01:28:21 Ring signatures are not zero-knowledge strictly speaking, but Bulletproofs are 01:29:49 Having nullifiers doesn't necessarily imply zero knowledge proofs. 01:33:51 Typically "zero-knowledge" as a term in cryptography means that adversaries with arbitrarily high compute power cannot narrow down the witness to the proof to a smaller subset set of all possible witnesses. That's not quite true, and oversimplifying a lot. That's why ring signatures are not widely considered zero-knowledge: an adversary with arbitrarily high compute power can find the secret key of each pubkey in the ring, compute the corre 01:33:51 sponding key image, then break the hiding properties of the ring signature. 01:35:12 But in FCMP++, all membership and SA/L proofs can be opened to all possible output pairs that can possibly exist, which makes knowing the opening meaningless in terms of reducing privacy 01:41:08 The zero-knowledge property of Bulletproofs is also why QAs won't ever be able to see amounts on-chain with solely on-chain data 01:42:10 jeffro256: Is it possible for a PQ adversary to reveal amounts of transactions Borromean range proofs? 01:42:17 *transactions with 01:43:47 I can't find much good info on this 01:45:41 That I'm not sure of, that's a good question. I do know that internally, it's basically just 64 ring signatures, so I'm included to say that a PQ adversary can view these. Please don't quote me on that ;) 01:46:32 *inclined 03:56:11 > But in FCMP++, all membership and SA/L proofs can be opened to all possible output pairs that can possibly exist, 03:56:11 ALL? Or a few leaves in a tree structure? 10:11:08 Hi everyone, as per the discussion during the MRL meeting last Wednesday, we've updated the ProbeLab proposal: https://repo.getmonero.org/monero-project/ccs-proposals/-/merge_requests/667. 10:11:08 cc: @plowsof:matrix.org @rucknium:monero.social 15:21:53 saltodon :) 15:23:12 saluton mates 15:23:36 today i want to take my chance and your time to start a scientific debate around tail emission 15:23:43 and why it is not needed AT ALL 15:24:20 the proper solution is to fix the supply at whatever number it is RIGHT NOW 15:25:14 there's a strong economical case to oppose it completely 15:27:09 So you just want to spam a discussion and have nothing to present? 15:27:10 Why would anyone continue mining to support the network if there was no block reward? 15:27:27 k 15:27:31 i'll explain 15:27:38 Thats gotta be the dumbest idea ive heard yet, tbf > the proper solution is to fix the supply at whatever number it is RIGHT NOW 15:27:55 malhela: Thanks 15:28:00 i am going to start 15:28:09 "be like nano! The end" 15:28:11 my argumentation is deeply rooted in austrian school of economics 15:28:26 and its reasoning around the need for a change in the supply of money 15:28:35 more specifically rothbardian argumentation 15:29:30 refrences: "what has governmnet done to our money?", "man, economics and state" and "power and market" 15:30:08 anyone familiar with them? or austrian economics in general? 15:30:40 there's a strong debate about the "proper" supply of money 15:30:58 IMO many of his arguments about inflation don't really apply to Monero, because Monero's "inflation" is predictable and fairly distributed 15:31:26 Also, Monero's coin supply is practically deflationary because of lost coins. There would be severe liquidity issues without some form of tail emission 15:31:27 AIUI the adaptive blocksize doesn't work without a tail emission 15:32:11 jpk68: sure. most of their book were written in time that were no cryptocurrency. they are talking about the state intervention in the money supply. however, they take an extra step to talk about the supply of money in general. 15:33:00 surely there is a difference between 0.1% and 10% inflation even though they are both inflation 15:33:07 1. There is no state intervention 15:33:07 2. The coin supply is still deflationary in practice 15:33:28 jpk68: explain how that is deflationary? 15:34:11 Because of lost coins. https://docs.getmonero.org/technical-specs/ 15:34:20 jpk68: nonsense argument. economically. 15:34:53 In fact, Monero is less inflationary than gold, which Rothbard saw as a gold standard for a sound currency 15:34:57 Do you think gold has no inflation? Of course it does, because it's continuously mined 15:35:22 jpk68: i'll explain about it. 15:35:34 firstly we should think of supply in general 15:35:45 how does the supply A do a better job than supply B? 15:36:12 the answer is it does not. 15:36:25 growth in the supply of money confers no monetary benefit AT ALL. 15:37:34 jpk68: about something you said, gold. rothbard analyzed the idea around a ban on mining gold by state to resist its inflation. should government step in and regulate it? answer is obviously no. but why is gold mining necessary when it confers no social benefit? 15:38:29 jpk68: the answer is obvious. gold and monero are different in one essential fact: gold is a consumable commodity. 15:38:42 You seem to think that artificially breaking social consensus would be more "sound" than keeping it as it is 15:39:29 jpk68: why though? 