"Reclaiming the Cypherpunk Dream" by Sandi Fatic // Ethereum Cypherpunk Congress 2
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Ethereum Cypherpunk Congress by Web3Privacy Now is the world's largest cypherpunk and human rights event. 4500 people gathering in Buenos Aires to celebrate privacy with internet freedom leaders like Richard Stallman, Vitalik Buterin, Roger Dingledine, and Eva Galperin. Join us in building a free internet for all. Website: https://web3privacy.info/ Congress site: https://congress.web3privacy.info/
Transcript
[applause] Hello. Hello. So before I start, I just want to like say uh so this presentation is going to be like about reclaiming the cypher dream. I'm going to discuss like what was the dream um what the internet looks like today and hopefully uh how do we fix it. Uh I will do an introduction about myself a bit later.
Uh but just for now I'm just going to say I'm the CEO of Calimera Network and get into it. So I'm going to start like what was the internet not supposed to be, right? Uh so like 23 and me selling customer genetic data, Amazon being fired for data protection problems, uh Facebook spying on competitors, uh bite, um you know, handling miners data. Currently we have GDPR, right? So like we have at least some fines for companies when they do wrong.
Sometimes they want to do it maybe and sometimes they're like just uh you know making a mistake. Um so like what was the internet supposed to be? So like if you say Julian Assange his quote so the internet our greatest tool of emancipation has been transformed into the most dangerous facilitator of totalitarianism we have seen like a very powerful quote. So like if you think about it every time when you use the internet today you talk to a centralized service provider you're giving a little piece of data which gets stored about you and they essentially know more than you do know about yourself and so like I'm going to start about my journey into like web two and web three. So essentially I started my career at big tech.
Um I worked there. I saw in 2017 uh this ICO boom is coming. So I joined the layer one project, spent some time there, worked as like a protocol developer. So worked on consensus. Um realized that like there's a lot of uh you know cool technology there but not really use cases.
So I went back to big tech again. I spent two more years there. Um and this sign was like in front of the office. I was smoking there every day and thinking about like okay this sign is telling me. Uh so essentially the sign was your right to privacy has been revoked and me working in a big tech company I was like thinking you know hm maybe I should go back to web3 so essentially in 2022 I joined as like the first infrastructure engineer at near protocol another layer one uh worked on you know various things um and then essentially transitioned into what I call the open web um and the open web like for me what web 2 is was like centralized service providers providing you a service for you know like sell either selling your data through ads or charging you for money but you have zero control and then web3 came and said like okay we're going to be decentralized now but the only focus of web3 mostly was about money so if you think about you know blockchain as a technology it's not really good for every single use case which we would love to see of the internet and then open web is kind of like this thing which encompasses this statement.
In my opinion, a trusted third party is one to many. So essentially if you you know read any cypher punk articles, titles, books, um David Cham, I mean one of the you know pioneers of cyberpunk um tells you that you should not trust anybody like why would you have to trust anybody with your data, with your money, with your private keys, with anything you do on the internet. And if you look historically the internet started decentralized, right? We had Darpanet, we had packet switching, we had SMTP. I mean SMTP is like the first usable decentralized protocol but we don't use it in a decentralized way then you know we had Chris Ktoarch under his manifest.
Worldwide web also in the idea of the worldwide web was to be decentralized, right? Then we had PGP to have privacy on the internet, HTTP which is a decentralized protocol again and then we get to 1994 first browser and then something happens and like I I like to call it like there's like three streams of the internet. One stream was centralized service providers. So like Amazon was born, uh eBay was born, Hotmail, Google, all of these companies. On the other side, we had you know first know first digital cash uh so you know many of of of predecessors of Bitcoin and then we had also peer-to-peer applications like Napster.
So like peer-to-peer music sharing and what I call open web is essentially Napster and the money. So like how do we use normal applications plus the financials part u and then we had the dotcom bubble obviously a lot of money was invested into centralized companies and there's a really good reason why so like why did we go from being peer-to-peer and decentralized into becoming centralized and the reason is very simple it's just cheaper and it's more convenient for the end user so the end user like didn't really care about his data at that point of time it was not even a discussion he was like I want to connect to the internet I want to use the easiest best solution out there and all the you know even today all the peer-to-peer solutions we have are like pretty crappy um and then we had you know Google Gmail a lot of money went into um into investments of centralized service provider today I actually looked up like how much money like what is the percent we say a lot of money went into web 3 so I looked up like how much is what's the percentage of uh web three companies versus um you know standard software as a service and centralized companies like one or 2% so like 50 times more or 60 times more went to into like the the standard web two uh investment so you know and that was much much earlier as well so like inflation and everything and then 2008 we have bitcoin um which starts right uh the financial revolution later on ethereum but there's like two protocols or like ideas which are not really talked about often uh one of them was orbit uh and the other is protocol essentially what they tried to do was and we have activity activity pub uh protocol and masttodon. So essentially there was this first again protocols which are trying to build peer-to-peer applications in the world and there's this this conference today I really like that we are here uh because uh cipher punks used to be like one group of people web three people used to be you know agents and another you know group of people and today we we see that we have like one thing in common we have like self- sovereignty right doesn't matter if you work in web two or you're like true hardcore private privacy guy or you're like a web 3 region. Everybody will agree that privacy is important. H so why does the open web suck today?
That's a question. So like we have many people here who are building you know web three or open web protocols but like why are we not getting adoption and I mean first developer experience is pretty bad. If you try to build anything on a like open like any open source privacy protocol today, it's quite quite hard and quite quite bad in my opinion. And the other thing is like user experience for the end user is terrible as well. So like the only application in my opinion today which is like true privacy application which is used by the masses is signal.
