April 6, 2021

CD16: bitcoin privacy and coinjoin with chris belcher and waxwing

CD16: bitcoin privacy and coinjoin with chris belcher and waxwing
Citadel Dispatch
CD16: bitcoin privacy and coinjoin with chris belcher and waxwing

EPISODE: 0.1.6

BLOCK: 678040

PRICE: 1719 sats per dollar

TOPICS: bitcoin privacy, coinjoin


chris belcher: https://twitter.com/chris_belcher_


streamed live every tuesday:

https://citadeldispatch.com


twitch: https://twitch.tv/citadeldispatch​

bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos

podcast: https://anchor.fm/citadeldispatch​

telegram: https://t.me/citadeldispatch​


support the show: https://tippin.me/@odell

stream sats to the show: https://www.fountain.fm/

join the chat: http://citadel.chat/

00:03 - Goldman Sachs offering Bitcoin investment products to wealthy clients

03:04 - Bitcoin privacy and the importance of security

20:00 - PayJoin as a Bitcoin privacy solution

39:10 - The way Tor works nowadays and the hot wallet aspect

40:20 - Early days of Bitcoin and the interactivity of Lightning

41:03 - The impact of PayJoin on fees and the practicality of its usage

01:19:06 - Jack Miles gave a talk about it

01:19:23 - Facebook and Oculus

01:19:37 - Zuck's Facebook account got hacked

01:59:00 - CoinSwap and its advantages

02:00:57 - Comparison between CoinSwap and Lightning

02:11:07 - Visibility of privacy transactions

02:37:13 - Discussion about the limitations of using heuristics in analyzing broken transactions

02:38:50 - Opinions on Bisq and its importance as a project

02:46:45 - Opinions on Liquid and its use cases

WEBVTT

NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 4:34:04 PM
Duration: 11570.809
Channels: 1

1
00:00:00.240 --> 00:00:01.220
Coming from cmbc.com.

2
00:00:01.680 --> 00:00:04.180
Banking reporter, Houston. Goldman Sachs

3
00:00:04.799 --> 00:00:08.420
is getting close to offering Bitcoin investment products

4
00:00:09.025 --> 00:00:10.565
to its wealthy clients.

5
00:00:11.025 --> 00:00:11.525
Kewsan

6
00:00:12.705 --> 00:00:13.764
joins us now.

7
00:00:14.705 --> 00:00:19.310
Does Goldman know Bitcoin was, like, $4,000, like, 18 months ago, and now it's, like, 57,000?

8
00:00:19.850 --> 00:00:22.190
They're this is part of their, their expertise

9
00:00:22.570 --> 00:00:23.070
view?

10
00:00:23.930 --> 00:00:25.289
Well, Joe, I think the,

11
00:00:25.850 --> 00:00:31.485
those dizzying charts that everybody has, is looking at and salivating over, that's one of the reasons why,

12
00:00:32.185 --> 00:00:36.285
Goldman and others are are getting into this. You know, they are in a client business.

13
00:00:36.590 --> 00:00:51.245
So when clients of Goldman Sachs or clients of Morgan Stanley, you know, call up their financial adviser and say, should I have an allocation to Bitcoin? Look look at what it's done. You know? Should I have a 1%, 2%, 3% allocation to this emerging asset class?

14
00:00:51.625 --> 00:01:00.690
You know, they've had to say, well, as as a firm, we can't really recommend that. Well, that changes, and that changes very, very soon. So as we report exclusively

15
00:01:01.789 --> 00:01:03.010
on, cbc.com,

16
00:01:03.550 --> 00:01:07.735
Goldman Sachs is is very close and in the second quarter will begin offering

17
00:01:08.195 --> 00:01:20.670
Bitcoin and other digital asset related investments to its private wealth management clients. This is the, this is sort of the Tony private bank of Goldman Sachs. You know, they really target people and endowments with at least 25,000,000

18
00:01:21.130 --> 00:01:22.430
in assets under management.

19
00:02:02.495 --> 00:02:05.795
Happy Bitcoin Tuesday, freaks. It's your boy, Matt O'Dell,

20
00:02:06.340 --> 00:02:09.080
here for another episode of Citadel Dispatch,

21
00:02:09.460 --> 00:02:15.080
the interactive live show about Bitcoin distributed systems privacy and open source software.

22
00:02:15.885 --> 00:02:25.750
To those freaks joining us from our various audio streams, whether that's our 2 podcast feeds, our Sphinx tribe, or through the recent Breeze integration with podcasting 2 point

23
00:02:26.050 --> 00:02:31.270
o. That clip out in the beginning was our boy Joe Kernan from CNBC Squawk Box,

24
00:02:31.890 --> 00:02:33.190
who's currently running

25
00:02:33.585 --> 00:02:36.325
the largest, most popular Bitcoin entertainment

26
00:02:36.625 --> 00:02:37.925
show in the world.

27
00:02:38.945 --> 00:02:45.019
And he had a lot of fun trolling Goldman Sachs there with that with that massive announcement coming from them.

28
00:02:47.079 --> 00:02:50.805
Shout out to all the rider dive freaks that are joining us live in the comments.

29
00:02:51.385 --> 00:02:51.925
This is

30
00:02:53.825 --> 00:02:55.285
another earlier episode

31
00:02:56.720 --> 00:02:58.900
to to help our guests with time zones.

32
00:02:59.360 --> 00:03:07.125
So I hope you don't find it too early. I know some people preferred it. I know some people didn't. It is what it is. We will probably be switching between the 2,

33
00:03:07.665 --> 00:03:13.285
time slots, whether that's 1700 UTC, which is right now, or 21 100 UTC,

34
00:03:13.825 --> 00:03:15.445
which we've have done historically.

35
00:03:17.570 --> 00:03:22.150
I am fortunate enough to be joined here by Chris Belcher and Waxwing,

36
00:03:22.450 --> 00:03:23.750
the 2 lead maintainers

37
00:03:24.435 --> 00:03:25.254
of JoinMarket,

38
00:03:25.555 --> 00:03:29.655
the oldest and most reputable CoinJoin implementation in existence.

39
00:03:31.235 --> 00:03:35.280
And we are gonna have a great conversation focused on Bitcoin privacy,

40
00:03:36.700 --> 00:03:37.920
past, present, future,

41
00:03:38.940 --> 00:03:45.834
and and just the current state of all these tools. I think it's gonna be a very great follow-up discussion to last week's discussion we had with Open

42
00:03:46.135 --> 00:03:47.275
Arms and NoPara,

43
00:03:48.080 --> 00:03:51.380
and, obviously, plenty of previous discussions we've had on here.

44
00:03:55.095 --> 00:03:56.635
With with all that said,

45
00:03:57.095 --> 00:03:58.955
I'd like to welcome both of them.

46
00:03:59.495 --> 00:04:03.550
It seems like Chris is having some audio issues, so we will start with,

47
00:04:04.030 --> 00:04:04.530
Waxwing.

48
00:04:05.790 --> 00:04:07.090
How's it going, Waxwing?

49
00:04:08.030 --> 00:04:11.810
It's good. Thanks for having me on. This is all, scarily professional.

50
00:04:12.345 --> 00:04:13.325
I wanna say that.

51
00:04:14.825 --> 00:04:18.925
I I appreciate that. Me and the freaks have only been doing this for

52
00:04:19.705 --> 00:04:20.905
a couple months now. So

53
00:04:21.509 --> 00:04:24.169
Actually, the bottle pop was the most impressive, but yeah.

54
00:04:24.710 --> 00:04:27.210
It's the only audio effect I have in the show.

55
00:04:30.014 --> 00:04:32.675
So I think Chris can't hear us. Chris, can you hear us?

56
00:04:35.455 --> 00:04:35.955
Exactly.

57
00:04:37.320 --> 00:04:40.700
So we're gonna have him try and reset. And while we're doing that,

58
00:04:42.280 --> 00:04:45.180
I I guess, Waxwing, let's just start off with, you know,

59
00:04:45.935 --> 00:04:58.010
like, why why should the freaks care about using Bitcoin privately? Why should they care about Bitcoin privacy best practices? You know, why should they care about privacy in general? Why why are you so focused on this this aspect of Bitcoin?

60
00:05:00.550 --> 00:05:01.930
Why care about it?

61
00:05:02.475 --> 00:05:04.015
I always prefer to

62
00:05:04.875 --> 00:05:07.615
answer that question more around security. Just thinking

63
00:05:07.915 --> 00:05:10.280
about average users are not, like,

64
00:05:10.820 --> 00:05:11.880
either or massive,

65
00:05:12.260 --> 00:05:18.115
you know, massively important people or whatever. Just you're just an ordinary user. It's to me, it's mostly about

66
00:05:18.435 --> 00:05:21.574
security. And you could there's there's different flavors of security. Right? There's

67
00:05:22.035 --> 00:05:28.480
the defense against someone literally coming at you violently with a with a hammer or whatever. And there's there's also just

68
00:05:29.260 --> 00:05:30.400
like, I don't really wanna

69
00:05:31.020 --> 00:05:35.920
when I pay someone for them to know where my my money came from, it could even be like business

70
00:05:36.544 --> 00:05:39.605
business intelligence. You know, you don't want your competitors to know

71
00:05:40.065 --> 00:05:49.419
what you're doing with your money. And, of course, the other thing about privacy is don't forget, it's it's kind of intertwined with with fungibility. People often use these two terms when they're

72
00:05:49.720 --> 00:05:50.220
advocating

73
00:05:51.000 --> 00:06:10.570
Bitcoin privacy, whether it be CoinJoin or other tech. They often say, oh, we we need Bitcoin to be fungible, and that's very true. And it's it's kind of it's not the same concept, but it's a very closely interrelated concept. So, you know, essentially, at the end of the day, money shouldn't have a memory. I think that's the simplest way to to express it. But the fact that the the way Bitcoin's designed is intrinsically

74
00:06:11.670 --> 00:06:15.210
kind of not like that, at least not at a surface level,

75
00:06:16.305 --> 00:06:18.485
it creates a need for us to really

76
00:06:19.105 --> 00:06:20.965
work on this stuff. Yeah.

77
00:06:21.345 --> 00:06:26.719
I really like that money shouldn't have a memory. I feel like that should be like a a plaque on a,

78
00:06:27.020 --> 00:06:28.560
like, a housewife's wall.

79
00:06:29.659 --> 00:06:31.599
Mhmm. Yeah. One of the inspirational quotes.

80
00:06:32.355 --> 00:06:36.375
Yeah. It's a shame that we don't live in that world, but we we don't I can hear you.

81
00:06:36.915 --> 00:06:37.575
Oh, excellent.

82
00:06:38.755 --> 00:06:44.919
Chris, so we were talking about why privacy is important. I I think it's a very I like, it seems, like, so basic,

83
00:06:46.419 --> 00:06:47.620
especially in in,

84
00:06:48.740 --> 00:06:49.800
a show like this,

85
00:06:50.794 --> 00:06:55.775
discussions like this that we have on Citadel Dispatch that are that tend to to lean more technical.

86
00:06:56.555 --> 00:07:00.410
But today, I mean, I was the last 2 days, I've been called a FUDster,

87
00:07:01.110 --> 00:07:02.570
that I'm spreading FUD,

88
00:07:02.870 --> 00:07:05.290
for saying that people should be skeptical of their governments,

89
00:07:06.025 --> 00:07:15.940
and then not your keys, not your coins is a thing. Now now I'm being told that saying not your keys, not your coins is is FUD. So I think it's important that we keep coming back to the basics as we have new people join. So

90
00:07:17.280 --> 00:07:21.460
just in in your own words, why should people care about Bitcoin privacy best practices?

91
00:07:28.775 --> 00:07:31.194
We definitely lost him again. You might be muted.

92
00:07:35.940 --> 00:07:36.680
That's unfortunate.

93
00:07:38.715 --> 00:07:41.935
He's so he's so private that he we can't even hear him.

94
00:07:43.675 --> 00:07:44.175
So

95
00:07:45.115 --> 00:07:47.215
while we wait for him to come back again,

96
00:07:48.460 --> 00:07:49.759
where should we start?

97
00:07:51.580 --> 00:07:53.120
I wanna start with

98
00:07:53.819 --> 00:07:56.080
with your work on Join Market.

99
00:07:57.905 --> 00:07:58.725
You know, JoinMarket,

100
00:07:59.505 --> 00:08:01.764
when did the project start? 2015, I think?

101
00:08:03.104 --> 00:08:06.370
So Chris originally came up with the idea late 2014

102
00:08:07.390 --> 00:08:12.930
and started writing, like, a a first version of the code, I think, in December of 2014. And so it's, like, December,

103
00:08:13.390 --> 00:08:22.365
January that time. Yeah. It was interestingly, it it coincides almost exactly with the the the bottom on the looking at the price chart here. I'm just thinking about the prices

104
00:08:23.110 --> 00:08:31.290
That that January 2015 was the the sub 200 plunge, if you remember. It was kind of a special time. Yeah. How can you forget?

105
00:08:32.055 --> 00:08:32.555
Indeed.

106
00:08:33.575 --> 00:08:39.995
Okay. Looks like Chris is gonna try and rejoin. That that would be a good idea, I think. We're doing it live, freaks. We're doing it live. That's what it's about.

107
00:08:40.580 --> 00:08:41.480
So 2015,

108
00:08:42.100 --> 00:08:43.960
it was a ridiculously

109
00:08:44.340 --> 00:08:47.320
brutal bear market as you so thoughtfully recounted.

110
00:08:49.295 --> 00:08:57.170
Yes. That was a group. Yeah. Go on. It was quite a special time. Like, psychologically, I remember, like, hanging out with friends on IRC, and we were all just, like,

111
00:08:57.889 --> 00:09:08.145
sitting there. It was like, this is where the, this is where the rubber meets the road. That there there were, I'm sure there were several people who just gave up because it's just like, because don't forget, that was the end of a very long period

112
00:09:08.685 --> 00:09:15.870
of sort of comedown, you know, that we had so much may and people that forget this now because they all think about 2017, but we had a a ton of mainstream attention

113
00:09:16.569 --> 00:09:29.324
at the end of 2013 and especially the beginning of 2014 because, you know, after that spike, that's when everyone sort of caught on. And, indeed, often how it works is you get tons and tons of new users just flooding in post the spike, you know,

114
00:09:29.820 --> 00:09:36.715
because they they think, oh, this is this new thing. And they all came in, and they all just said, yeah. This is great. And then they just watched the price collapse for an entire year.

115
00:09:37.115 --> 00:09:38.575
It was absolutely brutal.

116
00:09:39.755 --> 00:09:53.400
Yeah. And I was I was sitting there thinking I I remember having more than one moment where I was thinking to myself, well, this is it. You know? I've just I'm am I gonna go down with this ship? You know, and I I I mean that in a kinda literal way because I'd given up my my job as a teacher a couple years earlier.

117
00:09:54.325 --> 00:09:57.705
And, I thought, you know, fuck it. Yeah. I am gonna go to coffee shop.

118
00:09:58.405 --> 00:10:00.745
Yeah. I'm not ashamed to say that I I

119
00:10:01.380 --> 00:10:06.040
I was not stacking I was not stacking at the bottom of that bear market. Like, I I had

120
00:10:06.740 --> 00:10:11.285
I I had decided that I was gonna go down with the ship. I would go to 0 if I had to, but I

121
00:10:11.764 --> 00:10:14.665
I was did not have that much faith. I was losing the faith.

122
00:10:15.204 --> 00:10:19.020
I did actually buy a little bit sub 200. I'm very proud of that. But

123
00:10:19.500 --> 00:10:21.180
Okay. Because I'm trying to 2 of the most

124
00:10:23.420 --> 00:10:25.600
I got 2 of the most respected privacy,

125
00:10:26.855 --> 00:10:34.475
developers on the show, and we've started it off with price talk in potential dispatch fashion. Chris, can you hear us now? Yeah.

126
00:10:35.175 --> 00:10:35.675
Chris,

127
00:10:36.440 --> 00:10:38.220
Help Chris. Come back.

128
00:10:41.640 --> 00:10:43.100
He says he's back. Well,

129
00:10:44.765 --> 00:10:46.385
he could be muted now too.

130
00:10:47.645 --> 00:10:50.225
Maybe try a different browser if you can hear us, Chris.

131
00:10:53.569 --> 00:10:54.069
So,

132
00:10:55.089 --> 00:10:56.769
Matt, losing faith. I,

133
00:10:57.490 --> 00:11:05.285
yeah. I'm telling you, the bit the Bitcoin price hit, like, 180 or something. And I was just I was a young kid, and I was, like, fuck. My dad was right. It's,

134
00:11:06.805 --> 00:11:08.985
it it was a bubble. It's all the tulips,

135
00:11:09.510 --> 00:11:09.990
and,

136
00:11:10.630 --> 00:11:17.545
and I I just I just had found solace in the fact that, you know, I wasn't gonna sell, so we're really gonna go to 0 or I was gonna be right.

137
00:11:18.024 --> 00:11:18.524
Yeah.

138
00:11:19.144 --> 00:11:22.845
But, it was definitely a very different bear market than than today's

139
00:11:23.305 --> 00:11:29.730
than than the one we had recently. But maybe maybe that's just because of experience. Maybe it's just because we I think so. Yeah. That last one.

140
00:11:30.269 --> 00:11:36.995
Yeah. I think so. I mean, time scale seem to expand out, but also the fact that if you've been through it before, it's a totally different perspective. Yeah.

