Keybase chooses Zcash
keybase.io
keybase.io
When I shared a draft post with some friends, a lot of them had an ah-ha moment, so I was hoping for the same from others. I was trying to illustrate 2 privacy concerns around the graph Bitcoin exposes: (1) accidental associations and (2) exposing the people you transact with to each other.
In the blog's hypothetical, you're not receiving money from some asshole because you're collecting Klan dues from him. Rather, you performed some public transaction with a stranger. For example, maybe you sold him some tickets. An external observer of the graph who knows he's a dangerous character may start applying high odds that you, too, are a dangerous character, since they don't know why he sent you money. This would suck. And, second, this character who sent you money may also be learning things about you. Since you sold tickets to a local show and mailed them to him, (1) he's likely to live near you, and (2) he knows your return address. You really don't want him seeing that you're sending money to causes he opposes. If so, he might show up at your door.
The goal was to clear up this misconception that a private cryptocurrency is there to protect criminals. This is especially important if you'd like to post a static address on a profile.
We're sadly living in a society where people search high and low for grievances to publicly virtual signal over. Hopefully the Twitter-sphere will realize there's value in your example and not just clutch pearls.
Thank you for explanation.
I'm not saying it is, but Monero came out far earlier than Zcash, and unless there is a substantial argument for using it over Monero, I'm not convinced of the argument to standardize on it. The only striking difference I can see between Monero and Zcash is that Zcash was premined by investors.
I just did some digging and also found this: http://monero.stackexchange.com/questions/83/how-does-monero...
In Zcash on the other hand, your anonymity set is everyone who holds Zcash. It's a lot nicer, and there isn't really the same collapsing effect as can happen with Monero.
That said, Monero crypto is simpler, doesn't have trusted setup, and overall I would advocate that people treat Zcash as hemorrhaging-edge experimental, while Monero is somewhere between cutting-edge and bleeding-edge.
>When you spend money, you basically say "I am one of 2^256 people", where 2^256 is usually fairly small.
Disappointing/embarrassing level of insight from a crypto project leader - here's a good layman-friendly video https://youtu.be/GEVm1dMn5Ks?t=14m to bring you up to speed (the simplified example is continued at 20m).
I mean, your argument "you're stupid, look at this youtube video" is not very convincing either.
Step 1: make a bunch of addresses Step 2: the world know it was you
That reduces the anonymity set for everyone else. They thought they were mixing with you anonymously but now that you are revealed, your participation in the mixing is useless, people would have done better to select someone else.
Combine this with Sybil attacks, criminal investigation, and other unmasking techniques and you might get the anonymity set down to 1 for a particular output, allowing you to further reduce other anonymity sets.
I was not aware, but apparently the Monero blockchain has a snowball effect to help mitigate this.
Basically, unless you own 80% of the outputs on the blockchain you don't have enough to identify subsequent transactions, so any foothold you gain in owning outputs becomes rapidly weaker. Given the cost of owning 80% of the blockchain outputs, it's not an attack that is particularly effective even at Monero's current state of usage.
Individuals who publish their input history won't make any significant difference.
Since Monero outputs go to dual-key stealth addresses, outputs are effectively paid to a random 256-bit "address". So if you use a mixin of 50, in a transaction with 1 input, an external observer can say "this illicit transaction spends funds from 1 of 50 possible transactions", but then you need to go to those 50 and work your way back till eventually you find a needle, in a very large haystack, that you can actually identify.
Because of this, the anonymityset grows exponentially the further up the tx chain from an identifiable transaction (eg. a withdrawal from a KYC / AML exchange) you are.
The major advantage here is that every Monero transaction adds to this anonymityset, since privacy is compulsory.
On the other hand, ZCash's privacy is nearly unusable. Using it requires 8gb+ of RAM, and takes over a minute on a Xeon processor. Because of its unusability you end up being "1 of X people", where X is very tiny - it's limited to the people moving from traceable addresses to z-addresses who haven't identifiably moved ~the same amount out.
