New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

“Metadata Kills People”: Richard Carback on Why Privacy Matters | Privacy Academy Interviews

Ethereum Cypherpunk CongressTue, Oct 7, 2025, 12:00 AM

Dr. Richard Carback – Cryptographer & CTO at Quip Network | Privacy Academy Interviews In this deep-dive interview, Dr. Richard Carback shares insights from two decades in privacy tech. From his work on cryptographic voting systems inspired by David Chaum to his thoughts on zero-knowledge proofs, mixnets, and post-quantum security, Carback offers a unique perspective on building privacy for the digital age. Timecodes: 00:00 – Introduction & Early Journey into Privacy 02:00 – How Privacy-Preserving Voting Systems Work 04:55 – Hashing & Cryptographic Primitives 05:55 – Zero-Knowledge Proofs Simplified 07:00 – Advice for New Developers & Students 09:00 – Hackathon Strategy & Team Building 11:45 – Growing the Ecosystem: Collaboration & Networking 14:00 – Key Use Cases for ZK & Mixnets 15:55 – The Case for Anonymity & Privacy as Free Speech 17:50 – Post-Quantum Cryptography & the Urgency of Upgrades 19:15 – What Are Mixnets & Why They Matter This conversation is part of Privacy Academy Interviews (https://academy.web3privacy.info/) — a peer-to-peer knowledge project exploring Web3, privacy, and digital freedom. Filmed & edited: https://x.com/BabyBitProd Interviewer: https://x.com/0xfarbey Let privacy be with you!

Transcript

[Music] Uh my name is Richard Carbach. I am I've been in privacy since about 2005. And uh I got into it by uh I uh went to this talk by a guy named David Chum who happened to be a big name in cryptography. He invented uh digital cash. He invented blind signatures.

He did all these other wonderful things in privacy. And at the time he was working on a uh uh a voting system and that voting system had this property that you would be able to uh get a receipt for how you voted but the receipt would not show how you voted but it would allow you to prove that your vote was properly cast and counted in the election. And at the end of the talk he gives this very long talk. At the end of the talk he says I I haven't quite figured out how to build this and how to put it, you know, get regular people using it. And I was sitting through this talk and the whole time I'm thinking it's so obvious.

Let's just go do it. So I go up to him at the end and I said, I could totally build this. And sure enough, 6 months later, we had built it. We had tested it at the University of Ottawa and it worked pretty well. We had this uh very strange result where uh the way the system worked is you you had a um a letter next to each candidate and then you had to find the letter in a random ordering underneath and then uh uh mark it there and uh people hated that but they voted more accurately when you told them how to vote.

So, it's like a double-edged result. And what we realized was we need to figure out a way to make this system work and have all the privacy preserving features without the without the the without changing the experience at all. So, you're just marking next to the candidate as you're used to doing uh when you vote regularly. So, we have this this system. So, we modified the system to make it so that it did not change uh the experience of voting.

So, you just mark next to the candidate. And when you mark next to the candidate, you receive uh a confirmation number, and that confirmation number uh allows you to prove that your vote was counted, but not who you voted for. Uh you need a a little bit of technical knowledge. Let's let's start with the basics. Hopefully, everyone watching this video knows what a hash is.

But a if you don't a hash is is simply you you put a bunch of data into this function and it produces a fixed length output and from the fixed length output isn't the data that you put in is not recoverable. So if you knew it beforehand you can reproduce. Yes, but if you didn't know it beforehand and you can't guess it there's no way to reproduce it. So with that primitive in mind, we can use that to create a form of proof without zero knowledge, which is I think very interesting that you can do that. So zero knowledge is not necessarily the only way to do these uh very interesting proofs on the on on blockchains and more generally.

So with that with that knowledge, let's create a structure. And that structure is going to look a lot like the uh phone system from the 80s and 90s where you have uh uh numbers and you have wires going from somewhere into a central into a node that ends up in some sort of central node which ends up into another node and another node and then it goes to the destination of the person you were trying to call. But in the case of voting, these numbers are going to line up with candidates. uh half of the destinations will be to let's say apples. We'll try to keep this non-political and the other half of this situation will be to oranges, right?

