# Sismo Workshop | Leo Sayous | Deploying a Sybil Resistant ERC721 Airdrop | ETHDam 2023

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2023-10-07
- Duration: 31:08
- Watch: https://streameth.org/watch/yt-5AiQeE9QXIA
- YouTube: https://www.youtube.com/watch?v=5AiQeE9QXIA

## Description

More about SISMO 
https://www.sismo.io/

Follow Leo Sayous the CTO of Sismo
https://twitter.com/leo21_eth

Presentation slides: 
https://docs.google.com/presentation/d/19YxSch3Zl_4856vsNdXg4atLhMQnIZZUr6VwIKyK_pA/edit?usp=sharing

ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. 

Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants.

ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: 

CryptoCanal https://www.cryptocanal.org/
CryptoCanal Twitter https://twitter.com/CryptoCanal
Join CryptoCanal Community https://t.me/CryptoCanalCommunity 

We would like to thank our partners and sponsors that made this event possible. 🌷
Our BFF 1inch https://1inch.io/

Our Frens: 
Sismo https://www.sismo.io/
Aleph Zero https://alephzero.org/
Scroll https://scroll.io/
RAILGUN https://railgun.org/#/

And our Sisters:
oasis.app https://oasis.app/#earn
Maven11 https://www.maven11.com/
bitvavo https://bitvavo.com/en
Lido https://lido.fi/
Spankchain https://spankchain.com/
API3 https://api3.org/
Gelato https://www.gelato.network/
VanEck https://www.vaneck.com/nl/en/crypto-etn
Marlin Protocol https://www.marlin.org/
Silent Protocol https://www.silentprotocol.org/
Cyber Capital https://cyber.capital/
… and Proto https://twitter.com/protolambda 🍍

