6 ms·
I did a bunch of analysis on proof of burn, and came to the conclusion that it cannot work in practice because it relies on transactions in order to burn, which
by wildbunny 9y ago
I did a bunch of analysis on proof of burn, and came to the conclusion that it cannot work in practice because it relies on transactions in order to burn, which themselves are subject to consensus.
You can read my detailed analysis here: https://bitcointalk.org/index.php?topic=1182677.0 https://bitcointalk.org/index.php?topic=1182677.0
Cheers, Paul.
- sova 9y agoThanks! Very insightful
- barbegal 9y agoAnd the same applies to proof of stake. You need some form of external randomness to give you security. Of course many people have tried to come up with schemes where randomness can be created fairly by a group of people who don't necessarily trust each other [1]. Unfortunately all these schemes require at least half the participants to be honest so are vulnerable to trivial Sybil attacks. And the only way we know how to prevent Sybil attacks is to use proof of work or some sort of centralised system: leaving us back where we started. I am convinced it can be mathematically proven that Proof of Stake/Burn algorithms don't work (without some sort of external randomness) but I don't have the mathematical skill to produce the proof. [1] https://eprint.iacr.org/2017/216.pdf https://eprint.iacr.org/2017/216.pdf
- wildbunny 9y agoI found that proof of burn actually was exactly equivalent to proof of stake in terms of overall security. I.e. not good enough.
- timjver 9y agoDoesn't the Proof of Stake algorithm protect against Sybil attacks by trusting participants based on how much they are staking?
- ufo 9y agoThe issue is in a lower level than that. A proof of stake system will want to randomly choose who gets to mine the next block, weighted by how much everyone is staking. But making this choice depends on everyone agreeing on a source of randomness, which is what the previous posts were talking about.
- barbegal 9y agoThat might actually work but there is a lot to analyse to make sure that something is actually at stake. Firstly can dishonesty be detected and traced back to a stake holder? I'm not sure about that within specific randomness generating schemes. Secondly even if participants can be detected cheating it may still be economically advantageous for them to be dishonest if there is only a small probability that they lose their stake.
- dlubarov 9y ago> 1) Randomness (or entropy) in a p2p system is bounded by the data present in the chain. What this means is that (at the very least) an attacker can know ahead of time whether he will win the block reward, because he has all data necessary to compute the result of the random function, no matter what components he is required to use. He can then chose not to participate if he will lose. You could require miners to announce their proof of burn well in advance of the block they will use it for. Those announcements could be stored in the block chain so that the network can easily agree on when each announcement was made. If the distance in blocks between a burn announcement and the block it will be used for is less than K, the network would ignore that announcement. So if you want to predict the outcome of block N, you would have to win block N-K and all the blocks in between (or be colluding with all the winners). If K was small you could just burn more than the block reward justifies, discouraging competing miners from burning, but if K is sufficiently large (e.g. 1 month), that would be prohibitively expensive. > 2) Finney attack. It is completely trivial for an attacker to generate an infinite sequence of valid blocks in which he is the solo participant and is also the winner. I think you could come up with some rotation mechanism so that only certain accounts can participate in a certain round. It could perhaps be weighted by stake, so to participate in all rounds, one would need to control 100% of the currency (or some lower threshold could be chosen to minimize the rounds that no miners are eligible for). > 3) Making the block reward equal to the burnt amount makes this functionally equivalent to Proof of Stake for the case of the single miner. However, if you don't make the block reward at least equal to the amount burnt, it is not profitable to mine. I think you're looking at it backwards; the block reward should be chosen based on the desired inflation rate, and miners will adjust their burn amounts so that burn costs will always roughly equal block rewards. If the costs ever exceed the rewards, it will be brief; some miners will sit out until mining becomes slightly profitable again.
- barbegal 9y agoThe key is: >you could come up with some rotation mechanism so that only certain accounts can participate in a certain round which is impossible to do in a way that can't be exploited and is fair (without relying on some external source of randomness). And I advise against trying to come up with a way to do so because the internet is full of failed attempts.
- runeks 9y agoThe problem is that the coin that is provably burned isn't scarce unless the network has reached consensus in the first place, and doing a provable burn of something non-scarce is non-sensical. Doing a provable burn on a fork of the Bitcoin chain is irrelevant, as nothing is lost, which means it requires already-existing consensus in order to be effective. It's the same with proof-of-stake: it purports to use a chain's own coin -- as opposed to energy -- as the scarce commodity that is consumed in order to reach consensus. But coins on a chain are only scarce if only one chain exists, which means proof-of-stake relies on pre-existing consensus in order to reach consensus. In general, what Bitcoin solves through proof-of-work is actually making a digital token scarce in the first place (by reaching consensus on a single, valid chain). After this, a lot of cool stuff becomes possible, but you can't make use of this cool stuff until consensus has been reached, which means you can't use it to reach consensus.