7 ms·
I'd be curious to hear from Monero fans why one might select it over Zcash? Zcash seems to have stronger security guarantees when shielded transactions are use
by ahnick 5y ago
I'd be curious to hear from Monero fans why one might select it over Zcash? Zcash seems to have stronger security guarantees when shielded transactions are used.
- I_cape_runts 5y agoZcash has to have privacy enabled by the user. It’s not automatically private. Monero is automatically private.
- ahnick 5y agoYes, I understand. That's why I'm specifically asking about the advantage of Monero vs when shielded transactions are used on Zcash.
- betwixthewires 5y agoTechnical peculiarities aside, if all zcash transactions were shielded each protocol would provide comparable adequate privacy.
- null0pointer 5y agoTo expand on this a little bit, non-default privacy means that use of privacy features becomes de facto suspicious activity, thus rendering them useless. Another issue with Zcash is that it had a trusted setup, which is not an issue Monero has.
- ahnick 5y ago> To expand on this a little bit, non-default privacy means that use of privacy features becomes de facto suspicious activity, thus rendering them useless. That's not a true statement as far as I understand how Zcash works. Right now there are >742K ZEC in the shielded Sapling pool, so there are quite a few people using it and you can not tell their shielded transactions apart. https://electriccoin.co/zcash-metrics/ https://electriccoin.co/zcash-metrics/ > Another issue with Zcash is that it had a trusted setup, which is not an issue Monero has. Yes, but they took a number of steps to make sure that the ceremony for creating the trusted setup discarded the keys used and there was no one listening in. (they were geographically distributed and destroyed the hardware)
- fourstar 5y agoOne thing that has always rubbed me the wrong way about Zcash was after I listened to this RadioLab recording wherein the reporter's (Morgan) phone started to play the audio from the Google hangout during the trusted setup ceremony. https://www.wnycstudios.org/podcasts/radiolab/articles/ceremony https://www.wnycstudios.org/podcasts/radiolab/articles/cerem... Skip to around 36 minutes for that.
- fourstar 5y agohttps://electriccoin.co/blog/ecc-timeline-updates-and-planning-for-2022/ https://electriccoin.co/blog/ecc-timeline-updates-and-planni... Halo Arc removes the trusted setup and also sets shielded transactions by default. ECC also has announced that they intend to work on implementing shielded assests which seem compelling: https://electriccoin.co/blog/zsas-ecc-progress-and-next-steps/ https://electriccoin.co/blog/zsas-ecc-progress-and-next-step... One glaring issue is that there seems to be lots of tension between the community and the Zcash foundation (wrt power control).
- nmaleki 5y agoThis reddit user seemed to have some valid reasons: https://www.reddit.com/r/Monero/comments/oui6zj/-/h734kyq https://www.reddit.com/r/Monero/comments/oui6zj/-/h734kyq
- stiltzkin 5y agoBecause of this: https://twitter.com/zooko/status/863202798883577856 https://twitter.com/zooko/status/863202798883577856 zcash is shady
- hamburgerwah 5y agoThe underlying math (read cryptographic implementation choices) and people backing Zcash are extremely suspect. These days everything gets all lumped under one crypto banner but from a first principles standpoint I find things like bitcoin and monero extremely sound. On the same basis I find, very unpopular opinion, say ETH, is just trash. Zcash is even worse in that it seems largely in intentional scam.
- ianmiers 5y agoI think the reddit user someone else linked to pretty clearly explained the Monero side. Zcash has a bad reputation with darknet markets and the like that use Monero. Some of it deserved. ( I say this as someone who wrote original Zerocash protocol) https://www.reddit.com/r/Monero/comments/oui6zj/zcash_vs_monero_2021_comparison/h734kyq/ https://www.reddit.com/r/Monero/comments/oui6zj/zcash_vs_mon... Also, Zcash has optional privacy. On the other hand, the decoy based privacy protocols Monero uses are not really private at all. https://slideslive.com/38911785/satoshi-has-no-clothes-failures-in-onchain-privacy https://slideslive.com/38911785/satoshi-has-no-clothes-failu... Its cryptocurrency, everything is tribal.
- novok 5y agoAre there coins that learned from the bungled launch of zcash and did things right according to what was valued by the community? Like private by default, avoiding perceived trust issues by being more above board, making ASIC resistance a priority, adopting a public irreverence of compliance, not being associated with people who worked with untrusted organizations and so on?
- fourstar 5y agohttps://y.cash/what-is-ycash https://y.cash/what-is-ycash
- ianmiers 5y agoThere are some Zcash forks with iffy dev support and no market traction. The problem is the kind of cryptography you need to do something like Zcash is very very very hard to get right. Zcash actually got the tech right and handled the issues they hit well. They just didn't do a good job with reputation outside of tech. No one else as done the same tech yet themselves. A few things have launched and allegedly plan to add a privacy layer (Mina, Celo). But actually building that kind of tech is a lot harder than reputation management or standard blockchains. It's still an open playing field.
