New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

How R&D can solve critical privacy challenges | Will Scott - Sergei Tikhomirov - Daira-Emma Hopwood

Ethereum Cypherpunk CongressMon, Oct 7, 2024, 12:00 AM

Speaker

Panel #3: How R&D can solve critical privacy challenges Panelists Will Scott x Filecoin : https://x.com/willscott Sergei Tikhomirov x Waku : https://x.com/serg_tikhomirov Daira-Emma Hopwood x Electric Coin & Co : https://x.com/feministPLT Moderator: Mykola Siusko x Web3Privacy Now : https://x.com/nicksvyaznoy Support - Donate: https://docs.web3privacy.info/donate/ - Become a member: https://web3privacy.info/membership/ - Contribute: https://docs.web3privacy.info/contributors/ Explore http://web3privacy.info http://github.com/web3privacy/ http://docs.web3privacy.info

Transcript

and now we will have real deal R&D in the room uh will Sergey dma please join us and Round of Applause yeah bottles are necessary evil bring the bottles back to the B said don't put it on the ground thank respect the house One mic for this part um bear with me a second um and here we go so this panel is uh centered around um R&D and it's uh and it's a nice rhyme to where we started because the whole eth Berlin motto is identity crisis and here we go how uh R&D cryptography y uh let's say protocol design protocol research could solve and Tackle this identity crisis but by hearing y Tong I would start from the different angle like what kind of adversaries you are each of you that uh especially from the angle if you want to solve the uh let's say challenges within the privacy or censorship resistance you need to think like a sort of adversary and then how you play with this Duality like sort of Batman joke type of roles in your work and what kind of roles you love impersonate in your uh R&D uh let's say Direction but I forgot to say that D is from Electric coinco uh Serge is from wo/ status will is from file con incentive Labs yeah the and really nice people who know what we are talking about let's start from Di uh yeah so the the repeat the question what kind of adversary you are uh yeah we we should absolutely consider um protocol designers to be adversaries um uh this is important because um it it is very easy to sweep design problems under the carpet um so you you should be skeptical of the claims that people make about their protocols um and I think actually um so the the cryptography um of research and and uh design Community has a problem in communicating um our stuff to end users um oh hi um so we need to get better at that and um we we also need to so foster a culture of skepticism um because for example the a lot of um companies um promoting Things based on um sort of uh trusted execution elements and processes which are trivially vulnerable to not just the um the uh processor uh designers company um but also to um to State attackers which can trivially break um trusted execution environments and to to any hacker who exploits um a mistake in the design so um we should always be skeptical and I've picked on te's there but um we should be equally skeptical towards the kind of protocols that I design I get my mic uh thank you thank you for the question it was really a little bit unexpected I would say because uh it's not like something that at least uh I don't maybe think often enough in the frame of mind of an adversary so uh we in vaku basically uh Implement a communication layer so cont to some other projects out there contrary to blockchains we are not uh of financial nature per se we may be used by some Financial protocols but not necessarily but we mostly think in terms of message reliability and message privacy and how to ensure those kinds of things so I would say that from our perspective uh the uh crucial questions is to think uh who runs the nodes and if I were to run some say substantial part of vacon noes what could I uh do with that like how can I analyze the messages that's that pass through me and even though again like as previous speakers on this stage have mentioned already the metadata is often times even more important than the data itself so uh what what can I track if I um control many Vantage points in the network so this is like one aspect of adversarial thinking that I'm think might be relevant here um another another one is perhaps the economic incentives and motivation so we um at least at the moment we don't have explicit monetary incentives but research is happening around those lines so um protocols should generally be sustainable and we shouldn't expect just altruists to be running noes and to uh enable like our Network functioning forever but if we're thinking about incentives again we should uh be mindful of our limitations and be mindful of how the incentives even if they're monetary incentives what we provide potentially to node operators how that compares to other incentives that they might have and if I'm a malicious node operator how easy or how hard it is to bribe me for example to do something nasty or like I don't exist in a vacuum as a node operator I don't just consider okay these rewards versus that rewards I also have the real world around me that also provides me with some uh like rewards but also punishments if we are thinking about like governments uh uh and laws and court orders to reveal some data so ideally I shouldn't be even able to uh to do so so that was a bit of a uh I don't know maybe I'm not answering answering the question directly but that's what comes to mind I mean I think you brought up a couple of the the relevant points here and and one is how do you know that you've got a threat model that you're designing against that actually has um a scope of threats that's realistic and has these things that may fall outside of your protocol like someone being bribed on the side or out out of band it's not it's not part of your protocol but there's these externalities and making sure that you've scoped enough of