# Privacy: why is it important? | Lefteris Karapetsas (October 2025)

- Speakers: [Lefteris Karapetsas](https://streameth.org/speakers/lefteris-karapetsas)
- Channel: [Berlin Ethereum Meetup](https://streameth.org/berlin-ethereum-meetup)
- Date: 2026-04-09
- Duration: 19:35
- Watch: https://streameth.org/watch/yt-ANcgzvfbI4U
- YouTube: https://www.youtube.com/watch?v=ANcgzvfbI4U

## Description

Join us on Meetup to get up to date on our Berlin events: 
https://www.meetup.com/berlin-ethereu...
See you at the next one!

Apply to speak at our future meetups: https://forms.gle/txTvFB4E8E8KbEqX8

X (Twitter): @BerlinMeetup
https://x.com/BerlinMeetup

## Transcript

So, hi everybody. Uh, my name is Leeris. Um, I will talk to you about privacy, I guess. So, first things first, um, I kind of forgot about the meetup. I'm really sorry, Marley. Like, and I I kind of knew that I had to come here, but I forgot that I actually had to have a talk. So, there is no slide in the talk, but I don't need any slides. Like, I'm going to talk to you about what privacy is. what it is to me, uh what it should be to you and what it also means in web 3 in and like more particular but it really doesn't matter for web 3 so much as it matters for any kind of uh digital life that we all have. Um so maybe let's start by asking what is privacy? Like we said it's important that everybody should have it. It's a you know a a a human right and all of that stuff but what is privacy? I saw in the previously in the slide um Martin had the glasses right many times you see the black glasses to represent privacy. Other times you see this kind of detective with the thing you know up here hiding with a hat. This is privacy like that you you try to hide something. This is how we present privacy somehow. If you Google most of the times the word privacy, you will get some kind of a you know hidden guy or like black glasses as I said. So it somehow has become um let's say that you need to hide something. So you need privacy. So this is a totally totally wrong way to see um what privacy is. Privacy is not about hiding, but it's about freedom. And it's the freedom to decide for you as the user um what you're going to uh allow other people to do with your data. When you do not have privacy, that means that you have no freedom. That means that all of your data, everything that you are doing will be open to the entire world. Um that is how I would at least define privacy. There are other definitions I suppose. Um and then u let's see maybe more concrete examples. um KYC this is um one of the uh some people say necessary evils but uh it's also kind of what uh has completely eliminated privacy for almost all of us yet everybody um ignores it right like how many of you have KYCed with some service in the last month me too by the way um and Do you know what your data um what they do with your data like where does it stay? There are many uh regulations that they have to follow. um very strict regulations but a regulation uh an actual implementation does not make mistakes happen like many of you I suppose are developers um or even worse admins of or system admins you know you can make a misconfiguration make a mistake something bad happens and then somehow you have an open port I don't know like something happens and a lot of user data are exposed um the regression said that you should not have done But that doesn't really help right like okay you did a very big mistake but then all of your users data is is gone. There have been in this sector and outside of this sector many many cases of um uh data that were leaked because of KYC. Privacy in general means not only KYC data but um other uh smaller data that we don't really consider yet. There are um the so-called data brokers that are actually trading them. um anything that you uh do, anything that you um do online like visiting a website um um even using I don't know Amazon to have your preference etc. leave some kind of um a footprint that goes uh from uh side to side and people are gathering this data and are uh using them against you. Where am I going to go with this? That's a good question. Thank you. &gt;&gt; Good. So, how do we solve this, right? How can we solve privacy? Um, at the moment with the current uh web that we have, I don't think that uh it is it is solvable. Um we started uh crypto at first in order to um allow the freedom to transact um to have our own um economy so to say but then we didn't really think about privacy there and this is I guess something that they will talk about in the web three privacy um but as a web three user how many of you are um actually thinking of what you're doing with your address what you're leaking there. Okay, that's good. That's really good because there's many people um that I know of and are actually working in the sector who just don't don't care. They say I don't have anything so doesn't doesn't matter. Uh the problem with uh web 3 privacy is that it's a lot more permanent than any of the other data. you um the moment that you uh associate an address with an ENS which many of us have done then you have leaked basically everything that this address has been connected to. Um this is something that many people do not realize and um is basically let's say cardinal scene of of blocks in crypto of the the big ones like it's everywhere. It's Bitcoin, it's Ethereum, it's Solana. Everywhere we have the same um the same problem. Everything is public which is great if you are um I don't know a government using the blockchain. We're still trying to get them to use