Live data from Hacker News

Keybase chooses Zcash

keybase.io

101–110 of 167 posts

Re: Keybase chooses Zcash

#101
post #95
post #81

Earlier quoted context omitted.

The Monero blockchain is comprised of inputs and outputs - public keys/one-time addresses to power of 10 denominated amounts into which each transaction is split and mixed with past public keys of identical power of 10 amounts. There are no 'orthodox' addresses on the blockchain which can be linked to transactions or to an identity.

That's just a misunderstanding of inherent blockchain limitations. It's very easy for me to reveal a bunch of addresses on the Monero blockchain. Step 1: make a bunch of addresses Step 2: the world know it was you That reduces the anonymity set for everyone else. They thought they were mixing with you anonymously but now that you are revealed, your participation in the mixing is useless, people would have done better…

What you're talking about has already been covered in research by the Monero Research Lab: https://lab.getmonero.org/pubs/MRL-0001.pdf and https://lab.getmonero.org/pubs/MRL-0004.pdf

Basically, unless you own 80% of the outputs on the blockchain you don't have enough to identify subsequent transactions, so any foothold you gain in owning outputs becomes rapidly weaker. Given the cost of owning 80% of the blockchain outputs, it's not an attack that is particularly effective even at Monero's current state of usage.

Individuals who publish their input history won't make any significant difference.

Re: Keybase chooses Zcash

#102
post #55

Author here. Seeing some of the discussion go down on Twitter, I feel maybe I should explain further the "white supremacist" example in the post. (one tweet at me: "So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example.") When I shared a draft post with some friends, a lot of them had an ah-ha moment, so I was hoping for the same from others. I was trying to illustrate 2 pr…

Have you considered supporting a stealth address scheme for Bitcoin? The problem is reuse of addresses, period. Bitcoin has solutions for this.

Zcash's anonymous transactions are much more expensive CPU-wise to verify and aren't pruneable, and the cryptography behind it has been much less reviewed (Bitcoin operates on a bunch of very boring standard already established and long-trusted algorithms in comparison!), so I'd be surprised if an established project like Bitcoin adopted them before they were proven in practice. There's a lot of money tied up in Bitcoin, so the project is going to be pretty conservative in how it chooses to change.

Re: Keybase chooses Zcash

#103

Author here. Seeing some of the discussion go down on Twitter, I feel maybe I should explain further the "white supremacist" example in the post. (one tweet at me: "So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example.") When I shared a draft post with some friends, a lot of them had an ah-ha moment, so I was hoping for the same from others. I was trying to illustrate 2 pr…

So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example. But no one has a problem with the meth cook example??

Im not so sure why it has to be a "white supremacist" as opposed to "career criminal", "wall street husker", "hong kong gangster" or "isis radical".

very interesting choice. i can only guess the political affiliation of this author.

when i was in my formative years everyone was trying to shake labels and thus the stigmatism associated with them. and thats really what the civil rights leaders of the 60s stood for. its a shame that the movement has been subverted by corporatists and sycophants. you all lost me. and many others.

Re: Keybase chooses Zcash

#104
post #98

5 hours and almost 100 comments later no one has pointed out that Zcash and Keybase share the same investors. I am relieved that 'Keybase chose Zcash' purely on merit after an exhaustive and objective selection process, and that this potential conflict of interest is transparently disclosed in the linked adverticle - wait, they did no such thing. Does it concern no one that this security-focused company is shilling f…

I couldn't decide whether to up- or downvote this: it sounds like equal parts 1) information worth bringing to people's attention and 2) slandering a team that seem really nice fellas to me. So I looked both companies up on CrunchBase, and can find zero overlap between investors declared there. Where did your information come from?

Re: Keybase chooses Zcash

#105
post #98

5 hours and almost 100 comments later no one has pointed out that Zcash and Keybase share the same investors. I am relieved that 'Keybase chose Zcash' purely on merit after an exhaustive and objective selection process, and that this potential conflict of interest is transparently disclosed in the linked adverticle - wait, they did no such thing. Does it concern no one that this security-focused company is shilling f…

No. I wish they were more open about it, (if that's really the case!) but why would it concern me? Then again I don't see zcash as fundamentally questionable, so that may be the difference.

