CD55: signing devices and open source with @seedsigner and tony
EPISODE: 55
BLOCK: 722645
PRICE: 2217 sats per dollar
TOPICS: build your own hardware wallet, signing devices, open source software, off the shelf hardware, funding options, ux challenges, tradeoffs, risks and mitigations
@seedsigner: https://twitter.com/seedsigner
streamed live every tuesday:
https://citadeldispatch.com
twitch: https://twitch.tv/citadeldispatch
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://www.podpage.com/citadeldispatch
telegram: https://t.me/citadeldispatch
support the show: https://citadeldispatch.com/contribute
stream sats to the show: https://www.fountain.fm/
join the chat: https://matrix.to/#/#citadel:bitcoin.kyoto
00:00 - Problem with inflation
00:26 - Tightening and Fed's role
04:20 - Introduction to Seed Signer
09:26 - Updates and improvements to Seed Signer
22:40 - Comparison with other DIY hardware wallets
29:30 - Use cases and security considerations for Seed Signer
42:39 - Getting started with Seed Signer
44:51 - Upcoming features and updates for Seed Signer
52:08 - Security considerations and risks with Seed Signer
59:31 - Potential integration with Lightning Signer
01:13:39 - Funding and revenue streams for Seed Signer
01:24:58 - Ways to contribute to the Seed Signer project
01:29:26 - Keith and Nick's code review process
01:29:59 - Importance of more experienced Python developers
01:30:15 - The power of open source projects
01:31:26 - Creating an open source community
01:32:38 - Importance of effectively communicating a vision
01:33:45 - Gratitude for the open source community
01:34:44 - Appreciation for the conversation and panel
01:35:42 - Encouragement to dive into Bitcoin projects
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 8:07:09 PM
Duration: 6031.491
Channels: 1
1
00:00:00.160 --> 00:00:03.460
2
00:00:03.840 --> 00:00:09.995
Okay? So now it jumps huge, and everybody's right. From 2% up to, what, 7%
3
00:00:10.295 --> 00:00:20.480
plus, we're gonna start to come down. No doubt about it. And you're going to be right. It's gonna be 4a half, 5. The issue is just because it came down from 7,
4
00:00:20.860 --> 00:00:29.435
the real issue is where it started, and I think that's where everybody's gonna fall into this trap. Oh my god. Look at half of this inflation has disappeared,
5
00:00:29.735 --> 00:00:37.430
but it's still significantly higher than pre COVID. And that is the point. And and the other issue is, in my opinion,
6
00:00:38.129 --> 00:00:44.984
where where's the tightening been? Give me a break. We're 0 to 25. They're still buying. Soma was 30,000,000,000
7
00:00:45.765 --> 00:00:59.120
for the 3 year note. Okay? I don't see any tightening. I can't imagine that you have a microscope bigger than mine. Jack. Yeah. Come on. What is your mic? What is your mic? The Rick Ezel. There's 90 basis points.
8
00:00:59.695 --> 00:01:01.875
9
00:01:02.415 --> 00:01:13.299
10
00:01:13.600 --> 00:01:20.244
The Fed has done nothing. Blah blah blah blah blah. Rick, I I totally agree that the Fed's done absolutely
11
00:01:20.545 --> 00:01:24.485
12
00:01:24.810 --> 00:01:41.625
13
00:01:41.925 --> 00:01:43.140
14
00:02:20.109 --> 00:02:21.890
15
00:02:22.269 --> 00:02:24.609
It's your boy Odell here for dispatch
16
00:02:25.230 --> 00:02:25.730
55.
17
00:02:27.055 --> 00:02:29.635
Yes. This is a 2nd dispatch
18
00:02:30.335 --> 00:02:32.995
in this week. It's the first time we're doing it.
19
00:02:34.880 --> 00:02:35.840
First time we're doing,
20
00:02:36.240 --> 00:02:36.980
2 dispatches,
21
00:02:37.520 --> 00:02:38.500
in 1 week.
22
00:02:39.040 --> 00:02:42.580
I have our our boys, seed signer, and Tony
23
00:02:42.960 --> 00:02:44.020
here in the studio.
24
00:02:45.185 --> 00:02:49.125
So I felt it was prudent to have this conversation in person while we had the opportunity.
25
00:02:49.905 --> 00:02:55.120
Sale dispatch is an interactive live show about Bitcoin distributed systems privacy and open source software.
26
00:02:56.780 --> 00:03:00.400
Our show is a 100% audience funded without ads and sponsors,
27
00:03:00.845 --> 00:03:03.185
purely focused on actionable Bitcoin discussion.
28
00:03:03.885 --> 00:03:05.345
Thank you so much to,
29
00:03:05.645 --> 00:03:09.345
you freaks for continuing to support the show and keeping it ad free.
30
00:03:09.760 --> 00:03:13.380
I really do appreciate it. Easiest way to support dispatch,
31
00:03:14.160 --> 00:03:18.980
is through podcasting 2 point o apps. My favorite 2 are Fountain Podcasts and Breeze Wallet.
32
00:03:19.355 --> 00:03:34.609
They work like traditional podcast apps. You simply search Zillow Dispatch, press subscribe, load it up with sats, and you can choose how many sats per minute you think dispatch is worth, and it it it streams the sats directly to my node. You can also support the show at sildispatch.com.
33
00:03:37.625 --> 00:03:43.325
We have a BTC pay server set up there, so you can pay you can support the show via lightning
34
00:03:43.784 --> 00:03:45.004
or through Onchain.
35
00:03:45.590 --> 00:03:52.010
And, as always, I have a PayNim easy to remember. It's Odell. So if you use Sparrow or Samurais,
36
00:03:52.310 --> 00:03:52.970
you can,
37
00:03:53.670 --> 00:03:55.210
support the show via PayNim.
38
00:03:55.895 --> 00:04:00.475
As always, dispatch is broadcast via Twitch, Twitter, YouTube, and bitcoin tv.com.
39
00:04:01.335 --> 00:04:08.720
All archives are on bitcoin tv.com afterwards. You can use any podcast app to listen to the archives as well. You just search Sildispatch.
40
00:04:10.915 --> 00:04:12.855
So, yeah, thank you thank you all,
41
00:04:13.395 --> 00:04:17.095
for joining us. Again, I hope you enjoy this trip. I think it's gonna be a good one.
42
00:04:17.795 --> 00:04:26.320
So with all that said, we have Seed Signer here. How's it going, Seed Signer? Good. How are you? And we have Tony again in the studio. How's it going, Tony? It's okay.
43
00:04:26.955 --> 00:04:27.775
Fuck. Yeah.
44
00:04:28.155 --> 00:04:31.055
So, the focus today is basically,
45
00:04:31.515 --> 00:04:37.090
the seed signer, obviously, a signing device, an open source signing device, and also just discussion on open source software,
46
00:04:37.390 --> 00:04:41.330
the power of open source software, and we're gonna kinda just see where the conversation takes us.
47
00:04:41.950 --> 00:04:44.130
As always, if you wanna join the live chat,
48
00:04:45.185 --> 00:04:45.825
we're on Matrix.
49
00:04:46.865 --> 00:04:52.245
You can the easiest way to join us is to go to sil dispatch.com and click that Citadel's chat link,
50
00:04:53.060 --> 00:04:55.640
and then you just follow the instructions. You download Element,
51
00:04:56.100 --> 00:05:01.960
you make an account, and you join the chat. Now that is a live discussion that allows you to participate
52
00:05:03.865 --> 00:05:09.885
directly in the discussion as we are going, but it's also a very lively discussion throughout the week.
53
00:05:10.530 --> 00:05:14.949
So consider joining us. We have over 500 really good ride or die Bitcoiners there.
54
00:05:16.930 --> 00:05:17.430
Awesome.
55
00:05:17.745 --> 00:05:25.525
So where do you guys wanna start? We have we have a seed signer in front of us. We have the person seed signer in front of us. We have a seed QR.
56
00:05:25.825 --> 00:05:34.229
First time I ever saw that, which is right there. That's pretty fucking cool. And when I say right there, I'm just pointing to the guys in the studio, and I know none of you can see that.
57
00:05:35.955 --> 00:05:40.695
I guess I guess the first place to start is, we had NASH Bitcoiners last night,
58
00:05:41.955 --> 00:05:43.815
and I think we're all a little bit
59
00:05:44.639 --> 00:05:46.419
little bit hungover after that.
60
00:05:47.200 --> 00:05:55.095
61
00:05:55.955 --> 00:05:58.375
62
00:05:59.555 --> 00:06:04.480
What did you think? That was your 1st NASH Bitcoiners. Was how how was the experience? I loved it. I loved the,
63
00:06:05.120 --> 00:06:09.060
64
00:06:09.625 --> 00:06:14.845
recording devices, no photos. Like, what happens there stays there. I thought that was, like, a great,
65
00:06:15.465 --> 00:06:18.285
element of the meetup, but, like, the people were great,
66
00:06:19.310 --> 00:06:22.050
very engaged. Like, everybody I talked to,
67
00:06:23.389 --> 00:06:33.065
like, you could tell, like, they're interested. Like, they're paying attention. Fuck. Yeah. They're engaged, and it's, it's a great scene down here. I thought it was pretty cool that,
68
00:06:33.940 --> 00:06:45.025
69
00:06:45.725 --> 00:06:47.165
70
00:06:48.365 --> 00:06:52.720
I think that's a great opportunity because you don't you're not giving your credit card company your identity.
71
00:06:53.100 --> 00:06:57.520
You're not gonna get emails from, like, a wallet provider. You're like it's it's
72
00:06:57.854 --> 00:07:02.514
it's, a great way to get those without me knowing any anything about you.
73
00:07:03.375 --> 00:07:33.135
74
00:07:33.515 --> 00:07:43.700
man in the middles or anything like that too even. So I think it's, like, the best way to kind of, you know, get hardware. And honestly, like, with everything being open source, I'm kind of hoping that,
75
00:07:44.080 --> 00:07:51.824
76
00:07:52.125 --> 00:08:00.550
who have a reputation in in their local Bitcoin community, Like, maybe they order some parts and, like, it's a a way for them to stack sets a little bit on the side.
77
00:08:01.010 --> 00:08:02.950
78
00:08:03.475 --> 00:08:12.855
Right? Like, get a little bit extra sats for a meetup and then also support your local community. Yeah. The person that was selling the, lightning point of sale system, they weren't even,
79
00:08:13.539 --> 00:08:17.879
80
00:08:19.379 --> 00:08:32.899
So they were and they they they were honest. They're like, yeah. I'm I'm just charging, like, $10 more. Like, is that fine? I was like, yeah. Absolutely. Like, you know, thank you. I don't have to go through a shipping service or anything, so I was happy to pay it. The lightning point of sale was actually kinda funny because we had maulers in the house for that one.
81
00:08:33.360 --> 00:08:35.220
82
00:08:35.759 --> 00:08:36.240
and,
83
00:08:38.399 --> 00:08:47.714
I picked him up from the airport, went to the went to the meetup, and I got really excited. And I showed him the lightning point of sale. I was like, look how cool this is. It's offline lightning point of sale, but it uses lnurl,
84
00:08:48.649 --> 00:08:55.949
and Stripe doesn't support lnurls. So it was, like, it was very much a bittersweet thing. He's like, really, Matt? You're gonna drag me into the lnurl controversy?
85
00:08:56.250 --> 00:09:00.365
86
00:09:01.385 --> 00:09:02.765
87
00:09:04.505 --> 00:09:08.100
So where should we start? We had we've had Seed signer on the show previously.
88
00:09:10.560 --> 00:09:13.300
We went we went deep on Seed signer. I don't remember
89
00:09:13.680 --> 00:09:16.625
how long Seed signer. Do you remember how long ago that was?
90
00:09:17.665 --> 00:09:23.525
91
00:09:24.625 --> 00:09:29.600
How's the project going? It like, we things are going very well, and that's,
92
00:09:31.019 --> 00:09:36.884
primarily due to just additional people with such great skills, like, coming on board to help in various different ways.
93
00:09:37.185 --> 00:09:38.245
I don't know if,
94
00:09:38.704 --> 00:09:47.899
Keith Mukai was involved. I know that Nick. He was because Keith was on the show with you. Oh, duh. It was me, you, and Keith. That would mean that he was involved. Yeah. Me, you, and Keith.
95
00:09:48.845 --> 00:09:52.705
So Keith has really brought, like, a ton of creativity and productivity
96
00:09:53.485 --> 00:09:58.465
to the project in terms of implementing new features and coming up with creative
97
00:09:59.230 --> 00:10:01.810
ways to solve pain points that are kind of, like,
98
00:10:02.190 --> 00:10:03.330
built into the system.
99
00:10:03.950 --> 00:10:06.690
So our user experience has improved a ton, but, like,
100
00:10:07.205 --> 00:10:08.505
since then, also,
101
00:10:09.765 --> 00:10:15.519
there is a Bitcoiner in Europe. I don't wanna docs, like, specifically where he is, but he is,
102
00:10:17.519 --> 00:10:22.980
involved in manufacturing, like, a permanent long term backup solution for us where you take
103
00:10:23.425 --> 00:10:25.525
your QR code that
104
00:10:26.385 --> 00:10:26.785
that,
105
00:10:27.825 --> 00:10:32.245
is, like, just an alternative version of your seed phrase that makes it quick and easy to import
106
00:10:32.639 --> 00:10:36.740
into Seed Signers. So you take that QR code, and you can actually stamp it into metal,
107
00:10:37.440 --> 00:10:39.699
with this device using just a simple
108
00:10:40.214 --> 00:10:54.209
center punch instead of, like, some of the solutions you see where you have to stamp individual letters into, like, washers or Right. Some other kind of metal. So you just have one center punch, and you basically create handmade, like, a QR code. So the center punch is, like, these little cylinder
109
00:10:55.165 --> 00:11:06.330
thing. Right. You can buy like any hardware store or online or whatever. Yeah. There's a couple versions. There's either like one that you use kinda like caveman with a hammer, like a, you know, a hammer and a punch thing, but they're also
110
00:11:06.790 --> 00:11:11.350
automated ones that are a little bit easier to handle that work almost as good as, like, the hammer and,
111
00:11:12.805 --> 00:11:19.785
hammer and chisel type solution. But yeah. So you create this metal backup like cavemen now. We just went back to the hammer and chisel.
112
00:11:20.590 --> 00:11:25.570
But you can create this backup that is, you know, fire resistant, crush resistant, water resistant
113
00:11:26.030 --> 00:11:26.350
that,
114
00:11:26.990 --> 00:11:29.795
I'm excited for that as a great storage,
115
00:11:31.375 --> 00:11:34.435
medium for people to especially set up a multisig
116
00:11:34.895 --> 00:11:40.470
and be able to, like, be confident in their setup and preserve their keys long term that way.
117
00:11:41.250 --> 00:11:47.030
But, yeah, just other people, jumping in. There was another it was just this week. There was a guy over,
118
00:11:47.904 --> 00:11:49.764
I believe he's in somewhere in the UK,
119
00:11:50.225 --> 00:11:50.725
who,
120
00:11:51.985 --> 00:11:56.165
produced, like, a new version of the seed center enclosure that
121
00:11:56.510 --> 00:11:59.410
looks a lot like a classic 8 bit NES controller.
