New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Building Infrastructural Resilience - Panel || Ethereum Privacy Stack, Devconncet 2025

Ethereum Cypherpunk CongressFri, Jan 9, 2026, 12:00 AM

Panel discussion with.Sebastian Burgel (HOPR, Gnosis), ml_sudo (Silviculture Society), Pol Lanski (Dappnode), Kyle Den Hartog (Brave) sharing their thoughts and ideas about nodes and how is it for them to be running their own nodes. Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/

Transcript

All right. Uh, do you mind if we just do a quick intro of who everybody is so that people can associate faces with names because I see we've got a a few pseudonmous photos there. So, uh, I'm Kyle. Uh, I work at Brave. Um, I do privacy and security engineering for us.

Um, so a lot of what brings people into the space uh within Brave is actually just they want YouTube ads uh without or no YouTube ads and then we do a lot of other stuff that we give them.

How about you Lansky?

I'm Lansky. I'm the CEO of Dabnode. Uh we do free open source software for people to run infrastructure at home. So basically for digital self sovereignty and we also are a lot into hardware because people are supposed to be running this at home. And we also provide them for hardware to be able to self-host the tools that will allow them to be private and self-s sovereign.

Thank you. Uh I'm ML pseudo and thank you. I'm ML pseudo and I do a bunch of things. Uh all these things generally tend to be technologies that help you live in a more trustless fashion where you don't have to trust an intermediary, a person, a business, etc. One of this is Zcash and the other more recently is the trustless TE initiative.

So TEES are trusted execution environments. We're trying to make trustless versions of these.

Hi there. I'm Sebastian. I'm VP tech at Nosis. And at NOS Nosis, we fork banks. Uh so we build uh resilience infrastructure applications not just for you as crypton natives but increasingly for your normie friends as well.

Uh I'm also founder of Hopper which is a mixnet on top of which we're building NosisVPN that seeks to be the most anonymous and censorship resistant VPN there is. So, as you guys can tell, there's a bit of a a mixed uh version of the the different lower layers of the stack that really kind of play into the infrastructure. Um, and so I guess one of the first questions that I have for you guys is uh within your kind of domain expertises. Um, what is the best example of network or hardware resilience um today within your mind uh and within your space? Um, so let's start with you Lansky and and kind of like the self-hosted scene,

right? So um resilience or or resistance to me is an emerging property of a system and decentralization um it's like resilience is almost one of these emerging properties out of a decentralized system. So if you have one node um you can attack that node and it goes down you have a single point of failure. You have you have two nodes you have some very basic data redundancy. If you have three nodes and they're in different countries, you might have some sort of geopolitical uh capture resilience.

And if you have a bunch of nodes all over the world that have a non- hierarchical relationship between them, then you get to a resilient system. And it's we're we're right now. And I think blockchains are a very good example of this. And Ethereum in particular has dedicated a lot of effort into creating a validator system, a validator set that is decentralized and all over the place. So, um, honestly, Ethereum is a really good example of what a resilient system is.

Yeah, go ahead, Special.

Yeah. Uh just to support Paul, I guess the canonical answer here is you know DapNote is is an example of of you know resilient infrastructure. But I would say the more contentious answer is you know uh we make people believe that proof ofstake systems you know that is what secures a network but that is incorrect. When push comes to shove nerds protect networks. So you know actually uh yeah appreciation and education of nerds and nerd culture is what leads to you know security including hardware and network resilience.

Okay. Um so I wanted to uh be a little bit spicy.

So running your own hardware is important. You know having decentralized nodes is important. Um the trustless hardware um angle is that you can do a lot of things to kind of remove trust from the software layer but if at the end of the day you can't audit your hardware you don't really know what it's doing you're not that secure it's not just me saying this blog in September uh called open hardware and verifiability something like that basically makes this statement And we can be as decentralized and trustless as we want at the software layer, but if you don't go down to the hardware layer, everything is turtles all the way down.

Yep. I think uh something to highlight there uh that came from my computer security professor is that eventually at some point even within cryptographic systems, you have to trust somewhere. And what we're trying to do is we're trying to push lower and lower and lower. Um the reality is though uh quite a few people aren't going to go dig up some sand and make their own silicone and uh then write their own chips and and take it in that sort of way. Um so I think this is uh another thing that we should kind of chat about a little bit.

