Nothing Is Cheaper Than Proof of Work (2015)
truthcoin.info
truthcoin.info
As an analogy, if resources are spent on war, I think it's not so far fetched to say that there is an extraordinary amount of waste in terms of human talent, life, physical infrastructure, and diverted resources. Just because someone spends money doesn't mean it was well spent (unless you measure such things in money).
Society happily survived without proof of work for millennia, but I think it’s important to remember that entertainment is the good part of life that proof of work is ultimately supposed to enable.
I mean this in the same sense the founding fathers did when the wrote stuff like:
>“I must study politics and war that my sons may have liberty to study mathematics and philosophy.”
That is, proof of work is the tradeoff that ultimately should enable people’s personal entertainment and happiness.
If more of the former means less of the latter, I think we are in a bad way.
The question is not whether society does fine without proof of work, but whether the PoW mechanism generates marginal trust at a lower cost than the existing social and institutional mechanisms. Lawyers, police, and the legal and state apparatus are expensive, centralized, and slow. Humans (especially educated, first world humans) are also energetically expensive to run!
Basically, you are only accounting for the cost of PoW, which are trivial to measure, but not carefully accounting for the benefits, which are difficult.
You can put an awful lot of lawyers, police, legal and state apparatus in 280'000 homes.
It is sufficient to house all state and full-time employees of the state of Illinois [0] entirely, which unlike bitcoin can do more than transfer wealth.
Illinois has a population of 12'800'000 people [2], bitcoin.info "claims" 23 Million wallet users, however that is a poor number since it only seems to count the number of wallet addresses ever used, the number of unique addresses used is closer to 500'000 and the number of daily users is 200'000 at the current date, which with some rough statistics yields a more realistic 3-8 million users.
In conclusion: Employing humans to do the entire state things allows to service 1.5 to 4 times as many people as bitcoin is currently doing and it also includes a much much broader range of services than bitcoin.
[0]: http://www.governing.com/gov-data/public-workforce-salaries/... [1]: https://www.thebalance.com/how-much-power-does-the-bitcoin-n... [2]: https://suburbanstats.org/population/how-many-people-live-in...
I agree that bitcoin's PoW mechanism as it is today has relatively poor bang for your buck, but there are many potential mechanisms for increasing efficiency by an order of magnitude or more (dPoS, state channels, sharding, etc.).
Ethereum has a lot more potential to not just be a distributed ledger, but a distributed secured computer. If all you are interested in is moving around value, something like Nano might achieve that while burning far less computation that the Bitcoin network would require per transactions.
We should keep in mind that when discussing Bitcoin we're comparing the first version of a nascent technology to mature financial institutions that have developed over hundreds of years.
Nowhere else is this kind of thing celebrated.
This is a weird critique. Blockchains and banks are very different in their use cases. It’s like you’re criticizing someone for choosing a sorting algorithm over a deduplication algoritihm - they do vaguely the same thing, but no one likes the sorting algorithm because it’s less efficient, they like it because it actually sorts.
If you are choosing a blockchain (algorithm A) over a bank (algorithm B), you are doing so because you want the things a blockchain offers that a bank doesn’t. You can’t do comparative algorithm analysis on algorithms that aren’t comparable.
Or, think of it this way: requiring trust is not a bug, it's a feature. Trust is the "clever hack" humans have that allows us to coordinate at scale without absurdly wasteful solutions like blockchain. From this POV, bitcoin as a part of global economy is making a step backwards.
Why would a GPU manufacturer prefer that an end user use their GPU for games rather than cryptocurrency mining?
It would be rather convenient for them if older miner GPUs were quickly made 'incompatible' with the needs of the consumer gamer / PC market.
They don’t prefer anything in particular, they’d just like to keep both markets. They can bifurcate the market and earn more from each demographic rather than let one dominate the other by inefficiently adapting gaming cards to homelab supercomputing.