141
00:11:37.454 --> 00:11:44.035
But do like, that's the meme everyone's been saying over and over that timescales span out, but they don't like, do they really? Like, I felt like

142
00:11:44.380 --> 00:11:47.200
2015 was longer and most more painful

143
00:11:47.980 --> 00:11:53.420
than than this one. Like, this one, like, March was kind of brutal, but it was a quick brutal. Right? Like, it

144
00:11:54.605 --> 00:11:59.185
I mean, I don't know. I mean, I I done quantitative analysis of it or something, but, like, in 2017

145
00:11:59.645 --> 00:12:00.145
to

146
00:12:00.685 --> 00:12:09.410
I don't know to know when when you decide when it started going up again. I don't know. But anyway, maybe not. It's just that my how it feels to me. Honestly, I think somebody hear me.

147
00:12:10.110 --> 00:12:13.010
Oh, yes. He's here. Can he hear you? Okay. That's good. Great.

148
00:12:13.944 --> 00:12:15.964
And just to check, is does this sound better?

149
00:12:16.665 --> 00:12:20.285
I think we've lost the buzz. It's a bit distorted, but we've lost the buzz.

150
00:12:20.620 --> 00:12:23.760
Honestly, we're just happy to hear you, Chris. Yeah. It's true. Yeah.

151
00:12:25.660 --> 00:12:33.135
So, Chris, Waxwing was telling everyone about how you believe that Bitcoin is designed pump forever. Do you want to elaborate on that at all?

152
00:12:37.755 --> 00:12:39.135
I think we lose them again.

153
00:12:39.900 --> 00:12:42.480
Oh. Do we lose you again? We could price talk.

154
00:12:43.900 --> 00:12:46.080
It's the price talk. He he can't stand it.

155
00:12:46.700 --> 00:12:56.255
That's the that's the best thing too that I'm I've I've been accused of of spreading FUD, and I constantly remind everyone that Bitcoin's designed to pump forever, the most effective FUD ever.

156
00:12:57.699 --> 00:12:58.199
So,

157
00:12:58.899 --> 00:13:00.839
we've had joined market since 2015.

158
00:13:02.019 --> 00:13:02.519
Mhmm.

159
00:13:03.380 --> 00:13:08.154
Lot of time lot of time you guys have been working on it. Lot of time you guys have been using it.

160
00:13:09.415 --> 00:13:18.370
What lessons what lessons have you guys learned? What what, you know, what lessons have you learned? Thoughts on on the whole process of of maintaining this this implementation?

161
00:13:21.310 --> 00:13:30.745
Well, it's it's it's difficult, but it's also fun to to work in open source software. I think it's there's something very sort of beautiful about the process. And,

162
00:13:32.520 --> 00:13:33.980
in terms of learning, like

163
00:13:35.399 --> 00:13:42.275
I mean, the thing about CoinJoin is this weird case where on the one hand, it seems like this super technical thing, and it is.

164
00:13:43.135 --> 00:13:47.955
On the other hand hear me? Oh, he's back again. Okay. Right. Sorry about that.

165
00:13:48.279 --> 00:13:49.100
No worries.

166
00:13:49.880 --> 00:13:55.740
Oh, Matt, are you there? Was that Matt? No. No. I'm here. I'm here. I'm I'm just I don't wanna jinx it. Continue.

167
00:13:56.600 --> 00:13:57.100
Yeah.

168
00:13:57.735 --> 00:13:59.275
Okay, Chris. Go. Go.

169
00:14:00.455 --> 00:14:10.430
I think I think I've learned is because joint market's based on, like, a market mechanism with the makers and takers. I've learned that you can never there's often things that you'll try to predict with the market, and then

170
00:14:10.810 --> 00:14:20.154
that you'll just be completely wrong because markets and users, they they they have their own mind. So for example, right to the beginning of joint market, we had this this kind of operation.

171
00:14:20.455 --> 00:14:22.555
Those are scripts called the patient send payment.

172
00:14:22.860 --> 00:14:33.475
And the idea was that you could be a market maker, and then you could send the coin train it, but it it would be much cheaper because you wouldn't be paying fees. And I thought a lot of people use this, and it'll be a way to,

173
00:14:33.935 --> 00:14:41.820
have more payments merged into one transaction. And then it turned out that was basically never used. So the script was broken for about a year, and nobody even noticed.

174
00:14:43.320 --> 00:14:44.780
That's interesting one that. Yeah.

175
00:14:45.160 --> 00:14:51.695
So actually, now that I've now that we have you, and let let's pull it back for a second. Can we just explain to the freaks what makes,

176
00:14:52.395 --> 00:14:57.110
join market special? How does join market work? Let's explain the maker taker function, etcetera.

177
00:14:57.810 --> 00:14:59.570
High level. The biggest part of it is,

178
00:15:00.370 --> 00:15:01.110
there is,

179
00:15:01.730 --> 00:15:05.030
obviously, Coin Joins require many people to come together in one transaction.

180
00:15:05.355 --> 00:15:14.735
And the way join markets works is that one of the one of the entities in a coin join can control things about it. They'll control the amount, and they'll control the time of when it actually happens.

181
00:15:15.050 --> 00:15:31.710
And for this privilege, they have to pay a small fee, and everyone else in the coin join is just waiting there. They wait. They have their computers always turned on, and they'll do coin joins. They basically have an advert that says, I'll do any amount of coin join at any time you want, and all I want is a fee, like a 100 associate or whatever it might be.

182
00:15:32.270 --> 00:15:37.170
Then the effects of that means if you're this taker, I. E. You take liquidity from the marketplace,

183
00:15:37.550 --> 00:15:42.014
then you can make a coin join for what whatever amount you want, whatever time you want.

184
00:15:43.355 --> 00:15:51.910
And the other people in the coin join, they'll just they'll go along with you. Like, they'll they'll earn their fee, and they don't know what the amount is. And that's the that's the unique thing that joint market does.

185
00:15:53.490 --> 00:15:55.090
And there's there's something about

186
00:15:56.024 --> 00:16:02.204
there's something to be said or highlighted about the idea of when trying to set up these systems to create a financial incentive

187
00:16:04.110 --> 00:16:09.570
to participants Yeah. To to act to act not necessarily in their best interest, but greedy. Right?

188
00:16:10.165 --> 00:16:14.745
Yeah. That's right. So historically, there was actually an earlier CoinJoin implementation called Dark Wallet.

189
00:16:15.125 --> 00:16:32.694
Right. And that was a little bit like JoinMarket, but it didn't have any fees. So people were there was also you could call them makers and takers, but the makers didn't make any money. They just they were just expected to sit there and do coin joints without, you know, leave their computer on all the time for no reason. And, of course, the problem was that there were no makers.

190
00:16:33.154 --> 00:16:37.600
Yeah. But they didn't actually make that distinction of role, did they? Because they they they were just a little there was a lot

191
00:16:38.399 --> 00:16:55.250
they called it a lobby server. And essentially, the idea was you wanna do a coin join, you make the intention, and you would be sitting on the lobby server waiting for actually, they were only doing 2 parties, so they would just wait for one other party to do a coin join. Yeah. Yeah. Did it ever actually fully launch? I think. Okay. Oh, yeah. Yeah. It was used quite a bit. Yeah.

192
00:16:56.110 --> 00:17:00.529
I remember being, like, really hyped for it and then just, like, it just the hype died.

193
00:17:01.774 --> 00:17:19.105
I remember about 3 years after it stopped they stopped updating it. Like, I had user come to me, and I had to, like, extract his coins. It it took forever. It was really but that's the thing. They just abandoned it after, like, I don't know, 6 months of development. They worked really hard on it, and they just said, no. We don't care anymore. And everyone was just left eye and right. Kind of funny.

194
00:17:19.885 --> 00:17:24.065
Yeah. That's the problem. That's one of the things we see a lot with open source software.

195
00:17:25.299 --> 00:17:29.640
I I guess if we're going down in history, right, we also had before that, we had, what, shared send,

196
00:17:30.100 --> 00:17:34.520
right, from blockchain dot info. No disclosure, no one should use a blockchain dot info anything,

197
00:17:35.405 --> 00:17:35.905
nowadays.

198
00:17:37.645 --> 00:17:53.375
Do you guys remember shared send at all? Do we wanna talk about that? Or I don't even know. Yeah. I remember, but they didn't they didn't have equal output coin joins. That's right. If you saw this coin join on the blockchain, it was impossible. In fact, really plausible, really easy to actually unmix them and say these inputs goes to these outputs.

199
00:17:53.995 --> 00:18:02.580
Except except they did actually use a pretty large anon set. So it comes back to that whole discussion about, subset some, you know, feasibility of subset some extraction.

200
00:18:02.960 --> 00:18:10.825
It was kinda interesting. But, of course, it's not a cryptographically strong concept because, you know, individual payments might be trivially easy to find even if the

201
00:18:11.365 --> 00:18:23.160
entire graph might be difficult to to to displace. It was like custodial privacy. Right? Because they you didn't they didn't force Tor or anything, so you just connected through their web wallet, and just a lot of people probably weren't even using VPNs.

202
00:18:23.780 --> 00:18:26.760
Yeah. That's true. Yeah. You had to use their web wallet to use it.

203
00:18:27.705 --> 00:18:31.965
So that's why they stopped it presumably because it became a massive liability for them,

204
00:18:32.664 --> 00:18:40.610
and it didn't work. Right? Yeah. It was speculation. Yeah. It was speculation, certainly. I speculated it. I think a lot of other people did that they were probably somebody

205
00:18:40.990 --> 00:18:44.210
sort of quietly knocked on their door and said, turn it off, and they said, okay.

206
00:18:44.795 --> 00:18:45.535
Because, you

207
00:18:45.835 --> 00:18:50.175
know, I I think it was used quite heavily in those early days. The UX was fantastic.

208
00:18:51.035 --> 00:18:52.095
Mhmm. And then

209
00:18:53.419 --> 00:18:56.960
the other and then before that and still today, right,

210
00:18:57.740 --> 00:19:02.965
probably one of the most common and it's so funny because, like, in technical communities, we almost never talk

211
00:19:03.525 --> 00:19:12.789
about it. One of the most common Bitcoin privacy tools is this idea of a custodial of custodial mixer, where you send your coins in, and they send you someone else's coins.

212
00:19:13.970 --> 00:19:24.495
Yeah. You know, Silk Road had their own. Right? And then since then, there was a bunch of independent services that popped up, like, was it, like, Bitcoin Fog and, like, BitMxer and stuff.

213
00:19:24.955 --> 00:19:25.455
Yeah.

214
00:19:26.210 --> 00:19:29.110
And the concern there was always that they could be honeypots. Right?

215
00:19:29.570 --> 00:19:43.405
Yeah. And they could steal your money as well. Like, you you'd maybe use them for small you know, if you want to buy an anonymous VPN, but you wouldn't use them in your life savings if they could just walk away with them. But then the positive side of it was it completely breaks the transaction graph

216
00:19:43.770 --> 00:19:45.710
Yeah. If you if you trust them.

217
00:19:46.730 --> 00:19:47.770
Right? Yeah. Although

218
00:19:48.090 --> 00:19:58.825
yeah. Even that's not a complete panacea, but it but it certainly in principle is is better from Blockchain analysis point of view. Yeah. Okay. So we just went down history road, enter join market in 2015.

219
00:20:00.350 --> 00:20:00.850
Right?

220
00:20:01.470 --> 00:20:08.450
Yeah. Creating creating this this market with makers and takers, this idea that you don't have to have a centralized entity involved at all,

221
00:20:09.885 --> 00:20:12.225
and that the whole thing is is p to p,

222
00:20:12.845 --> 00:20:16.385
with this financial incentive for people to provide 247 liquidity.

223
00:20:19.310 --> 00:20:19.810
Revolutionary.

224
00:20:20.670 --> 00:20:21.170
Right?

225
00:20:22.510 --> 00:20:23.330
What what

226
00:20:24.110 --> 00:20:24.610
what

227
00:20:25.470 --> 00:20:26.930
is it fair to say?

228
00:20:27.615 --> 00:20:28.515
I I think

229
00:20:28.975 --> 00:20:32.434
well, you tell me if it's unfair to say, but is it fair to say that

230
00:20:33.534 --> 00:20:34.914
that CoinJoin adoption

231
00:20:35.375 --> 00:20:36.515
JoinMarket adoption

232
00:20:37.490 --> 00:20:37.990
has

233
00:20:39.970 --> 00:20:40.610
not meet

234
00:20:41.090 --> 00:20:41.910
met your expectations

235
00:20:42.290 --> 00:20:45.590
of of what you had hoped, the amount of people, services,

236
00:20:46.050 --> 00:20:46.550
users

237
00:20:47.235 --> 00:20:48.615
would be using join market.

238
00:20:50.355 --> 00:20:55.095
Yeah. I guess in one way, you could, I way back at the start in 2016

239
00:20:55.395 --> 00:20:59.410
or wherever, I sometimes thought exchanges would do this. And the idea being that

240
00:20:59.870 --> 00:21:15.645
an exchange doesn't want its traders to be spied on. Like, if a trader sends those of coins in exchange, someone could front run them, like, you know, open a short position before they before the coins confirm. So I thought exchanges would use some kind of coin join or join market, and that never happens. Obviously, now we know,

241
00:21:16.390 --> 00:21:18.650
because the regulator stopped them. Right? So

242
00:21:19.030 --> 00:21:19.770
they went,

243
00:21:20.310 --> 00:21:21.510
they went through it for that reason.

244
00:21:22.710 --> 00:21:23.850
So, yeah, I guess

245
00:21:24.905 --> 00:21:28.605
it hasn't really met my expectation. Also, back then, I've just remembered now,

246
00:21:29.305 --> 00:21:36.679
back then, this was before the the block size debates, before people really like, the whole community really accepted the idea that minor fees were

247
00:21:37.140 --> 00:21:46.255
were like a big deal that you always had to plan for them. In fact, in the very first versions of joint market, the minor fee was a constant number. It was 10,000 satoshis, like, for every coin ring,

248
00:21:46.875 --> 00:21:50.020
just because fees were so cheap that every transaction would confirm.

249
00:21:51.040 --> 00:21:56.180
And then and because these because coin joints are bigger than regular transactions, then they they're a bit more expensive.

250
00:21:57.605 --> 00:22:04.745
So in that sense, that's maybe another reason why they haven't been as adopted as you might hope. It's not that every single transaction is a coin joint.

251
00:22:05.399 --> 00:22:06.139
I mean, it's

252
00:22:06.519 --> 00:22:06.789
been

253
00:22:07.330 --> 00:22:09.419
traders that joins and they're expensive.

254
00:22:09.880 --> 00:22:13.500
Right. The cheapest way to use Bitcoin, I've just I've I've come to

255
00:22:14.274 --> 00:22:15.654
I've come to the

256
00:22:16.755 --> 00:22:18.375
the realization or

257
00:22:18.755 --> 00:22:20.855
the understanding with myself that I think

258
00:22:21.730 --> 00:22:24.789
using Bitcoin privately will always be the more expensive option.

259
00:22:25.490 --> 00:22:29.750
Am I right? I don't agree. Because Lightning is quite private, and

260
00:22:30.405 --> 00:22:36.345
and it's also cheaper. Like, the way we Wouldn't wouldn't custodial lightning be cheaper and less private?

261
00:22:38.000 --> 00:22:39.220
Oh, purely custodial

262
00:22:39.520 --> 00:22:56.500
PayPal would be even even cheaper as well. Just a completely centralized thing where Yeah. Yeah. Okay. You're right. But if you if you away all other trade offs, then the cheapest way of using it would be to have something that can censor you, that can steal your money, and that can spy on you. Well, I was thinking more from, like, on chain because because, yeah, layer

263
00:22:57.140 --> 00:23:05.275
the 2nd layer side chain, stuff like that does change the equation a little bit. But on chain, right, even if we get if we we get we get Snore, Taproot,

264
00:23:05.895 --> 00:23:19.090
signature aggregation later, right, which is it's not even coming with Taproot, but let's say we get it later Cross input aggregation is not coming. Right. Signature aggregation and multi sig is coming, but that's Right. Right. Cross input signature aggregation. Yeah.

265
00:23:19.710 --> 00:23:20.530
If if

266
00:23:21.565 --> 00:23:27.585
even even when we get all that, on chain, the cheapest option in a high fee can sustained high fee environment

267
00:23:28.205 --> 00:23:28.705
is

268
00:23:29.370 --> 00:23:33.230
to combine all your UTXOs into a single UTXO and spend from that.

269
00:23:34.409 --> 00:23:41.024
Yeah. You could put it that way, but then you could think that's exactly what another way. Never had You could look at another way that suppose you've been censored.

270
00:23:41.804 --> 00:23:48.190
Suppose you want to use Bitcoins and you get censored, then your funds get stolen. Basically, they get frozen. You've lost a 100% of your money,

271
00:23:48.990 --> 00:24:04.135
if you put it in the custodial system. But if you then pay your own minor fees and use your own wallet that you control, you only lose 10% for minor fees. Right? So if you take into account censorship and having your funds frozen, then it might end up being more expensive to use a custodial solution.

272
00:24:05.000 --> 00:24:09.020
Right. But I'm saying not custodial. I'm saying on chain. We saw this in 2017.

