> and if you try to validate and not censor, you will get your staked coins taken from you by the protocol (as opposed to PoW, where you just fail to get your block in the chain)
Is outright false. It is the same as PoW. You choose what transactions you include in your block. So some people may choose to not include some transactions (Ethermine is already doing this on PoW with Tornado Cash). But there is no mechanism that slashes your staked coins because the other validators didn't like what transactions you included. At most your block will not get attested. Slashing can only happen for other reasons (proposing twice, attesting twice, attesting something that surrounds something else).
PoS is in fact even more resistant because in PoS you can kick out the malicious validators by doing a social fork that slashes their stake. In PoW if 51% of miners are malicious there's nothing you can do, you can't slash their hardware.
So, your transaction will be confirmed in the next block mined by one of the other 49% of miners. Big whoop.
At any point there is still a 49% chance the next block will be mined by a good guy.
If the bad guys decide not to accept the good guys' blocks, then they are hard forking Bitcoin and will end up just like Bitcoin Cash: irrelevant.
This is the exact problem PoW was designed to solve, and it works very well, which is why a 51% attack has never succeeded or even been attempted against Bitcoin, and never will.
The 51% attack is not some made up thing.
The only way they can maintain that chain is by a hard fork.
So after a time, they are behind and have to jump to the other chain and ignore their own old blocks. Something like this graph:
Censored blocks: -
Uncensored Fork blocks: \
Uncensored Normal blocks: *
Censored: *--------------------------
Uncensored: \** \* \*** \** \*It doesn't matter if it's a 90% attack. The minority miners are constantly receiving and using the majority's blocks. So it is not 66% vs. 33%, or 90% vs. 10%; it is 60% vs. 100% and 90% vs. 100%.
All it takes is for the less-restrictive minority to mine two blocks in a row and they've permanently outpaced the majority's more restrictive chain.
They can use the majority blocks at the cost of discarding their earlier blocks. Every time they accept a block from the majority, they undo all the work they had done earlier.
> All it takes is for the less-restrictive minority to mine two blocks in a row and they've permanently outpaced the majority's more restrictive chain.
All it takes then is for the majority to mine three blocks in a row. The probability is always on their side.
If that's what it comes down to (and there is reason to believe it won't), I imagine sanction addresses will still transact, just with higher latency and at higher cost than others.
Assuming enough hash rate and the exchanges (and the users) agree to ignore the "sactioned" transactions, then they will never be in the main chain, not even slowly.
Also just noting that while the conversation here is about Ethereum, you are describing the fork rules of Bitcoin. Next month the concept "hash rate" won't exist on ETH mainnet (potentially depending on who you ask; looks like there might be an ETC2).
1) The hash of the old block.
2) The new transactions.
3) A number that must be bruteforced until you get a hash of all the block with a lot of zeros.
If you try to copy one block in the other chain/fork, then the hash of the previos block is invalid. If you change just that part of the block, you must bruteforce a new number until you get a new hash of all the block with a lot of zeros, that has the same cost of creating a new block from scratch.
You can copy the info of the transactions from one chain to the other, but you must create a new block to put them. You can't just copy the block.
Okay, I think I see now where I was separately wrong and partially wrong in the previous comments. When I said there's a huge monetary upside to a 51% attack, that's wrong. There's not really any upside to speak of, especially considering the huge amount of computing resources you would need to do it.
So it's not surprising it hasn't been tried yet, and that's not a proof that it's a canard as I said before (but it's not a proof of the opposite, either). Absence of evidence does not imply evidence of absence. So I'll concede and leave that point alone. I was wrong.
---
Now, when I said that the 49% can still use the 51%'s blocks, that's not entirely correct. It's correct only until the blockchain splits, then it's not correct. So my position wasn't entirely correct, but it still has value to this discussion. Let me illustrate with a randomly-generated timeline.
Let's make it easy and say 66% are censoring miners, and 33% are non-censoring miners.
We haven't discussed this yet, but let's also assume that the exchanges and non-mining users reflect this proportion. This is an unfounded assumption. But I'm steelmanning.
The 33% are in miner pool 1, and the 66% are in miner pool 2 and 3. The dots represent 5-minute intervals. Just like in Bitcoin, a block is mined roughly once every 20 minutes. Observe the moment at "X".
