Mastering Monero: The future of private transactions [pdf] (2019)
masteringmonero.com
masteringmonero.com
No $20 transaction fees. No influencer pump and dumps. No VCs who need to extract value. No fork drama. No unrealistic roadmap. No charismatic leader boiling the frog with scope creep. It's not trying to be an investment. It's actually private. It's actually anonymous. This is all a lot of us ever wanted from a cryptocurrency.
LOL
> It's actually private. It's actually anonymous. This is all a lot of us ever wanted from a cryptocurrency.
Yes indeed. I sometimes daydream Satoshi knew about ZKP's early enough to integrate it into Bitcoin ... we would have had the perfect storm.
> No $20 transaction fees.
This one isn't a structural guarantee of Monero, but rather a side-effects of being a late-comer to the game. In other words, it might come to pass that tx fees get in the $20 range.
EDIT:
> This is all a lot of us ever wanted from a cryptocurrency.
Agreed, except maybe for this: I've come to value the finite supply of Bitcoin more than it's value/usefulness as an actual currency.
I initially loved the idea of cryptocurrencies as a currency that would be used in everyday life.
I've changed my stance on this completely: I think that Bitcoin (or something like Monero, with indeed a neat advantage over BTC) is way more valuable as a financial instrument with is own unique characteristics and super-sharp edges than it would ever be as a currency
I think finite supply is overrated [1] ...
[1] https://john-tromp.medium.com/a-case-for-using-soft-total-su...
Can't read SN's mind but I don't know if transactional privacy was a priority for him when developing bitcoin. One of the downsides of Monero's anonymity was that it quickly became a target of censorship so large exchanges like coinbase don't offer it anymore.
Before transaction fees increased, Bitcoin had a capability of enjoying a pretty good mixing feature that is now only practical with similar but lower fee proof of work cryptos.
I did confirm at least one store: 3% discount for BTC and XMR https://shopinbit.com/electronics/tablets-smartphones/tablet...
I'd still be a bit worried to use it to pay on a website that's not well known, as I assume you don't get disputes if the website doesn't deliver the service after you paid ^^
If you take away the "crypto services" and alike (600), you get around 700 businesses.
And to be honest, I like them a lot too because they're very fashionable and look great and are iconic. But I also don't want to spend $12k+ on a watch. And also in honesty, I always present it as a replica when asked about it and usually provide the above context where appropriate.
I have no issue supporting replica manufacturers because they always represent their merchandise as replicas, and I also have no respect for intellectual property and the ridiculous practices of legitimate manufacturers.
All this to say (admittedly defensively) that Monero is used often in buying replica watches.
A friend of mine has also used it to buy drugs online (which was sent to labs for testing before using).
I know youre getting frustrated with the vague responses, but that's really how it is, with all money, and Monero people are very hell bent on reminding anyone that asks about this.
You can check out https://monerica.com/ for a resource that lists services and goods and websites that accept it, not including the darknet ones, if youre into illegal drugs you'll have to find those yourself. Obligatory reminder that most illegal drugs are purchased with US dollars.
https://www.techtarget.com/searchsecurity/news/252512142/Ran...
In such an environment, being able to donate money with anonymity quickly starts to look like a political necessity. And being able to support people directly if the financial system is further activated as a political weapon (I suspect not much has actually changed, just the records are more easily available - but for the sake of argument lets say this is a new phenomenon that we happen to have also just developed a method for resisting).
[0] https://www.washingtonpost.com/politics/2022/09/08/biden-mag...
This is on how their use if Bitcoin didn't help, and here is one on where the money went
https://www.cbc.ca/news/canada/ottawa/freedom-convoy-donatio...
https://www.forbes.com/sites/thomasbrewster/2015/12/11/bitco...
https://www.vice.com/en/article/jpgq3y/satoshis-pgp-keys-are...
He is trying to use courts around the world to bully bitcoin developers into writing code that gives him 1.1 million bitcoin for free. So of course he'd like to spread the idea that governments have control over it.
Jesse Powell's point was not that governments can control bitcoin - it was that governments can control exchanges under their jurisdiction. Kraken cannot seize your coins if you keep them in self-custody. Kraken is not responsible for you - you are responsible for yourself.
