ZCash Will Be a Truly Anonymous Blockchain-Based Currency
spectrum.ieee.org
spectrum.ieee.org
"Zcash's monetary base will be the same as Bitcoin's — 21 million Zcash currency units (ZEC, or ⓩ) will be mined over time. 10% of that reward will be distributed to the stakeholders in the Zcash Company — founders, investors, employees, and advisors. We call this the “Founders Reward”."
Here's a list of the other 709 altcoins.[1] 373 of them are still tradeable. 88 have a market cap in excess of $1M. 27 have a market cap in excess of $10M. 4 have a market cap in excess of $100M. PayCoin, which was last year's heavily promoted new cool coin with a "guaranteed floor" of $20, is now at position 415 with a value of $0.002606 and a market cap of $30,247.
Since there's no cryptographically provable way to know they won't do this, well, we have to assume it's what they'll do. Distrust is the basis for cryptocurrencies afterall.
Moreover, having worked with some of them, I can assure they're not shady no-gooders...
But these guys are much less likely to be scammers than the typical no-name GitHub/Twitter/Bitcoinforums accounts promoting a new revolutionary coin.
b/ Open source works well for very complicated pieces of software.
c/ As we saw in the case of Ethereum, assuming you can buy due diligence with money alone is a mistake.
Please let me know what specific topic of zkSNARK you find challenging to explain and we can write a blog post about it.
- "MPF (Mental Poker Framework): A new family of practical and secure Mental Poker protocols" http://www.dc.uba.ar/inv/tesis/licenciatura/2010/lerner
- MAVEPAY: a new lightweight payment scheme for peer to peer currency networks: https://bitslog.files.wordpress.com/2012/04/mavepay1.pdf
- Strict Memory Hard Hashing Functions: http://www.hashcash.org/papers/memohash.pdf referenced in the Ethereum original paper: http://gavwood.com/paper.pdf
The last link is more formal, and talks about models of computation, but once again does not provide any reductions.
a) the mechanics of the proof generation, including outlining the time for proof generation.
b) How the trusted setup works; for extra credit describe in detail how zcash plans to do it.
c) an ELI5 explanation of zkSNARKS
d) a comparison of the Ben-sasson and Parno implementations.
EDIT: Time and again getting downvotes because of HN's cognitive dissonance. Pathetic low-tier reddit run-off is entering HN's market share.
letting people exchange money (directly) with whatever currencies they want
If you had any idea the amount of regulation and ridiculousness involved in banking and forex, you'd laugh at this statement.Though to be fair, the rate at which new cryptocurrency pools are being created seems to more than keep up with the growth of the economy. Who needs the government to print money when anybody can?
That kind of macroeconomic analysis assumes that everybody already owns some amount of the currency.
However in the new currency markets that are developing, you have to consider the incentive to even start accepting a currency.
One that loses value over time is not attractive to the recipient.
How about stability and liquidity instead? The more readily exchangeable a unit of currency is for goods, the easier it will see adoption. Deflationary currencies, due to their incentivization of hoarding, tend to be both unstable and illiquid, driving away anyone but speculators.
Correction: One that changes value over time is not attractive to the recipient.
You can shine the deflationary currency as much as you'd like, but economists have a consensus on why the volatile behavior of set-supply currencies are inferior.
It's precisely why the world's major currencies don't use the gold standard, but honestly, this conversation repeats itself almost every time a deflationary cryptocurrency gets posted.
Edit: This altcoin also seems to provide anonymity [1]
> The value of Gulden is determined by the demand for Gulden, as with gold or silver. The price can go up or down, but on average the value of Gulden goes up.
Sure. It will only go up. Just like all the other altcoins.
There is something that irks me about the name of this project. Gulden is the name of the Dutch currency used before the introduction of the Euro. At this point in time it has strong historical connotations (obviously), but it is also a symbol of adherents of the nationalistic political (far) right in the Netherlands. There are plenty of people from the lower socio-economic classes who fuelled by demagogues who believe we should revert to the Gulden (the actual currency, not this altcoin), close our borders, get out of the EU and once again prosper (even though we are already doing pretty well all things considered, and the EU benefits us on the whole, despite all its warts).
Choosing Gulden as a name for this project seems to explicitly place it at the heart of that particular bit of discontent. It also feels extremely pretentious to use the name of our historic currency that anyone over the age of twenty actually used. This I can grok from a commercial standpoint, but it leaves a nasty taste.
Gulden is used for actual value transfer that is easier than currently possible between banks, I can just transfer value to you by scanning your QR code. As such there is value in this method. Moreover I can not only transfer value to you but also to shop holders and taxi drivers around Groningen, this is due to human labor by the company behind Gulden. Gulden was trending in the iOS store a couple of days ago by the way, so many people have heard of it, even internationally.
