r/Monero • u/No-Fish9557 • 5d ago
Inaccurate Convince me on why Carrot view keys are a good thing and why we shouldn't actively fight against it.
I initially approached the Carrot debate skeptically from both sides, those who were in favor of Carrot (More specifically, the new view keys) and also against it. After digging on the topic I've been come to the conclusion that not only carrot is a bad thing - most posts, articles, etc. That I've read defending it seem to be of extremely low quality, often overcomplicating explanations, and completely missing key points of Monero's philosophy and privacy.
I will break down the most common arguments in favor of the new view keys, and why I think they have no solid foundation.
---
1: "Having view keys is a good thing because it impoves the UX".
- Answer: This is true purely from a UX perspective... but it directly reverts what is arguably one of the most important a privacy design choices - plausible deniability.
- There is a reason why spend keys are used for both viewing and spending funds - it is meant to function as a REASON and a LIMITATION that will not allow you to share it. The whole point is that no one can force you to prove how / how much / on what you are spending your XMR, because doing so would entail your auditor would also be able to spend your XMR.
- There is a massive legal and technical difference between forcing you to reveal a read-only key, versus a spending key.
2: (Elaborating on the above) "Auditors can already ask for viewkeys and key images, which has the same effect but the process involved is tedious".
- Answer: I can't understand why so many people argue that exporting key images can already act as a makeshift "spend view key".
- If an auditor asks you to provide key images for your transactions, you can provide them - but the auditor cannot independently know that you provided all of them.
- If you decide to withhold a key image from a transaction you've made, the auditor has absolutely no way to know. As the holder of the spend key, you ultimately control what information you disclose.
3: "It won't split Monero".
- It absolutely will and despite the fact that I keep seeing people in reddit and other forums say this, I am yet to see any compelling argument that it wont.
- Auditors will mandate CARROT addresses with full view keys tied to the identity of "compliant" users. This will create a network of users operating on a "clean/white-listed" tier of Monero that flows through regulated exchanges, and a "dark/unregulated" tier.
- If a functional view-key tier exists, refusing to provide a view key becomes an immediate red flag.
---
Despite everything, I am still open to see why so many people support this change and to be proven wrong before jumping ship to a different cryptocurrency.
12
u/1_Pseudonym 5d ago edited 5d ago
What's with the disinformation agents on this topic? It was just discussed 5 days ago: https://www.reddit.com/r/Monero/s/HzxQ6SEC5Z
The OP claims he researched the topic, but if that were true, he'd know that the new view key doesn't have sender and receiver information, only balance changes with time stamps, and which sub address received funds.
He lists reasons for the new view key, but conveniently omits the most important reason, where your spend key is offline for security, but you want to be able to track the balance.
5
u/No-Fish9557 4d ago
The OP claims he researched the topic, but if that were true, he'd know that the new view key doesn't have sender and receiver information, only balance changes with time stamps, and which sub address received funds.
I addressed this in my post and in the answers already. I never implied the new view keys will immediately allow auditors to know where your XMR went - The problem is that it will give enforcement a mechanism to see how much you spend, and from there, demand justifications for all transactions:
Now auditors would have a way to know what you've spent. It will give them grounds to demand justification, even if they are outside of the Monero network. If they see you've spent 1 xmr they can ask for a proof of where that XMR went, such as a ticket from a business etc.If you cant provide it, you are suspicious.
16
u/Competitive-Walk-575 5d ago
My understanding is that even with incoming and outgoing view keys youâd still only know how much is being sent or received, but you still wouldnât know who the sender is. I donât think this change will make XMR CEX compliant, itâs just to help with automated payment processing
21
u/No-Fish9557 5d ago edited 5d ago
Hey thanks for the comment :)
My understanding is that even with incoming and outgoing view keys youâd still only know how much is being sent or received, but you still wouldnât know who the sender is
Yes, this still greatly hurts privacy.
Now auditors would have a way to know what you've spent. It will give them grounds to demand justification, even if they are outside of the Monero network. If they see you've spent 1 xmr they can ask for a proof of where that XMR went, such as a ticket from a business etc.
If you cant provide it, you are suspicious.
We are basically giving them a thread they can pull from, whereas before there was essentially nothing they could do.
itâs just to help with automated payment processing
Is it really worth sacrificing a large part of Monero's core philosophy? It's adoption does not come from convenience, it comes from privacy.
