Frontiers in Privacy and Usability | Panel | ETHDam 2024
CryptoCanal·Mon, Oct 7, 2024, 12:00 AM
Join Harry Roberts - Oasis, Captain McAteer - Firn and Mihai Scarlat - Ocean for a panel discussion moderated by Matej Janez from Oasis Network at ETHDam 2024. https://twitter.com/captainmcateer https://twitter.com/mihai_mas MC of ETHDam, data aficionado and your favourite wooden bowtie - Jonathan Knegtel. https://twitter.com/jpknegtel ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz We would like to thank our partners that made this event possible. 🌷 Battleship Partner 🛳Oasis Network https://oasisprotocol.org/ Jet Ski Partner 🛩⛷ NEAR https://near.org/ Canoe Partners 🛶WAKU https://waku.org/ 🛶Trail of Bits https://www.trailofbits.com/ 🛶Avalanche https://www.avax.network/ 🛶Privacy + Scaling Explorations https://pse.dev/en 🛶Threshold https://threshold.network/ Our Canoe Partner & Official Node Provider 🛶dRPC https://drpc.org/ Sponsor 🤝EF Ecosystem Support Program https://esp.ethereum.foundation/ Paddle Partners 🚣ChainSecurity https://chainsecurity.com/ 🚣Lido https://lido.fi/ 🚣Cyber Capital https://www.cyber.capital/ 🚣Diva https://www.divastaking.net/ 🚣Firn Protocol https://firn.cash/ 🚣Beefy https://beefy.com/ 🚣0xbow https://www.0xbow.io/ 🚣Obscura https://obscura.build/ 🚣Panther https://www.pantherprotocol.io/ 🚣Maven 11 https://www.maven11.com/ 🚣Zama https://www.zama.ai/ 🚣zkSync https://zksync.io/ 🚣Secret Network https://scrt.network/ ETHDam AfterParty Fren 🥳Bitvavo https://bitvavo.com/en Chapters: 00:00:00 - Panel Introduction 00:02:24 - The Importance and Challenges of Privacy Adoption in Crypto 00:04:32 - Demand for Privacy Solutions in Various Applications 00:06:59 - Starting with Payment as the First Use Case 00:09:22 - Breaking Through the Barrier of Privacy 00:11:48 - The Complications of Compliance 00:13:54 - Compliance Measures for Crypto Projects 00:16:10 - Decentralized AI and Privacy 00:18:35 - Privacy and Openness in AI Models 00:20:40 - Private and Public AI Models 00:25:12 - Confidential AI and Privacy in Payments 00:27:34 - Enhancing Privacy Coin Interoperability 00:29:52 - Facilitating Use with Privacy 00:34:26 - Excluding Accounts for Compliance and Privacy
Transcript
[Music] so um I'd like to invite to the stage uh another person from Oasis which is I didn't get managed to say his name so you're going to shout it now m m welcome and um we're going to have a panel about the Frontiers and privacy and usability I'm going to let you invite the other members yeah we get I'll get you them in a second Starling could you grab the mics and the last thing that I have to say is um don't forget that there is the slido and um so during this panel please ask the questions about the uh about stuff that you're interested in and then at the end uh we'll have the opportunity to answer them thank you thank you very much JJ I think yeah everybody can hear me well hi everyone pleasure to be here and I think we have an exciting uh uh panel guest here as well uh so we're just going to kick it off uh the kind of the team is uh from tears in privacy uh and usability so we're going to speak going to be speaking about that but before we dive in uh a short round of introductions so I'm mate I'm the be manager at Oasis uh but I'm going to let them speak more I think they have more interesting stuff to to say say about them so mi you can start and then we go down the line okay thank you uh my name is Mii I'm um working on the product side at Ocean protocol uh at my core I'm a developer so not that uh fond or uh familiar with panels presentations and so on so forth um I think that's it hello I'm the creator of a fern protocol known online as Captain mcateer and uh glad to be here and I'm Harry and I've uh got lots of thoughts on well why are we doing this and I I hope I'm I'm in the the right place in terms of the reasons why so uh yeah yeah here here here you're all about the ideological aspects of privacy and and why why it's needed and I like this I like this I like a lot so maybe we can just jump in and and ask the question you know why is privacy important um and also at the same time it's very hard to get adoption for it right so we I think there's the the crowd is getting bigger and bigger we having I think this event uh is becoming bigger and bigger as well so there is more interest in privacy but if you look at the larger let's say just crypto ecosystem right uh there's still not that much uh you know interest in it uh I can speak for myself I'm BD right so I'm I'm talking to part projects uh and trying to to convince them you know that privacy is needed for the users you know uh uh to to make it to make it more let's say um to make them more more self-aware self Sovereign in terms of their data but yeah can you maybe uh share maybe har I can start with you why why do you think you know I think you spoke about why it's important why why is it so hard to get it uh into uh into more mainstream option in crypto uh yeah so I I don't know one of the problems is it is really difficult to use like if you deep into the cryptography if you're uh used to doing encryption everywhere if you're used to thinking that way then it sort of comes naturally to jump through all these different Hoops to do something that you know is secure and it's almost like you to do it any other way would be doing it the wrong way you know it's like you have to strive to do something and uh the problem is that everybody just