## Transcript

foreign [Music] and today I'm quite excited because I'm going to deploy a simple resistance with a adorable contract with you only Photon Advocate users so it's something that is not really like intuitive because like Donald Lucas users it's highly not to be resistant because you can have deposit a lot of time on the tornado cash pool and you can have withdraw a lot of time also in this tornado cache pool um and your git coin passports usually is more on your public DNS and you don't want to link data between this git coin passport which is like on your very public identity with your internal cash address that you used which is your on your very private wallets so we are going to do this using sismo and in particular sismo connect uh and and yeah and the hopefully it will work and it will be cool uh so just a world about personal data so for instance me I am a leo21.is I have an ens name I have a proof of humanity a Bitcoin passport on this address and I have also a lot of different addresses very private wallets for instance I have one why I'm Donald cash user so I I deposited I withdraw a lot of time in it I also have a lot of transaction on this uh different wallets I have also some web 2 accounts identity like a Twitter account with followers GitHub account with commits so this is identity are more public they are linked a bit with my Leo 21. and uh what so so it's currently you can't really leverage all of this data it's a bit like see lot because we don't want to make links between these different accounts so what is is more it's a communication protocol between users personal data and applications so you can select just one data that you own and bring it to the application and the application will know only this information you you will be able to aggregate personal data privately from different accounts and selectively disclose only what you want to these apps and this is thanks to zero knowledge proof that we are using on in its core um so in sismo we have what we call the sismo Data Vault so I will we will do a demo and uh so you will see exactly how it works the product uh basically you import all of your different icons so all happen in the browser directly so local it's like a platform manager where you you can import your web to accounts so for now we have GitHub and Twitter we are going to add others but you can also import your public key account and your very private wallets like the one with Donald duckash you import all of this and uh you are able to bring this data to application using sismo connect uh so for us sismo connects it's what we call the crypto native single sign-on uh why because it allows to bring like if we use currently in single sign-on we have for example connect with Google but connect with Google you can only bring the data you have on Google to an application with sismo as its self Sovereign because you are the only one to own this S Mode data world because all happen in the browser in the front end all is encrypted you can import a lot of different icons and then share them to the application as you want and it's you that decide uh here for example you have a what is exactly the the system that Awards using system connect so you sign in with this more on an application on the front end it's like it's a button you are redirected to your system data Works where you can see okay uh and this is what we are going to do is done Workshop okay I want to share that you have a git coin passport with a score more than 15 so you are basically a civil resistant human and you have deposit into another cash result but we don't know which accounts you use for that we just know this information and then you came back with the CK proof to the application and the application can verify it on chain or off chain so here the Unchained flow you have your app your button you do your system connect request you are redirected to your your user system data world you generate the proof you send back this proof to the application that can send it with a transaction to a Smart contract and we verify if this proof is valid or not and you can do actions and gate your function with it it works also with a off-chain flow basically this proof verification can be done Unchained or off chain with a typescript package because it's just very famous proof so yeah now time for the for a demo okay so a bit of context for this demo um so when there was a tornado cache event last year we have printed um this is the code of tornado cache and we have we have put it into our uh wall uh and so we did this for fun and two two weeks ago Emiliano come to our office he discovered this he sent it to Twitter and there was a like a huge uh like of this type of of Art and so we we decided to so to show you a bit how it looks it's like that so it's a huge one um a lot of people asked to have it uh so we decided to do a lot three to win 10 of this piece of art and uh in order to do to do this Lottery um we we wanted to be severe resistant otherwise the lottery will be like it won't be functional and we want it to be only for tornado cache users so the one that choose effectively to another location so here you you can go to see a bit we have the our demo spaces.sismo.io so it's a new thing we have just released which which allowed to use this more connect with different use case um so for instance the lottery here so that is a participate in the printlow 3 and register to have a chance to be among the tenular key winners to get a privacy's normal print so we can see here that we need to be eligible we need to have like turnado cache at depositors and to be to own a git coin passport holders of at least 15. so we do sign in with sismo here we are in a demo environment so we can see the the fake Demo World all happening in the browser like you can see here it's vitalik safe you can navigate between your accounts import new accounts so we won't do this now but um and you can generate your ZK proof of being part of of having this information you already directed back to the application and here it's enough chain application because we uh to be part of this Lottery we just uh storing this in the database so I can add I don't know my my Twitter to be contacted again after to win the the if I win the the the the print system yeah I I didn't understand the question yeah yeah yeah we talked to this after like in this case it was more for the demo because as it's a demo people in the other system of that level they don't have the Twitter accounts it's just said to they can play with it but uh okay so what we are going to do during the workshop uh is to do exactly this but Unchained with a smart construct and instead of being added in a in a in a database we we will be just able to to meet the nft so it's pretty cool uh yes so just let's go again for for some from Theory a bit before we can lifeguard um so we have