Is this correct though, in terms of a confidentiality or non-repudiation guarantee? For a ledger system -- blockchain or not -- every unit can be traced back through the history, to one or more sources. Yes, multiple transactions can serve to obfuscate the sources, but the real source is within that subset of all possible sources. So unless obfuscation takes place by involving all possible addresses, there's still going to be some amount of knowledge revealed about the relationship of some source and some destination address.
But I think non-repudiation could be more damaging in a cryptocurrency context. Imagine a corrupt politician that takes a cash bribe. Unless the briber recorded the serial numbers, the politician can plausible repudiate any connection with the briber, because the cash could have come from anywhere else.
Whereas with cryptocurrency, if the briber's wallet address is ever revealed (eg. by hack, by change of heart, by blackmail, or by cryptographic collapse), then there's a line which can connect the briber to the politician. They cannot deny that it's possible to have received the bribe, which is a scandal unto itself. Probably not good enough to convict of a crime, but enough to do political damage.
Ultimately, I'm of the opinion that a ledger system still isn't as strong on confidentiality as cash, because cash records nothing at all, so there's nothing to accidentally reveal. To be clear, bribery is a stand-in for any sort of payment that would cause adverse effects if revealed. Other examples include secret child support, for a secret pregnancy, for a secret abortion, or anything else that people don't want to reveal to the world. The whole point of privacy, I maintain, is to have a choice on what other people get to know.
Monero is untraceable because it uses zero-knowledge proofs and ring signatures. The identity of neither party is known to the other, nor can the amount sent be seen by any outside party.
You'd be surprised how public your crypto transactions are
Edit: After looking more deeply into Monero, I gotta say, they are doing something that gets about as close as you can get. Good for them, and thanks for bringing this up.
It's not literally untraceable (unless you mean figuritively literally) it's just effectively untraceable.
Also important to note that your transaction is essentially as private as you are, which assume that the user is taking precautions to not broadcast to the world what website they are going to and at what time and for what. So obviously the biggest flaw is still user behavior (using a sketchy exchange, using the same Monero wallet for multiple transactions, connecting your Monero wallet to another non-private wallet, and leaking metadata outside of the block chain are all things that can and do happen and make this not literally untraceable.
But yes, it gets about as close as you can.
Another heuristic examined in the study is the Coinbase output heuristic. This method identifies mining-related outputs in transaction rings and assumes that these outputs are less likely to be actual spends. Since regular users rarely mine Monero, researchers can often use this strategy to eliminate decoys. While it’s not a foolproof method, when combined with other techniques, it can sometimes improve traceability in investigations.
Monero, the crypto, is untraceable. Any user error is unrelated to that.
using the same Monero wallet for multiple transactions
You can use the same Monero wallet as many times as you want. I'm not sure where you got this idea that you can't use the same wallet more than once, but it's simply not true.
connecting your Monero wallet to another non-private wallet, and leaking metadata outside of the block chain
I honestly don't know what you are even talking about? There are no "non-private" Monero wallets. It's not possible. And how does one "leak metadata outside of the [Monero] blockchain"?
Interesting link. Hmm you know, let me look up who this "TRM Labs" company actually is...
Oh wait that's weird, they seem to be directly aligned with the goals of the Trump administration. Huh.
Just a coincidence that you used them as your source I'm sure. I'm certain you have other sources corroborating those claims and have no problem posting them here.
They all pretty much have know your customer requirements for anti money laundering reasons. Unless you go via crypto payments and those have their own dangers with how often exchanges are hacked or just straight up scams.
I'm in the process of moving many of my accounts to European apps in order to take advantage of the better data privacy regulation, and it just occurred to me that I haven't pursued whether or not there's a useful payment aggregator headquartered there. I'll have to continue looking.
The closest thing to PayPal in Europe is probably Klarna, albeit they put a stronger focus on their credit product, you can use it to just pay up front.
Wero is being rolled out slowly as an alternative to the Visa/MasterCard duopoly, but that's a bit different to what you're asking
Edit: I'd forgotten, but Curve bank could be a viable option, but I'm not sure if you can get it outside the UK
Been using privacy.com for years. You can enter any ZIP code, any name and the seller won't know anything about you unless you're shipping to your home, I guess. Some markets will see the cards as gift cards and won't accept them, but that is rare.
