# Anonymous Engineering - parazyd | DarkFi

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2023-10-07
- Duration: 17:07
- Watch: https://streameth.org/watch/yt-sohXXWKqGzk
- YouTube: https://www.youtube.com/watch?v=sohXXWKqGzk

## Transcript

hello um yeah I want to talk to you today a little bit about Anonymous engineering and what it is so um coming from 2013 surveillance has been going on and there were encryption Technologies emerging and in 2013 James called me the FBI director has given a speech on a thing called the going dark problem and what he says is unfortunately the law hasn't kept pace with technology and this disconnect has created a significant Public Safety problem we call it going dark in the current Paradigm of web 3 we all use ethereum we all use Bitcoin and similar blockchains they all have transparent ledgers this is used to track wallets to do analytics to give you ads to surveil you in a general sense it's used to censor people and it's used for law enforcement as well what we have what happened also recently tornado cash the developer was arrested and the U.S enforced sanctions on on such privacy tooling in uh in Dubai we got we got a ban of privacy coins of Monero and Z cash you know like the layer two a delayed to zero knowledge chains and similar things binance yesterday or two days ago also stopped and disallowed trading of privacy coins in France and also in some other countries as well in the general sense what we have in had anonymity today we have a view of these blockchains like Monero and Z cash they take a different approach than the classic ethereum type style transactions and account systems they're more similar to bitcoin which uses like an etxo set they use techniques to enable privacy for people so in the in Monero we have ring signatures we have bulletproofs which allow us to hide the sender and the recipient and we were able to hide the balances it's not ideal and Monero devs are also thinking about implementing ZK snarks to improve the anonymity set zcash uses zero knowledge proofs from its Inception basically and it's been working well and some of their technology is also used in dark fire um however they didn't manage to scale to Smart contracts because of technical debt for example Z cash was forked off of Bitcoin I think in like 2015 and the problem there is like they had to build on top of these things they didn't start from scratch so they never managed to scale to have Anonymous smart contracts or similar things Monero was designed to be money just as a currency so I don't think they have any kind of plans to implement smart contracts in ethereum we have attempts of gaining privacy and fighting surveillance through things like tornado cache layer 2 mixers that not only mixers but Anonymous pools where we can deposit money and then change it with other people's money as well anonymously and then we can withdraw this money to different addresses that are unlinked to the previous deposits so we have a way on ethereum to at least somehow anonymize our money but I think it's only a stop Gap because ethereum as on its base is just purely a transparent chain so wherever the money ends you still know like yeah it was transferred to this address so like let's follow and you can depending on the person's Behavior they might use their wallet in certain ways that the anonymizes them so in uh I mentioned tornado cash this led to U.S sanctions being put on the actual like smart contract front ends it led to censorship uh in the sense that the websites that were not hosted on decentralized things were blocked from access and the rest where we saw Alexa got in let's say Netherlands got arrested because of writing free software and working on tornado cash so uh let's dive into a bit more technical things I basically want to give you tooling and a general idea on what Anonymous engineering is and how to how to actually build Anonymous protocols there is it's not like magical let's put everything inside ZK and somehow it becomes anonymous I also noticed people think like zke EVMS and these types of things bring kinds of privacy that's not really correct they only use their knowledge because of its succinct property so don't assume that ZK uh EVMS or ZK layer twos will bring you any anonymity in ethereum so what are ZK snacks let's say we have some secret values and I want to prove to them that I actually know them so if I have a secret data I can hash it and but do it through a ZK circuit so I will give you a proof along with it this means that I usually you can get a hash of some file or some data from the internet from someone but then there is no proof that you actually own this data but if I have this data and put it through some kind of caching circuit I can give you a proof that I actually calculated the hash function from this actual data so we take this assumption for our Anonymous engineering to then we'll see how uh how this works in practice I want to talk also about sapling it's just it's the name of a Anonymous scheme to use EK snarks and homomorphic commitments like Peterson commitments to enable Anonymous currency this was designed initially by zcash but also we took it and expanded the concepts a little bit so what it does it consists of two phases phases called burning and minting we have some object that exists as an output in the utxo set so this object can travel through the through the blockchain but being burned and then minted in a in a different place so there is no link to each other with these techniques we can we can have a currency on chain but balances are hidden and like payments to from A to B nobody except the party is doing it can see what's happening but we use zero knowledge proofs to prove that actual State transitions are passed correctly so let me see if this pointer works oh yeah cool so uh we can say we have like a coin c this object that I mentioned and we use a zero knowledge proofs to calculate its its values its inputs inside so let's assume there is a coin uh owned by Alice so it's what it says Alice Pub it's Alice's Pub Key then there is a unique serial number to each of these coins and there's some value so imagine it's like Alice's puppy is the her address and the serial is some random number like you see on the cash Bill the under account note and the value is like 100 so that's 100 tokens so in the first phase when we want to send this money to someone we will burn it and create derive a nullifier nullifier is also oops a nullifier is also a Hash Hash the hash of values but in the nullify we use this Alice's secret