16 ms·
Keybase chooses Zcash
- CiPHPerCoder 10y agoI like Zcash. I think it's a good solution to a problem that Bitcoin did not solve, and creates a cryptocurrency more in line with the vision spelled out in A Cyperpunk's Manifesto than the previous attempts. (Yes, I've looked at the other attempts to build a private alternative to Bitcoin, including Monero: https://github.com/monero-project/monero/issues/1271 https://github.com/monero-project/monero/issues/1271)
- blueprint 10y ago…
- deleted 10y ago[deleted]
- Ar-Curunir 10y agoYour links have nothing to do with ZCash. ZCoin is a separate currency that is not related to ZCash. Before wondering why you're getting doenvoted, try to make sure that you're not saying incorrect things.
- deleted 10y ago[deleted]
- exstudent2 10y agozcoin is not zcash: https://forum.z.cash/t/psa-zcoin-is-not-zcash/1821 https://forum.z.cash/t/psa-zcoin-is-not-zcash/1821
- Bombthecat 10y agoJust another cash grab. I'm every time amazed that it still works.
- alvarosm 10y agoLook around this thread's comments, they're all taken in
- elif 10y agoYeah, but proof that (Beyond the 10% pre-mine) more ZEC are not being secretly generated for the creators relies upon trust in a cabal of six individuals based upon a "public" exhibition of genesis involving theatrical destruction of computers (whose video was supposed to be published but I can't find?) Even if they are 100% legitimate actors, the lack of absolute proof undermines the provenance. From my perspective, Zcash is technically a Fiat currency without the clout of a state backer. I'm sticking to bitcoin and ethereum :)
- CiPHPerCoder 10y agoWhat would you have done differently to solve the same problem they did?
- elif 10y agoIf I could come up with something better, they would have done that. Absence of a better solution does not imply any fitness of the proposed solution. Until such time that someone comes up with a better idea, I am sticking to public blockchains.
- CiPHPerCoder 10y ago> If I could come up with something better, they would have done that. Don't give up so easily! If you're going to make a stance borne out of principle, why not follow through to outperform the suboptimal solution that you dislike so much? Innovate. Put some skin in the game. That's what I would do, anyway. As it stands: If any of the folks involved in the trusted setup was honest, then it's secure. It takes a 100% corruption to make it insecure. I think that's acceptable until a better solution is proposed.
- pablovidal85 10y agoWhy such a small group of people though?
- 10y ago
- plasticmachine 10y agoLinking to that GitHub issue is pretty embarrassing for you. Not only can it not be practically exploited, per the author of that issue, but it looks like it's just using Keccak as a stream cipher of sorts (but seeding it from /dev/urandom). That's pretty ok, and if we don't trust stream ciphers to produce pseudorandom numbers we have much bigger issues. But more importantly, the contributors acknowledged the issue, and are fixing it. Do you honestly expect bug free open-source development? No, and the entire benefit of it being a welcoming open-source development community (instead of ZCash's centralised development team) is that it is made better by many eyes. Hopefully the OP that opened that issue spends some more time reviewing the code along with the 160+ Monero contributors. Also, if we're going to view lapses like these as representative of a major failure, you'd best review some of ZCash's greatest hits, maybe starting with the fact that wallet encryption is ENTIRELY DISABLED in ZCash, and your wallets are stored in the clear and ready for malware to steal: https://github.com/zcash/zcash/issues/1552 https://github.com/zcash/zcash/issues/1552 - https://github.com/zcash/zcash/issues/713 https://github.com/zcash/zcash/issues/713 <- this one is particularly stupid, and shows a gross misunderstanding of how Bitcoin works - https://github.com/zcash/zcash/issues/1304 https://github.com/zcash/zcash/issues/1304 - https://github.com/zcash/zcash/issues/1522 https://github.com/zcash/zcash/issues/1522 - https://github.com/zcash/zcash/issues/1779 https://github.com/zcash/zcash/issues/1779 <- literally, they had ONE JOB for the release, how did they fail at that? - https://github.com/zcash/zcash/commit/f8ada2435bd3f6b7a1165eae5fdfd6ac8a96f018 https://github.com/zcash/zcash/commit/f8ada2435bd3f6b7a1165e... <- oh that's right, they failed at the one thing they had to do because they were focused on other...uhhh...important stuff And let's not forget the massive attack surface that ZCash has, which leads to fun things like this: - https://github.com/zcash/zcash/issues/98 https://github.com/zcash/zcash/issues/98 - https://github.com/zcash/zcash/issues/178 https://github.com/zcash/zcash/issues/178
- CiPHPerCoder 10y ago> it looks like it's just using Keccak as a stream cipher of sorts (but seeding it from /dev/urandom). That's pretty ok, and if we don't trust stream ciphers to produce pseudorandom numbers we have much bigger issues. I very strongly disagree with userspace RNGs being used instead of the kernel's CSPRNG being "pretty ok". Don't "seed a userspace RNG from urandom". Just use urandom.
