New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Vitalik Buterin Q&A Session | Web3Privacy Now - Tokyo Meetup 2025

Ethereum Cypherpunk CongressThu, Oct 9, 2025, 12:00 AM

Speaker

Ethereum Foundation · 24 talks

Vitalik Buterin (founder of Ethereum) in a Q&A Session during our W3PN Tokyo Meetup. Useful links: Web3Privacy now collective: http://web3privacy.info Web3 privacy market dashboard: http://explorer.web3privacy.info Cypherpunk Congress: http://congress.web3privacy.info TIMECODES 00:00 Intro 00:00:42 - Privacy from business perspective vs civilian perspective, what are your thoughts on that? 00:07:23 - So you've worked on economic incentives for about 10 years now and very successfully. How do we economically incentivize people's participation in privacy? 00:12:19 - So, what do you think that privacy on Ethereum, will enable use cases that are typically relegated to more like darknet market ? 00:14:16 - What are your thoughts on the EIP 7503? 00:16:35 - If you're making the L1 with privacy proof for that matter, how would that affect current L2s focusing on privacy to resolve that issue as in projects like Aztec, like Coti? 00:18:47 - Has the Ethereum Foundation made investments into L2s? 00:28:07 - At Zuitzerland earlier this year, one of the researchers of EF proposed that EF would have about four years of runway left currently. Well, will Ethereum be finished in four years? 00:29:58 - What are your thoughts on Peter Thiel, a.k.a. the founder of Palantir? Can you tell us about the role of the Thiel Fellowship's founding in the theory? 00:33:11 - Cypherpunk as an ethos has been around for 30 years. What does the Ethereum ecosystem can add to that, given its current developments? 00:43:25 - What do you think about one-chain analysis tools and also trap-rule calls? 00:47:09 - Any insights on building asset treasuries on chain? 00:55:16 - Bringing more money on-chain is a problem? 00:57:36 - We've built economies around proof of work and proof of stake. But what about proof of feeling or proof of ache or proof of aliveness? 01:03:48 - Negative incentives, thoughts. 01:10:26 - I'm trying to establish a new health standard where patients control their own data, but governments can still use it for training AI models. How do you see Ethereum privacy technologies helping to achieve that balance? 01:14:30 - Cypherpunk, what do you think the cryptocurrency space or the web3 spaces is bringing to the table? 01:17:34 - What is your view about having a black logo, the black Ethereum logo, meaning privacy? 01:20:01 - Expectations of the Hackathon EthTokyo, as a final question.

Transcript

[Music] I think our first guest doesn't need an introduction, but welcome. Thank you for joining us. Um would do you have some opening thoughts you'd like to share before we get into specific questions from the audience?

That is a vague question. Uh how about you how about you ask the question and I'll share my opening thoughts about it in response.

Okay,

fair enough. Um

okay, I have one I I was um I had my own mind on. I watched your talk um in Berlin at the privacy hackathon. Thank you for that. Mhm.

One of the things mentioned there was the uh current divide between focus on privacy from business perspective and privacy for civilians.

What are your thoughts on that and the efforts being taken for that in the Ethereum ecosystem?

Yeah. And so I think uh privacy is an interesting space because it uh combines a lot of people who care about privacy from a lot of different angles and often uh have a lot of thing different things in mind in terms of like what specific uh properties they want like what kind of data they're protecting who they're okay with seeing that data what kind of level of guarantees that they want and uh like you have individuals that are motivated by like various different different considerations, sometimes ideological, sometimes practical. You know, you have institutions motivated sometimes by their own interests, sometimes to satisfy some kind of liability or compliance related requirements. Uh then uh you know, you have uh governments that sometimes also care about keeping their data private from each other, right? And like these are all very different types of uh users, right?

And uh what we've seen in the privacy spaces so far, right, is like there are a lot of people in the enterprise world who care about some kind of privacy, right? And uh like the the like Nightfall and all of the efforts from EY have been I think excellent projects and you know they uh are just one example to show how much uh how much interest there is and even if we go beyond crypto there's a huge amount of interest in uh all kinds of uh privacy protection but then at the same time like uh I guess the two sort of uh you know concern you you could call concerning factors uh I'm not exactly sure what the right word is that one of them is uh that uh like there's this disjointness between the two ecosystems and uh and then the other one is that uh like the thing that they want and I think the thing that a lot of people here want is like not exactly exactly the same right like what we like the kind of uh privacy that uh you know an an enterprise gets and that it gives to its own users is different from the kind of privacy that like for example like a VPN is trying to provide right and uh it's uh and then there like one one aspect of it is like what level of privacy right so a lot of the time when you talk to enterprise-based projects like they're explicitly okay with uh certain kinds of back doors because uh the thing that they want is like only we can see our customers data or like oh well we know we have to give data to the government for some compliance reason but we want to keep data private from everyone else. Um but uh for consumer privacy use case like a lot of the time not having back doors is the whole point and uh and I would even say that for the first category of uh of use case like a lot of the time the underlying problems can be solved without backd doorors and can be solved with like more clever things. I mean either privacy pools type ideas or like ways of zero knowledge proving specific claims about yourself without revealing everything. Um the but uh and so like there is that uh like that reason for the for the separation between those two spaces.

I mean I think like to me the like the worst case outcome for me right is where you both have two different uh privacy spaces and at the same time the enterprise uh space kind of alone drives the agenda in terms of like what privacy actually means and what and what it is. Um and because I know like ultimately privacy is a a thing that has a lot of different constituencies and um I think uh there's like all kinds of different pe different people's needs need to be respect needs to be respected and catered to and catered to in a way that doesn't uh like enshrine in inst um in institutional actors in in situations where that's not necessary. Um and the uh and then uh the uh best case outcome I think is where the u kind of direction of influence goes the other way right and uh all kinds of privacy technologies that we develop here actually start making their way up up and even influencing how institutions operate and then at the same time while that whole process is happening there's a cooperation on technology going on and so like there's a lot of effort from both sides coming toward improving the the things that everyone does agree on which is the the core building blocks right and uh there's a lot of effort that needs to go into like making zero knowledge proofs better making fullomorphic encryption or obfiscation better um even uh and I think uh more divergence on some of the consumer level problems but also still quite a bit of overlap there, right? And I think even uh on the security side, like what we've seen with like more and more secure elements and different kinds of phones, like that's uh not that wasn't really done with crypto people in mind, but it's definitely been helpful to crypto users, right? And so I think there's a lot of opportunities for things like that to happen on the um on the privacy side.

Yeah. So I see them as uh I like I see these as ecosystems that can and should be cooperating a lot but also we should keep in mind that it's not the same ecosystem.

Yeah.

Yeah.

Like I have a list of prepared questions but

also it's a Q&A so I'm assuming you have some

burning questions somewhere in mind you'd like to ask about it. You have the chance. Yeah. Wake up. All right.

