# "Cypherpunk Silicon" by Ahmed Ghappour and Quintus Kilbourn // ECC#2 - Buenos Aires 2025

- Speakers: [Quintus Kilbourn](https://streameth.org/speakers/quintus-kilbourn)
- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-01-09
- Duration: 18:59
- Topics: web3, privacy, now, crypto, cryptography, blockchain, data, security, human right, rights, tech, technology, internet, open source, free, freedom, ethereum, hackers, ethics, cypherpunk, dev, developer, dapp, decentralization, bitcoin, computer, surveillance, cyber, peer2peer, p2p, love, solidity, zk, zero knowledge, education, academy, w3pn, congress, ethereum cypherpunk, buenos aires, argentina, vitalik buterin, privacidad
- Watch: https://streameth.org/watch/yt-m0k3IF0cItw
- YouTube: https://www.youtube.com/watch?v=m0k3IF0cItw

## Description

Ahmed Ghappour and Quintus Kilbourn from Flashbots discuss here what privacy is, what it means to them and how it relates to our very basic conceptions of freedom and liberty in digital age.

Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event.
4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. 

Join us in building a free internet for all.

Website: https://web3privacy.info/
Congress site: https://congress.web3privacy.info/

## Transcript

Okay. Um, hey everyone. All right. Uh, active bunch here. Good afternoon everyone. Thanks for being here. It's it's really great to be here uh among friends and peers and the the subset of the world that still cares about freedom and liberty in the digital age. Um I want to start off by framing our discussion um in the context of what privacy is uh what it means to me and uh what it isn't uh and also how it relates to our very basic conceptions of uh freedom and liberty in the digital age. Okay. So privacy is not a luxury. Um it isn't a preference. It's not a toggle. It's not about hiding or keeping secrets uh or even having something to hide or keep secret. Um it is the operational form of liberty in the modern world. And liberty requires space where your thoughts are not profiled, your relationships are not mapped, uh your intentions are not uh predicted, your actions are not scored by governments or corporations. Um, which is to say that I lost the clicker ah which is to say that when you lose privacy, you don't just lose secrecy. You lose the ability to act without permission, without pressure, without profiling, and without persecution. Now, humans were acutely aware of this in the physical context. Um, and they invented architecture to protect their private life. Walls kept the world out. Windows controlled visibility. Doors established permission. Locks enforced autonomy. And the nature of the physical world meant that you could tell when someone broke in. And without these various physical barriers, uh it would be impossible to speak freely, to descent safely, to love who you truly love, uh to explore what you truly think, and to develop your identity without any form of judgment. Physical privacy requires physical boundaries and we don't call a house with no walls or doors transparent. Uh we call it uninhabitable. Modern technology of course changed everything. Uh two of the most important inventions of our time are the internet and the mobile phone. Uh they've changed the world arguably for the better. Uh however they've also turned out to be the perfect tools of the surveillance state and that is because nearly 100% of our communications are transported as digital packets across the backbone of the internet. And so as people worldwide communicate, explore and transact business through online services, almost all of that information flows through internet choke points that nation states like the United States and its allies are capable of monitoring. Advances in computing technology that enable automated collection, automated processing of greater amounts and different types of digitized data uh mean that more information may be relevant and material uh and therefore legally accessible to criminal or intelligence investigations and a bunch of the the authorities that control that are thrown up on the wall at least in the US context. Um, and where passive surveillance is not possible, of course, governments will keep pushing for exceptional access, client side scanning, key escrow, lawful access mandates, supply chain controls, the idea that only the good that the good guys need a special backdoor. And we all know this story. Once exceptional access exists, it becomes the rule. And the rule is surveillance. And of course, much if not all of this is enabled by the centralized private actors that operate as parallel intelligence services. Your apps, your devices, your platforms, all quietly harvesting telemetry behavior, biometrics, and metadata. Uh, no warrants, no oversight, no off switch. They don't need suspicion. They only need your device to be theirs. And it is. And together these forces hollow out liberty uh from the substrate up. Your movements and communications uh your preferences, your relationships all continuously ingested into the opaque systems that you don't control. So again the point is simple but foundational. Privacy is not privacy is liberty. Privacy is not secrecy. Uh it is agency and agency is the foundation of freedom and liberty. And of course it follows that an erosion of privacy is an erosion of liberty. Liberty dies the moment a person begins performing for an invisible a for an invisible audience. And that is what surveillance creates. A stage where every thought feels judged. Every action feels logged. Every deviation feels dangerous. And you can't be free when every step you take is a data point. Every conversation is metadata. every gesture becomes a training material and uh for systems that you did not elect and cannot challenge. Surveillance doesn't need to punish you. It only needs to watch you because being watched uh as I'm being watched right now is its own form uh of violence. Um a soft sort of ambient coercion that turns autonomy into obedience. The