I use it wherever I can, especially for services that always used to end up with a stolen CC#. The cards can be single use or locked to a single merchant. I used a single use card on PSN three years ago and still get fraudulent charge attempts to this day, but the card stopped working after one use, as designed.
I'm just getting more diligent about my privacy in the face of the US tech empire going balls to the wall with stealing people's data, and it looks like this might be a helpful addition in that regard.
Revolut offers the exact same service (one-time-use credit cards). They're an EU company. They do a ton of KYC though (much more than your normal physical bank, as they have much more anti-fraud concerns being online-only). Also only available in their app which is an atrocity, their website is not functional for banking separately.
Know your customer or know your client (KYC)^[1][2]^ laws, regulations and guidelines in financial services require regulated businesses and professionals to verify the identity, suitability, and risks involved with maintaining a business relationship with a customer. These procedures fit within the broader scope of anti-money laundering (AML) and counter terrorism financing (CTF) regulations.
This makes sense re: my intuitive understanding that it protects you from giving your information to other businesses, but it won't protect you from the police if the police subpoena privacy.com and ask them about you specifically.
Privacy.com is still currently on the point of the enshittification curve where they are making a good free service for customers, but I don't doubt that once they have enough people locked in, they'll make the service worse by pivoting first to helping their advertisers and then to helping themselves and their financial backers at the expense of everyone else.
Unless something changed recently, Google Play has always accepted my privacy cards. I have one saved now a my family payment method on my Nvidia Shield account.
You can use Monero to buy gift cards. I think there's a way to get a card linked to a Monero wallet, but I'm less sure about that one. Cake Wallet has some options for that.
That's basically your only option for private online payments (unless whoever you're buying from accepts crypto), other than mailing cash.
No. Payment providers are legally obligated to collect your creditendials, screen you for fraud and report all of transactions above $10000 as well as all that they deem suspicious to authorities.
Only cash payments and crypto give you varying levels of privacy
Not anymore. If you buy a PaySafe Card for cash and want to pay with it online, you have to make an PaySafe account, enter your credit card information and full name, put the PaySafe Card Code as funds on the account and pay through that. It's absolute dogshit.
39 Comments
MnemonicBump@lemmy.dbzer0.com · 49 pts · 34d
Cash
FlashMobOfOne@lemmy.world · 22 pts · 34d
Not exactly what I asked for, but yes.
MnemonicBump@lemmy.dbzer0.com · 16 pts · 34d
It's the only one. There is no way to send digital payments that is privacy focused.
ImgurRefugee114@reddthat.com · 14 pts · 34d
Except for crypto, and then only if you put in a lot of effort to make it so.
litchralee@sh.itjust.works · 5 pts · 34d
Is this correct though, in terms of a confidentiality or non-repudiation guarantee? For a ledger system -- blockchain or not -- every unit can be traced back through the history, to one or more sources. Yes, multiple transactions can serve to obfuscate the sources, but the real source is within that subset of all possible sources. So unless obfuscation takes place by involving all possible addresses, there's still going to be some amount of knowledge revealed about the relationship of some source and some destination address.
But I think non-repudiation could be more damaging in a cryptocurrency context. Imagine a corrupt politician that takes a cash bribe. Unless the briber recorded the serial numbers, the politician can plausible repudiate any connection with the briber, because the cash could have come from anywhere else.
Whereas with cryptocurrency, if the briber's wallet address is ever revealed (eg. by hack, by change of heart, by blackmail, or by cryptographic collapse), then there's a line which can connect the briber to the politician. They cannot deny that it's possible to have received the bribe, which is a scandal unto itself. Probably not good enough to convict of a crime, but enough to do political damage.
