New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Troubles at the Horizon - Denis Jaromil Roio | Web3Privacy Now - Rome Meetup 2024

Ethereum Cypherpunk CongressTue, Oct 7, 2025, 12:00 AM

Web3 and Social Justice: Hacktivism in the #crypto Era and Beyond Are we building technology for machines to understand humans, or for humans to understand machines? This talk will explore practical insights on creating human-centric technopolitics in the age of #Web3, focused on the commons and social justice. Jaromil is Director of the http://Dyne.org foundation, and applied cryptographer at ForkbombEu. He started and facilitated many free and open source software apps (ZenroomOrg, DevuanOrg...), and some projects for the European Commission. He holds Ph.D. in #philosophy, and publishes papers on free software, ethics and society, media theory and mathematics → https://jaromil.dyne.org ABOUT US Web3Privacy Now is a think-and-Do-tank of hundreds of people, projects, and organizations committed to protecting and advancing civil liberties, decentralization, and open-source software. We aim to manifest profound political and social change by advocating #privacy in the #web3 Era. With unified efforts, we carve out a path toward a more equitable, decentralized and freedom-respecting digital commons. → https://web3privacy.info/

Transcript

[Music] I'm happy to be back here I was here one year ago and uh yeah it's a nice Journey I'm following you guys with web three privacy I think you're doing a lot of good things to the crypto uh space and uh yeah I'm saying this on top of uh quite some time that I've been around uh in in the crypto uh communities so this is this is the the foundation I represent dinor we are Partners that's a little bit of a bird's eye view point of view that of what we do and we're based in Amsterdam but we are really International uh so our members people volunteers projects are pretty much uh sparse around the world uh one big project we have is Devan which is a fork of Debian without systemd hence much more secure is very popular in the US and another project is T maybe some of you have um ever used for encrypting your files on New Linux we have a bunch of other projects I will talk about one only one here but I came here to talk about other things this is obviously uh what where we learned to do what we do so the G project was absolutely seminar important for us I know it's not very important to talk about it um in a crypto conference because fortunately crypto communities accepted the fact that there is no security through obscurity and most I would say all projects that are that are worth to to be mentioned they are absolutely open source so um these are the three four freedoms that the Grom project stated and the free software Foundation is there to represent that are very important to to have in every project so about me as as Pi Geo said yes i' I've been a squatter for about 10 years I I've squatted around Europe for in many different places and yes I was uh on the Interpol dossier for two pages they had about me when I was 19 as a potential cyber criminal I had the luck to look at it huh well you know uh yeah I had the luck that I had it was that my work Giver at that time uh a little lab in the University where I was helping to do like multimedia CDs that was the hype at that time uh he really liked me so when he got this news from the police telling him hey a potential cyber criminal is working for you he preferred to tell me so he showed me the the dosier and it was amazing because they had not only stuff about me but also about all the people that I hang out on IRC at that time we were using IRC they had nickname channels they had a lot of information it was like 99 so yeah warning to everyone like you know the sometimes the people you're trying to protect yourself they are way more advanced than you expect it's very difficult to maintain privacy I was a kid I wasn't really much attentive there wasn't thought at that time I had I had secure shells around I I I was cracking into systems I was having fun and then I decided what to do in my life became a developer and a squatter uh so yeah obviously no one of us here missed the crypto sensation so I'm around since 2011 these are the people that really inspired what uh what we are doing and uh I think it's uh unique to have them in the same picture uh here it's Richard stalman the founder of the free softer movement when he went visiting Julian Assange in the Ecuadorian Embassy I think uh the ethos of transparency that Wikileaks brought forward in in governance in the intelligence communities in in journalism uh matches very well the ethos of free and open source software when we are developers that want to see things uh work well and built in a transparent and bottom up way so yeah I think this thing is is just everywhere and we are one of the many processes that were forked by by uh our communities so one thing that is very important to focus on is that me nor anyone else here will be the solution or the hero not even a Sange uh or the Martyr of this movement but we are like really growing and this is where we are winning not actually in maintaining our privacy but in spreading our beliefs uh yeah farther one thing where I left you at the previous uh presentation uh it was uh well this is my my doctor research um and the statement following this you'll find the the research on Algos of.org which was one of the last statements in the previous presentation so I'd like to pick it up from here um this is a fundamental Choice when you look at what we are building and why and this is also the reason why I built Zen room as a product as a component in the web three space in the past five years uh when I develop software I start asking myself this question every time what am I developing it for and most of the uh commercial products they develop so that machines understand humans and provide answers this connects to the first problem uh of the three problems that I will present you today that are trou at the Horizon that I see that the web three Community needs to challenge this is just a a Prelude to that but it's a very simple question and um I believe that when we develop crypto cryptography uh let alone okay uix may be