7 ms·
First, some Proof-of-Stake setup: 1. Assume we have some set of "validators" who control the global consensus process. They come to consensus on the current gl
by phlip9 8y ago
First, some Proof-of-Stake setup:
1. Assume we have some set of "validators" who control the global consensus process. They come to consensus on the current global state of the system. These validators are vaguely analogous to miners in Proof-of-Work consensus.
2. These validators have coins bonded as collateral in exchange for more voting power in the consensus process.
One key idea necessary for Proof-of-Stake is to punish Byzantine validators, i.e., those who deviate from the consensus protocol, by destroying their bonded stake. If you misbehave, then you lose some proportion of your collateral. Thus, validators have incentive for participation (from rewards and fees) and a _disincentive_ for malicious behavior.
This is in contrast to Proof-of-Work consensus, where there is no way to punish a specific miner that misbehaves--we cannot programmatically take away physical mining ASICs. Changing the Proof-of-Work function is only an absolute last resort as it unfairly punishes the other honest miners.
So what constitutes misbehavior? When can we confidently punish another validator? An example is when a validator publishes signed attestations for conflicting forks--an example of equivocation. When presented with signed evidence of equivocation, the honest majority of validators can agree to punish the equivocator. This punishment system solves the original "nothing-at-stake" problem where a validator has no disincentive not to contribute to both sides of a fork.
On another note, the OP seems to misunderstand the fundamental consistency vs availability (in the event of a partition) trade-off that consensus algorithms must to make. Bitcoin's Proof-of-Work is more AP with probabilistic eventual consistency. In the event of a partition, the side with less mining power will make transactions unaware of the partition. When the partition heals, all transactions on the weaker side will revert, effectively double spending all transaction recipients on that side.
In contrast, many Proof-of-Stake protocols use a more traditional PBFT-style consensus process which favors consistency over availability. In the case of a partition, the weaker side will simply become unavailable (if it contains less than 1/3 of the voting power). In the event that no partition has >2/3+ of the voting power, the entire system will become unavailable. Also in contrast to PoW's eventual consistency, PBFT-style Proof-of-Stake allows for finality as soon as the validators come to consensus on the next block.
- aeternus 8y agoAs a new user in a Proof-of-Stake protocol, how do I determine which chain to follow? With PoW I can choose the 'longest' chain (chain with the most total work).
- stale2002 8y agoEasy. You'd probably pick the one with the biggest market cap. The whole point of money is that it is useful because everyone else is using it. So the one with the biggest market cap is almost certainly the one that you'd want to follow. Or you could not do that. You could instead pick a different one. There is nothing stopping you. If there are multiple networks, it would be obvious, and you can merely make up your own mind about which to follow. Interestingly enough, this also applies to POW chains. There is nothing stopping you from picking a shorter chain. But if I had to guess, I would say that almost nobody would be following the shorter one. This applies to POS coins as well. There would likely be 1 chain, that everyone is following. And this one chain would be obvious.
- CryptoPunk 8y agoThe client you download tells you, by giving you an accurate recent snapshot of the state.
- keymone 8y agoSo one has to trust distributors of the software? I mean it’s been known about PoS systems since inception, it’s just funny how it’s supporters never like to admit it.
- CryptoPunk 8y agoYes but you have to trust the distributors of the software anyway, even in PoW.
- keymone 8y agoNo you don’t. You only need to know consensus rules. You can use any software, you can build it yourself, you can order an audit, you can write software yourself. Proof of work committed to the chain that is valid according to consensus rules you know is universal and objective measure that everyone will observe equally. That’s where bitcoin’s security comes from and that’s how you can avoid to rely on trusting third parties.
- polyomino 8y agoMiners are not responsible for validating the Bitcoin blockchain. Users are responsible for validation, miners are responsible for ordering blocks. If a miner produces an invalid block, their block is not accepted by the network of users.
- DennisP 8y agoNevertheless miners have a strong incentive to validate, so they don't waste their effort on an invalid block.
- runeks 8y ago> 1. Assume we have some set of "validators" who control the global consensus process. This setup assumes there’s already consensus on a certain set of validators, but the challenge is arriving at this consensus in the first place. This is the general problem of proof-of-stake: it assumes the presence of consensus in order to arrive at consensus. This is because consensus is reached by utilizing the scarce resource that is the chain’s token, but without consensus in the first place this token isn’t scarce at all. Proof-of-work uses something external to its chain as the scarce resource that determines consensus (energy), while proof-of-stake uses something internal to its chain (the chain’s token). This means that when a PoW chain forks, the two chains have to share the external resource, while the resource is copied for PoS chain forks.
- phlip9 8y ago> This setup assumes there’s already consensus on a certain set of validators, but the challenge is arriving at this consensus in the first place. The validator set changes as people bond or unbond coins in exchange for stake. Running a fair and secure initial distribution is a somewhat orthogonal problem; perhaps you can run an open auction. Any Proof-of-Work or Proof-of-Stake systems has issues with low security in the beginning. Consider that until late ~2012 the total hashrate of the Bitcoin network was less than the hashrate of a single Antminer S9. > This is the general problem of proof-of-stake: it assumes the presence of consensus in order to arrive at consensus. This is because consensus is reached by utilizing the scarce resource that is the chain’s token, but without consensus in the first place this token isn’t scarce at all. Consensus and scarcity are tightly related. The consensus process and protocol spec are what make the token scarce, since by definition the majority agree on the token's inflation rate, supply, block reward, etc.... What happens when validators try to fork and change these parameters? They are directly incentivized to do so, yet similarly, what happens when Bitcoin miners try to change the block reward? Of course, they don't hold all the power; with sufficient cause and collaboration, users can signal a user-activated soft fork, or simply choose to follow the original unmodified fork. > Proof-of-work uses something external to its chain as the scarce resource that determines consensus (energy), while proof-of-stake uses something internal to its chain (the chain’s token). This means that when a PoW chain forks, the two chains have to share the external resource, while the resource is copied for PoS chain forks. Yes, this is called the "nothing-at-stake" problem, and it is solved by punishing validators who equivocate. This enforces scarcity of voting power across forks. The point is they can't exercise their voting power on both chains. As soon as they vote on one fork, they are committed. The validators on the other fork are incentivized to delete their stake if they vote on the other fork simultaneously.