# ETHWarsaw 2023: Adam Gagol, Aleph Zero - The Future of Anonymity

- Channel: [ETH Warsaw](https://streameth.org/eth-warsaw)
- Date: 2024-10-07
- Duration: 18:18
- Topics: main stage, day 1
- Watch: https://streameth.org/watch/yt-SYES3gCw0Q4
- YouTube: https://www.youtube.com/watch?v=SYES3gCw0Q4

## Description

Presentation - A talk by Adam Gagol from Aleph Zero. This presentation provides perspectives on the future of anonymity.

Follow us for more updates: https://twitter.com/ETHWarsaw

## Transcript

he everyone am I audible uh yep great okay so uh sorry for very general title uh I'm going to speak about uh my perspective and opinion on future of anonymity in the context of uh ethics black cuts and hugs so uh first of all to set up some stage why anonymity not privacy as you've seen in the agenda so actually if you would like to Define these terms we can Define three of them these are various levels of how private you can get on blockchain so first is sudon imity this is the default so uh usually you don't have your name written on the blockchain you have just your pseudonym or address and then uh you can send some tokens from one address to the other and as you see on the uh on the right is going to be visible something like that so one address sends one if to the other address and everybody in the world will be able to see that the next level higher level uh is anonymity meaning that the action itself is public but the um tender or uh or the the party which is initiating it is not so what would be visible on chain is that someone sense one if to someone um and yet another level is privacy where basically what is seen to the public is that something happens so like some cryptographic um nonsense is published on chain which is basically meaningless for anyone but the party which is originating the transaction So today we're going to focus mostly on anonymity uh and uh just to to uh kind of sketch how it looks like normally because it may be not so obvious so uh L kind of has this vibe that if this is anonymous transfers it is not most of the time or almost never it is not Anonymous for uh for the Pary so the The Annoying Thing for many users is that for example here the Alice uh she's doing some transactions she's she's transferring some some tokens to some other address maybe staking something maybe swapping some tokens at at some point she decides to make a transfer to Bob we and the annoying part is that at this point Bob learns Ali's address and can easily back track all the transactions Alice has ever done so by interacting only once with Bob Alice is revealing the entire history of her transactions to Bob and even worse than that not only to Bob but to everyone also potentially malicious parties that would like to use it for some evil evil things so one may think that well you can kind of obfuscate it by creating some additional addresses so well unfortunately it's going to be still linkable and uh well there are pretty sophisticated ways to pretty sophisticated ways uh to to unlink it to to unmix it there are actually companies which are making uh entire business model around it around tracking transactions on the blockchain so this kind of kind of patterns that that the user can come up naturally are actually useless in this regard yet another thing which is often uh which often happens and which many people use many people do is use using some third party as a kind of a mixing service so this third party is typically a centralized exchange like binance uh so what you can do in order to to make a fresh account which is not easily linkable to the other to to the old one is you can deposit tokens on binance and then you can withdraw them on the other address and then well in effect you're using binance as a mixing service at least for the for the outside observers so it is effective to some degree um it's actually pretty effective uh at least if you would like to hide just from Bob uh what's bad about it is that well we're building this decentralized world and well here uh to to solve the problem of privacy we are using centralized service that's that's not the way it should be we definitely don't want to keep our tokens at exchanges at all times just for the sake of of privacy uh so we would like to get some get something better than that so what's better than than this third part is Crypt magic uh like cryptography is better uh the same pattern uh is often used in uh in services such as mixers or or anonymizers uh I'm not going to go into technical details how it happens uh I guess most of you have heard this magical phrase ZK snark it's a buzzword in the recent years so using ZK snarks and other cryptography it is possible to create a single pool which in this regard will will operate as sex on the previous slide so multiple users can deposit tokens to this to this pool and then by providing cryptographic proofs they can withdraw them to an address which will be seemingly unconnected and uh unlike in the previous slide where there is a exchange operator which naturally is able to connect the dots here there is literally no one in the world but Alice that would be able to connect it which on one hand is good but on the other hand is bad so also probably probably wellknown fact that uh tornado hash the most popular mixer have been used used by by many many hackers around the world um for example almost half billion dollars have been lered in tornado K by Lazarus Group which is known to be related to North Korea China is claims that 23% of the funds sent to anonymity polls in last year are from illicit addresses and itself already it's very very bad I think I mean we definitely do not want to support North Korea in any of undergoing uh we definitely don't want allow hackers to to Lander their money uh but even worse than that of course governments are taking the actions so even normal users get affected because uh the addresses of tornado cash and tools like that get sanctioned and then even normal honest users which have been using them just for the sake of of maintaining their own privacy for for which they have every right uh even they get affected by sanctions so it's a major problem I mean we privacy is definitely lacking in blockchains but it's very easy to abuse it and we've seen multiple cases of abuse already so what I wanted to explore a little bit are are the ways to make a tradeoff between uh remaining Anonymous uh and yet uh countering blackheads so there are few ways to to go about it some of them are naive I'll start with the more naive ones or maybe simpler ones and then go to the the more uh somewhat more sophisticated ones uh so probably the the oldest trick in the book uh is uh voluntary reveal or so-called viewing keys this is something that has been implemented in zash long long time ago it's actually also been implementing in tornado cash and many many other uh mixing uh or an it preserving products so how it works is that Alice in this example she keeps her full anonimity and there is no other party which is able to link the the addresses but she has a specific key a specific way to provide a cryptographic proof for anyone she she chooses uh which will uh prove the origins of this of this funds so um it's good because because Alice owns her data like definitely we we like Solutions where there is no trusted