Utilizing national IDs in the Ethereum ecosystem
Devcon·Tue, Oct 7, 2025, 12:00 AM
This panel brings together developers of MynaWallet, Anon-Aadhaar, Proof of Passport and zkPassport, who are exploring and developing applications that utilize government-issued IDs in the Ethereum ecosystem. We will discuss the characteristics of each ID system and what functions can be realized using tech stacks in the Ethereum ecosystem and cryptographic technology.
Transcript
please give our guests a round of applause and welcome them to the stage are we all feeling good thank you very [Music] much all right so uh we're the people mostly working with the E times like ideas so then we're going to talk about like where are s like our like experience like our like our in past few years so like can you explain first yourself first from the Hest yes um hello everybody uh super happy to be here today uh I'm yanice I'm a developer and working at PSC and developing anadar uh which is Adar is like one of the biggest identity program in the world it's a res residency card that is signed and we are letting um people generate Z proof that they are the owner of a legitimate signed paper awesome thank you and uh Mike please yeah hi um really great to be here I'm excited about this panel it's going to be really good I'm Michael Elliot I'm co-founder of ZK passport and we allow to use you to use your government issued passport scan it into your phone via NFC and then um because it's been attested to uh by the by your issuing government you can generate zero knowledge proofs to select the reveal information about yourself to Services awesome and uh yeah please so nice to be here today um my name is Flo I'm working on open passports and um kind of similar to what Michael just explained we're working on making it super easy for people to scan the NFC chip in their passport the real government issued passports uh and then to do zero knowledge proofs of specific stuff so for instance they can prove that they are above 18 or 21 or that they are from a specific country or just that they have a valid passports awesome and her please hi I'm happy to hear I'm hello and from Miner wallet and minor wallet is the Smart account that operated by the government issued ID in Japan minor card so U minor card we can with minor card we can sign on any data with tapping the card and ENT the PIN code so actually our minor our smart account uh verified with minor card so yeah a awesome and lastly uh my name is Nico um so I used to work in the Min wallet and right now I'm working with a open passport and I'm going to be the moderator for the sessions okay uh next me you and firstly um I want to ask about like there is a two different project working on the passord so like what's the difference on your like what's the difference of your two project good good question um I think we could have started independently maybe m more in the a ecosystem and we were more like um supported by like PSC and and W um we've been collaborating on everything we can like sharing um code basically and making sure that we can like be in this very positive some ecosystem well even like um discussing like sharing the um like registry for all of the certificates that the countries publish to make sure that we can have like the same base of Truth for all passports um yeah we're fully open source my guess is that you guys from what I understand have like open to some stuff um and maybe you're more focused on like astec and and making your wallet on Aztec now if if that yeah if that's ACC yeah yeah it's a good summary for sure um so we actually started using circom circuits uh six or S months ago um and now we've moved over to to Noir circuits and I believe open passports also switching to Noir as well now uh a big big overlap uh the two projects um and yeah I think there's definitely an opportunity to to duplicate work and kind of work together to to share circuits um with s passport we've got a strong focus on ux um and that's kind of like one of our main driving forces uh with regards to Aztec it is sort of uh agnostic Aztec have obviously developed Noir but that's sort of decoupled from from the Aztec Network and then we'll be using ziga passport with the obsidian wallet and that's more so focused on um integrating with Aztec as a wallet um but yeah I think there's definitely opportunity to collaborate um possibly even maybe we could merge at some point down the road yeah join efforts yeah awesome awesome thank you and I guess like ZK passport in ad all is like used to like issue when you issue the debit cont ticket uh you can get like a discount when you like have like Nationals of like a southeast Asia yeah that was a wonderful integration I really really enjoy building that out yeah we utilized some of uh open passport circuits to that which which use help and essentially if you were from Southeast Asia you could get a discount on your Devcon ticket and so the the approach that was you know kind of going to be used was this status quo is you send a photograph of your passport in um which is a horrible ux and so with this we built out an integration you could just scan a QR code go through the flow you would prove just your country um and if from Southeast Asia then you you'd be able to apply a discount voucher to your checkout and get a discount on your defon to get awesome awesome thank you so much so there are there firstly I I ask to the yanis like um how do you think about like why we need like National IDs and etherum ecosystem yes um like if we go a level higher I would say I would say that we need we need a way to like um privately signal ourself like as human um because like um some very important primitive need anti mechanisms um I would say that what we are doing with this project is one way to solve this problem yeah um we I think that it should be pushed uh super hard because like there is a lot of a ton of signed data that is like again out there and that we can like snarfy and uh make it compatible with um with um publishing it like on a public public network uh such as ethereum so yeah I think it's really important because um for now it's like one of the most practical way maybe not the way that you can like have something that is global uh shared by everybody in well because like you have this requirement of having signatures uh but I think that with this logic we can tackle like maybe I don't know like a good chunk of human so I think as time passes more and more governments are going to start attesting digitally over this kind of information and credentials um like you mentioned the other day uh things like you know University degrees that's going to be a great one if you have a bachelor or Masters that can be attested to and then verified in zero knowledge yeah but then the question