4 ms·
> the "nothing at stake" issue inherent to proof-of-stake systems The "nothing at stake" problem was inherent to proof-of-stake more than six years ago. It has
by 0x64 4y ago
> the "nothing at stake" issue inherent to proof-of-stake systems
The "nothing at stake" problem was inherent to proof-of-stake more than six years ago. It has, since then, been solved on Ethereum (and Polkadot) with Slasher, which is a penalizing system that burns (a portion) of the stake of malevolent actors, and then kicks them off the consensus layer.
Ethereum's consensus layer has been live for 1.5 years now, and there have been 175 slashing events during that time [1]. Some have been misconfigurations by small pools, others have been caused by users running their keys twice on two different machines (causing double attestations and double block proposals).
[1] https://beaconcha.in/validators/slashings https://beaconcha.in/validators/slashings
- ShamelessC 4y agoLong range attacks likely exist on any implementation. It has not been "solved", the buck has simply been passed to more motivated adversaries. https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=8653269 https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=8653269 The most effective mitigation mentioned in the paper is the use of a "trusted" CPU module such as the Secure Enclave in Apple devices. Suffice to say, that's probably not going to see widespread adoption anytime soon and doesn't consider the other security problems inherent to such enclaves.
- deleted 4y ago[deleted]
- dlubarov 4y agoWhat they call "moving checkpoints" is a pretty widely-accepted mitigation to long-range attacks. Checkpoints might seem like a security issue, but it really depends on how recent they need to be (which is a function of staker exit delays) and the process for discovering checkpoints. E.g. most blockchain clients come with a genesis state baked in, which is effectively a (very old) trusted checkpoint. Someone could try a long fork attack by changing the genesis, but the attack would be obvious from the git history. (Many users might still not notice, but that goes for any attack on the client codebase.)
- ShamelessC 4y agoThe paper I linked discusses moving checkpoints.
- dlubarov 4y agoYes that's why I used their term. It doesn't say much about it though. The Ethereum Wiki [1] has a much better discussion of its security implications IMO. But my point is mainly that moving checkpoints is the standard solution to long forks, so a discussion about PoS security should probably focus on that, vs theoretical alternatives like trusted hardware. [1] https://eth.wiki/en/concepts/proof-of-stake-faqs#what-is-weak-subjectivity https://eth.wiki/en/concepts/proof-of-stake-faqs#what-is-wea...