follows down the easy path you know so it's like you have to deliberately go out of your way to do all of this to begin with and I think that's until it's the default for everybody which it is on on cellones in most cases until we have this that's just there and you don't have to think about it then you always have to make a decision and everybody goes is it a little bit more inconvenient for me yes therefore I won't do it so you think it's going to be more on the developers side integrating it than users actually starting demanding it maybe uh Captain I I I'd hope so maybe yeah so you know I'll I'll I'll gently push back on on the idea that it's hard to get users you know I think there have been a couple breakthrough cases like tornado cache for example which had massive massive amount of users and what that shows is that if you can just kind of puncture through a certain UI barrier then everything changes right do you agree um and I remember when I remember when tornado cach first appeared on the scene and it was really stunning right because actually compared to what other projects had attempted it was simpler more simple more basic right fixed amounts right nobody had had even tried this fixed amounts only deposit and withdraw no transfers or anything and yet they won how did they do it well when I went to their website I I could just sense that this was a new caliber of of graphic design UI UI design just the the JavaScript was so good that um it was unlike anything that had come before it and um I think there is a lot to learn uh from that example and maybe over time I I can say what that is but in short the demand is there the users are there um I think it's on us to build the stuff they want to use and um yeah but is that maybe on the so you mentioned tornado cach R that's a very specific use case right and of course then the uiux can also be very simple right um but looking more broadly let's say you know um us at ois we're looking about you know many applications you know many application vertical that need privacy from voting you know potentially confidential private trading how to add privacy into those products right because I guess the demand isn't there yet for those types of um solutions to have the same amount of privacy as let's say tornado cach has right so with tornado cach I guess we had like a very specific case right but how to apply it to a more General um landscape of DS right yeah I mean look like first of all payment it may be one use case but it's a very important one maybe the most important single use case I mean think about Bitcoin becoming massive and existing for years before ethereum existed and all you can do with Bitcoin is send it around right um so let's not discount that use case as probably the one that we should solve first um you know it's kind of like a walk before you run kind of thing right I I think there's a case you know we shouldn't ignore the other stuff but let's um start small do it really well and start to make a difference there and then maybe think about the other stuff that's my personal philosophy I mean I I'm a bit pragmatic in this kind of area where I want to build something that we can build today that's going to be a joy to use and that's going to convert users and um I think payment is a is a perfectly good place to start for that yeah Fern is working on that right so this is your your core product yeah yeah that's good to hear maybe Miki you can share a little bit more about how you came about you know Oasis Sapphire and and your privacy needs and Implement in adding it to a to a different type of application yeah so uh I mostly agree with what my colleague said I don't think we have this Mass adoption yet because from my point of view the ux is not yet there and uh unfortunately people want apps that are easy to use little friction as possible and even if they sort of understand that they need privacy because in various aspects of our life we kind of miss it for example if your phone leaks or email leaks then you get I don't know how many spams voice calls with Spam with anything so even that's like a super basic imagine if you could do that in in A Private Matter right it's super simple but we don't really have that right and I think once the technology gets to that point where the user doesn't even know that they have this feature we still have a bit of a way to go and we need to work hard to go get there going back to the question that you asked how we got to Oasis well simple after multiple text bikes and researches we realized that your technology was easy to implement and it was transparent for the end user it just brought us the features without the user actually knowing or having an extra layer of friction so uh and for you for you as I understood it was crucial to have that privacy on chain right so to to keep the decentralized nature of it because sure we could have made it the centralized but then we wouldn't have brought anything new and new to the market yeah for sure so going off of what you said um we have specific use cases as let's say Fern where uh there is let's say demand and you can go off user demand but I guess to uh simplify the experience for the end users in a broad Mark more broad category right there uh I guess there's still U the barrier where we need to break through is with the devs right so we need to make it simple enough for the devs to implement it in a way that um that it can be the same ux