# Nym Workshop | Harry Halpin | Nym and Ethereum Validator Privacy | ETHDam 2023

- Speakers: [Harry Halpin](https://streameth.org/speakers/harry-halpin)
- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2023-10-07
- Duration: 27:44
- Watch: https://streameth.org/watch/yt-cmDD7EkQRgs
- YouTube: https://www.youtube.com/watch?v=cmDD7EkQRgs

## Description

Harry Halpin is a founder of Nym.
https://twitter.com/harryhalpin

Nym Technologies 
https://nymtech.net

ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. 

Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants.

ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: 

CryptoCanal https://www.cryptocanal.org/
CryptoCanal Twitter https://twitter.com/CryptoCanal
Join CryptoCanal Community https://t.me/CryptoCanalCommunity 

We would like to thank our partners and sponsors that made this event possible. 🌷
Our BFF 1inch https://1inch.io/

Our Frens: 
Sismo https://www.sismo.io/
Aleph Zero https://alephzero.org/
Scroll https://scroll.io/
RAILGUN https://railgun.org/#/

And our Sisters:
oasis.app https://oasis.app/#earn
Maven11 https://www.maven11.com/
bitvavo https://bitvavo.com/en
Lido https://lido.fi/
Spankchain https://spankchain.com/
API3 https://api3.org/
Gelato https://www.gelato.network/
VanEck https://www.vaneck.com/nl/en/crypto-etn
Marlin Protocol https://www.marlin.org/
Silent Protocol https://www.silentprotocol.org/
Cyber Capital https://cyber.capital/
… and Proto https://twitter.com/protolambda 🍍

