-
xmrack[m]
-
xmrack[m]
Someone just donated $15,000 in the last 20 minutes πππ
-
ofrnxmr[m]
Prediction summary: ring sigs and mixing inputs make churning an act in futility.
-
ofrnxmr[m]
tldr: fmp or bust
-
ofrnxmr[m]
Best churn / only viable one = seappind 1xmr for 1 xmr with different, unrelated history.
-
ofrnxmr[m]
s/seappind/selling/
-
ofrnxmr[m]
Like "research into how well rectangles roll". Im all for it
-
ofrnxmr[m]
But dont expect to learn anything we dont already know
-
ofrnxmr[m]
Which is that rectangles and ring sigs dont roll and its a waste of time trying to make ring sigs fungible
-
ofrnxmr[m]
p2pool.observer shows just has asinine it is to mix your own outputs.
-
ofrnxmr[m]
tge decoy selection model needs an extremeky competent algo to force it to combine outputs that have been combined before or other craziness in order to not expose that only 1 person spends these known (change, refunds, whatever) outputs together
-
ofrnxmr[m]
Again, tldr: fmp
-
defeatoverseer[m
ofrnxmr: fmp?
-
defeatoverseer[m
And why are you assuming that a churn has to spend multiple outputs? A wallet could very easily segregate outputs to prevent this. It would be a usability trade-off, but so be it.
-
defeatoverseer[m
Can you expand on what it is that we currently "know" about churning? Are you holding something out on us?
-
ofrnxmr[m]
<defeatoverseer[m> "ofrnxmr: fmp?" <- Full membership proofs
-
ofrnxmr[m]
<defeatoverseer[m> "And why are you assuming that..." <- Sweep single is already possible a form of churning. Forgetting about what to do with the change kills the churn
-
ofrnxmr[m]
If you spend the churned output, say 1xmr and spend 0.97
-
ofrnxmr[m]
you have 0.03 xmr left. What do you do with it?
-
ofrnxmr[m]
Mix it with other churnd change?
-
ofrnxmr[m]
Or always spend whole outputs alone and somehow always have exact change
-
defeatoverseer[m
It's a trade-off. If privacy is more important to you than that 0.03 then you leave it.
-
ofrnxmr[m]
Thats burning xmr
-
ofrnxmr[m]
Not churning
-
ofrnxmr[m]
inefficient af.
-
defeatoverseer[m
You churn until you get an amount that is unusable to you.
-
defeatoverseer[m
Sometimes high privacy demands that.
-
ofrnxmr[m]
like, if you have to do that for privacy might as well use btc and 16 layers of nonsense
-
ofrnxmr[m]
l1 should work out of the box, period. Lol
-
ofrnxmr[m]
Not a bunch of workarounds to gain privacy
-
ofrnxmr[m]
Anyway, my tldr is the long story short is its a foregone conconclusion that ring sigs have a lot of fingerprintable heuristics that can never be perfect.
-
ofrnxmr[m]
"can i draw a line from transaction z back to a?" Yes. And not likely unless the real spend
-
ofrnxmr[m]
Ring sigs leave bread crumbs, churning just adds more crumbs
-
defeatoverseer[m
Where's the research that says that?
-
ofrnxmr[m]
As i said
-
ofrnxmr[m]
<ofrnxmr[m]> "Prediction summary: ring sigs..." <- ^
-
ofrnxmr[m]
<ofrnxmr[m]> "Like "research into how well..." <- ^
-
ofrnxmr[m]
Im not against research to prove it
-
ofrnxmr[m]
Or disprove it (lol)
-
ofrnxmr[m]
We all know the actual research is thin to non existent. we just increase ring size without actually using a decoy algo or input/outputs that make sense from a privacy perspective
-
merope
I'm much more optimistic, I believe that there are certain cases where churning one/a few times definitely helps (provided you do it in a specific way)
-
merope
And the main reason for that is due to the lack of dummy outputs (which imo would reduce the need for churning, but of course it comes at the cost of extra chain growth)
-
merope
Plus, I believe that there is *some* technique for picking decoys when combining outputs that would help hide that fact, but it's quite messy and complicated, and would definitely take a lot more work than just "pick according to some spend distribution"
-
midipoet
r4v3r23[m]1: if CBDCs arrive and they are net negative (likely), then the public will require a viable alternative for their day to day financial transactions. Scaling up to even a quarter of an average countries population size would be an extremely difficult task, all things considered.
