Bitcoin.Review E4: A Review of Updates to Popular Bitcoin Projects with NVK and Justin Moon
show notes: https://github.com/nvk/bitcoin.review.episodes/blob/main/2022-08-22-Episode-04.md
support the show: https://citadeldispatch.com/contribute
twitch: https://twitch.tv/citadeldispatch
youtube: https://www.youtube.com/channel/UCoA72saVAuQ8hYCnBO0Lymw
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://www.podpage.com/citadeldispatch
telegram: https://t.me/citadeldispatch
stream sats to the show: https://www.fountain.fm/
join the chat: https://matrix.to/#/#citadel:bitcoin.kyoto
00:07 - Introduction and podcast setup
01:45 - Discussion about upcoming events and conferences
02:18 - Review of software updates and wallets
41:56 - Tornado Cash and privacy on Ethereum
01:11:00 - Data breaches at Swan and Casa
01:21:28 - Differences between ETH and BTC in terms of attack surface
01:25:09 - Importance of privacy and security in online transactions
01:25:41 - Dorsey and others launching a defense fund for developers facing lawsuits
01:26:40 - General fund and legal defense fund at Open Sats
01:30:59 - OpenSats legal defense fund
01:32:38 - Reproducing a fault injection attack on Trezor
01:39:19 - New way to do DLCs
01:47:16 - Receiving a change derivation path in a single descriptor
01:49:02 - Taproot adoption
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 4:23:51 PM
Duration: 7135.452
Channels: 1
1
00:00:07.995 --> 00:00:10.495
2
00:00:12.235 --> 00:00:18.080
The podcast where we fail at boringly reading the latest release notes and discuss project updates.
3
00:00:21.180 --> 00:00:22.619
So we, have,
4
00:00:23.585 --> 00:00:26.324
Matt and Justin again on the show.
5
00:00:27.425 --> 00:00:30.370
Really it's just Justin. We have the ghost of Matt here.
6
00:00:30.930 --> 00:00:33.990
He's gonna be replaced by a computer, the booze.
7
00:00:35.730 --> 00:00:40.105
Well, I guess the next stop really is for us to have, Marty prerecord
8
00:00:40.645 --> 00:00:41.625
the show notes.
9
00:00:43.204 --> 00:00:44.585
And then we play Marty
10
00:00:45.100 --> 00:00:50.879
doing the show notes, and we talk about And we'll just tackle him. That's right. I mean, that that would be quite perfect.
11
00:00:52.059 --> 00:00:54.375
So, yeah, thanks thanks for coming again, guys.
12
00:00:55.095 --> 00:00:58.795
This is this should be fun. It's, it's quite the the long list.
13
00:01:01.079 --> 00:01:01.800
Do you guys,
14
00:01:02.440 --> 00:01:04.860
do you guys have a a a good day so far?
15
00:01:05.640 --> 00:01:06.140
Absolutely.
16
00:01:07.785 --> 00:01:08.845
17
00:01:10.185 --> 00:01:17.630
18
00:01:18.170 --> 00:01:19.710
19
00:01:21.130 --> 00:01:24.725
He's run off to New Jersey or wherever the hell he went. You know?
20
00:01:25.365 --> 00:01:27.545
Fled Texas, couldn't handle the heat.
21
00:01:28.244 --> 00:01:29.945
Now I got his podcast studio,
22
00:01:30.564 --> 00:01:30.884
and,
23
00:01:31.445 --> 00:01:34.430
24
00:01:35.130 --> 00:01:35.870
to California.
25
00:01:36.570 --> 00:01:38.590
It's gonna be very compatible lifestyle.
26
00:01:39.050 --> 00:01:40.350
27
00:01:41.075 --> 00:01:44.375
28
00:01:45.634 --> 00:01:48.134
29
00:01:50.260 --> 00:01:51.460
30
00:01:52.980 --> 00:01:54.600
it just like goes right in there.
31
00:01:55.220 --> 00:01:56.595
No. I'm not gonna make it.
32
00:01:57.075 --> 00:01:59.975
I I am not making to conferences until probably
33
00:02:00.275 --> 00:02:01.335
mid late October.
34
00:02:02.835 --> 00:02:05.575
35
00:02:06.040 --> 00:02:07.260
36
00:02:07.960 --> 00:02:10.700
37
00:02:11.240 --> 00:02:17.705
38
00:02:18.565 --> 00:02:29.310
39
00:02:29.690 --> 00:02:32.830
40
00:02:33.855 --> 00:02:34.594
to Justin.
41
00:02:35.215 --> 00:02:35.715
Sparrow,
42
00:02:36.415 --> 00:02:36.915
1.6.6.
43
00:02:40.600 --> 00:02:42.860
That was a good strong start there.
44
00:02:43.160 --> 00:02:43.660
Authentication
45
00:02:44.200 --> 00:02:44.700
via
46
00:02:45.160 --> 00:02:45.900
off 47
47
00:02:46.600 --> 00:02:47.500
and lnurls,
48
00:02:48.915 --> 00:02:51.975
improved performance for very deep wallets,
49
00:02:52.995 --> 00:02:54.215
change from notification
50
00:02:54.835 --> 00:02:55.335
tx's
51
00:02:56.115 --> 00:02:57.335
in spent last,
52
00:02:58.000 --> 00:03:00.260
copy labels from deposit UTXOs
53
00:03:00.640 --> 00:03:02.019
into bed bank.
54
00:03:05.280 --> 00:03:07.220
Any comments, concerns?
55
00:03:07.985 --> 00:03:11.525
56
00:03:11.825 --> 00:03:15.924
57
00:03:16.305 --> 00:03:16.555
but,
58
00:03:17.490 --> 00:03:19.670
no. It's a we got we got the deep ones.
59
00:03:20.050 --> 00:03:21.030
Alright. Joinbox
60
00:03:22.130 --> 00:03:23.430
version 0.7.0.
61
00:03:25.295 --> 00:03:30.435
Neo automatically generated SD card image for Raspberry Pi 4 and 3,
62
00:03:30.894 --> 00:03:31.394
connect
63
00:03:31.694 --> 00:03:35.500
fully loaded with QR code to the join market API,
64
00:03:36.439 --> 00:03:38.540
add custom labels to addresses,
65
00:03:39.319 --> 00:03:42.060
add join market API dot services dot tools.
66
00:03:42.395 --> 00:03:44.335
I have comments. Do you guys?
67
00:03:44.795 --> 00:03:45.695
68
00:03:46.155 --> 00:03:48.655
69
00:03:49.755 --> 00:03:50.575
70
00:03:51.800 --> 00:03:53.980
You would never go this unprepared to,
71
00:03:54.440 --> 00:04:08.305
72
00:04:08.610 --> 00:04:12.870
I sent on signal the the show notes. Thank you. Why don't you have them linked at bitcoin.review?
73
00:04:14.450 --> 00:04:27.800
74
00:04:28.100 --> 00:04:28.600
because
75
00:04:28.980 --> 00:04:32.200
Rudolph hasn't merged the pull request yet. But the list
76
00:04:32.580 --> 00:04:33.080
yeah.
77
00:04:33.485 --> 00:04:34.305
78
00:04:35.645 --> 00:04:39.165
79
00:04:39.805 --> 00:04:43.940
programming language here. It's just shell scripts for this UI for join market.
80
00:04:44.640 --> 00:04:45.860
81
00:04:46.800 --> 00:04:51.380
and and really sort of just ties things together because, you know, join market is the only
82
00:04:51.755 --> 00:04:53.775
sort of solution that we have
83
00:04:54.395 --> 00:04:57.215
that we know that our people are not gonna go to jail.
84
00:04:58.610 --> 00:05:01.270
85
00:05:02.290 --> 00:05:04.630
The lead maintainer is Open Arms,
86
00:05:05.810 --> 00:05:07.590
and it's primarily used
87
00:05:08.675 --> 00:05:13.255
via the Raspberry Pi Blitz project. So if you have Raspberry Pi Blitz, you basically just,
88
00:05:13.875 --> 00:05:17.655
you know, press install, and it's very, very straightforward to use.
89
00:05:18.129 --> 00:05:19.509
90
00:05:20.849 --> 00:05:26.710
I I think so this is still quite nerdy for for people listening, wanting to try join market.
91
00:05:27.825 --> 00:05:29.925
I think it's pretty much as nerdy as it gets.
92
00:05:31.265 --> 00:05:31.765
However,
93
00:05:32.465 --> 00:05:36.725
if you're a dev out there who can do UI, who can build something interesting,
94
00:05:37.669 --> 00:05:41.449
join markets, need some love. I think Gigi has some
95
00:05:42.150 --> 00:05:42.650
Yes.
96
00:05:45.030 --> 00:05:47.210
A bounty for join markets
97
00:05:47.575 --> 00:05:48.075
UI.
98
00:05:48.535 --> 00:05:56.315
99
00:05:56.930 --> 00:06:00.310
basically the main project that seeks to win that bounty,
100
00:06:01.090 --> 00:06:02.389
and that's jam.
101
00:06:05.104 --> 00:06:07.125
Forget what Jam stands for,
102
00:06:07.664 --> 00:06:25.125
but, essentially, it's a joint market web UI, so you can run it on, like, Umbrella or RaspiBlitz or something like that and just open it up in your browser, Use it with your own node really easily. Yeah. I haven't tried that one yet, but, it did look promising from the the specs I I I saw online. That's that that was the g g one that I knew of.
103
00:06:26.305 --> 00:06:32.599
104
00:06:33.539 --> 00:06:35.639
It's part of the reason why I like it so much.
105
00:06:36.659 --> 00:06:37.800
It's just a market.
106
00:06:38.525 --> 00:06:39.025
People,
107
00:06:39.405 --> 00:06:40.625
put out an offer,
108
00:06:41.085 --> 00:06:42.305
to mix their coins,
109
00:06:42.845 --> 00:06:47.105
with yours, and you choose to pay their fee or not or pick another offer,
110
00:06:48.450 --> 00:06:49.670
from a market maker.
111
00:06:50.770 --> 00:07:02.755
112
00:07:03.830 --> 00:07:08.490
offer, then you open up joint market as a taker and you use it. And then they have, like, different
113
00:07:08.870 --> 00:07:11.449
automated things that go through them and
114
00:07:11.865 --> 00:07:12.605
switch between,
115
00:07:13.145 --> 00:07:13.645
makers
116
00:07:14.185 --> 00:07:18.925
and whatnot. So one of the biggest trade offs with that is, yeah, you you have robust.
117
00:07:20.849 --> 00:07:30.389
It's a robust system that doesn't have central points of failure, but in return, you lack convenience. And the main lack of convenience there historically has been you have to use your own node with it,
118
00:07:31.205 --> 00:07:32.745
and the UI. So,
119
00:07:33.284 --> 00:07:36.824
to get to make the node part easier, you bundle it with node projects.
120
00:07:37.365 --> 00:07:42.170
And then to make the UI part easier, you provide a web UI, where it's just point and click.
121
00:07:42.790 --> 00:07:47.850
And that jam tries to accomplish both of those elements. Have anyone looked into,
122
00:07:48.230 --> 00:07:49.370
123
00:07:49.854 --> 00:07:52.514
protocol to create a joint market coordinator?
124
00:07:53.294 --> 00:07:56.435
I I could see how that would work because right now you could use
125
00:07:57.380 --> 00:07:57.880
IRC.
126
00:07:58.180 --> 00:08:08.335
There's a few ways to coordinate joint market. Right now, they use IRC, which is, like, not ideal. Yeah. But the well, at least the cool thing about IRC is that anyone can connect to that sort of
127
00:08:08.715 --> 00:08:09.615
quite privately.
128
00:08:10.155 --> 00:08:20.259
129
00:08:21.919 --> 00:08:27.205
I don't know how this thing has it's it's called the Joinster. You You just look on Twitter for example.
130
00:08:28.465 --> 00:08:28.965
131
00:08:29.345 --> 00:08:30.245
So Electrum
132
00:08:30.545 --> 00:08:31.045
4.3.0.
133
00:08:35.380 --> 00:08:36.840
This version introduces
134
00:08:37.540 --> 00:08:39.540
a set of UI modifications, simple
135
00:08:40.340 --> 00:08:42.464
simplify the use of lightning,
136
00:08:42.765 --> 00:08:44.065
the idea of stock payments,
137
00:08:45.084 --> 00:08:46.225
layer blah blah blah.
138
00:08:47.485 --> 00:08:50.144
Honestly, I am not a fan of Electrum lightning.
139
00:08:50.690 --> 00:08:53.270
I really wish they had not included that
140
00:08:53.730 --> 00:08:57.750
on Electrum. I actually have many things to bitch about Electrum recently.
141
00:08:58.185 --> 00:09:00.765
Do you guys wanna start before I go on my rant?
142
00:09:01.785 --> 00:09:15.110
Go for it. Go for it. So the new UI, UX really, on Electrum now requires, you know, 50,000 more clicks to just sign a transaction. I don't understand why they create that finalized screen, probably because of lightning stuff.
143
00:09:15.975 --> 00:09:21.675
As usual, why can't we just keep things separate? You know, the lightning stuff and the electrum stuff for Bitcoin,
144
00:09:22.455 --> 00:09:24.635
and, it's it's it's very brutal.
145
00:09:25.120 --> 00:09:25.620
Yeah.
146
00:09:26.160 --> 00:09:28.660
Anyways, so that's really that's that's my rant.
147
00:09:29.040 --> 00:09:30.180
148
00:09:30.640 --> 00:09:32.260
the Electrum team because
149
00:09:32.745 --> 00:09:37.245
they've been around forever, and, I used to heavily rely on their project.
150
00:09:38.185 --> 00:09:42.045
But, at this point, I just don't know why you wouldn't just use Sparrow.
151
00:09:42.400 --> 00:09:44.180
152
00:09:44.880 --> 00:09:47.780
I I am an absolute the the reason why I'm so passionately
153
00:09:48.240 --> 00:09:55.535
pissed at Electrum is because I'm passionately fan of Electrum. I love Electrum. I use Electrum. So you still use Electrum
154
00:09:55.995 --> 00:09:56.495
155
00:09:57.195 --> 00:09:59.455
156
00:09:59.910 --> 00:10:08.330
Right? And I know the amount of eyes that are on it. It's it's, you know, it's a fairly well reviewed project with a lot of user base.
157
00:10:09.135 --> 00:10:09.455
And,
158
00:10:10.335 --> 00:10:17.154
I I I think it it serves a huge purpose. We can't end up with just one wallet. It would be terrible. Well, yeah, obviously.
159
00:10:17.700 --> 00:10:22.680
So I really want Electrum to stop with the lightning stuff and and sort of focus on Bitcoin.
160
00:10:23.060 --> 00:10:25.720
161
00:10:26.145 --> 00:10:33.205
is what was happening is is is if you talked about power user wallets, we were basically just we basically just had Electrum.
162
00:10:33.569 --> 00:10:40.550
163
00:10:40.895 --> 00:10:51.280
Yeah. No. But but, like, that's kinda how I see the competition, and it's kinda funny because that's how the project started was literal competition for Bitcoin Core because Bitcoin Core, while it was unusable way back, still unusable.
164
00:10:52.460 --> 00:10:52.960
And,
165
00:10:54.140 --> 00:10:58.080
yeah, I mean like Spector Desktop, I I don't know where that's going.
166
00:10:58.394 --> 00:11:02.495
167
00:11:02.875 --> 00:11:04.575
a desktop software wallet,
168
00:11:05.330 --> 00:11:14.070
with, let's say, with your hardware signers, for instance, if you had hardware wallets Mhmm. Your basically, your your two choices were Electrum and
169
00:11:14.695 --> 00:11:15.195
maybe,
170
00:11:15.655 --> 00:11:16.875
like, Bitcoin Core.
171
00:11:17.335 --> 00:11:29.959
Now over those last 2 years, we've added Specter to it, we've added Wasabi to it, and we've added Sparrow to it. Yeah. But not really. Right? Because Wasabi now does chain analytics, and everybody hates it. Right. Correct. Sparrow
172
00:11:30.755 --> 00:11:35.575
173
00:11:36.035 --> 00:11:37.415
No. Listen. I I absolutely
174
00:11:37.795 --> 00:11:38.295
love
175
00:11:38.970 --> 00:11:43.310
Craig. Right? Like, it's this is not a criticism of Craig or the project.
