What should be addressed though is the problem of negative externalities not being priced in. This is not specific to energy usage of PoW or any other use of energy. Those producing emissions should categorically be required to foot the bill for repairing any damage done and those taxes should be put to use to that end. Once priced in, many things that otherwise commonize costs but privatize profits may prove to be not worth pursuing.
If the societal good done by certain things is worth the negative externalities, those can be explicitly and transparently funded through subsidies which offset some portion of the costs.
1) reducing the ability to profit off of actions that cause environmental damage thereby aligning the market interest to reduce such actions
2) funding the investment in reversing the damage
whereas your suggestion above is doing literally nothing to help…
https://en.wikipedia.org/wiki/Intergovernmental_Panel_on_Cli...
I really think that the possibility of obtaining the wrong conclusions are much higher than getting it right, yet the consequences of putting a ton of restrictions is really harmful for many people, especially in developing countries.
What it predicts for developing countries is disaster, which we already see. More droughts in the summer combined with floods in spring/autumn.
This leads to food insecurity and ecosystem disruption, which will be more harmful than not doing anything.
Weather is hard to predict short-term, but the long-term trends (i.e. climate) are visible.
But the dice experiment is: one leaves variables out of the model bc of its overwhelming complexity for what we know so far.
No, I do not buy this, vote me negative but I do not. If it was true, the weather forecast should be guessable.
Maybe you could compare it to dice. It's very hard to predict on what number a dice is going to land. But if you throw it a lot of times, you'll eventually start to see the distribution converge somewhere. And when you then take a drill and make a hole in the side of the dice, or glue something to its side or whatever, and then throw it a lot of times again, you'll see that the distribution changes. Also, you can make reasonable statements about those developments. "If I make it heavier on the side opposite six, I think I'll start seeing more sixes, because the side opposite is pulled down more by gravity". You don't need to be able to predict the short-term outputs of a system to see changes in its long-term trends, and you can absolutely reason about and possibly predict those long-term changes.
I think it is a really difficult thing to guess. And anyways, even if it is not, how can you stop it if China, India and US say no to it bc there is no current technology to replace?
We could be in the situation where a lot of restrictions are set and later the guess is wrong. More expensive energy means putting a ton of people back into poverty, literally.
Given the depth and breath of the costs, banning the use of fossil fuels in PoW schemes doesn’t seem particularly unreasonable. Especially given the broader social goal of reducing fossil fuel use wherever possible.
There are plenty of things I think people over-value. I may think that buying cars or living in places where you would need them is overvalued, but I won’t argue for banning those. People can form their own opinions on how much they value different things. They shouldn’t however profit from not cleaning up their own messes and having others foot the bill.
So there are certainly uses for PoW, but I agree they are few and far between.
The issue here is that at the very bottom you end up with really nasty vicious poverty circles... and now that I think of it, we don't know in advance what kind of combination of minimum low power and low time fraction of guaranteed supply is the best, and how you combine market discovery for that with regulation...
Of course, I know that many of you... as lomg as it is not your own business everything is ok.
It would [let us assume for the sake of argument] be better for society if proof of work systems did not exist. But if we ban it it will just happen anyway.
It would be better for society if murder did not exist but even though we banned it, murder just happens anyway.
Banning this type of activity has historically proven difficult, it's basically the lesson we keep re-learning with the prohibition, the war on drugs and so forth.
Why?
Debt is also something foreign intelligence looks for when attempting to recruit spies.
Crypto speculation. Like all speculation is ultimately gambling, which people can get addicted to.
Your terms are acceptable.
But miners just pay their energy bills like any other citizen. Who are you to tell them what activity should they perform with the energy they purchase?
With the current technology it is just impossible.
Sounds like this is a good reason for them to pay lower rates per kwh.
That's a sacrifice for the whole world and not only for the people it benefits though.
And I wish nobody made that sacrifice. I don't quite care about the blockchain being strongly immutable. However, I strongly care about global warming.
> It is not a waste
Well, it is a waste for anybody who does not need this blockchain. And I'm not sure it's that useful even for its current users.
"Don't feed the blockchain!"