-
evalda[m]
<merope> "I'm much more optimistic, I..." <- In what specific way?
-
merope
Hmmm I have a picture in my head, but I'm not really sure how to describe it (or if it's even accurate)
-
defeatoverseer[m
The research should tell us this.
-
defeatoverseer[m
People have ideas about how to do it, but there's nothing conclusive yet.
-
defeatoverseer[m
evalda[m]: This is the common way of doing it, it may be good it may not be.
-
merope
The XMR amounts are irrelevant, and you don't need separate wallets either. It's about the graph made by the inputs and the outputs in the transactions they show up in (either as decoys or real spends)
-
sech1
Separate wallets are not required, but they make it easier to not mix churned and unchurned outputs in the future. Although wallet accounts can do the same.
-
rbrunner
Is there word already from our Reddit mods how the story with the blackout is planned to continue for the Monero subreddit?
-
rbrunner
Just saw that r/CryptoCurrency is back. Hmmm.
-
monerobull[m]
I'll put it back to public later today
-
monerobull[m]
We can do a vote on what to do next
-
monerobull[m]
dEBRUYNE: and me are basically the only really active mods left
-
rbrunner
By all means put that vote up. Reddit moved about 1 millimeter yet, completely laughable if you ask me
-
monerobull[m]
To be honest, i don't care anymore about what reddit will do now
-
monerobull[m]
monero.town works great
-
monerobull[m]
The reddit privacy frontends and rif will die
-
monerobull[m]
Means I'll be checking the subreddit a whole lot less frequently
-
rbrunner
Understandable.
-
monerobull[m]
I think the best option would be to lock down participation but mirror posts from forum.monero.social and monero.town to the subreddit
-
monerobull[m]
Doesn't impact people just checking in, prevents a whole lot of bot comments and decentralizes the community platform a bit
-
xmrscott[m]
If you go that way, let me know. Forum.monero.space antispam bayesian filter has only had 2 days to train on click spam farms in Bangladesh and China so it doesn't catch everything.
-
xmrscott[m]
I'd need to tweak site permissions so new users can't post links to have 100% of spam not mirrored
-
monerobull[m]
That's cool
-
monerobull[m]
My spam filter is much more annoying for users to deal with
-
rbrunner
In my experience one tends to underestimate what it takes to smoothly run something of the size of Monero subreddit, assuming a sizeable portion of participants switches
-
monerobull[m]
(somewhat confusing signup, no email notifications)
-
rbrunner
The bots (the more clever ones) will migrate as well if there will be a sizeable exodus from Reddit now
-
monerobull[m]
But the benefit is that only humans can post in this town π₯
-
monerobull[m]
rbrunner: Depends
-
rbrunner
You have to say that, don't you :)
-
rbrunner
I mean, things like Reddit (the whole sheebang) count their servers in units of "data center" ...
-
monerobull[m]
If you had bots spam r/monero with braindead comments to make accounts look more legit to sell them and the spam on r/monero was just collateral damage
-
xmrscott[m]
Anecdotally, yes of the more proactive mods in the fediverse bad bots have started moving in. That's why one of the major topics of conversion at the recent fedicon was around moderation improvement for fedi serviced
-
rbrunner
Yeah, people complain about how bad the mobile Reddit app is. Is there a mobile, what is it, Lemmy app - *at all*?
-
xmrscott[m]
* Anecdotally, the more proactive mods in the fediverse have said bad bots have started moving in. That's why one of the major topics of conversion at the recent fedicon was around moderation improvement for fedi serviced
-
monerobull[m]
There's two actually
-
xmrscott[m]
And why Mastodon in the last month did an emergency captcha service add feature that has been requested forever
-
monerobull[m]
Lemmur and jebora
-
rbrunner
And those are good?
-
monerobull[m]
* Lemmur and jerboa
-
xmrscott[m]
* Anecdotally, the more proactive mods in the fediverse have said bad bots have started moving in. That's why one of the major topics of conversion at the recent fedicon was around moderation improvement for fedi services
-
monerobull[m]
I'd say on the level of the reddit app without the privacy violations and tons of ads
-
rbrunner
Ok, interesting to hear.
-
rbrunner
Anyway, the Reddit server claims that we have around 1000 concurrent readers on the subreddit. That's quite some load if true. On what kind of hardware is monero.town running right now?
-
monerobull[m]
Also, the web versions are actually useable on lemmy
-
monerobull[m]
rbrunner: 8gb RAM 2 cores VPS
-
rbrunner
And it's only serving that forum, basically, I assume?