## Transcript

foreign [Music] so I could start early I guess if you don't mind um so I'm Harry Halpin I'm the co-founder of nem and we'll be present name is a mixed net just wondering how many people are here know what a mix that is or I've heard of one okay cool that's okay we'll give you the the basic description how many here people here does anyone here run a ethereum two does anyone everyone knows what a validator is correct do you know what ethereum 2 validator is does anyone run one by any chance you don't have to raise your hand but we know who you are okay so we're going to describe how the Nim mixnet can be used to basically solve some of the outstanding problems in ethereum too because as as well known ethereum 2 is super fun to play with but has some of the worst privacy of any blockchain and unfortunately this can be used to disrupt ethereum to consensus which you know can happen and we would like to prevent that so I'm Harry Halpin I'm the CEO of nim I I am very interested in surveillance because I was personally surveilled for many years due to climate change activism so on a terrorist watch list among other things um and I've been working on surveillance ever since so the internet itself is broken and it's oh parts of slide didn't load I don't know why okay and my slides are broken as well let me see so what our solution is to enter to mass surveillance is what's called a mixed net so what a mixnet is is it uses it's rather like directly peer-to-peer gossip your traffic to another node or I'm a client your server I send you some traffic and you pink send me some traffic back you know like what we do is we build what's called an anonymous overlay Network similar to tor or um in there but wait a second we build you we build a network similar Tor on top of the existing internet um and it has some features which do something which is quite remarkable which is make internet traffic private even against an adversary such as the NSA that has us have God's eye view of the whole network they can watch for every single packet is going and there's no escaping this adversary we do this uh through a number of Tricks one trick is pretty straightforward which is multiple hops you can also do this with dandelion plus and other uh this is what Tor does for example but we add some things that Tor and dandelion others don't do one of which is we add fake traffic so if there's not enough traffic in the network we add fake traffic and that ossificates the existing traffic in the network uh second thing is we're a mixed Network so packets and tour or with a VPN or with dandelion or whatever technique you you use typically come first in first out you know maybe there's some Network churn but typically that's what you get in our solution we've actually said it the reason it's called a mixed network is so that you can mix the traffic so the network the packets come in and they wait a certain amount of time in the mix what's called a mixed node a computer inside the mixnet more traffic comes in and those pockets are mixed up like a deck of cards they're also encrypted so you can't tell them apart and then they're released into the world and this is kind of what looks like so if you if you look at a um a typical VPN here on the bottom the timing and volume of the packets are clearly reflected uh for entering the VPN and exiting the VPN so the VPN knows exactly what you're doing you're just moving your trust from your computer to a VPN which I mean may be useful to like download Netflix but doesn't actually provide any privacy so to speak of with Tor it's a bit better because it's a peer-to-peer Network so you you see you're shuffling the traffic through three hops but you can see that the timing and volume of the packets is revealed so adversary that's watching the entrance of you going into the Tor Network and the exit can do a statistical correlation attack and de-automize you on the other hand Nim sends the Trap individually route to each packet so it's not a circuit it's asynchronous message based routing and the traffic comes in and it's all kind of chopped up to be the same size and comes out and the timing and the volume is hidden so that's the big Advantage I don't know why that's not loading so what we are trying to do here is we are trying to create a solution what using them that can provide some level of validator privacy for ethereum too and the way ethereum 2 consensus works uh as probably everyone here knows is you have you have the beacon chain you separate consensus execution and you're basically gossiping who's got the next block uh the coordination algorithm chooses an X validator and that and and then you pick one validator and it signs the block and that validator then basically you know gets the book gets the reward now there's a there's some neat things that they do in ethereum too they do separate to a large extent then validator identity from the network identity but as ethereum researchers have shown it's pretty trivial to connect them uh mainly basically because you look for the batched rewards right so you know how do you know I'm a vet there's a validator behind my node or not well it's pretty clear look at who gets the rewards and because a lot of the algorithm is fundamentally deterministic You can predict a large extent who might get the next block and then you can you could DDOS that node and knock them offline so again there's a number of big issues here one is validator IP address collection there was a big Scandal on crypto Twitter we got revealed ethereum Foundation was indeed or at least someone said I don't know if it's true or not that they're collecting these IP addresses so this lets them for example sensor validators or censor the rewards of validators so maybe I'm running a validator a country that no one else likes and I may not get my rewards and we get kicked out of consensus so just the very fact that you reveal your IP address through this peer-to-peer gossip protocol is can be used against you um and then even if