273
00:24:09.320 --> 00:24:13.340
A lot of the large education accounts and stuff on on Twitter and Reddit,

274
00:24:14.115 --> 00:24:16.215
we're we're and we're suggesting that people,

275
00:24:16.595 --> 00:24:20.855
you know, combine all their UTXOs into a single into a single output

276
00:24:21.260 --> 00:24:25.600
so that their fees going forward, their fee burden going forward would be the lowest possible.

277
00:24:26.780 --> 00:24:31.295
Yeah. But can I can I just can I just say that that it's not I don't think it's technically correct to say that,

278
00:24:32.255 --> 00:24:36.355
the cheapest option would always be, non coin join because in the case

279
00:24:36.815 --> 00:24:38.115
of cross input aggregation,

280
00:24:39.390 --> 00:24:46.049
CoinJoin, you you at least save some of the the, so to speak, header bytes, the the the the constant overhead? It's a very small difference,

281
00:24:46.485 --> 00:24:58.400
but sort of philosophically, it's kind of critical. And I think one of the reasons that a lot of the, what you might call, Bitcoin gray beards have have been sort of not particularly enthusiastic about CoinJoin, but they're more enthusiastic about some future version of CoinJoin

282
00:24:58.700 --> 00:25:04.080
of the type that you just described involving Schnorr and cross and push signature aggregation because well,

283
00:25:04.605 --> 00:25:07.985
even if it's only 1¢ cheaper, if there's an economic incentive

284
00:25:08.605 --> 00:25:12.705
rather than just purely a privacy incentive, it encourages the crowd to come in.

285
00:25:14.799 --> 00:25:18.179
Right. Like, in a good example of that is is the often like,

286
00:25:18.480 --> 00:25:51.530
often floated something is is this idea that make every Lightning open a coin joint. Right? Yeah. And then Lightning opens cheaper and more private, and then you go into Lightning for forward privacy. Yeah. And also the nice thing about Lightning with CoinJoin is it it tends somewhat ameliorate or completely solve the, denomination problem, which is one of the main reasons join market was created as Chris explained earlier. The fact that, you know, it's a problem with coin joiners that you want to have equal sized outputs, but then you gotta you gotta have a negotiation agreement on what size of the output is. In the case of Lightning, you don't really care so much about what the size of the channel is.

287
00:25:52.950 --> 00:25:53.450
Yeah.

288
00:25:53.830 --> 00:25:55.610
Yeah. I I mean, I still think

289
00:25:56.535 --> 00:26:02.235
you're you're in a situation where to use Bitcoin privately, you have to make more on chain transactions than not.

290
00:26:02.615 --> 00:26:06.150
Today, that's definitely true. Yeah. Do we think that's gonna change going forward?

291
00:26:08.690 --> 00:26:10.310
I don't know. Probably not.

292
00:26:10.690 --> 00:26:21.810
It's difficult to be sure. And then I But but hang on. Hang on. I I would argue that we could say that that's true today, but only on a certain perspective. I mean, clearly, if you see Lightning as a privacy technology,

293
00:26:22.270 --> 00:26:30.654
as as not just a scalability technology, then it's clearly the case that it you you you're reducing on chain usage from using it rather than increasing.

294
00:26:31.115 --> 00:26:31.615
Right.

295
00:26:33.514 --> 00:26:38.014
And that would be true for other second layer technology in theory, although we don't really have anything

296
00:26:38.340 --> 00:26:39.320
well built out.

297
00:26:40.100 --> 00:26:41.720
Okay. But we all agree that

298
00:26:42.179 --> 00:26:51.575
so so, hopefully, we can get it cheaper than not using Bitcoin privately. But we all agree that for adoption, you know, the one of the main things is keeping costs down. Right?

299
00:26:51.955 --> 00:26:57.860
Yeah. Yeah. To get more people to use privacy. Another thing I was thinking, and I don't know if I'm just gonna throw us into a tangent, but fuck it.

300
00:26:59.780 --> 00:27:07.000
You know, today, I was arguing with people about all the the the newest hottest craze in Bitcoin land is these interest bearing accounts.

301
00:27:07.765 --> 00:27:15.544
Oh, yeah. Oh. And, you know, private Bitcoin users, Bitcoin users who care about their privacy, like, they can't get 6% interest,

302
00:27:16.929 --> 00:27:18.470
in a regulated custodian.

303
00:27:19.650 --> 00:27:20.950
So in a in a way,

304
00:27:21.730 --> 00:27:23.350
that kinda changes the

305
00:27:24.005 --> 00:27:24.505
mathematics,

306
00:27:25.045 --> 00:27:32.185
I guess, a little bit. Right? Uh-uh. It comes back to Chris's point about risk, though, doesn't it? I mean, he's pointing out that you can't think of privacy without the the concomitant,

307
00:27:33.040 --> 00:27:55.090
you know, risk of the the the cost that we are the reason I personally am not using those kind of services today is mainly because I think it's very dangerous. So if somebody says they're gonna give me 6% per annum on Bitcoin that they take from me and holding their wallet, I'm gonna think very differently than than than the case of, you know, the fiat current fiat system where I just maybe hold some stock when I never really owned it in the first place.

308
00:27:55.885 --> 00:27:58.225
I mean, but we we agree there.

309
00:27:59.245 --> 00:28:03.665
Obviously, we all agree on that. Like, I would never use that service. I tell I tell

310
00:28:04.330 --> 00:28:11.929
my audience not to use to consider the risks, like, to actually appropriately assess the risk. People don't they're not able to they're

311
00:28:13.135 --> 00:28:32.554
I but but then I'm on Twitter, you know, and I I tell people not your keys, not your coins, and they're like, it's not Mt. Gox anymore. The industry has moved up. There's it's not like it's riskless to hold your own keys. More people will lose their money if they go self custody. Yes. This time is different. Yeah. And, like, that's fine. Like, I believe that everyone

312
00:28:33.255 --> 00:28:42.330
should be able to you know, options are good and people should do what they wanna do. I'm not trying to stop anyone from doing it, but the Bitcoin privacy conversation is one

313
00:28:43.510 --> 00:28:48.410
where 61 02 is in the comments. This is also the 61 02 show because he doesn't dox his voice.

314
00:28:48.915 --> 00:28:54.695
So he joins us in the live comments. He's telling me he wants he wants the freaks to be aware that those people aren't using Bitcoin. Yes.

315
00:28:55.155 --> 00:28:57.335
Yeah. We do ideologically agree 6102,

316
00:28:58.090 --> 00:28:58.850
but I just

317
00:28:59.290 --> 00:28:59.770
it's

318
00:29:00.250 --> 00:29:02.910
the the Bitcoin privacy discussion is one where

319
00:29:04.010 --> 00:29:05.150
we we need

320
00:29:05.695 --> 00:29:07.475
we need more people to care.

321
00:29:08.095 --> 00:29:13.475
Right? Because these tools aren't effective unless we have proper scale to them. Right?

322
00:29:13.950 --> 00:29:17.809
But that's why that's why we I always come back to this concept of steganographic.

323
00:29:18.270 --> 00:29:24.425
You know, like, we we're always concerned about increasing the, anonymity set and trying to force people to use

324
00:29:24.805 --> 00:29:31.545
complicated privacy software or privacy software that's in any way inconvenient, as you correctly point out, is really problematic if you wanna increase your anonymity

325
00:29:32.005 --> 00:29:41.920
set like that. But then on the other hand, if we try to use steganographic tools, whether they be pay join or some variant of coin swap or even Lightning, because in the future, Lightning may well be steganographic on chain.

326
00:29:43.544 --> 00:29:53.720
Is everything okay? Oh, that's just the chat window. Yeah. So so He was a scammer, so I was I was blocking it. I got you. Yeah. So the thing about the steganographic is it flips that whole equation on its head. Right?

327
00:29:54.020 --> 00:30:02.025
Because, you you suddenly what you're trying to do is is hide in the crowd of people who aren't using your technology rather than hide in the crowd of people who are using your technology.

328
00:30:04.679 --> 00:30:13.019
Yeah. So making pay joins and lightning channels that look the same as other transactions and coin swaps, they do all come under steganographic technology.

329
00:30:13.480 --> 00:30:13.980
Yeah.

330
00:30:14.745 --> 00:30:16.605
Right. So should we jump into that?

331
00:30:17.225 --> 00:30:19.005
Yeah. Yeah. It's interesting.

332
00:30:20.185 --> 00:30:22.185
Let's talk about something really interesting. I think this

333
00:30:22.910 --> 00:30:29.010
so I I let's start with PayJoin. PayJoin is the lowest hanging fruit. There's been a push to try and integrate it into wallets.

334
00:30:31.215 --> 00:30:31.715
High

335
00:30:32.015 --> 00:30:40.674
high high yeah. Go on. Hit us. Did you see Electrum wallets, seems quite interested in implementing it? I think that's quite a big deal. Yeah. That was a champagne.

336
00:30:49.294 --> 00:30:50.995
To do it, that would be so great.

337
00:30:53.455 --> 00:30:54.255
I I I think

338
00:30:56.059 --> 00:31:00.960
and it's and so on the on the mobile wallet front, what we have, BlueWallet has already integrated it, I believe.

339
00:31:01.580 --> 00:31:03.040
I think they've done it. Yeah. Maybe

340
00:31:03.385 --> 00:31:12.685
there's there's a list somewhere. I think on the Bitcoin Wiki, there's a more reliable list on on the bit. They join the option list. Yeah. Maybe we could pull up that link for some for guys to look at.

341
00:31:13.145 --> 00:31:14.830
Was it on the privacy Wiki?

342
00:31:15.530 --> 00:31:22.565
They I'll find it for you. Okay. Chris is gonna get it. Yeah. Yeah. So so there's a few there's a few wallets who have at least,

343
00:31:22.945 --> 00:31:23.445
implemented,

344
00:31:24.705 --> 00:31:25.605
sender side.

345
00:31:26.145 --> 00:31:29.685
But obviously, ideally yeah. Thanks, Chris. That's it. Ideally, we want

346
00:31:31.170 --> 00:31:32.710
sender and receiver side.

347
00:31:34.530 --> 00:31:49.095
So receiver, like, in join market, we've implemented it with a hidden service. So it basically will start off an ephemeral hidden service, and you can do this in the GUI or or on the command line. And it will give you a a bit 21 URI, and you can just copy it and send it to your center

348
00:31:49.554 --> 00:31:52.470
or QR code. Just scan it, and then you can,

349
00:31:53.509 --> 00:31:55.929
then you can send the page on over to. So

350
00:31:56.309 --> 00:31:57.450
it's cool, I think.

351
00:31:58.135 --> 00:32:08.070
There is one thing with page join that should we should say with, from, like, a big picture point of view of how actually it works a bit different to equal output coin joins, like with join markets or.

352
00:32:08.690 --> 00:32:18.005
And that with those coin joins, it's about you as a user transacting with someone who might spy on you. For example, you'd you'd send a CoinJoin to an exchange, and you know the exchange will spy on you.

353
00:32:18.485 --> 00:32:24.919
But with PayJoin, it's a bit different. The way PayJoin works is it's a customer and a merchant together protect their privacy against

354
00:32:25.220 --> 00:32:25.960
other people.

355
00:32:26.340 --> 00:32:34.245
So it only works if you know the if you're a user and you know the merchant is not trying to spy on you. So probably what will happen, what I, you know, I predict,

356
00:32:35.025 --> 00:32:42.200
in the future, the people that adopt Pedro and you'll be merchants and, like, you know, businesses which are already somehow victims

357
00:32:42.659 --> 00:32:49.435
of of surveillance anyway. So that would be Bitcoin casinos or p to p exchanges or places like that or donation

358
00:32:49.975 --> 00:32:54.615
nonprofit donations. More likely to be like a smaller merchant rather than a

359
00:32:55.015 --> 00:32:56.955
Not for example, Coinbase or

360
00:32:57.279 --> 00:33:07.895
Tesla or something. It's just Coinbase. It's just Coinbase would do this. Yeah. I know. It's laughable. And you don't even you don't even really want to. Right? Because it's a trusted it's a trusted 2 party

361
00:33:08.595 --> 00:33:21.240
Yeah. Thing. Right? So, like, you're you're You might. It's it's only trusted in terms of privacy with the 2 parties. But for everyone else who just passively looks at the blockchain, it does really improve your privacy. But are are they are they sharing

362
00:33:22.260 --> 00:33:26.335
more than aren't they sharing more than one input in the coordination phase?

363
00:33:27.195 --> 00:33:33.295
Yeah. Yeah. They do. So they they the the customer and the merchant, they can mix the pay join easily, but nobody else can.

364
00:33:33.730 --> 00:33:40.789
But I'm saying when I use page join with the merchant, does that merchant only see the input I provide, or does does it see multiple inputs in my wallet?

365
00:33:41.625 --> 00:33:47.005
Well, that depends on what your wallet select. It's just it depends on what your wallet selects just like any other payment. Right? Yeah. Depends

366
00:33:47.865 --> 00:33:52.580
Right. So you're actually giving the merchant any you're not giving the other party any extra information.

367
00:33:52.960 --> 00:33:59.264
No more than you. Not more not more than a regular payment. Yeah. Right. And then on chain, someone looking at it on chain,

368
00:33:59.884 --> 00:34:01.424
it breaks the common input

369
00:34:01.725 --> 00:34:33.885
ownership heuristics. So so on chain, you can't tell whose input is what. Right? There'll there'll be 2 inputs in the usually, there'd be 2 inputs in the input side of the transaction, and one is coming from 1 per one's coming from the receiver, and one's coming from the sender, and you don't know which is which. Usually. Yeah. That's right. And that and then, of course, the crucial point there is is not just that that you wouldn't be able to untangle it, but that you wouldn't necessarily, as a blockchain analyst, even know it was a page. And that's that's the goal of the second graphic concept, you know, that we that we hope that it won't be obvious that it's a page. Now in fact, there's some little technical details there, but,

370
00:34:34.185 --> 00:34:35.645
I mean, just generally speaking,

371
00:34:35.950 --> 00:34:40.610
like, there's a there's a particular heuristic that tends to get violated in pay joins. It doesn't have to be violated.

372
00:34:41.390 --> 00:34:43.250
And but the thing is that that heuristic

373
00:34:43.695 --> 00:34:50.435
can easily and quite often is violated by normal spending transactions anyway. So without delving too much into the details, just essentially,

374
00:34:51.060 --> 00:35:02.565
it's hard to know that it's a pay join. It may be almost impossible for an outsider to know that, and it's also easy for the outside observer to be totally misled and think that the payment amount is x x whereas actually it's x minus y.

375
00:35:03.105 --> 00:35:06.525
And so that so that observer to think that 2 inputs are,

376
00:35:06.944 --> 00:35:10.440
co owned when they're not actually co owned. I'm sure, Chris will will

377
00:35:10.839 --> 00:35:13.339
will remember as well as I do the funny examples of,

378
00:35:13.880 --> 00:35:14.940
what's it called, walletexplorer.com

379
00:35:15.720 --> 00:35:17.099
that used to, like, regularly

380
00:35:17.615 --> 00:35:18.735
mark all of our,

381
00:35:19.215 --> 00:35:23.395
joint market inputs as being coming from mount or connect connected to Mt. Cox

382
00:35:23.855 --> 00:35:28.780
because, even though they were absolutely unrelated, I'd never, like, connected with Mt. Gox whatsoever,

383
00:35:29.240 --> 00:35:30.860
because the joint market

384
00:35:31.160 --> 00:35:36.075
coin joints had been joined with, people who had interacted with Mt. Gox or,

385
00:35:36.795 --> 00:35:40.734
therefore, Wall Explorer thought thought I was, you know, a Mt. Gox user or something.

386
00:35:41.275 --> 00:35:46.940
So before we move on, I I have up on the screen for the people watching on video and for the AudioFreaks,

387
00:35:47.559 --> 00:35:54.925
it it appears the software wallets that have integrated so far along this new standard is BTC pay server, join market, Wasabi Wallet.

388
00:35:55.225 --> 00:35:57.005
Wasabi is only for sending.

389
00:35:57.385 --> 00:36:00.285
Blue Wallet's only for sending. Sparrow's only for sending.

390
00:36:01.545 --> 00:36:03.805
Samurai has a has a separate

391
00:36:04.569 --> 00:36:08.270
pay join implementation that's not according to the standard that they call stowaway.

392
00:36:08.650 --> 00:36:11.069
Mhmm. And then you have Electrum listed as planned.

393
00:36:11.575 --> 00:36:16.955
Then hardware wallets, cold card's the only one who supports it because they're the only one that's Bitcoin only and actually gives a shit.

394
00:36:17.494 --> 00:36:18.395
Payment processors,

395
00:36:19.769 --> 00:36:26.349
BTC pay, because really that's the the main used payment processor. Now that's a huge huge bonus for us.

396
00:36:28.250 --> 00:36:39.030
So with all that said, let's Steelman PayJoins. What is the what are the negatives? What are the negatives of PayJoins? Why can't we just rely on PayJoins as a Bitcoin privacy all encompassing solution?

397
00:36:39.730 --> 00:36:41.830
It's interactive, and it requires a hot wallet.

398
00:36:42.130 --> 00:36:43.990
Okay. You you go, Chris. Yeah. And

399
00:36:45.235 --> 00:37:00.180
adding adding to that, there's also, people have to actually adopt it. So with with equal output coin joins, like with join market, for example, you don't have to bother the merchant to get them to adopt something new. You just pay to a regular coin address. But with PayJoin, you have to, like, nudge them, you know, if,

400
00:37:00.985 --> 00:37:11.260
which actually listeners should consider doing. If they transact with a Bitcoin casino or with something like that who they think could benefit, they should nudge them and say, look. I'm your customer. Can you adopt Pedro? And I think it'll be great.

