# "Data Liberation & Adversarial Interop with TEE and OAuth3"" by Andrew Miller // ECC#2 - BA 2025

- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-01-09
- Duration: 18:00
- Topics: web3, privacy, now, crypto, cryptography, blockchain, data, security, human right, rights, tech, technology, internet, open source, free, freedom, ethereum, hackers, ethics, cypherpunk, dev, developer, dapp, decentralization, bitcoin, computer, surveillance, cyber, peer2peer, p2p, love, solidity, zk, zero knowledge, education, academy, w3pn, congress, ethereum cypherpunk, buenos aires, argentina, vitalik buterin, privacidad
- Watch: https://streameth.org/watch/yt-sxln2WLqvho
- YouTube: https://www.youtube.com/watch?v=sxln2WLqvho

## Description

Andrew Miller from Teleport talks about non crypto things everyone should imply into web3 and crypto values, about data liberation and permisionless TEEs.

Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event.
4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. 

Join us in building a free internet for all.

Website: https://web3privacy.info/
Congress site: https://congress.web3privacy.info/

## Transcript

[applause] All right, thank you all for having me here. I'm Andrew. I'm from Teleport. This is a product studio being incubated by Flashbots X. Um, we make uh thought-provoking applications enabled by trusted hardware and confidential compute, which I'll give you a few examples. Um, first of all, I am also a board member of the Zcash Foundation. I want to say, did I get the right clicker? I want to advance my slides. Should I try the other? Yeah, there we go. So, first of all, I want to I'm going to talk mostly about a non-crypto kind of thing that I want to make the point that we should apply all of our web 3 and cipher punk values to. Um, but first of all, this is a really important moment for privacy. So I really want to shout out to everyone who has been working so hard on developing the technology and the philosophy and culture behind the use of privacy enhancing technologies for so long even before it was adopted as a really important positive mainstream thing to do. Yeah. Round of applause for everyone who has been working on this tech for a long time. No one can control when uh you know a fad happens or a trend happens but all the hard work leading up to this is what makes it possible to sustain that, right? So everyone's going to look now at oh we should be adopting privacy we should think about it but then they'll stay for you know the depth of technical work and and culture that's been brought to this. Okay so um with that aside the point that I really want to make today is that we should be you know widening our aperture a bit we should be looking about how to spread the cipher punk values not just to digital assets where it is very important and we're doing the right thing to that end but we should be looking at bringing these to other uh kinds of areas as well. So I'm going to be talking uh in this talk about social media and algorithmic feeds and how we can bring cipher punk technologies to um this kind of area and I'm also going to make the point that we should be especially embracing trusted hardware and confidential compute which compared to the ZK proofs in other cryptography that you're used to are way more of an unsatisfying compromise uh and not as good as tr in the trust model sense but they're really the thing that we should be using now to branch out into know beyond digital assets bringing uh cippher punk values to the world. So I'm going to be talking about some application examples that are built on top of Tik Tok and short form video. Short form video is actually a really important area that we should be looking at. It's something that is, you know, dominating the attention spans of youth and adults on YouTube shorts as well. Um, usually you hear about short form video in the porative sense, like it's wasting everyone's time with slop and encouraging very low agency, just like I'm addicted and doom scrolling kind of behavior. There's actually a lot of reasons to be interested and optimistic about the potential of short form video as a platform as well. Tik Tok has a stem feed, a STEM button. That's where you have your, you know, nominally educational videos as well, but it's um, you know, compared to the for you page, it's not algorithmically tuned. It's kind of boring, but you know, I think there's potential there. Um, and the creator tools are always near there as well. So, short form video doesn't just have to be about passively receiving content sent to you. It can also be a way that you can be motivated to produce something and share with others around you. Um, so I think this is a really important place to meet, you know, consumers and, uh, you know, not just the techies, but other people where they're at. Um now the basic problem and why I'll get to adversarial interop as the real important thing that we should be looking at is that um the platforms associated with short form video that give you the algorithmic recommended feeds are the masters of all of the data and control the interactions that you have. In principle user generated content you know anyone can record themselves with a selfie stick in a phone. That should be really good for, you know, creativity unleashed and being able to form uh societies and communities have things to share with your friends. It it's nominally peer-to-peer. There's relationships of interaction between uh content creators and their audience members and following. Audience [snorts] members can also be creative creators themselves. So, there can be, you know, a back and forth. The reason why this works so well and it's proliferated so well is because the platforms are really well tuned. They know your behavior so well from the behavioral data that they collect that they do a fantastic job of routing content right to you when you're definitely going to watch it if it's the next thing that shows in your feed. And they even also give data to creators that guide them towards making slightly better content that is going to be watched by people and more effective. Um, this of course is data that the platform has and so they get to put their fingers on the scale and tip it to make you watch addictive content or something that's going to make you buy more products rather than you know actually build some kind of health or learn something or build healthy connections with other people you're sharing videos with. So at the bottom is the design space of information diet apps meaning apps that will attach to the existing platforms and make use of the data which otherwise would be held by individuals unable to share them with each other for privacy reasons. This is a design space that we can uh actually bring cipher punk