for the US user while they're keeping their privacy right so um because one of one of the topics I want to touch on was exactly that so what basically what's the main block right is it the devs is it the user demands user demand is the tech what you guys say is it the text's not there the developers are not caring about it the users are not caring about it what's what's the key one blocker anybody hear you you I I I'd possibly say that a lot of people could go and do this right uh but they don't because they're like self censoring what they're going to develop or uh like think if you want to make the simplest private wallet ever you don't need to record any history so if you add history that's another feature that you have to develop then you have to decide well how do I sync the history how do I do I have to add a compliance tool do I have to kyi users and sometimes if you're looking at like the the simplest thing just don't do all of this extra stuff and that just complicates it massively but people feel they're obliged to do all of this extra stuff and you know compliance is one of those or am I allowed to open source this am I allowed to run it on Main net do we have to set up a dow it turns it from being a really simple very like uh straightforward application it being something that you're having like existential moral dilemmas about you know like am I now on a list because I've developed this and instead of like let's just do it you know it's uh let's look at these super simple uh little tools that we can make that we can build stuff out of without having to think or overthink these things may maybe when you touch on compliance maybe Captain you can share here uh do you do you think crypto projects should be very concerned about being compliant in any aspects or if you are compliant with everything are you actually building something new how are you looking at this cuz you're handling uh you're more in the payments uh side oh sorry I love the question for you there yeah you know not not the the most Pleasant thing to talk about but you know first of all um Fern we we at Fern are are very principled and and value privacy in itself um there may be a world down the line um if if we get big enough where we have to start looking at this and you know I I I guess I don't really want North Korea to use Fern I I don't know I I I don't know if I want to take a position really on that but um guess I'm not wild about it um regarding compliance I mean I will say one thing which is that there are kind of various approaches one which has um got some traction is this kind of proof of Innocence thing I'm I'm sort of against this for the very practical reason that um it unreasonably puts the burden on on the user to specify which you know accounts are um are are going to be dissociated I don't think that's really realistic um so maybe there's something where that would be baked in or or sort of come for free or something like that but I I I don't really want to take a stance on what Fern would do right now well I'll come go out and say it right now we we don't have uh compliance measures so um don't misuse Fern um but um yeah I I don't know what to say no no I it's it's not in relation to firm you can speak more broadly in terms of um should like crypto projects you know be too concerned about this uh I know it's at some level when you grow you know you get you potentially can get contacted by certain agencies right but um if you're trying to be compliant in every aspect or is is there is the protocol then any different than anything that's already out there in let's say more traditional space right um well yeah I think even if even if you did Implement some kind of compliance it would still be better than say using an exchange to store your funds or um or even just standard checking account I mean there will there will still be differences in that case obviously they're you know it's not the same as having no compliance at all but you know there always going to be great as with this kind of thing right yeah I didn't mean to put you on the spot with for it was just more like a broader question yeah um one thing I wanted to touch on um since you know we have here ocean as well uh that just joined the ASI Alliance uh and AI is becoming a big thing right and um big Tech right it's kind of owning the market now right now in AI um and if we want to kind of merge crypto an AI right and we definitely I think we kind of need some privacy there as well right if you want like a true decentralized AI um maybe Mi you can share there you know how you see um the future of these decentral AI um come about you know if we want to have like truly decentralized trustless you know AI uh that can handle you know private data um in this matter yes uh honestly I think we have U some road until we get there uh regarding uh ASI I can't really talk in everybody's name for now I can just tell you that from Ocean's perspective we constantly have been uh focusing on privacy uh the example working with you guys uh our c2d component that is our tagline privacy preserving compute so it's in the name um and actually this year we are focusing the second version of c2d is actually focusing on bringing actual machine learning models and the more complex algorithms with privacy so we do actually strive to get there so this is going to be one of the major components if we want to from Ocean's perspective yes we are definitely focusing