New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

[CLS] Programmable Cryptography | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

The Programmable Cryptography CLS hosts a series of talks exploring how advanced cryptography can reshape digital infrastructure beyond blockchain and trust infrastructure. SCHEDULE: 10:00–10:20 AM, Justin Glibert / 10:20–10:45 AM, Vitalik Buterin / 10:45–11:10 AM, Albert Ni / 11:10–11:35 AM, Barry Whitehat / 11:35 AM–12:00 PM gubsheep Speaker(s): Justin Glibert, gubsheep, Barry, Albert Ni, Vitalik Buterin Track: [CLS] Programmable / Frogrammable Cryptography, by 0xPARC Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] okay great so the uh far future of uh cryptography um sorry next slide okay great so I think first know we'll talk we'll talk about the uh very recent past and I think still ongoing present of cryptography right I think the biggest change that we've seen over the last few years is basically the way that sarks have really taken over everything right and one of the analogies that I've used is I've thought of SARS as being similar to a Transformer right so this is know the GPT architecture that's now famous from AI land and the analogy here is basically that if you think about what GPT did right it basically took a whole bunch of different use cases for which thousands of people have been putting in years of hard work years of application specific algorithms application specific data Gathering application specific expertise and it just like swept all of that away with just a really dumb system where you just like put like take half the internet like throw it into a funnel and then like run the G run a bunch of gpus for a while and it just manages to magically outperform all of them as a general purpose architecture right and snarks you have done basically exactly that same thing for cryptography right so we've seen ring signatures we've seen range proofs um you know we've seen all kinds of different use cases just basically swept away and subsumed under this umbrella of I am just making a proof about a computation about private data that is is expressed as some kind of standard um arithmetic circuit in a standardized language and that you can you can make a fair a fairly short proof that just proves whatever claim you want to prove about private information that you have in zero knowledge and oh at the same time it also solves scalability right so it's this extremely powerful general purpose technology and the ethereum road map has already changed completely as a result right so if you look at the plans that ethereum has for the next few years all of the far future stuff really uh depends on sonars existing the uh road map for replacing veral trees with something Quantum safe depends on Starks the uh road map for long-term full light clients depends on Starks the uh and rollups started off being optimistic rollups and now there's ZK rollups and they demand on Starks or depend on Starks they're um also plasma before sonar it was a a very limited architecture that that could only do a little bit after snarks it just be it actually has become something quite a bit more powerful so snarks have really overturned everything and in a lot of ways they've also simplified a lot of things right like if you remember trying to design protocols in the prear era like you really need specialized cryptographers putting in a lot of specialized cryptographic work to make specific applications work whether it's proofs or it's ring signatures or it's linkable ring signatures or it's chami and blinding every one of these Primitives would require a cryptographic professional to do a whole bunch of work and even still you'd only make something that works for a few particular sets of applications snarks indiv non- cryptographers can just go in and they can do their thing put in their code and it just works next slide so let's talk about what happens what happens Beyond snarks so in one of my recent posts talking about the future of the ethereum protocol and made this analogy to these Egyptian god cards from yui right these like extremely powerful monsters that just have these incredible Powers right and uh you know in Yu-Gi-Oh Legend these cards are so powerful that it's physically dangerous to actually attempt to create one of them and you're not actually allowed to use them in duels right and uh like these three protocols I think are exactly that powerful in the same way right so we talked about sarcs but let's talk about the other two items in the series right so the one in the middle is uh fully homomorphic encryption fully homomorphic encryption lets you do any computation on encrypted data without being able to learn anything about that data this is extremely powerful this basically lets you take a very wide class of applications and just Express them very easily as an FHA problem I have private data and I want you to do an algor run some algorithm on the private data and give me the results without um actually learning my private data that's an FHA problem um I want to be able to train on people's data without learning the data that's also an FH problem you do need a little bit of cleverness to make sure that like the thing that the model actually learns about you doesn't uh actually itself reveal your data and like that's a differential privacy thing right but the bulk of the hardness like actually is just captured by the FH piece if uh you want many kinds of uh like privacy pres uh preserving architectures privacy preserving Dows as long as you're willing to accept a certain certain trust assumptions it becomes an FH problem f is like actually an incredibly powerful technology another thing that it gives you actually is uh uh it gives you private information retrieval so the ability to make queries against a database without the database learning what you're asking for and one use case of this is privacy preserving light clients right so you can have an ethereum light clients and your light clients can go and like ask for like some piece of data about history without the server actually learning what you're asking for so very powerful stuff but you know we also have to get to the third Egyptian god protocol which is alisation right you can encrypt a program in such a way that the encrypt program has the exact same functionality but if you have a copy of the encrypted program you can learn nothing about the internals of it like basically yeah except for what the inputs and outputs are now technically like that exact definition is uh like not exactly achievable but like in real like for any realistic use case it's like basically close enough to that right and so alisation lets you uh be actually do everything that FHA does but it lets you kick out like even more of the of the trust assumptions almost all of them you can do Dows that have secrets you can you can actually use offis cation to implement basically any other cryptographic protocol you can use offis cation to implement encrypted mols you can use offis cation to implement a ZK SAR scheme where verifying the SAR only requires verifying a signature um it's it can uh let you Implement like any kind of uh FH MPC two party uh two- party computation it uh like basically is a superet of like almost everything else cryptographic so in order to try to make this a little bit more concrete let's look at voting as an example right so I think of voting as an example because I mean obviously voting is important in itself but also voting um to me is like a stand in for basically any kind of onchain mechanism that that is not purely financialized right so yeah I wrote this is like one of my own fra uh Frameworks right so I wrote an article about this um I think this was uh the one on Nathan Schneider's cryptoeconomics or coordination good and bad but the B what I call financialized is basically mechanisms where you don't mind people arbitrarily colluding and one example of this is like if you compare money to let's say like like likes on Reddit right if you think of money I give you a dollar in exchange for you giving me a dollar is not a problem it's working as intended on Reddit or on Twitter I upload your post and in exchange for you uploading my post especially if it got optimized to Infinity would just completely break the system right and so if you want to support any kind of mechanism that is not financialized then like that means that you have to be able to prevent uh collusion in some way at least make it difficults to trust and that requires as it turns out exactly the same type of properties that voting requires so let's look at voting as an example so base case put it on the blockchain so what does putting it on the blockchain give you right it gives you public verifiability so anyone can check that the result was computed correctly and it gives you censorship resistance if you're an eligible voter no one can stop you from voting so it's a good starting point Dows have been doing this for a very long time very basic now of course voting on The blockchain has a lot of problems so let's talk about adding cryptography on top let's add ZK ARS keep the previous properties but you also add and you keep public verifiability but you and uh you also have censorship or resistance okay sorry I wrote this incorrectly um the thing that you add is privacy right basically if you vote then no one will uh be able to tell who like which person made a particular vote you'll still be able to see the contest of the votes but you will not be able to see like who actually made a particular vote right and this already is a very significant privacy gain it already makes uh many types of collusion much uh much much harder and like it's already a really significant Improvement right but it's still not enough right and the reason it's still not enough is basically that if you really wanted to sell your vote then if you made a CK snark you could still prove to someone else that you voted for some particular particular candidate very easily so let's add the Macy mechanism the Macy mechanism does not rely on any new cryptography it keeps the previous properties but it also adds coercion resistance right and assuming that the server is honest so assuming that the server is honest you add this new property which is that you cannot prove who you voted for even if you wanted to make that kind of proof and this adds like a very large friction against actually trying to implement any of this kind of bribing because basically either they have to do some kind of like side Channel attack against you directly as a voter or they actually have to like attack the server now let's add FH right so with FH you keep the previous properties but you if you add FHA together with threshold decryption you can make the coercion resistance guarantee only depend on an mfn assumption so instead of relying on one operator you can rely on potentially like say seven operators out of which like four need to be honest right now there are voting protocols that have existed since like 2002 that have given all of these uh properties depending on an mfn assumption with simpler technology but those protocols they gave all of the prop all of these properties under that assumption this kind of design actually gives uh um every property except for corrsion resistance an even stronger guarantee and if you do it with general purpose cryptography it generalizes much more naturally to any voting system you're not if you H have a system that's designed for doing Simple vote counting you can switch it over to doing quadratic voting quadratic funding with like a few lines of code you can switch it over to doing pairwise bounded quadratic voting a few lines of code you can switch it over to doing cluster matching a few lines of code you can switch it over to doing the community notes bridging Matrix factorization algorithm with only the lines of code that you need to actually Implement that Matrix factorization algorithm and if you want to do it efficiently it's a bit hard but the