[00:57.880 --> 01:00.540] Good afternoon, everyone, and welcome again to A New HOPE. [01:00.860 --> 01:01.940] Just a couple quick things. [01:02.080 --> 01:04.360] Of course, it's ridiculously hot outside. [01:04.520 --> 01:08.520] Whether you're calling at 35 or 95, please stay hydrated. [01:09.760 --> 01:13.060] Gotta keep yourself cool in temperatures like this. [01:13.260 --> 01:17.660] Also, if you've just entered the space, please make sure, of course, that your cell phones are silent. [01:18.720 --> 01:21.100] Feel free to also join us on the Matrix Chat for this. [01:21.340 --> 01:27.180] And, of course, our virtual attendees, as well as anyone in the room that is on the Matrix Chat may have questions. [01:27.300 --> 01:28.320] Asked through the chat. [01:28.800 --> 01:30.160] Asked to our speakers. [01:33.350 --> 01:34.670] Now to our next talk. [01:35.110 --> 01:35.690] Do you want to take some? [01:35.770 --> 01:35.930] Okay. [01:36.230 --> 01:41.470] A lot of people think that crypto is secure, is private. [01:42.930 --> 01:47.290] The problem is that even the most secure cryptocurrencies may not be. [01:48.450 --> 01:56.670] But our speakers, Elaine Rettig, Arctic Byte, and Michelle Lye, have some information about that that might improve your privacy. [02:02.340 --> 02:02.800] All right. [02:03.020 --> 02:03.640] Thank you for the intro. [02:04.340 --> 02:05.640] Sounds like the audio is working. [02:06.320 --> 02:07.320] Nice to meet everybody. [02:07.500 --> 02:09.340] We can't see you at all. [02:09.540 --> 02:12.040] I have no idea how many people are out there, but this is... What did you say? [02:12.080 --> 02:13.120] It's like stage acting or something? [02:13.200 --> 02:14.100] It's just kind of exciting. [02:14.500 --> 02:14.820] So... [02:16.640 --> 02:17.280] Good privacy. [02:17.400 --> 02:21.540] You guys are in the anonymity set, which we'll talk about in a few minutes. [02:21.540 --> 02:23.140] We're in the public blockchain here. [02:23.380 --> 02:23.640] Exactly. [02:24.580 --> 02:26.700] Yeah, I guess we're the main chain here. [02:27.260 --> 02:27.400] Yeah. [02:27.660 --> 02:46.140] So, you know, tools like Bitcoin and Ethereum, not even to mention privacy-focused cryptocurrencies like Zcash Monero and a few others that we'll talk about, have great potential to have an application in privacy to be used in kind of a secure, private fashion. [02:46.140 --> 02:51.620] Obviously, they have additional properties that are really nice, like censorship resistance that we all care about. [02:52.440 --> 03:00.120] However, just to lay the stage for kind of what we're going to be speaking about here for the next hour, there's some nuance there, right? [03:00.260 --> 03:12.320] So, I mean, I imagine probably many or most or even all of you are kind of aware of the fact that, like, by default, transactions on networks like Bitcoin and Ethereum are actually completely public and visible. [03:13.360 --> 03:18.360] And, you know, many people conflate ideas like pseudonymity and anonymity, right? [03:18.420 --> 03:28.860] So you'll actually see, for example, many journalists writing articles about how, you know, there are, quote-unquote, anonymous, you know, shadowy supercoder types using anonymous transactions on networks like Bitcoin. [03:29.000 --> 03:30.000] Well, in fact, they're not anonymous. [03:30.140 --> 03:30.840] They're actually pseudonymous. [03:32.600 --> 03:41.980] And there have been a number of high-profile cases where criminals, in particular, have been identified, de-anonymized, and busted. [03:42.840 --> 03:45.140] And, of course, privacy is something that matters to all of us. [03:45.220 --> 03:53.360] So what we're going to talk about here in the next hour, just to lay the groundwork, talk about kind of why these things matter to us and why we should all care about these things. [03:54.380 --> 03:58.840] Talk about some of the weaknesses and vulnerabilities and common mistakes that we see people make. [03:59.600 --> 04:06.620] And we'll talk a little bit about what you can do about that and how to maintain plausible deniability, what that matters, why it matters. [04:07.800 --> 04:14.300] And I'll also just put in a mention up front here that we are really fortunate to have a workshop this evening. [04:14.300 --> 04:17.420] So at 7:30 p.m., we have about three hours. [04:17.560 --> 04:18.580] We have time to go quite deep. [04:18.800 --> 04:20.780] So 7:30 until about 10:30 p.m. [04:21.060 --> 04:22.720] on the fourth floor of the main building. [04:22.920 --> 04:25.920] I don't have the room in front of me, but one of those rooms up there. [04:26.060 --> 04:27.740] We're going to be doing a very, very deep dive. [04:27.760 --> 04:32.020] So you'll get kind of a high-level introduction to a lot of these ideas, tools, et cetera, here. [04:32.360 --> 04:35.720] And then if you're interested in joining and doing a deep dive, bring your laptop. [04:36.300 --> 04:40.520] We'll walk you through the case studies in more detail, some more background. [04:40.520 --> 04:47.200] And then we'll dive into specific tools you can use, how to use them to maintain strong privacy on cryptographic networks. [04:47.400 --> 04:47.580] All right. [04:47.980 --> 04:50.800] So with that out of the way, let's do some quick intros. [04:51.760 --> 04:54.160] So to my far right, we have A.B. [04:54.360 --> 04:55.480] You want to quickly introduce yourself? [04:55.860 --> 04:56.280] Yeah, hi. [04:56.400 --> 04:57.520] My name's Arctic Byte. [04:57.800 --> 05:07.100] And yeah, I've got a background in the cryptocurrency space from close to the beginning as one of the earliest scaled-up mines in the U.S., implementing FPGA and ASIC technologies. [05:08.180 --> 05:13.320] And yeah, privacy has been a huge part of my motivation to get a part of the space. [05:13.460 --> 05:22.900] But also, you know, as we start, you know, seeing the, you know, kind of corporatocracy taking more and more of our privacy over the years, it's just become more of a feeling. [05:23.060 --> 05:30.940] You know, it feels very good to remain relatively private and give away as little data as possible about yourself when you're interacting online. [05:30.940 --> 05:41.040] And cryptocurrency offers an amazing opportunity to, you know, at least pay for things privately as well as, you know, empower a lot of other services that can be privacy by default. [05:42.520 --> 05:45.400] But yeah, that's a lot of it for me. [05:46.840 --> 05:47.360] All right. [05:47.460 --> 05:47.700] Thank you. [05:47.840 --> 05:48.020] Michelle? [05:48.940 --> 05:49.660] All right. [05:49.880 --> 05:50.760] Thanks for being here, everybody. [05:50.980 --> 05:51.880] My name is Michelle Lai. [05:52.340 --> 05:57.560] I got my start in cryptocurrency as a full-time job at Anchorage in San Francisco. [05:57.560 --> 06:02.800] It's a crypto asset custodian, one of the earlier enterprise-grade custodians. [06:03.120 --> 06:07.160] And since then, I've worked with the payment processor called BitPay. [06:07.160 --> 06:13.500] You can pay merchants in crypto and a payment processor will basically settle to the merchant in fiat. [06:13.820 --> 06:15.340] So it makes everything very easy for everybody. [06:16.120 --> 06:22.880] I've also worked with Copper, a UK-based trading custody and trading crypto company. [06:23.640 --> 06:30.580] Right now, I do some investing and I also work with a privacy protocol on top of a network called Solana. [06:30.700 --> 06:31.480] It's called Light Protocol. [06:32.340 --> 06:44.500] I was on the first grant board at the Zcash ecosystem where we gave out Zcash or Zec grants to people building on top of Zcash. [06:45.120 --> 06:54.960] But we also had a broad enough mandate so that we could give an almost $1 million grant to the Tor Foundation to build a Tor implementation. [06:55.360 --> 07:03.280] And the reason it was important for Zcash is that it allows somebody to run a Zcash node with network level privacy. [07:04.220 --> 07:08.280] So that's my background and why I care about privacy. [07:10.140 --> 07:14.740] I grew up in a pretty conservative, conformist kind of environment. [07:15.160 --> 07:20.100] And I think it was then where I always looked at things a little bit differently than the people around me. [07:20.100 --> 07:31.100] And I felt like it's very controlling when people can look at what you're doing, everything you're doing, and have opinions on what you should do, should think, should say. [07:31.360 --> 07:42.940] And that, for me, was the core of when I started feeling like people should have privacy because, you know, to the extent I want freedom in how I think, other people should also