5 ms·
This article neglects to mention Monero or Dash, the preexisting altcoins designed to be have anonymous transactions, or any existing shuffling tools like dark
by micimize 10y ago
This article neglects to mention Monero or Dash, the preexisting altcoins designed to be have anonymous transactions, or any existing shuffling tools like dark wallet.
I'm not an expert by any means, but this seems like a good compare/contrast that elucidates zcash's actual place in the space:
https://www.reddit.com/r/Monero/comments/41vg68/monero_vs_zcash_eli5_fundamental_differences/cz63pqw/ https://www.reddit.com/r/Monero/comments/41vg68/monero_vs_zc...
- ewillbefull 10y agoDisclosure: I am an engineer working on Zcash. Anonymity is not a binary. Monero, even with the addition of RingCT, is vulnerable to transaction graph analysis (intersection attacks) that can de-anonymize users. Zcash takes a completely different approach that achieves ledger indistinguishability -- shielded transactions in the blockchain have no apparent relationship with each other, which is an essential privacy benefit. Much of what I read in that thread is wrong or misleading: Monero does not have a trusted setup, but it's important to note that a failure in Zcash's setup does not disrupt the privacy of the system. The "poison-pill" vulnerability is not a concern in our system. The claims about the anonymity set are very misleading. It is possible to do far more than multi-sig in our system, we just haven't implemented it yet. The point about mining is specific to the paper and is irrelevant. There are downsides to the system, such as our performance problems, but they are solveable given time. Zcash is obviously not the only player, but it's also going to continue to grow and adapt and improve, just like other cryptocurrencies will.
- jb613 10y agoGiven free market indicators such as Bitcoin marketcap and the recent rise of Monero vs zcash - perhaps absolute privacy is not what the market values?
- grapevines 10y agoMonero, even with the addition of RingCT, is vulnerable to transaction graph analysis (intersection attacks) that can de-anonymize users. Your comment is highly misleading. RingCT solves 4 of the 5 remaining, known, privacy vulnerabilities in Monero ## The last remaining vulnerability has to do with transactions made with very little turnover, i.e. an amount is received and then immediately spent again. The privacy is stronger as the amounts are held in the wallet for longer. Monero is useable on a magnitude greater scale in 2017, and a full node can be run with small CPU and memory. Zcash on the other hand requires minutes to send anonymouse transactions. In other words, Zcash provides 100% privacy at the expense of scalability while Monero provides privacy approaching 100 percent as variable with time. ## http://monero.stackexchange.com/questions/1495/what-privacy-issues-did-monero-have-and-still-has http://monero.stackexchange.com/questions/1495/what-privacy-...
- ewillbefull 10y agoYou misread my comment. There _is_ an oustanding privacy issue in Monero, one that is often overlooked by its proponents. Transactions involving the same individuals will appear closer together in the transaction graph, and this remains the case so long as Monero's transactions have so few mixins. My favorite example of anonymity is Richard Stallman's description of an anonymous currency: you should be able to pay a publisher for every article you read on their website, without them being able to associate the payments.
- plasticmachine 10y agoYou can do that with Monero right now (within a cryptographically negligible, but plausibly deniable, risk) and it doesn't require crazy unreliable cryptography, a (badly done) trusted setup, or 8gb+ of RAM and 60 seconds on a Xeon.
- CiPHPerCoder 10y agoWhat exactly is "badly done" about their trusted setup?
- kbody 10y agoThe "trusted setup" is a permanent unfixable security hole. While it's partially secure in theory, it goes against the core value of Bitcoin and cryptography where you trust he math and not some person. It will be a constant cloud over Zcash. (I still see great academic value on the work behind Zcash with zkSNARKs, but as a cryptocurrency at the current state it's way too risky for real use)