# ASIC Resistance

**URL:** <https://forum.zcashcommunity.com/t/asic-resistance/34393>\
**Category:** Mining\
**Created:** [August 4, 2019, 10:10pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393 "2019-08-04T22:10:20Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![sonya](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/sonya/32/9518_2.png) [@sonya](https://forum.zcashcommunity.com/u/sonya)\
**Post date:** [August 5, 2019, 9:37pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/22 "2019-08-05T21:37:41Z")

</div>

> [@johnwisdom](#):
>
> Zcash has proven to be too democratic and far from being a community driven project.

Too democratic? Do you mean the opposite?

@nathan-at-least explained the reasoning for NUP [when it debuted](https://electriccoin.co/blog/the-zcash-network-upgrade-pipeline/):

> We’ve developed this process to meet a variety of goals, based on everything we’ve learned from the Zcash launch and the Overwinter and Sapling upgrades. The primary goals are to **ship safely** — with plenty of time for **ecosystem partner integration** , in **collaboration across multiple organizations** — in a **governance agnostic manner** , all while **pipelining concurrent upgrades**.

Predictability is important if you want other organizations to coordinate with you. We don’t want to break the wallets and exchanges that support Zcash with surprise changes. Those teams have other stuff going on as well, so a long lead time is important.

---

<div class="post-metadata">

**Author:** ![johnwisdom](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/johnwisdom/32/5836_2.png) [@johnwisdom](https://forum.zcashcommunity.com/u/johnwisdom)\
**Post date:** [August 5, 2019, 10:03pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/23 "2019-08-05T22:03:44Z")

</div>

> [@johnwisdom](#):
>
> ASIC resistance would’ve been the perfect reason to hard fork fixing both issues (BCTV14 and kicking off asic from the network).

What do you have to say about this?

> [@sonya](#):
>
> Predictability is important if you want other organizations to coordinate with you.

This is what I mean by to democratic.  
Having a good excuse to not take action. (EDIT: from always having to having a good)

Democratic with ZIP’s, with deadlines, with informing when and how: zcash has never messed up.

But wait, the goal to ship safely wasn’t respected, then why respect the NU process at that point?  
Everyone is entitled to do an oopsie.  
Personally I think asking for forgiveness (to the SO MANY exchanges, developers, etc) would’ve been better than going full COV OP.

> [@sonya](#):
>
> We don’t want to break the wallets and exchanges that support Zcash with surprise changes. Those teams have other stuff going on as well, so a long lead time is important.

Are you speaking on behalf of the foundation?

I agree a long lead time is important, but critical management is critical management, heck critical management is “other stuff going on”.

---

<div class="post-metadata">

**Author:** ![sonya](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/sonya/32/9518_2.png) [@sonya](https://forum.zcashcommunity.com/u/sonya)\
**Post date:** [August 5, 2019, 10:17pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/24 "2019-08-05T22:17:22Z")

</div>

Just speaking generally, there’s no official Foundation position on the NUP. It’s an ECC thing — we may end up mirroring it with Zebra dev, but AFAIK that hasn’t been ultimately decided. @gtank will provide more info on our tech roadmap soon.

> [@johnwisdom](#):
>
> ASIC resistance would’ve been the perfect reason to hard fork fixing both issues (BCTV14 and kicking off asic from the network).

I don’t have a position on this, sorry =/

---

<div class="post-metadata">

**Author:** ![CitricAcid](https://avatars.discourse-cdn.com/v4/letter/c/cc9497/32.png) [@CitricAcid](https://forum.zcashcommunity.com/u/CitricAcid)\
**Post date:** [August 6, 2019, 4:24am UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/26 "2019-08-06T04:24:39Z")

</div>

you want an ASIC resistant version of Zcash, there was recently a friendly fork promising just that, and it’s now live. I would go chat up their forums.

