Live data from Hacker News

De-anonymization attacks against the privacy coin XMR

monero.forex

91–100 of 116 posts

Re: De-anonymization attacks against the privacy coin XMR

#91

Earlier quoted context omitted.

Isn't BTC privacy achievable these days with coinjoin, lightning network etc.? In that case no much reason for monero.

It still seems fantastical to me that lightning network is presented as "something running on BTC", when it is "something running completely separately, instead of BTC". Transactions on Lightning network are not transactions on BTC, and have none of the guarantees of BTC (and in fact have no reliable guarantees of no double spending). The only way to get BTC-like guarantees of no double-spending for Lightning network…

not a downvoter, but a criticism is yhat BTC doesnt actually offer defenses agaisnt double spend, at least when you use it to buy something.

if the chain swaps a month from now and drops my bbq purchase, the bbq shop isnt getting their bbq back, even though i get my BTC back on the new chain. the ethereum fork for ethereum classic also doubled everyone's wallets, which i'd consider to be a double spend

The double spend protection is quite limited, so whats the big loss from lightning?

Re: De-anonymization attacks against the privacy coin XMR

#92
post #44

Earlier quoted context omitted.

I long used to think that private money was a good thing for freedom helping the little guy living under state repression, but I'm recently starting to worry that it will do the opposite, by helping the ultra-rich engage in corrupt schemes. The rumors that people bought Trump-coin for the sole purpose of currying favor got to me.

None of the transactions systems are aiming to solve for that. The legacy financial system enables this too. Trump coin just happens to be more liquid than expensive dinner seats, campaign donations, and less cumbersome than a Trust. It is not private. So its fine to feel disillusioned from that goal because it was a misplaced goal. Monero on the other hand is private by default, and you can disclose transactions. It…

a bigger better thing it does is fund the north korean nuclear program.

easy to steal, liquid to sell, cant be confiscated.

Re: De-anonymization attacks against the privacy coin XMR

#93
post #6

If the US debt problem leads to capital controls, using Monero will become a federal offence overnight. Might as well call it money-laundering coin.

[flagged]

properly, money laundering is:

1. a predicate crime - the illegal thing you did to make money 2. placement - getting that money into the financial system 2. layering - hiding the money in legitimate transactions 3. integration - getting the money out

it sounds like you do have the predicate crime though, in some form of illegal drug dealing, since you mention trying to interfere with the government. if you actually think its unconstitutional, you might consider getting caught, and bringing your case up to the supreme court so that it can be struck for being unconstitutional.

Re: De-anonymization attacks against the privacy coin XMR

#94
post #66
post #64

Earlier quoted context omitted.

It's massively common. USDT is the usual coin of choice because even though the ledger is public, the convenience and relative stability massively outweighs the security risks. In the jobs I've seen, the marks will be 'investing' in BTC but the criminals will be moving those funds out into USDT the moment it hits the bandit wallet.

USDT can be frozen so its not the best choice. Its definitely a failure of the Tether team if criminals can openly use it to launder funds without it getting frozen, but they are famously anti regulation.

From what I've heard about Tether (allegedly printing tethers backed by loans to insiders, or backed by very risky commercial paper, or even potentially billions of USDT backed by nothing), I think being useful for money laundering is the least of anyone's worries...

Re: De-anonymization attacks against the privacy coin XMR

#95
post #44

Earlier quoted context omitted.

> Might as well call it money-laundering coin The state's concept of money is private and it has just enjoyed help in getting data about electronic ledgers for the last 55 years, by deputizing banks. And for the last 18 it has also enjoyed public ledgers of crypto currencies. But the successful stigma of financial privacy doesn't invent its right to having data. This is just a privilege, and private money is a revers…

I long used to think that private money was a good thing for freedom helping the little guy living under state repression, but I'm recently starting to worry that it will do the opposite, by helping the ultra-rich engage in corrupt schemes. The rumors that people bought Trump-coin for the sole purpose of currying favor got to me.

> but I'm recently starting to worry that it will do the opposite, by helping the ultra-rich engage in corrupt schemes. The rumors that people bought Trump-coin for the sole purpose of currying favor got to me.

How would government knowing exactly who spends what where help in that scenario?

Re: De-anonymization attacks against the privacy coin XMR

#96
post #92

Earlier quoted context omitted.

None of the transactions systems are aiming to solve for that. The legacy financial system enables this too. Trump coin just happens to be more liquid than expensive dinner seats, campaign donations, and less cumbersome than a Trust. It is not private. So its fine to feel disillusioned from that goal because it was a misplaced goal. Monero on the other hand is private by default, and you can disclose transactions. It…

a bigger better thing it does is fund the north korean nuclear program. easy to steal, liquid to sell, cant be confiscated.

[deleted]

Re: De-anonymization attacks against the privacy coin XMR

#97

This is by no means a comprehensive analysis. This analysis misses the most major limitation with Monero's decoy based approach to transaction obfuscation: Eve-Alice-Eve attacks (also known as ABA attacks). It also misses an analysis of the possible insecurity of churning and a significant history of randomness implementation errors and flooding attacks specific to Monero. The exact consequences of some of these atta…

100% agree that this is not a comprehensive analysis.

