As for Zcash and Monero, yes, these are sensibly some more anonymous cryptos, still nothing as anonymous as some simple bank notes .. :-)
Btw, when I see the amount of people thinking that Bitcoin is used (nowadays) for illegal activities, and commenting about it on HN (which has theoretically a more educated audience), this is mind-blowing how little Bitcoin is understood at the moment. It feels like our governments have made a really good job of disinformation
How about buying food and paying bills?
https://news.ycombinator.com/item?id=25797143
https://news.ycombinator.com/item?id=25889590
https://www.coindesk.com/bitcoin-adoption-venezuela-research
> By and large, this is true in Venezuela. Expats use bitcoin to send remittances back home, where locals convert it to bolivars to buy food and pay bills. With crypto remittances from expats plunging, peer-to-peer cryptocurrency transactions within the country have proven resilient. LocalBitcoins and Paxful trades using bolivars peaked in the first half of 2019, and have since hovered around $20 million.
> “People living in Venezuela are living under a very unstable and predatory government. They suffer from extreme inflation and general economic instability. And here’s a censorship-resistant, inflation-proof asset, so it’s very attractive to people who are looking for a way to maintain value,” said Andrea O’Sullivan, director of tech and innovation at James Madison Institute, a Washington think tank.
Speculation is one thing, but BTC is going nowhere and in a world hit by an incoming significant inflation, many have understood that Bitcoin is simply an easy place where to safeguard your wealth if the outlook is at least +5 years, not days / months. That's why people buy Bitcoins at the moment.
Who would have thought that the ARPANET would be the basis for today's Internet.. and still, here we are..
But, there is a string attached. Who knows whether a genius will not have found a solution in 6 months?
One thing is sure, if you buy some drugs with some bank notes, that's not the bank notes which will betray you. If you're into any kind of (highly) illegal activity, Monero is not bad, but bank notes are just safer.
Then again, they dont need to provide privacy, just the preception thereof.
(I stopped paying attention to cryptocurrencies a while ago. My opinions may be outdated)
Also, there are a number of projects coming on line using the same privacy tech. Good privacy is feasible, we have the technical protocols. But product-market-fit niche isn't entirely there yet: the problem is few people grasp then need for on chain privacy yet.
But it's at least possible if the tech works. So I guess my view is: at least someone has a shot.
There's even a draft spec for doing it for Zcash. https://github.com/zcash/zips/pull/420/files#diff-635022fa4a...
Can you provide some link to back this up? I am genuinely interested because in principle public ledgers and privacy seem to be antithetic to one another.
Here's Greg Maxwell (one of the Bitcoin core team members) explaining the confidential transactions.
https://crypto.stanford.edu/bulletproofs/
Here's an optimization used in Monero that optimizes the ledger size (initial confidential transaction proofs were too large).
You can have a public ledger but all of the data in it is encrypted and verifiable.
Each transaction, from the creation, to validation has its amounts and wallet ids hidden, the sender and the receiver cannot know anything about wallet contents of each other and receiver has no idea from where the sender is sourcing the coins.
This anonymity depends on encryption to hide the wallets & transaction, and decryption to verify it, and for the receiver to be able to use the funds in the future.
So, who/what controls those keys? Seems they've just exchanged an open ledger problem for a key management problem - why is this not the case?
The key insight is that you design a cryptographic algorithm that will preserve addition between amounts, even when encrypted but you need to also provide some encrypted data that will allow an independent verifier to validate the whole transaction.
The problem is more nuanced because you need to guarantee that coins aren't produced from thin air.
The problem of the approach in the linked article is that proofs are large. To support encrypted verification (there is no need to decrypt anything in any step of the process) you need thousands of bytes for verifying a 32-bit amount.
Bulletproofs reduced the proof size significantly. There are then additional approaches like MimbleWimble where the proofs on the ledger can be discarded to make it even smaller.
Start reading this paper above then, it goes from the simplest form to data optimized form.
Three years and much work by others later, it takes ~2 to 3 seconds on a Pixel three to make a zk-proof for a payment. This can be optimized down to 1 second fairly easily (on that you have only my assertion currently)
This is commercially deployed in Zcash (the above mentioned coin with usability and adoption issues), a few other straight up forks, and a new coin called IronFish. And related protocols are in a few things on Ethereum (e.g., Aztec). If you want to test performance numbers, you can download one of these systems and try it yourself (Nighthawk is a decent mobile wallet for Zcash)
Current technical objections (again, beyond criticisms of Zcash as a coin itself) 1) Current ZK proofs require trusted setup. New ZK proofs developed by engineers at Zcash removed this[1]. So its not longer an issue for the technology (or for Zcash once it's deployed)
2) you have to scan the blockchain to get notified of payments. No, this happens to be how Zcash does it. As I said in a separate comment, it's easy to send payment notifications out of band.
3) Vague objections about "scale." Even though zksnarks take a second or two to prove, they are very fast to verify. So adding privacy doesn't make blockchain's scaling problems worse. And the privacy tech is agnostic to the underlying consensus layer, so if you ever get a blockchain to scale, you can put privacy on it.
