Discord On-Chain | Dominic Letz (March 2024)
Berlin Ethereum Meetup·Mon, Oct 7, 2024, 12:00 AM
Managing Group Memberships, Moderation, Linked Devices and Privacy with the EVM --- Join us on Meetup to keep track of our events in Berlin: https://www.meetup.com/berlin-ethereum-meetup/ See you at the next one! --- Apply to speak at our future meetups: https://forms.gle/5y9Y5ywZC7pSEqpV9 --- Twitter: @BerlinMeetup
Transcript
and going to start with that Discord on chain uh just real quick about me uh this is if you see me on GitHub this is what we going to see um I I have all these titles CTO co-founder software engineer just means like I'm doing everything all day long like other people say like fullstack engineer so I'm just fixing everything the front end and the back end working on the thing called diode um I don't want to shill it too much but it's actually also why I'm in this uh in this topic and we do do build like a Discord on chain so we're going to see a couple of the smart contract that and the ideas and problems we have based on that and I'm also an Alexia Fanboy so there is like this Alexia is a niche functional language I'm running also the meet up there so it's completely unrelated to blockchain but it's amazing um just in case you want to check out so what we wanted to talk about is the introduction the motivation a bit and um the social graphs on chain like how do we how can we store them then how do we uh Define groups and roles uh and then we're going to talk a bit about recovery like what does it actually mean what are the problems uh multi-devices and also privacy and that's basically where I want again end up and talk about that a bit and I'm really curious at connecting with you people especially if you work in some of these areas or are researching in these areas um because it's there's a ton of open problems here so um with that said actually this talk has been triggered by isanda over there who presented in January uh this Anon Club where he presented like this kind of different um membership systems that we have whether it's an airdrop or a chat group so that's here we are today or voting or mixes all of these have the problem of anonymity or like privacy and he presented like one solution that they're working on with ZK snarks and so proof of membership and on chat groups that was like oh that's that's me like that's like we want to talk about so first thing is members this might be if this is way too small for you guys on the back um we can try to make it a little bit bigger maybe but um I think so we want to we want to talk about um members so you know this you log into Discord you see the member list and you see the names so how do we do that in a smart contract uh this is going to be pretty technical so I just want to go through some smart contract uh details I'm now zooming in on the slide so you guys can see there back there um this is like the simple thing in in a solidity contract we have a simple group we have a set this is already where like in solidity unfortunately there's no native set so an open zoline contract there's an inumerable Set uh there's different set implementations you could also just use a hash alone but the problem is if you use just use a hash to know if somebody's member or not you cannot iterate it right and so back to the screen it's actually really nice to be able to iterate it in app to say like oh there's six members and we can show all of them not not only check is he member or not but actually go over them so but this is not enough because so far we just have a group but we can actually not change any permissions so we want to add and remove more friends to our group right so we need a couple of more functions on this so first thing is we need some roles in Discord we see them actually highlighted in different colors so we can have somebody who's an owner an admin he can add and remove people but probably not the one who created my my chat and then we have normal members maybe we have Bots who do things in our group that have even lower permissions and we have like the the zero permission here really simple samples so this is all sample code um that I that I created here and uh basically took our contracts cleaned them up for presentation removed everything that is like the nitty-gritty details of our specific implementation so it's a bit easier to understand so what we're getting in addition um are roles so we have the members but now we're adding roles and on top of these roles we Define some actions that they can do again I think this is still too small in the back there but basically we have ADD member so if you're um an admin so that's like like if you're an admin you can add a normal member right this is kind of the permission system that we that we want to have we also have like um remove self that's very very common in most of these group systems so uh only admins can usually add or remove somebody but everyone can remove themsel like you always have the ability to leave um a group right so there's like that's smart contract function and the owner he can also elect admins he can uh promote admins he can uh demote them back to normal members and do change all of that um one of the challenges when doing with this is that there's unfortunately very few eips or erc's uh that standardize these things so open Zeppelin for example again they have uh this role based access but there is no EIP on that so it's not it's not a standard that everyone implements so everyone is kind of driving their own implementation of like how do we manage roles how do we manage role membership and group membership I want to going to to like the uh the challenges B