Revised Nym for ZCash Network-level Privacy

Hey everyone, just so you know Nym has officially completed the grant. You can read more on our blog post here (Nym mixnet now live in Zcash wallets | Nym), but here’s all the libraries we produced, and the Nym mixnet is now integrated into ZKool and Zingo wallets, with more coming soon we hope!

Improved Network Privacy Threat Model and Design Document for Zcash. This will be delivered by the Nym Research team; furthermore, we will use our network of privacy experts, including the Zcash Foundation, for a review. This document will be iterated as the integration continues.

The network privacy threat model document is now fully fleshed out, with clear guidance on recommendations for Zcash integration and design for developers - and animated graphics! Threat models and concrete implementation recommendations against a wide variety of threats, from a compromised lightwallet server to a local and global passive adversary are covered, each with a set of remediations using Nym. See the Threat Model and Design Document for Zcash here: https://zcash-sdk.nym.com/

Create HTTPS Connect Proxy for Nym to allow Nym to work with gRPC

We have made several Rust crates to deal with different traffic scenarios (tx send vs wallet sync) / threat models (untrusted endpoints vs GPA), to offer as many options as possible for ZCash wallet developers. All of these crates are available at crates.io. For when and where to use each crate, see the recommended hybrid integration approach.

A new networking crate was developed based on the original “proof of concept” that involves sending traffic through the Mixnet and then out to the internet via an Exit Gateway, de-linking the traffic from the user but allowing the endpoint to see transactions:

  • nym-smolmix is a userspace TCP/IP crate that runs over the Mixnet, allowing developers to swap in existing TCP or UDP streams/sockets with the same interface. It utilizes Nym’s IP Packet Router services to proxy traffic out of the Mixnet, meaning that integration is only client-side for wallet developers, and they don’t have to modify their addressing scheme. This allows developers to route HTTP(S) and gRPC traffic over the Nym mixnet and so is the key crate for using Nym mixnet with existing Zcash wallets.

We also created transport-independent pattern hygiene for crates: shaping the timing and content of your requests before they leave your device.

  • Nym-swizzle simply changes what your application puts on the wire and when. It is transport-independent - it works the same over the Mixnet, a VPN, Tor, or a direct connection.

  • Nym-swizzle-zcash is a crate utilising -swizzle but adapted specifically for ZCash with regards to timing assumptions and block times.

This crate can directly be integrated into both native and Rust wallets. FFI bindings for Go and C were also created by @maxnym from Nym:

Create a Service Provider component (transactions submission service) that would run between the mixnet and Zcash nodes:

Service providers may also want to be inside the Nym mixnet, and not accessible from outside the Nym mixnet. This is somewhat equivalent to running a “hidden service” for Zcash transactions inside the Nym mixnet. Full documentation for service providers is given our Zcash Wallet Design: Service providers — Zcash × Nym

In order to enable this use-case, we created a new crate:

  • The nym-sdk::Stream module is an abstraction that provides persistent, bidirectional byte channels that behave like TCP sockets over the Mixnet. This requires integration with both wallet and infrastructure code, as it does not rely on the Exit Gateway services to proxy tunneled traffic, but instead sends directly between Nym Client peers.

Integration via lighwalletd for sending, and possibly receiving, transactions.

In particular, we created documentation for Zcash wallet developers to show how to make lightwalletd as a service provider: Fork of lightwalletd + service provider — Zcash × Nym

There has been some vibecoding around it, including GitHub - nymtech/nym-rpc · GitHub and some work by the developers of Nosy Wallet like Lwd-mixnet-proxy: light-wallet gRPC over the Nym mixnet, and what three days of measuring it found - #31 by Joaco .

If you want to try it out, this service (used by ZKool) is completely inside the Nym mixnet, similar to a Tor Hidden Service. It can be accessed here: nym://BbTPrU1gNTsPiieXdC58xkp5QFSHhUUM98BP1Rm2adf9.GKiGLNQB116YszFwbuweeL2GsrfpHpuUzq6JuqFQ8EEE@ZXSDhRTKU5HgMpH8ma78FftvLiKyZ6jWL1e2U7GD7gQ

We at Nym are happy to answer any questions here!

8 Likes