The name YouTube also refers to old CRTs, perhaps indeed to evoke a certain feeling. Who cares.
> Gulden is used for actual value transfer […]
I can see some of the benefits touted, but for most of those situations cash or our excellent system of debit cards and POS-terminals already do this, and transferring money via IBAN is peanuts (and free within most EU countries). But convenience aside, cash works without a smartphone and middlemen. It's mostly anonymous too.
Besides, I get that companies are vying for the position of the one digital money transfer 'app' here in the Netherlands, because whoever manages to do that is in for a very profitable ride (like that one similar app popular in Sweden), but linking it to their own altcoin seems like a way to propagate a pyramid scheme by means of an app some will find useful.
The way the "10%" is done is that it's really 20% for the first 4 years then 0%. Given the past history of premined altcoins I wouldn't weigh the odds that this specific system really lasting more than 4 years out especially high.
Zcash 10% vig is an improvement over instamine or premine. I agree this structure is still not ideal for maximizing zcash value, as it creates an incentive to clone zcash (without the vig). Zcash looks like it will be rather more difficult to clone than, say, Ethereum. But it will certainly be done. I also expect that some of zcash features will be added to other protocols, thus diluting its tech advantage.
No one has figured out how to force everyone to invest in the same version of bitcoin, and perhaps that is as it should be. I still expect the Zcash devs to make out OK.
To my knowledge, ETHC maintained chain of title with original ETH up to the fork. However, the DAO exploits may have transferred some of the premine to the team that worked the exploit, to the extent any of the devs invested in the ill-fated DAO.
It's two year in the making and we're hoping to launch in March. Governance is necessary for the maintenance of the commons, but we don't think it should be in the hand of a foundation or a core development team.
For those reading this who don't know him, Doug has an impressive pedigree both as a lawyer and as a technologist / cypherpunk. He was, for instance, to president of "Evil geniuses for a better tomorrow"
https://en.m.wikipedia.org/wiki/Mnet_(peer-to-peer_network)
He now specializes in advising startups and I cannot recommend him enough. http://barneslegal.net/
http://www.telegraph.co.uk/investing/shares/lego-a-better-in...
The vast majority of "altcoins" are minor tweaks on Bitcoin and a couple others, they're not at all technically interesting, and I think it's an open secret they're pump-and-dump schemes.
I don't know much about ZCash, but I know it's pretty unfair to dismiss it as "another altcoin". The people behind it are well respected [1][2] and it makes use of novel technology.
ZCash has this ability to de-anonymize users through targeted blocks, and is a privately-held U.S.-based company that claims no liability for it's user's actions, meaning if subpoenaed they will [probably] turn over information.
They're also privately cashing in on 20% of all transaction fees.
Just because someone behind a project has credentials you respect doesn't mean we should ignore aspects of the project.
From the ZCash Whitepaper:
>A powerful attacker could potentially fabricate an additional block solely for a targeted user. Spending any coins with respect to the updated Merkle tree in this “poison-pill” block will uniquely identify the targeted user.
I agree. Good thing that's not what I did.
Regardless of any flaws, there has clearly been a lot of effort put into it by multiple smart people with good intentions (from what I can tell), therefore it is unfair to characterize it as just "another altcoin".
That's the only assertion I made.
Tromer's paper [2] may be helpful. At least there, the references are cited and findable. Tromer's first result deals with collision-resistant hash functions. That's been a big headache in practice. It's really hard to develop a cryptographic hash function for which someone can't create two strings that result in the same hash.[3] MD4 and MD5 have been broken, SHA-1 has been partially broken, and SHA-256 hasn't been (publicly) broken yet. Tromer seems to claiming that he has a solution to weak hash functions. But it's really hard to tell from his writing.
Anybody really understand this?
[1] http://web.stanford.edu/class/ee380/ [2] http://www.cs.tau.ac.il/~tromer/papers/huntingsnark-20140724... [3] https://www.cs.cornell.edu/courses/cs6830/2009fa/scribes/lec...
"Another altcoin."
"I wouldn't weigh the odds that this specific system really lasting
more than 4 years out especially high."
ZCash isn't just another fly-by-night cryptocurrency scam. It's a serious engineering effort that was carefully undertaken by some very well-known cryptography and security experts. Matthew Green
Daira Hopwood
Taylor Hornby
Ian Meiers
Zooko Wilcox-O'hearn
Every one of the names in the preceding list is or was involved in the ZCash project to some capacity. Every one of those names stands alone on their own merits.Ask your cryptography expert friends what they think about ZCash. Yes, the one who are always yakking about side-channel cryptanalysis and which character device to use for generating random numbers. If you don't have any such friends, go to ##crypto on Freenode and say "Hi". It's all uphill form there.
Saying the equivalent of "Monero is better" is little better than trolling. Let Monero stand on its own merits; being negative and hostile accomplishes nothing.
