Permissionless (ZK) Registers by Lasha Antatze [Rarimo] x Ethereum Cypherpunk Congress
Ethereum Cypherpunk Congress·Tue, Oct 7, 2025, 12:00 AM
Unstoppable ZK for self-sovereign identity, ERC 7812, privacy preservation. Ethereum Cypherpunk Congress facilitated by the Web3Privacy now collective: https://www.web3privacy.info Lasha https://x.com/LashaAntadze Rarimo http://rarimo.com Ethereum Cypherpunk Congress: https://congress.web3privacy.info X: https://x.com/web3privacy
Transcript
okay I'm going to talk about the rimo which was basically mention it like in other stages as well and there's like this parallel things as well announced of what we do with um other projects but in in general like what people know us about us and what we've what we've done recently and people recognize us is something that has to do with Anonymous untraceable voting so about like six months ago there went a digital protest like a referendum straight in the heart of Russia against Putin it was run by one of the opposition leaders and the idea was like people would completely anonymously join and vote against the regime the same concept and the technology we built was reused then by Amin suani and Iranians and his presenting in parallel to another stage and then it kind of spread on its own into with the Georgian opposition and peace reusing it for the election campaigns and like just bringing this digital civilians in complete Anonymous and unique way to support and show the sentiment how most of the users that have participated and in Russia the number was around like 40K votes which might sound small from the overall aan perspective but if you Benchmark it with the latest protest held in that country that was the largest single Gathering since 2021 and the users who basically were using the blockchain and zero knowledge proofs to cast their vote of descent they had no idea what was happening behind the app that was downloaded on the mobile phone they would just take a passport biometric passport which contains the chip inside tap it on a phone and then with the ease of a button cust their vote Anonymous voting consists of like two super important parts technically first one is how do we build the Registries of an eligible voters and another one how do we cost the anonymous vote on chain the second part fortunately has been taken care of by many teams and we had like more than enough technology like semaphor for maintaining the anonymity of the votes and untraceability but in a real world use case the part that was missing was how do we construct fully Anonymous ZK Registries that guarantee the validity of a vote on one end but as well does not allow anyone especially in the passport case for a government who has a copy of your passport right to be able to understand that you even registered to vote so for these very high sensitive privacy cases what we find out is there exist this kind of I sometimes call it like the three body problem the current in a current framework and setup you can't have a fully decentralized system like blockchain and while putting an identity on chain you can't guarantee the uniqueness of a user and the Privacy at the same time let me explain that for the uniqueness you need to have some kind of a unique identity ifier like a nullifier that's called in technical terms right and if you put that nullifier on chain that means that potentially somebody that gets on hold of your passport can derive the same number and understand that you've registered and basically they might not understand who you voted for or how you voted for but they'll be able to understand that you've participated and especially in high privacy cases such as Russia that could go like for 5 to six years in prison like even participating in this type of protest and the same happens like if we reverse it right so if we allow the user on a phone to Blind and generate the nulf fire that can be traced uh then we're losing the uniqueness so this three side problem in today's identity Frameworks is sold by something I call this kind of a hardware tail when we look at like any framework does no matter we bring passports we bring like the certain data out of the real world we heavily rely the identity to have those three properties guaranteed at the same time on an external issuer a tester s party it could be an NPC it could be a centralized issuer it could be like multiple servers running and other type of decentralized consensus in terms of updating but to derive uniqueness and privacy it's always delegated to an MPC that's how every identity is built like in traditional web 2 or the Frameworks that we see how do we of the modern Frameworks we see how do we bring this veriable identities on chain and I want go into like the risks that this technical approach has because like yeah there's kind of a chance of collusion and and most of the kind of innovation that happens around this is like how do we decrease the risks of NPCs or this kind of a a testers in this equation to not them being able to like collude or not being able to trace them and not being able to somehow take the systems down right and apart from these kind of a risks of Delegation what worries me and what we've already seen in real world is that those NPCs and those servers and those the testers are run by companies and the bare minimum we've seen is that like the pressure from a regulation so they go out they find the companies different Juris dictions different countries put out the investigation and in a way identity Frameworks because of this dependency does not really scale or does not provide a framework that is user owned and permissionless so while looking at this three body problem we said like how can we solve it especially for high sensitive cases where you know that government or like the other party the villain party might go out to NPCs might go out to business might go to the individuals so how do we change the framework where identities are not built as stable coins with the dependency on an issuer but can have a more permissionless user owned framework and that's basically what rimo does if we zoom out at rimo as this kind of a decentralized registry we maintain those three most important properties in and guarantee that through such a flow first thing the decentralization we've completely removed the issuer or an attester from the equation especially in the passport cases that makes a lot of sense because the passports that bear our information such as name age uniqueness citizenship and we all have this type of like national identity they have a chip inside that means that they can sign and they can verify the credibility of the information that is stored on the passport side so in the system of the centralized permission list regist such as rimo users are able to self-issue their identity so you can have like different apps