so next next problem is I'm going to zoom out here real quick so just we so we can see the whole slide um multiple devices so actually what happens here is that most people actually have not only a single device that they work on but they have a phone and a computer at least two and they want to be able to join Discord from both of these devices and so there's like the bad idea number one is we just take the same private key they have on this device and we copy it over to that device right and it's like that's the easiest then it's the same identity uh and they we know like it's the same person the problem with that kind of first bad idea is when you lose any of these devices that single key that you have is gone right it's now out in the wild and there's no way to recover or to delist that device as being lost or do anything like that it's like game over so a little bit better idea is we do one key per device so actually when you do uh endtoend encrypted applications like a signal you will see that as well or Whatsapp doing it as well every device you have has its own identity has its own key that it's using so we have one key per device but we have like a contract in the system that is used by all of them together to represent the identity of that user um I've put like a eoa some term that you often see in like ethereum speak I don't know how many are aware of that like I always have to look it up but it's externally owned account so that's a real wallet compared to like a smart contract like a um in this case is a multi contract so this is the idea again like the bad idea one is we just copy the same key like the same private key to two devices and uh let's say we are Anna in in our group that was like the first in the in the initial picture that we had then both devices are the same person the better idea here is like with a with an abstraction step in between so we have like a a multis contract uh we call it here the identity both of these devices are listed in that identity and then that identity is part of our group so that's part of like the our Discord group for example and we're jumping here to code so it's not really a multi sick because it's more like a one of many so it's it's kind of the opposite of multi you have five devices any of the five devices can do whatever is needed in the identity and what is needed in the identity um so we add like a identity contract here it needs to have an initial uh device an in initial device owner that's the starting device and that device has the ability to add other devices so again you know this probably from from WhatsApp you link your first device with a second device you link them together which means like the first device kind of authenticates the second device as this device can also uh impersonate me I can I'm also using that and so this way we're doing it on a smart contract so this ad device can only be called by another device so one device has the ability to add more and more devices and most importantly we want to let's say we are an admin of this group and so one of the functions we want to call is like add and remove people inside that Discord group or turn a moderator into an admin or an admin back to a normal member remember these kind of operations which are transactions so this has like a multis that you see in gnosis like this submit transaction that is then an external call under this identity and then allows you to um to impersonate really that identity now this this works pretty nice but it creates one another problem here um let me see whether I can go back um so we solved that the the the linking let me check whether we talked about everything every device can submit we don't have this master key and the multis we talked about that um so what happens when you lose your phone right so if you lose your phone we wanted to talk about that there's this problem right now that with this device that you lost it can still add new devices to your identity right so in theory if an attacker gets hold of your device and unlucky enough he's able to unlock it um you could be trying on to remove link devices and he could at the same time in the same speed try to add devices right and then you have like this raise where the question is who's going to be faster you or him and in the worst case he's removing all of your devices and then he locked you out so we thought of something like how can we recover from that we need something like a protector roll like something that is maybe a hardware wallet like a ledger or like a piece of paper that you have printed out that you can use to recover from here I'm going to I'm going to zoom in um this like this typical piece of paper with like the the backup words found this on the internet I don't think it's a real account so it's like um the this is a very similar to the previous contract we just have added like a protector and so that's now the initial the initial member is a protector and the protector has one feature he can turn the identity into protected modde which means only he can make changes right so the idea is your phone gets gets lost or gets stolen maybe if you're on a crypto event um and then you can enable protection on this identity with your backup with your Hardware wallet so so that nobody else can add more identities so we stop this race from happening and then you can clean up you remove the phone you remove any other suspicious link devices that you actually didn't add and then you can go back to like the original state you disable protection he can start using it normal again so kind of going through real world problems um that that we had to deal with and our customers had was were