I used it when originally trying jmp.chat out so I wouldn't have to worry about recurring charges/fraud etc.
I've bought some electronic components with it just to see it work.
The only strategies that can provide strong anonymity for on-chain crypto are full anonymity set currencies like Zcash.
> On June 8, 2020, Chainalysis added support for Zcash to their Chainalysis Reactor and "Know Your Transaction" (KYT) technologies.[22] This permits Chainalysis to trace and provide transaction values and at least the sender or receiver address for over 99% of Zcash activity.[22] Chainalysis explains that it is able to accomplish this since most Zcash users do not use privacy-enhancing features.
Bitcoin was never anonymous. It just took an incredible amount of effort to follow the transactions, along with subpoenas to exchanges, that even the shady exchanges gave into. Chainalysis are credited with bringing down the biggest criminals that tried to hide behind Bitcoin. Who knows if they have also cracked Monero, because there was a short while where people thought Bitcoin was safe before it was known that Chainalysis was already at their door.
People don’t want private transactions. All they want is those pumps and unrealistic roadmaps and charismatic leaders and investment promises. They want to dream of massive financial success, not to pay for coffee anonymously through a clunky UI.
Monero pre-dates dead drops?
Monero really is quite something. It is eye opening to realise there has never been a situation where one person could simply transfer wealth to someone else without anyone in the middle being able to say No. A powerful tool for liberty.
[0] https://www.getmonero.org/library/Zero-to-Monero-2-0-0.pdf
Well, this is what the promise of Bitcoin was, but the lack of anonymity in BTC missed the mark by a few inches.
Monero (and it's competitors: ZCash, Grin, Beam, MWC, ...), which IIRC uses the Mimblewimble [1] principle to preserve anonymity) bridged that gap a few years after BTC was launched, but by that time, Bitcoin had already grown to a huge size.
What I would really like to see in terms of innovation in the crypto world is Mimblewimble being actually added to BTC or ETH. Things would get truly interesting.
OTHO, if BTC and ETH had Mimblewimble, they might become a much bigger targets for folks that stand to benefit from controlling free economic transactions between people (governments, etc ...), so who knows, the lack of ZKP in BTC/ ETH might be a blessing in disguise.
This makes the latter two chains grow at a much faster rate [2] and leaves nodes unable to identify the UTXO set of unspent outputs, making them more resource intensive.
[1] https://electriccoin.co/blog/explaining-halo-2/
[2] https://forum.grin.mw/t/scalability-vs-privacy-chart/8114
John Tromp has a proposal for an interactive coin shuffling protocol for Grin [0] that would negate a lot of the privacy concerns, I personally haven't fully tried to understand it and it seems pretty cumbersome to me compared to Monero. I hope to see it in action so I can get an idea of how it compares.
[0] https://forum.grin.mw/t/mimblewimble-coinswap-proposal/8322
I believe the traditional tool for this is a suitcase full of either cash or jewelry.
Unfortunately, techniques to break Monero's anonymity have been known since 2018, and these techniques are effective at breaking essentially any partial-mixing based cryptocurrency. (Monero, Lelantus, CoinJoin, Wasabi, etc).
Initial attacks (famously The Flashlight Attack) were capable of breaking the anonymity of targeted individuals, but this attack was later generalized (by me) to break everyone.
These attacks never got a lot of coverage but they are highly effective. The only way to get strong on-chain privacy is to use a full-anonymity cryptocurrency like Zcash.
https://slideslive.com/38911785/satoshi-has-no-clothes-failu...
https://gist.github.com/DavidVorick/0dbd4906bfa50b7d8dba23f7...
The general idea behind each of these is that you can identify people by doing math that essentially asks "what is the likelihood that these N outputs are this close together in the transaction history graph" - and the answer ends up being "cryptographically unlikely" after just a handful of transactions from the same party. The privacy decays unexpectedly quickly. I never formalized the math but iirc you can get enough evidence to be convinced that two different transactions were by the same person after they spend something like 3 outputs total. The math is really nasty.
