Jump to content

Monero

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by StephanKrot (talk | contribs) at 08:38, 23 January 2018 (Illicit use). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Monero
Monero Logo
ISO 4217
Unit
PluralMonero, moneroj
Symbolɱ
Demographics
Date of introduction18 April 2014; 10 years ago (2014-04-18)
User(s)Worldwide

Monero (XMR) is an open-source cryptocurrency created in April 2014 that focuses on privacy and decentralization that runs on Windows, macOS, Linux, Android, and FreeBSD.[2] Monero uses a public ledger to record transactions while new units are created through a process called mining. Monero aims to improve on existing cryptocurrency design by obscuring sender, recipient and amount of every transaction made as well as making the mining process more egalitarian.[3]

The focus on privacy has attracted illicit use by people interested in evading law enforcement.[4][5] The egalitarian mining process made it viable to distribute the mining effort opening new funding avenues for both legitimate online publishers and malicious hackers who covertly embed the mining code into websites and apps.[6]

Architecture

Unlike many cryptocurrencies that are derivatives of Bitcoin, Monero is based on the CryptoNight PoW hash algorithm, which comes from the CryptoNote protocol[7]. It possesses significant algorithmic differences relating to blockchain obfuscation.[8][9] By providing a high level of privacy, Monero is fungible, meaning that every unit of the currency can be substituted by another unit. This makes Monero different from public-ledger cryptocurrencies like Bitcoin, where addresses with coins previously associated with undesired activity can be blacklisted and have their coins refused by other users.[3]

In particular, the ring signatures mix the spender's address with a group of others, making it exponentially more difficult to establish a link between each subsequent transaction.[5][10] Also, the "stealth addresses" generated for each transaction make it impossible to discover the actual destination address of a transaction by anyone else other than the sender and the receiver. Finally, the "ring confidential transactions" mechanism hides the transferred amount.[5]

Monero is designed to be resistant to application-specific integrated circuit mining, which is commonly used to mine other cryptocurrencies such as Bitcoin.[11] It can be mined somewhat efficiently on consumer grade hardware such as x86, x86-64, ARM and GPUs.[11]

History

The underlying CryptoNote protocol that Monero is based on was originally launched by pseudonymous author Nicolas van Saberhagen in October 2013.[5]

Monero was originally launched by a Bitcointalk forum user only known as "thankful_for_today" under the name BitMonero which is a compound of Bit (as in Bitcoin) and Monero (literally meaning "coin" in Esperanto).[5] Five days later, the currency's supporters opted for the name to be shortened to Monero.[8]

In September 2014, Monero was attacked when an unknown party exploited a flaw in CryptoNote that permitted the creation of two subchains that refused to recognize the validity of transactions on each other. CryptoNote later released a patch for the flaw, which Monero implemented.[12][13]

Monero experienced rapid growth in market capitalization and transaction volume during the year 2016, partly due to adoption in 2016 by major darknet market AlphaBay,[5] which was closed in July 2017 by law enforcement.[14]

On January 10, 2017, the privacy of Monero transactions were further strengthened by the adoption of Bitcoin Core developer Gregory Maxwell's algorithm Confidential Transactions, hiding the amounts being transacted, in combination with an improved version of Ring Signatures.[15]

Privacy

Graphical representation of ring signature tracking.[16]

Monero's blockchain protects privacy in three ways. Ring signatures enable the sender to hide among other transaction outputs,[17] stealth addresses hide the receiving address of the transaction[16] and RingCT hides the amount of the transaction.[18] As a consequence, Monero features an opaque blockchain. This is sharp contrast with transparent and traceable blockchain used by Bitcoin.[19] Thus, Monero is said to be "private, optionally transparent".

