Kihagyás

Privacy - Bitcoin Wiki

While Bitcoin can support strong privacy, many ways of using it are usually not very private. With a proper understanding of the technology, bitcoin can indeed be used in a very private and anonymous way.

As of 2019 most casual enthusiasts of bitcoin believe it is perfectly traceable; this is completely false. Around 2011 most casual enthusiasts believed it is totally private; which is also false. There is some nuance - in certain situations, bitcoin can be very private. But it is not simple to understand, and it takes some time and reading.

This article was written in February 2019.

Summary

Quick summary of how normal bitcoin users can improve their privacy:

  • Think about what you're hiding from, what is your threat model and what is your adversary. Note that transaction surveillance companies exist which do large-scale surveillance of the bitcoin ecosystem.
  • Do not reuse addresses. Addresses should be shown to one entity to receive money, and never used again after the money from them is spent.
  • Try to reveal as little information as possible about yourself when transacting, for example, avoid AML/KYC checks and be careful when giving your real-life mail address. Use email aliases whenever possible.
  • Use a wallet backed by your own full node or client-side block filtering, definitely not a web wallet.
  • Broadcast on-chain transactions over Tor, if your wallet doesn't support it then copy-paste the transaction hex data into a web broadcasting form over Tor browser.
  • Use Lightning Network as much as possible.
  • If lightning is unavailable, use a wallet that correctly implements CoinJoin.
  • Try to avoid creating change addresses, for example when funding a lightning channel spend an entire UTXO into it without any change (assuming the amount is not too large to be safe).
  • If digital forensics are a concern then use a solution like Tails Operating System or Qubes OS.

Introduction

Users interact with bitcoin through software which may leak information about them in various ways that damage their anonymity.

Bitcoin records transactions on the block chain which is visible to all and so creates the most serious damage to privacy. Bitcoins move between addresses; sender addresses are known, receiver addresses are known, and amounts are known. Only the identity of each address is not known.

The linkages between addresses made by transactions are often called the transaction graph. Alone, this information can't identify anyone because the addresses and transaction IDs are just random numbers. However, if any of the addresses in a transaction's past or future can be tied to an actual identity, it might be possible to work from that point and deduce who may own all of the other addresses.

Example - Adversary controls source and destination of coins

An adversary runs both a money exchanger and a honeypot website meant to trap people. If someone uses their exchanger to buy bitcoins and then transacts the coins to the trap website, the block chain would show the connection. The adversary can identify Mr. Doe through the combination of bank transfer data and blockchain analysis.

Example - Non-anonymous Chinese newspaper buying

  1. You live in China and want to buy a "real" online newspaper for Bitcoins.
  2. You join the Bitcoin forum and use your address as a signature. Since you are very helpful, you manage to get a modest sum as donations after a few months.
  3. Unfortunately, you choose poorly in who you buy the newspaper from: you've chosen a government agent!
  4. The government agent looks at the transaction used to purchase the newspaper on the block chain, and searches the web for every relevant address. He finds your address in your signature on the Bitcoin forum.
  5. A major reason this happened is because of address reuse.

Example - A perfectly private donation

  1. Run a Bitcoin Core wallet entirely through Tor.
  2. Download extra data over Tor so the bandwidth isn't exactly blockchain-sized.
  3. Solo-mine a block, send newly-mined coins to wallet.
  4. Send entire balance to donation address.
  5. Destroy the computer hardware used.

This scheme is extremely private. The only way to attack it is to be a global adversary that can exploit weaknesses of Tor.

Multiple interpretations of a blockchain transaction

Consider this transaction:

1 btc  ---->  1 btc
3 btc         3 btc

At least nine possible interpretations exist: 1. Alice provides both inputs and pays 3 btc to Bob. Alice owns the 1 btc output (change). 2. Alice provides both inputs and pays 1 btc to Bob, with 3 btc paid back as change. 3. Alice provides 1 btc input and Bob provides 3 btc input, Alice gets 1 btc output and Bob gets 3 btc output (CoinJoin). 4. Alice pays 2 btc to Bob (PayJoin transaction). 5. Alice pays 4 btc to Bob (using two outputs). 6. Fake transaction - Alice owns all inputs and outputs, moving coins between her own addresses. 7. Alice pays Bob 3 btc and Carol 1 btc (batched payment). 8. Alice and Bob pay 4 btc to Carol (CoinJoined batched payment). 9. Other combinations.

It's completely false to say that bitcoin transactions are always perfectly traceable. The reality is much more complicated.

Threat Model

When considering privacy you need to think about exactly who you're hiding from. Privacy requires a change in behaviour, not just downloading software.

For details read the talk "Opsec for Hackers" by grugq.

Method of Data Fusion

Multiple privacy leaks when combined together can be far more damaging to privacy than any single leak. Each privacy leak eliminates many candidates for who the sender is. Two different privacy leaks eliminate different candidates, leaving far fewer remaining.

The Chinese newspaper buyer was deanonymized because of a combination of visible transaction information and his forum signature donation address. Together the two privacy leaks resulted in serious consequences.

