Live data from Hacker News

ZCash (formerly Zerocash/Zerocoin) technology preview

z.cash

41–50 of 117 posts

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#41
post #7
post #2

Nothing new here. Add it to the pile of hundreds of other altcoins. Why is this here? Feels like the pump-and-dump world of altcoins is being done here to pump up this post.

> Why is this here? Actually there's a precise answer to that. In yesterday's popular Keybase.io thread, the submitter (rdl) said "Along with Zcash, it is the most amazing crypto-engineering project I've seen in years." https://news.ycombinator.com/item?id=11037297 That was evidence the community might find it interesting, and the project hadn't had discussion on HN yet, so we invited an earlier submitter (malgorithm…

^ This is why Hacker News is worth coming to. Snark and quick dismissal lead to negativity and thoughtlessness, which rapidly kills communities.

Thanks for everything you do, dang.

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#42
post #32

Correct me if I'm wrong but this is a for profit company telling me to use the currency, no commodity, they created and control in order to have privacy? How about I just stick to actual money?

I don't think they will actually control anything, once it takes off; just like no single entity really controls Bitcoin.

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#43
post #33

Earlier quoted context omitted.

1) Laptop stolen, unlocked, you never encrypted anything: yep, you're hosed as far as I know. How else would your wallet be able to tell you a balance? 2) The creation of the genesis block involves a trust 'game' of sorts, in which many participants are asked to pick a number. The statement from zcash, which a better cryptographer than me could verify, is that only one of the participants need be trustworthy in order…

Ah, two of the Four Horsemen of the Infocalypse rear their ugly heads: 8.3.4. "How will privacy and anonymity be attacked?" [...] like so many other "computer hacker" items, as a tool for the "Four Horsemen": drug-dealers, money-launderers, terrorists, and pedophiles. https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...

I think this moral panic (for lack of a better term) is omnipresent because it's actually true to some degree. You can't seriously claim these groups wouldn't benefit from anonymous, secure payment systems. However:

- They already have anonymous, secure payment systems (cash, drugs, jewels, shell companies, etc)

- The cat is out of the bag, so they're going to have it anyway

- These proverbial Horsement do more than just move money around; there's still plenty of room for detective work.

Splitting the atom gave us nuclear power, viable cancer treatment, smoke detectors, and also Hiroshima, Nagasaki, and the threat of radiological terrorism. The proverbial sword is always double-edged.

To make an actual point: I think we'd do well as a community to acknowledge the degree of truth these moral panics hold, because I suspect we frustrate a lot of people by being dismissive of what they perceive to be an apocalyptic problem.

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#44
post #5

Actually, zerocash is significantly different than other altcoins, in that it replaces digital signatures with zero knowledge proofs. It's technically very interesting, and seems like a believable next direction for Bitcoiners. The other direction would be some variant of ethereum. If you don't believe that a general purpose one-size-fits-all blockchain technology can be easily and safely created, but you would prefe…

Two questions I've yet to receive answers on: - my laptop is stolen in a compromised state (eg logged on, nothing left encrypted); can anyone trace my transactions? - I've read suggestions that Zcash themselves can deanonymize every transaction, thanks to generating the initial "Genesis" block. Is that roughly right? (Ignoring obfuscation techniques like getting many other people to create separate signatures) I'm de…

Hi, I'm Ian, one of the scientists behind ZCash, Zerocash, and Zerocoin.

-laptop being stolen: An attacker will get how much money you have, and if you have kept around the private keys for all your addresses, when and how much you were paid, but not who paid you or who you paid. The attacker can use those keys to go back and decrypt the notifications that get posted to the blockchain that allow you to access a transaction. This gets them how much funds you have been sent and when. It doesn't tell them who sent it unless someone put identifying info in the memo field(e.g.'For Homer Simpson's bar tab'), because senders are anonymous even to recipients. It also doesn't tell them anything directly about who you paid or how much. It does let them identify when you made payments though.

If you move your funds to a new address and delete those keys, then all an attacker gets is your current balance.

- deanonymize every transaction. We can't. The zero-knowledge proofs(zkSNARKS) we use to hide transaction data are zero-knowledge no matter what. The information simply isn't there.

The confusion is there is an issue with setting things up to ensure we can't forge coins. The zkSNARKs that ZCash uses need to be generated correctly to ensure the proofs are sound (i.e. actually prove what they claim) and someone therefore cannot forge coins. We plan on doing a multiparty computation setup where if at least one party is honest, the parameters are correct. But zkSNARKs provide statistical zero-knowledge without trusted setup. So assuming the software correctly does the protocol, no one can ever deanonymize transactions (see my other comment on post quantum security for the caveats) unless they get your keys.