have freedom in what they think. [07:42.940 --> 07:53.160] And we should protect ourselves from being prejudiced by everyone being able to selectively disclose themselves to each other. [07:53.360 --> 08:01.100] That's why even though I'm very paranoid about sharing my personal information, I still have a Facebook account because, to me, it's about selective disclosure. [08:02.860 --> 08:04.320] All right, thanks for that intro. [08:05.820 --> 08:12.660] Yeah, so, by way of background, I was formerly an Ethereum core developer. [08:12.660 --> 08:14.820] So I worked for the Ethereum Foundation for a couple of years. [08:16.700 --> 08:20.100] And for the past three to four years, I've been helping... [08:20.680 --> 08:21.580] Sorry, I'm Lane. [08:22.000 --> 08:23.320] I skipped my name. [08:24.080 --> 08:31.820] And for the past three to four years, I've been working on a new layer one smart contract blockchain platform called Space Mesh. [08:32.420 --> 08:45.680] And, yeah, I mean, privacy is something that I, as a core developer, think about every day, and we think about constantly as we're kind of designing our protocol, as well as just, like, thinking about the P2P layer, the networking layer, how transactions propagate across the network, [08:45.820 --> 08:46.300] et cetera, et cetera. [08:46.380 --> 08:47.380] So we'll talk about all that stuff. [08:48.500 --> 08:55.820] Another word on why privacy matters to me, since I guess we're all talking about that, I don't remember who said it this way. [08:55.880 --> 09:12.820] I think it may have been Zuko of Zcash, that everything that we take for granted in society today, so every kind of social innovation, right, started out as seditious, right? [09:12.820 --> 09:20.600] Whether that's democracy, whether that's same-sex marriage or reproductive rights, whether that's Bitcoin and the concept of money being detached from the nation state. [09:20.820 --> 09:35.840] I mean, all these things, like, that we today regard as, or at least most of us regard as highly valuable socially and really important aspects of the social fabric of our lives, like, these things all started among, you know, small groups of people, friends, [09:36.040 --> 09:39.020] trusted contacts, chatting in the back of a room somewhere in private. [09:39.020 --> 09:46.500] And if they didn't have that technology, the ability to have these conversations and spread these ideas in private, then I think, socially, we'd be in a very backwards place today. [09:46.660 --> 09:48.300] So I think this is why privacy is so important. [09:48.460 --> 09:55.940] Like, we need protected spaces in our society to push seditious ideas forward, in a nutshell. [09:56.040 --> 09:57.080] That's why privacy matters to me. [09:57.180 --> 09:58.220] And it's getting harder and harder. [09:58.420 --> 10:00.880] Yeah, we were actually missing one speaker. [10:00.880 --> 10:02.260] He couldn't make it here in time. [10:02.260 --> 10:05.920] But he is the legal counsel at Nym. [10:06.080 --> 10:08.460] It's a privacy-focused... Is he legal counsel? [10:09.720 --> 10:10.180] Chief... [10:11.780 --> 10:12.240] Chief... [10:12.240 --> 10:13.680] Well, he's an important person at Nym. [10:13.680 --> 10:14.320] Chief legal officer? [10:14.400 --> 10:15.240] What is the word for that? [10:15.440 --> 10:15.620] Chief? [10:16.160 --> 10:16.940] In-house counsel. [10:16.960 --> 10:17.320] Chief counsel. [10:17.620 --> 10:18.160] General counsel. [10:18.260 --> 10:18.660] General counsel. [10:18.720 --> 10:19.060] That's the word. [10:19.120 --> 10:21.000] He's got a long list of accolades. [10:21.200 --> 10:23.520] He's a professor at Boston University. [10:23.800 --> 10:25.800] He's got a specialization in cybersecurity and crime. [10:25.940 --> 10:27.200] He represented Chelsea Manning. [10:27.200 --> 10:33.200] Also, I think, 40 Guantanamo Bay detainees. [10:33.520 --> 10:41.600] And I think... I really appreciate when we were preparing for this panel, his point of view was... [10:41.600 --> 10:42.860] It's about prisons. [10:43.180 --> 10:47.780] And I think there's... [10:47.780 --> 10:52.200] A lot of people say, if you have nothing to hide, you know, well, then why are you nervous? [10:52.200 --> 10:58.700] And he put it very well, which is, you have nothing to hide today, but what about tomorrow when societies change? [10:59.000 --> 11:03.220] You know, who knew that today's searching for abortion clinics could be a problem? [11:03.820 --> 11:10.880] And so over a long enough lifetime, as societies change, as values change, everyone will have something to hide. [11:11.580 --> 11:20.580] And if you go to prison because of something you did, you know, an innocent search or an innocent thing, a meeting you went to 20 years ago, that feels very unfair. [11:21.540 --> 11:22.120] Well put. [11:22.440 --> 11:24.700] And, you know, I'll just add to that, just to, you know, so this... [11:24.700 --> 11:27.800] I don't think it's a very hard sell to this audience, like, why privacy is important. [11:28.020 --> 11:34.480] But just bringing it slightly back to the topic of kind of cryptocurrency, I believe that it's a human right that people should be able to transact privately as well. [11:36.460 --> 11:37.680] Okay, so let's dive in. [11:39.060 --> 11:39.880] Let's start with basics. [11:40.060 --> 11:42.640] Would you guys each mind just giving me a definition of privacy? [11:42.780 --> 11:43.860] Like, what does privacy mean to you? [11:44.000 --> 11:44.720] Michelle, do you want to go first? [11:46.220 --> 11:49.040] I covered it, I think, in my intro, it's selective disclosure. [11:49.500 --> 11:50.780] I don't mean to hide everything. [11:50.920 --> 11:53.660] I definitely have friends who hide a lot of things. [11:54.660 --> 11:57.000] You know, who they are, the online trail. [11:57.160 --> 11:59.040] They only use certain kinds of browsers. [11:59.040 --> 12:00.160] They're always on a VPN. [12:00.960 --> 12:03.980] They deleted Facebook many, many years ago, etc. [12:04.380 --> 12:05.680] I have friends who are like that. [12:05.680 --> 12:07.680] And at some point in my life, I decided... [12:09.100 --> 12:16.480] I think I went off Facebook, but then I came back when I realized that you do get a lot of things out of social media and being part of a community. [12:16.740 --> 12:17.860] You just need to... [12:17.860 --> 12:20.660] To me, you need to be able to choose where you draw the line. [12:21.240 --> 12:23.800] Like, maybe my line's not that straight, right? [12:23.820 --> 12:25.540] It's not all or nothing, or it's not everything. [12:25.820 --> 12:29.740] I kind of want to draw my own funny pattern of what I share and what I don't share. [12:30.160 --> 12:33.660] So to me, it's about being able to selectively disclose. [12:34.220 --> 12:36.340] I think that's a really important point, just to re-emphasize. [12:36.520 --> 12:40.360] Like, when I naively began thinking about privacy, it felt very black and white. [12:40.560 --> 12:42.120] It's kind of like things are either public or private. [12:42.440 --> 12:45.380] But, yeah, I think it's very nuanced, as Michelle was describing. [12:45.580 --> 12:46.980] It's more about selective disclosure. [12:47.160 --> 12:50.040] It's more about, like, to put it in technical terms, access control lists. [12:50.460 --> 12:57.080] You know, all the, like, various pieces of my life, whether it's photos or stories or documents or content or even just aspects of my identity. [12:57.080 --> 13:00.220] I want to be able to control in almost concentric circles. [13:00.220 --> 13:01.300] Like, who has access to those things? [13:01.380 --> 13:05.080] The most trusted people, you know, family, friends, the general public, et cetera. [13:05.660 --> 13:05.860] AB? [13:06.240 --> 13:06.640] Yeah. [13:07.000 --> 13:10.020] I definitely agree with those notions of access control. [13:10.300 --> 13:18.100] Currently, I'm running an experiment where I'm trying to kind of just not give any kind of data to anybody other than, you know, close friends, family, and... [13:18.100 --> 13:19.600] Can you pull the mic a little bit closer to you? [13:19.720 --> 13:19.800] Yeah. [13:19.900 --> 13:20.540] Yeah, absolutely. [13:21.120 --> 13:25.960] So, you know, I think privacy is definitely just the ability to express freely. [13:26.380 --> 13:31.440] I think that, you know, there's this kind of, like, thought running in the back of our minds when we know that we're being surveilled. [13:31.540 --> 13:34.100] I mean, there have been experiments that prove this. [13:34.620 --> 13:44.660] You know, that, you know, if you believe, if you know even subconsciously or if you're used to somebody constantly