CD64: BIP119, CTV, and the bitcoin development process with @rusty_twit and @brian_trollz
EPISODE: 64
BLOCK: 735810
PRICE: 3192 sats per dollar
TOPICS: BIP119, CTV, bitcoin development process, rusty's new covenant proposal, fungibility, consensus, timelocks, ossification, activation
https://citadeldispatch.com/cd64
@rusty_twit: https://twitter.com/rusty_twit
@brian_trollz: https://twitter.com/brian_trollz
streamed live every tuesday:
support the show: https://citadeldispatch.com/contribute
twitch: https://twitch.tv/citadeldispatch
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://www.podpage.com/citadeldispatch
telegram: https://t.me/citadeldispatch
stream sats to the show: https://www.fountain.fm/
join the chat: https://matrix.to/#/#citadel:bitcoin.kyoto
00:00 - Bitcoin and ARC
00:53 - Bitcoin prices and underwater holders
08:34 - Bitcoin development process and CTV proposal
26:43 - Fungibility concerns and covenants
45:21 - Vulnerabilities of Bitcoin to regulatory interference
46:45 - Miner incentives and their vulnerability to external factors
48:06 - The benefits and potential use cases of covenants in Bitcoin
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 7:57:17 PM
Duration: 5766.374
Channels: 1
1
00:00:00.960 --> 00:00:05.140
2
00:00:05.520 --> 00:00:07.359
Because if you feel bad about Bitcoin
3
00:00:07.919 --> 00:00:09.380
Yeah. If you're in ARC,
4
00:00:10.085 --> 00:00:13.785
5
00:00:14.805 --> 00:00:19.960
6
00:00:21.859 --> 00:00:22.599
7
00:00:23.300 --> 00:00:30.865
8
00:00:31.165 --> 00:00:43.899
9
00:00:44.920 --> 00:00:53.095
Well, not for him. No. But it it if you add up what it what it's sold for, it's a $1,000,000,000. If it was an NFT, maybe he'd get a piece.
10
00:00:53.520 --> 00:01:00.100
11
00:01:01.035 --> 00:01:06.095
late yesterday. It's regained some ground early this morning. We're about $31,449
12
00:01:07.730 --> 00:01:10.390
right now. Bitcoin, though, we should say, off about 55%
13
00:01:10.690 --> 00:01:14.790
from its November peak, and 40% of holders are now
14
00:01:15.104 --> 00:01:21.445
underwater on their investments. That's sequenced some new data out from Glassnode that says that, in the last month alone,
15
00:01:21.825 --> 00:01:22.325
15.5%
16
00:01:23.104 --> 00:01:25.979
of all Bitcoin wallets fell into unrealized
17
00:01:26.920 --> 00:01:35.975
18
00:01:36.835 --> 00:01:43.000
I mean, it was at 66. Right? So you would think it could even be worse in terms of the number of people that
19
00:01:43.540 --> 00:01:50.975
20
00:01:51.595 --> 00:01:53.534
20000, 5000. Right? Right.
21
00:01:54.075 --> 00:01:55.534
22
00:01:57.670 --> 00:02:06.170
that I bought higher than where it is right now. So and I don't have a lot. I don't I don't have a lot. But, but I have those. I got one as low as 5, 4 49100.
23
00:02:07.815 --> 00:02:08.315
StocksToWatch.
24
00:02:43.625 --> 00:02:45.805
25
00:02:46.665 --> 00:02:50.480
That clip that we just started off the show with with CNBC
26
00:02:51.660 --> 00:02:54.080
now addicted to on chain analysis
27
00:02:54.380 --> 00:02:58.720
as well as the rest of Bitcoin Twitter and Joe Kernan bragging about
28
00:03:00.135 --> 00:03:02.315
not being underwater on his Bitcoin holdings.
29
00:03:03.095 --> 00:03:11.810
Happy Bitcoin Tuesday to your all to you all. This is your boy Odell here for another Ciel Dispatch, the interactive live show about Bitcoin and FreedomTech.
30
00:03:12.590 --> 00:03:18.265
Dispatch is a 100% audience funded without ads or sponsors focused purely on actionable Bitcoin discussion.
31
00:03:19.205 --> 00:03:23.545
I wanna thank everyone who continues to support the show and makes that mission possible.
32
00:03:24.540 --> 00:03:31.760
I really do appreciate it. The easiest way you can support the show is through podcasting 2 point o apps. My two favorites are Fountain Podcasts
33
00:03:32.220 --> 00:03:33.360
and Breeze Wallet.
34
00:03:33.705 --> 00:03:34.364
You simply
35
00:03:34.905 --> 00:03:35.965
download the app,
36
00:03:36.265 --> 00:03:44.670
works like a regular podcast app. You load it up with sats, and you choose how many sats per minute you think dispatch is worth, and it streams those sats directly to my node.
37
00:03:45.290 --> 00:03:46.909
You can also support the show,
38
00:03:47.450 --> 00:03:50.190
via the BTC page server instance at sil dispatch.com
39
00:03:50.730 --> 00:03:52.269
through Onchain or Lightning
40
00:03:52.875 --> 00:03:58.575
as well as through my BIP 47 reusable payment code listed on the website.
41
00:04:00.230 --> 00:04:06.970
Although you can obviously listen to dispatch on podcasting 2 point o apps, you can also listen to it on any other podcasting app.
42
00:04:07.830 --> 00:04:09.130
My favorite is antennapod.
43
00:04:09.935 --> 00:04:12.435
You simply just search Siddle dispatch in those apps.
44
00:04:12.895 --> 00:04:20.340
If you don't have stats to spare to support the show, clicking the subscribe button, leaving reviews, sharing with your friends obviously helps tremendously.
45
00:04:21.680 --> 00:04:25.940
Dispatch is also broadcast on Twitch and Bitcoin TV as a video show,
46
00:04:26.800 --> 00:04:28.740
with all archives on bitcointv.
47
00:04:29.294 --> 00:04:31.715
Com. You can find all those links at syldispatch.com.
48
00:04:33.935 --> 00:04:44.350
Dispatch also has a live audience chat. I wanna thank all the freaks who continue to join us week in, week out in the audience chat. You guys make it truly special and unique,
49
00:04:45.565 --> 00:04:47.105
by participating in the discussion.
50
00:04:47.725 --> 00:04:49.425
That chat can be found at sidildispatch.com
51
00:04:50.125 --> 00:05:02.135
and clicking that sidildot chat link. Now that group now is over a 1000 Bitcoiners. We have conversations all throughout the week, not just on Bitcoin Tuesdays. So consider joining us. Really high quality conversation there.
52
00:05:02.935 --> 00:05:04.155
Last but not least,
53
00:05:04.775 --> 00:05:07.035
a new way to support dispatch
54
00:05:07.575 --> 00:05:10.315
is through the podcasting 2 point o boost feature.
55
00:05:10.630 --> 00:05:17.050
I've been trying to experiment with different value for value models in terms of supporting the show without corporate sponsors,
56
00:05:17.645 --> 00:05:24.500
And the boost feature basically allows you to choose how many sats you wanna send to dispatch and include a message with it,
57
00:05:25.460 --> 00:05:29.160
through podcasting 2 point o apps. So that works on both Fountain Podcasts
58
00:05:29.780 --> 00:05:30.520
and Breezewallet.
59
00:05:31.780 --> 00:05:40.675
And as part of that, I think what I'm gonna do going forward is that if you do a boost that's over a 100000 sats, I will read it on the following show.
60
00:05:41.330 --> 00:05:47.270
I'll read your message on the following show, and if nobody has any boost above a 100,000 sats, I will read
61
00:05:47.570 --> 00:05:51.574
the 2 highest paying ones, and we'll start from there and see where it goes.
62
00:05:52.275 --> 00:05:55.495
A bunch of freaks actually posted comments from
63
00:05:55.875 --> 00:05:56.854
2 weeks ago's,
64
00:05:57.715 --> 00:05:58.775
Nostra episode,
65
00:05:59.780 --> 00:06:03.240
the censorship resistant alternative to Twitter and a bunch of other things.
66
00:06:04.900 --> 00:06:11.215
And some of those comments were pretty fun. One was early but interesting. Thanks for all the helpful content that came from an anonymous user.
67
00:06:11.835 --> 00:06:16.415
Atbond said end of month boost for no ad podcasts, and that nostir sounds super interesting.
68
00:06:16.860 --> 00:06:20.000
Following Will's Nostra programming updates on Twitter have been good.
69
00:06:20.300 --> 00:06:26.145
Vake said, hi. This is Vake. Testing fountain app's boost feature, really compelling comment from Vake.
70
00:06:26.944 --> 00:06:28.164
And letter 6173
71
00:06:28.785 --> 00:06:33.205
said, your show is a godsend. I wouldn't go that far, but I appreciate the sentiment regardless.
72
00:06:33.689 --> 00:06:43.575
With all that said, we have a very important conversation today. We are going to be talking about the lightning and Bitcoin development process and how changes get implemented into Bitcoin.
73
00:06:44.195 --> 00:06:49.655
Specifically, we will be talking about the CTV proposal that has been very controversial recently.
74
00:06:50.560 --> 00:06:53.380
Potentially, we'll be talking about Bolt 12 on lightning,
75
00:06:53.680 --> 00:06:58.100
and we'll be talking about Rusty's new proposal, which is an alternative to CTV
76
00:06:58.535 --> 00:06:59.355
called OPTX.
77
00:07:00.375 --> 00:07:05.755
So with all that said, I wanna introduce our 2 guests. We have Rusty Russell here. How's it going, Rusty?
78
00:07:06.600 --> 00:07:08.300
79
00:07:08.919 --> 00:07:29.240
80
00:07:30.980 --> 00:07:32.520
And we end the conversation.
81
00:07:34.595 --> 00:07:46.300
So where do you guys wanna start? I was thinking more of a general overview of what the Bitcoin development process is and how changes get implemented. It seems like a lot of people are confused about how that all goes down. What do you think?
82
00:07:48.095 --> 00:07:50.675
83
00:07:52.415 --> 00:07:55.155
It's supposed to be confusing as part of the answer. Right?
84
00:07:56.350 --> 00:08:00.770
I think so, you know, it's it's sort of constructionist kinda anarchy.
85
00:08:02.110 --> 00:08:03.490
There's, you know,
86
00:08:04.155 --> 00:08:04.655
so
87
00:08:05.995 --> 00:08:11.055
I think the thing to bear in mind, right, is that we are all discovering how this stuff works.
88
00:08:11.410 --> 00:08:12.870
Right? And that is true
89
00:08:13.410 --> 00:08:13.910
universally.
90
00:08:14.290 --> 00:08:17.990
Right? What is the best way to do an upgrade to the protocol is
91
00:08:18.725 --> 00:08:20.025
still an open question.
92
00:08:20.405 --> 00:08:20.905
Right?
93
00:08:21.365 --> 00:08:23.865
But, you know, we can talk about how it has been done in the past,
94
00:08:25.365 --> 00:08:26.505
successfully or unsuccessfully
95
00:08:27.180 --> 00:08:29.040
and, you know, get some inspiration
96
00:08:29.740 --> 00:08:30.480
from that.
97
00:08:31.420 --> 00:08:32.720
I know, is that fair, Shinobi?
98
00:08:34.380 --> 00:08:39.035
99
00:08:39.575 --> 00:08:45.675
the whole thing is you just have an an arctic mob, and if you want to upgrade things, well,
100
00:08:46.430 --> 00:08:49.730
get up there and convince the mob to do something.
101
00:08:50.670 --> 00:08:53.730
I mean, I can't really think of any other way to describe it.
102
00:08:54.324 --> 00:09:00.024
103
00:09:00.485 --> 00:09:04.890
The question like, you know, the messy details are in how does that actual decision process
104
00:09:05.430 --> 00:09:09.770
happen and how do people know there's an upgrade going on? How do people know they're supposed to
105
00:09:10.390 --> 00:09:12.010
upgrade their node and do things?
106
00:09:12.735 --> 00:09:24.970
I guess the important thing with Bitcoin is it's always backwards compatible. Right? Nobody nobody goes in and breaks stuff. That's, you know, that that may not be a rule that's true forever. It's possible one day we'll do what's called a hard fork.
107
00:09:25.350 --> 00:09:32.895
But usually, we're talking about a soft fork, which means that all the stuff that works will keep working. There's just sort of new things added, basically.
108
00:09:34.635 --> 00:09:36.495
Technically, it means that things
109
00:09:37.720 --> 00:09:39.160
that new rules are added,
110
00:09:39.720 --> 00:09:45.625
but rules are never taken away, and that makes it backwards compatible. So if you take the, you know, the 0.3
111
00:09:46.165 --> 00:09:46.665
Bitcoin
112
00:09:47.365 --> 00:09:49.305
version with a couple of fixes,
113
00:09:49.845 --> 00:09:52.665
it will happily sync the current Bitcoin chain.
114
00:09:53.680 --> 00:09:55.459
Nobody's nobody's, you know,
115
00:09:55.839 --> 00:10:01.699
nobody's doing any non backwards compatible changes. And so we're talking about a soft fork here, a backwards compatible change.
116
00:10:02.125 --> 00:10:06.625
And importantly, even a backwoods compatible change could be bad. Right? A backwoods compatible change could be,
117
00:10:07.565 --> 00:10:17.080
you know, Block 9 coins can no longer be spent. Right? So that we've just stolen Satoshi's coins. That would be backwards compatible with the network. It would also be a really bad idea,
118
00:10:17.700 --> 00:10:19.375
and probably not,
119
00:10:20.095 --> 00:10:23.875
you know, but my my node would never run such software. Right? So,
120
00:10:24.415 --> 00:10:27.475
you know, just because it's back as compatible doesn't mean it's a good thing to do,
121
00:10:28.095 --> 00:10:32.250
but it's kind of a minimum bar. We want back compatible changes that don't break anything.
122
00:10:33.029 --> 00:10:36.649
And, you know, all the changes we're talking about as well are things that
123
00:10:37.325 --> 00:10:45.665
pretty much if you don't use them, they don't hurt you. Right? That's also kind of a minimum bar I think that people have. Right? Is is there often changes?
124
00:10:47.220 --> 00:10:52.760
125
00:10:53.355 --> 00:10:54.335
actual coordination
126
00:10:54.795 --> 00:10:57.935
of a change. Because, you know, there there is this conception
127
00:10:59.195 --> 00:11:00.815
that's pretty widely held
128
00:11:01.380 --> 00:11:05.400
amongst a lot of nontechnical users that, like, a soft fork
129
00:11:05.780 --> 00:11:12.395
magically means there is no possibility of a chain split, but with a hard fork, there is. And the the reality is
130
00:11:12.855 --> 00:11:13.915
if the coordination
131
00:11:14.455 --> 00:11:26.060
of activating something, you know, goes wrong or is not complete or starts in the wrong place, like, there absolutely is the risk of chain splits even though an upgrade is being done through a soft work.
132
00:11:26.839 --> 00:11:28.620
133
00:11:29.555 --> 00:11:34.935
okay. So let's let's talk about, let's let's kinda come down to brass tacks with being very abstract. Right? So,
134
00:11:35.394 --> 00:11:38.375
let's look at op CTV. So this proposal takes
135
00:11:38.870 --> 00:11:40.810
op no op 4, which is basically,
136
00:11:41.189 --> 00:11:43.290
you know, something that does nothing at the moment,
137
00:11:43.829 --> 00:11:50.404
in Bitcoin. If you put that in your little Bitcoin script, hey, in order to, you know, every every so every Bitcoin script,
138
00:11:50.805 --> 00:11:53.545
well, okay. Let's we should probably just talk about what it is. Right?
