CD70: using lightning privately with tony and @futurepaul
EPISODE: 70
BLOCK: 744604
PRICE: 4882 sats per dollar
TOPICS: private lightning wallet, vortex, austin bitcoin design club, tor tradeoffs, open source licenses
https://citadeldispatch.com/cd70
@futurepaul: https://twitter.com/futurepaul
support the show: https://citadeldispatch.com/contribute
twitch: https://twitch.tv/citadeldispatch
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://www.podpage.com/citadeldispatch
telegram: https://t.me/citadeldispatch
stream sats to the show: https://www.fountain.fm/
join the chat: https://matrix.to/#/#citadel:bitcoin.kyoto
01:10 - Using lightning privately
19:44 - Adding hops for increased privacy
33:59 - Running the wallet on a node box
39:35 - Discussion about private lightning wallets
40:53 - Conversation about the importance of trust in systems
01:00:34 - Discussion about the need for more Tor relay nodes
01:20:14 - No k y c version of Ibex that collapses all payments to an on-chain address
01:21:22 - LN Connect and its use of Tor for lightning network connections
01:26:30 - Voltage's non-custodial cloud hosting for lightning nodes
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 4:24:54 PM
Duration: 6683.611
Channels: 1
1
00:00:35.750 --> 00:00:36.650
2
00:00:37.670 --> 00:00:38.890
Monday, freaks.
3
00:00:39.270 --> 00:00:40.410
It's Monday. Right?
4
00:00:41.545 --> 00:00:45.805
It's a lot. It is. It's gonna check. It's the start of a long week.
5
00:00:46.425 --> 00:00:48.684
There'll be many dispatches this week.
6
00:00:49.410 --> 00:00:50.070
Make sure,
7
00:00:50.610 --> 00:00:54.230
if you wanna get notified, either join our matrix chat.
8
00:00:56.515 --> 00:00:57.415
9
00:00:58.274 --> 00:00:59.815
Oh, no. There we go.
10
00:01:00.995 --> 00:01:05.415
11
00:01:05.800 --> 00:01:10.060
It's gonna be a long week. A lot of great conversations are gonna be happening here at the studio.
12
00:01:10.840 --> 00:01:11.880
We got the start,
13
00:01:12.600 --> 00:01:17.405
of this week with Citadel dispatch 70 with our good friend, Tony, who was here last week,
14
00:01:17.705 --> 00:01:19.645
and Paul Miller, who's in town now.
15
00:01:20.425 --> 00:01:26.830
Our primary discussion today will be focused on using lightning privately, but we'll be going all over the place.
16
00:01:27.770 --> 00:01:34.354
If you wanna participate in the live chat, you can do that through Twitch or Twitter or our matrix chat, which you can find at citadel.chat.
17
00:01:36.415 --> 00:01:46.119
I did set up a YouTube for dispatch so you could get notified when we go live and also participate in the chat, But there's a 24 hour delay when you enable live streams.
18
00:01:46.420 --> 00:01:51.720
So this will be the last one that is not streamed there as well. I will post the the video clip there afterwards.
19
00:01:52.535 --> 00:02:02.360
But if you are a YouTube user, you can go and subscribe there, and dispatches going forward will be there. As always, I wanna thank all the ride or die freaks who continue to support the show
20
00:02:03.000 --> 00:02:07.100
and keep it ad free and sponsor free. Really could not do it without you.
21
00:02:08.280 --> 00:02:14.815
As always, the easiest way to support the show is through podcasting 2 point o apps. My favorites are Breezewallet,
22
00:02:15.115 --> 00:02:17.775
fountain podcast, and there's another one, podverse.fm,
23
00:02:18.555 --> 00:02:20.140
if you wanna do it from the browser.
24
00:02:21.660 --> 00:02:28.160
You can go in there. You can set how many sats per minute you think the show is worth. As you listen, it'll automatically stream sats
25
00:02:28.515 --> 00:02:30.135
to my node and also
26
00:02:30.754 --> 00:02:35.334
to the nodes of various open source projects that dispatch is supporting.
27
00:02:36.194 --> 00:02:37.735
Those projects include
28
00:02:38.670 --> 00:02:39.890
OpenSats, RaspiBlitz,
29
00:02:40.190 --> 00:02:42.770
RoboSats, Seed Signer, Sparrow Wallet,
30
00:02:43.070 --> 00:02:43.810
and Zeus.
31
00:02:44.350 --> 00:02:45.490
So if you support
32
00:02:46.055 --> 00:02:54.475
dispatch through podcasting 2 point o, not only do you keep this show ad free and sponsor free, completely audience funded, but you also support those great open source projects.
33
00:02:55.989 --> 00:02:58.970
You can also support the show using my pay name, which is Odell
34
00:02:59.670 --> 00:03:01.930
or the BTC pay server that's at sidildispatch.com.
35
00:03:02.470 --> 00:03:12.035
So once again, thanks to everyone who continues support the show. And if you don't have stats to spare, subscribing in your favorite podcast app by searching citadel dispatch or subscribing on YouTube, Twitch,
36
00:03:12.590 --> 00:03:13.090
Twitter,
37
00:03:13.630 --> 00:03:14.130
Rumble,
38
00:03:14.750 --> 00:03:24.224
does help the show, and I do appreciate it. As we start off every show, we're gonna start with the top boost, which is also a feature on podcasting 2 point o. It's called the Boostagram.
39
00:03:24.925 --> 00:03:26.385
That's a one time payment
40
00:03:26.685 --> 00:03:33.620
of your choosing that also gets split with the open source projects, and you get to include a message with it. I will read the top 4 Boostagrams.
41
00:03:34.320 --> 00:03:36.740
We have Tim Thielman with 20,000 sats.
42
00:03:37.120 --> 00:03:38.340
Thanks for your leadership.
43
00:03:38.795 --> 00:03:42.894
You've inspired the start up of our Bitcoin meetup in Victoria, BC.
44
00:03:43.435 --> 00:03:51.239
A question, many Bitcoiners I meet don't wanna spend only a HODL, but this leaves exchanges at choke points for government regulation, predatory tax, and seizure,
45
00:03:51.540 --> 00:03:56.415
which impairs the store value they are holding for. How can we overcome this incentive mismatch
46
00:03:57.035 --> 00:03:59.855
to grow the circular economies we will eventually need?
47
00:04:01.560 --> 00:04:02.540
So that's a question.
48
00:04:03.560 --> 00:04:18.840
Before we answer that, I'm gonna read the other 3 boostograms. We have shout out we have Odiums with 11,000 sats saying shout out to the Raspberry Blitz team and Root Soul, Open Arms and Co, Best Node Project, and thanks, Matt, for supporting the Raspberry Blitz Step Fund through value for value.
49
00:04:19.380 --> 00:04:27.000
We have Rick Amaru with 10,000 stats. I will stream stats to you all day for this level of discussion, Odell. Keep it up, brother. Peace.
50
00:04:27.305 --> 00:04:28.845
And we have Kobe saying,
51
00:04:29.384 --> 00:04:37.889
the split is breaking the boost for 10,000 sats. Well, clearly, his boost to gram went through, so I'm gonna continue to push the limits with the number of splits we have.
52
00:04:38.270 --> 00:04:41.889
Before we get started with the show, I guess let's introduce our guests first.
53
00:04:42.190 --> 00:04:57.760
We have returned guest and good friend, Paul Miller at future Paul on Twitter. How's it going, Paul? It's going good. Thank you for having me back. Appreciate it, man. And then we have good friend, Tony Giorgio, in the house. How's it going, Tony? My name is Giovanni Giorgio,
54
00:04:58.220 --> 00:05:00.639
55
00:05:08.440 --> 00:05:09.980
So, guys, it's good to be back.
56
00:05:11.320 --> 00:05:12.200
57
00:05:13.320 --> 00:05:16.860
such a rider, I guess, that now he has his own space on the soundboard,
58
00:05:17.400 --> 00:05:19.574
going forward. So you'll probably hear Tony,
59
00:05:20.035 --> 00:05:21.895
a lot more for the rest of the week.
60
00:05:22.275 --> 00:05:24.854
So let's go to this question real quick before we get started.
61
00:05:25.539 --> 00:05:30.280
Basically, it was around how do we incentivize a circular economy for Bitcoin rather than people
62
00:05:30.819 --> 00:05:31.960
buying and selling,
63
00:05:33.065 --> 00:05:37.885
Bitcoin. They are earning and spending Bitcoin. What do you guys think about that?
64
00:05:39.065 --> 00:05:46.220
65
00:05:47.500 --> 00:05:51.995
block party, which was about, you know, spending money at taco trucks,
66
00:05:52.615 --> 00:05:58.155
which was really fun. It was fun to buy things for real with Bitcoin. I think of it as like rehearsal.
67
00:05:58.919 --> 00:06:02.860
It is not really economically rational to spend Bitcoin
68
00:06:03.800 --> 00:06:05.820
for for goods when you have
69
00:06:06.195 --> 00:06:07.575
fiat in your bank account.
70
00:06:08.595 --> 00:06:09.895
And I really like
71
00:06:10.275 --> 00:06:15.415
saving things on, you know, if Bitcoin depends on us doing economically irrational things
72
00:06:15.889 --> 00:06:23.430
for for Bitcoin to succeed, then Bitcoin will succeed. So I don't think Bitcoin needs us to do economically irrational things. But what is nice is
73
00:06:23.735 --> 00:06:25.514
as someone who views themselves
74
00:06:26.055 --> 00:06:50.250
as part of building Bitcoin, it is fun to practice the circular economy. So that's the way I normally frame it. Like, hey, let's have a good time. Let's larp a little bit. Do some circular economy. I'm not gonna do all my payments like this yet, but let's make sure these rails work and and that will, you know, help kick the tires. And so we're gonna be ready when we need it. But we don't need it at least in the US. So, it's not
75
00:06:50.810 --> 00:06:52.590
rational to do it all the time.
76
00:06:53.290 --> 00:06:58.430
77
00:06:58.745 --> 00:07:07.085
if your income and savings is in Bitcoin already. Right? Mhmm. But if you haven't hit that part, then people are inclined to spend Fiat first.
78
00:07:08.840 --> 00:07:18.104
79
00:07:18.645 --> 00:07:20.645
But then there you know, there's an avenue of,
80
00:07:21.764 --> 00:07:30.410
you know, once we get these merchants and everything set up one time, like, you know, we go to Miami and we set up some merchants on Bitcoin there too, like, once a year,
81
00:07:30.870 --> 00:07:48.090
and then we sort of sleep. And then they're, like, left with, like, a Bitcoin integration that, like, maybe nobody's using at all. And then it's like, well, that was a failed experiment. No one actually came back and started using Bitcoin. Yeah. And what if they end up with a bad taste in the mouth? Like, the next time someone like, maybe Bitcoin is ready for them next time around.
82
00:07:48.525 --> 00:08:25.885
83
00:08:26.985 --> 00:08:29.880
84
00:08:30.180 --> 00:08:33.160
85
00:08:33.700 --> 00:08:35.480
86
00:08:38.625 --> 00:08:42.565
I mean, YouTube can go fuck themselves. If we get banned, we get banned, whatever. That's why bitcointv.com
87
00:08:43.265 --> 00:08:43.765
exists.
88
00:08:44.660 --> 00:08:50.680
I I one thing I would add here. First of all, there's been a bunch of different dispatch episodes purely focused on
89
00:08:51.060 --> 00:08:54.635
growing the circular economy. It's something that I've been very focused on lately,
90
00:08:55.335 --> 00:09:00.375
really in-depth conversations. People should go check them out. But one thing we are missing it here is,
91
00:09:01.560 --> 00:09:05.180
there is Oshi app now by our good friend, Michael Atwood,
92
00:09:05.880 --> 00:09:14.105
and Oshi gives you stats back. So that can change, that calculation in your head, if you can get a decent amount of sats back by spending Bitcoin.
93
00:09:15.125 --> 00:09:16.105
I also think,
94
00:09:17.340 --> 00:09:23.840
that if if I mean, this conversation is about Lightning using Lightning privately. Right? So if there's a transaction that,
95
00:09:24.154 --> 00:09:29.775
you know, you'd prefer not you know, if you're trying to get out of this surveillance state, right, where you're using credit cards,
96
00:09:30.475 --> 00:09:32.815
or using payment apps on your phone or something,
97
00:09:33.370 --> 00:09:36.269
and you want to start taking some of your privacy back,
98
00:09:36.649 --> 00:09:40.029
there's a strong argument for using Bitcoin in payments,
99
00:09:40.555 --> 00:09:48.735
if if you do understand the nuances of using it privately. But I would I mean, every transaction you make on a credit card or payment app is is tracked by default.
100
00:09:49.355 --> 00:09:49.515
101
00:09:50.160 --> 00:09:58.100
Right. And at least with I mean, we've gone over it many times, but at least spending on Lightning is has pretty good privacy. So you can comp you know, pretty competently
102
00:09:59.175 --> 00:10:03.035
not screw up if you're if you're using lightning in that way. Yeah. I think,
103
00:10:04.055 --> 00:10:07.995
104
00:10:08.590 --> 00:10:15.490
One of the things we do here with our community is we give them as many options as as possible to to spend with Bitcoin.
105
00:10:16.265 --> 00:10:25.245
And, you know, they'll find their way eventually when they're ready to spend it, but put those options in front of them. Right? Like, we like, at the NASH Bitcoiners meetup that we're gonna have
106
00:10:26.270 --> 00:10:27.010
on Wednesday,
107
00:10:27.950 --> 00:10:30.050
you'll be able to buy coffee
108
00:10:30.430 --> 00:10:37.305
from a nice local coffee purveyor with Bitcoin, and you'll be able to buy burgers from a local burger place, with Bitcoin.
109
00:10:37.925 --> 00:10:42.750
And, you know, you'll also be able to pay Fiat if you wanna pay Fiat, but the both of those,
110
00:10:44.910 --> 00:10:46.290
both of those small businesses
111
00:10:47.389 --> 00:10:57.235
intend to hold their Bitcoin long term. They're trying to build a Bitcoin stack themselves, and and you can kind of incentivize that adoption by these local businesses by by going and spending with them.
112
00:10:58.415 --> 00:11:00.275
113
00:11:01.600 --> 00:11:07.620
Michael Oshi onboarded a coffee shop in Austin, and they do, like, I think, like, a weekly get together
114
00:11:08.000 --> 00:11:08.500
there.
115
00:11:09.285 --> 00:11:13.305
Was it the yeah. At the meteor Bitcoin breakfast. So, like, onboard
116
00:11:14.085 --> 00:11:20.210
a Bitcoin business and then have your meetup at that business so that you create, like, the the regular thing so that it wasn't,
117
00:11:20.590 --> 00:11:33.345
118
00:11:34.250 --> 00:11:40.895
of customer revenue coming in, and they don't have to worry about swings, you know, so they're still paying fiat bills with the other customers. So,
119
00:11:41.695 --> 00:11:43.555
it it like, doing it consistently
120
00:11:44.015 --> 00:11:44.515
and,
121
00:11:44.895 --> 00:11:48.275
reliably and keep coming back, I I see a lot of value in that.
