Earlier quoted context omitted.
Heat generation is the only way we know to get the fairly robust security guarantees we need. Proof-of-stake and other “efficient” schemes have vastly worse security properties.
How secure is Bitcoin? How secure does it need to be? Can we put a number on any of these - are we at the optimum security level now? Are we maybe at 150%?
Bitcoin mining hash rate drops as blackouts instituted in China
381–390 of 431 posts
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#382Earlier quoted context omitted.
> if it's so bad, why does it work? As a currency? It doesn't. Do people actually think that Bitcoin is succeeding as a currency right now? If you want to talk about the market deeming something sufficient, the market has broadly, almost universally decided that credit cards are preferable to cryptocurrency. As a speculative investment? Because of what I said in my last paragraph. > chaumian coinjoin I've seen multip…
> I don't understand why a community would go down that route when solutions like zero-knowledge proofs already exist and have a better track record you don't understand why a community at a nash equilibrium wouldn't jump at the opportunity to break consensus? bitcoin is favorable because it is relatively speaking the minimum viable collection of traits needed to function as a cryptocurrency, reduced complexity leave…
Reduced attack surface only matters if the remaining surface is secure. Privacy-wise, the comparison here is that you've got a door with no locks, and you're arguing against putting a lock on it because "that'll make it more complicated, and then people will get in and steal my stuff."
There is no particular reason to be confident that coinjoins will protect your privacy in the long run. They've both broken in the past and they're easier to regulate than something built into the core design of the coin. This is a situation where you need a more fundamental guarantee, because Bitcoin at its current complexity level is not capable of protecting your privacy well, and I don't see strong evidence that coinjoins will solve that. You've got to put a lock on your door, even if it makes your door more complicated.
Even disregarding the fact that coinjoins are unproven, paying coordinator fees every time you want to make a private wallet is a bad solution anyway. Even if you could be confident that coinjoin wallets weren't going to leak information, you still wouldn't want a solution that had those fees, because we don't want a world where only rich people have privacy.
> at a nash equilibrium
I think the whole point of what I've been saying is that the nash equilibrium of Bitcoin is terrible. If the crypto market stays in the state it's in, it will not become a viable currency. So yeah, I don't understand why a community in a nash equilibrium where >50% of the network is subject to interference by the PRC, where transaction fees are spiraling out of control, and in which tracking is already a serious problem -- I don't understand why a community would be happy to stay in that state, complexity or equilibrium be damned.
That's what I've been saying. Bitcoin as it exists today is terrible, and making it better is going to require actual iteration, not just sitting around and trying to pump the market so somebody can buy a porche.
> why does it even matter?
Because some of us would like a functional, private, inexpensive online payment system at some point, and the entire crypto market is intertwined in the public eye, and silliness like speculative investing and NFTs distort that purpose and get in the way of other coins doing anything useful.
There's a reason why cryptocurrencies are now classified by the IRS as an investment. If you're trying to build a currency, then that's a bad outcome, but none of that matters if the only thing you care about is "becoming rich" instead of building something that's actually useful for the world.
> man in 1910: the market has universally declared horses superior to automobiles
Well OK, then don't act like 5-10 year temporary consolidation around Bitcoin means that the crypto market has decided that Bitcoin is the technologically superior option for a currency, rather than a temporarily valuable speculative asset. Particularly, don't act like Bitcoin prices prove its superiority during the same week that heckin Dogecoin prices spike.
You can't have it both ways here, either the market is always rational or it's not.
If the market is always rational, then credit cards are better than cryptocurrency in its current state. If the market isn't always rational, then speculative investment based on FOMO does not indicate anything about Bitcoin's quality as a tool for transactions.
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#383Earlier quoted context omitted.
“Runs fine” doesn’t mean it’s energy efficient. If we can get whatever value out of a payment system with 1 wind turbine instead of 10,000, the former is obviously a better choice. And right now it’s not obvious that PoW provides anything that other technologies can’t. Bitcoin itself has shown that when PoW doesn’t produce the results people want, developers can just release code that makes users ignore the most work…
If all it's using is surplus green energy (something regulators can enforce), then efficiency isn't a concern. That energy was wasted either way. Re: PoW, the thing it does provide that no other tech can't is Sybil-resistant open-membership replicated state machines. Anyone can join in deciding state transitions because the barrier to entry (access to mining tech and electricity) is decoupled from the system's operat…
This is the same attack model that leads there being a public debate about “Segwit coin VS BCash”. It’s also what happened with the 2013 fork[0]. The system ends up needing politics and power games just like the current financial system. The technology is a distraction to fool intelligent engineers into thinking this system is different. It isn’t.
