Jul 28, 2017 · 20m · a16z

Dan Boneh

Dan Boneh · 17m spoken Technical Assistant · 0s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

At the a16z Academic Roundtable, Stanford Professor Dan Boneh presents a groundbreaking zero-knowledge proof protocol for Bitcoin exchange solvency, shares Stanford's new blockchain curriculum, and outlines hardware-accelerated cryptographic research.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 0.0 Guest teaching 2.8 Guest disagreement 0.2 The host pushing back 0.0
05100:0010:0020:000:09–2:46 · The host as informed peer 0/10 Session Welcome and Speaker Introductions Dan opens the conference session with housekeeping and an informal slide on Bitcoin market cap. Because this is a solo presentation without host participation, host-side metrics remain at zero.2:46–7:05 · The host as informed peer 0/10 Stanford Bitcoin Course and Curriculum Dan presents background on Bitcoin history, blockchain append-only properties, and the Stanford course curriculum. The tone is purely instructional toward the audience.7:05–15:04 · The host as informed peer 0/10 Zero-Knowledge Proof Protocol for Exchange Solvency Dan outlines the cryptographic solvency protocol using zero-knowledge commitments. An audience member asks a question about customer asset holdings, which Dan patiently clarifies.15:04–17:46 · The host as informed peer 0/10 Experimental Benchmarks and Performance Dan reviews benchmark performance graphs for proof generation. When an audience member incorrectly assumes proof failures stem from small sample sizes, Dan firmly corrects the premise.17:46–19:07 · The host as informed peer 0/10 Cryptographic Control Flow Integrity and Hardware AES Dan briefly summarizes hardware AES cycle improvements on Intel x86 microarchitectures before making announcements regarding the Stanford Cyber Initiative.0:09–2:46 · Guest teaching 1/10 Session Welcome and Speaker Introductions Dan opens the conference session with housekeeping and an informal slide on Bitcoin market cap. Because this is a solo presentation without host participation, host-side metrics remain at zero.2:46–7:05 · Guest teaching 2/10 Stanford Bitcoin Course and Curriculum Dan presents background on Bitcoin history, blockchain append-only properties, and the Stanford course curriculum. The tone is purely instructional toward the audience.7:05–15:04 · Guest teaching 4/10 Zero-Knowledge Proof Protocol for Exchange Solvency Dan outlines the cryptographic solvency protocol using zero-knowledge commitments. An audience member asks a question about customer asset holdings, which Dan patiently clarifies.15:04–17:46 · Guest teaching 5/10 Experimental Benchmarks and Performance Dan reviews benchmark performance graphs for proof generation. When an audience member incorrectly assumes proof failures stem from small sample sizes, Dan firmly corrects the premise.17:46–19:07 · Guest teaching 2/10 Cryptographic Control Flow Integrity and Hardware AES Dan briefly summarizes hardware AES cycle improvements on Intel x86 microarchitectures before making announcements regarding the Stanford Cyber Initiative.0:09–2:46 · Guest disagreement 0/10 Session Welcome and Speaker Introductions Dan opens the conference session with housekeeping and an informal slide on Bitcoin market cap. Because this is a solo presentation without host participation, host-side metrics remain at zero.2:46–7:05 · Guest disagreement 0/10 Stanford Bitcoin Course and Curriculum Dan presents background on Bitcoin history, blockchain append-only properties, and the Stanford course curriculum. The tone is purely instructional toward the audience.7:05–15:04 · Guest disagreement 0/10 Zero-Knowledge Proof Protocol for Exchange Solvency Dan outlines the cryptographic solvency protocol using zero-knowledge commitments. An audience member asks a question about customer asset holdings, which Dan patiently clarifies.15:04–17:46 · Guest disagreement 1/10 Experimental Benchmarks and Performance Dan reviews benchmark performance graphs for proof generation. When an audience member incorrectly assumes proof failures stem from small sample sizes, Dan firmly corrects the premise.17:46–19:07 · Guest disagreement 0/10 Cryptographic Control Flow Integrity and Hardware AES Dan briefly summarizes hardware AES cycle improvements on Intel x86 microarchitectures before making announcements regarding the Stanford Cyber Initiative.0:09–2:46 · The host pushing back 0/10 Session Welcome and Speaker Introductions Dan opens the conference session with housekeeping and an informal slide on Bitcoin market cap. Because this is a solo presentation without host participation, host-side metrics remain at zero.2:46–7:05 · The host pushing back 0/10 Stanford Bitcoin Course and Curriculum Dan presents background on Bitcoin history, blockchain append-only properties, and the Stanford course curriculum. The tone is purely instructional toward the audience.7:05–15:04 · The host pushing back 0/10 Zero-Knowledge Proof Protocol for Exchange Solvency Dan outlines the cryptographic solvency protocol using zero-knowledge commitments. An audience member asks a question about customer asset holdings, which Dan patiently clarifies.15:04–17:46 · The host pushing back 0/10 Experimental Benchmarks and Performance Dan reviews benchmark performance graphs for proof generation. When an audience member incorrectly assumes proof failures stem from small sample sizes, Dan firmly corrects the premise.17:46–19:07 · The host pushing back 0/10 Cryptographic Control Flow Integrity and Hardware AES Dan briefly summarizes hardware AES cycle improvements on Intel x86 microarchitectures before making announcements regarding the Stanford Cyber Initiative.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 15:57 Dan's Quick Rejection of Question Premise

Dan offers his most emphatic disagreement of the session with a rapid series of 'No, no, no, no, no' to refute an audience member's assumption about proof failure causes.

