SlideShare a Scribd company logo
[ An introduction to ]
Jérémie Dubois-Lacoste – Arne Brutschy
jeremie|arne@cryptosphere-systems.com
Geneva
An Introduction to Monero
Intro
Who are we?
Three guys with a PhD
We help you build blockchain-based applicaions
Specializations
cryptocurrencies down to the nuts and bolts
scalable algorithms and scalable systems
security and dev ops
Experience: Several crypto apps deployed
2 / 45
An Introduction to Monero
Intro
Disclaimer
We own bitcoins and moneros
We’re geeks and computer scientists, not economists
3 / 45
An Introduction to Monero
Outline
Outline
Privacy, Fungibility, and Bitcoin
Monero’s Privacy Improvements
Summary
XMR.TO
4 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Outline
Privacy, Fungibility, and Bitcoin
Privacy in Bitcoin
Fungibility?
Fungibility in decentralized currencies
Monero’s Privacy Improvements
Summary
XMR.TO
5 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Financial Privacy
Financial privacy is important for a payment system
Anti-money laundering laws, taxation, etc. are possible
even when the payment system ensures privacy
6 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Privacy in Bitcoin
Privacy in Bitcoin
Bitcoin is not anonymous, it is pseudonymous. Pseudonymity is
very fragile in daily life:
Linking of transactions reduces privacy;
Usage leaves traces everywhere on the Internet;
Privacy-enhancing measures (tumblers/CoinJoin etc.) are
costly.
As a result, the analysis of the Bitcoin blockchain can reveal
identities.
7 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Privacy in Bitcoin
Practical ways to analyse the blockchain
Change addresses
Correlation of transactions
Addresses of public
services (pools,
exchanges, merchants,
etc.)
Leaked business records
Scraping of web resources
. . .
8 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Privacy in Bitcoin
Bitcoin blockchain analysis: a booming field
Network-focused blockchain analysis is a thriving research
field since a few years already.
Today, an increasing number of high-level analysis tools
are available:
https://bitiodine.net/
http://coinalytics.co/
http://www.quantabytes.com/
. . .
Permanent nature of blockchain ensures that privacy only
ever decreases!
9 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Fungibility?
What is fungibility?
Formal definition
Fungibility is the property of a good or a commodity whose
individual units are capable of mutual substitution.
That is, it is the property of essences or goods which are
“capable of being substituted in place of one another.”
TL;DR: Fungibility means that units are interchangable.
10 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Fungibility?
Why do we care?
Fungibility is a fundamental property of currencies.
In centralized currencies, fungibility is guaranteed by the
government.
. . . and in decentralized currencies?
11 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Fungibility in decentralized currencies
The formal description of Bitcoin:
Information exchange protocol, that allows the transfer of units
of account; These units behave like the money we are used to,
having these properties:
Durability
Portability
Divisibility
Relatively rare
Fungibility
12 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Fungibility in decentralized currencies
Is Bitcoin really fungible?
Social pressure not to accept tainted coins (theft/fraud. . . )
If privacy can be broken, fungibility is voluntary.
The lack of privacy in Bitcoin threatens its fungibility.
Services that track taint render bitcoins non-fungible, eg.:
http://www.coinvalidation.com/
http://coinalytics.co/
https://chainalysis.com/
13 / 45
An Introduction to Monero
Privacy, Fungibility, and Bitcoin
Fungibility in decentralized currencies
What can we learn from Bitcoin?
Voluntary fungibility does not work.
Fungibility in cryptocurrencies requires privacy.
People becoming more aware of the fungibility issue in
Bitcoin.
Many approaches to fix this exist nowadays.
14 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Outline
Privacy, Fungibility, and Bitcoin
Monero’s Privacy Improvements
Unlinkability and Untraceability
Stealth Addresses
Ring Signatures
Viewkeys
Summary
XMR.TO
15 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Unlinkability and Untraceability
16 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Unlinkability and Untraceability
17 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Unlinkability and Untraceability
Simple analogy
Unlinkability: I don’t know who are the children of X
Untraceability: I don’t know who are the parents of X
18 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Unlinkability and Untraceability
Monero’s approach
Unlinkability: I don’t know who are the children of X
→ Monero uses stealth addresses
Untraceability: I don’t know who are the parents of X
→ Monero uses ring signatures
19 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Stealth Addresses
Outline
Privacy, Fungibility, and Bitcoin
Monero’s Privacy Improvements
Unlinkability and Untraceability
Stealth Addresses
Ring Signatures
Viewkeys
Summary
XMR.TO
20 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Stealth Addresses
Stealth addresses (1)
The “destination” for each output is derived from the
Monero address, it is different everytime
Only the owner of the Monero address knows that an
output is for him
21 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Stealth Addresses
Stealth addresses (2)
Now Charlie can give his Monero address to everybody:
Each output sent to Charlie will look to observers as
having different destinations
Nobody can tell these outputs are going to Charlie
Nobody can even tell these outputs are going to the same
person
22 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Stealth Addresses
Stealth addresses (3)
Side remark:
Stealth addresses discussed and proposed for Bitcoin too.
Feasible but not very practical: requires exchange of
information beforehand (either with a secure channel or an
elaborated use of OP_RETURN).
23 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Outline
Privacy, Fungibility, and Bitcoin
Monero’s Privacy Improvements
Unlinkability and Untraceability
Stealth Addresses
Ring Signatures
Viewkeys
Summary
XMR.TO
24 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
A ring signature
A group of cryptographic signatures with at least one real
participant, but no way to tell which in the group is the real
one as they all appear valid.
25 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Real world analogy
“Say some unpopular military attack has to be ordered, but
nobody wants to go down in history as the one who ordered it.
If 10 leaders have private keys, one of them could sign the
order and you wouldn’t know who did it.”
26 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Real world analogy
“Say some unpopular military attack has to be ordered, but
nobody wants to go down in history as the one who ordered it.
If 10 leaders have private keys, one of them could sign the