ZCash is useless at best, dangerous privacy theatre at worst.
>Using zCash requires 8gb+ of RAM, and takes over a minute on a Xeon processor.
Cryptography in this area is rapidly advancing, we have seen dramatic speed ups in zkSNARKS (cryptography behind zCash's anonymity) over the last few years and the launch of zCash will probably accelerate this trend.
> it's limited to the people moving from traceable addresses to z-addresses who haven't identifiably moved ~the same amount out.
This number, X, is growing and will continue to grow.
>ZCash is useless at best, dangerous privacy theatre at worst.
zCash is an excellent and exciting experiment. It is not a very mature platform (it has only been live for a month), but that doesn't mean it will never been mature.
Thus X grows at a rate that is useless for its intended purpose: getting lost in the dust of millions of others.
But to make matters worse, ZCash is grossly irresponsible by not making private transactions mandatory, as people will use t-address transactions and think they're safe. Pools pay out to t-addresses, exchanges only accept t-address deposits, and lightweight clients will all end up being t-address only as it's the quick win.
Claiming that it's "just an experiment" is not acceptable when people's money is on the line, at best, and where their lives might hang in the balance, at worst. The disgusting and dangerous approach taken by the for-profit US company behind ZCash, that of fast-tracking the launch of massively immature technology due to investor pressure, is something that should lead to grave consequences for them because of the nature of this technology.
I greatly respect the work of Ben-Sasson, Green, Garman, Miers, et. al., but even they have been complicit in the rush hack-job that is ZCash. We would do well to consider what advantage a nation state attacker would have in encouraging adoption of this immature and likely broken system, over alternatives that are FOSS and have prolific contributor communities.
Claiming it is just an experiment means that people should NOT use it when serious money or human lives are on the line. I think we can both agree that people should wait for a technology to mature before betting their life on it.
Also if Gmail lost all your email it would be bad, but you'd probably be ok. If ZCash causes you to lose a significant portion of your life saving, on the other hand...
That was my point, gmail was in beta for five years, but it wasn't in beta forever. Technology takes a long time to mature and it is hard to get to that level of maturity without having people use it for real things.
Do not put a significant potion of your life savings in ZCash.
Stealth addresses seem like they give much weaker anonymity guarantees than Zcash, unless you only ever send and receive funds through stealth addresses with others who follow the same precautions.
http://sx.dyne.org/stealth.html
https://www.reddit.com/r/Bitcoin/comments/2r07hu/whats_happe...
To clear this up, I'd suggest adding the explanatory labels ("Old copy of...") directly adjacent the lines in the image, instead of in a separate key.
But no one has a problem with the meth cook example??
very interesting choice. i can only guess the political affiliation of this author.
when i was in my formative years everyone was trying to shake labels and thus the stigmatism associated with them. and thats really what the civil rights leaders of the 60s stood for. its a shame that the movement has been subverted by corporatists and sycophants. you all lost me. and many others.
Maybe because those examples are from the 80's?
i can only guess the political affiliation of this author.
And his drug of choice, I suppose?
they do this because they can justify their data derivative, but if there's no trace data to justify semi-justifiable decisions, such disastrous inferential machines would be impossible to justify.
it's a tricky case - but it would force law enforcement - and other parties of interest - to actually investigate before pulling triggers.
[1]: http://arstechnica.co.uk/security/2016/02/the-nsas-skynet-pr...
I am relieved that 'Keybase chose Zcash' purely on merit after an exhaustive and objective selection process, and that this potential conflict of interest is transparently disclosed in the linked adverticle - wait, they did no such thing.
Does it concern no one that this security-focused company is shilling for other (fundamentally questionable) products?
It might even be worse if it wasn't as such - a security-oriented business that, motivated by Bitcoin's shortcomings, does due diligence on anonymous crypto and genuinely concludes that Zcash, in its current state no less, is the answer? Come on.