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#45
post #37

Hi folks! I'm the Founder and CEO of the Zcash company. It's really great to have this much interest in a project that we just released in alpha "Technology Preview" form two weeks ago. There are a lot of good questions in here, some of which I answered in an AMA a few days ago: https://forum.bitcoin.com/ama-ask-me-anything/i-m-zooko-wilc... I can't wait to release the next iteration of the Zcash software, in — finge…

[deleted]

>Please, just tell me it's not premine.

Why are you opposed to premining? (I had to look up the term, so I'm not baiting you! I don't see the problem, so I'd like to hear your thoughts).

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#46

Earlier quoted context omitted.

OK so basically appeal to authority etc. Not much that a common guy can understand. Sounds to me like a product that is only designed for really smart people...

Most people don't understand how the Internet works, yet they manage to use it every day. Same goes for existing mainstream financial systems.

[deleted]

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#47
post #36

> We believe that privacy strengthens social ties and social institutions, protects societies against their enemies, and helps societies to be more peaceful and more prosperous. It's time to have a serious conversation about whether this is actually true when it comes to financial privacy. Our society is governed by money. Money governs our production directly, and it governs our regulations indirectly since votes ca…

That's... actually a really interesting idea, but you have to consider who you're building the system for - governments, or normal everyday people?

There is a principle, that I think has basically been proven at this point, if not academically:

A: In any non-optional system used by n people, the bad actors using that system are B: It is impossible to prevent bad actors from misusing any system.

C: Trying too hard means the system necessarily damages good actors.

Therefore:

D: Any system that punishes bad participants more than it helps non-bad participants is degenerate.

Bitcoin can be seen as a rejection of a system suffering from C. For perfectly legitimate businesses and people, sending money is an unmitigated pain in the ass, substantial bites taken by middlemen, arbitrary negative action (c.f. civil forfeiture, paypal freezes) and so on. Bitcoin solves almost all of those problems, but makes lives easier for the bad actors too (but not enough that it substantially increases corruption in the world - bad actors gonna bad act)

Now, if your hypothetical system is strictly opt-in, perhaps with social pressure for politicians and such to use it, then I'd have no trouble with it. Were it to become the de facto currency, on the other hand, the problems we have with government overreach and data mining just become a lot worse.

If we accept B as true, then it makes more sense to design for the case of innocent, law abiding people first, out of fear of harming them due to C.

Put another way, I'm a lot more worried about government misusing things under color of law, than I am worried about government corruption. At least regular people can oppose the second one in good faith, while the first one always comes with the "it's legal, so?" baggage.

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#49

Earlier quoted context omitted.

OK so basically appeal to authority etc. Not much that a common guy can understand. Sounds to me like a product that is only designed for really smart people...

Most people don't understand how the Internet works, yet they manage to use it every day. Same goes for existing mainstream financial systems.

Well the question really is, how do the masses start to use this? If only couple of smart people understand it, it won't help much. There are already lot of "like bitcoin, but anonymous" coins, which haven't gained that significant success. If most of the people can't understand why this one is "the shit", they aren't going to see difference between this and the other privacy-promoting altcoins.

Re: ZCash (formerly Zerocash/Zerocoin) technology preview

#50
post #37

Earlier quoted context omitted.

[deleted]

>Please, just tell me it's not premine. Why are you opposed to premining? (I had to look up the term, so I'm not baiting you! I don't see the problem, so I'd like to hear your thoughts).

Premining devalues future work done on a cryptocurrency because the underlying idea is to decentralize money, and the coins found at the start of a blockchain are easier to generate because the target difficulty for finding a block is significantly lower.

The most famous case of premining I can think of is https://en.wikipedia.org/wiki/Coinye (ltc clone), where people started mining it after dogecoin began. Dogecoin was in its first few weeks of release and had an extremely active number of miners; and was even more profitable to be mining than bitcoin at the time. There was speculation that having a celeb figure attached to a currency could bring the cryptocurrency movement mainstream; but when the block explorer for kanyecoin was released it was found that a very large number were premined by the developers, and few people considered it was worth dedicating mining time towards. The devs basically dumped all of their coins onto an exchange and abandoned the currency soon after. Premining is bad for building up a community of miners towards which an altcoin can be established for both trust and future earnings.

Post reply on HN