1
00:00:01,630 --> 00:00:06,680
So there are a variety of
solution to inhibit what we've

2
00:00:06,680 --> 00:00:13,110
been calling transaction graph analysis,
and the first of them is called mixing.

3
00:00:14,510 --> 00:00:15,940
So what is mixing?

4
00:00:15,940 --> 00:00:19,190
Well, the intuition behind this is very,
very simple.

5
00:00:19,190 --> 00:00:22,290
It's the same intuition that
comes up in a lot of contexts,

6
00:00:22,290 --> 00:00:24,500
which is that if you want anonymity,

7
00:00:24,500 --> 00:00:28,910
use an intermediary to route your
communications or your funds or what not.

8
00:00:29,920 --> 00:00:32,690
So let's look at what that
might look like visually.

9
00:00:32,690 --> 00:00:34,050
Here's an intermediary.

10
00:00:34,050 --> 00:00:37,460
And in a second, we'll get to who
these intermediaries might be.

11
00:00:37,460 --> 00:00:39,000
But assume that there
is some intermediary,

12
00:00:39,000 --> 00:00:42,320
some service that allows
users to put in BitCoins.

13
00:00:43,390 --> 00:00:46,110
But the key property
that it gives you is that

14
00:00:46,110 --> 00:00:50,000
after these BitCoins have been put in,
it forgets who put them in, and

15
00:00:50,000 --> 00:00:54,830
treats its entire store of BitCoins
as indistinguishable from each other.

16
00:00:54,830 --> 00:01:00,700
And in fact it might further combine them
all into one giant transaction, or it

17
00:01:00,700 --> 00:01:04,530
might further mix them or split them and
arrange them in different ways, whatever.

18
00:01:04,530 --> 00:01:10,230
But the key property is, that when users
later come in to withdraw their Bitcoins,

19
00:01:10,230 --> 00:01:12,210
it's not tied to the coin
that they put in.

20
00:01:12,210 --> 00:01:14,040
They're going to get some other,

21
00:01:14,040 --> 00:01:19,290
say randomly picked deposit
that the intermediary received.

22
00:01:19,290 --> 00:01:21,080
So when these three users come back,

23
00:01:21,080 --> 00:01:24,080
they're going to withdraw
these coins in a random order.

24
00:01:24,080 --> 00:01:29,930
And so somebody looking at this in the
block chain, who doesn't have the records

25
00:01:29,930 --> 00:01:33,360
that the intermediary might or might not
store just from the publicly available

26
00:01:33,360 --> 00:01:37,180
information in the block chain, is not
going to be able to link the ultimate

27
00:01:37,180 --> 00:01:40,689
input addresses to the ultimate output
addresses corresponding to the same user.

28
00:01:41,900 --> 00:01:44,450
So that's the intuition
behind intermediaries.

29
00:01:44,450 --> 00:01:47,280
Now, looking at this,
does that strike a chord?

30
00:01:47,280 --> 00:01:48,230
Have we seen,

31
00:01:48,230 --> 00:01:53,040
in previous lectures, something that
offers services that are similar to this?

32
00:01:53,040 --> 00:01:56,970
That allows you to deposit BitCoins and
then withdraw them later at a later time.

33
00:01:58,220 --> 00:02:01,730
You might recall that this is
exactly what online wallets do.

34
00:02:01,730 --> 00:02:05,280
There are services where you can
just store your bitcoins online,

35
00:02:05,280 --> 00:02:07,070
until you need them.

36
00:02:07,070 --> 00:02:10,200
And so, you might wonder,
well is that the solution to our problems?

37
00:02:10,200 --> 00:02:11,970
Do online wallets provide anonymity?

38
00:02:13,610 --> 00:02:14,650
Let's think about that.

39
00:02:14,650 --> 00:02:16,410
The answer to this is not obvious.

40
00:02:16,410 --> 00:02:22,500
But I will start by mentioning that it's
taken well-known researchers by surprise.

41
00:02:22,500 --> 00:02:27,320
Here was a post on
the New York Times' Bits blog,

42
00:02:27,320 --> 00:02:32,550
reporting on a preprint of a paper
released by two Israeli researchers,

43
00:02:32,550 --> 00:02:36,110
saying that there was a link between
Dread Pirate Roberts, the pseudonymous

44
00:02:36,110 --> 00:02:39,730
creator of Silk Road which we're going
to see more about, and Satoshi Nakamoto.

45
00:02:40,880 --> 00:02:43,450
This was, of course, very surprising.