122
00:11:49.569 --> 00:11:50.069
123
00:11:50.529 --> 00:11:58.230
Yeah. Okay. So let's let's talk into let's jump into our main topic of conversation, and then we can weave and move around. And as always, freaks,
124
00:11:58.725 --> 00:12:00.185
feel free to put your comments,
125
00:12:00.885 --> 00:12:06.745
in the live chat. And, I actually part of the reason we had the technical difficulty before is I actually have a TV in here now
126
00:12:07.090 --> 00:12:13.590
with the live chat up so both of our guests can see it, so I'm not a central point of failure on that. Shout out, weird robot,
127
00:12:14.585 --> 00:12:21.165
his coworker. 1st weird robot's the first person to ever post a YouTube comment from the CIL dispatch YouTube. Wow.
128
00:12:21.630 --> 00:12:24.050
That works. You'll never be you'll never be topped
129
00:12:24.430 --> 00:12:28.210
weird weird robot. Would I call him wide robot? Wide robot.
130
00:12:29.545 --> 00:12:34.845
Sorry, freaks. It's been a long day. We're just getting everything ready over here. I just got a ton of people coming in.
131
00:12:36.265 --> 00:12:39.085
So we're gonna be talking about using lightning privately.
132
00:12:39.770 --> 00:12:42.510
I've had Tony on multiple times for this conversation.
133
00:12:43.450 --> 00:12:48.925
You guys apparently he mentioned you in the last conversation, Paul. You guys are working on something called,
134
00:12:49.404 --> 00:12:51.584
really great name, the Private Lightning Wallet.
135
00:12:52.445 --> 00:12:56.225
You wanna go into, you know first of all, I guess, what was the,
136
00:12:57.079 --> 00:13:02.459
like, why are are you working on this? Mhmm. And and then what does it provide us?
137
00:13:03.695 --> 00:13:07.475
138
00:13:08.654 --> 00:13:22.504
139
00:13:23.365 --> 00:13:24.024
140
00:13:24.964 --> 00:13:28.425
141
00:13:28.805 --> 00:13:31.100
142
00:13:32.040 --> 00:13:33.100
143
00:13:34.200 --> 00:13:35.740
like, n stands for wallet. Yeah.
144
00:13:36.120 --> 00:13:39.605
Tony and I like to do hack on, projects. We've been talking about,
145
00:13:39.985 --> 00:13:42.964
what it would look like to make a wallet for a while.
146
00:13:43.665 --> 00:13:47.900
And it's one of those things it's, you know, it's a big project. There's a lot to it, typically.
147
00:13:49.800 --> 00:13:50.300
So,
148
00:13:50.760 --> 00:14:00.375
it, you know, it's a it's a little intimidating. So it's it's it turns into being a really fun hackathon projects. It's like, yeah, let's waste some time. Let's do a thing we're not gonna do normally.
149
00:14:00.995 --> 00:14:04.829
But when we sat down and, like, sketched out, what would it
150
00:14:05.209 --> 00:14:11.310
do, I think it, like it felt like it just right in that moment, crystallized a lot of the things that we've been discussing
151
00:14:12.265 --> 00:14:14.365
of of okay. There you know,
152
00:14:14.745 --> 00:14:18.845
Tony obviously has written a lot and thought a lot about how to actually use
153
00:14:19.545 --> 00:14:20.045
lightning
154
00:14:20.910 --> 00:14:28.050
privately, and that's a there's a lot of knowledge there. And so, if you sit down at your terminal or however you currently operate Lightning,
155
00:14:28.635 --> 00:14:30.975
and you try to have all the knowledge in your head
156
00:14:31.435 --> 00:14:44.790
of how to use lightning privately, you you for for someone like me that struggles to hold all the all those facts, I'm gonna be stressed out. And so I want a piece of software that guides me along the happy path
157
00:14:45.125 --> 00:14:49.145
of privately. That something that will, you know, be, like, you know, bumper bowling
158
00:14:49.605 --> 00:14:51.945
where you can't really do it wrong.
159
00:14:52.660 --> 00:14:58.360
Like, privacy is is potentially the only By the way, bumper bowling is a share coin. Continue.
160
00:15:00.215 --> 00:15:02.475
161
00:15:02.855 --> 00:15:05.275
162
00:15:06.135 --> 00:15:10.155
Children need privacy too. I don't have what you care about giving back to the children.
163
00:15:10.680 --> 00:15:13.900
164
00:15:14.840 --> 00:15:20.404
if if you're an adult and you're going to a bowling alley and you have the bumpers down and you're bowling with bumpers,
165
00:15:21.345 --> 00:15:29.040
166
00:15:29.660 --> 00:15:34.480
throw? Because they they don't need the bumpers to keep it on the lane. Right? Obviously.
167
00:15:35.495 --> 00:15:39.595
But it it it in the little it's a little it's it's the people who aren't the professional.
168
00:15:39.975 --> 00:15:44.875
Right? So, like, the solution to lightning privacy can't be let's all become professional bowlers. Right?
169
00:15:45.540 --> 00:16:16.875
170
00:16:17.820 --> 00:16:32.315
171
00:16:32.615 --> 00:16:40.440
in the ways that are private because there are there are different ways that you can do things on lightning. Some of them are more private than us. Okay. So how does it do that?
172
00:16:40.900 --> 00:16:41.880
You can't receive.
173
00:16:42.875 --> 00:16:49.295
174
00:16:50.200 --> 00:16:53.980
all things equal, it's way harder to use lightning privately
175
00:16:54.360 --> 00:16:58.620
on the receive side than on the sent side. So you guys have just solved that by
176
00:16:59.654 --> 00:17:10.370
177
00:17:11.309 --> 00:17:14.450
So so if you wanna add funds to this
178
00:17:14.835 --> 00:17:16.294
specific lightning wallet,
179
00:17:16.835 --> 00:17:17.335
you,
180
00:17:17.875 --> 00:17:18.375
you
181
00:17:18.755 --> 00:17:22.115
click deposit or I don't know what we'll call the button. Eventually, right now, it's,
182
00:17:22.755 --> 00:17:24.250
183
00:17:25.130 --> 00:17:29.390
184
00:17:29.770 --> 00:17:50.010
185
00:17:50.550 --> 00:17:55.395
Wait. Oh, it's it's Flutter, so it runs on, like, desktop or mobile.
186
00:17:56.095 --> 00:17:58.355
187
00:17:58.750 --> 00:18:03.490
Got it. So you load you load up you get an address. You load it up. Creates a new channel.
188
00:18:04.430 --> 00:18:13.054
Fresh. Mhmm. And then if I if I press open another channel at that point and send more funds, and it's a new node, new channel Yep. Yep. All running
189
00:18:13.515 --> 00:18:18.750
190
00:18:19.289 --> 00:18:32.305
It's John Cottrell's product. Got it. So Which is based on LDK. Right. Which is based on LDK. And since it has this concept of a root node that does all, like, the hard like, the it's not the hardest work. It's just the work that require that the CPU
191
00:18:33.110 --> 00:18:35.130
wise is the hard work of gossip.
192
00:18:36.710 --> 00:18:39.030
What else? Got gossip and
193
00:18:39.590 --> 00:18:56.950
is it mostly just gossip? I think it's gossip. Oh, creating, like, the network graph. Right? So talking to to peers and creating a network graph and and computing routes and stuff like that. That's the job of the root node. But then there's all these additional nodes, and all they are is just channel state. So they're really tiny and they're really lightweight to spin up
194
00:18:57.250 --> 00:18:59.270
additional nodes in the sensei model.
195
00:18:59.794 --> 00:19:06.135
196
00:19:07.059 --> 00:19:13.399
197
00:19:13.700 --> 00:19:20.105
198
00:19:20.645 --> 00:19:22.345
Bitcoin d and SIMs. Yeah.
199
00:19:23.365 --> 00:19:25.385
200
00:19:26.300 --> 00:19:29.679
Blockstream's Electrum if you wanted to give up on all the privacy. I
201
00:19:30.220 --> 00:19:36.375
there there's an aspect of this where it's like when we're telling you no, there's there's there's times
202
00:19:36.915 --> 00:19:43.495
when you want to allow the user to override that because they, they know better or they just have to get something done.
203
00:19:44.240 --> 00:19:54.015
So I think we're that's kinda where we're at right now is thinking through the absolute best UX for that. And, like, what should we make an option? And what should we just completely disallow?
204
00:19:54.715 --> 00:19:56.735
So for instance, with, you know, receives,
205
00:19:57.835 --> 00:19:58.815
you know, potentially,
206
00:19:59.230 --> 00:20:02.290
like or or what was it? Which for channel opens. Right?
207
00:20:03.630 --> 00:20:06.929
I think you guys talked on the last podcast about short channel IDs.
208
00:20:07.630 --> 00:20:08.130
209
00:20:08.805 --> 00:20:11.305
210
00:20:12.405 --> 00:20:15.385
the your channel ID is leaking information
211
00:20:16.180 --> 00:20:19.480
for for a private channel. Your private channel is findable
212
00:20:20.020 --> 00:20:23.400
because of this channel ID is is derived deterministically.
213
00:20:24.284 --> 00:20:31.184
So if now you have these short channel IDs that have no relation to on to chain state, that's more private. Right?
214
00:20:31.485 --> 00:20:31.985
So,
215
00:20:32.480 --> 00:20:35.700
potentially, we don't allow you to open a channel,
216
00:20:36.880 --> 00:20:37.929
without this new,
217
00:20:39.904 --> 00:20:46.815
218
00:20:48.140 --> 00:20:49.200
219
00:20:50.860 --> 00:20:55.520
hey, it looks like the node you're trying to open to doesn't support this short channel IDs yet.
220
00:20:56.195 --> 00:20:57.495
Here's a fall back.
221
00:20:59.475 --> 00:21:01.414
You know, do do you do you wanna
222
00:21:01.715 --> 00:21:04.940
do you wanna do the dangerous thing right now? And and
223
00:21:05.559 --> 00:21:06.940
and maybe we allow that.
224
00:21:07.480 --> 00:21:13.820
225
00:21:14.235 --> 00:21:23.135
At the same time, they know better about their own situation too. So it's like, there's an instance where if, you know, I trust Paul to a certain degree,
226
00:21:23.830 --> 00:21:31.850
and I may not care if I open a channel with Paul and it, like, leaks some UTXO information or or he knows some information about my note,
227
00:21:32.175 --> 00:21:37.635
or the UTXO I used. So, you know, there's still an idea of, like, let me decide
228
00:21:38.015 --> 00:21:40.595
to override the privacy options versus
229
00:21:41.010 --> 00:21:45.030
this wallet trying to protect the user or not let them shoot themselves in the foot.
230
00:21:45.570 --> 00:21:48.390
231
00:21:49.315 --> 00:21:52.215
Tony and I have a channel, and I wanna pay Tony.
232
00:21:54.595 --> 00:22:02.260
PLN should should notify me, like, hey. You're about to pay a direct channel partner. That means they're gonna associate your identity
233
00:22:02.720 --> 00:22:09.295
with your node. Right? Because the payment is probably initiated out of band. Right? So, like, I'm buying a t shirt. So he knows I'm buying something,
234
00:22:09.595 --> 00:22:13.615
and now he sees this incoming payment. So he's gonna associate these 2 facts.
235
00:22:15.020 --> 00:22:16.800
So if it's if if
236
00:22:17.260 --> 00:22:27.665
if if Tony is someone I I I view as a threat, I don't wanna associate those. So I'm like, oh, thanks for warning me. I'll find another route or maybe the wall will help somehow. I mean, that's
237
00:22:28.045 --> 00:22:44.585
obviously, we haven't built that. But that's those are the sorts of things that we wanna think about. But maybe I could say, you know what? Tony's a bro. He knows I'm I'm, paying him in lightning right now. He already knows my note ID. He set it up for, I don't know, whatever it is. If I choose to trust him, then that, you know,
238
00:22:45.125 --> 00:22:49.145
the fact that I'm leaking privacy in that moment is appropriate and fine.
239
00:22:49.850 --> 00:22:51.550
240
00:22:52.490 --> 00:22:53.310
best practices?
241
00:22:54.650 --> 00:23:16.220
242
00:23:18.205 --> 00:23:56.925
One of the options could be, like, you can't pay Paul because your direct channels with him. Do you want the advanced scenarios? Like, do you want to open a channel with another node that's not Paul, and then you can pay him that way. So that could be one option. The other option is, like, well, do you trust Paul? If you trust Paul, then you can go ahead and make this payment. Otherwise, you're gonna leak the fact that you're gonna leak your note ID, and then you're gonna leak, like, some other information. But my point is, so that makes sense to me, but my point is why would you not use a short channel ID? Did I miss that? Not all nodes support it yet. Oh, okay. Right. So there's some compatibility. You try and open a channel with a certain node, you might not be able to use your channel ID. And is that that's based on implementation.
243
00:23:57.305 --> 00:23:59.850
Yep. So I don't think l and d or c lightning
244
00:24:00.230 --> 00:24:05.535
245
00:24:06.015 --> 00:24:08.515
246
00:24:08.815 --> 00:24:19.060
Yeah. If in the payment case though, if we have a private channel between each other, we know that's short channel ID. Right? So in the payment case, they're still gonna be able to correlate it with me.
247
00:24:19.760 --> 00:24:20.260
Right.
248
00:24:20.880 --> 00:24:30.215
249
00:24:30.915 --> 00:24:50.075
So that's why it's not ideal to, for 1, pay your channel partner, but for 2, you may want some channels to be public, so there's some plausible deniability, and you could say, oh, that payment didn't come from me. It got sourced behind me. Just just as like a meta comment on that, there's a way of thinking of lightning privacy as basically
250
00:24:50.570 --> 00:24:57.470
251
00:24:58.325 --> 00:25:00.825
nodes could have originated this payment?
252
00:25:01.685 --> 00:25:14.895
Right. So, if if if that gets narrowed down to 2 or one, that's, you know Pretty bad. That's when you have trouble. So so whatever actions you're doing for lightning privacy, whatever that means in this that scenario is usually trying to expand
253
00:25:15.355 --> 00:25:16.495
the number of plausible
254
00:25:16.795 --> 00:25:24.669
255
00:25:24.970 --> 00:25:27.149
and you're paying another Breeze Wallet user
256
00:25:27.450 --> 00:25:28.750
and Breeze is your LSP,
257
00:25:29.235 --> 00:25:31.335
Breeze pretty much knows that,
258
00:25:32.595 --> 00:25:37.095
where the source of the payment came from and where the destination is because both of those parties
259
00:25:37.635 --> 00:25:40.570
do not typically have public channels with anyone else.
260
00:25:40.950 --> 00:25:45.850
So the only possible people that could have paid this person or routed through to this person
261
00:25:46.315 --> 00:25:55.055
is this specific sender and then that we know that's that specific receiver. So but especially if you're a mobile user and you're paying another mobile user of the same app,
262
00:25:55.650 --> 00:25:58.789
they pretty much know. Like, the person sitting in the middle pretty much knows
263
00:25:59.169 --> 00:26:03.750
who's paying who, and that's a pretty big privacy concern I think people aren't aware of either.
264
00:26:06.005 --> 00:26:08.425
265
00:26:09.045 --> 00:26:10.425
266
00:26:10.885 --> 00:26:12.425
You know, we we have our own law.
