Live data from Hacker News

Proof of stake is incapable of producing a consensus

yanmaani.github.io

761–770 of 822 posts

Re: Proof of stake is incapable of producing a consensus

#761

Earlier quoted context omitted.

PoS is not more quantum-resistant, because of the situation with Shor's algorithm, and that a key compromise would be much more damaging. It might be, in the future, if you replaced the keys, but it isn't now. Words mean things, and it really is important to use them correctly. (Also, wouldn't the network respond by just raising the difficulty, miners respond by buying quantum computers, and the world to spin as usua…

PoS is a class of consensus protocol, not any particular blockchain. It's orthogonal to signature algorithms. A blockchain can incorporate any combination of consensus algorithm and signature algorithm. So yes, please use your terms correctly. If sufficiently powerful quantum computers become readily available to anyone, sure, everybody will upgrade. Given the exotic hardware they typically require, it seems likely t…

If you're fine with changing algorithms, wouldn't PoW also be able to change to something more quantum-resistant?

Re: Proof of stake is incapable of producing a consensus

#762

Earlier quoted context omitted.

I imagine the idea of a hard fork of Bitcoin may become more popular as the supply limit is approached and transaction fees go up. The current transaction fee is only a few dollars but the cost is over a hundred. Eventually the fee will have to cover the full cost and a hard fork may start to look more interesting. If this happens I can technically stay on the original protocol, but that would be rather pointless if…

I wouldn’t worry about it. Bitcoin incentivizes energy development. As the world moves to a Bitcoin standard, we will unlock new types of energy that were previously unproductive. It’s likely that energy will more cheap and plentiful under a Bitcoin standard, leading to downward pressure on transaction prices as mining is more economical. Also, more transactions are likely to move off chain to Lightning Network and s…

Bitcoin proof-of-work difficulty must always increase, the electrical needs are always ever-growing. While you claim that incentivizing electrical production is what POW does, in reality it is a large drain of electricity on a finite electrical grids capacity and it DOES take away from other uses of electricity LIKE aluminum smelting or running hospitals. It is an active and actual source of pollution and uses more electricity than most countries. You can’t handwave this away or insist upon your rhetorical framework when. The apparent physical real world consequences of POW cryptocurrency cannot be evaded or ignored.

Re: Proof of stake is incapable of producing a consensus

#763
post #668

Earlier quoted context omitted.

I wouldn’t worry about it. Bitcoin incentivizes energy development. As the world moves to a Bitcoin standard, we will unlock new types of energy that were previously unproductive. It’s likely that energy will more cheap and plentiful under a Bitcoin standard, leading to downward pressure on transaction prices as mining is more economical. Also, more transactions are likely to move off chain to Lightning Network and s…

I agree with this. Just want to add, bitcoin mining can happen in remote locations with available power (hydro, geothermal) which are too far from cities to be transported by power wires. There is a limit to how far you can transmit electricity through wires. So, there are tons of untapped natural energy sources.

And precisely in places like these, such as Niagara Falls, you see coin mining displacing tangible goods production due to both needing cheap electricity and one being more profitable than the other. In this case the market is not thinking very clearly in long term priorities, nor is infinite development of hydro and geothermal possible. Actually, this is about realizing that we live on a finite planet with finite resources that a finite amount of humans can finitely exploit finite parts of before the whole thing goes catawumpus. POW and current cryptocurrency systems are thoughtlessly and needlessly wasteful and represent inelegant architecture and brute force hackery like lightnig to correct what ultimately isn’t scalable: blockchain ledgers and fast transaction speeds vs centralization and speed. Look at DNS, for example, and how slow that is, and it’s architecture amd full vs partial copies of ledgers and jeiraexhical canonical lookups etc.

Re: Proof of stake is incapable of producing a consensus

#764
post #696

Earlier quoted context omitted.

OK, “Crypto is bad until the entire grid is decarbonized” is a reasonable position. It’s not airtight: there are a number of grids and they aren’t all interconnected, but at least it’s on the right track.

Yes, I agree, and was thinking something like that after I wrote - the range is not actually global, but basically grid-scale. For example, if the Texas grid became ~100% wind and other clean-source-powered, then BTC mining in that grid would not in any practical sense consume clean power that could otherwise displace dirty power. The 100kW you use to feed your miners could in theory be used to reduce production from…

> So, maybe everyone with crypto should, instead of convening to buy the constitution or a basketball team, go fund the takeover and conversion of an entire grid to clean energy, and build all the miners there.

Agreed.

> That said, if it gets big and the miners are consuming enough production of solar panels and wind turbines to slow clean energy buildout on other grids, that's the second order of the same problem.

True, but even that's not zero-sum: demand drives investment in production which increases supply leading to commoditization. Commoditization, in turn, makes the solution (solar, wind components) more accessible to a broader range of the economy.

GPUs for machine learning wouldn't be where they are today if it wasn't for gamers creating a demand floor that subsidized the research into better hardware.

Re: Proof of stake is incapable of producing a consensus

#765

Earlier quoted context omitted.

