12 ms·
IMO proof of stake is a lot less contentious than you imply. ETH2's slashing algo should make these types of attacks very hard. For the curious a simple breakd
by zionic 7y ago
IMO proof of stake is a lot less contentious than you imply. ETH2's slashing algo should make these types of attacks very hard.
For the curious a simple breakdown Ethereum 2.0's Proof of Stake (PoS) plan is:
-Minimum 32 ETH to stake
-Staking locks the currency in the staking pool
-Your node votes on the validity of the transactions (this is super light weight and fast, can run on a rPi instead of huge mining nodes).
-If the network agrees you was acting maliciously your locked stake begins to be slashed/burnt.
-Voting with the majority gives you a % of the block reward.
This means a 51% attack on the chain requires 51% of the currency staked which would be extremely hard to get without skyrocking the price (making 51% exponentially harder to achieve). They've also done some spooky proofs I don't understand that make the actual number to take over the network >51% (70% or so IIRC).
So it's green, fast, and harder to attack successfully. And unlike PoW, if you fail your "attack money" gets nuked.
- StavrosK 7y ago> And unlike PoW, if you fail your "attack money" gets nuked. To be fair, in PoW your "attack energy" (and thus money) gets nuked too.
- zaarn 7y agoYour spent attack energy is nuked. But you still have the miners and can run another attack at reduced cost (since you don't have to buy them anymore). If your money is nuked, you don't get to try again at reduced cost but at increased cost.
- StavrosK 7y agoThat's not the cost of the attack, though, any more than buying a house to put the miners in is. The cost of the attack is miner time + power (ie what you paid to rent the miners, more or less).
- zaarn 7y agoEven then, the initial cost of the miners will be a significant part of the attack's cost the first time. Any subsequent attack will then be cheaper.
- drcode 7y agoI'm a full believer in POS, but if you don't think that asking Bitcoin variants to switch their algos to POS is contentious...I don't know what to tell you.
- WorldMaker 7y agoSome of the contention is directly in your choice of words: "should" and "plan". So far no Proof of Stake system has made it into the wild. There's a lot of talk about Proof of Stake, a lot of planning, a number of "almost attempts", but still no one running it at a big scale. It's trapped in "Soon™" the way Ethereum has talked about it, for years now. That's certainly an easy form of contention when even the biggest group talking about Proof of Stake have remained slow to pull the trigger.
- Zamicol 7y ago>So far no Proof of Stake system has made it into the wild Is wrong by years. See Blackcoin (2014) for just the tip of the iceberg. https://cryptoslate.com/cryptos/proof-of-stake/ https://cryptoslate.com/cryptos/proof-of-stake/
- mythrwy 7y agoTezos isn't in the wild nor at scale?
- WorldMaker 7y agoFirst I've heard of it, so equating "wild/at scale" to include general mainstream acceptance/word of mouth (or at least the impression of such to the average HN reader such as myself), the short answer right now is, based on my personal barometer: no. I will look into it later, and decide on the longer answer if it would meet characteristics that I would ascribe to "in the wild" or "at scale" given a deeper understanding of what it has accomplished to date.
- woah 7y agoThis is completely false. PoS is securing billions of dollars on Cosmos and Tezos alone
- shifto 7y agoYes, I've been hearing these PoS stories for years now. Nothing happened besides a lot of talk.
- im3w1l 7y agoIs it possible to spread conflicting information get half people voting one way and half the other for the sole purpose of griefing their stakes?
- andrewla 7y agoThe lack of action around ETH2's move to PoS makes me somewhat skeptical of the confidence in these arrangements. Does each block need a strict majority of outstanding currency to pass muster? It seems like it would be super risky to align yourself with any stake unless you were sure that it was going to be the majority, lest you inadvertently follow a post-facto "malicious" branch. Therefore it seems like it might require less than 51% of outstanding currency, depending on the level of risk you're willing to take on, and how much active stake is willing to commit itself to proving maliciousness -- if you're leading the "that was malicious" faction but your faction fails to assemble more stake than the attacker did, then instead you get burned, so there's no guarantee that evildoers will be brought to justice; and aligning with a reorganization in ETH is dicier in many ways (because of the per-address nonce's) than it is in a UTXO coin. Attack vectors are never within the bounds of tidy proofs of complex ideas; Bitcoin's brute-force solution is very simple to verify the correctness of, and the effective cost of pulling off a double spend is fairly easy to compute from first principles with some very weak assumptions about the quality of the hash function used. I'll give more credit to proof of stake when Ethereum makes the transition; at least then there's some skin in the game.