267
00:26:12.860 --> 00:26:16.380
Well, for 1, we're not sitting in the middle. So we're not an LSP. Right.
268
00:26:16.780 --> 00:26:22.785
And we won't be a node that, like, people connect to at all. Like, it it'll But if people, like, open private
269
00:26:23.885 --> 00:26:24.385
270
00:26:26.685 --> 00:26:27.185
wallet,
271
00:26:27.485 --> 00:26:33.720
I was just the n stands for wallet. People open private lightning wallet, and then they they create a
272
00:26:34.260 --> 00:26:34.760
channel
273
00:26:36.020 --> 00:26:37.000
to Breeze
274
00:26:37.465 --> 00:26:40.765
or one of the large routing nodes, like, async or something,
275
00:26:41.545 --> 00:26:45.940
there's a good chance that that they'll be the only hop. Right. So one possibility
276
00:26:46.399 --> 00:26:49.279
277
00:26:49.840 --> 00:26:54.005
we give a warning if the user wants to open a channel with kind of a hub,
278
00:26:54.725 --> 00:27:13.365
279
00:27:13.985 --> 00:27:27.640
280
00:27:29.375 --> 00:27:39.470
and you can add as many as you want, really. You're just there's a little bit of a cost to how private you wanna be, so a little bit of a trade off. You're gonna be paying a higher fee, but you're gonna have increased privacy.
281
00:27:40.090 --> 00:27:41.790
And I think that's a great trade off.
282
00:27:42.170 --> 00:27:46.750
Because the fee shouldn't be that much higher. It shouldn't be in most cases. I mean, if you're doing a large payment,
283
00:27:47.554 --> 00:27:48.215
the percentages
284
00:27:48.595 --> 00:27:53.735
285
00:27:54.660 --> 00:28:02.820
are the fee is based on the amount you send. It's, basically, a percentage fee on the amount you send. So the more you send, the higher the fee. On chain
286
00:28:03.765 --> 00:28:10.665
without with on chain, though, the difference is you pay on the the size of the transaction. So it doesn't matter how much money you're sending.
287
00:28:11.160 --> 00:28:12.220
It matters essentially
288
00:28:12.520 --> 00:28:19.125
all all sequel matters how many inputs you have on the input side of the transaction. Yeah. The actual amount of data rather than the amount of money.
289
00:28:20.165 --> 00:28:20.665
290
00:28:21.045 --> 00:28:24.505
And the other I mean, the other problem with adding hops is obviously the reliability.
291
00:28:25.845 --> 00:28:32.150
Like, the odds of a payment going through diminish rapidly every hop you add. Yeah. I was on the,
292
00:28:32.630 --> 00:28:34.570
293
00:28:34.870 --> 00:28:35.370
and,
294
00:28:35.830 --> 00:28:37.995
I believe it was Rockstar who was talking about
295
00:28:38.375 --> 00:28:43.115
how after one hop, your payment reliability goes down to, like, 70 to 80%.
296
00:28:44.160 --> 00:28:52.420
And then after that, it just gets worse and worse and worse. So there's also a little bit trade off. If you're wanting instant payments to always succeed,
297
00:28:53.264 --> 00:29:02.325
you're gonna want the shortest route, which is there's privacy concerns with that. But if you're adding hops or privacy concerns, you may be sitting there at the cash register for a little while,
298
00:29:03.320 --> 00:29:13.005
you know, trying multiple paths and trying to do longer paths to make sure it works. So there's even an option for, like, us to have an option where it's, like, oh, it's taking a while to make this payment.
299
00:29:13.465 --> 00:29:15.965
Do you want to, like, bump down on the privacy
300
00:29:16.825 --> 00:29:21.565
to have this payment go through? Like, if you're purchasing just like a sandwich at a shop,
301
00:29:21.890 --> 00:29:24.630
you know, you may not care about the most perfect privacy.
302
00:29:25.970 --> 00:29:31.350
So there's use cases allowing the user to override and say, I'm not trying to be the most private in this scenario
303
00:29:31.945 --> 00:29:38.445
could add to the reliability, but then, you know, where do you draw that line? We don't want everyone just to use the least private option all the time.
304
00:29:39.290 --> 00:29:41.150
So there's a battle between UX
305
00:29:41.530 --> 00:29:42.750
and not letting users
306
00:29:43.290 --> 00:29:44.669
shoot themselves in the foot.
307
00:29:46.784 --> 00:29:52.404
308
00:29:52.865 --> 00:29:57.230
309
00:29:57.630 --> 00:30:04.455
a proof of concept. We started it a few weeks ago at a hackathon. We spent good 48 hours on it, and then a few weekends after
310
00:30:05.894 --> 00:30:09.434
so we're we're still in the development phase of it. We're gonna come out with an MVP
311
00:30:09.975 --> 00:30:11.434
soon. We've narrowed down,
312
00:30:11.815 --> 00:30:13.995
the list. It'll just be something simple,
313
00:30:14.300 --> 00:30:16.080
open channel, and send.
314
00:30:16.460 --> 00:30:23.765
And so for sending wallet, it'll be great. You'll have a lot of privacy features built into it. And we're gonna start out with that little MVP.
315
00:30:24.225 --> 00:30:24.965
So hopefully,
316
00:30:25.345 --> 00:30:26.085
I don't know,
317
00:30:26.465 --> 00:30:30.965
a month or 2. I it's 2 weeks. 2 weeks. 2 weeks? Okay. 2 weeks, we'll have this ready. But,
318
00:30:31.450 --> 00:30:46.365
319
00:30:46.745 --> 00:30:51.580
or on a cloud host or something, or on your desktop or whatever. And your your
320
00:30:51.960 --> 00:30:58.380
mobile device will communicate back to that. Obviously, that's simple. If you're just running it on your desktop or something like that,
321
00:30:58.760 --> 00:31:00.299
that's pretty easy to launch.
322
00:31:01.705 --> 00:31:03.565
It since it's lightweight enough,
323
00:31:04.345 --> 00:31:07.005
that, basically, we could run all this on a phone.
324
00:31:08.080 --> 00:31:20.435
Like, all the nodes are all running on your phone. So, obviously, they're just offline whenever you the apps I mean, if you're just using for sending, that's fine. You're just sending. You're not routing anything. So perhaps that's just that's totally fine. So I'd be curious
325
00:31:21.455 --> 00:31:23.395
of if people who are interested
326
00:31:23.935 --> 00:31:27.650
in using this wallet, how many of them would be willing to run something
327
00:31:28.190 --> 00:31:28.929
on Umbrel,
328
00:31:29.309 --> 00:31:33.245
329
00:31:33.965 --> 00:31:35.184
330
00:31:35.725 --> 00:31:45.060
331
00:31:45.700 --> 00:31:54.465
332
00:31:54.765 --> 00:31:56.385
from one spot to another.
333
00:31:57.005 --> 00:32:02.600
334
00:32:02.980 --> 00:32:11.065
boxes or voltage or something, you need LDK support first? Well, no. It is l d LDK. Yeah. So They just they they run arbitrary binaries
335
00:32:11.445 --> 00:32:17.385
and LDK. So you just package LDK with the app or whatever. Mhmm. It's packaged inside of Sensei, which we package
336
00:32:17.820 --> 00:32:26.159
337
00:32:26.555 --> 00:32:41.625
node software. You don't need some external nodes. Got it. So, presumably, you can just get that added to RaspiBlitz or something. Right. RaspiBlitz doesn't have to support LDK separately. Correct. Just just like any app you add to one of those node node run. What's cool is that,
338
00:32:42.505 --> 00:32:43.965
339
00:32:44.985 --> 00:32:52.200
in and of itself. So you can take Sensei and throw it on a rasp Raspberry Pi or or a server somewhere, your own computer, your laptop.
340
00:32:52.660 --> 00:33:07.875
But then you can also take Sensei and use it as a library, which I think it's it's huge to be able to do that. The way John Cantrell is building it is it's fantastic to be able to support. Like, the only reason we were able to do this so quickly is because John Cantrell had been working on Sensei for a while,
341
00:33:08.190 --> 00:33:17.090
and he built it in a way that supports being a library and as a node itself. So we're we're we're kind of on the backs of giants here taking some of John Cantrell's MIT
342
00:33:17.935 --> 00:33:28.740
343
00:33:29.040 --> 00:33:36.660
And he really he he or sorry. Not l he also explained a lot about LDK, but he how sense is built. And he kinda had a call to action
344
00:33:37.085 --> 00:33:41.985
of, like, hey, build some stuff for the hackathon. I talked to him, like, hey, I think I'm gonna build this for the hackathon.
345
00:33:42.765 --> 00:33:45.025
Get a, like, a, like, maybe a better onboarding
346
00:33:45.405 --> 00:33:46.705
flow for Sensei.
347
00:33:47.150 --> 00:33:50.210
And then I just like, no. Actually, I'll just use your library
348
00:33:50.510 --> 00:33:51.809
and make my own wallet.
349
00:33:52.110 --> 00:33:53.170
Fuck you, John.
350
00:33:53.870 --> 00:34:07.020
351
00:34:07.720 --> 00:34:26.470
that you would probably want to throw as an always online node. But, it'd be cool to be able support the move mobile use case. Just get rid of certain features if you're using it like a a moon or a breeze. Yeah. Like, if you think what is that root, Also, what is that root node doing with, like, building that, you know, having that, up to date channel
352
00:34:27.089 --> 00:34:27.589
353
00:34:27.970 --> 00:34:32.454
is is pretty pretty valuable. If you have to every time you open up the phone, it has to, like,
354
00:34:32.755 --> 00:34:36.694
talk to a bunch of peers and do a ton of gossip to get anything like a realistic
355
00:34:37.150 --> 00:34:45.410
perspective on what's happening in lightning, like, that's just bad bad UX. So, ideally, you do have the root node running all And I guess, like, if you don't have a watchtower,
356
00:34:46.135 --> 00:34:49.675
357
00:34:50.375 --> 00:34:54.870
358
00:34:55.430 --> 00:35:08.185
359
00:35:08.825 --> 00:35:12.605
360
00:35:13.400 --> 00:35:20.619
361
00:35:21.744 --> 00:35:23.685
and not locked in the channel already.
362
00:35:25.505 --> 00:35:27.845
And there's some possibilities there where you could,
363
00:35:28.990 --> 00:35:33.090
be doing coin joins while you're still locked in a channel, which I think is,
364
00:35:34.030 --> 00:35:38.855
a brilliant use case. You could be always splicing in or splicing out into coin joints.
365
00:35:40.035 --> 00:35:50.440
366
00:35:50.980 --> 00:35:54.565
367
00:35:55.045 --> 00:35:56.744
be able to use something like this.
368
00:35:57.285 --> 00:36:01.065
Vortex will kinda do your channel opens are collaborative
369
00:36:01.365 --> 00:36:05.319
and your, your channel closes. You can't do those collaboratively yet, but,
370
00:36:05.859 --> 00:36:09.720
you know, you could be even coin joining after you your channel is closed,
371
00:36:10.575 --> 00:36:19.474
and then your channel opens your coin join. But there's even an aspect we've been talking to Ben about too where, you know, maybe in theory, once we get splicing in and splicing out,
372
00:36:20.700 --> 00:36:25.839
those have no downtime at all, when you're splicing in and out. So you could have a channel,
373
00:36:26.460 --> 00:36:32.035
the UTXO that's locked in the channel with your channel partner. You're using it to send payments, receive payments.
374
00:36:32.335 --> 00:36:33.555
And then in the background,
375
00:36:34.230 --> 00:36:35.530
it is actively
376
00:36:35.830 --> 00:36:39.610
participating in coin joint transactions with 0 downtime to you.
377
00:36:40.070 --> 00:36:42.150
You would want those to be unannounced channels,
378
00:36:42.470 --> 00:36:45.974
so you're not just broadcasting each channel open and channel close,
379
00:36:46.435 --> 00:36:48.055
because you want those kind of unlinked.
380
00:36:48.994 --> 00:36:52.950
But it'd be cool. You could have unannounced channels behind your public
381
00:36:53.250 --> 00:36:55.670
channels. So I have a channel with Paul
382
00:36:55.970 --> 00:37:01.684
that's public. You can route you can gain rounded fees from that. And then behind it, I have multiple
383
00:37:02.144 --> 00:37:05.444
unannounced channels with Paul, and those are also participating
384
00:37:06.144 --> 00:37:06.964
in the routing.
385
00:37:07.300 --> 00:37:10.760
They're adding to the liquidity without anyone else in the world knowing
386
00:37:11.140 --> 00:37:12.920
because those are unannounced channels.
387
00:37:13.380 --> 00:37:18.444
And in fact, we talked last week about, the hidden lightning network and probing for unannounced channels.
388
00:37:18.984 --> 00:37:25.849
Those are the kind of channels that I can't probe. So I don't think we talked about that, but I can't actually find the UTXO behind
389
00:37:26.150 --> 00:37:30.170
for a channel that's unannounced that's behind a public channel with the same peer.
390
00:37:30.790 --> 00:37:42.235
391
00:37:42.820 --> 00:37:44.440
Because So could you fill up that
392
00:37:44.900 --> 00:37:56.664
393
00:37:57.464 --> 00:38:00.620
but I would not be able to tell what UTXO makes it up. But that's that,
394
00:38:01.420 --> 00:38:04.720
but in either case, you could be you it'd be cool to have
395
00:38:05.100 --> 00:38:06.400
some unannounced channels
396
00:38:07.325 --> 00:38:10.785
that are adding to your liquidity without anyone else in the world knowing,
397
00:38:11.165 --> 00:38:14.625
and you're constantly coin joining those unannounced channels.
398
00:38:16.080 --> 00:38:28.375
399
00:38:29.475 --> 00:38:34.600
400
00:38:36.260 --> 00:38:37.380
401
00:38:37.860 --> 00:38:42.120
another idea. You know, how we have all these the PLN has all these channels,
402
00:38:43.035 --> 00:38:44.175
or all these nodes
403
00:38:44.635 --> 00:38:45.535
that are separate,
404
00:38:45.915 --> 00:38:46.974
you know, per channel.
405
00:38:47.755 --> 00:38:49.694
What if you have a larger payment?
406
00:38:50.980 --> 00:38:51.960
Can you combine
407
00:38:52.260 --> 00:38:53.080
those nodes
408
00:38:53.460 --> 00:38:53.960
together?
409
00:38:54.580 --> 00:38:57.640
Like, in a sense, you could think of, like, 3 nodes
410
00:38:58.135 --> 00:39:00.474
combining to make a payment as, like,
411
00:39:01.255 --> 00:39:10.410
you can make it look like you're halfway through, like, an amp payment, basically. Right? Like you're, you you know, an amp payment, like, splits goes through multiple routes simultaneously.
412
00:39:11.029 --> 00:39:24.110
Now you you present yourself as you are those 3 multiple routes all of a sudden, but you're actually those are the 3 originating nodes. So you could you you could have a combined balance even though you have individual
413
00:39:31.755 --> 00:39:35.295
414
00:39:35.595 --> 00:39:41.535
Yep. And it helps on You really need to fix it shouldn't be PLN unless you wanna call it, like, private lightning network wallet.