401
00:37:12.040 --> 00:37:19.740
But the fact that you have to do this and the fact that a merchant can choose to not adopt it, like Coinbase is probably never gonna adopt it, means you could they can stop it in that way.

402
00:37:20.454 --> 00:37:22.474
Mhmm. So that would be a downside.

403
00:37:22.934 --> 00:37:27.915
What like like, explain to the freaks what interactive means, what you know, the hot wall at risk.

404
00:37:28.400 --> 00:37:32.660
Yeah. So the So that would mean yeah. You go with them. Okay. Yeah. So so that one,

405
00:37:33.360 --> 00:37:37.700
I I was thinking on the more technical level. Chris' answer is very good, but my my answer was more

406
00:37:38.005 --> 00:37:48.349
the reason why this style of coin join wasn't sort of treated too seriously as an option back in the day, like, starting from 2013 when people started discussing it on Bitcoin talk.

407
00:37:49.050 --> 00:37:56.625
I think, because this is how I thought anyway, was the oh, that's kind of messy because you have to, like, actually, in real time, negotiate

408
00:37:57.325 --> 00:38:05.019
the, the payment transaction with the receiver, which is kinda related to what Chris actually just said because the receiver has to be involved. The receiver of the payment has to be involved.

409
00:38:05.720 --> 00:38:10.215
That's it's interactive specifically in the sense that you don't just send the payment like

410
00:38:10.695 --> 00:38:14.295
like the normal let's think about the normal payment workflow. You you you have some,

411
00:38:14.775 --> 00:38:15.275
merchant.

412
00:38:15.575 --> 00:38:19.035
They, you you negotiate an invoice. They send you an address,

413
00:38:19.570 --> 00:38:20.790
as in a Bitcoin address,

414
00:38:21.410 --> 00:38:26.070
and then it's entirely up to you to take your time and use your own wallet on your own machine

415
00:38:26.744 --> 00:38:36.720
and calculate the transaction, sign the transaction, and send the transaction. And the the merchant has to do absolutely nothing. They just wait until it arrives. Whereas here, we've got to have a process whereby

416
00:38:37.260 --> 00:38:41.599
the sender actually sends a network message to the to the merchant

417
00:38:41.900 --> 00:38:42.400
and

418
00:38:44.424 --> 00:38:51.724
do stuff and then send back another mess to the sender before the sender can finally send out this specific style of pay join payment.

419
00:38:52.250 --> 00:38:58.030
So there's it's it's not a big interaction, but any interaction at all is obviously like an order of magnitude worse than no interaction.

420
00:38:58.650 --> 00:39:06.585
So because of that, that's why, for example, in join market, I had to go through a whole load of, like, testing and and figuring out how to set up an ephemeral

421
00:39:06.965 --> 00:39:20.434
Tor onion service specifically for this payment, and it, you know, fires up. Thankfully, the way Tor works nowadays I mean, that's a tangent as well, I guess, Tor v 3. But thankful thankfully, the way Tor works nowadays, it's reasonably reliable and reasonably quick to just stop a hidden service,

422
00:39:20.895 --> 00:39:26.675
and then the sender can send a message and the receiver can send a message back. So that interactivity is clearly a big negative.

423
00:39:27.090 --> 00:39:37.255
The other big negative is the hot wallet aspect specifically for a merchant. So, again, thinking of the standard model of a merchant receiving payments, and this is how it's implemented by default in BDC pay server,

424
00:39:37.875 --> 00:39:45.095
is that you are gonna use something like an x pub, and it could be like an external x pub or it could be something that BC pay server has within its own software.

425
00:39:45.450 --> 00:39:59.615
Either way, it means that when a customer comes along and tries to make a payment, you simply farm out an address to them to pay to that address, and that's all you have to do. And you don't have to worry about whether the server or the infrastructure on which you put this BTC pay server instance is as secure

426
00:39:59.915 --> 00:40:04.174
because you you're not holding private keys. You're just holding xPubs, which can go to format addresses.

427
00:40:04.520 --> 00:40:13.980
So that would be average person who knows nothing can just easily just have it just automatically go to their hardware wallet. They don't have to worry about securing the server. Most of these BTC pay servers

428
00:40:14.505 --> 00:40:18.205
are held on on major cloud providers to have uptime. Right?

429
00:40:18.585 --> 00:40:19.965
And they don't control the hardware.

430
00:40:20.425 --> 00:40:21.645
Early days of Bitcoin.

431
00:40:22.400 --> 00:40:25.700
Remember early days of Bitcoin? It's like everyone's servers were getting hacked.

432
00:40:26.240 --> 00:40:33.095
Yeah. Yeah. Yeah. So, The thing is in in kind of replying to those sort of a steel man of a steel man, the interactivity

433
00:40:33.555 --> 00:40:43.920
that's being talked about. But it's also the same thing happens for lightning. So the lightning need coins on a on a hot wallet, and it requires information being sent back and forth. Mhmm. And

434
00:40:44.775 --> 00:40:50.954
so what was the second thing you said about, if anything lightning probably has a has worse hot wall at risk in that respect.

435
00:40:51.734 --> 00:40:52.315
Mhmm. Yeah.

436
00:40:54.420 --> 00:41:05.195
Yeah. Yeah. And in in practice, people aren't gonna like to I mean, it's it's the same thing of lightning. They don't do all this stuff themselves. They have software to do it, which they have to install and click. So I have a couple other steelmans.

437
00:41:06.055 --> 00:41:06.875
First of all,

438
00:41:07.975 --> 00:41:13.220
higher fees. Pay join increases your fees. Right? Because you have more you're automatically adding an an

439
00:41:14.180 --> 00:41:18.440
from a fee perspective, an unnecessary input. Is that would we agree Well, it's it's a complex.

440
00:41:18.925 --> 00:41:24.385
True. But it is true on us in itself, but it's a kinda complicated equation because you've got to consider the

441
00:41:25.005 --> 00:41:26.785
the on the merchant side,

442
00:41:27.160 --> 00:41:38.185
it could change the nature of the distribution of their UTXOs over time because I I when when I first wrote the page, I joined, like, blog post about this. I I I explained this concept of the snowball UTXO. Like,

443
00:41:38.485 --> 00:41:38.985
essentially,

444
00:41:39.605 --> 00:41:53.940
if a merchant just used page join as if as in every payment came in with a page join and they started off with 1 UTXO, then they'd be consuming 1 UTXO every time they receive a payment as well as receiving 1. So they'd have 1 UTXO that was just getting bigger and bigger and bigger, which is in dramatic contrast

445
00:41:54.335 --> 00:41:59.635
to the merchant who, let's say, sells a 1,000 widgets every day to a 1,000 distinct customers. But doesn't that add a heuristic?

446
00:42:00.895 --> 00:42:10.015
Yes. Exactly. Whatever was discussed at the blog post, like that's actually a heuristic. And, plus, also consider the practicality of whether whether this would ever be at the point where everyone was using it.

447
00:42:10.575 --> 00:42:24.350
And and I could have kind of finished off the blog post by saying, well, that's actually great because we don't need or even really want everyone using it. If even if just 10% of people used it and it was plausible that 10% of people were using it, the effect on blockchain analysis would be so detrimental.

448
00:42:25.930 --> 00:42:26.590
But anyway,

449
00:42:27.210 --> 00:42:28.575
absolutely, it could be a heuristic

450
00:42:29.135 --> 00:42:30.595
and so could some other things.

451
00:42:30.895 --> 00:42:33.714
It it would allow it would it would allow chain analysis

452
00:42:34.494 --> 00:42:35.474
chain analysts

453
00:42:36.015 --> 00:42:38.355
to identify that a page join was happening.

454
00:42:39.060 --> 00:42:41.000
Well, not not not unambiguous

455
00:42:41.540 --> 00:42:42.120
not unambiguously.

456
00:42:42.660 --> 00:42:44.920
Yeah. Go on. Yeah. Because it's this heuristic,

457
00:42:46.235 --> 00:42:57.580
just just to get it right. So the heuristic is the things that coins get joined together until they're bigger and bigger. But that can happen with in general usage as well. Like, people combine dust together or,

458
00:42:58.060 --> 00:43:02.540
I don't know. I haven't thought about it too much, but it's possible this heuristic happens in normalization.

459
00:43:02.940 --> 00:43:04.880
Know if if you're an active attacker,

460
00:43:05.235 --> 00:43:06.535
right, a very common

461
00:43:06.835 --> 00:43:07.575
threat model

462
00:43:08.115 --> 00:43:15.980
for, like, a BTC pay server. Let's say I'm accepting donations. Right? I'm a I'm an activist. I'm I'm accepting donations. Obviously, I'm a I have a privacy focus.

463
00:43:16.360 --> 00:43:17.980
Of course, I'm gonna enable pay join.

464
00:43:19.720 --> 00:43:21.980
A common thread model there is for

465
00:43:22.840 --> 00:43:24.220
who's ever trying to,

466
00:43:25.305 --> 00:43:31.244
track you would send in an it would send in an input. Right? They would pay they would pay with PayJoint. They would see what's going on.

467
00:43:31.865 --> 00:43:32.365
Yep.

468
00:43:33.130 --> 00:43:35.309
Right? So it it'd be vulnerable to that.

469
00:43:36.569 --> 00:43:39.789
How how would like, what does the attacker learn in that situation?

470
00:43:40.195 --> 00:43:41.015
Well, the the attacker

471
00:43:41.395 --> 00:43:42.135
would know

472
00:43:42.755 --> 00:43:47.015
that every transaction that Snowball is involved with is most likely

473
00:43:47.395 --> 00:43:48.855
that that user

474
00:43:49.430 --> 00:44:03.525
that's receiving the donations' pay joins. Right? The thing is so so the attacker would see pay joins on the Blockchain, but the inputs to those pay joins, they'd be owned by different people. So, for example, one of the One input would be the snowball. Right? And the other input would be the donation.

475
00:44:04.145 --> 00:44:07.670
Right. But the attacker can't tell which is which. So the other one, which is the donation,

476
00:44:08.050 --> 00:44:10.710
like, the change of it would end up going somewhere else. And

477
00:44:11.170 --> 00:44:14.290
do you see that the two things would get merged, the the transaction drop? So

478
00:44:15.095 --> 00:44:22.394
okay. We like, if we back up a bit. So there's the activist who accepts pay joins, and he's getting many people giving him donations.

479
00:44:23.059 --> 00:44:25.559
And the attacker has also given him one small donation,

480
00:44:25.859 --> 00:44:32.645
and they can't tell whether these inputs that he sees belong to the activist or if they belong to other people giving donations to the activist.

481
00:44:34.165 --> 00:44:36.905
But wouldn't the Snowball UTXO keep getting larger?

482
00:44:37.765 --> 00:44:45.890
But they might also get larger for the other people who donated as well. Right. So so you would actually be you're hoping that the donators are also snowballing.

483
00:44:46.510 --> 00:44:48.690
It couldn't be just BTC pay server

484
00:44:49.285 --> 00:44:56.984
as long as other the other wallets would need to be snowballing as well. I think what you're really where I'm lost. Combining. It just means combining inputs.

485
00:44:57.569 --> 00:45:08.305
Right. But the first time I heard about the Snowball was, specifically on the BTC pay server side as a way to incentivize merchants to use it. So I I in my head, I was just assuming that only the merchant side was using that

486
00:45:08.845 --> 00:45:09.345
model.

487
00:45:09.885 --> 00:45:10.385
Right?

488
00:45:11.405 --> 00:45:12.125
Okay. Anyway

489
00:45:12.829 --> 00:45:18.109
it's a complicated issue, but I think, okay. Go ahead. Yeah. But okay. So to continue this deal, man,

490
00:45:19.630 --> 00:45:22.609
there's also the fact that you have 2 party coin join, which is small.

491
00:45:22.975 --> 00:45:33.640
That's Right. 2 party coin joint is small. We have a chicken in the we already kind of addressed it. We have, like, a chicken and egg kind of thing in the room that that there's less incentive for people to maybe use it in the beginning,

492
00:45:34.660 --> 00:45:39.240
but we we need it to hit a certain threshold to be effective. Right? So it's kinda like you need

493
00:45:39.700 --> 00:45:42.825
a you need, like, early ideological adopters, basically,

494
00:45:43.365 --> 00:45:49.545
which is not necessarily the end of the world. I mean, Bitcoin has kind of relied on early ideological adopters throughout its full history.

495
00:45:50.500 --> 00:45:51.640
The other thing is

496
00:45:52.980 --> 00:45:56.040
I feel like a high KYC environment kind of

497
00:45:56.500 --> 00:46:00.045
throws a wrench into our plans, you know. I I don't,

498
00:46:01.165 --> 00:46:02.145
if if

499
00:46:02.685 --> 00:46:06.145
let's use our let's use our BTC pay server as an example.

500
00:46:08.170 --> 00:46:11.950
We accept pay joins. We we have pay joins enabled on on

501
00:46:12.650 --> 00:46:14.430
Okay. On, BTC pay.

502
00:46:16.330 --> 00:46:21.135
You should send me the address. I'll try it out. Send me the address. I'll try it out. First of all, this show

503
00:46:21.595 --> 00:46:28.569
is this show is is has no sponsor content. So if if anyone enjoy we have no ads, no sponsors. It's free and open,

504
00:46:29.430 --> 00:46:34.395
in the spirit of free and open source software. So if you wanna support the show, feel free to send me some stats.

505
00:46:35.095 --> 00:46:39.195
But all that said, we have BTC pay server enabled with pay join,

506
00:46:39.690 --> 00:46:42.350
and we don't know when people pay with KYC or not.

507
00:46:42.890 --> 00:46:43.790
And and

508
00:46:44.330 --> 00:46:49.230
so so, like, KYC is, like, fucking insidious, and and I I I think there's, like, a big disconnect,

509
00:46:50.075 --> 00:46:52.815
in, like, the Bitcoin privacy community because

510
00:46:53.515 --> 00:46:55.454
we're hardliners about KYC

511
00:46:55.835 --> 00:47:01.529
versus the realities of the situation, which is, like, the overwhelming majority of participants are coming in via KYC,

512
00:47:02.390 --> 00:47:06.605
and though all those inputs are obviously bagged and tagged and put in databases

513
00:47:06.905 --> 00:47:08.845
and shared around and collated,

514
00:47:10.425 --> 00:47:17.250
and kinda break through that that veil. Right? Yeah. But that's a little bit unfair. And then the last thing is,

515
00:47:17.710 --> 00:47:18.210
like,

516
00:47:18.670 --> 00:47:21.010
is anyone really gonna be making on chain payments,

517
00:47:21.895 --> 00:47:28.955
Or, like, are we are we wasting our time a little bit with PayJoint when when most people are gonna pay with lightning at least, I think, in the near term?

518
00:47:29.819 --> 00:47:32.400
They would make payments if they're for very big amounts.

519
00:47:33.500 --> 00:47:42.305
Yeah. But even with when number go up, like lightning capacity has gone up. Now you can, like, we make a lightning pay especially if you're a privacy focus. If you're someone like Open Arms,

520
00:47:42.925 --> 00:47:48.320
who's, like, Open Arms is, like, our perfect demo, right, of a of a pay join paying person.

521
00:47:49.820 --> 00:47:58.905
Like, he can comfortably make 200, $300 payments now. Yeah. But lightning That's all but whatever the number is, it's always gonna be larger larger transfers as well.

522
00:47:59.684 --> 00:48:02.585
But that's an adoption issue. Right? Because we're trying to get 10%,

523
00:48:02.940 --> 00:48:05.680
like you said, 10% paid join adoption. Mhmm.

524
00:48:06.540 --> 00:48:16.695
And if we have we're splitting up the privacy focused users because the privacy focused users, a lot of them are gonna go to Lightning. I know me personally, like, if I spend, I prefer to spend the Lightning. It's a better UX.

525
00:48:18.320 --> 00:48:22.020
Yeah. For sure. So just Whenever this this SteelMan is

526
00:48:22.320 --> 00:48:25.125
a downside of PayJoint, is that something else might be better?

527
00:48:28.965 --> 00:48:30.505
It's it's it's it's

528
00:48:31.205 --> 00:48:33.705
I'm I'm coming from the educator perspective,

529
00:48:36.310 --> 00:48:43.210
where where I'm I'm But that's more I'm on the front lines with new users and stuff. Right? And I'm trying to increase adoption on these different

530
00:48:43.750 --> 00:48:44.250
tools,

531
00:48:44.954 --> 00:48:49.535
and so I'm just that that's the perspective I'm coming out, I guess, from this steel man of k join.

532
00:48:49.994 --> 00:49:07.395
But that's the really just a subset of that whole argument about, you know, do we need any kind of privacy tech on chain if we're just the only thing we're gonna use check the on chain for is to move on and off of lightning or second layer. And I've I've always felt like there's always gonna be a need for on chain transfers. So there's

533
00:49:07.775 --> 00:49:09.714
there is a value even if,

534
00:49:10.414 --> 00:49:16.700
it's maybe not as pure and as simple as people would like. There's gonna be a value in all kinds of coin joins because of that.