139
00:11:54.085 --> 00:11:56.185
Every output in Bitcoin, every coin
140
00:11:56.570 --> 00:11:59.070
has a list of conditions that say who can spend it.
141
00:11:59.450 --> 00:12:03.709
Right? So how you need to spend it. And usually that's, you know, hey, if you have this,
142
00:12:04.015 --> 00:12:11.085
if you can produce a signature for this public key, it's yours. Take it. Right? That's the simplest script. It's it's, you know,
143
00:12:11.630 --> 00:12:20.770
it's got abbreviations. It's so common. That's the most normal use of script. But you can have other things. You have a little program in there. So so you have to you have to basically make this program work.
144
00:12:22.175 --> 00:12:27.395
So this would take up not 4, which currently does nothing, and makes it do something. Right? In this case,
145
00:12:28.015 --> 00:12:28.765
it it
146
00:12:29.430 --> 00:12:37.625
checks that the top thing on the stack matches the thing that, you know, it produces produced by, not for the the template verify thing. So it adds a new rule.
147
00:12:38.025 --> 00:12:39.325
Right? Now,
148
00:12:40.265 --> 00:12:45.805
if all the, you know, if all the nodes were to start enforcing this rule and your node didn't
149
00:12:46.460 --> 00:12:50.000
and somebody used opt not for the old way just as as a junk opcode,
150
00:12:50.700 --> 00:12:56.495
all the upgraded nodes would go, no. No. No. That means a special thing now, and and and this doesn't work anymore.
151
00:12:57.435 --> 00:12:58.735
You don't meet the conditions.
152
00:12:59.435 --> 00:13:12.529
We did that opt not 4, which is now CTV. And, no, your program doesn't work anymore. You can't spend those coins. Then you'd have a chain split, right? Your node would go to whatever. I'm ignoring that. That's fine. Everyone else would go no, no, no, that doesn't work. You can't spend that coin
153
00:13:13.055 --> 00:13:14.435
by definition then. Right?
154
00:13:15.375 --> 00:13:19.714
You'd have a split. Now in order for you to actually get a split, you'd have to have a miner,
155
00:13:20.310 --> 00:13:25.850
that is gonna mine a block that contains that transaction and that treats it the old way and ignores the stuff.
156
00:13:26.310 --> 00:13:34.715
But it could certainly happen. That's why we try to get Eberron to kind of upgrade at once. We don't want to have gratuitous chain splits and everything else. In particular, if all the miners upgrade,
157
00:13:35.070 --> 00:13:46.014
then no one's going to produce an invalid block. You're not going to get a chain split. Even if you haven't upgraded, you're probably pretty good. So there is definitely some staging in how we like to do our upgrades so it's not too messy.
158
00:13:46.315 --> 00:13:53.055
159
00:13:53.720 --> 00:13:54.620
auto updates
160
00:13:55.240 --> 00:13:55.980
for Bitcoin,
161
00:13:56.520 --> 00:14:01.100
162
00:14:02.735 --> 00:14:12.449
163
00:14:13.870 --> 00:14:19.535
164
00:14:28.450 --> 00:14:32.310
or that, you know, other developers are gonna go rogue and still order your coins.
165
00:14:33.890 --> 00:14:37.270
Now there well, there's never been an auto update. There was this alert key,
166
00:14:38.515 --> 00:14:44.615
feature in Bitcoin early on, right, that allowed you to basically send a message out to all the notes and say, hey, you know,
167
00:14:45.550 --> 00:14:48.990
do something. It was signed by this magic key that some of the developers had.
168
00:14:49.310 --> 00:14:50.449
That was ripped out,
169
00:14:50.910 --> 00:14:56.904
quite a while ago. But that was kind of a nod towards this idea that there might be some, oh, crap moment where
170
00:14:57.285 --> 00:14:57.785
early
171
00:14:58.965 --> 00:15:04.269
on, you know, you might have had to tell everyone, oh, crap, can you upgrade because we found this horrific bug or something.
172
00:15:05.050 --> 00:15:06.589
But, yeah, I think we're,
173
00:15:06.970 --> 00:15:11.149
hopefully I know we can never be sure with software, but, hopefully, we're past those days.
174
00:15:11.755 --> 00:15:13.855
And either way, the alert key is long gone.
175
00:15:14.315 --> 00:15:33.475
So so no, there's no auto upgrade. Everyone's got to kind of in theory, everyone like looks at the software and goes, yes, I like it. Okay. We're all good to go. And they tell their friends and we all kind of upgrade around the same time, and we don't end up with any chain forks and stuff like that. And that's generally worked pretty well, but it is pretty chaotic.
176
00:15:34.735 --> 00:15:37.155
177
00:15:38.149 --> 00:15:41.769
like, aspect of the whole coordination process for softworks,
178
00:15:43.430 --> 00:15:45.529
despite his minor's involvement.
179
00:15:46.305 --> 00:15:48.085
Like, a lot of the
180
00:15:48.545 --> 00:15:50.485
the problems and nonsense
181
00:15:51.105 --> 00:15:51.605
from,
182
00:15:52.065 --> 00:15:54.005
say, 7 years ago or so
183
00:15:54.600 --> 00:15:55.260
was around
184
00:15:55.640 --> 00:15:57.260
the dynamic of miners
185
00:15:57.560 --> 00:16:00.300
upgrading first and the importance of that.
186
00:16:00.760 --> 00:16:04.425
And, like, the the entire original reason for that was
187
00:16:04.965 --> 00:16:07.305
not giving minors some disproportionate
188
00:16:07.845 --> 00:16:11.145
vote or influence or anything like that. It was solely
189
00:16:12.630 --> 00:16:17.050
to prevent the risk of a chain split because you have to have miners
190
00:16:17.910 --> 00:16:20.970
mining invalid transactions according to the old rules
191
00:16:21.445 --> 00:16:29.625
or the the new rules New rules. In order to have that chain split occur. And so the the entire reason of miners signaling and miners, like,
192
00:16:30.010 --> 00:16:33.070
taking that role in the activation process was solely,
193
00:16:34.170 --> 00:16:35.310
a kind of defense,
194
00:16:35.770 --> 00:16:38.670
against that risk with a soft fork. Like, no,
195
00:16:39.575 --> 00:16:44.075
like, kind of giving disproportionate controller influence to them. It was simply,
196
00:16:44.775 --> 00:16:49.740
a safety mechanism to try to reduce the risk of a chain split as much as possible.
197
00:16:50.840 --> 00:16:57.900
198
00:16:58.445 --> 00:17:00.145
in theory, they can start
199
00:17:00.525 --> 00:17:16.870
unpicking old blocks and and create a new chain. So, you know, there's already some level of responsibility there. And so going, okay. Cool. Well, you know, we'll we'll just get them to upgrade to some extent makes makes makes a deal of sense. On the other hand, it doesn't matter what miners do. If
200
00:17:25.950 --> 00:17:27.170
201
00:17:27.630 --> 00:17:28.690
202
00:17:30.510 --> 00:17:33.010
I was I always thought maybe it was my side.
203
00:17:33.515 --> 00:17:34.575
The miner censored
204
00:17:35.195 --> 00:17:35.935
him. Uh-oh.
205
00:17:38.795 --> 00:17:40.655
Well, hopefully, he jumps back in.
206
00:17:42.630 --> 00:17:43.529
In the meantime,
207
00:17:45.590 --> 00:17:49.690
Shinobi, there was there was the term vote was just thrown around.
208
00:17:50.825 --> 00:17:52.205
The way I kinda look
209
00:17:53.465 --> 00:18:00.260
at implementing Bitcoin changes and, like, this loose Bitcoin governance process is that there are multiple stakeholders.
210
00:18:01.360 --> 00:18:03.620
You got you have miners, you have devs,
211
00:18:04.720 --> 00:18:07.860
and then maybe you have users that aren't devs or miners.
212
00:18:10.085 --> 00:18:13.545
I kind of look at it like all of those people all have a Vido.
213
00:18:14.165 --> 00:18:17.385
Do you think that's, like, a good way of looking at it, or is that a
214
00:18:17.769 --> 00:18:19.630
I mean, I I don't a good perspective
215
00:18:20.490 --> 00:18:23.230
or veto rather than vote. Veto or vote
216
00:18:24.010 --> 00:18:24.830
217
00:18:25.845 --> 00:18:30.985
like, a a accurate way to represent it. Like, I I just always come back
218
00:18:31.685 --> 00:18:33.705
to the idea of a a mob
219
00:18:34.220 --> 00:18:43.145
that just happens to all be doing the same thing, moving in the same direction, and the process of changing being trying to convince them to do something different.
220
00:18:43.705 --> 00:18:47.405
But I I I don't see things so much as a vote or a veto
221
00:18:48.025 --> 00:18:48.925
just as,
222
00:18:49.865 --> 00:18:50.365
like,
223
00:18:50.910 --> 00:19:00.725
people are free to do whatever they want. Like, you can always break off and form your own mob. Like, there is nothing that keeps you a part of this one.
224
00:19:01.184 --> 00:19:03.684
And ultimately, it just comes down to,
225
00:19:04.304 --> 00:19:04.804
like,
226
00:19:05.105 --> 00:19:05.605
how
227
00:19:05.985 --> 00:19:08.085
willing are people to do that
228
00:19:08.690 --> 00:19:11.909
and how long will they stick that out if they do that
229
00:19:12.289 --> 00:19:20.805
in order to see, you know, whether people will follow them or stick with the mob that they broke off from. So it's it's not so much,
230
00:19:21.265 --> 00:19:24.165
I think, a veto or a vote as it is just, like,
231
00:19:24.710 --> 00:19:26.730
how much value do you see
232
00:19:27.190 --> 00:19:33.690
in being part of the biggest mob and, like, how Right. How far will you take that game of chicken
233
00:19:34.125 --> 00:19:37.664
in terms of, like, threatening or actually breaking off from that?
234
00:19:39.485 --> 00:19:44.100
235
00:19:44.640 --> 00:19:48.580
like, if I'm running if I'm using my own node and I don't update it,
236
00:19:51.095 --> 00:19:51.995
I am basically
237
00:19:52.375 --> 00:19:57.035
individually saying I am not going with whatever change is being made. Right?
238
00:19:58.410 --> 00:20:02.590
239
00:20:03.210 --> 00:20:08.165
minors choose to not disrupt things, then you are still going to,
240
00:20:08.625 --> 00:20:13.125
you know, stay part of the larger mob. But you are kind of choosing,
241
00:20:14.490 --> 00:20:17.150
like, consciously if you're paying attention at least,
242
00:20:17.850 --> 00:20:19.870
to open yourself up to the possibility
243
00:20:20.330 --> 00:20:26.255
that you could be broken off into, like, another mob by some other actor inside of it.
244
00:20:26.875 --> 00:20:29.055
245
00:20:29.515 --> 00:20:31.135
And, Rusty, you're back.
246
00:20:35.600 --> 00:20:36.100
And
247
00:20:36.880 --> 00:20:37.780
he is not.
248
00:20:38.160 --> 00:20:40.900
249
00:20:41.280 --> 00:20:41.780
attack.
250
00:20:42.325 --> 00:20:50.660
251
00:20:51.620 --> 00:20:52.120
Anyway,
252
00:20:53.220 --> 00:20:54.440
hopefully, I'm back now.
253
00:20:55.700 --> 00:20:57.060
Yeah. Miners. So,
254
00:20:57.860 --> 00:21:10.440
so so to some extent, you know, there there's there's a reason to to go through the miners, but it doesn't matter because your node checks everything. And so if the miners start producing what your node considers to be crap, it will just drop those blocks on the floor. So
255
00:21:11.460 --> 00:21:13.240
at the end of the day, you know,
256
00:21:14.420 --> 00:21:24.635
you you have control over what your software does. Now that may not help you if everyone else goes the other way and you're the only one running you're a particular weird variant of Bitcoin and no one's mining it. Sure. But,
257
00:21:25.230 --> 00:21:32.530
that is, you know, that is the ultimate control. Right? Is is the economic control. Right? If the vast majority of people who use and have Bitcoin
258
00:21:33.070 --> 00:21:39.955
believe the rules are a certain way and their software enforces that, then that's what Bitcoin is. I'm sorry. You know, like it or not,
259
00:21:40.815 --> 00:21:50.500
that that's there there's definitely an economic majority argument. It doesn't really matter what the miners do. And importantly, in a meta sense, the miners will follow those people because those people have the money. Right?
260
00:21:51.904 --> 00:21:57.125
So the miners really are relying on that block reward. Right? That's that's why they're mining, presumably.
261
00:21:57.745 --> 00:21:59.745
At least most of them are doing it for profit motive.
262
00:22:00.385 --> 00:22:05.930
And if they mine something else with their machines and no one accepts those blocks, they don't get paid,
263
00:22:06.710 --> 00:22:16.735
at least not in any meaningful sense. Right? If there's only, you know, 3 people in the world who accept that weird Bitcoin fork, that's not gonna pay the bills. And so they are incredibly economically sensitive
264
00:22:17.149 --> 00:22:22.450
to what your node does if, you know, if if the vast majority of nodes are going the same way.
265
00:22:22.830 --> 00:22:26.205
So there is definitely a a, kind of,
266
00:22:27.065 --> 00:22:33.165
standoff here where, you know, the miners are you know, the miners kind of seem to have some signaling control, but
267
00:22:34.020 --> 00:22:45.794
they definitely are having to follow the economic majority in the end. So it is actually really important that people run their own nodes and and check their own stuff and and look after their own things, and the miners will have to follow.
268
00:22:46.495 --> 00:22:48.895
269
00:22:50.095 --> 00:22:51.235
learned that lesson,
270
00:22:51.570 --> 00:22:53.910
I will not learn, but had it reinforced,
271
00:22:54.690 --> 00:22:55.809
last year during,
272
00:22:56.130 --> 00:22:57.110
Taproot activation.
273
00:22:58.130 --> 00:23:01.030
I I was being a cheeky smart ass
274
00:23:01.535 --> 00:23:06.595
and patched my node to start enforcing Taproot from the genesis block.
275
00:23:07.535 --> 00:23:09.955
And then Wing Chung and f two pool
276
00:23:10.519 --> 00:23:12.120
decided to sweep some,
277
00:23:13.240 --> 00:23:13.740
Taproot
278
00:23:14.200 --> 00:23:20.205
outputs that developers created while testing before enforcement started. And so my node,
279
00:23:21.225 --> 00:23:26.205
is still sitting quietly in the corner waiting for everyone else to come back to the real Bitcoin.
280
00:23:26.665 --> 00:23:27.165
Yeah.
281
00:23:29.810 --> 00:23:36.150
282
00:23:36.845 --> 00:23:38.945
this is true of any money, right?
283
00:23:39.485 --> 00:23:41.745
If no one else accepts your money,
284
00:23:42.125 --> 00:23:42.625
that's
285
00:23:43.325 --> 00:23:46.145
good for you, but it's, you know, you're always economically reliant
286
00:23:47.140 --> 00:23:47.720
on this,
287
00:23:48.740 --> 00:23:55.320
this at least somewhat that there would be another group of people who recognize the same money as you. Otherwise, it's not really money,
288
00:23:56.635 --> 00:23:59.615
because trading with yourself generally isn't quite interesting. Right?
