# Obscura | R. Ramirez  - Privacy by Design: secure leaderboards with zk proofs on Aleo | ETHDam 2024

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2024-10-07
- Duration: 22:37
- Watch: https://streameth.org/watch/yt-V4VBtgp21uA
- YouTube: https://www.youtube.com/watch?v=V4VBtgp21uA

## Description

The video begins approximately 1 minute into the presentation due to a minor technical sound issue. We apologize for any inconvenience. Join Ramiro Ramirez, Solutions Architect at Obscura, for a talk titled 'Privacy by Design: Secure Leaderboards with zk Proofs on Aleo' at ETHDam 2024. Learn how to use zk proofs to develop privacy-preserving applications.
https://twitter.com/rami_decodes https://obscura.network/ https://twitter.com/Obscura_Network 

James Campbell - MC of ETHDam, Hackathon Organiser, and Web3 Developer.

ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. 

In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. 
ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich.
Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

We would like to thank our partners that made this event possible. 🌷
Battleship Partner 
🛳Oasis Network https://oasisprotocol.org/

Jet Ski Partner
🛩⛷  NEAR https://near.org/

Canoe Partners
🛶WAKU https://waku.org/
🛶Trail of Bits https://www.trailofbits.com/
🛶Avalanche https://www.avax.network/
🛶Privacy + Scaling Explorations https://pse.dev/en
🛶Threshold https://threshold.network/

Our Canoe Partner & Official Node Provider
🛶dRPC https://drpc.org/

Sponsor
🤝EF Ecosystem Support Program https://esp.ethereum.foundation/

Paddle Partners
🚣ChainSecurity https://chainsecurity.com/
🚣Lido https://lido.fi/
🚣Cyber Capital https://www.cyber.capital/
🚣Diva https://www.divastaking.net/
🚣Firn Protocol https://firn.cash/
🚣Beefy https://beefy.com/
🚣0xbow https://www.0xbow.io/
🚣Obscura https://obscura.build/
🚣Panther https://www.pantherprotocol.io/
🚣Maven 11 https://www.maven11.com/
🚣Zama https://www.zama.ai/
🚣zkSync https://zksync.io/
🚣Secret Network https://scrt.network/