..3..........2...X1.3......1...1..........2......2..
At this point, the blockchain looks like this. 100% 3--2
You might ask, "Why is it not forked at this point? Miner pools 3 and 2 are the malicious actors, and they had two blocks in a row." Because 1 has no reason to fork. All previous blocks are valid according to Miner pool 1.Now, observe the point at X:
..3..........2....1X3......1...1.......X..2......2..
At this point, the blockchain has forked. It looks like this. 66% 3--2
33% 3--2--1
Notice, 33% has the longer chain, but the 66% do not accept the 33%'s block because it contains censored transactions, so a re-org does not occur. This situation will continue as long as the 33% chain is equal to or longer than the 66%, which could be a while.But how can that be possible if the 66% has more hashpower?
Observe the point at X:
..3..........2....1.3X.....1...1..........2......2..
Chains: 66% 3--2--3
33% 3--2--1
They are equal. No re-org happens.One should question at this point what's going on in the mempool here? One can assume the 66% censoring miners are not transmitting the censored transactions to the mempool. But how many censored transactions are we talking about? How much of a fee is each side collecting? Is this still in the coinbase reward era or after? Are the 33% smart enough to route around the 66%? Or punish them by kicking them off the mempool? Not sure. All of these variables can mitigate this attack. But I will not explore that now.
Although there are now two rival chains, for simplicity's sake, lets just assume the same timeline holds, and remove each of the two side's blocks from the other's chain starting from at the time of the fork.
66% ..3..........2....1.3.....................2......2..
33% ..3..........2....1........1...1....................
Now, observe the point at X: 66% ..3..........2....1.3.....................2......2.X
33% ..3..........2....1........1...1...................X
Chains: 66% 3--2--3--2--2
33% 3--2--1--1--1
3 hours later, the 66% still have not overtaken the 33%.One should wonder even more, what is going on in the mempool and ~$250B Bitcoin economy during this time?
In this example, only two blocks by the 33% are mined consecutively. What about 3 or 4? Could it be days before the 66% overtakes the 33%? I think it's possible.
On the other hand, the mining of consecutive blocks by the 66% does not create a contention between the two sides. So all miners are unified until the 33% gain an advantage. This is my point.
From the POV of the censored Bitcoin transactions, the 66% will succeed in censoring them until the issue is resolved. But I don't think you can say that the 66% have control of the network at this point. They've only succeeded in disrupting the network until more non-censoring miners come online, or something else happens.
Consider also that the attacker has to either possess 66% of all computing power devoted to Bitcoin in the known universe OR an incentive more attractive than the BTC block incentive for the operators of 66% of miners. Even for 51%, that's an impressive achievement.
It's a very interesting scenario but I still say it does not constitute a credible threat to Bitcoin. More of a thought experiment.
66% ..3..........2....1.3.....................2......2.X
33% ..3..........2....1........1...1...................X
but that's closer to a 50%-50% split of the miners, not a 66%-33%.The problem is that 2 and 3 will produce the double of blocks. For e while 1 may tie or get ahead, but after 30 blocks the the 23 fork will almost always be like 10 blocks ahead of the only 1 fork.
Ignoring most of the . to make the graph shorter
66% 3213...223.3223..23.23.323..3.2223
33% 321.11....1....11..1..1...11.1....
or looking at each chain 66% 32132233223232332332223
33% 3211111111111
After a while, 1 canA) Give up and start mining censored blocks
B) Start a new fork, from the current 2-3 chain with many censored blocks
C) Declare that they are a fork and convince the exchanges to give them a new moniker, like ETC of BXC
D) Convince the exchanges that they are the real chain in spite they are shorter, and convince the exchanges to give the other chain a new moniker.
Let's say that MiningPoolA controls 51% of hashpower, and MiningPoolB controls 49%. MiningPoolA is refusing to mine transactions from/to some wallet W.