46
00:02:43,450 --> 00:02:49,170
But as it turned out, all that had
happened was that they had mistook this

47
00:02:49,170 --> 00:02:52,990
link that went through an intermediary,
and that intermediary just turned out to

48
00:02:52,990 --> 00:02:56,870
be Mount Gox, which you can think of
sort of as an online wallet service.

49
00:02:58,200 --> 00:03:00,320
And so a few days later,

50
00:03:00,320 --> 00:03:03,939
this other post was published at the same
menu, see if you can spot the difference.

51
00:03:05,240 --> 00:03:09,970
They had to retract their study and
I think they had made a very simple

52
00:03:09,970 --> 00:03:12,410
mistake of not accounting for
the presence of this intermediary.

53
00:03:13,550 --> 00:03:17,330
So, it's clear that, at least in some
sense, online wallets provide some sort of

54
00:03:17,330 --> 00:03:21,390
anonymity, because at least somebody tried
to make a connection between an input and

55
00:03:21,390 --> 00:03:23,820
an output address and
completely failed at that.

56
00:03:25,200 --> 00:03:29,620
So let's try to understand exactly
the sense in which online wallets provide

57
00:03:29,620 --> 00:03:33,460
anonymity, and I think a good way
to do that would be to in fact

58
00:03:33,460 --> 00:03:38,330
contrast online wallets with online
services that exist specifically for

59
00:03:38,330 --> 00:03:41,980
the purpose of acting as these
intermediaries for anonymity, and

60
00:03:41,980 --> 00:03:44,359
those are going to be
dedicated mixing services.

61
00:03:45,750 --> 00:03:48,780
We'll talk about mixing services
in much more detail, but

62
00:03:48,780 --> 00:03:54,080
very briefly the two things that
they promise: that you won't get

63
00:03:54,080 --> 00:03:57,310
simply by putting your BitCoins
into an online wallet and

64
00:03:57,310 --> 00:04:01,050
retrieving that again,
is that they promise not to keep records.

65
00:04:01,050 --> 00:04:03,270
It's not just that as a side effect,

66
00:04:03,270 --> 00:04:07,780
they sort of randomly give you BitCoins
that came from some other address, but

67
00:04:07,780 --> 00:04:11,900
they specifically say that they won't keep
records, and so even if they tried to,

68
00:04:11,900 --> 00:04:14,420
they wouldn't know which BitCoins
were the ones you put in.

69
00:04:14,420 --> 00:04:18,240
And so, with a high probability, you're
going to get some other BitCoins back.

70
00:04:18,240 --> 00:04:21,210
And, furthermore, even if someone
came knocking for their records or

71
00:04:21,210 --> 00:04:23,870
if they got hacked and so on,
there would be nothing to find.

72
00:04:23,870 --> 00:04:25,410
There would be no records.

73
00:04:25,410 --> 00:04:27,750
So that's something that
a mixing service promises.

74
00:04:27,750 --> 00:04:31,200
And the other thing is that you
don't need your real-life identity

75
00:04:31,200 --> 00:04:33,950
in order to interact with the services.

76
00:04:33,950 --> 00:04:37,280
And this is in contrast to
most of these online wallets.

77
00:04:37,280 --> 00:04:40,240
Why?
Because online wallets are typically

78
00:04:40,240 --> 00:04:42,599
reputable and in fact,
often regulated businesses.

79
00:04:44,110 --> 00:04:46,710
And this fact has two consequences.

80
00:04:46,710 --> 00:04:49,650
One is that they all typically
require your identity.

81
00:04:49,650 --> 00:04:52,530
In banking,
there is the know your customer principle,

82
00:04:52,530 --> 00:04:54,430
which essentially at a technical level,

83
00:04:54,430 --> 00:04:58,430
translate to learn the customer's
identity and store those records.

84
00:04:59,780 --> 00:05:03,900
And in fact, they will keep records,
if they receive a deposit,

85
00:05:03,900 --> 00:05:07,090
they will keep the link between
the identity and the Bitcoin address.

86
00:05:07,090 --> 00:05:10,480
If they move money around internally, they
will probably keep records of all of that.

87
00:05:12,090 --> 00:05:15,150
And just because when you would draw
your BitCoins they come from a different

88
00:05:15,150 --> 00:05:20,010
address, does not mean that the online
wallet does not know the link.

89
00:05:20,010 --> 00:05:23,480
That link probably does exist in
their records and will exist for

90
00:05:23,480 --> 00:05:28,280
all eternity, even if they don't
explicitly ask for your identity.

91
00:05:28,280 --> 00:05:29,220
Think about this.

92
00:05:29,220 --> 00:05:31,260
To even interact with an online wallet,

93
00:05:31,260 --> 00:05:33,770
you do need a persistent
long term identity.

