New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Edge | Driving Adoption of Privacy - Paul Puey | ETHDam 2024

CryptoCanalMon, Oct 7, 2024, 12:00 AM

Join Paul, CEO and Co-Founder of Edge for a talk on “Driving Adoption of Privacy” at ETHDam 2024. Privacy protocols are here and have use and utility but they require key changes to achieve adoption and resistance from governments. Learn what the crypto industry needs to focus on to ensure success of privacy coins and protocols. We’ll learn from the history of privacy technology as a template of what to do and what not to do. Paul is CEO and Co-Founder of Edge, a self-custody exchange and security platform for crypto. Edge (formerly Airbitz) has won accolades including being one of the top 3 mobile apps for bitcoin in the 2014 Blockchain Awards, being voted in the 'Top 50 FinTech Companies to Watch' by AlwaysOn Inc, and receiving first place in the Inside Bitcoins 2015 and Coin Agenda 2016 pitch competitions. Paul held lead engineering positions with Nvidia and Chromatic Research. https://twitter.com/paullinator https://twitter.com/EdgeWallet https://edge.app/ Sterling Schuyler - MC of ETHDam, copy and content writer for emerging fund managers & crypto enthusiasts. ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz We would like to thank our partners that made this event possible. 🌷 Battleship Partner 🛳Oasis Network https://oasisprotocol.org/ Jet Ski Partner 🛩⛷ NEAR https://near.org/ Canoe Partners 🛶WAKU https://waku.org/ 🛶Trail of Bits https://www.trailofbits.com/ 🛶Avalanche https://www.avax.network/ 🛶Privacy + Scaling Explorations https://pse.dev/en 🛶Threshold https://threshold.network/ Our Canoe Partner & Official Node Provider 🛶dRPC https://drpc.org/ Sponsor 🤝EF Ecosystem Support Program https://esp.ethereum.foundation/ Paddle Partners 🚣ChainSecurity https://chainsecurity.com/ 🚣Lido https://lido.fi/ 🚣Cyber Capital https://www.cyber.capital/ 🚣Diva https://www.divastaking.net/ 🚣Firn Protocol https://firn.cash/ 🚣Beefy https://beefy.com/ 🚣0xbow https://www.0xbow.io/ 🚣Obscura https://obscura.build/ 🚣Panther https://www.pantherprotocol.io/ 🚣Maven 11 https://www.maven11.com/ 🚣Zama https://www.zama.ai/ 🚣zkSync https://zksync.io/ 🚣Secret Network https://scrt.network/ ETHDam AfterParty Fren 🥳Bitvavo https://bitvavo.com/en

Transcript

[Music] all right cool well we're going to go ahead and kick off our programming today with [Applause] Paul I assume this is my mic can everyone hear me okay I want to to lean into this thing all right so if I could kick over the slides thanks everyone for coming by waking up early hopefully not parting tooo hard last night um so given the uh topic of this conference and what everyone's building in the Privacy space um I thought I wanted to talk about how we get privacy generally adopted how do we get people using it especially considering that we've been trying to build privacy tools for decades and many of the tools have failed adoption some have succeeded so my goal is to kind of go back in history history and look at the different privacy tools protocols Technologies and see and analyze what we think might have been their kind of good decisions or missteps um and hopefully learn from that especially for everyone out here who happens to be a builder to really help build the the tools and technology that get not just interesting from the Viewpoint of what privacy can deliver but to make sure it actually gets adopted and delivered to the masses so quick introduction my name is Paul P I'm CEO and co-founder of edge were a uh a self- custody multiplatform trading app uh for cryptocurrency um former senior engineer over at Nvidia back before AI was even a a thing or what was called um been in the crypto space since about 2014 now running on about 11 years and spoken at you know a few dozen conferences in that period of time um can't say I I know everything about crypto for sure I don't think anyone does the thing I've noticed is as the years go by the industry grows faster than anyone can actually learn it so I feel like I know less and less every single year but you know try to give insights on what I've seen over time so going into into history of privacy technology let's start with stuff that's not even cryptocurrency just just encryption which is obviously the core of what delivers privacy and so doing a little case study of pgp pgp or um pretty good privacy uh was a technology invented in 1991 W by Phil Zimmerman um and it was a technology that allowed you to both sign and encrypt messages or data it was primarily targeted for email use right for us to actually be able to sign to verify that you know message that we sent was created by us and then also to encrypt that message so that you know obviously the re the recipient could uh decrypt and see it and no one else um it had plugins for various email clients uh Outlook you you know was fairly oquit at that time uh Thunderbird udora if anyone remembers that era back when Qualcomm was barely a chip company they actually made email software and then like macmail um but in 1999 the the fifth version of pgp um pgp 5 was analyzed by some researchers and they looked at the usability and tried to see you know how usable was pgp5 and they analyzed it using two different techniques one was um basically just a walk through and looking at the different steps needed and pretending that you were a beginner or someone not familiar it's kind of what we try to do is you know when you're inside the bubble of cryptocurrency and you analyze your own product you pretend that you don't know so that's the best you can do and then they also took true laboratory user survey and studies asking people to walk through the process of you know creating Keys signing um email messages using pgp encrypting messages decrypting them and at the end um they really gave a good analysis of everything from the visual metaphors use such as these icons uh to the types of keys