Summary & Insights
Can a system remain reliable when some of its parts not only fail but actively behave maliciously? This central question drove the pioneering work of Turing Award winner Dr. Barbara Liskoff, whose research in the 1980s and 90s created the architectural blueprint for what we now know as blockchain. Long before cryptocurrencies existed, Liskoff was developing state machine replication and “view stamp replication” to ensure that distributed systems—like a shared file system—could continue functioning even if a primary node crashed.
The conversation highlights the evolution from handling “benign” failures (where a machine simply goes silent) to tackling “Byzantine” failures (where a node might lie or be compromised). Liskoff describes the shift to Practical Byzantine Fault Tolerance (PBFT) as entering a “funhouse of distorting mirrors,” where the system can no longer trust any single replica. By introducing certificates—proofs consisting of signed messages from a supermajority of nodes—Liskoff and her team bridged the gap between abstract theoretical computer science and practical, benchmarked systems.
Beyond the technical protocols, the discussion emphasizes a philosophy of “first principles” and modularity. Liskoff draws a compelling parallel between writing modular code and proving mathematical theorems, arguing that breaking complex problems into independent, verifiable lemmas is the only way to build large-scale, reliable software. As AI begins to automate the act of coding, she suggests that the future of computer science lies not in writing loops, but in high-level design, specification, and the rigorous verification of AI-generated output.
Surprising Insights
- The “Accidental” Foundation: Many of the core mechanisms used in modern blockchains were developed in the 1980s for simple file system replication, decades before the concept of a cryptocurrency existed.
- Parallel Discovery: Liskoff notes a historical “mutual lack of understanding” where her View Stamp Replication and Leslie Lamport’s Paxos were essentially the same protocol, yet the two parties didn’t realize it for years.
- The “Embarrassing Pause”: Early replication protocols suffered from a critical window of vulnerability where a failure of the primary node would bring the entire system to a complete halt.
- Theory vs. Benchmarks: While theoretical papers prove a system is possible, Liskoff observes that the community’s mind only truly changes when “good benchmarks” prove that a technology is actually usable in practice.
Practical Takeaways
- Think in Modules: Treat software architecture like a mathematical theorem. Break a system into small, independent modules with clear specifications so you can prove the correctness of each piece without needing to analyze the entire “blob.”
- Focus on Verification: In an era of AI-generated code, shift your skill set from “how to code” (syntax and loops) to “how to verify” (design, specification, and testing) to ensure AI output is actually correct.
- Study First Principles: To move the needle in research or engineering, identify the areas where your understanding is incomplete. The “gap” in your knowledge is usually where the most impactful insights are hiding.
- Separate Consensus from Execution: When designing distributed systems, maintain a strict separation between the layer that decides the order of events (the ledger/consensus) and the layer that executes those events (the application).
Liệu một hệ thống có thể duy trì sự tin cậy khi một vài thành phần của nó không chỉ bị lỗi mà còn chủ động hoạt động một cách độc hại? Câu hỏi trọng tâm này đã thúc đẩy những công trình tiên phong của Tiến sĩ Barbara Liskoff, người đoạt giải Turing, với những nghiên cứu trong thập niên 80 và 90 đã tạo ra bản thiết kế kiến trúc cho cái mà ngày nay chúng ta gọi là blockchain. Từ rất lâu trước khi tiền điện tử ra đời, Liskoff đã phát triển cơ chế sao chép máy trạng thái (state machine replication) và “sao chép dấu thời gian góc nhìn” (view stamp replication) để đảm bảo rằng các hệ thống phân tán — như một hệ thống tệp chia sẻ — vẫn có thể tiếp tục vận hành ngay cả khi nút chính (primary node) bị sập.
Cuộc hội thoại làm nổi bật sự tiến hóa từ việc xử lý các lỗi “lành tính” (khi một máy đơn thuần im lặng) sang giải quyết các lỗi “Byzantine” (khi một nút có thể nói dối hoặc bị xâm nhập). Liskoff mô tả sự chuyển dịch sang cơ chế Chịu lỗi Byzantine Thực tế (PBFT) giống như việc bước vào một “ngôi nhà gương biến dạng”, nơi hệ thống không còn có thể tin tưởng vào bất kỳ bản sao đơn lẻ nào. Bằng cách giới thiệu các chứng chỉ — những bằng chứng bao gồm các thông điệp được ký bởi một siêu đa số các nút — Liskoff và nhóm của bà đã thu hẹp khoảng cách giữa khoa học máy tính lý thuyết trừu tượng và các hệ thống thực tế, có điểm chuẩn (benchmark) cụ thể.