94
00:05:33,770 --> 00:05:36,630
You can't possibly use
a different pseudonym every time.

95
00:05:36,630 --> 00:05:40,990
Because if you did, they would have no way
of associating an account with you knowing

96
00:05:40,990 --> 00:05:43,040
how many BitCoins they owed you.

97
00:05:43,040 --> 00:05:46,280
Right, so because of that,
even if they didn't ask for your identity,

98
00:05:46,280 --> 00:05:51,380
at the very least, the online
wallet knows the address of every

99
00:05:51,380 --> 00:05:56,470
single deposit that you made of the
bitcoins that you put into the system and

100
00:05:56,470 --> 00:06:00,070
more importantly,
every single withdraw that you made.

101
00:06:00,070 --> 00:06:03,246
And so when you make a series of
withdraws from an online wallet and

102
00:06:03,246 --> 00:06:04,922
precede to spend those bitcoins,

103
00:06:04,922 --> 00:06:08,360
the wallet service can now connect
all of those together in a profile.

104
00:06:09,640 --> 00:06:12,440
And of course it's not just
the wallet service, people who care

105
00:06:12,440 --> 00:06:16,030
about anonymity are also worried
about those records getting hacked.

106
00:06:16,030 --> 00:06:20,800
Insider attacks,
somebody who has a subpoena for

107
00:06:20,800 --> 00:06:22,610
getting those records,
and so on and so forth.

108
00:06:24,660 --> 00:06:27,230
So, with respect to the wallet
service itself, and

109
00:06:27,230 --> 00:06:32,300
whoever they might be cooperating with,
you have no anonymity in this context.

110
00:06:32,300 --> 00:06:34,830
On the other hand,
there is something cool about this.

111
00:06:34,830 --> 00:06:38,960
If you are willing to trust
them with your BitCoins, then

112
00:06:38,960 --> 00:06:42,090
what's going to happen is you're going
to keep them in the wallet service for

113
00:06:42,090 --> 00:06:45,370
much longer than you typically
would with a mix service.

114
00:06:45,370 --> 00:06:46,630
Why?
Because you don't trust in mix

115
00:06:46,630 --> 00:06:47,500
servers as much.

116
00:06:47,500 --> 00:06:49,980
You want to put in your BitCoins and
you want to receive it back

117
00:06:49,980 --> 00:06:54,190
immediately from some other address
at an address of your serving.

118
00:06:55,720 --> 00:06:57,120
Right?
So unlike that, for

119
00:06:57,120 --> 00:07:01,670
an online wallet service you're going
to have a bigger anonymity set.

120
00:07:01,670 --> 00:07:03,900
Why?
Because your anonymity set,

121
00:07:03,900 --> 00:07:07,060
from the point of view of someone
with no privileged information,

122
00:07:07,060 --> 00:07:10,360
from the point of view of someone who's
merely looking at the block chain,

123
00:07:10,360 --> 00:07:13,630
your withdrawal could
look indistinguishable

124
00:07:13,630 --> 00:07:16,979
from every single withdrawal ever
made from that service provider.

125
00:07:18,450 --> 00:07:21,180
So with respect to the wallet service,
you have no anonymity.

126
00:07:21,180 --> 00:07:25,530
With respect to everybody else, you'd have
a bigger anonymity set than you possibly

127
00:07:25,530 --> 00:07:29,330
would with using a mixing service, or at
least with using a single mixing service.

128
00:07:31,333 --> 00:07:34,783
So if we look at this, this looks
suspiciously similar to the kind of

129
00:07:34,783 --> 00:07:39,370
privacy properties that you have
with the traditional banking system.

130
00:07:39,370 --> 00:07:43,930
There are these centralized intermediaries
that know a lot about our transactions.

131
00:07:43,930 --> 00:07:47,270
But from the point of view of a stranger
with no privileged information,

132
00:07:47,270 --> 00:07:48,830
we have a pretty good amount of privacy.

133
00:07:50,200 --> 00:07:52,790
So, even if this gives you
some sort of anonymity,

134
00:07:52,790 --> 00:07:56,830
it's almost at best what you get with
a traditional system, and so those are not

135
00:07:56,830 --> 00:08:00,834
the kind of people who are typically
looking for anonymity in BitCoin anyway.

136
00:08:00,834 --> 00:08:04,138
If they were happy with their anonymity
properties of the traditional system,

137
00:08:04,138 --> 00:08:06,419
And they would have probably
stayed with that system.