and the challenges that people had deciphering the kinds of keys the key sharing a backup and security of keys which we can definitely attest to in this world of crypto um they analyze things such you know these visual metaphors as an example you know these buttons that showed Keys encrypt sign encrypt and sign and some of the challenges that they noticed were the analogies to the real world of keys kind of break down because in encryption you have public and private and in the real world you just have a key right it unlocks it locks and it unlocks there's not a concept of this public versus a private key in in the real world um uh and decrypting there's no key on the icon but you need a key to decrypt um so these little subtle um visual metaphors really broke down for for a lot of people with their study and at the end their summary was it was a complete failure this was a fully by and large unusable both app and and protocol and the summary was they they took about one about onethird of the people that they had passed through the test could not successfully sign an encrypt an email message given 90 minutes 90 whole minutes that's an hour and a half and they could not successfully do it that's you know um what was it actually yeah onethird of them only one3 could do it 2/3 could not and so an example of what I would say is definitely not what to build when you want to get Mass adopted uh software one of the challenges I know I had looked into this this paper was actually the key sharing not the PRI not the private key but the public key how do we properly get the key from you know sender to recipient um discovery of the key the key servers um and that's something that will go into newer technology and how that newer technology solves and helps with adoption but kearing was easily one of the biggest challenges that people had let's go to another technology good old SSL and HTTP invented in 1989 by Tim burner Lee we had finally the web and browsers um prefix with hdp everything was in the clear every piece of traffic could be seen by every server that Happ happened to be in the middle of the Hops to go from sender and recipient come 1994 though we introduced SSL or https as you'd see which now exists today um first implemented I Believe by Netscape um and then looking into today that little snippet at the very bottom is actually a clip from the government's website saying use SSL use encryption um everything should be considered sensitive not something that we would have expected the government to do given that they were trying to clamp down on any kind of encryption at the time now they effectively mandate it um SSL by and large I would consider to be a successful deployment of encryption it came with tradeoffs especially in that public key Discovery we have certificate servers that are in essence somewhat of trusted entities that we go to to determine is this truly the public key of a server that we're going to be communicating with and while we have that compromise we've distributed that trust across many different certificate authorities and so the benefit is it's automatic you go to a browser you punch in a URL you're done there is no key management there's no encrypt and sign there's no the it it's it's impossible to get it wrong and that's kind of the beauty and they've there are now even newer domains that mandate SSL if you ever say doapp domain you punch that into the browser the browser now knows rules that say this cannot be non SSL this has to be SSL um so looking at this protocol I would say this is the shiny example of one that took you know what I'd argue are the the good Alternatives in compromises of privacy versus usability now getting into some of our favorite things chat apps I'm I'm going to a handful of different chat apps and where they've kind of gone right and gone wrong so telegram oquit Us in the cryptocurrency world what do they do wrong with respect to getting privacy adopted number one it's optional privacy you have to specifically create an encrypted chat or what they call a secret chat with people all right so by default nothing is encrypted in telegram if anyone told you telegram was a private chat app they're wrong all right by and large unencrypted um every chat that you do that is encrypted creates a different key pair so you could find yourself chatting with the same person and have multiple chats that are individually encrypted and it'll appear in the app as two different chats with the same person you're like well why are my chats confused um and they arbitrarily Target different devices so if you have telegram on multiple devices uh when someone tries to send you a secret message it finds one of them shares keys with with that one specific device and that's where you chat so I'd find that telegram on my iPad and on my Compu and on my phone when someone sent me a message I wouldn't know which device it would go to it very very bizarre user experience what do they do right in my opinion nothing this is a complete failure for adoption of privacy because no one's using the actual privacy protocol that telegram has from an adoption point of view they've got 800 million active users and privacy near 0% at this point are using the privacy portion of telegram and I think this starts to Veer into one of the biggest challenges of privacy when it becomes optional so what'sapp what do they do right uh from the Viewpoint of discovery that key management part they they made phone number Discovery an easy way to find someone there are a few other chat apps in the past that didn't do this you had to like find handles and you know share keys this one simple phone number Discovery at the compromise of even though chats are encrypted you do know which phone numbers are talking talking to which other phone numbers so that is a compromise but realize that they did allow for people to get um encrypted chat almost invisibly it's encryption by default so