Zcash begins
z.cash
z.cash
Huh? Why? How? It's an altcoin with more anonymity than Bitcoin. That's nice, but no big deal.
I went to hear Tromer's talk on the theory behind Zcash at Stanford last Wednesday.[1] There were a lot of very strong claims and a lot of hand-waving. I'm not an expert in that area, but the claims were awfully strong and the presentation didn't back them up sufficiently. Here's his key paper.[2] He claims, at least, to have developed a new way to generate cryptographically strong hash functions. See section 1.1 of that paper. That's a hard problem. Of the existing crypto-grade hash functions, Snefru, MD2 (128-bit), MD4, MD5, RIPEMD, HAVAL-128, and SHA-0 have all been broken, and SHA-1 is looking weak. Solving that problem alone would be a noteworthy achievement. So where's Tromer's proposed hash function, evaluated by the crypto community?
On the financial front, the insiders take a 20% rakeoff of new Zcash coins for the first four years. That's a huge cut for a financial product. The investors include Roger Ver, the convicted felon who publicly said Mt. Gox was sound. What could possibly go wrong?
[1] http://web.stanford.edu/class/ee380/ [2] https://eprint.iacr.org/2014/580.pdf
The internet used to provide low-barrier super-human communication abilities, but only in very limited contexts -- possibly beside a giant mainframe, and only able to talk with other giant mainframes. Now that we have instant comms in our pockets and on our wrists all the time, the effects are pretty expansive. Blockchains are not yet ubiquitous, but when they are (in every device and underlying many services we use), every person will have the infrastructure to create and maintain complex agreements for near-zero costs. (Financial agreements and otherwise.) This will be pretty transformative.
I assume ZCash is acknowledging that privacy is a critical piece of that transformation in organizational structure for society. Kinda like how ubiquitous communications are almost pointless without the possibility of E2E encryption.
But this is a lot of speculation given that I haven't read the linked article ;)
Sorry, but this is wishful thinking. The simple question about how you can enforce agreements running in blockchains can't be answered. In the real world you have the military or police force while in the blockchain itself you are pretty limited. On the other hand external oracles are the weakest part of the blockchain system. If they are hacked you hacked the agreements.
I think the blockchain/cryptocurrency/smart-contracts/app-coin scene is really exciting but the connection with the real world is problematic, more when the financial institutions are enforcing AML/KYC/etc
Check out https://www.augur.net/ for an attempt at answering that question. They crowdsource the outcomes of the various bets from people holding REP tokens. REP holders have a financial incentive to act honestly to increase or maintain the value of their REP.
Also, we don't know yet how public blockchains (where Augur runs) work with State or powerful actor attacks, when the incentives are not purely financial.
Sure, that's the traditionally accepted way to go about solving the problem in the real world. But there are many other ways to solve the same problems that we're all intimately familiar with by now based around reputation systems. When it becomes public that a counterparty to a contract has engaged in delinquency, they suffer a reputational hit. If their reputation has value (and there is nothing about pseudonymous entities that mean that they cannot accrue reputational value, rating systems work on darknet markets quite well and have since their inception), and the amount of damage to their reputation is higher cost than making good on the contract, then they will make good on the contract (and even if they can't, you've punished their delinquency by damaging their reputation, instead of dragging them through an expensive inefficient corrupt legal system involving violence as the final sanction).
All sharing economy and peer to peer systems that currently exist work on systems of this kind, and cryptocurrencies to the extent that reputations are valued and contracts made similarly so, and this will only become more prevalent as time goes by.
Not everything requires recourse to violence.
You could use transparency to tell how much a given escrow agent is holding and don't use them if it approaches the value of their reputation. And/or use a system where they don't hold the funds, they merely choose to unlock a transaction to pay to A or B.
That should be embraced and noted, and where appropriate migrated to, not pushed aside because there is a rapidly decreasing class of problems not suited to resolution with this model.
The default rate on BTCJam, which was one of the first loan services is 10%, this doesn't compare well with mainstream rates however, Bitlendingclub is supposedly one third of that, which compares favourably to mainstream rates https://fred.stlouisfed.org/series/DRCLACBS
From a product value perspective, that's a pretty big deal for the illegal commerce side of the Bitcoin market. Which I would guess is some double-digit share of Bitcoin (currently $11B). That use alone could make Z-cash a billion dollar product.