- xiphias 10y agoI'm not that much into zcash, but this is cool: https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trusted-setup-ceremony https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trust...
- mtgx 10y agoSince Zcash uses the same codebase of Bitcoin, does that mean it would be possible to later integrate it back into Bitcoin, and just transition Zcash T-addresses to regular Bitcoin addresses, and then add the Z-addresses on top of the Bitcoin addresses ecosystem? I also wonder about how much of a risk to its own ecosystem Zcash being a private company represents. Was that really better than making it a non-profit? And won't this make it easier for law enforcement to go after Zcash as the sole culpable entity for "money laundering" and other such charges?
- Ar-Curunir 10y agoNo, most likely not. ZCash shielded transactions have completely different structure to normal BTC ones.
- petertodd 10y agoNah, they're just extra data, that could easily go in the signature fields; it's definitely possible to add Zcash functionality to Bitcoin in a backwards compatible soft-fork. Basically you'd have a pool of "shielded" txouts that could be spent with a zcash signature, without any requirement that a particular txout be spent for a given signature. Surpisingly easy upgrade all things considered; the main blocker is Zcash's crypto is very experimental and slow.
- speps 10y ago> HN users: those PM'ing me for an invitation.... in the FAQ there is a temp code to skip the queue. We'll turn that code off in a day or two. > use the invitation code "zcash" during signup
- alvarosm 10y agoYou need a ton of space and/or processing power for the zero-knowledge transactions. The anonymity isn't free! In practice Zcash/zcoin (different tradeoffs) are of no use to you unless you are willing to go the extra mile to hide something (criminal activities and such). There's no point in paying for the extra effort for normal transactions.
- detaro 10y agoHow large is the overhead in numbers? I tried to search but didn't find any clear examples. EDIT: found some data in the ceremony report linked elsewhere in this discussion: https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trusted-setup-ceremony#scale-and-scalability https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trust...
- petertodd 10y agoSending takes a few minutes of computation on your wallet - but that's not such a big deal as it's comparable to the time it takes for block confirmations anyway. The problem is verification of private transactions is very slow by cryptocoin standards, and verification is something that every full node and miner must do. Zcash would fail if private transactions were used in large numbers, as blocks would take too long to validate for mining to remain decentralized; Bitcoin transactions are a few orders of magnitude faster to validate, with a 4x more conservative block interval and 2x smaller blocksize, and the Bitcoin dev community has had to make heroic efforts to further optimize validation.
- daira 10y agoThere are ways to significantly reduce the cost of zk proof verification by batching (that are compatible with the existing Zcash protocol without a fork).
- petertodd 10y agoProve it first by actually implementing those ways and having them survive peer review; this is highly experimental crypto so it's not clear what's actually possible. Again, I don't think it's very responsible to knowingly release design a protocol that in its current form would collapse if heavily used due to a lack of safety limits.
- kneel 10y agohttps://z.cash/blog/funding.html https://z.cash/blog/funding.html ctrl-f 'founders reward'
- exstudent2 10y ago"After the first four years the ZEC created per ten minutes will drop to 25ⓩ, but after the first four years, 100% of it goes to the miners." Seems like a good business model and a way to fund the innovation they've created.
