HN user

hnolable

247 karma
Posts0
Comments73
View on HN
No posts found.

The part you're missing is that Bitcoin is totally fine if it never changed from how it is today. Anonymity will come via Tumblebit. Lightning network can already work even without segwit.

Segwit never getting activated may even be a good thing. It will show everyone that Bitcoin has crystalized and can never be changed via petty human emotion. This was always Bitcoin's true selling point and we may be about to demonstrate it.

So yes, politics can and will be ignored.

Yes that's the issue here, the miners are playing politics by trying to flex their power. But no one is willing to play petty games. There's an obvious win for everyone sitting on the table ready to go. Political games will be ignored.

You admitted that "The whole reason people want bigger blocks is for higher transaction throughput on-chain."

And said that "Segwit doesn't deliver that".

Segwit delivers that.

You can play semantical games but segwit gives about 2x onchain capacity. And the only thing holding it up is a group of chinese miners/pools. Anyone truly wanting more onchain capacity should be engaging those miners/pools.

Of course that's not really what people bitching about tx fees want.

Segwit requires 95% of miners to activate. Currently about 75% of hash power is controlled by a group of chinese miners/pools. This is about the % of hashing power that is missing for Segwit to activate.

If Eric was serious about this he would have targeted this post at chinese miners who are stalling on activating segwit (which is a 2x blocksize increase and the foundation for instant & nearly free txs via the Lightning Network).

Shares are valued by people based on three things. Future direct cash you receive from the company based on the shares you hold (e.g. dividends/distributions and share buybacks). Voting power (i.e. control) in the company based on the shares you hold. And finally the ability to sell the shares you hold on the open market in the future (i.e. price speculation). Issuing more shares (usually) directly affects (i.e. dilutes) #1 and #2. But #3 is not directly affected in any way.

Yes I get that, I think there is a new DH for almost every message, much better than TLS. The problem is we have no idea what the NSAs abilities are in terms of actual cryptanalysis/cracking, but we do know that they have an immense desire for it.

RFC 3526 puts the low end of the 1536 bit group's strength at 90 bits. If some unknown weakness was found that lowers that significantly that doesn't leave things very safe.

Agreed that curves would be ideal.

I believe the weakest link in OTR is its Diffie-Helman key exchange. If you break that you get the symmetric key and can decrypt everything passively. OTR has been using a 1536 bit modulus for its Diffie-Helman exchange since 2004 [1] (The weakest one from RFC 3526 [2]). Seems they are still using the same one today.

In 2004 this was probably a fine choice, especially considering the tradeoff between CPU processing (usability) and security. But considering the NSA scandal, specifically them recording all encrypted communications forever, and Bruce Schneier increasing his key lengths [3], and the ability for CPUs to process higher keylengths without any noticeable slowdown, I don't feel confident it is strong enough today.

Other than this gripe OTR is amazing and everyone should be using it.

Edit: xnyhps's post [4] concludes that only a single "cracking" of the 1536 bit group would need to occur to then decrypt any past or future OTR conversation "instantly".

[1] https://web.archive.org/web/20041215062523/http://www.cypher... [2] http://www.ietf.org/rfc/rfc3526.txt [3] https://news.ycombinator.com/item?id=6376954 [4] https://blog.thijsalkema.de/blog/2014/01/17/misconceptions-a...

No, the DHE/ECDHE (ephemeral key exchanges) don't protect against MITM, it protects against passive dragnet decryption. But the RSA/ECDSA/DSS part (certificate signing) does. All TLS ciphersuites include certificate signing to protect against MITM, but not all include ephemeral key exchange.

My understanding is app.net is trying to be a paid version of twitter. There was/is much debate whether it could ever take off. This is the first time I've ever seen someone link to it. Although now I realize that the link is to the app.net cofounder so that doesn't really say much.

Here's something to ponder... Sure once in a while your bank/CC payment system protects you from a shady merchant... saving you what... 100$ (max?). Personally in my entire life I can't remember charging back once due to a shady merchant but let's assume you've saved 1000$ because of chargebacks.

Here's one of the risks you have to bear to enable your chargebacks: http://mashable.com/2011/01/28/identity-theft-infographic/ ... worth it? Think how many insecure databases your name and address and credit card # (and sometimes phone number) are stored in across the net...

Wow, so it _is_ true, that's the confirmation I was looking for. Really hard to believe. I knew if they did shut them off they would point to the fact it's still "beta". The subscription feature has been labeled beta since it was released in March 2009. This is sick.

That sentence is confusing at best. "If you don't have your own payment processing" What does that mean? I thought Google Checkout was my payment processor? Do they mean if you already have a payment processor other than Google?

And if I _do_ have my own payment processing then I won't need to "transition to a different solution within six months". What does that mean, are they going to give me all the subscribers credit card info so I can start charging their cards myself? I don't think so.

As far as I know Braintree only does direct credit card processing, similar to Stripe. If they are planning on migrating all the Google Checkout subscriptions to Braintree credit card subscriptions that would be great but it doesn't sound like that to me. And how would that work for the Google Checkout users who were able to manage their subscriptions through the Google Checkout interface? Does Braintree have an interface for all Google Checkout users or do they lose their interface and need to go through the merchant now?

Anyone have any idea if this effectively terminates any existing recurring Google Checkout subscription payments (on November 20)? If so, that's kind of a big deal. Cutting off merchants from their revenue stream is a great way to get people really angry and could easily destroy a business.

NSA, China, Russia, most governments really, and possibly a lot of banks, could do a 51% attack and shut down transaction processing... or do double spends, but shutting down all transaction processing seems more damaging. This won't ever change, unless Bitcoin really causes governments to lose most of their power and money.

Edit: gavin has a plan (http://gavintech.blogspot.com/2012/05/neutralizing-51-attack...) but my guess is if they did the work to start an attack in the first place they'd have planned for gavin's plan and acquired enough older coins to foil it. It'd be nice if more thought went into other ways to thwart a possible attack but I'm not sure there really are any. Most people seem to discount and completely avoid the issue.