Time T1:
MiningPoolA: OldChain -- Block1(no W)
MiningPoolB: OldChain -- Block1'(W receives 1BTC) still in progress
Any client will accept the chain with Block1 (no transactions from/to W)
Time T2 - if MiningPoolB tries to compete
MiningPoolA: OldChain -- Block1(no W) -- Block2 (no W)
MiningPoolB: OldChain -- Block1'(W receives 1BTC) -- Block2' (parent=Block1') still in progress
Any client will accept the chain with Block1 (no transactions from/to W), and MiningPoolB will never be able to catch up
Time T2 - if MiningPoolB decides to accept MiningPoolA's chain, but add the transaction in the second block:
MiningPoolA: OldChain -- Block1(no W) -- Block2 (no W)
MiningPoolB: OldChain -- Block1(no W) -- Block2' (parent=Block1, adds transaction W receives 1BTC) still in progress
Any client will accept the chain with Block1 (no transactions from/to W), and MiningPoolB will never be able to catch up
If a mining pool had 51+% of hashpower, they would always be mining the longest chain, no one would be able to compete with them and publish another block (in principle, at least; in practice, since mining is not entirely deterministic, someone else will occasionally win the lottery and propose a new block faster).The 51% chain is mined with 51% of the total mining power, while the 49% chain will contain 100% of the mining power (as the 49% miners are more than happy to build off the 51% chain, while the 51% miners will only building off the chain without the censored transactions).
They are correct in asserting that a 51% attack to censor transaction is largely just a nuisance to the users and that all transactions should eventually end up on the longest chain (the 49%).
Each miner takes a bunch of transactions and chooses a previous block B1 to build on, then starts hashing. If some other minerB advertises a new block B2 based on B1 that includes different transactions before minerA, then minerA can throw away all the work it did, and start from scratch on B3 based on B2. But minerB will probably already be working on its own B3 - and has every chance to win again.
I will not go into depth here but it's a commonly held view that this changes under PoS. Just flying by so hopefully sources are easily located
The only way 51% of miners can fork the blockchain and actually overtake the other 49% with more restrictive rules is if they have a hidden nuclear reactor dedicated to mining Bitcoin that produces hashpower equal or more than 49% of the network and they flip it on at the moment they fork.
Again, it doesn't matter how many people are convinced a 51% attack is possible on Bitcoin. It's never even been tried once. So the burden of proof is on you all. I'm just trying to help explain why this concept has never been proven.
If the 51% can ignore the blocks from the 49%, then why does it matter what the 49% is doing?
Occasionally the 49% will be able to mine a block and temporarily create the longest chain, but the 51% can always just ignore that block and continue mining off of the one before it - eventually their chain will be the longest and the block(s) from the 49% will be lost.
Really this isn't theoretical, it happens all the time by accident when two blocks get mined off of the same previous block. When that happens one of the two blocks gets lost, and the only difference with this scenario is that the 51% have enough hash power to ensure that their blocks are the ones that always (eventually) win and the 49% blocks are always lost.
The other 49% are still incorporating the 51%'s blocks in their work. There is no way 51% of miners can stay ahead of the combined hashpower of the entire Bitcoin mining population.
It's not that simple. That block from the 49% will be ignored by the 51% (since it contains "banned" transactions), which will continue the chain on the previous block (the "51% chain". Now the 49% has two options. If they continue to build the chain on top of that 49% block (the "49% chain"), after a while the 51% chain will be longer (because that side has the most hash power). The other option is to build again on top of the 51% chain, as you suggested (and AFAIK that's what unmodified Bitcoin software will do after a while); but to do that, they have to discard that block they had included earlier (since it's not in the 51% chain).
That is: yes, the 49% can include "banned" transactions, but that inclusion will be undone later. They can include these transactions again, but that inclusion will be undone again. They can never get far enough for these blocks with the "banned" transactions to be permanent.
> Again, a 51% attack has never even been attempted on the Bitcoin network despite huge potential monetary upside if it succeeds.
First, this is not the "traditional" 51% attack, which involves mining an alternative longer chain in secret. Second, the most a 51% attack can do is double spend coins (or prevent them from being spent); converting that into real money requires spending the coin twice (for instance, sending coins to an exchange, withdrawing the resulting money, and then undoing the sending to the exchange so the attacker keeps the coins), and the monetary upside isn't that big in most scenarios. Third, the cost for doing that is not as small as you're thinking (start with the cost to obtain enough miners to have 51% of the hash power), which is why it hasn't AFAIK been attempted on Bitcoin (but AFAIK, it has been attempted on less popular networks which have small total hash power). And if you fail the attack, you have wasted all that cost.
As soon as the chain diverges, they are seperate chains.