122
00:11:59.870 --> 00:12:04.030
And it's just so Yeah. It's, like, great design on his part. And,
123
00:12:04.785 --> 00:12:21.714
like, I haven't gotten a test one in hand, but he's been able to implement, like, a d pad instead of And it's all 3 d printed. Right? It is. Now it uses a couple different types of, 3 d printing. There's, like, the traditional type where you use the filament that people are more familiar with, but there's another type 3 d printer that's called SLA,
124
00:12:22.415 --> 00:12:28.915
and it's where you have a vat of, like, liquid resin, and you have a photostatic screen that,
125
00:12:29.370 --> 00:12:30.750
hopefully, I'm using the right terminology.
126
00:12:31.130 --> 00:12:31.790
The screen
127
00:12:32.329 --> 00:12:49.089
illuminates and basically, like, photo activates the, resin so that it hardens, like, one crazy tiny layer at a time. And the thing about those is you can produce items with, like, so much more precision and detail than you can with, like, a traditional 3 d printer. So to get that d pad,
128
00:12:49.790 --> 00:12:51.250
working with our,
129
00:12:52.269 --> 00:12:54.209
LCD hat, like, you need a really
130
00:12:54.510 --> 00:12:59.965
precise piece of equipment. So, I'm excited to see that he's launched sales of those, and,
131
00:13:00.365 --> 00:13:02.065
they've, like, gotten good feedback
132
00:13:02.660 --> 00:13:07.959
so far, and I'm excited to just see more of them in the wild. The the more we can make the device, like,
133
00:13:09.540 --> 00:13:15.095
appealing to people just visually in terms of better usability in terms of interacting with the controls,
134
00:13:15.555 --> 00:13:17.175
the more it looks like something,
135
00:13:18.115 --> 00:13:22.450
some other type of consumer electronic device that they use. Right. Like, that that bear
136
00:13:22.910 --> 00:13:27.330
137
00:13:28.545 --> 00:13:30.565
a little bit finicky or maybe intimidating.
138
00:13:31.025 --> 00:13:34.105
139
00:13:34.545 --> 00:13:36.885
any way that I can communicate to people
140
00:13:37.350 --> 00:13:38.089
that SeedSiner,
141
00:13:39.029 --> 00:13:50.025
is not just a project for, like, Bitcoin hackers or Bitcoin, like, makers. It's a project that is, like, attainable for people with, you know, very modest technical skills. It's not something that,
142
00:13:51.445 --> 00:13:55.385
people need to conceive of as this, like, super highly technical project.
143
00:13:57.150 --> 00:13:59.090
144
00:13:59.470 --> 00:14:01.090
So it was so dispatch,
145
00:14:01.630 --> 00:14:02.130
33
146
00:14:02.750 --> 00:14:04.530
was when you guys were on,
147
00:14:06.175 --> 00:14:07.635
which is block 694,094
148
00:14:10.815 --> 00:14:11.875
blocks. Mhmm.
149
00:14:13.320 --> 00:14:15.660
And then this one is block
150
00:14:16.760 --> 00:14:17.260
722-645.
151
00:14:18.920 --> 00:14:20.540
So what is that?
152
00:14:21.635 --> 00:14:22.535
I hate math.
153
00:14:23.635 --> 00:14:33.430
I'm a Bitcoiner. I'm a Bitcoiner who hates math. I'm not gonna do that, Mike. It's been it's been, like, 30,000 blocks, since we since we last had you on. I I think,
154
00:14:34.610 --> 00:14:36.925
before we go any deeper, just in
155
00:14:47.470 --> 00:14:49.089
But let's just do a quick
156
00:14:49.790 --> 00:14:51.970
overview on what the seed signer is.
157
00:14:52.670 --> 00:14:53.810
158
00:14:54.485 --> 00:14:56.904
like, I get a little finicky about the hardware wallet versus
159
00:14:57.365 --> 00:15:00.024
signer thing, but the only, like, distinction there is,
160
00:15:00.644 --> 00:15:07.990
I can see of a hardware wallet as something that has some sort of secure element technology in it that is meant as a
161
00:15:08.450 --> 00:15:15.285
technological safeguard to store your keys. So a hardware wallet is something that is intended to be storage for your keys, whereas a signer,
162
00:15:16.145 --> 00:15:20.165
it's just taking your keys and generating signatures with them. And a signer,
163
00:15:20.545 --> 00:15:29.460
I guess, kind of definitionally for me means that it's not meant to hold your private keys. Like, once the device is turned off, it's not meant to store your keys.
164
00:15:30.465 --> 00:15:32.965
Like, with seed signer so if I can just kinda
165
00:15:33.425 --> 00:15:37.205
go over the basic value proposition, seed signer does 3 things.
166
00:15:37.825 --> 00:15:42.160
It helps you trustlessly generate private keys using real world entropy.
167
00:15:42.860 --> 00:15:58.620
And then the kinda second functionality is once you And when you say entropy, it's it's randomness, which is the key element to generating secure private keys. Yeah. And I I'm you know, there's there's some debate, like, in the Bitcoin space and the larger computer science community about, like, can you really generate
168
00:15:59.480 --> 00:16:03.019
truly random data with code that was written by human beings
169
00:16:03.320 --> 00:16:14.935
and, like, technology that was made by human I'm I'm not gonna dive into that debate, but I just feel like a real great source of entropy that is accessible to everybody is just the world around us, whether that be picking,
170
00:16:15.730 --> 00:16:25.445
bit 3 9 words out of a hat or rolling dice 99 times, or we even have a a feature where you can take a digital photograph and capture the entropy from that to,
171
00:16:25.925 --> 00:16:35.440
172
00:16:37.660 --> 00:16:45.515
can accomplish a lot what hardware wallets can accomplish, the hardware wallets you can buy at, like, a website or something, but it's all off the shelf parts.
173
00:16:47.015 --> 00:16:51.835
Last time you were on, the parts came out to about $50. Now I think they're a little bit more expensive.
174
00:16:53.140 --> 00:17:02.064
175
00:17:02.605 --> 00:17:03.584
So the specific,
176
00:17:04.205 --> 00:17:07.825
Raspberry Pi 0, which is a version 1 dot 3 that we use,
177
00:17:08.260 --> 00:17:11.000
And the special thing about that version is there's no,
178
00:17:11.460 --> 00:17:15.240
Bluetooth, no Wi Fi built into it, so you can think of it as, like, this inherently
179
00:17:15.700 --> 00:17:16.919
little air gap computer.
180
00:17:17.785 --> 00:17:25.220
Those have been a little bit harder to find. I think they're running for about $30 on eBay. That's the most expensive part. Right? Right. Yeah. And then you have,
181
00:17:25.700 --> 00:17:38.425
the screen. There's a screen on it, and there's a camera. Yeah. The screen's, like, 10 to $15 depending on where you buy it. And the camera is, like, you can get those for $5 or a little bit more on Amazon depending on where you buy it.
182
00:17:39.045 --> 00:17:39.545
183
00:17:41.540 --> 00:17:45.240
Okay. So the seed signer is a stateless device, which means,
184
00:17:45.620 --> 00:17:47.400
when you unplug it from power,
185
00:17:48.260 --> 00:17:50.040
it loses all of its memory.
186
00:17:50.705 --> 00:17:53.684
So you have to enter your private keys every time you use it.
187
00:17:54.145 --> 00:17:58.005
Since last time, you have now this QR code method.
188
00:17:59.920 --> 00:18:03.780
And, you kind of talked about it earlier already, but, like, this idea that you basically,
189
00:18:05.120 --> 00:18:06.260
record your seed
190
00:18:06.560 --> 00:18:11.174
not as seed words, but you record it in a QR code format, and you have these metal
191
00:18:11.715 --> 00:18:27.105
these metal plates where you can punch in the QR code. I guess you you look at the screen. The screen shows you how to punch it, then you punch it in. And then every time you boot up the seed signer, you just use the camera to scan the QR code to load up your load up your seed. Right? Yeah. That's correct. We also have,
192
00:18:27.725 --> 00:18:34.820
193
00:18:35.280 --> 00:18:40.100
we have some templates in the repo where you can just use a a home printer, print up a QR code template
194
00:18:40.480 --> 00:18:43.405
that you then like, with a Sharpie marker, you can,
195
00:18:43.785 --> 00:18:46.765
color in the dots. Keith also also came up with a
196
00:18:47.065 --> 00:18:48.845
a super clever kind of interface
197
00:18:49.225 --> 00:18:49.725
for,
198
00:18:51.070 --> 00:19:01.565
transcribing the QR codes where, you know, it'd be kind of overwhelming to transcribe a 29 by 29 QR code dot by dot. But he breaks it down into 5 by 5 kind of like quadrants.
199
00:19:02.105 --> 00:19:04.684
And you just step through the grid 5 by 5,
200
00:19:05.385 --> 00:19:07.325
5 by 5 by 5 by 5.
201
00:19:08.030 --> 00:19:12.850
And it's it sounds a little, cumbersome maybe, but usually in about 10 minutes.
202
00:19:13.550 --> 00:19:18.645
You don't have to be super meticulous about filling in the squares. QR codes are pretty forgiving that way,
203
00:19:19.185 --> 00:19:25.285
with the built in error correction. But, yeah, you either you can still type in your your seed phrase
204
00:19:25.649 --> 00:19:33.750
using, you know, the joystick and buttons on seed center. You know, if you wanna bring a seed in that you created using a different device or that you're using on a different device.
205
00:19:34.130 --> 00:19:34.370
But,
206
00:19:35.125 --> 00:19:39.625
the QR code was just a great hack that we came up with in terms of being able to instantaneously,
207
00:19:40.565 --> 00:19:50.060
get your seat active in the device because, like you said, it's stateless. So every time you power it on It was a fucking pain in the ass. You had to Yeah. Fucking enter the seed. Yeah. That was that was a good
208
00:19:50.360 --> 00:19:50.860
point.
209
00:19:52.505 --> 00:20:03.100
210
00:20:03.640 --> 00:20:20.550
components as well where I can, like, maybe enter, like, a 25th word Yeah. Or or things like that? Just so someone does just fly by and, like, capture my QR code and run off. Right. That was important. Something that was important to us, early on, even before, I believe, we we implemented the CQR was to be able to support BIP 39.
211
00:20:21.330 --> 00:20:23.910
212
00:20:24.450 --> 00:20:27.510
But, yeah, the the important thing for people to understand with that
213
00:20:27.924 --> 00:20:34.985
is that the entropy from, like, the data from the passphrase you choose, and obviously, people wanna choose, like, a strong passphrase.
214
00:20:35.525 --> 00:20:36.505
But the the
215
00:20:37.510 --> 00:20:41.930
data within that passphrase is incorporated into the entropy that makes up your key.
216
00:20:42.310 --> 00:20:46.665
So it's not just like, an access mechanism to your key. It's actually part of your
217
00:20:46.965 --> 00:20:49.625
key. So you have to make sure you you
218
00:20:49.925 --> 00:20:55.929
somehow, either in your memory or otherwise, preserve that. But yeah. So that's a great kind of mitigating factor,
219
00:20:56.550 --> 00:20:59.370
depending on where people plan on storing and accessing
220
00:20:59.750 --> 00:21:03.450
their QR codes. It's a safeguard that some people choose, some people don't.
221
00:21:04.205 --> 00:21:07.825
But it was important to us to have that there because, like you said, like,
222
00:21:08.365 --> 00:21:09.905
depending on your OPSEC situation,
223
00:21:10.525 --> 00:21:11.425
you should obviously
224
00:21:11.780 --> 00:21:20.485
be aware of who's around you or if there's any sort of cameras, you know, in the area. Ideally, there aren't any of those things, but, you know, Bitcoiners are careful.
225
00:21:20.785 --> 00:21:21.845
So that that,
226
00:21:22.625 --> 00:21:26.565
passphrase is another kind of additional safeguard. Yeah. That's awesome.
227
00:21:27.400 --> 00:21:29.820
228
00:21:31.160 --> 00:21:32.300
with a cold card,
229
00:21:32.840 --> 00:21:36.380
and we went through the whole process, and she stamped it on steel.
230
00:21:36.765 --> 00:21:39.025
He, like, got a seed ready to go.
231
00:21:39.405 --> 00:21:40.065
And then,
232
00:21:42.685 --> 00:21:44.065
his his wife
233
00:21:46.280 --> 00:21:57.275
took a picture, and he had his like, he had written out the words on a piece of paper before he stamped it in his deal. And you could you could see it in the background of the picture, and you had to do everything over again. Oh my gosh.
234
00:21:57.815 --> 00:22:01.675
235
00:22:02.120 --> 00:22:04.220
with actually a, Spectre DIY
236
00:22:04.760 --> 00:22:10.620
of going through and putting my seeds in the metal. And it's, you know, it's long, laborious process where you have, like,
237
00:22:10.935 --> 00:22:31.445
you know, 26 stamp letters, and you're constantly pulling out different stamp letters and hammering on them. My son's helping me just kind of, like, pull the letters out for me while I'm stamping them in. And he started to say one of the words out loud. And I was like, no, no, no. We don't even say these words out loud. There's probably, like, Siri or Alexa, You know? Like, a 1000000 different live mics everywhere. Right. Right. Right.
238
00:22:32.545 --> 00:22:34.725
239
00:22:36.330 --> 00:22:37.310
Get in the bathtub.
240
00:22:38.650 --> 00:22:46.575
241
00:22:47.215 --> 00:22:49.235
hardware wallets or or signing devices,
242
00:22:49.695 --> 00:22:53.440
you know, where where does what does that current environment look like?
243
00:22:54.320 --> 00:23:00.820
I think there's also like the jade wallet. Is that is that DIY as well? And then, like, how you know, maybe if you wanted to do,
244
00:23:01.215 --> 00:23:05.715
you know, a comparison or something just like a quick little snippet. I'm not sure of all the various DIY,
245
00:23:06.655 --> 00:23:17.140
246
00:23:17.440 --> 00:23:18.820
There's, I think,
247
00:23:19.135 --> 00:23:22.435
I don't know if Jade is partly on the MD 5 stick platform,
248
00:23:23.775 --> 00:23:27.395
which is another kind of one of these single board computer kind of prebuilt,
249
00:23:27.780 --> 00:23:28.760
premade platforms.
250
00:23:29.140 --> 00:23:34.920
Somebody has actually done a version of seed center kind of on that called Crocs, I believe it is.
251
00:23:35.700 --> 00:23:36.200
But
252
00:23:37.274 --> 00:23:38.014
the Crux,
253
00:23:38.634 --> 00:23:39.134
SpecterDIY
254
00:23:39.514 --> 00:23:42.654
and Seed Center are they're the only ones that I'm familiar with.
255
00:23:42.955 --> 00:23:46.630
I I hope that we see more development in this space because,
256
00:23:47.730 --> 00:23:49.110
I kind of see
257
00:23:49.809 --> 00:23:52.789
the specter DIY and Seed Center as
258
00:23:55.285 --> 00:23:55.785
emblematic
259
00:23:56.165 --> 00:23:58.265
of a new generation of hardware wallets
260
00:23:58.725 --> 00:24:00.745
that are intended to bring
261
00:24:01.080 --> 00:24:03.419
some power back to users in terms of
262
00:24:04.039 --> 00:24:08.860
there there's a lot of trust that goes into the existing existing hardware wallet kinda landscape
263
00:24:09.265 --> 00:24:11.765
where it's this proprietary device that this,
264
00:24:12.625 --> 00:24:17.030
manufacturer has made. And and from what I understand, they're all good actors. It's just
265
00:24:17.510 --> 00:24:20.010
we, as Bitcoiners, have to trust their implementation
266
00:24:20.310 --> 00:24:21.370
of a secure element,
267
00:24:21.910 --> 00:24:23.210
and they're, you know,
268
00:24:23.590 --> 00:24:27.755
most mostly, they're open source, but we still have to trust they're kinda like hardware implementation,
269
00:24:28.375 --> 00:24:33.195
as well as some of the personally identifying information you have to give up to order one of those through the mail.
