Live data from Hacker News

80% of Monero Transactions Trivially De-Anonymized

ipfs.io

81–88 of 88 posts

Re: 80% of Monero Transactions Trivially De-Anonymized

#81
post #45

Earlier quoted context omitted.

Sorry if I'm looking at the data wrong, but this chart suggests less than 5% are shielded https://explorer.zcha.in/statistics/value Is the chart wrong?

Perhaps it could have something to do with termonology (%value vs %transactions). For value I get: 42588 / (891015+222753) = 3.8% Shielded Value / (Cumulative Miner's Reward + Cumulative Founder's Reward) Perhaps it is 28% of transactions are shielded worth only 4% of zec value?

Note that the number of prior shielded transactions (not the proportion, and not the value) is what is actually relevant to the privacy of new shielded transactions. Roughly speaking, the privacy you get with Zcash is comparable to what you would get with Monero if you could use all previous shielded transactions (over 120000 of them, currently) as mixins. That's why the criticisms of Zcash based on the percentage use of shielding (either by transactions or value) are totally missing the point.

-- Daira Hopwood (Zcash developer)

Re: 80% of Monero Transactions Trivially De-Anonymized

#82

Earlier quoted context omitted.

You're mistaken in saying that it is most likely that the actual note is the most recent one for Zcash. The figure gives a slightly misleading impression because it has to show few enough inputs to fit on the page. The number of possible inputs is the total number of previous shielded notes (before the JoinSplit anchor) that the adversary does not control or know to have been spent. There have been around 129000 Join…

Yes you are likely correct that "most recent" being the "most likely" is not accurate. However, there is a distribution and it has a peak. It is certainly not flat, so it is incorrect to say that the entire set constitutes an "effective anonymity set" while at the same time claiming that Monero's ring signatures only have an "effective mixin size" that is smaller than the actual size due to the same non-uniform distr…

As far as I know we've never claimed that the distribution is flat or that the "effective anonymity" is equivalent to a uniform distribution over prior notes (I certainly didn't claim that). One of the advantages of Zcash's approach is that you don't need to know the distribution in order to have a strong privacy claim. As I said, this is because the content of a transaction is not revealed, and so the attacker's advantage is no better than guessing based on their prior knowledge (plus the little information that can be inferred from timestamps and number of JoinSplits in a transaction).

It's the same claim as for semantically secure encryption, for example: no competent cryptographer would claim that encrypting a message implies that the adversary's knowledge of the plaintext distribution is uniform; only that the ciphertext gives the attacker no further information (apart from length, typically) about the distribution.

Re: 80% of Monero Transactions Trivially De-Anonymized

#83

Earlier quoted context omitted.

To correct a minor point, none of the current Zcash code comes from the Zerocash academic prototype. All of the code that had come from the prototype was rewritten before launch (mainly in https://github.com/zcash/zcash/pull/625 ). Much of the performance issue comes from a single design decision made in Zerocash: to use SHA-256 for the Merkle tree, PRF, and note commitment hashes. We'll be changing this for the Sapl…

My apologies, I had assumed the codebase was legacy due to some lamentations about not being able to use Rust. I hope my portrayal of the performance issues was appropriate.

The legacy codebase issue we are lamenting there is just that the code inherited from Bitcoin is in C++. It's of course possible to interface between C++ and Rust, and that's what we're intending to do in future. It would have been risky to try to do that in the code we wrote before launch.

Yes, your portrayal of the performance issues was fine.

Re: 80% of Monero Transactions Trivially De-Anonymized

#84
post #81

Earlier quoted context omitted.

Perhaps it could have something to do with termonology (%value vs %transactions). For value I get: 42588 / (891015+222753) = 3.8% Shielded Value / (Cumulative Miner's Reward + Cumulative Founder's Reward) Perhaps it is 28% of transactions are shielded worth only 4% of zec value?

Note that the number of prior shielded transactions (not the proportion, and not the value) is what is actually relevant to the privacy of new shielded transactions. Roughly speaking, the privacy you get with Zcash is comparable to what you would get with Monero if you could use all previous shielded transactions (over 120000 of them, currently) as mixins. That's why the criticisms of Zcash based on the percentage us…

The number of note commitments can be found using 'zcash-cli getblockchaininfo' and is currently 301068 commitments, i.e. 150534 JoinSplits (so a bit more than the 120000 I said).

Re: 80% of Monero Transactions Trivially De-Anonymized

#85

Earlier quoted context omitted.

