1
00:00:00,360 --> 00:00:02,250
Now let's turn to Zerocoin and

2
00:00:02,250 --> 00:00:07,030
Zerocash, which are a completely
different approach to Bitcoin anonymity.

3
00:00:07,030 --> 00:00:10,590
The approach is sort of to bake
it in at the protocol level, and

4
00:00:10,590 --> 00:00:13,130
these are cryptographic heavyweights, and

5
00:00:13,130 --> 00:00:17,250
so Zerocoin was first developed by
cryptographers at Johns Hopkins.

6
00:00:17,250 --> 00:00:21,620
And later on, they started collaborating
with other researchers around the world

7
00:00:21,620 --> 00:00:26,560
who had been developing a very efficient
cryptographic technique that would enable

8
00:00:26,560 --> 00:00:30,230
making some of the cryptographic
operations in Zerocoin more efficient.

9
00:00:30,230 --> 00:00:32,530
And that resulted in Zerocash.

10
00:00:32,530 --> 00:00:36,720
As you'll see, these techniques provide a
qualitatively different level of anonymity

11
00:00:36,720 --> 00:00:40,290
than mixing solutions that
sit on top of Bitcoin.

12
00:00:40,290 --> 00:00:41,300
But what's the catch?

13
00:00:41,300 --> 00:00:45,250
The problem is that this is not quite
backward compatible with Bitcoin.

14
00:00:45,250 --> 00:00:48,670
Zerocoin and
Zerocash are going to require Altcoins.

15
00:00:48,670 --> 00:00:53,050
Technically, it's possible that Zerocoin
can be deployed as what is known as a soft

16
00:00:53,050 --> 00:00:57,030
fork of Bitcoin, but the practical
difficulties are high enough that this

17
00:00:57,030 --> 00:00:59,380
is not really considered feasible and,
in fact,

18
00:00:59,380 --> 00:01:03,390
Zerocoin developers, Intent to
deploy it as an Altcoin themselves,

19
00:01:03,390 --> 00:01:07,240
instead of trying to be
compatible with Bitcoin directly.

20
00:01:07,240 --> 00:01:08,800
Let's start talking about the details.

21
00:01:08,800 --> 00:01:11,230
Here, let's read some of
the things that I've just said.

22
00:01:11,230 --> 00:01:13,570
So Zerocoin brings protocol level mixing.

23
00:01:14,870 --> 00:01:18,080
And being baked into the protocol,

24
00:01:18,080 --> 00:01:21,510
what it gives you is a cryptographic
guarantee of mixing.

25
00:01:21,510 --> 00:01:22,540
What does that mean?

26
00:01:22,540 --> 00:01:26,820
You don't need to trust a single mix, or
even a set of mixes or a set of peers, or

27
00:01:26,820 --> 00:01:29,850
anybody at all, to ensure your anonymity.

28
00:01:29,850 --> 00:01:33,010
You just need to rely on
the underlying crypto being solid.

29
00:01:33,010 --> 00:01:36,260
You don't een need to rely on
the miners enforcing this,

30
00:01:36,260 --> 00:01:40,070
in order to achieve anonymity,
it's purely a cryptographic guarantee.

31
00:01:40,070 --> 00:01:40,880
So that's really great,

32
00:01:40,880 --> 00:01:44,710
that's qualitatively better
than what we have so far.

33
00:01:44,710 --> 00:01:47,680
And of course, it's not currently
compatible with Bitcoin, and

34
00:01:47,680 --> 00:01:49,160
here's the paper if you
wanted to look it up.

35
00:01:51,850 --> 00:01:53,260
So how does Zerocoin work?

36
00:01:53,260 --> 00:01:55,890
I'm going to introduce
a concept called Basecoin.

37
00:01:55,890 --> 00:02:00,170
And I'm taking a few liberties with the
presentation here in order to simplify and

38
00:02:00,170 --> 00:02:01,390
clarify the concepts.

39
00:02:01,390 --> 00:02:05,590
I'm going to do that by mixing some
concepts from Zerocoin and Zerocash, but

40
00:02:05,590 --> 00:02:09,440
toward the end, I'll make very clear what
the differences are between the two.