asking us I'm trying to be quick with this so social graph that's like the thing we wanted to talk about so the so whom is who doesn't know what the social graph is anyone like it seems I I think it's pretty well known but just to go through this picture real quick so you might be member of three Discord communities and now because everything is on chain somebody scanning the chain can actually see well there's all of these members but actually F stre members are also part of this community and now I can get a pretty good picture of like what are your interests probably what who are your friends probably and start doing really nasty stuff it can be as simple as these nasty telegram Bots that sometimes you see they join all the same groups you're part of and you wonder like how do they do that like why do you see plopping up all this this name in like five different groups that you're member of so they can start following you or they can start like social engineering against you right so you're like oh there's a you have a friend maybe we cannot attack you directly but maybe we can get into your friend first and then impersonate your friend and then do stuff like that right so there's a lot of bad things you can do once you get into the social graph so generally we want to protect the social graph protect against those people scanning it so there's like three ways I have identified so far and that we are doing right now the first one because it's the dumbest and like the way you can actually we tell our customers for whom it's really important you create multiple profiles you actually like you don't join like with the same profile 15 Discord Discord groups you create different uh profiles on chain and you keep them separated this way so you have completely independent wallets you have completely independent identity contracts on chain and you do it this way um there's there's a problem with like um how do you manage then recovery because it can't be the same address everywhere and also what about time correlation so imagine you have an identity it has like four devices maybe an iPad and a computer and a phone and so on and now you add one more device right and but now there's one more device that you link to your Fleet of devices it's going to be added to all these copy identities like your multiple profiles that you have because of course you want you want on this new device access to all your groups and so that means it's not transactions going to the same addresses but they're happening at the same time now this happening two or three or four times might can be enough for an attacker to deduct oh this is actually the same person so time and tornado cach for example has a very similar problem like if you torado cash is like totally Anonymous but if you uh send Ed uh100 million us and then basically you deduct immediately 100 million even though the addresses are random everyone looking at it is nose like oh yeah this is the same guy you know like this is how they found that North Korea is deducting through uh tal cash because they didn't do it very smart um so snarks again I talked about that there some really I just want to put that out here there's like this noral language I don't know if you ever implemented snarks like tornado cache like that's really nice and makes it it's super easy so I can I'm just putting the link here um and there's some of that um uh these enablers already in ethereum right so there's like some of this is super small you cannot read this uh even if I zoom in I think you you still cannot read this but some of the enablers are there as pre-compiled and so you can do certain ZK snarks today there all these old BN 100 128 so there's bit of tooling around that and doing basically zero zero knowledge proofs like membership proofs for example you can do with that but the problem is like some of the things we just talked about like we want to have multiple devices we want it to be enumerated It all becomes a very very gas expensive to like the um to the degree of nonfeasible like with torado cash it's fine if you transfer like a 100 10K Us doll it's fine if you pay 50 bucks in in transaction cost if you add a member to your Discord group it's it's not fine to pay 50 bucks you know like there's um we have to be very gas efficient the other thing it makes it very complicated just from the amount of engineering you need to do uh in the solidity contracts to do it so and that means it's you can have errors easier there's way more code you have to write and it's much harder to understand what's what's happening actually so this is this is a pretty big problem with with stars uh so far far and then there's like the I don't know another another cheap out I don't know who was on East Denver but there's quite a couple of these evm engines now out there that say they're privacy EVMS so they actually proect the evm state so Oasis is one uh Phoenix is one I think secret protocol somehow they're the same as Phoenix I'm not quite sure on their separation um so have these EVMS that keep State private there's still the problem with like the sender and um the receiver so you if you if you don't uh encrypt that then still people can see on chain what's happening there how am I doing in time here um still have minutes that's that's great and with that actually I'm I'm coming to the end here so really we talked about these challenges um a really big one is that there's not enough erc's in EIP so again like even though we built this there's not a lot of building on top of each other which is really really sad I I would uh hope maybe if you guys are curious I I would really hope to uh also uh I would love to