Bitcointalk · Bitcoin minting is thermodynamically perverse

中本聪,2010 年 8 月 7 日

SN-2130 已核对来源,附原文与上下文。

阅读语言
中文译文

这和黄金与挖金子的情形一样。挖金的边际成本总是倾向于贴近金价。挖金是浪费,但这种浪费远小于让黄金作为交换媒介可用所带来的效用。

我认为 Bitcoin 也会是同样的情形。Bitcoin 使交换成为可能所带来的效用,将远超其所耗电费。因而,没有 Bitcoin 才是净浪费。

总的来说,我也不认同「币生成的巨大计算负担是现行系统的必要代价」这种说法。据我理解,货币创造从根本上是以*时间*计量的——倘若那才是根本控制变量,那为什么每个人还需要在给定时间段内「掷尽可能多的骰子」?币所有权和交易的「证明链」并不依赖硬币的生成方式。

每个节点对网络的影响力与其 CPU 算力成正比。向网络证明你有多少 CPU 算力的唯一办法,就是实际使用它。

倘若每个人还有限量的其他什么东西,可以用来做一人一票,我想不出。IP 地址……比 CPU 容易大量获取得多。

我想在某些时间点测量 CPU 算力兴许是可能的。譬如,CPU 算力挑战只在每 10 分钟里平均运行 1 分钟。你仍然可以在给定时间点证明你的总算力,而不必一直运行。不过我不确定这怎么能实现。一个当时不在场的节点,没有办法知道过去这条链其实是在「穿插着歇 9 分钟」的占空比下生成的,而非连续不停。

工作证明有个很好的性质:它可以通过不可信的中介转发。我们不必担心通信的监管链。谁告诉你最长链的并不重要,工作证明自己会说话。

ORIGINAL · 英文原文
It's the same situation as gold and gold mining.  The marginal cost of gold mining tends to stay near the price of gold.  Gold mining is a waste, but that waste is far less than the utility of having gold available as a medium of exchange.

I think the case will be the same for Bitcoin.  The utility of the exchanges made possible by Bitcoin will far exceed the cost of electricity used.  Therefore, not having Bitcoin would be the net waste.

As an overall point, I also do not agree with the idea that the very high computational burden of coin generation is in fact a necessity of the current system. As I understand it, currency creation is fundamentally metered by TIME - and if that is the fundamental controlling variable, what is the need for everyone to "roll as many dice as posible" within that given time period? The "chain of proof" for coin ownership and transactions doesn't depend on the method for spawning coins.
Each node's influence on the network is proportional to its CPU power.  The only way to show the network how much CPU power you have is to actually use it.

If there's something else each person has a finite amount of that we could count for one-person-one-vote, I can't think of it.  IP addresses... much easier to get lots of them than CPUs.

I suppose it might be possible to measure CPU power at certain times.  For instance, if the CPU power challenge was only run for an average of 1 minute every 10 minutes.  You could still prove your total power at given times without running it all the time.  I'm not sure how that could be implemented though.  There's no way for a node that wasn't present at the time to know that a past chain was actually generated in a duty cycle with 9 minute breaks, not back to back.

Proof-of-work has the nice property that it can be relayed through untrusted middlemen.  We don't have to worry about a chain of custody of communication.  It doesn't matter who tells you a longest chain, the proof-of-work speaks for itself.
来源
Bitcointalk 原始链接 ↗ 记录编号 SN-2130