algorithm itself like basically about 20 lines of code right so FHA basically together with SARS you actually create this like very general purpose uh design and you keep all of your all of these properties that you want out of a voting system except cion resistance depends on an MN assumption which is like not ideal right because M out of n can still collude silently and they can collude silently they can like pass all of the information over to the NSA and like no one would be able to actually tell that any collusion is happening so now let's add aisc so with aisc you can keep the previous properties but you can make you can make it so that extracting or proving any information at all about individual votes requires blockchain consensus and you can even make it require some amount of proof of work per bit of entropy that you extract so how do you do this basically when a user votes instead of sending their vote to a a threshold key um or like FHA encrypting it to a threshold key they FH encrypted to a key that is inside of an offis gated program and uh the so this is a trusted setup but but there are ways to make the trust setup be one of one of N and you can make the N be like extremely large right so FHA encrypted into this key that's held inside of a program and then that program only gives the total output of all of the votes and in order to give the the total output at all and even there it's not going to give the full number it's just going to give like the one bit basically who won right and or potentially a few more bits if it's like quadratic funding right and the way that this program works is it Tellies the votes and it also checks that there is a proof that the block consent has finalized it and on top of that it also can check for like some little amount of proof of work right so you could do it like say like $500 worth of proof of work or you could imagine like ethereum eventually adding like maybe like $10,000 proof of work on every finalized blocker like some simple uh simple amounts right and so then even if the blockchain consensus colluded um even if like everyone colluded they would only be able to extract a very small number of bit of bits of entropy from the system right and so actually deter and then you can also make the program add a little bit of gy and no noise and so extracting any information about how an individual voter voted will basically just become extremely hard so this is like very close to Ideal right so but there's more so we'll talk about onot signatures onot signatures are A Primitive where you can make you can have a key where that key can only be used in to make one signature one signatures require users to have quantum computers so this is a milestone that will come at quite a bit after the bad guys have quantum computers right when quantum computers come they're going to be like hundred million dollar things you know the the bad guys or at least the people that we consider threats will have them first right and so you'll have to wait quite a bit of time after that until regular users can also have quantum computers right but you do is what what this ISS is basically yeah you know you can have a public key and it's a mechanism by which it's a public key such that the you for any given uh Nots you're only allow it's only possible for the owner of the private key to sign exactly one message with that Nots and this all depends on the quantum no cloning theorem right if you have a Quantum State then you cannot actually copy the quantum State there's mathematical proofs that this is impossible and the signature scheme depends on solving a problem which is um infeasible with classical computers but doable with quantum computers and so you're basically like proving that you have and that you're spending one of these unclonable Quantum States so this could actually be used to make Quantum money without a blockchain now it doesn't remove the need for blockchains completely it still doesn't solve sensorship resistance on its own but this is the thing that like I'm not I don't want to call an Egyptian god protocol because like this is not just the land of computer science this is like in the land of physics right and so it's like it's some kind of tier that's like even more powerful than these things so when will we get all of this technology right so zekus SARS we're seeing an increasingly high level of maturity I mean I personally look would declare Victory once we're able to actually have ZK EVMS that are proving blocks within one swad currently we're probably still like a couple of orders of magnitude away from this but there's a huge amount of progress there's a huge amount of work in binary field proving systems like basically the race is on um FHA we're starting to see viable applications so if anyone here was at at H City you probably got one of those like Square wristband things and there was an application called cursive where basically you could provide a list of what your interests are someone else could provide a list of what their interests are and actually used FHA to compute the intersection so we're starting to like see toy applications that like right consumers can use on local devices the FHA has roughly a million Factor overhead and so you can run business logic inside of it but you can realistically you cannot run cryptography inside of it right so it's like at that interesting level where it's like you good for some things not it's still not good for a lot of things it's uh you know in that middle Zone alisation the big news over the last few years is that we're starting to see viable protocols in 2020 there was the first protocol that was dependent on only standard assumptions and this protocol someone actually tried to implement it and they discovered that it would take 10 to the power of 27 years to run a year later someone created a slightly improved protocol and someone else started to implement it and they're estimating that it's going to take one year to run now there's also a separate line of work that's trying to make off escas protocols based on slightly more exotic assumptions and it's like actually more debatable in the long run whether this is more or less secure right because it's like on the one hand you have more exotic lattice based assumptions that are like based on multi-linear map constructions and like zero testing and like that whole line of stuff but on the other side you have like Normie assumptions about luses I mean you know go go out and like ask anori what they what they assume in belt lce is right that kind of stuff um and but at the same time you have to like assume and that and elliptic Cur pairings and like one or two other things right and so but that stuff you know if you want to in office get a program it takes like a couple of weeks right and then one shot signature is obviously no idea definitely a long time and we'll see quantum computers break half of existing cryptography including anything lip to curve based long before this actually becomes possible so basically I think the takeaway is that all this stuff that was like extreme science fiction a decade ago is like slowly coming into view right every single piece is like with every single passing year is becoming slightly more and more clear and I think we can actually really start getting excited about these things right and we get excited about a world where cryptography actually can get to the point of in a general purpose way actually being able to replicate the or replace the functionality of any trusted third party and uh I think that future will be amazing thank you thank you vitalic um so we will do three of Q&A uh we have the QR code here you can scan to both add questions and up vote questions um there are only two questions so far and one with I I'll start with the fun one which is vitalic if you played the frog game and if yes how many frogs have you collected unfortunately not this time I've had like zero time to do anything other than jumping around Devon stuff but but but here it's been fun um okay what advantages will the snark ification of uh the beacon chain um have I mean I think uh the big the big one is basically that you will have light clients that will be able to fully verify the ethereum protocol right so like on your phone on your watch anywhere anywhere that you wants to do things with ethereum you'll be able to like actually fully verify the rules of the chain and uh like you'll be part of the mechanism that ensures that the the chain and like even 51% of the of the sakers are not changing the rules on you and uh that's uh so and this will all just like happen passively and automatically um to invite me to a conference to speak out how does one go I'm not not answering um One Shot signature on the book possible not answering can we call beam chain ethereum 3.0 I think no and I think this is like an important misconception right because I think like a lot of people like got this weird Twitter impression that like oh you know in the be the beam chain it will only happen in 2029 and it only happen gives you these nice Ivory Tower Properties about the consent layer and so it doesn't even mean anything for users and like this is ethereum 3.0 right and the reality is like very different from that right the beam chain is only covering the ethereum consensus layer which is only like maybe one third or one quarter of the ethereum stack right the execution layer that so the evm has its own road map and then layer twos and Layer Two interoperability has its own road map and uh even on the consensus side all of the key things that are actually meaningful for users so ESP especially getting dank charting um up I think can happen a lot sooner than uh 2029 thank you um okay more questions what do I think about tees I mean I think they're definitely interesting for some uses though I think it's always important to remember that like they depend on a lot of trust in specific manufacturers and they get frequently broken right and so you want to use them for like applications where they're either just additive in terms of security or where the cost of them breaking is like not too high but you don't actually want to use them to like literally replace cryptography so you know use them responsibly um what can on shot signatures plus sisc plus blockchain not do it cannot give you true love thank you thank you vtic so what our next speaker um is going to prepare the connection with their top um I've been sent to entertain you guys so uh one thing I found interesting with vitalic presentation is when you start listing down these cryptographic protocols one by one um you don't need to like scre your eyes that hard to kind of like see some form of mathematical computer emerge right like each of these Primitives are synergistic with each other um as an example one primitive V did not talk about is Oram oblivious RAM and one thing that's interesting with that is the same way in traditional computers we could put all of our state in CPU registers but we don't because they're hella expensive and we have like you know multiple layers of storage we have CPU registers Ram uh blog storage network storage Etc it's probably going to be the case that with cryptography we will have to do the same so while some of these protocols can technically do everything we'll probably compose them with each other in order to like reap the best performance possible and so who knows maybe in a decade we will have cryptography computer Engineers whose entire job is to build computers out of polinomial and not out of silicon uh which and they will I one thing I was thinking about yesterday night when I couldn't sleep is who's going to be the tsmc of cryptography you know kind of like a polinomial Constructor For Hire that put together the biggest cryptography computers um I will also check with a if we're ready we're ready okay cool so I will introduce our next speaker to the stage um so Albert KN has been many things to many people at both eorum foundation in zerx park but above all