270
00:24:33.495 --> 00:24:33.995
So
271
00:24:35.310 --> 00:24:37.330
DIY may not be an option for everybody,
272
00:24:37.710 --> 00:24:42.050
but I it's super important to me that it is an option out there because it it
273
00:24:42.735 --> 00:24:46.115
allows Bitcoin users to reclaim some of their privacy
274
00:24:46.495 --> 00:24:46.995
and
275
00:24:47.934 --> 00:24:48.434
necessarily
276
00:24:48.815 --> 00:25:01.525
277
00:25:02.165 --> 00:25:17.250
and Micro Center and, like, pretty much pick up these devices as long as they're in stock. So, like, I I love the privacy aspects of it as well. I think it's super important that we have this option so we don't just say, yeah, let's everyone just use Treasure and everyone just use Ledger and then, you know, things like that.
278
00:25:18.655 --> 00:25:19.395
On the
279
00:25:20.015 --> 00:25:26.250
one hot topic that's kinda come out I guess maybe this year and last year, where do you kinda see the whole NFC
280
00:25:26.630 --> 00:25:27.130
environment?
281
00:25:27.670 --> 00:25:36.945
Is that something that you would look at as incorporated into Seed signer? I think there's been some arguments that NFC is cheaper to implement than a camera, but
282
00:25:37.325 --> 00:25:45.190
like what I have wondered about that is like you you have implemented a camera and and a very affordable one. So, you know, where do you kinda sit on the whole NOC,
283
00:25:45.730 --> 00:25:48.710
versus, like, camera thing or a combination of both? Yeah.
284
00:25:49.330 --> 00:25:53.775
285
00:25:54.315 --> 00:25:57.615
Everybody has to kinda make their their own choices in terms of,
286
00:25:58.395 --> 00:25:59.135
their preferences
287
00:26:00.080 --> 00:26:01.220
on hardware profiles.
288
00:26:01.760 --> 00:26:07.620
For me, and this is maybe a little bit of a tinfoil hat thing, but what I don't like about NFC
289
00:26:08.145 --> 00:26:10.725
is that it is communication that I can't see.
290
00:26:11.985 --> 00:26:12.485
And,
291
00:26:13.265 --> 00:26:22.920
you know, that it's it's excellent that it is, like, geographically sort of, like, restricted so that only within a certain number of meters or I don't know what the spec is. But you have to be,
292
00:26:23.700 --> 00:26:30.015
positionally close to 2 devices. You basically have to touch it almost. Right? Right. They have to be, like, super close. Yeah.
293
00:26:30.795 --> 00:26:41.330
I just, I I just don't trust information that I can't see. And you don't, like even when you're sitting there with your hardware wallet that's near your phone or your laptop, like,
294
00:26:43.395 --> 00:26:49.895
again, tinfoil hat stuff, but I I don't feel absolutely assured that those devices aren't somehow communicating without my awareness.
295
00:26:50.920 --> 00:26:51.820
With SeedSigner,
296
00:26:52.280 --> 00:26:55.500
the what I really like about the Airgap QRs
297
00:26:56.280 --> 00:26:57.020
is that,
298
00:26:57.640 --> 00:26:58.620
one, they're auditable.
299
00:26:59.155 --> 00:27:04.215
It's not a super easy process. But if you really wanted to know what information is going back and forth
300
00:27:04.595 --> 00:27:05.795
between your,
301
00:27:06.195 --> 00:27:07.415
your wallet coordinator
302
00:27:07.799 --> 00:27:12.059
and your sign of device, like, you could audit that and confirm that there's no
303
00:27:12.600 --> 00:27:15.020
nefarious sort of data or
304
00:27:16.355 --> 00:27:18.215
funny business or whatever. But
305
00:27:18.515 --> 00:27:22.215
another aspect of it that I like is, like, it's very apparent
306
00:27:22.515 --> 00:27:24.215
when the 2 devices are communicating.
307
00:27:24.710 --> 00:27:27.850
Like, the only way that SeedSigner can communicate with the outside world
308
00:27:28.630 --> 00:27:30.250
is via the camera
309
00:27:30.550 --> 00:27:50.090
that's built into it and then the screen. So if you're not, you know, using the camera to capture QR codes and you're not holding the screen up to your your laptop to relay information back to it, like, it's not communicating with anything else. And if you suspect that, like, there's something weird going on while you're relaying QR codes, you can abort that communication,
310
00:27:50.465 --> 00:27:53.525
like, immediately just by removing the QRs from the field of view.
311
00:27:55.425 --> 00:27:58.085
I'll say it one more time. Like, is that tinfoil hat territory?
312
00:27:58.465 --> 00:27:58.965
Maybe.
313
00:27:59.265 --> 00:28:06.770
But it's it's all about meeting people where they are. And me with a background kind of, like, in digital forensics and information security,
314
00:28:07.230 --> 00:28:10.305
like, you know, certain technologies that were once beliefs
315
00:28:10.845 --> 00:28:27.565
to be secure were subsequently, you know, over time, security is a cat and mouse game. There are vulnerabilities that are discovered and then solved for and then other vulnerabilities are discovered. I I just like the assurance of that. You know, I know when the 2 devices are talking to each other.
316
00:28:28.205 --> 00:28:29.105
317
00:28:30.044 --> 00:28:51.304
And and as I think just even being able to have, like, different trade offs and and vectors for each. Right? Like, you know, I think this is where, like, multi sig is really important and and, you know, we can we can say, like, I have, you know, one of each of these devices and if there's a flaw with one of them or the other or, like, you know, I keep 1 in, like, super secure storage, like, I don't even let anyone, like, get access to the actual hardware wallet
318
00:28:51.659 --> 00:28:55.360
versus, you know, versus my seed signer, which I can carry around in person,
319
00:28:56.299 --> 00:29:01.635
even without the QR code attached. Like, I can walk around without my backpack and just be fine because there's no
320
00:29:02.014 --> 00:29:13.950
loss of funds as a possibility. And then, you know, when I get home or or maybe I have my QR code in, like, 2 geographic spots, you know, when I get to the next location, then I can bust out my seed signer and and be ready to go. So,
321
00:29:14.330 --> 00:29:15.610
where do you kinda see, like,
322
00:29:16.090 --> 00:29:22.804
or maybe that's part of it. Where do you kinda see, like, Seed signer in the realm of, like, other hardware wallets and signing devices? Do you see,
323
00:29:23.365 --> 00:29:33.270
do you see it, like, maybe for yourself or for other users like them doing multisig a lot and and with with this as one of the keys in the quorum? Right. You bring up a good point that, like, not all security,
324
00:29:34.665 --> 00:29:38.685
325
00:29:38.985 --> 00:29:45.889
So Bitcoiners may have, you know, some funds that they're they carry around that are, like, akin to, like, a wallet that they have in their pocket,
326
00:29:46.990 --> 00:29:48.289
or, you know, maybe,
327
00:29:48.669 --> 00:29:53.465
some funds that maybe it's, like, a little bit more money, and you want additional safeguards kinda like a checkbook.
328
00:29:53.765 --> 00:30:00.025
And then you have, like, your long term savings, like your Huddl stash. And they're like, it totally makes sense to have different security profiles
329
00:30:00.679 --> 00:30:02.780
for each of those kinda different use cases.
330
00:30:03.160 --> 00:30:09.020
And I think, like, NFC can totally make sense for, like, everyday wallet use and even, like, a checkbook.
331
00:30:10.755 --> 00:30:11.654
But, like,
332
00:30:12.034 --> 00:30:16.455
for my long term stash, like, that's where I really start thinking about, like, vulnerabilities
333
00:30:16.755 --> 00:30:20.090
and and and ways that I can mitigate different vulnerabilities.
334
00:30:21.510 --> 00:30:22.010
But
335
00:30:22.630 --> 00:30:24.010
to get back to your question,
336
00:30:24.870 --> 00:30:25.370
SeedSigner,
337
00:30:26.155 --> 00:30:31.855
when I conceived of it and first, like, you know, started creating the proof of concept, it was created with multisignature
338
00:30:32.155 --> 00:30:32.815
in mind.
339
00:30:34.130 --> 00:30:35.590
And it was created with,
340
00:30:36.050 --> 00:30:38.870
like, long term Bitcoin storage in mind.
341
00:30:39.650 --> 00:30:42.150
So that was kinda, like, built into it. Now
342
00:30:42.665 --> 00:30:54.200
some of our users that have, like, you know, discovered the device and become more familiar with it, more comfortable with it, like, are comfortable using it for more, like, day to day spending or or more frequent spending.
343
00:30:54.980 --> 00:30:55.480
But,
344
00:30:56.659 --> 00:31:01.885
you know, we're designed kind of with the initial presumption that this is something to help people
345
00:31:02.185 --> 00:31:03.405
soar Bitcoin with,
346
00:31:03.945 --> 00:31:08.169
over the long term. And we really try to put a lot of thought and care into
347
00:31:08.630 --> 00:31:09.770
the user interface
348
00:31:10.470 --> 00:31:11.690
to make the multisig,
349
00:31:12.789 --> 00:31:13.289
experience
350
00:31:13.909 --> 00:31:16.409
as user friendly and approachable as possible.
351
00:31:17.965 --> 00:31:18.865
You know, I've I've
352
00:31:20.285 --> 00:31:21.025
kind of
353
00:31:21.645 --> 00:31:22.705
watched Multisig
354
00:31:23.005 --> 00:31:29.660
evolve over the last few years. And when, you know, when there first started to be rumblings of it, it was super technical and theoretical.
355
00:31:30.120 --> 00:31:35.115
And then once, like, you know, standards started to emerge and it became a little more feasible,
356
00:31:35.735 --> 00:31:39.915
that was the point at which, like, people had to start building tools that were accessible
357
00:31:40.535 --> 00:31:45.420
to not just highly technical users, but accessible to more like what I call everyday Bitcoiners.
358
00:31:46.160 --> 00:31:46.660
And,
359
00:31:47.400 --> 00:31:53.725
you know, Seed Center rose out of my own interest to transfer my long term Bitcoin storage from,
360
00:31:54.745 --> 00:31:59.405
what was previously like a Shamir's secret sharing type setup, which is kinda like
361
00:32:01.700 --> 00:32:03.320
a proxy of multisig.
362
00:32:04.020 --> 00:32:06.760
And I wanted to get to real multisig on the protocol.
363
00:32:07.220 --> 00:32:09.320
And when I started kinda, like,
364
00:32:09.664 --> 00:32:15.044
looking back into it, I'd set multisig away for a while because the tools are being built. And when I revisited it,
365
00:32:15.424 --> 00:32:16.164
like, Spectre
366
00:32:16.760 --> 00:32:19.880
desktop, you know, had been out for a little while and was,
367
00:32:21.000 --> 00:32:23.179
was improving and and becoming much more
368
00:32:23.480 --> 00:32:24.620
user approachable.
369
00:32:25.625 --> 00:32:26.365
And so,
370
00:32:27.545 --> 00:32:28.845
I think over time,
371
00:32:29.305 --> 00:32:29.805
like,
372
00:32:30.345 --> 00:32:32.365
the multisig tools are gonna become
373
00:32:33.080 --> 00:32:39.180
more intuitive, more user friendly because I I hate this notion that multisig is only for highly technical Bitcoiners.
374
00:32:39.640 --> 00:32:40.140
Like,
375
00:32:40.565 --> 00:32:44.025
if it's something that only highly technical Bitcoiners can use, like,
376
00:32:44.645 --> 00:33:14.180
we at Seats are doing it wrong and the people making the coordinators are doing it wrong. Like, we we we can make the tools such that they're accessible to people. And that's that's I've already strayed so far probably from your question. I Oh, no. I love it. This is awesome. But, yeah, that's that's like, we are built with multisig in mind, and we're that's something I'm personally really excited about. We have a solid link in the comments saying that a friend of his worked in a marketing startup that successfully identified and located all visitors' NFC enabled bank cards in the shop with advanced antennas,
377
00:33:15.184 --> 00:33:19.125
378
00:33:19.985 --> 00:33:21.845
a higher powered antenna. So
379
00:33:22.250 --> 00:33:24.590
seems to validate some of what you said.
380
00:33:25.930 --> 00:33:32.110
Just to, like, bring this back, I mean, so when we're talking about using a seed signer with multisig or single sig,
381
00:33:33.915 --> 00:33:39.375
the the actual flow is is rather simple. Right? So, you can use, like, a BlueWallet on your phone,
382
00:33:39.990 --> 00:33:44.330
You can use Spectre desktop, as you said, on your computer or Sparrow on your computer,
383
00:33:44.789 --> 00:33:46.330
and what happens there is
384
00:33:46.965 --> 00:33:49.544
it is showing QR codes on the screen
385
00:33:50.804 --> 00:33:52.105
to construct your transaction.
386
00:33:52.725 --> 00:33:55.304
You're scanning that with the camera on the seed signer,
387
00:33:56.450 --> 00:34:06.545
Then the seed signer's signing that transaction, showing a new QR code on the seed signer screen, which then you you scan with either your computer's camera or, your phone's camera,
388
00:34:07.165 --> 00:34:10.705
and then you broadcast the transaction. So it's a relatively simple flow,
389
00:34:11.480 --> 00:34:13.579
even if it sounds more complicated
390
00:34:13.880 --> 00:34:17.020
391
00:34:18.225 --> 00:34:23.125
labor intensive kind of flow. But feedback I've gotten from people is that, like, going through those steps
392
00:34:23.665 --> 00:34:26.805
1 by 1 of, you know, moving the
393
00:34:27.270 --> 00:34:37.085
PSBT or what I would call is, like, a rough draft of a transaction that includes most of the information, just not the signatures needed to spend the money. Like, the process of moving that from
394
00:34:37.385 --> 00:34:38.045
the coordinator
395
00:34:38.345 --> 00:34:41.725
on your laptop or on your phone into the seed signer
396
00:34:42.105 --> 00:34:42.845
and then
397
00:34:43.180 --> 00:34:46.880
adding the, keys to the device and then adding the signatures
398
00:34:47.180 --> 00:34:47.920
to the PSVT
399
00:34:48.460 --> 00:34:53.165
and then going through the process of passing that back to the coordinator that's gonna interact with the protocol.
400
00:34:54.345 --> 00:34:59.964
I have gotten feedback from people, which I love to hear that it helped them understand the basic mechanics of
401
00:35:00.309 --> 00:35:09.289
the process of multisig and a partially signed transaction. So it it breaks it down into steps that I think, for whatever reason, just resonate more with people.
