The Security Behind the Birth of Zcash
spectrum.ieee.org
spectrum.ieee.org
If the list is so small, who are they?
In all seriousness though, if I were one of a handlful of people who understood a rising anonymous currency platform, I wouldn't want to be publicly exposed that way.
That aside, the MPC (Multi-Party Computation) setup is more of a security theater than actual security. It completely goes against of what cryptography is all about and I'm puzzled as to why any cryptographer would base their system's security in such a way.
http://zerocash-project.org/media/pdf/zerocash-oakland2014.p...
It's a peer-reviewed conference and basically the top venue (along with Usenix Security and ACM CCS) for academic computer security.
I'm not sure what you mean by "for something that ground-breaking"?
(For background, I used to publish at this conference and others, did my share of paper reviewing, and my colleagues were working on e-cash crypto around the time of bitcoin's rise.)
[My own background is firmly in systems security – I've had papers at Oakland and CCS – and I'm not as familiar with the crypto side]
SNARKs have gotten the appropriate peer review from the right parts of academia. To everyone else reading this: Of course, that doesn't make it secure and there are limmits to peer review. Just because 3 to 5 reviewers read the paper and thought it was publishable doesn't mean it's correct. However, those works were high enough profile that others have looked at the papers once they were published, which is the real meaningful part of peer review and that comes after publication.
None the less, snarks are one of the more sophisticated cryptogrphic techniques ever deployed. And peer review also says abosultely nothing about the security of the implimentations of software instantiating the cryptography. But the only way to remidy that is to build software, deploy it, and get people to look at it.
Zerocash itself is a fairly simple protocol built on top of SNARKs, so the fact that it was published at Oakland isn't the biggest worry. It's also gotten a bunch of scrutiny after that.
[0] http://link.springer.com/chapter/10.1007/978-3-642-38348-9_3... [1] http://link.springer.com/chapter/10.1007/978-3-642-40084-1_6... [2] https://eprint.iacr.org/2013/507.pdf
Speaking of - why did you rush it out? Because your investors wanted to make profit? Absolutely despicable.
[1] http://web.stanford.edu/class/ee380/ [2] https://www.youtube.com/watch?v=KP8TPeYQyN4
But I mean a realistic one, including info such as: - how much it has been pre-mined. - why is it being pushed ( research, corp goals, etc) - limits (does one need a GPU to use it or can it execute on a CPU)
I know of few places that have lists, but I get the impression that people start currencies lately as a shot at getting rich if they take off, and not from a realistic need to do so.
Unlike Bitcoin, Zcash transactions can be shielded to hide the sender, recipient, and value of all transactions on the blockchain.
So you can't claim Monero already solved all the problems that Zcash is trying to solve.
Not only does Monero already do what ZCash is trying to do, but it has two main advantages:
1. EVERY transaction is private, which means that the entropy of the anonymityset is continuously growing. Instead, ZCash restricts privacy to an opt-in mechanism (mostly due to private transactions being horrible - requiring north of 8gb of RAM and several minutes on a modern computer) which means that there is a trivial amount of entropy, and deanonymization is pretty trivial.
2. Monero is focusing on further improvements that ZCash is just dreaming about, such as their C++ i2p router, Kovri. They can do this because they've been in production, tested, and hammered for several years.
The real question is: what does ZCash provide that Monero doesn't, except some sort of ridiculous "star cred"?
I agree with your other criticism of Zcash though. The situation is far from perfect.