he's someone who pushes us all to think in more Direction and I think he's going to do that yet once again with this talk titled the future of cryptography the real surreal and super real thank you [Music] Albert like I said we have to do this there we go all right hi everyone thank you Justin for a very fitting intro today above all I want to share some interesting ways I think about the future of cryptography some many perhaps are ways people have not considered um this is going to go to some interesting places as the title hints at but before I dive in I want to emphasize that while I want folks to consider more directions the point is not to replace how you currently think about things this is not new thinking in a totalizing sense it's not declaring it's not even predicting at least not in the sense that people usually interpret the concept of talking about the future this is just thinking creating awareness for what may be possible and may be true because sometimes that awareness is what makes something unexpectedly possible we don't have much time so I'm going to talk as fast as possible uh just kidding but seriously buckle up so part one the real let's start with some easy stuff things many of you know if you've been exploring modern cryptography here are some uh slogans if you will come for the encryption stay for the signatures or come for the security stay for the interoperability like today https is a statement of security but maybe zps or pctp programmable cryptography transfer protocol will be a statement of possibility how about this come for the nuk proof paint stay for the superconductor we've known for a long time that cryptography is digital nuke proof paint but it's the superconductor aspect that we are only beginning to realize and understand now I want to go in a bit of a different direction here's a quote from Steve Jobs recorded in the book Valley of Genius an oral history of Silicon Valley that I'd highly recommend one of many things that stands out from this quote is this phrase medium of expression today what is the thing that this thing we call computer technology what is it a medium of expression for consider all that's been built around computer technology especially the companies the organizations the products the institutions what are they expressing or this is a bit more of a leading question what have they become everyone senses something has gone a bit ay with our relationship with the digital a relationship that's largely mediated by what we broadly call computer technology and so I want to take this immune system lens when we think of the word immune system we naturally think of our physical immune systems this predates literally Humanity itself but for much of human history there's also been this implicit notion of an intellectual immune system you could also consider calling this a philosophical immune system think about how you respond intellectually to various things how that's changed developed over time sometimes it strengthens sometimes it's probably weakened kind of like your physical immune system what about the digital right now we think of digital stuff in terms of security and protection but as our digitally anchored and oriented experiences become increasingly intertwined with our lives perhaps the notion of an almost organic digital immune system is a way to think about it notably a digital immune system conceptually wouldn't even have been cogent 100 years ago probably less it's simply much newer almost primordial so we need to remember it's going through things that are more associated with the very early stages of a system or ecosystem developing for instance one might say that the interaction between the physical and the digital currently leans parasitic this is partly because we haven't realized the full potential of digital Technologies and and I guess the digital realm to be more symbiotic with our overall existence but I think this can and inevitably inevitably will happen especially as our intellect ual immune systems co-develop or co-evolve with our digital immune systems remember one of the most underrated things about evolution is that symbiotic coexistence is literally a more effective equilibrium than Total Takeover this is true even when the specific organisms fundamentally remain in competition such as predator and prey if the Predators start doing too well they crowd each other out same goes for the prey now you might think okay cool digital immune system cryptography that makes sense the connection is relevant but that's not exactly where I'm going what I want to consider next is literacy consider this word and why it even exists it used to be notable when someone was literate as in could read or write for most of History it was rare or definitely not universally expected for people to be literate that's why the word exists to point out an unexpected thing of course today it's notable when someone is illiterate it's not just notable it kind of feels wrong like Society has failed that person keep this in mind going from default illiterate to default literate happens all the time often slowly then quickly one of the most well-known company slogans of my childhood was from Bill Gates and Microsoft as you can see the slogan was a computer on every desk and in every home 30 plus years ago this sounded incredibly ambitious it was almost awe inspiring as it turned out this was nowhere near ambitious enough should have been a computer pocket computer with you at all times a computer the first thing when you wake up the last before you sleep a computer while you're on the toilet when you're in a meeting or attending a talk a computer every we at all times computer literacy as in being able to make use of a computer for your needs was rare until very recently when I was a kid aptitude with computers was actually low viewed as low status phrases like computers are for secretaries were common today everyone below a certain age is computer literate but not in the way that you might have naively expected 25 years ago and it's definitely not that everyone now knows how computers work it's that every computers became a thing everyone knew how to use thanks in large part to the iPhone and the subsequent smartphone Revolution again default illiterate becomes default literate but how it happens is often hard to predict even when the iPhone came out many thought it was going to be a total flop consider also how the concept of photographic evidence has only existed for like a hundred years imagine telling someone in 1850 that there's a photograph or video or audio recording to prove or disprove their version of events today that idea is entirely second nature most of us have never known a world without it of course there's a storm brewing brewing with progress on what we call AI because we don't know what else to call it the current concept of photographic evidence definitely won't last another 100 years might not even last 10 if you naively extrapolate you might think we're going to revert to the world of trust me bro just like all of history before the photographic evidence era but naive extrapolation almost never actually plays out a couple Generations from now cryptographically grounded evidence will be second nature to people the same way iPhones made computers second nature to kids today the same way photographic evidence has been second nature for decades but it's not even really the cryptographic evidence era we kind of have that already to some some extent it's the cryptographic literacy era remember literacy doesn't mean Mastery and widespread cryptographic literacy doesn't mean widespread understanding of how cryptography Works similar to how I noted earlier that widespread computer L literacy doesn't mean everyone knows how a computer works still what's really going to happen is not actually going to be thought of as cryptographic literacy what will it be thought of as I consider this one of italic most underrated blog posts should be pretty easy to look it up given the title within the post balic defined legitimacy as a pattern of higher order acceptance Loosely speaking people expecting other people to expect the same things and therefore we can all expect something recall that smartphones are what unlocked computer literacy they are the form and mechanism through which computer literacy became near Universal for cryptographic literacy or legitimacy literacy the form and mechanism is something we don't know yet what is it that makes things more high order accepted in this broader sense product and Technology Innovations will unlock this future and I bet some of them will feel just as surprising as the iPhone would have felt just 30 years ago to someone still being AED by Bill Gates's computer on every desk Vision also remember the value of the wheel it was unlocked by the invention of the axle people weren't idiots they long noticed that round things can move more easily but that's not what it takes to make use of the wheel we don't know what the axles are to Crypt phography Wheels yet one consequence of all this is that something that feels like cryptographic writing will exist I'm sure it won't feel literally like writing combined with cryptographic signatures in fact we already have that but what's important is it'll have the property of being inherently higher legitimacy than conventional digital writing we will not think of all things written digitally as being more or less the same this is already true to a limited extent depending on the context but the distinction will be much more substantial and there will be a reflexive feedback loop that causes even more widespread legitimacy literacy through throughout Society all of this will contribute to another shift in how people feel about cryptography even if they don't know that's the thing that they are feeling something about so everything so far I've put under the real now I want to start to segue towards the super real to do that first I want to revisit some miracles of science here I'll Loosely Define Miracle as something where if you didn't know something existed or was possible it would be very surprising that such a thing exists just as it would be surprising if magic exists my first example is fire the existence isn't a surprise since it spontaneously occurs in nature but the ability to control fire was a significant development to say the least next is electricity this one is a bit surprising I guess people had seen lightning but what reason was there to believe that this thing could be harness that it would turn out to be magic juice that moves infinitely fast and basically gives us permanent light communication across vast distances or to be able to construct things like computers then there's nuclear power which was I think truly a surprise like wait a second effectively infinite power is everywhere mass is literally energy but there's one more source of quote unquote power that gets overlooked because it's a fundamentally different type of power each of the first three Miracle power sources can be viewed as asymmetric offense it's a lot easier to burn something to make than to make it fireproof and we know how powerful a nuclear weapon can be but as I noted earlier cryptography is digital nuke proof paint cryptography is an almost infinitely powerful defensive or protective technology and the fact that it's the digital superconductor is like the icing on the cake so I do think it's reasonable to consider cryptography a miracle of Science and one reason is because cryptography is a physical realization of the potential of mathematics now let's consider the four fundamental forces of the physical Universe we've got gravity a force that was definitely apparent to humans since well before we were humans then there's the electromagnetic force which was the fact that was a force was not actually really clear until about 200 years ago then we've got these two crazy forces that operate at Atomic scales the weak force and the strong force we actually didn't even realize they existed until