on this any thoughts from you guys on on AI coming into the space uh here yeah I I I want like it's almost there like full confidential AI is almost there but I I'm not sure I necessarily want a lot of this so one of the big problems is like uh when's the GPT model going to leak you know when can I run this on my own Hardware if they lock it forever in this like confidential Enclave that we can never get this even though my data is safe when I'm uh you know giving it to them which at the moment it's not you know uh they say they don't log it if you have the the team's account but I don't trust them because you can't verify the infrastructure right um yeah what if the the bad side is what if this Tech gets locked out of the public domain forever you know and so uh I'm not sure that's a a a response to that really but that's the the question can kind of answer to you uh in the initial thoughts designs we're not trying to keep the actual model private but the creation of the model so all the data collection the training that is the focus so that should be private and this way you can have you can train more models in easier but the actual model then that doesn't necessarily need to be private that makes sense so basically you can use data from everybody that data is private and you have a model that everybody can benefit at the end of the day that model can be open source or will it be open source though like if you know it's if we're trying to do privacy for the right reasons and you have to take a stand and you have to um do it uh completely private or as private as you possibly can then surely we should also have a stand with AI as well and say the models must be open just as you know encryption must not have a back door is that equivalent for AI honestly I think uh while in the previous year or years AI has blown a lot I think we're are still learning a lot and this scene is evolving constantly and honestly you might be perfectly right but depending on how these models evolve maybe we want to keep them private honestly I do not have a definitive answer for that yeah that would be my question cuz if all the models are transparent like if you're building out a company and your Competitive Edge is the model itself like uh but you still want to okay then maybe it's not fully decentralized but you still want to train it on data you know that's out there that uh users can selectively disclose with your model right I guess there are some cases where you potentially want that model to be private right oh yeah like like my Diaries I don't want the model of my Diaries to be out there although if you want to buy it in you made a model sorry you made a model of your Diaries no you can do your your model the model of your Diaries or your Diaries I I both you know I I don't want you to be able to say what was Harry's Thursday like and it gives you an imaginary Thursday in the life of Harry right um but at the end of the day it wouldn't be about options why not have the option of both so for example that model can be private you can own it host it whatever only you have access to it or you can have other models that everybody can benefit and they are decentralized crowdsource for [Music] example yeah that makes sense yeah yeah I mean I see I see it from the let's say uh crypto is very focused on trading right defi is still one the the main use cases probably where the majority of the the funds uh you know get the majority of volume comes right then with predictor you you see that as well right so there are I guess a lot of use case where you can have you know certain models you know that you that are profitable for you that you potentially would want to share with with someone uh to be able to so they able to purchase it right um but if you share it what the model is then you're you lose your Edge right so in that sense that way your model should stay private but at the same time they can verify the let's say the how Prof itable with is and and gain from it right so I guess uh there is a little bit of a spectrum here what what should be public what should be uh PRI in terms terms of AI models as well I'm not sure how we're doing on time uh question okay okay then we need to go to closing thought than yeah I I didn't see any any time here yeah so uh I guess three minutes yeah uh thank thanks for the uh touch on AI uh any last thoughts on you know what what do you think privacy will be in next let's say six months to a year and then what's kind of the fiveyear goal maybe anything like that or any last comment just on on a personal level we can start with you Harry and go back I I I I do think that um uh whenever you end whenever you end up with like privacy alliances or people coming together or you know you ask for legal advice on this stuff it always ends up going towards like the the conservative let's better be careful and it's almost like to to do what you know must be correct you you have to be very focused and you can't get sucked into this compromise sort of situation and I think that that applies to lots and lots of different things and um yeah the problem is uh is doing it is it takes uh it takes effort in its own right to say I'm going to do it this way uh rather than doing it the way everybody else is so uh do it and ask questions later something like that sorry do it now and ask questions later yeah yeah definely Captain yeah so you know I'm a pretty downto earth guy I I I I think the right