Saying the equivalent of "Sigh! Another doomed altcoin" is needlessly pessimistic. ZCash represents what every other altcoin should have been doing all along:
- It uses a real proof-of-work function.
- It offers actual anonymity (an improvement over BitCoin).
- It uses an entropy source that won't fail open (like so many BitCoin apps did).
- It was designed and implemented by a team of academic cryptographers
and industry experts on secure cryptography implementations.
- The team took their time bringing a solid implementation to market.
- Every design decision was documented and discussed openly.
If you have technical concerns about the protocol design or implementation, please don't feel discouraged in sharing them. It's the dismissive attitude that's bothering me.It's Ian Miers, not Meiers.
The Equihash proof of work, its name notwithstanding, is a real puzzle, not a Hashcash hash function. Each instance can yield 0, 1, 2 or more solutions (though rarely more than 7).
The implication that most of the alt coins are like this is unfortunate. Sure, a very many of the alt coins are just bitcoin clones with a different genesis block trying to get rich but many of the alt coins have had great minds behind them, that's not novel in and of itself.
Same reason Gary Johnson didn't answer the "Name a foreign leader you respect"... once you name someone you open up to answering for all their mistakes.
I was one of the first and most dismissive when bitcoin was released. I'm on record saying "yet another p2p currency piece of crap" one ~day after its January 2009 announcement and release. There are so many endless p2p currencies out there-- this was even the case when bitcoin was first launched-- so many that, frankly, any dismissive attitude is completely justified. You can't go around saying "you're too dismissive" because by doing so you commit the same crime you're accusing others of committing. Keep in mind that for some of us there's a lot of background in reviewing cryptocurrency proposals; it came as surprise to me to later learn that there was actual working source code associated with bitcoin rather than merely manifesto emails.
Also, "I wouldn't weigh the odds that this specific system really lasting more than 4 years out especially high" is clearly a reference to the author's experience analyzing (or reviewing) zk-SNARKs and related cryptocurrency proposals. I suspect even Zooko would readily admit that there are alternative SNARKs constructions that they might move towards over time. Heck, it was nullc who pointed out to me that Bryan Parno had published on a libsnark security hole: https://eprint.iacr.org/2015/437 -- and besides, it's not yet time to say that the trusted setup and the host of new cryptographic assumptions are rock solid... otherwise let's merge this into bitcoin. "Attitude", ha.
Also... it's not clear whether a high-privacy cryptocurrency, built by a specific nameable centralized company, is able to both operate as a legal business entity while still ensuring they are not operating under secret court orders from secret courts or other adversarial government interests, such as to inject silent inflation or otherwise compromise your integrity. It's too early to dismiss the concerns (of adversarial intervention) regarding the financial link between the Zcash developers and the Zcash cryptocurrency. (It may not be clear to casual readers that, unlike in Zcash, in bitcoinland there's no protocol rules about paying developers from the mining subsidy reward amounts. There are very strong reasons for why this is still the case.)
(If you are going to have adversarial intervention like that, then you might as well use a much more directly centralized currency. It's not enough to handwave about the wonders of crypto and theoretical computer science while subjecting your work to extreme adversarial intervention. High-privacy designs in a centralized system can somewhat work, even if you were to want to explicitly make a backdoor for whatever law enforcement interests you pledge loyalty to.)
Precisely.
kanzure: An informed criticism is valuable. Thank you for sharing yours.
Maybe. You might have to admit that it's pretty funny that out of all the "overly dismissive comments" from which OP could have selected, one of the two quotes picked happens to be from someone I have pointed out as having done far more diligence than myself :).
My understanding of the execution of Zcash is pretty clear, and it seems like a worse execution that existing technologies, especially cryptonote of which Monero is one. Am I trolling, or looking for a counterpoint? Do you understand how cryptonote technology works? The criticisms have been the exact same since 2014
Blockchain technologies are intended to be able to stand on their own without high profile names attached to them. ZCash is doing the opposite of that, and not even offering anything to make up for it. This invites criticism, let alone the product itself.
-ZCash is a US-based LLC, and given what is publicly known about the capabilities and past behavior of its intelligence apparatus I don't see how anyone can claim that such an organization can shepherd a 'truly anonymous blockchain', particularly one that is essentially a black box
-ZCash's blockchain is a black box and requires you to not only trust them with your anonymity, but also to trust them not to create coins arbitrarily - a successful attacker could also mint coins at will - as there is no way to verify circulation
-Anonymous transactions are optional and require tremendous resources to generate
-It is an innovative take on a pre-mine where insiders were given opportunity to pre-purchase coins at the expense of future miners
I suggest that anyone looking for a truly anonymous blockchain experience take a look at Monero.