535
00:49:19.320 --> 00:49:25.035
Pay joins as as retail payments, well, then I you you your argument is more that

536
00:49:25.335 --> 00:49:37.500
Bitcoin itself is not ideal for retail payments, so, like, base low Bitcoin, and I kind of agree with that generally. But but But these are already getting pretty high. Yeah. As of today, it's still usable, but it tends to be only really valuable

537
00:49:38.174 --> 00:49:46.770
for higher higher sizes. And, like, try explaining, like, confirmation to, like, a new corner that has never fucking understood it at all in a high fee environment.

538
00:49:58.665 --> 00:50:01.965
Fucking create like, we take that for granted that we just assume

539
00:50:02.665 --> 00:50:04.045
that makes sense to people.

540
00:50:04.910 --> 00:50:05.410
Mhmm.

541
00:50:06.990 --> 00:50:14.994
Yeah. I completely agree with that. I'm not trying to say like, I I I hate the idea that I I think on chain and privacy is extremely important.

542
00:50:15.855 --> 00:50:17.634
I'm I'm not saying that's not the case.

543
00:50:18.015 --> 00:50:18.755
I'm saying

544
00:50:19.500 --> 00:50:22.079
to me, PayJoint seems more like

545
00:50:23.260 --> 00:50:31.145
and I I know Chris disagrees with me here, so I wanna dive into this. I think I think pay join seems like more of a post mix tool to me

546
00:50:32.085 --> 00:50:33.705
after, like, a coin join,

547
00:50:34.380 --> 00:50:35.039
and then

548
00:50:35.900 --> 00:50:40.480
and then Lightning also seems like a post mix tool to me. So I think I feel like pay join

549
00:50:40.859 --> 00:50:43.525
kind of competes with Lightning more than a coin join competes with Lightning.

550
00:50:54.150 --> 00:51:01.770
But yeah. No. That that's a fair analysis, I reckon, that they the the only time it would maybe make sense if it is if you're doing an on chain, very large payment,

551
00:51:02.385 --> 00:51:06.645
which therefore can't be on lightning. So I don't know. You want to gamble,

552
00:51:07.185 --> 00:51:12.005
10,000 Bitcoins or something ridiculous, then you send it via k page you into a Bitcoin Casino.

553
00:51:12.529 --> 00:51:20.710
Okay. It's not very realistic, but that would be You're Arthur Hayes or something. Yeah. But I think Exactly. You know? I I think that's to me to me, you would the issue

554
00:51:21.115 --> 00:51:32.750
issue with it was always practicality. It was never to me the issue like, oh, there isn't any point to this. Because I I my perspective is a bit different from most people in these discussions is that I tend to look at CoinJoin as very much

555
00:51:33.130 --> 00:51:34.270
this kind of opportunistic

556
00:51:34.650 --> 00:51:36.985
thing rather than some kind of rigid frame

557
00:51:37.465 --> 00:51:37.965
work.

558
00:51:39.065 --> 00:52:02.765
Like, one of the ways I've used join market open I I still do to some extent, but I tend to use Lightning more now is it it I've I've used it as like, oh, let me just make a retail payment. In the old days, it was via BitPay, but I don't use them anymore. But there's other, like, coin payments and what have you. And it was like, let's just do a coin join. And now I I'm not I have no pretense that in doing this specific coin join, I am somehow magically bit making this perfectly

559
00:52:03.510 --> 00:52:08.089
blockchain analysis resistant to, you know, constructed transaction. It's just not the case.

560
00:52:08.470 --> 00:52:15.645
But every single person that does this is is it's half a political and also half of just a kind of

561
00:52:16.265 --> 00:52:16.765
commonsensical

562
00:52:17.145 --> 00:52:20.445
thing to do is just to it's like fighting for fungibility.

563
00:52:21.240 --> 00:52:28.460
Every payment I make if I'm going to make a payment online, the first thing I'm gonna check is can I use PayJoint instead of just an ordinary payment or or join market,

564
00:52:29.775 --> 00:52:31.155
because I just feel like

565
00:52:31.535 --> 00:52:38.120
it's something that every every user and participant of the system could con could consider doing as as a way of just

566
00:52:39.320 --> 00:52:44.540
sort of not I don't fight the right way, but but just sort of asserting the right to fungibility?

567
00:52:44.920 --> 00:52:45.580
You know?

568
00:52:46.895 --> 00:53:00.130
Yeah. That's okay. It's it's the ideological. You know, Matt was talking about the ideological users from there. Yeah. But as it as it as it but but but that's almost pejorative to call it ideological because it is ideological. Yeah. Yeah. It's not a bad thing. Yeah. Ideology

569
00:53:00.430 --> 00:53:03.330
have to But but it what I'm trying to say is it's not just purely

570
00:53:03.734 --> 00:53:07.595
ideological, is it? Right? Because when I when I make a coin joint payment instead of an ordinary payment,

571
00:53:08.695 --> 00:53:14.540
I'm creating something like a part of the permanent record of Bitcoin's transaction graph, which is either less,

572
00:53:15.320 --> 00:53:15.820
disentanglable

573
00:53:16.280 --> 00:53:17.020
or totally

574
00:53:17.480 --> 00:53:19.100
not not disentanglable,

575
00:53:19.560 --> 00:53:21.180
if that's I have too many in there.

576
00:53:21.720 --> 00:53:37.780
You know, so so so so my point is is is that we we're not just being altruistic if we sit in, like, slave all way and construct these incredibly complex collections instead of just making a payment. It's not just it's not just ideological altruistic. It's it's actually creating a

577
00:53:38.240 --> 00:53:45.954
it's like a you you live in a in a housing estate, and you all share a garden and, you know, you you look after the garden a little bit because, you know, both you and everyone else involved

578
00:53:47.535 --> 00:53:54.600
will will have a happier life because of it. Yeah. I mean, not just I agree. Yeah. It's something can be ideological and self interested.

579
00:53:55.220 --> 00:53:56.600
Yes. Exactly. Yeah.

580
00:53:56.900 --> 00:53:57.400
Yeah.

581
00:53:58.875 --> 00:54:21.924
Right. So paid join to me is like one of tool you could use in your flow of everyday work. You know, I'm paying for a t shirt on this the t pay server. Oh, look. It's a page on URI. I just click that and bang. I I make that payment instead of the other one. And, yeah, I pay for 1 more. You could say the same about lightning. Right? Like, that you'll you'll if you see if you see a service offering Lightning, you go out of your way to pay with Lightning because Definitely. Yeah. Definitely.

582
00:54:22.865 --> 00:54:23.365
But

583
00:54:24.130 --> 00:54:25.270
so so so

584
00:54:26.130 --> 00:54:28.610
kind of tangential, let's unpack this a little bit,

585
00:54:28.930 --> 00:54:31.830
about talking about making a you're making a point,

586
00:54:32.395 --> 00:54:34.815
you mentioned. Making a making a

587
00:54:35.435 --> 00:54:40.015
standing your ground standing your ground and and making a visible protest,

588
00:54:40.630 --> 00:54:42.170
to the surveillance economy.

589
00:54:42.789 --> 00:54:44.569
Yeah. It's kind of weird to me

590
00:54:45.029 --> 00:54:45.529
that,

591
00:54:45.910 --> 00:54:47.690
you know, I've I've been a very,

592
00:54:49.825 --> 00:54:50.724
very active

593
00:54:51.345 --> 00:54:54.964
promoter of using CoinJoin and and using Bitcoin best practices,

594
00:54:55.744 --> 00:55:01.450
and I come up right against this whole, like, compliance culture in Bitcoin land, especially among,

595
00:55:03.510 --> 00:55:10.655
you know, for better or worse, you know, I'm a public figure. People know my face, you know, they they see me at these conferences and stuff.

596
00:55:11.275 --> 00:55:13.535
So I'm I'm literally butting heads,

597
00:55:14.635 --> 00:55:20.460
with with with these other public people that are are very compliance focused, regulation focused.

598
00:55:22.360 --> 00:55:25.545
And I got a lot of pushback about this idea of of

599
00:55:26.105 --> 00:55:27.885
trying to encourage increased CoinJoin adoption.

600
00:55:28.265 --> 00:55:30.845
And a lot of my arguments were even if

601
00:55:32.025 --> 00:55:34.444
certain CoinJoin implementations aren't perfect,

602
00:55:35.950 --> 00:55:52.015
because, honestly, like, if you're a privacy advocate and you're saying something's perfect, you're probably full of shit to begin with. But even if a user screws something up, the signaling mechanism of these coins going through coin joint and being visible on chain, I think, is super important. And we're we're seeing the ramifications of this

603
00:55:52.400 --> 00:55:54.100
with all these regulated services,

604
00:55:55.600 --> 00:56:03.355
flagging them and denying service and use of them and and, you know, we even have block file. I'll pull the graphic up again just because I have it saved in here.

605
00:56:03.895 --> 00:56:06.315
Going out of their way to specifically say

606
00:56:06.855 --> 00:56:07.355
that,

607
00:56:07.920 --> 00:56:13.700
and I think they use the word mixing instead of coin joint to insinuate more criminal intent, but that they don't accept,

608
00:56:15.040 --> 00:56:18.555
mixed funds. They don't accept anything that goes through, like, Bisk,

609
00:56:19.655 --> 00:56:22.955
peer to peer exchanges. They have this whole block list or whatever.

610
00:56:23.575 --> 00:56:25.115
So there's been, like, this weird

611
00:56:25.600 --> 00:56:26.100
element,

612
00:56:26.680 --> 00:56:27.180
and

613
00:56:27.760 --> 00:56:33.700
and and I I I love the idea of of these these demographic techniques as you said, like, things like PayJo and Coinswap

614
00:56:34.195 --> 00:56:38.695
that that are really it isn't visible on chain that they're being used and they break the heuristics.

615
00:56:39.075 --> 00:56:42.695
But this idea that, like, we should hide that we're using Bitcoin privately

616
00:56:45.230 --> 00:56:47.570
seems weird to me in a world where

617
00:56:48.030 --> 00:56:52.690
we've we've gone through the same exact argument and fight with with speech,

618
00:56:54.215 --> 00:57:01.835
and and encryption is obviously is very visible. Like, people know you're using encryption. The idea is that they can't see the message anyway.

619
00:57:03.400 --> 00:57:14.765
Right. Right? Like, what's the difference? Like, why should we be ashamed of using CoinJoin? The the fact that it's visible on chain isn't as big of a negative to me. I think it, like, falls right in line with with encryption. Does it not?

620
00:57:15.545 --> 00:57:21.244
I guess, but they, it's a method of resistance, like hiding that you're mixing helps you

621
00:57:22.010 --> 00:57:26.410
helps you get away with it in a way. So I don't know. BlockFi, they they try and block,

622
00:57:27.210 --> 00:57:33.714
they try and censor payments which are which are coin joints. And if you can if you can stop that from happening, then that's good. Right?

623
00:57:34.734 --> 00:57:41.140
But I agree with you that with the thing, I really don't understand Bitcoin as you have that thing of we shouldn't use CoinJoin. We shouldn't use

624
00:57:41.839 --> 00:58:00.410
because even if they're only interested in it for number go up, do they really think that, say, central banks who want to print loads of money, are they just gonna allow people to just move into Bitcoin? Like, of course, they won't. They'll they'll want to spy on them. They'll want to do surveillance on them. So their whole the whole plan of number go up depends on having some kind of privacy because otherwise,

625
00:58:00.790 --> 00:58:06.155
people will take, you know, they'll take your money. They'll the number go up that you won't that you earned, they'll

626
00:58:06.535 --> 00:58:08.235
confiscate it, like, in the 6102.

627
00:58:09.575 --> 00:58:11.845
Yeah. It makes no sense to me. Order.

628
00:58:12.250 --> 00:58:17.710
Yeah. Like, the the number go up and sensitive resistance have to go together. You can't have one without the other.

629
00:58:19.290 --> 00:58:32.060
Exactly. And and and and, like, let let's just go deeper into this BlockFi example, because BlockFi now is right is a darling of this fucking industry. Everyone has their hands in it. You know, there's investors all the all the big accounts on Twitter, they're

630
00:58:32.360 --> 00:58:33.980
all investors and shit in BlockFi.

631
00:58:34.280 --> 00:58:36.540
The thing is valued at, like, 2,000,000,000, $3,000,000,000

632
00:58:37.080 --> 00:58:38.700
right now. They wanna go public.

633
00:58:39.080 --> 00:58:40.220
They're offering Bitcoiners

634
00:58:40.845 --> 00:58:43.265
the ability to get 6% interest

635
00:58:43.644 --> 00:58:44.704
if they go custodial.

636
00:58:45.244 --> 00:58:46.625
They give them full KYC,

637
00:58:47.244 --> 00:58:48.865
and then on the withdrawal,

638
00:58:49.640 --> 00:58:57.740
they're not allowed to actively use Bitcoin privacy best practices. If they use active if they if they visibly use Bitcoin privacy best practices

639
00:58:58.215 --> 00:59:03.355
after they withdraw from BlockFi, not even the deposit, after they withdraw from BlockFi,

640
00:59:04.055 --> 00:59:05.675
then their account gets closed.

641
00:59:06.470 --> 00:59:10.730
That'd be like that'd be like me if I if I

642
00:59:11.110 --> 00:59:16.575
if when I withdrew money from the bank, I didn't, like, post my fucking receipt on social media,

643
00:59:17.035 --> 00:59:21.454
my account gets blocked. Like, we're not far. Oh, we're not far away from that today.

644
00:59:22.155 --> 00:59:24.174
We are not far away from that today

645
00:59:25.020 --> 00:59:26.240
with banks under each.

646
00:59:27.020 --> 00:59:27.760
But, yeah,

647
00:59:28.700 --> 00:59:30.080
how many hops? I'm curious.

648
00:59:30.700 --> 00:59:37.325
Well, that's the thing. No one can tell us. Right? Of course, they can't tell you. Right? Yeah. It's it's just like the legacy system. Right? It's like,

649
00:59:37.625 --> 00:59:40.925
you're not allowed to do money laundering or or or any of these other activities.

650
00:59:41.950 --> 00:59:45.089
So is this okay? And then they'll say, well, we can't tell you whether it's okay.

651
00:59:45.549 --> 01:00:04.700
So just deposit them deposit the money and then we'll figure out if it's okay afterwards. And we won't they they will block your account, and we won't tell you why it's blocked. It's the same bullshit, and it's gonna be the same bullshit every time. You just have to have some dignity and just say fuck fuck these people. Honestly, you're not really 6% isn't even that much. Right? I don't I don't know if if you can,

652
01:00:05.480 --> 01:00:06.140
you know,

653
01:00:07.615 --> 01:00:12.835
would you, would you invest if it was 50%, Chris? What about that? Well, at 50%, it sounds like a Ponzi scheme.

654
01:00:16.710 --> 01:00:28.245
Economic activity in the world that gives you 50% per year. So there's a golden number that you so there's a golden number that you're not gonna reveal at which you would invest in Blockfire. But if it's anywhere below or anywhere above that, you're not gonna invest in them.

655
01:00:29.345 --> 01:00:59.795
Well, when you put it that well, no. I mean, no. You've got you've got me there, I guess. The thing is is someone's privacy is quite valuable, and I wouldn't I'm just confused. The 6% isn't even that much. I don't know. It's a hell of hell of a lot better than bank accounts or or most investments nowadays. But the thing is, even if you just hold Bitcoin in a in a hardware wallet or in cold storage, it moves 6 percent all the time. Every month, it goes up or down 6%. So why are people running so quickly to the 6% thing? Well, the people who accuse me of FUD when I say the same thing want it to be clear

656
01:01:00.255 --> 01:01:07.715
that this is 6% compounded interest on top of the Bitcoin gains, and you get paid out in Bitcoin, Chris. So we can't just say 6%.

657
01:01:08.040 --> 01:01:12.840
We can't Oh, yeah. Okay. But you're already getting, like, 20% of the profit. So

658
01:01:13.880 --> 01:01:29.450
No. I'm aware that that we've we've discovered an asset that's designed to pump forever, and people are willing to throw out complete control of it, and all of their privacy for 6 percent is absolutely ridiculous. But I just wanted I wanted to be clear that I also know what compound interest is, and that does not change the equation for me.

659
01:01:30.630 --> 01:01:31.595
I think it's important that

660
01:01:32.135 --> 01:01:36.905
way. Yeah. Go ahead. Sell yourself if you're gonna sell yourself in that way, at least charge more than 6%.

661
01:01:38.340 --> 01:01:41.080
I literally had someone tell me in my comments today

662
01:01:41.620 --> 01:01:47.320
that I'm a rich Bitcoiner that's out of touch and that people need these interest payments to feed their family.

663
01:01:47.965 --> 01:01:52.385
And if I don't if if by me telling people that it's a risky investment,

664
01:01:52.685 --> 01:01:54.065
it's a risky move,

665
01:01:54.765 --> 01:01:59.540
that I'm I'm just completely heartless, and Dan Held liked that fucking comment.

666
01:02:00.480 --> 01:02:10.565
So Okay. That's what we're up against in this world. You probably already told them why that's bullshit. But, so, you know, poor people say you only had a $100 or $10. 6% is $6.

667
01:02:10.865 --> 01:02:13.045
Right? Not that much. If you have $6,000,000

668
01:02:13.585 --> 01:02:15.670
and you get 6% on that, then that's immediately

669
01:02:16.609 --> 01:02:22.070
$60,000, a huge amount. So 6% benefits rich people way more than it benefits poor people.

