12 ms·
ZCash (formerly Zerocash/Zerocoin) technology preview
- milesf 11y agoNothing new here. Add it to the pile of hundreds of other altcoins. Why is this here? Feels like the pump-and-dump world of altcoins is being done here to pump up this post.
- droffel 11y ago10% of all mining rewards for the first 5 years go to the developers. The tech is certainly interesting, but the pseudo-premine makes me a little wary of putting any significant amount of money into it. Citation: https://z.cash/blog/funding.html https://z.cash/blog/funding.html (Check the "Founder's reward" section)
- sarciszewski 11y ago> Nothing new here. Add it to the pile of hundreds of other altcoins. It sounds to me like you don't understand the technology involved. To be fair, it's probably Greek to most people outside of crypto. How many of the other altcoins were based on zero-knowledge proofs or allowed for private transfers (with respect to the blockchain)? I'm not aware of any. I think that's something new and worth talking about. (EDIT: Snark was removed. Sorry dang.)
- dang 11y agoPlease don't be rude and confrontational when someone comments like the GP, even though they shouldn't have. Instead, respond with the information you clearly have and they (and the rest of us) don't. Then we all learn something.
- grubles 11y ago>allowed for private transfers Monero? https://getmonero.org/knowledge-base/moneropedia/ringsignatures https://getmonero.org/knowledge-base/moneropedia/ringsignatu... https://getmonero.org/knowledge-base/moneropedia/stealthaddress https://getmonero.org/knowledge-base/moneropedia/stealthaddr...
- dang 11y ago> Why is this here? Actually there's a precise answer to that. In yesterday's popular Keybase.io thread, the submitter (rdl) said "Along with Zcash, it is the most amazing crypto-engineering project I've seen in years." https://news.ycombinator.com/item?id=11037297 https://news.ycombinator.com/item?id=11037297 That was evidence the community might find it interesting, and the project hadn't had discussion on HN yet, so we invited an earlier submitter (malgorithms) to repost it. From there it received significant community interest. > Nothing new here. Add it to the pile Whoa, this is exactly what we ask commenters not to do when discussing new work on Hacker News. The ratio of dismissiveness to substance in your post is too high. Substantive criticism is fine, of course, but not this; it degrades the discussion. If you know something or have a genuine insight—including a critical one—you're more than welcome to share it. But "nothing new here", "add it to the pile", and "feels like" is far too weak to justify a dismissive swipe. A comment like this would be better phrased as the question, "What is new here?", in a spirit of curiosity not snark.
- vessenes 11y agoI can't speak to as to whether Zcash is a pump-and-dump particularly, but I do know a bit about financing the technology development behind blockchains, and it's difficult. If the code is open source, you risk a fork and loss of any intrinsic value. If you sell the coins, you risk SEC difficulties in the USA. If you premine, people complain that you premined. If your company controls the currency, you get forks when founders leave (e.g. Ripple/Stellar), and you have to build large compliance teams. In the end, though, blockchain tech needs SIGNIFICANTLY more technology development than it has had so far to develop its latent potential. I'm sure blockchain enthusiasts would be interested in your suggestions as to how to get development funded.
- bb88 11y ago> I can't speak to as to whether Zcash is a pump-and-dump particularly. Look at the founder's stake noted here: https://z.cash/blog/funding.html https://z.cash/blog/funding.html They get 20% of the mined coins off the top for the first 4 years, without doing any actual mining.
- DennisP 11y agoGiven that the coin hasn't launched yet, it can't be a pump-and-dump. Anyone who wants to profit that way has to pump after they obtain their coins, and it's not yet possible to obtain zcash coins.
- milesf 11y agoWell, I was wrong. I suppose when you see so many scams, you rely on instinct. But had I read more of the site, I would have realized that Zcash really is something different. So what did I do? I relied on Cunningham's Law: "the best way to get the right answer on the Internet is not to ask a question, it's to post the wrong answer." I rarely notice my karma score going up, but I certainly notice it when it goes down. That caused me to look at the comments and figure out why. So I learned something :)
- jerguismi 11y agoThere seems to be plenty of privacy-oriented altcoins around. How does the privacy model of zcash compare to others, like monero or dash?
- sarciszewski 11y agoI can't do an apples-apples comparison to the ones you listed because I'm only familiar with Bitcoin and the original Zerocash paper. I can say that the zkSNARK approach to crypto-currency is certainly novel and they have a great team of competent cryptographers and engineers on the team. That is to say, Zcash isn't a hobbyist effort, it's the result of serious crypto engineering. It's not clown-shoes privacy.
