Live data from Hacker News

Proof of stake is incapable of producing a consensus

yanmaani.github.io

671–680 of 822 posts

Re: Proof of stake is incapable of producing a consensus

#671

(my day job is developer on Proof-of-Stake Algorand block chain, I'm a developer, this may not be polished official PR) Article's theory about malicious old blocks doesn't hold up. Let's say I start a new node and verify history since the beginning. Somewhere along the line I'm connected to a malicious node which hands me a fictionalized block. It would need to have been signed by not just one but about 30-45 account…

> Article's theory about malicious old blocks doesn't hold up.

I don't mean to be rude here, but none of what you have said refutes my point.

The attack here is that you control keys that (1) once held 67% of the value, and (2) no longer do. Because they did hold value once, they are dangerous to consensus. Because they no longer hold value, nothing is sunk into the network, so the attacker bears no cost or risk.

To apply your analogy: I don't have to be Warren Buffet, I just have to riffle through his trash.

Re: Proof of stake is incapable of producing a consensus

#672
post #78

Earlier quoted context omitted.

Here’s a recent ETH2 block: https://beaconcha.in/block/2604970#votes It was voted for by 8000+ validators. Many of them have been validating since beacon chain genesis a year ago. There are like 260k validators active right now. I find it highly unlikely some entity is going to come along and try to pretend their alternate history, with a whole new set of hundreds of thousands of validators (which wouldn’t be support…

How is that different from 8000-of-260k multisig?

It's similar in that 8k sigs are collected and coalesced to sign something. From there the differences begin. M-of-N schemes must be orchestrated ahead of time, using Shamir's or by constructing a BTC multisig UTXO or something. When signing, one may choose freely among the key shards. It's performed in the usual execution layer of the chain.

Whereas in ETH PoS, validation happens in the consensus layer, following strict self-imposed rules. With each new block, one validator is chosen to propose the block, and thousands of validators are asked to back the proposer. The proposer and attestors are chosen randomly but specifically with no freedom to mix and match; the chosen validators must attest (and receive a reward) or else be penalized. Validators don't know each other and they don't need to cooperate to create a shared key ahead of time, all they have to do is deposit and follow the rules. The signatures are agglomerated by [BLS ellipical curve stuff idk it's magic] and help to form the consensus chain itself.

Re: Proof of stake is incapable of producing a consensus

#673

Earlier quoted context omitted.

There's also an alternative: 3. cryptocurrencies stop the Austrian economics fetishism and index the coin reward to the mining difficulty. That means getting rid of the fixed coin supply. That would stabilize the price of the token a lot (since price going up would increase the mining appeal, thus expanding the money supply, driving the price down) and also make it much more usable as a mean of payment (the number of…

The focus on fixed money supply seems a little absurd to me anyway, given the triviality of creating new crypto-currencies, and the relatively low transaction costs of trading between them. Imagine making a case for returning to the gold standard, when thousands of other choices for new precious metals, all with the same performance characteristics, were literally just lying around, and a network of drones would let…

Indeed. And I personally love to remind the fans of bitcoin's limited supply that with the different forks the bitcoin faced during its life, the bitcoin money supply grew a lot more than it was supposed to, without causing any price collapse.

Re: Proof of stake is incapable of producing a consensus

#674
post #655

(my day job is developer on Proof-of-Stake Algorand block chain, I'm a developer, this may not be polished official PR) Article's theory about malicious old blocks doesn't hold up. Let's say I start a new node and verify history since the beginning. Somewhere along the line I'm connected to a malicious node which hands me a fictionalized block. It would need to have been signed by not just one but about 30-45 account…

I would add that the silly argument that a super-wealthy individual or a government could in theory degrade or destroy a transaction platform is applicable, not just to Algorand and other block chains, but also, more generally, to ANY transaction platform . I mean, if Doctor Evil suddenly decided to spend tens of billions of dollars to destroy the three main credit card networks, he could probably do it. In fact, it…

IMO people listing things that discourage an attack (people will hate him, his credit cards won't work, etc) are just people trying to comfort themselves. It's like saying, "No one would break into my home because they might hurt themselves breaking in, or I might hurt them up, or they might get caught by the police and go to jail. It's just too risky."

At the end of the day, Dr. Evil will gladly spend 10s of billions to destroy the network if doing so nets him 100s of billions. Stop listing reasons people won't attack the network and start listing reasons they would.