way to see this is to just build things that are real that are practical um make incremental steps always meet the users where they are um and build great products so that that's my philosophy that that that's what we've done with with Fern um and you know this is something that I guess we can improve by daily work and stepbystep improvements and um that should bring us to a more mainstream adoption of the yeah I I think so um yeah yeah thanks thanks Mii I think its adoption is inevitable because there are a lot of eyes on it a lot more developers that are actually focusing on it and sooner will or later we'll just be there it's just going to be in the apps you're not going to even think about it it's just going to be there period like multiple other technologies that you're just using them without even knowing you know but you're not conscious conscient is conscience about I guess that's it uh let's see what slido says on this come up oh we have a few questions first one do you have already successfully trained larger aiide rafle with ah this is for Oasis har I think we can both say no to this one uh yes this is definitely in the works at the moment uh we do have uh some interesting ways of tackling like confidential AI um but I do think it takes a bit of time to get it right and to to roll this out to people so we're looking at it but not now is is the the answer I guess is privacy in payments unresolved Captain I'll go on a limb and say no it is resolved uh you can go to fern. and uh see for yourself loving it uh how how is how is it differs from Secret Network different network yes but something else we do evm simple as that uh next one more about the partnership with RI chain uh I think it's better if you read up on the blog post there uh than I if I go into details here on the stage um next one agencies and Regulators are looking for Meaningful control through compliance or just paper compliance to their arbitrary rules h i I I'm a I'm a glad mathematician and cryptographer not a lawyer or regulator so um I I'll just happily defer thank you K do you think there's a world where privacy will have as easy of ux as non privacy apps I think we answered that that yeah there's a little bit work to be done on that side but we're going towards that that it would be seamless for the users uh and the devs as well so ux and devx are very important I think the most important question question just popped up now where can I use the model for Harry's diary I'm not sure but if you are a GPT employee and you have access to a torrrent client there are lots of beautiful things you can do with that combination and the last one what's the one thing we should do better cooperate across the Privacy space I think conferences like this are uh great for collaboration where I think the Privacy um privacy aligned projects can meet up can share thoughts you know and and push this space forward I took the liberty of answering that so yeah I I might add you got minutes so you I I I'll add I'll add one more thing though which is uh there's lots of different privacy projects and and all of them have uh uh the different strengths and weaknesses and uh one of the big problems is that there isn't much liquidity between the these privacy coins so um I think if there's one thing that we can do is to make it possible to send coins privacy coins from one chain to another uh without ever having to get out of the Privacy coin send it over a bridge put it back into another privacy coin that if we can find ways of like being more interoperable or doing swaps or something like that then that's better for the the entire anonymity pool and it's better as a for all of the the coins rather than you know these little niches here and there and that's one of the the big problems I've seen is you know if you're trying to use this on a day-to-day BAS basis uh we need in uh intense solving for privacy or something like that of you know just uh give here's all my money make it private and then do stuff with the private money and it will be able to do it much better than I can clicking buttons yeah I mean just to continue the Practical bent here right so Fern is on ethereum um it's also on a couple ethereum L2 so if you have eth okay that many people do um then it's kind of right there you don't need to change chains or anything like that um you know back back to the case study of tornado you know I think that's one reason they were so wildly successful was that uh the idea of of sort of plugging um privacy into eth was totally new right there there was zcash and Monero and and these Standalone coins which were extremely hard to acquire you had to go through some you know non- us exchange and things like that to even get Monero um and all of a sudden there was a way to take eth just any old eth and um get privacy with it um that I think was a was a was a massive change in ease of use and sort of uh utility right because now um you know exchanges can delist Monero but they can't just delist e right I mean I guess they can try to put you on a list or something like that but um that to me is a major facilitator for for use I I'd say like getting cut off from an exchange for using zcash for the sole reason that exists was like a point of frustration for me like well why is it even listed on there if you don't allow me to Tink with z and shielded transactions it's you know but at least with uh on chain there's no way of censoring or they you