New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Navigating Privacy & Scaling Explorations | Panel | ETHDam 2024

CryptoCanalMon, Oct 7, 2024, 12:00 AM

Join panel discussion on “Navigating Privacy & Scaling Explorations” with Vivian Plasencia, Tyler AtHeartEngineer, Hendrik Eeckhaut, and Sam Richards at ETHDam 2024. Moderated by Hodlon (Coordinator, PSE). https://twitter.com/ViviPlasenciaC https://twitter.com/AtHeartEngineer https://twitter.com/heeckhau https://twitter.com/samonchain https://twitter.com/PrivacyScaling https://pse.dev/en https://tlsnotary.org/ https://maci.pse.dev/ MC of ETHDam, data aficionado and your favourite wooden bowtie - Jonathan Knegtel. https://twitter.com/jpknegtel ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz We would like to thank our partners that made this event possible. 🌷 Battleship Partner 🛳Oasis Network https://oasisprotocol.org/ Jet Ski Partner 🛩⛷ NEAR https://near.org/ Canoe Partners 🛶WAKU https://waku.org/ 🛶Trail of Bits https://www.trailofbits.com/ 🛶Avalanche https://www.avax.network/ 🛶Privacy + Scaling Explorations https://pse.dev/en 🛶Threshold https://threshold.network/ Our Canoe Partner & Official Node Provider 🛶dRPC https://drpc.org/ Sponsor 🤝EF Ecosystem Support Program https://esp.ethereum.foundation/ Paddle Partners 🚣ChainSecurity https://chainsecurity.com/ 🚣Lido https://lido.fi/ 🚣Cyber Capital https://www.cyber.capital/ 🚣Diva https://www.divastaking.net/ 🚣Firn Protocol https://firn.cash/ 🚣Beefy https://beefy.com/ 🚣0xbow https://www.0xbow.io/ 🚣Obscura https://obscura.build/ 🚣Panther https://www.pantherprotocol.io/ 🚣Maven 11 https://www.maven11.com/ 🚣Zama https://www.zama.ai/ 🚣zkSync https://zksync.io/ 🚣Secret Network https://scrt.network/ ETHDam AfterParty Fren 🥳Bitvavo https://bitvavo.com/en Timestamps: 0:00 - Introduction 0:43 - Discussion on Programmable Cryptography 2:10 - What Does PSE Build? 2:25 - Understanding PSE's Role and Projects 3:06 - The Goal of PSE: Bringing More Cryptography into the World 4:00 - Programmable Cryptography and Its Relation to ZK 6:13 - The Importance of Protecting Identity in Systems Cooperation 9:10 - Real World Use Cases Solved by PSE Tools 10:37 - The Importance of Selective Disclosure in Protecting Privacy 12:48 - Future Aspirations for Privacy Protection in Transactions 13:23 - Discussing the Experience within PSE and Working on Projects 14:06 - Lessons Learned from Working on Privacy Scaling Projects 14:46 - The Importance of Adoption for a Solid Project 15:12 - The Challenge of Building Cool and Assuming People Will Use It 15:33 - The Paradox of Privacy Products and User Experience 16:03 - The Journey of MACI Project: From Research Post to Implementation 16:28 - The Need to Demonstrate Use Case for Developer Adoption 17:00 - The Vision of Running Government Elections on Chain with MACI 17:38 - The Importance of Building from the Ground Up and Making Demo Apps 18:04 - Making Privacy Tech More of a Feature than Added Friction 18:54 - The Need for Good Documentation and Code Examples for Developers 19:23 - The Role of Documentation in Making Tech Accessible and Understandable 20:00 - The Importance of Good Documentation for Developer Experience in PSE Projects 22:02 - Recommended Tech Stack for Developers Wanting to Get Started with Advanced Cryptography 23:12 - The Role of Security in Emerging Programmable Cryptography within PSE 24:00 - How Security People Can Get Involved with PSE 25:03 - The Importance of Open Source Contribution in the Space 26:00 - How to Make Advanced Cryptography Accessible and Understandable to Developers

Transcript

[Music] so next up we're going to be navigating privacy and scaling Explorations I'm interested to hear what's going to happen over this discussion the guys that are standing around the back if you want to come and actually sit down again if you want to stand by all means I've said this for the 10th time today um but I'd like to welcome hold Holden to the stage and he can introduce the panel members and we'll go from there and don't forget to ask questions on slido um and then we'll make sure to get to those yeah let's come on up hi everyone uh we're going to be talking about uh programmable cryptography and the tools that psse is building uh after some uh introductions in the panelist Tyler do you want to start yeah yeah we only have one uh hi I'm Tyler I go by adart engineer I'm a technical project coordinator within psse uh working on TS notaries zekk email and a whole handful of other projects um yeah H thank you hello everyone my name is Vivian Placencia and I'm working as a software engineering engineer in the privacy and scan expiration team and I'm working on SEMA for bandal and also CK kit and y happy to be here hey everybody my name is Sam Richards I work on a project called Macy which does Private onchain voting which we might get into I'm I'm not this handsome guy up here I swapped in I'm the bald guy who's just replacing um for now but excited excited to chat with you guys yeah and so again quick reminder if you have questions that come up uh while we're speaking if you go to slido um you can put them in there and uh we'll hopefully uh we'll get to at the end um so can somebody uh take on the question and tell us um what do we build at psse um are we building web 3 infrastructure are we building products are we just doing research maybe all