Live data from Hacker News

Is Zcash’s encrypted blockchain Satoshi’s vision?

cryptopotato.com

41–50 of 71 posts

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#41
post #9
post #2

No. Two words. Trusted setup. Monero is way closer to Satoshi's vision, up to and including having an unknown inventor.

The trusted setup is not as bad as those two words make it sound without any context: 1. All people present in the trusted setup would have to be colluding or be compromised to cause an issue. 2. Some of these people have reason to make the currency succeed, because they own large amounts of zcash. 3. Some show the lengths they went to to prevent compromise: https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trus…

I'd suggest you read my "Cypherpunk Desert Bus" article a little more closely, notably section 1.2 where I say:

"Until the software and deterministic builds are audited, the entire ceremony is a bunch of crypto hocus pocus that means nothing."

The trusted setup is really dubious and highly vulnerable; so far my efforts were wasted due to the fundamental problems that everyone in the multi-party-computation ran the exact same unaudited software.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#42
post #35

When Zooko says that Zcash "is a kind of money that doesn’t come from any government or company" he is only 90% correct...

80% for the first 4 years. 90% "eventually"

Correct. 20% of block rewards before the first halving (roughly the first 4 years, accounting for half of the eventual Zcash supply) goes to the "Founders Fund" for investors and developers.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#43
post #33
post #16

Earlier quoted context omitted.

Mimblewimble [0] is a radically different approach to privacy and fungibility, making all transactions look alike. [0] http://mimblewimble.cash/

This is a cool project. Thanks for sharing the link. I'll totally buy/mine some GRIN when it comes out. Things I like so far: 1) Solves privacy and scaling in a single elegant stroke. 2) Inventors seem to be anonymous. I didn't try too hard to identify them but Tom Elvis Jedusor is the French name of Lord Voldemort. This is an important feature for privacy focused coins and for cryptocurrency as a political statement…

> Reasons I'm skeptical (perhaps you can address these):

1) Monero may have first mover advantage in the privacy realm, but at the cost of prunability. Grin not only avoids that cost but further improves prunability beyond bitcoin. To me the first mover advantage will always belong to bitcoin, which will likely adopt privacy improving features in the long term.

2+3) Indeed; when evidence appears of quantum computers becoming feasible at breaking EC crypto, current blockchains will need to adopt post-quantum crypto methods of signing transactions, and migrate existing balances. Since EC crypto is more heavily ingrained into Grin, it may have a much harder time than the more modular bitcoin design, or even find it impossible to do so. I'm not aware of any post-quantum equivalent to Pedersen commitments. My hope is that quantum computer development runs into insurmountable barriers...

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#45
post #15
post #13

Earlier quoted context omitted.

Could you elaborate on this flaw, or perhaps point to a link - especially with regards to Monero?

Here's a stack exchange question: https://monero.stackexchange.com/questions/2158/what-is-mone... TL;DR Monero requires every transaction input to include a "key image" (an elliptic curve point, looks like a public key). The key image is deterministically constructed from the actual coin being spent, without actually revealing which one it is. So making sure the chain never contains a repeated key image is sufficient…

Very good summary of the issue. This is actually a solveable problem. You use a tree of spent serial numbers and non-membership proofs. This basically eliminates the over head to the network of managing serial numbers and checking for double spends. However, it requires they be stored somewhere because some of that data is needed to make non-membership proofs and update the tree. To further reduce it, keep separate serial number data structures per some long epoch and reveal which epoch a coin was create in on spending. Now the burden epochs is only one people with coins in that epoch. For most reasonable scales, epochs can be very very long. Like 10 years.

As an aside, the fact that mimbelwimble does not have this issue should make you wonder just how much privacy it provides.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#46
post #16
post #2

No. Two words. Trusted setup. Monero is way closer to Satoshi's vision, up to and including having an unknown inventor.

Mimblewimble [0] is a radically different approach to privacy and fungibility, making all transactions look alike. [0] http://mimblewimble.cash/

Mimblewimble doesn't provide very strong privacy protections. Indeed, to a first approximation all it hides is transaction value. The aggregatable transactions only provide privacy if you assume they are generated, fully formed from nothing. Which isn't true. If they are passed around the network and things are aggregated in, than anyone observing the networking will see exactly what went in and what didn't. IF you pass them to a trusted party, well then you have a centralized party you trust for privacy.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#47
post #15

Earlier quoted context omitted.

Here's a stack exchange question: https://monero.stackexchange.com/questions/2158/what-is-mone... TL;DR Monero requires every transaction input to include a "key image" (an elliptic curve point, looks like a public key). The key image is deterministically constructed from the actual coin being spent, without actually revealing which one it is. So making sure the chain never contains a repeated key image is sufficient…

Very good summary of the issue. This is actually a solveable problem. You use a tree of spent serial numbers and non-membership proofs. This basically eliminates the over head to the network of managing serial numbers and checking for double spends. However, it requires they be stored somewhere because some of that data is needed to make non-membership proofs and update the tree. To further reduce it, keep separate s…

That doesn’t solve the issue. It just pushes the responsibility of holding all this data onto the signer instead of the validator, which is a free choice. But signers are usually more space constrained than validators.

And there is no connection between privacy guarantees and this issue. I’m not sure what you’re getting at there.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#49
post #17

The unfortunate thing to me about Zcash is that privacy is opt-in. It would be like if Signal was default no privacy, but then you could enable it per message if you wanted to send something secret. Governments could just ban you from turning the privacy on and we've already seen this happen with TOR. Opting into privacy "raises suspicion", and we need services where privacy is enabled by default. Monero does this.

you can interpret this as a problem and as a solution too. Yes, ztransactions will could dye your money so no exchange will accept it because you are a terrorist and the US can ban the usage of ztransactions. In my opinion it's better like this, since the overall goal is to not rely on exchanges and regulatory thirdparties. In a P2P economy (which is this technology is meant to lead us) fungibility problems are not a thing beacuse there is no relative central party to make a standard.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#50

Is it just me or are more and more stories which look like fluff pieces for ZCash coming up on the HN frontpage? If they were a startup, I'd guess they were prepping for an IPO/acquisition. Most of them have titles with rhetorical questions, and come across as marketing pieces more than anything else. Really weird.

Along the same line, you get public endorsements and comments from people like Snowden and Assange. ZCash, as opposed to f.e. Monero, is a private company and consciously spending time, money and effort on brand-building and PR. Nothing really weird with that IMO.

For the record, someone who gives an interview to a journalist almost never gets a say over what headline it gets published under. Did you read the article? I really liked the way it came out!

Also for the record, we didn't ask Assange or Snowden to start accepting donations in Zcash or anything. Or at least, I didn't. It's quite possible some other members of the Zcash community did without my knowledge.

[New account because I can't remember my password and when I ask it to the reset the password on zooko-zcash it says "sorry there is no valid email address associated with that account". Maybe it thinks "zooko@z.cash" is not a valid email address.]

Post reply on HN