“Proof-of-work” proves not to work for spam prevention (2004) [pdf]
cl.cam.ac.uk
cl.cam.ac.uk
> Richard Clayton and I claim that PoW doesn't work:
> http://www.cl.cam.ac.uk/~rnc1/proofwork.pdf
It's in the context of a discussion about why PoW-based tokes are a bad idea in terms of burning CPUs and their carbon footprint. The generous interpretation is that he was claiming that this discussion was moot because the bigger issue was that PoW wouldn't actually work as a feature of Bitcoin.
The less generous (but probably accurate) interpretation is that he posted that without reading either the Bitcoin whitepaper itself or the abstract of the whitepaper. IIUC his paper is about how PoW applied to email would either break a lot of the desirable features or the difficulty would be too low to prevent spam.
I'm not sure why this bothers me enough to post about it on HN-- I'd actually prefer it to be true and Bitcoin fanbase never to have existed. Nevertheless, his paper wasn't really relevant to that discussion and I'm not sure why he posted it there.
1: https://www.mail-archive.com/cryptography@metzdowd.com/msg10...
Edit: clarification
why, only because of carbon footprint?
I'm not so sure about that. I've seen plenty of people at the grocery store spending USD in exchange for food who don't appear greedy. I haven't actually ran a survey, though. But I'm mostly confident that USA doesn't run on greed.
Amazingly, quite literally the biggest immediate bounty on the internet.
https://www.theguardian.com/technology/2004/jan/25/billgates...
Question: has any email system attempted proof of work? Did it run into the problems this paper predicted?
You might want to have a look at hashcash[0]
I can see exactly why this wouldn't work - nowadays wouldn't spammers have enough processing power to just do this for every spam email? And how does this not slow down email processing for the end-user, sending an email now requires me to brute-force a hash, right?
I don't think anything else can solve decentralized rate limiting more effectively than proof of work.
I wrote a short blog post about the use of Proof of work beyond crypto mining [0]
When you use "but" it's customary for the following statement to disprove or argue against the previous statement. How does it being applicable to more stuff stop it from being a gigantic waste of energy?
"Applicable" means that it is useful, as it solves the problems I talk about in the post.
No, it's very much not besides the point - and I'd argue it's one of the core issues with PoW and the reason why people are so appalled by it.
Yes, everything expends energy, but the special property of PoW is that the energy cost is intentional. Therefore it's fundamentally impossible to reduce the energy cost as that would defeat the whole point: If someone manages to find a more efficient way to mine, this is a threat to the network and has to be counteracted by raising the difficulty. Conversely, the amount of energy that can be expended for mining a single block is potentially unbounded, in contrast to other problems ehere the energy actually perform useful work.
This leaves belief whether or not the problem is worth pursuing as the only measure about the energy cost of PoW. And this belief is influenced by all kinds of factors from technical to financial to psychological. But it is generally not influenced by the amount of energy already spent.
Energy consumption is not fundamental in any way. Proof of work depends only in the consumption of some resource that has economic value. It doesn't have to require any energy at all.
For example, Chia had a proof of work mechanism that uses disk storage instead of computation. It uses comparably very little energy and the difficulty is not substantially sensitive to energy efficiency because the cost is dominated by space rather than computation.
There are other examples that attempt to use things like spatially distributed network bandwidth as a resource. I'm not a fan of most of these, but the point is that energy is not fundamental.
And how do you think those disks get made? (And how do you run those disks without expending energy?)
For example, suppose Bitcoin consumed as much energy as a few households. Would that be acceptable?
Alternatives aren't quite that efficient, but my point is that the relative energy consumption matters a lot.
But in this scenario, Bitcoin would consume rising amounts of some other resource, say SSDs or network capacity.
That's not possible. The marginal cost of mining has to equal the value of the coins mined.
Nope.
However if you value freedom/decentralization, it isn't. (I know about the debatable parts of decentralization and Bitcoin but you probably got the main idea)
Then your passion for freedom has to grow in lockstep with the Bitcoin market cap, because this is what tracks the actual cost per unit of work with Bitcoin.
Also note who has to bear the cost: PoW resource waste is something that affects everyone, even if only a small group perceives it as valuable.
Yes, or in other words: PoW has to waste something valuable. This something doesn't have to be energy, it can also be physical devices + the energy needed to produce/operate them - or whatever else someone can think up.
