# AKI - Mycel Foundation | Web3Privacy Now - Tokyo Meetup 2025

- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-01-09
- Duration: 14:21
- Topics: Vitalik, Buterin, Ethereum, Cypherpunk, W3PN HACKS, web3privacy now, hackathon, Q&A, Blockchain, privacy, human right, Berlin, 2025, Education
- Watch: https://streameth.org/watch/yt--V98caG15kg
- YouTube: https://www.youtube.com/watch?v=-V98caG15kg

## Description

...

Useful links:
Web3Privacy now collective: http://web3privacy.info
Web3 privacy market dashboard: http://explorer.web3privacy.info
Cypherpunk Congress: http://congress.web3privacy.info

## Transcript

Hi. &gt;&gt; How's it going? &gt;&gt; Um, let's start. &gt;&gt; The floor is yours. &gt;&gt; Okay. So, hi, I'm Aki, co-ounder myself. And so, today we I going to talk about uh practical guide to software uh software verification. So, so people says um don't trust verify but so raise hand. Uh do you know how to verify the software in general? &gt;&gt; YouTube. &gt;&gt; Yeah. So I know the face. [laughter] Okay. So let's start it. &gt;&gt; Okay. &gt;&gt; Okay. Oh wait. &gt;&gt; Just meet you care. So &gt;&gt; yeah so quick introduction uh I'm Aki uh co-ounder myself which is a private uh chain agnostic oh [clears throat] &gt;&gt; nice &gt;&gt; decentral exchange for the peerto-peer uh tradings so my interest is OS operating systems hardware and peerto-peer uh tech technologies and cryptography implementation So another question. So do you use uh privacy focused application like signal uh any kind of words? Yeah. Do you? &gt;&gt; Yes. So next question is uh have you ever compiled uh the app like privacy focus there and for using it and have you ever look at it at code base of the before they compile the software? Oh wow. I I I know face. Okay. So uh in the crypto uh we love end to end encryptions. uh zero zero knowledge proof ensures complete privacy and fully decentralized um trustless and it said many applications says uh it's end and equipped even we can see that your data say this company so but how you can how we can verify it so promise is like just implemented as code it's not mathematic proof So and code is compiled to interbinary. So and the application uh the binary is like just um machine language. So you can lead uh directly if you don't have any if you don't have a special skills. And &gt;&gt; so so when you install apps uh you probably uh download application from the uh distri distributor's uh website but um so and the distributor says it's open source and the open source group uh so this code doesn't have a uh this open source code is audited so it's not corrupted but there's no guarantee that you should in this applications. So there is a verification gap between the source code and the binary. So they if if [laughter] the application uh crypto is a cryp uh sorry cryptography is perfect it's proved and the code is uh open source and the security orders reviews it and but no none of that matters if app you can uh download from that code. So how we are currently verify applications those open source applications is a it's basic uh way to the verify the application is like a hash verification so there's a developer and users so probably you are uh users so if you want to install application you you just download application from their website and download it and probably you just install it. But before install it, you can uh calcate hash and you can uh match the hash of the uh binary this it's you can uh check the it's a file wasn't corrupted during the download but um so this is a um hash verification. So this uh guarantees a file wasn't completely uh could not corrupt it uh during download and fire master was hashed but uh this doesn't guarantee uh who create a hash and what source code is compiled and whatever source had malware. So this is a problem and next uh method is you just read the code yourself. It's really hard to uh uh if you don't have a knowledge but if if you just read the code it's doesn't uh guarantees that it's its code is compiled to the uh uh binary in proper way. So, so you need to uh &gt;&gt; sorry uh you need to check the uh binary hash and the source code uh in so whole this whole process is required. So maybe uh another method uh you just download from the app source. So maybe you you guys have a phone and you probably install uh application from the uh what's it called? Uh app store. Yes, app store and Google play store. So this uh those uh company uh handles verifi verifications for you. So the process is like um just uh developers submit apps and the developer needs to uh uh register uh as their certificated uh developers and the safe the store company uh reviews malware reviews for malware is is there's no u suspicious code in there and the store signs up and you downloaded signed up is This this is a um usual way to install app your phone and so but this method has a uh &gt;&gt; few uh cons uh so instead of uh uh stores verifies uh application for you but uh you cannot uh verify applications independently. And also no art no alternative distribution method and the so there's no there are transparency in the labing process and uh probably uh uh platform can modify your apps uh without your permissions. Uh this is um a cons in the app stores. So, so you need to so as I said uh you need to verify the whole process like uh from source code to the uh application and the application should be uh download uh and the user devices this uh binary should be uh same with the first uh build uh views. So then uh reproducible bills comes in. Uh this serves u a source to binary gap. Uh given a identical source and build environment you get a bit for biting skin binaries and no matter who builds or who build it is when. Um so these systems uh guaranteed as a um this uh uh systems uh packaging the this uh process that uh source code uh compiling source code and calculate hash and the hash is like a it's you can check the hash uh from others uh compiled applications. So if you if multiple parties uh get identical binaries uh and it proves uh the binaries match from source code uh no back door was no back doors were inserted and during the compilation and the build process is completely transparent. So this is a uh bit uh example. So first uh developers builds application and this make build is uh command for the building application with uh reprod reproducible uh systems and independent uh verifier like users uh running the same command and uh returns exact same hash and and the people runs the build command and still the hash is still Okay. So uh there's some implementation uh to the uh completed uh reproducible I'm sorry reproducible bills package is wise a n os you can check the website if you want to use it and this next is a future has really uh the cache is really nice and if you interested in you can check it and So this is a use case of the reproducible bills. Um the Devian uh I think Debian has a 90 five percentage of package is lift reducible. Uh the have you used a tour to before you guys? Yeah. So is a refusal of course uh it's it's for critical for an bit bitcoin core also uh signal probably everyone signals so uh Android app uh app is verifiable and if draws is uh one of the alternative Android store of uh pre uh sorry what's how it's called uh play store yes uh as this is our alternative Android store with reproducible wheels. So uh another things is if you want the higher level guarantees uh if you want to uh get higher level guarantees you can combine with a trusted execution environment. This is a really interesting uh project. It's called autonomous build network is that uh you can uh running uh uh reproducible build with inside of TE is a trusted execution environment is &gt;&gt; it's guarantees uh uh computation uh in the sorry uh TE provides uh isolation from the user space uh in by hardware. So you can uh isolate the uh user space and uh you can encrypt the and you can sign any kind of um you can perform signing and uh you can verify uh after uh comparation outside of T. So this is really nice uh protocols. So &gt;&gt; same &gt;&gt; in conclusion uh what you can actually verify of the applications. So if you do uh hash check you can check that file integrity. So you can uh it's and if you it's open source software you can read so uh you can read source code and you can uh community can audit of it source code and the reproducible is a b uh provides a binary matching source and to the uh build uh process is transparent. So the option is like app store is like they uh you can uh use apps for the if you don't uh want to uh verify yourself you verify the basically um signature or build process right &gt;&gt; so so what you can talk today is like uh you can choose softwares that are pro hash verification And you can try the hash verification on your laptop. home and uh you can check that the your software is has a reproducible bills and is uh the software uh is the software is open source with active community and well audited and they use a sign lees and they um the software available through the gigs nroids. Yeah. Thank you. [applause] [screaming]
