As blockchain tech goes, Ethereum always seemed the most interesting.
As blockchain tech goes, Ethereum always seemed the most interesting.
Last but not least, full eth2 turns eth into a positive yield asset, a share in ethereum (real income depends on fees paid by users - ethereum already dominates).
To not overhype, the current launch is really an incentivized testnet only for PoS itself - real ethereum still runs on PoW as it was. It's important because it shows that after long delays eth2 is finally starting to happen, and because consensus itself is like a car that can drive without transporting anything or anyone - not very useful at the moment, but changes required to make it useful are relatively small compared to building the car from the ground up.
Uh, why do you say that?
The security of PoS in fact ought to be much LOWER than the security of PoW:
The goal of requiring proof of work is that you cannot just send multiple versions of the same transaction into different areas of the network to double-spend your money - because you need to commit work for producing a block, and due to consuming energy you can't fake that.
Well, you can compute two (or more) blocks in parallel, but then you'll spend half of your available CPU (or ASIC nowadays) cycles on each block, thus cutting your speed in half. So the non-malicious competitors on the network will produce more blocks meanwhile because they're not splitting their computation power, and thus your fake blocks will get invalidated because they're on the shorter chain.
With PoS on the other hand you can create as many fake blocks as you want and spam them to the network. The only security is the hope that the random network topology arbitrarily results in the double-spending blocks arriving at the targets under attack after the other blocks arrive.
But if you run thousands of nodes on the cloud and thus have better network connectivity than the victims you can make your double-spend blocks arrive first at the victims.
So:
- PoW: Relies on physical limits, you need to have physical hardware and physical energy to conduct an attack.
- PoS: Relies on the network connectivity of the attacker being hopefully worse than the connectivity of the non-malicious network. Who can guarantee that? Nobody.
Also, I'm not sure why you and the other commenter are so argumentative about this. There are several PoS networks out there such as Cosmos, Tezos, etc, holding more than a billion dollars. If there was an issue, someone would have hacked them by now.
Is that a link to an article from a peer reviewed academic journal?
> There are several PoS networks out there such as Cosmos, Tezos, etc, holding more than a billion dollars. If there was an issue, someone would have hacked them by now.
I'll give you a hint: "slashing" is not a thing that sustains security of these networks.
Last but not least, there's no way to delete PoW attacker's gpus, but hostile stake is always going to be slashed. Asic pow chain can be forked - once - to a gpu pow, but that's it, and after that there's no recourse to sustained attacks. This property virtually guarantees that no attack against PoS with slashing is ever going to happen.
What defends against the attacker configuring his nodes to just not relay the blocks which slash his deposits, by having a majority in the network connectivity, and thereby convincing victim nodes that he in fact is the victim of false slashing because the victims will only discover the slash-claims much after the attackers "valid" blocks?
Or in other words:
Isn't the slashing mechanism also reliant upon mere hope that the network topology randomly happens to be in favor of non-malicious peers?
There are probably many botnets of IoT devices with 10x that many nodes, aren't there?
So a single botnet could probably ensure that a target victim has the majority of peer connections to the attacker.
If I understand it correctly, you are now saying that someone would DDOS the entire gossip network, completely halting any more production of blocks so that their slashing doesn't go through?
We're not even talking about "nothing at stake", or anything having to do with PoS anymore. We're just talking about a massive DDOS of an entire network. Node operators in PoS networks, as well as Bitcoin, have ways of dealing with DDOS which are the same as how anyone deals with it, and I don't need to get into them here.
If someone was able to overcome these DDOS mitigations and completely prevent a PoS network from receiving any legitimate transactions, they could do this to Bitcoin as well.
Who will record this "evidence" to the blockchain? Anyway there will be two versions of the blockchain. In one of them attacker's stake was not slashed and there is no any "evidence" of his malicious actions.
Not sure what these two versions of the blockchain you're talking about are. Signing two blocks at the same height with the same chain id is the slashable offense. It doesn't matter what's in them.
If the attacker wants to have his own blockchain off in the corner where he has all the money, nobody cares.
Really?! One version is "Vitalik's fork" and another one is "non-Vitalik's fork". Which one of them is a valid chain? Any idea?
