19 ms·
(my day job is developer on Proof-of-Stake Algorand block chain, I'm a developer, this may not be polished official PR) Article's theory about malicious old blo
by brianolson 5y ago
(my day job is developer on Proof-of-Stake Algorand block chain, I'm a developer, this may not be polished official PR)
Article's theory about malicious old blocks doesn't hold up. Let's say I start a new node and verify history since the beginning. Somewhere along the line I'm connected to a malicious node which hands me a fictionalized block. It would need to have been signed by not just one but about 30-45 accounts _which had stake at that time_. Proof-of-Stake attacks aren't about having 51% of the CPU that overwhelms a Proof-of-Work system, but about having 60-70% of the _value_ in the network. So, if Warren Buffet comes along and wants to spam our network, I guess he could, but that would destroy the network and destroy his value that he sunk into the network. _That_ is a guardrail for PoS systems as much as any crypto or consensus-protocol element (and the algorithms are right, original article misunderstands them).
- kranke155 5y agoGlad to see an Algo dev here.
- ivalm 5y ago> but that would destroy the network and destroy his value that he sunk into the network Isn’t the whole point that by that time he would have withdrawn from the network so he would sink it without losing anything himself.
- dawnbreez 5y agoBut...if you no longer have value on the network, doesn't that mean you no longer have enough stake to control the network?
- inter_netuser 5y agoa coalition of wealthy interests can trivially dictate the consensus rules with very little to no recourse on your part. Even if the chain splits, they can maintain their share on both chains, and even suppress the minority chain. In PoW miners risk going bankrupt overnight for egregious behaviour like that. I'd like to see how one defines "slashing" programmatically that is impartial, works algorithmically, and does not have edge cases that can lead to catastrophic failures without handwavy assumptions that every single PoS network has today.
- dawnbreez 5y agoNo, no, back up a second. The argument being made in the parent comment is that once there is one entity with enough stake in the network to dictate where it goes, they can just pull out before tanking the network. But my understanding was that you can only have enough stake in the network to make decisions...by having that stake in the network. If you un-stake your crypto and cash out, by definition, you no longer have any stake in the network. If you no longer have any stake, how do you have a controlling stake?
- newaccount74 5y agoIf you had a controlling stake in the past, couldn't you just rewrite history to make it seem like you still have stake?
- delaaxe 5y agoYou can look up how Ethereum's beacon chain implements slashing
- inter_netuser 5y agoYep, isn't it great to get slashed for being DDoSed? Amazing breakthrough, realy. Now ddos blackmail can be actually measured in money. At least you could point to avalanche or something else that's better constructed. Eth is a dinosaur at this point, albeit with the fattest treasury.
- DennisP 5y agoIf you go offline the penalties are very small. You can be offline a third of the time and break even. The real penalty happens if you send conflicting messages, and even that's not too severe unless a lot of other nodes do it at the same time.
- rocqua 5y agoYou can fork far in the past, before you cashed out. Any new entrants into the network will not be able to distinguish your fork from the real chain. You cannot be slashed for this in the real chain because you already cashed out your stake there. This 'long range attack' is different from a 50% attack because it doesn't affect nodes that were running before the attack happened. But a situation where new entrants into the network are uncertain of the 'true' fork is not tenable in the long term. This seems more viable for a value destruction attack than for a double spend. But value destruction can be lucrative for blackmail. It means a coalition of stakers could withdraw their stakes and state "increases the blocksize or suffer a long-range attack".
- bastiantower 5y agoWouldn't anyone then be able to provide proof of that participant having exited? The participant would have generated a signature the moment they exit.
- jaggirs 5y agoBut why would a new entrant get the chain from a node that already exited, and why would this affect anyone other than the entrant itself? I assume the new entrant is itself liable if it copies the wrong chain, because other nodes will vote against it once it starts operating, so it will make an effort to get the correct chain (maybe by buying it from current nodes and ensuring they all provide the best chain). So maybe you would have some kind of cartel of running nodes that may or may not allow new nodes to enter, but I don't see a critical network-destroyig issue here.
