Live data from Hacker News

Proof of stake is incapable of producing a consensus

yanmaani.github.io

181–190 of 822 posts

Re: Proof of stake is incapable of producing a consensus

#181
This is a silly article. Only working in a weaker security model does not, a priori, mean that proof of stake is a scam; it just means you need to convince yourself that the weaker security model holds. You can read the post linked (https://blog.ethereum.org/2014/11/25/proof-stake-learned-lov...) and decide for yourself.

Personally, I think this kind of "quiescent" knowledge, letting you differentiate the real chain from the fake chain on long enough timescales (which basically amounts to knowledge of a single hash, when you get right down to it), is perfectly reasonable to assume under realistic circumstances, for the same reason that synchronized time is not a remotely difficult problem on long enough timespans. The only problem lies in new nodes (that enter the system when there's not a quiescent state, and the longer chain is being withheld) being exposed to fake chains.

By using a VDF as mentioned below to make sure it takes just as long to construct a new chain as it took to construct the old one, one can ensure that as long as at the time the stakers held their keys (rather than for all time) a majority were trustworthy, then the probability that they were able to maintain a longer chain becomes vanishingly small. Therefore, nodes will be able to reliably choose the longer chain on reconnecting to the system. This trust model seems pretty realistic to me, and it's not like Bitcoin can handle the case of a continuous partition to begin with.

So this just reduces to "once a majority is not trustworthy, the chain can't be trusted anymore" which is the actual security tradeoff of PoW vs. PoS (PoW puts trust in hashpower rather than staked coins, so by definition it's immune to this sort of issue; if your private key is stolen you "only" lose your coins, not any voting power). I don't think this is news to anyone who's done much research into cryptocurrency.

Re: Proof of stake is incapable of producing a consensus

#182
post #152

Earlier quoted context omitted.

"who gets to decide" it's called "we the people" or democracy if you will. We as a society decide that cryptocurrency aren't worth destroying the world over, and that's about it.

If bitcoin mining uses renewable power (and pays for it), is that destroying the world or is that encouraging renewable adoption? If bitcoin mining uses co2 producing power (because the economics supports it), is that the fault of bitcoin or the government for not sufficiently taxing the negative externalities of that means of production?

Using power is never a net good, regardless of the type of power. If we don't need more power for something specific, the ideal is to just not build more power - consumption is not some noble goal.

Unless we believe that Bitcoin has some use, its power consumption would be problematic even if it weren't so monstrously large. And vanishingly few people believe Bitcoin has any value beyond a get rich quick scheme.

Re: Proof of stake is incapable of producing a consensus

#183
post #164

Earlier quoted context omitted.

> Why would they structure it otherwise? It gets a lot more complicated than that because setting up competing systems is cheap. It is like saying "nobody would write this piece of software for free". What we learned with open source is if the cost of distribution gets low enough then there needs to be just one person somewhere on earth willing to maintain it and it can work. If the cost of creating trustworthy local…

You can't fork gigawatt powerplants and silicon foundries by clicking a button on Github. You can't even fork a stablecoin. in case of a split in a PoS chain, the correct fork will be decided for you by USDC and Coinbase.

You can fork decentralized over (crypto) collateralized stablecoins even if you can't force a fork of a centralized stablecoin operated by incorporated entity to be recognized by them.

Unless we're going to pretend that there is only one way on and off networks and only in one currency denomination…

Re: Proof of stake is incapable of producing a consensus

#184

As far as I am aware, these long-range forks can be hindered by using verifiable delay functions (VDFs) [1, p. 6]. Essentially, VDFs take a certain amount of steps to compute and cannot be parallelized. However, the correctness of their output can be verified efficiently. Now if a proof of stake includes a VDF that needs to be computed for every block, then a long-range attack needs to recompute the VDF outputs as we…

> Essentially, VDFs take a certain amount of steps to compute and cannot be parallelized. However, the correctness of their output can be verified efficiently. this...sounds exactly like proof of work?

It is, just wrapped in enough layers of misdirection.

Re: Proof of stake is incapable of producing a consensus

#185
post #149

Can't wait for the day all PoW mining activities are declared illegal. To be honest, I don't understand why it hasn't been banned already. Sweden has recently called for a EU wide ban because it identified PoW mining as a threat to transition their economy to renewable energy. https://www.fi.se/en/published/presentations/2021/crypto-ass...

You never mentioned why you think mining should be illegal. Probably because of the outrage published by the media based on intuitive assumptions that end up not being true. That bitcoin mining long term is bad for the environment. However, this is not true even though it intuitively seems that way. (Similar to how making highways wider actually ends up making traffic worse, not better). We can actually start with 1…

> If electricity demand from PoW mining spurs new renewable plants to be built, is that bad for the environment?

Yes, obviously.