the 20th century and we didn't confirm how the weak Force functions until like 1960 so are we sure that we've got them all there's even like a digital strong force strong nuclear force parallel here you know cryptography holds things together at a level that overcomes the inherent collapse of Digital Data kind of like the strong force overcomes the repulsion that positively charge protons otherwise would experience when packed together in an atomic nucleus so that's why I wonder if it might be apt to think of cryptography as like a fifth fundamental force of the universe especially a universe that is increasingly becoming a combination of the physical and the digital and so that takes us to part two the super real and I I like this particular definition of the word marked by extraordinary vividness so if cryptography is a force of nature then actually utilize that Force requires implementation our day-to-day us usage of electricity isn't just some like General usage of the electromagnetic force you know there's voltage there's how what decisions around batteries alternating versus direct current and so much more there are a lot of specific things so when I say Cryptor here what I'm gesturing at is the specific form that of things that actually harnesses the cryptographic force this is one reason I kind of like to think of cryptography as a digal duel to physical reality electricity the transition we're undergoing can be likened to the transition from a world that only knew fire to a world where electricity is everywhere back when people only knew fire if someone told you about electricity that we could somehow harness lightning you might imagine better lights better heat perhaps better cooking ironically because I fire is actually better than cooking for cooking in a lot of situations you can imagine lighting up a city and heating a city but you wouldn't really imagine powering a city you wouldn't imagine computers the Internet or that electricity actually kind of runs even through our brains you wouldn't you definitely would not imagine artificial intelligence and you definitely wouldn't imagine cryptography so in the future digital stuff such as data computation information transmission that makes use of programmable and other future cryptography will feel like electrically powered objects in comparison to what we have across the web today Computing that is cryptographically charged or maybe Enchanted is far from what we currently think of as Computing same with data that is cryptographically Enchanted and Beyond now why is this even more important than it might seem at first blush because the tech industry as of now has philosophically flattened in fact we can see remnants of the higher dimensional space it it fell from if you look at any Tech startups pitch they pretty much all still contain a mission and the mission is never build the most valuable company now if you've ever seen a hedge fund like a new hedge funds pitch deck they never have a mission it's all business it's how they're going to make the most money the whole tech company Mission thing at this point is kind of a Remnant from a philosophically higher dimensional era of Silicon Valley and at the same time and not coincidentally while computer technology has improved dramatically it is regressed from the standpoint of how it feels counterintuitive counterintuitively using computers going back to like Doom or civilization 1 or the well or IRC or aim or text-based multi-user dungeons in many ways felt more expansive enriching not that things were anywhere near perfect back then don't get me wrong but there was a hard to quantify feeling of moeness that feels so different than how the web feels now it's fascinating how differently and in so many in some ways better I felt using a dialup modem with terrible bandwidth and latency than I do now on my 5G pocket superc computer now a common response to this is technology is bad and we need less of it I'm open to that perspective but I don't think it should be a totalizing one we've got to also explore how the digital can return to being an expansive and enriching experience we've gone from it being symbiotic to parasitic how do we go back to being symbiotic that's the real game and the future of cryptography plays a vital necessary though certainly not sufficient role in this and it's why looking at cryptography strictly through the lens of what it can technically do is incomplete instead or in addition I think we need lenses such as this no one today thinks of cryptography in terms of nourishment um it might sound crazy but I think we not only can but perhaps must think of it in these terms because only then can we potentially discover or realize that it's actually a valid way to think about it we might even find out eventually it's the only natural way to think about it and as for enrichment this is a cryptocurrency conference so I want to emphasize I'm saying enrich you know kind of like the soil got enriched and we were able to support much more people on Earth not the uh the other one um one last lens from the super real is how can cryptography help us reenchant the digital it's not just now we can do do programming on cryptography even if that is very cool it's that cryptography itself is fundamentally a bridge between math and physics between the digital and the physical and perhaps between computation and lived experience so finally I want to spend a quick few minutes on what I'm going to call The Surreal I've got a quote here from Italo calino um that closes with if a new world were discovered now would we be able to see it and the definition of surreal a definition at least is Beyond reality so I want to start somewhere again probably a bit unexpected what's the greatest invention in the history of mathematics in my opinion it's the polom the ancient Greeks Romans Chinese they were all excellent in math but they were held back by not having something like polinomial representation but here's the interesting thing about pols even though they were invented close to a thousand years ago and even though they were instrumental to things even like the invention of calculus we didn't really understand how awesome were until around 200 years ago what happened then we got the first rigorous proofs of a theorem about pols that's so important we call it the fundamental theorem of algebra the thing about the fundamental theorem of algebra is it doesn't even work if you only have real numbers it only works when you have complex numbers and it turns out pols are just one of many things that make way way way more sense with complex numbers that's why I say the most unbelievable realization in the history of mathematics and arguably the world is that reality itself consists of more than just real numbers that the real numbers were nowhere near all that was required to Simply describe and reason about reality accurately complex numbers show up everywhere from Electronics to fluid dynamics to quantum mechanics and more what's more the reals themselves became more spectacular once we completed or algebraically closed for those are who are familiar with that notation once we completed the reals to form the complex numbers e goes from being the number that's defined as like the derivative of e to the x is still e to the X to being a fundamental basis of rotation in the complex plane Pi goes from circles being cool to being far more significant in part because the set of points equidistant from the origin becomes far more interesting in a two-dimensional complex plane than on a one-dimensional number line where you just have X and negative X and that's barely scratching the surface of examples so consider this if the real numbers aren't the full picture of reality should we expect anything else to be does the digital the internet the web and perhaps more not really make sense until we complete it with a unit of cryptography as the reals were to form the complex if physical reality is built on physics can we enrich a complex super Reality by bringing elements of the physical into the digital realm just as we've clearly brought elements of the digital into our physical existence and can this be a symbiotic relationship it almost can't not be to actually feel like super reality is there a complex big BL bang will it look like a Genesis block or something else is cryptography where silicon based life really comes from and what's more real places in the physical Universe we can literally never reach like we get light from places that are so far that if we traveled at the speed of light towards them because the universe is expanding we will literally never get there what's more real those places are places in this perhaps more vast complex reality that we actually can visit and so the last thing I'll say is in science fiction you know we see this phrase outer World sometimes will we one think of outer realities and I wonder when we hear a voice from an outer reality what we will look like by then and who will be listening and so I'll leave you with this final note as we uh take a few for Q&A thanks a lot for coming thank you Albert so to start the Q&A session the first question is how does cryptography as a fifth Force interface with the firmy Paradox are all the aliens encrypted yeah I love this question actually because I've always thought the firming Paradox was a little bit simpler than people make it out to be because the key is why aren't we observing things and given that for example we can observe an ant farm without it having any sense that we're observing them there's a pretty big assumption that it should be like that easy to observe stuff out there so that's not exactly what this question is saying but I just kind of wanted to point that out like what if you could cryptographically be like encrypt your mind onto like neutrinos and then flow through everything maybe that's happening right now and maybe that's where things will go so even just at that level like cryptography has helped me with my thinking around the fmy Paradox not saying that's the answer but I think it's people kind of skip over the whole like oh of course we'd be able to see it even though it's actually it's like literally trivial for us to observe life that is probably closer to what we are than you know maybe more powerful intelligences are to us thank you Albert um reminder that you can scan the Cure code to ask questions we still have two minutes of questions so many things you can ask Albert um there's one question one vot which is what's your suggestion for individual to contribute to this um so this can mean a lot of things right it can mean you know a lot of the stuff that people are showing here or it can mean the thing that I just talked about but I will actually focus on what I just talked about I I think as simplistic as it sounds my goal here is for people to recognize that sometimes just taking a moment to think about things can be surprisingly valuable that sounds really obvious and yet like how much time is spent trying to just take a moment and think and the talk here the goal of nothing else was to give an example of how many directions that can go in and and not in a way where I'm like I'm trying to convince you of something or or sell something or anything else like that so I think you may be able to contribute more than you expect by just taking a moment to think about what you know and what and your perspective and see how that might intermingle with stuff as for other ways I think there's a lot of great opportunities to ask folks about that overall so we'll go to the next one thank you um anyone you care more more about what you want to answer um sure I'll go with how do you see cryptography contributing to an Internet that is joyful symbiotic and expansive to use um I don't have much time but the quick answer here is uh the physical world has a lot of properties we take for granted and if nothing else we're evolved to like Orient around that even the fact that like non-f fungibility is like default on in