http://blog.zorinaq.com/bitcoin-electricity-consumption/
and the author of that has specific criticisms of the BECI calculation:
Also note that BECI overestimates the consumption: http://blog.zorinaq.com/serious-faults-in-beci/
(If Bitcoin didn't exist, the hydro power would still be there and would be used for something else, therefore less fossil fuel would have to be burned in its place.)
That's not a good assumption. There are many power plants in China in the middle of nowhere unconnected to much. It's completely plausible that the entire bitcoin network could run on clean energy that otherwise couldn't be used for much else because it's too remote (geothermal in Greenland or something).
All this outrage is misguided, the market incentives mean miners go to where the cheapest power is, all the industrial scale mining is located next to large renewables sources in China, Pacific NW, Scandanvia/Iceland.
The largest ethereum mine in the world is 100% renewable.
Blockchains only work by probably wasting in order to build a history. If you aren't wasting, then it wasn't expensive to build the history (it was subsidised), and it wouldn't be expensive to build a different history (that one could also be subsidized)
It's possible for something to provide a social benefit but not make sense for anyone to pay for as a for-profit business because others would get the same benefit and free ride off them. (Hence the problem of public goods in economics.)
So if the proof of work is only solving some general research problem, then it might not be feasible to double dip like you've described. That's why primecoin was able to avoid the problem.
My unprovable guess is that any other non-sellable problem will ultimately have the same outcome. It's interesting and useful for a bit, but when you have a billion dollars of hardware grinding nonstop for years in a row, you eventually exhaust everything interesting about the original problem and then it's back to the same waste you started with.
I've seen partial schemes for this, but no complete ones that would justify implementation. If a full and workable scheme could be devised, I would bet on it replacing sha256 based proof of work, eventually.
Edit: See my here for a model of how NP complete problems could fill the role of you could predict difficulty in advance. There wouldn't be double dipping because the person wanting the answer wouldn't pay both bounties.
If you attack the network you can steal billions - so if you have that much computing power available for your useful work, you can temporarially use it against the block chain.
As long as that mining power is available anywhere the chain isn't secure.
https://en.wikipedia.org/wiki/Primecoin
Generally, to have a useful PoW, it needs to meet some criteria:
1) Easily verifiable
2) Necessary work on the problem is easily quantifiable and estimable
3) Problem can be programmatically generated from random data.
One model might be NP-complete problems. Users feed in problem instances they want solved, with a bounty. You find out how many guesses it should take. A valid proof of work then requires solving enough such problems, combined, to exceed the difficulty threshold. (You'd also need to solve one based on the current known transaction history.)
The problem there is that it's hard to know if a given NP complete problem instance is "one of the hard ones" and to find such instances.
It would be great if it ever became profitable to mine this.
If a transaction is confirmed by 1 TWh of proof of work, that much energy is required to alter it, meanwhile the bitcoin network has expended even more energy.
It is still young, and the exponential growth in energy consumption is going to stop as an equilibrium is reached.
I don't see how your analogy applies.
The difference being that a bitcoin does not entitle you to some unit of energy or work produced from it. The energy used to verify bitcoin transactions is just lost.
Energy ensures bitcoin's ownership, not its value (although it does impact its value indirectly).