Chainalysis: A startup that helps governments trace crypto
bloomberg.com
bloomberg.com
* Bitcoin lightning transactions when the lightning nodes involved are trusted to not keep logs
* Transactions through mixers with a lot of users
* Monero transactions
* Zcash private transactions
And everything is de-facto traceable except:
* Tornado cash users who use standard-size amounts (or users of another equivalently large smart-contract-based mixer)
* Monero users who are careful about their entry/exit
Zcash privacy doesn't have enough users for anonymity, most mixers are too small, and lightning users generally use nodes from exchanges which do log a lot of information that isn't kept on chain.
Am I missing anything? This seems kind of bad for cryptocurrencies in general if everything is basically traceable.
ZK based privacy was possible and working fine for many users through TC before the sanctions. Now it is risky as you may end up with locked funds or in jail for seeking privacy.
Edit: Should also mention Aztec and Aleo. These are working currently but in the same position that TC was before its sanctions. Hard to know what regulators will do as these tools allow for absolute privacy which is antithetical to the US government’s goals.
This is simply not going to happen in the current anti-money-laundering environment. The US made Switzerland give up hiding money, they're not going to let some random geeks make trillions of dollars vanish.
i've heard this sentiment conveyed in the crypto space since 2011... still waiting on this prophecy to come true.
Due to incompetence, profit motive or traitors to their country, who can tell the difference? (Paraphrasing Robespierre here)
Want to purchase an ENS name without corporations and the US government having clear knowledge of it? Too bad, the US government will not allow that. The privacy that we enjoy wish cash purchases will erode as we continue down the path of stripping away privacy in digital transactional systems.
AFAIK ring signatures hold. It's like a mixer on every transaction so trying to track more than a few transactions back, the complexity explodes.
TL;DR Ring signatures, like all sender-obfuscation methods, have a limited anonymity set: it limits you to a pool of possible senders. If Alice frequently sends funds to Bob, who frequently sends funds to Carl, who frequently sends to Alice, she can see that Alice->Bob->Carl->Alice is one possible outcome. She does this because she can trace the coin she associates with Bob to a coin she associates with Carl. There is a ton of plausible deniability at first, but the relationship between Bob and Carl becomes more obvious the more Alice->Bob->Carl->Alice continues to happen.
Alice can be multiple exchanges collaborating using KYC.
How to resist poisoning: limit your risk, churn, bigger ring-size/anonymity set, do atomic swaps (this severs chain of ownership, but is not generally sybil-proof), do multi-output transactions if you are sending to multiple people at once who can co-ordinate (this reduces the number of coins they can co-ordinate).
Reference: https://github.com/lightning/bolts/blob/master/04-onion-rout...
It seems an obvious target to be a Trojan horse in the midst of criminals and tax-evaders.
I suspect that most monero black markets are taken down by sting operations. The black markets all have a limited shelf life and these days they tend to intentionally retire before getting "silk-roaded"
The original btc had a networked pokergame along with the wallet, but was taken out for a couple of reasons, including regulatory issues.
I'm not saying parent is right, or wrong but to dismiss it and to speak for the core team out of hand is folly.
First, it isn’t easy technically. Especially back when you’re designing the very first decentralized cryptocurrency and have no prior experience informing your design. ZCash, Monero, MimbleWimble and others came later after learning from Bitcoin, and there’s zero chance they could have come first.
Second, shielded transactions risk undetected inflation bugs, which actually happened to ZCash some years ago.
Third, Bitcoin was designed shortly after the Liberty Dollar founder was arrested and jailed, and everyone in Bitcoin was concerned about that too, including Satoshi. He may have decided just not to push his luck.
https://satoshi.nakamotoinstitute.org/quotes/privacy/
https://bitcointalk.org/index.php?topic=770
It seems like satoshi thought pseudo-anonyminity was sufficient. The integration of zero-knowlege proofs into cryptocurrencies was not really well understood at the time.
Being anonymous to the 'Real world' but carry an identity in the "BTC world". Wallets, mining, interactions are all public within the network and significantly contributed to it's 'Community', 'make btc wallet size go up', and increase account nonce with use.
Early in the community, these metrics where your 'leaderboards'.
BTC never was anonymous, but rather a 'seperate idenitity'.
The transparency of the ledger is key to the censorship, control, and abuse of the network.
>open source
Are you implying that the cryptonote/zerocoin projects like monero aren't open source?
>we could just iterate on existing ones, and have our userbase intact without having to 'gain traction' for an entirely new alt-coin.
I think there are some fundamental limits to the throughput of a single cryptocurrency due to network latency and bandwidth. Perhaps the solution to scalability is simply to have multiple cryptocurrencies and to facilitate atomic swaps between them. So in this sense, the creation of new cryptocurrencies with minor feature changes (litecoin, bitcoin cash, wownero, cheapeth, etc.) is actually good for network diversity.
That being said, the owners of existing "big" cryptocurrencies will usually want to make changes that increase its usability to compete with these "trivial forks"
Bitcoiners have been soured by the idea of a hard fork since the XT dispute, while the monero userbase has commited itself to regular hard forks every 6 months to upgrade the network.
