Die Seite wird umgeblättert.
Das nächste Kapitel kommt in Sicht…
Psst… lies auf deine Weise.
Schriften und Designs findest du unter Darstellung. Deine Augen entscheiden mit.
Das nächste Kapitel kommt in Sicht…
A system design in which users or wallets can choose between transaction paths that reveal different amounts of information, making privacy depend on both protocol rules and actual usage.
Vorlesefunktion dieses Browsers wird geprüft…
Diese Lektüre ist derzeit auf Englisch verfügbar. Die Oberfläche verwendet deine gewählte Sprache.
Das englische Original lesen →Kappos and colleagues' USENIX Security 2018 paper investigates how much anonymity the deployed Zcash system achieved in practice. It studies transparent transactions, the shielded pool and interactions between them. Usage patterns support heuristics that substantially reduce the candidate set for some transactions, despite the underlying privacy construction. The finding concerns the observed system and dataset, not a universal break of zero-knowledge proofs.
Read the dataset dates, heuristic conditions and validation strategy before repeating a tracing percentage. A heuristic association is not automatically a uniquely proven identity. Protocol versions, wallet defaults and user behavior change, so the historical sample cannot measure every later deployment. The durable lesson is methodological: evaluate information exposed by the complete transaction lifecycle rather than infer user privacy from the name of one cryptographic primitive.
ZIP 315 is a draft statement of Zcash wallet best practices. It discusses explicit user consent for information disclosure, handling transparent funds, and automatic shielding. It also distinguishes information visible through different viewing permissions. These are implementation recommendations, not proof that every wallet follows them. The draft itself notes incompatibilities in legacy behavior, making version and wallet identification important.
A wallet can offer a privacy feature while choosing a transaction path that reveals more than the user expects. For evaluation, identify the actual transaction type and inputs, not only a shield icon or balance label. Record whether the wallet discloses the consequence before submission and whether a user can distinguish watch-only information from spending authority. User-interface defaults are therefore relevant evidence in a technical privacy review.
Imagine a fictional ledger where ten people enter a private pool, but one publicly deposits an unusual amount and soon afterward withdraws a nearly identical amount to a publicly identified account. An observer might infer a connection. This does not demonstrate a broken proof: the observer is exploiting information around the private step. A careful investigator would state alternative explanations and the confidence of the inference rather than claim mathematical certainty.
Change the example so the funds remain shielded and circulate through several independent transactions before a public withdrawal. The observer now has a different inference problem. There is no universal waiting period or number of hops that guarantees safety. This exercise helps readers ask which observations an analysis actually uses, whether its candidates are independent and how off-chain records might change the conclusion.
ZIP 316 specifies unified addresses and viewing keys, illustrating that receiving destinations and observation permissions are separate design objects. Viewing authority can be granted without handing over a spending key. However, the precise scope depends on the key type and protocol. The specification also evolves, so a guide should not assume an address format's old behavior remains unchanged across revisions.
For a research note, draw three columns: information public on the ledger, information visible to the counterparty, and information available to a holder of a viewing key. Put each claimed privacy benefit in its correct column. Then list network metadata and account records outside those cryptographic boundaries. Optional privacy is best understood through these concrete disclosure paths; the availability of a private route does not imply that all users, applications or transactions take it.