Yes, if you have a minority of the hashpower, you can hardfork yourself off the main chain, and continue to follow your smaller chain, regardless.
But you don't get a longer chain than the main one. So you'd continuously be behind, and would not get the work of the main chain, and likely most exchanges would not accept your smaller fork coin, and you would end up like bitcoin cash.
They can also prevent you from getting your transaction in ever. The 49% cannot prevent this because they cannot make a longer chain, that is the entire point of proof-of-work.
What you do is this:
- spend btc with a transaction and get it included in the chain.
- start mining blocks starting from before your transaction in secret
- include a trnasaction to a different address in the secret chain
- broadcast the secret chain once it's longer than the "official" one
- since your chain is longer, your chain is now the official one. All the transactions in the other chain are now discarded
Here an attacker controlling 51% of mining power decides to not play by the rules; we are considering what that means for everybody else. For Bitcoin it means they can block transactions forever, and they can double-spend.
Obviously if the attacker plays by the rules there is no attack.
The Bitcoin blockchain constantly "forks" for the latest 1-2 blocks. If you sell your car for BTC and hand over the car the moment you see the latest block contains the transaction where the BTC enters your wallet, you may see 1h later that the longest chain does NOT contain your transaction, and in fact your transaction is now invalid, because the buyer wallet has sent all the money somewhere else.
This only proves that ether is already too centralized.
FWIW. I used to mine eth on a small scale so I am obviously biased.
Basically, concentration of power means that eth will quickly become everything the banks are.. only worse ( because with banks you at least have some regulation to back you up ):P
Like 4 pools control 51% of the hashrate so they already can easily bully solo-miners.
>So some people may choose to not include some transactions (Ethermine is already doing this on PoW with Tornado Cash). But there is no mechanism that slashes your staked coins because the other validators didn't like what transactions you included.
>PoS is in fact even more resistant because in PoS you can kick out the malicious validators by doing a social fork that slashes their stake.
If a group of validators don't agree with your particular arrangement of transactions in the block, they can engineer a "social fork" that slashes your stake.
But you can reach a social consensus (i.e. outside the protocol) and decide to slash the censors. At that point there would be effectively two different chains, the censored one and an uncensored one. The worth of each chain would be decided by market dynamics.
It's absolutely terrible. Wasn't the goal to create digital money no one can control? I might as well use the US dollar then.
Why would I want to be on their fork? They can have their censored fork, but they can't do anything to anymore who doesn't want to be a part of it.
Stick a fork in it. Ethereum is done.
With that degree of centralization, might as well just run a database and call it a day.
Are you talking about lack of ideological purity of Ethermine?
Yes, and the fact that everyone in the Ethereum community has largely glossed this over in their enthusiasm for the "merge" and what it will do the price of their assets.
Cryptocurrencies that embrace the centralization and censorship of fiat currencies are completely unnecessary and have no real utility. Tornado Cash and Ethermine should have been a line in the sand, a hard boundary for what's acceptable and what's not.
But the fact that no one even cares tells me that the community will be happy to accept even more censorship as long as their bags keep going up. Pathetic, really.
As for TC - who is rolling over? While some US based businesses are complying, protocol builders are saying that they will fight tooth and nail.
There will always be a miner (or validator in PoS) that will be willing to take Tornado Cash fees.
There is only one Bitcoin, and it's basically the chain the most clients are following. If you decide to follow another chain, you have created a new "coin", but Bitcoin is unaffected.
IMO - this behavior is a blip. As soon as it becomes clear that “censorship” isn’t effective, it will become less popular for validators to do it at all.
Is that how you evaluate technologies? By their marketcap?
> but now it is just managed by the big holders
To have any influence during the proof of work days you needed a server farm. This was also restricted to a small elite who could, if they wished, censor transactions.
With PoS, the big players control the small players. If the minority doesn't play along, their funds will be slashed by the procotol. If 66% of validators censor you, your transaction will never be finalized.
With PoW, the big players cannot coerce the small players in any way. Everyone independently controls their own blocks. If 66% of miners censor you, your transaction will merely take 3x as long to be confirmed.
If <50% of miners want to censor you, they can make it take longer for your transactions to be processed. If it's >50% (or thereabouts) they can prevent your transactions from every getting confirmed. Sure, the 34% could collude until they happen to produce 6 blocks in a row, but each individual member of that group would make more money by going along with the censorship and not being censored themselves.