The only fix we know of is to switch to full anonymity systems. The privacy break is exponential in strength, and therefore even systems like Lelantus that use mixin sizes of >50,000 outputs fail to provide meaningful anonymity.
Formalizing the math seems very important to underpin a bold claim such as this one.
And why have you not collected your money?
https://www.forbes.com/sites/kellyphillipserb/2020/09/14/irs...
If what you write is true then please write the paper; it would be tremendously important. Until then it's impossible to take you seriously.
Now, just like cash wasn't built with digital transfers in mind, neither was Bitcoin built with anonymity in mind, so not sure why Monero would be better/worse than Bitcoin for a thing Bitcoin was never made for in the first place.
The purpose of Bitcoin was never that all transactions were anonymous. Monero is great for this (or zCash), but it's a bit misleading to say Monero is "better" at something when what you are comparing it to, was never built for that "something" in the first place.
For some definitions of "you"
Presumably it matters because the person you are replying to cares more about the less popular problem.
Other issues are opened up like the possiblity that a coalition of mining pools will censor transactions in the future.
Bitcoin has clearly failed at its originally intended purpose and monero is now what it wanted to be
In other words: everything you can do with Bitcoin can be done with Monero while the converse isn't true.
Strikes me as a pretty decent definition of "Better".
(unless of course, you consider the lack of anonymity a "feature". I'd bet most people don't unless they work in law enforcement or for the IRS).
[1] https://phyro.github.io/grinvestigation/why_grin.html
It's missing several of Bitcoin's features, such as an identifiable UTXO set, relative time locks, a fully auditable supply, instantly verifiable PoW...
You can audit Monero's supply as well. The only difference with Bitcoin is that it uses more advanced math, making it much harder for regular Joe.
Best take criticism from a self-proclaimed Monero competitor with some skepticism.
You're right though that technically Monero doesn't do everything that Bitcoin does.
Not to the same degree. If anyone knows or learns the discrete log of H, then they can create Monero out of thin air undetectably.
At real-world crypto recently the zcash people (MIT and Tel Aviv cryptographers) found a way to massively speed up the process of finding your balance (privacy chains are often very slow because they have to sum up all the transactions you were potentially involved in).
I also want to do a deep dive into light protocol - which is a privacy mechanism on top of solana, so transactions go at reasonable speed and you can use mainstream dapps (solana has the most amount of developers outside eth and is a lot faster and cheaper).
“The first two chapters of this book are friendly non-technical intro- ductions to key topics and skills. For readers curious to learn more about behind-the-scenes details, chapters 3 and 4 contain conceptual non-mathematical explanations of Monero's privacy features and blockchain. Later chapters dive into complex technical details for understanding, developing, and integrating Monero.”
So it seems like they treat it as something to be killed (impossible) as opposed to something to buckle up and get ready to manage (more or less like they correctly do with AI.)
I do think you are right that this is a topic where emotion strongly gets in the way of reason, but I think the people lacking reason are the advocates and not the critics.
Here is a tip. Money is a transaction cost reducing device. That is it's primary function. By transaction costs I don't mean just fees that a bank or payment service provider charges you, no I mean every economic cost that is involved in negotiating payments. You could think of transaction costs as friction and money as a lubricant. If you have to exchange currencies this causes friction, if you have to physically transport goods or meet in person to barter with them this causes friction. If the value of the goods you are trading is unknown this causes friction. The purpose of money is to be better than some alternative world without money and most cryptocurrencies are hardly better, they are worse or outright useless. The legitimate niches that cryptocurrencies occupy will barely even influence the real world.
Money is sometimes that, but it's also merely a store of value. And I think this what people are missing. I agree that we're almost certainly not going to say paying for coffee in bitcoin.
But where it has legs is as the 401k/money in the mattress replacement; a space that's still very "competitive," i.e. a lot of the options here still really suck, thanks to inflation and/or third parties.
Parallel to barter, desire-to-use is all that is required for use-case.
Governments are going to remain challenged by the need to now assert that possession or use of a legal instrument, with no inherent illegal characteristic, is now evidence of intent to crime.