Monero has two sets of keys, called a "view key" and a "spend key".[20] View key can be separately shared to enable optional transparency. However, the system is designed to ease processing on mobile devices,[17] as it is impossible to calculate an accurate wallet balance without a spend key.[17]

Transaction linkability

In April 2017 research highlighted three major threats to Monero user's privacy. The first relies on leveraging the ring signature size of zero, and ability to see the output amounts.[21] The second, described as "Leveraging Output Merging", involves tracking transactions where two outputs belong to the same user,[21] such as when a user is sending the funds to himself ("churning"). Finally the third threat, "Temporal Analysis", shows that predicting the right output in a ring signature is easier than previously thought.[21]

Monero development team addressed the first concern in early 2017 with introduction of Ring Confidential Transactions (ringCT)[22] as well as mandating a minimum size of ring signatures in the March 2016 protocol upgrade. Monero developers also noted that Monero Research Labs, their academic and research arm, already noted and outlined the deficiency in two public research papers in 2014 and 2015.[22]

Client software

Monero Client
Original author(s)The Monero Project
Initial releaseApril 18, 2014; 10 years ago (2014-04-18)
Preview release
v0.11.1.0 "Helium Hydra" [23] / October 15, 2017; 7 years ago (2017-10-15)
Repositorygithub.com/monero-project/monero/
Written inC++, C
Operating systemWindows, Linux, macOS, FreeBSD (CLI only), DragonflyBSD (CLI only)
PlatformIA-32, x86-64, ARMv7, ARMv8
LicenseBSD license[24]
Websitegetmonero.org


A user needs client software, a so-called wallet, to interact with the Monero network. The Monero Project produces the reference implementation of a Monero wallet. This implementation is broken up into three parts. The main software daemon is called monerod and it is responsible for reading the blockchain and claiming the user's transactions.[25] monero-wallet-cli is responsible for managing the user's account, also known as wallet address, and generating new transactions.[26] Finally, Monero GUI allows the user to interact with the aforementioned components through a graphical user interface. All of the software produced by The Monero Project is open source and licensed under a broadly permissive BSD licenses.[27]

Other third party implementations of Monero clients exist such as Monerujo[28] which also make it possible to use Monero on Android. Finally, a web wallet allows users to interact with the network entirely through the browser using a third party website.

Illicit use

The feasibility of CPU mining Monero has made it viable for malicious actors to covertly distribute miners embedded in malware, using the victim's hardware and electricity for the financial gain of the malware developer.[6][29]

The JavaScript implementation of Monero miner Coinhive has made it possible to embed the miner into a website in such a way to use website visitor's CPU to mine the cryptocurrency while the visitor is consuming the content of the webpage. While this can be done with user's consent in an effort to provide an alternative funding model to serving ads,[30] some websites have done this without informed consent which has prompted the in-browser miners to be blocked by browser extensions and ad blocking subscription lists.[29][31]

Monero is sometimes employed by Bitcoin users to break link between transactions, with bitcoins first converted to Monero, then after some delay, converted back and sent to an address unrelated to those used before.[10] Researchers have reported that the operators behind the global ransomware incident WannaCry have converted their proceeds into Monero. It is also the preferred payment method of choice for The Shadow Brokers.[4]Exchanges ShapeShift and Changelly cooperating with police after it emerged that the WannaCry attackers used it to convert Bitcoin to Monero. “Any transactions made through ShapeShift can not be hidden or obscured and are thus 100 percent transparent” stated ShapeShift.[32]

