How This Monero Bug Could Impact User Privacy

2021-7-28 21:00

A “significant” decoy selection bug has been reported for Monero via the project’s official Twitter handle. According to the investigation, carried out by software developer Justin Berman, the bug “may impact your transaction’s privacy” during a brief window of time after funds have been received.

If users spend funds immediately following the lock time in the first 2 blocks allowable by consensus rules (~20 minutes after receiving funds), then there is a good probability that the output can be identified as the true spend.

Monero Research Lab clarified that the data at risk of exposure is related to addresses or transactions amounts, the funds themself are “Never at risk of being stolen”. Since the report was published around 10 hours ago, the bug has persisted in the “official wallet code”.

In order to mitigate the bug, users can wait 1 hour before spending funds after receiving them. Developers are currently working on a wallet software update. This won’t need to be implemented via a Hard Fork.

The Monero Research Lab and Monero developers take this matter very seriously. We will provide an update when wallet fixes are available.

A Potential Fix For The Monero Decoy Selection Bug

On the Monero Project GitHub repository, Berman made a detailed explanation of the bug. He revealed that his investigation was run by core developers before it was published. He clarified that the decoy selection mechanism that affects the software wallet has “0 change of selecting extremely recent outputs as decoys”.

Thus, why users can mitigate the bug by spending their funds after a while. As the developer clarified, the algorithm introduces 10 “decoys” into a Monero ring, later, it hides the real output. The selection mechanism has almost 0 chance of selecting a decoy with less than 100 outputs, but still, the probability is there:

The fact that there is still a chance to select a decoy with output index <100 is thanks to this part of the algorithm which takes the output_index determined by exp(x), finds the block it’s in, and then randomly selects an output from that block. So outputs from blocks that have >100 outputs have a chance at being selected as decoys.

Although it is still under development, Berman believes that the solution for the Monero bug will require a modification to the decoy selection mechanism. This could potentially impact the uniformity of the transactions if they are processed by a node without the update versus the way update nodes will construct rings, the developer said.

The fix I’m leaning toward at the moment is that the algorithm is off by 1 block, meaning that the paper’s observed gamma distribution simply plotted observed spents. At a block time of 120 seconds, you would expect next to 0 outputs to be spent in less than 120 seconds, which the paper’s recommended gamma distribution seems to corroborate.

At the time of writing, Monero (XMR) trades at $220.95 with a 16.1% profit in the weekly chart. XMR follows the general market sentiment moving sideways after a significant push to the upside during the weekend.

XMR follows the general market sentiment in the daily chart. Source: XMRUSDT Tradingview

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Impact (IMX) на Currencies.ru

$ 0.0005193 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: -34.78 %
Cегодня L: $0.0005193 - H: $0.0005193
Капитализация $57.451k Rank 99999
Доступно / Всего 110.631m IMX

bug privacy monero impact your software berman

bug privacy → Результатов: 19


Фото:

Bug in Crypto-Platform Beam Causes Brief Halt in Blockchain

Beam, a newly launched privacy oriented cryptocurrency, experienced a bug that caused a sudden, but brief stoppage in its blockchain, the company announced in a Tweet on January 21, 2019. Technical Difficulties Cause a Halt in Beam’s Blockchain (Source: Steemit) One of two recently released implementations of the Mimblewimble privacy protocol, the Beam Mimblewimble blockchain, experienced technical difficulties that caused.

2019-1-23 15:00


Why is Zcash 2.0 Sapling Release Important for Private Crypto Transactions?

Privacy cryptocurrency Zcash (ZEC) announced the release of their 2. 0. 0 version on August 16th, introducing the first Sapling-compatible version of the Zcash node software.   The privacy currency also added several other notable features in the newest software update, including an important fix to the peer banning bug that came about following the previous Overwinter update.

2018-8-18 22:00


Фото:

The Genesis Files: With Bit Gold, Szabo Was Inches Away From Inventing Bitcoin

As his Hungarian parents had fled post-war Soviet regime to settle in the United States, Nick Szabo came to call the Californian Bay area of the 1990s his home. Here, he was among the first to frequent the in-person “Cypherpunk” meetings organized by Timothy May, Eric Hughes and other founding members of the collective of cryptographers, programmers and privacy activists centered around the ’90s mailing list of the same name.

2018-7-13 17:16