order and you wouldn’t know who did it.”
Can you find the author of this quote?
26 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Brilliant idea: apply it to cryptocurrencies!
“Crypto may offer a way to do "key blinding". I did some
research and it was obscure, but there may be something
there. "group signatures" may be related.”
27 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Brilliant idea: apply it to cryptocurrencies!
“Crypto may offer a way to do "key blinding". I did some
research and it was obscure, but there may be something
there. "group signatures" may be related.”
And now, can you find the author of the quotes?
27 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Foreseen in 2010 by... Satoshi Nakamoto!
Satoshi on ring signatures, 13/08/2010:
Source: https://bitcointalk.org/index.php?topic=770#msg9074
28 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Ring signatures to achieve untraceability?
You want to spend output O of amount X, and send it all to Bob.
In Bitcoin:
You construct a transaction saying “I use output O, and
create a new output going to Bob’s address”
You sign this transaction with the private key of the address
that received the output O
In Monero:
You find some outputs in the blockchain with the same
amount X as your output O
You construct a transaction saying “I use one of these
outputs, and create a new output going to <stealth
destination>”
You sign this transaction using a ring signature
29 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Usual Bitcoin signature
30 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Monero equivalent
31 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Ring signatures achieve untraceability
Not only you are “mixing” your output when actually
spending it: everybody is constantly using other people’s
output in ring signatures, they will use yours too
No need for people controlling the other outputs in the ring
signature to be online or active
Combinatorial explosion kicks in very quickly and render
impractical forensic analysis of the blockchain
32 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Ok, ring signatures are cool! But...
Output spent using ring signature is not “spent for sure”:
how to prevent double-spend?
33 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Ok, ring signatures are cool! But...
Output spent using ring signature is not “spent for sure”:
how to prevent double-spend?
Signatures are deterministic, so spending the same output
twice can be detected easily
33 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Ok, ring signatures are cool! But...
Output spent using ring signature is not “spent for sure”:
how to prevent double-spend?
Signatures are deterministic, so spending the same output
twice can be detected easily
To spend my output of amount X using a ring signature, I
must find other outputs with the same amount X! Isn’t it
difficult?
33 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Ok, ring signatures are cool! But...
Output spent using ring signature is not “spent for sure”:
how to prevent double-spend?
Signatures are deterministic, so spending the same output
twice can be detected easily
To spend my output of amount X using a ring signature, I
must find other outputs with the same amount X! Isn’t it
difficult?
Outputs are automatically broken down into common
denominations. For instance, sending 11.5 XMR actually
creates an output of 10, plus another one of 1, plus another
one of 0.5.
Thus, always plenty of outputs with proper amount. And all
of them use their own ring sig!
33 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Summary of privacy aspects
Monero hides destination of transactions
Monero hides origin of transactions
Monero hides precise amount being transferred
There is no “rich list”: nobody can see the amount
associated to each address
34 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Ring Signatures
Ok, privacy is cool. But?...
Having a fully-private decentralized ledger is useful, but
also problematic
No way to comply in many tax jurisdictions
No way to prove a transaction was made in case of dispute
No way to be transparent about donations for a non-profit
No way to prove certain holding to ask for loans, etc.
35 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Viewkeys
Outline
Privacy, Fungibility, and Bitcoin
Monero’s Privacy Improvements
Unlinkability and Untraceability
Stealth Addresses
Ring Signatures
Viewkeys
Summary
XMR.TO
36 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Viewkeys
Viewkeys
A clever cryptographic mechanism, the “viewkey”. For each
address, you have:
A spend key (≈ Bitcoin private key)
Plus a viewkey
Give viewkey to somebody: they can see which outputs you
control (= what you received, and your balance).
Viewkey mechanism exists also for one single transaction only.
37 / 45
An Introduction to Monero
Monero’s Privacy Improvements
Viewkeys
Viewkey: transparency or privacy, user’s choice!
With optional, voluntary use of viewkeys, Monero
transparency becomes close to Bitcoin’s one
Monero provides high privacy by default whilst still
providing opt-in full transparency when desired
It does all of this at the (very elegant) cryptographic layer
38 / 45
An Introduction to Monero
Summary
Outline
Privacy, Fungibility, and Bitcoin
Monero’s Privacy Improvements
Summary
XMR.TO
39 / 45
An Introduction to Monero
Summary
More Cool Tech Stuff
Example: Monero has an adaptive block size.
Bitcoin: the maximum block size is hardcoded
(Ever heard of 1MB vs. 20MB debate?...)
Monero adapts the maximum block size with a simple rule
(very similar to mining difficulty adjustments).
Idea is that the size is determined by free market
mechanism.
40 / 45
An Introduction to Monero
Summary
Conclusion
Monero: a great future?
Demand for more fungible/private cryptocurrencies
Bitcoin is a decentralized fully transparent public ledger
We now have a technology for a decentralized
private-by-default/transparent-on-demand public ledger
Monero is the best contender currently for that role
- Electronic cash is easy. Facebook could do it.
- Private electronic cash is harder, but Chaum
figured out how to do it in the early 90s.
- Decentralized electronic cash is even harder.
That’s Bitcoin.
- Decentralized private electronic cash is even
harder. That’s the next step.
– pdtmeiwn on /r/bitcoin
41 / 45
An Introduction to Monero
Summary
Conclusion
Ressources
Online: http://getmonero.org
In real life, upcoming Monero meetups in Europe:
Brussels – 19th of May
Paris – 21th of May
Amsterdam – 23th of May
Berlin – 24th of May
42 / 45
An Introduction to Monero
XMR.TO
Motivation
Main problem of Monero
Theory, usage practices and software are quite different
from Bitcoin
Few merchants support Monero
Few Monero-specifc services exist
Getting started is difficult
43 / 45
An Introduction to Monero
XMR.TO
Motivation
Our goal
Make Monero usable in many places
Low barrier of entry
Maintain primary advantage of Monero (privacy)
44 / 45
Monero Presentation @ Bitcoin Meetup Geneva

