# Smart Accounts need Smart Sessions

- Channel: [EthCC](https://streameth.org/ethcc)
- Date: 2024-08-30
- Duration: 27:15
- Topics: Sorry
- Watch: https://streameth.org/watch/66d1837135d51347e0856ae7

## Description

The world of dapps is evolving and wallets are becoming smarter. This is powered by developments in Smart Accounts which unlock more user-friendly experiences. Learn about how WalletConnect will introduce Smart Sessions The text provided does not contain any specific information to summarize. If you can provide the content of the video or a description, I would be happy to help summarize it for you.

## Transcript

All right, everyone. Thanks for joining. As you can see from the screen, we're going to talk about WalletConnect. Or more importantly, we're going to talk about wallets. And you know, the definition of a wallet has changed a lot, and it's going to continue changing. So we're going to go a little bit through a journey here. And we're going to have to be fast. So first, to introduce myself, my name is Pedro Gomez, and I'm the founder of WalletConnect. We connect wallets, as it says in the name. But today, we're going to be talking about how smart accounts need smart sessions. And then we have to ask ourselves, what is a smart account, and why do we need smart sessions? Well, let's start breaking down the lingo. There's a lot of, like, new names, and, like, Web3 really likes to reinvent the wheel here. And you might have seen all of these words thrown around, and you basically have to be proficient in all of these words to even reply on Twitter. But most importantly, the big change in Web3 is that we moved from a login to a connect. But what does that actually mean, like to move from a login to a connect? It essentially is the same thing. It just kind of defines this idea of authentication, which is basically just a process of identifying you are who you are. And when you actually do it, whether it's in Web 2.0 or Web 3.0, what the user actually thinks about it is just like, let me in. Like, they don't care. Like, it's not important to them. They just want to use your app. And actually, authentication is just one step towards that. So you have to do it in as less clicks as possible. So less clicks is more. That's our mission. That's how we're going to achieve the superior wallet experience, and now we're actually going to onboard users with a better wallet. So why is Web3 different? Why do we need to reinvent the wheel? Why is everything so difficult? Basically, when you look at Web2, you actually have on the left a server, which the application connects to. And a server is a lot of things. Like if you build a server, it's not just one thing. It's actually now we have the term like microservices, and they're all interconnected. It's not a monolithic piece of code. But one of the most important ones is the authentication part. And that lives on the server. Well, when we moved into a blockchain ecosystem with Web3, that authentication moved into the user's device as a wallet. So in a sense, authentication is a wallet, and that lives on the user's device, and the blockchain does not have authentication in itself. The user is in controlled authentication, and neither does the app has controlled authentication. So let's start by defining what a wallet is. I like to define it as three parameters, and regardless if it's a software, mobile wallet, browser wallet, hardware, or even like some new design with like a cloud wallet, an MPC wallet, it all comes down to a set of credentials, which actually enables your wallet to work, some signing, which can happen locally, remotely, on-device, hardware, software, and then accounts. And as you see from this presentation, we're going to talk about smart accounts, but all wallets today are pretty much external accounts. And we're going to talk why. So in order to authenticate, it used to be really hard before, because people would connect their wallets but you actually didn't know if they are the wallet who they are. So everyone started signing these little cryptic messages to actually verify them and it was really a terrible experience so the sign-in with Ethereum standard made it much easier and much more human readable. It currently looks like the left, and as you can see, this message kind of resembles a little bit the existing Web2, where it says this website wants to access this account, and you have to accept some terms of service. Hopefully, in the future, wallets will introduce a better user experience where you actually might have something like this. OpenSea wants to access this ENS name, and you will be able to send and receive NFT assets on OpenSea, and you accept the terms of service. So in a sense, Signup Ethereum is just another Google login, Facebook login, whatever you want to call it, but just for blockchain. So it did solve one problem, but it also introduced another problem, which is now you have to connect to your wallet, and then you have to sign a message. So at WalletConnect, we created a standard to solve this problem, which some wallets have supported today. And with CIP222, we just removed the need from Connect and just jumped into signing, which was a big step for, you know, less clicks is more. And it looks just like you would when you connect to wallet, but you're also authenticating yourself. So you're essentially signing in with Ethereum when you establish your connection. But is that enough? Like at the end of the day, a wallet is not just a piece of identity, it's also something that manages your accounts with a lot of state and assets. And at the end of the day, you need to sign transactions. That's actually what makes Web3 really interesting because you have granular control of every action that is taken that interfaces with your account. And most people just close your eyes and approve. Like, unfortunately, no matter how much you tell yourself that, like, people are reading these transactions and verifying, they're just, like, closing their eyes and approving because they just trust the app. But that's not the right way of thinking about it and we need to kind of like fix this in a way that's both striking a balance between convenience and security but at the same time is actually making it a better internet so let's stick to our mission less clicks is more we can achieve all the features of blockchain and still have as less clicks as Web2. Let's talk about the accounts. So we talked about external accounts and smart accounts, but what makes a difference? An external account has a single signer. That singular key is your account and nothing else. You lose that key, you lose your account. In a smart account, you can have