monitoring your activities, your conversations, your thoughts, you're going to act differently. [13:44.660 --> 13:57.540] And I think it's really important to just continue, you know, evolving in a natural way and in a way that, you know, is, you know, most aligned with, you know, what we truly believe inside of ourselves and feel. [13:57.780 --> 14:06.180] That, again, like Lane said, having those open spaces to keep moving forward is really critical and increasingly difficult. [14:06.760 --> 14:18.040] So, yeah, the experiment I'm running currently is, you know, can I, you know, essentially be private from, like, sharing information with everybody except for, you know, government entities and banks? [14:18.700 --> 14:20.700] Because those are obviously very hard to get around. [14:20.960 --> 14:27.660] But, you know, other than that, yeah, remaining private is kind of like an experiment that I'm running right now, mostly to see how it feels. [14:27.880 --> 14:30.280] And, yeah, so far so good. [14:30.640 --> 14:35.720] So you said you want to disclose information to everyone except governments and banks, right? [14:35.720 --> 14:36.480] Did I get that correct? [14:36.720 --> 14:36.780] Yeah. [14:36.780 --> 14:37.720] So how? [14:38.360 --> 14:39.360] Let's start with the basics. [14:40.940 --> 14:42.840] Yeah, there's a long list of things to do. [14:43.060 --> 14:50.860] And, you know, for instance, you know, setting up anonymous, you know, legal structures for ownership of your home, paying bills, this kind of thing. [14:51.760 --> 14:53.820] But it really starts on technology. [14:54.140 --> 14:55.900] I mean, this is where we leak the most data, obviously. [14:56.160 --> 15:05.240] So it requires setting up, like, a privacy-preserving operating system, both for, you know, your computer and your phone. [15:06.060 --> 15:07.400] And it goes from there. [15:07.620 --> 15:10.600] So we can dive kind of deep into that. [15:10.700 --> 15:24.880] But I think to stick to the topic of, like, cryptocurrency privacy, it might be worthwhile going over kind of the areas where, assuming that, you know, you haven't already connected your crypto account to your real identity in some way. [15:24.880 --> 15:30.860] For instance, you went and, at this conference or somewhere else, you purchased some cryptocurrency with cash anonymously. [15:31.540 --> 15:33.280] And that person doesn't know who you are. [15:33.820 --> 15:34.880] Then what... [15:35.520 --> 15:41.820] How can you leak data going forward from there that might lead to discovery of, you know, who you are? [15:41.880 --> 15:43.620] For instance, maybe you want to donate... [15:43.620 --> 15:51.640] Maybe you live in a very oppressive country that doesn't support donation to, you know, efforts that are here today, like EFF, Free Software Foundation, this kind of thing. [15:53.360 --> 15:58.140] So maybe you want to keep those kind of activities that you want to, you know, support private. [15:59.500 --> 16:08.620] You know, in normal crypto networks such as Bitcoin or Ethereum, you know, the sending address or account is necessarily exposed, revealing all associated transactions with that account. [16:09.740 --> 16:14.420] So this is the easiest way to identify, you know, who the owner of a wallet is in particular. [16:14.900 --> 16:24.760] And it starts really with, you know, if you accidentally, you know, pay for something where there's an order in your name and that company is, like, you know, sharing that data with data miners, I mean, then you're linked. [16:24.760 --> 16:31.920] And obviously, if you put any exchanges where you've, you know, identified yourself, that's a thing. [16:32.500 --> 16:50.740] But going a bit deeper, you know, the most common ways to, you know, reveal data about yourself is, you know, anybody can run, like, a global cluster of nodes on any blockchain network that basically monitor for where transactions are first seed on the network. [16:50.740 --> 16:58.460] And this can help locate exactly where you are or at least roughly your IP address range of, like, where you probably are in the world. [17:00.800 --> 17:16.480] And this is really trivial to get around, actually, by using, you know, proxy chains and, you know, timers and, you know, deploying transactions and making it seem like they originate from different points in the world to kind of isolate or separate that activity from yourself. [17:16.480 --> 17:19.460] But by default, this isn't done at all. [17:20.020 --> 17:26.420] Most people connect to a publicly available endpoint run by a centralized company because that's easier than running your own node. [17:26.820 --> 17:35.340] And that publicly available endpoint receives your IP address and probably other data that is included in the transaction. [17:36.080 --> 17:37.220] such as the time. [17:37.260 --> 17:44.580] And we do know some of these end nodes, these RPC endpoints have been, you know, subpoenaed for IP addresses. [17:44.920 --> 17:46.500] Yes, that's a really important note. [17:47.260 --> 17:52.980] And, yeah, this is an example of, you know, this data getting out in the public. [17:54.440 --> 18:00.820] There's also, you know, another common data gathering point in crypto networks is Block Explorers. [18:00.820 --> 18:09.860] So it's a website like Etherscan or, you know, blockchain.info, blockchain.com, where you go to, you know, look at your transaction history. [18:10.380 --> 18:14.760] You know, let's say I'm the only one who's ever looked up, you know, addresses A, B, and C. [18:14.940 --> 18:21.180] They can be pretty sure that, you know, all the information associated with my machine is now linked to those addresses. [18:21.180 --> 18:28.560] And that can be used to, you know, track further down the line not only IP address but operating system and everything that's exposed when you visit a website normally. [18:30.320 --> 18:41.100] So, yeah, these are the most common ways that, you know, that people kind of leak data around ownership of addresses when otherwise they could be anonymous. [18:41.680 --> 18:49.080] So, A.B., some of the tools and techniques that you mentioned like proxy chains and, you know, VPNs, Tor, et cetera, these sound pretty useful. [18:49.220 --> 18:52.280] Are you going to show us how to use these at the panel, sorry, at the workshop this evening? [18:52.620 --> 18:53.260] Yeah, absolutely. [18:53.260 --> 18:55.760] It's actually not too difficult to set up these things. [18:55.760 --> 19:04.460] It just requires the diligence to, you know, remember to use them and ideally bake in those habits as automatic. [19:05.260 --> 19:05.640] Yeah. [19:05.960 --> 19:07.960] Privacy is definitely not convenient. [19:08.740 --> 19:10.000] But, yeah. [19:12.760 --> 19:24.740] Michelle, what are a couple of examples of techniques or tools or techniques, I guess, that have worked well for you with respect to sort of maintaining strong privacy while transacting with cryptocurrency on cryptographic networks? [19:25.200 --> 19:25.640] Yeah. [19:25.860 --> 19:30.020] I think, for me, the main one is I don't do anything too fancy. [19:30.380 --> 19:32.660] Not as, you know, at that level. [19:33.580 --> 19:40.040] But I think, for me, the important thing is to kind of be clear which wallets you use for which purposes. [19:40.040 --> 19:47.240] Like, if you sign up for some of these crypto conferences, as part of your application process to go to a conference, they ask you for an address. [19:47.440 --> 19:50.860] So that clearly is an address that, you know, anyone could know. [19:51.160 --> 20:02.160] And to the extent you don't want to be targeted or you simply want to preserve your own privacy, I think you need to be smart about who you disclose what information to. [20:02.740 --> 20:12.440] I think a lot of people also practice, actually, probably not enough people practice kind of using a new wallet every time you engage in a new transaction. [20:12.740 --> 20:21.520] And for different blockchains, whether there's this concept of a UTXO blockchain versus a balance-based blockchain, it's a little bit easier in the first to kind of have... [20:21.520 --> 20:25.620] Michelle, what's the difference between a UTXO and an account-based blockchain? [20:26.160 --> 20:27.600] Can we get the TLDR? [20:27.920 --> 20:29.280] Actually, can you do the TLDR? [20:29.280 --> 20:31.980] So UTXO stands for unspent transaction output. [20:32.200 --> 20:37.940] So Bitcoin and its derivatives, so this includes projects like Zcash, for example, are UTXO-based. [20:38.120 --> 20:42.380] And so the best way to think about a UTXO is it's like a bill in your wallet, right? [20:42.420 --> 20:45.120] So