Um how are you guys thinking about the trade-offs between users who don't want to maintain and run their own infrastructure but are upset with the trade-offs that exist at the application layer because of these sorts of like walled gardens that are built.

Right. Um so you're talking about unicorns. Yeah. um those those do not exist or are minimal like they there are people who who want to run and they understand what it takes and they are willing to run and there's people who put all of their private data to chat GPT and there is a middle layer and probably a lot of this middle layer is here but it is not anything that would make any sort of sense at any scale to to target uh to target specifically for except that we do because um because of what uh Sebastian was saying because there it is those nerds who add the biggest value to these networks. But going back to to your question um the tradeoffs are massive and they're not economical.

They are not uh they're not only economical. Um they are almost ideological and also you cannot expect everybody to even if they're minimally interested to say no or to renounce to make the sacrifices that it takes to to become private. So ideally we build systems that push and push this boundary of trust further away and and we let people connect to that through an RPC and yes they are trusting this RPC but at least there's some verification on this RPC um that can be done at browser level for example uh with a light client with whatever it is and uh and and there's like a green check most people will not know what this green check is but it it gives to the rest of them the assurance that they're connecting to a system that has some asurances of of safety.

Yeah. Um so I think that the trade-off space is also realizing or important part about this trade-off space is it's not as big. So maybe I disagree there with Paul like just you know to gauge this who here in this room like is or has been running adapto? Hands up please. Woo.

Like,

okay, congrats first of all for everyone who's been running a Dubnote, right? But secondly, everyone who did not have their hand up, like why not? I'm not going to put you on stage and actually ask you, but like this is possible, right? So, this is about like engagement, caring, and you know, fostering a culture of actually engaging and securing the networks that we actually built here. So as somebody who builds a project of anything in the space whatever it is if it's you know I'm interested very much in a data exchange side there's other people interested in the money issuance side there's other people interested in you know data storage side whatever it is what you are actually doing here is you are enabling people that showed up their hand to run stuff for you and you're enabling those people who did not show up their hand to do so in the future and as an individual in the space what you are actually doing here is you're not swapping like meme tokens to make a quick buck because well that's just not going to go well and either you learned that already or you're going to learn it.

You're actually participating in these networks. So this trade-off space for me is about realizing that this gap is not as big as it seems and we have to actively contribute to increase and lower the barriers and increase the number of people who can actively participate. This is our duty in this space. This is the actual value contribution.

Okay, I have a spicy response to that.

Michelle's here all for the spice. I love it.

So, I don't think the way to make people run more nodes is to say everybody should be a nerd. I think nerds will always be, you know, a small part of the population. Um, I think the problem now is that it is very hard. Among all the many nerds I know, I only know one who wants to stab himself every day by running his own mail server. Like I think it's unrealistic to say everybody should.

It's part of your duty. You help you know the network, whatever. I think more work needs to be done on making it easy so that you know all the people who didn't raise their hands. I bet at least oneird thought I want to do this but it doesn't fit my setup, my lifestyle, you know, my my constraints. So, for example,

but but but that you're saying eventually everybody should run their node.

They should, but we shouldn't say you you have to do it now otherwise you're failing your duty. It is

Oh yeah, sure. Okay. Well, to to that I agree there is more work needed, but the end goal should be everybody should run their node and I agree this is a mess. It shouldn't take you know 700 gigabyte minimally to run a node. Um and it should not take you know a couple of days to sync it up.

A bunch of progress is being made towards that which is great. But ultimately we should converge in a world where you know things are actually you know unruggable by some you know centralized service providers because you do run your own node. We have to like uphold that as a goal I think. And I think something to add to that is if you're not at the point of being able to run your own node, one of the simplest things that you can do is vote with your feet by connecting to somebody else who's running their own node. So in that sort of sense, like a very simple answer of of what happens today is you can leave Gmail, you can go to Proton Mail, you can go to a lot of these sort of usable systems that exist and vote with your feet.

And by doing that, you're disempowering the centralized wall gardens that we have today and showing and reinforcing those sorts of feedback. And so I think with that too, um, some of the participation that we we see from like kind of the normal users, um, that's like I think a powerful lesson that we can we can use here as well if you're not wanting to run your own node today.