is that can you trust them hopefully the government can trust the universities and then you can trust the universities and there like a chain of trust yeah but I would say that yeah in some places maybe you not like like because all our projects makes the the trust assumption that a government will not will not use his private key to sign fake identities yeah um so it's a very strong um assumption it works like most in most of the region of our world but in some region it could not be the case so you need alternative like when it's not when you can't trust the government for sure I I think the advantage of e passports at least in this situation is because it's being used by governments to protect their borders you get that same level of guarantee so if one government kind of just goes Rogue or you know starts minting e passports it's going to be obvious to every other government and they'll kind of be like what the hell like what are you doing um which is kind of like a protection mechanism in that regard but degrees maybe less less serious so they could do that awesome um like uh like you mentioned about like uh we utilize like not only the national IDs but like we have like driver's license like National deg like courage degrees U but like um do you have any idea like how you we can integrate those IDs into one IDE or like we can just use like those IDs in a separately like in a like it depends on the situations like do you have any SS like we can just integrate or something um yeah you can yeah um so I think the point that CH touched is is like importance that we're all making these trust assumptions on on the country um I think that it the the problems that we're trying to tackle like Cil resistance are actually quite hard to tackle like there's no really simple straightforward way to make sure that someone is a real person online it's kind of like the meme of on the internet you can be a dog and nobody knows you're a dog um there are some teams that are trying to use Biometrics but it's like it's still very hard because they have to ship their device everywhere because the current like phones that people have are not accurate enough for bi metrics not even really sure how much of how much different attack vectors there's on all of this so I think what's interesting about the work we're all doing is that we just take those existing signatures we wrap them in ZK and we make sure that they're easily verifiable onchain and offchain and then we make this kind of bets of there's going to be a lot more signatures in the future governments are going to sign things um companies are going to sign things universities are going to sign thing sign things and maybe at one point we have enough attestations that we can start to have a really reliable identity layer or general like aggregated system in which if one actor starts like behaving in the wrong way like a government like printing fake passports or like a university doing something then it's not that bad for the overall system a bit like giton passports you might know how it works it's like this system for Cil resistance for quc funding for air drops you can add different like we account and it gives you stamps and that's kind of the way I think about it it's like in the future if the tech is mature enough and it becomes super easy maybe thanks to Z kvms and we can like run them on on phones and everything that would be great um and it's like mature enough so that we can take all the signatures that are going to be emitted and use them um maybe at this point we kind of can break the tradeoff and have everything at the same time have C resistance privacy preserving uh proofs for every everything and still have the reliability that you would have um um yeah that you would need TS it off a lot like you were sort of what you were saying there was uh Layer Two for identity to some extent I'm not I'm not saying that needs to be lay to like yeah but like probably some kind of system uh that has a common standard and uh we've had discussions about standards I think it's kind of hard right now to know exactly what are going to be the standards because we're all like trying to figure out um what's the best way to use those things and I think the standards that's going to emerge is probably not something that um will have been like discussed that much but just the the one used by the the end user product that's going to work the best I think just get here quickly about the collaboration part there's such an opportunity for a shared registry whether it's like the certificate route uh registry where all the the country certificates are kind of combined and shared across like rare Remote open passports a passport and other project it's going to be very helpful awesome okay so like you first mentioned about like compared to the word like a using the passport and national ID is like less effort to legalize a civil resistance like uh for example in a in a passport uh like how reliable like when you prove the proof passport like this is uh this is a c resistance or this is a very good question so um passports were originally not really made for that we're kind of just taking them and reusing them for other things um so there's actually two levels of security in passports pretty much all of them support the basic level which is there's an attestation in the passports uh and you can read it and then you can verify it the kind of problem with that is that anybody that reads your passport wants can just take this attestation store it and then make proofs afterwards and like basically impersonate you so that's not great but a lot of newer now have this better security mechanism which is active authentication in which the chip inside the passport actually has a private key and makes signatures so we can like send a challenge make sure that the challenge is like um comes from like a valid source like for instance could be like renow onchain or something like that um and then um you you can make sure that the person really has the passport in hand at this point you can even like challenge the person every six months or something or every transaction um so that's something that we're excited about it's kind of it takes a lot of time for countries to ship that because you know like renewing your passport is not something you do every day um but maybe I'll add something um so even with this better security mechanism you still can't make sure that the actual person behind the passport is the person um who owns the passports and uh one thing we're really excited about is trying to use Biometrics um not not exactly in the same way that W is doing it but more like um maybe having a kind of face ID that matches with the photo of the passport because the photo of the passport is actually in the chip and it's actually