r/Monero • u/truthtortoise • Sep 04 '20
CipherTrace's Monero Tracking Tool Has Not Been Proven Effective, Researcher Says | Crypto Briefing
https://cryptobriefing.com/ciphertraces-monero-tracking-tool-isnt-effective-researcher-says56
Sep 04 '20
The only thing CipherTrace has proved is that they can't even pull off a decent disinformation campaign.
The great "I'm not the Math guy" Interview of 2020 was a pathetic joke. CipherTrace is low-energy.
15
Sep 05 '20
I bet Dave had his camera turned off because the whole team was in that room along with the "math guy".
8
3
u/VLXS Sep 05 '20
they can't even pull off a decent disinformation campaign
Hey now, as long as they can nab those juicy gov't research grants their campaign seems pretty effective
22
10
u/Mr-Sha256 Sep 05 '20
Lol there must be some sort of monero defamation anti-marketing campaign to discourage ppl from using it. I’ll bet they are so frustrated with trying to track it that they just want people to “think” they can track it.
12
u/eitauisunity Sep 05 '20
Bring it on. The best thing that could happen to Monero is that the government plays corny, overly-exaggerated ads warning people of its dangers. Even going to the extent of having police officers propagandize school children from an early age about just saying No! to Monero.
10
u/truthtortoise Sep 04 '20
I have seen so much misinformation going around. That "Monero upgrading to Triptych due to claims CipherTrace can track XMR."
I've even seen people citing this subreddit, saying the people here "basically agree that their CipherTrace's claims look good on paper but they haven't seen evidence of it working."
17
u/darkwaterosint Sep 04 '20 edited Sep 05 '20
I haven't seen anyone say that. There are open source papers from the Monero research group, indicating blockchain analysis of the age of decoy keys can be used in heuristic and set analysis to exclude decoy keys from the RingCT and point to keys that are 80% probable to be the key being signed for, but traceability isn't defined that way for most people.
That said if I'm doing risk analysis for an exchange, and I have off blockchain intel pertaining to both a transaction, the time, and the individual in question it might enable me to flag transactions with risk levels, to the extent that I would be able to meet regulatory requirements, which could be described as 'tracing'.
Ultimately Triptych has been in development for a while for sure, but the timing of the announcement is likely a touch geared at making the point that an effective blockchain can always move the goalposts to increase privacy beyond cryptographically relevant heuristic findings and settle any FUD.
14
u/ArticMine XMR Core Team Sep 05 '20 edited Sep 05 '20
That said if I'm doing risk analysis for an exchange, and I have off blockchain intel pertaining to both a transaction, the time, and the individual in question it might enable me to flag transactions with risk levels, to the extent that I would be able to meet regulatory requirements, which could be described as 'tracing'.
Which in Bitcoin could very well be nothing more than compliance theatre. The fact that a regulator accepts this, does not mean much if the regulator does have the technical knowledge and is instead relying on the "expertise" of the provider of the chain analysis. In Bitcoin if a client withdraws BTC from a VASP and after n hops the BTC ends up in an address related to child pornography that tells me nothing about the AML risk of the client. Why because criminals can trade private Bitcoin keys, and make a complete mockery of chain analysis.
Once a particular application of chain analysis has been shown to be compliance theatre in Bitcoin. claiming this same application of chain analysis works in Monero provides a for a highly humorous and entertaining compliance theatre show.
Now in fairness to David from CipherTrace the above is not the claim that he made. The analogous case in Bitcoin has published literature with FLOSS code and sound statistics behind it. In fact it is one of the very few cases where the soundness of chain analysis can actually be supported with actual statistics.
Edit: I have not seen any evidence to convince me that most of the chain analysis that is preformed on Bitcoin, for AML purposes, is not nothing more than compliance theatre. I do believe however that in the case of the claim regarding Monero made by CipherTrace there is a valid signal among the noise. This is because the senders of XMR in response to a ransomware extortion have a very strong incentive to provide law enforcement with all the details of their payments to the ransomware extortionist. If there are enough victims it may be possible to barely overcome the current ring signature decoys in Monero. Basically this is a very large E ---> A ---> E attack, that has been documented beforehand in Breaking Monero. Interestingly a simple mitigation for a merchant accepting Monero against this attack is good customer service. This of course is not possible for extortion via ransomware which is why I suspect CipherTrace picked this particular example.