values to and I'll give some examples of this in a second. Um I will actually just go straight to giving a couple of app examples. These are not live right now. they're like in review in the app store and hopefully we can make a launch announcement about these by the end of the week. I will give just um you know two examples though we have a couple others. So the first one is called feedling. So this is an application that it gives you an interpretive feedback of your behavioral patterns on Tik Tok. So this is a digital pet that you can keep and adopt the digital pet with a group chat or your friends that is fed the same information diet that you are fed. So, every time you watch a video about cats, your cat avatar picks up some skills based on whatever was in the uh uh whatever was in the video, the the you know, and it pops up like while you're watching the video as like a a little popup. So, you get to see this in real time as you're watching it. You can think of this as surfacing insights about your behavioral patterns that you didn't even know that you had delivered to you in a way that's a little bit, you know, subliminal, not like on an entirely separate app, but you know, right there where you're saying it. Now for this to be to work and I'll get into the technical details of how this has to be able to observe your watch history and link it into this separate application. Let me give one more example that's even a little more evocative about why this is um an interesting kind of technical paradigm. So this one is called sync and the idea is that it is an AI agent that takes uh for it is in a group chat that you join and this agent gets to see the group chat that you are the discussions in your group chat. It also gets to see the delegated watch history of both of the people in the chat or you know all the members of the group. And the [snorts] idea is that it's going to drop in insights into the group chat when it's relevant or likely to spark a conversation or be productive to do so. So in this example, someone is starting to speak and kind of coded references to a TV show that they're watching. So it's interesting to drop a card revealing, oh, the other person actually was also interested in this TV show a little while ago. So there's some insight there. Um, some other examples. I won't go through too many of the examples. Maybe you kind of get the idea. The other ones that are interesting are where there's some complimentarity like someone has been binge watching educational videos on building something and someone else in the group chat has just started down this rabbit hole. You should probably recommend uh you know the new learner should be in contact with the person who's just acquired a lot of expertise. There's some value uh to the insight of matching them together. It's also interesting to roast you for when your watch history betrays the wrongness of what you're saying. like you're talking about health, but actually your watch history reveals that you're staying up very late watching videos long past your bedtime. [snorts] Um, so you get the idea of the kind of things that this would show there. Just to abstract from, you know, what's the point of what's going on here. So the platform has all of this behavioral data about what you're watching. You individually can go and look at your watch history and see what's going on. There's no facility in the existing platform to share this watch history with other people and nor would that be a good idea. You wouldn't want to share your entire watch history. That's too personal and would be too much sharing. That said, there's still some value that's like left on the table, which would be insights that would be meaningful if they were brought to the surface that are only apparent from the, you know, application viewpoint of this aggregate data from multiple users. Um, it's not a good idea to share all of the data, but it's a wasted opportunity not to share any of the data. So what we want is the ability to um you know define apps that work like this and be able to get the value of sharing without actually having to give up all of the control over your private data to do so. Um so this idea of um building apps that retake the power of private data that the platforms currently have with or without their permission and in particular without waiting for their permission to do so. This is an instance of the problem of adversarial interoperability. That's a phrase coined by Corey Doctoro in in an essay while at the EFF. And the gist of it is that if you want to, you know, really get a way to get more of the value back to yourselves rather than simply giving control over it to the platforms, you need to have an ecosystem technology and a will to do so that isn't waiting for the platforms to do this for us, but is able to do it ourselves. Now, I'm going to talk about trusted hardware and confidential compute. I think that this is I gave the background on this that it's a very imperfect technology and I hope you enjoyed um Quintis' and Akmed's talk about the trustless TE effort. Long term that kind of effort is the only good solution to be able to to do. I don't want to convey that we should settle for being stuck relying on Intel and Azure to um you know bring this to us. But to be pragmatic and to actually expand to some you know uh areas beyond just digital assets this is really the the like right technology for the moment that we should use. So basically on clouds right now there are confidential compute VMs. So these are VMs where you can run encrypted code and process encrypted data and the cloud promises that they won't look at it. Not only do they promise they won't look at it, um they use hardware features in Intel Xeon and AMD. Like half of all the server class processors have support for this confidential VM mode. The thing that's imperfect is that the these have a bad track record of bugs. The bugs eventually get patched. There are ways that you can mount physical attacks. So you have to trust that the cloud vendors are not actively exploiting those physical attacks. there's at least a little bit of a separation of concerns like the hardware manufacturers and the cloud would have to be um you know violating each other's uh intended agreements and use of their uh tech to do so. Um the main feature that these have is isolated execution and remote attestation. So the important thing about this is kind of like how in smart contracts you have to trust the blockchain to run and maybe there's politics or you know hard fork risks of the blockchain you have to understand and decide that you're okay with. The important thing is that you don't have to trust the application developers like who wrote a smart contract doesn't matter. It's even better if it's an anonymous