3 ms·
I was thinking that one of the PoS papers might fit, but the Tendermint paper was 2014, and the Casper FFG paper was 2017. Do you think Groth16 counts? So name
by px43 3y ago
I was thinking that one of the PoS papers might fit, but the Tendermint paper was 2014, and the Casper FFG paper was 2017.
Do you think Groth16 counts? So named because it was written by Groth in 2016. Groth16 introduces the first really practical zero knowledge proving scheme. I'm pretty sure it's used by zcash as well as Filecoin, and projects like Tornado cash. It opened the floodgates on verifiable computation techniques that are used for everything from scaling to privacy.
Every year there's a ton of braindead noise, obviously, but every year there are also fundamental breakthroughs that change how we compute.
Actually, specifically because of Groth16, the "world computer" concept is becoming more and more possible every day. When you have verifiable computing, you shift the paradigm from every node on the network having to verify every state transition to any given state transition only needing to be verified by one machine somewhere in the world, once (which can be done in parallel with the proving of every other state transition). This means something like a blockchain network is now only limited in scale by how much compute you can throw at it, and as the algorithms get faster, and the compute gets better, we're seeing multiple orders of magnitude throughput increases every year. Things have been getting pretty wild in the cryptocurrency space for the past couple years, and the future looks insane.
edit: For people interested in diving into WTF "verifiable computing" is, this is a really awesome project that does some cool stuff with it that I'm not affiliated with in any way : https://github.com/risc0/risc0 https://github.com/risc0/risc0
- debarshri 3y agoAre you from 2021? Because in 2023 the landscape has literally been obliterated to say the least. P.S I think "global computer", "verifiable computation" are a make believe concept if you ask a computer scientist. Sounds good on paper and feel futuristic though.
- n4ru 3y ago>he doesn't know
- mhluongo 3y agoZK cryptography is still relevant today, regardless of how you feel about cryptocurrencies. I don't think cryptographers believe it's a "make believe concept", at least not the ones I know.
- SkyMarshal 3y agoComputer scientists don’t believe verifiable computation is make believe, it’s real and here now, and all of the ones working in cryptography or adjacent fields know it. It’s only the rest of the mainstream business world that hasn’t yet caught on to the value it can provide. There are numerous good ideas for using it in business contexts that aren’t being done yet. It’s mainly the cryptocurrency ecosystem that grokked its value first and have been rapidly deploying it into production.
- 3np 3y agoFirst line: Sure. Second line: No way. Very little of the cryptocurrency ecosystem and industry actually do verifiable compute in any meaningful sense. A lot is API calls to third-party trusted services (who are probably doing that, yes).
- px43 3y agoSince October 2020, the entire future roadmap of Ethereum, the second largest cryptocurrency, has been heavily based on verifiable computation, in the form of rollups. https://ethereum-magicians.org/t/a-rollup-centric-ethereum-roadmap/4698 https://ethereum-magicians.org/t/a-rollup-centric-ethereum-r... In 2023 alone, maybe 5 or so fully functional proving systems for running verifiable compute in the Ethereum Virtual Machine have been launched, and are currently live and operational. It's still early days, and there's a lot more work that needs to be done to fulfill the vision, but progress is happening faster than anyone expected.
- SkyMarshal 3y agoYes, and there are other blockchains purpose-built around verifiable computation like ZCash and Mina.
- 3np 3y agoHow many actually do that and how many just make HTTP calls to SaaS providers? It only means anything if you run your own node and/or actually implement or at least use verifiable compute code.
- px43 3y agoHa, I started using Bitcoin in 2009. There was maybe a three month mania back in 2021 where everything was valued 3x higher than it should have been, and now we're back to the mean. The idea that a 60% dip from ATH is "obliteration" is pretty laughable. Verifiable computation doesn't require your faith. It works, and it's powering several billion dollar economies at the moment, and growing like crazy. By all means you're free to demonstrate that the math is faulty. Basically every project in that space has a million+ dollar bounty program for such bugs.
- JanisErdmanis 3y ago> Verifiable computation doesn't require your faith Isn’t it so that in general verifiable computation needs a trusted setup phase? Although it can be run between multiple parties, still one needs to have faith in their honesty. Only a small subset of computations does not require a trusted setup phase. Proof of shuffle and threshold decryption comes to my mind as examples.
- madars 3y agoI'd call Pinocchio [PGHR13] the first truly practical zk-SNARK and Groth16 close to being the endgame of pairing-based SNARKs. The difference between earlier constructions and Groth16 (in proof size/prover complexity/verifier complexity) is less than 2x: https://github.com/scipr-lab/libsnark/blob/master/libsnark/zk_proof_systems/ppzksnark/README.md https://github.com/scipr-lab/libsnark/blob/master/libsnark/z...
- matthewdgreen 3y agoWe academically wrote (2014) and then deployed Zcash (2016) using PGHR13, and then later Zcash upgraded to a better circuit that used Groth16. It was, to my knowledge, the first production system to use SNARKs, and “modern” systems like Tornado Cash Nova use basically the same ideas. ETA: I just noticed I'm responding to Madars ;)