402
00:35:09.915 --> 00:35:12.974
403
00:35:13.755 --> 00:35:21.180
I know when you start getting, like, really advanced multi sig, for instance, you know, some of the data can be kind of large. Is there ever a,
404
00:35:21.980 --> 00:35:31.724
qual like a picture quality issue that that you see at all with either the signing device camera quality or the screen quality on your on your seed signer? So with,
405
00:35:32.204 --> 00:35:32.944
406
00:35:33.325 --> 00:35:35.025
the camera that we have,
407
00:35:35.405 --> 00:35:42.280
in it, like, even for an inexpensive camera, it's, it's a very capable camera. Like, I I've been impressed at
408
00:35:42.660 --> 00:35:46.805
the size of some of the QR codes that we've been able to import, like, in a single
409
00:35:47.285 --> 00:35:49.224
frame with the density that they have.
410
00:35:50.565 --> 00:35:57.280
With the screen that we have, you know, with the current first kind of iteration of Seed signer, it's pretty limited. So it's 240
411
00:35:57.740 --> 00:35:59.520
pixels by 240 pixels.
412
00:36:00.060 --> 00:36:00.560
And
413
00:36:01.100 --> 00:36:04.000
with larger transactions where you're consolidating UTXOs
414
00:36:04.965 --> 00:36:08.025
or if, you know, you have a larger multisig,
415
00:36:09.365 --> 00:36:10.425
you're gonna be holding
416
00:36:10.885 --> 00:36:14.540
the seed signer screen in front of your webcam, like, for a little bit longer period of time.
417
00:36:15.100 --> 00:36:20.960
I personally have so for our development fund for the seed center project, we have a 4 of 6 multisig
418
00:36:21.580 --> 00:36:31.300
that, you know, I myself have a couple of the keys and then 4 other contributors have keys. And when we have done distributions from that, like, I sign everything with the seed signer. And so,
419
00:36:31.700 --> 00:36:38.785
it's been such that, you know, it's like I said, I'm I'm holding the screen up for a little bit longer. But once you get it dialed in, it
420
00:36:39.484 --> 00:36:40.385
it's it's
421
00:36:40.845 --> 00:36:47.164
a reliable process. It works back and forth. We've tried to improve the user experience as much as we can in terms of,
422
00:36:48.240 --> 00:36:52.180
being able to adjust the brightness of the QR codes as they're displayed on the screen.
423
00:36:52.640 --> 00:36:58.484
Sometimes at full brightness, it creates a glare that your webcam doesn't like. So you can reduce that. But there are some other
424
00:36:59.025 --> 00:37:04.645
what I'm gonna get at here is, like, it's software, and the user experience is gonna improve over time,
425
00:37:05.620 --> 00:37:08.520
as well as I'm super bullish on us getting into,
426
00:37:09.620 --> 00:37:22.455
supporting multiple different displays, especially a touch screen, because the larger the screen gets, the fewer QRs you have to pass back and forth because you can pack more information into them. What I've noticed is, from my experience,
427
00:37:23.859 --> 00:37:26.440
428
00:37:27.700 --> 00:37:29.640
has trouble. It's, like, not,
429
00:37:30.180 --> 00:37:42.070
it's not as high quality. Right. So, like, obvious and, also, it's just a little bit awkward trying to use a integrated webcam on a laptop to actually scan the QR
430
00:37:42.450 --> 00:37:42.950
code.
431
00:37:43.890 --> 00:37:52.185
Ways around that is, like, having a USB webcam, like a cheap USB webcam that you can actually, like, hold in your hand and is separate from the screen is higher quality.
432
00:37:53.125 --> 00:37:55.225
Also, just in general, like, the
433
00:37:56.005 --> 00:37:58.025
like, a new gen phone with BlueWallet
434
00:37:58.405 --> 00:37:59.625
tends to be a much
435
00:38:01.320 --> 00:38:04.300
more user friendly experience in terms of of
436
00:38:04.680 --> 00:38:08.460
437
00:38:09.005 --> 00:38:13.025
in addition to the brightness, which helps with a lot of those webcam issues, we've also
438
00:38:13.485 --> 00:38:15.665
implemented some QR density settings.
439
00:38:16.020 --> 00:38:16.920
So if you wanna
440
00:38:17.300 --> 00:38:18.339
reduce the,
441
00:38:19.300 --> 00:38:24.040
reduce the resolution of the QR so that they each frame takes a little bit less data,
442
00:38:24.505 --> 00:38:27.885
but it's a little easier to scan. That's an option that helps a lot of people.
443
00:38:28.185 --> 00:38:29.565
And, also, on webcams,
444
00:38:31.145 --> 00:38:44.055
you're right that the integrated webcams on some laptops, just for whatever reason, whether it's the drivers and the software implementation or if it's just the hardware itself isn't able to capture a good enough resolution. But, I've found, especially on Linux,
445
00:38:44.835 --> 00:38:46.055
there are some kind of, like,
446
00:38:46.515 --> 00:38:49.015
secondary driver packs where you can tweak,
447
00:38:49.960 --> 00:38:52.279
the ambient light settings and tweak the,
448
00:38:53.240 --> 00:38:57.260
the focus settings. And I've been able to get it working on some some fairly
449
00:38:57.799 --> 00:38:58.635
like, I have a
450
00:39:00.635 --> 00:39:01.195
$250, like,
451
00:39:01.835 --> 00:39:12.550
452
00:39:13.330 --> 00:39:33.655
multiple like it scatters the data across Animated QR's. Animated QRs. Yeah. I think Chris Round has, like, like, a project utilizing it and trying to do that in the Bitcoin space. It seems promising because there's also, like, like, data error handling and and check sums too. So so you make sure you're not, like, getting some bad packets of data that gets scanned. Have you looked at any of that at all? No. That's
453
00:39:34.055 --> 00:39:35.495
454
00:39:35.975 --> 00:39:37.195
for, like, transactions,
455
00:39:38.615 --> 00:39:44.650
usually, when you're passing a PSBT, there's at least 3 or 4 QR code frames. So we we do implement animated
456
00:39:44.950 --> 00:39:45.990
QR codes and,
457
00:39:46.790 --> 00:39:48.970
the standards that Christopher Allen's working on.
458
00:39:49.589 --> 00:40:00.235
For some of the coordinators that we support, we use those standards, and I I look forward to those being kinda, like, once we figure out what the best practices are in terms of, you know, error handling and how to
459
00:40:01.080 --> 00:40:04.620
how to handle those animated QRs. I look forward to just, like,
460
00:40:05.880 --> 00:40:12.505
not saying that we support these 3 coordinators, but we support any coordinator that, you know, is consistent with whatever standards emerge.
461
00:40:14.645 --> 00:40:15.785
462
00:40:16.165 --> 00:40:18.505
add back in there in this in the scanning
463
00:40:18.940 --> 00:40:19.440
discussion,
464
00:40:21.100 --> 00:40:30.465
there is there is something about on the it's not even just well, first of all, I am using Linux, so that probably has something to do with it. Like, I imagine if you have, like,
465
00:40:30.845 --> 00:40:55.560
a, like, a new gen MacBook or something, it'll have a better camera, a better software, whatever in terms of scanning. But there's something about, like, actually because when you're using a phone to scan it, you're actually using the back camera, which is a better camera. Right. And you actually can, like, point and aim. Like, you see you see what what the screen sees rather than, like, blocking your screen trying to use the inter it's just something about the integrated web cam is just,
466
00:40:57.460 --> 00:40:59.000
like, it's it's just physically
467
00:40:59.460 --> 00:41:07.015
more cumbersome in terms of trying to use it. I, like, I I see and and let's be honest. Right? Like, the majority of people that are coming in,
468
00:41:07.475 --> 00:41:13.175
to Bitcoin over the next 5 years, 10 years will probably just be using a mobile phone as their primary device anyway.
469
00:41:14.579 --> 00:41:28.255
470
00:41:28.555 --> 00:41:32.859
And then as they accumulate a little bit more Bitcoin and they start thinking about,
471
00:41:33.400 --> 00:41:35.660
seizure resistance and security issues,
472
00:41:36.119 --> 00:41:36.599
they're gonna,
473
00:41:37.559 --> 00:41:39.819
they're gonna want to, you know, set up
474
00:41:40.175 --> 00:41:45.955
something with, like, a a more secure kinda signed device or hardware wallet, and then they're gonna start to think about multisig.
475
00:41:46.494 --> 00:41:50.010
And what I'm super bullish on, like, hats off to BlueWallet
476
00:41:50.310 --> 00:41:58.170
for, like, being right now, they're kind of the only game in town in terms of a a mobile based coordinator. But I'm also looking forward to other
477
00:41:58.505 --> 00:42:00.684
wallets that will implement more flexible,
478
00:42:01.704 --> 00:42:03.484
multi sig kind of implementations
479
00:42:03.785 --> 00:42:04.525
on mobile
480
00:42:05.065 --> 00:42:07.484
so that people in parts of the world
481
00:42:08.529 --> 00:42:08.849
where,
482
00:42:09.329 --> 00:42:16.150
laptop computers and desktop computers are kind of more the exception than the rule, like people who are operating in a mobile first environment,
483
00:42:16.455 --> 00:42:18.315
like, they'll have access to more tools
484
00:42:18.695 --> 00:42:29.260
while at the same time being able to keep their private keys off of their phone. Like, that's that's just a a security no no for secure for security larger amounts of Bitcoin, as I'm sure you guys know. And,
485
00:42:29.660 --> 00:42:31.200
486
00:42:31.580 --> 00:42:36.685
487
00:42:39.145 --> 00:42:39.865
488
00:42:40.825 --> 00:43:06.520
you know, what would you say, like, the suggest the suggestion should be for just, like, a user to just get started with with Seed signer? Like, what should be the the the very basic beginner flow for it, is it using Seed signer, using a piece of paper and then using BlueWallet or like kind of how like if you were to say like how to get started in like the easiest way possible just to, like, you know, throw maybe a $100, you know, just to spending money on it. Right. No. I'm, like,
489
00:43:06.980 --> 00:43:10.755
490
00:43:11.214 --> 00:43:19.880
because I am, like, super big on test net. Like, even before you put $10 that you're gonna move around or whatever, like, people need to practice with their storage system
491
00:43:20.260 --> 00:43:23.880
and be comfortable with it. And, like, test net is perfect for that, and it's something that
492
00:43:24.245 --> 00:43:26.985
even, you know, your average Bitcoiner can get up and running
493
00:43:27.445 --> 00:43:27.765
with,
494
00:43:28.245 --> 00:43:31.625
Sparrow, like, in less than 10 minutes with a with a Testnet set up.
495
00:43:33.170 --> 00:43:36.710
In in terms of, you know, getting that kind of independent
496
00:43:37.090 --> 00:43:37.590
custody,
497
00:43:38.690 --> 00:43:40.150
savings set up in place,
498
00:43:40.515 --> 00:43:46.455
I'm super excited about an independent custody guide that I'm working on, and I kind of have the first rough
499
00:43:46.994 --> 00:43:52.900
draft finished. And I'm I'm selectively letting a few other Bitcoiners I know look at it to give me feedback.
500
00:43:53.440 --> 00:43:53.940
But
501
00:43:54.400 --> 00:43:58.345
I I anticipate that's gonna be done within, like, the next few weeks, and I'm
502
00:43:58.744 --> 00:44:07.724
bullish to get that out because I realized that, like, I've done some walk through videos on how to set up, like, a simple 203 and stuff. But in terms of a proper guide
503
00:44:08.350 --> 00:44:13.650
that people can follow kind of step by step, as well as a guide that explains some of the,
504
00:44:14.430 --> 00:44:21.865
security choices and some of the implementation choices that we've made with Seed signer, something that spells those out so people can understand those.
505
00:44:22.244 --> 00:44:26.789
I'm excited to get that out just so people can have like an exhaustive go by it. Kind of,
506
00:44:27.970 --> 00:44:32.869
I realized that we didn't have anything like that. And it was an obvious gap in our our
507
00:44:33.795 --> 00:44:38.855
ecosystem. So I'm I'm excited to get that out there. But, currently, if somebody's excited to jump into it,
508
00:44:39.315 --> 00:44:42.055
on Citadel Dispatch I I'm sorry, on bitcointv.com,
509
00:44:43.460 --> 00:44:46.039
I believe I have a simple, 2 or 3 setup
510
00:44:46.420 --> 00:44:46.920
demonstration
511
00:44:47.539 --> 00:44:54.944
that people can kinda use as a go buy, and we're gonna have more stuff coming out on the way. That's awesome. That's awesome. Yeah. What what are you excited about,
512
00:44:55.345 --> 00:45:04.020
513
00:45:04.480 --> 00:45:07.700
514
00:45:08.855 --> 00:45:09.994
But beyond that,
515
00:45:10.694 --> 00:45:12.875
our 2 developers, especially Keith Hokai,
516
00:45:13.255 --> 00:45:14.395
is deep into
517
00:45:15.095 --> 00:45:17.035
what I would call, like, the 3rd full,
518
00:45:18.270 --> 00:45:19.490
the second full
519
00:45:19.869 --> 00:45:25.170
rewrite of our software. So kinda like the 3rd iteration of seed signer's basic code structure.
520
00:45:26.125 --> 00:45:30.545
First being the proof of concept that was kinda hammered out by me, and then
521
00:45:31.165 --> 00:45:37.450
big props to Nick, who's our other kinda lead developer who came in and took my sloppy,
522
00:45:37.990 --> 00:45:41.290
ignorant spaghetti code and turned it into something that was much more performant
523
00:45:41.825 --> 00:45:43.125
and much more structured.
524
00:45:43.505 --> 00:45:46.725
And now Keith, who's kind of like a Python native,
525
00:45:47.345 --> 00:45:51.150
first language kinda guy, is doing a complete rewrite that's gonna,
526
00:45:52.490 --> 00:45:52.990
increase
527
00:45:53.450 --> 00:45:56.990
the quality of the underlying structure of the code, make it more performant,
528
00:45:57.775 --> 00:46:03.395
more to where other developers familiar with the standards can step in and use kinda, like, modular
529
00:46:04.095 --> 00:46:07.600
portions of it to implement new features or change things.
530
00:46:08.080 --> 00:46:14.420
But what is also coming with that kind of, like, new rewrite of the code is an entirely new user interface
531
00:46:15.015 --> 00:46:19.835
that we have, I wanna give a shout out to. He's a NIM on Twitter. B c one easy
532
00:46:20.295 --> 00:46:20.935
is his,
533
00:46:21.335 --> 00:46:30.920
his NIM, and he is, as I understand, like, a user interface designer. That's his daytime gig. And he has, like, been super generous with his time and expertise
534
00:46:31.545 --> 00:46:35.165
to help us overhaul our user interface to make it much more
535
00:46:35.785 --> 00:46:39.965
graphically driven, to make the the user flows more intuitive,
536
00:46:41.039 --> 00:46:42.420
And to make Seed signer,
537
00:46:43.119 --> 00:46:44.740
like, when this code comes out
538
00:46:45.359 --> 00:46:46.160
in our next,
539
00:46:46.640 --> 00:46:49.575
like, major version release, like, it's gonna transform
540
00:46:50.355 --> 00:46:55.895
the device in its current form as something that almost looks, like, DOS like when you look at it because you're selecting,
541
00:46:56.340 --> 00:47:01.320
like, these, you know, text based options on a screen. It's gonna make it look much more
542
00:47:01.700 --> 00:47:10.505
like a device you would buy as opposed to something that you would build yourself. So I think I'm excited to get people's reactions to that and for just people seeing that
543
00:47:10.885 --> 00:47:15.785
to make them more excited to take the plunge and, like, maybe consider building one themselves.
