3 ms·
http://cstheory.stackexchange.com/questions/11722/a-lottery-that-you-can-be-convinced-that-it-is-fair http://cstheory.stackexchange.com/questions/11722/a-lotter
by grimtrigger 13y ago
http://cstheory.stackexchange.com/questions/11722/a-lottery-that-you-can-be-convinced-that-it-is-fair http://cstheory.stackexchange.com/questions/11722/a-lottery-...
- Prefinem 13y agoIf I could prove the fairness (paying out to the winner) without compromising anything, I would. If you know of a way, I would be more than willing to do so.
- slig 13y agoI'm not an expert, but the way satoshidice.com does verification seems legit. Anyone here can verify that?
- mcherm 13y agoHere is a simple algorithm that gives you the basic ideas. A different bitcoin wallet is set up for each day's lottery. The total number of bitcoins received can be seen in the blockchain. A source of entropy is chosen which can easily be verified but cannot be controlled or predicted before a date after the cutoff for that day's lottery, for instance, use the NYSE stock market closing price. A hash of that is divided by the number of bitcoins received in the lottery (plus an overhead for the small percentage that funds running the lottery) to determine the winner. Anyone entering can confirm that that their contribution was a certain percentage of the total funds received and that they had that same percentage of the chance for winning: even if the operator of the lottery wanted to be malicious they couldn't do so without making it obvious to anyone who checked. There are some additional details that would matter, if you wanted to implement this seriously you may contact me separately for a discussion of some of those details.
- Prefinem 13y agoI already have some of this implemented but, picking a random winner based off of an outside source (provable by providing the algorithm) is only trust worthy if you trust the author posting the correct algorithm. You would still have to trust that I was using the code I said I was using. I may be understanding you wrong, and if I am please let me know. I would love to make this 100% fullproof and trustworthy.
- mcherm 13y agoPublish the algorithm. Anyone who wants to check can run it themselves! For this to work, ALL of the data needed to run the algorithm and determine the winner must be data that is outside the control of the contest organizer (or published before the contest begins) and publicly available. The algorithm I described should meet this criteria. Assume you have published (before the contest starts) that the lottery itself takes a 1% cut, and that all funds should be deposited to a particular Bitcoin wallet. Anyone who is suspicious of you (or just very careful) can inspect the blockchain to see the total number of bitcoins received before the contest cutoff time (call it "N"). They can find the closing price of the NYSE and run it through the hash function to find the random input (call it "R"). Then they can perform "X = (N mod R)" and count through the transactions until they find the one that added the "X'th" bitcoin to the wallet. If that was their transaction then they know to expect to receive "0.99*N" bitcoins. Like I said before, for rigorous use, the algorithm needs some details and a little improvement, but this demonstrates the existence of algorithms that allow any participant in the lottery can verify that the lottery is fair.