Bitcoin Users Reveal More Private Information Than They Realize
medium.com
medium.com
That said, I hope this is less of a surprise to people now: I coauthored one of the first pieces of working pointing out basically these same issues back in 2011 - almost 5 years ago:
http://anonymity-in-bitcoin.blogspot.ie/2011/07/bitcoin-is-n...
It's interesting to see what perceptions have changed. That there's still confusion shows how hard it is to disseminate information about encryption and privacy; maybe this the same reason e2e email encryption seems so difficult to get adopted, even decades after PGP: it's just hard to communicate about the bounds of privacy.
One point: the 'clusterisation' mentioned in the linked article isn't 'magic': most of the techniques people are using are actually very simple heuristics, based on properties of the Bitcoin protocol (transaction input linking, which we demonstrated), or assumptions about transaction 'change' (prone to false positives).
It's worth noting that there are more sophisticated tools that could be applied: machine learning or stats methods - but I've not seen them yet. Possibly because its hard to come up with good training datasets (unless you are a retainer or wallet?) and not worth investing in when simple methods show so much. But its worth bearing in mind that more complex analysis is possible.
The overall conclusion being, IMO, that if you want privacy, it's probably usually easier to design it in from the start, rather than retrofit by progressively patching holes in a leaky system, against progressively better attacks: the latter is so hard to get to the point where it works solidly: for human reasons as much as technical ones; I think Bitcoin privacy seems destined to be an example of this.
I think it has more to do with those methods not being 'deterministic' for a broad interpretation of that word. By that I mean, if you're doing de-anonymizing for regulatory purposes, it's a hard sell to convince people 'these transactions are correlated because my neural net, which is a complete black box, says so'.
ISIS, for instance, can only hold territory because everyone accepts the claims on value that they give their foot soldiers. I want to stop honoring those claims to reduce their power. Manufacturers shift their carbon emissions to friendly jurisdictions instead of, you know, not risking our only home for cheap consumer goods. They do this to acquire more claims on value, and I don't want to honor those claims because I like Earth.
Fungibility is literally killing people and destroying our planet. I think we'll be better off without it, though as with all significant social shifts, it probably needs more study to avoid unforeseen consequences like genocides and stuff. Blockchains are not anonymous—their incorruptible histories give us the tools to reshape our society. Use them.
That's a slippery slope and you probably don't want to go down that road. Think of the power that would confer to a totalitarian state.
edit: See also https://github.com/shennoether/ringct and https://github.com/monero-project/bitmonero
Yet - I also deeply felt intuitively that the Panama Papers exposed bad behavior. The bad behavior it exposed were people aiming to archive financial privacy.
I can't really reconcile the two beliefs.
It uses Ring Signatures and a few other cryptographic tricks to make the currency provably unlinkable and untraceable. In 6 months, the network will hard fork to support what is being called "RingCT", which will hide the amount sent in a transaction, in addition to the sender and the receiver that are hidden at the moment.
If you want to read some more about it, ask all the questions you like on /r/monero, they'll be happy to get as technical as you want.
1. http://www.euronews.com/2015/12/16/cash-losing-its-currency-...
2. http://www.theguardian.com/world/2016/feb/08/german-plan-pro...
Privacy and anonymity in all forms can both benefit and be abused, which is why there's usually some sort of balance. Bitcoin doesn't attempt to find any balance, which is too bad.
Physical currencies are anonymous, and they are not widely seen as unethical.
Difficult but not impossible, you can easily carry $100,000 in $100 notes in a bag, and at most you would only need to carry a thousand or so.
As far as legally stashing cash, a large safe or gold would suffice.
Well, true anonymity via zero knowledge proofs of course.
Does it resist clusterization?
Also, note that even against an adversary that can observe all connection metadata, Zcash maintains strong unlinkability of which notes are involved in a private transaction.
One way to try to deter pump-and-dump is to make it so that the founders don't have any sort of privileged position, but then how could you afford to do all of the work to create a solid, usable protocol? The Zcash team (https://z.cash/team.html) is a world-class team of experts, and we all have mouths to feed during the years of our lives that we're devoting to this project.
Our solution is to trickle the Founders Reward out to the founders incrementally over the first four years, integrated with the rhythm of mining.
This militates against pump-and-dump in two ways:
1. Neither the Founders nor anybody else has a giant stash of Zcash at the beginning with which they can manipulate the market price.
2. The Founders are locked into receiving more and more Zcash over the first four years, so their incentive is for the price of Zcash to go up during that time.
In my opinion, this hack is awesome.
It affords us the opportunity to focus several years our lives on solving this important problem, which otherwise would probably go unsolved, and it offers a transparent and simple financial setup that users can evaluate for themselves if they think it is a good deal.