Hi Dalik and from the right privacy foundation. Uh so you've worked on economic incentives for about 10 years now and

very successfully.

How do we economically incentivize people's participation in clubs?

It's a very broad question but 35 some thoughts

I mean liquidity rewards.

No just kidding. No, I think it's uh I I think that things like that could be useful as a short-term thing, but obviously yeah, like on net rewards and fees have to sum to zero, so you can't be rewarding everyone. Um I mean to me the the more important like the mo the most important variable is reducing the cost, right? because uh if the cost is reduced then uh like like if the cost is reduced to the point where it's negligible then people will use the private thing and uh I mean HTTPS is a great example of that right and so when I look at uh like I think uh like the the question of why isn't there more volume in privacy protocols like the the right question to ask is not why are people not putting more more money into privacy protocols it's why are you not putting more money into privacy protocols Right. And so like for me personally for example the the like the probably the biggest answer is kind of just like trust in technology right so uh like and then there's two parts to this right one of them is that you know there's zks are I mean they're definitely a less new thing than before but uh a lot of skeletons in the closet a lot of uh really complicated code And uh like I would not want to be in a position where if that complicated code breaks and then there's a soundness bug and like all my all my money disappears, right?

I'm okay with a with a a small portion but not all. And then the other one and this one is like I think actually solvable for you guys is uh multi-igs like I fundamentally do not believe that single key wallets should be supporting the the a safety dependency for the bulk of people's money. And uh right now in rail gun like uh you know there is one seed phrase and there's one computer that has the key. And so uh if uh and like my view in the long term is actually that this is part of why I've been talking about like the EVM moving to risk 5 so we can get to the point where like your uh public account and your private account are the same account and then you just uh zkrove EVM code that shows that you can control your public account. But while we're not there, just like explicit native multisig support like would uh actually improve things quite a bit for me, right?

And then uh yeah, so those are probably the two big reasons why like if you had to ask me like why I'm sto like why I don't have uh 10 times more money inside of a real gunpool right now, right? And I'd be curious to answer for other people like why don't you have 10 times more money in a real gun pool? Just if I would have 10 times more then maybe I

no why don't you have 10 times more than you have already or if what you have already is zero then you already have 10 times more than you have but

empty doc scripts there's a lot of cases where I could have had

actually it's a good question to ask also to you from fractton ventures later talk about

yeah the topic here

yeah it's a good answer Yeah. Who uh who else wants to shout out a reason why don't you have 10 times more of your money in a rail gun pool?

Opportunity cost.

Okay. Um what other things would are you doing with your money?

Other investments.

Okay.

Real estate.

Okay. Oh, I see. So, uh like outside of crypto things.

Okay. Mhm.

Um, who here has a reason why they don't have more of their crypto money in rail gun?

User experiment.

H

user experience.

User experience. Okay. Um,

the lack of assets like if you want to hold like

it's difficult to do because the privacy is going to be pretty

right.

It's just my like poly is not really privacy.

Yeah. lack of assets you said for the recording.

Yeah.

Yeah. So, I think it's a a combination of all of all of these things and I do think that like a large portion of them just uh like boil down to tech maturity and tech maturity is something that uh will continue improving over time.

S okay.

Okay. Who else? Otherwise, I'm just going to fire another one. We have one in the middle.

I'll repeat it for you.

Um, so to what extent do you think that uh privacy on Ethereum will enable use cases that are typically relegated more like darknet market like that market does?

To what extent do you expect privacy features on Ethereum to eventually

I mean it's an interesting question and it's hard to answer because uh but like if you compare Zcash and Monero for example, right? Like functionally speaking, Zcash is more private than Monero, but then like there's this social norm that Monero is where the druggies go. And uh I mean I think to some extent uh you like Zuko has never catered to to druggies and that has been has some like led to Zcash not really been um being a thing a thing there. So I think uh you know like social factors matter quite as much as technology but then I mean even social factors you know like Ethereum is a diverse ecosystem and there's L2s and so um and all kinds of different chains connected to it. So it's uh yeah like basically yeah to like when general purpose technology exists people uh you people can and will use it for general purposes but uh the uh exact details of uh like what gets used for what to what extent I think uh depend on a a lot of factors that go beyond the like whether or not the technology exists and like the whole Passion Monero thing is a a really good example there.

Is your question answered? Yes. Thank you.

Okay.

I see a hand in the back. Yes. Go ahead.

What are your thoughts on EIP 7503 and

the move to risk five and like trying to make it less likely that that ever

Okay. Um

that's on EIP75.

Yes. Okay. So EIP7503 is the wormhole EIP and what it is is it's a an a proposed L1 protocol feature where if you can there's a new transaction type where if you provide a snark that that is a proof that shows that you uh had previously sent ETH to an address where that address is uh unspendable and it and it commits to a value and you prov that that you provided an nullifier for then uh you can effectively like from Ethereum's perspective, get that like get get that ether back out of thin air. And like that basically is Ethereum baking in like explicit L1 privacy. And uh the it's an interesting idea.

Um the the reason why I'm like I'm against it short term is again basically tech readiness, right? because uh if the wormhole gets AP included like now then if there is a soundness bug then people will be able to print infinite money and we will not even be able to tell to what when that's happening right and that's like a really scary thing for a blockchain protocol and so I think to me like the lowerhanging fruit in uh expanding the privacy user set is like solving all of the UX layers other than uh you like the whether it's like enshrined or or a higher level feature, right? And so that's part of why, you know, the F has been getting more uh invol active in uh in wallets. Um it's uh also why we've been thinking about things like account abstraction and fossil and like with in the context of privacy protocols, right? And like that's the more kind of like short-term stuff.

And then you know like if we have an infinite level of uh trust in ZK technologies then like in principle I think uh I think wormholes are great but uh like it is the like the tech readiness thing is the issue right now. That's

so to add to that question, yeah, if

if you're making the L1 with privacy proof for that matter,

what would how would that affect current L2s focusing on privacy to resolve that issue as in

projects like Aztec, like COT,

right?

Yeah. I mean I think uh I mean realistically okay so I think uh priv like privacy for payments is something that uh like I think will be commoditized and should be commoditized right and uh it's uh something that needs to become a default part of the Ethereum user user experience that uh is just a natur part a natural part of people's workflow and is like not a like it it should not feel like an even partially separate EOS uh separate ecosystem. I think uh the place that's valuable for privacy protocols to shine is basically everything beyond payments, right? And uh this is where like rail gun has been uh doing a good job in terms of uh all of their private defy features. Uh I think Aztec has also been doing a good job there in terms of uh like because their entire thing is a privacy friendly smart contract programming language.

