Bitcoin is still relying on SHA-256, but that's a gamble with quantum threats looming. If quantum computers get serious, we gotta think about upgrading our consensus mechanism to keep it safe long-term.
Should Bitcoin Move Beyond SHA-256 to Quantum-Resistant Algorithms?
20 replies 139 views
viper_bridgeMember
Posts: 9 · Reputation: 237
#2Sep 8, 2021, 06:45 AM
Yeah, I read some stuff about quantum-resistant options like SHA-3 and BLAKE3. But honestly, aren't they just as vulnerable to quantum attacks as SHA-256?
CryptoRocketNewbie
Posts: 66 · Reputation: 24
#3Sep 9, 2021, 05:44 AM
All those hashes can be hit by Grover's algorithm. Just gotta accept that even BLAKE3 isn't immune to quantum stuff.
notyourkeysNewbie
Posts: 75 · Reputation: 12
#4Sep 9, 2021, 12:03 PM
What are the actual attack scenarios for Bitcoin's Proof of Work with quantum computing? I need clarity here.
k1ng_blockNewbie
Posts: 58 · Reputation: 6
#5Sep 9, 2021, 02:45 PM
Same question here. I’m not too worried about quantum attacks since there’s no solid evidence of them happening yet. Would be nice to hear about any real risks though.
Quick side note... if a state actor somehow got 51% of the hashing power, could we fork away from them without changing the mining rules? What do you think?
CryptoRocketNewbie
Posts: 66 · Reputation: 24
#7Sep 10, 2021, 07:11 AM
Yeah, I think you could soft-fork to invalid blocks from those attackers. But it’s tricky and could backfire if not done right. Look at what happened with BCH.
AtomicLordMember
Posts: 14 · Reputation: 184
#8Sep 10, 2021, 08:50 AM
For sure, quantum computers would have to compete with ASICs, which are way faster than classical computers. So, they might not be a huge threat just yet.
Sounds like a hard fork situation if we’re rejecting blocks that were valid before. But how's that not a version change?
viper_bridgeMember
Posts: 9 · Reputation: 237
#10Sep 11, 2021, 10:07 PM
Yeah, like with Segwit and Taproot, right? Those changes allowed certain transactions that were valid before to become invalid after the fork. So how do we classify that?
fork_vaultMember
Posts: 11 · Reputation: 223
#11Sep 13, 2021, 01:43 AM
You’re mixing up hard forks with what we call consensus changes. Soft forks need hashpower, hard forks can survive on less.
k1ng_blockNewbie
Posts: 58 · Reputation: 6
#12Sep 13, 2021, 04:12 AM
And to be clear, keccak is not the same as SHA-3. Just saying.
Let’s say a group got 51% power. Could we hard fork them out without changing the mining algorithm? That’s the real issue.
k1ng_blockNewbie
Posts: 58 · Reputation: 6
#14Sep 15, 2021, 04:52 AM
Best way to learn is to run some local nodes and test it out. You can see how various versions react in different scenarios.
I’m curious. If there’s no need for a hard fork or mining algorithm change, that would simplify defending against any attack, right?
Defending against a bad soft fork is actually harder than a bad hard fork. With soft forks, once accepted, it’s hard to go back.
Not to mention, a quantum miner could outperform ASICs, leading to crazy centralization and potential attacks.
Imagine someone builds a quantum nonce generator. If they made it work, would you use it to mine Bitcoin? Morally, would that feel right?
Why not try it out? Testing new ideas is just part of it. But it depends on what kind of advantage it gives.
eric.tokenNewbie
Posts: 1 · Reputation: 1
#20Sep 19, 2021, 03:54 AM
Great convo. If you could mine $40 million worth of Bitcoin using that tech, and then fix the network later, wouldn't you just do it?