# Pragmatic Guide to Verifiable Data - zkMarek

- Channel: [ETH Warsaw](https://streameth.org/eth-warsaw)
- Date: 2025-10-07
- Duration: 29:59
- Watch: https://streameth.org/watch/yt-ingEzrbkpUk
- YouTube: https://www.youtube.com/watch?v=ingEzrbkpUk

## Description

Blockchain is nearing scalability and mass adoption, but it still lacks a compelling mainstream use case. Verifiable data has the potential to bridge Web2 and Web3, unlocking access to vast amounts of data currently siloed in centralized systems and enabling its use on-chain.

In this talk, we'll explore how to build smart contracts that leverage Web2 data, while addressing key privacy and security considerations. Discover how verifiable data can drive the next wave of blockchain innovation and how you can be a part of it.


🧜🏻‍♀️ ETHWarsaw is a series of educational and entertaining events for an active community of blockchain builders, developers and enthusiasts with focus on Ethereum-related tech. Once a year, we organize a large conference and hackathon for the community in the center of the Polish capital with speakers from the best web3 projects and participants from all over the world.

Follow ETHWarsaw on social media for the latest updates!
X (Twitter): https://twitter.com/ETHWarsaw
LinkedIn: https://www.linkedin.com/company/ethwarsaw
Telegram chat: https://t.me/joinethwarsaw
See you all at our events in Warsaw 🙌🏻