415
00:39:42.540 --> 00:39:46.720
416
00:39:48.140 --> 00:39:59.960
With an n at the end. It's private lightning. Oh, private l n. L n. Yeah. Okay. That makes sense. Private lightning. Yeah. We'll figure it out. We'll figure it out. Sorry. Engineers are bad at naming things. But I will say before we move off
417
00:40:00.340 --> 00:40:03.720
the topic vortex, which is really cool, hop on to,
418
00:40:04.260 --> 00:40:10.954
Stefan Lovera and listen to the recent I don't know what number it is. Sorry, Stefan. But, Ben Carman probably knows. He's in the comments.
419
00:40:11.815 --> 00:40:19.170
Ben was just on to talk about privacy stuff, Fortex stuff. So if you wanna learn more about Fortex and You just search Ben Carmen. Ben Carmen.
420
00:40:19.950 --> 00:40:21.090
Yeah. I mean, PLNW
421
00:40:21.555 --> 00:40:22.802
could work too.
422
00:40:23.217 --> 00:40:30.284
423
00:40:30.780 --> 00:40:40.415
in the SIL dispatch feed, they are time stamped. There's both Tony Tony talked twice. I had him on stage twice for that. Back to back? One for lightning payments and one for lightning privacy.
424
00:40:41.295 --> 00:40:48.995
Also, still dispatch 21. We go for, like, 2 and a half hours on all the nuances of lightning privacy. That's aged pretty well. Not a lot of them have been.
425
00:40:49.660 --> 00:40:52.320
They're pretty much still all outstanding for the most part.
426
00:40:53.100 --> 00:40:57.775
Yep. So so we're talking about 2 things here that I think make it a little bit more confusing. We're talking about
427
00:40:58.575 --> 00:40:59.795
this vortex wallet,
428
00:41:00.575 --> 00:41:04.275
which I are you you're contributing to that as well. Right? Not yet. No.
429
00:41:04.815 --> 00:41:06.560
430
00:41:07.280 --> 00:41:09.280
431
00:41:09.600 --> 00:41:19.155
I've I've helped a little bit with the design for a front end. But And then we're talking about PLN with 2 so 2 different wallets we're talking about. That's why I'm I'm sorry. I like a little
432
00:41:19.455 --> 00:41:21.635
put in a little p n PLN fact,
433
00:41:22.400 --> 00:41:24.980
But that that's a distraction from from Vortex.
434
00:41:25.440 --> 00:41:25.840
But,
435
00:41:26.240 --> 00:41:27.440
I did wanna shout out,
436
00:41:29.365 --> 00:41:31.865
we're starting Austin Bitcoin Design Club.
437
00:41:32.484 --> 00:41:37.704
And a part of it was a little inspired by Vortex of, like, Vortex is an open source project
438
00:41:38.060 --> 00:41:40.000
It didn't have a front end. Somebody,
439
00:41:42.220 --> 00:41:42.720
oh,
440
00:41:43.420 --> 00:41:46.720
somebody's working on the front end for it, needed some design,
441
00:41:47.425 --> 00:41:49.205
Like, got a few people together,
442
00:41:50.305 --> 00:41:56.640
like, created a Figma and, like, came up with an aesthetic and did some design for it. So I I really wanted to,
443
00:41:58.300 --> 00:42:02.560
connect with the design community to better and or or basically find open source projects
444
00:42:03.180 --> 00:42:03.680
that
445
00:42:05.005 --> 00:42:05.825
want design.
446
00:42:06.125 --> 00:42:19.230
And I think the biggest, the bigger problem, like developers know that they can go around on GitHub and if they see something interesting, they can create an issue or create a poll request or, you know, hit up you know, like, developers know how to contribute to code projects,
447
00:42:19.930 --> 00:42:21.869
help designers know how to
448
00:42:23.865 --> 00:42:30.605
449
00:42:30.984 --> 00:42:39.240
Yep. Awesome. Good shout out. So Trinity is asking, Tony, would the node software for PLN have a feature to block you jamming channels?
450
00:42:41.244 --> 00:42:44.385
451
00:42:45.085 --> 00:42:47.265
so I would easy answer is
452
00:42:47.964 --> 00:42:48.464
no.
453
00:42:50.730 --> 00:42:51.230
But,
454
00:42:51.609 --> 00:42:54.670
you know, if we were to able able to get unannounced channels
455
00:42:54.970 --> 00:42:55.470
and,
456
00:42:56.755 --> 00:42:58.215
short channel ID aliases,
457
00:42:58.915 --> 00:43:00.935
that would help the channel jamming,
458
00:43:01.875 --> 00:43:03.175
problem a lot. So,
459
00:43:03.875 --> 00:43:07.070
it's not it's not a perfect fix, but,
460
00:43:07.930 --> 00:43:10.910
461
00:43:11.610 --> 00:43:17.155
is a different node. Right. Then all of a sudden, like, an attacker needs to know all of your nodes and
462
00:43:17.615 --> 00:43:24.860
discover those channel all of those channels and then jam each one individually rather than, like, one public node, and they're, like, I'm just gonna channel it.
463
00:43:25.240 --> 00:43:28.540
I'm just gonna jam every channel. Right? So if I design it,
464
00:43:29.395 --> 00:43:34.055
it's resistant at least. Exactly. Because, it's resistant to probing, and it's resistant
465
00:43:34.355 --> 00:43:42.039
466
00:43:42.500 --> 00:43:54.520
you've never leaked your pub key to the gossip network, so you can't search it on 1 ml. You can't go through a list of net like, you could try to channel jam, people randomly, but they would never be able to find your public key,
467
00:43:55.320 --> 00:44:11.644
unless you leaked it out, like, on Twitter or something. But then Post an invoice publicly. Right. But then that's just one of your nodes. If you have multiple channels, you have multiple nodes, and they can't channel, jam them all if you didn't link them all. But you won't be posting an invoice anytime soon on PLN because No. You can't receive. So No. Received. Yeah. So we're waiting on,
468
00:44:12.920 --> 00:44:15.420
what's blinded routes, blinded paths,
469
00:44:16.120 --> 00:44:22.060
which is kind of been paper clip to bolt 12. So when we start getting that support and LDK,
470
00:44:22.585 --> 00:44:24.845
we can actually and the cool thing is, like, you know,
471
00:44:26.505 --> 00:44:29.645
LDK is working on so many different cool features,
472
00:44:30.539 --> 00:44:41.944
and one of them is 1212. And as far as I know, LND is not working on it. So we don't have to wait for LND to get this. Like, once LDK works on some of these features, we can have that in Sensei, and then we can have that
473
00:44:42.325 --> 00:44:46.484
in PLN without waiting on lnd or c lightning to do it. So,
474
00:44:47.230 --> 00:44:49.250
I think that's a pretty pretty cool,
475
00:44:49.710 --> 00:44:52.690
476
00:44:53.390 --> 00:44:53.890
LDK
477
00:44:54.914 --> 00:45:06.910
478
00:45:07.370 --> 00:45:08.990
No. Once we add blind pass.
479
00:45:09.535 --> 00:45:10.035
480
00:45:10.734 --> 00:45:12.674
481
00:45:13.615 --> 00:45:18.434
482
00:45:20.250 --> 00:45:20.750
Awesome.
483
00:45:21.369 --> 00:45:24.430
Before we go move on to another topic, first of all,
484
00:45:24.809 --> 00:45:31.505
Paul, welcome to Bitcoin Park. What do you what you think of Bitcoin Park so far? You've been working here all day. It's beautiful. I like this the soundproofness.
485
00:45:32.605 --> 00:45:33.585
486
00:45:33.940 --> 00:45:34.440
several,
487
00:45:35.140 --> 00:45:37.560
music albums since I've been here.
488
00:45:38.900 --> 00:45:43.595
489
00:45:44.155 --> 00:45:44.655
490
00:45:45.435 --> 00:45:47.775
some freaks might not know, but Paul is a prolific,
491
00:45:49.515 --> 00:45:53.570
prolific podcaster. He was one of the founders of of the Vergecast.
492
00:45:54.350 --> 00:45:56.130
Just one of, like, the first tech podcasts.
493
00:45:57.310 --> 00:46:05.234
Let's see. So you've been in a lot of studios. I've been. This is a pretty nice studio. Right? This is a very nice studio, actually. Yeah. Like, the last place I
494
00:46:05.535 --> 00:46:08.595
495
00:46:08.895 --> 00:46:10.675
like, a room that had been
496
00:46:11.390 --> 00:46:11.890
mostly
497
00:46:12.430 --> 00:46:22.105
converted into a professional podcast studio. So you think this is, like, a step above that? Step above because this is, like, a real this is designed, like, as, like, a music. It has a lot more sound treatment
498
00:46:22.724 --> 00:46:23.865
than the average
499
00:46:24.405 --> 00:46:27.625
500
00:46:28.460 --> 00:46:34.080
Like, you heard it here first, Freaks. It's endorsement by Paul Miller himself. All this stuff. All this stuff.
501
00:46:34.460 --> 00:46:36.160
So what do you guys wanna talk about?
502
00:46:38.805 --> 00:46:40.505
503
00:46:40.965 --> 00:46:41.465
Paul,
504
00:46:42.325 --> 00:46:44.085
you're you you've been,
505
00:46:45.490 --> 00:46:49.830
you haven't been on here in a while. I think the last time you were on Citadel Dispatch, we were in Miami.
506
00:46:50.450 --> 00:46:51.910
You were talking about abolishing
507
00:46:52.325 --> 00:46:56.905
508
00:46:57.205 --> 00:47:00.185
509
00:47:00.750 --> 00:47:01.970
510
00:47:02.670 --> 00:47:06.610
Tony's belief that people under 10 should not be allowed to drive?
511
00:47:08.590 --> 00:47:09.090
512
00:47:09.725 --> 00:47:10.545
hard disagree.
513
00:47:13.005 --> 00:47:21.440
And, I think, I think Tony should be not allowed to say something like that. I think if if you say something like that, you should be deplatformed.
514
00:47:22.060 --> 00:47:24.960
515
00:47:26.385 --> 00:47:32.965
516
00:47:35.140 --> 00:47:35.880
All about,
517
00:47:36.580 --> 00:47:37.080
deregulation.
518
00:47:39.860 --> 00:47:47.025
519
00:47:47.405 --> 00:47:48.225
would I support,
520
00:47:48.685 --> 00:47:51.609
I think the word I was looking for were,
521
00:47:52.150 --> 00:47:52.650
certifications,
522
00:47:53.829 --> 00:47:54.650
not regulation.
523
00:47:55.349 --> 00:48:00.954
Like, the enforcement of it, I would not stand by that. But that's So what do you see as the difference between certification
524
00:48:01.414 --> 00:48:01.895
525
00:48:02.775 --> 00:48:09.600
regulation? By the way, Weird Robot's calling someone a bigot in the comments. I don't know if he's calling Paul or Tony a biggie. Yeah. That's probably Paul.
526
00:48:10.300 --> 00:48:13.200
527
00:48:13.875 --> 00:48:16.535
Like food is highly regulated. Right?
528
00:48:17.635 --> 00:48:26.140
But what I would, what I care more about is, is things that aren't like expressed in the regulation. Like, I care, like, where it came from,
529
00:48:26.520 --> 00:48:29.980
which isn't printed on a package. So you can get a stamp.
530
00:48:30.435 --> 00:48:32.055
So it's abiding by a regulation.
531
00:48:33.795 --> 00:48:38.295
But I know there are other things that I would rather be captured. But anyways, so the USDA
532
00:48:39.075 --> 00:48:39.815
533
00:48:42.970 --> 00:48:43.470
difference.
534
00:48:43.850 --> 00:48:49.390
Opt in. You're you're you're letting USDA say, I certify that these are following my rule set,
535
00:48:49.875 --> 00:48:51.575
but people could sell non USDA
536
00:48:52.275 --> 00:48:55.015
meat if they wanted to. That's their prerogative. Yep. Exactly.
537
00:48:55.635 --> 00:49:05.650
538
00:49:06.605 --> 00:49:07.505
539
00:49:08.445 --> 00:49:09.905
certification too. So,
540
00:49:10.685 --> 00:49:14.785
whatever they're I forget what that regulation is. But But I guess to keep it
541
00:49:16.300 --> 00:49:17.599
542
00:49:17.980 --> 00:49:18.880
it would be
543
00:49:19.339 --> 00:49:27.345
it would be like if if you could opt in to the beef initiative saying, this is where the beef came from. And the beef initiative is not a government entity.
544
00:49:27.885 --> 00:49:30.785
They're just putting their reputation on the line and saying,
545
00:49:31.165 --> 00:49:37.079
we know you trust us, so we're gonna let you know that it came from this ranch and it went through this process or something. Right?
546
00:49:37.780 --> 00:49:42.195
547
00:49:42.734 --> 00:49:45.375
a a a lot about this. And, like, basically, it it will
548
00:49:46.494 --> 00:49:51.570
you're always gonna end up having trust in a system. So it's like you just wanna be, like, good at it. So, like,
549
00:49:51.870 --> 00:49:54.850
it turns out that, like, blindly trusting,
550
00:49:55.710 --> 00:49:56.910
that that, like, we
551
00:49:57.925 --> 00:50:06.665
if you walk into a grocery store, you have this example, like, if you're gonna buy a tent. Right? You're gonna go online and, like, do all this, like, investigation
552
00:50:07.285 --> 00:50:19.805
and comparison shopping and, like, read a bunch of reviews and, like or, you know, maybe you have a trusted source. Like, I really like Wirecutter. Right? Wirecutter, if I'm gonna buy a certain Is Wirecutter affiliated with The Verge?
553
00:50:20.665 --> 00:50:23.085
No. They I think the New York Times owns them. Okay.
554
00:50:24.105 --> 00:50:26.125
My favorite publication, The New York Times.
555
00:50:27.310 --> 00:50:33.970
556
00:50:35.195 --> 00:50:36.415
557
00:50:36.715 --> 00:50:39.295
do these, like, comparisons of, like, mattresses
558
00:50:39.595 --> 00:50:48.060
or something like that. Right? They'll, like, get a bunch of mattresses in and then compare them and write these in-depth reviews about them. Right? So I'm gonna trust them and offload
559
00:50:48.440 --> 00:50:49.180
this decision
560
00:50:49.560 --> 00:50:56.545
of what the best one is there. But, like, how often do you do that for when you are in, like, a on a grocery store aisle?
561
00:50:57.565 --> 00:51:02.740
Like, you're comparing based on, like, the branding, and you're you're basically assuming everything is blessed
562
00:51:03.200 --> 00:51:09.645
by our regulators. So you are you're placing an implicit trust in the grocery store and all the and the FDA
563
00:51:09.945 --> 00:51:17.740
that everything in front of you is in some sense safe. But or in in like the the the food pyramid. You're, like, believing the food pyramid.
564
00:51:18.040 --> 00:51:23.475
But it so, in fact, you you you are using a lot of trust. It's just misplaced trust. And so
565
00:51:23.875 --> 00:51:25.175
we we need to to
566
00:51:25.555 --> 00:51:28.295
hopefully dial down the places where we just
567
00:51:28.675 --> 00:51:32.135
blindly trust, like fiat trust, and
568
00:51:32.515 --> 00:51:33.015
instead
569
00:51:33.410 --> 00:51:34.550
choose very carefully
570
00:51:35.090 --> 00:51:37.970
571
00:51:39.090 --> 00:51:41.590
by the way, shout out BTC pins. He's still selling,
572
00:51:42.130 --> 00:51:43.110
dispatch magnets.
