Live data from Hacker News

The rise of crypto laundries: how criminals cash out of Bitcoin

ft.com

221–230 of 236 posts

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#221
post #67

Earlier quoted context omitted.

>Monero is fundamentally about as private as bitcoin. That's contrary to what I've read, care to expand? As far as I know the IRS is still offering a bounty to crack Monero

https://gist.github.com/DavidVorick/0dbd4906bfa50b7d8dba23f7...

I read through this entire gist, and I was not able to find a single section categorically proving that Monero is unsafe. It makes big claims such as "Monero has been broken." and "Monero is substantially unsafe and incapable of providing anonymity [...]", but then at the end the very same paper says the following:

"Monero is the best-in-class anonymous cryptocurrency in production today."

What the hell is it trying to say then?

From what I've been able to gather from this gist, its argument that Monero is "unsafe" hinges on the extra sentence: "under the formal threat model proposed and analyzed in this paper". Curiously, section 8, "Analysis Under Full Threat Model", is completely blank. And it also curiously never properly defines the "full threat model"

From what I gather however, its main argument is that 10 decoys (in RingCT) is too few and there could be probabilistic attacks and the some of the decoys could be malicious actors. The Monero developers already know this however, and are working on Triptych and Arcturus [1] to fix this. Note that this doesn't mean that Monero is 0% safe (as the gist likes to pretend by writing stuff like "Monero has been broken"), but it rather means that Monero is 80-90% safe rather than 100% safe. And if you're that worried, the Monero wallet offers the option for churning [2]

Lastly, the gist is more than 3 years old now, without a single update to it. Does the author not know that in 3 years there could be lots of upgrades and fixes to Monero? The fact that the largest Dark Net Market is now using Monero only surely should be an indication that Monero is doing something right?

[1]: https://www.monerooutreach.org/stories/monero-triptych.html

[2]: https://monero.stackexchange.com/questions/4565/what-is-chur...

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#222
post #67

Earlier quoted context omitted.

https://gist.github.com/DavidVorick/0dbd4906bfa50b7d8dba23f7...

I read through this entire gist, and I was not able to find a single section categorically proving that Monero is unsafe. It makes big claims such as "Monero has been broken." and "Monero is substantially unsafe and incapable of providing anonymity [...]", but then at the end the very same paper says the following: "Monero is the best-in-class anonymous cryptocurrency in production today." What the hell is it trying…

> "Monero is the best-in-class anonymous cryptocurrency in production today." > > What the hell is it trying to say then?

It's trying to say everything else is broken too. I think Zcash is now best is class though.

> Note that this doesn't mean that Monero is 0% safe (as the gist likes to pretend by writing stuff like "Monero has been broken"), but it rather means that Monero is 80-90% safe rather than 100% safe.

No, the main point of the gist is that the analytic attacks are able to entirely break any user whose wallet functions as a stream wallet, which in practice is nearly everyone. To fall outside of the "stream wallet" definition provided in the gist, you have to run a custom wallet (not the main Monero code), and the implementation of that wallet has to be highly user hostile.

The attack doesn't target weaknesses in the monero implementation, it targets weaknesses in the monero architecture. Any decoy system has the exact same issues. If Monero is still on a 10 decoy system (even if it were on a 100,000 decoy system), all the attacks in the gist apply.

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#223

Earlier quoted context omitted.

Here’s a little story to help balance the ratio https://www.google.com/amp/s/www.vogue.co.uk/fashion/article...

Here is the exact same URL without Google's AMP: https://www.vogue.co.uk/fashion/article/wansho-laundry

Thanks for that Cute story, right?

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#224
post #195

Earlier quoted context omitted.

It's important to realize that attribution - knowing which human got which money when - is actually very important in many contexts, particularly when a lot of money is involved. This allows for an un-do button in the case of mistakes, fraud, etc. If I'm wiring my down payment for a house for $200k, it's nice to know that if I fat-finger the receiving account I can get the money back. How would you feel paying your d…

Attribution is important but you don't need the government to be able to do it without your authorization. You can very well have private unattributable transactions that you decide to disclose to the authorities only if you need and want to. If you send your coins from wallet A to wallet B with CoinJoin, it's not possible for a third party to identify this transaction, but you can disclose the seed of wallet A and s…

AFAICS none of your points addresses the problem posed by your parent commentor: someone accidentally sent a lot of money to the wrong account/wallet and wants it back, even if the receiver is uncooperative.

