Signal's tying encrypted messages and phone numbers to a publicly available ledge of transactions?
It’s like how you can’t charge someone with possession of cocaine because there’s cocaine on the US dollar bills in their pocket: there’s actually trace amounts of cocaine on every US dollar bill.
It says that no particular individual made a Bad Guy payment, but that all of them facilitated it by providing cover noise.
The problem is that transacting with a darknet market will still bring your illicit output % above average. Right now monero has 10 decoy outputs per transaction. If the proportion of illicit addresses to legitimate addresses were 50%-50%, then a legitimate transaction would have an average of 5 illicit outputs but a illicit transaction would have an average of 6 illicit outputs. The same applies to inputs. The difference between 5 and 6 might be small enough to be indistinguishable from background noise, but that result is heavily dependent on the proportion of illicit vs legitimate address. If the proportion is something like 95%-5%, then the difference would be 0.5 vs 1.5, which is significant. I won't bother to do the probability calculations for this, but I'm going to estimate you can get to 95% certainty within 10 transactions.
>It’s like how you can’t charge someone with possession of cocaine because there’s cocaine on the US dollar bills in their pocket: there’s actually trace amounts of cocaine on every US dollar bill.
The interesting bit is that they don't have to charge you based on that alone. If they're 80% sure you bought illegal drugs, they'll either get a warrant to search your house or perform surveillance on you and wait for you to slip up.
Though also, you’re assuming a constant “your account” in the above. If you mix 100% of your holdings every time you transact, setting it so that a set amount goes to a darknet market, and the rest goes back to a newly-created public-key-hash that you just generated the keypair for — and then when you want to use money from that address, you fully consume it to mix it again — then nobody ever gets the opportunity to fingerprint “your” traffic. There’s no stable “you.”
(I have a theory that this is the goal Satoshi was aiming at with Bitcoin UXTOs, but never finished that element of the design, and launched it half-baked.)
This also means that the mixer gets to eat a percentage fee off of your complete holdings every transaction, so it kind of sucks, but what can you do.
https://steemit.com/monero/@sgp/7yjqso-a-monero-introduction...
(This is basically what already happens if you do a “network version upgrade” on a Cosmos-based network: everyone keeps their balances, but just in the form of a new genesis block that all the nodes from the previous generation of the network separately deterministically generated from the state, but which new nodes have to just trust. If you join the network during the new generation, you just download the new genesis, and so can’t “see back” past that point.)
Just make the whole network do an automatic “network upgrade” every block — and keep all the state in-memory in the meantime — and now you’ve got a blockchain with forward secrecy.
(To be clear: nobody’s done this yet.)
Think about physical replication in a DBMS: you only need to transact with the master. Physical replication receivers don’t see logical TXs; they just see the new state (= WAL segments) that the master decided on.
Of course, in a Proof-of-Work network, the quorum could be anybody, so your OPSEC is “leaky” — it’s like having forward-secrecy enabled on a public chatroom that anyone can enter and sit in listening/recording.
But in a Proof-of-Stake or Proof-of-Authority network, the quorum only consists of the stakeholders. So, as long as the stakeholders all intentionally discard transactions, then there’s nobody to recover the data from. It’s very similar to private corporations whose service involves intentionally discaring (or avoiding logging) user interactions, e.g. “private” / “anonymous” email services. Just scaled into a federated, “open-but-audited membership” system. In such a system, network governance would likely declare that new stakeholders must have their infrastructure setup security-audited by auditors chosen by the existing stakeholders, at the new stakeholder’s expense, before being allowed to run as a validator for the network.