289
00:23:59.915 --> 00:24:00.395
So,
290
00:24:00.875 --> 00:24:08.760
so so so, you know, this it's kind of fundamental to the problem. So the fact that Bitcoin has this issue that you need to all agree on it is actually
291
00:24:09.914 --> 00:24:14.495
just a question of degree. All monies have this issue. Anything you treat as money, you kind of need
292
00:24:14.955 --> 00:24:21.350
to have another group of people who agree. Doesn't have to be everyone, but it has to be enough. So it's not like Bitcoin
293
00:24:21.650 --> 00:24:26.715
created a new problem here. It's just that that's just how it is. And that's it in life. Right? If if no one else,
294
00:24:27.015 --> 00:24:28.715
you know, agrees with you about the rules,
295
00:24:29.095 --> 00:24:30.555
you're going to have a hard time.
296
00:24:33.390 --> 00:24:33.890
297
00:24:34.830 --> 00:24:35.330
298
00:24:35.790 --> 00:24:38.050
yeah, I I think now might be a
299
00:24:39.525 --> 00:24:42.505
a good time to kinda shift towards covenants
300
00:24:43.205 --> 00:24:46.184
Yep. Just to, like, actually be able to get into that deeply.
301
00:24:46.900 --> 00:24:53.059
Let's do it. I I do wanna say though before, you you get into that as the expert here, Rusty, that
302
00:24:54.015 --> 00:24:58.835
yeah. I actually, for for a long time, and I'm kind of just
303
00:24:59.375 --> 00:25:02.435
coming around to the counter arguments against this,
304
00:25:03.290 --> 00:25:04.830
I was one of those people
305
00:25:05.690 --> 00:25:06.430
that was,
306
00:25:06.810 --> 00:25:07.870
like, concerned
307
00:25:08.890 --> 00:25:10.270
with the fungibility
308
00:25:10.810 --> 00:25:11.310
implications
309
00:25:12.010 --> 00:25:12.670
of covenants
310
00:25:13.035 --> 00:25:15.615
and the potential to kind of create
311
00:25:15.915 --> 00:25:16.415
UTXOs
312
00:25:17.595 --> 00:25:18.895
that could be perpetually
313
00:25:19.275 --> 00:25:22.529
locked into some more restrictive condition,
314
00:25:23.630 --> 00:25:24.450
in perpetuity.
315
00:25:25.230 --> 00:25:28.770
And, yeah, I'm I'm I'm kinda I'm seeing, like,
316
00:25:29.335 --> 00:25:30.875
the arguments for why,
317
00:25:31.175 --> 00:25:32.955
like, that doesn't fundamentally
318
00:25:33.335 --> 00:25:35.675
change the fact that you can do
319
00:25:36.809 --> 00:25:40.269
that type of thing with other mechanisms that already exist.
320
00:25:40.730 --> 00:25:42.190
But I'm I'm still
321
00:25:43.049 --> 00:25:44.669
kind of on the fence
322
00:25:45.305 --> 00:25:49.885
of just opening the door of a covenant that does not require
323
00:25:50.345 --> 00:25:50.845
precomputing
324
00:25:51.865 --> 00:25:54.045
what it's committing to ahead of time,
325
00:25:54.420 --> 00:25:57.400
just because when it comes to things like
326
00:25:57.780 --> 00:25:59.240
second layers on Bitcoin,
327
00:25:59.860 --> 00:26:00.920
I am really
328
00:26:01.755 --> 00:26:06.495
hesitant to kind of just open the floodgates of things that could potentially
329
00:26:06.795 --> 00:26:08.495
interact with minor incentives,
330
00:26:09.290 --> 00:26:11.550
specifically, like, things like side chains,
331
00:26:12.410 --> 00:26:14.830
that have a direct involvement with minors.
332
00:26:15.450 --> 00:26:17.070
And so, like, I I see
333
00:26:17.505 --> 00:26:21.605
the fungibility concerns are kind of just arguing, like,
334
00:26:22.625 --> 00:26:25.924
why do we want to enable something that you can already do?
335
00:26:26.230 --> 00:26:27.289
But I I'm still
336
00:26:27.830 --> 00:26:28.809
kind of skeptical
337
00:26:29.110 --> 00:26:33.610
and a little cautious around the idea of just opening the floodgates of
338
00:26:33.975 --> 00:26:39.515
not requiring that pre computation because that's really what opens the door to just general,
339
00:26:39.975 --> 00:26:40.475
like,
340
00:26:41.100 --> 00:26:43.039
constructs that can do whatever you want.
341
00:26:43.419 --> 00:26:48.720
342
00:26:49.805 --> 00:26:51.585
let's let's let's talk about fungibility.
343
00:26:52.045 --> 00:26:52.705
Right? So,
344
00:26:54.525 --> 00:26:56.980
so fungibility is basically every coin can be treated as every
345
00:26:59.059 --> 00:26:59.880
346
00:27:00.980 --> 00:27:03.720
347
00:27:04.020 --> 00:27:11.645
I can't covenant your coins. Right? You can covenant your coins. I can covenant my coins. Right? You can't.
348
00:27:12.025 --> 00:27:12.525
And
349
00:27:12.905 --> 00:27:15.325
this is an important misunderstanding. Right? So
350
00:27:16.570 --> 00:27:22.990
the way Bitcoin works is you have control over your coins. You have a certain number of outputs, technically,
351
00:27:23.450 --> 00:27:25.310
on the blockchain that you can spend
352
00:27:27.115 --> 00:27:39.730
because you have the secret key that that that lets you sign for them. Right? And they have little rules that say that, you know, you need you need the key to this thing in order to in order to spend this coin. Right? And that's all Bitcoin is, like a list of outputs, list of rules.
353
00:27:41.390 --> 00:27:42.050
And so
354
00:27:43.905 --> 00:27:55.850
very simple. And everything else, you you don't have control over. Right? For better or worse. Other people have those secret keys or they've lost them or they sent them to bogus addresses like the 1 Bitcoin eater address and stuff, and there's no known,
355
00:27:56.230 --> 00:27:57.850
secret key for it, and they're gone.
356
00:27:58.789 --> 00:27:59.289
So
357
00:28:00.035 --> 00:28:06.855
step 1 in Bitcoin is always to accept that the vast majority of Bitcoin are not under your control, and you just have to kinda live with that.
358
00:28:08.210 --> 00:28:19.125
You know, they're they're controlled by sovereigns. You may not know in many cases who controls them, but they're gone. So you can't control what other people do with their Bitcoin already. Right? And they can do insane things, and they have.
359
00:28:20.225 --> 00:28:27.690
And you hope that the again, this whole money argument. Right? You hope the vast majority of them don't do things that you consider ridiculous because that will,
360
00:28:28.630 --> 00:28:38.275
you know, not directly affect your you'll still have your control of your Bitcoin, but they could totally, you know if everyone else decides tomorrow that it's all worthless, then your economic value goes to 0.
361
00:28:38.735 --> 00:28:58.560
362
00:28:58.860 --> 00:29:01.654
and refuse to accept anything else. Like,
363
00:29:01.955 --> 00:29:04.294
you can't do anything about that. Like, that's
364
00:29:04.914 --> 00:29:05.495
just possible.
365
00:29:05.875 --> 00:29:09.575
366
00:29:09.920 --> 00:29:12.020
yeah, these Yeah. It is this existential
367
00:29:12.480 --> 00:29:15.220
crisis that you can't do anything about. So,
368
00:29:15.920 --> 00:29:18.544
can you make it technically more difficult for people to do this?
369
00:29:18.924 --> 00:29:25.745
Yes, you can, but that boat already sailed. With Taproot, it is not even more expensive to make something a 2 of 2. Right? So
370
00:29:26.070 --> 00:29:42.215
if everyone decided they wanted to have this this okay. We're gonna hand our coins over to some control entity that that is gonna cosign every transaction that we have. You're totally allowed to do that, And it used to be before Taproot. That would be a bit more expensive for you to spend your coins because you'd have to have 2 signatures, not 1. And, you know Well,
371
00:29:42.675 --> 00:29:43.975
it's about technically melting.
372
00:29:44.500 --> 00:29:45.960
373
00:29:46.980 --> 00:29:47.480
multiparty
374
00:29:47.780 --> 00:29:53.160
computation, you could even have done it before Taproot. It's just a lot more complicated to coordinate.
375
00:29:53.925 --> 00:29:54.905
Exactly. Exactly.
376
00:29:56.005 --> 00:30:08.050
377
00:30:08.830 --> 00:30:16.745
on Blockstream, who, disclaimer, I work for. We have our liquid side chain. And if you're if you're dealing with registered securities on the liquid side chain,
378
00:30:17.125 --> 00:30:19.625
we cosign everything. It's called AMP, asset,
379
00:30:20.230 --> 00:30:23.130
something something acronym. Anyway Management platform.
380
00:30:23.670 --> 00:30:41.970
Thank you. Yeah. And it's basically it's a cosigning for all the things. Right? That's how we control. We go, cool. Is this person allowed to have a transfer? Yes. They are. Great. So so we can transfer that. So it's not like a theoretical technology. This already exists. It's totally the way you would do an evil coin control thing. Right? So
381
00:30:42.670 --> 00:30:46.955
the idea that covenants introduces this is is actually forced. That's not how you would do,
382
00:30:47.335 --> 00:30:48.875
how you would do your evil coin.
383
00:30:49.175 --> 00:30:51.675
You would not want to give up control. Covenants
384
00:30:52.295 --> 00:30:52.795
fundamentally
385
00:30:53.095 --> 00:30:54.155
let you control
386
00:30:55.190 --> 00:31:00.809
how your coins are spent. Now, you already can control how your coins are spent. Right? You can say, hey, you need this
387
00:31:01.350 --> 00:31:09.155
public you need to have this secret key and make a signature for me, or you need to have these 2 keys, or you need to get this evil government corporation
388
00:31:09.615 --> 00:31:15.299
or government organization to sign off on your thing. Whatever it is, you can already set those for your stuff. That's fine.
389
00:31:15.760 --> 00:31:19.299
It's just a question of degree. Now, what's really interesting here
390
00:31:20.159 --> 00:31:22.179
is bitcoin could have just been released with
391
00:31:23.065 --> 00:31:30.605
say single signature, right? The most common use is like, hey, you got to have a signature for this key and you're done. Bitcoin could have just had that ability from day 1 and it did,
392
00:31:31.220 --> 00:31:33.080
but it did it in a very weird
393
00:31:33.380 --> 00:31:34.500
way. Right?
394
00:31:34.900 --> 00:31:39.000
It did it in its gin by having this generic little program attached to every output.
395
00:31:39.804 --> 00:31:40.465
And Satoshi
396
00:31:41.725 --> 00:31:46.340
originally claimed that basically if he didn't put it in at the beginning, then it would never be put in later.
397
00:31:47.220 --> 00:31:50.039
And this was the programmable money thing, and it is
398
00:31:51.140 --> 00:31:59.304
weird because you're already talking about a revolution in this this kind of, you know, this money thing. Why would you add this feature as well? It seems like a real go out in a limb
399
00:31:59.684 --> 00:32:00.904
stretch thing, right?
400
00:32:01.684 --> 00:32:03.385
It makes the system much more complicated.
401
00:32:04.890 --> 00:32:15.934
It makes them not fungible. Instead of every spend being the same, you just add a signature and you go. Now, you've got this thing has this weird encumberment that everyone can see, and so that coin looks nothing like any other coin.
402
00:32:16.395 --> 00:32:17.934
And the language used was
403
00:32:18.315 --> 00:32:28.130
not ridiculously powerful, but reasonably powerful. It's like this 4th based language with all these different instructions like add 1 and add these two numbers together and subtract this and compare with this. All this stuff that you can do.
404
00:32:29.605 --> 00:32:34.185
And it's generally you know, the 99% of transactions do not use this at all.
405
00:32:35.765 --> 00:32:37.545
But it was very
406
00:32:38.110 --> 00:32:44.050
foresighted. Right? It turns out that some of the stuff that we didn't even know that we wanted to do really,
407
00:32:44.430 --> 00:32:46.210
like the lightning protocol stuff,
408
00:32:46.534 --> 00:32:49.914
uses a small fraction, to be honest, of this scripting capability.
409
00:32:50.855 --> 00:32:54.475
And in fact, we have enhanced it since then, and this is the trick. Right?
410
00:32:56.140 --> 00:32:59.520
Satoshi actually had some powerful stuff in there that he pulled out because
411
00:32:59.900 --> 00:33:01.280
he was concerned that the implementations
412
00:33:01.660 --> 00:33:09.685
were probably vulnerable to various denial of services. So he just kind of ripped off a bunch of fairly powerful opcodes out for technical reasons.
413
00:33:11.265 --> 00:33:17.460
And we are perhaps very slowly experimenting with kind of putting stuff back, and doing things in a better way.
414
00:33:19.120 --> 00:33:30.725
But the idea that there's these weird non fungible, like, different coins out there, If that boat has already sailed, Bitcoin is already there. We have this weird script capability that we don't use very much.
415
00:33:31.440 --> 00:33:35.140
And we're looking at, you know, hey. How do we enhance it? And we, over the years, have enhanced it in little ways.
416
00:33:36.000 --> 00:33:42.154
The if we look at, like, check sequence verify and check time lock verify, these were 2 soft forks that basically let you say,
417
00:33:42.774 --> 00:33:44.875
you can spend this but your transaction
418
00:33:45.414 --> 00:33:47.914
has to be time locked after a certain point
419
00:33:48.320 --> 00:33:51.060
basically. So you can only spend this in the future. So you could lock
420
00:33:52.560 --> 00:33:55.940
an output and say, hey, you can only spend this in 6 months' time or whatever.
421
00:33:56.245 --> 00:33:56.745
Right?
422
00:33:57.125 --> 00:34:00.025
Mhmm. And that is a kind of covenant.
423
00:34:00.965 --> 00:34:03.065
424
00:34:03.445 --> 00:34:03.945
from,
425
00:34:04.960 --> 00:34:16.895
like, something Satoshi built that was not as functional. Like, you only had the unlock time, so you could only do that previously with pre signed transactions. You couldn't actually time lock the script,
426
00:34:17.355 --> 00:34:25.030
which Yep. Was a huge extension of what Satoshi did. Yep. He did it as it's it's a covenant. Right? It says your transaction must look like this.
427
00:34:25.650 --> 00:34:29.345
428
00:34:29.805 --> 00:34:33.905
It is exactly a covenant. It's a very limited covenant, but, you know, it's been very powerful.
429
00:34:36.300 --> 00:34:42.000
430
00:34:42.460 --> 00:34:43.680
and that it doesn't
431
00:34:44.595 --> 00:34:45.735
limit the destination
432
00:34:46.755 --> 00:35:00.020
of of the transaction, which I which I think is I I at least think of that as, like, the the defining characteristic of a covenant. It's, like, actually limiting where it can be spent. Okay. That's the Rubicon for you. Fair enough. I I accept that.
433
00:35:01.059 --> 00:35:09.135
434
00:35:10.990 --> 00:35:18.050
So, you know, but but Satosh definitely threw this kind of, you know look. Here's here's a generic kind of forth like language that we'll put on the in the scripting language,
435
00:35:18.750 --> 00:35:19.810
with a kind of
436
00:35:20.565 --> 00:35:42.715
an idea that we wanted this programmable money. Now, why do we want this programmable money? It's an interesting question. Right? Why didn't we just why didn't Satosh just go, no, you just have multi signatures and you can have 2 things sign off. You can have this you know, other entity that that that will sign off for you and that can enforce all these rules. We don't even need this complication. We don't need it. Why do we have it? And When you think about it, the only reason you have this is because multi party stuff.
