Faster, cheaper bitcoin transactions? Check. But at what cost?
For bitcoin users, many of whom were drawn to cryptocurrency for its promise of financial sovereignty, bitcoin is still synonymous with privacy. But the gap between the vision and the reality, in which user transactions today must be published to a globally distributed ledger, has long been one of the technologyâs biggest points of controversy.
âBitcoin is Twitter for your bank account. Everything is public to everyone,â Ian Miers, the co-founder of the privacy-centric cryptocurrency zcash, told CoinDesk.
Compounding matters, however, is that as bitcoin users get closer to gaining a whole new way to send transactions, powered by an innovation called the Lighting Network, concerns are spreading that privacy could degrade from its already imperfect state.
On the surface, the idea might seem promising â because Lightning payments occur âoff-chain,â the information isnât included in the blockchain that all nodes store.
But while there is no Lightning ledger so to speak, payments in the scheme are still broadcast across nodes within the network. Essentially, to ensure routing is always available, those using Lightning channels need to trust other network users to help relay transactions.
Conceptually, this means that participants within the system could pry on a transaction, or even potentially sell that information to governments or advertisers. This is a risk thatâs worsened if the network becomes centralized into a âhub-and-spokeâ type structure, where hubs are large, well-known and often-used entities.
âLightning likely wonât improve privacy, it may make it much worse from an average consumerâs perspective,â Miers added.
And like many, more speculative concerns surrounding the upcoming tech, the risk to user privacy may not be obvious until the network is deployed â an uncertainty that, combined with a wave of efforts on behalf of Lightning developers to include privacy features, has led to mixed sentiments as to what the future of private bitcoin transactions might be.
According to privacy researcher Kristov Atlas, in a worst-case scenario, privacy attackers could âthriveâ on hubs âvampirically feeding offâ the data as he wrote in a blog post.
However, the upcoming Lightning release does have some privacy features embedded, and thereâs reason to believe that developers are at least making advances on the problem.
To date, the most advanced privacy feature included within Lightning is called âonion routing,â and itâs part of the Basics of Lightning Technology (BOLT), a series of protocols that ensure the multiple iterations of Lightning can interoperate.
In onion routing, payments are passed through multiple channels, and only the minimum of information about that payment is exposed.
For instance, upon receiving an encrypted payment, a node can only know where that payment came from and to what node that payment should be relayed.
According to Olaoluwa Osuntokun, a leading figure in Lightning development who first suggested the scheme on the developer mailing list, the importance of this is that nodes canât be selective when it comes to what payments theyâre willing to take.
âNodes shouldnât be able to arbitrarily censor certain payments, or blacklist certain destinations within the channel graph,â Osuntokun explained.
Often compared to the Tor network for its use of onion routing, Lightning has occasionally been celebrated as a darknet for bitcoin payments â however, itâs comparatively untested, and could face some of the problems native to Tor as well.
âSimilar to Tor, there exist known possibilities of timing leaks, and also unknown active attacks that may be viable,â Osuntokun said.
And according to some, thereâs ways that onion-routing could be manipulated, leading to the loss of privacy, especially in an early Lightning network.
For example, the last node within a route, as well as whoever sent that payment, will know the transaction information, and theoretically, nodes could collude to break privacy, piecing together each layer of the payment in order to create a complete picture.
On top of this, thereâs the risk of a âglobal adversary which is able to instantaneous monitor all channels on the network,â something that the current privacy protocol doesnât address, Osuntokun continued.
And thereâs further defects to privacy on Lightning today as well.
For example, Lightning payments are currently given a fixed identifier that is repeated throughout the entire route. âThis means that if an adversary has two non-contiguous nodes on the route, then they can trivially link a payment flow,â Osuntokun said.
That said, Osuntokun assured that thereâs ways to correct this in future.
For example, if Schnorr signatures, a scaling method that works by aggregating public keys, are adopted into bitcoin, it could correct this issue in a âsimple and attractiveâ way, Osuntokun said.
Plus, thereâs other, âmore heavy weight solutionsâ such as using zero-knowledge to encrypt payments. However, because this encryption device is heavy, it will âsignificantly increase the amount of data one needs to send in order to complete a payment,â Osuntokun said.
According to Osuntokun, the âlowest hanging fruitâ is to obscure this payment identifier with random numbers as the payments pass through the network.
Even more speculative risks exist as well, but according to Miers, itâs all highly contingent on the structure that the Lightning network will take.
âSome people think the amount of money you need to lock up in a channel and the costs of running nodes will inevitably lead to centralization,â Miers said. âAnd then thereâs clearly no privacy.â
Because onion routing works by passing payments through multiple nodes, in the case of a highly centralized network, active nodes could have perfect visibility of the payments.
However, Blocksteam engineer Christian Decker told CoinDesk that the development teams are creating âcounter measuresâ against this risk of centralization.
Programming the system to open channels at random, Lightning âtries to avoid having hubs that can observe traffic,â Decker explained, which has the added benefit of âstrengthen[ing] the network as a whole against single points of failure.â
Decker said that this randomness could be extended to how routes are formed on the network, making payment paths less predictable but potentiality increasing fees.
Other researchers maintain the risk involved in maintaining a node with high throughput will stave off the formation of centralized hubs.
Miers concluded:
âWe will see which one actually ends up happening.â
Disclosure:Â CoinDesk is a subsidiary of Digital Currency Group, which has an ownership stake in Zcash Company, the for-profit entity that develops the zcash protocol.
Tesla coil image via Shutterstock