1. e.g. what happens if a large exchange's records leak / are subpoenaed, a criminal group being compromised by law enforcement, etc. means that a fair fraction of a mixer's transaction volume at a particular time can be identified, making it easier to focus on the remainder?
Bitcoin transactions that use CoinJoin (e.g. Wasabi Wallet). https://en.bitcoinwiki.org/wiki/CoinJoin
> is a very effective decentralised Bitcoin mixer with many privacy-focused options
> provides possibly the most convenient and secure way to mix Bitcoins
[0] https://www.tbstat.com/wp/uploads/2020/06/Europol-Wasabi-Wal...
Similar tech to this could become standard on Ethereum L2s in the future after more optimisations.
I'm pretty sure withdraws from Ren darknodes are private as they come from the network itself and aren't correlates to your node.
Bitcoin as it currently exists will never be a replacement for fiat --- not even close --- for a multitude of reasons.
Individual lightning transactions are not recorded on the blockchain and are not subject to chain analysis.
Direct peers are only limited by channel capacity, and the biggest nodes (exchanges like Bitfinex) keep 5+ BTC public channels (could be much larger unannounced channels).
As far as routing larger payments across the network, the Loop service handles 1.2 BTC swaps today:
If you want untraceable, you can go out of your way to achieve that using something akin to tornado.cash
I think the point is that the technology is already here and available - it's just not evenly distributed yet.
A) A user picks the economically best peer to open channels with, or chooses peers randomly. Neither of these are sybil proof, which basically means you are transmitting your requests publicly.
B) A user only opens channels privately within a cohort of peers that privately agree not to keep logs, have special means of transmitting requests privately, etc.
I would assume that most users follow some of A's heuristic and some of B's. To the extent that situation B offers privacy, it prevents you from transacting with other users globally in a more general sense.
In other words, it is useful as a privacy mechanism only if you trust your peers not to keep logs, but don't trust them not to double-spend, and also you are not worried about guilt-by-association of owning a channel with these peers. If you were running some sort of dark net market or something, it would be easier to implement some sort of (cryptocurrency-backed?) chaumian cash, as you already implicitly trust the marketplace's sysadmin to some extent (as they can simply MITM your relationships unless you establish them by keypairs out-of-band (this is another sybil problem), which is probably more dangerous than double-spending).
Better yet, what prevents a lightning network operator from going rogue and draining your account to fund his retirement and then moving to Tonga?
Imagine the outcry if government suddenly announced that all your fiat bank transactions will be routed through small, unregulated 3rd party operators who can do as they see fit with them?
From day one anyone in the know with Bitcoin has said LN is a scam and/or completely pointless for the users.
LN is a way for big central authorities to lock away and control the assets of individuals, sounds like a bank right?
Amazing that such an obvious scam has gone on for so long and gathered so many "users".
Unless you mean signing up with strike or some centralized service in which case the old adage "not your keys not your coins" applies.
For example Bitcoin onchain transactions are routinely compared to Visa network - fairer comparison would also include transactions from lightning network and offchain transactions within services.
people aren’t warrant proof, the government is just used to a brief period of time where they could go to intermediaries instead of doing an actual investigation. this is just a reversion to the mean.
https://zeroknowledge.fm/246-2/
I'm not clear if the conversation concluded with zk is impervious, or whether it is an active question of research.
You might trace that the coins went into a laundry, but you will never associate with the previously laundered coins that the client got.
I, for one, am shocked that moving decentralized currency to a centralized service that knows your identity de-anonymizes said currency.
I don't like the way any of these companies encourage authorities to impose requirements for KYT, but it's unsurprising.
There are many, relatively simple, models to do that in real time. Wouldn't the market appreciate this?
sorry, federal government. Keep up
Almost every cryptocurrency with sender-obfuscation features bumps up against "poisoned output" attacks for low enough anonymity sets: https://www.youtube.com/watch?v=iABIcsDJKyM
But it is good enough for many purposes. The goal is to provide a high level of plausible deniability for the sender.
I sure was.
I'd be surprised if there aren't any. Any large-scale criminal action can be strategically simulated and analyzed on those to make these guys' job harder up to the point that it's no longer feasible for many situations.
(clarification: while I do not support any criminal action, I equally hate government survelliance)
It's called Ballet and it's open source, too!
- Quick demo video: https://www.youtube.com/watch?v=7hnNzSf2-Ak
- Live application: https://alexisrondeau.me/algorand-ballet/
- Github repo: https://github.com/akaalias/algorand-ballet
Chainalysis in Action: Justice Dept Demands Forfeiture of 280 Crypto Addresses - https://news.ycombinator.com/item?id=24306511 - Aug 2020 (54 comments)
There's XMR, some interesting little projects like DERO, and a vast sea of tokenomic pyramid scheme garbage that governments can and should stop.
Can I get this on a t-shirt? I have no idea what it means, but it sounds amazing.
https://www.buzzfeednews.com/article/katienotopoulos/you-can...
Specifically U.S. and protectorates right?