544
00:47:17.430 --> 00:47:27.605
So new that's gonna be in our 0 dot 5 dot 0 release. I'm super excited about that. And, also, coming down the line, like, 2 other things that come to mind are, multi language support.
545
00:47:28.065 --> 00:47:33.045
So Keith was the one who led the multi language support charge with Spectre desktop,
546
00:47:33.780 --> 00:47:41.240
And he's he's Alright. Has experience in that. So I'm eager to get like, we have a lot of people have reached out that are not
547
00:47:41.845 --> 00:47:50.185
English first speakers in different parts of the world who know enough English, and our menu is simple enough that they can kinda navigate through it. But I think also getting
548
00:47:50.599 --> 00:47:52.460
versions of SeedSigner out to where
549
00:47:53.000 --> 00:47:57.180
once you, you know, power it on, you select your native language, and it becomes a much more intuitive,
550
00:47:57.725 --> 00:47:58.225
approachable
551
00:47:58.525 --> 00:48:00.305
device for maybe less technical
552
00:48:00.685 --> 00:48:01.185
Bitcoiners.
553
00:48:02.605 --> 00:48:05.345
So I'm super excited about multi language support.
554
00:48:05.780 --> 00:48:07.540
And then there's also a,
555
00:48:08.500 --> 00:48:09.400
another contributor
556
00:48:09.940 --> 00:48:12.839
in our Telegram group and that I've interacted with
557
00:48:13.174 --> 00:48:23.370
who has we've already gotten it into proof of concept. If you follow me on Twitter, you've probably seen it. But we are going to be moving away from building on top of, like, a stack a a stock
558
00:48:23.750 --> 00:48:26.010
version of the Raspberry Pi operating system
559
00:48:26.390 --> 00:48:27.450
to a custom,
560
00:48:28.790 --> 00:48:29.530
build route
561
00:48:29.964 --> 00:48:30.865
Linux implementation
562
00:48:31.645 --> 00:48:35.105
where it it's gonna be a much smaller footprint, and it only contains
563
00:48:35.405 --> 00:48:37.025
kinda, like, the necessary
564
00:48:37.970 --> 00:48:39.510
building blocks that we need.
565
00:48:40.290 --> 00:48:43.090
And a couple, like, great things come out of that.
566
00:48:43.890 --> 00:48:46.390
I'm gonna screw up his name. But on Twitter, he's called
567
00:48:47.105 --> 00:48:47.605
Desobediente
568
00:48:48.465 --> 00:48:48.965
Technologico.
569
00:48:49.585 --> 00:48:50.085
Like,
570
00:48:51.025 --> 00:48:51.425
he's
571
00:48:51.905 --> 00:48:53.445
572
00:48:55.930 --> 00:49:05.744
573
00:49:06.684 --> 00:49:09.825
it makes it such that there's a static OS image
574
00:49:10.125 --> 00:49:14.144
that when you power on the device, the static OS image gets loaded into memory
575
00:49:14.570 --> 00:49:15.470
in the Raspberry
576
00:49:15.930 --> 00:49:25.905
Pi. And once it's fully loaded in the memory, you can pull the micro SD card out. So what that does just kinda right off the top is it creates an additional security assurance for users
577
00:49:26.285 --> 00:49:31.984
that if for whatever reason you still had suspicions that your private key might somehow be making it onto the memory card,
578
00:49:32.500 --> 00:49:42.235
Being able to remove the memory card now, like, gives people that additional level of insurance that there's no way that my private key can somehow be making it onto the memory card if it's physically removed from it. And
579
00:49:43.655 --> 00:49:46.795
a couple other possibilities that that opens up are,
580
00:49:47.575 --> 00:49:48.395
number 1
581
00:49:48.910 --> 00:49:52.850
is it makes it it's going to make it much easier to verify your software installation.
582
00:49:53.550 --> 00:49:55.250
So if you've set your seed signer,
583
00:49:55.790 --> 00:49:58.735
up with your, like, long term storage and maybe you haven't
584
00:49:59.535 --> 00:50:02.115
used your SeedSigner in 6 months.
585
00:50:02.655 --> 00:50:13.740
And in the back of your mind, you're like, what if someone got access to my micro SD card and put, you know, some sort of unwanted code changes on there or something? It's gonna make it much easier to where you can just pop your memory card,
586
00:50:15.000 --> 00:50:25.835
into, like, your laptop or whatever and hash a range of sectors on the memory card that are that static image that's loaded into memory. And you'll be able to get, like, an additional level of assurance
587
00:50:26.400 --> 00:50:30.420
that you're running, you know, the verified version of the software that doesn't have anything malicious,
588
00:50:30.880 --> 00:50:31.860
inserted into it.
589
00:50:32.240 --> 00:50:32.740
And
590
00:50:33.845 --> 00:50:38.744
whereas, like, you're you can currently do that with seed signer, but it right now, it's it's
591
00:50:39.045 --> 00:50:40.585
a process of, like,
592
00:50:41.120 --> 00:50:49.300
writing a new 3.5 gigabyte image to the memory card to know that you're getting, like, a clean version of the software where whereas with, like,
593
00:50:49.635 --> 00:50:50.214
this update, once
594
00:50:50.515 --> 00:50:51.175
it's implemented
595
00:50:53.155 --> 00:51:00.220
like, with the current version of ours, you can't hash it because it's a live operating system. So it's gonna change. Like, there are changes that are happening on the device
596
00:51:00.520 --> 00:51:06.380
after you boot it. So you can't go back and rehash it and try to verify that against our our verified release image.
597
00:51:06.855 --> 00:51:10.955
But with the new OS, you'll be able to do that. Also, it opens
598
00:51:12.055 --> 00:51:13.195
the door to,
599
00:51:14.240 --> 00:51:15.540
being able to move PSBTs
600
00:51:16.320 --> 00:51:18.020
with a micro SD card.
601
00:51:18.560 --> 00:51:21.060
Now we're gonna have to be very careful about
602
00:51:21.585 --> 00:51:26.245
implementing that, and I think best practices is still always gonna be air gap QRs.
603
00:51:26.785 --> 00:51:32.000
But there are some people that you seed signer that have asked about being able to move PSB Ts via,
604
00:51:33.020 --> 00:51:33.840
micro SD.
605
00:51:34.300 --> 00:51:34.800
And
606
00:51:35.100 --> 00:51:37.600
for, you know, larger, more complicated transactions
607
00:51:38.140 --> 00:51:45.575
or where you're consolidating a bunch of UTXOs or you have a larger multisig, like, I get that it's more convenient. It just has to be something that,
608
00:51:46.630 --> 00:51:51.530
that is done the right way on our end, and that people just understand that there's an additional level of
609
00:51:51.910 --> 00:51:55.290
of risk that comes with, you know, removing the memory card,
610
00:51:56.115 --> 00:52:25.620
611
00:52:26.000 --> 00:52:29.540
the I'm I'm really curious. Like, what what would be the, you know, surface
612
00:52:30.615 --> 00:52:38.234
613
00:52:39.390 --> 00:52:40.370
storage media.
614
00:52:40.750 --> 00:52:42.930
But, like, let's just say with, like,
615
00:52:43.230 --> 00:52:45.730
a Windows system because, obviously, it's less secure.
616
00:52:46.030 --> 00:52:46.850
When you
617
00:52:47.515 --> 00:53:01.450
insert a memory card into your Windows desktop, like, it automatically runs some code that recognizes that as a removal of storage volume and automatically mounts it. And there's, like, there's some just inherent security risks associated with that process.
618
00:53:01.910 --> 00:53:05.130
So, depending on how you're moving that PSPT around,
619
00:53:05.474 --> 00:53:08.135
like, it just becomes riskier. There's there's,
620
00:53:09.875 --> 00:53:13.015
room for some sort of malicious code to be able to
621
00:53:13.474 --> 00:53:13.974
execute
622
00:53:14.275 --> 00:53:24.330
623
00:53:24.835 --> 00:53:35.079
624
00:53:36.819 --> 00:53:42.994
it's important. So for your private key to leak or for malicious code to be introduced by a seed signer, practically speaking,
625
00:53:43.855 --> 00:53:52.254
626
00:53:52.812 --> 00:53:58.654
you know, and everything has trade offs. Right? And if you wanna be on the more secure side, like, your coordinator,
627
00:53:59.194 --> 00:54:01.454
so whether that's your phone or whether that's,
628
00:54:01.835 --> 00:54:09.070
a computer running Sparrow or Spectre Mhmm. It should be it should be a dedicated device. Right? Like, if you if you're using a a
629
00:54:09.710 --> 00:54:11.810
if you're using your everyday computer,
630
00:54:13.550 --> 00:54:22.234
we'll go back, like, your everyday Windows computer. Right? And, you know, a lot of people are, like, playing games on it or looking at porn or something like that. Like, there's a bunch of different,
631
00:54:23.515 --> 00:54:34.475
threat vectors that open up there because you're using your everyday computer. Right? So, like, best practice was, you should you can mitigate a lot of these risks if you're using a dedicated machine as your coordinator. And for larger amounts,
632
00:54:35.275 --> 00:54:42.415
if that's negligible cost to to just have a dedicated machine to do that, or an old phone or something that is that is dedicated, wiped.
633
00:54:43.020 --> 00:54:43.520
Ideally,
634
00:54:44.220 --> 00:54:46.800
you know, use one of these non Google Android Forks,
635
00:54:47.980 --> 00:54:50.000
and just use it only as your coordinator.
636
00:54:50.385 --> 00:54:57.685
637
00:54:58.140 --> 00:55:01.440
between you and your, your coordinator that's actively talking to the Internet.
638
00:55:02.220 --> 00:55:07.885
But one kind of, like, security thing that that I wanna point out, I I tweeted about this the other day because you see, like,
639
00:55:08.445 --> 00:55:08.945
Trezor,
640
00:55:09.325 --> 00:55:10.545
has their own, like,
641
00:55:11.165 --> 00:55:15.920
you know, application portal that you use with their you can obviously use Trezor with Electrum
642
00:55:16.220 --> 00:55:27.985
643
00:55:28.285 --> 00:55:33.985
644
00:55:34.300 --> 00:55:38.160
Like, it's a security best practice to have what they call separation of duties.
645
00:55:38.540 --> 00:55:41.280
So you don't want the entity that is,
646
00:55:41.945 --> 00:55:44.445
writing the software that you used to interact with the protocol
647
00:55:44.745 --> 00:55:59.175
to be the same entity that is writing the software that you used to interact with your private keys because there's that natural opportunity for collusion between the 2 parties. So best practice not even collusion at that point. It's just the same party. Yeah. Yeah. Exactly. So, like, yeah, you want
648
00:55:59.475 --> 00:56:02.055
you wanna have, like, that that separation of,
649
00:56:02.595 --> 00:56:06.615
entities so that there's just less likelihood of some some sort of
650
00:56:08.050 --> 00:56:08.550
malicious
651
00:56:09.010 --> 00:56:18.635
652
00:56:19.175 --> 00:56:23.355
to to their transaction. They say they're not. But They say they're not, but they are.
653
00:56:23.655 --> 00:56:25.755
654
00:56:28.869 --> 00:56:29.369
And
655
00:56:29.990 --> 00:56:31.609
and just to add on top of that,
656
00:56:32.390 --> 00:56:33.050
I think
657
00:56:33.990 --> 00:56:34.630
I think,
658
00:56:34.950 --> 00:56:46.400
Ledger Live just added support, but just by default, you know, you those aren't using your own node. You're using their node. So you're trusting them with validation, and you're you there's an additional privacy trust there.
659
00:56:46.859 --> 00:56:47.359
660
00:56:49.740 --> 00:56:50.240
Cool.
661
00:56:51.180 --> 00:56:53.119
662
00:56:54.165 --> 00:56:59.945
I'm I I like lightning a lot, and there's this lightning c sorry, lightning signer project,
663
00:57:01.285 --> 00:57:03.550
which is kind of like a way to be able to
664
00:57:03.930 --> 00:57:05.550
take the light, the the
665
00:57:06.250 --> 00:57:09.310
the seed and private keys that are, like, on a lightning note typically,
666
00:57:09.665 --> 00:57:13.765
and we're able to extract that away and have a different device or a different process,
667
00:57:14.224 --> 00:57:23.400
you know, manage all the all the keys there so it's not just in the node. Mhmm. Have you have you looked at that at all and, like, you know, possibilities of being able to integrate it with something like seed signer?
668
00:57:24.420 --> 00:57:38.590
669
00:57:39.310 --> 00:57:42.130
my first thought about that would be is, like, with lightning,
670
00:57:43.305 --> 00:57:49.245
a part of the security model is that you need high availability of keys. Right? Because if you need to, for whatever
671
00:57:49.625 --> 00:57:55.070
reason, like, close a channel quickly to to make sure that you don't, you know, somehow lose funds.
672
00:57:56.010 --> 00:58:02.825
You have to have availability that's used to a hot wallet. Yeah. It basically has to be a hot so I'm curious about, like, Or Watchtower too.
673
00:58:03.285 --> 00:58:15.369
674
00:58:15.990 --> 00:58:25.045
675
00:58:26.900 --> 00:58:35.080
I don't even know if it's it's related to Lightning who have been in contact and kinda like playing around with seats. I'm curious about some of the the possibilities with it. But,
676
00:58:35.525 --> 00:58:42.345
yeah, I what I love about Keith's rewrite of the code that he's currently going through is that it makes it much more modular
677
00:58:42.700 --> 00:58:45.440
and makes it much more to where you can insert different functionality.
678
00:58:46.140 --> 00:58:51.415
So it potentially opens the door to where you could build a version of seed signer that is PGP compatible
679
00:58:51.795 --> 00:58:53.255
to where you can use it to
680
00:58:53.715 --> 00:58:55.175
encrypt and decrypt messages,
681
00:58:55.795 --> 00:59:19.560
682
00:59:20.280 --> 00:59:21.400
Do you see any other,
683
00:59:21.800 --> 00:59:23.740
interesting non Bitcoin related
684
00:59:24.145 --> 00:59:26.965
projects that you could like use the same model for?
685
00:59:27.585 --> 00:59:36.970
Because, you know, maybe it's just PGP, but do you do you know of any others that come to your mind? Other people like we spoke a little bit before we went on air about, like possibly a password manager.
686
00:59:37.349 --> 00:59:42.095
687
00:59:42.475 --> 00:59:51.380
of FOSS and open source. Right? If somebody else has, like, an opportunity they see and they have, like, the skills like it, The code's out there, and we're happy to, like, see other people
688
00:59:51.839 --> 01:00:08.520
working with it and building with it. So, yeah, we'll just kinda keep an eye out. That's awesome. And it is, it is a MIT license, I believe. It is. That was that was one of the things that, like, I I I think I talked to Matt a little bit about when We literally talked about it on air because we were about to make the decision,
689
01:00:09.540 --> 01:00:11.700
30,000 blocks ago. That was like a
690
01:00:12.765 --> 01:00:22.780
that was probably the hardest decision I've made with regard to SeedSiner that, like, I I feel good about in retrospect, but I don't feel great about the process that we got there with
691
01:00:23.320 --> 01:00:24.060
692
01:00:24.760 --> 01:00:36.065
693
01:00:36.365 --> 01:00:39.789
I kind of solicited some opinions on Twitter.