I do appreciate you're pointing out this alternative take. I guess what clouded our discussion is that we mixed questioning their motivations (the investors thing) and their judgement (ie is zcash a good choice?). I missed the latter, focusing on the former only.
Worth adding here that it also appears Zcash stakeholders have been internally buying/selling their own ZEC at inflated prices on Poloniex to artificially increase both volume and the market price.
Whilst perfectly legal, it doesn't enhance a "trustworthy" reputation to me.
I don't understand this. None of the stakeholders have even received their money yet; this is publicly verifiable.
You wouldn't need any ZEC to begin with.
Just to be clear, I am not specifically claiming the devs are doing this, but somebody with an interest in ZEC performing well (and money to burn to prop up the price) has been.
It's eased off now in any case, but it hasn't gained trust from a trading point of view.
https://lists.randombit.net/pipermail/cryptography/2016-Nove...
(Yes, I've looked at the other attempts to build a private alternative to Bitcoin, including Monero: https://github.com/monero-project/monero/issues/1271)
ZCoin is a separate currency that is not related to ZCash.
Before wondering why you're getting doenvoted, try to make sure that you're not saying incorrect things.
Even if they are 100% legitimate actors, the lack of absolute proof undermines the provenance. From my perspective, Zcash is technically a Fiat currency without the clout of a state backer.
I'm sticking to bitcoin and ethereum :)
Don't give up so easily! If you're going to make a stance borne out of principle, why not follow through to outperform the suboptimal solution that you dislike so much?
Innovate. Put some skin in the game. That's what I would do, anyway.
As it stands: If any of the folks involved in the trusted setup was honest, then it's secure. It takes a 100% corruption to make it insecure. I think that's acceptable until a better solution is proposed.
Except that they had to rush the launch because they're a for-profit, centralised company, with investors that are demanding return on their investment. Thus they went with a shoddy, half-baked attempt at a trusted setup, with a whole lot of hand-waving to make it seem like it was done securely.
The protocol is expensive; it took 2 days with 6 people. After a certain point, it's not practical to add more participants without increasing risk. It requires gigabytes worth of communication per participant and many millions of curve operations.
It's 20% for the next few years, not 10%
It may be 20% for the next few years, but it's also 10% overall. You're both right, why even try to nitpick over these details or correct anyone?
Keep in mind that while videos of the destruction are entertaining - and and possibly useful for education and peer review - they prove nothing. You shouldn't trust Zcash significantly less because they haven't been released yet - if that'd make you trust Zcash more, you're probably not thinking carefully about how fundamentally based on trust the whole process was. I'm one of those six individuals, and the simple fact is it would have been trivial for me collude with the other five to backdoor the process undetectably; if we did that you would never know. End of story. (and sorry, but the video footage of the ceremony that some stations apparently kept doesn't change that either)
Also remember that everyone ran the exact same software - a bootage DVD image - and that software was produced by one guy the day prior to the ceremony. I hear Andrew Miller successfully reproduced the build of that DVD image, but there's a lot more independent auditing work that needs to be done on that software. Until that work is done by multiple independent people, the entire multi-party aspect of the ceremony is just a bunch of crypto hocus pocus that means nothing.
You don't trust ZCash but you trust Ethereum? The coin that's had it's network hard forked and invalidated... what 4 times now?
But more importantly, the contributors acknowledged the issue, and are fixing it. Do you honestly expect bug free open-source development? No, and the entire benefit of it being a welcoming open-source development community (instead of ZCash's centralised development team) is that it is made better by many eyes. Hopefully the OP that opened that issue spends some more time reviewing the code along with the 160+ Monero contributors.