As a side effect, that could increase the proportion of Bitcoin transactions that are legal, which might have some nice legitimizing effects on the brand.
The presentations motivation and conclusions are indeed very high level. The body of the presentation presented several different applications, including Zcash and several applications of Proof-Carrying Data (the extensions of SNARKs), to exemplify this. Unfortunately not could be described in detail, but they all have corresponding technical detailed papers (see http://www.cs.tau.ac.il/~tromer/publications.html).
Regarding the conclusion, patcon's interpretation is accurate, and more generally: There are numerous situation where parties cannot cooperate due to mistrust, and modern cryptography, SNARK included, allows them to use digital cryptographic schemes instread of certifications, accountants etc.
About the hash functions: collision resistance is discussed in the paper, but note that such algebraic/combinatoric/geometric hash functions are a totally different animal from SHA etc. The latter are much more efficient, but completely heuristic, whereas the former often have security proofs that relate them to well-established computational hardness assumptions.
My Equihash PoW solver silentarmy gets 45 Sol/s on an R9 Nano, so there seems to be only about 10 GPUs mining worldwide, 65 minutes after the launch of Zcash :)
Edit: oops scratch everything I said. I forgot difficulty 1 was redefined for the mainnet. In testnet difficulty 1 was defined as:
genesis.nBits = 0x200f0f0f;
So you needed the 32-byte SHA256 hash to be less than 0x0f0f0f00_00000000_00000000_... But with the mainnet it was redefined as: genesis.nBits = 0x1f07ffff;
This value is 0x0007ffff_00000000_00000000_... so only 1 in 8192 random hashes is less than this. So the network's speed seems to be around 130,000 Sol/s. So that's already 3-4k GPUs mining. Ouch.> 10% pre-mine to founders
This smells super fishy. Altogether, I've yet to see anything to do with cryptocurrencies be useful. Nothing but scams, hiding illegal activities, and hopeless optimism so far.
If you see "nothing but scams", it only tells me you live in a strange bubble. There are tons of legitimate businesses that use bitcoin daily. There are some that use litecoin, and even dogecoin.
I don't want "peace of mind". I (a Canadian) want to be able to buy something online from a US supplier and have it shipped to me in Thailand. This is just not possible with any kind of chargeback-enabling payment method.
Just because you haven't been in a situation where the "fraud protection" is impacting your life (or your sales) doesn't mean those situations don't come up for others.
WTF are you saying?
Something more comparable to Bitcoin than regular banking would be Western Union; they make 5 billion dollars a year in revenue transferring money. And they charge vastly higher rates than the Bitcoin network does, charging in the 5-10% range for for transactions, which is a pretty hefty overhead.
So does anyone else with access to your information. How sure are you that your account info is absolutely secure enough to prevent that AND will remain so for the lifetime of your use of a specific cryptocurrency?
I'm not, and it's irrelevant because I only have a tiny fraction of my net worth in easily-accessible Bitcoin at any given time.
I'm not advocating replacing bank accounts with Bitcoin, I'm just showing that Bitcoin does solve real problems that traditional payment processors cannot or will not solve.
I don't know which debit cards you're referring to but I'm almost 100% sure that the cardholders are not liable for fraud. Meaning someone else along the chain is liable and is monitoring/blocking transactions to reduce that liability.
Even if a bank has the right intention, poor implementation can be a huge headache.
When my bank does that, they have a number i can call 24 hours a day. I also believe the last time it happened they called me.
I agree - it should work like that.
>In the first case, it's a service they are providing you
I like knowing that I have some money that I control myself, not through some service I have to worry about locking me out at inopportune times, though I admit it's mostly an ideological position than an economic one.
