Personal Data Aggregation and Selective Disclosure | Hadrien Charlanes | Sismo Connect | ETHDam 2023
CryptoCanal·Sat, Oct 7, 2023, 12:00 AM
More about SISMO https://www.sismo.io/ Follow Hadrien Charlanes, the founder of Sismo https://twitter.com/dhadrien_ Presentation slides: https://docs.google.com/presentation/d/1qBHJbV3ZY5CgBGoEhY26V0bgHL6US6fdw6QBtqYX9jA/edit?usp=sharing ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants. ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: CryptoCanal https://www.cryptocanal.org/ CryptoCanal Twitter https://twitter.com/CryptoCanal Join CryptoCanal Community https://t.me/CryptoCanalCommunity We would like to thank our partners and sponsors that made this event possible. 🌷 Our BFF 1inch https://1inch.io/ Our Frens: Sismo https://www.sismo.io/ Aleph Zero https://alephzero.org/ Scroll https://scroll.io/ RAILGUN https://railgun.org/#/ And our Sisters: oasis.app https://oasis.app/#earn Maven11 https://www.maven11.com/ bitvavo https://bitvavo.com/en Lido https://lido.fi/ Spankchain https://spankchain.com/ API3 https://api3.org/ Gelato https://www.gelato.network/ VanEck https://www.vaneck.com/nl/en/crypto-etn Marlin Protocol https://www.marlin.org/ Silent Protocol https://www.silentprotocol.org/ Cyber Capital https://cyber.capital/ … and Proto https://twitter.com/protolambda 🍍
Transcript
foreign next up is Hadrian from sismo but he's yes you do not want to see what telegram is like right now where is this dude are you really yeah okay sorry for this you made it cool well I will leave you to it and enjoy thank you hi everyone so today today we're going to talk about data aggregation and selective disclosure and hopefully you'll learn that privacy is not only normal but it's really powerful um I'm gonna start to speak about personal data I think that we are all aware that in web 2 it's app Centric as a user I can access an app and then I do interactions there and I build up my identity that is stored on their servers so I'm not owner of my data I'm lending an account and so problem of ownership but there's another problem I'm doing the same on multiple apps and my data is isolated this side load and so here for instance you cannot leverage your identity within Facebook or Twitter at the same time so we have this issue in web 2 in web3 it's different we have data ownership it's centered around the user so here it's more I have my accounts my serving account and I bring my identity to the applications so here I have a wallet and I use uni swap with my data and it's my account but we still have a similar problem because I would use uni swap more on my private wallets that I act like a bank accounts but then when I want to use like social networks like lens I would tend to use my ens docs accounts my public ones and advanced users they tend to have multiple wallets for different use cases and so we realized that actually you are recreating the silos that we're trying to avoid so what's the problem is that we want to use our social capital at once we want aggregation we want to be able to prove to someone hey I'm solvable I have some good financials but at the same time I have a good reputation on that system and that's something that we can do we can't do first reason is that we don't have ownership of the data it's stored on the servers in web 2 so of course you you can't use it it's their most important assets your data so they keep it for themselves but even in web 3 where we got the ownership because of the lack of privacy and we we don't use that as an aggregated Manner and and the solution to this problem that that that's our visional system is to have aggregation at the local level as at the user level so as a user I'm able to get all my accounts my web 2 and web 3 Accounts at once I'm the only one that can see the aggregated view so I have I see my entire social capital and then thanks to selective disclosure I'm able to leverage it anywhere so that's what we do asismo sismo is a communication protocol between users personal data and application so again the user is able to aggregate all its data their data locally privately and then reveal it to Applications as they will um so we have two concepts so here we will take the user side so as a user how I'm using sismo I have access to this data volts that's the private local storage where I import let's say my daydream.ether accounts my public wallets that I use on all public things that's my public title and then I also import my private wallet the one on which I use rooneyswap or I use tornado cache for instance uh and I can also add some other data sources Twitter architer and soon many others so all of this is stored in my system of data world my local aggregated identity then so that looks like this here we see a data table that has some wallets a Twitter GitHub and then from this data world we Leverage gkps to selectively disclose what I want so technically how it works ZK proofs work with the following concepts you have approver where your generator proof ZK proof so here in the context of sismo I will generate proof that I voted in this download that I have this nft I'll create a ZK proof of a granular data that I own and then the application will verify it and they won't get access any more information that's what I share so that's how it works you have the approver in the in your system Data Vault and you send the GK proof and the application will understand that with its verifier so that's why we are communication protocol so that looks like this we'll get into that later but here I'm able to prove anything from my simulator that I own this specific evm address that I have this nft and other things so now that was the end user side now what about application developers because what we serve in the end is application Developers let's take a look at how today nft are checked nft ownership I've checked it's while in used to use sign in with ethereum so basically the concept is like I request a signature from a user's wallet I verify it so similarly proverb verifier here's the proof is signature verifier is like I verify the signature I know that the users own that wallet and then I check in it do I really need the full wallet for this when I do nft check like let's say that this NFC is an operator do I really want the private wallet of users I I don't think so similarly and that's even more interestingly um let's say that I want to access two types of data for user and these two types of data are on different cycles that are presented to you before so let's say that I want to