573
00:51:43.715 --> 00:51:46.695
So if you want a dispatch magnet, you can go to sill dispatch.com/stack,
574
00:51:48.915 --> 00:51:52.775
and that supports him, that supports the show, and it supports open sets.
575
00:51:53.900 --> 00:51:56.560
He's saying voluntary is the key, and I think
576
00:51:56.860 --> 00:51:57.760
that's kind of
577
00:51:58.220 --> 00:52:02.160
a lot you know, you guys are kinda doing the long winded version of of that. Right? Absolutely.
578
00:52:03.244 --> 00:52:07.105
Like, that nails it that nails it down. Bunch of different certification
579
00:52:07.805 --> 00:52:12.200
580
00:52:12.680 --> 00:52:15.420
too pick and choose what they wanna sell. It may not be
581
00:52:15.800 --> 00:52:38.600
regulated by the FDA or not, but you can have trust in your own. Like, you're a grocery store owner, Paul. Right? You own a grocery store. You literally do. And I shop it all the time, and I trust that the food I'm not checking certification, but I trust that Paul's grocery store is not selling me something bad. Because he's in my local community, and I may I may hurt him if he tries to sell Paul has a grocery store? Yeah. He does in Austin.
582
00:52:38.984 --> 00:52:41.165
583
00:52:41.785 --> 00:52:44.525
584
00:52:44.905 --> 00:52:45.885
585
00:52:46.345 --> 00:52:59.775
But they ask you when I check out, are you an owner owner here? And I say, yes. Oh, and I say, yeah. My name is Paul Miller. And it turns out this whole time, he gets receipts sent to his email. So he goes through and he he gets a receipt
586
00:53:00.155 --> 00:53:06.335
randomly in the mail in the email. And he sees all the items that I typically buy, and he's like, oh, busted.
587
00:53:06.635 --> 00:53:11.010
That was you using using my, privacy expert. Yeah. Tony Georgiou.
588
00:53:12.030 --> 00:53:18.835
589
00:53:19.135 --> 00:53:30.860
590
00:53:32.464 --> 00:53:57.170
It's it's going back to the aspect of trust and even bringing back enlightening privacy too. There's also sometimes trusting people, not with your security or or your health, but trusting them with your privacy too, which I think is an interesting aspect. You don't wanna we you know, the first reaction you may have is I don't wanna trust someone else or rely on them for my own privacy. Right? Like, that seems like a given. Right?
591
00:53:57.809 --> 00:54:00.230
Except there when you are
592
00:54:00.530 --> 00:54:03.829
hiding amongst the an onset of other users,
593
00:54:04.525 --> 00:54:07.905
you are literally trusting them with your privacy.
594
00:54:08.445 --> 00:54:10.785
If every single one of their users,
595
00:54:11.565 --> 00:54:14.140
the users that you're hiding in the anon set with,
596
00:54:14.700 --> 00:54:19.359
let's say that's actually chain surveillance or that's the government. Like, every one of those users
597
00:54:19.740 --> 00:54:23.359
are not and and then they publicize that information or,
598
00:54:24.484 --> 00:54:32.105
or they see your transaction and they know it's not them, so they can kinda reduce your add on set that way. You are like, when you do a coin join,
599
00:54:32.570 --> 00:54:33.790
even lightning itself,
600
00:54:34.170 --> 00:54:36.030
you're trusting that it's not owned.
601
00:54:36.570 --> 00:54:38.910
Like, that process is not owned by
602
00:54:39.525 --> 00:54:43.545
a single actor. You trust that everyone you're collaborating with is not a single actor.
603
00:54:44.085 --> 00:54:46.505
Well, you don't have to trust that, but if if if,
604
00:54:47.365 --> 00:54:50.600
605
00:54:50.980 --> 00:54:54.120
Nick Szabo's trusted third parties are security holes.
606
00:54:54.740 --> 00:55:00.995
He he has kind of a a section in there where he says, you know, trust is actually kinda like a funny word.
607
00:55:01.455 --> 00:55:02.515
Some privacy,
608
00:55:03.135 --> 00:55:03.875
and security
609
00:55:04.400 --> 00:55:08.180
researchers think that maybe a better term is vulnerable to.
610
00:55:09.040 --> 00:55:14.105
So you what what you are vulnerable to is is the scenario that you're
611
00:55:14.505 --> 00:55:23.900
or or or if if all these people were bad, you you are vulnerable to. You're trusting that they're not bad is a sense of not that you trust that they're all good guys, but you you are vulnerable
612
00:55:24.200 --> 00:55:28.540
to the fact that if they were all against you, you're screwed.
613
00:55:28.920 --> 00:55:38.705
614
00:55:39.820 --> 00:55:46.240
either not being owned by the same actor or I I think there was someone in Twitter today that, responded to you.
615
00:55:46.540 --> 00:55:48.595
You're trusting that they're not selling
616
00:55:49.454 --> 00:55:50.914
their transaction history,
617
00:55:51.615 --> 00:55:56.194
on the free markets because you could if if there was a market for selling
618
00:55:56.530 --> 00:55:58.150
transaction history on lightning,
619
00:55:59.410 --> 00:56:02.710
and there's an aggregator of all this transaction history
620
00:56:03.385 --> 00:56:04.285
that is purchasing
621
00:56:05.065 --> 00:56:07.645
other people's transaction history because, like, some nodes
622
00:56:08.105 --> 00:56:10.285
literally don't make that much on lightning. Like,
623
00:56:10.720 --> 00:56:22.505
Alex Bosworth may make, you know, 1,000,000 of dollars a year routing lightning payments, but, like, the reality of the situation, like, we the rest of us aren't or most of us aren't. And he doesn't make 1,000,000, but it's like that. You know, I think 1,000
624
00:56:22.965 --> 00:56:23.625
a month.
625
00:56:25.369 --> 00:56:31.309
But there is this aspect if the entire Lightning Network is owned or they are incentivized to sell transaction history,
626
00:56:32.650 --> 00:56:36.315
and they do so, that hurts your privacy by a lot.
627
00:56:37.095 --> 00:56:38.395
Because if you could dynamize
628
00:56:38.775 --> 00:56:39.275
lightning,
629
00:56:39.575 --> 00:56:46.120
it's just like the Tor network being owned by the NSA. If every single node on Tor was the NSA, you're fucked.
630
00:56:46.420 --> 00:56:50.280
631
00:56:51.765 --> 00:56:54.825
Let's start with the question that you mentioned that was on
632
00:56:55.685 --> 00:56:57.545
that was on Twitter by atmetis
633
00:56:59.410 --> 00:56:59.910
galactic.
634
00:57:00.210 --> 00:57:05.190
He goes, can you please discuss the possibility of l n node operators selling transaction data
635
00:57:05.970 --> 00:57:08.790
and that being more profitable than transaction fees?
636
00:57:10.494 --> 00:57:11.555
637
00:57:12.335 --> 00:57:12.835
if
638
00:57:13.295 --> 00:57:14.115
639
00:57:14.575 --> 00:57:17.315
problem with Lightning Network right now is all HTLCs
640
00:57:17.615 --> 00:57:20.740
have the same hash. So if you are multiple nodes
641
00:57:21.120 --> 00:57:22.980
on the lightning network and you see
642
00:57:23.840 --> 00:57:36.420
a payment come in with a certain hash and it comes in one node and that's your node and then it leaves your node. But then, like, a few seconds later, it comes into a different node, and you can see the hash. You see it's the same one. You can start doing some
643
00:57:37.280 --> 00:57:38.500
to kinda figure out,
644
00:57:39.280 --> 00:57:51.705
where that payment came from and where it's going. And in theory, if you're every single one of the nodes in the path You're you control multiple of the hops. Multiple of the hops. You see where it's going and and you see where it came from,
645
00:57:52.859 --> 00:57:56.480
and you have pretty good analysis. And you can even start doing routing,
646
00:57:57.500 --> 00:57:58.000
deanonymizing
647
00:57:58.779 --> 00:58:05.275
the routing that they took, the pathing that they took, You do all kinds of analytics on that. But if if every single
648
00:58:05.815 --> 00:58:07.035
node were publicizing
649
00:58:07.335 --> 00:58:11.670
the payments that were coming in and leaving or they were selling it to a single actor,
650
00:58:12.369 --> 00:58:14.069
that would be terrible for privacy.
651
00:58:15.329 --> 00:58:16.630
And in theory,
652
00:58:17.155 --> 00:58:18.695
chain analytics, a multibillion
653
00:58:18.995 --> 00:58:19.975
dollar company,
654
00:58:21.395 --> 00:58:22.375
could actually
655
00:58:22.755 --> 00:58:27.580
create a market where they're asking people to sell transaction data. How valuable
656
00:58:27.960 --> 00:58:28.460
657
00:58:29.400 --> 00:58:30.380
the timeliness
658
00:58:30.760 --> 00:58:31.740
of that data
659
00:58:32.335 --> 00:58:39.454
from a chain analytics perspective. Like like, if if this, you know, this new alternative business model of selling
660
00:58:40.130 --> 00:58:45.830
661
00:58:46.450 --> 00:59:01.160
a meme. It's not really a meme. Like, data is the new oil. Right? Like, all the major tech companies You are the product. Are pretty much they monetize the data. That's that's their business model. Right? They give you a product for free, and then they monetize the data. So it's it's an established business model
662
00:59:01.700 --> 00:59:03.400
potentially moved over to lightning.
663
00:59:03.700 --> 00:59:08.555
I mean, I would say my simple monkey brain had, without getting, like, super technical,
664
00:59:09.335 --> 00:59:11.435
I mean, this is the main reason why we need
665
00:59:11.815 --> 00:59:12.315
independent
666
00:59:12.630 --> 00:59:17.930
Sovereign Bitcoiners, basically, running routing nodes over tour rather than just having, like, a few large companies
667
00:59:18.550 --> 00:59:20.410
running the major routing nodes.
668
00:59:21.464 --> 00:59:23.085
I have, like, no reason to,
669
00:59:26.505 --> 00:59:27.724
no reason to think
670
00:59:28.350 --> 00:59:32.130
that that guy, 0 fee routing, is a malicious actor.
671
00:59:32.750 --> 00:59:34.290
Right? But he offers
672
00:59:34.750 --> 00:59:42.165
0 fee routing. And if you're on if you're the if he's the only node you're connected to and he's one hop away from everyone else, then presumably,
673
00:59:42.465 --> 00:59:45.205
he doesn't even need to control other hops. Right? He could
674
00:59:45.710 --> 00:59:47.090
surveil you. Right.
675
00:59:47.470 --> 00:59:50.130
676
00:59:50.430 --> 01:00:11.359
677
01:00:11.885 --> 01:00:13.585
678
01:00:14.125 --> 01:00:17.905
yeah. I was not trying to drag his name to the I'm just clarifying. Yeah.
679
01:00:18.205 --> 01:00:22.740
And it but this is good because Paul's so far defended New York Times, China,
680
01:00:23.359 --> 01:00:24.260
Kyle Lager,
681
01:00:24.799 --> 01:00:30.045
and and 0 fee routing. So you're in good company, 0 fee routing. 0 fee routing implicitly.
682
01:00:31.065 --> 01:00:40.840
But you're vulnerable to 0 fee routing in that situation. Exactly. And just to use your words. It's a group. And but so there's an argument from a user point of view.
683
01:00:41.460 --> 01:00:45.465
Tell me if I'm wrong here. If you wanna distill it down to an easy digestible
684
01:00:45.845 --> 01:00:46.505
2 liner.
685
01:00:48.405 --> 01:00:52.185
If you if if your main incentive is to have the lowest fees,
686
01:00:52.590 --> 01:00:57.570
there's a strong argument to open to a very large public routing node.
687
01:00:58.110 --> 01:01:01.410
If if your if your goal is better privacy,
688
01:01:02.085 --> 01:01:03.625
you're better off with smaller
689
01:01:04.005 --> 01:01:06.345
routing nodes that are ideally Tor only.
690
01:01:06.645 --> 01:01:07.145
691
01:01:07.845 --> 01:01:12.390
And and ideally also ones that either don't have an alias
692
01:01:13.010 --> 01:01:18.390
or, you know, you don't know who actually owns them because there is an aspect of,
693
01:01:19.455 --> 01:01:20.515
and some people
694
01:01:21.855 --> 01:01:23.155
suggest this sometimes.
695
01:01:25.215 --> 01:01:29.050
If if if you have a payment come in or you're being probed
696
01:01:29.830 --> 01:01:34.170
or someone's trying to DDoS your channels or something like that, you could ask your channel partner.
697
01:01:34.550 --> 01:01:45.850
Hey, all these payments are coming in from your node. It might not be you or I've had a channel with you forever. I don't think you're actually randomly deciding to probe me. So where are you getting this spam from?
698
01:01:46.410 --> 01:01:52.270
And then you check, oh, it's from Matt's notes. So you ask Matt's. So there's this way to anonymize
699
01:01:52.650 --> 01:02:07.770
onion routing by literally just asking your channel partner, where is this coming from? Then they ask their channel partner, where is this coming from? And eventually, you can try to figure out who is actually if you if you know everyone in that path or you have access to talk to them,
700
01:02:08.950 --> 01:02:12.730
you could even send them like a lightning payment with a with a message in it.
701
01:02:13.595 --> 01:02:14.335
You can
702
01:02:14.715 --> 01:02:18.975
without even doing surveillance or without even doing active attacks or probing yourself.
703
01:02:19.275 --> 01:02:22.975
So you are vulnerable to everyone in the path, not colluding
704
01:02:23.579 --> 01:02:27.119
705
01:02:27.900 --> 01:02:36.925
706
01:02:37.705 --> 01:02:38.205
vulnerable
707
01:02:38.970 --> 01:02:47.630
to the payment hash being the same. I could go on Twitter, and I say, well, I don't know my channel partner. I'm trying to ask him where this payment is coming from. He's not responding.
708
01:02:47.930 --> 01:02:48.430
Twitter,
709
01:02:49.035 --> 01:03:02.060
does anyone have this payment hash in your transaction list? I'm trying to figure out where it came from. And then so you skip the hop that's being good by not actively de anonymizing you, but you found you went you found the pop before him,
710
01:03:02.760 --> 01:03:04.700
because you went on Twitter and you colluded
711
01:03:05.244 --> 01:03:11.744
712
01:03:12.125 --> 01:03:21.435
not know that that's a problem. So you, you know, you're vulnerable to not just people who are malicious towards you, but also people just making mistakes with And then, presumably, if you wanna talk
713
01:03:23.355 --> 01:03:29.615
714
01:03:30.150 --> 01:03:37.370
715
01:03:37.670 --> 01:03:39.370
716
01:03:41.095 --> 01:03:42.555
717
01:03:44.214 --> 01:03:44.714
718
01:03:48.620 --> 01:03:49.680
just use voltage.
719
01:03:50.300 --> 01:03:53.520
Voltage uses AWS, doesn't it? It really depends on your threat model.
