# "Whats buried under Identity stack? A Talk about Real Privacy" by Lasha Antadze x Rarimo

- Channel: [Ethereum Cypherpunk Congress](https://streameth.org/ethereum-cypherpunk-congress)
- Date: 2026-01-09
- Duration: 16:32
- Topics: web3, privacy, now, crypto, cryptography, blockchain, data, security, human right, rights, tech, technology, internet, open source, free, freedom, ethereum, hackers, ethics, cypherpunk, dev, developer, dapp, decentralization, bitcoin, computer, surveillance, cyber, peer2peer, p2p, love, solidity, zk, zero knowledge, education, academy, w3pn, congress, ethereum cypherpunk, buenos aires, argentina, vitalik buterin, privacidad, filecoin, foundation
- Watch: https://streameth.org/watch/yt-vAXOcDxDcS0
- YouTube: https://www.youtube.com/watch?v=vAXOcDxDcS0

## Description

Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event.
4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. 

Join us in building a free internet for all.

Website: https://web3privacy.info/
Congress site: https://congress.web3privacy.info/

## Transcript

[applause] Hello everyone. Basically today I'm going to be running a sort experiment with all of you for the first time because what I'm going to unveil now it's like fresh out of the innovation and I still kind of wrap my head around if this is the right direction or no. So I'll try to walk you through the entire concept of identity and this privacy preserving one and just through that example I really want you to understand where we are as an industry what challenges we have ahead and can they be solved or some of them are kind of unsolvable. I work on RAMO protocol and uh it's this privacy preserving identity protocol but we all agree right identity as a product it's like not that much sexy but what's really interesting is like it's an enabler so privacy preserving identity and this the real world identifiers we can bring on chain are the enablers of an amazing use cases and that's what's the most exciting part about our team as well. So we can run I don't know anonymous digital protest polls elections we can have access to our digital money without the dependency. So these are like new areas of what can real world identities unlock. But when we talk about how this ind entire industry is constructed, I built this little demonstration. I don't know if you see the other part, but for that to understand like let's run a little simulation that's you and on the left side these are like the inputs. We call it identifiers. So different companies within web 3 outside of it are working into how do we bring this inputs identifier and make them privacy preserving and verifiable. At the end of the experiment we're doing all that to get access to the keys and unlock some funds from the wallet. Pretty simple, right? Input access to the keys unlock of the wallets. This is the kind of a use case I want to run through. But be between this input and the keys there is this huge maze. This is something that most of the companies don't talk about. So how do we connect those two things without compromising or sacrificing the privacy or dependency just in general. So this is the kind of a area where most of the time you don't have to ask the questions just believe me works as is. So I'm going to go one by one and show where we are as an industry uh from that perspective. I don't know how many of you have tried the zero knowledge passport technology that has been going pretty active right so for the past two years now I I I'll start with a positive note so we as an industry did really figure out how to work with the passports and it works the way we want so it's censorship resistance it's more or less does not depend on this kind of external parties and because the chip within The password contains all the information. We can use just our phones, tap it on a phone, generate the proof of our age or citizenship or uniqueness directly on a mobile phone. And as it works client side, it's a kind of pretty scalable non-dependent technology. So we can use that. The use cases are different, right? So we we oursself about a year and a half ago used it for anonymous voting. You can tap a passport and uh just vote. Adtec has launched an airdrop using the same passport. Some are building proof of humanity based on passports. That's another story. But in general, we did really figure out how to work with these docs. But what's next? Because behind this beautiful tech, the reality is that it's not quite a production ready workable product. Because while tapping our passport, what we really do are we verifying the validity of a document, but we're not really verifying you. So if somebody else is holding this passport, if it's been stolen, etc., we don't have that capacity. So current identification is just a document identification. For to solve that, we need to add another layer. And here we move to the biometrics. So now we need to run the comparison of a face of a holder with the passport photo uh on the other side and that's where the system breaks because unfortunately the amount of computation we need to do to extract the face run the comparison on the mobile phone and being able to contain this entire computation locally currently does not work. We've published a paper on it. It's called the ZKML framework bayoneta. And with all due respect to my team members, the model is heavy. It's like 800 megabytes. You need to download it. It's super hard to use it locally. So in a way once we move away to the passport, that's the where everyone is having a challenge now. You can't contain the client side and non-dependency of uh identifiers. And the shortcut we're taking and most of the players is like introducing a third party dependency in the form of the MPCs trusted execution environments potentially when the tech is mature like fully homework encryption but you can see this is not the dream of a client side fully sovereign identity anymore and that's kind of what gets derailed apart from the trust assumptions why this thing is computation ally heavy and never going to work the client side as we want it now is because of the nature of the neural networks. So the problem apart from dependency is that when you're scanning any biometric parameter in today's world whether it's your face, your voice, your fingerprint, your palm of the hand or your iris scan or whatever heck body part you want to do. What is really happening is that we're using in neural networks that extract the points