it's kind of like in the case of where you could think of it as a coin in the case of Bitcoin. [20:46.160 --> 20:54.080] And so you can, like, a transaction consists of kind of giving, like, imagine giving someone a $100 bill and then getting like $75 change or something, right? [20:54.140 --> 20:56.320] So this is how transactions work in the Bitcoin network. [21:00.120 --> 21:06.100] You send a large note to the network and then a piece of that gets sent to the recipient and then you get change back. [21:06.680 --> 21:12.600] And so a wallet in a network like Bitcoin, in a UTXO network like Bitcoin, is like a physical wallet, right? [21:12.660 --> 21:14.140] There's a metaphor there where it actually has... [21:14.140 --> 21:17.080] You can, again, imagine, like, actual physical notes in that wallet. [21:17.160 --> 21:19.980] Each of those is a UTXO that you can go on and spend and give to someone else. [21:21.080 --> 21:25.480] The paradigm is totally different in an account-based network like Ethereum where you... [21:25.480 --> 21:28.480] So the reason is because the way that... [21:28.480 --> 21:29.500] How do I talk about this? [21:30.600 --> 21:33.420] There's a notion of an account with state in it in the Ethereum virtual machine, right? [21:33.480 --> 21:34.260] It's like a bank account. [21:34.360 --> 21:35.140] Like a bank account, exactly. [21:35.300 --> 21:37.740] And so you have a balance that goes up and down as you receive and send transactions. [21:37.740 --> 21:43.080] So, naively, the former is better for privacy and the latter is worse for privacy, right? [21:43.180 --> 21:56.300] Because in an account-based system like Ethereum, by default, if you don't make any attempt or effort to, like, increase your privacy, all your transactions are flowing into and out of the same account with the same, what's called address, which, again, [21:56.360 --> 21:57.300] is like your bank account number. [21:57.840 --> 22:01.460] Having said that, there are a lot of tools and techniques you can use to increase privacy. [22:01.460 --> 22:09.320] On that point, I think a point of interest is given that there are two kinds of blockchains in this fashion. [22:09.940 --> 22:15.100] When Satoshi published his paper at first, he gave a bullet point summary of what it was. [22:15.320 --> 22:19.380] His third bullet point is that participants can transact anonymously. [22:19.680 --> 22:27.560] And the only reason he thought that would be possible is through this UTXO system, whereas any other system would probably not qualify. [22:27.560 --> 22:35.580] Of course, what he... he didn't expect Bitcoin to be so successful and have billions and billions of dollars thrown at blockchain analysis. [22:36.080 --> 22:38.980] And so anonymous is at best eudonymous today. [22:40.020 --> 22:49.220] Yeah, so just to restate, even though UTXO-based systems work a little bit more like cash, they're not... you don't get strong privacy out of the box. [22:49.420 --> 22:57.340] And we will, in the workshop later today, go through some examples of de-anonymization attacks that have actually happened, some in theory, some that have actually happened in practice. [22:57.340 --> 23:01.840] And we'll actually try to do some live de-anonymization of transactions on the blockchain, which should be fun. [23:02.680 --> 23:05.440] And in the case of account-based networks like Ethereum... [23:06.720 --> 23:10.620] So I said, with UTXO-based systems, they sound like they give you better privacy. [23:10.720 --> 23:12.360] You don't actually get strong privacy out of the box. [23:12.500 --> 23:20.820] And the opposite is also true, which is that it is possible to have strong privacy even in an account-based system like Ethereum, even though it's even worse out of the box. [23:20.880 --> 23:22.500] And we'll go through some of those techniques later as well. [23:24.080 --> 23:24.980] That's a mouthful, okay. [23:26.540 --> 23:27.960] And your favorite techniques? [23:28.180 --> 23:32.020] Yeah, I would say... what do I do that works well? [23:32.160 --> 23:35.520] So, again, I would say the most basic things you can do... [23:35.520 --> 23:38.700] Okay, the most obvious, obvious thing is, like, use a VPN. [23:38.960 --> 23:43.140] Like, always, everywhere, at home, you know, on your mobile device, et cetera. [23:43.140 --> 23:44.740] That's just, like, out of the box. [23:44.860 --> 23:52.940] That helps enormously because it makes it harder to establish those links that AB alluded to between, like, your IP address and your wallet addresses and your actual transactions. [23:53.220 --> 23:58.680] As I'm sure folks here are aware, if you have someone's IP address, you have an enormous amount of information about that person and where they are. [23:59.900 --> 24:03.420] And I think the other thing is just good management of wallets and addresses. [24:05.400 --> 24:07.680] So, you know, we have these beautiful standards. [24:07.820 --> 24:08.760] There's one called BIP32. [24:08.940 --> 24:17.420] So BIP refers to a Bitcoin improvement proposal, which lays out an algorithm for something called a hierarchical deterministic wallet. [24:17.640 --> 24:24.100] And the way this works, if you've ever used basically any cryptocurrency wallet, you will have seen, like, a seed phrase, which is usually a 12- or 24-word phrase. [24:24.800 --> 24:27.280] That's, like, your seed root phrase. [24:27.460 --> 24:31.060] And, I mean, that just maps to a cryptographic, to a number, to a private key. [24:31.240 --> 24:39.840] But then using this BIP32 kind of deterministic algorithm, you can actually spawn an unlimited number of fresh wallet addresses from that single seed. [24:40.600 --> 24:45.520] And, again, all modern cryptocurrency wallets support this, but they don't all make it easy out of the box. [24:46.000 --> 24:55.040] And so I guess, as Michelle said, like, I guess the best practice and something that I try really hard to do is to always use a fresh address for every application, for every... [24:55.040 --> 24:57.620] We talked before about how privacy is selective disclosure. [24:57.820 --> 25:00.220] And in my mind, I have a notion of kind of concentric circles. [25:00.500 --> 25:13.680] So it's not that you can never reuse an address, but, like, transacting within a single context, like within the context of a single application or a single community or a single group of people, I try to, you know, just be cognizant of which address is used for each of those. [25:13.680 --> 25:15.060] It's hard because there are many of them. [25:15.180 --> 25:17.100] And, again, the wallet software is not amazing. [25:18.380 --> 25:22.660] There's a lot of Bitcoin on the blockchain that's just locked because people forgot their keys. [25:22.940 --> 25:24.000] They mismanaged it. [25:24.740 --> 25:27.360] A hard drive got sent to the trash pile. [25:28.760 --> 25:30.880] We all have stories of this, believe me. [25:30.960 --> 25:33.940] Anyone who's been in the space for more than a year or two, like, definitely has versions of this story. [25:34.180 --> 25:35.120] AB, what's your version? [25:35.260 --> 25:37.900] You've been here longer than most of us. [25:37.900 --> 25:50.180] I saw a forum post in the early days where Satoshi, you know, the synonymous group that, you know, supposedly invented Bitcoin, Satoshi said, you know, never delete private keys. [25:50.400 --> 25:51.640] You might need them at some point. [25:51.840 --> 25:52.380] So, yeah. [25:53.560 --> 25:56.020] I've never lost any so far. [25:58.120 --> 26:05.740] But, yeah, that's the really beautiful part about crypto is, you know, you can keep unlimited backups, and you can secure those using any kind of cryptographic means that you'd like. [26:06.040 --> 26:08.080] You know, for instance, Shamir's secret sharing scheme. [26:08.240 --> 26:10.280] I'm sure some of you are familiar with that for various purposes. [26:11.340 --> 26:15.540] Using that to store crypto keys is amazing because you can, you know, store it in M of N places. [26:15.980 --> 26:22.060] And as long as M of those aren't compromised or lost, you still are in control. [26:22.200 --> 26:31.840] And you can also set up canaries in those places so then you know if somebody's, like, making moves to compromise your account, you can migrate to a new, more secure setup. [26:32.160 --> 26:41.860] So, this is extremely powerful for just the ability to, you know, securely hold assets of any kind that are, you know, digital. [26:42.920 --> 26:50.660] But, yeah, to your guys' point with, you know, addresses, UTXO, it just really depends on your adversary. [26:52.140 --> 26:59.920] For instance, one popular technique, if you don't want, you know, on the public network to reveal, you know, all these addresses, you don't want accounts to be linked. [27:00.700 --> 27:04.980] And your exchange, like, for instance, you have an exchange who you trust to not share your info. [27:05.160 --> 27:07.280] And, you know, the government isn't your adversary. [27:07.480 --> 27:11.220] The exchange isn't because they, you know, are supposedly keeping that information private. [27:11.820 --> 27:25.260] Then one popular method to achieve blockchain level security or privacy is basically just to make a withdrawal from an exchange to a new account for each purpose that you use for each one of those new wallets that you create. [27:25.260 --> 27:33.520] That way you're not sending a transaction from your old wallet to your new wallet, which, you know, if you're sending the entire balance, it's pretty obvious that you're just migrating accounts. [27:34.220 --> 27:37.500] So, yeah, so that's one popular method that's easy to use. [27:37.940 --> 27:53.060] There are other services that can basically take the place of an exchange as a mixer in that place, and you can use fully, you know, cryptographically executed mixers which exist as smart contracts on various networks. [27:53.060 --> 27:55.040] Can you explain the concept of a mixer? [27:55.680 --> 27:56.200] Sure, yeah. [27:56.440 --> 28:05.580] Like, a mixer, in essence, is a place where, you know, it's usually ideally a smart contract that's running autonomously where you can view the source code and make sure that you agree with everything that's going to happen. [28:06.300 --> 28:13.300] That basically accepts a lot of inputs from a lot of different users and allows those users to withdraw the same amount that they've put in. [28:13.300 --> 28:24.720] In a blockchain kind of situation where all the transaction inputs are public, basically it's a requirement to standardize the amounts that you're inputting, so that way it can't be identified. [28:24.720 --> 28:31.860] For instance, you know, if I input, you know, five, Michelle puts in three, Lane puts in one, and then we all make those same withdrawals, it's pretty obvious who's who at the end of that. [28:32.980 --> 28:41.900] So, yeah, standardizing the amounts, adding them all to a pool, and giving certificates, cryptographic certificates, which then allow you to redeem the amount you deposited prior. [28:42.520 --> 28:44.280] That's the basic concept of a mixer. [28:44.720 --> 28:48.000] That could be used to the same effect as what I mentioned in exchange for in the past. [28:48.000 --> 28:51.740] That's directly linked to the title of this panel, which is Plausible Deniability. [28:52.160 --> 29:02.120] So, whoever took a coin from this pool, this joined pool, it's not clear which input provided that output. [29:03.160 --> 29:05.660] Yeah, so let's just... I mean, I had a note on this. [29:05.660 --> 29:14.500] I think it is worth mentioning, like, I think we all have an intuition for what plausible deniability means, but there is an actual, like, cryptographic definition, which is k-anonymity, right? [29:14.580 --> 29:15.260] So I'm just going to read this. [29:15.360 --> 29:21.760] Generally speaking, a k-anonymized dataset has the property that each record is indistinguishable from at least k-1 others. [29:21.880 --> 29:24.820] So this is the size of the privacy set or anonymity set. [29:25.640 --> 29:40.240] Specifically, if a mixer contract, which AB was just describing, holds n deposits, out of which n-k had already been withdrawn, in other words, k are still remaining, then the next withdrawer will be indistinguishable among at least those k users who have not withdrawn from the mixer yet. [29:41.480 --> 29:51.380] Right, so basically, each person who is withdrawing from this mixer has transaction privacy that makes them indistinguishable from among at least k different addresses. [29:51.720 --> 29:54.760] So, I mean, that's just... it's pretty simple math, but just keep this in mind. [29:54.760 --> 30:00.140] Like, when we talk about privacy, when we talk about plausible deniability, like this is the kind of rigorous definition. [30:00.480 --> 30:07.720] At the same time, if not used properly with all the usual safeguards, what can happen is people can demix. [30:07.940 --> 30:19.320] And that's what happened more recently, where a user of a Wasabi wallet was demixed, and they were arrested. [30:20.360 --> 30:22.640] Yeah, so, okay, we're jumping on a little bit. [30:22.800 --> 30:25.580] So, there are... so, mixtures are a really important topic. [30:25.740 --> 30:31.560] So, there are mixtures in the Ethereum network, like TornadoCash, which is quite well known, and ZK... what is it called? [30:32.780 --> 30:33.160] Sorry. [30:33.280 --> 30:34.780] The DLayer2, not ZK Sync. [30:35.920 --> 30:37.300] Z... the Aztec. [30:37.500 --> 30:37.880] Aztec. [30:37.920 --> 30:38.460] ZK Money. [30:38.760 --> 30:39.200] ZK Money. [30:39.580 --> 30:43.480] And then in Bitcoin world, there are wallet software. [30:43.620 --> 30:47.720] There's tools like Samurai Wallet and Wasabi Wallet. [30:47.720 --> 30:52.440] And we're gonna... we don't have time on this panel, nor do we have, like, the AV set up to kind of, like, demo these things. [30:52.560 --> 30:55.480] But we're gonna do that all... sorry, I keep plugging the workshop later. [30:55.700 --> 30:58.220] So, you'll get a chance to roll up your sleeves and play with those tools there. [30:59.860 --> 31:06.340] Okay, so let's... so, yeah, so let's stay on the topic of mixtures for a few minutes, because this is actually, like, a very concrete, powerful tool we can use. [31:07.880 --> 31:09.920] But people make common mistakes with them. [31:10.440 --> 31:16.560] And so, like, one example of a mistake people make is not waiting long enough to withdraw, right? [31:16.560 --> 31:22.480] So if you deposit into a mixer, the way these things work is they allow deposits in specific amounts, right? [31:22.620 --> 31:26.620] So let's look at, like, TornadoCash allows, like, 0.1 ETH, 1 ETH, 10 ETH, 100 ETH, something like this. [31:26.760 --> 31:27.580] Basically powers of 10. [31:28.140 --> 31:35.840] And you need to wait some minimum period of time to withdraw your coins from the mixer to allow the size of that anonymity set to grow. [31:36.160 --> 31:42.580] In other words, if you just deposit your coins and take them out right away, then the anonymity set is much, much, much smaller, and it's much easier to establish a link. [31:43.940 --> 31:46.280] Another mistake, I mean, there's many mistakes people make. [31:46.400 --> 31:49.520] Another one is not randomizing the time intervals, right? [31:49.560 --> 31:56.360] So if you have a tendency to deposit things and take them out one day later and you kind of repeat yourself again and again, like you're leaking metadata as you do this. [31:56.440 --> 32:04.080] And so it would be ideal if the wallet software were designed in such a way that this could be automated. [32:04.160 --> 32:07.380] And I'm not aware of wallet software that's this sophisticated yet, but they are getting better. [32:07.380 --> 32:08.260] Yeah, not yet. [32:08.480 --> 32:15.700] And time zone is a huge metric for correlating ownership of wallets, or at least location of origin of wallets. [32:15.780 --> 32:27.880] You know, if you're only sending transactions between, you know, nine to five New York time, in the entire history of an Ethereum account, for instance, which you can very easily see, or even with a chain of Bitcoin addresses where you can quite clearly see, [32:27.980 --> 32:35.760] you know, that a change amount is going to be a kind of a random amount because the fee size is variable and has a bunch of like random seeming decimal places. [32:36.040 --> 32:49.000] It's quite easy to trace kind of like the originator of that address and as that goes through the UTXO chain, like who's the account that's still in control of the original balance minus what's been spent. [32:49.640 --> 32:51.580] But yeah, time zone is a huge one. [32:51.720 --> 33:02.220] So a wallet software which did, which will incorporate, you know, randomization of both, you know, IP address where it's originated from and time zone is critical. [33:02.220 --> 33:02.540] Yeah. [33:04.720 --> 33:07.720] No, yeah, I think you can just pull the microphone a little bit closer to you. [33:07.820 --> 33:07.860] Okay. [33:08.220 --> 33:08.280] Yeah. [33:09.020 --> 33:09.160] Good. [33:09.360 --> 33:09.460] Yeah. [33:09.660 --> 33:14.320] Time zone, like, so, I mean, I actually think about this a lot. [33:14.420 --> 33:14.840] It's kind of funny. [33:14.960 --> 33:20.480] Like, should I just set my alarm