Bitcoin.Review E5: Bitcoin Hardware Wallets Roundtable
NVK and I are joined by Ledger CTO, Charles Guillemet, independent security researcher, Lazy Ninja, and Sparrow maintainer, Craig Raw to discuss bitcoin wallets.
- 45:22 Support requests
- 01:03:12 Noob vs advanced user features
- 01:06:42 Most common attack vectors
- 01:11:32 Backup and seeds
- 01:12:29 Seedless multisig setups
- 01:21:49 Single sig passphrases
- 01:26:30 Security tradeoffs and considerations
- 01:31:41 Air gapped PC vs hardware wallets
- 01:40:28 SD card vs USB connection
- 01:48:26 BIPs and standards
- 01:49:16 BIP Proposal: Wallet Labels Export Format
- 01:58:146 The BIP process
- 02:03:42 TAPSGINER design and security tradeoffs
- 02:19:25 Squares new hardware wallet
- 02:40:00 Defending against government attacks
------
support dispatch: https://citadeldispatch.com/contribute
twitch: https://twitch.tv/citadeldispatch
youtube: https://www.youtube.com/channel/UCoA72saVAuQ8hYCnBO0Lymw
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://www.podpage.com/citadeldispatch
telegram: https://t.me/citadeldispatch
stream sats to the show: https://www.fountain.fm/
join the chat: https://matrix.to/#/#citadel:bitcoin.kyoto
45:22 - Support requests
01:03:12 - Noob vs advanced user features
01:06:42 - Most common attack vectors
01:11:32 - Backup and seeds
01:12:29 - Seedless multisig setups
01:21:49 - Single sig passphrases
01:26:30 - Security tradeoffs and considerations
01:31:41 - Air gapped PC vs hardware wallets
01:40:28 - SD card vs USB connection
01:48:26 - BIPs and standards
01:49:16 - BIP Proposal Wallet Labels Export Format
01:58:14 - 6 The BIP process
02:03:42 - TAPSGINER design and security tradeoffs
02:19:25 - Squares new hardware wallet
02:40:00 - Defending against government attacks support dispatch
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 4:23:44 PM
Duration: 9852.656
Channels: 1
1
00:00:03.600 --> 00:00:06.020
2
00:00:07.040 --> 00:00:10.475
We're trying something different today. This is a Bitcoin review
3
00:00:10.775 --> 00:00:11.275
conversation
4
00:00:11.655 --> 00:00:18.155
in which we talk to people working on the Bitcoin projects that we often talk about.
5
00:00:21.390 --> 00:00:24.689
So we have a great panel today to talk about wallets.
6
00:00:25.710 --> 00:00:27.890
And these guys are all
7
00:00:28.675 --> 00:00:31.015
actual industry people, not LARPers.
8
00:00:31.875 --> 00:00:33.655
I'm really looking forward to this.
9
00:00:34.355 --> 00:00:35.975
We have Craig Raw,
10
00:00:36.915 --> 00:00:37.735
who builds
11
00:00:38.500 --> 00:00:41.239
Sparrow Wallet. Craig, thanks for coming.
12
00:00:42.739 --> 00:00:44.280
13
00:00:45.140 --> 00:00:47.320
Looking forward to our discussion today.
14
00:00:48.594 --> 00:00:51.175
15
00:00:51.554 --> 00:00:52.054
a
16
00:00:52.355 --> 00:00:53.414
a security researcher
17
00:00:53.795 --> 00:00:55.094
for actual hardware,
18
00:00:56.090 --> 00:01:05.455
which is very very cool and is not somebody you normally have in this, kinds of discussions. So, thanks for coming, Lazy. Hey, Yeah. Thanks for having me, Rodolfo. Yeah. I just,
19
00:01:05.855 --> 00:01:08.995
20
00:01:09.535 --> 00:01:11.130
21
00:01:11.570 --> 00:01:14.070
Ledger. He is the CTO, but previously,
22
00:01:14.690 --> 00:01:17.270
pencil before he was a pencil pusher there,
23
00:01:18.485 --> 00:01:19.865
He was an actual,
24
00:01:20.405 --> 00:01:21.385
security researcher
25
00:01:22.005 --> 00:01:23.625
and ran the Don John.
26
00:01:24.085 --> 00:01:27.384
They broke pretty much all the wallets, which is a lot of fun.
27
00:01:28.030 --> 00:01:29.410
Thanks for coming, Charles.
28
00:01:30.350 --> 00:01:32.370
29
00:01:32.830 --> 00:01:36.515
Yes. I'm CTO at Ledger, and my background is
30
00:01:36.835 --> 00:01:37.335
cryptography
31
00:01:37.635 --> 00:01:38.455
and security.
32
00:01:39.235 --> 00:01:42.775
And, as a lazy ninja, I spent a lot of time
33
00:01:43.315 --> 00:01:43.815
studying
34
00:01:44.520 --> 00:01:52.940
hardware security in general and also wallet in in particular. But, yeah, this is my background. Thanks for having me, and I'm looking forward to discussing with
35
00:01:53.265 --> 00:01:54.405
all these great people.
36
00:01:55.665 --> 00:01:57.445
37
00:01:58.064 --> 00:01:58.564
guest,
38
00:01:59.424 --> 00:02:00.244
Matt O'Dell,
39
00:02:01.380 --> 00:02:03.160
who is an all star
40
00:02:03.780 --> 00:02:04.280
podcaster,
41
00:02:06.260 --> 00:02:07.400
privacy advocate,
42
00:02:07.700 --> 00:02:09.880
and an educator for Bitcoin,
43
00:02:10.545 --> 00:02:13.665
somebody who tends to have opinions about wallets, and,
44
00:02:14.305 --> 00:02:15.924
oftentimes, they are good opinions.
45
00:02:16.305 --> 00:02:18.004
So, thanks for coming, Matt.
46
00:02:19.110 --> 00:02:21.050
47
00:02:21.830 --> 00:02:26.330
48
00:02:27.635 --> 00:02:30.935
because the the list do take 2, 3 weeks to have meeting them.
49
00:02:31.314 --> 00:02:41.470
And I figured I'd bring the people who actually work on the projects that we often talk about on the list. So why don't we start talking maybe a bit the the UX challenges
50
00:02:41.770 --> 00:02:45.790
that like a lot of the the Bitcoin client software has.
51
00:02:47.515 --> 00:02:54.415
We often hear the memes about Bitcoin is hard to use, harder wallets are hard to use, harder wallets are not hard to use.
52
00:02:55.300 --> 00:03:00.200
It's a big messy topic out there because, you know, being your own bank is not exactly,
53
00:03:00.900 --> 00:03:02.440
the cup of tea for everyone.
54
00:03:03.105 --> 00:03:03.605
So,
55
00:03:04.385 --> 00:03:05.045
you know,
56
00:03:05.825 --> 00:03:08.645
Charles, you guys make a wallet that's
57
00:03:09.025 --> 00:03:10.165
more noob friendly.
58
00:03:12.920 --> 00:03:14.860
You know, what kind of stuff do you guys
59
00:03:15.239 --> 00:03:17.340
encounter in in UX challenges?
60
00:03:19.000 --> 00:03:20.859
61
00:03:21.284 --> 00:03:22.025
UX challenges
62
00:03:22.325 --> 00:03:25.704
is one of the biggest challenge we have, for,
63
00:03:26.245 --> 00:03:27.064
mass adoption.
64
00:03:27.364 --> 00:03:29.465
And often we, we take
65
00:03:29.810 --> 00:03:34.790
the Bitcoin revolution and we compare it to, the Internet revolution.
66
00:03:35.330 --> 00:03:37.350
And if we if you do this comparison,
67
00:03:37.975 --> 00:03:42.075
we are very early. And, in terms of adoption, you can compare,
68
00:03:42.615 --> 00:03:44.955
Bitcoin adoption to, like, 1998.
69
00:03:45.940 --> 00:03:47.000
And if you remember,
70
00:03:47.540 --> 00:03:53.000
Internet at this time, that was quite creepy. The UX was, horrible. And It was great.
71
00:03:54.694 --> 00:03:57.915
Yeah. Because you're like terminal UX. That's why.
72
00:03:58.694 --> 00:04:00.635
And, yeah, I think we are
73
00:04:00.940 --> 00:04:04.319
we have plenty of things to, to improve. And
74
00:04:04.780 --> 00:04:08.239
the mass adoption of Bitcoin and cryptocurrency
75
00:04:08.700 --> 00:04:09.360
in general,
76
00:04:09.900 --> 00:04:14.945
I'm trying to be a little bit more general even if I know we're talking about Bitcoin here.
77
00:04:16.525 --> 00:04:17.025
Today,
78
00:04:17.340 --> 00:04:19.600
it's very complex for
79
00:04:20.220 --> 00:04:22.480
someone who is not tech savvy.
80
00:04:23.020 --> 00:04:24.080
It's not usable.
81
00:04:24.540 --> 00:04:26.560
When I think about that I think about
82
00:04:27.525 --> 00:04:31.145
my mother. My mother can't use Bitcoin. She can't use,
83
00:04:31.525 --> 00:04:34.825
how how we're at it because it's simply too complex.
84
00:04:35.205 --> 00:04:36.265
And for me,
85
00:04:36.890 --> 00:04:39.070
first of all, there is a paradigm shift.
86
00:04:39.610 --> 00:04:40.910
You have to understand
87
00:04:41.290 --> 00:04:43.950
what is cryptocurrency, what is Bitcoin,
88
00:04:44.825 --> 00:04:45.885
where it lives,
89
00:04:46.505 --> 00:04:49.485
then what is self custody. This is something
90
00:04:49.865 --> 00:04:52.285
very different from, having an account,
91
00:04:52.745 --> 00:04:55.660
to to to bank. So this is something to understand.
92
00:04:56.200 --> 00:04:56.940
And second,
93
00:04:57.480 --> 00:04:58.220
for me,
94
00:04:58.840 --> 00:05:00.780
my top of mind UX challenges,
95
00:05:01.935 --> 00:05:18.600
the the the best 2 are seeds. Like, what what what are these 24 words? Like, my mother, if I if I had to explain her Bitcoin and I start, okay, you would generate a secret and then you will you will have 24 words. You will you will have to secure them.
96
00:05:18.935 --> 00:05:25.915
This is something complex to understand. And for me, this is one of the challenge we have today. Like, see how can we
97
00:05:27.090 --> 00:05:28.069
hide this complexity,
98
00:05:28.770 --> 00:05:34.630
to people. And the second thing is addresses. Like, what is just one of them, exact decimal string
99
00:05:35.125 --> 00:05:39.785
for a normal user? This is something weird. When you have exadecimal,
100
00:05:40.165 --> 00:05:43.145
usually this is because you have an error. And
101
00:05:43.490 --> 00:05:46.789
we we need to, we need to manage the those issues.
102
00:05:47.330 --> 00:05:48.310
And there was nothing,
103
00:05:48.770 --> 00:05:51.005
104
00:05:51.565 --> 00:05:52.945
attacking those problems
105
00:05:53.405 --> 00:05:54.065
at Ledger?
106
00:05:54.685 --> 00:05:55.185
107
00:05:55.485 --> 00:06:01.400
if there was an easy solution, like, we already would have implemented it or some someone else,
108
00:06:02.020 --> 00:06:04.199
we have ideas. We are researching
109
00:06:05.060 --> 00:06:05.800
for both.
110
00:06:06.324 --> 00:06:08.905
Unfortunately, this is made a matter of trade off.
111
00:06:09.685 --> 00:06:11.625
How do you trade off security
112
00:06:12.324 --> 00:06:13.065
with convenience?
113
00:06:13.659 --> 00:06:15.759
How do you trade off, convenience,
114
00:06:16.939 --> 00:06:17.419
with,
115
00:06:17.819 --> 00:06:18.319
decentralization
116
00:06:19.099 --> 00:06:20.159
and the security?
117
00:06:20.620 --> 00:06:23.520
These are these are the the kind of discussion we have.
118
00:06:24.495 --> 00:06:26.435
We we have some IDs.
119
00:06:26.815 --> 00:06:28.595
There are there was a couple of ID,
120
00:06:29.055 --> 00:06:29.455
which,
121
00:06:30.015 --> 00:06:31.795
I hope we'll implement.
122
00:06:32.680 --> 00:06:34.140
But, there was
123
00:06:34.920 --> 00:06:37.180
for now, we didn't find the perfect solution,
124
00:06:37.640 --> 00:06:40.940
with, without Drift. I I have to to admit that.
125
00:06:41.305 --> 00:06:46.525
126
00:06:47.465 --> 00:06:58.640
You know, we have the cold card crowd, right, that sort of like we try to give all the tools and everything you could possibly need in the most high security environment that we can possibly come up with. Right?
127
00:06:59.755 --> 00:07:04.655
And then with the TapCigner, we sort of try to make the trade offs where, you know, you don't have a screen,
128
00:07:05.035 --> 00:07:06.014
it's very cheap,
129
00:07:06.880 --> 00:07:10.900
and there is no seeds. It's just a blind signer, right? So, you
130
00:07:11.200 --> 00:07:16.205
know, the way, like, when you initialize it with a phone, he asked, do you want to store the encrypted
131
00:07:17.065 --> 00:07:21.805
private queue on your phone? Right? So that your mother would have a backup of that,
132
00:07:22.345 --> 00:07:26.790
but then again, right, like, I cannot recommend people putting their life savings on a top signer,
133
00:07:27.330 --> 00:07:31.110
unless they're doing it in a multisig. Right? So now if they're doing multisig
134
00:07:31.570 --> 00:07:32.870
with Nunchuck, for example,
135
00:07:33.285 --> 00:07:35.785
you know, what are the other keys
136
00:07:36.485 --> 00:07:38.005
being held with, right?
137
00:07:38.805 --> 00:07:41.225
We still like started so early on this,
138
00:07:42.520 --> 00:07:44.940
and that sort of, like, brings Craig in because
139
00:07:45.480 --> 00:07:47.180
Craig did did a very
140
00:07:47.640 --> 00:07:49.260
incredible, in my view,
141
00:07:50.040 --> 00:07:51.180
upgrade in UX,
142
00:07:52.275 --> 00:07:55.975
from a similar model to Electrum. Right? It's an SPV wallet,
143
00:07:56.995 --> 00:07:58.295
it's a desktop wallet,
144
00:07:58.910 --> 00:08:07.570
and and it's sort of like it does multi sig, it does a lot of the advanced features, but like it's a much more sane UI and UX. So Craig, like
145
00:08:08.435 --> 00:08:09.815
what brought you to
146
00:08:10.355 --> 00:08:10.855
develop,
147
00:08:11.795 --> 00:08:12.295
Sparrow
148
00:08:12.675 --> 00:08:16.455
and and, like, some of the reasons why you made those UX decisions?
149
00:08:18.310 --> 00:08:18.550
150
00:08:19.830 --> 00:08:24.185
You know, if we zoom out a little bit here, and we look at, you know, kind of
151
00:08:25.145 --> 00:08:27.565
where we have come from and where we're going
152
00:08:28.985 --> 00:08:34.100
and what people kind of view as important in the space, I think that most
153
00:08:34.560 --> 00:08:38.000
of the the the kind of opinions and the views that you see all,
154
00:08:39.920 --> 00:08:44.485
you know, have a a very natural and human flaw is that they fail to kind of take into account
155
00:08:45.185 --> 00:08:46.165
the the kind of
156
00:08:47.105 --> 00:08:50.324
span of time. They all have quite a recency bias to them.
157
00:08:52.550 --> 00:08:54.650
And, you know, for me, designing
158
00:08:55.350 --> 00:08:57.290
Sparrow, it's it's not dissimilar.
159
00:08:58.470 --> 00:09:00.170
Really, I was just trying to improve
160
00:09:00.654 --> 00:09:02.035
and take, you know,
161
00:09:02.335 --> 00:09:10.195
what I think is ultimately going to be seen as a fairly small incremental step in terms of the UX of wallets. You know, taking
162
00:09:10.500 --> 00:09:13.880
at least the UX of sort of more more advanced, more,
163
00:09:14.420 --> 00:09:14.920
capable
164
00:09:15.459 --> 00:09:16.839
wallets, perhaps more,
165
00:09:17.459 --> 00:09:19.399
more difficult for noobs, but certainly,
166
00:09:20.755 --> 00:09:25.255
you know, you're able to do more with them. You know, my intent was to
167
00:09:25.635 --> 00:09:27.015
really take what
168
00:09:27.579 --> 00:09:35.120
Electrum was offering at the the time, which I thought was a good concept and a good kind of model, this idea of a light client,
169
00:09:35.425 --> 00:09:36.885
which they really pioneered,
170
00:09:37.345 --> 00:09:39.845
and really just put it into a a different
171
00:09:40.625 --> 00:09:45.140
package with better UX, with with a a more sane kind of
172
00:09:46.660 --> 00:09:48.520
data model and UI model.
173
00:09:48.980 --> 00:09:51.000
You know, that was really my intent.
174
00:09:52.345 --> 00:10:00.445
Where we are going next, it's hard to say. Right? If I knew the answer to that, I would be trying to build it perhaps, but, you know, it's really hard hard to say.
175
00:10:01.060 --> 00:10:06.040
And that's, I guess, one of the great things we all get to experience on this journey is the ability to
176
00:10:06.500 --> 00:10:08.020
see whatever's next,
177
00:10:08.340 --> 00:10:09.785
and kinda be part of that.
178
00:10:10.105 --> 00:10:16.764
But, yeah, I mean, that that's really what I was trying to do. I kind of built Sparo for myself. It's still really the case.
179
00:10:17.144 --> 00:10:22.190
Whenever I come to a decision point and I don't know what to do, I kind of have to go back and say, well,
180
00:10:22.570 --> 00:10:27.310
what would I like to use use here? And that kind of defines it for me.
181
00:10:28.565 --> 00:10:33.705
I have the advantage that I didn't set this thing up to be a business like you guys.
182
00:10:34.245 --> 00:10:37.785
183
00:10:38.449 --> 00:10:43.029
We we did it because there was no alternative that we were, like, sorta happy with.
184
00:10:44.850 --> 00:10:50.615
185
00:10:51.395 --> 00:10:57.700
And, you know, I think that that's that's always a challenge. Right? That's the that that kind of trying to maintain the balance of,
186
00:10:58.180 --> 00:11:04.680
you know, who are you building this thing thing for? Because if you're building it for somebody that isn't you, that immediately creates
187
00:11:05.345 --> 00:11:10.725
a bit more of a challenge. Right? Now you're trying to imagine yourself as someone else, and what would this person need?
188
00:11:11.185 --> 00:11:13.610
189
00:11:14.470 --> 00:11:15.290
one is,
190
00:11:15.750 --> 00:11:17.610
like, do you see yourself
191
00:11:17.990 --> 00:11:19.290
porting Spiro
192
00:11:20.070 --> 00:11:21.050
to the phone
193
00:11:21.735 --> 00:11:27.834
so that, you know, like, you wouldn't, of course, be all the functionality and everything that's in there, but,
194
00:11:28.615 --> 00:11:29.115
I
195
00:11:29.495 --> 00:11:30.714
I failed to find
196
00:11:31.540 --> 00:11:32.199
a reasonable
197
00:11:32.579 --> 00:11:33.480
phone wallet
198
00:11:34.019 --> 00:11:40.360
that that is not like, you know, like, so Moon is fantastic for, you know, a total noob that has $50.
199
00:11:40.740 --> 00:11:44.825
Right? But it would be nice to have a phone wallet where you can live a couple
200
00:11:45.205 --> 00:11:47.705
$1,000 as your sort of like checking account. Right?
201
00:11:48.165 --> 00:11:51.920
And and and go about your life without having to pull out the computer.
202
00:11:52.460 --> 00:11:58.080
Because funny enough, if the opponent is not a state actor, the phone is fairly secure.
203
00:12:00.645 --> 00:12:01.145
So
204
00:12:02.005 --> 00:12:07.340
I, you know, anyways, I was just curious if you intend to port that that wallet at some point,
205
00:12:07.800 --> 00:12:09.180
to the to the phone.
206
00:12:10.520 --> 00:12:33.160
207
00:12:33.464 --> 00:12:35.644
That that said, I I completely recognize,
208
00:12:36.665 --> 00:12:37.884
the need for better,
209
00:12:38.584 --> 00:12:55.475
better access to, you know, phone wallet apps, and I hope we get more of them. You know, that's that's absolutely some something. In fact, I actually feel, you know, somewhat guilty at times that I live here in Africa where most people don't own desktop computers and here I have built a desktop app. So,
210
00:12:55.875 --> 00:12:57.894
there is a degree to which I recognize
211
00:12:58.600 --> 00:13:00.940
the irony of that situation. But,
212
00:13:01.640 --> 00:13:02.540
in any case,
213
00:13:03.560 --> 00:13:06.300
to for me to stretch Sparo to a phone,
214
00:13:06.855 --> 00:13:10.315
is I think just a complete reimagining of the UI.
215
00:13:10.694 --> 00:13:15.274
You know, why did I choose a desktop in the first place was really because, as I said previously,
216
00:13:15.790 --> 00:13:25.505
I wanted to build it for me. And if I'm gonna manage my funds, I'm gonna use the most capable device that I have, which is my PC. So that's what led me to make that call.
217
00:13:25.985 --> 00:13:37.660
218
00:13:37.960 --> 00:13:38.780
in Miami,
219
00:13:39.945 --> 00:13:41.725
when I also met your lovely lady.
220
00:13:42.425 --> 00:13:50.550
I said to you, how can, you know, how can I help? Do you do you need more contributors? Do you need more eyes on the code? And usually in an in open source land,
221
00:13:51.970 --> 00:13:53.990
you know, projects are always in demand,
222
00:13:54.290 --> 00:13:58.405
for more contributors, They're open source project. And you said something interesting to me.
223
00:13:58.785 --> 00:13:59.525
You said
224
00:14:00.145 --> 00:14:04.245
that in a lot of ways, when you have all these different moving parts,
225
00:14:05.110 --> 00:14:11.850
bringing in additional contributors makes your life more difficult, and you like being in total control. You wanna touch on that a little bit?
226
00:14:12.775 --> 00:14:13.915
227
00:14:14.535 --> 00:14:15.275
I completely
228
00:14:15.815 --> 00:14:20.795
support, and, I did say that. That that that is very, very much the case. You know,
229
00:14:21.710 --> 00:14:32.024
I'm experiencing right now, and I imagine we'll get to it late later, but I'm experiencing right now the joy of of kind of trying to find agreement with with others via the BIP process.
230
00:14:32.805 --> 00:14:38.420
And it's really, for me anyway, not a lot of fun. It's not something I particularly enjoy doing, and I didn't start
231
00:14:38.800 --> 00:14:39.300
Sparrow,
232
00:14:40.000 --> 00:14:46.875
as I said previously, at commercial intent. So I'm I started it because I enjoy what I do. I enjoy the creative process,
233
00:14:47.815 --> 00:14:55.190
and I primarily enjoy the creative process, or at least my creative pros press process is one that I do on my own.
234
00:14:56.150 --> 00:15:00.890
You know, I like to imagine things. I like to design sign things. And that's not to say that I haven't
235
00:15:01.270 --> 00:15:03.530
enjoyed working in teams before, but,
236
00:15:03.990 --> 00:15:04.650
you know,
237
00:15:05.515 --> 00:15:08.075
if you look at the great, you know, the the
238
00:15:08.395 --> 00:15:13.055
if if you're sort of inspired by great works of art or whatever, usually those are
239
00:15:13.420 --> 00:15:15.279
created by solo individuals.
240
00:15:15.740 --> 00:15:18.480
241
00:15:18.860 --> 00:15:22.755
you know, in our sort of open source saga with CodeCard,
242
00:15:23.375 --> 00:15:26.755
what a lot of people fail to to see is that,
243
00:15:27.535 --> 00:15:30.515
you know, it was open source but it was single source.
244
00:15:32.579 --> 00:15:34.839
It was mostly Peter's design,
245
00:15:35.540 --> 00:15:37.240
for the software and
246
00:15:38.085 --> 00:15:40.505
if anything, every time somebody makes a contribution,
247
00:15:41.285 --> 00:15:42.105
the effort
248
00:15:42.565 --> 00:15:46.265
to review the contribution because this is security software, right?
249
00:15:46.800 --> 00:15:51.060
And oftentimes just have to politely disagree that we don't want that contribution
250
00:15:52.000 --> 00:15:58.884
is an immense time sink and that's not to say that it's a nice, I mean like we have received contributions that were amazing.
251
00:16:00.714 --> 00:16:01.214
HODAwave
252
00:16:01.690 --> 00:16:02.670
I think did
253
00:16:03.450 --> 00:16:09.710
some con I can't remember right now, but he had some interesting contributions that were accepted. It was the address explorer. Right?
254
00:16:10.365 --> 00:16:12.785
No. He he did a the multisig explorer
255
00:16:13.165 --> 00:16:17.185
which we had to turn down because there was no secure way of doing that.
256
00:16:17.725 --> 00:16:19.265
But there were a few other contributions.
257
00:16:21.790 --> 00:16:29.410
And and a lot of people sort of like fail to see the toll that it takes on open source to receive these contributions and sort of disagree
258
00:16:29.790 --> 00:16:32.355
and say kind of like very politely fork off.
259
00:16:34.015 --> 00:16:34.515
So,
260
00:16:35.375 --> 00:16:38.415
I find, and I've been following your, your,
261
00:16:39.055 --> 00:16:39.770
CSV request
262
00:16:50.715 --> 00:16:52.735
And and I find that there is sort
263
00:16:53.115 --> 00:17:02.800
of like 2 kinds of open source people. There is the people who are sort of like working on base layers, OSes, the very the larger picture that everybody builds on top,
264
00:17:03.339 --> 00:17:06.800
and those folks tend to be more academic like workers
265
00:17:07.595 --> 00:17:12.255
where they are very good at sort of like being polite and doing the back and forth
266
00:17:13.434 --> 00:17:18.510
and working through that and they also have the patience to deal with outside ideas and outside contributions
267
00:17:19.290 --> 00:17:21.550
while the people who build client software
268
00:17:23.850 --> 00:17:27.465
that runs on top of this sort of like base layers
269
00:17:27.765 --> 00:17:28.665
or assets,
270
00:17:29.365 --> 00:17:30.905
they tend to be more opinionated
271
00:17:31.365 --> 00:17:32.345
and they tend
272
00:17:33.100 --> 00:17:35.120
to want to build their vision,
273
00:17:35.900 --> 00:17:40.880
and that's sort of like the goal, right? I hope that people like my vision but it's still my vision.
274
00:17:42.455 --> 00:17:45.355
And and I I find the the sort of like the the dynamic
275
00:17:45.735 --> 00:17:51.920
between these two, the tension between these two to be a very interesting place where a lot of cool stuff gets built. But,
276
00:17:52.560 --> 00:17:53.060
yeah.