ETHDam AfterParty Fren
🥳Bitvavo https://bitvavo.com/en

## Transcript

[Music] it's a little bit in the future too much busws and hype I want to bring the hype a little bit more concrete and show you some things that are already available some privacy based networks that are launching main it even this year so a little bit to inspire you to actually build a private private first tabs apps my name is Ramiro I'm part of cry apps we develop obscura obscura it's a it's a layer that we put on top or under privacy based networks that allows developers to connect easier to this new privacy based networks that are coming up very soon so this is a little bit of what's ahead of for this conversation I want to have a little bit on privacy uh CK cryptography all the buw I want to focus on privacy Network specifically on alio tell you a little bit what's going on there uh but let's Jump Right In so quick things you already been talking about this for the whole weekend pretty much what is privacy why do we care about it a little bit the why and the what so of course the why is a little bit what the previous talk was about uh we would like to be more proactive disclosing what we want and the what I think is something that is not entirely clear in terms of the solutions that we want to build uh you have of course ethereum that is completely open all the transactions all the addresses the volumes everything is is transparent there so that's a little bit of an issue um what we in the ideal world and this is also an invitation for you to think a little about what you want to have as a private statement versus a public state statement on a decentralized system so you have things like transaction details the metadata there are certain metadata then aggregation can be very dangerous but it's certain metadata that by the fact being public allows for compliance so we're going to dive a little bit deeper into this and feel free to stop me if you want to really zoom into one of these things uh but I think this is the hardest thing well for us it's been for a couple of years already but I think it's breaking more into the the common knowledge and and the public and developers that are coming from web 3 and even from web through because it CK literally enables privacy but in which way um I'm going to spend a little bit of time here just to showcase a little bit the the flow of a CK proof and how it works this depicting specifically a snark so we're going to go left to right and you may have already seen this if you already Dove a little bit into CK but I think it's important to highlight a little bit what's coming on on the flows that maybe you as a developer as a Solutions architect you want to start thinking about these terms of uh the identities that are involved in actually structuring things things like that so you have a prover you have a verifier the general thing that you want to understand about your knowledge is that the prover tried to states that the prover Knows X such that Y is f ofx what does this mean the prover on the other side needs to be convinced of that so usually you have a protocol that is interactive so provs creates a proof send a the proof to the the verifier the verifi offer a challenge in the same of a mathematical uh equation that needs to be solved and then it this is an interaction that usually happen at a statistical level the great breakthrough was having an Oracle in between that allows you to kind of skip that interaction to make it literally very succinct because of the size of the proofs can be very small uh but also non interactive which means that there is no interaction that needs to happen between the prover and the verifier what does this mean it means that you can effectively Implement these two subsystems completely independently and you can work asynchronously and that's a little bit of what's the new privacy based networks are trying to leverage uh in this example to to put it more concrete terms if I'm the prover um maybe in the use case of your an adult trying to buy alcohol online the very first thing that somebody will ask you is okay are you actually an adult and can you prove that under normal circumstances you will need to reveal uh maybe your date of birth uh something about your ID your name the issuer of that ID so in in the spirit of keeping as much privacy as you can about yourself you're probably not inclined to share all those things so in this example um I know x x will be the claim that you are above 18 is just a Boolean yes no are you adult in some countries you can consider to be adult Beyond 18 21 um the X in this case is the witness witness in you you will find in the literature if you brave enough to dive into the white papers you will see that the witness is literally the data that you care about generating a proof of so the witness it can be a private and that's kind of the most juicy aspect of that but it can also be public in our case our witness or data will be your ID the the your the DAT that you were born for example and what you're trying to compute is a proof that you're claiming that the output is y that yes why should be true right you are an adult and that's what a little bit of the exchanges what you see on top is the Sal is the idea change that in reality in implemented protocols U this doesn't really happen because now based on the current snark systems or any other modern proving system you kind of skip this and the prover is uh smart enough to just generate uh a proof that already contains challenges so there's no need to go back and forward a couple of times the proof itself contains the randomness needed that both the prover and the verifier shares in order that the verifiers can immediately start challenging the proof itself so I know this a little bit of a manful but I think it's interesting to have this in context for the conversation that follows and just to demystify a little bit because probably what you hear uh when you talk about Ser knowledge is the the idea of a snark and if you're brave enough you di a little bit deeper and you find Starks and plunks and Sonic and all the things you can read in the literature um I think CK snarks are the entry level for s knowledge and this is one of the things that if you want to dive deeper and start building privacy based applications it's good for you to understand this this very principles and and this is why it's so so rich so important and so useful the the secet part is because the proof doesn't carry any information about the witness the data that you're trying to prove so the proof only contains yes no and it doesn't contain any information in this example about my age or the ID or anything behind that it is synced because literally the size in bites and you have different flavors or ck CK proof some of them are bigger some of them are smaller and there's a little bit of a trade out between the size of the proof the time of generating that proof the time that takes to verify that proof and different systems or different solutions uh choose different CK proof systems based on these constraints and trade-off and depending on what you need maybe you need a a very short proof because what you're trying to optimize is the space on the storage of that proof maybe you need a different system that the proof can be a bit larger uh but B allows you to build a faster proof or the computation to build a proof is a little bit less