like imagine like this points template out of the your face and when reauthenticating we need to compare the initial input with the new one and grant access based on that. So even if we remove dependencies server side, the problem with this core neural network technology is that you still need to keep the template, the initial template somewhere. Without that, you won't be able to guarantee uniqueness. You won't be able to identify any person etc and etc. And that is the biggest challenge and problem not only from a technology dependency perspective but the biggest problem with this template is called European Union already because if you doom scrolling recently you see like two bad news right one is the falling prices of the crypto and another one is someone somewhere in European Union came up with this new regulation and the package to I don't know do chat control or do this and that. In this case, unfortunately, they don't even need to come up. They already have something called GDPR. And GDPR touches the templates, the one that I showed you. So, does not matter what you use, we wrap it in ZK, we wrap it in like special encryption or like this environment and secret walls. GDPR and regulators will come after it because they don't care about the beauty of your mass. They care about the storage of the template that happens with it. So in a way us working on this truly decentralized self-s sovereign identity the answer is that today unfortunately we don't have one and the past how to make it kind of revolutionary is like a bit like provocative and that's what I'm going to like run with you. So maybe the entire thing of zero knowledge proof identity and that path is wrong because we all always going to run into this dependency and limitations the way we process the identifiers. And while thinking about it, we were like looking at different technologies and we realized that revolution might be if we just cut out this entire process of template generation, comparison run and the storage. And that's something that has not been done to this day. What we discovered this amazing technology and that's what I'm betting on is called fuzzy extractors. It enables you to skip all the template generation but from a human friendly factors whether it's voice, face, object, I don't know anything that is in the real world to transform the entropy. So every object has this kind of uniqueness to transform the entropy directly into cryptographic keys. It's like a new tech where entire concept of even storing the keys just goes away. Key only exist on demand when you generate it. Once it's used, it's gone. So there is no template required for the phase 2 identify. There is no special environment. No keys to be held to provide you access. It's just this crazy primitive more like a Harry Potter movies. Why I'm betting on this direction and technology while being in the ZK space and have contributed a lot? Because I think that this tech is the only way so far that promises the truly sovereign fully decentralized non-dependent identities that can work on chain that can work off chain but completely disintermediating the market. So there is no space in this equation for custodials, the key managers, the m the multi- signature or whatever heck logics everything can live outside and using the fuzzy extractors become this kind of a ondemand key management world. This is the kind of how current identity access management systems work. And you see it's not only about privacy and sovereignty. It it's a it's a paradigm shift from what I'll just run again. So before you had an input of biometry or any secret feature vectors reference template and encryption of a reference template of the face then you had to run comparison give you access to the keys and you would store template and the keys at the same time in this paradigm. That's how today everything is done like in custody with the crypto keys everything works in this paradigm but with fuzzy extractors you're just eliminating it's like input fuzzy encryption decryption and you get the keys. So you you just like getting the keys even if you make a mistake as something changed you still getting a key but this key either opens or not. It's that's the kind of a paradigm shift here. We're productizing and that's what I'm going to talk about this kind of productized version of this technology under this brand unforgettable which we will be rolling out into three products. One is this kind of brain wallets where you can store crypto and this entire keys into physical objects that only you remember. So it could be a cover of a book or some combination of three or five faces as a kind of multisig and um it's it's already out. So if you go you can test out the early version of it. We're going to rolling out as SDK for non-custodial wallets. So instead of seed phrases, you can use this biometrics and um any type of physical secrets as part of the recovery process or it could just remove the dependency on clouds and servers and hardware because suddenly your master key can leave with you into your knowledge and you can rederive this kind of instead of the pass keys you can have your root pass key bound to something only you know and then it can like spread into the systems etc. That's it but basically you can test the productized version of this technology here or find me on Twitter and happy to discuss because as I mentioned this is like the first time I talked about it. I kind of tested the ground and for the entire week I'm going to be running and pitching this tech and product across different events. Thank you. If you have questions Oh, okay. We have we have an audience question. We have room for one question. Let's do one question. Yeah, I just wanted to ask on the key side of the verification, how can it can I'm assuming it can be verified on any chain, right? Like Ethereum, different any execution environment, &gt;&gt; but you need the you need the registries. &gt;&gt; Okay. What do you need on the on chain side to be registered &gt;&gt; like a wault or whatever you're applying keys, but what really happens is that you're deriving keys offchain locally. So when you scan your face, your voice or something, you're using these inputs to derive keys locally and then you can use these keys wherever you want. So you can work on Ethereum, you can derive the Bitcoin keys and use it within the Bitcoin as well. So it's pretty universal technology. It's a key management step. [applause]
