Pages:
Author

Topic: Is putting public bitcoin address for donation dangerous for your privacy? - page 2. (Read 5292 times)

legendary
Activity: 1358
Merit: 1003
Ron Gross
Let's get serious here. For ordering drugs, sure, what you suggest works, but if we want bitcoin to replace all the world's currencies (and I sure do), we can't seriously ask all the people to use fake names and PO boxes everywhere.
And a real address is already enough to connect to you to a name. Many people's address are public.
revealing how much money you (may) have is much better than giving out your REAL name.

I don't understand your point.

Today: When I (and A LOT of other people) purchase something from company X, they give X their real name, address, and credit card.
Tomorrow, the same people will also give them a complete record of their shopping history, and bank balance.

Yes, some ultra small proportion of the population will not give real names or addresses on online shopping websites. So, you want Bitcoin to be Hax0r money? I want it to be Galatic Credits, and would like to see how we can overcome the attack I pointed out.

For bitcoin to be universal, it needs to be accessible, secure and reasonable private to soccer moms, not hackers.
legendary
Activity: 2058
Merit: 1452
Let's get serious here. For ordering drugs, sure, what you suggest works, but if we want bitcoin to replace all the world's currencies (and I sure do), we can't seriously ask all the people to use fake names and PO boxes everywhere.
And a real address is already enough to connect to you to a name. Many people's address are public.
revealing how much money you (may) have is much better than giving out your REAL name.
legendary
Activity: 1358
Merit: 1003
Ron Gross
When I order anything on Amazon, I give them my name, address and credit card.
Do you know an online store that doesn't require your address?
>name
fake
>address
real, or a PO box

edit:
aww shit, my post count is 666.

Let's get serious here. For ordering drugs, sure, what you suggest works, but if we want bitcoin to replace all the world's currencies (and I sure do), we can't seriously ask all the people to use fake names and PO boxes everywhere.
And a real address is already enough to connect to you to a name. Many people's address are public.
legendary
Activity: 2058
Merit: 1452
When I order anything on Amazon, I give them my name, address and credit card.
Do you know an online store that doesn't require your address?
>name
fake
>address
real, or a PO box

edit:
aww shit, my post count is 666.
legendary
Activity: 1358
Merit: 1003
Ron Gross
Quote
bitcoin ... are more private than credit card
Dare I say "false"? If I give a 3rd party my credit card, there's no chance he will know how much money I have in my bank account.
but does he know your name? you address? your phone number?

When I order anything on Amazon, I give them my name, address and credit card.
Do you know an online store that doesn't require your address?
legendary
Activity: 1764
Merit: 1015
I think MTGOX is going to have to come up with a system where they can have private accounts. And where they can gurantee up to a certain amount (simular to how banks operate today). But thats not even enough, there needs to be a (dare i say) Paypal type website, that secures funds, and prevents frauds with the use of bitcoins. Not everyone wants to live in a reckless society. I personally would feel much saver leaving my coins to a multi-milliondollar entity that can get results done, compared to a bunch of nerds (no pun intended.I'm prob the biggest one in here). There are alot of things people can do to secure their wallets, but the general population (dare I say again) is simply to slow to understand the simple concept of enrypted thumb drives. Imagine explaining that to an 80 year old grandma whos looking to diversify her porfolio with a bit of digital gold. Lets hope the market can correct this.
legendary
Activity: 2058
Merit: 1452
Quote
bitcoin ... are more private than credit card
Dare I say "false"? If I give a 3rd party my credit card, there's no chance he will know how much money I have in my bank account.
but does he know your name? you address? your phone number?
legendary
Activity: 1358
Merit: 1003
Ron Gross
Quote
bitcoin ... are more private than credit card

Dare I say "false"? If I give a 3rd party my credit card, there's no chance he will know how much money I have in my bank account.
I'm just digesting how serious this is. How do you envision this resolved eventually?

One possible sollution is to have a smart wallet management software that manages 10,000 different wallets, all belonging to you, and  makes sure not to link them. To the end user, the user experience should be "I have a single bank account, a way to generate incoming address, a way to pay", and the smart wallet should do the rest.

Without a solution to this problem, I dare say bitcoin loses a significant portion of its appeal.
A payment method that leaks that much information won't reach mass adoption.
full member
Activity: 168
Merit: 103
Yeah, I think the claim that bitcoin is anonymous is a huge overstatement that shouldn't be made.


You can - if you are aware how bitcoin works - have a lot of privacy. And even when you just use bitcoin without thinking about it, you have more privacy than with paypal. But it's not true that it is anonymous, which is in my opinion an absolute thing. Nothing is "a little anonymous". Something is anonymous or not. Bitcoin is not.


EDIT: long posting short:
What I want to say: Bitcoin does not force you to release your identity. But it does not protect it automatically either.
legendary
Activity: 1652
Merit: 2301
Chief Scientist
Yep. Every transaction you make potentially leaks a little information about other transactions to/from your bitcoin wallet.

That's why I always say "bitcoin anonymity is complicated" and "bitcoin transactions are more private than credit card or bank transactions, but less private than cash transactions" or "staying completely anonymous while using bitcoins is hard."

And that's why you won't find (or, at least, shouldn't find) any claims that bitcoin is anonymous on the bitcoin.org home page or in the bitcoin source code.

What can you do? Use separate wallets. Make your donation address an instawallet or mybitcoin address that you don't use for anything else.
legendary
Activity: 1358
Merit: 1003
Ron Gross
Scenario:

1. I publish address X in my signature, for donations or just pure fun.
2. I buy bitcoins in Mt. Gox, move them to my wallet at address Y1.
3. I move 99% of my bitcoins from my main wallet to a new encrypted wallet at address Z1
4. Someone donates to me at my public address X.
5. I buy some more bitcoins at Mt. Gox, move them to my wallet at address Y2, then move 99% to my encrypted wallet at address Z2.
...
6. I move some money from my encrypted wallet back to my private wallet at address Y3.

Note that Y1, Y2, Y3 were all generated by the same wallet, and Z1 and Z2 were both generated from another wallet.

Now ... suppose one my Z (encrypted) address is under scrutiny, because they hold a large amount of coins.
Someone backtraces every transaction in them, guesses that the Z address and Y address belong to the same person, because of many back-and-forth transactions between them.
X can be linked to Y as well by block explorer.
X can be linked to my identity, because I put it on my sig.

End result - someone knows (or has a pretty good guess) exactly how much bitcoin I have, just because I put up a public donation address.


Is this analysis correct? Can anything be easily done to prevent it?
I understand that one could try to cloak the connection between Y and Z address, and make it harder to guess they belong to the same person.
But - I don't think it's trivial to cloak.

Also, this attack seems to be possible not just on public address, but also by anyone that ever sent you money.

Please refute.
Pages:
Jump to: