We Built the Wrong Internet. Rob Knight 0xPARC
Ethereum Cypherpunk Congress 2026·Ethereum Cypherpunk Congress·Wed, Sep 9, 2026, 12:00 AM
Speaker
Can privacy become the default instead of an afterthought? Rob Knight (0xPARC) explains how programmable cryptography and zero-knowledge proofs can transform the way we build software, making privacy, integrity, and trust foundational rather than optional. We discuss zero-knowledge proofs, programmable cryptography, digital surveillance, why "nothing to hide" is the wrong question, and how privacy-first technology can give people, not corporations, control over their digital lives. Timecodes 00:00 Introduction 00:12 What is 0xPARC? 01:58 Why programmable cryptography changes everything 03:30 Why privacy should be the default 06:13 Today's biggest privacy threats 07:13 Privacy tools everyone should use 08:43 Why "I have nothing to hide" is wrong 10:52 A vision for a privacy-first future 12:29 Transparency for institutions, privacy for people -- This conversation is part of Privacy Academy Interviews, a peer-to-peer knowledge project exploring the most important ideas in Web3, privacy, and digital freedom. Learn more: https://academy.web3privacy.info A W3PN Media House production. Directed by Federico Marchi https://x.com/BabyBitProd Interview by Peter Farbey https://x.com/0xfarbey Let privacy be with you!
Transcript
Hi, my name is Rob Knight. I'm a research engineer at Zero X Park. I've been working on zero knowledge proofs and related technologies for about the last 3 years. Previously on the Zcash project and the Pod project and most recently on Pod 2, which is a next generation recursive zero knowledge proof system. So, Zero X Park is a focused research organization working on a sort of applied research in programmable cryptography, which is sort of a new generation of cryptography, which is not focused just on encrypting messages or signing messages, but is about being able to perform programmable operations inside encrypted containers.
So, we can take private data and generate proofs about that data that can be shared with people and the output of that proof, like the the the the the claim that is being justified by that proof, can be completely trusted even though the recipient didn't see the underlying private data. This is zero knowledge proofs. There's also things like fully homomorphic encryption, which allows for computation over encrypted data where the person or entity performing the computation can't actually see the data they're computing on, but can take data from multiple participants and then compute things like averages or or statistical measures of that data and then share that with the the people who participated. And [snorts] we've been particularly focusing on the affordances of this kind of cryptography for software engineers, for people building systems in the real world, and how this can be operationalized in a wide range of applications. So, going beyond just uh but also into, you know, all kinds of everyday applications that people can run on their computers, on their phones, uh and that can solve real problems for businesses and and and people alike.
So, I think there's the sort of perennial challenges for any computer system, which is, you know, can you make it faster? Can you make it cheaper? Can you make it more efficient? Uh and those things we see obviously, you know, annual improvements. People figure out new techniques.
They figure out new ways of of doing things. The challenge for us is in some ways more conceptual, which is to try and understand what new possibilities this technology opens up. What are the new categories of things or the new ways of thinking about uh computing that are opened up by this technology. And this is where privacy I think has a really interesting role in that in that picture, because it's it's a fundamental assumption uh for cryptography that you have privacy, but well, you know, in our experience, privacy on its own or privacy as a kind of add-on is not sufficient to to build a whole system. So, you need these other aspects.
You need integrity, composability, interoperability. Um and if you can build those features into a system that has also privacy as kind of the default assumption, data is private by default rather than kind of private in the form of being hidden or as a kind of opt-out um thing, then you can build you can architect your whole system with privacy kind of baked into the the fundamental uh basis of the of the design. So, I think there are two reasons why privacy is important or two ways to think about privacy being important. And one is just all the ways in which not having privacy can be harmful to you. You can lose control of your private data.
You can be spied on. You can be, you know, manipulated in various ways. You can be observed and tracked. And even if you trust some of the entities that have that data, there's always a risk that they won't be able to keep that data safe and secure. And so you're opening yourself up to risk from criminality, from you know, just you know, the exploitation of that data by people who do not have your best interests at heart and who would like to exploit that to control or influence or manipulate you in in various ways.
I think there's another sense in which privacy is important. And to me this as somebody who's in my mid-40s now, you know, I remember a time when my computer was a box on my desk and I would type into that box and what happened in that box stayed in the box. And if I switched the box off, you know, that data would go silent and everything would be um would be there when I came back to it. Now we live in this very connected world where data is not private by default with the systems that we built in the last 25 years. Um my computer is in a sense not really a box that lives on my desk.
It's a kind of amalgamation of cloud hosting and services that are provided to me by third parties who assume that they have a right to see all of the data that flows through their systems. And so I feel like privacy has this um kind of emergent property that that that privacy emerges from the relationships between people and their computing devices. And I would like there to be without this being a big, you know, a big a major kind of political point or a major point about, you know, how we organize society, just a default assumption that like if something doesn't need to be shared with somebody else, if there's no real reason for anybody else to have a copy of this thing, then I should be the only person who has a copy of it in much the same way as as would have been the case 30 or 35 years ago when you again, you know, I edit my documents on my computer on my desk and nobody else needs it's no big deal. Nobody else needs to see that. It's just not relevant to them.
And so I think if we could go back to a world where the default is privacy just because there's no need for other people to have that information, we cut out a whole range of of risks and and problems. I think now we're in a world that's just very It's very very clear what the risks and problems are. I think ordinary people experience much more the risks of things like identity theft um that would have been a very strange idea in the early '90s. Uh you know, it would have involved forging paper documents and and all of these kinds of things. Now, we're in a world where fake data is trivially easy to produce, where voices can be faked, video can be faked.
Um all kinds of personal identity documents can be trivially uh manipulated or or or forged. And so we're in a world where the risks are actually just much higher for ordinary people. And so having control, having integrity, having privacy is something that affects everybody and it's it's not something that only a few kind of weird ideological people think about. It's something that everybody has to think about. I think it's uh it's important to to recognize that um actually in the past people thought there was a kind of trade-off between privacy and and usability that um you know, a private tool sort of was was just a was a kind of clunky weird thing that you had to be a kind of bit of a privacy nut if you if you wanted to use that.
Um but if you use something like Signal, for example, that is as easy to use, it's as good, it's as as high quality as um Telegram, for example, um but private by default. Your messages are not being collected somewhere and read and analyzed by anybody. They're being read only by the intended recipients and I think that that's a really good example of how modern privacy conscious applications can work. Beyond that, I think you need to think very carefully about about sort of what you have as your fault. So, if your default collaboration tools Google Drive for example, Google Docs, that is going to be seen by Google and maybe you don't need that.
Maybe you can use an an offline word processing package and share that document with someone else. Maybe you can use you know, encryption to share certain pieces of information with only a small number of intended recipients rather than sharing it with your cloud hosting provider. So, yes, so people do say if if you have nothing to hide, then why do you care about privacy? You know, you're not worried about anybody finding out what you're up to. Well, I think that's a naive way of thinking about things.
There's lots of things that we do every day that are perfectly innocent things and we're not trying to hide anything or we're not trying we're not ashamed of what we're doing, but we don't need we don't want people to know our financial transactions. We don't want people to know who we're talking to. We don't want people to know intimate conversations that we are having. Again, not that anything illegal or immoral or anything shameful is is happening in those conversations, but if they can be observed by other people, maybe that's used to market products to you. Maybe that's used just to collect and and build a profile, and you don't know when that profile will will be used or what it will be used for.
If you have friends or family or children, for instance, the profile on you could be linked to a profile that's being built for them, and information that you've disclosed that you thought was perfectly innocent and and harmless could be used to, you know, build profiles or to to market things or to influence other people uh who you are connected to, your friends, your family, you know, children, etc. in ways that you just couldn't possibly have imagined. So, again, this is the reason why privacy as the default makes so much sense, that you don't have to think about um oh, well, what do I mind if anybody sees this piece piece of information? Do I mind if anybody sees that piece of information? With privacy as the default, you just don't have to think about that at all.
Nobody sees anything unless you choose to share it with them. And that puts you in a position that of much more control, much uh greater peace of mind. You don't have to worry about what might happen at some point in the future that you can't anticipate. You know that the communications that you've made, the actions that you've taken, are private. So, for me, the the utopian outcome here is that we um we actually flip the entire relationship of observer and observed uh around.
We're in a situation right now where we have large, powerful entities that want to observe and track uh people so that we can so they can market to us. Uh what we want and what we don't have is the inverse. I want to know what the businesses uh that I'm dealing with are doing. I want to know what's going on in their supply chains. I want to know what's going on in their environmental policies.
What's going on in in how they treat their workers. And so, there is a need for information to be gathered. There is a need for information um to be shared, but the direction uh of travel that we that we have right now is that we should uh by default are opted into sharing everything with people who are not sharing anything with us. So, I think we want to see a world where ordinary people feel empowered to make choices in their own lives that align with their own values uh and that are theirs to make. And when they do so, they're free from influence.
They're free from surveillance. They're free from uh that becoming part of some permanent record or or profile that's being kept about them. I think that flipping around that turning around of that relationship is fundamentally what we can have with particularly with programmable cryptography technologies where we can build in those rules and those structures into the nature of the interactions that we have with with our counterparties. When we deal with a company, uh we can require proofs from them rather than them requiring proofs from us. And I think this is um something that is is a reorientation or a reframing of of this question away from proof good or bad to to the question of who is proving what to whom and why.
And so, privacy I think for private citizens um is something that we really want. I think for um for sort of large entities, corporate entities, institutions, we want yes privacy for the individuals working in those uh in those institutions, but as institutions, we want integrity. We want transparency. We want those guarantees. Again, only the information that is needed should be shared.
But I I do believe that we can have a world where these technologies facilitate better governance, better decision-making, a better and more freedom for individuals rather than the current situation which is very much the alternative.
Automatic transcript — names and jargon may be misspelled.