1
00:00:04,578 --> 00:00:09,940
All right, I said several times earlier
that Bitcoin is only pseudonymous,

2
00:00:09,940 --> 00:00:14,180
so all of your transactions or
addresses could get linked together.

3
00:00:14,180 --> 00:00:16,630
Let's now go in and
see how that might actually happen.

4
00:00:18,620 --> 00:00:21,542
Let's, in fact,
start from WikiLeaks again.

5
00:00:21,542 --> 00:00:24,685
I showed you a quote from them
saying Bitcoin is a secure and

6
00:00:24,685 --> 00:00:26,361
anonymous digital currency.

7
00:00:26,361 --> 00:00:28,920
And this is actually the page
that that was taken from.

8
00:00:30,100 --> 00:00:32,390
This is their donations page.

9
00:00:32,390 --> 00:00:36,271
And here you'll see that, in addition to
this blurb about Bitcoin being secure and

10
00:00:36,271 --> 00:00:38,779
anonymous, they have
a donation address over here.

11
00:00:38,779 --> 00:00:40,740
This is, of course,
the hash of a public key.

12
00:00:40,740 --> 00:00:43,318
You've seen things like
this in previous lectures.

13
00:00:43,318 --> 00:00:47,474
But, they also have this interesting
refresh button right next to that.

14
00:00:47,474 --> 00:00:49,770
What do you imagine this
refresh button might do?

15
00:00:50,810 --> 00:00:52,300
Well, as you might expect,

16
00:00:52,300 --> 00:00:56,730
if you click on that refresh button, it'll
give you an entirely new donation address.

17
00:00:57,950 --> 00:00:59,790
Let's go in and take a look at that.

18
00:00:59,790 --> 00:01:02,321
So, a totally new address
popped up on the page.

19
00:01:02,321 --> 00:01:03,807
So what is going on here?

20
00:01:03,807 --> 00:01:08,921
What WikiLeaks is doing is it's making
sure that each time a person visits

21
00:01:08,921 --> 00:01:13,950
the page, each time a person wants to
visit the page and make a donation,

22
00:01:13,950 --> 00:01:19,642
they send that donation to a totally new
public key that WikiLeaks creates just for

23
00:01:19,642 --> 00:01:20,737
that purpose.

24
00:01:20,737 --> 00:01:25,429
So here, WikiLeaks is taking advantage
of the ability to create new pseudonyms,

25
00:01:25,429 --> 00:01:27,539
new public keys, to their maximum.

26
00:01:27,539 --> 00:01:30,085
Every single transaction
that they receive,

27
00:01:30,085 --> 00:01:32,312
they want to receive it at a new address.

28
00:01:32,312 --> 00:01:35,192
And in fact,
this is the Bitcoin best practice for

29
00:01:35,192 --> 00:01:39,179
anonymity, to always receive new
transactions at a fresh address.

30
00:01:40,420 --> 00:01:41,410
So you might look at this and

31
00:01:41,410 --> 00:01:45,600
think, surely then, these different
addresses must be unlinkable.

32
00:01:45,600 --> 00:01:48,110
You receive a transaction over here,
and then much later,

33
00:01:48,110 --> 00:01:50,176
you just spend it by sending
it to somebody else.

34
00:01:50,176 --> 00:01:52,798
You receive another transaction
at this address, and

35
00:01:52,798 --> 00:01:54,912
then you send it to
someone else over there.

36
00:01:54,912 --> 00:01:56,757
So how might somebody link?

37
00:01:56,757 --> 00:01:59,149
Well, here's the key.

38
00:01:59,149 --> 00:02:01,552
Let's imagine this scenario.

39
00:02:01,552 --> 00:02:06,350
Alice, our customer, goes to a Big
box store and wants to buy a teapot.

40
00:02:08,040 --> 00:02:12,139
So in this scenario, Alice has a few
Bitcoins lying around with these different

41
00:02:12,139 --> 00:02:16,009
denominations, and the store lists
the teapot for a price of 8 Bitcoins.

42
00:02:17,420 --> 00:02:20,231
That's a pretty expensive teapot
at today's exchange rate.

43
00:02:20,231 --> 00:02:24,016
So, imagine that's 70 Bitcoins or
something, if you like.

44
00:02:24,016 --> 00:02:28,892
Any rate, Alice has these different
addresses and wants to pay for the teapot.

45
00:02:28,892 --> 00:02:30,854
How is she going to accomplish this?