Not that I don't expect them to rise to the occasion. As they have been by implementing crude sanction power in place of legislation.
Someone in the 1600s saying that joint stock companies are terrible, solve a problem that doesn’t really need solving, and are being used to rip off investors and fund unethical colonialism would have been right. It took a while before people used them in good ways. And even today they are questionable.
After all these years, all scam stories apart, what crypto allow its users to do that they would not be able to do otherwise with less resources? Really I don’t know, and I admit I never wanted to dig the topic as there are many other topic I will never have the time to learn and yet doesn’t seem to have such an issue of what is at best a tremendous noise/signal ratio.
International money transfers, for instance. The traditional banking system was always slow and expensive, and, on top of that, countries cut each other out due to geopolitical reasons. Many third-world countries have a decent crypto adoption, you can send someone money in a matter of minutes (I do).
For a sovereign state this is a feature, not a bug. If you think that countries will take sending of funds to embargoed countries lying down you are sorely mistaken.
And if you have a mixer or private coin that isn't under sanction, it is only a matter of time as determined by the US gov's assessment of the risk of it being widely adopted.
Some very big sums require approval and are delayed. But guess what - it's not a technical limitation but a legal one. It not like some TCP packet can transmit wire transfer of 1000 dollars and unable to do so for 50000 dollars. And we as society do want to control large sum transfers, unless we want to end up like my home country, with funds funneled with close to no control to offshores.
Sure, if a person want to skirt the law and transfer millions without control then current token systems are perfect for him.
To any country of your choosing? I doubt that.
Until crypto becomes at least as easy to get set up with and use as dealing with a bank, Western Union, or online banking, it'll remain niche.
Add some zeroes to those numbers and now it is.
(especially if the transaction fees remain in the 10s)
I think it's the crypto bros who misunderstand it's "inevitability." Crypto has far, far fewer practical applications than the people pushing for it it claim. There are two useful situations for crypto:
1) Where you need a trustless distributed consensus method or database (and where the Oracle Problem doesn't get in your way). Trustless is the key word here, 99% of the time that someone proposes a potential use for crypto it would be better served by traditional databases like Postgres, or traditional consensus algorithms like Raft, because being able to handle such things in a trustless manner isn't actually as desirable as crypto bros suggest.
2) Where you need to bypass financial regulations, sanctions, laws, etc. Crypto has shown some real utility for buying illegal drugs and guns online, for example. Whether or not you see this as a good or bad thing depends largely on your political leanings.
F.x. instead of your money funding illegal wars in Libya you could save some of that wealth and try to build a better future.
All progress depends on the "unreasonable man". I don't think it's inevitable at all, nor have I seen any evidence that it will be. Thus far non-government blockchains have proven to be ill suited for applications other than speculation (and crime). Central bank "programmable money" is definitely a threat - but it's hardly inevitable if popular opposition is vigorous enough.
If you were to ask a tech enthusiast in 2010, they'd might you that 3D TVs were inevitable. Instead they fizzled out. Then there's "the Metaverse", which seems to be on bumpy terrain as well. SPACs seem to be doing not so hot[1]. Not every tech/financial trend sticks around if the value proposition isn't there. And the value proposition for cryptocurrency is very poor in my view.
[1] https://en.wikipedia.org/wiki/Special-purpose_acquisition_co...
Inevitable for lawful daily usage? Nope. Fundamental problems and lack of benefits will prevent blockchain based ledgers to be deployed in any useful scalable way. Actually not "will" but rather "did". Token proposals had a decade of time already and all failed (except for law avoidance of course). Any legitimate proposal has failed spectacularly:
1) Legal currency - failed due to no privacy, bad performance, atrocious UX, unstable exchange rate, shady providers;
2) Distributed storage - fail
3) Distributed calculator - fail
4) Distributed network (Helium) - fail
5) Smart contracts - neither smart nor contracts, very pricey, limited functions (on chain only), oracle problem unsolved
6) NFT - one big lie, impossible to implement any promise made about them because they don't facilitate transfer of the ownership
7) Supply chain ideas - fail, the problem is not securing the DB but securing the humans doing data input in the DB
Anything else I've forgot? Basically most of the good ideas on paper turned out to be either impossible or impractical with blockchains.
