12 ms·
Mastering Monero: The future of private transactions [pdf] (2019)
- WrtCdEvrydy 3y agoCrypto content on HN... this is either gonna go really great or the opposite of that.
- jrm4 3y agoYup. It's always felt like there's a disproportionate amount of hate for crypto -- not that people should like it or love it, but that I'm surprised that tech people here don't appear to understand its inevitability. So it seems like they treat it as something to be killed (impossible) as opposed to something to buckle up and get ready to manage (more or less like they correctly do with AI.)
- birdyrooster 3y agoWe are so familiar with the technology we have actual informed opinions in either direction. The only dispassionate people are those who don’t know yet.
- jrm4 3y agoNot what I've seen here. This is one of the few topics here where I think emotion STRONGLY gets in the way of reason. Too few people are "first princpl-ing" this to understand that the crypto-train, to some extent, is happening whether any of us like it or not.
- tedivm 3y agoHonestly I hear this a lot from crypto advocates, but it just seems like wishful thinking on their part. There are a ton of legitimate complaints about cryptocurrency that come up, and the fact that after a decade the field still hasn't made any real progress is telling to me. At this point the "shitcoins" have mostly collapses, NFT has been devalued, and use cases seem to be disappearing. While I do think things like migrating away from proof of work have been helpful, I still don't believe that we're going to see larger adoption. I do think you are right that this is a topic where emotion strongly gets in the way of reason, but I think the people lacking reason are the advocates and not the critics.
- junofan 3y agoWhat progress do you want cryptocurrency to make? They’re bearer assets. You can go pay people with them today.
- imtringued 3y agoThe most obvious first step is to stop all initial coin offerings against money. If the cryptocurrency is a security, then that is ok, but there are some regulations that need to be followed. In the EU there are plenty of companies willing to manage a security token offering for your company. A security token is basically a cryptocurrency that acts as an informal stock.
- junofan 3y agoI don’t see what that has to do with cryptocurrency like Monero, the topic of this post.
- imtringued 3y agoThe problem with the cryptocurrency advocates is that they have zero clue about money. Neoclassical economics declares money irrelevant and not something to study, so there is hardly any research how money influences a society beyond central bank policy about how much money there should be. Here is a tip. Money is a transaction cost reducing device. That is it's primary function. By transaction costs I don't mean just fees that a bank or payment service provider charges you, no I mean every economic cost that is involved in negotiating payments. You could think of transaction costs as friction and money as a lubricant. If you have to exchange currencies this causes friction, if you have to physically transport goods or meet in person to barter with them this causes friction. If the value of the goods you are trading is unknown this causes friction. The purpose of money is to be better than some alternative world without money and most cryptocurrencies are hardly better, they are worse or outright useless. The legitimate niches that cryptocurrencies occupy will barely even influence the real world.
- jrm4 3y agoI 99% agree and and also argue that the 1% is significant. Money is sometimes that, but it's also merely a store of value. And I think this what people are missing. I agree that we're almost certainly not going to say paying for coffee in bitcoin. But where it has legs is as the 401k/money in the mattress replacement; a space that's still very "competitive," i.e. a lot of the options here still really suck, thanks to inflation and/or third parties.
- zirgs 3y agoIt's been almost 15 years. There's still no valid crypto use case outside of speculation and crime.
- mrangle 3y agoSpeculation is all that is required for validity. Parallel to barter, desire-to-use is all that is required for use-case. Governments are going to remain challenged by the need to now assert that possession or use of a legal instrument, with no inherent illegal characteristic, is now evidence of intent to crime. Not that I don't expect them to rise to the occasion. As they have been by implementing crude sanction power in place of legislation.
- toppy 3y agoCall it "programmable money" and we're good to skyrocket.
- tibbetts 3y agoI think of it as a bunch of bad early implementations that are being used for dubious financial purposes and outright fraud, fueling a bubble. The same could be said for joint stock corporations in the 1600s. Something can be inevitable (maybe it is maybe it isn’t) and the current situation can still be bad. Someone in the 1600s saying that joint stock companies are terrible, solve a problem that doesn’t really need solving, and are being used to rip off investors and fund unethical colonialism would have been right. It took a while before people used them in good ways. And even today they are questionable.