profile photo that wrote the smart contract. You get to look at the smart contract code it yourself and know that it's being run correctly by the blockchain platform. It's the same thing with these imperfect but you know pragmatic and available today confidential compute uh products on clouds. Um you don't have to trust the account owner at the cloud who wrote the code before deciding to trust your sensitive data or link your account to it. You get to look at the code yourself or have auditors around evaluate it. And what you get is that the cloud tells you this is the code that's running. [snorts] Uh this is the hardware spec that it's running on. So you use that to make your decision to trust it, not having to trust the owner of the account or the developer who originally wrote the code. So now let me go to um there's a lot of really interesting examples about that. The point of this slide is to give um some pointers to some interesting applications you can um that are like mechanism design using this kind of tech. But let me just go straight to you know how this works to use it for the Tik Tok apps that I just showed you. So this is going to be in about three steps. The first step is to take whatever browser or mobile OS you would have used to interact with a platform via an app and actually run that browser inside one of the confidential compute VMs as a TE. This means that you essentially get the same kind of uh privacy as running it locally even though it's in a cloud and it can be run remotely. Um you know the code that's running and you know that whoever wrote that code can't be looking at the data that you link there. Um, in principle, running a browser in a confidential compute VM on a cloud doesn't look any different to the platform than actually just using it on your browser uh on your laptop. In fact, you can have the TLS traffic start in the confidential VM, but routes through the outer layer through the user's own laptop and therefore the user's own IP address. It could even copy the user's uh fingerprint. It can be an exact replica of the browser that they were going to be running on their laptop. Just now it's running on a cloud VM and going out through their own IP address. So there's no way for the platform to be able to tell that this is happening. Also, if you wanted to do something that's either automation or a browser plugin or having an AI agent um you know uh uh help you carry out the agentic tasks of doing interactions on on the web app. The user can bring that themselves. it doesn't alter the um you know trust model of having the browser start off in the confidential compute. Um now then the last thing to mention and I'll give the name OOTH3 for this and explain a little bit about this in a moment is you can separate the task of collecting this data and handling the account uh delegation to do this from the specific apps like the examples that I gave that would use it. So you should think of this as maybe you're familiar with or you know I'll just tell you that there was a project called solid pod which was a web 3 uh not a web 3 uh what do I mean by this um uh W3C right worldwide web project from Tim Berners Lee that says oh you should decouple applications from storage this is like a but they had no answer to confidentiality like you could pick lots of different storage providers but each one of them would get to see all of your data that's very limiting so here the idea is you can have a a data pod side where you can store account credentials, delegated accounts, instances of browsers logged into accounts and data that you've collected from your own account and you can store that in a confidential VM of your choice. You can choose which cloud to put it in, which TE provider to to have. Um, that's your data pod. You as the user are fully empowered and in control of it. If you want to delegate this data to thirdparty defined apps, um, then you can do so. You don't have to go redelegate the account just to be able to use a different form of an app. Um, and you don't have to ask the platform's permission for all of this. All they know is that you have a browser. You've, you know, looked at your own watch history through a browser. But what you do to delegate with it can be done then this way without the uh without the provider having to know. So we use the name OA3 for this. This is a very funny troll of a name. Maybe this pattern if you're familiar with web standards you know this kind of delegation intermediation is a lot like kind of the familiar thing of ooth normally oath is something that has to be provided by the platform and the abilities that it provides are only those abilities provided you know defined by the platform they tend to be very limited um if you search for oath3 you just get a page that says oath3 just definitely doesn't exist so it's sort of like an anti-mimetic space that's a good place to put a new name and so it's a good joke of a name because you know it's not really a standard. The whole point is adversarial interop. You don't need the platform's permission to do this. In fact, it doesn't you know the platform can't stop it if they tried because it can just blend in with ordinary traffic overall. So you know this modular approach of it's your own account data nothing stops you from making a log of your own account data and if you choose to delegate it to thirdparty applications which you should that's a good idea um you can do that. This is a modular way of doing so. Um I think that I am going to stop there. I mentioned what the point of um OA3 is and the the rationale for that. I think a very interesting trend that's related to this is the expansion of AI agents in operating systems in browsers. This leads to a really interesting blurred line or breakdown between what counts as a user initiated action and what counts as automation. If an agent helps you carry out some task then um you know that's somewhere in between automation and just carrying out the express intent of the user. the sharing and delegation to apps that I'm advocating and the use of confidential compute is really unrelated to whether you know you you do agentic actions on your browser or OS. So these are separate but it's really the use of AI agents that is you know pressing this line about what counts as automation versus um so yeah I I will stop there and I I guess I will just lastly thought I had some link here I wanted to say all of the code that I mentioned for this is open source like the apps aren't out yet but we're doing the Ethereum style working in the open so I'd encourage you to go look at this teleport talk scope repo it gives you tools for you know handling your own accounts and running them in confidential compute um And that's all. Thank you. [applause] &gt;&gt; [screaming]