expensive these are the kind of things that you you will consider if you dive deeper into architecting a Ser knowledge system um it is not interactive because of what I just described we skip basically all this thanks to an intermediate random Oracle and this is part of an initial setup that the prover and the verifier can can share a a secret that doesn't even need to be secret based on the new secret proofs like like PL for example um this also the last argument is a little bit confusing it's the argument of knowledge what does it mean but it's very rooted in the mathematics of it in the polinomial structure that this proof actually has but without getting too deep into the mathematics it basically says that the proof actually carries um an actual knowledge that this is it and you for this you need to trust me we're not going to dive deeper into this but if you want to find me afterwards we can go deeper into the mathematics of how you kind of actually encode arguments in proofs based on polinomial U so I'll leave you with that image um this is a little bit what I was talking before uh there's a plethora of CK systems many different teams very brilliant people have been working on this for the past decade or so the very first paper on on Ser knowledge was I think published in 1985 and it depict the idea of an inter active proof that the Challenger and the verifier like need to go very much back and forward since then I think growth 16 came in the 16 2016 and ever since you've seen like the ecosystem exploring basically mostly at a research level and this took quite a long time to be picked on the engineering side so a lot of Brave teams uh before I jump into the teams um I'll share of course the slides with you but a little bit of the what I was talking about before the different constraints and the trade-offs that you will have in different proofs and I will show you first the proof and later I will show you the systems different systems that are using these proofs so then you can make your own decision on based on the solution that you want to build what's a system that suits better your your own needs and that's a little bit of like as software Engineers what we try to uh need to try to understand what are the constraints that we have and what are the possibilities that we have to actually build a real life solution um coming back to the usage and I feel CK has been a bus word uh not for the wrong reasons but mainly because of scalability right uh you see polygon uh well how many other rollups you know better than me uh I hear rollups rollups rollups rollups rollups none of that is using C knowledge for privacy and since this is a conference for privacy we're going to skip all the rollups because I feel also been more in the public eye so you probably already know quite a bit of how to use your knowledge uh for rollups which is basically aggregating proof of transactions and bundling transactions into bigger bits so you can spend less in the finality where it goes actually to something like ethereum in a block this is where I want to focus on the the CK usage for for privacy um we as scura and and CA we've been working on on this side of the spectrum for a couple of years now and we had a chance to work with many different uh teams they're actually focusing on all these topics and you can see that this is pretty wide uh like range of solutions that you can build and later in this talk uh I will focus a little bit more on the gaming side just to give you a more concrete example of the type of systems that you can start architecting with this technology uh but what we see that is coming even this year and in the coming years is Solutions on on the defi area like an actual decentralized exchange that can keep the privacy of their users and it's not a Tri thing to to build but it's one of the very first things that you're going to see being built and launch even this year um the other big area of course is identity manage management so think about an encrypted verifiable credential the idea of hey you have your ID your passport every time you go somewhere that you need to prove something about yourself you're disclosing your full data what if you don't need to disclose your full data what if you can just generate a Ser knowledge proof that makes the claim that you were born in this country or you were not born in this country or you're above certain age and these the kind of solutions that we're going to start seeing in the coming years hopefully governance Dows right how do you make decisions together how you reach a a consensus as humans as part of a group as part of a squad um well messaging there are some applications on CK mailing or ck email uh if you goog CK email it's a really good project uh machine learning the ckl uh ecosystem is kind of exploding right now it is a big buzz word but also the research in terms of the mathematics on how to merge Matrix manipulations Matrix multiplications with a polinomial structure of information that you have in Ser knowledge proof there's a lot of uh teams that are starting to bridge that Gap so I'm I'm actually very excited about that I don't think we're going to have like production ready Ser knowledge machine learning applications tomorrow but it's definitely one of the most exciting things in terms of the complexity of the mathematics behind that and ultimately gaming um specifically gaming on if you're more coming from a gaming Theory perspective the incomplete information games things like involve uh two parties and sharing some Secrets poker or anything involving a fog of War basically um I want to introduce you to a little bit of what uh we've been working with and partnering up from from C and obscura these are the layer ones and layer twos that are using Ser knowledge specific spefically for privacy so polygon is a little bit of a X case because they do have their CK virtual machine and they're using your knowledge for scalability but also for privacy not going to talk too much about polygon because you know polygon um what I want to focus in those these three these are layer ones that are launching well in the case of Alo is launching this year mayet is already testing this on you can go and have a blast and try to build something cool like some of the things that we showed before uh Mina um they released last week on their test net Berkeley they release the programmability aspect of their chain so also you can immediately go and try to build something on Mina uh dusk is also out there is focusing more on the defi aspect of things very strong team and then we have the l2s like Aztec Works a little bit on top of ethereum and say with Manta going to skip polygon um I would like to focus a little bit more on on Alo but if you're curious about any of this please find me later and we can talk more about it you can also see that some of them have different trade-off they use different proving systems and they also use uh specific languages because when you try to encode logic that can generate Ser knowledge proofs you need to go through a process of arithmetization so you need to translate this logic into a mathematical circuit that eventually can be formally proven um different teams have found different solutions to actually go around that so you can see like iio using Leo um atic is using Noir is actually using typescript on top of a of a library that they they develop so depending on