- psychoslave 3y agoNo hate, but no interest either. After all these years, all scam stories apart, what crypto allow its users to do that they would not be able to do otherwise with less resources? Really I don’t know, and I admit I never wanted to dig the topic as there are many other topic I will never have the time to learn and yet doesn’t seem to have such an issue of what is at best a tremendous noise/signal ratio.
- suslik 3y ago> what crypto allow its users to do that they would not be able to do otherwise with less resources International money transfers, for instance. The traditional banking system was always slow and expensive, and, on top of that, countries cut each other out due to geopolitical reasons. Many third-world countries have a decent crypto adoption, you can send someone money in a matter of minutes (I do).
- AlexandrB 3y ago> and, on top of that, countries cut each other out due to geopolitical reasons For a sovereign state this is a feature, not a bug. If you think that countries will take sending of funds to embargoed countries lying down you are sorely mistaken.
- suslik 3y agoSure, and that's exactly why sovereign states don't like monero and mixers - but that is their problem, not mine. Also, in many cases transferring crypto is not illegal - for instance, it is legal to transfer money to non-sanction banks in Russia, but in many countries, the banking system doesn't allow that. If you had a 90y.o. starving grandma there, you'd be grateful for the crypto.
- mrangle 3y agoVia sanctions, it is illegal for you to use specific mixers assuming you are a US citizen. Which does make it your problem. And if you have a mixer or private coin that isn't under sanction, it is only a matter of time as determined by the US gov's assessment of the risk of it being widely adopted.
- HideousKojima 3y ago>inevitability I think it's the crypto bros who misunderstand it's "inevitability." Crypto has far, far fewer practical applications than the people pushing for it it claim. There are two useful situations for crypto: 1) Where you need a trustless distributed consensus method or database (and where the Oracle Problem doesn't get in your way). Trustless is the key word here, 99% of the time that someone proposes a potential use for crypto it would be better served by traditional databases like Postgres, or traditional consensus algorithms like Raft, because being able to handle such things in a trustless manner isn't actually as desirable as crypto bros suggest. 2) Where you need to bypass financial regulations, sanctions, laws, etc. Crypto has shown some real utility for buying illegal drugs and guns online, for example. Whether or not you see this as a good or bad thing depends largely on your political leanings.
- alphanullmeric 3y agoBypassing financial regulations is indeed a great thing. It’s none of your business whether someone wants to trade derivatives or earn interest on their own money. Love it when supposed investor protections aren’t opt out, and then the surveillance infrastructure they put in place get used for tax enforcement or state sponsored looting of political enemies.
- nonameking2026 3y agoMaybe if you lived in some 3rd world countries - you could find more utility for it. Hyperinflation is the default for some countries, being able to keep some evil dictators from your money might be a good thing. F.x. instead of your money funding illegal wars in Libya you could save some of that wealth and try to build a better future.
- jrm4 3y agoOne could quite easily construct arguments that sound exactly like this, but for encryption and/or online anonymity, for what its worth.
- nicholasbraker 3y agoI think tech people are in the best position to judge that in most cases the technology doesn't bring any benefits that a current / non-ledger like technology doesn't bring already. Use-cases are few and far between. I doubt it's actually inevitable. (again some use cases are, especially in the utility realm)
- AlexandrB 3y ago> I'm surprised that tech people here don't appear to understand its inevitability. All progress depends on the "unreasonable man". I don't think it's inevitable at all, nor have I seen any evidence that it will be. Thus far non-government blockchains have proven to be ill suited for applications other than speculation (and crime). Central bank "programmable money" is definitely a threat - but it's hardly inevitable if popular opposition is vigorous enough. If you were to ask a tech enthusiast in 2010, they'd might you that 3D TVs were inevitable. Instead they fizzled out. Then there's "the Metaverse", which seems to be on bumpy terrain as well. SPACs seem to be doing not so hot[1]. Not every tech/financial trend sticks around if the value proposition isn't there. And the value proposition for cryptocurrency is very poor in my view. [1] https://en.wikipedia.org/wiki/Special-purpose_acquisition_company#History https://en.wikipedia.org/wiki/Special-purpose_acquisition_co...