[0] https://freedom-to-tinker.com/2015/07/28/analyzing-the-2013-...
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#384Earlier quoted context omitted.
Yeah, so if you look at some commentary around that paper there is a variant of the problem with "approximate agreement" that can solve for example the 3 person variant. This fits with the theory (really just a hypothesis at this point but actively worked on) that I have w.r.t. datalisp. Edit: see for example slide 30 of this slideshow: https://www.cs.cmu.edu/~15712/lectures/15-bft.pdf I'm not (yet) very good at prob…
If you read the Avalanche paper, you'll see early on that all of its claims to being BFT stem from an assumption about the distribution of message arrival rates in the system. That is a very generous assumption that can easily be wrong. Also the original BFT literature makes no assumptions about the arrival times or even reliability of the network -- BFT constraints apply even if the network is 100% reliable. It only…
Again, the Byzantine generals problem of the paper is not an accurate description of what is happening in the datalisp network and does not apply except locally (in a 'neighbourhood' of the dispute) so it's not 2/3 of the whole network but rather 2/3 of the echo chamber that needs to agree...
Anyway you seem to be eager to dismiss off-hand so I am losing interest in debating with you as-is.
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#385Re: Bitcoin mining hash rate drops as blackouts instituted in China
#386Earlier quoted context omitted.
If you read the Avalanche paper, you'll see early on that all of its claims to being BFT stem from an assumption about the distribution of message arrival rates in the system. That is a very generous assumption that can easily be wrong. Also the original BFT literature makes no assumptions about the arrival times or even reliability of the network -- BFT constraints apply even if the network is 100% reliable. It only…
I am in no way trying to defend avalanche. I have been speaking from the standpoint of datalisp. Again, the Byzantine generals problem of the paper is not an accurate description of what is happening in the datalisp network and does not apply except locally (in a 'neighbourhood' of the dispute) so it's not 2/3 of the whole network but rather 2/3 of the echo chamber that needs to agree... Anyway you seem to be eager t…
If not, then why compare it to Avalanche at all?
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#387Earlier quoted context omitted.
How is that pull request relevant to our chat here? By the way I don't think it's a good argument to say that your job depends on proof of stake being secure and therefore it must be secure (or "therefore you would know if it wasn't"). The coordinated bribery attack can be done by having people stake on a different chain until a majority is reached and then softfork and slash the minority. If you don't believe the at…
It's a relevant answer to your personal attack "I don't think you've studied how the attack would work." My job is literally implementing proof-of-stake securely. Also when I work and implement an algorithm, I provide references and sources, which my PR is. > The coordinated bribery attack can be done by having people stake on a different chain until a majority is reached and then softfork and slash the minority. Cha…
W.r.t. to the proofs in the paper, they happen within certain assumptions, assumptions that do not hold when the attack is as I described because the majority will be byzantine!
The key idea in the argument is not computer science but economics. If you can earn more we have to assume you will do that (charitable behavior exists but is not a good thing to rely on for security) the issue is that PoS is vulnerable to the tragedy of the commons in a similar way to democracy (the amount of influence each person has is small but time investment of being a rational voter big, hence it is rational to be ignorant - in PoS setting the idea is that you defecting is unlikely to change things so the bribe does not need to be big). Once you've obtained a majority you can censor the minority. How much you can do with your soft fork depends on the chain in question but in general the very fact that you can stop byzantine behavior works against you when the majority is malicious.
The reason we cannot do the same in proof of work is because of how expensive the bribes are.
Anti-sybil based in racing is hard to censor but when you start voting you can do bullying.
Regarding formal verification, you can formally verify the algorithm, implement it safely and still it will not work in the real world due to the game theory considerations. However bittorrent worked and that was largely charity. Similarily the data availability problem has not been a problem (e.g. all bitcoin blockchain is accessible even though there is no monetary incentive to make the archive accessible). While there is no way to exploit known vulnerabilities they may as well not exist.
From our exchange you have been appealing to authority but I suggest working through the math and looking at tragedy of the commons. Since you are intimately familiar with how proof of stake works you will be able to convince yourself one way or the other.