670
01:02:22.525 --> 01:02:26.945
Yeah. I mean, also, like, yeah, you shouldn't, like, be relying on a high risk

671
01:02:27.885 --> 01:02:41.985
interest account on top of a volatile asset to feed your children if you're gonna try and lecture me on risk risk management. Like, that's fucking ridiculous, but that's all I digress. This is my my point was, do we do we all agree that this idea that regulated

672
01:02:42.285 --> 01:02:42.785
institutions

673
01:02:43.485 --> 01:02:45.745
might not accept your Bitcoin in the future

674
01:02:46.125 --> 01:02:46.945
is a bullshit

675
01:02:47.460 --> 01:02:57.595
that that's a bullshit reason to not care about Bitcoin privacy best practices, like, just opt out of those systems. That's what Bitcoin's about. Yeah. Yeah. I get it. I I I I'm I'm gonna just disagree just for the

676
01:02:58.395 --> 01:03:00.255
like, I I I don't think the

677
01:03:00.635 --> 01:03:08.810
I I I I don't think it's bullshit in a sense that, you know, people come people are in this space and come into this space with very, very different perspectives for all kinds of

678
01:03:09.110 --> 01:03:17.255
reasons. And, they might be a bit goosed, you know, like, what exactly they're doing. They they might be think that that they're dealing with Bitcoin or actually that they're dealing with, like,

679
01:03:17.635 --> 01:03:29.480
regulated instruments on top of Bitcoin effectively because they're really just playing around with money on exchanges, you know, and then they're just playing around with, you know, their their taxes and their accountants and just and their their their their brokerage accounts.

680
01:03:30.484 --> 01:03:33.704
But, you know, it's not completely stupid for people to think,

681
01:03:34.325 --> 01:03:51.904
you know what? I'm a stand up citizen and I abhor, and I am not gonna get involved in anything that even smells slightly of you know, they're very, like, risk averse people. You know? Okay. Fine. But but they should at least understand our point of view, that that that we actually believe in this as a as a as a different system, and we

682
01:03:52.345 --> 01:03:52.845
anyway

683
01:03:53.464 --> 01:03:56.125
But, Waxwing, this is what I'm saying. Right? It's like

684
01:03:56.920 --> 01:03:59.820
is is this is when we're talking about increasing

685
01:04:00.760 --> 01:04:05.580
the pool of of privacy focused Bitcoin users, right, to try and increase

686
01:04:06.545 --> 01:04:07.685
our own privacy.

687
01:04:09.905 --> 01:04:12.565
You're you're we're up against this

688
01:04:13.585 --> 01:04:16.800
this thought process, and I I'm telling you

689
01:04:17.340 --> 01:04:17.660
that

690
01:04:18.380 --> 01:04:27.405
and I'm curious what your guys' guys' opinion here is. I know exactly what's gonna come next. What's gonna come next, and I already see it happening amongst my peer group,

691
01:04:28.025 --> 01:04:28.525
is,

692
01:04:29.865 --> 01:04:35.869
we're gonna be sold this idea, and people are gonna, I'm gonna have them. They're all gonna attack me on Twitter about it.

693
01:04:36.250 --> 01:04:38.109
We're gonna be sold this idea that

694
01:04:38.810 --> 01:04:44.915
Bitcoin privacy best practice is to spend directly from a custodial wallet because BlockFi will protect my privacy,

695
01:04:45.935 --> 01:05:00.235
and the other person the transaction graph is completely broken, and I've done nothing wrong. And my government I can completely trust my government, and they'll protect those records. And if you look it up on on chain, you won't you won't be able to tell. And and why do I make this

696
01:05:00.775 --> 01:05:04.315
expectation? Why do I have this expectation? Why do I have this conclusion? Because

697
01:05:04.855 --> 01:05:10.300
I when people pay me in Bitcoin, I chain analysis them. Right? I look back,

698
01:05:10.600 --> 01:05:21.125
and I've called people multiple times sending me money directly from Cash App, directly from strike, and I say to them, I'm like, you sent me money directly from Cash App, for a poker game.

699
01:05:21.425 --> 01:05:30.890
You send me KYC funds directly, and you know who I am. And they're like, yeah, Matt. I didn't want you to fucking know how much Bitcoin I have, so I sent it from Cash App instead of doing it.

700
01:05:32.405 --> 01:05:46.730
Oh, I see. Right. Yeah. That's what's gonna happen. That's gonna be the next narrative. The next narrative is if you have nothing to hide, if you're not a criminal, you can just send from a custodial wallet, and you'll have perfect privacy. They're gonna say perfect privacy because they don't care about disclosing trade offs.

701
01:05:47.590 --> 01:05:48.230
Well, they can,

702
01:05:48.710 --> 01:05:54.505
you can in that situation, they could send via lightning, then you would also not be able to tell how much money they have.

703
01:05:54.964 --> 01:06:03.990
Right. But if you if Yeah. If they sent if if they pay me as lightning stands right now, and, obviously, it's not at a standstill. Development's actually been moving pretty quickly.

704
01:06:04.530 --> 01:06:06.550
I have tons of respect for the developers.

705
01:06:06.895 --> 01:06:08.675
But as lightning stands right now,

706
01:06:09.295 --> 01:06:13.234
if they pay you from something like a strike or a bottle pay or something, that

707
01:06:13.935 --> 01:06:14.435
PubKey

708
01:06:15.280 --> 01:06:20.900
is is in a KYC database somewhere with the invoice, whatever you put in the invoice. So I actually had I'd

709
01:06:21.280 --> 01:06:21.780
I,

710
01:06:23.040 --> 01:06:23.540
I

711
01:06:23.895 --> 01:06:26.315
I did I did a poker game, and I was the bank,

712
01:06:27.175 --> 01:06:34.599
and I put in an invoice. I put in the invoice to keep track for my own Sovereign lightning note. I put in the invoice the guy's NIM,

713
01:06:35.700 --> 01:06:39.000
and poker. So it was his NIM plus poker. Right?

714
01:06:39.779 --> 01:06:48.655
And he paid me from strike. So strike now knows his NIM, knows we played poker, and knows my pubkey, and it's in their fucking database forever, presumably.

715
01:06:49.300 --> 01:06:50.040
No one knows,

716
01:06:50.340 --> 01:06:54.360
you know, what how what the retention is for these k y c services, but,

717
01:06:56.020 --> 01:07:07.020
like No. That's a good good point. What I what I meant was that your friend was using a custodial service for privacy reasons so that you couldn't tell how much money he had. But he could use a non custodial lightning wallet.

718
01:07:08.380 --> 01:07:12.240
That would that would also not reveal how much money he had in his wallet.

719
01:07:13.500 --> 01:07:22.025
And, yeah, you're right. If he uses, like, a custodial wallet as well, then things won't work. But I didn't realize he paid me from strike until, like, an hour into the poker game.

720
01:07:22.640 --> 01:07:29.539
Right. Right? Like, neither of us real like, there was no there's no from a UX point of view, I saw the invoice was paid. Right?

721
01:07:30.145 --> 01:07:33.745
I didn't I didn't even consider it. It wasn't even,

722
01:07:35.985 --> 01:07:38.405
I don't know. That's gonna become more common. Am I wrong?

723
01:07:39.589 --> 01:07:41.690
No. You're right, unfortunately, but

724
01:07:42.069 --> 01:07:46.970
there's people who people who for if it matters to someone, then they'll make the extra effort.

725
01:07:49.535 --> 01:07:54.975
But I don't think we should spend all our time wringing hands about the fact that people are gonna make,

726
01:07:55.375 --> 01:08:03.745
practical trade offs, including, you know, how they deal with regulators and banks and governments. I mean, they they always have done and they always will do and until there's some

727
01:08:04.145 --> 01:08:05.105
dramatic changes

728
01:08:05.665 --> 01:08:15.970
But the reasoning the reason that I bring this up is the reason I bring this up is because I think we I I think I think it's important when you're building these tools and trying to set up the incentive structures

729
01:08:16.670 --> 01:08:18.030
that that you're targeting

730
01:08:18.965 --> 01:08:25.144
you you can't just we can't just target, like, OGs that care about we can't just target, like, the 1,000 OGs that care about privacy.

731
01:08:26.720 --> 01:08:34.580
No. I don't think we're just targeting that, though. I mean I mean, look at look at the kind of thing that Open Arms is doing. I don't I don't know what what he's I know you've talked with him extensively,

732
01:08:35.040 --> 01:08:47.370
but but, you know, know, look at the he's doing it. He he's not just addressing the needs of a 1,000 OGs who are like cryptography experts. He's addressing he he is addressing people who are kind of couriers, people who like technology.

733
01:08:47.910 --> 01:08:50.330
They're playing around with things like Raspi, blitz,

734
01:08:50.790 --> 01:08:53.690
which I do as well, actually. I really like that device. It's really cool.

735
01:08:54.375 --> 01:08:59.015
But these are people who just like Bitcoin. I'm sure some of them are are relatively new.

736
01:08:59.895 --> 01:09:03.275
And, yeah, they are technically savvy much more than the average user,

737
01:09:04.290 --> 01:09:12.950
but they still like the fact that what he provides them is, like, this packaged version of join in box. They can just slap on their Like join in box. Plug in.

738
01:09:13.385 --> 01:09:19.165
Yeah. Join in box. They can just slap it into their already existing, you know, core node, lightning node, what what have you.

739
01:09:19.785 --> 01:09:27.070
Where am I going with this? Oh, yeah. The the point is, well, there's some truth, obviously, to your point, the how do we get all the masses involved?

740
01:09:28.250 --> 01:09:47.000
I have I've always been I've always had this attitude even from the early days that I always used to tell people Bitcoin is is swift, not Starbucks points, and you stop constantly, like, worrying about how you can get retail on board or whatever. Retailer always gonna do what retail do. Right? They're they're gonna use trusted third parties because that's just how people operate.

741
01:09:48.555 --> 01:09:54.655
They're all on the other hand, there are always gonna be those special people and not just people, but organizations as well. I mean,

742
01:09:55.355 --> 01:09:59.440
an example I like to give people even though it's totally fictitious is, like, the canonical

743
01:10:00.059 --> 01:10:02.719
Bitcoin user is probably a Nigerian trader

744
01:10:03.099 --> 01:10:04.960
who's sourcing products from Guangzhou.

745
01:10:05.335 --> 01:10:22.010
You know? In other words, it's not just it's not just like Joe Blogs on the street in London or or New York or whatever who's just playing around with his phone. I mean, talk to those people. There's nothing wrong with being that person. I'm just saying that isn't really what Bitcoin address is. I don't care what Satoshi wanted to use it for, vending payments or whatever, vending machines.

746
01:10:22.375 --> 01:10:24.715
The the truth is it's just not that kind of thing. It's

747
01:10:25.094 --> 01:10:28.155
much more like SWIFT. It's some very, very hard money.

748
01:10:28.855 --> 01:10:51.590
Right. It's almost financial plutonium. Like, remember people coming up to me when I was in Prague saying, no. Don't buy us in Bitcoin. I said, I I just say no. Don't buy Bitcoin. Fuck away from it. Because Right. Because, honestly, it's it's just not consumer product. Now lightning is a different story. If it gets polished enough, then maybe that's a different story. Right? I mean, in hindsight, they probably should have bought it. Right? Like, what was the price in price?

749
01:10:54.050 --> 01:10:55.190
It was near the 2017.

750
01:10:56.595 --> 01:11:15.155
It was it was like 5th 10, 15 k. Maybe they did. Yeah. Alright. I'll give it that. Literally any time in history, they should have brought me. And that's the point. They didn't deserve it unless they ignored my advice because they knew what the fuck they would do. They had their confidence in themselves to actually operate and own things like keys. That is not something ordinary people ever wanna deal with.

751
01:11:16.015 --> 01:11:17.635
I'm sorry. I know it sounds elitist,

752
01:11:18.495 --> 01:11:22.290
and maybe I'm just an asshole. It doesn't sound elitist. I'm not I'm not

753
01:11:22.770 --> 01:11:24.150
I I was trying to be provocative,

754
01:11:24.530 --> 01:11:26.950
obviously. I didn't mean there's, like, a 1,000 OGs.

755
01:11:27.970 --> 01:11:31.910
I I I'm I'm not I'm not saying, like, I need grandma to use the privacy tools.

756
01:11:32.635 --> 01:11:45.889
I'm saying, like, this show this show why do I do this show? I do this show to increase the adoption of these kind of tools and these practices and spread this knowledge. Right? And I I I want people to pay it forward. Right? Like, I I I think it's it's interesting,

757
01:11:46.590 --> 01:11:50.449
where, like, a lot of people, like, I'm not competing with other podcasters.

758
01:11:51.045 --> 01:11:56.025
I would love if there's a 1,000,000 shows that cover the same exact topic. That's when we're winning.

759
01:11:57.205 --> 01:11:59.465
But, like, we have we have,

760
01:12:00.440 --> 01:12:04.780
you know, over over 20,000 people are gonna listen to this to this discussion.

761
01:12:06.200 --> 01:12:07.420
Out of those people,

762
01:12:08.335 --> 01:12:08.835
maybe

763
01:12:09.535 --> 01:12:11.635
5,000 of them have used the tools,

764
01:12:13.375 --> 01:12:15.475
and actively use the tools. Right?

765
01:12:16.660 --> 01:12:21.160
I'm talking about getting that number up by a magnitude of 10:10 x. Right?

766
01:12:21.620 --> 01:12:31.055
Let's get that number up to 50,000 people worldwide that are that care about these tools and are using these tools. And when we talk about that, when we talk about Yeah. You're right. Crossing that chasm,

767
01:12:32.860 --> 01:12:39.599
this is what we're up against. Right? We're up against the UX of the custodial regulated products. We're up against the the

768
01:12:40.935 --> 01:12:44.155
the incentives that those products are offering their users. Right?

769
01:12:45.415 --> 01:12:58.920
Yeah. But do you envision a world where Do you envision Just if I could jump in, Wack said, because the thing you're saying, it's about, elitism. I'd actually argue it's the opposite because there's the point that Alex Gladstein made that most people in the world are actually not in the first world with,

770
01:12:59.685 --> 01:13:08.850
they're not somewhere in London, New York, and they had so someone like, in Nigeria, you mentioned the example of Nigeria. That country has a 100,000,000 population. Right? It's a third of America. So

771
01:13:09.150 --> 01:13:09.810
they actually,

772
01:13:10.750 --> 01:13:27.900
the I think Alex Gladstein put it in another way. Bitcoin is for the other 5,000,000,000 people in the world, the people who don't have good and in fact, I can point out they actually can't use BlockFi because BlockFi only accepts customers from certain places in the world. So I question. It it could be argued. It's actually not elitism. It's the opposite. It's for more Mhmm.

773
01:13:28.360 --> 01:13:34.775
There's the old cliche of Bitcoin helping people in third world countries, but you could argue it's that. People have to hold their own coins because there's nothing else.

774
01:13:35.955 --> 01:13:39.895
But this is where those other those other aspects come into play. Right? Sure. Cost,

775
01:13:40.360 --> 01:13:40.860
accessibility.

776
01:13:41.320 --> 01:13:41.820
Yeah.

777
01:13:43.240 --> 01:13:53.745
You know, if if if you're if you're in an adversarial environment in Nigeria and Bitcoin is is is borderline illegal, if not completely illegal, it's hard to have a 247 interactive,

778
01:13:55.005 --> 01:14:01.159
client available. It's it's hard to run a a VPS in general nowadays on a major cloud provider without KYC.

779
01:14:02.340 --> 01:14:17.360
Yeah. So so I think I think a good example of this might be, like, you you you see the in little experiments like they did in I don't know which South American country it was where they tried to set up a little, like, learning community thing. So what they actually end up doing, of course, is they use essentially

780
01:14:18.140 --> 01:14:21.520
yeah. Or maybe it's that. I don't remember. They they use essentially completely custodial

781
01:14:22.145 --> 01:14:26.085
versions of the tools. So it's like you you talk about the traders in Nigeria,

782
01:14:26.385 --> 01:14:45.805
that they they're constrained bandwidth wise. They're constrained cost wise. They're constrained regulatory wise, and they don't have a a solid basis of a lot of Bitcoin developers in the local area. I mean, good old Tim McMo's there, but most sadly, anybody else there who knows anything about Bitcoin. Right? So so the the the essentially, what's gonna end up happening is they go into these custodial,

783
01:14:46.265 --> 01:14:46.765
systems.

784
01:14:47.250 --> 01:14:50.869
So, unfortunately, while I agree with your point, Chris, I suspect in practice,

785
01:14:52.050 --> 01:14:56.065
while 3rd world is where Bitcoin is kind of the most useful in some

786
01:14:56.365 --> 01:14:57.825
ways, it isn't actually,

787
01:14:58.525 --> 01:15:05.969
the kind of Bitcoin that we'd like it to be. But but but just wax me, quick quickly, I mean, I don't know if you're talking about, Bitcoin Beach in El Salvador,

788
01:15:06.270 --> 01:15:07.890
but Bitcoin Beach in El Salvador,

789
01:15:08.910 --> 01:15:15.285
is is fostering this this grassroots lightning community, and they do have their own wallet. Mhmm. You were correct,

790
01:15:15.825 --> 01:15:17.445
that that is custodial,

791
01:15:18.305 --> 01:15:21.605
but it's kinda cool because it's it's locally custodial.

792
01:15:22.080 --> 01:15:32.395
Right? So, like, it's, like, the local El Salvador Bitcorders are running this custodial wallet that doesn't comply with US regulations and is completely interoperable with the wider Lightning Network.

