02:44:07 do monero devs have any clue how kripos monero tracing works? is it suspected to be different from a dust attack? 02:46:26 I thought it's already established that Monero isn't really vulnerable to dusting attacks? 02:47:57 CEO_of_Linux: It could be real, or it could be the feds using this opportunity to create FUD and bluff again 02:48:59 Cindy_ i don't think they can bluff in the court case tho. they need to show how they obtained the evidence 02:49:08 Well there is no court case 02:49:20 At least I haven't found one 02:49:47 I'm betting 99% it's just crappy opsec and timing attacks on exchanges 02:52:28 This isn't the first time they lied out of their ass, they like doing it so that they can create some FUD around technology and discourage people from even trying 02:55:13 seems a bit random for norway to do that 02:56:55 CEO_of_Linux: You've read the news beyond its headline? 02:57:30 Cindy_ there were arrests made, i presume there will be a court case sooner or later 02:57:35 but it's not amazon 02:58:28 There are other ways of deanonymizing people than just attacking Monero 02:58:46 I wrote my theory above 02:58:52 It's like having a giant fortified gate but your walls are made out of cardboard 02:59:03 I think that they have some kind of limited attack and found a clever way to use it 02:59:14 yanmaani: What's your theory? 02:59:18 I wasn't on here to see it 02:59:35 Does it have to do with the coinbase outputs 02:59:48 coinbase doesn't list monero 03:00:15 Coinbase as in the first transaction where a output is created 03:00:20 Not the company 03:00:31 ah sorry 03:00:47 Cindy_: If you look what they write, they use a very specific phrasing: "track the use of Monero in specific cases. This method ... enabled us to identify individuals who paid ... Kripos has also identified two sellers" 03:01:01 They are clearly stating that they were able to identify buyers 03:01:13 While strongly hinting that the sellers were caught for different reasons 03:01:59 So the sellers got the $5 wrench? 03:02:13 The other thing is, maybe it's just how it got translated but 03:02:18 "Track the use of monero"? 03:02:25 Why not "track monero" or "track monero transactions" 03:02:36 I think it has to do with the site they were using 03:02:43 So my guess would be maybe some kind of side channel, maybe network related, OR 03:02:56 something like, first they spent $10 on a site 03:02:59 then spent $10 elsewhere 03:03:08 Then spend $10 on that site again 03:03:37 Whoever runs that site can now make a very strong guess on which ring member was the real transaction. 03:04:04 Ah yeah true 03:04:33 I'm not saying I'm confident of my theory, but it logically fits the details of their claims 03:04:35 How would a side channel occur? 03:04:58 Cindy_: Well if for example you broadcast transactions on clearnet, you do not use a VPN, and they simply monitor your network traffic 03:05:04 that sort of thing 03:05:05 I mean wouldn't the timing be vastly different from when they made the offer? 03:05:07 Oh 03:05:34 Classic chainlytics attack 03:05:53 Getting the txid and then tracking their IP along with it 03:06:02 there are also the malicious nodes that were discovered which afaik nobody knows yet what kind of attack they were being used for 03:06:03 well they also have more resources; they could theoretically do much worse 03:06:09 That would make sense if they also had the sellers too 03:06:19 like "select * from isp where port = 18081" 03:06:48 It would be plausible really, we're talking about pedophiles 03:06:48 and then just look at who makes outgoing data transactions on that port a few minutes before a transaction of interest enters the mempool 03:06:57 They aren't really the smartest tool in the shed 03:07:45 yanmaani: How would you know if someone made a transaction or was just trying to fetch new blocks? 