Even if every single miner pool built its own solar/wind plant to power 100% of its energy needs, that would still be horrible for the environment: building the power plant itself produces harm to the environment; and the space and work and money used to create the Bitcoin miner's power plant could have gone into replacing (closing down) a non-renewable power plant.

Silly arguments about pricing volatile electricity only work if we assume maximizing profit is the ultimate good or that PoW is the only way to use that excess power. In reality, if we want to avoid the worse catastrophes that our current economy is pushing the world towards, we have to stop looking at profit, and choose less profitable but more useful ways of handling volatility - batteries, long-distance transmission, etc.

Re: Proof of stake is incapable of producing a consensus

#186

Earlier quoted context omitted.

> For PoW, you'd have to know the hash of the start of the chain (the "genesis block") in advance to verify you downloaded the correct chain. Nope. You could fork the chain at a period of low difficulty and it would still stem from the genesis block. It would either be a short chain, or have clearly low difficulty though, so it wouldnt fool anyone knowledgeable. Im not sure how you would leverage that chain for fraud…

Why fork at low difficulty?

You need to fork at low difficulty if you want to significantly lengthen the chain from that point, because creating a high difficulty, long chain that is valid is hard.

But-- there's nothing to preclude you making big steps up in difficulty at the end of the chain. It means that one evaluating the length of the chain for authenticity really needs to integrate the difficulty over the entire chain and not just look at the number of blocks.

Re: Proof of stake is incapable of producing a consensus

#187
post #40

Earlier quoted context omitted.

'Policy changes' and hard forks have about as much to do with PoW as whether the Federal authorities should ban cryptocurrencies or not - they're outside the realm of consensus algorithms. In PoW there are no friends. If your blockchain is incorrect (i.e not the longest) your transactions on it are invalid and will be rejected by the rest of the network.

> If your blockchain is incorrect (i.e not the longest) your transactions on it are invalid If your chain tip is on the dead side of a hard fork (i.e. if the majority of the network will predictably soon finish switching away from software which considers your chain tip valid, to software which considers your chain tip invalid), then nobody cares if your chain tip is the longest in the interrim, or how long you still…

"nobody cares if your chain tip is the longest in the interrim,"

Except the people you bought something real-world from, once they figure out that their "tipcoin" is worthless. So now it's a question of convincing some people that your technobabble is valid enough. How hard is that?

Re: Proof of stake is incapable of producing a consensus

#188

Earlier quoted context omitted.

Maybe I didn't word it right, but I wasn't calling bitcoin's method reliant on centralised authorities, just asking if there were more methods out there that weren't as well. Bitcoin is an open source permissionless protocol, so you have multiple clients to chose from, each with their own list of bootstrapping nodes, many open source where you can submit a PR to add your node too. You can even build your own client a…

It seems that PoW is like recursion. You don't get it at all until you completely get it. It's a leap to understand it and somehow many very technical people don't understand a seemingly simple protocol even a decade after it became mainstream and is threatening national banks due to the very characteristics these people claim it doesn't have.

Indeed, a very strange phenomena. Willful ignorance?

Re: Proof of stake is incapable of producing a consensus

#189

This is a silly article. Only working in a weaker security model does not, a priori, mean that proof of stake is a scam; it just means you need to convince yourself that the weaker security model holds. You can read the post linked ( https://blog.ethereum.org/2014/11/25/proof-stake-learned-lov... ) and decide for yourself. Personally, I think this kind of "quiescent" knowledge, letting you differentiate the real chai…

Great comment, let's do a TL;DR of the article: - Clickbait title. - Some of the claims can be debunked with a 2014 blog post. - Tradeoffs pow/pos are known and accepted for a long time. Nothing new added except drama.

Re: Proof of stake is incapable of producing a consensus

#190

Earlier quoted context omitted.

Other merit's aside, Bitcoin's incentivizing cheaper energy provides nothing new of value. All uses of energy incentivize the search for cheaper energy. Not all energy uses are optimized to increase usage over time, to cancel efficiencies. Proof of work, whatever it's merits, is anti-efficiency with respect to itself. This is a significant difference.

nothing new of value? I know this sounds cliche but maybe consider you dont know enough about it?

I made a strong statement, so maybe I need to be more precise with my point.

Bitcoin has merits. So proof of work, being a part that is currently necessary for it to work has merits.

But the argument that proof-of-work has the merit of incentivizing cheaper energy sources does not stand up.

1. All uses of energy already incentivize the search for cheaper energy. This isn't a novel incentive that proof-of-work provides.

2. But proof-of-work does have a relatively novel disadvantage. It won't just incentivize greater energy uses as prices come down, as in normal supply-demand curves, but must keep up the original and even grow the amount spent on energy.

This would not be a problem in a market without negative externalities, but energy is famously a huge industry that will be struggling with negative externalities for quite some time and at great cost.

Post reply on HN