Zerocoin startup revives the dream of truly anonymous money
wired.com
wired.com
[UPDATE] Let me try to make this a little more precise: I don't understand the appeal of anonymous digital money. Physical cash is very useful, and I would not want it to go away. But even physical cash is not completely anonymous because you have to be physically present to exchange it, which entails a certain amount of risk, and that puts some checks-and-balances on potential abuses. Anonymous digital money does away with those checks-and-balances and makes a lot of activities with questionable societal value like crypto-extortion much more lucrative than they were before. For example, malware that encrypts your hard drive for ransom was unheard of before the advent of Bitcoin.
Regions like Scandanavia are trying to eliminate anonymous money.
If you eliminate anonymous money, it is unclear how freedom of speech, religion, inquiry etc can be preserved.
Anonymous money is always going to be less convenient that paying in the clear. But it should exist.
Good Luck Electric Coiners
Consider that if the money was truly anonymous, we wouldn't be able to use serial numbers to track down who used it.
People have used anonymous money in the form of coins for millennia. It wasn't until the 1860s that the first one-dollar bill in the U.S. was printed with serial numbers. For ~95% of the time that money has existed, it has been what you would call "truly anonymous."
If you go back to pre-coin history and use weights of silver as opposed to minted or hammered coins, you're looking at maybe 153 years of serial numbers vs. about 5,000 years of non-serial numbers. "Truly anonymous money" is the historic norm; the current situation with numbers printed on paper/linen/plastic is something of a historical aberration.
Even if the bank gives me a tracked 20, I can easily "launder" it by using it to buy something. Now I have $19 in anonymous cash and stick of gum.
Which is to say, the specter of "you're violating a bunch of laws all the time anyway, so better to make it harder in general to prosecute stuff".
Recall the Bennett Haselton (sp?) fracas:
http://yro.slashdot.org/story/13/06/07/1439220/seeking-fifth...
[1] Of course, it always will, irrespective of a judge's sheepish instructions.
Great contribution there, Tom.
I think it's great that Uber is undercutting the absolutely shitty medallion system. But that doesn't mean I'm okay with them underpaying their workers, for example.
The reason I am for anonymous money is that it is of no one else's business what I do with my money. It's really that simple.
EDIT: David Friedman wrote a good piece on the misuse of "externality" arguments that every Freedom-loving person should know (and I'd be surprised if lisper did not know of it): http://www.daviddfriedman.com/Machinery_3d_Edition/The%20Mis...
What is basically desirable is that (some kinds of) transactions can be made anonymously.
I think you might be surprised.
> it is of no one else's business what I do with my money
If you use your money to, say, hire a hit man to kill me, how is that not my business?
> It's really that simple.
No, it's really not that simple at all. You should read this:
But I know what you mean, you don't want non-directly-involved third parties to know about transactions you make. But then there are always contracts, laws and regulations you must follow and be held to account on. These are the things which bind the economy together and make modern civilisation work.
Your bank balance and the things you buy with your money do not exist in a vacuum. There will always be a trail of your spending left behind anyway, even if it's just asking the people you bought things from what you bought and when. It's an inescapable fact deeply embedded into the nature of what money is, and the function it serves in society.
Say I want to pay somebody in another country for perfectly legal goods. (Example I've personally done: local food from a friend in Japan)
My options are:
* Bank wire transfers (expensive and annoying to set up, requires paperwork)
* Cash transfer services like Western Union or Moneygram (expensive and inconvenient, requires physical presence at a branch location for both parties, if one exists in the location)
* Electronic cash transfer services like PayPal (awful and opaque CS/policies, expensive, requires linking a physical bank account/credit card, something people in many countries don't have - if they operate in the country at all)
* Currency through the mail (danger of never getting there)
* Something like Bitcoin (annoying to set up.. once)
The last one ticks all the boxes in a way that the previous few do not.
