5 ms·
Hi folks! I'm the Founder and CEO of the Zcash company. It's really great to have this much interest in a project that we just released in alpha "Technology Pre
by zooko-zcash 11y ago
Hi folks! I'm the Founder and CEO of the Zcash company. It's really great to have this much interest in a project that we just released in alpha "Technology Preview" form two weeks ago.
There are a lot of good questions in here, some of which I answered in an AMA a few days ago: https://forum.bitcoin.com/ama-ask-me-anything/i-m-zooko-wilcox-ceo-of-the-zcash-company-ask-me-anything-t5413.html https://forum.bitcoin.com/ama-ask-me-anything/i-m-zooko-wilc...
I can't wait to release the next iteration of the Zcash software, in — fingers crossed — just a couple of weeks. We'll continue to have lots of blog posts and technical discussions from us along the way. This is only the beginning!
- paragon_init 11y agoHi Zooko, Has there been any serious discussion about incorporating the results of PQCRYPTO in your protocol so Zcash is still secure and viable (at >= 2^128 security level) after the development of practical quantum computers? http://pqcrypto.eu.org http://pqcrypto.eu.org
- ianmiers 11y agoHi, I'm one of the ZCash scientists: Section 8.1 in the full paper describes how to get anonymity that survives quantum computers. (http://zerocash-project.org/media/pdf/zerocash-extended-20140518.pdf http://zerocash-project.org/media/pdf/zerocash-extended-2014...). The zero-knowledge proof itself offers statistical privacy in the face of unbounded (so more powerful than quantum) attackers. So surprisingly, you are mostly fine. But you would need to take two steps to protect yourself. First, you have to use each zcash address only once. Second, you need to use a post quantum secure means of notifying the recipient they got a transaction and of the coin commitment openings. The built in mechanism in ZCash, which posts a ciphertext to the blockchain encrypted under the recipients public key is standard off the shelf public key cryptography. It's efficient, but is of course not post quantum secure. Nothing requires that you use this mechanism, however. You can always post a garbage ciphertext and inform the recipient some other way.
- deleted 11y ago[deleted]
- omginternets 11y ago>Please, just tell me it's not premine. Why are you opposed to premining? (I had to look up the term, so I'm not baiting you! I don't see the problem, so I'd like to hear your thoughts).
- deleted 11y ago[deleted]
- kregasaurusrex 11y agoPremining devalues future work done on a cryptocurrency because the underlying idea is to decentralize money, and the coins found at the start of a blockchain are easier to generate because the target difficulty for finding a block is significantly lower. The most famous case of premining I can think of is https://en.wikipedia.org/wiki/Coinye https://en.wikipedia.org/wiki/Coinye (ltc clone), where people started mining it after dogecoin began. Dogecoin was in its first few weeks of release and had an extremely active number of miners; and was even more profitable to be mining than bitcoin at the time. There was speculation that having a celeb figure attached to a currency could bring the cryptocurrency movement mainstream; but when the block explorer for kanyecoin was released it was found that a very large number were premined by the developers, and few people considered it was worth dedicating mining time towards. The devs basically dumped all of their coins onto an exchange and abandoned the currency soon after. Premining is bad for building up a community of miners towards which an altcoin can be established for both trust and future earnings.
- MCRed 11y agoZcash gets %10 of the mined coins for the first 4 years and %1 goes to a foundation. This is their business model. It seems reasonable to me... using the currency you're creating to fund the development of the currency. If Zcash ends up worthless, then they won't have captured any value. Since it's not a pre-mine it's not subject to the pump-and-dump dynamics of a pre-mine... it will take 4 years and the coins will have to be valuable over those four years for them to net anything. It's a reasonable approach to aligning the companies interests with those of the users. I'd love to hear a better one though, if you know of one.
- swsieber 11y agoHi Zooko, There have been some concerns raised about your ability to do a pump-and-dump scheme. You mention on your funding page that you are incentivized to support it for at least 4 years due to the payout scheme. My question is, how can that statement be audited, since the transactions are anonymous. Is it built into the client then?