---

<div class="post-metadata">

**Author:** ![sonya](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/sonya/32/9518_2.png) [@sonya](https://forum.zcashcommunity.com/u/sonya)\
**Post date:** [August 6, 2019, 5:38am UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/27 "2019-08-06T05:38:53Z")

</div>

For anyone new, CitricAcid is referring to [Ycash](https://www.ycash.xyz/)

---

<div class="post-metadata">

**Author:** ![francesco1983](https://avatars.discourse-cdn.com/v4/letter/f/34f0e0/32.png) [@francesco1983](https://forum.zcashcommunity.com/u/francesco1983)\
**Post date:** [August 6, 2019, 5:57am UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/28 "2019-08-06T05:57:48Z")

</div>

Hello everyone … I’m a bit new in the world of crypto, I’ve been slamming my head for only 3 years. according to my point of view the choice to increase ASIC was due to achieve fundamental goals in the future. I believe that those who say that resistance to asics was better, is only talking about the busnes that concerns them. I believe that over time ZCASH will become a great Crypto, not only by looking at the price, but also in terms of technology, privacy, speed and security . It has a strong potential and the people who are working on it know it and I think they will push to improve it even more.

---

<div class="post-metadata">

**Author:** ![arielgabizon](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/arielgabizon/32/11082_2.png) [@arielgabizon](https://forum.zcashcommunity.com/u/arielgabizon)\
**Post date:** [August 6, 2019, 10:23am UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/29 "2019-08-06T10:23:34Z")

</div>

I verified indeed that the overwinter rules were committed March 2 [New Release: 1.0.15 - Electric Coin Company](https://electriccoin.co/blog/new-release-1-0-15/)  
which is another reason why it’s invalid imo to try to connect no asic resistance to the exploit:  
If the company was really serious about no asics it would’ve changed equihash params already for overwinter - otherwise you kill the GPUs and need to revive them later, and all of overwinter (except the _day_ before release) was planned/executed without knowledge of the vuln.  
sidenote: the fact that the Ycash team managed to change the equihash params with much less engineering resources is another indication to the (perhaps obvious) fact that it’s a simple change.

---

<div class="post-metadata">

**Author:** ![arielgabizon](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/arielgabizon/32/11082_2.png) [@arielgabizon](https://forum.zcashcommunity.com/u/arielgabizon)\
**Post date:** [August 6, 2019, 10:30am UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/30 "2019-08-06T10:30:07Z")

</div>

Well I would argue a network where you know your ASIC will only be good for two months each time would be a great disincentivization.  
In the worst case, keeping the GPUs alive for another 4 months would at least have kept much more good will.  
More generally, the argument of the company is we need a lot of resources cause we have the best people doing complicated stuff…  
that doesn’t go together with: we’ll break previous promises whenever something is a bit harder than trivial.

As a point of reference, I’ve understood Monero’s opt-in donation budget is around 25k per month on average, and they fight ASICs + integrate new crypto (maybe a little less fancy than Zcash, but not much less, with new stuff like bulletproofs) with that budget.

In any case, all of that is in the should Zcash be asic resistant question;  
my main point was more: please don’t use the counterfeit bug as the reason/excuse you didn’t do something about ASICs.  
That is what crosses a line for me and makes me talk publicly about issues I usually don’t.

---

<div class="post-metadata">

**Author:** ![tromp](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/tromp/32/522_2.png) [@tromp](https://forum.zcashcommunity.com/u/tromp)\
**Post date:** [August 6, 2019, 12:15pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/31 "2019-08-06T12:15:41Z")

</div>

Even before launch, we knew that 144,5 would be a much preferable parameter choice. The only reason it launched with 200,9 is that 144,5 solving was feared to be too slow, the choice was already made before the realization that 144,5 instances can in fact be solved within seconds, and launch was on a tight schedule.

The switch to 144,5 was always desirable, both for ASIC resistance and for header space savings (200,9 proofs are well over a KB). I think the switch should have been on the roadmap from launch, and definitely be included in Overwinter.

---

<div class="post-metadata">

**Author:** ![daira](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/daira/32/43253_2.png) [@daira](https://forum.zcashcommunity.com/u/daira)\
**Post date:** [August 6, 2019, 5:32pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/32 "2019-08-06T17:32:05Z")

</div>

> [@str4d](#):
>
> ECC lost a lot of goodwill from a section of the community as a result of the ASIC mining issue. We lost a lot of miners who had been invested in GPUs. And as it turns out, part of the reason that we couldn’t just keep the protocol GPU-friendly was that we needed to do Sapling, and we needed to do Sapling because of the BCTV14 flaw. And so our hand was forced, basically, but there’s still a perception that we kind of fluffed that from a technical point-of-view, which I don’t think is actually the case. And maybe we wouldn’t— maybe there would be more trust in ECC if things had gone differently.