437
00:35:43.015 --> 00:35:48.560
You don't need to encumber your own coins. Like, you presumably trust yourself to sign it or not sign it, right?
438
00:35:49.900 --> 00:35:52.080
But thinking one step ahead, you want
439
00:35:53.500 --> 00:35:58.424
the Bitcoin system to enforce these rules. The only reason you'd want that is because there's multiple people involved.
440
00:35:58.885 --> 00:36:03.065
Right? So even while other people were still wrap grappling with the idea of of of
441
00:36:03.790 --> 00:36:10.609
Bitcoin and how we would send money to each other and all this stuff, this is already one step ahead in talking about how will multiple people construct
442
00:36:11.145 --> 00:36:11.645
these
443
00:36:12.665 --> 00:36:14.045
financial instruments together
444
00:36:14.425 --> 00:36:18.525
and create these transactions together in a way that they don't have to trust each other or things like that.
445
00:36:19.305 --> 00:36:19.805
So,
446
00:36:20.580 --> 00:36:23.320
scripting is all about multiple parties interacting,
447
00:36:24.020 --> 00:36:30.225
and not having to have yet another thing that they trust. They can do it all in Bitcoin. So, I don't think there's
448
00:36:31.405 --> 00:36:35.345
no clear line for me between the scripting system we have today
449
00:36:35.690 --> 00:36:42.510
and any slightly more powerful system that that lets you control how you can spend stuff because we're already kind of there.
450
00:36:43.050 --> 00:36:43.550
Now
451
00:36:44.545 --> 00:36:48.145
we do we talk people talk about recursive versus nonrecursive covenants. Right?
452
00:36:48.625 --> 00:36:50.724
A nonrecursive covenant says, basically,
453
00:36:52.120 --> 00:36:54.380
your outputs must look exactly like this.
454
00:36:55.640 --> 00:36:56.140
And
455
00:36:57.000 --> 00:37:05.165
a recursive covenant can say, and, you know, they must look and the outputs of the next one must also look like that. So you can basically encumber coins forever.
456
00:37:05.945 --> 00:37:07.725
But this isn't a really useful
457
00:37:08.410 --> 00:37:08.910
distinction
458
00:37:09.369 --> 00:37:09.869
because
459
00:37:10.170 --> 00:37:14.190
you can effectively encumber coins forever because you can say your output must look like this,
460
00:37:14.730 --> 00:37:16.109
and one of those outputs
461
00:37:17.335 --> 00:37:24.075
says that the next one must look like this. I mean, you've got to step through it, but computers are really fast, and I can encumber the next, like, 1,000,000 spends of a coin,
462
00:37:24.694 --> 00:37:26.315
in probably under a second.
463
00:37:26.670 --> 00:37:27.630
Right? So,
464
00:37:28.349 --> 00:37:33.010
I can make that chain as long as I want. So the fact that it's not technically infinite,
465
00:37:33.390 --> 00:37:41.065
but especially with check lock time verify, I can say, well, you can only do one spend every hour and I've incumbent it for the next, you know, 100000000 hours.
466
00:37:41.440 --> 00:37:42.260
It's forever.
467
00:37:43.520 --> 00:37:43.920
So
468
00:37:44.480 --> 00:37:46.820
469
00:37:47.440 --> 00:37:48.740
for people listening,
470
00:37:49.224 --> 00:37:51.944
kind of make a little finer point there.
471
00:37:52.585 --> 00:37:53.885
Although I I do agree
472
00:37:54.744 --> 00:37:56.605
that in the grand scheme of things,
473
00:37:57.140 --> 00:38:05.720
the important issue is having to precompute versus not precompute everything. Yes. But I I do think it's not really
474
00:38:06.525 --> 00:38:07.025
practical
475
00:38:07.965 --> 00:38:15.105
to kind of create that long chain of locks in the way that people think it is with things like CTV.
476
00:38:15.520 --> 00:38:16.820
Because let let's say
477
00:38:17.200 --> 00:38:20.900
that the whole thing you're worried about is receiving these coins
478
00:38:21.440 --> 00:38:23.540
where you can only spend them
479
00:38:24.355 --> 00:38:25.335
at, like, preapproved
480
00:38:25.635 --> 00:38:26.695
merchants or whatever.
481
00:38:28.115 --> 00:38:29.575
In the case of CTV,
482
00:38:30.355 --> 00:38:32.695
like, it's not just a simple linear
483
00:38:33.880 --> 00:38:39.100
commitment to, like, one path of where those coins get spent because you don't know,
484
00:38:39.560 --> 00:38:42.620
like, how much money somebody is going to spend,
485
00:38:43.355 --> 00:38:51.135
where they're going to spend it. And so when you look at trying to use CTV for that type of thing, you're talking about an infinite,
486
00:38:51.580 --> 00:38:52.320
like, forking
487
00:38:52.940 --> 00:38:56.640
recursion where you have to go down to the single satoshi
488
00:38:57.260 --> 00:38:58.865
and look at the value of that output
489
00:39:08.625 --> 00:39:12.790
and So while it's totally possible to take, like, a single line
490
00:39:13.250 --> 00:39:20.695
and precompute that, if you're talking about, like, something that would be usable in general commerce, like, that that's just not
491
00:39:21.075 --> 00:39:22.295
practical or scalable.
492
00:39:22.835 --> 00:39:23.575
493
00:39:23.875 --> 00:39:24.375
Absolutely.
494
00:39:24.755 --> 00:39:28.339
And this is where your distinction is exactly on point. Right? The difference is,
495
00:39:29.040 --> 00:39:30.660
is it partial or full specification?
496
00:39:31.119 --> 00:39:35.265
Do you specify exactly what the transaction looks like, or do you specify some part of it?
497
00:39:36.464 --> 00:39:38.885
And this is really interesting because the OpsCTV
498
00:39:39.585 --> 00:39:48.240
already steps over that and says, actually, we're going to specify some parts of the transaction. In particular, it doesn't specify all the inputs.
499
00:39:48.860 --> 00:39:51.920
Right? So the simplest covenant would be
500
00:39:52.545 --> 00:39:53.045
optxd
501
00:39:53.825 --> 00:39:54.325
verify,
502
00:39:54.625 --> 00:39:56.005
right? Which would be literally,
503
00:39:56.465 --> 00:39:57.925
this is the transaction ID
504
00:39:58.225 --> 00:39:59.925
of the thing spending this output.
505
00:40:00.600 --> 00:40:03.820
And based on saying the only transaction that can ever spend this is this one.
506
00:40:04.200 --> 00:40:08.674
Right? That would be the simplest covenant form that we could come up with. Right?
507
00:40:09.635 --> 00:40:12.454
And and op check template verify is not that.
508
00:40:12.914 --> 00:40:17.720
It does not just do that, and that that would be really simple. And the re one of the reasons is there's a couple of reasons.
509
00:40:18.280 --> 00:40:22.619
But one of the reasons is that you often want to add fees later. Right?
510
00:40:23.800 --> 00:40:33.515
You don't know what fees are going to be in the future, so locking yourself into a particular transaction may look really, really foolish. It should fees spike, and you're suddenly like, oh, crap. I can't actually spend this now.
511
00:40:35.450 --> 00:40:41.230
Now you can use child pays for parent perhaps, but it depends on whether your outputs are time lock encumbered and all those things. So,
512
00:40:42.785 --> 00:40:46.325
we've already crossed that point from fully specified to partially specified,
513
00:40:47.345 --> 00:40:50.325
but it does fully specify all the outputs which makes it restricted,
514
00:40:50.710 --> 00:40:51.210
right?
515
00:40:53.030 --> 00:41:16.954
Now I guess I come back to first principles here, like as if you get well, should we allow generic covenants and I'm like well Satoshi never disabled anything because he said, oh, wow. This is too powerful for humans to handle or any crap like that. Right? It was always you know, otherwise he would have gone away and done something else and not invented Bitcoin. Right? So the idea that, wow, this thing is too powerful, perhaps we shouldn't enable it, is not an argument I find convincing
516
00:41:17.494 --> 00:41:19.835
at all. I think we should
517
00:41:20.295 --> 00:41:24.960
as long as it is neat and technically feasible and will allow cool things in the future,
518
00:41:26.140 --> 00:41:32.904
I think we should probably look seriously at how do we do this technically the best? Right? What's not the technical, you know,
519
00:41:33.444 --> 00:41:35.944
design things that we can make the best possible
520
00:41:36.484 --> 00:41:37.625
thing that we can do.
521
00:41:38.950 --> 00:41:44.010
And then if we want to introduce it slowly, I think it's worth looking at what would the generic thing look like. Okay,
522
00:41:44.470 --> 00:41:45.770
this is what a whole
523
00:41:47.655 --> 00:41:52.315
covenant system would look like and they go, cool, but let's soft fork it in slowly,
524
00:41:53.495 --> 00:41:55.115
but not randomly, right?
525
00:41:56.200 --> 00:41:59.580
If we want to have some limited ability to start with, that's fine,
526
00:41:59.960 --> 00:42:04.860
but don't keep adding more and more different warts to the system. So you've got this
527
00:42:05.475 --> 00:42:07.895
check template verify. And then we go, oh, we want
528
00:42:08.435 --> 00:42:10.455
check template verify 2 and then
529
00:42:10.835 --> 00:42:13.175
check template verify 3 and all these things.
530
00:42:13.530 --> 00:42:19.230
Because remember, in Bitcoin, we can only ever add new rules. We can't really take them away. So once we put something in,
531
00:42:19.930 --> 00:42:21.710
we are stuck with it forever,
532
00:42:22.255 --> 00:42:24.595
and the code has to handle it forever.
533
00:42:25.215 --> 00:42:27.155
So we tend to be really cautious,
534
00:42:27.615 --> 00:42:30.595
not only about the changes that we make, but,
535
00:42:32.070 --> 00:42:35.450
what what that means technically from the point of view of, you know, every every
536
00:42:35.910 --> 00:42:39.450
everyone has got to check this stuff forever and we need to maintain that forever.
537
00:42:40.464 --> 00:42:45.365
So, that's one of the reasons that there's so much debate and nuance around the different proposals,
538
00:42:45.904 --> 00:42:50.730
because we're going to be stuck with this. Our children are gonna be stuck with the decisions we make here today.
539
00:42:52.550 --> 00:42:53.050
540
00:42:53.350 --> 00:42:55.475
541
00:42:55.935 --> 00:42:59.555
know, like I said when we started this topic,
542
00:43:00.095 --> 00:43:02.195
like, I I don't really see
543
00:43:03.040 --> 00:43:03.540
fungibility
544
00:43:03.840 --> 00:43:05.780
arguments as, like, a valid counterargument
545
00:43:06.080 --> 00:43:07.140
anymore, but
546
00:43:07.680 --> 00:43:09.300
I am I'm still
547
00:43:10.645 --> 00:43:14.984
kind of skeptical about just jumping into full blown covenants,
548
00:43:15.605 --> 00:43:16.665
especially after
549
00:43:17.980 --> 00:43:18.480
zmns,
550
00:43:19.340 --> 00:43:22.800
c p x j on the the mailing list, I think, like,
551
00:43:23.340 --> 00:43:26.080
2 months ago now, maybe a month and a half,
552
00:43:26.895 --> 00:43:29.075
got into a a long thread
553
00:43:29.455 --> 00:43:29.955
with,
554
00:43:30.655 --> 00:43:31.474
Paul Stork
555
00:43:32.095 --> 00:43:36.540
Yep. And kind of just spelled out how with a fully recursive covenant,
556
00:43:37.400 --> 00:43:41.100
you could just implement something like a a drive chain pack.
557
00:43:41.880 --> 00:43:42.380
And
558
00:43:42.760 --> 00:43:45.885
I I just I do not like the idea
559
00:43:46.505 --> 00:43:47.725
of enabling
560
00:43:48.345 --> 00:43:49.805
the the ability to make,
561
00:43:50.505 --> 00:43:52.765
peg systems like that for other layers
562
00:43:53.220 --> 00:43:54.039
that directly
563
00:43:54.740 --> 00:43:56.680
interact with mining incentives.
564
00:43:56.980 --> 00:43:58.680
I mean, I think there is worry
565
00:43:59.299 --> 00:44:07.545
potentially if if Bitcoin actually does become a global money that everything's running on for that to potentially
566
00:44:07.925 --> 00:44:08.425
destabilize
567
00:44:08.885 --> 00:44:09.865
the mining incentives
568
00:44:10.725 --> 00:44:11.225
altogether
569
00:44:12.030 --> 00:44:20.210
If you literally have entire nation's economies running on that and you have coins encumbered where miners could just steal them,
570
00:44:20.725 --> 00:44:24.345
I think that's the type of thing where you might just see a permanent
571
00:44:24.805 --> 00:44:27.385
fork of Bitcoin that never resolves itself.
572
00:44:27.830 --> 00:44:28.330
And,
573
00:44:28.710 --> 00:44:29.450
like, that
574
00:44:29.990 --> 00:44:33.770
is kind of damaging to the whole idea of building a a single
575
00:44:34.310 --> 00:44:36.285
system around a single network effect.
576
00:44:36.765 --> 00:44:37.744
And I'm also
577
00:44:38.845 --> 00:44:40.385
really concerned about
578
00:44:40.845 --> 00:44:44.625
how the economic incentives play out there in terms of
579
00:44:45.520 --> 00:44:46.420
the the validation
580
00:44:46.720 --> 00:44:48.020
cost for miners
581
00:44:48.720 --> 00:44:52.580
and how centralized that could make dependence on, like,
582
00:44:52.915 --> 00:44:56.215
central entities like mining pools. Because once you
583
00:44:56.675 --> 00:45:01.494
kind of activate the ability to make a two way peg like that involving miners,
584
00:45:02.049 --> 00:45:05.269
like, you've just opened the door. Like, there there's no guarantee
585
00:45:05.970 --> 00:45:14.494
that a a side chain somebody makes is just going to be some sane, like, small, easy to validate block size. Like, you could just hitch
586
00:45:14.875 --> 00:45:16.095
something like BSV
587
00:45:16.395 --> 00:45:17.934
and just go full retard
588
00:45:18.474 --> 00:45:19.535
onto Bitcoin's
589
00:45:19.915 --> 00:45:20.415
miners.
590
00:45:21.150 --> 00:45:21.650
And
591
00:45:22.270 --> 00:45:29.410
I I'm I think one of the biggest vulnerabilities of Bitcoin right now going forward for the next 10 years, 20 years
592
00:45:29.950 --> 00:45:30.450
is
593
00:45:31.115 --> 00:45:31.775
the miner's,
594
00:45:32.795 --> 00:45:33.775
kind of exposure
595
00:45:34.234 --> 00:45:38.015
to regulatory or government interference or or capture.
596
00:45:38.550 --> 00:45:47.369
And so, like, turning on something like a fully generalized covenant, which just completely opens that door to never be closed again
597
00:45:47.744 --> 00:45:49.525
to all of these types of incentive
598
00:45:49.905 --> 00:45:50.405
distortions
599
00:45:51.425 --> 00:45:56.805
really worries me. And, you know, to to just get be blatantly honest about this, like,
600
00:45:57.510 --> 00:45:58.010
any
601
00:45:58.790 --> 00:46:02.650
kind of half opens that door as well with things like Ruben Thompson's,
602
00:46:03.430 --> 00:46:06.955
space chain design. And, Jeremy Rubin just dropped
603
00:46:07.435 --> 00:46:11.935
an idea for also doing a drive chain type design using APO.
