Live data from Hacker News

Proof of stake is incapable of producing a consensus

yanmaani.github.io

111–120 of 822 posts

Re: Proof of stake is incapable of producing a consensus

#111
post #97

Earlier quoted context omitted.

> LMAO I don't get your criticism. Why does requiring gossip to every node cause centralization? Why does everyone having the current state of everything cause centralization?

To make progress, every few seconds or minutes, all transactions in the world must be gathered in ONE place, and placed in ONE block, as the network and adoption grows this becomes more and more expensive for everyone. There are various aspects of centralization. This is one major aspect: a bottleneck . Just like when all Web 2.0 conversations in the world would have to go through a centralized server. Even if it was…

I think you have some fundamental misunderstandings of the term "centralization". And also of the way bitcoin works.

All transactions are not gathered in one place, ever. All nodes receive all transactions independently. All nodes are capable of providing a copy of the ledger for verification.

Transactions don't go through a server. Historical record gets finalized by any one participating node. These two things are not the same thing. The transactions that will be mined are publicly known by all nodes before they are mined. Mining only ensures that nobody can change them after the fact.

There is no concurrency, this is true. The systems we have currently are single threaded systems, and from a classical standpoint, hugely inefficient single threaded systems. But this is not the same thing as centralization.

Re: Proof of stake is incapable of producing a consensus

#112
post #34

Is this FUD from Bitcoin maximalists? > That key is valid to sign any number of versions of, let’s say, block #200, and there is no objective, system-internal standard for which version is legitimate, other than “the one that was published first”. The real block #200 will have hundreds of attestations courtesy of randomly-selected validators, each of those signatures attesting to its validity and finality.

Attestations don't have a real world economic cost that can be validated trustlessly within the system. If you compromise or coerce enough validators, you can rewrite the history for no cost. That's what PoW provides that PoS just doesn't. Immutability. In fact, I would argue that one of the most important products of bitcoin, is providing the hardest, most immutable database human civilization has ever created. We c…

> but once a piece of data gets confirmed... it can never be changed or removed from the blockchain.

But it can, in the exact same manner as described in this article: have an 51% attacker build up a long chain and hide it from the world; then publish it.

PoW is vulnerable to exactly the same type of attack described in this article. In order to build a longer chain with non-negligible probability, you need to stake at least 51% of the pool.

Re: Proof of stake is incapable of producing a consensus

#113
post #78

Earlier quoted context omitted.

The block 200 will be adding validation to the previous blocks, and will be validated by the future ones. Without other types of checks, nothing stops you from rewriting the previous 199 blocks and using block 200 to validate them. This is not FUD, it's the most obvious PoS flaw, called long range attack, and the reason PoS chains often need more checks to be more trustworthy (e.g. keeping hardcoded checkpoints, choo…

Here’s a recent ETH2 block: https://beaconcha.in/block/2604970#votes It was voted for by 8000+ validators. Many of them have been validating since beacon chain genesis a year ago. There are like 260k validators active right now. I find it highly unlikely some entity is going to come along and try to pretend their alternate history, with a whole new set of hundreds of thousands of validators (which wouldn’t be support…

> It was voted for by 8000+ validators.

Which parts of this are checked by the client software, and which parts are just checked by interested humans in the block explorer?

There's a trade-off here. If you require 8000 guys to all vote in favor of your block, what does the client do if it only sees 7999?

> which wouldn’t be supported by any ETH1 deposits ... signed by 260k freshly generated public keys

You misunderstand. What happens if some of those private keys get compromised? In Bitcoin, if I sell my miners to someone else, it's not like they're radioactive waste that has to be buried. In PoS, someone can cause quite a bit of damage with keys that ostensibly don't contain any money. And because I've already withdrawn, I have no reason to care.

Re: Proof of stake is incapable of producing a consensus

#114
post #20

Earlier quoted context omitted.

Is the threat of long range attacks in PoS any worse than PoW in practice? Bitcoin for example still relies on a list of hardcoded nodes for bootstrapping clients. Not to mention very few people actually bother to verify the full chain (360GB and counting) from genesis. As for auditing the the integrity of the code or binary, it is signed by GPG keys hosted on public key servers accessed using X509 certificates pinne…

The Bitcoin Core client includes a hardcoded list of DNS servers that point to thousands of nodes. These lists get updated frequently by different people. Other clients may use other lists. What is the threat model you're suggesting here, exactly? Do you know any other way to bootstrap a peer to peer network without centralised authorities? All network participants are forced to verify the full chain from genesis. So…

> Do you know any other way to bootstrap a peer to peer network without centralised authorities?

In IPv4 a client might have a chance at auto-discovering peers.

It's also not necessary to rely on a single centralized authority. There are many things (DNS, Encyclopedias, Linux kernel mirrors, etc.) where the majority of existing centralized authorities agree with each other.

Re: Proof of stake is incapable of producing a consensus

#115

Earlier quoted context omitted.

What is your source according to which Christmas lights and porn use more energy than bitcoin? I fear you may seriously underestimate the energy usage of bitcoin. Even clothes dryer seem to be using less energy than Bitcoin. If you run the dryer for an hour each week, you're at 12-15kWh per month, which is 1-2% of your average household energy usage in the US, Canada or the EU. Now households at most around a third o…

You're missing the point. If we're going to start legislating how we're all allowed to use energy that civilization has made available, who gets to decide what's allowed? Numbers I've seen suggest that global PC gaming alone (excluding consoles) currently uses about as much electricity as bitcoin. Should we ban that too since playing cards are readily available and use almost no energy? Maybe we can make a concession…

> If we're going to start legislating how we're all allowed to use energy that civilization has made available, who gets to decide what's allowed?