More Related Content

What's hot

Bitcoin
BitcoinBitcoin
Bitcoin
Layani Malsha
 
Polygon Encode Club_deck
Polygon Encode Club_deckPolygon Encode Club_deck
Polygon Encode Club_deck
Vanessa Lošić
 
Cryptocurrencies and the Blockchain
Cryptocurrencies and the BlockchainCryptocurrencies and the Blockchain
Cryptocurrencies and the Blockchain
Matt Thompson
 
Introduction to bitcoin
Introduction to bitcoinIntroduction to bitcoin
Introduction to bitcoinWolf McNally
 
Crypto wallets
Crypto walletsCrypto wallets
Crypto wallets
Christian Kameir
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
Sarvesh Meena
 
Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...
Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...
Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...
Stephen Peters
 
BITCOIN EXPLAINED
BITCOIN EXPLAINEDBITCOIN EXPLAINED
BITCOIN EXPLAINED
Murlidhar Sarda
 
Crypto Wallet Types Explained
Crypto Wallet Types ExplainedCrypto Wallet Types Explained
Crypto Wallet Types Explained
101 Blockchains
 
Crypto currency Ppt Presentation
Crypto currency Ppt PresentationCrypto currency Ppt Presentation
Crypto currency Ppt Presentation
AbinashRout21
 
An Overview on Bitcoin
An Overview  on Bitcoin         An Overview  on Bitcoin
An Overview on Bitcoin
Touroxy
 
NFTs and Art: An artist’s perspective - art10studio
NFTs and Art: An artist’s perspective - art10studioNFTs and Art: An artist’s perspective - art10studio
NFTs and Art: An artist’s perspective - art10studio
Nettra Pan
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
MZain17
 
Blockchain
BlockchainBlockchain
Blockchain
Sai Nath
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
Suman Nayak
 
Crypto currency
Crypto currencyCrypto currency
Crypto currency
Raju Samanta
 
Finanzas descentralizadas (DeFi) para todos los públicos-4.pdf
Finanzas descentralizadas (DeFi) para todos los públicos-4.pdfFinanzas descentralizadas (DeFi) para todos los públicos-4.pdf
Finanzas descentralizadas (DeFi) para todos los públicos-4.pdf
Juan Ignacio Pérez Sacristán
 
Litecoin Crypto Currency Bootcamp
Litecoin Crypto Currency BootcampLitecoin Crypto Currency Bootcamp
Litecoin Crypto Currency Bootcamp
Joseph Holbrook, Chief Learning Officer (CLO)
 
WIlliam Mougayar Designing Tokenomics and Tokens 2.0
WIlliam Mougayar Designing Tokenomics and Tokens 2.0WIlliam Mougayar Designing Tokenomics and Tokens 2.0
WIlliam Mougayar Designing Tokenomics and Tokens 2.0
The Business Blockchain
 
Blockchain technology
Blockchain technologyBlockchain technology
Blockchain technology
Dr. Mohamed Torky
 

What's hot (20)

Bitcoin
BitcoinBitcoin
Bitcoin
 
Polygon Encode Club_deck
Polygon Encode Club_deckPolygon Encode Club_deck
Polygon Encode Club_deck
 
Cryptocurrencies and the Blockchain
Cryptocurrencies and the BlockchainCryptocurrencies and the Blockchain
Cryptocurrencies and the Blockchain
 
Introduction to bitcoin
Introduction to bitcoinIntroduction to bitcoin
Introduction to bitcoin
 
Crypto wallets
Crypto walletsCrypto wallets
Crypto wallets
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
 
Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...
Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...
Tokenomics: What Tokens, ICOs, Cryptography, and the Blockchain Mean for the ...
 
BITCOIN EXPLAINED
BITCOIN EXPLAINEDBITCOIN EXPLAINED
BITCOIN EXPLAINED
 
Crypto Wallet Types Explained
Crypto Wallet Types ExplainedCrypto Wallet Types Explained
Crypto Wallet Types Explained
 
Crypto currency Ppt Presentation
Crypto currency Ppt PresentationCrypto currency Ppt Presentation
Crypto currency Ppt Presentation
 
An Overview on Bitcoin
An Overview  on Bitcoin         An Overview  on Bitcoin
An Overview on Bitcoin
 
NFTs and Art: An artist’s perspective - art10studio
NFTs and Art: An artist’s perspective - art10studioNFTs and Art: An artist’s perspective - art10studio
NFTs and Art: An artist’s perspective - art10studio
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
 
Blockchain
BlockchainBlockchain
Blockchain
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
 
Crypto currency
Crypto currencyCrypto currency
Crypto currency
 
Finanzas descentralizadas (DeFi) para todos los públicos-4.pdf
Finanzas descentralizadas (DeFi) para todos los públicos-4.pdfFinanzas descentralizadas (DeFi) para todos los públicos-4.pdf
Finanzas descentralizadas (DeFi) para todos los públicos-4.pdf
 
Litecoin Crypto Currency Bootcamp
Litecoin Crypto Currency BootcampLitecoin Crypto Currency Bootcamp
Litecoin Crypto Currency Bootcamp
 
WIlliam Mougayar Designing Tokenomics and Tokens 2.0
WIlliam Mougayar Designing Tokenomics and Tokens 2.0WIlliam Mougayar Designing Tokenomics and Tokens 2.0
WIlliam Mougayar Designing Tokenomics and Tokens 2.0
 
Blockchain technology
Blockchain technologyBlockchain technology
Blockchain technology
 