604
00:46:12.555 --> 00:46:13.295
And so,
605
00:46:13.995 --> 00:46:17.180
like, I that I think is is really
606
00:46:17.880 --> 00:46:21.340
my main reason now for wanting to start very simply
607
00:46:21.960 --> 00:46:30.315
with something like CTV or or the proposal that you just dropped today, which looks like it would be much simpler to upgrade slowly over time
608
00:46:30.935 --> 00:46:36.830
rather than just right out of the gate, just below everything open into fully generalized covenants.
609
00:46:37.610 --> 00:46:41.290
610
00:46:41.610 --> 00:46:45.115
the the minor incentive thing is is that's really hard. Right?
611
00:46:45.915 --> 00:46:48.175
Meta miner incentives are, you know,
612
00:46:49.675 --> 00:46:57.950
threatened by a whole whole whole pile of things, many of which are already outside our our control. Somebody starts a successful fork of Bitcoin and the miners go and mine that, right? We're all screwed.
613
00:46:58.809 --> 00:47:03.825
Somebody starts using Bitcoin blocks for like a lottery that actually becomes more valuable
614
00:47:04.125 --> 00:47:11.319
than like, so they use the blockhash as like a random thing for their lottery, right? And cool, you win the lottery if you, you know, guess the hash or whatever, right,
615
00:47:12.099 --> 00:47:22.845
of the next block. And the problem with that is that if that lottery becomes big enough, it biases miners to like, you know, to to to suppress blocks and crap like that because they're trying to get the winning lottery numbers.
616
00:47:23.545 --> 00:47:29.940
Any system that builds on Bitcoin that is bigger than Bitcoin itself has, I think, these properties that it can screw with the incentives.
617
00:47:30.800 --> 00:47:31.300
618
00:47:32.160 --> 00:47:34.660
619
00:47:35.785 --> 00:47:37.245
So I think to some extent,
620
00:47:37.705 --> 00:47:41.725
you're in the, Hey, not your coins, not your control. You're
621
00:47:42.700 --> 00:47:49.200
gonna have to chill about that. People are gonna do stupid stuff with their coins all the time. And if enough people do stupid stuff, you're in trouble.
622
00:47:49.580 --> 00:47:50.320
But that's
623
00:47:50.825 --> 00:47:55.725
the fundament. Right? We already came back to that. If everyone decides to go to go east and you're going west,
624
00:47:56.185 --> 00:48:00.830
it's gonna be very lonely. And, you know, now there's a question of degrees,
625
00:48:01.610 --> 00:48:04.110
but I think people will figure out a way
626
00:48:04.570 --> 00:48:05.070
to
627
00:48:05.530 --> 00:48:19.050
do these things. People are going to figure out, Shinobi, they're going to figure out ways to do stupid stuff without our help. That, I think, is a universally true thing. So I find it hard to look at some technical thing unless it's obviously stupid
628
00:48:20.550 --> 00:48:22.385
to go, we shouldn't do it for that reason,
629
00:48:23.345 --> 00:48:35.950
Particularly when there are valid things that people want to do with these things, right? So if no one could come up with a reasonable use for it and be like well, I'm not going to waste my time on it. But there are also reasonable things that you would wanna do with covenants. Right? There are
630
00:48:36.570 --> 00:48:39.150
decent same things that I might wanna do.
631
00:48:40.275 --> 00:48:51.180
You know, the idea of this, like, the cold storage vaults and stuff like that is is kinda cool where you could basically go, cool. You can spend this, but you can only spend it this particular way unless you have this super, super secret key, in which case you can pull it out.
632
00:48:51.740 --> 00:48:53.280
You know, that that kind of covenant
633
00:48:53.900 --> 00:48:54.400
design
634
00:48:55.340 --> 00:48:57.840
is is is kinda interesting to me.
635
00:48:58.415 --> 00:49:00.515
So, you know, if you've got
636
00:49:00.815 --> 00:49:04.595
you've got kind of nebulous worries on one hand, but you've got a concrete
637
00:49:04.895 --> 00:49:11.980
way of act you know, of of real use on the other. Now your point, there is, of course, a technical point right here where,
638
00:49:12.460 --> 00:49:15.200
if we were to do something really foolish
639
00:49:17.475 --> 00:49:19.415
and have some opcode that
640
00:49:19.955 --> 00:49:20.615
was really
641
00:49:21.315 --> 00:49:28.540
hard to validate, that took like a whole heap. We could wipe out a whole heap You can no longer validate with a Raspberry Pi. Right? If we did something
642
00:49:28.840 --> 00:49:29.740
technically stupid,
643
00:49:30.760 --> 00:49:36.815
then we could obviously create an opcode that would be centralizing and things like that. And that's I'm assuming here that,
644
00:49:37.434 --> 00:49:46.930
technically, we don't make script significantly harder to validate or, you know, buggy or all these things that that that bar is passed. We're just talking about, like, meta incentives.
645
00:49:48.190 --> 00:49:52.585
And, yeah, I think it's an argument for going slowly. I don't find it a convincing argument.
646
00:49:53.285 --> 00:50:04.799
I also don't find it an illuminating argument for which which bits like where the line is. Right? So we've got all these things we could look at in a transaction. We're looking at covenants, you know, we talked about whether you can, you know, control the outputs or not.
647
00:50:05.345 --> 00:50:05.845
You
648
00:50:07.505 --> 00:50:08.885
know, it's not illuminating
649
00:50:09.185 --> 00:50:12.484
for me to go, cool. Well, where where do we go? Other than, you know,
650
00:50:12.849 --> 00:50:14.210
you can have at the moment,
651
00:50:15.730 --> 00:50:20.725
CTV says you have to specify exactly what all the outputs look like, which makes it infeasible to do, as you say,
652
00:50:21.205 --> 00:50:25.065
an arbitrary control structure because you don't know how much they're going to spend and stuff like that.
653
00:50:25.445 --> 00:50:25.945
So
654
00:50:27.685 --> 00:50:28.645
that's one line,
655
00:50:29.525 --> 00:50:30.025
but
656
00:50:30.390 --> 00:50:35.130
I don't know where the other lines are, and and which you know, so so if we go beyond the OPCTV,
657
00:50:35.510 --> 00:50:46.785
which is the interesting thing for me because I think you need to rethink really long term when you're designing Bitcoin stuff, because we're gonna be stuck with it. What what would the next step be? Right? What would the next thing be? Cool. Okay. Now you can start writing
658
00:50:47.299 --> 00:50:49.799
transactions that have to inspect this other thing.
659
00:50:50.420 --> 00:50:53.960
And I don't know what that is other than you should just allow all of it.
660
00:50:54.955 --> 00:50:55.775
So, you know,
661
00:50:56.635 --> 00:51:03.055
but I I think I've got to thank Jeremy Rubin here for really making a lot of noise on this topic and bringing it to the fore.
662
00:51:03.740 --> 00:51:05.200
Because a lot of people considered,
663
00:51:05.579 --> 00:51:09.040
you know, covenant design kind of a too hard basket. Right?
664
00:51:10.505 --> 00:51:15.065
It wasn't clear what the right things were and what the trade offs were and, you know,
665
00:51:15.385 --> 00:51:20.110
and most people just kinda push it in the corner and he's been really agitating for this kind of CTV
666
00:51:20.730 --> 00:51:21.790
kind of mid level
667
00:51:22.090 --> 00:51:26.270
covenant design I would say, not the simplest thing you could do but not the full covenant design,
668
00:51:26.785 --> 00:51:28.805
and kind of like, cool. This is where I draw the line,
669
00:51:29.345 --> 00:51:32.405
and we should do this. And he has been very loud and vocal,
670
00:51:33.265 --> 00:51:34.085
and certainly
671
00:51:35.690 --> 00:51:40.590
forced at least me to seriously look at covenants in a way I had no intention of doing this year. So,
672
00:51:42.090 --> 00:51:43.070
yeah, I don't know.
673
00:51:44.405 --> 00:51:54.150
I think your points are fair. I disagree with them. I think, you know, there's there's always a fear of unknown. And I think if Satoshi may think that way, he would have just gone, no. We're not putting any scripting in. There's
674
00:51:54.630 --> 00:52:05.835
it's it's opening a huge can of worms. We don't know what people will do with this, which is fundamentally the argument. Right? We don't know what people will do with this. They could do stupid shit. It could destabilize the whole thing. Maybe we shouldn't give them this power.
675
00:52:07.495 --> 00:52:14.860
676
00:52:15.960 --> 00:52:19.180
677
00:52:20.200 --> 00:52:27.075
but full on Lightning, like he put a scripting system in because of the stuff he didn't know, which is also stuff to fear, yes,
678
00:52:27.455 --> 00:52:30.595
but it is also the opportunity of people doing awesome things.
679
00:52:30.990 --> 00:52:31.890
And I guess,
680
00:52:32.430 --> 00:52:34.450
I'm I'm an optimist kind of person,
681
00:52:34.829 --> 00:52:36.690
and I naturally go to,
682
00:52:37.230 --> 00:52:40.895
yeah, look, if we can give people the tools to do awesome stuff,
683
00:52:42.095 --> 00:52:45.555
some of them will do terrible things. But I think some of them will do cool stuff.
684
00:52:46.415 --> 00:52:48.435
685
00:52:48.890 --> 00:52:55.790
a good time to kinda break down your proposal, Rusty, because I'm I'm not gonna lie. Like, all of the alternative
686
00:52:56.090 --> 00:52:59.845
designs that have been pushed out in the last 6 months,
687
00:53:00.545 --> 00:53:01.845
I have been
688
00:53:02.385 --> 00:53:04.964
very skeptical of either just because
689
00:53:05.265 --> 00:53:07.270
I think it's too generalized
690
00:53:07.810 --> 00:53:09.430
of a place to start
691
00:53:09.890 --> 00:53:11.430
or they were just too
692
00:53:12.210 --> 00:53:17.095
narrow in terms of designing for a specific use case. But I I
693
00:53:17.395 --> 00:53:20.135
think, honestly, your proposal is the first one
694
00:53:20.595 --> 00:53:22.855
that I might prefer over CTV,
695
00:53:23.234 --> 00:53:24.694
like, with what I
696
00:53:25.210 --> 00:53:28.030
kind of thought about since I glanced at it before we started.
697
00:53:28.730 --> 00:53:29.230
698
00:53:29.609 --> 00:53:36.795
Okay. So so CTV, as I've said before, takes up not 4 and turns into this thing that basically hashes these certain parts of the transaction,
699
00:53:37.175 --> 00:53:40.795
not covering all the inputs, but, you know, the current input and the number of inputs,
700
00:53:41.120 --> 00:53:42.820
all the outputs and a few other things.
701
00:53:45.120 --> 00:53:51.855
And just makes a hash of that and goes cool. Now the thing you've got sitting on top of the stack right now has to be exactly the same as that. Otherwise, you fail.
702
00:53:52.494 --> 00:53:58.275
And it's done that way for complicated back compatibility reasons. So that's the only way you can extend old school script.
703
00:53:59.890 --> 00:54:03.670
Now in in in Taproot, so so version 1,
704
00:54:04.370 --> 00:54:04.870
Segwit,
705
00:54:05.410 --> 00:54:05.810
we got
706
00:54:07.145 --> 00:54:15.005
we do we do we do things in a different way. So in the old school way, it used to be if you don't understand something like that, all these things are just no ops, you just ignore them.
707
00:54:15.540 --> 00:54:19.320
In Taproot v 1, Anthony Towns, I believe, came up with this. It's brilliant.
708
00:54:20.260 --> 00:54:27.625
If you see, an undefined opcode, so you don't do you just it's success. The answer is yes. All good. You can spend the coins. Go for that.
709
00:54:28.165 --> 00:54:29.785
And that makes it much more upgradeable.
710
00:54:30.165 --> 00:54:32.585
It means that in the future, opcodes can do
711
00:54:32.900 --> 00:54:34.520
all kinds of things. Alright?
712
00:54:35.300 --> 00:54:39.400
With the op not idea, the only thing an opcode can do basically is fail at that point.
713
00:54:40.420 --> 00:54:40.920
So
714
00:54:41.655 --> 00:54:49.515
so we take advantage of this thing that that was invented for for Tapscript v one and we go, cool. So in Tapscript v one, we will have a new opcode called optx
715
00:54:50.590 --> 00:54:51.730
and it will take
716
00:54:52.110 --> 00:54:56.930
a series of like 32 bits that basically say, here, take these parts of the transaction
717
00:54:57.365 --> 00:55:04.905
and do stuff with them. And you can say, do you want the inputs? Do you want, you know, particular parts of the input? Do you want the version number? Do you want all these things? Right?
718
00:55:06.160 --> 00:55:12.339
And there are other bits that say, hey. Do you want me to hash them all together? Do you want me to just like put them all in a row? Do you want me to push them on the stack as separate bits?
719
00:55:13.920 --> 00:55:14.420
And,
720
00:55:15.434 --> 00:55:17.855
you know, and so it's a very, very generic
721
00:55:18.315 --> 00:55:24.600
here, look at I wanna look at the transaction that's spending. Right? That's that's basically OPTX. It's what's a very generic name.
722
00:55:25.160 --> 00:55:31.615
And you say what what thing, what person to look at, and, you know, and and it it does that. Now this is incredibly generic. Right?
723
00:55:33.535 --> 00:55:35.715
But the trick here is that
724
00:55:36.095 --> 00:55:37.615
to start with, we say,
725
00:55:40.309 --> 00:55:44.809
you have to set exactly the bits that are equivalent to object template verify.
726
00:55:45.109 --> 00:55:47.690
Right? So you're only allowed to look at the things that
727
00:55:48.565 --> 00:55:50.265
template verify would let you look at,
728
00:55:50.645 --> 00:55:53.065
and you have to hash them together and put that on the stack
729
00:55:53.525 --> 00:55:59.599
and any other bits of success. So we can define them in future, but for the moment, you're very restricted. So it's a very generic
730
00:55:59.900 --> 00:56:00.400
design
731
00:56:00.940 --> 00:56:05.875
that lets you do all these cool things in future. But right now, we only enable a part that
732
00:56:06.335 --> 00:56:09.315
basically gives you off check template verify, so CTV.
733
00:56:10.160 --> 00:56:23.515
The cool thing about this is that it gives us a way forward. We don't have to do an op CTV 2 and be stuck with, Oh, everyone uses CTV 2 these days, but we've got to support old op CTV because we promised, and promises are forever in Bitcoin.
734
00:56:23.895 --> 00:56:29.550
Right? So it's it's basically the same thing, only it is basically has a road clear road forward
735
00:56:29.930 --> 00:56:30.670
rather than,
736
00:56:32.090 --> 00:56:34.670
rather than being this, okay, comp technical compromise
737
00:56:34.970 --> 00:56:41.535
that some people feel that if we want to go further, we're going to be stuck with and it's going to be ugly, which is my concern with Ops TV.
738
00:56:42.619 --> 00:56:50.080
Not not that I think it's a bad place to draw the line and go, oh, let's start with these ones. It's that I think pretty clearly we're gonna want some other things
739
00:56:50.455 --> 00:56:52.635
and that was always going to make CTV ugly
740
00:56:52.935 --> 00:56:56.155
and so in future generations we're going to look back and go, oh man,
741
00:56:56.455 --> 00:56:57.435
that was a pain,
742
00:56:57.800 --> 00:57:01.660
Right? So this is it's a generic thing but then it's soft worked back down to
743
00:57:02.040 --> 00:57:05.635
this minimal thing. So I've tried to kind of square the circle here
744
00:57:06.275 --> 00:57:07.735
but it does have some disadvantages.
