Live data from Hacker News

Proof of stake is incapable of producing a consensus

yanmaani.github.io

751–760 of 822 posts

Re: Proof of stake is incapable of producing a consensus

#751
post #727
post #693

Earlier quoted context omitted.

That's not what I said. Please don't attack a straw man. My main point was, and is, that the same attack-logic applies to ANY transaction network. The example with Doctor Evil was about other transaction networks. Why would Doctor Evil attack a block chain network when he could attack global/national/regional credit card/wire transfer/ACH networks, many of which are built upon ancient pre-Internet technology, are ful…

You didn’t answer the parent post. Your point was, in game theory, there’s no benefit in attacking the network or the loss is huge that it doesn’t worth the the attack. The parent post gave the counter point that there could be a benefit which we haven’t thought. If Dr Evil is heavily invested in 2 network, he might destroy one to focus on the remaining. The chance of the attack is low but it is not zero

he's a POS shill, there's no point arguing with these kinds of people. Proof of work will outlast all consensus protocols

Re: Proof of stake is incapable of producing a consensus

#752
post #687

Earlier quoted context omitted.

If you'd read the article till the end, perhaps you'd understand where the author is coming from: PoS systems aren't getting hacked today because they aren't truly decentralised. You can't have decentralisation and security with POS, you have to choose one of these. All the projects currently active have chosen security for obvious reasons - they control the majority of validators to make sure nobody steals, and are…

Except that they are though...You can go run a validator on Eth or Cardano right now.

Sure, but if the majority of validators are actually run by the project owners it's effectively centralised. And it's easy to maintain this control if you have the majority of coins to stake. It's not Sybil resistant for this reason - all validators could be owned by one person and you would have no way of knowing.

Re: Proof of stake is incapable of producing a consensus

#753

Earlier quoted context omitted.

I imagine the idea of a hard fork of Bitcoin may become more popular as the supply limit is approached and transaction fees go up. The current transaction fee is only a few dollars but the cost is over a hundred. Eventually the fee will have to cover the full cost and a hard fork may start to look more interesting. If this happens I can technically stay on the original protocol, but that would be rather pointless if…

I wouldn’t worry about it. Bitcoin incentivizes energy development. As the world moves to a Bitcoin standard, we will unlock new types of energy that were previously unproductive. It’s likely that energy will more cheap and plentiful under a Bitcoin standard, leading to downward pressure on transaction prices as mining is more economical. Also, more transactions are likely to move off chain to Lightning Network and s…

“as mining is more economical”

Mining doesn’t use a fixed amount of energy. As it becomes more economical more people will mine.

Re: Proof of stake is incapable of producing a consensus

#754
Get in touch with coinwalletrecoup . com to help you recover all your scammed funds. I got in touch with them when i was scammed by Tradestation to be precise, having deposited over $175,000 but still couldn’t withdraw any funds. They kept on telling me to deposit more to reach a certain amount but still couldn’t withdraw then it dawned on me that these people were playing games with my money. Within a week of contact, Coinwalletrecoup . com did the impossible, they recovered everything and also my ROI for the agreed duration of investment. Dont hesitate to contact them if you need any help. They’re the Best out there.

Re: Proof of stake is incapable of producing a consensus

#755

Earlier quoted context omitted.

Bitcoin uses about .1% of the worlds power currently. 10x less than you have suggested: https://nydig.com/research/report-bitcoin-net-zero The bitcoin reward also halves every 4 year, so even if price continues to appreciate, the effect is evened out by the fact that less is created every block over time. Lastly, bitcoin mining to could sustained solely by using stranded energy, which would otherwise be unused. Flare…

> Flared gas in texas, for instance, could provide more power than the network currently uses. While the amount of gas that is flared off is immense (25-30% of the actual consumption of the US and Europe), the problem is that it is only flared off because there are no pipelines to transport the gas away and the amount that the small oil wells produce is too low to justify the cost. If it were for me I'd force oil wel…

> the amount that the small oil wells produce is too low to justify the cost.

> but unfortunately "regulation" of any kind is seen as a bad thing in wide parts of the US.

So you would have them be regulated out of business? Most of us in the U.S. do indeed see that as a bad thing.

Re: Proof of stake is incapable of producing a consensus

#756
post #713

Earlier quoted context omitted.

> If it is recognised that you mine on more than one fork at a time, you lose the security deposit you gave before the fork. Yes, modern proof-of-stake algorithms work this way. The caveat is that at some point (on the order of months later) the security deposit is refunded, and at that point you can lie about the past without consequence. But this is a limited attack: you can only successfully lie to someone who has…

The original article asserts that this does not work according to their requirements since there's no way to independently verify which is the "real successor chain" - they just have to trust someone's word that chain A is true and chain B is not, and a convincing liar could provide them with opposite data. In schemes like Bitcoin, there's objective validation of the "longest chain" with the most work invested; in yo…

> they just have to trust someone's word that chain A is true and chain B is not, and a convincing liar could provide them with opposite data. In schemes like Bitcoin, there's objective validation of the "longest chain" with the most work invested;

Note that in Bitcoin you can have a fork in which both chains have equal length. The idea is that eventually the longest chain will be established, but if say 90% of the mining is malicious that malicious miner could ensure that most of the time both chains are of equal length.