In one scenario, they let things continue and the mining market reduces supply for the gaming market, which makes their overall market share more brittle. In the other scenario, they increase the volume of cards purchased by gamers, securing that market, while selling more optimized, higher cost mining cards to miners. This has the added benefit of product diversity.
As for why they don't just make more cards: The volatility of cryptocurrencies makes manufacturers hesitant to ramp up production. They are afraid of being stuck with an oversupply of cards if the bottom falls out of the market.
Given that they use pretty different interfaces to the cards this seems pretty feasible.
You can see the effects of this: Nvidia is selling their GPUs at close to MSRP on their website with a set limit on the amount you can buy per customer. If they're making bank on cryptocurrency mining why would they hurt their sales by doing that? To me that move only makes sense if Nvidia wouldn't be making a lot of money otherwise and highly valued their current gaming customers.
Because one is a fad the other is their major customers (though the market for ML is growing and nVidia is investing there as well)
From the perspective of the card manufacturers, they don't want to chase the mining market and ramp up card production to match it as they view the end of mining demand as a potential risk.
From the perspective of the card buyer, they don't want to buy a 'mining only' card for much the same reason, with one addition. Mining profitability for the individual drops over time, due to rising difficulty. Which means any card you buy has a finite profitable shelf-life. This makes both ASICs and special-purpose mining GPU cards (basically cards with regular GPUs but no video outputs) unattractive -- they aren't worth much on the second-hand market. At least with a gaming card, once you're done mining with it you have a card you can game with that has essentially paid itself off.
I personally think it would be silly and dangerous for graphics card manufacturers to gimp their own hardware in an attempt to appease the gaming market. GPUs are useful for a whole range of things now, which could be impacted negatively by such a move (including things that might be important for gaming performance in the future). To be clear, I say this as an avid gamer myself.
The near future is going to be very interesting, especially if the sentiment that 'cryptocurrencies might go away' disappears. There is always the ever-looming 'Proof-of-Stake' also. If that gets popular, the dynamic will shift again and you might see a flood of cheap graphics cards hitting the second-hand market. That would be nice. I think that PoS is fairly risky though; I keep hearing people saying that Ethereum won't be able to deliver on it.
Cards which have been very much used. Not sure if that's a problem, seen conflicting info for each side on that one.
As a miner, you want to use as little power and generate as little heat as possible. This means in my case that my cards are run underclocked and undervolted.
Two cards in my rig run at 1250MHz core clock and 1085MHz memory clock, at a voltage setting of 0.810V.
I haven't been quite as lucky with the remaining third card in my rig - I can only run that at a core clock of 1220MHz and a memory clock of 950MHz, at a voltage setting of 0.850V.
I have what some might consider rather aggressively low temperature targets for the cards - 54 degrees C. My two good cards can achieve this temperature with fan speeds around 3650 RPM. The fan on the not-so-lucky card needs to spin around 4500-4650 RPM to achieve this. This is on a hot day and these fan speeds are lower if I'm running my air-conditioner. I haven't seen what the rig is like in winter yet. These numbers are likely the worst-case, since it's summer right now.
In my mind, these cards are subjected to much less stress than cards that have been used for gaming, which will run hotter, at higher voltages, with much more thermal cycling, often overclocked. The lifetime of the fans is probably my only concern when it comes to a card that's been used for mining and is what I'd watch out for if buying used. Otherwise, I feel far more confident buying an ex-mining card than an ex-gaming card. Mining done properly seems like it should be far less stressful on a card than gaming, to me.
It would be interesting to see if any kind of concrete data has been collected on this actually - anyone know if any of the big mining farms have published any reliability data (akin to those data centre hard drive reliability reports that get released occasionally)?
Those people are not credible. Most of them are 1-MB-limited-Bitcoin maximalists who are desperate to harm the reputation and adoption of platforms that threaten Bitcoin's place as the top cryptocurrency in the public mind, like Bitcoin Cash and Ethereum.
