47 ms·
Proof of stake is incapable of producing a consensus
- josephcsible 5y agoThe most important part of this post doesn't even have anything to do with cryptocurrency: > If the broad masses of people disagree with the platform landlord, their opinion will be altered to conform with the rules, or else they will no longer have a voice. We really need to fix that problem.
- jimbob45 5y agoIt’s already fixed to some extent. On Reddit, you make a new subreddit of your own. On GitHub, you fork. The problem is that some projects are too big to effectively fork (or forking would over leverage the community) or people are lazy and don’t want to do the forking themselves despite accurately identifying the presence of a problem.
- josephcsible 5y agoWhat about when it's the Reddit or GitHub admins who judge you to be guilty of thoughtcrime?
- cube00 5y ago...or the Reddit CEO who goes into the backend to invisibly edit your posts. https://web.archive.org/web/20170720143148/https://www.reddit.com/r/The_Donald/comments/5ekdy9/the_admins_are_suffering_from_low_energy_have/dad5sf1/ https://web.archive.org/web/20170720143148/https://www.reddi...
- Sevii 5y agoOr more realistically, you get banned from Reddit and Github.
- cube00 5y agoHave we already forgotten what happened to youtube-dl at the hands of GitHub? I know GitHub were only following the DMCA but it shows they have the capability to not only remove the project but also all of its forks.
- Godel_unicode 5y agoI genuinely don't understand the fear generated by the youtube-dl storm in a teacup. It's a great example of the system working: someone thought they had a DMCA case so they filed a takedown, the takedown temporarily removed the content, then after a review the content was put back up. This is just evidence that this particular slope isn't as slippery as some thought.
- Eelongate 5y ago> the content was put back up. The repo is back up, but the project is dead. I suspect the developers got nasty letters from lawyers behind the scenes. I believe yt-dlp is the future of this project, but it's presently lesser known than youtube-dl so the lawyers got what they wanted in the end.
- jokethrowaway 5y agoThat's a problem with our laws. Copyright should just be a contract between seller and buyer. You promise not to redistribute this. If you didn't buy something, you have no contract with the seller and you can be free to download whatever you want or build whatever software or service you want. The onus of finding who is the buyer breaking the contract and dragging them to court is on the seller. We shouldn't have things like DMCA which allow you to censor anything tangentially related or being able to scare people off, but that's what you get when you have a corrupted government that does the bidding of Big Business. Similarly, patents shouldn't be a thing. You came up with something, you already have first mover advantage. If someone comes along and does the same thing better, too bad, they were better than you. If you have a manufacturing secret, protect it with contracts and sue for damage if they get broken.
- SturgeonsLaw 5y agoSo you can sit around in your new subreddit with enough subscribers that you can count them on your fingers, posting freely, while /r/politics (or wherever) has a subscriber base measured in millions. Reminds me a bit of the "free speech zones". It's a poor facsimile of true freedom of speech. Seeing as the new public squares are, by and large, digital spaces controlled by megacorps, we need to expand the first amendment to apply to private enterprise.
- Godel_unicode 5y agoFreedom of speech is not the same thing as requirement that others listen. If someone has no audience, with all the platforms that are available, it's not because they're being censored. It's because nobody cares what they have to say.
- josephcsible 5y agoIt's not that nobody wants to listen. There are plenty of people who want to listen, but the megacorps refuse to let the talkers and listeners connect.
- fallingknife 5y agoThis is not what is happening on these platforms. r/thedonald had millions of subscribers and not a single one was forced to listen. Then it was banned by reddit for thoughtcrime.
- skinnymuch 5y agoYou could have brought up hard left subreddits getting banned too. Like Chapo. So it doesn’t seem like only the right is persecuted/appearing to continue the trope of how the right are such victims.
- fallingknife 5y agoSame thing
- poetically 5y agoSomething about means of production and who owns it. This is most obvious on social media. The people participating on the platform do not get to decide the rules for how it operates. Which is a little ironic given that most people on social media are ostensibly in favor of democracy.
- DonHopkins 5y agoI've invented a new get high quick scheme called "NFTHC", which is based on "Proof of Weed" instead of "Proof of Work". It's 100% green, and based purely on sustainable renewable resources. NFTHC: Burn Weed, Not Coal!
- ottomanbob 5y agoOccam’s razor points to PoW.
- DonHopkins 5y agoSpeaking of POS scammers, what ever happened to Richard "Dodge Dodge" Heart, winner of the "Golden Pump Award" for "Best New Scam" for his POS get-rich-quick pyramid scheme called "HEX", who falsely claims that proof of stake is a proven successful replacement for proof of work, and who shills HEX and tries to recruit unsuspecting developers and victims here on HN and many other places, by making illegal false claims of providing CDs (certificates of deposit)? To be fair, I'd love to hear him chime in on this discussion, and tell his side of the story, relate his exploits and prosecution as a viagra spammer, and finally answer all those unanswered questions people have asked him, to which he replied "Dodge Dodge". Not that he's unique or special: POS shills like him are a dime a dozen. But he hangs out here and shills on HN, and has won awards for his deceptive scams (and also lost court cases too), and claims to "help people" on his web site, so I hope to hear from him again. https://richardheart.com/ https://richardheart.com/ His real name is actually Richard J Schueler, under which he is famously known as the "Spam King", for being one of the first people in the world to be successfully sued for online spam, specifically the Viagra spam scheme that he ran from Panama (which he lost). Richard Hart (aka "Spam King" Richard J Schueler) wins the "Golden Pump Award" for "Best New Scam" for his POS shitcoin Ponzi scheme "HEX": https://twitter.com/JuanSGalt/status/1233242355995750400 https://twitter.com/JuanSGalt/status/1233242355995750400 https://www.youtube.com/watch?time_continue=857&v=tf-lJu5iDh8&feature=emb_logo&ab_channel=WorldCryptoNetwork https://www.youtube.com/watch?time_continue=857&v=tf-lJu5iDh... Peacefire.org beats spammers in court. https://www.zdnet.com/article/peacefire-org-beats-spammers-in-court/ https://www.zdnet.com/article/peacefire-org-beats-spammers-i... >Free-speech group Peacefire.org wins a legal round in its fight against unsolicited e-mail, invoking Washington state's anti-spam law. >The King County District Court in Bellevue, Wash., on Monday granted Peacefire $1,000 in damages in each of three complaints filed by Peacefire Webmaster Bennett Haselton. The small-claims suit alleged that Red Moss Media, Paulann Allison and Richard Schueler [who now operates under the pseudonum "Richard Hart"] sent unsolicited commercial messages to Haselton that bore deceptive information such as a forged return e-mail address or misleading subject line. Confronting Richard Heart of HEX - SPAM KING and Crypto Scammer https://www.cointelligence.com/content/confronting-richard-heart-of-hex-spam-king-and-crypto-scammer/ https://www.cointelligence.com/content/confronting-richard-h... >During ANON Summit 2020, I participated in a “fireside chat” with Richard Heart, founder of HEX. HEX is one of the most sophisticated, if not THE most sophisticated scams I have ever seen. >Why was I so aggressive with Richard? I have a lot of experience fighting with scammers, at events, and in online discussions. I’m familiar with their bullshit techniques. Richard is the sort of “master debater” who will answer a question without actually answering the content of the question. I watched more than 6 hours of his previous talks and learned how to tell when he was trying to avoid a real answer. >If you don't want to sit through hours of interviews yourself, this 4 minute video not only sheds light on Heart's motivation for establishing HEX, but also shows just how abrasive and crude he can be. This video was not created or edited by Cointelligence. https://www.youtube.com/watch?v=_MIdlXHedlU https://www.youtube.com/watch?v=_MIdlXHedlU >I want to draw your attention to the quote in the video above: "What am I going to make more money doing? Promoting my token, that I own a whole ton of? Or promoting bitcoin, where I own one-one zillionth of the available supply?" He's clearly in this to make money for himself in any way possible. [...] >When asked why HEX was not categorized as a security, at around the 21 minute mark, Richard offered an explanation that has no legal grounding. On the website, HEX claims that it is "The first high interest blockchain certificate of deposit." However, HEX has no legal authority to issue CDs. Richard is illegally claiming to provide CDs when in fact the instruments are nothing but glorified savings accounts. More quotes: "What's up now, fggot? What are you going to do now, you little btch? Get the fuck out of here! That's the dumbest piece of shit I've ever seen in my fucking life. [...] Let me give you some more bullshit, ok?" -Richard Heart aka Richard J Schueler Richard Heart - Spam, ICOs, and Death Threats https://imnotdead.co.uk/blog/richard-heart https://imnotdead.co.uk/blog/richard-heart Richard James Schueler - Friggin Spam King https://web.archive.org/web/20190416235350/http://www.panama-guide.com/article.php/20070926122502156 https://web.archive.org/web/20190416235350/http://www.panama... Why HEX is a Ponzi and not a solid investment (Part 2): Richard Heart https://www.reddit.com/r/CryptoCurrency/comments/kwhjxa/why_hex_is_a_ponzi_and_not_a_solid_investment/ https://www.reddit.com/r/CryptoCurrency/comments/kwhjxa/why_... >During the interview at ANON, Richard confirmed that he was one of the first people in the world to be sued for online spam, back in 2002. This shows us Richard has experience abusing unregulated markets, as he is doing with crypto these days. Richard: this an accurate quote of your own words? >When I pressed the matter and asked for a simple “yes” or “no” as to whether he, as the FOUNDER of HEX, knows who benefits from the funds sent to the “Origin Address” he flat-out said “I’m dodging your question.” Dodging the question! He proceeds to repeat “Dodge, dodge.” Richard, your tag-line "Do you want to develop my new cryptocurrency?" is the new "Do you want to develop an app?" https://www.youtube.com/watch?v=jVy0JWX5XEY&ab_channel=AdultSwim https://www.youtube.com/watch?v=jVy0JWX5XEY&ab_channel=Adult... "Dodge, dodge." -Richard Heart aka Richard J Schueler
- dschlossman 5y agoIn some systems Ive seen, bad actors get slashed (lose stake). I like pOs but it gives too much power to centralized exchanges that hold a large % of stake...
