14 ms·
How Monero’s proof of work works
- residentzero 5mo agoRandomX has some interesting use cases beyond Monero RandomX in Javascript (web mining?) https://github.com/l1mey112/randomx.js/ https://github.com/l1mey112/randomx.js/ Bitcoin with RandomX (agentic cash?) https://scashnetwork.org/ https://scashnetwork.org/ https://miningpoolstats.stream/satoshicash https://miningpoolstats.stream/satoshicash
- dgacmu 5mo agoIf folks are interested in the old Monero PoW function (and, uh, the reason they changed it), I wrote up a thing about it a long time ago: https://da-data.blogspot.com/2014/08/minting-money-with-monero-and-cpu.html https://da-data.blogspot.com/2014/08/minting-money-with-mone... The history of people trying to design GPU or ASIC-resistant proof-of-work functions is long and mostly unsuccessful. I haven't looked into RandomX; it's possible they've succeeded here (or possible that with the alt-coin market mining profitability tanking after Ethereum moved to proof-of-stake, it just wasn't worth it).
- alcazar 5mo agoThis was a super interesting read, and it highlights exactly the strength of cryptocurrencies. They turn game theory in their favor, so egoistic players (I don't mean this in an offensive tone) contribute to making it stronger and safer for everyone else. Thank you for sharing!
- dgacmu 5mo agoThey kinda do - I'll admit honestly that the final game I played in the cryptocurrency space I played solely to profit. (It was a minor, uh, **coin that didn't have a lot of redeeming value to start with). Though it turns out the incentives remained somewhat aligned: I ended up providing the developer with some security bug fixes to make sure someone couldn't mess with the cash cow. :) (To be clear: We were just optimizing mining; in the process of looking for ways to mine it faster, I found some security bugs and fixed them. We weren't exploiting the bugs, that crosses a line for me.)
- AureliusMA 5mo agoThere was a proposal on Ethereum that didn't succeed (progpow) since they were already in the late stage of transitionning to PoS. Ethereum did quite a good job at keeping asic advantage moderate (the speedup was 100% max - not orders of magnitude). RandomX is basically progpow that succeeded. You might be interested in Chia's Proof of Space and Time... and how it collapsed!
- hyc_symas 5mo agoProgPow was ridiculously simple and would never have accomplished its goal. I covered it briefly in my Monerokon talk as well.
- idiotsecant 5mo agoI don't know if PoW based approaches make much sense in the modern environment, anyhow -even very clever ones that provide ASIC resistance. Ethereum has been doing real proof of stake (and not delegated proof of stake which is both easier and terrible from a system safety perspective) for quite a while and it's seemingly cheap, effective, and robust.
- hyc_symas 5mo agoPoW is useful in far more situations than PoS. A derivative of RandomX is now used to protect TOR too (Equi-X). https://github.com/tevador/equix/blob/master/devlog.md https://github.com/tevador/equix/blob/master/devlog.md
- idiotsecant 5mo agoYes I suppose it's difficult to stake something of value when the system you're securing is not stapled to a currency.
- jancsika 5mo ago> You might be interested in Chia's Proof of Space and Time... and how it collapsed! Because it was written by Bram Cohen, I'd be interested in reading two or three sentences about how it collapsed. Because it's a blockchain-based cryptocurrency, feel free to stop writing after three or four sentences.
- tardedmeme 5mo agoRandomX is designed so that if you design a RandomX ASIC then you've designed a CPU. It writes and then executes random programs. To minimize the possible efficiency gains from matching the instruction set architecture, the same program is executed several thousand times, reducing the relative overhead of translating it to a different ISA.
- ProllyInfamous 5mo agoI partially heat my home by running the default Monero client on old Xeons (heat ejects near my desktoes). As I only mine when it's cold outside (otherwise using resistive heating), there is no actual net electricity cost. IMHO it's not "worth it" for an individual to buy equipment specifically to mine crypto... but if you already have an old machine AND you heat without a heatpump, it's a free hobby/heater. ---- To anybody else that is syncing a fresh monero blockchain copy (i.e. installing the official client), I recommend using the custom node flag ` --db-sync-mode safe ` — which is slower but corruption-avoiding — before node's initial bootup. Without safemode, any halt of the client will [most likely] corrupt the local blockchain (losing days of DL/verification). Also, if you use an SSD for storing any blockchain (as recommended by monero team... but not by me), know that its lifespan will be greatly reduced from the constant IO/access. Personally, I recommend safemode (see above) on a 7200RPM spinner (HDDs effectively don't wear during IO/access). ---- What are your thoughts on running xmrig vs. the default getmonero.org client? Would you in general agree that monero remains ASIC-resistant?
- hyc_symas 5mo agoJust use a Linux laptop with a working battery so you never have to worry about power outages or other system crashes. In that case, you don't need safe sync mode, and you don't have to kill your SSD.