your preference of language as a developer you can kind of you can even use rust sometimes and you have teams like Risk zero that is like a zero knowledge virtual machine where you can just rust and that will generate proofs so it's pretty powerful um I'm seeing the time and I think I'm going to skip uh some of the I also want to have some time for you to ask some questions um but this is a little bit Elio Elio stands for auton Ledger execution of chain um Howard Wood the founder of Elo publish a paper I think it was 2019 it was called sexy um Zer knowledge execution the idea behind Elio is what you see here is the evolution of programmability versus uh privacy and you can of course everything starts with Bitcoin uh but as you can see like if you remember zcash that was trying to add some privacy on top of that butach still didn't have um programmability ethereum came to be and here we all are uh but ethereum of course is super transparent everything is public a was trying to merge the idea of a utxo model on terms of data structure that Bitcoin had and the idea of an account model that ethereum had so ELO came up with the record model where you can still have kind of The Best of Both Worlds where you can still store your transactions but also you can add private State on chain with specific logic um this is a little bit of the evolution of that that timeline um coming back on the things that you can actually build with this technology today uh with a caveat some of these things may be slow some of the things may be expensive um and some of these things may break but this is where we're all trying to understand what's the best way to build what can be built and what's the most coste efficient and secure way to to build this kind of things so um this is more like a suggestion to all of you to try to think about what are the kind of privacy based apps that can be built today just to inspire you of like all these areas have something that you can immediately solve using Ser knowledge without circumventing all the craziness that you need for adding privacy to this thing so what I mentioned a little bit before identity well you have verifiable credentials uh you have different ways of authentication without revealing some aspect of who you are and kyc if you're working more on the Enterprise side of things knowing your customer it's a is a very big deal and a lot of companies are trying to figure out how to do that without this over disclosing too much information uh gaming probably my favorite topic uh incomplete information games uh because now you have verifiable random functions that can actually be verified because they just can generate a proof and in a later stage in in the a synchronous way you can eventually prove something and verify something that kind of allows things like I don't know if if you're familiar with the actual Dark Forest that's one of very first onchain games put together in ethereum you could be rebuild your uh Dark Forest using Ser knowledge and you probably reduce the code size by like 1X like 10x or something um see the time I'm going to skim through this but come to me later we can talk about all these use cases but this is just to give you an idea of the things that you can build today and to zoom in a little bit of one of the things this was a project scor s was a project for hackathon that the obscura team did I think was last year in Paris uh this is just a glance to give you an idea of of the kind of things that you can start architecting uh with your knowledge and you start seeing like different entities where you will have like a verifier in your in your architecture map and you can start decentralizing and having things asynchronously and I'm going to skem through this come to me later if you want to dive deeper into into leaderboards the great thing about leaderboards if you make it private is that you can get the best of both worlds if you're a player of a rank rank based game you want to play pocker you don't care about the betting but you care to be top one usually what happens for onchain games is that what's going to be revealed in a leaderboard is going to be your address if I give you a price and that price goes to your address you have 1 million ethereum in in in that uh address you're going to become a Target because because that's public everyone knows that now you have like that amount of of value in that address with these kind of setups what you can have is instead of revealing your address you Reveal Your public username and in the back we can privately store on chain the relationship between your username and your address so you get the best of board words you get to brag about that you're actually the best because you can actually verify because you will have a Ser knowledge proof that you actually you are who you say you are and you can keep kind of your valuables because that's not exposed to the rest of the network um sneak peek if you want to write this in Leo for example this is a little bit how the code look like you can scan this this is a repository uh on on GitHub it's open source knock yourself out it's a tiny repository this is a little bit the same uh but implemented in a different language this is using AE Noir so you can have different implementations for the same kind of problem and you can judge what makes more sense to to your own use case um and I want to leave some space for question and know like on the mark yeah we probably got time for one quick question yeah nice thank you very much for that talk um the question I had was about the bit where you said that everybody's using different languages when they're using zero knowledges for for privacy um and my question is maybe like you could touch on that again as to why that's happening that that sounded very interesting more importantly where do you think that goes as in how that converges like because normally you have like languages that go out of fash and then the more popular ones they have like this network effect that mean that you know unless we can start imp zero proof with solidity it makes it more and more restrictive and prohibitive what what are your thoughts on all these different languages two things B what I would like to happen is that everything converts to rust so nobody needs to learn any other language what I see in reality is completely the opposite that you're going to start seeing uh domain specifically languages dsls uh like ELO lad Noir like something else just because teams had a lot of trouble um encoding logic into Ser knowledge arithmetic circuits that can generate proofs that's kind of the most active area of research how you can do that an optimal way and that's why entire companies are being built to develop Z knowledge spirital machines so it's uh it's going to take some time um if you learn Ross you're good because a lot of of companies are also trying to kind of converge into Ras there are a few virtual machines that now can compile Ras code and generate proofs out of that uh that's a little bit the the point like those domain specific languages are there to easily encode the semantics that you will use on a s knowledge kind of architecture thinking about the prover and the verifier and the witness I hope that answer your question thank you very much that was really good well thanks a lot please connect to us on Discord uh here we can all the question questions thanks a lot [Music]