Viewers also liked

Lykke Exchange: Initial Coin Offering
Lykke Exchange: Initial Coin Offering Lykke Exchange: Initial Coin Offering
Lykke Exchange: Initial Coin Offering
LykkeCorp
 
Augur Presented by Founder Joey Krug
Augur Presented by Founder Joey KrugAugur Presented by Founder Joey Krug
Augur Presented by Founder Joey Krug
Bitcoin Wednesday
 
Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...
Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...
Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...
Alan Wunsche, MBA,CPA,CA,CBP
 
Introduction to Ethereum
Introduction to EthereumIntroduction to Ethereum
Introduction to Ethereum
Terek Judi
 
GDPR: A Step-By-Step Guide To Compliance
GDPR: A Step-By-Step Guide To ComplianceGDPR: A Step-By-Step Guide To Compliance
GDPR: A Step-By-Step Guide To Compliance
MarkLogic
 
Intro to Coins Interactive Powerpoint
Intro to Coins Interactive PowerpointIntro to Coins Interactive Powerpoint
Intro to Coins Interactive Powerpoint
revordm
 
The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0
The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0
The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0
Guy Kawasaki
 

Viewers also liked (7)

Lykke Exchange: Initial Coin Offering
Lykke Exchange: Initial Coin Offering Lykke Exchange: Initial Coin Offering
Lykke Exchange: Initial Coin Offering
 
Augur Presented by Founder Joey Krug
Augur Presented by Founder Joey KrugAugur Presented by Founder Joey Krug
Augur Presented by Founder Joey Krug
 
Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...
Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...
Blockchain Initial Coin Offerings - The Future for Online Investing or Regula...
 
Introduction to Ethereum
Introduction to EthereumIntroduction to Ethereum
Introduction to Ethereum
 
GDPR: A Step-By-Step Guide To Compliance
GDPR: A Step-By-Step Guide To ComplianceGDPR: A Step-By-Step Guide To Compliance
GDPR: A Step-By-Step Guide To Compliance
 
Intro to Coins Interactive Powerpoint
Intro to Coins Interactive PowerpointIntro to Coins Interactive Powerpoint
Intro to Coins Interactive Powerpoint
 
The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0
The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0
The Only 10 Slides You Need in Your Pitch Deck from The Art of the Start 2.0
 

Similar to Monero Presentation @ Bitcoin Meetup Geneva

Token development company
Token development company Token development company
Token development company
danidani119564
 
Are you ready to kickstart your trendy cryptocurrency business (2).pptx
Are you ready to kickstart your trendy cryptocurrency business (2).pptxAre you ready to kickstart your trendy cryptocurrency business (2).pptx
Are you ready to kickstart your trendy cryptocurrency business (2).pptx
danidani119564
 
What is monero
What is moneroWhat is monero
What is monero
draglet GmbH
 
[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners
[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners
[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners
Hessan Adnani
 
Cryptocurrency and Online Income Secrets
Cryptocurrency and Online Income SecretsCryptocurrency and Online Income Secrets
Cryptocurrency and Online Income Secrets
imammahedi3050
 
Cryptocurrency - A Complete Article CQL.pdf
Cryptocurrency - A Complete Article CQL.pdfCryptocurrency - A Complete Article CQL.pdf
Cryptocurrency - A Complete Article CQL.pdf
DEEPENDRA MERADEV
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
alihaider191777
 
How To Mint An NFT?
How To Mint An NFT?How To Mint An NFT?
How To Mint An NFT?
101 Blockchains
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
phexcom1
 
Monero.pptx Monero is used as a security purpose to protect.
Monero.pptx Monero is used as a security purpose to protect.Monero.pptx Monero is used as a security purpose to protect.
Monero.pptx Monero is used as a security purpose to protect.
Zoha681526
 
illusoryTLS: Impersonate, Tamper, and Exploit
illusoryTLS: Impersonate, Tamper, and ExploitillusoryTLS: Impersonate, Tamper, and Exploit
illusoryTLS: Impersonate, Tamper, and Exploit
a001
 
CRYPTO BLOCKCHAIN.pptx
CRYPTO BLOCKCHAIN.pptxCRYPTO BLOCKCHAIN.pptx
CRYPTO BLOCKCHAIN.pptx
DrTazeentajMahat
 
Vertcoin stealth addresses (sx)
Vertcoin stealth addresses (sx)Vertcoin stealth addresses (sx)
Vertcoin stealth addresses (sx)depboy
 
nft.pptx
nft.pptxnft.pptx
nft.pptx
AswinKO2
 
Cryptocurrency Benefits and Risks By Frederick Acquah.pdf
Cryptocurrency Benefits and Risks By Frederick Acquah.pdfCryptocurrency Benefits and Risks By Frederick Acquah.pdf
Cryptocurrency Benefits and Risks By Frederick Acquah.pdf
FrederickAcquah7
 
Top 5 Cryptocurrency Scam Risk Factors
Top 5 Cryptocurrency Scam Risk FactorsTop 5 Cryptocurrency Scam Risk Factors
Top 5 Cryptocurrency Scam Risk Factors
Maxim Kozlovsky
 
Are Cryptocurrency Transactions Anonymous.pdf
Are Cryptocurrency Transactions Anonymous.pdfAre Cryptocurrency Transactions Anonymous.pdf
Are Cryptocurrency Transactions Anonymous.pdf
Laurie Suarez Corporation
 
Cryptocurrency — meaning, types and how do i buy cryptocurrency in canada
Cryptocurrency — meaning, types and how do i buy cryptocurrency in canadaCryptocurrency — meaning, types and how do i buy cryptocurrency in canada
Cryptocurrency — meaning, types and how do i buy cryptocurrency in canada
Bitcoin Wallet Canada
 