So you have a bunch of numbers and you have a 50% chance if you pick one of these numbers at randomly you will find apples or oranges and you can always look at all of the links in that chain and you can know one for one that all the links are proper. Right? So all we have to do is for each of these links hash them and put them on the internet and sign them or put them on a blockchain so that they can't be changed after the fact and say this is what the the data structure will look like but we've hidden all of the links and where they go between each node. And because we've done that, we've created a digital audit trail. And the first thing we can do is did we do the digital audit trail correctly?

So, we'll just take half of all the numbers uh and we will audit the links to make sure they go to one candidate and one candidate only and they don't cross paths or collapse onto the same candidate or all the other things that you could imagine that you might potentially try to do if you're a bad guy. So, once you've done that, you then run the election. The users get their confirmation numbers. You can secretly decode the links and post the results. And the way that you audit those results is you commit to those uh those results and then you essentially reveal the hash of everything but one of the links in the chain.

And because you've hidden that one link, you've protected everyone's privacy. That's how the system works.

Let's talk about other easy to explain uh cryptographic primitives. And I'll I'll focus on

on sort of the logical explanation and not necessarily the technical. So, one of the the building blocks that hopefully you're learning uh as part of the web 3 privacy uh project here is uh about zero knowledge and zero knowledge is a very important tool. So, it allows you to prove a result or that knowledge of something without revealing any of the other information that went into proving that result and people have a lot of difficulty with how that works in practice and what that means. So uh the simple explanation that is generally I think the introduction that most people get is uh you want to you have the where's Wall-E or the where's Waldo book and the idea is to find Waldo. So what I will do instead is I will create a very big sheet.

I will cut a very small hole the size of Waldo and I'll hold the book up and show you that that's where Waldo is. And when you do that, uh, that is essentially a zero knowledge proof because you've not shown all the information that needed to be processed to find Waldo. You've only shown that you know who Waldo is. And that is exactly what is happening with zero knowledge. So whenever you're building a zero knowledge algorithm, you need to ask yourself the question of what is hidden and what are we revealing.

I think it's very important because sometimes you'll see these proposals where they say they use zero knowledge, they're not really doing something interesting. Uh another aspect that is very interesting with zero knowledge is uh you you go and you you uh because you're doing this proof the verification of the proof in some cases is faster than having to you know do the full verification of the entire thing. And when you when you hear people talk about ZK rollup that's what they're talking about. Most people who get into this want to build. And if you want to build, my recommendation to you is to find teams and come to conferences.

And uh I would say the number one thing you can do as a beginning student is go to a hackathon and join a team with someone who looks a little older like me because I go to these hackathons and I exclusively look out and seek out students to be on my team to essentially give them a good learning experience. So that is that is probably the number one piece of advice I would give you. Um the other thing is you need to learn how to read research papers and yes school can help you do that. I think school may accelerate that for some people and school is completely useless for others. This is an industry where your degree is not uh important.

It's how what you can do and how you can execute. And if you can do things and execute uh even if they are not necessarily cryptographically relevant, you can take the cryptographic primitives and do something useful with that. That is still a very useful thing that will get you into the industry that will get you exposed to cryptographers. And when you're exposed to these cryptographers, they will point you at the papers to read and things like that. Um, as another practical matter, if you are looking for things to read, go on GitHub and look up like ZK awesome list.

There's a lot of GitHub repositories of just centralized information on specific topics and you can find uh a wealth of knowledge there and you have something you have access to the best tool that I think humanity has ever created with the artificial intelligence. Uh, I would not use it to do all of your coding. uh you definitely want to be that human in the loop to make sure it's doing the right thing but as a learning tool it is the ultimate machine because you can essentially endlessly explore topics

and eventually you are going to need to go read the source material right but in terms of discovering what source material is out there what it actually proves who may be uh opposed to it the AI is excellent at helping you navigate that situation which I used I I just wish that I had that that resource So what's my advice for hackathons?

Uh number one, be prepared to lose. Don't go thinking you're going to win. You don't need into it's uh it's a very tactical experience. So even if you have the best project, sometimes you just don't you don't win. Um, in terms of winning the hackathon, you need to pay very careful attention to the presentations at the beginning, especially the ones by the sponsor because that will tell you what they're looking for in the hackathon.