Uh I mean Inmax is uh I think it like the the value ad there is uh actually yeah well in that case it is payments focused but it's privacy on top of the extreme scalability that's uh enabled by their version of like the hybrid plasma technology. Um so basically uh like L like to me I think uh L2s should not be trying to just kind of like be branded shards of Ethereum L1 right L2 should be trying to like bring interesting things on top and I think uh a very similar thing is uh going to be true for private for private transactions as well here and you'll

know as here I think.

There we go. Untie

it. There we go. Yeah. Let's see if we can reach it.

Okay. So since you mentioned L2s as let's say um their own sort of things on top of L1 Ethereum I'm wondering about the perverse incentives within the investments of Ethereum foundation in L2s

uh that uh that lead to difficulties with L1 Ethereum scaling because

L1 Ethereum is in a way then not allowed to compete with the L2s.

Has the Ethereum foundation made investments into L2s?

Not okay. Not necessarily Ethereum Foundation but many people involved with Ethereum. many people move with leadership but many key decision makers in a way right

I would just like to open that topic

right okay yeah and I think uh it's yeah and it's definitely true kind of both like within the uh it's the privacy space and outside of it this is something that we need to look at I mean my way of uh approaching this is that I think the uh like the Like I don't think that we can or should rely kind of entirely on like people being pure and people not having all kinds of side interests because like side interests are just a very healthy thing for anyone doing technology to have and then those just inevitably yeah turn into other kinds of participation in uh various projects. I think uh the the solution that I favor is like being aware of the problem and uh at the very least the like making sure that we're balanced um in terms of what kinds of things we have exposure to, right? And uh like and I feel like our efforts at like for example being balanced uh been like having a balanced level of communication and like relationships with with different L2s has uh improved quite a bit compared to a few a few years ago. Um I mean of course uh you know there definitely is a level a point at where you just get to the question of well you know like what if a problem can be yeah solved like either with infrastructure or just without infrastructure at all by yeah the with through the L1 absorbing more functionality and uh that one uh like and I think the best answer there is like there will always be a subset of people who um either like have investments in L2s but still believe in the L1 first and foremost because despite that because because like ETH is their primary thing or people who just don't have any any connections to L2s or maybe they don't have connections to L2s but they do have connections to DAPs or maybe if we're talking about like say yeah something that DAPs like DAPs could provide versus L1 then like people who don't have connections to DAPS but do have to all twos or like there will be some people who uh don't have a conflicting incentive who are able to propose make a proposal and then uh if that proposal makes sense then uh like our ability to have technical uh uh debate within the IP process I think should be strong enough that like that argument wins and like the and people on on the other side like would not be able like if there isn't a good argument to not um expand like what what one can do then it should not happen right or or or as in if if there is not an argu if there is no good argument for uh for why like a particular form of uh expanding L1's capability is uh should uh should not happen then like that that form of expansion should just happen right and uh you know I I think we have seen a lot of willingness recently to increase the scale of L1. I think probably to the point to the point where like I'm definitely not worried about the L1 scaling too uh too little.

I am uh like I'm I'm also scared about the problem on the other side which is basically that uh you know people try wanting to meet the demands of an eager community but then uh like t taking corners on decentralization or taking quarters on deadlines um like like I think that you know if it has like if security demands that foraka comes in 2026 foraka should come in 2026 right like when enterprises talk about why they uh value Ethereum like they uh the thing that they always talk about again and again is the reliability of the chain right and that Ethereum doesn't go down right and so they you know like like the flip side is um like actually being able to value that right so like I guess to summarize the answer it's to me the solution can't come from like people being uh like everyone being pure and not having um interest. I think a solution has to come from having diversity within the ecosystem. So that if a uh if the right solution exists and there always will be people who are able to to come up with it and to champion it and we needs to have an environment where the approach that is better can win.

Thoughts on competition of the standards proposed in the ecosystem? Yeah, I think uh the answer of this depends a lot on like what specific standard we have in mind, right? Because uh like in the case of account abstraction for example, one of the issues is that uh like something like 4337 inherently has inefficiencies from the fact that it's a standard instead of a protocol feature and like the fact that it has this kind of like like it gets a lot of extra gas overhead as a result of that, right? And so the solution is to just make something inspired by uh ERC 4337 but more optimized uh a protocol feature. Sometimes uh like it is something that does not make sense to put into a protocol.

It just is a standards issue. In uh in that case I think uh I mean the Ethereum foundation for example has a few levers that we theoretically can use right. So one of them is uh funding and like for example paying for implementations potentially even paying for integration. um one uh and so far like our funding has been almost entirely focused on uh like L1 client development but uh being more active in the ecosystem is uh something that the that theoretically could happen right and I think in uh like we've started uh recently or early in the year we opened the DeFi treasury and still in the process of expanding that and so that's also a way for the EF to like support projects that actively follow um follow the I the EF's goals which include things like open source and privacy and security and also uh include standards compliance. Um then uh the and then also just uh so there's like supporting application layer and then there's just like writing code directly and uh reducing the cost for people to adopt things right and so this is uh part of where uh like we there's always this question of like how do you get people to adopt the private thing right and uh making it much cheaper both there's like transaction fee cheaper there's like cheaper for users is also just cheaper for developers like making it into a library is something the foundation can do and there is things like signaling and social pressure and uh like supporting L2B is one of the things that we've uh done in that regard.

Um and I think uh all of these different tools like they uh have to be used together and I think it's uh like it it it definitely is not an easy process but it's also not an impossible process. Um and also another thing is of course you know the EF itself having some aspects of uh infrastruct infrastructure that it's maintaining right so the GU client is one example of uh of that I mean uh also for like the wallet side for example right so I think uh you know the recent announcement started talking about kohaku and then also one of one but then the goal there is like not uh you know like win as a as a wallet but like more to demonstrate right and then alongside there's a the goal is to develop an SDK and then work with uh like any wallet that's willing to integrate any of the uh any of those features right so that's also a kind of cost uh like reduced other people's costs to do the right thing uh sort of approach um the Uh yeah. So I think it's a just a combination of all of those.

As you touched upon the EF and also the Treasury crash

um at Zwitzulent earlier this year, one of the researchers of EF

proposed that EF would have about four years of runway left.

Kirk

um well will Ethereum be finished in four years is one question. I so uh that was probably made one like what was the ETH price when that question got was made?

Yeah.

Yes. I think actually Yeah. Yeah. As of uh as of recently actually I think the the financial situation is very healthy. Um but uh like because our goal I think as we stated again in that uh uh treasury policy right is that uh like our our burn rate for uh I guess like kind of historically has been about 15% of our remaining funds every year right and that does not mean that we run out in 6.

67 years right because clearly Ethereum is more than 6.67 six, seven years old and we're still here. It just means like, you know, like whatever the amounts we had left, we'd spend roughly 15% of that. And so the foundation as a share of the ecosystem would decrease over time. And then in the policy, we basically said, well, actually, you know, we wants to decrease that spend as a percentage and go from the 15% uh a year model to like something closer to like like 5% which is standard for uh a lot of endowments, right?

endowments often spend like either four or 5% of their total assets every year and uh I mean the recent ETH price rises have definitely like really uh accelerated our path toward that particular sustainability milestone. Um, so I don't know I'm like I personally am like actually very confident there.