See also

References

  1. ^ "Monero (XMR) Price Chart, Market Cap, Index and News". Investing.com. Retrieved 9 August 2017.
  2. ^ "Downloads page in the official website". 31 December 2017.
  3. ^ a b "What to Know Before Trading Monero - CoinDesk". CoinDesk. 2017-05-28. Retrieved 2017-11-22.
  4. ^ a b Gallagher, Sean (4 August 2017). "Researchers say WannaCry operator moved bitcoins to "untraceable" Monero". Ars Technica.
  5. ^ a b c d e f "Monero, the Drug Dealer's Cryptocurrency of Choice, Is on Fire". WIRED. Retrieved 2017-11-22.
  6. ^ a b Tung, Liam. "Android security: Coin miners show up in apps and sites to wear out your CPU | ZDNet". ZDNet. Retrieved 2017-11-22.
  7. ^ "Monero". Cointelegraph. 24 May 2015.
  8. ^ a b Rizzo, Pete (February 4, 2017). "Drugs, Code and ICOs: Monero's Long Road to Blockchain Respect". CoinDesk.
  9. ^ Lopp, Jameson (April 9, 2016). "Bitcoin and the Rise of the Cypherpunks". CoinDesk.
  10. ^ a b van Wirdum, Aaron (September 1, 2016). "How Bitcoin Users Reclaim Their Privacy Through Its Anonymous Sibling, Monero". Bitcoin Magazine.
  11. ^ a b Tsihitas, Theo (September 22, 2017). "Monero vs Bitcoin: Monero Adopted by Privacy Focused Crypto Users". CoinCentral.
  12. ^ Werner, Albert (September 8, 2014). "Monero network exploit post-mortem". Cryptonote forum.
  13. ^ Macheta, Jan; Noether, Surae; Noether, Sarang; Smooth, Javier (12 September 2014). "MRL-0002: Counterfeiting via Merkle Tree Exploits within Virtual Currencies Employing the CryptoNote Protocol" (PDF). Monero Research Labs.
  14. ^ Popper, Nathaniel; Ruiz, Rebecca R. (20 July 2017). "2 Leading Online Black Markets Are Shut Down by Authorities". The New York Times.
  15. ^ O'Leary, Rachel Rose (September 8, 2017). "Increased Hashrate Forces Premature Monero Hard Fork Sep 8, 2017 at 15:00 UTC by Rachel Rose O'Leary". CoinDesk.
  16. ^ a b Noether, Shen; Noether, Sarang. "Monero is Not That Mysterious" (PDF). lab.getmonero.org. Retrieved 6 November 2017.
  17. ^ a b c Saberhagen, Nicolas. "CryptoNote Whitepaper" (PDF). cryptonote.org. Retrieved 6 November 2017.
  18. ^ Noether, Shen; Mackenzie, Adam. "Ring Confidential Transactions" (PDF). lab.getmonero.org. Retrieved 6 November 2017.
  19. ^ Reynolds, Perri; Irwin, Angela. "Tracking digital footprints: anonymity within the bitcoin system". emeraldinsight.com. Retrieved 6 November 2017.
  20. ^ "A beginner's guide to Monero". medium.com. Retrieved 6 November 2017.
  21. ^ a b c Kumar, Amrit; Fischer, Clément; Tople, Shruti; Saxena, Prateek. "A Traceability Analysis of Monero's Blockchain" (PDF). eprint.iacr.org. Retrieved 6 November 2017.
  22. ^ a b "You Can Link Monero Transactions – But Which? And What's the Impact? - CoinDesk". CoinDesk. 2017-04-22. Retrieved 2017-11-15.
  23. ^ "Monero: Monero 0.11.1.0". getmonero.org, The Monero Project. Retrieved 2017-11-22.
  24. ^ Project, The Monero (2017-11-22), monero: Monero: the secure, private, untraceable cryptocurrency, retrieved 2017-11-22
  25. ^ "Monero: Monero tools". getmonero.org, The Monero Project. Retrieved 2017-11-22.
  26. ^ "Monero: Monero tools". getmonero.org, The Monero Project. Retrieved 2017-11-22.
  27. ^ "Monero License". {{cite web}}: Cite has empty unknown parameter: |dead-url= (help)
  28. ^ "Monerujo Android Wallet Makes Using Monero on Mobile Easier". The Merkle. Retrieved 2017-11-22.
  29. ^ a b Goodin, Dan (October 30, 2017). "A surge of sites and apps are exhausting your CPU to mine cryptocurrency". Ars Technica.
  30. ^ Thomson, Iain (October 19, 2017). "Stealth web crypto-cash miner Coinhive back to the drawing board as blockers move in". The Register.
  31. ^ Pearson, Jordan (2017-09-19). "Someone Made an Ad Blocker But for Cryptocurrency Mining". Motherboard.
  32. ^ "Bitcoin Exchange ShapeShift Helps Police As WannaCry Attacker Converts To Monero". Cointelegraph. 4 August 2017.