the physical world and we need like sophisticated constructions to make things like essentially fungible like words are fungible in a sense to apples are more or less fungible that's only because we've gotten good at putting them all in a market and so on the digital world has like these inversion of a lot of properties so if nothing else I think cryptography uh is underrated its potential to enrich because it's a way for us to imbue the digital world with physical world properties and that's a lens that I think we haven't really explored much yet yeah there's the fungibility scarcity stuff but I think there's a lot more to go in that direction thank you Albert thank you another round of applause for Albert please thank you all right so we have a special treat next our next speaker is Barry White Hat a self-proclaimed Street cryptographer a longtime collaborator with the EF and zerox Spark Barry will wideboard out his thoughts on how to build with IO and more um I always a treat to hear what he's cooking up please welcome to the stage Barry White hat thank [Applause] you okay folks uh can you hear me okay okay we're going to do some whiteboarding stuff um so like basically the plan for today is to like architect some simple things using IO um can I turn this around so like do people have things that they would want to architect so like a couple of things I was thinking about doing is like how to do is how to how to oh p goes the other way how to use uh zero knowledge how to use IO to uh to make zero knowledge group that are just like a single signature to verify so you have this iio box it it does some stuff and it's bits out of signature and like once you check the signatures it's enough it's enough to say to to to know that that computation was done correctly so that's one thing that we could do other things we could do is like uh uh trusted setup uh other things we could do is we could do like a Bitcoin Bridge which is kind of more blockchain e uh anything else people want do this is supposed to be like interactive so feel free to like shout stuff out and interrupt me like I I want to have more of like a conversation here than like a a presentation your thoughts and send them as nutr across the Galaxy oh no that's too much can I encrypt my thoughts and send them as neutrinos across the Galaxy uh not today anything else okay well if there's nothing like just shout at me later I'll ask you again in a while so let let me turn this around oh yeah it's okay okay so basically the toolbox of IO is that we have like some program that we express as like Gates and we have some ins and some outs and then we do like the io thing we do this IO kind of like almost like encryption step and on the other side we get like a whole bunch of a whole bunch more Gates or more more information and it still has ins and outs but the like what's happening in the middle is impossible for us to figure out so this you can think of this as like an encryption step that takes a program it encrypts the program such that the output is like unknowable it's like all you can all you can do is like put stuff in and get the outs and you can like see stuff that's going in and coming out but you can't figure out like what the original program is uh so one example of this okay so let's take like a really simple example and let's say that our gate here is just like a uh and gate yeah so we have a really simple program as an and gate and we put it into our IO encryption box IO and then we get out this like more complicated representation right so this is this is also just like a list of like operations like M maybe it's Matrix multiplications that's what uh schemes ADP uh and Matrix branching programs you tend to use but maybe it's just like other binary Gates that's the local mixing schemes tend to use those so we get this encrypted format of our program but we have like blackbox access to it right so we can put inputs and we can get outputs so like this one this one takes just two inputs but there's like a whole bunch more gates here the gates are really complicated so we don't know what's happening inside our circuit but we are able to do like blackbox access so I can just put like I can just because there's only two inputs I can just go just calculate the whole truth table right because I have the encrypted program I can just put in 0 and I get out uh I don't know what I don't know what the truth table of andate is well let me try and guess so 0 0 1 1 0 0 uh 0 1 0 one one one okay that's it source of Truth this is and gate okay so we can just like these are ins out okay so we can we can just put that in and and like that's XR oh huh we good yeah okay okay so we can we can just go through and like do the whole uh State space enumeration and we can find out the truth table but we don't know if this is actually an anate or if it's a more complicated circuit but like what I'm getting at here is that like you're able to you have blackbox access to the thing right like the goal here is to try and build up this model so you're able to sit down and be like I can I can imagine how to make things with IO okay cool okay so let's do our first example then of our Z KP right because like I don't know if you've seen the kind of like tree of uh different the teag tree of different cryptographic Primitives but IO is kind of the the one at the very top because you can use it to implement all of the others so like as a way to just introduce the concept let's do zkps okay so let's say that like oh yeah let's introduce this other model of how to think about it so so we have our setup which is what we just talk aled about and now let's talk about like how we think about the io box so we have this IO box okay iio box does some things right so the first thing that it will do that it does is it it does some like we can Define some computation we want it to do and then given that the computation succeeds we get the io box to produce a signature so this is kind of like an if if computation I have to move over to the other side then produce the signature so if the computation succeeds then produce a signature so like this iio box has been encrypted and I have given it to you right so you have this box on your computer you're able to give it any inputs and the output you get is a signature of something okay maybe the signature is maybe we just signed the computation right so basically if we want to make a zero knowledge proof what we need to do is we need to have other colors we need to take this computation we just set that to be whatever the whatever the the the thing we want to prove is right for example if you want to prove that you have like 10 signatures from a certain public key what you do is you take your IO box you set the computation to be the verification of 10 signatures and then you have this Clause that like well if 10 signatures are here produce this other signature and pass it out so one important thing to remember is that we have a secret inside the io box yeah so let's do secrets we have secrets inside our IO box and inside our IO box what are our secret our secret is the uh the the secret key of this signature right and we have this uh it's not secret we have the public key so at the at the setup phase what I do is I create this IO box and I do the encryption step that we talked about on the previous slide and and now what I do is I I publish the public key and I say hey look if you ever get something that's signed by this public key you know that it has passed this this check right cuz the only way that you can produce this signature is if you execute the io box okay so this is how you do Zer knowledge poost do we have any questions so far yes there we go so the question is how do you trust the output of the iio box if you don't know the computation so like I'm using the computation as like a placeholder here but like when you do the setup you would Define the computation and you would sort of show people that like oh this is the thing that I set up so like IO inherently has this kind of like setup phase which you can think of as like similar to the zero knowledge proof uh trusted setup where you set up the circuit and you set up the com the program that you want to prove but you also need to set up the kind of like private key right you set up the private key and you you publish the public key and this is like part of the of the setup that you need to go go through good anything else okay oh Jordie oh no okay all right later Jordie um Okay cool so this is how you do Zer proofs uh so like a quick aside is there any other things that people are interested in architecting we have 10 minutes so I I have enough stuff to go through but if there's something people are specifically interested in we can think about them okay well feel free to interrupt me if something comes to oh that was signing things okay let's do that then at the end um so you want to have oh so you want to have like a dow that that has a private key and it wants to sign things but like what's the point of doing that is it like a you want to have an EA EA is externally owned account like a private key for a dow but like I don't it like the the reason I'm I I don't I'm concerned about doing this is that like well you can just have the dowo be a smart contract and you can just verify the smart contract did something as opposed to like verify the signature of something but like maybe Jordy means that he wants to be able to have stuff encrypted for the Dow that the D can yeah uh so Jord saying that he has he has an external file he wants it to be encrypted uh but he only wants you to be able to decrypt the file if you send funds to the Dow right yeah and and this and nobody knows I mean this file was encrypted and nobody knows the key except that though yeah yeah yeah okay okay okay this is kind of like is this witness encryption I'm not sure but yeah okay we can do that let's uh let me what was the other things I had written down here okay trust the setup okay so let's do the trust setup and then we'll then we'll talk about J St okay okay so okay so historically like we've done trusted setups for a whole bunch of different ZK applications and this basically means that we like gather Randomness from a whole bunch of different people and then we compute this kind of like uh special key that has certain properties and basically what I want to talk about now is how we can use IO to do that uh in a way that we don't need to in a way that's that's like more programmable that we can have this like Universal setup that we can gather Randomness and anyone is able to use that Randomness to do whatever they want with so here's how we do it uh so again we have have our iio box okay and our IO box does some compute and if the compute succeeds it produces a signature of the compute okay but in this case it will also uh encrypt something encrypt the output of the compute yeah and it's also able to do like a decrypt so this is kind of like similar to what Jordi was was getting at so it takes the input it decrypts it uh it it uh oh hold on I want to put this the compute at the end I want to put the signature at the end so it gets an input it decrypts it it does some compute on the thing and then it uh encrypts it and it signs it and that's that's all that it does this is our whole compute so it takes input it does this and it outputs the signature and it also outputs the uh this out also up puts out okay so like it's important to remember that like the io box is created with the with the process that we described at the very start where we have some some like binary circuit you like encrypt the binary circuit and you have this like encrypted circuit that you're able to execute but you're not able to like understand or comprehend you're able to do like blackbox stuff to it but you're not able to see you're not a able to see what's going on inside so this is like the the the core API of IO and this is the thing that you like once we combine this with the ability to take to make signatures we have this like