key and the same serial from the coin we have so with this we actually proved that Alice indeed owns the coin and then if we want to send it to Bob we will create another proof of hashing Bob's Bob key which he gives us through some Channel we derive a new serial number and we reuse the value and then we can reveal this c as a public input to the ZK snarks so the and check that it's Unique what this means uh this means that no two nullifiers can be the same or no two coins can be the same it has to keep changing uh this does break change surveillance maybe it's still a little bit abstract but it doesn't make change surveillance because when we're burning a coin we're just making inclusion proofs that it has existed and the nullifier was not published before so we cannot double spend and then we're minting on a complete and completely different coin and they're unlinkable to each other because no addresses are public no values are public so we can extend this scheme to do more interesting things for example we can append another attribute called the token ID so now we just now we simply have erc20 tokens arbitrary tokens on our Network we can extend it even more to add like the current slot ID so with this now we have a Time locked mechanism as well and we can we can do we can do use these techniques to actually like build cool systems and on top of that we can make smart contracts work in an anonymous paradigm for example one of the things we did in dark file is making the world's first Anonymous now so this is a mechanism for to create ours it's not a dial on its own it's a smart contract to create Anonymous dials so as I mentioned we have the coin that's something we can also build a dial the same way so in a dial we have the proposal limit which is look the minimum amount of governance tokens that's needed to make a proposer proposal we have some Quorum that we want like for a proposal to pass we know take note of what the governance token of the Dao is and we also have a Pub Key of The Da which is the essentially the last Treasury so back here when we have like Alice's kind of public key we we can also like have a daos treasury to be able to send money into the treasury then let's say we created our Dao and then we can make a proposal somebody makes I want to send money to WikiLeaks so I'll make a proposal and then we make then we calculate zero knowledge proofs of hashing the Wikileaks Pub Key the Dao itself so we can actually make a note of on chain we can figure out which Dao is supposed to send it and the amount that we want to send and obviously some token it could be any arbitrary token in the daos treasury so we create a proposal we publish it on chain now we get to voting so I want to vote I support Wikileaks I want this Dow to donate money to WikiLeaks so we use uh homographic commitments to actually encrypt our votes so we have our we have our coin the our governance token and we want to use it to vote on a proposal so we will when there is a proposal we will copy the entire state of the Merkel tree the where the all the coins are all the existing governance tokens are as outputs in this tree so we can prove that we have a certain amount of governance tokens and we're allowed to vote on this specific proposal and we can encrypt the yes and no using uh commitments we can commit to them and we can encrypt it with the Dallas key so only the members of the Dao and only after the proposal has ended are able to decrypt the votes and uh and see if the proposal has passed so let's assume the proposal it did indeed pass and then we can execute the proposal so this means we decrypt the votes and if it passes to Quorum we will perform the again the burn and Bin scheme so the Dow has its treasury has its coins it's going to burn the tokens and mint them to WikiLeaks what's happening on chain is somebody's token got burned we don't know what it is and somebody got some tokens we don't know what they are who they are Anonymous Engineering in dark Phi um yeah in darkfine we use these Concepts to implement all these things as smart contracts so everything on darkfi is basically a smart contract we use this to implement Anonymous payments Atomic swaps between people Downs as I mentioned exchanges Anonymous nfts all these kinds of things the goal of being like introducing people to these Concepts is to remember that these schemes are supposed to be simple and modular so you can like build bricks with them not complex I think like complex things are easy to do and keeping things simple is the real challenge so maybe I sparked some interest maybe not but if you do want to like learn Anonymous engineering or like talk to us more we don't like weekly seminars and math online you join fully anonymously you don't have to like tell who you are or you will you can join and ask questions and we can study math and cryptography together the dark fight devs we have a public meeting every Monday on our Anonymous chat which you can find easily you can just search the internet for dark file and uh it should be relatively simple there's a threshold to entering so if you can find that you're welcome and yeah the Dark5 book is um is the MD book where it's our Wiki and we hold like very cool info also philosophical and engineering and how to study math and also technical documentation about things and I want to say like darkfi is just the beginning as Bogdan had a nice keynote talk we're still early but we're expanding into a whole new paradigm of things we're learning how to build Anonymous systems we're learning how to do Anonymous engineering we're learning how to break surveillance and we're learning how to fight so if you have any questions I'll welcome them no thanks [Applause] no questions okay there's a question in Enterprise Finance there's a principle between confidentiality and privacy have you thought about confidentiality specifically do you mean confidentiality yeah what do you mean by that so that if um a regulator wants to see the log of events or the log of transfers he would be able to do that they would but the point is you have you would opt in you so you what what's needed is privacy by default and then if you want to show something about you you should you should be you should be the guy who chooses I want to show you this data not the influenced back doors right sorry but not through back doors not through back doors but you're in control of your data you're in control of your money so you choose when to review and to whom okay cool well uh thanks for listening and enjoy the conference [Applause]