very difficult so it may be very difficult to make it usable but we are developing so that there is a transparent process to the transactions there is um there is a predictability and the underpinning of everything that we develop in crypto is determinism so there is a deterministic system that we can actually uh read as humans and and and base as a truth that we can establish one thing that I develop which was the last and the only product that I tell you about today is Zen room this is a VM I'm busy with for the past years it was funded by European uh commission uh research and it is today used in various products the VM can be programmed in human like language it runs in 2 megabytes of ram its payload is less than 2 megabytes it runs also in wasm in a browser so we build endtoend cryptography systems the most beautiful part of it is that it's programmable in humanik language so you don't need a developer you don't need a coder to develop uh with z and uh this is this is exactly why I develop it so when I have when I and I tell you also as an entrepreneur when I let humans understand machines there is an enormous value that is not seen by the majority of the industry is that I can have work people work in an interdisciplinary way and I can have domain experts to work besides developers and this is making our software unique our process of devel in software unique because we can involve directly the people that are domain experts imagine we work for instance in the energy sector with uh smart meters and people working on the grid for uh you know renewable production that can be resold to the grid they study uh a single nation for 10 years just to understand the percentages how they go around and all the taxes and levies that need to be paid to the grid these people have a unique knowledge that needs to be uh communicated to developers in the moment in which we make a firmware that will go into the the smart meters and this point is a point of failure in most of the developments because there is a big liability in the communication which is overhead of communication between the domain experts and the developers so when you have humans to understand exactly what goes on machines you can also distribute this liability you can have a lawyer to review your contracts and this will facilitate a lot the internal processes also of your company so this is the direction we took we have a very successful spin-off company now which is Fork bomb but I'm not here to talk about that uh I introduce you this concept because I want to take it off from the last presentation and go forward to look at three challenges that I see at the Horizon that we could solve as web three privacy and in general as what I call the real crypto movement so not those Road shows full of sociopaths in Las Vegas and were not uh uh that are you know like the Balmer style of of crypto but from the real crypto uh Community which I believe is here so the three challenges are briefly put like this we have in in front of us the rise of non-deterministic Technology we have a big identity grab coming out uh from various Technologies deployed all all around the world and we have complete lack of threat awareness so I will zoom in in each of those and explain and I don't have a solution so I'm proposing you as a challenge new use cases perhaps I don't know we'll talk about it in front of beers so one thing that I mentioned already is uh that we are living in a software defined era there are four eras that I try to sketch in the past talk and this this is I believe the one where we are are uh living in it's um it has many characteristics it could be described in many ways but uh yeah well since we are in Rome one important thing to keep in mind is that in this era we are losing what we called the Roman law on possession so uh private property is changing its uh configuration completely today you can buy cars that have functionalities in them but you will activate them only if you pay a subscription BMW cars have heating Wheels steering wheels uh only if you pay a subscription that activate them so you hold and of course if you're are Gamers you know uh you know that is a very problematic what you own and what you don't own in games there is a discussion in the European Parliament about this and a law to uh terminate the strings attached in games you buy a game and maybe the server goes down and your game doesn't runs anymore so this software defined era is actually deciding us from these three rights that were established in Roman law uh that well simply put is that once we own something we can use it the way we want and U you can see these in many different fields I invite you also to to stand up and and try to relate to this later so I believe that we have a new paradigma in in ICT coming up now and this impacts directly the era in which we are living the new paradigma is that our technology stops being deterministic this is perhaps on the llm hype so on the machine learning hype now growing but the fact is that the deployments of these machine learnings are detaching us from a deterministic process this is I believe a huge shift in Paradigm um it is similar to uh the difference between physics and chemistry in chemistry you don't have the terministic processes if you mix something in chemistry you cannot get to the ingredients anymore you can hide the ingredients huge industries were built on Industrial Secrets based on this sugar sugar uh sugar water Industries so uh nowadays we are you know like downhill to uh so much choice between peps in Coca-Cola de facto these industries built themselves on on huge indal secrets that were possible because the technology was not deterministic now I'm making a very broad context shift but imagine we are dealing now with llms that do not document the thought process so we cannot reproduce the same output with the same input this is a fundamental change especially impacting us in a software defined era so we will not be able to distribute liabilities or establish why our subscription worked or not why our software defined reality has reacted in a way or another so reality will be not anymore interpretable by causing effect reactions this is the smile for Medics for instance medicine is based on