Yeah, I think that's right. The hypothesis was that on average , one in a million cards is a hit. That implies that if you scratch a million cards, you have a 50:50 chance of a hit. That the author got this basic thing wrong doesn't inspire much confidence in the rest of his reasoning.

Well, I guess in real life blockchains it’s like the latter case. You have a block and look for a nonce. There is an effectively infinite stream of nonces (“lottery tickets”). You have no guarantee that even one works, other than statistical hope. So then if probability of a match is 1 in X, you expect to have to do X attempts. I have other issues with the article but this bit seems ok.

/me not a statistician!

I'm not clear how "expected no. of attempts for X" is related to the probability of X. And I seem to be struggling to recall what little I used to know about probability.

I'd welcome a (link to a) clear unpacking of this scenario. I'm feeling rather stupid, as if I've had a stroke and lost a mental faculty. It seems to be a straightforward and obvious scenario, but I've lost confidence in my reasoning about it.

Re: Proof of stake is incapable of producing a consensus

#766

Earlier quoted context omitted.

> So after the attack, there are two conflicting sets of signatures signed using the evil cabal's private keys; those on the fake chain, and those on the real chain. So anyone in possession of both of these sets of signatures can conclude that the validators in the cabal are "evil", and then they can see that once the cabal's support is removed from consideration, the real chain had more valid validator support (at t…

> I think this is where you get the problem - if you just have two sets of signatures, how do you tell which is legitimate and which one isn't? How do you conclude in which set the cabal was lying? I feel like you should be able to deduce it from the distribution of participation after the fork, right? The “fake” chain would lose all honest verifiers (and all transactions from honest wallets?) which seems like it wou…

How do you know what are honest verifiers and wallets?

Re: Proof of stake is incapable of producing a consensus

#767
post #78

Earlier quoted context omitted.

Here’s a recent ETH2 block: https://beaconcha.in/block/2604970#votes It was voted for by 8000+ validators. Many of them have been validating since beacon chain genesis a year ago. There are like 260k validators active right now. I find it highly unlikely some entity is going to come along and try to pretend their alternate history, with a whole new set of hundreds of thousands of validators (which wouldn’t be support…

ETH2 was years in the making, with multiple delays and not fully migrated yet precisely because of how unsafe standard PoS is. Vitalik and co spent years researching the best mitigations. Right now, it seems to be one of the best protected PoS chains. It's still fairly new, with novel mitigations, so it still doesn't stand the test of time against all possible attack vectors. In that sense, it still can't be consider…

Is there a known limit for the energy to hash ratio ?

Re: Proof of stake is incapable of producing a consensus

#768

Earlier quoted context omitted.

> I think this is where you get the problem - if you just have two sets of signatures, how do you tell which is legitimate and which one isn't? How do you conclude in which set the cabal was lying? I feel like you should be able to deduce it from the distribution of participation after the fork, right? The “fake” chain would lose all honest verifiers (and all transactions from honest wallets?) which seems like it wou…

How do you know what are honest verifiers and wallets?

You any specific verifier/wallet, you won't - but the fake chain will have 0 uncompromised actors after the fork.

Which means that large stakeholders suddenly stop verifying blocks. Long-term active wallets stop transacting.

The same might be true for both chains after the fork, but I would imagine the fake one would have a larger change in participation (weighting older wallets and larger stakes) than the real one.

Re: Proof of stake is incapable of producing a consensus

#769
post #256

The author has good points, bad points and badly explained stuff. The article is a bit confusing at best and disorientating at worst. But I'll try to explain here, why the author thinks that PoW is magical. It's still bound to the readers, or philosophers, to pull whatever they want from this. Proof of Work creates time. In a decentralized system, you don't have time. If time was provable, the double-spending problem…

>If time was provable, the double-spending problem would not happen.

Can't you sign two transactions at the same time? If yes then you could double-spend even without faking timestamps.

Re: Proof of stake is incapable of producing a consensus

#770

Earlier quoted context omitted.

> Just read, please. You're coming off worse in this argument because you seem to realize on some level they're just using different (possibly wrong) terms in their accurate description of the mechanisms, but then you keep making snide remarks that imply they don't understand the mechanisms.

i in fact do insist on them not understanding the mechanism. trying to force incoherent terminology is just the largest red flag signifying that lack of understanding. snide remarks is my bad, i definitely lost my patience, it's hard to argue with somebody saying that sky is pink because they've changed what pink means.

Red flag, sure. But when they say things like "The peer-reviewed paper to which I linked, which I am not proposing as a replacement for Bitcoin, explains (to those who are willing to read it) why the block being chosen before or after the leader election does not matter when it comes to the security and consensus properties of Bitcoin." it seems very clear to me that they do understand the mechanism, despite that red flag.

I think your analogy to flat earth was better. Because sure, treating the earth as flat isn't correct, but it's often a perfectly good approximation, and arguing about whether a big field is flat or not is a giant waste of time. Don't completely dismiss someone because they use those terms.

"Leader" or not, it's basically equivalent. And the process of letting miners input yes/no values for whether they support a proposal into their block, averaged over thousands of blocks, gives you the same result as "voting". So talk about whether those results are useful.

Post reply on HN