New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Cryptography and Privacy in Context | Ying Tong | Web3Privacy Now Berlin Meetup 2024

Ethereum Cypherpunk CongressMon, Oct 7, 2024, 12:00 AM

Keynote #4: Cryptography and Privacy in Context | Ying Tong | W3PN Berlin Meetup Ying Tong x Geometry Research https://x.com/therealyingtong https://therealyingtong.github.io Support - Donate: https://docs.web3privacy.info/donate/ - Become a member: https://web3privacy.info/membership/ - Contribute: https://docs.web3privacy.info/contributors/ Explore http://web3privacy.info http://github.com/web3privacy/ http://docs.web3privacy.info

Transcript

um I I would say coming from Singapore but that won't be true to 100% um I think uh what a personally like uh of what uh inong is doing is that she's kind of cryptographer with a human face at the beginning we've seen legal people with a human face and I think that's a nice way of kind of like uh speaking with each other finding the common language although we can be from diff so many different fields does your mic Works test yeah please do okay thank you Mika and um hi everyone um thank you for being here and thank you Stella thank you Stella for bringing the energy and like zero into the space so my name is inong and I'm an applied cryptographer um I work on zero knowledge proofs so this talk is not about Seer knowledge proofs this talk is about my sort of my existential crisis um this talk is about how basically I felt decontextualized in my work and how I've managed to regain context um how I've managed to connect with people outside of cryptography and outside of the blockchain world um and S of Find meaning in my work so yeah in um May this year yes I went to Boston for the recap conference and recap stands for reimagining cryptography and privacy so this conference brought together a really diverse group of people there were defense attorney there were people from the ACLU there were activist organizers there were academics there were practitioners um and I was the only cryptocurrency person there and they were really nice about it um so the focus of this conference was first of all to highlight the ways in which cryptography and surveillance contribute to marginalization currently first of all to acknowledge that problem and then secondly to then reenter these marginalized voices that too often don't make it into the protocols that we construct um to resist the toxic aspects of Technology production and to work towards dismantling systems of marginalization with the tools we have cryptography and privacy so yeah for someone who's been working on zero knowledge proof for 4 years honestly what my life looks like on a daily basis is just it's just pols it's committing to pols oh my God evaluating them interpolating them folding them evaluating them in a different domain and then back in the original domain and I don't know like after two years of this I started to ask myself really why I'm doing this and um the reason I'm doing this the reason that I work on zero knowledge proofs and privacy enhancing Technologies is to help reenter marginalized voices and is to help fight these toxic systems um that worsen power imbalances in our society so this conference for me was lifechanging um in the sense that it changed my frame of mind it gave me new mental models and over here I've put down five of them um not in any particular order so for me these were profound um yeah and I'll share them with you right now so the first one is really meta is cryptographic metaphors so metaphors what metaphors are they are a familiar mental model that we use to understand New Concepts so when faced with like a new stimuli we map that onto something familiar something that we already know um and metaphors in that way are the realest thing ever metaphors shape the way we make reality we make meaning and cryptographic metaphors um shape the way we imagine protocols and we design protocols so there was one talk here that was discussing uh these two metaphors trust minimization versus purpose limitation so trust minimization is a really popular metaphor it's saying um basically yeah like actually all blockchains love this metaphor this is this meme that um as long as you keep data hidden from some centralized server you minimize the trust in that server um so you see here the example of privacy preserving machine learning whereby you encrypt the data and then you send the cipher text over um to the model um the model is trained on the cipher text and the results are then returned to you without ever having revealed your data the problem with this um metaphor is that it completely ignores the fact that this data can still be used for harmful purposes so like even though the server didn't see any of your real data they were still able to train their model to better Target you and so on the net um your welfare has been reduced even though um trust was minimized in this way so um this is highlighting sort of the limits of this metaphor in um informing how we assess um Solutions so um in contrast purpose limitation is a more useful metaphor so this is an example of um contact tracing apps swissco so it was developed to be so narrow and so single purpose that they shut it off um after the pandemic because they literally could not find another use for it um the app only sent random data it gave no information at all about people's location and identity and it was so useless that they shut it down and so this this metaphor of purpose limitation actually is useful in helping us design um applications that reduce harm so yeah this is an example of the power of metaphor um in guiding our thought um and guiding our decisions as cryptographers oh oh no I have an offline [Laughter] backup yeah yes that's right um so the next sort of Mind shift I had was an interdisciplinary one um legal cryptography hacks so this is still sort of related to the theme of