Live data from Hacker News

Keybase chooses Zcash

keybase.io

91–100 of 167 posts

Re: Keybase chooses Zcash

#91

Earlier quoted context omitted.

That's why I said "for the next few years"

I know, but you're both talking about different things. It may be 20% for the next few years, but it's also 10% overall. You're both right, why even try to nitpick over these details or correct anyone?

Since this is an investment we're talking about, I think we should strongly lean towards the interpretation of the facts that more conservative rather than less; 20% vs. 10% is a big difference to Zcash as an investment for the first few years, which could easily be longer than the lifespan of the currency.

Re: Keybase chooses Zcash

#92

I like Zcash. I think it's a good solution to a problem that Bitcoin did not solve, and creates a cryptocurrency more in line with the vision spelled out in A Cyperpunk's Manifesto than the previous attempts. (Yes, I've looked at the other attempts to build a private alternative to Bitcoin, including Monero: https://github.com/monero-project/monero/issues/1271 )

Linking to that GitHub issue is pretty embarrassing for you. Not only can it not be practically exploited, per the author of that issue, but it looks like it's just using Keccak as a stream cipher of sorts (but seeding it from /dev/urandom). That's pretty ok, and if we don't trust stream ciphers to produce pseudorandom numbers we have much bigger issues.

But more importantly, the contributors acknowledged the issue, and are fixing it. Do you honestly expect bug free open-source development? No, and the entire benefit of it being a welcoming open-source development community (instead of ZCash's centralised development team) is that it is made better by many eyes. Hopefully the OP that opened that issue spends some more time reviewing the code along with the 160+ Monero contributors.

Also, if we're going to view lapses like these as representative of a major failure, you'd best review some of ZCash's greatest hits, maybe starting with the fact that wallet encryption is ENTIRELY DISABLED in ZCash, and your wallets are stored in the clear and ready for malware to steal: https://github.com/zcash/zcash/issues/1552

- https://github.com/zcash/zcash/issues/713 - https://github.com/zcash/zcash/issues/1304

- https://github.com/zcash/zcash/issues/1522

- https://github.com/zcash/zcash/issues/1779 - https://github.com/zcash/zcash/commit/f8ada2435bd3f6b7a1165e... And let's not forget the massive attack surface that ZCash has, which leads to fun things like this:

- https://github.com/zcash/zcash/issues/98

- https://github.com/zcash/zcash/issues/178

Re: Keybase chooses Zcash

#93

Earlier quoted context omitted.

That's why I said "for the next few years"

I know, but you're both talking about different things. It may be 20% for the next few years, but it's also 10% overall. You're both right, why even try to nitpick over these details or correct anyone?

You're some random on HN. Peter Todd is a core developer who works on software that runs a billion Dollar economy (Bitcoin), and is also one of the 6 people involved in the ZCash trusted setup.

I think you need to stop talking and start listening, because the economics at play and the framing of the founder's reward is critical. Downplaying the 20%, when it is a massive sum that could be used to significantly bolster double-spend attacks and lead to all sorts of perverse incentives, is just irresponsible.

Re: Keybase chooses Zcash

#94
post #78

Earlier quoted context omitted.

Why such a small group of people though?

ewillbefull explains in another comment that the protocol is really expensive per participant: https://news.ycombinator.com/item?id=12979677

Then rushing the launch in the absence of a superior MPC protocol is just a bad idea.

Except that they had to rush the launch because they're a for-profit, centralised company, with investors that are demanding return on their investment. Thus they went with a shoddy, half-baked attempt at a trusted setup, with a whole lot of hand-waving to make it seem like it was done securely.

Re: Keybase chooses Zcash

#95
post #81

Earlier quoted context omitted.

Hmm. I don't think this is clear issue at all. I have been looking at monero block explorer, and there seems to be "mixing level" etc parameters. What do these parameters imply if not the level of how many people you mix the inputs with? I mean, your argument "you're stupid, look at this youtube video" is not very convincing either.

The Monero blockchain is comprised of inputs and outputs - public keys/one-time addresses to power of 10 denominated amounts into which each transaction is split and mixed with past public keys of identical power of 10 amounts. There are no 'orthodox' addresses on the blockchain which can be linked to transactions or to an identity.

That's just a misunderstanding of inherent blockchain limitations. It's very easy for me to reveal a bunch of addresses on the Monero blockchain.

Step 1: make a bunch of addresses Step 2: the world know it was you

That reduces the anonymity set for everyone else. They thought they were mixing with you anonymously but now that you are revealed, your participation in the mixing is useless, people would have done better to select someone else.

Combine this with Sybil attacks, criminal investigation, and other unmasking techniques and you might get the anonymity set down to 1 for a particular output, allowing you to further reduce other anonymity sets.

