5 ms·
Yes, transaction fees are a big problem. One possibility is to not pay any fees: currently, there is a social convention that if all outputs are 0.01 BTC or lar
by ezyang 14y ago
Yes, transaction fees are a big problem. One possibility is to not pay any fees: currently, there is a social convention that if all outputs are 0.01 BTC or larger, and so if we're not mixing too many addresses together, we can do the transaction for free. But once the intrinsic benefits of mining taper out, one would expect transaction costs to eventually become non-zero.
In this case, the transaction fee will have to be paid out of another wallet, not subtracted from the BTC involved in the transaction. Furthermore, this wallet must also be anonymous (e.g. to get anonymity, you must have some anonymity to begin with). But an important concern is how to pay for the transaction, when the size of Bitcoin you are anonymizing is about the same amount of the transaction cost anyway! One mitigating factor may be that it is really easy to find lots of participants willing to perform this mix, so a few benificient participants (who ostensibly want to be able to mix things) pay the entirety of the transaction fee for large, mini-mixes, and then uses the results of the mini-mix to pay for their bigger mixing.
- mindslight 14y agoI haven't fully thought this through, but why can't the protocol just be redefined so that the transaction incentive came out of each individual un-mixed input? Each party transferring a token would designate a fraction that goes towards the incentive. (Of course the quanta difference would would suck for multi-layer mixing, but I'd think some conventions could solve this) BTW what are the specific resource requirements of SMP sort using currently accepted crypto primitives? I didn't get into digesting the linked paper just to see if they were working towards something feasible or if they required akin to one public key op per boolean gate.
- ezyang 14y agoYou could this, but you would then be unable to mix any further, so the first mix must be sufficient to give you sufficient anonymity for the transaction you want to carry out. The resource requirements are not well studied, since none of the literature attempts to handle sorting larger than 32-bit integers. However, on order of minutes would be my expectation.