176
00:11:43.610 --> 00:11:47.150
It's just sort of like a a a factor of the the time in the market
177
00:11:48.165 --> 00:11:54.185
and sort of like install base size. Right? So, like, when you're talking about, like, you know, putting all your,
178
00:11:54.725 --> 00:11:56.665
like, doing very large transactions
179
00:11:57.170 --> 00:11:58.230
on on a computer,
180
00:11:59.410 --> 00:12:00.950
you kind of really want
181
00:12:01.410 --> 00:12:03.190
the the project to have,
182
00:12:03.650 --> 00:12:05.270
you know, time in the market,
183
00:12:06.065 --> 00:12:08.085
like, a lot of people who don't necessarily
184
00:12:08.545 --> 00:12:13.125
like it, use it to also audit it. It's just a function of market size and time.
185
00:12:13.540 --> 00:12:23.144
I think you'll get there. It's already getting there. It's a fantastic project, but, you know, it's also Java, which has a lot less people in Bitcoin space looking at it as well. Nunchuk
186
00:12:23.685 --> 00:12:27.865
too. Yeah. So Nunchuk is fantastic, but also, you know, still
187
00:12:28.404 --> 00:12:29.144
sort of
188
00:12:29.524 --> 00:12:32.265
not quite there in time in the market, install base,
189
00:12:32.629 --> 00:12:33.689
and and reviews.
190
00:12:35.110 --> 00:12:39.290
We need people using it so that they do get there, and we want them to get there.
191
00:12:40.524 --> 00:12:45.425
192
00:12:45.885 --> 00:12:51.189
193
00:12:51.490 --> 00:12:53.110
you know, much going on.
194
00:12:53.490 --> 00:12:53.990
195
00:12:54.370 --> 00:12:57.975
responded to one of my tweets saying that that deal didn't happen.
196
00:12:58.595 --> 00:13:09.660
197
00:13:10.280 --> 00:13:18.845
198
00:13:19.225 --> 00:13:21.324
Right? Right. It's a false project.
199
00:13:22.860 --> 00:13:27.120
200
00:13:27.660 --> 00:13:33.645
you know, it's a shame that because of the way app stores work and stuff, you can't just side load and whatever on iOS.
201
00:13:34.505 --> 00:13:41.430
But ideally, it shouldn't matter. Right? People can review the code. People can build a project. People can test, and it shouldn't
202
00:13:41.810 --> 00:13:44.310
203
00:13:45.090 --> 00:13:46.470
BlueWallet is MIT.
204
00:13:46.850 --> 00:13:49.670
Mhmm. So, presumably, like, we could get off this podcast,
205
00:13:50.475 --> 00:13:59.855
just rip a direct copy of it, put it on the App Store, and call it, you know, Aqua Wallet or something. Yep. Well, I I mean, you know, I am a huge sort of,
206
00:14:00.780 --> 00:14:01.280
207
00:14:01.660 --> 00:14:06.800
fan to when I when people ask me which wallets they should use as, like, a simple
208
00:14:07.340 --> 00:14:08.240
single sig
209
00:14:08.805 --> 00:14:09.625
iOS wallet,
210
00:14:10.325 --> 00:14:15.545
but progressively, I've been sort of switching to tell people to I send them to either Nunchuk,
211
00:14:16.950 --> 00:14:24.970
or Mun Moon Moon Wallet. Although Moon Wallet, I can't send people to because they don't use seeds, which drives me absolute bonkers.
212
00:14:27.065 --> 00:14:31.325
I I can't, in the right mind, send anybody to a wallet that doesn't use seeds.
213
00:14:31.785 --> 00:14:38.630
214
00:14:39.170 --> 00:14:41.270
trajectory because it doesn't have seeds.
215
00:14:42.095 --> 00:14:44.835
216
00:14:45.375 --> 00:14:52.440
people wanting to make an encrypted backup into the Icloud for those kinds of wallets, which is fair. It's a very reasonable way of handling backups.
217
00:14:53.220 --> 00:14:55.160
But you should still be seed based because
218
00:14:55.700 --> 00:15:02.805
then you're compatible with every other wallet that can recover those funds. My understanding is it's because they use a a multisig.
219
00:15:03.985 --> 00:15:08.650
But it still doesn't matter. You can still use the seed the seed as the source of entropy.
220
00:15:09.029 --> 00:15:13.415
221
00:15:14.214 --> 00:15:26.350
222
00:15:27.370 --> 00:15:31.950
Yes, but green uses nonstandard multisig too, unless you use the
223
00:15:32.265 --> 00:15:34.045
their new version of green
224
00:15:34.425 --> 00:15:34.925
now
225
00:15:35.865 --> 00:15:36.845
allows you
226
00:15:37.145 --> 00:15:40.365
to create single sig and standard multisigs.
227
00:15:41.090 --> 00:15:41.990
But if I remember right,
228
00:15:42.450 --> 00:15:43.750
their basic
229
00:15:44.130 --> 00:15:44.630
automatic
230
00:15:45.090 --> 00:15:45.590
default,
231
00:15:46.210 --> 00:15:47.750
their 2 of 2 thing,
232
00:15:48.745 --> 00:15:49.964
is non standard.
233
00:15:50.745 --> 00:15:53.324
You know, there's recovery scripts out there and stuff, but,
234
00:15:53.704 --> 00:15:58.750
you know, I ideally, I don't want to send users to any wallet that needs,
235
00:15:59.310 --> 00:16:02.449
some custom script that nobody else uses. Right?
236
00:16:02.750 --> 00:16:08.165
237
00:16:09.024 --> 00:16:14.084
Like, it's weird that Moon even came up in this conversation. Right? Because, you know, we were talking about
238
00:16:14.940 --> 00:16:19.440
specifically on chain wallets and specifically within that savings wallets
239
00:16:20.060 --> 00:16:28.375
or wallets that you use to, you know, to interact with your savings. While Moon, on the other hand, to me, is, you know, an easy way for people to participate in lightning on mobile,
240
00:16:29.875 --> 00:16:35.370
with very, you know, little little user friction. And in that situation, it's really competing against,
241
00:16:35.670 --> 00:16:44.154
you know, like, Wallet of Satoshi and Blue Wallet's custodial lightning wallet, and both of those are custodial lightning wallets. So let alone the backup method. I mean, you don't even have your keys.
242
00:16:44.455 --> 00:16:45.834
243
00:16:46.295 --> 00:16:49.274
People are not gonna download more than one wallet, and they shouldn't.
244
00:16:49.720 --> 00:16:59.260
Right? Especially the people we're talking about here. Right? The the person who is just gonna have some bucks to spend on lightning or some bucks to spend on on on chain. They're gonna want a single wallet,
245
00:17:00.035 --> 00:17:06.055
or they might download 2 wallets if each of them does not do what the other one does in the wrong way.
246
00:17:08.090 --> 00:17:17.175
So the problem is, you know, they get they get blue water and then they're gonna use blue water for all their stuff. Right? So then they're gonna end up on on custodial lightning.
247
00:17:17.955 --> 00:17:20.055
And then if they use moon,
248
00:17:20.355 --> 00:17:21.815
then they're gonna end up using
249
00:17:22.200 --> 00:17:25.340
Bitcoin base layer in a way that is not easy to recover.
250
00:17:26.200 --> 00:17:27.980
So it kinda sucks.
251
00:17:29.160 --> 00:17:32.855
You know, my dream wallet, which I might end up having to do,
252
00:17:33.155 --> 00:17:33.655
is
253
00:17:34.035 --> 00:17:34.615
I want
254
00:17:34.915 --> 00:17:37.655
a phone wallet that does single sig
255
00:17:38.195 --> 00:17:38.695
basic.
256
00:17:39.860 --> 00:17:41.799
Okay, very basic single sig,
257
00:17:42.260 --> 00:17:43.080
and then
258
00:17:44.020 --> 00:17:45.880
go use Lightning somewhere else,
259
00:17:48.475 --> 00:17:49.375
You know, or
260
00:17:50.795 --> 00:17:52.655
261
00:17:53.434 --> 00:17:56.799
262
00:17:57.740 --> 00:18:03.820
263
00:18:04.394 --> 00:18:08.254
like, this idea that Moon should have, like, all this different functionality is ridiculous.
264
00:18:09.115 --> 00:18:13.774
265
00:18:14.310 --> 00:18:17.770
266
00:18:18.230 --> 00:18:22.330
That's just icing on the cake. Like, if you're carrying around, like, $400, $500,
267
00:18:23.425 --> 00:18:24.645
it's a spending wallet.
268
00:18:25.025 --> 00:18:34.170
Yeah. But, man, like, people lose phones. People break phones. Which is why they have email password recovery, which for, like, 99% of people is more intuitive than a seed anyway.
269
00:18:34.870 --> 00:18:39.210
270
00:18:40.335 --> 00:18:53.520
But meanwhile, like, right now, my current Moon Wallet, not backed up at all. Yeah. I I can't. I just I just can't. Because, you know, the problem is people are gonna have, like, $400 in their moon wallet or a $100 in their moon wallet. Right?
271
00:18:53.820 --> 00:18:54.480
And then
272
00:18:54.860 --> 00:18:58.320
they're gonna forget that they had it, and then 2 years later,
273
00:18:58.625 --> 00:19:01.044
Bitcoin's worth, you know, a 100 times more,
274
00:19:01.424 --> 00:19:02.645
and then they go like,
275
00:19:03.105 --> 00:19:07.525
276
00:19:08.059 --> 00:19:18.425
277
00:19:19.045 --> 00:19:20.585
with 12 words minimum
278
00:19:21.205 --> 00:19:29.570
their freaking wallet. It shouldn't be that hard. It makes no difference. I I can't comprehend why they couldn't use 12 words as the entropy for whatever they're doing.
279
00:19:30.029 --> 00:19:33.250
280
00:19:33.815 --> 00:19:37.595
using lightning on mobile and easily backing up lightning things
281
00:19:38.774 --> 00:19:43.110
and, like, easy channel management and all this other stuff, and Moon is kind of
282
00:19:43.670 --> 00:19:48.650
dealing with what they have today and giving, like, a pretty good user experience for people
283
00:19:49.190 --> 00:19:56.535
284
00:19:57.475 --> 00:19:57.975
Anyways,
285
00:19:59.030 --> 00:20:02.010
we're not gonna come up with a solution on this call, but,
286
00:20:02.710 --> 00:20:04.410
you know, that's the problem.
287
00:20:04.790 --> 00:20:06.790
288
00:20:07.110 --> 00:20:09.075
289
00:20:09.455 --> 00:20:11.715
cool. And then but then we're gonna have to be polite
290
00:20:12.175 --> 00:20:15.370
because the person is gonna be here who actually does all the work.
291
00:20:17.610 --> 00:20:23.470
There's a very big difference between bitching about projects when the people who work on the project are around and when they aren't.
292
00:20:23.815 --> 00:20:31.035
So just so everybody knows, we're just bitching. Right? I mean, like, really, it's not like we're taking our time going and fixing it or forking it. Alright.
293
00:20:32.220 --> 00:20:32.460
So Nunchuk,
294
00:20:34.060 --> 00:20:34.560
1.9.12,
295
00:20:36.300 --> 00:20:40.560
they have some bug fixes and they added Sats card integration.
296
00:20:41.325 --> 00:20:44.385
That is the first SatsCard integration in the wild.
297
00:20:44.765 --> 00:20:45.905
That's pretty cool.
298
00:20:46.845 --> 00:20:48.785
I don't know, have you guys seen the video yet?
299
00:20:49.170 --> 00:20:50.710
300
00:20:51.010 --> 00:20:53.510
301
00:20:53.810 --> 00:20:54.310
boom.
302
00:20:54.850 --> 00:20:55.830
Bitcoin is yours.
303
00:20:56.130 --> 00:20:57.670
304
00:20:58.605 --> 00:21:00.945
305
00:21:01.805 --> 00:21:06.065
Oh, yeah. Taps. Okay. Gotcha. Yeah. No. The Sats card is just like OpenDime,
306
00:21:06.990 --> 00:21:07.650
like, modern.
307
00:21:08.190 --> 00:21:12.610
308
00:21:12.910 --> 00:21:18.435
309
00:21:19.775 --> 00:21:20.595
That's awesome.
310
00:21:20.975 --> 00:21:22.835
Another thing I love about Nunchuk
311
00:21:23.455 --> 00:21:24.915
is that there is no dependencies.
312
00:21:25.700 --> 00:21:27.240
Like the the whole thing
313
00:21:27.940 --> 00:21:28.920
is there.
314
00:21:29.380 --> 00:21:30.600
All c plus plus,
315
00:21:31.060 --> 00:21:31.560
libsack,
316
00:21:32.260 --> 00:21:35.735
it's absolutely brilliant. It's a lot less attack surface that way.
317
00:21:36.115 --> 00:21:43.740
And also, they're not doing what the JavaScript guys have to do there's no serializing, deserializing, serializing, deserializing of all the secrets
318
00:21:44.200 --> 00:21:45.500
between many libraries.
319
00:21:46.120 --> 00:21:48.495
It's, it's very nice. Mhmm.
320
00:21:49.375 --> 00:21:49.875
321
00:21:50.335 --> 00:21:50.835
322
00:21:51.455 --> 00:21:54.355
And moving on to Blockstream Green,
323
00:21:55.135 --> 00:21:55.635
3.8.6.
324
00:21:57.710 --> 00:21:58.850
IOS and Android,
325
00:21:59.470 --> 00:22:03.890
display, firmware wash no. Sorry. Firmware wash. Firmware hash
326
00:22:04.270 --> 00:22:05.810
during Jade firmware update.
327
00:22:13.549 --> 00:22:15.890
Display the net amount without fees,
328
00:22:16.510 --> 00:22:19.410
handle connection failure during wallet discovery.
329
00:22:19.790 --> 00:22:20.929
And then on Android,
330
00:22:21.230 --> 00:22:22.210
login same,
331
00:22:22.985 --> 00:22:25.245
Thrasir and Ledger, single sig.
332
00:22:25.625 --> 00:22:27.325
Faster Jade firmware update,
333
00:22:27.625 --> 00:22:32.060
334
00:22:33.340 --> 00:22:40.480
They're working on it. So it's it's a lot different. The flow the flow is a lot different than with Tap Signer? Yes. So
335
00:22:41.005 --> 00:22:46.145
336
00:22:47.085 --> 00:22:48.945
dumb blind signer for Bitcoin
337
00:22:49.490 --> 00:22:52.390
with a pin. Tapsider doesn't understand,
338
00:22:53.250 --> 00:22:53.750
PSBT,
339
00:22:54.210 --> 00:22:57.110
some of this stuff. Right? The the the stack is much reduced.
340
00:22:57.865 --> 00:23:01.485
While on cold card, it's the opposite. There is no proprietary
341
00:23:01.865 --> 00:23:02.365
SPAC,
342
00:23:03.385 --> 00:23:05.325
it just it's just data
343
00:23:05.820 --> 00:23:07.039
in and out via NFC.
344
00:23:07.980 --> 00:23:09.840
So technically it would be much faster,
345
00:23:10.220 --> 00:23:10.720
but
346
00:23:11.179 --> 00:23:14.000
the value add of doing cold card NFC
347
00:23:14.705 --> 00:23:15.685
is much lower
348
00:23:16.145 --> 00:23:17.125
than TapCigner
349
00:23:17.505 --> 00:23:18.405
with a multisig
350
00:23:19.425 --> 00:23:22.405
on Nunchuk, like collaborative or by yourself.
351
00:23:23.559 --> 00:23:24.460
352
00:23:25.160 --> 00:23:26.780
353
00:23:27.320 --> 00:23:29.179
Does, does green actually
354
00:23:29.559 --> 00:23:30.299
do the
355
00:23:30.815 --> 00:23:36.755
firmware updates for the Jade, like, via via Bluetooth or something? Or how do they how do they do the firmware update?
356
00:23:37.055 --> 00:23:39.315
Does it say, like, faster Jade firmware update?
357
00:23:39.720 --> 00:23:43.740
I have no clue. That'd be kinda cool if you could update your firmware with your phone.
358
00:23:45.160 --> 00:23:46.700
359
00:23:48.435 --> 00:23:53.015
Can you imagine? Yeah. Because the the phone is, like, essentially, like, fully fully owned.
360
00:23:53.395 --> 00:23:59.430
Right? And now you're gonna take firmwares that you can't sort of verify on hardware that has no security,
361
00:24:00.450 --> 00:24:02.610
because Jade doesn't have any security. Right?
362
00:24:03.410 --> 00:24:03.910
Their
363
00:24:04.255 --> 00:24:04.655
their,
364
00:24:05.055 --> 00:24:06.675
security model is very different.
365
00:24:07.215 --> 00:24:09.555
So, essentially, Jade is using ESP 32,
366
00:24:10.815 --> 00:24:11.315
and
367
00:24:11.855 --> 00:24:13.395
which you cannot defend,
368
00:24:14.240 --> 00:24:15.540
like, at all. Right?
