Bitcoin Forum
May 04, 2024, 06:43:28 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Bitcoin IS anonymous  (Read 4643 times)
cypherdoc (OP)
Legendary
*
Offline Offline

Activity: 1764
Merit: 1002



View Profile
August 04, 2011, 03:57:38 AM
 #21

By observing timing and size of network traffic bursts, one may deduce who is the sender of a bitcoin transaction, even if the network connection is encrypted.  And by default, the connection is not encrypted.
This is why it would make no sense to just encrypt bitcoin traffic as a separate overlay network.

Making use of an existing onion net such as I2P/Tor allows hiding the bitcoin traffic between other traffic. Still not 100% fool proof, as you could always do some kind of statistic analysis, but it moves it a lot more toward the tinfoil hat domain.

Anyway, the most effective way to trace people is indeed to have inside info at the exchanges. At the point where bitcoins are exchanged for bank money it's easy to ID who is behind it. From there, the network can be followed. This will become infeasible when there are people that are only paid in bitcoin and spend bitcoin and never trade, but my gut feeling is that those are really rare at this moment.


i often buy large amts of btc one on one with another bitcoiner here on the forum.  after he sends to me i go and deposit USD in his bank acct.  what if MyBitcoin has numerous P2P contacts like me and slowly liquidates his stolen btc.  how do you detect that esp. if he creates several wallets and routes through each of them prior?
"Bitcoin: the cutting edge of begging technology." -- Giraffe.BTC
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714848208
Hero Member
*
Offline Offline

Posts: 1714848208

View Profile Personal Message (Offline)

Ignore
1714848208
Reply with quote  #2

1714848208
Report to moderator
foggyb
Legendary
*
Offline Offline

Activity: 1652
Merit: 1006


View Profile
August 04, 2011, 04:06:53 AM
 #22


Pseudo-anonymous ...

... bitcoin's biggest deficiency as money, imo.

This is such a cheesy argument. My bank knows what I buy with my credit cards, where I buy it, and how much i spent. So does your bank. Everyone's bank.


To do the same thing with bitcoin, you need to be one of two things:

1.  A skilled hacker.
2. A government agency with probable cause.

  
Big Time Coin
Sr. Member
****
Offline Offline

Activity: 332
Merit: 250



View Profile
August 04, 2011, 04:36:14 AM
 #23

No, it's not "just theory".

By observing timing and size of network traffic bursts, one may deduce who is the sender of a bitcoin transaction, even if the network connection is encrypted.  And by default, the connection is not encrypted.

This is obviously predicated on someone already observing you, as well as actively sampling the P2P network.  If you find out about a crime after the fact, it is a lot more difficult to associate a transaction with a network address.

Other spends from the same wallet may compromise your identity, if you have ever posted a public bitcoin address somewhere.

In a closed ecosystem without ISP wiretaps and social engineering, bitcoin is highly private.  Use of dead drops, transaction delaying, mixing services and other means help increase anonymity, but are too difficult / time consuming for most people to want to use.  So we must live in the real world, where methods of discovering who is using bitcoin are already well known and used in the field today (keylogging, data sniffing and snarfing, network timing analysis, ...)



jgarzik, I bow to your superior knowledge on this issue.  Much respect.

However, you will always find out about a crime after the fact unless it is part of a larger criminal enterprise that is undergoing an active investigation.  Even when there is active monitoring with wiretaps, it is fairly useless in the P2P context.  This has been demonstrated by the huge proliferation of child pornography on the gnutella p2p network.  The police catch a small percentage of people sharing it, and it continues to multiply faster than it is stamped out, for almost a decade, despite continuous monitoring (dedicated, large-scale, expensive, distributed) of the P2P network in real time.

Here's the test, for you, Gavin, and whoever else knows enough about bitcoin and computer science to qualify as an expert in court.  Can you apply your theories about bitcoin not being anonymous to a real-world case.  Where are the mybitcoin, bitomat, and allinvain's bitcoins now?  Obviously, no one knows.  That's because bitcoins are anonymous.

You have publicly said and continue to maintain that they are not, and I respect that opinion as much as I respect you as a core developer.  But "keylogging, data sniffing and snarfing, network timing analysis" all presume that the investigator already has a target, has a court order in place to allow real-time monitoring of the target's electronic communication, and is monitoring that target when the crime takes place.  This is not going to happen in the real world with a real criminal but rarely, if ever.