can censor that if you end up with too many nodes in the wrong country right so maybe we need to look at more resilience and anti that's kind of my point right is that like if your privacy deals with ether and not with some other coin then that completely shuts off a vector for exchanges to obstruct access right but but they still know you're using a privacy system you know they know that oh this money came out they you have the dirty eer you know that that I think that was the case with actually with tornado cash as well right uh where um um basically chainalysis you know and and the likes can flag you know how how tainted your Bitcoin or your eth is right and that can be problematic as well from a centralized exchange point of view I I guess fair enough but at least you can acquire it in the first place right and if if we both have eth already right then we can use Fern to pay each other versus um if we don't have right if if our only option is to pay in Monero and then we have to get Monero somehow right but yeah point taken that I guess if you try to go back to the exchange then maybe there will be trouble there yeah then you're on the let's check your funds scream for a little bit no um but good point good point um so basically wrapping the existing um assets that are transparent uh in a private manner but um I think what the point that Harry wanted to make was when we were speaking to a project that was dealing with uh you know crypto invoicing you know and uh how to do private payments there right private invoices it was they needed to move the whole thing to safire in order to have that privacy right because you can't just uh you know have the payment be routed through there because you can obviously see then you know going in I guess you could have a pay with fun button and it just auto raps your your Stu you don't have to go in and out to use Fern to pay you can transfer between uh Fern users so yeah something like that okay okay we ar enough or yeah yeah you're done great we have a couple of questions on so like a couple what does it mean by is it killed by governor uh I I do kind of get the sentiment there of of like at some point somebody stands up and tries to be the sensible person in the room and says like H maybe we should do governance um and I I think like I'm not sure if it mean governance or government yeah is it governance or governments could be L translation doing the uh Infamous duck in cover uh back in days right I don't see that work when like the last yeah they're all up [Music] there yeah that's why it's open source right and when so yeah we I don't know how do we uh do we need like the the sacrificial person the the hobo off the street that just happens to release all my software you know it would be nice if I could if I could see these questions without doing this but um so the second one yeah what does fern do different from tornado cache I mean is that in terms of the cryptography which haven't talked about but is interesting or the features or are is this a compliance specific question I guess maybe the person doesn't want to De anonymize themselves um many things um but regarding yeah meaning the features no ending up where torado cash ended up oh well I I didn't expect so many regulatory questions but um you know yeah yeah yeah see you in a year um no but like first of all if if we get you know if we get big enough that this becomes a risk then I'll find some very smart uh legal Minds to maybe advise me um but there are there are some proof of Innocence like things we can do actually we have uh Amin here um you know Fern Fern in principle could do something like this but actually arguably more in a bit more native way I think you know Fern transactions sort of contain ring signatures so what you can do is sort of exclude um at the protocol level some or at the client level right so I can tell my client to only sample rings that don't contain those accounts or um you know maybe we or somebody marks certain accounts as being sort of off limits to any ring um I guess the benefit of doing this is that um instead of presenting a separate cryptographic proof of Innocence I can just point on chain and say look my ring didn't intersect that thing so um the proof of innocence is kind of baked in in a in a native way um this is a a nice feature that could um in principle be done we don't do this now um but um that is at least in the you know in the deck of cards that we could play so I just need to dust all the accounts to keep everything fair and on the level to prevent the compliance from working well okay so if we call unfortunately we're running out of times I can't go too in depth but it just got spicy no but um yeah I just wanted to add I think yeah I think the questions around compliance maybe uh you know people are wondering because they want to use it and just want to make sure it's good um we look I love privacy I love Liberty I also want to be a positive force in the world not a negative one so you know I I guess I would prefer it if Fern if if there were some way to make fern only be used for good um obviously determining which is which is is is a weighty question uh but uh look um I I my my specialty is cryptography not uh not legal so um that that that was that was that was all we needed thank you thank you Captain thank you everyone uh for joining here thank you guys for listening in [Music]
Automatic transcript — names and jargon may be misspelled.