138
00:08:06,419 --> 00:08:09,460
And so
generally people who are looking for

139
00:08:09,460 --> 00:08:14,447
anonymity properties in Bitcoin simply
do not want to accept the trust

140
00:08:14,447 --> 00:08:18,690
requirements that these online
wallet services require.

141
00:08:18,690 --> 00:08:22,520
And they don't want the sort of
anonymity properties that it gives you.

142
00:08:22,520 --> 00:08:25,580
They don't want to have to trust
that service with their anonymity.

143
00:08:26,950 --> 00:08:27,780
And in fact,

144
00:08:27,780 --> 00:08:31,350
we've seen that there have been a lot of
closures of these exchanges and services.

145
00:08:31,350 --> 00:08:34,872
And so there's good reason for
believing that if you put all your trust

146
00:08:34,872 --> 00:08:37,747
in an online service,
you might simply lose your money.

147
00:08:37,747 --> 00:08:42,458
Okay, so having rejected online wallets
as an anonymity solution, let's turn

148
00:08:42,458 --> 00:08:47,500
to these dedicated mixing services
that I told you a little bit about.

149
00:08:47,500 --> 00:08:51,800
Before looking at their details, let's
talk about the terminology a little bit.

150
00:08:51,800 --> 00:08:55,200
I like to call it a mix,
some people call it a mixer.

151
00:08:55,200 --> 00:08:56,780
These are really the same thing.

152
00:08:56,780 --> 00:09:00,910
Some people also call them laundries,
I don't like this term at all.

153
00:09:00,910 --> 00:09:05,550
The reason why is because it needlessly
attaches moral meaning to something that's

154
00:09:05,550 --> 00:09:07,340
a purely technical term.

155
00:09:07,340 --> 00:09:10,250
As we've seen earlier,
there are very good reasons why

156
00:09:10,250 --> 00:09:12,840
you might want to protect
your privacy in Bitcoin and

157
00:09:12,840 --> 00:09:16,510
use mixes for entirely good reasons,
for everyday privacy.

158
00:09:16,510 --> 00:09:19,150
Of course,
we must also acknowledge the bad uses.

159
00:09:19,150 --> 00:09:22,760
But it seems a little bit weird
to me to use the term laundry,

160
00:09:22,760 --> 00:09:25,610
that implies that your coins are dirty and
you need to clean them,

161
00:09:25,610 --> 00:09:30,270
and attaching a negative moral
value to the whole thing.

162
00:09:30,270 --> 00:09:34,020
Which, and for that reason, I'm not
going to use that term in this lecture.

163
00:09:34,020 --> 00:09:36,740
We'll go with the technically
neutral term, which is mixing.

164
00:09:38,440 --> 00:09:42,090
So, in talking about mixing,
there are several of us,

165
00:09:42,090 --> 00:09:43,750
about six of us, who got together.

166
00:09:43,750 --> 00:09:46,420
Researchers at Princeton, Concordia, and

167
00:09:46,420 --> 00:09:50,210
Maryland, including all four of us who
are doing this online lecture series.

168
00:09:50,210 --> 00:09:54,970
And analyzed the existing mix ecosystem
and proposed a series of changes for

169
00:09:54,970 --> 00:09:58,770
improving the ways that mixes operate,
both in terms of anonymity and

170
00:09:58,770 --> 00:10:00,840
the trustworthiness of mixes.

171
00:10:00,840 --> 00:10:02,870
So, let's look at those principles.

172
00:10:02,870 --> 00:10:04,500
Before I show you those principles,

173
00:10:04,500 --> 00:10:08,540
as a quick reminder, at a very fundamental
level, how does a mix operate?

174
00:10:08,540 --> 00:10:12,240
It asks for an address at which
you want to receive Bitcoins, and

175
00:10:12,240 --> 00:10:15,320
gives you an address to
send Bitcoins to the mix.

176
00:10:15,320 --> 00:10:17,570
And then,
you both execute that transaction.

177
00:10:17,570 --> 00:10:19,040
It's a swap, basically.

178
00:10:19,040 --> 00:10:22,010
In a second, I'll show you
what that looks like visually.

179
00:10:22,010 --> 00:10:25,540
But what were our principles for
running these mixes properly?

180
00:10:25,540 --> 00:10:30,140
Well, the very first one is that you
might want to use a series of mixes

181
00:10:30,140 --> 00:10:33,630
instead of just a single mix, and
this is a very well-known principle.

182
00:10:34,850 --> 00:10:37,950
Using a series of routers
is the same principle in

183
00:10:37,950 --> 00:10:40,360
the anonymous communication system TOR.

184
00:10:40,360 --> 00:10:47,389
And it's a good idea, because it allows
you to not have to trust a single mix.

