Being on the Monero team, can you comment on the differences between the privacy guarantees provided by the two platforms?
Being on the Monero team, can you comment on the differences between the privacy guarantees provided by the two platforms?
Monero uses ring signatures to prove that one out of n people signed a transaction without revealing which one of the n. Over the course of k steps the possible transaction history might be in any of n^k states. Typically n=5.
Zcash uses Zero-Knowledge-Proofs for anonymity. Any private zcash tx may have gone to or come from any other private zcash tx.
Here are the problems with Zcash as I see them
1) trusted setup. There is some toxic seed data that needed to be destroyed at the time Zcash was created. With that seed you could inflate the coin as much as you want. There was an elaborate ceremony of 6 people (5 of them Zcash employees) showing the seed was destroyed. But elaborate ceremony isn't cryptographic proof.
2) privacy is optional. If a transaction goes from non-private address, to private address, to non-private address it is traceable. The Zcash anonymity set is actually very small.
3) Zcash is a company. I consider the political structure of a coin (or lack thereof) as an attackable surface. A government can force Zcash to back-door their software (hi NSA). There is no head of Monero.
On 3: How many people must agree in order to change something in Monero such as HF parameters like ringsize? There is not a single company but it looks [to an outsider like me] as a similar position.
I chose Monero too for similar reasons inc ZCash people openly saying they support backdoors for LE [but promising ZCash would never have them]. And taking 20% of block reward and not doing anything useful with it [for millions I expect really polished clients and some quick upgrades].
But the low ringsize is weak [hence going from 3 to 5 to now 7]. All ring members are not equal to n^k is very naive. Fee, ringsize, payment ID, in/out count are all metadata that distinguish on-blockchain. Let alone off-blockchain such as keys being hacked/warranted.
Given this and Monero's lack of disclaimer or warning at all about how to use it safely... a paranoid person might suspect ill-motives. [Consider: MyMonero, the Monero 'lead' Web Wallet, goes out of its way to suggest users use a few higher ringsizes to get better privacy, when we know this makes their TX stand out. This is something that presumably he could change with 1 or 2 lines of code but has not.]
That's actually a difficult question. I won't try to estimate here. But IIRC something like 95% of ZCash tx are non-private by user opt in, and the remaining 5% are also vulnerable to things like warrants at the exchange and timing attacks. So the bar is set really low for Monero to have the best anonymity set of all privacy tokens.
>On 3: How many people must agree in order to change something in Monero such as HF parameters like ringsize? There is not a single company but it looks [to an outsider like me] as a similar position.
I think Monero is in a similar-but-better position. True the core team can be compromised and true the core team is more powerful than others. But I view this as a necessary centralization to get the ball rolling. I want the Monero core team to eventually be more hands off. Spagini's "I'm not a CEO" statement inspires confidence.
>But the low ringsize is weak [hence going from 3 to 5 to now 7].
can't wait for bulletproofs!
>All ring members are not equal to n^k is very naive.
I was intentionally very cautious with my words here. What I actually said was "Over the course of k steps the possible transaction history might be in any of n^k states". I did not say that all n^k states are equally likely. The actual amount of entropy in the Monero blockchain is much harder to explain/estimate so I used n^k as an upper bound.
I was under the impression that no exchanges handle shielded transactions. What do you mean by timing? I would assume you go t-z-t and leave it quite a while as shielded.
>can't wait for bulletproofs!
Bulletproofs do not help verification time which is why we have low ring size. Going from 5 to 21 ringsize only increases size 8%. 15 is even less, a reasonable compromise on size. There is an unspecified perf target that must be met on verification.
Many people skip the "leave it a while" step.
Also you can look at things like x-amount left this exchange and y-amount entered this exchange.
Huh? Doesn't that contradict https://blog.z.cash/the-design-of-the-ceremony/ ?
I'll admit I'm biased: I worked a bit with Zooko and Nathan (Wilcox), pre-Zcash, on some other security audits. My experience was that making the client look good is really not a consideration. Phrase your findings neutrally and informatively, yes; but you earn your rep by being as creatively nasty as you can at breaching the system.
Not to argue against evaluating claims skeptically -- just to state my most important disagreement.
I have the same problem with Signal, it tries to be 'seamless' in it's integration with SMS. But now I could be talking to someone on Signal who also uses Signal so the communication is secured, but if they don't, Signal just sends messages as an unsecured SMS (though it shows you on the app with a slight UX tweak that this is an unsecured communication channel, but that's not good enough).