- jrm4 3y agoYou should look harder for the evidence. 1% is all you need. There is a not-insignificant number of people using crypto to move and store money today. I agree A LOT of garbage is going to get shaken out, but this says to me "okay, what part/idea in crypto survives this bloodbath and gets bigger," not "throw the whole thing out."
- Yizahi 3y agoInevitable for law avoidance? Sure. We know quite well that humans like very much systems which allow them to avoid laws of any kind, so of course such a system will survive for a long time. Inevitable for lawful daily usage? Nope. Fundamental problems and lack of benefits will prevent blockchain based ledgers to be deployed in any useful scalable way. Actually not "will" but rather "did". Token proposals had a decade of time already and all failed (except for law avoidance of course). Any legitimate proposal has failed spectacularly: 1) Legal currency - failed due to no privacy, bad performance, atrocious UX, unstable exchange rate, shady providers; 2) Distributed storage - fail 3) Distributed calculator - fail 4) Distributed network (Helium) - fail 5) Smart contracts - neither smart nor contracts, very pricey, limited functions (on chain only), oracle problem unsolved 6) NFT - one big lie, impossible to implement any promise made about them because they don't facilitate transfer of the ownership 7) Supply chain ideas - fail, the problem is not securing the DB but securing the humans doing data input in the DB Anything else I've forgot? Basically most of the good ideas on paper turned out to be either impossible or impractical with blockchains.
- Eisenstein 3y ago> Anything else I've forgot? Going by the claims I have encountered: * Inflation proof/Store of value/Stock market hedge * Bringing banking to the poor * Web3 * Play-and-get-paid gaming
- landemva 3y agoAlso, preventing corrupt goverment and court from finding and stealing stored value.
- jrm4 3y agoNot daily and I think that's the thing. I suppose when one says "cryptocurrency," there are a lot of possible ways one might use it. I agree that for a daily driver, very unlikely. But "store of value" is still very much in play. Crypto as a competitor to the 401k or "money in the mattress" strikes me as damn near inevitable.
- imtringued 3y agoI don't see cryptocurrencies as something to be killed. I think the vast majority of them are illogical, based on wishful thinking and severe ignorance or outright scams. People will point out one among twenty thousand without realizing that the exception proves the rule. Yeah sure keep speculating on your "digital gold" I don't care. Unlike holding dollars as demand deposits or cash, you can't hijack the economy. You are accountable for the risks you take but that doesn't mean anyone is going to use Bitcoin or Ethereum to pay their groceries, especially since so many of the crypto credit card companies love operating in jurisdictions where they are completely unaware about the tax implications of their product. What a well thought out business model... Even though Europe/EU is embracing a regulatory framework for cryptocurrencies and making it easier to do business, crypto exchanges operate in regulatory safe havens, engage in shady practices or get hacked and lose your money.
- roenxi 3y ago> People will point out one among twenty thousand without realizing that the exception proves the rule. This argument doesn't hold well. Creating huge amounts of value is expected to be the exception rather than the rule - one of the powerful mechanisms at play here is this is an unusually free market where failure is cheap and all the money clusters to success. It is reasonable to ignore the thousands of failures. They failed because they were easy to ignore.
- landemva 3y ago>> this is an unusually free market where failure is cheap [public quick] The speed and amount of effort to innovate, by basically every demographic of persons, is breathtaking and exciting. Due to low startup costs (lack of gatekeepers), most will fail. That is okay, because the builders are not playing with super powder.
- 5350-uiop-1130 3y ago> its inevitability crypto's new paradigm is always just around the corner. i've been involved in cc for long enough to know that it's popularity (and price) are not driven by utility. as vb said, it's the linux of money. > step 1: install gentoo > step 2: install xmr wallet
- sircastor 3y agoI’m kind of surprised it made it to the top of the page. HN is certainly divided about crypto, not recently it has felt to me it’s slipped the wayside in favor of AI stories.