- le-mark 5y agoBitcoin gold has a asic resistant pow, but all the same btc issues so far as I know, because it’s a btc fork.
- baby 5y agoThere are two extremely cool projects with talented engineers who are pushing the boundaries of what’s possible. Anybody telling you otherwise is trying to sell you something.
- ajkdhcb2 5y agoThere was a bug, with which the Zcash developers could have used to generate infinite coins for themselves, and it so far cannot be proven that this did not occur. I do not know how so few people are aware of it. I do not mean the trusted setup, but this: https://forum.zcashcommunity.com/t/zcash-counterfeiting-vulnerability-successfully-remediated/32671/39 https://forum.zcashcommunity.com/t/zcash-counterfeiting-vuln... The developers were funded by suspicious government organisations including DARPA and Israeli Ministry of Science and Technology. It is centralised, with an organisation receiving significant coins directly from the protocol. Opt-in privacy defeats much of the point and creates traceability issues - privacy needs to be the default for people to use it, for their coins to not be treated suspiciously if they turn on the privacy feature, and it is a requirement to have a large anonymity set. Among other reasons, there are many...
- minsc__and__boo 5y agoZCash is controlled by a privately-owned company in the U.S., who gave themselves founder's rewards. It's also designed in a way to allow "poison pills" - i.e. those in control can force a single transaction on a block, thus giving a vector to deanonymize someone. You may ask, "Who would do something like that?" and the answer would be the U.S. government who can compel privately owned organizations via secret court subpoenas. Monero is more private than ZCash, and has a record of not acting on self-interests.
- R0b0t1 5y agoWith monero you can analyze residuals to deanonymize people.
- yawaworht1978 5y agoHow does this work?
- R0b0t1 5y agoThe video was posted elsewhere I think. Basically, if you view enough of the residual ring inputs you can link them together. This is not quite practical yet but assuming wide adoption of XMR chain stores, etc, would be able to do this attack.
- akimball 5y agoThe IRS has paid out millions of dollars in a failed effort to deanonymize Monero transactions without a lawful subpeona. Thus, a lawful subpeona is still required in order to unseal Monero transactions in the US, I.e., to compel the production of a view-only cryptographic key.
- minsc__and__boo 5y agoWhich takes quite a bit of time and hasn't been proven possible yet. Very different from an on-demand poison pill.
- mattwilsonn888 5y agoThe best answer I've seen, is that zero knowledge proofs as Zcash uses in isolation are superior to the ring signatures that Monero uses, but Zcash has one major flaw in that it allows its anonymity pool to be small. What I mean by this is that transactions in Monero are always private, while users of Zcash can choose to send public transactions. What this does is it makes the group of users who send private transactions through Zcash much smaller and far, far more susceptible to being identified through metadata and process of elimination. This is heavily simplified - and Monero community members would be happy to get into the weeds with you about it if you were to visit their realms on the web, I'm sure.
- __MatrixMan__ 5y agoI prefer Zcash's privacy perspective, but one thing I've noticed about using both is the zcash cli wallet is pretty terrible (especially if you're using shielded addresses) and the monero cli wallet is among the most user friendly cli apps that I've ever used. Little touches like that keep making me reconsider the project in a favorable light.
- sensei58258 5y agoZcash's privacy perspective seems to be highly flawed because of the way it was implemented though (optional opt-in privacy): https://news.bitcoin.com/not-so-private-99-of-zcash-and-dash-transactions-traceable-says-chainalysis/ https://news.bitcoin.com/not-so-private-99-of-zcash-and-dash... and https://electriccoin.co/blog/new-research-on-shielded-ecosystem/ https://electriccoin.co/blog/new-research-on-shielded-ecosys...
- __MatrixMan__ 5y agoHaving the network boundaries be explicitly nonprivate and giving users the ability control when/where/how they negotiate the private/nonprivate boundary seems like a reasonable design choice to me. It makes the network more interoperable with nonprivate networks. If the whole network private, then the privacy faults can only happen at its boundaries--which are places that the protocol designers have less control over. The alternative is having to wonder about what kind of identifying metadata the exchanges are leaking--and they're an easier target for an adversary. Also, I have to imagine that the everywhere-private nature of XMR is why I don't see it on my exchange's list, while I do see ZEC there. But I wasn't talking about that. With zero-knowledge proofs protecting the shielded transactions, your anonymity pool is essentially the entire set of people that use shielded transactions. With the Monero approach, your anonymity pool is large, but it's still a subset of the whole network.
- young_unixer 5y agoThis article summarizes the issues: https://lukesmith.xyz/articles/monero-and-other-privacy-coins https://lukesmith.xyz/articles/monero-and-other-privacy-coin...