contrary to telegram you're always using endtoend encrypted chats but what did they get wrong um single mobile device use this is a small little gripe I have I can't have an Android and iPhone both have WhatsApp on it for whatever bizarre reason seemed like an arbitrary limitation um which try to avoid bizarre limitations like that doesn't make any sense but their biggest flaw was the that WhatsApp automatically backs up your chats um to Google Drive if you're on Android if you have that um and iCloud on on an iPhone and those are not encrypted by default so what's the whole point of you know this beautiful end end encryption when two of the biggest companies in the world will effectively have copies of your entire chat history unencrypted and so while they've got a huge amount of adoption with two billion monthly active users um the Privacy I'm G to Ballpark based on anecdotal asking of people how many people don't have um iCloud active on their phone um or uh Google Drive probably less than 10% of people um don't have that so you're not getting quite the adoption that you'd like so you know less than 10% maybe 5% so instead of 2 billion maybe 200 maybe 100 million people might actually have the benefit of privacy and the problem is you might not have your chats backed up but the people you talk to might and therefore you've exposed your chats through someone else iMessage um I gave credit to Apple as being one of the few companies that really Mass deployed um end to end encrypted chat and uh they did it for a lot of people that care nothing about privacy and so similar to Whatsapp encryption by default phone number Discovery as well as email Discovery through iCloud um they did that right what they did wrong iOS only so iOS and Mac you're really limited there as soon as you chat with uh for those of us that have iPhones you chat with an Android friend you're you're green bubble friends you're going over SMS which is probably the worst of all um from a privacy point of view and they have very similar flaw as WhatsApp they back up by default everything into iCloud unencrypted um that has partially changed with uh newer versions of iOS like 16.2 and above where you could encrypt your backup but it's extra steps that you have to look up online on how to do so another example of a gosh this was a great opportunity to drive massive um adoption of a privacy tool but failed because well you know Apple basically sees all of the uh uh backed up messages and with 1.3 billion active once again a guesstimate of less than 10% of that we've lost a huge amount of uh potential um adoption and I think a lot of the Privacy Advocates favorite signal what do they do right phone number Discovery obviously encryption by default you cannot send a message that's not encrypted um they've recently added user handles which helps a lot on privacy because you no longer have to expose a phone number to that other user that you're chatting with um and what they did wrong small little gripe the the synchronization of chat history so when you switch devices is a complete mess um you basically lose chat history by and large when you switch devices especially going from like phone to desktop to iPad um but there is no unencrypted backup like you would have to manually go through the trouble of trying to backup your chat history which isn't even possible on certain types of devices um so it's kind of harder to mess up even though it's inconvenient that you don't have this backup um unfortunately it's just a much smaller user base you know at about 4 million total not active but 4 million total as of 2021 hopefully that's much larger now um but all of those people get close to 100% privacy so let's look at crypto cryptocurrency protocols look at two two of the most popular that of that are trying to drive privacy um zcash and uh Monero starting with zcash what do they get right biggest one is the cryptography like these are some of the the smartest cryptographers in the world working on this protocol um the anonymity set baked in to the protocol is everyone that is using their their private Z addresses um as opposed to trying to mix with a handful of uh inputs and outputs but what they got wrong is once again similar to um pgp they got wrong optional privacy meaning by default uh what are people using is are the transparent addresses um and another gripe is synchronization performance it takes a very long time to discover which transactions are yours um from an adoption point of view you know in 2020 only about 6% of the transactions broadcast uh were actually shielded um and a study by Carnegie melon um showed that about 99 plus per of the transactions could be traced um and so it shows that even though you might have a really really good technology if you don't have more people inside of your pool of private uh transactions or private Communications you stick out like a sore thumb and therefore increase by a large margin the traceability um and I like to say if you're in a room of people you're the only one with a mask on your head and you know everyone you know the entire kind of headcount of who's here you'll know who is hiding and the same model happens in you know crypto tools and so so the adoption curve unfortunately of zcash which I think there's still hope right that it's a smart team they they know what they're doing but you know really trying to drive that default privacy as as kind of without that you've really leveled the amount of adoption and I think the people do care about privacy are not quite using it yet um that strong cryptography needs to be paired with you know more more of that default privacy um then in contrast Monero uh what did they do right privacy by default um it didn't start that way um they had definitely poor privacy early on until about 2017 um but now it's by default with about what they call a mix uh a rank signature of about 10 which gives pretty good privacy um a