signed which is really great so if we can um like it's probably too too too early to use ZK with that because ZK ml doesn't really work right now in terms of performance for client side but if we can like have some kind of cosign similarity or like matching um system with like convolution or something in the te um that could make like there could be something that um makes um makes this all more reliable and we're excited by that yeah so it'd be really great to be able to like check like a face fingerprint from your passport photo and then you could scan your face with your iPhone and get and then you could compare those two face fingerprints uh in zero knowledge to prove that you are the person on the passport at the time that you use the passport really exciting yeah okay um yeah okay so like you mentioned about like active authentications um so like in the other are Sy like in adult system uh do you have any those kind of active authentication features included in adult system or like no well no like um yeah so sometimes I think it's the case for mina like uh the government is not signing like just the concatenation of like your identity attributes but sometimes they're like giving you a key pair that they are attesting that it's yours yeah um and you can use this Keir to like authenticate and the um yeah identify yourself um in like in the India stack there is no such mechanisms yeah but to go back to the to the um theme question about like uh how can we rebuild like an identity I think like with anadar we try to there is this app called digilocker where you can s um all your documents official documents like driving license degrees so we make the exercise to like try to figure out what could be like uh the there is this idea about self Sovereign identity so what could be like The snar Sovereign identity how could we like use all these piece of data and like um use it so it's very new we developed like this circuit like in the past uh past few months um very exciting excited about it like to see like what type of usage um it's going to be it's going to be like unlocking so okay yeah I heard like you are using like a QR code issued by the government and you check the time stamp or something and it can be like active authentification or something like yes so it's not active authentication because active authentication is like the fact that as Floren described like you can sing send a challenge to the user and he gives you back a signature um no but so so this mechanism can like um um make you can you can make sure that the the person behind the screen has like actually the the document and you can send like regular challenges to to make sure he he still owns the document um no in the case of Adar like the cool point is that U um inside of the signature you have like a Time step of when the the data was signed and we are using it like as a Time based one time password so meaning that um at the verifier level you can um set it up in you can you can create your own logic and you can say oh um I want to verify your signature um like a snack proof of your signature but I want like this data um signed like um less than three hours ago okay okay like it's a proxy to to know if the user has access to like the platform where he can generate his okay like it's it's not exactly the active authentication but you can still check the like a time stamp when the when the signature is issued or something yes it's more like uh you want to make sure that the person behind the screen has the document and has access to like the official platform and has the credential and um is the because like in India it's like mainly like OTP so like a connection through SMS so you can make sure that he is the owner also of the phone with my understanding of this is to be able to uh to get get back your adha if you for example lost it or you need it at that time the you can request one and the government will be able to SMS you a link to be able to get it again uh no it's not only used for Recovery it's used like for authentication right and you you leverage that to be able to prove that you are the person at the top yes so for example like for the app we developed for uh the def cut discounted tickets we wanted to make sure that that the proof was like generated less than three 24 hours ago because otherwise like a c code like I can drop my card like on the floor and I can like uh it's like a liveness check through one one time password okay okay awesome and in the minor case uh like you are actually have like a active authentications and and like you use like also like so like for active authentication that like they can actually do like make a signatures and you can like like hack the features and it can make a account wallet yes so like what's your experience about this so uh first uh I need to explain what is minor card in detail so minor card is the uh NFC card NFC type B card and there is a secure element inside so there is two RSA key Pairs and to sign with this card we can tap the card and enter the PIN code like a credit card so just this is so we can generate the signatures and then we dialect Tre verify the signature on chain uh like ERC sport 3 S con smart contract that's why we can uh generate the smart account by this card and also um as we we talked um the government provide us a kind of a liveness check API so that uh we can uh directly create uh directly create this transaction also we have directly verify that uh the the user is actually uh existing uh residence in Japan okay okay and like you have like a like a AA wallet from from that card right yeah uh like um like how do you have any s about like a privacy or like how do you have any idea about like how use like how like those keys are used in wallet okay um so uh we red the uh current pki system for the identity verification of the minor card so to verify the signature from minor card on chain and we need to store the part of the public key on the certificate in the minor card to on the smart contract so uh actually so this is a pki system a pki system the the the mapping of the electric certificates that includes the public key and uh identities uh government can related information so um yeah the actually The Government Can trct it it users uh activities on chain so that's that's kind of a privacy concern but uh Nico you did the I um yeah so like basically the Min wallet is like AA wallet and like they generate like their wallet address from the public key inside the minor card so like the government as the hero tolds like there is a mapping the public to the like your identity so like The Government Can truck uh like kind of brute forcely and they they like Brute Force like kind of brute force and they can detect or like I'm using this vist or this Vol arist like for our general public