4 ms·
100% correct, but bitcoin isn't centralized because of PoW, more because of a bad implementation of PoW that was too soon and too easily optimized (if you had t
by deft 8y ago
100% correct, but bitcoin isn't centralized because of PoW, more because of a bad implementation of PoW that was too soon and too easily optimized (if you had the cash). Existing algos will all be eaten in the same way SHA256 was, but why does that mean PoW as a concept is a failure?
- Animats 8y agobecause of a bad implementation of PoW See yesterday's YC article from a cryptocoin ASIC designer.[1] It's possible to design an ASIC for any proof of work algorithm that will be more cost-effective than a general purpose CPU. Monero was supposed to be resistant to special-purpose ASIC approaches. It isn't. Someone quietly built an ASIC for Monero about a year ago and made a ton of money. [1] https://news.ycombinator.com/item?id=17059858 https://news.ycombinator.com/item?id=17059858
- deft 8y agoI know. A flexible ASIC is a GPU. Optimized hardware will always be more cost effective, but like I said elsewhere in the thread, algos that are hard(er) to optimize than even cryptonight are being worked on. People didn't notice monero had asics because no one was paying attention. Looking back on the hashrate graphs and price make it very clear. Monero has since forked and removed the ASIC threat temporarily, and they will continue to fork to keep them at bay. Anti-ASIC is a cat and mouse game where the coin developers have the upperhand at all times. Do you really believe there's no conceivable algorithm that will reduce the cost-effective difference between general purpose and specialized hardware? The goal isn't to prevent someone from optimizing, it's to prevent the difference from being so large that no one else can compete. Monero managed to do that for years, and that was using an algo that claimed ASIC resistance solely on memory prices.
- foxhill 8y agoof course, specialised hardware will always outperform general purpose hardware. all that is indicative of is the question you’re trying to ask in malformed. suppose, for instance, you could parameterise a merkle-damgard construction, such that a fixed physical network for calculating hashes could not exist (of course, there are many avenues of pitfalls with that suggestion, my gut tells me they are soluable). something that could be calculated from previous block values, somehow. now you have an ever changing hash function that lives for 10 minutes, requires strictly general purpose hardware to operate, and would solve (one of the) issues i identified in my opening reply.
- foxhill 8y agosorry, i wasn’t clear there - for reference, i don’t believe PoW as a concept is a failure. only this current implementation focused on SHA256. the reason for this is because, unlike bitcoin’s beginning, one bitcoin network participant is no longer comparable to an equal share of the resources required to reach consensus on the network.