Isn’t this similar to the “useful work”/“Mining Heater” situation discussed in the article?
In both hashrate vs intial cost and hashrate vs power consumption.
So that they can price-discriminate by raising prices for mining and machine learning.
Its launch MSRP was $110. Today, they are either sold out, or available for $160 or more.
GTX 1060 6GB: launch MSRP was $250. Today it's either of stock or selling for $350.
It's no different for AMD and for higher end GPUs.
Bitcoin is increasing the amount of nonsense and waste we can generate in ten minutes. And under standard economic guff like that expressed in the OP that's considered an increase in productivity.
However, we see here that there are really social utility costs, beyond the environment, to locking up GPU hardware.
I suspect that the capital lockup costs are less damaging for the same dollar amount, because capital is more fungible, so the void can be filled by more sources of capital. In the case of GPUs, however, the void can only be filled after a time-lag in changing production focus.
Errrr, no. That's not how things work. Mining is profitable because it produces bitcoins which are valuable. Whether they are valuable because they are useful to society or because of some other reason is unclear.
- distributed payment systems are valuable to society (true for our discussion)
- POW is the only way to implement them (his overarching conclusion, that may or not be true)
=> Therefore, POW is not wasted, but a legitimate cost of such systems.
> It's not enough to simply say that marginal cost approaches marginal revenue; one must also posit a plausible mechanism by which someone can actually expend that cost. For example, if tomorrow I announce that every day from then on I will give $100 to a randomly selected one of a given list of ten people (using my laptop's /dev/urandom as randomness), then there is simply no way for anyone to send $99 to try to get at that randomness. Either they are not in the list of ten, in which case they have no chance no matter what they do, or they are in the list of ten, in which case they don't have any reasonable way to manipulate my randomness so they're stuck with getting the expected-value $10 per day.
The author here suggests that grinding attacks could be that plausible mechanism, but in a PoS system with a minimum account age, grinding attacks depend on being able to predict the state of the blockchain's entropy after that minimum age has passed. See [2] for some ideas about how entropy can be generated.
Keep in mind that grinding attacks aren't free due transaction fees, so an attacker needs a certain degree of confidence that an entropy state will occur in order for a grinding attack to have a positive expected value; they can't just create a huge number accounts to cover all the possible states. In a well-designed system, the minimum account age and minimum transaction fee will be chosen such that all grinding attacks have negative expected value.
[1] https://github.com/ethereum/wiki/wiki/Proof-of-Stake-FAQ
can't I send one of the 10 people $99 today, and he pays me out in 10 days? Can't that person rent the fact he/she is on the list of 10 out. I am new to economic terms, but it seems your example even better shows his MC_rent + MC_nonrent = MR. Where he says in p2p systems MC_rent should be 0, because it's exclusionary. Again .. your example's main feature is that it excludes all but 10 people.
But if he already received the $100, why would he trade his $100 for your $99?
Are you saying the recipient might want $99 now rather than $100 later? Let's say that the donor doesn't give any advanced notice; the recipient doesn't know they've been selected until they see $100 appear in their bank account.
Mr-give-away-$100 is burning resources (his cash reserves) to create an asset for 10 people (the potential to be given money randomly in the future, which is a strange financial asset). That asset is absolutely saleable on a secondary market and will be priced at some value south of $100.
We can deduce who is on the list by observing who gets the $100 payments and deduce the probability after a few days of observation. The listees have incentive to provide this information as asset + secondary market is better for them than asset + no secondary market.
Upper bound: Nobody is going to pay >$100 for a promise of $100 (I lie, that does happen, but only in rare and extreme circumstances. We'll ignore those).
Lower bound: If the listed individual needs money NOW for some reason, which does happen in practice, then they may be willing to sell at any price >$0.
Mechanism: A contract. They work well for events that happen in the future.
Motive: The listees are giving up a small amount of value to smooth out their income stream.
Results: When the $100 is transferred out of Mr-give-away-$100's account it will immediately be transferred to someone who bought it for some value $100 > X > $0; at a guess probably in the high $90 range.
The person who was gifted a free asset will get rich, but that can be realised before the actual payment is made.
Even if the contracts did add some costs to the system, PoW systems can have similar contracts. I could join a PoW pool and agree to share any $100 rewards I receive with the pool.
Alternatively, we could just avoid the matter of contracts by replacing $100 with $1. $1 is small enough that nobody would need to think about diminishing returns, so there would be little point in spreading out the risk.
See section: IS A “WORK-INDEPENDENT” PROTOCOL POSSIBLE?
> If any cryptosystem is to periodically release coins, without immediately creating an incentive to “waste” an amount equal to the value of those coins, the cryptosystem is going to have to release the coins in a manner which is totally independent of all possible human activities. The coins will have to be rewarded on a completely effort-blind basis. The coin-reward must have a Spearman correlation of zero with everything that mankind could influence.
If you can make it so that there is no way for human influence to affect who gets the coins, then of course marginal revenue will not necessary approach margincal cost. However, it's quite hard to design a system that doesn't have at least some way to influence who receives the rewards. And once you have some way of paying to modify the rewards, then marginal cost start creeping closer to marginal revenue ...
> The coins will have to be rewarded on a completely effort-blind basis
He's right that an effort-blind system is impossible, but that doesn't matter as long as the expected costs of influencing the block reward exceed the expected benefits. And it is is fact possible to design a system where the expected costs will always exceed the expected benefits, so putting effort toward influencing the block reward is unprofitable.
The profitability of a PoS grinding attack depends on the transaction fee, the minimum account age, and the certainty with future blockchain states can be predicted. In a well-designed PoS system, those variables will be chosen such that grinding attacks have negative expected value.
This is the key point, and also why the author's analysis is much too broad: as stated, the argument applies to all social structures in general.
For example, under the author's analysis, PoW itself should not be able to exist, because if $10 of economic value is generated by the blockchain, then at least $10 of energy needs to be burned in order to keep the blockchain secure. This is wrong; it ignores the high real-world cost of dispersed attackers to acquire the (dispersed) surpluses from an attack.
Yet we see that in practice social structures exist and produce net surpluses greater than their maintenance cost (in fact, these two facts are equivalent, since a social structure that did not provide an energetic surplus would not survive in dynamic equilibrium).
The ability to punish rule-breakers as a large multiple of the magnitude of their attempted rule-breaking is what allows social structures (including markets) to gain the necessary leverage; otherwise there can be no surplus derived from creating structure, because to get $1 of social surplus, you need to burn $1 of surplus.
Therefore, the real question is whether dPoS creates structures with higher leverage to punish cheaters than PoW.
Let's say you were forced to invest all your savings in either a PoW or a PoS currency; no other investments are possible. Say they both have the same block reward, which is essentially inflation tax.
Since you'll have to pay inflation tax either way, wouldn't you rather invest in the PoS currency, where the tax is redistributed to stakeholders including yourself? Rather than the PoW currency where the tax goes toward hardware and electricity bills.
That's simply not true. You could potentially loan out your Bitcoin to a company which would play to use that money to create a profitable business. (Of course, it's a bit trickier to do that with Bitcoin due to the deflationary nature, but that's another story.)
When you stake your coins, that's not quite possible.
We can tweak the scenario to say that you're forced to buy and simply hold one of the currencies, without loaning them out or otherwise touching them for 5 years. Then clearly PoS has the advantage.
Even disregarding grinding attacks, the value diverted to coin purchases ultimately has a cost in goods and services. It diverts economic activity to non-economically productive activity in cycling capital into and out of deposits.
I think Proof of Stake could potentially be better than Proof of Work, but the point about cost being equal across validation methods is correct in general in my opinion. There are specific circumstances where it is not true, like if producing the mining resource creates negative externalities.