46
00:02:30,854 --> 00:02:35,393
She doesn't have an address with
eight Bitcoins sitting in there.

47
00:02:35,393 --> 00:02:40,284
And so what she's going to do is she's
going to combine several different input

48
00:02:40,284 --> 00:02:45,470
transactions into a single transaction in
order to pay eight BitCoins to the store.

49
00:02:47,050 --> 00:02:49,320
So this reveals something.

50
00:02:49,320 --> 00:02:51,820
For somebody who's looking
at this transaction that

51
00:02:51,820 --> 00:02:53,720
gets recorded permanently
in the block chain,

52
00:02:53,720 --> 00:02:57,920
they're going to think, ah-ha,
two different inputs to this transaction.

53
00:02:57,920 --> 00:03:02,318
That could only happen because both
of these input addresses are under

54
00:03:02,318 --> 00:03:04,189
the control of the same user.

55
00:03:04,189 --> 00:03:08,171
They were able to use their wallet
software to create a transaction

56
00:03:08,171 --> 00:03:10,387
that combined both of them into one.

57
00:03:10,387 --> 00:03:11,820
So in other words,

58
00:03:11,820 --> 00:03:17,470
shared spending is evidence of joint
control of two different addresses.

59
00:03:17,470 --> 00:03:18,665
And it doesn't stop there.

60
00:03:18,665 --> 00:03:22,556
This is not just about linking two
different addresses that are inputs to

61
00:03:22,556 --> 00:03:23,460
a transaction.

62
00:03:23,460 --> 00:03:25,538
You can do that transitively.

63
00:03:25,538 --> 00:03:29,922
And every time Alice has a whole cluster
of addresses that have been linked, and

64
00:03:29,922 --> 00:03:34,371
then she creates a new transaction that
combines one of those addresses with a new

65
00:03:34,371 --> 00:03:37,530
address, you could add this
new address to the cluster.

66
00:03:39,030 --> 00:03:43,650
So this is first insight behind being
able to link transactions together.

67
00:03:43,650 --> 00:03:47,605
And we'll see later on that an anonymity
technique called CoinJoin works by

68
00:03:47,605 --> 00:03:49,594
violating exactly this assumption.

69
00:03:49,594 --> 00:03:53,850
But if you assume that people are just
using regular Bitcoin wallet software, not

70
00:03:53,850 --> 00:03:58,239
doing anything special on top of it, then
this technique tends to be pretty robust.

71
00:03:59,380 --> 00:04:03,210
And this has been explored in
a variety of research papers.

72
00:04:03,210 --> 00:04:07,566
And as just a note about this lecture,
a lot of what we're going to be discussing

73
00:04:07,566 --> 00:04:11,283
today gets into the frontiers of
where the research knowledge are.

74
00:04:11,283 --> 00:04:14,531
So a lot of this, the state of the art
may have advanced in a few months or

75
00:04:14,531 --> 00:04:15,148
a few years.

76
00:04:15,148 --> 00:04:18,937
So every time I talk about a technique
that we know from a particular research

77
00:04:18,937 --> 00:04:22,736
paper, I'll give you a reference to
that paper, so that you can look it up.

78
00:04:22,736 --> 00:04:24,419
You can look up papers that cite it.

79
00:04:24,419 --> 00:04:27,171
And you can build up that
knowledge on your own.

80
00:04:27,171 --> 00:04:31,880
Now, in particular, one of the papers
that used this technique used it for

81
00:04:31,880 --> 00:04:33,394
a particular purpose.

82
00:04:33,394 --> 00:04:37,411
There was a well publicized
Bitcoin theft a few years ago.

83
00:04:37,411 --> 00:04:42,166
And what they wanted to do, the authors
of this paper decided to see how this

84
00:04:42,166 --> 00:04:47,160
thief has been moving Bitcoins around
between multiple addresses of his own.

85
00:04:47,160 --> 00:04:49,297
And so this is that paper in question.

86
00:04:49,297 --> 00:04:52,639
It is called An Analysis of
Anonymity in the Bitcoin System.

87
00:04:52,639 --> 00:04:57,542
So this is one of the first major research
efforts that did what we call transaction

88
00:04:57,542 --> 00:04:58,619
graph analysis.

89
00:04:58,619 --> 00:05:01,917
So you can use the techniques that
I showed you in previous slides.

