Live data from Hacker News

Is Zcash’s encrypted blockchain Satoshi’s vision?

cryptopotato.com

51–60 of 71 posts

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#51
post #2

No. Two words. Trusted setup. Monero is way closer to Satoshi's vision, up to and including having an unknown inventor.

I really don't like the reliance on the Ceremony to prevent counterfeiting, but it is the only way science has yet discovered for how to enable full-strength (encryption-based) privacy. Fortunately, science continues to advance and I hope we'll be able to upgrade to a trapdoor-free cryptographic proof system someday.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#52
post #19
post #15

Earlier quoted context omitted.

Here's a stack exchange question: https://monero.stackexchange.com/questions/2158/what-is-mone... TL;DR Monero requires every transaction input to include a "key image" (an elliptic curve point, looks like a public key). The key image is deterministically constructed from the actual coin being spent, without actually revealing which one it is. So making sure the chain never contains a repeated key image is sufficient…

Thank you very, very much for that long and thorough answer. I need to read it through more thoroughly when I return from work. But sounds like I may need to re-think my holdings of Monero :)

Mimblewimble used properly gets nearly the same benefits that you have in Monero (essentially non interactive coinjoin) but with scaling guarantees better than bitcoin. If it was possible to ring signatures like Monero has without the scaling difficulties, I guarantee you bitcoin developers would be working on it. Friends don’t let friends invest alt coins.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#53
post #52
post #19

Earlier quoted context omitted.

Thank you very, very much for that long and thorough answer. I need to read it through more thoroughly when I return from work. But sounds like I may need to re-think my holdings of Monero :)

Mimblewimble used properly gets nearly the same benefits that you have in Monero (essentially non interactive coinjoin) but with scaling guarantees better than bitcoin. If it was possible to ring signatures like Monero has without the scaling difficulties, I guarantee you bitcoin developers would be working on it. Friends don’t let friends invest alt coins.

Thanks a lot once more! I need to read that Mimblewimble white paper.

Haha yeah the last sentence came a bit late as I have lost some money on Monero. I may just hold them until they perhaps gets even and then sell. Just liked the philosophy and idea behind. But thanks anyway :)

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#54
post #43
post #33

Earlier quoted context omitted.

This is a cool project. Thanks for sharing the link. I'll totally buy/mine some GRIN when it comes out. Things I like so far: 1) Solves privacy and scaling in a single elegant stroke. 2) Inventors seem to be anonymous. I didn't try too hard to identify them but Tom Elvis Jedusor is the French name of Lord Voldemort. This is an important feature for privacy focused coins and for cryptocurrency as a political statement…

> Reasons I'm skeptical (perhaps you can address these): 1) Monero may have first mover advantage in the privacy realm, but at the cost of prunability. Grin not only avoids that cost but further improves prunability beyond bitcoin. To me the first mover advantage will always belong to bitcoin, which will likely adopt privacy improving features in the long term. 2+3) Indeed; when evidence appears of quantum computers…

>current blockchains will need to adopt post-quantum crypto methods of signing transactions, and migrate existing balances.

That's sort of true. Bitcoin is mostly quantum safe. The only vulnerability is that a quantum computer could deduce a private key and change a transaction during the brief (~1 hour) window when the transaction is pending. Quantum computers would have get to ~660*10^6 quantum gates per second before this becomes feasible (roughly a clock cycle of 660 MHz in classical terms). The first quantum computers will likely be slower than this.

The bitcoin ledger itself is quantum safe because addresses are hashes of public keys rather than just naked public keys. QC won't significantly speed up hash inversion thus a QC won't be able to steal funds out of an arbitrary address.

This is what I mean by bitcoin "layering the crypto" so as not to have a single point of failure. Sure bitcoin could have just used public keys as addresses. Instead it choose to use hash's of keys seemingly for no reason. Some of the facets of Satoshi's design are so genius that we only learn their purpose years later.

>My hope is that quantum computer development runs into insurmountable barriers...

ehhh maybe the GRIN devs should think about this now rather than later.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#55
post #15

Earlier quoted context omitted.

Here's a stack exchange question: https://monero.stackexchange.com/questions/2158/what-is-mone... TL;DR Monero requires every transaction input to include a "key image" (an elliptic curve point, looks like a public key). The key image is deterministically constructed from the actual coin being spent, without actually revealing which one it is. So making sure the chain never contains a repeated key image is sufficient…

Doesn't it scale? Isn't it the case that the Merkle tree holding all the shielded coins can be pruned just as easily as the Merkle tree storing Bitcoin transactions? Pruning either tree eliminates the information needed to verify the claimed owner of a coin in a pruned branch, correct?

You can’t get rid of the requirement that this data be kept around. Either you implicitly have the validators keep it, which is what I assumed for simplicity, or you have the spender provide a Merkle proof, the generation of which requires access to that data set that scaled linearly with the entire block chain history. On the face of it this is a bad trade off because signers often need to be low power mobile or tamper resistant devices with limited bandwidth, whereas full validation nodes have access to high powered servers on low latency networks. A middle ground is to have a third party archivist maintain these records and provide proofs for a fee. That’s fine until running one of these becomes beyond the reach of individuals or scrappy organizations, as them you’ve introduced de facto centralized gateways.