Right. There there's a very very very interesting point in here and at at the very core of when we started uh dab node was the idea that you could provide to your community um and one person would be running a dab node and it would give access to IPFS. It would be it would give access to an Ethereum node any sort of infrastructure maybe like a an instance of next cloud or own cloud or image for the centralized image self-host anything for the community right there's this one nerd and then the community drinks from it. Um but some things that have maybe economical value have just sort of like let made us close this a little bit more. Oh, if I'm running my Ethereum validator, maybe I'm not going to open this this node to to everybody else.

So here is the the next stage is creating systems where this trust this implicit trust that we have for our node into other people can be eliminated. Can we create a verification system on top, a cryptographical verification system on top where I as a consumer I can use a service um that so again going to Ethereum and RPCs I can connect to infura which is a company and it has a reputation and centralizes everything and al they also get a lot of money or I can connect to the centralized RPC and get information from a random person that is running a note and is offering uh access to to that note and this layer. But then the question is I trust infura because they have a reputation but should I trust this random dude on the internet and building that system for verification in in between is sort of like the gap that we have now. Um I think this is probably the most exciting application of of zero knowledge uh that we have right now. Paul, sorry.

I mean, doesn't it sound that instead of trusting my friends, I should now rely on some weird kind of technology because humans can't trust each other? Like, shouldn't we rather like focus on a societal aspect of no, you know what? Like, there's a couple of people here in this room who all care. Like, isn't it enough? And like, we as a community gather up instead of like bringing tech because humans fundamentally in their nature fail to coordinate.

Like, we're not all that autistic, are we? that's already built. We already have this that we you can already share your node with your friends. You can already do this and we're not seeing implementation at maybe at browser level of like being able to choose your RPC or being able to connect to your friend because like there's

because we foster a culture where you can slap a token onto it and you know share it through you know another network.

Yes. um among other things.

Sudo, I want to have you jump in here a bit too and and talk a little bit about um kind of how uh we can exhibit kind of like practical privacy um when we're utilizing these sorts of things. And so I think this is what is interesting about the TE space is we may be taking trade-offs in terms of uh centralization or decentralization um in order to get these sort of things deployed um but we're making it easier for deployment structures in order to get more trustlessness with it and can we do very simple things where we don't need fancy crypto for the the privacy but instead I can audit the uh you know the Docker container that's running in there and see that there's no logs that are actually logging this data in the first place. So, do you want to talk a little bit about kind of like how you see the the trustless um TE uh contributing to this movement?

Yeah, so TES have been in use for quite a while, something like 20 plus years. Um, and the problem with them today is that they're extremely vulnerable to physical attacks or so-called side channel attacks. And in fact, in just the last month or so, there have been several researchers that published research show showing pretty inexpensive ways to um side channel attack these TEES. But at the same time, they remain very useful um in terms of being able to do a lot of computation in a secure fashion um without having to rely on you know other technologies ZK, FHE that are still pretty frontier. They're very limited in computation.

So um the question is how to make them more secure and the reason they haven't been secure now even though you have lots of large companies working on them is they have actively chosen to choose performance over security. Um they even have written papers about this and the reason for that the reason it's not an insane decision for them is their their threat model is this TE is going to be hosted by Amazon or Google in a very secure location with multiple layers of uh physical security access controls etc. So it's not crazy to make that tradeoff. The problem is now as we technology in the last uh I don't know 40 to 50 years has been built in an environment which is pretty benign. You have one to four major powers building technology.

They generally like each other. They trust each other to some extent but like the world is fracturing right with people hate each other. They have the economic might to fight each other. And um with Snowden's revelations, we now know that you know we can't really trust the things and the people that we have trusted in the past. So the way we make hardware hasn't changed and it's pretty crazy to think about it that way.

So we have to make hardware in a way that fits today's threat models which is all over from all directions and that's what so I'm working on a trustless TE initiative where we are trying to make TEEES that are uh physically secure against these threat actors and and make them also fully open. So one thing uh that's one thing that is a few people know is every Intel chip that has been shipped since 2008 has a little component called the management engine which has extremely low-level access to everything that the chip is doing. And we're trying to go beyond that by making a fully open-source uh chip, not just in the blueprints for the chip, but all the way to manufacturing the actual physical chip that you hold in your hands. This is a this is a wild endeavor because doing hardware is so hard and you can spend years creating something with open plants but as soon as you go to manufacturing

you have to commit the money.