41
00:02:09,440 --> 00:02:12,910
So like I said,
Zerocoin is an Altcoin, and

42
00:02:12,910 --> 00:02:14,920
I'm going to call that Altcoin basecoin.

43
00:02:14,920 --> 00:02:18,080
I'm not calling it Zerocoin because
Zerocoin is something else.

44
00:02:18,080 --> 00:02:19,580
It's an extension of this basecoin.

45
00:02:19,580 --> 00:02:22,189
It's something that sort of
sits on top of this Altcoin.

46
00:02:24,410 --> 00:02:28,010
And the key property that gives
the anonymity is that these basecoins

47
00:02:28,010 --> 00:02:32,990
can be converted into zerocoins and
back again, and when you

48
00:02:32,990 --> 00:02:37,470
do that it breaks the link between the
original basecoin and the new basecoin.

49
00:02:38,610 --> 00:02:41,890
So think of this as
a cryptographic mixing system.

50
00:02:41,890 --> 00:02:43,620
That's provided by the protocol itself.

51
00:02:45,100 --> 00:02:45,930
So how might this work?

52
00:02:47,310 --> 00:02:51,850
Another way of looking at a Zerocoin
is that it's a cryptographic proof

53
00:02:51,850 --> 00:02:55,100
that you own the Basecoin,
not anymore, but you owned it.

54
00:02:55,100 --> 00:02:56,480
And then you made it unspendable.

55
00:02:57,950 --> 00:03:00,330
A Zerocoin is something that
allows you to assert that,

56
00:03:00,330 --> 00:03:01,740
to say any miner who might care.

57
00:03:03,110 --> 00:03:08,280
And miners can verify these proofs and
that's what gives you the right to later

58
00:03:08,280 --> 00:03:12,650
redeem a new Basecoin in exchange for
the Zerocoin.

59
00:03:12,650 --> 00:03:14,600
And the analogy is a little
bit like poker chips.

60
00:03:16,060 --> 00:03:17,030
So how could that work,

61
00:03:17,030 --> 00:03:20,049
and what properties do these proofs
need to have in order to enable this?

62
00:03:21,750 --> 00:03:23,940
So one challenge is how to
construct these proofs.

63
00:03:23,940 --> 00:03:28,510
And the other trick is how do you make
sure that each proof can be spent only

64
00:03:28,510 --> 00:03:31,420
once, can be used only once
to redeem a base client?

65
00:03:31,420 --> 00:03:33,130
Because if you don't have that property,

66
00:03:33,130 --> 00:03:34,630
then it's going to lead
to double spending.

67
00:03:36,240 --> 00:03:37,950
So let's see how to do that.

68
00:03:37,950 --> 00:03:41,720
It crucially involves a concept
called zero knowledge proofs.

69
00:03:41,720 --> 00:03:43,112
What are zero knowledge proofs?

70
00:03:43,112 --> 00:03:45,810
I'm going to tell you at a little
bit of an intuitive level,

71
00:03:45,810 --> 00:03:48,440
so I'm calling it crypto magic again.

72
00:03:48,440 --> 00:03:52,270
But, what it is is its a way for
somebody to prove a statement,

73
00:03:52,270 --> 00:03:58,930
without revealing any other information
that makes that statement true.

74
00:04:00,560 --> 00:04:02,460
You might be able to
prove a statement like,

75
00:04:02,460 --> 00:04:05,250
I know an input that hashes
to this particular value.

76
00:04:06,960 --> 00:04:09,900
I notice that if the input that you
had picked were long and random,

77
00:04:11,490 --> 00:04:15,400
if you did a proof in such a way that
you don't actually reveal the input,

78
00:04:16,730 --> 00:04:20,169
it won't necessarily allow somebody
else to infer what that input is.

79
00:04:22,220 --> 00:04:25,440
A more complex version of this
is you could say I know an input

80
00:04:25,440 --> 00:04:30,228
that hashes to some hash in a following
set of several different possible outputs.

81
00:04:30,228 --> 00:04:34,272
And the Zero-knowledge proves that
Zerocoin is going to use something that is

82
00:04:34,272 --> 00:04:36,488
very similar to the second category here.

83
00:04:38,787 --> 00:04:40,750
Let's dive in a little bit more.

84
00:04:40,750 --> 00:04:42,880
So, zerocoins are minted.

