<oembed><type>rich</type><version>1.0</version><author_name>npub1swfeusu3ua9trup00qcnrgc2yndksyvgku4epk5tec7u4fmrez6qxpul5t</author_name><author_url>https://nostr.ae/npub1swfeusu3ua9trup00qcnrgc2yndksyvgku4epk5tec7u4fmrez6qxpul5t</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-02-12&#xA;📝 Original message:&gt; Miners are *not* incentivised to earn the most money in the next block&#xA;&gt; possible. They are incentivised to maximise their return on investment.&#xA;&gt;&#xA;&#xA;This would be right if you assume that all Bitcoin miners act as a single&#xA;entity. In that case it is true that that entity&#39;s goal is to maximize&#xA;overall ROI.&#xA;&#xA;But each miner makes decisions on his own. Are you familiar with a concept&#xA;of Nash equilibrium, prisoner&#39;s dilemma, etc?&#xA;&#xA;The fact that nobody is using this kind of a behavior right now doesn&#39;t&#xA;mean that we can rely on it.&#xA;&#xA;For example, Peercoin was horribly broken in 6 months after its release&#xA;(e.g. people reported that they are able to generate 50 consecutive blocks&#xA;simply by bringing a cold wallet online) and yet nobody bothered to exploit&#xA;it, and it managed to acquire non-negligible &#34;market cap&#34;.&#xA;&#xA;So we have an empiric evidence that proof-of-stake miners are motivated to&#xA;keep network secure. So, maybe, we should switch to proof-of-stake, if it&#xA;was demonstrated that it is secure?&#xA;&#xA;There are good reasons to not switch to proof-of-stake. Particularly, the&#xA;kind which is used in Peercoin is not game-theoretically sound. So even if&#xA;it works right now, it can fail in a big way once attackers will really get&#xA;around to it. An attack requires significant knowledge, effort and,&#xA;possibly, capital, so it might be only feasible on a certain scale.&#xA;&#xA;So, well, anyway, suppose Peter Todd is the only person interested in&#xA;maintaining replace-by-fee patches right now, and you can talk him into&#xA;abandoning them.&#xA;OK, perhaps zero-confirmation payments will be de-facto secure for a couple&#xA;of years. And thus a lot of merchants will rely on zero-confirmation&#xA;payments protected by nothing but a belief in honest miners, as it is damn&#xA;convenient.&#xA;&#xA;But, let&#39;s say, 5 years from now, some faction of miners who own&#xA;soon-to-be-obsolete equipment will decide to boost their profits with a&#xA;replace-by-fee pool and a corresponding wallet. They can market it as &#34;1 of&#xA;10 hamburgers are free&#34; if they have 10% of the total hashpower.&#xA;&#xA;So would you take a responsibility for pushing the approach which isn&#39;t&#xA;game-theoretically sound?&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150212/b4b4de32/attachment.html&gt;</html></oembed>