6 ms·
On Fungibility, Bitcoin, Monero and why ZCash is a bad idea
- deleted 10y ago[deleted]
- grondilu 10y agoI'm always surprised how people seem to focus on bitcoin's alleged anonymity. It was quite clear from the beginning that bitcoin is not completely anonymous, or rather that it is not more anonymous than internet itself is. Just as you don't have to give your name or a photocopy of your passport to register to a website, you don't have to do that either to use bitcoin. So to a degree it is anonymous, but only when compared to other payments systems like Paypal for instance. This relative anonymity is not what attracted the vast majority of bitcoin users anyway. It was more the idea of a public, decentralized ledger.
- ChemicalWarfare 10y ago>> it is not more anonymous than internet itself is It's less anonymous than that. Not a 100% accurate analogy but this would be similar to having your browsing history stored in a public location mapped to your IPs.
- sirsar 10y ago>> your browsing history stored in a public location mapped to your IPs. It's more anonymous than that. Most people can't change their IP, let alone generate a new IP address for every single page load.
- ChemicalWarfare 10y agolike I said, not the best analogy, but.... you can go through a proxy or reboot your cable modem for example and because your web site hits are not linked (contrary to blockchain txs linked back all the way to where you acquired the coins) - I'd argue that this would be more anonymous than BTC.
- grondilu 10y agoThere are no IPs in the blockchain, are there?
- wmf 10y agoNo, but there are third-party databases that try to track the first IP seen for each transaction.
- grondilu 10y agoWell you could do that with any packet on the network, couldn't you? It's not specific to bitcoin. The transaction itself has no IP either.
- wmf 10y agoP2P protocols like BitTorrent and Bitcoin are less private than client-server protocols. A random grad student in the Netherlands could track nearly every Bitcoin peer if they wanted to, but they can't track people posting to HN.
- ChemicalWarfare 10y agothere are btc addresses tied to your wallet (in my analogy this would be an IP address) mapped to transactions with a major kicker being that the coin involved in these transactions is traceable back to where you acquired it and then back to where it was mined in the first place. so my analogy is actually less 'severe' than the reality of the bitcoin setup.
- deleted 10y ago[deleted]
- ikken 10y agoThis is a very one-sided discussion which makes it seem like it was written by a person who wants Monero's value to rise. It doesn't mention any drawbacks of Monero - like poor scalability - that blocks it's wide adoption. There's also a good deal of FUD around Dash and Zcash, which has been quickly refuted on reddit [1]. Apart from that I liked this post and it shone some light on issues I wasn't aware of. [1] https://www.reddit.com/r/btc/comments/4nai1r/on_fungibility_bitcoin_monero_and_why_zcash_is_a/ https://www.reddit.com/r/btc/comments/4nai1r/on_fungibility_...
- plasticmachine 10y agoI read through that Reddit post. How has it been refuted, exactly? If anything, the criticisms are shown in even more stark contrast with unbalanced commenters hurling insults instead of addressing points that are raised. ZCash has a number of very real problems. The SMPC paper [1] (which is meant to fix the trusted setup issue) will result in 12.8gb of data PER PARTICIPANT. A new node seeking to verify the SMPC will not only have to download double- or triple-digit gigabytes of data, but will then spend several days verifying it. Incidentally, the SMPC paper's results were based on a monster Core i7 with tons of RAM, so let's not even get started on how much of a fail that will be on a consumer PC. Oh and then it's controlled by a CORPORATION! That gets paid taxes by the blockchain!!! If there was ever a way of handing the TLAs a central point of control, that's it. ZCash should never even attempt to exist right now, the cryptography is way, way too immature to attempt implementation that could result in people losing tons of money. One last thing I noticed is that the developers (especially Zooko) have no idea how cryptocurrency works. They need to be taken out back and put out their misery for attempting idiotic shit like this: https://github.com/zcash/zcash/issues/713 https://github.com/zcash/zcash/issues/713 As for Dash, the participants on Hacker News are not your run-of-the-mill idiots. Surely you're not stupid enough to think that Dash is decentralized, with a small cluster of masternodes mostly owned by one guy (Otoh)? Cmon, nobody in their right mind believes that except pumpers and MLM idiots. [1] https://ieee-security.org/TC/SP2015/papers-archived/6949a287.pdf https://ieee-security.org/TC/SP2015/papers-archived/6949a287...
- petertodd 10y agoNote that Monero's scalability problem also exists in Zcash - an indefinitely growing list of spent tokens; if scalability is a drawback of Monero it's a drawback for Zcash.
- Olscore 10y agoIn practice, many of the gatekeepers to the layman using Bitcoin require so much documentation that anonymity should not be a major selling point. Perhaps you can acquire a few thousands USD worth that is anonymous, but trying to scale that anonymity doesn't go easily. Ironically, the needlessly growing inquisition into how I was using Bitcoin is what forced me to close my Coinbase account. They pretty much require the same information as a bank does, including photocopies of your state ID, even tax documents. Having used a handful of the exchanges and other more casual wallets like Circle, it's obvious that the trend is towards more "security" and legitimacy by vetting users and knowing their real world identities, etc. Which can include Skype interview, scanning personal bills to prove addresses and so forth.