- lngnmn2 5y agoI really like the analogue with aluminium smelting. This is what bitcoin mining is nowadays, plus the increasing difficulty. Prof of stake is analogous to Wall Street institutions and probably modelled after them.
- arisAlexis 5y agoCrypto is a weird space. Firdt thing to make clear is if OP has a vested interest in another blockchain platform
- barbegal 5y agoProof of work has always had an economic flaw that you could theoretically temporarily rent enough mining power to perform double spends of more value than the cost of renting those devices. But this attack has never been performed because the reality of all these cryptocurrencies is that the security depends only relatively weakly on proof of work. Instead it relies on trust between the main stakeholders: miners, big nodes and developers. This is just like any other human organisation. That trust is only reinforced by proof of work, making it easier for new parties to become trusted.
- crazypython 5y agohttps://www.crypto51.app/ https://www.crypto51.app/ To execute a double spend, you the one sending the transaction and the miner must coordinate. For large transactions, it is recommended to wait for six confirmations. (six blocks that agree with the transaction and have not been 51%ed.) The 1 hour 51% cost of Bitcoin is 1.9m$. However, you would need much more time than that to find six consecutive blocks alone, without the help of the network. So, while the network is 6 blocks ahead, you need to find 7 blocks. The network moves forward a block, you must move forward more than one block to catch up. This could take a long time, and longer the more confirmations required- each confirmation makes each previous transaction exponentially more secure. Simply controlling the mining power momentarily only puts recent transactions vulnerable. However, that much hardware is available for rent-see “Nicehashable.”
- yuliyp 5y agoI don't see how more confirmations makes it exponenrially harder to mount a 51% attack: you just need to be mining faster privately than the remaining community until you (a) have a lead, and (b) have maintained that lead for the confirmation window.
- yanmaani 5y agoThere's luck involved too. In the limiting case, imagine you have 0.001% of the network hash rate and need a 1 block lead. This can happen every now and then, but getting a 2 block lead is basically impossible. The exact formula is given in the Bitcoin whitepaper <https://bitcoin.org/bitcoin.pdf https://bitcoin.org/bitcoin.pdf>, see page 6 and on.
- josnyder 5y agoPoW systems rely on the "phone a friend method" as well. When you download a Bitcoin client from a "friend", you are trusting them to honestly introduce you to the network. If you fall asleep for a period of years, you have to trust your friends to honestly inform you of all of the PoW forks and policy changes that have occurred over that interval. The only difference is that PoS blockchain clients must be bundled with a modestly-recent block hash along with the thousands of lines of code that you have no practical way to audit. The problem eventually reduces to Ken Thompson's "Trusting Trust" [1] problem. There's no way to externally validate the honesty of any system (cryptocurrency, or otherwise). [1] https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
- crazypython 5y agoThe difference in Proof of Stake is a lawsuit could force the distributor of the software to change the hash to one where coins weren’t stolen. As most developers are not pseudonymous, this poses a threat to the honesty of the system. You mention “POW forks”, but Bitcoin’s POW has never been hard forked: you’d need to trust a Bitcoin expert to tell you if it was a good idea.
- everfree 5y ago> The difference in Proof of Stake is a lawsuit could force the distributor of the software to change the hash to one where coins weren’t stolen. In Proof of Work, a lawsuit could force the distributor of the software to hard-code a transaction that reverses the coin theft. But in both the PoS case and the PoW case, anyone using that client would be partitioned off from the honest network majority. > You mention “POW forks”, but Bitcoin’s POW has never been hard forked: you’d need to trust a Bitcoin expert to tell you if it was a good idea. Bitcoin's PoW forked in 2013, when a database upgrade to the software made it incompatible between two recent versions. The Bitcoin developers had to jump in and tell people which PoW fork to follow and which one to abandon.
- comex 5y ago> The difference in Proof of Stake is a lawsuit could force the distributor of the software to change the hash to one where coins weren’t stolen. And with proof of work a lawsuit could force the distributor to change the consensus rule so that a particular transaction is invalid - just as Ethereum did voluntarily with the original DAO. > You mention “POW forks”, but Bitcoin’s POW has never been hard forked Instead it’s been soft forked, which turns the consensus rules into a popularity contest. If a soft fork produces two competing branches of the blockchain, old clients will go with whichever branch has more mining power. Which means you open yourself up to interesting attacks like convincing 51% to literally steal the funds of the other 49% (which is much worse than a mere double spend). Or, more realistically, in the case of a contentious soft fork that ends up roughly fifty-fifty, you could ‘just’ end up on a different side of the fork from the people you want to transact with. Either way, soft forks don’t make the downsides of policy changes go away.
- 5350-uiop-1130 5y agoPoS is a flawed system that enriches the project founders primarily. Just look at Charles Hoskinson or Gavin Wood. PoW is apparently bad for the environment. So it leaves us in an interesting situation. The Ethereum project has shown that the concept of decentralization only applies when it's on their terms. It's not a true principle.
- pmorici 5y ago“Decentralization” has been the argument ideologues have fallen back on time and again in crypto. It’s never well defined and typically used to oppose policies that would promote low transaction fees or increased transaction throughput. It’s why things like Solana which is focused on massive scale and low fees have found a foothold. Ethereum is repeating the mistakes of Bitcoin
- rank0 5y agoIt’s because if you’re not decentralized, then you don’t need a blockchain.
- duped 5y agoThe gold standard was decentralized. Over a century of monetary policy has shown that decentralization isn't aligned with political or economic goals.
- janeroe 5y ago> Over a century of monetary policy has shown that decentralization isn't aligned with political or economic goals. Or rather it has shown that decentralization isn't aligned with the political or economic goals of those who conceive the monetary policy.
- duped 5y agoWhich often aligns with the people that elect them. Central banking fixes serious flaws in money systems, and provides levers to mitigate disasters caused by external forces. Compare it to a boat. Central banking gives you the ability to steer, sure someone might be bad at it and lead you into dangerous waters. But decentralized currency is like shooting the helmsman and ripping out the rudder because someone did a bad job of it once.
- a-dub 5y agoregarding the private mining attack: proof of work proves that not just one miner had sufficient hash power, but that the entire network had a certain aggregate hash power that was required to mine the block. can't this be emulated by requiring all major stakers to sign the block? (so rather than one miner staking being enough, all the aggregate staked was required to mine the block)
- a-dub 5y agoin any event i think the op is wrong in terms of the hard part of proof of stake, private mining attacks are solvable. the stickier issues are around maintaining the decentralized nature of pow mining and the random and decentralized election of who mines the next block. under pow, everybody does their own thing and when someone finds a block they are able to publish it without direct collaboration with other miners. the fact that the miner is chosen at random gives rise to all sorts of anti-censorship and anti-collusional properties. proof of stake will have to emulate this, and possibly make a few targeted and carefully chosen compromises in order to emulate the decentralized nature of pow mining. it's not obvious how this will play out, but i don't think it's impossible and efforts to do so certainly aren't a "scam."