- dlubarov 5y ago> But a situation where new entrants into the network are uncertain of the 'true' fork is not tenable in the long term. This is an important point to consider, but it can be mitigated with exit delays. E.g. with Eth2's current settings, if an attacker had 2/3 stake at one point, I believe it would take them 6-7 months to exit all those validators. So while it's true that new entrants must sync from a trusted checkpoint, the checkpoint can be quite old. Let's say my client has a hardcoded list of checkpoints, with a new one added once a month. The client would only accept forks containing all of those checkpoints in their history. It seems like there are two ways an attacker with commit access might try to corrupt this checkpoint list. First, they could try to add bad checkpoints over a period of 6-7 months, until they've fully exited and can safely perform a long-fork attack. This seems impractical, since the bad checkpoints would be noticed by existing node operators (who would get stuck after upgrading their clients), and 6-7 months seems like plenty of time to raise the alarm. Alternatively, an attacker could just delete 6+ good checkpoints, and replace them with 6+ bad ones, all at once. This would violate the convention of adding monthly checkpoints, so it should be easily recognized as a malicious change. One could argue that it might go unnoticed anyway, but sneaking in such a change seems roughly as hard as sneaking in any other clearly-malicious client change.
- inter_netuser 5y agoPoS is Plutocracy on Steroids. You've outlined only one, the most obvious and least probable, mode of failure. The more subtle and wildly prevalent failure mode is that the consensus will be set by the few whales, who will maximize their rent extraction at the expense of numerous small players, which will include most later adopters, aka the entire population of Earth. It's already visible on smaller scale in DAOs, every vote resembles a banana republic: "90% voted, 90% in favour". No matter what smaller stakeholders do/say, the early big investors and dev team always win. Why would they structure it otherwise? The same dynamics exist in PoS, just not as grotesque. Perhaps that's OK for a private company governance, but for a global currency? You want the multibillionaires to dictate the properties of the medium of exchange that serves the entire globe? Seems rather strange that so many have such a burning desire to be governed by someone much richer than them.
- turbinerneiter 5y agoHow is that different from PoW or our current political system?
- inter_netuser 5y agominers go bankrupt in PoW for misbehaving. Large stakers can be rewarded for misbehaving, at your expense.
- jack_pp 5y agoThey only go bankrupt if they don't hold the majority of the mining power, if they do they take over. How is this different from PoS? Actually in PoS if you try to attack and you don't have a majority you will lose all your coins. in PoW if you try to attack and somehow you miscalculated you will lose a couple of hours worth of electricity after which you can go back to mining normally so much lower stakes for an attack.
- viro 5y agoBecause money can't literally buy votes. no matter how many ads you show me I would never vote for Trump.
- locallost 5y agoCharlie Munger is on record saying he hates crypto. I doubt Buffet is far off. How many billions would they need to sink into destroying something they hate?
- DonHopkins 5y agoDo you work on HEX for Richard Heart? As a POS developer, what do you think of HEX and Richard Heart (whose real name is Richard J Schueler)? If you don't work on HEX, how is your POS get rich quick pyramid scheme any better or more trustworthy than HEX? If you do work on HEX, then please ask Richard to drop by, join the discussion, and answer the questions below (to which he replied "Dodge Dodge"), and any other questions the HN community wants to ask him: https://news.ycombinator.com/item?id=29367412 https://news.ycombinator.com/item?id=29367412
- keymone 5y agoI don’t investigate every shitcoin out there, but all of them have the same flaws in general. Your particular shitcoin probably has something called voting quorum, where only a fraction of global supply is required to proceed in staking. By reducing that fraction you’re making large stake holders more and more able to overpower all others the moment they decide to become malicious. In PoW all hashrate is always voting and security is paid for external expenditure, not something virtual within the system. PoS is a scam and you should stop supporting it.
- prepend 5y ago> if Warren Buffet comes along and wants to spam our network, I guess he could, but that would destroy the network and destroy his value that he sunk into the network Not if he’s undetected and does it for years while extracting value at key points in time. There are numerous people who could put up $50B with the ability to get very high returns. It’s not even worrying about Buffet. I worry about hedge funds and sovereign wealth funds that would definitely manipulate PoS if it earned enough for them.
