Live data from Hacker News

Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

petertodd.org

21–30 of 40 posts

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#21

Earlier quoted context omitted.

The protocol could not scale to a large number of participants at the time. Just with six participants it took an entire weekend to perform.

I've been looking for some kind of discussion of the scalability of the trusted setup, but I cannot find it. Do you have a link?

https://eprint.iacr.org/2017/602

The protocol scales linearly with respect to the number of participants, but as you can tell, each participant needs to do a lot of time-consuming computations.

Each participant needs to maintain custody of the hardware during the process of the ceremony, and then destroy the hardware afterward. If it was your turn, you'd do some stuff for an hour, and then it's the next person's turn in a round-robin circle. You had to wait maybe ~8 hours before it was your turn again. The protocol involved three rounds of this.

Nobody can abort (players commit to their moves in advance to defend against adaptive attacks) and so there needs to be a time when all N participants are available for the entire duration of the ceremony. This makes it very sensitive to scheduling problems.

If you want to do your own MPC, you also need to perform very expensive fast-fourier transforms in between round 1 and 2. In our ceremony that required a very beefy 128-core server and it still took over an hour.

I actually just found a log file from the ceremony's coordinator server (not a privileged server, just handles messages and archives them) which shows the timings of everything, which is kind of fun:

https://gist.github.com/ebfull/fde1e167ba35ca67e086ca458eabc...

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#22

Earlier quoted context omitted.

What my blog actually said about that was: "I’ve had some experts tell me they thought the security level was 2^80 operations (very weak), while others (including Zooko himself) thought it was [more like 2^96]( https://moderncrypto.org/mail-archive/curves/2016/000742.htm... ). I’m not sure which figure is right, but the fact that there’s disagreement is a bad sign." I made it very clear that it is an unsubstantiated…

> To both yourself and the person you're replying too, please don't put words in my mouth. What words did I put in your mouth? I cited the 2^80 figure in your blog post and a reasonable theory for why you would bring up such a figure. "Regurgitated" came across as snide so I apologize for that. Note that you used this unsubstantiated figure to say "the fact that there’s disagreement is a bad sign." If there isn't act…

> "Regurgitated" came across as snide so I apologize for that.

That's the thing, it didn't just come across as snide, it made it sound like I repeated the number uncritically, when in fact I made it clear to the reader where it came from and that there was disagreement.

> If there isn't actually any disagreement and the figure is unsubstantiated, why is it not baseless FUD?

The fact that competent experts could be unfamiliar with Zcash's crypto to the degree that they could disagree on basic facts like that is a sign of concern, precisely because it's yet another strong sign that the crypto is quite new. If this were "tried and tested" crypto, there wouldn't be any disagreement. Note that Zooko himself was unsure of the exact strength due to a recently found attack - tried and tested crypto wouldn't have recently found attacks.

> BTW I notified you of this error in your blog post some time ago but never heard back.

Where did you notify me? For that matter, who are you anyway? I probably know you by name from elsewhere; I don't by handle.

> I also don't believe some kind of one-and-done audit of the software/deterministic builds would satisfy either of us.

Well, I was just discussing the trusted setup with Matthew Green, and I think there's some fundamental disagreement on what kinds of vulnerabilities exist and what the risks of them are. So I really need to write a blog post on it.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#24

Earlier quoted context omitted.

> To both yourself and the person you're replying too, please don't put words in my mouth. What words did I put in your mouth? I cited the 2^80 figure in your blog post and a reasonable theory for why you would bring up such a figure. "Regurgitated" came across as snide so I apologize for that. Note that you used this unsubstantiated figure to say "the fact that there’s disagreement is a bad sign." If there isn't act…

> "Regurgitated" came across as snide so I apologize for that. That's the thing, it didn't just come across as snide, it made it sound like I repeated the number uncritically, when in fact I made it clear to the reader where it came from and that there was disagreement. > If there isn't actually any disagreement and the figure is unsubstantiated, why is it not baseless FUD? The fact that competent experts could be un…

I'm Sean from Zcash, I coordinated the MPC and wrote the software. I messaged you on twitter or emailed you or something about this last year.

> it made it sound like I repeated the number uncritically

I didn't say you regurgitated it. I said the person you talked to did, presumably after looking at libsnark or an unrelated paper.

> The fact that competent experts could be unfamiliar with Zcash's crypto to the degree that they could disagree on basic facts like that is a sign of concern, precisely because it's yet another strong sign that the crypto is quite new.

I claim the person you talked to was looking at the wrong curve construction. 2^80 is quite a torch to carry into an argument and no experts that we know have ever suggested a security level less than 2^96. The only "disagreements" about security were far more subtle and reasonable than what your blog post suggested.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#25

When reading this, pay attention to section 1.2: "Until the software and deterministic builds are audited, the entire ceremony is a bunch of crypto hocus pocus that means nothing." I'm 100% serious, and even a year later this still hasn't been done properly.

Totally agree. hopefully this time the laptops weren't all owned by amt

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#28
post #23

Why does ZCash get shilled so much on HN compared to every other altcoin?

The top comment on the Zcash post from yesterday (!) has a good theory on why Zcash is posted about so often:

"Is it just me or are more and more stories which look like fluff pieces for ZCash coming up on the HN frontpage? If they were a startup, I'd guess they were prepping for an IPO/acquisition. Most of them have titles with rhetorical questions, and come across as marketing pieces more than anything else.

Really weird."

- https://news.ycombinator.com/item?id=15430668

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#30
post #23

Why does ZCash get shilled so much on HN compared to every other altcoin?

Because the math is freaking cool? :)

thats what all the drones at Zcash say. It is either that they like the math, or they find validation from stacking the team with renowned cryptographers.

there is almost no intersection of people interested in zcash and people that actually want to use cryptocurrency or keep zcash in their portfolio who have done any analysis of how this is not something to hold for long.

Post reply on HN