# How to onboard 22 million users overnight using non-conventional cryptography | Devcon SEA

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-07
- Duration: 08:16
- Watch: https://streameth.org/watch/yt-DKJYpdXsOwQ
- YouTube: https://www.youtube.com/watch?v=DKJYpdXsOwQ

## Description

Since 2004, the Mexican tax administration started to issue digital identity certificates that linked government IDs to sovereign private keys. These has facilitated the electronic invoicing system that is designed around a public key infrastructure maintained by the central bank.

This infrastructure has provided with private keys to over 22 million people. We're onboarding all of those using Account Abstraction in a friendly-manner.

Speaker(s): Ernesto García
Skill level: Intermediate
Track: Real World Ethereum
Keywords: Identity, Cryptography, Account Abstraction, pki

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

[Music] all right everyone how's it going are you enjoying Decon great so let's get into it this is a quick presentation so uh we better go quick let's start by the agenda we're going to cover three topics today the number one is a quick refresher on web to cryptography because this is important for what we're going to talk about number two Mexican case for digital signatures I'm Mexican so I want to share more a bit uh about this specific use case and number three what is the status of this very similar use case around the world in other countries let's get into it and let's start with this refresher on web web2 cryptography for understanding this we're going to explore public infrastructure who's familiar with this topic okay I see some some hands perfect let's go into it so basically uh public infrastructure works by having a certification or uity right this certification Authority can certify that a certain private key Either for encryption or signature is belonging to someone right for example we can use this to issue a certificate for a website if you have seen the green log before that is basically what it's doing it can also enable machines and of course individuals but what is interesting is that we can also enable more certification authorities which at the same time can enable more certificates for again websites machines and individuals all right so the most common use case of this is basically using the certificate for encrypting the communication for a website if you are putting a password on certain website this is probably encrypted by using one of these certificates all right now that this is clear let's get into uh some particular use case using uh government certified credentials because most countries already use some sort of regulation for certifying uh private keys for digital signatures so what can we do about this and how can we use it to ort uh 22 million people let's take a look for those who don't know uh basically there is a model law published by the United Nations in 2001 this is for electronic Commerce and if you have ever used your credit card on a certain website is basically according to these regulations in this one it is specified that governments should issue a certificate for a private key for individuals so in reality even before even Bitcoin was invented some government were already trying to onboard people to use crypto for uh digital Commerce all right so the important thing is that the call the the talk is called how to ort 22 million peoples but in in reality on this couple of months before I submitted a presentation until today there has been around three million more people certified by The Mexican government to use a private key and these certificates are tracked by some public data that you can also find I don't have the source here but I can definitely share it with you so as you can say see there are 24 million people like individual people and around 2 million businesses who already have a private key that is certified by the government and already has kyc so we don't have to ask them for a passport or a digital ID or something like that they literally have a private key we can use and put into an account like using account obstruction and on board people immediately to that so the way this works is in Mexico at least the bank of Mexico which is the main authority C C ifies the taxes authorities right by having this uh this structure of intermediary um certification authorities more private organizations can issue digital signatures for individuals like this literally all my family and even my aun understand how to manage this private key so these people already understood how to do basic private Key Management revocation and these kind of things like recovery as we all do all right so this is the interface to generate your private key as you can see this is pretty familiar uh this is basically telling you to move the mouse who's familiar with that to create entropy right this is Rong locally so that means that the account is completely self- Sovereign even that the government is certifying it because you only share the public key you have your your public key for your own and you can use this for any legal purpose in Mexico at least so just a quick meme um not everyone is really happy with that because you know uh there are some privacy privacy issues related reled to this uh but we we're definitely going getting there at the end of the day people is already certifying their own private Keys sharing their passport or some other way of identity so what's the status for these around the world all of these countries have some way of uh public infrastructure that can be already used for enable people to use crypto and crypto Services most of this is already regulated so if you were looking for regulation there it is guys um some other cases like for example if you're from from Spain in Spain you have this this small ID with a little chip on that that chip includes another private key and the only issue with the with this is that these are RSA Keys which is not recommended anymore uh but by the NSA on the following years but we can definitely change that right so aside from inside instead of this sorry uh we have been scanning some of these codes and making a CK proof and adding some trust assumption to the process so my call to action for you guys is just use the cryptography it's already there thank you so much thank you for this interesting talk yeah question you have any question okay try um so whenever you generate a private key and you use you know entropy and then like a developer you are trying to secure this SSH cas how does it work from the consumer's endpoint in the Mexican case how do you store and secure those private Keys you store them locally um usually if you go to the office they ask you to have a USB which is obviously not the best case but the problem is that I think nobody has like brought these questions up right so the more we ask question about it the better we get right now it's just an USB so if you have if you happen to lose to lose your USB you have to do the process again okay yeah uh but you can do online you just need to uh basically tell the authority to revoke the certificate there is a Merle tree who has like all of the all of the public Keys enabled or disabled so you just put it on a revocation list generate another one certified again you're good to go next question is over there yeah there is a security issue in ec20 standard which was classified as the lack of transaction handly this issue cost $150 millions of dollars losses since 20 17 in 2023 the author of ec20 standard the Fabian V confirmed that ec20 lack of transaction handling is a security issue this was reported to open Zeppelin three times but you didn't apply any fixes to your implementation of your sit token why why is this issue not documented in your jhub repository and causing Financial damage to your user okay I think there is an issue for that it's open so everyone is pretty welcome to contribute I think there is not much contribution on that that so that would be my answer thanks okay any more questions one over there hey uh what would you say is the main impact of the adoption of private kids for everyone in Mexico I mean not everyone but so many people yeah I guess the main impact is for tax purposes is is that's what it's used for and that's why people don't really like them right but basically you can use it for uh legal documents and there is some regulation that specifies how to transfer digital assets I mean it's not called digital assets exactly there is like a some some sort of legal framework but basically you can put real world assets fully compliantly using this keys