seen the flow here we have our our app we do the requests to the user data table we generate the proof we come back with the response and we verify it in the smart contract so the question is what can be requested from A system that level to what type of request we can do we haven't first authentication so in authentication we can regress okay I want to know give me an evm address so basically it's like doing sign in with ethereum but inside system connect you can ask for the Twitter so that was exactly your question and you can ask for a voltage so what is the Vault ID exactly it's a way to connect to an application only with your Vault it's like an anonymous authentication and how it works is that inside your sysmode Data Vault you have a secret proof we can hash this secret with an app ID which is a unique identifier from the app we are going to to send this ZK proof and you will have a unique volt ID and each time you go to the app and you use a system connect and with authentication of type volts you can bring this voltages like your user ID you will have inside the application so as for our for the workshop we will use this word ID as a token ID for our drop so another another thing you can request is what we call data claims um data claims will be for example for example being a tornado cash user or having a Bitcoin passport how does it works it works by using data groups membership claims you are basically downloading in your browser the world set of all the the group that have the same character heuristics so for example the the group of all users that interacted with tonado cache and all users that have a Bitcoin password you download all of this in your browser you there is my culture and stuff like that and you prove that you are part of these groups without revealing which account isn't is effectively you effectively earn inside this group and this will be what is used as a ZK proof then inside sismo connect to be able to use uh this so I will show you after we have a UI which is called the factory which helps to generate groups to uh the groups can be refreshed so you can choose at which frequency you want to have new groups and you need when you do your request to identify this group with what we call a group ID so you have a group ID for the cache users you have a group ID for the Bitcoin passports and you can retrieve all of this inside our Factory or the sysmob which is a the back end of the factory it's a open source repository so all what we are doing is basically open source except the front end of the system that evolved for now um okay another thing which is interesting here is that these groups are made of a count identifier and a value so you can then prove that you have a value that is which is lower equal or greater than uh the value that that is inside the group for instance here so internal education we have different type of pool the the pool of Vanessa 10 meters 100 liters and we see here in which pool the users deposited or deposited in the git and passport one we have directly the value of the score so all of these groups are main things to uh publicly available data and it's just indexing this data and put it in the form where we can do this proof with it finally the last one is what we call a message signature it's basically signaling an information to the app uh for instance it can be okay I wrote yes or I vote no I disagree and here for the workshop we will use I want to Mint on this address why because uh this data will be embedded inside the zero net proof and it will be a protection again against front running otherwise this proof could be front-end and attacked by Mev and stuff like that so okay so if we if we see a bit what we are going to do we want to do an airdrop where we use a vault ID as a token ID we want so it will be here the fact that we share the Vault ID then we want to share that we have a git coin passport with a score more than 15. that we are part of the group of little cache users and a signature requests were for example here you can see this is my address here where I'm going to Mint the the drop we are going to do okay so for for solar let's I think we have still some time so let's start um to to do this uh this Adobe we are going to start from the this tutorial we have on our dock show you so in our dock you can go to tutorials and change tutorials and build a civil resistant gated a lot so uh inside we um we propose a template where we have already imported some of the standards like it's a template of thoughts we are using Foundry we have like a front end also which is installed with uh with an xgs so it's much more easier to do than the the tutorial and okay so we are going to to start from that and sorry I will run it so I already started the Jana style so we don't have to do it now and we can go to the lunch tutorial okay I am already connected sorry okay so when new starts uh we we allow you to to play a bit like inside the tutorial so early is already connected it's easier and uh we are we are going to do it all happen in local uh you have a local Fork of Mumbai that is launched using Anvil which is a tool of a fortune Foundry so I'm going to claim with sismo I'll arrive on this uh on on my Dev sys mode at awards and here um so you know you can see that the default application we have put for this tutorial is this sample system Connect app we are going to share only our vault ID entity proof I came back to the application and I can claim my nft so here you can see the the local Fork which is used and it works so now we are going to modify this system connect button to do the real one we want to do so to add the gigant password to add the turnado cache users and to use our app so basically in this first step we are just modifying the sign in with this mode to have a good request so at the end we have this interface in the system database okay let's start again so we go to the front-end page claimer drop and we have the system connect button here so we can see that we have the configures for the system connect button authentication so we are going to authenticate using the words we have the signature and here we don't have the claim for now so we are going to add the claim we also need to change in the config the app ID we are using so we are going to go to the system Factory .sismo.io where you can create a new application so when you create an application you you enter the name description the authorized domains that will be able to generate so to ask data from the users for this application and upload the logo so I have already did it here so you can see and with this logo so I'm just going to take the app ID here put it here instead save normally there is a auto reload let's refresh the Fontan and try to claim again okay so now we have changed here the Vault ID will be different will be depending on this app we have our logo