There was a question in the back.

What are your thoughts on Peter Teal aka the founder of Coward here in Can you tell us about the role of the Teal Fellowship's founding in Ethereum?

Thoughts on Peter Teal? Yeah, I mean, you know, he uh funds a lot of technologies, some of which is uh the surveillance technology of the type that we're all trying to protect ourselves against. Uh so, uh yeah, you know, it's a a lot of concern there. Um the Peter the fellowship is interesting. I mean because you know I ended up getting it you know like after Ethereum started right and I think the you know the money is like at that time like helpful though already not life-changing for myself.

I think uh the intent of it was of course uh like more for people in the kind of more average positions where they're doing something in university that was like like they're in university but they're doing an interesting thing and then uh like they uh at that time it was not even just about the money. It was like about the kind of legitimacy signal, right? like uh especially toward a lot of like people like kids whose families come from more traditional cultures like uh they get a lot of social pressure to not do anything unconventional and if you tell them you're dropping out of school they're like whoa like and uh uh basically scared that you're bringing the you know like the family back into extreme poverty and uh just like the positive signal of like oh Mark Zuckerberg dropped out and like oh um like in this case it was like the Teal Fellowship just being a respected institution and like offering something that looks like a credential. It's like actually meaningful in that way. But then since then 10 years have passed, right?

And like startups are not a rebel thing to do. And even dropping out of school is not like that rebel a thing to do anymore. I mean, who knows? Maybe the way things are going now, the real rebel thing is going to be to like to stay your whole life and contribute to academia, right? Um but uh yeah I mean since then I think you know like everything the whole kind of like map has uh reshuffled by such a a such a huge amount and like those earlier winds of uh just uh things like dropping out of school and doing your own thing being legitimate and like working on radical technology being legitimate like I think uh like we've In in a lot of ways, uh like th those battles have been won and the battles that we have this decade are are different and uh like preserving individualism autonomy and and dignity and privacy in the context of technology that will accelerate realistically whether we like it or not is a really big uh and important one.

So you know happy to be here with a group of people that's focusing on that

from our colleagues at web privacy

as we're organizing the cipher congress later this year

like cypher as an ethos has been around for 30 years

what does the etherum ecosystem can add to that

given the its current uh development to the technology

yeah so I think at the beginning the core of the the of the answer like from was just like raw volume of resources, right? Like if you compare things like Bitcoin and if you compare like for example even like diaspora like remember like the the alt Facebook that launched way back in 2009, right? Like all of these things they and then like I2P tour they all came from you know like roughly the same kind of you know a cryptoarctic social bubble, right? And the reason why crypto pulled ahead is basically that crypto makes you money, right? And uh this is both a blessing and a curse.

And uh I think we've seen plenty of instances of uh the curse play out over the last few years in all kinds of contexts, right? And uh I know I think uh like we've uh a lot remember you know like Bitcoin Bitcoiners writing think pieces about and being excited about like political adoption of cryptocurrency and like we've seen political adoption of cryptocurrency and it's like not great and uh the um and so but then at the same time right like the cryptocurrency space basically is the thing that was singlyhandedly responsible for funding I think programmable cryptography to the point where it's like actually viable right and like that's a big win and that's a big win that a lot of people outside of the crypto space will uh be able to benefit from um I think the crypto space has also really brought together and maintained a community of people who care about those goals and who work together toward those goals. Um it's uh it has created like motivating use cases for people to to to work around and to um like put put all these things together into some like into something that's uh more practical. Um I think I would say yeah going forward into the future I yeah I mean I do think that uh and the I mean the cipher punk ethos is important and I also think it uh it it needs to evolve and adapt and like make sure that it uh continues to be uh to be useful and uh like pushing in the in the right interactions in the context of the kind of world that we're in right now, right? And there's a lot of these uh like very subtle uh differences between the world now and the world 30 years ago, right?

Like uh I mean if I had to just like list a few, right? like 30 years ago the uh you know the the slogan you know on the internet nobody knows you're a dog is like you know this uh beloved as this kind like slogan of how anonym like anonymity is this uh force that brings freedom right but then now basically if no the problem is if nobody knows you're a dog then nobody knows you're a bot and then uh like you just have a whole bunch of you know like swap which we've been seeing social media collapse into and uh and so like even you know the privacy space like what is ZK? It's about hiding some information while proving claims about other information, right? And that's like a really powerful thing that people back in those days were not really thinking about in the same way. Um, another thing I would say is like the role of powerful institutions, right?

Because 30 years ago, uh, you know, governments were the weary giants of flesh and steel and, uh, they were perceived as an opposition and like I think they often should be perceived as an opposition. They do like really freaking scary things and especially the last few years. And uh they but in the 90s it was like an opposition where the main like wrong thing that they do is like basically being too decelerationist and uh now like governments do scary things but the scary things that they do have uh nothing to do with like being an anti-technology bureaucracy. I mean like okay there are a lot of specific contexts where anti-technology bureaucracy is like a really huge problem and like apparently yeah you know the US is going after solar panels now and like that's crazy um but they're but on like those guys are like are using technology and they are are are very sophisticated and like they are the ones that are create uh creating it right and so um also another one is like the need to think more explicitly about coordination, right? And to think about no like not just escaping other people's structures, but about creating your uh your own structures uh because that's just needed uh to do useful things involving large group large groups of people at scale.

So there's a lot of these uh I think shifts in philosophy that need to be taken into account. And then I also think uh like actually in here's one uh thing that I think uh is going to be important like a a full stack focus on things like privacy and verifiability and openness, right? Like uh you know your application is uh not safe if the npm dependencies are not safe. Therefore we have to fix the npm dependencies. Your application is not safe if the browser is not safe.

Therefore we have to fix the browser. your browser is not safe. If your operating system is not safe, therefore we have to fix the operating system. And like graphine OS is like used by major world figures trying to protect themselves. And uh somehow it receives uh like much less like funding or even or attention or even competition than like a single Ethereum client.

Um so and then if you go further down like one of the ultimate prizes is the hardware layer, right? Because uh none of these things are secure if there is a back door in the hardware, right? And uh

use a stack.

Exactly. Full stack and like also on the hardware layer thinking also bio biology, right? in biotech. Um and uh you know basically like at some point I think uh this whole like if you like you can't completely surrender the physical world because uh like there's all of these studies about how uh you like if you uh like you can uh intercept what keys someone is pressing from a from their keyboard from like a microphone three rooms away or like from light refractions, right? And uh like brain computer interfaces could fix that.