277
00:17:54.480 --> 00:17:54.980
The
278
00:17:55.280 --> 00:17:59.780
the other question I had for you was the maintainability that Matt did bring up,
279
00:18:00.855 --> 00:18:06.315
which is, you know, there is a point in which, especially with security software,
280
00:18:06.695 --> 00:18:10.210
where you have to have enough either time, budget, or something
281
00:18:10.910 --> 00:18:15.410
to get appropriate amount of reviews, especially as the project grows, it becomes more complex.
282
00:18:16.195 --> 00:18:22.934
So, I mean, I don't wanna put you on the spot and you feel free to sort of like move on from this if you don't want to, but I'm just very curious,
283
00:18:23.635 --> 00:18:24.615
as to like,
284
00:18:25.220 --> 00:18:28.520
do you have plans, ideas on on sort of, like,
285
00:18:29.140 --> 00:18:31.400
you know, further monetizing it,
286
00:18:31.860 --> 00:18:33.240
in in a way
287
00:18:33.595 --> 00:18:39.695
to to keep the project healthily, sort of, like, maintain and and get more help under your terms?
288
00:18:41.010 --> 00:18:43.029
289
00:18:44.370 --> 00:18:47.010
Sparrow is is, you know, not exclusively
290
00:18:47.490 --> 00:18:52.335
I'm not gonna rule anything out, but it's kind of an attempt to see what one man can do.
291
00:18:53.434 --> 00:18:57.900
And if it doesn't work, then fine. It doesn't work, but so far, it seems seems to work.
292
00:18:58.940 --> 00:19:04.640
I don't see the pace of development in terms of new features happening at anything like the rate
293
00:19:04.940 --> 00:19:15.285
in which it has happened. And I sort of, you know, was rolling out features really intensely at the start because I realized that my user base is small and the the cost of
294
00:19:15.770 --> 00:19:21.630
making a mistake is less. That has now changed. I don't view it that way anymore. I think Sparrow is probably
295
00:19:22.010 --> 00:19:24.030
managing 1,000,000,000 of dollars.
296
00:19:24.695 --> 00:19:29.755
I don't say that as a any kind of credit. It's quite a burden, but it is probably true.
297
00:19:30.455 --> 00:19:34.630
And as a result, I have to be really careful with anything that I do. So,
298
00:19:35.010 --> 00:19:43.515
you know, it's it's it's really time now to, you know, to kind of review code, to go over things, to check algorithms, to
299
00:19:43.975 --> 00:19:51.610
and and that's the one of the reasons that you see, you know, a much slower release cycle now is because I'm really, you know, taking the time
300
00:19:51.910 --> 00:19:54.490
to really just go back over over over things.
301
00:19:54.790 --> 00:19:56.970
I try to stay very involved in
302
00:19:57.575 --> 00:19:58.635
the user support
303
00:19:58.935 --> 00:20:10.790
because that's where you get most of your feed feed feedback and staying close to your users, I found, is the best way to really understand what's going on and to see see things coming down the pipe. So,
304
00:20:12.050 --> 00:20:25.980
yeah, I mean, you know, that's not to say that I I'm not I'm I'm certainly keen to find good people in the space who can review things that I'm maybe less qualified to do, you know, cryptographic algorithms and and the and the like.
305
00:20:26.920 --> 00:20:28.140
But I don't see that
306
00:20:28.679 --> 00:20:33.674
as something that's gonna cost a huge amount because, you know, most of the time, the algorithms,
307
00:20:34.455 --> 00:20:38.315
using the libraries that I use are very well reviewed anyway.
308
00:20:38.850 --> 00:20:39.350
So,
309
00:20:39.730 --> 00:20:47.590
yeah, I'm just gonna see how how far I can go and try and think about it in a in a sane way and approach it in that way.
310
00:20:47.915 --> 00:20:49.935
311
00:20:50.955 --> 00:20:52.575
on the monetization aspect,
312
00:20:53.355 --> 00:20:54.575
I mean, I think Sparrow
313
00:20:54.955 --> 00:21:05.020
has already found a a pretty stable monetization method for a one man shop because he is collecting coin joint fees right now. So as far as open source wallets go, that seems to be,
314
00:21:05.995 --> 00:21:07.294
one of the most obvious,
315
00:21:07.755 --> 00:21:08.815
sustain sustainability
316
00:21:09.275 --> 00:21:09.775
models.
317
00:21:10.395 --> 00:21:12.975
318
00:21:13.400 --> 00:21:17.260
319
00:21:17.640 --> 00:21:18.540
you know, so
320
00:21:19.080 --> 00:21:26.255
it's hard to design UX when you don't know exactly how people are gonna be using things in the long term. Because right now in Bitcoin,
321
00:21:26.715 --> 00:21:33.730
we're sort of using Bitcoin in a different way than I think it will maybe ultimately be used. Like, I'll just sort of take myself, like,
322
00:21:34.350 --> 00:21:40.050
people would look at me as, like, maybe a wallet power user or just a Bitcoin power user because I've been around a long time.
323
00:21:40.735 --> 00:21:41.235
And
324
00:21:42.255 --> 00:21:43.955
I I so in reality,
325
00:21:44.575 --> 00:21:46.275
I probably only use
326
00:21:46.655 --> 00:21:49.875
a hardware wallet to sign transactions and really use it
327
00:21:50.460 --> 00:21:51.760
once or twice a year.
328
00:21:52.060 --> 00:21:59.520
So when I get that hardware wallet out again, it's actually been a long time, and I sort of need to go slow and be careful with stuff
329
00:22:00.195 --> 00:22:06.135
just because it's been a long time because I'm just sort of in HODL mode. Like, I, you know, I just accumulate Bitcoin. I don't I'm never
330
00:22:06.674 --> 00:22:10.600
spending it, so there's just very little I have to do with my hardware wallet.
331
00:22:11.220 --> 00:22:13.080
And it just sort of
332
00:22:13.460 --> 00:22:20.425
if I'm sort of somewhat a noob sometimes, I can't even imagine how newbie real newbie people are. Right? So it sort of creates this
333
00:22:21.285 --> 00:22:21.785
falsely
334
00:22:22.325 --> 00:22:26.745
reinforcing thing that everybody's just really dumb and doesn't know how to do stuff on hardware wallets. I think
335
00:22:27.590 --> 00:22:33.610
maybe in a future where Bitcoin is used differently I guess your model was sort of the tap signer and things like that somewhat
336
00:22:33.990 --> 00:22:35.450
address address that.
337
00:22:35.915 --> 00:22:40.015
You know, maybe people will be using hardware wallets much more often, and
338
00:22:40.395 --> 00:22:46.550
it will be easier to understand you and they'll be more capable of understanding complex UX. So maybe we may be oversimplifying
339
00:22:46.930 --> 00:22:52.390
340
00:22:53.045 --> 00:22:58.184
you know, we all know all the phones are owned. Right? Like, they they're fully backdoor devices,
341
00:22:59.445 --> 00:23:00.985
by state actors. Right?
342
00:23:02.140 --> 00:23:02.640
Now,
343
00:23:03.020 --> 00:23:10.640
they're fairly walled garden and nice in regards to other attack surfaces. Right? Like, say, your average bad guy. Right?
344
00:23:11.145 --> 00:23:11.645
Now,
345
00:23:12.345 --> 00:23:14.285
what's interesting to me is,
346
00:23:16.905 --> 00:23:17.965
as exploits
347
00:23:19.490 --> 00:23:22.070
sort of start to become known on phones,
348
00:23:22.690 --> 00:23:29.935
is that will inform us which direction we have to go. Right? Can we still have private keys on phones or do we need TapCigner
349
00:23:30.315 --> 00:23:32.715
or some other solution like the Ledger,
350
00:23:33.355 --> 00:23:34.495
with the with the Bluetooth?
351
00:23:35.755 --> 00:23:46.875
Like, do we need to offload those keys from the phone or we don't? Or or where is the happy medium? Right? Is it multisig? Is it multisig with a server with a server? Right? The Nunchuck guys are releasing,
352
00:23:48.315 --> 00:23:51.535
hopefully, like, a service soon that that does some of that. So,
353
00:23:52.475 --> 00:23:57.330
I I don't think there's gonna be, 1, an answer that sort of fits everybody,
354
00:23:57.870 --> 00:23:58.770
and 2,
355
00:23:59.550 --> 00:24:06.305
I don't think we we are capable now of of just knowing the the environment, the security environment we're
356
00:24:06.685 --> 00:24:08.625
in in 5 years from now. Right? Because
357
00:24:09.485 --> 00:24:10.625
you know imagine
358
00:24:10.925 --> 00:24:11.665
you are
359
00:24:12.260 --> 00:24:13.800
you know, a quality dictator.
360
00:24:14.100 --> 00:24:16.840
Right? Like, very nice guy, but still a dictator,
361
00:24:17.220 --> 00:24:23.065
you know, all the phones are sharing their their memory with the carrier that's state owned.
362
00:24:23.685 --> 00:24:29.145
And then, you know, the the dictator is in a in a pickle because he ran out of money, he bought too much lobster,
363
00:24:29.900 --> 00:24:30.400
and
364
00:24:30.860 --> 00:24:33.680
then, you know, like he sees that there's this massive,
365
00:24:34.700 --> 00:24:43.425
install base in his country where everybody's using a phone wallet, the private keys in their phone, and then he goes like I need money, I'm gonna just sweep everybody's phone.
366
00:24:43.805 --> 00:24:48.385
Right? Like we are not far from that technically speaking, that is already possible.
367
00:24:49.860 --> 00:24:53.799
If the wallets have x y's. Go ahead. I mean, is the Chivo model?
368
00:24:55.380 --> 00:24:58.745
Yeah. I mean, I don't know. Right? But the Chivo is worse than that. Right? Because
369
00:24:59.625 --> 00:25:01.485
the Chivo is custodial. So
370
00:25:02.985 --> 00:25:05.565
people are already accepting that they are owned. So
371
00:25:05.920 --> 00:25:09.620
go ahead, Charles. Sorry. We cut you off. Yeah. In in your analysis,
372
00:25:11.280 --> 00:25:14.080
373
00:25:15.275 --> 00:25:20.255
for stealing your keys in your phone is a state actor, I would tend to disagree.
374
00:25:21.434 --> 00:25:21.934
Like,
375
00:25:23.910 --> 00:25:27.450
the secure security vulnerability market, because there is a market,
376
00:25:28.230 --> 00:25:28.730
is,
377
00:25:29.110 --> 00:25:31.530
mostly there there are plenty of actors.
378
00:25:31.830 --> 00:25:32.490
You have,
379
00:25:33.015 --> 00:25:36.155
on one side, security researcher who find vulnerabilities.
380
00:25:36.455 --> 00:25:37.755
In this researcher,
381
00:25:38.215 --> 00:25:43.180
some, some of them are more, like, responsible disclosure like like what WhiteHat.
382
00:25:43.800 --> 00:25:49.980
Some other are more, like, with BlackHat. They are using the ability for for them, directly,
383
00:25:50.674 --> 00:25:56.934
trying to monetize them, in a way or another. And in between, you have a gray hat, and these these people are,
384
00:25:57.554 --> 00:25:58.534
mostly selling
385
00:25:59.000 --> 00:26:12.135
their vulnerability to the one who who gives them the most money. And people who are buying this vulnerability, of course, you have state actors, but you also have a criminal organization. Right? This is, this is something widely
386
00:26:12.675 --> 00:26:14.215
known. You have, brokers.
387
00:26:14.515 --> 00:26:16.295
Like, if you go to xerojam.com,
388
00:26:17.390 --> 00:26:22.450
this is a broker for Vulnerability, and they buy Vulnerability and they sell Vulnerability. And,
389
00:26:23.550 --> 00:26:26.855
this market has been huge. Like, 25 years ago,
390
00:26:27.575 --> 00:26:29.355
when I started in in this area,
391
00:26:29.815 --> 00:26:31.995
when when you found when you found the critical
392
00:26:32.295 --> 00:26:32.795
vulnerability,
393
00:26:33.179 --> 00:26:37.360
if you've got 100 bugs bugs, you you were very happy. Now,
394
00:26:37.660 --> 00:26:38.480
if you find,
395
00:26:38.780 --> 00:26:40.799
like, a zero click persistent
396
00:26:41.179 --> 00:26:42.240
vulnerability on,
397
00:26:42.795 --> 00:26:43.855
on Android,
398
00:26:44.155 --> 00:26:48.015
it's 2,000,000. This is this is the price for, this kind of.
399
00:26:48.475 --> 00:26:52.810
You have state actors buying those, but also criminal organization.
400
00:26:53.590 --> 00:26:54.330
And today,
401
00:26:55.430 --> 00:26:56.490
this kind of vulnerability
402
00:26:56.790 --> 00:26:59.485
is mostly exploited to spy on
403
00:26:59.865 --> 00:27:01.485
people or, like, doing,
404
00:27:02.825 --> 00:27:06.284
like, doing intelligence and this kind of thing. But tomorrow,
405
00:27:06.840 --> 00:27:09.260
if the opportunity cost of, like,
406
00:27:09.560 --> 00:27:10.060
draining
407
00:27:10.520 --> 00:27:13.740
all the software wallet on, a given device
408
00:27:14.265 --> 00:27:16.685
is higher than the price of the vulnerability,
409
00:27:17.305 --> 00:27:19.005
and this will come very fast,
410
00:27:19.705 --> 00:27:20.445
these vulnerabilities
411
00:27:21.545 --> 00:27:23.309
will be bought for draining,
412
00:27:24.090 --> 00:27:25.070
software wallet.
413
00:27:25.529 --> 00:27:30.590
And it's even worse than that because when I when I say, like, 2,000,000 for
414
00:27:31.505 --> 00:27:32.005
vulnerability
415
00:27:32.305 --> 00:27:38.325
allowing me to drain your software wallet without you doing anything, this is the this is the worst
416
00:27:39.150 --> 00:27:39.890
worst situation.
417
00:27:40.190 --> 00:27:42.130
But this is for an up to date
418
00:27:43.470 --> 00:27:45.490
phone. Like, if if you use,
419
00:27:46.030 --> 00:27:51.955
an old phone, like, this will cost nothing. They are known already. They have been patched, and, unfortunately,
420
00:27:52.495 --> 00:27:53.235
your vendor
421
00:27:54.015 --> 00:27:54.675
do not
422
00:27:55.215 --> 00:27:58.595
provide upgrades. So your your phone is vulnerable or
423
00:27:59.040 --> 00:28:08.775
you didn't click on upgrade my my phone. And in this kind of situation, you're not protected at all. You know, so people know, like, when you are on an airport,
424
00:28:09.635 --> 00:28:11.095
425
00:28:11.475 --> 00:28:15.815
it doesn't matter how latest the model is, they'll stick it in a little machine
426
00:28:16.400 --> 00:28:25.940
that will, like, take all the data out of the phone even if they can't break it right now. They'll wait until they have a vulnerability to break it later. It's it's so hopeless.
427
00:28:26.565 --> 00:28:29.465
428
00:28:29.845 --> 00:28:38.540
Yes. And they they have this, like, some kind of mallet and, a bunch of wires. You plug in your your phone phone and then they they can extract everything.
429
00:28:39.000 --> 00:28:42.059
But you also have another vendor, which is called NSO.
430
00:28:42.440 --> 00:28:45.260
And NSO is the company which develops,
431
00:28:45.945 --> 00:28:49.565
Pegasus Pegasus Software. And this software is quite simple.
432
00:28:49.945 --> 00:28:59.960
I put your phone number on the software. I click on hack and I am root on your phone. And there's nothing you can do. You you you don't even have to do anything.
433
00:29:00.419 --> 00:29:01.880
This is Artrix. And
434
00:29:02.275 --> 00:29:05.875
to build this software, what they what they did was to,
435
00:29:06.355 --> 00:29:16.220
search for VINR which is all by them. This is Yeah. This is the this is the market. But for now, these VINROGs are not used for draining words,
436
00:29:16.600 --> 00:29:26.455
437
00:29:26.995 --> 00:29:27.655
a coin.
438
00:29:28.140 --> 00:29:29.520
And now you have,
439
00:29:29.900 --> 00:29:34.640
you know, maybe not in a major Western country, but say like a developing country,
440
00:29:34.995 --> 00:29:41.815
like Brazil, Russia, India, China, something like that, and they're experiencing a high volume of capital flight,
441
00:29:42.410 --> 00:29:42.910
right
442
00:29:43.610 --> 00:29:45.390
maybe they start draining people's wallets
443
00:29:45.930 --> 00:29:49.965
you know it's it's a lot cheaper and easier than go and hit somebody with a club in the head
444
00:29:50.365 --> 00:29:59.664
445
00:30:00.160 --> 00:30:04.100
And, this threat of Pegasus is is very real. When we were in Oslo,
446
00:30:06.000 --> 00:30:09.620
there was a partner there that was was doing Pegasus checking.
447
00:30:10.054 --> 00:30:18.554
And me being paranoid, I would never plug my phone into the Pegasus checker, but, apparently, there was 7 7 different attendees had Pegasus on their phone.
448
00:30:19.450 --> 00:30:21.550
449
00:30:21.850 --> 00:30:26.670
And and remember, phones were not designed to have a a a a supply chain
450
00:30:28.215 --> 00:30:29.435
security between
451
00:30:29.975 --> 00:30:32.315
the manufacturer, the carrier, and yourself.
452
00:30:32.855 --> 00:30:39.240
So one is, especially with Android. Right? With Android, you're buying something that the carrier already rooted.
453
00:30:40.180 --> 00:30:47.525
Right? Like, it comes pre rooted. If you buy your Android directly, you know, maybe a better chance, but still somebody can intercept in the middle of the way.
454
00:30:49.205 --> 00:30:54.585
IPhones, it's my opinion that you are a little bit more secure against the, you know, the average scumbag,
455
00:30:55.179 --> 00:30:58.559
but, but, you know, you're still sort of at the mercy of state actors,
456
00:30:59.179 --> 00:31:01.440
or old exploits or old hardware.
457
00:31:02.195 --> 00:31:02.695
But
458
00:31:03.075 --> 00:31:09.335
it is pretty bleak and and that's why I highly discourage people doing large transactions on phones.
459
00:31:10.190 --> 00:31:15.170
It's it's not not a good idea. If anything, you could just be losing your privacy. Right? Maybe they're just capturing,
460
00:31:16.670 --> 00:31:19.615
you know, transactions on you just so they can attack you later.
461
00:31:20.495 --> 00:31:28.755
462
00:31:29.520 --> 00:31:30.020
iPhone,
463
00:31:30.640 --> 00:31:36.500
iPhone Xplots are a little bit cheaper than Android Xplots, but just a detail.
464
00:31:37.065 --> 00:31:38.445
465
00:31:39.144 --> 00:31:42.524
I I know that the volume of exploits is different there too.
466
00:31:42.825 --> 00:31:46.524
My understanding of the reasoning, correct me if I'm wrong, Charles, is because,
467
00:31:47.130 --> 00:31:49.310
468
00:31:50.570 --> 00:31:51.070
homogenic
469
00:31:51.450 --> 00:32:00.635
ecosystem, like all the phones are pretty much standardized because they still get updates. But with Android, it's very fragmented. So if you get an if you get an iOS vulnerability,
470
00:32:01.174 --> 00:32:04.330
you pretty much get access to to all the iPhones.
471
00:32:05.030 --> 00:32:07.530
But with Android, there's a bunch of different ones.
472
00:32:07.830 --> 00:32:11.725
473
00:32:12.125 --> 00:32:17.184
474
00:32:17.645 --> 00:32:22.730
and it's not really a matter of demand, but of offer. Like, when when some researcher,
475
00:32:24.070 --> 00:32:29.610
start to find many vulnerabilities, the price of vulnerabilities drop. This is this is more of this mechanism.
476
00:32:31.424 --> 00:32:39.044
477
00:32:39.790 --> 00:32:45.170
So you just have more suckers to steal stuff from if you buy an exploit for Android.
478
00:32:45.790 --> 00:32:46.290
Okay.
479
00:32:46.725 --> 00:32:51.225
480
00:32:52.164 --> 00:32:53.065
I mean, Charles,
481
00:32:53.924 --> 00:32:56.940
obviously, Ledger supports, you know, all these alt coins
482
00:32:57.240 --> 00:33:04.700
and NFTs, and there's all these other complexities that you guys have to deal with because of that. You know, you have to think about staking. You have to think about NFTs.
483
00:33:05.095 --> 00:33:05.835
How does
484
00:33:06.215 --> 00:33:11.915
that how does that factor into your UX equation? Has there been any thought to having a Bitcoin only product?
485
00:33:13.070 --> 00:33:16.690
486
00:33:17.390 --> 00:33:20.130
So in terms of security, in order to
487
00:33:21.085 --> 00:33:23.345
segregate your asset and mitigate
488
00:33:23.885 --> 00:33:30.530
the the risk, what what we did is the is the following. We have developed an operating system, which is quite simple,
489
00:33:30.910 --> 00:33:32.210
and this is on purpose.
490
00:33:32.590 --> 00:33:37.650
And this operating system is mostly a big cryptographic toolbox, and you have
491
00:33:38.115 --> 00:33:43.095
different API where you can, ask for a request for a hash, a signature,
492
00:33:43.554 --> 00:33:44.775
encryption, whatever.
493
00:33:45.395 --> 00:33:45.895
And
494
00:33:46.399 --> 00:33:49.779
on top of this operating system, you can load application
495
00:33:50.159 --> 00:33:52.419
and this application are isolated
496
00:33:53.679 --> 00:33:54.820
from one to another.
497
00:33:55.255 --> 00:33:57.675
And to do so, we are leveraging
498
00:33:58.055 --> 00:33:58.555
the,
499
00:33:59.735 --> 00:34:04.235
hardware feature, which is which is MPU. We are we are using a hardware feature
500
00:34:04.570 --> 00:34:08.250
so that even if your application is trying to,
501
00:34:08.570 --> 00:34:09.630
access to,
502
00:34:10.490 --> 00:34:12.990
to some data which is not, in its
503
00:34:13.355 --> 00:34:14.095
in its
504
00:34:14.795 --> 00:34:15.295
world,
505
00:34:15.994 --> 00:34:17.214
you will have a hardware
506
00:34:17.515 --> 00:34:22.335
failure. This is this is what what we are using. So we are using the MPU hardware
507
00:34:23.080 --> 00:34:23.560
to,
508
00:34:24.040 --> 00:34:24.540
isolate
509
00:34:25.000 --> 00:34:25.500
application
510
00:34:25.800 --> 00:34:26.860
from one to another.
511
00:34:27.560 --> 00:34:28.860
This is how we
512
00:34:29.320 --> 00:34:34.585
avoid that even if there is an, even if there is a vulnerability in
513
00:34:35.045 --> 00:34:37.785
your, Ethereum app, your Bitcoin
514
00:34:38.085 --> 00:34:39.780
keys, if everything is
515
00:34:40.340 --> 00:34:41.800
is is well done. This
516
00:34:42.260 --> 00:34:50.375
is a yeah. There was always a question about that, of course. If everything is well done, if there is a vulnerability in the Ethereum app, it cannot
517
00:34:50.675 --> 00:34:55.734
be leveraged to access to your Bitcoin keys. So this is how we we mitigate that.
518
00:34:56.355 --> 00:34:58.615
If you want to tell me that more complexity
519
00:34:59.075 --> 00:35:08.120
complexity is the enemy of security, I really agree with that. There was no no debate, but this is a trade off for you. I can't even imagine the amount of work that it is to review
520
00:35:08.775 --> 00:35:09.515
521
00:35:09.815 --> 00:35:10.714
like, capacity,
522
00:35:12.135 --> 00:35:15.835
for all the Shecoins. It must be, like, an absolute,
523
00:35:16.135 --> 00:35:16.635
like,
524
00:35:17.450 --> 00:35:25.630
hell. Like, you know, it's a good business. Right? I mean, people want a single solution that supports all the stuff. Right? Yeah. But like just
525
00:35:26.325 --> 00:35:37.190
speaking as as like somebody who builds software is is is just I I can't even imagine what it is in terms of like just the amount of people and teams and stuff you need to just support the stuff because,
526
00:35:37.650 --> 00:35:52.400
527
00:35:53.359 --> 00:35:56.900
because there was no absolutes in security. And the more eyes you have,
528
00:35:57.200 --> 00:36:03.215
the better it is. Also, we we have improved our SDK. We are providing more tools,
529
00:36:03.835 --> 00:36:11.695
some static analysis tools and so on. So, yeah, this is this is not absolute, but this is, we we are putting a lot of effort
530
00:36:12.030 --> 00:36:18.210
to improve the security of everything we do, especially when it comes to to signing. You know, it's funny.
531
00:36:19.005 --> 00:36:20.785
532
00:36:22.685 --> 00:36:28.830
For free. We for free. We send, we send code cards to Don John, for them to try to break.
533
00:36:29.710 --> 00:36:31.250
So, thank you very much,
534
00:36:31.790 --> 00:36:35.170
for that work. I I seriously, like, I I mean that for real.
535
00:36:35.630 --> 00:36:37.010
I I think it's fantastic
536
00:36:37.455 --> 00:36:39.955
that you guys are willing to spend so much money,
537
00:36:40.495 --> 00:36:45.635
trying to break you know, I know you get the PR from it and all that stuff too, which is great for your brand, but,
538
00:36:46.690 --> 00:36:54.550
it's just nice that there is enough market and enough economies of scale now that there can be an actor like you that sort of goes out of your way
539
00:36:54.954 --> 00:36:56.255
to try to break
540
00:36:56.875 --> 00:36:58.415
other devices. It's
541
00:36:59.035 --> 00:37:01.375
surprising. I mean like we gained a lot in security
542
00:37:02.050 --> 00:37:03.270
from you guys breaking,
543
00:37:03.650 --> 00:37:05.430
all the all the microchip,
544
00:37:05.890 --> 00:37:07.110
secure elements. Right?
545
00:37:07.490 --> 00:37:09.990
They're working even a new version now. Right? So,
546
00:37:10.984 --> 00:37:11.704
which is which is great.
547
00:37:13.305 --> 00:37:21.470
And and, you know, as much as there will be, of course, vulnerabilities in the next one, the next one, the next one, they start to become more expensive, and and we start to understand
548
00:37:21.850 --> 00:37:32.605
where the limitations of that technology is and try to build around it. Right? So you get a secure element like a secondary secure element and and sort of try to navigate that way. It's better to know from a friendly actor
549
00:37:33.065 --> 00:37:43.120
than, than to find out from, you know, exploits in the wild, which we would never know. It's part of the reason why we we advocate so much for for air gapping and and that kind of stuff is because,
550
00:37:43.660 --> 00:37:45.520
you know, what a lot of people
551
00:37:46.005 --> 00:37:48.345
sort of, you know, on Bitcoin Twitter don't understand
552
00:37:49.045 --> 00:37:49.785
is that
553
00:37:50.484 --> 00:37:54.265
the biggest challenge with security is the unknown unknown.
554
00:37:54.780 --> 00:37:57.200
Like most exploits will be overused
555
00:37:57.660 --> 00:37:59.440
before they become known.
556
00:38:00.540 --> 00:38:12.085
It's not that like, you know, like most guys that are friendly are gonna send you an email, hey, I found a bug, do you wanna pay me? No. Most guys are gonna go try to go in the market and steal people's money. Hey Charles, I have a question sort of extending Matt's question.
