Live data from Hacker News

Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

petertodd.org

31–40 of 40 posts

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#31
post #8

> The secret key (“cryptographic toxic waste”) generated during this phase can be used to steal money - currently in the form of creating counterfeit coins, stealing from everyone collectively. > As one of those participants, here’s my account of what I did to ensure that secret was destroyed. Regardless of what he did or did not do to destroy this secret, doesn’t this make ZCash inherently non-trustless? If we trust…

> Nothing you will read below changes the fact that you’re trusting me and five other participants not to collude. Full stop. End of story. It is IMPOSSIBLE for myself and the other participants to prove to a third party that we did not collude to keep the secret key. If you do not believe you can trust me, you should stop reading now.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#32
post #6

Earlier quoted context omitted.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously. There is no good justification for 20…

> Alas I am in no position to analyze ZCash math vs RingCT but my feeling is the latter is more understandable and thus might be more secure even if it has much weaker safety promises. Depends on what type of security you want. If you're talking about security against inflation, then RingCT is definitely safer than Zcash. But if you're talking about privacy security, then Zcash is more secure than RingCT; the trusted…

Well it’s a free choice. You can make non look math systems that have unconditional privacy instead of unconditional inflation guarantees.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#33
post #6

Earlier quoted context omitted.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously. There is no good justification for 20…

> Alas I am in no position to analyze ZCash math vs RingCT but my feeling is the latter is more understandable and thus might be more secure even if it has much weaker safety promises. Depends on what type of security you want. If you're talking about security against inflation, then RingCT is definitely safer than Zcash. But if you're talking about privacy security, then Zcash is more secure than RingCT; the trusted…

>the trusted setup can only be used to create fake Zcash, not deanonymize transactions.

"I think we can successfully make Zcash too traceable for criminals like WannaCry, but still completely private & fungible"

"I _don't_ mean weakening security (https://z.cash/support/faq.html#backdoor …). I mean that a secure protocol layer is compatible with good law enforcement." -zooko

Not sure how your statements carry water in the face of that comment.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#35
post #32

Earlier quoted context omitted.

> Alas I am in no position to analyze ZCash math vs RingCT but my feeling is the latter is more understandable and thus might be more secure even if it has much weaker safety promises. Depends on what type of security you want. If you're talking about security against inflation, then RingCT is definitely safer than Zcash. But if you're talking about privacy security, then Zcash is more secure than RingCT; the trusted…

Well it’s a free choice. You can make non look math systems that have unconditional privacy instead of unconditional inflation guarantees.

*non moon-math

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#36
post #6

Earlier quoted context omitted.

2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. I agree with your 20%/10% comments, but I do not know why you call ZCash an investment. Zcash should discourage people from investing, like Monero does. Be a privacy coin, do not try to get in on the moon and lambo hypetrains if you want to be taken seriously. There is no good justification for 20…

> 2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. Note that the 2^80 figure from Peter's blog post is really unsubstantiated. There's another curve in libsnark (which we don't use) that has 80-bits of security. I suspect what happened is whoever Peter was consulting with just repeated this number to him. We've spoken to many cryptographers who…

> employed grsec

This is one situation in which I think that using grsec is absolutely the wrong choice. Grsec mitigates a lot of kernel bugs, but it also adds bugs. More importantly, it isn't particularly well audited, and it is unlikely to have many eyeballs on it at all in the future, given it's not-really-open-source status.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#37

Earlier quoted context omitted.

Because the math is freaking cool? :)

thats what all the drones at Zcash say. It is either that they like the math, or they find validation from stacking the team with renowned cryptographers. there is almost no intersection of people interested in zcash and people that actually want to use cryptocurrency or keep zcash in their portfolio who have done any analysis of how this is not something to hold for long.

I am very interested in the math, but I kind of agree with you, I am not invested in zcash. If they didn't have first mover advantage they would not be doing as well as they are.

The best implementation using this mathematics is definitely yet to come, I would not be surprised if they weren't surpassed by someone else using similar tech in the very near future.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#38
post #36

Earlier quoted context omitted.

> 2^80 is not very weak. That's the level of brute forcing a SHA-1 collision. It's low for a new system, but not very weak. Note that the 2^80 figure from Peter's blog post is really unsubstantiated. There's another curve in libsnark (which we don't use) that has 80-bits of security. I suspect what happened is whoever Peter was consulting with just repeated this number to him. We've spoken to many cryptographers who…

> employed grsec This is one situation in which I think that using grsec is absolutely the wrong choice. Grsec mitigates a lot of kernel bugs, but it also adds bugs. More importantly, it isn't particularly well audited, and it is unlikely to have many eyeballs on it at all in the future, given it's not-really-open-source status.

In our case, the use of grsec was one of the simplest counter-measures that achieved an almost purely additive security improvement. That's even when accepting the risk that grsec has security bugs in it.

If the participant did everything right, one of the only remaining ways that the secrets could be exfiltrated from the machine was by exploiting a theoretical vulnerability in xorriso, the software we use to read/write DVDs for airgapped communication in the ceremony. Even then, it was likely to leave an evidence trail on the DVDs for post-hoc review.

As an extra precaution, we needed to impose strict policies on the xorriso process. Grsec was trivial to employ using off-the-shelf Alpine Linux tools, and didn't require any dependencies which would increase the cost of auditing afterward. Grsec was also not likely to introduce bugs we couldn't catch in post-hoc review due to the evidence trail left on the DVDs.

The hope was to force an adversary to exploit both xorriso and grsec in practice. One important question is: was grsec likely to introduce a category of bugs that would not otherwise exist in Linux already? I think the answer to that question is no. Funny enough, just a day or two before the ceremony the Dirty COW vulnerability was patched in the Linux kernel, and we just managed to update our OS before the scheduled ceremony.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#39
post #8

> The secret key (“cryptographic toxic waste”) generated during this phase can be used to steal money - currently in the form of creating counterfeit coins, stealing from everyone collectively. > As one of those participants, here’s my account of what I did to ensure that secret was destroyed. Regardless of what he did or did not do to destroy this secret, doesn’t this make ZCash inherently non-trustless? If we trust…

The trust involved in the Zcash trusted setup is a significantly better type of trust than what you're suggesting, because you only have to trust the people involved once . Signing messages is an ongoing trust, which is far more vulnerable to attack.

> The trust involved in the Zcash trusted setup is a significantly better type of trust than what you're suggesting, because you only have to trust the people involved once.

I disagree. Since there’s no way for you to prove that you have actually destroyed the secret in question, there’s no way for me to know where that key is now and, hence, how long I need to trust you.

“Only having to trust the people involved once” presupposes that I trust that they have destroyed the key properly, otherwise the key might still be out there, and the trust would be ongoing in this case as well.

Re: Cypherpunk Desert Bus: My Role in the 2016 Zcash Trusted Setup Ceremony

#40
post #39

Earlier quoted context omitted.

The trust involved in the Zcash trusted setup is a significantly better type of trust than what you're suggesting, because you only have to trust the people involved once . Signing messages is an ongoing trust, which is far more vulnerable to attack.

> The trust involved in the Zcash trusted setup is a significantly better type of trust than what you're suggesting, because you only have to trust the people involved once. I disagree. Since there’s no way for you to prove that you have actually destroyed the secret in question, there’s no way for me to know where that key is now and, hence, how long I need to trust you. “Only having to trust the people involved onc…

Worst case the two scenarios equate to the same thing. Namely there's one or more people you need to trust indefinitely.

Best case however is where they differ a lot. Best case for this method is trusting someone once. Best case for the other method is still trusting one or more people indefinitely.

Post reply on HN