85
00:04:42,880 --> 00:04:45,190
They come into existence by minting.

86
00:04:45,190 --> 00:04:47,140
And anybody can do this.

87
00:04:48,310 --> 00:04:50,270
And zerocoins come in
standard denominations.

88
00:04:50,270 --> 00:04:54,780
Let's assume, for the rest of this,
that zerocoins are worth 1 basecoin each.

89
00:04:54,780 --> 00:04:57,404
You could also imagine multiple
denominations co-existing.

90
00:04:59,180 --> 00:05:00,700
How do you make a Zerocoin?

91
00:05:00,700 --> 00:05:02,750
Well, we're going to see
that in the next slide.

92
00:05:02,750 --> 00:05:03,870
But let me just say for

93
00:05:03,870 --> 00:05:07,650
now that minting a Zerocoin doesn't
automatically give it any value.

94
00:05:07,650 --> 00:05:09,130
You can't get free money.

95
00:05:09,130 --> 00:05:12,080
It only acquires value once you
put it onto the block chain.

96
00:05:12,080 --> 00:05:15,730
And so putting it on to the block chain
is going to be about as expensive

97
00:05:15,730 --> 00:05:19,910
as the value of that zerocoin that
you're later going to be able to redeem.

98
00:05:21,230 --> 00:05:23,590
So you have some sort of
a conservation principle here.

99
00:05:25,660 --> 00:05:26,310
Okay.

100
00:05:26,310 --> 00:05:29,470
So here's how specifically
in cryptographic terms

101
00:05:29,470 --> 00:05:31,380
how we mint a Zerocoin.

102
00:05:31,380 --> 00:05:34,340
It's something called
a cryptographic commitment.

103
00:05:34,340 --> 00:05:38,800
What a cryptographic commitment is is
intuitively you can think of it as

104
00:05:38,800 --> 00:05:40,570
you're taking a serial number.

105
00:05:40,570 --> 00:05:42,800
A random serial number that you generated.

106
00:05:42,800 --> 00:05:44,170
And putting it into an envelope.

107
00:05:45,700 --> 00:05:48,420
So this intuitive notion of
putting it into an envelope,

108
00:05:48,420 --> 00:05:50,690
cryptographically what
does that correspond to?

109
00:05:50,690 --> 00:05:55,340
What it corresponds to is
generating another random secret r,

110
00:05:55,340 --> 00:05:58,720
which you're never going
to make public and

111
00:05:58,720 --> 00:06:04,130
computing the hash of the coin serial
number together with this random secret.

112
00:06:04,130 --> 00:06:08,060
Now this is a little bit of a
simplification, but it really helps you to

113
00:06:08,060 --> 00:06:10,990
understand the properties of the system,
so let's go with this description.

114
00:06:12,600 --> 00:06:14,410
So what just happened here?

115
00:06:14,410 --> 00:06:18,990
You generated arbitrarily, just like
you generate Bitcoin public keys,

116
00:06:18,990 --> 00:06:21,760
a serial number for your zerocoin.

117
00:06:21,760 --> 00:06:23,000
And if it were long and random,

118
00:06:23,000 --> 00:06:26,550
hopefully no one else has ever picked
that same serial number before.

119
00:06:28,760 --> 00:06:32,320
And you also generated this other random
number that you're going to keep secret.

120
00:06:33,800 --> 00:06:36,600
And intuitively, generating a commitment

121
00:06:36,600 --> 00:06:41,280
to the serial number corresponds to
putting it in an envelope and sealing it.

122
00:06:42,450 --> 00:06:46,770
And mathematically, it happens by
computing the hash of the serial number

123
00:06:46,770 --> 00:06:47,970
together with this random value.

124
00:06:49,690 --> 00:06:54,190
Once you've generated this commitment,
what do you do with that?

125
00:06:54,190 --> 00:06:57,130
At the next step is to put that
commitment onto the block chain.

126
00:06:58,920 --> 00:07:01,830
That's when the zerocoin
sort of becomes real.

127
00:07:01,830 --> 00:07:06,680
And doing this requires,
in a sense, burning a basecoin and

128
00:07:06,680 --> 00:07:08,380
making it unspendable.

129
00:07:08,380 --> 00:07:11,070
So, in concrete terms,
how would that work?