Note that in cryptocurrency, there is no bank to call when your crypto "coins" are gone. Then it's gone harder than anything else that ever went, ever:
- you can't explain to your family or friends what happened
- law enforcement will hardly consider it a crime and in any case can't do anything about it
- the community will berate you for not watching out better for yourself and somehow call your loss "a good thing"
- if it's anything like Ethereum's DAO hack the fraud will not even be considered any wrongdoing at all
- everyone in the game has already made their money by pre-mining or getting in early and nobody has your interest in mind
I would not use the word "fraud" here, regardless of which side of the Eth fork you sit on.
Either way, this confirms my point - Your cryptomoney is GONE and no one would even acknowledge ANY wrongdoing whatsoever. Hilariously you losing money is absolutely part of the pseudo-libertarian crypto worldview and not worrying anybody. But at the same time crypto currencies should replace real money?
"DAO-Hacker just executed code as intended". "Of course you lose your money if a) your PC is hacked (easy) b) the wallet software is in beta (always is) c) your coins are not in a cold wallet (complicated) d) you are using the 3rd party providers/exchanges (which are hyped by the community) e) your password is weak etc. etc."
I'm having a laugh but then again I haven't lost any money in this.
If you want that service, buy it. Transfer your crypto-backed currency with a "trusted" party who will rollback certain transactions. Do this with a well-capitalized service in a country you can sue them in.
But as we've seen with Paypal (and now Upwork), etc, that can be just as disastrous. They're un-sueable because of their size, and have draconian and arbitrary policies. Many people have had money confiscated or indefinitely frozen because of this misplaced trust.
If you really want to get paranoid, you can buy something like a Trezor[0] or other hardware wallet. I'm pretty sure it would cost more than my net worth for someone to figure out how to compromise it, given the lengths[1] they've gone to to secure it. There's no equivalent option for credit cards.
[0] http://bitcointrezor.com [1] http://doc.satoshilabs.com/trezor-faq/software.html
That's actually a great observation that might fit into security advice on this issue somehow. Keep track of which banks freak out about which things. Get cards from more diverse-thinking ones. Reduce odds of unnecessary freezes or rejections. Now how to do the assessment itself...
Since it's hard to use BTC anonymously, Z Cash allows nice insertions of hard privacy points.
Fraud systems are there for the bank, not for you. Don't ever think otherwise.
10% is hilariously greed and maybe fit "nothing but scams"
The 'random' early adopters of bitcoin were experienced cryptographers whos investment in bitcoin helped it grow.
[1] http://gizmodo.com/5995301/how-much-money-is-there-on-earth
Heh, you may be right.
The only issue I really sometimes have is that my bank will sometimes block transactions which they find suspicious and call me to confirm that it was me who did the transaction. That card does support 3d secure though so usually if the merchant supports 3d secure then the card works perfectly and has no issues.
Unless something changed.
It'll never be economical to mine cryptos with fossil fuels in the long term. Commercial mining will end up concentrated in Iceland etc. where the electricity is both cheap and difficult to export.
Short term, yes, unfortunately they're using fossil fuels but only because of Chinese capital controls that effectively subsidize Chinese miners.
Not sure what you mean by the "etc." in "Iceland etc." -- I don't know of a country besides Iceland that has more power than they can use.
I ask this as someone who is intrigued by cryptocurrency, but never felt a pressing need to be able to transact 100% anonymously.
This isn't how cash works, which is the real "money" in our system. At some point (even if on credit) cash is transferred for stuff. I don't want people to know which places I have a news subscription for. I don't want them to know who I donate to just from the blockchain. I have a choice to want them to know that. This is a practical problem because that means either I need to use shady services to hide these facts for normal purposes. That, or never use them except in a few cases where I don't care people know (but I also might regret that).
I think from a practical perspective, this makes bitcoin really hard to use. How do you make transactions that aren't easily traced to you by literally anyone? Answer: it's hard and possibly won't work completely.
This part seems to be the major problem zcash solves from what I can tell. Delivering on the promise of true anonymity which Bitcoin currently lacks. I see the appeal to current Bitcoin users, but outside of that group, can't see the appeal in a broad "general consumer" sense.
zcash seems like a company addressing a small problem (true anonymity) in the broader context of issues cryptocurrency faces (ubiquity, liquidity, ease of transacting, fraud prevention). Creating an entirely new currency which has to retread the efforts of building out the ecosystem to support that currency is a huge mountain to climb.
