New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

You Have Nothing to Hide! - Vaclav Pavlin | Web3Privacy Now

Ethereum Cypherpunk CongressMon, Oct 7, 2024, 12:00 AM

Web3Privacy Now | Community 1st - Rome Takeover (5/10/23) - ETHRome 2023 You Have Nothing to Hide! Vaclav Pavlin: https://twitter.com/vpavlin | Core Contributor at Logos: https://logos.co/history, Waku: https://waku.org/, Status: https://status.im/ Web3privacy Now is a think-and-do tank made by individuals who care about digital privacy and individual rights. Its primary objective is to explore, spotlight, and evaluate privacy-centric goods and services within the web3 domain. Twitter: https://twitter.com/web3privacy Github: https://github.com/web3privacy/web3pr... Recordings powered by Logos: https://logos.co/history Filmed & Edited by BabyBit Production: https://twitter.com/BabyBitProd

Transcript

[Music] and VAV here represents the vaku messaging protocol and you will tell more about why it's really important these days and what specific role of waku plays within the Privacy landscape sounds good thank you very much mikola um I would like to First explain this uh vaku has not given me any t-shirt yet so I had to fix it it's a 3D printed vaku logo I love it um anyway my talk is about that you have nothing to hide and that it's okay to share everything with with the world uh we've already heard in previous presentations that that's the way to go and that hiding stuff from your government or anyone else is wrong um no obviously I'm just kidding um we have heard that privacy is your right and you should be able to do anything in private and we have heard about how you feel safe at home and how cyberspace does not really uh help us with that so I would like to talk about why and how we are all hiding something and uh why that's okay and how vaku that's kind of the tie back to um the project uh how vaku handles it my name is v p i work on vaku I'm cor contributor of logos and vaku and Status um just as an interaction but michad did that so I would like to start this with a tweet uh it's actually from Ministry of interior uh vdra kushan Ministry of interior of Czech Republic uh so he oversees police and all these investigation bodies uh that will care about you not being so private uh and he tweeted recently that a phone with encrypted communication have doesn't make you a mafioso uh or a criminal um uh but your connections and action make you MAFO which is great to hear from a representative of government right uh although um I don't know for sure but I believe he only tweeted that because he's connected to some crime that he's trying to cover and someone used an encrypted communication app through that so he's trying to like explain it's okay sometimes but what I want to point out is the replies uh to the tweet and they I have to admit um I I have I'm be with regards to privacy and I've been like these people uh an ordinary person who does not care about his privacy and about privacy of others really um but I'm I'm working on that um so the first tweet says normal and decent person does not need encryption you can say what you want but it's just a theater decent person does not have a need for encryption obviously your intentions are not clear and the last one is a bit longer but basically it says once more please why do you need an application for encrypted communication that the organizations that investigate all these things that you lead cannot then investigate because you have encrypt communication so there was a lot of retweets uh sorry replies like that uh but there was one that stood out that actually um pushed further with my with my story um from bedar it it linked to this analysis of Czech National cyber and information security agency I believe it's something like us CIA but probably way better um sorry guys if you're watching um and uh and they put out an analysis of communication applications um it's in check so you won't be probably able to read it unless you translate it but uh it's okay there is some there are some details of of those applications but um I basically just wanted to highlight this uh table or sheet um we've heard in one of the previous slides that the the big entities do not really care about the data you actually send because they are encrypted and it's possible but maybe hard to decrypt they care about metadata um and I wanted to show this here that basically if you look that there is a there is a a comparison of like who has ENT encryption for DMS who has ENT encryption for group messaging um so yeah I guess don't use Facebook or Google I don't know um and then this is important who doesn't require any personal identification like email or phone number like everyone does right so there the problem with communication these days and and this is chat applications but it generally works the way the same way for anything else where you send some information and we've heard from Hopper um how they are solving it um that that you need you are leaking your private personal information whenever you communicate regardless of whether it's chat application or whether it's calling some apis or calling something else sending emails right so we all have something to hide um like me like I'm hiding from my loved one which is my wife who's my wife uh this she's here uh with me in Rome and she has a birthday in two days and I am hiding that I haven't planned anything for her um we are hiding for our enemies um so the enemy can be your competitor in the business and you're hiding your Trade Secrets or it can be an actual enemy where like if you leak your secrets they will kill you right and we are hiding from our governments which can be good or bad or for reasonable reasons or not I don't really care but there are governments which will prosecute you for nothing basically just because