However, I indeed don't want Christmas light on my home for somewhat related reasons.gratuitously
But I suspect Christmas lights are not even close to reaching the levels of energy consumed by blockchain mining worldwide. Even Christmas lights are more useful than PoW blockchains.
As human beings we are going to consume energy and produce CO2 for pleasure (we are not talking about strict necessity here). Because in the end, I believe enjoying life is almost an (the?) end-goal of life, if any. But we don't need to burn some so gratuitously neither.
For the record though, bitcoin mining uses more than Christmas lights, but far less than clothes dryers, and far less than gold mining (and gold mining is pretty horrible for human rights and land destruction as well).
Completely agree.
> far less than clothes dryers, and far less than gold mining (and gold mining is pretty horrible for human rights and land destruction as well).
Agree too.
> I would rather just tax the externalities and let people decide how to spend inside of that.
Mhm, I don't believe in the effectiveness of this and I think we need something stronger than this, but that's a belief. One problem with taxing externalities is that richer people get to waste more with fewer consequences than poorer people a.k.a they have a right to pollute more / more power to pollute and I don't think we should be able to buy "pollution power". Currently, the amount of money one have is actually already roughly equivalent to one's power to pollute. Limiting the amount of CO2 each people can spend (without the ability to transfer, because that's equivalent to being able to buy pollution power", equally, might be fairer, and that would probably eliminate PoW mining because people will probably want to "spend" their limited amount of pollution in other ways.
Of course, I'd even prefer that people reach the conclusion that PoW mining is heresy and decide by themselves not to do that. That's an opinion, of course.
But...
> Your argument seems to be that energy use that doesn't benefit you is wrong
Not at all. It's not about me. It's about everybody on Earth. A few people are being, in my view, harmful to everybody, including themselves, for no clear benefits to themselves, and for no gain for society.
While, like (increasingly) many people, I'm trying hard to not heat my home too much in winter, avoiding planes, avoiding producing waste too much, some people gratuitously burn energy because why not.
Don't make me look like I'm self-centered or something.
This is where your argument keeps falling down for me. This may be your view, but I and many others find great benefit in Bitcoin. I dry my clothes on a clothesline, but don't feel that electric clothes dryers should be made illegal (not sure if you are arguing for this as OP does).
If you are interested in reading about the ways in which Bitcoin benefits different people around the world I recommend the writing of Alex Gladstein of the Human Rights Foundation.
Bitcoin is not one of them.
Proof of work is only a way to randomly and incontestably select a participant when participation is open and no one is trustable, i.e., a consensus mechanism (which, once augmented with other conventions (I'm thinking of choosing the longest chain), will also prevent double spending).
But what makes the blockchain immutable is the Merkle tree structure (each block containing the hash of its parent) and the distribution of the data (which is what guarantees that participants have a comparison point to detect modification). It would work the same without proof of work. A Git repository has the same exact property.
If anything, proof of work makes mutability easier since it is only required to compute partial collisions to have blocks considered valid.
Merkle tree makes verifying the blockchain datastructure easier, and enables older blocks to be further secured by newer blocks.
Proof for work however makes producing an entirely alternive blockchain expensive. When looking at the bitcoin blockchain, you can prove exactly how much energy was used to make it, and know that energy was not used for making any other variant. This means you can be confident the blockchain is not a altered forgery meant to defraud you, as this attack would require spending all of that energy again.
So yes, PoW can give you confidence, but it is unnecessary in practice. Well, let's say it's an additional security measure where something else more trivial is already enough.
When you get a copy of the blockchain, verifying if all the Merkle tree structure (without even checking for the PoW) and comparing the last hash (or the few last hashes) with what you see on the network from other sources is enough to be sure that your copy is valid. Because providing you with a fake chain which still has the same last hash would require to have at some point (for the block the attacker –i.e., the source of your copy of the blockchain– wants to modify) found a full collision, which is much more difficult than computing alternative valid PoW.
So yeah, here PoW can give you confidence in the copy of the blockchain you get without having to even minimally interact (just looking at a blockchain explorer not controlled by your source for example) with others. But the whole point of the tech is to interact otherwise you don't need to bootstrap a client. So this refinement makes little to no sense.