fast sync option so once again that performance issue I was mentioning um uh the my Manero API allows people to effectively sync their transactions with a a bit of a privacy uh compromise but with a huge performance uh Improvement what do they do wrong much weaker cryptography so the cryptography in Myer does not use ZK snarks um instead ring signatures which is effec hiding your inputs and outputs within nine other decoy inputs and outputs but ironically because the anonymity set is so much larger because all the transactions are are shielded effectively um the same researchers from Carnegie melon had determined that recent transactions in all of history about 80% of the transactions are by and large untraceable with the recent ones being almost 99% untraceable and so the weaker technology but with a very high level of adoption across many more people and many more transactions actually equated to a higher level of privacy so adoption is key in that sense not just because we want people using it but for the people that care about privacy getting more people adopted into our pool helps give it to us as well um and that shows in their adoption curve so the traceability this is a traceability graph and the traceability dropped off a cliff which is a good thing um as soon as they had adopted some additional Technologies such as ring signatures and increasing the the in the ring signature size to about 10 and the adoption curve has kind of grown with it these are the number of transactions the red line number of transactions on on the network over time and I think we see that people do care of privacy are are adopting this uh uh adopting Monero nicely and so uh in summary right what do we have to take away from some of the study is uh make privacy hidden is what I like to say um you know we use privacy to be hidden well privacy itself likes to be hidden hide it from the users don't make them go through any extra effort um to get it otherwise you'll only get really kind of the illicit actors and the people that care um which means we get lumped into that same group we don't want the people that care about privacy to be lumped into the list of actors in a way that's somewhat what happened with tornado cache it didn't have enough usability and seamless invisibility to get the masses using it um make privacy default and then yeah don't actually make a back door right like that back door with a backup you you don't want one you didn't intend to do one but until you gave it one so you know don't don't weaken it For No Good Reason um and then anecdotal requirement from our experience having deployed many privacy protocols is make it performant um uh in our experience when Monero didn't have bulletproof it took about 45 seconds to sign a transaction um we easily skyrocketed our our tickets you know our support tickets because people would say what's taking so long and they'd give up and they'd close the app in the same sense when it takes a long time to synchronize um tickets shoot up the roof and then people just stop using the the protocol um the My Manero API for Monero did definitely improve that so learning to keep things performant and with an interact ability is a pretty key thing and that is it thanks for listening um you know if you ever want to get in touch pollinator my Twitter handle edge.a you can find me there as well U we do support multiple privacy uh protocols you see on here pirate chain Monero and zcash that's where we help learn a lot of what you know it takes to to get get these things adopted and we get feedback from users which is helpful I'd love to hear feedback from you guys as well so thanks everyone great awesome thank you so much we have a couple questions from slido uh that if you'd like to take some questions cool M check so the fir and everyone remember c.com oh we've got it right here ask your questions so the first one we have here is what was the peak of adoption in zcash in summer 2022 was it tornado cash related so because it's private it's hard to tell right so those that was a I'll go back that slide that huge Peak right there um you'll notice that that was one of the times when like the Red Bar was almost 50% of the total transaction volume um as opposed to 6% which is what it had been in the past and today and so there's believed to have been a Spam attack unfortunately as opposed to there being real transaction volume but in all honesty it's hard to tell there were they were encrypted um and shielded so unknown believe to be a Spam attack which definitely slowed down the network um made it take days to synchronize a wallet right to discover your transactions um and with that a huge drop in you know effectively real usage of the network by at least people that we were aware of and so we've got another great question here what did it moved what did Monero do uh that zcash could learn from adoption wise um the two things that i' had mentioned which is uh privacy by default is one of the big ones like don't um don't make privacy an extra step make transparency an extra step a lot of the criticisms of privacy by default are like oh but I you know maybe I want to be transparent because I'm a nonprofit and I want to be able to show what our our what funds we're getting and receiving that's easily possible you can share a key that can decrypt all the transactions that you receive doesn't mean it needs to be the default and so that's one thing Mona did I think all the Privacy protocols honestly should do is allow for transparency but don't make it the default and then second um the the protocol where a Vu key is is given up and it compromises some privacy but at a huge huge usability and performance increase those are probably the two biggest things that I would say any privacy protocol should learn from from the Viewpoint of adoption awesome thank you so much all right thanks everyone [Music]

Automatic transcript — names and jargon may be misspelled.