- jerguismi 11y agoOK so basically appeal to authority etc. Not much that a common guy can understand. Sounds to me like a product that is only designed for really smart people...
- sarciszewski 11y ago> OK so basically appeal to authority etc. No, I'm not making an appeal to authority. Sorry if it sounded like that. The team behind Zcash has serious technical chops, and it's worth pointing out that some of the most competent cryptographers and engineers in the world are working on this project. They've openly published the paper behind their protocol and their code base is open source. They aren't going the "trust us, we're kind of a big deal" route. If you want to understand, read the paper: http://zerocash-project.org/paper http://zerocash-project.org/paper ...and the source code: https://github.com/Electric-Coin-Company/zcash https://github.com/Electric-Coin-Company/zcash If you don't want to bother to understand (e.g. if you don't consider yourself a subset of "really smart people"), then you have to find some other metric to decide whether or not to trust it. I offered the backgrounds and reputations of the people involved as one possible heuristic, but feel free to choose another if you prefer.
- statoshi 11y ago
- vessenes 11y agoActually, zerocash is significantly different than other altcoins, in that it replaces digital signatures with zero knowledge proofs. It's technically very interesting, and seems like a believable next direction for Bitcoiners. The other direction would be some variant of ethereum. If you don't believe that a general purpose one-size-fits-all blockchain technology can be easily and safely created, but you would prefer more privacy and security, Zcash is a frankly compelling idea, and deserves a look. Monero uses a different scheme (ring signatures, essentially mixing in fake and real digital signatures) for privacy. To my knowledge, they don't duplicate the 'blinding' type of hiding about bucket recipients and ownership that zcash does. Note also that BIP47 and the like are trying to add some of these privacy features into Bitcoin core, so there's lots of angles on improved privacy.
- mootothemax 11y agoTwo questions I've yet to receive answers on: - my laptop is stolen in a compromised state (eg logged on, nothing left encrypted); can anyone trace my transactions? - I've read suggestions that Zcash themselves can deanonymize every transaction, thanks to generating the initial "Genesis" block. Is that roughly right? (Ignoring obfuscation techniques like getting many other people to create separate signatures) I'm definitely concerned that this comes with a lot of asterisks next to its claims.
- vessenes 11y ago1) Laptop stolen, unlocked, you never encrypted anything: yep, you're hosed as far as I know. How else would your wallet be able to tell you a balance? 2) The creation of the genesis block involves a trust 'game' of sorts, in which many participants are asked to pick a number. The statement from zcash, which a better cryptographer than me could verify, is that only one of the participants need be trustworthy in order to make this step safe. I think anyone can participate in the genesis block creation, so you may be just who they need to get the genesis block in good shape. :) On a different note, it would take a juvenile and short-sighted thinker to want to be able to deanonymize the transactions; not that those people don't exist, but most rational adults would not wish to be emotionally and personally liable in some way for knowing the identities of the money launderers, child pornographers and others who will undoubtedly be drawn to a technology like this.
- smaili 11y agoFor those of us who'd like to buy, which platform would be best? I'm only aware of Coinbase but they seem to be a Bitcoin-only exchange.
- jerguismi 11y agoThere isn't a live version yet, just testnet network. The real thing will come out 6 months later.
- bbatha 11y agoIts in beta right now and the current blockchain will be reset at 1.0 invalidating current coins. So buying in right now is pointless.
- milkey_mouse 11y agohttps://shapeshift.io/ https://shapeshift.io/ will probably have it once it's off the testnet.
- MCRed 11y agohttp://poloniex.com http://poloniex.com is a US based alt coin trading system.
- bb88 11y agoI wish someone would come up with a bitcoin alternative that isn't based upon speculation to get people interested in it.
- PierreRochard 11y agoWhy?
- bb88 11y agohttp://www.coindesk.com/bitcoin-price-15-network-failure-claims/ http://www.coindesk.com/bitcoin-price-15-network-failure-cla...
- DennisP 11y agoI don't see another way to bootstrap value in an unbacked unofficial currency. It's possible to back digital currencies by gold or something, but then we have counterparty risk and potential for shutdown by governments.