694
01:00:40.170 --> 01:00:41.769
And I got like a lot of,
695
01:00:42.490 --> 01:00:42.990
very
696
01:00:44.490 --> 01:00:46.029
we'll call them forceful DMs.
697
01:00:47.735 --> 01:01:01.710
Just kind of like people Very strong opinion. Very strong opinions and even, like, to the point of I wouldn't call it, like, extortion, but people saying, like, you know, I was thinking about contributing your project. But if you don't go with MIT, like, well, I just can't do it either because,
698
01:01:02.410 --> 01:01:08.484
my employer doesn't allow me to contribute to things that aren't MIT or it's just not consistent with what I think software should be.
699
01:01:09.025 --> 01:01:13.970
700
01:01:14.670 --> 01:01:19.125
a unrestricted free open source license. Anyone can modify the code Right.
701
01:01:19.685 --> 01:01:25.945
Distribute the code, sell the code, use it for however they wanna do. Then I guess your other choice was GPLv3,
702
01:01:27.640 --> 01:01:29.020
which anyone can modify,
703
01:01:30.119 --> 01:01:32.220
distribute, or sell, but they have to keep
704
01:01:32.520 --> 01:01:33.579
that code GPLv3.
705
01:01:33.960 --> 01:01:34.780
With MIT,
706
01:01:35.234 --> 01:01:44.990
they can they can relicense the code however they wanna do it. They can they can even make it closed source if they want to. Right. Some people refer to GPLv3 as copy left Right. Well,
707
01:01:45.690 --> 01:01:46.430
708
01:01:46.730 --> 01:01:51.630
like, I'm sympathetic to that licensing scheme, and it, like, ultimately, it comes down to
709
01:01:52.225 --> 01:01:53.525
choices and trade offs.
710
01:01:55.265 --> 01:01:57.125
What what could happen with,
711
01:01:58.225 --> 01:01:58.725
with
712
01:01:59.025 --> 01:02:06.109
MIT is that somebody could take our code and, like, monetize SeedSigner out from under us to where they build, you know, some sort of, commercially,
713
01:02:09.435 --> 01:02:14.655
available product that uses our code, but that's that's just kinda like that's that's the nature of the beast. Like,
714
01:02:15.275 --> 01:02:16.795
we're so focused on
715
01:02:17.460 --> 01:02:40.860
716
01:02:41.340 --> 01:02:44.320
I mean, you should just never use a closed source hardware wallet.
717
01:02:44.855 --> 01:02:51.515
But meanwhile, you know, Ledger is probably the most successful hardware wallet in the business, and they are closed source, so or partially closed source.
718
01:02:51.815 --> 01:02:52.555
719
01:02:53.780 --> 01:02:54.280
it's,
720
01:02:54.580 --> 01:02:56.920
you know, props to the other projects for being,
721
01:02:57.540 --> 01:03:02.440
open source. We talked about this a little bit at the meetup last night, but I kind of see
722
01:03:03.015 --> 01:03:04.214
seed signer as
723
01:03:04.615 --> 01:03:08.795
and and some of the DIY projects as, like, kind of a new generation of hardware wallets
724
01:03:09.335 --> 01:03:09.835
that
725
01:03:10.260 --> 01:03:13.079
are the 2nd the 2nd generation is kind of these,
726
01:03:14.500 --> 01:03:16.920
secure element enabled USB connected,
727
01:03:18.005 --> 01:03:22.105
purpose built and designed devices that are, you know, sold by companies.
728
01:03:22.484 --> 01:03:27.065
And when they first were made available, like, I don't wanna knock them. Like, they were huge security,
729
01:03:27.510 --> 01:03:31.530
730
01:03:32.310 --> 01:03:36.035
like, it used to be before Reddit completely died, like, r/bitcoin.
731
01:03:36.655 --> 01:03:38.595
It was just, like, every day, you would see,
732
01:03:39.855 --> 01:03:50.839
733
01:03:51.174 --> 01:03:51.674
when,
734
01:03:53.174 --> 01:04:02.230
Trezor came out and when other hardware wallets started to come out, like, hugely forward, that gave people a ton of security, but, like, security is an evolution and it's a process.
735
01:04:02.690 --> 01:04:05.109
And I think, like, a few things falling into place
736
01:04:05.490 --> 01:04:09.965
are creating this, like, new evolution of the security process that has an emphasis
737
01:04:10.505 --> 01:04:11.325
on multisig.
738
01:04:12.345 --> 01:04:17.725
Because, frankly, a lot of the the current wallets, I've heard feedback that they're not created with multisig,
739
01:04:18.730 --> 01:04:21.390
first in mind. So an emphasis on multisig
740
01:04:21.770 --> 01:04:22.810
and emphasis on,
741
01:04:24.570 --> 01:04:25.070
like,
742
01:04:27.885 --> 01:04:35.750
publicly available components, I guess you'll say. Building you can build a signed device from non Bitcoin specific components so you don't have to give your information to a distributor
743
01:04:36.050 --> 01:04:40.390
or hardware wallet so you can maintain that degree of privacy. Right. Like, we saw with Ledger,
744
01:04:40.770 --> 01:04:47.655
745
01:04:48.755 --> 01:04:59.870
746
01:05:00.395 --> 01:05:05.615
747
01:05:06.155 --> 01:05:13.920
So, like, you're also using your credit card, which is your credit card. Is literally just corporate surveillance card. Right. So I see, like, multisig first.
748
01:05:14.220 --> 01:05:28.280
749
01:05:28.740 --> 01:05:31.800
you know, is something gonna happen if you have a USB connected,
750
01:05:32.500 --> 01:05:39.545
hardware wallet? Like, in great likelihood, their security precautions are adequate. But as we reflect Like, I don't think we've seen a single
751
01:05:40.725 --> 01:05:44.825
752
01:05:45.440 --> 01:05:48.180
like the ledgers and the treasures, we haven't seen a
753
01:05:49.040 --> 01:05:55.924
USB style attack Like a USB. Actually executed in the real world. Right. Now what I would throw out, like, this is my,
754
01:05:56.464 --> 01:05:57.684
755
01:05:58.065 --> 01:06:02.005
is like, as someone who previously worked in law enforcement As a previous spook.
756
01:06:02.545 --> 01:06:03.924
You can trust me now.
757
01:06:05.410 --> 01:06:05.990
See you
758
01:06:06.470 --> 01:06:06.970
see
759
01:06:07.450 --> 01:06:07.950
you
760
01:06:08.430 --> 01:06:08.930
later.
761
01:06:09.410 --> 01:06:14.995
The the federal government like has and I've, you know, during my career had access to it, like they have
762
01:06:15.955 --> 01:06:17.415
for like the Android platform,
763
01:06:18.035 --> 01:06:18.855
for the,
764
01:06:19.395 --> 01:06:28.660
iOS platform. And there's nothing to say that they don't have access to 0 day for 1 or more of the commercially available hardware wallets that we just don't know about. Right. That could leverage either,
765
01:06:29.440 --> 01:06:29.940
USB
766
01:06:30.855 --> 01:06:35.275
connectivity or that could just be getting your hands on the device and taking it apart to exploit the hardware.
767
01:06:35.735 --> 01:06:38.329
768
01:06:39.130 --> 01:06:40.510
I think rightfully so.
769
01:06:41.130 --> 01:06:45.069
There's criticism leveled at Ledger here throughout this discussion, but
770
01:06:45.595 --> 01:06:48.654
they do deserve props for their Ledger Don John
771
01:06:50.635 --> 01:07:00.880
security team where they basically are just taking these commercial hardware wallets, their own hardware wallets and other hardware wallets, and they're trying to compromise them. They're spending 100 of 1,000 of dollars trying to compromise them
772
01:07:01.365 --> 01:07:03.704
and releasing their findings rather than
773
01:07:05.684 --> 01:07:25.805
which is which is what you wanna see. You wanna see, you know, good actors in the space. You wanna see positive actors in the space trying to compromise all these things. So we know, you know, what kind of vulnerabilities are out there rather than getting surprised by 0 days. Or Yeah. That's a great service just to leverage that kinda, like, white hat adversarial thinking to expose vulnerabilities
774
01:07:26.539 --> 01:07:27.920
775
01:07:28.380 --> 01:07:29.519
bad actors do.
776
01:07:31.259 --> 01:07:32.000
777
01:07:32.700 --> 01:07:33.819
Yeah. Is there, like
778
01:07:34.484 --> 01:07:56.355
yeah, have have you or anyone else, like, done like, what are the analysis here? Like, basically, once you unpower this device, like, the the seed is gone, the seed is wiped, right? Right. But in theory, like, what if someone, you know, were to get their hands on it, like, while it was on, right? So like, basically, the model here, like, we can assume like, you know, someone gets the ledger and someone gets the treasure like some people in this space will say,
779
01:07:56.655 --> 01:08:19.920
assume that if someone gets their hands on it, it's compromised and and you know, those are completely powered off, you know, in their default state. So assume it's compromised, but like I love this model because like, you know, assume, once you unplug it, like, there's nothing to be compromised. Right? Like, it's it's it's safe. Right. So the way it's engineered is that, when you enter your private keys into it, they're stored as temporary Python memory
780
01:08:20.619 --> 01:08:24.639
781
01:08:25.085 --> 01:08:36.820
So and we've gone to additional lengths to make sure that, like, through virtual page file or swap file, like, your keys don't somehow get involved in that and end up being written to the memory card. Like, we we disable virtual paging.
782
01:08:37.920 --> 01:08:41.219
But, yeah, your keys exist in RAM, and RAM is
783
01:08:41.715 --> 01:08:46.054
by nature, a volatile memory, meaning that once power is removed from the the media,
784
01:08:46.355 --> 01:08:51.330
like, the information that's stored on it just dissipates and goes away. But you you still,
785
01:08:52.990 --> 01:08:54.210
786
01:08:55.070 --> 01:08:57.410
your seed signer physically secure because,
787
01:08:57.915 --> 01:09:02.975
you you still have, like, evil maid attacks. I know maids get a bad rap, because of that term.
788
01:09:03.355 --> 01:09:14.430
But if someone, like, gets access to your device, they could they they might not be able to pull the seed from it, but they could compromise it and load up, like, a malicious version of SeedSauna. The next time you put the seed in,
789
01:09:15.515 --> 01:09:20.255
they can maybe store it or take it, or they could even there could be a a physical attack where
790
01:09:20.715 --> 01:09:38.720
they add, you know, some kind of transmission mechanism. So, like or it looks like they just swap out the device. So, like, they take your device and put a compromised one that maybe has Wi Fi in it, and then they can just transmit it out. So you wanna keep it physically secure. You want it you don't want it to be out in the open where someone can get access to it.
791
01:09:39.520 --> 01:09:43.460
And that that goes for all hardware wallets. But, I would say particularly,
792
01:09:44.880 --> 01:09:45.700
probably particularly,
793
01:09:46.875 --> 01:09:53.775
the seed signer because it, you know, doesn't have a secure element on it. Right. I'd I'd kinda compare it to that private but not secret
794
01:09:54.680 --> 01:09:58.220
795
01:09:59.160 --> 01:09:59.660
It
796
01:10:00.680 --> 01:10:01.580
it it doesn't
797
01:10:02.025 --> 01:10:07.805
require the absolute security that you would give to your private keys, but, like you're saying, you definitely don't wanna leave it out, you know, for
798
01:10:08.185 --> 01:10:14.270
any sort of mal intended third party to interact with it because they could jack with, like you said,
799
01:10:15.050 --> 01:10:18.030
creating some sort of mechanism that does capture the private keys,
800
01:10:18.395 --> 01:10:21.295
or they could jack with your PSB Ts, or they could,
801
01:10:21.835 --> 01:10:24.494
like you said, with the hardware, put something else in there.
802
01:10:25.890 --> 01:10:27.590
Yeah. Just to go back to,
803
01:10:27.970 --> 01:10:30.950
like, the the mitigator for that is, obviously, if you
804
01:10:31.330 --> 01:10:38.764
feel like you left your seed signer out or somebody used it that you don't feel is, like, a trusted third party or anything like that, then
805
01:10:39.625 --> 01:10:44.364
the solution is just to zero out the memory card and write a new fresh version of software, and that's gonna mostly
806
01:10:44.820 --> 01:10:45.320
counteract,
807
01:10:45.780 --> 01:10:52.120
808
01:10:52.625 --> 01:10:53.364
809
01:10:54.465 --> 01:10:56.164
Right. Never be too paranoid.
810
01:10:56.704 --> 01:10:57.364
I agree.
811
01:10:58.065 --> 01:11:01.045
812
01:11:01.370 --> 01:11:02.270
I wanted to
813
01:11:02.650 --> 01:11:08.510
actually I was I was gonna frame it a little bit differently because seed signer used to be the person who's sitting in front of us,
814
01:11:09.195 --> 01:11:11.855
used to be, like, a digital forensics guy for,
815
01:11:13.034 --> 01:11:14.954
the police, for the cops. And,
816
01:11:15.434 --> 01:11:20.060
he would literally go in and and, you know, look at computers and stuff that criminals had,
817
01:11:20.600 --> 01:11:28.114
to try and see what kind of information was there. And I I thought it's kind of an interesting dynamic that, like, whoever replaced him, there's some, like, young
818
01:11:28.415 --> 01:11:39.900
young seed signer replacement. And he's, like, going into he he's, like, he's seeing a seed signer on the table, and he's trying to compromise it. Right? He's for It's come full circle. He's like, WTF is this first.
819
01:11:40.465 --> 01:11:41.844
What is this nest controller?
820
01:11:42.864 --> 01:11:43.364
Exactly.
821
01:11:43.985 --> 01:11:46.644
822
01:11:47.640 --> 01:11:48.140
the
823
01:11:48.760 --> 01:11:58.264
the points you guys brought up with hardware wallets and the the PIN security on them. Like, that's something I've seen firsthand from my time in digital forensics is, unfortunately, people don't use,
824
01:11:59.205 --> 01:12:01.304
really secure pins just as a habit.
825
01:12:01.685 --> 01:12:15.635
Somebody who has, like, either had knowledge of or had to, like, brute force, like, pins on people's Android phones or their iPhones. Like, people use the most brain dead stuff. Like, they're you know, it's always their date of birth, last four of their Social Security number. Or 1111?
826
01:12:16.255 --> 01:12:19.375
Yeah. Or 1234, you know, whatever. And that's actually like some of the,
827
01:12:20.255 --> 01:12:22.034
some of the tools that
828
01:12:22.640 --> 01:12:25.300
are created to exploit, like, iPhones and stuff,
829
01:12:25.840 --> 01:12:26.340
they
830
01:12:27.360 --> 01:12:30.515
have, like every time they crack, like,
831
01:12:30.895 --> 01:12:38.275
a a a pin code, it gets added to a database. And the next phone you try to crack it, the first thing it runs through is the database of busted pins
832
01:12:38.850 --> 01:12:44.950
with the theory being that, like, we're all human beings, and we tend to think alike. So if one person used a particular pin,
833
01:12:45.665 --> 01:12:52.670
be it because it was a certain visual pattern on their phone or whatever, like, somebody else might have thought of that. So it's a game of is terrible entropy.
