BitTorrent Inventor Bram Cohen Will Start His Own Cryptocurrency
torrentfreak.com
torrentfreak.com
Of course, the Internet doesn’t remember that he worked on cryptocurrency almost 20 years ago (with Zooko of ZCash) before he started BitTorrent. Pepperidge Farm remembers.
> In group of order 2^k, square k-1 times to find a square root
I don't want to say anything stupid, but I don't know if this is trivially true, for instance in [the multiplicative group of] a field of char 2, square is linear and so it's square root.
Edit: to clarify, in a field of char 2 the multiplicative group has order 2^q-1, which can't be 2^k. I'm just giving this as an example of a group where square root is fast.
From the video, it sounds like the claim is that sqrt(x) = x^(2^(k-1)), which you verify by checking that x=x^(2^k) [0]. However, since the order of the group is 2^k, it is an elementary result of group theory that x^(2^k)=1 [1]
[0] That is, you square the claimed root which should be x^(2^(k-1)).
EDIT: watching the video some more for clues, he does mention that he uses a particular kind of group, so the claimed property does not need to hold for any group of order 2^k. However, as I argue above, I still don't see how it is possible for any group of order 2^k.
[1] This is a direct result of Lagranges theorem. https://en.wikipedia.org/wiki/Lagrange%27s_theorem_(group_th...
Further, if you are given the value y=x^2, then no power of y will give you x.
We also go into the pre-history of BitTorrent at Mojo Nation.
Citation needed.
So I get that he's trying to get at the fact that it's not a large majority, but 51% is a majority.
It's odd that it wasn't architected to require a super-majority of 60-66% from the outset. That would make it more resilient.
If instead it'd been defined as requiring a two-thirds majority then that's how consensus would be achieved. The system would simply halt until that came about.
I don't quite follow what you mean here: longest chain wins is a central tenet of cryptocurrency design, and even if you did something with consensus in the product a majority could still hardfork away from that design. Am I missing something here?
but if B and C are working together, it implies there is some sort of relationship between them so they could be coordinated together(e.g. owned by same org), this not the case I am trying to use here; my case is really 3 independent miners
A in your scenario would likely be malicious to the network would have to be a state actor looking to kill the network. Luckily, in a sufficiently large network even governments are bound by CPU/GPU supply. It gets even harder for this kind of state maliciousness to take place in tech like ethereum: whose PoW function is both CPU and memory bound (I.e. You cannot use custom ASICs)
I casually enjoy cryptocurrency, so anyone who knows better please correct me if you find me incorrect.
With a 60% consensus, 41% can deadlock the network. A deadlock of a financial transaction system is de facto control (if we believe Dune).
With a 50% consensus, 51% can deadlock the network, but have no need to, as they're already capable of voting their agenda in.
Any increase of consensus past 50% gives an increasingly small minority group the power to deadlock the network. Further, 50% is the magic point at which a minority can neither overrule a majority on consensus nor deadlock the network.
Deviation from that middle increases one of those two failure modes.
Can't you have a "reputation". If a node is consistently acting in bad faith you blacklist it.
This quote is quite reductive of all the game theory involved with Bitcoin and I'd argue against Bram on his statement. In fact, Bitcoin is a democratic protocol. Nodes organize around which miners meet their protocol's consensus settings. All that a miner with >50% of the hashrate can do is attempt to reorg a chain of blocks to double spend or DoS the chain by not including certain transaction. A miner with >50% of hashrate cannot force me to accept blocks bigger than my consensus rules state or accept some new ScriptSig with different OP codes.
I mean, we joke about how corrupt American politics are, but it's not like the Kochs or George Soros or whoever can actually control 51% of the vote directly.
https://eprint.iacr.org/2016/989.pdf
Litecoin uses scrypt.
I wrote a game for programmers about 5 years ago that used a toy proof-of-storage system. It gave as many 1GB blobs to players as requested, picked random chunks and stored checksums of those. The player doesn't know which chunks have been picked.
Some hours later you could start the challenge that you still have the file and the system challenged you to send the checksum of the chunks it picked. If you could answer this, you obviously still have the file and got points.
This allowed the system to force a player to store 1GB of data while the verification only needed some bytes of storage.
Broken how?
So while scrypt itself is not broken, its feasibility in a proof of work system with a serious memory footprint (e.g. exceeding a single DRAM chip) is.
https://stealthisshow.com/s02e14/
http://content.blubrry.com/stealthisshow/S02_E13_The_Future_...
That alone could be a reason too. My other guesses: versatility and in some countries ease of use when compared to standard solutions.
It's the hot new thing, there's a frontrunner but not an established winner, and investors are still willing to give people money for it.
Sending value anywhere in the world in a very short amount of time without having to trust a middleman.
That's what cryptocurrencies could offer.
All of the transparent block chains create another problem, however: Pervasive surveillance, and chilling effects. For that reason, I like the singular cryptocurrency which offers the anonymity and fungibility of cash, without a pre-mine scam or a graft tax, Monero. I think it is the only exemplar which offers all of the features required to serve as both a store of wealth and a medium of exchange. (Privacy being a requirement for fungibility.)
"Burstcoin is busted. For proofs of work you can throw any random bullshit together and it will be a functioning proof of work. Proofs of space aren't like that."