07:53:05 Hello, When spending XMR, do I need to manually select UTXOs/stealth addresses and manually set the change address? 07:53:05 Or can I simply spend the funds and let the wallet automatically select multiple UTXOs and generate a change address, without harming my privacy? 08:13:07 as far as I know: some wallets have the ability to select UTXOs manually, but usually it is done automatically. Stealth addresses are generated automatically, you may want to create a subaddress when receiving something, but no need for sending. Change addresses are automatically generated too. 08:18:49 @p4xxus:matrix.org: Thank you! 08:18:49 Wouldn’t letting the wallet automatically select multiple UTXOs and generate a change address in a single transaction compromise my privacy? 08:18:49 do I need to consolidate UTXOs into a single address first? 08:24:10 There is no change address 08:24:44 Change is sent back to your xmr account first address 08:25:32 Also no addresses are visible on chain 08:25:32 If you are combining lot of utxos, best to send it your own address, do a few churns and then spend it. 08:27:47 @elongated:matrix.org: So I don’t need to manually select UTXOs or set a change address at all, I just need to churn some of the UTXOs? 08:28:29 If you are going to churn utxos and then spend them together, the churn is useless 08:29:26 If you have 10 utxos of 1 xmr and want to spend 9 xmr, you should combine those 10 utxos , then churn a few times before spending 08:29:58 Churn at random time, random nodes 08:31:51 @elongated:matrix.org: What does “random nodes” mean? I only have a local monerod instance. 08:33:26 @leah6866:matrix.org: Use a trusted remote node once or twice while Churning if you don’t have tor 08:34:49 > Use a trusted remote node once or twice while Churning if you don’t have tor 08:34:50 I’m making transactions in Whonix, is it okay to use only the local node? 08:54:38 When churning, should I use different wallet software, or is using the same wallet sufficient? Does XMR have a wallet fingerprinting issue similar to BTC? 08:54:38 And what range of random waiting times is recommended between churnings? 09:26:53 same wallet is fine, you can even send it to the same address as the original transfer as Monero its doesnt know it uses stealth addresses and mixes it with others in a block. 09:26:53 it can be done straight away too 09:27:24 don't really need to churn either for the above reasons 09:30:01 @pw:xmr.mx: Do all XMR wallet fingerprints look the same on-chain? 09:31:05 I'm going to day no... I think 09:32:55 because of stealth addresses and ring signatures 09:34:33 Before full-chain membership proofs were introduced, did ring signatures have certain vulnerabilities? 09:36:35 plowsof @ofrnxmr:xmr.mx selsta @syntheticbird:monero.social 09:36:35 one of those will have the answer to that i would of thought... or someone else 09:37:34 depends on what you mean with vulnerabilities 09:37:43 implementation bugs? 09:39:52 selsta: e.g. poisoned output attack 09:42:27 eae attack? 09:42:34 yes, you can find info on the internet 09:42:49 Thank you 09:42:56 Spending this way: BTC KYC exchange -> BTC Core Wallet -> Convert to XMR -> Feather Wallet -> convert back to BTC -> Sparrow Wallet -> pay for goods 09:42:56 For the "Feather Wallet XMR -> Sparrow Wallet BTC" step, would it be a problem to convert only exactly the amount needed and spend the entire amount immediately each time (avoid dealing with change)? 09:42:56 Or would it be better to convert more BTC in advance and spend only part of it, leaving the rest for future purchases? 09:43:42 why convert to XMR and pay in BTC? can't you just pay in XMR. 09:43:43 much less gas fee 09:44:17 @pw:xmr.mx: Some services do not support XMR, such as ProtonVPN. 09:45:34 since you mentioned feather you're talking desktop. 09:45:35 try stack wallet. multi coin and has built in Tor (you need to turn it on with single press of the onion icon 09:45:45 using monero just as a short step won't give you good privacy generally 09:46:00 mullvad accepts XMR and no other information is needed 09:48:49 Thank you. ProtonVPN was just an example, I’d like to know which approach is best for that kind of spending: “convert only the exact amount” or “convert more BTC in advance”? 09:52:01 best approach. get XMR, spend XMR :P 09:54:51 Again, they're talking about situations when this is not an option. 10:17:32 for poisoned output attack just look at https://moonstoneresearch.com/2023/11/03/Postmortem-of-Monero-CCS-Hack.html 10:29:46 that info isnt available to an outsider looking in - the eae is a targeted attack against people that are 1. worth being targeted 2. can be targeted (did you steal someone elses wallet and make the news? do you have a public address where people can send you transactions? are you consolidating outputs while depositing directly to a KYC'd CEX?