It wasn't until March 2024 that the Samourai guys addressed the change of identities in Tor to make the coordinator blind, and only applied on soroban which never went live and also on the desktop client. And it's one of the worst structured code I've ever seen and people trusted these guys with their privacy.... https://github.com/Archive-Samourai-Wallet/whirlpool-client/commit/fbee9e820f511661c888a53c75a5e5e610b000f5 nostr:note1s8g546a7j2de3ez2x27z8x4gh6qq20qmtfskr930f8wx2t0vysdssc97w9
So we can assume coordinator can link input-outputs for all the coinjoin transactions that were done before March 2024?
Yes, and I hope they have deleted the logs.
you can assume shit It was actually in the whirlpool client all along - it always used a different identity for output registration. https://github.com/Archive-Samourai-Wallet/whirlpool-client/blob/6eefd5b854110ad5758eb2b34be775ca44d867f5/src/main/java/com/samourai/whirlpool/client/whirlpool/ServerApi.java#L73
It is not used in the android app because it is computationally expensive, nor in sparrow. https://github.com/sparrowwallet/sparrow/issues/1328
Crickets
Wouldn't it be much fairer to address the devs directly? and it would be interesting to see you discussing your findings with the team. What's all your Samurai bashing about?
😂 the cult
they are in jail/ House arrest
Charge for a privacy service easily doxxed? I only analyze privacy methods, I don't give a damn who is behind it.
so what do you recommend for privacy in bitcoin?
Well, it's honestly a really difficult question and it depends largely on who you are protecting yourself against. A three-letter agency is not the same as a national government or any user.
i mean imo not without flaws (and the one you mentioned is a big one) but by far the best overall privacy solution in the space.
Samourai is not one of the best, in fact it is one of the worst.
name a better one
In order from best to worst: Joinstr Joinmarket Wabisabi And there are other non-coinjoin solutions such as Lightning that offer great privacy.
I can see why you'd rank like that, however if the only criteria would be privacy and nothing else, then the rank order would be reversed, wouldn't it?
If we are talking about privacy in chain, wabisabi from my point of view is the one that gives the best privacy, besides solving the problem of toxic change. It would be great if in the desktop client you could pay through coinjoin without having to depend on BTCPay Server.
It seems they just put that into the RPC yesterday. Although I don't personally think it's a good idea. I think payments in coinjoins will always have bad UX unless a proper P2EP is implemented, and everything that doesn't bring towards making the average Bitcoin user use Bitcoin privately by default is a distraction. But anyway, I'm not there anymore and even when I was I wasn't able to keep the project on track and kill all the advanced feature requests so all I can do now is to bitch about it on nostr😅 https://github.com/WalletWasabi/WalletWasabi/releases/tag/v2.3.0.0
Thanks for the info, I saw that it was included in the new version.
"don't trust verify" they say & it does pay @ least imho. it's taken sum of my time but glad i did spend. now i read all fine print & try to verify code from know sources. i think anyone can too, cuz, i'm not used to this nuance either & still trying to keep up. Bless this mess & ours! pow 866400
https://github.com/Archive-Samourai-Wallet/whirlpool-client-cli/blame/91f8609bad8a9d33948b915a01e89aae99c09034/src/main/java/com/samourai/whirlpool/cli/wallet/CliWallet.java#L72 https://image.nostr.build/f235bee06f4f20b0090a9e5109bcedcbcb5c50290f3ced4d7596c5783091729f.jpg
False, the Android app does not manage identities, nor does sparrow.
https://x.com/PavelTheCoder/status/1847820728462201333?s=19
bad actor Meister best to move along he was pushing LN as a privacy solution over Monero until recently
I guess I should have known better. those who need to call themselves cypherpunks ...
For the record, the whirpool-client code does have Tor identity management. The code I showed belongs to the new soroban implementation and I did not review the old client (very badly structured code). However neither the android app nor sparrow manage identities. The android app because it is computationally expensive, hence one of the reasons why wasabi never had a phone client and sparrow because it was not implemented correctly. I don't know what percentage of people were using said desktop client, but evidently everyone who has used the android client or sparrow has not been protected. nostr:note15720avmmchg6fy8rqmwxrxut3cy6kfg297l7scn3gjysemmzrfzsxjva9p
Mofos never used the wallet and it shows. Back when Whirlpool was still spinning, every time you'd submit a UTXO for a premix/remix, your android Samourai client would display a message that a new tor identity has been claimed when submitting that output. Stop this unproductive FUD shit show, go touch the grass and enjoy your day. Support the FOSS devs via p2prights.org #FREESAMOURAI https://image.nostr.build/227a0d7d82adcca0c889f8935698dd36b05a130e8d3694d86ce82824c78cb6c8.jpg nostr:nevent1qqsvy6tf55qwz4nm9ds5g7qgqptx8acqu8uturnd6nqcl3zy9wzvdfqpz4mhxue69uhkummnw3ezummcw3ezuer9wchsyg8u7u9ytnagzl42syaeh29rwht385ckna9z0u7u4s75jyfd7e7n0cpsgqqqqqqsrxvn35 nostr:nevent1qqsvy6tf55qwz4nm9ds5g7qgqptx8acqu8uturnd6nqcl3zy9wzvdfqpz4mhxue69uhkummnw3ezummcw3ezuer9wchsyg8u7u9ytnagzl42syaeh29rwht385ckna9z0u7u4s75jyfd7e7n0cpsgqqqqqqsrxvn35 nostr:nevent1qqs20987kdaut5dyjr3sdhrpnw9cuzdty59zl0lgvfc5fzgvaa3p53gpzpmhxue69uhkummnw3ezumt0d5hsyg8u7u9ytnagzl42syaeh29rwht385ckna9z0u7u4s75jyfd7e7n0cpsgqqqqqqs06qf6j