720
01:03:54.140 --> 01:03:58.234
You know, if you're a merchant trying to receive or if you're a routing node,
721
01:03:59.194 --> 01:04:00.234
you know, you you,
722
01:04:00.615 --> 01:04:02.474
you care much less that,
723
01:04:04.500 --> 01:04:06.120
well, especially when you're a routing node.
724
01:04:06.740 --> 01:04:14.145
Think of why do we have all these routing nodes on the network that are, like, these huge deals and we don't even know who's running them?
725
01:04:14.925 --> 01:04:16.785
Because if they're not initiating
726
01:04:17.085 --> 01:04:18.145
sends and receives,
727
01:04:19.160 --> 01:04:19.900
you can act
728
01:04:20.600 --> 01:04:21.820
surprisingly anonymously
729
01:04:22.520 --> 01:04:27.500
as just A routing node. As just as a node. Especially a TOR only node.
730
01:04:28.405 --> 01:04:28.984
Oh, yeah.
731
01:04:29.525 --> 01:04:31.785
732
01:04:32.484 --> 01:04:34.825
you're obviously broadcasting your IP address.
733
01:04:35.190 --> 01:04:39.530
But, like, someone like Ellen Bigg, I mean, all of his IP addresses are a single
734
01:04:40.070 --> 01:04:41.450
server farm in
735
01:04:41.910 --> 01:04:42.410
Virginia.
736
01:04:43.425 --> 01:04:44.805
Doesn't mean he's from Virginia,
737
01:04:45.265 --> 01:04:47.765
but it's hard to buy a server privately.
738
01:04:48.145 --> 01:04:52.645
739
01:04:53.260 --> 01:04:54.800
computer hosting that IP
740
01:04:55.180 --> 01:04:56.160
or that ISP
741
01:04:56.460 --> 01:04:58.160
where that IP came from,
742
01:04:59.260 --> 01:05:02.560
there could be a court order. So a nation state could figure it out
743
01:05:02.975 --> 01:05:07.315
even if we can't, by just the IP address. We at least know it's in Virginia somewhere.
744
01:05:07.935 --> 01:05:08.335
745
01:05:08.815 --> 01:05:19.290
so we have ride or die freak alternative way in the matrix chat saying each time there's privacy discussion on CD, I think that Bitcoin and privacy is a lost cause, sweaty face.
746
01:05:19.975 --> 01:05:21.195
What do you say to him?
747
01:05:22.535 --> 01:05:23.915
748
01:05:24.935 --> 01:05:26.455
I'm I I'm not
749
01:05:27.150 --> 01:05:30.049
There's a fine line between, like, educating
750
01:05:30.430 --> 01:05:32.530
and being doom and gloom. And,
751
01:05:33.710 --> 01:05:36.369
you know, people need to be educated that,
752
01:05:36.945 --> 01:05:39.285
it's not perfect, and there's a lot of holes
753
01:05:39.745 --> 01:05:43.400
in lightning privacy and Bitcoin privacy as well.
754
01:05:44.599 --> 01:05:45.900
It's not a lost cause.
755
01:05:46.599 --> 01:05:51.819
You know, we I like to tow the line between breaking privacy and fixing privacy.
756
01:05:53.234 --> 01:05:59.654
Breaking privacy to educate people that it is kind of broken and you need to be careful, but then also trying to
757
01:06:00.049 --> 01:06:03.349
educate and make it better at the same time. So the reason,
758
01:06:04.210 --> 01:06:11.535
you know, I do this is is is so we can get privacy to be better. Well, to to fix problems, you have to be aware of the problems first. Yeah.
759
01:06:12.155 --> 01:06:14.734
760
01:06:16.450 --> 01:06:18.470
Otherwise, nothing will ever get fixed.
761
01:06:19.170 --> 01:06:24.310
It's definitely not a lost cause. If it was a lost cause, we wouldn't be having the conversation. I wouldn't be here. Yeah.
762
01:06:25.045 --> 01:06:25.444
763
01:06:25.925 --> 01:06:27.525
keep your keep your head up.
764
01:06:27.925 --> 01:06:34.900
765
01:06:36.260 --> 01:06:41.640
the the dollar cost averaging model. Like, you don't wanna, like, necessarily ape into,
766
01:06:43.045 --> 01:06:44.425
privacy in the sense of
767
01:06:44.725 --> 01:06:48.265
don't do it in such a way that you get burned out or discouraged
768
01:06:48.645 --> 01:06:50.185
or, you know, you, like,
769
01:06:50.650 --> 01:06:53.390
do how much you feel, like,
770
01:06:53.770 --> 01:06:55.390
psychically you can afford
771
01:06:56.089 --> 01:07:04.345
on a on any given day. Like, I I'm not recommending this as a privacy thing, but I did this for my own sanity as I got sick of,
772
01:07:07.990 --> 01:07:08.490
Calix,
773
01:07:09.350 --> 01:07:17.485
OS. And I just got tired of being, an Android user and it was pain in the ass And I did not I wasn't enjoying it psychically.
774
01:07:18.025 --> 01:07:24.205
And so I I switched to an iPhone. And I'm not that I I think graphy and Calix are are vastly
775
01:07:24.505 --> 01:07:25.005
better
776
01:07:25.609 --> 01:07:30.910
choices, but I wasn't enjoying the trade off of the amount of time and effort I was spending,
777
01:07:31.930 --> 01:07:33.549
and and the user experience.
778
01:07:34.265 --> 01:07:46.330
And so I was like, you know what? I want to do that. I admire people that do do it, but I don't wanna be I don't want that to be my focus right now. I have other things I'm focused on being good at and and achieving right now.
779
01:07:47.350 --> 01:07:53.545
780
01:07:53.925 --> 01:07:58.665
Yeah. This convenience privacy trade off, I I don't like. Right. It's counter
781
01:07:59.040 --> 01:08:04.420
it's counterproductive for myself, but I'm still gonna focus on improving other aspects of my life.
782
01:08:04.800 --> 01:08:07.060
And I'm not gonna get discouraged about it. Right?
783
01:08:08.985 --> 01:08:10.285
Feel like that's a good analogy.
784
01:08:11.465 --> 01:08:13.965
785
01:08:14.400 --> 01:08:17.540
as well on the topic, and you know the trade offs, and you know
786
01:08:18.000 --> 01:08:23.700
when when you would use it maybe in the future Mhmm. Versus what you're sacrificing right now.
787
01:08:24.635 --> 01:08:29.535
So it's it's cons, it's going into your threat modeling in in the back of your head.
788
01:08:31.810 --> 01:08:32.630
789
01:08:35.410 --> 01:08:46.170
Do you guys have anything else you wanna talk about? I know, Tony, when you said when we when we finished up yesterday, you said you had a lot more privacy lightning conversation you wanna have. Do you think we we nailed it all? Or
790
01:08:48.010 --> 01:08:50.410
791
01:08:51.850 --> 01:09:00.625
You know, Paul and I and and and Ben Carmen and a few other people also got, like, a grant to work on lightning privacy stuff too. So it's it's really cool to be able to,
792
01:09:01.005 --> 01:09:06.500
we've been going through it for about 2 months or so. And what does that look like? Yeah. So it's, like, 1.1
793
01:09:06.880 --> 01:09:08.100
Bitcoin split amongst,
794
01:09:08.400 --> 01:09:11.055
a few people, and it's basic right now, it's
795
01:09:11.695 --> 01:09:12.595
weekly meetings
796
01:09:12.975 --> 01:09:18.070
talking about we we try to hone in to a specific topic of lightning every single time we meet up,
797
01:09:18.790 --> 01:09:27.849
and we'll hone in, like one time we had TBAS on and and we focused on trampoline routing and how we can improve privacy by utilizing trampoline.
798
01:09:28.535 --> 01:09:33.115
Soon, we'll be we'll we'll have someone talk about splicing. We'll have someone talk about,
799
01:09:33.575 --> 01:09:39.740
bolt 12 and and and route finding, and and we're gonna go through that. We're still going through it, but then come up with,
800
01:09:40.680 --> 01:09:47.575
what a lightning privacy wallet could look like with, like, backed research and analysis on all these topics. So we're not just,
801
01:09:48.275 --> 01:09:53.975
we're not we're not just, like, aping into, like, new Lightning wallets. We're actually trying to also leverage
802
01:09:54.450 --> 01:09:55.190
the research,
803
01:09:55.970 --> 01:09:59.510
and the studying that we've been doing over months and trying to come up with,
804
01:09:59.970 --> 01:10:03.430
805
01:10:04.375 --> 01:10:09.594
806
01:10:10.135 --> 01:10:15.929
807
01:10:16.630 --> 01:10:19.929
808
01:10:20.364 --> 01:10:26.685
809
01:10:27.140 --> 01:10:35.880
today actually with with PLN was was, you know, you can think of some of these things as like a decision tree. Like, the the the user tries to do this.
810
01:10:36.955 --> 01:10:43.455
Is this super private of an action to do? Like, you know, the example of trying to pay a direct channel peer,
811
01:10:43.970 --> 01:10:56.144
Or do we wanna warn them about that? How dangerous is that? You know? Are they willing to embrace that danger or do they wanna try an alternate route? Like, you know, how else can we pay this person? Well, another route is to,
812
01:10:56.684 --> 01:11:02.150
create a new channel, maybe create a channel with a a well connected hub. Well, there's privacy trade offs there.
813
01:11:02.450 --> 01:11:11.575
So, you know, it so, like, there there's a tree of decisions to make so we can do that research and and and write that down. And then, also, hopefully,
814
01:11:11.955 --> 01:11:18.855
815
01:11:19.449 --> 01:11:31.614
It's mostly just designing what it would look like, and, you know, we're kind of at the same time. Sounds like easy money. It sounds like you guys are just talking about what you enjoy talking about already, and you just got a grant for it. I mean, isn't that what it's all about? Right? Getting
816
01:11:32.475 --> 01:11:35.855
getting paid to do what you believe in, what you care about,
817
01:11:36.235 --> 01:11:37.130
day to day.
818
01:11:37.449 --> 01:11:39.949
819
01:11:41.290 --> 01:11:46.750
820
01:11:47.495 --> 01:11:51.835
But it's nice to have a little back pocket money. And if I wanna do it anyways,
821
01:11:52.375 --> 01:12:03.590
822
01:12:03.985 --> 01:12:17.780
go on DuckDuckGo or whatever your favorite search engine is and type and change my I my IP address and then the ISP name, whether that's, like, Verizon or Comcast or whatever, they'll usually be someone else who has had to do that in the past.
823
01:12:19.765 --> 01:12:24.905
I remember at my last apartment with Fios, like, you did something with the
824
01:12:26.085 --> 01:12:35.850
you you did something with, like, unplugging your Ethernet, and then you just, like, turned it off for a while, and then the network gives you a new I s a new IP address. Sometimes it's a little bit more complicated.
825
01:12:36.255 --> 01:12:38.435
The burn it all down approach is you just
826
01:12:38.815 --> 01:12:45.235
cancel that Internet provider, and you get a new Internet provider. You get a new You move to a new new IP address. Yeah. You can also move.
827
01:12:45.920 --> 01:12:57.875
That that's an option. I don't know how actionable that is. It. Hacker bags move away. But I think of I think I, like, turned off my my Internet for, like, 3 hours or something. And then when I turned it back on, I got a new IP address.
828
01:12:58.815 --> 01:13:00.835
829
01:13:01.190 --> 01:13:09.555
if you do change your like, if you start out with an IP address and then you later change it, you get rid of that on your node and you go Tor only.
830
01:13:10.095 --> 01:13:10.915
That gossip
831
01:13:11.215 --> 01:13:24.370
that you broadcasted your IP address, that is, like, stays there forever. And Right. They still know that previous IP address. Right. Every node knows that you just switched from an IP address to a Tor address Right. And have that previous IP address. Like, with my node, I
832
01:13:25.085 --> 01:13:27.985
833
01:13:29.965 --> 01:13:49.645
And then there was a freak that reached out to me. He's like, Matt, I think I found a vulnerability in Tor. Like, I discovered your IP address. I was like, no. That's just the old one that it was it was publicly gossiping on. Right. 1 ML keeps track of it. I believe Amboss keeps track of it too. You got Ben Carmen in the chat. You can use a VPN too. Yeah. If you've already leaked your IP address, then
834
01:13:50.105 --> 01:13:51.165
835
01:13:51.920 --> 01:13:58.179
836
01:13:58.605 --> 01:13:59.505
like Mullvad
837
01:14:00.045 --> 01:14:00.864
or IVPN.
838
01:14:01.324 --> 01:14:08.680
And then and, basically, they know your IP address, but the rest of the world sees the shared IP address that's provided to you by the VPN provider,
839
01:14:09.780 --> 01:14:12.825
which is why VPNs are useful tool, especially if you
840
01:14:13.225 --> 01:14:15.325
don't provide personal information and
841
01:14:15.865 --> 01:14:17.565
you pay privately with Bitcoin.
842
01:14:20.960 --> 01:14:28.659
843
01:14:29.515 --> 01:14:39.800
844
01:14:40.600 --> 01:14:42.700
Oh, run a separate tour relay note.
845
01:14:43.560 --> 01:14:48.864
Fucking Rod leaves the studio and just leaves the door propped open, so we don't have soundproofing.
846
01:14:49.405 --> 01:14:50.364
847
01:14:51.244 --> 01:14:53.905
a Tor node as, like, an actual Tor implementation.
848
01:14:54.605 --> 01:15:03.160
849
01:15:03.540 --> 01:15:10.505
it bothers me that we have this such a outsized dependency on something that's, like, not This tourist coin?
850
01:15:11.285 --> 01:15:12.185
I don't know.
851
01:15:13.045 --> 01:15:14.805
It it's not it's clearly not
852
01:15:15.980 --> 01:15:18.320
I mean, lightning actually has these problems as well.
853
01:15:18.940 --> 01:15:19.760
Not necessarily
854
01:15:20.139 --> 01:15:20.639
designed
855
01:15:21.020 --> 01:15:21.679
to be,
856
01:15:22.380 --> 01:15:23.199
spam tolerant.
857
01:15:24.485 --> 01:15:27.705
858
01:15:28.165 --> 01:15:33.120
859
01:15:33.680 --> 01:15:35.940
about how to solve these problems, and
860
01:15:36.480 --> 01:15:38.900
other projects don't I mean, it's it's
861
01:15:39.280 --> 01:15:41.540
other projects by virtue of not being
862
01:15:42.034 --> 01:15:43.094
the one money
863
01:15:44.034 --> 01:15:53.570
864
01:15:54.030 --> 01:15:54.990
865
01:15:56.515 --> 01:16:00.614
866
01:16:01.315 --> 01:16:08.199
867
01:16:08.660 --> 01:16:14.554
868
01:16:14.855 --> 01:16:27.070
I two p works, but you can have that as another option now. There's, like, probably 2 I two p nodes. Bitcoin nodes big like, John Attack and Corolla or the 2 running. Is, like, a lot like tour, but without, like, the exit node aspect.
