New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Vitalik Buterin & Roger Dingledine on Integrating Tor into Ethereum | Ethereum Privacy Stack

Ethereum Cypherpunk CongressFri, Jan 9, 2026, 12:00 AM

Speakers

One of the biggest announcements during the Ethereum Privacy Stack was revealing of what all will be applied from Tor into Ethereum ecosystem. Quote from Buterin: ""We now have an effort in Ethereum Foundation to put Tor and Onion hidden services into the Ethereum ecosystem across the stack pretty much everywhere"". Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: https://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/

Transcript

Test test one, two, three.

Great. Hello everybody. Welcome to the next installment of the Vitalic and Roger show where uh this time we're talking about privacy and the Ethereum ecosystem. Uh would you like to start this or how how should we begin?

Sure. I mean I think um maybe some uh you know background, right? I think we've uh talked a lot about privacy this whole week. Privacy has been uh a core value of the uh crypto space. Um I actually think uh all the way back since the real beginning of the crypto of the cryptocurrency space which is David Chum's ecash in 1982 which was actually private but not decentralized.

And so you know originally privacy came first right and then of course uh Bitcoin was famously decentralized but not private and uh we have the technology now to really have both at the same time and know and and so we're going full circle right and uh privacy is a human right. Privacy is a basic expectation that people even in in many cases people who you know do not have who were not able to enjoy many human rights nevertheless had for thousands of years just because in the uh offline world there is uh just inherent limits to how much uh information you're able to collect and process. But uh in the uh digital world these things are very quickly changing and we need to make sure that privacy continues being a uh reality and uh for us in Ethereum for the uh last especially year I think we've had a big push uh toward these kinds of goals being you know first class priorities uh for not just at a very theoretical way but also at the in a way that directly uh touches users. Um so I guess uh I mean maybe Roger could maybe just briefly go through you know tour and some of the evolution that tour has had over the past couple of decades and where the project is now.

Yeah. So tour is a privacy project at the network layer. The goal so from my perspective I look at privacy from from two pieces. The first one is at the application layer. In in the tour world, we think of this as tour browser where we try to get the browser layer, cookies, fonts, all sorts of cookie- like things uh safe.

But underneath that is the network layer where when you're using tour, somebody watching you locally can't learn what destinations you're going to and somebody at the destination end can't figure out what IP address you're coming from. and no single point in the middle is able to match up which users are going to which destinations. So from my perspective, every time I see a new uh application situation like the Ethereum one, I think, okay, great. You need to think about application layer privacy. You need to think about whether the bites you're sending back and forth are revealing what you want to reveal and don't accidentally put things you don't want.

And then underneath that, at the network layer, by default, it should all be private, anonymous, secure. It should all you should not be revealing your IP address to the people that you're talking to and that lets you choose at the application layer how much you want to reveal. Maybe it makes sense to

use tour to get to Facebook and then log into Facebook if you choose to. Or maybe it makes sense to use tour to get to Facebook and not log into Facebook if you choose to. So the goal of tour in that context is to give you the user the choice about how much information you want to reveal to whoever you're talking to. And you shouldn't by default reveal everything to people watching you to uh large telephone companies or intelligence agencies in the middle or to the websites you talk to.

Yeah. Uh maybe uh so when I first saw tour 20 years ago, you know, to me my mental motto of tour is this is a private browser, right? Tour is a browser and you know I open tour and through tour I can either access regular websites in an anonymized way or I can access hidden services. And one of the shifts that I think has been uh interesting is viewing tour not just as you know like that kind of you know like full stack thing that uh contains a browser but as a general purpose infrastructure that as something that uh protocols more generally can uh plug into and that tour is about making everything that happens over the internet be able to happen in a much more privacy preserving way. So can you maybe talk a bit about that journey?

Yeah. So, absolutely. Back in back at the beginning, we were in the peer-to-peer community. Now, peer-to-peer means something else. And then we were decentralized, and maybe decentralized will mean something else soon.

But part of the the the point of this was we're building an overlay network over the internet that gives you various security properties. And yes, you can use it for web browsing, but you can also use it for uh anonymized messaging where each side is a tour user. you don't have to know who is what which. So, one of the other uh fun things in the tour world is the variety of types of people who care about it. Over time, we've had interest and use by militaries, by governments and law enforcement, by individual people who read newspaper articles about NSA uh you know spying on them or companies losing data.

We've had use by uh folks in uh the Middle East in the Arab Spring situation. So having all those types of users blending together on the on the same privacy system is part of how the journey has come to this. So it'd be great to have even more uh varieties of users such as the Ethereum folks.

So what are some of the uh most uh s in interesting and surprising kind of application users of tour that you've had so far?

Yeah. So at the beginning it was just the tour proxy. it was the one and and we said maybe you want to hook up a a web browser to this. Good luck getting that right. And that turned out to nobody got it right.