130
00:07:11,070 --> 00:07:13,690
You've got the block chain over here, and

131
00:07:13,690 --> 00:07:16,530
one of those transactions
might be a mint transaction.

132
00:07:16,530 --> 00:07:20,310
And if you zoomed in, it would be
a transaction that's signed by Alice,

133
00:07:20,310 --> 00:07:23,810
who created this zerocoin,
who minted the zerocoin.

134
00:07:25,422 --> 00:07:29,980
And what we saw early in the structure
of transactions is that over here,

135
00:07:29,980 --> 00:07:33,850
you would have the recipient's public,
the recipient's.

136
00:07:33,850 --> 00:07:36,859
Instead of that, here you have
this cryptographic commitment.

137
00:07:39,430 --> 00:07:43,140
And just like before, just like a
transaction having a pointer to a previous

138
00:07:43,140 --> 00:07:48,870
transaction, the same structure is carried
over for zero coin transactions as well.

139
00:07:48,870 --> 00:07:50,270
So, what has happened here,

140
00:07:50,270 --> 00:07:54,750
we've spent the space coin in
order to mint the zero coin.

141
00:07:54,750 --> 00:07:58,770
And this commitment, the sealed envelope
that we've put into the zero coin

142
00:07:58,770 --> 00:08:03,030
that's what is going to allow us to redeem
that zerocoin later in exchange for

143
00:08:03,030 --> 00:08:03,990
a basecoin once again.

144
00:08:06,430 --> 00:08:08,040
So how does that work?

145
00:08:08,040 --> 00:08:10,070
To spend the zerocoin later,

146
00:08:10,070 --> 00:08:14,170
you will reveal that serial number
that you put inside the envelope.

147
00:08:14,170 --> 00:08:15,650
And what miners will do,

148
00:08:15,650 --> 00:08:20,460
it's their job to verify that the serial
number has not been spent before.

149
00:08:20,460 --> 00:08:22,640
That the serial number
has not been revealed,

150
00:08:22,640 --> 00:08:25,200
as a number that was put
inside some other envelope.

151
00:08:25,200 --> 00:08:26,910
That's what prevents double
spending in the system.

152
00:08:28,550 --> 00:08:32,390
Next you'll create a zero knowledge
proof that we just talked about, and

153
00:08:32,390 --> 00:08:34,550
specifically the zero
knowledge proof will say,

154
00:08:34,550 --> 00:08:39,480
I know a number r such that
the hash of the serial number

155
00:08:39,480 --> 00:08:44,420
together with r corresponds to one
of the zerocoins of the block chain.

156
00:08:44,420 --> 00:08:47,670
And we'll make that statement more
mathematically precise in a second.

157
00:08:47,670 --> 00:08:48,910
But, think about what this says.

158
00:08:48,910 --> 00:08:52,180
It doesn't reveal that random number r,
but

159
00:08:52,180 --> 00:08:54,940
somehow you're proving that you
are in possession of that number.

160
00:08:56,050 --> 00:08:58,519
Combined with the serial number
that you have just made public

161
00:09:00,020 --> 00:09:05,100
Will result in the zerocoin that was once
in the past, put onto the block chain.

162
00:09:06,620 --> 00:09:07,340
Right.
So for

163
00:09:07,340 --> 00:09:11,230
somebody looking at this proof,
this is all they need to know

164
00:09:11,230 --> 00:09:15,980
to verify that you earlier spent a base
coin in order to get to this point.

165
00:09:15,980 --> 00:09:20,095
So this now, should give you
the right to redeem a basecoin.

166
00:09:21,220 --> 00:09:21,980
But which basecoin?

167
00:09:21,980 --> 00:09:24,770
And here's where the anonymity
property comes in.

168
00:09:24,770 --> 00:09:28,880
You can pick an arbitrary
zerocoin in the block chain and

169
00:09:28,880 --> 00:09:34,960
use that as an input to a new transaction
out of which comes a base coin and

170
00:09:34,960 --> 00:09:36,280
miners will allow you to do that.

171
00:09:36,280 --> 00:09:38,330
All right?

172
00:09:38,330 --> 00:09:41,039
So, put a zerocoin in, take a zerocoin
out, but a different zerocoin.