We already legislate different pricing for different applications. Household electricity has a different price than industrial usage. A 1000x price of electricity for certain applications is just a small extension of what we currently have.

Re: Proof of stake is incapable of producing a consensus

#116
> If a node can present a lottery ticket of rarity one-in-a-million, the network can conclude the node did about a million lottery tickets’ worth of work, on average.

This is not true. You will have scratched far fewer tickets on average than one million.

If you have one million tickets, one of them guaranteed to be a winner, you will on average scratch exactly half of them (500 000) before finding the winning ticket. If you have an infinite supply of tickets, each with a 0.000,001 chance of winning, the number becomes higher, but the number of tickets scratched on average is still lower than one million.

Finding an error regarding something I know makes me skeptical about the rest of the article.

Re: Proof of stake is incapable of producing a consensus

#117

Earlier quoted context omitted.

What is your source according to which Christmas lights and porn use more energy than bitcoin? I fear you may seriously underestimate the energy usage of bitcoin. Even clothes dryer seem to be using less energy than Bitcoin. If you run the dryer for an hour each week, you're at 12-15kWh per month, which is 1-2% of your average household energy usage in the US, Canada or the EU. Now households at most around a third o…

You're missing the point. If we're going to start legislating how we're all allowed to use energy that civilization has made available, who gets to decide what's allowed? Numbers I've seen suggest that global PC gaming alone (excluding consoles) currently uses about as much electricity as bitcoin. Should we ban that too since playing cards are readily available and use almost no energy? Maybe we can make a concession…

"who gets to decide"

it's called "we the people" or democracy if you will. We as a society decide that cryptocurrency aren't worth destroying the world over, and that's about it.

Re: Proof of stake is incapable of producing a consensus

#118

He lost me at the part where he thinks you can sign messages after withdrawing your stake. The whole point of proof of stake is that you can only sign blocks or messages while you have something staked. When you withdraw you are no longer allowed to sign anything. He also didnt need to spend 1000 words going on about the history of bitcoin and proof of work. This is literally just a filler piece with a provocative cl…

> When you withdraw you are no longer allowed to sign anything.

Allowed to by whom?

Who's to punish me if I disobey them?

Re: Proof of stake is incapable of producing a consensus

#119
post #60

Earlier quoted context omitted.

The Bitcoin Core client includes a hardcoded list of DNS servers that point to thousands of nodes. These lists get updated frequently by different people. Other clients may use other lists. What is the threat model you're suggesting here, exactly? Do you know any other way to bootstrap a peer to peer network without centralised authorities? All network participants are forced to verify the full chain from genesis. So…

> Do you know any other way to bootstrap a peer to peer network without centralised authorities? I’m not the parent, but – no, I don’t. But that’s exactly the point. The need to bootstrap from centralized authorities is what’s supposedly so bad about weak subjectivity in proof-of-stake. Yet in practice, it’s needed with proof-of-work as well.

Maybe I didn't word it right, but I wasn't calling bitcoin's method reliant on centralised authorities, just asking if there were more methods out there that weren't as well.

Bitcoin is an open source permissionless protocol, so you have multiple clients to chose from, each with their own list of bootstrapping nodes, many open source where you can submit a PR to add your node too. You can even build your own client and point to whatever you want. You can also just ignore them and just point directly to nodes in a list from a public forum, a private chat, whatever.

Also, you're not just connected to those bootstrapping nodes: you use them to find the rest of the peers in the network.

Re: Proof of stake is incapable of producing a consensus

#120
post #97

Earlier quoted context omitted.

To make progress, every few seconds or minutes, all transactions in the world must be gathered in ONE place, and placed in ONE block, as the network and adoption grows this becomes more and more expensive for everyone. There are various aspects of centralization. This is one major aspect: a bottleneck . Just like when all Web 2.0 conversations in the world would have to go through a centralized server. Even if it was…

I think you have some fundamental misunderstandings of the term "centralization". And also of the way bitcoin works. All transactions are not gathered in one place, ever. All nodes receive all transactions independently. All nodes are capable of providing a copy of the ledger for verification. Transactions don't go through a server. Historical record gets finalized by any one participating node. These two things are…

I hate to argue from authority but here is @vbuterin saying the same thing about centralization:

https://medium.com/@VitalikButerin/the-meaning-of-decentrali...

Blockchains are politically decentralized (no one controls them) and architecturally decentralized (no infrastructural central point of failure) but they are logically centralized (there is one commonly agreed state and the system behaves like a single computeR

I think you’re mistaken that I don’t know how Bitcoin works. Not only do I know, but I have spoken to many teams doing work in the last 10 years in various alternative systems, and I have even designed alternatives myself.

I used the word server in my analogies. The transactions are, however, all going through one COMPUTER which receives them, puts them in a envelope, and finds the right PoW input to “seal” the envelope, and sends it out to everyone. Whoever does that first, gets the rewards on that chain. If the transactions do not make it into the block, they don’t count on-chain.

Therefore, every 10 minutes, ALL TRANSACTIONS IN THE WORLD must be gathered by one computer, the one that will happen to mint the next block. This is a bottleneck, and it is the cause of the skyrocketing fees whenever the system sees any on-chain adoption.

But it’s actually worse than centralized — because we don’t know who will mint the next block so we have to send everything to on everyone. Imagine if all BitTorrent nodes seeded every file in the world. Bitcoin failed as a peer to peer cash system because of this topology and people on the group were telling Satoshi this back in the day.

Post reply on HN