{"type":"rich","version":"1.0","author_name":"npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2","author_url":"https://nostr.ae/npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2017-06-19\n📝 Original message:On Tue, Jun 20, 2017 at 02:01:45AM +0800, Wang Chun via bitcoin-dev wrote:\n\u003e There has been proposal to change the PoW in case of potential 51% attacks\n\u003e from malicious miners during a fork. But such a change in PoW renders\n\u003e multi-billion-dollar of ASIC into worthless. which hurts economy so much\n\u003e and the average innocent mining users. I would propose, instead of PoW\n\u003e change, we could change the system to the same double sha256 PoW but mix it\n\u003e with PoS features. Such a PoW+PoS system has several advantages:\n\n\nYou have to specify what you mean by \"PoS\" - there's dozens of variations.\nEqually, existing pure PoS schemes probably don't make sense as a \"bolt-on\"\nadd-on, as once you introduce PoW to it you should design something that uses\nthe capabilities of both systems.\n\nFWIW, I've heard that the Ethereum guys are leaning towards abandoning pure PoS\nand are now trying to design a PoW + staking system instead.\n\n\u003e * It protects existing multi-billion dollar investments from innocent\n\u003e mining users,\n\nTo be clear, you mean such a scheme would protect the multi-billion dollar\ninvestments non-malicious miners have made in SHA256^2 hardware by ensuring it\nremains useful, right?\n\n\u003e * A malicious miner cannot launch attacks and rewrite the blockchain with\n\u003e 51% or even more hashrate,\n\u003e * If we insert 4 PoS blocks between 2 PoW blocks, we'll have 2-minute block\n\u003e time span, that solves the long confirmation time problem,\n\nNote that if those PoS blocks are *pure* PoS, you'll create a significant risk\nof double-spend attacks, as there's zero inherent cost to creating a pure-PoS\nblock. Such blocks can't be relied on for confirmations; even \"slasher\" schemes\nhave significant problems with sybil attacks.\n\n\u003e * We'll suddenly have 5 times of block space, that solves the scaling\n\u003e problem,\n\nThe scaling problem is one of scalability; PoS does nothing to improve\nscalability (though many in the ETH community have been making dishonest\nstatements to the contrary).\n\n\u003e * The PoS blocks only mine transaction fees, so the 21M cap remains,\n\u003e * With careful design, the PoW+PoS transition _might_ be able to deploy\n\u003e with a soft fork.\n\nAs a sidechain yes, but in what you propose above the extra blocks wouldn't\ncontain transactions that non-PoS-aware nodes could understand in a\nbackwards-compatible way.\n\n\nAll the above aside, I don't think it's inherently wrong to look at adding PoS\nblock *approval* mechanisms, where a block isn't considered valid without some\nkind of coin owner approval. While pure-PoS is fundamentally broken in a\ndecentralized setting, it may be possible to mitigate the reasons it's broken\nwith PoW and get a system that has a stronger security model than PoW alone.\n\nFWIW there's some early discussions by myself and others about this type of\napproach on the #bitcoin-wizards IRC channels, IIRC from around 2014 or so.\n\n-- \nhttps://petertodd.org 'peter'[:-1]@petertodd.org\n-------------- next part --------------\nA non-text attachment was scrubbed...\nName: signature.asc\nType: application/pgp-signature\nSize: 455 bytes\nDesc: Digital signature\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20170619/9c314d95/attachment.sig\u003e"}