Yes. And if then after starting to print some attack is discovered and there is a physical aspect of it that needs to be improved, you need to restart the process again. And I think this is also a a reason why Intel or or the the TE providers as well just decided to take them off their consumer hardware and go with the trust assumption that the person that's running it, Google etc. what you were saying that uh because it's so expensive you in order to do something like this you need to be prepared for things to go wrong and they will go wrong and it will be very expensive

it's also very expensive when your nuclear reactor spins out of control

extremely expensive

um so I think this kind of hits at uh something that I heard in a talk uh previously a little bit about um kind of it was during DACK day about uh open hardware and kind of the the struggles that they ran into within the hardware space. Um, so how do you guys see that open hardware plays within this kind of movement to help us build this sort of infrastructure resilience? Like um I know with people like running nodes uh within Hopper um for the hopper net uh people are supposed to be running this themselves but there's no sort of assumption about uh that the hardware is not being invalidated in some sort of way because we're doing all of the uh trustlessness at the architecture layer. So, how do you think like uh open hardware uh may assist in being able to run these sorts of networks and potentially solve for some of these like trade-offs here that occur?

Yeah. So, I applaud any and all efforts towards open hardware and um yeah, I mean basically it comes down to I think the best we can do right now is rely on highly standard commoditized components, right? So I sometimes see projects go, oh we we could be way faster if we add this little chip which you know you can buy like it exists. It's like okay and that ship has one vendor right um that is closed source I have no idea how it actually works that is not helping right so I think the best we can do is have you know all the things that Michelle just mentioned is on getting us towards you know something that is verifiable but ideally have something which is running on retail available commodity hardware that's I think the best we can do and that's why you know I Like I I bring up the word dubnote a lot. Sorry, Paul.

But you know, run that not just on their hardware, right? They they ship these boxes, but run it on your own, right? We need we need a wide variety of retail available hardware, you know, to secure the networks that we that we support. Like in our case, a mixet like a mixet has the assumption that at least one node along your relay chain where you transmit data is honest, right? So what honest actually means is it entails a lot but it also entails that we have not just everything running on you know Intel pre-fabricated hardware and I would love to see more and more diverse open hardware to secure these networks in a trustworthy fashion not ending at the compiler level but going beyond that.

So I think something that would be a takeaway that would be important for us to talk about is the why factor here. Um why should we care? Um uh essentially what I'm trying to get to is um how are you thinking about the importance of these like sort of network uh infrastructure resilience um running your own nodes with self-hosting um how is this actually helping us at the human level to exert our values like how is this helping us to the right to privacy? How is this helping us to the right to self-determination and the ability to resist censorship which are common core values that we have within the network? Um, how are you guys thinking about uh how the technical actions we take play into our ability to experience the human uh and the social aspects a little bit more?

Um, who wants to jump in on that one? Sudo, you got an opinion or Lansky? So I think with the rise of AI and threat actors that can access you from anywhere in the world because everything's connected now the only way to remain human to engage with each other in human ways is to be able to trust who you're dealing with what you're dealing with. So I think all this trustless enabling technology will help us remain more human. Like right now just I just I just can't imagine a world where I go around and I don't know if this is really from my mother or like this is from somebody who's doing what they're saying they're doing.

It's it's really scary for me. And so if I can get past that through trustless technology, I think I can interact more naturally and freely with people.

100%. Um on the privacy aspect, I always like to say the the same story. Um which is why why privacy is important and why why do we need systems that protect us way before we even know that we need to be protected. Uh why this data should just simply not be out there. Um and the the reason is so in in the Netherlands before World War II, they had one of the fairest tax systems in the world.

And one of the things that they try to do is to uh distribute their religious budget onto uh the population according to the percentage of the population that subscribe to a particular religion. Meaning that if there's an 11% of Muslim population, 11% of the religious budget would go to uh Muslim associations etc etc. What happened is World War II comes in and Hitler only has to go to the census office in Amsterdam and has the name and address of every single Jew in the Netherlands. And that's why the Netherlands has the highest mortality rate per capita of Jews of Jews in the Holocaust because this information which nobody can say that the reason they were capturing this information wasn't fair. The opposite.

It was probably it was a very fair and very judicious way that they would want to capture this and and it was for a good reason. But as long as this data exists,

you never know when another crazy guy with a mustache will come in and we'll use this data for the wrong side. So that's why that's why I think privacy is important. That's why I think thinking about these things before they become important is is crucial to protect ourselves.

