8 ms·
An incomplete guide to stealth addresses
- tolani_somoye 4y agoRead vitaliks article, not sure how to feel about it yet.
- Animats 4y ago[flagged]
- mnd999 4y agoOf course it does. That’s a large chunk of the model.
- yokem55 4y agoMoney laundering is a crime that (ab)uses privacy. But privacy is not in itself a crime.
- dleslie 4y agoGiven the uses for crypto in practice, it's a safe bet that the majority of use will be for illegal activities.
- nobody9999 4y ago>Given the uses for crypto in practice, it's a safe bet that the majority of use will be for illegal activities. For the moment, that appears to be a good bet. I'm not aware of any current practical use case for cryptocurrency, that government-backed currencies don't provide, other than purchasing illegal goods and services. That said, government-backed currencies are also used for doing so as well, except cash transactions require physical proximity while cryptocurrencies do not.
- mhluongo 4y agoSending money is a pretty clear use case. Ukraine received a bunch of international crypto donations last year, for example. Your lack of imagination doesn't mean something is just for "illegal activities".
- RandomLensman 4y agoUkraine uses(used) normal funding markets and is accessible via standard transfer avenues. Not sure why crypto is needed - certainly billions being transferred to Ukraine are not in crypto.
- pcthrowaway 4y agoI actually think there are plenty of legitimate uses of cryptocurrency, and that it is being used in those ways today. But the Ukraine example is a strange one to me, only because I'm unclear on the legality of funding the war efforts of another country.
- nobody9999 4y ago>I actually think there are plenty of legitimate uses of cryptocurrency, and that it is being used in those ways today. Absolutely. I never said anything that contradicts that statement. Rather, I pointed out that the majority of those legitimate use cases are currently better served with the global financial system. And as such, the current, practical* use cases for cryptocurrency are as a medium of exchange for goods and services that governments frown upon. I make no judgement as to whether that's good or bad, just that it is. I'll remind you that I said currently, not forever, not it's just a scam, not everyone who touches cryptocurrency is a criminal and most certainly not there are no legitimate uses for cryptocurrency; Just that currently the most compelling use case for cryptocurrency is as a medium of exchange for "illegal" goods and services. Most (not all, I'm not being categorical here) other use cases are currently better served via the global financial ecosystem based on government-backed currencies.
- dmitriid 4y ago> Ukraine received a bunch of international crypto donations last year, for example. That they can surely use, right, right? Because all that crypto can be easily used for buying stuff, right? right? In reality it looks like those donations were laundered through an offshore exchange. Someone will always find ways to profit from war.
- pjkundert 4y agoEquating the desire for privacy with criminality says more about you than the object of your contempt.
- jcpham2 4y agoSounds like Monero/zcash being appropriated by Ethereum If appropriated is to harsh, how about integrated instead?
- DennisP 4y agoMonero uses ring signatures, which as far as I know haven't gotten much traction on Ethereum so far, since gas payments undermine their privacy. Zcash uses zksnarks, which have advanced considerably since Zcash launched. Ethereum's zkrollups use more recent types of zksnarks. Stealth addresses "using elliptic curve cryptography were originally introduced in the context of Bitcoin by Peter Todd in 2014," according to Vitalik's post.
- deleted 4y ago[deleted]
- dumbfoundded 4y agoThis is already doable with most wallets today. Most wallets enable you to create 2^64 addresses from the same seed phrase. These are hardened and can't be linked together by just creating them. So if Alice wants to send Bob an NFT, Bob creates a new address (recoverable with the same seed phrase) and Alice sends it there. Bob can then fund the wallet with tornado cash to use the NFT. It's a stupidly complex way to achieve privacy and Tornado Cash is illegal. That's why we need private by default chains like Aztec & Aleo
- tromp 4y agoThat seems different though, since Bob needs to give out a new address for each transfer. With stealth addresses, once Bob published his public address, multiple senders can transfer to Bob without further interaction by Bob.
- monero-xmr 4y agoTornado cash is illegal for US citizens. Not illegal for anyone else. And a lawsuit against the overreach of the Treasury department will likely make it legal again.
- woodruffw 4y agoWhat exactly is the "overreach" argument? In terms of statutory authority, the Treasury hasn't done anything particularly unusual in adding a known money-laundering vehicle to the OFAC list.
- monero-xmr 4y agoAll tornado notes generate a proof that you can use to show where it came from. It’s the same as monero, another privacy coin which is not illegal. There is a long list of issues here but tornado is just a program. The users of that program can use it for good or bad. They sanctioned the creators and Tornado is still chugging along. It’s equivalent to banning cryptography because money launderers encrypt their messages. Here is a good summary of the argument against Treasury by Coin Center https://www.coincenter.org/coin-center-is-suing-ofac-over-its-tornado-cash-sanction/ https://www.coincenter.org/coin-center-is-suing-ofac-over-it...
- zaroth 4y agoStealth addresses are super simple bit of crypto and also pretty easy to implement. When Peter Todd wrote a paper describing the technique for Bitcoin in Jan 2014 I wrote the first implementation. [1, 2] At the time I wanted to call them re-usable addresses, because the published address by the person wanting to receive funds is truly and privately re-usable. This is super useful for writing static addresses in places (like GitHub pages or on business cards) which don’t implicitly divulge the full transaction history for that address. So for example taking donations for your open source project without having to show a public record of all those donations. The trade-off of not having to provide a server for generating one-time addresses is that the receiver has to scan the whole blockchain and perform a bit of work to check if each one might actually be for them. Anything you do to reduce this scanning burden also reduces the privacy of the scheme, necessarily. So although the usability of the paying semantics are fantastic, the usability of receiving requires network and computation. Typical PIR trade-off. However, one thing I really love is that on the receiving side you can have just one private key which will allow you to discover all sent funds. Under the hood on the blockchain no addresses are actually being reused. So you have to scan for your funds, but they will all be there with just one key to keep secure and one public address that can be “paid-to” without being able to actually lookup any transactions that were actually sent to that address. I don’t know if they ever standardized an address form to use this scheme in Bitcoin but in my opinion it is a really fantastic way to use a public blockchain. At the time, I tried and failed to write the receiver-side scanning code into bitcoind because I didn’t know enough C++. [1] - https://www.mail-archive.com/bitcoin-development@lists.sourceforge.net/msg03613.html https://www.mail-archive.com/bitcoin-development@lists.sourc... [2] - https://gist.github.com/jspilman/8396495 https://gist.github.com/jspilman/8396495
- Gigachad 4y agoThis reminds me of how bitmessage works. You'd not know if a message was for you without trying to decrypt it so you just attempt to decrypt every message. They reduced the burden by using "streams" where your address might be on "stream 7" and everyone could tell a message was for stream 7 but not who for on that stream. So you'd only have to decrypt everything on the stream your address is on. With the more users being on a stream, the more anonymous it is but the more network and cpu work it is.
- EGreg 4y agoThe EVM can actually check digital signatures, hashes, lamport signatures etc. The problem is that once Bob actually spends something from this address, everyone knows that Bob controls the address. Because if Alice can calculate an address for Bob, so can anyone else.