11 ms·
Bitcoin Users Reveal More Private Information Than They Realize
- NobleSir 11y agoShameless plug for Monero https://eprint.iacr.org/2015/1098.pdf https://eprint.iacr.org/2015/1098.pdf (ring ct author here) edit: See also https://github.com/shennoether/ringct https://github.com/shennoether/ringct and https://github.com/monero-project/bitmonero https://github.com/monero-project/bitmonero
- hybridsole 11y agoThank you for your contributions, NobleSir. I think out of all the cryptocurrencies, if there's one that will take real market share away from Bitcoin, it'll be Monero.
- NobleSir 11y agono problem - these things are quite interesting to me.
- moeadham 11y agoMonero definitely deserves more credit that it is currently given.
- sposer-kyle 11y agoNationalSecurity https://criticl.me/post/what-nsa-created-cryptonote-2292 https://criticl.me/post/what-nsa-created-cryptonote-2292
- ultramancool 11y agoWhat's next? Well, true anonymity via zero knowledge proofs of course. https://z.cash/ https://z.cash/
- knughit 11y agoDoes z.cash prevent deanonymization via IP traffic analysis? Does it resist clusterization?
- deleted 11y ago[deleted]
- CiPHPerCoder 11y agoNo, that's Tor's job.
- daira 10y agoIt's a bit more complicated than that. The main responsibility for implementing connection layer unlinkability lies with Tor (if you use Zcash over Tor, which we will aim to provide good support for), but how effective that is in resisting deanonymization attacks at that layer depends a great deal on the higher level protocol and its implementation. That's why it's recommended to use TorBrowser to browse the web anonymously; if you were to use a stock browser, then there would be numerous attacks that reduce the size of your anonymity set. We've tried to pay attention to minimizing leakage of information in the Zerocash protocol; you can read the numerous tickets on that here: https://github.com/zcash/zcash/issues?page=2&q=is%3Aissue+label%3Aanonymity https://github.com/zcash/zcash/issues?page=2&q=is%3Aissue+la... Also, note that even against an adversary that can observe all connection metadata, Zcash maintains strong unlinkability of which notes are involved in a private transaction.
- bduerst 11y agoIsn't 10% of mined zcash coins being skimmed by the founder?
- aminorex 11y agoYes. z.cash centralizes control under a corporation, which makes it vulnerable to legal process and political risk, and it is what is known in the crypto world as a "pre-mine scam".
- matt_wulfeck 11y agoFor privacy, this is one of those pesky places where having judicial law and oversight is useful. With laws you can control who can and can not use personal data. With fiat currency you get the good and the bad. With digital currency you get the good and the bad.
- djdkjehjehe 11y agoLOL Are you trolling? Because all those secret courts handing out secret gag orders really tell me that the law predicts privacy... Except that's not true at all. I can only assume you work for the government.
- halestock 11y agoHe didn't specify the US government, he just said "judicial law and oversights." Your attack is the equivalent of saying digital currencies are worthless because bitcoin has a security flaw.
- icebraining 11y agoIs there any government you would trust to keep your data from the NSA and similar organizations, though?
- raykyri 11y agoGoogle Cache, if anyone else is having trouble accessing Medium right now: https://webcache.googleusercontent.com/search?q=cache:rU5Ohf8AKUUJ:https://medium.com/bitaccess-inc/bitcoin-users-reveal-more-private-information-than-they-realize-d783f0cd57f3+&cd=1&hl=en&ct=clnk&gl=us https://webcache.googleusercontent.com/search?q=cache:rU5Ohf...
- LAMike 11y agoWhen SegWit is released in a few months, confidential transactions will be right around the corner
- ikeboy 11y agoThat only keeps the amount transferred private, not the addresses. Also, it has nothing to do with segwit, it was proposed well before segwit was a thing.
- joosters 11y agoEverything is around the corner in bitcoinland... Lightning networks, confidential transactions, improved performance, etc etc... It's a very crowded corner and it only seems to get more crowded!