745
00:57:08.275 --> 00:57:09.815
You cannot use this
746
00:57:10.195 --> 00:57:10.695
in,
747
00:57:11.795 --> 00:57:12.595
in in,
748
00:57:12.915 --> 00:57:13.415
either
749
00:57:13.910 --> 00:57:14.569
v zero,
750
00:57:16.150 --> 00:57:17.930
SegWit or pre SegWit
751
00:57:18.230 --> 00:57:21.210
outputs. It has to be in in in in a Tapscript,
752
00:57:21.935 --> 00:57:23.955
because that's the only thing it has is ops success.
753
00:57:24.335 --> 00:57:29.075
Now if we discover after, you know, people use this and do all these things that there really is
754
00:57:30.480 --> 00:57:39.365
a subset that's far more common than anything else, we go, Cool. Actually, almost all the time, you want off CTV. You want those particular bits, and that's the right thing to do, and it's this really common use case.
755
00:57:39.845 --> 00:57:44.665
And, hey, this opcode is like 5 bytes long. It'd be really nice if we had, you know,
756
00:57:45.845 --> 00:57:49.080
really nice if we had, like, a shortcut version for the really common case.
757
00:57:49.560 --> 00:58:00.925
Then we could totally do OPNOT 4 or OPNOT 3, you know, take one of those opcodes and turn it into just that specialization later on. And to be fair, we already do this in Bitcoin for the public key case, right?
758
00:58:01.225 --> 00:58:11.680
The standard, I just want to spend this. If you've got this signature by this key, you can spend it. Right? We already have a shortcut, for those because it's such a common case. You don't have to spell it out in script.
759
00:58:12.140 --> 00:58:14.505
You can, but the standard things don't.
760
00:58:15.065 --> 00:58:17.404
So, yeah, we can totally put in a shortcut later,
761
00:58:18.505 --> 00:58:21.484
but doing it today is doing it backwards. It's a premature optimization
762
00:58:21.850 --> 00:58:28.830
to take an opcode and and give it for some special case when we don't even really know that that's gonna be the most common thing that we do.
763
00:58:30.575 --> 00:58:33.235
764
00:58:33.615 --> 00:58:37.955
things the same way SegWit did. Like, SegWit redefined an OPNOP,
765
00:58:38.550 --> 00:58:41.130
but set it up so that you could version that
766
00:58:41.670 --> 00:58:44.650
and just keep iterating how that single
767
00:58:45.590 --> 00:58:46.970
newly defined opcode
768
00:58:47.395 --> 00:58:48.215
is validated
769
00:58:48.515 --> 00:58:58.630
instead of having to eat up a new one each time because we only have so many before we run out of them and can't Yep. Add new bare op codes.
770
00:58:59.250 --> 00:59:07.335
771
00:59:08.035 --> 00:59:13.255
But as Andrew Polster said, even the idea of a soft fork versus a hard fork Bitcoin upgrade
772
00:59:13.630 --> 00:59:17.089
really only came about in 2012. So it took us a few years to really realize
773
00:59:17.710 --> 00:59:23.089
the right way to upgrade Bitcoin. You know? And it was only really with Tapscript that we realized the right way to upgrade script
774
00:59:23.485 --> 00:59:25.745
was to define everything as ops success and
775
00:59:26.365 --> 00:59:28.635
then take those away later on. So
776
00:59:30.260 --> 00:59:33.800
this is all part of that that that learning experience, and I think that's
777
00:59:34.180 --> 00:59:37.400
that's natural because this stuff is hard and and and weird,
778
00:59:38.115 --> 00:59:42.055
and this gives me sympathy for the the CTV crowd going, actually,
779
00:59:42.434 --> 00:59:47.415
we wanna have it out there so people can play with it, so we can learn stuff, so we know what we want next.
780
00:59:48.020 --> 00:59:52.600
There are people who are like, no, no, let's go full covenants because we know we want them. And I'm like, I think we want them to,
781
00:59:52.980 --> 00:59:53.480
but
782
00:59:54.580 --> 00:59:54.975
I
783
00:59:55.615 --> 01:00:04.675
my experience at Bitcoin has led me to go that we're not as smart as we think we are. And there is real benefit in having something out there that people can play with because
784
01:00:05.040 --> 01:00:10.580
people will come up with cool new things, and that will set our priorities for what we would turn on next. Right?
785
01:00:11.520 --> 01:00:12.720
786
01:00:13.315 --> 01:00:17.575
like, nobody sees everything a 100% clearly. And I I think,
787
01:00:18.435 --> 01:00:23.420
like, a good example of that is the making one of the point variables
788
01:00:24.040 --> 01:00:26.460
in Schnorr pub keys implicit.
789
01:00:28.040 --> 01:00:28.540
When
790
01:00:29.400 --> 01:00:32.220
the whole proposal for tap, leave, update, verify,
791
01:00:32.755 --> 01:00:33.654
was dropped,
792
01:00:34.434 --> 01:00:37.255
that created a whole big problem because
793
01:00:37.954 --> 01:00:43.990
now you have to make sure that when you add or subtract subtract a key from a Schnorr multisig that
794
01:00:44.610 --> 01:00:47.590
what you wind up with is a valid key. Otherwise,
795
01:00:48.665 --> 01:00:50.765
you could wind up just burning coins.
796
01:00:51.305 --> 01:00:56.765
And that adds a lot of client side, you know, work that has to be crunched and computed
797
01:00:57.250 --> 01:00:58.390
anytime that is
798
01:00:58.850 --> 01:01:00.230
used to make sure that
799
01:01:00.610 --> 01:01:06.390
you don't wind up with some combination of somebody wanting to leave, like, a multisig output where
800
01:01:06.855 --> 01:01:12.875
everybody else's coins wind up getting burned because it's not a valid pubkey according to the TAPR rules.
801
01:01:13.495 --> 01:01:13.995
802
01:01:14.980 --> 01:01:15.460
Yeah.
803
01:01:15.860 --> 01:01:16.920
Yeah. We we,
804
01:01:17.780 --> 01:01:20.600
we we do learn things. And then importantly, right, so I guess,
805
01:01:21.700 --> 01:01:22.680
there was a
806
01:01:24.015 --> 01:01:24.915
a really dumb,
807
01:01:25.295 --> 01:01:26.915
soft work in Bitcoin's history,
808
01:01:27.375 --> 01:01:29.075
that predates me.
809
01:01:29.935 --> 01:01:31.235
810
01:01:31.950 --> 01:01:34.210
811
01:01:36.110 --> 01:01:41.295
No. P2sh was good because it made room for to do it properly with with Segwit. Right? But,
812
01:01:43.454 --> 01:01:49.234
no. The the the dumber one I was thinking of was was basically the the forcing the block high in the Coinbase.
813
01:01:50.640 --> 01:01:52.080
814
01:01:52.800 --> 01:01:56.340
815
01:01:56.720 --> 01:01:57.540
on the coinbase
816
01:02:02.195 --> 01:02:07.655
It's clean. It's already 32 bit field. It's designed to put a block height in there. Why the hell do you put it in the beginning of the,
817
01:02:08.710 --> 01:02:20.125
the script pub key for that's like just that doesn't even make sense, right? So, there was a smarter way of doing it, but we're stuck with those old rules because that was, you know, it was early on. It was all a little bit more free and loose
818
01:02:20.744 --> 01:02:21.405
and nobody
819
01:02:22.025 --> 01:02:22.525
why?
820
01:02:23.065 --> 01:02:36.575
There there there's several things going on. 1 is like not enough eyeballs, just not enough serious developers looking at it. 2, it wasn't important enough at the time. It was early days. Nobody cared. It was a little bit of experiment. And 3, nobody really understood that they were gonna be stuck with these decisions forever.
821
01:02:38.475 --> 01:02:46.690
So, we're now aware of that and so there's a lot more eyeballs, there's a lot more thought, there's a lot more care going on about any upgrade.
822
01:02:47.950 --> 01:02:53.090
But there's also there's almost a counterpoint here, there's like a clock ticking. We know at some point
823
01:02:53.625 --> 01:02:57.005
the protocol is going to ossify, right? We're not going to be able to upgrade anymore.
824
01:02:57.785 --> 01:03:00.205
And we've talked about this anarchic upgrade process
825
01:03:00.665 --> 01:03:01.165
and
826
01:03:02.410 --> 01:03:05.950
I'm not sure that that works when your nation states are at play.
827
01:03:06.330 --> 01:03:08.430
When there's so much on the line
828
01:03:08.730 --> 01:03:10.990
that you can no longer have this
829
01:03:11.335 --> 01:03:12.795
bonhomie of, like,
830
01:03:13.335 --> 01:03:18.474
developers all getting around trying to mutually find out the best thing. But people start game playing and,
831
01:03:19.049 --> 01:03:19.630
you know,
832
01:03:20.650 --> 01:03:22.510
trying to sneak stuff in and
833
01:03:23.130 --> 01:03:24.029
dishonest motives
834
01:03:24.329 --> 01:03:25.150
start appearing.
835
01:03:25.769 --> 01:03:26.670
And that's inevitable,
836
01:03:27.049 --> 01:03:28.349
and it happens with any
837
01:03:38.539 --> 01:03:47.839
doing, you know, nasty gameplay to try to get their patented technology and all this kind of crap that occurs. Now, not universally, but at some point when things get big and important,
838
01:03:48.704 --> 01:03:52.484
particularly when you get this generational shift of the original people move on,
839
01:03:53.025 --> 01:04:03.050
we see this. Right? It no longer becomes an attempt to produce the technical produce technical excellence and becomes an opportunity to to to aim for your particular angle.
840
01:04:03.590 --> 01:04:04.090
So
841
01:04:04.924 --> 01:04:10.065
being aware of this, I suspect Bitcoin may be particularly vulnerable to this idea that
842
01:04:10.444 --> 01:04:11.345
there will be
843
01:04:11.805 --> 01:04:16.260
a huge amount of disinformation, and it will be increasingly difficult
844
01:04:17.040 --> 01:04:20.660
to to to be confident that a change is good.
845
01:04:21.505 --> 01:04:22.645
And so at some point,
846
01:04:23.505 --> 01:04:30.085
most reasonable people will go, no. Bitcoin cannot be changed anymore. I don't care how good your excuse is. It's not. Unless, you know, unless
847
01:04:30.540 --> 01:04:39.839
848
01:04:40.244 --> 01:04:45.865
Like, it's it's one or the other, in my opinion. How close do you guys think we are to that?
849
01:04:46.645 --> 01:04:47.785
850
01:04:49.000 --> 01:04:50.539
851
01:04:50.920 --> 01:05:06.205
every every time. Yeah. There's so much stuff to do. But every every time we have this debate, we wonder, is this the time that we're gonna just stall, right? Every time there's a software proposal you're always thinking in the back of your mind is this the one where people go no, no, it's not worth the risk.
852
01:05:07.289 --> 01:05:09.789
It's not worth the risk to the system
853
01:05:10.250 --> 01:05:20.325
to make this change that I don't think benefits me enough. And you should be thinking that. That is a totally fair and reasonable thing to think, right? Is this worthwhile?
854
01:05:21.105 --> 01:05:25.090
People want to change this? Is it worth it, right? No change is free.
855
01:05:26.510 --> 01:05:27.890
And, you know,
856
01:05:28.350 --> 01:05:36.734
how conservative do you need to be? That's an individual choice. You've really got you know, assess things. I don't think we're I don't think we're there yet. I'm pretty sure we're not there yet.
857
01:05:37.595 --> 01:05:42.510
But I would suspect that we're we're we're going to get there at some point.
858
01:05:44.730 --> 01:05:46.589
And, yeah, it I don't know.
859
01:05:47.450 --> 01:05:52.065
860
01:05:52.445 --> 01:05:59.910
I mean, we had Taproot, which I think a lot of us thought was gonna be more difficult to actually activate it, you know, implement and activate,
861
01:06:01.650 --> 01:06:03.349
but that kinda just flew through
862
01:06:03.809 --> 01:06:05.349
with the speedy trial activation.
863
01:06:06.435 --> 01:06:07.095
And then
864
01:06:07.715 --> 01:06:10.775
Jeremy tried to propose this with the speedy trial activation,
865
01:06:12.115 --> 01:06:12.935
and everyone
866
01:06:13.430 --> 01:06:19.850
flipped fucking shits. And I'm not saying that maybe maybe that's the right move to flip shits with that.
867
01:06:20.390 --> 01:06:20.890
But,
868
01:06:21.955 --> 01:06:26.675
like, how do you activate going forward? What's like, do you guys think speedy trial is a good
869
01:06:27.155 --> 01:06:27.655
No.
870
01:06:27.955 --> 01:06:28.455
Method?
871
01:06:29.049 --> 01:06:31.450
872
01:06:32.089 --> 01:06:35.069
Taproot so so Taproot was just so unanimously,
873
01:06:35.769 --> 01:06:36.269
obviously
874
01:06:37.275 --> 01:06:37.775
great,
875
01:06:38.155 --> 01:06:41.695
and opt in, so you didn't have to use it. It didn't take anything away.
876
01:06:41.995 --> 01:06:43.295
It was, you know,
877
01:06:44.230 --> 01:06:48.410
it had been really well studied, really well thought out. It had been a lot of time had passed.
878
01:06:48.710 --> 01:06:55.255
We were pretty sure there was nothing better coming down the horizon. There were no big question you know, It it had all the things, including
879
01:06:55.555 --> 01:07:00.135
a lot of time to bake and a lot of broad discussion, a lot of, you know,
880
01:07:01.720 --> 01:07:09.020
you know, it it it had been done in the right way, and everyone was pretty comfortable with it. So I said at the time a blind monkey could activate,
881
01:07:10.005 --> 01:07:16.905
Taproot and yeah. Sure. Speedy trial. We could have chosen any method. We could have chosen throw darts at the board and it would have activated. Right? So,
882
01:07:17.440 --> 01:07:21.380
you know, it both wasn't a fair thing for speedy trial because it was so easy to activate.
883
01:07:22.560 --> 01:07:25.140
And also, you know, we're also at a unique time
884
01:07:25.600 --> 01:07:26.100
where
885
01:07:26.845 --> 01:07:30.545
nobody really has an interest in Bitcoin OsoFine, not any significant players.
886
01:07:31.005 --> 01:07:33.025
And the miners were
887
01:07:35.380 --> 01:07:39.400
a little bit cowed from their previous experience with, you know, forking.
888
01:07:40.260 --> 01:07:41.240
And so,
889
01:07:41.860 --> 01:07:47.545
you know, in in in view of all that consensus, it was gonna be really hard for,
890
01:07:48.244 --> 01:07:53.020
for anyone to, like, push back on it. So it was almost optimal conditions for a fork.
891
01:07:53.340 --> 01:07:56.240
I don't think we'll see that again. It will only get harder from here in.
892
01:07:57.020 --> 01:07:59.680
893
01:08:00.060 --> 01:08:01.600
attitude of how
894
01:08:02.125 --> 01:08:04.785
I think fork should get turned on going forward.
895
01:08:06.605 --> 01:08:11.424
I don't think miners or developers should have anything to do with it.