those in ends up being one of the tricks in being able to say you know what it actually is that you're that a protocol that gets designed is secure against um because that that unknown space is very large uh and to feel confident that you've properly characterized that landscape of threats ends up being um not necessarily effective or a thing that you're going to feel confident about in approaching it in that framing um and so trying to find ways where you can approach from the other side where you have a um a threat model that is um more than what a realistic adversary would have um and so clearly a stronger Threat Level and then working down um often will get you more confidence than starting with the okay well the protocol does this and then we've got these specific externalities that we're going to try and defend against like you know resistance to bribes or resistance to collusion of this specific form you really would will generally end up with a more confident thing if you approach from a um much more powerful adversary and then uh carve out exceptions that you need to but at least clearly qualif and like have a sense of what that is and why you had to carve it out yeah um this is actually um so one thing that I think the academic um uh crypto Community is doing right that um if you look at for example um security models for um say encryption it's not just um uh can you find the key can you find the plain text it's also um if you have an oracle that allows you to do absolutely anything except um decrypt this specific PL text can you distinguish these two plain text in other words can you get any information whatsoever so so that kind of model um we is the kind of thing that we should be designing for uh we should be developing for more advanced and more complicated protocols um then you said we should be critical um let's follow this approach in terms of um within the within the cryptography specifically and within the ZK realm now F realm there's a sort of Buzz around it when many entrepreneurs are using basically cryptography as some sort of VC uh incentivization or VC mechanism for fundraising for let's say having uh money for the future product shipment and stuff like that how you would see the sort healthier relationship between the cryptography then implementation itself uh let's say on on the behind the dev team and then scalability within the product teams because sometimes they're Gap they're not just kind of like developers shipped the whatever cryptographers the on or applied cryptographers kind of like made on but then you need to kind of like product manager so sort of people who could really bring the audience if it's to B2B b2c or whatever so how you would State this from critical standpoint the balancing between cryptography then uh development uh team and then the delivery team within the one whatever it's electronic coin Co or the previous experiences stuff like that uh I have a conflict of interest here as a direct recipient of a um protocol funded Dev fund so uh I should not answer this question I'm I'm happy to um you know uh speak here I think my perspective is that once you get into the relationship where there are products being built on top of cryptographic Primitives in some sense you can think of that as a win because it is Flowing a bunch of money into productionizing and scaling and making that area of resarch uh grow and um is is is sort of what we're after right like that that is a flowing of capital into additional research to figure out scaling um and so the the place where we really need to be figuring out how we invest in what the model is is the problems that are still just in theory that we haven't figured out how to productionize or build the protocols on because there it's purely in an academic world the motivation and incentive is make new papers figure out some new extension um go to novelty uh that gets you published and not to you know how does this actually work in a world that's got Doses and availability and all these practical nitty-gritty problems that make them potentially got a gap there right after Academia um that I think zero knowledge has recently crossed but a lot of the others haven't yet and so that's like uh a big problem of like how do we identify and how do we get that even more speculative uh Capital flowing uh to get these additional cryptographic uh Primitives um the attention they deserve yeah I totally agree with the like observation about about Academia I mean uh there are bonuses to Academia I'm also coming from an academic background and I very much appreciate the enough rigorous approach and the formal approach that allows you to precisely State what is being proven or what is being um you know stated but on the other hand um yeah the incentives are not aligned very much and of course there's like there's no perfect solution but perhaps a solution that is not perfect but working in the hands of users that actually brings value to the users is better than an ideal paper that just published and doesn't make any other impact on the world apart from maybe uh like gaining tenure for the for the person who wrote the paper uh so yeah I mean uh what can I say I I would say that for like for the researchers that kind of cross between these worlds it's important or I think it's important for me at least to kind of um not let the product development become too deceptive and become too like detached from the scientific foundations and not like of course we perhaps we have to take some shortcuts to make it usable for the users because that's what we aim for eventually but still we have to be mindful of our limitations and be uh like remind ourselves and people around us and our users as well that it's not perfect and cryptography even if it's uh a well-designed algorithm it's not a silver bullet and there is lots of implementation details there's lots of potential attacks and we cannot do everything perfectly