Live data from Hacker News

Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

petertodd.org

1–10 of 40 posts

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#2
When reading this, pay attention to section 1.2:

"Until the software and deterministic builds are audited, the entire ceremony is a bunch of crypto hocus pocus that means nothing."

I'm 100% serious, and even a year later this still hasn't been done properly.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#6

When reading this, pay attention to section 1.2: "Until the software and deterministic builds are audited, the entire ceremony is a bunch of crypto hocus pocus that means nothing." I'm 100% serious, and even a year later this still hasn't been done properly.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak.

I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously.

There is no good justification for 20% right now. ZEC market cap is half a billion today. Do they really need that extra 50 mln now versus over time? Feels greedy.

But with so much taken by them that way, does that not reduce their desire to get a backdoor?

At any rate, all of this ceremony and your measures seem, as you say, hocus pocus if you're not building from known source! Forget hardware attacks! How can they not have the basics of a secure toolchain?!?

Did some participants at least publish the source they used and hashes of the toolchain and environment?

At my startup (details in profile) we will end up depending on crypto (among other things) to stay out of prison. Monero is hard to use, privacy wise - EABE and EWE attacks are our concerns. At least with ZCash the model is fairly easy to understand with shielded transactions. Much easier than figuring out ringsize and traceability there. But the Monero community seems better with no 20% take, no central company, none of this trusted nonsense. And no odd comments by both founders that require lots of mental gymnastics to make sense of. Not that any of this should matter. ZCash should be trusted on its own merits regardless of the inventors. Monero has anonymous inventors which could be the NSA for all we know.

Alas I am in no position to analyze ZCash math vs RingCT but my feeling is the latter is more understandable and thus might be more secure even if it has much weaker safety promises.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#7
post #6

When reading this, pay attention to section 1.2: "Until the software and deterministic builds are audited, the entire ceremony is a bunch of crypto hocus pocus that means nothing." I'm 100% serious, and even a year later this still hasn't been done properly.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously. There is no good justification for 20…

> 2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak.

Note that the 2^80 figure from Peter's blog post is really unsubstantiated. There's another curve in libsnark (which we don't use) that has 80-bits of security. I suspect what happened is whoever Peter was consulting with just repeated this number to him. We've spoken to many cryptographers who are experts on these curves, and none of them think that figure is reasonable. I actually don't believe there are _any_ cryptographers that have publicly made such a claim about the security.

2^96 was the original conservative estimate when the NFS attack was discovered, but subsequent analysis showed concrete security closer to 2^110 (and that's ignoring the unrealistic memory costs of the specific attack.)

> How can they not have the basics of a secure toolchain?!?

We provided participants with a reproducibly built and stripped down version of Alpine Linux, employed grsec, wrote all of our crypto software in pure Rust, etc. All of our software is reproducibly built, hashed and signed. There is nothing (software-wise) that cannot be caught in post-hoc review. All of it is open-source: https://github.com/zcash/mpc

Several academic papers regarding our protocol have been published since then. We wrote a full security proof of the crypto. We hired NCC group to audit the ceremony as well: https://z.cash/blog/ceremony-audit-results.html

More auditing can always be done but this is a continuing process. The primary goal is to make it difficult for someone to undetectably compromise the ceremony.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#8
> The secret key (“cryptographic toxic waste”) generated during this phase can be used to steal money - currently in the form of creating counterfeit coins, stealing from everyone collectively.

> As one of those participants, here’s my account of what I did to ensure that secret was destroyed.

Regardless of what he did or did not do to destroy this secret, doesn’t this make ZCash inherently non-trustless? If we trust that these people are honest, why not just have them sign messages with their keys to resolve double-spends, rather than build an elaborate system on top of this trust?

In other words, the ZCash crypto might be trustless itself, but if it’s employed on top of a base that requires trust, what’s the point in the first place? The weakest link is at the base.

“If you just trust me, I have some really cool trustless crypto to show you”

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#9
post #6

Earlier quoted context omitted.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously. There is no good justification for 20…

> 2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. Note that the 2^80 figure from Peter's blog post is really unsubstantiated. There's another curve in libsnark (which we don't use) that has 80-bits of security. I suspect what happened is whoever Peter was consulting with just repeated this number to him. We've spoken to many cryptographers who…

What is Peter referring to when he says there's no reproducible builds?

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#10
post #6

Earlier quoted context omitted.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously. There is no good justification for 20…

> 2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. Note that the 2^80 figure from Peter's blog post is really unsubstantiated. There's another curve in libsnark (which we don't use) that has 80-bits of security. I suspect what happened is whoever Peter was consulting with just repeated this number to him. We've spoken to many cryptographers who…

What my blog actually said about that was:

"I’ve had some experts tell me they thought the security level was 2^80 operations (very weak), while others (including Zooko himself) thought it was [more like 2^96](https://moderncrypto.org/mail-archive/curves/2016/000742.htm...). I’m not sure which figure is right, but the fact that there’s disagreement is a bad sign."

I made it very clear that it is an unsubstantiated figure, and linked to Zooko's analysis. To both yourself and the person you're replying too, please don't put words in my mouth.

> We provided participants with a reproducibly built and stripped down version of Alpine Linux, employed grsec, wrote all of our crypto software in pure Rust, etc. All of our software is reproducibly built, hashed and signed. There is nothing (software-wise) that cannot be caught in post-hoc review. All of it is open-source: https://github.com/zcash/mpc

I agree. But that's not what I said; what I said is that post-hoc review hasn't been done, even a year after the fact.

Post reply on HN