- rhincodon 5y agoIf POS is really as bad as claimed, then why is Ethereum 2.0 going to be using POS?
- sp332 5y agoWell, how many times has it been delayed? Clearly it's not all sunshine and rainbows.
- suikadayo 5y agoWhat’s delayed? Beacon chain has been running on mainnet since last December-ish. http://beaconcha.in http://beaconcha.in
- hanniabu 5y agoBut-but-but! frustrated by facts
- seoaeu 5y agoThey’ve been saying Etherium will switch to proof of stake “soon” since like 2017!
- sp332 5y agoThe merge was going to happen by the end of this year, but miners complained https://news.ycombinator.com/item?id=26441399 https://news.ycombinator.com/item?id=26441399 and then it was delayed again. https://www.coinhighlight.com/2021/10/ethereum-eth-devs-looking-to-delay-difficulty-time-bomb-what-could-this-mean/ https://www.coinhighlight.com/2021/10/ethereum-eth-devs-look...
- suikadayo 5y agoThe merge was expedited over miner concerns, prioritizing it over sharding as originally planned, so it’s actually the opposite of what you are saying.
- CraftingLinks 5y agoCan't wait for the day all PoW mining activities are declared illegal. To be honest, I don't understand why it hasn't been banned already. Sweden has recently called for a EU wide ban because it identified PoW mining as a threat to transition their economy to renewable energy. https://www.fi.se/en/published/presentations/2021/crypto-assets-are-a-threat-to-the-climate-transition--energy-intensive-mining-should-be-banned/#dela https://www.fi.se/en/published/presentations/2021/crypto-ass...
- thesausageking 5y agoShould we also ban clothes dryers, Christmas lights, porn, and video games? Each of those uses significantly more energy than Bitcion. If not, who gets to decide what a "good" use of electricity is?
- jancsika 5y agoI'm just imagining downloading a porn client which fetches 300 gigabytes of bullshit before it finally lets me watch a movie at a whopping five frames per second. And best of all, someone complaining that this is clearly a wasteful scam and being told back, "how much energy did videocassettes and magazines consume, huh?"
- dagmx 5y agoBut won't each of those take up significantly more energy once they use Bitcoin than today? I.e the costs will be additive , and crypto aims to replace fiat. So crypto would need to be more efficient at the same scale as fiat to make sense. Also aren't each of those used by significantly more people than Bitcoin? So the per capita use is less and they scale better? Also how are you estimating cost of porn? Viewing cost? Generation cost?
- chrischattin 5y agoNo. Bitcoin network power usage isn’t related to the number of transactions.
- _2d30 5y agoI'm blown away by how quickly this rose on HN and how unconvincing it is.
- deleted 5y ago[deleted]
- hanniabu 5y agoIt's a fud piece by a bitcoin maxi and HN is anti-crypto so it resonates with them and gives the echo chamber some good confirmation bias kool aid.
- yanmaani 5y agoAm I a Bitcoin maximalist?
- make_it_sure 5y agoIt's the same for the other side.
- TrackerFF 5y agoI wouldn't say that HN is staunchly anti-crypto, more crypto skeptical. Many of us were in the scene from the beginning, and have made good money on the hype. But one thing that's extremely apparent, is that for the past 10 years, the crypto community has been 95% greed, 5% innovation. With the innovation part having picked up speed only the past few years. At first, it was the an-cap dream. Decentralized, trustless, govt free internet money. No longer were you a prisoner to slow bank-transfers, expensive middle-men (PayPal, etc.), and could purchase whatever you wanted. Then the price shot up, and everyone wanted to become rich. So people "agreed" that BTC is no longer a coin made for spending, but rather a storage of value. Like gold. Use altcoins if you actually want to spend your crypto. But who wants to spend any, with the rising prices? Meanwhile, centralized banks, 3rd party businesses, etc. have solved all the personal finance issues that plagued us 10 years ago. In most countries today, you can transfer money pretty much instantaneously, without getting anxiety every time you press "send". I'll give DeFi, Dapps, etc. credit - they've finally managed to roll out usable things, but it's still way, way too hard for regular users. And most regular people do not give two shits whether something is decentralized and trustless. I can think of multiple legit uses for the blockchain technology - but I'm gonna be honest, I'm having a harder and harder time seeing how cryptocurrencies will replace any national currency. As of right now, it's almost purely speculation and get-rich-quick schemes. We're still in the wild west, but it's not gonna stay that for long. With regulations looming around, it's just a mater of time. But I digress
- TTPrograms 5y agoWhy do unsophisticated, redundant, vitriolic takes like this get upvoted on HN so much? Is there some common ax to grind here? The strongest point here is the strawman presentation of the altered security model that PoS can be proven to form consensus under. Reading the source he cites is far more informative: https://blog.ethereum.org/2014/11/25/proof-stake-learned-love-weak-subjectivity/ https://blog.ethereum.org/2014/11/25/proof-stake-learned-lov... The majority of the article frames distributed consensus mechanisms in an extremely sophomoric understanding of asset value and the PoW security model. All of these topics (including valid ETH criticisms) are discussed in much better ways in many other places.
- 127 5y agoThey might not upvote the article, just the discussion in this thread; which in my humble opinion is quite good.
- jeron 5y agoOccam's razor points to sour grapes
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- omarfarooq 5y agoOne way of conquering FOMO is to totally write the thing off, and to stubbornly stick to that thesis.
- lukebitts 5y agoQuestioning people's motives is always a boring endeavor. You don't actually know that's the reason, why not respond to the arguments that were made?
- omarfarooq 5y ago
- anonymoushn 5y agoDo people deploy PoS chain clients that are ok with blocks that totally ignore the historical leader schedule or use a leader schedule that could not have resulted from the distribution of stake in the network at the time? If not, how will the attacker who wants to swap out a single block a year later get all the other validators to sign a year worth of new blocks?
- lofsigma 5y agoThe cope is strong with this one.
- pshc 5y agoIs this FUD from Bitcoin maximalists? > That key is valid to sign any number of versions of, let’s say, block #200, and there is no objective, system-internal standard for which version is legitimate, other than “the one that was published first”. The real block #200 will have hundreds of attestations courtesy of randomly-selected validators, each of those signatures attesting to its validity and finality.
- ricardolopes 5y agoThe block 200 will be adding validation to the previous blocks, and will be validated by the future ones. Without other types of checks, nothing stops you from rewriting the previous 199 blocks and using block 200 to validate them. This is not FUD, it's the most obvious PoS flaw, called long range attack, and the reason PoS chains often need more checks to be more trustworthy (e.g. keeping hardcoded checkpoints, choosing the first received block as valid, introducing penalties and so on).
- pshc 5y agoHere’s a recent ETH2 block: https://beaconcha.in/block/2604970#votes https://beaconcha.in/block/2604970#votes It was voted for by 8000+ validators. Many of them have been validating since beacon chain genesis a year ago. There are like 260k validators active right now. I find it highly unlikely some entity is going to come along and try to pretend their alternate history, with a whole new set of hundreds of thousands of validators (which wouldn’t be supported by any ETH1 deposits) and millions of signatures signed by 260k freshly generated public keys, is in any way legitimate.
- crazypython 5y agoHow is that different from 8000-of-260k multisig?
- pshc 5y agoIt's similar in that 8k sigs are collected and coalesced to sign something. From there the differences begin. M-of-N schemes must be orchestrated ahead of time, using Shamir's or by constructing a BTC multisig UTXO or something. When signing, one may choose freely among the key shards. It's performed in the usual execution layer of the chain. Whereas in ETH PoS, validation happens in the consensus layer, following strict self-imposed rules. With each new block, one validator is chosen to propose the block, and thousands of validators are asked to back the proposer. The proposer and attestors are chosen randomly but specifically with no freedom to mix and match; the chosen validators must attest (and receive a reward) or else be penalized. Validators don't know each other and they don't need to cooperate to create a shared key ahead of time, all they have to do is deposit and follow the rules. The signatures are agglomerated by [BLS ellipical curve stuff idk it's magic] and help to form the consensus chain itself.
