Live data from Hacker News

80% of Monero Transactions Trivially De-Anonymized

ipfs.io

51–60 of 88 posts

Re: 80% of Monero Transactions Trivially De-Anonymized

#51
post #6

Amiller, Figure 1 should show that the overwhelming majority of Zcash transactions have the privacy properties of Bitcoin transactions (or worse). No? It seems kind of imbalanced to have an analysis which emphasizes the security compromises caused by older monero (pre-CT, pre minimum mixin count) while ignoring the ongoing privacy flaw in Zcash usage in practice.

> should show that the overwhelming majority of Zcash transactions have the privacy properties of Bitcoin transactions (or worse). Agreed, this should updated to specify that only transactions between shielded addresses are protected. The point they are trying to make is that the anonymity set between shielded addresses is that of all transactions in the anonymous set. (FWIW, this is a pre-publication draft.) > No? I…

> The point they are trying to make is that the anonymity set between shielded addresses is that of all transactions in the anonymous set.

This way of stating is somewhat questionable in light of the claims in the second half of the paper.

What is shown in the second half of the paper is that all possible sources are not equally likely and this most probably applies to Zcash (and every other coin) as well. In the Figure 1 illustration of Zcash, it is most likely that the rightmost (most recent) arc is the correct one. Of course this can't be stated with certainty in either coin.

Another way of interpreting the trend shown in Figure 8 is that Zcash gains little (though of course it still gains something) from including all transactions in the anonymity set (arbitrarily far to the right) because once one departs from focusing predominantly on the more recent transactions, the effective anonymity set does not grow much.

> Instead, it looks like clients weren't even doing basic checks:

>> We find that among Monero transaction inputs with one or more mixins, 62% of these are deducible, i.e. they can be incontrovertibly linked to the prior TXO they spend.

There are no basic checks that can solve that issue. It was fixed in a different way.

> even if Monero fixes everything in this upcoming release,

Most of the issues in the paper were already addressed in the past, and the paper says this. The remaining issue is the time bias which the paper states has already been improved, but can be improved further.

Re: 80% of Monero Transactions Trivially De-Anonymized

#53
post #29

Disclaimer: I hold Monero In my opinion, this is an attempt at smearing a better cryptocurrency competing for the same recognition: true anonymity. It could very well be the tip of a broader, coming attack. The developers of other cryptocurrencies are spending money for marketing and acceptance into exchanges, Monero is not. They are willing to grease the wheels to success while Monero grows organically instead. This…

Regardless of the veracity of your allegations, this paper is a sound empirical analysis. It's a solid piece of research, and it's not surprising that folks from a competing blockchain would be the first to unveil real problems with Monero.

> the first to unveil real problems with Monero

It is not. The problems were previously identified and documented by Monero developers, and the paper acknowledges this.

The paper attaches specific historical numbers to those problems, which is good, though one can still quibble about how the numbers are aggregated and presented.

Re: 80% of Monero Transactions Trivially De-Anonymized

#54

This response is interesting and worth a read: https://word-view.officeapps.live.com/wv/mWord.aspx?Fi=SD473...

Any chance i could get that as a static document? It seems chrome on linux and microsoft office online don't get along

Though I'm not disputing the preference for static documents, which Linux and Chrome version are you using? On CentOS 7.3 with Chrome 52 the document looks fine, as it does on the same system with Firefox 52.

Note that the document is unformatted plain text, divided into six pages.

Re: 80% of Monero Transactions Trivially De-Anonymized

#55

Earlier quoted context omitted.

The key phrase being "in this section" - section 3 deals with the older vulnerability while section 4 deals with RingCT transactions.

The section 3 vulnerability traces (aka "de-anonymizes") precisely no transactions at all. It indicates that the probabilities across potential outputs sources are biased, but does not offer any method at all to identify any actual source. The estimate of the bias given in the paper for the current default and typical usage is that the most recent potential source has a probability of 45% instead of the ideal 20%. In…

Yes, that's section 3. What about section 4?