369
00:24:16.160 --> 00:24:23.300
And, what they do is they do a 2 factor authentication There's no secure element. No. It's worse than that. So ESP 32
370
00:24:23.935 --> 00:24:24.675
is an extremely
371
00:24:26.655 --> 00:24:27.155
372
00:24:29.135 --> 00:24:29.955
373
00:24:30.335 --> 00:24:30.835
Chinese
374
00:24:31.295 --> 00:24:31.795
platform.
375
00:24:33.140 --> 00:24:35.880
Okay? It was designed for you to create
376
00:24:36.340 --> 00:24:42.415
essentially, like, fun things like a block clock, right, not for you to handle money. However,
377
00:24:43.195 --> 00:24:45.375
they came up with this sort of 2 factor authentication
378
00:24:45.675 --> 00:24:46.175
thing
379
00:24:46.635 --> 00:24:49.135
where you use Blockstream servers
380
00:24:49.515 --> 00:24:50.015
as
381
00:24:50.720 --> 00:24:52.500
the security of the jade,
382
00:24:53.360 --> 00:24:53.860
but
383
00:24:54.640 --> 00:24:56.740
you know, like you're still
384
00:24:57.200 --> 00:25:02.395
like holding a device that you can't trust, right, so if you see an address on a screen you can't trust that.
385
00:25:02.775 --> 00:25:05.755
That's part of the model problem that I see with with Jade.
386
00:25:06.630 --> 00:25:12.330
It's an interesting proposition, and it was a great solution because no other wallet was supporting Liquid at the time,
387
00:25:14.390 --> 00:25:19.705
but, like, you know, as an actual security solution, I am not, I'm not a huge fan.
388
00:25:20.405 --> 00:25:22.345
And presumably, it's cheap as fuck.
389
00:25:23.000 --> 00:25:26.140
Yeah. I mean, ESP 32, the module itself is very cheap.
390
00:25:26.840 --> 00:25:29.100
It's a very powerful platform
391
00:25:29.400 --> 00:25:30.380
for the price.
392
00:25:31.095 --> 00:25:32.394
It's actually quite incredible.
393
00:25:33.495 --> 00:25:39.755
The reason why it's possible to do that is because it's made by a Chinese company that doesn't give a fuck about patents or licensing
394
00:25:40.215 --> 00:25:40.680
IP.
395
00:25:41.160 --> 00:25:41.800
So they go
396
00:25:42.520 --> 00:25:47.980
they they they they went, they did that, and and it has, like, you know, no security at all, for example. Right?
397
00:25:48.674 --> 00:25:53.095
All these things will save a lot of cost, and you can create these incredible devices that can do a lot.
398
00:25:53.475 --> 00:25:56.294
You just can't depend on them. Let's put it this way.
399
00:25:56.950 --> 00:26:01.210
400
00:26:01.670 --> 00:26:02.650
and they're considering
401
00:26:03.110 --> 00:26:03.610
getting
402
00:26:04.150 --> 00:26:04.650
a
403
00:26:05.270 --> 00:26:05.770
Jade
404
00:26:06.465 --> 00:26:09.924
because it has a screen on it versus a TAP signer? What would you say to them?
405
00:26:10.225 --> 00:26:20.390
406
00:26:21.330 --> 00:26:25.510
At least Tapsigner is secure. Right? It uses an actual secure element.
407
00:26:26.495 --> 00:26:30.995
It doesn't have a screen, so you are depending on the software that gives you the address.
408
00:26:31.535 --> 00:26:32.035
Now
409
00:26:32.415 --> 00:26:39.900
at least you know that the integrity of the device is much more secure. Is it perfect? Absolutely not. It's still a cheap secure element,
410
00:26:40.680 --> 00:26:46.745
but in my view is a much better security trade off scenario, especially if you're using TAP signer or multisig.
411
00:26:47.045 --> 00:26:49.865
412
00:26:50.245 --> 00:26:52.025
413
00:26:52.620 --> 00:26:57.600
if you're using a multisig, you can be the other party or your other device,
414
00:26:58.299 --> 00:27:00.720
so to be your sanity check for that address.
415
00:27:01.455 --> 00:27:06.195
It could also be, Jade or it could also be a cold card as the cosigner. Right? So
416
00:27:06.735 --> 00:27:13.380
you you would you you would rely on another party or another device to double check that address.
417
00:27:14.480 --> 00:27:17.860
Now, if you're using TapSigner as a single signer,
418
00:27:19.235 --> 00:27:27.655
the security model is not for you to have your life savings on it, it's for you to just not have your private keys on a phone, right? So you would have your spending wallet
419
00:27:28.080 --> 00:27:30.179
say your $500, $5,000
420
00:27:31.919 --> 00:27:34.820
using the Tap signer just so that it's not on the phone.
421
00:27:35.865 --> 00:27:40.365
It's just a little bit of a different sort of security trade off in a place there.
422
00:27:40.904 --> 00:27:45.779
While the Jade, in my opinion, gives you a false sense of security by having that screen
423
00:27:46.159 --> 00:27:48.500
when the device itself is not secure.
424
00:27:51.015 --> 00:27:57.595
But in the same way as the tap signer, you could rely on a third party to be your sanity check for that address.
425
00:27:58.350 --> 00:28:02.530
So I see the 2 actually very similar in terms of security threshold,
426
00:28:04.910 --> 00:28:06.290
but one is much cheaper
427
00:28:06.695 --> 00:28:08.794
and much more secure itself,
428
00:28:09.255 --> 00:28:10.475
but doesn't have a screen.
429
00:28:11.495 --> 00:28:13.434
Does that make any sense, Matt?
430
00:28:13.880 --> 00:28:17.660
431
00:28:19.400 --> 00:28:21.660
you would need multiple points of failure,
432
00:28:22.405 --> 00:28:25.545
to be compromised. Right? Because you'd have you'd have different
433
00:28:26.565 --> 00:28:29.065
coordinators for each of the signers anyway.
434
00:28:29.790 --> 00:28:43.625
Yeah. I mean, unless you're all using the same wallet software, right, which in the case of Nunchuck could be true. Right. But you might not all be updated, or your individual phone might not be pwned or something. That's correct. Even in a situation where it was a 3 of 5
435
00:28:44.390 --> 00:28:44.890
multisig
436
00:28:45.590 --> 00:28:49.690
and 3 of the signers are different people holding tap signers and
437
00:28:50.230 --> 00:28:50.730
nunchuck,
438
00:28:52.535 --> 00:28:55.435
the tax surface becomes way smaller Yes.
439
00:28:55.895 --> 00:29:08.530
Yes. Even in that situation. Just because there's multiple devices that need to be compromised. I guess you could, yeah, and update. Yeah. I mean, unless Nunchuk is malicious, right, like themselves, because then they would have to make a release for each platform,
440
00:29:08.990 --> 00:29:10.370
441
00:29:11.054 --> 00:29:11.955
and the same
442
00:29:12.495 --> 00:29:13.315
443
00:29:14.174 --> 00:29:19.315
444
00:29:20.049 --> 00:29:39.360
445
00:29:39.660 --> 00:29:42.080
So just, like, that's the path. Right?
446
00:29:42.460 --> 00:29:46.534
447
00:29:47.315 --> 00:29:54.810
you do you do feel a bit of an extra safety that it's like, okay. If I fuck up this one signer, this one signer gets compromised or
448
00:29:55.190 --> 00:30:01.455
I lose the backup or something like that, I don't lose everything, and the other devices need to be compromised too.
449
00:30:01.915 --> 00:30:05.695
450
00:30:06.155 --> 00:30:08.015
the reason why we often
451
00:30:10.360 --> 00:30:15.340
recommend people to use single sig plus strong task phrase for real money
452
00:30:16.265 --> 00:30:21.325
is because most people will screw themselves out of their coins before they're actually robbed by somebody. Right?
453
00:30:21.784 --> 00:30:22.845
And having
454
00:30:23.610 --> 00:30:28.010
essentially a split secret, right, that's what passphrase plus single sig
455
00:30:28.650 --> 00:30:29.550
plus seed is,
456
00:30:30.490 --> 00:30:32.190
is very hard to screw up.
457
00:30:33.934 --> 00:30:36.115
So especially if you have a backup of each.
458
00:30:36.495 --> 00:30:37.635
Now with multisig,
459
00:30:38.015 --> 00:30:41.075
it's a lot easier to screw up, and
460
00:30:41.440 --> 00:30:46.080
you're still now depending on multisig. You either have extreme sort of,
461
00:30:46.560 --> 00:30:48.020
understanding of the stuff,
462
00:30:48.554 --> 00:30:51.054
and you're using, say, Electrum with multisig
463
00:30:51.355 --> 00:30:51.855
plus
464
00:30:52.235 --> 00:30:55.375
Sparrow. So, like, you're using multi client multisig.
465
00:30:56.179 --> 00:30:59.399
Right? Now you're really getting the benefit of multi sig.
466
00:30:59.700 --> 00:31:06.015
If you're using single client multi sig, you know, the benefits of multi sig start to diminish
467
00:31:06.794 --> 00:31:07.294
because,
468
00:31:07.835 --> 00:31:13.519
you know, now you're relying that the client is not lying to you in multiple platforms too. Right?
469
00:31:14.139 --> 00:31:14.639
So
470
00:31:15.100 --> 00:31:17.840
it's not like a magical thing. The desktop? The coordinator?
471
00:31:18.299 --> 00:31:23.685
Yeah. So so imagine imagine for sake of argument that Nunchuk is evil. Right?
472
00:31:24.385 --> 00:31:27.045
They could be releasing evil software into 3 platforms,
473
00:31:27.585 --> 00:31:34.150
right, and then they could be doing a grifting attack or something like that, because you're using the same software
474
00:31:34.450 --> 00:31:35.990
to validate the transaction,
475
00:31:36.770 --> 00:31:38.230
like, before you sign it.
476
00:31:38.530 --> 00:31:48.645
477
00:31:48.945 --> 00:31:53.850
478
00:31:54.150 --> 00:31:56.570
put, like, fake software on it.
479
00:31:56.950 --> 00:32:00.515
Right? Like, some some dummy software on it that's lying to you.
480
00:32:00.975 --> 00:32:03.475
481
00:32:03.775 --> 00:32:09.520
482
00:32:10.220 --> 00:32:29.860
483
00:32:30.320 --> 00:32:31.700
484
00:32:32.240 --> 00:32:43.610
you become very obvious if there is a change to the firmware because you'll have a hash of it, and you also check all the bytes. Right? How would you check the bytes on a new firmware update that the old firmware doesn't know about yet?
485
00:32:44.170 --> 00:32:46.429
So the the secure element has a,
486
00:32:47.210 --> 00:32:47.710
certificate,
487
00:32:48.490 --> 00:33:04.370
right, that checks the signature when it receives the firmware binary. Yep. So then, you know, it checks that. And then once you have it in memory, right, it always knows that the signature checks, but it also checks the, you know, the stuff that's actually running in memory is also the stuff that's supposed to be there.
488
00:33:04.750 --> 00:33:12.235
Oh, okay. Interesting. Yeah. So so the the challenge when you don't have a secure element is that, like, if you if you can run any software you want,
489
00:33:12.855 --> 00:33:16.955
the the user won't know. Right? That maybe once they put their PIN,
490
00:33:17.290 --> 00:33:20.990
they're actually unlocking their secrets to a malicious firmware.
491
00:33:21.450 --> 00:33:23.950
492
00:33:25.245 --> 00:33:28.865
like, they their official instructions don't have anything about GPG
493
00:33:29.405 --> 00:33:52.630
494
00:33:53.090 --> 00:33:59.030
If I remember right, Jade goes a bit a bit further, right, because they are using a server model to do some validation,
495
00:33:59.544 --> 00:34:04.605
but at the end of the day, I mean, you know, if the client is weak, the client is weak. Right?
496
00:34:05.225 --> 00:34:15.370
There's only so much you can do, And mind you, like, you know, this is not to FUD any of these projects or or, like, to to FUD the stuff in in general. It's just we're just sort of discussing,
497
00:34:16.355 --> 00:34:17.175
you know,
498
00:34:17.715 --> 00:34:18.615
like, realistic,
499
00:34:20.115 --> 00:34:20.615
attacks
500
00:34:20.995 --> 00:34:21.495
surface
501
00:34:22.275 --> 00:34:23.735
that is not trivial
502
00:34:24.210 --> 00:34:29.030
to do. Right? I mean, it is trivial to to extract a seed from a treasure,
503
00:34:30.050 --> 00:34:30.550
but
504
00:34:31.010 --> 00:34:33.555
it's not trivial to replace the signature
505
00:34:33.935 --> 00:34:36.915
on the device and load a new firmware that looks the same.
506
00:34:38.895 --> 00:34:41.635
It shouldn't be too hard, but I would say it's not trivial.
507
00:34:42.640 --> 00:34:46.579
508
00:34:47.119 --> 00:34:52.224
509
00:34:52.765 --> 00:34:54.704
They they have some some clever
510
00:34:55.325 --> 00:34:56.865
cryptography there, but,
511
00:34:57.430 --> 00:34:59.770
you know, you're still depending on the device. Right?
512
00:35:00.710 --> 00:35:03.450
513
00:35:04.150 --> 00:35:05.610
Yes. It it does.
514
00:35:06.255 --> 00:35:11.075
Actually, I I don't I I don't know. Have no idea. I didn't even know that's was their configuration.
515
00:35:11.375 --> 00:35:23.360
516
00:35:23.994 --> 00:35:26.095
It's mostly like a liquid thing, so
517
00:35:27.515 --> 00:35:28.415
it's just different,
518
00:35:28.875 --> 00:35:31.214
to to the amount of eyes on a lot of stuff.
519
00:35:32.080 --> 00:35:36.020
They employ a lot of smart people too. Like, you know, cryptographically
520
00:35:36.320 --> 00:35:36.820
speaking,
521
00:35:37.360 --> 00:35:39.220
they have a lot of very, very
522
00:35:40.035 --> 00:35:41.575
high quality cryptographers
523
00:35:41.955 --> 00:35:42.695
at Blockstream.
524
00:35:44.115 --> 00:35:50.109
So I I don't think that would be the the attack surface there. I think for them would be more like implementation on the hardware
525
00:35:50.970 --> 00:35:51.369
and,
526
00:35:51.930 --> 00:35:52.910
you know, just,
527
00:35:53.289 --> 00:35:56.190
you know, ESP 32. It's a Swiss cheese.
528
00:35:57.515 --> 00:36:01.535
Man, I think we should rename this pod the the bitching about wallet pod.
529
00:36:03.435 --> 00:36:10.680
We join you every few weeks to bitch and also to be grateful. I mean, the last one the last one, we didn't bitch this much.
530
00:36:11.700 --> 00:36:16.995
531
00:36:18.735 --> 00:36:21.075
532
00:36:21.535 --> 00:36:22.035
0.3.1.1.
533
00:36:25.339 --> 00:36:26.720
Loads of updates.
534
00:36:28.619 --> 00:36:30.640
I think it was Bitcoin mechanic who
535
00:36:31.635 --> 00:36:35.575
who gave us the update. Oh, Jesus Christ. It is a lot of updates.
536
00:36:37.395 --> 00:36:39.815
I'll start reading some, and then I'll give up.
537
00:36:40.500 --> 00:36:41.000
Doctor,
538
00:36:41.380 --> 00:36:42.600
doctor, Docker,
539
00:36:43.220 --> 00:36:44.200
stats fix,
540
00:36:45.780 --> 00:36:47.000
update back end dependencies,
541
00:36:47.860 --> 00:36:48.760
fix receipt,
542
00:36:49.295 --> 00:36:50.355
receipts, health,
543
00:36:52.255 --> 00:36:58.089
return correct. Okay, guys. You guys really need to you could work on her. Keep going. It's so
544
00:36:58.470 --> 00:37:01.210
so organic. I can't I can't do this. It's too long.
545
00:37:01.910 --> 00:37:05.450
There's like 50, like it's literally every commit
546
00:37:05.815 --> 00:37:07.995
too long. Is there a TLDR?
547
00:37:08.855 --> 00:37:10.075
Let's look at their website.
548
00:37:10.535 --> 00:37:11.195
549
00:37:12.135 --> 00:37:18.430
a it's it's not a major commit there. How many decimal places here? Three decimal places in this version. Yeah. That's not.
550
00:37:20.730 --> 00:37:24.030
551
00:37:24.395 --> 00:37:26.735
You guys have any comments about, Embassy OS?
552
00:37:28.075 --> 00:37:34.020
553
00:37:35.599 --> 00:37:37.059
Well, stuff I never heard of.
554
00:37:37.920 --> 00:37:43.925
Burn after reading share messages and files that are destroyed after they are viewed. You know, all kinds of little things like this you never heard of.
