Show HN: EtherPot – A decentralized, autonomous, provably fair lottery
etherpot.github.io
etherpot.github.io
1) The "random" selection of a winner seems to come from the modulo of the hash of a determinidtically selected block in the blockchain. How difficult would it be for someone to rig the lottery by simply waiting until the right moment and adding a block to the chain with a hash that would make them the winner?
2) Aside from the above, the "random" winning ticket index is not uniformly distributed unless the number of tickets is a power of 2, so there will be a significant bias in ticket selection.
Are these real shortcomings or am I misunderstanding something?
2. Not sure if I understand this. Can you expand on it a little more?
Here's an example {0..7} % 3 takes on the values 0,1,2,0,1,2,0,1. Notice that 0 and 1 appear 3 times but 2 only appears twice. So even if you chose x from a uniform distribution of the numbers 0-7, x % 3 would have a 3/8 chance of being 0 or 1, but only a 2/8 chance of being 2. This bias disappears only when the order of the set that's being randomly sampled is a multiple of the modulus. I hope that made sense.
So even assuming that the block hash is randomly distributed, you're still introducing a bias with the modulus. I think this might be fixable by simply multiplying the number of tickets everyone has by 2.
Edit: Strike that last part. If the number of tickets is not a power of 2, and the digest of the hash is a uniformly selected number from a set with a magnitude that is a power of 2, then there must be a bias in the winning ticket selection as it's performed in this code.
If my understanding is correct, the overall level of bias is extremely small ~(total#oftickets/2^256) but its definitely something to consider. The only way I see around it is to toss out a block if its hash is in a certain range, that way there are the same number of hashes for each ticket.
The solution I've seen done (at least in the Rust rand crate) is exactly what you say: throw out every hash >= 2^256 - (2^256 mod n). This ensures that the order of your sampling set is a multiple of n. I'm not sure how you could go about that in Ethereum but it may still be possible.
Imagine a lottery where instead of 2^256 there are only 100 possible outcomes and there are 3 players.
The odds are 34/100, 33/100, and 33/100 respectively. The bias is around 1/33.
But if I plug that scenario into your equation, I get:
2/(4+100%3) - (1/3) which is 2/5-1/3 which is 1/15.
100% of finds (except for transaction costs that go to miners) get returned to the users who play.
[1] https://en.wikipedia.org/wiki/Unlawful_Internet_Gambling_Enf...
I must check out Ethereum when I get chance.
It's a very difficult challenge to keep control of resource use in any such decentralized system, and even more of a challenge when scripts can loop. It's going to be interesting to see if Ethereum can eventually work without frequent human intervention to modify the code. Even Bitcoin didn't quite get to that state yet.
Each block they do not submit costs them the block reward (5 ether). The jackpot is split into subpots of 5 ether for this reason. Each subpot is decided on by a single blockhash. The incentive of the miners is to play honestly.
https://etherchain.org/account/0x539f2912831125c9b86451420bc...