Vượt ra ngoài các giao thức kỹ thuật, cuộc thảo luận nhấn mạnh triết lý về “nguyên lý cơ bản” (first principles) và tính mô-đun. Liskoff đưa ra một sự tương đồng đầy thuyết phục giữa việc viết mã mô-đun và việc chứng minh các định lý toán học; bà lập luận rằng việc chia nhỏ các vấn đề phức tạp thành các bổ đề độc lập, có thể kiểm chứng được là cách duy nhất để xây dựng phần mềm quy mô lớn và đáng tin cậy. Khi AI bắt đầu tự động hóa việc lập trình, bà cho rằng tương lai của khoa học máy tính không nằm ở việc viết các vòng lặp, mà ở thiết kế cấp cao, đặc tả và kiểm tra nghiêm ngặt các kết quả do AI tạo ra.
Những góc nhìn bất ngờ
- Nền móng “tình cờ”: Nhiều cơ chế cốt lõi được sử dụng trong blockchain hiện đại đã được phát triển từ thập niên 80 cho việc sao chép hệ thống tệp đơn giản, nhiều thập kỷ trước khi khái niệm tiền điện tử tồn tại.
- Khám phá song song: Liskoff lưu ý về một sự “thiếu hiểu biết lẫn nhau” trong lịch sử, khi mà cơ chế View Stamp Replication của bà và Paxos của Leslie Lamport về cơ bản là cùng một giao thức, nhưng hai bên đã không nhận ra điều đó trong nhiều năm.
- “Khoảng lặng đáng ngại”: Các giao thức sao chép thời kỳ đầu gặp phải một kẽ hở nghiêm trọng về tính dễ bị tổn thương, nơi mà sự cố của nút chính sẽ khiến toàn bộ hệ thống dừng hoạt động hoàn toàn.
- Lý thuyết đối lập với Điểm chuẩn: Trong khi các bài báo lý thuyết chứng minh một hệ thống là có khả năng tồn tại, Liskoff quan sát thấy tư duy của cộng đồng chỉ thực sự thay đổi khi các “điểm chuẩn tốt” chứng minh rằng một công nghệ thực sự có thể sử dụng được trong thực tế.
Bài học thực tiễn
- Tư duy theo mô-đun: Hãy coi kiến trúc phần mềm như một định lý toán học. Chia hệ thống thành các mô-đun nhỏ, độc lập với đặc tả rõ ràng để bạn có thể chứng minh tính đúng đắn của từng phần mà không cần phân tích toàn bộ “khối” mã khổng lồ.
- Tập trung vào kiểm chứng: Trong kỷ nguyên mã nguồn do AI tạo ra, hãy chuyển đổi bộ kỹ năng từ “cách lập trình” (cú pháp và vòng lặp) sang “cách kiểm chứng” (thiết kế, đặc tả và thử nghiệm) để đảm bảo kết quả từ AI thực sự chính xác.
- Nghiên cứu các nguyên lý cơ bản: Để tạo ra bước đột phá trong nghiên cứu hoặc kỹ thuật, hãy xác định những lĩnh vực mà sự hiểu biết của bạn còn thiếu sót. “Khoảng trống” trong kiến thức thường là nơi ẩn chứa những hiểu biết sâu sắc và có tác động lớn nhất.
- Tách biệt sự đồng thuận và thực thi: Khi thiết kế các hệ thống phân tán, hãy duy trì sự tách biệt nghiêm ngặt giữa lớp quyết định thứ tự của các sự kiện (sổ cái/đồng thuận) và lớp thực thi các sự kiện đó (ứng dụng).