that is the smile for for lawyers uh it will be very difficult to establish uh the the cause effect chain effects of systems I believe that so I mentioned this as the first trouble at the Orizon because I believe that our movement is there to stand against this if as a as a applied cryptographer that's my daily job uh every every day since 10 years I am I stand against non-deterministic Technologies what I want to know is exactly like how to how to reobtain and demonstrate the same outut with the same input uro you work on Oni which is like a huge worldwide struggle to determinism you're trying to establish where internet is blocked in the world by a sort of angiography of the network so that is extremely difficult and and Uphill but uh you see you you probably can really understand what it means to live in a non-deterministic system where you cannot establish the liabilities we cannot say this country has blocked locked or not it's very difficult to to do that so beware this is very much on a philosophical level so I want you to relate to it in your own context eventually the second danger now I'm I'm talking about my biggest client so uh but uh I am very open about it and I am open with them as well whether they like to hear it or not um the fact that the European Commission in particular the jrc The Joint Research Center is working on a European digital identity architecture is not news to many of us so this is part of Adas 2.0 is an update to the identity systems that are being used in Europe uh the Adas 1.0 for instance has compliance with what is used here in Italy as a speed and the Adas 2.0 is getting to new standards what they are to do the standards they will put a wall in your phone so that you can load on it an ID or a driving license for instance these there are pilots also in the US there are developments of different standards and different protocols between the US and Europe is very interesting to compare them I was just one week ago running a seminar of two hours into the Central Bank of Italy about this it's uh there are many people working on this in Italy the mint is very Advanced and also there is a team of the Govern government that is implementing this open- Source standards I'm not here to tell you that this is dangerous because it's not open source it's actually the the methodology is quite okay there is a problem in there this is like a you know quick glance of the use case you are in crypto so you are familiar with this I guess um you can load a a a credential on your on your mobile phone and then show it and produce it so you one will think oh then I can do like selective disclosure zero knowledge selective disclosure yes zero knowledge no and we will see why and um in general in this system we have people that believe that it's a good idea to put a a card into a mobile phone so who comes from cyber security knows uh there are some threats this system has one big problem that was death to criticism perhaps and I know internally the project was pretty late so is running late and he rushing to obtain uh the set of of kpis that wanted to have large scale pilots on the other side were slowed down on their on their initiatives and kept uh sticking to a main standard which was um which was criticized especially on the crypto side so I'm showing this slide which is the first first page of a cryptographers feedback presented by these names and if you are into cryptography you will recognize that some of them I would say all of them they these are the superheroes of cryptography like these are cryptographer stars like Yan kamish or Anna Lanaya or you know Bart prel or my my colleague yapen hman was there we worked on a previous European project so they came out saying that many things don't work this and especially the cryptographic part so I'm not CR I'm not alone criticizing this there's also a very interesting feedback by the team in Finland working on it and I will just make a very short overview of what doesn't works let alone the politics of having an identity centralized into a standard and protocol across Europe but what doesn't Works technically so first of all there's a lack of privacy this system does not uh do any zero knowledge it could be depending from the implementation it could be even vulnerable to replay attacks and definitely there is linkability of presentations so in case of issuer and and even verifier collusion especially verifier collusion you can collect the the presentations so every time you show an ID card or a or a or a or a driving license colluding verifiers could track you across your presentations inadequate cryptography this system is stuck to what is an approved standards by Boards of Engineers that are extremely slow in Europe and so it can only use hmac basically key hashing there is no zero knowledge proof there is not even BBS plus which is a 20 years old algorithm for zero knowledge proofs which is used in the US in my opinion the US is Way Forward in in their in their approach here and uh in Europe we are justay staying on on hmac why especially because we have faith in hardware and this touches us especially in the web 3 space there is an extreme faith in the fact that something buried in Hardware will be secure so if a computation is done by a particular chip a te so a trusted execution environment which can be then uh can be compliant as an Hardware secure module these are the bdsw then it must be secure and I know this is wrong there are a lot of attacks done on these chips the chips can be isolated into simulation environments they can be peeled under the microscope keys can be retrieved from them there are tons of attacks on this and this is just like not looked at by the people working on this they're just like you know sliding off the reliability well the engineers said that the hardware must be good I think one big challenge here I hint you the web three community and in general the crypto Community can can take up is to demonstrate that software computation so computation made in software can be secured we need to start talking about secure uh Hardware um like HSM Hardware secure modules software secure modules you can make Compu uh deterministic and you can make it peer reviewed this is you know blockchains in a DLT