6 ms·
Yet ignores the founders of zCash saying they can make a backdoor for police and make it too traceable for criminals. >Green says that he and his fellow resear
by the_stc 9y ago
Yet ignores the founders of zCash saying they can make a backdoor for police and make it too traceable for criminals.
>Green says that he and his fellow researchers are not interested in facilitating criminal activity with Zerocoin. "Zerocoin would give you this incredible privacy guarantee, then we could add on some features which let the police, for instance, to be able to track money laundering. A back door."
https://www.newscientist.com/blogs/onepercent/2013/03/bitcoin-zerocoin.html https://www.newscientist.com/blogs/onepercent/2013/03/bitcoi...
That alone scares me off of it, and why we're suggesting people use Monero to invest with us. I know that was a while ago, and zerocoin isn't zCash but combined with Zooko's tweets about making zCash too traceable for criminals, no thanks. The crypto is too new, so who knows how they could go about hiding a backdoor.
It's so odd anyone would ever work with these guys given their attitude and statements.
- geofft 9y agoThat's a very weird statement, and I wish there were some more context behind it in the article - is this a cryptographic or protocol-level back door, or is this just the idea that you can start with an anonymous system and add tracing (but you can't start with a visible system and add anonymity)? It could be either, and I'm not sure how to read it.
- ewillbefull 9y agoZooko explained afterward: https://twitter.com/zooko/status/864341289374023680 https://twitter.com/zooko/status/864341289374023680
- the_stc 9y agoThat's not an explanation. It's just an assertion they'd not do bad stuff, ignoring what he previously tweeted. Neither is his stuff about it being compatible with law enforcement. A real explanation would follow through the thought and say exactly how they can make zCash "too traceable for criminals". Especially when Green has his own quote saying they're OK building backdoors for police. Or maybe that is their entire plan. Say something slightly sketchy, knowing any real criminal will be too paranoid to trust it. Worked for me.
- geofft 9y agoI want to rely on a cryptosystem which means that at a protocol level, the designers can't build in backdoors for police even if they want to. Then I don't have to worry about their public statements. Maybe they're firmly ideologically opposed today and get a court order tomorrow. (This is exactly what happened with well-intentioned scam artist Ladar Levison: he built a system that didn't have the cryptographic properties he promised, and the government called his bluff. He didn't particularly desire to help the government, but he had no choice.) The question is, do we believe that there's room in the Zcash protocol for a cryptographic back door?
- the_stc 9y agoI am unable to judge zcash and must rely on other cues. So when the founders seem to be saying they're OK with backdoors, it makes me think hey, given the chance maybe there's something they could do. Anyways once they get mandatory shielded transactions I'll look at it in more depth and see if I can get comfortable.
- neuro_imager 9y agoA couple questions: - Aren't zerocoin and zerocash two different currencies? Did you mean to say zerocash in your previous comment? - If what Matt Green is saying is true, is there a way to create a backdoor in Monero or any other new crypto that comes along? - One of the reservations that I have around z-cash is the "don't roll your own crypto" mantra even if you are an experienced, academic cryptographer? Is z-cash inherently more risky because its using newer crypto?
- the_stc 9y agoI know, but it's the history of the person I'm looking at. Monero could well have weaknesses. That's why I don't rely on it. In fact, I know it has weaknesses. Monero's problem is they do not adequately tell people how to use it safely. The marketing is all about how Monero is safe, not about its limitation. Dangerous game for them to play. It's not about rolling own crypto. My understanding is that zcash is more risky due to the newer concepts involved. This is all theoretical right now anyways. Without more support for shielded transactions, it isn't feasible to use zcash to clean Bitcoin or other cryptocurrencies. Exchange volumes of XMR-ZEC are also too small from what I can see to make stacking them useful. That said, we are reconsidering things. We will probably add zcash as a payment method sometime this week.
- matthewdgreen 9y agoMatt Green here. This statement has been trotted out a lot by people who I don’t honestly feel are offering it up with any kind of good faith. As you suggested, all I meant is that once you have a fully anonymous currency it’s always possible to deliberately weaken that privacy if you want to. I think that sort of decision is up to the currency adopters. But to be clear, that kind of feature is absolutely not included in ZCash. Anyone who implies so is selling FUD. Since the ZCash code and design is fully open source this is easily verifiable, and plenty of people have looked. For the record: as a researcher I deal with a lot of people who’ve told me that privacy technology is fundamentally dangerous. One standard response I give them is that this is crazy: a fully private currency is the right starting point. If you want to make a fork of ZCash that has less privacy, you can do that and I won’t stop you. But that isn’t ZCash.
- the_stc 9y agoI don't mean it in bad faith. I am one of the people you and Zooko talk about preventing from using zCash. That's very offputting and since I cannot audit zCash it makes me nervous. People tell me zcash is very advanced and thus hard to understand and audit for other people too: newer crypto. I am not implying any backdoor, just that it seems you are sympathetic to such works. I don't follow Zooko's explanation that he wasn't talking about zcash but about some other unmentioned layer. If it's a generic statement about all currencies, why bring it up and mention zcash in the same breath?
- deleted 9y ago[deleted]