Crypto currency secrets
Crypto currency secretsCrypto currency secrets
Crypto currency secrets
Sahir
 
What is cryptocurrency everything you need to know - ultimate guide
What is cryptocurrency  everything you need to know - ultimate guideWhat is cryptocurrency  everything you need to know - ultimate guide
What is cryptocurrency everything you need to know - ultimate guide
PreparationInfo
 

Similar to Monero Presentation @ Bitcoin Meetup Geneva (20)

Token development company
Token development company Token development company
Token development company
 
Are you ready to kickstart your trendy cryptocurrency business (2).pptx
Are you ready to kickstart your trendy cryptocurrency business (2).pptxAre you ready to kickstart your trendy cryptocurrency business (2).pptx
Are you ready to kickstart your trendy cryptocurrency business (2).pptx
 
What is monero
What is moneroWhat is monero
What is monero
 
[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners
[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners
[Workshop] Getting Started with Cryptos, NFTs & Web 3.0 for Absolute Beginners
 
Cryptocurrency and Online Income Secrets
Cryptocurrency and Online Income SecretsCryptocurrency and Online Income Secrets
Cryptocurrency and Online Income Secrets
 
Cryptocurrency - A Complete Article CQL.pdf
Cryptocurrency - A Complete Article CQL.pdfCryptocurrency - A Complete Article CQL.pdf
Cryptocurrency - A Complete Article CQL.pdf
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
 
How To Mint An NFT?
How To Mint An NFT?How To Mint An NFT?
How To Mint An NFT?
 
Cryptocurrency
CryptocurrencyCryptocurrency
Cryptocurrency
 
Monero.pptx Monero is used as a security purpose to protect.
Monero.pptx Monero is used as a security purpose to protect.Monero.pptx Monero is used as a security purpose to protect.
Monero.pptx Monero is used as a security purpose to protect.
 
illusoryTLS: Impersonate, Tamper, and Exploit
illusoryTLS: Impersonate, Tamper, and ExploitillusoryTLS: Impersonate, Tamper, and Exploit
illusoryTLS: Impersonate, Tamper, and Exploit
 
CRYPTO BLOCKCHAIN.pptx
CRYPTO BLOCKCHAIN.pptxCRYPTO BLOCKCHAIN.pptx
CRYPTO BLOCKCHAIN.pptx
 
Vertcoin stealth addresses (sx)
Vertcoin stealth addresses (sx)Vertcoin stealth addresses (sx)
Vertcoin stealth addresses (sx)
 
nft.pptx
nft.pptxnft.pptx
nft.pptx
 
Cryptocurrency Benefits and Risks By Frederick Acquah.pdf
Cryptocurrency Benefits and Risks By Frederick Acquah.pdfCryptocurrency Benefits and Risks By Frederick Acquah.pdf
Cryptocurrency Benefits and Risks By Frederick Acquah.pdf
 
Top 5 Cryptocurrency Scam Risk Factors
Top 5 Cryptocurrency Scam Risk FactorsTop 5 Cryptocurrency Scam Risk Factors
Top 5 Cryptocurrency Scam Risk Factors
 
Are Cryptocurrency Transactions Anonymous.pdf
Are Cryptocurrency Transactions Anonymous.pdfAre Cryptocurrency Transactions Anonymous.pdf
Are Cryptocurrency Transactions Anonymous.pdf
 
Cryptocurrency — meaning, types and how do i buy cryptocurrency in canada
Cryptocurrency — meaning, types and how do i buy cryptocurrency in canadaCryptocurrency — meaning, types and how do i buy cryptocurrency in canada
Cryptocurrency — meaning, types and how do i buy cryptocurrency in canada
 
Crypto currency secrets
Crypto currency secretsCrypto currency secrets
Crypto currency secrets
 
What is cryptocurrency everything you need to know - ultimate guide
What is cryptocurrency  everything you need to know - ultimate guideWhat is cryptocurrency  everything you need to know - ultimate guide
What is cryptocurrency everything you need to know - ultimate guide
 

Recently uploaded

How to get verified on Coinbase Account?_.docx
How to get verified on Coinbase Account?_.docxHow to get verified on Coinbase Account?_.docx
How to get verified on Coinbase Account?_.docx
Buy bitget
 
Tumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdf
Tumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdfTumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdf
Tumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdf
Henry Tapper
 
The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.
DOT TECH
 
Managing marketing information to gain customer insights
Managing marketing information to gain customer insightsManaging marketing information to gain customer insights
Managing marketing information to gain customer insights
sanamalam3
 
Pensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdf
Pensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdfPensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdf
Pensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdf
Henry Tapper
 
Instant Issue Debit Cards - School Designs
Instant Issue Debit Cards - School DesignsInstant Issue Debit Cards - School Designs
Instant Issue Debit Cards - School Designs
egoetzinger
 
Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...
Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...
Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...
Godwin Emmanuel Oyedokun MBA MSc PhD FCA FCTI FCNA CFE FFAR
 
一比一原版(IC毕业证)帝国理工大学毕业证如何办理
一比一原版(IC毕业证)帝国理工大学毕业证如何办理一比一原版(IC毕业证)帝国理工大学毕业证如何办理
一比一原版(IC毕业证)帝国理工大学毕业证如何办理
conose1
 
The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...
The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...
The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...
muslimdavidovich670
 
一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理
bbeucd
 
when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.
DOT TECH
 
5 Tips for Creating Standard Financial Reports
5 Tips for Creating Standard Financial Reports5 Tips for Creating Standard Financial Reports
5 Tips for Creating Standard Financial Reports
EasyReports
 
BONKMILLON Unleashes Its Bonkers Potential on Solana.pdf
BONKMILLON Unleashes Its Bonkers Potential on Solana.pdfBONKMILLON Unleashes Its Bonkers Potential on Solana.pdf
BONKMILLON Unleashes Its Bonkers Potential on Solana.pdf
coingabbar
 
how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.
DOT TECH
 
一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理
一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理
一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理
obyzuk
 