- aminorex 11y agoBitcoin is a panopticon tool. That is why I use Monero instead.
- Sinergy 11y agoI hope everybody here knows about BitcoinFog, Shared Send, and other mixers. And uses them for random transactions now and then to give the rest of us plausible deniability.
- Taek 11y agoMost mixers introduce points of centralization, which allow a party to steal your coins or allow them to break privacy. JoinMarket is a good solution that works on Bitcoin today. Monero is a good altcoin which will automatically mix your coins using crypto. I believe it is more powerful than JM but requires using an altcoin. Zcash offers unmatched anonymity powered by fancy new crypto (less tested, less certainty on the security, but much more powerful). Still under development, but I'm guessing will be more ready in August.
- Sinergy 11y agoAssuming you are careless enough to use only one mixer for a transaction, they form points of centralization. Assuming no mixer reputation, they allow a party to steal your coins. Note that breaking a large transaction into small pieces allows you to determine a sort of short-term reputation while only risking one piece at a time. My standard first two steps used to be SharedCoin->BitcoinFog, for example.
- gnaritas 11y ago> Mixers A PC name for money launderers. If you need a money launderer, you should rethink what you're doing.
- AgentME 11y agoThey're not necessarily about hiding from the law. They can be used to get any privacy from the general public. All bitcoin transactions are publicly broadcast to everyone. Do you use a shower curtain specifically for hiding from the government?
- 11y ago
- feral 11y agoThis is a nice write-up. That said, I hope this is less of a surprise to people now: I coauthored one of the first pieces of working pointing out basically these same issues back in 2011 - almost 5 years ago: http://anonymity-in-bitcoin.blogspot.ie/2011/07/bitcoin-is-not-anonymous.html http://anonymity-in-bitcoin.blogspot.ie/2011/07/bitcoin-is-n... It's interesting to see what perceptions have changed. That there's still confusion shows how hard it is to disseminate information about encryption and privacy; maybe this the same reason e2e email encryption seems so difficult to get adopted, even decades after PGP: it's just hard to communicate about the bounds of privacy. One point: the 'clusterisation' mentioned in the linked article isn't 'magic': most of the techniques people are using are actually very simple heuristics, based on properties of the Bitcoin protocol (transaction input linking, which we demonstrated), or assumptions about transaction 'change' (prone to false positives). It's worth noting that there are more sophisticated tools that could be applied: machine learning or stats methods - but I've not seen them yet. Possibly because its hard to come up with good training datasets (unless you are a retainer or wallet?) and not worth investing in when simple methods show so much. But its worth bearing in mind that more complex analysis is possible. The overall conclusion being, IMO, that if you want privacy, it's probably usually easier to design it in from the start, rather than retrofit by progressively patching holes in a leaky system, against progressively better attacks: the latter is so hard to get to the point where it works solidly: for human reasons as much as technical ones; I think Bitcoin privacy seems destined to be an example of this.
- roel_v 11y ago"It's worth noting that there are more sophisticated tools that could be applied: machine learning or stats methods - but I've not seen them yet. Possibly because its hard to come up with good training datasets" I think it has more to do with those methods not being 'deterministic' for a broad interpretation of that word. By that I mean, if you're doing de-anonymizing for regulatory purposes, it's a hard sell to convince people 'these transactions are correlated because my neural net, which is a complete black box, says so'.
- natrius 11y agoMoney is a claim on value, and fungibility forces everyone to honor all claims on value. An incorruptible record of the flow of trade through an economy allows you to eliminate fungibility. You can withdraw your consent for people to trade claims on your production. This ability requires no one's permission and makes you more powerful as an individual. ISIS, for instance, can only hold territory because everyone accepts the claims on value that they give their foot soldiers. I want to stop honoring those claims to reduce their power. Manufacturers shift their carbon emissions to friendly jurisdictions instead of, you know, not risking our only home for cheap consumer goods. They do this to acquire more claims on value, and I don't want to honor those claims because I like Earth. Fungibility is literally killing people and destroying our planet. I think we'll be better off without it, though as with all significant social shifts, it probably needs more study to avoid unforeseen consequences like genocides and stuff. Blockchains are not anonymous—their incorruptible histories give us the tools to reshape our society. Use them.