party which would have access to to Ali data it's good because it's useful for financial Audits and proving the the legitimacy of funds so for example if Alice wants to deposit funds on Exchange it's a convenient way to to prove that this funds were not uh not illicit and and they are from the legal origin what's bad about it is that actually it does not counter lering as I just said tornado cash had this mechanism and even though uh of course it was used for money laundering and why it happens is that well it's voluntary I mean it's highly unlikely that the hacker will choose to do any kind of reveal and surely it's possible to find someone to to just sell the tokens to perhaps with some small discount uh because of of the unability to prove but still there is market and I think one could argue that there will always be market for such a shady tokens uh to be to be sold at discount so probably we would like something something a bit stronger if we really would like to to counter uh this kind of abuse uh the second idea this one is a bit naive uh is proof of Innocence the proof of innocence in General is the idea that one can be can provide a cryptographic proof uh assessing that the funds did not originate from some some list of uh of addresses so like uh there is some blacklisting gate so there is some uh onchain list of addresses which are known to be either sanctioned or otherwise Shady uh and whenever Ali would like to deposit any funds to anonyms there is just a simple check whether the funds are originating from the list of this addresses so well yeah the good thing is that it's simple uh the bad thing is uh that it's pretty easy to circumvent U I think the the main driving example for me is usually the example where someone hacks a bridge for example and then wants to ler a money so in this uh in this example if Alice is fast enough that she can deposit funds before the hug is detected there is absolutely no problem for her uh so well that does not counter money lering at least not the not the kind uh that that have been on the previous slides so not the the loud hugs and uh and stuff like that a bit better meod proof of Innocence on withdraw so here Alice can deposit funds but whenever she would like to withdraw then she needs to present the the proof that this funds did not originate from from the from the bad addresses so the good thing is she owns her data and it seems to be actually effective like if anyone know something about the mixers usually people wants to keep the tokens in the mixer for longer time because otherwise just from the timing it's easy to to link The Exchange if someone link the addresses if someone deposits and withdraws within the same day let's say a big amount it's pretty obvious pattern and it's pretty obvious to link this to this two actions so here if Alice deposits uh and then uh then would like to withdraw before the address LS on The Blacklist well it's already pretty problematic because uh because this this pattern will be linkable of course there is a entire uh like uh entire list of problems with that so it's technically problematic she needs to compute the proof this proofs tend to be actually pretty pretty hard uh Blacklist needs to be updated frequently and well it's pretty subjective which address should be there which should be not so there is some decision factor which is not obvious how to how to go about it uh there is some problem with with black dividing the funds so again another technical problem and there is also weird scheme that Alis can can use so what she can do is she can quickly after the hug deposit the tokens then she can already withdraw them like uh there is a risk that that this will be linked but she's okay with that because she's going to deposit it again withdraw again deposit again and she's going to run the circles for perhaps entire week and eventually the HCK is revealed and the initial address is is revealed that this was the evil one but it's not easy to to act now because well there has been entire week of Alice running in the circles and in the meantime legitimate users have been also doing deposit and withdrawals so right now I mean we could ban all the addresses that have been used but then we would definitely ban some addresses of of honest users as well and that's that's is by itself as I said before like Banning and making problem for regular users is unfortunately something that happens and that's something that well we definitely do not want in this system either so this pattern I mean this is very problematic thing for for this proofs of innocence and I don't think there is an easy technical solution for it the last the last uh the last idea is external reveal controller or like that's how I how I call it so the idea here is that Alice needs to have kind of an ID in the system and uh there is some party outside that knows this ID so whenever it happens so that the hug is discovered and the the deposit to the to the anonymity pool then is uh is discovered that that was from the from the IL address then this controller makes a decision whether to reveal or to not reveal the entire Trace uh so this is uh there is some some properties of the ID system I I don't think I have time to to go through it uh but the the key question is well who is that controller actually so first note well the solution previous Solutions also required some some designated party at least to for example operate The Blacklist so it's not the problem only of this solution but well who is the controller so it can be a single party in the of course the most obvious scenario so for example there can be a kyc provider acting as such a controller to make a decisions what to reveal and what to not reveal it can be a group of parties uh that that uh share this secret so the decision needs to be done by the specific committee and perhaps it may be a DA that would be deciding which which address are really illicit and which things we really want to track down one point the last point the C it is that it's not the same actually as in the case of Blacklist in the case of Blacklist is only about the decision in the case of this reveal controller there is this secret that we don't want to to leak so besides the fact that we need something to make the decision like a DA we need actually a place to store this particular Secret so uh it's a bit harder actually than than making a dow for blacklisting although still still quite possible we can we can make I mean sharing Secret in big committees is very much doable so uh so it's not impossible uh yeah so that's that's very Mark so the conclusion is that yeah when it comes to coning black Cuts there are basically this uh three three ways proof of Innocence voluntary reveals and reveal controllers at least the ones with with I I've seen being explored and in Alf zero in the product we call Lial right now we're uh targeting the uh the reveal controller uh in the evolving way so we're starting with a very simple and then we're we're planning to make bigger and bigger committees and perhaps with time we experient with proof of Innocence but as I said before right now the techn problems we that seems seems pretty pretty hard to uh to solve so I think some some at least small cryptographic breakthrough is still needed to to make it operational thank [Applause] you