- ProllyInfamous 5mo agoWorking battery ≠= avoiding system crashes | my local node has a UPS, and still Monero's client is dicey (Mac & Linux distros). Particularly on its initial sync, Monero's daemon is flakeyAF. If you (e.g.) don't allow `sync in background` (why is this not the default behavior?!), the official Monero client is notorious for locking up on wakeup. Once you kill the process, your local blockchain is [most likely] unusable. Another reason to use safe-sync is (e.g.) if your system (Linux or whatnot) decides to update/restart during the several days it takes to sync-initially. ---- Just out of curiosity, why do you abuse an SSD so (safe-mode, or not)? For SSD-diehards, I'd recomment getting a very large size because this'll last longer, presuming the drive self-levels.
- tomjen3 5mo agoThey had to design a specialized verification function, which I imagine would be the easy way to break it. The brilliant part of Bitcoin is that it uses very widely known crypto primitives - verification is the same as getting the right seed (you just happen to be told what the right seed is, rather than having to pay for it to be discovered).
- hyc_symas 5mo agoYou must be on drugs. There is no separate specialized verification function. It's the same algorithm for verification as for mining.
- tromp 5mo agoCorrect; both Bitcoin and Monero use Hashcash as PoW, only differing in the choice of hash function. Verification is only different from a solution attempt in asymmetric (i.e. non-Hashcash) PoW, such as Cuckoo Cycle or (the poorly named) Equihash.
- fluffypony 5mo agololwut. There is no specialised verification function.
- fluffypony 5mo agoHmmm. That's not the reason we changed it. We just got tired of tweaking things to prevent ASICs. I'll add that there was such a large influx of miners at the outset, that (statistically) it seems any crippling of the original algorithm was fairly futile - the edge was both short-lived and minimally impactful. We're over a decade later, and nobody mining in the first month (even with that unfair advantage) was able to gain any meaningful percentage of Monero's emission. I'll add that RandomX has proven that it is indeed possible to create a GPU and ASIC-resistant PoW algorithm. I'd encourage you to dig in further - the closest to an "ASIC" is a multi-CPU miner (Bitmain X9) with a bunch of RISC-V CPUs in it.
- dgacmu 5mo agoSorry, I was not quite saying my fun was the reason, but that the failure to create something GPU/ASIC resilient was the more general underlying cause. But be careful about "proven" in that last sentence - the absence of a solution isn't exactly proof, it's more of a proof that _either_ it is possible to create an ASIC-resistant algo _or_ it has not been worthwhile to ASIC-ify it given the economics of mining XMR and the research & NRE required to do so. I haven't the foggiest which of those two it is, mind you, just that there are a few remaining valid explanations.
- rschneid 5mo agoIt's a proof that something is possible to show one example. In this case the claim was ASIC-resistant PoW is possible, and the proof has been the historical behavior of miners after years of RandomX. Nobody said it would be eternally or entirely resistant to optimizations...
- Nevermark 5mo agoYou are twisting words beyon any coherent meaning. > It's a proof that something is possible to show one example. Agreed. > the proof has been the historical behavior of miners after years of RandomX. > Nobody said it would be eternally or entirely resistant to optimizations... These are contradictory statements. If historical behavior was a proof, then it would be eternally and entirely resistant.
- yieldcrv 5mo agoMonero has used Random X for 7 years Why even mention that era? Your fascinating by that time was shorter than its post Random X lifecycle
- add-sub-mul-div 5mo ago[flagged]
- j4cobgarby 5mo agoI never quite understand this stuff, maybe someone can help. Are cryptocurrencies supposed to be a potential replacement for real life cash? This was my understanding of the motivation behind Bitcoin, at least. If so, why does it make sense that people can "generate" cash by proving some amount of work done? This of course cannot be done with normal cash. Is the main functionality of these cryptocurrencies supposed to be "people can send currency to each other", or "people generate currency -- a number -- and sell this currency for real life money"?
- gear54rus 5mo ago> If so, why does it make sense that people can "generate" cash by proving some amount of work done? Because you need an incentive for 'miners' to participate in transaction processing. Main functionality is transactions which are not controlled by any single entity (like the government). Most of it is speculation unfortunately, which gives it a bad name, drowning out real usecases.
- ourmandave 5mo agoSo now I'm wondering, why wouldn't they just charge a transaction fee in Monero? Why mine at all? If you want to scale up to Mastercard levels.
- dale_glass 5mo agoA transaction fee of what? To take a fee from a transaction there has to be a transaction to take a fee from, which needs some sort of "coin" that came from somewhere. Somebody has to create a money supply and distribute it somehow. When the network first comes into existence, nobody has any money, so where does it come into being from? Mining is what generates the coins. And you need mining because otherwise you need some other issuing organism. Without decentralized mining you get a central issuer, and that's untrustworthy and possible to shut down.