- swsieber 11y agoFor those of you concerned about pump and dump, they've specifically addressed it in a blog post [1]. And they are open sourcing a ton of stuff. But that's addressed in their blog. So to me, the lay man, it seems like they won't be doing a pump and dump. I say lay man because I'm really not qualified to assert that my statements are indeed correct. [1] https://z.cash/blog/funding.html https://z.cash/blog/funding.html
- bb88 11y agoFrom that link I see this: > With this approach, the founders are incentivized to support Zcash for the long haul (at least for four years), and they have limited ability to pump-and-dump. I don't see how anyone can audit that statement since the transactions are encrypted [1]. [1] https://z.cash/tech.html https://z.cash/tech.html
- jacobr1 11y ago> I don't see how anyone can audit that statement since the transactions are encrypted Couldn't one audit the code? Provided zcash itself doesn't have 51% or more of the mining network post launch the open source code should be verifiable and needs to have some special case to route the "founder reward". Though I admit I haven't looked through the source code so I may be missing something.
- davidsarah 11y agoMining rewards, and the proportion of them that goes to the Zcash company, are transparent (not encrypted).
- grubles 11y agoSo, what is to stop someone from forking the code and removing the percentages that go to the Zcash company and devs? Similar to how Monero was forked from Bytecoin due to some odd shadiness (not that I think Zcash and co. are shady!) [0]. [0]https://bitcointalk.org/index.php?topic=740112.0 https://bitcointalk.org/index.php?topic=740112.0
- jerguismi 11y ago
- zooko-zcash 11y agoHi folks! I'm the Founder and CEO of the Zcash company. It's really great to have this much interest in a project that we just released in alpha "Technology Preview" form two weeks ago. There are a lot of good questions in here, some of which I answered in an AMA a few days ago: https://forum.bitcoin.com/ama-ask-me-anything/i-m-zooko-wilcox-ceo-of-the-zcash-company-ask-me-anything-t5413.html https://forum.bitcoin.com/ama-ask-me-anything/i-m-zooko-wilc... I can't wait to release the next iteration of the Zcash software, in — fingers crossed — just a couple of weeks. We'll continue to have lots of blog posts and technical discussions from us along the way. This is only the beginning!
- paragon_init 11y agoHi Zooko, Has there been any serious discussion about incorporating the results of PQCRYPTO in your protocol so Zcash is still secure and viable (at >= 2^128 security level) after the development of practical quantum computers? http://pqcrypto.eu.org http://pqcrypto.eu.org
- ianmiers 11y agoHi, I'm one of the ZCash scientists: Section 8.1 in the full paper describes how to get anonymity that survives quantum computers. (http://zerocash-project.org/media/pdf/zerocash-extended-20140518.pdf http://zerocash-project.org/media/pdf/zerocash-extended-2014...). The zero-knowledge proof itself offers statistical privacy in the face of unbounded (so more powerful than quantum) attackers. So surprisingly, you are mostly fine. But you would need to take two steps to protect yourself. First, you have to use each zcash address only once. Second, you need to use a post quantum secure means of notifying the recipient they got a transaction and of the coin commitment openings. The built in mechanism in ZCash, which posts a ciphertext to the blockchain encrypted under the recipients public key is standard off the shelf public key cryptography. It's efficient, but is of course not post quantum secure. Nothing requires that you use this mechanism, however. You can always post a garbage ciphertext and inform the recipient some other way.
- deleted 11y ago[deleted]
- rrggrr 11y agoI hope I'm wrong, but if ZCash delivers on the technical promise the blowback from legislators and law enforcement is sure to result in a net loss of privacy for everyone. Enabling illegal profiteering from the very real pain and suffering of others almost always results in government actio (appropriately so); but also legislative over-reaching (eg. mandated sentencing legislations, zero tolerance policies, warrantless wiretapping) because ZCash's message of economic and societal benefits will be utterly lost amid stories of how the tech hurt people. ZCash is very impressive. Brilliant even. But for those who want better privacy... elect leaders who share the concern. Donate to the EFF and ACLU. Advocate for a 'privacy czar' as a cabinet/ministerial level position.
- deleted 11y ago[deleted]
- wcummings 11y agoI think many prefer non-violent direct action, for good reason. The cost to the government to spy on you is so low, cryptographically enforcing privacy is the only way to guarantee it.
- rrggrr 11y agoIf successful ZCash cryptographically guarantees more government regulation and surveillance to counter the very real and also the very irrational fears of harm anonymous payments make possible. It will have opposite the desired impact on privacy if it takes off. I want to be wrong about this, but experience tells me otherwise.
- DennisP 11y agoThe same could be said of strong encryption: if people use it, the government might crack down. On the other hand, the more people use encryption, the less useful mass surveillance will be to the government. When the government no longer gets much worthwhile information from eavesdropping, it may be easier to get politicians to put a halt to eavesdropping. So it could be that the best way to protect privacy is to use both technical and political approaches.