555
00:37:44.385 --> 00:37:46.325
And even, like, for example, after the,
556
00:37:48.065 --> 00:37:51.205
what was the, Ethereum thing that got that got sanctioned?
557
00:37:52.210 --> 00:37:55.910
Oh, no. They're coming in at for my studio here. Tornado Cash.
558
00:37:56.210 --> 00:37:59.670
Yeah. Tornado Cash. After that, they they did a self hosted
559
00:38:00.975 --> 00:38:05.955
get service that they added, you know. So they add all kinds of stuff to there, much more so than I think any other implementations
560
00:38:06.255 --> 00:38:06.915
tend to.
561
00:38:07.535 --> 00:38:12.100
562
00:38:12.880 --> 00:38:15.040
563
00:38:16.960 --> 00:38:20.020
everyone I've talked to that uses it really enjoys it.
564
00:38:20.545 --> 00:38:27.045
And I I just I I appreciate I appreciate their goal, which is basically all the things that we currently use,
565
00:38:27.640 --> 00:38:28.140
like
566
00:38:28.760 --> 00:38:29.340
AWS and
567
00:38:29.800 --> 00:38:31.740
these big cloud providers for.
568
00:38:32.280 --> 00:38:36.619
You know, maybe we can host some of those at home in a relatively easy convenient way.
569
00:38:36.925 --> 00:38:39.425
570
00:38:39.885 --> 00:38:41.025
try to cover everything.
571
00:38:41.405 --> 00:38:44.465
572
00:38:44.819 --> 00:38:49.480
Like, Bitcoin supported on it. No. But it's really a sovereignty project.
573
00:38:50.020 --> 00:38:50.740
574
00:38:51.140 --> 00:38:54.964
like, your own cloud. Like, there was there was a term for this.
575
00:38:56.625 --> 00:38:58.405
Self cloud. Self hosting?
576
00:38:58.785 --> 00:38:59.285
Cloud.
577
00:39:00.120 --> 00:39:01.640
No. No. But there was, like
578
00:39:02.280 --> 00:39:05.740
remember, like, when when people started getting pissed at Dropbox
579
00:39:06.280 --> 00:39:09.935
and all this service, the the photo sort of hosting software,
580
00:39:10.635 --> 00:39:12.895
somebody came up with a term for this stuff.
581
00:39:13.755 --> 00:39:16.575
Whatever. Let's call it own cloud, cloud,
582
00:39:16.960 --> 00:39:17.460
cloud.
583
00:39:18.240 --> 00:39:19.060
Own cloud.
584
00:39:20.720 --> 00:39:21.220
Alright.
585
00:39:23.120 --> 00:39:23.940
Ras Blitz,
586
00:39:24.585 --> 00:39:25.164
introduction of
587
00:39:25.785 --> 00:39:27.244
WebUI and API.
588
00:39:28.585 --> 00:39:31.805
Rasp Blitz is an interesting project. This is fairly Bitcoin
589
00:39:32.105 --> 00:39:32.765
sort of
590
00:39:34.310 --> 00:39:36.810
591
00:39:37.270 --> 00:39:38.490
a Bitcoin project.
592
00:39:38.950 --> 00:39:45.595
Yeah. They have CK bunker. Yeah. They support pretty much every good Bitcoin project that, you know, that you want
593
00:39:46.295 --> 00:39:48.875
to use with your own node and that you want hosted 247,
594
00:39:49.175 --> 00:39:53.160
and you can run it relatively easily. Now it's interesting because,
595
00:39:54.420 --> 00:39:57.160
you know, RAS by Bliss has always been extremely powerful,
596
00:39:57.994 --> 00:40:03.134
and I honestly think it's pretty convenient to use. But for their their big differentiator,
597
00:40:03.595 --> 00:40:08.230
the the reas all of a sudden, all these other node projects started to be successful.
598
00:40:09.250 --> 00:40:11.109
You could think like Umbrel and MyNode.
599
00:40:12.930 --> 00:40:18.454
They were becoming successful because they were more convenient to use than RAS by Blitz, and that was because they had a web UI.
600
00:40:18.755 --> 00:40:20.135
And for a long time,
601
00:40:23.069 --> 00:40:25.410
the Raspberry Pi Blitz guys did not want to
602
00:40:25.710 --> 00:40:30.930
they said, you know, if if you can't figure out how to use our command line interface, then use a different project.
603
00:40:31.665 --> 00:40:34.005
But it looks like I mean, technically,
604
00:40:34.785 --> 00:40:35.685
605
00:40:35.985 --> 00:40:39.125
you know, for half of the purposes people use this
606
00:40:39.510 --> 00:40:40.010
these,
607
00:40:40.630 --> 00:40:41.770
node in a box,
608
00:40:42.790 --> 00:40:46.730
honestly, they shouldn't be using them if they don't know what's going on under,
609
00:40:47.654 --> 00:40:50.954
especially with, like, auto updates and stuff for core,
610
00:40:51.654 --> 00:40:54.075
major attack surface there. Right. But
611
00:40:54.710 --> 00:41:02.329
612
00:41:03.155 --> 00:41:08.055
613
00:41:09.315 --> 00:41:09.715
Alright.
614
00:41:10.195 --> 00:41:11.015
B d k
615
00:41:11.475 --> 00:41:11.975
645
616
00:41:13.300 --> 00:41:14.119
adds away
617
00:41:14.660 --> 00:41:17.800
well, this is just a pull request. It's not a release yet, but,
618
00:41:18.820 --> 00:41:20.440
adds away to specify
619
00:41:20.900 --> 00:41:21.720
which Taproot
620
00:41:22.265 --> 00:41:24.525
span paths to sign for.
621
00:41:24.905 --> 00:41:27.965
Previously, bdk would sign for a key path
622
00:41:28.265 --> 00:41:30.365
span if it was able,
623
00:41:30.880 --> 00:41:33.460
plus sign for any script path leaves
624
00:41:33.920 --> 00:41:34.420
it,
625
00:41:35.359 --> 00:41:38.180
leaves it had the keys for.
626
00:41:40.184 --> 00:41:41.565
That doesn't sound right.
627
00:41:42.025 --> 00:41:42.525
Anyways
628
00:41:43.545 --> 00:41:48.045
yeah. No. BDK, it's it's it's interesting. It's a lot of effort going to it. It's a shame it's in Rust.
629
00:41:52.560 --> 00:41:59.665
630
00:42:00.045 --> 00:42:08.170
sometimes. It's not trying to sign too much. You know? Like, if if there's hidden things in the Taproot, it's trying not to, like, leak them, basically. That's what I'm guessing.
631
00:42:08.710 --> 00:42:09.770
632
00:42:10.150 --> 00:42:19.244
It also makes sense. Right? Because with Taproot, you you don't know what you don't know as part of the script. Right? Because there's there's a bunch of other stuff that could be there that
633
00:42:19.705 --> 00:42:21.725
634
00:42:22.690 --> 00:42:23.350
635
00:42:26.130 --> 00:42:26.630
Alright.
636
00:42:27.890 --> 00:42:30.150
It's nice to see Taproot sort of, like,
637
00:42:30.835 --> 00:42:31.335
moving
638
00:42:31.875 --> 00:42:34.775
in in in good Bitcoin fashion, like, boring
639
00:42:35.075 --> 00:42:36.454
and sort of quietly
640
00:42:36.755 --> 00:42:37.255
moving
641
00:42:38.020 --> 00:42:38.680
a lot.
642
00:42:39.780 --> 00:42:41.640
643
00:42:42.100 --> 00:42:44.200
644
00:42:44.580 --> 00:42:49.275
I'll die before I move to Segwit. Have you used the Segwit address yet? What's that?
645
00:42:51.734 --> 00:42:57.115
646
00:42:57.520 --> 00:43:08.335
647
00:43:08.875 --> 00:43:10.255
like, what percentage of
648
00:43:10.555 --> 00:43:12.015
all UTXOs are Taproot.
649
00:43:12.474 --> 00:43:16.095
And this is BitNex's thing. It's down right now. But it was, like, something like 0.06
650
00:43:16.450 --> 00:43:17.430
percent of all transactions
651
00:43:18.210 --> 00:43:22.390
are, are tap root right now, the UTXO set. So it's it's very minimally,
652
00:43:22.930 --> 00:43:25.595
Point 6? Something like that.
653
00:43:25.895 --> 00:43:31.675
0.6 or 0.06? Yeah. We add it to the show notes. Yeah. It's just it's crashed right now, so I can't see.
654
00:43:32.060 --> 00:43:34.560
655
00:43:35.020 --> 00:43:41.280
when it comes to money, I am a huge fan of not changing anything unless you need the something that's gonna come from it.
656
00:43:41.985 --> 00:43:42.725
You know,
657
00:43:43.265 --> 00:43:49.925
like, Taproot is amazing, very cool. Can't wait to have all kinds of cool stuff I can do with it, but I'm not gonna use it for real money,
658
00:43:50.320 --> 00:43:52.900
for real every day until there's a specific feature
659
00:43:53.200 --> 00:43:55.540
660
00:43:55.840 --> 00:43:56.900
100% aligned.
661
00:43:57.680 --> 00:43:58.180
662
00:43:59.244 --> 00:44:00.785
I'm glad to hear it, Matt.
663
00:44:01.244 --> 00:44:17.495
664
00:44:17.875 --> 00:44:20.215
665
00:44:20.755 --> 00:44:25.470
666
00:44:26.250 --> 00:44:26.750
where
667
00:44:27.930 --> 00:44:31.150
you don't have to to have an order for the signers.
668
00:44:31.714 --> 00:44:36.454
Yeah. While the legacy analysts as you do, which is a huge deal
669
00:44:36.915 --> 00:44:41.255
when the widow of a programmer who overcomplicated the script hits our support.
670
00:44:41.700 --> 00:44:42.200
671
00:44:43.220 --> 00:44:43.720
672
00:44:44.260 --> 00:44:45.640
next is, Kotlin
673
00:44:46.580 --> 00:44:47.080
multiplatformtor,
674
00:44:49.895 --> 00:44:51.115
Add store controller
675
00:44:51.415 --> 00:44:55.035
support for map address and resolve, full change log there.
676
00:44:55.655 --> 00:44:58.475
Who was it who brought this up? Somebody did on the
677
00:44:58.840 --> 00:44:59.660
on the issues.
678
00:45:00.440 --> 00:45:03.100
Nice to see more tour stuff happening.
679
00:45:04.840 --> 00:45:05.740
Alright, guys.
680
00:45:06.224 --> 00:45:10.005
We're moving on to the noteworthy section of the show.
681
00:45:11.505 --> 00:45:13.845
New self custody redundancy service,
682
00:45:14.559 --> 00:45:15.380
seed bank,
683
00:45:15.680 --> 00:45:16.180
upstart,
684
00:45:17.039 --> 00:45:18.260
service for passphrase,
685
00:45:18.720 --> 00:45:23.694
multisig users act as an Internet connected location in the context of redundancy backups.
686
00:45:24.954 --> 00:45:26.335
Seeds are sent obscure
687
00:45:27.115 --> 00:45:31.454
obscured over multiple channels, stored offline, anonymous operators, synonymous.
688
00:45:32.360 --> 00:45:33.020
689
00:45:33.640 --> 00:45:34.460
Like an ad?
690
00:45:36.360 --> 00:45:38.620
691
00:45:39.805 --> 00:45:40.445
that's their,
692
00:45:41.165 --> 00:45:47.585
It's a seed bank. It's a seed bank just like, for Kumrockets. Like a third party service. Right?
693
00:45:48.210 --> 00:45:52.390
694
00:45:52.930 --> 00:45:53.670
695
00:45:54.130 --> 00:45:55.775
696
00:45:56.335 --> 00:45:59.954
It was working before when I checked. You gotta get rid of the www.
697
00:46:00.414 --> 00:46:01.315
And then it worked.
698
00:46:01.775 --> 00:46:02.275
699
00:46:02.895 --> 00:46:03.295
So
700
00:46:04.220 --> 00:46:15.145
701
00:46:15.525 --> 00:46:16.984
I I I can't remember.
702
00:46:17.285 --> 00:46:18.105
Point is,
703
00:46:18.484 --> 00:46:19.305
it's essentially
704
00:46:19.685 --> 00:46:21.145
a place for you to
705
00:46:21.730 --> 00:46:25.430
store your seed on the 3rd party, which is kind of a terrible idea,
706
00:46:26.450 --> 00:46:28.630
but at the same time, it is kinda cool.
707
00:46:29.065 --> 00:46:37.725
If provided that encryption is strong enough and you know the implementation of the encryption does not have any And the website works. And the backdoor there's no backdoors.
708
00:46:38.430 --> 00:46:47.250
709
00:46:49.315 --> 00:46:49.815
710
00:46:50.355 --> 00:46:50.934
I mean,
711
00:46:51.395 --> 00:46:54.055
personally, you probably wanna encrypt before
712
00:46:54.434 --> 00:46:57.859
713
00:46:58.560 --> 00:47:01.220
encrypt it and put it in some kind of cloud or something?
714
00:47:02.935 --> 00:47:07.415
715
00:47:08.215 --> 00:47:09.275
Yeah. Final Message.
716
00:47:09.580 --> 00:47:14.640
Final message in a little bit. So it's like a way to store seeds. I always wanted to make a online
717
00:47:15.660 --> 00:47:17.600
lockbox Yeah. Right, for people.
718
00:47:18.060 --> 00:47:20.875
The problem is unless you can prove
719
00:47:21.494 --> 00:47:25.115
that the stuff is not illegal stuff in the file,
720
00:47:25.494 --> 00:47:26.795
you could have
721
00:47:27.630 --> 00:47:28.130
spam
722
00:47:28.590 --> 00:47:29.650
takedown requests.
723
00:47:30.110 --> 00:47:32.690
724
00:47:33.310 --> 00:47:38.535
But I I mean, when I was thinking about with final message, it was specifically for inheritance.
725
00:47:39.555 --> 00:47:45.540
We're like, some trade offs have to be made for inheritance and you have to be careful with those trade offs because they can affect your
726
00:47:46.020 --> 00:47:52.840
727
00:47:53.565 --> 00:48:19.285
728
00:48:20.040 --> 00:48:20.700
to someone
729
00:48:21.240 --> 00:48:22.220
after you die?
730
00:48:22.520 --> 00:48:33.565
I didn't check that fully. No. Because that could be that's useful. Like, I was hoping the only reason I created Final Mess because no one else did it. I needed that's the tool that could be very useful to me. If I could take a multisig
731
00:48:35.384 --> 00:48:36.924
one signer in the multisig
732
00:48:38.030 --> 00:48:40.930
and be able to pass that down to someone,
733
00:48:41.869 --> 00:48:43.730
in a dead man switch kinda way.
734
00:48:44.030 --> 00:48:45.250
735
00:48:45.630 --> 00:48:46.530
of having
736
00:48:48.295 --> 00:48:49.675
a encrypted lockbox
737
00:48:49.975 --> 00:48:50.875
on the Internet
738
00:48:51.895 --> 00:48:53.675
that is available to you,
739
00:48:54.610 --> 00:49:00.950
but I don't see a safe way of making that project in a way that the founders don't go to GAO or
740
00:49:01.890 --> 00:49:02.630
is just
741
00:49:02.955 --> 00:49:04.815
completely spammed out of existence
742
00:49:05.435 --> 00:49:10.735
with takedowns that you don't wanna fight in court. But if it's text, that's not the case.
743
00:49:11.430 --> 00:49:16.650
Well, but but then you can't really do text. It needs to be encrypted. Yeah. But encrypted text.
744
00:49:17.110 --> 00:49:18.330
No. You can't. But that
745
00:49:18.925 --> 00:49:21.665
then you can't prove that the data inside that
746
00:49:22.285 --> 00:49:24.385
is not something that shouldn't be there.
747
00:49:24.765 --> 00:49:25.265
See,
748
00:49:25.565 --> 00:49:30.860
what what law enforcement is gonna do is they're gonna be dicks. They're gonna go they're gonna get,
749
00:49:32.120 --> 00:49:39.915
kind of pictures that gets people in jail, and then they're gonna encrypt those pictures. Right? And then they're gonna put on your website, and they're gonna go to the judge and say, look.
750
00:49:40.775 --> 00:49:50.130
There is encrypted pictures of things that shouldn't be there. But how do they put pictures and text? Well, it's it's gonna be binary, my Matt. That's the encrypted data,
751
00:49:50.705 --> 00:49:53.045
unless you're using XOR or something else,
752
00:49:53.425 --> 00:50:02.950
and that would have to be a seed kind of thing. But if there's if if there's just a text box on the website. No. But it doesn't matter. I could see, I could get binary data
753
00:50:03.250 --> 00:50:05.430
or or, you know, encoded
754
00:50:06.050 --> 00:50:07.430
base 58 or whatever.