of these things none of these things somebody want to uh take the first thing first question so psse stands for privacy and scaling Explorations we are funded by the ethereum foundation you could call us like a research group within the ethereum foundation I would say we we do a broad range of things we probably have you know 20 or so project teams doing things from research in different areas of cryptography to building tooling and infrastructure to actually building like user facing um applications to kind of demonstrate what's possible with this Tech um yeah what would you guys say yeah so I think um our primary goal is getting more cryptography into the world right there's um a lot of stuff that lives in Academia that never makes it to the real world um because there is this kind of gap between um you know the people that are capable of writing these academic papers coming up with these techniques and the people that actually uh can program these things and make sure that they're actually secure and really our goal uh for most of this is not the immediate blockchain effect of you know I can prove something on chain or I can you know carry some data on chain it's really um making the second and third order effects that will eventually lead to all of everything being digitally signed or being able to be approved on chain there's one panel i' say most people um here might be familiar with uh the term with zero knowledge zero knowledge technology um there's a term more recently programmable cryptography that's been uh come about and been used more often can you tell us about what programmable cryptography is what it means and how it relates to ZK yeah so um ZK which yeah most people have probably heard of at this point zero knowledge um is just one subset of advanced cryptography so there's multi-party computation and homomorphic encryption which we're also getting pretty deeply into now um and yeah the whole idea is um back in the day when there was just signing and encryption and you know hmax like very simple Primitives that's all there was now there's techniques to make this more generic so you don't need to understand all the underlying cryptographic Primitives that are actually being used under the hood you can just use something like circom or Halo 2 and be able to um just understand the logic space that you're working in and be able to do you know practically anything so you can you know have parties cooperate together and be able to hide information or just have you know with ZK you can just prove something one way fhe you can you know uh hide encrypted user data and have other people be able to operate on it without ever revealing anything there's all kinds of cool stuff you can do and we're trying to make this readily available so I have a I have a question for you Vivian um can you give us some examples of um PSE projects that are used by other psse projects um within within the team uh within within privacy scaling Explorations and maybe also psse projects that are used by other projects in the ecosystem yes um we have a project called semafor and another called bandala and we are using semafor in bandala and also that's inside PSC and outside PSC I will say the Supa bu project is also using in semafor so so yeah that two examples of one in inide PSC and one of Tai PSC yeah would just say I mean what's interesting with this new programmable cryptography space it's very similar to you know early projects in the blockchain space of like you realize we're building these Legos that can kind of plug and play together and I think it kind of goes back to your first question of like what does psse do like do we do infrastructure do we do products I think some of it was just kind of exploring this design space of just like what use cases come out of this ZK stuff and like we don't really know let's kind of Tinker around and figure out and learning some of these use cases like I work on you know a voting protocol I mentioned um sometimes to like build a workable production use case you realize the tooling for a space doesn't really exist and you're like okay we actually need to build a lot of infrastructure and I think probably a lot of blockchain projects out there that can relate to that of like you know you go out to do one thing and you're like wait there's no [ __ ] tooling for this we got to build the foundation first to actually enable the use cases on top but I think through going through a lot of those processes the past few years we've now kind of assembled a lot of these nice little Primitives and building blocks and Vivan you mentioned semaphore which you work on which basically just allows creation of anonymous groups um and there's similar projects within psse that allow for like taking government identity putting that as a proof um potentially on chain of like participating in something if you are a citizen of this country right and like cool places where that's kind of interplayed is you know you mention zup pass is a project that does event ticketing among many other things that's built on semafor um Macy is a voting protocol that needs some sense of authentication or Cil resistance for like how does someone participate in a vote what gives them authorization to do that um and we can build you know like onchain gate keeper contracts that says hey anyone who has this event