uh they don't really have like the list of like a public key to like my identities so like we can protect the Privacy for the general public but the still the government can track our identities and there is some kind of like uh like like technique to hide our identity even from the government but it only works for the RS key especially for the RSA like kind of some kind of pting scheme but like uh in near future like a minart will turn like right now they're using the RSA but they turned into like a ecdsa and like in the ecdsa they uh we need to input like a random value to make a signatures so like we cannot use like those kind of technique so like we need to like like in the current version we can like think like we can have like a solution to from hide from the government like in the ecdc or we need to like a figure out like how we can like achieve like a privacy from the government like um I think you have a kind of Sal like um should we should we actually need to hide our privacy from the government or like the for depends on the government I suppose I'm sorry depends on the government yeah yeah yeah yeah yeah yeah or like maybe like some there's some people want like um it's okay to reveal the Privacy to the government because like there is another privacy wallet named the EA so like it's fine as long as you're using the EA you want to be a private private and like you want do something with the government or like you want to pay tax or something it's okay you fine like I can live government so like I think this is because like right now the Min is like um like generate their address from the public key I guess yeah right yeah it depends on the use cases yeah because uh if you want a private private address you you you can use your any EA right but uh yeah this our solution our product is for like people PE uh for not for people like us people here because um um they can choose which which which address to or which you know uh on purpose which you can you can check you know um like so so like you're more focused on like a more mass adaption not really so like first you just like think about the mass adaption and think later about like a privacy or those things right right okay awesome just kind of zooming out from what we're talking about here I think one nice way to think about it is everybody has their own Pho or like even like Hardware wallet that's issued by the government allowing them to sign over data themselves but you've still got that chain of trust back to the government that's been you know that's issued it to a particular person somewhere um some are some are kind of weaker signatures so like the E passport the active authentication that Florent was talking about earlier that's RSA 20124 bit so you can really use that for kind of like very short time periods um with a challenge request that that maybe like a few minutes um that was the intended purpose at airports and we're leveraging that existing infrastructure um but you you can still do that but any longer and you risk people being being able to break that um through Brute Force attack on RSA um but the great thing about the the minor card here is that because it's like kind of like a national ID card issued just in Japan they've used the same standard which is must be amazing not having to integrate so many different signing algorithms um and you get this really cool functionality coming out of it it's the same across all of the cards yeah okay um yeah okay so like and um do you have any thoughts about like um so right now you are verified RSC signature on onchain directory right but like uh in near future like mineart turned to be like a ecdsa like a 384 bits and it's going to be very expensive to verify and on chain like do you have any SS on like this one so one idea is to raise the kind of EIP EIP something like that to at prep compile so like you are kind of stick to like like a verify the low ecdc signature on on chain or like you have any idea on like using the ZK or something that's that's a one one one option okay so I guess I guess like also like a like creating a ZK proof for those kind of long like a very like a heavy signature on Z proof uh but like also like in the passport there's so many like a like a signature algorithm I use like there so much VAR and it's crazy right so like do you have any idea like currently like RS is fine but the others like do you have any idea yeah so um Cloud side proving for DK has always been kind of challenging one of the main reasons is that um teams that are working hard on on ZK are often just optimizing for big beefy servers because this is what the rollups are doing and so this is what the incentives are because it's rollup you got business tokens things but like we're doing kind of cloud side proving on people's phone because there's no way we're like sending people's off like passport data or like personal data anywhere else this is a must have it must be all generated locally on the device exactly so historically sirom has kind of been the way to go we've switched between different proving Stacks like the polygon ID one mpro that's been great too uh I think no now Noir is becoming kind of more of maybe it's going to become the new standard I think what's really exciting with Noir and really great for passports um for instance is that um all those different countries have different signature algorithms and so it's super hard to support everything in circom because you have to write a specific program a specific circuit for each of them but with you can have easy recursion uh that's not too like uh that doesn't have too much overhead or you can just delegate this overhead to a server that does not see theice private uh values because you do smaller proofs locally and so it's way easier to have a system in which you're going to split the proof into smaller um like pieces that you can do locally that only have like small um like requirements for for RAM usage and for like bandwidth and then recursively um verify them um like server side on a big b server and then post them on chain or do whatever you want with them so that's something we're super excited about yeah on mobile you're really limited by memory so you don't want to go beyond 4 GB and so the larger your circuit the larger the memory requirements and so the design that we've we've created in war is we have these subcircuits a b c and d and each subcircuit is responsible for a different part of the verification process so subcircuit a for example verifies the um authenticity of the uh so it basically verifies the root certificate of the country has signed over the intermediate certificate and then uh subm module uh subcircuit B verifies that the intermediate certificate has signed over the E passport data subcircuit uh C verifies the Integrity