For user privacy and corporate IP reasons, many of the largest deployed transparency systems rely on designated auditors, both in the informal software sense and as protocol participants. Key Transparency auditing requires access to sensitive metadata about key churn, some Binary Transparency schemes rely on a trusted party for append-only guarantees, and private AI systems often cannot release all source code due to IP or guardrail considerations.
Trail of Bits serves as an auditor (in at least one of the senses) for five large-scale private AI systems and for the Signal key transparency deployment. We will present a quick tour of Signal’s KT architecture and where third-party auditors fit in, and compare to other deployed systems. Then we will look at some other domains where semi-trusted third parties enable practical deployment of transparency systems.
Finally, we will discuss the ethical, contractual and technical considerations that we consider when making attestations about non-public components of otherwise transparent systems.
Speaker
Tjaden Hess worked for four years on the cryptography assurance team at Trail of Bits and now leads the ML security team. He has a particular interest in building and auditing systems that enable service providers to make binding commitments around their use of personal data and other sensitive IP. Recently, he has been working on building out Trail of Bits' capabilities for automated verification of such claims, starting with well-defined protocols like Key Transparency and slowly branching into more experimental domains such as automated analysis of source code and binaries for Binary Transparency.