So we realized we had to include the browser in what we were developing. Um some of the cooler use cases came from onion services where originally onion services were so basically once you've got the building block of I can go somewhere safely over tour glue two of those building blocks together so the client can reach the onion service and the onion service doesn't have to know where the client is the client doesn't have to know where the onion service is and nobody in the middle can know either of them and that started off with people running websites that governments would get upset about But then we started having more interesting use cases. There's one called Onion Share where imagine you're a journalist and you want to share the Snowden documents with another journalist. You run onion share locally. It spins up a web server on your computer.

Spins up a singleuse Onion address. You send that address to your friend who puts that into tour browser and downloads it. And then your web server goes away and there's nothing left on the internet to to there's no evidence that any transfer happened. So this is how file sharing should be done on the internet and it's something that you can build once you have building blocks like onion services.

Yeah. And one of the other things that surprised me is that uh Bitcoin nodes are started connecting through tour now. Right.

Yeah. That was also uh so I I met the Ethereum Foundation people at Foss Asia in Hanoi a few years ago and I had just found this graph on bit nodes.io IO which was uh the portion of Bitcoin nodes that are reachable over IPv4 or IPv6 or onion services and at this point something like 3/4 of the Bitcoin nodes are only reachable as their onion addresses. So we the tour network are the critical infrastructure underneath the Bitcoin network which is uh which is quite a world to live in.

Yeah. So now I think this is a good time to get into what we're doing with Ethereum. And I think here the uh the big new thing that we wanted to talk about is that we now have an effort in the uh Ethereum Foundation to put tour and onion hidden services into the Ethereum ecosystem across the stack pretty much everywhere where we're doing that is possible. Um so this is uh something that we started thinking about um a few months ago. Um basically uh you know we've uh I think had a big conceptual shift from uh thinking about privacy purely as uh zking your transactions and uh you know publishing a proof that you have a coin instead of uh instead of directly publishing the index of your of your coin and linking all your money together to this uh much more holistic vision where I mean if you've seen me present about this before you know you've probably seen the graph where you have like privacy of rights and priv privacy of reads and uh this includes things like uh being able to read, you know, data from the Ethereum blockchain without having to give up your entire access patterns to to an RPC node.

Um and uh one of the other big components here is broadcasting transactions, right? Because if someone is uh spying on the network, then uh they can see the uh transactions that you're sending as soon as you're as soon as they uh leave your machine. And so we're looking at that layer. Um we looking at uh applications uh across the uh Ethereum network. We're looking at other kinds of uh user user level applications and uh basically really uh pushing up the uh standard of uh privacy for Ethereum both at the uh you know low low levels and the high levels and across the stack.

Yeah. One of the ways that I look at this and I've been talking to the like anonymous single show credential people for decades now and I keep running across the application layer credential people saying I've got all this flexibility in my protocol. I can go from totally identified to totally anonymous and you can choose anywhere in the spectrum. And and I always look at them and say that's great but this 97% of your spectrum you're sharing your IP address with the server. So, it's awesome that you've got your anonymized single show whatever, but I get to know who you are when you're doing it.

So, remembering both sides of this is uh uh is key and it's awesome that that Ethereum is now aiming to be more holistic in this. So, I guess one question for you. Um I don't know enough about the various pieces layers of the Ethereum architecture.

Um we've got users sending their transactions. We've got users trying to read from the blockchain.

We've also got validators and those have to talk uh really quickly.

So, we talked a couple of days ago about the the traditional finance people of the world wanting to drive down the the blockchain frequency down to 200 milliseconds.

Uh how do you balance the

wanting privacy at that layer versus wanting everything the finance people want at that layer? I think it's there to some at some point I mean even for reasons that go beyond uh privacy we do have to put our foot down and say Ethereum is not going to be the fastest. Ethereum is not going to be able to compete with chains that have 30 or 300 nodes on uh things like latency and uh the Ethereum L1 will not uh uh deliver like literal blink of an eye UX where you're not a where you're not seeing uh delays at all. And uh like I think we just have to be uh open and honest about that because Ethereum's primary goal is to be the world ledger. is to be the network that is decentralized that is censorship resistant um and that it is you know like the file of Gajreel and Lord of the Rings it's the light that remains when all the other lights go out right and uh that kind of goal I think is uh needs to be primary for Ethereum in order for Ethereum to be the home of uh applications that last in the long term that uh you know like finance where the upside is plus 1% the downside is minus 100% % where you uh really uh depend on that level of uh reliability, right?