834
01:12:53.870 --> 01:12:59.410
835
01:13:00.735 --> 01:13:05.635
I mean, a lot of phones have settings where, like, 10 wrong pin codes wipes the device or
836
01:13:06.335 --> 01:13:07.715
837
01:13:08.335 --> 01:13:14.440
838
01:13:15.620 --> 01:13:18.440
And that's why I think it's always important to remind the freaks,
839
01:13:18.935 --> 01:13:29.630
that, like, don't get overwhelmed with this stuff. It's it's, you know, you're never gonna have a perfect solution. It's always gonna be a constant learning experience and evolution. You're you're really just trying to do little steps to continually,
840
01:13:30.650 --> 01:13:31.790
reduce that risk,
841
01:13:32.890 --> 01:13:34.910
of coin theft or or privacy.
842
01:13:35.955 --> 01:13:37.735
Bitcoin q and a has a good question,
843
01:13:38.515 --> 01:13:40.695
in the comments. He goes, notoriously
844
01:13:40.995 --> 01:13:48.570
difficult for false projects, but does Seed Signer have any alternative revenue stream plans just to ensure project longevity?
845
01:13:49.350 --> 01:13:52.055
846
01:13:52.995 --> 01:13:59.655
847
01:14:00.160 --> 01:14:18.955
848
01:14:20.850 --> 01:14:33.585
849
01:14:34.605 --> 01:14:35.185
or individual
850
01:14:36.045 --> 01:14:41.539
donations, or if it's corporations giving donations, or if it's these foundations like HRF or
851
01:14:42.000 --> 01:14:58.140
Brink or OpenSats, which I cofounded. Like, how do you how do you look at revenue? And do you do you have, like, a business model that you're trying to attach to this, or is it gonna only be donation funded? So just in terms of the the larger funding question, I kind of view that in terms of a problem
852
01:14:58.520 --> 01:15:00.540
853
01:15:00.905 --> 01:15:02.685
and it's not, like, solved yet,
854
01:15:03.385 --> 01:15:04.445
but we're getting there,
855
01:15:05.305 --> 01:15:12.130
just to give people kinda, like, some insight into, like, how we've historically been funded, and then we can talk forward from that.
856
01:15:13.790 --> 01:15:18.610
First off, like, we have a, I think I mentioned it before, a jointly managed multisig
857
01:15:19.475 --> 01:15:22.375
wallet that is what we call our develop development fund.
858
01:15:22.675 --> 01:15:23.415
And so
859
01:15:24.275 --> 01:15:34.900
I tried to give a lot of thought to how we compensate people who contribute to our project, and I tried to approach it from, like, an early stage venture kinda model
860
01:15:35.280 --> 01:15:39.145
to where every time we release kinda like a major version of the software,
861
01:15:39.605 --> 01:15:41.065
we have essentially a scoreboard
862
01:15:41.525 --> 01:15:43.145
that scores people's contributions
863
01:15:44.005 --> 01:15:56.185
and awards new points to, like, a scoring pool based on, like, new features that are added and stuff like that. It's not a perfect system, but it it's intended to be, like, some way of, like, rewarding people for,
864
01:15:57.045 --> 01:16:00.265
what they're doing for the project. So when we release a new version,
865
01:16:00.790 --> 01:16:11.185
we take some funds from this development fund, and we basically split them up according to the proportions of contributions as they exist on the score board. So people accumulate points over time.
866
01:16:13.485 --> 01:16:20.120
The the challenge with that is just raising, you know, donations at large from, you know, our user base. And some people,
867
01:16:20.980 --> 01:16:25.000
you know, have been very generous. I'm sure there are other people that use it and haven't donated yet.
868
01:16:25.380 --> 01:16:25.700
But,
869
01:16:26.180 --> 01:16:27.080
it has been
870
01:16:27.605 --> 01:16:31.385
a good mechanism to provide some sort of reward for open source developers,
871
01:16:32.645 --> 01:16:36.905
especially people who are doing this kind of in their spare time, not as their full time gig.
872
01:16:38.440 --> 01:16:39.820
We recently had,
873
01:16:40.120 --> 01:16:43.100
like, the opportunity at the beginning of the year where Keith,
874
01:16:43.800 --> 01:16:48.465
previously had, like, from what I understand, like a non Bitcoin related job. He primarily works contracts,
875
01:16:48.845 --> 01:16:53.585
and so he's contracted by a particular company for a set period of time to provide development services.
876
01:16:54.280 --> 01:16:57.580
And he had a contract that was expiring, and he was looking for a new gig.
877
01:16:57.960 --> 01:16:58.460
And,
878
01:16:59.880 --> 01:17:02.380
Spectre desktop took him on for about 3 months,
879
01:17:02.785 --> 01:17:15.320
as a contract gig. So he did some, like, very cool development work for them. But as of the beginning of this year, like, his contract with them was up, and he was looking again for a new gig. And so we started just kinda, like, raising funds
880
01:17:15.780 --> 01:17:19.960
based on the idea of his previous contributions and some of the great,
881
01:17:20.765 --> 01:17:22.545
innovation that he brought to our project.
882
01:17:23.005 --> 01:17:23.505
And
883
01:17:24.205 --> 01:17:24.765
there were,
884
01:17:25.245 --> 01:17:31.290
some very cool companies, individuals that reaped up reached out, some of which were anonymous, but some of which, like,
885
01:17:32.070 --> 01:17:40.135
coin ATM radar. And I'm I'm gonna do a horrible job at remembering specific people that that contributed to this, but Keith has done a great job of acknowledging them.
886
01:17:41.315 --> 01:17:42.695
And the the
887
01:17:43.074 --> 01:17:46.614
if you think of those as donations to our project, they've actually been
888
01:17:47.150 --> 01:17:48.450
donations to Keith
889
01:17:48.830 --> 01:17:52.530
that I don't have a handle in. It's between Keith and the people that are gifting that money.
890
01:17:53.070 --> 01:17:55.730
And, generally, those gifts have come without strings attached
891
01:17:56.335 --> 01:18:04.435
to where people, you know, are super excited about the possibilities that he brings to seed signer, and they're willing to give him kind of open ended money just to focus,
892
01:18:05.239 --> 01:18:07.500
a lot of his day to day work on SeedCenter.
893
01:18:07.880 --> 01:18:13.900
After that, he set up a BTC pay server and said, like, hey. I'd really like to focus on SeedCenter for the Q1 of 2022.
894
01:18:14.985 --> 01:18:15.485
Would
895
01:18:15.945 --> 01:18:18.765
any people in the Bitcoin ecosystem be willing to,
896
01:18:20.425 --> 01:18:24.670
donate some funds to allow me to do that? And like much to every one of the community's credit,
897
01:18:25.230 --> 01:18:28.610
there were smaller donations that came in, and then we actually had, like, a 12 or
898
01:18:28.910 --> 01:18:31.330
$13,000 equivalent donation in Bitcoin that came in.
899
01:18:31.949 --> 01:18:35.285
That's an anonymous donation, but, like, it's it's amazing.
900
01:18:36.465 --> 01:18:38.725
So Keith will be working on SeedSigner
901
01:18:39.265 --> 01:18:41.925
full time through the end of Q1 2022.
902
01:18:43.860 --> 01:18:46.680
Moving forward, like funding is a general question,
903
01:18:48.100 --> 01:18:50.280
I can't totally close the door to
904
01:18:50.954 --> 01:18:53.934
creating, you know, a purpose built retail available
905
01:18:54.235 --> 01:18:56.574
version of SeedSigner, but what I can tell you
906
01:18:56.875 --> 01:19:00.014
is that the open source source off the shelf
907
01:19:00.489 --> 01:19:07.230
ethos of our project is very important to us. And regardless of anything that we would do with some sort of retail available device,
908
01:19:07.745 --> 01:19:09.365
like, we are still going to
909
01:19:09.825 --> 01:19:12.005
maintain and build new functionality into,
910
01:19:12.545 --> 01:19:14.645
the the do it yourself version because,
911
01:19:15.345 --> 01:19:15.845
like
912
01:19:16.305 --> 01:19:16.805
and
913
01:19:17.590 --> 01:19:19.989
huge credit to Alex Gladstein who,
914
01:19:20.550 --> 01:19:21.369
915
01:19:21.750 --> 01:19:28.585
916
01:19:29.365 --> 01:19:37.140
for recognizing kind of the value of SeedSigner for people in parts of the world where Bitcoin use is either discouraged or even outright banned.
917
01:19:37.520 --> 01:19:41.220
People who want to use Bitcoin as a way of just preserving their
918
01:19:41.785 --> 01:19:51.165
savings ability or even to fund dissident activities, like seed center or something that's available to them that they can build privately in secret without the self off the shelf components
919
01:19:51.590 --> 01:19:54.810
to be able to store their Bitcoin in a more secure way.
920
01:19:55.430 --> 01:20:02.595
It doesn't involve them having to try to source a hardware wallet or anything like that. And having that ability out in the world,
921
01:20:03.455 --> 01:20:08.035
you know, the the attending the HRF conference last year was a very eye opening experience to me.
922
01:20:09.440 --> 01:20:20.325
That's a great event. To get a glimpse of, like, things going on in other parts of the world that, you know, myself as an American don't have a lot of exposure to in the media and just in, you know, news sources or,
923
01:20:20.865 --> 01:20:22.725
persons that are within my circle.
924
01:20:23.345 --> 01:20:23.845
So
925
01:20:24.945 --> 01:20:31.880
it's a long winded way of saying that functionality and that ability to privately and secretly build a seed signer is extremely important to me personally,
926
01:20:32.180 --> 01:20:39.455
and it's something that I will not steer the project away from. Like, I've had people who live in the Middle East that have reached out to me privately,
927
01:20:40.395 --> 01:20:50.775
that, you know, talk about why they love the device because they can build it in private and not have, you know, anyone knowing that they're saving with Bitcoin when they would otherwise have trouble obtaining a hardware wallet and don't wanna use
928
01:20:52.775 --> 01:20:54.395
their phone because that's inherently less secure, yada yada yada. So,
929
01:20:55.975 --> 01:21:02.770
930
01:21:03.470 --> 01:21:03.970
donate.
931
01:21:06.350 --> 01:21:09.425
I mean, I have a couple thoughts here. First of all, I mean, dispatch
932
01:21:15.665 --> 01:21:22.250
emulate kind of what open source projects have to deal with in terms of funding. So we don't have Azure sponsors. It's all community funded.
933
01:21:22.870 --> 01:21:24.890
I consider it a free and open project.
934
01:21:25.355 --> 01:21:27.855
People can cut it up. They can torrent it.
935
01:21:29.035 --> 01:21:31.615
They can do whatever they want, with dispatch.
936
01:21:33.720 --> 01:21:35.020
So seed signer.com/
937
01:21:35.560 --> 01:21:36.060
donate.
938
01:21:36.600 --> 01:21:44.255
One thought is, first of all, like, on the splash screen when you first load up the seed signer Right. Like, you should just tell people seed signer.com/
939
01:21:44.715 --> 01:21:50.770
donate to support the project every time they load it up. Like, I feel like just a nice reminder, like, this is a community funded project.
940
01:21:51.070 --> 01:21:57.090
A lot of people wanna support it. They just they need a little bit of a reminder. Right? So I think that's kind of a cool idea.
941
01:21:57.535 --> 01:22:02.595
The second thing is, I'm I mean, I know we've talked about this privately, and I'm curious if your thoughts have evolved.
942
01:22:04.095 --> 01:22:06.755
Like, what are the thoughts on in terms of, like,
943
01:22:07.659 --> 01:22:13.760
ads or sponsors or something? Like, is is is that a thought, like, to on the on the splash screen? Yeah.
944
01:22:14.355 --> 01:22:17.655
Show a sponsor logo or something like that. That's something that we're
945
01:22:17.955 --> 01:22:18.915
946
01:22:19.554 --> 01:22:31.985
We would have to give careful in terms of a corporate sponsor, we'd have to give careful thought and consideration to the values of the company that was offering the sponsorship as well as, like, the the level of sponsorship that they'd be,
947
01:22:32.445 --> 01:22:34.445
offering to be able to get the splash screen.
948
01:22:35.485 --> 01:22:38.770
Another interesting kind of idea that came up was the screensaver
949
01:22:39.070 --> 01:22:43.970
on SeedSiner, which I think initiates after a minute or 2 of of device,
950
01:22:44.995 --> 01:22:45.895
device inactivity.
951
01:22:46.435 --> 01:22:49.255
So one idea that came up was, like, for
952
01:22:49.795 --> 01:22:52.680
plebs or people in the Bitcoin e ecosystem Clubs.
953
01:22:53.160 --> 01:22:53.980
Damn it.
954
01:22:54.440 --> 01:22:58.140
955
01:22:59.240 --> 01:23:07.285
956
01:23:07.745 --> 01:23:19.125
screen saver comes up, like, what if it every time it bounces off? Because we have if people haven't seen it, like, it has a very classic, like, Microsoft kind of screensaver feel I've been staring at it the whole year. Where you stare at it waiting for it to bounce,
957
01:23:19.605 --> 01:23:23.465
like exactly into one of the corners and you feel like excited if it gets close to that.
958
01:23:23.925 --> 01:23:26.745
What if every time it bounces up against like one of the perimeters,
959
01:23:27.060 --> 01:23:29.000
it were just display a different,
960
01:23:30.020 --> 01:23:33.080
NIM or identity that was chosen by the person who
961
01:23:33.460 --> 01:23:43.105
donated or some sort of message? And maybe That's cool. Maybe that was, something that just lasted for a given, like, major version release, and then we'd kinda reset it, make it a new version of
962
01:23:43.430 --> 01:24:02.320
so Contribute this amount and your message or you can get a in the screensaver kind of thing. And this I like that idea. I like that idea better than an ad or sponsor. This this kind of stuff is, like, what I'm talking about. We're, like, you know, we're in the process of gaming these ideas out, not just us, like anybody working open source just to creatively come out
963
01:24:03.500 --> 01:24:06.960
with ways of incentivizing people to make support
964
01:24:07.345 --> 01:24:11.685
and to recognize people that make support, like in the way that they like to be
965
01:24:12.145 --> 01:24:13.605
recognized. It's just
966
01:24:14.660 --> 01:24:22.500
we'll get it figured out over time. And I think this is one of the things that, thankfully, like, Bitcoin really does fix this, like, beyond the meme, like, the ability to,
967
01:24:23.355 --> 01:24:25.295
send censorship resistant money
968
01:24:26.875 --> 01:24:31.409
in flexible dominations anywhere in the world to anybody you want to, like, No middleman.
969
01:24:31.710 --> 01:24:39.489
Yeah. This this, like, this can fix open source and the open source funding problem. So I'm I'm bullish on, like, finding solutions moving forward.
970
01:24:40.975 --> 01:24:42.275
971
01:24:42.735 --> 01:24:55.140
besides funding, are there any other ways that, like, people can get involved in the project or, like, you know, maybe some of the needs that you're specifically looking for right now, whether if it's, you know, Python developers or, you know, you know, people that, you know,
972
01:24:55.600 --> 01:24:57.380
manage projects or documentation,
973
01:24:57.680 --> 01:25:04.925
things like that. Like, what are your, like, more specific, needs right now that people can help out with? I am, like, forever looking for,
974
01:25:05.545 --> 01:25:10.330
975
01:25:11.190 --> 01:25:12.890
excuse me, multi language support.
