Tuesday, October 25, 2022

Non-Fungible Token Bubble Lasted 10 Months

Although the first Non-Fungible Token was minted in 2014, it wasn't until Cryptokitties bought the Ethereum blockchain to its knees in December 2017 that NFTs attracted attention. But then they were swiftly hailed as the revolutionary technology that would usher in Web 3, the Holy Grail of VCs, speculators and the major content industries because it would be a completely financialized Web. Approaching 5 years later, it is time to ask "how's it going?"

Below the fold I look at the details, but the TL;DR is "not so great"; NFTs as the basis for a financialized Web have six main problems:
  1. Technical: the technology doesn't actually do what people think it does.
  2. Legal: there is no legal basis for the "rights" NFTs claim to represent.
  3. Regulatory: much of the business of creating and selling NFTs appears to violate securities law.
  4. Marketing: the ordinary consumers who would pay for a financialized Web absolutely hate the idea.
  5. Financial: like cryptocurrencies, the fundamental attraction of NFTs is "number go up". And much of the trading in NTFs was Making Sure "Number Go Up". But, alas "number go down", at least partly because of problem #4.
  6. Criminal: vulnerabilities in the NFT ecosystem provide a bonanza for thieves.

Thursday, October 20, 2022

A White Swan Event

Bitcoin Fails to Produce 1 Block for Over an Hour by Oliver Knight makes it sound like something went wrong:
It took more than an hour to mine a block of bitcoin (BTC) on Monday, leaving thousands of transactions stuck in an unconfirmed state.

According to on-chain data from several block explorers, the interval between the two latest blocks mined by Foundry USA and Luxor was 85 minutes.

According to Mempool, over 13,000 transactions were pending before the latest block was mined.

Last week Bitcoin underwent a difficulty adjustment to ensure block confirmations kept taking place every 10 minutes. With mining difficulty surging to 35.6 trillion it becomes more expensive to mine bitcoin, which heaps pressure on a mining industry that is dealing with soaring energy prices and a crypto bear market.
But the tail of Knight's post contradicts that:
Tadge Dryja, founder of the Lightning Network, tweeted that an 85-minute interval between blocks can be expected to happen once every 34 days, not taking into account difficulty changes.
Below the fold I explain that Dryja is right, the system is behaving as designed.

Tuesday, October 18, 2022

The Power Of Ethereum's Merge

The laudable goal of Ethereum's "Merge", the long-awaited transition from Proof-of-Work to Proof-of-Stake, was to eliminate more than 99% of the massive environmental damage caused by Ethereum's consuming about half as much power as Bitcoin. There are many reasons to criticize Proof-of-Stake, but the Merge definitely achieved this goal. We can no longer point the finger at Ethereum and its users and claim they are wrecking the climate half as much as Bitcoin.

However, as usual when cryptocurrency advocates tout claims like "more than 99%" it is necessary to apply skepticism. From the planet's point of view the issue is not whether the Merge reduced Ethereum's carbon emissions, but whether the Merge reduced the carbon emissions of cryptocurrencies as a whole. The answer is "not so much". Below the fold I discuss the details and estimate the real reduction to be ~35%, because most of the power has been diverted to mining Bitcoin.

Tuesday, October 11, 2022

The "DNA Typewriter"

It is time to catch up on a few developments in the field of storing data via chemicals, such as DNA. Below the fold I discuss a half-dozen recent reports.

Thursday, October 6, 2022

Piercing The Veil

In Deconstructing ‘Decentralization’: Exploring the Core Claim of Crypto Systems Prof. Angela Walch gets to the heart of what the claim that a system is "decentralized" actually means:
the common meaning of ‘decentralized’ as applied to blockchain systems functions as a veil that covers over and prevents many from seeing the actions of key actors within the system. Hence, Hinman’s (and others’) inability to see the small groups of people who wield concentrated power in operating the blockchain protocol. In essence, if it’s decentralized, well, no particular people are doing things of consequence.

Going further, if one believes that no particular people are doing things of consequence, and power is diffuse, then there is effectively no human agency within the system to hold accountable for anything.
In other words, it is a means for the system's insiders to evade responsibility for their actions.