This is an accurate transcription of what I said. What I should have clarified, though, is that the BCTV14 flaw was not the only reason we did Sapling (which is kind-of obvious).

The point I was trying to make is that the flaw made it _necessary_ to do Sapling on a shorter timescale than several of the ECC engineers, who didn’t know about the flaw, would have wanted. And that completely precluded doing an ASIC-resistance fork. I’m not sure whether or not an ASIC-resistance fork would have happened under other circumstances. I don’t think I’m revealing too much by saying that it was a source of significant controversy _within_ ECC that we weren’t doing one. If you remember, we did try to do a hybrid PoW with an ASIC-resistant component later in Blossom, and that had to be abandoned –unfortunately– due to security concerns about the hybrid aspect.

---

<div class="post-metadata">

**Author:** ![daira](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/daira/32/43253_2.png) [@daira](https://forum.zcashcommunity.com/u/daira)\
**Post date:** [August 6, 2019, 5:37pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/33 "2019-08-06T17:37:07Z")

</div>

Overwinter couldn’t possibly ever have included a PoW change. It would have been far too risky. Overwinter was always conceived as a minimal upgrade in order to prove that we could safely do hard-fork upgrades (which was not at all clear!) Remember that the Bitcoin Core community is generally implacably opposed to hard-fork upgrades; Zcash inherited that code base and the assumptions coded into it.

---

<div class="post-metadata">

**Author:** ![arielgabizon](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/arielgabizon/32/11082_2.png) [@arielgabizon](https://forum.zcashcommunity.com/u/arielgabizon)\
**Post date:** [August 6, 2019, 5:41pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/34 "2019-08-06T17:41:14Z")

</div>

How is the change of equihash params more risky/complicated than the change of signature hash in overwinter? Given @tromp’s comment for example, it seems reinforced that it is a simple not risky change. What is the relevance of bitcoin’s opposition to hardforks when Zcash _in any case_ regularly hard forks?

Also, I don’t think it’s a fair comparison to mention the hybrid PoW which we both agreed was, putting it delicately, much more controversial and risky (especially with the selective timelock feature)

---

<div class="post-metadata">

**Author:** ![arielgabizon](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/arielgabizon/32/11082_2.png) [@arielgabizon](https://forum.zcashcommunity.com/u/arielgabizon)\
**Post date:** [August 6, 2019, 5:50pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/35 "2019-08-06T17:50:42Z")

</div>

I understood you were saying it’s not the only reason. My opinion that I have tried to convey is that even saying that it was a non-negligible factor (and since that’s the only reason you mention explicitly you’re hinting it’s not just non-negligible but at the very least prominent) is “exploiting the exploit” unfairly to go back on initial promises. And I find it personally offensive, cause it’s using my work to endorse things I disagree with.

One additional reason for this that I haven’t mentioned yet in this thread but @mistfpga mentioned is that there was a mitigation to the vuln that didn’t require sapling.  
I agree it had its own disadvatnages (as I explain in zeroknowledgefm podcast if anybody’s interested) but it’s another indication that if it was a priority it could’ve been done.

---

<div class="post-metadata">

**Author:** ![arielgabizon](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/arielgabizon/32/11082_2.png) [@arielgabizon](https://forum.zcashcommunity.com/u/arielgabizon)\
**Post date:** [August 6, 2019, 6:02pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/36 "2019-08-06T18:02:03Z")

</div>

By the way, also adding privacy is a huge complication to the Zcash protocol, but of course it would be absurd to remove it for simplicity, cause it’s the main feature.  
Similarly I (and seems many others) understood asic-resistance as a main feature in the early days.  
When someone would ask me “In two sentences what is Zcash?”  
I’d say “It’s like bitcoin, with a privacy layer, asic-resistance and 10% dev fund”

---

<div class="post-metadata">

**Author:** ![daira](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/daira/32/43253_2.png) [@daira](https://forum.zcashcommunity.com/u/daira)\
**Post date:** [August 6, 2019, 6:10pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/37 "2019-08-06T18:10:59Z")

</div>

I thought I was clear: we had never done a hard-fork upgrade at that point. Overwinter was _always_ primarily a test upgrade.