With a PoS fork you can ask, which fork has the most amount of stake voting for it. An attacker that controls enough stake might be able to balance the total stake vote in the same way as a malicious miner could on Bitcoin.

In both cases if the core security assumption of the blockchain is violated, that blockchain should halt until that assumption is made sound again. If someone orphans the last two years of Bitcoin's blockchain something has gone horribly wrong. The fact that Bitcoin now switches to the longest chain doesn't actually address the problem that two years of transactions may have been rendered invalid.

Re: Proof of stake is incapable of producing a consensus

#757

Earlier quoted context omitted.

i don't know as much about this as you, but it seems to me that the attack you describe in the blog post would also require a successful eclipse attack? My understanding is that the attack you describe involves a cabal of "evil" validators signing some alternate chain (call it the "fake" chain) long after their stake is withdrawn, creating a fork in the distant past. Before they did this, they pretended to be good va…

> So after the attack, there are two conflicting sets of signatures signed using the evil cabal's private keys; those on the fake chain, and those on the real chain. So anyone in possession of both of these sets of signatures can conclude that the validators in the cabal are "evil", and then they can see that once the cabal's support is removed from consideration, the real chain had more valid validator support (at t…

> I think this is where you get the problem - if you just have two sets of signatures, how do you tell which is legitimate and which one isn't? How do you conclude in which set the cabal was lying?

I feel like you should be able to deduce it from the distribution of participation after the fork, right?

The “fake” chain would lose all honest verifiers (and all transactions from honest wallets?) which seems like it would be pretty detectable with simple statistical analysis. Staked nodes not participating (and active wallets not transacting) becomes less and less likely the longer the post-fork chain is.

Re: Proof of stake is incapable of producing a consensus

#758

Earlier quoted context omitted.

I want to take a moment to note what you're doing here. You're making a negative argument, in want of a better word. It goes something like this: 1. X is a problem? 2. But Y is also a problem, in my opinion. 3. X and Y are both the same, I think. 4. Therefore X is not a problem. We can - theoretically - verify the correctness of PoW software by downloading the source code, reading it over, etc. We can also refuse to…

> 3. X and Y are both the same, I think. It seems like you reject this premise, maintaining that PoW networks are objectively verifiable? But you didn't really refute the parent's point there, which was that there are no "objective standards" in deciding which bootstrap nodes to use; it's ultimately a matter of trust. If I trust the wrong bootstrap nodes, I can be eclipsed from the real network. Granted, I only have…

> It seems like you reject this premise, maintaining that PoW networks are objectively verifiable? But you didn't really refute the parent's point there, which was that there are no "objective standards" in deciding which bootstrap nodes to use; it's ultimately a matter of trust. If I trust the wrong bootstrap nodes, I can be eclipsed from the real network.

Right, but it's not about trust in the same way. I can add an infinite list of bootstrap nodes. Quantity matters, not quality.

> But PoS involves a very similar 1-of-n trust model; I can request checkpoints from n semi-trusted sources and check that they match.

"Very similar," not the same. You need "semi-trusted sources", and there's no objective standard in case they disagree.

Re: Proof of stake is incapable of producing a consensus

#759

Earlier quoted context omitted.

> So after the attack, there are two conflicting sets of signatures signed using the evil cabal's private keys; those on the fake chain, and those on the real chain. So anyone in possession of both of these sets of signatures can conclude that the validators in the cabal are "evil", and then they can see that once the cabal's support is removed from consideration, the real chain had more valid validator support (at t…

> I think this is where you get the problem - if you just have two sets of signatures, how do you tell which is legitimate and which one isn't? How do you conclude in which set the cabal was lying? I feel like you should be able to deduce it from the distribution of participation after the fork, right? The “fake” chain would lose all honest verifiers (and all transactions from honest wallets?) which seems like it wou…

> The “fake” chain would lose all honest verifiers (and all transactions from honest wallets?) which seems like it would be pretty detectable with simple statistical analysis. Staked nodes not participating (and active wallets not transacting) becomes less and less likely the longer the post-fork chain is.

But you don't know who's honest - you may as well be saying the real chain lost all the dishonest verifiers.

Re: Proof of stake is incapable of producing a consensus

#760
post #716

Earlier quoted context omitted.

> So after the attack, there are two conflicting sets of signatures signed using the evil cabal's private keys; those on the fake chain, and those on the real chain. So anyone in possession of both of these sets of signatures can conclude that the validators in the cabal are "evil", and then they can see that once the cabal's support is removed from consideration, the real chain had more valid validator support (at t…

If you actually see two conflicting chains (either proof-of-work or proof-of-stake) with large numbers of people vouching for both, then the correct chain is not necessarily "whichever one is longer". Well, it could be, for you; "correct" is subjective. But by assumption in this scenario, a large number of people disagree, and you might want to transact with some of them. There is no way for software to decide this o…

None of this actually refutes my point. You're just suggesting that the fact that PoS is incapable of producing a consensus is outweighed by it allegedly being more decentralized. Be that as it may, it's not relevant to this thread.

Is it even true? Steemit had the exchanges do a hostile takeover, because everyone was staking through them.

Post reply on HN