If the system were truly decentralized, with a large number of insiders none of whom had significantly more power over it than any other, this veil might be effective. But this is never the case in the real world. As I described in Are Bloockchains Decentralized?, based on Prof. Walch's work, the report from Trail of Bits and Kwon et al's Impossibility of Full Decentralization in Permissionless Blockchains, there are always loci of control behind the veil for regulators to address.

Below the fold I discuss recent moves by US regulators that indicate they agree.

Thursday, September 29, 2022

Responsible Disclosure Policies

Recently, Uber was completely pwned, apparently by an 18-year-old. Simon Sharwood's Uber reels from 'security incident' in which cloud systems seemingly hijacked provides some initial details:
Judging from screenshots leaked onto Twitter, though, an intruder has compromised Uber's AWS cloud account and its resources at the administrative level; gained admin control over the corporate Slack workspace as well as its Google G Suite account that has over 1PB of storage in use; has control over Uber's VMware vSphere deployment and virtual machines; access to internal finance data, such as corporate expenses; and more.
And in particular:
Even the US giant's HackerOne bug bounty account was seemingly compromised, and we note is now closed.

According to the malware librarians at VX Underground, the intruder was using the hijacked H1 account to post updates on bounty submissions to brag about the degree of their pwnage, claiming they have all kinds of superuser access within the ride-hailing app biz.

It also means the intruder has access to, and is said to have downloaded, Uber's security vulnerability reports.
Thus one of the results of the incident is the "irresponsible disclosure" of the set of vulnerabilities Uber knows about and, presumably, would eventually have fixed. "Responsible disclousure" policies have made significant improvements to overall cybersecurity in recent years but developing and deploying fixes takes time. For responsible disclosure to be effective the vulnerabilities must be kept secret while this happens.

Stewart Baker points out in Rethinking Responsible Disclosure for Cryptocurrency Security that these policies are hard to apply to cryptocurrency systems. Below the fold I discuss the details.

Thursday, September 22, 2022

Cryptocurrency-enabled Crime

Source
Robin Wigglesworth's An anatomy of crypto-enabled cyber crime points to An Anatomy of Crypto-Enabled Cybercrimes by Lin William Cong, Campbell R. Harvey, Daniel Rabetti and Zong-Yu Wu. They write in their abstract that:
Assembling a diverse set of public, proprietary, and hand-collected data including dark web conversations in Russian, we conduct the first detailed anatomy of crypto-enabled cybercrimes and highlight relevant economic issues. Our analyses reveal that a few organized ransomware gangs dominate the space and have evolved into sophisticated firm-like operations with physical offices, franchising, and affiliation programs. Their techniques also have become more aggressive over time, entailing multiple layers of extortion and reputation management. Blanket restrictions on cryptocurrency usage may prove ineffective in tackling crypto-enabled cybercrime and hinder innovations. But blockchain transparency and digital footprints enable effective forensics for tracking, monitoring, and shutting down dominant cybercriminal organizations.
Wigglesworth comments:
Perhaps. But while it is true that blockchain transparency might enable arduous but effective analysis of crypto-enabled cyber crime, reading this report it’s hard not to think that the transparency remedy is theoretical, but the costs are real.
I have argued that the more "arduous but effective analysis" results in "tracking, monitoring, and shutting down" cybercriminals, the more they will use techniques such as privacy coins (Monero, Zcash) and mixers (Tornado Cash). Indeed, back in January Alexander Culafi reported that Ransomware actors increasingly demand payment in Monero:
In one example of this, DarkSide, the gang behind last year's Colonial Pipeline attack, accepted both Monero and Bitcoin but charged more for the latter because of traceability reasons. REvil, which gained prominence for last year's supply-chain attack against Kaseya, switched to accepting only Monero in 2021.
Below the fold I discuss both Cong et al's paper, and Erin Plante's $30 Million Seized: How the Cryptocurrency Community Is Making It Difficult for North Korean Hackers To Profit, an account of Chainalysis' "arduous but effective" efforts to recover some of the loot from the Axie Infinity theft.