Skip to content

Comment on Proof of work algorithm in Monero based on random code execution

Comments

This PoW is rather complex and takes nontrivial amounts of time and memory to verify. It accepts these downsides in an attempt to achieve "ASIC resistance", which means limiting the potential efficiency gains of custom chips to a small factor like 2x or 3x. This should make their design and manufacture economically unattractive, with long ROI times. And thus allow commodity hardware to remain competitive.

This just another cat and mouse that just proves how flawed PoW is. It will always favor people who have access to cheap power thus consolidating the chain in the hands of few powerful people.

So there is a computer virus cat-and-mouse game, where viruses always get better, and antivirus software and new computer languages always get better. So what in your logic, does that somehow display "how flawed" computers in general are? We are still going to use them because we need them, and some people are still going to keep using PoW until that is the only viable method to achieve a decentralized trustless ledger.

There are decentralized ledgers that do not use PoW or PoS see for example XRPL.org/consensus.html

"Trust less" however is a matter of definition. You allays need to trust "something" outside of you control like for example the majority of validator nodes or miners or those in control of the mining pools etc. and on a lower level thous in control of the internet hardware like undersea cables and thous in control or power grids etc. etc. You need to trust them all that they don't turn off the nodes or collude and disconnect the nodes form each other etc.

However you need no trust to verify that what they already did so far on the ledger/chain is correct you can locally check that and verify for yourself that the current state of the ledger is correct (sill need to trust the code ofc but you could theoretically write you own code to do the verification).

For the most part you only need trust less verification of the past/present and reasonable certainty that there will be correct forward progress. However BTC for example can not deliver that because although you can verify the past/present state you have no way to assure that you will not see a different and longer chain later on that is also verifiable and correct and thus would change "your assumed correct past state".

"Trust less" however is a matter of definition.

Well yes, and you are stretching that definition really far, if you are presenting Ripple as a "trustless" platform. They are very far from Satoshi's cypherpunk vision (which while is perhaps extreme in some ways, a lot of people really like, and most importantly, it actually works in practice, in PoW chains). Ripple's "trustlessness" is about as trustless as the SWIFT network.

you have no way to assure that you will not see a different and longer chain later on that is also verifiable and correct and thus would change "your assumed correct past state".

Yes, you do, you wait for 6 confirmations. This has been, i fact, working in practice for all of the history of Bitcoin. This principle, in the context of the Bitcoin network has historically had less outage time than any one of the world's stock exchanges or banks.

I have never even mentioned Ripple. Ripple is a company like Google or Apple. They have have a service called RippleNet which is kinda like SWIFT. Nothing about that is relevant to what I said because I did not talk about Ripple and also not about RippleNet. The XRPL is NOT controlled by that company or any company. Again XRPL.org/consensus.html if you are interested in how the XRPL works.

Yes, you do, you wait for 6 confirmations.

That exactly what I said. You can not rely on the present state even if you can validate it and "know" it's "correct" it doesn't have to be the longest correct chain. Waiting 6 blocks may be the real world workaround but it does not change that fact. Also 6 blocks is arbitrary why not 7? or 21? Longer is obviously better but there is no certainty it just gets exponentially more certain the longer you wait.

Bitcoin network has historically had less outage time than any one of the world's stock exchanges or banks.

That's kinda a nonsense statement, the bitcoin network can not really have an outage because as long as there is one miner it technically still running. Or if large part of the network go offline it still keeps going for the rest there could be accidental forks and very long block times and what not but it can't be down. Since transaction take forever anyway because you need to wait many blocks, no one relies on it "being there" every second of the day. Its not like an stock exchange where at any second data has to be processed and any delay is "downtime". You just send your Tx into the network and it has plenty time to spread and eventually be included in the next block.

BTW the XRPL went online (completely centralized back then) in 2013 and since has never had any outages. In the early days there where some time synchronization problems which resulted in larger block times but they where still an order of magnitude shorter than bitcoins median block time.

The point is that it encourages centralisation, and where mining is centralised, miners can play games like blacklisting wallets if they want to. Particularly if, say, most of the mining capacity ends up somewhere with an authoritarian government that might take an interest.

(I am willing to admit here I don't know enough about monero in particular to grok whether the mining blacklist thing would work on that chain. I'm pretty sure it could for BTC)

Blacklisting addresses is not possible in Monero due to the use of stealth addresses, so this particular concern doesn't exist.