03:08:01 I'm assuming node traffic is encrypted (it would be dumb if it wasn't) 03:08:16 So the signal would be polluted with block update requests 03:08:46 Cindy_: well, a block download goes in the other direction :) 03:09:14 Yeah I know but I mean users polling a node for updates 03:09:26 Like "what block number are you on?" Over and over again 03:09:32 those requests should be smaller, no? 03:09:43 you could also correlate it with the exact size of the transaction 03:09:49 different package sizes, handshakes, timing, etc. 03:09:51 as a transaction won't really compress well 03:09:55 ^ 03:10:12 True 03:10:32 there are defenses against it, im not aware of such techniques actually being used anywhere 03:11:04 but norway is a small country, i think ISP market is very concentrated 03:11:06 mullvad has DAITA for that 03:11:25 state owns major telecom 03:11:41 I think TLS has some padding btw 03:11:48 For the connection data 03:11:49 they also do some intense stuff "to protect the children" 03:11:52 this is all assuming their wallet was connected to the clearnet. but they were obviously using tor, at least to access the dark web 03:12:08 I don't know if it's to the extent to the size of an average Monero transaction 03:12:40 CEO_of_Linux: DAITA is just connection padding 03:12:46 yeah, it's just a theory. if you want to get REALLY paranoid you can of course say, well if you look at all these tor users here, and then we look at who was connected when X Y and Z happened ... 03:13:08 i mean it can't be more than few thousand people right? 03:13:15 but this is really too depressing to think of 03:13:29 because even though it';s an admirable goal it implies mass surveillance has gone so far that you can just ... 03:13:54 Yeah 03:14:21 nah Tor has a lot more users. all cybercrime operates on it 03:14:40 On another topic (and I know I probably repeated it): payto:// now supports Monero 03:14:58 I thought the GNU Taler guys would not like it, but uhh 03:15:02 They didn't care much 03:17:12 I'm a bit confused tbh. because it's obvious LEA has some insane capabilities. they were insane in the snowden leaks, they only got better since then. but there seem to be very few busts compared to the horrifying amount of crime 03:17:55 i'm not really sure what's going on. there's some cognitive dissonace in all of this 03:19:12 i remember a few months ago there were two guys who threw a grenade inside a cafe in Paris then ran away. they live streamed the whole thing. they never got caught 03:19:27 how is that possible 03:19:47 Incompetence 03:20:25 people shoot each otehr while livestreaming with their face and get away with it. and then there was the actually competent guy who killed the health insurance ceo 03:21:58 gotta use the good stuff to protect the ceos 03:22:56 I hate how the EU gov completely nerfed GNU Taler 03:23:27 It used to be privacy for the buyer, but now it has KYC and age verification 03:27:08 just reading on taler now. it seems like it provides privacy only in so far as you trust the taler exchange to implement the blind signature protocol correctly? 03:28:02 any entity that interfaces with the fiat banking system is going to have to do KYC 03:28:24 Not like it really matters because of the KYC 03:28:40 Taler is just an extension of the fiat banking system, not a cryptocurrency 03:28:53 A payment network/system or something 04:06:58 Yeah really curious to hear more about that because every time I heard about "tracing Monero" (like in the Chainalysis leak) there was a "gotcha". 04:10:42 I recall one case where the culprit was exchanging exact amoungs on a cooperating swapper 04:17:50 Regarding the USA, the Roman Sterlingov case demonstrated that BS companies can hand wave away the rigorousness of their techniques and just tell the jury "trust me bro, the clusters are speaking to me". Also IDK about standards of evidence in Norway, where Kripos is HQ'ed. > Cindy_ i don't think they can bluff in the court case tho. they need to show how they obtained the evidence 04:18:31 As far as it has been applied so far in the US, BS companies actually can sort of bluff. 04:20:11 Cindy_ | It used to be privacy for the buyer, but now it has KYC and age verification <- I recall watching a presentation on Taler and tbh I still don't entirely understand it. So what point is there now? 04:20:24 So far BS on transparent chains like BTC fails the Daubert Standard, but I guess that US courts don't care about that anymore 04:21:05 the BS theory would work better for an individual caught using parallel construction. but this was a large operation that conssitently gave them multiple results 04:21:12 On one hand, I REALLY want for something less resource-intensive than crypto to fill the "non-KYC payment" niche, but at least this implementation is not it. I wonder if there's any way forward with the core technology? 