755
00:50:07.730 --> 00:50:15.415
Right? That looks like text dumped on your on an input box on your website and upload it. But no, a character limit prevents that.
756
00:50:15.715 --> 00:50:16.215
No.
757
00:50:16.630 --> 00:50:19.930
You can do BIS 58. So that's the that's the characters
758
00:50:20.310 --> 00:50:21.770
that you would use for text.
759
00:50:22.550 --> 00:50:24.715
760
00:50:25.275 --> 00:50:25.775
761
00:50:26.795 --> 00:50:30.735
Yeah. Yeah. That that's that's how, for example, you put, like, say, PNGs
762
00:50:31.915 --> 00:50:32.415
in
763
00:50:32.890 --> 00:50:36.430
a, like, on page on a web in an HTML file.
764
00:50:37.050 --> 00:50:42.484
Anyways, point is it's very easy to yes. You can encode your binary data in whichever
765
00:50:42.945 --> 00:50:49.045
sort of format you want. Base 58 is an extremely common one because it is a limited char set
766
00:50:49.369 --> 00:50:53.710
that looks exactly like text, so that there is no issues with the parsers,
767
00:50:54.250 --> 00:50:57.150
and then somebody can put that stuff in your website.
768
00:50:57.745 --> 00:50:58.245
Noted.
769
00:50:58.865 --> 00:50:59.365
Now
770
00:50:59.825 --> 00:51:01.845
if you have normalized data,
771
00:51:02.145 --> 00:51:03.685
say for example seeds,
772
00:51:04.750 --> 00:51:07.650
you could come up with a SPAC that it can provably
773
00:51:08.190 --> 00:51:11.490
say that there is 12 words in there,
774
00:51:12.005 --> 00:51:14.345
as opposed to encrypted pictures.
775
00:51:16.165 --> 00:51:16.665
Anyways,
776
00:51:18.165 --> 00:51:26.720
moving on from this one. It's a tricky one. It was all over Twitter. I figured I'd mention it. It's actually good that we discussed it in case somebody was thinking about putting their seed there.
777
00:51:27.744 --> 00:51:32.325
Foundry, the largest mining pool provides grants to open source Stratum V2.
778
00:51:32.705 --> 00:51:36.405
That's great. We need Stratum 2 v 2 to happen.
779
00:51:37.050 --> 00:51:37.950
It's about time.
780
00:51:38.330 --> 00:51:41.550
781
00:51:42.010 --> 00:51:44.330
mining pool in the world, but also because
782
00:51:46.365 --> 00:51:53.025
so so a major aspect of stratum b two is right now mining pool operators are able they're the ones who choose
783
00:51:53.325 --> 00:51:55.345
which transactions go into a block.
784
00:51:56.820 --> 00:51:58.680
They can obviously be coerced,
785
00:52:00.020 --> 00:52:01.720
or forced to
786
00:52:02.420 --> 00:52:13.385
not include certain transactions, so they become a central point of failure. In the current setup, individual miners in that situation could leave and go to a different pool. They basically have, like, a soft,
787
00:52:13.970 --> 00:52:15.590
like a soft veto there.
788
00:52:16.609 --> 00:52:25.414
But with Stratum v 2, one of the implications of it, one of the main goals of it is to make it so that the individual miners actually construct the blocks.
789
00:52:26.595 --> 00:52:34.210
So it takes that power away from the pool operator and gives it to all these individual miners that are much more distributed than the pool operators.
790
00:52:36.349 --> 00:52:38.369
Also notable here is Foundry
791
00:52:39.665 --> 00:52:40.565
fully KYCs
792
00:52:40.865 --> 00:52:42.165
all of their customers.
793
00:52:42.545 --> 00:52:43.765
So they're, like, particularly
794
00:52:45.265 --> 00:52:47.125
regulatory friendly pool,
795
00:52:48.410 --> 00:52:49.870
and they're funding something
796
00:52:51.530 --> 00:52:52.030
that
797
00:52:52.730 --> 00:52:55.790
dethoots a lot of that defangs a lot of that regulation.
798
00:52:56.385 --> 00:52:59.045
799
00:53:00.865 --> 00:53:01.845
that is not
800
00:53:06.660 --> 00:53:13.800
aligned with the state thinking. They're just following, you know, the regulation that they have to so they don't get in trouble.
801
00:53:15.015 --> 00:53:19.115
Sees that it's important to create the tools that makes regulation pointless.
802
00:53:19.494 --> 00:53:20.234
So then
803
00:53:20.615 --> 00:53:23.194
they can get out of it without having to fight it.
804
00:53:23.700 --> 00:53:24.200
805
00:53:25.059 --> 00:53:28.680
But, anyway, great to see. Shout out to the founder team on this one.
806
00:53:29.059 --> 00:53:34.755
807
00:53:35.295 --> 00:53:42.595
sort of people sort of thinking that, you know, Coinbase is gonna fight, you know, the US government and risk 30 years in prison,
808
00:53:43.440 --> 00:53:44.740
for all the executives.
809
00:53:46.560 --> 00:53:48.260
You know, it's completely ludicrous.
810
00:53:49.200 --> 00:53:50.980
It's not it's completely unrealistic.
811
00:53:52.155 --> 00:53:54.974
You know, nobody's gonna risk jail time
812
00:53:55.515 --> 00:53:58.815
because, you know, people want privacy. That's why the
813
00:53:59.115 --> 00:54:01.700
regulations are designed the way that they are, is to
814
00:54:02.660 --> 00:54:05.960
discourage large companies from supporting the privacy stuff,
815
00:54:08.020 --> 00:54:13.215
and it's designed very well. Like, they're they're very good at making things awful to people.
816
00:54:14.555 --> 00:54:14.795
So,
817
00:54:15.995 --> 00:54:17.695
the technology has to be inherently
818
00:54:18.420 --> 00:54:20.280
good at making regulation
819
00:54:21.060 --> 00:54:21.560
useless,
820
00:54:21.940 --> 00:54:22.760
not requiring
821
00:54:23.540 --> 00:54:25.320
some large entity to be benevolent.
822
00:54:26.355 --> 00:54:29.255
823
00:54:29.715 --> 00:54:33.895
And laughing too. No. I was laughing. I was laughing at Justin eating.
824
00:54:34.900 --> 00:54:35.400
825
00:54:36.020 --> 00:54:37.960
Small bite. Long podcast.
826
00:54:38.900 --> 00:54:39.560
827
00:54:40.180 --> 00:54:42.440
Can't you stay 2 hours without eating?
828
00:54:42.775 --> 00:54:46.474
829
00:54:50.535 --> 00:54:51.035
830
00:54:52.630 --> 00:55:03.435
Wait. Why don't we talk about no. No. No. Let's talk about tornado cache. I'm curious in your opinion. No. We will. After. After. Okay. Yeah. Because then there is, like, more than one story there.
831
00:55:04.215 --> 00:55:08.715
I'm I'm I but I only have so much capacity of reading text, Matt.
832
00:55:09.160 --> 00:55:15.900
833
00:55:16.424 --> 00:55:21.964
834
00:55:23.065 --> 00:55:28.240
835
00:55:28.540 --> 00:55:30.720
836
00:55:31.180 --> 00:55:36.015
News and noteworthy. Okay. Or just noteworthy. Why is Nick's Bitcoin in here then? Because,
837
00:55:37.115 --> 00:55:51.805
838
00:55:52.425 --> 00:55:56.285
thing like that. It's more security focused, less moving parts.
839
00:55:56.680 --> 00:55:58.359
The interesting thing is, like, next is a,
840
00:55:59.720 --> 00:56:00.460
it's actually
841
00:56:00.760 --> 00:56:09.275
a distribution of Linux where you can have, like, one little config file that can completely define your operating system, and it can, you know, build an entire
842
00:56:09.655 --> 00:56:21.859
operating system from that. And so you can have all kinds of restrictions, like what users can see which folders and can make which network requests. You can really lock it down at the operating system level. And so Nix Bitcoin is,
843
00:56:22.325 --> 00:56:23.465
a config, basically,
844
00:56:23.765 --> 00:56:34.110
in next that can build up such an operating system just for running a Bitcoin node, lightning node, and other things like that. So it's very security focused. Like, you know, for example, Jonas Nick from Blackstream
845
00:56:34.490 --> 00:56:43.365
is one of the main people behind it. I mean, he was just basically building a node from himself, and next batch plan is what it became. And so we're, Teddy went I think some probably some of our first
846
00:56:43.905 --> 00:56:45.925
production deployments will use this,
847
00:56:46.600 --> 00:56:52.700
just because we were using mix for our developer environment and our build system currently, and so it's pretty easy to just
848
00:56:53.505 --> 00:56:59.765
integrate it with this. So it's a it's a it's a really interesting security focus like node in a box solution that's much more aimed at tempers.
849
00:57:00.145 --> 00:57:03.470
850
00:57:03.850 --> 00:57:06.590
they're very careful about dependencies management
851
00:57:07.770 --> 00:57:15.585
and, and reproducible builds. Right? So they they take a lot of extra effort to make sure that the dependencies
852
00:57:16.125 --> 00:57:16.285
are
853
00:57:17.060 --> 00:57:22.360
let's call it this way, the supply chain of dependencies, that the dependency chain is way better managed,
854
00:57:23.540 --> 00:57:28.415
and is sort of properly paid attention to, so you're not pulling some of the dependency that could be
855
00:57:28.715 --> 00:57:42.520
a non review new version that has a hole in it or something like that. They're they're a lot more conservative about dependencies that than your usual Linux. Yeah. This is this is the whole point of the project. This is the the reason it's different from other ones, is that they they
856
00:57:42.980 --> 00:57:43.480
857
00:57:44.725 --> 00:57:47.865
the software. It's just a is is a graph of dependencies. Right?
858
00:57:48.405 --> 00:57:56.360
So it's like Bitcoin Core. Right? Like, I'm just on a very high level. Right? Bitcoin Core is dependent on the GCC compiler because that's what's used to build the code. It's also dependent
859
00:57:56.820 --> 00:58:08.945
on SQLite. That's the database for files. And it's also dependent on LevelDB. That's the database for blocks. SQLite is for blocks. LevelDB is for blocks. So it, but this sort of graph can get much, much more granular
860
00:58:09.329 --> 00:58:24.455
because each one of these has dependencies. And so if you want a really deterministic build, you you need, like, a model of all the dependencies. And so the really cool thing about Nix is that they took this There's actually a fork of it called Geeks, which is used for Bitcoin Chorus build system, which took this to the absolute extreme
861
00:58:24.835 --> 00:58:25.315
where,
862
00:58:26.299 --> 00:58:28.559
not only can you build
863
00:58:29.019 --> 00:58:30.559
basically, like, if you use Ubuntu,
864
00:58:30.859 --> 00:58:35.200
you start you have to trust about 400 megabytes of trusted binaries.
865
00:58:35.665 --> 00:58:41.365
Like, they're just, blobs of of of computer programs that you can't really audit. They're outputs of compilers.
866
00:58:41.744 --> 00:58:47.720
But, with geeks, you can build you can basically build all that from from source and a 250
867
00:58:48.100 --> 00:58:48.600
byte
868
00:58:48.900 --> 00:59:05.740
trusted binary. So, like, this is basically a a a really interesting way of of making it so your reproducible build for a software project is, like, reproducibly correct. It's built from source code and not source code and a bunch of trusted binaries can't audit. So it's it's really interesting for security.
869
00:59:06.120 --> 00:59:08.380
870
00:59:09.000 --> 00:59:19.025
871
00:59:19.960 --> 00:59:21.980
they're all the way on the security side.
872
00:59:22.440 --> 00:59:27.580
873
00:59:28.904 --> 00:59:30.204
874
00:59:30.664 --> 00:59:34.605
875
00:59:35.980 --> 00:59:36.720
the other lead maintainer
876
00:59:37.340 --> 00:59:41.760
on on dispatch, and it was a really great conversation. It was episode 40 42.
877
00:59:42.540 --> 00:59:44.960
878
00:59:45.345 --> 00:59:48.005
879
00:59:49.984 --> 00:59:50.484
signatures.
880
00:59:50.865 --> 00:59:51.924
He's a real cryptographer.
881
00:59:52.440 --> 00:59:53.660
He's fucking awesome.
882
00:59:53.960 --> 00:59:54.460
883
00:59:55.160 --> 00:59:57.260
884
00:59:57.640 --> 00:59:59.020
you know, he works for Blockstream.
885
00:59:59.640 --> 01:00:01.180
Alright. Signing devices.com.
886
01:00:02.715 --> 01:00:08.895
Oh, that's mine. It's a website to remind everybody that hardware wallets are a stupid term for Bitcoin wallets.
887
01:00:09.355 --> 01:00:11.775
It should be signing devices for hardware.
888
01:00:12.130 --> 01:00:13.670
You can go there and check it out.
889
01:00:15.329 --> 01:00:16.630
890
01:00:17.010 --> 01:00:19.430
891
01:00:21.325 --> 01:00:25.505
892
01:00:26.765 --> 01:00:27.265
Yeah.
893
01:00:27.565 --> 01:00:31.260
Oh, but you didn't But Did you did you did you not approve the pull request?
894
01:00:32.519 --> 01:00:33.339
895
01:00:34.200 --> 01:00:35.160
896
01:00:35.640 --> 01:00:38.779
I just wanted to say on the previous on the previous topic,
897
01:00:39.135 --> 01:00:41.875
you said it's another lizard creation. I mean,
898
01:00:42.415 --> 01:00:43.934
the Bitcoin space has has
899
01:00:46.550 --> 01:00:49.770
I wonder how many people in the Bitcoin space recognize that
900
01:00:50.710 --> 01:00:51.210
comment.
901
01:00:52.230 --> 01:00:55.954
902
01:00:56.414 --> 01:00:58.035
the block wars Exactly.
903
01:00:58.815 --> 01:01:02.595
The a lot of people were saying that, you know, like,
904
01:01:03.310 --> 01:01:09.090
me and other people who supported small blocks were people paid by Blockstream, which I'm not,
905
01:01:09.550 --> 01:01:10.930
and we were all dragons,
906
01:01:12.605 --> 01:01:19.345
and we were lizards. So, you know, the the joke going forward always is if you work for Blockstream, you're a lizard.
907
01:01:19.839 --> 01:01:26.339
908
01:01:26.695 --> 01:01:31.755
909
01:01:32.135 --> 01:01:32.955
open source
910
01:01:33.335 --> 01:01:35.995
and all verifiable, so it makes really no difference
911
01:01:36.380 --> 01:01:38.240
even if it was evil.
912
01:01:39.579 --> 01:01:43.440
Alright, tornado cache GitHub taken down, lead developers
913
01:01:44.059 --> 01:01:44.960
accounts frozen,
914
01:01:46.115 --> 01:01:50.295
and in response to Tornado Cash GitHub being taken down, Start9 added,
915
01:01:50.755 --> 01:01:52.934
GTS service to the EmbaseOS.
916
01:01:54.850 --> 01:01:57.030
Well, we can talk about all that together.
917
01:01:57.890 --> 01:01:58.390
So
918
01:01:58.770 --> 01:02:01.990
for people that don't know, this Tornado Cash was a
919
01:02:02.530 --> 01:02:03.350
sort of like
920
01:02:03.765 --> 01:02:05.225
a quote unquote decentralized
921
01:02:06.244 --> 01:02:07.625
contract on Ethereum
922
01:02:07.925 --> 01:02:09.865
that provided reasonably good privacy,
923
01:02:10.645 --> 01:02:11.145
except
924
01:02:12.085 --> 01:02:13.700
that the way Ethereum
925
01:02:14.000 --> 01:02:14.500
works,
926
01:02:15.280 --> 01:02:16.500
it doesn't have UTXOs
927
01:02:16.800 --> 01:02:18.500
like coins. It has accounts,
928
01:02:18.960 --> 01:02:20.260
which is very dumb.
929
01:02:20.815 --> 01:02:22.675
So anyone who received,
930
01:02:24.175 --> 01:02:26.515
Tornado Cash token into their account,
931
01:02:27.214 --> 01:02:33.720
and all these accounts clearly monitored because within minutes everybody was being sort of like completely doxxed on Twitter,
932
01:02:35.380 --> 01:02:36.840
now has a
933
01:02:37.415 --> 01:02:41.035
has funds from a tool that is under sanctions,
934
01:02:41.655 --> 01:02:44.635
which is a very big deal in in legal
935
01:02:44.960 --> 01:02:45.460
problems.
