This is not true, Proof-of-stake creates a suitable incentive to verify transactions and maintain the network. It's a legitimate alternative to proof-of-work.
This is not true, Proof-of-stake creates a suitable incentive to verify transactions and maintain the network. It's a legitimate alternative to proof-of-work.
While it may be possible to make that checkpointing distributed, the only way that I'm aware of is to use proof of work. The easier path is to just checkpoint in the client, so that the trust comes from the github repository that pushes the client, or gets trusted updates from some trusted authority.
That's not to say that trustless consensus is necessary for a currency. I used to be a very strong believer that that was a necessary component, but I've begun to question that belief. The notion of censorship-resistance is an important part of why I liked Bitcoin in the first place, but may turn out not to be sufficiently valuable to people to impact coins that don't have that property.
It turns out that "trustless" is more subtle and not quite as discrete as we might've thought. While PoW coins like Bitcoin are probably ranked higher on this scale than others, it might not matter.
> That's not to say that trustless consensus is necessary for a currency.
Agreed. IMO these newer coins that are lower on the trustless scale would not have been possible without the high bar that Bitcoin set. But now, they are.
That's exactly it -- even in the centralized variants, the "trusted" authority doesn't have a lot of power. The main power they have is censoring transactions, both in the present (not accepting a new transaction) and in the past (rewriting the chain to omit a transaction and all of its dependents).
The ability to rewrite history is a dangerous one, but is mitigated by the fact that they can't do so undetected by the network. This is a social/economic effect rather than a cryptographic one, which has its own dangers, but means that the trusted authority risks losing (or forking) its status to a competing trusted authority for the same coin if the consensus of the network is that they cannot be trusted.
The forward security guarantees are just that the transactions are signed, and those signatures cannot be forged, even by the trusted authority, so there is no way for another actor (including the trusted authority) without access to your private keys to spend your coins.
(https://eprint.iacr.org/2016/889.pdf
https://news.ycombinator.com/item?id=13134363
https://www.reddit.com/r/ethereum/comments/52qfwl/provably_s...)
It would take the endorsement of someone that I consider extremely trustworthy to even go to the trouble of trying to deconstruct whether this approach is valid.
It stands, I think, in stark contrast to the simplicity of the proof-of-work based Sybil resistance, and the "central authority will sign the block" based Sybil resistance.
That said, given this discussion about the nature of trust, this scheme may work in effect, even if in the end it devolves into a centralized or social proof to find the correct chain. I'm not sure it adds a lot on top of that except instilling some potentially false sense of security in naively written nodes.
Are you not trusting the client you're running anyway? It seems like this is not a very big increase in trust.
There is such a mining incentive in proof-of-stake, block signers get rewarded.
> There is such a mining incentive in proof-of-stake, block signers get rewarded.
Not in all PoS coins, actually. And arguably you don't need it. Your stake's value is contingent on fulfilling the implicit promise of the network: honest, accurate, fast transactions.
I think it's a good article but "equitable distribution" is a big function of PoW that I thought was a critical ingredient but now I'm not so sure.
I submitted in the wrong thread