## Transcript

the topic I would like to share with you today is very exciting so those are web proofs have anybody heard about web proofs before almost nobody ZK TLS multi party computations okay excellent so there is a few folks here that already know what's going on so web proof is one of the most exciting Technologies and we're gonna so I I'm M Kik I'm CDO of vayer and um the thing we do is we do verified data infrastructure so we're going to deliver more data on the blockchain and we're going to write a comprehensive three parts report about it and I'm going to give you a sneak peek what's going to be the first part which going to be about web proof so if you want to get notified you can go to the link or just uh do um uh QR code scan and leave your mail and we're going to send it over so you get it first all right uh and today we're going to talk about what the web proofs are what are the use cases how does the work under the hood we're going to talk a lot about security because web proofs are very nuanced topic and we're going to talk about some protocol designer considerations if we still have time but first we're going to talk about the state of the eum and where we are today and I think it's in this very intriguing uh moment ethereum is this very intriguing moment because it's more legal than it ever was we have ETFs in the United States we have MAA coming into power on the other side on our side of the Atlantic it's more scalable than it ever was we have l2s finally get maturing getting secure we have blocks we have cheap transactions we have high volumes and by the way it's more usable than it ever was there are great wallets like I think it's Dao like the track transaction fees are not there is you can just send USD back and forth with that it feels like revolute right so it's a really good place that crypto is best that it has ever been but somehow it feels something is still missing and I think what's missing we're still missing this kind of a mainstream use case we still crypto is still a lot about speculation a little bit about International transfers a little bit about art but mostly about speculation and it's hard to justify the even today when the when the prices are not so high it's really hard to justify Market cup with just you know being a big Casino crypto being a big casino and I believe the reason why we didn't find those mainstream use cases those use cases appealing to the mainstream is because web free is so isolated like when you enter the world of web free it's isolated island you need to be set up your Anon New unnown identity and it's all very isolated but if you look at the web too if you look at the internet and your mobile phone it's so heavily intertwined with your life you play games you read news you watch shows you order you do shopping you order your taxi so on so forth right so why can't we just you know take some of the things to the web free well it turns out we're just lacking the technology like we we would like to get some of this data that is closely related to our lives but we can't because the web to is you know it's in the cloud it's all private behind the bars and data storing data in the cloud is basically for free like gigabyte of data storage is nothing when on the blockchain it's crazy expensive everything is public how do we combine one with the other right and and and then maybe the question arise for those of you who've been in the world of web free a little bit longer can we really solve the problem with more technology and cryptography and I believe the answer is yes we can so verifiable data there are free main uh there are three main types of verifiable data there is more other sources that we can that we can look at but the main most interesting ones are web proofs related to web pages there are storage proofs related to uh history on the blockchain or also cross blockchain uh getting data across the blockchains and email proofs related to the emails and as I said before today we're going to talk about web proofs so what's a web proof um I'm going to start with example of the use cases to make it very tangible for you so imagine real world asset right real world asset are those token that reflect some real life value in the world so that might be a that might be you that might be a stable coin that might be a security like a sh or stock in the company or bonds or whatever else or it can be even like a tokenized uh real like object like a car real estate piece or yacht um so there are many options and real world assets are the fastest growing Subspace in in the blockchain today the problem with real world assets is there is some issue where like a asset manager and he says okay this is you know three billion usdt or I have this real estate but there is really not much more than just his word for it and he can of course screenshots from the documents from his bank account but that's easy to forge and so on so forth is the sound right I feel like it's on and off a little bit is it okay and also like that a little bit okay maybe I'll try it like that or something all right so with web proofs you could do following flow you want to issue a token with call it a quackle and you want to generate a bunch of qu Quackles and before you can issue a transaction that going to issue a token you need to hit generate proof of funds you jump into the bank there is a special this there is a special um plugin browser plugin in your browser that you need to install ahead of time and it's going to have bring you this sexy sidebar here and it's going to tell you the sidebar going to tell you go to this go to there and when you in the right place there is the amount that you're interested in it's going to show up to generate proof you hit the proof you hit the generate proof the proof get generated and you go back to the application and now you can submit the transaction and the amount that's going to be issued is going to be the amount you have in the bank of course that only helps at the beginning you can say okay I'm issuing 2 million Quackles right but maybe tomorrow I'm going to transfer that away so we still need some kind of health checks uh periodic health checks and it's never going to be fully permissionless but we can push it like your C20 tokens right but we can push it way closer to being trust minimized from where it is today which is there is no me significant mechanis trust at all and so so this is very I hope this is this was very tangible example for you I'm going to show one more example very different so this is we believe there's going to be a new category of apps that's going to happen in upcoming months and years and we call it when two web free markets I don't think it has a name yet but people are already talking about it and people trying to build it so the the idea for the web to web free market is that you have a market that you operate on on chain but you are trading things on the web too you're trading again either assets uh Securities or you know could be virtual objects like game items or could be things that get notorized in the real were like real estate so how such a FL and and one one interesting example one interesting cases on ramp so you can trade uh Fiat currencies so US dollar for usdc let's say tokens right and in this way you can build an onra so how does it work you go to your favorite on RAM fyz you decide to swap $200 for 200 usdc and there's this you know you need to pick the bank you can to be using to generate your proof you go to the bank the sidebar shows up and it tells you to go there uh to the transfer and when the transfer when the transfer is complete you go to the transfer page and you generate a proof I did send $200 to this specific account and here's a proof and with that proof you go back to the application and the application recognizes the prove and you can hit claim and the usdc tokens can be transferred to you in the next transaction does that make sense all right questions no questions easy peasy good so there is a little bit of a Nuance around how we fetch this data because it's not a public API that we're using it's usually guarded behind login and password or some kind of authentication tokens so there are so we need to get a little bit creative you've seen an example with a plugin so the plugin that you install into your web browser uh ethereum is already very successful in