I take it that a person just finds a few random strangers' public keys with previous history, and gives them signing power over the coin. Those strangers just have no way of knowing they have signing power because the ring is represented in the unspent coin by its hash. Is that correct? In order to spend a coin, however, the ring needs to be revealed. How is the race condition resolved where those strangers could see there's a pending transaction for a coin they could spend. Can't those strangers just see the transaction and pay a huge mining fee to jump the queue and spend the coin first?
Zero-knowledge proofs/cryptographic accumulators are used to verify each coin is spent at most once. Any of 11 coins could have been spent, each owned by a different single key.
For some reason, I thought Monero was basically ZCash plus using ring signatures to make traffic analysis much more difficult even if the zk proof system were broken. I was completely mistaken.
Edit 2: Sorry droffel, I wasn't fast enough editing away my old understanding of how it worked and asking what I was missing. Thanks for the explanation.
The ring signatures are used when spending an output. For minting an output you essentially just spend to a single public key.
When spending an output, you pick 10 other outputs (at random from an age-based distribution so the age of a ring-member does not say much) and you produce a ring-signature saying "I have the key to one of these 11 outputs". They combine this with Pedersen commitments to ensure that you are not spending more than you are minting, without ever revealing the total amount of the transaction.
In older versions of Monero, you would pick a few (rings were smaller then) outputs of the same amount, and the amounts were hidden.
> The Babuk group said on its website late Monday
I don't think they care about it being untraceable, they can dump it on a non-US exchange, they probably care about it being un-censorable.
That said, the article doesn't mention if they want the payment in crypto (presumably they do).
Bitcoin, for example, doesn't claim to be an anonymous payment system.
In addition there is no 3rd party verification of the wallet owners so in practice there is plenty of ways to whitewash dirty bitcoin into clean currency, especially in economies with an large black/gray sector.
Add to that that any international investigation into cyber crime becomes an instant political hot potato due to the prevalent political rhetoric around state sponsored actors and you have an environment where the treat of actual capture/punishment is extremely low.
And because none of the wallets aren't accurately linked to real persons all tree actors in the above transaction could be the same entity with 3 distinct fictional personas.
Add to that that the former soviet block is littered with regions where nobody really agrees on who the legitimate government is and where the entire economy happens using foreign currency, there is plenty of ways to deliberately block investigations from simply following the money trail.
"CoinJoin requires multiple parties to jointly sign a digital smart contract to mix their coins in a new Bitcoin transaction, where the output of the transaction leaves the participants with the same number of coins, but the addresses have been mixed to make external tracking difficult."
For example, the service Whirpool [2] cycles users' Bitcoin numerous times; the end result is one which can be interpreted 1,496 different ways.
Wouldn’t the simple solution be tagging coins that exited such a tumbler?
Perhaps. But the legal precedent is for laundered money to be tainted per se. The laundering itself taints the cash independent of any preceding criminality.
If I have an output of 1 BTC, and I want to send you 0.3 BTC, then that 1 BTC gets split up in 0.3 and 0.7BTC the 0.3 goes to your address, the 0.7 goes to a new address belonging to me. If that 1 BTC was "known bad" is the 0.3 BTC now also "known bad"? Also, for the outside it is a guess whether the 0.3BTC or the 0.7BTC transaction was my "change".
You cannot fully trace every transaction. You can just find every other transaction it was linked to. That list grows somewhat big.
I am curious about this. If Uncle Sam serves Coinbase notice that it considers the contents of XYZ wallet to be stolen goods, then haven't they created lower-value coloured coins, and won't other exchanges start creating lists of those pretty quickly?
There are ways around this on BTC that do not require protocol changes. For example, you can use a coin mixing service like whirlpool to essentially `wash` your BTC. However, this solution is incomplete unless everyone agrees to use it and in doing so `taint` their own BTC supply.
> "If we are all using stolen BTC then none of us are."
The proper way to fix this is with a protocol change as mindslight said. This already exists in a half-way form called ZChash. This is a fork of the BTC blockchain that updates to protocol to allow for `shielded` transactions. These protect anonymity and, I believe, transaction amount as well.
However, ZChash only gives the option to perform a `shielded` transaction. Most transactions on the ZCash blockchain do not utilize this function since it is slower than a standard BTC transaction.
The actual proper implementation of `shielded` transactions that I know of is called PirateChain.
LEOs pay millions dollars yearly to have firms do this type of white hacking of using key collisions to unmask crypto coin users.
If you use Google you can find the more than 20 firms that offer their services to LEOs to do this.
Key size was based on number of users not number of transactions big mistake!
Permanently kill illegal addresses.
Yes crypto is theoretically decentralized, but in practical terms it is remarkably centralized - very similar to the Internet’s supposed decentralization.
There would be a limited black market but the value of crypto coins would fall to nearly zero. Certainly crypto would be much less attractive as a means of transferring illicit money.
Humans want what they cannot have and the government saying you can't have crypto would be the ultimate sign you need crypto. See India and China "bans" on crypto.