當系統中的某些部分不僅發生故障,甚至開始產生惡意行為時,該系統還能保持可靠嗎?這個核心問題驅動了圖靈獎得主 Barbara Liskoff 博士的開創性工作。她在 80 和 90 年代的研發,為我們今日所知的區塊鏈奠定了架構藍圖。早在加密貨幣出現之前,Liskoff 就致力於開發狀態機複製(state machine replication)和「視圖印記複製」(view stamp replication),以確保分散式系統(如共享檔案系統)即便在主節點崩潰時仍能持續運作。
這次對話強調了從處理「良性」(benign)故障(機器僅僅是停止回應)到應對「拜占庭」(Byzantine)故障(節點可能會撒謊或被入侵)的演進過程。Liskoff 將轉向「實用拜占庭容錯」(PBFT)的過程描述為進入了一個「充滿扭曲鏡子的迷宮」,在這種情況下,系統再也無法信任任何單一的副本。透過引入「憑證」(certificates)——即由絕大多數節點簽署的消息證明——Liskoff 和她的團隊彌合了抽象的理論電腦科學與實際且經過基準測試的系統之間的鴻溝。
除了技術協定之外,討論還強調了「第一原理」(first principles)和模組化(modularity)的哲學。Liskoff 將編寫模組化代碼與證明數學定理之間建立了一個令人信服的類比;她主張,將複雜問題分解為獨立且可驗證的引理(lemmas),是構建大規模可靠軟體的唯一方法。隨著 AI 開始自動化編碼過程,她認為電腦科學的未來不在於編寫迴路,而是在於高階設計、規格定義以及對 AI 生成輸出的嚴格驗證。
驚人洞見
- 「偶然」的基石: 許多現代區塊鏈所使用的核心機制,早在加密貨幣概念出現數十年前的 1980 年代,就為了簡單的檔案系統複製而開發。
- 平行發現: Liskoff 提到一段歷史性的「相互缺乏理解」:她的視圖印記複製(View Stamp Replication)與 Leslie Lamport 的 Paxos 本質上是相同的協定,但雙方多年來竟未意識到這一點。
- 「尷尬的停頓」: 早期的複製協定存在一個關鍵的脆弱窗口,一旦主節點失效,整個系統將陷入完全停擺。
- 理論 vs. 基準測試: Liskoff 觀察到,雖然理論論文可以證明一個系統是「可行」的,但唯有當「良好的基準測試」證明某項技術在實務中確實「可用」時,社群的觀念才會真正改變。
實務啟示
- 以模組化思考: 將軟體架構視為數學定理。將系統分解為具有清晰規格的小型獨立模組,這樣你就可以證明每個部分的正確性,而無需分析整個龐大的「代碼塊」。
- 專注於驗證: 在 AI 生成代碼的時代,將你的技能集從「如何編碼」(語法和迴路)轉移到「如何驗證」(設計、規格定義和測試),以確保 AI 的輸出確實正確。
- 研究第一原理: 若想在研究或工程領域取得突破,請找出你理解不足的領域。知識中的「缺口」通常正是最具影響力的洞見所在之處。
- 將共識與執行分離: 在設計分散式系統時,應在決定事件順序的層級(帳本/共識層)與執行這些事件的層級(應用層)之間保持嚴格的分離。
Un système peut-il rester fiable lorsque certaines de ses parties non seulement tombent en panne, mais se comportent activement de manière malveillante ? Cette question centrale a guidé les travaux pionniers de la Dr Barbara Liskoff, lauréate du prix Turing, dont les recherches dans les années 1980 et 90 ont créé le schéma architectural de ce que nous connaissons aujourd’hui sous le nom de blockchain. Bien avant l’existence des cryptomonnaies, Liskoff développait la réplication de machines à états et la « réplication par horodatage de vue » (view stamp replication) pour garantir que les systèmes distribués — comme un système de fichiers partagé — puissent continuer à fonctionner même en cas de panne d’un nœud primaire.
La conversation met en lumière l’évolution du traitement des pannes « bénignes » (où une machine devient simplement silencieuse) vers la gestion des pannes « byzantines » (où un nœud peut mentir ou être compromis). Liskoff décrit le passage à la Tolérance aux Pannes Byzantines Pratiques (PBFT) comme l’entrée dans une « fête foraine aux miroirs déformants », où le système ne peut plus faire confiance à aucune réplique individuelle. En introduisant des certificats — des preuves composées de messages signés par une supermajorité de nœuds — Liskoff et son équipe ont comblé le fossé entre l’informatique théorique abstraite et les systèmes pratiques et étalonnés.
Au-delà des protocoles techniques, la discussion souligne une philosophie basée sur les « principes fondamentaux » et la modularité. Liskoff établit un parallèle frappant entre l’écriture de code modulaire et la démonstration de théorèmes mathématiques, affirmant que la décomposition de problèmes complexes en lemmes indépendants et vérifiables est la seule façon de construire des logiciels fiables à grande échelle. Alors que l’IA commence à automatiser l’acte de coder, elle suggère que l’avenir de l’informatique ne réside pas dans l’écriture de boucles, mais dans la conception de haut niveau, la spécification et la vérification rigoureuse des résultats générés par l’IA.