- mercurial_sucks 5y agothis forum is actually retarded. Either you dismiss both or neither given there are literally no differences
- mNovak 5y agoAm I understanding this correctly; is the threat model that a block signer, some time later after liquidating their stake, can go and publish arbitrary versions of that older block?
- betwixthewires 5y agoYes, but it is a little more than that: that future nodes will not be able to distinguish these two blocks without relying on some authoritative source for the canonical chain, thus introducing centralization to the game environment.
- udbhavs 5y agoWhat about delegated proof of stake?
- anonymoushn 5y agothat's just worse, but not in ways that really interact with the thrust of the article
- EGreg 5y agoThis is like two homeless people arguing who is richer. Yes both PoW, PoS solve the double-spend problem, but in a brute-force way. And they never really get rid of the ambiguity of which chain is the one to go by. They just aggregate all the little ambiguities into one or another consistent version of history (a chain) and let them duke it out by massive electricity or stake or whatever. But at any moment, someone could have been mining a chain in “secret” and will emerge to thwart the rest of the network for a while. There is a better way. Blockchains are actually quite centralized since to make any progress every N seconds you need to send all transactions in the entire world to one miner, and the block is limited in size. Actually it’s worse than that in Proof of Work — because you don’t know who will solve the silly problem, you have to gossip every transaction to every miner! Oh yeah, and if you store UTXOs then you have to store the history of everything. And even if you didn’t, you have to store the current state of everything. Oh how nice and decentralized! LMAO
- betwixthewires 5y ago> LMAO I don't get your criticism. Why does requiring gossip to every node cause centralization? Why does everyone having the current state of everything cause centralization?
- EGreg 5y agoTo make progress, every few seconds or minutes, all transactions in the world must be gathered in ONE place, and placed in ONE block, as the network and adoption grows this becomes more and more expensive for everyone. There are various aspects of centralization. This is one major aspect: a bottleneck. Just like when all Web 2.0 conversations in the world would have to go through a centralized server. Even if it was a different server each time, it’s still an extremely centralized topology for that state transition. It means that there can only be one transaction at a time for the whole world, no matter how many computers join the network. No concurrency — it is also why you can have flash loans. This is why Ethereum is called “the world computer” and why Bitcoin failed at being a peer to peer cash system and became a store of value.
- 5y ago
- rich_sasha 5y agoMy general observation is that blockchains are, at best, secure in the same way https is secure. Yes I have padlock icon on the browser address bar, and my connection is secure, there’s a security certificate, but the whole thing can still be a scam. Who personally verifies every contract they use? Wallet implementation? Cold wallets are closed-source, trust-me devices, maybe with a security certificate from a centralised, government-linked security org. The strongest link in any security chain is not irrelevant, but the whole system is really not perfectly trustless anyway.
- kajaktum 5y agoWhat is preventing someone from DDOS a cryptocurrency network by spamming it with inane transaction between 2 people?
- eximius 5y agotransaction fees you either dont pay enough and are ignored or you pay enough and... great?
- anonporridge 5y agoTransaction costs. It's actually suspected that happened during the blocksize wars when proponents of forks like Bitcoin Cash may have been spamming Bitcoin with transactions to feed their narrative that it is too expensive to use. You'll eventually go bankrupt if you do this long enough. This is actually another reason unlimited blocksizes that can allow for very low to no cost transactions are risky, and DDOS protection is likely why Satoshi added the 1MB limit in bitcoin to begin with.
- ikt 5y agocost, this is an issue polygon had https://beincrypto.com/polygon-raise-network-fees-spam-transactions/ https://beincrypto.com/polygon-raise-network-fees-spam-trans...
- darcys22 5y agoHe lost me at the part where he thinks you can sign messages after withdrawing your stake. The whole point of proof of stake is that you can only sign blocks or messages while you have something staked. When you withdraw you are no longer allowed to sign anything. He also didnt need to spend 1000 words going on about the history of bitcoin and proof of work. This is literally just a filler piece with a provocative clickbait title to stir up the anti cryptocurrency folks here
- inter_netuser 5y agoYou can withdraw your stake. Withdrawing a gigawatt plant and a silicon foundry is a little more involved, you see.
- yanmaani 5y ago> When you withdraw you are no longer allowed to sign anything. Allowed to by whom? Who's to punish me if I disobey them?
- michaelsbradley 5y agohttps://github.com/ethereum/annotated-spec/blob/master/phase0/beacon-chain.md#aside-randao-seeds-and-committee-generation https://github.com/ethereum/annotated-spec/blob/master/phase... After withdrawal is completed, your node would no longer be in the set of active validators and from that time could not validly propose a block or submit an attestation (or, more accurately, be selected as a block proposer, etc.)
- yanmaani 5y agoYes, "validly" being the operative word here. I can still propose blocks invalidly, you see. And then someone who doesn't already have the consensus (e.g. trying to sync) will have no way to tell which is legitimate. This is the problem - you can't look at what the system does when everything's working as it should, you have to look at what happens when it's outside of the comfort zone.
- vages 5y ago> If a node can present a lottery ticket of rarity one-in-a-million, the network can conclude the node did about a million lottery tickets’ worth of work, on average. This is not true. You will have scratched far fewer tickets on average than one million. If you have one million tickets, one of them guaranteed to be a winner, you will on average scratch exactly half of them (500 000) before finding the winning ticket. If you have an infinite supply of tickets, each with a 0.000,001 chance of winning, the number becomes higher, but the number of tickets scratched on average is still lower than one million. Finding an error regarding something I know makes me skeptical about the rest of the article.
- rich_sasha 5y agoIf there’s a million tickets and you know one of them is a winner, then yes. If you have an effectively infinite stream of tickets and each have a 1 in X probability of winning, you will indeed go through X on average.
- denton-scratch 5y agoYeah, I think that's right. The hypothesis was that on average, one in a million cards is a hit. That implies that if you scratch a million cards, you have a 50:50 chance of a hit. That the author got this basic thing wrong doesn't inspire much confidence in the rest of his reasoning.
- rich_sasha 5y agoWell, I guess in real life blockchains it’s like the latter case. You have a block and look for a nonce. There is an effectively infinite stream of nonces (“lottery tickets”). You have no guarantee that even one works, other than statistical hope. So then if probability of a match is 1 in X, you expect to have to do X attempts. I have other issues with the article but this bit seems ok.
- denton-scratch 5y ago/me not a statistician! I'm not clear how "expected no. of attempts for X" is related to the probability of X. And I seem to be struggling to recall what little I used to know about probability. I'd welcome a (link to a) clear unpacking of this scenario. I'm feeling rather stupid, as if I've had a stroke and lost a mental faculty. It seems to be a straightforward and obvious scenario, but I've lost confidence in my reasoning about it.
- jl6 5y agoIf it’s scam, the article could have presented a stronger case for it. The objection seems theoretical. If PoS is broken, I would expect to see a plausible attack spelled out.
- c0742e9366 5y agoAs far as I am aware, these long-range forks can be hindered by using verifiable delay functions (VDFs) [1, p. 6]. Essentially, VDFs take a certain amount of steps to compute and cannot be parallelized. However, the correctness of their output can be verified efficiently. Now if a proof of stake includes a VDF that needs to be computed for every block, then a long-range attack needs to recompute the VDF outputs as well. This is infeasible as it will take a long time given the correct choice of VDF parameters. Notably, the Chia blockchain mentioned in the article would succumb to long-range attacks as well were it not for their usage of VDFs [2, p. 17]. [1] https://eprint.iacr.org/2018/601.pdf https://eprint.iacr.org/2018/601.pdf [2] https://www.chia.net/assets/ChiaGreenPaper.pdf https://www.chia.net/assets/ChiaGreenPaper.pdf
- evil-olive 5y ago> Essentially, VDFs take a certain amount of steps to compute and cannot be parallelized. However, the correctness of their output can be verified efficiently. this...sounds exactly like proof of work?
- inter_netuser 5y agoIt is, just wrapped in enough layers of misdirection.
- c0742e9366 5y agoNo, a VDF just proves that, given a certain input, you spent a certain amount of time to compute the unique (!) VDF output. As said, this computation must be carried out sequentially. Of course, it can still be sped up by creating an ASIC (the same technology used for Bitcoin miners nowadays). However, there is not point in running multiple ASICs (like a Bitcoin mining farm) because the computation cannot be parallelized and the output is unique. Thus, running one ASIC has exactly the same effect as running thousands ASICs and there is no energy waste.