of the passport and finally d discloses uh the data that you wanted to selectively reveal and so this modular approach means that we can if there's different signature algorithms for say the intermediate certificate we can kind of the when we generate the proof client side you can pivot through the different subcircuits easily um and kind of like route through to whatever the passport uh requirements are for this finish algorithm some countries even have you know a variety of different algorithms and the biggest challenge we have right now is adding support for more and more signature algorithms to maximize compatibility yeah so uh what's the point like what's the mostly the difficulties like you mentioned about the memory usage or like the other things like what's the like a bottleneck in a CLI proving or especially the iPhone like whatever like I think currently the two main bottlenecks are rhyme usage and um then load uh speed and everything cuz with like sirom and gr 16 what we were using before need to download this huge file to be able to use proof it becomes very tricky when you have uh like big circuits but with Noir it's kind of more manageable and um I think in the future the end game of all of this is probably Z kvms and you might already know about Z kvms it's like very easy to use you can just write your code in like some normal rest um like Aztec yeah yeah yeah yeah I mean yeah like I'm thinking more about like ZK VMS like in rust or something um but yeah Noah is kind of similar to rust and no is like already easier to write than than other like dsls U but yeah maybe maybe the future you could just like um natively import your R library that does RSA like literally the same one that you that's used everywhere and then um directly like verify like do proofs on on phones but right now we kind of looked at the performance and it's not quite there uh like I heard like you kind of experienced with the sp1 which is the GBM do you really think like like dkbm also be used for the curent side proving or like one day one day one day yeah right now it's it's a bit yeah right now it's challenging yeah s1's great it's a it's a nice you know ux um to be able to just develop natively in Rust and not even change the interface for your uh crates because there's like pre- compiles in in the sp1 crates but because it's the Stars uh the memory requirements are way too large for clients side proving a mobile currently so maybe um S2 could could reduce those requirements but currently it I think snarks and um andir is is the best approach okay awesome and yanis are you also working with the nor or like you're turn into like nor or like you're just like what's your what's your problem for like our so like those like a ram problem or like DK problem yes so we have the same bottleneck um which is like client side proving so we are try exploring like what could be the next step for client side proving because um I think that this type of protocol especially like in the case of India like you want to like distribute them like broadly and we want like have like the lighter possible but also like a proof that is Su so we can use it on chain because we think that the main news cases would be probably on chain because um it's there that where you need like the more privacy um we tend to see like from government side that you can have like they like more um listening to like privacy issues and selective disclosure so we really want like to have like a light prover but also have sness so we can like prove on chain yeah and yeah I think like main of the exploration as as uh flora and Mike was speaking about is that maybe one solution could be like to have like um a proof that is like that is very fast to compute on a client but not sucin and then send it to a server that can Max in suin without learning like what we the input of the computation yeah that's one way um and us like on our side what we're doing is that we are exploring so there is no end game for now there is no um perfect solution so we are trying to have our implementation in like different language like for example we did Implement our circuit in hello to because uh we know that some people are exploring like um hello to GPU acceleration so that could be like an interesting path have you explored Noir yes Noir and I think Noir is more like in the so um Noir is committed to ship backend so like uh it's um it's more secure that to to to bet on Noir because like you know that maybe if there is a new interesting backends the the team is dedicated and they will ship and they will ship it so yes we for now we we will stick to grow 16 because for us is the it's the best but of course like we want to see like more exploration in the client side proving I think there is a lot of money spent on server side proving and trying to optimize uh Z for server side uh but I think that for privacy uh we really need like to have efficient clients approving here awesome awesome and you're talking about like mostly the use cases is onchain like it's also like our like kind of ID system can be used like offchain like EK things like um do you have ins SS on like offchain use case I think you need both like uh um as an application developer uh you should be able like to tackle any environment where you want to check this proof uh so I think especially if you're revealing like for example your full name datea of birth that's not something that you want to publish on chain for eternity this is perfect for a backend proof for some sort of service to verify yes yes uh uxy it's hard but yes uh I mean uy is like maybe the end user like doesn't know like what is where is send that would be horrible could you imagine just publishes it forever yeah that's why like no it's an interesting question about selective disclosure because on the case of anonadada we could have like implemented it like in a in such a way that the the developer can set the prover to to say oh I want to I want you to reveal your first name but as like we are very early we were super precautious about selective disclosure and only U like our prover is only able like to um s disclose information that if you disclose all of them you can be in a Anon anonymity set that is like large enough to not be de anonymized so you be selective about SEL disclos sorry you need to be selective about selective disclosure yes that's kind of a security because like you know like it's quite early and we don't want like like the chain is immutable so we don't want like developer messing up control Z on blockchain yeah yeah so no we need to to be very precautious uh about that um yeah okay okay so like uh as about like as I mentioned about the offchain like our ID system can be used in the real world and recently Like A Min world did is some kind of real world experiment