- PeterisP 10y agoThis is not really specific to Bitcoin, but to any player/system that is going to become popular and thus used/supported by companies and/or integrated with the rest of global infrastructure. The laws in almost everywhere (except niche jurisdictions that treat holding offshore accounts as their main industry) pretty much require you to know your customer and not be an enabler of any anonymous transfers of money - or alternatively, be treated as responsible for any "bad" money passing through you. Any institution that would enable you to trade a scalable amount of USD for Monero or some new cryptopayment solution would also have to require the same information to know your real world identity. Any institution that would enable you to trade a significant amount of such new cryptocurrency for USD would be required (perhaps not immediately, but definitely if/when it becomes sufficiently popular) to report that to IRS, who would then request documentation about the transactions and originators where you obtained that amount (which you surely reported when filing your taxes, didn't you?), and it doesn't really matter that much that the blockchain is anonymous since essentially you'll give them the transaction details anyway or go to jail. If no institutions enable that, then the cryptocurrency cannot be liquid enough for everyday use, as it's not easy to trade it with other liquid currencies.
- mindslight 10y agoA major feature of untraceability is that exchanges can know your identity in this way, yet your transactions still remain confidential.
- SakiWatanabe 10y agoSounds like a Monero pump to me
- plasticmachine 10y agoThis is an utterly stupid comment. If you read an article that slammed MongoDB's eventual consistency and encouraged people to use mysql instead would you call it a "mysql pump? This is also not the first time someone has smacked down ZCash for being ill-conceived and dangerous: https://blog.okturtles.com/2016/03/the-zcash-catch/ https://blog.okturtles.com/2016/03/the-zcash-catch/
- dang 10y agoYour comments in this thread are unfortunately breaking the HN guidelines, by calling names and generally being uncivil. Please don't present your argument that way. It poisons the atmosphere and makes your argument less credible. Instead, please refresh your memory about what HN is looking for by reading the following, and then post civilly and substantively (or not at all) in the future. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newswelcome.html https://news.ycombinator.com/newswelcome.html
- plasticmachine 10y agoThat's fair enough, but consider that SakiWatanabe's comment is equally uncivil and insulting to an open-source project and the contributors that have built it. Why is that allowed, but when I call that person out I get SJW safe-space thrown at me? Don't you think that is hypocritical as a moderation strategy?
- dang 10y agoI didn't notice that comment. It's bad because it's a shallow dismissal, but yours were worse because you called names and conducted yourself flamewar-style, and you did it repeatedly in the thread. I don't think it's hypocritical, for a couple reasons: (1) it's impossible for us to read all the comments, and (2) one bad comment doesn't justify another. HN is not a good place to "call that person out"—that just causes threads to degenerate nastily. On HN, an appropriate way to respond to such a comment might be to remind the commenter that unsubstantive dismissals aren't helpful, and then point out some relevant good things about the article.
- ChemicalWarfare 10y agoGood read till the "Enter Monero" line :) I'd also mention that bitcoin had a BIP at some point to add stealth address support to the core (BIP63) with a couple of wallets providing support for those.
- plasticmachine 10y agoStealth addresses aren't nearly enough. It needs to be mandatory stealth addresses + some sort of mandatory passive mixing that can't be Sybil attacked + Confidential Transactions. At a minimum.
- petertodd 10y agoYup, Stealth Addresses are just a small fix to one usecase, not a general solution. And I say this as the guy who came up with the name and played a part in developing the exact protocol Dark Wallet implemented (many others deserve credit, including for the underlying math).
- ChemicalWarfare 10y agoJust mentioned those since the OP's article is talking about monero using stealth addresses but doesn't mention these when talking about bitcoin. SX and DarkWallet was what kind of pulled me personally into the bitcoin "ecosystem", very entertaining read trying to understand all of that :)
- cloudjacker 10y agoI typically start talking about the cryptonote protocol as a solution and then mention Monero as the primary implementation Monero has existed for the entire two years that Zerocash has been whitepaper vaporware, and it works really well.
- CiPHPerCoder 10y ago> Another problem with ZCash is the fact that it’s brand new cryptography. It's using libsodium. This is an alarmist and false statement. > Nobody can really guarantee that there aren’t some bugs in the system that will make it possible to deanonymize transactions or create coins out of thin air. Sure, that's technically true of all crypto-currencies.
- plasticmachine 10y agoYou can't be serious. It's using libsodium in one part of the code, so therefore ALL cryptography uses libsodium? You do know that Bitcoin has already switched most of the secp256k1 stuff away from OpenSSL and to libsecp256k1, and ZCash will follow suit? But more importantly than that it uses libsnark for the actual clever bits, which has already been critically broken[1] precisely because it is so new and poorly tested. Even the cryptography in ZeroCash/ZeroCoin is too new to be trusted with a financial system. That is not alarmist, that is practical. Relying on old, established cryptography is precisely why Bitcoin hasn't been trivially broken, and the zk-snarks cryptography will need to go through the same peer-review and refinement process over the next decade or two. [1] https://leastauthority.com/blog/a_bug_in_libsnark.html https://leastauthority.com/blog/a_bug_in_libsnark.html
- __jal 10y agoNot to pile on (the other response is dead on), but you also seem to be assuming that libsodium is magic crypto dust, offering strong security anywhere you sprinkle it. It isn't. To be sure, libsodium is shiny and nifty and wonderful, but the root cause of a large number of crypto insecurities is in key management. A bunch of others can be regarded as subtle mistakes in using an otherwise solid algorithm. Assuming that using a trusted implementation of a trusted algorithm means your crypto is solid is roughly like saying, "my car as airbags, so it is safe."
- NobleSir 10y ago> It's using libsodium. This is an alarmist and false statement. Really? Does libsodium support pairing base cryptography? https://github.com/zcash/zcash/issues/714#issuecomment-216910906 https://github.com/zcash/zcash/issues/714#issuecomment-21691...
- VMG 10y agoThe navigation header effect is infuriating.