- carlosdp 7y agoIt will actually be staked currency, not outstanding, and it's more than 51% because Eth2 is sharded (64 shards at the moment) and randomly selects committees to verify blocks, so you'd need to hold enough validators (each holding 32 ETH) to guarantee a majority in a randomly selected committee for a block. And the Eth2 genesis won't occur until a sufficiently large amount of validators are active on the beacon chain, so you can't hijack it by investing large early.
- nullc 7y ago"slashing" does nothing to address the fundamental problem. It leaves you with the same circular dependency. Step 1. Acquire crypto currency. Step 2. Stake. Step 3. unstake and sell cryptocurrency. Step 4. use older keys to produce an alternative history. Or, to simplify things, let other people do 1/2/3. Then purchase or hack their now-worthless old used keys to use in your attack... keys which they have no reason to protect and/or not sell. At most, all slashing does is makes Step 3 take more time. I say "at most" because it doesn't necessarily do that much: if the funds you can earn from the attack (from double-spends and/or shorts) are large compared to the staked amounts, then step 3 isn't even required. POS is fundamentally circular: you use ownership to determine ownership. The only solution to this is to introduce another consensus mechanism like POW or, more commonly in POS proposals, a centralized authority. Some just assume the users are communicating over a synchronous lossless global totally ordered reliable broadcast-- which, again, is equivalent to running on top of another consensus system. There is a reason you see people promoting POS that have an established history of committing fraud: the idea is most convincing if you obfscuate the details so much that no one is going to be willing to waste their time reviewing it. This is one of the classic moves used to convince someone to agree to a fradulent deal-- baffle 'em with bullshit.
- wolco 7y agoWhy would anyone sell their old keys?
- admax88q 7y agoThe biggest flaw in Proof of Stake IMO is that it then costs you nothing to fork. Forking bitcoin requires deciding which fork to spend your mining processing time on. Forking a PoS coin does not, since you can use the same coins for stake on as many different chains as you want.
- totony 7y agoWhy is this a flaw? Edit: it seems like it makes it more robust, basing ur interest in a fork not in your involvment in it but in its merit (e.g. you are incentivized to support them all)
- rocqua 7y agoNothing to prevent you from staking honestly on one chain, and dishonestly on a chain that undoes some of the spends on the other chain. Hence people can band together to try and create forks without losing any money if the fork fails. Whereas with PoW, any effort spend on a fork is effort that did not to towards mining on the main chain.
- totony 7y agoBut you'd lose money on the second chain? Assuming >50% are honest. If <50% are honest the second chain is probably not worth anything anyway
- Zamicol 7y agoNothing at stake is never truly nothing at stake, but I've always considered "nothing at stake" not really a problem that's unfixable.
- andrewla 7y agoWith Ethereum's algorithm I don't think this is the case (without some serious changes) because if you can prove that an address staked on a different chain then you can penalize that address on the main chain. I guess ultimately as long as you make sure that you empty out the address on the main chain, the main chain will simply disregard your attempts to claim a stake as being without merit. I don't know that anyone has analyzed the general case of an ongoing fork; the entire point of a proof-of-X is to be able to definitely prove from scratch that a given fork is the "correct" one simply by examining all alternative forks presented.
- MadWombat 7y agoHow does this deal with very large transactions? If someone wants to pay someone a billion ETH, where do you find enough stake-holders with big enough stakes?
- Zamicol 7y agoA billion in dollar value? There's only about 110 million eth.
- MadWombat 7y agoLets not focus on the actual numbers. What happens if someone wants to conduct a transaction and there are no stake holders big enough? With proof of work it is not a problem, but if stakes have to be commensurate with the transaction amount, doesn't that put a hard limit on the transaction size?
- Zamicol 7y agoI am unaware of any limit on transaction size in relation to staking.
- hatinthecat 7y agoYou should also take a look at 0chain. They are using proof of stake and have decentralized storage.