at once so it's gradual process I I realize there is part of this question that I can address because um I also have experience in the the academic world um as a co-author on the the sinks paper and to to be honest I find that world very exclusionary um it it makes a lot of assumptions about um of uh what your incentives are um your your access to education um your history of education um uh your ability to write a certain kind of paper um and uh often the best protocols um don't come from the the academic world um and then now that sorry just a short note on that it's like some Twitter and I'm quoting it's like if satosi has submitted the Satoshi white the Bitcoin white paper to conference it wouldn't be accepted yeah um and also right now with lots of challenges within the persecution of privacy developers it's interesting that there's interplay between the applied cryptography and general research like how we can really tackle those issues having so complex range of players around and also it even led to it's related but kind of like a bit separated to kind of like what decentralization of ethereum would even mean mean within recent kind of like uh many people around questioning the protocol Guild role some sort of non transparency in terms of tackling the research side moving forward who is responsible for what what kind of uh endgame scenario we are looking forward and who who should uh kind of like uh Foster it and then should this person work could this person work at the same time from agen L and the same time for etherum foundation or someone around so the question is basically in uh this realm like uh how you would uh summarize the key challenges that research is passing through in this environment that I won't call hostile because if you trace back and you read books like I don't know like people's history of United States of America of who in you would be like oh those things existed for many centuries it's just you want you were not a part of that specific group who were threatened by some sort government or other type of adversity so what are the key challenges of uh R&D in that sense within the Privacy realm that's happening here and now I um I I would call it hostile but obviously all of the the other things you're referring to are were also and are also hostile um I I don't really um think of uh attacks on privacy researchers as distinct from from attacks on um from attacks that are based on people trying to maintain power in general um there a special case of that um and I mean the the solution is Revolution um the solution is to to overthrow the current order um I it is that that is the solution um and if I was to say anything else then I would just be and you I I guess I could add to that uh that um yeah I mean thinking about this like research basically is just a tool it's just a me like a scientific method of Discovery or like of trying to figure out whether a certain statement is true and how we apply it and to which questions we apply it is a question of uh like either some project leader in some way or is some consensus among the uh founding members of a project or whoever defines the direction or um I mean yeah I'm just thinking out loud basically so uh coming also from Bitcoin background in Bitcoin is a special situation where it's not controlled by anyone and I would say that it development is mostly based on like principles rather than strategy they have a certain set of like defining um fundamental principles and they the the scope of potential changes is so narrow Within These principles that there is I mean there is lots of debate but compared to what happens in other projects that have wild you know swings of whether we do this or that it's quite narrow band um the theorum is kind of different in that regard because it has a leaders like it has italica as a leader although maybe not like a dictator but still a person at the helm uh who defines the direction and I like I think uh it's good to take advantage of the situation because although it's not as decentralized quotee unquote uh it still can be more you know like directed to some to some to towards some aim and then it's the question of how do we um uh how do we uh direct the research towards the goal that has some kind of broad Community consensus around it so um I'm not sure again if if it answers the question really or not uh no good good good maybe I should just pass the mic I I guess the the space that is sort of getting called research around be it ethereum or or within this crypto currency space more broadly um is you know a thing to look at as a job and a deal that is being presented to to researchers of like you get a salary and an exchange you do work in our ecos system um and is you know something that you should evaluate uh as you know is that going to give you the space to do the work that you find impactful versus Academia or any of the other options out there versus running off and you know you can you can make your own protocol you can do your own thing um and and you know set up your own uh terms and deal uh for for doing that work as well um and and write like we exist in a capitalist Society uh like you can you can play the game they're going to be giving you as as little compensation as they think they can get away with but uh you know that's that's that game that's getting offered in that space um that may be enough flexibility it may be more than what you're getting in Academia um and I think we see that that's been an effective way to build movements in this space and build some of this transition um but like that's just part of like the tradeoff is it is more constrained uh and directed and you've got some additional risks uh and that's like an evaluation that each person's going to have to make well remind me you have uh it's written ethical Hacker no on your X account or on the website something like oh I just write web hacker ah okay does have any