A lot of things could fix that. But then I mean brain computer interfaces themselves are going to be the ultimate privacy battleground, right? Um and uh yeah, if you like brain computer interfaces done wrong are um you know Mark Zuckerberg and Xihinping and Vladimir Putin all reading your brain at the same time, right? Um so that you know like we don't want that. Um we another thing I think also is that uh like very early stage cypher punk culture like I think it was uh in a lot of ways like very full-on oppositional right in the sense of like viewing the government uh entirely as uh um as an enemy in terms of like framing about the things as being like a a battle between against mainstream actors and like I think all of those people like like you definitely need strong counter pressures against those things, but at the same time like there's lots of people within all of those entities to like actually share a surprising number of all of those goals.

I mean even like being anti-government is uh famously popular among governments because uh you know every government really believes in this thing called sovereignty which means not having to bow down to any of the other 200 governments that are walking the face of this earth. So like data protection is uh something that is uh like valuable at every level right and then uh there's I think a growing realization that if there is a centralized database of everyone's information that centralized database will get hacked and then lots of other people are going to get access to that information. Um the whole also uh you know governments care a lot about protecting against privacy abuse from corporations and then similarly protect corporations often are uh a thing that you have to rely on to have a strong actor that's capable of counterbalancing the governments right and I think you know like Apple has done a lot of quiet good in uh that regard as much as at the same time they do a lot of other things that I really disagree with like uh you know the general kind of locks down operating system that they collect the 30% tax from thing. Um, so it's uh I mean I think having a more uh kind of nuanced like view of like how the cypher punk world kind of inter u acts on and interfaces with uh the rest of the world. And the idea of like being a strong counterbalance without being fully oppositional is uh also one of those uh things that I think is uh interesting to think about.

So I know long answer but uh Yeah,

we have a question in the middle. Yeah,

thanks for

uh what do you think about one analysis tools and also trap rule calls? What's the effect to the LQ space?

So AML as

yeah sure

um so and then the first part was chain analysis tools right which is like a bit of a a different question. Yeah, I mean I think uh I mean all of these uh legal requirements are going to continue to exist, right? And uh I probably new ones will keep coming uh keep coming up and uh I mean I feel like the best like the things that we need to do as a space are like one is just continuing to kind of fight the legal fight in terms of like at the very least keeping base layers and uh open source technology away from uh those kinds of requirements. And there's been like some positive updates in the US in that in that regard or at least either things that things that have happened or or some of the bills that are currently in progress which is uh good. Um and then uh you know like similarly continuing to you know like do what we you know what we can to support people uh go going against you know like chat control proposals in Europe for example.

Um and then the other part of the issue I think is that like the type of compliance that is like not like complying with laws as they are written but it's about like not creating like big scary situations that make politicians feel like they like they need to act right and uh I think uh the the like the worst thing that we've done as a community in that space is just all of the large scale DeFi hacks and uh I think it's been good that like for like both improvements in DeFi security and uh improvements uh in and even you know like things like privacy pools and railway and like making protocols that are private for people but that uh at the same time uh are uh like filter out transactions that come from the uh from like known attacks and like similar types of sources, right? And uh because if you can just make it uh harder by for like North Korea to use uh to like anonymize like their stolen coins by enough that like you don't have to make it impossible. You don't even have to make it crazy difficult. just to make you have to make it harder by enough that crypto is not easier for for them to do that than the fiat banking system, then like we've basically succeeded in not contributing to the problem and in getting the target off our backs, right? And like the fiat system is crazy vulnerable, right?

Like there's a huge number of uh you know like scams in uh especially in this part of the world, right? And like most people who get scammed like despite the fact that it happens through fiat and theoretically fiat is regulated in KYC like they never get their money back, right? And so like being better than fiat is like actually not a super high bar, right? And I think uh with things like zero knowledge proofs like we have a lot of tools to be both much more privacy preserving than fiat and more inconvenient for large-scale criminals than fiat and like we should try to do that. Go ahead.

Here you go. Excited. Um my name is Farad. I'm here at S capital

and um we are trying to bring in large volume of assets, institutions, family offices

into blockchain building asset treasuries for them. So the biggest challenge we have is basically bringing them compliance at scale globally while at the same time enviring them privacy and security.

I think there's too many questions within just the last part aspect.

Um which is not too easy to solve. I think

um looking at all the layers of structure offered this just complicated to offer this at scale for firms. Is this some chic? Maybe you have like some insights into DeFi protocols or

Yeah, I mean honestly it's like hard for me to answer because I think the answer in this case just depends so much both on the individual application type and on the individual jurisdiction. So yeah,

if it's just exposure to ETH in general and ecosystem, then ETSs and other existing tools would be an option which are already compliant. But if you want access to D5 to yeah actual then it's different

L1's and L2s. So it goes basically into strategic reserves. Some companies want to build as a treasury for E for so many.

This is a good question for fractum ventures later as well as they invest in solutions for this.

Yeah. Uh yeah, I think like I just did one al just wanted to kind of rehighlight this uh like the importance of the like taking this kind of full stack approach, right? And I think this is something that uh where the ecosystem like I think we're really in a position to start kind of pivoting um much more to this right and uh like basically yeah if you just look at any of like average DAP right and like and also like I think we can in this case we can merge privacy and security into one category because there's a lot of like a lot of shared issues and concerns and really privacy is a type of security um but uh basically Yeah. So, you know, when you you access a DAP, right? And like theoretically, the smart contracts are fully audited.

It's like amazing. It's um even formally verified at this point. It's secured, but uh one you're accessing the DAP uh through a uh web UI and that web UI is just fetched in real time from a server. And so if the server gets hacked then at any time you know like if basically yeah you could end up using the wrong UI and then if you bas it suggest a transaction if you don't look carefully and then you you know you lose your money right two is uh that UI is not just looking at the chain it's also making all kinds of

HTTP calls and so you don't really know where your data is going. Um and then three it's uh it's using all kinds of software dependencies. Those dependencies uh are getting pulled from all kinds of places. Any one of those can get hacked, right? And so both from a not losing your coins perspective and from a keeping your privacy perspective like there is this like ecosystem level uh problem, right?

And so I would actually yeah love to see the ecosystem doing more uh to uh like figure out a uh like a a full stack approach to uh to to building DAPs and to presenting DAPs to users that can solve these kinds of problems, right? Like I think we need version control for UIs like UIs should be hashed. they should be on IPFS and then like it should be the team's multisig that is directly updates the IPFS and then you have an onchain history that shows and like when it last got updated. Uh

swarm actually did this.

