5 ms·
To play Signal's advocate, MobileCoin is one of the only cryptocurrencies that meets their requirements. The only other cryptocurrency that I know of that might
by qqii 5y ago
To play Signal's advocate, MobileCoin is one of the only cryptocurrencies that meets their requirements. The only other cryptocurrency that I know of that might come close is Grin.
The details of the distribution are lacking but as a beta it meets the experience they're going for - it's not as if they'd choose something that doesn't meet their requirements for the beta.
- godelski 5y agoTo clarify the only coins that meet their privacy requirements are ZCash, Monero, and MOB. The only subset of that that meets their transactional speed requirements is MOB. At least AFAIK. There's a ton of alt coins so I might have missed something.
- nullc 5y agoThis seems extremely misleading to me. Their "privacy" is strongly based on the confidentiality of SGX. If you're willing to trust SGX for your confidentiality and security, as they have, they could use any cryptocurrency in a highly private and instant manner. E.g. via an implementation of the moneypot server in SGX: https://bitcointalk.org/index.php?topic=5302025.0 https://bitcointalk.org/index.php?topic=5302025.0 MOB is transparently a scheme to generate a windfall from shoving a pre-mined coin into a mass-market application. One could debate the ethics of that with a straight face, I suppose, but to argue that it is anything but is just dishonest.
- godelski 5y agoMy understanding is that SGX is only a layer. As in that it acts like ZCash or Monero and then has SGX as an additional layer. Even Signal uses SGX. But breaking SGX isn't going to break Signal. Also, my understanding is that these speculative attacks are still difficult to pull off in the first place. I mean everything is hackable, question is how easy it is to pull off.
- nullc 5y agoThe monero like part effectively runs on their servers inside SGX for performance reasons. If the SGX were completely insecure the users would have no privacy against the operators at all.
- qqii 5y agoThis is false, their privacy is similar to Monero (RingCT). SGX is only an added level of privacy.
- nullc 5y agoNo, that is smoke and mirrors. The client fully identifies itself and its keys to the server, the wallet is entirely implemented server side. Without SGX there is no privacy what-so-ever. Usage of ringct is incidental. It's like claiming that your documents are private when your operating system submits them all to the NSA because the NSA encrypts them after receiving them. :) (and, of course, we trust the NSA to behave honestly...)
- ianmiers 5y agoYou got sources for that being how the construction works? From various telegram groups with the devs in them , my understanding is 1) rings are constructed client side 2) uploaded to the server inside SGX. This has two major weaknesses 1) it doesn't specify how payment notification happens, which can be a massive privacy hole 2) if SGX is broken you are subject to all of the long term intersection attacks on Monero's/k-anonymity because the rings are now public. This is a very limited threat model and worthy of serious scrutiny.
- runeks 5y agoWait, haven’t they published a white paper?
- petertodd 5y agoAlso, _even if_ we steel-manned the design and imagine SGX is truly only used as a "defence-in-depth" layer on top of a ringct blockchain, using SGX to prove that SGX Lightning nodes weren't keeping transaction info would still be better privacy under many circumstances. Lightning transactions are ephemeral: once the transaction happens, _no_ data about the transaction actually needs to be kept by anyone, let alone on a public blockchain. And only the peers directly involved in the route ever learn about the transaction directly. Whereas with SGX, if SGX is broken in the future - and it will be - the statistical analysis on the underlying blockchain data is still possible. And unlike MobileCoin, this design wouldn't put SGX in any kind of trust or custodial position at all: if SGX failed, you'd just close the Lightning channels the same way any other Lightning implementation would, and open new channels with non-SGX peers.