you are you um and that's it's perfectly okay that we hide something um we just need to make sure we here need to to make sure that people can hide things securely and and without having to reveal them if they don't want to um but there is the other case the other side of the story uh we are the good guys hopefully um but they are the the bad guys they whatever that means um and they are trying to prevent it right U they're trying to make us less private and this is for example link to a regulation put out by EU they are still it's not in place but they are pushing it hard is for child sexual abuse regulation so they want to prevent child sexual abuse online which is a great idea I really think that children should be um safe online but the thing is EU wants to surveil internet to Pro protect children so they want to see our communication and and all the like everything that's encrypted now what you're sending what your uh what your chats are to protect children great but then everybody who is an expert in this so protecting children and internet says it won't work so obviously if you are sending um some malicious pictures of uh of a child sexual abuse they may not be able to decrypt it unless they are CIA right so like if you encrypt it on your local machine that they can't get the hands on then they won't be able to see it on the servers um so it won't work from the technical perspective and this is just one example but then also it won't work from the apparently it won't work from the from the uh perspective of protection because it's dangerous for children if they can't be anonymous and private online um if if there is some chance of discrimination in real life the online cyberspace is maybe the only Escape that they have because they can be private and anyo there um and everyone is trying to kind of voice their opin opion against this but EU still pushes the law in other words that sounds to me that they are trying to convey that privacy is dangerous from children's age up interestingly enough um my friend just shared this um there is a UK bill that basically says trying is trying to push the same and the response in UK from all the experts is generally the same so there's probably something wrong with these bills uh and regulations I'm not a legal expert so I can't really comment that but there is something weird happening um now back to the Privacy from the technical perspective and we have heard that this is why this talk is hard for me because everyone talked about all these things already um privacy is not just an encryption right and we have heard that again from the hopper talk ENT encryption prevents them from accessing the content but that's just one part of the story there there are other parts linkability is another keyword it represents matching sender and recipient and uh we can imagine that if you interact with someone who is later maybe connected to someone else who is who has done something bad then you may be persecuted for that because you have ever had a connection to them and with internet you get in touch with many many people so you cannot you can never be sure so being able to prevent that linkability is very important from for privacy anonymity then ensures that users are indistinguishable in a set so if I go into a group chat or something I don't want to be identified by my phone number or my IP address or something I I if I want to be anonymous right I need to be make sure that all the users are equal and are the same it's like the yellow cars in the Rome I really like that anology and then ownership helps to keep control of your private data if you if you can own the data which is a problem with web to world if you can own the data uh own your data then it's it's way easier to keep them private so now we are coming back to this uh vaku so just briefly what is vaku um vaku is a privacy preserving decentralized modular mod modular Network for generalized messaging what does that mean our core main focus is is privacy preservation um is the centralizes built on top of L peer-to-peer and uses all the fancy protocols that Li peerto beer and uh add-ons offer it's modular we want to make sure that you can not only run it on a b machine like a laptop or I don't know dep note but also you can use it from your phone or your Raspberry Pi or something like that that has that does not have that compute power and bandwidth which is often a problem with the centralized uh software and then it's for generalized messaging so I've been talking about chat applications a lot and that always comes up as a great use case for vaku like hey let's build a chat so there is one project that is using vaku under the hood called status um they're also paying us um who uses vaku as a as a underlying infra infr layer for their chat application but it's not just that you want to be it it should it is it is for generalized messaging so rail gun is using vaku for their PR layers xmt which is another a chat application but it's using waku under the hood um and then the graph is using waku somewhere in their stti and I always forget where I think there is like validators of their decentralized indexing Network which synchronize over vaku but I don't want to lie about that if there is someone from graph here maybe they can explain so from vacu and private perspective I have this disclaimer here um we are talking about base layer waku that's what I'm talking about it's the base layer it's like the layer zero I'm stealing from the Hooper talk um you still need to be very careful about which application you use even if it's built on top of vaku because the application can leak a lot of information and they can send anything over vaku including your email including your phone number and including your IP address so like we can't control that so you need to be very Vigilant and I