- StingyJelly 3y agoThere are aspects to hate about crypto but monero is not one of them.
- duckqlz 3y agoFrom the first chapter: “The first two chapters of this book are friendly non-technical intro- ductions to key topics and skills. For readers curious to learn more about behind-the-scenes details, chapters 3 and 4 contain conceptual non-mathematical explanations of Monero's privacy features and blockchain. Later chapters dive into complex technical details for understanding, developing, and integrating Monero.”
- helsinki 3y agoMonero is the only crypto I hold, really.
- diegoholiveira 3y agoWhy? Asking because I know nothing about crypto yet.
- HideousKojima 3y agoMonero is supposedly untraceable, or at least far harder to trace than Bitcoin, Ethereum, and other "traditional" cryptocoins. It's untraceability has made it receive even greater scrutiny and attempts to regulate it/ban it than other coins.
- saesdev 3y agoto me it's because I see how it's properties are valued by the markets it is transacted in, giving me enough safety that I can find a p2p seller to acquire some Monero without being identified (no-KYC), which then I do not risk being part of data leaks and becoming a target of attacks, and I am able to move some funds to a cold storage, which means funds I don't need to touch or connect its keys the internet, as I know in months or years from now I'll still be able to transact those as I need them, as it retains its properties and all coins are always interchangeable no matter where they come from (https://en.wikipedia.org/wiki/Fungibility https://en.wikipedia.org/wiki/Fungibility)
- lawn 3y agoMy main reasons: - Private by default. With most other cryptos you can see all transactions on the blockchain (although you'll only see address hashes instead of names). - ASIC resistant POW. Meaning you don't need specialized hardware to mine it but can do it with your PC (assuming it's fairly powerful). - Transactions are cheap and fairly fast. - Development is focused on the primary use-case of making transactions for payments, instead of making a "decentralized computing network" or similar.
- deleted 3y ago[deleted]
- nailer 3y agoMonero is cool - the ring signature mechanism is something i’d never heard of before. Its a way to be possibly, but not provably, be involved in a transaction. Ie plausible deniability. At real-world crypto recently the zcash people (MIT and Tel Aviv cryptographers) found a way to massively speed up the process of finding your balance (privacy chains are often very slow because they have to sum up all the transactions you were potentially involved in). I also want to do a deep dive into light protocol - which is a privacy mechanism on top of solana, so transactions go at reasonable speed and you can use mainstream dapps (solana has the most amount of developers outside eth and is a lot faster and cheaper).
- once_inc 3y agoI feel like Monero is in a tough spot. Not enough network effect to compete with Bitcoin, and new scaling layers like Arc and Lightning actively building out to provide privacy.
- bboygravity 3y agoThe network effect will come when the FED and ECB "save" everybody from their manufactured hyper inflation (give or take 2 years from now) through CBDC.
- mrangle 3y agoUnsure about the network effect, but you are spot on about the rest.
- jpmattia 3y agoI don't know why you're being downvoted, it's an entirely valid observation. And as I type, it's the only comment mentioning lightning as competition. Moreover, my greater sense is that the nuts and bolts of crypto is not an HN strong suit. It usually brings out religious-type arguments with little sense of balance. <sigh>
- saesdev 3y agoActually I think that thanks to Bitcoin coming first and being bigger, Monero is able to rise in its shadow, because bitcoin as a crypto people use is like giving governments a safe environment of still being in control, with its traceability and ASIC mining by corporations that can sanction addresses and etc, if Monero was the first ever cryptocurrency it would be way more regulated and attacked as a tool for criminals and would never reach mass adoption, so it's way easier to move from Bitcoin - the coin for social media and legal tender - to Monero - the anonymous alternative -, than from your regulated and enforced fiat currency to a "criminal coin" everyone is afraid to have, making it impossible to spend and use. If Bitcoin continues to grow, so will Monero
- kinakomochidayo 3y agoWell, except Lightning UX is horrible.
- qzx_pierri 3y agoI think Monero is awesome because it's actually designed to be an anonymous payment system. Unlike Bitcoin, anonymity is built into each transaction. No need for washing your coins via sketchy "tumbler" services.