- brilliantcode 10y agoConsider that after by end of this month there will be 200,000 ZEC released following every month with 20% going to the founder's coffers after 4 years. Extreme inflation will continue sending prices crashing. Recall early this month prices were hovering around 2 Ferrari 458 and now it's tanked to under a 100 dollars. If we were to assume that in 48 months X 200,000 ZEC = ~100,000,000 ZEC with 20,000,000 ZEC belonging to the Founders. edit: why the downvotes? I'm just reporting the facts: https://twitter.com/TommyEconomics/status/793435785097646081?s=09 https://twitter.com/TommyEconomics/status/793435785097646081...
- exstudent2 10y agoPrices were very high on day one due to an extremely limited supply and a lot of (warranted) attention. They've since normalized.
- elif 10y agoZEC is currently down 14.24% on the day. 8 days ago, Daily volume exceeded the market cap. I don't think that qualifies as normalized by most standards. [0] https://coinmarketcap.com/currencies/zcash/ https://coinmarketcap.com/currencies/zcash/
- Animats 10y ago"Normalized" is spin control. "Screaming dive" is more like it. From $6000 to $92 in a month, and dropping about 10% per day. Zcash is on its way to joining the other 700 dead and dying altcoins. Right now, it's the 43rd most valuable altcoin, and dropping in rank. Mining is generating Zcash way too fast for the market to absorb. The "market cap" has been holding steady as the priced dropped over 99%.
- gtlondon 10y agoTo be fair to ZCash, the high prices at launch were primarily due to very limited supply and market manipulation. The "screaming dive" is really just heading towards a sustainable price. Somewhere between $2-$10 is a more realistic valuation (based on other coin valuations) -- it will be interesting to see if the price stabilises once within this range.
- Walkman 10y agoSome invitation codes for keybase: https://keybase.io/inv/81ae92fb55 https://keybase.io/inv/81ae92fb55 https://keybase.io/inv/1405ab98be https://keybase.io/inv/1405ab98be https://keybase.io/inv/841bcaf887 https://keybase.io/inv/841bcaf887 https://keybase.io/inv/1b2d6b8489 https://keybase.io/inv/1b2d6b8489 https://keybase.io/inv/d4d629e661 https://keybase.io/inv/d4d629e661 https://keybase.io/inv/aa8d6f88a7 https://keybase.io/inv/aa8d6f88a7 https://keybase.io/inv/1e2d324856 https://keybase.io/inv/1e2d324856 https://keybase.io/inv/ed26718971 https://keybase.io/inv/ed26718971 https://keybase.io/inv/3b60a5f56d https://keybase.io/inv/3b60a5f56d https://keybase.io/inv/c11ebfb7ac https://keybase.io/inv/c11ebfb7ac Sold out.
- rgbrgb 10y agoHow do you purchase zcash with USD?
- cjbprime 10y agoNot an expert, but: Kraken is an exchange that sells Zcash to USD holders (as long as you aren't in NY state!). Another option is to buy Bitcoin (e.g. from Coinbase) with USD, and then use shapeshift.io to convert your Bitcoin to Zcash.
- computerwizard 10y agoI recommend supporting Zclassic also ( http://Zclassic.org http://Zclassic.org ) It's the same exact code as Zcash except there is no 20% "genius" tax for 4 years. It's the fair choice and even has the blessing of Zcash developer Zooko.
- abledon 10y agoIf Zclassic existed, why didn't Keybase go with this instead!!!
- johnnyfaehell 10y agoProbably because chances of zcash becoming popular is very slim, chances of zclassic becoming popular is even slimmer. Personally I find the whole idea of zclassic a bit disappointing. Some people spent a lot of time and effort on to something which cost a lot of money. They're giving it away for free and people have a problem with them making money off it.