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#227

Earlier quoted context omitted.

There's a difference between privacy and secrecy. If I'm involving my bank, what I'm doing is already not secret. My bank knows. But normally they keep those things private, because it's generally not anybody's business. There are occasions where society's interest in preventing crime outweighs personal privacy, and one way to look at that is that when something (like, say, ransomware) has an effect on other people,…

>>When that happens, as long as there are reasonable checks and balances, I'm fine with banks giving out information, especially when it's organizations that generally respect the privacy of the people involved. A reasonable check and balance would be the requirement for the state to get a warrant, issued by a court when probable cause is found, not 'every transaction over $10,000 is reported to the state for its war…

Yes, different people have different ideas about what's reasonable. But if you want to make a case for a reasonable balance between your desire for secrecy versus the desire of other people to be free of crime, you'll have to talk about more than what you personally dislike.

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#228

Earlier quoted context omitted.

>>When that happens, as long as there are reasonable checks and balances, I'm fine with banks giving out information, especially when it's organizations that generally respect the privacy of the people involved. A reasonable check and balance would be the requirement for the state to get a warrant, issued by a court when probable cause is found, not 'every transaction over $10,000 is reported to the state for its war…

Yes, different people have different ideas about what's reasonable. But if you want to make a case for a reasonable balance between your desire for secrecy versus the desire of other people to be free of crime, you'll have to talk about more than what you personally dislike.

I want to be free from the crimes of the state too, and the kind of suffocating repression [1] [2] and centralization of power [3] that highly controlled societies create.

We should oppose warrantless mass-surveillance of private financial transactions for the same reasons we oppose mass-surveillance of every one's private communications. The desire to live free from crime does not justify engaging in either.

I think most would agree, and that AML laws are only instituted due to:

1. the complexity of the subject matter obfuscating what these laws do

2. the euphemization of AML laws by the AML industry, like calling them anti-money laundering laws rather than the more descriptive 'financial surveillance laws', and

3. the stigmatization of money, as a result of the public relations efforts of the many who stand to gain from laws restricting people's ability to transact with it.

[1] https://www.reddit.com/r/MakerDAO/comments/de0sys/kyc_is_abs...

[2] https://www.coindesk.com/money-reimagined-ugly-side-kyc-aml-...

[3] https://twitter.com/SpencerKSchiff/status/125276128577685913...

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#229
post #14

I get that money laundering is always linked to criminal activity, but how have we always just accepted the lack of personal privacy when it comes to finance? Privacy is a feature, not a bug; and whilst crypto may not be the way forward, I hope one day we can reach a solution that has both privacy and also safety. The language used by law enforcement is quite alarming, it suggests that they should be privy to ALL tra…

> but how have we always just accepted the lack of personal privacy when it comes to finance? We didn't. This is something that has changed in the UK in my lifetime. Unless you were the subject of an investigation you didn't have to provide much detail to the tax authorities, and what you did provide was kept strictly separate from other areas of government. There was an attempt to strike a balance with the emphasis…

The UK is a more or less a cashless society, give or take a few regional variations and laggards.

I've lived in London for 3 years and don't think I've ever used cash for anything in that time. Trains, buses, taxis, bills (don't even need snail mail for those), restaurants, shops.

Outside of London it's a little different, but it's only a matter of a a few more years.

Re: The rise of crypto laundries: how criminals cash out of Bitcoin

#230
post #195

Earlier quoted context omitted.

Attribution is important but you don't need the government to be able to do it without your authorization. You can very well have private unattributable transactions that you decide to disclose to the authorities only if you need and want to. If you send your coins from wallet A to wallet B with CoinJoin, it's not possible for a third party to identify this transaction, but you can disclose the seed of wallet A and s…

AFAICS none of your points addresses the problem posed by your parent commentor: someone accidentally sent a lot of money to the wrong account/wallet and wants it back, even if the receiver is uncooperative.

I'm not sure we understood the parent comment the same way but you're right, you can't get your money back if sent to someone uncooperative. However, you can call the authorities and prove that you sent funds to that person and let them recover it if possible. I only addressed the question of attribution.
Post reply on HN