Assume the attacker is Vitalik and there an "evidence" of his attack. Who will dare to slash him? Vitalik won't include this evidence into "Vitalik's fork". If Vitalik wants to have his own blockchain, nobody cares, isn't it?
when a PoW block is mined, there's no way to know how much hidden equipment is out there mining a parallel chain, which could suddenly appear and take over with more accumulated work. You hope the malicious actor doesn't have 51%, but there's no way to actually prove that they aren't out there.
with PoS on the other hand, the set of validators who are voting on a block is known many blocks in advance. so say a malicious validator has X% of the voting power on a given block: he can't refuse to relay the other votes, because it will be obvious to all other nodes that he only speaks for X%, and what he's broadcasting lacks quorum, because the other (100-X)% votes are missing.
Whereas the other (100-X)% group will be actively broadcasting that they're slashing his stake; and if (100-X) has quorum, those votes will be accepted as valid by all the nodes on the network, regardless of what the malicious actor decides to broadcast.
TLDR: under PoW, silence is assumed to be absence of dissent, since number of miners out there is unknown. Whereas under PoS, silence still allows proving lack of quorum (since the voters are known well in advance), so censorship doesn't let a malicious validator legitimize their vote.
>and thereby convincing victim nodes that he in fact is the victim of false slashing because the victims will only discover the slash-claims much after the attackers "valid" blocks?
It's not possible for 'false slashing' to occur, because slashing requires presenting conflicting votes.
>Isn't the slashing mechanism also reliant upon mere hope that the network topology randomly happens to be in favor of non-malicious peers?
topology doesn't matter in this case, 2/3+ consensus is asynchronous. 2/3 of stake is required to finalize blocks, so the attacker would finalize his own chain without slashing.
There are some ideas about 99+% proof consensus which rely on topology and nodes being online (which means they can observe that censorship is happening) but it's not currently implemented. Eventually I expect it to happen, making attacks a practical impossibility, by coupling asynchronous 2/3+ consensus guarantee with synchronous 99+% guarantee, effectively automatically coordinating anti-censorship forks.
https://vitalik.ca/general/2018/08/07/99_fault_tolerant.html
https://twitter.com/technocrypto/status/1330150362427387910
In proof of stake, mining equipment and electricity consumption is replaced by the cryptocurrency itself. You put up your currency as a bond, get rewarded more for running the network, and lose your bond if you misbehave.
The other big advance for ETH2 will be sharding, so each node doesn't have to process every transaction. But that's not the part that launched today.
A new virtual machine for smart contracts (EWASM instead of EVM) giving better contract analysis options, and possibly higher sync speeds due to optimisations.
Also, sharding - so multiple jndependent blockchains, that should fix the scalability.
If I’m not mistaken, this release is not yet a full blown new chain, but just a partially functional one, designed to test stabiloty and safety.
Disclaimer - I’m a bit out of loop, so I meay be slightly wrong somewhere.
The roadmap has changed for the phases after this launch so that Eth1 contracts and the Eth1 chain can run on Eth2 so that the past years of Eth1 development are not thrown away.
Reading on the roadmap: https://ethereum-magicians.org/t/a-rollup-centric-ethereum-r...
Disclaimer, this roadmap is valid as of today Dec 1st 2020 but it might have change a couple of months from now.
I wouldn't mind staying with EVM, since EWASM doesn't seem to offer much significant improvement (static jumps only, really).
- scaling issues (it can't be used as a currency if this isn't fixed) - power issues (would be nice if we didn't create a huge pointless energy sink if we could avoid it) - the amount of footguns in ethereum (I think the language is too permissive)
It looks like this solves at least 2 of the three!
The other part, which is on Ethereum mainnet already, is a layer-2 idea called rollups, which store transactions on chain in a very compressed format without losing security guarantees. There are several rollup systems, capable on today's Ethereum of doing 1000 to 9000 simple tx/sec.
Once both systems are live, total capacity will be 20K to 100K tx/sec, not counting the quadratic improvements.
On the research side, there's also work to make data validation more efficient by replacing merkle trees with something more compact, like polynomial commitments. That would add another 10X factor to rollup scaling.
Regarding footguns, people are working on more rigorous languages than Solidity that still compile to the EVM. So far their compilers aren't as solid so they don't get much production use yet.
Anything more than ~3000 tx/sec will be a game changer and maybe ethereum will finally deliver on the promise of usability as currency.