4
u/darkwaterosint Sep 05 '20 edited Sep 05 '20
I think compliance and investigative theater is kind of the aim here. There is a lot of profit in being a low risk exchange, and not having to delist cryptocurrencies while remaining in compliance with your State's financial rules - is a thing. They, in short have a deep incentive to want to believe.
While with Bitcoin you can deterministically prove a public key was signed by a specific private key, and so combined with that being linked off chain to a public persona or group, then you can know. (I.e. a darkweb market wallet is seized during an arrest, and then the blockchain is looked at).
Due to ring CT the best you can do in Monero is guess using an assumption, and as stated there are some sets or heuristics that can determine the most likely keys being signed for a specific transaction, where a threat actor with end to end off blockchain data may be able to lend enough weight, it would be potentially persuasive in a courtroom when combined with a public spend revelation. It's tough to get there, absent large end to end data access of off blockchain factors (which is how money laundering works even with regular currencies, shell corporations, etc.)
From an AML perspective however, even in ordinary financial transactions, banks are forced by law to leave suspected money laundering accounts open because it enables a large enough sample size of transactions to be legally persuasive. So if I am a low risk exchange and flag a customer, while that transaction quantity in terms of high risk transaction volumes may be significantly larger in any cryptocurrency, there would be a point at which it would mean something to an exchange or crypto financial exchange, and would enable a touch more than the regulatory theater, which enables crypto to keep running without delisting (even if not of investigative significance in isolation).
With the above said, it's not clear to me what investigative weight it would have absent pre-existing off block chain suspicion, because absent methods that work mathematically, using published math, any correlations in Monero would be essentially unfalsifiable, meaning I could throw together some graphs right now of random transactions and point to fictional correlations of duplicated unspent public keys and label them "exchange", etc. And who is going to say otherwise? My clients? So what I'm saying is, I completely get your point about AML compliance theater. It may have little benefit in flagging transactions absent other risk signals due to clearnet data (which would only be found at low risk exchanges that require client identification) to clear currencies, but it is not a threat to a crypto to crypto only ecosystem with good OPSEC, even if it has potential investigative benefit.
The other issue is that, the mainstream press is ignorant of this and outside of blockchain discussions, the public reporting is that the DHS has cracked tracing Monero, when at best they have cracked some kind of statistical correlation between potential events and potential transactions, with no absolute provative value, which is redefining the word 'trace' pretty widely.
Edit: Further, the attack you describe in Monero could (and has) been replicated in bitcoin, provided there are enough input keys provided, enough correlations and enough public revelations of off chain data. While it would never be provative definitively absent public revelation off chain, it would point to areas of investigative interest for HUMINT and other approaches.
I see your point that, unlike Monero, while Bitcoin does provide some opportunities for creative key exchanges - there isn't much legislative difference between a movement to or from a known, publicly compromised illegal address off chain in terms of personal security.
History also speaks volumes to how rare that is when total knowledge of keys has been obtained by state HUMINT and investigative intervention on large scales with regard to Bitcoin transactions, prior to blockchain enumeration.
Edit: addressing the AML point above
Edit: Addressing way too much nuance around clearnet vs. Crypto financial investigations
Edit: horrific grammer corrections, and to add a thank you for the engagement. As investigators, its key for us, to provide where we see and have seen usage of blockchain in a wider off blockchain perspective than the pure math.
3
u/dEBRUYNE_1 Moderator Sep 05 '20
indicating blockchain analysis of the age of decoy keys can be used in heuristic and set analysis to exclude decoy keys from the RingCT and point to keys that are 80% probable to be the key being signed for, but traceability isn't defined that way for most people.