Perspectives Surprenantes
- Le fondement « accidentel » : De nombreux mécanismes centraux utilisés dans les blockchains modernes ont été développés dans les années 1980 pour la simple réplication de systèmes de fichiers, des décennies avant que le concept de cryptomonnaie n’existe.
- Découverte parallèle : Liskoff note un « manque de compréhension mutuelle » historique où sa réplication par horodatage de vue et le protocole Paxos de Leslie Lamport étaient essentiellement le même protocole, sans que les deux parties ne s’en rendent compte pendant des années.
- La « pause embarrassante » : Les premiers protocoles de réplication souffraient d’une fenêtre de vulnérabilité critique où la défaillance du nœud primaire entraînait l’arrêt complet de l’ensemble du système.
- Théorie vs Benchmarks : Alors que les articles théoriques prouvent qu’un système est possible, Liskoff observe que l’opinion de la communauté ne change véritablement que lorsque de « bons benchmarks » prouvent qu’une technologie est réellement utilisable en pratique.
Leçons Pratiques
- Pensez en modules : Traitez l’architecture logicielle comme un théorème mathématique. Divisez un système en petits modules indépendants avec des spécifications claires, afin de pouvoir prouver l’exactitude de chaque pièce sans avoir à analyser l’ensemble du « bloc ».
- Concentrez-vous sur la vérification : À l’ère du code généré par l’IA, faites évoluer vos compétences du « comment coder » (syntaxe et boucles) vers le « comment vérifier » (conception, spécification et test) pour garantir que le résultat de l’IA est effectivement correct.
- Étudiez les principes fondamentaux : Pour faire progresser la recherche ou l’ingénierie, identifiez les domaines où votre compréhension est incomplète. Le « fossé » dans vos connaissances est généralement l’endroit où se cachent les idées les plus percutantes.
- Séparez le consensus de l’exécution : Lors de la conception de systèmes distribués, maintenez une séparation stricte entre la couche qui décide de l’ordre des événements (le registre/consensus) et la couche qui exécute ces événements (l’application).
Kann ein System zuverlässig bleiben, wenn einige seiner Teile nicht nur ausfallen, sondern sich aktiv bösartig verhalten? Diese zentrale Frage trieb die Pionierarbeit der Turing-Award-Preisträgerin Dr. Barbara Liskoff voran, deren Forschung in den 1980er und 90er Jahren den architektonischen Entwurf für das schuf, was wir heute als Blockchain kennen. Lange bevor es Kryptowährungen gab, entwickelte Liskoff die Zustandsmaschinen-Replikation („State Machine Replication“) und die „View Stamp Replication“, um sicherzustellen, dass verteilte Systeme – wie ein gemeinsames Dateisystem – auch dann weiter funktionieren konnten, wenn ein primärer Knoten abstürzte.
Das Gespräch beleuchtet die Entwicklung vom Umgang mit „gutartigen“ Fehlern (bei denen eine Maschine einfach verstummt) hin zur Bewältigung „byzantinischer“ Fehler (bei denen ein Knoten lügen kann oder kompromittiert wurde). Liskoff beschreibt den Übergang zur Practical Byzantine Fault Tolerance (PBFT) als den Eintritt in ein „Kabinett aus verzerrenden Spiegeln“, in dem das System keiner einzelnen Replika mehr vertrauen kann. Durch die Einführung von Zertifikaten – Beweisen, die aus signierten Nachrichten einer super-Mehrheit von Knoten bestehen – schlossen Liskoff und ihr Team die Lücke zwischen abstrakter theoretischer Informatik und praktischen, durch Benchmarks belegten Systemen.
Über die technischen Protokolle hinaus betont die Diskussion eine Philosophie der „Erstprinzipien“ (First Principles) und der Modularität. Liskoff zieht eine überzeugende Parallele zwischen dem Schreiben von modularem Code und dem Beweisen mathematischer Theoreme. Sie argumentiert, dass das Zerlegen komplexer Probleme in unabhängige, verifizierbare Lemmata der einzige Weg ist, um groß angelegte, zuverlässige Software zu entwickeln. Da KI beginnt, den Akt des Codierens zu automatisieren, legt sie nahe, dass die Zukunft der Informatik nicht im Schreiben von Schleifen liegt, sondern im High-Level-Design, in der Spezifikation und der strengen Verifizierung von KI-generierten Ergebnissen.