- xorcist 5y agoThis explanation does not make sense to me, which is probably due to my lack of understanding, but perhaps you can expand on this: > about 30-45 accounts _which had stake at that time The this is stated makes it sound difficult. But if this is false history presented by a malicious node, surely they could make up anything, as it the data does not need to line up with any official history at any point. (Without a trusted party, no history line is really offical anyway, is't it?). Constructing a history with 30 accounts with stake at any given point in time isn't any harder or easier than constructing 3 or 3000.
- rictic 5y agoWith Ethereum at least, it's proof of work leading up to proof of stake, so you'd have to break proof of work to create a fake early history, so the initial stake has to be legal within the proof of work history of Ethereum. Unsure how pure PoS chains work, maybe they hard code an early block's hash? Like, it's not a legit xorcist-chain unless block #10 has hash #deadbeef
- comex 5y agoThe history still needs to be signed by former stakers to be valid. The "nothing at stake" problem is that a staker might break the rules by signing two mutually incompatible histories. During the staking period, they are strongly disincentivized from doing this because anyone can present proof that they've done so, causing the network to punish them by taking away all the funds they staked. But once that period expires, they can send those funds to someone else, and now they can't be punished. Someone who's sent away their funds is longer a staker moving forward, but they can still sign an alternate history for the time when they were a staker, potentially fooling clients who haven't connected to the network for a long time. In practice, among the people who once staked large amounts of a proof-of-stake currency, most of them will probably continue being invested in its ecosystem moving forward. Even if they can't be personally punished for lying about the past, a successful history split would likely reduce the community's confidence in the currency, and thus its market value. Most of those people are also emotionally invested in the ecosystem and would not want to dishonestly subvert it. There will be exceptions. But to create an alternate history you need to subvert not just one validator, but most validators (or rather, validators who together control most of the currency being staked).
- SilasX 5y agoI just read most of the article. As I understand it, the failure mode isn't that one attacker could hand you a malicious node, it's that the network doesn't actually reach unambiguous consensus -- all/most "stakers" could simultaneously be signing a different transaction history the whole time, at virtually no cost, which is just as valid as "the" one you believe in; there's no (cryptographic) way to distinguish them. And so it's possible for, one day, the whole network to get pulled out from under you. "Nope, this other one is the real deal." Is this a problem in practice? As the article says, no ... but only because there is a sort of vaguely specified "proof of authority" that backs the current chain, which actually just reintroduces centralization. The author cites the Bitcoin Cash and DAO/ETH Classic forks as cases where that proof of authority gets tested and shows the actual centralization. It's my understanding that Algorand has something on top of pure PoS that ensures the consensus (which the article says is necessary) so I'm not sure the same criticism is applicable there, but can't comment further until I get more familiar.
- evergrande 5y agoWhat if Buffett just wants to see the world burn and doesn't care about getting the money back out? Or if a nation state or the central banks see it as an existential threat, they could consider it the cost of doing business? Maybe $30B to take out Algo or Solana and destroy trust in all PoS networks? That's a rounding error for them.
- ertian 5y agoIt's a temporary state, until the PoS coin market cap gets too large to be attackable. Bitcoin's market cap is in the 1T range now, Ethereum is close to half that. Buffet couldn't do a thing against a PoS coin that large, and it would be a serious commitment and risk even for a nation state. Buffet could take down some random smaller coin, maybe, at the cost of most of his personal fortune, but if he did so the world would not burn. It's _possible_ that a government might choose to attack a random small coin just to discredit the notion of PoS cryptocurrencies, but it's hard to picture a government gaining consensus to do it, and it would be obvious to knowledgeable onlookers that larger coins are immune (or anyway, much better protected), so the resulting disruption would probably be temporary.
- bitcurious 5y agoPoS encourages centralized exchange-held staking, which means that there are only a handful of failure/pressure points. In other words, a government doesn’t have to buy 66% of the stake - merely compel the exchanges.
- yellowapple 5y ago> PoS encourages centralized exchange-held staking Not when the protocol actively encourages decentralization by cutting off staking rewards to larger pools, like what Cardano does (as one example). Sure, the exchanges can (and probably do) run multiple pools, but so can anyone else, and for far less expense than is required for mining.
