commit 610b4ace10a8c2db54e016704cd59e034353f5f3
parent 2f68823360ec8bb1a4a9e81ce7140bd0d6b439dd
Author: Iván Ávalos <avalos@disroot.org>
Date: Fri, 18 Sep 2026 15:36:23 +0200
add missing files for Datenspuren 2026
Diffstat:
2 files changed, 436 insertions(+), 0 deletions(-)
diff --git a/presentations/2026-datenspuren/.gitignore b/presentations/2026-datenspuren/.gitignore
@@ -1 +1,9 @@
svg-inkscape/
+*.nav
+*.out
+*.log
+*.pdf
+*.aux
+*.vrb
+*.toc
+*.snm
diff --git a/presentations/2026-datenspuren/slides-datenspuren.tex b/presentations/2026-datenspuren/slides-datenspuren.tex
@@ -0,0 +1,428 @@
+\documentclass[aspectratio=169,t]{beamer}
+
+\input texinputs/taler-macros
+
+\usepackage{svg}
+\svgsetup{inkscapearea=page}
+\usepackage{tikz}
+\usepackage{ragged2e}
+\usepackage{graphicx}
+\usepackage{bbding}
+\usetikzlibrary{positioning,fit,patterns}
+
+%
+% Presentation at "Datenspuren 2026"
+% Copyright (C) 2026 Iván Ávalos, ....
+%
+% This program is free software: you can redistribute it and/or modify
+% it under the terms of the GNU General Public License as published by
+% the Free Software Foundation, either version 3 of the License, or
+% (at your option) any later version.
+%
+% This program is distributed in the hope that it will be useful,
+% but WITHOUT ANY WARRANTY; without even the implied warranty of
+% MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+% GNU General Public License for more details.
+%
+% You should have received a copy of the GNU General Public License
+% along with this program. If not, see <http://www.gnu.org/licenses/>.
+%
+
+% *Especially* edit these...
+% \setbeameroption{show notes on second screen=right} % Both
+
+
+\newcommand{\SPEAKER}{Iván Ávalos}
+\newcommand{\DATE}{19.09.2026}
+
+\newcommand{\TITLE}{GNU Taler: Lose your phone, lose your money?}
+\newcommand{\SUB}{Datenspuren 2026}
+\newcommand{\AUTHOR}{Iván Ávalos}
+\newcommand{\INST}{https://www.taler.net/}
+
+% Do not edit this part
+\title{\TITLE}
+\subtitle{\SUB}
+\date{\DATE}
+\author[\SPEAKER]{\AUTHOR}
+\institute{\INST}
+
+\usepackage{amsmath}
+\usepackage{multimedia}
+\usepackage[percent]{overpic}
+\usepackage{url}
+\usepackage[absolute,overlay]{textpos}
+\usepackage{listings}
+
+\usepackage{tikz, xcolor}
+\usetikzlibrary{shapes,arrows,positioning}
+\tikzset{
+ %Define standard arrow tip
+ >=stealth',
+ %Define style for boxes
+ punkt/.style={
+ rectangle,
+ rounded corners,
+ draw=black, very thick,
+ minimum width=3.5em,
+ minimum height=2em,
+ text centered},
+ % Define arrow style
+ pull/.style={
+ <->,
+ thick,draw=red,
+ shorten <=2pt,
+ shorten >=2pt,},
+ % Define arrow style
+ pil/.style={
+ ->,
+ thick,
+ shorten <=2pt,
+ shorten >=2pt,}
+}
+
+\usetikzlibrary{shapes,arrows}
+\usetikzlibrary{positioning}
+\usetikzlibrary{calc}
+
+
+\begin{document}
+
+\frame{\maketitle}
+
+\begin{frame}{What is GNU Taler?}
+ \begin{columns}[T]
+ \begin{column}{0.62\textwidth}
+ \begin{itemize}
+ \item \textbf{Private} like cash, but digital!
+ \item Your money is stored locally \textbf{in your wallet}.
+ \item Your bank has no record of your purchases.
+ \item Not a new currency nor married to any.
+ \item Pay online without registration.
+ \item 100\% free software!
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.36\textwidth}
+ \centering
+ \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/wallet}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}{How does it work?}{General overview}
+ \centering
+ \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/TalerDiagram}
+\end{frame}
+
+\begin{frame}{How does it work?}{Withdraw coins}
+ \centering
+ \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/flow1}
+\end{frame}
+
+\begin{frame}{How does it work?}{Pay anonymously}
+ \centering
+ \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/flow2}
+\end{frame}
+
+\begin{frame}{How does it work?}{Deposit coins}
+ \centering
+ \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/flow3}
+\end{frame}
+
+\begin{frame}{Self-custody: bug or feature?}
+ \begin{columns}[T]
+ \begin{column}{0.62\textwidth}
+ \begin{itemize}
+ \item Your money and purchase history are stored \textbf{locally} in your wallet.
+ \item Your are responsible for keeping them safe against \textbf{loss}, \textbf{theft}, or \textbf{unauthorized access}.
+ \item Your bank and exchange have no record of your individual purchases.