- Taek 10y agoI think it's worth paying the "genius" tax. Though controversial, the tax manifests in the form of inflation and will help fund a company that can get things running and stable. Of all the qualms I have with Zcash, I think that their mining fee is one of the cleaner ways in the ecosystem to fund altcoin development. This technology takes a lot of effort, and a lot of salary money to develop. And then you have to do marketing, PR, bizdev, etc. re: qualms: - trusted setup makes me uneasy - could have picked more than 5 people for signing party - cryptography is really scary - lots of assumptions, lots of things that haven't really stood the test of time or the examination of experts - equihash was a poor decision, and a confusing one given that it's pretty well understood that complex hashing functions are counterproductive (and we've seen this play out already for Zcash, things are just getting started) - The 'slow start mining' was also a really bad idea, and I would almost suggest that it's abusive to the community. More than $100,000 of trade volume happened over Zcash at prices that are 1000x the current price of Zcash. It should have been easy to understand that this would happen. Mostly, I would urge people not to use Zcash for situations that require real anonymity. E.g. wikileaks accepting donations, or routing around captial controls in oppressive countries. And this is because I do not believe that the cryptography will hold up. There's too much of it, it's too new, and it's too interesting (e.g. a lot of aspiring undergrads and grads are looking to make their mark on the world, and breaking Zcash would be a great way to do that). I believe that your privacy will be compromised retroactively, and not due to bugs but due to actual cryptographic breaks. And then you're back to the Bitcoin network where everyone can see everything, and you're vulnerable.
- malgorithms 10y agoAuthor here. Seeing some of the discussion go down on Twitter, I feel maybe I should explain further the "white supremacist" example in the post. (one tweet at me: "So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example.") When I shared a draft post with some friends, a lot of them had an ah-ha moment, so I was hoping for the same from others. I was trying to illustrate 2 privacy concerns around the graph Bitcoin exposes: (1) accidental associations and (2) exposing the people you transact with to each other. In the blog's hypothetical, you're not receiving money from some asshole because you're collecting Klan dues from him. Rather, you performed some public transaction with a stranger. For example, maybe you sold him some tickets. An external observer of the graph who knows he's a dangerous character may start applying high odds that you, too, are a dangerous character, since they don't know why he sent you money. This would suck. And, second, this character who sent you money may also be learning things about you. Since you sold tickets to a local show and mailed them to him, (1) he's likely to live near you, and (2) he knows your return address. You really don't want him seeing that you're sending money to causes he opposes. If so, he might show up at your door. The goal was to clear up this misconception that a private cryptocurrency is there to protect criminals. This is especially important if you'd like to post a static address on a profile.
- exstudent2 10y agoThank you for your post (and Keybase!). I thought the example was a good one. Buying a book creates a permanent transaction record with the seller who's ethics you may not share. Humorous as well with the tongue and cheek reference to Atlas Shrugged :) We're sadly living in a society where people search high and low for grievances to publicly virtual signal over. Hopefully the Twitter-sphere will realize there's value in your example and not just clutch pearls.
- zapu 10y agoThat's an important example. Person A can make a perfectly legal transaction with Person B who is involved in illegal activities, without Person A knowing that. Then, external observer, not knowing the transaction details, might as well associate Person A with the same illegal activities. A false positive in metadata analysis. Thank you for explanation.
- prashnts 10y agoI have ~15 invites left, in case someone needs it they can ping me at ps+hn <at> noop <dot> pw. :)
- wbinford 10y agoActually, the faq in the ZCash blog post (https://keybase.io/blog/keybase-and-zcash https://keybase.io/blog/keybase-and-zcash) has a way to sign up for keybase.io immediately.
- anondon 10y agoIs there any way to mimic Zcash's z-addresses in Bitcoin? I like the ideas behind Zcash and it solves important privacy issues, but I don't like the idea of a for profit company being the heavyweight behind Zcash. From what I gather, Bitcoin is more of a community effort than most other altcoins, which inspires trust. I looked up Zcash's price chart, it fell from ~$1300 at launch to ~$90 now. Ouch.
- Taek 10y agoIf I recall correctly, more than 500btc was traded when the price was over 100 btc per Zcash - $350,000 in trade volume at a price exceeding $70,000 per token, when the price today has fallen to about $100 per token. Max price was almost $2,000,000 per token, someone actually literally spent that much. Perhaps the greatest example I've ever seen of tulip mania. And I'm fairly confident those were real trades, as they occurred on a public exchange where anyone with money or zcash was able to buy or sell at any time. Granted, at this point there were only dozens of people with the asset, but anyone was able to mine the currency and blocks were being found every 2.5 minutes using commodity hardware (e.g. laptops and desktops).