Going by the claims I have encountered:
* Inflation proof/Store of value/Stock market hedge
* Bringing banking to the poor
* Web3
* Play-and-get-paid gaming
But "store of value" is still very much in play.
Crypto as a competitor to the 401k or "money in the mattress" strikes me as damn near inevitable.
Yes, agreed. If you can stomach the volatility over decade-long time spans, of course - which very many people can't.
Why would I put my money under the mattress if I could pull it out tomorrow and it'd be worth half of what I thought it was? Yes, inflation is a thing for fiat, but that's nowhere near as volatile as crypto has and continues to be.
Putting a lot in a retirement account today is of course less dumb than putting a lot in crypto.
But neither is guaranteed or certain; and quite a few people diversify their portfolios.
Today, I'd say you're an idiot if you do a lot of crypto -- but also, you're not too bright if you don't throw in a little.
As for tomorrow, who knows. The technology of crypto definitely works. The humans might also decide that this is worth something, or they might not.
Yours is a great way to explain it. I'd say - bitcoin and siblings are 'inevitable' like drug trafficking, not like breathing air
(as in bootlegging was also once drug-trafficking)
Heroin bad/Codeine good. Prozac good/marijuana bad.
etc...
1) International transfers: crypto is the best here. No stupid regulations, fast and cheap unlike SWIFT or something like it.
I've used to work as international freelance programmer since 2003 or about and payments were the pain all time before 2015 or about when I have moved to crypto. Lost transfers, compliance investigations without any real reason with blocking funds for many months, failed transfers because of some stupid errors like missed letter in the receiver name, etc. And even in the best case you should wait for day or two without any info about the transfer progress. Instant card payments are illusion only, it works only in some cases until it fails (for example, my country currency exchange rate is very volatile sometimes, and some people used to buy with card payments smth nominated in US dollars during this periods, hosting for example, and they thought they have saved their money with this buys, but they were really surprised when their accounts were decreased in several days after that, because real transfer takes several days, and it is executed with the exchange rate actual at that time). There is nothing comparable with crypto in international transfers.
2) Distributed storage. I can't believe you don't know about IPFS. When I've tried to download the book I've failed to buy last time I've found that pirate sites use IPFS links more often than torrents now.)
3) Smart contracts allows amazing things sometimes. Do you know about the flashloans for example? You can loan a millions without any credentials, use it for exchange arbitrage for example and if you fail to get your profit and can't return loan plus interest it suddenly becomes like you didn't loan it at all.) Looks like some kind of magic for me.)
4) NFT is misused tech. It really guarantees the ownership, but not for associated media.) Best cases for NFT are tickets or license keys. But this cases can't give you millions in a minute that's why nobody knows about them.
2) I have heard about IPFS and other file storage projects like Filecoin or Siacoin. All of them are noncompetitive with any centralized service. And as for illegal filesharing - sure, it may be useful, bittorents are better though and have no shitty monetization attached to them.
3) Yes, I have heard about flashloans, a lot. It's an amazing source of lulz and comedy godl, finding out how another bridge had been abused, often by the flash loan. It's a completely bullshit and useless idea for a normal human, unless you are a technically inclined hacker, who looks for vulnerabilities in the shitty code running on a virtual machine actively discouraging writing longer code with test coverage and better programming practices, because the longer the code the pricier it is to run. To such hackers flash loans are invaluable to properly abuse broken contracts.
4) NFT doesn't guarantee ownership of nothing but the token itself (and token is useless, because of the tech limitations). Tickets have no benefits on the blockchain because they are always issued by the centralized source. Any property you wish can and MUST be set by that same centralized corporation. NFTs add zero, nothing to it. Same with license keys, again issued by a central authority. NFTs is a cargo cult by tokenbros who don't know how business works.
Yeah sure keep speculating on your "digital gold" I don't care. Unlike holding dollars as demand deposits or cash, you can't hijack the economy. You are accountable for the risks you take but that doesn't mean anyone is going to use Bitcoin or Ethereum to pay their groceries, especially since so many of the crypto credit card companies love operating in jurisdictions where they are completely unaware about the tax implications of their product. What a well thought out business model...