ticket in zup pass anyone who is a member of this semaphore group can participate in this vote um so it's almost these like yeah like cryptographic apis that you can kind of plug into and consume um and I mean it's one reason we're all like sponsoring this hackathon is because there's a lot of emerging use cases of like hey if you like grab this and grab that and plug these together like that's actually an interesting emerging use case Yeah you mentioned uh ticketing you mentioned voting um I'm curious if any if any of you uh if there are any uh use cases like real world use cases um that uh the tools that psse building is kind of solving uh or or maybe um Can should should look at or or solve within psse or anywhere in the space um yeah so yes I will say h Anonymous feedback for example um you can H send your feedback uh using Google forms H but it's Anonymous but not um you cannot prove that you are part of the group for example if you want to send feedback here how you can prove that you are part of the event so that's the difference H with Google forms you cannot prove that you are part of a specific group and then H send the feedback so that H with semaphor which is a protocol C protocol for anonymous interactions you can do that you can join a group and then do a many things there H like H send feedback or voting or any other interaction and this way you can prove that you are part of the group and then do the thing anonymously so that's the different so I would say Anonymous feedback or Anonymous voting or things like that Tyler do you have any I think uh more generally being able to cooperate in systems and hide your identity is kind of generally like where I want to go with a lot of this stuff so uh you know semaphor is a very good primitive for that but yeah like ticketing voting I mean like really we're um potentially building a lot of systems that like Dallas can use and stuff like that like you know eventually governments could use these things um but yeah really it a lot of this comes down to being able to uh protect your identity and be able to cooperate with systems cooperate with other people yeah similar to that I mean I think generally an exciting area is just like unlocking web 2 data and bringing that on chain among other things I mean shout out to the TLs notary folks for for doing some of this but yeah in the identity space like I mentioned of just like if you can prove certain things about yourself in real life like whether it's taking a government ID giving a proof about that um but giving it in a way where you kind of have this selective disclosure of like hey you don't need to see all the information in my government ID you don't need to see my specific address or my specific birth date I can kind of selectively disclose and prove to you cryptographically what things about me actually matter for this specific application like just that I'm above 18 just that I live in this jurisdiction um and like empowering applications to be able to yeah like only take like what is the minimal viable information that I need from this user to to authenticate them and Empower to use this system um and I think just like yeah for what I think all of us here care about is right just protecting our privacy and I think that selective disclosure is just like a huge empowering uh primitive yeah uh one of the things I would love to be able to do one day is buy a house and hide as much information as possible right you need to prove that you make some income and you have some amount of money right and you have a good track record of paying your bill bills that's it right now you basically have to send a bank your whole life right which is insane right I they shouldn't need to know my social security number they shouldn't need to know what I bought last Tuesday that's crazy right they should just know that I'm a responsible adult and can pay my bills that's it and I'd love to be able to prove that so I want to shift a little bit um and talk about um your all's experience uh within psse um and working on projects um uh psse has uh Sam you said about 20 projects say several dozen projects all in different states um some of them are just starting some of them have been uh going on for a while some have been completed and wrapped up some have uh halfway through pivoted to uh some other use case um and some other thing entirely so I'm I'm curious to hear about um maybe the most important or one of the most important things that come to mind uh of things that you've learned while working on these projects within privacy scaling Explorations yes I can start so I will say adoption is very important if you are building a a package for example um you need developers H using this package H to get feedback with this H this is very helpful because you can improve H the package in this case and we have improved the some of the projects A Lot H thanks to that and yeah I think that's very important and the same for applications so I think adoption is very important H to to to have a solid project I agree it's it's a big challenge because I think I mean what attracts a lot of talented smart people to like a research group right is to get to work on really interesting problems but it really is the classic of just like let's just build cool [ __ ] and assume people will use it um and I think from a lot of these