Also, if we're going to view lapses like these as representative of a major failure, you'd best review some of ZCash's greatest hits, maybe starting with the fact that wallet encryption is ENTIRELY DISABLED in ZCash, and your wallets are stored in the clear and ready for malware to steal: https://github.com/zcash/zcash/issues/1552
- https://github.com/zcash/zcash/issues/713 <- this one is particularly stupid, and shows a gross misunderstanding of how Bitcoin works
- https://github.com/zcash/zcash/issues/1304
- https://github.com/zcash/zcash/issues/1522
- https://github.com/zcash/zcash/issues/1779 <- literally, they had ONE JOB for the release, how did they fail at that?
- https://github.com/zcash/zcash/commit/f8ada2435bd3f6b7a1165e... <- oh that's right, they failed at the one thing they had to do because they were focused on other...uhhh...important stuff
And let's not forget the massive attack surface that ZCash has, which leads to fun things like this:
I very strongly disagree with userspace RNGs being used instead of the kernel's CSPRNG being "pretty ok".
Don't "seed a userspace RNG from urandom". Just use urandom.
Personally I find the whole idea of zclassic a bit disappointing. Some people spent a lot of time and effort on to something which cost a lot of money. They're giving it away for free and people have a problem with them making money off it.
Of all the qualms I have with Zcash, I think that their mining fee is one of the cleaner ways in the ecosystem to fund altcoin development. This technology takes a lot of effort, and a lot of salary money to develop. And then you have to do marketing, PR, bizdev, etc.
re: qualms:
- trusted setup makes me uneasy - could have picked more than 5 people for signing party - cryptography is really scary - lots of assumptions, lots of things that haven't really stood the test of time or the examination of experts - equihash was a poor decision, and a confusing one given that it's pretty well understood that complex hashing functions are counterproductive (and we've seen this play out already for Zcash, things are just getting started) - The 'slow start mining' was also a really bad idea, and I would almost suggest that it's abusive to the community. More than $100,000 of trade volume happened over Zcash at prices that are 1000x the current price of Zcash. It should have been easy to understand that this would happen.
Mostly, I would urge people not to use Zcash for situations that require real anonymity. E.g. wikileaks accepting donations, or routing around captial controls in oppressive countries. And this is because I do not believe that the cryptography will hold up. There's too much of it, it's too new, and it's too interesting (e.g. a lot of aspiring undergrads and grads are looking to make their mark on the world, and breaking Zcash would be a great way to do that). I believe that your privacy will be compromised retroactively, and not due to bugs but due to actual cryptographic breaks. And then you're back to the Bitcoin network where everyone can see everything, and you're vulnerable.
I think it was six people: https://github.com/zcash/mpc/blob/master/README.md
Which component do you think is most likely to break?
I would disagree; the cryptography that people are more skeptical of in Zcash involves soundness of the zero-knowledge proofs. (i.e., if counterfeiting could occur) Privacy is protected by standard cryptographic assumptions that are relied on in other systems.
In fact I would advocate for a zero-day start, where the first few hundred blocks following genesis have exactly 0 reward, coupled with an overestimated initial difficulty, so people have some less stress-full time to get set up and sort out technical problems.
The crazy initial prices are abusive to no-one except the fools who pay them.
I generally hold the opinion that you should not create traps for speculators, that's exactly what slow start mining is.
I think there are better ways to prevent unfair early distribution, such as a more responsive difficulty adjustment algorithm (per the work of maaku), or even just a longer inflation taper. Instead of mining half the entire supply in just 4 years pick something a bit slower.
Or do something like let Bitcoin holders as of X date collect a proportionate amount of coins in a premine. Then you get to borrow from some of the distribution that Bitcoin has already achieved.
---
And you are right as far as traders only hurting themselves. Nobody aware of the inflation schedule bought above $1k per coin, I'm almost certain of that. But I think what happened is akin to throwing a bunch of black belts into an arena with people who have never been in a fight before. Sure, they might have chosen to be in the arena, but are you free of responsibility when they get hurt? Especially if they did not realize they would be fighting champions?