And I suggest that anyone looking for strong provable anonymity guarantees not look at Monero. The security guarantees of ZCash are stronger than those of Monero, and the trusted setup issue can be mitigated via the MPC protocol detailed in a recent paper.
EDIT: compromising the trusted setup does not compromise anonymity; the zero knowledge proofs used enjoy a property known as "perfect zero knowledge".
You do not trust anyone with your privacy in our system. Assuming you're talking about our zk-SNARK parameters, if they were not securely generated you still could not violate anyone's privacy.
why does it matter where zcash is incorporated when the apparatus you're describing operates without regard for borders?
zcash is the first effort at a cryptocurrency where I have immense respect and trust for its team right out of the gate. not sure where the FUD is coming from (although I'd hypothesize that you are long monero?).
>Anonymous transactions are optional and require tremendous resources to generate
this is indeed a problem. hopefully temporary.
Yes, they can do intelligence ops and attacks in others countries, but can't issue a subpoena along with gag order. Attacks can be defended against, secret court orders - not. A decision to make this currency US based killed it before it was even born. That's sad, because technically ZCash looks quite interesting.
I really don't understand the risk of US incorporation that you're talking about, or why it is better or worse than any other country without introducing other potentially even less desirable risks. Can you explain further?
More recently the US is known for failing to force companies to add back doors (see Apple/FBI). It's probablg worth noting Jospeh Bonneau (EFF) is on the board of Zcash. I just don't see the risk that you're seeing, sorry.
No other western country (to my knowledge) has secret courts, that were also proven to target tech companies. If such reason is not enough for you, I don't know what else could it be then.
That's it, I'm not going to argue in circles anymore, I don't trust and will not trust any US based, privacy related tech company unless something fundamentally changes in its legal and power structures -- there are more than enough reasons and examples for me. If you do -- that's fine by me.
1. https://en.wikipedia.org/wiki/RSA_BSAFE#Dual_EC_DRBG_backdoo...
If you could name a single country that would offer better protections, we might have something to talk about. Western Europe, seriously? [1]
The reason we are going in circles is because you're unwilling to trust ZCash, not because of where it's incorporated. If, like me, you trusted ZCash, it wouldn't matter to you where their articles of incorporation were filed, because you would trust that the zero-knowledge implementation would prevent law enforcement from mattering at all. If open source, audited code by some of the brightest minds in the space doesn't earn your trust, nothing will. IcelandBux won't save you.
1. https://www.theguardian.com/world/2015/may/05/france-passes-...
* The founder is Zooko Wilcox-O'Hearn, creator of Zooko's triangle, the BLAKE2 hash function, Tahoe-LAFS, and former employee at MojoNation (an early attempt at cryptocurrency/P2P filesharing where another employee, Beam Cohen, went on to create Bittorrent). He knows a thing or two about decentralization/P2P.
* This project is NOT a trivial Bitcoin clone with only a new proof-of-work swapped in. The Zero Knowledge Proofs they use to keep transactions private is state of the art crypto. Also their PoW is actually memory-hard (many currencies have used PoW functions which they thought would be memory-hard and ASIC-proof, such as Litecoin with Scrypt, but it turned out not to be the case).
* Their "Founders Reward" is less like a premine and more like startup vested equity (it pays out to them gradually over 4 years to incentive themselves not to pump and dump).
* The team is extremely helpful in the Zcash Slack and are a relief after dealing with the pedantic, difficult Bitcoin developers.
Some advantages Cryptonote has that come to mind:
- They are private by default. Zcash requires two states, a state analogous to bitcoin, and the anonymous zcash state which has to be explicitely opted into. Shadowcash also has this, but opted for ring signatures for the anonymous state (like cryptonote coins use by default) instead of the zkSNARKs. The market hasn't focused much attention on Shadowcash.
- Cryptonote projects have proof of work algorithms that are durable and so far ASIC-proof. Cryptonite, Wild Keccak still are CPU and GPU friendly. But I'd have to read their respective papers before I say "ASIC Proof because memory hard"
- Cryptonote are also auditable if a user wants to reveal information about a transaction. But even then the information is limited, it will show that payments came in and out of specific amounts, but it won't show the sending/receiving address along with those transaction IDs.
- Cryptonote projects have nonthreatening names. Many privacy centric projects have names like Dark- Shadow- Anon- whereas noteworthy cryptonote projects have names that at worst simply wouldn't be taken seriously by a "powerful establishment" until so much capital and infrastructure is already built. I think ZCash or "Zerocash" isn't going to get smiles and congratulations from FinCEN. Hyperbole, but I don't think it is an advantage for the project.
Its one thing to be optimistic about the founders and their company, but for you to say "long" something that doesn't seem like a better investment, makes me wonder what you see in comparison to some other existing technologies.
