True.
>How is this expected to scale over time and are there any challenges for the network if it becomes too large to quickly/easily share?
This is debated.
>(Or not since only the tail is really needed?)
That's basically the first approach.
If you trust someone else to tell you the state at time X (give you a 'checkpoint' basically), then the volume of data still grows with the number of separate accounts that have 'bitcoins' in them, but [where all the remaining money is as of recent time X] is a lot less information than [the complete set of previous transactions for all time].
Or you could have a thin client, that trusts some other service to maintain and monitor the current state of the system, which your thin client regularly queries.
Both of these schemes cut down the data storage requirement a lot, and sort of solve that scalability problem.
However, both require trusting some third party to supply you with an abbreviated version of the transaction history (or group or parties, or chain of authority, etc.), and its open to debate whether, if you do that, you lose some of the 'decentralised' aspects of the system that make it nice. Or you could say that's "just a philosophical concern" that doesn't really matter.
I personally guess that the various developers will be able to engineer around this problem.
I'd be more worried the system handling real time transaction volume, if it became mass adopted, and people tried to do all transactions on the blockchain.
Check out https://en.bitcoin.it/wiki/Scalability as a starting point.
There are definitely challenges with its current growth rate. As currently designed, it's capped at about 25,000 transactions per hour. The developers are working on addressing this limitation, but the solution is complex and they aren't done yet. We went from ~200 transactions/hour in Jan 2012 to ~2,700 transactions/hour in Dec 2013, so it's conceivable we end up getting pretty close to (or hitting) the cap in the near future.
25,000/hour is a shockingly small number to me. I feel like I must be misunderstanding something, or else someone from 4chan would have already DOS'd bitcoin for fun.
Current transaction fees are typically in the range of 0.1-0.5mBTC, so in order to continuously flood out everyone else, you'd need to spend more than 2.5BTC/hour in fees.
I agree with fragsworth that once Bitcoin is mature the blockchain will grow linearly; in the short term we may see more rapid growth. Most users are not expected to store the whole blockchain; using SPV or UBC a peer can store much less data.
Good run down, it was this year.
A change can not be enforced. If a significant subset of clients decides on a different path (for example stay on the old protocol), a fork of the blockchain would be the result. I guess then if you would own 1 BTC before, you'd suddenly own one "old Bitcoin" and one "new Bitcoin".
There are already clients that only download parts of the blockchain, trading storage and bandwidth for reduced security - for example the mobile clients, or Multibit (afaik). I suppose they rely on trusted nodes (not sure).
But suppose SHA256 would be broken and the "vote" would be to change the mining protocol to scrypt. Why wouldn't the nodes and miners change? It's not so different from updating your web server when there has been a security bug. Some people forget to update their web servers and get hacked. The next time, maybe they won't forget to update. Maybe if you installed your bitcoin software with a package manager, it will be automatically updated.
It would be interesting if there was an attempt to enforce "tainted coins" (forcing clients to reject bitcoins that are known to have been through criminal hands). I suppose governments could require businesses to only accept btc that are not tainted. I honestly don't know how things would play out - maybe the community would addopt it, maybe not, or maybe there would be a fork...
All just from my limited understanding, please correct me if necessary.
I suppose some of the fun parts would go away then, such as the possibility to view every transaction that has ever been made - in the Merkel Hashed blockchain not all information would be preserved.
Edit: I suppose it would still be possible to monitor all transactions and remember them by some other means, just not in the blockchain.