- oliv__ 11y agoWell, that is one cool domain.
- jessaustin 11y agoDefinitely! I wonder what a single-letter domain costs?
- GigabyteCoin 11y ago$1,118.00 USD, apparently. [0] [0] https://www.namecheap.com/domains/registration/results.aspx?domain=p.cash https://www.namecheap.com/domains/registration/results.aspx?...
- ebbv 11y agoCorrect me if I'm wrong but this is a for profit company telling me to use the currency, no commodity, they created and control in order to have privacy? How about I just stick to actual money?
- mangeletti 11y agoI don't think they will actually control anything, once it takes off; just like no single entity really controls Bitcoin.
- ebbv 11y ago> just like no single entity really controls Bitcoin. That's just not true. The core developers do control it. Look at the problems its having with the blockchain limit. Yes in theory anyone can fork it and people can run the fork, but that theory has now been tested and it failed. Similarly, if ZeroCash took off, the "official" devs would be the ones to control it. And they're a for profit company on top of it. I can't think of a worse idea than that. A commodity "currency" that is controlled entirely by a for profit company.
- mangeletti 11y agoYou mean like the US Dollar?
- natrius 11y ago> We believe that privacy strengthens social ties and social institutions, protects societies against their enemies, and helps societies to be more peaceful and more prosperous. It's time to have a serious conversation about whether this is actually true when it comes to financial privacy. Our society is governed by money. Money governs our production directly, and it governs our regulations indirectly since votes can be purchased. Governments derive their power from the consent of the governed, but we use money that doesn't allow us to withdraw our consent without opting out of the economy entirely. Your complaints about money in politics or unstoppable violent cartels around the world are complaints about tyranny, and we should be fighting that tyranny. Anonymous currencies go in the other direction. I'm glad people are building them, but we need to start talking about the implications of using them. Everything about our society will be decided by the people with the most money if people accept anonymous currencies. Democracy isn't possible when you can't hope to detect when influence is being purchased. We're already most of the way there: dollars are anonymous to everyone except the governments that regulate banks. Since those governments have been purchased, those regulations can only really be used against those who haven't already purchased strong representation in the government already. I think we need to go in the opposite direction. We need currencies that everyone can track so individuals can decide whose power they'd like to submit to. If I know someone is buying influence and I want to reject their power to do so, I can stop accepting any money they've used in that way. People accept money to influence politics because other people will accept that money. If other people stop accepting that money, it won't be possible to buy influence anymore. The people who sell their goods, services, and labor will set the rules by their decisions about what money to accept. Wealth won't govern our society, production will. This is merit capitalism. I think it's closer to the world we want to live in. I hope you'll join me in reconsidering whether financial privacy is actually a good thing. http://meritcapitalism.com/ http://meritcapitalism.com/
- Karunamon 11y agoThat's... actually a really interesting idea, but you have to consider who you're building the system for - governments, or normal everyday people? There is a principle, that I think has basically been proven at this point, if not academically: A: In any non-optional system used by n people, the bad actors using that system are < n/2 (read: not a majority) B: It is impossible to prevent bad actors from misusing any system. C: Trying too hard means the system necessarily damages good actors. Therefore: D: Any system that punishes bad participants more than it helps non-bad participants is degenerate. Bitcoin can be seen as a rejection of a system suffering from C. For perfectly legitimate businesses and people, sending money is an unmitigated pain in the ass, substantial bites taken by middlemen, arbitrary negative action (c.f. civil forfeiture, paypal freezes) and so on. Bitcoin solves almost all of those problems, but makes lives easier for the bad actors too (but not enough that it substantially increases corruption in the world - bad actors gonna bad act) Now, if your hypothetical system is strictly opt-in, perhaps with social pressure for politicians and such to use it, then I'd have no trouble with it. Were it to become the de facto currency, on the other hand, the problems we have with government overreach and data mining just become a lot worse. If we accept B as true, then it makes more sense to design for the case of innocent, law abiding people first, out of fear of harming them due to C. Put another way, I'm a lot more worried about government misusing things under color of law, than I am worried about government corruption. At least regular people can oppose the second one in good faith, while the first one always comes with the "it's legal, so?" baggage.
- jhasse 11y agoFor anyone interested in how Zcash (formely Zerocoin) works and who understands German, I've written my Bachelor thesis about it in 2013: http://www.math.uni-bremen.de/~jhasse/Kryptografische%20Grundlagen%20von%20Bitcoin.pdf http://www.math.uni-bremen.de/~jhasse/Kryptografische%20Grun... (see Part IV)
- davidsarah 11y agoNote that the Anonymity section of this describes Zerocoin. Zcash is an implementation of Zerocash which is a later and more efficient, but cryptographically quite different protocol (by the same and additional authors).