This Merkle tree commitment approach is basically what zerocoin and zcash do — except with fancy zero knowledge proofs to achieve full cryptographic anonymity. But to make those proofs you still need the data...

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#56
post #17

The unfortunate thing to me about Zcash is that privacy is opt-in. It would be like if Signal was default no privacy, but then you could enable it per message if you wanted to send something secret. Governments could just ban you from turning the privacy on and we've already seen this happen with TOR. Opting into privacy "raises suspicion", and we need services where privacy is enabled by default. Monero does this.

It's just as possible to not use Monero's mix-ins as it is to use Zcash's transparent addresses. So no, Monero doesn't win here.

not true. Monero has had forced ringsize > 1 (the new term for mixin, because mixin implies active mixing) since around 2016 or so.

http://moneroblocks.info/stats/ring-size

ooh i can edit. And the recent fork increased the minimum to 5. Hopefully some magic math will soon make it possible for a minimum of 10.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#57
post #49
post #17

The unfortunate thing to me about Zcash is that privacy is opt-in. It would be like if Signal was default no privacy, but then you could enable it per message if you wanted to send something secret. Governments could just ban you from turning the privacy on and we've already seen this happen with TOR. Opting into privacy "raises suspicion", and we need services where privacy is enabled by default. Monero does this.

you can interpret this as a problem and as a solution too. Yes, ztransactions will could dye your money so no exchange will accept it because you are a terrorist and the US can ban the usage of ztransactions. In my opinion it's better like this, since the overall goal is to not rely on exchanges and regulatory thirdparties. In a P2P economy (which is this technology is meant to lead us) fungibility problems are not a…

> In a P2P economy (which is this technology is meant to lead us) fungibility problems are not a thing beacuse there is no relative central party to make a standard.

wat?

fungibility is not about a standard. fungibility applies at every level.

"Hrmmm yes while you are looking at this car here I'm just going to scan your blockchain activity and hrmmmmm it seems that you are in about the top 30% of income in this country so yessss the price of this car is X"

boom. That car salesman just defacto made your tracecoin less valuable than some poor shmuck in the lower 50%.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#58
post #54
post #43

Earlier quoted context omitted.

> Reasons I'm skeptical (perhaps you can address these): 1) Monero may have first mover advantage in the privacy realm, but at the cost of prunability. Grin not only avoids that cost but further improves prunability beyond bitcoin. To me the first mover advantage will always belong to bitcoin, which will likely adopt privacy improving features in the long term. 2+3) Indeed; when evidence appears of quantum computers…

>current blockchains will need to adopt post-quantum crypto methods of signing transactions, and migrate existing balances. That's sort of true. Bitcoin is mostly quantum safe. The only vulnerability is that a quantum computer could deduce a private key and change a transaction during the brief (~1 hour) window when the transaction is pending. Quantum computers would have get to ~660*10^6 quantum gates per second bef…

> The bitcoin ledger itself is quantum safe because addresses are hashes of public keys rather than just naked public keys.

This is true of later addresses, but in early times, addresses were naked public keys, and tons of bitcoins are thus vulnerable to slow quantum computers.

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#59
post #16

Earlier quoted context omitted.

Mimblewimble [0] is a radically different approach to privacy and fungibility, making all transactions look alike. [0] http://mimblewimble.cash/

Mimblewimble doesn't provide very strong privacy protections. Indeed, to a first approximation all it hides is transaction value. The aggregatable transactions only provide privacy if you assume they are generated, fully formed from nothing. Which isn't true. If they are passed around the network and things are aggregated in, than anyone observing the networking will see exactly what went in and what didn't. IF you p…

It's true that an entity like NSA would notice transactions at their point of origin, before aggregation, and could relate inputs to outputs.

Reducing this linkability doesn't require a trusted party though, as MimbleWimble is compatible with the valueshuffle [0] protocol.

[0] https://people.mmci.uni-saarland.de/~truffing/papers/valuesh...

Re: Is Zcash’s encrypted blockchain Satoshi’s vision?

#60
post #43
post #33

Earlier quoted context omitted.

This is a cool project. Thanks for sharing the link. I'll totally buy/mine some GRIN when it comes out. Things I like so far: 1) Solves privacy and scaling in a single elegant stroke. 2) Inventors seem to be anonymous. I didn't try too hard to identify them but Tom Elvis Jedusor is the French name of Lord Voldemort. This is an important feature for privacy focused coins and for cryptocurrency as a political statement…

> Reasons I'm skeptical (perhaps you can address these): 1) Monero may have first mover advantage in the privacy realm, but at the cost of prunability. Grin not only avoids that cost but further improves prunability beyond bitcoin. To me the first mover advantage will always belong to bitcoin, which will likely adopt privacy improving features in the long term. 2+3) Indeed; when evidence appears of quantum computers…

> I'm not aware of any post-quantum equivalent to Pedersen commitments

I just learned from Andrew Poelstra of just such a construction [0], which even supports migration from Pedersen commitments.

[0] https://eprint.iacr.org/2015/628

Post reply on HN