It's also highlights why I feel the concept of a "decentralized" currency is essentially impossible. Someone always controls some facet of it, be it features of the currency, supply, restrictions, or value.
In the case of cryptocurrencies, the authors of the protocol and governance put in place to maintain it are the central authority. For zcash, the central bitcoin authority (whoever you referenced as 'Bitcoin') wouldn't/couldn't integrate features they wanted so they rolled their own currency of which now THEY are the central authority.
It seems you and him disagree, he says ZCash couldn't/wouldn't have happened in Bitcoin and you say it could.
Is your blog post about this still coming?
https://twitter.com/matthew_d_green/status/78153309118155571... https://twitter.com/matthew_d_green/status/78154154453702656... https://twitter.com/matthew_d_green/status/78154374789720064... https://twitter.com/matthew_d_green/status/78153489377171865... https://twitter.com/matthew_d_green/status/78154782708016742...
Ha!
> It seems you and him disagree, he says ZCash couldn't/wouldn't have happened in Bitcoin and you say it could.
Yeah, I'm just surprised he feels so strongly about that, given how little I remember him actually doing along those lines. Like I said, I actually was hired by him on a monthly retainer to do consulting... and he did almost nothing at all with that contract. :(
> Is your blog post about this still coming?
Yes, although holy fuck I have a lot on the todo list. :( I also need to writeup my part of the trusted setup ceremony too.
And a blog post on that isn't paid work, so doesn't get as high priority as paying rent. :)
Can you cite this? If he said said it-- it's an outright lie.
Places with no banking infrastructure.
Places with bad government.
Places with capital controls.
If you're counting "people who hold on to your money and promise to probably give it back", I'm pretty sure you can find some of those in most countries.
http://zerocash-project.org/q_and_a#what-is-bitcoins-privacy...
I could see one problem it could solve: donating to organizations that governments find "undesirable", like say Wikileaks, Manning/Snowden defense fund, or even the EFF, and then would take secret (or even more direct ones) actions against me (IRS audit, no-fly list, etc).
These technologies are about resilience in the face of rare but probable hiccups in social order. It's long-term investment and not about a killer feature that a single individual might crave :)
From the last thread they pointed out: "Zcash's monetary base will be the same as Bitcoin's — 21 million Zcash currency units (ZEC, or ⓩ) will be mined over time. 10% of that reward will be distributed to the stakeholders in the Zcash Company — founders, investors, employees, and advisors. We call this the “Founders Reward”."
It's nice to have a currency with more security and privacy features in mind but I would be extremely wary of compromises like this for that achievement.
Let's get real here. These guys are fucking opportunists at best, ponzi median, outright thieves at worst.
What you're basically doing is analogous to applying planet scales to a galaxy.
Even accounting for miniscule market share, 10% "founders reward" for any venture targeting global money, is a ludicrously large sum and a strong signal of probable charlatanry.
Let's do something more reasonable, which least is approximately in the order of magnitude. The BTC market cap is ~$10bil. 1% of that is 100 million dollars. Which means that if Zcash ever becomes more valuable than the phenomenon that was bitcoin, you have a 100 million dollar stake for the founders. A pretty penny, but still a far cry from your ridiculous half a trillion.
The pitch is that zcash will "uplift millions of people". As per your numbers, you're saying 2e-06 proportion of global money. Can you see the disjoint between the ambition pitched and the (entirely reasonable) numbers that you cite? They're pitching a game change ("zcash begins") and you're saying their target is 2 in every 1 million dollars of global cash?? Come on. If that's true, fine, 10%. But that is not "uplifting millions of people" and this is not "Zcash Begins", biblical style.
What we have here is an unfeasibly large founder's share in the case of success, and this unreasonableness is precisely the signal that indicates that they do not believe in long term success, themselves. Therefore we have a credibility problem.
TL;DR: If they had 1% founders share, they'd have a shot. At 10%, they're doomed to failure. 1% of something or 10% of nothing.
If they can provide 1% of global transaction services for 100 years then sure, $500 billion seems super reasonable.
