4 ms·
You're almost there, but not quite. Since Monero outputs go to dual-key stealth addresses, outputs are effectively paid to a random 256-bit "address". So if yo
by plasticmachine 10y ago
You're almost there, but not quite.
Since Monero outputs go to dual-key stealth addresses, outputs are effectively paid to a random 256-bit "address". So if you use a mixin of 50, in a transaction with 1 input, an external observer can say "this illicit transaction spends funds from 1 of 50 possible transactions", but then you need to go to those 50 and work your way back till eventually you find a needle, in a very large haystack, that you can actually identify.
Because of this, the anonymityset grows exponentially the further up the tx chain from an identifiable transaction (eg. a withdrawal from a KYC / AML exchange) you are.
The major advantage here is that every Monero transaction adds to this anonymityset, since privacy is compulsory.
On the other hand, ZCash's privacy is nearly unusable. Using it requires 8gb+ of RAM, and takes over a minute on a Xeon processor. Because of its unusability you end up being "1 of X people", where X is very tiny - it's limited to the people moving from traceable addresses to z-addresses who haven't identifiably moved ~the same amount out.
ZCash is useless at best, dangerous privacy theatre at worst.
- deleted 10y ago[deleted]
- EthanHeilman 10y agoI like both Monero and zCash. As technologies they both have different advantages and they are both pushing the state of the art in privacy cryptocurrencies. As a researcher it makes me optimistic that we are pursuing multiple paths to the goal of "digital cash". >Using zCash requires 8gb+ of RAM, and takes over a minute on a Xeon processor. Cryptography in this area is rapidly advancing, we have seen dramatic speed ups in zkSNARKS (cryptography behind zCash's anonymity) over the last few years and the launch of zCash will probably accelerate this trend. > it's limited to the people moving from traceable addresses to z-addresses who haven't identifiably moved ~the same amount out. This number, X, is growing and will continue to grow. >ZCash is useless at best, dangerous privacy theatre at worst. zCash is an excellent and exciting experiment. It is not a very mature platform (it has only been live for a month), but that doesn't mean it will never been mature.
- plasticmachine 10y agoSorry but I can't agree with you here. When Monero still allowed mixin 0 transactions almost nobody used the privacy-enhancing transaction type. The same goes for Dash and it's DarkSend, or Shadow's ring-signature side-currency - all virtually unused. Thus X grows at a rate that is useless for its intended purpose: getting lost in the dust of millions of others. But to make matters worse, ZCash is grossly irresponsible by not making private transactions mandatory, as people will use t-address transactions and think they're safe. Pools pay out to t-addresses, exchanges only accept t-address deposits, and lightweight clients will all end up being t-address only as it's the quick win. Claiming that it's "just an experiment" is not acceptable when people's money is on the line, at best, and where their lives might hang in the balance, at worst. The disgusting and dangerous approach taken by the for-profit US company behind ZCash, that of fast-tracking the launch of massively immature technology due to investor pressure, is something that should lead to grave consequences for them because of the nature of this technology. I greatly respect the work of Ben-Sasson, Green, Garman, Miers, et. al., but even they have been complicit in the rush hack-job that is ZCash. We would do well to consider what advantage a nation state attacker would have in encouraging adoption of this immature and likely broken system, over alternatives that are FOSS and have prolific contributor communities.
- EthanHeilman 10y ago>Claiming that it's "just an experiment" is not acceptable when people's money is on the line, at best, and where their lives might hang in the balance, at worst. Claiming it is just an experiment means that people should NOT use it when serious money or human lives are on the line. I think we can both agree that people should wait for a technology to mature before betting their life on it.
- plasticmachine 10y agoIf the aim was for it to be experimental, why create a "live" monetary system? Why not keep it testnet-only, untradeable?