869
01:16:27.530 --> 01:16:35.525
870
01:16:36.065 --> 01:16:36.705
which is
871
01:16:37.185 --> 01:16:43.010
872
01:16:44.449 --> 01:16:49.190
Presumably, don't run an exit node unless you understand the ramifications of that because
873
01:16:50.335 --> 01:16:53.875
exit node traffic is associated with you, but it could be anybody
874
01:16:54.494 --> 01:16:55.554
going through tour.
875
01:16:56.335 --> 01:16:58.434
But relay nodes don't have that issue
876
01:16:59.270 --> 01:17:06.090
877
01:17:06.655 --> 01:17:11.955
some I two p work on the lightning network as well so you can have an option that's not tor.
878
01:17:12.255 --> 01:17:16.210
That way when tor goes down as it does a lot,
879
01:17:17.090 --> 01:17:23.750
880
01:17:24.255 --> 01:17:26.434
what the problem is. You know?
881
01:17:28.735 --> 01:17:31.715
Like, you don't quite know why something failed.
882
01:17:33.550 --> 01:17:39.010
Right? Like like, it was in clear net Internet, you get, like, an error from back from the server.
883
01:17:39.525 --> 01:17:42.325
Like, you just couldn't couldn't connect. Like, Tor doesn't
884
01:17:43.285 --> 01:17:50.890
885
01:17:51.910 --> 01:17:56.250
Yeah. Because, on when I was doing some of those lightning probe and stuff, it was hard to tell
886
01:17:56.795 --> 01:18:05.055
why some payments would get stuck or be slower. They're unreliable. Is it because it's slow on lightning? Is it because the tour network's slow?
887
01:18:05.760 --> 01:18:21.375
I know every time, you know, some some people say this about Zeus. I love Zeus. Evan is doing a fantastic job on it. One thing that he'll get, like, support tickets on, they open up their Tor only lightning network node and even has a Tor only address to interact with it.
888
01:18:22.300 --> 01:18:30.800
So people open up Zeus, and they try to access their note at home. And it's it fails a lot sometimes because it's going through Tor only.
889
01:18:31.245 --> 01:18:43.750
And, you know, sometimes you'll get support tickets where it's like, well, why is this slow? You know, Zeus keeps failing. It's like, it's not it's not me, guys. It's like, literally, Tor. And we're building Tor potentially into, like, the UX
890
01:18:44.210 --> 01:18:46.550
891
01:18:47.755 --> 01:18:51.135
Like, what if I you know, like Oh, then we go to 711,
892
01:18:51.435 --> 01:18:57.420
893
01:18:57.720 --> 01:19:04.380
Jack Mallers did where he, like, pulls out his node. He pulls out his phone. He's like, oh, I just paid for Coke at 7:11.
894
01:19:05.035 --> 01:19:09.135
Via tour. Yeah. Lighting network. I was like, I've never seen for work that fast in my fucking life.
895
01:19:09.435 --> 01:19:12.655
896
01:19:12.955 --> 01:19:15.140
And then, what if, you know, now,
897
01:19:15.520 --> 01:19:17.860
what if you're making longer routes?
898
01:19:18.560 --> 01:19:20.260
I one potential way,
899
01:19:22.045 --> 01:19:23.985
to use lightning is to
900
01:19:24.525 --> 01:19:40.665
involve slowing down lightning, basically. Like, you know, longer longer routes are gonna be a lot slower because you need all of this But then you get more privacy. Essentially, you get more privacy. But if you think of lightning is is the coffee solves the the coffee problem of Bitcoin,
901
01:19:42.085 --> 01:19:44.585
you know, if it doesn't solve it well,
902
01:19:45.489 --> 01:19:55.815
we're gonna have to we're gonna have to, either improve it or we'll have to have another layer to solve coffee. So do you think if someone goes to a coffee shop and buys
903
01:19:57.155 --> 01:20:03.575
904
01:20:05.050 --> 01:20:06.270
are they using Bitcoin?
905
01:20:09.850 --> 01:20:22.830
With Ibex, can you, like, choose for it to go to your node instead of just them? No. But I'mx Ibex has a no k y c version that just collapses all the payments to an on chain address at the end of the day. Pay with strike
906
01:20:23.370 --> 01:20:26.670
907
01:20:27.450 --> 01:20:34.135
908
01:20:34.515 --> 01:20:35.175
You know,
909
01:20:35.875 --> 01:20:40.570
like, Coinbase is technically, like, a layer on top of Bitcoin, you can argue. So it's like
910
01:20:41.110 --> 01:20:54.775
they're not using Bitcoin directly. They're using Bitcoin between 2 untrusted parties. Right. You know, strike doesn't trust ibex, and ibex doesn't trust Stripe. Although, they probably have a channel between But the user and the merchant are trusting both. Right. Or they're vulnerable to both.
911
01:20:55.460 --> 01:21:03.560
Yeah. I mean, they're vulnerable. Well, the merchant's vulnerable to Ibex, and then the user is vulnerable to Stripe. And they're both vulnerable to each for their privacy.
912
01:21:04.554 --> 01:21:06.175
True. Yeah. I mean, they could collude.
913
01:21:06.635 --> 01:21:13.215
914
01:21:13.920 --> 01:21:17.540
topics for discussion, tour, tail scale, and LN Connect.
915
01:21:18.000 --> 01:21:23.015
LN Connect kind of solves this Zeus tour issue we were talking about. Right? Exactly.
916
01:21:23.575 --> 01:21:29.835
917
01:21:30.295 --> 01:21:32.715
So Allen Connect is this idea that,
918
01:21:33.470 --> 01:21:33.970
you,
919
01:21:34.910 --> 01:21:35.810
it kinda uses,
920
01:21:37.790 --> 01:21:41.970
I I don't know the exact type behind it, but some relay. So you can have your lightning network
921
01:21:42.435 --> 01:21:43.175
not exposed,
922
01:21:44.915 --> 01:21:50.659
via you don't have to, like, do port forwarding or anything like that. It'll be a Tor only node, but you can
923
01:21:50.960 --> 01:22:01.054
924
01:22:01.594 --> 01:22:05.614
925
01:22:07.230 --> 01:22:11.570
926
01:22:11.870 --> 01:22:12.930
of lightning connection.
927
01:22:13.710 --> 01:22:26.030
928
01:22:26.730 --> 01:22:31.790
929
01:22:32.465 --> 01:22:33.285
I think it's socket.
930
01:22:34.145 --> 01:22:34.645
931
01:22:35.105 --> 01:22:51.120
932
01:22:51.885 --> 01:23:00.465
933
01:23:00.990 --> 01:23:04.930
you need to get him on dispatch sometime soon. Yeah. Because I need to explain it to me, actually.
934
01:23:06.670 --> 01:23:07.170
Cool.
935
01:23:08.165 --> 01:23:12.344
So, Freaks, first of all, like, if you have any questions for these great guests,
936
01:23:12.724 --> 01:23:14.905
once again, feel free to put them in the comments.
937
01:23:16.210 --> 01:23:18.390
938
01:23:18.850 --> 01:23:21.510
939
01:23:22.210 --> 01:23:27.665
940
01:23:29.405 --> 01:23:31.744
I know my IP address. Right?
941
01:23:32.125 --> 01:23:34.320
So it is not,
942
01:23:34.780 --> 01:23:35.679
in some sense,
943
01:23:36.139 --> 01:23:41.525
if if my phone is talking to my home node, right, it is not a leak to,
944
01:23:42.545 --> 01:23:45.605
myself what my IP address is. Right? Right.
945
01:23:45.985 --> 01:24:01.735
946
01:24:02.355 --> 01:24:09.369
configuring ports on your router and stuff is pain in the ass. So if you just do Tor, you don't have to deal with that work forwarding
947
01:24:09.670 --> 01:24:34.310
948
01:24:35.715 --> 01:24:47.810
But you're not trusting them with all of your light they don't see all of your lightning traffic. I mean, it's similar to kind of the trade off with Ellen connect, where you are allowing somebody to be a proxy between 2 of your devices.
949
01:24:48.270 --> 01:25:03.739
And and the traffic is obviously encrypted, so they don't see the traffic. But they do see that traffic is happening between 2 points. Alright. So if you don't want anybody to know that you have a lightning node and that you communicate to it from this specific device,
950
01:25:05.639 --> 01:25:11.260
then these are not good solutions for that. But if you are fine with that trade off, which I think personally I am,
951
01:25:12.045 --> 01:25:12.545
then,
952
01:25:13.165 --> 01:25:22.780
953
01:25:23.400 --> 01:25:28.060
there's a mode where they can tell 2 points, handshake, and then they take it
954
01:25:28.465 --> 01:25:36.325
They don't see that there's traffic between them. But then if there's, like, heavy firewalls and things in place between the home network and the the other points,
955
01:25:37.210 --> 01:25:42.270
they then they see that traffic is actively happening between 2 points, but they don't.
956
01:25:42.970 --> 01:25:46.270
But then there's also a mode where they just see 2 points, handshake,
957
01:25:46.745 --> 01:25:50.844
but then they don't see that traffic if actively flowing. So Allen Connect also has,
958
01:25:51.625 --> 01:25:52.745
that aspect, and,
959
01:25:53.225 --> 01:25:56.489
I don't think it's I don't even think Lightning Labs is hosting their
960
01:25:57.030 --> 01:25:59.130
own proxy service for these. I think they're utilizing
961
01:25:59.590 --> 01:26:01.530
the ones that already exist on the network.
962
01:26:02.465 --> 01:26:06.805
963
01:26:07.265 --> 01:26:15.530
So, obviously, they don't it's not exactly a proxy server. That's a loose term. But Yep. You can run your own one. So you don't just have to trust Lightning Labs for this.
964
01:26:15.990 --> 01:26:16.490
965
01:26:17.295 --> 01:26:18.915
Alternative way, ask another question.
966
01:26:19.215 --> 01:26:22.915
What if Lightning payments required a minimum number of hops for privacy?
967
01:26:23.375 --> 01:26:25.395
I mean, we kinda talked about that already.
968
01:26:25.860 --> 01:26:33.300
I think if that happened, you'd it'd basically be on the wallet level. Right? Not on the protocol level. Yeah. You couldn't enforce that on the protocol level, really. But,
969
01:26:33.940 --> 01:26:35.320
970
01:26:35.815 --> 01:26:36.554
it is
971
01:26:36.935 --> 01:26:39.034
better. For privacy. Want to do for privacy.
972
01:26:39.735 --> 01:26:41.994
It does not make privacy bulletproof
973
01:26:42.695 --> 01:26:44.715
for many other reasons like correlation
974
01:26:45.094 --> 01:26:45.594
for
975
01:26:45.960 --> 01:26:47.740
timing analysis for HCLC
976
01:26:48.360 --> 01:26:50.540
hash analysis for amount analysis.
977
01:26:52.280 --> 01:26:58.295
978
01:26:59.475 --> 01:27:00.135
For privacy.
979
01:27:00.675 --> 01:27:02.760
So I have a question for Paul. Paul,
980
01:27:03.220 --> 01:27:05.480
this is my own question, not from the audience.
981
01:27:06.420 --> 01:27:10.920
You've been working at Voltage for a while. Voltage makes it really easy for people to run,
982
01:27:11.364 --> 01:27:15.465
lightning node, through your service that's in a trust minimized way.
983
01:27:17.980 --> 01:27:25.920
What have you guys learned over at Voltage in terms of, you know, making Lightning easier? Like, what do you how do you guys think about Lightning? Or how do you think about Lightning?
984
01:27:26.364 --> 01:27:28.864
985
01:27:29.245 --> 01:27:31.245
at Voltage, it's sort of this,
986
01:27:32.285 --> 01:27:33.344
there's this interesting,
987
01:27:34.045 --> 01:27:34.545
like,
988
01:27:35.110 --> 01:27:38.330
usability slider with all things. So like the the magic
989
01:27:38.790 --> 01:27:41.690
special sauce of voltage. Voltage is non custodial
990
01:27:45.105 --> 01:27:46.005
cloud hosting.
991
01:27:46.545 --> 01:27:48.804
So which sounds like pretty ridiculous.
992
01:27:49.184 --> 01:27:50.405
And so what's the
993
01:27:50.830 --> 01:27:52.370
trust model, the vulnerability
994
01:27:52.750 --> 01:27:53.250
there
995
01:27:53.630 --> 01:27:57.170
is that the way the way we pull this off is that we
996
01:27:59.114 --> 01:28:06.815
encrypt in the front end, which is what I work on, so I hope I'm doing a good job. The in the front end, we encrypt the macaroon.
997
01:28:07.910 --> 01:28:16.170
So when you you fire up the the the lightning node, you're you're and then we put your the front end in direct contact with the lightning node.
998
01:28:17.175 --> 01:28:17.675
And
999
01:28:19.255 --> 01:28:25.115
that is where the front end generates the the node generates the wall, it gets the the admin macaroon,
1000
01:28:25.660 --> 01:28:32.400
and encrypts that and then sends it back to voltage encrypted to that password. So we we only store an encrypted
1001
01:28:32.700 --> 01:28:34.960
copy and we don't have the power
1002
01:28:35.395 --> 01:28:42.454
to direct your notes. So we can turn your note off. We could delete all your data. We could delete the encrypted macaroon,
1003
01:28:43.730 --> 01:28:49.830
but we we don't have the decryption key. We don't have the password that decrypts that macaroon. Therefore,
1004
01:28:50.530 --> 01:28:51.990
we, in fact, can't
1005
01:28:52.315 --> 01:28:58.175
move the money. Now the vulnerability there, the trust there, is that you're trusting that we haven't
1006
01:28:58.635 --> 01:29:03.090
secretly forked our copy of LND or did something else in the back end
1007
01:29:03.390 --> 01:29:20.579
that, we actually do end up with some sort of decrypted MAC group. But if you if you if you trust us to do that, we in fact and we've in fact haven't done that. So therefore, we can't move your money around. So that's the trust model. And, also, the key thing is you're trusting basically
1008
01:29:20.960 --> 01:29:21.780
1009
01:29:22.800 --> 01:29:31.375
I mean, because you could do, like, you could just delete all the data or just not have the note online. Right. Yeah. We could we could turn it off for the Yeah. For sure.
1010
01:29:32.635 --> 01:29:33.135
1011
01:29:33.620 --> 01:29:39.719
so the the upside you get for that is the is I think the big thing is is reliability
1012
01:29:40.100 --> 01:29:41.639
and and and the findability.
1013
01:29:42.375 --> 01:29:46.554
Like, we're talking about a lot of, like, privacy stuff, but for,
1014
01:29:48.295 --> 01:29:48.954
a merchant,
1015
01:29:49.860 --> 01:29:56.199
or for a routing node, or for for somebody who wants a node that is very easy to connect to,
1016
01:29:56.900 --> 01:29:57.719
and visible
1017
01:29:58.515 --> 01:29:59.655
on the Lightning Network.
1018
01:29:59.955 --> 01:30:04.135
And, also, is easy to work for with from a developer perspective.
1019
01:30:04.755 --> 01:30:09.719
Like, we haven't talked much about this, but if you're you're making an app on top of lightning,
1020
01:30:10.820 --> 01:30:12.520
that app needs to communicate
1021
01:30:13.460 --> 01:30:18.325
with with you like like, let's say you're making an app that accepts payments. Right?
