<oembed><type>rich</type><version>1.0</version><author_name>npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_name><author_url>https://nostr.ae/npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-06-19&#xA;📝 Original message:On Tue, Jun 20, 2017 at 02:01:45AM +0800, Wang Chun via bitcoin-dev wrote:&#xA;&gt; There has been proposal to change the PoW in case of potential 51% attacks&#xA;&gt; from malicious miners during a fork. But such a change in PoW renders&#xA;&gt; multi-billion-dollar of ASIC into worthless. which hurts economy so much&#xA;&gt; and the average innocent mining users. I would propose, instead of PoW&#xA;&gt; change, we could change the system to the same double sha256 PoW but mix it&#xA;&gt; with PoS features. Such a PoW+PoS system has several advantages:&#xA;&#xA;&#xA;You have to specify what you mean by &#34;PoS&#34; - there&#39;s dozens of variations.&#xA;Equally, existing pure PoS schemes probably don&#39;t make sense as a &#34;bolt-on&#34;&#xA;add-on, as once you introduce PoW to it you should design something that uses&#xA;the capabilities of both systems.&#xA;&#xA;FWIW, I&#39;ve heard that the Ethereum guys are leaning towards abandoning pure PoS&#xA;and are now trying to design a PoW + staking system instead.&#xA;&#xA;&gt; * It protects existing multi-billion dollar investments from innocent&#xA;&gt; mining users,&#xA;&#xA;To be clear, you mean such a scheme would protect the multi-billion dollar&#xA;investments non-malicious miners have made in SHA256^2 hardware by ensuring it&#xA;remains useful, right?&#xA;&#xA;&gt; * A malicious miner cannot launch attacks and rewrite the blockchain with&#xA;&gt; 51% or even more hashrate,&#xA;&gt; * If we insert 4 PoS blocks between 2 PoW blocks, we&#39;ll have 2-minute block&#xA;&gt; time span, that solves the long confirmation time problem,&#xA;&#xA;Note that if those PoS blocks are *pure* PoS, you&#39;ll create a significant risk&#xA;of double-spend attacks, as there&#39;s zero inherent cost to creating a pure-PoS&#xA;block. Such blocks can&#39;t be relied on for confirmations; even &#34;slasher&#34; schemes&#xA;have significant problems with sybil attacks.&#xA;&#xA;&gt; * We&#39;ll suddenly have 5 times of block space, that solves the scaling&#xA;&gt; problem,&#xA;&#xA;The scaling problem is one of scalability; PoS does nothing to improve&#xA;scalability (though many in the ETH community have been making dishonest&#xA;statements to the contrary).&#xA;&#xA;&gt; * The PoS blocks only mine transaction fees, so the 21M cap remains,&#xA;&gt; * With careful design, the PoW+PoS transition _might_ be able to deploy&#xA;&gt; with a soft fork.&#xA;&#xA;As a sidechain yes, but in what you propose above the extra blocks wouldn&#39;t&#xA;contain transactions that non-PoS-aware nodes could understand in a&#xA;backwards-compatible way.&#xA;&#xA;&#xA;All the above aside, I don&#39;t think it&#39;s inherently wrong to look at adding PoS&#xA;block *approval* mechanisms, where a block isn&#39;t considered valid without some&#xA;kind of coin owner approval. While pure-PoS is fundamentally broken in a&#xA;decentralized setting, it may be possible to mitigate the reasons it&#39;s broken&#xA;with PoW and get a system that has a stronger security model than PoW alone.&#xA;&#xA;FWIW there&#39;s some early discussions by myself and others about this type of&#xA;approach on the #bitcoin-wizards IRC channels, IIRC from around 2014 or so.&#xA;&#xA;-- &#xA;https://petertodd.org &#39;peter&#39;[:-1]@petertodd.org&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: signature.asc&#xA;Type: application/pgp-signature&#xA;Size: 455 bytes&#xA;Desc: Digital signature&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20170619/9c314d95/attachment.sig&gt;</html></oembed>