing power and storage capabilities. Interesting.


Scalability is definitely a challenge -- in fact, scaling to deal with SatoshiDice is what triggered the recent fork.

https://en.bitcoin.it/wiki/Scalability (which has some recent research on CPU optimizations) and https://bitcointalk.org/index.php?topic=34597.0 (a response from a year ago) answer some of Kaminsky's scalability criticisms.

There's also the possibility of off-the-chain transactions: http://gavintech.blogspot.co.il/2012/07/off-chain-transactio...


The bitcoin industry/community is not the same as the official client though is it?

I'm pretty sure that the poster was referring to the community of services that exist around bitcoin, rather than the protocol itself, that have been repeatedly and expensively compromised.


Sure Satoshi's original code & protocol design are good. But Satoshi's gone. All that's left is people who thought storing unsalted MD5 hashs of user passwords is acceptable (MtGox)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: