Safety, liveness and fault tolerance—the consensus choices
stellar.org
stellar.org
I particularly enjoy this quote from http://adamierymenko.com/decentralization-i-want-to-believe/:
A centralized alternative to Bitcoin would be a simple SQL database with a schema representing standard double-entry accounting and some meta-data fields. The entire transaction volume of the Bitcoin network could be handled by a Raspberry Pi in a shoebox.
Instead, we have a transaction volume of a few hundred thousand database entries a day being handled by a compute cluster comparable to those used to simulate atomic bomb blasts with physically realistic voxel models or probabilistically describe a complete relationship graph for the human proteome.
EDIT:
To those pointing out the 2013 Bitcoin fork, good point.
However, in cryptocurrency land, 2013 is ancient history, and I'd argue standards are higher already.
If you want a centralized system, just use your bank, Paypal or whatever. Nobody was claiming that Bitcoin, a distributed system, was more efficient computing than other systems. The whole point of Bitcoin is that nobody controls it. Finding something that is more efficient than Bitcoin, without the decentralization, is plain stupid. I don't need an "expert" telling me that "hurr I could have done that faster with a SQL database".
Any voting system will fail if someone can cheaply and easily create new voting identities. Email spam, web spam, and social networking spam all suffer from that problem - email addresses, web sites, and social networking accounts are cheap and easy to create. Bitcoin beats this by giving voting power to whomever spends the most on mining hardware. That works, but at high cost and only because there's a big financial reward for being a big miner.
How to limit fake online identity creation? Facebook tried "real names", which semi-worked until they ran into the gay agenda. Google tries to make you tie your whole life into one account, and they can tell if your account doesn't have enough of your life tied in. The credit industry tries to do this by chasing down people who don't pay up, and is reasonably successful, but at high cost.
ID by phone number has been tried, as "phone verification". That created a small industry in phony phone numbers. (http://www.sitetruth.com/doc/socialisbadforsearch09.pdf) ID by postal address was tried, but there are too many mailbox services.
There's no really good solution to this known.
Also, the benefits of decentralized consensus has benefits the are so vast, the resources it takes to achieve it are miniscule by comparison.
(Stellar was, of course, founded by a couple of the Ripple founders using exactly the same technology they used for Ripple. Also, we're talking about the new "decentralized" Ripple here; there was an older version of Ripple that was centralized but didn't have the same problem, and that's the version that predated Bitcoin.)
My nomination: Dogecoin.
It's fairly obvious we currently have no way to do perfect identity management. It's also fairly obvious you are using it as one-of-your-many ad hominem arguments.
Trust is the original currency and was the basis for the very first monies ever invented; monies based on trust are much more empowering than "hard" currencies which always have the effect of disproportionately empowering those who already have money.
>That is also how the fiat money system works.
The difference is that now, for the first time in history, you get control over your obligations, not banks. BTW your bias is showing.
This is a patently false statement.
is incomplete: a distributed consensus system (which is, at heart, a distributed database) can not have all three features... but there is no guarantee that a distributed database has any of those features.
As with everything else, execution matters.
If you're going to be recording history for financial transactions, you need to put immutability as your first goal. This is not compatible with unlimited space-time separation of trusted inputs, so the second thing you need is to decide how you're going to resolve inconsistent histories. Doing so always involves a centralized trusted system, even if it is fed from a distributed system: someone needs to decide what transactions really happened. You can claim that you have a distributed algorithm to do so (consensus) but that itself will always fall into the same distribution problem.
And that's what seems to have happened here.
False, the Bitcoin system resolves inconsistent histories in a completely decentralized manner.
To limit the number of blocks that could be invalidated in this way, the bitcoin reference implementation contains checkpoint hashes. These are indeed decided centrally.
If you accept the core assumption in bitcoin that an attacker will never control a majority of the hashing power, then there probably isn't a problem and the checkpoint s aren't needed.
The checkpoint hashes are not imposed on the users, but rather the users must choose to upgrade to the new checkpoint hashes. As such, you can argue that it is decentralized.
No, one could not argue that. The economic majority will decide which fork is valid. That's the opposite of centralization.
"To limit the number of blocks that could be invalidated in this way, the bitcoin reference implementation contains checkpoint hashes. These are indeed decided centrally.
If you accept the core assumption in bitcoin that an attacker will never control a majority of the hashing power, then there probably isn't a problem and the checkpoint s aren't needed."
You fail to realize you are not forced to download anything you don't want to. And the checkpoints are hundreds of blocks deep. They don't decide anything the network hasn't already decided (6 blocks deep transactions are considered practically irreversible). The checkpoints ARE needed as an anti-DOS measure (they protect the storage of full nodes from being flooded by forks that could suddenly start to appear at low block numbers). I don't know why people are so eager to spit opinions on things they don't know anything about.
> We were able to replay most of these rolled back transactions on chain B to minimize the impact
And
> To ensure no ledger forks going forward in Stellar, we have decided to temporarily only run one validating node until the new consensus algorithm is live
I don't see the decentralisation here?
[1] https://www.stellar.org/learn/#Decentralized_network "This means that the Stellar network does not depend on any single entity"
I'm a layperson when it comes to crypto currencies, but my impression is that most people would consider the fact that you can centralize a bug (separate to the hiccup you had in the article).
We do not have the ability nor do we want the ability to control other people's nodes.
Since Stellar only launched 4 months ago, the number nodes in the network was still small. In the future, when the network is on the new consensus system and able to run safely in a truly decentralized, then it would be up to individual nodes to decide what to do.
Hope that clarifies things.
In many ways a centralised, but highly anonymous, digital cash system puts stronger practical limits on the power of a single individual. In such a system the the only way the central authority (bank etc) to doctor history, once money has moved out of their hands, is to drive the entire currency in to the ground and start over.
[0] http://www.coindesk.com/ghash-commits-40-hashrate-cap-bitcoi...
With Bitcoin, such a change is very difficult. With stellar, it is easy for the central Corp to change the rules at it's whim.
Without decentralisation, Bitcoin has nothing to offer over everyone trusting some random entity offering to keep a ledger of account balances. And we already have plenty of those around.
"Prof. Mazières’s research indicated some risk that consensus could fail, though we were nor certain if the required circumstances for such a failure were realistic."
I'm surprised to see the above statement in a press release; maybe it was not worded quite right. At the scale of 100s of thousands, or a millions of transactions a day, "some risk" will manifest itself on operation timescales itself. So when one is "not certain" it's always best to assume that problems will show up and it will take less time than expected. "We are still investigating the triggers for this consensus failure, but believe it is caused by the innate weaknesses of the Ripple/Stellar consensus system outlined above compounded by the number of accounts in the network."
Also not great wording. Saying the system had "innate weaknesses" and we "believe" kind of implies engineers are still guessing on the trigger. Your building a financial corporation and if you lose you loose everythinghttps://ripple.com/why-the-stellar-forking-issue-does-not-af...
(Ripple Labs develops the software that Stellar modifies for their own use, and the original Ripple network still runs on unmodified Ripple Labs software. Stellar was started by Jed McCaleb, who founded Ripple Labs, but broke with the CEO last year.)
The Ripple consensus protocol puts certain requirements on the topology of the network of transaction-validating nodes in order to work properly. They are still investigating, but it's possible Stellar's network fell outside the workable range. Ripple Labs manages their network topology more carefully than Stellar, and this incident may validate their approach. We'll have to see what actually happened.
They re-branded as "Stellar" + somehow got Stripe to give them a mention and the scam repeats