- evil-olive 5y ago> proves that, given a certain input, you spent a certain amount of time so, proof of work?
- darawk 5y ago> Proof of stake is a scam. When I say that, I mean that proof of stake is (1) claimed to be a consensus system, and (2) constitutionally incapable of actually producing a consensus. Ok. Go break one of the many existing systems that operates using proof of stake then. If you've done this, you should be leading your article with it. If you haven't, you shouldn't be speaking. Proof of stake is not some theoretical thing being proposed in the abstract. Many systems operate on it as we speak.
- inter_netuser 5y agoyou didn't read the article to the end, did you? about 40% in: "Because of all the arguments above, we can safely conclude that this threat of an attacker building up a fork from arbitrarily long range is unfortunately fundamental, and in all non-degenerate implementations the issue is fatal to a proof of stake algorithm’s success in the proof of work security model. However, we can get around this fundamental barrier with a slight, but nevertheless fundamental, change in the security model." —Vitalik Buterin, saying the quiet part out loud Security model in PoS = trust the rich. Some like having masters, whatever floats your boat.
- darawk 5y ago> you didn't read the article to the end, did you? I skimmed it. It made no serious arguments. If it had a serious argument, it would have exploited one of the many existing proof of stake systems. > Security model in PoS = trust the rich. Some like having masters, whatever floats your boat. You mean...exactly like PoW mining?
- inter_netuser 5y agoNo, exactly the opposite of PoW mining. Miners do not set the rules, they are merely a service that provides immutability to a ledger, with a nuclear option that will bankrupt all the billions they have invested, should they misbehave. Large stakers can rent-seek and extract your wealth, PoS is the same system we have now, plus some code. You are quite literally being exploited right this minute, by the same methods outlined in the article.
- brianolson 5y ago(my day job is developer on Proof-of-Stake Algorand block chain, I'm a developer, this may not be polished official PR) Article's theory about malicious old blocks doesn't hold up. Let's say I start a new node and verify history since the beginning. Somewhere along the line I'm connected to a malicious node which hands me a fictionalized block. It would need to have been signed by not just one but about 30-45 accounts _which had stake at that time_. Proof-of-Stake attacks aren't about having 51% of the CPU that overwhelms a Proof-of-Work system, but about having 60-70% of the _value_ in the network. So, if Warren Buffet comes along and wants to spam our network, I guess he could, but that would destroy the network and destroy his value that he sunk into the network. _That_ is a guardrail for PoS systems as much as any crypto or consensus-protocol element (and the algorithms are right, original article misunderstands them).
- kranke155 5y agoGlad to see an Algo dev here.
- ivalm 5y ago> but that would destroy the network and destroy his value that he sunk into the network Isn’t the whole point that by that time he would have withdrawn from the network so he would sink it without losing anything himself.
- dawnbreez 5y agoBut...if you no longer have value on the network, doesn't that mean you no longer have enough stake to control the network?
- inter_netuser 5y agoa coalition of wealthy interests can trivially dictate the consensus rules with very little to no recourse on your part. Even if the chain splits, they can maintain their share on both chains, and even suppress the minority chain. In PoW miners risk going bankrupt overnight for egregious behaviour like that. I'd like to see how one defines "slashing" programmatically that is impartial, works algorithmically, and does not have edge cases that can lead to catastrophic failures without handwavy assumptions that every single PoS network has today.
- CryptoPunk 5y agoThe author takes issue with the Phone-a-friend-consensus (PFC) for establishing base consensus. I disagree with his objection for two reasons: 1. For all consensus systems, at least a vast majority will rely on PFC for base consensus since they will not personally audit the client software they download, and thus will rely on PFC to determine which software distribution channel to trust to download the client software from. In other words, there is in practice no pure PFC-free consensus protocol, to be taking such a hard stance on Proof of Stake for its reliance on it. 2. The Schelling Point PFC in Proof of Stake will always be the real order of transactions, and therefore PFC will be highly reliable. Cases like Bitcoin's block size hard limit dispute, and Ethereum's DAO hack rollback dispute, dealt with something other than order of transactions, and in both cases, the dispute was severe enough to lead to a hard fork - which jettisonning PFC can't protect against - regardless.
- patrickaljord 5y agoHas anyone ever not been accused of being a scammer in this space?
- knorker 5y agoEverything else about cryptocurrency in a scam, and people promoting it are scammers, so this is not exactly a surprise if true.
- Jweb_Guru 5y agoThis is a silly article. Only working in a weaker security model does not, a priori, mean that proof of stake is a scam; it just means you need to convince yourself that the weaker security model holds. You can read the post linked (https://blog.ethereum.org/2014/11/25/proof-stake-learned-love-weak-subjectivity/ https://blog.ethereum.org/2014/11/25/proof-stake-learned-lov...) and decide for yourself. Personally, I think this kind of "quiescent" knowledge, letting you differentiate the real chain from the fake chain on long enough timescales (which basically amounts to knowledge of a single hash, when you get right down to it), is perfectly reasonable to assume under realistic circumstances, for the same reason that synchronized time is not a remotely difficult problem on long enough timespans. The only problem lies in new nodes (that enter the system when there's not a quiescent state, and the longer chain is being withheld) being exposed to fake chains. By using a VDF as mentioned below to make sure it takes just as long to construct a new chain as it took to construct the old one, one can ensure that as long as at the time the stakers held their keys (rather than for all time) a majority were trustworthy, then the probability that they were able to maintain a longer chain becomes vanishingly small. Therefore, nodes will be able to reliably choose the longer chain on reconnecting to the system. This trust model seems pretty realistic to me, and it's not like Bitcoin can handle the case of a continuous partition to begin with. So this just reduces to "once a majority is not trustworthy, the chain can't be trusted anymore" which is the actual security tradeoff of PoW vs. PoS (PoW puts trust in hashpower rather than staked coins, so by definition it's immune to this sort of issue; if your private key is stolen you "only" lose your coins, not any voting power). I don't think this is news to anyone who's done much research into cryptocurrency.
- Cantinflas 5y agoGreat comment, let's do a TL;DR of the article: - Clickbait title. - Some of the claims can be debunked with a 2014 blog post. - Tradeoffs pow/pos are known and accepted for a long time. Nothing new added except drama.
- inter_netuser 5y ago> Essentially, VDFs take a certain amount of steps to compute and cannot be parallelized. However, the correctness of their output can be verified efficiently. this...sounds exactly like proof of work? Indeed, you can probably fix plutocracy with some PoW.
- rkagerer 5y agoI've heard of proof of time, proof of space, proof of authority... What other oddball mechanisms are out there? eg. Anything like "proof of latency"?
- deft 5y agoNot really, its unfair but not a scam. Can we talk about the actual scam known as layer 2 rollup chains? Optimism is completely centralized and even Vatalik is shilling it like a good thing. At least the PoS shill makes sense, it artificially benefits early adopters.
- inter_netuser 5y agoAmazing clarity.
- cmogni1 5y agoAre there known issues/vulnerabilities with using something like Proof of History?
- ggambetta 5y agoProof of Steak is obviously better: https://meatver.se https://meatver.se
- collinmanderson 5y agoAlso https://steak.network/ https://steak.network/ "Decentralized networks are a rare medium well-done."
- JimWestergren 5y agoThanks for the laugh ;)
- gvv 5y ago"everything I didn't manage to gain from is a scam" - the article
- yunohn 5y agoAh yes, the “you’re just jealous because you missed the boat” retort. Magnificent!
- miohtama 5y agoFlagging this post, because most definitions of scam involve fraud and here is not fraud involved.
- dgan 5y agoI thought I understood what author says. After reading comments, I am lost again. I will continue my journey clueless, without ever touching this burning pile of trash with scammers on top.
- ulzeraj 5y agoMy opinion on PoS is that because no other community that I know of outside of bitcoin has a culture of running nodes normal people will just stake through exchanges. Now you have these exchanges acting not only as the in and out ramps but also as the biggest network validators meaning that they can direct transactions. Congratulations. You’ve just went full circle and invented central banks. Am I wrong? Would gladly read counter arguments.