1. Elemental Economics - Introduction to mining.pdf
1. Elemental Economics - Introduction to mining.pdf1. Elemental Economics - Introduction to mining.pdf
1. Elemental Economics - Introduction to mining.pdf
Neal Brewster
 
BYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptxBYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptx
mikemetalprod
 
Intro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptxIntro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptx
shetivia
 
Patronage and Good Governance 5.pptx pptc
Patronage and Good Governance 5.pptx pptcPatronage and Good Governance 5.pptx pptc
Patronage and Good Governance 5.pptx pptc
AbdulNasirNichari
 
How Non-Banking Financial Companies Empower Startups With Venture Debt Financing
How Non-Banking Financial Companies Empower Startups With Venture Debt FinancingHow Non-Banking Financial Companies Empower Startups With Venture Debt Financing
How Non-Banking Financial Companies Empower Startups With Venture Debt Financing
Vighnesh Shashtri
 

Recently uploaded (20)

How to get verified on Coinbase Account?_.docx
How to get verified on Coinbase Account?_.docxHow to get verified on Coinbase Account?_.docx
How to get verified on Coinbase Account?_.docx
 
Tumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdf
Tumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdfTumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdf
Tumelo-deep-dive-into-pass-through-voting-Feb23 (1).pdf
 
The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.
 
Managing marketing information to gain customer insights
Managing marketing information to gain customer insightsManaging marketing information to gain customer insights
Managing marketing information to gain customer insights
 
Pensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdf
Pensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdfPensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdf
Pensions and housing - Pensions PlayPen - 4 June 2024 v3 (1).pdf
 
Instant Issue Debit Cards - School Designs
Instant Issue Debit Cards - School DesignsInstant Issue Debit Cards - School Designs
Instant Issue Debit Cards - School Designs
 
Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...
Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...
Tax System, Behaviour, Justice, and Voluntary Compliance Culture in Nigeria -...
 
一比一原版(IC毕业证)帝国理工大学毕业证如何办理
一比一原版(IC毕业证)帝国理工大学毕业证如何办理一比一原版(IC毕业证)帝国理工大学毕业证如何办理
一比一原版(IC毕业证)帝国理工大学毕业证如何办理
 
The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...
The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...
The WhatsPump Pseudonym Problem and the Hilarious Downfall of Artificial Enga...
 
一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理
一比一原版(UCSB毕业证)圣芭芭拉分校毕业证如何办理
 
when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.
 
5 Tips for Creating Standard Financial Reports
5 Tips for Creating Standard Financial Reports5 Tips for Creating Standard Financial Reports
5 Tips for Creating Standard Financial Reports
 
BONKMILLON Unleashes Its Bonkers Potential on Solana.pdf
BONKMILLON Unleashes Its Bonkers Potential on Solana.pdfBONKMILLON Unleashes Its Bonkers Potential on Solana.pdf
BONKMILLON Unleashes Its Bonkers Potential on Solana.pdf
 
how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.
 
一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理
一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理
一比一原版(GWU,GW毕业证)加利福尼亚大学|尔湾分校毕业证如何办理
 
1. Elemental Economics - Introduction to mining.pdf
1. Elemental Economics - Introduction to mining.pdf1. Elemental Economics - Introduction to mining.pdf
1. Elemental Economics - Introduction to mining.pdf
 
BYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptxBYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptx
 
Intro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptxIntro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptx
 
Patronage and Good Governance 5.pptx pptc
Patronage and Good Governance 5.pptx pptcPatronage and Good Governance 5.pptx pptc
Patronage and Good Governance 5.pptx pptc
 
How Non-Banking Financial Companies Empower Startups With Venture Debt Financing
How Non-Banking Financial Companies Empower Startups With Venture Debt FinancingHow Non-Banking Financial Companies Empower Startups With Venture Debt Financing
How Non-Banking Financial Companies Empower Startups With Venture Debt Financing
 