metaphors so I learned um at that Workshop that metaphors have a very real ontological weight in the legal system so for example whether you call whe whether you compare encryption to a container um versus each um so now there's in in the US there's the fifth amendment that protects you from Forced testimony so it protects you it from having to reveal some secret that you have and for instance if you had an account that was protected by a password I couldn't force you to tell me the password because the password is in your head and if you tell tell me that then that's for Testimony but if you had a safe with a key I could force you to give me the key cuz the key is in your pocket is not in your head and that's not force testimony so depending on whether you call encryption an account with a password versus a safe with a key um that either precludes it or includes it in the fifth am protection so to me that was really wild um and the the thing is when these concepts are communicated to non-technical judges and juries metaphors are crucial metaphors are what help them understand it help them map it to something familiar that they know and so um yeah sort of how okay this is an example I took from the recent tornado cash proceedings um if you're not familiar one of the charges of tornado against tornado cash is that they're a money transmitter and the tornado cash people respond like we are not a money transmitter because um we don't control the funds like we don't control your private Keys we can't spend it so in response the doj said you know what what is a transfer like a transfer you can think of let's say USB cable transfer data do a a frying pan transfer heat a metal pan transfers energy to a juicy ribby steak this was from the document and so maybe yes for maybe to the cryptographers here this seems really funny however look they're not literally saying that tornado Cates a a a a frying pan but they're drawing this analogy to suggest um to something familiar something intuitive to the jury and a jury is supposed to make decisions that are common sensical common sensical is another way of saying familiar so yeah the persuasiveness of a metaphor that we can all understand um should not be discounted here so some more um legal cryptography hacks um so there's this project called Kalisto Vault um um it's a platform for sexual assault survivors to anonymously report incidents now um the incident reports and personally identifiable information are encrypted um to protect um the survivors um but the key here is that they are encrypted to an attorney to a legal outside Council and the reason for that is to make use of attorney client privilege because the attorney cannot be compelled to decrypt so to me this was like an amazing hack because um like a lot of problems in cryptography reduce the key management problems who's holding your key so in this case an attorney is holding your key and cannot be compelled to decrypt so I thought that was like really genius um and the same project also did another hack um um this time related to sub penas so they said yeah we're going to model the subpena and our threat model as um a situation where all of our servers are corrupted now in that case the best attack that these service can do is a dictionary attack which is expensive but the subpena cannnot place undo burden on its subject they cannot um request their subject to do something unreasonable to recover the data in other words they cannot compel the service to perform a dictionary attack so it's good enough that the best attack you have is unreasonably expensive so yeah this was I I think I think I'm just scratching the surface of legal cryptography hacks and if we could have a legal cryptography hackathon that would be like the chaos that I live for um [Laughter] yeah yeah um so I definitely leveled up here with some just a little bit of legal knowledge now the next mind shift is something I think Dara would um Dara Emma would resonate with um and it it has to do with the design process of our particles so if you're not familiar with cryptographic par calls often their model their effectiveness is measured against um how How likely an adversary is to succeed um in an attack against the model but the question here is who's the adversary so take this example of a digital identity protocol um so these protocols have three parties the holder that's you the issuer that's the your government and the verifier that's the bartender let see now um the thing is about these systems is that more often than not they're designed with the holder as the adversary so they're designed to protect the issuer and verifier from forgeries from um the use of expired credentials and this is um absolutely not a coincidence these systems are designed by those in power or people funded by those in power um so but what if um we're in a situation where the power imbalance doesn't fall that way so let's say a policeman stops you and asks to see your ID so the power imbalance here is definitely you're definitely not the dangerous one here you're definitely not the one that we we need protection against so why not think about protecting the holder so for example selective disclosure allowing the holder to reveal only what's necessary or for example unlinkable presentation defending a holder from multiple from being tracked by multiple colluding verifiers also like why why are we trusting the verifier why are we assuming that the verifier is always like in the right how does the holder know who the verifier is how do they know that the verifier is um allowed to even be asking them um for for that information um and if the verifier is like scanning something how does the holder know like what exactly the verifier can see um yeah and how does the holder um how does the holder know whether or not the the issuer is lying to them so yeah this these are all from the example of digital identity um and