1022
01:30:19.285 --> 01:30:24.825
You you want the you want the the app to do to show when the payment goes through.
1023
01:30:25.420 --> 01:30:46.860
So that app needs to be talking to the node like, hey, did you see this payment go through? I showed the invoice to the user, but I was and so there there's that communication. Right? So how does your app communicate to the to to the node? That's another thing that the that that having, like, the this sort of cloud hosting thing instead of something that is hosted at home.
1024
01:30:48.520 --> 01:30:49.660
I mean, as a developer,
1025
01:30:50.680 --> 01:30:55.695
I don't talk to my home node from the apps that I make. Right. I I think LNC
1026
01:30:56.074 --> 01:31:04.170
Lightning node connect is actually a really interesting way to potentially do that. And I'm actually looking into that because I think there's some really there's some cool potential there.
1027
01:31:06.070 --> 01:31:12.865
So anyways, what we end up with, though, at Voltage is there's a trade off slider. You know, there are custodial lightning solutions
1028
01:31:13.645 --> 01:31:14.145
that
1029
01:31:16.230 --> 01:31:18.010
that just take a fee or,
1030
01:31:19.190 --> 01:31:21.850
that it's it's possible to make
1031
01:31:22.445 --> 01:31:23.345
a lot easier
1032
01:31:24.285 --> 01:31:25.025
in experiences
1033
01:31:25.565 --> 01:31:26.465
on top of.
1034
01:31:27.325 --> 01:31:28.385
So we basically
1035
01:31:28.925 --> 01:31:30.785
we offload a lot of challenge
1036
01:31:31.150 --> 01:31:33.890
and difficulty to the user in order to achieve,
1037
01:31:35.150 --> 01:31:36.050
this this,
1038
01:31:37.630 --> 01:31:47.435
non custodial binding. And so I think that's it it it's I think it's a challenge that I think every Bitcoin company ultimately ends up with is do we compromise,
1039
01:31:48.190 --> 01:31:48.690
like,
1040
01:31:49.949 --> 01:31:51.489
the properties of Bitcoin
1041
01:31:52.829 --> 01:31:55.969
in order to achieve a user UX?
1042
01:31:57.255 --> 01:32:00.635
Or do we kinda stay true to the properties of Bitcoin
1043
01:32:01.094 --> 01:32:02.155
and and
1044
01:32:02.614 --> 01:32:07.210
and have something that's harder to use, but in some sense is built for the longer run.
1045
01:32:07.910 --> 01:32:12.810
So it's kind of like a high time preference, low time preference. But the other aspect of that is
1046
01:32:13.835 --> 01:32:18.175
there are things that are hard to do, but can be made easier
1047
01:32:18.475 --> 01:32:19.534
without compromising,
1048
01:32:21.360 --> 01:32:25.860
the Bitcoin Ethos. And those are, to me, like, the most exciting And what is the Bitcoin Ethos to you?
1049
01:32:28.535 --> 01:32:30.475
It's the the the non
1050
01:32:31.574 --> 01:32:32.715
it non sensibility.
1051
01:32:33.895 --> 01:32:38.320
It it's sort of the the ability to to use money without permission.
1052
01:32:39.179 --> 01:32:41.679
So, obviously, privacy becomes a big part of that,
1053
01:32:42.860 --> 01:32:43.360
because
1054
01:32:44.585 --> 01:32:49.565
to tell you no, they need to know if. Right? So that's why privacy is interesting.
1055
01:32:50.264 --> 01:32:52.684
But, yeah, it's it's sort of it's using money,
1056
01:32:52.985 --> 01:32:54.910
in a permissionless way. So,
1057
01:32:56.010 --> 01:32:58.990
you know, putting a node on a on on,
1058
01:32:59.450 --> 01:32:59.950
AWS
1059
01:33:00.410 --> 01:33:02.750
that Jeff Bezos shut down
1060
01:33:03.130 --> 01:33:03.950
is not
1061
01:33:04.324 --> 01:33:08.505
entirely permissionless money. Right. And so it is not,
1062
01:33:10.405 --> 01:33:11.465
completely cypherpunk.
1063
01:33:12.340 --> 01:33:18.920
1064
01:33:19.375 --> 01:33:23.155
1065
01:33:23.615 --> 01:33:24.355
and performance
1066
01:33:24.975 --> 01:33:31.580
that you would want in a real, you know, buying coffee situation or if you're building an app on top of
1067
01:33:32.120 --> 01:33:34.940
lightning that you you need performance, you need
1068
01:33:35.415 --> 01:33:40.955
you want something enterprise grade that you have confidence in the uptime and in the latency
1069
01:33:41.255 --> 01:33:47.110
1070
01:33:47.810 --> 01:33:49.430
would be, like, the Canadian Truckers.
1071
01:33:49.890 --> 01:33:51.350
So the Canadian Truckers,
1072
01:33:53.275 --> 01:33:54.235
used an app called,
1073
01:33:56.395 --> 01:33:57.295
Tali coin
1074
01:34:00.290 --> 01:34:02.710
created by DJ Booth. Awesome dude.
1075
01:34:03.490 --> 01:34:08.310
They reused an address for on chain payments, so there's no privacy there.
1076
01:34:08.945 --> 01:34:13.525
The Lightning node they used was they connected an already existing Lightning node, and it was,
1077
01:34:14.304 --> 01:34:15.605
our boy, Ben Sessions,
1078
01:34:16.065 --> 01:34:16.965
Lightning node.
1079
01:34:20.139 --> 01:34:22.719
And as as a result, there was
1080
01:34:23.980 --> 01:34:36.185
obvious actors that could be pressured Mhmm. For that fundraiser, and the Canadian government pressured them and got them to hand over a bunch of the Bitcoin, and they were tracking all the on chain Bitcoin. So those are all
1081
01:34:36.550 --> 01:34:38.250
still being tracked to this day.
1082
01:34:39.030 --> 01:34:39.930
If that fundraiser
1083
01:34:40.310 --> 01:34:41.610
had been done by NIMS
1084
01:34:42.630 --> 01:34:45.705
and they used a voltage node without KYC,
1085
01:34:49.385 --> 01:34:52.925
it wouldn't have been purely permissionless, but it would have been a massive step
1086
01:34:54.270 --> 01:34:58.130
forward in censorship resistance. Right. It wouldn't have been a perfect situation,
1087
01:34:58.510 --> 01:35:07.905
but it would have been a significant it would have been a significant improvement there because they would have been using a BTC pay instance. They would have been using a fresh node. They wouldn't have been reusing addresses,
1088
01:35:09.005 --> 01:35:12.625
and we go through all that in detail on still dispatch 57
1089
01:35:13.150 --> 01:35:17.410
that Tony was a part of. But I feel like that's a that's a pretty good example of
1090
01:35:18.190 --> 01:35:24.525
of where Voltage sits in that trade off model. And, obviously, in that situation, it was in a a proper adversarial environment.
1091
01:35:25.145 --> 01:35:27.565
If you're talking about, like, a merchant receiving payments,
1092
01:35:27.945 --> 01:35:31.780
they can use something like Ibex, where they're trusting their privacy to Ibex,
1093
01:35:32.320 --> 01:35:33.540
or they can use Voltage,
1094
01:35:34.400 --> 01:35:35.619
not do k y c,
1095
01:35:35.920 --> 01:35:37.060
not reuse addresses,
1096
01:35:37.445 --> 01:35:44.345
hold their own keys. The on chain portion, literally, you don't even there's even less trust on the on chain portion with something like Voltage
1097
01:35:44.965 --> 01:35:50.100
because you can use it. You can be holding your keys offline and just have a x pub connected.
1098
01:35:50.560 --> 01:35:53.915
1099
01:35:54.875 --> 01:35:59.135
Flow, which is a a wrapper for for Lightning Labs pool.
1100
01:35:59.515 --> 01:36:02.335
Basically, we have, like, a pool account on your behalf.
1101
01:36:02.880 --> 01:36:06.100
One of the cool things privacy wise is if you want inbound liquidity,
1102
01:36:06.560 --> 01:36:10.500
you can or even outbound liquidity, you can pay out of band
1103
01:36:11.095 --> 01:36:13.355
for a channel open on flow,
1104
01:36:14.055 --> 01:36:20.715
which is a is a pretty nice setup. It's not there there are a lot of different interesting emerging ways. Because, again, we're
1105
01:36:21.400 --> 01:36:27.980
especially interested in in, like, the merchant use case. Right? Where you're gonna have a lot of inbound. Like, if you think of why is a company spending money
1106
01:36:28.325 --> 01:36:31.305
to run a lightning node? It might be because they wanna earn some Bitcoin.
1107
01:36:32.085 --> 01:36:36.630
So you wanna have inbound. And so that's something that we think a lot about is
1108
01:36:36.930 --> 01:36:42.950
and I again, you asked, like, what are some thoughts from working at voltage? Like, a lot of the aspect is
1109
01:36:43.410 --> 01:36:44.945
a lot of people
1110
01:36:45.485 --> 01:36:47.905
know what lightning is in a pretty,
1111
01:36:49.405 --> 01:37:12.210
I'd say, limited sense. And and you and and so they like know that they need a node and they fire up a node, but what's step 2 is actually very challenging. And so that's, to me, there it it's actually a really exciting opportunity. There is so much UX improvement I can do before I say like, hey, I need a 3 d scan of your face or something, you know? Like, there's just like, how do I help people,
1112
01:37:12.750 --> 01:37:14.930
you know, get liquidity to their node?
1113
01:37:15.390 --> 01:37:19.010
How do I help them easily build apps on top of,
1114
01:37:19.375 --> 01:37:21.655
you know, like, you know, you know, how do I,
1115
01:37:22.295 --> 01:37:24.235
enable developers and users
1116
01:37:24.615 --> 01:37:28.235
to effectively use this? I think there's so much we can build to improve
1117
01:37:29.050 --> 01:37:29.790
the experience
1118
01:37:30.490 --> 01:37:30.990
without
1119
01:37:31.370 --> 01:37:34.430
at all impacting like this this custodial aspect.
1120
01:37:34.810 --> 01:37:36.430
And I'm sure there are custodial
1121
01:37:37.105 --> 01:37:41.525
ish trade offs that we can make as well, but I I'm not thinking much about that right now.
1122
01:37:42.305 --> 01:37:44.325
1123
01:37:45.060 --> 01:37:48.760
Guys, I mean, this is an hour and 40 minutes so far. I think it's been a great conversation.
1124
01:37:49.780 --> 01:37:51.640
We have gotten really technical,
1125
01:37:53.655 --> 01:37:59.994
which I love. It's good it's good to to dive deep, and and some things will be over some of our heads.
1126
01:38:01.270 --> 01:38:04.890
But that's how we learn through through osmosis and pushing ourselves.
1127
01:38:06.070 --> 01:38:06.810
I imagine
1128
01:38:07.190 --> 01:38:12.895
this next week of dispatch will include heavy technical conversation and more accessible conversation.
1129
01:38:13.755 --> 01:38:16.735
You guys are familiar with a lot of the people that are coming in.
1130
01:38:17.260 --> 01:38:19.440
We have a massive crew coming in. I'm curious,
1131
01:38:21.179 --> 01:38:29.415
I'm both curious, and also it takes a little bit of effort off of my plate. What kind of conversations do you wanna see on dispatch over this next week?
1132
01:38:31.850 --> 01:38:32.910
1133
01:38:38.385 --> 01:38:42.725
1134
01:38:43.345 --> 01:38:43.845
tail,
1135
01:38:45.370 --> 01:38:49.070
1136
01:38:49.930 --> 01:38:52.170
1137
01:38:52.995 --> 01:38:59.415
if if you wanna add inflation to Bitcoin, just fork Bitcoin and add add add inflation and see what the fuck happens. I like the,
1138
01:39:00.275 --> 01:39:01.574
1139
01:39:02.340 --> 01:39:03.000
thought where,
1140
01:39:04.820 --> 01:39:05.320
you,
1141
01:39:07.140 --> 01:39:08.600
if you had infinite,
1142
01:39:09.300 --> 01:39:09.800
divisibility
1143
01:39:10.545 --> 01:39:11.284
in Bitcoin,
1144
01:39:11.744 --> 01:39:14.164
we don't ever have to stop the
1145
01:39:15.264 --> 01:39:18.324
the the block reward. It just gets smaller and smaller forever.
1146
01:39:18.704 --> 01:39:19.204
Casino's
1147
01:39:19.585 --> 01:39:20.085
paradox.
1148
01:39:21.170 --> 01:39:25.030
1149
01:39:25.570 --> 01:39:40.460
1150
01:39:40.760 --> 01:39:47.180
1151
01:39:47.955 --> 01:39:59.699
I think 8. Or is it 8 or 9? One of those. One of those. Okay. A 100,000,000 sets, but if you went deeper than sets, like, millisats Yeah. Or something. Yeah. So, like, or, like, every time yeah. Every time you ran out of
1152
01:40:00.000 --> 01:40:06.844
1153
01:40:07.304 --> 01:40:08.685
but not you're not
1154
01:40:09.145 --> 01:40:10.525
adding any more Bitcoin.
1155
01:40:11.065 --> 01:40:13.565
Other you are adding a small
1156
01:40:14.510 --> 01:40:15.010
view.
1157
01:40:15.470 --> 01:40:16.370
It is inflationary
1158
01:40:16.670 --> 01:40:22.930
over the current cap because you are adding a small fraction of, of what Satoshi
1159
01:40:23.474 --> 01:40:32.135
1160
01:40:32.620 --> 01:40:45.735
Carmen about Vortex for sure. Okay. So Carmen Wanna learn about it. And he talked on What what other guests do you wanna see on dispatch? Who do you which people should be at the stable talking on dispatch? I wanna see Carmen talk about chain analysis.
1161
01:40:46.915 --> 01:40:56.670
1162
01:40:57.370 --> 01:41:00.110
I wanna see that and then also the trade offs of working
1163
01:41:00.585 --> 01:41:02.045
at a custodian or
1164
01:41:02.425 --> 01:41:07.965
a place needing to implement something like that. Because Carbon's building the Bitcoin company right now. Which
1165
01:41:08.300 --> 01:41:13.760
you never know if they need to add that in the future or not. So, like, what are the trade offs there? Would he really quit,
1166
01:41:14.300 --> 01:41:20.445
1167
01:41:22.045 --> 01:41:25.905
1168
01:41:26.590 --> 01:41:34.210
1169
01:41:35.465 --> 01:41:39.405
Ergo had Ergo was on one of the first episodes, which I was pretty proud of.
1170
01:41:40.025 --> 01:41:42.125
Who else do you wanna see on dispatch this week?
1171
01:41:42.599 --> 01:41:45.260
1172
01:41:45.800 --> 01:41:48.940
1173
01:41:49.615 --> 01:42:00.600
1174
01:42:02.100 --> 01:42:04.680
1175
01:42:05.140 --> 01:42:06.520
1176
01:42:08.085 --> 01:42:14.745
So So there's 2 there's actually 2 two angles on this. You could easily implement no stir over dits,
1177
01:42:16.090 --> 01:42:18.110
and you could also do something
1178
01:42:18.489 --> 01:42:21.469
like dids over no stir. So, like, I there there are,
1179
01:42:22.730 --> 01:42:28.075