# The Next Wave of Privacy Products | Alan Scott and John Meurer Jr. | RAILGUN | ETHDam 2023

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2023-10-07
- Duration: 17:59
- Watch: https://streameth.org/watch/yt-PCin1sH9wiQ
- YouTube: https://www.youtube.com/watch?v=PCin1sH9wiQ

## Description

More about RAILGUN 🔫
railgun.org (Info site)
railway.xyz (Partner wallet)
@railgun_project (Twitter)

🔫 Alan Scott is a co-founder of RAILGUN DAO
https://twitter.com/tsu_kareta

🔫 John Meurer Jr. is a co-founder of RAILGUN DAO
https://twitter.com/therealjmj


ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. 

Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants.

ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: 

CryptoCanal https://www.cryptocanal.org/
CryptoCanal Twitter https://twitter.com/CryptoCanal
Join CryptoCanal Community https://t.me/CryptoCanalCommunity 

We would like to thank our partners and sponsors that made this event possible. 🌷
Our BFF 1inch https://1inch.io/

Our Frens: 
Sismo https://www.sismo.io/
Aleph Zero https://alephzero.org/
Scroll https://scroll.io/
RAILGUN https://railgun.org/#/

And our Sisters:
oasis.app https://oasis.app/#earn
Maven11 https://www.maven11.com/
bitvavo https://bitvavo.com/en
Lido https://lido.fi/
Spankchain https://spankchain.com/
API3 https://api3.org/
Gelato https://www.gelato.network/
VanEck https://www.vaneck.com/nl/en/crypto-etn
Marlin Protocol https://www.marlin.org/
Silent Protocol https://www.silentprotocol.org/
Cyber Capital https://cyber.capital/
… and Proto https://twitter.com/protolambda 🍍