U so it Berlin publish Manifesto there kind of like ethical thing how we should approach the whole hacking I would say uh situation and the distalization situation and I never heard ethics behind let's say researchers cryptographers explicitly in terms of kind of like well written Manifesto or like what we stand for apart from the whole organizations how they um write something like we Foster lates cutting agge blah blah blah how you would State the core ethics that researchers should follow within the Privacy Realm um I I mean just try to to do things that will help people um and especially uh marginalize people um and especially um create systems that um try to disrupt existing systems of power over people um that th those are the principles that I follow in general um not just when I'm designing uh cryptographic protocols um and we have won some some huge battles in the past um just in the crypto realm um so we we've been winning the crypto Wars um we we won the right to um publish uh openly cryptographic protocols we um we defeated uh attempts to force um government to access to Keys clipper ship and so on um we have more recently um so established uh https as um s of the the default for um well administered websites um those are huge victories um we were um in the process of normalizing um sort of uh endtoend encryption for messaging um we we can win this battle for financial privacy too will I mean I I think I'm personally happy to take a pretty Broad View uh here which is if you're building something and you've got a threat model and you're building a protocol addressing that threat model like that is a useful contribution it doesn't have to be my threat model like there's still like having a diversity of protocols having a diversity of ideas come out there having new things happen is helping you know provide a a a diversity of options that become useful uh for others to build on so in that sense I I think like whether you're directly you know solving the problem I have or directly you know even if you're not challenging systems of power If You're Building A cryptographic Primitive that someone else can build the system around that's super useful and so I'm I'm I'm really happy to sort of take this very broad view of you know if you're if you're just doing some sort of scam that's you know on the other side of that line um but but my line is is fairly far on the like if you've got some thought model and you're Building A system that addresses it like that's useful yeah I I think we should like there are different levels I guess in in the original question I mean when we're talking about some uh lowlevel cryptographic cryptographic research when you're operating keys and okay this adversary has some I don't know game and with this probability it distinguishes between that message and this message it's quite abstract and it's kind of it's difficult for me to come up with a way to explain why this could be unethical but if we go like into situations where someone I don't know works for a dictatorship and develops a deanonymization methods that will be used for political persecution and it's quite clear that it will be used for that purpose then it's definitely unethical and of course the line is blurry then and different people have different like political opinions about what constitutes this ethical an ethical line so I don't have the clear answer U just invite people to think about this and maybe the last point that I will add is that uh there is this kind of saying or maybe an explanation of people who doing arguably unethical things who say like if I decline to do that someone else definitely will and so it doesn't matter and that's I mean I'm not sure what I think about this line of defense because uh cryptography generally is is based or should be based on the assumption that if we have I don't know a private key the key is private but everything else can be public and still the algorithm should be secure so uh if we have some like unethical quote unquote work that does some deanonymization if deanonymization is possible in like in theory then it's possible and someone will discover this so we'd better Discover it sooner and then think about how to defend against it then to be in this unclear situation then we don't actually know what the text could be so again just an invitation to think about this uh don't have the answers of course yeah um so yeah there there are different levels at which you can design um cryptographic protocols um the there's a even when you're designing something that is quite general purpose um it matters how you describe the model and what assumptions you make so um let's take something like um identity based encryption um it it's still quite an abstract primitive but but if you think about um the threat model that's um so inherent in how that's being described when used for its um original identity based purpose it it's completely trusting the um so the the key um I I forget what it was called but the um the key generation Authority um now that same primitive could also be used for um forward scoring cryp for example um in which case the so how you using the same primitive um you it changes completely how you think about it and it matters as Ying Tong was saying earlier the metaphors we use matter and so how we describe so even the lower level um Primitives matters um uh uh I forgotten the other point I was going to make uh um and then um these industry there's a culture of saying maybe it's influenced by IO times like uh skip marketing look for devs and research team as kind of like the more devs kind the better the more researchers the better uh and then once I was working in N I understood that people don't know how to check up if researcher is valid or not they there's a certain lack of within the general public go and check academic citations amount of publishing materials and stuff like that although Google Scholar and other