04:22:11 there are cryptos which aren't resource intensive. but they're not as robust i guess 04:22:45 Like? 04:22:56 the ones that use proof of stake 04:23:36 Ah, that. Yeah, that's kinda concerning. Also, is the resource intensivity that much lower? Either way, that seems so easily controllable so idk if there even is any point in that direction... 04:24:03 it's much lower yeah 04:24:49 Like, I still hope that we figure something less resource-intense eventually. 04:26:29 Alledegely... > the BS theory would work better for an individual caught using parallel construction. but this was a large operation that conssitently gave them multiple results 07:06:58 if i have a wallet seed and no key images or knowledge of whether any funds were ever present on it, would putting it in the gui show me all historical incoming transactions to it or would i have to manually force the gui to calculate all possible addresses in all possible accounts ((2^32)^2 i think?) for it to scan the blockchain for old incoming tx's to any of them? 07:14:52 chiselfuse: If it's the seed of a wallet that was used "normally" it's enough to just restore and let the GUI wallet app do its work; just make sure to give it the correct restore height (before any transactions happened) and it will find transactions to the main "4" address and also transactions to subaddresses in any accounts that were used. 07:15:59 rbrunner7: really? how does that work? 07:18:55 The lookahead generates/scans the first 50 account and 200 subaddresses of each of them 07:19:10 Not sure what you mean with "really". If nothing really special happened with the wallet, accounts and subaddresses with low numbers were used, and it will catch those 07:19:48 If funds are found on any if those, the lookahead is offset by the last address or account with funds on it 07:21:13 ofrnxmr: and if funds aren't found it stops after 50x200 accounts? 07:21:32 yes 07:22:05 ofrnxmr: but isn't that unreliable? what if someone had used account 51 and none of the preceeding ones 07:22:59 Then you change the lookahead before scanning the block those txs were in, or when you create/restore the wallet 07:23:31 is there an option for that in the gui or do i use the cli 07:23:53 Use the cli 07:24:24 Easiest way is to use the commandline flag when restoring the wallet 07:26:27 ofrnxmr: which commandline flag are you talking about 07:28:05 Are you on linux? 07:34:57 ./monero-wallet-cli --help | grep subaddress 07:38:05 "but isn't that unreliable?" In theory, yes. As a prank, or to scam you, somebody can send funds to subaddress #1,000,000. You will never find those funds unless you get to know somehow which index was used. 07:39:02 But under normal circumstances this all does not really apply and you could as well worry that in the next second an asteroid will hit your house, and that's the end of the story ... 07:39:53 ofrnxmr: oh, i thought you were talking of a cli flag to the gui 07:41:31 rbrunner7: yea i guess. i still wonder how expensive it would be to scan (2^32)^2 addresses just to be exhaustive 07:41:54 afaik the account is int32 and so is the address index 07:47:35 I am pretty sure that with the way it's currently implemented your RAM would not be enough to hold the necessary lookup tables, and even if, preparing those tables might take days. 07:48:55 Seraphis (which won't get implemented) had a way to solve this problem, interestingly, but the necessary data was one of the reasons Seraphis addresses would have been very long. 14:58:04 PSA in about 1hr there's a community meeting at #monero-community to discuss many things Monerokon, some info at https://github.com/monero-project/meta/issues/1417 15:08:38 I keep mistaking Monerokon for another conference that's in the middle of nowhere. This one's actually in Europe so hope to make it there eventually) 15:32:08 Monerotopia? In mexico? 15:39:08 Yeah, I think that one 15:40:25 It's just kinda weird that it's in Mexico of all places 15:41:18 an alternative to being help in murica 15:41:26 Always wondered: is there some lore to this? Sorry if this is offensive. 15:41:53 *being held 15:44:33 *being held down and shot point blank 15:55:24 o_0 15:59:54 Isn't that that they do nowadays when they don't like you ? 16:01:30 Well, we've had that in the UK too, mind. 16:01:42 Just a lot less. 16:01:51 I mean I'm asking outside of jokes 16:02:16 btw is Mexico even safe to travel to for someone white and almost middle-class? 