(Yes, I've looked at the other attempts to build a private alternative to Bitcoin, including Monero: https://github.com/monero-project/monero/issues/1271)
(Yes, I've looked at the other attempts to build a private alternative to Bitcoin, including Monero: https://github.com/monero-project/monero/issues/1271)
Even if they are 100% legitimate actors, the lack of absolute proof undermines the provenance. From my perspective, Zcash is technically a Fiat currency without the clout of a state backer.
I'm sticking to bitcoin and ethereum :)
Don't give up so easily! If you're going to make a stance borne out of principle, why not follow through to outperform the suboptimal solution that you dislike so much?
Innovate. Put some skin in the game. That's what I would do, anyway.
As it stands: If any of the folks involved in the trusted setup was honest, then it's secure. It takes a 100% corruption to make it insecure. I think that's acceptable until a better solution is proposed.
Except that they had to rush the launch because they're a for-profit, centralised company, with investors that are demanding return on their investment. Thus they went with a shoddy, half-baked attempt at a trusted setup, with a whole lot of hand-waving to make it seem like it was done securely.
The protocol is expensive; it took 2 days with 6 people. After a certain point, it's not practical to add more participants without increasing risk. It requires gigabytes worth of communication per participant and many millions of curve operations.
It's 20% for the next few years, not 10%
It may be 20% for the next few years, but it's also 10% overall. You're both right, why even try to nitpick over these details or correct anyone?
Keep in mind that while videos of the destruction are entertaining - and and possibly useful for education and peer review - they prove nothing. You shouldn't trust Zcash significantly less because they haven't been released yet - if that'd make you trust Zcash more, you're probably not thinking carefully about how fundamentally based on trust the whole process was. I'm one of those six individuals, and the simple fact is it would have been trivial for me collude with the other five to backdoor the process undetectably; if we did that you would never know. End of story. (and sorry, but the video footage of the ceremony that some stations apparently kept doesn't change that either)
Also remember that everyone ran the exact same software - a bootage DVD image - and that software was produced by one guy the day prior to the ceremony. I hear Andrew Miller successfully reproduced the build of that DVD image, but there's a lot more independent auditing work that needs to be done on that software. Until that work is done by multiple independent people, the entire multi-party aspect of the ceremony is just a bunch of crypto hocus pocus that means nothing.
You don't trust ZCash but you trust Ethereum? The coin that's had it's network hard forked and invalidated... what 4 times now?
But more importantly, the contributors acknowledged the issue, and are fixing it. Do you honestly expect bug free open-source development? No, and the entire benefit of it being a welcoming open-source development community (instead of ZCash's centralised development team) is that it is made better by many eyes. Hopefully the OP that opened that issue spends some more time reviewing the code along with the 160+ Monero contributors.
Also, if we're going to view lapses like these as representative of a major failure, you'd best review some of ZCash's greatest hits, maybe starting with the fact that wallet encryption is ENTIRELY DISABLED in ZCash, and your wallets are stored in the clear and ready for malware to steal: https://github.com/zcash/zcash/issues/1552
- https://github.com/zcash/zcash/issues/713 <- this one is particularly stupid, and shows a gross misunderstanding of how Bitcoin works
- https://github.com/zcash/zcash/issues/1304
- https://github.com/zcash/zcash/issues/1522
- https://github.com/zcash/zcash/issues/1779 <- literally, they had ONE JOB for the release, how did they fail at that?
- https://github.com/zcash/zcash/commit/f8ada2435bd3f6b7a1165e... <- oh that's right, they failed at the one thing they had to do because they were focused on other...uhhh...important stuff
And let's not forget the massive attack surface that ZCash has, which leads to fun things like this:
I very strongly disagree with userspace RNGs being used instead of the kernel's CSPRNG being "pretty ok".
Don't "seed a userspace RNG from urandom". Just use urandom.
ZCoin is a separate currency that is not related to ZCash.
Before wondering why you're getting doenvoted, try to make sure that you're not saying incorrect things.