90
00:05:01,917 --> 00:05:07,267
And you can draw a lot of these pretty
graphs, and deduce that this represents

91
00:05:07,267 --> 00:05:12,053
the thief moving money around
between his own different addresses.

92
00:05:12,053 --> 00:05:15,873
This is the thief sending money to someone
else, and various things like that.

93
00:05:15,873 --> 00:05:20,202
I haven't yet shown you anything that
allows you to link any of these clusters

94
00:05:20,202 --> 00:05:23,940
to real world identity, but
let's defer that question for a bit.

95
00:05:25,270 --> 00:05:30,030
Let's defer that question and go back to
the scenario of Alice and the teapot.

96
00:05:30,030 --> 00:05:31,200
So let's look at it again,

97
00:05:31,200 --> 00:05:36,190
maybe the teapot has gone up in
price to 8.5 centibit coins.

98
00:05:36,190 --> 00:05:38,290
So what is Alice going to do now?

99
00:05:38,290 --> 00:05:43,610
She can't combine any subset of her
transactions or her addresses to produce

100
00:05:43,610 --> 00:05:46,550
the exact amount of change necessary for
purchasing this teapot.

101
00:05:47,790 --> 00:05:51,020
So instead, what she's going to do is
exploit the fact that transactions can

102
00:05:51,020 --> 00:05:53,320
have any number of inputs and outputs, and

103
00:05:53,320 --> 00:05:56,110
create a single transaction
that looks like this.

104
00:05:56,110 --> 00:06:00,526
It combines these two inputs to produce
this output that goes over here, and

105
00:06:00,526 --> 00:06:04,400
another output that goes to
an address that she, herself, owns.

106
00:06:04,400 --> 00:06:08,219
And this is called a change address,
which you saw in a previous lecture.

107
00:06:08,219 --> 00:06:13,200
This presents a conundrum for
an adversary who's looking at this.

108
00:06:13,200 --> 00:06:17,350
The adversary might be able to deduce that
these addresses belong to the same user.

109
00:06:17,350 --> 00:06:21,879
He might suspect that one of these
addresses also belongs to that same user,

110
00:06:21,879 --> 00:06:24,447
but has no way of knowing
which one that is.

111
00:06:24,447 --> 00:06:27,895
In this particular example, the change
address is the small amount, but

112
00:06:27,895 --> 00:06:29,684
it doesn't have to be that way at all.

113
00:06:29,684 --> 00:06:33,180
Alice might own an address
that has 10,000 Bitcoins, and

114
00:06:33,180 --> 00:06:35,510
might spend a little bit on the teapot,
and

115
00:06:35,510 --> 00:06:39,540
might send the most of the rest of it
back to her and her own change address.

116
00:06:40,640 --> 00:06:44,614
And these transaction outputs don't
have any particular ordering in

117
00:06:44,614 --> 00:06:45,631
the block chain.

118
00:06:45,631 --> 00:06:47,500
That order is not meaningful at all.

119
00:06:47,500 --> 00:06:49,674
So, it's not clear what
the adversary might do.

120
00:06:49,674 --> 00:06:54,139
It's not clear how the adversary might
determine which address has changed in

121
00:06:54,139 --> 00:06:55,975
a multi-output transaction.

122
00:06:55,975 --> 00:06:58,459
So what is the adversary to do?

123
00:06:58,459 --> 00:07:00,910
There's another pretty cool technique for
this,

124
00:07:00,910 --> 00:07:03,591
again from a research paper
which I'll tell you about.

125
00:07:03,591 --> 00:07:07,417
But the technique is this,
the authors call this idioms of use, and

126
00:07:07,417 --> 00:07:11,392
they exploit idiosyncratic features
of different wallet software.

127
00:07:11,392 --> 00:07:16,202
For example, one thing they found
is that most wallet software

128
00:07:16,202 --> 00:07:20,180
use an address as a change
address only once.

129
00:07:20,180 --> 00:07:22,560
That means that this, in fact,

130
00:07:22,560 --> 00:07:27,080
seems to sort of follow Bitcoin best
practice for anonymity, in a sense.

131
00:07:27,080 --> 00:07:30,876
If you have a new transaction where you
need to create a new change address,

132
00:07:30,876 --> 00:07:34,743
don't use an address that you've already
used before as a change address.

133
00:07:34,743 --> 00:07:38,399
Create a new address and
use it for this purpose, right.

134
00:07:38,399 --> 00:07:44,450
Now, not all addresses that are outputs
of transactions might have this property.