And you need to make sure your project goals align and what your project is doing align with the things that they were excited about when they spoke.

In terms of actual execution, you need a team. uh you generally need one at least two people who are very technical who can deploy servers who can get the code compiling get that deployed and and do you need someone who can do a user interface it's generally very useful to have someone who's working on the slides at first and then jumps into testing the prototype and the proof of concept so that I tend to tell people you really want a team of about four or five and you need those roles well defined in that team one or two technical people one person who really works on the slides and the vision and the the the the discussion and then uh so and then that person will then work on the the actual prototype. So that's that's generally the advice. Uh in terms of finding hackathons you can you can go online you can look for a hackathon. Uh almost the the great thing about crypto is almost every crypto conference has a relatively good hackathon.

Um, you know, this conference here at East there's honestly the vibe here is amazing in terms of the the makers here working on their projects. Uh, you know, other examples include ETH Denver uh which is very similar ETH Dam uh out in the United States uh consensus every year has a hackathon. They have a consensus in Hong Kong every year. They have a consensus generally in America. I think it's in Toronto, Canada this year.

They're a very good option for you and they all offer if you look early enough free hacker passes and sometimes they offer scholarships and you can look for those things and then you're attending a conference for free. You're meeting all of these interesting people for free and you're making all these connections for free. When you go to these hackathons, it is important to have humility about what you're doing. I think a lot of people get very uh bravado. Uh uh they're the best.

I'm going to win. And you really want to go engage people, be interested in what they're doing, spend at least an hour or two talking to the other people in the room to learn about what they're doing. This is not for competitive reasons. This is to make connections that will help you in your career. Yeah.

How can we help this ecosystem to evolve in a more thoughtful and intentional way? I think that the number one thing that you can do is to not hoard opportunity. I think a lot of people they'll talk to someone, they'll find out that they're very interested in doing something else or they have some resource available and they don't go and and introduce people that could, you know, do that and they don't make that connection. And I think that's very harmful. And it's because it's it's very easy to say, well, that doesn't apply to me.

Uh hopefully they find someone, but I'm not going to do the work. And I think uh if you go to Silicon Valley or you go to a startup accelerator, one of the things you learn there is having these networks of founders is incredibly important and the founders always are looking out for each other. Uh I was at a conference recently and uh I was talking to a guy who has a team of about a hundred and he has big problems in um I I won't get into the technical details but I had two two different companies that solved two of his major problems. I don't I'm not invested in those companies. It's not going to I'm not going to get any benefit at all.

But I went out of my way and I made sure I made those connections. So when you find yourself in that position, don't be greedy. try to be and make that connection if you can. Uh the other thing that is particularly bad in in pro in the privacy space in the cryptography space is we tend to be very toxic with each other in terms of shooting each other down and not really thinking about and saying oh there is value to what this person is working on. It may not solve all the problems I care about but it does improve the situation.

And you know that is a a an issue that has been around since I first started it. I think it's probably never going to go away, but I would appreciate and I would encourage you all not to participate in that. I for one try not to say anything negative about any other project. I try to talk about how they are uh working together or how they could work together or I talk about sort of the benefits and the the disadvantages of both but I try to be very fair as fair as I possibly can be. you you can't avoid your own implicit biases.

So those are my two pieces of advice. What are those use cases where uh privacy preserving technology should really be brought into the spot spotlight for mixets and for uh ZK in particular? They're very similar but different technologies, right? So a zk uh allows you to perform an operation and provide privac privacy around that operation and the uh canonical examples are things like privacy coins. There's all kinds of things that you can do uh that are very good use cases for ZK.

Um zero knowledge shuffling would be a really interesting use case and you can use that for playing card games like poker. You can uh use that for uh fair selection algorithms. Uh you can use that for fair bidding processes. So these are the types of real world applications where privacy matters. Uh and it's not always obvious upfront why privacy matters in something like a bidding application.