15:39:42 tail emission absolutely confers no benefit 15:40:00 It pays miners to mine blocks 15:40:15 And it keeps supply stable 15:40:40 boog900: 1. there should be a free pricing on fee. mandated by supply and demand for mining process. 15:40:50 https://petertodd.org/2022/surprisingly-tail-emission-is-not-inflationary 15:41:18 boog900: keeping the supply stable has no benefit by its own. 15:41:49 ok ok 15:41:52 A currency is valued due to many variables. The rate of monetary debasement is one of them, and an important one, but does not represent the whole picture. Why did the dollar and other banknotes beat out gold in the age of industry and globalization? Because the dollar and other banknotes wins on utility. The tiny amount of monetary debasement that the tail emission incurs is more than offset by its utility to the security of the chain and 15:41:52 the ability to do adaptive blocksize 15:42:06 Deflationary money is not good money 15:42:11 we ahouldvreduce the supply by 500k every year 15:42:23 malhela: Because the end goal is sound money, and gold's usage as a commodity is irrelevant to its role as money 15:43:45 gold mining is only useful for its usage as commodity. in fact, historically, all types of money were commodities. mining gold is only useful for real world usages like in dental work, computing industry, ornaments, etc. 15:44:56 No, it's useful as currency because of the social consensus surrounding it. By that logic, Monero is 100% useless because it's not real 15:45:46 jpk68: the first sentence is correct. in fact, enforced supply should not dictate the value of money, but the demand for that money. 15:45:58 the tail emission should be optimally a percent inflation and not fixed 15:45:59 it would be interesting to explore if reducing the miner rewards by a % on some timeframe could lead to significant deflation without deincentivizing miners 15:46:04 monero value should be dictated by the demand of poeple to keep it or sell it. 15:46:14 suppose 1% annual inflation to secure the 100% of funds 15:46:23 otherwise after 200 years what happens? the security has decreased relative to the funds secured 15:47:24 @kiersten5821:matrix.org: Compounds rather quickly 15:47:44 fees are enough for mining incentives. they must be chosen through free market process. 15:48:12 Do you know how profitable mining would be in that case? It wouldn't 15:48:14 with tail emission soon 1% becomes 0.1% and 0.02% and less and less and then "LOW SECURITY BUDGET! USE MY POS COIN!" 15:48:38 soon meaning decades but in the long term you know 15:48:42 Electricity costs money and you would have to increase the fees by an insane amount 15:49:25 For the first time in human history, Monero lets people have a money which is: non-custodial, censorship-resistant, digital, global, settles in minutes, fairly distrubuted, has zero-trust crypto, is confidential, anonymous, and scalable. Does is really matter if the monetary debasement is below gold levels? Especially since the coin is still small and demand for the coin has and will continue to offset debasement 15:50:29 jpk68: in fact the proper fee would be determined like this: supply is the amount of mining services invested in monero. demand is the amount of fee people are willing to spend on monero. their relation will mandate prices. 15:50:33 kiersten: read the link boog sent 15:50:42 From the CryptoNote whitepaper: "In such inflexible models, it is more efficient to roll-out a new project rather than perpetually fix the original project." 15:50:42 Why not make a new cryptocurrency if there's demand for this? 15:51:32 jeffro256: fair. monero is great. however, why not even better? 15:51:43 inflation is never benefitable for anyone. 15:51:47 also about lost coins 15:52:07 some people ask about lost coins and their effects 15:53:32 firstly, "lost coins" are not different than "held coin" for a long time. imagine a crypto normie opening youtube, watching a video about monero, then buy a lot of xmr and wait for a long time, without selling them out. you know, kind of hoarding. 15:53:49 that crypto normie, unconciously, did a horrible job to our underground economy? 15:53:52 or what? 15:54:09 jeffro256: > In the case of Monero, they’ve introduced tail emission at a point where it represents a 0.9% apparent monetary inflation rate6. Since the number of previously lost coins, and the current rate of coin loss, is unknown7 it’s not possible to know exactly what the true monetary inflation rate is right now. But regardless, the rate will only converge towards zero going forward. 15:54:09 no, he is saying the rate will converge to 0 "regardless" because as the supply gets bigger the tail inflation is fixed regardless of how much is actually lost, which is exactly the problem 15:54:16 is financial freedom really a problem? (or freedom to hoard or lose your coins) 15:54:31 Number one, inflation is sometimes good. Unpredictable supply-side inflation which gives already wealthy banks more liquidity which they can charge us fees for, and for which the debt is paid off by taxpayers is surely negative. But Monero does had that. And like people have said several times: removing tail emission necessitates removing adaptive block size and long-term security guarantees. That move would be much more destructive than th 15:54:31 e replaced debasement 15:54:37 as he says the rate of coin loss is unknown, maybe it's 0.1% annual 15:54:51 you can't buy lost coins no matter how much you offer in exchange 15:55:14 a fixed % inflation annual is better than tail inflation in the very long term of decades/centuries 15:55:19 hoarding or losing coins cause no damage. 