135
00:07:44,450 --> 00:07:46,740
Going back to the example
of the big box store,

136
00:07:46,740 --> 00:07:50,324
the store might advertise a long term
address in which it wants to receive

137
00:07:50,324 --> 00:07:54,107
Bitcoins instead of receiving Bitcoins
at a different address every time.

138
00:07:54,107 --> 00:07:59,057
So not every non-change address has
this property that is used only once as

139
00:07:59,057 --> 00:08:03,710
a change address, but every change
address does have that property.

140
00:08:04,850 --> 00:08:07,330
So they used this and
they found that it does work pretty well.

141
00:08:08,500 --> 00:08:11,059
On the other hand,
this has some limitations.

142
00:08:11,059 --> 00:08:14,298
It just happens to be
a feature of wallet software.

143
00:08:14,298 --> 00:08:19,271
And so there are a lot of false positives
that might creep into these clustering

144
00:08:19,271 --> 00:08:22,296
techniques, if you use
techniques like this.

145
00:08:22,296 --> 00:08:25,293
So it required a lot of
manual intervention.

146
00:08:25,293 --> 00:08:29,697
Nevertheless, they were able to use
the technique that I showed you before,

147
00:08:29,697 --> 00:08:34,033
which is clustering shared inputs
together, as well as a few heuristics for

148
00:08:34,033 --> 00:08:35,680
change address detection.

149
00:08:36,700 --> 00:08:40,929
And then, what they were able to do is
they were able to look at the entire

150
00:08:40,929 --> 00:08:45,791
Bitcoin transaction graph and create some
giant clusters that they hypothesized

151
00:08:45,791 --> 00:08:48,548
belongs to various major
service providers.

152
00:08:48,548 --> 00:08:52,821
And here's what that graph looks like
after applying these two heuristics.

153
00:08:52,821 --> 00:08:57,215
And this is the paper in question,
this is by Sarah Meiklejohn and others,

154
00:08:57,215 --> 00:08:59,679
as a whole bunch of authors of this paper.

155
00:09:01,300 --> 00:09:03,620
This graph looks very interesting here.

156
00:09:03,620 --> 00:09:06,190
The sizes of these circles represent

157
00:09:06,190 --> 00:09:09,440
the amount of money flowing
into those clusters, and

158
00:09:09,440 --> 00:09:14,040
the number of edges going out of a cluster
represent the number of transactions.

159
00:09:14,040 --> 00:09:17,460
Let's try to just stare at this for
a second and see if we can guess what some

160
00:09:17,460 --> 00:09:21,040
of these major service providers and
other clusters of nodes might be.

161
00:09:22,720 --> 00:09:27,625
This huge one here that dominates in
transaction volume compared to any other

162
00:09:27,625 --> 00:09:28,307
cluster.

163
00:09:28,307 --> 00:09:32,725
Given that this paper was written in 2013,
we might guess that it's Meiklejohn's,

164
00:09:32,725 --> 00:09:36,170
which was a very prominent exchange
at the time that later went under.

165
00:09:37,470 --> 00:09:41,518
Now we might also guess that this little
one here, that only has a little bit of

166
00:09:41,518 --> 00:09:45,629
transaction volume, in spite of having
a very large number of transactions,

167
00:09:45,629 --> 00:09:49,830
sort of corresponds to the profile of
the gambling service, Satoshi Dice.

168
00:09:49,830 --> 00:09:53,526
Because the way that it works is
you send a tiny amount of Bitcoins,

169
00:09:53,526 --> 00:09:56,174
and you either win that bet or
you lose that bet.

170
00:09:56,174 --> 00:09:59,471
And so, you might get double
the Bitcoin or none of the Bitcoins.

171
00:09:59,471 --> 00:10:02,070
So that's the gambling
service Satoshi Dice.

172
00:10:02,070 --> 00:10:06,080
We might guess that it's this one here, we
might guess that it's Mt Gox, and so on.

173
00:10:06,080 --> 00:10:08,460
But this kind of guessing is sub-optimal.

174
00:10:08,460 --> 00:10:12,880
The authors wanted some sort of reliable
way of identifying what are the service

175
00:10:12,880 --> 00:10:15,370
providers corresponding to
each of these clusters?

176
00:10:16,520 --> 00:10:17,460
How did they do that?

