Post
Topic
Board Altcoin Discussion
Re: rpietila Altcoin Observer
by
smooth
on 27/07/2014, 03:17:26 UTC
As I wrote upthread, I don't think that 5 or 6x calculation is accurate. Because someone told me that Monero currently has a limitation wherein you can't mix too many inputs (incorrect?), so you need to mix multiple times to achieve the same level of mixing you would with one transaction without the limit. Thus many of the transactions are multiple mixes for the same transaction, thus the real bloat is orders-of-magnitude higher than Bitcoin.

People are going to decide what degree of mixing is necessary for their threat model, and we don't know yet what will be typical.

To avoid massive (big data scale) linking and analysis of the entire blockchain, it may be that small mixes of 2 or 3 are sufficient. Even these offer an exponential explosion of paths once the tracing goes through multiple transactions (as opposed to mixes of 1, which offers no such explosion i.e. bitcoin).

As for mixes-of-mixes, those are more efficient than flat mixing (though perhaps vulnerable to some forms of analysis especially if not done carefully). If we assume everyone mixes with mix=2 five times there is an ambiguity factor of 32 to the original source of funds, yet the increase in total signature size on each transaction is only 9. This still does not get to orders of magnitude. Note that you don't need to create all the mix paths, only one path to the true source, because there is no way to identify which path leads back to it.