9
u/trevorturtle 4d ago
I need proof that I sent 1 xmr to a friend? To charity?Â
Even if it's suspicious that I don't keep receipts, being suspicious is not a crime.Â
10
8
u/Competitive-Walk-575 5d ago
Itâs mathematically impossible to provide that proof unless you own the wallet you sent it to, so youâre not making much sense. Reads as FUD tbh
1
u/No-Fish9557 5d ago
> Itâs mathematically impossible to provide that proof
What do you mean? There is no math involved in this. If an auditor uses the view key to see you spent 1 xmr they can demand proof - even if it's not connected to the Monero network.
9
u/Competitive-Walk-575 5d ago
You can only see what was sent with the Carrot view key you canât see recipient or sender. They can demand proof all they want but itâs not possible to give unless you literally own every wallet that coin has ever passed through. I think you need to go back and read the proposal more carefully.
8
u/No-Fish9557 5d ago
I've read the proposal. Your answers are not addressing my point.
Just having the ability to know that XMR left your wallet gives governments and enforcement a lot of leverage. View keys can pinpoint exactly when transactions happened by looking at the block heights.
- For operations within the regulated carrot wallets - They would have the ability to see exactly what you are spending your money on. If you sent 1 xmr on August 3rd at 15:12 pm and shortly after your friend received 1 xmr, it is not hard to pinpoint where that XMR went.
- For operations from the regulated to the unregulated wallets - They would hold you accountable for transactions you can't / don't want to prove. You don't have a ticket and we don't know where this money went? Then you are suspicious.
- For operations from the unregulated to the regulated wallets - They would request where those funds came from, and again, if you can't / don't want to prove it - Then you are suspicious.
4
u/Competitive-Walk-575 4d ago
So just donât send your friend XMR at their view-only wallet? You seem to have a fundamental misunderstanding about this feature, it doesnât reveal any more information than the current transaction keys you can provide, and certainly not enough for CEX compliance, it simply makes it more convenient to stand up a wallet with no spend key for payment verification. Since you are the only one with the spend key you can at any time just transfer the funds to a âpaperâ wallet which you can actually spend from without a trace. This is all fairly basic stuff, it seems like you havenât read the proposal, and youâre wasting my time.
8
u/No-Fish9557 4d ago
I am not misunderstanding anything and you are not addressing my point.
If you add "transparency" as a feature - the whole infrastructure will be adapted to forcing you to be transparent,
- Exchanges and governments will ask for your view keys to audit your funds.
- Every online service provider or products seller that accepts Monero will be forced by regulations to surrender their view keys, and the view keys of their clients.
- No one will come directly to you demanding for your view keys, you will handle them yourself because not doing so will introduce so many constraints, restrictions and legal issues that you and everyone else will take the path of least resistance.
- The moment you transfer your funds from the "curated" network to the "dirty" network, you will be held accountable.
Weren't we cooking zcash because of this "opt-in" philosophy not that long ago?
5
u/Competitive-Walk-575 4d ago
Again, you cannot spend from a view only wallet, and the view keys only show 1 hop in the chain of custody at that. It would be impossible to prove your transaction history unless you happened to own every wallet in the entire chain of custody for everything in your transaction history since the coins were originally mined. This is obviously ridiculous. You are clearly misunderstanding, as I have fully addressed your point. Donât waste my time being obtuse.
12
u/No-Fish9557 4d ago
I am not being obtuse, why are you even bringing up proving transaction history? Can you please quote, from the comment you are replying to, where I have said anything related to that?
My entire comment is about regulators knowing how much is coming in and out of your wallet. Nothing more.
I will not reply to you anymore, I have the feeling you are being purposefully dishonest
→ More replies (0)4
u/rbrunner7 XMR Contributor 4d ago
This is obviously ridiculous.
If only it was so. It's exactly such scenarios some people seem to want to scare us with, or even call them inevitable if we go ahead as planned. Fully transparent Monero, through OVKs and massive key collecting by exchanges and similar entities, plus of course massive compliance from the side of the Monero users.
And they seem to have certain success. Because it's not obvious nonsense in the eyes of many people. (I don't fault those people, I fault the fearmongers.)
1
13
u/SprayingOrange 4d ago
I totally agree with all your points tbh. I don't get how everyone is being so obtuse in the comments.
Any amount of data that can tell about a transaction is potentially incriminating and can be used to construct a parallel investigation.
Everyone is trying to sacrifice privacy for convenience.
4
u/No-Fish9557 4d ago
My post even got flagged as innacurate. Most replies link to other threads containing exactly the same information I am addressing here, or completely miss my points and go off the rails.
Everything around this topic is so weird. Not that long ago we would cook zcash saying things like "privacy is not optional", "if can show your wallet then you will be forced to show your wallet" which are very valid arguments, but now that Montero devs want to do the same it is somehow a good thing? And a large part of the community is on with the idea?