process of eroding liberty is of course not done dramatically. It erodess quietly through surveillance, through profiling, through the slow normalization of being watched. And the moment people expect observation, they begin to self-censor. They behave for the observer and not for themselves. And you cannot be free if you cannot think or act without anticipating someone else's gaze. And that's why every political philosopher in history agrees that privacy is not the opposite of transparency. Privacy is the precondition of freedom. And if you remove it, liberty collapses into performance. Of course, the cyber punks, the cipher punks understood this. Um, the cipher punks uh ideology gave us a very clean model. Math beats trust. Cryptography beats surveillance. Code beats law. And for a moment, it really did. BGP and TOR and later Bitcoin and Zcash and Ethereum, these are all tools that pushed back the frontier of digital autonomy. But of course, there's an uncomfortable truth. Cippher punks write code. Uh, and we're running that code on unfree silicon. Silicon that's been captured by centralized actors like governments and corporations. And so today, cypher punk code runs on silicone we can't read. Every instruction your machine executes, every key you generate, every secure enclave you trust, all of this trans transits through closed source microode and firmware that is designed by a handful of companies, none of whom work for you. So if liberty in the digital world relies on encryption but the substrate executing encryption is unverifiable then what do we really have? What we have today is actually uh a hardware stack that is a surveillance dream examples like Intel me, AMD, Qualcomm uh bassband uh opaque microode proprietary firmware blobs. This is not a conspiracy. It is architecture. Even the most private software stacks run on foundations that we cannot audit, we cannot verify, and we cannot meaningfully control. And so we could talk about encrypted mem pools and private auctions, confidential transactions, but if your TE is signed only with keys that Intel has and its security properties depend on Intel's business model or whatever AMD's firmware actually does, then privacy is aspirational. It's not real. It's actually an extension of these guys good favor. And sometimes it is the battering ram that gets you got uh when you least expect it. Um now I'm going to turn this over to Quintis who will provide a bit more of a technical explanation of uh how silicon how open silicon can solve this and what we're doing about it. &gt;&gt; Yeah, cool. Thanks Ahmed. Um, so Awan did a good job of sort of teeing up why silicon is a really important problem for the cipher punk mission. Uh, but to get a little bit deeper, maybe just to recap what A was saying, uh, look, we do have this sort of closed proprietary layer that sits beneath basically everything we build in the software world. Um, and this opens up room for back doors that undermine our privacy. And it's not theoretical. we have a lot of uh historical examples to point to to know that this is actually a legitimate threat and and these are only the cases we found. It's very hard for us to know what actually is out there today, who's monitoring us in ways that we don't expect. Um but but hardware isn't just something we have to rely on not to undermine our privacy. It's actually something we rely on to provide us security and to provide us privacy. Uh so even if the adversary isn't the one who produced the hardware or the firmware, uh they sit outside the hardware. We still need to rely on the the hardware to to protect us. And now you might be wondering why why do we need to rely on secure hardware? The most basic answer is genuiness. How do you know that a physical chip is the same one that was sent to you or that corresponds to the design that was maybe made open or maybe uh closed but at least some claims were made about it. A most concrete example is if you order a hardware wallet uh you actually have a mechanism through which you can check that this isn't some phony that uh someone you know intercepted or or planted between you and Ledger uh sending it to your home. And the way we do this is by embedding a private key in the hardware. And we need to protect that private key because if an adversary can extract it, they can put it in their uh phony hardware and send that to you. Now once we have a private key in chips, we can take it a step further and say uh why can't the chip sign the software that that we're running and tell us even if we don't have physical access to it uh what software is being executed on this chip and allow us to remotely interoperate with that software. And then taking that a step further, we say well why don't we build security mechanisms into the chip so that uh even if some adversary is trying to interfere with the execution of that attested program uh we know that the program is giving us confidentiality guarantees it's giving us integrity guarantees over the software execution and this is where the term trusted execution environment or TE comes into play. Now there are very many examples of how tees are being used today and I just wanted to choose a few. The first is AI big buzzword uh obviously sort of the the frontier of where technology is heading at the moment and really the only way that we scalable way that we have right now of making sure that the inferences we send to AI models or even the weights that comprise the models are kept confidential uh are through the use of is through the use of secure hardware. uh signal uses TEES to preserve confidentiality while uh providing contact discovery. Uh verifiable sensors is a very important category when uh generative models can produce images and we don't know if they're coming from journalists or real people uh or a lab in some country we've never heard of. Um this is very important. You also want to know that security cameras are not sending data off somewhere else. Maybe they're processing things