There could be money in it for you, as an expert witness for the plaintiffs in a lawsuit against the operator(s) of mybitcoin.com, bitomat, and the allinvain malware, probably $10k to $25k, in each case though I won't be paying you so that's just a guesstimate, ballpark fee for an expert witness in a lawsuit.  Could higher if it turns out to be a $1 million lawsuit that requires your testimony.

Consider that some people that have lost bitcoin through fraud trusted the developers when they said that bitcoins were not anonymous.  That there was some way to trace them.  The time has come to prove it isn't "just theory".  Didn't Gavin Andresen go talk to the CIA about this at a hacker conference?  If you guys have any software at all to help out or are working on tracing software, now would be a good time to release it and start building some cases. 

Big time, I'm on my way I'm making it, big time, oh yes
- Peter Gabriel
Big Time Coin
Sr. Member
****
Offline Offline

Activity: 332
Merit: 250



View Profile
August 04, 2011, 04:53:33 AM
Last edit: August 04, 2011, 05:09:56 AM by Big Time Coin
 #24

Problem #1: How the hell am I supposed to know what addresses were Mybitcoin receiving addresses to begin with?  I can start a thread, but only a tiny fraction of people are going to see it or post their receiving addresses in there.
Quite easily. Using the blockchain, you can narrow down which transactions were from an ewallet by looking for transactions with almost no change. From there, some additional analysis can tell you with near certainty which addresses belonged to Mybitcoin.

Sounds good, please help turn this into an actual bit of pseudocode.  I give it a 1 out of 4 in its current state, no offense, but I can't write up an algorithm from it without fleshing it out some more.  What do you mean by "almost no change" and "additional analysis".

OK here is a blockexplorer link with a 14901.47 bitcoin transfer, that's pretty big.
http://blockexplorer.com/block/00000000000006770211a16cffd5ef085f3c3ed192967bb468545a8208b6dd01

following by hand we see that address 1H7otjEVe8hToKZp1pkiwy5U1Q4AoxPE61 was a one-off, received from
1C7NuqhuPhzTnga9oEgWpppNB94H6pqkcq  was 16901.47
1NiaokMExGmHc6rXnYZVC2kmNxVuBkgUpd
1MkZPvYxrfsi2oMJzLXJkeFdirnRrPY7gE
1Js9KagG6XriQwGMSnmsKAbEaAeb5SktqH
1HWyXtxDztaHQVDC3AsExkjBLb6QJEV812
1ABSwcSCem629fsyE1iSms9R2QTU8CL21p
1Em38UYdqmqXK8HtsbckL9867XL2WE73KQ
1MiBVHXdLTZXG5R7FdtxDt8gA3XPfTGtDm
13CCfvtvppQnFtQxE12sNufVa9j4WNm3v2
133eqQmq8HrGxPNiJSGFVXC9RGBjhFL66W
171utvtF4SVkgNR7VXqht5dZStn7UvJ5wL
1748UZ1VXeFqSp8qFXdGB3PM8nz5zjbqRY
1K31DMjDXJUEqQxH5LaXipyeUFZEm3KZrG   35k btc

but anyway, that goes back way into 2010... probably not the coins we are looking for

and here is the blockexplorer for my mybitcoin address, so I have one confirmed sample to work with:
http://blockexplorer.com/address/15qEeifQfkkgThE81PzaZsEkA79dvaMMXE

Big time, I'm on my way I'm making it, big time, oh yes
- Peter Gabriel
allinvain
Legendary
*
Offline Offline

Activity: 3080
Merit: 1080



View Profile WWW
August 04, 2011, 05:16:39 AM
 #25


Pseudo-anonymous ...

... bitcoin's biggest deficiency as money, imo.

So you wish it to be 100% anonymous? Or?

allinvain
Legendary
*
Offline Offline

Activity: 3080
Merit: 1080



View Profile WWW
August 04, 2011, 05:28:10 AM
 #26

No, it's not "just theory".

By observing timing and size of network traffic bursts, one may deduce who is the sender of a bitcoin transaction, even if the network connection is encrypted.  And by default, the connection is not encrypted.

This is obviously predicated on someone already observing you, as well as actively sampling the P2P network.  If you find out about a crime after the fact, it is a lot more difficult to associate a transaction with a network address.

Other spends from the same wallet may compromise your identity, if you have ever posted a public bitcoin address somewhere.

In a closed ecosystem without ISP wiretaps and social engineering, bitcoin is highly private.  Use of dead drops, transaction delaying, mixing services and other means help increase anonymity, but are too difficult / time consuming for most people to want to use.  So we must live in the real world, where methods of discovering who is using bitcoin are already well known and used in the field today (keylogging, data sniffing and snarfing, network timing analysis, ...)