materials are there um and we were kind of playing around like how to make these numbers accessible or reputable to General Public what would be the way of reintroducing it's kind of like explain research reputation to 11y old and then you try to break your head and think around like oh what could be done there but I would go the other way around because people don't talk necessarily about where cryptography or R&D fails like what's the limitation of it more it's kind of like easier to say that that's a Holy Grail Sil bullet that's the way we will solve the issues and then kind of not or there could be like a big gap between the paper and implementation so I would uh want you to mediate on the what are the limitations of the research base field how you feel them and maybe was the real image of the role of cryptography in the in this industry in that sense I I I'm quite optimistic about the general Public's um ability to get um a correct impression of how trustworthy a given sort of cryptographic system is because if if you think about the the Six Degrees of Separation idea um I think almost everyone probably has a friend of a friend of a friend of a friend who's a cryptographer um and so it is possible to Via so friendship networks which we shouldn't underestimate for people to to get an accurate idea of um or maybe it isn't even accurate but it's it's well motivated they're they're trying to get to the truth um about how um a particular system will or won't protect them um and I don't think we should be unduly negative about that um uh we should um try and do better in terms of explaining our systems um and as I said before we should try to Foster this s this attitude of skepticism um but it's not an unsolvable problem yeah uh like perhaps it somewhat disagree I don't know maybe again like thinking out loud for for me it sounds like um I mean this the scientific uh papers are written in such a um language that is difficult to comprehend for a reason I mean it's good when they are written clearly and like the sentences are short and clear and so on but there is notation there is like some um definitions and they all exist for a reason so um I guess what I'm trying to say is that for me it sounds like a little bit unreasonable to expect everyone or even some significant share of the population to like really understand what's happening under the hood and I don't think it's happening in like other areas of society like we don't understand how like medicines work if we're not doctors we don't understand how even like how cars operate under under the hood although we use it all the time so for me I think the priority should be to at least um do a better job at explaining to to your fellow researchers and developers maybe people who are somewhat familiar with the field but not an experts in this particular topic what you're doing and um what problem you are solving and what your solution is so what I've come to realize is that uh there is like even if you don't understand the NR details of a particular algorithm if it's clearly explained and if for example I go on the web website of some blockchain is project and they have their idea or their key proposition explained in different forms they have a paper they have a blog post they have a video and a podcast and a poster and whatever and if everything is kind of harmonized between each other and I have a clear picture of this is the problem this is roughly what their key idea is and this is why it works and how it differs from Alternatives that's already I don't know a very large uh step towards establishing your reputation as a um as a good researcher or is a good project that is based on sound research uh let will and then go I guess I've got a couple comments I think um part of that uh premise comes from um I don't know if it's like compromising on what our definition of researcher is um that that that term researcher gets used quite a bit as you know a marketing term itself um you know if just just because you've hired someone from grad school and then had them build your your system um doesn't necessarily you mean that that's research right uh so so we could have the strict definition of like the research is the stuff that has paper outputs and then you've got a much clearer you know line that you've drawn and you've got a clearer way to sort of explain you know is this you know impactful using more traditional academic uh you know I don't know as as as flawed as those metrics are you just go to the same ones uh and that and that works um or or you've just got you know a software engineering team um so I I think that's maybe limitations the the limitations of of a research like an applied research team um I mean I I think I think if you take that strict approach of saying the researchers are the ones who are still writing the papers um It's Not So Different uh because I think for the people who are um primarily producing either paper output or are you know building some model and then writing the papers about it um they've got enough flexibility generally uh and there's a competitive landscape right now where if they feel too Limited in one place uh they can likely either go to Academia or somewhere else uh I I I think that um if if you're getting you know published and having impact that bridge of whether that's happening in an R&D lab in a crypto company lab Thing versus in Academia is pretty uh undifferentiated would be would be my claim uh by the way you you used uh medicine as an example um it is arguably doing even worse than crypto in terms of um uh explaining and justifying itself to patients um as I know as a transperson you basically have to take over your own Healthcare and so you see all of the mistakes that doctors make um and it's terrible it's it's worse than cryptography here we go um but uh and now reversing to collaboration because I saw that recently I think EC uh will do an audit of penumbra