REM: Resource-efficient mining for blockchains
blog.acolyer.org
blog.acolyer.org
Would you also criticize the current state of Ethereum as "proof of Nvidia" and imply that Ethereum is centrally controlled by Nvidia, just because Nvidia makes the GPUs that many people are using to mine it?
Nvidia does not have this ability in Ethereum. They have to pay for electricity just like everyone else.
Alternatively, PoS is probably just fine. I'm not sure this is really better in any way.
They are on the early stages of developing sharding/"sub-chains", but it's still unclear if it's even viable. And it will never be a truly efficient computing platform -- for them it must be completely secure and only cheap enough to enable the most interesting distributed apps, which is a different beast from PoUW discussed here.
Overall I'm skeptic (even of PoUW). That's because verifying work is usually almost as difficult as computing. I believe the only true solution to this is Fully Homomorphic encryption (FHE), but known constructions so far have had absolutely massive constants.
Is there enough demand of highly-assymetric and verifiable NP-hard like problems?
More complex methods allow fraud to be proven with only a partial computation, by applying merkle proofs. I haven't really dug into it but the TrueBit paper is probably the best source: https://truebit.io/
Where did you get that idea? What about zk-proofs, like SNARKs and STARKs? I'm working on a multiparty computation system right now that uses a proof system to offload costly computation.
As a challenge, take the problem of computing 1000000 iterations of a memory-hard hash function, such as scrypt or argon2d. If someone presents you a hash (of length N), the best you can do to verify it is actually compute the iterated hash function (assuming it has no cryptographic weakness). This would prove, in particular, that my required method is impossible (i.e. there are at least some problems that can't be efficient offloaded).
What kind of problems can the technologies you cited offload?
>skew the rng and/or manipulate the instruction counter
Congratulations, you "hacked" REMCoin.