Also, Zcash has optional privacy.
On the other hand, the decoy based privacy protocols Monero uses are not really private at all. https://slideslive.com/38911785/satoshi-has-no-clothes-failu...
Its cryptocurrency, everything is tribal.
No one else as done the same tech yet themselves. A few things have launched and allegedly plan to add a privacy layer (Mina, Celo). But actually building that kind of tech is a lot harder than reputation management or standard blockchains.
It's still an open playing field.
This is simply not true, otherwise you should present real evidence. It is not perfect, but nothing ever will be, and Monero continues to move forward and use the best technology available. Research continues, and they hope to move away from "decoy based protocols" altogether eventually, but the tradeoffs have so far been too great. Unlike bitcoin, it is able to do large changes, since there is a completely different development culture
Can be read as: a 'relatively' small group of people control the protocol to such a level that arbitrary changes can be enacted with relative ease.
An example that comes to mind is Ethereum, which is essentially controlled by a single developer aided by a few others. When a bug in a contract would have cost many people a significant amount, the lead developer lead the charge (to the applause of almost all) in forking the chain.
I haven't looked at Monero in enough detail to confirm this, but your statement is not exactly a selling point. Having decentralization to the point that it becomes hard for developers to force through changes, should be a feature... not a bug.
>Having decentralization to the point that it becomes hard for developers to force through changes
This is happening to Monero too over time, as the community grows. I expect it will continue to become more difficult to gain consensus over time. There is, at least, many developers and no 'leader' figure like Vitalik
It's also designed in a way to allow "poison pills" - i.e. those in control can force a single transaction on a block, thus giving a vector to deanonymize someone.
You may ask, "Who would do something like that?" and the answer would be the U.S. government who can compel privately owned organizations via secret court subpoenas. Monero is more private than ZCash, and has a record of not acting on self-interests.
The developers were funded by suspicious government organisations including DARPA and Israeli Ministry of Science and Technology.
It is centralised, with an organisation receiving significant coins directly from the protocol.
Opt-in privacy defeats much of the point and creates traceability issues - privacy needs to be the default for people to use it, for their coins to not be treated suspiciously if they turn on the privacy feature, and it is a requirement to have a large anonymity set.
Among other reasons, there are many...
Another issue with Zcash is that it had a trusted setup, which is not an issue Monero has.
That's not a true statement as far as I understand how Zcash works. Right now there are >742K ZEC in the shielded Sapling pool, so there are quite a few people using it and you can not tell their shielded transactions apart.
https://electriccoin.co/zcash-metrics/
> Another issue with Zcash is that it had a trusted setup, which is not an issue Monero has.
Yes, but they took a number of steps to make sure that the ceremony for creating the trusted setup discarded the keys used and there was no one listening in. (they were geographically distributed and destroyed the hardware)
https://www.wnycstudios.org/podcasts/radiolab/articles/cerem...
Skip to around 36 minutes for that.
Halo Arc removes the trusted setup and also sets shielded transactions by default.
ECC also has announced that they intend to work on implementing shielded assests which seem compelling: https://electriccoin.co/blog/zsas-ecc-progress-and-next-step...
One glaring issue is that there seems to be lots of tension between the community and the Zcash foundation (wrt power control).
What I mean by this is that transactions in Monero are always private, while users of Zcash can choose to send public transactions. What this does is it makes the group of users who send private transactions through Zcash much smaller and far, far more susceptible to being identified through metadata and process of elimination.
This is heavily simplified - and Monero community members would be happy to get into the weeds with you about it if you were to visit their realms on the web, I'm sure.
zcash is shady
Little touches like that keep making me reconsider the project in a favorable light.
If the whole network private, then the privacy faults can only happen at its boundaries--which are places that the protocol designers have less control over. The alternative is having to wonder about what kind of identifying metadata the exchanges are leaking--and they're an easier target for an adversary.
Also, I have to imagine that the everywhere-private nature of XMR is why I don't see it on my exchange's list, while I do see ZEC there.
But I wasn't talking about that. With zero-knowledge proofs protecting the shielded transactions, your anonymity pool is essentially the entire set of people that use shielded transactions. With the Monero approach, your anonymity pool is large, but it's still a subset of the whole network.