Here's the test, for you, Gavin, and whoever else knows enough about bitcoin and computer science to qualify as an expert in court.  Can you apply your theories about bitcoin not being anonymous to a real-world case.  Where are the mybitcoin, bitomat, and allinvain's bitcoins now?  Obviously, no one knows.  That's because bitcoins are anonymous.

You have publicly said and continue to maintain that they are not, and I respect that opinion as much as I respect you as a core developer.  But "keylogging, data sniffing and snarfing, network timing analysis" all presume that the investigator already has a target, has a court order in place to allow real-time monitoring of the target's electronic communication, and is monitoring that target when the crime takes place.  This is not going to happen in the real world with a real criminal but rarely, if ever.

There could be money in it for you, as an expert witness for the plaintiffs in a lawsuit against the operator(s) of mybitcoin.com, bitomat, and the allinvain malware, probably $10k to $25k, in each case though I won't be paying you so that's just a guesstimate, ballpark fee for an expert witness in a lawsuit.  Could higher if it turns out to be a $1 million lawsuit that requires your testimony.


I'm going to have to take the side of Big Time Coin on this one...I challenge anyone to find out who is behind the following address:
http://blockexplorer.com/address/1C7tbiXExkyXfZLyCBNZYH24VDC5JryVXK

That's a chunk of my 25K bitcoins

I can track these damn things in perpetuity, but what good is that going to do me?

ctoon6
Sr. Member
****
Offline Offline

Activity: 350
Merit: 251



View Profile
August 04, 2011, 05:38:37 AM
 #27

i have been trying to tell people, centralization is not the answer a little after i got into bitcoin, i guess it takes this to kick the message in.

marcus_of_augustus
Legendary
*
Offline Offline

Activity: 3920
Merit: 2348


Eadem mutata resurgo


View Profile
August 04, 2011, 06:01:19 AM
Last edit: August 04, 2011, 06:11:48 AM by marcus_of_augustus
 #28

No, it's not "just theory".

By observing timing and size of network traffic bursts, one may deduce who is the sender of a bitcoin transaction, even if the network connection is encrypted.  And by default, the connection is not encrypted.

This is obviously predicated on someone already observing you, as well as actively sampling the P2P network.  If you find out about a crime after the fact, it is a lot more difficult to associate a transaction with a network address.

Other spends from the same wallet may compromise your identity, if you have ever posted a public bitcoin address somewhere.

In a closed ecosystem without ISP wiretaps and social engineering, bitcoin is highly private.  Use of dead drops, transaction delaying, mixing services and other means help increase anonymity, but are too difficult / time consuming for most people to want to use.  So we must live in the real world, where methods of discovering who is using bitcoin are already well known and used in the field today (keylogging, data sniffing and snarfing, network timing analysis, ...)



But in practicality, who has the means to carry out these kinds of traffic analysis and ISP connection snooping?

Government agencies.

Go figure on that one.

marcus_of_augustus
Legendary
*
Offline Offline

Activity: 3920
Merit: 2348


Eadem mutata resurgo


View Profile
August 04, 2011, 06:10:32 AM
 #29


Pseudo-anonymous ...

... bitcoin's biggest deficiency as money, imo.

So you wish it to be 100% anonymous? Or?

Is gold anonymous?

allinvain
Legendary
*
Offline Offline

Activity: 3080
Merit: 1080



View Profile WWW
August 04, 2011, 06:20:14 AM
 #30


Pseudo-anonymous ...

... bitcoin's biggest deficiency as money, imo.

So you wish it to be 100% anonymous? Or?

Is gold anonymous?

Sort of...someone can perhaps trace where you bought to gold from (assuming you're holding it in physical form and not stored with some storage provider or in "paper form") but it would be pretty damn hard to find out where you may have hidden your gold stash. If you buy gold from coin shops with cash and assuming they don't video tape everything then you're 100% anonymous. I'd say that bitcoin can be far more anonymous than gold.

marcus_of_augustus
Legendary
*
Offline Offline

Activity: 3920
Merit: 2348


Eadem mutata resurgo


View Profile
August 04, 2011, 06:35:10 AM
 #31

Quote
I'd say that bitcoin can be far more anonymous than gold.