896
01:08:12.430 --> 01:08:18.450
They actually half of the reason that I did that troll patch of my node last year to just enforce
897
01:08:19.765 --> 01:08:21.705
Taproot from Genesys was,
898
01:08:23.525 --> 01:08:30.409
me me and a buddy of mine have been talking for a while, and I think, actually, Rusty, in the next core release, this is something
899
01:08:30.710 --> 01:08:32.070
developers are doing now.
900
01:08:32.550 --> 01:08:33.050
But
901
01:08:33.909 --> 01:08:34.409
just
902
01:08:34.710 --> 01:08:36.730
I think everything should be a UASF.
903
01:08:37.515 --> 01:08:40.495
I do not think that minors or developers
904
01:08:40.955 --> 01:08:44.735
should really be deeply involved with the activation of anything.
905
01:08:45.355 --> 01:08:49.700
And I think that that is really the only way going forward to really
906
01:08:50.400 --> 01:08:51.940
create a consistent
907
01:08:52.560 --> 01:08:55.220
solidified dynamic where we maintain
908
01:08:56.525 --> 01:08:57.185
this mob
909
01:08:57.565 --> 01:09:00.225
and that dynamic where you don't just have
910
01:09:00.844 --> 01:09:06.940
that devolve into figureheads that are perpetually followed and listened to. And I think that either
911
01:09:07.560 --> 01:09:24.165
a feature done and turned on that way will gain the critical mass of support to successfully activate without too much disruption, or it will just be a bunch of goofballs like me with my single node getting attacked, while everybody runs away from the one true Bitcoin.
912
01:09:24.990 --> 01:09:25.310
And,
913
01:09:26.110 --> 01:09:29.570
you know, after that point, developers can just go back
914
01:09:30.030 --> 01:09:30.690
and just
915
01:09:31.390 --> 01:09:32.930
flip a rule on from
916
01:09:33.525 --> 01:09:35.945
Genesis. Like, you wait and let
917
01:09:36.565 --> 01:09:42.639
other clients or other groups actually get something turned on. And if it's successful,
918
01:09:42.940 --> 01:09:48.960
then just flip it on in the next release. Like, I I feel that developers should kind of just step back
919
01:09:49.355 --> 01:09:51.535
from the entire activation mechanic
920
01:09:52.315 --> 01:10:00.309
and just implement the validation logic of something. And if it's if they people want it and it gets turned on, then just flip that activation
921
01:10:00.610 --> 01:10:02.789
for, validation on in the next release.
922
01:10:03.170 --> 01:10:07.255
923
01:10:07.655 --> 01:10:10.455
The the overwhelming majority of people do not understand
924
01:10:11.255 --> 01:10:12.235
925
01:10:13.094 --> 01:10:20.210
as many of those as possible instead of just let things devolve to fewer and fewer of them. Fair enough.
926
01:10:20.590 --> 01:10:26.405
927
01:10:32.065 --> 01:10:38.130
There are real shelling points, Right? There are real points that make things a lot easier to deal with.
928
01:10:38.930 --> 01:10:44.875
And having the developers go, cool. This is what we think is the best thing is a perfectly reasonable thing for them to do.
929
01:10:46.135 --> 01:11:02.625
I do believe that it is very important that, you know, so so just just mechanically, there is a reason that you want to upgrade Bitcoin Core because, you know, there are CVEs or other things, you know, vulnerabilities in previous releases and other other reasons and speed improvements, you know. So
930
01:11:03.085 --> 01:11:04.545
there's a danger in tying
931
01:11:06.420 --> 01:11:07.480
upgrades to,
932
01:11:08.100 --> 01:11:09.160
support for a particular,
933
01:11:09.860 --> 01:11:11.800
fork. Right? I think just that's
934
01:11:13.220 --> 01:11:15.320
935
01:11:15.965 --> 01:11:19.664
If if things were done my way Yep. Everything,
936
01:11:19.965 --> 01:11:21.905
all those clients can be transitory.
937
01:11:22.364 --> 01:11:29.730
Like, you you use it to turn something on and then switch back to court. Yeah. I mean How do you know if you hit the critical mass in your
938
01:11:30.430 --> 01:11:31.490
939
01:11:32.270 --> 01:11:40.195
940
01:11:41.375 --> 01:11:52.990
941
01:11:53.485 --> 01:12:14.065
Now statistically, that can happen sometimes. So you've got to produce a few of them. Like, it's a really expensive test to run, but it is the only true way to test whether or not people are enforcing the rules is to break them. So you, like, pay the miner out of band or something? You literally have to pay a bunch of miners out of band to produce what are now invalid blocks to see if anyone follows them. Right?
942
01:12:15.725 --> 01:12:16.625
It's really tempting
943
01:12:17.600 --> 01:12:21.940
to to do. Fortunately, miners screw up all the time and so sometimes they accidentally do this experiment.
944
01:12:24.695 --> 01:12:38.780
But that that you'd have to have some litmus test there where where they and and they have to be stealth, right? So you can't just go, oh, well, all miners are blocking things from this pool because they know that pool is trying to produce invalid blocks and they haven't actually upgraded. They're just blocking. So, there are tricky mechanics in here,
945
01:12:39.240 --> 01:12:48.974
and it could be producing a valid block and they, oh, hey, no miners built on that. Yeah, Yeah, but it happened to be produced at the same time as this other block and maybe they stole the other block. So you've got to, you know, there are problems with this approach. But
946
01:12:49.594 --> 01:12:56.490
fundamentally that would be the test. Now before that everyone's nervous to use a new feature because they're not sure if it's enforced or not. So
947
01:12:57.190 --> 01:12:57.690
the
948
01:12:58.390 --> 01:13:13.260
minor signaling gives you a shelling point to go cool. Well, I'm pretty sure that everyone else is following that. My node has has activated is now enforcing that rule because it's sort of the minor signal. And I know everyone else will have seen the minor signal, So I'm assuming that all of us have moved forward together
949
01:13:13.719 --> 01:13:16.699
and we are all enforcing the rules. So now I have some degree
950
01:13:17.159 --> 01:13:17.820
of assurance.
951
01:13:18.175 --> 01:13:20.995
One, that the miners can't go back and stop enforcing the rules
952
01:13:21.295 --> 01:13:25.955
because all the nodes are already switched on and they're enforcing the rules so the miner's block will be rejected.
953
01:13:26.340 --> 01:13:35.000
Secondly, I can start using this feature pretty sure that everyone's got my back. Right? There are real shelling points here, and the developer's role as setting shelling points
954
01:13:35.725 --> 01:13:40.465
for for for ways we coordinate things should not be confused with their endorsement
955
01:13:40.925 --> 01:13:41.985
of a particular
956
01:13:42.450 --> 01:13:43.830
fork or not. I mean, obviously,
957
01:13:44.210 --> 01:13:51.430
they they have responsibility to do things that they think are technically correct. As individual developers are like, I really like the software. I think it's good for Bitcoin. Go ahead.
958
01:13:52.205 --> 01:13:57.025
But I have always believed that there should be an option well documented to say no,
959
01:13:57.645 --> 01:14:04.690
I do not want to support this fork. I want all the other good things, but no, I do not want this software to go ahead
960
01:14:05.630 --> 01:14:12.235
with full knowledge and documentation that that means that you may be on your own. You may fork yourself off the Bitcoin network.
961
01:14:14.135 --> 01:14:15.755
But I think fundamentally that responsibility
962
01:14:17.380 --> 01:14:20.440
no, fundamentally that responsibility is in an end user's hands,
963
01:14:20.740 --> 01:14:23.880
so we should make it clear that it is in their end users' hands, right?
964
01:14:24.795 --> 01:14:29.514
At the end of the day, the nodes get to decide what the network is and so we really need to make that
965
01:14:30.554 --> 01:14:37.060
like putting gratuitous road bumps in like, oh, yeah, you could do it, but you've got to run this patch software from this weird place and everything else
966
01:14:38.080 --> 01:14:41.300
is putting a hurdle in the way of them actually exercising that sovereignty.
967
01:14:41.615 --> 01:14:51.520
And so I would argue that the developer should probably just give them all the pieces, you know, maybe set the defaults and say, cool, by default it will do this, but you can totally turn it off
968
01:14:52.800 --> 01:14:59.860
and just embrace the fact that some people will do dumb shit and they may well fork themselves off the network. And,
969
01:15:01.075 --> 01:15:02.855
I'm sorry. At the end of the day,
970
01:15:03.475 --> 01:15:06.375
whether you like it or not, these people actually do have responsibility
971
01:15:06.675 --> 01:15:07.415
and control
972
01:15:07.875 --> 01:15:20.375
and so you might as well recognize it. I think trying to suppress it is dangerous. So what you're referring to is like a toggle in the the user interface? Like, there's you just switch it on or off? You've gotta be able to switch it on or off. Right?
973
01:15:20.695 --> 01:15:21.755
And I've already been
974
01:15:22.135 --> 01:15:26.870
975
01:15:27.350 --> 01:15:32.330
976
01:15:32.950 --> 01:15:34.650
977
01:15:35.615 --> 01:15:54.364
developers, it's natural to kind of go, well, we know the system best and we should decide. And the current crop of developers are fantastic and everything else, but I do worry about this generational change. Right? I do worry about, you know, I trust the existing developers. That may I trust all developers in the future? No. I have worked in open source software for 25 years. I have had developers
978
01:15:55.945 --> 01:15:59.005
do stupid shit. I've had them go insane.
979
01:15:59.385 --> 01:16:00.445
I have had them
980
01:16:02.160 --> 01:16:06.180
sorry, I'm not qualified to make that diagnosis but I've had them do things that
981
01:16:06.640 --> 01:16:07.780
take your breath away,
982
01:16:09.185 --> 01:16:10.485
Things that you would not believe
983
01:16:11.025 --> 01:16:11.845
that no normal
984
01:16:12.705 --> 01:16:15.045
just things that you would consider to be extreme
985
01:16:15.425 --> 01:16:18.325
irrational behavior. I've seen that. Breakdowns,
986
01:16:18.930 --> 01:16:19.670
you know,
987
01:16:21.250 --> 01:16:26.365
self, you know, self destructive behavior, all these kind of things. Anything that you can say considered human done, do,
988
01:16:26.825 --> 01:16:38.660
I've seen developers do it. It's their own projects and everything else. Right? So while generally, I think open source developers are these godlike figures who strut across the world and bring peace and happiness and all those things that we do,
989
01:16:39.520 --> 01:16:42.900
you know, I my experience has led me to believe that, you know,
990
01:16:44.614 --> 01:16:47.355
while I love them, I don't want to trust them
991
01:16:47.815 --> 01:16:51.835
and, you know, and things can go wrong. Right? So,
992
01:16:52.295 --> 01:16:58.160
I think the more software developers would like to get rid of this. Any perception of this having this power,
993
01:16:58.780 --> 01:16:59.600
over the network.
994
01:17:01.505 --> 01:17:04.485
You know, and I think some of the younger developers don't don't feel the same,
995
01:17:07.185 --> 01:17:08.325
don't feel the same
996
01:17:08.690 --> 01:17:09.190
urge
997
01:17:09.650 --> 01:17:14.710
to to to withdraw themselves. Right? I I think that's something that comes with time and experience.
998
01:17:15.170 --> 01:17:22.415
And I worry that, you know, the next generation developers will will feel that they're the logical masters of the network, and I think that's dangerous.
999
01:17:25.180 --> 01:17:25.920
1000
01:17:26.460 --> 01:17:31.040
Yeah. I mean, we we we actually, I think there should be a historical
1001
01:17:32.700 --> 01:17:33.200
course
1002
01:17:33.705 --> 01:17:34.765
for new developers
1003
01:17:35.225 --> 01:17:36.265
on the likes of,
1004
01:17:36.985 --> 01:17:39.165
Gavin Andresen and Mike Hearn.
1005
01:17:41.360 --> 01:17:45.940
1006
01:17:48.400 --> 01:17:49.699
1007
01:17:50.355 --> 01:17:51.975
I I am constantly
1008
01:17:52.835 --> 01:17:54.135
these days just
1009
01:17:54.435 --> 01:17:59.094
randomly thinking, like, half of the Bitcoiners who got here since 2017
1010
01:18:00.099 --> 01:18:01.800
don't even know who Greg is.
1011
01:18:03.219 --> 01:18:05.800
1012
01:18:07.139 --> 01:18:07.639
Look,
1013
01:18:08.865 --> 01:18:14.165
you know, look, you're not a Bitcoin OG unless you're in Bitcoin before me. Right? That's always everyone's definition of Bitcoin OG.
1014
01:18:16.510 --> 01:18:20.050
So unless you had, you know, unless you're on the IRC channel, Bitcoin OTC,
1015
01:18:21.230 --> 01:18:24.750
trying to get Bitcoin and using your GPG address to, like, you know,
1016
01:18:25.555 --> 01:18:28.535
to do that, then you're not a real OG Bitcoiner. Sorry.
1017
01:18:30.835 --> 01:18:31.155
So
1018
01:18:32.435 --> 01:18:32.935
yeah.
1019
01:18:33.715 --> 01:18:34.215
Yeah.
1020
01:18:35.030 --> 01:18:35.850
I I think
1021
01:18:36.870 --> 01:18:37.830
I don't know. I
1022
01:18:38.390 --> 01:18:38.890
inevitably,
1023
01:18:39.670 --> 01:18:47.445
you know, some knowledge will get lost and and people will will come in with different viewpoints. And as we go more mainstream, this is inevitable. But I do like the idea that,
1024
01:18:48.705 --> 01:18:49.925
we have a whole heap of,
1025
01:18:51.185 --> 01:18:57.159
you know, I think it is important for Bitcoiners to realize and I believe that they do, that they have a responsibility,
1026
01:18:57.860 --> 01:18:59.880
at the end of the day. If you're a sovereign individual,
1027
01:19:00.405 --> 01:19:09.385
then you are going to have a lot of responsibility over your own your own coins. Right? Just running your own node, it's it's it's having your own stuff and it means upgrades
1028
01:19:10.679 --> 01:19:13.420
are, for better or worse, are gonna be your concern.
1029
01:19:14.120 --> 01:19:19.260
They're gonna affect you to some extent, or at least you should make sure that you're happy that they don't affect you.
1030
01:19:19.755 --> 01:19:20.255
Right?
1031
01:19:21.675 --> 01:19:23.695
But, yeah, I don't know. Maybe that doesn't scale.
1032
01:19:24.155 --> 01:19:26.255
1033
01:19:26.635 --> 01:19:30.690
like, pure ossification anytime soon, I think for, like, these major changes,
1034
01:19:32.670 --> 01:19:33.890
the safer approach
1035
01:19:35.230 --> 01:19:36.350
tends to just be,
1036
01:19:38.014 --> 01:19:39.554
to default to no.
1037
01:19:39.934 --> 01:19:43.795
Right? Like, I was with with this CTV conversation, I was hoping
1038
01:19:44.255 --> 01:19:46.114
it was just gonna kinda go away.
1039
01:19:46.560 --> 01:19:49.460
Didn't really wanna have the conversation or learn about it.
