Post
Topic
Board Altcoin Discussion
Re: XMR vs DRK
by
ArticMine
on 27/03/2015, 20:45:24 UTC
Quote

This assumes that one un-compromised round of Darksend is enough.

Enough for what? Could you elaborate please?

For the level of privacy / fungibility desired by the user. For example in his paper http://cdn.anonymousbitcoinbook.com/darkcoin/darksend-paper/Atlas_Darksend-Analysis-v001.pdf Kristov proposes using multiple levels of Darksend to mitigate the impact of a Sybil attack.
Quote
Users can reduce the impact of Sybil attacking peers by increasing the number of rounds of Darksend+ they require their funds to go through in order to be “anonymized.” Increasing the minimum number of Darksend+ peers per mixing transaction also increases the amount of work required for would-be Sybil attackers.

One of the problems with the probability arguments that have been made by many Darkcoin/Dash proponents is that they only apply for the most basic level of protection. When one starts to combine attacks then these arguments break down. For multiple rounds of Darksend to provided additional protection one needs a sequence of un-compromised masternodes. So it is not for example the probability of getting a single Darksend round that is un-compromised, with a partially compromised masternode network, it is the probability of getting for example 4 Darksend rounds in sequence out of a 20 round Darksend with a partially compromised masternode network that matters.

Edit: With Monero I can increase my privacy /  fungibility by increasing the mixing level. The equivalent in Darkcoin/Dash to a large degree is to increase the number of rounds of Darksend. The problem is that this will not work with a partially compromised masternode network. I could very likely still end up with and effective Darksend of 1 round. One the Monero side MRL0004 provided an excellent discussion of some of these risks. https://lab.getmonero.org/pubs/MRL-0004.pdf