no one uses against you uh on the ethereum side of things uh malicious actors can use that IP address against you by essentially launching a DDOS attack on your validators they know where you are kind of know where you live IP addresses are generally correlated to geographical location and they can knock your validator offline um hasn't happened yet but you'd be surprised when money's on the line people can start doing crazy things so our solution is to use the mixnet and in order to use them then mix that you have Dev P to p and live P2P we chose lib P2P because it's a bit more uh used in more Stacks uh we need to integrate the mixnet against lib P to p and this was done jointly with chain safe and it's done you can go to the GitHub right there and we'll tweet it shortly and and I'll look at our wonderful rust lip P2P uh transport so we what it is is it's a Nate we basically made it so it's easy to use if you're familiar with lib P to p a trait for Lippy to Peak that basically natively uses nem so you don't have to worry too much about Nim all the complexity of nim is hidden from you you just kind of turn it on inside of lib T to p it's in full rust uh you basically integrate Nim as a plugable transport and you get not just transport later level guarantees but you get privacy guarantees on the network layer now you could solve out there privacy using consensus changes but that may be even harder and just to go a little bit of a deep dive while I have a second um so we abstract away from the complexity and we have a full spec thanks to Elizabeth from X chain space and you basically you implement this abstract connection um on top of lib P2P and there's a few things that make Nim and libidity not really work well together and we fix those so for example if I open up I want to dial and I want to gossip using libp to P you need to have I need to open like essentially some sort of connection to you and you need that connection you need to have a Nim address if you're using Nim and then Nim does not guarantee message ordering right remember sending all the packets one by one through the mixnet and they're mixing up so you want to guarantee message ordering so we add a little nonce with the index space counter on it to make sure that you basically can uh can keep your messages in order and rehide the addressing with a temporary 32-bit randomized identifier and these kind of changes allow you to run multiple data streams uh what's called a streaming mutex on top of lib P to P in one of those streams can now be Nim uh so that's basically the hard part of the integration to defend validators against uh validator attacks now I think one question is uh which validator should we use does anyone here use Lighthouse Lighthouse any lighthouse rust users so Lighthouse is the East 2 validator software stack for the consensus and it's built in Rust and licensed in Apache and so we have instructions for using Nim it's still I would say beta at least but you know we'll tell you when it's ready to go um but you can play with it now and then furthermore I think the big question is you know whenever you add an anonymizing layer on top of a transport stack and you're trying to do something like produce blocks you know the whole point of of producing blocks to produce them particularly proof of stake networks relatively quickly so the question is can we fit how slow is in the mixnet and can we fit it within the amount of time it takes to make a block so these are some stats from a team called lodestar who are great folks and they basically said you need four seconds in total for Block production and other less optimized Anonymous Solutions like dandelion plus plus do not fit within that four second Gap and the four seconds can be divided uh you have some sub so there's some time you need right so you need 300 milliseconds to produce a block 1250 for a slot to receive the block from the network and then 550 to process and validate the block right so we're already at two seconds so the question is can we speed and then mix that up the fit within the remaining amount of time necessary and the answer is yes we currently run about 400 milliseconds we think we can pump it even faster down to 300 milliseconds So currently the Nim mix that does indeed fit within the total time needed for Block production on ethereum two at least according to the numbers from lodestar and chain safe and this makes it easy to add more anonymity to your block production the speed of the mix that's determined by your the client software so we don't tell you how much to mix so if you just kind of speed it through as fast as possible you get three 400 milliseconds actually got 400 or 500 spare milliseconds so you couldn't mix it a bit more if you want if you want to be more Anonymous and furthermore we enimo that we haven't announced this yet we are looking at a possible two to four x speed up of the underlying mix that shortly because well you know we have Daniel Bernstein working with us on optimizing the curve 25519 diffie-hellmens which is the thing that you use to communicate to the nodes to kind of give you the keys encrypt the packets to send it through the mixed net and we use a special Sphinx packet format also used by lightning and other networks and this packet format is uh re-randomizable so each hop randomizes and The Ordering of the bytes kind of changes you can't tell it's the same packet so you can't like attack the packet and flip a bit and look for that flip bit later that we're speeding up that packet format by removing one of the diffie-hellmens so we think we should get a relatively fast uh Network implementation there so that's what we're up to and thanks a lot for chainsafe for all the heavy work in particular Elizabeth who is unfortunately not with us and if you have any questions I am more than happy to answer them uh that's it [Applause] go for it thank you have you got research on like uh the number of nodes like how that scales how speed scales with the number of nodes the number