Even though Europe/EU is embracing a regulatory framework for cryptocurrencies and making it easier to do business, crypto exchanges operate in regulatory safe havens, engage in shady practices or get hacked and lose your money.
This argument doesn't hold well. Creating huge amounts of value is expected to be the exception rather than the rule - one of the powerful mechanisms at play here is this is an unusually free market where failure is cheap and all the money clusters to success.
It is reasonable to ignore the thousands of failures. They failed because they were easy to ignore.
The speed and amount of effort to innovate, by basically every demographic of persons, is breathtaking and exciting. Due to low startup costs (lack of gatekeepers), most will fail. That is okay, because the builders are not playing with super powder.
crypto's new paradigm is always just around the corner.
i've been involved in cc for long enough to know that it's popularity (and price) are not driven by utility.
as vb said, it's the linux of money.
> step 1: install gentoo
> step 2: install xmr wallet
- Private by default. With most other cryptos you can see all transactions on the blockchain (although you'll only see address hashes instead of names).
- ASIC resistant POW. Meaning you don't need specialized hardware to mine it but can do it with your PC (assuming it's fairly powerful).
- Transactions are cheap and fairly fast.
- Development is focused on the primary use-case of making transactions for payments, instead of making a "decentralized computing network" or similar.
* Slightly off topic, wikipedia for zcash is terrible, it's written by people that don't understand that a 'ceremony' is part of any asymmetric cryptosystem from your Linux package manager to the CA that signed the cert for the website you're looking at.
With Zcash you get opt-in privacy, with Monero it's enforced with every transaction, for everyone.
https://forum.zcashcommunity.com/t/zcash-counterfeiting-vuln...
Moreover, my greater sense is that the nuts and bolts of crypto is not an HN strong suit. It usually brings out religious-type arguments with little sense of balance. <sigh>
- The UX is horrible.
- To be user friendly, you need to reintroduce trust into the system, defeating the point.
- It's still more expensive to lock up Bitcoin in Lightning than to use Monero.
- The privacy of Lightning is poor compared to Monero.
The only thing Monero lacks compared to Bitcoin is the amount of speculative network effect it has, which is indeed what's holding back Monero's popularity.
I'm not saying that one can't hope for privacy. Only that the investment risk is extremely lopsided in this moment. Expect that the government can ramp up their criminalization efforts faster than a coin can reach escape velocity should its use become more common.
Private coins may be inevitable, but it is going to be a bumpy road to get there.
Bitcoin has absolutely capitalized on giving the impression of privacy, to those (most) not paying full attention, while offering the opposite. Without privacy, DCs are worse than cash unless you feel that you are under threat of seizure or you have a plan to abscond across borders sometime soon.
1. Best monero wallets?
2. How to develop for monero? Links?
2. https://www.getmonero.org/resources/developer-guides/
Or just join libera.chat (IRC) and hang in #monero-dev
When someone forks monero, the new fork is called "monero" and all the small userbase moves over it. The old chain simply dies. No network-effect to resist changes because theres no network at all compared to bitcoin.
Same for all the crypto.
Its absurd to save money in monero or in all the crypto where someone can easily move the inexistent userbase and do hardforks. But if you cant save because the expected value of the cryptos over time is zero, what is the meaning of exchange these assets?
All crytpos that are not bitcoin (even monero) can only work on the informative asimmetry where some people ignore these facts and, scammed by promoters, holds these non-sense assets expecting returns that will never come. The promoters, instead, will make money dumping on them.
Whenever Monero upgrades to new consensus rules they indeed do so via a hardfork, but that only works because there's social consensus (both economic and mining wise). If the consensus would be to stay with the original rules, people would (and it has happened before).
Even in Bitcoin this works, and Bitcoin has even hardforked before! The difference is that in Bitcoin people want to stay on the original chain.
Keeping money in Monero is safe because you'll still keep the money after the hardfork, that's just how they work.
This is just Bitcoin maxi nonsense scary talk.