so like can you explain about like your experience about it yeah uh just recently we conducted a real world demonstration minor wallet in a rural area in Japan which is called yamakoshi nigata Japan and yamakoshi is very uh unique where the da is actually working on um Regional revitalization and in the in the in the in the demonstration participants run from children to the actually the uh people at the age of 18 and they and there we uh demonstrated that top two pay top two pay by usdc and without and actually uh there are people can make uh could make it to pay by miner card using the usdc because uh uh they don't even know uh what's going on on the Box on the background they are using uh what the blockchain is working or they are paying by usdc but they have have the mental model like tap and tap to pay because uh it's mental model is totally same as the credit card so yeah in this demonstration we realized that uh real world use case is um is very important ux is the very important and actually uh this is uh interesting uh about uh sorry uh Japan's minister of digital transformation Mr Tyler is actually uh very interested in our our demonstration and they he had he actually came to our demonstration and create his smart account okay awesome awesome so like the Japanese like our digital Minister are interested in uh like our like cryptocurrency or like they are very open to the new technology awesome uh you have some communication with the government like do you have any pressures or government like it's I heard like a very positive side like do you have like any like a negative side from the government yeah uh negative side I think uh uh uh they are very open to new new technology so we had a lot of conversation and uh of course there's several regulation to uze the disc card but uh yeah uh there are so yeah but yeah we can talk and we can you know yeah yeah yeah so like we you have have like more well good discussion with the government awesome awesome okay and uh so like if the government is like more friendly to us like more friendly to like our like ZK friendly or like ethereum friendly uh what do you want to expect for so one thing I'm very excited about but it's also very long term I guess is compliance in general so right now if you look at the compliance Frameworks of most countries you can't have any privacy right if you do kyc to create a bank account to create an account on an exchange you have to send basically all of your data and it's going to be kept it's going to be stored for monitoring so that the government can ask for any your data um afterwards and when you think about it it's kind of it's actually really bad like there's it's it's kind of horrible there's like um often leaks um that leak like all of the private data of everyone it's like really sensitive data you can do crazy things with it like get SIM cards bank accounts um and also it's not really secure anymore because now with generative models you can just like generate whole databases of like fake people and just do kyc um so right now it's not really like compliant according to the current like standards to do privacy preserving proofs but there's some interesting explorations to do I think so for instance one thing we recently prototyped is you can do a zero knowledge proof that you're not on the ofac list so you might know about the ofac list is like the US list for saned entities they have names of a lot of people and everything and you can like scan your passport and do a proof that specifically you're not in this list thanks to like non inclusion proof in the SP tree and then send it when you do a transaction for instance and this could be integrated into like a dii protocol or even the base layer of an L1 or an L2 and what this would allow is to have this kind of system in which you know that the person at least at the time is not on the OAC list and I think this is all U pretty much kind of um like Explorations now but it looks to me like compliance sometimes can be a bit more flexible and there there should be a kind of like Middle Ground we can find in which for some transactions it's actually fine just to do this and that would be great because again it's like breaking the trade-off we get the privacy and we get the freedom at the same time yeah I think it's a journey and I think we want to be able to like explore this and just sort of see how governments respond and how Regulators respond to this I think a really amazing use case for what Florent just described is you could have like a private usdc where you have you know full privacy you can transfer it around but every time you transfer this USD DC on a private Network like Aztec Network for example you're generating a proof that you're not on the ofac SN sanctions list um you're not from a sanction country and you can even Implement logic where there's this nullifier that's unique for every passport and then it allows you to track privately that you haven't exceeded some super generous a limit like for example 100,000 usdc per month um and that means that it's going to severely mitigate any kind of like Bad actors from using this protocol and this this token and so when you come out to an exchange to offramp users can sort of have this uh you know certain or guarantee or or at least some sort of comfort that they're not going to be banned by that exchange whether it's coinbase or binance or whatever yeah and I think it's really going to help satisfy regul letters um that yeah this is really mitigating Bad actors from using it allowing people to have privacy um full privacy and you know eat their cake and have it too yeah yeah yeah yes um yeah I'm super excited like to again like push this ID forward like distribute it like to to Broad broader population because then like maybe we can have like at some point like some voting um at a scale of a government like using this primitive yeah I'm also super like um interested about like how you could like resolve a full identity like all your documents like boring news cases yeah I had like to fill a v Visa file like recently everything was in my email so maybe it could have been like Z proof zof um like yeah like more like generally going toward like some like where you can compute something on your on your hand like just in like a suene proof um also yeah on the government side and like this technology I think there is like two ways to see that um like one optimistic way would be like all right so if the Govern like The Government Can de anonymize me is it a feature or is it a bug I think there is no like strong answer to this question for now depends on the government I suppose again depends on the government but like you can imagine like then in I don't know 10 years maybe we were going to have like air drop from the government and