Looking forward to your thoughts
It does not require two states, this is a misconception that originates from the paper which refers to "basecoins" and other obsolete terminology. The protocol was anticipated to be a sidechain of some kind, but due to technical limitations that never panned out. Our system does use two states, but I personally advocate for removing the "transparent" system in the future when we have things like private multi-sig.
> Cryptonote are also auditable if a user wants to reveal information about a transaction. But even then the information is limited, it will show that payments came in and out of specific amounts, but it won't show the sending/receiving address along with those transaction IDs.
You can do all of this with our system as well, it was one of our design goals!
As regard to your second point, I know, thats why I said "also".
Aside from the marketing budget and evangelists, Zcash isn't really standing out to me. What do you see? Your idea and possibility of removing the transparent system? From my understanding this means every transaction will have the high system requirements, it still seems like a worse execution of this technology than other existing cryptocurrencies who will be even further ahead by the time these growing pains are even considered on the Zcash network.
Have you talked with the monero team on how they plan to address it?
They might not have a good answer (cheaper storage, computers faster in the future), maybe they do have some solutions in mind
This seems to be an issue with zcash too? Can you explain why it isn't?
Given current information if seems like these problems won't become apparent till the year 2021
Let me know when there's a cryptocurrency based on proof-of-carbon-sequestration or something.
A couple weeks ago I presented the idea at MIT's Solve conference, and I've got a writeup at MIT's ClimateColab that made finalist this year.
http://climatecolab.org/contests/2016/shifting-behavior-for-...
http://solvecolab.mit.edu/challenges/2016/fuel-carbon-price
(The Solve writeup is pretty old, the Colab is recent but I've done more thinking about the minting schedule since then and made some changes.)
Aside from the fact that it's built on a bug-prone foundation (Ethereum), the idea at least gives me some hope that cryptocurrencies don't have to have a negative impact.
As for Ethereum, so far the bugs in the underlying platform have been minor; right now they're dealing with DoS attacks resulting from mispriced opcodes but that's getting fixed. Most issues have been due to poorly-written smart contracts rather than the platform. That's not entirely the fault of the contract authors; it's taking some time to figure out the attacks and best practices.
I'm not planning to launch in the near future anyway, because Ethereum is going through some major changes next year for scalability, and contracts will need to be coded differently to take advantage of that. In the meantime I've gotten a job doing Ethereum app work, so I should be reasonably well-prepared to get the technical side of things right.
I think the bigger challenge is making sure the climate action is actually effective. Something I learned from people at the MIT conference is that while carbon offsets are readily available in the voluntary market, even the certified offsets are often very poor quality, or even outright scams.
Also I'd like to figure out a governance system that doesn't rely on central administration, but that may not be workable; a more democratic system could end up funding charismatic projects that don't actually do much good. I've got some ideas though.
Do you actually understand the utility of proof-of-work? Whenever someone proposes something silly like "proof of recycling" or "proof of solar power" I can't imagine they do.
I didn't claim it would be straightforward to make a cryptosystem whose mining process causes a benefit instead of a harm. I didn't claim I had such an idea. But let's rank some options in order of goodness:
1. Figure out a cryptocurrency with a real-world benefit
2. Don't use cryptocurrencies
3. Use cryptocurrencies
You may have chosen the worst option. I'm content with option #2.
Hint: it's impossible.
But regardless, I seriously doubt that Bitcoin mining actually has negative utility even after taking into account any negative externalities introduced by the relatively small electricity use from mining. My suspicion is it's more or less negligible compared to manufacturing or transportation.
Not a fare comparison; all of visa/mc's servers have externalities, all of the money trucks driving around physically collecting cash have carbon externalities, building ATMs and printing plastic credit cards have carbon externalities, building banks and running them have carbon externalities.
You have to compare the relative carbon impact. Cryptocurrency miners obviate all of those things.
Visa et al. are incredibly efficient compared to Bitcoin. I heard a Bitcoin advocate point out that all it would take to make Bitcoin have enough throughput that everyone could use it is 1% of the power in the entire world.
The tradeoff is that the 'peer' need to be relatively high performance servers (just normal commodity servers, nothing special).
Its impossible to achieve with the concept of everybody running their own nodes on a laptop.
In BitShares the Shareholders (people who own BitShares) can vote on either improving the performance and decreasing the distribution or the other way around.
So you are still gone be somewhat less efficient compared to Mastercard but you can achieve the same the scalability with a reasonable amount of extra power usage.
Could someone enlighten me as to why that's the case? I know of ZCash via the academic papers on it, and because the people involved – Zooko Wilcox, Matthew Green, etc. – are extremely well known and trusted in the security community. I've heard basically nothing about Monero.