Monero Presentation @ Bitcoin Meetup Geneva

  • 1. [ An introduction to ] Jérémie Dubois-Lacoste – Arne Brutschy jeremie|arne@cryptosphere-systems.com Geneva
  • 2. An Introduction to Monero Intro Who are we? Three guys with a PhD We help you build blockchain-based applicaions Specializations cryptocurrencies down to the nuts and bolts scalable algorithms and scalable systems security and dev ops Experience: Several crypto apps deployed 2 / 45
  • 3. An Introduction to Monero Intro Disclaimer We own bitcoins and moneros We’re geeks and computer scientists, not economists 3 / 45
  • 4. An Introduction to Monero Outline Outline Privacy, Fungibility, and Bitcoin Monero’s Privacy Improvements Summary XMR.TO 4 / 45
  • 5. An Introduction to Monero Privacy, Fungibility, and Bitcoin Outline Privacy, Fungibility, and Bitcoin Privacy in Bitcoin Fungibility? Fungibility in decentralized currencies Monero’s Privacy Improvements Summary XMR.TO 5 / 45
  • 6. An Introduction to Monero Privacy, Fungibility, and Bitcoin Financial Privacy Financial privacy is important for a payment system Anti-money laundering laws, taxation, etc. are possible even when the payment system ensures privacy 6 / 45
  • 7. An Introduction to Monero Privacy, Fungibility, and Bitcoin Privacy in Bitcoin Privacy in Bitcoin Bitcoin is not anonymous, it is pseudonymous. Pseudonymity is very fragile in daily life: Linking of transactions reduces privacy; Usage leaves traces everywhere on the Internet; Privacy-enhancing measures (tumblers/CoinJoin etc.) are costly. As a result, the analysis of the Bitcoin blockchain can reveal identities. 7 / 45
  • 8. An Introduction to Monero Privacy, Fungibility, and Bitcoin Privacy in Bitcoin Practical ways to analyse the blockchain Change addresses Correlation of transactions Addresses of public services (pools, exchanges, merchants, etc.) Leaked business records Scraping of web resources . . . 8 / 45
  • 9. An Introduction to Monero Privacy, Fungibility, and Bitcoin Privacy in Bitcoin Bitcoin blockchain analysis: a booming field Network-focused blockchain analysis is a thriving research field since a few years already. Today, an increasing number of high-level analysis tools are available: https://bitiodine.net/ http://coinalytics.co/ http://www.quantabytes.com/ . . . Permanent nature of blockchain ensures that privacy only ever decreases! 9 / 45
  • 10. An Introduction to Monero Privacy, Fungibility, and Bitcoin Fungibility? What is fungibility? Formal definition Fungibility is the property of a good or a commodity whose individual units are capable of mutual substitution. That is, it is the property of essences or goods which are “capable of being substituted in place of one another.” TL;DR: Fungibility means that units are interchangable. 10 / 45
  • 11. An Introduction to Monero Privacy, Fungibility, and Bitcoin Fungibility? Why do we care? Fungibility is a fundamental property of currencies. In centralized currencies, fungibility is guaranteed by the government. . . . and in decentralized currencies? 11 / 45
  • 12. An Introduction to Monero Privacy, Fungibility, and Bitcoin Fungibility in decentralized currencies The formal description of Bitcoin: Information exchange protocol, that allows the transfer of units of account; These units behave like the money we are used to, having these properties: Durability Portability Divisibility Relatively rare Fungibility 12 / 45
  • 13. An Introduction to Monero Privacy, Fungibility, and Bitcoin Fungibility in decentralized currencies Is Bitcoin really fungible? Social pressure not to accept tainted coins (theft/fraud. . . ) If privacy can be broken, fungibility is voluntary. The lack of privacy in Bitcoin threatens its fungibility. Services that track taint render bitcoins non-fungible, eg.: http://www.coinvalidation.com/ http://coinalytics.co/ https://chainalysis.com/ 13 / 45
  • 14. An Introduction to Monero Privacy, Fungibility, and Bitcoin Fungibility in decentralized currencies What can we learn from Bitcoin? Voluntary fungibility does not work. Fungibility in cryptocurrencies requires privacy. People becoming more aware of the fungibility issue in Bitcoin. Many approaches to fix this exist nowadays. 14 / 45
  • 15. An Introduction to Monero Monero’s Privacy Improvements Outline Privacy, Fungibility, and Bitcoin Monero’s Privacy Improvements Unlinkability and Untraceability Stealth Addresses Ring Signatures Viewkeys Summary XMR.TO 15 / 45
  • 16. An Introduction to Monero Monero’s Privacy Improvements Unlinkability and Untraceability 16 / 45
  • 17. An Introduction to Monero Monero’s Privacy Improvements Unlinkability and Untraceability 17 / 45
  • 18. An Introduction to Monero Monero’s Privacy Improvements Unlinkability and Untraceability Simple analogy Unlinkability: I don’t know who are the children of X Untraceability: I don’t know who are the parents of X 18 / 45
  • 19. An Introduction to Monero Monero’s Privacy Improvements Unlinkability and Untraceability Monero’s approach Unlinkability: I don’t know who are the children of X → Monero uses stealth addresses Untraceability: I don’t know who are the parents of X → Monero uses ring signatures 19 / 45
  • 20. An Introduction to Monero Monero’s Privacy Improvements Stealth Addresses Outline Privacy, Fungibility, and Bitcoin Monero’s Privacy Improvements Unlinkability and Untraceability Stealth Addresses Ring Signatures Viewkeys Summary XMR.TO 20 / 45
  • 21. An Introduction to Monero Monero’s Privacy Improvements Stealth Addresses Stealth addresses (1) The “destination” for each output is derived from the Monero address, it is different everytime Only the owner of the Monero address knows that an output is for him 21 / 45
  • 22. An Introduction to Monero Monero’s Privacy Improvements Stealth Addresses Stealth addresses (2) Now Charlie can give his Monero address to everybody: Each output sent to Charlie will look to observers as having different destinations Nobody can tell these outputs are going to Charlie Nobody can even tell these outputs are going to the same person 22 / 45
  • 23. An Introduction to Monero Monero’s Privacy Improvements Stealth Addresses Stealth addresses (3) Side remark: Stealth addresses discussed and proposed for Bitcoin too. Feasible but not very practical: requires exchange of information beforehand (either with a secure channel or an elaborated use of OP_RETURN). 23 / 45
  • 24. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Outline Privacy, Fungibility, and Bitcoin Monero’s Privacy Improvements Unlinkability and Untraceability Stealth Addresses Ring Signatures Viewkeys Summary XMR.TO 24 / 45
  • 25. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures A ring signature A group of cryptographic signatures with at least one real participant, but no way to tell which in the group is the real one as they all appear valid. 25 / 45
  • 26. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Real world analogy “Say some unpopular military attack has to be ordered, but nobody wants to go down in history as the one who ordered it. If 10 leaders have private keys, one of them could sign the order and you wouldn’t know who did it.” 26 / 45