557
00:38:13.025 --> 00:38:13.525
558
00:38:14.670 --> 00:38:15.170
when
559
00:38:15.550 --> 00:38:19.490
Ledger is receiving I just want to sort of think about the economic incentive
560
00:38:20.349 --> 00:38:20.849
alignment.
561
00:38:21.445 --> 00:38:22.585
Right, so when
562
00:38:22.885 --> 00:38:25.705
Ledger is receiving $1 for selling
563
00:38:26.725 --> 00:38:28.105
a hardware wallet,
564
00:38:28.725 --> 00:38:30.025
some portion of that
565
00:38:30.760 --> 00:38:31.260
is
566
00:38:31.720 --> 00:38:32.220
is
567
00:38:32.520 --> 00:38:33.420
is put into
568
00:38:33.800 --> 00:38:38.460
supporting new tokens and feet and things like, you know, that we'll call shit coins.
569
00:38:39.825 --> 00:38:44.244
Not not to disparage the business model, but it's it's it's a good it's an interesting business model.
570
00:38:44.785 --> 00:38:49.205
And then some portion of that is put into hardware and hardware security.
571
00:38:49.650 --> 00:38:52.390
And where I get a little concerned is when
572
00:38:53.490 --> 00:38:56.070
that ratio of new money coming in
573
00:38:56.370 --> 00:39:01.454
where the incentive becomes more to support more and more tokens and
574
00:39:01.994 --> 00:39:03.214
alternate altcoins
575
00:39:04.154 --> 00:39:10.309
rather than to improve and increase security. I mean, is sort of DanJon just sort of the
576
00:39:11.010 --> 00:39:14.549
a fixed security spend, like, you allocate this much money to DanJon
577
00:39:14.849 --> 00:39:15.510
and then
578
00:39:16.049 --> 00:39:16.549
increase
579
00:39:17.045 --> 00:39:30.589
you don't maybe maybe that's too much detail for you to give away, but I'm just curious your thinking on that as how as new money revenue comes into Ledger, how are you divvying deciding how to divvy that up to security, new hardware security, and just new software altcoins?
580
00:39:31.605 --> 00:39:33.785
581
00:39:34.085 --> 00:39:36.825
So recently, we have grown a lot.
582
00:39:37.285 --> 00:39:44.970
And when we when we grow, of course, we are allocating some resources to support new features and so on, but also to security.
583
00:39:45.670 --> 00:39:50.235
Frankly, to to be honest, I I I would have difficulty to to to tell you,
584
00:39:50.795 --> 00:39:52.175
x amount of percent
585
00:39:52.555 --> 00:39:55.595
and so on. First of all, what I can say is,
586
00:39:56.640 --> 00:39:59.140
last year especially, we invested a lot
587
00:39:59.440 --> 00:40:00.260
on platformizing
588
00:40:00.720 --> 00:40:02.819
our products in order to
589
00:40:04.405 --> 00:40:07.465
so that this is the community which invests in
590
00:40:07.765 --> 00:40:10.805
supporting new features and new coin. So this is
591
00:40:11.770 --> 00:40:15.390
there, you have a great alignment in in incentives because
592
00:40:15.690 --> 00:40:19.150
the community is happy to have its new application,
593
00:40:19.715 --> 00:40:21.255
its new coin within,
594
00:40:21.955 --> 00:40:22.535
a ledger
595
00:40:22.835 --> 00:40:23.335
environment.
596
00:40:24.195 --> 00:40:26.295
And, on our side, we can continue
597
00:40:28.260 --> 00:40:29.640
investing in security.
598
00:40:30.099 --> 00:40:31.960
And about these very parts,
599
00:40:32.820 --> 00:40:39.455
like security, like, is about it's also when you are a security vendor, it's mostly about trust.
600
00:40:40.075 --> 00:40:42.255
And if you do a big mistake,
601
00:40:42.650 --> 00:40:44.190
your clients, the ecosystem,
602
00:40:45.050 --> 00:40:49.230
the trust can fade away very quickly. So and and
603
00:40:50.010 --> 00:40:51.310
investing in security
604
00:40:53.145 --> 00:40:59.885
is is probably a good idea, short term, but long term, it's a very bad idea. Long term, you lose. And
605
00:41:00.500 --> 00:41:04.680
at leisure, I can say that this is this is really true. We are
606
00:41:05.300 --> 00:41:07.720
playing the long tech long term game.
607
00:41:08.415 --> 00:41:20.700
And I agree it's always a matter of trade off. So how can you make sure that, this amount of investment is enough on the long on the long run and so on? It's always difficult to to say. But what I can say is security
608
00:41:21.960 --> 00:41:28.224
is always our top priority, and we we we can't do a big mistake in this area because, otherwise,
609
00:41:29.484 --> 00:41:34.305
we lose we lose the game, and that's it. So, yeah, this would be my my answer.
610
00:41:34.940 --> 00:41:38.320
611
00:41:39.180 --> 00:41:41.360
Charles, first of all, I appreciate your answers.
612
00:41:41.740 --> 00:41:47.155
Look, I think I think, you know, you and the rest of the ledger team have, you know, a very strong,
613
00:41:48.255 --> 00:41:49.315
security reputation,
614
00:41:49.695 --> 00:41:53.540
very good track record. Don John, as MBK said, is absolutely,
615
00:41:54.960 --> 00:41:56.580
fantastic to have in the space.
616
00:41:57.520 --> 00:41:58.339
My question
617
00:41:59.115 --> 00:42:04.255
with the alt coins and the staking and the NFT was more on the UX side. So it's,
618
00:42:04.795 --> 00:42:06.975
you know, I, I, I wonder
619
00:42:07.549 --> 00:42:14.130
that there's been a recent move that I've I've really enjoyed in the in the Bitcoin industry of of trying to simplify
620
00:42:14.430 --> 00:42:15.809
to simplify the UX.
621
00:42:16.244 --> 00:42:19.224
But on the ledger side, you know, you guys have
622
00:42:20.325 --> 00:42:25.945
a, a, a pretty great mobile app and a mobile experience with, with the ledger device.
623
00:42:26.390 --> 00:42:29.850
But ultimately, it's it's it's a feature packed,
624
00:42:30.150 --> 00:42:33.050
like, software suite. Is there any thoughts about
625
00:42:34.065 --> 00:42:42.405
offering maybe some kind of simplified experience that doesn't give you all the things that Ledger Live gives you, or is that not a priority?
626
00:42:43.970 --> 00:42:47.810
627
00:42:48.130 --> 00:42:49.110
again and again.
628
00:42:50.115 --> 00:42:51.495
And for now,
629
00:42:52.035 --> 00:42:53.655
the I think the consensus
630
00:42:54.035 --> 00:42:58.700
at ledger after, like, doing user research and so on is that the market
631
00:43:00.680 --> 00:43:01.819
is more expecting
632
00:43:02.200 --> 00:43:05.180
what we built at Ledger, I think, a one stop shop
633
00:43:06.055 --> 00:43:08.715
software rather than adding something very,
634
00:43:09.255 --> 00:43:10.615
minimal and very,
635
00:43:11.575 --> 00:43:15.675
and very simple. So this is this is where we are in terms of user or research,
636
00:43:16.520 --> 00:43:28.625
but things change. Like, user change. We have new and new users. The users we had, like, 5 years ago are very different from the one we have today. So this is something we we we have to think about. And when when
637
00:43:29.005 --> 00:43:33.105
when we talk about UX and ease of use and when I think about my mother using,
638
00:43:33.660 --> 00:43:36.640
using crypto, frankly, digital life is too complex for her.
639
00:43:37.260 --> 00:43:44.875
So probably this answer will evolve in the future and probably we will need, like, something more simple for for my model.
640
00:43:45.495 --> 00:43:47.755
641
00:43:48.190 --> 00:43:49.089
I mean, obviously,
642
00:43:49.710 --> 00:43:51.410
CoinKite is Bitcoin only,
643
00:43:51.869 --> 00:44:00.305
but the cold card is a very feature full device. There's a lot of things you could do on a cold card. And the moved the move with the tap signer to me
644
00:44:00.605 --> 00:44:05.905
signifies, you know, oh, this is a a more simple straightforward device that does one thing,
645
00:44:07.020 --> 00:44:08.320
does it does it well,
646
00:44:08.860 --> 00:44:11.280
and takes a different trade off balance. Right?
647
00:44:11.660 --> 00:44:14.320
648
00:44:14.755 --> 00:44:16.855
right, in this whole industry,
649
00:44:17.875 --> 00:44:18.375
I
650
00:44:19.075 --> 00:44:21.654
I I think shitcoins are only gonna grow.
651
00:44:22.070 --> 00:44:26.730
Right? And and they're gonna grow a million x still until they go to 0.
652
00:44:27.430 --> 00:44:32.474
So I I think it's gonna be hard for a more mass market product,
653
00:44:33.015 --> 00:44:46.119
like Ledger to sort of cut that off. I mean, like, you know, you guys are gonna have to sort of get rid of, like, what? Like, a 5th of your like, 5 sorry. 4 5ths of your team because it's like, you know, you have the exchange services, you have all that stuff,
654
00:44:46.420 --> 00:44:47.960
and and it's extremely lucrative,
655
00:44:48.900 --> 00:44:58.315
and, you know, and, I believe in the free market, and there seems to be a very strong market demand for providing a secure solution for the Shecoins,
656
00:44:58.940 --> 00:45:03.840
And then that opens space for people like us who want to do Bitcoin only,
657
00:45:04.700 --> 00:45:07.520
don't want to sort of address that specific market.
658
00:45:08.275 --> 00:45:15.815
If anything, I find Ledger to be a great funnel, sales funnel for us because a lot of their users graduate and come to us to be Bitcoin only.
659
00:45:16.420 --> 00:45:22.120
Some leave us to go to them because they wanna have Shecoins now. I mean, you know, it it it that's that's how a market works.
660
00:45:22.420 --> 00:45:26.045
661
00:45:26.345 --> 00:45:43.230
is what is sort of the number one support question you get? Because you guys all you Craig too. Right? You guys all see support stuff, and I only have sort of micro interactions where I I either had a problem or I know somebody that had a problem. I'm just sort of curious if if you guys all see the same things or different things.
662
00:45:43.664 --> 00:45:45.924
663
00:45:46.545 --> 00:45:47.045
is,
664
00:45:49.105 --> 00:45:54.670
one of those things that that direct and inform us on almost every decision we make.
665
00:45:55.210 --> 00:45:58.430
So we make almost all decisions based on
666
00:45:58.845 --> 00:45:59.345
diminishing
667
00:46:00.045 --> 00:46:00.704
or extincting
668
00:46:01.404 --> 00:46:02.704
any support question.
669
00:46:03.244 --> 00:46:03.744
So,
670
00:46:04.765 --> 00:46:07.184
you know, our rate of support is abysmal
671
00:46:07.710 --> 00:46:14.610
tiny, right, because we've been making decisions, design decisions that further that goal through years,
672
00:46:15.105 --> 00:46:21.285
and even pre in our previous iterations of CoinKite and services that offered before even Cold Guard or OpenDine.
673
00:46:21.825 --> 00:46:22.325
So
674
00:46:22.880 --> 00:46:23.540
when people
675
00:46:23.840 --> 00:46:28.580
on Twitter like to go and sort of like bitch about, you know, UX, Bitcoin's difficult,
676
00:46:28.960 --> 00:46:30.100
Coldcard is difficult,
677
00:46:30.865 --> 00:46:37.285
You know, they're speaking from their asses, they don't understand that like the people who get into Bitcoin,
678
00:46:39.630 --> 00:46:41.330
they find a way, they learn,
679
00:46:42.270 --> 00:46:48.585
and they actually don't have support problems. I mean, we only get support questions when there is a bug. Right?
680
00:46:48.965 --> 00:46:51.945
A bug is found. It's like these users keep on hitting something
681
00:46:53.230 --> 00:47:00.914
that, like, we're like, hang on a second, like, it's not supposed to, like, you're not supposed to have this question. Oh, wait, you found a bug. Right?
682
00:47:02.095 --> 00:47:13.830
Really, the support questions are where is my order? Or why do customs have my order? Right? Like, this is the support that we get, and and I assume that for Ledger, it's probably going in that direction too because the market is evolving
683
00:47:14.290 --> 00:47:15.730
and becoming a lot more,
684
00:47:16.530 --> 00:47:17.030
knowledgeable
685
00:47:17.595 --> 00:47:20.495
or or find other means of finding that that knowledge.
686
00:47:21.755 --> 00:47:22.255
But,
687
00:47:22.715 --> 00:47:25.055
you know, I remember when we designed the OpenDime,
688
00:47:26.030 --> 00:47:30.050
we're like, how can I make a device that doesn't doesn't require software?
689
00:47:30.510 --> 00:47:35.650
Right? Like, there's no app, there's nothing, you just stick the thing in, and it's very sort of easy.
690
00:47:37.455 --> 00:47:37.955
And
691
00:47:39.615 --> 00:47:47.090
I find that generally speaking, the majority of the people who also buy our product are very self selecting too. Right? These are people who want to be Bitcoiners,
692
00:47:47.710 --> 00:47:51.810
so they will try to find answers by themselves too,
693
00:47:52.190 --> 00:47:52.690
which,
694
00:47:53.230 --> 00:47:53.890
you know,
695
00:47:54.795 --> 00:47:58.415
it's kinda sad because it prevents us from knowing questions they may have.
696
00:48:00.474 --> 00:48:02.895
So, yeah, so that's sort of like from our end.
697
00:48:03.490 --> 00:48:04.150
I'm curious,
698
00:48:05.090 --> 00:48:11.830
on on Craig and Charles, like, what are the support questions they have? And, Matt might have some great, unquote, gym questions there too.
699
00:48:12.415 --> 00:48:19.155
700
00:48:19.950 --> 00:48:20.450
701
00:48:20.910 --> 00:48:25.410
702
00:48:25.710 --> 00:48:37.375
you know, that's what they're thinking about, right? The wallet application is giving them the error. It's saying I can't do x or y. In fact, often, even if the hardware wallet is showing them in their error, they still contact
703
00:48:37.770 --> 00:48:42.910
Sparrow support group and still kind of like, you know, my cold card won't sign the transaction.
704
00:48:43.610 --> 00:48:44.865
You know, what should I do?
705
00:48:45.345 --> 00:48:56.120
And I frequently then jump onto, you know, cold card's code and kind of look through and try and see, well, why is it throwing an error on this line, which it often quite helpfully provides the line number. So,
706
00:48:56.420 --> 00:48:57.080
you know,
707
00:48:57.620 --> 00:49:03.400
that is something that I didn't fully appreciate when I started this whole thing off is that kind of, you know, kind of all,
708
00:49:03.704 --> 00:49:13.810
not all, but certainly I think most of it gravitates towards the wallet application that's being used. You know, so there's there's a whole whole lot of lot of that. But to go back to the original question,
709
00:49:14.110 --> 00:49:17.170
you know, the the major, you know, recurring support,
710
00:49:17.710 --> 00:49:21.665
you know, issues that I have, I actually made a note of them before this.
711
00:49:22.385 --> 00:49:31.370
They are, you know, perhaps in order or the the the the major one, at least for Sparrow is how do I connect to my node? I'm having issues connecting to my
712
00:49:31.670 --> 00:49:32.330
node. Obviously,
713
00:49:32.710 --> 00:49:33.770
we could have taken
714
00:49:34.070 --> 00:49:36.170
the sort of ledger approach, the blue wallet
715
00:49:36.470 --> 00:49:37.335
approach of
716
00:49:37.734 --> 00:49:45.670
by default, you know, you connect to the the sort of company server if you will or the provided one. I really didn't wanna do that.
717
00:49:46.150 --> 00:49:52.170
I still don't wanna wanna do it. One of my aims with Sparrow is to get more people running nodes. And,
718
00:49:53.055 --> 00:49:54.035
you know, so
719
00:49:54.335 --> 00:50:01.790
that's kind of one way to do it is just not to ever run the server yourself. So I'm kind of But you have a curated list, right, of,
720
00:50:02.090 --> 00:50:03.230
721
00:50:04.090 --> 00:50:09.265
722
00:50:09.825 --> 00:50:14.565
Spud Sparrow, and it just kind of realized there's a whole bunch of people out there who, you know,
723
00:50:15.265 --> 00:50:21.500
can use the soft soft software if they could just connect to a node. Like, it's not too difficult to use if they can just,
724
00:50:22.280 --> 00:50:23.180
get their wallets,
725
00:50:23.560 --> 00:50:33.325
to load. So, you know, providing those was really and remains a jumping off point. But, you know, the UI, the support, everyone kind of pushes people towards
726
00:50:33.680 --> 00:50:36.820
getting their own node. And so if you're a Sparrow user,
727
00:50:38.000 --> 00:50:41.220
and, you know, you're having issues with, you know,
728
00:50:41.855 --> 00:51:09.040
public nodes, the the general advice that anybody on the support group will give you is really consider getting your own node at this point. You know? So, definitely, there's a strong push towards towards that even though the public nodes are provided for people who just kind of getting into it. So that's support issue number 1 and will probably always remain support issue numb number number number 1. Then I would say Tor is the next issue. Tor,
729
00:51:10.140 --> 00:51:11.280
as as we know,
730
00:51:11.660 --> 00:51:12.160
is,
731
00:51:12.620 --> 00:51:14.560
often down, often has issues.
732
00:51:14.940 --> 00:51:17.920
No one really knows knows why an issue occurs.
733
00:51:19.055 --> 00:51:24.755
You know, it's just one of those things. Hopefully, at some point, it gets better, but I I suspect it won't.
734
00:51:25.270 --> 00:51:33.130
Maybe we need to look more closely at, I2P, but, you know, TOR is is one of those major things that never really goes away.
735
00:51:33.715 --> 00:51:35.655
And then just, for you guys,
736
00:51:36.595 --> 00:51:40.775
I I do get a fair number of of USB kernel
737
00:51:41.075 --> 00:51:42.695
kinda issues, which are
738
00:51:43.270 --> 00:51:47.370
just, you know, random issues where the USB kernel is just giving errors.
739
00:51:47.990 --> 00:51:49.850
And very unclear why.
740
00:51:50.710 --> 00:51:51.930
But often the best
741
00:51:52.605 --> 00:52:01.665
advice there is just to ask the user to re reboot, which almost always clears it up. So, you know, that's just one of those those things. I wouldn't say it's super common,
742
00:52:01.970 --> 00:52:04.150
but, it is kind of one of those,
743
00:52:04.770 --> 00:52:09.405
queries that you you get, and there's no real way to solve it or to
744
00:52:09.805 --> 00:52:11.725
reset set things that I'm aware of.
745
00:52:12.685 --> 00:52:15.425
But it it does pop up from time to time.
746
00:52:16.125 --> 00:52:19.025
747
00:52:19.900 --> 00:52:23.839
What kind of signing difficulty do you see? Is it because the user
748
00:52:24.540 --> 00:52:32.005
so the the main issue with Coldcard, which is kind of by design is that it doesn't sign stuff that it shouldn't sign. Right?
749
00:52:32.385 --> 00:52:36.900
So it wants to make sure that it's sending change addresses back, you know,
750
00:52:37.360 --> 00:52:39.780
so essentially trying to not just YOLO. Right?
751
00:52:40.080 --> 00:52:45.300
It's trying to have some sanity check on what's signing to prevent the users from either being grifted
752
00:52:45.825 --> 00:52:46.484
or accidentally
753
00:52:46.785 --> 00:52:49.285
sort of sending to, you know, proof of burn.
754
00:52:49.825 --> 00:52:55.730
So I'm actually curious, like what kind of signing difficulty do they have?
755
00:52:57.390 --> 00:53:21.665
756
00:53:22.125 --> 00:53:28.609
more issues with the Trezza these these days because they are very restrictive on their derivation parts.
757
00:53:28.910 --> 00:53:33.950
And as a result, you kind of you often get these kind of errors where it just won't sign this path,
758
00:53:35.395 --> 00:53:53.319
and the error is not always super clear. And I think they've actually done quite a bit of work in the last few months, but people's firmware is not always up to date with that work. So they get a quite an odd error, and then you're not quite sure sure why. I think the more recent firm firm firmwares tend to make it a lot more more sort of clear.
759
00:53:53.905 --> 00:53:55.285
760
00:53:55.585 --> 00:54:08.210
it sounds that, like, one major thread on on how you end up having to spend your time doing support is because the hardware all the hardware is not up to date or the or the or the OS is not up to date.
761
00:54:08.670 --> 00:54:12.530
I know like USB on Linux is an absolute disaster.
762
00:54:13.835 --> 00:54:19.055
So that's a whole different problem, right? Like the majority of the people using Linux shouldn't be using Linux.
763
00:54:20.600 --> 00:54:27.420
They should be using a Mac or a PC and they would actually be safer doing that because they wouldn't be able to muck around and break things,
764
00:54:27.865 --> 00:54:32.445
but that's like a whole different thread. Now have you thought about, like, on the UI
765
00:54:32.905 --> 00:54:34.925
of Sparrow when they set up
766
00:54:35.600 --> 00:54:38.740
a new hardware wallet? Maybe you pull from,
767
00:54:40.640 --> 00:54:41.940
our GitHub repos,
768
00:54:42.320 --> 00:54:44.660
right, the latest version, not the software,
769
00:54:45.125 --> 00:54:50.744
just like, say maybe a model saying, hey, oh, I see that you are setting up a code card or a ledger.
770
00:54:51.204 --> 00:54:54.424
Are you running this latest software version xxx?
771
00:54:54.940 --> 00:54:55.440
You
772
00:54:55.900 --> 00:54:57.440
know, like maybe maybe
773
00:54:57.980 --> 00:55:02.720
them reading that or having to press okay to that might incentivize them to maybe upgrade,
774
00:55:03.194 --> 00:55:04.494
that's just an idea,
775
00:55:05.355 --> 00:55:08.655
that that could maybe help you have less support tickets.
776
00:55:09.275 --> 00:55:14.640
777
00:55:15.020 --> 00:55:20.160
design philosophy of like, don't build Nag Ware. You know, I really don't want to nag anyone.
778
00:55:20.460 --> 00:55:27.035
I kind of want to treat everyone as an adult who's kind of thinking about this. That may often not be the case, and maybe I'm
779
00:55:27.415 --> 00:55:27.734
I'm,
780
00:55:28.215 --> 00:55:39.270
misguided in in in that that that approach. But again, you know, I built Sparrow for me, and I don't want to have a little pop up that I have to dismiss saying, have you upgraded to the latest firm firmware?
781
00:55:39.650 --> 00:55:43.075
So that's why it isn't that kind of thing isn't isn't there.
782
00:55:43.615 --> 00:55:50.490
It may very well, you know, if I did that kind of thing, reduce the number of support tickets and, well, you know, queries. But,
783
00:55:51.190 --> 00:55:52.810
it's gonna, in my opinion,
784
00:55:53.110 --> 00:55:57.690
diminish the quality of the soft software. So, you know, I'm always gonna tend towards,
785
00:55:58.205 --> 00:55:59.745
inequality rather than
786
00:56:00.205 --> 00:56:01.985
trying to diminish support, I guess.
787
00:56:02.365 --> 00:56:05.505
788
00:56:06.330 --> 00:56:09.790
of the stuff that we make is to make sure users don't lose their money.
789
00:56:10.410 --> 00:56:14.670
Like, it's sort of like that's always sort of like priority number 1 in my head.
790
00:56:15.385 --> 00:56:22.125
I mean, Coldcard was designed in our image. We wanted to have all the features and all the things that Bitcoin does, but
791
00:56:22.790 --> 00:56:30.970
I find myself also as a normal user who is just sitting trying to do core, you know, corporate treasury operations, and I don't wanna have to think
792
00:56:31.695 --> 00:56:35.155
about all this stuff. So I try to build sort of, like,
793
00:56:36.015 --> 00:56:39.955
things that that sort of I can offload some of that thinking to the device
794
00:56:40.620 --> 00:56:49.600
in a pinch. Right? So, or like, you know, I just have to go sign a transaction. I don't wanna have to, like, check the signature and all the stack and doing all these things. So
795
00:56:50.145 --> 00:56:51.845
that that balance and and the
796
00:56:53.425 --> 00:56:57.845
the the friction in that balance, it really is sort of like where
797
00:56:58.410 --> 00:57:00.270
you try to find good software.
798
00:57:00.890 --> 00:57:01.390
Charles,
799
00:57:02.170 --> 00:57:03.230
you must get
800
00:57:03.930 --> 00:57:09.035
a, you know, you're probably like a 1000000 x bigger than all of us in terms of like install base.
801
00:57:09.494 --> 00:57:10.315
Very curious,
802
00:57:11.494 --> 00:57:13.434
aside from where is my ledger,
803
00:57:14.535 --> 00:57:15.434
tickets, like
804
00:57:16.630 --> 00:57:17.930
where do people fail?
805
00:57:18.550 --> 00:57:19.370
Maybe not
806
00:57:19.910 --> 00:57:21.770
the super normie people because,
807
00:57:22.070 --> 00:57:28.615
you know, that's the obvious stuff, but like where is that middle ground of people who are at least trying to understand what they're doing?
808
00:57:29.475 --> 00:57:32.055
Where do they fail and they need to ask for help?
809
00:57:33.190 --> 00:57:40.650
810
00:57:41.109 --> 00:57:41.930
very simple.
811
00:57:42.535 --> 00:57:52.200
Like, clients, customers don't really understand what's going on, what to do, how to initialize their wallet. We we have a lot of, this this kind of stuff.
812
00:57:52.920 --> 00:57:57.500
Also, something which, which comes quite often is, like, connection issue.
813
00:57:57.800 --> 00:57:58.859
When you have, like,
814
00:57:59.855 --> 00:58:00.355
Bluetooth,
815
00:58:01.055 --> 00:58:02.755
BLE, with the NanoX.
816
00:58:03.055 --> 00:58:05.395
If you have, like, an old phone or,
817
00:58:06.095 --> 00:58:08.280
some some very, very weird
818
00:58:09.140 --> 00:58:10.280
BLE implementation,
819
00:58:10.740 --> 00:58:12.360
it can it can be difficult.
820
00:58:13.060 --> 00:58:14.180
USB on Linux,
821
00:58:14.580 --> 00:58:18.825
can be can be an issue as well. So, So, yeah, we we have this kind of stuff. And
822
00:58:19.285 --> 00:58:26.810
I I don't have, like, precise numbers, but I think that this is 90 90% of, of the of the volume of of tickets.
823
00:58:27.430 --> 00:58:27.930
And,
824
00:58:28.790 --> 00:58:32.010
and sometimes you have very tech savvy
825
00:58:32.470 --> 00:58:35.475
users who are, like, asking, like,
826
00:58:35.935 --> 00:58:37.875
very, very precise question.