793
01:15:32.775 --> 01:15:37.680
Maybe that is gonna be something that we see scale out. You know? That kinda makes sense to me.

794
01:15:38.080 --> 01:15:39.380
Yeah. I think so. Yeah.

795
01:15:40.480 --> 01:15:42.980
And then you don't have to worry about the pub keys. Like,

796
01:15:43.280 --> 01:15:47.060
if if if if a user and strike just so strike,

797
01:15:47.705 --> 01:15:52.845
just opened up in El Salvador, they just have bit now now they have business in El Salvador because Jack Mahler's

798
01:15:53.385 --> 01:15:57.290
fucking boss, man. Like, he flew down to El Salvador, one of the highest

799
01:15:57.930 --> 01:15:58.430
crime

800
01:15:58.970 --> 01:16:05.895
crime rates in the world. Him and Myles Suter of Cash Apps down there, both my boys are are in at Bitcoin Beach right now.

801
01:16:06.935 --> 01:16:11.115
And Wow. And strike launched in El Salvador with no banking relationship.

802
01:16:11.975 --> 01:16:18.900
And and the reason why they were able to do that is because the overwhelming amount of transactions coming from are coming from the United States

803
01:16:19.599 --> 01:16:20.099
as

804
01:16:20.400 --> 01:16:20.900
as,

805
01:16:22.755 --> 01:16:23.655
goddamn it.

806
01:16:24.275 --> 01:16:27.415
What what's the the word when you're sending money abroad,

807
01:16:29.610 --> 01:16:30.110
remittances?

808
01:16:30.810 --> 01:16:42.385
Remittance. Remittance from the United States. Right? So the United States users have they're fully regulated. They have bank accounts, and they're connected to strike, and they're sending to the custodial wallets in

809
01:16:43.085 --> 01:16:43.905
El Salvador.

810
01:16:44.525 --> 01:16:51.830
And and you and you know you know they're part of Bitcoin Beach's pilot program or whatever, but you don't know who the individual user is.

811
01:16:53.170 --> 01:16:55.875
They have their own in on an onset, basically. Right?

812
01:16:57.395 --> 01:17:03.895
So what how does the American side so the the Syrian American who wants to send a remittance or you're in American who send a remittance. You send,

813
01:17:04.640 --> 01:17:05.140
like,

814
01:17:05.440 --> 01:17:15.845
a a a card payment or a or a fee let's say a fee payment to strike, and then it gets sent over lightning to the El Salvador. Your debit card you hook up your debit card or

815
01:17:16.305 --> 01:17:19.685
you hook up your debit card or bank account to strike,

816
01:17:20.890 --> 01:17:21.390
and

817
01:17:22.170 --> 01:17:23.150
you you

818
01:17:23.450 --> 01:17:26.990
it's k it's considered KYC lite because what he did was

819
01:17:27.465 --> 01:17:29.325
he had a he has a partnership

820
01:17:29.945 --> 01:17:30.685
that basically

821
01:17:31.225 --> 01:17:36.525
allows you to put in your phone number, and if the KYC infos already exists, you don't have to reenter it.

822
01:17:37.530 --> 01:17:41.790
So so you still have full KYC, but at least friction wise, it's reduced.

823
01:17:42.890 --> 01:17:45.790
And then you actually never see Bitcoin. So

824
01:17:46.225 --> 01:17:53.364
you can just scan any lightning invoice, and he'll automatically do the conversion in the behind the scenes, and the receiver receives Bitcoin.

825
01:17:53.740 --> 01:17:59.520
And the reason it's set up that way is it provides him regulatory cover because he never has to

826
01:17:59.900 --> 01:18:01.040
custody Bitcoin,

827
01:18:02.605 --> 01:18:09.345
And Yeah. It provides the user Right. A a a a pro tax way of spending Bitcoin

828
01:18:09.760 --> 01:18:24.945
because the users never actually buying Bitcoin and then spending the Bitcoin and incurring capital gains. They're just Right. They're they're just processing this transaction in the background and using Bitcoin as the rails. The receiver receives Bitcoin. So it's it's become very, very popular among

829
01:18:26.390 --> 01:18:27.930
mainstream Bitcoin Twitter,

830
01:18:29.830 --> 01:18:30.630
but it's,

831
01:18:31.670 --> 01:18:39.875
That's why I haven't heard of it. But it leaves yeah. So waxwing to the freaks to the freaks that are aware, waxwing's the first guest on the show

832
01:18:40.495 --> 01:18:45.860
who really truly cares about privacy and and and boycotts and boycotts Twitter.

833
01:18:46.240 --> 01:18:50.100
We have a bunch of freaks that are listening to this through Twitter. I'm sorry. So,

834
01:18:50.800 --> 01:18:52.580
props to you for doing that, waxwing.

835
01:18:53.315 --> 01:18:54.614
You can find them on Mastodon.

836
01:18:56.835 --> 01:19:00.535
But, yeah, is that it's an interesting dynamic that is that is has

837
01:19:01.155 --> 01:19:02.695
exist that exists now,

838
01:19:04.020 --> 01:19:11.480
and and a lot of people are using that. Yeah. Jack gave a talk about it on, Jack Miles gave a talk about it on, in our in our little

839
01:19:12.005 --> 01:19:18.105
army. I think you you came a few sent you to our v army top. Yes. And it was kind of interesting to me. My eyes started to hurt.

840
01:19:18.565 --> 01:19:39.641
Okay. Yeah. My eyes hurt sometimes after a while. Yeah. It's funny that. And also Facebook. Fuck Facebook. Right? Like, I was using Oculus or whatever, and they started requiring the account, so I just had to make a difference. That's really shitty. It's even worse when you look under the hood of what they're doing there. It's really horrible, I think. But, anyway Yeah. Facebook's the one I got rid of my account a long time. Do you see that Zuck

841
01:19:40.044 --> 01:19:44.075
the the Facebook accidentally got hacked for 533,000,000 users' accounts

842
01:19:44.635 --> 01:19:48.415
information, and they they use that to realize that Zuck is using signal,

843
01:19:48.795 --> 01:19:51.615
which is hilarious. Oh, that's cool. On WhatsApp.

844
01:19:53.980 --> 01:19:54.800
That's cool.

845
01:19:55.900 --> 01:19:56.880
Yeah. I I

846
01:19:57.739 --> 01:20:03.285
it's it's the the strike phenomenon is is very interesting, and it that's

847
01:20:03.905 --> 01:20:04.405
that's

848
01:20:05.185 --> 01:20:14.220
it's a it's an awesome product. It's really pushing it's pushing the tears, but this that's kind of where I come from when I say that that's what we're up against. Because you're you're trying to convince the user

849
01:20:14.760 --> 01:20:18.940
to to spend Bitcoin privately rather than using a service like that

850
01:20:19.525 --> 01:20:20.345
a lot of times.

851
01:20:20.965 --> 01:20:41.825
Yeah. I think it realistically is gonna be second, and it is gonna be semi custodial. I think both of those things that's that's the good outcome. I mean, the worst outcome is everyone just decides that they just wanna use Bitcoin as, like, an investment stuck in a regulated financial institution and nobody has Did you see ever. Did you see what Taylor posted the other day that got, like, 7,000 likes and fucking

852
01:20:43.085 --> 01:20:44.465
amazing amount of retweets?

853
01:20:45.699 --> 01:20:50.328
I mean, I know waxwing did see it, but did you see it? He he tweeted out

854
01:20:51.219 --> 01:20:51.880
the name?

855
01:20:52.865 --> 01:20:55.285
Michael Taylor. Do you not know who Michael Taylor is, waxwing?

856
01:20:55.825 --> 01:21:08.380
Oh, yeah. I do. Yeah. Oh, no. I do. I just I didn't hear that the connection was bad. Oh, I did follow him, but, yeah, did he say he bought what did he buy? Like, he bought more Bitcoin from something. Oh, no. No. Not that. He tweets that out every 2 weeks or whatever.

857
01:21:09.160 --> 01:21:23.610
He tweeted out that the ideal the ideal Bitcoin wallet is a wallet that's a custodial wallet where you send Bitcoin in, and it automatically provides you a fiat based loan on it, and then you pay with fiat. And then that way you never incur capital gains,

858
01:21:24.870 --> 01:21:26.570
and you never have to sell your Bitcoin.

859
01:21:28.575 --> 01:21:32.835
Well, he's wrong because the central banks will just steal your Bitcoin in that case.

860
01:21:34.335 --> 01:21:38.610
Look, I'm I'm not saying that that I know you're not We disagree.

861
01:21:39.390 --> 01:21:39.890
Right?

862
01:21:40.990 --> 01:21:47.974
But that's what we're up like like, you're competing when you're talking about increasing from 5 1,000 to 50,000 users.

863
01:21:48.755 --> 01:21:52.375
Right? You're you're competing against that, like, that those concepts.

864
01:21:54.114 --> 01:21:55.335
Do we agree on that?

865
01:21:57.140 --> 01:21:58.280
Well I agree. Yeah.

866
01:22:00.660 --> 01:22:02.660
I don't know what to think about. Be in trouble,

867
01:22:03.140 --> 01:22:04.600
when there's a bear market.

868
01:22:05.014 --> 01:22:11.675
I'm gonna pull it up for you. When the price goes up. I'm gonna pull it up for you guys. Yeah. I I think you're interested. You don't believe me?

869
01:22:12.119 --> 01:22:21.260
No. Of course. Believe that it is a No. Of course, I believe that because I heard him say something's I heard about him say something similar before. Like, some months before he said something about it. It's all, you know,

870
01:22:21.639 --> 01:22:22.765
you it should all be regulated

871
01:22:23.225 --> 01:22:25.645
and forget about privacy. Yeah. He's He has crazy.

872
01:22:25.945 --> 01:22:27.565
It has a 1,000 retweets.

873
01:22:27.865 --> 01:22:32.240
I have you ever come close to getting a 1,000 retweets on something?

874
01:22:33.100 --> 01:22:37.600
That's crazy. That's that that's this is consensus opinion. Look at this.

875
01:22:39.644 --> 01:22:40.125
Right.

876
01:22:41.405 --> 01:22:46.144
Well, maybe it's bots. You never know. This is not smart. Oh, wait.

877
01:22:46.490 --> 01:22:48.910
Wait. Wait. Wait. Wait. He says the ideal mullet.

878
01:22:49.450 --> 01:22:56.110
I wanna qualify. Is this the ideal mobile wallet? Well, I don't know. Maybe he's right because the ideal wallet certainly isn't on a mobile phone.

879
01:22:57.195 --> 01:22:59.215
Well, oh, do you wanna unpack that?

880
01:23:00.395 --> 01:23:06.720
Well, of course, it's not the most secure way. I mean, if you're dealing with large amounts, you you would you would be crazy to to hold it on a phone, surely.

881
01:23:07.580 --> 01:23:10.800
But if we're talking if we're talking about the other 5,000,000,000,

882
01:23:11.580 --> 01:23:22.915
the other 5,000,000,000, most of them don't have computers. They have cell they have cell phones and they have Well, that's just comes back yeah. That just comes back to the discussion we were just having. Right? Which is, like, how is it actually gonna play out in 3rd world type environment.

883
01:23:23.230 --> 01:23:24.989
And it will I'm sure it will be at least

884
01:23:25.710 --> 01:23:31.650
I'm sure it will you know, I the the the positive outcome is that there's a lot of usage of semi custodial

885
01:23:32.205 --> 01:23:33.985
Bitcoin like the example you give from

886
01:23:34.285 --> 01:23:36.785
which I think is a really interesting and cool example.

887
01:23:37.805 --> 01:23:47.559
And it's gonna be on phones because phones are the devices that those people have, and it's gonna be something which respects stream bandwidth limitations because bandwidth is very expensive in those places

888
01:23:48.179 --> 01:23:48.760
and unreliable.

889
01:23:49.765 --> 01:23:59.520
So we just gotta face up to the reality there. You know? It's all very nice to think of satellites and stuff, and it's all cool, but and there will be some nodes. But god, I remember back in the early days when you used to look on the,

890
01:23:59.980 --> 01:24:04.320
the maps of, like, where all the nodes were in the world. You'd look at Africa, and there'd be, like, 2 nodes

891
01:24:04.625 --> 01:24:05.925
on the entire continent.

892
01:24:06.864 --> 01:24:11.364
It's just it's just terrible, really, but I don't think it's gonna get much better, at least not quickly.

893
01:24:12.940 --> 01:24:14.240
Sorry. I'm I'm woofing.

894
01:24:14.780 --> 01:24:17.820
No. I think this is this has been a great conversation so far.

895
01:24:18.220 --> 01:24:20.720
We haven't even talked about coin swaps yet.

896
01:24:23.085 --> 01:24:27.105
I I just before before we move on, I just want to,

897
01:24:30.660 --> 01:24:32.360
on on on a on a bigger sense,

898
01:24:32.660 --> 01:24:37.400
what do you guys think? Like, do you feel a sense of urgency in terms of Bitcoin privacy?

899
01:24:38.065 --> 01:24:40.465
Do we have all the time in the world or should we

900
01:24:40.945 --> 01:24:43.445
is it is it important that people care right now?

901
01:24:43.824 --> 01:24:47.105
Yeah. I think it's quite urgent because every every month you get more,

902
01:24:47.730 --> 01:24:50.390
for example, more services which block coin joins.

903
01:24:52.449 --> 01:25:02.915
Yeah. I think it's so every yeah. The more the more this goes on, the more information the the surveillance people get. And the KYC is just going farther and farther. Right? It's just like

904
01:25:04.440 --> 01:25:05.100
I don't know.

905
01:25:08.200 --> 01:25:08.700
Okay.

906
01:25:09.960 --> 01:25:13.325
So so we kind of talked about current Bitcoin privacy.

907
01:25:15.385 --> 01:25:20.850
Let's move on let's move on to the future. Let's let's oh, oh, no. No. No. We're not moving to the future. Sorry, freaks.

908
01:25:22.830 --> 01:25:26.370
Last last discussion we had on civil dispatch last week,

909
01:25:27.535 --> 01:25:29.795
there was some confusion about civil attacks.

910
01:25:32.335 --> 01:25:32.835
Arguably,

911
01:25:33.215 --> 01:25:34.835
civil attacks are

912
01:25:35.440 --> 01:25:36.980
the number one threat model

913
01:25:38.240 --> 01:25:40.980
for users that are trying to use Bitcoin more privately.

914
01:25:41.840 --> 01:25:45.755
Do you guys want to explain I guess, we'll start with Chris. You wanna explain,

915
01:25:46.135 --> 01:25:48.715
like, what what a Sybil attack is?

916
01:25:50.580 --> 01:25:53.719
Maybe we'll talk about Fidelity Bonds really quick. Are you talking about

917
01:25:54.260 --> 01:25:59.400
yeah. I I suppose you're talking about civil attacks for joint markets. So that would mean where,

918
01:26:00.014 --> 01:26:12.970
now with with joint markets, anyone can be a maker. They just put Bitcoins in a in a bot in the wallet and then start it up and it'll become a maker. And a civil attack would be when there's an adversary who create the 10 or 20 or 50 bots,

919
01:26:13.510 --> 01:26:17.690
and has all of them on into the order book, and they all create coin joints. And

920
01:26:18.005 --> 01:26:22.264
if a you if a user is unlucky, they'll coin join, but only with these Sybil users,

921
01:26:22.724 --> 01:26:24.264
only with these Sybil makers.

922
01:26:24.645 --> 01:26:26.985
And then they would get a coin join, but

923
01:26:27.320 --> 01:26:31.420
because all the all the other all the other people in the coin join would actually be the same person,

924
01:26:32.200 --> 01:26:33.900
their coin join could be easily unmixed.

925
01:26:35.160 --> 01:26:36.140
Now the way,

926
01:26:36.635 --> 01:26:45.000
so that's called a Sybil attack because it comes from it comes from that there was someone who had, like, a mental disorder where she had multiple personalities, and she was called Sybil. Her name was Sybil.

927
01:26:45.380 --> 01:26:47.159
That was actually her name. Something like that. Yeah.

928
01:26:47.460 --> 01:26:48.199
Like Sybil

929
01:26:48.500 --> 01:26:49.560
Johnson. I don't know.

930
01:26:50.020 --> 01:26:53.425
Right. Now the way the thing I'm I'm working on right now is

931
01:26:54.224 --> 01:26:54.625
a thing

932
01:26:55.344 --> 01:26:57.684
the idea is called Fidelity Bonds, which is where

933
01:26:58.304 --> 01:27:09.080
in joint markets and in in Coins Swap later, you'd have makers would also have the option of putting coins into a time locked address. For example, they could lock up their coins for 1 year or 6 months or something,

934
01:27:09.485 --> 01:27:13.264
and that's kind of like a sacrifice. You can you can precisely work it out mathematically

935
01:27:13.565 --> 01:27:25.460
how much they've sacrificed in value to lock up coins for a year or 2 years. And then takers, joint market takers, would be programmed to preferentially choose makers which have a more valuable fidelity bond.

936
01:27:26.640 --> 01:27:27.140
So

937
01:27:27.665 --> 01:27:32.804
the effect of that would mean if someone then wants to do a Sybil attack, they have to sacrifice much more value.