185
00:10:47,389 --> 00:10:51,652
But instead, be sure that as long as
any one of these mixes is promising

186
00:10:51,652 --> 00:10:55,860
to delete its records, then you
have a good guarantee of anonymity.

187
00:10:55,860 --> 00:11:00,725
And in particular, mixes should implement
a standard API so that this could be

188
00:11:00,725 --> 00:11:05,775
very easy for clients to accomplish, and
right now, this is not quite the case.

189
00:11:05,775 --> 00:11:09,370
And this is our paper for your reference.

190
00:11:09,370 --> 00:11:10,820
So, now let's go in and

191
00:11:10,820 --> 00:11:15,900
look at what a series of mixes would
look like visually, so, here it is.

192
00:11:15,900 --> 00:11:21,420
Here is a user, who starts with a coin,
or an input address,

193
00:11:21,420 --> 00:11:27,070
that we assume that the adversary has
managed to link to this particular user.

194
00:11:27,070 --> 00:11:30,200
They're going to send it to
the mix at this address and

195
00:11:30,200 --> 00:11:33,160
get back a Bitcoin at this other
output address that they provide.

196
00:11:33,160 --> 00:11:37,730
They freshly generate this output address
and provide that address to the mix.

197
00:11:37,730 --> 00:11:42,920
The mix will hopefully return the same
amount of Bitcoins at this output address,

198
00:11:42,920 --> 00:11:45,460
there's no way for
the user to force the mix to do that.

199
00:11:45,460 --> 00:11:47,990
The user has to trust the mix,
and this is, as we'll see,

200
00:11:47,990 --> 00:11:50,469
a recurring problem with
the whole notion of mixes.

201
00:11:52,510 --> 00:11:55,610
And either immediately or
after a time gap,

202
00:11:55,610 --> 00:12:00,250
it doesn't matter, the user will take
the Bitcoin or Bitcoins of whatever

203
00:12:00,250 --> 00:12:04,320
value they've received at this address and
send it to a different mix.

204
00:12:04,320 --> 00:12:06,890
Which is hopefully not cooperating
with the first mix and

205
00:12:06,890 --> 00:12:08,550
repeat this process over and over again.

206
00:12:10,420 --> 00:12:13,790
So from an adversary's point of view,
looking at the public block chain,

207
00:12:13,790 --> 00:12:17,360
they're merely going to see along
with all of these transactions,

208
00:12:17,360 --> 00:12:21,670
a variety of other mixed transactions
that other users are executing.

209
00:12:21,670 --> 00:12:25,897
And will, hopefully, the adversary will
have no way to tell apart which of those

210
00:12:25,897 --> 00:12:28,698
transactions correspond to
this particular user and

211
00:12:28,698 --> 00:12:31,017
which one corresponds to some other users.

212
00:12:31,017 --> 00:12:32,410
So that's the first principal.

213
00:12:32,410 --> 00:12:36,529
And the second one, if you think about
what I've just said, in order to make that

214
00:12:36,529 --> 00:12:40,225
possible you want to make these
transactions as uniform as possible, so

215
00:12:40,225 --> 00:12:42,180
that this linkability is minimized.

216
00:12:43,775 --> 00:12:47,335
And what does it mean to make these
transactions as uniform as possible?

217
00:12:47,335 --> 00:12:51,374
One important consequence is that
all of these mixed transactions,

218
00:12:51,374 --> 00:12:55,759
not only from a particular mix, but
all of the mixes in this mix ecosystem,

219
00:12:55,759 --> 00:12:57,448
should have the same value.

220
00:12:57,448 --> 00:13:01,235
So we think that all mixes out there
providing service should agree upon

221
00:13:01,235 --> 00:13:02,024
a chunk size.

222
00:13:02,024 --> 00:13:05,663
A standard chunk size, and of course
there can be multiple denominations, but

223
00:13:05,663 --> 00:13:06,867
there can't be too many.

224
00:13:06,867 --> 00:13:11,409
And you can't simply allow the users
to put in whatever amount of Bitcoins

225
00:13:11,409 --> 00:13:13,980
they wish to, that wouldn't work.

226
00:13:13,980 --> 00:13:15,440
So you need this kind of standardization.

227
00:13:16,890 --> 00:13:21,180
In addition to this, we found that there
are a variety of possible attacks in which

228
00:13:21,180 --> 00:13:25,160
a clever adversary might
infer various things.

229
00:13:25,160 --> 00:13:29,500
Not just the amount, even if you remove
the amount, some other properties,

230
00:13:29,500 --> 00:13:33,810
including timing for example, in order
to try to link users input addresses and

231
00:13:33,810 --> 00:13:34,720
output addresses together.