My actual point was that the amount of cost per unit of work is unbounded - and to my knowledge this is true for all PoW schemes: Otherwise, an attacker could simply invest enough resources to produce more work units than everyone else and capture the network.
Networks with bigger ratios truly are more efficient, even in absurd hypotheticals in which all economic activity is devoted to operating the network. All I'm assuming here is that actors don't put in more than they get out of it.
I agree with this point - but over the last few years, we have seen how wildly the perceived value of cryptocurrencies can fluctuate. There are a lot of actors who are strongly interested in driving up the value - either through legitimate means, but just as often through fraud, e.g. manipulated exchanges, wash trading, etc.
So the market cap can easily reach fantasy numbers which aren't really justified by economic utility - but because this fantasy valuation represents real money for miners, energy consumption will follow it.
Controlling or even having Crypto currencies may be valuable beyond/outside their market cap to some (eg cybercriminals, intelligence agencies).
Isn't the opposite true though? That everything is either directly or indirectly tied to energy?
Cost of disk space vs computing power is just an equation of the energy put into it (mining, manufacturing, marketing, shipping).
Maybe I'm too hungover to think this through. :D
> It uses comparably very little energy and the difficulty is not substantially sensitive to energy efficiency because the cost is dominated by space rather than computation.
I don't see how this would equate in the end. If you want to keep the level of difficulty high enough it would have to go hand in hand with real life resources (= energy).
Granted there are complex externalities in the calculation and computing continuously uses energy while disk space is more of an "expend and forget" type of scenario, but to me that would simply result in malicious actors being able to afford to put more resources into it (buying more disk space) until we're at the level of the same energy expenditure.
There is no free lunch.
To be more specific, the dominant cost is the opportunity cost of disk space. Producing and using a drive can't be accounted for as "e-waste", otherwise you'd be forced to claim that drive efficiency doesn't matter because more efficient drives produce just as much e-waste.
I wasn’t trying to be funny.
chia nodes regularly wears out crappy consumer-grade SSDs, and it’s cheaper to just burn through them than buy more resilient drives.
The real cost is from buying the drives, which is not e-waste. You'd have to convince me that there are enough unrecoverable nonrenewables in disk drives for this to be a significant "environmental" cost, and I think it clearly is not.
I don't care about what will be true, I care about what is true now. If electricity were completely environmentally friendly then the conversation would be moot, as PoW would itself be fine.
But that's not the state we're in. Most electricity is not sustainable.
To me the relevant question is, are HDDs _currently_ produced with fewer environmentally harmful externalities than electricity? I strongly believe the answer is yes. Energy is a small part of the inputs to produce an HDD. You'd have to convince me that on average, the non-energy inputs to HDDs have a larger proportion of environmentally negative externalities than energy itself, or that the energy used for HDDs is somehow less green on average than the energy used for PoW.
I believe mining today in the US is 70-75% sustainable, which is pretty good, if true. (I haven't done a deep dive on this to confirm, seems a bit high).
Personally, I find the notions of reducing energy usage in general quite terrifying.
As we go up the Kardashev scale, our energy needs will keep rising exponentially, and for human civilization to pass the Great Filter we have no other choice but move and move quickly, but of course not too quickly to commit suicide.
Not sure what's the best way to achieve it, but it is very hard to believe we can become a multiplanetary spacefaring civilization on a combination of hydro dams, windmills and solar panels.
My hope is that Bitcoin can stimulate development of clean nuclear, or if we get lucky, maybe even aneutronic fusion.
Is taking more energy than Argentina really worthwhile for the few that uses cryptos?
Nuclear and fossil fuels are similar, but the timescales involved there are far too long for humans. Ie burning coal does have negative side effects because we aren't creating new coal from the carbon in the atmosphere at comparable rates.
If the problem is the pollution produced by power generation, then it's disingenuous to single out crypto for criticism. We really should be enforcing accountability and forcing markets to price in the negative externalities. Carbon capture and other technologies are surfacing to allow for that, and within a decade or so we should see widespread implementation. Legislation will arise out of the consensus of voters and mate technology and regulation.
If the problem is that you think crypto is frivolous or implicitly a waste of resources?
"Well, that's just, like, your opinion, man..."