I was not aware, but apparently the Monero blockchain has a snowball effect to help mitigate this.

Re: Keybase chooses Zcash

#96
post #68

Earlier quoted context omitted.

I do not understand all of the details behind Monero, but basically the privacy is incomplete. When you spend money, you basically say "I am one of X people", where X is usually fairly small. It's a lot better than Bitcoin where X=1, but it's still something that advanced algorithms can get though, and it still collapses if enough people have their identities and transactions revealed. In Zcash on the other hand, you…

You're almost there, but not quite. Since Monero outputs go to dual-key stealth addresses, outputs are effectively paid to a random 256-bit "address". So if you use a mixin of 50, in a transaction with 1 input, an external observer can say "this illicit transaction spends funds from 1 of 50 possible transactions", but then you need to go to those 50 and work your way back till eventually you find a needle, in a very…

[deleted]

Re: Keybase chooses Zcash

#97
post #54

Earlier quoted context omitted.

If I recall correctly, more than 500btc was traded when the price was over 100 btc per Zcash - $350,000 in trade volume at a price exceeding $70,000 per token, when the price today has fallen to about $100 per token. Max price was almost $2,000,000 per token, someone actually literally spent that much. Perhaps the greatest example I've ever seen of tulip mania. And I'm fairly confident those were real trades, as they…

>Max price was almost $2,000,000 per token, someone actually literally spent that much. No. When zcash was trading at such a price, it was less than a single zcash coin in total. So a few people were paying significant sums for very small fractions of a zcash coin, but no one payed 2,000,000 for a single coin. The price has crashed because supply has grown exponentially. What you were seeing was supply vs demand in a…

I did not mean to suggest that a whole $2M was dropped, but someone did buy a fragment for $2M per coin.

These people buying it hopefully would have been aware of the publicly known upcoming inflation, the fact that they bought at these prices I believe is a tragedy and a black mark against Zcash.

Re: Keybase chooses Zcash

#98
5 hours and almost 100 comments later no one has pointed out that Zcash and Keybase share the same investors.

I am relieved that 'Keybase chose Zcash' purely on merit after an exhaustive and objective selection process, and that this potential conflict of interest is transparently disclosed in the linked adverticle - wait, they did no such thing.

Does it concern no one that this security-focused company is shilling for other (fundamentally questionable) products?

Re: Keybase chooses Zcash

#99
post #71
post #44

Earlier quoted context omitted.

I think it's worth paying the "genius" tax. Though controversial, the tax manifests in the form of inflation and will help fund a company that can get things running and stable. Of all the qualms I have with Zcash, I think that their mining fee is one of the cleaner ways in the ecosystem to fund altcoin development. This technology takes a lot of effort, and a lot of salary money to develop. And then you have to do m…

The slow start was a good way to avoid unfair distribution in the beginning phase when miner implementations were still being written, deployed, tested, debugged, ported and optimized. In fact I would advocate for a zero-day start, where the first few hundred blocks following genesis have exactly 0 reward, coupled with an overestimated initial difficulty, so people have some less stress-full time to get set up and so…

We will have to agree to disagree. Inflation is a trade-off - it hurts people holding the coin but it increases distribution.

I generally hold the opinion that you should not create traps for speculators, that's exactly what slow start mining is.

I think there are better ways to prevent unfair early distribution, such as a more responsive difficulty adjustment algorithm (per the work of maaku), or even just a longer inflation taper. Instead of mining half the entire supply in just 4 years pick something a bit slower.

Or do something like let Bitcoin holders as of X date collect a proportionate amount of coins in a premine. Then you get to borrow from some of the distribution that Bitcoin has already achieved.

---

And you are right as far as traders only hurting themselves. Nobody aware of the inflation schedule bought above $1k per coin, I'm almost certain of that. But I think what happened is akin to throwing a bunch of black belts into an arena with people who have never been in a fight before. Sure, they might have chosen to be in the arena, but are you free of responsibility when they get hurt? Especially if they did not realize they would be fighting champions?

Perhaps a weak metaphor. But I think disingenuous to call someone a fool simply because you had more information than they did. It doesn't seem right to me to use that to justify predatory behavior.

Re: Keybase chooses Zcash

#100

Author here. Seeing some of the discussion go down on Twitter, I feel maybe I should explain further the "white supremacist" example in the post. (one tweet at me: "So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example.") When I shared a draft post with some friends, a lot of them had an ah-ha moment, so I was hoping for the same from others. I was trying to illustrate 2 pr…

So now you can hide the fact that white supremacists are sending you money? F!@#ing weird example.

But no one has a problem with the meth cook example??

Post reply on HN