Why Proof of Stake?
vitalik.ca
vitalik.ca
Are there other whitepapers in the distributed ledger space that are similar, from a readability perspective? Any insight would be appreciated.
Thanks in advance!
Bitcoin is a store of value, Ethereum is an universal computer with a Turing-complete language.
I personally use Bitcoin because it has a smaller attack surface, and it’s excellent for my needs. The bug in the multisig contract in one of the Ethereum implementations a few years ago was where I decided never to trust Ethereum as a store of value, as multisig is very important for me. Another important difference is that with Bitcoin I can verify the whole blockchain on my computer, with Ethereum it’s much harder. Also the hard forks in Ethereum means that it’s not yet ready to be a store of value.
Also for Bitcoin I myself was able to read and verify and understand the whole smart contract code base (a few hundreds of lines altogether in 1 file), which increased my confidence.
Bitcoin, on the other hand, builds these core crypto competencies into the base layer, so that scripting can exist purely in the application domain.
My opinion in the parent post to yours is based on my decade of experience with bitcoin, and having been there every step of the way in its evolution and the birth and erratic journey of Ethereum.
In short summary, Bitcoin seeks to provide a secure, stable, no-BS minimal base layer upon which financial contracts of all sorts can be written. The Lightning Network is an example of a smart contract on Bitcoin, one that has been quite stable and secure compared with frothy DAO, ICO, DeFi, or whatever the latest marketing term for smart contracts is in the Ethereum space.
Bitcoin adds small, targeted features to the base protocol after a truly intense amount of work goes in to proving their correctness and the way in which they interact with other parts of the base layer. Ethereum chases after whatever the fad of the moment is and crams everything into a gigantic toolbox of everything and the kitchen sink, and makes you use all that complexity for even things as simple as multi-sig and replay protection.
To stretch an analogy, Bitcoin is a minimal RISC architecture while Ethereum is x86, with all the history of legacy features and obsolete stuff included. Now your task as a cryptocurrency application engineer is to build a secure protocol that must survive without mercy from attackers. Would you rather do this on x86 or a minimal, proven-correct RISC platform?
The choice to me is obvious. Going into the details of why is way more than could possibly fit in a HN comment, however.
OK, so what's driving the buyers of bitcoin to be more comfortable with ever higher prices and is that feeling not permeating over to ethereum?
Ethereum aspires to have fun.
There is a narrow gap where Bitcoin or Gold could potentially be useful if some kind of breakdown happens. But if it's global, you can forget that anybody will be interested in them.
Bitcoin as well as Gold are pretty useless in the zombie apocalypse.
It’s portable and you can trade it without infrastructure. Unlike Bitcoin.
It’s value during a collapse is based on the idea that there will be a future recovery of some kind, but we don’t have to recover very far before gold is good, whereas we need to get back to the level of silicon fabs before Bitcoin can be useful again.
If it’s really an ‘apocalypse’ that we can’t recover from, then you only need one bullet.
Even if Ethereum is at present better technology (I think it is), it's also trying to become even more (scaling and PoS and more). That progress has been slow, and has many competitors with great technology. Labeling Ether as "digital oil" gives one useful mental image, but that's certainly not as sexy as "digital gold".
I attribute the continued market cap dominance of Bitcoin over Ether almost entirely to Bitcoin being (at least for now) a better meme.
That Ethereum seems superior is just an effect of marketing and language around their scene. It helps they have people who can quickly say seemingly smart things (think GPT-3) that no sane person can parse in a short amount of time to arrive at knowledge. The system is overly complicated for a single individual to understand and trust easily. It may well be very difficult or impossible to tell if a given contract is secure or not.
In reality, there are very few mainstream "killer" use cases being served by Ethereum, although they do entertain themselves by trying to "break" each other's contracts. The most famous case was when the authors of Ethereum rolled back the chain to get their own coins back from a clever "hacker".
The fact is, that individual followed the rules and still lost the coin they were due them by contract! That's not happened with Bitcoin, at least on mainchain.