Perhaps a weak metaphor. But I think disingenuous to call someone a fool simply because you had more information than they did. It doesn't seem right to me to use that to justify predatory behavior.
It's fair-ish distribution, without the absurd trading game that followed the Zcash release.
Privacy is compulsory with Monero and also the entire platform is decentralised.
The privacy features in Zcash are optional & very slow / difficult to use -- most users will simply make non-private transactions. Also Zcash requires trust of the founders (Any "private" coin that requires trust of a third party is a fail in my mind).
ctrl-f 'founders reward'
Seems like a good business model and a way to fund the innovation they've created.
Bitcoin worked just fine without Satoshi programming rewards for himself.
The home page also follows a similar pattern: just beautiful, uncluttered, no bullshit design, that gets straight to the point. Why can't more websites do this? A+++ would browse again.
If anonymity is so important for people, there are already excellent solutions, Monero being one of the best, if not the best, with a strong and serious dev team.
Disclaimer: I am not a Monero dev and I own a huge total of 0.6 XMR. This is only my opinion as a software dev.
I also wonder about how much of a risk to its own ecosystem Zcash being a private company represents. Was that really better than making it a non-profit? And won't this make it easier for law enforcement to go after Zcash as the sole culpable entity for "money laundering" and other such charges?
Basically you'd have a pool of "shielded" txouts that could be spent with a zcash signature, without any requirement that a particular txout be spent for a given signature. Surpisingly easy upgrade all things considered; the main blocker is Zcash's crypto is very experimental and slow.
> use the invitation code "zcash" during signup
I like the ideas behind Zcash and it solves important privacy issues, but I don't like the idea of a for profit company being the heavyweight behind Zcash.
From what I gather, Bitcoin is more of a community effort than most other altcoins, which inspires trust.
I looked up Zcash's price chart, it fell from ~$1300 at launch to ~$90 now. Ouch.
Perhaps the greatest example I've ever seen of tulip mania. And I'm fairly confident those were real trades, as they occurred on a public exchange where anyone with money or zcash was able to buy or sell at any time. Granted, at this point there were only dozens of people with the asset, but anyone was able to mine the currency and blocks were being found every 2.5 minutes using commodity hardware (e.g. laptops and desktops).
No. When zcash was trading at such a price, it was less than a single zcash coin in total. So a few people were paying significant sums for very small fractions of a zcash coin, but no one payed 2,000,000 for a single coin. The price has crashed because supply has grown exponentially. What you were seeing was supply vs demand in action in an unusually obvious way.
These people buying it hopefully would have been aware of the publicly known upcoming inflation, the fact that they bought at these prices I believe is a tragedy and a black mark against Zcash.
[1] I realize this is not really possible because you'd have to buy the entire order book first, but in the case of ZCash the order book was empty.
There is no tragedy here, IMO. Just some calculated market manipulation...
It is pending a Bitcoin softfork (segregated witness) (edit: actually I don't think it depends on this), and I don't think anyone has implemented something approximating z-addresses on this yet, but the opportunity is there.
I got myself a Keybase account a while ago; is it reasonable to use it if Zcash is not something I would touch with a ten-foot pole?
Kraken is an exchange that sells Zcash to USD holders (as long as you aren't in NY state!). Another option is to buy Bitcoin (e.g. from Coinbase) with USD, and then use shapeshift.io to convert your Bitcoin to Zcash.
Extreme inflation will continue sending prices crashing. Recall early this month prices were hovering around 2 Ferrari 458 and now it's tanked to under a 100 dollars.
If we were to assume that in 48 months X 200,000 ZEC = ~100,000,000 ZEC with 20,000,000 ZEC belonging to the Founders.
edit: why the downvotes? I'm just reporting the facts: https://twitter.com/TommyEconomics/status/793435785097646081...
Mining is generating Zcash way too fast for the market to absorb. The "market cap" has been holding steady as the priced dropped over 99%.