authenticity that we're able to use the bootstrap basically the whole almost everything that a trusted party can do so like one way to think about this is that like you you have like trusted party like IO can be like a really trusted trusted third party right where you can just say to the io people the iio Box hey do this thing and sign this thing and then just give me the signature and because no one is able to see inside or affect what's happening inside this becomes a really powerful tool that we can use to build like all the systems that we ever wanted like imagine that if you could really trust Facebook or if you could really trust like these internet services that's kind of what we're getting at with iio okay so how do we do the how do we do the random number how do we do our random number generation so basically what we do is we we we we have this box and then we say to people that like okay you take a random number and encrypt it and put it into the box and then Inside the Box the Box will you encrypt it uh I have to put the secrets here so we have a public key and a secret key these are secrets so no one knows the oh well no one knows the secret key but everybody knows the public key so basically the user encrypts for the public key they put it into the iio box the iio Box does the compute where it decrypts it it it it combines it with the with with the previous Randomness that that was oh we need to have two inputs right one is not enough so this is input from the user and this is input from the current state so you have two inputs so it takes the input from the user it decrypts it it takes the input from the state it decrypts it it joins the two Randomness together and then it encrypts the output and it it returns that and assigns that so this is the so then what we do is we make it like a chain where like we have like this iio box kind of pass the value to the next one which pass the value to the next one and like what we're doing is that we're just stacking Randomness up on top of it of itself right and this is kind of like phase one of our trusta setup where we're generating this random number that no one knows and like the assumption is that like if any single parody uh includes uh honestly passes a random number then there's no way for anyone to to to know like to to to to calculate the random number right because in order to calculate the final random number you need to have all of the intermediate random numbers okay so this is how you generate the random number then like we have to make another box to actually use a random number cuz like with the with the trust setups that we've historically done they need to have a special property uh it's not enough for them to just be like random or whatever they need to be able to they need to have this like for the trust for the powers of to it needs to be like the G to the x equals g to or gt to the to the x or something like that I can't remember but like it needs to have a special property so we just we just make another IO box that does that so the io box has the same kind of like uh uh public key and secret key so we have the same secrets so it's kind of like these two these are two different trusted parties and they're able to talk to each other so this one encrypts some values for this one and this one takes those values and does some stuff with them and then we can have like our arbitrary compute here and we do our compute and we and it and it outputs the actual Tres up okay okay how is this any questions yes I think secret key is included in iob box but is it make able that no one's know that secret key yeah that's an important property here that we have to make sure that no one is able to know the secret key and that's one of the properties that we get from the like the encryption Step At the very start yeah so this is like a programmable encryption ah thank you M yep hello so if you are uh off skating the program does the programmer have any advantage by knowing the actual program and if so like how can other people agree that the program is corrective it's sophiscated yeah okay so this is I saw this in in one of the this is a question earlier uh that vitalic didn't answer but yeah I I think this is a good question so basically like in general what we would do is we would publish most of the program that the only thing that we really care about about about hiding is is is what this person was getting at that all we care about hiding is that is a private key like we're okay with someone like the property of IO that we care about is not that the program is like indistinguishable it's that the private key is indistinguishable like in most cases we want to tell you everything about the program we want to explain everything except the private key cool uh so questions like some intuition for the the blowup so if you let's say you implement CPS with this iio box uh and then if you have a more complex CP how does it relate to sort of the exponential blow up like what is a good intuition for how how much SI efficient it become as of the logic inside this box changes oh so it seems like you're asking two questions here like one of them is like what's the overhead of IO and the other is that like like is could IO potentially be competitive with dkps in terms of like Pro time are you asking both or are you asking one of them on the logic inside I box huh it's basically both questions that you you okay okay let me answer both questions then uh so the first question is that it depends upon the Assumption like different IO different IO schemes have different overhead like some of the more like extreme assumptions are actually pretty pretty efficient in terms of execution the setup is the main cost um but it remains to be seen it's still very early so I can't really give specific numbers or whatever um I'm not sure if like I suppose that like the thing that you're gaining from the io zkp is the succinct verifier the verifier is really easy it's just verifying a signature so it's much less overhead than traditional Zer knowledge proofs uh which tend to be like a couple of pairings uh the best gr 16 or F long is like a pairing and like some other scal mes and stuff so it's better uh it's faster ver fire but the appr time is likely going to be like really a lot worse at least in the short term uh but it depends on the the assumptions that we end up using or the basis that we're end up building things on so not really clear yet I don't think that Zer knowledge proofs need to worry about anything anytime soon I think that they are going to remain like this is more an example like this is more an example of what you can do I'm not saying that like oh this is what we should do yeah okay Barry it's Q&A time ah okay sorry Jord no it's great that was the first question um I'll read them from the ones with the most votes but feel free to not answer or skip to the next one okay um the top one is can you explain IO as explain me like I'm five and why do we need to use IO instead of other zkps ah ah like oh you know what like I feel like we got into so much trouble because we abused the zero knowledge proof not or name for such a long time than that like this question just it's hard for me to understand what this means by like other zerge proofs cuz I suppose that this person is thinking that like oh they just this blanket term for all like privacy technology and that's zerge proes so ah so I think that the key thing that iio gives is a non- interactivity I think that like that's the missing piece of the puzzle but zkps are that people use are non- interactive I think I think the person doesn't understand that yet that zkps cannot do everything far from it yeah yeah zero zero knowledge proofs are a single player technology iio is a multiplayer technology this is what we're this is what seems interesting about this we can take the other one which is how do we get from weeks to seconds for Io uh I suppose we just have to like try more we haven't really tried at all um I think I don't know like I mean well come on I know like we just need to work on it you heard that just go work on it the next one is what are exotic cryptographic assumptions oh I think they're like more like like do they want examples or they want like the vibe I I just think they want to know what you mean by that ah so there's like standard assumptions which are assumptions that people have made for a long time all like all cryptography is based upon assumptions because like there's this open problem in math that P is not equal to NP and that basically means that like some things are hard and some things are easy so because we're not able to prove that some stuff is hard and some stuff is easy we're not able to prove that any particular thing is hard and because we're not able to prove that any particular thing is hard we have to base everything we're doing on assumptions we assume that things are hard so there's different things that people assume there's things that been people being assuming for a long time and people are much more open to these assumptions because we've been making them for a long time but then there's newer assumptions that are more radical uh that that that and those are what I mean by exotic assumptions and if you're interested in that uh Brian Lawrence will give a talk about that in one of the workshop the iio workshop so there will be a talk about cryptographic assumptions um so that's it we're running out of time thanks everybody thanks folks and with that I will introduce our next speaker to the stage goep um goip is one of the co-founder of zor spark and the creator of Dark Forest please welcome him to the stage thank [Music] you hey everybody thank you for joining us this morning for the programable cryptography CLS uh the title of my talk today is contact and I'm going to be explaining a little bit about what that means short as a quick introduction I'm gub sheep I'm one of the co-founders of Dark Forest uh I coined the term programmable cryptography about two years ago and ever since then we've been exploring a lot of its consequences so this talk is going to be a little bit more of a mental models and Frameworks talk it's not going to be a a whiteboarding session or a session where we go deep into the cryptography um we are going to hear more about the technology in this afternoon's workshops uh and what we're going to do in this talk is you know we're going to look at some history and some worked examples of how we've come to build up even the ways that we think about programmable cryptography um at the end we'll also tag on some highly uncertain speculation of what we might do with those Frameworks in the future okay so the title of this talk is inspired by a Sci-Fi series this is the culture series by Ian Banks raise your hand if you've read or heard of these books oh actually it's pretty Prett pretty decent number so the premise of the culture series is that explorers adventures in the this universe where this transhumanist post scarcity Society exists and you know it's sort of there's a uh G galaxy-wide culture of all of these humans or transhumans that are involved in this Society um and one of the most interesting sort of agencies that exists in the culture civilization is the contact Division and what the contact division does is they're the ones who are essentially at the Frontiers or the fringes of the civilization uh handling all kind of interactions with any other extraterrestrial life or intelligences or things that they're finding at the fringes and one thing that I kind of want to prompt is what does it look like for ethereum or applied cryptography or programmable cryptography to have a contact division what does that look like okay so let's first take a step back and ask what are we trying to do here with programmable cryptography um the the various organizations the various individual contributors the various people thinking about programmable cryptography you know what is what is sort of the goal here with progammable cryptography we've seen a couple