827
00:58:38.415 --> 00:58:49.829
And when this question come to, the technical team, we are like, woah. How? How how to deliver that? I I I don't have a precise example, but you have people, like, playing with complex,
828
00:58:50.914 --> 00:59:04.170
with with a complex dApp on Polygon chain and so on. There's a stuff we we don't even know. So we have to, research in order to to help them. So various thing, but mostly mostly simple stuff, of course.
829
00:59:04.950 --> 00:59:07.690
830
00:59:08.555 --> 00:59:10.734
like, Matt has had the privilege
831
00:59:11.914 --> 00:59:12.575
and and
832
00:59:12.954 --> 00:59:16.015
the the amount of work that it is to try to sort of like
833
00:59:16.600 --> 00:59:19.500
educate people on Bitcoin, deal with activists,
834
00:59:19.800 --> 00:59:23.580
deal with, you know, like different categories of people
835
00:59:24.575 --> 00:59:26.435
who are not necessarily, you
836
00:59:26.895 --> 00:59:28.595
know, the the proverbial
837
00:59:29.055 --> 00:59:29.555
mother,
838
00:59:30.175 --> 00:59:31.155
but, like, the
839
00:59:31.510 --> 00:59:36.170
the the next people, right, the the the people who are actually trying to understand what they're doing, like,
840
00:59:36.550 --> 00:59:45.215
where do people fail, and where do they hit up you or or you tell them to sort of go talk to support and try to figure out what's going on? I will say,
841
00:59:47.660 --> 00:59:49.599
842
00:59:50.059 --> 00:59:52.000
I'm a relatively pragmatic person.
843
00:59:52.619 --> 00:59:54.319
So with a lot of people, they,
844
00:59:54.815 --> 00:59:56.355
they do want to hold altcoins.
845
00:59:57.135 --> 00:59:58.835
And because they want to hold altcoins,
846
00:59:59.455 --> 01:00:07.460
I do send them to Ledger a lot. Particularly the mobile app, I feel like has made it a lot easier. It's a lot lower lift. Most people do not have phones,
847
01:00:07.920 --> 01:00:14.905
and do not have computers. So the fact that that you can just do everything from the phone from the get go is a is a massive win.
848
01:00:16.885 --> 01:00:21.945
The single biggest thing, I mean, I see is people trying to move from Ledger Live
849
01:00:23.740 --> 01:00:27.360
to Sparrow Wallet or something like that where they wanna use their own node.
850
01:00:28.460 --> 01:00:37.215
And most of that, like, we've made it easier, but Craig Craig has touched on it already about Tor issues. I mean, most of the time, people are connecting
851
01:00:37.660 --> 01:00:39.280
to their own node via Tor.
852
01:00:40.460 --> 01:00:41.760
With Ledger specifically,
853
01:00:42.060 --> 01:00:46.320
there's, like, always, like, the issue of, like, okay. So I gotta initialize the device.
854
01:00:46.865 --> 01:00:53.204
I have to set it up. I have to update the firmware. What information am I leaking to Ledger? There's a lot there's a little bit of nuance there,
855
01:00:53.984 --> 01:01:00.300
in terms of of trying to set that up where you're not leaking data before you're connecting it to your own node. But, specifically,
856
01:01:01.560 --> 01:01:12.255
that pairing process with your own node or with the trusted friend's node, uncle Jim node. Right? When we say uncle Jim, we mean, you know, a friend or family member that you trust using their node.
857
01:01:12.780 --> 01:01:21.440
I we see a lot of difficulties with that. I will give Craig a huge shout out that because he has Tor directly built into Sparrow, you literally just need to
858
01:01:21.755 --> 01:01:26.415
just need to copy and paste, the Tor Electrum address directly in there and boom, done.
859
01:01:27.675 --> 01:01:30.655
860
01:01:33.030 --> 01:01:38.170
It's a 2 minds on this. One is I don't think any client should have
861
01:01:38.550 --> 01:01:39.930
4 in them because
862
01:01:40.515 --> 01:01:42.135
users end up with 2, 3,
863
01:01:42.595 --> 01:01:45.174
4 services running at the same time in their computers
864
01:01:45.635 --> 01:01:46.934
that can cause problems,
865
01:01:47.530 --> 01:01:49.790
or if anything just slows down further.
866
01:01:50.730 --> 01:01:51.230
So
867
01:01:51.610 --> 01:01:53.710
I mean I have never looked into it but
868
01:01:54.170 --> 01:01:55.310
have you looked into
869
01:01:55.610 --> 01:01:56.110
maybe
870
01:01:57.525 --> 01:02:01.225
helping users sort of like set up Tor natively on their computer,
871
01:02:02.405 --> 01:02:10.870
as just a, like, know, every time you boot your computer, you'll have a Tor proxy running. Right? I I do this. Right? You go brew, services,
872
01:02:11.730 --> 01:02:12.710
start Tor.
873
01:02:13.705 --> 01:02:18.125
Matt, this this is this is a You're wrong on this one.
874
01:02:18.665 --> 01:02:19.405
Yeah. So
875
01:02:20.300 --> 01:02:22.300
you don't want it to tour in each app.
876
01:02:22.940 --> 01:02:28.320
You you definitely don't. It does help the noobs. I'm I'm not denying that. It really does help the noobs,
877
01:02:28.895 --> 01:02:32.915
but I I really don't want my client's software choosing which store to run
878
01:02:33.375 --> 01:02:34.755
and and have that
879
01:02:35.055 --> 01:02:37.954
being the default. Yeah. I think you're wrong in this one, MBK.
880
01:02:38.800 --> 01:02:53.565
881
01:02:53.945 --> 01:02:57.805
Meanwhile, with with Sparrow, all I have to do is tell them install Sparrow,
882
01:02:58.250 --> 01:03:05.150
then go to the setup guide and either press ledger or or cold card, and then follow the steps and paste the tour address into the thing.
883
01:03:05.770 --> 01:03:07.630
It's, like, well, it's way simpler.
884
01:03:07.935 --> 01:03:11.875
885
01:03:12.415 --> 01:03:14.035
I almost feel like in Bitcoin,
886
01:03:14.655 --> 01:03:17.840
when you when you turn on any Bitcoin device or software,
887
01:03:18.880 --> 01:03:21.780
there should be a a pop up that asks,
888
01:03:22.480 --> 01:03:22.980
noob,
889
01:03:24.240 --> 01:03:24.980
not noob.
890
01:03:25.600 --> 01:03:27.845
And and and it's like, and he presents
891
01:03:28.145 --> 01:03:32.485
completely different sets of defaults, completely sets different sets
892
01:03:32.865 --> 01:03:34.645
of like features and everything
893
01:03:35.265 --> 01:03:35.765
because
894
01:03:36.225 --> 01:03:38.339
I I find it so frustrating,
895
01:03:40.880 --> 01:03:41.539
when people
896
01:03:42.319 --> 01:03:49.275
obviously make different design decisions based on the expectation of how new or not new I am,
897
01:03:49.575 --> 01:03:52.474
and we are all always gonna disagree on that.
898
01:03:52.855 --> 01:03:56.315
Right? Like I mean, it is the very nature of advanced people.
899
01:03:56.700 --> 01:03:59.440
We're all gonna have opinions and and it's such
900
01:03:59.740 --> 01:04:06.445
a a huge, huge challenge to to find that balance and and anyways, it's just more like a rant than like anything actionable.
901
01:04:14.980 --> 01:04:16.680
Noob or not noob?
902
01:04:17.220 --> 01:04:23.960
And sort of like change the UX after that. But then, you know, we go through the struggle of trying to create the the UX that serves both.
903
01:04:24.355 --> 01:04:28.535
But because it does expose the noobs to more stuff, right, and sort of like people learn.
904
01:04:29.395 --> 01:04:32.135
But, yeah, that's, that's an interesting thing there.
905
01:04:32.970 --> 01:04:36.430
906
01:04:37.049 --> 01:04:47.655
I'm always like, my my heart often sinks a bit when people, like, are saying, well, I'm trying to connect via via tour. Because now I just think think to myself, well, now there's just a whole lot of other issues that it could be.
907
01:04:48.434 --> 01:04:55.140
You know, tour is is this thing that we all love and love to hate at the same same same time. Right? So,
908
01:04:56.240 --> 01:05:07.760
you know, for me, I always you know, if I'm talking to somebody over support, I always say, listen. The best way you can connect if you're running your own node and you're sitting in the same house as that node
909
01:05:08.140 --> 01:05:13.119
is con is connect to the local IP, get the best speed that you can, and then configure
910
01:05:13.525 --> 01:05:17.385
an external Tor proxy, which is exactly what you're saying, MBK,
911
01:05:17.685 --> 01:05:28.920
you know, that is that is it makes complete sense. Then all of your external communications are going out over tour, and you're connecting over your local private network to your your your node to sync your
912
01:05:29.619 --> 01:05:33.405
wallet. So, you know, that's that's kind of the way that I do it.
913
01:05:34.205 --> 01:05:46.950
Obviously, if you leave your your home, then you might need a different way to do things, but then I tend to opt for a VPN. So, you know and I kind of VPN into that private network that I have at at home. So there's
914
01:05:47.250 --> 01:05:48.145
there's kind of,
915
01:05:48.945 --> 01:05:51.765
I try to avoid using Tor to download,
916
01:05:52.625 --> 01:06:01.700
you know, the data for the for the wallet. Because if you have a large wallet, you can imagine there's a lot of data that you have to now transmit over Tor. And it's just a very slow
917
01:06:02.079 --> 01:06:04.740
transport mechanism to use. So, you know,
918
01:06:05.280 --> 01:06:10.245
I very much support for a more advanced user is don't use the tool built into
919
01:06:10.545 --> 01:06:17.860
Sparrow. You know? Rather go out there and set up your own tool, which starts whenever the computer could've starts. But to Matt's point, you know,
920
01:06:18.160 --> 01:06:26.675
trying to explain to a user that they need to run brew services, tour, or, you know, whatever it is, that's a challenge. That's a real challenge.
921
01:06:26.975 --> 01:06:36.279
922
01:06:37.460 --> 01:06:39.799
923
01:06:42.245 --> 01:06:46.025
See, that that's actually another, like, small rant on the UX part. Right?
924
01:06:46.725 --> 01:06:49.065
One of the biggest problems with, like,
925
01:06:49.960 --> 01:06:52.460
creating experiences that are too easy,
926
01:06:52.920 --> 01:06:54.299
right, is that the users
927
01:06:54.920 --> 01:06:56.380
rightfully being lazy
928
01:06:56.724 --> 01:06:59.145
and busier with the other parts of their lives,
929
01:06:59.765 --> 01:07:01.704
don't put any effort into learning
930
01:07:02.405 --> 01:07:04.265
what the seed is or what it does.
931
01:07:04.805 --> 01:07:23.495
So there is this very easy social engineering attacks where they'll go to a user and they'll say, like, you know, to the mom, right? The mom has a hardware wallet, set it up, whatever, and then it goes to her, you know, on a DM saying, hey, I've heard that you have a problem with your wallet, send me your seed, and people do,
932
01:07:24.275 --> 01:07:25.015
right? Because
933
01:07:25.460 --> 01:07:26.279
they were not forced
934
01:07:27.220 --> 01:07:29.640
into understanding how dangerous that is,
935
01:07:30.259 --> 01:07:36.615
936
01:07:38.035 --> 01:07:39.815
never put this seed into anything
937
01:07:40.275 --> 01:07:56.765
unless you call me first. That's just what I say to them. I just say never never take this into anything unless you call me. So what do you do what he did is you're essentially the personal firewall for, for family and friends. That's right. That's right. I mean, we we talk about all this advanced security stuff, and then 99%
938
01:07:57.065 --> 01:08:11.855
939
01:08:12.475 --> 01:08:15.695
But this is this is a little bit like at the beginning of the Internet
940
01:08:16.020 --> 01:08:17.800
when, people didn't know,
941
01:08:18.580 --> 01:08:24.369
that they they they have to be careful about their credit card number and so on. Now,
942
01:08:24.905 --> 01:08:25.405
people
943
01:08:25.865 --> 01:08:28.845
have gained experience and understand better.
944
01:08:29.225 --> 01:08:29.725
And,
945
01:08:30.105 --> 01:08:30.605
but
946
01:08:30.960 --> 01:08:45.195
for for crypto, for Bitcoin, we are at the very beginning. People do not understand, and phishing them is the easiest way to steal them. But I think it it won't last. At some point, people will be educated and will be will understand
947
01:08:45.575 --> 01:09:05.639
948
01:09:06.020 --> 01:09:06.840
self custody
949
01:09:07.380 --> 01:09:09.159
and robust backup. And I think
950
01:09:09.699 --> 01:09:12.920
that you just that is the preemptive thing, and then you just need
951
01:09:13.665 --> 01:09:20.405
reinforced training that you don't enter this into things. Because even with, you know, sort of binary type x string type of things,
952
01:09:20.780 --> 01:09:25.840
people still can cut and paste those into things. Right? You can get phished on those things almost as easy.
953
01:09:26.620 --> 01:09:29.040
954
01:09:29.990 --> 01:09:31.745
like, where I was going.
955
01:09:33.005 --> 01:09:39.970
What what a lot of people don't understand is that most people will screw themselves out of their coins before they're ever robbed or phished
956
01:09:41.970 --> 01:09:44.630
even by anybody. Right? So, you know, asking a user
957
01:09:45.250 --> 01:09:50.185
who might put real money into a wallet to not have a non digital backup
958
01:09:50.645 --> 01:09:51.864
that's human legible,
959
01:09:52.645 --> 01:09:54.025
it's it's an absolute
960
01:09:54.405 --> 01:09:56.425
disaster waiting to happen. Right? Because
961
01:09:57.000 --> 01:09:58.940
statistically speaking, I mean, the chances
962
01:09:59.320 --> 01:10:04.780
of your house catching on fire, your phone catching on fire with the house, or you losing the phone,
963
01:10:05.445 --> 01:10:08.184
and maybe not having access to your cloud or something
964
01:10:08.724 --> 01:10:10.344
are much higher,
965
01:10:10.724 --> 01:10:13.179
sorry, sorry, much much lower than,
966
01:10:13.739 --> 01:10:17.760
you know, your house catching on sorry, your house catching on fire has a much higher
967
01:10:18.060 --> 01:10:25.114
capacity of happening than somebody stealing the money from you. So having that seed, that human legible
968
01:10:25.815 --> 01:10:26.315
seed,
969
01:10:26.695 --> 01:10:28.235
right, on a piece of metal,
970
01:10:29.255 --> 01:10:32.340
it's like in my view, it's like this just,
971
01:10:32.960 --> 01:10:40.165
it's almost like another huge advancement just like Bitcoin was. This idea that it can have, you know, this this cryptographic
972
01:10:40.785 --> 01:10:41.285
secret
973
01:10:41.905 --> 01:10:47.925
974
01:10:48.240 --> 01:10:49.620
and I I really hadn't
975
01:10:50.000 --> 01:11:00.275
been priming him very much. I mean, he was sort of aware of Bitcoin and dabbling and looking at this or that, but I really hadn't been pushing him at all. And he was sort of ready at one point, and we sort of went into it. And
976
01:11:00.655 --> 01:11:14.210
when I sort of told him about the metal backup and I sort of showed him what to do, I showed him, you know, stamping washers and stuff. That made perfect he's not a technical guy. I mean, that made perfect sense to him, and we went through it, and he he took it really seriously. And
977
01:11:15.225 --> 01:11:20.445
and and I I thought it was a really great success, and he he understands. I'm like, if somebody finds this,
978
01:11:21.305 --> 01:11:26.409
they have your money. Right? I mean, this is like a bar of gold. You know, wherever you put this, you're putting a bar of gold.
979
01:11:26.710 --> 01:11:35.545
And that that's just a really easy concept for him to get, I think. Yeah. No. That's exactly it. I mean, humans have been doing physical custody
980
01:11:36.245 --> 01:11:36.745
981
01:11:37.125 --> 01:11:44.600
since humans were around. Right? Like, I was there screaming in the forest, running after animals to eat, and I was probably custodying
982
01:11:44.980 --> 01:11:46.815
whatever I killed, right?
983
01:11:47.915 --> 01:11:50.655
So like it is it is a very natural
984
01:11:51.755 --> 01:12:01.190
thing for people to do which is really cool. People understand that natively. They don't have to sort of like get schooled on how to keep something secret physically,
985
01:12:02.695 --> 01:12:05.835
So that's like a nice first step, so that when they
986
01:12:06.455 --> 01:12:13.840
go to the next round and sort of like the next upgrade in security and do, I don't know, multi sig or pass phrase or whatever,
987
01:12:14.460 --> 01:12:15.600
they will instinctively
988
01:12:15.980 --> 01:12:21.305
understand that now maybe they have 2 secrets as opposed to 1, and they should put it in 2 separate places,
989
01:12:21.685 --> 01:12:22.185
right?
990
01:12:22.565 --> 01:12:23.065
Yeah,
991
01:12:23.365 --> 01:12:28.440
I am not a fan of the seedless designs, and I think will will lead to a lot of grief.
992
01:12:29.219 --> 01:12:31.159
993
01:12:31.540 --> 01:12:33.080
seedless multisig setups?
994
01:12:35.445 --> 01:12:37.385
995
01:12:37.765 --> 01:12:38.265
Right?
996
01:12:39.445 --> 01:12:39.945
That
997
01:12:40.565 --> 01:12:42.825
essentially, like, negates all my rants
998
01:12:43.270 --> 01:12:44.410
that I just had.
999
01:12:45.750 --> 01:12:46.250
Because,
1000
01:12:46.630 --> 01:12:47.130
you
1001
01:12:47.510 --> 01:12:48.570
know, really, like,
1002
01:12:48.950 --> 01:12:50.810
we have to try stuff
1003
01:12:51.605 --> 01:12:56.105
to see if we can come up with the next thing. Right? Because seeds are not perfect.
1004
01:12:56.804 --> 01:12:59.545
They're amazing, but they're not perfect. So
1005
01:13:00.040 --> 01:13:02.219
how do we go to the next thing?
1006
01:13:02.679 --> 01:13:03.739
And there is also
1007
01:13:04.119 --> 01:13:06.940
Taproot, which does change the
1008
01:13:07.425 --> 01:13:08.165
the security
1009
01:13:08.465 --> 01:13:17.330
trade offs as well when it comes to multisig and and each signer sort of derisking them and stuff. So TapSigner is our attempt at doing seedless
1010
01:13:18.430 --> 01:13:18.930
by
1011
01:13:19.390 --> 01:13:20.610
still making the user
1012
01:13:21.230 --> 01:13:24.050
ideally back up on their phone an encrypted key
1013
01:13:24.955 --> 01:13:29.135
where the encryption of the key is laser etched on the card.
1014
01:13:29.594 --> 01:13:32.895
So the phone cannot see that private key. Now
1015
01:13:33.580 --> 01:13:34.880
we're very clear
1016
01:13:35.580 --> 01:13:36.080
that
1017
01:13:36.540 --> 01:13:38.960
the trade offs that we made on that product
1018
01:13:39.260 --> 01:13:42.240
are not for you to put your life savings in single sig,
1019
01:13:42.705 --> 01:13:43.205
right?
1020
01:13:43.744 --> 01:13:48.005
But they could work for you to have your life savings in multi sig because
1021
01:13:48.385 --> 01:13:53.460
see, you can use you can have a tap signer as just one of your signers,
1022
01:13:54.160 --> 01:13:55.060
one that is
1023
01:13:56.000 --> 01:13:57.540
high availability to you
1024
01:13:57.865 --> 01:13:59.485
so the keys are not on the phone.
1025
01:13:59.865 --> 01:14:03.805
And the other signer could be a cold card that's deep buried somewhere
1026
01:14:04.185 --> 01:14:08.360
where you do have a backup and maybe the third one is a service
1027
01:14:08.739 --> 01:14:13.000
or is another cold card or something. Right? So you could derisk
1028
01:14:13.460 --> 01:14:14.840
the lack of that seedless
1029
01:14:15.715 --> 01:14:16.215
signer
1030
01:14:16.994 --> 01:14:17.895
of that multisig.
1031
01:14:19.315 --> 01:14:20.215
We essentially
1032
01:14:20.675 --> 01:14:22.455
get back to seeds
1033
01:14:23.000 --> 01:14:26.219
even though you're functioning on your daily base seedless.
1034
01:14:27.320 --> 01:14:28.940
I think it's an interesting proposition,
1035
01:14:29.880 --> 01:14:30.940
and as Charles
1036
01:14:31.435 --> 01:14:35.535
and Lazy would would be very familiar with this is Java cards
1037
01:14:35.995 --> 01:14:39.535
are a very old and resilient technology. Right? So
1038
01:14:39.850 --> 01:14:40.350
the
1039
01:14:41.530 --> 01:14:44.110
the chances of that device breaking beyond
1040
01:14:44.490 --> 01:14:44.990
recoverability
1041
01:14:45.530 --> 01:14:46.510
are very low.
1042
01:14:47.025 --> 01:14:52.165
So that also gives me a bit more comfort. And these devices are essentially fully sealed,
1043
01:14:52.465 --> 01:14:53.685
right, because they are,
1044
01:14:55.025 --> 01:14:55.525
NFC
1045
01:14:56.000 --> 01:15:01.300
sort of essentially baked into plastic. And on Charles case, I think you guys put epoxy over the the SE, right,
1046
01:15:02.400 --> 01:15:09.965
or no? I can't remember. But but, you know, but the package is resilient enough and and and you should be able to at least recover in a lab in case you need to,
1047
01:15:10.345 --> 01:15:17.490
provided that you have the PIN and all the good stuff on your case. But anyways, I I think 2 things are important. 1 is we need to recognize
1048
01:15:18.350 --> 01:15:20.850
that seeds are an incredible achievement.
1049
01:15:21.555 --> 01:15:23.735
We should push people towards them,
1050
01:15:24.355 --> 01:15:28.455
but we should not stop attempting to come up with alternatives
1051
01:15:29.410 --> 01:15:33.750
that may resolve some of the UX challenges, at least for the daily operational,
1052
01:15:35.250 --> 01:15:36.310
part of your life.
1053
01:15:37.105 --> 01:15:39.765
That that's sort of, like, my my view on this.
1054
01:15:40.225 --> 01:15:42.565
I'm kinda curious on Lazy's view on this.
1055
01:15:43.905 --> 01:15:44.965
1056
01:15:45.320 --> 01:15:46.620
a single sig maximalist.
1057
01:15:47.800 --> 01:15:49.980
I will so well, for say for
1058
01:15:51.080 --> 01:15:58.645
personal savings, like, I think there may be a c list multi sig for an intermediate value of spending or something like that, like,
1059
01:15:59.025 --> 01:16:01.525
your normal bank account, not your
1060
01:16:01.825 --> 01:16:04.165
life savings account might work. But I
1061
01:16:04.890 --> 01:16:07.150
I've just been really against I I mean,
1062
01:16:07.610 --> 01:16:11.310
what bothers me with multisig is when you have sort of the
1063
01:16:12.255 --> 01:16:23.360
2 of 3. Like, a 2 of 2 multisig, I'm much more comfortable with, but when you start having 2 of 3, I think it starts really leaving room for people to mess up because they they don't realize that they need
1064
01:16:23.739 --> 01:16:24.639
3 of 3
1065
01:16:25.020 --> 01:16:26.480
public keys backed up,
1066
01:16:26.860 --> 01:16:28.000
and the redundancy
1067
01:16:28.380 --> 01:16:31.095
in their their backup setup of all those. So
1068
01:16:31.635 --> 01:16:42.630
I I I'm really 2 of 2 may be multisig, but I'm I'm really just a single sig passphrase guy. I that's all I ever recommend right now. I I am a 100% with you there. I don't think people appreciate
1069
01:16:43.090 --> 01:16:49.955
1070
01:16:50.575 --> 01:17:01.699
1071
01:17:02.400 --> 01:17:07.815
I I so I well, I I don't wanna describe what I did specifically, but I I did something with,
1072
01:17:09.015 --> 01:17:17.280
my backup so I could have it sort of more available. So there was some superficial protection not superficial. Some strong protection against somebody just casually finding it,
1073
01:17:17.659 --> 01:17:24.265
outside the passphrase. And I had I had sort of done it a couple times and tested it, and then I tested it one time and I realized
1074
01:17:24.965 --> 01:17:34.480
I had duplicated one of the things on there in a way that I could figure it out, but I'm, like, I did this, like, 3 times and I didn't catch this simple mistake, and this is just sort of
1075
01:17:34.780 --> 01:17:38.000
a simple single sig type of thing. I'm like, holy cow.
1076
01:17:38.635 --> 01:17:42.494
Adding small things just create a lot more additional complexity than people appreciate.
1077
01:17:43.275 --> 01:17:47.360
1078
01:17:54.535 --> 01:18:01.115
husbands and then the husband dies and then, like, he left a super complex multisig setup that is incredible. It's so secure
1079
01:18:01.495 --> 01:18:04.315
that the wife can't figure out. Nobody can.
1080
01:18:05.239 --> 01:18:07.820
You know, I I I am a staunch believer
1081
01:18:08.280 --> 01:18:12.860
that multisig should be done managed. Right? So you're gonna have a wallet like Nunchuk
1082
01:18:13.315 --> 01:18:22.054
that will sort of, like, help you set up the multisig in very specific use case or, you know, Craig's solution is gonna use a similar solution.
1083
01:18:22.420 --> 01:18:24.199
Ideally, like on Sparrow, like,
1084
01:18:24.500 --> 01:18:29.800
you know, I understand you wanna let people be grown ups and set up all the stuff however they want, but like
1085
01:18:30.265 --> 01:18:35.005
people make mistakes and they don't back up things the right way, so they do end up screwing themselves
1086
01:18:35.385 --> 01:18:37.565
over. And I think a lot of the hate
1087
01:18:38.170 --> 01:18:40.670
for single sig come from people doing,
1088
01:18:42.010 --> 01:18:43.870
FUD ing, harder wallets really.
1089
01:18:44.410 --> 01:18:47.390
There is some actors in the space, they're like,
1090
01:18:47.965 --> 01:18:52.625
the paranoia that they have against hardware wallets is completely uncalled for because it's provably wrong.
1091
01:18:52.925 --> 01:18:53.425
Right?
1092
01:18:54.205 --> 01:18:58.370
You can be provably wrong, right, if you do your diets, if you do all the stuff, and
1093
01:18:58.750 --> 01:19:00.850
you could resolve that that paranoia
1094
01:19:01.470 --> 01:19:05.010
instead of pushing noobs to do multisig with 50 CDs.
1095
01:19:05.804 --> 01:19:15.025
1096
01:19:15.630 --> 01:19:21.410
and you pass away and whoever you want to receive your Bitcoin, isn't able to access it.
1097
01:19:22.350 --> 01:19:24.555
That, and that is not unique to multisig.
1098
01:19:25.015 --> 01:19:25.995
I have had,
1099
01:19:26.775 --> 01:19:31.515
I've gotten messages at, you know, midnight from a friend. I'm going into surgery tomorrow.