Yeah, that's good. Uh then uh you know we need similar things for npm. uh we need uh similar things for uh and all like any kind of uh any kind of languages that are being used then for privacy. I mean, I've seen there's a bunch of projects that have already done the uh equivalent of Ether Scanuh contract verification, but for uh uh uh like ZK verification keys, that stuff is good, but that's like those pre-existing contracts needs to be organized uh much better. Uh then uh no no four like a user does not have a good way like if a user cares about privacy they don't have a good way of uh approving and uh and rejecting and like getting any fine grained view into their privacy situation the way that wallets uh do for their assets right and so like making a more walked down browser that enforces some of those policies and even where HTTP calls might have to be clicked through permission in the same way as web 3 requests do I think could be interesting.

Another thing to also look at is uh I think uh exploring AI in the context of all of this, right? Because uh like to me I view security as like even my definition of security is basically a systems ability to uh approximate a user's intent um as weighted by like how badly things go wrong if the approximation is incorrect. And so uh that is and a user's intent is fundamentally a very complicated thing and like a user's intent is not something that you can uh like mathematically specify in a simple formula right and uh I think too much of what we see in security is we see people either saying um like yeah whatever security doesn't matter you know as Kyle Sani famously said on Twitter I value speed more tbh um and then uh you know, on the uh um on the flip side, uh you have uh people like I think uh the thing that the Rabby wallet did recently, I'm not sure if it still does, which is just like ask for permission too much. It's like if you make uh if you require every e sense to require five security clickthroughs, eventually people's eyes are going to glaze over and it's not going to make sense, right? And so like good UX is not about making it easy to do things.

Good UX is also not about making it hard to do things for the sake of security. Good UX is about making it easy to do good things and making it hard to do things uh to do things that are destructive for your money and your privacy. Um so it's uh and like splitting those categories is like inherently a difficult task, right? that like actually LLMs are a technology that has been surprisingly good at approximating those divides in a lot of those situations. And so figuring out like the right way to use that.

So like split apart like lower risk, higher risk categories based on uh what are you uh like amount of economic value at stake and what a user cares about and like doing it properly and like not going in the other extreme where you're saying like oh you know you're going to trust an agent, right? and uh is uh I think uh an important pro problem like basically I think like for very small value it's like what you want is a one of two between you and the agent for very high value you what you want is a two of two between you and the agent right like b it's uh like like there are challenging UX problems there and I think they have to be solved at this kind of bottom of the stack um level and like it can't be just a an every app for itself sort of thing. There's inherently one more question behind it is when you bring large volumes of assets into Ethereum or any other chain is not posing any kind of challenge or problem for blockchain itself. Mhm.

So you're asking if bringing more money on chain is a problem

like I think yeah I mean I think it can be um I think uh the I mean think there's uh one of the big risks for example is that if there's only like one dominant stable coin and it's a centralized stable coin then uh the issuer has a lot of bargaining power in terms of determining the winner of a contentious hard fork. And so uh like if you care about uh getting stronger privacy and censorship resistance on Ethereum then uh that would be a risk. If you care about not reverting transactions then that would be a risk. I mean it's a risk in a lot of situations right. Um and so I do think that we as Ethereum have an interest in there being a more diversified set of uh stable coins and more decentralized ones and uh more types of real world assets.

I mean um another type of risk that the ecosystem has is obviously if there's a type of activity happening on it that uh some I mean either regulatory agency or large groups of people don't like right and uh and the balance there is like on the one hand uh you know there's uh and this is this ecosystem is about censorship resistance and it is about enabling like regular people to do things without having to ask big guys for permission. But then on the other hand, it's like one example of a thing that regulatory agencies are scared of is US dollar dominance, right? And uh at the same like we as Ethereum like I don't think we have a a positive ideological interest in increasing US dollar dominance, right? And so, you know, to the uh extent that uh you know, we can have a g get a stable coin ecosystem on Ethereum that is more diversified. Like I actually think that it's both good for cyberpunk goals and good for regulatory goals.

And so I think we should work together on uh making that happen.

Okay,

one more.

Hi, I'm AJ. I my company is inspiration voice

and I have a question about

like we've built economies around proof of work

um and proof of stake

but what about proof of feeling or proof of ache or proof of aliveness like is there a path where economic systems can verify not just transactions but transcendence

I'm exploring resonance-based ledgers um one that listens to the nervous system

and I'm just wondering if you think there's a future where the body itself becomes the most trusted oracle.

H I guess I'm I'm I'm curious like what are some uh things that you wants to do with like those kinds of signals?

Um to show to show the viability of overflow as um as value

and capable of being exchanged and reciprocated in an an economic system

where it's not coming from scarcity or lack. It's actually coming from abundant overflow

and then reciprocity becomes something that is like powered by an infinite source. Like I think there's definitely applications where it uh makes a lot of sense to like explore making different aspects of a a person's inner life and of and a and also like like a a community people's interactions and a and a community's life more legible and uh if you do that then uh I mean like that can even, you know, like feed into things feed into things like reputation and like all of these all of those different identity um identity applications. a way to like if you like if you can show things about yourself then like that can make other people more willing to trust and uh and interact with you and that's uh and a lot of the time that doesn't require a blockchain obviously but uh there are like like I think what you want to look for is you want to look for these kinds of social processes that are like very organic and that happen naturally at like a physical and a small scale, but then where they can't happen across a larger scale because like trust issues exist and like on the internet we're we're far away. And then try to see if uh like making those those processes that already exist more legible like somehow enables them to scale in ways that uh that they were not able to before. I mean it's it's pretty abstract but like that's where I I think there's some interesting things.

question I received. Um, you're familiar with different encryption methods used in the space.

Any thoughts on garbled circuits?

Yeah, garbble circuits are great. Um, I mean, I think uh like I've been saying for a while that like I think uh like two-party computation and multi-party computation are different enough that like we should view 2PC not as being MPC but as being a different category and uh like the because just like in in practice the type of trust model is very different right MPC is just fundamentally about like hey let's have a committee of 16 people and like we assume nine of them are honest but garbled circuits are like let's do things with my data and your data and then warn the answer of some combined computation without either of us learning things about the other, right? And so there isn't this kind of external trust assumption involved. And also global circuits are just much faster than more complicated forms of MPC, right? So it's uh I mean I I think there's really cool application categories that could be done there.

like uh the most natural one is the sort of like the are we compatible use case right which is uh like like I've seen people like explore this for dating sites I've seen people explore it for employment I think uh compatibility between a person and a community in general um based off of some private information that like a person's private history and uh potentially private history of people on the other side or potentially a private algorithm on the other side. Um I think a lot of interesting uh interesting stuff there. I mean like generally being able to I mean even uh you know like things like uh sort of private training right or even things like being able to extract like a very limited number of bits of from a person's in a person's information. uh but uh in a way where like if you have to combine information from multiple people then and like potentially the computation itself might involve data from other people and so you you know you don't really want to do it fully in the clear like there's a lot of these use cases where it's uh good uh it's a valuable thing and so I think it's uh great that that technology is continuing to improve. See, I have another.

Okay. One, two, three.

Uh, going back to the initial question mark is privacy privacy effect.