You don't really have that much experience with using cash or gold do you?

ctoon6
Sr. Member
****
Offline Offline

Activity: 350
Merit: 251



View Profile
August 04, 2011, 07:11:14 AM
 #32

if you buy a bar of gold, i think it has a serial number on it. so you would be crazy to accept damage gold unless at a good price  Wink

allinvain
Legendary
*
Offline Offline

Activity: 3080
Merit: 1080



View Profile WWW
August 04, 2011, 07:51:23 AM
 #33

Quote
I'd say that bitcoin can be far more anonymous than gold.

You don't really have that much experience with using cash or gold do you?

And I suppose you do? How do you draw that judgement based on my statement is beyond me. When you buy gold you typically have to provide some real world proof of id or some info about you (assuming you did not fake it) gets left behind at the merchant or point of purchase. With bitcoin what info info about you is stored? Your e-mail address? Your IP? Get real man, bitcoin IS anonymous.

allinvain
Legendary
*
Offline Offline

Activity: 3080
Merit: 1080



View Profile WWW
August 04, 2011, 07:55:34 AM
 #34

if you buy a bar of gold, i think it has a serial number on it. so you would be crazy to accept damage gold unless at a good price  Wink

You can still get scammed with gold too. But usually if you stay within the gold chain of integrity (Gold bars from the "good delivery list" )..anyways google "gold chain of integrity"..


westkybitcoins
Legendary
*
Offline Offline

Activity: 980
Merit: 1004

Firstbits: Compromised. Thanks, Android!


View Profile
August 04, 2011, 08:18:46 AM
 #35

Quote
I'd say that bitcoin can be far more anonymous than gold.

You don't really have that much experience with using cash or gold do you?

And I suppose you do? How do you draw that judgement based on my statement is beyond me. When you buy gold you typically have to provide some real world proof of id or some info about you (assuming you did not fake it) gets left behind at the merchant or point of purchase. With bitcoin what info info about you is stored? Your e-mail address? Your IP? Get real man, bitcoin IS anonymous.

Huh

I've never had to provide ID, background info, or even my name when buying gold, although I chose to once or twice by buying via debit card. Just find a brick-and-mortar shop that sells gold. Take cash. Buy smallish amounts. Nothing to it.

If you want to spend a lot, either first build up a rapport with the shop owner over time, or look for several more out-of-the-way places to buy from. (Look hard. Odd downtown shops and flea markets can surprise you.)


Bitcoin is the ultimate freedom test. It tells you who is giving lip service and who genuinely believes in it.
...
...
In the future, books that summarize the history of money will have a line that says, “and then came bitcoin.” It is the economic singularity. And we are living in it now. - Ryan Dickherber
...
...
ATTENTION BFL MINING NEWBS: Just got your Jalapenos in? Wondering how to get the most value for the least hassle? Give BitMinter a try! It's a smaller pool with a fair & low-fee payment method, lots of statistical feedback, and it's easier than EasyMiner! (Yes, we want your hashing power, but seriously, it IS the easiest pool to use! Sign up in seconds to try it!)
...
...
The idea that deflation causes hoarding (to any problematic degree) is a lie used to justify theft of value from your savings.
allinvain
Legendary
*
Offline Offline

Activity: 3080
Merit: 1080



View Profile WWW
August 04, 2011, 08:27:18 AM
 #36

Quote
I'd say that bitcoin can be far more anonymous than gold.

You don't really have that much experience with using cash or gold do you?

And I suppose you do? How do you draw that judgement based on my statement is beyond me. When you buy gold you typically have to provide some real world proof of id or some info about you (assuming you did not fake it) gets left behind at the merchant or point of purchase. With bitcoin what info info about you is stored? Your e-mail address? Your IP? Get real man, bitcoin IS anonymous.

Huh

I've never had to provide ID, background info, or even my name when buying gold, although I chose to once or twice by buying via debit card. Just find a brick-and-mortar shop that sells gold. Take cash. Buy smallish amounts. Nothing to it.

If you want to spend a lot, either first build up a rapport with the shop owner over time, or look for several more out-of-the-way places to buy from. (Look hard. Odd downtown shops and flea markets can surprise you.)



True enough, and that's what I was saying in one of my previous posts. But keep in mind that you are still exposing your visual identity (ie your face) to the shop keeper. In that sense it is not 100% anonymous. You'd be surprised how good some people's memory can be.

I think it's a bad idea that the gold shops you frequent don't ask for id - ie money laundering.

The gist of my argument is that it is a lot easier to leave no traces in the digital world than in the physical world - hence anything do in "real life" carries the risk of compromising your "anonymity"

cypherdoc (OP)
Legendary
*
Offline Offline

Activity: 1764
Merit: 1002



View Profile
August 04, 2011, 01:59:17 PM
 #37

Quote
I'd say that bitcoin can be far more anonymous than gold.