I mean, that's about 10x of a SnapChat or an Instagram.
You must be thinking of something else. Matthew Green has said he would have much rather got this implemented in BitCoin.
ZCash forked off of BitCoin because BitCoin core wouldn't accept it. The proposed solution was a "side chain" to BitCoin. Side chains have been being talked about since around 2009, and that's all that is happened: talking. There is no code and no agreement on how they should work.
The fork happened when it became apparent that this would never make it into Bitcoin in any form.
Matthew Green was _insistent_ about making an altcoin. I believe can substantiate this with DKIM-signed emails by Google, if it's actually being refuted. He was especially concerned about difficulties monetizing any other path.
In particular, later I begged for access to the efficient SHA256 circuits which had been created and benchmarked as part of their publications, which were held back from publication with libsnark. ... so that I could begin working on applications of them with Bitcoin, only to be blown off.
> and that's all that is happened: talking. There is no code and
https://github.com/ElementsProject/elements sidechain right here.
"Let me reiterate, I would 10,000x rather have put Zerocash in Bitcoin." - https://twitter.com/matthew_d_green/status/78154154453702656...
> He was especially concerned about difficulties monetizing any other path.
"Rewards doesn't even start the discussion. I'd have done it for free just to see it used." - https://twitter.com/matthew_d_green/status/78153489377171865...
admittedly he does bring up monetization: "And even when you got the code, nobody ever answered the problem of how you pay miners and devs." https://twitter.com/matthew_d_green/status/78154634460341043...
>sidechain right here.
"Last I checked - a few months back - it was just a bunch of ideas. No code on main." "And more importantly, no schedule on when it was going to go live. You can't build something that doesn't exist." - https://twitter.com/matthew_d_green/status/78154605479791821...
"A cynical part of me came to think the whole thing was just a put-on designed to squash competing coins." - https://twitter.com/matthew_d_green/status/78154720002742681...
I don't see how it's arguable for a currency to have a 10% cut for the founders. That's too high.
one of the critical aspects of Bitcoin's success is that
there was no premine
Satoshi has about a million bitcoin: https://bitslog.wordpress.com/2013/04/17/the-well-deserved-f...The wealth distribution of the Bitcoin accounts vs the U.S. dollar is interesting. Here's a visual one:
https://www.landmarkcash.com/articles/bitcoin-wealth-distrib...
Note: There's also the other problem of hoarding happening a lot since it's a commodity rather than a currency. I'm not sure if that's changed since I last looked at it.
It's basically claiming all unspent Bitcoins mined during the first year were mined by Bitcoin's creator. But there is _no_ evidence linking them to Bitcoin's creator except pure handwaving.
- fork this
- remove the 10% economy imbalance
- remove centralized alerts and anything centralized
- integrate ethereum & namecoins
- Get a governance body that would be very neutral and protect principles of the blockchain (EFF? ...)
And then we could have a normalized, standardized, basis for the rest of blockchain based protocols...
https://cryptowat.ch/poloniex/zecbtc/5m
Pretty crazy, it hit a high price of 3300 BTC! That's $2MM.
Also, the other reply to you mistook you for not understanding that your link is satire, which I believe you understood.
Haha. 10% premine to uplift the founders with millions, more like.
Or should we say tax-mined ?!
At this point, in order for me to pay attention to any crypto-currency other than Bitcoin, it would have to allow for more than just one of the following:
- buy black-market without getting pinched, more easily than paper money
- pay bills with a verifiable proof of payment, more easily than checks
- buy from untrusted parties, more easily than credit cards
- save at lesser risk of theft than cash in the mattress
- save at lesser risk of confiscation/forfeiture than money in the bank
- save at lesser risk of market volatility than Bitcoin alone
- allow anyone to issue barter scrip
- facilitate trade-chain settlements and redemptions of barter scrips
- allow both anonymous transactions and provable-identity transactions
- facilitate honest trade while crippling scammers
- stable decentralization, such that N% attacks are impossible
- built like a pile of bricks, instead of a house of cards
- no excessive pre-mining or front-loading
- if not future-proof, at least future-resistant
So far, the only thing Bitcoin really has going for it is that it got to the mountaintop first. But since no other alt-coin has proven to be superior in more than one or two of the ways that matter to the users, none have yet displaced even it, and never mind surpassing any of the traditional currencies.And I think none of the schemes set up to reward those investing in the costs of development will succeed. In the end, a currency has to be a commodity, and you can't charge much more as seigniorage on a commodity currency than the actual cost of operating the mint, unless you have a monopoly. Otherwise, you're better off running the power plant than the data center packed with ASICs.