173
00:09:42,640 --> 00:09:45,710
And all that anybody needs to know is
that you have the right to do that

174
00:09:45,710 --> 00:09:47,740
because you put in some
zerocoin in the past.

175
00:09:47,740 --> 00:09:50,250
It doesn't matter which zerocoin.

176
00:09:50,250 --> 00:09:54,610
And you can do that twice, you can spend
twice corresponding to a single mint

177
00:09:54,610 --> 00:09:57,760
because the serial number
now will become public and

178
00:09:57,760 --> 00:10:00,880
there's only one serial number
corresponding to one zerocoin.

179
00:10:00,880 --> 00:10:03,791
And you only know the serial numbers
corresponding to your zero coins and

180
00:10:03,791 --> 00:10:05,088
not anyone else's zerocoins.

181
00:10:07,525 --> 00:10:08,210
Great.

182
00:10:08,210 --> 00:10:10,930
So, where does the anonymity
property come from?

183
00:10:10,930 --> 00:10:12,460
Here's the anonymity property.

184
00:10:12,460 --> 00:10:14,550
Since you have kept this
random number r a secret.

185
00:10:16,090 --> 00:10:18,000
And this is what is available
on the block chain.

186
00:10:18,000 --> 00:10:20,970
There are a number of hashes or
commitments corresponding to

187
00:10:20,970 --> 00:10:23,150
the different zerocoins that have
been put on the block chain.

188
00:10:25,050 --> 00:10:29,860
Even though you've revealed the serial
number Not knowing this other random input

189
00:10:29,860 --> 00:10:33,040
r,, nobody can try to brute force this and

190
00:10:33,040 --> 00:10:37,370
guess which of these zero coins
corresponded to your serial number.

191
00:10:37,370 --> 00:10:41,150
So even after the serial number
inside an envelope has been revealed,

192
00:10:41,150 --> 00:10:45,340
and it's been verified that this serial
number was inside one of the envelopes,

193
00:10:45,340 --> 00:10:47,700
we still don't know which
serial number it is.

194
00:10:47,700 --> 00:10:52,326
So this is the sort of magical property
that zero cryptography give us that you

195
00:10:52,326 --> 00:10:56,517
wouldn't get in a real world,
physical world base analogy of this.

196
00:10:59,385 --> 00:11:03,727
So the next cool thing about this whole
construction is the fact that these

197
00:11:03,727 --> 00:11:07,384
proofs are efficient I'm putting
efficient in quotes here.

198
00:11:07,384 --> 00:11:09,768
The sense in which they're
efficient is that,

199
00:11:09,768 --> 00:11:13,819
compared to what we know of zero knowledge
proofs and have come to expect on them,

200
00:11:13,819 --> 00:11:17,599
it's quite an achievement that these
proofs are as efficient as they are.

201
00:11:17,599 --> 00:11:21,798
However, compared to the efficiency
of Bitcoin transactions themselves,

202
00:11:21,798 --> 00:11:23,800
these are in fact quite slow.

203
00:11:23,800 --> 00:11:25,670
It occupies a space in between those two.

204
00:11:26,880 --> 00:11:31,860
So exactly what I mean by efficient,
the reason it's efficient is that it

205
00:11:31,860 --> 00:11:37,230
manages to avoid being linear in
the number of zerocoins on the chain,

206
00:11:37,230 --> 00:11:39,370
even though that's what you would expect.

207
00:11:39,370 --> 00:11:41,090
Why is that what you would expect?

208
00:11:41,090 --> 00:11:45,620
Think about the statement that
the spender is proving here.

209
00:11:45,620 --> 00:11:51,540
I know a random number r such that either
the hash of the serial number with

210
00:11:51,540 --> 00:11:55,910
r corresponds to the first commitment, or
the first hash, or the second commitment.

211
00:11:55,910 --> 00:11:58,810
Or any one of these giant
number of commitments

212
00:11:58,810 --> 00:12:00,840
that reside on the block chain.

213
00:12:00,840 --> 00:12:04,740
So it's a very long statement
that the prover is proving.

214
00:12:04,740 --> 00:12:07,570
It's a statement whose
length is proportional

215
00:12:07,570 --> 00:12:09,340
to the number of zercoins
on the block chain.

216
00:12:10,350 --> 00:12:12,500
And yet,
the proof is much smaller than that.

