Shady El Damaty [Holonym] x Ethereum Cypherpunk Congress
Ethereum Cypherpunk Congress·Tue, Oct 7, 2025, 12:00 AM
Speaker
Ethereum Cypherpunk Congress facilitated by the Web3Privacy now collective: https://www.web3privacy.info Ethereum Cypherpunk Congress: https://congress.web3privacy.info X: https://x.com/web3privacy
Transcript
um I would like to shift the conversation a little bit away from uh the consumer choices that we can make which are important and I think are something that uh definitely could be improved and maybe perhaps there is a hard limit on what sort of consumer choices we even have available to us something that Bob alluded to in the sense that most of the software most of the hardware that's available out there is built on existing infra um and some of it while has been hardened because it is open source it has been available for uh attackers out in the open to try to make the best of exploits and maybe there are still zero days out there I want to introduce you guys to a line of thinking or framework that we need to build out better Primitives uh deep-seated cryptographic Primitives to really make uh a true cyer Punk reality possible and I think that starts really I mean The Cypher Punk reality really is just uh I think a me M to an end a meme like not a meme a meme to an end uh and I think that end really is where we build upon a rich intellectual tradition of Freedom sovereignty natural individual rights that started you know way back with the first musings with Thomas aquinus uh and into the modern day uh with with um folks like Hobbs and John Lock Etc um so yeah my name is SHI I'm a Founder at hollam Foundation I'm really excited today to talk a little bit about what we do uh building application uh building backends for applications that provide security that's rooted in intrinsic humanity and I'll say a little bit about what I mean by that let me see if I can figure out how to change the slides here cool right so why why is this whole movement important why is cryptography so significant and and especially today and that's because for the very first time cryptography makes digital right enforceable um so when I talk about natural rights you know that's something that might mean something different to different people um I actually you know would love to hear what you guys think are natural rights what would you say is one spech free speech yeah um I think um how you call it like human Integrity as in you're not allowed to be invaded physic Ally in any form yep sovereignty self- sovereignty right to governance right to Independence yeah and there's there's a bunch out there right so um you know natural rights are typically a very broad category and they're defined by the culture by the political um I guess history the Traditions Etc that particular culture but John Lock really penned it down straight I think and pretty accurately which is that they're inali they's something that can't be taken away once they're given uh they're fundamental right they're seed into the culture the tradition and they're um uh Universal right so they apply equally to everybody and when we look at kind of how they've been implemented and how they've uh influenced like I guess you know different Societies or different constitutions or political systems all of these um systems are rooted off of law right so Thomas aquinus was really interesting he's like all right well uh the natural law basically says that uh um anything that humans do that can be reasoned about is ethical that's it's moral right um but in the case that you know God suddenly changes the rules changes the environment then we don't have to accept you know we can't expect that those rights are going to be guaranteed because there's the universal law that's subject to God and I think that has a lot to do with how they how early thinkers were rationalizing our role in a universe that we didn't have really control over didn't have control over entropy our science was still really young and emerging Etc um later on you know you you kind of these ideas kept kind of evolving uh you get to the point where it's uh rouso starts talking about a social contract right where we're all kind of bound together in our relationships uh and those kind of influence what sorts of Rights we can enforce and can enforce so cryptography just to wrap up a really longwinded Point here but like cryptography really allows us to take these uh natural rights that are kind of out in the The Ether uh and embed them into the technology that we use uh there's a lot of properties about cryptography that make that possible the ability to uh prove uniqueness between individual claims attestations uh identifiers Nims Etc the ability to uh prove that something is authentic or not that it came from a certain Providence or history and all of this comes together especially usefully in uh deterministic systems like blockchains and smart contract systems which are really useful for coordination uh something that hasn't been possible until recently so at ham Foundation we're making digital human rights real and the way that we're doing that is by granting every single human a key only they can control to unlock rights for digital privacy personhood security by default uh the ability to Access Financial Services Etc so the way we do that is we have uh uh kind of like a a bit of a stack here uh where we have um basically a low-level infrastructure for driving Keys what we call human Keys um and a framework built on two-party MPC technology for providing security that's not dependent on say a single provider or a single centralized system and lastly the ability to infuse uh claims or signatures or proofs or