It is definitely a major flaw in Bitcoin and all other transparent blockchains.

And thus allow commodity hardware to remain competitive. This would make the system more robust, at the expense of increasing the power consumption. Is that correct? Doesn't seem really eco-friendly.

Everything about proof-of-work systems is not eco-friendly, and involves burning power 24/7, up to as much power as the produced cryptocurrency is worth. This seems perverse in a world where we're trying to cut down on energy use in almost every other area.

(no doubt someone will be along in a minute to tell me that cryptocurrency mining somehow uses "spare" electricity and burning the same amount of power as a mid-sized country isn't actually a problem at all!)

Nope! The[0] blockchain necessarily has use on the order of half the (non-dedicated) power generation capability it's host civilization in order to achieve proper security; otherwise the other half of said power could used to mount a 51% attack. It's less in practice, both because it's not worth that much to attack, and because it's not fully secure, but in theory, a Kardashev 3 civilization would need a Kardashev 2.97 or so energy expenditure to secure it's blockchain.

0: and it is a definite article, like the internet. There by definition can't be more than one at any given time.

PoW doesn't run on "power" in general, but on electricity. It can be trivial to convert some forms of power into electricity, but not all. One particular form of power which could seen as "wasteful" is that of burning fuels to create heat. A mining chip is a 100% efficient electricity to heat converter. If the cost of useful mining chips could become small enough, it would never make sense to use a traditional burner for heating a space, but using mining equipment would be preferable because you could recover some of the cost of the energy used to heat the space in potential mining rewards.

This is the goal we should aim for: As we're approaching the upper limit of Moore's Law, mining equipment will have a much longer lifetime and focus on reducing the cost of production could turn households and other buildings into data furnaces. It may not even be necessary for mining to be profitable - as long as there is there is a large enough ROI for users of such data furnace to cover its initial cost and eventually reduce their heating bill.

0: and it is a definite article, like the internet. There by definition can't be more than one at any given time.

Technically multiple chains can and do exist at any time because there is no "given time" - time is relative. Two miners at two ends of the earth may both produce a valid block at a given time (say, in UTC), but the nodes in proximity to them will receive their blocks at different times, due to distance and the fundamental speed limit of information transmission. The multiple chain conflict lasts until the next block is produced. Such conflicts could last for multiple blocks in a row, but with a probability which rapidly declines with number of blocks.

Two miners at two ends of the earth may both produce a valid block at a given time

Er, no, I mean you can't have more than one (distinct) live blockchain standard; eg if you have Bitcoin and Litecoin, one of them must be using less than 50% of the available hashing capacity (because otherwise it would add up to >100%), and therefore not be secure[0].

Good point about some power use having beneficial side effects (heating) in addition to the actual work though.

0: because if it ever actually needed the security - was more valuable to attack than the majority chain - then the miners on the majority chain would have a economic incentive to attack the minority chain and gain more from attacking than they lost from undefended attacks on the majority chain.

Obviously it's possible to have two blockchains in practice, just like it's possible to have two internets in practice, but there's a constant pressure to drain applications from the minority (quasi-)singleton into the majority singleton until the minority goes defunct from lack of use.

This seems empirically false as for example Bitcoin Cash is gaining more applications and usage compared to Bitcoin to a larger degree than it's 3% hashrate would suggest.

There have even been reorg attempts that have been defended by miners that support the minority chain, making it a bit more difficult to determine how secure a chain really is.

I'm fascinated by this idea of a civilization harnessing the power output of an entire galaxy to facilitate the movement of small green pieces of (virtual) paper.

... Thank you so much for reminding me that there's a non-negligible chance that someone would actually be stupid enough to do that.

The system trends towards consuming the same cost of power as the mining rewards, so increasing the efficiency of mining doesn't actually decrease power consumption, it just increases the overall hash rate

It doesn't necessarily affect the total power consumption, just the more democratic distribution of it. Where many more small players can be in the game, instead of consolidating all of the mining in a hands of a few centralized miners.

"Commodity hardware being competitive" isn't a desirable thing either? Remember when Ethereum caused a run on desirable GPUs? Miners were buying them by the truckload and locking them away in datacenters, where they basically computed hash collisions and made heat.

Personally I'd rather miners use ASICs for their hash collision wankery and leave the consumer markets alone. But I'd really like to see miners cease to exist because crypto comes with a huge environmental cost and so many externalities.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.