## Transcript

foreign now it's time for our last keynote of the day um I hope they're here um I'd like to welcome Alan and John to the stage to talk about the next wave of privacy products after this we'll have some short remarks from Eleanor the uh the founder of Ethan and then you you'll be able to enjoy some alcoholic beverages I believe so woo for that my new one I said Can someone grab him yeah what are you looking for maybe we can get it delivered I can wait all right yeah you can use the one that's on there or you can use that one check one two super all right hold this down just talk okay sick thanks Eleanor all right yeah um yeah thanks for having us and um big shout out to the people who are running youthamp this has been really fun so far and uh also thanks to all the hackers who've been asking us all these really great questions about what we're building um it's been really really fun um but we're gonna be talking about the next wave of privacy products I of course am Alan one of the co-founders my name is John and uh yeah we're working on a protocol called railgun which is effectively a suite of smart contracts that live all on chain uh it acts like a private wallet and you can take and transact from this private wallet however you would like whether it be sending tokens to people speculating on nfts swapping yield farming flash loans uh the list goes on you can do a lot of really cool stuff yeah and then we deployed it just about a year ago on ethereum polygon Finance smart chain arbitrim more recently and they've seen collectively about 300 million in volume in the last year uh our first year so kicking it off I come from the web 2 space where there's a host of data privacy issues like as it as it even stands today um you know we think about vulnerabilities uh you know how some of these things translate to web3 we have to think about vulnerabilities not only at the Smart contract layer but also the full stack right you could have privacy vulnerabilities on the client interfaces the web and mobile apps that people use these products on uh you know and it's things as as simple as like when they're connecting to different rpcs those rpcs can track IP addresses so you have to proxy those through your own services to make them sort of VPN friendly uh you know if they're pulling data from apis coin gecko or other things for pricing that's another privacy leakage issue right you're requesting data that can be associated with your address certain tokens that only certain people have Etc yeah so in other words like uh the the big consideration that a lot of people have when it comes to Smart contracts like are fun say food but when you're thinking about privacy it's not just our fund safe but you know are they private and you know making sure that you're protecting against uh various vectors Beyond just what's on chain uh that could dox people and so yeah like a lot of these challenges you know definitely uh translate over to the uh the web uh web free space um I think one of the things that's really quite interesting is we talk about self-sovereignty uh in crypto a lot uh but what's really ironic about the fact that we talk about self-sovereignty is that we actually don't have like control over who has uh you know access to our data in other words there's no limitation to this on a lot of the public ledgers that we transact on um we transact on it it's recorded and it lives there in perpetuity and we have no ability to revoke or uh you know choose who gets to see this data right I mean this problem was solved a long time ago let's say in the web 2 space where if you work for a large company you have a certain role customer support sees different uh data than you know about customers than the admins versus uh business folks and so Access Control in a smart contract system on a public Ledger is somewhat non-existent and this is where privacy Solutions come in and can help to solve some of these issues yeah and I think too you know one of the things above and beyond that right has to be the um the data availability uh issue uh and serving that to you know client-side uh Solutions like railgun because there isn't any sort of like you know back-end services with railground there's not like a railgun server or something like this you're tapping into when you use the project uh it's all just uh client-side logic so what you're doing on your phone or a laptop is wholly included there and so getting data to those uh particular clients is definitely a challenge in itself yeah I mean we this is something we've focused on um over the last six months uh really honed in on uh data availability in a privacy system is a little bit different than kind of data availability when you can just look up a balance of a certain address you actually have to build a full like Merkle tree client side um if you're storing balances accumulating them through like a Merkle tree data structure you need to basically pull in download a whole bunch of data decrypt it all client-side and this is happening on a mobile phone for the most part uh so it's really kind of a challenge to make it optimized and friendly for for usage yeah and I think too you know just above and beyond that right you know um you know getting access to this data uh is certainly a challenge in its own right but one of the biggest problems that we face when we're developing these sort of things is the uh the on-chain costs associated with it right so we work really hard to make sure that there's no like extra validators or something like this when it comes to railgun so you don't have any like off-chain um uh sequencers or something like this you don't have to worry about there being a vector of of you know control in that regard but what comes uh at you know it comes at a cost right and it's computational costs and the storage cost associated with zero knowledge uh this uh Moon math is really magical and it allows us to do some really cool private stuff but it's certainly computationally intensive in fact you know one side of a railgun transaction can be in excess of a million gas and so this is uh certainly a challenge that we've been working on and uh has made some pretty exciting progress on it in fact yeah no doubt so when I talked about the last six months being about data availability in terms of the infrastructure layer the next six months is going to be about cost savings bringing this more in line with the public transfer right now as Alan mentioned a million gas for a private transfer on railgun that is as opposed to about 160 to 200 000 for uh um you know it's many times what a public transfer would be less than a hundred thousand gas and so we actually have a Model A new cryptographic model uh what's called kzg commitments uh something being worked on in the cryptographic community pretty heavily and this will bring the railgun transactions down by 5x we think it'll bring it down from a million to 200 000 gas to do a private transfer which obviously makes it more much more accessible for everyday users yeah kcg is really exciting because it's not only like computationally less intensive but it's also a lot cheaper to store so it's a double whammy savings so we're really excited about that um I don't think this is a talk for that we could certainly get in the weeds of it over some beers outside after this but um so if you want to talk more about that come find us and I think one of the last things that I think is really quite important when it comes to um well decentralized apps right is the the decentralization part of it right and so this is something that we focus on pretty heavily when it comes to um to railgun yeah I mean uh the anchain governance system for railgun is pretty exciting uh it in in some ways it's the first of its kind complete custom governance system uh for example we have governance on ethereum that actually controls the smart contracts that are launched on arbitrum and so uh rail uh holders are Governors on ethereum they hold and they vote with that token and that they can put up proposals the arbitrary system of governance actually watches for changes on ethereum and automatically updates the arbitrim system when it sees ethereum changing and this had never been deployed before we have some really uh awesome smart contract Engineers working on these hard problems yeah in other words there's no like trust me bro statements like a multi-state controlling part of it or something like this right um and I think that that's something that's certainly a challenge also you know sequencers and things like this and so these are you know certain things to be thinking about when you're building privacy protocols especially because centralized control can lead to pressure from uh people who want to apply it right and that brings to one of the probably um the biggest topics of the day uh talking about regulate uh regulatory concerns uh when it comes to building privacy products uh yeah I think this is one of the biggest challenges and I think um the last panel was actually really