- hackinthebochs 10y ago>Max price was almost $2,000,000 per token, someone actually literally spent that much. No. When zcash was trading at such a price, it was less than a single zcash coin in total. So a few people were paying significant sums for very small fractions of a zcash coin, but no one payed 2,000,000 for a single coin. The price has crashed because supply has grown exponentially. What you were seeing was supply vs demand in action in an unusually obvious way.
- Taek 10y agoI did not mean to suggest that a whole $2M was dropped, but someone did buy a fragment for $2M per coin. These people buying it hopefully would have been aware of the publicly known upcoming inflation, the fact that they bought at these prices I believe is a tragedy and a black mark against Zcash.
- Panino 10y agoThe biggest criticism of Zcash is the Founder's Reward. Some people say it's greedy, that they should have given away their work for free. I disagree. I think it's great that they will get paid for their work, and it also gives me confidence for the future of the coin. They have an incentive to make Zcash a long-term success. Getting paid for work done should be the default, of course. I could understand that if a billionaire ran a lemonade stand for an afternoon and steadfastly demanded payment with no free handouts, people would criticize that. But it should be expected that normal people get paid for doing real work.
- petertodd 10y agoThe founders reward is extremely high, so high that the founders have a significant ability to manipulate the market. This is a concern in part because the founders may be forced to do that - the actual implementation is with a single address, rotated periodically, which means that address is a single-point-of-failure for the whole currency in the sense that compromising it can be used to crash the price. Finally, 20% is high enough that it gives a significant advantage to 51% attackers.
- daira 10y agoThe concern in that last sentence seems misplaced; there is no relation between proportion of monetary base held by an attacker, and proportion of mining power held by an attacker.
- petertodd 10y agoThe problem is that it reduces the cost for an attacker; why do you think monetary base has anything to do with it?
- choffman 10y agoI think Keybase is making a mistake in choosing Zcash over Monero - especially so soon after Zcash's launch. But that's okay - they'll come around soon enough. Zcash has been fantastic advertising for Monero.
- nickik 10y agoPM me if you are interested in invites, I have a bunch.
- atweiden 10y agoThe "zaddress" is already implemented in Bitcoin in the form of a stealth address, pioneered by libbitcoin [1]. This news spurred me to delete my Keybase account. I regret ever giving a corporation that much control over my personal privacy. [1] https://github.com/libbitcoin/libbitcoin-explorer/wiki/Stealth-Commands https://github.com/libbitcoin/libbitcoin-explorer/wiki/Steal...
- detaro 10y agoCare to explain why for someone who doesn't know much about the bitcoin/cryptocurrency world? I don't get what the link is supposed to tell me.
- atweiden 10y agoA regular Bitcoin address of the form `1LoD3JXVckEKkZh8nkSrvmQaovnGYu8fNP` is non-private, everyone knows this. Posting such an address in your public profile allows blockchain data harvesting firms to learn when your address receives BTC and from where, and to whom your address sends money to. But there is no reason to post such an address. If Alice wants to post a fully private Bitcoin address that can't be monitored by data harvesting firms, she should post a stealth address [1]. If Bob wants to send Alice BTC, he takes Alice's stealth address and derives from it a regular Bitcoin address. No one but Bob can know what Alice's derived Bitcoin address is, because the address is derived from Bob's private data. The libbitcoin software suite supports these stealth addresses, but because libbitcoin isn't VC backed and doesn't have the hype of moneyed interests behind it, libbitcoin wasn't good enough for Keybase. They probably never even evaluated it. A ZCash "zaddress" is basically just a Bitcoin stealth address. That the CEO of a privacy-focused social networking service is not in tune with this information is a huge red flag to me. As each Keybase.io profile is an implicit endorsement of Keybase and by extension Keybase's investors, I was deeply saddened and frustrated to learn the news that Keybase has decided for its entire userbase to prop up ZCash based on their faulty assumptions. [1] http://sx.dyne.org/stealth.html http://sx.dyne.org/stealth.html
- dstaten 10y ago"The sex toy shop knows you gave to UNICEF so that feels good."