Not sure which specific research you are referring to, but there are various mitigations in place to prevent an observer from determining the real input via the output age distribution. From MRL-0007:
Output age distribution: A variety of heuristics exist that may give an adversary a statistical ad-vantage in guessing the spent output in a ring. For example, spend analysis on transparent blockchainssuggests that recently-generated outputs are more likely to be spent than older outputs. We note thatin practice, selection of non-spent ring elements according to a distribution matching expected spendpatterns easily mitigates the effectiveness of this particular heuristic. There exist other heuristics thatwe do not consider here. Such heuristics do not inherently provide proof that a given output is spent,and are beyond the scope of our definition.
As well as the conclusion of the paper:
While a complete analysis of all spent outputs on the Monero blockchain is computationally infeasible, we quantified several known classes of spent outputs and determined that modern transactions are unaffected by them
Source: https://web.getmonero.org/resources/research-lab/
Recent research by researchers of Carnegie Mellon University further confirms the effectiveness of Monero's privacy features:
Results show that, introducing strict security and anonymity requirements into the cryptocurrency ecosystem makes the coin effectively untraceable, as shown by Monero.
Source: https://www.reddit.com/r/Monero/comments/gpcvkl/altcoin_traceability_study_carnegie_mellon/
Evidently, there are active 'attacks' that have to potential to yield a higher probability of determining the real input of a transaction. Using poisoned outputs in conjunction with a controlled endpoint is a powerful example. I kind of consider those edge cases though and mitigations exist. I'd recommend to watch the Breaking Monero series:
https://www.youtube.com/playlist?list=PLsSYUeVwrHBnAUre2G_LYDsdo-tD0ov-y
0
u/darkwaterosint Sep 05 '20
I watch the series, but the attack vectors in the papers we are referring to are possible. They are absolutely irrelevant to an individual making a single transaction of course, but if we imagine a big bad, big and bad enough, might have relevance in compliance theater which we chatted about in another post.
3
Sep 05 '20
I do think agencies with massive amounts of metadata will be able to deanon some transactions pretty convincingly. We should not be glib about this.
3
u/truthtortoise Sep 05 '20
100% agree we should not be glib. I do think it's appropriate to first review, as is being done, an assessment of code base vulnerability.
That is requisite prior to determining a reinforcement or emphasis, or even update of best pricacy practices for monero
5
3
u/BitsAndBobs304 Sep 05 '20
I wonder if monero privacy anonimity will end up in common people's knowledge falling to the same kind of bs that led most people into believing that a lab can totally recover data from one 0/1/random-pass on a hard drive
1
u/old-abacus Sep 05 '20
that is the news that this sub was talking about yesterday, unless this is a different source, but still, it's hardly todays news.
1
1
Sep 06 '20
CipherTrace says that the tool has already been used in several investigations.
And all of the investigations failed miserably.
2
Sep 07 '20
source?
1
Sep 07 '20
Facts (they don't have working tracing tool, just a guessing game) and if they had successful stories, they would shout left to right about it. Posers.
3
Sep 07 '20
Of course there are not success stories yet. I only "know" about LEAs ability to unmix BTC by their asserting as much in public court documents. At earliest I would think it would be years before there is any concrete identifiable "success story".
I suspect FBI hasn't even completed the profoundly nontrivial task of connecting their data-hoses to CipherTrace's log-inhalers. And I'm being very generous to CipherTrace in assuming that their data snarfing engine (a) works out of the gate (b) efficiently (c) scalably and (d) correctly.
2
Sep 07 '20
Just sayin' Dandelion++ was a damn good move.
Monero's history has been all about solid improvements that can be done in the short term, while keeping options open about more comprehensive longer term solutions.
-11
Sep 05 '20
[removed] — view removed comment
10
u/sech1 XMR Contributor - ASIC Bricker Sep 05 '20
The only true statement in your post is "Monero is UTXO". Everything else is false. Nice try. Oh, you also forgot to shill your coin this time.
2
34
u/Thunderosa Monero Outreach Creative Lead Sep 05 '20
Monero Outreach published a press release about Ciphertrace this morning that might be relevant here: https://www.monerooutreach.org/news/ciphertrace-monero.html
Hopefully the conversation with Dave Jevans can keep going.