177
00:10:17,460 --> 00:10:21,840
Well, one idea you might have is you might
think, oh, why not just go to the Mt Gox

178
00:10:21,840 --> 00:10:25,720
website and see what address they
advertised for receiving Bitcoins?

179
00:10:25,720 --> 00:10:30,153
Well, that doesn't quite work because
they're going to advertise a new address

180
00:10:30,153 --> 00:10:31,899
for every single transaction.

181
00:10:31,899 --> 00:10:34,313
And if you just go to the website,
look at the address, and

182
00:10:34,313 --> 00:10:37,618
actually don't complete that transaction,
you don't send Bitcoins there,

183
00:10:37,618 --> 00:10:40,130
then they're simply going
to discard that address.

184
00:10:40,130 --> 00:10:42,403
They're not going to reuse that
address for another customer.

185
00:10:42,403 --> 00:10:44,586
In other words,
that address will never get used.

186
00:10:44,586 --> 00:10:46,547
You simply won't find
it in the block chain.

187
00:10:46,547 --> 00:10:49,120
So what's the way around this?

188
00:10:49,120 --> 00:10:54,470
Well, the only way to reliably
infer addresses that are associated

189
00:10:54,470 --> 00:10:58,360
with a service provider is to actually
transact with that service provider,

190
00:10:58,360 --> 00:11:00,360
which is exactly what the authors did.

191
00:11:00,360 --> 00:11:03,210
They went ahead and
bought a variety of things and

192
00:11:03,210 --> 00:11:07,770
interacted in a variety of other ways
with a bunch of service providers,

193
00:11:07,770 --> 00:11:10,770
comprising 344 transactions in all.

194
00:11:10,770 --> 00:11:15,370
Mining pools, wallet services, exchanges,
various merchants, even gambling sites,

195
00:11:15,370 --> 00:11:15,916
and so on.

196
00:11:15,916 --> 00:11:19,121
And they got a bunch of cool
things to show for their efforts.

197
00:11:19,121 --> 00:11:22,760
And Meiklejohn informs me that,
in fact, the cupcakes were really good.

198
00:11:24,650 --> 00:11:28,611
At any rate, the authors use this
very clever technique to go ahead and

199
00:11:28,611 --> 00:11:32,990
label the major clusters in the graph
that I showed you on the previous slide.

200
00:11:32,990 --> 00:11:35,464
And so,
this is what the labeled graph looks like.

201
00:11:35,464 --> 00:11:37,948
Now, in fact, this was Mt Gox,
as we might have guessed.

202
00:11:37,948 --> 00:11:39,283
This was Satoshi Dice.

203
00:11:39,283 --> 00:11:42,120
But a lot of the others would have
been very difficult to guess.

204
00:11:42,120 --> 00:11:44,540
And by actually transacting
with these services,

205
00:11:44,540 --> 00:11:47,300
they were able to identify most
of these service providers.

206
00:11:48,810 --> 00:11:53,980
So already now, we've seen something
pretty interesting beyond just clustering

207
00:11:53,980 --> 00:11:55,860
and being able to put
labels on the clusters.

208
00:11:56,990 --> 00:11:59,910
So the next question is,
sure you can do these labels for

209
00:11:59,910 --> 00:12:03,330
these major service providers,
can you put labels for individuals?

210
00:12:03,330 --> 00:12:04,390
In other words,

211
00:12:04,390 --> 00:12:10,020
connect little clusters corresponding to
individuals to their real life identities.

212
00:12:10,020 --> 00:12:13,234
Well, there's at least a couple of
different ways in which that can happen.

213
00:12:13,234 --> 00:12:16,415
One is, intuitively,
what I told you right at the beginning.

214
00:12:16,415 --> 00:12:20,197
You could simply interact at a coffee
shop, or with some other merchant, so

215
00:12:20,197 --> 00:12:23,861
they learn some transaction or
some address that corresponds to you, and

216
00:12:23,861 --> 00:12:25,890
they might use that to tag your cluster.

217
00:12:27,160 --> 00:12:30,780
There are at least a couple of other
ways in which this might happen.

218
00:12:30,780 --> 00:12:35,435
And one is that there's high
centralization in the service providers.

219
00:12:35,435 --> 00:12:40,094
So the intuition here is that most users,
in the course of normal usage of Bitcoin

220
00:12:40,094 --> 00:12:44,342
over a period of months or years,
are going to interact with at least one of

221
00:12:44,342 --> 00:12:48,550
those major service providers that
were labeled in the previous graph.