And Proof of Waste is about more than it's impact on the environment through it's egregious energy use. Even in places that use clean energy, Bitcoin mining is putting a strain on the grid. (I suspect mining had something to do with Texas' grid problems last winter.) Even if you're harnessing off grid energy, you're a leech sucking value out of the economy by being a major contributor to the chip/GPU shortage.
And for what? All to contribute to a system that has greater wealth inequality than the existing financial system. Brilliant stuff.
Would bitcoin mining be better if it would use clean energy? I think you really are mixing two things here: energy production (that can be “good” or “bad” from ethical or evological perspective) and energy consumption that cannot be bad, just inefficient in terms of the return in business value (but it’s for the owners or customers to calculate, not bystanders to judge).
Imo mixing two is a massive fallacy.
Edit: typos.
No, Bitcoin mining should not exist. It serves no demonstrable net-positive value to society.
> I think you really are mixing two things here
I'm not, you seem to be confused. Energy production is produced only because it is economically viable to do so. Bitcoin makes it economically viable to produce most forms of energy, regardless of that specific source's environmental impact. This is harmful consumption of energy. Like leaving the lights on when you're not home, simply because you don't care. Bitcoin is not indifferent, its core function is to increase energy usage. Some people would have you believe Bitcoin's core value is its use as a currency. Its value is as infrastructure that wastes energy for profit, and the collective buy-in and infrastructure created to ensure it remains a store of value.
You could maybe argue this is worth it, if there were absolutely no other way to do it. But there is, and it works much better. Central banking is strictly superior to cryptocurrency for most reasons that the average person cares about. If you don't agree, that's irrelevant, because you're an outlier. Most people want cheap transactional costs, fast transactions, and for their money to have stable value. They couldn't care for a second if the transaction is cryptographically secure as long as it's reasonably insured.
Tell that to sun
And what’s bad about leaving the lights on? Is energy a scarce resource or what? Since when is it bad to use it? This is such a strange take you have. We are not talking about water in the desert. We are talking about energy and increased consumption just stimulates more production and decreases cost.
It’s like saying “don’t type stupid comments on your laptop, it’s a waste of your laptop resources”. They are not finite. We can produce more. In so many different ways. Some of which are bad and some are good.
Doesn’t make typing stupid comments bad in no way.
I'm not sure if you're being intentionally daft or what, but obviously we're talking about energy used by humans.
On Earth, the means to capture or produce any energy is a result of economic interest. If you want to capture energy from the sun at scale, there's a cost attached to it.
> And what’s bad about leaving the lights on? Is energy a scarce resource or what?
Yes, captured energy is literally a scare resource. Texas had rolling blackouts last winter. Many places in the developing world have constant rolling blackouts. That's why we charge money for it, that's why we invest money to drill for it, that's why we've invested decades of research and development into improving our ability to capture energy.
The electric company where I live, which is hydro-electricity based has run commercials for as long as I can remember to conserve energy because of its positive impact on the environment. Where the hell do you live that you think energy is infinite and free? The sun?
It needs to always be expensive or the system is vulnerable to a sudden burst of new and malicious workers.
I'd be curious to hear more about decentralized rate limiting. That sounds like a reasonable problem to solve with PoW. Although it also sounds like a problem I can solve pretty easily today without PoW so idk.
https://eprint.iacr.org/2021/1379
It gets about 50% efficiency compared to the current state of the art for the problem space without compromising any of the security properties that make for a good PoW algorithm. Generally I'm not a fan of PoW and prefer internal resource based consensus algorithms but PoUW algorithms seem rather interesting. I think we are reaching a point of maturity in the space that'll allow these types of self-securing service marketplaces (which really is what PoUW is) to reach their logical conclusion.
I.e. the basic purpose of PoW is security: Allow desirable actors in, keep malicious actors out. But this implies that "ability to put in more work" is actually a working way to distinguish good actors from bad actors. This is true in very specific cases, like blockchains - but I believe in most cases, this is actually not given, such as emails.
E.g., suppose we're using PoW to secure email: We do away with SPIF and all that and simply require each email to contain some hash that a sender had to bruteforce (just an example: use whatever PoW scheme you want).