check nft ownership on the asset wallet of a user and that the user voted on the Dao and this would be more on his public wallet here the current way of doing it with significant would be okay sign a message with your public wallet I verify it I check nft sign a message from your private toilet I check in it and here what I'm doing is that I get access to both what IT addresses and I'm creating a link between these two addresses and the ux also is not very good but there are some projects that try to do it and I think that it's really a bad idea to to incentivize users to docs themselves because they might not be aware of these things whereas with sismo the way to do that is very simple it's like as an app I don't request a signature I request a ZK proof it's like prove me that you have this NFC and that you voted in that now I don't want to know your addresses nothing so sismo connects is the SSO that is somehow the same stack of signing with ethereum or like signing with Google we're trying to replace all these things with the Sovereign single sign up so we enable app developers to access any data from the users any data they imported into their Data Vault and responsibility meaning that they don't request more than they need and I think that's at the core of all what we do is to really like respect the sovereignty of users and and and yeah and we have the tool for this so with csmo connect if you integrate it as an app developer what you do you are able to request authentication from any of the data sources that the user has imported in this world so that will be a Twitter account like prove me that you are on our vitalik.it vitalik or evm address so um yeah you can also request some granular data but it's nft ownership that your vote on the Dow and you can also request message signature what is powerful which is more connected that you can request them all at once so you could request potentially multiple wallets multiple data granular data and a signature so we're going to take an example of a privacy preserving gated airdrop that is by the way to be resistant here to do that as an app developer I need to integrate a system button so in my front end I will have a button a bit like signing with ROM or wallet connect when the user click on it he will be redirect they will be redirected to the system data alert and here they will say Okay I I consent that this app has access to this granular piece of data here it's git coin passport so prove that you are a human or that you have some civil resistance and access that you own a known nft that would be on your privatory so I'm able to do that so I redirected them to the The Vault and then I verify it and I drop them an energy so a bit more precisely how it works again so you have the ZK drop that that has a front-end and a smart contract in the front end you integrate the the sign in with system button you do your request I want my user to prove me that they have a Bitcoin passport and that they have a non-nft when they redirected they generated ticket proof and from that I get it back and I send it on chain so on chain you will send the ZK proof and your spat contract will verify the proof and if it's if all is good then you'll meet the nft so that's the flow of C smoke connect and it's really simple to integrate basically if you think about it we try to we are abstracting away all the ZK proofing as an app developer you just say okay I request prove me ownership of that account prove me that you have this nft and it's quite simple so it's like some lines in the front end to make the request and then some some lines in your in your smart contract to verify it um we have the similar flow for option apps because if you think about it like the system data world is a local thing that is option and you can DK proof we can verify it both on chain or off chain so here the use case will be let's say a gated newsletter and you require them to give them to give you the Twitter account because you want to have a way to contact them for instance and like prove me that you are a small contributor so similarly your integrated sismo button hey I request that you give me your Twitter account and that you proved you that you are a system contributor and this time same flow this time I'm I've verified in my backend so we give to app Developers clients packages so that they can make this request and backend and smart contract verifiers package so they can verify the proofs um yeah so that's it so let's do a let's stand the floor it's yeah I don't think that I need to repeat again but it's still the same thing it's really easy to integrate and it's secure so we a good example that is live today if you want to trade out is for the occasion of this event that is put in a known passes on privacy we had this privacy's normal campaign and we had a lottery for this painting like on the right that is in our office it's a it's a code of Toronto cash it's a celebration of privacy and so in this luxury to get in you need to prove two things both that URL tornadoes are that you wear one and that you have a Bitcoin passport at the first glance you might think it's between because like Bitcoin passport is doxing is super privacy and so it's not private or something like that but it's because we are tend to think that privacy is like yeah I just want to be present that's the only goal of privacy but here what we want to showcase and demonstrate is that privacy enables you to have some to not be all indexed or private you can have very well a private credit and here that would use tornado cash for good reasons of course and a public docs one your ens that has a Bitcoin passport that's all all right and thanks to privacy you'll be able to leverage all of this data as well so the lottery you get in that's the flow you can by the way access it today on Spaces that is more uh you see you can trade by yourself and if you are not a tornado cash users or or don't have a git coin passport you can either do it now it will be like it will be updated in 24 hours or you can try the demo again what we want to to give you today is the feeling that there's a path somewhere that is better than signing with ethereum or that sign in with Google that is as easy to use as an app developer I can request many things but responsibly so that's it for my presentation I have no idea at all about the timing so I will be very happy to to get some questions another time yeah yeah because the the schedule this guy okay I got it
Automatic transcript — names and jargon may be misspelled.