- josu 11y ago>Fungibility is literally killing people and destroying our planet. (...) Blockchains are not anonymous—their incorruptible histories give us the tools to reshape our society. Use them. That's a slippery slope and you probably don't want to go down that road. Think of the power that would confer to a totalitarian state.
- natrius 11y agoTotalitarian states do just fine as it is. They use money to maintain their power. This might make totalitarian states impossible.
- kristofferR 11y agoI'm weirdly ambivalent about Bitcoin privacy/anonymity. On the one hand I deeply value my privacy, and would personally love it if Bitcoin were fully anonymous. Yet - I also deeply felt intuitively that the Panama Papers exposed bad behavior. The bad behavior it exposed were people aiming to archive financial privacy. I can't really reconcile the two beliefs.
- droffel 11y agoThere is currently an actively developed alternative cryptocurrency called Monero, that uses the 'Cryptonote Protocol', and has a completely different codebase from Bitcoin. It uses Ring Signatures and a few other cryptographic tricks to make the currency provably unlinkable and untraceable. In 6 months, the network will hard fork to support what is being called "RingCT", which will hide the amount sent in a transaction, in addition to the sender and the receiver that are hidden at the moment. If you want to read some more about it, ask all the questions you like on /r/monero, they'll be happy to get as technical as you want.
- kbart 11y agoYes. Fully anonymous digital currency and and widespread, legal usage is hard to imagine together. There's simply no way governments would allow that, so regulations of digital currencies is only a matter of time. Yes, I know that argument that "physical money is anonymous too", but that's not the same, physical money has physical constraint and you can't transfer huge amount of them around the world in a matter of seconds. Furthermore, a crackdown on real money has already started(1, 2 etc).. 1. http://www.euronews.com/2015/12/16/cash-losing-its-currency-sweden-prepares-to-bid-farewell-to-physical-money/ http://www.euronews.com/2015/12/16/cash-losing-its-currency-... 2. http://www.theguardian.com/world/2016/feb/08/german-plan-prohibit-large-5000-cash-transactions-fierce-resistance http://www.theguardian.com/world/2016/feb/08/german-plan-pro...
- abishekk92 11y agoI think Monero fits in nicely in such a scenario with its view key. They call it private, but optionally transparent. The regulators can ask to "view" a transaction.
- jacquesm 11y agoI have no illusions about my privacy when using bitcoin, and privacy is not the reason why I would use it in the first place. From what I gather the key to bitcoin always was that it was decentralized, not that it was private. And over time even the decentralized has been hollowed out quite a bit.
- martindale 11y agoTrue privacy is (probably) coming to Bitcoin in the form of Confidential Transactions [1], a new construction of Pedersen Commitments and Range Proofs, as combined with some number of other mechanisms (such as CoinJoin). [1]: https://www.elementsproject.org/elements/confidential-transactions https://www.elementsproject.org/elements/confidential-transa...
- jimlunard 11y agoBitcoin has full anonymity only when you know what you're doing. And it is hard for an average joe to maintain that. There are many other coins to choose from - Ethereum, Dash, Monero https://www.coingecko.com/en https://www.coingecko.com/en
- loourr 11y ago"This also means whenever a transaction has multiple input addresses, we can safely assume those addresses belong to the same wallet." This is not true. You can sign partial parts of a transaction and have M of N signatures. This is what mixing services are designed to do.
- throwaway2016a 11y agoNot to mention a great many transactions come from cloud wallets / exchanges with shared pools of addresses. However, if you are using a QT wallet it is probably generally true.