That's mentioned explicitly in the article. With explicit dates of certain protocol changes that have improved things.
> And it's not like we aren't actively working on ways to improve anonymity.
In other words, there are threats now. Which is what the article says.
> I always appreciate research into ways to improve Monero, but I don't think this article does the research justice.
I haven't seen the original research, so I cannot tell if the article does it justice. But I can say that what you have said here doesn't call the article into question. You have just restated the things it says.
(For whatever it's worth, I do own some Monero and I would like it to be successful. Part of that is accepting valid, constructive criticism.)
The paper has 3 recommendations:
1. Warn users who made early transactions that they may have had their ring signatures compromised. The stealth addresses would still work. This isn't a suggested improvement, and I believe that any user interested in maintaining their privacy should have considered researching Monero, including reading MRL-0001. I'm sure not everyone did this, but keep in mind that Monero was a much smaller network back then made of mostly enthusiasts. If you were transacting on AlphaBay, the least you could have done is seem what the limitations of your tool are. They were much higher at the time than they are now.
2. Improve the decoy selection algorithm. There is definitely room for improvement to make the most out of the decoys selected for the ring signature.
3. Consider avoiding public pool payout outputs, which are known to be used in the pool transactions. This is a fair point, though from the proportion of pool payout transactions to total transactions as found in the paper, this case is likely still adequately covered with ringsize 7. Monero can still consider avoiding these outputs as decoys though in some way.
Monero would gain credibility if it took a conservative approach to ringsize then used research to lower the ringsize. Instead we get no justification for ringsize saying there is no research that shows an increase needed. This is the opposite way of how security is approached. Indeed: The only MRL statement I know of on churn is that it does not work.
I appreciate the work you do and MRL overall. But without practical examination of real-world threats it feels a bit empty. And Monero team refusal to provide any sort of disclaimer at all really undermines the sincerity.
Being on the Monero team, can you comment on the differences between the privacy guarantees provided by the two platforms?
Monero uses ring signatures to prove that one out of n people signed a transaction without revealing which one of the n. Over the course of k steps the possible transaction history might be in any of n^k states. Typically n=5.
Zcash uses Zero-Knowledge-Proofs for anonymity. Any private zcash tx may have gone to or come from any other private zcash tx.
Here are the problems with Zcash as I see them
1) trusted setup. There is some toxic seed data that needed to be destroyed at the time Zcash was created. With that seed you could inflate the coin as much as you want. There was an elaborate ceremony of 6 people (5 of them Zcash employees) showing the seed was destroyed. But elaborate ceremony isn't cryptographic proof.
2) privacy is optional. If a transaction goes from non-private address, to private address, to non-private address it is traceable. The Zcash anonymity set is actually very small.
3) Zcash is a company. I consider the political structure of a coin (or lack thereof) as an attackable surface. A government can force Zcash to back-door their software (hi NSA). There is no head of Monero.
On 3: How many people must agree in order to change something in Monero such as HF parameters like ringsize? There is not a single company but it looks [to an outsider like me] as a similar position.
I chose Monero too for similar reasons inc ZCash people openly saying they support backdoors for LE [but promising ZCash would never have them]. And taking 20% of block reward and not doing anything useful with it [for millions I expect really polished clients and some quick upgrades].
But the low ringsize is weak [hence going from 3 to 5 to now 7]. All ring members are not equal to n^k is very naive. Fee, ringsize, payment ID, in/out count are all metadata that distinguish on-blockchain. Let alone off-blockchain such as keys being hacked/warranted.
Given this and Monero's lack of disclaimer or warning at all about how to use it safely... a paranoid person might suspect ill-motives. [Consider: MyMonero, the Monero 'lead' Web Wallet, goes out of its way to suggest users use a few higher ringsizes to get better privacy, when we know this makes their TX stand out. This is something that presumably he could change with 1 or 2 lines of code but has not.]
That's actually a difficult question. I won't try to estimate here. But IIRC something like 95% of ZCash tx are non-private by user opt in, and the remaining 5% are also vulnerable to things like warrants at the exchange and timing attacks. So the bar is set really low for Monero to have the best anonymity set of all privacy tokens.
>On 3: How many people must agree in order to change something in Monero such as HF parameters like ringsize? There is not a single company but it looks [to an outsider like me] as a similar position.
I think Monero is in a similar-but-better position. True the core team can be compromised and true the core team is more powerful than others. But I view this as a necessary centralization to get the ball rolling. I want the Monero core team to eventually be more hands off. Spagini's "I'm not a CEO" statement inspires confidence.
>But the low ringsize is weak [hence going from 3 to 5 to now 7].
can't wait for bulletproofs!
>All ring members are not equal to n^k is very naive.
I was intentionally very cautious with my words here. What I actually said was "Over the course of k steps the possible transaction history might be in any of n^k states". I did not say that all n^k states are equally likely. The actual amount of entropy in the Monero blockchain is much harder to explain/estimate so I used n^k as an upper bound.
I was under the impression that no exchanges handle shielded transactions. What do you mean by timing? I would assume you go t-z-t and leave it quite a while as shielded.
>can't wait for bulletproofs!
Bulletproofs do not help verification time which is why we have low ring size. Going from 5 to 21 ringsize only increases size 8%. 15 is even less, a reasonable compromise on size. There is an unspecified perf target that must be met on verification.
Many people skip the "leave it a while" step.
Also you can look at things like x-amount left this exchange and y-amount entered this exchange.
Huh? Doesn't that contradict https://blog.z.cash/the-design-of-the-ceremony/ ?
I'll admit I'm biased: I worked a bit with Zooko and Nathan (Wilcox), pre-Zcash, on some other security audits. My experience was that making the client look good is really not a consideration. Phrase your findings neutrally and informatively, yes; but you earn your rep by being as creatively nasty as you can at breaching the system.
Not to argue against evaluating claims skeptically -- just to state my most important disagreement.
I have the same problem with Signal, it tries to be 'seamless' in it's integration with SMS. But now I could be talking to someone on Signal who also uses Signal so the communication is secured, but if they don't, Signal just sends messages as an unsecured SMS (though it shows you on the app with a slight UX tweak that this is an unsecured communication channel, but that's not good enough).