of nodes validation just for like the net in general okay so the the question is the scaling for if two validation or scaling for the Mixed Nat they're two different things yeah so the mixed net the thing with the mix that is if you look at it the diagram is a bit uh a little bit old-fashioned but um you can see that we everyone gets three hops so when we add more mixed nodes than that work it's it's the handle more traffic so it does something called horizontal scalability similar to a website like your website's getting pounded by too much traffic you sub another instance and that absorbs some of the traffic so we scale but we scale uh we scale this way right so let's vertical in this particular diagram so we'd add another node there and another node there and so the amount of hops the network remains constant at three so it really doesn't matter how many nodes are in the network uh because we're not doing consensus among the Nim mixed nodes themselves so all that matters is that you are going through three Hops and on that level we we have we believe that shouldn't really matter uh how many how many uh nodes are in the whole network because you know everyone's divided into three layers you're always getting three hops so you should always remain around that uh 400 milliseconds of goodness which is what we want to achieve eth2 validation properly you don't have like any uh Gossip which slows it down no we don't use gossip so it's uh it's more like Tor we do have a little bit of element of gossip but that gossip based we have a little blockchain which we call NYX so one question is when I use an anonymous overlay how do I find the entrance to the how do I find where is it how do I find the keys for all the nodes and and the IP addresses for the entrance um and that is maintained by Nim on a blockchain called NYX which actually is running Cosmos not ethereum because it's faster and we get finality very quick um and so but we only run consensus we don't run consensus on that blockchain constantly the mix the mix note itself only reorganized itself every hour or so so that means that you're because we want people to use the network and for it to remain sorry for uh this net this part of the network to remain fairly stable does that make sense so we're not there's not like a big uh consensus uh problem any other questions go for it is is your main goal to protect validators against uh each other so validate the sabotaging each other or just yeah while there's could sabotage each other but also third parties could uh could could sabotage let me just thank Elizabeth here all her work there we go um anyways she did a lot of heavy lifting here but couldn't be here um the the validators basically could sabotage each other so that's one really good economic reason like if I DDOS your validator then I may get the next slot then I get the reward and you don't that's great ha ha uh but also you can imagine outside adversaries attacking the ethereum network maybe people just don't like ethereum maybe who knows Bitcoin maximalists is going the attack against ethereum uh who know governments all sorts of things Anything is Possible the the thing with governments and I have this assumption about Tor that it's infiltrated by NSA that most of those are run by NSA is Nim any more resilient against this kind of infiltration yeah well let's think about the the well first the question is is you know is Bitcoin or ethereum infiltrated by the essay so the answer well I mean the nsh can just watch the traffic and the question is how much traffic do they watch they watch a good chunk of it and we have we know this from Bitcoin I won't be surprised if it was the case with ethereum because the ns8 won't do it directly they will contract out a third party firm so in the case of Bitcoin that firm I believe was chain analysis it got revealed that chain analysis was running a fairly large amount of Bitcoin full nodes in order so they could capture that peer-to-peer traffic so the way thing is in the IP when I gossip I'm sending you packets you're sending someone else packets those packets are kind of being shipped around and if I can I'm if I watch I can if I intercept the packet from you let's say it's got a block on it uh that's a block producing packet I can I can think well maybe you're gossing from someone else so then I I can watch the person that you got the bat the blocks from you so you can follow you can like trace the path through the peer-to-peer Network to find the originating nodes that's pretty easy because peer-to-peer networks are open networks anyone can run up here so if enough peers uh run the network then they can get a large view of all the traffic we have not done this for ethereum but we have done this for I think lightning and Bitcoin we actually did the stats on it if you want to know the exact stats of how many malicious knows has to be to see what everyone's doing I think there's a paper by our chief scientist Claudia Diaz d-i-a-z and her student piyush p-i-y-u-s-h called on the anonymity of peer-to-peer topologies that was published in a conference called ndss I think last year so the answer is you don't need the whole network you only need like 30 to 40 percent and then you can see all the traffic now the question is is Nim itself uh under attack am I say how many how much traffic do you have to watch to figure out what Nim's going on well Nim is surprisingly resistant to this but because of reason some people really don't like uh Nim itself is not a peer-to-peer Network it is what you called a layered topology so you have three layers of mixed nodes they're randomly assigned and so the layering prevents people to some extent from just jumping in at any time and the layering is re-randomized and because each other I think there's two separate questions do they know who you're talking to that's what you call an Indian correlation attack or can they decrypt your packet so I'm sending encrypted packets in here and they're coming out and if I in order to