it reflects how power imbalances can creep into the design into these underlying assumptions um of our of our protocols so I think this point here is a point that Dara Emma made um at zon 5 um which is which is in relation to a class of protocols called compliance protocols that um compliance protocols that try to preserve some degree of privacy um except um when it comes to an authority or an auditor so this is to be compliant with for example kyc or AML regulations so in these situations should the protocol model um the authority and The Regulators as the adversary um it's an interesting question and um another example of um sort of the benefits of carefully considering your adversary is um this paper that came out recently about air tags um so this paper made the point that um a stalking victim has very similar goes to ATT tracking adversary so if you're being stalked you want to you absolutely want to De anonymize your stalker and Link an Airtech to their identity however if you are trying to track someone that's also your goal so this paper um managed to sort of Identify some um granular differences between these two adversaries namely that the stalking uh mainly namely that the stalker is always um in close proximity to the victim um and the victim is able to collect um more information about the stalker and de anonymize them so yeah I think for me previously reading papers I never questioned um who's the adversary and why the adversary is what the paper says um but after this conference I'm definitely really suspicious um and asking that about every paper I think Dara Emma said just now like a few hours ago like everyone should be an adversary in your models um I'm starting to think that's that's true um and um another sort of class of um entities left out of threat models are bystanders um so I think the point here is that um we need to question the assumptions underlying our threat models so um The Fourth Kind of Mind shift I got was um public perceptions of privacy and this is only possible um this only becomes clear from actually interacting with the public FYI um so there were a bunch of um anthropologists at the conference who had spent some time um in the field so this person was um observing UK climate activists and their opsac practices and they found that several of the activists were worried about the police case so they they thought that even having signal installed on their phone would look suspicious in itself like they had something to hi and they were particularly wary of this because of the possibility of undercover cops being in their midst so yeah this is this is um very valuable to know like that privacy preserving apps could be perceived as being suspicious or unsafe instead of providing additional security as we would have assumed perhaps um another interesting observation was from um um this study stud in Colombia where they found that people in Conflict zones become accustomed to just handing over personally identifiable information for example at military checkpoints and so the obsc practices there are degrade and it becomes normalized that people shouldn't have autonomy um over their data so I think these sort of perceptions of privacy are unspoken um very often um and can vary wildly depending on context and without knowing these without actually taking the effort to find out um um we wouldn't be as effective um in trying to educate or in trying to communicate um privacy and good offsite practices so my last um sort of concluding meta mind shift is that we diversity in the room um that's why I wanted to give a shout out to Stella I think Stella brings just a completely different bold daring energy into this crowd which we need um so from that Workshop I I interacted with people who have on theground experience who have deployed something IRL um and yeah these included defense attorneys activists organ izers standards bodies um and a lot of human computer interface designers so these interactions help us to discover knowledge gaps understanding gaps and to understand problems in context to understand why people might have some attitudes and beliefs that they have um another thing that was really valuable and special was the interdisciplinary perspective Ives so there were it wasn't just computer scientists and cryptographers there were a lot of um anthropologists in the room there were a bunch of attorneys legal experts um and so they bring a different perspective because they they think of things for example through the lens of power dynamics and that revealed like the the assumptions behind um who we assume is the aders um and they also taught me a lot of cool legal hacks so it's only by talking with people from different fields that we can find these overlaps um and that we can actually be creative um in these zones of overlap and yeah the last thing about diversity in the room is just talking to real people I guess this is the same as the first point but um yeah I I I think it Bears repeating cuz I don't think I've talked to a real person in two years um and um yeah like outside of our bubble outside of our privacy cult there's a A diversity of um opinions and perceptions about privacy and um there's also a bunch of different threat models like we can't always assume that we're capturing people's concerns in our threat models um the holder issue or verifier thing is one example the air Tex um is another example um so like for example yes stalking victims um for example marginalized people who are surveilled all of these threat models are not ours and it's only by talking with real people that we can learn them and begin to accurately model them so I think that's all I had yeah thanks so much for listening to my rant check check um some questions because we have lots of cool information here uh then then we will move forward so thank you a lot for thank you get

Automatic transcript — names and jargon may be misspelled.