clock so that I wake up at random times of the night to like transact if I want? [33:20.540 --> 33:22.060] I mean, I'm half joking. [33:22.160 --> 33:22.620] I'm half serious. [33:22.780 --> 33:25.260] But like, again, like ideally, wallet software would do this for us, right? [33:25.320 --> 33:25.980] We're not there yet. [33:26.080 --> 33:29.400] But this just goes to show that there is enormous scope for any hackers in the room. [33:29.400 --> 33:37.280] Like, you can add incredible value to the world, I think, and to these networks by implementing even some of these like basic, basic, basic things that haven't been implemented yet. [33:37.460 --> 33:37.740] Yeah. [33:37.840 --> 33:48.000] For instance, just like a centralized service that requires no trust by the user that, you know, where you guarantee that a transaction will be broadcasted randomly within the next 48 hours. [33:48.160 --> 33:50.120] You know, that would be a tremendous service to people. [33:50.120 --> 33:56.240] The problem with implementing that, you know, in a centralized way is there's the avenue for censorship. [33:56.800 --> 34:00.120] You're probably going to knock on the door from our friends in the alphabet soup. [34:01.460 --> 34:03.140] While we're on this topic, here's another fun one. [34:03.280 --> 34:06.500] Are you aware of the gas price de-anonymization in mixers? [34:06.660 --> 34:07.660] Have you noticed this one at all? [34:07.840 --> 34:09.000] This is something I was reading about. [34:10.720 --> 34:25.120] So, more sophisticated... So, most users who are using a network like Ethereum will not pay attention to gas and they'll just like use whatever default gas price their wallet software, like MetaMask or whatever, just suggests for them, which it often calculates based on how busy the network is at a given point in time and how fast you want your network, [34:25.260 --> 34:26.520] your transaction to be confirmed. [34:26.980 --> 34:41.780] More sophisticated users will often do a thing, and I'm guilty of this myself sometimes, where I just feel that I have... I can estimate the required gas better than my wallet can, and I'm often right, and so I'll like manually specify a gas price, but it turns out that if you do this, [34:42.200 --> 34:44.420] you're leaking metadata again, right? [34:44.520 --> 34:57.620] And so, if you do this regularly or if you just set a gas price manually and then kind of don't update it for a while, and you, for example, deposit into a mixer and then withdraw a day later and you haven't changed the gas price, well, you've just leaked metadata that allows someone to de-anonymize you. [34:57.620 --> 35:02.100] So there's many, many, many ways that you're leaking metadata in using these systems if you're not very careful. [35:04.860 --> 35:10.440] I think a while ago there was a browser extension called Make Some Noise. [35:10.700 --> 35:17.120] This is quite a few years ago when we were just being aware of how much we're being tracked across the website. [35:17.440 --> 35:28.020] It's a browser extension where if you click on it, it'll just randomly go to a bunch of links which help to deflect attention a little bit perhaps to kind of mix, I guess, mix your browser usage. [35:28.320 --> 35:35.540] I wonder if, you know, that would be something that, you know, would kind of serve our purposes. [35:35.820 --> 35:43.140] I just... it'll be gas heavy for sure, but perhaps on less expensive networks that would be quite valuable. [35:45.020 --> 35:47.680] I don't ever want to assume like a ton of prior knowledge. [35:48.080 --> 35:51.200] But so the idea of gas is like, I mean, just more generally known as fees, right? [35:51.280 --> 35:52.400] So in Bitcoin, they're just called fees, right? [35:52.440 --> 35:57.260] So basically every transaction that goes to the network has to have a fee payment, or in the case of Ethereum, it's called gas. [35:57.480 --> 35:58.840] Different networks have different names for this, right? [35:58.860 --> 36:01.540] Attached to that transaction to pay the miners who mine the transaction. [36:02.100 --> 36:08.360] And when the network is busier and the blocks are more full, typically you have to like pay a higher fee in the case of Bitcoin or pay more gas in the case of Ethereum. [36:09.260 --> 36:12.560] So yeah, so more expensive computation costs more gas. [36:12.680 --> 36:21.220] And it turns out that cryptography, when it's running inside the Ethereum virtual machine, like in a smart contract on a network like Ethereum, is quite expensive. [36:21.700 --> 36:27.940] And this is one of the downsides to doing kind of strong privacy and cryptography in a network like Ethereum. [36:28.400 --> 36:33.700] You know, like a single transaction into a mixer like TornadoCash. [36:33.700 --> 36:38.380] Last time I checked was something on the order of about 100 U.S. dollars in gas. [36:39.020 --> 36:41.300] It varies obviously from day to day, but that's not cheap. [36:41.640 --> 36:57.720] But I think linking that to kind of the cryptographers who are in this conference, people are building zero-knowledge cryptography tools to be able to help do some of this computation off-chain, and then settle back to the Ethereum layer one. [36:57.720 --> 37:05.320] So that's an area where cryptography can really contribute to privacy by helping more of these networks get off the ground. [37:05.860 --> 37:11.000] We're still kind of at the frontier of making science happen. [37:11.760 --> 37:27.500] Yeah, I like to reflect on the fact that even if cryptocurrency fails completely and goes away, hopefully we as a community will still have added some value to the world by sort of pushing the cryptography space forward, and especially, you know, areas like zero-knowledge proofs, [37:27.560 --> 37:31.600] which communities like Zcash, which Michelle was a part of, have done a lot for. [37:31.760 --> 37:36.720] So I think there's some public good here, lest we all hate on cryptocurrency too much. [37:36.780 --> 37:45.920] Anyway, so a point that's been touched upon a few times on this panel already is this tension between usability on the one hand and privacy on the other hand. [37:46.920 --> 37:48.180] A.B., you mentioned this a couple of times. [37:48.840 --> 38:02.580] It's a bit of an open-ended question, but do you have any thoughts on this tension and how, I guess, on the one hand, the tools we use, like wallets, which we keep coming back to, could be better designed to make this stuff easier on the one hand, or on the other hand, [38:02.640 --> 38:05.360] just your personal approach and how you balance these two? [38:05.500 --> 38:12.020] Because, like, we can't always all have perfect privacy because, as you said, like, privacy is frustrating. [38:12.180 --> 38:13.780] So, like, what's your kind of personal philosophy? [38:13.940 --> 38:14.840] A.B., do you want to start? [38:14.840 --> 38:22.200] Yeah, in general, I think, obviously, it would be ideal if all of these kind of privacy features were baked into the operating systems, apps, everything that we use. [38:22.820 --> 38:36.400] Aside from, you know, for instance, like, Apple is very famous for marketing privacy when actually, you know, opening up a back door to directly channel analytics to their servers outside of the VPN if you run it on macOS these days. [38:37.480 --> 38:47.960] So, you know, privacy is something that, you know, it seems like a checkbox to most people, where people just want, like, oh, okay, yes, what I'm using is relatively private, good enough, move on. [38:48.240 --> 39:09.260] So, it just is, you know, anything that is not commercially viable in the sense that, you know, users most efficiently provide the best experience ultimately won't, you know, won't, you know, die in the face of an app that comes by by an open source community that says, [39:09.360 --> 39:13.920] okay, you can use this one instead because it's very private even though there's a couple quirks and it's harder to use. [39:14.980 --> 39:28.860] So, I think that what we really need to think about as a community is to, you know, how do we motivate those who control, like, the most popular apps, both, like, crypto wallets and stormable applications, et cetera, to integrate privacy by default. [39:29.560 --> 39:31.760] You know, there are a few ways of doing this. [39:31.840 --> 39:47.700] For instance, like, this whole innovation around ZK zero-knowledge proofs allows for opportunities of, like, monetization of data in a way that where, you know, nobody ever actually sees the data, but you're allowed to draw the insights from it, which completely minimize the possibility of, [39:47.700 --> 39:57.920] you know, data that's