Re: 80% of Monero Transactions Trivially De-Anonymized

#56
Copy from a monero dev answer on reddit:

Heuristic I not applicable to RingCT, so moving on...

Heuristic II is basically people sending a transaction to themselves and thus creating 2 new txo's (amount and change). Then at some point people spend both txo's in one transaction. This is something that can be avoided by just not sending coins to yourself and by the wallet giving you a warning when you are about to spend 2 txo's stemming from the same txo.

Heuristic III is basically the fact that the newest txo in a transaction is likely the one that is being spent and can be prevented by people actually keeping a small reserve of XMR and refilling this at random intervals. Don't spend all your XMR all at once just after you received it.

Re: 80% of Monero Transactions Trivially De-Anonymized

#57

Earlier quoted context omitted.

The section 3 vulnerability traces (aka "de-anonymizes") precisely no transactions at all. It indicates that the probabilities across potential outputs sources are biased, but does not offer any method at all to identify any actual source. The estimate of the bias given in the paper for the current default and typical usage is that the most recent potential source has a probability of 45% instead of the ideal 20%. In…

Yes, that's section 3. What about section 4?

Sorry my mistake. My comment was about Section 4, not Section 3.

RingCT is immune to the methods in Section 3 as stated in the last paragraph of Section 3.

Section 4 does not trace any transactions. It identifies a probability bias which make the ring sigs less efficient, but still functional.

Re: 80% of Monero Transactions Trivially De-Anonymized

#58
Intellectually very dishonest, especially considering Zcash's Ceo (yes, that actually exists) response on some twitter-'trolling': https://twitter.com/AeonCoin/status/854247126473228288

I mean come on, it's OK to cherrypick xmr's blockchain and post sensationalist and exaggerated tweets, but not Ok to do the same for Zcash...

Their academic integrity has obviously lost it from their financial incentives. Will be very hard to 'trust' these guys again, wouldn't 'trust' the 'trusted setup' that was needed for Zcash for a billion dollars now...

Re: 80% of Monero Transactions Trivially De-Anonymized

#59
post #5

Intellectually and academically dishonest hitpiece by peddlers of a competing cryptocoin. That this subset of transactions is not safe is not news, nor is it even original research - it was covered in research more than 2 years ago by The Monero Project itself - and is something the project has addressed since and is working to further improve even beyond the recommendations of this paper. Lengthy discussion on reddi…

Andrew Miller does not hide his ties to Zcash; I believe none of the other authors are associated with Zcash. I do not think he needs to recuse himself from academic study of competing currencies, just because he has loose ties to Zcash. Also, the authors do not hide the fact that the vulnerability is not new. Most science is incremental; I haven't seen any evidence of 'academic dishonesty'.

>The Zcash Foundation will now be endowed with 273,000 zcash, worth more than $13m at press time. As part of the network’s rules, 10% of the cryptocurrency’s mining rewards are automatically awarded to stakeholders.

>The four-person board of directors includes chair and president Andrew Miller, associate director of the Initiative for Cryptocurrencies and Contracts (IC3), and Matthew Green, assistant professor of computer science at Johns Hopkins University.

Source: https://archive.fo/BoxUe

Re: 80% of Monero Transactions Trivially De-Anonymized

#60
post #5

Intellectually and academically dishonest hitpiece by peddlers of a competing cryptocoin. That this subset of transactions is not safe is not news, nor is it even original research - it was covered in research more than 2 years ago by The Monero Project itself - and is something the project has addressed since and is working to further improve even beyond the recommendations of this paper. Lengthy discussion on reddi…

It is not true that this result was previously known. Please see the section “Comparison with related work on Monero linkability.” in the paper (https://monerolink.com), which starts "We note that earlier reports from Monero Research Labs(MRL-0001 [10] and MRL-0004 [7]) have previously discussed concerns about such deduction, called a “chain-reaction,” based on similar insights as described above. However, our results paint a strikingly different picture than these." and then goes on to show those striking differences in the new results and the previous knowledge.
Post reply on HN