Hardest push from the host ▶ 15:57 Audience Probing Solvency Mechanics

An audience questioner challenges the validity of the benchmark results by questioning whether inadequate address sampling could cause false negatives.

Biggest teaching moment ▶ 15:57 Explaining Anonymity Sets vs Address Subsets

Dan systematically educates the audience member on why address subsets necessarily cover exchange holdings while preserving public key anonymity.

The host holds their own ▶ 14:07 Dan Explaining Obligations vs Asset Commitments

Dan demonstrates deep domain knowledge by immediately unpacking how customer obligations under sub-protocol one differ from public key asset verification under sub-protocol two.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Session Welcome and Speaker Introductions 0100 Dan opens the conference session with housekeeping and an informal slide on Bitcoin market cap. Because this is a solo presentation without host participation, host-side metrics remain at zero.
Stanford Bitcoin Course and Curriculum 0200 Dan presents background on Bitcoin history, blockchain append-only properties, and the Stanford course curriculum. The tone is purely instructional toward the audience.
Zero-Knowledge Proof Protocol for Exchange Solvency 0400 Dan outlines the cryptographic solvency protocol using zero-knowledge commitments. An audience member asks a question about customer asset holdings, which Dan patiently clarifies.
Experimental Benchmarks and Performance 0510 Dan reviews benchmark performance graphs for proof generation. When an audience member incorrectly assumes proof failures stem from small sample sizes, Dan firmly corrects the premise.
Cryptographic Control Flow Integrity and Hardware AES 0200 Dan briefly summarizes hardware AES cycle improvements on Intel x86 microarchitectures before making announcements regarding the Stanford Cyber Initiative.

Statements from this episode (10)

Insight
VCs ignore pitches without "billions of dollars" on slide one
“When, ah, when you go pitch to VCs, the first thing they tell you is like, on slide number one, you're supposed to have some word, somewhere, it's where, you're supposed to have the words, billions of dollars, somewhere on slide number one, otherwise the VCs d…”
Dan Boneh Jul 28, 2017 ▶ 1:35
Assertion Contradicted
Bitcoin market capitalization has stabilized around $3.5 billion
“Today the, you can see that in the last six months or so, things have kind of stabilized, and market capitalization is around three and a half billion.”
Dan Boneh Jul 28, 2017 ▶ 2:28
Assertion Not checkable as stated
Bitcoin is the first cryptocurrency to achieve working adoption
“This is the first cryptocurrency that's actually seems to work, that's actually been, being adopted.”
Dan Boneh Jul 28, 2017 ▶ 2:40
Insight
Blockchain is the first publicly available, append-only database
“The thing that we're excited about Bitcoin is, A, the, obviously, the currency, but what's more interesting is even the block applications of the blockchain, right? It's the first time when we have sort of an append-only database that's kind of you can put thi…”
Dan Boneh Jul 28, 2017 ▶ 3:14
Assertion Supported
Bitcoin exchange solvency can be proven without trusted auditors
“The beauty of Bitcoin is that you need no trust in third parties. And this proof of solvency can be done without, ah, any expense, any payments done to a third party.”
Dan Boneh Jul 28, 2017 ▶ 6:32
What-if
Mt. Gox insolvency would have been detected earlier with ZK proofs
“If Mt. Gox had run this protocol, their problems would have been detected much earlier than they were.”
Dan Boneh Jul 28, 2017 ▶ 7:17
Insight
Verifying 1% of balances exposes corrupt crypto exchanges
“It's enough to, say, one percent of the customers check, If the exchange cheats and actually does not include people's obligations, you know, if a small number of fraction of the, ah, ah, customers actually check that the proof is valid, a, ah, a corrupt excha…”
Dan Boneh Jul 28, 2017 ▶ 9:58
Assertion Partly supported
Generating a solvency proof for 500,000 customers takes 10 minutes
“So the exchange will take 10 minutes to generate the proof.”
Dan Boneh Jul 28, 2017 ▶ 15:53
Prediction Didn’t hold up
Intel AES round execution will drop to two cycles within two years
“In two years, it's gonna get down to two cycles.”
Dan Boneh Jul 28, 2017 ▶ 18:33
Insight
Non-AES block ciphers cannot compete with Intel hardware acceleration
“It's gonna be really hard to promote any other block cipher, because any other block cipher is gonna have to be implemented in, in software, and there's no way it will compete with what Intel did.”
Dan Boneh Jul 28, 2017 ▶ 18:49
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.