1100
01:19:31.900 --> 01:19:47.565
You know, my wife knows where my seed and my pass raises, but I told her to call you if something bad happens, it's free to recover it. And like, obviously that's not a great situation because she has, you know, whoever, whoever your air is, has the whole, the whole kit and caboodle. Now, if you have,
1101
01:19:48.685 --> 01:19:51.665
a well oiled, you know, multisig UX,
1102
01:19:52.270 --> 01:19:54.930
then if you're already trusting me for the recovery process,
1103
01:19:55.710 --> 01:19:57.330
I could have one of those keys.
1104
01:19:57.870 --> 01:20:08.974
She could, she could still call me in that situation. I could still walk her through the setup, but I can't spend it on my own. She can't spend it on her own. Maybe you involve some other third party in there so that I'm not trusted.
1105
01:20:09.610 --> 01:20:11.150
Right? So, like, all of a sudden,
1106
01:20:12.010 --> 01:20:13.950
that inheritance issue could
1107
01:20:14.570 --> 01:20:17.710
be mitigated to a degree and made more safer
1108
01:20:18.135 --> 01:20:29.500
1109
01:20:30.040 --> 01:20:31.100
you can find out
1110
01:20:31.800 --> 01:20:32.860
the the amount.
1111
01:20:33.215 --> 01:20:38.275
Right, and you don't wanna share that amount with friends or family, right, you want to be blinded
1112
01:20:38.575 --> 01:20:40.435
but you want them to be part of the recovery
1113
01:20:41.219 --> 01:20:55.475
setup later. I think that's where Taproot is gonna really shine later on once we have like a proper MOSIG spec and sort of because then you can you can lower the threshold of those keys and you can come up with much more clever ways
1114
01:20:56.630 --> 01:21:04.010
of blinding that that, those amounts to essentially the saving grace keys that are out there, the emergency keys.
1115
01:21:05.055 --> 01:21:05.875
Until then,
1116
01:21:06.175 --> 01:21:14.440
you know, every time you do multisig with a third party, you're essentially doxing your your coins to that third party, which is a much worse attack surface
1117
01:21:14.900 --> 01:21:17.640
than the security of the single sig, right? Because
1118
01:21:18.260 --> 01:21:21.880
say we're friends now or or say, for example, you're a non Bitcoiner,
1119
01:21:22.739 --> 01:21:25.724
you know, and let's say some bad guys assume
1120
01:21:26.105 --> 01:21:29.324
that you do have knowledge over other people's
1121
01:21:29.625 --> 01:21:37.769
money, you're now at risk and they could try to coerce you even though you don't have that to try to get that information on other Bitcoiners.
1122
01:21:38.150 --> 01:21:38.650
Right?
1123
01:21:39.005 --> 01:21:41.265
This this attack surface is terrible. Yeah.
1124
01:21:43.805 --> 01:21:46.705
1125
01:21:47.710 --> 01:21:49.170
1126
01:21:49.870 --> 01:21:57.145
just a bit of a counterpoint to the single sig pass pass passphrase argument. You know, getting back to
1127
01:21:57.525 --> 01:22:00.344
the support queries thing, I get a lot of support queries.
1128
01:22:00.804 --> 01:22:04.505
Well, when I say a lot, I mean there there's there's been a few people
1129
01:22:04.880 --> 01:22:06.820
who have forgotten their passphrase
1130
01:22:07.760 --> 01:22:14.264
and can no longer access their funds. And that's a really sad situation. You know? I mean, as we all know, people,
1131
01:22:14.965 --> 01:22:18.824
lose access to their funds far more often than they get stolen.
1132
01:22:19.684 --> 01:22:20.744
And, unfortunately,
1133
01:22:21.045 --> 01:22:23.400
past phrase phrase phrases are generally
1134
01:22:23.940 --> 01:22:26.600
considered something you need to keep in your your head.
1135
01:22:26.980 --> 01:22:40.415
And as we know, humans are really bad at keeping things in their head. So people, you know, forget them, and then you kind of have to say that, you know, they're they're just panicking and freaking out in the support chats, and and, you know, you just gotta say, just calm down,
1136
01:22:40.880 --> 01:22:47.219
Try the all the different options. Take your time, it's gonna take many hours, but you know, you'll eventually get the right one.
1137
01:22:48.165 --> 01:22:51.625
I gotta gotta say, I don't love passphrases for that reason.
1138
01:22:52.245 --> 01:22:57.225
I I really do find that they have a major UX challenge there.
1139
01:22:57.640 --> 01:23:00.460
1140
01:23:01.160 --> 01:23:04.940
especially sort of noobs with a lot of money is to
1141
01:23:05.800 --> 01:23:06.300
pick,
1142
01:23:07.145 --> 01:23:08.525
essentially 12 words,
1143
01:23:09.625 --> 01:23:11.005
out of the BIP 39,
1144
01:23:11.865 --> 01:23:12.365
namespace,
1145
01:23:13.865 --> 01:23:14.365
and
1146
01:23:14.699 --> 01:23:24.625
back use those as the passphrase and bake those into a metal plate as well. So you put one metal plate to the seed somewhere, and then you put the passphrase seed plates elsewhere.
1147
01:23:25.085 --> 01:23:26.545
Right? So now
1148
01:23:27.485 --> 01:23:28.385
you diminish
1149
01:23:29.220 --> 01:23:34.040
the risk of 1, you don't have to remember anymore, right, except for operation,
1150
01:23:35.140 --> 01:23:35.960
but also,
1151
01:23:37.235 --> 01:23:40.135
you know, you don't have a challenge with people having complex passphrases
1152
01:23:40.435 --> 01:23:42.135
using, you know, like
1153
01:23:42.755 --> 01:23:43.415
a larger
1154
01:23:44.239 --> 01:23:48.099
character set that could also be not supported by a different hardware,
1155
01:23:48.960 --> 01:23:53.675
and and they do have a nice backup for that. Hey, Rodolfo. I I agree with that strategy,
1156
01:23:54.455 --> 01:24:09.494
1157
01:24:09.954 --> 01:24:12.534
it's really hard to enter that many characters
1158
01:24:13.315 --> 01:24:19.880
on a hardware wallet, so people just aren't gonna do that because the UI and hardware wallets is just painful to enter
1159
01:24:20.260 --> 01:24:22.280
a large number of characters for a passphrase.
1160
01:24:23.300 --> 01:24:25.000
1161
01:24:25.785 --> 01:24:27.885
You know, I'm of 2 minds on that.
1162
01:24:28.265 --> 01:24:28.925
One is
1163
01:24:29.385 --> 01:24:35.780
that's a good thing and the real money should not be easily accessible, should not be fastly typable.
1164
01:24:36.239 --> 01:24:38.900
You know, like for money you need to actually transfer,
1165
01:24:39.280 --> 01:24:42.585
like all the time, then just use a phone wallet, use something else, use,
1166
01:24:43.204 --> 01:24:44.344
you know, non passphrase,
1167
01:24:45.045 --> 01:24:58.640
wallet, hardware wallet, whatever. Like, there's a million ways for you to do that. But then for the the real money, you want to be in a position where not even you can transfer that money in less than, you know, like, 10, 15 minutes typing.
1168
01:24:59.245 --> 01:25:05.265
1169
01:25:05.725 --> 01:25:18.505
they don't touch their savings for, you know, a certain amount of time. We go through a bear cycle, then it's like 5 years later and they're not comfortable at all of using their using their funds. Maybe the funds are up 10 x, 20 x at that point,
1170
01:25:18.965 --> 01:25:26.690
and they have no idea what they're doing. Like, they just like, there there needs to be some level of familiarity there. And, obviously, it gets solved
1171
01:25:27.150 --> 01:25:41.489
if you have a separate wallet that is easier to access. It's not your savings wallet, and you're using and spending Bitcoin all the time or you're getting comfortable with it, but most people don't. And I do feel like there's a bit of a disconnect. I think Ledger does a pretty good job with this, but there's a bit of a disconnect
1172
01:25:42.270 --> 01:25:43.889
between pragmatic options,
1173
01:25:44.750 --> 01:26:00.520
versus overly secure options. I think SeedXor is a good example of a pragmatic option that you've implemented on cold card. But for just for an easy example here, you know, when it comes to really close friends, when it comes to people I went to high school with or college with that are that are not,
1174
01:26:00.820 --> 01:26:19.900
you know, very proficient with using Bitcoin, but they've heard me just harp about it all the time, so they end up doing it. There's been so many situations where I just have their full seed in front of me, you know, where they just put it in front of my face because they won't recover their funds unless I have that that thing. Like, I, like, I can completely own them,
1175
01:26:20.475 --> 01:26:24.655
And and there are probably little pragmatic things we can do to prevent
1176
01:26:25.275 --> 01:26:30.040
that from being the end result. Right? From that being end result in reality.
1177
01:26:30.660 --> 01:26:37.320
1178
01:26:37.685 --> 01:26:45.465
I think we have plenty of people who just lose the access to defense because they, they set up a too complex
1179
01:26:46.600 --> 01:26:53.020
methodology. Either that was something with with, with multisig. Either they they lost their passphrase.
1180
01:26:53.595 --> 01:26:55.695
And, again, you you don't really
1181
01:26:56.395 --> 01:27:03.970
you don't really improve security if you if at the end, you lose your fence because, because your your setup is not is not usable
1182
01:27:04.510 --> 01:27:05.489
anymore. So
1183
01:27:05.870 --> 01:27:11.730
I remember a couple of years ago, there there was some debate on, Twitter with
1184
01:27:12.365 --> 01:27:13.265
Michael Flaxman,
1185
01:27:13.725 --> 01:27:19.245
for for instance, like, that hardware was not were not secure enough, and you you had to,
1186
01:27:20.280 --> 01:27:27.260
to use a multisix setup and so on. I think we are we there are plenty of people who just lost money because they've listened in.
1187
01:27:28.245 --> 01:27:32.825
Yeah. I think this is this is a mistake. We we we need to have, like, a simple setup.
1188
01:27:33.365 --> 01:27:35.385
After that, it depends if you are
1189
01:27:35.840 --> 01:27:46.395
a financial institution and so on and you need governance and so on, then it's different. Then you need some some some rules. Using a multisig can make sense. And,
1190
01:27:46.835 --> 01:27:48.054
and and, by the way,
1191
01:27:48.675 --> 01:27:54.900
there's are some steps which are often requested to to us. But again, there are very few people,
1192
01:27:55.220 --> 01:28:06.595
who who use them. We we are working in, in implementing a mini script, by the way. We will release it in a couple of months. I think it's, it it will be ready in on October.
1193
01:28:07.055 --> 01:28:09.670
So if you want to implement some, like,
1194
01:28:10.230 --> 01:28:11.290
enhanced governance,
1195
01:28:11.910 --> 01:28:15.449
this is the tool you need. But for, like, 99%
1196
01:28:16.070 --> 01:28:19.505
of the users, don't choose MiniScript, don't choose, Multisig.
1197
01:28:20.045 --> 01:28:21.105
And even passphrase,
1198
01:28:22.605 --> 01:28:28.150
think about that. If you lose your passphrase, you lose your friends for forever. So you have to,
1199
01:28:28.770 --> 01:28:30.610
to think about your threat model,
1200
01:28:30.930 --> 01:28:41.095
but also to think about what happens if you lose your, passphrase. So this is a there's a there's a lot of stuff, to to be, to be taken into into consideration.
1201
01:28:41.955 --> 01:28:42.935
1202
01:28:43.475 --> 01:28:48.760
one of one of the biggest issues I have with the with the conversations about wallet,
1203
01:28:49.139 --> 01:28:53.159
on Twitter and and some of the other sort of, like, chat systems where Bitcoiners
1204
01:28:53.460 --> 01:28:55.719
sort of, like, bitch and
1205
01:28:56.055 --> 01:28:59.355
and also cheer for things that they like personally,
1206
01:29:00.295 --> 01:29:02.315
is that there's this sort of, like,
1207
01:29:03.020 --> 01:29:03.760
all or
1208
01:29:04.099 --> 01:29:04.599
nothing,
1209
01:29:05.020 --> 01:29:06.480
sort of like view
1210
01:29:07.020 --> 01:29:07.520
of
1211
01:29:07.900 --> 01:29:08.400
of
1212
01:29:08.780 --> 01:29:12.719
of of security. Right? And and a lot of times, most of the people giving
1213
01:29:13.025 --> 01:29:16.485
opinions on these things are not people who are
1214
01:29:16.945 --> 01:29:19.445
capable of giving an opinion about these things.
1215
01:29:19.985 --> 01:29:27.909
And you know they're very sort of like a strong opinion about security where they don't fully understand what's going on under the hood.
1216
01:29:28.530 --> 01:29:29.030
And
1217
01:29:29.645 --> 01:29:36.865
you know, I I really think that as as an industry, like, one of the best one of the best things we can do
1218
01:29:37.245 --> 01:29:37.745
is
1219
01:29:38.890 --> 01:29:41.390
push people to have more than one setup.
1220
01:29:41.890 --> 01:29:42.390
You
1221
01:29:42.890 --> 01:29:57.210
know, like, is for them to have a spending wallet on their phone, a very easy moon wallet or something like that. Right? And then have a middle ground place where, you know, they have their sort of like more money but not all the money.
1222
01:29:57.510 --> 01:30:01.370
Where maybe maybe is a passphrase wallet, maybe is not.
1223
01:30:01.965 --> 01:30:06.865
And then they have their deep cold stuff where it's like really is the money under the mattress. Right?
1224
01:30:07.565 --> 01:30:09.585
Where where they do have a different
1225
01:30:11.360 --> 01:30:12.020
a different
1226
01:30:13.120 --> 01:30:18.100
they need to have a different view on this as as, like, don't don't put all your eggs in one basket
1227
01:30:18.720 --> 01:30:20.260
and and and don't
1228
01:30:21.135 --> 01:30:25.715
don't listen to people who tell you to put all your eggs in one basket either. Right?
1229
01:30:26.094 --> 01:30:28.275
And and also don't listen to overly,
1230
01:30:28.655 --> 01:30:29.475
like, expert
1231
01:30:31.659 --> 01:30:32.560
opinion. Right? Because,
1232
01:30:33.420 --> 01:30:44.165
you know, like, I absolutely love the questions that that Flaxman open up. Like, it was actually a lot of advancements that happened in Multisig because of the questions that he did open up.
1233
01:30:44.730 --> 01:30:47.710
But the problem is Flaxman is a wallet developer.
1234
01:30:48.570 --> 01:30:49.070
Like,
1235
01:30:49.530 --> 01:30:54.110
you know, if he screws up his system, he can go and code his own wallet
1236
01:30:54.445 --> 01:30:56.545
to redeem those coins, right?
1237
01:30:56.845 --> 01:30:58.545
That's true. And the challenge is
1238
01:30:58.845 --> 01:31:03.025
with his design choices, like the average person would be completely screwed.
1239
01:31:04.270 --> 01:31:06.930
And we had conversations about this publicly too
1240
01:31:09.310 --> 01:31:16.845
and I find it's like you as an expert is very easy for you to see all the flaws and everything, but you're not necessarily measuring,
1241
01:31:17.945 --> 01:31:25.790
what are the chances of stuff happening for 1, and and 2 is how people are gonna screw themselves up because you wouldn't screw yourself up. Right?
1242
01:31:26.250 --> 01:31:28.670
So so that's sort of like just how I view that
1243
01:31:29.265 --> 01:31:31.844
that that specific time in Bitcoin space,
1244
01:31:32.945 --> 01:31:38.880
when, when multisig was sort of like coming forefront because of the was a 10 x improvement security paper that,
1245
01:31:39.180 --> 01:31:40.239
Flexman wrote.
1246
01:31:41.500 --> 01:31:45.520
1247
01:31:46.224 --> 01:31:54.724
where the layperson it looks so easy and simple. I'll just you know, where the the opposite is with multisig, but yeah. So people just I know this is one of the topics, and I
1248
01:31:55.490 --> 01:31:59.990
1249
01:32:00.850 --> 01:32:12.170
1250
01:32:12.810 --> 01:32:21.790
I I just and they're like, well, how could this possibly be hacked? Like, one guy just asked me that recently. It's like, please explain this to me. I just don't understand, and I I almost don't even know where to start. I'm like,
1251
01:32:22.305 --> 01:32:24.085
you clicked download Ubuntu,
1252
01:32:24.865 --> 01:32:26.405
right? But there was
1253
01:32:27.025 --> 01:32:27.525
3,000
1254
01:32:28.065 --> 01:32:29.845
other things developed downloaded
1255
01:32:30.305 --> 01:32:30.805
from
1256
01:32:31.480 --> 01:32:44.375
from repositories that other people were maintaining and developing. I mean, it's just there's so much happening and people just don't appreciate it. I mean, you know, computers were designed for you to answer email and go watch porn.
1257
01:32:44.915 --> 01:32:56.485
1258
01:32:56.965 --> 01:32:58.985
And that's not even getting to the hardware.
1259
01:32:59.764 --> 01:33:03.864
Right? Like so so let's say you use Tinfoil OS.
1260
01:33:04.389 --> 01:33:04.889
Right?
1261
01:33:05.349 --> 01:33:07.130
Like and and Tinfoilos
1262
01:33:07.829 --> 01:33:08.570
was like,
1263
01:33:08.949 --> 01:33:11.475
you know, reviewed line by line by Max,
1264
01:33:12.743 --> 01:33:18.855
by, g Max. Right? Like, you have a team reviewing line by line of every single
1265
01:33:19.720 --> 01:33:21.820
thing that the computer does. However,
1266
01:33:22.200 --> 01:33:24.860
now you have another problem which is the hardware.
1267
01:33:25.320 --> 01:33:28.620
Every single little subsystem in that computer has closed
1268
01:33:28.955 --> 01:33:33.455
source hardware stuff running on it, and it's all remote upgradable.
1269
01:33:33.915 --> 01:33:46.170
1270
01:33:46.470 --> 01:33:46.970
Well,
1271
01:33:47.645 --> 01:33:54.784
in a PC there's 50 of those chips in the PC, all of which can be faulted in the same way, if not easier
1272
01:33:55.420 --> 01:33:59.600
than than the Trezor, we'll click on Trezor, but the STM 32 just generically.
1273
01:33:59.980 --> 01:34:04.480
I mean, people just, you know, because all the chips are wrapped up in this box,
1274
01:34:04.835 --> 01:34:08.215
they don't realize how much is going on inside that box.
1275
01:34:08.995 --> 01:34:12.195
1276
01:34:12.630 --> 01:34:21.594
secure than, your gapped computer. There was there was no debate about that. Like, the attack surface of a computer, even if it's a gapped, is wide. Like,
1277
01:34:21.895 --> 01:34:24.555
you you have to to think about that. It's a Swiss cheese.
1278
01:34:25.495 --> 01:34:29.880
Yeah. Definitely. Definitely. And, if you want to to take an example, like,
1279
01:34:30.840 --> 01:34:32.940
Al Iranian sent refuge, like,
1280
01:34:34.360 --> 01:34:35.659
15 years ago, I think.
1281
01:34:36.040 --> 01:34:38.655
They were they were completely gapped in,
1282
01:34:39.095 --> 01:34:39.595
secure,
1283
01:34:40.775 --> 01:34:44.075
premises and so on. And then the American with,
1284
01:34:44.465 --> 01:34:44.965
Israeli
1285
01:34:46.350 --> 01:34:46.850
secure,
1286
01:34:47.310 --> 01:34:50.850
secure services, they developed TextNet and TextNet
1287
01:34:51.230 --> 01:34:51.730
broke
1288
01:34:52.110 --> 01:34:52.850
the Iranian
1289
01:34:53.150 --> 01:34:53.650
centrifuge
1290
01:34:54.304 --> 01:35:03.205
even if they they were a air gapped. I I just want to say that there was no magic, with, with air gapped thing. So, yeah, Stuxnet was this thing.
1291
01:35:03.540 --> 01:35:06.840
1292
01:35:07.620 --> 01:35:10.920
we are not seeing more software wallets getting hacked
1293
01:35:11.235 --> 01:35:13.735
and people's funds getting taken. Because, presumably,
1294
01:35:14.275 --> 01:35:24.520
you know, it should be happening every day. Right? We should be hearing about this every day. People should be jumping on Twitter saying, I lost all my funds. I don't know what's going on. And then someone says, oh, you have a virus.
1295
01:35:25.060 --> 01:35:52.645
1296
01:35:53.185 --> 01:35:56.165
a matter of opportunity cost cost of
1297
01:35:56.465 --> 01:35:56.965
very,
1298
01:35:57.345 --> 01:35:59.030
like, advanced attack
1299
01:35:59.410 --> 01:35:59.910
versus,
1300
01:36:00.610 --> 01:36:06.950
1301
01:36:07.515 --> 01:36:09.535
install base size problem too. Right?
1302
01:36:10.395 --> 01:36:20.440
So the amount of people putting their seeds in a computer is tiny. Right? Majority of people who do who do use their own self custody solution do use hardware wallets,
1303
01:36:20.820 --> 01:36:24.815
but the great, great, great majority of users have their coins on Coinbase.
1304
01:36:25.435 --> 01:36:26.495
Like so,
1305
01:36:27.755 --> 01:36:28.655
you know, like,
1306
01:36:29.035 --> 01:36:30.335
you just don't have
1307
01:36:31.390 --> 01:36:35.090
a lot of people doing these stupid solutions that get sort of, like,
1308
01:36:35.630 --> 01:36:36.130
recommended
1309
01:36:36.670 --> 01:36:37.490
on on
1310
01:36:38.365 --> 01:36:39.105
on Twitter,
1311
01:36:40.125 --> 01:36:43.745
for for people to do the air gaps sorry, the the air gap laptop.
1312
01:36:45.005 --> 01:36:50.690
Sorry. One more thing is is the same for the Raspberry Pi based hardware wallets. It's like it's idiotic,
1313
01:36:51.469 --> 01:36:53.969
that that, like, you cannot protect that OS.
1314
01:36:55.135 --> 01:36:57.155
So you cannot protect that firmware,
1315
01:36:58.094 --> 01:37:01.235
and and, you know, you may not see attacks
1316
01:37:01.909 --> 01:37:07.690
while this this install base is tiny, but as it grows, you will, and people won't know what happened.
1317
01:37:08.230 --> 01:37:11.575
And most of them may not be even on Twitter, so they won't go complain there.
1318
01:37:12.455 --> 01:37:20.075
1319
01:37:20.520 --> 01:37:23.100
the single biggest advantage that a dedicated
1320
01:37:23.960 --> 01:37:27.179
hardware wallet or hardware signer does is
1321
01:37:27.480 --> 01:37:30.139
I'm able to tell them when they get into it,
1322
01:37:30.505 --> 01:37:36.205
that they should only enter their secret backup words. That's what I call the seed to them into the device,
1323
01:37:36.585 --> 01:37:46.080
that one single piece of advice. And that one part of the UX flow that you you enter it directly into the device rather than entering into your phone or into an email or to a computer
1324
01:37:46.780 --> 01:37:48.480
saves a shit ton of people.
1325
01:37:49.065 --> 01:37:53.005
1326
01:37:53.305 --> 01:37:56.925
forces users to have good hygiene and including advanced users.
1327
01:37:57.430 --> 01:37:58.170
Right? Because
1328
01:37:58.470 --> 01:38:11.355
you can be the most advanced person, but when you're dealing with your accounting and dealing with your, like, other stuff of your business, you might have your programmer brain turn off and make a mistake as well. Right?
1329
01:38:12.110 --> 01:38:14.770
It is surprisingly easy to make a mistake with this stuff.
1330
01:38:15.630 --> 01:38:18.290
1331
01:38:18.805 --> 01:38:27.145
a large scale attack that we we that we saw a little bit in the past. Some people are just taking pictures of this of their seed and with their phone.
1332
01:38:27.460 --> 01:38:29.240
And, yeah, it's, unfortunately,
1333
01:38:29.700 --> 01:38:34.120
this happens. Yeah. This happens a lot. And in the past, there were some
1334
01:38:34.784 --> 01:38:35.304
some random,
1335
01:38:35.744 --> 01:38:37.684
application on Android, which,
1336
01:38:38.224 --> 01:38:39.025
just request,
1337
01:38:39.425 --> 01:38:45.190
the right to access to to your your photos, and that's it. They scan them. And as soon as they they they,
1338
01:38:46.210 --> 01:38:50.790
they find seed, they just send them to the other cars. So this happens every day, Craig.
1339
01:38:52.795 --> 01:38:56.655
1340
01:38:57.035 --> 01:39:02.090
preloading hardware wallets on Amazon with a seed? Remember they were ledgers and Trezors. Right?
1341
01:39:03.130 --> 01:39:08.190
You know, you guys have a bigger install base, so they were just putting them for sale on Amazon for cheap.
1342
01:39:08.515 --> 01:39:11.655
First was eBay, but then it was Amazon for cheap repackaged,
1343
01:39:12.355 --> 01:39:14.775
and users just don't know. I mean, even
1344
01:39:15.235 --> 01:39:20.850
even us going through the extent that we go with the security, I mean, the the user is still sort of like the biggest,
1345
01:39:21.230 --> 01:39:22.210
security hole.
1346
01:39:22.990 --> 01:39:27.935
1347
01:39:28.395 --> 01:39:30.655
a scratching card, like, with a prefilled,
1348
01:39:32.155 --> 01:39:37.460
seed, and you don't know what to expect. And you think it's normal, and then you just load your Bitcoin on it and that's
1349
01:39:37.840 --> 01:39:41.060
1350
01:39:42.800 --> 01:39:50.315
You know, one thing that I love about the air gap stuff is that it sort of essentially saves you from unknown unknown. Right? Like, we were talking about,
1351
01:39:50.934 --> 01:39:54.155
we just don't know if the device has a bug that's exploitable
1352
01:39:55.000 --> 01:39:55.500
or,
1353
01:39:55.880 --> 01:40:02.860
you know, or the the manufacturer is malicious or something has a backdoor on it. And if you're not connected, you remove the synchrony,
1354
01:40:03.320 --> 01:40:07.724
synchronous of the attack capacity. Right? So the attacker would have a much,
1355
01:40:08.185 --> 01:40:11.465
harder time to to remotely access it. And,
1356
01:40:12.025 --> 01:40:13.724
you know, USB is a shitcoin.
1357
01:40:14.330 --> 01:40:14.830
But,
1358
01:40:15.210 --> 01:40:15.710
yeah.
1359
01:40:16.090 --> 01:40:18.570
Sorry. So so Charles needs to step out,
1360
01:40:19.450 --> 01:40:24.645
in was it 10 minutes or so? If you guys wanna keep on going, there is other things for us to talk about,
1361
01:40:25.025 --> 01:40:27.045
but, you know, it's all up to you guys.
1362
01:40:27.585 --> 01:40:33.830
1363
01:40:34.130 --> 01:40:34.610
I do have a
1364
01:40:35.330 --> 01:40:43.715
Go for it. Some thoughts on SD card and versus USB connection, which I think is sort of interesting. I'll give you sort of my you've heard this before Rodolfo, but,
1365
01:40:44.275 --> 01:40:49.095
the benefit of the cold card, right, is you can do USB less. Right? You can just do
1366
01:40:49.460 --> 01:40:51.880
SD cards to physically transport
1367
01:40:52.660 --> 01:40:53.160
the
1368
01:40:53.540 --> 01:40:54.200
the PSPTs
1369
01:40:54.740 --> 01:40:56.440
across the air gap. Right?