You keep referring to other consensus mechanisms that are not really trustable without the PoW foundation (looking at other copies on the network, blockchain explorer). The beauty of PoW is that it speaks for itself-- you could download the data over an untrusted network with just one peer, and still be confident you got the real thing, because you can prove energy was sacrificed for its construction.
PoW has other benefits beyond this quite silly scenario, I am just explaining it again as you don't seem to get it.
I'm not talking about other consensus mechanisms. We were first discussing what makes a blockchains immutable, I already explained why PoW is not necessary for that. Then you reframed the discussion to how can you trust that a copy of the blockchain you were just given by someone you don't trust is valid, and you are right that PoW is a solution to this specific problem. My point, again, is that it is an unnecessarily costly solution for this specific problem, because the properties that makes a blockchain immutable (Merkle structure + distribution) are already enough to ensure that in practice, because a fake blockchain copy, even without PoW, will have a different last hash from the real one, and it will be easy to see that by simply comparing it with others sources (if you trust no one, which is one of the requirements for blockchains to be useful, you just need to do that with multiple sources to gain enough confidence, typically ones that are very public and would be easily denounced if they lied). And anyway by participating in the blockchain protocol it will be obvious very soon that your copy doesn't match with everyone else's.
The only way this strategy won't work is if the last hash of the Merkle structure is valid while the blockchain copy is not, and the only way for this to happen is if a full collision has been found on the modified block. Which is way more costly than building a PoW valid hash.
Let me take an example with another technology that has the same immutability properties as blockchains do but don't use PoW: Git.
If you want to get a copy of the git repository of a project and you clone it from my version of the repository, either it is the real repository and everything is fine, or it is not —for example I could have introduced a backdoor somewhere in my version of the project— and then there is two possibilities:
1- Using the copy you downloaded from me you won't be able to participate (push or pull) in the project with anyone else than me because the commit log of the copy you got is incompatible with everyone else's version of the repository. You'll quickly understand that something's wrong with mine, and it will even be easy to see at which point the commit history diverges from the other copies of the repository that you attempt to collaborate with.
2- I've added my backdoor in a past existing commit, and found a collision in its hash to make it have the exact same hash as the original version of the commit (the one without my backdoor), and I have rebuild the exact same commit history from there. But here it requires me to have computed a full collision, which is actually impossible (at least much more so than computing a valid PoW hashes for a few commits after adding my backdoor), as long as there is no vulnerabilities discovered in the hashing algorithm.
Now, if you never interact with anyone else than me, I don't have to find a collision because my commits hashes won't be compared to any others, and then you are right to say that you won't be able to know about the backdoor and that using PoW would make this scenario less plausible (not impossible, but way less plausible) in terms of cost for me. But, even more in the case of bootstrapping a blockchain client, it is the very idea of only interacting with the person you got a copy of the blockchain from that makes no sense.
Your analysis of git makes complete sense to me. I understand how git uses hashes and merkle trees to prevent tampering of data. It is also a good analogy in that bitcoin uses similar properties. I am furthermore perfectly happy to trust a single authoritative source (or trusted peer) when initializing a git repo, it works better that way. But git is not solving the same problem as bitcoin.
You concede that PoW is a solution to this problem, but that it is "unnecessarily costly". But you haven't given a solution to the problem that costs less, only argued that in practice the problem has assumptions that are in practice not necessary. You seem to believe that bitcoin without PoW could still in practice arrive at a consensus through either being able to check that a last block hash is the same as the "real hash", or that you would be able to compare your value to multiple sources. These ideas both rely on another consensus system outside of what is promised by bitcoin itself-- either a trusted third party to enshrine what hash is "real", or being able to rely on a consensus merely based on some number of network peers. Number of peers will not work by itself, because there is almost no cost for an attacker to create many dishonest peers. Note that the purpose of an attack of this kind is not merely to defraud users of bitcoin, but could also be a denial of service attack. Seeing peers with different blockchain history would make the network unusable.