15:55:50 TIL we have no need for coins 15:55:52 since people can continue to trade with active supply of monero. nothing is changed. prices in monero will change to satisfy the demand. 15:56:01 ah never mind i read something wrong i think 15:56:06 tell that to the people who lost coins lmao 15:56:08 well we do have 12 decimal places :) 15:56:16 yes i read it wrong 15:56:29 but this may take an even more absurd time than centuries to converge 15:57:15 imagine a bottle of milk is traded for 1 xmr. and supply of monero is 1000 xmr. 15:57:22 malhela: what do you think about Monero's adaptive block size? 15:58:51 if we double the supply, prices double. if a person loses 500 xmr, prices fall to 1/2 of their previous value. 15:59:01 no loss to anyone. 15:59:46 It will take ~115 years for the supply to double after reaching tail emission 16:00:50 nioc: it is obvious that dynamic block size is great. but fees must be demanded by market process. how that is not possible? 16:01:46 adaptive blocksize works via a penalty and without a block reward there is nothing to penalize 16:02:25 In contrast, the supply of gold has doubled in the past ~45 years, and could increase somewhat unpredictably if a lot more is discovered 16:03:13 movements in prices caused by change in supply, have no benefit AT ALL. since monero is not used up like gold in real world and it is efficiently being used as a medium of exchange, there's no real need to care about increase or decrease in the supply. 16:03:51 in contrast, changes in prices caused by changes in demand yield benefits. 16:03:59 "there's no real need to care about increase or decrease in the supply" - So what's wrong with being inflationary in that case? 16:05:10 ok ok 16:05:17 i think our definition of inflation is different 16:05:31 would you please define inflation in your opinion? 16:06:11 I was under the impression that Rothbard's definition of inflation was being used for this argument ;) 16:06:36 it is though. :) 16:07:46 imagine that we double the cash balances of people in a society. no one will be richer than before, because prices will double or continue to increase as long as demand is satisfied. also no loss is made in this case. the purchasing power is dilluted by each unit, but not by each person. 16:08:52 Yes, we all understand that. I think you aren't listening to anything people are saying 16:09:21 however, in other cases, when someone else achieves the increased amount of supply, prices jump to satisfy the demand. not only the purchasing power of each unit is lowered, but by each person is damaged too. exactly like what is happening in current status-quo. 16:09:54 in that case, we call it inflation. inflation is never benefitable. it is only benefitable for a few at the expense of all. 16:10:29 @boog900: ^ 16:12:12 since it is not necessary. we should fix it. the current supply of monero is currently working in market. why a higher or lower supply would cause benefit? the only thing that matters is the demand to use it as the medium of exchange. 16:13:02 people choose how much balance they favour to keep in their wallet. 16:13:10 If privacy or usability doesn't matter, then just use gold instead of Monero? 16:14:14 since it is not necessary. we should fix it. <<>> but it is necessary 16:14:22 jpk68: obviously both matter. the difference is again in demands. how can we use gold for online private marketplaces? 16:15:12 nioc: you got me there. :) however, the answer is highly tied to demand of people to use monero. 16:15:32 what if supply rapidly increase, faster than the demand for monero? 16:15:47 the main tool against monero, by states and glowfriends is this. 16:16:18 the supply increase is set, it will not rapidly increase 16:16:18 the only thing needed is to make increase of demand for monero slow. 16:16:47 Demand can't be met if we have insane liquidity issues caused by no available supply 16:16:47 by delisting it, spreading fud and other ways that we all know 16:17:10 how does one balance supply and demand? 16:18:26 price has gone up for 14 years, does that mean that there is not enough supply? 16:19:13 jpk68: even if now we decrease 1000 xmr supply to 1 xmr, no loss will be made, since the previous 1 xmr will be now 1 mxmr. what is the problem? 16:19:21 guess what I am trying to say is to look at the larger picture 16:20:13 nioc: i think you did not understand my point. price has gone up, because of high supply that is not suitable for that amount of demand. 16:20:18 most here are well aware of the perspective you are talking about 16:22:00 then what is the real need for tail emission? 16:22:14 since the only thing that matters is the demand of people for monero. 16:22:32 by demand, i mean that people who use monero as real currency to trade "staff" with. 16:24:04 so, how tail emission is benefitable? 