3 ms·
> If there’s a reward for computing a VDF faster than everyone else There's no direct reward for being a bit faster than everyone else. If you are much faster
by justindrake 7y ago
> If there’s a reward for computing a VDF faster than everyone else
There's no direct reward for being a bit faster than everyone else. If you are much faster (say, 100x faster than the general public) then you may be able to bias the randomness, and therefore manipulate things like lotteries built on Ethereum.
> The article claims that proof of work is costing Ethereum hundreds of millions of dollars per year, but this VDF competition is also wasting millions of dollars in human capital
It's about orders of magnitude. Ethereum burns about $0.5B per year. The VDF project is about $15m, and the ASIC should last about 10 years.
- nnnnn11111 7y agoFrom what you’re saying it seems like an “incentive cliff” at 100x the power of whatever the competition produces is being relied upon for the security of the currency, meaning there exists a strong incentive for someone to waste human capital computing a faster VDF if he thinks he can “hurdle” the incentive cliff of 100x the power of whatever the competition produces. Given the competition is only a ~$15m investment in a group of hobbyists, and given we’ve already seen order of magnitude improvements over and over again with proof of work in Bitcoin once the incentives are there, why is it assumed that someone won’t mount a long range attack to break the system by engineering a 100x faster VDF? Moreover, how does the system recover if that were to happen?
- topmonk 7y agoThere is quite a difference between a steady stream of income, and some far off reward which you may or may not be able to achieve. Nearly anyone can do the former, but only a few have the luxury to attempt the latter.
- nnnnn11111 7y agoModern asic farms require a lot of up-front investment in developing hardware. All it takes is for one person to think he can hurdle the cliff and he can raise a lot of money to do it if the reward is there, not unlike the first group of people to raise funds to develop ASICS for Bitcoin (which were orders of magnitude faster than the hardware available at the time). We know Bitcoin can cope with a 100x more powerful asic coming online— can these systems cope with a 100x more powerful VDF?
- justindrake 7y ago> how does the system recover if that were to happen? The Ethereum 2.0 consensus layer gracefully falls back to a slightly biasable form of randomness called RANDAO. This is merely a "weakening" of the consensus, not a breakage. Applications built on Ethereum 2.0 (such as lotteries) may indeed break with RANDAO biasability. > why is it assumed that someone won’t mount a long range attack to break the system by engineering a 100x faster VDF? One of the things we are doing is trying to prove lower bounds on the circuit depth of modular squaring. (Ryan Williams is working on such lower bounds right now.) On the hardware engineering front, getting a 100x speedup is extremely difficult. Improvements to sequential speeds in traditional ASICs has tapered off at around 5% per year (see for example https://github.com/preshing/analyze-spec-benchmarks https://github.com/preshing/analyze-spec-benchmarks). And if possible, being able to increase the speed of multiplication by 100x would be an amazing development for humanity (multiplication is arguably the key basic operation in computing). > Given the competition is only a ~$15m investment in a group of hobbyists We can afford a few experts with $15m :) > we’ve already seen order of magnitude improvements over and over again with proof of work in Bitcoin Keep in mind that Bitcoin is an energy consumption game, not a latency game. Latency improvements do not follow Moore's law and other related laws.