been collected about users to be leaked because, you know, it's all encrypted and remains so for the entire purpose of its life, the entire duration of its life. [39:58.460 --> 40:03.940] So, yeah, integrating privacy by default is something that, you know, doesn't make money necessarily. [40:04.360 --> 40:08.760] So, it's not going to be prioritized by development teams from most mainstream apps. [40:08.760 --> 40:22.100] And this is, I actually, I can't say I know the solution to that, but it's something that I think we all need to, you know, consider and think about, and I think that it's possible that there's some way that we can motivate, you know, privacy by default being built into, [40:22.340 --> 40:23.680] you know, popular applications. [40:25.440 --> 40:35.860] So, on that note, I think the biggest threat to privacy in these applications is consumers, biggest non-legal threat, is consumers not demanding for privacy. [40:36.260 --> 40:43.800] I know a lot of projects who would, the project team love the idea of talking about privacy, but the truth is they have a hundred things on their stack. [40:44.040 --> 40:49.060] And if their users aren't clamoring for these private features, then they're not going to build it. [40:49.820 --> 41:01.260] I think it's very important because, on one hand, you have the authorities pushing down on all these projects, like saying, give us your data, make sure you don't do this or do that or encrypt this, encrypt that. [41:01.440 --> 41:05.740] On the other hand, if consumers don't push back, then obviously the domino is going to fall this way. [41:06.640 --> 41:12.120] I think it was, for example, I mean, this is directly tied to the crypto wars in the 90s, right? [41:12.480 --> 41:17.400] Because of pushback, we're here today, you know, we were able to make progress. [41:17.400 --> 41:27.840] I think it was Biden himself as a senator then who put in a bill that said the government must have plain text access to communications. [41:28.360 --> 41:38.660] And I believe that was what motivated Paul Zimmerman to kind of work day and night, to get his PGP out before the bill was enacted. [41:39.140 --> 41:41.100] We stand on the shoulders of giants. [41:41.440 --> 41:47.340] Like seriously, I think we all need to take a moment to express our gratitude for the cypherpunks and that movement in the 90s. [41:47.500 --> 41:56.800] And like Michelle said, I mean, we're, like, quite literally, we are here today talking about this because of them and their work and these strong privacy tools that they created. [41:57.300 --> 42:00.280] Like, we all use these every day in all of our apps and software. [42:00.280 --> 42:03.600] I'm sorry, we're using the technology to swap pictures of monkeys. [42:08.380 --> 42:09.380] Where did I want to go? [42:11.440 --> 42:12.980] I think we're at Q&A last time. [42:13.000 --> 42:14.620] Yeah, almost, almost, yeah. [42:14.620 --> 42:16.380] We'll do Q&A shortly. [42:17.680 --> 42:21.220] I think you had one or two... [42:21.220 --> 42:22.940] Oh, sorry, zero-knowledge proofs. [42:23.000 --> 42:24.460] We've talked about zero-knowledge proofs a bunch of times. [42:24.860 --> 42:30.740] I think it might be worth just digressing just for a moment to briefly talk about what a zero-knowledge proof is and what its application is in privacy. [42:30.860 --> 42:33.580] And this is another topic that we can discuss more during the workshop. [42:34.900 --> 42:35.740] Oh, my gosh. [42:36.460 --> 42:37.500] We'll keep it simple for now. [42:37.580 --> 42:38.900] I have a cryptographer friend in the audience. [42:39.060 --> 42:40.060] Pull her out, Ying Tong. [42:41.800 --> 42:51.400] I think the short of it is how do you prove to somebody that I have the money I say I have without disclosing who I am, what I have, and who I want to send it to? [42:52.540 --> 42:56.220] And it's a lot of math, which I'm not very familiar with. [42:56.380 --> 42:56.820] Moon math. [42:58.040 --> 42:59.800] And that's the power of it. [43:01.580 --> 43:02.960] I can't really say more than that. [43:03.220 --> 43:03.980] Yeah, I think that's accurate, right? [43:04.080 --> 43:15.980] So it allows someone to assert knowledge of or sort of custody over a particular piece of information without revealing anything else, like no metadata whatsoever. [43:16.220 --> 43:28.900] And so I think the best sort of simple example of this is, like, let's say you want to, you know, go to a bar and the bouncer at the door asks you to prove that you're over age 21 in this particular jurisdiction. [43:29.460 --> 43:30.420] And what do we do now? [43:30.420 --> 43:33.020] We have to hand them, you know, this piece of plastic that has our name on it. [43:33.080 --> 43:33.820] It has our address on it. [43:33.900 --> 43:34.560] It has our birthday on it. [43:34.620 --> 43:35.280] It has our photo on it. [43:35.380 --> 43:36.000] Like, all this metadata. [43:36.580 --> 43:37.340] And it's actually funny. [43:37.480 --> 43:40.160] I have a friend who actually did this. [43:40.160 --> 43:45.440] She had her ID and she actually taped over everything. [43:45.600 --> 43:46.860] This is basically a driver's license, right? [43:46.920 --> 43:49.760] She taped over everything on it except her face and the birthday. [43:50.420 --> 43:53.620] And would hand this to people at bars because she didn't want to leak metadata. [43:53.800 --> 43:56.140] And it was such a beautiful metaphor for a zero-knowledge proof. [43:56.600 --> 44:01.840] Technically, it's not zero-knowledge because, like, because her birthday's on there and her face is on there, right? [44:01.900 --> 44:10.660] So really a zero-knowledge proof would be a cryptographic piece of data that says, I am at least 21 years old and says nothing else whatsoever about the bearer of that information. [44:11.020 --> 44:24.160] And that sounds too good to be true, but, like, actually this is a technology that, you know, emerged in the 90s, I think, and really has found footing in practice in a number of cryptocurrency-related applications the past few years, which is really exciting. [44:24.340 --> 44:27.480] And we've just begun to see, I think, what this technology is capable of. [44:27.580 --> 44:28.760] It's not the only one, though. [44:30.260 --> 44:34.360] People have different views on it, but trusted execution environments is another way people... [44:35.520 --> 44:38.560] secretly attest to certain transactions. [44:39.300 --> 44:49.040] It's where data is...my transaction is encrypted, I send it to a secure computing environment, and the final output is then sent out publicly. [44:49.600 --> 44:57.360] So technically, people believe...some people believe it's secure, some people believe you have to trust the hardware manufacturer, but that's an alternative approach. [44:57.440 --> 44:59.980] Although zero-knowledge is the more predominant approach today. [44:59.980 --> 45:11.520] I think one thing I wanted to say also about using privacy is there is, I think, a risk of...I don't know what the right word is, but maybe tainting yourself. [45:11.800 --> 45:19.980] It's almost like if somebody sees, oh, you were using a privacy service, okay, that's suspicious, I'm going to target you just because of that. [45:20.100 --> 45:28.360] And I think that's a real risk if, as a society, as a community, we don't be louder about why we have the right to privacy. [45:30.240 --> 45:32.200] Yeah, that's a super important point, right? [45:32.360 --> 45:36.520] Privacy only works when it's something that we all adopt, right? [45:36.600 --> 45:40.360] So that the people who need the privacy can hide in the crowd, figuratively speaking. [45:40.940 --> 45:44.620] And so even if...just going back to this initial question we asked, which is, why should I care? [45:44.620 --> 45:45.600] I have nothing to hide, right? [45:45.620 --> 45:50.180] This is what so many people say when you ask them, you know, to care about privacy. [45:50.900 --> 45:59.920] Even if you have nothing to hide today, well, first of all, you may have something to hide tomorrow, because who knew a month or two ago that searching for an abortion clinic, you know, could get you in trouble in certain places. [46:00.540 --> 46:09.680] But even more to the point, right, there are people among us in society who need us to care about privacy because they're doing important work. [46:09.940 --> 46:11.100] So I think that's an important point. [46:11.140 --> 46:19.180] But beyond being an altruist, I think also there's something inherently that feels manipulative about the nothing to hide argument. [46:19.180 --> 46:23.840] It's like, oh, well, you know, I'm going to put you in a spot and accuse