As you suggested, all I meant is that once you have a fully anonymous currency it’s always possible to deliberately weaken that privacy if you want to. I think that sort of decision is up to the currency adopters. But to be clear, that kind of feature is absolutely not included in ZCash. Anyone who implies so is selling FUD. Since the ZCash code and design is fully open source this is easily verifiable, and plenty of people have looked.
For the record: as a researcher I deal with a lot of people who’ve told me that privacy technology is fundamentally dangerous. One standard response I give them is that this is crazy: a fully private currency is the right starting point. If you want to make a fork of ZCash that has less privacy, you can do that and I won’t stop you. But that isn’t ZCash.
I am not implying any backdoor, just that it seems you are sympathetic to such works. I don't follow Zooko's explanation that he wasn't talking about zcash but about some other unmentioned layer. If it's a generic statement about all currencies, why bring it up and mention zcash in the same breath?
Especially when Green has his own quote saying they're OK building backdoors for police.
Or maybe that is their entire plan. Say something slightly sketchy, knowing any real criminal will be too paranoid to trust it. Worked for me.
The question is, do we believe that there's room in the Zcash protocol for a cryptographic back door?
Anyways once they get mandatory shielded transactions I'll look at it in more depth and see if I can get comfortable.
- Aren't zerocoin and zerocash two different currencies? Did you mean to say zerocash in your previous comment?
- If what Matt Green is saying is true, is there a way to create a backdoor in Monero or any other new crypto that comes along?
- One of the reservations that I have around z-cash is the "don't roll your own crypto" mantra even if you are an experienced, academic cryptographer? Is z-cash inherently more risky because its using newer crypto?
It's not about rolling own crypto. My understanding is that zcash is more risky due to the newer concepts involved.
This is all theoretical right now anyways. Without more support for shielded transactions, it isn't feasible to use zcash to clean Bitcoin or other cryptocurrencies. Exchange volumes of XMR-ZEC are also too small from what I can see to make stacking them useful.
That said, we are reconsidering things. We will probably add zcash as a payment method sometime this week.
Why start up world wide? Why not start only in jurisdictions where what you're doing is legal? Wouldn't that give yourselves an opportunity to build and test all the layers of your company in a relatively safe environment before moving into markets like the US?
US targeted for mid-2018 after we have a few cities smoothly operating.
This approach is vulnerable to an easy attack: get government funding, design a cryptosystem with lots of backdoors, and proudly proclaim that you will never add one and you will absolutely stand up to the government.
I think you should find a better way to evaluate cryptosystems.