of instances of goals maybe it's realizing the the real or the super real or the sural um one framing that I really liked actually from Albert's talk and that you know I've been thinking about a bit myself as well is this idea of programmable cryptography as a fifth fundamental force and as we saw in Albert's talk um cryptography represents a set of extraordinary new capabilities that would a priori seem impossible much like how something like nuclear technology or the ability to harness electricity might have seemed impossible as well and my question in terms of what do we actually what are we doing here is we're trying to figure out how to even grapple or come to terms with this how do we even think about this what does this enable what are the right mental models for this technology what will the different path dependencies be to realizing this what are the right abstractions for the technology and how do you design the interfaces between each level of the stack here um in short you know we have to we have to Grapple with the same problem that nuclear technologists had to Grapple with you know in the last 100 years are we first going to make a bomb or are we going to make infinite energy and what are the sort of cross- dependencies both technologically and socially that are involved in figuring that question out or something like Computing you know it's it's very non-obvious in the days of something like the eniac one of these giant room scale computers that the descendant of this 60 70 80 years out is going to be something like you know virtual worlds like EV on line where hundreds of thousands of people are battling in a virtual space reality for control of virtual space planets right how do you even begin to start thinking about what might take you from the leth hand side to the right hand side okay so there's a lot of stuff that we could do that that wouldn't make sense um in particular it's easy to Rabbit Hole down one particular kind of programmable cryptography technology uh or to Rabbit Hole down like one particular sort of use case or or product or something like that but ultimately it's really important to to keep a solid head on your shoulders when you're approaching this question because this is a decades long civilization scale technology and we need to approach it and and take it seriously as such we need to build some foundations mental models in a way that takes seriously that a mental model needs to be useful on the time scale of potentially decades that doesn't mean we need to get those mental models exactly correct today but how we think about this should be credibly progressing us towards the goal of understanding how to think about this from a from a multi-decade civilization scale kind of scope now the other thing you have to avoid while doing that is you have to avoid getting sucked into the perfect system trap especially in a way that's not grounded in reality so the other thing that we could do is we could be like all right programmable cryptography allows us to do this crazy stuff this crazy stuff with tur machines with these crazy guarantees let's sort of sit down and and theorize for that theorize about that for a really long time and build some sort of like crazy like category Theory type Theory like you know correct by construction sort of thing um and then you know that that's real mouse trap too we don't want to go down that rabbit hole but somehow we still want to be making progress knowing that this thing has as Grand of a scope as it does okay so I want to talk about some of our thinking on how we've approached this problem over the last five years so beginning about five years ago we started to get the sense that there was something interesting happening in cryptography we didn't have the words to describe it we didn't have the the Frameworks you know nowadays people talk about the idea of oh you know ZK enables data interoperability that was not how we were thinking about ZK at all when I started building a game called Dark Forest in 2019 the way that I was thinking about this was I had just learned about ZK snarks from Jordy actually and I had this idea wow you could use zero knowledge proofs and blockchain to build this really specific and very strange game so dark forest was a game built on zero knowledge proofs on blockchain um it was one of if not the first non- cryptocurrency application of zero knowledge proofs and it just seemed like a total one-off hack at the time so um we spent this time we spent some time building uh Dark Forest and what we came to realize was actually there was a general principle going on which is that zero knowledge proofs were not just enabling this one specific game construction they were enabling this idea of incomplete information games or games where players have some private State on a blockchain or on a decentralized system where the whole state is public so that enabled us to you know that that came through building a bunch of other prototypes of of some other games this is a screenshot from a game we built called boat fight um and unlocking that realization allowed us to suddenly see what was going on with dark forest and this category of games and suddenly it became actually a lot easier to build the different kinds of features and even figure out what kinds of features we could add into Dark Forest so for example you know early on the into the game we introduced this idea of procedural generation that was enabled by this mental model unlock of what ZK was fundamentally doing here okay so then we get into uh so dark force was out 2020 this idea of incomplete information was about 2021 in 2022 we started experimenting with wait a second can we apply this principle across a bunch of other kinds of domains not just games so you know we built a bunch of these circuits we built um thing we had folks in the Xerox park community ecosystem building things like private message boards um ZK reppel over here is a developer tool for working with zero knowledge proofs there's stealth drop which was like private airdrops and we got the sense that what was going on was you know the Common Thread between all of these things and between the game thread was this idea of programmable privacy right and I I use privacy in quotes here because I I sort of am referring to a specific connotation of privacy which is oh I want to hide something I want to have anonymity or pseudonymity or something like that and we kind of distilled this down into this idea that ZK snarks turn cryptography problems into programming tasks it was much like what vitalic was sort of saying in the morning where uh we don't you know need a cryptographer to invent for us a new protocol for every feature you can have someone WR code and compile that into cryptography okay so from there once we had this notion of programmable cryptog programmable privacy we were like well let's step on the gas pedal here the point is now a bunch of people can make privacy preserving applications and those people specifically don't have to be cryptographers so we got a bunch of people together started bringing folks into this ZK ecosystem and we produced things like the first zero knowledge machine learning demonstrations stuff like handon with pseudonymous or Anonymous speech ethos which was the first demonst ation of recursive zkps in a consumer social graph kind of use case um things which would allow you to Port RSA identities into zero knowledge proofs and so we did probably like you know five 10 15 of these projects and that's what got us to arrive at this other concept called proof carrying data the idea that actually the thing going on here with zero knowledge proofs is not something about privacy or scalability like yes those things are very relevant particularly in the blockchain context but after building 10 or 15 of these apps we realized that what the zero knowledge proofs were fundamentally doing that was a Common Thread in each of these apps was they were enabling permissionless data porting from Source a to destination B so now you can move things like a GitHub Identity or an email or anything like that from this Destin um from this origin Source o over to this destination without needing to call apis or things like that okay so that gets us to proof carrying data um we built this framework called the proof carrying data software framework so this is a mental model that then got actually translated into a library and the beginnings of a software abstraction and then we started building a bunch of stuff on proof carrying data so this is kind of the the the Blind Men and the elevant sort of thing we were realizing that all of these eight things were instances of this common category um so a lot of our proof caring data experiments led us to Zulu which was a community that wanted to adopt decentralized identities cryptographic identities work with cryptographic data and we built this thing called zup pass which everyone here has used to basically uh claim their ticket generate a zero knowledge friendly identity um and store zero knowledge friendly data and we built a bunch of apps on top of this concept of proof carrying data with zup pass as one of our levers so we have things like you know the frog game you can make zero knowledge proofs about your frogs we had zo pole which was a polling app for the Zulu community that also expanded to a couple of other communities zuo cast or zookat which were these social sort of private social Message Board apps for these communities um just these various different things and we built a bunch of pcds proof caring data uh instances and we tried to build a bunch of stuff with them and then we ran into more limits and then we started to factor out well what are the common threads where those limitations are holding us back and this is what really led us to programmable cryptography so for example with proof carrying data and with ZK snarks we could only enable individual people to make proofs about operation on their own data but there are a bunch of places where we would want say two people or multiple people to be able to jointly compute across data that I have in my zup pass and you have in your zup pass and that led us to realize oh there's a very natural connection with these other kinds of general purpose programmable cryptography Primitives like multiparty computation and more another realization that we had was that even though we had this abstract concept of proof carrying data PCD um it was actually in practice really hard to use pcds what we'd have to do is we'd have to write one more bespoke circuit for every kind of cryptographic operation or every kind of you know proof carrying transformation we wanted to do and so we ended up with this whole repository of all these different circuits and PCD types um and we were back to kind of square one on well you do need a cryptography aware developer uh in order to even be able to engage in this ecosystem so that led us to programmable cryptography um which is the subject of this community-led session here today um and concretely what it means to say it led us to the mental model of programmable cryptography or this this way of thinking about programmable cryptography is it allowed us to figure out what the problem was and what the capabilities would be un what capabilities would be unlocked if we solved those problems so you know me and Andrew we took a look at all the stuff going on with pcds and we were like well this needs to become generalizable and this needs to become much more flexible so now we have pod and pod 2 as a result which we'll learn about more today in the afternoon sessions um we have uh if you can go to you can go to p.org to see sort of the latest on that um and then we started carrying out other experiments to see well now that we've been led to this next line of Investigation what what what might we do if we take fhe or obfuscation or these other Technologies to their logical conclusion so uh this Devcon if you've gone down to the Frog Hub you've might you might have