think mola talked about the L2 bead for privacy project and things like that and those are the things that will help uh users to figure out how to use privacy focused projects without revealing information about yourself so vaku is a base layer we do not care about anything about you but anyone at the layer can potentially so first of all um we talked about the ENT encryption that it prevents from someone reading the content so vaku itself does not encrypt anything because it's up to you to figure out if you need encryption and what kind of encryption but it helps you there are protocols and solutions and tools and sdks on top of vaku um like noise protocol which allows you to encrypt easily and use sdks and tools to do the encryption properly with your messages then linkability so for us we say unlinkability because we want to prevent linkability um this is the vaku message this is the message that is sent over vaku from every node there is nothing that would link you from the send as a sender to the recipient or the way or the other way it's a gossip Network so you send a message and it travels through the network it reaches all the nodes hopefully in the network and then whoever understands the message and knows what to do with that will take it and do something about it so there is payload which is the main chunk um what you want to send then content topic for for the filtering of messages because you may not be interested in everything in the network and then version time stamp and whether it's FML are basically all optional and and uh do not really help anyone to figure out who you are or link you anywhere um anonymity um you need to make sure that every single message on the vaku subtopic is like two piece in the part I is it not funny sorry um so again similar to this the messages are all looking the same the only change is then the contents toic and the maybe the length of the payload um but they they look the same and all the users look the same because they are just basically relaters they are sending messages and whatever the message whether the message is is coming from them or whether that message is coming from someone else and they are just relaying it nobody really can figure it out um there is one part of privacy that is important because if you can spend the network you can find some hot spots and you can you can potentially exclude people and that can be also uh deemed as a privacy uh problem so there is a spam spam protection and uh someone said that I should Prov simplify this I wanted to have this here this diagram it looks very complicated and it is very complicated uh it's it's based on zero knowledge proofs uh there is blockchain involved and and me and membership contracts and things like that um so basically what it means um rln rate limiting modifiers is a p protection in privacy present manner so you attach a zero knowledge proof to your message basically saying I am part of a membership set that that can send messages and I can send messages in this rate into the network and I'm doing that and then if multiple people catches or if someone catches multiple messages above that rate they can guess your secret which is kind of leads to that membership contract and if there is a stake or if there is a um if there is some identity behind that they can either take the stake slash it or or they can they can um reveal your identity depending on the implementation so here right now we just have that you're are part of the membership set and we can leak your secret whatever that secret is um but uh in the future there will be some Financial probably um Financial stake that that can be taken by someone catching you cheating the spam protection and then the data ownership um vaku does not own any of your data we do not store your data because we cannot link the data to you so there is only thing is the vaku store protocol which allows you to um which allows you to query old messages on a particular content topic so if there is if if there is a Content topic you care about and your node has been disconnected you can query the uh store node and it will uh give you some messages that have been sent or received between your connections um but that's all and there is no again there is no linkability the the messages are all the same uh from the perspective of the receiver or the person querying um if the well I'll definitely publish the slides um I don't know if you noticed there are always links to some rfc's we we tend to do things in a way that we first come up with an RFC we discuss that we make sure that everything is kind of um in order and then we implement it so I have I have provided links to various rfcs in the slides so I'll I'll publish the slides uh after the talk well that's it um so my main point here is that privacy is not just encryption we've heard that before uh offchain privacy which vaku is is very important we've heard that before um and uh you should not use Telegram and we we have heard that before so I'm basically just saying nothing new uh also waku is great uh you should join us somewhere um a website a Twitter Discord yeah I know we use Discord which is a centralized um solution but we will eventually migrate to status for the community um yeah so that's that and then if you have questions which I have no clue if I have time for questions but nobody had so I'm assuming I don't either um you can scan the QR code um there is a Q&A thingy behind it it's decentralized on top of vaku I build it um you can ask questions if you want to and yeah most of the pictures came from mid journey and this one was very disturbing so I put it at the end as a last slide uh just for you to enjoy um so thank you very much and enjoy the rest of the event and E Rome if you're [Applause] [Music] going

Automatic transcript — names and jargon may be misspelled.