> The point they are trying to make is that the anonymity set between shielded addresses is that of all transactions in the anonymous set. This way of stating is somewhat questionable in light of the claims in the second half of the paper. What is shown in the second half of the paper is that all possible sources are not equally likely and this most probably applies to Zcash (and every other coin) as well. In the Fig…

You're mistaken in saying that it is most likely that the actual note is the most recent one for Zcash. The figure gives a slightly misleading impression because it has to show few enough inputs to fit on the page. The number of possible inputs is the total number of previous shielded notes (before the JoinSplit anchor) that the adversary does not control or know to have been spent. There have been around 129000 Join…

The number of note commitments can be found using 'zcash-cli getblockchaininfo' and is currently 301068 commitments, i.e. 150534 JoinSplits (so a bit more than the 129000 I said).

Re: 80% of Monero Transactions Trivially De-Anonymized

#86
post #6

Amiller, Figure 1 should show that the overwhelming majority of Zcash transactions have the privacy properties of Bitcoin transactions (or worse). No? It seems kind of imbalanced to have an analysis which emphasizes the security compromises caused by older monero (pre-CT, pre minimum mixin count) while ignoring the ongoing privacy flaw in Zcash usage in practice.

Take this as a prime example of the corruption that has become the defacto behavior of a small but very influential group of Bitcoin developers.

Greg has been promoting Monero since it's inception, a cryptocurrency advertised as being unlinkable.

T addresses in ZEC were NEVER STATED TO BE PRIVATE.

The argument that Monero transactions being found to be linkable at a wide range of mixins, as demonstrated by the paper and the search facility on http://monerolink.com, is somehow comparable to ZCash NON PRIVATE transactions between T addresses, is essentially academic fraud, which is in many ways the norm for people so jaded by the pursuit of profit - Yes, Greg is a Monero holder.

Greg, as you continue to flap around this issue presenting such fallacious arguments to essentially cover your own incompetence, and an incompetence that potentially could have cost many people their own privacy and security by promoting such a defunct privacy system, please understand that most people are not this easily fooled and your own credibility is permanently tainted in this regard, as it very well should be.

I would add that the additional argument being floated on this issue, that this major flaw is fixed now and doesn't matter, is another case of academic fraud; Any system that has is misrepresented for so long (May 2014- Jan 2017) at the cost of user's privacy and once a "fix" such as CT is applied to then say this system is sound is another pathetic attempt by dishonest academics to cover the incompetence and protect their reputations and personal financial interests.

Bitcoin was intended to fight corruption and the influence of corrupt "officials".

It is time for change.

Re: 80% of Monero Transactions Trivially De-Anonymized

#87

Earlier quoted context omitted.

> should show that the overwhelming majority of Zcash transactions have the privacy properties of Bitcoin transactions (or worse). Agreed, this should updated to specify that only transactions between shielded addresses are protected. The point they are trying to make is that the anonymity set between shielded addresses is that of all transactions in the anonymous set. (FWIW, this is a pre-publication draft.) > No? I…

What do you mean "if Monero fixes everything"? They already fixed everything, which is why the paper shows the decline in their ability to deduce things, and the paper COMPLETELY STOPS showing data after RingCT went into action. Perhaps you should familiarise yourself with the papers that Monero themselves published on this in September 2014, and the follow-up in January 2015? Here- https://lab.getmonero.org/pubs/MRL…

How exactly do you fix the reputation of a system that previously claimed unlinkable transactions that is now essentially deanonimized, with some of those users DN users? Everything is ok now and users should have confidence in these people, including G. Maxwell?

Re: 80% of Monero Transactions Trivially De-Anonymized

#88
post #82

Earlier quoted context omitted.

Yes you are likely correct that "most recent" being the "most likely" is not accurate. However, there is a distribution and it has a peak. It is certainly not flat, so it is incorrect to say that the entire set constitutes an "effective anonymity set" while at the same time claiming that Monero's ring signatures only have an "effective mixin size" that is smaller than the actual size due to the same non-uniform distr…

As far as I know we've never claimed that the distribution is flat or that the "effective anonymity" is equivalent to a uniform distribution over prior notes (I certainly didn't claim that). One of the advantages of Zcash's approach is that you don't need to know the distribution in order to have a strong privacy claim. As I said, this is because the content of a transaction is not revealed, and so the attacker's adv…

The comment to which I replied (not by you) claimed that the anonymity set is all shielded transactions.

It is, in the same sense that the first order anonymity set of Monero transactions is all outputs included in the ring signature which can't be proven implausible (e.g. using the methods in Section 3 of the paper). However, Section 4 of the paper points out that a non-uniform distribution means this is reduced, in practice, to a smaller effective degree. The same method can be used with Zcash to estimate a smaller effective degree since many previous shielded transactions are probabilistically unlikely.

This is certainly not 'deanonymization' or 'tracing' or any such thing, but it isn't that in the Monero case either.

Post reply on HN