I also don't understand the hangup over PoW and immutability. Immutability is the concept of data that is not changed. If you have a more precise definition, please give it. This could be split into the idea of a design principle, versus the idea of enforcement of immutability. E.g. using an immutable data structure in a trusted programming environment does not need enforcement. We are only talking about the enforcement aspect. A hash digest is a really strong, almost perfect enforcement-- finding a collision is in practice impossible. A digest hash only guarantees that "if trust the hash, I should trust data that matches the hash also". On the otherhand, PoW does act as a soft form of immutability, using economic barriers rather than cryptographic guarantees. PoW guarantees that "this data could not have been produced, and could not be further changed without expending some amount of physical power, and therefore there are unlikely to be variations of this". This effect is orthogonal to the internal immutability provided by hash digest / merkle trees.
Aiming for solutions to problems that do not exist is a thing among blockchain aficionados, but I'm not one. Yet, remark that I also addressed the concern that if you do not interact with anyone else than the source of your blockchain copy, PoW makes it largely unlikely, but not impossible, that they would have tempered with the copy they provided you. So even in this scenario you partly rely on broader interactions.
> I also don't understand the hangup over PoW and immutability.
This whole discussion was started by my answer to your claim that “It [PoW] is not a waste, but a sacrifice made to make the blockchain strongly immutable.”.
I don't think it is worth discussing this further.
For example, if we used a public-writable git repo to track our cryptocurrency transactions, it would have the Merkle structure required for append-only/immutable-history. However, we could get lots of diverging branches; e.g.
+--- Commit sending all my money to Alice
|
Parent commit --+
|
+--- Commit sending all my money to Bob
Who gets my money? The consensus mechanism used by Bitcoin will choose the branch with the longest history. In the above case they're equal, so we wait until some more commits appear. If more commits appear on the Alice branch, then that's chosen as the "correct" one. However, Bob can later spam a bunch of commits on top of the other branch (e.g. just sending one coin back-and-forth), until that branch becomes the longest. The consensus will then change, to consider that branch as the "correct" one, and Alice loses all the money (as does anyone she previously sent it to!).Proof-of-work makes this spamming much harder. All miners will be trying to add blocks to the longest branch they're aware of (picking arbitrarily, in case there are multiple), since it's unlikely any shorter chain will be able to overtake it (this is a largely self-fulfilling prediction!).
Preventing double spending is a feature of the consensus mechanism indeed, if it is augmented with other rules (longest chain wins), but immutability does not rely on it, as I said in the comment you are replying to.
EDIT: I've updated my previous comment to make it clearer that what I'm saying is "PoW is not an immutability mechanism" (to which answering "you are wrong, PoW prevents double spending" makes little sense).
No, forbidden forbiding, please, for things like these.
[0] https://energyeducation.ca/encyclopedia/Miles_per_gallon_gas....
[1] https://fortune.com/2021/10/26/bitcoin-electricity-consumpti...
Anyways, I think the real fear here is from govts. and their loss of control through fiat currency and transaction systems, honestly.
But that is an entirely different topic...
Also, I don't really see how this is really relevant, it really sounds like a "But Sometimes" issue, where some edge case of something sucks, but that doesn't say much about if that something in total is bad or not.
In a lottery the ticket fees go to the organizer, who wastes a little in administrative fees, takes a percentage for themselves, and returns the rest as prizes. Bad for income distribution, but not especially wasteful.
In a PoW blockchain the "ticket fee" — the electricity and depreciating hardware — is completely used up. The reward doesn't come from the other miners, but from transaction fees and new coins (diluting the value).
It's like a lottery that uses all the income from tickets to pay for marketing, and the actual prizes are paid by government subsidy.
(Or, in other words: It's my lighter, and I'm paying for the gasoline, so why is it any business of yours what I'm setting on fire with it?)
There's more to mining than hashing [1]. My Cuckoo Cycle Proof-of-Work scheme for example searches random graphs for fixed length cycles.
It would be more correct to say all the Hashcash Proof-of-Work does is calculating hashes.
[1] https://cryptorials.io/beyond-hashcash-proof-work-theres-min...
However useful uses (typically finding new primes and similar mathematical searches) seem to be fundamentally incompatible with using a blockchain as a distributed ledger in a zero trust environment, because that usefulness automatically weakens the cryptographic safety ?
also works if your browser is picky about expired certs.
It's a probabilistic distributed rate limiter to speed up information convergence in a gossip system. I agree it's a wasteful way of deciding what your VCS' HEAD is.
The market still considers a bitcoin to be worth 10x more than ethereum.