decrypt to figure out what's going on I have to know your whole path that I can decrypt your packet if your whole path is malicious so that means we currently have 500 mixed net 500 mixed nodes I capture your entire path but your path is randomly selected through the mixed net so I could only even I was very lucky and I believe the stats you have to capture about 80 percent of the network to be lucky with about a 50 chance I would still have to basically um I would only capture one packet and I could decrypt one packet and maybe that packet I might need a lot of messages or more than one packet including ethereum messages um the second question is how about how many of these nodes themselves are compromised I mean that's always a good question what we do to try to prevent compromise on those nodes is uh you know you kind of got to make it a bet that you're not starting in a fully compromised position and we use a reputation system to determine uh which I know is tokenized a lot of people dislike that I think here people would understand that we have a reputation token so that the more mixing you do the better your reputation is and the people can delegate their tokens to you and the one thing the NSA and other intelligence agencies have trouble doing is they have trouble faking The Social Network of a real human being because the NSA all their nodes would come in together maybe they'd all befriend each other they would maybe delegate stake to each other but I think the chances of like the eff or myself delegating to NSA node is pretty low so you can actually watch The Social Network of these kind of stake nodes and use that to kind of figure out are a bunch of new nodes coming in and who who are they already friends with and who do they know and who do they not know and it's hard to fake uh organic development of a friendship graph even with llms so it's called a power law graph and they kind of stand out a bit with this kind of small world effect any other questions one more just a quick one um I'm not so familiar with the protocol but one of the things that tour has suffered from was the um Ingress and egress notes having knowledge of the traffic yeah for the first or the the final layer of the mixing nodes to then have some idea of who the originate would is you you you suffer the same vulnerability and maybe we'll let's see if I can get one of the the zoom one of these to work um but effectively the the vulnerability is a bit is a bit different uh insofar as that Nim does what we call per packet routing while toward is a stream of packets so in Tour all your packets are coming out the same the same exit nodes the same so and then it changes out every 10 minutes you roll over you get a new a new circuits created through tour so that means that I the average area gets like a stream of 10 of 10 minutes of traffic they can correlate that against your stream now with Nim it's a bit different so you do have exit nodes but with every packet the exit node changes so that makes you the average height gets one pack from one exit node one pack from another exit node and the packets aren't coming out in the same order because they're not coming in the same order that's what gives you resistance against this kind of two-sided statistical disclosure tab because the average area gets one side they they see you're sending traffic in and they kind of see the pattern of that traffic coming in you can add some cover traffic here and that does help and we do add cover traffic um but the real key is that it's much harder to do the statistical disclosure attack on the exit nodes because each packet the packets aren't coming on the same order there's fake packets and there's in each stream of traffic comes to not one but many exit nodes now that being said are there probably attacks there yes there are and again we're looking where we should have a paper out on those attacks at some point and we're trying to understand how bad those attacks are off the top of the cuff they should be less bad than tor but they will exist there will still be this all whenever there's any day it's impossible to make something which is like completely statistical correlation free there's always a little bit of leakage because the real world has leakage um now there's another interesting question um one interesting question could be uh let me try to think about how to say this like you know there's people watching they're passive observers and there's like maliciously active nodes so you had to mixture maliciously active nodes how dangerous that is right um and these are different kinds of attacks and we're still trying to analyze them all um I would say that one thing a lot of people worried about Tor is there has been a lot of DDOS attacks on tour recently now people here run a hidden service or use hidden services but uh what's happened at least Roger Dingle Dean from torblies at the various dark markets are attacking each other like trying to knock Alpha Bay out or whatever uh Nim does not have this problem because essentially everything that comes to network to some extent anonymized and those those particular DDOS attacks are attacks almost called distributed hash table inside tour which kind of redirects you uh to the onion surface or the hidden service and we don't use a DHT we use Source routing but it's randomized basically that may have been too much of explanation so but anyway the answer is yes there'll be some attacks but will they be better than Tor uh yes they will be better in tour and we are still trying to figure out the exact danger routes for those tax uh anything else okay well thanks a lot and uh please if you're interested in hacking on Nim or P2P lib P2P or getting down to the network stack of ethereum and the theorem validators do get in touch and follow us for the big announcement of when we're fully integrated as the option the lighthouse which means people can easily turn on privacy and still run ethereum validators and we're quite excited by that take care [Applause]