Überraschende Erkenntnisse
- Das „zufällige“ Fundament: Viele der Kernmechanismen, die in modernen Blockchains verwendet werden, wurden bereits in den 1980er Jahren für die einfache Replikation von Dateisystemen entwickelt – Jahrzehnte bevor das Konzept einer Kryptowährung existierte.
- Parallele Entdeckungen: Liskoff erwähnt ein historisches „gegenseitiges Unverständnis“, bei dem ihre View Stamp Replication und Leslie Lamports Paxos im Grunde dasselbe Protokoll waren, was beide Parteien jedoch jahrelang nicht bemerkten.
- Die „peinliche Pause“: Frühe Replikationsprotokolle litten unter einem kritischen Schwachstellenfenster, in dem der Ausfall des primären Knotens das gesamte System zum völligen Stillstand brachte.
- Theorie vs. Benchmarks: Während theoretische Arbeiten beweisen, dass ein System möglich ist, beobachtet Liskoff, dass sich die Meinung der Fachwelt erst dann wirklich ändert, wenn „gute Benchmarks“ belegen, dass eine Technologie in der Praxis tatsächlich brauchbar ist.
Praktische Lehren
- In Modulen denken: Behandeln Sie Softwarearchitektur wie ein mathematisches Theorem. Zerlegen Sie ein System in kleine, unabhängige Module mit klaren Spezifikationen, sodass Sie die Korrektheit jedes Teils beweisen können, ohne den gesamten „Datenklumpen“ analysieren zu müssen.
- Fokus auf Verifizierung: Verlagern Sie in Zeiten von KI-generiertem Code Ihr Skillset von „wie man codiert“ (Syntax und Schleifen) hin zu „wie man verifiziert“ (Design, Spezifikation und Testing), um sicherzustellen, dass die KI-Ergebnisse tatsächlich korrekt sind.
- Erstprinzipien studieren: Um in der Forschung oder im Engineering wirklich etwas zu bewegen, identifizieren Sie die Bereiche, in denen Ihr Verständnis lückenhaft ist. In dieser „Lücke“ Ihres Wissens verbergen sich meist die wirkungsvollsten Erkenntnisse.
- Konsens von Ausführung trennen: Behalten Sie beim Entwurf verteilter Systeme eine strikte Trennung zwischen der Ebene bei, die die Reihenfolge der Ereignisse festlegt (das Ledger/der Konsens), und der Ebene, die diese Ereignisse ausführt (die Anwendung).
The psychologist Daniel Kahneman — a Nobel laureate and the author of Thinking, Fast and Slow — recently died at age 90. Along with his collaborator Amos Tversky, he changed how we all think about decision-making. The journalist Michael Lewis told the Kahneman-Tversky story in a 2016 book called The Undoing Project. In this episode, Lewis explains why they had such a profound influence.
- SOURCE:
- Michael Lewis, writer.
- RESOURCES:
- The Undoing Project, by Michael Lewis (2016).
- Thinking, Fast and Slow, by Daniel Kahneman (2011).
- The Big Short: Inside the Doomsday Machine, by Michael Lewis (2010).
- Nudge: Improving Decisions About Health, Wealth, and Happiness, by Richard Thaler and Cass Sunstein (2009).
- Moneyball: The Art of Winning an Unfair Game, by Michael Lewis (2004).
- “Who’s On First,” by Richard Thaler and Cass Sunstein (New Republic, 2003).
- “The Framing of Decisions and the Psychology of Choice,” by Daniel Kahneman and Amos Tversky (Science, 1981).
- “Prospect Theory: An Analysis of Decision Under Risk,” by Daniel Kahneman and Amos Tversky (Econometrica, 1979).
- “Judgment under Uncertainty: Heuristics and Biases,” by Daniel Kahneman and Amos Tversky (Science, 1974).
- “Subjective Probability: A Judgment of Representativeness,” by Daniel Kahneman and Amos Tversky (Cognitive Psychology, 1972).
- EXTRAS:
- “Remembering Daniel Kahneman,” by People I (Mostly) Admire (2024).
- “Why Are People So Mad at Michael Lewis?” by Freakonomics Radio (2023).
- “Did Michael Lewis Just Get Lucky with ‘Moneyball’?” by Freakonomics Radio (2022).
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