1040
01:19:50.159 --> 01:20:08.110
And, like, my hand was forced, and a lot of freaks were like, Matt, you need to have a conversation about it on sale of dispatch. I was like, I really don't wanna I don't even wanna do it. Like, I just don't wanna update, don't wanna bother with it. I mean, like, that's perfectly, like, rational. I mean, to to say no by default, to be conservative
1041
01:20:08.490 --> 01:20:09.150
1042
01:20:09.610 --> 01:20:17.695
to go, I don't understand or see how this benefits me. I'm not okay with this. All of those things are
1043
01:20:18.235 --> 01:20:19.535
completely reasonable
1044
01:20:20.155 --> 01:20:21.055
and what
1045
01:20:21.435 --> 01:20:27.320
this system should be built on. The thing that's been driving me insane, like, the last 2 weeks
1046
01:20:27.620 --> 01:20:38.395
is all of these people, like, confidently asserting, like, all these things that CTV can do to be a huge risk to Bitcoin or, like, break the system. And it's just like, no.
1047
01:20:38.715 --> 01:20:40.255
That's factually incorrect.
1048
01:20:41.719 --> 01:20:44.460
Either make a reasonable argument for why,
1049
01:20:45.320 --> 01:20:50.300
you don't wanna do this, learn what you're talking about, or shut the fuck up.
1050
01:20:51.454 --> 01:20:56.034
1051
01:20:57.454 --> 01:21:00.770
And I have a day job, and this is not it. So,
1052
01:21:01.150 --> 01:21:04.610
you know, I'm I'm concentrating on lightning and all those cool things, but,
1053
01:21:05.070 --> 01:21:11.204
you know, it it it reaches a certain point where you're like, okay. I've gotta to weigh in, I've got to have an opinion, I've got to read the bib, I've got to think through it,
1054
01:21:11.925 --> 01:21:12.824
and all those things.
1055
01:21:13.125 --> 01:21:15.224
So I am also dragged here reluctantly.
1056
01:21:15.740 --> 01:21:23.485
1057
01:21:24.364 --> 01:21:27.025
1058
01:21:27.645 --> 01:21:31.185
everyone's really busy doing cool stuff and everything else. And so
1059
01:21:31.965 --> 01:21:32.465
almost
1060
01:21:33.790 --> 01:21:38.930
it needs to get to the point where people feel, Oh, crap. It's happening now, before the leaders start paying attention,
1061
01:21:39.390 --> 01:21:39.890
which
1062
01:21:40.430 --> 01:21:45.895
is too late. You really hope that everyone was paying attention the whole time. And by the time it got to the, oh, it's about to happen,
1063
01:21:46.275 --> 01:21:49.415
you've had all those debates, you've had all these arguments, there's broad consensus.
1064
01:21:49.795 --> 01:21:52.020
But in practice, it doesn't work that way. Right?
1065
01:21:53.140 --> 01:21:54.920
Yeah. Same with Taproot. Right?
1066
01:21:55.620 --> 01:22:02.054
Everyone's happy with it. It shipped. And now people are finally starting, Oh, we better start building all the stuff that we promised. Right?
1067
01:22:02.355 --> 01:22:04.135
So that's human nature,
1068
01:22:05.074 --> 01:22:05.895
and that's
1069
01:22:06.355 --> 01:22:16.940
1070
01:22:19.945 --> 01:22:28.340
1071
01:22:28.640 --> 01:22:30.500
drafts for a while that I've been bouncing
1072
01:22:31.120 --> 01:22:33.135
bouncing back and forth with Anthony Towns,
1073
01:22:33.534 --> 01:22:34.675
who had some good feedback.
1074
01:22:36.494 --> 01:22:37.155
You know,
1075
01:22:38.255 --> 01:22:51.784
and I went okay, well I needed to post that last night, my time, or this morning, your time, because I'm like, well, I'm gonna appear on Citadel Dispatch, so I better have better bring something to the show. Right? So so that that was that was an incentive for me to finally
1076
01:22:52.324 --> 01:22:53.224
push that out.
1077
01:22:54.324 --> 01:22:57.465
Love it. Yeah. Otherwise, we would have done this last week.
1078
01:22:58.610 --> 01:22:59.990
1079
01:23:00.770 --> 01:23:03.430
that's my contribution to the development process.
1080
01:23:05.570 --> 01:23:07.270
1081
01:23:08.425 --> 01:23:11.405
short, like, the people who've just been actively
1082
01:23:11.864 --> 01:23:12.925
spreading misinformation
1083
01:23:13.625 --> 01:23:17.005
instead of just being a healthy level of skeptical,
1084
01:23:17.750 --> 01:23:22.090
this was a really healthy thing to happen. Like, it's forced
1085
01:23:22.949 --> 01:23:24.010
actual information
1086
01:23:24.389 --> 01:23:30.015
out into the community so that people can start really understanding this. It's brought the whole
1087
01:23:30.395 --> 01:23:34.255
topic of covenants to, like, the wider discussion. I mean, all the
1088
01:23:34.699 --> 01:23:40.639
the annoyance, the nonsense, the drama, I think at the end of the day, this was a a really healthy thing to happen.
1089
01:23:41.659 --> 01:23:46.625
1090
01:23:47.805 --> 01:23:55.290
And, you know, that that will increase as people start playing with them more as they seem more real. And that feedback loop is gonna be interesting because I don't quite know where it'll lead.
1091
01:23:56.150 --> 01:23:59.850
I would look to people like Russell O'Connor, who is the the other
1092
01:24:00.445 --> 01:24:01.324
Russell at,
1093
01:24:02.925 --> 01:24:03.585
at Blockstream.
1094
01:24:03.965 --> 01:24:09.350
And and and you can tell us apart, by the way, because if we're having an argument over something technical, he's the one who's right
1095
01:24:11.910 --> 01:24:23.905
and I'm the one who's wrong. So so so, you know, I I always you know, it'll be interesting. I think that as our as our thinking matures, there'll be people come forth with with other ideas, and we will reach consensus because I feel that we haven't had that
1096
01:24:24.525 --> 01:24:31.239
level of, like, really rigorous oversight so far in this conversation. Because I think most people being just staying on the sidelines.
1097
01:24:31.860 --> 01:24:40.865
1098
01:24:41.805 --> 01:24:45.320
I mean, we should have probably had this conversation before Taproot got activated,
1099
01:24:45.860 --> 01:24:48.840
but at least we're having it now. Well, I mean, ironically,
1100
01:24:50.235 --> 01:24:56.255
1101
01:24:56.795 --> 01:24:59.454
so that it could be embedded in a Taproot tree.
1102
01:25:02.130 --> 01:25:02.630
1103
01:25:03.409 --> 01:25:04.630
Same with, you know, anyprevout
1104
01:25:05.010 --> 01:25:06.230
was the other one that
1105
01:25:08.505 --> 01:25:15.640
was people were thinking, you know, hey. We we really want this in. And, you know, there's particular work around making sure that it could go in later.
1106
01:25:16.120 --> 01:25:23.660
And this is the same. Right? It's like, well, if it can be unbundled, it should be. And particularly, yeah, Taproot was was a pretty big big deal.
1107
01:25:23.994 --> 01:25:27.855
So that that, to be fair, it's gonna take us, like, 5 years to truly exploit.
1108
01:25:29.915 --> 01:25:30.875
1109
01:25:31.990 --> 01:25:34.530
is, is simplicity still 2 weeks away?
1110
01:25:36.270 --> 01:25:37.330
1111
01:25:37.950 --> 01:25:42.765
Yes. Again, ask ask Russell O'Connor. I mean, you know, simplicity is one of those things that's incredibly ambitious.
1112
01:25:43.705 --> 01:25:56.550
And, really, for humans like me to use it, it's gonna have to be you know, there's gonna have to be, like, tooling on top that that does the thing and turns it in simplicity and and, you know, and does a lot of the great things that it does because, you know, I'm not smart enough to write raw simplicity.
1113
01:25:57.094 --> 01:26:00.875
Hell, I'm not smart enough to write raw Bitcoin scripts. So, you know,
1114
01:26:02.295 --> 01:26:04.554
tooling definitely has a long way to go on both of those.
1115
01:26:05.400 --> 01:26:07.400
1116
01:26:07.880 --> 01:26:09.179
I barely understand
1117
01:26:09.639 --> 01:26:12.219
any of it beyond the logic of formal
1118
01:26:12.520 --> 01:26:13.020
verification,
1119
01:26:14.645 --> 01:26:17.625
and there's definitely value I see in that. But,
1120
01:26:18.405 --> 01:26:20.585
yeah, I I I could not
1121
01:26:21.445 --> 01:26:27.680
say 2 sentences besides it would let us do more complicated things and be sure they won't explode.
1122
01:26:28.540 --> 01:26:29.040
Yep.
1123
01:26:29.765 --> 01:26:33.545
1124
01:26:35.525 --> 01:26:41.960
simplicity is basically a a completely different scripting system, basically, that that that Blockchain Research,
1125
01:26:42.739 --> 01:26:45.000
under Russell O'Connor have been developing,
1126
01:26:45.699 --> 01:26:48.675
particularly with an emphasis on being able to formally prove stuff about it
1127
01:26:49.474 --> 01:26:50.755
in in useful ways.
1128
01:26:51.155 --> 01:26:51.895
So it's
1129
01:26:52.675 --> 01:26:58.120
it's really great stuff so you can go cold. Okay. I I can prove that these coins will be spendable under these conditions and whatever else.
1130
01:26:58.760 --> 01:26:59.240
So,
1131
01:26:59.720 --> 01:27:07.180
it's it's great from that point of view, and it's called simplicity because basically the fundamental level at level, it's very, very simple, and you build everything up from that.
1132
01:27:08.265 --> 01:27:10.525
But simple doesn't mean easy. Right? So,
1133
01:27:12.185 --> 01:27:24.389
so it all comes down to, like, the tooling and and your ability to actually utilize this. And, you know, just because you can prove that something happens doesn't necessarily mean that you prove what you want it to happen. Right? You can still foot gun yourself, I'm pretty sure.
1134
01:27:24.690 --> 01:27:24.849
So
1135
01:27:26.005 --> 01:27:27.065
1136
01:27:27.844 --> 01:27:30.265
this has been an absolutely fantastic conversation.
1137
01:27:30.645 --> 01:27:35.140
I know we're hitting the point where Rusty has some other responsibilities
1138
01:27:35.520 --> 01:27:36.580
to take care of.
1139
01:27:36.960 --> 01:27:39.140
I I really appreciate both of your time.
1140
01:27:39.600 --> 01:27:46.175
You know, this conversation has been very helpful to me. I often say that my favorite dispatches are the ones where I just sit quietly and listen,
1141
01:27:46.955 --> 01:27:51.215
and I really needed this conversation, so I hope the freaks have found it helpful as well.
1142
01:27:52.130 --> 01:27:55.430
I like to end the shows with final thoughts.
1143
01:27:56.130 --> 01:27:58.150
So with that said, final thoughts, Shinobi.
1144
01:27:59.945 --> 01:28:01.805
1145
01:28:03.145 --> 01:28:07.245
you know, I would say when things like this come out of left field,
1146
01:28:07.740 --> 01:28:08.240
like,
1147
01:28:08.860 --> 01:28:12.400
no as a default answer is totally reasonable.
1148
01:28:12.780 --> 01:28:13.920
Like, caution
1149
01:28:14.220 --> 01:28:15.120
and or
1150
01:28:15.660 --> 01:28:17.455
skepticism and even paranoia
1151
01:28:18.235 --> 01:28:18.975
is totally
1152
01:28:19.675 --> 01:28:20.175
rational.
1153
01:28:21.035 --> 01:28:21.535
But,
1154
01:28:22.475 --> 01:28:26.929
like, you should not cross the line of actively misinforming
1155
01:28:27.389 --> 01:28:27.889
people
1156
01:28:28.429 --> 01:28:35.329
and stating things that you are not sure of or that are just hearsay to you about something being proposed
1157
01:28:35.695 --> 01:28:38.355
because that actively attacks and undermines
1158
01:28:39.215 --> 01:28:45.550
the entire process of understanding something to see whether there is or isn't consensus.
1159
01:28:46.330 --> 01:28:47.550
And also, Rusty,
1160
01:28:48.410 --> 01:28:50.010
because of the time constraint and,
1161
01:28:50.785 --> 01:28:58.325
us not being able to get into that, I am going to twist your arm to come back on sometime to talk lightning because this is a really fun conversation.
1162
01:28:59.830 --> 01:29:07.370
1163
01:29:08.125 --> 01:29:16.225
1164
01:29:16.930 --> 01:29:28.525
I do think, you know, there's a meta incentive question that that is harder to answer. Like, as we make Bitcoin more powerful, are we risking people build things on top of Bitcoin that we don't like either because they do stabilize Bitcoin or because they're stupid or whatever else?
1165
01:29:30.025 --> 01:29:34.925
But, fundamentally, they are that on a technical level, I think, you know, there's nothing,
1166
01:29:35.560 --> 01:29:36.780
you know, there's nothing
1167
01:29:37.400 --> 01:29:38.780
evil or novel about,
1168
01:29:39.160 --> 01:29:43.900
Bitcoin covenants. On the other hand, I actually watched Shinobi said that, you know, caution is,
1169
01:29:44.555 --> 01:29:46.895
you know, as long as not gone to ridiculous lengths,
1170
01:29:47.195 --> 01:29:49.455
caution is very, very important to Bitcoin.
1171
01:29:49.755 --> 01:29:54.830
And so we should be slowly and carefully. That means it's gonna take years, and that's okay.
1172
01:29:56.490 --> 01:29:58.910
1173
01:29:59.505 --> 01:30:05.925
I look forward to having you both on dispatch in the future to have that lightning conversation and other conversations, hopefully.
1174
01:30:06.920 --> 01:30:14.475
And I wanna do a huge thanks to all of our listeners who continue to support the show and join us in the live chat. Cheers all. Thank you.
1175
01:30:30.965 --> 01:30:32.905
1176
01:30:33.205 --> 01:30:33.945
a wall.
1177
01:30:47.165 --> 01:30:47.665
City
1178
01:30:48.125 --> 01:30:49.185
on a hill.
1179
01:30:54.205 --> 01:30:56.385
Gonna build their city
1180
01:31:04.765 --> 01:31:06.625
teas are gonna spill.
1181
01:31:10.765 --> 01:31:11.265
So
1182
01:31:32.510 --> 01:31:33.410
until it's
1183
01:31:33.870 --> 01:31:34.370
done.
1184
01:31:38.510 --> 01:31:39.010
Don't
1185
01:31:39.550 --> 01:31:40.850
build that wall
1186
01:32:36.675 --> 01:32:43.495
the ground, searching to behold the stories that I told. My black ones to the world that was smiling when I've heard,
1187
01:32:43.795 --> 01:32:45.335
tell you we are the greatest. Put
1188
01:32:46.195 --> 01:32:46.580
my
1189
01:35:27.870 --> 01:35:31.650
1190
01:35:32.350 --> 01:35:37.165
Really do appreciate all your support watching the SAD stream in, watching the boost come in
1191
01:35:37.545 --> 01:35:41.485
through the podcasting 2 point o, watching the BTC pay server get hit.
1192
01:35:43.210 --> 01:35:45.310
It really is an honor and a privilege
1193
01:35:46.810 --> 01:35:48.830
to be with you guys every Bitcoin Tuesday.
1194
01:35:49.530 --> 01:35:53.445
It's something that I really do love doing, and I appreciate you all.
1195
01:35:54.625 --> 01:35:56.244
Now it's time for me to
1196
01:35:56.704 --> 01:36:00.804
have 20 Bitcoin over 20 Bitcoiners over and grill them some stakes.
1197
01:36:01.250 --> 01:36:02.950
Love you all. Stay on, BoomstackSats.
1198
01:36:03.570 --> 01:36:04.070
Cheers.