1370
01:40:56.855 --> 01:41:06.680
But and then you mentioned this, you know, the attacker's synchronicity. Right? He he can't he maybe can modify the PSBT and but it's physically transported over that barrier
1371
01:41:07.140 --> 01:41:08.280
by a human.
1372
01:41:08.580 --> 01:41:13.239
Now, I I do have one thing there that I brought up before is SD cards
1373
01:41:13.545 --> 01:41:14.364
aren't just
1374
01:41:14.744 --> 01:41:17.324
physical media, they are actually microcontrollers.
1375
01:41:18.184 --> 01:41:19.244
So the hacker
1376
01:41:20.184 --> 01:41:24.230
can actually insert software on the SD card and when you plug the software
1377
01:41:24.690 --> 01:41:27.430
when you plug that SD card into the cold card,
1378
01:41:27.890 --> 01:41:32.685
it can do stuff, Right? It could do things like you could maybe drop a file on it on the computer,
1379
01:41:33.225 --> 01:41:41.960
but when it gets plugged into the cold card, it shows the cold card different files. Now, obviously, the user can, you know, verify addresses and catch it there,
1380
01:41:42.420 --> 01:41:56.000
but there's other things it could do. It could try to exploit protocol errors in the SD card interface with the thing. Right? So there's the attacker has a small microcontroller that he can attack with. Yeah. No. I I completely agree with you there.
1381
01:41:56.460 --> 01:41:57.440
1382
01:41:57.820 --> 01:42:03.245
because, like, essentially, like, nothing is fail proof given enough resources, enough time. Right? That's that's
1383
01:42:12.125 --> 01:42:13.230
code card reads a drive.
1384
01:42:13.790 --> 01:42:16.610
Right? Like, the way Coldcard is looking at that micro SD,
1385
01:42:16.989 --> 01:42:18.610
it is a substantially
1386
01:42:19.230 --> 01:42:19.730
smaller,
1387
01:42:20.645 --> 01:42:25.945
surface and purpose. Right? So we can audit that, we can look at that, and try to find
1388
01:42:26.805 --> 01:42:30.179
paths in which, you know, attacker could try to exploit that.
1389
01:42:30.880 --> 01:42:34.179
The amount of people out there that can insert, you know,
1390
01:42:34.480 --> 01:42:39.735
malicious firmware on a micro SD is much smaller than the people who can do malicious things with USB.
1391
01:42:40.355 --> 01:42:43.655
Right? I mean, USB is an absolute clusterfuck.
1392
01:42:44.550 --> 01:42:46.410
It's huge attack surface.
1393
01:42:47.190 --> 01:42:52.890
What's nice about what Ledger does is that Ledger is using a secure element that is designed
1394
01:42:53.275 --> 01:43:02.310
to handle things in a very narrow way too. Right? You guys are probably using CBOR or something like that to talk back. So the thing is, you but you're still connected,
1395
01:43:02.690 --> 01:43:03.670
and that connection
1396
01:43:04.050 --> 01:43:07.190
matters because if you are trying to do a remote attack,
1397
01:43:08.775 --> 01:43:18.940
you want feedback. Right? Like, is this working? Try this other thing. Is this working? Try this other thing. Oh, did you get something? Oh, you need to go there to get it now. You need this other bug to happen in order to extract. Right?
1398
01:43:19.320 --> 01:43:24.620
So there is this very long list of things you're gonna probably need to do to pen test it. Now
1399
01:43:25.215 --> 01:43:26.034
if you're not
1400
01:43:26.574 --> 01:43:38.130
USB, technically, you could have the software trying to do that, and and then there is the bugs. Right? You could have a bug that has a hole on it, and then boom, gone. Yeah. I I'm really curious to hear Charles' thoughts on this before he goes because so I'm really interested.
1401
01:43:38.829 --> 01:43:40.050
1402
01:43:40.645 --> 01:43:47.385
When when when you have to sign a transaction, at some point, you need to communicate with the blockchain. There was, there was nothing like
1403
01:43:47.929 --> 01:43:51.630
those worlds are completely separated. You need to bring some data
1404
01:43:52.090 --> 01:43:52.590
from,
1405
01:43:53.050 --> 01:43:54.350
like, the blockchain
1406
01:43:54.865 --> 01:44:02.405
to your signer, sign it, and then bring back this sign paid up to the blockchain. So when we say a gap or something,
1407
01:44:02.790 --> 01:44:12.570
this is just a matter of channel. What what does your your channel look like? Is it complete? Is it SD card? Is it USB? And then we can discuss. Then
1408
01:44:13.095 --> 01:44:13.835
this is about,
1409
01:44:14.695 --> 01:44:15.755
like attack surface.
1410
01:44:16.295 --> 01:44:20.955
So your thesis is to say, like, the SD card attack surface is
1411
01:44:21.700 --> 01:44:22.200
simpler
1412
01:44:22.580 --> 01:44:23.239
than USB.
1413
01:44:24.180 --> 01:44:25.140
It can be debated.
1414
01:44:25.860 --> 01:44:26.680
I don't know.
1415
01:44:27.700 --> 01:44:29.320
USB is large
1416
01:44:29.804 --> 01:44:30.304
standard.
1417
01:44:30.844 --> 01:44:35.824
You you agree I agree with you, Enrique. This is large standard and if you try to implement
1418
01:44:36.580 --> 01:44:37.960
the the standard overall,
1419
01:44:38.420 --> 01:44:40.679
there is some area to
1420
01:44:41.219 --> 01:44:47.295
to to do mistakes. So what we do is to implement a very small subset of this tunnel.
1421
01:44:47.675 --> 01:44:48.175
And
1422
01:44:48.795 --> 01:44:52.255
when we implement USB, it's implemented on another
1423
01:44:52.760 --> 01:44:54.940
microchip. It's not implemented in,
1424
01:44:55.480 --> 01:44:59.535
the secure element so that you have, like, another layer of
1425
01:45:00.495 --> 01:45:00.995
of
1426
01:45:02.575 --> 01:45:10.380
another layer to to to to do this this communication. And the attack surface of the secure element itself is,
1427
01:45:10.920 --> 01:45:11.840
is less,
1428
01:45:12.160 --> 01:45:13.620
is is is not bigger
1429
01:45:14.000 --> 01:45:15.460
because of because of USB.
1430
01:45:15.760 --> 01:45:22.065
But, Adrian, what what I want to say, there was no perfect solution. There there's plenty of trade off. And
1431
01:45:22.765 --> 01:45:23.665
when you choose
1432
01:45:24.125 --> 01:45:25.025
SD cards
1433
01:45:25.640 --> 01:45:26.620
versus USB,
1434
01:45:27.320 --> 01:45:30.220
you in terms of UX, it's clearly,
1435
01:45:31.080 --> 01:45:37.775
less for less convenient and it's it's yeah. The the UX is is, is better with with USB.
1436
01:45:38.955 --> 01:45:39.935
Does USB
1437
01:45:40.315 --> 01:45:41.275
have a lot larger,
1438
01:45:41.595 --> 01:45:42.095
larger
1439
01:45:42.520 --> 01:45:47.400
surface? Maybe. Maybe you're you're correct with that. But I think the trade off is,
1440
01:45:48.120 --> 01:45:51.945
is better in terms of UX, and this is, this is the one we, we choose.
1441
01:45:52.344 --> 01:45:52.844
But,
1442
01:45:53.224 --> 01:46:00.364
yeah, I I I will review. When when you implement USB, you have you have to be very careful. You have, you have to
1443
01:46:00.890 --> 01:46:01.390
limit,
1444
01:46:02.570 --> 01:46:07.150
what kind of USB standards you you you implement, and then you have to to
1445
01:46:07.505 --> 01:46:09.605
to do penetration testing, verify,
1446
01:46:10.145 --> 01:46:15.445
1447
01:46:15.745 --> 01:46:21.199
is that we no longer need to take arbitrary data in or arbitrary formats in
1448
01:46:21.739 --> 01:46:22.239
to,
1449
01:46:23.020 --> 01:46:29.475
to to operate with. Right? So you can be very, very picky about which data
1450
01:46:30.095 --> 01:46:40.389
bytes really you are you are picking in and you're letting in to sign. Right? It's not like we're, like, you know, executing stuff from my micro SD card too. Right?
1451
01:46:41.010 --> 01:46:43.510
So it's, you do reduce there.
1452
01:46:44.195 --> 01:46:45.715
But, you know, that reminds me,
1453
01:46:46.355 --> 01:46:48.934
way back then there was a a power differential
1454
01:46:49.235 --> 01:46:53.489
analysis attack on a Trezor and they were able to read the Trezor
1455
01:46:54.030 --> 01:46:57.090
calculating keys and able to leak out the keys.
1456
01:46:57.789 --> 01:46:59.170
So so, you know,
1457
01:46:59.550 --> 01:47:01.730
it just goes to show. Right? I mean, like,
1458
01:47:02.955 --> 01:47:07.215
the stakes are very high. Right? So, like, how you find the straight offs,
1459
01:47:07.915 --> 01:47:11.055
and how we derisk each solution really is
1460
01:47:13.470 --> 01:47:15.090
really is the challenge there
1461
01:47:15.550 --> 01:47:16.450
of of finding
1462
01:47:17.390 --> 01:47:18.370
a good security
1463
01:47:18.750 --> 01:47:20.610
sort of set for people.
1464
01:47:21.945 --> 01:47:22.445
Yeah.
1465
01:47:23.385 --> 01:47:32.659
1466
01:47:33.120 --> 01:47:38.385
the discussion in the in the next episode. Thank you. Thank you again. It was a pleasure. Appreciate you, Charles.
1467
01:47:38.784 --> 01:47:47.525
1468
01:47:48.860 --> 01:47:52.480
And then, if you if you if you guys are still game, we can keep on going.
1469
01:47:55.475 --> 01:47:56.615
1470
01:47:56.995 --> 01:48:01.255
1471
01:48:02.035 --> 01:48:02.535
1472
01:48:03.409 --> 01:48:20.114
Yeah. No. It's just like I I just love the fact that we can have, like, a bunch of, like, different people from the industry in a non contentious sort of environment to sort of, like, just talk shop, you know, and sort of discuss the challenges and things we have and sort of where we can go. I don't see a lot of that out there.
1473
01:48:21.620 --> 01:48:23.800
So, yeah, thanks for for being here.
1474
01:48:24.820 --> 01:48:26.120
Okay. So,
1475
01:48:26.660 --> 01:48:32.465
what do you guys wanna talk about next? Do you wanna talk about BIP standards and things like that, since since that's timely?
1476
01:48:33.805 --> 01:48:34.305
1477
01:48:35.005 --> 01:48:35.505
1478
01:48:36.125 --> 01:48:39.265
I guess, like, just generally speaking, the BIP process,
1479
01:48:40.050 --> 01:48:41.910
for people who are not academic
1480
01:48:42.210 --> 01:48:44.150
is is a challenge. Right? I mean,
1481
01:48:44.770 --> 01:48:48.230
people like us like to go our own way and build things,
1482
01:48:48.885 --> 01:48:52.025
and and sort of, like, have the least amount of input from others,
1483
01:48:53.365 --> 01:48:54.745
based on our design choices.
1484
01:48:55.500 --> 01:49:00.559
But standards are the magic that makes all the stuff work between each other. Right? And
1485
01:49:01.340 --> 01:49:11.795
and there is a good xkcd cartoon about, you know, the best standard is all is this next one that's gonna solve everything else, right? So standards are about compromises, and
1486
01:49:12.190 --> 01:49:13.710
right now we have one that,
1487
01:49:14.350 --> 01:49:14.850
Craig,
1488
01:49:16.110 --> 01:49:16.610
proposed.
1489
01:49:17.230 --> 01:49:21.650
So, Craig, do do you wanna talk about your your last, BIP proposal?
1490
01:49:22.495 --> 01:49:24.835
1491
01:49:25.215 --> 01:49:26.495
last one that I ever do.
1492
01:49:27.455 --> 01:49:31.870
I know you didn't mean it that way. No. It's it's, it's basically a,
1493
01:49:32.190 --> 01:49:32.690
format
1494
01:49:33.070 --> 01:49:36.050
for Warts to be able to export their labels.
1495
01:49:36.670 --> 01:49:40.074
So right now, as we were talking about earlier, we can export,
1496
01:49:40.614 --> 01:49:44.235
you know, the funds from a wallet just by using the seed seed words,
1497
01:49:44.775 --> 01:49:51.590
but we have no standard to be able to export labels from a wallet. And those labels can contain a lot of valuable information.
1498
01:49:52.050 --> 01:50:03.115
For example, you labeled your UTXOs to show where they've come from, and then that allows you when you spend them to determine whether you are linking UTXO's that may be giving away
1499
01:50:03.440 --> 01:50:11.300
more information that you would like to. So, you know, there's a lot of value to the labels, and currently, they're quite siloed within different different wallets.
1500
01:50:12.555 --> 01:50:18.895
So what I was trying to do here, and to be honest, I pulled off this task for about 6 months because I knew it wouldn't be much fun,
1501
01:50:19.870 --> 01:50:20.370
is
1502
01:50:20.750 --> 01:50:26.130
to, you know, come up with a a BIP that just really just sits sits down here as a format
1503
01:50:26.615 --> 01:50:32.075
to export the address labels, the transaction labels, and the input and output labels from a wallet.
1504
01:50:33.255 --> 01:50:36.670
Unfortunately, I think it's probably the one of the most bike shedable,
1505
01:50:38.330 --> 01:50:44.030
bips that you could ever write. You know, everyone has an opinion on something as basic as,
1506
01:50:45.055 --> 01:50:45.955
you know, exporting,
1507
01:50:47.295 --> 01:50:49.715
what is basically just a a map or
1508
01:50:50.175 --> 01:50:50.755
a dictionary
1509
01:50:51.135 --> 01:50:52.835
of of kind of the
1510
01:50:53.380 --> 01:50:53.960
transaction ID
1511
01:50:54.260 --> 01:50:56.360
to the label or whatever it is.
1512
01:50:57.540 --> 01:51:05.155
But what I was guided by when I was trying to do it was just the idea of trying to build something for users as opposed to building something for devs.
1513
01:51:06.015 --> 01:51:11.619
And that led me to and I I didn't actually get here at the start, but I it led me to
1514
01:51:12.000 --> 01:51:12.579
the CSV
1515
01:51:12.960 --> 01:51:15.940
format, which is, you know, in some ways not ideal,
1516
01:51:16.719 --> 01:51:17.940
because it is so,
1517
01:51:18.935 --> 01:51:29.960
you know, so long in use has been exposed to, you know, different ways of doing it over over time. But it's just some something that everyone can use. Right? Everyone knows how to fire up Excel,
1518
01:51:30.660 --> 01:51:39.015
and load a CSV in it, and that kind of gives everyone access to their labels outside of a wallet. So, you know, that's what I'm trying to do.
1519
01:51:39.635 --> 01:51:40.135
Hopefully,
1520
01:51:40.675 --> 01:51:44.295
you know, we managed to get a standard across the line which
1521
01:51:44.710 --> 01:51:46.010
retains that kind of,
1522
01:51:46.790 --> 01:51:47.770
user accessibility.
1523
01:51:49.510 --> 01:51:54.145
And that's, you know, that's also what I'm trying to do when I'm saying, let's if we
1524
01:51:54.525 --> 01:52:00.305
want to make these labels more secure, which obviously they should be because they contain a lot of private information
1525
01:52:00.685 --> 01:52:02.625
or is privacy sensitive information,
1526
01:52:03.740 --> 01:52:11.760
You know, let's use a zip file because we can encrypt that. Right? So it's, again, a tool that in some ways is not ideal
1527
01:52:12.335 --> 01:52:15.155
because zip files used to support relatively
1528
01:52:15.535 --> 01:52:16.035
insecure
1529
01:52:16.575 --> 01:52:20.835
encryption. But there's a way you can use them with strong encryption as well.
1530
01:52:21.290 --> 01:52:28.350
And if we can do that, then we can if if effectively give somebody a file which is in encrypted state at rest.
1531
01:52:29.364 --> 01:52:30.264
And that just
1532
01:52:30.565 --> 01:52:36.105
means that we don't, by default, have everyone exporting files which contains lots of privacy sensitive
1533
01:52:36.760 --> 01:52:41.820
information that's just sitting around in hard hard drives, which obviously we're trying to avoid.
1534
01:52:42.840 --> 01:52:49.445
So, you know, that was the kind of the design thinking that I had when I went into this. It was just trying to create some some something which
1535
01:52:49.824 --> 01:52:52.405
allowed people to get their labels
1536
01:52:52.730 --> 01:52:55.230
out of one application and into another,
1537
01:52:55.770 --> 01:53:15.480
and secondarily, to be able to edit those labels in an application outside of a wallet. So, you know, integrate them into maybe their personal accounting, if it's a business, whatever business process that they're in. And I was kind of guided here by some of the the kind of professional users that Sparrow has. You know, those guys want to
1538
01:53:15.940 --> 01:53:19.320
be able to, you know, manage and do their sort of work,
1539
01:53:19.855 --> 01:53:20.595
in applications
1540
01:53:20.975 --> 01:53:23.235
outside of the Sparrow Wallet. So
1541
01:53:23.535 --> 01:53:30.450
yeah. So that that was kind of my my thinking on it. Obviously, when you submit a sort of
1542
01:53:31.550 --> 01:53:37.915
a a a proposal like like that to a very developer focused list like Bitcoin Dev. You get a lot of views on
1543
01:53:38.375 --> 01:53:47.210
why CSV is bad, why zip files are bad, and all of those kind of things, which I don't. You know, they do have down downsides, and they are always a better tool for the job.
1544
01:53:47.510 --> 01:53:52.775
But that tool tends to be very niche. And that just means that, again, those users don't get
1545
01:53:53.655 --> 01:53:53.975
access,
1546
01:53:54.534 --> 01:54:00.315
outside of, you know, one wallet application to the other. So that's, yeah, that's kind of what I'm trying to do.
1547
01:54:00.870 --> 01:54:01.530
1548
01:54:02.469 --> 01:54:02.969
think,
1549
01:54:03.989 --> 01:54:07.449
I mean, like, Electrum has had this issue for millennia.
1550
01:54:07.805 --> 01:54:12.465
Right? I mean, there is a reason why, like, nobody used Core as the wallet after Electrum came out.
1551
01:54:13.405 --> 01:54:15.905
It it did have labels, exportable labels,
1552
01:54:16.380 --> 01:54:24.000
and and I think what you're trying to do is something that's extremely necessary even though it's technically so silly in a way.
1553
01:54:25.895 --> 01:54:27.755
You know, this is not like you're inventing,
1554
01:54:28.695 --> 01:54:35.035
like, some major thing that could cause some major problems for Bitcoin. Right? This is just a standard for labels.
1555
01:54:37.159 --> 01:54:37.659
And,
1556
01:54:38.440 --> 01:54:44.060
you you know, parsing CSVs is is very tricky. Right? That's why I think a lot of devs
1557
01:54:44.495 --> 01:54:47.635
have an issue on the list about, CSVs.
1558
01:54:48.574 --> 01:54:49.074
But,
1559
01:54:49.775 --> 01:54:51.635
you know, as you pointed out,
1560
01:54:52.440 --> 01:54:54.219
there really is no other
1561
01:54:55.160 --> 01:54:57.340
open format that is widely
1562
01:54:58.360 --> 01:54:58.860
importable
1563
01:54:59.239 --> 01:54:59.739
by
1564
01:55:00.155 --> 01:55:01.135
consumer software.
1565
01:55:01.435 --> 01:55:08.175
Right? I mean, you know, I do this monthly. I have to submit, like, I have to to put all the Bitcoin stuff
1566
01:55:08.820 --> 01:55:12.760
into the accounting software. Right? And the accounting software does
1567
01:55:13.300 --> 01:55:14.360
import CSV.
1568
01:55:14.739 --> 01:55:16.040
What it does not import
1569
01:55:16.485 --> 01:55:17.945
is JSON. Right?
1570
01:55:19.205 --> 01:55:26.105
So, you know, as much as JSON is sort of like a great machine readable format, it is not human readable. So
1571
01:55:26.940 --> 01:55:29.440
I I don't you saw maybe my reply there
1572
01:55:30.060 --> 01:55:32.160
which is, you know, I personally
1573
01:55:32.860 --> 01:55:35.520
have big doubts that most people will
1574
01:55:35.915 --> 01:55:36.415
go,
1575
01:55:36.795 --> 01:55:40.094
with the proposal as is just knowing the
1576
01:55:41.355 --> 01:55:43.375
the the cat herding that would be there.
1577
01:55:44.635 --> 01:55:45.135
So,
1578
01:55:45.640 --> 01:55:50.540
I mean, I think that having a format for import and export between wallets,
1579
01:55:51.160 --> 01:55:57.495
with JSON and then, you know, just having a spec that most people export the CSV as
1580
01:55:58.115 --> 01:56:02.135
might be a higher chance of getting a BIP going.
1581
01:56:03.350 --> 01:56:06.969
I think that the ZIP you brought up, it's true. 7Z
1582
01:56:07.350 --> 01:56:07.850
does
1583
01:56:09.805 --> 01:56:14.545
support strong encryption as well, and it is supported by most systems, so maybe that helps your proposal.
1584
01:56:15.165 --> 01:56:24.250
But, yes, I mean, you know, Zip, at least it's it's familiar to people, but I think most Zip clients do support 7 zed as well. Yeah. Yeah. It you'll be tricky.
1585
01:56:25.195 --> 01:56:33.295
1586
01:56:33.915 --> 01:56:34.560
for it.
1587
01:56:35.520 --> 01:56:39.940
And if you follow the RFC, which my proposal now mandates, then
1588
01:56:40.480 --> 01:56:46.395
I personally can't see how you're gonna end up in some kind of pausing hell. Like, you know, it's just,
1589
01:56:47.094 --> 01:56:48.395
that's not to say that,
1590
01:56:48.855 --> 01:56:55.410
you know, clients who implement the BIP will follow the BIP. They might, you know, do some something wrong. But at least,
1591
01:56:55.790 --> 01:56:58.210
you know, if you follow the BIP and you implement
1592
01:56:58.670 --> 01:56:59.250
the definition,
1593
01:57:00.270 --> 01:57:00.510
which,
1594
01:57:01.505 --> 01:57:10.645
as far as I can tell, is also what what is supported and implemented in Excel, in Numbers, in LibreOffice, Calc, you know, all of the sort of
1595
01:57:11.010 --> 01:57:19.030
platforms, they all kind of follow this RFC as well. Then I think CSV is actually fine. I don't actually think it is the issue that I thought it was,
1596
01:57:19.410 --> 01:57:22.025
when I first posted this to Bitcoin
1597
01:57:22.565 --> 01:57:24.244
Dev. So I'm kind of,
1598
01:57:25.204 --> 01:57:29.704
I'm kind of hoping that it's enough to get over the bar because I think losing
1599
01:57:30.100 --> 01:57:35.320
the ability to export and see a CSV and we just go back to sort of a JSON, which would be easy,
1600
01:57:36.180 --> 01:57:37.400
really just deprives
1601
01:57:37.985 --> 01:57:40.645
users who don't really have much of a voice in this,
1602
01:57:41.344 --> 01:57:44.725
to you know, from being able to sort of access the labels.
1603
01:57:45.105 --> 01:57:53.110
You know, then they have to rely on, hopefully, the wallet building some kind of a CSV export in addition, which which obviously is not ideal.
1604
01:57:53.490 --> 01:57:57.235
So, yeah, so I'm kind of hoping that CSV is actually okay.
1605
01:57:57.535 --> 01:58:01.475
But, you know, one of the things that I'm not sure of, this being my first BIP
1606
01:58:02.015 --> 01:58:09.969
sort of process is, you know, how do you know that you're you're good? Right? How do you know that people have kind of
1607
01:58:10.349 --> 01:58:11.650
gotten over the line?
1608
01:58:12.295 --> 01:58:13.435
I'm not actually sure.
1609
01:58:14.614 --> 01:58:26.330
1610
01:58:26.790 --> 01:58:28.730
that CSV is okay for that.
1611
01:58:29.445 --> 01:58:34.105
Just knowing like, being experienced experiencing this crowd a little bit.
1612
01:58:35.925 --> 01:58:38.870
And I think a lot of them will have a problem with the actual
1613
01:58:40.310 --> 01:58:45.370
FC. You know, it it just might be like a a path of high resistance that may not be overcome.
1614
01:58:45.750 --> 01:58:48.090
But just generally speaking about BIPs,
1615
01:58:49.114 --> 01:58:51.455
there is no formal formal process,
1616
01:58:52.074 --> 01:58:54.015
but it seems that the tradition
1617
01:58:54.475 --> 01:58:57.455
is to, you know, you propose your bIP on the mailing list.
1618
01:58:58.619 --> 01:58:59.579
You know, let's say,
1619
01:59:01.020 --> 01:59:03.520
let's say, you know, it's not super contentious
1620
01:59:04.300 --> 01:59:09.655
or it is say say it's mid to low contention, right, which I think it's where you are at maybe.
1621
01:59:11.235 --> 01:59:13.415
You know, maybe then what you do is
1622
01:59:14.114 --> 01:59:16.695
you go and you submit the BIP
1623
01:59:17.700 --> 01:59:19.320
to the actual BIP repo,
1624
01:59:19.700 --> 01:59:20.200
right,
1625
01:59:20.660 --> 01:59:23.000
asking for to be assigned a BIP number.
1626
01:59:23.995 --> 01:59:28.975
That's normally where the people who are more high stakes in the game start to have an opinion,
1627
01:59:30.315 --> 01:59:32.735
for things that are not too contagious outside,
1628
01:59:34.370 --> 01:59:35.590
and and these are people
1629
01:59:36.050 --> 01:59:38.630
who often actually care about the code
1630
01:59:39.330 --> 01:59:44.655
and and be a little bit more skin in the game as opposed to just people replying on the mailing list.
1631
01:59:45.435 --> 01:59:47.935
The mailing list sometimes can just get in the way,
1632
01:59:48.300 --> 01:59:53.360
and and there is no, like, written requirement that it has to go through the mailing list to then have
1633
01:59:53.820 --> 01:59:57.565
a a number assigned or or wait for a number,
1634
01:59:58.185 --> 02:00:02.205
to be assigned on the BIP thing. Right? Remember, Bitcoin, we don't ask for permission.
1635
02:00:02.745 --> 02:00:03.245
Now
1636
02:00:04.080 --> 02:00:05.780
when you're trying to create a standard
1637
02:00:06.480 --> 02:00:07.860
from the social perspective
1638
02:00:08.240 --> 02:00:13.485
is you want to have buy in. Right? Because you can create an amazing standard,
1639
02:00:14.025 --> 02:00:19.650
get a BIP assigned to it, and nobody ever uses it or adopts it. Right? I mean, PSBT
1640
02:00:20.190 --> 02:00:21.170
bit point 74
1641
02:00:21.869 --> 02:00:23.810
was never used before Codecard.