Re: Proof of stake is incapable of producing a consensus

#675
post #78

Earlier quoted context omitted.

Here’s a recent ETH2 block: https://beaconcha.in/block/2604970#votes It was voted for by 8000+ validators. Many of them have been validating since beacon chain genesis a year ago. There are like 260k validators active right now. I find it highly unlikely some entity is going to come along and try to pretend their alternate history, with a whole new set of hundreds of thousands of validators (which wouldn’t be support…

> It was voted for by 8000+ validators. Which parts of this are checked by the client software, and which parts are just checked by interested humans in the block explorer? There's a trade-off here. If you require 8000 guys to all vote in favor of your block, what does the client do if it only sees 7999? > which wouldn’t be supported by any ETH1 deposits ... signed by 260k freshly generated public keys You misunderst…

The system is fault tolerant. You typically get 99.X% participating. Any validator that doesn't perform their duty in a timely fashion is penalized and eventually ejected if they are disruptive.

Those private keys are useless unless you had something like 50% of all the active validators' keys. So, hundreds of thousands of private keys hacked. You're not going to be able to damage consensus using a few old leaked private keys. The best you could do would be to slash some active validators and get them ejected, but the chain would carry on finalizing without them.

Re: Proof of stake is incapable of producing a consensus

#676
post #454
post #314

Earlier quoted context omitted.

> Literally unprecedented in human history. Hardly unprecedented, considering that until very recently nations did not have a monetary policy.

Monetary policy goes at least as far back as the Roman Empire, which adulterated their money supply over time.

I don't think this what economists understand by monetary policy.

Re: Proof of stake is incapable of producing a consensus

#677

Earlier quoted context omitted.

I think the argument was that you could withdraw at 201 then sign new 200b messages.

But then everyone has a signature that you exited at 200

Which you don’t include in your alternate chain.

Re: Proof of stake is incapable of producing a consensus

#679
post #631

Earlier quoted context omitted.

It's a temporary state, until the PoS coin market cap gets too large to be attackable. Bitcoin's market cap is in the 1T range now, Ethereum is close to half that. Buffet couldn't do a thing against a PoS coin that large, and it would be a serious commitment and risk even for a nation state. Buffet could take down some random smaller coin, maybe, at the cost of most of his personal fortune, but if he did so the world…

PoS encourages centralized exchange-held staking, which means that there are only a handful of failure/pressure points. In other words, a government doesn’t have to buy 66% of the stake - merely compel the exchanges.

> PoS encourages centralized exchange-held staking

Not when the protocol actively encourages decentralization by cutting off staking rewards to larger pools, like what Cardano does (as one example). Sure, the exchanges can (and probably do) run multiple pools, but so can anyone else, and for far less expense than is required for mining.

Re: Proof of stake is incapable of producing a consensus

#680

Earlier quoted context omitted.

What do you mean by "allowed to"? In a PoW system, the PoW is a distributed timekeeping device. That's the actual operation the PoW does, and the distributed timekeeping is then what you can build a blockchain on. PoS doesn't not do distributed timekeeping . If you sign a block now, then go back later and sign a different block with the same key, there's no distributed clock that can be used to prove which was actual…

The clock issue is an excellent point, but the ethereum PoS have a nano scale PoW mechanism for this exact problem. Look at VFD "Verifiable Delay Functions" [1]. In short: If you take the pbkdf2 key derivation function: its job is to slow down hashing a thousand fold or so, so that hashing an entire search space becomes impractical. You give your secret in input, and it gives you a hash, let's say, in 1 second. You'l…

The site isn’t particularly accessible for a quick discussion so I appreciate your explanation, thank you.

However, I’m not sure I understand how this is supposed to help. Proving that a few seconds passed just slows down block generation a little, but this cannot be a significant barrier to block generation or else you just have a full PoW system again. And if it’s not a significant barrier then it’s not clear to me what this is supposed to do, beyond preventing me from generating and signing a new block within milliseconds of some event happening.

But since the “nano scale” PoW doesn’t define the rate of block generation, it just establishes a lower bound, it feels like it’s just a speed bump for anyone trying to attack the system. If it only takes 10 seconds to rebuild the last 100 minutes worth of blocks, then it doesn’t establish a universal clock and therefore cannot prove which block came first.

Post reply on HN