If you can’t control your emotions and start FUD’ing XMR just because ZEC got an ETF and is pumping, I don’t want to follow you.
Monero will never have an ETF; it’s actually private and used by dissidents. The system you claim to hate would rather you hold BTC and Zcash instead.
Once you enter a privacy coin circular economy, never make an exit!
You want to buy something in the physical world? Find sellers who will take your coin.
We are out there!
Revolut banned GrapheneOS users.
GrapheneOS is more secure than any Google-certified Android.
Revolut still runs on Android 9 with no security patches since 2018.
The security justification is not about security....
Revolut recently banned using GrapheneOS without any justification. They're falsely claiming to do be doing it for security reasons. In reality, they're enforcing licensing Google Play. Revolut doesn't enforce security standards. It runs on Android 9 with no patches since 2018.
“We must defend our own privacy if we expect to have any. We must come together and create systems which allow anonymous transactions to take place.”
— Eric Hughes, A Cypherpunk’s Manifesto (1993)
⚠️ Monero + Tor : une faille réseau vient d’être exposée !!
Le Monero Research Lab se réunit demain 29 juillet pour en discuter...
Monero est conçu pour cacher :
👉 qui envoie
👉 qui reçoit
👉 et combien
Pour protéger aussi l’adresse IP de l’utilisateur, beaucoup de gens (et de nœuds) font passer leurs transactions via Tor
Le paper montre qu’il existe une faille au niveau du réseau (pas dans la cryptographie de Monero elle-même) quand on utilise Tor avec Monero
Explication...
Quand un nœud Monero tourne derrière Tor :
➡️ Il crée une adresse oignon (hidden service)
➡️ Quand il veut envoyer une transaction, il ne la diffuse pas directement sur internet clair
➡️ Il l’envoie d’abord uniquement à deux nœuds Tor proxy (des hidden services sortants) avant que la transaction ne passe sur le réseau Monero normal (clearnet)
C’est une particularité de la façon dont Monero gère les connexions Tor
Un attaquant peut :
👉 Prendre la place de ces deux connexions sortantes du nœud cible
👉 Capturer les transactions qui sortent de ce nœud
👉 Puis utiliser une technique appelée watermarking (marquage du trafic) pour lier l’adresse oignon Tor à la vraie adresse IP de la machine
Ils appellent leur méthode ProxyMark
Elle se déroule en trois étapes :
➡️ Identifier le rôle des nœuds (qui est un proxy, qui est un client, etc.)
➡️ Capturer les transactions qui originent du nœud cible
➡️ Dé-anonymiser la localisation (trouver l’IP réelle)
Les auteurs ont testé leur attaque sur :
👉 le réseau Tor réel
👉 le mainnet Monero
👉 et le testnet
Résultats rapportés :
Identification des adresses oignon : 100% de précision ‼️
Occupation des connexions sortantes :
Très efficace (7 à 11 sur 12 connexions selon les conditions)
Watermarking :
100% de précision et plus de 91-93% de rappel
Autrement dit, dans les conditions de leurs expériences, l’attaque fonctionne très bien !
👉 Ça ne casse pas les ring signatures, les stealth addresses ni RingCT
👉 Ça ne permet pas de lire le contenu des transactions Monero
👉 Ça ne dé-anonymise pas les utilisateurs qui n’utilisent pas Tor de cette façon (ou qui utilisent Tor correctement avec d’autres précautions)
C’est une attaque réseau... elle exploite la façon dont Monero et Tor interagissent ensemble, pas la crypto on-chain
Le Monero Research Lab en discute demain 29 juillet
Ils vont regarder s’il faut changer quelque chose dans le code
Bref... Dès que deux protocoles se rencontrent, un point faible apparaît souvent 😉
#Monero #Tor #Privacy
"Privacy is only for people hiding something."
So is a locked door.
So is a curtain.
So is an unlisted number.
Protection is being re-framed as "hiding".
Locks were never about guilt.
They were always about who gets to decide who enters.
On Friday the 15th of May, we became aware of a fingerprinting issue affecting Mullvad users.
We have a method which changes this behaviour currently being tested, with plans to begin rolling it out to our VPN servers in the coming weeks.
Read more here: https://t.co/MH32Odwrj0
PSA: please update Tails with the latest release. It is an emergency release to fix a critical security vulnerability in the Linux kernel, as well as security vulnerabilities in Tor Browser and in the Tor client. https://t.co/2fkXzsxngs
We're celebrating our 12th birthday today! 🎉
A happy Moneroversary to all, to many more years of Monero being at the forefront of privacy, keeping your transactions and holdings private and secure!
"Privacy is dead."
Then why do:
CEOs use encrypted phones.
Executives demand NDAs from staff.
Billionaires build compounds with no public address.
Privacy didn't die.
It was redistributed upward.
"I have nothing to hide."
False.
You have medical history.
You have financial behavior.
You have location patterns.
You have political views.
You have relationship data.
Privacy was never about hiding crimes.
It was always about owning your life.
GrapheneOS will remain usable by anyone around the world without requiring personal information, identification or an account. GrapheneOS and our services will remain available internationally. If GrapheneOS devices can't be sold in a region due to their regulations, so be it.