What Satoshi Did
coinscrum.com
coinscrum.com
Using plain numbers, I would explain it to a layperson like this:
The hash is number from 1 to 1,000,000 (actually, it's a lot larger and we are counting from zero, but you get the idea). You can't control how large or small the value is. If some people generate a hash of 10,000 or below, this means they had to try roughly 100 times, computing 100 hashes, until they found that one by chance. This is a "Proof of work". If you reduce the threshold from 10,000 to 5,000, people will have to compute on average 200 instead of 100 hashes. So the smaller the threshold, the more difficult the challenge is to solve.
On top of its simplicity, this explaination has the advantage that the statistics are pretty obvious and don't even contain exponentials or logarithms, which you would have to use when talking about strings and leading zeros.
Not to be blunt, yet after 100 attempts w/ 1% positive outcome, there is roughly 63.3% odds to actually succeed.
The less-than comparison is more fine-grained, while counting the number of leading zeros is just a nice approximation that is used for laymen explainations.
For example, if your threshold is 00001011, you will accept "00001010" but not "00001100", despite both having the same number of (four) leading zeros.
In truth there's probably only about twenty people on Earth who have the requisite skills, knowledge and obsessive personality to pull off what they did, and you'd think somebody like that would be well known in the security community. It should be EASY. But the mystery endures.
Furthermore, I think what's easy to miss in hindsight is that somebody with that knowledge would certainly be asking themselves how such a thing as a Bitcoin could ever have value. Certainly I know that if I'd been thinking about digital money at the time, I would have rejected the idea of Bitcoin as obviously infeasible because why would it ever have value? Whatever the required properties are for somebody to actually believe that something like Bitcoin could take off, they are in the political/social/economic domain and therefore unlikely to correlate much with being known in the security community.
And to top it all off, the mining arms-race inherent in Bitcoin requires an extreme amount of computing power. On the other hand, crypto researchers are always looking for protocols that are efficient to implement. In that sense, there is even an anti-correlation between being likely to invent Bitcoin and being well known in the security community.
You could easily imagine a Torvalds-Tanenbaum-style argument happening in the early days of Bitcoin between the inventor of Bitcoin and, say, DJB. The parallel is actually kind of eery ;)
It's stands to reason that the more boring answer is correct- that Satoshi is a group of people from the beginning working on the blockchain and the ideology behind it. This allows the Satoshi Group to engage in public discussion about the 'chain without the starry-eyed bullshit of celebrity appeasement.
As for Bitcoin itself, it is not nearly as complicated as people imagine. It certainly does not take anything like an expert in security to understand or implement. It is very clever, don't get me wrong, but it requires almost no understanding of cryptography. Any competent programmer could implement/devise it easily.
Also, when I was curious about who Satoshi might be, I looked at the source code and the initial development forum. Based on that, I can pretty much say with confidence that the people who are trying to find out who he is, haven't done so :-P Not that it says who he is, but let's just say that it narrows the field pretty well...
To be honest, the reason nobody knows who Satoshi is relates a lot more to the fact that nobody with the skills to find such a person is looking.
One person who understand economics, applied crypto, networking, etc is hard to find but 2-3 people who could work together would make the candidate pool much, much larger.
This is roughly true, although Nakamoto's original paper only proves this for the case where no single entity controls > 50% of the mining power in the network (weak incentive compatibility). Nakamoto argued it was also true for the case where a single entity controls > 50% of the mining power (strong incentive compatibility) but failed to prove this, instead providing a vague argument based on some difficult-to-prove assumptions.
For more information, including an interesting theoretical attack based on this idea, see http://www.jbonneau.com/doc/BFGKN14-bitcoin_bribery.pdf.
Good post though, well explained.
Every result on the first two pages points to this.
The fact that he's most likely a hoaxer supports the AFPs claim.