1642
02:00:24.190 --> 02:00:27.015
Right? No single implementation of it
1643
02:00:27.415 --> 02:00:29.435
was in use by users.
1644
02:00:29.895 --> 02:00:30.395
So
1645
02:00:30.855 --> 02:00:38.460
great, somebody invented PSPTs, but, you know, what's the point if there is no buy in? So I think the part that the majority of the engineers
1646
02:00:39.080 --> 02:00:42.620
who sort of submit BIPS or want a new standard for something disregard
1647
02:00:43.080 --> 02:00:46.905
or don't put enough effort into is go knock on the doors
1648
02:00:47.525 --> 02:00:49.545
of other similar clients,
1649
02:00:50.645 --> 02:00:53.865
or talk in private with a lot of people before submitting
1650
02:00:54.889 --> 02:00:58.270
a bIP to the list or submitting a bIP for a number.
1651
02:00:58.730 --> 02:01:05.685
So because if you do a little bit of the legwork of selling a standard, because that's really what it is, right? You have to sell a standard.
1652
02:01:06.225 --> 02:01:08.485
You will find that, you know,
1653
02:01:08.920 --> 02:01:12.219
people are just either caught off guard or they just go immediately
1654
02:01:12.599 --> 02:01:13.099
into,
1655
02:01:13.639 --> 02:01:15.179
you know, I don't like the implementation,
1656
02:01:16.175 --> 02:01:22.435
as opposed to, you know, I've talked to Craig in private or I've talked to him, you know, we've discussed in this conference
1657
02:01:22.895 --> 02:01:24.114
and I can understand
1658
02:01:24.630 --> 02:01:32.330
why he wants to do this in the way that he wants to do. So maybe I will either sort of, like, be less picky about
1659
02:01:32.705 --> 02:01:37.925
some some part of the standard that may not be my preference. It's not necessarily wrong, but it's not my preference.
1660
02:01:38.465 --> 02:01:43.570
Or I might just abstain from the discussion and not sort of like add more to the contention.
1661
02:01:44.350 --> 02:01:44.850
So
1662
02:01:45.230 --> 02:01:47.010
I just think that, like, in Bitcoin,
1663
02:01:47.550 --> 02:01:51.010
the most successful stuff or really in any open source software
1664
02:01:52.125 --> 02:01:53.985
is is for people to find
1665
02:01:54.525 --> 02:01:57.185
outside of public discussion consensus
1666
02:01:57.645 --> 02:01:58.625
or buy in,
1667
02:01:59.085 --> 02:02:01.025
before sort of suggesting something.
1668
02:02:01.900 --> 02:02:04.560
Maybe maybe that would be, where I would start.
1669
02:02:05.340 --> 02:02:06.560
1670
02:02:06.940 --> 02:02:09.280
good advice and kind of I reached the same
1671
02:02:09.815 --> 02:02:10.875
conclusion myself,
1672
02:02:11.335 --> 02:02:25.590
is to kind of at least get other wallet devs to kind of agree. You know, I'm not I'm I'm obviously hoping it ends up in a certain way, but the primary goal is really just to get wallets to be able to share labels. You know? That is that remains
1673
02:02:25.969 --> 02:02:26.469
the
1674
02:02:26.905 --> 02:02:34.525
the the sort of goal here. So, you know, if I come up with something and and nobody else implements it, well, then that's failed.
1675
02:02:35.690 --> 02:02:36.590
So, yeah, I
1676
02:02:36.969 --> 02:02:40.429
mean, I guess part of it is is talking about it here,
1677
02:02:40.730 --> 02:02:43.469
and I'll keep on doing so. And, hopefully,
1678
02:02:44.185 --> 02:02:46.364
that's that at least that first goal,
1679
02:02:46.824 --> 02:02:47.704
we can reach,
1680
02:02:48.105 --> 02:02:52.764
1681
02:02:54.830 --> 02:02:58.370
Yeah. I mean, you you just need more people that want the standard,
1682
02:02:58.990 --> 02:03:07.945
even if it's not their preferred implementation because it would never be. Right? I mean, that's the very definition of a standard is a set of trade offs that most people will agree to use.
1683
02:03:08.645 --> 02:03:10.105
1684
02:03:10.610 --> 02:03:13.190
1685
02:03:14.290 --> 02:03:15.030
1686
02:03:16.690 --> 02:03:20.075
1687
02:03:20.555 --> 02:03:21.775
comments about this?
1688
02:03:22.235 --> 02:03:26.655
1689
02:03:27.370 --> 02:03:28.830
1690
02:03:29.450 --> 02:03:33.550
1691
02:03:34.065 --> 02:03:35.505
1692
02:03:36.065 --> 02:03:45.980
what what else do you guys wanna talk about in regards to wallets? Any any specific topics you guys wanna bring up? I want to bring up, while we have Lazy and Craig here,
1693
02:03:46.360 --> 02:03:49.580
1694
02:03:50.165 --> 02:03:52.165
1695
02:03:52.885 --> 02:03:54.745
question or statement there,
1696
02:03:55.844 --> 02:04:04.130
and I'd love to hear, Craig and and Lazy, what what are your opinions about this different type of set of trade off device?
1697
02:04:05.445 --> 02:04:10.185
1698
02:04:10.885 --> 02:04:14.505
makes sense to me, so I I I don't have any big problem with it. But I
1699
02:04:15.100 --> 02:04:19.200
sometimes you just gotta gotta think it through a little bit more and see if we're really
1700
02:04:19.820 --> 02:04:21.200
adding anything. So
1701
02:04:22.255 --> 02:04:23.074
is the TapSigner
1702
02:04:23.375 --> 02:04:27.955
always a multisig, or can you just go through the TapSigner architecture, Rodolfo?
1703
02:04:28.415 --> 02:04:34.810
1704
02:04:35.990 --> 02:04:37.990
the invention advancement here was
1705
02:04:38.755 --> 02:04:43.895
essentially, what we did is we have a Java card, right, a secure Yep. Chip there,
1706
02:04:44.355 --> 02:04:52.000
you know, of of sort of, like, Mead grade kind of thing so so that you could achieve the cost that you want, and it also means a lot less memory too.
1707
02:04:52.540 --> 02:04:54.755
And we built the Bitcoin stack in there,
1708
02:04:55.235 --> 02:04:56.935
right, the signing capabilities,
1709
02:04:58.435 --> 02:04:59.735
but we built it
1710
02:05:00.114 --> 02:05:01.735
to the extent that we could
1711
02:05:02.370 --> 02:05:04.949
in the limitations of the hardware, which means,
1712
02:05:06.690 --> 02:05:11.670
the the tap signer is essentially a a key holder, right, master
1713
02:05:12.245 --> 02:05:12.825
a master,
1714
02:05:13.205 --> 02:05:13.705
secret,
1715
02:05:14.725 --> 02:05:17.785
and what it does is it takes messages, digests,
1716
02:05:18.405 --> 02:05:20.665
and signs it with a Bitcoin signature.
1717
02:05:21.239 --> 02:05:26.780
That's that's all it does and it can do, and that's all protected by a PIN,
1718
02:05:27.800 --> 02:05:30.540
which is also user changeable.
1719
02:05:31.145 --> 02:05:31.645
Right?
1720
02:05:33.065 --> 02:05:36.285
This means that essentially what you have is
1721
02:05:36.825 --> 02:05:39.245
a a little device that
1722
02:05:40.000 --> 02:05:41.139
when you give it
1723
02:05:41.760 --> 02:05:46.980
any Bitcoin related thing, it will just sign provided that the pin is correct,
1724
02:05:47.599 --> 02:05:48.099
right?
1725
02:05:48.915 --> 02:05:49.415
Now
1726
02:05:50.355 --> 02:05:53.175
use cases for it that we initially
1727
02:05:53.555 --> 02:05:55.620
see and why we made it
1728
02:05:56.100 --> 02:05:59.560
was 1, to start taking seeds off of phones.
1729
02:05:59.940 --> 02:06:02.360
Right? Because phones are becoming progressively
1730
02:06:02.980 --> 02:06:03.720
less secure,
1731
02:06:04.525 --> 02:06:07.985
and also if you go to developing world
1732
02:06:08.844 --> 02:06:14.480
as Bitcoin starts to take hold people are gonna get physically robbed on the street and be forced
1733
02:06:15.040 --> 02:06:32.409
to sign a transaction out of their funds. I mean, I grew up in Brazil. It's exactly how it works with everything else. As soon as the bad guys find out that you have a thing that they want, they're gonna start robbing people on the street. And if they know everybody has a Bitcoin on their phone, they're gonna go and force the guy with a gun to their head to to take the money out. Now
1734
02:06:33.510 --> 02:06:34.730
with the Tap signer,
1735
02:06:35.190 --> 02:06:38.570
at least the key is not on the phone, so you can
1736
02:06:39.105 --> 02:07:00.035
either leave it somewhere else, right, so when you leave your house with your phone because you don't actually have a computer, you have a single computing device in your life is your phone, you can leave your tap center at home, so if somebody robs you, it shows right there on the UI, there's no key here. So that's a huge improvement for these people's lives. Yeah. So I'm just thinking through just the security implications. I mean, it's
1737
02:07:00.975 --> 02:07:04.675
1738
02:07:05.215 --> 02:07:16.784
he can just fake everything and your device will just sign whatever it signs and you'll send yourself the money. But that's not a standard attack. Usually, a phone is not completely controlled by an attacker
1739
02:07:17.085 --> 02:07:19.025
and at the same time in your possession.
1740
02:07:19.645 --> 02:07:20.784
Correct. Typically,
1741
02:07:21.244 --> 02:07:25.710
right, a phone's gonna be stolen or something like that, and they're gonna have to
1742
02:07:26.090 --> 02:07:26.989
do an attack
1743
02:07:27.290 --> 02:07:31.949
at rest. Right? The the data you you haven't typed in your PIN. It's not just gonna sign anything,
1744
02:07:32.385 --> 02:07:32.885
and
1745
02:07:33.425 --> 02:07:42.210
they probably don't even have both devices, but even if they did, everything's at rest and then your setup provides relatively strong protection and that's probably the most
1746
02:07:42.770 --> 02:07:45.110
common form of attack people experience.
1747
02:07:46.450 --> 02:07:51.955
Exactly. So just generally I mean, just that simple general thinking on it. I think it's a it's a fine trade off
1748
02:07:52.515 --> 02:07:54.615
as long as people understand that
1749
02:07:55.315 --> 02:08:00.215
this shouldn't necessarily be life savings money. This should be spending money, and I think
1750
02:08:00.570 --> 02:08:01.230
it's completely
1751
02:08:01.530 --> 02:08:04.910
1752
02:08:05.530 --> 02:08:10.475
And and the other part of that is people forget that, like, in in developing world,
1753
02:08:11.094 --> 02:08:12.955
maybe their life savings is $500.
1754
02:08:14.054 --> 02:08:17.515
Right? And a hardware wallet costs a 100 plus dollars,
1755
02:08:18.090 --> 02:08:18.590
so
1756
02:08:18.970 --> 02:08:19.950
it is economically
1757
02:08:20.650 --> 02:08:31.345
impossible for them to justify a hardware wallet for those $500 life savings. Right? So at least with the TapCigner, they're increasing their security with trade offs, right, to achieve
1758
02:08:31.805 --> 02:08:34.385
a developing world cost of security.
1759
02:08:34.730 --> 02:08:39.870
It's kind of like the, you know, your bike lock should be relative to the price of your bike.
1760
02:08:40.650 --> 02:08:42.110
1761
02:08:42.445 --> 02:08:47.885
1762
02:08:49.245 --> 02:08:51.905
we can we can encrypt the private key AES,
1763
02:08:52.240 --> 02:08:56.980
right, with a key that is physically etched on the card on the back,
1764
02:08:57.760 --> 02:09:01.125
but you cannot export that backup without the PIN.
1765
02:09:02.885 --> 02:09:12.090
So that means you're never in a single sort of point of failure scenario in terms of usage. Right? So when you set up your Tap Signer, the the wallet
1766
02:09:12.470 --> 02:09:25.685
software wallet ideally would ask if you wanna back it up. Right? And if it does, it's gonna say, okay. Just put your PIN and then it's gonna say it's gonna send a message to the card saying hey give me the encrypted private key and then they, you know, if the pin is correct,
1767
02:09:26.090 --> 02:09:30.590
TapCigner gives the encrypted private key, you can store in your Icloud or whatever. Right?
1768
02:09:31.130 --> 02:09:36.415
It's very strong encryption. I'm not very concerned, especially for this level of funds.
1769
02:09:36.715 --> 02:09:37.215
Right?
1770
02:09:37.995 --> 02:09:42.500
It's better than anything else this person that cannot afford a proper hardware wallet would be able to get.
1771
02:09:42.980 --> 02:09:48.120
So the recovery method is Yeah. So the recovery method is simple. Right? I mean, it's essentially
1772
02:09:48.660 --> 02:10:02.860
you can, you you just decrypt that file that that you start in your cloud somewhere else or or you give it to your nunchuck or whatever. You give it the the actual AES key, and you can sweep the funds. Right? One one more question on that. So the AES key is backed
1773
02:10:03.560 --> 02:10:18.000
1774
02:10:18.400 --> 02:10:22.260
hex string down somewhere else. So the the normal methodology is Icloud,
1775
02:10:23.440 --> 02:10:25.460
backup of the data, and then
1776
02:10:25.784 --> 02:10:28.045
write the hex string down on a piece of paper
1777
02:10:28.505 --> 02:10:58.220
and keep that at home. Something like that. No. I I mean, the card. Right? I mean, the card itself, the chances of you destroying the card are much lower than destroying paper. Right? Yeah. Not destroying it, but losing it losing it. Right? Like, you know, somebody steals your wallet type of thing. Exactly. Yes. But but the concept is that's the money and maybe you don't. Exactly. You just accept that it's lost. So backup of the actual key would be less common in your opinion. Oh, yes. Exactly. Right? I mean, the the the limitations of this target market are very severe in terms of of, like, cost,
1778
02:10:58.840 --> 02:10:59.340
1779
02:11:00.035 --> 02:11:14.300
and and also economical capacity. Right? So so, you know, like, yeah, sure. Piece of paper, write it down, an extra, like, string there. You have it. You know, you're in a much better scenario now, for that very limited cost of security.
1780
02:11:15.880 --> 02:11:16.620
But then
1781
02:11:17.215 --> 02:11:22.115
what's nice because it's a general purpose message digest signing device is that
1782
02:11:22.815 --> 02:11:35.780
you can use this for a lot of money with multisig, for example. Right? Because the device doesn't have a screen for you to verify, right? So you're not going to rely on that and you're not going to rely on the client software to not lie to you in that scenario but
1783
02:11:36.675 --> 02:11:38.454
because this is a resilient platform,
1784
02:11:38.994 --> 02:11:42.135
you could use this as one of your backup keys,
1785
02:11:42.675 --> 02:11:45.175
right, or one of your fast keys
1786
02:11:45.810 --> 02:11:46.870
that you just cosign,
1787
02:11:47.410 --> 02:11:48.470
but you don't necessarily
1788
02:11:49.810 --> 02:11:53.255
do the original verification of transaction proposal, right,
1789
02:11:53.975 --> 02:12:27.060
or better yet is the second signing key. So Matt Matt holds your cap card of your funds. Exactly, exactly. Right? Sure. And and that sort of, like, makes it very easy for you to enter that space. So in that case, then you really do want the backup. I I mean, I I always think 2 of 2 multisig, so you would really wanna backup in the multisig case with that. Yes. You can do more. Right? You can do 4, like 2 out of 4. Oh, I hate I hate those types of multisicks. I know, I know you don't like it, but in this scenario, maybe you do because you'd have 2 cards
1790
02:12:27.555 --> 02:12:39.000
together somewhere in a in a safe or like 2 separate, sorry, 2 separate places for those cards, right? Because the the cards are very resilient in terms of like weathering and all that stuff. So Yeah. Maybe maybe that helps.
1791
02:12:39.380 --> 02:12:42.199
I think most people would just use one for that scenario,
1792
02:12:42.579 --> 02:12:51.965
1793
02:12:52.745 --> 02:12:59.140
the physical well, I I just so I'm just thinking this through on the fly. Mhmm. I'd almost like a version of card where
1794
02:13:01.200 --> 02:13:01.940
the key
1795
02:13:02.725 --> 02:13:22.475
that that AES key on the back is like a sticker and you can either leave it on the card or you can peel it off and stick it somewhere else. So I'd almost like to give Matt the card. I peel off the AES key. I keep that at home. I can recover this card if if need be. But Matt has the card which he has no ability to I mean, obviously, he'd have to have access to my
1796
02:13:22.855 --> 02:13:23.355
Icloud.
1797
02:13:24.055 --> 02:13:37.420
1798
02:13:37.960 --> 02:13:38.405
Lacey.
1799
02:13:38.885 --> 02:13:42.585
I'm gonna actually so so the antenna does not span the whole,
1800
02:13:43.045 --> 02:13:44.025
size of the card,
1801
02:13:45.125 --> 02:13:45.625
so
1802
02:13:46.099 --> 02:13:52.280
what I'm thinking because right now, just for for resiliency, we print we print, we etch,
1803
02:13:53.219 --> 02:13:58.885
the the keys in 3 places on the card, right, like around the edges, on on three edges,
1804
02:13:59.665 --> 02:14:05.150
so so that just there is less chances of screwing up. But what I'm thinking now is maybe
1805
02:14:05.610 --> 02:14:13.695
I could draw on the card where to cut and put the c the the key below that cut line. Oh, yeah. I
1806
02:14:14.074 --> 02:14:18.895
like that. So if you do want, you can just cut that off from the card. The card still works,
1807
02:14:19.675 --> 02:14:31.205
and then you can just put that to the side. That that could be a fun little, different experiment for this. I mean, that does add complexity, more confusion, and everything, but I don't think it should be disregarded as an
1808
02:14:31.605 --> 02:14:40.230
1809
02:14:40.530 --> 02:14:46.630
inconspicuous thing. You can fall out of a wallet. You lose your wallet. Yep. It'd be cool to back up or the Uncle Jim scenario.
1810
02:14:47.415 --> 02:14:56.315
1811
02:14:56.730 --> 02:14:57.550
So the security
1812
02:14:57.929 --> 02:14:59.869
sort of trade offs are not as
1813
02:15:00.170 --> 02:15:02.110
important really. Yep. Agree.
1814
02:15:02.730 --> 02:15:05.230
Yeah. Craig, what what are your thoughts on this?
1815
02:15:06.195 --> 02:15:09.655
1816
02:15:10.034 --> 02:15:12.534
You know, I think it is a very decent
1817
02:15:13.270 --> 02:15:19.130
option for those who are not looking to store too much funds and are, you know, not able to afford,
1818
02:15:19.670 --> 02:15:27.205
something, you know, which costs a lot lot more. You know, something, you know, that I've actually consented, which is sort of similar,
1819
02:15:27.665 --> 02:15:29.285
you know, in in a very,
1820
02:15:30.360 --> 02:15:38.295
kind of low tech way is actually just, you know, some kind of a system where you have a multiseg of seed seed words,
1821
02:15:38.995 --> 02:15:39.815
no devices.
1822
02:15:40.835 --> 02:15:41.335
And
1823
02:15:41.635 --> 02:15:47.080
in in a sort of a village, you maybe have, you know, the different elders of of the village,
1824
02:15:47.700 --> 02:15:52.520
each have their own seed, and they can kind of control the sort of community immunity
1825
02:15:52.820 --> 02:15:54.015
funds in that way.
1826
02:15:54.895 --> 02:15:59.795
You know, there's there's definitely something something there, and I can see how the TAP signer can,
1827
02:16:00.575 --> 02:16:06.480
work in that such situation as well. You know? There's I think that we kind of need a way for,
1828
02:16:06.860 --> 02:16:12.435
you know, people in the developing world to be able to save, And many of them won't have the education
1829
02:16:13.935 --> 02:16:20.270
to manage their funds them themselves, but perhaps if they can kinda outsource that to their village elders,
1830
02:16:21.130 --> 02:16:22.990
they can actually find a way
1831
02:16:23.370 --> 02:16:32.485
to do that. You know? We we have a kind of a word for it here in USA. It's called a stock fell, where people can save, you know, their funds together in a sense.
1832
02:16:33.745 --> 02:16:38.990
Those are the kind of ideas which obviously Sparrow isn't trying to, you know, you know,
1833
02:16:39.530 --> 02:16:42.431
aim at, but I kind of think about them because
1834
02:16:42.925 --> 02:16:50.020
I wonder how people in Africa are going to take advantage of how do they save in Bitcoin. You know? What
1835
02:16:50.420 --> 02:16:53.000
mechanism do they use to store store funds?
1836
02:16:53.539 --> 02:17:05.465
And, you know, it's it's a long road to get from a hardware wallet to where they are. And I think steps along that path can definitely bring them closer to that sort of world.
1837
02:17:06.010 --> 02:17:15.715
1838
02:17:16.274 --> 02:17:17.175
some sort of,
1839
02:17:18.595 --> 02:17:23.015
authentication mechanism where, end user can verify this is an authentic?
1840
02:17:23.650 --> 02:17:27.970
We do that. Oh, you do that? Okay. Awesome. Yes. Good. Good. I I absolutely love that.
1841
02:17:28.930 --> 02:17:37.445
1842
02:17:38.145 --> 02:17:44.940
you you know, your phone is gonna ask you to open the browser, and it opens the browser and it talks to our server to check the certificate.
1843
02:17:45.735 --> 02:17:56.930
1844
02:17:57.311 --> 02:18:02.210
store in a third world country, and they're just gonna hand them out. So the user needs to be able to gain some,
1845
02:18:02.726 --> 02:18:06.505
1846
02:18:07.045 --> 02:18:11.780
we we always wanted to make a a cheap hardware wallet. Right? That was, like,
1847
02:18:12.980 --> 02:18:16.200
economically viable with enough security. Right?
1848
02:18:16.980 --> 02:18:17.480
And,
1849
02:18:18.020 --> 02:18:24.475
you know, the the challenge always was, like, finding 1, the the correct secure element that was economically viable
1850
02:18:25.175 --> 02:18:25.995
and a package
1851
02:18:26.375 --> 02:18:29.354
that it could actually ship anywhere in the world flat.
1852
02:18:30.490 --> 02:18:33.550
It's surprisingly hard to make something flat that's not a card,
1853
02:18:34.570 --> 02:18:37.471
and that is not a Java card, and Java cards are not that cheap.
1854
02:18:37.925 --> 02:18:40.185
So, finding that sort of like that
1855
02:18:41.204 --> 02:19:05.280
the Venn diagram of that was was really it, and and being able to ship the top signer on a on a plain envelope anywhere in the world is huge because, you know, most stuff you ship to developing world doesn't make it there. Right? Unless it's flat on an envelope, people think it's a ladder or a credit card or whatever, it makes it there. And and the issue was like, okay. Great. So what if it gets intercepted? Right? Like how do we test that the device is Kosher,
1856
02:19:05.979 --> 02:19:08.000
and that is through the certificate model,
1857
02:19:08.380 --> 02:19:11.200
and we also sleeve the card so that customs
1858
02:19:11.815 --> 02:19:19.355
in these countries don't just have a machine that reads NFCs and look for those to intercept them, right? So they are sleeved
1859
02:19:19.740 --> 02:19:21.120
so the NFC doesn't leak
1860
02:19:21.540 --> 02:19:22.040
in
1861
02:19:22.460 --> 02:19:22.960
shipment.
1862
02:19:24.860 --> 02:19:28.320
So yeah guys, any other topics that come to mind?
1863
02:19:28.675 --> 02:19:32.854
1864
02:19:33.955 --> 02:19:42.590
1865
02:19:43.130 --> 02:19:44.670
to this recording.
1866
02:19:45.295 --> 02:19:50.995
1867
02:19:51.614 --> 02:19:55.600
and, you know, make a big splash when it comes out, and there's been a lot of
1868
02:19:55.979 --> 02:19:57.279
updates they've been releasing,
1869
02:19:58.220 --> 02:20:01.795
lately, including one that seems they released while we were,
1870
02:20:02.436 --> 02:20:06.936
during this discussion. And that's from the Block hardware wallet team, Block, formerly Square.
1871
02:20:08.160 --> 02:20:11.301
I'm curious on your guys' thoughts. If you're familiar with,
1872
02:20:12.240 --> 02:20:15.221
their setup, the the main idea is a cheap
1873
02:20:15.915 --> 02:20:17.215
NFC enabled,
1874
02:20:18.955 --> 02:20:20.015
hardware device,
1875
02:20:21.194 --> 02:20:23.854
presumably without a screen. It might have a screen.
1876
02:20:24.350 --> 02:20:26.050
The phone holds one key.
1877
02:20:26.590 --> 02:20:28.289
The device holds one key.
1878
02:20:29.630 --> 02:20:30.130
Square,
1879
02:20:30.510 --> 02:20:31.569
I'm now block,
1880
02:20:31.949 --> 02:20:33.250
has the 3rd key,
1881
02:20:33.596 --> 02:20:34.735
and most transactions,
1882
02:20:35.516 --> 02:20:43.056
the phone key and the square key are the ones that authorize it, and you have some kind of threshold limit. And then if you wanna sweep
1883
02:20:43.500 --> 02:20:45.359
at any point, you bring in
1884
02:20:45.740 --> 02:20:48.320
that hardware key that's kind of just used as, like,
1885
02:20:48.700 --> 02:20:49.840
a escape hatch
1886
02:20:50.516 --> 02:20:51.575
type of situation.
1887
02:20:52.035 --> 02:20:55.176
1888
02:20:56.115 --> 02:20:59.735
I don't see the point in making the device being electronic.
1889
02:21:00.370 --> 02:21:06.229
It'd be much better to just write down some secret than it is for you to keep around
1890
02:21:06.930 --> 02:21:08.070
a device.
1891
02:21:09.204 --> 02:21:10.824
You know, devices do,
1892
02:21:11.604 --> 02:21:13.465
tend to fail over time.
1893
02:21:14.244 --> 02:21:14.744
So,
1894
02:21:15.284 --> 02:21:18.585
you know, that's that's one tricky part. The other one is
1895
02:21:19.030 --> 02:21:26.090
collusion between the two servers, you know, is less likely a massive company, but also, you know, if the state doesn't like anybody,
1896
02:21:26.630 --> 02:21:27.770
these these massive
1897
02:21:28.405 --> 02:21:34.425
big actors like Square and whoever is gonna hold the other key are exactly the targets that do have to comply.
1898
02:21:35.205 --> 02:21:42.811
So, so so there is some some challenges there. But, you know, they they are looking at mass market, so
1899
02:21:43.670 --> 02:21:45.690
there's very few easy answers
1900
02:21:46.230 --> 02:21:47.051
that do
1901
02:21:47.525 --> 02:21:52.345
incentivize self custody on mass market, and it's just nice to see people trying different stuff.