222
00:12:49,840 --> 00:12:54,538
So, if somebody wants to identify
a cluster corresponding to a particular

223
00:12:54,538 --> 00:12:59,310
user, there's a very high chance that
they're going to be able to identify

224
00:12:59,310 --> 00:13:03,580
a transaction that ties that cluster
with a known labeled cluster.

225
00:13:03,580 --> 00:13:05,870
And then,
they can go to that service provider, and

226
00:13:05,870 --> 00:13:09,204
if they have the appropriate authority,
subpoena that service provider,

227
00:13:09,204 --> 00:13:12,560
or if they're a hacker, try to hack
into that service provider, and so on.

228
00:13:12,560 --> 00:13:17,421
This is one major avenue in which regular
users can get de-anonymized because

229
00:13:17,421 --> 00:13:21,470
they eventually, inevitably
interact with one of these major,

230
00:13:21,470 --> 00:13:23,987
easily identified service providers.

231
00:13:23,987 --> 00:13:26,842
Another one is simply carelessness.

232
00:13:26,842 --> 00:13:33,041
A lot of users end up posting
address information in forums.

233
00:13:33,041 --> 00:13:37,816
They might post one of the Bitcoin
addresses that they own, for example,

234
00:13:37,816 --> 00:13:42,063
to receive donations when they're
posting comments on forums.

235
00:13:42,063 --> 00:13:46,903
Now that might be because these users are
not worried about getting de-anonymized.

236
00:13:46,903 --> 00:13:50,308
It could also be because they
don't realize that posting one of

237
00:13:50,308 --> 00:13:53,649
their addresses is almost going
to inevitably allow somebody

238
00:13:53,649 --> 00:13:56,683
to connect all of their
different addresses together.

239
00:13:56,683 --> 00:14:00,840
Okay, so hopefully, I've convinced
you that there are clever ways that

240
00:14:00,840 --> 00:14:05,132
an attacker might utilize, in order to
not only link different addresses or

241
00:14:05,132 --> 00:14:09,518
transactions belonging to a user, but
go from there to real world identity.

242
00:14:09,518 --> 00:14:14,260
And our experience, our history of
these de-anonymization algorithms shows

243
00:14:14,260 --> 00:14:19,212
that they only get more powerful with time
and more auxiliary information as we call

244
00:14:19,212 --> 00:14:24,188
it for attackers to utilize in order to
link together to get to users' identities.

245
00:14:24,188 --> 00:14:27,124
So this is something to worry
about if you care about privacy.

246
00:14:27,124 --> 00:14:30,812
Before we look at how to make
things better for anonymity,

247
00:14:30,812 --> 00:14:36,050
let's look at a completely different way
in which users can get de-anonymized.

248
00:14:36,050 --> 00:14:40,810
So far, what we've looked at is all based
on what is available to the attacker

249
00:14:40,810 --> 00:14:45,200
in the block chain, right, the part that
is permanently and publicly recorded.

250
00:14:45,200 --> 00:14:47,883
But recall that that's not
the only part of Bitcoin.

251
00:14:47,883 --> 00:14:51,309
There's also a peer-to-peer
network in which a lot of messages

252
00:14:51,309 --> 00:14:55,869
are sent around that don't necessarily get
permanently recorded in the block chain.

253
00:14:55,869 --> 00:14:58,548
So the block chain,
in networking terminology,

254
00:14:58,548 --> 00:15:00,408
is called the application layer.

255
00:15:00,408 --> 00:15:03,764
And the peer-to-peer network is,
of course, the networking layer.

256
00:15:03,764 --> 00:15:07,286
And so, de-anonymization can happen
at this totally different layer,

257
00:15:07,286 --> 00:15:08,548
at the networking layer.

258
00:15:08,548 --> 00:15:10,450
Well, how could that happen?

259
00:15:10,450 --> 00:15:11,620
Here is an example.

260
00:15:11,620 --> 00:15:17,469
This was first pointed out by Dan Kaminsky
a few years ago, in a talk at Black Hat.

261
00:15:17,469 --> 00:15:19,141
Here's the peer-to-peer network.

262
00:15:19,141 --> 00:15:23,199
What he noticed is that when
a node creates a transaction and

263
00:15:23,199 --> 00:15:28,148
wants to broadcast it, it's going to
connect to a lot of nodes at once and

264
00:15:28,148 --> 00:15:30,274
broadcast that transaction.