Why Privacy

Financial privacy is essential for:

  1. Fungibility: If you can distinguish one coin from another, fungibility is weak. Weak fungibility leads to blacklists, censorship, and centralization.

  2. Free markets: If suppliers and customers can see all your transactions, you cannot effectively set prices or compete.

  3. Personal safety: Thieves can target you if they can see your holdings.

  4. Human dignity: No one wants nosy neighbors commenting on their spending habits.

Globally visible public records in finance are completely unheard-of and arguably intolerable.

Blockchain Attacks on Privacy

Common-input-ownership heuristic

If a transaction has more than one input then all those inputs are assumed to be owned by the same entity. CoinJoin breaks this heuristic.

Change address detection

Change addresses can be detected through:

  1. Address reuse: Reused addresses are likely payment outputs, not change.
  2. Wallet fingerprinting: Different wallets create transactions differently (address formats, script types, BIP69 ordering, nLockTime, low-R signatures, etc.).
  3. Round numbers: Payment amounts often round, change is non-round.
  4. Fee bumping: RBF transactions reduce change amounts.
  5. Unnecessary input heuristic: If one input could have been avoided, it suggests which output is change.
  6. Sending to different script type: Different script type from input suggests payment.

Transaction graph heuristic

Addresses are vertices, transactions are edges. Taint analysis tracks "tainted" coins through the graph, though it doesn't account for transfer of ownership.

Amount leaks

  • Input amounts reveal sender wealth (sending from 10 BTC input to pay 1 BTC reveals at least 10 BTC holdings)
  • Exact payment amounts (no change) suggest same ownership

Batching

Payment batching shows recipients each other's addresses and amounts.

Mystery shopper payment

Adversary pays target to obtain one of their addresses and learn about their business.

Forced address reuse

Adversary sends small amounts to already-used addresses, hoping the user will spend them together with other UTXOs, linking more addresses via common-input-ownership.

Amount correlation

Searching for output amounts near a known input amount can unmix some privacy tech.

Network-level Attacks

Sybil attack

Adversary runs many nodes to learn IP addresses of transaction originators.

Observation of addresses

Network observers can learn which IP address knows about an address.

Traffic analysis

Analyzing timing and volume of network traffic.

BIP 324 transport encryption

Provides encryption between nodes, prevents passive eavesdropping.

Dandelion

Privacy-enhancing transaction broadcast: "stem" phase (one node), then "fluff" phase (diffusion).

Other Attacks

User's software

Wallet software may leak information.

Public transaction history

Anyone can search past transactions.

Public websites

Exchanges and merchants may have poor privacy.

Email address

Giving email connects identity to transaction.

Wallet backups

Wallet backups contain all private keys and transaction history.

Privacy-enhancing Technologies

Avoiding address reuse

Each address should be used only once. Avoiding reuse makes wallet fingerprinting harder.

Multiple interpretations

Use wallets that create transactions with multiple interpretations.

Change outputs

Wallets should create change outputs properly without leaking information.

BIP 324 transport encryption

Encrypted P2P connections.

Dandelion

Alternative broadcast protocol for transaction privacy.

CoinJoin

Multiple users create a transaction together, breaking the common-input-ownership heuristic. Implementations include JoinMarket, Samourai Whirlpool, Wasabi.

PayJoin

A type of CoinJoin where the receiver contributes an input. Appears as normal transaction, breaks common-input-ownership heuristic. Steganographic.

CoinSwap

Protocol for transferring coins between two addresses without on-chain connection. Uses multiple transactions with hash preimages. Like Lightning but on-chain. Implementations include Teleport, BTCPay Server.

Lightning Network

Off-chain transactions. Not visible on blockchain. But has privacy issues: routing nodes see amounts, can probe channel balances, topology reveals information.

Payment codes / BIP 47

Reusable payment codes that derive unique addresses. Avoids address reuse notification problem.

Silent payments

Reusable address that doesn't appear on blockchain until spent. Uses ECDH to derive unique addresses.

JoinMarket

Decentralized CoinJoin with liquidity markets.

Samourai Whirlpool

CoinJoin implementation with mixing pools.

Wasabi Wallet

CoinJoin wallet using Chaumian mixing.

Switching to a different wallet

Create new wallet with fresh addresses, send all coins to break link with old wallet.

Cold storage

Offline wallet doesn't leak information about addresses.

Air gap

Physically isolated from internet.

Tor

Route traffic through Tor network.

Tails / Qubes OS

Operating systems designed for privacy. Amnesic (no persistent storage by default).

In-person / Cash-by-mail

Obtain bitcoins without KYC. Meet in person, use cash.

ATMs

Some Bitcoin ATMs require minimal KYC.

Bisq / Hodl Hodl / Robosats

DEXs and P2P marketplaces for KYC-free bitcoin acquisition.

Monero / Altcoins

Monero has privacy by default. But introduces counterparty risk (tracing back to exchange).

See Also

References

Full references available at: https://en.bitcoin.it/Privacy

Vissza a tetejére