And aside from uh privacy, the other reason uh is geographic decentralization, right? We do not need a network where even there there because of incentive pressures, nodes would naturally all concentrate in like London and New York, right? We need a network where it's not just possible but also economically viable to participate from uh you know places like Bonosirus um and uh Southeast Asia and uh like say yeah Zambia right and uh this is but but then uh improving privacy at the same time is uh is important right and I think we've started by uh identifying the u the places where privacy is the most important, right? And uh the really key one actually is privacy for denial of service resistance, right? Because uh even though the network has a lot of nodes, there's a very small number of nodes that are responsible at each individual slot, right?

And so there's one node that is the proposer and uh if you can identify the proposer ahead of time and you can do a a targeted denial of service attack that lets you uh basically kill the chain and uh the possibility of that happening is itself you know an incentive for people to just uh rely on centralized actors. So for a few years we've had this these proposals in the pipeline. They're called SSLE, single secret leader election that basically allow proposers to be chosen in a zero knowledge way, but where only the proposer is aware that they're propos the proposer right up until the very moment that they actually make their proposal. And actually, if we want you could even uh you know with the newer ZK stuff extends that and say you keep your privacy even after that point, right? Um and so that we've been exploring that.

Um and uh like in I think in all of these situations like you have to combine a kind of blockchain layer like data leak minimization with a network layer um equivalent and uh some form of uh onion routing and mix nets is going to be very important for that. Um and uh yeah the uh the core uh you know the core challenge here basically is uh making that uh both uh work and be fast enough and also be uh economically viable right so that people don't you know feel uh feel the pressure to give up on it and like do things like maximizing transaction fees. You said the word censorship resistance earlier and this is actually the phrase that that confused me at first because I found the the the cryptocurrency people years ago and I'm like I work on censorship resistance. We've got Russia trying to block tour. We've got China trying to block tour.

And they're like oh wow you got to come talk to us about censorship resistance. We do that too. And it it was months until I realized they meant application level censorship resistance as in you can't stop transactions from happening. And I meant network layer censorship resistance as in users can reach your network.

So China has said they don't like cryptocurrencies.

When is China going to block Ethereum at the network layer? When are they going to start rolling out great firewall style blacklists of the validators and uh and the proxies and so on and and what do we do then? Yeah, I mean know I think these are things that are really important to you know build build up uh defenses on and uh you know it's like we need Ethereum to be a globally access a globally accessible network where people from uh anywhere in the world are able to participate as users and also as uh you know nodes you know doing staking and participating in the network right and uh these are there's like a certain base level of this which is uh possible just by being a decentralized network and I think like 10 years ago that was enough and now that's not enough and uh really yeah building out the technology to go on top uh to actually yeah make it possible to have a node to have it not be immediately detectable as a node and uh at the same time like actually be fast enough is uh I mean it's a it's a super important problem. Um I mean one thing also I think proof of stake it uh often gets talked about either about helping the ETH supply go down or about not killing trees which are both good. Uh but uh it has this other benefit which is that it um allows u you like it basically means that to be one of the nodes that is holding up the network you don't need this uh huge server farm which is incredibly easy to detect and uh incredibly easy to uh censor and uh and instead like as a a proof ofstake note it's like basically you can run one off of a laptop right and uh you know in the future hardware requirements for that will uh go down even further right so that's uh something that we uh care about as well so no I think it's an ongo an ongoing journey and an ongoing process

so one of the things that we in the tour world have been working on are called pluggable transports and the idea is tour takes care of your privacy and the transport that you have inside tour browser transforms your tour traffic into some protocol that the sensor doesn't want to block and talks to some destination the sensor doesn't know to block and I was talking to Igor from PSSE and he's excited not only about adding onion services to everything and everything but also including some of the pluggable transports. There's one called Snowflake that transforms your traffic into WebRTC. And part of the goal there is to have like the wallets and the blockchain reading software not only be able to give you privacy at the network layer, but also eventually have some of these pluggable transports included so that if you're in China and you want to get to that website they blocked, then you can either it turns it on for you or you can click help, I'm being censored and then you can route your uh transaction read or write over something that still lets you reach the network.

Yeah. No, I think uh that would help a lot. I mean, I think from a yeah privacy perspective, from a censorship resistance perspective and uh even just from a resilience perspective, right? Like once you uh move away from just talking directly to a server, you know, often things break and having multiple ways to connect to a network helps things uh break less. So I think uh that's it's a major win for Ethereum and I yeah look forward to us integrating all of this.

Sounds good. We are officially out of time according to this, but according to the organizers, we've got six more minutes. So, we're going to keep talking for six more minutes. Um,

in in terms of like, so we've got some short-term plans of of ununifying, torifying a bunch of pieces of the ecosystem.

What does this look like in in a year or two once we've got

I guess what are the what are the what are the stumbling blocks between then? Do you

do you envision all the wallet operators being excited and they just do this or do you need to go one go to them one at a time and advocate to them? How how do we get from here to there?

