SN-10018 附来源、原文与上下文。
Ray Dillinger 写道:
Ray Dillinger wrote:
引用的来信Ray Dillinger来源 ↗一种做法是让收币的人生成一对非对称密钥,然后将其中一半随交易公布。为了以后花掉这个币,他或她必须证明自己持有这对非对称密钥的另一半,可能是用它为新卖方提供的密钥签名。
One way to do this would be to have the person recieving the coin generate an asymmetric key pair, and then have half of it published with the transaction. In order to spend the coin later, s/he must demonstrate posession of the other half of the asymmetric key pair, probably by using it to sign the key provided by the new seller.
对,使用的是 ECC 数字签名。每笔交易都使用一对新密钥。
Right, it's ECC digital signatures. A new key pair is used for every transaction.
它不是用化名来识别人的那种假名制,但它至少有一点假名制的性质:人们可以认定,对某个币的下一次操作来自这个币的所有者。
It's not pseudonymous in the sense of nyms identifying people, but it is at least a little pseudonymous in that the next action on a coin can be identified as being from the owner of that coin.
引用的来信Ray Dillinger来源 ↗嗯。我不知道自己是否能接受这一点。你是说完全不尝试识别并排除不合作的节点?我怀疑这会带来麻烦,甚至可能遭受拒绝服务攻击。
Mmmm. I don't know if I'm comfortable with that. You're saying there's no effort to identify and exclude nodes that don't cooperate? I suspect this will lead to trouble and possible DOS attacks.
这里不依赖于识别任何人。正如你所说,这样做徒劳无功,很容易用马甲账号绕过。
There is no reliance on identifying anyone. As you've said, it's futile and can be trivially defeated with sock puppets.
证明某个参与者真实存在的凭据,是他能够提供 CPU 算力。
The credential that establishes someone as real is the ability to supply CPU power.
引用的来信Ray Dillinger来源 ↗直到……直到什么时候?谁能知道一笔交易何时变得不可撤销?“几个”区块是三个?三十个?一百个?这取决于节点数量吗?与节点数量呈对数关系还是线性关系?
Until.... until what? How does anybody know when a transaction has become irrevocable? Is "a few" blocks three? Thirty? A hundred? Does it depend on the number of nodes? Is it logarithmic or linear in number of nodes?
第 11 节计算了遭受攻击时的最坏情况。通常,5 或 10 个区块就足够了。如果你卖的东西不值得别人为了偷走它而发起全网规模的攻击,那么实际操作中可以把等待时间缩短一些。
Section 11 calculates the worst case under attack. Typically, 5 or 10 blocks is enough for that. If you're selling something that doesn't merit a network-scale attack to steal it, in practice you could cut it closer.
引用的来信Ray Dillinger来源 ↗但是,如果没有身份信息,只要他们已经拿到双重支付所换来的商品(网站访问权限、下载,或者别的东西),支付变得无效对他们就没有坏处。商家只能承担“无效”币的损失,除非先等待那神奇的“几个区块”(又怎么知道该等几个?),再认定付款人已经付款。
But in the absence of identity, there's no downside to them if spends become invalid, if they've already received the goods they double-spent for (access to website, download, whatever). The merchants are left holding the bag with "invalid" coins, unless they wait that magical "few blocks" (and how can they know how many?) before treating the spender as having paid.
如果消费者花了币后,需要一小时结清才能使用购买的东西,他们就不会这么做。如果商家发现收到的币因顾客双重支付而无效,却无法向顾客追收款项,商家也不会这么做。
The consumers won't do this if they spend their coin and it takes an hour to clear before they can do what they spent their coin on. The merchants won't do it if there's no way to charge back a customer when they find the that their coin is invalid because the customer has doublespent.
这是第 2 版要解决的问题,我相信对于大多数应用,都能找到相当令人满意的解决办法。
This is a version 2 problem that I believe can be solved fairly satisfactorily for most applications.
这里比的是谁先把交易传播到网络中。想想 6 个自由度——传播是指数式的。只需大约 2 分钟,交易就能传播得足够广,使迟一步开始的竞争交易几乎无法在第一笔交易覆盖全网之前抢到太多节点。在这 2 分钟里,商家的节点可以监测双重支付交易。双重支付者无法把替代交易发遍全球,却不让商家收到,所以他必须等待之后才能开始。
The race is to spread your transaction on the network first. Think 6 degrees of freedom -- it spreads exponentially. It would only take something like 2 minutes for a transaction to spread widely enough that a competitor starting late would have little chance of grabbing very many nodes before the first one is overtaking the whole network. During those 2 minutes, the merchant's nodes can be watching for a double-spent transaction. The double-spender would not be able to blast his alternate transaction out to the world without the merchant getting it, so he has to wait before starting.
如果真实交易到达了 90% 的节点,而双重支付交易到达了 10%,双重支付者就只有 10% 的概率不用付款,却有 90% 的概率花掉自己的钱。对于几乎任何商品,这都不值得骗子去做。
If the real transaction reaches 90% and the double-spent tx reaches 10%, the double-spender only gets a 10% chance of not paying, and 90% chance his money gets spent. For almost any type of goods, that's not going to be worth it for the scammer.
网站访问权限或下载这类信息商品无法销赃。没人能靠偷网站访问权限或下载来谋生。他们可以去文件共享网络盗取那些东西。大多数即时访问产品,都不会让人有很强的动机去偷。
Information based goods like access to website or downloads are non-fencible. Nobody is going to be able to make a living off stealing access to websites or downloads. They can go to the file sharing networks to steal that. Most instant-access products aren't going to have a huge incentive to steal.
如果商家确实遇到了盗取问题,可以让顾客等 2 分钟,或等待邮件中的某样东西,很多商家已经这么做了。如果他们真的想优化,而且是较大的下载,可以在交易被判定为双重支付时中途取消下载。如果是网站访问权限,通常先让顾客访问 5 分钟,等交易被拒绝后再切断访问,也不是什么大问题。反正很多这样的网站都有免费试用。
If a merchant actually has a problem with theft, they can make the customer wait 2 minutes, or wait for something in e-mail, which many already do. If they really want to optimize, and it's a large download, they could cancel the download in the middle if the transaction comes back double-spent. If it's website access, typically it wouldn't be a big deal to let the customer have access for 5 minutes and then cut off access if it's rejected. Many such sites have a free trial anyway.
Satoshi Nakamoto
Satoshi Nakamoto