different Frameworks just a phone just an app tap a passport self-issue your identity no one can come after you no one can ban it no one can unless they don't take the passport from right and this and passport infrastructure has been going on for like I don't know 10 years right and at least like the expir date is 10 years and even if those documents expire we can reuse them because those microchips are owned and like they just sit in our pocket another important feature like how can we guarantee the [Music] uniqueness without relying on the third party issuer and that's an important aspect so what we do it's a bit of a cringe version so when you scan your passport you derive a n Fire in the form of the hash and you just publish it on chain but it's a distributed large registry as a chain where all the passports all these identity documents go out there and build this kind of a unique nullifier Registries but the privacy is maintained because the same tree and like the nullifiers and unique identifiers are shared by the different use cases so we call it this kind of the Privacy is the network effect where somebody even if they get on hold of your passport and derive the nullifier of uniqueness of yours all they understand that they you registered within the chain but they will never figure out you came in here for like meme tokens or you came in to vote against the regime or you just came into here to register or do whatever you want so this kind of plausible deniability due to network effect creates this kind of a shield where every passport every document every person around the world registering there is contributing to a kind of this network effect of the privacy on its own if you you look at this approach it creates this completely new framework and the setup in identity systems which is permissionless ZK Registries I mean we can call it like that nothing exists this naming yet but that's the cool part it's not owned by anyone it's not dependent on any issuer or company it is B just basically exists on chain and people are creating contributing and developing and like validating and auditing that thing permissionless I always say it's like this moment uh when for an identity you always have this kind of stable coin type of framework now into this kind of self-owned user generated permissionless way to put your identities the cool part about this entire concept is that you can reuse the same logic and the setup for to run different type of Registries and I don't know I mean if you presented and talked about it but the idea is that like you can take the same setup and just launch the ofac list like this sanctioned list of the people and the cool part about it that like anyone the this data about like the sanctioned list is like available online right and this setup allows you to basically download the data you as a user upload generate the proof at like that whatever registry is used by XYZ application it the proof that it is the same registry of the data that you just downloaded you can check the validity of it and what's notable you can check yourself whether you're included or not in the same registry so it's a kind of open setup how anybody can become a registry without relying on any Oracle service or any service provider outside on these type of lists that are public and that could be verifiable on Chain by everyone else we're looking into we started off this kind of like subregistry of passports that everybody can already tap and join we extending into this kind of a registry of like sanction list Offa list all that type of things you can build out the commitments of like self-building social graphs and reputation systems and I think like on its own this entire concept and new category of permissionless DK Registries is something that makes a lot of sense in a decentralized setups we're looking to introduce it as the kind of a rollup that could exist across the different ecosystems it could have these kind of sub Registries across the different layer ones layer TOS uh or even like evm and nonm setups and the cool part about it is that you can build this shielding Network effect as the data grows and it could be maintained by any individual from all around the world who just have a passport or who just like been able to download and generate the proof of validness of the Registries I guess that's it thank you for your time we do have some room for questions from the audience I'm looking around Who Dares not all at the same time okay yeah okay we got one here how do you see registries you know the growth of AI massive amounts of data going on chain lots of yeah Mass just data going on chain with AIS how do you see Registries being impacted by that and then where does passports play into that and identity how do you see that space moving forward over the next few years you mean like how can AI feed on this or uh think of that like the ZK part right so what you see in this registry it's like this blinded points of data with no correlation like how they really connect to each other the primary difference between this framework is that like there is no there's no like a uni unique identifier unifier that is attached to a person but it's just like these kind of bits of like different identities that could exist in different Registries and only you as a user can decide what to bind what to show what to prove other than that like there won't be a source or a force even like your passport created as the government you've been able to trace it right what what I don't like in a way in other type of identity systems that are biometric is that why passports are better than Biometrics so any a way in the passport scenario it has this unique thing so you generate your identity Keys you bind the passport to this identity key and this passport has an expired date so you can you always have this kind of chance to go like reissue this documents throw ditch the old one away and you got this kind of the Everlasting ability to restart yourself as an identity and in that case what happens is like you got this number passwort attached to it but this number is completely out of a thin air so no one can trace it even the AI and you can always kind of like clean up yourself or like tied it up for the next reuse when you put a Biometrics like I right or I don't know a hand Palm this is the number so your eyeball is the number and that based on that number AI could do magic of tracing stuff and that's I think this fundamental difference why we should move from dependent identity Frameworks to this scattered chaotic even like Blurry and confusing Registries and I think that that is kind of pruned to all this AI threat more and it gives more control on the user side and that's what it makes sense in the longer future thank you [Applause]
Automatic transcript — names and jargon may be misspelled.