and this is one of the best things that you can do with a blockchain rather than put it anywhere where you don't need so we need to start moving politically and technically technopolitical I would say this front I believe there can be computation in software that is as secure if not even more than in Hardware we can sign VMS our our VM is one of many you can sign a evm build and obtain deterministic results so why not and you can put it in as a payload you can facilitate this has a lot of U consequences one consequence of Fate In hardware I like to mention is uh is the fact that and I will see I will show it in the threat if you have Fai only in Hardware only only Hardware manufacturers will be on top of this it means that only certain Hardware manufacturers will be able to develop devices that can process your identity and guess how many companies are in the market producing mobile phones how many operating systems 99% of the world uses Apple and Google so we are in the hands of two everyone knows in the commission they are just preparing a red carpet for them but no one says it and there are proofs of what I'm saying there is a NGO which is called open Wallet Foundation funded by Google Google and Apple getting all its space into the lobbies and basically they are the ones pushing if you see the events they organize they are Road shows they don't have scientists on the stage saying oh this could be done this this could be done that it's like Steve Balmer shows oh we're going to have digital ident in Europe yeah like this so Fai in Hardware has many many consequences and here we need really to to step up as a community revocation very very bad um remember green pass here in Italy Minister salute they published uh the the revocation lists in clear you could actually work through them to understand Who had covid who not like complete violation of privacy guarant privacy overlooked it emergency okay things could have been done better but they weren't and this is happening again no revocation no privac privacy preserving revocation is built into the system it could be done we produced a paper called sdls published by E Triple E a month ago in which we demonstrated a system of revocation privacy preserving with accumulators basically this is not going to be like this and worst of all also we demonstrated the revocation needs a threshold otherwise we live in a dystopia because if we put a one button in the hands of the same issuer that give you the ID card and this Governor this government this prime minister this this power can push the button and revoke you any time this is a problem we need by by law but also by cryptography that more than one institution approves the revocation of something imagine you are a journalist that is writing the truth in Hungaria and you have a prime minister like the one now in Hungaria which is also by the way the president of the commission right now this this power could just like revoke all your credentials strain you leave you without a car you you will not even be able to bring your kids to school with the car in at the Press of a button but if you're a journalist we argue you should have also the league of journalists approving such a thing and so on and so forth so we need the revocation that has a threshold we need a little bit of a safety there it's not there they are deaf to it scalability and usability were issues raised by The Finnish um by The Finnish colleagues and you can guess what they are about this thing doesn't processes enough verifications and issuance and usability is is very bad because it's very complex they're adding things to it they're adding against as a protection uh against uh linkability there are the issuer will give you 10 or 100 credentials that you will show and you have to choose through them so you you will use them like a strip card and um yeah well there are huge usability issues in all what they are doing as a patchwork the all identity system some lawyer raised the hand was not designed for legal persons this is only for for natural persons so big lack of feature there and last not least I get to the third point that I wanted to make there is no threat model Believe it or not I work with my colleague and cyber security expert Simone onofrey uh who he's right now at the w3c I will explain you why I'm mentioning this we looked at this together and we looked at at the LR specification and we saw that there was no threat model before doing the architecture reference framework so no one has studied what are the threats the security model of the system we are defending against so every time you talk to them it's just like well this is not a threat you know you it's depends who you have in front they can tell you no but this is not a threat for us you know like you have officers promoting this yeah but this is not a threat this is a threat this is not a threat so it's it's completely you know you are just like making it up as it goes I as a security researcher am used to have a threat model before there is a reference frame before there is an architecture because you need to establish what you're defending against because that you like it or not you cannot defend about everything so there will be no architecture that will be defending about everything you have to choose and you have to choose well what is your threat so I think this is utter disgust utterly disgusting about LD ARF I understand people that are doing it are in good fate but probably they're not capable of of the task they are they are taking uh one thing thing that they see everywhere is this threat so here I tell you the lack of threat model is the third problem I see in front and is something that we we need to work on we need to tell people we need to educate ourself and people outside about threat awareness this is not the only threat that we are facing when we do an identity system how much time do I have more like is and this is what everyone work working on the system Seas all the time they just see identity theft as criminals well no I think that if we work in an interdisciplinary way and we consult really the stakeholders Civil Society people working journalists and so on and so forth there are many more threats and I give you here an example one