-
monerobull[m]
Yeah
-
monerobull[m]
Monero.house had 1 core and 1 gb ram and served 100 users fine
-
monerobull[m]
It is trivial to migrate to a bigger server should we ever have to
-
monerobull[m]
But people on the Lemmy admin chat told me their instances with thousands of users don't require much more impressive hardware either
-
rbrunner
You mean a total of 100 users? So maybe 10 active in parallel or so.
-
-
monerobull[m]
this is house
-
monerobull[m]
this is town
-
-
monerobull[m]
* ^this is house
-
rbrunner
Ah, ok. I just barfed on my keyboard after seeing that "Gendersternchen" there. I hate those with a passion :)
-
monerobull[m]
lmao
-
rbrunner
I say use only feminine form all the time, problem solved without butchering the language and the spelling. But well, I am going off-topic now ....
-
monerobull[m]
I'm not sure what the English version says but i bet it's just users π
-
monerobull[m]
Btw, damn good stats on the migration from house to town
-
monerobull[m]
Over 50% of users in less than two days
-
rbrunner
Yes of course. That's what I see if I use it, "users"
-
monerobull[m]
Had to do it since the .house domain was used by scammers in 2018 and on a bunch of blocklists. .town is clean though
-
rbrunner
Well, good for your migration, but not yet much of a sudden influx with the subreddit dark, seems to me
-
cryptogrampy[m]
reported
-
rbrunner
The subreddit claims 100,000 users. So you have still some freaking magnitudes of possible growth ahead of you
-
xmrscott[m]
I think the biggest issue server wise is probably going to be storage for Lemmy/Kbin. 1000 users performing top 20 links + aggregate sum of comments and votes shouldn't be too intensive. Fedia.io is up to something like 1GB consumed storage after 2 days so even if you assume linear growth a few years down the line if storage isn't optimized it'll cost a pretty penny every month
-
xmrscott[m]
In theory though whatever monero link fedi service exists though should only have subs that are monero based, not a lot of image based subs, so maybe storage won't be so bad for a monero instance
-
monerobull[m]
xmrscott[m]: I'll be moving the image database to backblaze storage once it fills up the vps too much
-
monerobull[m]
<rbrunner> "The subreddit claims 100,000..." <- that is a lie, every single day there are many, many bots joining the subreddit
-
rbrunner
I imagine. And of course it's in the interest of Reddit to exaggerate, so no wonder.
-
xmrscott[m]
CEO already has. "Please don't wear reddit gear in public or you could be assaulted" as if anyone has encouraged physically harassing random people wearing reddit apparel
-
rbrunner
I start to seriously consider that monero.town might, just, barely, be a viable replacement for the Monero subreddit ...
-
r4v3r23[m]
luigi1111plowsoflets get those CCss merged
-
r4v3r23[m]
s/CCss/CCSs/
-
rbrunner
Yes, that CEO is jumping from one climax to the next currently. Probably a little overstrained the poor man.
-
rbrunner
Hoping to become a billionaire with the IPO, and now this.
-
rbrunner
Nobody understands him :)
-
monerobull[m]
he scammed me with the last reddit nft drop
-
monerobull[m]
good thing the two drops before that made up for it
-
rbrunner
You did something despite the word "NFT" showed up somewhere in the "thing" that they wanted you to do? :)
-
monerobull[m]
nono
-
monerobull[m]
they are "collectible avatars"
-
monerobull[m]
on the polygon chain
-
monerobull[m]
certainly not nfts π
-
rbrunner
Ah, yes, those.
-
rbrunner
As non-NFT as it gets, yeah
-
monerobull[m]
<rbrunner> "I start to seriously consider..." <- we got to be the publisher for some cool investigative journalism already :D
-
monerobull[m]
-
rbrunner
Yes, saw that. Interesting.
-
rbrunner
Anyway, worst case the party lasts only a few weeks, and then somebody with a grudge DOSSes you off the Internet, or gets monero.town blacklisted as well "because Monero", or whatever
-
rbrunner
but still a party of several weeks was had, which was nice.
-
rbrunner
Worst case, I mean
-
monerobull[m]
ill just buy cloudflare protection then
-
rbrunner
Is that expensive?
-
monerobull[m]
i dont think so
-
-
monerobull[m]
lol
-
rbrunner
That looks suspiciously reasonable. Waiting for the catch.