+ \item You can only spend money from the wallet(s) where you have it stored.
+ \item \textbf{If you lose your phone, you lose your money!}
+
+ ... unless...
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.36\textwidth}
+ \centering
+ \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/cliff}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}{...you do backups!}
+ \begin{columns}[T]
+ \begin{column}{0.62\textwidth}
+ \begin{itemize}
+ \item Create a copy of your wallet regularly.
+ \item Simple, right? However:
+ \begin{itemize}
+ \item What is the size of the backup?
+ \item Where do you store the backups?
+ \item How do you keep them safe and private?
+ \item Is deleted data really gone?
+ \item How often do you backup?
+ \item What happens if you restore a backup twice in two different wallets?
+ \item ...and then try to spend the same money on both at the same time?
+ \end{itemize}
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.36\textwidth}
+ \centering
+ \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/copies}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}{What is the size of the backup?}
+ \begin{columns}[T]
+ \begin{column}{0.62\textwidth}
+ \begin{itemize}
+ \item Each coin in the wallet is represented by a \textbf{keypair} and a \textbf{signature}.
+ \item Transaction history (purchases, withdrawals, etc.) can grow indefinitely.
+ \item Purchases can contain images, such as merchant logo and product
+ images, which are often stored multiple times.
+ \item Large old wallets will take longer to backup/restore and require more storage.
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.36\textwidth}
+ \centering
+ \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/size}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}{Where do you store the backups?}
+ \begin{center}
+ \includesvg[width=\textwidth,height=0.50\textheight,keepaspectratio]{assets/storage}
+ \end{center}
+ \begin{itemize}
+ \item If storing them \textbf{locally}, do you trust the storage medium?
+ \item If storing them \textbf{remotely}, do you trust the service provider?
+ \end{itemize}
+\end{frame}
+
+\begin{frame}{How do you keep them safe and private?}
+ \begin{center}
+ \includesvg[width=\textwidth,height=0.40\textheight,keepaspectratio]{assets/eyebackup}
+ \end{center}
+ \begin{itemize}
+ \item \textbf{Goal:} disclose as little as possible about the wallet contents.
+ \begin{itemize}
+ \item Which encryption scheme and at which level to encrypt?
+ \item How to prevent metadata from being leaked to the backup service?
+ \end{itemize}
+ \end{itemize}
+\end{frame}
+
+\begin{frame}{Is deleted data really gone?}
+ \centering
+ \includesvg[width=\textwidth,height=0.50\textheight,keepaspectratio]{assets/deletion}
+ \begin{itemize}
+ \item ...both from the wallet and from all backups?
+ \item ...as well as the evidence that it was deleted?
+ \end{itemize}
+\end{frame}
+
+\begin{frame}{How often do you backup?}
+ \begin{columns}[T]
+ \begin{column}{0.70\textwidth}
+ \begin{itemize}
+ \item Once a day, once a week, once a month?
+ \begin{itemize}
+ \item \textbf{Achtung!} Money can be lost if the wallet gets lost before a backup!
+ \end{itemize}
+ \item After completing a withdrawal?
+ \item After completing a purchase?
+ \begin{itemize}
+ \item \textbf{Achtung!} Timing can reveal behavioral patterns!
+ \item ...also, planchets \textbf{before} a withdrawal completes are still valuable.
+ \end{itemize}
+ \item Again, how much time/bandwidth for each backup?
+ \begin{itemize}
+ \item Is it all in one go or incremental?
+ \item If fast and efficient, it can be done more often.
+ \end{itemize}
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.30\textwidth}
+ \centering
+ \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/time}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}{Restore a backup twice and pay twice?}
+ \begin{center}
+ \includesvg[width=\textwidth,height=0.50\textheight,keepaspectratio]{assets/doublespend}
+ \end{center}
+ \begin{itemize}
+ \item Double spending is imposible, since the exchange keeps track of spent coins.
+ \item Wallets still need to handle this gracefully and select only unspent coins.
+ \begin{itemize}
+ \item (Exchange can tell you which of your coins were already spent.)
+ \end{itemize}
+ \end{itemize}
+\end{frame}
+
+\begin{frame}{If everything works nicely...}
+ \begin{columns}[T]
+ \begin{column}{0.62\textwidth}
+ \fontsize{9pt}{12pt}\selectfont
+ \begin{itemize}
+ \item \CheckmarkBold \, Backups are small, efficient and incremental.
+ \item \CheckmarkBold \, Stored securely with minimal metadata leakage.
+ \item \CheckmarkBold \, Happen on schedules that reduce data loss potential.
+ \item \CheckmarkBold \, Wallets handle double spending gracefully.
+ \end{itemize}
+
+ Then why not go ahead and use it also to \textbf{sync} wallets?
+
+ \begin{itemize}
+ \item Allow multiple devices to share the same wallet.
+ \item On every backup cycle:
+ \begin{itemize}
+ \item download only new increments.