Yeah. Uh so I think the good news is that with the Kohaku stuff that we've announced this week there's already a lot of momentum of uh wallets understanding that you know we are working on these kinds of things and uh that we are and are going to be churning out software packages that makes all of these things as uh plugandplay as possible. Um and so there's been already been interest from quite a few wallets in uh integrating these technologies. Um, another piece of the puzzle I think is uh going to be uh like basically verifying that wallets are actually doing it, right? It's uh the the difference between um you know claiming that you're decentralized as a marketing term and actually being decentralized.

And so you know like we've had a a project called L2B which like basically verifies like how trustless are individual Ethereum L2s and it publishes a bunch of information. and it kind of compresses it into you know like stage zero, stage one and stage two. Um and so there's um you know a project uh that's like still like starting early stage wallet beat uh to do a similar thing for wallets. Uh people have also suggest uh like I know talked about like doing zk beat for like zk protocols and uh like just expanding that kind of account um you know accountability layer for for the ecosystem. So that's uh important too.

Um so you know existence of technology existence of these like easy to use SDKs um like actually ver verifying that people are doing it and not just advertising that they're doing it but still collecting your data in a 100 different ways. Um like these things are all really uh important near term. Um and then if we can get to a place where like in you know one year at least wallets uh will users will be able to access wallets and we'll be able to access applications through wallets in a way that uh the users privacy is protected both on chain and in terms of their interaction with both the DAP and the RPC node. like I think that's already in a amazing goal and we'll be in a much better place and uh then you know in the strength of the Ethereum ecosystem is it's so parallelized right and so in uh five years hopefully we'll have much better user level privacy and we'll have a much more hardened and uh privacy friendly uh and resilient Ethereum network and we can have uh all of these things uh together um so um that that's exciting for What what excites you about the next 5 years of tour?

Yeah. Oh boy. Um part of the momentum of uh people around the world are starting to realize I mean we saw the the Snowden documents, we saw the NSA leaks, we see more and more companies losing their data. So there are a lot of

ordinary people out there who are who are still realizing, wait, privacy is important. And part of the part of the fun of working on all this is reaching so many different types of people who care about privacy for different reasons and helping them understand what tools are available and how they can be more safe on the internet. So uh again for me it comes down to the people. So finding all the different NOS's around the world who are trying to help their communities be safer. That's the part that that excites me and we have a lot more work to do in terms of like every time I read about a new law against uh against certain kinds of people in Uganda or like rightscon is happening in uh in Africa this coming uh couple of months and they have some laws that are making the trans LGBT LGBTQ community not not want to go to RightsCon because that country is a scary place to go to.

So, uh, while the world is realizing privacy is more important, also the governments are making it a scarier and scarier place. So, we'll see what happens when those two collide.

Yeah. Well, I think those of us who really care about privacy should remember that we have a lot more allies and a lot more people in the world who care the about the same causes than we realize. and we need to really figure out how to strengthen those uh relationships and uh work together to you know make a more private uh more free and more dignified internet happen.

Speaking of working together, one of the topics that I've been pondering so we talked uh on Wednesday about tour as a commons and like the capitalism based building block or the altruism based building block. So the tour network is made up of volunteer relay operators and as a project like Ethereum shows up and adds a lot more load to the tour network one of the things that's helpful to do is since it's a commons to give back at the relay capacity layer also and that could that could look like the Ethereum Foundation running a bunch of relays or there are a bunch of nonprofits around the world that already run relays and it could look like helping to support those nonprofits. maybe uh tell us about uh running a relay like what are what are the costs? How much compute do you need? How much bandwidth do you need?

Yeah, so uh running a relay is is just installing the tour program and editing a text file to configure it to be a relay and and having an IP address that's reachable from the rest of the world. So you can do this at your university, at your workplace, some people do it from home. In the modern world, people get uh virtual servers somewhere and run relays there. And part of the challenge with that is they all get the same virtual server at the same German company. And then we've got centralization versus diversity challenges.

Yeah. Maybe one of the things we could do is uh make it easy for stakers to also be relays at the same time.

Yes. So, yep. That would be awesome. So if if you're working on uh packaging easy staker software, come talk to us about how you could also put in a tour relay at the same time. And one of the other fun things about adding onion service support to all these things.

If you're connecting to like CNN.com over tour, you need to have an exit relay involved so you can get exit the tour network and go to that website. But if you're going to some wallet service over its onion address, you don't need an exit relay involved. So getting all the stakers running non-exit relays is uh is less of a request, less of an ask, easier for them to do. It's all about bandwidth and connectivity and not so much about uh whether it's scary or not to to be a tour relay.

So I think that would be a great easy onboarding way to help you help us help you.

Amazing. Thank you, Roger. Okay.

Automatic transcript — names and jargon may be misspelled.