I believe it's similar with PoS, but with somewhat different incentive magnitudes.
If 66% of miners censor their own blocks to comply with OFAC, then eventually the transaction will get in.
If 66% of miners not only censor their own blocks, but also collude to continually reorg the chain, then obviously all bets are off, the project has failed, and the exchange rate is headed to 0.
I think the former is infinitely more likely than the latter.
Is it though? If crypto ever becomes a common currency people will still want to transact in it regardless of corruption/collusion among miners. Most are not going to stop using it for ideological reasons like "miners are altering the chain" unless it negatively impacts their own transactions.
I believe the point is that there’s no prerequisite that all miners are independent, and will definitely collude. PoW or PoS this is the case, as blockchains cannot prevent IRL agreements.
This is false. If miners controlling 66% of hash power decide to censor you, they can ignore any blocks produced by the minority who include your transaction.
Legitimate question because I don't know.
When I'm mining eth on my GPU while part of a mining pool, my understanding is that my GPU is racing to try and find the hash that works to start the next block. If I find it, I then am able to put transactions into the block and cap it off, but the reward doesn't go to me because I was part of a pool, so the pool shares the reward with everyone involved.
Are you saying I only find the answer to the block but the pool itself stuffs the block with transactions?
Though it's entirely possible that mining pools dictate which transactions get sent to their miners for them to try mining.
With the old system, miners could try to sabotage our fork if most hashing power were to be on the censored fork. With this update, that would not be possible as the censors would lose their money on the non-censored fork and therefore be unable to stake. The relative power of the forks no longer matter as they cannot attack each other anymore.
Ethereum is becoming more decentralized and permissionless as a result of this change.
$4k vs $128k
Literally the same numbers.
Stake pooling also eliminates one of the supposed benefits of decentralised cryptocurrency - you have to trust someone else with your currency.
If I have to give my currency to a third party who will then invest it for me, then why bother with decentralised cryptos at all?
>any operation on the network requires trust that the network will do what it agreed it will do.
If I were an Eth apologist, I would explain how the code that defines the network operations is fully open and inspectable, so no trust needed.
[1]: https://eth2book.info/altair/part2/incentives/inactivity
In that case, without any stakes, half of nodes will be locked to NIL, half - to a valid block.
In case of stakes, byzantine proposer (it is only one node that is really byzantine, but it can control how network is split) can partition network according to a proportion of stakes, so that neither half gets prevalence.
The algorithm in the link you provided does nothing in that case. The only node that will be punished is a byzantine validator which does not care.
The system will be in no-progress-possible state indefinitely.
Inactivity leak is an emergency measure to restore liveness when the network stops finalizing blocks. It happens when >33% of validators are offline(WW3 scenario), major bug in widespread implementation, etc.
Your link explains that.
ETH2 is friendly to home stackers - you may lose some profit by being offline sometimes, and in the worst case minor penalties are applied.
EDIT: If you are interested in a much better description of what happens if you are offline, see this:
https://eth2book.info/altair/part2/incentives/penalties
Some points from the link:
- penalties =/= slashing
- If you are online > 42.5% of the sime - you are earning profits
In PoS you still have the staking tokens.
To me it sounds like staking has a much more powerful snowball effect than mining and the gap between the wealthiest ETH participants and everyone else will increase faster under PoS.
Every holder who is staking is rewarded for staking, in proportion to their stake.
> To me it sounds like staking has a much more powerful snowball effect than mining
No, because issuance under proof of stake is much lower than that under proof of work.
The point of validating is to secure the chain, not to get rich. The more validators that are active, the lower the per-validator rewards, reducing compounding effects.
Also you lock-up capital which has an opportunity cost and must competes with every other investable asset. As the barriers to entry staking are negligible (just acquiring a liquid staking derivative like rETH, for example) it means that everyone willing to stake will likely do so which drops the returns lower, which may push some stakers out as they see better investing opportunities. So staking is likely going to have thin margins in the future and will give a rate of return that is fairly priced given its risk adjusted returns.
Last I saw, ETH mining was about 33% profitable. With mining rewards ten times higher than staking rewards, that means miners take home about three times more on their investment than stakers.