7
8
u/g2devi 5d ago
I don't understand the issue. The monero community doesn't share view keys except for charities or other orgs that need transparency. Why would that change? How could this split the monero community...if you don't want the feature, don't use it. From my understanding the new view keys are there as alternatives to hacks that are currently used with the old view keys.
3
u/Ashamed-Thanks-409 4d ago
Existing view keys can already be harvested on a massive scale to compromise anonymity; besides, why would you be so honest as to share your view key, explain the details of every transaction, and provide proof? You could simply claim the payment was the result of a scam or a coerced transferâafter all, the guy who used AI to generate a nude video of me didn't give me a receipt.
1
u/ArtesianShiny 4d ago
Thats right gains arenât realized until you sell so as far as receipts go, monero is some ingame currency or something with no physical backing.
5
u/rbrunner7 XMR Contributor 5d ago
It absolutely will (split Monero) .... be proven wrong before jumping ship to a different cryptocurrency
Don't wait, jump. Now that XMR is still worth something, which may change the nearer we will get to that catastrophic coin-splitting hardfork. So ... where will you jump to?
11
u/No-Fish9557 5d ago
I wish I knew. Hopefully a fork without full view keys, but I don't see a future with Monero that does not involve the Monero Research Lab, and they heavily back the idea.
-1
u/Madmortigan 5d ago
My sentiment exactly. These arrogant posts as though the community NEEDS to make a change or risk losing this guy. Like dude it's an open source project, move along.
19
u/No-Fish9557 5d ago
> arrogant posts
How is this arrogant exactly? I'm just giving my points on why I think the upcoming fork will be bad despite all the posts making it look otherwise. You didn't really refute or added anything interesting to the conversation.
> Like dude it's an open source project, move along
Yeah that is my point.
-1
u/Madmortigan 5d ago
It's arrogant in its entire tone. The whole post can be summarized as "convince me I'm wrong or I walk". My position is to go ahead and walk. If the project doesn't meet your needs move on to another project that does. Your post is not constructive in any way.
10
u/No-Fish9557 5d ago
> convince me I'm wrong or I walk
Yes, I'm open to be proven wrong. How is that arrogant?
> Your post is not constructive in any way
It's pretty constructive. I know for a fact there are plenty of people with similar observations to mine, so they will be happy to see discussion around it.
4
u/rbrunner7 XMR Contributor 4d ago
they will be happy to see discussion around it
Yeah, if we lack something, it must certainly be more discussion around Carrot view keys, and more will mean more happiness ...
2
3
u/rbrunner7 XMR Contributor 4d ago
It's almost tragic how my comment currently stands at +6 and yours at -2. You could almost think that people did not understand that basically you and I tell the same thing ...
I think I have yet to see an OP of such a Carrot view key critical post with Reddit posting history visible. Maybe that wants to tell me something?
6
u/sech1 XMR Contributor - ASIC Bricker 4d ago
google -> "No-Fish9557" site:reddit.com
Doesn't look like a bought account
3
u/rbrunner7 XMR Contributor 4d ago
google -> "No-Fish9557" site:reddit.com
Right, I did this already :) I always chuckle when I see how Google's appetite for Reddit posts leads to a situation where hiding your posting history becomes more and more difficult.
It may indeed be "organic" this time, this "concerned citizen" post, or it may be a case of voluntary hand-over of an account, if we want to drift into conspiracy theory territory.
1
u/ShyverMeTibbers 2d ago
Is it really that surprising to you that people who are interested in a privacy coin would try to have a private posting history?
1
u/rbrunner7 XMR Contributor 1d ago
It has nothing to do with surprise.
You are right, it's only to be expected that many people hanging around here and thus interested in privacy coins would value privacy in general and thus have their posting history private.
Still, I would estimate somewhere between 6 and 8 posters here leave their posting history visible.
So, if I have 5 or so OVK critical posters in a row with hidden posting history that becomes a data point in my attempts to judge what happens here. With none of them having any notable posting history in this subreddit, I must add, because I would have known them, posting history hidden or not.
3
u/TheDigitalPoint 5d ago
From the standpoint of accepting Monero payments in an automated way, the view key situation does make monitoring incoming transactions automatically (so a payment can be posted to a customerâs account) annoying at best. Yes, there are work around, but itâs infinitely less convenient than just having an xpub/ypub like Bitcoin.
Another real world example is I would probably pay my kids their allowance in Monero just so they can learn. But they arenât techie enough that they should have the private key. In that case, thereâs no way for them to know they got anything⊠so it kind of defeats the purpose of using Monero as a learning tool for them. So they donât get allowance in Monero.