quite Illuminating uh to hear from these folks uh you know some of the things that we've thought about of course naturally like a lot of privacy Solutions out there are view keys and so this allows you to take and have that um you know view access that we're just talking about um I think it was on the first slide wasn't it and um I think this is um really cool because you can take and choose right you have self-soverty over your data which is really interesting and I think this is a very very important thing right so you can choose who has that kind of stuff or access to to see right and we um we do this in a really cool way right yeah viewing keys are sort of a separate key pair from you think of public private key for your public wallet for your private railgun wallet and many privacy protocols have a similar structure you have a spending keep pair and you have a viewing key pair you keep the spending key pair close to home don't share that with anybody because they'll have access to spend your spend your crypto not your keys not your crypto ring uh the view keys are read-only access so you could give this to an accountant or you could give it to um you know an auditor or a business manager or whatever to share your transaction history uh in in um in total sort of in perpetuity which which we'll get into uh because there are there are some problems with that structure but it is a way to have uh compliance in these encrypted systems yeah and so one of the tricks you just got into which is really true is that this view key is irrevocable right so once you've you know given access to people to view these uh you know you can't just take it back right because they have access to this viewing key right um and you know we're working on some things that are really interesting we'll talk about that in just a second but one of the things that I thought was really interesting too that we've worked on is the ability to take and have like tax compliance features within a private wallet infrastructure so I can actually take export my transactions anybody here use coinly other than me yes nice at least one person here right so I could take and export my transactions upload that to coinly and do my taxes with the tools that I'm used to and um you know I think this is really nice because it's something that's really familiar to people especially in the US it's really big I've learned very recently that the taxes here are a lot more favorable for crypto so maybe I'll migrate over here but uh suffice it to say it's a really cool feature but there's also something that I really thought was really interesting that we're working on uh with some folks out of turkey they're called chain way they've invented this thing called proof of Innocence tell us a little about that yeah so actually they had developed the first proof of innocent system for tornado cash that launched a few months ago I think to a bunch of news articles and and pretty good claim from the community we have given them a pretty sizable Grant to work on a recursive proof of Innocence that'll work on top of railgun private balances which are you it's a little more intense kind of ins and outs within the system because of peer-to-peer transfers that can happen privately inside of the system and so they're working on that we expect to see a kind of demo ready version in the next couple months and this fall to have a production version that's available for for people to use and so this is actually really exciting to someone like me because you don't have to give people view keys and we can also move away from like intermediaries that control like kyc and gatekeep the protocols and adjudicate who is and who isn't a bad actor but rather we can rely on moon math to you know prove our you know do-goodery or maybe we're just a regular old DJ and like the rest of the people gambling on chip coins on ethereum or something like this right and so we can actually take and make arbitrary statements and have them be privacy preserving about our balances and this is something that's really exciting and uh you know something you know these guys earlier alluded to at the previous panel you know we can get involved and present these things to people who are regulators uh and so um yeah I'm actually going to take our proof of concept go to DC in the US where I'm from and show this to folks I have a meeting set up with like the AML Folks at Vincent if you're familiar with that regulator I've been door knocking at the office of foreign asset controls pretty excited to see if we can't show this to people and get uh you know get people comfortable with this because I think this is really quite important you know kyc and current AML rules in my opinion are really quite difficult to deal with in a peer-to-peer ecosystem and so if we could actually take and Leverage The immutable ability you know the immutable nature of crypto and the really cool awesome moon math that is zero knowledge and have them make a baby that is a new compliance regime that's not based on intermediaries but mathematics instead I'd argue that this is pretty powerful so when we're looking uh to the Future near-term longer term uh we look at unlocking kind of the potential of these products in a few different ways I think one of the biggest challenges right now is that for people in this room privacy is a grave concern uh obviously that's why we're United here but for the everyday user they might not think about these things as much right so education events like this are a huge component of that educating the public but also creating creating systems and applications that kind of bring privacy to them where they're already doing business in the apps that they're already using on a daily basis that they're familiar with in a context that is easy to use that's not uh that's not posing a challenge that's not much more expensive these are all very difficult problems on their own to solve and collectively obviously you know it's it's it's a can of worms uh and it will be a challenge but I think this is the way we kind of bring we bridge that Gap and bring privacy to Everyday people that don't necessarily think about it as much as we do yeah 100 um I would say too that we can if we want to think about the future we can look at the past right and you know I don't think that history repeats itself uh but I do think it frequently Rhymes right and so if we reflect back to the Advent of the internet right uh SSL encryption actually wasn't a thing uh it took until what 95 and Netscape did it yeah uh and you know on you know online Commerce uh wouldn't happen without it um just a quick show of hands who would put their credit card information in on a non-secure website all right no hands we have a well-educated room in here right and so this sort of thing right allows us right privacy allowed like this uh Cambrian explosion of a really new and interesting way to interact with each other uh in terms of Commerce and I think that the same thing is going to happen in the web 3 environment and um I I would argue that you know privacy uh is is going to become the norm uh going forward yeah and uh so one other thing like is that we are not only concerned with end users and kind of the way they think about products and about privacy in general but it's also influencing developers to include privacy more into the apps that they build and making it easier to do that because right now it is a significant challenge to build privacy and to adapt for example uh and so we actually last week released a new product we call the railgun cookbook and it is a selection of recipes we tried to break it down into like bite-sized pieces uh for people uh uh in order to make what is a kind of a hairy complex topic and make it a little more approachable and give people the tools to build privacy ready dapps um you know with with uh the railgun encryption system kind of underlying them uh yeah I mean so I guess if we think about the future we got some near-term exciting stuff that people are hopefully hacking on uh diligently downstairs that I'm excited to see um which I think is really cool man and so yeah uh our argument is that uh privacy is going to become the default uh and you know we hope that people who are building these sort of applications and the decentralized land of Finance uh integrate this kind of thing uh I think cookbook is a really great way to do it uh it certainly makes it a lot less challenging uh you know the people writing the code on railgun the contributors uh participating in this decentralized ecosystem have smashed their heads against keyboards for many hours for almost two and a half years uh to make this and hopefully this helps lower that barrier for entry for people to take and you know add this to the things that they're doing in the ecosystem whether it's payroll or private seal bit auctions and things like this yeah so thanks for listening guys we'll uh we'll be roaming around so come say hi and ask us any questions you got yeah perfect thanks guys [Applause]