then uh V is actively collaborating like with rail gun and I think there's sort uh feedback loop um then will works in in incentivization lab which all I guess means working with others and external Partners I would uh jump into the topic of collaboration like what's the nature what should be the nature of collaboration between the research teams on the different sites and how projects focus on privacy could help each other uh I I think we need more more collaboration and we need um to to be more deliberate about it I mean the the um the ECC audit of penumbra just happened um so by accident um uh Henry from uh penumbra Henry devant um theyve contacted me about it um and yeah we we we just need more of these kinds of collaborations um so to to make friends with the um researchers at the other um so protocols um that that often helps um and without getting too s of cozy and and ending up um designing all the same systems um just replicated um yeah I'm not sure I have anything else to say about that sery yeah definitely collaboration is uh indeed uh a good thing and we should track each other's work I guess and uh for again like maybe a tangential thought somewhat related that uh I think an issue in the industry may be that different teams are working on roughly the same problem and calling the same things by different names and uh in Academia it's I mean sometimes it's also the case but in general Academia is stricter in terms of defining precisely what we are studying and what the properties are so I think it's is quite helpful and what industry can learn from Academia is this more rigorous approach to definitions and what help helped me a lot uh are some systematization of knowledge papers where some researchers go into I don't know 20 different white papers and websites and then they make a big table that like half a page on their paper that says okay this projects calls this thing by this name and this thing by that name and now you can compare things and now some kind of unified picture emerges and allows everyone to learn from everyone else so uh I think we should do more of that uh just comment there when we were assembling database uh there's a hilarious simple thing it's super hard to find out what project is literally doing for privacy when they're stating uh stateof art privacy uh the the latest development privacy I'm like what are you doing exactly I just need product description generally speaking it's a horror movie it's a thriller if we comparing with the movie genes and it's hilarious because basically you spending lots of time just finding out what's that what's your one use case for example how people should or could use you um I I think commercial projects especially are not incentivized to compare themselves with other projects um I I mean I I argued from the start um that Z should um sort of um write a comparison of itself with um Monero uh it would have been controversial but um people don't have a clear idea of what the the tradeoffs are between so the different approaches we take to privacy um and it it it was just considered too toxic to um to touch really um yeah I I guess uh so there's a couple things that probably I want to say uh on this point um one is um we have already some forms of collaboration here um so an example would be Universal privacy Alliance um the the a fair number of um privacy Focus protocols um uh have a an industry Alliance like there there's a legal Swiss entity um that can act as a joint advocacy uh Organization for them um and so I think there there's some uh you know things of that nature that that help us have some of these collaborative Unified voices um the the the other side purely as you get into research is that uh I think a lot of the the conferences and places where people are presenting papers end up being fairly neutral uh against corporates so like maybe maybe not uh a Devcon or um a dapon or something like that but if we if we look at things like uh real world crypto or um pets will be in the UK in July these are so privacy enhancing technology Symposium these These are larger Gatherings of both Academia and um industry research um that um are are places where the researchers can come together in pretty neutral settings and trade ideas and I think that's working reasonably well yeah just to the point of conference I would also recommend people who want to know more about this intersection of academic and uh Industrial Research to look at Financial cryptography FC conference and advances in financial Technologies or AF which are also one of the major avenues for publishing research in our general area and to wrap things up I'm interested what kind of papers or the projects not of your own you're looking forward to kind of like uh be implemented or delivered or you just read them this year like something fresh that interest you as researchers as cryptographers as hackers um within the again privacy realm and maybe something fresh in that sense so we will have a snapshot of right now so people can go explore and that will kind of like that will be an incentivization because it's called curiosity um uh binas uh which is um so a a category of proof systems using um towers of binary Fields um and I think that has the potential to sort of um bridge the gap between between um what has previously been efficient in circuits and what is efficient um so for General computation yeah it's kind of uh difficult to be honest to like pinpoint something in particular uh I would say that again like uh listen to a few talks on Deon earlier today and uh again it's not maybe directly related although again tangentially related to what waku is doing specifically but I've Heard lots of talks about like more financial applications and defi stuff and um rollups and related things I think that uh often times people kind of put privacy on the back burner I would say for the sake of efficiency whatever you define it like especially