232
00:13:36,290 --> 00:13:39,850
This type of linking can be avoided but
human users,

233
00:13:39,850 --> 00:13:42,680
if they interact with the mix,
are not going to be

234
00:13:42,680 --> 00:13:46,150
able to take into account all of
those possible linking attacks.

235
00:13:46,150 --> 00:13:51,680
So instead, what needs to be done is this
client side software must be automated and

236
00:13:51,680 --> 00:13:53,410
built into desktop wallet software.

237
00:13:54,550 --> 00:13:57,460
So that this desktop wallet
software automatically knows how to

238
00:13:57,460 --> 00:14:00,710
interact with these mixes in order
to preserve the user's anonymity.

239
00:14:02,180 --> 00:14:04,320
So that was our third principle.

240
00:14:04,320 --> 00:14:06,580
Our fourth principle is a subtle one.

241
00:14:06,580 --> 00:14:10,200
Now these mixes,
why do they provide this service?

242
00:14:10,200 --> 00:14:12,300
Typically, it's because
they're a business.

243
00:14:12,300 --> 00:14:14,560
And if they're a business,
they want to be paid.

244
00:14:14,560 --> 00:14:16,450
How are they going to get paid?

245
00:14:16,450 --> 00:14:20,359
Well, it turns out that pretty much
the only way for these mixers to get

246
00:14:20,359 --> 00:14:24,480
paid is to take a cut of the transaction
that the user is sending to the mix.

247
00:14:26,320 --> 00:14:31,530
That seems a bit weird, because if
a mix takes a standard percentage,

248
00:14:31,530 --> 00:14:34,970
then an adversary might be able to use
that to link the input transaction and

249
00:14:34,970 --> 00:14:36,300
the output transaction.

250
00:14:36,300 --> 00:14:40,489
So some current mixes try to
randomize the transaction fee,

251
00:14:40,489 --> 00:14:44,443
they might say we take a random
cut between 1% and 3%.

252
00:14:44,443 --> 00:14:46,554
We found that this is
not a good idea either,

253
00:14:46,554 --> 00:14:48,905
because if you put that
through a chain of mixes.

254
00:14:48,905 --> 00:14:53,748
Then the amount of the value in the chunk
is going to dwindle in a predictable way,

255
00:14:53,748 --> 00:14:57,180
and this is an important side channel for
the adversary.

256
00:14:58,410 --> 00:15:00,150
So what is a way to avoid this?

257
00:15:00,150 --> 00:15:05,600
We proposed that these mixed
fees should be all or nothing.

258
00:15:05,600 --> 00:15:10,490
In other words, the mix should
either swallow the whole chunk

259
00:15:10,490 --> 00:15:14,480
with a small probability, or
should return the whole chunk.

260
00:15:14,480 --> 00:15:18,600
So if the mix wants to charge
a 0.1% mixing fee, this is,

261
00:15:18,600 --> 00:15:22,360
by the way, very different from the
transaction fee that mining notes charge.

262
00:15:22,360 --> 00:15:24,650
This is a mixing fee on top of that.

263
00:15:24,650 --> 00:15:27,290
So if the mix wants to
charge a 0.1% mixing fee,

264
00:15:27,290 --> 00:15:32,500
then 1 out of 1,000 times,
the mix should swallow the entire chunk.

265
00:15:32,500 --> 00:15:34,600
And 999 times out of 1,000,

266
00:15:34,600 --> 00:15:38,000
the mix should return the entire
chunk without taking any mixing fee.

267
00:15:39,920 --> 00:15:42,320
This is a tricky property to accomplish,

268
00:15:42,320 --> 00:15:46,985
which means that the mix should generate
a random number in a way that can convince

269
00:15:46,985 --> 00:15:51,116
the user that the mix has not cheated
in generating this random number.

270
00:15:51,116 --> 00:15:55,684
And has genuinely flipped
a coin which has 99.9%

271
00:15:55,684 --> 00:15:59,550
chance of coming up one
way versus the other.

272
00:15:59,550 --> 00:16:04,005
But we do show how to do this using
cryptography in a way that both

273
00:16:04,005 --> 00:16:07,469
parties can be satisfied
has worked correctly.

274
00:16:07,469 --> 00:16:11,958
We think that really all four of these
principles are necessary to have anything

275
00:16:11,958 --> 00:16:16,246
approaching mathematical confidence
in having a large anonymity set, and

276
00:16:16,246 --> 00:16:20,333
in our ability to resist clever
inferential attacks by an adversary that

277
00:16:20,333 --> 00:16:23,360
looks at the blotching to
try to link input to output.