- EthanHeilman 5y ago> Or if a nation state or the central banks see it as an existential threat, they could consider it the cost of doing business? Maybe $30B to take out Algo or Solana and destroy trust in all PoS networks? That's a rounding error for them. While you are correct that burning $30 billion dollars to destroy trust in PoS blockchains isn't that much money, I disagree that such an action would actually destroy trust in PoS blockchains. We have seen serious attacks on a number of blockchains, Ethereum for instance had enormous amounts of money stolen or destroyed via weaknesses in the blockchain. Yet Ethereum is still going strong. Bitcoin suffered 51% attacks that were used to perform double spends and Bitcoin is more valuable than ever. It might be cheap to burn $30B to destroy a blockchain, but what if you burn $30B and the blockchain recovers 12 hours later.
- cs702 5y agoI would add that the silly argument that a super-wealthy individual or a government could in theory degrade or destroy a transaction platform is applicable, not just to Algorand and other block chains, but also, more generally, to ANY transaction platform. I mean, if Doctor Evil suddenly decided to spend tens of billions of dollars to destroy the three main credit card networks, he could probably do it. In fact, it might be easier and cheaper than attempting to degrade or bring down a distributed block chain network. The credit card networks are built upon many layers of ancient, pre-Internet technology, full of discoverable vulnerabilities and critical points-of-failure. But we all know that it wouldn't happen. Doctor Evil would never want to do so, because even him, the most evil person in the world, would still want to be able to use his credit cards to eat out, go to the movies, and order stuff online. Also, he would never want to do something that would make him enemy #1 of every other person in the planet, including every other super-criminal! What Doctor Evil actually wants to be able to do is figure out ways to steal or get balances from participants in the network without destroying the network: steal poorly protected wallets, hack into poorly secured exchanges, find ways to get blackmail payments on the network (e.g., by launching DoS attacks on the web), etc. The network itself is too useful to everyone for anyone to want to destroy it. -- PS. For the record: I have no economic connection to Algorand the block chain nor to Algorand the company, but I'm (superficially) familiar with some of Silvio Micali's past work and also, I know one of the company's top executives. In my judgement, the Algorand block chain has great technology, and Algorand the company has really great people. Their main challenge, as I see it, is overcoming the powerful network effects already accruing to other block chains.
- cblconfederate 5y agohe would in case of war
- teawrecks 5y agoIMO people listing things that discourage an attack (people will hate him, his credit cards won't work, etc) are just people trying to comfort themselves. It's like saying, "No one would break into my home because they might hurt themselves breaking in, or I might hurt them up, or they might get caught by the police and go to jail. It's just too risky." At the end of the day, Dr. Evil will gladly spend 10s of billions to destroy the network if doing so nets him 100s of billions. Stop listing reasons people won't attack the network and start listing reasons they would.
- sidiropo 5y agoThe Algorand PoS consensus protocol assumes that honest nodes use so-called "ephemeral keys" (see Section 5.2 of the white paper). This implies they are supposed to "forget" part of their past state. A malicious node could choose not to forget their past state, thus making double-spend a possibility (assuming an adversary with majority of stake). Therefore, the formal proof of security provided in the Algorand white paper does not resolve the nothing-at-stake problem, which is inherent to all PoS systems.
- akrymski 5y agoBy this argument the only real consensus mechanism we need is FAITH. In PoS we trust. As long as a sufficient number of people believe some currency has value - it has value. If they don't believe, it doesn't have value, and the stakes are worthless too.
- yanmaani 5y ago> Article's theory about malicious old blocks doesn't hold up. I don't mean to be rude here, but none of what you have said refutes my point. The attack here is that you control keys that (1) once held 67% of the value, and (2) no longer do. Because they did hold value once, they are dangerous to consensus. Because they no longer hold value, nothing is sunk into the network, so the attacker bears no cost or risk. To apply your analogy: I don't have to be Warren Buffet, I just have to riffle through his trash.
- Zamicol 5y agoImportantly, if "Warren Buffet comes along and wants to spam our network" his bad actions would be tied to addresses that can be blacklisted. You can't do that with PoW without "additional" consensus rules, which is that slippery slope to PoS!