- mattdesl 5y agoIn a chain like Tezos, the validator software is relatively easy to run if you have a Raspberry Pi and some terminal chops, and a lot of hobbyists do stake this way. But it’s easier for most people to delegate to another party. This is where decentralized staking pools for ETH2[1] built around smart contract interactions could be a good alternative for many users, and may compete with centralized staking platforms. The mere fact that these peer-to-peer and decentralized alternatives exist, and that some portion of users will prefer to use them, is what makes this technology distinct. [1] - https://rocketpool.net/ https://rocketpool.net/
- ulzeraj 5y ago> The mere fact that these peer-to-peer and decentralized alternatives exist, and that some portion of users will prefer to use them, is what makes this technology distinct. I can imagine projects that can run on cheap hardware thriving but what happens when you put the weight of exchanges like Coinbase and their users against the hobbyst node count?
- mattdesl 5y agoThis is already happening; centralized exchanges and staking pools like Kraken make up a high percentage of ETH2 validators (just as PoW seems to gravitate toward large mining pools). Despite that, PoS has the benefit of offering decentralized staking pools like RocketPool, and the fact that they are growing may indicate that the chain will over time become more decentralized and less able to be centrally attacked[1]. The PoS mechanism itself is also perhaps more resilient to these kind of attacks, see [2]. None of this mechanism is as simple as PoW (which has worked quite well for BTC and ETH so far), but the environmental cost makes it worth exploring an alternative mechanism. [1] - https://uk.style.yahoo.com/valid-points-ethereum-2-0-113000527.html https://uk.style.yahoo.com/valid-points-ethereum-2-0-1130005... [2] - https://vitalik.ca/general/2020/11/06/pos2020.html https://vitalik.ca/general/2020/11/06/pos2020.html
- csomar 5y agoThe author has good points, bad points and badly explained stuff. The article is a bit confusing at best and disorientating at worst. But I'll try to explain here, why the author thinks that PoW is magical. It's still bound to the readers, or philosophers, to pull whatever they want from this. Proof of Work creates time. In a decentralized system, you don't have time. If time was provable, the double-spending problem would not happen. You would sign a transaction and broadcast it; a second transaction that you would sign later, will have a higher timestamp. Obviously, you can sign a transaction later and have a lower timestamp, there is nothing that prevents you from that. What Proof of Work does, is create an arrow of time. Using this arrow of time, the nodes create a ledger (the blockchain). The OP is arguing that PoS cannot create an arrow of time; and as a result, the PoS is still liable to the double-spending problem.
- dorgo 5y ago>If time was provable, the double-spending problem would not happen. Can't you sign two transactions at the same time? If yes then you could double-spend even without faking timestamps.
- csomar 5y agoNot sure I understand you. When you are signing a transaction, you are the one who fills in the timestamp. The timestamp of a transaction in the bitcoin blockchain is the block height. The actual timestamp is merely informative.
- samarama 5y agoThis person doesn’t have any idea how PoS works and all of the people upvoting it don’t either. It’s very astonishing that the HN crowd still doesn’t understand blockchain after 13 years. The article is complete nonsense because: 1. The author thinks that PoS is about having computing power. If someone thinks that they seriously don’t know anything about PoS and haven’t done any research 2. Proof of Work is 100x more centralized because 2 companies control the majority of mining equipment production and 4 companies control the hashpower including all kinds of attack vectors, instead of the around 200 entities in PoS. 3. There are many attack vectors for the PoW model of which many only require malicious behaviour of 1 person, be it the CEO of one of these companies or a disgruntled worker that is bribed with a couple of million dollars. 3. The cost of taking over consensus for a PoS network, such as Solana or Ethereum 20 requires billions or trillions of dollars worth of coins that then all would rank heavily in value That’s why PoS is around 1,000x -1,000,000x more secure than PoW depending on how big the market cap of the PoS network is.
- cryptica 5y agoThis article is complete BS. Proof of Stake is more secure than Proof of Work for a simple reason. The cost of doing a 51% attack (to stop the blockchain or to start censoring specific transactions) on a PoS blockchain is exponential, whereas the cost of doing such an attack on a PoW network is linear. This is because as an attacker acquires more tokens, the price of remaining tokens increases exponentially as the attacker approaches the 50% mark. If the network is well decentralized in terms of token ownership, it may not ever be possible for the attacker to acquire 50% of tokens; also, their incentive to continue with the attack decreases as their stake in the blockchain increases. Unlike with PoS which requires the attacker to keep buying more (limited-supply) tokens, with PoW, ASIC miners don't become more expensive as the attacker gets closer to having 51% of the hash power; this is because the market will produce more ASIC miners to compensate for any increase in demand. The global supply of ASIC miners has no upper bound. The article is also misleading in inferring that there is a very narrow range of ways to implement PoS; in reality, there are many ways and all of the 'drawbacks' mentioned only apply to certain (poorly designed) implementations which no modern PoS blockchain would ever use. > What happens if you’re presented with two identical blocks, and have to decide which one to pick? Easy, you can just have a vote on one of the block and choose the one with the majority votes; it can be chosen on the basis of any attribute of the block (E.g. commonly you can look at block IDs). This is what PoS blockchains like COSMOS do with the Tendermint protocol. Other blockchains like Lisk have a delayed voting so that consensus is reached after a certain number of blocks. > The entire point of the consensus mechanism was to allow us to tell which transaction was first, without personally having seen it take place. Anyone who understands distributed systems knows that the exact order of transactions (down to a few hundreds of millisecond) cannot be physically determined due to latency between the nodes and the unpredictable geography of participants. This is as true for PoW as it is for PoS. The most important thing (for certain use cases such as DeFi) is that transactions cannot be predictably front-run; using block ID ordering with voting as the basis for selecting between two valid blocks guarantees this. If the forger tried to cheat the system by producing multiple blocks, the network may not be able to reach consensus on the block vote and the forger would not receive any block rewards.
- wcoenen 5y agoWhether PoS will work, I don't know. But the author didn't realize that PoW is certainly doomed. PoW miners tend to spend more and more resources on finding blocks, until the cost approaches the rewards. But the rewards go up as the cryptocurrency becomes more popular, because the price and transaction fees go up. Therefore, a PoW cryptocurrency tends to "eat the world" as it becomes bigger. That's why Bitcoin is already approaching 1% of global electricity consumption, if it hasn't passed that point already. If the price were to go up tenfold, then so would electricity usage (roughly). That's not sustainable, both technically for grids and economically because electricity prices go up. Because of that, I foresee two possible futures for PoW cryptocurrencies: 1. The resource usage overshoots and PoW collapses because it gets banned everywhere. (This seems to be playing out now with China having banned crypto mining, Kazakhstan running into grid issues because of the miner influx, and Sweden arguing for a ban in the EU.) 2. The popularity of these currencies stops growing and only some niche applications remain. Speculators leave because there's no more money to be made. Prices go down.
- keymone 5y agoIt’s a system with feedback loops, it’ll eventually level out at some equilibrium. You didn’t provide an actual argument for why it should definitely collapse.
- inter_netuser 5y agoSeems like he’s insinuating a global ban will occur.
- lukifer 5y agoInterestingly enough, as the ledgers are all public by nature, there would be nothing stopping states from forking blockchains into centralized solutions, outcompeting miners by reducing transaction costs to zero. Crypto-anarchists would lose their minds, but most consumers would probably pick whatever's cheapest and which "just works". Don't get me wrong, I love the politics of decentralization. But it's worth remembering that decentralization tends to be a cost-center, not a profit-center, from the standpoint of efficiency and performance; and decentralized tech is no guarantee of decentralized results (see Amazon/Facebook/Google, who have quasi-monopolies in their niches, despite being delivered over open and federated web protocols).
- perlgeek 5y agoI'm trying to understand the central technical argument being made here. Please tell me if I got this right. --- Somebody has a stake in a PoS crypto currency. They can now do two things: 1) sell their stake 2) sign something fraudulent (like a double spend). Since there is no decentralized timestamp service, a node validating those two actions doesn't know how to order them, so different validating nodes come to different conclusions, and no global consensus is reached. --- Is that what the article is trying to say? And if yes, isn't the solution fairly easy? Within the same "chain link" of the block chain, require each action singed by the same private key to have a strictly monotonic sequence number, and if two actions appear with the same sequence number, discard both these two and all actions signed by that private key.
- ComodoHacker 5y ago> have a strictly monotonic sequence number Then you lose decentralized property.
- perlgeek 5y agoNote that I meant a strictly monotonic sequence number PER PRIVATE KEY. This only means that each holder of a private key must have some sort of synchronization mechanism (if they use several agents/clients), but it doesn't centralize the whole network.