So I categorically reject the word "scam". There is no reasonable interpretation of the word "scam" which applies to the Zcash Founders Reward.
Don't get me wrong - You're doing great work and I hope it pays off, but I won't be using it unless it's forked and the founders reward is removed. I just can't trust it with 10% of the coin in control of a small group who didn't have to "pay" to get it.
I understand the desire to pay the founders, but couldn't something closer to the Bitcoin Foundation work?
The separate altcoin is the smartest way to experiment with it for now at least.
"As I described on my blog post about "the Zcash Founders Reward", this seems to align incentives in everyone's best interest."
1: https://forum.bitcoin.com/ama-ask-me-anything/i-m-zooko-wilc...
Nothing about what he said prevents this at all. It's still a pump and dump scheme, just longer term.
Basically they solved the most minor part of the pre-mine problem and claim they solved the whole issue.
"Pump and dump" means fraudulently manipulating the price of a stock by making deliberately misleading or inaccurate statements in order to sell it at a premium. That's illegal under securities law. If you invest in something that then increases in value over a long period because people generally think it is valuable, and at some point you sell it, that is not "pump and dump".
Declaration of interest: I'm a Zcash developer and I hold some shares in Least Authority, which owns part of Zerocoin Electric Coin Company.
[1]: https://www.elementsproject.org/elements/confidential-transa...
From what I gather the key to bitcoin always was that it was decentralized, not that it was private. And over time even the decentralized has been hollowed out quite a bit.
This is not true.
You can sign partial parts of a transaction and have M of N signatures. This is what mixing services are designed to do.
However, if you are using a QT wallet it is probably generally true.
With fiat currency you get the good and the bad. With digital currency you get the good and the bad.
JoinMarket is a good solution that works on Bitcoin today.
Monero is a good altcoin which will automatically mix your coins using crypto. I believe it is more powerful than JM but requires using an altcoin.
Zcash offers unmatched anonymity powered by fancy new crypto (less tested, less certainty on the security, but much more powerful). Still under development, but I'm guessing will be more ready in August.
Assuming no mixer reputation, they allow a party to steal your coins. Note that breaking a large transaction into small pieces allows you to determine a sort of short-term reputation while only risking one piece at a time.
My standard first two steps used to be SharedCoin->BitcoinFog, for example.
A PC name for money launderers. If you need a money launderer, you should rethink what you're doing.
Sure, like torrents aren't necessarily about ip theft.
Do you have any evidence that suggests that all users of mixers obtained their Bitcoin illegally?
This HN post is a criticism of the privacy of Bitcoin transactions. Mixers can improve the privacy of Bitcoin transactions. I don't see how your comment adds to this discussion, unless you think financial privacy is a crime - in which case your statement applies equally to cash transactions.
And why would I require that? I haven't accused all bitcoin users of anything.
> This HN post is a criticism of the privacy of Bitcoin transactions. Mixers can improve the privacy of Bitcoin transactions. I don't see how your comment adds to this discussion, unless you think financial privacy is a crime - in which case your statement applies equally to cash transactions.
The law thinks financial privacy is a crime, thus KYC laws, and as such it's on topic for any discussion of bitcoin privacy since said discussion should include the issue that you fix social problems with engineering. You can't break the law "because the protocol just works that way".
Make more sense?
As the name implies, this law only applies to (financial) businesses and their customers. Most Bitcoin transactions are P2P and hence there is no business/customer relationship and hence there is no KYC law applicable.
That's a bit of a nonsense statement. It's a P2P payment network so you have no way of knowing if most of the transactions going across it are between businesses and customers or person to person. Quite simply that's a claim you can't back up.
By the way, that is a valid opinion to have - it's just that not everyone agrees that it optimal in the long run for all personal information to be auditable by a government in real time.
Sure, your bank would probably want to inquire about the source of the cash if you were to bring a briefcase of cash to the branch for a deposit. But that would be private information sharing "channel" between you and your bank - both the source of your funds and the fact that you have them in your account is reasonably private compared to a wide open ledger sitting out there with all of the txs from day one.
I'm pretty sure I didn't say that, so no.
On the Bitcoin network all transactions are public and can be linked to an individual. Without mixers it quite possible that the details of all of your financial transactions will be public.
> Are you saying you're 100% comfortable sharing the details of all financial transactions you're a part of with "the world"?
and
> using a Bitcoin mixer is equivalent to money laundering.
Are not equivalent statements.
> Without mixers it quite possible that the details of all of your financial transactions will be public.
Not true since you've forgotten the other option available to me; I don't have to use Bitcoin; you've presented a false dichotomy. I can simply choose not to use Bitcoin, consider mixing money laundering (that is after all its express intent, hiding the source of money), and still keep my financial transactions non public as they are today.
People do the same thing with real money and go to jail.