Live data from Hacker News

Proof of stake is incapable of producing a consensus

yanmaani.github.io

651–660 of 822 posts

Re: Proof of stake is incapable of producing a consensus

#651

Earlier quoted context omitted.

ETH2 was years in the making, with multiple delays and not fully migrated yet precisely because of how unsafe standard PoS is. Vitalik and co spent years researching the best mitigations. Right now, it seems to be one of the best protected PoS chains. It's still fairly new, with novel mitigations, so it still doesn't stand the test of time against all possible attack vectors. In that sense, it still can't be consider…

PoS is more quantum-resistant though. If someone were to build a quantum computer capable of running Grover's algorithm on bitcoin hashes, they would get a quadratic speedup over classical miners. That's a threat that doesn't exist on PoS. (Both would be vulnerable to Shor's but post-quantum signatures would fix that.)

PoS is not more quantum-resistant, because of the situation with Shor's algorithm, and that a key compromise would be much more damaging.

It might be, in the future, if you replaced the keys, but it isn't now. Words mean things, and it really is important to use them correctly.

(Also, wouldn't the network respond by just raising the difficulty, miners respond by buying quantum computers, and the world to spin as usual?)

Re: Proof of stake is incapable of producing a consensus

#652

(my day job is developer on Proof-of-Stake Algorand block chain, I'm a developer, this may not be polished official PR) Article's theory about malicious old blocks doesn't hold up. Let's say I start a new node and verify history since the beginning. Somewhere along the line I'm connected to a malicious node which hands me a fictionalized block. It would need to have been signed by not just one but about 30-45 account…

What if Buffett just wants to see the world burn and doesn't care about getting the money back out? Or if a nation state or the central banks see it as an existential threat, they could consider it the cost of doing business? Maybe $30B to take out Algo or Solana and destroy trust in all PoS networks? That's a rounding error for them.

Everyone gets paid!

> Proof-of-Stake attacks aren't about having 51% of the CPU that overwhelms a Proof-of-Work system, but about having 60-70% of the _value_ in the network.

If a nation buys 2/3 of the coin and destroys the network, investors (as a whole) take a 1/3 loss. Then they can (re)start another PoS coin.

Ironically the nation would be up against the old saying that the market can stay irrational longer than you can remain solvent.

Re: Proof of stake is incapable of producing a consensus

#653
post #632

Earlier quoted context omitted.

A while ago, I asked folks if PoW happened entirely off-Earth using the Sun. Predictably, that was still a problem to some people which, to me, says everything.

"folks" is not me, that is certainly not the point I was making, and your "predictability" indicates that your comment is no less based on fact-free as those you criticize. Obviously, if the mining is done off-earth anywhere, it will not contribute to the CO2 problem, =ASSUMING= that it does not require on-earth energy resources to put the power generation there. Crypto mining also stops being a problem when 100% of…

OK, “Crypto is bad until the entire grid is decarbonized” is a reasonable position. It’s not airtight: there are a number of grids and they aren’t all interconnected, but at least it’s on the right track.

Re: Proof of stake is incapable of producing a consensus

#654
post #199

Earlier quoted context omitted.

The argument he's making is, you could stake for blocks 10000-10005 and get your money back. And then produce a big fake chain from 10,002 (in the middle of the time you were staking) -> 10,000,000 later, with an alternate history in which you didn't stop staking. I don't think this attack is particularly realistic for a lot of reasons, but PoW does have some small amounts of additional strength against these scenari…

it's not realistic on POW because you have to mine the block and spend the resources. on pow you dont have to. Thats the whole problem.

You wrote POW twice.

Re: Proof of stake is incapable of producing a consensus

#655

(my day job is developer on Proof-of-Stake Algorand block chain, I'm a developer, this may not be polished official PR) Article's theory about malicious old blocks doesn't hold up. Let's say I start a new node and verify history since the beginning. Somewhere along the line I'm connected to a malicious node which hands me a fictionalized block. It would need to have been signed by not just one but about 30-45 account…

I would add that the silly argument that a super-wealthy individual or a government could in theory degrade or destroy a transaction platform is applicable, not just to Algorand and other block chains, but also, more generally, to ANY transaction platform.