936
01:02:46.560 --> 01:02:47.300
So, anyways,
937
01:02:47.600 --> 01:02:50.100
there's there's a lot of stuff going on here.
938
01:02:50.400 --> 01:02:52.180
I mean, you know, of course,
939
01:02:52.525 --> 01:02:56.385
you know, they should not take the cold or the dev down because
940
01:02:57.005 --> 01:02:58.385
cold is free speech.
941
01:02:59.245 --> 01:03:04.440
In some countries it's not, maybe in Holland it's not where he is and the reason why he was taken.
942
01:03:05.220 --> 01:03:06.520
My theory is,
943
01:03:07.395 --> 01:03:09.095
you know, if this developer,
944
01:03:09.474 --> 01:03:10.935
one, was in communication
945
01:03:11.315 --> 01:03:12.375
with bad people,
946
01:03:12.675 --> 01:03:14.055
knowingly or unknowingly,
947
01:03:14.355 --> 01:03:19.890
they would use that against him. Ethereum people have a history of talking about DPRK
948
01:03:20.190 --> 01:03:21.569
somehow in North Korea.
949
01:03:22.030 --> 01:03:25.569
I think there was a guy that went there and got arrested on the way back.
950
01:03:26.154 --> 01:03:27.775
951
01:03:28.474 --> 01:03:30.575
Virgil went to Yeah.
952
01:03:31.595 --> 01:03:34.335
North Korea and gave a presentation on how to
953
01:03:35.270 --> 01:03:38.170
use Ethereum to circumvent sanctions and then got arrested.
954
01:03:40.470 --> 01:03:41.290
955
01:03:41.910 --> 01:03:43.050
Generally speaking,
956
01:03:44.195 --> 01:03:45.495
when it comes to
957
01:03:46.435 --> 01:03:48.215
privacy providing tools
958
01:03:48.995 --> 01:03:49.735
that are
959
01:03:50.355 --> 01:03:53.415
highly used by people who the state
960
01:03:53.859 --> 01:03:54.359
deemed
961
01:03:55.380 --> 01:03:55.880
unliked,
962
01:03:56.900 --> 01:03:59.240
and is very very successful.
963
01:04:00.579 --> 01:04:01.400
The state
964
01:04:01.855 --> 01:04:04.755
doesn't care what is correct, what's not correct,
965
01:04:05.055 --> 01:04:12.160
what is truly illegal, what is not illegal, they will find a way to get these people, right, because they are now people of interest.
966
01:04:13.420 --> 01:04:14.320
Remember that
967
01:04:14.700 --> 01:04:21.605
at all, the state doesn't have to really follow the law when it comes to anything that they deemed terrorism or whatever, they would just come up with some bullshit reason,
968
01:04:21.985 --> 01:04:22.485
but
969
01:04:22.785 --> 01:04:25.685
there's also this other concept in law which is
970
01:04:26.440 --> 01:04:28.380
profiting from proceeds of crime.
971
01:04:28.839 --> 01:04:29.339
So
972
01:04:30.040 --> 01:04:31.020
say for example
973
01:04:32.040 --> 01:04:32.540
somebody
974
01:04:33.720 --> 01:04:35.339
runs a coordinator
975
01:04:36.185 --> 01:04:36.925
for CoinJoin,
976
01:04:37.945 --> 01:04:40.365
and they are taking profit directly
977
01:04:40.905 --> 01:04:42.045
from the CoinJoin
978
01:04:42.425 --> 01:04:46.660
of that specific transaction, and the state might see that as a problem,
979
01:04:46.960 --> 01:04:50.339
and they might try to frame it that way and go after the people.
980
01:04:50.825 --> 01:04:54.605
That's, in my view, how they will go after some of these people.
981
01:04:55.625 --> 01:04:59.725
Is that correct? Absolutely not. Is that fucked up? Yes. It is fucked up.
982
01:05:00.025 --> 01:05:05.280
But, you know, these are not the good guys. Right? These are just assholes in suits,
983
01:05:05.740 --> 01:05:06.240
so
984
01:05:07.974 --> 01:05:12.474
it's gonna get weird out there, especially for projects that are like meaningfully
985
01:05:13.335 --> 01:05:17.035
doing volume. Right? These guys were doing quite a bit of volume.
986
01:05:19.580 --> 01:05:20.880
I'm sure Matt will have opinions.
987
01:05:21.420 --> 01:05:22.320
988
01:05:22.780 --> 01:05:24.320
total volume they had done.
989
01:05:25.500 --> 01:05:27.445
990
01:05:27.745 --> 01:05:30.485
991
01:05:31.185 --> 01:05:31.845
the situation,
992
01:05:32.305 --> 01:05:36.030
and we have a lot more to cover. So I don't have that much more to add, but it it was
993
01:05:36.990 --> 01:05:39.410
it was good to hear your opinion on the situation.
994
01:05:40.190 --> 01:05:47.595
995
01:05:48.855 --> 01:05:51.115
but it does. So our
996
01:05:52.680 --> 01:05:54.300
our goal and our
997
01:05:55.320 --> 01:05:59.500
like, we should strive to create tools that don't get the devs in jail,
998
01:06:01.365 --> 01:06:07.945
because, you know, we don't put people in jail because people use the dollar for bad things, you know, it's ridiculous.
999
01:06:08.965 --> 01:06:09.465
So
1000
01:06:10.570 --> 01:06:14.270
unfortunately, there will be a learning curve for people, and, you know,
1001
01:06:14.570 --> 01:06:20.325
you can't you can't prevent. Like, people will come up with alternative solutions, and it's gonna be a cat and mouse game.
1002
01:06:21.345 --> 01:06:25.365
If you're on the, you know, the state side or on the freedom side, it doesn't matter.
1003
01:06:26.570 --> 01:06:27.710
It is what it is.
1004
01:06:28.650 --> 01:06:35.204
I just I just hope that, you know, this guy has a good lawyer and he gets out because it's fucking bullshit. It's just gold.
1005
01:06:35.744 --> 01:06:38.805
1006
01:06:39.664 --> 01:06:43.599
I personally kind of feel like it's a very low lift,
1007
01:06:44.539 --> 01:06:46.319
fact finding kind of mission.
1008
01:06:46.940 --> 01:06:47.920
So, I mean,
1009
01:06:48.380 --> 01:06:56.215
all all the treasury had to do is, you know, they basically just updated the blog post. They just copy and pasted the contract address into,
1010
01:06:56.675 --> 01:06:58.855
you know, the OFAC list blog post.
1011
01:06:59.970 --> 01:07:01.190
And then they just watch,
1012
01:07:01.730 --> 01:07:04.710
and they they just watch to see what happens from there.
1013
01:07:06.130 --> 01:07:10.005
And sure enough, you know, most of these so called DeFi services,
1014
01:07:10.305 --> 01:07:13.285
you know, they have very centralized front ends, and they, like, immediately
1015
01:07:13.825 --> 01:07:20.210
started blocking accounts that are that have a history, a shared history with with that contract address.
1016
01:07:20.750 --> 01:07:24.290
And, the dusting aspect is really interesting because,
1017
01:07:24.635 --> 01:07:27.695
you know, as you said earlier, a bunch of celebrities and stuff
1018
01:07:27.995 --> 01:07:34.460
were getting sent to their account, this Tornado Cash, and you can't there's no coin control in Ethereum, so you can't not spend it.
1019
01:07:37.020 --> 01:07:41.820
So there's gonna be all these things that get exposed because of this single little
1020
01:07:42.645 --> 01:07:51.385
this single change, which was put that contract address into that into that sanctions post. And, it should be interesting to see how everything plays out.
1021
01:07:52.519 --> 01:07:58.779
Personally, in in America, code is is is speech, and speech is supposed to be a protected right.
1022
01:07:59.995 --> 01:08:03.855
Unfortunately, we've learned we can't really rely on on those legal protections.
1023
01:08:05.035 --> 01:08:11.109
I mean, it's it's it's I think I think we will look back and it will be like the start of a very strong
1024
01:08:12.130 --> 01:08:13.109
fight against
1025
01:08:13.945 --> 01:08:14.845
financial privacy
1026
01:08:15.225 --> 01:08:15.965
in the
1027
01:08:16.265 --> 01:08:25.980
the Bitcoin world, but we shall see. On the coordinator side, one thing that should be noted, I think, at least in terms of any kind of service that relies on a centralized coordinator.
1028
01:08:26.680 --> 01:08:29.900
A big thing there is how how hard is it to run a coordinator,
1029
01:08:31.165 --> 01:08:33.505
you know, self host to coordinator through Tor.
1030
01:08:34.365 --> 01:08:36.545
And I wonder if we will see
1031
01:08:37.165 --> 01:08:42.520
if we will see alternative coordinators pop up that are not connected to
1032
01:08:43.059 --> 01:08:44.280
known legal identities.
1033
01:08:44.985 --> 01:08:45.805
1034
01:08:46.585 --> 01:08:51.965
I think what the state just did with this tornado cash thing is piss off a fuck ton of devs.
1035
01:08:52.969 --> 01:08:57.550
And if there is one thing you don't want, it's to piss off a ton of fucking devs.
1036
01:08:57.850 --> 01:08:58.590
1037
01:08:59.210 --> 01:09:01.070
1038
01:09:01.575 --> 01:09:04.315
you know, as much as we get some shit or fried at Ethereum
1039
01:09:04.695 --> 01:09:05.675
design choices,
1040
01:09:06.215 --> 01:09:08.795
you know, like I think we get more pissed at the state
1041
01:09:09.120 --> 01:09:11.780
sort of going boot after these people, right?
1042
01:09:12.080 --> 01:09:12.580
So
1043
01:09:13.280 --> 01:09:21.125
I think there will be a lot of new tools coming out that will be substantially better trying to cover exactly whichever attack scenarios,
1044
01:09:21.585 --> 01:09:22.085
legal
1045
01:09:22.545 --> 01:09:23.364
or technical,
1046
01:09:24.065 --> 01:09:24.724
were used
1047
01:09:25.264 --> 01:09:26.244
after these guys.
1048
01:09:26.670 --> 01:09:28.050
1049
01:09:28.430 --> 01:09:32.610
like, the best thing they could have done to neuter these systems is
1050
01:09:33.070 --> 01:09:47.330
they've been doing nothing for so long that a lot a lot of these projects are built in a completely non adversarial environment. So if there's an adversarial environment all of a sudden Exactly. Things get hard hardened. Right? More robust, and and the end result is
1051
01:09:47.870 --> 01:09:49.570
is stronger tools.
1052
01:09:50.110 --> 01:09:52.909
1053
01:09:54.435 --> 01:09:57.495
fight back in the day. You know, if you wanna classify,
1054
01:09:58.355 --> 01:09:59.495
encryption as munition,
1055
01:09:59.875 --> 01:10:02.215
which is, like, one of the the most
1056
01:10:02.870 --> 01:10:05.530
strict ways of classifying something.
1057
01:10:06.150 --> 01:10:10.490
It's it's like this is, like, literally the worst thing the state can try to do
1058
01:10:11.075 --> 01:10:14.615
is classify something as a weapon of war,
1059
01:10:15.875 --> 01:10:24.760
to prevent citizens from doing anything and having zero legal recourse, and look how that turned out. Right? And then look at the war on drugs and look how that turned out.
1060
01:10:25.145 --> 01:10:25.645
So,
1061
01:10:26.105 --> 01:10:29.405
you know, we're fortunate to live in a time where
1062
01:10:30.664 --> 01:10:31.324
the only
1063
01:10:32.239 --> 01:10:37.460
nuclear option a state has is to turn off everything, which they can't because everybody goes broke.
1064
01:10:37.840 --> 01:10:38.340
Right?
1065
01:10:38.880 --> 01:10:43.405
So if they have any tap open, everything else leaks through.
1066
01:10:43.784 --> 01:10:44.764
So, you know,
1067
01:10:45.304 --> 01:10:50.890
best of luck, and I I I really hope that some of these people that work in this in this entities,
1068
01:10:52.070 --> 01:10:56.570
you know, find a better thing to do with their lives than than to make people's lives miserable.
1069
01:10:57.864 --> 01:10:58.364
Anyways.
1070
01:10:59.385 --> 01:10:59.885
Alright.
1071
01:11:00.344 --> 01:11:00.844
Next,
1072
01:11:01.705 --> 01:11:05.565
is, let's talk about the 2 disclosures at the same time because why not?
1073
01:11:05.900 --> 01:11:06.720
Swan email provider
1074
01:11:07.660 --> 01:11:08.880
leaked data,
1075
01:11:09.980 --> 01:11:11.680
which is Swan's data,
1076
01:11:12.300 --> 01:11:16.275
and Casa discloses also a data breach of the Casa store.
1077
01:11:17.535 --> 01:11:19.875
It it all it's a tricky one because,
1078
01:11:20.415 --> 01:11:22.435
you know, realistically speaking,
1079
01:11:23.220 --> 01:11:30.520
nobody can run an email server anymore. You get immediately flagged as spam by all the big, big email providers.
1080
01:11:31.395 --> 01:11:32.855
So that boat has sailed.
1081
01:11:35.155 --> 01:11:35.655
And,
1082
01:11:36.435 --> 01:11:39.735
you know, this third party email providers
1083
01:11:40.560 --> 01:11:41.620
were not designed
1084
01:11:42.400 --> 01:11:44.580
to have the level of security required
1085
01:11:45.760 --> 01:11:48.739
to hold Bitcoiners' information private.
1086
01:11:49.520 --> 01:11:50.020
So
1087
01:11:50.835 --> 01:11:53.975
it's it's not a matter of if, it's a matter of when
1088
01:11:54.435 --> 01:11:55.415
email providers
1089
01:11:56.675 --> 01:11:57.175
will
1090
01:11:58.410 --> 01:11:59.790
will screw up. Now
1091
01:12:00.410 --> 01:12:04.430
that doesn't mean you can't do something about it, like, for example, delete information.
1092
01:12:05.175 --> 01:12:12.315
You can't guarantee that these email providers will delete their logs and do that, all that stuff. So for email's sake,
1093
01:12:13.390 --> 01:12:13.890
please
1094
01:12:14.430 --> 01:12:16.850
use an email that is not your email,
1095
01:12:17.150 --> 01:12:22.370
like your like, for example, me from way back in the day, you'd have, like, your name,
1096
01:12:22.855 --> 01:12:26.155
full name kind of thing, and Gmail or something like that. Right?
1097
01:12:26.775 --> 01:12:28.155
Don't use those emails.
1098
01:12:29.495 --> 01:12:31.995
I don't use mine of those anymore.
1099
01:12:32.800 --> 01:12:35.620
So maybe use burner emails to order things
1100
01:12:36.240 --> 01:12:37.460
from Bitcoin companies.
1101
01:12:38.320 --> 01:12:40.020
And then for the Casa leak,
1102
01:12:40.505 --> 01:12:43.165
I didn't see full information on that.
1103
01:12:43.625 --> 01:12:48.445
I don't know if this was a storefront that they were running internally, if it was third party.
1104
01:12:49.020 --> 01:12:50.699
Do you guys know if this was,
1105
01:12:51.500 --> 01:12:52.640
internal or external
1106
01:12:53.020 --> 01:12:53.520
breach?
1107
01:12:54.620 --> 01:12:55.680
1108
01:12:56.060 --> 01:12:56.560
1109
01:12:56.875 --> 01:12:59.855
1110
01:13:00.715 --> 01:13:01.215
merchant
1111
01:13:02.074 --> 01:13:02.574
vendor,
1112
01:13:03.515 --> 01:13:08.550
and it was for their store. So it was if you bought, like, additional hardware wallets or Faraday bags
1113
01:13:08.950 --> 01:13:10.810
Right. Or seed plates,
1114
01:13:11.190 --> 01:13:17.465
you would you would get them from that store. So, technically, not all their users, but you have to or or the nodes that they sold.
1115
01:13:18.005 --> 01:13:22.825
So, technically, not all their customers, but probably a large portion of their customers. And then,
1116
01:13:23.510 --> 01:13:32.330
even the Bitcoiners bought the node. And, yeah, a shit ton of people that aren't their customers that just bought the nodes. Right? They probably have more people buy the nodes than use the multisig.
1117
01:13:33.255 --> 01:13:37.915
Maybe I'm talking about it in my ass, but I remember a lot of people bought those nodes when they still had them out.