Ultimately, I'm of the opinion that a ledger system still isn't as strong on confidentiality as cash, because cash records nothing at all, so there's nothing to accidentally reveal. To be clear, bribery is a stand-in for any sort of payment that would cause adverse effects if revealed. Other examples include secret child support, for a secret pregnancy, for a secret abortion, or anything else that people don't want to reveal to the world. The whole point of privacy, I maintain, is to have a choice on what other people get to know.
prole@lemmy.blahaj.zone · 4 pts · 34d
Monero is untraceable because it uses zero-knowledge proofs and ring signatures. The identity of neither party is known to the other, nor can the amount sent be seen by any outside party.
prole@lemmy.blahaj.zone · 10 pts · 34d
Monero
MnemonicBump@lemmy.dbzer0.com · 9 pts · 34d
You'd be surprised how public your crypto transactions are
Edit: After looking more deeply into Monero, I gotta say, they are doing something that gets about as close as you can get. Good for them, and thanks for bringing this up.
prole@lemmy.blahaj.zone · 3 pts · 34d
"about as close as you can" = literally untraceable lol
Monero is legit. The technology is fucking impressive.
MnemonicBump@lemmy.dbzer0.com · 2 pts · 33d
It's not literally untraceable (unless you mean figuritively literally) it's just effectively untraceable.
Also important to note that your transaction is essentially as private as you are, which assume that the user is taking precautions to not broadcast to the world what website they are going to and at what time and for what. So obviously the biggest flaw is still user behavior (using a sketchy exchange, using the same Monero wallet for multiple transactions, connecting your Monero wallet to another non-private wallet, and leaking metadata outside of the block chain are all things that can and do happen and make this not literally untraceable.
But yes, it gets about as close as you can.
https://www.trmlabs.com/resources/blog/the-rise-of-monero-traceability-challenges-and-research-review
prole@lemmy.blahaj.zone · 1 pts · 32d
Monero, the crypto, is untraceable. Any user error is unrelated to that.
You can use the same Monero wallet as many times as you want. I'm not sure where you got this idea that you can't use the same wallet more than once, but it's simply not true.
I honestly don't know what you are even talking about? There are no "non-private" Monero wallets. It's not possible. And how does one "leak metadata outside of the [Monero] blockchain"?
Interesting link. Hmm you know, let me look up who this "TRM Labs" company actually is...
Oh wait that's weird, they seem to be directly aligned with the goals of the Trump administration. Huh.
Just a coincidence that you used them as your source I'm sure. I'm certain you have other sources corroborating those claims and have no problem posting them here.
slazer2au@lemmy.world · 28 pts · 34d
They all pretty much have know your customer requirements for anti money laundering reasons. Unless you go via crypto payments and those have their own dangers with how often exchanges are hacked or just straight up scams.
FlashMobOfOne@lemmy.world · 7 pts · 34d
Ah, I'd forgotten AML. That's a good point.
I'm in the process of moving many of my accounts to European apps in order to take advantage of the better data privacy regulation, and it just occurred to me that I haven't pursued whether or not there's a useful payment aggregator headquartered there. I'll have to continue looking.
9point6@lemmy.world · 5 pts · 34d
The closest thing to PayPal in Europe is probably Klarna, albeit they put a stronger focus on their credit product, you can use it to just pay up front.
Wero is being rolled out slowly as an alternative to the Visa/MasterCard duopoly, but that's a bit different to what you're asking
Edit: I'd forgotten, but Curve bank could be a viable option, but I'm not sure if you can get it outside the UK
deafboy@lemmy.world · 2 pts · 34d
The financial regulations in EU are draconian. There is no concept of privacy whatsoever.
They took the worst disadvantages of a blockchain and made them a feature.
sem@piefed.blahaj.zone · 14 pts · 34d
There is something called privacy.com that gives credit card numbers but i think they do not protect you from police, idk.
s38b35M5@lemmy.world · 12 pts · 34d
Been using privacy.com for years. You can enter any ZIP code, any name and the seller won't know anything about you unless you're shipping to your home, I guess. Some markets will see the cards as gift cards and won't accept them, but that is rare.
I use it wherever I can, especially for services that always used to end up with a stolen CC#. The cards can be single use or locked to a single merchant. I used a single use card on PSN three years ago and still get fraudulent charge attempts to this day, but the card stopped working after one use, as designed.