Where I think the article is wrong is in neglecting other aspects of consensus algorithm efficacy, like the potential security benefits from Proof of Stake totally aligning the incentives of owners of mining capital (which in the case of PoS is the network coins) with the success of the network.
I see what you mean, but that opportunity cost applies to all currencies. Every dollar we hold in currency (be it fiat, PoW or PoS) could have been invested in productive businesses. People tend hold substantial amounts of currency anyway since it's convenient.
If we assume that people are going to hold about $10 trillion in currencies anyway, then it makes sense to ignore that opportunity cost when comparing PoS to PoW.
> Proof of Stake totally aligning the incentives of owners of mining capital (which in the case of PoS is the network coins) with the success of the network.
I agree -- aligning validators' and stakeholders' incentives has some nice benefits. It means we can have validators vote on parameters like minimum transaction fees, and the outcome of the vote should reflect what's best for stakeholders as a whole. In a PoW system that wouldn't work well -- the miners would likely vote for minimum fees that were higher than required for secure validation.
I don't mean that. I mean the actual process of converting liquid wealth into/out-of ether staking deposits, and of sacrificing liquidity to maintain stake deposits. That is not a free activity.
Given the earnings accrued to anyone with staking deposits, there will be competition to increase the share of one's wealth that are held as staking deposits, and that requires increasing frequency of these activities.
The cost of all of these activities will approach the revenue generated by holding ether.
- The economic cost doesn't have to be an energy cost, which means it can be more environmentally friendly than Bitcoin.
- With PoS you have the option of making attacks expensive by penalizing the attacker, which lets you achieve a given level of security at lower economic cost to honest actors.
Sure there is: black bag your house and bug your laptop, or remotely compromise it.
If the original article's argument is basically correct then it means that for any alternative to PoW such as PoS compute-grinding work may be replaced by attempts to game the system or attack the system's security.
I'm also skeptical of the claim that PoW is necessarily more expensive than fiat currency issuance. To account for the cost of fiat you must include the cost of all the security, administration, and governance that is required to enforce the integrity of the system. A dollar costs a lot more than the paper it's printed on (or numbers in a database).
There will always be promises, because that is how humans trade: "Here's a pig, pay me back a pig's worth sometime". There you go - you just created money.
One such example I can find is Luckychain[0] which is where I'd start if I was going to attempt something like this. Intel SGX is the closest thing we have to a legitimate system in which we can place trust in the client. That being said, it requires trusting the signer, Intel. And we have to trust that it can't be cracked even with government-level capability, for the duration of the network's lifetime.
I wonder if you could somehow move the job of signing onto the blockchain itself, so it becomes self-trusting and autonomous.
A minor variation would have that entity retain ownership of most coins - which are released and in its wallet - to spend over time. Let's say, a United Way issued coin 10% of which was spent (auctioned for contributions in dollars) each year for ten years. After which point, the coin would be free of any connection to the United Way.
But there has to be a small charge, in work, to keep your coins valid in order to maintain the blockchain/shared ledger. Weirdly, this has sorta been tried with a real currency, Alberta (Canada)'s "Velocity Dollar." It was ruled illegal before being fully put to the test, but since it could be used to pay taxes to the government, it would likely have worked, at least as a supplementary currency.
"If any cryptosystem is to periodically release coins, without immediately creating an incentive to “waste” an amount equal to the value of those coins, the cryptosystem is going to have to release the coins in a manner which is totally independent of all possible human activities."
And he's absolutely right. When you break it down all cryptos need to waste an amount of resources equal to the value produced by the coins. In bitcoin it's mining equipment and electricity but there's another coin which is setup to use these resources more efficiently than BTC or ETH.
EOS is releasing as a dPoS blockchain which converts the energy the 'miners' (block producers) use in a way that's beneficial for the users (server and network resources). It still expends resources, but does so in a non wasteful manner.
And how exactly does it do that?