- meribold 5y agoI think another top-level comment (by csomar) answers your question: > you can sign a transaction later and have a lower timestamp, there is nothing that prevents you from that.
- DennisP 5y agoPoS does produce a reliable monotonic sequence, it's just that it doesn't go back to genesis. Every few months you need a checkpoint hash. The idea here is that this is rare enough so it's easy to find the accepted checkpoint out of band, like we pretty much do for client software already.
- tycoat 5y agoI was thinking deeply about the threat model in a PoS posed about coordinated pooling of resources to effectively mimic the size of a large institutional borrowers with high collateral, i.e. proof of work in the present economic system (US Dollars gathered by him by providing real world value). The main reason proof of work works so effectively is that it deals in physics with the actual expenditure of electricity as the punishment system for failing to produce the correct desired outcome. Abstracting this away again, we have reality itself to content with. Evolutionarily we have evolved in respect to the dominance hierarchy (https://youtu.be/rUiG5_GcMyY https://youtu.be/rUiG5_GcMyY) Where effort itself is a necessary precursor to ascending the ranks and being fit to lead. Not to get too metaphysical, but essentially it boils down to: - Social Status is based on real world implications and not self derived from the perceived ranking itself, that is if it is to be most stable across time. Being labeled the boss is essentially useless long term unless you truthfully represent the ideal or most capable individual. (Michael Scott from the television series The Office is a funny example of this) - PoS offers reliability for the system based on its election of stake amount in the system that favors inventors, early adopters, and pre ordained position holders where distribution was not derived from effort in the real world with non-reversible consequences (burning electricity) - Instead the selection mechanism its own value structure which may or may not accurately assess competence for reliable trust in a domain where zero-trust is key to consensus. - Outsourcing consensus to something mediated by the laws of physics is more stable across time, and is yet another abstraction upon competence taking it outside the realm of US Dollars for social proof, but also adding in the component of physical consequences towards the chain of proof. I'm also thinking as I write this that it would be important to consider changes in the environment as useful to the selection pressures. Why purely basing it upon success (stake) at one point in time is non-useful as the rules of the game may change, or reputation lost or abused in a PoS system would not accurately reflect changes in the need for rotation of positions of voting authority.
- williamtrask 5y agoPoW came from a paper by Cynthia Dwork (https://www.wisdom.weizmann.ac.il/~naor/PAPERS/pvp.pdf https://www.wisdom.weizmann.ac.il/~naor/PAPERS/pvp.pdf) not Hashcash
- optimalsolver 5y agoIt was independently discovered by Adam Back as Hashcash, and that was the proof-of-work algorithm Satoshi was familiar with.
- josephagoss 5y agoTezos is Proof of stake, decentralized and clearly has consensus, the three things the author argues cannot occur in a proof of stake system. I did not find this post convincing especially as many proof of stake systems have been running consistently for years now and with significant transaction and economic volume. As an example Tezos has decentralized apps such as liquidity pools, collateral based stablecoin systems, nft ecosystems, coin bridges to other networks such as Ethereum (two way) I use these smart contracts on a weekly basis and have done for a long time now. Tezos manages several orders of magnitude more transaction throughput based on opcode count count vs Bitcoin, transactions, even complex ones cost pennies the network has not been attacked, is worth billions and Tezos energy usage is easily a million times less than Bitcoin.
- SideburnsOfDoom 5y ago> the three things the author argues cannot occur in a proof of stake system. The author appears to be saying that "any decentralized consensus via proof of stake system is vulnerable to timing attacks" The counter-argument that "This here proof of stake system has not been successfully attacked ... that we know of ... yet" does not seem to be watertight.
- student2k 5y agoDecred witch is a dao focused on evolving with governance had an interesting block reward split, 60% miners, 30% pos (you get chosen randomly) and 10% tresuary. Seems miners have been driving the price down for years and a new proposal just was written to give them only 10%, and 80 to stakeholders. https://proposals.decred.org/record/427e1d4 https://proposals.decred.org/record/427e1d4
- nootropicat 5y agoAn intentionally dishonest article. The actual truth is that PoS is infinitely safer than PoW in the short to medium term, while theoretically weaker in the long term. A long-term attack would require first buying obsolete signing keys, which would stop nodes that sync starting from the pre-fork point from syncing - ie. a denial of service attack. Which is in a very weak threat, as online nodes wouldn't even notice it. A short to medium term attack would stop finalization for a while at an enormous cost of slashing. It's a denial of service attack because nodes would be able to see contradictory signing from the same keys - so while without out of band data they won't be able to decide which one is the commonly accepted chain, it's enough information to recognize than an attack is happening. PoW is very weak in the short term to medium term because runtime cost of attack is equal to mining rewards + epsilon, which is negligible, meaning it's just a question of hardware. Contrary to PoS, mining hardware is an external resource - it's always possible to get enough of it, given enough money (single digit billions for bitcoin). Getting 2/3 stake of a long-running PoS system is impossible - it's a scarce internal resource and there isn't enough for sale. Reverting years of blocks is indeed infeasible - but interestingly in practice it would also amount to a DoS attack, as everyone would notice it and pause all payments. Contrary to PoS, where it would only work on newly syncing nodes, it would stop everyone. However, while theoretically more expensive, it's still only a matter of money - while a long-run DoS attack against newly syncing nodes in PoS would require buying obsolete keys, which is very likely to be impossible in practice. Is this even an advantage? I don't think so, but it's arguable. However, for this singular arguable point PoW pays with a 4 orders of magnitude higher cost and a much, much weaker short and medium term security. Empirically, lower security of PoW is confirmed: multiple 51% attacks happened (most famously ETC), while even a much weaker DPoS coins never had a successful double spend attempt. In terms of public trust, not many people are able or even interested in technical arguments - they just observe if something works. In reality, consensus-level attacks are very rare as it's currently very hard to profit from them regardless of the consensus method, and the biggest danger is from software bugs in nodes, most likely unrelated to consensus. If any PoW blockchain became a foundation of global commerce, attacking it would become very profitable, or even a military target - but that's never going to happen. So I don't expect bitcoin to get 51% attacked in any near future - at best years in the future when value of block rewards is so low one person with lots of old mining hardware can attack it just for fun.
- jcpham2 5y agoI am a retired PoW miner and whereas on one hand I think proof of work is a revolutionary, life altering idea, on the other hand it is a self fulfilling apocalyptic premise with no endgame.
- dan-robertson 5y ago> To use an analogy, it is as if someone would sit down to design a building in the following way: first, they draw how they would like for the exterior to look. Then, they draw how they would like for the interior to look. They make basic measurements, to confirm that the interior does not exceed the exterior in terms of dimensions. They then suggest that the house is plausible, and send it off to the construction workers to build. For what it’s worth, this is how plenty of buildings are designed. Ignoring silly things like the inside not fitting in the outside, an architect may design the building and hand it off to a technical architect who works out how to make it stand up and has some back and forth with the architect modifying the design. At a later stage it goes to a structural engineer who will make sure that it really is likely to stand.
- theknocker 5y agoYet another post where the top comment is some dweeb selling a facile perspective and trying to be an activist. Great website, Dan.
- JohnJamesRambo 5y agoWhen you see articles like this, buy more Ethereum not less. It means they are scared of it.
- LittlePeter 5y agoWho is "they"? Why would they be scared of it? Did you buy more Ethereum after seeing this article? And if you did not see this article you would be still be buying Ethereum, but "less" right?
- JohnJamesRambo 5y ago“They” is Bitcoin holders, of which I will no longer be one by Dec. 1. Proof of work makes no sense anymore and proof of stake will take over with the launch of Ethereum 2.0 in 2022. I’m unbiased, this is just the market and math I see coming.
- qnsi 5y agoyou have money invested in Ethereum. Obviously you are biased
- X6S1x6Okd1st 5y agoPoW only works for the biggest chains that use the specific heading Algo. Smaller PoW chains regularly experience re-orgs. IMO PoW for the bigger chains produce far too much waste & none of the supposed PoS attacks have materialized even though hundreds of millions are up for grabs
- yholio 5y agoWhile the discussion about consensus algorithms is interesting and each side has good points, it should not be confused with the much more pertinent decision about simbolic currency (conceptually similar to fiat) versus proof of burned resources money (conceptually similar to gold). We should not confuse the two topics. It's entirely possible to have a chain where the consensus is established by PoW, yet the monetary base is created by decree without any wasted resources, for example gifted to some charities or dropped by helicopter to anyone who has a Twitter account. While the security PoW chains create is proportional to the amount of resources spent, there is absolutely no reason to think the current level of burn in Bitcoin is optimal - and strong reason to think that there is massive waste, that is, Bitcoin protects against double spend to a degree orders of magnitude harder than what a credible attacker might be willing to spend. What results is wasted energy that brings no tangible security to the users of the currency.