For instance, recently a core Monero dev published something called OSPEAD which is a proposed fix to the "Map Decoder Attack" which he also publicly disclosed at the same time : https://github.com/Rucknium/OSPEAD

The TLDR is that Monero has about 75% less privacy than anybody thought, and this attack is still "live" in production. It requires a mandatory upgrade by every node on the network to fix and as far as I know, no fix has been decided upon yet. The attack can be combined with other attacks to completely de-anonymize transactions. I recently wrote about the bug and my proposed mitigation that users can do to regain privacy here: https://duke.hush.is/memos/6/ . AMA, if you desire.

This attack (and mitigation) is not getting the attention it deserves, partially because it is technical and hard to explain and partially because it does not serve the interests of content marketers and Monero influencers.

Monero is indeed moving to ZK proofs because they are mathematically superior in every way. At a very high level, they are moving towards being more like Zcash but they are not using Zcash ZK machinery, they are rolling their own. They are called "Full Chain Membership Proofs" or FCMPs. You can read the paper about those here: https://github.com/kayabaNerve/fcmp-plus-plus-paper/blob/dev...

As another example, recently an anonymous researcher published http://maldomapyy5d5wn7l36mkragw3nk2fgab6tycbjlpsruch7kdninh... (you will need Tor Browser to access that) which explains how the Monero network is being spied on by malicious nodes, with the end result being that transaction id's can be linked to IP addresses.

There are various other examples of de-anonymization attacks on Monero but OSPEAD and network spying (which can be combined) are some of the worst, because they are very inexpensive and effective.

Re: De-anonymization attacks against the privacy coin XMR

#98
post #91

Earlier quoted context omitted.

It still seems fantastical to me that lightning network is presented as "something running on BTC", when it is "something running completely separately, instead of BTC". Transactions on Lightning network are not transactions on BTC, and have none of the guarantees of BTC (and in fact have no reliable guarantees of no double spending). The only way to get BTC-like guarantees of no double-spending for Lightning network…

not a downvoter, but a criticism is yhat BTC doesnt actually offer defenses agaisnt double spend, at least when you use it to buy something. if the chain swaps a month from now and drops my bbq purchase, the bbq shop isnt getting their bbq back, even though i get my BTC back on the new chain. the ethereum fork for ethereum classic also doubled everyone's wallets, which i'd consider to be a double spend The double spe…

First, if people didn't believe that BTC protects from double spend, then it would not be used by anybody. Secondly, the whole point of the proof of work scheme is that it's impossible, or at least extraordinarily costly, for anyone to outrun the main chain enough to publish a new block that replaces blocks from a week ago. It's in fact considered impossible for blocks from an hour or so ago.

So, assuming the BBQ supplier waited about an hour for confirmation, the chance that the money would be lost is minuscule with BTC transactions. With Lightning transactions, the same is not true at all - the customer could close their channel abruptly two months later when the BBQ joint is on vacation, and the money would suddenly vanish forever (assuming they don't catch the fraud in the time window before it becomes permanent).

Of course, in both cases, if you're the person who sent the money and the BBQ never arrived, you're out of luck entirely. Which is why the claim that BTC or Lightning enable trustless monetary transactions is mostly bogus, even with a no-double-spend guarantee. And waiting one hour for a payment to a BBQ joint to clear is basically unworkable (and the reality is more like two hours - one hour for the transaction to make it to be mined, and the other hour to confirm the block where it was included remains permanent).

Re: De-anonymization attacks against the privacy coin XMR

#99
post #29

Earlier quoted context omitted.

Yes, it scales much worse: * node resources scale with the size of the UTXO set (unspent outputs), which in Monero's case balloons to the entire TXO set (all outputs, orders of magnitude larger) * a typical 2-input 2-output transaction is 4 times larger * wallets have to track all outputs to choose random decoys for transaction inputs One can argue that this is the price to pay for significantly better privacy, but t…

Don’t forget that opaque blockchains can have invisible inflation. Transparent blockchains will always be worth more, as the user can verify that inflation has not occurred. This applies to grin as much as xmr.

wrong

https://www.moneroinflation.com/inflation

Re: De-anonymization attacks against the privacy coin XMR

#100
post #88

This is by no means a comprehensive analysis. This analysis misses the most major limitation with Monero's decoy based approach to transaction obfuscation: Eve-Alice-Eve attacks (also known as ABA attacks). It also misses an analysis of the possible insecurity of churning and a significant history of randomness implementation errors and flooding attacks specific to Monero. The exact consequences of some of these atta…

I will word this carefully since I previously worked on crypto de-anonymization attacks, but nothing in this "analysis" seems to be grounded in more than the blockchain developers echo chamber of self congratulation. Amusingly, assume the CIA has figured out a clever trick for opening up Acme Secure Envelopes in transit. If they publish a report detailing at length how amazing and tamper proof Acme products are, the…

Your point is correct, you sound like salty CIA spreading FUD because it is job of NSA to provide them with solution which did not came. :) So you are saying that ZKSnarks are CIA approved ? XD
Post reply on HN