Distributed File Sharing or computation without the whole tokenomics that, while interesting, creates too much attention from scammers.
Distributed File Sharing or computation without the whole tokenomics that, while interesting, creates too much attention from scammers.
"Massively redundantly replicated"
A distributed consensus mechanism would segment the decisions amongst nodes, not poll for a unanimous response.
Blockchain as such has nothing to do with the costs of a node and incentives to run one
Blockchains are built under the assumption that everyone is selfish and untrustworthy. Which is a decent assumption when building a crypto currency, but that doesn't mean that every system has to run like that.
Typically on a tracker you’re given a currency (although not as sound as some e-coins) and can use that to influence your upload or download statistics, which in turn affect your ratio. Some trackers might employ rules where your user class has to have a certain ratio, or else you’ll lose privileges like certain forums or even the ability to download at all. (The trackers are private and can control which peers you can see)
I see some similarity here to the world of private torrent trackers. You want a Linux ISO, I want a Linux ISO, we're all working towards the same goal. So we're already incentivized to cooperate, without getting money involved. And trackers also have things like minimum seeding ratios to keep people honest. In the case of AI, you and I both want to generate images, so we're also working towards the same goal, so let's help each other out so both of our workloads finish faster. Maybe idealistic, but I think it could work.
Is this also how IPFS works?
In zk proofs-of-computation-result, different nodes can perform different intensive parts of a calculation and send the results along with proofs that those are the correct results. Other nodes can accept the results and verify the proofs with remarkable efficiency, then use those partial results for further calculations. To me it still feels counterintuitive and almost magical that any large, arbitrary computation result can be easily verified without repeating the computation, without the verifier needing much memory or data.
For cryptocurrency blockchains this allows smart-contract (computational) transactions to be accepted with only one node having to execute the code, everyone else just efficiently verifies the proof to accept the state change. As proofs can be aggregated, this scales well: it isn't necessary for every node to run all the verifications, either.
For big, distributed calculations like the article's, the whole calculation can progress using those partial results without having to rely on trust and reputation, and everyone can have high confidence that the final result is what it should be, not undermined by subterfuge or subtly inaccurate contributions.
This is an offshoot of zero-knowledge proofs, as ironically zero-knowledge is not required for these types of applications. Just the efficient verifiability part.
(Fwiw, I am working on large, scalable zk-proofs-of-computation in my spare time, in optimised software and with hardware accelaration, if anyone is interested in discussing this stuff.)
Why counterintuitive? That’s kind of all of cryptography and most of computer science. Take factoring into primes (which has been done for forever): it’s really time consuming and expensive to determine what the prime factors for a number are, particularly if it’s a big number and you know it only has two. That’s because division is very very difficult and time consuming. Multiplication on the other hand is super cheap so once you tell me the prime factors, I can confirm much more quickly whether or not they’re factors.
In computer science, one of the earliest identified computation classes is NP complete which has this property. Eg traveling salesman and knapsack packing problem are examples. It can be insanely difficult to find a path that exists between two cities in a graph under some cost. But if you give me a solution I can easily confirm whether it meets the criteria (global optimality testing is itself NP complete but if you give me a set of solutions you can verify which one is the cheapest).
I’m not claiming that factorization is NP btw. There are complexity classes beyond NP that share this property. https://cstheory.stackexchange.com/questions/159/is-integer-...
Anyway. ZK proofs themselves are super surprising and not intuitive but not because verification is fast but because verification reveals nothing to the verifier about the solution. That’s the mind blowing result.
What I find remarkable is that zk-proof-of-computation works for any kind of computation. On the face of it, it might seem that some computations would resist being compressible that way, but no, it works with anything that can be run on any real computer.
It doesn't depend on what kind of computation, so it has nothing to do with which program, how it's written, the complexity class (linear time, P, NP-complete, superexponential etc), or even on the size of the problem. It doesn't even depend on how much memory the problem requires. You can have a computation that requires terabytes or exabytes of RAM to compute, and the world's largest supercomputer running for a decade: The proof that the output is correct, no matter how much complexity went into calculating it, is still small and fast to verify.
But you still have to do the computation somewhere to get the proof. That's why it's called "argument of knowledge", because the entity constructing the proof must have access to ("knowledge of") the computation.
So it's still about feasible computations. Usual zk-proof-of-computation can't be used to prove things larger than there's a computer able to compute.
That boundary is different from cryptography (and P vs NP), which is more about verifiability of problems requiring exponentially larger time and/or space to solve if you don't have the secrets, so if the parameters are suitable, these are about infeasible computations by any physically realisable computer.
The connection is that that zk-proofs-of-computation are about making proofs of feasible computations, while ensuring it's infeasible to compute a false proof, or to find the secret inputs if there are any (there don't have to be).
(By the way, you may be thinking of discrete logarithm not division. Division is not difficult. In finite fields such as used in cryptography, division can be computed by constant exponention using Fermat's Little Theorom, and exponentiation takes logarithmic time in the size of the field using a repeated squaring method. Division is slower than multiplication, but not prohibitively so; it's used in elliptic curve operations. The hardness of factorising certain numbers is for a different reason than division.)
Decentralized tech would never be where it is today if it weren't for investor attention and the potential for gains. We just have to separate the wheat from the chaff, and remain vigilant for bad actors.
I’ll bet blockchain is only as popular as it is because of the money. But other forms of decentralization like Mastodon or Matrix are pretty separate from the whole crypto sphere
Federated platforms appeal to the privacy-oriented "f** big tech" mindset, which is pretty common in the hacker & FOSS crowds. I'd put it in the same category as VPNs, E2E messengers and TOR.
So VPN are not really in the same category
Big corps only invest in blockchain because of the buzz words that are used as marketing by the consulting firms to sell their "expertise" and by VCs to sell their companies.
Sure they hope to gain some money, like luxury brands wanting to sell to crypto-billionaires. But crypto was a useful toy, then Ponzi scheme and now it's a closed loop. How long will the bubble last?
Nobody around me ever uses any of it. Old p2p networks (gnutella, kademlia, emule) had way larger impact on society 20 years ago.
This created a lot of bubbles. NFTs are already down by a lot, now yield farming (https://www.bloomberg.com/news/articles/2022-04-25/sam-bankm...) just took a big hit from the FTX case. I see way too many "revolutionnary" projects from fresh graduates. There is no way that tens of thousands of inexperienced people with barely enough CS education to pass programming interviews would magically create innovation just because VCs put a ton of money on them.
Also, can you tell me more about where decentralized tech is today? BitTorrent was a revolution as a way of information sharing, Onion was a revolution for privacy and Bitcoin was a revolution for decentralized ledgers.
Starting from that, IPFS is the continuation of BitTorrent with more features and Ethereum is a more efficient (especially since The Merge) and customizable (smart contracts are advanced checkers for write operations) ledger.
But what are the real world applications of those technologies? What are concrete use cases of Ethereum and IPFS besides payments, records and file sharing?
Surely there are exciting progresses to be made on the technical side like zk-SNARKS but how useful will they be to society?
I think we already have all the technical blocks we need. If there is no real-world adoption maybe we should just wait another 10 years before pumping crazy amounts of money.
The real decentralized tech, the one that serves a purpose other than emptying the wallets of naïve crypto-enthusiasts, does just fine without a profit motive. You don't need get-rich-quick promises to get an audience if you're actually doing something useful.
That’s exactly why blockchains haven’t found Product Market Fit.
Investors != Users
They went hand in hand even back in the day: private torrent trackers were all about tokenomics where tokens were the number of bytes you've seeded (uploaded) minus you've downloaded.
I'm not saying it's impossible to imagine distributed file sharing otherwise, but to "guarantee" the availability of (especially unpopular) content, you need some incentive mechanisms either built in to the protocol or externally imposed.
>Please do not use the public swarm to process sensitive data. We ask for that because it is an open network, and it is technically possible for peers serving model layers to recover input data and model outputs or modify them in a malicious way. Instead, you can set up a private Petals swarm hosted by people and organization you trust, who are authorized to process your data.
This is what blockchain and staking tokens is for. (Part of the reason, at least)
You act maliciously, the network slashes your stake. "pinky promise not to do bad stuff" only goes so far... and it's really not far at all. You can trust "trusted" organizations or private individuals, but they have no incentives to ensure that the service works as intended, regardless of intent.
In fact, it adds traceability. And data stored in it can never be deleted. Just to name a few issues.
No, but staking is certainly an improvement over "pinky promise", and it requires a public blockchain.
> issues
I'm fairly sure those are features, not issues. You are free to disagree.
This is a weird statement. Blockchain security is real and it isn't "magic". Blockchain is specifically designed to secure decentralized applications.
> In fact, it adds traceability. And data stored in it can never be deleted. Just to name a few issues.
These aren't issues, these are part of the security model. Traceability is fine here because everything is pseudonymous, if you want to avoid that use a chain that has untraceable transactions with zero knowledge proofs (zero traceability).
> And data stored in it can never be deleted. Just to name a few issues.
Storing data on blockchain is extremely expensive. Only hashes are stored on chain, not the data itself. Hashes are much different from encryption because they're irreversible.
First, automating the detection of malicious acts against sensitive data seems pretty difficult. So this can't be implemented to systematically occur, and has to be determined after the fact by an investigation. Then, if a malicious act has been detected, the stake is slashed (and the acts are reverted where possible).
Is my understanding sound so far?
Because this would mean in any case where a slashed stake is considered an "acceptable cost" to the bad actor, then the sensitive data is fairly accessible -- the stake is effectively a paywall. And raising the stake is a difficult decision because higher stake means less actors and higher risk of collusion.
I mean this is probably fine for a very large public blockchain where detecting malicious acts is not as difficult or where the malicious act is not very profitable, but sensitive data can, depending on its nature, be extremely profitable to exploit (and as I stated, I don't see how it could be easily detected).
With sensitive data, "trusting" an organization only means having a legal agreement or strategic alliance with a third party. In these circumstances the consequences are usually more serious for the malicious actor than the loss of an arbitrary amount of money.
I've seen suggestions to do sensitive (e.g. medical) data processing on the ethereum blockchain from some enthusiasts and I have never been able to understand this beyond assuming they have a insufficient threat model in mind for this kind of data.
BitTorrent style projects are far more restrictive for a lot of applications though. If something is without cost, then it becomes open to abuse.
Take domain names for instance. I would love to have a decentralized name registry, so that no country have censorship power on the _whole_ internet, as we've seen with recent US intervention at the tld level.
DNS is a good example because it's quite trivial to implement with a plain old DHT. The problem though is how do you prevent scammers and squatters in this model?
There needs to be a cost on a distributed database, otherwise after 1 year it will be fully squatted, used as free hosting, store illegal content, DDoS'd for fun, etc.
How to set this cost though, while keeping the distributed nature of this database ? the simplest solution is to let the users decide, over the price of a token, sold by people running nodes, bought by people using the service.
Honestly I love this idea. The problem with crypto currently is that a whole bunch of parasites jump on these tokens to speculate on their price without giving a.. about the underlying utility. This completely screws the price optimum and creates a inflated price bubble, in turn preventing adoption.
We have exactly the same problem with real life systems like food, raw materials and real estate.
Take the DNS example for instance, this was implemented on Ethereum by "ENS", but the price of ETH/gas at the time made a single ".eth" domain name cost something like $500.
Way more in terms of money involved, just slower.
Its a mute point whether the whole crypto/blockchain period was a net positive. It certainly made a noisy case for "re-decentralization" given the very real and mostly harmful status quo. One could also argue that it diverted vital resources to potentially dead-end or limited use areas. The recurrent scams may also give decentralization a bad name to an uninformed public that can't distinguish all the different versions.
What matters next is that projects that deliver real benefits to users get attention and traction. Worth keeping in mind that the real trouble starts when you get noticed by vested interests as a potential threat.
That's why you can actually attack and shut down a bittorrent network, by targeting the index servers, that are not massively replicated. I.E. The Piratebay is often down.
As a solution for this, I'll shamelessly plug my small project here, that combines bittorrents with the blockchain as a invulnerable piratebay-like bittorrent index server, called Blockchain Bay: https://github.com/ortegaalfredo/blockchainbay
It's command line, and don't use any tokenomic scams. You pay the blockchain only for the data you need to upload, that is fortunately, very little as bittorrent magnet links are very small.
Of course its abused by shady operators out to make a quick buck, but issuing tokens, when done right, is a great innovation by itself.