3 ms·
>An honest mining majority is a hard requirement of Bitcoin. But proof-of-stake doesn't solve the problem of collusion -- it's even more susceptible to it since
by peercoin 9y ago
>An honest mining majority is a hard requirement of Bitcoin. But proof-of-stake doesn't solve the problem of collusion -- it's even more susceptible to it since it's so easy to recreate valid-looking chains. With Bitcoin, two or more competing chains will at least be visible (two distinct chains with a lot of work), whereas they're everywhere in PoS and the main chain is qualitatively no different from any other valid chain (of which we can create thousands quickly).
I'm not sure what math you are using to base this assumption on. A formal argument by algorand is that the probability of a fork would be the age of the universe. It is NOT straightforward or cheap to recreate valid looking chains and generate the next block creating a fork.
https://arxiv.org/pdf/1607.01341.pdf https://arxiv.org/pdf/1607.01341.pdf
- runeks 9y agoA fork is not just created by the next block, but can be created by rewriting any number of blocks (including from the very beginning, which must be valid or it wouldn't be possible to begin a chain). Starting a new chain from scratch -- with all valid blocks -- is easy with PoS, and it would look no different from the right, valid chain. Again, the challenge is to come to agreement on the correct history, not just any valid chain. The inherent problem is that any valid chain of blocks can be produced quickly (just start from scratch), and there's no way to know you have the right chain except through majority vote, since there's nothing qualitatively separarating all the valid chains. PoS seems simple if we assume that everyone will gladly stay on the same old chain, and only accept blocks that extend this, rather than attempt to get a new chain accepted on which they have 10x as many coins. But why would they? Why not switch to an entirely new chain, with the coins of the wealthiest 1% assigned to the remaining addresses? Surely, the person who owned those coins will protest, but no one will hear 1% in a network where majority vote is the only solution to consensus (and the 1% would have no actual proof that the chain, on which they own 1% of coins, is the right one).
- peercoin 9y agoAt this point this is just trolling. The proof of stake you are describing is of your own invention and doesn't address how systems like Peercoin or algorand actually function. Starting from scratch with a new genesis block? Sure go ahead. Rewriting any number of blocks is not straightforward due to the use of digital signatures and the cryptographic guarantees that go along with generating and choosing who gets to sign and generate the next block.