Monero uses ringCT algorithm on transfer to mix the payments and obfuscate the sender
Monero has a private view key and separate spend key. View key can decrypt transactions made by you to confirm your total balance (Monero balance is unknown to daemon, is calculated as (xmrRecieved - xmrSpent)
ZCash has 'zero-knowledge' proofs and while the whitepaper[1] is a bit intense it uses a novel Proof-of-Work explained within. Called zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARKS).
ZCash coins origins obfuscated before recieved by user, reducing need to mix payments together
Personally, I think they're both great and it's a healthy time for a privacy-based cryptocurrency face off. Having said that, ZCash theoretically sounds better (to me) yet Monero is proven in the wild - and both have people with money already sunken in.
IMO the cryptocurrency world will be much better off when it's userbase is looking for a CURRENCY and not a COMMODITY.
[1]: http://zerocash-project.org/paper
[2]: https://github.com/zcash/zips/blob/master/protocol/protocol....
[3]: https://www.reddit.com/r/Monero/comments/41vg68/monero_vs_zc... - decent ZEC vs XMR ELI5 thread
edit: formatting
It would be simple to create an alt-coin that degrades in value over time, thus encouraging circulation and not hoarding (though how you would battle fake-circulation through shill transactions is up for debate), but no one wants to buy into such a thing.
I happen to think the conflation of money/debt/interest with the corresponding need for continual economic growth is one of the great tragedies of our age, but I'm not entirely sure how to get out of it.
Whether you want to spend it.
> If the rate of appreciation is perceived as high enough, and the exchange rate into goods and services is high enough, anyone will have a tendency to hoard a currency - why wouldn't you?
Of course it's reasonable to do in such a situation, but that doesn't make it good for the thing being hoarded. Ideally a currency would have minimal appreciation.
https://blog.okturtles.com/2016/03/the-zcash-catch/
http://weuse.cash/2016/06/09/btc-xmr-zcash/
If you are interested in anonymous blockchains, I highly encourage you to look into Monero. It meets or exceeds that of ZCash. And Monero's RingCT is currently implemented and in use on TestNet with a target "go-live" this January.
_"And Monero's RingCT is currently implemented and in use on TestNet with a target "go-live" this January."_
I couldnt find any relevant infromation on this. Does it mean that from January 2017 bitcoin will have anonymity properties of Monero?
I agree that it is very important for people to be able to conduct financial transactions without having to disclose them to third parties. It's also important for people to be able to use a mutually-agreed-upon trusted third party to mediate transactions where neither party knows the other's identity. But I'm much less convinced of the wisdom of enabling people to conduct financial transactions with no possibility of knowing who they are doing business with. That seems to me to be fraught with all manner of moral hazard.
we have anonymous darknet markets, where you can buy many controlled substances, in visibility of law enforcement.
My point is that you can't uninvent these things. They have already changed society, and moralizing on how we shouldn't invent these things has gone way past into heavy production.
Use the technology, dont use it; this is really the only choice you can make. Their existence wont go away.
BTW, I didn't know about Monero. Is there any substantive difference between it and ZCash?
Anonymity facilitates the exposing of bad actors and systemic failures in the bureaucracies we've created to help and protect each other, i.e., whistle blowers.
I would also argue think ransomware is a good thing. Although it's annoying, it's providing just enough of a shift in incentives for people to start taking data security seriously. Ransomware makes everyones data more secure in the long run.
No, it doesn't actually. What are called "anonymous sources" in the press are actually not anonymous in the sense that ZCash makes them anonymous: their identity is known to the journalist who publishes the story. The identity of the source is kept confidential by the journalist. This mechanism is an important check on the credibility of the source. True anonymity leads as much to vendetta-driven libel as it does to legitimate whistle-blowing. There's a reason that serious people get their information from the Register and the Washington Post instead of 4chan.
Also, anonymity in general and an anonymous currency are not the same thing.
This alone makes me extremely sceptical.
(See: Tulip Trust)
The other option might be a blockchain that doesn't do time based payouts but does volume based payouts. Rather than having blocks issued on fixed intervals you could have them dynamically issued and computed based on the previous blocks time to reach a calculated size threshold to hash. Unless you were psychic and could guarantee your coin would take off, investing the electricity to generate bogus volume would be a tremendous gamble in resources to try to beat the market.
> At first, 50 ZEC will be created every ten minutes. 80% of the newly created ZEC will go to the miners, and 20% ZEC to the founders.
> Every four years, the rate of ZEC being created will halve (again, just like in Bitcoin). After the first four years the ZEC created per ten minutes will drop to 25ⓩ, but after the first four years, 100% of it goes to the miners.
> The end result (as shown in the diagram) is that there will ultimately be 21 million ⓩ, and 10% of it, or 2.1 million ⓩ, will have been initially distributed to the founders.
> With this approach, the founders are incentivized to support Zcash for the long haul (at least for four years), and they have limited ability to pump-and-dump.
