# Least Authority | From Freedom to Autonomy - Liz Steininger | ETHDam III - 2025

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2025-10-07
- Duration: 22:33
- Watch: https://streameth.org/watch/yt-t68fai69wUA
- YouTube: https://www.youtube.com/watch?v=t68fai69wUA

## Description

Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo.
🌷 https://www.ethdam.com// 🌷

------------------

Least Authority | From Freedom to Autonomy: How Internet Freedom Principles Can Shape Web3 Privacy - Liz Steininger | ETHDam III - 2025         

🎤 About the Speaker: 
Liz Steininger is the CEO/Managing Director of Least Authority, a leading Web3 security consulting company and builder of privacy enhancing technology products, including Private.Storage and Winden.App. Least Authority specializes in securing Web3 products, capability-based security and implementing advanced cryptography, especially zero-knowledge proofs (ZK) and multi-party computations (MPC). Beyond security audits for new technologies, Least Authority has also released the MoonMath Manual, a practical guide for developers to understand zero-knowledge proofs. The company focuses on cutting-edge security and empowering users to control their right to privacy.

𝕏 Follow:
https://x.com/liz315 https://leastauthority.com/ https://x.com/LeastAuthority 

------------------

About ETHDam & CryptoCanal
ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich.

Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance.

------------------

🎥 Credits:
Intro / outro by babyPRO -  https://babypro.art/
ETHDam Photography by Paulus – https://concretestate.eu/ 

------------------

Special thanks to our partners who made ETHDam possible: 
🌹 Hackathon – Bouquet:
Oasis Network https://oasisprotocol.org/ 

🌷 Hackathon – Petal:
Circles https://aboutcircles.com 

💛 Conference – Gold:
Zano https://zano.org/ 
Dash https://www.dash.org/ 
Bitvavo https://bitvavo.com/en 

🩶 Conference – Silver:
Igra Labs https://igralabs.com/hero

💛 Conference – Copper:
Lido https://lido.fi/ 
DeTrip https://detrip.travel/
Cake Wallet https://cakewallet.com/ 
The Grid https://thegrid.id/ 
Calimero Network https://calimero.network/ 
0xbow https://0xbow.io/ 
Mina https://minaprotocol.com/
JobStash https://jobstash.xyz/ 
Cyber Capital https://www.cyber.capital/  
POAP https://poap.xyz/ 
Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 

🌱 Sponsor:
EF Ecosystem Support Program https://esp.ethereum.foundation

------------------
0:00 Intro
1:28 Freedom and Autonomy in Web3
2:42 Internet Freedom and Web3 Alignment
3:40 Snowden Revelations and Impact
4:45 Privacy Tools for High-Risk Users
6:00 Designing for Privacy by Default
7:43 Practical Privacy UX Patterns
9:12 Leveraging Internet Freedom Tools
12:03 Case Study: Magic Wormhole & Winden
17:00 Zero-Knowledge Use in Payments