  • 27. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Real world analogy “Say some unpopular military attack has to be ordered, but nobody wants to go down in history as the one who ordered it. If 10 leaders have private keys, one of them could sign the order and you wouldn’t know who did it.” Can you find the author of this quote? 26 / 45
  • 28. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Brilliant idea: apply it to cryptocurrencies! “Crypto may offer a way to do "key blinding". I did some research and it was obscure, but there may be something there. "group signatures" may be related.” 27 / 45
  • 29. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Brilliant idea: apply it to cryptocurrencies! “Crypto may offer a way to do "key blinding". I did some research and it was obscure, but there may be something there. "group signatures" may be related.” And now, can you find the author of the quotes? 27 / 45
  • 30. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Foreseen in 2010 by... Satoshi Nakamoto! Satoshi on ring signatures, 13/08/2010: Source: https://bitcointalk.org/index.php?topic=770#msg9074 28 / 45
  • 31. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Ring signatures to achieve untraceability? You want to spend output O of amount X, and send it all to Bob. In Bitcoin: You construct a transaction saying “I use output O, and create a new output going to Bob’s address” You sign this transaction with the private key of the address that received the output O In Monero: You find some outputs in the blockchain with the same amount X as your output O You construct a transaction saying “I use one of these outputs, and create a new output going to <stealth destination>” You sign this transaction using a ring signature 29 / 45
  • 32. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Usual Bitcoin signature 30 / 45
  • 33. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Monero equivalent 31 / 45
  • 34. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Ring signatures achieve untraceability Not only you are “mixing” your output when actually spending it: everybody is constantly using other people’s output in ring signatures, they will use yours too No need for people controlling the other outputs in the ring signature to be online or active Combinatorial explosion kicks in very quickly and render impractical forensic analysis of the blockchain 32 / 45
  • 35. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Ok, ring signatures are cool! But... Output spent using ring signature is not “spent for sure”: how to prevent double-spend? 33 / 45
  • 36. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Ok, ring signatures are cool! But... Output spent using ring signature is not “spent for sure”: how to prevent double-spend? Signatures are deterministic, so spending the same output twice can be detected easily 33 / 45
  • 37. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Ok, ring signatures are cool! But... Output spent using ring signature is not “spent for sure”: how to prevent double-spend? Signatures are deterministic, so spending the same output twice can be detected easily To spend my output of amount X using a ring signature, I must find other outputs with the same amount X! Isn’t it difficult? 33 / 45
  • 38. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Ok, ring signatures are cool! But... Output spent using ring signature is not “spent for sure”: how to prevent double-spend? Signatures are deterministic, so spending the same output twice can be detected easily To spend my output of amount X using a ring signature, I must find other outputs with the same amount X! Isn’t it difficult? Outputs are automatically broken down into common denominations. For instance, sending 11.5 XMR actually creates an output of 10, plus another one of 1, plus another one of 0.5. Thus, always plenty of outputs with proper amount. And all of them use their own ring sig! 33 / 45
  • 39. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Summary of privacy aspects Monero hides destination of transactions Monero hides origin of transactions Monero hides precise amount being transferred There is no “rich list”: nobody can see the amount associated to each address 34 / 45
  • 40. An Introduction to Monero Monero’s Privacy Improvements Ring Signatures Ok, privacy is cool. But?... Having a fully-private decentralized ledger is useful, but also problematic No way to comply in many tax jurisdictions No way to prove a transaction was made in case of dispute No way to be transparent about donations for a non-profit No way to prove certain holding to ask for loans, etc. 35 / 45
  • 41. An Introduction to Monero Monero’s Privacy Improvements Viewkeys Outline Privacy, Fungibility, and Bitcoin Monero’s Privacy Improvements Unlinkability and Untraceability Stealth Addresses Ring Signatures Viewkeys Summary XMR.TO 36 / 45
  • 42. An Introduction to Monero Monero’s Privacy Improvements Viewkeys Viewkeys A clever cryptographic mechanism, the “viewkey”. For each address, you have: A spend key (≈ Bitcoin private key) Plus a viewkey Give viewkey to somebody: they can see which outputs you control (= what you received, and your balance). Viewkey mechanism exists also for one single transaction only. 37 / 45
  • 43. An Introduction to Monero Monero’s Privacy Improvements Viewkeys Viewkey: transparency or privacy, user’s choice! With optional, voluntary use of viewkeys, Monero transparency becomes close to Bitcoin’s one Monero provides high privacy by default whilst still providing opt-in full transparency when desired It does all of this at the (very elegant) cryptographic layer 38 / 45
  • 44. An Introduction to Monero Summary Outline Privacy, Fungibility, and Bitcoin Monero’s Privacy Improvements Summary XMR.TO 39 / 45
  • 45. An Introduction to Monero Summary More Cool Tech Stuff Example: Monero has an adaptive block size. Bitcoin: the maximum block size is hardcoded (Ever heard of 1MB vs. 20MB debate?...) Monero adapts the maximum block size with a simple rule (very similar to mining difficulty adjustments). Idea is that the size is determined by free market mechanism. 40 / 45
  • 46. An Introduction to Monero Summary Conclusion Monero: a great future? Demand for more fungible/private cryptocurrencies Bitcoin is a decentralized fully transparent public ledger We now have a technology for a decentralized private-by-default/transparent-on-demand public ledger Monero is the best contender currently for that role - Electronic cash is easy. Facebook could do it. - Private electronic cash is harder, but Chaum figured out how to do it in the early 90s. - Decentralized electronic cash is even harder. That’s Bitcoin. - Decentralized private electronic cash is even harder. That’s the next step. – pdtmeiwn on /r/bitcoin 41 / 45
  • 47. An Introduction to Monero Summary Conclusion Ressources Online: http://getmonero.org In real life, upcoming Monero meetups in Europe: Brussels – 19th of May Paris – 21th of May Amsterdam – 23th of May Berlin – 24th of May 42 / 45
  • 48. An Introduction to Monero XMR.TO Motivation Main problem of Monero Theory, usage practices and software are quite different from Bitcoin Few merchants support Monero Few Monero-specifc services exist Getting started is difficult 43 / 45
  • 49. An Introduction to Monero XMR.TO Motivation Our goal Make Monero usable in many places Low barrier of entry Maintain primary advantage of Monero (privacy) 44 / 45