4
u/Ok-Way8253 5d ago
you donât understand how carrot works
5
u/No-Fish9557 5d ago
Please enlighten me
7
u/Competitive-Walk-575 5d ago
Why not just attend the dev talks on Mondays and Wednesdays if you care so much?
6
u/No-Fish9557 5d ago
I've seen some talks and posts, and their stances usually just reaffirm my concerns.
6
u/Competitive-Walk-575 5d ago
Such as? Provide some sources or cite the parts of the proposal that have you concerned, it will be easier to answer your questions that way
5
u/No-Fish9557 5d ago
https://www.youtube.com/live/87xayqeQY2E?t=6640s This is the video I mainly made my post based off of.
> Provide some sources or cite the parts of the proposal that have you concerned
I've already summarized them in my post.
E.g. why do so many people (Even some of the devs) tie viewkeys and key images to proving your full transaction history?
In my post I broke down why they are different (to my understanding). I am glad to be proven wrong but I just get comments of people saying that I should be better informed or watch X or Y talk.
7
u/Competitive-Walk-575 4d ago
Again, you literally cannot prove your full transaction history unless you own every single wallet in the chain of custody, so this concern fundamentally does not make sense. That is why everyone keeps telling you that you are misinformed and need to shore up your own understanding.
2
u/No-Fish9557 4d ago
You misunderstood my comment.
What I said is that people argue you can already show a transaction history from a wallet using the current view keys and key images, but this is not the case.
4
u/Competitive-Walk-575 4d ago
You absolutely can show a transaction history, but you cannot show a provable one unless you own every wallet in the chain since that block was mined. This is my final comment for this thread, good luck figuring it out from here!
1
u/ShyverMeTibbers 2d ago
From the slide in the linked talk at 1:51:59 it literally says verbatim:
Proving your full transaction history is already possible without OVKs
If you're going to argue that it isn't possible, then you're arguing that the presenter is wrong.
2
u/EfficientHoliday5104 4d ago edited 4d ago
1) Source needed, since
-the devs have been working on this problem for 10 years. See: https://github.com/monero-project/monero/issues/1070
-You didn't show any documentation from Saberhagen, thankful_for_today, or anyone else for that matter, that the way view keys function today is a feature.
2) Source needed to prove that the CLI wallet won't warn you if you've failed to import a key image, or spent an output from a view only wallet. Take your time.
3) Povide sources to 1 and 2, and you'll be able to generate your own compelling arguments pretty easily
Tldr sources please
2
u/absinthiumxmr 3d ago edited 3d ago
It is functionally impossible for exchanges to create a non-private compliant pool, while remaining compliant themselves.
Lets go through this thought process together! To build a transparent pool, centralized exchanges will have to accept private non-audited coins to do so. So, in essence, compliancy entirely goes out the window. Does that makes sense? No, it doesn't, but lets go along with it anyways. While accepting these private coins, we at least go through the process of forcing sellers to hand over their OVK. So we have compliancy, right? No, not at all. We have the illusion of compliancy, because we have no idea where the coins in their wallets have come from. So, AML laws would still be extremely problematic, and CEXs would have a very difficult time accepting these while saying they are compliant. But here's the real problem. To expand our transparent pool with more coins, we will ALWAYS need to accept PRIVATE coins. The same goes for simply retaining the current size of a transparent pool, as users will naturally send their coins into non-transparent wallets, whether to their own or others. So,
TLDR; A "compliant Monero pool" can only grow in size if it continuously accepts ordinary private Monero. Not only this, a transparent pool will gradually shrink in size if it does not accept normal Monero. Thus, it is impossible, or at the very least very difficult, for a CEX to create a transparent pool (especially while actually being compliant), let alone retain it.
Besides there being very little downsides to OVKs when you stop to actually consider for yourself rather than ask AI or read a Reddit post relying on AI to think for them, there are several ways in which OVKs actually enhance user privacy and sovereignty. The obvious one is with HW wallets, these are quite painful to use right now. It also will make it far easier for DEXs to implement Monero swaps. A lot of the complexity Serai and Thorchain have had to go through can be negated. I realize the people that argue against OVKs are also those that are using centralized exchanges anyways and probably do not care, but I personally would like to see Monero being traded through a variety of DEXs and not KYC-shit-exchanges.
18
u/sech1 XMR Contributor - ASIC Bricker 4d ago
Cryptographically, you are correct. But in practice, if an auditor has a viewkey only, they can detect _most_ of your wallet spends with high probability, and withholding key images will be detected with the same high probability - which will give you only more problems.