New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

From Packets to Privacy: Understanding and Evolving Network Security | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

This talk will provide a comprehensive journey through the fundamentals of network communication, explore the workings and risks of Virtual Private Networks (VPNs), and dive into the world of Mixnets. We’ll discuss how decentralized Mixnets can offer privacy by default, potentially eliminating the need for traditional VPNs. Speaker(s): Max Hampshire, Med Amor Skill level: Beginner Track: Cypherpunk & Privacy Keywords: Privacy, Anonymity, Censorship Resistance, vpn Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] is Max Hamshire and M Mo it's just me today so yeah packets to privacy um I am Senior devel at Nim we are a company that builds mix nuts and and a decentralized vpm product at the moment I'm going to give you a bit of a tour of uh qu have a bit of a flash drive through how packets move through networks just so we're all on the same page how inherently insecure they are and how we can try and protect it so initially how packets move through a network so we're on all on the same page for the rest of this conversation data is sent between two network devices in packets packets are just chunks of data right so you don't have a stream to whatever server whatever rpcm Point you're actually trying to connect to you send all the data in chunks just so these things can multitask and talk to multiple things at once right packets themselves broadly speaking contain a header which has a bunch of information about the protocol the type of content that's in this packet the origin IP address and where and the IP address that it's going to right which corresponds to physical space as well uh then you have the payload which is your actual data sometimes you have tailor as well which have more information I'm not going to go through this whole list you can take a picture or come and talk to me afterwards but this is the metadata the data about the data that is exposed by sending packets unprotected uh through a network between two devices so where it's coming from where it's going going the location when the type of packets higher order patterns like the signature what it kind of looks like um repeat Communications maybe also like device IDs accounts email addresses cookies fingerprints all of this kind of fun stuff and this is ultimately because when the internet was made it wasn't made with network privacy kind of in mind and the situation at the moment is that Network traffic is captured and analyzed both by governments and corporations kind of on mass they just blanket capture everything thing and what they essentially try and do is using machine learning try and find patterns in this data who's talking to who and when where you're located what kind of traffic is being sent and then relationships are inferred from that why are you only talking to you after midnight what's the nature of your relationship all of these kinds of things right so which can be used to De anonymize you there's a lot of different approaches that people take so if we look at this diagram right at the bottom we have your kind of centralized VPN should we say all you're doing is you're kicking the trust down the road you're sending all of your packets to a vpm provider their server then forwards it on to wherever you want to go right you're not able to defend against anyone who can uh see the size and the timing of your packets and be able to infer what you're doing maybe you're downloading a video maybe you're kind of getting your emails or something and that is a centralized point of trust that you're trusting that that vpm provider will not sell your data and or when they are subpoenaed give your information away to does a bit better um it doesn't have a single point of failure in that regard but against someone who can watch uh watch kind of the whole internet which is kind of the situation we're in now then they can still be de anonymized tour does not add noise to their connection it doesn't pad the packet so they're the same size you can still do traffic timing attacks and all of this kind of stuff mix Nets however fragment your packets into um encrypted SX packets all the same size they all look exactly the same individual packets are rooted differently a decentralized network of mix nodes that delay the packets variably as well so what you're doing is and we also have cover traffic so there's kind of hiding a signal in a noise idea right so what you're doing is you're reducing the capacity for an observer to be able to pull patterns out of looking at this network traffic right to be able to De anonymize you and another technology we're working on as well ZK Nims which are Anonymous credentials for payments because non Anonymous payments are a problem I want to pay for a privacy service that helps me out even if I want to pay with mulvad and I want to pay in zcash or use rail gun or Monero um they're still susceptible to network Dean automization and generally we'll have a small anonymity set of people who are using that stuff to pay for a VPN however privacy loves company you need to have as big an anonymity set as possible the possible sets of variations of actors to uh basically make this patent finding impossible therefore you need to be able to construct a way where people can actually pay in Fiat or pseudonymous cryptocurrencies right but the usage is cryptographically unlinkable to the actual payment so I can basically say yes I've paid for this in you know with my credit card however you can never tell when how much they're using this credential to access this privacy service itself there are also selective disclosure credentials which means that you can prove certain things about yourself maybe that you passed that you have paid for something and in a generalized sense you've gone through you can pass kyc you've done another payment you can vote in a Dow um it's decentralized because it's uh generated by our validators and it's a combination of the coconut and offline ecash schemes finally nvn is a the first kind of um the first kind of product app that's being built on the mixet for Network traffic protection so we are using ZK Nims for private unlinkable randomizable payments and access credentials it has two modes the anonymous mode where it goes into the mixnet and you get the full um full metadata protections of the mixnet and it also has a two hop uh dual tunnel in a tunnel wire guard which is using the outside fringes of the mixnet infrastructure if you want to we have an open Beta right now um also come and talk to me afterwards and I have um Flyers with credential codes on them so you can try it out I am also Devo if you want to build with this because all of this that I've just said also applies to you know all crypto apps wallets everything uh check out our Builder docs or come say hi afterwards thanks thank you Max um so do we have any question oh over that thank you so if someone is using you know there's the simple mode that's faster and the more complicated node yeah if someone is using the simple node what can the government find out about me okay so you still the the Speedy mode where you you have tunnel in a tunnel right you're still doing you're disintermediating none of the infrastructure that your traffic is going through neither of the gateways that it's passing through can have the full picture of either where your traffic is going or where and where it's coming from right so you're breaking those two things apart Nim also has uh Anonymous reply systems as well so you can talk to a service and then you kind of send let's say pre- addressed envelopes along with that traffic so the replies are all anonymized so the people you're talking to don't know who you are basically right so you never dock yourself um we don't it doesn't have the addition of the noise and the mixing so there is that to be said one of the things that we want to aim for with this is uh split tunneling so then you kind of get to a point where if you can capture say all of your devices networking traffic and then the stuff that is essentially asynchronous messaging apps email anything that's not like browsing and streaming basically you can send through the mixet mode and then for the other stuff then it's still better than the vast majority of other the options out there basically yeah yeah I started using it yesterday thanks do we have any other question over there and there thank you for the talk um just a question so if so you want to have a decentralized VPN solution I assume yeah that's that's what the Speedy mode is essentially yes um so the the exit nodes they're the dra is basically internet traffic that comes out at the end yeah um so how do you protect those note operators from malicious traffic so if if there would be like illegal content being downloaded from the location where I'm at operator we're relying on using TOS toal list um so we're basically like you know Tor and a bunch of other people have had this problem for a very long time so we're kind of using a lot of the public resources they have there in terms of the uh block lists and everything that like they maintain so we're starting off with that but we're also working a lot with our Val with our operators and uh yeah kind of putting together making sure that everyone's running in a particular like legally okay way and that they have protection as well but it is a thorn it's a thorny problem it's a constant problem but yeah okay well thank you very much unfortunately we we won't have time for another question um thank you very much for for your presentation uh

Automatic transcript — names and jargon may be misspelled.