1118
01:13:38.935 --> 01:13:39.835
1119
01:13:40.989 --> 01:13:44.530
eventually, our store is also gonna get hacked at some point, but,
1120
01:13:45.230 --> 01:14:18.870
you know, we keep it in house for a reason because you can't trust the store providers to defend Bitcoin or information. Trusted third parties or security holes. Yep. And another thing too is that when we delete the data internally, we actually delete the data. We know that the data was deleted. You shouldn't trust us, but this is not about you. It's about us knowing that we deleted the data. Right. You don't have to trust a third party. Like, CoinKite doesn't have to trust a third party with it. Exactly. Like, when when people say trusted third parties or security holes, like, sometimes you have to use a trusted third party, but you wanna use a trusted third party that's not using another trusted third party
1121
01:14:19.250 --> 01:14:23.830
1122
01:14:25.555 --> 01:14:29.495
1123
01:14:30.035 --> 01:14:30.775
for example,
1124
01:14:31.155 --> 01:14:40.600
shipping companies. Right? Like, your information in order to ship to you has to be sent to a shipping company and a company that calculates shipping costs and shit.
1125
01:14:41.140 --> 01:14:41.640
So,
1126
01:14:42.535 --> 01:14:45.915
you know, shipping to a PO box really is your ultimate
1127
01:14:46.775 --> 01:14:47.275
realistic
1128
01:14:47.735 --> 01:14:52.700
solution. Everybody should have a PO box somewhere where they ship stuff to.
1129
01:14:53.160 --> 01:14:58.860
Because listen, the state is gonna find out where you are. Right? Because you normally can't even get a shipping,
1130
01:14:59.375 --> 01:15:05.475
PO box without your ID being photocopied, but It's like full k y c to get one of those. Yeah.
1131
01:15:06.015 --> 01:15:08.435
Yeah. But at least bad guys won't. Right?
1132
01:15:09.160 --> 01:15:10.940
So so that's one nice thing.
1133
01:15:11.560 --> 01:15:17.100
Phone numbers is trickier. Sure. There's a few solutions. No. Use a use a use burner numbers.
1134
01:15:17.720 --> 01:15:21.715
1135
01:15:22.095 --> 01:15:23.555
my pseudo or Hush.
1136
01:15:24.735 --> 01:15:33.395
Use burner emails. If the state's not in the issue, then you can use, like, the different aliases these services offer, like Proton offers it, 2 DeNoto offers it.
1137
01:15:33.875 --> 01:15:37.895
These things reduce your attack surface. Obviously, use companies that,
1138
01:15:38.755 --> 01:15:41.895
you believe are taking your your privacy and your security
1139
01:15:43.350 --> 01:15:43.850
seriously.
1140
01:15:44.950 --> 01:15:46.170
But one thing, Enrique,
1141
01:15:46.630 --> 01:15:48.150
you know, at Bitcoin Park,
1142
01:15:48.550 --> 01:15:54.224
that's one of the key features that we're one of the key benefits we're offering our members is that they can get
1143
01:15:54.525 --> 01:15:55.824
things shipped to the park.
1144
01:15:56.284 --> 01:16:05.119
Nice. And, also, we're just gonna have, like, a merge store. Like, we just wanna have, like, cold cards and block locks and stuff for people to buy there. That that's pretty cool. I mean, having
1145
01:16:05.875 --> 01:16:06.275
1146
01:16:06.675 --> 01:16:07.175
see,
1147
01:16:08.675 --> 01:16:10.775
there's a couple of things going on there, but, like,
1148
01:16:11.475 --> 01:16:12.455
you don't wanna
1149
01:16:12.970 --> 01:16:19.390
have a seal of approval on a reseller, right, because that's a security hole. What you want to have is local webs of trust.
1150
01:16:20.075 --> 01:16:25.455
So there's a few guys who you know that based on the security threat model of their hardware wallet,
1151
01:16:25.835 --> 01:16:31.650
you know, those guys are probably trusted to buy the wallet for you because you trust them. Right.
1152
01:16:32.830 --> 01:16:39.650
Right? Not because they're being certified kind of thing. Right. Straight offs. Because that's stupid. That just gives false security. Exactly.
1153
01:16:40.655 --> 01:16:45.155
That that's pretty cool. And and another thing too is that, like, if you're a company out there
1154
01:16:45.534 --> 01:16:49.920
who wants to sell stuff online, please don't use Shopify, please don't use WooCommerce
1155
01:16:50.380 --> 01:16:51.360
PHP crap.
1156
01:16:52.780 --> 01:16:59.835
It all it doesn't matter that you're hosting the PHP stack. It's still a PHP stack store, not designed to be safe.
1157
01:17:00.215 --> 01:17:00.715
Right?
1158
01:17:01.335 --> 01:17:03.355
There is a lot of LARPing out there
1159
01:17:04.750 --> 01:17:07.090
about stores, and remember, right,
1160
01:17:08.670 --> 01:17:10.130
like it seems to be
1161
01:17:10.990 --> 01:17:12.610
that the marketing and
1162
01:17:13.065 --> 01:17:13.965
commercial tools
1163
01:17:14.505 --> 01:17:17.885
are always how most Bitcoin companies get owned.
1164
01:17:18.905 --> 01:17:26.550
Remember the Ledger guys was not like, them or their store themselves. It was the the CRM tool that was feeding from the store. List.
1165
01:17:27.010 --> 01:17:32.775
1166
01:17:35.155 --> 01:17:39.095
1167
01:17:39.530 --> 01:17:43.550
Okay? Having a CRM tool, right, having some
1168
01:17:44.010 --> 01:17:48.190
analytics on your sales and your customers and knowing a bit of your customers
1169
01:17:48.625 --> 01:17:51.844
is a huge advantage in sales, it really is. Right?
1170
01:17:52.784 --> 01:17:54.005
The question for companies
1171
01:17:54.465 --> 01:17:55.844
that we asked ourselves
1172
01:17:56.545 --> 01:17:58.570
was, in our case, for
1173
01:17:59.030 --> 01:18:02.410
example, what's worse? And this is like pure selfish question, right?
1174
01:18:03.030 --> 01:18:04.969
What's worse? The cost
1175
01:18:05.475 --> 01:18:06.215
of not having new
1176
01:18:06.515 --> 01:18:08.375
customers because we lost the data
1177
01:18:08.995 --> 01:18:09.495
or
1178
01:18:09.955 --> 01:18:14.535
being able to cater sales to people using a CRM in terms of sales gains?
1179
01:18:15.500 --> 01:18:18.800
I mean, it all, like we, in our opinion, feel like
1180
01:18:19.580 --> 01:18:22.640
having the bad news of being hacked and losing all that information
1181
01:18:23.260 --> 01:18:24.240
is not gonna
1182
01:18:24.545 --> 01:18:26.405
is is gonna be worse for sales
1183
01:18:26.784 --> 01:18:29.125
than having advanced sales capabilities.
1184
01:18:30.704 --> 01:18:32.644
It's a business question, like,
1185
01:18:33.025 --> 01:18:36.320
you know, like forget about the morals of this for a second.
1186
01:18:36.620 --> 01:18:43.445
I think it's a much better way of looking at it. So No. Yeah. 100%. It's not marketing to people. It's not it's not,
1187
01:18:44.304 --> 01:18:51.764
1188
01:18:52.130 --> 01:18:53.590
then get your shit in order,
1189
01:18:53.970 --> 01:18:58.230
or you're not gonna last very long in this space because it's fucking ridiculous. And I I would say
1190
01:18:58.530 --> 01:19:06.255
and I've I've already said this publicly, but I will reiterate it, that specifically on the on the Casa side,
1191
01:19:06.875 --> 01:19:07.615
you know,
1192
01:19:08.040 --> 01:19:09.980
I have a lot of respect for that team,
1193
01:19:10.280 --> 01:19:14.460
but I was, I was really disappointed because the thing is, first of all,
1194
01:19:14.760 --> 01:19:16.380
it's one thing. If you get owned,
1195
01:19:17.025 --> 01:19:20.724
if you get owned, you need to be transparent and you have to learn from your mistakes.
1196
01:19:21.025 --> 01:19:26.450
And with this particular breach, their public release, didn't say what information was leaked.
1197
01:19:26.850 --> 01:19:30.470
You had to go and search for it. Like, they they had emailed people,
1198
01:19:31.810 --> 01:19:36.070
what had actually been leaked, but they their public release didn't say that.
1199
01:19:36.415 --> 01:19:46.114
And I feel like that is that's that's kinda some bullshit. I I don't I don't necessarily have it. Publicly downplaying it. Like, the leaked data was names, emails, phone numbers,
1200
01:19:46.720 --> 01:19:52.100
shipping and billing addresses, and the products ordered. It was it was basically as owned as you could get.
1201
01:19:52.800 --> 01:19:53.620
1202
01:19:55.015 --> 01:19:57.995
I just wanna make sure at least the people who got owned
1203
01:19:58.615 --> 01:20:00.715
got informed that they got owned.
1204
01:20:01.015 --> 01:20:02.715
How people handle their PR,
1205
01:20:03.120 --> 01:20:05.060
there is nice ways, there's bad ways,
1206
01:20:06.080 --> 01:20:07.940
but, like, you know, it's debatable,
1207
01:20:10.080 --> 01:20:18.755
but I I just at least I'm happy to hear that they informed each. They're they're a responsible actor. Right? Like, they're not a bad actor in Bitcoin.
1208
01:20:19.490 --> 01:20:26.550
So and there there's good people there. So, like, I I'm just happy to know that they informed each customer about what got owned.
1209
01:20:27.244 --> 01:20:31.025
I just wish they didn't keep that data because they don't sell nodes anymore.
1210
01:20:31.405 --> 01:20:32.704
Just delete the data.
1211
01:20:33.804 --> 01:20:36.730
1212
01:20:37.370 --> 01:20:53.130
lengths to to not KYC people for their multisig service. Right? Like, this was has been a big Mhmm. Selling point of theirs for a long time. They said they don't do any KYC. You can use a NEM. And, yeah, to leak addresses is
1213
01:20:54.090 --> 01:20:54.989
is, you know,
1214
01:20:55.530 --> 01:20:58.510
is pretty bad. If that's if that's what, like, our core
1215
01:20:59.050 --> 01:21:00.685
thing your business is trying to do.
1216
01:21:01.805 --> 01:21:02.285
1217
01:21:02.845 --> 01:21:06.305
maintaining anything that's online secure is not easy.
1218
01:21:08.125 --> 01:21:14.600
Assume you will get owned. I mean, we we we know eventually our store is gonna get hacked. Right?
1219
01:21:14.980 --> 01:21:17.835
It's like, how can I minimize the amount of data that's there?
1220
01:21:19.594 --> 01:21:20.094
Alright.
1221
01:21:21.835 --> 01:21:25.295
ETH versus BTC differences in capturable attack surface,
1222
01:21:25.870 --> 01:21:27.650
that's a whole different rabbit hole.
1223
01:21:28.030 --> 01:21:32.210
That was there because the list was not this big yet when it was added there,
1224
01:21:32.885 --> 01:21:38.745
but I just I guess I just need to comment a little bit on this just because such a fucking mess out there.
1225
01:21:39.125 --> 01:21:40.665
You can't compare the 2.
1226
01:21:41.090 --> 01:21:41.830
Okay. Bitcoin
1227
01:21:42.610 --> 01:21:45.030
was designed for the worst case scenario.
1228
01:21:46.610 --> 01:21:47.010
It's,
1229
01:21:47.970 --> 01:21:54.675
you know, is designed for a battlefield. It's the Byzantine general's problem. How do you trust a message to get to the other side?
1230
01:21:55.614 --> 01:22:00.409
And Ethereum literally made all the bad trade offs so that it can have,
1231
01:22:00.710 --> 01:22:03.130
you know, high yield smart contracts,
1232
01:22:04.469 --> 01:22:13.635
and, like, it's just, it drives me insane to see all these people arguing as if there is anything to be argued in any sort of comparable footing.
1233
01:22:15.310 --> 01:22:17.409
I assume that you have your tired of that subject.
1234
01:22:17.949 --> 01:22:18.270
1235
01:22:18.909 --> 01:22:22.290
Wait. Was that you went back to Tornado Cash. Is that what just happened?
1236
01:22:22.935 --> 01:22:26.955
1237
01:22:27.495 --> 01:22:28.955
1238
01:22:29.335 --> 01:22:36.150
this is is one of those things. Right? It's it's if if you're trying to build an open global financial network,
1239
01:22:36.610 --> 01:22:38.390
you need a really stable foundation,
1240
01:22:39.315 --> 01:22:43.574
and you need that foundation to be as censorship resistant and robust as possible.
1241
01:22:43.955 --> 01:22:46.215
And so Bitcoin Development has
1242
01:22:46.640 --> 01:22:48.260
has prioritized that
1243
01:22:48.800 --> 01:22:49.780
since the beginning,
1244
01:22:50.239 --> 01:22:57.355
and Ethereum has done pretty much the exact opposite, and that doesn't become obvious right away. So now it's gonna start to become obvious,
1245
01:22:58.455 --> 01:23:05.630
and that that and that's really the situation right now. But see, Ben, what drives me nuts is Bitcoiners
1246
01:23:06.410 --> 01:23:08.989
1247
01:23:09.449 --> 01:23:11.070
as as if there was
1248
01:23:11.465 --> 01:23:13.005
anything to argue about
1249
01:23:13.305 --> 01:23:14.525
on the same footing.
1250
01:23:14.985 --> 01:23:20.925
It's like it's like trying to compare water and oil. Right? Like like it's like it's 2 different things.
1251
01:23:21.370 --> 01:23:27.150
1252
01:23:27.770 --> 01:23:35.375
1253
01:23:35.755 --> 01:23:38.255
you know, it's always been what they've done. Right?
1254
01:23:38.690 --> 01:23:45.430
They they they want to sort of use Bitcoin and sort of like straw man Bitcoin because it makes their keys don't look as bad,
1255
01:23:46.344 --> 01:23:48.925
but it's gonna be a lot of fun to watch that project fail.
1256
01:23:49.945 --> 01:23:59.330
1257
01:23:59.630 --> 01:24:01.090
explaining how you do a CBDC
1258
01:24:01.710 --> 01:24:04.895
on Ethereum. Right? So it's like, I think capture is almost
1259
01:24:05.535 --> 01:24:06.675
a goal to get
1260
01:24:06.975 --> 01:24:14.675
1261
01:24:15.040 --> 01:24:15.780
1262
01:24:16.560 --> 01:24:17.060
Yeah.
1263
01:24:17.760 --> 01:24:19.060
Yep. Right? I mean,
1264
01:24:19.600 --> 01:24:21.780
like, Ethereum is essentially a factory of Ponzi's.
1265
01:24:22.215 --> 01:24:24.715
Mhmm. Which is a shame. Right? Because,
1266
01:24:25.575 --> 01:24:29.195
you know, there is interesting stuff you could build on that platform
1267
01:24:30.110 --> 01:24:32.690
knowing that that platform could be fully captured.
1268
01:24:33.310 --> 01:24:36.050
It's just what pisses me off, I guess, is that they pretend
1269
01:24:37.065 --> 01:24:42.045
that it isn't, right? They pretend it's decentralized, they pretend all this stuff, but, you know,
1270
01:24:42.425 --> 01:24:43.645
it really is AWS,
1271
01:24:44.310 --> 01:24:46.010
right? Everything is running on Amazon,
1272
01:24:46.390 --> 01:24:54.945
nobody can run a node, nobody can verify anything, it's not ultrasound money, it's not a world computer, it's none of the crap that they sell us.
1273
01:24:57.085 --> 01:25:02.239
It really is the false market marketing and Bitcoin affinity scamming that pisses me off, I guess.
1274
01:25:03.020 --> 01:25:05.440
You can see I am very passionate about the topic.
1275
01:25:09.225 --> 01:25:13.085
Alright. This one is, Matt's, Matt related here. OpenSats
1276
01:25:13.385 --> 01:25:15.405
launches legal defense fund.
1277
01:25:16.360 --> 01:25:24.265
It aims to defend open source Bitcoin contributors from lawsuit regarding their activities in Bitcoin and free open source ecosystems
1278
01:25:24.645 --> 01:25:29.705
by directing donations to the fund to to fund legal fees related to the contributions.
1279
01:25:30.245 --> 01:25:31.305
That's pretty cool.
1280
01:25:31.800 --> 01:25:36.220
I think Square or Jack also launched, some some defense fund as well.
1281
01:25:36.840 --> 01:25:39.660
I think Bitcoiners should fight hard and
1282
01:25:40.120 --> 01:25:42.175
with all the money. Right. So,
1283
01:25:42.954 --> 01:25:44.815
1284
01:25:45.755 --> 01:25:49.135
a defense fund for developers facing lawsuits.
1285
01:25:50.179 --> 01:25:51.780
We we had Huddl not,
1286
01:25:52.340 --> 01:25:53.480
reach out to us
1287
01:25:54.020 --> 01:25:54.520
when
1288
01:25:55.219 --> 01:25:57.000
reach out to us a couple of months ago.