locally, etc. Uh another category that's very uh important for the future but even relevant today is is these cryptographic protocols that um are vulnerable to collusive dete attacks undetectable collusive attacks that break privacy and these kinds of things and even if we look at deployments today or most NPC nodes or many NPC nodes are deployed in TEES to protect against exactly this kind of attack and this will only become more and more important as these uh deployments scale and become more widespread. Maybe a very basic uh justification also is that uh the vast majority or very large fraction of our uh sensitive data of our important computations are flowing through data centers. Uh and that certainly isn't hardware that we have physical uh protection over or custody of. Now the reason we're giving this talk uh is not because hardware security is great is because it's a mess. uh and there's you know many reasons why it's a mess but to condense it into maybe two reasons uh one is that there are lots of bugs uh and the reason we have these bugs is really because of sort of structural issues in the hardware world this is one interesting example where Raspberry Pi did a great thing and they said we'll have a public bounty we're producing a new chip uh we'll let anyone come and try to to break this hardware uh and lo and behold very quickly uh an a design that they had incorporated that had been around for many years and believed to be very secure, was very easily broken. And if you read the report from Ioactive, the team that did the break, they say, "Well, we've actually been waiting for an opportunity to break this mechanism. We thought that it was broken for a very long time, but we're waiting for a legal opportunity where it would be it would be okay for us to do this." If you read other papers publishing these kinds of attacks, they say 90 95% of the time we spent pulling off the attack, we did reverse engineering and then it was easy to do the attack. uh and this means that there are so many security mechanisms out there that may just not actually work. There definitely are some that do work and we have to be able to tell the difference and we can't right now. The other problem is that by design a lot of hardware isn't actually that secure because it was built for GDPR tickbox exercises and not for uh the same threat model that people at this kind of conference care about. Um and the bottom line here is that uh a lot of secure hardware doesn't give us security in the way that we think about it here. It's basically an extension of the good favor of large corporations. And it might be useful today, but it's not something that we want to enshrine or continue to rely on going into the future. So what what can we do? What should we do? Uh we need I'm trying to introduce a new meme. Uh and so I put extra effort in. We we we need solves uh secured open verified silicon. Open is the most important crosscutting property here. Um there are many aspects to it. Uh you know we can open up some of the code that the act you know different the logical design that different teams are working on. Uh then there's a harder problem of opening up third party IP. The fabs have to work work together. It's a complex problem and we can start tackling all of these bit by bit. Thankfully there are already organizations that are sort of leading the charge here. Tropic square, Open Titan, you may have heard of Vitalik announced the Vensa initiative which is also pushing in this direction. Um and you know even if we aren't working on silicon what we can do is uh favor the open silicon, prioritize openness and think about that at the silicon level. Often you'll see companies say, "Oh, we have open hardware. We're open hardware solution." And then really what that means is that the software running on the closed source chips is open source, which is not the same thing. Um, we need the hardware to be verified, which means that we need a way to compare the physical instance of the silicon to the design that was it was claimed to satisfy. And this means we need to invest in verification technologies like imaging. Um but also we need to design the chips to be easily verified. And finally we need this verification to be transparent so that uh the end user can uh verify it themselves. And so we need to be cryptographically signed, decentralized and posted to public databases like blockchains. Um and finally we needed to be secure. And so these are these are the keys that or this is the key representation that was read out of the Raspberry Pi. Um uh and we need to do more of this. We need to break more of the security uh uh mechanisms. We need to test the assumptions uh just in the same way that we did uh or we built up security in the cryptographic world uh through competitions like what NIST has run to find which assumptions we can rely on. We need to do that for hardware and that means we need to propose mechanisms for security and break them and go through the cycle as fast as we possibly can. Uh and that also means removing legal barriers to doing so. Uh so to to wrap it up, what are what are we doing about it? Um this trust is te initiative started at flashbots. It's a sort of ecosystemwide thing. Now um our main goal is to produce an open physically secure TE within the next three years. Um what that exactly means, find me afterwards. We can talk about it. &gt;&gt; Wait, I'm sorry. Could you repeat that? What's our main goal? But uh our goal is to produce an open-source physically secure TE in the next three years which is a very ambitious project. Uh but I think we can do it. Uh and I have two minutes which is more than I need. Uh and then you know around that we have uh a lot of uh secure hardware topics and research that we're trying to support and develop uh especially around puffs around side channels and a bunch of other stuff. Uh, and if you'd like to to learn more, you can go to t-te.org uh or or find us afterwards. Uh, thank you very much for listening.
