4 ms·
> These statements directly contradict each other. They don't contradict each other at all. > Once block 26 comes online, block 6 is a permanent feature of th
by speakeron 8y ago
> These statements directly contradict each other.
They don't contradict each other at all.
> Once block 26 comes online, block 6 is a permanent feature of the blockchain.
What defines the 'blockchain'? It's the chain with the most work. Outside of a centralized checkpointing mechanism, the only definition of the valid blockchain is the one with the most work behind it.
- thaumasiotes 8y ago>> These statements directly contradict each other. > They don't contradict each other at all. They do; for a transaction to be revocable means you haven't accepted that it went through. If every block is revocable indefinitely, then you can't say that 20 confirmations confirm a block, because they don't. > What defines the 'blockchain'? It's the chain with the most work. No, it's the chain accepted by a group of miners. Miners are the sole authority of a bitcoin-style blockchain. Work is not. > Outside of a centralized checkpointing mechanism, the only definition of the valid blockchain is the one with the most work behind it. Centralization is not necessary for this. As a miner, you're free, in your individual capacity, to reject blockchain candidates that invalidate blocks you consider permanent. Centralization would mean that a block could require only 0 following blocks before being considered permanent. With a consensus of decentralized, less-than-perfectly-synchronized miners, you'd want a fuzzier boundary -- which is what "wait for 20 following transactions" provides.
- askmike 8y ago> They do; for a transaction to be revocable means you haven't accepted that it went through. If every block is revocable indefinitely, then you can't say that 20 confirmations confirm a block, because they don't. From the blockchain perspective a block with a confirmation is confirmed. But everyone else can make new rules on top regarding payments: Do you consider most crypto exchanges to not support "Bitcoin" since they require 6 confirmations per transaction before they credit it? > With a consensus of decentralized, less-than-perfectly-synchronized miners, you'd want a fuzzier boundary -- which is what "wait for 20 following transactions" provides. This is done to raise the cost of reversing the transaction (the more confirmations deep, the more expensive your attack needs to be).
- thaumasiotes 8y ago>> With a consensus of decentralized, less-than-perfectly-synchronized miners, you'd want a fuzzier boundary -- which is what "wait for 20 following transactions" provides. > This is done to raise the cost of reversing the transaction (the more confirmations deep, the more expensive your attack needs to be). No, it isn't done at all. You state as much: > From the blockchain perspective a block with a confirmation is confirmed. As far as I can see, this is just a design mistake. (And equivocating over the meaning of "confirmed".) The current system never treats any block as confirmed. The only statuses a block can have are "invalid" and "provisionally accepted". There is no "accepted" status, and a valid block may be revoked at any time, no matter how long it may have been valid for. But there's also no reason not to have an "accepted" status, and to reject candidate blockchains which alter accepted blocks. This should be part of the mining protocol. Treating it as non-binding advice to merchants misses the point.
- Robin_Message 8y agoSo, I just ran through the same thought process and the problem is this: How does a new entrant to the network know which is the valid chain? They didn't see the previous 20 confirmations, so the only rule they can use is picking the longest chain. Another way to do it is to have a separate voting system to attest to the "valid" chain, but then you could use an ordinary botnet to outvote the real chain. In short, confirmations are there for vendors to be sure a few blocks weren't mined at the same time, but they do nothing against a 51% attack.
- thaumasiotes 8y agoI don't follow this. A new entrant to the network knows which is the valid chain because the chain the network uses defines "the network". Consider the case[1] of Ethereum Classic (ETC) versus Ethereum (ETH). They are exactly the same, except for the chain each group of miners follows. The ETC blockchain is a valid ETH blockchain and the ETH blockchain is a valid ETC blockchain, but miners adhere to one or the other for political reasons. As a new entrant to the ETC network, how do you know which blockchain to use? Well, you use the ETC blockchain, because that's the network you're entering. [1] I'm describing my understanding of the ETH/ETC split. If they've diverged more than I was aware of, that doesn't affect the argument; just substitute other names for ETH and ETC.
- nearbuy 8y agoI don't follow. Even if the current group of miners decided older blocks are irrevocable, if there was a prolonged 51% attack, it would mean the majority of miners would be saying, "Hey, those confirmed blocks... that's not what actually happened. Look, here's the real history, with the real confirmed blocks." And then everyone else on the network would say, "Crap, who should we believe? Let's go with the majority." And the attack would win.