5 ms·
I've said it before: Zcash has nothing Monero isn't already offering. And like others said, right now, I still haven't seen a mining pool or an exchange that ca
by EvilMonkeyMat 10y ago
I've said it before: Zcash has nothing Monero isn't already offering. And like others said, right now, I still haven't seen a mining pool or an exchange that can handle anonymous transactions. An example: http://zcash.flypool.org/ http://zcash.flypool.org/
Also, Zcash had an initial trusted setup ceremony after which the 6 participants supposedly all deleted their private keys. You DO have to trust none of those have colluded to someday, for example, start creating zcash coins for their own good without anyone knowing. All the info here: https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trusted-setup-ceremony https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trust...
- FiloSottile 10y agoAnd as others said before, Monero does some sketchy weak mixing of something like a 100 tx, which is really not enough for long term anonymity (think what happens when the other 99 outputs are spent). EDIT: there are a couple papers linked in a child comment that seem to analyze this which I haven't read entirely yet; the following two points still stand. You don't need an exchange to use z-addresses, just receive into a one-use t, and then make it disappear into your main z-address yourself. Finally, you have to trust that AT LEAST ONE won't collude, because you need all pieces to fake Zcash, which is very different. Enough with this FUD. It's innovative tech, I expected HN to appreciate it more than the usual cryptocurrency circles.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- otheotheothe 10y agoHello Mr. Cloudflare, Your whole understanding of how XMR works seems to be wrong; theres no concept of spend outputs at all, to deanonymize tx with a certain certainity one would have to own around 83% of the networks outputs. Theres a good academic read about this here: https://lab.getmonero.org/pubs/MRL-0001.pdf https://lab.getmonero.org/pubs/MRL-0001.pdf and here: https://lab.getmonero.org/pubs/MRL-0004.pdf https://lab.getmonero.org/pubs/MRL-0004.pdf And also a privacy improvement which gets into effect in about 25 hours or so with the next hardfork called RingCT, which has been peer reviewed by Ledger journal: http://www.ledgerjournal.org/ojs/index.php/ledger/article/download/34/45 http://www.ledgerjournal.org/ojs/index.php/ledger/article/do... Optional privacy a la ZCASH is broken by design and cannot work, you are still able to have tainted coins and do blacklisting etc, its effectily useless, also it opens up a whole world of other attack vectors like this one: https://github.com/zcash/zcash/issues/1360#issuecomment-246109488 https://github.com/zcash/zcash/issues/1360#issuecomment-2461... A good read for everyone unbiased tho a bit old is here (which explains the inner workings): https://lab.getmonero.org/pubs/MRL-0003.pdf https://lab.getmonero.org/pubs/MRL-0003.pdf
- otheotheothe 10y agoTheres are a whole bunch of different downsides at ZCash too: - multisig with zaddresses seems not to be possible. - Using Z Addresses on a Smartphone or HW device like Trezor is too resource intensive Looks like a privacy disaster to me, as no one will be using it.
- aminorex 10y ago20% of the mining goes to the controlling corporation. This is not decentralization; it's a blatant grab at your wallet.
- FiloSottile 10y agoI hope there is no need to spell out that my understanding of the Monero technology is not an official position of my employer, is there?
- otheotheothe 10y agoNo i just called you that way as i saw your talk at 3c33 about TLS :)
- plasticmachine 10y agoYour lack of understanding of how Monero works is embarrassing. Please educate yourself before commenting! As to the trusted setup, there are a few salient points: - you don't have to "just trust one participant", what if 3 of them collude and 3 were compromised? - every participant booted off the same ISO which was provided by a single person. The claim is that the ISO can be built deterministically, but that still does not prevent it being compromised in subtle ways, and it seems that hardly anyone has bothered to try verify the ISO build process even subsequent to the ceremony. - even when there was clear evidence that someone's phone was compromised, the ceremony went ahead. This is a huge red flag - why not just stop the ceremony and rethink it, given the fact that there was obvious infiltration? - why only 6 participants? Why were they chosen by Zooko? Why was there no open application process where applicants could be considered by the community? Why were no members of academic institutions involved as participants? The way the trusted setup was conducted is shocking, this is privacy theatre at best. On your closing remark about it being innovative: nobody doubts that the ZeroCash white paper is innovative, but it is also too new for us to be trusting it. Would you advocate for TLS 1.3 to default to only use some encryption method that was in a very recent, largely unreviewed whitepaper, especially when that whitepaper contains math that is particularly hard to grok (Greg Maxwell calls it "moon math")? Why do we hold all of our cryptography to such high standards, distrusting everything that is new and unproven, but we're expected to give a financial system a pass? Would you feel the same if all of your net worth was held in that financial system?
- nextos 10y agoI also trust Monero more. Both Zcash and Monero (plus perhaps Dash, but it has some issues) try to augment Bitcoin with some privacy guarantees. Ethereum is extending Bitcoin with Turing-completeness. I follow Bitcoin, Ethereum and Monero with interest. I wonder whether any of these additional features will prove advantageous enough to surpass Bitcoin, which is more mature and has much bigger market cap right now. IMHO, Bitcoin is secure enough for its current main use-case, which seems to be escaping Yuan / Bolivar. But I might be proven wrong. It's also interesting to note some other black swans may trigger cryptocurrency adoption in 2017 [1]. Ethereum seems advantageous for many business applications which are impossible with a traditional blockchain, but they really need to ensure Turing completeness doesn't lead to more fiascos. Perhaps by enforcing much much better static analysis than currently available [2]. You can err on the safe side and reject contracts that don't pass whatever static analysis. Seems the only way to retain Turing-completeness and safety. However, given EVM semantics is complicated, perhaps a redesign will be needed so that static analysis does not rule most contracts as potentially unsafe. [1] https://s3.amazonaws.com/storage.saxobank.com/TradingFloor/2017-Outrageous-Predictions.pdf https://s3.amazonaws.com/storage.saxobank.com/TradingFloor/2... [2] http://www.cs.umd.edu/~aseem/solidetherplas.pdf http://www.cs.umd.edu/~aseem/solidetherplas.pdf
- xiphias 10y agoBitcoin will get all features that Monero has, but security is still the most important aspect, so the maintainers take a very slow, conservative path (which I think is awesome for something so important). Segwit is still a great first step. It will take multiple years to get there...there's no rush though. People who really believe in BTC understand that it's not something that will be finished in 5-10 years.
- plasticmachine 10y agoBitcoin will get a minimum block reward that ensures miner incentives in perpetuity? Bitcoin will switch from secp256k1 to Curve25519? Bitcoin will get a dynamic block size limiter that adjusts with transactional demand? You must be joking.
- corv 10y agoYou only have to trust that ONE of the participants has not colluded. Zcash offers more anonymity at the expense of more computational resources.
- aminorex 10y ago..and that the framework was proven correct.