16:04:39 (again, sorry, just mostly wanted to ask about the lore) 16:19:09 BlueyHealer: Yes? people from the U.S travel to Mexico all the time 16:19:11 also define "white", most Mexicans won't be able to tell that you're an European, if we're talking about stupid skin-color classification, see: https://en.wikipedia.org/wiki/White_Mexicans then 16:19:14 Tehehe, banned in -community by mister plowsof, IRC bridge can't relay messages from IRC to Matrix, of my username, others' work. 16:19:24 Comical state of affairs. 16:19:27 Hopefully y'all have a great meeting in there. 🤷 16:19:37 DataHoarder[m]: Please let me know if you figure out why my IRC messages aren't passing through; I know this is not your fault. ^_^ 16:20:02 yeah, will have to schedule some time with you to debug 16:20:17 sorry, nothing I could do besides a restart + enable debug mode there 16:20:49 you are seen on monerologs at least 16:22:51 can you try to chat on this room on IRC side? 16:23:06 gan, yeah, I mean for a European 16:23:47 dukenukem: ^ 16:27:56 @rottenwheel:unredacted.org: on the banlist of the matrix room dukenukem (Rotten) @irc_dukenukem:monero.social is listed 16:28:10 so your IRC nick is also banned on the Matrix side 16:28:50 the bridge cannot join/type using your puppet. about the IRC counterpart not seeing them, it might be that triggering an early skip so they don't dump to debug log, so that might be fine. 16:30:12 I think the bot could send some feedback back to the source via a direct notice when that fails 16:31:43 Why is Rotten banned? 16:32:53 probably something to bring up after the current community meeting, it was a while ago. but they saw necessary to do both sides 16:33:17 a bit silly solution, isnt it? 16:34:09 well afaik they were banned on matrix, then whatever was going on made it continue using the irc nick after being banned, so got banned that way too 16:34:39 I can't remember what happened, and I'm not the one that set the bans, just bringing up the reason why the bridge could not bridge the messages 16:38:08 DataHoarder: It was a ridiculous as, I said I won't stop asking for my revuoxmr X credentials and our brilliant "CCS coordinator" from Britain decided to take my word on it, then banned both ends. 16:38:14 That's the summary of the situation. 16:38:21 @slowbeardigger:matrix.org: That's why. ^^ 16:38:41 Credentials that he has not handed, to date, for the record. 16:39:11 I see 16:39:14 https://nitter.privacyredirect.com/revuoxmr my X profile, not his. No matter whatever he does, or says. https://x.com/revuoxmr 16:39:22 and i can notice all of that form the drama on the voting 16:39:40 Plow is a bad actor and should be treated as such. Simple as. 16:39:58 Thanks for your insights, DataHoarder. =] 16:41:46 what is happening 16:42:25 Monero drama 16:42:40 #monero-community meeting on https://github.com/monero-project/meta/issues/1418 with MoneroKon drama as main item https://github.com/monero-project/meta/issues/1417 16:50:55 +1 to for 2-person custody, no ajs 16:50:55 Looks like this is the leading side 16:54:45 I'm fine with 2-person custody, ajs and core eligible, fine. :) 16:56:02 Yep 16:56:06 seems like the right thing to do 16:56:21 its good to keep it "decentralized" 16:58:50 just a matter of making sure to have the right measures to deal with it 17:53:48 Someone maybe here redirected me to ##fix_your_connection probably 2 days ago when one of my vps was shitting tungsten bricks. Fixed but out of my control. Next time I will kill my bouncer if I notice. 18:06:10 afaik RavFX it was join/parting quick 18:06:19 and spamming the rooms 18:06:51 That's their kind way of telling even if out of your control 18:22:43 fucking heard it all now > btw is Mexico even safe to travel to for someone white and almost middle-class? 18:27:55 Heard what? 18:47:10 wut. 18:49:17 If is a Spanish speaking country, just go to touristic areas, and even there be careful > (again, sorry, just mostly wanted to ask about the lore) 18:49:23 being "safe" is relative xd 18:50:54 Mexico is fine, as long as you don't do stupid 18:52:36 I mean someone replied "** heard it all now" and I was confused what exactly were they referring to. 18:53:59 It was in reply to a previous Matrix message 18:54:18 Guess it's not bridged properly