different types of use cases or uses of keys providing utility of these Keys uh uh with identity and that could be really useful when we start thinking about governance we start thinking about building nation states that aren't just built into you know the geographical boundaries we make up but perhaps into the software and the code that we Implement to coordinate so we start with universal access uh to cryptography we give every single person a key we believe that's a fundamental right uh the ability to uniquely prove your authenticity to uniquely claim ownership to your assets your ability to um uh securely communicate Etc and so the way that we do this is we actually do something a little counterintuitive a little controversial actually we cryptographic Keys typically are derived from Randomness for good reason because with a really strong key you can generate outputs that can't be brute forced and for this reason specifically it's why all the attempts to drive keys from like low entropy sources like kitty 123 or perhaps Biometrics or perhaps um other identifi like identifying human memorable human friendly easy uh inputs has failed and that's something that has been very difficult to solve until recently and there's a few cryptographic Primitives that make that possible uh one of them is a technology called uh the verifiable oprf I believe is PUD random function which allows us to take any low entropy data and derive a really secure High entropy key without revealing any information during that process and that's done using a threshold Network so we take this human data what you are are what you have what you know and we provide that as input to uh a network that we call mishy network uh it's named after my co-founders cats uh which is an AVS on igen layer so this ABS you can think of it as decentralized middleware that provides universal access to your keys whenever you need them you just need to present your human attribute that you use to drive that key whether it's a security question whether it's like a special key you keep in your pocket at all times or that you give to your family member uh or whether it's something that's derived perhaps from a biometric authentic ation and one thing we you know that's really I think important here to point out is that Mishi is you can think of it as like a key availability system and that key availability is rooted in the economic security of ethereum that's restak on that Network so in a way what we're doing is we're layering the TR uh the trust that's embedded within I guess you could say like codependent ecosystems to be able to create uh a service that performs a very specific function and where that those incentives are only possible uh because you know of the ability to have tokens right the ability to tokenize value and to provide um in the same way that uh ethereum stakers are cized so you know it's one thing to give people Keys it's another thing to guarantee that those keys are going to be secure um it's actually obnoxious to guarantee that those keys are going to be secure it's a bit presumptuous that people are going to be able to use keys in the way that they're intended and we see hacks all the time that reflect the these assumptions that sometimes are implicit in the software that we ship out there sometimes by accident sometimes by ignorance sometimes you know on purpose so one thing we've done and I think this is a bit of a novel approach which is instead of trusting uh anyone really uh instead of trusting the user with the key that they're going to use their key properly instead of trusting that uh say the application is going to treat the user in a way and handle them with kid gloves and make sure that they're doing things the right way um and instead of uh say like trusting um for example us like a middleware anything that's going to be deriving or supporting or providing infrastructure we're going to remove all that trust and what we're going to do actually is Implement a mechanism called 2pc uh two-party computation has anyone here heard of MPC multi-party computation so 2pc basically is a simplification of this where it's just two parties uh typically a client and a server and this can be generalized to 2pc MPC where two parties are two decentralized networks now this is a huge unlock that hasn't been really any possible uh up until recently uh a research group uh based out of Israel uh recently cracked a two-party ecdsa problem which was something that was very difficult to implement uh in kind of the systems that we care about and what and are designing and made it possible for example for two networks to actually uh generate uh signature so it's really useful for us because what we can do is bring break the user's key into two pieces where now instead of having just self- custody it's protected self- custody the user has one key that they can derive using their human attributes from the ABS and then the second key is stored in a decentralized MPC Network and whenever the user wants to sign a transaction they have to basically query the MPC Network which must come to consensus to approve the transaction so what happens now is if there's malware on the user's device like for example uh with the radiant hack right with the radiant $50 million hack uh it was a three out of 11 safe multisig that controlled uh all the funds and attackers spent a lot of time socially engineering uh the the signers after they' ID identified them had them install malware without their knowledge and when they went up to sign a transaction using safe HTML code was suspected to have been injected into their transaction which they were using ledgers with right they were using ledgers to