I think that's less than constructive. We know that intelligence and law enforcement have significant issues with Tor [1] that mostly are overcome by people missing the point of what Tor does and having bad operational security in general.
Also, when parts of the government have attacked the security provided by Tor, it's been visible (and kind of hamhanded) [2].
I actually think the WIRED piece [1] to which OP refers does a good job of addressing this point. In particular, the WIRED article mentions PORTAL, a competing device called the SafePlug (which we did some research on to show that it does this job rather poorly), and something I'd never previously heard of called OnionPi.
Also, the article states very clearly states:
"If you use the same browser for your anonymous and normal Internet activities, for instance, websites can use “browser fingerprinting” techniques like cookies to identify you.", which is basically the point of this post.
The WIRED piece even goes further, offering the same solution as is offered in this piece:
"[an expert] suggests that even when routing traffic over Tor with Anonabox, users should use the Tor Browser, a hardened browser that avoids those fingerprinting techniques."
So while I understand the gripe that a transparent Torifying proxy doesn't necessarily do what you think it should, I would also praise WIRED for doing a pretty good job of handling these difficult and subtle issues in their article about the Anonabox.
I noticed this, too. I think it speaks less of spell checkers and more about Time's ability to do copy-editing.
If I submitted a piece to a major outlet such as this, I would do so in full faith that they would assign at least one person to read through it and copy-edit it before publication. Apparently, Time is not a sufficiently reputable institution of journalism to believe in doing this, or at least is unwilling to spend enough money to have it done by competent people.
EDIT: As for Janet's credibility, I can speak to it personally, having spent a year with her working down the hall from my office. Probably the coolest stuff she's done relates to how decisions are made in big teams of scientists (she studied the sociology of scientists running some Mars rover missions: http://janet.vertesi.com/projects/social-life-spacecraft).
I did not previously know that there was work suggesting that mining is naturally an oligopoly. People have suggested to me that mining may already be a monopoly and that this could have been going on for a long time, with a monopoly pool "laundering" its work through rented time on other pools. So there are definitely interesting questions to consider in this area, including questions about how a rational mining monopolist will want to behave.
Apparently, the hearing focused mostly on issues of the appropriateness of the venue and not much on the computer crime aspects. That means the appeals panel may not actually rule on the merits, but may dismiss the case on what amounts to "a technicality". That would leave the gray area of the form of the original ruling against Weev about what does or does not constitute a CFAA violation.
Chromebook owner here. I haven't been able to convince the data on my machine to function on the free plan yet this month, but I'd chalked it up to the 3g modem being mostly iffy anyway. Looking forward to watching this.
People keep telling me that research I'm doing with some friends overlaps with what these people are proposing, so I've spent a little time trying to figure out what they do and how they do it from their website. I haven't yet played with their client or anything like that.
I really can't see any substance here. The name is also sort of darkly humorous: they've clearly poured a lot of effort into (at least marketing) what they're doing, but have yet to realize that they're just tilting at windmills.
How about a simple antitrust argument: if Google wants to use their power in the browser market, where they have majority power, to dictate the shape of the online advertising market, I think DoJ would have a pretty slam dunk case. Especially since Microsoft would be happy to pay for the best lawyers out there to write all the briefs in the case.
But the most important question about the dynamics of Bitcoin mining, which nobody has yet answered, is whether there is an equilibrium that can actually occur in which the Bitcoin economy can no longer function. This is the question that everyone would like to answer.
Indeed, the Cornell attack on Bitcoin mining claims to demonstrate that Bitcoin is not incentive compatible. This claim is demonstrably wrong. The burden of proof is on the original authors to rebut their (correct) detractors.
> In the ES paper, and in your responses, the assumption is a colluding group of miners. I find myself agreeing with you there; it looks like the colluders have more incentive to break ranks. But suppose a single individual controlled 33%. Couldn't they use this same strategy to benefit more than we previously thought they could?
Yes, I think they could. I'm currently trying to model what happens in mining pools where the pool master attempts to keep the pool's state a secret from the pool members to deter the kind of hopping behavior necessary for fair weather mining.
I think it's interesting to calculate how much less the BTC/USD exchange rate would have to be as a function of how much power the ES-adversary has. It's substantial!
One could even imagine creating "poison pill" derivative instruments where someone agrees to sell a lot of BTC if some predicate over the blockchain becomes true (such as a predicate that's only true if ES-mining is happening).
Imagine I have N resources, and instead of hopping between pools, I'm deciding what percent to allocate to ES-mining and what percent to allocate to "honest" mining. I could certainly allocate 99% of my resources to one or the other in each round, which would be a good (99%) simulation of fair-weather mining.
How would such a proof protocol work? I spent most of yesterday trying to answer that question and came up with nothing. Imagine that you and I are mining and we've agreed to use the ES "selfish" strategy. When I want to getWork, I have to choose which branch I'm targeting as the parent of whatever block I'm trying to mine (I have to choose which hash to put into my block). But how do I prove this to you? I could send you a commitment to the hash and you could promise to come beat me up after the fact if I lied, but that's outside the stated protocol. In fact, if your model is that you can coerce me to follow your protocol when it's better for me to do something else, then you may as well coerce me to give you all my bitcoins.
Our argument is that the protocol, as stated, is not incentive compatible. That's ironic, because the protocol, as stated, is offered as an argument that Bitcoin is not incentive compatible.
Hi, Author of the referenced blog post [2] here (and one of Felten's grad students).
Let me lay out the argument from our post in a more technical way: the biggest problem with the Eyal/Sirer paper is that they don't think about the problem as an equilibrium problem, but rather argue about what's best from the perspective of a particular player. This leads them to propose a strategy which is not even optimal for any player (we prefer to think of Bitcoin as a kind of consensus game, in the game theoretic sense. See our earlier paper on the topic [1]).
They argue that Bitcoin is not incentive-compatible by virtue of the strategy they demonstrate. I think this question needs to be the crux of any Bitcoin research paper. I'll define "incentive compatible" to mean one of two things
(1) (weakly incentive compatible) If people follow their incentives, rather than the rules of Bitcoin as written down and understood by the community, then there exists an equilibrium in which all players follow the rules.
(2) (strongly incentive compatible) The above equilibrium is the only equilibrium in Bitcoin.
The question of whether the current Bitcoin ruleset is incentive compatible strikes me as the most important Bitcoin research question: it answers whether Bitcoin, as a system, will continue to be stable over the long term. A secondary question is to ask "what rule sets could exist which would be incentive compatible?" Obviously, if the answer to the first question is "no" then the second question is more important.
Stripe [1] seems to be a favorite around here. I don't know much about their competitors and a quick search of the archives didn't turn up the flamewars I remember seeing, but I do know a lot of the Stripe team and I can vouch that they're all top-notch.