1902
02:21:53.125 --> 02:22:00.409
1903
02:22:01.590 --> 02:22:03.770
So, unfortunately, I can't offer any
1904
02:22:04.105 --> 02:22:09.405
any views on it. I don't know enough about the space, but I know that, both you, MBK
1905
02:22:10.426 --> 02:22:14.931
and Lazy, would certainly have some interesting views on on this choice of chip.
1906
02:22:15.730 --> 02:22:20.471
But, yeah, it's, it seems that at least they are moving forward with their design.
1907
02:22:21.330 --> 02:22:22.631
Do you think you could
1908
02:22:24.296 --> 02:22:25.436
you could explain
1909
02:22:26.056 --> 02:22:28.235
how a secure element differs
1910
02:22:28.855 --> 02:22:29.355
from
1911
02:22:30.220 --> 02:22:33.840
an MCU and then what is a secure MCU in that
1912
02:22:34.220 --> 02:22:34.720
context?
1913
02:22:35.739 --> 02:22:43.145
1914
02:22:43.605 --> 02:22:54.740
So you would have something like a mesh on the top of the silicon. So if you try to to probe from the top, you you you essentially trigger the chip to either raise itself or break or something.
1915
02:22:55.205 --> 02:23:01.064
You'd have you'd pay very good attention to not leak calculation secrets over the power.
1916
02:23:02.245 --> 02:23:02.984
You would
1917
02:23:04.040 --> 02:23:06.620
you'd have, like, write one's memory
1918
02:23:07.320 --> 02:23:10.380
so that you cannot change the memory. Right? So,
1919
02:23:10.840 --> 02:23:14.655
so that, for example, you store there a hash of the firmware.
1920
02:23:16.635 --> 02:23:18.095
You would have, like,
1921
02:23:18.476 --> 02:23:23.320
the the pins are enforced by hardware. Right? So that you can't change the firmware
1922
02:23:23.860 --> 02:23:35.545
that checks the pin. You know, Lazy can can sort of do a much better job than I can at, like, going through all the defenses that some of the stuff would have, but essentially, that's what Secure Element is. Right?
1923
02:23:36.005 --> 02:23:38.105
It's it's a processor designed
1924
02:23:38.601 --> 02:23:39.341
to secure things,
1925
02:23:40.040 --> 02:23:42.700
and it makes a lot of trade offs in terms of functionality
1926
02:23:43.080 --> 02:23:46.460
to achieve that, and then what happens is
1927
02:23:48.225 --> 02:23:54.325
when you try to do more advanced things inside of secure enclave or meaning you have a normal type of processor
1928
02:23:55.280 --> 02:23:55.780
running
1929
02:23:56.240 --> 02:24:00.580
virtually or physically inside all this other net of securities
1930
02:24:01.760 --> 02:24:12.455
to try to do more more general purpose things like say for example, calculating Bitcoin keys or something. So cold cards secure elements are very rudimentary on purpose.
1931
02:24:13.359 --> 02:24:18.899
Right? The more rudimentary these chips are the less attack surface you have, in my opinion.
1932
02:24:19.359 --> 02:24:20.100
And then
1933
02:24:20.516 --> 02:24:23.415
what we do is use the secure elements to 1,
1934
02:24:23.716 --> 02:24:25.575
attest and guarantee the firmware,
1935
02:24:26.436 --> 02:24:27.176
2 is
1936
02:24:27.900 --> 02:24:31.600
like make sure that you cannot get in unless they are unlocked pin wise.
1937
02:24:32.140 --> 02:24:37.120
And, you know, we use it for a few other things, like that's where we store it encrypted seed and stuff like that. But generally speaking,
1938
02:24:38.365 --> 02:24:42.625
we use an MCU which is a mostly undefended
1939
02:24:44.046 --> 02:24:44.546
processor,
1940
02:24:45.006 --> 02:24:48.930
right, because we just assume it's gonna, you know, it could be broken anyways,
1941
02:24:50.430 --> 02:24:52.370
and then we do the secure stuff
1942
02:24:52.830 --> 02:24:53.890
on the other chips
1943
02:24:54.675 --> 02:24:55.175
when
1944
02:24:56.035 --> 02:24:57.976
the main processor is not
1945
02:24:58.355 --> 02:24:58.855
employed.
1946
02:24:59.875 --> 02:25:13.235
But in this design here, it looks like they're using a secure element that does have an arm capability, meaning a general purpose computing capability there so that they can do the Bitcoin stuff inside the secure element, which is great.
1947
02:25:13.615 --> 02:25:16.515
It's it's similar to how Ledger does their things,
1948
02:25:16.975 --> 02:25:17.475
but
1949
02:25:18.175 --> 02:25:39.649
there'll be a few challenges here. One is unlikely the firmware will be open source all the way down the stack. 2 is the cost to increase. And 3 is the the complexity of this chip will be higher, so more attack surface. You know, you ask a secure element vendor, they'll give you this spec sheet sheet of all the amazing things to defend against until they fail,
1950
02:25:40.590 --> 02:25:50.305
1951
02:25:50.925 --> 02:25:57.200
so this is an m 33 core. So that's just a standard ARM core. So that's not actually an ARM secure core device.
1952
02:25:57.660 --> 02:25:59.440
1953
02:26:00.300 --> 02:26:04.605
1954
02:26:05.645 --> 02:26:11.266
secure element. So this is just a generic new so the m 33 is sort of the newer ARM core,
1955
02:26:13.500 --> 02:26:18.160
but I see so they list a secure vault, but the secure vault looks like
1956
02:26:19.340 --> 02:26:20.560
just a software
1957
02:26:21.420 --> 02:26:21.920
peripheral
1958
02:26:23.405 --> 02:26:25.905
that includes a bunch of features. So,
1959
02:26:26.445 --> 02:26:27.825
I'm just going through here.
1960
02:26:28.205 --> 02:26:28.705
So
1961
02:26:29.405 --> 02:26:35.590
the people like to do this, and this side really gets me. So they they have a puff, so a physically uncountable function. So, basically,
1962
02:26:36.210 --> 02:26:37.030
that's a methodology
1963
02:26:37.410 --> 02:26:39.270
where, a device collects
1964
02:26:40.175 --> 02:26:40.675
randomness
1965
02:26:41.215 --> 02:26:44.355
from the initial state of its SRAM, so it's,
1966
02:26:44.735 --> 02:26:49.370
it's sort of provably random that bits in, SRAM will power up
1967
02:26:50.250 --> 02:26:58.965
uniquely random between devices if you get large enough samples, but then consistently in that state, and so it gives a unique fingerprint for the device.
1968
02:26:59.505 --> 02:27:02.165
But people often use that
1969
02:27:03.185 --> 02:27:07.990
aspect to infer a lot more security than that feature actually
1970
02:27:08.450 --> 02:27:08.950
provides.
1971
02:27:09.971 --> 02:27:12.950
Not it it's a nice it's a nice feature, but people
1972
02:27:13.325 --> 02:27:15.505
infer way more security than it provides.
1973
02:27:16.925 --> 02:27:20.225
I do see DPA countermeasures, so that's differential
1974
02:27:20.540 --> 02:27:23.200
power analysis. So that would be for people trying to,
1975
02:27:24.460 --> 02:27:24.960
probe,
1976
02:27:25.500 --> 02:27:27.440
what the chip is doing. So there is
1977
02:27:27.900 --> 02:27:29.120
some DPA countermeasures
1978
02:27:30.405 --> 02:27:31.785
and some anti tamper,
1979
02:27:33.925 --> 02:27:34.425
but
1980
02:27:35.205 --> 02:27:42.370
this I I have to look at this more to determine exactly what it is. But I mean, it looks like a it looks like a good choice, but this is not a secure element.
1981
02:27:43.870 --> 02:27:48.530
This is just a general purpose ARM controller with security features and peripherals.
1982
02:27:49.105 --> 02:27:52.806
Is what it appears to me in just a quick look here. Well, that that would make sense because
1983
02:27:53.266 --> 02:27:54.565
1984
02:27:54.945 --> 02:27:57.846
a secure element would, cost a lot more,
1985
02:27:58.360 --> 02:28:02.780
and I'm sure they are cost conscious because this is a mass mass market.
1986
02:28:03.720 --> 02:28:07.900
1987
02:28:09.466 --> 02:28:09.966
separate
1988
02:28:10.426 --> 02:28:13.865
processor embedded within another within their their,
1989
02:28:14.506 --> 02:28:17.645
silicon, but Exactly. Yeah. This this looks like just a single,
1990
02:28:18.649 --> 02:28:20.750
m 33 core with security features,
1991
02:28:21.450 --> 02:28:29.835
which is it is good. So there's nothing wrong with it. This is, you know, this is gonna have good features. This may be hard to defeat or not, but, I mean, it will have to be,
1992
02:28:30.315 --> 02:28:30.815
tested,
1993
02:28:31.355 --> 02:28:33.855
by the market to see how well it does.
1994
02:28:34.395 --> 02:28:41.061
1995
02:28:42.240 --> 02:28:53.285
there is no the SPI is already fully taken here, so the SPI, probably not enough ports for more, so they're not gonna be driving a display. Hey, Matt. Are we rambling about anything
1996
02:28:53.601 --> 02:28:58.820
1997
02:28:59.360 --> 02:29:07.096
1998
02:29:07.815 --> 02:29:22.885
it's been pretty interesting. I mean, you guys are touching on things that are obviously way above my pay grade. And there's absolutely nobody listening right now anyway, so we can just sorta talk about what Yeah. I know. We should we should do what we enjoy. You'd be surprised. A lot of the die hards make them all the way through. Yes.
1999
02:29:23.585 --> 02:29:29.284
2000
02:29:29.931 --> 02:29:31.870
I don't think they would have enough ports
2001
02:29:32.811 --> 02:29:43.025
2002
02:29:43.565 --> 02:29:45.186
2003
02:29:47.530 --> 02:29:49.790
No. No. Actually, there might be more.
2004
02:29:50.170 --> 02:29:57.255
2005
02:29:57.875 --> 02:30:06.069
is there's just so many attacks that come in over wireless. They now there's there's logical things, so they have TrustZone, which is sort of ARM's proprietary
2006
02:30:07.010 --> 02:30:08.949
logical way of isolating
2007
02:30:09.649 --> 02:30:13.189
memory. So one process can be isolated from another process,
2008
02:30:14.234 --> 02:30:18.574
just generically speaking. But it's actually tricky to do everything
2009
02:30:18.875 --> 02:30:20.015
right. So
2010
02:30:20.450 --> 02:30:28.870
we'd have to look to make sure they have good isolation between their wireless stacks and then the stacks that are dealing with Bitcoin stuff.
2011
02:30:29.285 --> 02:30:36.905
2012
02:30:37.670 --> 02:30:44.090
you know, this is a substantially step up, say, from a ledger sorry, from a Trezor. Right? So this actually has security.
2013
02:30:44.630 --> 02:30:47.370
There's a few things going on here they try to do,
2014
02:30:47.735 --> 02:30:50.555
you know, of course at the end of the day implementation
2015
02:30:51.815 --> 02:31:01.190
2016
02:31:01.830 --> 02:31:04.645
2017
02:31:05.125 --> 02:31:07.864
Yeah. Which is what I think the target is. For sure.
2018
02:31:08.324 --> 02:31:14.505
2019
02:31:15.590 --> 02:31:17.130
on on the STM.
2020
02:31:17.750 --> 02:31:19.930
Maybe there's a new glitching attack,
2021
02:31:20.390 --> 02:31:23.689
but the original, I think, will be much harder with proper ECC.
2022
02:31:24.695 --> 02:31:25.675
I know this because
2023
02:31:26.455 --> 02:31:34.989
our choice of, MCU does have good ECC and data attack is is not, like, I have not seen anybody successfully achieving it.
2024
02:31:35.609 --> 02:31:38.590
But the thing is it doesn't have a display. Right? So,
2025
02:31:38.970 --> 02:31:41.135
you know, there is that issue. Fingerprint
2026
02:31:41.595 --> 02:31:42.095
sensors
2027
02:31:42.555 --> 02:31:44.175
are, you know, with
2028
02:31:44.635 --> 02:31:45.215
a photocopy
2029
02:31:45.675 --> 02:31:47.935
piece of paper, you can spoof them.
2030
02:31:48.620 --> 02:31:54.080
And if they're a little bit better, you can just there's 50 ways to spoof, you know, fingerprint is pointless,
2031
02:31:54.620 --> 02:31:55.840
but it's much cheaper
2032
02:31:56.220 --> 02:31:57.680
and much easier
2033
02:31:58.115 --> 02:32:12.860
to deploy on the on the mechanical package than it is to put a keyboard, for example, or buttons. Right? So because the fingerprint sensor is, is like static. Right? There's no movement on that, so it's much easier to build a package. It's mentally less burdensome. Yeah.
2034
02:32:13.720 --> 02:32:15.101
But again, this is
2035
02:32:15.495 --> 02:32:18.555
from their model. This is designed as the backup system,
2036
02:32:19.575 --> 02:32:20.314
which is
2037
02:32:20.854 --> 02:32:21.354
great,
2038
02:32:21.655 --> 02:32:33.265
but I I you know, if for backup, I will just use seeds. Maybe maybe they have more plans. Why this conversation is important to me is because Cash App already has 80,000,000 users.
2039
02:32:34.604 --> 02:32:41.825
2040
02:32:42.409 --> 02:32:42.909
Presumably,
2041
02:32:43.930 --> 02:32:49.390
this will allow them to offer a Bitcoin only type of Cash App,
2042
02:32:50.065 --> 02:32:58.485
that is quote, unquote self custody so they can get around international regulation in terms of KYC and friction stuff and allow them to open up globally.
2043
02:32:59.000 --> 02:33:04.300
Obviously, Square is an extremely trusted brand just among among the normal population.
2044
02:33:04.680 --> 02:33:08.140
So, I mean, I'm kinda operating on the assumption here that this could quickly
2045
02:33:09.215 --> 02:33:15.715
2046
02:33:16.095 --> 02:33:18.141
setup was? It was this
2047
02:33:18.601 --> 02:33:19.580
2048
02:33:19.960 --> 02:33:21.740
their square server holds a key.
2049
02:33:22.520 --> 02:33:29.635
I'm saying cash app, but they're probably going to have a different app, a separate app, but the app holds a key. Their server holds a key
2050
02:33:30.255 --> 02:33:34.436
and the hardware device holds a key. It's a basic 2 of 3.
2051
02:33:34.930 --> 02:33:38.949
And then most of the time, their server and the phone are signing.
2052
02:33:39.409 --> 02:33:46.016
2053
02:33:46.875 --> 02:33:52.415
because one is in their client that's developed and maintained by them and the other one is on their server.
2054
02:33:52.800 --> 02:33:53.300
2055
02:33:54.080 --> 02:33:56.500
2056
02:33:56.880 --> 02:34:08.155
If you're building something for 60,000,000 people today immediately, because they will deploy this to literally 60,000,000 people, right, you have to come up with something that has a lot of trade offs,
2057
02:34:08.520 --> 02:34:16.381
Right? So you can immediately meet these people where they are. Yeah. No. I'm I'm excited. This looks good. You could say the same thing about
2058
02:34:17.045 --> 02:34:21.145
Casa's 2 of 3 setup. Yeah. But that is a concern. Right? Yeah.
2059
02:34:21.685 --> 02:34:35.240
The phone app is holding a key. Casa is holding a key, and you have a key on a hardware device. And also on the Casa scenario, they have some custom multisig that's sort of like their thing. Right? The key rotation and all that stuff that makes it extremely hard to recover
2060
02:34:35.615 --> 02:34:43.795
2061
02:34:44.610 --> 02:34:48.950
2062
02:34:49.330 --> 02:34:57.835
Right. I I I actually, to be fair to them, like, I don't know like, I the last time I look at the CASA actual implementation was, like, ages ago.
2063
02:34:58.375 --> 02:35:07.900
I don't know where they are at, so I can't really, like, you know, educately comment on it. But the point stands the point stands that this doesn't protect from essentially
2064
02:35:08.520 --> 02:35:10.381
2065
02:35:10.925 --> 02:35:13.585
actively malicious. Correct. But presumably
2066
02:35:14.045 --> 02:35:14.545
presumably,
2067
02:35:15.244 --> 02:35:21.020
they will open source the client, and presumably, they're trying to get it. It's more of a a regulatory
2068
02:35:21.400 --> 02:35:30.766
play in in my book because it's, you know, quote, unquote technically self custody, but you get a lot of the so called benefits that people like with the handholding of a custodian.
2069
02:35:31.306 --> 02:35:46.020
2070
02:35:46.415 --> 02:35:46.915
Exactly.
2071
02:35:47.535 --> 02:35:53.795
2072
02:35:54.250 --> 02:36:07.734
they give people the ability to actually back up. So you didn't just Exports. Basically export the key from your phone, export the key from this hardware device, and actually do physical backup. If they did that, then I think I have almost no complaints.
2073
02:36:08.194 --> 02:36:09.895
2074
02:36:10.811 --> 02:36:13.790
thinking from their perspective and extrapolating here,
2075
02:36:14.091 --> 02:36:21.675
I think the whole point is not to let the user export the secret. I I think that is probably correct, and that's that would be my concern.
2076
02:36:22.055 --> 02:36:26.314
Because that's how I see that design. I don't see any way in which the secret comes out,
2077
02:36:26.931 --> 02:36:34.950
unless it was sort of like similar to TapCigner where they're encrypting with something and then spitting it out. Because to me, this looks like there could still be a regulatory capture
2078
02:36:35.275 --> 02:36:40.415
2079
02:36:41.275 --> 02:36:41.775
and
2080
02:36:42.210 --> 02:36:43.590
Square goes out and basically
2081
02:36:43.970 --> 02:36:52.405
disables the app on his phone or removes it from his phone. So effectively he and then he can't recover from their server, so effectively he loses to his clients.
2082
02:36:53.024 --> 02:36:54.165
2083
02:36:54.865 --> 02:37:00.085
It could also be just extraction. Right? They could be mandated to extract the seed from the device,
2084
02:37:00.460 --> 02:37:18.365
you know, provided that there is backdoors and things, which, again, I I don't I I just want the people to know we're not trying to beat on them or think that they're in affairs or anything like that. We're just trying to sort of, like, play out the game theory here of how could they get captured and be forced to do something they don't wanna do. I think that's very important for people to understand
2085
02:37:19.010 --> 02:37:21.350
that we have very mean laws,
2086
02:37:22.529 --> 02:37:23.510
to make sure
2087
02:37:24.130 --> 02:37:24.630
that
2088
02:37:25.010 --> 02:37:26.115
companies comply
2089
02:37:26.596 --> 02:37:35.539
when the government asks men to jump, they jump as high as the government wants. Right? Like, nobody wants to go to prison for 30 years. Yeah. There should be an advanced option
2090
02:37:36.239 --> 02:37:37.060
2091
02:37:37.920 --> 02:37:42.819
data that they can back up. I think if if that if they add that, then I think everything's good.
2092
02:37:43.275 --> 02:37:45.056
2093
02:37:45.835 --> 02:37:46.495
I haven't
2094
02:37:46.875 --> 02:37:47.775
read it through.
2095
02:37:48.476 --> 02:37:54.051
2096
02:37:54.590 --> 02:37:58.290
that their clients get when they export their wallets to
2097
02:37:59.070 --> 02:38:04.516
Sparrow for the first time, and they see their funds appear in a different app. Right? So now they have this experience
2098
02:38:05.056 --> 02:38:11.500
that my funds are not locked into an Unchained in some sense that I can get out of that world
2099
02:38:11.880 --> 02:38:20.556
is a very powerful thing. And they say that that that's you know, they often get a lot of lean in at that point, and, you know, the client's eyes really light up. So, hopefully,
2100
02:38:21.255 --> 02:38:22.075
that incentive
2101
02:38:22.455 --> 02:38:27.436
will apply to Square as well, and they will see that if they wanna get people to trust,
2102
02:38:28.109 --> 02:38:29.649
it's obviously not the same
2103
02:38:30.189 --> 02:38:39.404
user base. We're talking about a much, much, much broader set of users who are probably just gonna say, you know what? It's Square. I'm gonna give them all my my money. But,
2104
02:38:39.944 --> 02:38:40.845
hope hopefully,
2105
02:38:41.225 --> 02:38:56.875
that still remains a sort of a backdoor for people, and Square kind of see the value of that, because I think it is a very powerful thing, to allow people to to kind of know that their funds are safe even if the company that they are currently using isn't there anymore.
2106
02:38:57.895 --> 02:39:06.360
2107
02:39:06.740 --> 02:39:08.120
2108
02:39:08.580 --> 02:39:10.601
that the Pareto distribution continues,
2109
02:39:11.605 --> 02:39:20.825
you would say that 80% of people will never want to take custody of their Bitcoin, right? They're gonna want to outsource that security thinking
2110
02:39:21.260 --> 02:39:23.279
and risk to a 3rd party,
2111
02:39:23.580 --> 02:39:26.960
right, at the expense of incurring third party risk.
2112
02:39:27.580 --> 02:39:28.080
So
2113
02:39:28.995 --> 02:39:29.975
I think that
2114
02:39:30.435 --> 02:39:30.935
anything
2115
02:39:31.555 --> 02:39:37.895
that just moves people an inch away from not being fully exposed to a third party is a monumental
2116
02:39:38.195 --> 02:39:38.695
win,
2117
02:39:39.110 --> 02:39:42.090
Right? So if we can have 60,000,000 people
2118
02:39:42.630 --> 02:39:44.250
who do use Cash App
2119
02:39:44.630 --> 02:39:51.265
to have even a set of trade offs that may not appease us as people who care about security, but it's already
2120
02:39:51.805 --> 02:39:54.385
a huge upgrade from FUO on
2121
02:39:55.170 --> 02:39:56.229
custodial Bitcoin,
2122
02:39:56.689 --> 02:39:58.550
it's it's it's a big win.
2123
02:39:59.250 --> 02:40:03.590
2124
02:40:06.024 --> 02:40:09.324
like, consider consider the trade offs that signal has made,
2125
02:40:09.704 --> 02:40:12.284
and and just try and limit the amount of
2126
02:40:12.585 --> 02:40:13.085
of
2127
02:40:14.020 --> 02:40:19.960
control you have over your users because there will be governments that will push you, and you'd rather not have that ability.
2128
02:40:20.261 --> 02:40:24.415
2129
02:40:24.716 --> 02:40:27.455
You're gonna be you're gonna have a user who accidentally
2130
02:40:28.155 --> 02:40:40.016
ended up with a coin from the old fact list, and then, and then you're gonna have to act on that user even though that guy probably didn't even know what's going on here. The tornado cache guy is still in jail, I believe. Yep.
2131
02:40:40.476 --> 02:40:46.336
It's, well, remember. Right? Like and even when a developer puts themselves in a way that they cannot
2132
02:40:46.760 --> 02:40:58.976
do anything for this stage, they can find themselves in a lava bit scenario where the state may try to coerce them to change that software or risk jail in order to to continue that business going.
2133
02:41:00.555 --> 02:41:05.500
Alright, guys. I think we've really covered a lot today. This was was pretty monster
2134
02:41:06.680 --> 02:41:08.140
conversation. I can't
2135
02:41:09.000 --> 02:41:10.220
thank you all enough
2136
02:41:11.080 --> 02:41:11.580
for
2137
02:41:12.045 --> 02:41:15.185
for giving so much of your time and coming here and talking shop.
2138
02:41:15.564 --> 02:41:18.465
I will try to have more of these in between
2139
02:41:19.779 --> 02:41:20.840
list episodes.
2140
02:41:21.620 --> 02:41:24.520
I think it's, it's super fun to have,
2141
02:41:25.779 --> 02:41:26.279
actual
2142
02:41:26.755 --> 02:41:27.255
builders
2143
02:41:28.274 --> 02:41:29.415
and people who
2144
02:41:30.034 --> 02:41:31.175
have user bases,
2145
02:41:32.114 --> 02:41:35.734
who do actually interactive security things,
2146
02:41:36.841 --> 02:41:44.860
and and are the people working on all the client stuff that that everybody in Bitcoin uses. It was an absolute blast.
2147
02:41:45.455 --> 02:41:50.355
If you guys have any final words or or any any things you want to,
2148
02:41:51.215 --> 02:41:52.595
to shield, please do,
2149
02:41:53.260 --> 02:41:58.479
And, yeah, I really appreciate it. It was an absolute pleasure. Thank you guys for joining us.
2150
02:41:59.420 --> 02:42:01.439
Final thoughts, Craig. You first.
2151
02:42:03.105 --> 02:42:08.245
2152
02:42:09.230 --> 02:42:10.370
Other than, you know,
2153
02:42:11.311 --> 02:42:15.011
I'm really looking for feedback on the wallet labels
2154
02:42:15.551 --> 02:42:19.985
spec that I put out, you know, particularly from users. I'm trying to actually
2155
02:42:20.525 --> 02:42:25.025
talk to people on Bitcoin talk and all kinds of other forums that I don't usually
2156
02:42:25.405 --> 02:42:29.730
use. So I'm gonna try and engage more on that and and just, you know,
2157
02:42:30.190 --> 02:42:41.895
I guess, try and sell it as MBK says or at least the the idea and and see what format we come up with at the end of it. So, yeah, so that's kind of, what I'm thinking about
2158
02:42:42.275 --> 02:42:42.936
right now.
2159
02:42:44.150 --> 02:42:48.010
Otherwise, it's been great to chat to you you guys. It's always nice to,
2160
02:42:48.391 --> 02:42:54.604
you know, interact with others, particularly when you're working on a solo project. So thanks again. It's been it's been awesome.
2161
02:42:55.225 --> 02:43:01.245
2162
02:43:02.010 --> 02:43:07.870
do not let anything said here scare you away from using hardware wallets. It's it's exponentially
2163
02:43:08.330 --> 02:43:13.074
even with problems and this and that, it's always exponentially safer,
2164
02:43:13.614 --> 02:43:15.955
not to poke Craig here, but you know,
2165
02:43:16.530 --> 02:43:19.110
than using a a PC based,
2166
02:43:21.490 --> 02:43:24.630
wallet. So just wanna remind everybody of that.
2167
02:43:25.415 --> 02:43:26.235
2168
02:43:26.935 --> 02:43:27.675
2169
02:43:28.295 --> 02:43:32.590
any final thoughts as a guest? Thank you for coming. Stay on, bullstack, Seth.
2170
02:43:33.710 --> 02:43:37.570
Thanks, guys. You you all have a a fantastic day. I'm gonna stop recording
2171
02:43:38.391 --> 02:43:38.891
now.
2172
02:43:39.710 --> 02:43:53.750
Thanks for listening and going through another boring list of updates once again. Don't forget to get in touch on Twitter at Bitcoin Review h HQ or the Telegram Bitcoin review pod or email bitcoin review atquaintite.com.
2173
02:43:55.569 --> 02:44:02.795
Remember, I don't have a crystal ball. So if you have a cool project you're working on, do make sure to get in touch with us.
2174
02:44:03.575 --> 02:44:07.229
And if you're still not bored, you can follow me on Twitter at nnickay.