If the scheme has a fixed difficulty, spammers can easily defeat it - they just have to rent (or capture) more machines. So you have to dynamically adjust the difficulty to meet some message/time unit quota. Congrats, suddenly the whole network is limitited to some maximum throughput. Alternatively, you can have separate difficulties for each user - but then, you need a way to track individual users, compute individual difficulties, etc. All of this needs some centralized entity again and agents that enforce the rules. If you have all that, why not use traditional rate limit and forgo the energy (or resource) waste?
But there aren't many things it solves well. The easiest and most economical solution to "decentralizing rate limiting" is usually centralizing something.
https://eprint.iacr.org/2021/1379
It provides a Proof-of-Useful-Work algorithm that is resistant to pre-computation and most other weaknesses that would otherwise prevent useful work from being done while achieving Nakamoto Consensus while at the same time managing to convert ~50% of the computation spent into useful work. Additionally the work being done is pretty generally useful and is applicable to a lot of different problems.
I think the space is starting to reach a point of academic maturity and formalisation of the tech stack such that we can start meaningfully trying to solve these types of problems.
Have you heard of Rate Limiting Nullifiers?
https://github.com/vacp2p/research/blob/master/rln-research/...
I am more than happy to use a cryptocurrency where I can take 1 USD and receive a coin that is worth ~1 USD, without needing the promise that it will be a moonshot "investment," merely a vehicle for value.
When is that coin coming our way?
1. Proof of space and/or time: https://en.wikipedia.org/wiki/Proof_of_space#:~:text=A%20pro....
2. Proof of authority: https://en.wikipedia.org/wiki/Proof_of_authority
Not sure either makes a huge difference
I'd argue though that Proof of Authority definitely is the most useful outside of Proof of Stake and the slowly maturing Proof of Useful Work consensus systems. It's simplistic but it perfectly covers the needs of a lot of government systems.
I ask this question because a lot of things that are run on blockchains seem like they're losing more than they're gaining. It makes me suspicious of even DAI.
When I say "fully open database", you might object that this compromises a person's privacy in order to make the database mirror-able. But then again, all blockchains are fully open and public, so there's nothing more to be lost there.
* - By which I mean the Ethereum blockchain, which is inefficient like all blockchains currently are.
Nope, See my reply, stable refers to pegged to something and thus stable in value to that something.
The absence of massive short-term volatility is not a property of stablecoins its a property of pegging to something without massive short-term volatility.
Stablecoins exist in the Fiat world too. For example the Bahamian dollar is pegged to the US dollar on a one-to-one basis. So its a Fiat USD stablecoin. It doesn't have a long term stable value (buying power) just like the USD does not.
That part of your question about stablecoins doesn’t have much to do with a Proof of Stake though-a consensus model.
I wrote how they compete on collateral choices which lets people predict their growth/issuance trajectory. MIM grows faster than DAI for a variety of reasons that DAI didn’t have when it launched, which is not likely that DAI can replicate now or at least not quickly.
My guess is around the time central banks start issuing it.
USDC stable-coin [0]($34 Billion in circulation) is arguably the most trustworthy in terms of having a 1 to 1 exchangeable backing through a regulated centralized custodian (Circle/Coinbase primarily but also BlockFi and other entities that hold USD reserves for exchange).
Many of these entities (as well as "DeFi" decentralized finance platforms that use Ethereum or similar smart contracts to decentralize the process) allow for various forms of deposit and lending accounts that provide a whole range of yields way way above traditional banking deposits. On top of this, some of these custodians add an additional layer of payment ability to these deposit accounts. Crypto.com[1] for example has a Visa debit card that ties into your USDC/stable coin deposits that you can transact from, in theory avoiding needing to use fiat at all. As well as "CD-like" 3-month lockups where you can get 8-12% yield.
There are also many decentralized stable coins that have various forms of over-collateralized crypto-asset reserves backing the coin and algorithms to stabilize the value by buying or selling from these reserves, trading off possible volatility and uncertainty around peg to avoid centralization and KYC and other regulations of 1:1 backed coins.[2]
[0] https://www.circle.com/en/usdc
[1] https://crypto.com/us/earn
[2] $MIM dollar stable-coin: https://cointelegraph.com/news/magic-internet-money-races-pa...
Today. It is called USDC; but on the Stellar Blockchain. [0]
You will always know that 1 USDC will always be worth 1 USD and you won't have to deal with ridiculously slow transactions or incredibly high gas fees for every operation and it is not using PoW. [0]