You don't really have that much experience with using cash or gold do you?

i do.  its less anon than you think.  i've been selling my gold and silver and the coin shop issues a 1099 to me when i do.
they also took down my drivers license, address, and a fingerprint.

when i bought it i don't remember having to do that tho.
lettucebee
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
August 04, 2011, 03:09:25 PM
 #38

To do the same thing with bitcoin, you need to be one of two things:

1.  A skilled hacker.
2. A government agency with probable cause.

But "keylogging, data sniffing and snarfing, network timing analysis" all presume that the investigator already has a target, has a court order in place to allow real-time monitoring of the target's electronic communication, and is monitoring that target when the crime takes place.  This is not going to happen in the real world with a real criminal but rarely, if ever.

Guys, I am following this thread with great interest.  I am a student of how one sifts through the blockchain, but when I encounter comments like the above I have to weigh in with what I do know. 

We can all assume that every single thing we do on the internet, phone calls we make, credit card purchases, our location (from our cell phones), bank transactions, pretty much every electronic transaction, travel patterns, and on and on....are stored and analyzed WITHOUT A COURT ORDER.

See http://www.eff.org/issues/nsa-spying just for starts.  You should assume that the traffic analysis discussed here is already being done on the blockchain at a minimum.

"Every purchase you make with a credit card, every magazine subscription you buy and medical prescription you fill, every Web site you visit and e-mail you send or receive, every academic grade you receive, every bank deposit you make, every trip you book and every event you attend — all these transactions and communications will go into what the Defense Department describes as "a virtual, centralized grand database," infamously wrote New York Times writer William Safire, announcing the birth of Total Information Awareness, a kind of Echelon on steroids introduced a year after 9/11.


▄██████████████████▄
▄██████████████████████▄
█████▀              ▀█████
▄████▀    ▄▄▄▄▄▄        ▀████▄
▀█████▄    ▀█████▄     ▄█████▀
▀█████▄    ▀█████▄ ▄█████▀
█▄  ▀█████▄    ▀█████████▀  ▄█
██▄  ▀█████▄    ▀█████▀  ▄██
███▄  ▀█████▄    ▀█▀  ▄███
▀███▄  ▀█████▄     ▄███▀
▀████▄  ▀████▀  ▄████▀
█████▄  ▀▀  ▄█████
▀█████▄  ▄█████▀
▀█████  █████▀
▀████████▀
██████
▀██▀
E R N
               ▄▄█████████▄▄
           ▄▄█████████████████▄▄
        ▄███████▀▀       ▀▀███████▄
       █████▀▀               ▀▀█████
     ▄████▀    ▄▄█████████▄▄    ▀████▄
    ████▀   ▄█████████████████▄   ▀████
   ████    █████████████████████    ████
 █████    ███████  ▀█████████████    █████
█████    █████████    ▀███████████    █████
████    ▄██████████▄     ▀████████▄    ████
████    █████████████       ███████    ████
████    ▀██████████▀     ▄████████▀    ████
█████    █████████    ▄███████████    █████
 █████    ███████  ▄█████████████    █████
           █████████████████████
            ▀█████████████████▀
               ▀▀█████████▀▀
████
████

████
████

████
████

████
████
TOKEN SALE
AIRDROP
                              ████
                              ████

                              ████
          ████            ████  ████

          ████            ████  ████
          ████  ████  ████  ████  ████

████  ████  ████  ████  ████  ████  ████
████  ████  ████  ████  ████  ████  ████
  ▬▬   GET IN TOUCH   ▬▬ 
TELEGRAM  FACEBOOK  TWITTER
YOUTUBE   INSTAGRAM
allinvain
Legendary
*
Offline Offline

Activity: 3080
Merit: 1080



View Profile WWW
August 04, 2011, 03:28:12 PM
 #39

I wonder if they do this for non US Citizens as well.

foggyb
Legendary
*
Offline Offline

Activity: 1652
Merit: 1006


View Profile
August 04, 2011, 03:29:39 PM
 #40

Quote
I'd say that bitcoin can be far more anonymous than gold.

You don't really have that much experience with using cash or gold do you?

i do.  its less anon than you think.  i've been selling my gold and silver and the coin shop issues a 1099 to me when i do.
they also took down my drivers license, address, and a fingerprint.

when i bought it i don't remember having to do that tho.

In my part of Canada (mid-west) i am not aware of any reputable retail location that I can purchase PM's from, without supplying photo ID.

Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!