- It's available everywhere with an internet connection without exception
- It's not subject to any middleman fees (though you can splash out a very tiny amount of money to get the transaction processed quicker)
- It's not subject to any middleman misbehavior, the transaction is strictly between you and the other person.
- There's no paperwork or going to a physical location required, it's all electronic
- Once you send a transaction, it will most assuredly reach its destination
- It requires nothing from the sender/receiver other than a piece of software
The (pseudo?)anonymity is just a bonus in this instance. It's none of the GCHQ, NSA, their associated cronies, etc business knowing what I'm buying and why.
Of course if you're getting something physical shipped to your house, anonymous currency doesn't help you.
Really? Maybe okay with your current government, but I bet their are governments out there that you would not be fine with seeing this information when they are in a position to attack you, warrant or not. And there is no guarantee that your government will not become the same.
One thing Jeff Bezos can't do is trump up "structuring" charges, arrest me, prevent access to decent legal representation by freezing my assets, and then use the threat of decades in prison to extort me into accepting a plea deal of being locked in a cage with violent people for just a few years.
I'd be FAR more accepting of Amazon having full detailed knowledge of my financial life than an entity with the real power to destroy my life on a whim.
In short, those checks and balances are starting to become corrupt and thus people create a means to do away with them.
Witness this occurring recently with Wikileaks being banned by Visa, MC, and PayPal without any criminal complaint filed against them, much less a trial.
The government cannot have the ability to censor payments or perform traffic analysis on one's payments and receipts if we are to maintain a free and civil society. The US Supreme Court has ruled several times that free speech is not free speech without anonymous speech.
Dependency chart:
(anonymous payments) <- (anonymous publishing) <- (freedom to publish unpopular opinions without reprisal) <- (freedom to publish with the intent of changing public opinion and changing society) <- (free and civil society)
Another: (anonymous payments) <- (untracked travel) <- (freedom of association with unpopular groups) <- (ability to form new political parties) <- (free and civil society)For instance, it was impossible at one stage to donate to Wikileaks by Credit Card or Paypal due to Senatorial Pressure on private business.
If you have never read A Clockwork Orange by Anthony Burgess, it is a 20-minutes-from-now sci-fi story that briefly explored the consequences involved in making people physically unable to break the law. Go ahead and read it. It's considered by some to be a classic in the same vein as 1984.
I consider it vitally important that there be some avenue by which a person can choose to break the law, even if there is only a miniscule likelihood of subsequently escaping punishment for it. Otherwise, the law becomes the iron collar around our necks, and those at the other end of the chain are able to drag us wherever they choose, just by rewriting the statutes.
"One has a moral responsibility to disobey unjust laws." --M.L. King Jr.
"Protest beyond the law is not a departure from democracy; it is absolutely essential to it." --H. Zinn
"It is not always the same thing to be a good man and a good citizen." --Aristotle
"An unjust law is itself a species of violence. Arrest for its breach is more so." --M. Gandhi
"...if it is of such a nature that it requires you to be the agent of injustice to another, then I say, break the law." -- H.D. Thoreau
How then will you engage in nonviolent civil disobedience when you find that you cannot break the law, even when throwing your whole strength against it? What will happen when every person who stands in protest vanishes into an oubliette the instant after they rise to their feet?The impulse to stamp out crime so thoroughly as to make it practically impossible is an open invitation to the tyranny of the totalitarian police state. I much prefer the sort of society where people can choose between doing good and doing evil, by the measure of their own moral standard, over one where people are forced to obey the commandments of others.
To be perfectly honest, that's exactly the reason I think anonymous money is a good idea. In a world where laws for huge nations are made by corporations, overthrow of government is impossible, and change within the system is too slow to solve problems now, breaking the law and getting away with it is one of the few remaining recourses an individual wishing to exercise their freedoms has.
The kinds of crimes this enables are exactly the kinds of crimes I don't think should be crimes: drug use, prostitution.