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#388Earlier quoted context omitted.
If all it's using is surplus green energy (something regulators can enforce), then efficiency isn't a concern. That energy was wasted either way. Re: PoW, the thing it does provide that no other tech can't is Sybil-resistant open-membership replicated state machines. Anyone can join in deciding state transitions because the barrier to entry (access to mining tech and electricity) is decoupled from the system's operat…
Of course you can mine 2 “conflicting blocks” in PoW cryptobeans, you can just tweak the clients of a fork to require negligible work for the next block and convince everyone that the most-work chain is a hostile takeover. Satoshi did not anticipate how forking clients with tweaked implementations invalidate the whole security model. This is the same attack model that leads there being a public debate about “Segwit c…
If I have the power to tweak any/all peers of any p2p system arbitrarily, then I already have supreme authority over what that system does. So your hypothetical is vacuous and uninformative. Wake me up when you've found a way to reliably mine two conflicting Bitcoin blocks using the same amount of PoW guesses.
> This is the same attack model that leads there being a public debate about “Segwit coin VS BCash”. It’s also what happened with the 2013 fork[0].
Wanna know something truly mind-blowing? You can fork Bitcoin at any time! And yet, none of the forked pretenders have come close to replacing the original Bitcoin. The biggest pretender by marketcap has a measly _2.21%_ of Bitcoin's hashpower [0], despite having the same PoW algorithm.
> The system ends up needing politics and power games just like the current financial system
Per the above, PoW has so far done a great job indicating which system is the real Bitcoin, and which are the pretenders. Wake me up when one of them overtakes the original.
> The technology is a distraction to fool intelligent engineers into thinking this system is different. It isn’t.
Yeah? Well, you know, that's just like, uh, your opinion, man.
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#389Earlier quoted context omitted.
I am in no way trying to defend avalanche. I have been speaking from the standpoint of datalisp. Again, the Byzantine generals problem of the paper is not an accurate description of what is happening in the datalisp network and does not apply except locally (in a 'neighbourhood' of the dispute) so it's not 2/3 of the whole network but rather 2/3 of the echo chamber that needs to agree... Anyway you seem to be eager t…
So is global agreement on state a criterion for datalisp's correct operation, or not? If not, then why compare it to Avalanche at all?
From what I can tell; I agree with your dismissal of avalanche and offer an intuition for what may be the problem by contrasting it to my work-in-progress idea, then we have a series of back-and-forths where I consistently mention datalisp but never once talk about avalanche..
Regarding global agreement of state, yes it is not a criterion for datalisp. Datalisp approaches the network like a sheaf (locally consistent but globally not necessarily so) and uses the properties of propagator networks (which are fully CP, therefore they converge on a fixpoint) to reason about convergent consensus that executes lazily.
The casual dismissal of datalisp (as it stands) is that the message format for communicating your beliefs w.r.t. probability of signal-to-noise is not fully worked out yet and all we have is a series of heuristical arguments.
However, datalisp is a data-intechange format first and foremost and optimized for building authenticated datastructures. It is not specialized for cryptocurrencies per-se (since the focus is on second order byzantine fault tolerance).
Re: Bitcoin mining hash rate drops as blackouts instituted in China
#390Earlier quoted context omitted.
So is global agreement on state a criterion for datalisp's correct operation, or not? If not, then why compare it to Avalanche at all?
Could you please read our exchange from your first comment and tell me how you parse it? From what I can tell; I agree with your dismissal of avalanche and offer an intuition for what may be the problem by contrasting it to my work-in-progress idea, then we have a series of back-and-forths where I consistently mention datalisp but never once talk about avalanche.. Regarding global agreement of state, yes it is not a…
> I believe the problem in the first place is forcing the network to come to global consensus. In my project the idea is to form "lazy consensus" (i.e. just enough consensus for everyone to have a consistent outlook on the world).
So, which is it? Not coming to global consensus and "just enough consensus for everyone to have a consistent outlook on the world" seem mutually exclusive.
Don't be afraid to lay down a bold system description, and don't hold back on the specifics. Not trying to brag, but I have a PhD in distributed computing, I work on a blockchain at my day-job (https://github.com/blockstack/stacks-blockchain), and I chair its governance process. I'm pretty sure I'll be able to understand a rigorous system design. But, I don't have very much patience for weasel-wording, pussyfooting, or hand-waving.