- capableweb 3y agoI think Bitcoin is awesome because unlike cash, digital transfers are built into the system. Now, just like cash wasn't built with digital transfers in mind, neither was Bitcoin built with anonymity in mind, so not sure why Monero would be better/worse than Bitcoin for a thing Bitcoin was never made for in the first place. The purpose of Bitcoin was never that all transactions were anonymous. Monero is great for this (or zCash), but it's a bit misleading to say Monero is "better" at something when what you are comparing it to, was never built for that "something" in the first place.
- candiddevmike 3y agoUnlike cash, Bitcoin keeps a public log of everything you've bought though.
- Koshkin 3y ago> you For some definitions of "you"
- lawn 3y agoAnonymity is absolutely an integral part to digital transfers.
- johtso 3y agoReally not sure what you're trying to say here. People use Bitcoin for anonymous transactions and jump through various hoops to try and achieve this goal (for example using tumbling services). It seems perfectly valid to say Monero is better for anonymous transactions than Bitcoin. I'm not sure why it matters what it was "made for". All that matters is what it is used for in practice. This does not seem like a misleading statement.
- StingyJelly 3y agoYou probably should add the year (2019) to the title. It's still a great book that made me understand ring signatures. Everything is well explained but some bits may be outdated (eg. monero now uses randomx for ultimate asic resistance.)
- EscapeFromNY 3y agoMonero is perhaps the only cryptocurrency that both works as advertised, and has gathered a self-sustaining userbase. No $20 transaction fees. No influencer pump and dumps. No VCs who need to extract value. No fork drama. No unrealistic roadmap. No charismatic leader boiling the frog with scope creep. It's not trying to be an investment. It's actually private. It's actually anonymous. This is all a lot of us ever wanted from a cryptocurrency.
- trw_phy 3y ago[flagged]
- ur-whale 3y ago> No charismatic leader boiling the frog with scope creep. LOL > It's actually private. It's actually anonymous. This is all a lot of us ever wanted from a cryptocurrency. Yes indeed. I sometimes daydream Satoshi knew about ZKP's early enough to integrate it into Bitcoin ... we would have had the perfect storm. > No $20 transaction fees. This one isn't a structural guarantee of Monero, but rather a side-effects of being a late-comer to the game. In other words, it might come to pass that tx fees get in the $20 range. EDIT: > This is all a lot of us ever wanted from a cryptocurrency. Agreed, except maybe for this: I've come to value the finite supply of Bitcoin more than it's value/usefulness as an actual currency. I initially loved the idea of cryptocurrencies as a currency that would be used in everyday life. I've changed my stance on this completely: I think that Bitcoin (or something like Monero, with indeed a neat advantage over BTC) is way more valuable as a financial instrument with is own unique characteristics and super-sharp edges than it would ever be as a currency
- tromp 3y ago> I've come to value the finite supply of Bitcoin more than it's value/usefulness as an actual currency. I think finite supply is overrated [1] ... [1] https://john-tromp.medium.com/a-case-for-using-soft-total-supply-1169a188d153 https://john-tromp.medium.com/a-case-for-using-soft-total-su...