Yeah, exactly that. I mean like as somebody from America I avoid I I'm afforded the luxuries in a lot of cases uh that I don't have to exert these rights in a lot of cases. Um I no longer live there but I get to see how thing things like that are kind of changing. Um and as I've heard it described through the historical perspective there's kind of uh there's a name for this. Uh it's called the bad emperor problem.

Um, so I think it's important for us to talk a little bit too about kind of some of the legal things that come into play here and and tie this back into the technical perspective. Um, I'm sure a lot of people here are familiar with the idea of chat control. Um, but I don't know if people also are aware that there's uh talks about uh KYCing crypto wallets uh forcing self-custody crypto crypto wallets to KYC in order to to on board. Um, there's also uh age verification laws that are passing with this as well. Um so uh within uh for example the UK one of the things that's happening quite naturally is that uh VPNs are being used in order to push back on resisting the law because it is a legal way that you can resist it today.

Um, and hopefully I don't need to talk with a lawyer after this talk, but um, uh, so with that, um, Sebastian or anybody up here, um, since I know this is a little bit, uh, kind of like pushing in this, how do you guys see that the infrastructure and the things that we're doing, um, are actually important, uh, like precursors to be able to push back on some of these things that we consider to be immoral within our community, but may not be shared by others uh, within the legal legal side of the government.

Yeah, definitely. I mean, as you build, you know, technology that can be also used by bad actors, I think it's firstly worth acknowledging that we don't want bad actors, right? So, the intent of the regulator and our, you know, purpose of doing stuff is aligned. I do not want to help North Korea. I do not want to enable any pedos out there, right?

I want to stop all of that and I will do whatever I can to stop them. But coming in because you have the mon monopoly on violence and like stopping you know users from you know having weird age verification on porn in the UK which then like you know whatever I think about that is you know is secondary but like you shouldn't infringe you know user rights on that which then carries over to VPNs. Like that's absurd right? So building technologies that not just I I I think pushing back on the state is kind of like a framing that's not very helpful. I would say we are aligned right and also when talking to regulators I think we have to embrace more a narrative even though I hate a lot of that right believe me I hate a lot of regulation of embracing the narrative of saying we are aligned we want the same thing we protect the people you do it via regulation and laws we do it with technology we want the same thing though you want to jump in here too because I know you have some interesting experience with where you live

yeah right um being being Catalin um the Spanish government has actively censored in the past ways of uh Catalin expression and referendums. Um, so we the the the main goal here is that as long as you have let's say the chat control passes and and it's accepted the the way to go against this is civil disobedience same as using VPNs for for avoiding chat verification for example and civil disobedience goes through um using alternatives to what they're censoring meaning um if a a company that is established in any jurisdiction they have to abide by the laws. they they need to put whatever chat control whatever uh whatever the law has passed but using then therefore using something where you can just connect to another pro you don't have to connect to that company that has to comply even if they don't want to they they have to comply but me running my dab node at home running a relayer for tornado uh or for tour or for any sort of technology or even for for signal or for another that allows you to to uh to to run relayers yourself and giving access to my community. This is when it becomes crucial this civil disobedience and at some point a critical amount of the population is using these other systems and the law becomes inapplicable uninforceable

to to add to that I think like one way if you're building one of these technologies it may be very frustrating not enough people uh you know adopting etc even though it makes a lot of sense to you and other nerds. Um but like the way I like to think about it is if you look at the example of VPNs if you built a VPN about like 15 20 years ago you built it because you believed in these values in anti-serveillance and privacy and liberty etc. But then what made you very rich over the last 15 20 years is the fact that you could not predict that Snowden did what he did right Snowden was the first major tailwind for VPNs and then you know people really want to watch Netflix excess content from other countries that was your second tailwind so like for me like the the lesson in that is keep doing what you're doing

patiently scrappily and one day a major tailwind will come pick you up. Maybe chat control is that third tailwind.

Yeah, definitely. So for for decentralized social media, I I see that that will probably be a tailwind for it. So um with that, I see that we're at time. So I appreciate that everybody coming up here and and joining the conversation, mixing a little bit of tech and politics. Um thank you guys.

Uh I think it's important that we push the Overton window a little bit.

Automatic transcript — names and jargon may be misspelled.