pull down to refresh
this idea opens the path for an economically rational ecosystem that creates herd privacy as a side effect
That's the correct framework to approach solutions with, so off to a good start.
#1562360
I take some issues with this, others apply to coinjoins/vtxo's as well because of the coordinator replacing the peer or swap provider.
Point of order, bolt11 can do blinded paths.
It does reduce to good practices are still required, which is correct, and that's also part of my framework of thinking about these issues.
Ring change channels
Would take time I don't have to dive into the detailed mechanics of this properly and form a mental model, so the following impressions from a quick first pass.
I think this is presupposing the bifurcation of the coordinators. The VTXO coordinator has different information than the CoinJoin coordinator in theory, but I'm not sure that's true, because if the change is obvious on chain then its provenance is just as obvious to the VTXO coordinator.
I don't think it can be assumed that the VTXO coordinator is oblivious to the movement within the lightning channels after the fact either. You may shield chain information from your channel peer, but the same sybil risks still apply and are perhaps made worse by the VTXO coordinator having an incentive to secure Lightning liquidity.
A swap offers a different exposure profile, not an automatic anonymity guarantee.
I think this recognizes to the crux of the issue, if you use the VTXO to wash the change, its still roughly the same amount on-chain within a few bps with a similar heuristic of entrance/exit out of a coordinated scheme. I don't see what's additive by the extra steps.
Since we can't reasonably assume bifurcation of the coordinators given the shared chain view nor sybil resistance of the off-chain movement, I think this might be an over-complication of an Ark etc that only allows chain outputs of a given size with anything other than that being restricted to a Lightning payment so there are no change outputs at all.
What I don't know is if that an Ark can enforce those output size constraints, that would undermine any unilateral exit claims, which may be why you've arrived at 2 coordinators with different tasks but not inherently blinding the second.
From an economics standpoint, I don't see what appeals to the herd to make privacy the by-product of something other. Sitting on would-be change in a virtual channel adds even more costs with rounds. Since there's those added costs privacy is ultimately the product, which combined makes it honeypot. There's always going to be a cost to enter a privacy scheme vs. making a direct payment. Even if you get the post mix output costs down substantially through batching, its still at least a second tx that needs confirmation.
At the risk of sounding like a nihilist on these matters, I think what you're trying to solve is intractable. At least this is outside the box a bit and combining different elements, unfortunately I think it's just moving problems around though.
If an epiphany strikes me i'll follow up.
At the risk of sounding like a nihilist on these matters, I think what you're trying to solve is intractable.
Translation: "There's nothing wrong with coinjoin Lightning channels, but I will shit on them for absolutely no reason."
Your illiteracy is evident yet again
Thanks for having a look!
I think I didn’t make the construction clear enough: there are no VTXOs or second coordinator here. The CJ (coordinated by the taker) directly creates jointly funded LN channels instead of individual change outputs, so there’s no separate channel-opening tx.
The taker knowing the initial splits is assumed. The intended setup doesn’t disclose the other channels’ node IDs or subsequent updates through coordination. It still sees its own channels, of course, and Sybils/collusion remain a concern.
For an outside observer, the uncertainty isn’t just a few bps around somebody’s change. Each funding output combines two people’s contributions, and many balance splits fit the same public capacities. Those balances can then change offchain. The funding history doesn’t disappear, but the output is no longer one person’s change balance. Cooperative spending of the whole channel can be achieved with a escrow (akin to atomic LN swaps) with the settlement paid over LN, so that when the channel closes the split is not leaked onchain (and it would have possibly shifted by then).
Economically, the idea is another way to obtain and rebalance liquidity. LN users could get channels with liquidity on both sides with better privacy than using a UTXO to open a channel directly. It also puts JoinMarket makers in a very good position for being decentralized LN swap providers (much needed ATM).
The aim is to reduce what’s publicly exposed, not eliminate every observer’s knowledge (which I agree might be impossible in L1). Fair correction on BOLT11 blinded paths, will clarify.
Dual funded batches are better than VTXO's so thats good.
Perhaps flipping the description makes for an easier mental model of utility, think of the change as what's not going into the channel. You want a channel, you send an amount to get a batch channel, and everyone gets the same amount of post-mixed "change".
That might be cost neutral* vs. a regular LSP and doesn't rely on absolute privacy as the selling point, its a mostly regular operation with a plausible privacy dividend.
*cost neutral assuming the person getting a channel wouldn't have committed a whole utxo to a channel anyway
Idiots will still use it assuming absolute privacy and turn it into a honeypot eventually, and the maker is still a surveillance choke-point, that's the tragedy of the commons with these things. But, if it is cost neutral, and some creative UX can be applied, a large enough anonset could emerge that raises the bar against low-sophistication trackers and provides non-honeypot incentives for makers.
Interested on @justin_shocknet's opinion on this. I know you think CoinJoins are bullshit, and your views on privacy solutions becoming honeypots/counter productive. But hopefully this idea opens the path for an economically rational ecosystem that creates herd privacy as a side effect.