278
00:16:24,760 --> 00:16:29,990
The sad news is that virtually, none of
the current mixes follow these principles.

279
00:16:29,990 --> 00:16:32,620
They're in a very different model,
where each mix operates

280
00:16:32,620 --> 00:16:36,050
completely independently, and
they have a web interface.

281
00:16:36,050 --> 00:16:38,470
And the user interacts with
them totally manually,

282
00:16:38,470 --> 00:16:41,550
instead of automatically
through their wallet software.

283
00:16:41,550 --> 00:16:44,260
And we'll manually put in the amount.

284
00:16:44,260 --> 00:16:46,020
Instead of standard chunk size,

285
00:16:46,020 --> 00:16:48,760
it's whatever amount
the user chooses typically.

286
00:16:48,760 --> 00:16:52,960
And the mix will take some cut
of that as a mixing fee and

287
00:16:52,960 --> 00:16:56,440
send the rest to the user.

288
00:16:56,440 --> 00:17:00,390
We don't think this is a situation that
gives mixed users a lot of anonymity, but

289
00:17:00,390 --> 00:17:04,540
we think that by moving to a slightly
different model based on these

290
00:17:04,540 --> 00:17:05,540
four principles,

291
00:17:05,540 --> 00:17:09,072
the anonymity properties of the mixed
ecosystem can be dramatically improved.

292
00:17:09,072 --> 00:17:13,280
All right, so
through these four principles we've seen

293
00:17:13,280 --> 00:17:16,090
how the anonymity properties
of mixing can be improved.

294
00:17:16,090 --> 00:17:19,150
But there is still one major
problem which is that users

295
00:17:19,150 --> 00:17:21,410
still have to trust these mixes.

296
00:17:21,410 --> 00:17:25,260
So again we had a few ways that
we talked about in our paper for

297
00:17:25,260 --> 00:17:26,139
what to do about this.

298
00:17:27,290 --> 00:17:31,500
Mixes can do several things to
improve their trustworthiness.

299
00:17:31,500 --> 00:17:33,680
One is that,
simply by staying in business for

300
00:17:33,680 --> 00:17:38,630
a long time, and not stealing user's
money, they can build up a reputation.

301
00:17:40,010 --> 00:17:41,710
You might wonder,
does this reputation count for

302
00:17:41,710 --> 00:17:44,770
anything, because it's simply
a matter of he said, she said.

303
00:17:45,840 --> 00:17:50,840
In fact, a mix operator can claim
that a competing mix operator

304
00:17:50,840 --> 00:17:53,320
stole all their money,
even if that did not in fact happen.

305
00:17:54,760 --> 00:17:58,060
Well, generally,
reputation systems in the real world

306
00:17:58,060 --> 00:18:01,530
manage to operate even though there can
be conflicting claims that are made.

307
00:18:01,530 --> 00:18:03,640
In this context, for example.

308
00:18:03,640 --> 00:18:07,100
Users might learn to only trust the word
of prominent members of the BitCoin

309
00:18:07,100 --> 00:18:10,670
community who they think have the best
interests of the ecosystem at heart.

310
00:18:12,550 --> 00:18:16,310
Another way is that in
the system that we proposed,

311
00:18:16,310 --> 00:18:20,410
the chunk sizes are going to be so small
that in the regular course of mixing,

312
00:18:20,410 --> 00:18:22,619
users are going to mix a pretty
huge number of chunks.

313
00:18:24,470 --> 00:18:26,960
Or at least the system can be
configured in that way, so

314
00:18:26,960 --> 00:18:29,150
the chunk sizes are relatively small.

315
00:18:29,150 --> 00:18:34,270
So in that context, if a mix has even
a one percent probability of stealing

316
00:18:34,270 --> 00:18:36,940
a user's chunk, then after a hundred or

317
00:18:36,940 --> 00:18:41,160
so interactions, with small chunk
sizes with a particular mix.

318
00:18:41,160 --> 00:18:42,510
The user is going to know.

319
00:18:42,510 --> 00:18:44,430
The user is going to detect the theft, and

320
00:18:44,430 --> 00:18:46,920
so the user will learn to
never use this mix again.

321
00:18:48,340 --> 00:18:52,420
And so the system might sort of correct
itself by users, testing mixes for

322
00:18:52,420 --> 00:18:54,980
themselves for trustworthiness.

323
00:18:54,980 --> 00:18:58,960
An important thing to keep mind in here is
that the chunks that users are sending to

324
00:18:58,960 --> 00:19:03,160
mixes have typically already
been through other mixes.