like maybe yeah yeah like maybe just being able to identify and receive like cbdcs and like have like a universal based income is like I think what we're building is like could be like a base ground like to build that so yeah yeah so so do you think like a like you like a universal basic of happens like uh it could be like like a paid in a blockchain like it could be paid in a in a bank account it should be paid with cbdcs and and you just can I don't know sign a message or like just send a zik proof and then you can redeem your money okay okay okay uh So like um you live in a like a uh Europe right and you have some kind of identity system in the Europe right uh like how the situation in Europe like ekyc like how those ideas are used in the Europe or something yes so uh I think like last April uh like the European commission like voted on like uh the fact that zero knowledge will be like a solution in the future like for privacy preserving identities so they did like a tender proposal where they like called every projects that were interesting like to help them like build their identity wallet that they want to launch like around 2013 30 sorry um yeah so like Europe seems to be like listening to like all these privacy issues I mean it's Europe that basically did the gdpr so yeah we we are like maybe slow on Innovation but good at regulating I guess like Europe is more interested in like a privacy things like they're more care about like privacy or like compliant so like there is a I don't I'm sorry I don't remember the the project but Europe also have like a a project about their own blockchain I don't know about it I don't know if it's good I don't know if it's bad but yes they are interested like into this technology for the good or for the bad we don't know but at least like if tomorrow we can sit on the table they will know what we are talking about okay so and like do you have any idea that we can like we can actually like enable those IDs right now like do you have any ideas for those kind what kind of ID we can like enable right now like do you have like idea like uh I think the most present use cases are s resistance in general whether it be for quadratic funding for air drops yeah okay I think for us we're excited about um being able to have Zig passport as this you know open source public goods identity infrastructure we're building obsidian wallet to kind of dog through that and we be integrating ziga passport in uh as identity like at the wallet level so you'll be able to have it as like a first class citizen that exposes an API to daps to be able to request identity proofs and compliance proofs so you could have for example uscc token requests that you have these different compliance checks and then the wallet uh obsidian wallet it then manages that completely and generates these proofs behind the scenes um so I'm excited about that kind of yeah integration uh and being able to use it more and more with uh web 3 and and apps awesome awesome yeah okay so like there is so many things like we can consider about like our our wallet like our identities and like there's bunch of use cases for those like nationales or like like for example civil resistance or like uh like like R dat on Alpha or whatever on ekyc so um and there is more a bunch of more like National identities like the identities which is signed from some kind of organizations especially of course in a is like in the ca area definitely also in the Europe definitely like there is e identities so like uh it would be great like like everyone working more like more identities is like coming to the etherum okay thanks so much for our our panel uh that's all yeah insightful conversation that we had thank you very much I'll be throwing a few questions to Nico and then you can distribute accordingly to our speakers okay I'll be reading the most voted comments you can also scan on the right to throw in your comments right now and so I'll be reading it word for word on based on votes the first question that we have today which is the most voted is what are the business model for each of your projects government identity is typically a government service that people expect in exchange for paying taxes who would you like to take the first call um I guess you can inter again yeah I think we don't really have the same value proposition as um government identity right now we're almost like we most like repurposing government identity for other stuff um yeah I'm not too worried about business model I feel like if you do something that's very valuable and that's some kind of that has some kind of like platform on network effects um you you shouldn't be too worried that's my take I yeah yeah okay okay going to say sort of sort of answers the question but one thing I think would be great to discuss is if you think about um digital think think about identity in general um who would be the best entity responsible for attesting to your identity and your credentials and you know who you are as a person um your name birthday this kind of stuff it's the same entity that issues you a birth certificate and so if you change your name for example who do you go to it's it's the government um as opposed to like a so it's like State attested identity versus um cooperation attested identity yeah yes and in the case of anadar is the PSC project founded by ethereum foundation so we don't have like any business model it's a public good and open sours so right right right how about how about Minor wallet I guess minor wallet is a wallet so it can be kind of um fee model right PR model okay okay pre model okay all right heading to the next question the most voted one as well one of the challenges of presenting government IDs remotely is inherence I.E how to prove that the presenter is the same person the ID was issued to how should we best do this uh one of the challeng of the presenting the AL ID name yes so in the case of anada is like the same mechanism we spoke about like we are using the time stamp to actually ask the for the user to generate fresh data on the official platform so it's a proxy that he has like the also the credential and like the SIM card that is like enabling him to authenticate that's how we are solving this problem I think the face fingerprint is also a really great um way to do this if you have a photograph that's signed over the uh signed over by the government yeah so like using a photograph or like a time stamp or like if they have like a signatures can make active authentications also maybe like a like a name and address like correspondence and find like a relationship so like one identity is have like active authentication and the other identity doesn't have but like we can have a corations between uh between them from like name Ork address or something yeah I