threat is populist politicians not absolutely accounted but it's happening in Europe we are getting the worst people elected for a reason or another and the in using fake news is not saying it's going better so these people will have one push button and we revoke the the the credentials of those who they like and don't like don't tell me this is not happening because here right here in Italy there was a market of secret information leaking off Telecom uh just 10 years ago and and it was a market about information of politicians that were sold between between parties so this will happen and this is probably already happening and this is one threat that they need to account for hence for instance threshold revocation gray bureaucrats they are well-meaning they of course are all in very good faith but what they have in front is a gun chart and they need to finish before the funding goes back to home so they are rushing into implementing systems that are that are exposing us to this sort of threat threats obsolescence they want just to use the chip that is there the standard that is there no one wants to make the leg work to understand what is zero knowledge and apply it they will just ship it you know this this Audi needs to be already implemented in 2025 expert Consultants you will see the lobbies crawling through them you have an amazing amount of them right now there are only a few people working at the very top level they are completely overworked of course they are in good fi but you cannot develop the standard be on the board of two foundations and go around in Road shows telling people that a is good there are very few people on top of the of the of the system right now and uh this is like a very colluding and small circle right now Mega corporations you know what they have to take from this if I told you that even uh whatever verifier between who checks your uh your driving license and who checks your uh I don't know the ticket of a bus or a train if you want if they collude they can follow you imagine the big corporations behind the main OS where this is running what they will know about people they will have a huge amount of data about people I'm talking about an ID so I'm talking about what you're are compelled in the Netherlands we need to carry an idea at all times uh if an officer asks you for an ID three times you go to jail if you don't produce if you don't present your ID so this is something that is not just for geeks is for everyone the data grab that we are behind we are looking at which will be in the hands of Google and apple right as it has been in the in their hands for for the green pass already technical trial that was the green pass under covid it will be all in their hands as you know they have God on their side they are doing good they are good doing no evil but in fact they will have a huge really huge uh stake an asset so that's all um I look forward to your reactions here or of the stage and U I hope uh I didn't scare you too much I think that us as a as a as a community we are on the Forefront to face what is happening and again there are ways technical ways already already unlocking the fact that we can do secure computation in software we can demonstrate it we can Lobby and make it understood by people it's very important and uh personally I join forces with the w3c here you see a a new community group this is a threat modeling community group tmcg it's open you can just join it as a community community group you don't need to pay fees or be an invited expert and you're very welcome to join it if you want to bring your experience not as a developer of security expert what do you think is a threat that we will face in the moment in which we develop such an identity solution and uh yeah then all contact you have all the channels where we hang out cheers [Applause] yes any question um I'm coming I'm coming hey um so I just walked in like five minutes after you started or something and I guess the reason why you're talking about this um EU reference framework so a governmental framework rather than you know theoretical Frameworks that we could build our sales without reference to governments is this because because of the worry that these things are going to be required for basically like ultimately there is the big stick of the government behind it so in which case is there any other option than um getting government or bodies to agree something better I think for now the option is keeping things as they are and I know from internal sources across governments working on this that they are doing this as a as a demonstration that can they can Implement what the EC is talking about but they will never put it in production because they think it's insecure because they have read this this criticism and they don't think this this can really roll out so this is the good news at the end but yes I'm talking about it not because it's the coolest thing but it's because it's going to be mandated to our grandmothers uh you know so anyone and I think that's very worrying and I'm telling you because probably you have better Solutions but they don't know about it and uh anytime I tried to tell them about better solutions they can look at they thought I was just like uh you know uh not not really credible uh talking about what I was talking zero knowledge proof blockchain nothing is standardized so um yes there are alternatives but we need to go back to you know uh first I think I think I'm not I'm not a lobbyist or an expert in politics and here becomes very political I think we need to uh face this wave first because it's a hype to wave and then and then go back to actually discuss in in a scientific way with a scientific method with a peer-reviewed method which we have already in our communities in a way or another what what works what can work what can really make our life better and the privacy of citizens better and the liability of companies lower uh and and so on and so forth I hope I reced you yeah yeah first first stop it and then go back to the ding board I I I think I yeah I'd rather do that anyone else yeah but you you said we have beers at the end so everyone wants to just like cheers thank you [Music]

Automatic transcript — names and jargon may be misspelled.