## Transcript

Welcome to EA to E to E to E to E. So to move on, that's where as I mentioned, we've got Liz from least authority who's going to be talking about internet freedom principles can shape web 3 privacy. Please give a round of applause and we will connect your laptop. [Applause] So, there is a clicker that you can use. Otherwise, if you just plug that in, you should be off to the races and we're good to go. Fingers crossed. Did everyone sleep well last night? Who's Who's here hacking? Okay, that means they're you're hacking. Good man. Did you sleep? Okay, good. My first ever hackathon that I went to, I ended up sleeping on a concrete floor. And then when I woke up, my whole side of my whole thing was just like cooked. And then I had to give the presentation and I gave the presentation and I was reading from the iPad and then I couldn't get my words out properly and everyone felt so bad for me. Now I do this so I don't have any slides. Do we think it's good? Yeah, it's good. Perfect. All right. Well, take it away. Thanks. Well, I don't have my speaking notes, so I will just go without them. Um, but yeah, I wanted to talk to everybody about how um, uh, freedom and autonomy are related in the sense of, um, internet freedom principles can shape web 3 privacy. So, why this talk? There are two very active and vibrant communities that have existed pretty much adjacent to each other um with one shared goal to empower and have um users um use tools privately. Internet freedom as mentioned before has a legacy of over 30 years um and web 3 has shared roots but web 3 is still writing the story about um how web 3 is going to play out in history. Bridging these two uh communities more effectively can support the incorporation of privacy into our tools which we all agree is important and it can accelerate mass adoption of secure decentralized tech. So the core principles I'll go through quickly because I think um this audience is very special that probably all agrees about these things that privacy is non-negotiable. We need fundamental security and we need to enable user autonomy and um radical decentralization is what we're trying to push for with web 3 along with uh the use of open-source code. So this is a good timeline of where we came from. I will uh say that chat GPT helped me out with this. I double tried to double check for errors but um I'm sure it doesn't encapsulate everything. Uh but it it shows that you know we we talk a lot about the cipher punk history of web 3. Um but that happened in the early 1990s but more has progressed since then uh adjacent to um web 3 and this internet freedom is the term that is used and um basically the the term even came in the early 2010s uh as part of a broader discourse on digital rights and online uh liberties. So the again the core principles and the value systems are very much aligned uh and the Snowden revelations I don't know how many people have heard of those or remember them in 2013 um but I distinctly remember them. I had joined uh the open technology fund which is a a government funded a US government funded program for internet freedom around the world. It funds open-source secure communications and circumvention technologies. And when I joined the team it was I was the third hire. It was a new program and it was just before the Snowden revelations. But this changed the world when everybody saw that Snowden had released about mass surveillance that it was real and widespread. We were no longer paranoid people. We were actually like legitimate technologists in the space again. And this was a very meaningful change that I personally remember. But after that there became a surge in funding development and public demand for secure tools. And in the 2010s to present, we see human rights defenders, journalists, and activists around the world increasingly depend on tools like Signal, Secure Drop, VPNs, tour, all these tools that are from the internet freedom space. The web 3 space might not completely um I don't know take it take them in as like saying that this is related, but they are very much related because of those core values. And then the other thing that the internet freedom uh community has done over the years is done interventions interventions with policy infrastructure and usability research. So the cipher punk roots as mentioned before there's some examples there. The other thing is grassroots activism versus state level censorship and surveillance. This is that fight that I was talking about with Snowden. And the core victories that we saw came out of this space were HTTPS everywhere, signal, tour, let's encrypt etc. But things like um let's encrypt and https everywhere were this movement for um this infrastructure too being widespread and used not just by certain communities but by everybody. And the tactics that have worked are this resilient censorship resistant protocol. So the things that have come out of this movement also human- centered threat modeling for high-risk users and I'll talk a little bit more about this later because I think targeting the needs of high-risisk users allows us to meet the needs of everybody else because if you can secure those people and their use and keep them safe then everybody else is okay and there are equivalents of this in the web 3 space when we have talking you know talks about big hacks and such and then this community audits bounty programs privacy security as the default in the UX. This was also very big with is is also very big within the internet freedom community. And like I said, the policy advocacy is very synchronized with the technical technological um progress or the technical progress. And this is an again another important synchronization that instead of the space always working in completely independently of the governments and policy and regulators, they would work in conjunction with them because they found that shared goal. So you all know that's why you're here that privacy is the missing native feature in web 3. That's what we're all trying to change or at least I think most of the people that have come to this conference. So we had this vision with web 3 yet we're seeing that privacy is often bolted on after the launch and this is arguably show slowing the adoption. So a lot of people are also talking right now about how do we, you know, transition from tools that work in small use cases to tools that are mass adopted and how do we get to that mass market and users uh unknowingly leaking financial or social behaviors, their data, the hacks, all of this is going to slow adoption and so privacy is very fundamental to this. And also complex retrofitted privacy tools will create a bad user experience and that is not going to help people want to on board. And just to just to reiterate that autonomy without privacy is an illusion. So this idea that web 3 is empowering users is not going to be uh fundamentally true until we actually have the the privacy there. Otherwise users are still surveiled and manipulated. So, where do we go from here? Um, well, these are three things that I think are easy to do. I had a list of like 10 and I had to narrow it down to three because, you know, that's easier to remember. But basically, design for privacy by default. And, you know, this