you of having something to hide. [46:23.980 --> 46:26.280] But I think we should flip the narrative around to... [46:26.280 --> 46:26.300] Right. [46:26.300 --> 46:28.660] The burden of proof is on you. [46:28.860 --> 46:31.840] We should actually ask, why do you want to know? [46:31.960 --> 46:33.000] Why are you being such a creep? [46:33.880 --> 46:37.580] I think that's...for me, that's how I would flip the narrative. [46:41.250 --> 46:44.030] Anything that helps move forward privacy by default? [46:45.690 --> 46:47.310] Okay, so we'll go to Q&A in just a sec. [46:47.430 --> 46:49.950] I think the last topic I wanted to ask about was case studies. [46:49.950 --> 46:53.410] You began to talk a moment ago about mixers and people being de-anonymized. [46:53.570 --> 46:55.930] I think you had one or two you wanted to briefly share about. [46:56.070 --> 46:56.270] Yeah. [46:56.970 --> 46:58.930] I'll treat them both together. [46:59.310 --> 47:02.950] And at a high level, the problem space is... [47:03.690 --> 47:06.350] In 2016, two major hacks happened. [47:06.950 --> 47:10.650] One, the hack of one of the largest exchanges then called Bitfinex. [47:11.550 --> 47:17.190] The exchange ended up having to haircut all their customers by 36% because of that. [47:17.190 --> 47:18.910] Essentially, a lot of Bitcoin was stolen. [47:20.190 --> 47:27.950] And another one, the DAO was a decentralized VC organization that did an ICO in 2016. [47:28.390 --> 47:32.270] And they were hacked as well for a lot of ETH, a lot of Ethereum. [47:32.730 --> 47:41.310] And at that point, the stolen Ethereum was 5% of all ETH in existence and famously led to a fork in Ethereum. [47:41.930 --> 47:46.010] And the Ethereum we see today is a V2 because of that fork. [47:46.470 --> 47:49.710] And the first two... [47:50.310 --> 47:53.230] The two people behind the first hack have been apprehended. [47:53.610 --> 47:58.790] This was reported in February this year, so five years afterwards. [47:59.270 --> 48:05.670] And then the other one, there's a suspected person, but nobody has been arrested yet. [48:05.670 --> 48:17.390] And the few factors that led to their arrest or suspicion have been, number one, the on-chain analysis we've been talking about on this panel. [48:17.510 --> 48:18.710] On-chain forensics, yeah. [48:18.750 --> 48:18.990] On-chain forensics. [48:18.990 --> 48:19.810] Pretty exciting stuff. [48:20.030 --> 48:20.210] Yeah. [48:20.530 --> 48:30.770] There's a central concept called clustering where if you see certain behaviors of how Bitcoin or Ethereum are moving around, you can make certain deductions. [48:30.770 --> 48:33.170] So that's one vector. [48:33.450 --> 48:35.590] The other vector is behavioral analysis. [48:35.850 --> 48:36.950] We talked about timing. [48:37.270 --> 48:43.990] If you do your transactions from 9 to 5 New York time, people are going to guess where you live in this world. [48:44.330 --> 48:51.770] The other plain and simple legal subpoenas of exchanges where most of them you do have to KYC with. [48:52.670 --> 48:55.170] And subpoenas also of ISP providers. [48:58.410 --> 48:59.710] And what was the fourth? [49:01.790 --> 49:03.750] I forget the fourth, but come to the workshop. [49:05.150 --> 49:05.590] All right. [49:05.750 --> 49:06.770] One final plug. [49:06.890 --> 49:09.010] So 7:30 p.m., the fourth floor of the main building. [49:09.230 --> 49:13.090] We'll do a workshop where we'll, among other things we've talked about, we'll also go into these case studies in more depth. [49:13.170 --> 49:14.490] I think we have a couple of other case studies, too. [49:15.270 --> 49:15.730] All right. [49:15.850 --> 49:21.310] Any final words on cryptocurrency privacy best practices before we go into Q&A? [49:21.390 --> 49:21.570] AB? [49:23.090 --> 49:23.490] Yeah. [49:23.850 --> 49:27.210] It's, you know, absolutely, you know, more than anything. [49:27.330 --> 49:33.210] I think especially for us as, you know, hackers and enthusiasts of technology. [49:33.430 --> 49:37.810] It's just, you know, yeah, doing the work and practicing just for fun. [49:37.970 --> 49:48.270] You know, how can you use something extremely privately and try and, you know, form a group with your friends and see if you can de-anonymize transactions with basic tools that you can learn very, very quickly. [49:49.510 --> 49:55.770] It's incredible how much data we voluntarily offer to, you know, anybody who wants to listen on the Internet. [49:56.070 --> 50:01.330] So, yeah, minimizing that just for the purposes of, you know, education. [50:01.650 --> 50:09.030] And through that education, I think a lot of people realize, like, oh, wow, like, this is something that's worth spending some more time on. [50:09.170 --> 50:12.570] So, yeah, that's what I'd like to convey. [50:13.930 --> 50:16.530] I'm not a hacker, so I think... [50:16.530 --> 50:18.090] You're at this conference that makes you a hacker. [50:18.850 --> 50:20.210] I'm a side channel hacker. [50:22.010 --> 50:26.310] I think the most powerful way some of us can contribute is on narrative. [50:27.250 --> 50:33.090] You know, go out there, talk to people, talk to the people in charge, talk to people who create products. [50:33.090 --> 50:42.610] When you make it clear to them that you care about privacy and you are not a criminal, I think that helps change the narrative tremendously over a long enough period of time. [50:44.210 --> 50:44.690] Awesome. [50:45.750 --> 50:56.650] I guess my final thought would be that privacy is something that matters always and everywhere, which we've mentioned, but also kind of, like, has implications up and down the software stack. [50:58.210 --> 51:08.630] So, we as developers, me as a core developer, as a protocol developer, like, you know, there are things that we can do at the layer one of a network to assist with privacy. [51:08.870 --> 51:17.630] So, like, for example, there's a technique called dandelion routing that can be used to kind of route transactions through a network in such a way that it hides the original source of that transaction. [51:17.630 --> 51:19.350] Something else we'll talk about this evening. [51:20.590 --> 51:25.410] And then there's, again, like, you know, there's, like, the application layer, things like wallet software. [51:25.570 --> 51:36.770] Like, I think a lot, as I mentioned earlier, about how it can be made more user-friendly and how we can push software forward in such a way that, like, we get sort of strong privacy or pretty good privacy. [51:37.150 --> 51:38.670] Ha, ha, ha, right, out of the box. [51:39.390 --> 51:41.350] But a lot of work remains to be done there. [51:42.550 --> 51:44.290] And, you know, educate yourself. [51:44.470 --> 51:45.490] I guess that's the final message, right? [51:45.490 --> 51:54.390] Because all of these tools, like, by far, by far, by far, the biggest issue that happens that results in loss of privacy is user error. [51:54.470 --> 51:58.350] And people kind of not caring enough or kind of not understanding the technologies they're using. [51:58.510 --> 51:59.730] So, yeah. [51:59.850 --> 52:00.730] I mean, we're here. [52:00.850 --> 52:01.490] We're having this conversation. [52:01.490 --> 52:03.030] So that's a good step in the right direction. [52:03.890 --> 52:04.490] Okay, yeah. [52:04.630 --> 52:05.710] I think we have a few minutes left. [52:05.750 --> 52:07.510] So I think we'd love to take questions if folks have questions. [52:07.710 --> 52:08.630] Thank you so much for listening. [52:19.460 --> 52:20.560] How do the questions work? [52:20.680 --> 52:21.520] There's, oh, no questions. [52:21.760 --> 52:22.320] We don't have time. [52:22.320 --> 52:24.000] I saw some at the back. [52:25.720 --> 52:26.020] No? [52:26.200 --> 52:26.680] No time. [52:26.920 --> 52:28.240] Yeah, because we're supposed to end at 15. [52:28.340 --> 52:28.800] Ah, okay. [52:29.040 --> 52:29.240] Sorry. [52:29.320 --> 52:30.480] We went a little bit later than we expected. [52:30.640 --> 52:30.760] All right. [52:30.840 --> 52:31.200] Thank you, guys. [52:31.280 --> 52:32.380] We'll see you at the workshop this evening. [52:41.590 --> 52:41.890] Okay. [52:42.850 --> 52:44.770] Our next speaker will be coming up shortly. [52:44.970 --> 52:47.990] And just as a reminder, please stay hydrated. [52:48.330 --> 52:51.530] Again, that cannot be overemphasized on a day like today. [52:51.530 --> 52:51.550] We're going to add the celebration as a song. [52:51.570 --> 52:51.590] Bye. [52:51.690 --> 52:51.710] Thanks, everybody. [52:51.910 --> 52:51.950] Have a great day. [52:52.410 --> 52:52.450] Thank you, everybody. [52:52.450 --> 52:52.470] Bye. [52:52.470 --> 52:52.490] Bye.