think this is a this is a pin code I suppose for for Minard yeah yeah P card yeah yeah yeah all right heading to the third question why should people use open passport if it relies on government data people will stick to the current method and it's more convenient for now is there a way that doesn't depend on government data well people will stick to the current method what's exactly the current method like for instance if you want to do an airdrop or or like C resistance for quartic funding this is an actual issue that people have actually had and I think most people know that even today like on gon gr you kind of see that some projects have come some yeah have have have some like kind of we Behavior with regards to the uh like donations um so yeah I think basically what we're trying to do is we take what's working right now which is government ID and we repurpose it so that now we can use it in a privacy preserving way on chain um for the kind of things that we tryer address I don't even really see an alternative um I guess it's also like they asking about like passport is used in the real word right but how they turn into open passport used in the real word um what what what what you mean currently they have like some kind of infrastructure using the open like a passport right like I guess they are asking about like how they start using the open passport instead of current infrastructure like in the real world like in know like at airports yeah yeah yeah yeah um yeah I think the airport thing is a bit like compliance um it in the future if regulatory Frameworks change it could be just like compliance you maybe could just do like a proof of of a specific stuff uh I do think it's like more on the line because uh like National Security issues are like pretty yeah like not keen on um privacy right now yeah I guess like the difference is like um so like we using a ZK so like we don't have to Lio all the data into the passport but like current system uh we need to Ral all the things so like it's a different it's a different I think privacy is a very compelling privacy privacy yeah wrapping it in ZK yeah okay I'm going to squeeze in one more question before we do a final wrap-up of each of your minutes okay the final question is has anyone developed Hardware like a kiosk for these forms of ID for users without devices I think here oh you did okay no but I I was about to say that it's a very interesting area like I had like some chat with some hackers recently and U um we had this idea about maybe um for a hackaton project could be cool like to recreate this uh hairport gate but with a nanar proof so you can you can scan it and the hardware has like the verifier component inside of it so yeah I I would say that there is a bunch of stuff to do like with hardware and C proofs awesome awesome I think hero did like like you previously not before before the M wallet you worked with like NF nft Gateway or something and also like you're using like kind of Hardware with the Like A Min right especially in Min this is an nfg car so if the uh the Dev can be communicated with like NFC so can be yeah we can build the kind of chos device but uh the the in minor case uh the actually the specification of the NFC card is not open S open source because this is under the n n yeah so we can yeah kind of like we reverse engineed the minor card and we using the card right before we start uh there are sever people to sever people did and there is some document about the Min card that you using those documents okay awesome yeah okay all right as a closure to the session I'd like to do a one minute wrap up for everyone else perhaps we'll start with Janis and go all the way to niiko to do a one minute wrap up of your projects your takeways Etc yes um we so at PSC we have a Discord so um please uh pass by the PSC website uh go to our Discord we have like a proof of citizenship channel uh if you have like if you see some chip on your identity card if you see some QR code somewhere uh try to scan it try to read it see if there is a signature that might be a high chance that your identity could be snark ified and like please uh reach reach reach us and we can uh we can help the help you um and U yeah that's it yeah I think it's very important for this trust infrastructure to be you know nonprofit credibly neutral um open infrastructure that everybody can access um and yeah I think that's what we're building out with to get passport I'm very excited about that and uh yeah we also have a workshop at midday today in classroom B I believe so um if you want to check out what building please come by uh bring your passport if you have it if not that's okay too and we're going to be going through our SDK and and showing you how you can essentially uh recreate the the Devcon integration that we made where you can request specify which credentials you'd like to request from users and then the entire flow is is taken care of and all you get back is a a xologic proof that you can then verify and use You' like yeah um so yeah same thing for us we have a workshop today if you want to come by and see how the whole flow looks like if you want to try out the SDK or the app um I'm super excited by the future of uh what we're doing I think one thing that's kind of been underexplored is uh there's a lot of different ID systems now I think some in like Brazil some in Malaysia a lot of them also in Southeast Asia that also have signatures and for which the public keys for some of them might also be available but this is just something that looks like nobody has really uh explored deeply I think the more of those government standards we can snarfy and the more conversations we can have with uh Regulators about making those standards more ZK friendly and more open and more um like common across countries the more this is all going to accelerate oh thank you for coming today and uh yeah so I couldn't tell about a lot more about detail about Min Min wallet so we have the uh kind of session at a have 4 pm today so if you're interested it please come to join us yeah yeah yeah okay and lastly um so like I worked the M wallet and also I'm currently working on open passport and from my experience uh like there's still some problem because like those government IDs is not issued as supposed to use on the blockchain like as supposed to use on the ZK but there is still space we can work on a lot and it could be like a used for like it's it's definitely like a like a future like in the future like we need some Z like privacy all Technologies we need it for those IDs so like it's kind of early right now but it's not early but I think like we can we can have we have a lot of things to do and we can have like more like many things to experiment
Automatic transcript — names and jargon may be misspelled.