is going to be something that you can do moving forward. But even when you're adding new features to existing tools and products, think about that. how to normalize it, how to make it completely seamless within an application or within different use cases, and then leverage existing research tools and designs from the internet freedom community. And I'll get into that in a bit more detail, too, because I think that there are some great tools out there that can already be leveraged. And then also utilize modern and advanced cryptography to address these challenges. So, I'm sure a lot of you have heard of ZK, etc., But I think that there's a there's a whole toolkit there that um needs to be further utilized. So here is just a table of some um you know comparisons here where again internet freedom has the strength of mature anti-censorship infrastructure and then um we're seeing that in the web 3 space we might have bottlenecks that need to be bypassed and so we can look at for the joint wins where these two communities can share this work and especially this UX for at risk users I think is interesting because again if we're targeting the most at risk users they're often in high pressure situations where they have limited resources and so if the UX can meet their needs then it's going to be easy for the normal person. So designing for autonomy so I'll go through each of those three things um designing for autonomy is really important um to focus on the human and the in the activity not just the technical activity that you're trying to complete the function you're trying to complete that matters but the human that's involved with it matters too. So there's things that we can do. These are some practical steps. So uh you know create um defaults that reduce cognitive load. This idea of safe by defa def default, open by choice, private by default. You choose to share. And so just make that have no thought process for your users. It's just there for them. All they have to think about is sharing or you know uh making their data open as opposed to having to think about how to make it private. And then granular consent dashboards. give them choices, give them control, and this doesn't have to be overwhelming. This could be something that you drill down into. Um, and then distinct flows for high-risk users like I mentioned that if you're under duress, you're under stress. This is what can happen in the in this instances of hacks. People or under pressure in situations and this is what leads to hacks because people are thinking fast and acting quickly and they're not reading everything that they should be reading or thinking about it. And so if we have these flows of privacy and security by default for those high-risk users and that are under duress then we can meet it for everybody else. And then this concept of local first apps so keeping things under the control of the user keeping things at the end points will also help us make it more human- centered as opposed to organizational or um you know centralized and then inapp safety cues to increase retention. So help them not make mistakes. And so you can achieve this through mixed method user testing. There's user interviews that you can do. Largecale surveys can be very affordable to do. Um and also iterative remote or in-person usabil usability tests. So giving people, you know, AB options and seeing how it works. But to conclude, less friction equals broader adoption and strong privacy becomes the default rather than a specialist skill as it requires now. So, here's some lever um some internet freedoms tools that could be leveraged. Um these are just a short list. Again, I just quickly did a query to chat GPT and I was like, make me a table of these and tell me how they can help people. And of course, I know this stuff so I can like fact check. But um I like there's a list of hundreds of internet freedom tools that are out there that can be used right now. The code is open source with open source licenses. It's available online. They've been funded by, you know, very good sources. Most of them have been audited already. And so these are available for use already. And so you've got tour, which you can do like traffic anonymity, signal, which you've all heard of, the protocol that underlies it. It can be available to use. Um, magic wormhole and Tahoe LAFS are two that least authority uses. And so I can talk a little bit about that case study. Um, and then we've got operating systems like cubes and tails. I know yesterday the panel I was on cubes OS was mentioned and this can help people stay secure and keep their data private on their machines and so this is very good for users but these tools can be integrated into web 3 products and tools and infrastructure and then I mentioned earlier the modern cryptography toolkit so these are some key words that you've heard about um a threshold and secure multi-party computation zero knowledge proofs fully homamorphic encryption trusted execution environments. Indistinguishable obfuscation is still um in research and then postquantum cryptography and formal verification. It's been great to see the new formal verification program that's going on with the Ethereum Foundation and what that's helping with uh ZKVM security. So all of these are all tools that are at our disposal and more and more libraries are being released all the time with them. So now the case studies to give you a little bit more practical example. So in least authority we have been using magic wormhole for file transfer. Uh anybody can use it right now like the magic wormhole is just uh the code base is you know code. It doesn't necessarily have these user interfaces but it can also so it can be plugged into existing infrastructure or it can be um used um exactly with users. So, we incorporated it into Winden, which is an open- source web app for secure file transfers. You've got privacy by default because it's using a pa um key exchange. Um, and it embodies our values with the human readable codes, ephemeral serverless model, and it's grant funded the work that we did um to extend magic wormhole to have a user interface. So, this is what it looks like on the web. You can actually go try it out if you want, if you want to securely send a file to somebody. And you don't have to in like the the key here that makes it different is that you don't have to enter your phone number. You don't have to enter your email address. There's no identity information collected when using this. So it's that's where um it's really useful for um use cases where you know again high-risisk users who don't want to be signing up with a service that allows metadata to be captured that they were sending files um to another user. I mean, even just that sometimes can be uh incriminating to high-risk individuals, the fact that they sent stuff to someone else. And so, not leaving a trail um can be important for particular use cases. But yes, so that is usable to see what these kinds of tools can look like if um can can uh work like if they have the front end added. Another use of magic wormhole that we did was for onboarding and in another product and um this was with private storage which is secure file storage and for this um we needed to bootstrap the the setup. So