seen this game called frog Zone which is as far as we're aware the first game where the back end is running entirely in fully homomorphic encryption like Justin mentioned we've basically built this four player game where you've got four uh four frogs on a 32 by 32 grid the frogs can move up down left or right they can collect items slay monsters Etc and all of that is happening inside a fully homomorphic encryption with 1 billion x overhead on top of what it would take to run this kind of a game normally on a you know plain text ordinary computer and that's unlocked some really interesting thoughts and it's sort of that is one of the thing the things that's actually led us to obfuscation because one of the huge pain points of building something like frog Zone if you've actually tried the game downstairs is that there is a ton of interactivity there's a ton of multi-party computation decryption that needs to happen the Wi-Fi keeps going down going out downstairs our Hardware switcher thing keeps failing and so there's no way that you can take this technology and scale it to something like a billion people unless you bring in a non- interactivity technology like obfuscation so each of these things has been essentially some sequence of figuring out what's really going on here trying to generalize what we currently know and looking for what is the general category of thing that this is and how do we solve that problem um each of these steps in the understanding tree for programmable cryptography has taken about a year and uh each of them has been a concrete step towards a grounded conceptual framework for how to think about programmable cryptography and what you can do with it so again like I said in the beginning none of these are complete Frameworks none of them are you the end all be all of how to think about programmable cryptography but each of them does build on each other and and we're starting to get hints that this might be a generally pretty good way to think about what you can do with this technology you know first starting with zkps let us build incomplete information games and decentralized systems then generalizing that to saying ZK snarks turn privacy math problems into coding problems then generalizing that into ZK snarks are about data interoperability and as vid Alik said actually earlier on a pan panel earlier this week rather than calling them ZK snarks we might just call all of these things proofs and then finally we we've you know come to this sort of model of programmable cryptography as this general purpose way to think about computation between a network of people okay so in essence what we've been trying to do over the past several years is build a machine to produce this kind of thinking and what is the mechanism by which this machine operates that mechanism is what I sometimes think about as contact with reality right so rather than sitting in a room and and theorizing a bunch about what might be an interesting system or what might be an interesting thing to put it put inside of a snark you know we'll sit down and we'll try to we we'll build a lot of stuff we'll take as much of that stuff as we can we'll deploy it whenever possible in as real of a setting as possible even if that's just to a few hundred or a few thousand users and then we'll constantly go through this process of looking back auditing pruning and synthesizing and trying to figure out what is the general principle what's the line that you can draw between all of these points here are some forms of what contact with reality might actually look like one is building a first endtoend prototype of some technology that we've never tried before so something like frog Zone again let's let's just try to put a server inside a fully homomorphic encryption even if it's a billion times slower and we'll figure something out another one is trying to build something that folks for whatever reasons will use or need or ideally love even if it's a small group of just a couple of hundred people um another one is teaching developers and providing them with different tools or sdks or abstractions and if that actually enables them to do something that they couldn't do before or understand something that they couldn't do before maybe maybe even build something that we could not even have anticipated if we can do that then we have some sense that oh this abstraction is actually something that makes sense that is is maybe worth refining and building on top of um by the way as uh sort of you know in reference to that that last particular point I think that Folks at Devcon should think very hard about the fact that every Devcon attendee now has access to a ZK friendly EDSA and semaphor key you know there's there's essentially you can think of what will you do with the Merkel route of all Devcon attendees in addition thanks to the Frog QR code scanning thing that's been going on there are hundreds of thousands of self-issued attestations now between attendees that form a dense social graph each of those frog requests is essentially your P your key pair signing someone else's public key okay so yeah it's important to make a lot of stuff equally important is not to get distracted so if something that we're building doesn't fundamentally make sense but has the potential to you know make a lot of money or score really highly on some notion of model as of metrics like users um knowing when that is not the right track to keep going down um another thing that we think about is if we're really here with the goal of testing out a new mental model not compromising on the mental model and getting that goal mixed up with something like adoption it's better to have a test with a thousand people that test the right kind of framework or mental or mental model than to scale to you know 10,000 or 100,000 in a way that is testing a different thing now the ideal thing would be to you know test with a 100,00 people with the right mental model but that's what we're working towards trying to scale up um and yeah the last one is being willing to constantly reassess resynthesize and move on from things that don't make sense or aren't working so we've had plenty of false starts in terms of how to think about what you can do with programmable cryptography okay so with that um I want to talk about a couple of new mental models or Frameworks that have uh come up even just through discussions over the last week with Folks at Devcon um so one is again this idea that interactivity really kills this is another one of those motivations for obfuscation like I mentioned we've been running this frog zone game in the basement of Devcon four players can get around and you know it's just a real difficult problem to get all four of the clients doing the decryption multiparty computation with every single operation in the game now when we think about something like interact activity versus non- interactivity that's something that doesn't sound as sexy as like now I can do arbitrary programs on encrypted state but it just turns out that for scaling these systems to millions or potentially even billions of people um you need some strategy for actually dealing with the fact that only the people involved in a computation should need to be involved in the actual process of running the computation and an interesting connection that actually someone made at at a mpf panel yesterday was wait maybe this is actually one of the reasons why ZK have been such a powerful technology that's been so accelerated compared to FHA over the last years especially with respect to blockchains we've actually had general purpose zero knowledge proofs for a long time now ZK snarks one of the additional things is that they're non-interactive you can make a one-hot publicly verifiable proof and this is a thing that's actually unlocked a ton of use cases and a ton of actual you know in the real world developer activity um another one that I think about um and I know I'm running out of time I just have I have two more of these um what is this idea of global private state so we've noticed that with things like fhe or MPC you can build these decentralized applications that have state you know imagine like a variable or a location of a monster or something where none of the participants in the application actually know that state but the state is being computed on correctly so in frog Zone there's monsters around the map that move around but nobody knows where they're moving to or from the servers and the maches are just sort of executing in fully homomorphic encryption advancing the state of the game one step at a time and the bat is just sort of its own like autonomous agent that's that's just moving around you know so one question is like you know I I had a moment when we got the bat moving around on its own working where I was like wait a second like what is the subjective experience of this bat like is this a new kind of agent it's somehow moving around in encryption there's literally no single computer or person or program in the world that knows where the bat is or knows anything about what it's doing and yet it somehow has this like independent objective experience where it's doing its own thing um it raises a bunch of interesting questions about cryptography and agency right like one thing that I think about also here is you know a cryptographic agent has a different flavor or affordance to it than an AI agent um a thought that then was prompted from that from some other folks who looked at frog Zone was like well what's actually going on with encryption we think of encryption as a technology for hiding messages but maybe that's not what's actually going on in the same way that zero knowledge in many context is not really about zero knowledge or hiding it's about proving and it's about data interoperability so maybe the thing going on with encryption here is you know if I mind uploaded my brain in encryption to you know some server somewhere in plain or sorry not in encryption in PL text to some server somewhere the operator of that server would be able to do surgery on my neurons to really really like with my subjective experience but if I uploaded my brain in encryption or in obfuscation somewhere the only way for the person operating that program to mess with me specifically would be for them to essentially take down the whole system because now all of the gates describing my brain are intimately connected with the rest of the off fiscated program you can either turn the crank on the entire program at once or you can just like destroy it completely that internal logic of the world is somehow preserved because of the fact that it's OB fiscated and the hiding thing comes out as an accidental property so you know going back actually to to one of the things Albert was referencing as well there's this idea of we call something X because we don't yet know what to call it it's it's pointing at the idea that the words that we're using to describe these systems are placeholders and they represent the fact that we just don't have a better understanding yet so we called it zero knowledge because we didn't know what to call it um now we're moving to a world of some maybe something like proofs maybe we call it encryption because we don't know what to call it and maybe it's actually about creating worlds with somehow mathematically unwind codependencies between everything maybe we call it cryptography or programmable cryptography because we don't know what to call it so that's it basically for contact um you can find out more about what's next uh this afternoon uh we will be talking about a bunch of these different systems that we've put into varying stages of production um hopefully over the next couple years years we essentially take these mental models and we can start building out a lot more mature systems uh and thank you everybody if you want a little froggy gift feel free to scan this QR code as well any froggy gift it's not any froggy gift this is most

Automatic transcript — names and jargon may be misspelled.