I think one of the five one of is that a punishment. Mhm.

So if I this central exchange here in Japan find out if I need to collect them with a safe

they might just collect with me and then I lose access to

Alma

and what's happening to like witnessing what's happening to me cash centers

uh how do you encourage people to speak by the

push boundary negative incentives to price.

Yeah, I guess I'm curious like are the exchanges hostile to rail gun too or or have they just not heard of it yet?

Yeah, I guess because I think uh like one of the more kind of one one of the important variables here, right, is like what is the mechanism by which uh exchanges decide like what they what they blacklist, right? And uh because uh a lot of the time they uh outsource it to some third party provider and like often it's chain analysis but like basically because if the underlying algorithm is like less about detailed analysis of individual protocols and it's more about oh this guy had has money from a thing and that thing interacted with lots of North Koreans and therefore I'm going to blacklist a thing right then like that actually creates uh almost like a very optimal kind of incentive structure for people like rail gun because they have an incentive to like figure out a way to make a thing that is as private as possible but at the same time excludes North Koreans well enough to pass the test right and so if that is the uh like that like like the kind of underlying incentive structure at play then like I think it's like a good thing and uh probably the thing to do now is to like use the smaller protocols and then it's up to them to basically make sure that they can you know like limit things like large scale DeFi thefts by in by enough that they don't get into the blacklisted position. If it's uh like a very uh generic kind of hostile legal stance to that kind of privacy then obviously it's uh going to be much harder to

come to to to get past that and and uh in that case I think I mean the best answer there is like both I mean both hope and I think that it doesn't happen and actively make the case to government for and and also to the public for why a a friendly stance to privacy protocols is both viable and a good and the right thing to do. Um so

as cash was mentioned what can current and next generation of privacy build at the government gets? Uh yeah, I mean I think uh I mean to me actually yeah to radio cashache is like one of those uh examples of this uh like aspect of a cypher punk ethos that's like a little bit too openly oppositional right I think I mean even like they did a lot of things I mean even calling it tornado like making it like um having like swag that involved things like what things like like laundry machines and uh like basically kind of flying very close to the sun in terms of those kinds of optics, right? And uh I think like there's a very sort of 1990s kind of like spirit to that approach and like I really yeah like I respect the spirit and I admire the bravery in it, right? But uh at the same time the like I uh I think that approach is like well adapted for that world. It's less adapted for the current world.

And the reason why it's less adapted for the current world is because uh communication is much stronger between everyone and everyone. And uh basically like I think the winning strategy in the modern game is to have uh be have a strong incredible story for why your thing is not a rebellion against the world. your thing is like actually compatible with uh the uh the goals that a major that a majority of people care about and uh as well as being uh like compatible with you know like any explicit laws that are available. And uh like you can push the boundary and like and you still should push the boundary and like you still should uh even uh be willing to publicly phrase your thing um in the context of uh you know like being a uh a tool for uh for protecting people against oppression, right? But uh at the same time like uh so I think like on the on the PR side the uh like that's one of the things that I would say and like a lot of the the best protocol like and like mo a lot of the most successful privacy projects that we see do a good job of this.

I mean like Signal does a good job of this, right? And like there's a lot of things to criticize in uh Signal, but I I think it does uh do a good job of that, right? It's like when the US government uh uses your messaging application, like that's a win condition, right? Um the other part of this is of course you know in practice, right? basically uh the fact that like North Koreans started use government started using their stuff in an obviously criminal way on a large scale and uh they I mean both pretty conspicuously did not do anything and did not did not manage to decrease that at all was like a pretty big deal right whereas if you compare to something like rail gun like it uh like with the pro the uh privacy pools mechanism.

It has a lot of uh a lot of tools to make it make it harder for any type of bad actor to participate. Like there's a lot of uh lines for uh response while at the same time still preserving the privacy property which is like baked into the protocol in a deep way that can't really be taken away, right? like you can't really just like suddenly flip a switch and say, "Okay, yeah, you know, a grill gun is KYCing everyone now because the contracts don't let you do that." And and so yeah, I think striking that balance is good.

In the middle

I'm trying to establish a new health standard

where patients control their own data.

Mhm.

But governments can still use it for training AI models. Okay.

How do you see Athereum privacy technologies helping to achieve that balance?

Okay.

Patient data.

Yeah. So I think uh

the right so the the question I think that is interesting is like what part of that whole piece blockchains are good for right because uh like you can do all of that without a blockchain right and you can make a protocol where like if I had that problem I would probably use some differential privacy thing where you know basically every user provides their data with a lot of like noise and a lot of uh you know like you like replace uh like things a lot of data with kind of like much more coarse grained indicators and like figure out what are the specific things applications need and then uh focus on that and then on top of that you know maybe add FHE and then on top of that even maybe add TES right but then that's so so for preserving privacy for solving the problem of privacy and compute at the same time like that part blockchains don't help and you cryptography where I think blockchains do help is in providing like more interesting kinds of security asurances. Um basically in terms of uh ensuring the authenticity of the data, right? Because if you want like for example if you want to do one of these things where you like have a marketplace for data and people get compensated for providing their data then the problem is well people as soon as that incentive exists people are going to create fake people and are going to try to farm it right and uh like at the very least the thing that you can do is you can uh authenticate uh like try to authenticate the device and you can do you can have like onchain gadgets that can uh provide some interesting uh guarantees in that regard, right? So, like for example, a thing that you can do is you can have a TE and then you pair that with an onchain contract where that onchain contract has a bounty and that bounty just automatically pays out like a half a million dollars to whoever can uh uh can either extract the atestation key and atestation key or even cause an atestation key to sign any kind of message that it's not supposed to sign. Right?

And then you just have that bounty exist and then the existence of the bounty is is is proof that that type of hardware still can be trusted at least up to half a million dollars. Right? So

that's great. That is um another uh type of thing that you can do is also that a user can uh like regularly commit like they can regularly publish hashes of uh personal data that they are storing and then the idea is that if they later decide to sell the data then they at least have a proof that that data was created before a particular point in time. already have data.

Yeah,

I already have data. But not personally me a government,

right? Wait, so you mean the government already has data about people? Okay. I mean, if the government already has data about people, then like it can already train what it wants and it's hard to get have any guarantees, right? Because uh if you make one process that has guarantees, it could just do another process in parallel that bypasses all of them.

They not satisfied the speed the speed of transactions,

right? But okay with the speed of transactions on the blockchain or in general

okay what like what kinds of transactions do they want to do

train AI models

right okay so they wants to have more compute to train AI models yeah I mean I don't really think of that as being a blockchain problem like isn't that just like a buying AWS credits problem [Music]

let's not mention that here

there's a question in the back shout out.

Sure. Yeah.