976
01:25:13.910 --> 01:25:18.170
I I'm always excited to have people do walk through demos and videos or people who create documentation.
977
01:25:18.935 --> 01:25:25.835
But, like, the ways that people have found to contribute to the project have been amazing. There's a a guy from South America who
978
01:25:26.240 --> 01:25:37.195
people have seen, like, the baseball baseball card style, QR cards that we have where you can manually transcribe your QR code that way. Like, that was created by a guy who does graphic design on the side in Brazil.
979
01:25:38.055 --> 01:25:41.435
Or our website was built and maintained by a guy from the Philippines
980
01:25:42.050 --> 01:25:44.630
who just saw Seed Signer, was excited about it.
981
01:25:44.930 --> 01:25:46.630
And he's actually recently,
982
01:25:47.250 --> 01:26:00.790
launched also, like, a, a sales portal to where, like, it's tough for me or people in Europe to ship devices or to ship hardware kits to people in Asia. So now, like, people in Asia have a source where they'll be able to buy a kit.
983
01:26:02.530 --> 01:26:04.310
People who just generally, like,
984
01:26:05.489 --> 01:26:07.590
you know, it it it sounds like,
985
01:26:07.890 --> 01:26:08.550
you know,
986
01:26:09.155 --> 01:26:12.775
not trivial, but, like, people would just tell other people about seed signer. Like, that's
987
01:26:13.155 --> 01:26:26.305
we don't have any kind of advertising budget. We don't have, like, you know, I I'm on Twitter, but it's not like we have a social media offensive or anything. So, like, at meetups, just people Bitcoiners talking to other Bitcoiners, that is our primary way
988
01:26:26.865 --> 01:26:36.630
of spreading the word about what we're working on is, like, people just saying, hey. Like, I'll talk for a few minutes at a meetup about seed signer and point people to, like, the website and the repo and stuff.
989
01:26:37.250 --> 01:26:44.355
That's such a it's this is, like, truly a grassroots thing. I that term grassroots is, like, overused to some degree, but, like, we are just
990
01:26:44.835 --> 01:26:48.614
people that are trying to build, like, a kick ass little sign device that,
991
01:26:49.475 --> 01:26:52.855
provides value to others in the Bitcoin ecosystem. So there's,
992
01:26:53.300 --> 01:26:56.280
like, a myriad of different ways to contribute to that.
993
01:26:57.780 --> 01:26:58.280
994
01:26:59.620 --> 01:27:01.400
You got any more questions for him?
995
01:27:02.495 --> 01:27:03.795
996
01:27:04.335 --> 01:27:08.755
997
01:27:09.590 --> 01:27:10.730
What's it been like
998
01:27:11.830 --> 01:27:14.970
running a being a maintainer for an open source project?
999
01:27:15.590 --> 01:27:34.630
This is like the second iteration of that question that I didn't answer well enough in the first I'm giving I'm giving you a second I'm giving you a second chance. I asked him 30,000 blocks ago, and he froze up a little bit. So, And a lot has happened since then too. So I feel like you're more experienced now. And the repo is, like honestly, the the repo, we've gotten more contributions. There's probably,
1000
01:27:35.155 --> 01:27:36.755
1001
01:27:38.035 --> 01:27:39.735
Nick and Keith who were eligible.
1002
01:27:40.435 --> 01:27:44.615
By the way, shout out to Bitcoin Magazine and for you for organizing the, open source
1003
01:27:45.780 --> 01:27:51.880
tickets develop 100%. Tickets for open source developers is what I'm trying My pleasure. To get out. We had a few contributors
1004
01:27:52.185 --> 01:27:56.505
that, like, when that came out, I made sure to DM them and send them a link to their PR and,
1005
01:27:57.945 --> 01:27:59.645
make sure that they were aware of that program.
1006
01:28:03.040 --> 01:28:08.500
But the experience of managing a repo, like, has been probably a reflection of, like, the amazing,
1007
01:28:09.040 --> 01:28:14.015
collaborators that I have Because me being you know, it went from me being the only contributor
1008
01:28:14.635 --> 01:28:15.114
to,
1009
01:28:15.594 --> 01:28:20.230
when Nick came in, like, I was reviewing his PRs, but his code was quickly,
1010
01:28:21.090 --> 01:28:29.855
getting to the point that, like, it wasn't something that I could review at a glance. I really had to sit down and dig in because I'm not, like, a coder by trade, and I'm not, like, a Python native thinker.
1011
01:28:31.434 --> 01:28:33.934
So then as Keith has come in, like,
1012
01:28:34.315 --> 01:28:39.000
it has become more about me responding to issues that are raised and me kinda,
1013
01:28:39.540 --> 01:28:41.480
like, creating the new repos and kinda,
1014
01:28:42.580 --> 01:28:44.360
a big part of what I do is assembling
1015
01:28:44.740 --> 01:28:49.005
the prepared releases, and I control the private keys that are used to
1016
01:28:49.465 --> 01:28:50.445
sign those releases.
1017
01:28:51.705 --> 01:29:00.180
I I become a little bit more like an administrator, but the developers do a great job of playing off of each other to where when there's, like early on, I offered Nick,
1018
01:29:01.280 --> 01:29:07.905
like, admit some degree of administrative rights in the repo and much to his credit, like, he totally declined it. He was like, I like having,
1019
01:29:08.685 --> 01:29:17.730
you as a check against the things that, like, I'm writing. And even if you can't review the code, like, it's trivial just to load it onto, like, a development,
1020
01:29:18.750 --> 01:29:26.095
seed signer where I can swap code out real quickly? I can test, like, is it doing what it it's supposed to? Does it crash? Does it not crash kind of a thing?
1021
01:29:26.555 --> 01:29:28.975
But Keith and Nick do a great job of kind of, like,
1022
01:29:29.390 --> 01:29:37.170
thumbs upping each other's code. So when somebody does a pull request, they they do a great job of looking deeply at it, and, I rely on them,
1023
01:29:37.805 --> 01:29:39.505
heavily on that just for, like,
1024
01:29:40.045 --> 01:29:41.025
checks and balances,
1025
01:29:41.645 --> 01:29:43.185
as we move forward. But,
1026
01:29:43.565 --> 01:29:44.765
I am super bullish on,
1027
01:29:46.060 --> 01:29:47.440
we've been doing this for a year,
1028
01:29:47.900 --> 01:29:48.400
and
1029
01:29:49.020 --> 01:29:55.280
I am super bullish on as the the project gets a little bit more exposure in the Bitcoin space, like,
1030
01:29:55.695 --> 01:29:58.675
getting more experienced Python developers involved.
1031
01:29:59.215 --> 01:30:02.595
And just like we need like every project, we need more eyeballs on our code
1032
01:30:03.020 --> 01:30:03.520
and,
1033
01:30:03.900 --> 01:30:13.025
people being able being interested rather to fix, like, little pain points that they see or little opportunities to tweak it or to, like, build a new functionality. Like, I I'm
1034
01:30:13.405 --> 01:30:17.965
excited for that, and that just helps me. Like, as a maintainer now, I'm kind of,
1035
01:30:19.270 --> 01:30:21.369
like, I feel like my role is
1036
01:30:21.909 --> 01:30:23.210
less than what it was,
1037
01:30:24.070 --> 01:30:26.650
because we have more people looking at the code.
1038
01:30:27.185 --> 01:30:37.940
1039
01:30:38.880 --> 01:30:45.220
1040
01:30:45.635 --> 01:30:50.614
incentivized to collaborate with each other and to produce the best version of of what they're collectively
1041
01:30:50.994 --> 01:30:52.534
trying to work on. Like, it's
1042
01:30:53.699 --> 01:30:56.360
it, like, is this great, like, collaborative
1043
01:30:56.900 --> 01:31:06.554
brings out, you know, usually the best in people kind of thing. I it's that aspect of open source has been something that I had no exposure to, you know, in my previous
1044
01:31:06.855 --> 01:31:07.675
life journey.
1045
01:31:08.054 --> 01:31:08.554
And
1046
01:31:09.100 --> 01:31:10.960
it has been just an amazing,
1047
01:31:12.220 --> 01:31:13.280
almost rejuvenative,
1048
01:31:14.380 --> 01:31:24.935
aspect of, like, my experience with it. Like, you you see the just the the beauty in people and their goodness, and they're willing to just pitch in and help out, like, when you need stuff. Like, it that's just been a mix.
1049
01:31:26.100 --> 01:31:33.239
1050
01:31:33.625 --> 01:31:39.405
are ran really well and are really successful. It's, like, being able to foster an environment, being able to create a community,
1051
01:31:40.264 --> 01:31:42.125
sharing vision, getting people,
1052
01:31:43.199 --> 01:31:48.099
like minded individuals to believe in that vision as well and and then, you know, kind of, you know, dedicate,
1053
01:31:48.719 --> 01:31:52.465
you know, time and effort to, you know, once you find, you know, other people,
1054
01:31:53.005 --> 01:31:59.740
that that share the same vision, you almost wanna, like, you know, work together and, like, make sure that you guys can come together. I don't know if you have any, like,
1055
01:32:00.060 --> 01:32:03.840
other other advice for anyone maybe thinking about,
1056
01:32:04.540 --> 01:32:05.760
not only just contributing,
1057
01:32:06.300 --> 01:32:13.755
to you guys, but also just, like, creating their own, like, you know, how to find and create an open source community. That's, like, that's one of,
1058
01:32:14.554 --> 01:32:20.170
1059
01:32:21.030 --> 01:32:24.090
I I was not a developer by trade. I had a little bit of, like,
1060
01:32:24.550 --> 01:32:33.695
exposure to coding in college and stuff like that. But, like, I am the perfect example of somebody who is not, like, a native coder. It's not, like, something
1061
01:32:33.995 --> 01:32:38.219
that I've done for 5 or 10 years in, you know, some sort of professional capacity.
1062
01:32:38.680 --> 01:32:39.180
But
1063
01:32:39.960 --> 01:32:47.804
what I want people to come away with when, you know, I talk to them or they asked me about a project that they have in mind, like, it is so important to,
1064
01:32:48.425 --> 01:32:49.965
in the best way you can.
1065
01:32:50.905 --> 01:33:00.530
There's a highly underrated skill in this world. It's just effectively communicating a vision for something you have, an idea you have that you would like to see come into existence, being able to
1066
01:33:01.170 --> 01:33:04.150
1067
01:33:06.824 --> 01:33:08.284
I don't know where you lost
1068
01:33:08.824 --> 01:33:11.565
us, but, SeedSiner was giving a very inspiring,
1069
01:33:12.185 --> 01:33:13.885
tale of of how
1070
01:33:16.410 --> 01:33:22.270
of how welcoming the open source community can be and not to be afraid of jumping in. Right?
1071
01:33:22.905 --> 01:33:25.085
1072
01:33:26.425 --> 01:33:26.925
1073
01:33:27.225 --> 01:33:29.325
Well, I appreciate your time.
1074
01:33:29.705 --> 01:33:31.645
I appreciate your time as well, Tony.
1075
01:33:32.280 --> 01:33:34.620
Absolutely. We've been ripping for an hour and 40 minutes.
1076
01:33:35.800 --> 01:33:37.260
It's time for some lunch.
1077
01:33:38.040 --> 01:33:40.139
We got a rabbit hole recap in 2 hours.
1078
01:33:41.805 --> 01:33:42.785
Final thoughts.
1079
01:33:45.565 --> 01:33:50.145
1080
01:33:50.550 --> 01:33:51.210
The the,
1081
01:33:52.230 --> 01:33:56.730
BitKite, who's the organizer of the Nashville meetup, has been, like, an amazing host.
1082
01:33:57.765 --> 01:34:10.880
Like, logistically, just in terms of, like, the meetup that he leads and everybody else who helps with that meetup. If anybody's out there listening and you're, like, anywhere near Nashville, it's worth, like, a it's worth a weeknight of your time to to come in and experience it
1083
01:34:11.260 --> 01:34:24.159
and, just the opportunity to sit here and talk with you guys. And and for everybody out there who's built a seed signer or talked about it, like, much love, much gratitude. Like, I this if you would have told me, like, a year and a half ago, I was a guy listening to Bitcoin podcasts,
1084
01:34:25.340 --> 01:34:32.445
like, who had just kind of like stepped away from his career as a stay at home dad. And I, like, was just tinkering with 3 d printing and different things.
1085
01:34:32.985 --> 01:34:33.465
And,
1086
01:34:34.105 --> 01:34:44.219
like, to be here, like, 18 months later, never would have believed it. Like, this is this has been such an amazing experience, and I'm thankful to everybody out there for. Well, we appreciate you. Thank you.
1087
01:34:44.760 --> 01:34:47.820
1088
01:34:48.285 --> 01:34:50.225
you know, and the Nashville,
1089
01:34:51.085 --> 01:34:54.945
Bitcoin, you know, you know, we don't record anything, and I just wanna say, like, your,
1090
01:34:55.310 --> 01:35:12.034
your your panel with Rockstar and Matt, like, that was, like, as an audience member, I loved it. There's a lot of really good questions and a lot of good answers, and the the back and forth was amazing. So thank you for taking the time to, like, come here and then the conversation today as well, was amazing. So, yeah, my closing thoughts just, you know,
1091
01:35:12.770 --> 01:35:18.070
along the same vein, you know, just just do it, you know, just go to a meetup, you know, if if just dive right in,
1092
01:35:18.610 --> 01:35:44.100
you know, if you have a project, just just do it, and, you never know where you're gonna end up. If you've never used Seed Center before, just just, you know, buy 1 and just start playing with it. Like, you're it sometimes just seems intimidating going to a big Bitcoin meetup or or using a new device that, like, you never used before, especially if you've already gotten used to something. So, yeah, just just dive right in, start playing with it, start going to meetups, and, you know, you never know what's gonna take you. I think that's a great final thought.
1093
01:35:44.660 --> 01:35:48.840
1094
01:35:49.300 --> 01:35:51.640
If you wanna support the project, that's seed signer.com/
1095
01:35:52.340 --> 01:35:52.840
donate.
1096
01:35:53.695 --> 01:35:54.835
Every sat counts.
1097
01:35:56.255 --> 01:35:58.755
I think I can speak for them that they'd really do appreciate
1098
01:35:59.055 --> 01:36:00.035
all of your support.
1099
01:36:01.080 --> 01:36:06.620
I will see you freaks for rabbit hole recap in 2 hours. I'll see you for dispatch next week.
1100
01:36:07.400 --> 01:36:11.165
I got some of the Spectre team joining us on on Tuesday,
1101
01:36:12.264 --> 01:36:12.665
and,
1102
01:36:13.145 --> 01:36:14.525
I I love you all.
1103
01:36:14.985 --> 01:36:16.364
Cheers. Thanks, guys.
1104
01:37:05.389 --> 01:37:05.889
1105
01:37:06.429 --> 01:37:06.929
faces
1106
01:37:07.389 --> 01:37:08.530
in the cloud.
1107
01:40:22.210 --> 01:40:23.110
1108
01:40:23.410 --> 01:40:27.295
See you next week. Don't forget to try and support seed signer, seed signer.com/
1109
01:40:27.755 --> 01:40:29.615
donate. Stay humblestack sets.