4) Other approaches(Monero/RingCt/Coinjoin) are better. The major problem is these don't offer strong privacy, just obfuscation. See [2] if you want a 20 minute talk on the issues or [3] for a blog post covering the same
5) There's an inflation risk. Yes, once you hide the values of a payment, because you want privacy, if the crypto breaks, things can go wrong. This is true of any serious approach to privacy. So you want to very carefully vet the crypto design. But if you don't hide payment values, you get no privacy and your blockchain is twitter for your bank account.
[0] https://www.cs.umd.edu/~imiers/pdf/zerocash-oakland2014.pdf [1]https://electriccoin.co/blog/technical-explainer-halo-on-zca... [2]https://www.youtube.com/watch?v=9s3EbSKDA3o [3]https://www.zfnd.org/blog/blockchain-privacy/
It is shown everywhere that it does not work. This due to human nature, timing analysis, lack of censorship resistance and lack of fungibility.
Can you elaborate on why you say this and what you mean by it? From what i've seen no entities, including governments, have been able to crack Monero's privacy, so i'm pretty interested if there's an obvious flaw.
The initial version of Monero had a flaw but if you start transacting now I do not believe anyone can deanonymize wallet ids or amounts.
Even if there's a 51% takeover, those guys would just be able to mint new coins, they still wouldn't be able to see the amounts and wallet ids.
Also, confidential transactions and optimizations (bulletproofs) are math proven.
Zcash and Dash with their optional privacy just leave everyone vulnerable to deanonymization.
Hard to do that if the crowd is all criminals lol. I often say BTC is only used for speculation and crime. At least the criminals in BTC can hide among the speculators. Zcash and Monero are literally only used by criminals and a handful of die hard ancaps. That gives you nowhere to hide.
It's the equivalent of trying to cash out El Chapo Bux. Simple possession is enough to pretty much guarantee anyone looking you've been involved in one crime or another.
The thing about the law is, as Lavrentiy Beria (Stalin's head of the secret police) said, "You bring me the man, I'll find you the crime." Once someone's looking at you, it's too late.
Pretty much all countries still have presumption of innocence and a legal system
The ownership of the monero itself may be granted the presumption of innocence however if you have a bunch of El Chapo Bux they'll just start digging for other things.
[1] https://www.wsj.com/articles/SB10001424052748704471504574438...
IMO The whole world has gone mad with the need for surveillance of everything.
Luckily, they can't really do that, since people would be able to poison an arbitrary BTC wallet just by sending them a quantity of BTC laundered via monero. But it'd be a pretty expensive poison pill.
Right now, you can probably do that without being sent to prison. It's a matter of using one of the many conversion websites to go from XMR to BTC, then depositing to your exchange and selling it. (I don't know how you'd explain it on a tax form, but maybe you can think of something clever.)
But if exchanges start actively cracking down on any account that deposits BTC in response to XMR transactions (i.e. the exchange maintains a known list of wallets used by those conversion websites), they can start putting accounts on hold if those accounts have received large quantities of BTC from any of those XMR-related BTC wallets.
Also with the lightning network you can mix and change different crypto currencies, and it can be really hard to trace the provenance of the coins. Not something an exchange can do automatically.
> the exchange maintains a known list of wallets used by those conversion websites
Remember that new wallet can be created for each transactions. So even if they'd try to do that, it wouldn't work.
Most wallets aren’t used for any high volume transactions; most account holders at Coinbase have no need for that. So it’s certainly possible to map out the network and partition it into known good / known bad categories, and handle the middle ground manually.
In other words, yes, XRP is very clever. That’s not the problem. The problem is, you’ll someday find it very hard to convert large quantities of XMR to USD without risking jail time.
You can't do this sort of analysis on the XMR blockchain. Can't see who's actually sending or receiving money. Can't see the transaction amounts. Can't see how much money any given wallet contains. Can't taint coins by association with criminal activities. Without exchange metadata it's impossible to correlate transactions with any certainty.
There's essentially nothing that can be done about it. Will governments become oppressive enough to jail people for the crime of using a medium of exchange they can't control? I'm not even sure that'd be enough to stop it.
Suppose I want to map an XMR->BTC converter.
I sign up for the converter, and say "Here's some XMR. Give me BTC."
At that point, some BTC wallet gives me BTC. I now know which wallet is being used by the XMR converter. And I know all the other metadata as a result.
When I accept these 'tainted' BTC tokens, they might get blocked by others parties.
So even here, XMR has a real benefit since those tokens are really fungible.
The question will indeed be if it can live together with the economy, or beside it.
This is the original cryptocurrency dream. Monero is the only coin that has a shot at actually achieving this.
1 Satoshi is only $0.0006 USD plus the transfer fees... which is pretty low on the lightning network
If you're worried about the code changing, you can run e.g. ETH nodes yourself, download the DEX frontends, and run the DEX locally.