217
00:12:12,500 --> 00:12:17,470
It's not linear,
it's only logarithmic in the value N here.

218
00:12:17,470 --> 00:12:19,432
And that's part of the magic of zerocoin,

219
00:12:19,432 --> 00:12:21,948
that's what makes it possible
to even run the system.

220
00:12:24,304 --> 00:12:28,520
All right, moving on,
let's talk about Zerocash now.

221
00:12:28,520 --> 00:12:32,330
Zerocash kind of takes the cryptography
sort of to the next level.

222
00:12:32,330 --> 00:12:36,900
It uses a cryptographic tool called
Snarks which we won't get into at all.

223
00:12:36,900 --> 00:12:38,260
But the upshot of that,

224
00:12:39,400 --> 00:12:43,290
the upshot of the use of these more
efficient cryptographic constructions for

225
00:12:43,290 --> 00:12:48,030
proofs Is that the efficiency gets
to a point where the authors suggest

226
00:12:48,030 --> 00:12:51,600
that you can in fact run the whole
system without having any base coin.

227
00:12:53,500 --> 00:12:56,922
All transactions can be done
in the zero-knowledge matter.

228
00:12:58,415 --> 00:13:02,075
You don't need to have separate expensive
transactions that are used only for

229
00:13:02,075 --> 00:13:06,665
mixing, and a set of regular everyday
transactions that you use when

230
00:13:06,665 --> 00:13:09,575
you don't want special anonymity
properties, that distinction is now gone.

231
00:13:11,005 --> 00:13:14,245
The claim is that you can run
all of these transactions

232
00:13:14,245 --> 00:13:18,335
sort of inside these envelopes, and
what I mean by that is the following.

233
00:13:20,050 --> 00:13:21,650
All transactions are zerocoins, and

234
00:13:21,650 --> 00:13:25,450
so zerocash becomes untraceable in
a sense because there is no base coin.

235
00:13:27,100 --> 00:13:31,650
And the reason for that is that spilling
and merging of coins are also transactions

236
00:13:31,650 --> 00:13:35,130
that are supported in zero cash
itself without going to basecoin.

237
00:13:35,130 --> 00:13:40,540
And in particular, the transaction value
is the transaction amounts You can put

238
00:13:40,540 --> 00:13:45,720
those inside the commitments, those won't
be visible on the block chain anymore.

239
00:13:45,720 --> 00:13:48,620
The only thing that
the ledger records publicly,

240
00:13:48,620 --> 00:13:50,240
is the existence of these transactions.

241
00:13:51,800 --> 00:13:56,110
You know that Alice put in some
transaction, you know much later that Bob

242
00:13:56,110 --> 00:13:59,940
retrieves some transaction, that might be
the same user, might be a different user,

243
00:13:59,940 --> 00:14:03,940
but the only people who need to know
what the amount is are the sender and

244
00:14:03,940 --> 00:14:05,870
the receiver of any
particular transaction.

245
00:14:05,870 --> 00:14:07,560
The miners don't need to know that.

246
00:14:07,560 --> 00:14:10,510
If there's a transaction fee then
the miners need to know that fee.

247
00:14:10,510 --> 00:14:13,770
But that doesn't really compromise
your anonymity properly.

248
00:14:15,550 --> 00:14:20,870
So the ability to run zero coin in it's
different configuration where it's

249
00:14:20,870 --> 00:14:25,860
not two different coins anymore, it's not
a base coin with a mixed layer on top, but

250
00:14:25,860 --> 00:14:29,540
instead an entirely untraceable
system of transactions,

251
00:14:29,540 --> 00:14:33,360
puts Zerocash sort of in the next
level when it comes to anonymity.

252
00:14:33,360 --> 00:14:37,600
Because a lot of the possible side channel
attacks that were true for mixing, that

253
00:14:37,600 --> 00:14:43,200
were true to a certain extent at least for
Zerocoin, are no longer true for Zerocash,

254
00:14:43,200 --> 00:14:47,790
because the transaction amounts will no
longer be visible in the public ledger.

255
00:14:47,790 --> 00:14:50,110
But that almost sounds
too good to be true,

256
00:14:50,110 --> 00:14:53,650
a completely untraceable
electronic cash system.

