On 8th August 2022, the United States Treasury sanctioned Tornado Cash, a cryptocurrency mixer, adding forty-five Ethereum addresses to the list of Specially Designated Nationals. Two days later, the Dutch Fiscal Information and Investigation Service arrested Alexey Pertsev, a Tornado Cash developer. These events are turning points for the cryptocurrency space as they impact individual privacy and financial sovereignty for all users. We argue that these actions not only undermine their goals to enforce existing laws, but also show a fundamental misunderstanding of how the web operates and is regulated today.
To understand why, it is important to distinguish the dialectical relationship between platforms and protocols.
Over the past twenty years, technology activists, such as the Electronic Frontier Foundation, as well as private companies like Apple, have fought to establish legal precedents that code is protected speech, and that developers should enjoy First Amendment privileges. Nevertheless, internet technologies can facilitate crime, thus individuals and private companies are required to cooperate with state agencies i.e. taking down harmful content, disclosing metadata, etc. Yet, not all software can or should be regulated, censored, or otherwise restricted. This begs the question: which forms of software should be? To answer this question, one must distinguish between protocols and platforms.
A protocol, put simply, is an agreed way in which participants share meaningful messages. Often, it involves no central authorities, are extendable, and provide a point upon which developers can build services, including profit-generating ones. Such services, which abstract away the details of the underlying protocol, are platforms.
Importantly, a platform is a service offered by private entities at their sole discretion. It often operates atop one or more protocols. The Facebook social network, for instance, is a platform, as it is controlled by a company, and runs atop protocols like the domain name system (DNS). While the user of a platform typically consumes and creates content, the platform operator can subject them to restrictions, censorship, or deny them access completely.
We argue that some components of Tornado Cash are a protocol, but other parts are platforms. Tornado Cash works atop the Ethereum blockchain, where a set of permissionless and immutable smart contracts define the rules of the system. It also relies on the availability of several components: a user interface, and a data storage location for proving keys (necessary for the generation of zero knowledge proofs). Finally, at least one relayer must offer their services to process withdrawals for users.
Tornado Cash’s smart contracts are a protocol since no-one can modify or control the code deployed on the Ethereum blockchain. Furthermore, there is no need to seek permission from anyone to invoke its functions. By contrast, its user interface and data storage for proving keys are platforms. They are hosted by centralized entities. Even though the user interface source code and proving keys are widely available from third parties, most users opt for the convenience of using hosted versions. Moreover, each relayer is a platform because it has sole control over the availability of their services and full discretion over which users to serve.
Yet, the fact that Tornado Cash’s smart contract addresses were sanctioned by the U.S. do not prevent users from using the protocol, as anyone may access them via an uncensored user interface. In the same way that websites censored (by the U.S. or China, for instance) can be circumvented via VPNs, anyone can connect to a non-censoring Ethereum node and broadcast transactions that engage with the Tornado Cash smart contracts, and non-compliant validators can include these transactions in blocks. Such loopholes, however, are insufficient for most users. The platform aspects of Tornado Cash are still necessary for its practical use.
As such, we argue that the sanctions imposed by the U.S. on Tornado Cash’s smart contract addresses neither adequately stop its use, nor demonstrate a comprehensive understanding of the system. On the one hand, these sanctions ineffectively target the protocol, leaving the platform aspects untouched. On the other hand, the actions taken against its developers are unfair, as they have no control over the immutable and uncensorable protocol.
A more sensible approach would be to regulate relayers and miners who handle Tornado Cash transactions. We believe that more nuanced regulations would be fairer and less heavy-handed. For instance, more sensible rules would allow relayers and miners to operate within limits that are fair to regular users who merely seek transaction privacy, but prohibitive to actors which regulators deem undesirable. Moreover, protocol developers should not be unfairly held liable for actions far beyond their own control, as this sets a dangerous and chilling precedent for all open-source software developers, and will not only unjustly malign innocent individuals, but also harm innovation and progress.
One may object that any regulation of a permissionless system is ideologically unacceptable. We neither condone state censorship nor necessarily agree on which actors are undesirable (if at all), but as long as we live in a world of competing interests, it makes more sense to reduce harm than to accept that the entire space should be deemed objectionable. Proponents of maximal protocol decentralization should recognize that as long as protocols are maintained in a diverse set of locations, they should be naturally resistant to pressure from any particular jurisdiction.
We hope that this way of thinking above informs developers on how to architect systems to better protect themselves, and provides the basis for a more nuanced framework to reconcile the reality of state-mandated enforcement with a world of permissionless protocols.
https://twitter.com/laurashin/status/1565012035045302275?s=27&t=Zz7W09-QRGH3Xz1kTNrLKA

