|
|
|
|
|
by plasticmachine
3883 days ago
|
|
The point you're actually trying to make is "every privacy scheme has trade-offs". Zerocoin's trade-offs are massive: untested / unreviewed cryptography, a trusted initial accumulator that can ruin the anonymity for everyone forever, a significantly larger transaction size, and a blockchain so opaque that double-spends and false coin creation cannot be seen. Those are the issues that matter, and Monero suffers from none of those problems. |
|
This is false: even if somebody compromises the initial setup (which, if implemented using the proposed MPC protocol, would require compromising every single participant; compromising n-1 parties doesn't do anything), the system continues to enjoy the same zero-knowledge guarantees. Compromised setup or not, in Zerocash the anonymity set is all participants of the system.