Okay. So, depending on who you who you ask, cypher pun can be a different thing. And I think there's a whole history to it. Bone freaking frack magazine and so on. So, let's say some people would

gently raise their eyebrows hearing

cypher punk. Yeah. In this cryptocurrency space and

I mean you look around how many people use Telegram? Can you use any sort of

Ethereum client on Tails OS? I don't know.

What do you think the cryptocurrency space or the space is bringing to the table?

Yeah. Okay. So, I think uh

perhaps you can also shed some light on DeFi poker because I think you guys came up with that one.

Yeah. Maybe uh so I think the biggest concrete thing that the cryptocurrency space has realistically contributed to like broader cipher punctum is uh I mean one is obviously just uh like making it possible for people to have payments privately which has been a a cypher punk goal since David Cham in 1982. The other one is the sheer volume of resources that it has brought into the development of uh cryptography and especially programmable cryptography. Like things like ZK Snarks and uh probably even modern fully homorphic encryption would not exist to anything like the the level at which they existed without the resources that uh probably yeah the the cryptocurrency space itself was uh provided. Right.

So I think if I had to like ask what are the biggest positive things um that like the cryptocurrency space has contributed I would say those two. Um I mean I definitely uh like I definitely think that uh like we should be getting off of telegram. actually I mean I feel like actually Signal has uh been uh um gained a huge amount of uh like market share in terms of conversations within the crypto space over the uh p over the past year or so right um and uh I mean like fileverse I use it regularly and uh like we actually have an end to end encrypted alternative to Google Docs which is good um also So uh and this is uh and then the other area where like I think is incentive compatible for crypto to contribute uh for or for the cryptocurrency space to contribute is uh as I've said for going like full stack right because uh like cryptocurrency is not secure if the browser and the operating system in npm are not secure and at the same time any other application that claims to be cippher punk made by anyone is not secure if those things are not secure, right? And so uh I think uh um collaborating on improving the uh the the security guarantees of uh of those things is something that we uh like all of us like I think really needs to be more actively involved in going forward.

Last question. Thank you.

Great. Um my name is Laco. I'm based here in Tokyo. Um the idea of privacy and crypto and um I think branding

is so important. We live in a world of branding. Adidas, Nike, the Ethereum logo is one of the most famous logo

beside Bitcoin. I think even more than Bitcoin.

Yeah. Uh what is your view about having black logo the black Ethereum logo meaning privacy equally you know meaning privacy and pushing it

between all the conference you know worldwide.

Yeah etc. It's interesting. I mean, I do wonder if like uh privacy should necessarily be associated with uh like black, right? Like I think I mean I like No, I mean I I get I I get the uh like

I mean obviously yeah kind of it makes sense in terms of the raw physics that like when it's dark you can't see things, right? And uh obvious like I it's been this appealing meme, right? But it's at the same time like you know things like dark dark like they definitely contribute to a type of perception of privacy that like I think could even be harmful toward its broader adoption and like I think we should all be thinking about like well maybe privacy needs to be cute and then thinking about like what is a cute private Ethereum logo and like I don't like like I think there is value in also thinking about that uh that that kind of that other direction as well. Unlike our posters, we do promote um joy as in optimism in privacy because there's enough options, enough reasons to be dooby and globy and you need the optimism in the space to to yeah to to collaborate and to incentivize and so um yes they don't think black should should need to be synonymous with privacy from our perspective at least. Please

I think that was the last one. Oh okay, dear colleague of web privacy go ahead.

Um just curious so since there is a launch to start

and I always like to ask you this question. What would you like to see from the house in the next

expectations of the hackathon at East Tokyo as a final question?

Yeah it's a it's a good question. I mean I feel like uh a lot of the things that I had suggested before like um one of them is this uh like there should be an ether scan contract code verification equivalent for ZK like actually 10 of those exist and there the problem is just uh getting them more integrated into mainstream things. Um I think uh going in the uh direction of uh like privacyfriendly DAP UIs is is a valuable thing and like obviously you can like take individual like projects and uh like make a fork that doesn't uh that doesn't call home but then there's a question of like a more systematic way of doing it, right? like uh you know could you have a browser extension that has like a mode where you just say like okay this application is not allowed to call home anymore. Uh could you have uh a like a UI programming language that is like more restricted than HTML and JavaScript but that like enforces security properties better.

Um then on the other side I think um privacy for identity and like making privacy for identity actually convenience. Okay. So here's like one specific puzzle, right? So uh the like there's a lot of these projects that are like ZK passport and you know like ZK I mean World Coin has ZK baked in by uh by default ZK minor ZK government ID, right? And uh one of the problems that I have with these things is what I talked about in my blog post on uh like uh disliking overly strong proof of personhood about two months ago, right?

And the comment that I made there is like actually proof of personhood can be exclusionary and be anti-freedom even if it's ZK wrapped. And uh then the question is well how do you avoid that right? And then to me the only solution is pluralistic identity, right? Which basically means that like you have a bunch of different actors that are making a bunch of different claims about different people and then you when you prove your identity, you're proving some claim about multiple different uh statements that are in your history, right? And so like one very basic example of this is like if you want a kind of decentralized version of a college diploma, you just zk prove a history of interactions with a bunch of other people who have a college diploma, right?

And uh for a lot of people like that's going to be a good enough substitute, right? And that reduces the you know like the university as a as a point of control, right? But then the challenge is uh like you need to have a framework that can actually make that intelligible for application developers, right? Because the reason why people love these like very binary either you're a human or you're nothing kind of uh identity models is that they're just like really conceptually simple to understand. They're really conceptually simple to develop around as a programmer, right?

And so if uh figuring out some kind of uh abstraction that satisfies the goals that some applications have but that uh is more more pluralistic I think uh is something that uh is going to be very uh very valuable. Um let's see throwing around uh other uh kinds of uh ideas. Um like one example of a problem to tackle is like okay who here is has used a VPN in the past month. Okay just checking this is an actual cipher bug conference. Um then uh okay basically yeah who okay who here has expects that they filled more than 10 captures while using a VPN in the last month?

More than a hundred. See probably right. Oh, it's basically it's like, you know, the unavoidable experience of a VPN is that you just get asked for a capture everywhere, right? And so if you could prove that like basically that you're not a civil attacker using some ZK approach that like I think proistic identity is actually perfect for this because it's like a little risk use case. There's no legal requirements uh to do anything there.

like if you fail like you just get your application just gets spammed more but then at the same time it's like solving a real pain points for people then uh like basically yeah like essentially figuring out some kind of cloudflare like um alternative that uh does anti- deni a denial of service protection but that uh accepts zero knowledge proofs of not being a symbol of like maybe 10 different kinds like that is a a product that could be very useful to the world like I think that's also potentially a project worth making

okay that was the last one thank you for your time thank you for joining us today and uh glad you're all coming to your talk tomorrow [Applause] [Music]

Automatic transcript — names and jargon may be misspelled.