- latchkey 5mo ago
- Aeroi 5mo ago[flagged]
- Hilliard_Ohiooo 5mo agoYou'll get nothing but up votes here on HN, a lot are still angry they missed the boat. But solving the problem of how to transfer value trustlessly and anonymously, instantly anywhere in the world is one of the biggest breakthroughs since the Internet. Amazing how in a few short years kids started growing up with Bitcoin and don't understand how it work or why it exists :(
- jayd16 5mo agoIf it's actually a transformative technology, there's no boat to miss. But it's still mostly about the speculation, it seems.
- mothballed 5mo agoIt was mainly the early wall street types that cashed in big. If it was used as suggested by satoshi, then you were using it as spending cash rather than an investment to sit on, in which case you shouldn't have made much money on it.
- AureliusMA 5mo agoDon't forget about the pineapple fund : https://en.wikipedia.org/wiki/Pineapple_Fund https://en.wikipedia.org/wiki/Pineapple_Fund Also wall street never considered it seriously until a few years ago.
- dgellow 5mo agoIt’s an interesting technical problem to solve. But after 15y still has no meaningful benefits for our societies. Other than gambling/speculation/illegal stuff. The transformative cryptocurrency shift didn’t happen
- AureliusMA 5mo ago
- OsrsNeedsf2P 5mo agoCan someone explain to me why RandomX miners don't just generate programs without branching? I'm a bit confused on why that's not possible
- tardedmeme 5mo agoBecause it's designed to be hard to execute on anything that is not a CPU.
- OsrsNeedsf2P 5mo agoRight, but the program is generated by the miner. So the miner could just generate a program that has no branching, and run it on a GPU.
- tardedmeme 5mo agoEach program is guaranteed to have a certain number of certain types of instructions, such as (IIRC) exactly one divide instruction.
- hyc_symas 5mo agoSince the programs are randomly generated, there's no guarantee that any particular program always uses some number of any particular instruction. There's only a probability, X/256 instructions will be somesuch operation.
- captn3m0 5mo agoThe program is randomly generated and I am guessing that the seed for this is deterministically determined from the current block head (or something similar) making it hard to attack. It might lead to scenarios where a miner may optimise block generation itself, I guess? I was more curious about the possibility of generating optimised branchless variants and then running them in parallel on multiple ASICs to ensure you cover every branch and submit all the results and hope you’re fast? Would that be more inefficient than relying on branch prediction and CPUs?
- kerkeslager 5mo agoSide question: what's the least scammy and complicated way to buy Monero these days?
- Synaesthesia 5mo agoBuy some other crypto like Litecoin then exchange it for Monero, there are quite a few exchanges around that do it anonymously.
- kerkeslager 5mo ago...such as?
- flotzam 5mo agohttps://kycnot.me/?categories=aggregator https://kycnot.me/?categories=aggregator https://kycnot.me/?categories=exchange https://kycnot.me/?categories=exchange
- gkbrk 5mo agoI've seen https://kyc.rip https://kyc.rip but haven't tried it so far.
- nohell 5mo agoThat's just using Trocador with referral fees. You could just use Trocador directly and skip the "hackerish" aesthetic and save 2% on fees.
- k4rli 5mo agoBinance offers XMRUSDT pair.
- Acrobatic_Road 5mo agoKraken?
- 5mo ago
- deleted 5mo ago[deleted]
- nmz 5mo agoSo many people here know how bitcoin works but don't know that it doesn't. It is hilarious.
- hyc_symas 5mo agoI walked through the design at Monerokon in 2019 here https://www.youtube.com/watch?v=4Hkd-n1W_e4 https://www.youtube.com/watch?v=4Hkd-n1W_e4
- KolmogorovComp 5mo agoThe article skip over the results? Did the design succeeded? Which hardware do miner uses, and is it evenly distributed? Can I mine Monero on potato hardware?
- hyc_symas 5mo agoThe design has been working perfectly from 2018 till today. https://old.reddit.com/r/Monero/comments/1h6e4nk/randomx_5_year_anniversary/ https://old.reddit.com/r/Monero/comments/1h6e4nk/randomx_5_y... Most miners use AMD Ryzens. Couldn't tell you the actual breakdown of CPU types in use. Apple's M series CPUs are quite efficient at it too. Bitmain now sells a "Monero RandomX Mining ASIC" which is just a bunch of RISC-V cores, seemingly based on Sophon SG2042 SOCs. There's nothing special or more cost-effective about their product. You can mine on old smartphones quite easily. I use a bunch of old Android TVboxes myself. Their hashrates are nothing to crow about, but their hashes/watt are still competitive with faster CPUs. There is a RandomX V2 that will be deployed soon. Its main improvement is even cheaper verification cost.