- echopurity 5y ago>If the same people own all the tokens, control all of the staking pools, the project governance, and run all the full nodes, an attack isn’t even possible. It’s so centralized, it produces the impression of decentralization from a distance. Yeah, crypto has never been truly decentralized. But that doesn't make people scammers, especially when this article is largely just quoting Vitalik.
- Magnusmaster 5y agoI don't understand the "nothing at stake" problem. Can't it be solved by just not allowing people to withdraw the coins they have staked?
- dcow 5y agoThe author suggests proof of space as an interesting option but then deliberately avoids commenting on Chia’s implementation of proof of space time. Can someone explain that to me? Is it the pre-mine that drives people away? If so there is already a fork (Flax) with a much smaller pre-mine that is surely worthy of assessment and scrutiny at an algorithmic/system level... Or is the author simply acknowledging they aren't ready or qualified to comment on PoST versions of Nakamoto consensus?
- otiose_tortoise 5y agoThis article completely misunderstands proof-of-stake and the distributed consensus space in general. Both proof-of-work and proof-of-stake are mechanisms for making distributed consensus sybil-resistant. Distributed consensus is the problem of getting a bunch of computers to agree on some state when some of the computers can behave maliciously. In the case of cryptocurrency, the state is a log of transactions, which when replayed tells you who owns what. There are well-known algorithms for distributed consensus, such as Paxos and Raft, that are used in real-world applications, e.g., the Chubby lockservice. Distributed consensus algorithms can be proven to reach consensus as long as at most a fixed percentage (e.g., 1/3) of the computers are behaving maliciously. This assumption is fine for applications like Chubby, where Google is running all 5 of the computers participating in the consensus, and no one can add additional computers. However, this assumption breaks down in the case of cryptocurrency, where anyone can spin up computers to participate. In fact, an adversary can effectively spin up an infinite number of computers. This form of attack is known as a sybil attack. Proof-of-work and proof-of-stake add sybil-resistance to distributed consensus algorithms by requiring the adversary to commit a scarce resource in order to participate in the consensus process. In the case of proof-of-work, the scarce resource is computing power. For proof-of-stake, the resource is the currency secured by the system itself. This may seem a bit circular, but it's fine. In order to attack the system, the adversary would have to purchase or borrow a bunch of the currency on the open market, which has an economic cost. Proof-of-work permits the same attack, where the adversary buys or rents computing power instead. From this perspective, the bitcoin consensus algorithm is in fact the odd one. Most distributed consensus algorithms (like Paxos and Raft) rely on some kind of voting system.
- dcow 5y agoThe main point the author is making is that PoS doesn’t require spending of any scarce resource on a per block level so the accuracy of the distributed clock is not to be trusted. I don't think they misunderstand their argument. You’re just not replying to it.
- dathinab 5y agoYou spend "safety of your stacked money while having stacked a lot of money" it's a scarce resource as if you over spend it you lose your money. And the more money you have stacked the less interest you have into braking the currency as it makes you lose that money.
- X6S1x6Okd1st 5y agoI'd expect we get more and more of these pieces as Ethereum gets closer to moving to proof of stake. The current estimate is that it'll transition 2022Q1
- wfbarks 5y agoDoes proof of history as implemented by Solana find a middle ground here?
- p2p_astroturf 5y agohashcash was not obscure even before bitcoin came out
- mgraczyk 5y ago> If you have a file on a computer, despite what NFT promoters believe, it is not possible to prevent people from copying it. Not sure if these quips are meant to be jokes or serious, but nonsense like this detracts from the credibility of the argument. Nobody believes the data corresponding to an NFT cannot be copied.
- Bjartr 5y agoPart of the problem of the NFT hype is that some people DO believe this to sure degree and believe that those redistributing the NFT content are somehow attacking the NFT itself.
- mgraczyk 5y agoShow me a single example of anybody claiming this in earnest (using a real identity, not a troll or stooge) and I'll delete my comment
- p2p_astroturf 5y agoThis article is terrible and does not explain how proof of stake works let alone how it's broken, but links to another (probably better article on etheruem.org). back to studying it for myself, then. I literally have a headache after reading the bitcoin analogy and trying to guess which parts of the analogy I will need to remember for later in the article (hint: none). It would have been simpler to just explain what a nonce and hash is.
- joshuajbouw 5y agoDeveloping PoS systems for 8 years, the research is completely dated on both old Bitcoin-like PoS and modern PoS. That, and the author has a wrong understanding of the Nothing at Stake problem. At the time, the argument was there was nothing stopping someone from staking on multiple forks to hedge their bet on the dominate chain, giving them nothing at stake on the forked branches since the get equal ownership on each chain. Mind you, Nakamoto consensus is pretty awful and completely ignored these days. Why do you believe that nodes flagged for support of protocols and miners with dominate hashrate LOST the big block debate? Because of the nodes, and community consensus.
- randomNumber7 5y agoDo you mind explaining what the author understands wrongly?
- neycoda 5y agoProof-of-stake is the closest thing to centralization there is in cryptocurrency.
- cblconfederate 5y agoI think what rubs a lot of people wrong about PoS is that it puts a name behind the validator and people don't trust people. One may claim that all validations require some level of trust, but it s the same reason why people trust google and not <person>'s link directory. And people have reasons to be suspicious because they know that when humans become actively malicious they find devilish ways to coopt others, while algoritms can just fail.
- hartator 5y agoWhy the change in HN title? "Proof of stake is a scam and the people promoting it are scammers" is clickbait for sure but it's the author own title and it is the subject of the article.
- mgraczyk 5y agoAfter reading this whole article, I find it really scary that something like this can get so much attention. It looks like the author read about PoS circa 2014 and hasn't read anything written or done since then. It's true that the "nothing at stake" problem exists, but there are tons of practical solutions and mitigations that work, many of which are already deployed and protecting >$100M. Soon ETH will be securing trillions with such mitigations. To address the specific points the author makes: 1. If a node signs another version of the same block within a reasonably short time period, “slash” their deposits (e.g. punish them inside of the system) You don't have to know which came first, just like in BTC. You just need a longest chain rule with the property that the longest chain is final after a certain point (subject to certain assumptions about the % of stake that is honest). This is how nearly every blockchain works and it's not special in proof of stake. 2. If a node signs another version of the same block, like, a year later, just ignore it. Yes, that's fine. Lots of chains do this. It's called a "finality mechanism". Even ETC has one called MESS while still using proof of work (although MESS is probably broken). Bitcoin could add one too. This is orthogonal to PoS vs PoW.
- naveen99 5y agoProof of work is good for jobs that require skill (science, technology, productivity, markets). It’s ok to have proof of stake (corporation shareholders) or proof of vote (communities, unions, families) for things that don’t require skill so much.
- yellowapple 5y agoThe author's objection to proof-of-stake seems to be based entirely on some ostensibly-inherent vulnerability to the nothing-at-stake problem, but at least one consensus protocol¹ has had explicit mitigations against that vulnerability (and numerous others) for almost half a decade now, and I'd be very surprised if other protocols haven't adopted any mitigations at all. ¹: https://eprint.iacr.org/2016/889.pdf https://eprint.iacr.org/2016/889.pdf
- shawnk 5y ago3000000000000000000000000000000000000000000000
- JanDietch 5y agoGet in touch with coinwalletrecoup . com to help you recover all your scammed funds. I got in touch with them when i was scammed by Tradestation to be precise, having deposited over $175,000 but still couldn’t withdraw any funds. They kept on telling me to deposit more to reach a certain amount but still couldn’t withdraw then it dawned on me that these people were playing games with my money. Within a week of contact, Coinwalletrecoup . com did the impossible, they recovered everything and also my ROI for the agreed duration of investment. Dont hesitate to contact them if you need any help. They’re the Best out there.
- puchatek 5y agoIt seems the author is confused about the meaning of the word "scam". PoS might not be as secure as PoW but that does not make the concept some sort of fraud.