Yes, it also enables tax evasion. However, I would argue that it's merely leveling the playing field in this respect: the ultra-rich already have legal means of avoiding taxes which aren't available to most people. Anonymous currency just makes it possible for average-to-poor people to avoid taxes. And ultimate, I'm not entirely against tax evasion: I like my roads, schools and libraries, but the US has spends more on the military than the next 7 top spenders combined to kill people for economic reasons, and I don't have any way of preventing my tax money from going to that.
The kinds of crimes I do care about leave behind lots more evidence besides a money trail: murder leaves behind bodies, rape leaves behind witnesses (victims). Typically money trails have little to do with investigations on these kinds of things.
In the end, though, I don't think talking about the upsides and downsides of anonymous money makes any difference. Bitcoin isn't really anonymous, but it's only a matter of time before easily anonymous money exists, and there's really nothing that can be done to stop that.
Cryptonote, by default, is an opaque blockchain - your transactions are not visible to the world. But, let's say you're a non-profit organization and you do wish for your donations to be public. Cryptonote allows for that using a "view key".
In this way, you get the best of both worlds - privacy by default, and openness when you need it.
The cryptonote wallets are still in their early stages, but the various coins are available and trading on exchanges today. And you can even use them to pay bitcoin based merchants using a service like ShapeShift or xmr.to .
Does the 'mixing' of coins happen on a server (so you trust the server not to log anything) or does it happen p2p so said agencies can analyze the network?
Mixing does not happen on a server - that would be an atrocious violation of privacy. Monero (and other cryptonote coins ) use ring signatures - https://lab.getmonero.org/pubs/MRL-0004.pdf
There is also work being done to employ gmaxwell's Confidential Transactions: https://github.com/ShenNoether/MiniNero/blob/master/RingCT0....
Cryptonote's ring signatures scale linearly in the number of people your transactions are mixed with. As a result, you can't mix an individual transaction with that many people without it getting too big and too computationally costly(chaining transactions doesn't solve this). In contrast, Zerocash mixes every transaction with every other transaction ever[1].
If you are worried about maintaining privacy given repeated interactions with merchants or others who already have some partial information about you, the size of the anonymity set matters considerably. Longterm intersectional attacks are a major problem with anonymity systems. The smaller the set you mix with on any given transaction, the easier it is for some third party to use outside information to eliminate everyone else in the mixing set (e.g because she knows no one else in the set was online at the time of the transaction or was in your approximate geographic area), and determine the true spender. One of the few effective defenses we have for this is to simply include as many people as possible in the anonymity set. If you want to avoid companies building financial profiles of users from the blockchain, this is precisely the type of attack you need to thwart.
[1] Technically, up to 2^64 transactions and the networks ability to handle the spent serial number list. So there is a limit, but it's rather large.
Zerocoin's trade-offs are massive: untested / unreviewed cryptography, a trusted initial accumulator that can ruin the anonymity for everyone forever, a significantly larger transaction size, and a blockchain so opaque that double-spends and false coin creation cannot be seen.
Those are the issues that matter, and Monero suffers from none of those problems.
This is false: even if somebody compromises the initial setup (which, if implemented using the proposed MPC protocol, would require compromising every single participant; compromising n-1 parties doesn't do anything), the system continues to enjoy the same zero-knowledge guarantees. Compromised setup or not, in Zerocash the anonymity set is all participants of the system.
Also there is nothing so suggest that a clever MPC will solve the collusion problem. Of course the participants will make claims about their honesty, but if ZeroCoin is worth massive amounts of money the temptation to seek collusion will be there.
Of course, whilst it's true that some participants might stick to their proverbial guns, what is going to prevent a motivated state-level attacker from monitoring as many participants as they can during the computation? Then they only need to compromise the handful that they couldn't monitor, and for that they have rubberhose cryptanalysis.
That said, I'm not sure how they will ever be able to scale their product and comply with all the reporting requirements of the feds. Traditionally, the primary users of anonymous money transfer systems have been those trying to evade either the law man or the law (or both).