5 ms·
> Why not move to proof of stake? >> Because it doesn't make sense. If a chain, on which a token exists, needs securing, you can't use that chain's token to se
by peercoin 9y ago
> Why not move to proof of stake?
>> Because it doesn't make sense. If a chain, on which a token exists, needs securing, you can't use that chain's token to secure itself.
I mean I'm not entirely sure what this argument is based on? In addition to existing proof of stake systems which have been running for years now, there exist several papers with rigorous formal proofs. Including Turing Award winner Silvio Micali's algorand.
Refute his paper. You will became very famous overnight.
https://arxiv.org/abs/1607.01341 https://arxiv.org/abs/1607.01341
> Mining has huge energy requirements as shown by the article.
>> Mining has no requirements at all. People just follow the best chain, and miners can sell the bitcoins they earn by extending the best chain. It's entirely voluntary.
I assume this is trolling or extreme nitpicking. Securing the network in proof of work requires that the majority of computing power is held by honest miners.
- runeks 9y ago> I mean I'm not entirely sure what this argument is based on? Proof-of-stake (PoS) doesn't solve the fundamental problem that we need to reach consensus on one, single history of transactions. All PoS does is enable us to say whether a new block is valid, but that's not important. The important part is that everyone else in the network agree that this is the new block (and not some other valid block). Valid blockchains are easy to create, the valid blockchain isn't. Defining a valid block as a function of some preceding blocks is simple. The challenge is to incentivize a decentralized network to come to complete agreement on one, single version of all people's balances. Collusion is a huge risk factor here (rewrite blockchain to assign the balance of the five most wealthiest accounts to everyone else), and PoS does nothing to mitigate that. In the worst case scenario -- where an exploit spreads through a security hole in the reference implementation, and replaces the blockchain with its own copy, silently assigning the balance of an old, rarely used account to the attacker -- PoS falls on the floor, and proves unsuitable as a base for digital money.
- peercoin 9y ago>> In the worst case scenario -- where an exploit spreads through a security hole in the reference implementation, and replaces the blockchain with its own copy, silently assigning the balance of an old, rarely used account to the attacker -- PoS falls on the floor, and proves unsuitable as a base for digital money. Replace exploit with malicious miner and it's not clear why proof of work is better than proof of stake.
- runeks 9y agoAn honest mining majority is a hard requirement of Bitcoin. But proof-of-stake doesn't solve the problem of collusion -- it's even more susceptible to it since it's so easy to recreate valid-looking chains. With Bitcoin, two or more competing chains will at least be visible (two distinct chains with a lot of work), whereas they're everywhere in PoS and the main chain is qualitatively no different from any other valid chain (of which we can create thousands quickly).
- peercoin 9y ago>An honest mining majority is a hard requirement of Bitcoin. But proof-of-stake doesn't solve the problem of collusion -- it's even more susceptible to it since it's so easy to recreate valid-looking chains. With Bitcoin, two or more competing chains will at least be visible (two distinct chains with a lot of work), whereas they're everywhere in PoS and the main chain is qualitatively no different from any other valid chain (of which we can create thousands quickly). I'm not sure what math you are using to base this assumption on. A formal argument by algorand is that the probability of a fork would be the age of the universe. It is NOT straightforward or cheap to recreate valid looking chains and generate the next block creating a fork. https://arxiv.org/pdf/1607.01341.pdf https://arxiv.org/pdf/1607.01341.pdf
- runeks 9y agoA fork is not just created by the next block, but can be created by rewriting any number of blocks (including from the very beginning, which must be valid or it wouldn't be possible to begin a chain). Starting a new chain from scratch -- with all valid blocks -- is easy with PoS, and it would look no different from the right, valid chain. Again, the challenge is to come to agreement on the correct history, not just any valid chain. The inherent problem is that any valid chain of blocks can be produced quickly (just start from scratch), and there's no way to know you have the right chain except through majority vote, since there's nothing qualitatively separarating all the valid chains. PoS seems simple if we assume that everyone will gladly stay on the same old chain, and only accept blocks that extend this, rather than attempt to get a new chain accepted on which they have 10x as many coins. But why would they? Why not switch to an entirely new chain, with the coins of the wealthiest 1% assigned to the remaining addresses? Surely, the person who owned those coins will protest, but no one will hear 1% in a network where majority vote is the only solution to consensus (and the 1% would have no actual proof that the chain, on which they own 1% of coins, is the right one).