16:24:15 when the current supply is working right now. 16:25:41 the real value of monero and the only real reason that monero is valueable is its potential for private marketplaces. just like bitcoin back in 2010s, when it was used as a super anonymous coin. 16:25:56 adaptive blocksize and incentivizing miners 16:26:48 the miner part is an ongoing experiment and not a known solution 16:27:17 I need to go, l8r 16:27:44 nioc: about incentivising miners. how do banks historically make money for their services? by charging fees. not getting new coins. 16:28:04 s/how do/how did/ 16:28:38 Miners != banks 16:29:15 jeffro256: sure they are not. however, they can make money by charging fees for their services. 16:31:31 for each 2 or 1 minute. all transactions are collected and sent to miners. the price of each transaction will be determined by the demand (money people wish to spend for a transaction) and supply (money miners wish to spend to submit a transaction) for mining. 16:31:32 Not if the next guy does it for lower and the next guy does it for lower, etc etc until you hit 0 cost and thus 0 hashrate, which is what this trends to with 0 tail emission 16:32:01 nioc: ok. thank you for responses. have a nice time. 16:33:14 You either have to A) put an artifical cap on the volume and hope that it's low enough to artifically increase prices (e.g. BTC), or B) have some mechanism which pays miners to keep block sizes reasonable (e.g. XMR). You can't have both scaling and zero tail emission 16:35:01 Given that historical tx fees are a tiny fraction of total miner reward, I don't want to put the long-term security of the chain on a hyptothetical that has yet to materialize, like in the Bitcoin model. I'd prefer to have some floor of security 16:35:33 Because at the end of the day, if the blockchain isn't secure, then we have unlimited debasement due to withdraw of demand 16:37:33 Another alternative is that people see that fees for usage are artifically high, and switch to a money which has higher salability across space. This will also trigger debasement for us 16:38:27 malhela: others have presented this point obliquely, but the underlying fact is that in order to change the tail emission--say, to remove it, as you wish--we have to hard fork. So you have to convince not only a majority of the developers and maintainers, but also the users themselves. 16:38:27 Regardless of the economic arguments involved, there are technical AND social barriers to altering the consensus whatsoever. 16:38:27 Removing the tail emission is almost guaranteed to result in 2 chains where many of us will continue on the original chain with the tail emission.[... more lines follow, see https://mrelay.p2pool.observer/e/4ur8tYsLdGFDR3hl ] 16:39:33 You could also do it as a soft fork: new nodes validate the miner tx iff it contains a "burn output" 16:39:49 i'll think of it. 16:41:03 i think our discussion inspired me a lot. probably i'll do it by hand to see what will happen in next. 16:42:23 thank you all people for the respect and responses. i appreciate it. 16:52:13 @jbabb:cypherstack.com: And the miners* 16:53:41 Should I put LLM-driven vulnerability search on tomorrow's MRL agenda? 17:02:27 malhela: Emission was added for network stability, there have certainly been many austrian-oriented people involved with the project who would have balked if the design issue weren't so serious. You can think of it this way: right now the emission leaches value from users to maintain network stability, and in the long run that leaching will all shift to lost/destroyed coins (rather than lost/destroyed coins being a 17:02:27 subsidy to existing users, as is the case with e.g. a gold standard). 17:56:15 I ran into some content blocking with Claude, so I applied for Claude Cyber Verification. Strangely, it would often block me from outputting text copies of certain cryptography PDFs (e.g. Triptych) 18:01:02 https://mrelay.p2pool.observer/m/monero.social/ZysvhfVwJWIlwXTeJNoRCpeU.png (image.png) 18:01:14 this is a really robust safety guardrail, I have to say 18:08:15 https://www.anthropic.com/news/claude-fable-5-mythos-5 > <@jpk68:matrix.org> I swear Anthropic could release a model tomorrow called "Claude the Ripper" or something, then put out some advertising material, and people would be shaking in their boots because it sounds menacing and is going to haxx their bank accounts 18:08:51 just released 18:09:12 apparently unusable for security review without being whitelisted 18:27:13 sgp_ btw thanks, I'm using the non-profit Claude account now. Claude Fable 5 blocks almost all my prompts though, for "cybersecurity" reasons - and then switched to Opus 4.8 18:33:09 lmao 18:33:09 https://pbs.twimg.com/media/HKY6S8yacAAeF48.png?name=orig 18:33:59 Biology topics? Are people trying to make bioweapons or something? 18:34:26 That's their reasoning yeah 18:39:28 Looks like this new model is only part of the regular "Pro" plan until late June 18:42:01 Yes, until June 22nd 18:42:19 After that, "Pro" users will have to use credits to use Fable 18:50:36 sech1: check your email please 18:53:36 sgp_ done 18:55:11 sech1: we were accepted to the Claude Cyber Verification program, including your account 18:55:35 nice 18:55:52 In only two hours? That's impressive 18:56:08 25 mins lol