work with somebody together on standards if there's somebody doing similar projects right then I think it's much more likely to be successful the only one like even though it's so fundamental I feel like memberships and groups and permissions there's very little ercs around that and eips um social graph privacy I think is an unsolved problem like everyone talks about it but there's not like the Silver Bullet yet um if you know something please let me know again um and the paying for transactions is a bit of pain but I think there are some solutions now we use some some solutions um so at least that is good it also has a like there's an anonymity aspect to it right if you don't if you want to hide the sender address you have to have somebody else who's paying the gas fees for you um but it seems to more be more or less solved and then recovery methods um I presented what we do but there's a lot around like social recovery um like that whole topic is also not very well covered if at all by earc ORS there's no no golden formula out there so again if you have if you if you're connected to like the project that has totally solved this or that like I'm I'm really happy uh to talk with you guys and um this is really what we have done so far and how we have approached it yeah yeah I'm curious like the beginning are you building onum like on M uh um we started out on like our own application chain that was evm compatible because we had this we didn't solve the gas problem initially like who's paying for it so we did like what everyone did like four years ago we started on an application chain that is basically gas free um and we changed that and going to other evm compatible chains and we want to get rid of our L1 because it's just like a maintenance hell um and we're going to to like a moon beam right now and then afterwards we going to Aon more yeah yeah I'm asking because uh like as a solution to this privacy issue that the blockchain might be indexed you mentioned that you like create multiple identities on chain and it's like gas consuming operations the gas consumer so I was curious how do you solve it from a user perspective I yeah like running on ethereum mainnet is not is not cost efficient right so so it must be an L2 right now no no I'm also saying that if you're trying to create multiple identities you still try to create multiple identities from different bullets so you first have to top off wallets with some amount of in order to exactly yeah so like some kind of pay Master B yeah yeah so that's what I'm saying like this this is actually like you have the pay master um the different El like many of like the alternative chains have their own solutions to that uh in moon beam for example they have construct called a call permit but it does effectively the same you let somebody else pay which solves like you need some construct whether it's 4 337 or different but you always need that not only um not only for the single account multi account account problem but just to have like a smooth experience uh on like a like like you like a normal Discord user would expect from Discord you want to add a member and you don't want like a popup with a signature and you don't know what's like that this kind of experience doesn't doesn't work too well if that makes sense yeah yeah I just wanted to mention if you're like relying on some moon like features it's not that transferable to other chains like easily so like some features like moon be might not be supported by other yeah it doesn't affect it doesn't affect the smart contracts too much I mean in the in the s in the sample smart contracts I these are just sample smart contracts and I made it really simple I just used message sender right if you use uh Force Through Series 7 you don't do that you use like the underscore message sender because that's actually overridable um but but this is just sample Contra uh con uh contracts I wanted to make here to make sure actually the difference um to support moon beam or one of the other Alternatives or for 337 is not big actually the impact on the smart contract is really small actually with there is no need to use underscore mtion with like so like the Hand by the soort without to the smart let's let's talk about that because then maybe you understand saying is different than mine but let's talk about it have you have you worked with that yeah let's talk about this then I like it any more questions on this anyone working on anything with groups or memberships I see one I mean I haven't saw the a regarding the memberships but there is definitely a draft here regarded the dos and it might be applicable to the case of the groups so so there is also members yeah yeah yeah there's some on the Dows but even on the Dows I'm really sad like you would think that Dow being such a common concept that there would be more consolidation already but there's there's not yeah that's why it's a DFT yeah exactly it's a draft and there's so many Dows out there but like not not many follow any any standards and also like Dows have a different kind of different prompt set often like en being able to enumerate all members is not necessar needed in a DA and also Dows often want the opposite in terms of privacy like they actually want to say like we have these pop like famous members and you can look them up by their ens names right and this is truly this guy which is really opposite from like you have these 15 chat groups and you don't want to tell the world what are you a member of but yeah I I would hope there's more standardization thank you so much there's no further questions then
Automatic transcript — names and jargon may be misspelled.