Daniel Filan

Privacy vs proof of character

Below, I outline some musings I’ve produced while thinking about the private cryptocurrency Monero. I make no pretense to originality, cleverness, or exhaustiveness in covering considerations.

There are (at least) two distinct types of privacy. For instance, suppose you have an item in your house that you want nobody to see, even an intruder. One way you could handle this would be to buy a large black safe and hide the items in the safe, locked with a key that only you possess, and leave the safe on your desk. The other way would be to build a similar safe into a wall, and put a framed portrait in front of the safe. In the first case, an intruder can tell that they can’t open the black safe, but they know that you have something that you wish to keep hidden. In the second case, unless the intruder is perceptive enough to look behind the portrait, they will not even be able to tell that you have anything to hide. One could imagine an even better-concealed safe that would take painstaking effort to find - for the sake of this post, please imagine that it is very difficult to imagine that there might be anything on the wall behind a portrait.

You might prefer to own the second type of safe rather than the first, because the very fact that you possess something that you do not want others to see conveys almost as much as the sight of the item that you want to conceal. For instance, if you own something that proves that you violate certain social norms, the reason that you want to conceal it is to make others think that you actually abide by social norms - but if people only conceal things that do not abide by social norms, the fact that you are concealing something demonstrates that you do not, the very fact that you wanted others to remain ignorant of!

The hidden safe has another interesting property. If hidden safes exist, and it would be possible for you to install one in your home without others finding out, then it becomes extremely difficult for you to prove to others that you do not own a hidden safe. You could bring others inside your house, but in order to prove that you do not own a hidden safe you would have to take them thru a detailed enough level of search where they could find the hidden safe if it existed, which by hypothesis is no simple matter. Furthermore, in conducting such a search you would not be able to avoid parts of your walls that have embarrassing photographs of you as a child, while if you wanted to prove that you didn’t own a large black safe, you could cover up those photographs without any detriment.

This second property sometimes holds by design. For instance, take the case of the secret ballot. In many jurisdictions, it is not just possible to fill out a ballot in a booth where nobody else can see what you are doing, it is mandatory, and illegal to e.g. take photographs of your ballot to show others. This is precisely so that you cannot prove to others how you voted, so that votes cannot be bought or coerced.

The result of the second property is that it makes certain types of ‘proofs of character’ impossible. Consider the following scenarios:

  1. Alice is running for a position in the local branch of her preferred political party. Others suspect that she may actually be disloyal to the party. In order to increase people’s trust that she will act in the best interests of the party, Alice would like to prove that she voted for the party in the most recent election.
  2. I run a podcast where I interview AI alignment researchers about their papers, some of whom are personal friends of mine. People listening could be unsure that I’ve asked all relevant questions, and suspect that I have entered into an arrangement to ‘go soft’ on some interviewee in exchange for some kind of benefit. In order to demonstrate my integrity, I might like to show that no such conversations have ever taken place, and show the history of any financial dealings I have with interviewees.

If elections are run by secret ballots, then 1 is impossible. Regarding 2, if it is possible to have unrecorded conversations with others without special software, then I can’t prove that I have never had an untowards discussion with an interviewee. Furthermore, there is a cryptocurrency called Monero that has the property that nobody can tell who anybody is transacting with or how much they are transacting for (similarly to how cash works, and differently to how most blockchains work). There is currently a project called Kovri which aims to make it so that someone can access the Monero network without this fact becoming known by e.g. one’s internet service provider. As such, if Kovri were successful, as long as one could conceal a piece of paper containing one’s private keys, it would be a trivial matter to make a Monero transaction using Kovri and then delete the software used to do so from one’s computer, making it impossible to find out that the transaction ever took place or indeed that one ever used Monero without difficult forensic techniques. This means that I would be unable to prove that I have not received money from an interviewee without submitting to arduous and invasive scrutiny.

I regard it as somewhat unfortunate that this second type of privacy leads to the impossibility of proofs of character. An abating factor is that as far as I can tell, people very rarely seem to want to prove their character even when this is possible. For instance, one could film one’s whole life for several years before going into politics in order to prove virtue, quick-wittedness, and a lack of any ill-intent. These would seem to be desirable properties of leaders of countries, and yet I am unaware of any serious candidate doing such a thing. Perhaps a counterexample is the common custom of US presidential candidates to release their tax information before presidential elections, but this is hardly exhaustive, and might be rendered obsolete by the refusal of a recent presidential candidate to do so. My guess is that the lack of such proofs is caused by a combination of the poor character of such candidates relative to an ideal candidate, the paucity of scenarios where such a proof would be desired (either due to a lack of importance of such character, or a lack of relevant doubt), and a desire to not prove that one is extremely unusual.