- jszymborski 10y agoSlightly OT, but I realllyy wish Keybase would prioritise email validation so that it could fulfill the much needed role of general PGP key server, with the added "sum of your social identities" assurance.
- rspeer 10y agoAnd that's what I thought Keybase was until this article. I got myself a Keybase account a while ago; is it reasonable to use it if Zcash is not something I would touch with a ten-foot pole?
- pero 10y ago5 hours and almost 100 comments later no one has pointed out that Zcash and Keybase share the same investors. I am relieved that 'Keybase chose Zcash' purely on merit after an exhaustive and objective selection process, and that this potential conflict of interest is transparently disclosed in the linked adverticle - wait, they did no such thing. Does it concern no one that this security-focused company is shilling for other (fundamentally questionable) products?
- yungchin 10y agoI couldn't decide whether to up- or downvote this: it sounds like equal parts 1) information worth bringing to people's attention and 2) slandering a team that seem really nice fellas to me. So I looked both companies up on CrunchBase, and can find zero overlap between investors declared there. Where did your information come from?
- pero 10y agohttp://archive.is/wdNh3 http://archive.is/wdNh3 http://archive.is/vnmkv http://archive.is/vnmkv
- yungchin 10y agoThanks very much for this. Based on the one or two private individuals featuring on both lists, I'm inclined to think your original post was exceedingly strongly worded.
- pero 10y agoDid you read the blogpost? It's basically a Zcash presskit - note the surely calculated title, and the omission of any actual "anonymous" competitor coins in the first paragraph as well as the entire article, all at a time when ZEC price is in free-fall. It might even be worse if it wasn't as such - a security-oriented business that, motivated by Bitcoin's shortcomings, does due diligence on anonymous crypto and genuinely concludes that Zcash, in its current state no less, is the answer? Come on.
- deleted 10y ago[deleted]
- gtlondon 10y agoWouldn't it make more sense to use Monero instead of ZCash? Privacy is compulsory with Monero and also the entire platform is decentralised. The privacy features in Zcash are optional & very slow / difficult to use -- most users will simply make non-private transactions. Also Zcash requires trust of the founders (Any "private" coin that requires trust of a third party is a fail in my mind).
- EvilMonkeyMat 10y agoI have read almost all comments, and it seems like nobody has pointed out that the supposedly anonymous transactions (using z addresses) are still not working. All mining pools are warning about it. For example: http://zcash.flypool.org http://zcash.flypool.org If anonymity is so important for people, there are already excellent solutions, Monero being one of the best, if not the best, with a strong and serious dev team. Disclaimer: I am not a Monero dev and I own a huge total of 0.6 XMR. This is only my opinion as a software dev.
- daira 10y agoFixed in Zcash 1.0.3. (They were always "working", despite the bugs that were recently fixed. You can see plenty of successful z-address transactions on the blockchain.)
- plasticmachine 10y agoYou had a single thing with ZCash that you had to get right, and you couldn't get it working in your initial release? What an utter embarrassment.
- yownie 10y agoDoesn't anyone else find this post funny for talking about discovery of social graphs while the main product keybase.io offers does exactly this? I mean the entire service acts an a nice centralized graph linking users nyms across various services. Irony much?
- Uptrenda 10y agoCompletely unrelated to the article but boy do I like the design for Keybase. The blog is beautiful and minimal with no crap popping up on your screen asking for your email (every modern blog now seems to do this.) The colors work perfectly too. In fact, that combination of white, blue, black, and gray is very similar to what Bitcoinica originally used for their popular Bitcoin margin trading platform back in the day (and I like it as much now as I did back then - contrasts so well on every screen type.) The home page also follows a similar pattern: just beautiful, uncluttered, no bullshit design, that gets straight to the point. Why can't more websites do this? A+++ would browse again.
- doozler 10y agoIs it too late to get started with Zcash? If not would you recommend buying it or trying to mine it? Last question, would AWS be a good resource to mine it?
- alexmingoia 10y agoWhy not Monero? Why not Ethereum? The reasons stated aren't very consistent.