the blockchain, right? But we as private uh individuals we are using the blockchain and we are leaking everything and I was trying to explain that to my to my parents at some point that um you know if if I give you this address then you basically it's not as if I give you my IBAN because there were people who were kind of thinking okay an address is an IBAN so I can send you money. Yeah, but you can also fetch all the history of everything that I've ever done by knowing the address. This this is insane. So, this is something that we um and there are people in web3 that are trying to solve this but with different um uh blockchains and also with uh other solutions on top of currently existing blockchains. Um so in web three what can we do in order to make privacy um better um any ideas because as I said in the creative talk so I would like some help from the audience &gt;&gt; tornado cash &gt;&gt; yeah mixes mixes is one thing that many people uh use unfortunately we had like the case with uh uh uh tornado cuts that basically has created a lot of problems legally for anybody that wants to use tornado. Anything else? &gt;&gt; More seriously on the KYC note, I don't know why uh zero knowledge proofs aren't all prevalent in Syria. &gt;&gt; So, I'm no regulator, but I I was talking with um some teams who were trying to think of using zero knowledge proofs for this. I from the technical perspective it should be okay but I think that they they hit hurdles with the regulators that they also need to have some um like copies of the actual documents which is insanely stupid if you think about it because this just creates um all the problem the toxic waste of of KYC that can leak and it's a problem for everybody who has to keep it and yes a zero knowledge proof alone should be enough but I don't So we need to educate the regulators better there I guess. Um yeah so mixers is one one way to stay uh private. Yeah. Um is there any other way if you're a bit more careful maybe like have you guys considered like something that I have been advising to many people that I know to just try and keep your private addresses and your public addresses. So you have uh how do you say like groups of addresses that you have uh you consider your public for example left and any address ever connected to it and then your private addresses where you just do stuff that you don't want to share with anybody else. This should work in theory right &gt;&gt; depends on how you manage it. &gt;&gt; Yeah. How how would you manage it? How would you um try to not connect them ever? I mean do transactions in different time zones maybe from this addresses um interact maybe with different instances of the same like different accesses so you cannot connect all these addresses you sends &gt;&gt; yeah yeah I mean that's that's all good advice why why specifically different time zones just to different times do not leave metadata from the IP if anybody's also &gt;&gt; if you do some analysis on maybe so it's even harder to connect. &gt;&gt; Yeah. Yeah. So, this is even more um like hard work to try to not leak metadata from if you use your own client, right? If I understand correctly, &gt;&gt; to not um uh connect the addresses. This is definitely a good idea, but there's some other things that um um are very very big traps when you do this because I have fallen into that. I have basically created multiple groups of addresses which basically became public over time because I just made mistakes and one of the biggest is basically offramping and um with offramping when you go to an exchange one of the biggest mistakes that people even knowledgeable just make because it's so easy to make is to just use the same deposit address by mistake because even the the exchange doesn't remind you that it was ever used before then you just click click send and then suddenly you're like oh my god I just sent to the same deposit address from the public one that I had sent to the from the private one then everything is is connected again uh so uh in the end like in order to have real privacy if you think about it if we can make mistakes like that then this is not really a solution I think That would mean like because I I I I wanted to at some point consider this a solution. You know, you have to just be more more careful and more um have discipline. Be a very disciplined user of of crypto. You will be tired one night. You will make a mistake and then these mistakes are irreversible. So the only real privacy that you can have is in my opinion from my experience so far is is like protocol level privacy. just to not be allowed to make mistakes, to not be allowed to leak your privacy. Um, does anybody else have any opinion on this for how to achieve privacy in web 3? You know what I'm saying? &gt;&gt; I mean, it really depends on what situation you're dealing with, right? So, I think privacy is also from the other side um like who is going to request something. So, I say that's like someone need to verify something. I think if you need to verify something then you just build on what you request from this person. So let's say there is um me as an owner of my credentials or me as an owner of my whatever I own and then I guess the other side there's someone that needs to request something for you. So for example in terms of identity you need to know um someone's age when you want to buy alcohol in the store. I think there you don't need to know what the actual birthday is of the person. You need to know if this person is above 18 or not. Right? So I think how you in that sense