multiple signers. Those could be multiple individuals signing, but it also could be multiple devices. It really doesn't matter. Like a smart account is just a much more programmable account that allows you to manage that account with less risks on a singular key. With that, it comes with a consequence, which is a nice feature, that if you have multiple signers, who is actually paying for that? You actually don't have to pay with the same signer. You actually decouple the idea that the signer is the payer, which is mandatory by design in the external account. And then another feature that it comes with is that the blockchain cryptography is no longer mandatory. is that the blockchain cryptography is no longer mandatory. You might not know what 256K1 means, and it doesn't matter, because that's blockchain responsibility, not our responsibility. When you support any curve, you basically can support what you as a user support, whether you're on Android, whether you're on Google, whether you're using a smart TV, whether you're using a hardware wallet, or a YubiKey if you're really proficient. That's what we should be using as signers. And that's what smart accounts can enable us. And when you think about smart accounts, there's actually these terms, you know, blockchain, reinventing the wheel again, externally owned account or EOAs, and smart contract accounts and SECAs, and it's just really hard. So we're just like, think external account and smart account. How can we migrate people to smart accounts? The smart account's biggest definition here is that you need a smart contract to be deployed. But then again, like if you have a smart contract, you don't have a key. So when we had sign-in with Ethereum, we had to sign a message. So who actually signs this message? Because we can no longer have this tightly coupled verification of one key, one account. And there's a standard called 1271 that fixes this problem, which basically just says, hey, you as an app, don't just like verify the key, actually check with my smart contract accounts if this key is a signer. So once again, another thing that's been solved, some apps are not supporting this, which is a big problem for adoption smart account, and we need to fix that by having more 1271 support. But we don't stop there. So things get a little bit more complicated once we actually go into the transactions, because now we have multiple apps and multiple wallets, and then you have one blockchain, but which smart account are you going to use? Ideally, you want one smart account everywhere. Like, it doesn't matter what wallet and what app, you just have one big smart account that manages your assets. And then you can just, like, fine-tune the scope of what each one of them can do. So what is actually being connected? When you connect, you expose the accounts that you have, you read some blockchain data, you create a session with the signer that will actually be signing on the behalf of your account. And for every request approval, you have to submit transactions. But this changed a lot with 4.3.7, especially around 2022, where even the definition of signing transaction was very different. And they even had to once again rename transactions to user operations. The reason they renamed the transactions to user operations is because now we have a concept of a paymaster. As you saw, smart accounts, the signer is not necessarily the payer. So now we actually can have a third party paying for my gas. So we actually have the wallet sign a user operation, sends to the paymaster. The paymaster countersigns it that it says, I'm going to pay for this gas. And then the bundler is actually responsible for taking all of these user operations, which is a nice feature as well, where you actually can send multiple user operations and turns it into a single transaction in the blockchain. So now the good thing about this is the wallets don't need to care about the blockchain. And that's why we can use different cryptographic curves. Because we're not the ones actually submitting the transaction. So yeah, this is a good thing. But how do you actually discover if a wallet supports smart accounts? This is something that, you know, it's not going to be a smooth transition. Some external accounts would exist. Some smart accounts would exist. That's why we have to reinvent how the wallets talk to apps. And exist. That's why we have to reinvent how the wallets talk to apps. And with this new standard, 5792, you actually have new formatted, get capabilities, send calls, get calls, show calls. And this allows us, first of all, with send calls, to send multiple transactions as user operations. So you can see like this really cool example with our UIUI where you actually have depositing, swapping ETH to WEF, and then you actually having buying a doodle with some of that WEF. And basically that all happens with multiple user operations that is all batched by the bundler. And then this would also be able to be sponsored by a Paymaster. But then the most important part is that you also introduced the idea of get capabilities. And basically you can ask the wallet, do you support Paymasters? Which Paymasters do you support? And what is the interface for these Paymasters? Well, this was the original idea. But then we realized that every Paymaster was doing something a little different, but they were all doing the same thing. So we then created a standard for Paymasters. And this is just going to be a journey of standard to standard because it's so hard to make smart accounts work if everyone is doing everything differently. So now Paymasters all work the same following the 7677 standard. So this is very competitive because then we can have both wallets paying for gas. We can have, for example, one inch paying for gas. And we have a much more competitive market for gas sponsorship. But even then, like, Paymaster standardization is only one part of the question. What if all smart contracts work a little differently? Like, what if you recover accounts differently? What if you manage your signers differently? What if you use your cryptographics differently? That's why we have also the standards being driven mostly by Rhinestone with 7579, but also in collaboration with ZeroDev and Byconomy and Wallacanang, where we actually have a more minimal interface of how we actually make smart contracts more modular. And then you kind of start making the question of, wait a second, if we already have all the standardization, we know how Paymasters can be used by ADAPT, we know how the modules can work in a smart contract. We know how to authenticate for a smart account. Why don't you just let the dApp sign the user operations?