- jhasse 11y agoOh didn't know that! Thanks :) I thought that Zcash was just a new name ;)
- elorant 11y agoWe need to talk about the elephant in the room. A totally untraceable digital coin is gonna be Christmas for organized crime.
- sandstrom 11y agoCash and gold already exist. They are already celebrating Christmas, every day.
- dlsx 11y agoIt's not hard to create crypto currency, stop reporting this as news. These people are notoriously shady and hard to identify. Try my new magic money, it's going to be great. No seriously read this message outloud: "fuck you"
- aminok 11y agoWith it use BTC or have a new money supply, or both? Will it be launched as a Bitcoin sidechain, or are there any plans to make it one after launch?
- GigabyteCoin 11y agoZcash runs it's own blockchain. The original zerocash team approached the bitcoin developers over a year ago asking to integrate some of their ideas into the bitcoin blockchain and were turned down entirely. So they went underground and developed zcash. Zcash still seems to share quite a bit in common with bitcoin, however. For example, they are sticking with the 21,000,000 coin market cap.
- kanzure 11y agoHere's some stuff on zerocash: Zerocash: Decentralized anonymous payments from Bitcoin: http://diyhpl.us/~bryan/papers2/bitcoin/Zerocash:%20Decentralized%20anonymous%20payments%20from%20Bitcoin%20(extended%20version)%20-%202014-05-18.pdf http://diyhpl.us/~bryan/papers2/bitcoin/Zerocash:%20Decentra... Zerocoin: anonymous, distributed e-cash from bitcoin: http://diyhpl.us/~bryan/papers2/bitcoin/Zerocoin:%20anonymous%20distributed%20e-cash%20from%20bitcoin.pdf http://diyhpl.us/~bryan/papers2/bitcoin/Zerocoin:%20anonymou... How to explain zero knowledge protocols to other people's children: http://diyhpl.us/~bryan/papers2/bitcoin/snarks/How%20to%20explain%20zero%20knowledge%20protocols%20to%20other%20people's%20children.pdf http://diyhpl.us/~bryan/papers2/bitcoin/snarks/How%20to%20ex... GGPR paper, NIZKs without PCPs: http://diyhpl.us/~bryan/papers2/bitcoin/snarks/Quadratic%20span%20programs%20and%20succinct%20NIZKs%20without%20PCPs%20-%20GGPR.pdf http://diyhpl.us/~bryan/papers2/bitcoin/snarks/Quadratic%20s... Snarks for C: Verifying program execution succinctly and in zero knowledge: http://diyhpl.us/~bryan/papers2/bitcoin/snarks/SNARKs%20for%20C:%20Verifying%20program%20executions%20succinctly%20and%20in%20zero%20knowledge.pdf http://diyhpl.us/~bryan/papers2/bitcoin/snarks/SNARKs%20for%... Secure sampling of public parameters for succinct zero knowledge proofs: http://diyhpl.us/~bryan/papers2/bitcoin/snarks/Secure%20sampling%20of%20public%20parameters%20for%20succinct%20zero%20knowledge%20proofs.pdf http://diyhpl.us/~bryan/papers2/bitcoin/snarks/Secure%20samp... https://github.com/scipr-lab/libsnark https://github.com/scipr-lab/libsnark FWIW I think that confidential transactions and even SNARKs will eventually make their way into Bitcoin.
- meow_mix 11y agoIt bothers me that there are "investors" for this and a CEO. What happens if it takes off? There's one or two founders and a couple investors that essentially control the flow of money in the system. Bitcoin was appealing precisely because it lacked a center control. Is there something I'm missing here?
- AgentME 11y agoIf they're making a decentralized currency and things are sane, then the code is all open source, and their authority is only in developing the official client.
- dmix 11y agoNo links in the article but I found an ArchLinux AUR package for ZCash: https://aur.archlinux.org/packages/zcash-git/ https://aur.archlinux.org/packages/zcash-git/ Builds from source, pulling from Github.
- acd 11y agoHow can the state trace transactions as to collect tax on transactions made with Zcash? If the state cannot trace the transactions and this becomes black economy 2.0 then will it not face banning and seizure from the authorities? Ie how can we build roads and schools in a Zcash economy?
- erikpukinskis 11y agoHow does the state trace transactions made with paper cash?