In return they're entitled to be paid from network inflation. A rate which is agreed on by vote and divide up amongst the 21.
The users receive a decentralized network, free of any costs to transact (no fees) and infinitely scalable.
The arms race in crypto mining has led to an impossibility of solo-mining. Miners now join a pool or will never see a dime for their efforts. Overtime smaller pools dwindle and merge or die out until only a few survive.
Believe it or not bitcoin has less than 10 pools controlling the network - which is highly concerning due to a possibility of a 51% attack and ethereum is no different.
There's much more to the project and a lot of brilliant people with over a billion dollars in funding making sure this thing is bulletproof. So if you're interested in learning more about it I'd recommend you read their whitepaper as it will be a much better source of information.
However to quickly answer your comment, the 21 are elected by vote and are easily replaced by vote from the users they serve.
This is addressed in the article, under "MAKING THE “WORK” USEFUL (WON’T WORK)"
> Secondly, this only works because the benefits are externalities, they are public and not owned by the miners. So there is no incentive for Miners to switch to such a system or even adopt such a system.
By this logic there is no incentive for Folding@home et al to exist either, but they do.
The incentive to switch to it is that it solves the collective action problem. That itself is another collective action problem, but it's an easier one. The difference to the miner between e.g. folding proteins and hashing is much smaller than the original difference between folding proteins and doing nothing, while still providing the full public benefit of protein folding.
And this is a flaw. There is a law of conservation at work here, whereby to create one source of value, another has to be destroyed. You can't destroy that first source "in a non-wasteful manner". It's not actually destroyed in that case and you've effectively double-spent it and cheated the system in a way that has subtle ramifications on the incentives and security. Even in blockchain, incentives matter and there's no free lunch.
Their incentive is in controlled network inflation, between 1-5% per year and paid to the 21 block producers running the network.
In block chain more than anything incentives matter, just look at bitshares if you want to see how a network can collapse if the incentives aren't calibrated properly.
Raw materials + innovation + labor + capital + time = waste byproducts + new utility added to the world in the form of convenient personal transportation that is sometimes (hopefully all the time) worth more than the sum of its inputs (profit). But all of those inputs get consumed in the process and one thing of value is the result.
Dual purpose mining consumes the inputs but creates two things of value, such that the miner is able to hedge, and to recoup their losses if the cryptocurrency fails. The fundamental problem is that reduces the cost the of attacking the currency, rewriting the ledger from some past point in history, should the miner decide to attempt that. In order for cryptocurrency to be secure, it requires that the miner be fully committed to the currency and that attacks are maximally costly and risky, unhedge-able (at least within the system, they can always short on third party exchanges and whatnot, but there's nothing the protocol can do about that), such that the miner's highest expected value is follow the protocol honestly.
Bitcoin cash would like a word, I expect. Sure, the value of both currencies would drift down until ~the same total value is achieved initially (or some approximation of that), but after a while, we essentially multiplied the value without destroying Bitcoin it was created from.
IMO this is clearer if you use the word "spend" instead of "waste".
> but does so in a non wasteful manner.
s/non/less/
But otherwise I agree.
Not to mention that you have to pay the delegates more than their actual costs as you have to pay them a premium to prevent them from cheating.
Also, the voting under dPoS is fraught will all sorts of worries (imagine sockpuppets and all sorts of fake news).
There is already an update that article: http://www.truthcoin.info/blog/pos-still-pointless/ which partially takes into account the critisism. And here is my reply to it: https://medium.com/@zby/proof-of-stake-can-be-cheaper-than-p...
It has a general point, in that the ultimate direction of cryptocurrency systems is towards energy efficient systems of value and transaction, but this goal tends to lead towards a spectrum of trusted/delegated behavior where proof is not a hard requirement. Much of the argument rests on trust costing as much as work, and I don't buy that. It defies what technologies do: let you leverage effort in a particular direction and get a resulting overall productivity benefit.