6 ms·
This article completely misunderstands proof-of-stake and the distributed consensus space in general. Both proof-of-work and proof-of-stake are mechanisms for m
by otiose_tortoise 5y ago
This article completely misunderstands proof-of-stake and the distributed consensus space in general. Both proof-of-work and proof-of-stake are mechanisms for making distributed consensus sybil-resistant.
Distributed consensus is the problem of getting a bunch of computers to agree on some state when some of the computers can behave maliciously. In the case of cryptocurrency, the state is a log of transactions, which when replayed tells you who owns what. There are well-known algorithms for distributed consensus, such as Paxos and Raft, that are used in real-world applications, e.g., the Chubby lockservice.
Distributed consensus algorithms can be proven to reach consensus as long as at most a fixed percentage (e.g., 1/3) of the computers are behaving maliciously. This assumption is fine for applications like Chubby, where Google is running all 5 of the computers participating in the consensus, and no one can add additional computers. However, this assumption breaks down in the case of cryptocurrency, where anyone can spin up computers to participate. In fact, an adversary can effectively spin up an infinite number of computers. This form of attack is known as a sybil attack.
Proof-of-work and proof-of-stake add sybil-resistance to distributed consensus algorithms by requiring the adversary to commit a scarce resource in order to participate in the consensus process. In the case of proof-of-work, the scarce resource is computing power. For proof-of-stake, the resource is the currency secured by the system itself. This may seem a bit circular, but it's fine. In order to attack the system, the adversary would have to purchase or borrow a bunch of the currency on the open market, which has an economic cost. Proof-of-work permits the same attack, where the adversary buys or rents computing power instead.
From this perspective, the bitcoin consensus algorithm is in fact the odd one. Most distributed consensus algorithms (like Paxos and Raft) rely on some kind of voting system.
- dcow 5y agoThe main point the author is making is that PoS doesn’t require spending of any scarce resource on a per block level so the accuracy of the distributed clock is not to be trusted. I don't think they misunderstand their argument. You’re just not replying to it.
- dathinab 5y agoYou spend "safety of your stacked money while having stacked a lot of money" it's a scarce resource as if you over spend it you lose your money. And the more money you have stacked the less interest you have into braking the currency as it makes you lose that money.
- SilasX 5y agoBut it’s not a scarce resource you spent. As the author says, you can sign multiple, contradictory stakings.
- dathinab 5y agoWhich can (likely will) make you lose all the stacked money.
- SilasX 5y agoThe article addresses that in the section starting: >>Therefore, once they have withdrawn their deposits, they are untouchable. This is the “nothing at stake” problem. There will inevitably come a point when a node is free to liquidate their entire stake and cash out. And later concludes that, In order to know which is the valid staking, you have to already have a decentralized mechanism for ordering transactions, which was the problem to begin with.