---

<div class="post-metadata">

**Author:** ![arielgabizon](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/arielgabizon/32/11082_2.png) [@arielgabizon](https://forum.zcashcommunity.com/u/arielgabizon)\
**Post date:** [August 6, 2019, 6:26pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/38 "2019-08-06T18:26:06Z")

</div>

Again, I think it’s a misleading use of the word “primarily”.  
The signature hash change, included in overwinter, was an order of magnitude more complex than changing equihash params. Do you disagree?  
But we included it, cause we _cared_ about users not being able to make large transactions.

---

<div class="post-metadata">

**Author:** ![daira](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/daira/32/43253_2.png) [@daira](https://forum.zcashcommunity.com/u/daira)\
**Post date:** [August 6, 2019, 6:33pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/39 "2019-08-06T18:33:12Z")

</div>

> [@johnwisdom](#):
>
> ASIC resistance would’ve been the perfect reason to hard fork fixing both issues (BCTV14 and kicking off asic from the network).

Frankly that would be a preposterous amount of technical risk to incur in a single upgrade. There’s a reason we have had so few bugs, and it depends on not doing things like that. Sorry if I sound frustrated, but there’s a lot of armchair engineering and protocol design going on here (as there was in many of the previous PoW discussions).

---

<div class="post-metadata">

**Author:** ![daira](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/daira/32/43253_2.png) [@daira](https://forum.zcashcommunity.com/u/daira)\
**Post date:** [August 6, 2019, 6:36pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/40 "2019-08-06T18:36:06Z")

</div>

> [@arielgabizon](#):
>
> The signature hash change, included in overwinter, was an order of magnitude more complex than changing equihash params. Do you disagree?

I don’t really agree. I think they’re incomparable kinds of complexity.

> [@](#):
>
> But we included it, cause we _cared_ about users not being able to make large transactions.

It just barely made it in, _not_ because we cared so much about large transactions, but because it was a serious DoS problem even for 100 KB transactions.

---

<div class="post-metadata">

**Author:** ![arielgabizon](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/arielgabizon/32/11082_2.png) [@arielgabizon](https://forum.zcashcommunity.com/u/arielgabizon)\
**Post date:** [August 6, 2019, 7:07pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/41 "2019-08-06T19:07:53Z")

</div>

@daira: wasn’t the DoS problem solved way before by restricting transaction size: [Make 100KB transaction size limit a consensus rule, rather than a standard rule by ebfull · Pull Request #1501 · zcash/zcash · GitHub](https://github.com/zcash/zcash/pull/1501)  
And so given that earlier change, I think it’s more accurate to say the sighash change was about allowing larger tx?  
(Your phrasing makes it sound like there was a DoS attack possible until overwinter using large tx,  
and that’s the primary reason we did something in overwinter that was beyond a test upgrade, and I think that’s misleading given this attack was mitigated in this earlier restriction)

---

<div class="post-metadata">

**Author:** ![boxalex](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/boxalex/32/14872_2.png) [@boxalex](https://forum.zcashcommunity.com/u/boxalex)\
**Post date:** [August 6, 2019, 7:44pm UTC](https://forum.zcashcommunity.com/t/asic-resistance/34393/42 "2019-08-06T19:44:35Z")

</div>

I can’t comment the technical details discussed in the last posts, but what makes me thinking is that after a One-Man-Show project (Ycash) can fork with ease to a new algo parameter within equihash and obviously, at least it looks like that, without problems after as well.

Sure, there are a bit different circustances as Ycash had not to deal with sapling and overwinter, but than again, they on the other side don’t have a ~50 engineer team at Ycash.

Just out of curiousity, as what is done is done anyway, but would it had been an option to postpone an asic resistance hardfork for some months and meanwhile test things on a test net?

[Previous page](https://forum.zcashcommunity.com/t/asic-resistance/34393.md?page=1)

[Next page](https://forum.zcashcommunity.com/t/asic-resistance/34393.md?page=3)