FlashMobOfOne@lemmy.world · 7 pts · 34d
Holy crap, that sounds fantastic.
I'm just getting more diligent about my privacy in the face of the US tech empire going balls to the wall with stealing people's data, and it looks like this might be a helpful addition in that regard.
RodgeGrabTheCat@sh.itjust.works · 3 pts · 34d
I could be wrong but privacy.com is USA only.
Edit: from their faq
"Who can use Privacy and do you need a bank account?
Privacy is currently available to US citizens or legal residents with a checking account at a US bank or credit union, and who are 18+ years of age."
s38b35M5@lemmy.world · 3 pts · 34d
You can't avoid all of the surveillance, but this helps a lot.
Fiery@lemmy.dbzer0.com · 2 pts · 34d
Revolut offers the exact same service (one-time-use credit cards). They're an EU company. They do a ton of KYC though (much more than your normal physical bank, as they have much more anti-fraud concerns being online-only). Also only available in their app which is an atrocity, their website is not functional for banking separately.
defaultusername@lemmy.dbzer0.com · 2 pts · 34d
Worth noting that privacy.com has KYC.
sem@piefed.blahaj.zone · 2 pts · 34d
What is this? EDIT: https://en.wikipedia.org/wiki/Know_your_customer
This makes sense re: my intuitive understanding that it protects you from giving your information to other businesses, but it won't protect you from the police if the police subpoena privacy.com and ask them about you specifically.
Privacy.com is still currently on the point of the enshittification curve where they are making a good free service for customers, but I don't doubt that once they have enough people locked in, they'll make the service worse by pivoting first to helping their advertisers and then to helping themselves and their financial backers at the expense of everyone else.
defaultusername@lemmy.dbzer0.com · 2 pts · 34d
Know Your Customer. It's where the company keeps a record of your personally identifiable information on record and linked to your account.
NakedNateRollerSkate@lemmy.dbzer0.com · 1 pts · 34d
sem@piefed.blahaj.zone · 4 pts · 34d
That's really interesting -- any theories as to why/how PSN leaks yor CC info?
s38b35M5@lemmy.world · 2 pts · 27d
No idea, but it could be the account I used (my friend in Belize) is compromised. The charges are coming from PSN. I've checked, And it's not him
db_null@lemmy.dbzer0.com · 3 pts · 34d
Please stop buying from Amazon
Hairyfishnuts@feddit.online · 2 pts · 34d
sem@piefed.blahaj.zone · 4 pts · 34d
I respect that. You should also know you don't have to use it as an app you can also just use their website.
I don't think they're a noble company or anything. It just seems worth it to me for the time being.
s38b35M5@lemmy.world · 1 pts · 34d
Unless something changed recently, Google Play has always accepted my privacy cards. I have one saved now a my family payment method on my Nvidia Shield account.
Don't use Apple products, so can't speak to that.
defaultusername@lemmy.dbzer0.com · 6 pts · 34d
You can use Monero to buy gift cards. I think there's a way to get a card linked to a Monero wallet, but I'm less sure about that one. Cake Wallet has some options for that.
That's basically your only option for private online payments (unless whoever you're buying from accepts crypto), other than mailing cash.
BlackLaZoR@lemmy.world · 4 pts · 33d
No. Payment providers are legally obligated to collect your creditendials, screen you for fraud and report all of transactions above $10000 as well as all that they deem suspicious to authorities.
Only cash payments and crypto give you varying levels of privacy
Sivecano@lemmy.dbzer0.com · 1 pts · 34d
Paysafecard perhaps?
LouNeko@lemmy.world · 2 pts · 34d
Not anymore. If you buy a PaySafe Card for cash and want to pay with it online, you have to make an PaySafe account, enter your credit card information and full name, put the PaySafe Card Code as funds on the account and pay through that. It's absolute dogshit.
Sivecano@lemmy.dbzer0.com · 1 pts · 34d
I just put in the code and buy my steam games tho... (Maybe it depends on your country)
Sivecano@lemmy.dbzer0.com · 1 pts · 34d
GNU TALER? (sparsely available and centralized tho)