- m348e912 3y ago
- roenxi 3y agoMight also consider https://www.getmonero.org/library/ https://www.getmonero.org/library/ which has links for both both Mastering Monero and the more technical "Zero to Monero" [0] where they go through the maths in detail. Monero really is quite something. It is eye opening to realise there has never been a situation where one person could simply transfer wealth to someone else without anyone in the middle being able to say No. A powerful tool for liberty. [0] https://www.getmonero.org/library/Zero-to-Monero-2-0-0.pdf https://www.getmonero.org/library/Zero-to-Monero-2-0-0.pdf
- ur-whale 3y ago> It is eye opening to realize there has never been a situation where one person could simply transfer wealth to someone else without anyone in the middle being able to say No. Well, this is what the promise of Bitcoin was, but the lack of anonymity in BTC missed the mark by a few inches. Monero (and it's competitors: ZCash, Grin, Beam, MWC, ...), which IIRC uses the Mimblewimble [1] principle to preserve anonymity) bridged that gap a few years after BTC was launched, but by that time, Bitcoin had already grown to a huge size. What I would really like to see in terms of innovation in the crypto world is Mimblewimble being actually added to BTC or ETH. Things would get truly interesting. OTHO, if BTC and ETH had Mimblewimble, they might become a much bigger targets for folks that stand to benefit from controlling free economic transactions between people (governments, etc ...), so who knows, the lack of ZKP in BTC/ ETH might be a blessing in disguise. [1] https://www.coingecko.com/learn/what-is-mimblewimble https://www.coingecko.com/learn/what-is-mimblewimble
- tromp 3y agoGrin and Beam use Mimblewimble, but Monero uses ring signatures to obscure the transaction graph (with every real input hiding among 16 decoys), and Zcash uses ZK-SNARK zero knowledge proofs [1]. This makes the latter two chains grow at a much faster rate [2] and leaves nodes unable to identify the UTXO set of unspent outputs, making them more resource intensive. [1] https://electriccoin.co/blog/explaining-halo-2/ https://electriccoin.co/blog/explaining-halo-2/ [2] https://forum.grin.mw/t/scalability-vs-privacy-chart/8114 https://forum.grin.mw/t/scalability-vs-privacy-chart/8114
- tikkun 3y agoWhat's considered better these days: Monero or Zcash, and why?
- nailer 3y agoThe researchers involved in zcash are a combo of DJB acolytes (in a good way) and Tel Aviv infosec researchers. Plus Ed Snowden was one of the people that participated in their keygen ceremony. * * Slightly off topic, wikipedia for zcash is terrible, it's written by people that don't understand that a 'ceremony' is part of any asymmetric cryptosystem from your Linux package manager to the CA that signed the cert for the website you're looking at.
- lawn 3y agoOpt-in privacy is poor because most people don't bother, and this drastically reduces the privacy for those that do. Even if something has perfect privacy features, this alone is a deal-breaker. With Zcash you get opt-in privacy, with Monero it's enforced with every transaction, for everyone.
- saesdev 3y agothere's way more to those crypto than just privacy, Zcash for example is moving to proof-of-stake, they also want tokens and smart contracts on their chain, while Monero is focused on also being more broadly distributed/decentralized, and harder to take down, with a CPU based proof-of-work to enforce that
- vitehozonage 3y agoZcash has directly admitted that it already had a catastrophic inflation bug [1]. Nobody can prove if it has been hyperinflated by an attacker. Developers linked to DARPA and the Israeli government had the knowledge, capability and opportunity to do so - do you trust them? https://forum.zcashcommunity.com/t/zcash-counterfeiting-vulnerability-successfully-remediated/32671/39 https://forum.zcashcommunity.com/t/zcash-counterfeiting-vuln...
- deleted 3y ago[deleted]
- mrangle 3y agoInvesting in a coin for the purpose of privacy is not a good investment. This is because the government has to criminalize every private currency and privatizing method with any significant use. If it hasn't been criminalized yet, it is just because they haven't yet gotten around to it. I'm not saying that one can't hope for privacy. Only that the investment risk is extremely lopsided in this moment. Expect that the government can ramp up their criminalization efforts faster than a coin can reach escape velocity should its use become more common. Private coins may be inevitable, but it is going to be a bumpy road to get there. Bitcoin has absolutely capitalized on giving the impression of privacy, to those (most) not paying full attention, while offering the opposite. Without privacy, DCs are worse than cash unless you feel that you are under threat of seizure or you have a plan to abscond across borders sometime soon.
- lawn 3y agoThe biggest issue with cryptocurrencies is that people always seem to only view them as an investment, instead of what usage they may have.
- mrangle 3y agoI was using "investment" as a catch-all for both speculation and use. As in one "invests" dollars into BC with either the intent of selling it for cash later, or the intent of eventually using it. See "with any significant use" in my second sentence.