From https://z.cash/blog/funding.html.
I don't know if this makes things better or not, but it sounds reasonable to me. From what I understand, "pump-and-dump" has been a concern in cryptocurrencies.
Four years is not the long haul when talking about a new currency.
Currencies take time for sure.
[1] https://en.wikipedia.org/wiki/United_States_dollar?wprov=sfl...
It's 80% for the first four years then all after.
The fact that this isn't completely clear to people is another reason to be skeptical.
See also https://news.bitcoin.com/meet-top-3-coins-cryptocurrency-ano...
It is interesting how the same (or similar) technologies that have made cash rare, and allowed tracking of transactions and spending, may subsequently enable radical anonymity.
P.S. I hope to see an investment market based on anonymous cryptocurrency one day; it would allow many people who currently lack access to investment markets or funding to prosper.
How does it prevent civil forfeiture specifically? Can you elaborate?
More significantly, if you have an anonymous ZCash account, the state has very little idea of how much money you have, where it is, or how you've used it; this means they don't know whether you have anything they want, or how to get it.
For more direct criminal elements, you can make it difficult enough that its not worth them going through the effort to use the 5$ wrench and wait while you have to fetch the key. Beyond that, you're no worse off than you were versus carrying cash. The only thing electronic cards might have advantage over this is many provide fraud protection which will refund/void fraudulent charges.
I don't think you understand what happens when you defy court orders...
Also, mostly this will be used for tax issues, where guess what, the burden is on you to prove that your income was only X, so the more crypto shit you have the easier it is for the prosecution to say you have millions in crypto currency.
You really think ZCash is the first company to think of hiding assets from the gov't?
The court reference you replied to is saying that the court system protects you from having a state actor use force to take your property before you've had your day in court.
ETA: That said, I don't think you need anonymity for this, so it would apply to any currency you can use as cash and secure with a password. I guess the anonymity just makes it more like physical cash in that nobody can track how much or where you spend/receive it. For tax purposes, it would be no different from cash in terms of ability to work under the table and be called on it or accused of it by the IRS.
If state actors use the 5$ wrench, that's illegal and consequently you have the defense of the courts to counter that behavior. Civil forfeiture is dependent on being able to "prosecute" your stuff, rather than you. So if they can't seize it, they have to go after you directly, which puts the burden of proof on the prosecution to demonstrate that the money is unlawfully possessed. The fundamental principle of the US court system is "innocent until proven guilty", so you don't have to prove what your income is, they have to prove it. You only need to counter their claims.
The US certainly has had cases prosecuting "stuff" where said stuff is cryptocurrency. See "United States v. 178.95842915 Bitcoins" [0], which appears to be a civil forfeiture case [1][2].
[0] https://www.usmarshals.gov/assets/2016/bitcoinauction/index....
[1] https://www.pacermonitor.com/public/case/10752506/United_Sta...
[2] https://docs.justia.com/cases/federal/district-courts/washin...
Imagine the opposite scenario. The government thinks you have millions, but you genuinely do NOT have that money. How do you prove to the government that you are innocent and don't actually have the money.
You can't. You, an innocent person, are indistinguishable from a person who actually DOES have millions hidden away in crytocurrency.
If none of those means of getting you to pay work out, they can always leave you to enjoy your internet money in jail.
If someone threatens you with a wrench, you simply do what they ask you to do and provide a password to your "account" that conveniently doesnt have much money in it.
"yes officer! I have done exactly what you asked me to do. Here is all the electronic money that I own. "
[1] https://www.reddit.com/r/TREZOR/comments/2e8a9i/can_someone_...
This type of attack probably won't work on Zcash, but that statement seems to be wrong these days:
http://www.npr.org/sections/alltechconsidered/2016/07/02/483...
Furthermore with the push for "Online identity" they could just seize all your data storage and your various account information sets. Maybe your Ident never touched any of your personal hardware, or maybe you opened access to your hardware and pumped so many Idents through your confident they wont be able to figure out which is yours. But they can still out wait you.
I mean MAYBE with smart contracts will get us out of that.
It doesn't prevent some vague yet menacing government agent from breaking your kneecaps in order to get the password, but no security system has been able to plug that hole yet.
For anyone who's interested about the practice of "civil forfeiture" in the U.S. and why its so concerning. This is decent introductory read:
https://priceonomics.com/how-police-officers-seize-cash-from...
HYIPs were plain ponzi schemes, given the fancy name of 'high yield investment portfolio'; they promised things like "1.5% yield/day on investments of egold" but all of them would fold.
* https://getmonero.org/knowledge-base/about * https://github.com/monero-project/monero
So if Zooko Wilcox et al are indeed respected in the P2P and security community, then I am interested in this.
I do not trust Israeli SIGINT people with my secrets.