+ \item \textbf{merge} remote increments with the local state
+ \item \textbf{delete} data that is no longer in the backup
+ \item \textbf{encrypt} local increments and upload them
+ \end{itemize}
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.38\textwidth}
+ \centering
+ \includesvg[width=\textwidth,height=0.65\textheight,keepaspectratio]{assets/sync}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}{After many discussions...}
+ \centering
+ \includesvg[width=\textwidth,height=0.60\textheight,keepaspectratio]{assets/discussions}
+\end{frame}
+
+\begin{frame}{Incremental Wallet Backup and Sync}{Design Document \#92}
+ \begin{itemize}
+ \item \textbf{Incremental}: uploads only new changes, not the full wallet
+ \item \textbf{Encrypted}: backup data stays end-to-end encrypted
+ \item \textbf{Two-layer storage}: block DLL for state, hash-indexed object store for blobs
+ \item \textbf{Efficient}: restore only downloads new and updated blocks (TODO)
+ \item \textbf{Conflict-free}: CRDT-based merging keeps multiple devices consistent
+ \item \textbf{Plausible deniability}: removed data is silently redacted from the backup
+ \end{itemize}
+ \textit{Still a work in progress!}
+\end{frame}
+
+\begin{frame}{Architectural overview}{Incremental Wallet Backup and Sync}
+ \centering
+ \includesvg[width=\textwidth,height=0.80\textheight,keepaspectratio]{assets/architecture}
+\end{frame}
+
+\newsavebox{\blockstorebox}
+\begin{frame}[fragile]{Block store}{Incremental Wallet Backup and Sync}
+ \begin{columns}[T]
+ \begin{column}{0.60\textwidth}
+ \fontsize{10pt}{12pt}\selectfont
+ \begin{itemize}
+ \item Each block contains a set of wallet \textbf{increments} (i.e. changes in state)
+ \item Identified in the double-linked list by a \textbf{nonce}.
+ \item \textbf{Versioned} to prevent replacement attacks.
+ \item \textbf{Encrypted} using its own symmetric key derived by the wallet per block (\textit{libsodium secretbox}).
+ \item \textbf{Kilobyte-padded} to minimize metadata leakage based on size.
+ \item Every DLL operation must be \textbf{authenticated} via a signature generated by the wallet.
+ \item \textbf{Bloom filter} is used to efficiently compare and find updated blocks to restore (TODO).
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.40\textwidth}
+ \begin{lrbox}{\blockstorebox}
+ \begin{minipage}{\columnwidth}
+\begin{verbatim}
++----------------------------
+| version number (2 byte) |
++----------------------------
+| nonce (24 byte) |
++----------------------------
+| serial (8 byte) |
++----------------------------
+| JSON length n (4 byte) |
++----------------------------
+| gzipped JSON (n byte) |
++----------------------------
+| padding (to next full KB) |
++----------------------------
+\end{verbatim}
+ \end{minipage}
+ \end{lrbox}
+ \resizebox{\columnwidth}{!}{\usebox{\blockstorebox}}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}[fragile]{Object store}{Incremental Wallet Backup and Sync}
+ \begin{columns}[T]
+ \begin{column}{0.60\textwidth}
+ \fontsize{10pt}{12pt}\selectfont
+ \begin{itemize}
+ \item Allows binary objects to be stored \textbf{deduplicated} in the backup.
+ \item Objects can be referenced by blocks using an identifier derived
+ from the hash and the secret key of the wallet.
+ \item \textbf{Encrypted} using a symmetric key derived by the wallet
+ for each object from its contents (also \textit{libsodium secretbox}).
+ \item \textbf{Reference counted:} objects with count zero are garbage
+ collected after a configured period of time.
+ \end{itemize}
+ \end{column}
+ \begin{column}{0.40\textwidth}
+ \begin{lrbox}{\blockstorebox}
+ \begin{minipage}{\columnwidth}
+\begin{verbatim}
++----------------------------
+| version number (2 byte) |
++----------------------------
+| data length n (4 byte) |
++----------------------------
+| gzipped data (n byte) |
++----------------------------
+| padding (to next full KB) |
++----------------------------
+\end{verbatim}
+ \end{minipage}
+ \end{lrbox}
+ \resizebox{\columnwidth}{!}{\usebox{\blockstorebox}}
+ \end{column}
+ \end{columns}
+\end{frame}
+
+\begin{frame}{Signatures}{Incremental Wallet Backup and Sync}
+\end{frame}
+
+\begin{frame}{Increments}{Incremental Wallet Backup and Sync}
+\end{frame}
+
+\begin{frame}{CRDT}{Incremental Wallet Backup and Sync}
+\end{frame}
+
+\begin{frame}{Deletion}{Incremental Wallet Backup and Sync}
+\end{frame}
+
+\begin{frame}{Wallet implementation}{Incremental Wallet Backup and Sync}
+\end{frame}
+
+\begin{frame}{Demoooooo!!!}
+\end{frame}
+
+\begin{frame}{Limitations}
+\end{frame}
+
+\begin{frame}{Future work}
+\end{frame}
+
+\begin{frame}{References}
+\end{frame}
+
+\begin{frame}{Acknowledgements}
+\end{frame}
+
+\begin{frame}{Contact}
+\end{frame}
+
+\end{document}