- ponymontana 3y agoWhen someone try to hardfork bitcoin, bitcoin remain the same and the new fork is just a fork of bitcoin. Network effect and convergence over the open standard in action; the edge that protects bitcoin. When someone forks monero, the new fork is called "monero" and all the small userbase moves over it. The old chain simply dies. No network-effect to resist changes because theres no network at all compared to bitcoin. Same for all the crypto. Its absurd to save money in monero or in all the crypto where someone can easily move the inexistent userbase and do hardforks. But if you cant save because the expected value of the cryptos over time is zero, what is the meaning of exchange these assets? All crytpos that are not bitcoin (even monero) can only work on the informative asimmetry where some people ignore these facts and, scammed by promoters, holds these non-sense assets expecting returns that will never come. The promoters, instead, will make money dumping on them.
- lawn 3y agoThis betrays a complete lack of understanding of hardforks in Monero. Whenever Monero upgrades to new consensus rules they indeed do so via a hardfork, but that only works because there's social consensus (both economic and mining wise). If the consensus would be to stay with the original rules, people would (and it has happened before). Even in Bitcoin this works, and Bitcoin has even hardforked before! The difference is that in Bitcoin people want to stay on the original chain. Keeping money in Monero is safe because you'll still keep the money after the hardfork, that's just how they work. This is just Bitcoin maxi nonsense scary talk.
- Taek 3y agoGoing to mention this as a top level comment because a lot of people here seem to believe that Monero is an anonymous cryptocurrency. Unfortunately, techniques to break Monero's anonymity have been known since 2018, and these techniques are effective at breaking essentially any partial-mixing based cryptocurrency. (Monero, Lelantus, CoinJoin, Wasabi, etc). Initial attacks (famously The Flashlight Attack) were capable of breaking the anonymity of targeted individuals, but this attack was later generalized (by me) to break everyone. These attacks never got a lot of coverage but they are highly effective. The only way to get strong on-chain privacy is to use a full-anonymity cryptocurrency like Zcash. https://slideslive.com/38911785/satoshi-has-no-clothes-failures-in-onchain-privacy https://slideslive.com/38911785/satoshi-has-no-clothes-failu... https://gist.github.com/DavidVorick/0dbd4906bfa50b7d8dba23f7665598a2 https://gist.github.com/DavidVorick/0dbd4906bfa50b7d8dba23f7... The general idea behind each of these is that you can identify people by doing math that essentially asks "what is the likelihood that these N outputs are this close together in the transaction history graph" - and the answer ends up being "cryptographically unlikely" after just a handful of transactions from the same party. The privacy decays unexpectedly quickly. I never formalized the math but iirc you can get enough evidence to be convinced that two different transactions were by the same person after they spend something like 3 outputs total. The math is really nasty. The only fix we know of is to switch to full anonymity systems. The privacy break is exponential in strength, and therefore even systems like Lelantus that use mixin sizes of >50,000 outputs fail to provide meaningful anonymity.
- deleted 3y ago[deleted]
- fastball 3y ago> I never formalized the math Formalizing the math seems very important to underpin a bold claim such as this one.
- lordofgibbons 3y agoIf that's the case, why does the IRS still have a $625k bounty for anyone who can defeat monero's anonymity features? And why have you not collected your money? https://www.forbes.com/sites/kellyphillipserb/2020/09/14/irs-will-pay-up-to-625000-if-you-can-crack-monero-other-privacy-coins/?sh=1e3213285cc8 https://www.forbes.com/sites/kellyphillipserb/2020/09/14/irs...
- serhack_ 3y agoDespite the name, I'm the author! Ask me anything :)
- Frisiavones 3y agoWill you make an updated version?
- serhack_ 3y agoOf course :D working on it right now
- Frisiavones 3y agoLooking forward to buying the paperback mate :)
- lucabs 3y ago[dead]
- chalanero 3y agoTwo questions: 1. Best monero wallets? 2. How to develop for monero? Links?
- joreto 3y ago1. https://www.getmonero.org/downloads/ https://www.getmonero.org/downloads/ 2. https://www.getmonero.org/resources/developer-guides/ https://www.getmonero.org/resources/developer-guides/ Or just join libera.chat (IRC) and hang in #monero-dev