There's skepticism, and then there's this stupid crap like your post. No technical foundation, no evidence, nothing, just FUD.
The central conflict is over authority: should the system be in the hands of miners or in a central power? Both of these have pros and cons.
Miners have an economic incentive to ensure changes to the system are in favor of users. And in theory, these changes are democratic: representing the opinions of the majority of miners. However, in practice, this is rarely the case; as voting power is allocated based on computing power, the result is a system governed by a few individuals with the economic resources and advantages to cheaply 'outrepresent' others. In effect, they do not represent the majority of miners and users. Look at Bitcoin, where a handful of Chinese companies control the network (http://www.nytimes.com/2016/07/03/business/dealbook/bitcoin-...)
A central power has the ability to enact large scale change affecting the whole system, but is inherently undemocratic. Ethereum, in response to a capital fund being hacked, performed a hard fork earlier this year, mitigating the adverse effects. This rapid collective action would be hard to do in Bitcoin.
The benefits of blockchain are anonymity, security, and low costs of transactions. Both of these features need to be upheld if blockchain-based currencies are to be competitive with current credit systems, regardless of which form of authority is adopted.
In my opinion, a central power blockchain-based currency would be preferable. Why? Current credit systems charge high fees for transactions to offload the cost of fraud and corresponding insurance. Blockchains don't, but there is no guarantee of security against hackers in a system not run by a central power. Low cost and security of transactions must be maintained. In addition, in a miner-based blockchain, all transactions are not treated equally. For Bitcoin, transactions which give a fee to miners are processed faster (https://docs.google.com/spreadsheets/d/1aYfkjiN534p4zyE5WJNm...).
Any response?
ZeroCoin was an entirely different approach based on different cryptography with radically different properties.
ZCash seems relatively neutral to me, not evoking positive or negative feelings.
ZeroCash (from which it comes) is somehwat negative, since it evokes "no more money".
I was thinking of some old Bond villain.
Not quite. I mean surely there were people interested in that, but frankly this is exaggerated. We knew very early that anonymity was far from obvious, even on a purely theoretical point (that is, even if you could anonymise your IP for instance).
Bitcoin was approximately anonymous not by design, but by convenience. Who wants to have to bother checking the identity of users? In fact, I'd argue that bitcoin was no more anonymous than any other FOSS project. You usually don't ask for an ID before allowing someone to download your software.
There's also the interesting psychological side to it: while a blockchain system is in a theoretical sense more transparent than anything else, from a popular standpoint it's incredibly opaque compared to a county registrar counting two different stacks of paper ballots.
https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
If we want it to be secure anyway...
Oh God, I'm _really_ hoping you're being sarcastic.You've read about the dozens on dozens of compromised exchanges?
You heard about the DAO hack?
You realize that the majority of bitcoin is mined by like a dozen people in China?
Maybe someday we'll get our act together, but right now blockchains are a recipe for FUD and centralization.
(I say this as someone who thinks bitcoin is cool. For instance, the traditional financial system makes it unnecessarily hard to send money overseas, a need bitcoin can fill well. But secure? No.)
all of those things improve the resilience of the implementations
exactly as the original white paper suggested
mining pool centralization has ebbs and flows. I'm not concerned about bitcoin's TODAY for example, but maybe tomorrow and at times in the past. There are a lot of blockchains people don't put under much scrutiny, where it turns out there is massive centralization. But this isn't an inherent problem, Satoshi was 100% of Bitcoin's network for a long time.
[1] https://en.wikipedia.org/wiki/Economic_calculation_problem
Disclaimer: I may be extremely biased from spending the majority of my time trying to figure out how to put that into practice.
It seems bitcoin just doesn't scale very well.
So my question is does ZCash? How will it cope with current bitcoin volumes? Or 10 times? Or 1000?
...but, is there a reason that anonymity would be good for use in a blockchain for use by businesses? Or, is it categorically better for a business-centric blockchain to have the most identity possible?
I agree with this sentiment.
"Apple wouldn’t want the government to be able to track its transactions and gain valuable tax revenue."
good luck.
the sender and the receiver can always verify that the transaction has occurred. it wouldn't be much of a currency if it relied on anonymous rumours of payment!
Now imagine that the restaurant didn't possess any information that it could use to identify you as a result of the payment, and that no payment intermediary possessed information that could be used to identify the parties to the transaction, and that when the restaurant later spent the money, the source of the funds couldn't be associated with your payment transaction (perhaps even by you as the customer).
Those are some properties that we could wish for in an anonymous payment system. It doesn't mean that the payee can't tell that a payment was made in response to a particular request, though it might not know "by whom" in any other sense.
There's a whole lot of fud and hype and just plain misinformation in the cryptocurrency space because a lot of people treat them like penny stocks to run pump and dump scams on, but that doesn't mean they're all just that.