can like preserve your privacy is to say okay we don't need to know the birthday of someone. We just need to know whether this is like above 18 or not. I think that's called um select disclosure. I think that's how you can like preserve your privacy in one way. make sure that only the necessary things are um requested and that you only need to verify or that you only can give the information that is needed other than uh any additional information. &gt;&gt; Yeah. Yeah. I mean in theory that is good if if it can be implemented right with some kind of zero knowledge proof like taking the above 18 not not &gt;&gt; implemented right that's not &gt;&gt; h &gt;&gt; that can be implemented right or &gt;&gt; yes yes um I guess I not dealing with zero knowledge proof technical part myself um but I was more about the specifically web 3 activity uh type of privacy how to how to preserve it when you are out and about doing stuff in in in crypto, um how do you make sure to that that you don't don't leak your privacy? &gt;&gt; Yes. to be not so not not having to be so disciplined and um um careful. You can maybe separate this address into different software or even hardware like you have a separate laptop where you would never connect like a public address to an exchange and this would be slightly easier. &gt;&gt; Yeah. Yeah. But this also may fall under the discipline, right? I mean you you have an entire different laptop that that takes discipline. Um yeah uh so the the point that I'm trying to make here is that even if there's no uh like even if there's a lot of will from the part of the user and a lot of technical expertise it's uh you will make mistakes like I guarantee you you will make mistakes and this is why we need protocol level privacy. So if you take anything out of this is just that we need protocol level privacy uh for web 3. Um and for the other privacy uh this actually apart from web three privacy what concerns me a lot and like made me create the company that I I am working on is privacy in general like having the ability to share uh data with whoever uh I I want and not be forced to share data. This is not specifically web3 related even though uh so I have created this company called uh this product called roki with my team and it was created from the uh the need to do accounting. This was the very first uh reason of it existence and then to track and to manage um mostly crypto but it the fact that it's crypto doesn't really matter. It's the fact that it is your personal financial data. And everybody back then, back in when was it like 2017 was telling me, "Oh yeah, you you should go to bitcoin tax.com. They are good. They just you just give them all the addresses and they tell you how much you need to." And I was like, "Are you kidding me?" Like that's basically just giving as we said everybody or I but also all of the ability to get the entire history. So I wanted a way to do all the calculations myself. So I made the script in like back of them uh in the CLI and I got what I wanted and then I I used it and then I realized that many other people had the same problem. Um and wanted to have something that is not a web app. Um so this is also something that personally concern me a lot and that is um having the ability to have a choice to use um local applications that keep data locally and not uh web apps. This is not this not specifically for even though this is again a crypto management and crypto accounting application. This is a question of having the choice for other stuff too. Um because we have a tendency in the tech field for the plus who quite a long time actually. Yeah. For last 10 plus years yes maybe more to just put everything to the to the cloud right. Everything is a web app and and the word app has become uh kind of synonymous with just having like opening a browser tab and there it should be there like you don't care that most of your data actually passes and is visible to to that server. This this is insane to me. I I can't do this and I'm physically unable to do this. This is why I have I'm a very big proponent of of uh self-hosted or local first software. You can call it many different ways. Um so if anybody um has the need to um uh manage their crypto in a private way, safe way and decide what to share and with whom. uh you can go and use um Sunnis very by the way um the tool that my team and I are creating called Roki so roki.com but also um I I would encourage you guys because this is actually very very big part of your privacy to ask yourselves what does each and every single app that you use do with your data and where is it stored. So, if everything is stored in a server, then you're fat. Like, you're you're completely screwed because at any point anything can leak and uh I don't know like when I first started saying it, it felt like um uh fear mongering, but as the time passes, as time passes, then we just saw it happen so many times. We have had so many leaks and so many um um data um go out there and not just go out there and then it's out there and it's it's okay but it has led to people uh getting harmed and I don't really it probably has also led to loss of life. So it's it's like something really dangerous. It's not just fearongering. So I would just like to to close um the this uh talk with u the call out for you guys to just think what each and every app that you use does with your data and try to use and support applications that give you the choice um to keep your data locally or to at least decide how much of your data to share with whom. But that's all.
