26 ms·
He lost me at the part where he thinks you can sign messages after withdrawing your stake. The whole point of proof of stake is that you can only sign blocks o
by darcys22 5y ago
He lost me at the part where he thinks you can sign messages after withdrawing your stake.
The whole point of proof of stake is that you can only sign blocks or messages while you have something staked. When you withdraw you are no longer allowed to sign anything.
He also didnt need to spend 1000 words going on about the history of bitcoin and proof of work.
This is literally just a filler piece with a provocative clickbait title to stir up the anti cryptocurrency folks here
- inter_netuser 5y agoYou can withdraw your stake. Withdrawing a gigawatt plant and a silicon foundry is a little more involved, you see.
- yanmaani 5y ago> When you withdraw you are no longer allowed to sign anything. Allowed to by whom? Who's to punish me if I disobey them?
- michaelsbradley 5y agohttps://github.com/ethereum/annotated-spec/blob/master/phase0/beacon-chain.md#aside-randao-seeds-and-committee-generation https://github.com/ethereum/annotated-spec/blob/master/phase... After withdrawal is completed, your node would no longer be in the set of active validators and from that time could not validly propose a block or submit an attestation (or, more accurately, be selected as a block proposer, etc.)
- yanmaani 5y agoYes, "validly" being the operative word here. I can still propose blocks invalidly, you see. And then someone who doesn't already have the consensus (e.g. trying to sync) will have no way to tell which is legitimate. This is the problem - you can't look at what the system does when everything's working as it should, you have to look at what happens when it's outside of the comfort zone.
- michaelsbradley 5y agoEven a relatively light reading of the Annotated Specs for Eth2[1] and/or the Eth Org's Proof of Stake FAQs[2] suggests the designers (and independent implementer-teams who gave feedback to designers, who gave direction to the implementers... lather, rinse, repeat) understand it's important to consider the overall system "outside of the comfort zone". [1] one such: https://github.com/ethereum/annotated-spec/blob/master/phase0/beacon-chain.md https://github.com/ethereum/annotated-spec/blob/master/phase... [2] https://eth.wiki/en/concepts/proof-of-stake-faqs https://eth.wiki/en/concepts/proof-of-stake-faqs
- seniorsassycat 5y agoI think the argument was that you could withdraw at 201 then sign new 200b messages.
- bastiantower 5y agoBut then everyone has a signature that you exited at 200
- runeks 5y agoWhich you don’t include in your alternate chain.
- mlyle 5y agoThe argument he's making is, you could stake for blocks 10000-10005 and get your money back. And then produce a big fake chain from 10,002 (in the middle of the time you were staking) -> 10,000,000 later, with an alternate history in which you didn't stop staking. I don't think this attack is particularly realistic for a lot of reasons, but PoW does have some small amounts of additional strength against these scenarios.
- tsimionescu 5y agoI think the biggest problem with his whole argument is when he wants to give some examples of community consensus being a problem, and gave examples from the PoW world (Bitcoin small block size decision, Ethereum bhard fork) - that to me complety destroyed his own argument that PoS is more community-dependent than PoW.
- lilyball 5y agoThose two examples were demonstrating what happens when you don't have provable consensus. They weren't issues with the validity of the blockchain, but debates over changing the software itself. They're good examples of why centralized development of a decentralized protocol still opens up the software to attacks (though with the option of continuing the blockchain without the software change, as Ethereum Classic did for a while), and demonstrates why having a provable consensus mechanism is important.
- lilyball 5y agoWhat do you mean by "allowed to"? In a PoW system, the PoW is a distributed timekeeping device. That's the actual operation the PoW does, and the distributed timekeeping is then what you can build a blockchain on. PoS doesn't not do distributed timekeeping. If you sign a block now, then go back later and sign a different block with the same key, there's no distributed clock that can be used to prove which was actually signed first. The obvious argument here is "the one that was signed first will then have other blocks built on top of it". But since there's no PoW, building a parallel blockchain is trivial to compute, the only restriction is being able to produce something that's actually convincing enough. That and having people say "well, I was there at the time and I saw a different block than this", but that's just relying on authority rather than something that can be proven within the system. Basically, PoS requires something external to the system to prove that history hasn't been changed. PoW technically does too, but what it relies on is "physics" and "provable historical fact" (i.e. approximate computing power available in the past). You certainly can build a system that depends on something external to itself to ensure its consistency, but this challenges its claim to being "decentralized" and limits the amount of trust you can place in the system (and consequently the power of what it can do).
- light_cone 5y agoThe clock issue is an excellent point, but the ethereum PoS have a nano scale PoW mechanism for this exact problem. Look at VFD "Verifiable Delay Functions" [1]. In short: If you take the pbkdf2 key derivation function: its job is to slow down hashing a thousand fold or so, so that hashing an entire search space becomes impractical. You give your secret in input, and it gives you a hash, let's say, in 1 second. You'll have to spend the time again to recompute the hash. With a faster machine, you can compute in maybe 100ms, but still, there is a limit in how fast you can obtain the result. Now change the cryptographic properties of pbkdf2, so that you can go back from the output to the input in constant time, so you can find the secret from the hash in O(1). Then, it becomes useless for actual secrets, but you now have an instantly verifiable proof that a certain amount of time (or serial computation) had to pass to get from the input to the output. Plug the input to the previous block hash, and embed the result in the next block, and you have your clock, based on physics and provable historical facts. [1] https://vdfresearch.org https://vdfresearch.org
- globular-toast 5y ago> When you withdraw you are no longer allowed to sign anything. But I didn't withdraw my stake. I have a whole chain of blocks saying I never withdrew anything and it's perfectly valid because I signed it, and I still have a stake. Oh, you have another chain that says I did withdraw? Who are we going to believe? Who was first?
- darcys22 5y agoOn the ethereum chain you get slashed (on both your chains) for signing two messages.
- crazypython 5y agoSigning is a cryptographic operation. You can still sign a block after you don’t have something staked. People won’t accept that signature unless you have something currently staked. But then the question arises- who decides who withdrew their stake? Other stakers?