Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ewillbefull
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
ewillbefull
10y ago
Disclosure: I am an engineer working on Zcash. Anonymity is not a binary. Monero, even with the addition of RingCT, is vulnerable to transaction graph analysis (intersection attacks) that can de-anonymize users. Zcash takes a completely dif
32.
▲
by
ewillbefull
10y ago
That's not the full picture. Zcash has a "mining slow start" which slowly ramps up the mining reward for the first two weeks, to reduce the threat that a large amount of the ultimate monetary base would be in control of early
33.
▲
by
ewillbefull
10y ago
> Zcash requires two states, a state analogous to bitcoin, and the anonymous zcash state which has to be explicitely opted into. It does not require two states, this is a misconception that originates from the paper which refers to "
34.
▲
by
ewillbefull
10y ago
> ZCash's blockchain is a black box and requires you to not only trust them with your anonymity You do not trust anyone with your privacy in our system. Assuming you're talking about our zk-SNARK parameters, if they were not se
35.
▲
by
ewillbefull
10y ago
The stolen coins are unspendable for the time being due to the design of the contract.
36.
▲
by
ewillbefull
10y ago
Can you give some examples?
37.
▲
by
ewillbefull
11y ago
I think the tooling will improve significantly this year and you should see people able to build protocols with zkSNARKs soon -- without spending days figuring out how everything works. Ahmed Kosba has been working on jSnark ( https:/&
38.
▲
by
ewillbefull
11y ago
Thanks! In this case, the Zcash team did build the first zero-knowledge contingent payment, but we performed it on the Bitcoin network.
39.
▲
by
ewillbefull
11y ago
The simple explanation -- which I unfortunately left out of my slides but did elaborate on during my talk -- is that Bitcoin has a way for you to send money to someone contingent on them producing the preimage of a SHA256 hash. The remainde
40.
▲
by
ewillbefull
11y ago
In this particular ZKCP case we use zk-SNARKs because they're fast and they exist, but theoretically we do not need their "non-interactivity" properties.
41.
▲
by
ewillbefull
11y ago
Additionally, lightning actually uses the HTLC (Hashed Timelock Contract) transaction style that is used by ZKCPs. I believe it is used to extend lightning channels to multiple hops.
42.
▲
How White Hat Hackers Stole Crypto Keys from an Offline Laptop in Another Room
(motherboard.vice.com)
3 points
by
ewillbefull
11y ago
|
0 comments
43.
▲
by
ewillbefull
11y ago
I haven't used Apple software in a long time, but Google is not immune to this either apparently. If you use the YouTube app, and especially if you use Chromecast, you'll experience countless bugs as it fails to reconcile state ch
44.
▲
by
ewillbefull
11y ago
One of the most important properties of Zcash is "selective disclosure." Effectively, you can audit and perform proofs-of-solvency with the same security as in other cryptocurrencies. But yes, if someone on the inside "steals
45.
▲
by
ewillbefull
11y ago
This video should give you a better idea of how anonymous Bitcoin is. https://www.youtube.com/watch?v=AypRF9q0llU There are also several startups dedicated to performing Bitcoin blockchain analysis for this specific purpose
46.
▲
by
ewillbefull
11y ago
Virtually everyone involved in Bitcoin's development is also well-known and presumably "coerceable." The company makes no difference as far as I can see.
47.
▲
by
ewillbefull
11y ago
> Or does the 'spend' merely provide a zero knowledge proof that the funding was legitimate? This. :) (Alongside a demonstration that it wasn't spent before.)
48.
▲
by
ewillbefull
11y ago
The actual setup of the parameters hasn't occured and will use a much more secure construction which isn't complete yet. The software is still in alpha.
49.
▲
by
ewillbefull
11y ago
Zcash is planning to use a new multi-party trusted setup scheme that allows a group to securely compute the mathematical structures necessary to protect the zero-knowledge proof integrity. (Secure Sampling of Public Parameters for Succinct
50.
▲
by
ewillbefull
11y ago
"Buckets" contain cryptographic trapdoors which are necessary to witness spendable value. The sender constructs them and encrypts them with an IND-CCA2-secure key and places it inside the transaction. Only the recipient should be
51.
▲
by
ewillbefull
11y ago
Buckets are basically Coins from the original paper. It was changed because a `Coin` implies things that it actually isn't, but bucket is an even worse name, so it'll probably either be called Coin again or perhaps "pour outp
52.
▲
by
ewillbefull
11y ago
Monero and other ring signature schemes can only feasibly "mix" your transactions with a small number of previous transaction outputs, opening the door to statistical attacks. Zcash mixes your transaction with every previous trans
53.
▲
by
ewillbefull
11y ago
I don't understand this complaint. If the company that is launched fails or is attacked, the currency and the code can live on without it. Its development probably wouldn't be as well-financed but that's about it.
54.
▲
by
ewillbefull
11y ago
That's a dumb, deliberate misreading of my comment and a ridiculous jump to conclusions. I have done nothing illegal. I said clearly that I made _one_ transaction (a wire transfer) and I said clearly that they questioned me on my incom
55.
▲
by
ewillbefull
11y ago
Same here. I've been through the KYC loops and I know how invasive they have to be occasionally. Coinbase took it to another level.
56.
▲
by
ewillbefull
11y ago
No, I didn't conduct any illegal transactions. I thought that would be obvious from my second comment. Somehow you believe I would waste my time complaining about Coinbase yet be at clear and obvious fault?
57.
▲
by
ewillbefull
11y ago
They only appear to care about the customer experience when someone complains on social media, until then they have a history of being jerks to their users. They closed my account after I made a (relatively small) wire transfer after not us
58.
▲
by
ewillbefull
11y ago
You can now use Bitcoin anywhere VISA is accepted, so long as coinbase doesn't close your account, ignore you and close all the tickets you open. Even if you painstakingly collect and compile sensitive documents for them to review, whi
59.
▲
by
ewillbefull
11y ago
The way you phrase it makes it seem like the parties involved are perpetually at risk of being compromised, as though they must retain and store the secrets necessary for parameter generation forever. When in fact it will be done once, and
60.
▲
by
ewillbefull
11y ago
Selective disclosure means you decide who can see your transaction information (value, recipients, etc.) and that it's not publicly knowable by default.
More ›