I mean, if Doctor Evil suddenly decided to spend tens of billions of dollars to destroy the three main credit card networks, he could probably do it. In fact, it might be easier and cheaper than attempting to degrade or bring down a distributed block chain network. The credit card networks are built upon many layers of ancient, pre-Internet technology, full of discoverable vulnerabilities and critical points-of-failure.

But we all know that it wouldn't happen. Doctor Evil would never want to do so, because even him, the most evil person in the world, would still want to be able to use his credit cards to eat out, go to the movies, and order stuff online. Also, he would never want to do something that would make him enemy #1 of every other person in the planet, including every other super-criminal!

What Doctor Evil actually wants to be able to do is figure out ways to steal or get balances from participants in the network without destroying the network: steal poorly protected wallets, hack into poorly secured exchanges, find ways to get blackmail payments on the network (e.g., by launching DoS attacks on the web), etc. The network itself is too useful to everyone for anyone to want to destroy it.

--

PS. For the record: I have no economic connection to Algorand the block chain nor to Algorand the company, but I'm (superficially) familiar with some of Silvio Micali's past work and also, I know one of the company's top executives. In my judgement, the Algorand block chain has great technology, and Algorand the company has really great people. Their main challenge, as I see it, is overcoming the powerful network effects already accruing to other block chains.

Re: Proof of stake is incapable of producing a consensus

#656
post #354

Earlier quoted context omitted.

If a halving forces a bunch of miners off the market (because their expected revenue drops below operating cost), there could be a huge glut of hardware flooding the market that is not profitable for honest mining but allows a bad actor to temporarily accumulate hashrate.

Bitcoin's price goes up faster than the effect of the halving (16x vs 0.5x every 4 years), and with the current chip shortage and slowdown of improvements miners generally plan for 4 years, but old, inefficient miners with low utilization can become an attack vector.

If your security model requires exponential increase in the value of crypto, it's a bad security model.

Re: Proof of stake is incapable of producing a consensus

#657

My opinion on PoS is that because no other community that I know of outside of bitcoin has a culture of running nodes normal people will just stake through exchanges. Now you have these exchanges acting not only as the in and out ramps but also as the biggest network validators meaning that they can direct transactions. Congratulations. You’ve just went full circle and invented central banks. Am I wrong? Would gladly…

No, you are right. In the old school PoS days when we did Blackcoin we were vehemently against staking from pools.

Re: Proof of stake is incapable of producing a consensus

#658

Earlier quoted context omitted.

No, not true. Nodes can literally just choose to use the version of software that provides the best money. You can’t choose to use the US monetary policy from 1960, for example. This has happened multiple times with attempted hard forks of Bitcoin which have failed because once you change the monetary policy once, the promise of hard money effect disappears. So the original monetary policy remains in place and the or…

I imagine the idea of a hard fork of Bitcoin may become more popular as the supply limit is approached and transaction fees go up. The current transaction fee is only a few dollars but the cost is over a hundred. Eventually the fee will have to cover the full cost and a hard fork may start to look more interesting. If this happens I can technically stay on the original protocol, but that would be rather pointless if…

I wouldn’t worry about it. Bitcoin incentivizes energy development. As the world moves to a Bitcoin standard, we will unlock new types of energy that were previously unproductive. It’s likely that energy will more cheap and plentiful under a Bitcoin standard, leading to downward pressure on transaction prices as mining is more economical. Also, more transactions are likely to move off chain to Lightning Network and sidechains.

Still plenty of scaling left in the Bitcoin ecosystem.

Re: Proof of stake is incapable of producing a consensus

#660
post #131

> Proof of stake is a scam. When I say that, I mean that proof of stake is (1) claimed to be a consensus system, and (2) constitutionally incapable of actually producing a consensus. Ok. Go break one of the many existing systems that operates using proof of stake then. If you've done this, you should be leading your article with it. If you haven't, you shouldn't be speaking. Proof of stake is not some theoretical thi…

If you'd read the article till the end, perhaps you'd understand where the author is coming from: PoS systems aren't getting hacked today because they aren't truly decentralised. You can't have decentralisation and security with POS, you have to choose one of these. All the projects currently active have chosen security for obvious reasons - they control the majority of validators to make sure nobody steals, and are just fancy centralised mints.
Post reply on HN