conversations today and probably this weekend like privacy products in particular are just really interesting from just like a product strategy perspective of like often you're like adding friction to the user experience um when people maybe don't really care about privacy until they really [ __ ] care about privacy because they really need it right so like the education and awareness around like hey here's why we think this will be useful in the future and and how you could think about doing that um so I'd say like a challenge for us or like maybe just learning from Macy is like you know Macy's a project that's been around for like four or five years now it started has like a vitalic eth research post and like hey we should do like collusion resistant private voting and you know people built an implementation a few years ago and just kind of like hey we did it we're done we're good but like no one really built on it um and to your point of adoption it's like sometimes you can't just like build a protocol and just assume devs will come and use the thing sometimes you kind of need to demonstrate the use case and like build something useful so that other developers see oh here's a product that was actually built and there's actually demand for this thing so maybe I should invest my time to also build this thing um so like one thing we've just been experimenting with recently on Macy is like well [ __ ] like maybe we should build a usable application and find a good use case to kind of prove that out and like our end goal is to eventually run government elections on chain right and like we think Macy or in iteration of Macy is one way to do that but it's like okay we're going to pitch governments to adopt this blockchain application and expect them to just use this we're like okay well first we should probably find ways to like get onchain projects using it so okay optimism's running a retro pgf round and distributing grants of you know $100 million we recently like put together a proposal of like hey we could build that stack using Macy and make it onchain and make it private and make it usable and since then we've had some small communities come to us and say like hey we want to run little rounds on this so I don't know we definitely don't have the answers we're still feeling our way into it but I think that's been one big learning for a lot of projects in the space is just like that kind of chicken and egg problem of like okay like we need users we believe this privacy Tech is really important but sometimes no one really cares about it yet so like how can we make it more of a feature than just like added friction that like you know only the really serious people who understand the Privacy implications are using this stuff yeah I think uh the best education sometimes is showing someone what something is capable of right and that's uh we're wandering into territory that no one's really played with that much like there's you know maybe a couple thousand people in the world that really work on ZK stuff deep down um yeah a lot of these questions are very unanswered and uh a lot of the stuff we build is very low-level Primitives and yeah if we don't have the tooling on top of that the infrastructure on top of that then a developer is not going to even know uh what to understand and how to use this thing so we kind of have to start building from the ground up and then yeah making demo apps and stuff like that I think is is super usable or super useful to show how some of the stuff is is actually usable in the real world so I'm definitely looking forward to playing with more of our stuff and building more of our stuff uh out so it's actually uh yeah usable and fun to play with how do you make that accessible and understandable to other developers and to end users and is it the documentation you know often talk about make it build the documents uh you know as the first place to send people have you found that that works um have you found other ways to engage the community um to to help yeah I think it depends on the project H every project is different if it's a package for developers is different than an application or an infrastructure so if it's a package H having developers using it h and we can we need a good documentation code examples and boilet plate template um yeah make it easier for developers to build with it and so yeah I would say developer experience is very important for all the PSC projects and that's very important uh for that so yeah it depends on the project but for developers I will say that and maybe for others is is different yeah I think um um you have to kind of inspire some curiosity from like certain devs won't understand a lot of what's going on but if you can kind of show them like hey this thing is useful and you know really unlocks a lot of capabilities they're willing to work a little bit harder than just like oh I'm going to use you know should I use this framework over this framework like react or view or whatever then you really need good documentation but yeah if you have something that's like super powerful they're they're willing to do a little bit more work I heard you earlier convincing a application developer to learn circom an example yeah yeah yeah yeah so yeah this is a kind of a common problem that we run into is uh someone comes to us and is like hey can