325
00:19:03,160 --> 00:19:08,180
So the mix itself can't know which
user the chunk is coming from.

326
00:19:08,180 --> 00:19:12,540
And so the only thing the mix can do is
to essentially steal randomly from users.

327
00:19:12,540 --> 00:19:14,990
The mix can't steal
from a particular user.

328
00:19:14,990 --> 00:19:19,320
So from a user point of view,
on average, they won't suffer losses

329
00:19:19,320 --> 00:19:22,130
that are more than the average
rate at which the mix steals.

330
00:19:22,130 --> 00:19:26,640
So they don't have to worry that a mix
might particularly have it in for

331
00:19:26,640 --> 00:19:28,850
that particular user, and
steal all of their money.

332
00:19:28,850 --> 00:19:29,980
There's no way that that can happen.

333
00:19:31,230 --> 00:19:34,610
So that's what I mean when I say
users can test this for themselves.

334
00:19:34,610 --> 00:19:39,220
And finally, we proposed a cryptographic
mechanism where the mix can issue sort of

335
00:19:39,220 --> 00:19:45,030
a promissory statement to the user, that
once it receives a chunk at a particular

336
00:19:45,030 --> 00:19:48,860
address it will send a chunk back at some
other address that the user provides.

337
00:19:50,000 --> 00:19:54,110
And so, if the mix fails to keep this
promise, our idea is that the user can

338
00:19:54,110 --> 00:19:58,750
publicize this warranty and everybody will
know that a particular mix is cheated.

339
00:19:58,750 --> 00:20:02,370
And so everybody will stop using this
mix and the mix will lose business.

340
00:20:02,370 --> 00:20:06,600
And in combination, all of these three
mechanisms provide incentives for

341
00:20:06,600 --> 00:20:07,690
mixes to act honestly.

342
00:20:09,320 --> 00:20:12,680
So these were our calculations anyway,
and our proposal.

343
00:20:12,680 --> 00:20:14,910
We haven't proved that this
will work in practice.

344
00:20:14,910 --> 00:20:15,820
That remains to be seen.

345
00:20:17,950 --> 00:20:18,800
All right.

346
00:20:18,800 --> 00:20:23,470
On that note, let's quickly look at
how things are in practice right now.

347
00:20:23,470 --> 00:20:26,830
It doesn't seem that
there are any reputable

348
00:20:26,830 --> 00:20:31,440
services providing dedicated mixing
that users have learned to trust, or

349
00:20:31,440 --> 00:20:33,810
at least enough to use on a regular basis.

350
00:20:33,810 --> 00:20:38,430
In fact, this is from the BitCoin Wiki
where original is also highlighted in red.

351
00:20:38,430 --> 00:20:40,470
I took the liberty of doing that myself.

352
00:20:40,470 --> 00:20:43,840
Mixing services may themselves
be operating with anonymity.

353
00:20:43,840 --> 00:20:48,160
So, if your funds are not delivered,
you have no recourse.

354
00:20:48,160 --> 00:20:50,010
Use at your own discretion.

355
00:20:50,010 --> 00:20:53,920
So, we are proposing moving to a different
model where mixes stay in business,

356
00:20:53,920 --> 00:20:55,310
become reputable businesses, and so on.

357
00:20:55,310 --> 00:20:56,569
That hasn't quite happened yet.

358
00:20:57,740 --> 00:21:01,400
And note that is sort of
a bootstrapping problem here.

359
00:21:01,400 --> 00:21:05,410
If mixes were reputable entities they
would have a big volume of transactions,

360
00:21:05,410 --> 00:21:08,460
and so by interacting with them you'd
get a pretty good anonymity set.

361
00:21:08,460 --> 00:21:11,510
And so users would be more confident
in interacting with them, and

362
00:21:11,510 --> 00:21:15,790
mixes would realize that they're making
more money by staying in business and

363
00:21:15,790 --> 00:21:18,380
taking a small cut,
than by trying to steal

364
00:21:18,380 --> 00:21:21,620
the small amount of money that
they're controlling at any given time.

365
00:21:23,290 --> 00:21:26,369
So mixes would be further
incentivized to stay in business.

366
00:21:27,550 --> 00:21:30,570
So you can imagine that once
a mixed ecosystem gets going,

367
00:21:30,570 --> 00:21:32,160
it will be self sustaining.

368
00:21:32,160 --> 00:21:34,726
But whether or not that can
eventually happen, we can say for

369
00:21:34,726 --> 00:21:36,500
sure that it hasn't quite happened yet.