putting plugins into your browsers unlike anything ever before so we believe that's going to be a good start We Believe eventually as technology matures it's going to get integrated into the wallets so you ain't going to even see it you don't even want to you won't even need to think about it uh there are some companies that try to do it on mobile I'm personally a little bit skeptical about mobile because we didn't see any web plugins really taking off on mobile and there are applications that serves as the browser and you know need to go to a website and log in I didn't see anything successful like that so there are some Pro companies building protes like that I'm not very bullish on that one but we'll see how it works out uh but I do think there is one more way you can do that that kind of gets overlooked by wider Z cryptographic community that is kind of exploring those ideas it's server like a lot of health checks you don't want to go every day to your bank and log in and so on which is annoying so probably it's going to get automated you're going to leave your credential on your server and and it's going to do those automatic checks for you and that been an explosion of ideas I don't know how much of you are big on the crypto Twitter but last week there was a tweet from vitalic to our guys each three of the tweets went viral and people started discussing all the ideas of the things you can do with web proof uh so yeah so that brings us to the very essential question how does that all work at all so we need to take a step back and look at the thing called TLS connection as probably vast majority of you here know TLS connection is just an encrypted connection and it's pretty much every single connection you do on the internet to your bank web gaming and whatever else is probably encrypted with a TLS protocol and it's you know the https the S stands for TLS so uh probably any data that exists in the world is behind some kind kind of TLS connection and just to agree on the naming there is client server like an NCP I connection and the content they exchange between each other we call transcript so idea of the pro of the web proof is that we take this transcript and we can somehow stamp it somehow we can authenticated origin and make sure it's not tempered with and send it to verifier and the verifier can grab it in hand and be sure that happened between this client and the server and based on that do something right so that turns out to be extremely difficult problem to solve from the cry cryptographic standpoint and it took years for very good teams to uh get to the working solution partially because TLS was updated a few times so every time they got near to the solution they kind of have to redo it um but essential problem is that TLS connection is using symmetric encryption which means it's indistinguishable if content was produced by the server or by the client so usually we want to prove that server send something like hey hey Bank what's my balance $2 million so if client can produce it then obviously he can say oh my balance is $20 million right so well that sucks but there it turns out there is a very interesting um sophisticated solution that introduces this multi- party computations and the way it works is you introduce this new role in the system called notary so the notary is a server that you the client going to connect to so he's going to connect to the original server and additionally to the notary and notary going to be uh taking part in the connection and the way it takes part is half of the encryption happens on client and half of the encryption happens on not and there are very clev algorithm that makes it so that only the two together can make a full connection if one of them is in any way malicious and is not conforming to the protocol what happens is the verification fails right so the client and the notary need to collaborate together to work to connect to the server exchange the information produce the transcript each of them is uh transmitting half a crypted transcript to the verifi which can combine the two into the actual transcript does that make sense is that easy see you're already getting better in cryptograph good so that's pretty cool that's kind of working there is a great team called Tas noty there are part of PSC team so privacy and scalability exploration so that's a kind of a uh Foundation related to ethereum foundation and they do this they do this they created this TS not that that works like I explained here as a public good project so it's open source they keep updating it it's a great very clever team but that's where the TLs story ends but that's not where our story ends so how do we take those web proofs and put them on the blockchain well why don't we just run verifier on the blockchain right why can't just smart contract be a piece of code that runs well unfortunately it turns out that ver verification is very comput computational expensive thing and we won't be able to run it on blockchain or Layer Two or even layer three anytime soon um yeah so that sucks so let's explore so that's the problem let's explore Solutions so there are five Solutions I want to talk about today I don't think we're going to go in details on every single one but I just want to show you the map of what's possible of the kind of a ro ah had so I'm going to start with a naive solution so the na solution is since verifier is already convinced he can just add a signature and say hey I'm Ving I'm telling you this is good stuff and I can send it to the blockchain can anybody see an issue with that what's the issue sir centralization so the verifier can design now on anything and he can issue any action he wishes on the blockchain this is not what we fighted for right so yeah that's a dumb idea by the way that's how every single project who combines CS notary that I'm aware of is working we very that doesn't mean you know they're done projects or anything we just very early we just those web proofs that kind of started working very recently people start to figure out how to use them on the blockchain so yeah so single po failure so actually if you ever drill down they're usually going to tell you you need to trust not not verifier so the naming who's not who's verifier is a little bit fuzzy but you get the Dr the single point of fail and yeah so that's funny we came up with this Solution by accident how about if you run a verifier and in the ZK prover right so who knows what ZK proofs are okay so ZK proofs in just free sentences we can agree on the algorith up front and this is the program and I can run the program can be very complicated program can be run for hours and um at the end I get a result and a proof that the result was actually produced by the program and that's how Z rollups works right so just for the people who's going to watch it on the YouTube uh around the half of the of the people in the room knew what the ZK proofs are so I thought it's going to be important to explain it so this is how thek rollups work they keep calculating the transition function between every transaction of block and keep proving that everything was correctly um correctly uh calculate yeah so with zq proves we can prove that the verifier that a verifier was honest and this can be translated to this can this can be taken to the blockchain and verified on the blockchain now so we're going to have two verifiers TLS no verifier and the smart contract verifier that's going to verify ZK proofs right so we have now two proofs web proof and ZK proof just how just but I'm going to clarify that so the nice thing about that is since we already writing the ZK prover we can add some computation to that because if you think about it you get your Json from your API do I want to par it on the smart contract probably not so we can use ZK uh computations inside the verifier and the ZK prover in the TLs not verifier So Pro and find in Json wherever we want to find and just flash those straight to the blockchain so that already have pretty interesting uh that already have pretty interesting security properties because it kind of translates the original properties of Tas notary to the blockchain so one thing and I'm going to start with a second Point here so we now getting kind of a multi2 out of two so the client and the notary need to collaborate together to get this proof they cannot do it alone so