we use this library to do this thing and it's like well no because of this one nuanced thing but if you knew a little bit more you could just modify this and do that yourself and yeah once you kind of unlock the ability to to do things like WR circom and actually be able to um kind of develop your own stuff instead of just like taking cookie cutter stuff some other people have already made uh you can do a whole lot more I mean it just it unlocks so many possibilities some cookie cutter and glue yeah um so if you uh if you're a developer um in the space and you're wanting to get started so say there's a developer that does want to get started with Advanced cryptog or with Advanced cryptography um what kind of background is good for that um what is the best Tex stack you would recommend they start with yes um so if regarding the background you don't need a to have a solid math background to start with cka that's a common question I think you don't need it if you are going to create CK apps and if you have it it's better I think uh but if you don't have it you can just play around with it and and that's fine and regarding the tech stock I think that the best one to start H is still H circum and snars so that's what I think and for fre War applications I still think that is circum is Nas I think uh nor will be nice in the future and but I still think that [ __ ] and snar JS are the best for fre World applications and so yeah let's see what other C dsls appear in the future so yeah but for now that's yeah I agree sirom JavaScript is probably the best place to get started some solidity background would be good so we have some questions from the audience we're going to spend the last couple minutes answering those you ready yeah okay um the first one um there's a couple questions in here I'll just read it out um how big of a concern is security with emerging uh emerging uh programmable cryptography cryp crypto within psse so how big of a concern is security and where does the responsibility Ally for auditing like on the infrastructure app layer or both it's a good question it's a tough one I would say like it depends where the project is at right like a lot of what we do or what we started doing right was just like very early stage Explorations and really just tinkering around with stuff so if you're just building a proof of concept right like you don't need to pay hundreds of thousands of dollars for a security audit but like if you're putting it out in the world and and things are getting use and adoption like you need to start start considering that like thankfully like we do have an internal security auditing team that does at least like help with uh projects who are looking to you know release a you know a public version or what have you um but yeah security security matters in the space right really really depends on the application you're trying to build but uh you should probably think about it related to that uh GM hacker asks how can security people get involved with psse are there break our stuff yeah find exploits um yeah I mean I feel like we have a bug Bounty program maybe I'm making that up um but like we've definitely talked about it yeah what's definitely cool I'd say is like everything we build is open source and is on GitHub and we have a public discour and like we've hired plenty of people who started as like GitHub or Discord contributors right or like hackers who who built on our things um so I think like yeah just by like opening issues pointing out bugs um that's a great way to get hired in the space generally right like open source for the win yeah it's also a great way to learn ZK like if you want to dig in on some of the stuff we've written in circom uh to try to find exploits or like under constraints then uh that's yeah also a good way to learn so sem4 is like relatively simple um Arin is relatively simple but are super powerful you can dig in and try to understand like what's actually going on under the hood and um yeah I mean we've had people come in to our Discord and like drill me with questions about rln and like you know making sure the implementation's correct and like um yeah I mean it's it definitely comes up pretty often uh we concentrate a fair bit of effort on audits um but I think really um if it's not handling money if it's you know not got a lot whole lot of users yet then you don't have to concern yourself with it a whole lot yes I I agree for example H SEMA 4 is being audited the the version four is being audited right now and yeah with h since this project is used by H internal and external projects uh yeah we think that that's very important so so yeah we are in this process of auditing the the code so maybe just to wrap uh the panel up uh we can mention that uh all of us and other members from psse are going to be at the psse booth uh in the back back corner so if you're uh a hacker if you're in the hackathon or if you have a project or you're just generally curious or interested we'll be here all weekend uh come to the booth come ask us questions and see what we're building and how it might be able to to fit into um your own projects cool thank you all very much for for uh coming up here and sharing your thoughts and ideas and joining us thank you everyone thank you guys [Applause] [Music]

Automatic transcript — names and jargon may be misspelled.