-
monerobull[m]
i think they just have so much spare ddos protection lying around that they can hand out while there are no massive attacks going on
-
monerobull[m]
they also have some program that gives FOSS projects some services for free
-
rbrunner
Might be. Maybe that's the catch. "Best effort". Which is no effort if they are busy with something really important
-
Rucknium[m]
Is there good DDoS protection that isn't Cloudflare?
-
rbrunner
No idea. At least the impression from over here is that they got that market pretty much cornered.
-
monerobull[m]
they give away unmetered protection for free since their big boy business contracts is all they need
-
monerobull[m]
there is zero place for competitors
-
monerobull[m]
all they need to do is have enough infra to withstand the current biggest botnet
-
Rucknium[m]
AFAIK, they block Tor with no way around. No working captcha option.
-
monerobull[m]
good thing tor is getting its own ddos protection
-
Rucknium[m]
You could serve the site over an onion service and make the PoW DDoS protection mandatory.
-
monerobull[m]
that is what i plan to do
-
rbrunner
Exclusively, or as an alternative?
-
monerobull[m]
like, just serve both
-
monerobull[m]
tor exclusive sites are not user friendly at all and will leave you with at best 5% of the userbase
-
rbrunner
Probably.
-
Rucknium[m]
Serving both clearnet and an onion hidden service from a single server are extremely easy if you are using NGINX. Probably easy with any reverse proxy software.
-
SNeedlewoods
hey monerobull, I just want to say thanks for monero.town
-
xmrscott[m]
<Rucknium[m]> "Is there good DDoS protection..." <- Not free, no
-
monerobull[m]
yeah ruck you can help me with that if you want to
-
Rucknium[m]
-
Rucknium[m]
But I can help, sure.
-
xmrscott[m]
There's a few others like Fastly and Akamai that are good, but they cost money
-
cryptogrampy[m]
<Rucknium[m]> "Is there good DDoS protection..." <- Tor PoW protection π
-
cryptogrampy[m]
time to start generating xmrtownalkjwef;lakjewf;oiaj23234234.onion
-
monerobull[m]
i might have
-
monerobull[m]
* i might have to
-
monerobull[m]
the donation address is 43townyvWJ82Ct4xWKrgAMJyfcbtUNfA6VVhgXWiH6pdgexBvcU8AnfTXDecaP12cqM7d7jYiriAwiyFff1o5C8xEBiLU3h :3
-
r4v3r23[m]
to spin up an onion? takes 2 secs
-
cryptogrampy[m]
is that PoW protection for tor live yet?
-
Rucknium[m]
Does not take two seconds to generate a vanity onion address unless it's very short.
-
cryptogrampy[m]
Well, you just don't have enough compute power
-
-
-
cryptogrampy[m]
I have over a dozen Gateway towers in my nursing home computer lab.
-
monerobull[m]
monerobull[m]: monero subreddit
-
r4v3r23[m]
cryptogrampy[m]: yeah just not enabled by default
-
cryptogrampy[m]
Cool. I need to test it out
-
r4v3r23[m]
Rucknium[m]: still not very hard
-
dEBRUYNE
I think we should leave r/Monero as it is and not force a transition
-
dEBRUYNE
If a transition occurs it will occur organically, like the BitcoinTalk -> Reddit switch basically
-
monerobull[m]
I will make a poll on the subreddit with a few options
-
monerobull[m]
#1 keep everything like before
-
monerobull[m]
#2 mirror all posts from forum.monero.social and monero.town (with disabled comments)
-
monerobull[m]
#3 disable commenting and posting and only allow mirror posts
-
monerobull[m]
Anything else like going private indefinitely will just get the subreddit banned or taken over by reddit itself
-
hbs[m]
<Rucknium[m]> "Is there good DDoS protection..." <- OVH has automatic and free DDoS mitigation as part of all its hosting offers
-
Rucknium[m]
hbs: Thanks.
-
Rucknium[m]
monerobull: Wouldn't 2 and 3 require API access?
-
monerobull[m]
Just for posting? Perhaps?
-
monerobull[m]
It would be a mod tool and they said they allow those π
-
monerobull[m]
If they don't, we can just use selenium to do it
-
hbs[m]
Rucknium[m]: you can read more about it here
ovhcloud.com/en/security/anti-ddos
-
monerobull[m]
Btw i just checked and monero.town provider has some ddos protections built in
-
RavFX[m]
nice
-
RavFX[m]
-
monerobull[m]
"ah this will pass" might be the worst thing for him to say rn even if he's right π
-
RavFX[m]
-
geonic
nice indeed