we authorize we have the the name of the application so this is pretty cool and we want to add the claims so for the claims we go back to the button and we want we need to find the group ID of our claims so the first one is Donald Lucas user so let's go again to the factory so the groups already exist I will show you in the factory but uh you can go to seismo data groups here and to look up for a lot of different groups we have so it was created mainly by the community um if I'm looking for tornado cache cache users I can see there is different groups so in this here it's interesting to see a bit so you can go to the group generators which is uh which is the code that is run at some frequency to generate these groups so here for instance it's a tornado cache with Rover ethical minutes we can see that we are we are we we listen to the we call an indexer to have the all the address that interacted with the different pools and generates the group so all these open source and you can see how it was made you see when was the last generation when will be the next generation and you can take a look at the at the group so it's basically you can see here the icons identifiers the evm address and here's the value for instance it's the deposit tool in in a way okay so we want the tornado cache users which is this one if I go again on the code I see that it's a union between the uh I know it's not this one it's the main net I want yeah it's this one minute it's a union between the depositors and the withdrawals okay so I take the group ID here I bring it to to here and here we go uh I also want the Bitcoin passport one so Bitcoin passport holders it's here okay let's go again to the front end here we go it's not what I wanted to do yes cool so now we have uh we have the fact that uh I have my Vault ID I have my gigant passwords here I don't have the the value 15 so now I'm not CB resistant at all we will change this and I have the fact that I am a Donald cache ATM user this one is not validated because in fact here we are in Dev mode which is used for test Nets and for local environments so we have devmod enabled too in this Dev mode uh in it's a different systems I I don't have imported my toneado cache ECM address I don't want to docs myself in front of you so uh I won't be able to to pass it okay so first let's let's add the value 15. so we just need to put okay I want value 15. as a request and I I'm doing a claim type of great thousand or equal that means that I want the user have more than 15 in its value and and that's all so let's do it again claim with sismo just looking the timing okay and now I have well the uh the data I want so I I'm just I will just show you for the because it's important for the hackathon if you don't if you are not eligible at all because you don't have a dress you can in local environment fake the data groups so it's called Dev groups here and you can uh I think I have already put it here so it's easier to gain some time yes here you can fake the data inside the groups in local environments so you can try the world stuff and it it will it will work directly it can't work once deployed on Mumbai and I'm not in prod at all so uh we need to remove it when we will deploy okay I'm just verifying its group the good group here so yes we have B3 and okay perfect let's try again so I go back to the application I redo my requests and I'm I'm eligible for all uh okay so now um let's do the other part the smart construct part so we did the request and how to do this request and now we are going to to do how we can verify this response so basically we are going to to create a claim we see smooth function inside our contract and verify this response I have a 25 yeah okay okay so let's remove these parts I no longer want to be on devmod because I'm going to deploy on polygon directly and let's go to the airdrop contracts so here I need to declare my app ID so it need to be exactly the same as info in the front end so let's take again this app ID so the error contract is here in the SRC folder and we need to declare our group ID again so same and normally I have saved them here to gain some time and we need to verify that this response is valid regarding the request we have made so here we need to have the claims which is our claim request so we are going to declare our claim requests we want to claim 0 to be turnado gas user so compilot is doing it for me it's cool claim one Bitcoin passport with a value of 15 and with a claim type being it's bad greater than or equal okay so let's add the claims here so all of this example you can find it in the tutorial after if you want so now we have changed the app ID we have put our tornado cache I'm just verifying it's working well we have the I'm just running okay I'm three minutes left right uh to another question password I'm more than 15 and greater than or equal I am also verifying just last time I have well the group IDs that are defined you know in the button because if it meets match it will it will fail so we have the 0xb 3 and 0x1 okay seems good okay let's deploy so I have a an environment with uh like mnemonic and stuff like that and we can deploy it's using Foundry so you just do third script deploy uh and uh and the dash dash verify and the deploy and verify for you it's it's quite easy thank you so once you zip let's let's put it deploying we need to change our page to have to use the chain polygon here and to say to user ABI uh one three seven and here we go so now it's verifying let's go again here and polygon scan let's find our contracts so we have well deployed our contracts we can find our app ID here Donald Lucas users and Gigan passport group ID okay let's try to Mint it I need to go here and let's go claim with system so now I am in the prod one we see the world better here I have 22 accounts inside it I won't show you it to you I am eligible because I have one of my accounts inside and I'm doing this generate DK proof that's right yeah switch the chain yeah seems to work and yes seems to have been claimed let's go to our address go to openc my account is here let's refresh and yes I have it here 24 five seconds ago okay and I'm running out of time so thank you and have you enjoy your hack and we are hiring also maybe you have some some question maybe we can have one questions oh can we have a one or two question or it's uh it's done okay thank you if you have one question maybe or yes foreign like if you arrive to create this group we could do it but you need to have a group where you have this information because when you use sismo and sismo connect you each time need to prove that you are part of a group so you will need to have the group of all git gun passports who have made for instance with Twitter stamps and it's possible because all is a publicly available with guitar and passport so we could do it okay thank you foreign
