Live data from Hacker News

Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

petertodd.org

11–20 of 40 posts

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#11
post #8

> The secret key (“cryptographic toxic waste”) generated during this phase can be used to steal money - currently in the form of creating counterfeit coins, stealing from everyone collectively. > As one of those participants, here’s my account of what I did to ensure that secret was destroyed. Regardless of what he did or did not do to destroy this secret, doesn’t this make ZCash inherently non-trustless? If we trust…

The trust involved in the Zcash trusted setup is a significantly better type of trust than what you're suggesting, because you only have to trust the people involved once. Signing messages is an ongoing trust, which is far more vulnerable to attack.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#13
post #9

Earlier quoted context omitted.

> 2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. Note that the 2^80 figure from Peter's blog post is really unsubstantiated. There's another curve in libsnark (which we don't use) that has 80-bits of security. I suspect what happened is whoever Peter was consulting with just repeated this number to him. We've spoken to many cryptographers who…

What is Peter referring to when he says there's no reproducible builds?

I didn't say that.

What I said was those builds hadn't been properly audited; just being reproducible isn't enough unless people actually reproduce them, and additionally, audit the dependencies that go into those builds.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#14
post #6

When reading this, pay attention to section 1.2: "Until the software and deterministic builds are audited, the entire ceremony is a bunch of crypto hocus pocus that means nothing." I'm 100% serious, and even a year later this still hasn't been done properly.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously. There is no good justification for 20…

> Alas I am in no position to analyze ZCash math vs RingCT but my feeling is the latter is more understandable and thus might be more secure even if it has much weaker safety promises.

Depends on what type of security you want. If you're talking about security against inflation, then RingCT is definitely safer than Zcash.

But if you're talking about privacy security, then Zcash is more secure than RingCT; the trusted setup can only be used to create fake Zcash, not deanonymize transactions.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#15

Earlier quoted context omitted.

> 2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. Note that the 2^80 figure from Peter's blog post is really unsubstantiated. There's another curve in libsnark (which we don't use) that has 80-bits of security. I suspect what happened is whoever Peter was consulting with just repeated this number to him. We've spoken to many cryptographers who…

What my blog actually said about that was: "I’ve had some experts tell me they thought the security level was 2^80 operations (very weak), while others (including Zooko himself) thought it was [more like 2^96]( https://moderncrypto.org/mail-archive/curves/2016/000742.htm... ). I’m not sure which figure is right, but the fact that there’s disagreement is a bad sign." I made it very clear that it is an unsubstantiated…

> To both yourself and the person you're replying too, please don't put words in my mouth.

What words did I put in your mouth? I cited the 2^80 figure in your blog post and a reasonable theory for why you would bring up such a figure. "Regurgitated" came across as snide so I apologize for that.

Note that you used this unsubstantiated figure to say "the fact that there’s disagreement is a bad sign." If there isn't actually any disagreement and the figure is unsubstantiated, why is it not baseless FUD? (BTW I notified you of this error in your blog post some time ago but never heard back.)

> what I said is that post-hoc review hasn't been done, even a year after the fact.

I know, I wasn't replying to you. As I said, I believe more auditing is needed. I also don't believe some kind of one-and-done audit of the software/deterministic builds would satisfy either of us.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#16
post #5

he uses a BLU phone in a few of the pictures, they had factory installed malware if i remember correctly?

Multiple[0][1] forms of possible malware, or at least poorly constructed update platforms.

[0] https://www.kryptowire.com/adups_security_analysis.html

[1] https://www.bitsighttech.com/blog/ragentek-android-ota-updat...

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#20

Why not up the number of participants to 1000? Or 1M?

The protocol could not scale to a large number of participants at the time. Just with six participants it took an entire weekend to perform.

I've been looking for some kind of discussion of the scalability of the trusted setup, but I cannot find it. Do you have a link?
Post reply on HN