257
00:14:53,650 --> 00:14:54,940
It is ledger-based, but

258
00:14:54,940 --> 00:14:58,850
the ledger doesn't record anything that
might compromise anonymity or privacy.

259
00:14:58,850 --> 00:15:00,500
Well there is one catch.

260
00:15:00,500 --> 00:15:02,580
Here's the catch in zerocash,

261
00:15:02,580 --> 00:15:06,150
it requires a certain setup
process to even set up the system.

262
00:15:06,150 --> 00:15:08,800
Specifically one needs random and

263
00:15:08,800 --> 00:15:11,560
secret inputs in order to
generate the public parameters.

264
00:15:11,560 --> 00:15:15,010
Think of those as public keys,
except that these are giant public keys,

265
00:15:15,010 --> 00:15:16,699
they're over a gigabyte in size.

266
00:15:18,500 --> 00:15:22,800
And not only that, not only is the size a
bit of a problem, these secret inputs for

267
00:15:22,800 --> 00:15:26,540
the security of the system then
have to be securely destroyed, so

268
00:15:26,540 --> 00:15:29,510
that nobody knows what
those secret inputs were

269
00:15:29,510 --> 00:15:31,900
that were used in order to
generate these public parameters.

270
00:15:33,420 --> 00:15:34,930
That seems like a bit of a problem.

271
00:15:34,930 --> 00:15:38,310
And the reason that no one can know
them is because if somebody knows them,

272
00:15:38,310 --> 00:15:41,170
it doesn't mean that they will be
able to compromise anonymity, but

273
00:15:41,170 --> 00:15:44,860
they will be able to create new
zerocoins for themselves and

274
00:15:44,860 --> 00:15:48,700
nobody will be the wiser, which is also
an equally bad problem for the currency.

275
00:15:50,360 --> 00:15:53,180
So it's kind of an interesting
sociological problem here.

276
00:15:53,180 --> 00:15:56,910
How could some entity set up this system,

277
00:15:56,910 --> 00:16:00,210
and then convince everybody that
they have securely destroyed

278
00:16:00,210 --> 00:16:03,460
the parameters that were of course
necessary to set up the system?

279
00:16:04,600 --> 00:16:07,010
So it's not entirely clear
how that can be solved.

280
00:16:07,010 --> 00:16:09,221
There have been various proposals for
us, but

281
00:16:09,221 --> 00:16:12,689
at the moment we don't have a very clear
idea of how to go forward on this.

282
00:16:14,210 --> 00:16:15,209
So what have we seen so

283
00:16:15,209 --> 00:16:18,430
far in all of the different efforts
to improve anonymity in Bitcoin?

284
00:16:19,680 --> 00:16:22,660
Well, if we put them on a line,
as I'll show you in a second,

285
00:16:22,660 --> 00:16:26,360
we see that there are five clearly
different levels of anonymity

286
00:16:26,360 --> 00:16:31,230
that we've seen in different
proposed solutions.

287
00:16:31,230 --> 00:16:32,700
And what are these?

288
00:16:32,700 --> 00:16:36,760
So, let's look at not only the levels of
anonymity that these systems provide, but

289
00:16:36,760 --> 00:16:39,480
also the deployability of these systems.

290
00:16:39,480 --> 00:16:42,490
Let's start with Bitcoin,
which is already here.

291
00:16:42,490 --> 00:16:45,719
It's only pseudonymous, it doesn't
even aspire to be really anonymous.

292
00:16:47,380 --> 00:16:50,690
And we've seen that pretty bad
transaction graph analysis are possible.

293
00:16:50,690 --> 00:16:54,030
I showed you many beautiful graphs with
a clustering of different address and

294
00:16:54,030 --> 00:16:56,770
in many cases how to go from
those addresses to identities.

295
00:16:58,160 --> 00:17:00,970
So, not a lot of anonymity
provided by Bitcoin.

296
00:17:00,970 --> 00:17:05,340
The next level is simply using a single
mix stirred up in a manual way in which

297
00:17:05,340 --> 00:17:08,059
people are doing right now with some
of these dedicated mix services.

298
00:17:09,790 --> 00:17:13,010
And that still allows you
transaction graph analysis,

299
00:17:13,010 --> 00:17:17,220
because, as you might remember from
the four principles that I gave you,

300
00:17:17,220 --> 00:17:20,560
if you don't have this automated system
that has uniform chunk sizes and so on,

301
00:17:20,560 --> 00:17:23,600
a lot of transaction graph
analysis is still possible.

