Bitcoin Forum
April 30, 2024, 05:42:11 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: "Mintchip is designed to track you" claims anonymous insider  (Read 1463 times)
Peter Todd (OP)
Legendary
*
Offline Offline

Activity: 1120
Merit: 1150


View Profile
August 17, 2012, 04:58:53 AM
 #1

Interesting post on Slashdot today:

Quote
it's about time I clear my conscience...

The system keeps track of what funding sources you've been "in contact" with, kinda like Bitcoin's idea of "taint"

The implementation is quite clever, involving some modular arithmetic and the 24-byte "Transaction Authentication Code" detailed in the Mintchip Messages [mintchipchallenge.com] documentation. Or I should say, revealed... of course they're not telling you what the TAC does because they don't want to admit it's true purpose. It's also not just the TAC, all those supposedly random nonces generated by the hardware aren't going to be as random as you'd think. Basically you can use them as an additional way of stenographically hiding data between transactions that goes way beyond what they document.

I can't reveal too many details on how it works as they'd probably figure out who I am, but essentially that's enough bits to encode a probabalistic record of every Sender ID that has transfered funds that ended up in your balance. Then when you resend your balance, you "infect" subsequent Mintchip balances with that record.

I'll give an toy example to prove the point: lets suppose you assigned prime number to every user of the system. If the TAC were simply multiplied by each prime from every payer, you could then factor the resulting large product of primes to determine who the payers were. The actual implementation is more involved, and probabalistic, but you get the idea. Sure it essentially becomes a brute forcing problem, but when you have a rough idea of who might be paying who, brute forcing is a lot easier than you'd think. Canada's population is only a bit over 30 million...

Don't trust closed hardware or software. You have been warned. This may look like a anonymous Bitcoin competitor, but the mint isn't stupid, and they're not going to give back any of the anonymity cash provided that the government wants so badly to get rid of.
-http://news.slashdot.org/comments.pl?sid=3051283&cid=41008501

Also reddit discussion here: http://www.reddit.com/r/canada/comments/ybn40/mintchip_is_designed_to_track_you_anonymous/

Sounds like the crypto is plausible, although who knows if the guy is legit. Nothing we didn't already suspect of course, but it's a clear way it could be done.

1714498931
Hero Member
*
Offline Offline

Posts: 1714498931

View Profile Personal Message (Offline)

Ignore
1714498931
Reply with quote  #2

1714498931
Report to moderator
According to NIST and ECRYPT II, the cryptographic algorithms used in Bitcoin are expected to be strong until at least 2030. (After that, it will not be too difficult to transition to different algorithms.)
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
NASDAQEnema
Full Member
***
Offline Offline

Activity: 182
Merit: 100


View Profile
August 17, 2012, 06:31:38 AM
 #2

Jesus fuck.

I'm gonna be so fucking busy this fall with my crews dealing with this shit.

OpTrapWire, MintChip.

Fine. Expect us.

If you feel Universe has trolled you exclusively, please donate to Emergency Butthurt Support Fund:
1Jv4wa1w4Le4Ku9MZRxcobnDFzAUF9aotH
Proceeds go to Emergency Butthurt Escape Pod none of you will be allowed to use. If you have read this far, you must pay Emergency Butthurt Internet Tax.
Endgame
Sr. Member
****
Offline Offline

Activity: 412
Merit: 250



View Profile
August 17, 2012, 02:30:34 PM
 #3

It will be interesting to see whether mintchip is able to gain any traction with users if that is the approach it adopts. The pseudo-anonymity bitcoin provides seems much more desirable than this kind of implementation
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!