we needed to have every new device or team member have the the correct capability string. So this um thing that allows them to interact with the storage system. But we didn't want to send it by things like email. That's what we were doing initially sending it by email. But then you have the this capability string which needs to be secure sitting in a third-party application email which then could be hacked and a hacker could have access to it. So this is not good for security and then that would you know break all of the um the privacy that we have baked into it because then you know somebody has access to your files. So here we have the use of magic wormhole to just bootstrap. So we're just send send like using this internet freedom tool that was created allowing and it's um not related to blockchain but you can use it in these web 3 systems to allow people to get onboarded easier and so this makes the user experience more easy. So again, this is something that we've written blog posts about that. There's stuff online if you want to dig into some of these case studies more. I can share more details, but yeah, there's a UA UX win here. The user experience becomes twoclick onboarding instead of this manual copy and paste thing through other tools. And so they can stay within the application and it recovers um automatically. So we don't have to worry about um problems there. And then uh the same flow is for solo versus multi-device. So then the user is familiar with that. And so then this is again more information about private storage. We're also using Tahoe laughs for it which is another internet freedom tool that I had mentioned. But um yeah and we use uh like I said magic wormhole for this but um Tahoe laughs if you're interested in using it for any kind of storage. It offers clientside encryption. It's a capability based system which means that again there's no identity information, no accounts, no usernames or passwords. It's really this capability string of information that gives you access to things, access to the files, um access to the decryption and also it does um it doesn't say it here but uh we do it also Tahoe Laps supports sharding of files um so the files are sharded and they're stored um distributed on different servers. There's also an algorithm that manages that. So it's got lots of good privacy and security features. And then we also use zero knowledge proofs. So talking about these um case studies with um this is a very case studies with um cryptography advanced cryptography. This is a very simple one. It's just during a payment process. We're using the zero knowledge um proofs. Uh we call them zero knowledge access passes in this implementation. But this use of a zero knowledge proof allows us to separate the payment information that is necessary to be gathered to operate a business. Keep that payment information separate from the users's use of the service. And again, these things are um it was it's getting easier to implement these. Okay, so that's it for all the slides. I know I went through quickly so then we'll have hopefully some time for questions but my key takeaways I mean again I feel like you've heard this before but privacy is a prerequisite for autonomy and let's make it native to web 3 and um let's leverage the 30 plus years of work that's been done in the internet freedom space and figure out how that can better help um web 3's vision and goals with using privacy and um yeah I think we need to see more cross like cross-pollination and have the two movements get together, initiatives, even funding that can be gone, that can be bridging these two spaces. Um, but yeah, reach out if you want to talk about this more. Um, super cool. Thank you very much. Uh, if you could unplug your laptop. We're going to ask the next one to plug in the laptop and then we're going to switch over to the slido so I can ask you some questions. So, we've got two questions here. Um, you can put your laptop on there. We optimize for chill while we're up here. Um, so the first question, uh, that I've got here is, um, obviously there's a lot of stuff with the European Union kind of trying to get its fingers into privacy and stuff like this. And so how do you feel everything that you talk about which is trying to move the world towards I guess like privacy by default how does that how do you see that interacting on this kind of like global level of obviously the regulators wanting to see what we're doing? Yeah I mean the European Union also has GDPR which has been around for a while. So the the right to privacy is um regulated in the EU. So I think um and also the EU is supportive of technological advancements. Um there are many uh funding resources even within the EU that try to fund open-source projects that help you know user autonomy and privacy and so I think leveraging those relationships and those goals to say what you're now proposing is going to possibly go against that and this is how and let's talk about it and that's again where these relation existing relationships with the policy makers can be used um for our goals too and where if the two communities can come together and you know again continue to recognize these shared goals then we can ensure that the future policy doesn't go against the past policy and our current values. Yeah. Nice. I'm a big do you know Marina from the EUCI? It's like a EU lobbying group but I'm a big fan of Marina in this in this country. I guess I need to know them now too. Um we learn new things here. And the other question is um what do you think about kind of third party verification standardization of privacy tools? I guess the way I interpret this is someone says I'm building privacy tools as the one that you've said, but is it actually doing what it says in the tin and how can I trust that as a user that might not have the technical understanding to go and do that or Yeah. This is where accountability is really transparency and accountability is really important. So I mean ultimately we want to empower all users to be able to do that research should they want to. Yeah. But of course not everybody will want to, not everybody will know how to. And so then we need these yeah these third party these independent organizations but we also need to make sure that we're holding them accountable for the work that they're doing. We need to ensure that you know their incentives are aligned correctly. They're not being manipulated themselves. Um and that's where the transparency of those organizations is incredibly important um to keep that trust so that people have that. And then I mean also recognize that there are other sources of trust. It doesn't always have to be organizations. It can be your friend. It can be, you know, oh, that tech guru that's your friend. I mean, that's often what people rely on more. All the people here. Yeah. Yeah. I mean, we all go back to our families and they're like, oh, can you tell me like what's this blockchain thing and how do I use Bitcoin? And you know, so we have to recognize that that is out there and how do we empower those people, those influencers, um, not in the web 3 influencer sense, but in the practical day-to-day sense. Yeah. Cool. Well, thank you so much, Liz. Uh, please give a round of applause and