Re: Keybase chooses Zcash

#106

Earlier quoted context omitted.

So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example. But no one has a problem with the meth cook example??

Im not so sure why it has to be a "white supremacist" as opposed to "career criminal", "wall street husker", "hong kong gangster" or "isis radical". very interesting choice. i can only guess the political affiliation of this author. when i was in my formative years everyone was trying to shake labels and thus the stigmatism associated with them. and thats really what the civil rights leaders of the 60s stood for. its…

Im not so sure why it has to be a "white supremacist" as opposed to "career criminal", "wall street husker", "hong kong gangster"

Maybe because those examples are from the 80's?

i can only guess the political affiliation of this author.

And his drug of choice, I suppose?

Re: Keybase chooses Zcash

#107
post #98

5 hours and almost 100 comments later no one has pointed out that Zcash and Keybase share the same investors. I am relieved that 'Keybase chose Zcash' purely on merit after an exhaustive and objective selection process, and that this potential conflict of interest is transparently disclosed in the linked adverticle - wait, they did no such thing. Does it concern no one that this security-focused company is shilling f…

I couldn't decide whether to up- or downvote this: it sounds like equal parts 1) information worth bringing to people's attention and 2) slandering a team that seem really nice fellas to me. So I looked both companies up on CrunchBase, and can find zero overlap between investors declared there. Where did your information come from?

http://archive.is/wdNh3

http://archive.is/vnmkv

Re: Keybase chooses Zcash

#108
post #68

Earlier quoted context omitted.

I do not understand all of the details behind Monero, but basically the privacy is incomplete. When you spend money, you basically say "I am one of X people", where X is usually fairly small. It's a lot better than Bitcoin where X=1, but it's still something that advanced algorithms can get though, and it still collapses if enough people have their identities and transactions revealed. In Zcash on the other hand, you…

You're almost there, but not quite. Since Monero outputs go to dual-key stealth addresses, outputs are effectively paid to a random 256-bit "address". So if you use a mixin of 50, in a transaction with 1 input, an external observer can say "this illicit transaction spends funds from 1 of 50 possible transactions", but then you need to go to those 50 and work your way back till eventually you find a needle, in a very…

I like both Monero and zCash. As technologies they both have different advantages and they are both pushing the state of the art in privacy cryptocurrencies. As a researcher it makes me optimistic that we are pursuing multiple paths to the goal of "digital cash".

>Using zCash requires 8gb+ of RAM, and takes over a minute on a Xeon processor.

Cryptography in this area is rapidly advancing, we have seen dramatic speed ups in zkSNARKS (cryptography behind zCash's anonymity) over the last few years and the launch of zCash will probably accelerate this trend.

> it's limited to the people moving from traceable addresses to z-addresses who haven't identifiably moved ~the same amount out.

This number, X, is growing and will continue to grow.

>ZCash is useless at best, dangerous privacy theatre at worst.

zCash is an excellent and exciting experiment. It is not a very mature platform (it has only been live for a month), but that doesn't mean it will never been mature.

Re: Keybase chooses Zcash

#110

Author here. Seeing some of the discussion go down on Twitter, I feel maybe I should explain further the "white supremacist" example in the post. (one tweet at me: "So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example.") When I shared a draft post with some friends, a lot of them had an ah-ha moment, so I was hoping for the same from others. I was trying to illustrate 2 pr…

yeah that's how skyline is black listing journalists in conflict zones as terrorists judging from geo data[1].

they do this because they can justify their data derivative, but if there's no trace data to justify semi-justifiable decisions, such disastrous inferential machines would be impossible to justify.

it's a tricky case - but it would force law enforcement - and other parties of interest - to actually investigate before pulling triggers.

[1]: http://arstechnica.co.uk/security/2016/02/the-nsas-skynet-pr...

Post reply on HN