Somewhere between $2-$10 is a more realistic valuation (based on other coin valuations) -- it will be interesting to see if the price stabilises once within this range.
20% for the next 4 years goes to the "founders" (which is not just the developers, but investors as well). But much like Bitcoin the total monetary base is fixed at 21,000,000 ZEC. And also like Bitcoin, the total mining reward is halved (roughly) every 4 years, and consequently decreases exponentially until it reaches that total reward.
Effectively, this means that the Zcash Founders Reward doles out 10% of the currency to the investors/early development team over the lifetime of the currency, and in many ways mirrors a startup vesting cycle of 4 years (minus the one year cliff). Their blog goes into more detail about the reward here: https://z.cash/blog/continued-funding-and-transparency.html
Personally, I think this reward distribution is a significant improvement to the "premine/ICO" antics you see in many other cryptocurrencies/tokens, even if I think it's a little high. I applaud the team for trying something new/seemingly more fair.
(Also, not affiliated with the team, just a cryptocurrency nut: http://keybase.io/cin)
What does this part mean?
In cases they seem to be reporting a price in terms of random objects instead of currency. For reference the price converts into roughly 1.5 pints (US) of gold
https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trust...
Did you actually read it?
In practice Zcash/zcoin (different tradeoffs) are of no use to you unless you are willing to go the extra mile to hide something (criminal activities and such). There's no point in paying for the extra effort for normal transactions.
EDIT: found some data in the ceremony report linked elsewhere in this discussion: https://petertodd.org/2016/cypherpunk-desert-bus-zcash-trust...
The problem is verification of private transactions is very slow by cryptocoin standards, and verification is something that every full node and miner must do. Zcash would fail if private transactions were used in large numbers, as blocks would take too long to validate for mining to remain decentralized; Bitcoin transactions are a few orders of magnitude faster to validate, with a 4x more conservative block interval and 2x smaller blocksize, and the Bitcoin dev community has had to make heroic efforts to further optimize validation.
Again, I don't think it's very responsible to knowingly release design a protocol that in its current form would collapse if heavily used due to a lack of safety limits.
Maybe even if I don't need the anonymity now, maybe in 10 years I will, and then I don't want to start using them because that change provides information.
https://keybase.io/inv/81ae92fb55
https://keybase.io/inv/1405ab98be
https://keybase.io/inv/841bcaf887
https://keybase.io/inv/1b2d6b8489
https://keybase.io/inv/d4d629e661
https://keybase.io/inv/aa8d6f88a7
https://keybase.io/inv/1e2d324856
https://keybase.io/inv/ed26718971
https://keybase.io/inv/3b60a5f56d
https://keybase.io/inv/c11ebfb7ac
Sold out.
This news spurred me to delete my Keybase account. I regret ever giving a corporation that much control over my personal privacy.
[1] https://github.com/libbitcoin/libbitcoin-explorer/wiki/Steal...
But there is no reason to post such an address. If Alice wants to post a fully private Bitcoin address that can't be monitored by data harvesting firms, she should post a stealth address [1]. If Bob wants to send Alice BTC, he takes Alice's stealth address and derives from it a regular Bitcoin address. No one but Bob can know what Alice's derived Bitcoin address is, because the address is derived from Bob's private data.
The libbitcoin software suite supports these stealth addresses, but because libbitcoin isn't VC backed and doesn't have the hype of moneyed interests behind it, libbitcoin wasn't good enough for Keybase. They probably never even evaluated it.
A ZCash "zaddress" is basically just a Bitcoin stealth address.
That the CEO of a privacy-focused social networking service is not in tune with this information is a huge red flag to me. As each Keybase.io profile is an implicit endorsement of Keybase and by extension Keybase's investors, I was deeply saddened and frustrated to learn the news that Keybase has decided for its entire userbase to prop up ZCash based on their faulty assumptions.