But uh if you don't have that privacy, then someone is collecting the bids and then they can use their global access to that information to take advantage of the situation. So having private bids is actually very important and I think it's a critical piece that we just don't h we don't see in the world today. So these are things that don't exist now that could be built in the future. Um another very good use case is in the voting use case. Uh in particular you you want to have the voter role be public so that you can stop like a civil attack but you want to keep the votes themselves private.

I talked about that earlier in terms of how you can build that without without even zero knowledge just a form of a mixet that's uh static. Um, so there's all kinds of of interesting use cases there. And yeah, I think I'll stop there. I don't Yeah, those are the those are the top ones that come to mind right now.

I think is or what's the the justification for anonymity? And uh I'll throw that I'll throw a curveball into what is the justification for anonymity and uh I'll say you know what is the justification for uh owning your own money. So as an American uh we have a ruling that says that uh cash is speech right? So, I really associate privacy with free speech. And let's let's complete the analogy.

Uh, you know, who should have the right to use their money, right? Uh, should the truckers that were protesting the government in Canada not that long ago, should they have a right to their own money, right? Should a pedophile have the right to their own money? Right? So, it really matters where you draw that line.

And the government right now is defining that. And it depends on what government. And it you don't have to think very hard when you look at certain governments in the world that just say this entire class of people are terrorists or they are illegal immigrants or whatever and uh those people deserve to you know be able to spend their own money. They don't deserve this uh you know what what kind of world would we live in if you didn't have physical cash where you could you could do those types of things. So you should be able to do those types of things on the internet.

And when you are talking about your your speech and what you're trying to do on the internet, it's very very critical that you have that same type of protection. And a lot of people will say, well, if you have nothing to hide, you have nothing to fear. And uh I tell those people, okay, give me your phone because I'm going to go look and see what you sent to your wife recently. So, and most people object to that. And the reason they object to that is because they do have things that they want to hide and they're not necessarily illegal things.

They're just everyone has this right inherent right to privacy. I think it's very important that we need to protect that. Let's talk a little about the reason why postquantum cryptography uh this is a dated thing. So if you had talked to me six months ago in like August of 2024, I would have told you, oh that's a problem you need to worry about 20 years from now. And what has happened recently is the the amount of progress and the significance of that progress has really started seeing an exponential pattern in the last year or so.

And in November, I mapped out all the recent progress and I put that into a u a mathematical model and did an exponential fit on that mathematical model. And then I figured out how many logical cubits you would need to break cryptography like all of modern cryptography uh that we rely on for these crypto cryptocurrencies. It turns out the number that popped out was March 2028. That's much closer than I had anticipated. I expected 10 years or 15 years, not three.

And because of the urgency of that problem, I'm now looking at well, how can we have a safe upgrade path into uh cryptocurrency? And if anybody wants to check my math, they can go to quantumdclock.com which has the mathematical model and the data and you can you can play with it. Um so that is that is kind of the the impetus for postquantum cryptography right now. Uh and uh I think it's it's going to be more important than ever to incorporate that into uh privacy preserving systems.

Let's talk about what a mixet is and then sort of what the what the current state of the the world is right now. And uh a mixnet is a a system where you send data into it and then the sender information is removed and then it goes through the system and then it's sent to someone randomly and you on the on the receiving end. And the purpose of that is to break the link that people have between the senders and the receivers. Uh about 10 years ago uh you had the um Michael Hayden at the NSA who said we kill people with metadata. So obviously a mixnet is very important protective tool against that type of behavior and you know I guess I probably don't have to justify it more than that but I will say there are different types of mixn nets.

There are the mixet that you see with loopix uh and the big example of that is nim where they add random delay into as they as it travels through the the mixet and then there's the the the we call them mix cascade networks where it's a a subset of nodes are are randomly selected to choose the block and the two differences between those and that's what you see at xx network and the two differences between those are the uh you know the client controls the path versus the network controlling the path. And when you have the network controlling the path, you can do things like delivery guarantees still with good privacy properties. And if you wanted and ideal world, I would say you'd want to use something like Lubix in conjunction with a uh uh a cascading mix as well. I think they they're very complimentary in terms of what they protect and how. [Music]

Automatic transcript — names and jargon may be misspelled.