265
00:15:30,274 --> 00:15:34,698
And so, if a few nodes on the network put
their heads together, they can figure out

266
00:15:34,698 --> 00:15:38,609
that, hey, this new transaction,
this is the first we heard of it, and

267
00:15:38,609 --> 00:15:42,180
all of us first heard of it
from this particular node.

268
00:15:42,180 --> 00:15:43,070
So this must be the node.

269
00:15:43,070 --> 00:15:48,460
This must be the IP address corresponding
to the user who created this transaction.

270
00:15:48,460 --> 00:15:55,700
So here you have a linkage not between a
transaction or a cluster and a real world

271
00:15:55,700 --> 00:16:01,430
identity, instead, you have a linkage
between a transaction and IP address.

272
00:16:01,430 --> 00:16:01,980
And of course,

273
00:16:01,980 --> 00:16:05,250
IP address is something that's very
close to your real world identity.

274
00:16:05,250 --> 00:16:09,226
There are a lot of ways to go from there
to the next level of finding identity.

275
00:16:09,226 --> 00:16:11,304
So this is already a serious problem.

276
00:16:11,304 --> 00:16:17,364
Luckily though,
this is not a very hard problem to solve.

277
00:16:17,364 --> 00:16:18,363
Why?

278
00:16:18,363 --> 00:16:22,008
Because this is now a problem
of communications anonymity.

279
00:16:22,008 --> 00:16:26,566
And communicating anonymously is a problem
that has received a lot of attention from

280
00:16:26,566 --> 00:16:27,988
the research community.

281
00:16:27,988 --> 00:16:30,618
And as we already saw in the introduction,

282
00:16:30,618 --> 00:16:35,670
there is a good system called Tor that you
can use for communicating anonymously.

283
00:16:37,290 --> 00:16:39,070
Now there's one little caveat.

284
00:16:39,070 --> 00:16:42,390
Tor is intended for what is called
low-latency activities such as web

285
00:16:42,390 --> 00:16:46,990
browsing, where there is a large
volume of flow, and you don't want to

286
00:16:46,990 --> 00:16:50,550
sit around waiting for too long, and
you get the response immediately.

287
00:16:50,550 --> 00:16:55,170
So it makes some compromises in anonymity
in order to achieve low-latency.

288
00:16:55,170 --> 00:16:58,320
Bitcoin is inherently
a high-latency system, right.

289
00:16:58,320 --> 00:17:02,037
Because it takes awhile for transactions
to propagate through the network, and

290
00:17:02,037 --> 00:17:04,386
especially to get confirmed
in the block chain, so

291
00:17:04,386 --> 00:17:06,587
we don't have this low-
latency constraint.

292
00:17:06,587 --> 00:17:10,185
So it's possible that we could
come up with a more specific,

293
00:17:10,185 --> 00:17:14,417
fine tuned sort of anonymity network for
this particular purpose, and

294
00:17:14,417 --> 00:17:17,500
there are such things called mixed nets.

295
00:17:17,500 --> 00:17:21,710
The only problem is that Tor is a system
that's most widely deployed, and

296
00:17:21,710 --> 00:17:24,170
analyzed, and robust,
and functional today.

297
00:17:25,290 --> 00:17:28,631
But it's possible that somebody might
develop a mixed net solution for

298
00:17:28,631 --> 00:17:30,756
anonymizing your Bitcoin communications.

299
00:17:30,756 --> 00:17:34,737
And if that happens,
that would be something to switch to.

300
00:17:34,737 --> 00:17:37,770
So let's summarize what we've learned so
far.

301
00:17:38,990 --> 00:17:42,780
We've seen that based on the information
in the block chain, different addresses

302
00:17:42,780 --> 00:17:45,410
could get linked together,
could also get linked to identity.

303
00:17:45,410 --> 00:17:49,030
We've also seen that based on
the information at the network layer,

304
00:17:49,030 --> 00:17:52,970
a transaction or
address could get linked your IP address.

305
00:17:52,970 --> 00:17:55,130
Luckily, this latter
problem is simple to solve.

306
00:17:55,130 --> 00:17:58,596
If you care about your anonymity and
privacy when using Bitcoin,

307
00:17:58,596 --> 00:18:00,622
it's a good idea to do it through Tor.

308
00:18:00,622 --> 00:18:02,914
But the former problem is much trickier,
and

309
00:18:02,914 --> 00:18:06,728
that's what we're going to spend
the rest of this lecture talking about.

