4 ms·
Sure. Starting from the academic beginning and then going to commercial usage: Zerocash[0], a paper from 2014 (I'm an author on it), proposes using zksnarks to
by ianmiers 5y ago
Sure.
Starting from the academic beginning and then going to commercial usage: Zerocash[0], a paper from 2014 (I'm an author on it), proposes using zksnarks to get a public ledger + privacy with no centralized parties. Instead of identifying the origin of your money on the blockchain and moving it to someone, you just prove in zero-knowledge your payment is correct. This showed strong privacy on a public blockchain was feasible. But slow (2 minutes per payment IIRC)
Three years and much work by others later, it takes ~2 to 3 seconds on a Pixel three to make a zk-proof for a payment. This can be optimized down to 1 second fairly easily (on that you have only my assertion currently)
This is commercially deployed in Zcash (the above mentioned coin with usability and adoption issues), a few other straight up forks, and a new coin called IronFish. And related protocols are in a few things on Ethereum (e.g., Aztec). If you want to test performance numbers, you can download one of these systems and try it yourself (Nighthawk is a decent mobile wallet for Zcash)
Current technical objections (again, beyond criticisms of Zcash as a coin itself)
1) Current ZK proofs require trusted setup. New ZK proofs developed by engineers at Zcash removed this[1]. So its not longer an issue for the technology (or for Zcash once it's deployed)
2) you have to scan the blockchain to get notified of payments. No, this happens to be how Zcash does it. As I said in a separate comment, it's easy to send payment notifications out of band.
3) Vague objections about "scale." Even though zksnarks take a second or two to prove, they are very fast to verify. So adding privacy doesn't make blockchain's scaling problems worse. And the privacy tech is agnostic to the underlying consensus layer, so if you ever get a blockchain to scale, you can put privacy on it.
4) Other approaches(Monero/RingCt/Coinjoin) are better. The major problem is these don't offer strong privacy, just obfuscation. See [2] if you want a 20 minute talk on the issues or [3] for a blog post covering the same
5) There's an inflation risk. Yes, once you hide the values of a payment, because you want privacy, if the crypto breaks, things can go wrong. This is true of any serious approach to privacy. So you want to very carefully vet the crypto design. But if you don't hide payment values, you get no privacy and your blockchain is twitter for your bank account.
[0] https://www.cs.umd.edu/~imiers/pdf/zerocash-oakland2014.pdf https://www.cs.umd.edu/~imiers/pdf/zerocash-oakland2014.pdf
[1]https://electriccoin.co/blog/technical-explainer-halo-on-zcash/ https://electriccoin.co/blog/technical-explainer-halo-on-zca...
[2]https://www.youtube.com/watch?v=9s3EbSKDA3o https://www.youtube.com/watch?v=9s3EbSKDA3o
[3]https://www.zfnd.org/blog/blockchain-privacy/ https://www.zfnd.org/blog/blockchain-privacy/