All of this is not great. This is why we say Bitcoin is not anonymous, but "pseudonymous".
So Zcash fixes this by obfuscating all of this: sender, amount, recipient are just obfuscated blobs of data. You don't know how much was sent, from who, to whom, but you cryptographically know the transaction is valid (didn't try to send more coins than the recipient has, etc). This is verified through fancy so-called "zero-knowledge proofs". See https://blockchainhub.net/blog/infographics/zcash-explained/
zCash offers a level of anonymity beyond anything we have seen (Monero hasn't activated CT yet). Systems with similar properties as zCash ([see auditable eCash](http://www.cs.tau.ac.il/~amnon/Papers/ST.crypto99.pdf)) have been discussed since the late 90's, today marks the first time to my knowledge one has been deployed in production. This is a big deal. I'll raise a glass to the zCash team.
tl;dr zCash is a very impressive cryptographic achievement.
Bitcoin, to which it is most similar, is the currency it tries to differentiate itself from, but it is not its main competitor, and it looks like it shares most of its flaws compared to its main competition, the dollar.
In terms of availability, the US government has facilities in place to produce more cash without breaking the economy, while there is a limit to how many Zcash coins can be produced. In fact, since people cannot transfer Zcash after their death, there is absolute certainty that Zcash has an expiration date.
In terms of volatility, Zcash shares Bitcoin's (and most traded commodities') flaw in that the value of assets held can fluctuate tremendously, making Zcash one of the riskiest currencies on the market. Even buying pounds is a safer investment. The dollar has, yet again, facilities in place to avoid huge swings in its value.
In terms of ease of use, Zcash requires complex maintenance, careful security practices, and computing power. The dollar has a whole banking industry in place, from paper money to debit cards to Apple and Android Pay. All of that makes storing and transacting painless, and not that expensive, all things considered.
In terms of energy consumption, well, yet again Bitcoin's flaws shine through.
Most people want to exchange money for goods and services lawfully, which means adhering to taxes and audits and ensuring that no money laundering takes place, so Zcash's anonymity is not a huge selling point.
Bitcoin had the benefit of being the first practical currency of its kind, which was enough to surpass its flaws. Do you believe Zcash will survive ten years?
Tell me how I can anonymously send $10,000 to another country with dollars?
Sending $10,000 to another country should not be anonymous, to combat fraud and illegal activities. Many countries have laws about that kind of thing.
Do not underestimate how much a system like that is abused and that is where the problem is with not allowing anonymous transactions.
As much as I'd like to stop terrorism and activities that really are immoral to society as a whole, you can't circumvent the security of the people who are good because it's proven those systems become abused in ways that it was not originally intended.
But within the cryptocurrency space people are even less rational since after investing their money they now have a perverse incentive to try discredit any competition and the effects of their confirmation bias after investing are truly immense. Bitcoin in that sense, is one of the most toxic communities out there since its entire community seems to be against any kind of innovation taking place outside of Bitcoin and are quick to dismiss any such attempts as "crapcoins."
I wish we could go back to 2011 when people were more opened minded ... It's honestly gotten to the point where no one can work on anything new in this space without some shill from Bitcoin trying to cast doubt on their project to steer people back to it ... So I guess pick your favorite investment and support your side.
"Arguments are soldiers. Once you know which side you're on, you must support all arguments of that side, and attack all arguments that appear to favor the enemy side; otherwise it's like stabbing your soldiers in the back—providing aid and comfort to the enemy. People who would be level-headed about evenhandedly weighing all sides of an issue in their professional life as scientists, can suddenly turn into slogan-chanting zombies when there's a Blue or Green position on an issue."
Cryptocurrencies are the new mind-killer.