- tomjen3 5mo agoI had hoped this would describe a system that did not use very large amounts of power. Sadly it does.
- boldlybold 5mo agoHow can you have proof of work without consuming large amounts of power?
- tromp 5mo agoBy having a small daily dollar value (the column "PoW Produced (24h) in [1]). All but the top 15 coins sorted by that column have less than $10k emitted per day in block rewards, which limits the power that miners can spend on competing for it. [1] https://www.f2pool.com/coins https://www.f2pool.com/coins
- OsrsNeedsf2P 5mo agoThat would mean all but the top 15 coins are exploitable for under $10k per day
- tromp 5mo agoBut the value of a 51% attack is roughly proportional to marketcap, so while they are cheaper to attack, there's less incentive for the attack. The most (relatively) vulnerable coins are those where the daily dollar value is low relative to the market cap.
- tomjen3 5mo agoThats what I am interested in - Etherium does it, and I believe Chia(sp?) does too.
- HDBaseT 5mo ago[dead]
- legalmoneytalk 5mo ago[flagged]
- NooneAtAll3 5mo agough, "GiB" author sold his soul to marketmen
- killerstorm 5mo agoHow many bits is a gigabit?
- NooneAtAll3 5mo agoare you selling or buying? it's binary, thus 2^30
- killerstorm 5mo agoAll telecom standards use standard SI prefixes. E.g. 1982 Etherenet specification: http://decnet.ipv7.net/docs/dundas/aa-k759b-tk.pdf http://decnet.ipv7.net/docs/dundas/aa-k759b-tk.pdf > a data rate of 10 Megabits per second > Data rate: 10 Million bits/sec RAM modules have to have power-of-two size for technical reasons. These reasons do not apply to telecom, magnetic storage, etc. Has nothing to do with "binary".
- user3939382 5mo agoProof of waste. I wonder for the base price of the currency what the cost of energy and environment are to create it.
- CuriousRose 5mo agoIn terms of software that genuinely fascinates me Monero would have to be up there (along with Postgres, ZFS and OpenBSD). It's in my opinion one of the only (but probably the only) cryptos that has actually held true in terms of its principles of privacy (which was a perceived principle of crypto by users) and mass ability to mine and not be dominated by ASICs. I've since taken to running a non-public Monero node, which will become public when I can ensure my network security as it's being run from my home. In saying that, there is a lot of concern around the new Carrot changes. To preface, I don't understand it enough to have an opinion either way, but a good chunk of the vocal user base seems to be worried that making “optional” view keys show both incoming and outgoing transactions will force the hand of the remaining exchanges, and be a condition of adoption of new exchanges to support Monero. I haven't really seen a dumbed down explanation from the core Monero team as to exactly what the change looks like, and what the theoretical implications could be. It would be nice if Monero had more accessible PR for non-technical users to encourage adoption and squash FUD when it arises or at least acknowledge it from a top level in a blog post or something so that the already hyper-paranoid user base doesn't unnecessarily drive a mass anti-Monero campaign.
- protocolture 5mo ago>held true in terms of its principles of privacy (which was a perceived principle of crypto by users) Crypto wasnt so much straight up privacy, but like high information / low revelation. The idea was to create an economic system where you the individual could have relative anonymity while being able to go online and audit the bank in detail. Not a criticism of you enjoying monero I just think this got lost somewhere. I think Ethereum is probably going to strike the closest balance eventually, but it depends on a lot of factors.
- snthpy 5mo agoAs PoW goes, this is cool. One thing I didn't understand though is Light mode: > Fast mode is for mining. Light mode is for verification. The reference README says The post only describes Fast mode, right? Presumably verification is done by miners who already have the memory set up so Fast mode would be faster for them. Verification is still relatively fast because you don't have to try gazillions of nonces so who is Light mode necessary and how does it work?
- hyc_symas 5mo agoLight mode is used mostly by the monerod, validating incoming blocks. But on a machine with sufficient free RAM, monerod can also be set to use Fast mode instead. The post described both modes. The only difference is that Fast mode processes the cache to generate the full 2.1GB dataset, so subsequent programs can just reference it as needed. Light mode uses only the 256MB cache and generates the required dataset values individually, on each access. That saves RAM but costs more CPU time.
- cawksuwcka 5mo ago[dead]
- baby 5mo agoIf people are interested we covered Monero and all the other protocols that implement private transactions in https://blog.zksecurity.xyz/posts/pudding-8-privacy/ https://blog.zksecurity.xyz/posts/pudding-8-privacy/ (video: https://www.youtube.com/watch?v=TFZKuIq7v60 https://www.youtube.com/watch?v=TFZKuIq7v60)