1289
01:25:58.225 --> 01:25:58.725
He
1290
01:25:59.185 --> 01:26:04.805
has immense legal burden. He's a very humble dude. He we base I we basically had to push it out of him,
1291
01:26:05.940 --> 01:26:07.159
to ask for help,
1292
01:26:07.780 --> 01:26:10.520
and he's inundated in legal fees right now,
1293
01:26:11.219 --> 01:26:12.760
over a tweet he made,
1294
01:26:13.875 --> 01:26:14.775
about CSW.
1295
01:26:16.035 --> 01:26:16.535
So
1296
01:26:16.995 --> 01:26:18.375
none of the existing
1297
01:26:18.755 --> 01:26:19.255
avenues
1298
01:26:19.555 --> 01:26:20.055
were
1299
01:26:21.489 --> 01:26:23.670
he he didn't have any help any other way.
1300
01:26:24.610 --> 01:26:25.989
So we worked with him
1301
01:26:26.369 --> 01:26:27.510
and some other partners,
1302
01:26:28.265 --> 01:26:31.005
to set up this fundraiser, and alongside the fundraiser,
1303
01:26:32.665 --> 01:26:41.570
we set up this fund where the funds are getting directed to. That that's great. So we have our general we have our general fund. Our general fund is
1304
01:26:41.870 --> 01:26:42.370
mandated
1305
01:26:42.750 --> 01:26:44.690
to support open source projects.
1306
01:26:46.255 --> 01:26:48.115
People can apply for grants, whatnot,
1307
01:26:48.495 --> 01:26:55.260
tax deductible. Then we have this legal defense fund, also tax deductible, or you can donate anonymously, whichever way you prefer,
1308
01:26:55.560 --> 01:26:56.860
Bitcoin or credit cards.
1309
01:26:57.640 --> 01:27:00.860
And this mandate is much broader. Right? This mandate
1310
01:27:01.400 --> 01:27:02.460
is is is
1311
01:27:03.395 --> 01:27:04.375
legal fees,
1312
01:27:04.755 --> 01:27:06.295
defensive legal fees,
1313
01:27:07.155 --> 01:27:09.175
and free space free speech
1314
01:27:10.115 --> 01:27:10.615
cases
1315
01:27:11.230 --> 01:27:11.970
that are,
1316
01:27:12.430 --> 01:27:16.770
of open source contributors. But when we say open source contributors, we don't just mean developers.
1317
01:27:17.470 --> 01:27:20.850
So Huddl not will be a recipient of some of the funds, but, also,
1318
01:27:21.535 --> 01:27:26.595
hopefully, we raise excess of that, and, it can be used, for others as well.
1319
01:27:27.055 --> 01:27:29.315
1320
01:27:29.800 --> 01:27:31.100
people can have
1321
01:27:31.480 --> 01:27:36.775
peace of mind knowing that, you know, if there is, like, extra money that's that's,
1322
01:27:37.415 --> 01:27:44.235
donated that doesn't that's unneeded to the legal fees, they will just go to a fund for further legal defenses.
1323
01:27:45.030 --> 01:27:49.130
1324
01:27:50.790 --> 01:27:53.770
So if you believe that Bitcoin will increase in price,
1325
01:27:56.054 --> 01:28:01.514
then, you know, we're holding your funds in the hardest money possible. So so even if you donate via credit card,
1326
01:28:02.040 --> 01:28:02.940
Ledger has,
1327
01:28:04.200 --> 01:28:08.940
basically stepped up to and they they they donate the
1328
01:28:09.320 --> 01:28:12.275
the processing fee for our credit cards, and then Okcoin
1329
01:28:13.295 --> 01:28:15.315
has agreed to convert it to us,
1330
01:28:16.095 --> 01:28:22.740
convert it for us free of charge. So if you donate via credit card, it's it's immediately without fees converted into Bitcoin and held as Bitcoin.
1331
01:28:23.200 --> 01:28:26.100
1332
01:28:26.805 --> 01:28:28.585
when you have assholes
1333
01:28:29.045 --> 01:28:31.625
who have very deep pockets to sue people,
1334
01:28:32.245 --> 01:28:33.625
what they do is,
1335
01:28:34.070 --> 01:28:40.330
aside from the fact that, like, normal litigation is extremely expensive already. Right? Like, it's always a few $100,000.
1336
01:28:41.704 --> 01:28:45.565
What they would do though is they'll go crazy on discovery,
1337
01:28:47.385 --> 01:28:53.619
and and all kinds of other aspects of the litigation so that they their goal is to suck you dry
1338
01:28:53.920 --> 01:28:56.820
so that you cannot fight anymore and you settle
1339
01:28:58.925 --> 01:29:09.100
or you withdraw. Right? So so that's what, what, what that fraudster is doing is, he's trying to to suck people dry off their legal
1340
01:29:09.800 --> 01:29:10.620
fund capacity,
1341
01:29:11.720 --> 01:29:13.980
and that's terrible because that sets precedent,
1342
01:29:14.755 --> 01:29:16.695
and then next time a judge goes,
1343
01:29:17.315 --> 01:29:21.895
in the same jurisdiction or even sort of any common law jurisdiction really,
1344
01:29:22.310 --> 01:29:24.889
people cite that case saying, hey, you know,
1345
01:29:25.590 --> 01:29:29.210
there is enough people who agree that CSW is Satoshi
1346
01:29:29.745 --> 01:29:31.605
just because they withdraw their case,
1347
01:29:33.745 --> 01:29:34.625
right, and,
1348
01:29:35.185 --> 01:29:39.400
it's a terrible thing, so the more people that fight this guy, the better.
1349
01:29:42.440 --> 01:29:43.580
Boy. Anyways,
1350
01:29:44.920 --> 01:29:48.699
good for you, Matt, for putting this together. That's pretty awesome.
1351
01:29:51.185 --> 01:29:51.685
1352
01:29:52.785 --> 01:29:54.645
Huddl not surreal one, and,
1353
01:29:56.785 --> 01:29:57.345
I'm just,
1354
01:29:58.950 --> 01:30:01.770
I'm just grateful. There was a lot of people involved, and,
1355
01:30:04.470 --> 01:30:10.585
it came together pretty quickly. It was pretty cool to to watch unfold, but we're gonna have a, we're doing a 12 hour telethon.
1356
01:30:11.445 --> 01:30:12.585
So first of all, defendingbtc.com
1357
01:30:14.085 --> 01:30:16.425
if you want to donate. Every set matters.
1358
01:30:16.780 --> 01:30:19.520
The legal fees just for Halton, not alone, are significantly
1359
01:30:20.300 --> 01:30:22.320
high. They're very high. They're in the millions,
1360
01:30:23.100 --> 01:30:30.645
1361
01:30:31.105 --> 01:30:31.605
1362
01:30:32.050 --> 01:30:44.525
1363
01:30:45.304 --> 01:30:50.605
1364
01:30:50.990 --> 01:30:53.810
So consider that instead of sending it to the state,
1365
01:30:54.350 --> 01:30:57.730
send it send it to our defense fund or our general fund.
1366
01:30:58.165 --> 01:31:00.324
1367
01:31:00.724 --> 01:31:04.665
tax deductible entity here in Canada too. I think there's some reciprocation,
1368
01:31:05.125 --> 01:31:05.900
1369
01:31:06.460 --> 01:31:10.080
1370
01:31:11.179 --> 01:31:17.945
1371
01:31:18.565 --> 01:31:24.025
And then the second thing is Yes. We're gonna be doing a 12 hour telethon live from
1372
01:31:24.690 --> 01:31:25.830
Austin on Friday,
1373
01:31:26.290 --> 01:31:27.670
during Bit Black Boom.
1374
01:31:28.050 --> 01:31:32.469
So join us for that. That should be a good time. There's gonna be art is gonna be auctioned,
1375
01:31:33.114 --> 01:31:39.775
Different collectibles and stuff like that will be auctioned. We're doing a limited edition block clock courtesy of NVK and CoinKite.
1376
01:31:40.760 --> 01:31:43.580
So it'll be a fun time. Hopefully, we'll raise a bunch of money.
1377
01:31:44.440 --> 01:31:45.740
So so defendingbtc.com.
1378
01:31:48.325 --> 01:31:57.385
1379
01:31:57.989 --> 01:32:00.250
1380
01:32:00.949 --> 01:32:03.449
But just know to anyone listening That's great.
1381
01:32:04.230 --> 01:32:10.265
For my for my wedding, NVK gave me a limited edition orange block clock,
1382
01:32:11.445 --> 01:32:14.105
and the only one that's not in his hands
1383
01:32:15.860 --> 01:32:25.345
is currently in my hands, but there's gonna be another one that's gonna be available for, during this telethon. So if you're interested in that, consider joining us and bidding up that auction.
1384
01:32:26.125 --> 01:32:29.105
1385
01:32:31.330 --> 01:32:32.850
Alright, well this one is cool.
1386
01:32:33.170 --> 01:32:33.670
Replicant
1387
01:32:34.530 --> 01:32:35.030
reproducing
1388
01:32:35.650 --> 01:32:37.510
a fault injection attack on Trezor.
1389
01:32:38.105 --> 01:32:39.965
So this is this is the old,
1390
01:32:41.065 --> 01:32:42.205
Trezor 1 attack.
1391
01:32:42.585 --> 01:32:47.485
It's just it's just fun to see when other people go and reproduce this attack by themselves,
1392
01:32:48.730 --> 01:32:54.190
And I don't know if I ever heard in a podcast anybody talk about it, like, in a way that
1393
01:32:54.810 --> 01:32:57.070
they sort of explain how this is done,
1394
01:32:57.915 --> 01:32:59.614
and I figured I'd bring it up.
1395
01:33:00.235 --> 01:33:01.855
So this was Tresor 1,
1396
01:33:02.395 --> 01:33:07.295
but it was was it already when Tresor t was already around or not? I can't remember.
1397
01:33:07.740 --> 01:33:10.080
So essentially what this attack does is
1398
01:33:10.380 --> 01:33:11.200
it glitches
1399
01:33:11.980 --> 01:33:12.480
essentially
1400
01:33:13.020 --> 01:33:14.000
when you have,
1401
01:33:15.100 --> 01:33:15.760
a chip
1402
01:33:16.205 --> 01:33:19.344
that is not designed to monitor voltage
1403
01:33:20.205 --> 01:33:21.505
for security purposes,
1404
01:33:22.364 --> 01:33:23.665
what it does is,
1405
01:33:24.620 --> 01:33:25.520
say for example,
1406
01:33:26.060 --> 01:33:28.000
you have the the chip saying,
1407
01:33:28.300 --> 01:33:36.315
hey, is this been correct? Is this been correct? Is this been correct? And then the response is not correct, not correct after the user puts it in.
1408
01:33:37.255 --> 01:33:39.995
Imagine that sort of like as voltage. Right?
1409
01:33:40.700 --> 01:33:41.200
Now,
1410
01:33:41.740 --> 01:33:44.160
essentially, what this attack does is
1411
01:33:45.020 --> 01:33:46.880
when when I'm responding
1412
01:33:47.260 --> 01:33:48.160
not correct,
1413
01:33:57.000 --> 01:34:00.780
but because it's not designed for security it also doesn't hear is correct either,
1414
01:34:01.400 --> 01:34:04.380
so it just assumes is correct and then
1415
01:34:05.114 --> 01:34:12.574
it's bound, it's on. Right? So the reason why I brought this article up is because it's a great
1416
01:34:13.034 --> 01:34:14.574
explanation of the attack,
1417
01:34:16.460 --> 01:34:20.240
it's very fun for people to understand how this attack is done,
1418
01:34:20.620 --> 01:34:21.920
and understand how
1419
01:34:22.765 --> 01:34:23.505
chips work,
1420
01:34:24.125 --> 01:34:26.065
especially non secure chips work.
1421
01:34:26.365 --> 01:34:28.625
Anyways, it's it's a very good article
1422
01:34:28.925 --> 01:34:30.225
with very accessible
1423
01:34:30.740 --> 01:34:32.760
sort of, like, level of information.
1424
01:34:33.220 --> 01:34:34.600
It's not like a paper.
1425
01:34:35.380 --> 01:34:37.480
1426
01:34:39.255 --> 01:34:41.075
1427
01:34:41.455 --> 01:34:42.915
stuff, but you can do, like,
1428
01:34:43.695 --> 01:34:45.315
$20 worth of parts.
1429
01:34:46.130 --> 01:34:46.950
1430
01:34:47.490 --> 01:34:55.670
1431
01:34:56.675 --> 01:34:59.815
we're gonna be at a point where when you go through the near port,
1432
01:35:00.515 --> 01:35:08.070
the same way they can plug your iPhone or Android to a little machine that can essentially own the device, copy its memory even if it's fully encrypted.
1433
01:35:08.690 --> 01:35:09.910
It either knows
1434
01:35:11.489 --> 01:35:16.315
essentially, all phones are backdoor. Right? Doesn't matter how fancy your distro is.
1435
01:35:17.094 --> 01:35:24.270
The difference is some of them may achieve a level of encryption on the OS that's, like, acceptable or breakable later.
1436
01:35:24.889 --> 01:35:36.025
So there is this black box that's made by security farms for airports where they plug your phone in when they take it from you, and then they copy everything. They can either break it there or they can break it later.
1437
01:35:37.100 --> 01:35:39.520
I think we're gonna arrive at a point soon where,
1438
01:35:40.540 --> 01:35:44.320
state actors and bad guys will have, like, little black boxes
1439
01:35:45.365 --> 01:35:47.625
so that they don't have to have the technical,
1440
01:35:48.645 --> 01:35:55.390
know how to do any of these attacks. They just plug the device or stick the device into these machines that take the seat out essentially. Right?
1441
01:35:56.090 --> 01:35:58.590
This is what they are achieving with this thing.
1442
01:35:59.050 --> 01:36:02.830
I I think, I think we will be at that that space soon. So
1443
01:36:03.315 --> 01:36:05.574
that's why it's so important to have strong passphrases,
1444
01:36:05.875 --> 01:36:08.215
to have physically secured hardware,
1445
01:36:09.554 --> 01:36:16.060
multisig, and sort of upgrade your security because, you know, it might already be out there. It's just we won't know until we know.
1446
01:36:16.520 --> 01:36:19.660
Very, very nicely done by this, the security researcher.
1447
01:36:20.255 --> 01:36:22.275
1448
01:36:22.655 --> 01:36:28.275
Surprisingly to this point, I have not I I I tend to like to travel with empty
1449
01:36:28.655 --> 01:36:29.155
signings
1450
01:36:29.670 --> 01:36:33.210
just to see if, like, when they pay attention. Mhmm.
1451
01:36:34.389 --> 01:36:37.369
The most recent time was I was I was going to Norway
1452
01:36:38.485 --> 01:36:38.885
and,
1453
01:36:39.925 --> 01:36:41.385
I was carrying a couple,
1454
01:36:42.565 --> 01:36:43.864
empty MK fours,
1455
01:36:44.565 --> 01:36:47.145
SATS cards, tap signers, and open dimes,
1456
01:36:47.700 --> 01:36:49.320
because I wanted to show the activists
1457
01:36:49.700 --> 01:36:51.239
your complete line of products.
1458
01:36:52.420 --> 01:36:56.875
Not because I wanted to show the activists, like, all these different form factors you could use,
1459
01:36:57.195 --> 01:36:58.335
for holding Bitcoin.
1460
01:36:59.115 --> 01:37:02.095
And we're connecting through Heathrow in London,
1461
01:37:02.810 --> 01:37:10.430
and we have to go through a separate security because I was a fucking idiot and I forgot the UK wasn't in the EU. So I had to go through customs twice.
1462
01:37:11.525 --> 01:37:14.505
But that's besides the point. I went through a security there
1463
01:37:14.805 --> 01:37:17.865
and they pulled me over to the side and they opened up my bag
1464
01:37:18.280 --> 01:37:20.700
directly to where the signers were.
1465
01:37:21.160 --> 01:37:27.180
And the signers were just in this mesh compartment wide out in the open. I was like, it's finally it's finally gonna happen. And then he just grabbed
1466
01:37:27.565 --> 01:37:28.784
he grabbed my,
1467
01:37:29.324 --> 01:37:34.864
like, bathroom bag and pulled out a conditioner and told me the conditioner was too large and then sent me on.
1468
01:37:36.760 --> 01:37:43.900
Do you use conditioner, Matt? I don't know. Whatever it was. It was like conditioner or shampoo or something. I think that's the egregious part here.
1469
01:37:44.545 --> 01:37:48.805
1470
01:37:49.425 --> 01:37:54.770