from the user perspective from the protocol user the one who's interacting with the blockchain doing stuff with the blockchain it's already pretty nice property because now the malicious real world asset manager cannot print fake tokens without notary helping him right and vice versa uh the notary cannot do anything but even more interestingly the client don't need to trust the notary so imagine there is a notary and a bunch of different real world ass managers and one day not get hacked now nothing can happen without those clients so the clients are safe against the not right so we already get arriving at much better security properties which you know it's not perfect but it's already so much better at trusting and centralized property so that's especially reasonable for real world asset scenario probably not so good for the web to web free market because in scenario with real world assets we know who their asset manager is right but in case of web to web free market anyone can be a client so not a we can just found a bunch of clients and attack your protocol good everything makes sense so far any questions wow everybody a lot of people are noting yes I think that means some of them really understand what I'm talking about good so one interesting and this is what cryptographic community around blockchain was talking he's talking about a lot for a few months now is how about we use hardware and claves or trusted execution environments so this is the idea so one one of those was sgx it was introduced by Intel and it's an environment where you can run some executions everything is encrypted inside of that and they have a hardware keys that are in the Silicon that are very hard to retrieve from the Silicon right so that's pretty cool with that we could write we can run a notor in trusted execution environment and a verifier which makes it really um which makes it even more safe because now client cannot collaborate with a notary without breaking the trusted execution environment because everything that happens in the notary is encrypted and it's pre pre agreed algorithm and notary can sign on it and say this was the notary The Trusted execution environment can design with his private silicon key saying this result is result of execution of pre-agreed program that was run in encrypted environment that user didn't have access to right so that's pretty cool that we solved the problem finally didn't we yeah except tees get hacked all the time and it feels like there is at least one major hack every year uh so I gave this presentation just yesterday on verifiable Summit and I said there was not a single haw that led to leaking of the hardware key in Silicon and someone came to me after presentation and said you know this hack that happened three weeks ago they actually extracted uh haror keys from the silicon and also something to keep in mind there are very expensive techniques like scanning electron electron microscopy or Focus ion beams so those are techniques available to State actors or Advanced kind of agencies um that kind of can get anything from the Silicon right so those are expensive unlikely to be uh in the hands of attacker but the risk here is if web proof is going to become very successful eventually some State actor um like Lazarus group uh could take advantage of it so also in this first variant we run te on notar and verifier um so it seems we can prove of that by running verifier ink and not in Te so that's that's increasing security a little bit because now client need to call the notary and uh he also needs to break uh the get the T hacked right so it's getting higher and higher um yeah so so so that could be an interesting solution one thing about to know about trusted execution environment they require maintenance right so things get hacked usually the things get hacked are not the most recent version of The Enclave but a little bit older when things get hacked you can apply a software update to the hardware Enclave when that happens you need to make sure that the Enclave is reporting and signing on the fact that the upgrade was applied so it seems like with a little bit of Maintenance that's that's a nice that's a nice direction to go to and uh I think it's a good time to introduce the concept of black phone event so when you design your protocol that is using web proofs then the big question you want to ask yourself is there a black phone event can there be like can I generate a thousand users and each going to uh generate a web proof fake web proof and that's going to drain my liquidity or is there some limitations that allows you to me to when the attack happens to me at the results and making sure that the protocols can go on so we're now getting into this space where we need when we see how nuanced it is and it really depends on our protocol and what are the different solutions that we use to uh to make AQ protocols and I I think it's more mentioned because we're using U multiparty computations but it's also so called 2pc two party computations cine and the notary but what if we increase the number of notaries to to two so then we have three- party computations a client two notaries right so that is technically possible it requires major upgrades to the TS notary protocol or whatever else is available today uh one thing to important to understand is that there is a giant overhead that MPC have so it's a fre orders of magnitude so if you're exchanging one kilobyte between client on the server then the notary and the client are exchanging a megabyte of data so you can see the limitation so the Tas not team is working on speeding that up pushing that down to two order of magnitudes which is order of magnitude Improvement and then when we going to go back to free PC it's going to increase it again right so it's going to so it's very very difficult trade I think I'm running out of time is that right all right then so just going to sum up three out so that's going to bump two out of two multi to kind of three out of three and the nice thing we can combine it with ZK and we can combine with two different tees so we becoming you know now the attacker needs to Haack two different uh Hardware playes needs to collaborate with the with the client so on so forth so you see where this trajectory goes we can add more cryptography we can add more hardware and make it more secure and yeah so there is a bunch of other things I would love to talk to you about other crypto economics based models and uh other considerations for the protol protocol designer so I'm going to skip on them and um just going to say that web proofs are among the most exciting Technologies to transer into ecosystem and broader blockchain ecosystem the new exciting new cases are coming technology needs time to mature so don't send billions of dollars tomorrow with tell us notaries or or web proofs in general uh its nuance and protocol design should be aware of security of those security nuances and stay tuned for the report if you want to know more thank you very much do we do we have a time for one question let's do one question one question then has to be a good one Damian we're counting on you so uh there is a case with two of2 multi for notar and the client and three three of three can you make it two of n at this moment like if if one notary is down then the whole no not really because of the well you can pick two out of n for the connection but once the connection start you cannot Swap and you can really add a third one because it's going to be like you know four five or magnitudes overhead so now you're going to exchange gigabyte to to to verify kilobytes sure so so now you can like choose two of n but when the connection starts you have to keep this one not for the whole connection yeah yeah but uh so now now the only thing available is a single notary it's going to be a major upgrade to the protocol to make it to like that's maybe a year ahead and um and so that's important to understand that you know we need time of for this technology to mature uh but any solutions we've seen based on Randomness and uh building a uh group of notaries there are very new on and not leading to A Simple Solutions so that's something to keep in mind as well so just to sum up currently you can select only one but can you select any from a list you can select you connect to the IP you like the best okay thank you thank you