We can discuss about this or that but in general like signal is the only application which truly has good enough user experience which masses use. So the question is like how are we actually doing so bad than if you like compared like open web or web 3 as an industry. I would say not because first we wanted decentralization. We got you know we can you know discuss how decentralized some protocols are but we are getting there. Transparency we solved censorship resistance pretty good permissionless as well pretty good.
programmability, composability, I think also like quite decent. But the things which we are missing is like user sovereigntity. So we always said users will own their data. We don't we don't even own like we own our p private and private key and our identity on transparent blockchain protocols where everybody can see uh which transactions you made. So like you're not even anonymous like you if you trust your bank at least your bank can see your data and you know sell it.
But if you use like some of the privacy like if you use some of the open protocols everybody can see it right. Um and then the other thing is like a privacy I mean privacy is generally pretty bad and I said user experience developer experience. Um and one thing like how do we solve it right? Um one of these thesis of cippher punks was that cippher punks write code. Uh so like we need to build the systems which are better but to build a better systems we need a very nice developer experience.
And I'm going to talk about like how we as a company and what do we do um are trying to achieve this. So if you're interested like what we do at Calimero uh you can check out our core repository our other repositories and our docs. And one thing I just also wanted is like this if you read if you just read any of the cypher punk manifests or like any cyberpunk texts I mean they're awesome. So for privacy to be widespread, it must to be part of a social contract. People must come together to deploy these systems for the common good.
Privacy only extends so far as the cooperation of one fellows in society. And people always say like you know it's it's a like you know standard thing at this conference like people say oh do you believe in private do you trust do do you want to have privacy? Yes I want to have privacy but what are you doing about privacy? I'm doing nothing about privacy. Uh and I mean essentially we are like on the same spot.
So I want to say like what is Calyro like what we learned like what I learned personally from working at like big tech then working in web 3 on like various blockchain protocols is that to really get user ownership users who should have the ability to host their apps and data. So like having local first applications local p first doesn't mean that every single you know data point has to be stored on your device but it could be stored like in a t in the future maybe we could use uh but ideally you would have to have your data by yourself somehow. Then the other thing it should be simple. So like we should be able to build privacy applications without thinking about complex stuff like you should not be an encryption expert. You should not be you know uh we use for example CRD is expert a database expert.
You should be able just to write a simple micros service which is peer-to-peer by default. There should be no central like central authority. So just no servers just peers. So like with torrent with compute it should be encrypted. So every time when you interact with some peers the data is encrypted.
Nobody can see it peer-to-peer obviously. And it has to be open source. Like if any project claims that they are privacy preserving and not open source it's like an oxymoron like it cannot be has to be open source people have to validate what's inside you have to see is is it doing actually what is supposed to do and then first protocol SMTP what happened you have a center you have a server you host your server somebody else hosts a server you send an email directly peer-to-peer and then hosting servers is hard so host hosting servers is expensive especially like you know 20 years ago. So what we did was like let's say somebody any company provides the SMTP server for me they host it but I give my privacy away in an ideal world like today you know the internet is fast storage is cheap comput is cheap there's like nothing preventing us of actually you know running our own services except the user experience and like what Calimero is essentially is is this uh how do I go back uh it's an general purpose framework which allows you to build a simple micros service in Rust or Java JavaScript you deploy it on the calimera node and you have application context an application context is a peer-to-peer network where the data is replicated between the mmers and how does it work so we use WASM is the application runtime we have our own uh we have our own um runtime which we build on top of you write your application you can say like this you know this data point is shared this data point is private this data point is immutable Um and then this gets broadcast to your peers. So you have sync and execution.
For sync and execution, it has to be real time, right? Like blockchains are slow because you have to have block times, you have to wait. Even with some fast blockchains like half a 500 milliseconds, it's too slow, right? And especially if you're like replicating data a lot. So what we use, we use CRDTS and ducks.
uh CRDT is a conflict free replicated data type which allows you to merge state locally in any order. So essentially you have determinism once you receive the payload and you apply uh like you you deterministically apply like everybody else and the D is essentially just a directed a cyclic graph which allows us to like GitHub uh track the changes how the changes were made. So essentially if I made a change I'm going to make the change on top of my root hash and then broadcast it to the network. If somebody else does a change on top of their on top of their uh they're going to broadcast it and then we're going to have some conflict resolution to essentially converge to the same state and then we have I mean standard uh li P2P and APIs. Um you have an RPC client so you can use like Python uh to talk to the node uh talk to the node.
You can use JavaScript to talk to the node. You can use Rust to talk to the node uh and build any application mobile uh front end whatever. Um so yeah we use like uh gossip sub broadcast. So essentially every every every uh every contest application contest context is a li2p gossip sub which is encrypted and only the members of the specific gossip sub can decrypt the messages. So you have a key key sharing exchange between all the members.
uh you encrypt with your sender with your sender key and on all the other nodes have a public like they have a public key which they can decrypt uh the messages with like I mean public sender key to decrypt the payload um and pretty much like how it works there's like two types of um operandi if you are executing a transaction locally you run it through the runtime you produce a CRD diff you broadcast it to everybody else and then everybody else who receives it they can just dump it to the storage um based on that and then you have per periodic P2P syncs uh in case you were offline. So you could even use the CRDT while value offline edit a document uh work on on the board and once you get online you will broadcast it to everybody else and everybody else will convert to the same state. Uh yeah and that's pretty much it. I mean if you want to learn more about what we are doing and how we get to you know normal applications to be again peer-to-peer and fast uh talk to me. Thank you.
[applause]
Automatic transcript — names and jargon may be misspelled.