Financial efficiency and people talk a lot about uh which tokens gain yields here and there and how you can lock tokens from tokens uh but who tracks all these things like how private are you while you're doing this who knows probably you're not very private so this I think is some uh area of research that requires more attention in my opinion and maybe projects like vaku could be useful for communication layer for privacy focused you know interactions between different actors in this ecosystem but I don't think it will be sufficient we should think more about privacy from different angles in U Financial applications and others as well um one one that uh seems to be continuing to advance um fairly quickly that's got some interesting um things you can do with it is um time lock constructions so how do you have things that are uh encrypted uh such that at some future point in time they will become able to be visible by either globally or at least some parties um and so with with that sort of construction depending on your efficiencies and like can you have everything get encrypted against a single key so that there's one decryption so you've got a bunch of efficiency things at this point it's a systems problem um but it gives you a way to sort of get around a bunch of um weird constructions that have popped up um in ethereum and elsewhere actually one more one more do you ever iterate uh talk or sit and talk with legal side because it's interesting that a totally different Spectrum although I know that in filecoin there's a big team doing lobbying many others even I saw once gr manager on file con Foundation I'm like oh that's a real deal um have you ever like how what's the nature of iteration between the This legal side of yours uh not necessarily in organization but in General within the market is there connectivity between those two Realms I mean we do have um people working on regulatory um Outreach uh at ECC are fewer than um before because we have less money um uh and we do talk to them um but I mean the that doesn't directly influence protocol design um so yeah and I don't think it should um I think that um we we have to build the most private systems we know how to build um and I'm not here to compromise on that even if there is a lot of regulatory push back yeah so I don't actually have much of a comment I mean these type of things haven't affected my work personally that much or at all to be honest but uh like some kind of a canary warning here so probably no further comment I I think there there are um like Tech policy um Labs or um entities that will generally uh output white papers um that help sort of lay out um what shapes of Technical Systems are going to be effective in a regulatory landscape so you know you should expect that the regul regulation is going to think of money as it crosses borders as happening in this way and so a system would need to do X or Y in order to be seen in this regulatory light like is the sorts of white papers that you see come out of these Tech policy Labs that are sort of at that intersection um between you know trying to interpret some of the Technical Systems and then what what that legal perspective is going to take so I think that's like a um one form of that feedback loop that happens I think the other one is you get um requirements or um risk mitigation requests from legal and then you try and iterate back and forth on like well what solves that okay you need to you know make sure that you're doing your kyc how does that work with a smart contract there's no customer um so um it gives you some interesting uh places to start designs I I said that it hadn't affected protocol design but um it does affect the um it does affect uh our ideas of what services we run versus um Outsourcing to other people or letting the community run because um there is um a lot of centralization risk um with the protocol developers um being the the same entity that runs um of nodes or um so of facilitates um transfers and we saw that with um tornado cach for example um so um we are trying we are very consciously trying to separate um protocol design from running infrastructure oh one more one more but that's that's a good one uh it's not a technical advice right now disclaimer how you would do tach differently hypothetic it's not a technical advice but how you would do approach tornado cash differently uh tornado cach is a mixer I don't think mixers provide adequate privacy um you need to hide the whole transaction graph um so that I guess that doesn't answer the question it's it's a I would not be involved in that project anyway because I don't think it provides adequate privacy I think we should learn from satosi Nakamoto that's a great rep up of today's evening thanks Dar thanks Serge thanks will yeah thank you I I will do uh small uh closing remarks but just to be quick um I want to thank everyone involved today uh especially the cabbas crew uh San doing the streaming lii hosting us many other people voting deciding that it will be okay to have us here uh all the speakers all the contributors uh there were many people behind behind the thingy all the friends I guess all the I'm not sure I'm lost in those uh files uh everyone who said yes when we Outreach everyone who said also no for any reason and also that's cool to have a diversity uh lots of contributors who came here today uh and I hope that whatever we do uh will help you to smile like ja uh or to or to drink a beer like Max uh or to be like King Tong that said D would join the show today uh or Tim who asked about his colleagues to get in uh it's about human connectivity and we do things not for ourselves but for others too and I wish I really happy that you heared the blockchain Socialist song uh that that that's epic thanks lot let's wrap up for [Applause] today and we socialize uh no one is throwing you out you can talk

Automatic transcript — names and jargon may be misspelled.