sign on this smart account but when the LED when when the safe returned uh the contract call to The Ledger you know they're clicking through it if you guys have used the Ledger before you just see a bunch of heximal code you don't see that uh that heximal code is different than what was intended originally you don't see that you're transferring funds to a completely different entity or a completely different address that you didn't intend to and so if the if they had implemented this in a 2pc setting uh there's a bunch of ways actually could this could have been avoided uh one is reducing the resilience on the front or reducing the dependence on the front end um um and then the other is implementing basically uh a second party that will only sign that transaction after some say conditions have been met right like checking that the destination address is in contacts that a certain amount isn't being transferred within a short period of time etc etc so we're we think 2pc is something that will definitely change how we think about Security in general especially when these Primitives become widely accessible for any Builder to basically plug into these systems and the Eco Network which just recently launched onu is making Stellar progress to making this available to all Builders so when we put all of these things together what we're really looking at is how do we actually ensure everyone has access to keys cryptographic keys as a fundamental right how do we actually um ensure that they can have act they can set themselves up not to fail with at least you know good enough standards for security and being able to implement those keys and use those keys to do things like prove facts about their identity vote Etc um so putting it all together we have mishy Network which is our AVS it works together with a separate MPC network uh running on eom and basically these two keys come together where even if there's malware on the user's device or the network gets compromised the entire the entire wallet doesn't become compromised um and then you could do things such as uh a ZK identity proof right where you tap the NFC chip on your wallets make a pre-commitment in z ZK CL you know generate the proof client side um and then make a pre-commitment say onchain that it was you who created this key to begin with so if you lose access to that Hardware key that you used to create the wallet or if you're doing social login and you lose access to that you can always recover the wallet with a secondary redundant identity proof which is pretty cool so the way we're thinking about it you know we like to zoom in and zoom out frequently we get a lot of vertigo doing this but it's a lot of fun sometimes and how we're thinking about it is we we need to be able not only to instantiate exciting new protocols in code and be able to provide resilient backends uh we need to take these protocols everywhere and the way that we do that is we wrap it up in a web I'm not going to say Web Two I'm not going to say Web Two a web standard because that's what it is a web standard user interface that appeals to any developer who's has issues with privacy security uh sovereignty Etc so this is what we call silk silk is a wallet as a protocol it's white labelable uh and allows you to embed different types of I guess you could say uh user flows for particular types of use cases so for example here you could have uh completely white labelable iframe that you embed say in your uh digital nation state onboarding platform where anybody anywhere can sign up with a Social account they can sign up with um they can sign up with Biometrics Etc and then they can be guided through an onboarding flow where they could prove facts about their identity prove that they're a unique person that they're not a bot uh and be able to assure things like that they have one one vote per their one unique person and that's how we and zerm is how we bring these sorts of uh tools and features to life so zerm is actually how we first got started with CID it's a v based proving system uh built on the Quicksilver proving system actually and this is how we're able to really efficiently scale um ZK identity uh on the client side which is very difficult to do with CK proof proof systems that were typically built for uh scaling blockchains right like Starks so yeah I mean like we're we're pretty excited about what's possible today I mean it's crazy to think that the space is all of this was built actually within the next last two years and two and a half years ago none n of this was possible there was a Confluence of really important contributions in cryptography as well as the flood of investment like you know praise vitalic and praise Satoshi because they provided attention to an area that otherwise would go underfunded uh and gave VCS an excuse for Te for technology uh for academics basically uh to fund this really really important Tech so I think this is just the beginning and we're going to make digital human rights real we can't do it alone though because because digital human rights are different according to where you are what the needs are um but we feel we've built the core Primitives that allow uh folks from displaced populations um communities that perhaps want to transcend the limitations of the borders that constrain them and really open up a new future of possibilities for what coordination looks like and this is going to be very important as things start to get very weird as technology continues to accelerate faster and faster and faster we need cryptography we need natural digital human rights and we need your help getting it done thank you
Automatic transcript — names and jargon may be misspelled.