Unlike Proof of Work, Proof of Stake is not a coin distribution method. PoS-only block chains just create all initial coins out of thin air, like a 100% ICO, which is the worst possible concentration of wealth.
That actually might be the best way, as you're proving that you believe the coin is worth something in the beginning by burning work, giving your initial stake consequences.
Advocates of it have responded to fact of PoS's tautological security by applying seemingly unending amounts of complexity, essentially obfuscating their design until people give up reviewing it. Cryptographic security against review is not cryptographic security, it is the opposite of it.
At best these schemes have security that reduces to the underlying consensus mechanism that they're running on top of (which usually ends up being some not-at-all-decenteralized system like the Ripple UNL, where all participants must accept a consistent set of authorities or it will eventually fail to converge), but they can do worse than that-- and often do, as a result of vulnerabilities that come out of the obfuscation.
Vitalik Buterin isn't a stranger to making deceptive claims: Before he created this technobabble laden massively pre-mined altcoin, and dumped it on an unsophisticated public while misleading them about its properties, he was primarily known to me as some kid that got banned from the Bitcoin chat channels by driving people nuts trying to solicit people to invest in his sham "Quantum Miner" project.
If by chance these systems act in a secure manner in practice -- e.g. they successfully operate as a centralized consensus and the central authorities remain benign -- their economics lock in massive ongoing revenue streams for their prior participants. Especially in the context of a system which pre-mined some 72 million coins most of which are illiquid held by a small number of parties-- as selling them would completely collapse the market-- the result is a tremendous rent-seeking windfall.
In fact, when Vitalik made the decision to edit the ethereum ledger to claw-back funds taken from himself and others as the result of the technically-correct (but surprising) execution of "DAO" smart contract, part of the justification given was that if the funds were not taken back the system couldn't make its impending transition to POS (now delayed for years) because POS would benefit the "hacker". So it isn't surprising to see continued efforts towards that model from the persons who most stand to gain from it, even after years of delays and failure. Nor is it surprising that this article extols greater ease at editing the ledger ("recover from attacks") through processes external to the rules of the system as a purported _benefit_ of the proposed insecure mechanism. It's not that unusual to see a security weaknesses spun as advantages, but it is unusually audacious and self-serving in this case.
There are plenty of systems in the world which are perfectly happy with a distributed-but-centralized security model as they can have robust and clear security properties within the scope of their limitations. People should be happy to use them where they fit their needs. I don't think the world benefits from having more systems with security models obfuscated by pretending to be strongly decentralized when they are not, no matter how many benefits can be derived from not being decentralized.
In my opinion, it seems like the criticism in the paper is valid, but the conclusion is too dire. Proof of Stake is a different and weaker model of consensus than Proof of Work, but one that seems practical enough for the real world. To address the two main criticisms in the paper, the FAQ seems to state that there are decent schemes to inject enough randomness to prevent stake grinding, and that Proof of Stake does have a "weak subjectivity" as a con, but that in the real world coordination on which block is real to get started on out of band isn't too onerous. Asking a trusted friend or just looking at major forums or whatever would work to get started, and then after that you don't need to keep trusting a third party. Trust on first use, kinda, which a lot of us use every day, SSHing into things, but this case is even better because your first trust can be to a friend or trusted party.
This seems like a very reasonable concession in order to not burn wild amounts of electricity and make the system much more sustainable.
The 'weak subjectivity' issue doesn't just arise at the first use, it becomes a very important consideration in the event of a network fork (ie, a bad actor attacks the chain, and users attempt to defeat the attack by following a different chain that ignores the attacker). This is a much larger issue, it is easy to find consensus on a 'genesis block', but finding consensus in the moment of an uncertain/contentious chain-split is very different. At best it falls back to trusting some centralized party to make the correct choice, and then having a large enough portion of the users follow them.
https://hugonguyen.medium.com/work-is-timeless-stake-is-not-...
Signed, the new wannabe financial oligarchy.
At least when I rent a server on the cloud I can pick my own markup for a solution I build, with Dapps the market will compete away all profits in the same way most profit goes to landlords. They know this, but think that I don't know this, as if I am some idiot lacking self interest.