302
00:17:23,600 --> 00:17:24,520
And in addition,

303
00:17:24,520 --> 00:17:28,700
you have to worry that this mix might not
be trustworthy as storing records and

304
00:17:28,700 --> 00:17:32,100
might be sharing them with other people,
and, again, could get hacked, etc.

305
00:17:33,930 --> 00:17:37,100
The third level that we saw
is a chain of mixes, and

306
00:17:37,100 --> 00:17:40,110
this can be in a centralized model or
a decentralized model.

307
00:17:40,110 --> 00:17:40,740
It doesn't matter.

308
00:17:40,740 --> 00:17:43,980
Both models give you roughly
the same level of anonymity.

309
00:17:43,980 --> 00:17:47,780
But where really the anonymity improvement
comes in, for this one compared to

310
00:17:47,780 --> 00:17:52,050
a single mix, is that, you have
these standardized chunk sizes, and

311
00:17:52,050 --> 00:17:56,690
you have a series of mixes, and
you have a variety of other bells and

312
00:17:56,690 --> 00:17:59,240
whistles on top of it,
like automated clients and so on.

313
00:18:00,660 --> 00:18:03,550
And for this,
some side channels are still possible,

314
00:18:03,550 --> 00:18:08,430
not as bad as before, transaction
graph analysis is no longer that easy.

315
00:18:08,430 --> 00:18:13,340
And you still have to worry about an
adversary who might collude with multiple

316
00:18:13,340 --> 00:18:17,540
mixes or, in the decentralized model,
some peers that might be malicious and

317
00:18:17,540 --> 00:18:18,640
compromise your anonymity.

318
00:18:19,850 --> 00:18:22,700
This is, of course, perfectly
backward compatible with Bitcoin.

319
00:18:22,700 --> 00:18:25,360
Could be deployed and adopted any day.

320
00:18:25,360 --> 00:18:28,659
Hasn't quite happened yet in a way that
we would consider to be truly anonymous.

321
00:18:30,990 --> 00:18:31,980
And then we saw zerocoin,

322
00:18:31,980 --> 00:18:37,160
which is cryptographic mixing baked into
the protocol, doesn't depend on anybody

323
00:18:37,160 --> 00:18:39,810
promising to destroy their records or
anything like that.

324
00:18:39,810 --> 00:18:41,120
You just need to trust them out.

325
00:18:41,120 --> 00:18:43,700
So that's a whole different
level of anonymity.

326
00:18:43,700 --> 00:18:46,950
In my opinion, it still has some
possible side channels, but

327
00:18:46,950 --> 00:18:50,530
it's not as bad as the other
mixing-based solutions that we saw,

328
00:18:50,530 --> 00:18:52,070
where it's not baked into the protocol.

329
00:18:53,290 --> 00:18:55,780
And Zerocoin of course
as we saw is an Altcoin.

330
00:18:55,780 --> 00:19:00,240
So it's not quite Bitcoin compatible
in a way that one might hope.

331
00:19:00,240 --> 00:19:01,800
And finally, Zerocash.

332
00:19:01,800 --> 00:19:04,770
The difference between Zerocash and
Zerocoin is not so

333
00:19:04,770 --> 00:19:08,850
much at a fundamental mathematical level,
but because of the fact that you can

334
00:19:08,850 --> 00:19:12,890
run Zerocash in a configuration where
you get rid of the base coin altogether.

335
00:19:12,890 --> 00:19:17,430
The efficiency is not too
bad in that configuration.

336
00:19:18,980 --> 00:19:20,800
What that gives you is untraceability,

337
00:19:20,800 --> 00:19:22,550
which is something on
top of unlinkability.

338
00:19:23,800 --> 00:19:25,130
That's a new anonymity property.

339
00:19:26,420 --> 00:19:32,090
There really aren't any anonymity
attacks that I can think of at least.

340
00:19:32,090 --> 00:19:35,777
The downside of course is that not only
is it Altcoin, but it also has this very

341
00:19:35,777 --> 00:19:39,542
tricky setup process that we don't
necessarily know how to make progress on.