938
01:27:33.665 --> 01:27:38.910
I've done the I've I've got some calculations on this that if if kind of the honest order book sacrifices

939
01:27:39.370 --> 01:27:45.565
1 Bitcoin worth of value, then a similar attack would have to sacrifice about 60 Bitcoins worth of value to to

940
01:27:45.945 --> 01:27:50.445
be successful at attacking. Because the idea is the idea is is that

941
01:27:50.985 --> 01:27:54.940
the with with with the Sybil attack is is is where

942
01:27:55.720 --> 01:28:04.885
the the goal when in privacy focused Bitcoin is is to be amongst a crowd. A Sybil attack in its most extreme form is that the whole crowd is a single attacker.

943
01:28:05.264 --> 01:28:17.260
So if if we're talking about fighting Sybil attacks, the plan should be to make it so that an attacker has to spend more than an a so called honest actor, someone acting in good faith. And with Fidelity Bonds

944
01:28:17.715 --> 01:28:20.455
with fidelity bonds I just like to interrupt that 606102

945
01:28:21.155 --> 01:28:29.699
made the same joke that I was gonna make that they they sacrificed 6% a year. Right? Right. Of course. It's it's important to remember that the civil attacker is sacrificing 6%

946
01:28:30.160 --> 01:28:40.824
per year. But also, the honest actors also sacrificing 6% per year. Compounded annually in Bitcoin. It's important that we remember that we're not funding it, and that it is compounded annually and paid in Bitcoin.

947
01:28:41.910 --> 01:28:42.410
But

948
01:28:42.950 --> 01:28:51.370
the the the the idea with Fidelity bonds is if you spread out your Bitcoin among multiple maker positions,

949
01:28:51.895 --> 01:28:56.395
that's gonna cost you significantly more money than if you just do one large maker position.

950
01:28:56.775 --> 01:28:57.275
Right?

951
01:28:59.560 --> 01:29:00.300
Yeah. Exactly.

952
01:29:02.200 --> 01:29:05.260
And coming back to the the 6% per year idea,

953
01:29:05.640 --> 01:29:07.580
you could think of this as a way to

954
01:29:07.915 --> 01:29:13.455
earn income from your Bitcoins without I mean, join market already has this. You can earn an income from your Bitcoins without

955
01:29:13.755 --> 01:29:22.440
having without having to give up your Bitcoins. So they stay in your wallet, and you don't have to give up any KYC information, and you earn money from them. But you're on Hot Wallet. Because, like, from the

956
01:29:23.355 --> 01:29:36.140
yeah. And from the point of view of someone who's doing this, like an investor, you could call it, in a way, it competes with the BlockFi thing. So the thing that the effect that Fidelity Bonds would have is they'll make the joint market system more capital intensive.

957
01:29:36.600 --> 01:29:45.135
Like, it would require more Bitcoins to be involved. And from, like, from financial principles, you could expect that then the yields that the interest people could earn would go upwards.

958
01:29:46.450 --> 01:30:02.035
So once for and to put short, once Fidelity bonds added to join market, market makers, if they have loads of money, could earn more money. But let's still manage a little bit. First of all, the fees are are basically nothing right now. Right? Like, you're not really making any money being a maker.

959
01:30:02.810 --> 01:30:04.170
That that that's that's definitely

960
01:30:05.130 --> 01:30:12.784
I mean, that's definitely true, but never forget that there is, like, a a kind of edge case because the at the very larger sizes, that isn't really as

961
01:30:13.165 --> 01:30:27.250
true. Like, the the Right. If you're special, there's not that much competition in the major Exactly. Right. For the larger. But but Generally, it's true. If if if we got taker usage up, those fees should go up, and and the maker should be able to make more money. Do you agree on that?

962
01:30:28.565 --> 01:30:33.385
Yeah. Generally, you know. Like, would we would we agree that, like, the the the biggest

963
01:30:33.764 --> 01:30:41.670
the biggest example that adoption of join market is unfortunately lower than what we were hoping for is that the fees are still pretty low.

964
01:30:42.290 --> 01:31:17.500
Right? Well, I mean, you can just scan the chain and look for quantitative measures. The reason the fees are low is that everyone who can everyone who wants liquidity can easily find it. That's why there's Right. Because we don't have enough we don't have enough takers. But if we had more takers if we had more takers, the fees should go up. Right? Yeah. That's so that would be the the demand side. But also, that's the supply side in that. Right. I think there's loads of Bitcoins out there just sitting in cold storage, not doing anything. And if fees went up even a little bit, then many of those Bitcoins would move out from cold storage into this, and that would make sense. The weird thing about join market

965
01:31:18.360 --> 01:31:22.645
the weird thing about join market is the UX is is, in my opinion,

966
01:31:23.745 --> 01:31:29.205
good enough. It's easy enough to use for someone who is is savvy enough to try and be a maker,

967
01:31:29.670 --> 01:31:30.170
but

968
01:31:30.550 --> 01:31:32.810
but could use work on the taker side

969
01:31:33.270 --> 01:31:46.485
to get, like, more, you know, mainstream users in. But on the maker's side, like, they have an incentive to just figure it out and and Yes. And then just to go back to my previous provocative example, like, you only really need, like, the a1000

970
01:31:47.040 --> 01:31:50.179
dedicated ideological OGs on the maker side,

971
01:31:50.960 --> 01:32:00.445
and and they can figure out the US. On the taker side, we we kinda need taker adoption to go up and then the and the fees should go up at that point. But but wait. I think there's a danger here

972
01:32:00.745 --> 01:32:05.070
that that people have attended to look at the market and say, oh, the market's wrong. You know?

973
01:32:05.630 --> 01:32:12.210
The way I try to explain this in the past is that that there's many, many costs and benefits to add in to the to the system. So

974
01:32:12.565 --> 01:32:13.605
on the on the,

975
01:32:15.045 --> 01:32:15.864
maker side,

976
01:32:16.244 --> 01:32:21.945
there are benefits such as the the passivity means you don't have to make decisions. The fact that you,

977
01:32:23.190 --> 01:32:24.250
you you get,

978
01:32:24.710 --> 01:32:25.210
privacy

979
01:32:25.510 --> 01:32:35.545
while you don't spend Bitcoin network transaction fees, which are which are usually the larger by far of the 2 components of fee is the is the Bitcoin network transaction fee.

980
01:32:35.845 --> 01:32:48.220
So the unusual thing you know, like, if you came at the joy market from the point of view of something like Wasabi, you you understand that or at least the first anyway. Yeah. The the taker's, like, bearing that entire cost and distributed among all the participants.

981
01:32:49.165 --> 01:32:55.585
So there's several, I mean, advantages the taker gets such as being able to choose an exact size. Go go ahead.

982
01:32:56.230 --> 01:32:59.750
But the takers, it's it's considerably a taker and joy market is

983
01:33:01.030 --> 01:33:06.495
a taker and joy market is considerably cheaper than Wasabi. Everything out everything equal. Wasabi's

984
01:33:07.275 --> 01:33:10.255
Wasabi's coin joint fee is dramatically high.

985
01:33:11.275 --> 01:33:11.675
It's like

986
01:33:12.960 --> 01:33:16.980
like, it it you you save a ton of money if you're a taker in your market. Yeah.

987
01:33:17.840 --> 01:33:22.175
But even the network fee, the network fee is a 100 inputs or whatever. Sorry. Continue.

988
01:33:23.835 --> 01:33:55.220
No. But but that has to be distributed. I I okay. Let me just go through because I wanted to make a quick list of all of, like Go through it. To work out what the the price of of of joint market usage is. Because because if you're the if you're the taker, you get several, like, distinct advantages. You're able to choose the exact time at which you do it, and it goes through quickly. You're able to, choose the exact size of the payment, which means you can make a payment in a coin join if you want. You're able to and the second advantage of choosing the exact size of the payment is the crucial one, which is it allows you to do something called a sweep, which means you get no change.

989
01:33:55.895 --> 01:34:03.275
Another advantage you get, which if you compare it to, like, other CoinJoin implementations is you could do any size, including very large sum principle.

990
01:34:03.910 --> 01:34:10.475
So there's a lot and the and, of course, the biggest, maybe the most crucial advantage that the taker gets is that you're supposed at least, assuming there's no bug,

991
01:34:10.875 --> 01:34:18.575
it's supposed to be the case that you don't reveal any information about your inputs and outputs to the other participants in the whereas the maker doesn't get that advantage.

992
01:34:19.920 --> 01:34:24.500
So there's all these advantages. On the other side, it has the advantage of, well, I'm not paying any network transaction fee,

993
01:34:24.800 --> 01:34:27.220
and I can just leave it runnatively and,

994
01:34:27.695 --> 01:34:44.380
a couple of other things I can't remember. But but the point is that there's many different, like, components of cost and benefit to play in. And the fact that it works out the most of the time, we're talking about, like, tens to hundreds of sats for coin joint fee. Only if you'd go to larger sizes does that price get significantly larger.

995
01:34:45.005 --> 01:34:52.065
It's just it's just the result of all these, like, difficult to measure factors. And I I totally agree, by the way. None none of this is to disagree with what Chris just,

996
01:34:52.605 --> 01:34:53.824
expounded on fidelity

997
01:34:54.210 --> 01:34:55.590
bonds as it would add

998
01:34:56.050 --> 01:34:59.030
a much stronger anti civil effect, which means that,

999
01:35:00.130 --> 01:35:06.905
most likely or almost certainly, the prices will go up because the quality of what's being offered is gonna be is gonna be higher.

1000
01:35:07.365 --> 01:35:08.345
But I would also

1001
01:35:08.805 --> 01:35:13.980
mention because I I wanted to mention this because I think it earlier podcast is that when we had this bug recently,

1002
01:35:15.080 --> 01:35:21.260
well, we could talk about the bug if you like. But but the thing is We could talk about that. But Okay. We'll we'll talk about it in a minute. But I just wanna say that,

1003
01:35:22.365 --> 01:35:27.345
people do have 1 and you specifically, I think, perhaps have forgotten a rather, important,

1004
01:35:27.725 --> 01:35:34.240
change that was made to join market as a system about, I don't know, 2 years ago. I can't remember exactly when, which is that the,

1005
01:35:35.420 --> 01:35:39.675
it's slightly less it's significantly, I would say, less syllable than it used to be

1006
01:35:39.994 --> 01:35:41.215
in as much as,

1007
01:35:42.554 --> 01:35:43.934
you don't have the situation

1008
01:35:44.235 --> 01:35:53.360
where somebody can simply of the lowest possible fee and just almost automatically get chosen. Because it was kind of sort of like that in the early days where there was another exponential.

1009
01:35:54.220 --> 01:35:59.520
Well, it was it was kind of an exponential distribution giving too much weight to the very lowest fees.

1010
01:35:59.885 --> 01:36:05.105
And all that we changed was we made it so that without going to huge amount of detail, we made it so that,

1011
01:36:05.565 --> 01:36:10.280
when a taker comes along, he doesn't just aim for the very lowest fees possible, but he aims for

1012
01:36:10.580 --> 01:36:26.469
any random fees within some reasonable range, which gives him a much broader set of potential participants to choose from. I'll just put that down. Let's just talk so so yeah. I mean, that's massive. That's very important when we're talking about the threat model with Joy Mark. Right? So so

1013
01:36:27.170 --> 01:36:31.750
the reason I bring this up, first of all, is that, I mean, people should do their own research.

1014
01:36:32.445 --> 01:36:41.550
Fucking people say that too much in this space. People should listen to the the the last conversation we had with No Power and Open Arms. But No Power just, like,

1015
01:36:42.730 --> 01:36:47.395
is extremely frustrating when you start talking about sibling. Right? Because because it

1016
01:36:47.935 --> 01:36:50.035
when we're talking about actively seeking

1017
01:36:50.495 --> 01:36:54.835
privacy when using Bitcoin, we're talking about very well funded actors,

1018
01:36:55.720 --> 01:36:57.900
that are very secretive in what they do.

1019
01:36:58.200 --> 01:37:04.540
And I'm talking about the chain analysis of the world. I'm talking about the Elliptics of the world, and I know their founders listen to this show.

1020
01:37:06.555 --> 01:37:07.615
Elliptic, especially,

1021
01:37:08.475 --> 01:37:10.015
like, Tom, I know you're listening.

1022
01:37:11.035 --> 01:37:17.100
I appreciate that you're you're very upfront with what you do, to a degree, but everything is very secretive.

1023
01:37:17.640 --> 01:37:24.205
And if we're talking about them and we're talking about threat modeling them in an active an attempt to actively

1024
01:37:24.745 --> 01:37:26.205
seek privacy in Bitcoin,

1025
01:37:26.985 --> 01:37:29.645
the threat model is is that they're gonna try

1026
01:37:30.260 --> 01:37:30.920
and flood

1027
01:37:31.619 --> 01:37:42.465
our usage. Right? And in in joint market in joint market, we're talking about them being multiple makers. Right? They're gonna be multiple makers, and they're gonna offer very low prices.

1028
01:37:43.005 --> 01:37:49.489
Mhmm. Right? And they're gonna try and be as in as many of of your make arounds as possible. Do we agree on that?

1029
01:37:50.909 --> 01:38:04.815
I don't know if we agree that it actually is happening, but it certainly No. I'm not saying it's happening. We don't know what's happening. That's the crazy part. Right? Yeah. Is that we're talking publicly, but they're not talking publicly about this shit. So we don't know if it's happening or not. But the if they were to attack joint market

1030
01:38:05.170 --> 01:38:07.750
from a Sybil scenario, that's how they would do it. Right?

1031
01:38:08.849 --> 01:38:15.844
Yeah. They would do it on the maker side. Yeah. Right. And that's what Fidelity Bonds is trying to solve is, like, is is is so that it becomes

1032
01:38:16.545 --> 01:38:18.965
way more expensive for them to be multiple makers

1033
01:38:19.905 --> 01:38:23.284
Yeah. Yes. Than than be a single maker. Right?

1034
01:38:25.320 --> 01:38:29.820
But Yep. But if they're a regulated entity like chain analysis,

1035
01:38:31.094 --> 01:38:32.074
can't they just

1036
01:38:33.415 --> 01:38:34.395
can't they just

1037
01:38:34.855 --> 01:38:40.670
reduce that that fidelity bond risk? The idea is that that you have such a large Fidelity Bond

1038
01:38:40.970 --> 01:38:44.670
that you have this massive price risk. Right? You have to lock up Bitcoin,

1039
01:38:44.970 --> 01:38:48.030
which is nice because first of all That's not right.

1040
01:38:48.955 --> 01:38:53.775
Well, so what what Right. The exchange rate risk doesn't come into this. What comes into this is that,

1041
01:38:54.395 --> 01:38:58.540
in the maths of it is that, the the value of your fidelity bond is

1042
01:38:58.840 --> 01:39:06.415
the amount of Bitcoins you have squared. So for 5 Bitcoins, it would be 5 times 5 is is 25. If you have 6, it's 6 and 636.

1043
01:39:06.795 --> 01:39:10.975
And that means people are trying to to lump up their Bitcoins into 1 bot.

1044
01:39:12.449 --> 01:39:29.705
Right. But Right. There probably is a risk where it doesn't come into the analysis of it. Like, you know, you can analyze proof of work to see how it works. Right. But you're I mean The way this thing there's a there's a strong incentive for someone to lump up their Bitcoins into 1 bot rather than if they spread it out over many different bots, then they have a disadvantage, a strong disadvantage.

1045
01:39:30.110 --> 01:39:37.570
But if I recall correctly if they if Chainalysis is doing this, they would they would have to it ends up working out. They'd have to own, like, a $100,000,000

1046
01:39:38.110 --> 01:39:40.355
worth of Bitcoins or something. Right. Right. So

1047
01:39:40.895 --> 01:39:43.395
which is significantly less than Michael Sailor owns.

1048
01:39:44.255 --> 01:39:49.090
They can just borrow they can just borrow on BlockFi. Right? That that's what I'm saying. Right? But that's exactly what I'm saying.

1049
01:39:49.710 --> 01:39:54.369
Can they just can't they just if they're a regulated entity, they don't care about privacy.

1050
01:39:54.909 --> 01:39:57.969
They can borrow this shit. They can hedge it with shorts.

1051
01:39:58.335 --> 01:40:05.635
They can do all these different things. Right? And and and and the cool part about Fidelity Bonds is that it's not a hot wallet, which is awesome.

1052
01:40:06.500 --> 01:40:07.000
Yeah.

1053
01:40:07.700 --> 01:40:09.800
Right? I'm I'm correct on that. I recall correctly.

1054
01:40:10.420 --> 01:40:21.875
Yeah. Which is awesome. So you don't have hot wallet risk. So, really, what you have is capital risk. Right? You have you have to you have to own this much Bitcoin and Bitcoin's a volatile asset, which is kinda nice

1055
01:40:22.210 --> 01:40:30.550
in terms of a trade off if you're a Bitcoiner, which is the same trade but it's the same trade off it's it's on a high level, it's the same trade off as

1056
01:40:30.905 --> 01:40:33.005
trying to actively surveil lightning.

1057
01:40:33.385 --> 01:40:39.645
In that, they have to force number go up if they try and they have to, like, literally buy Bitcoin and own Bitcoin.

1058
01:40:40.790 --> 01:40:55.295
Right? Yeah. So that's so just to add in, you're right. Exchange rate risk is one thing, but a bigger like, the the kind of way I analyze it, that it's a big cost there is opportunity cost. So if they put all this money into Bitcoin, it means they haven't put it into some other

1059
01:40:55.755 --> 01:40:56.255
investment.

1060
01:40:57.680 --> 01:41:02.340
That's the that's how you work out things in financing. It's called the cost of capital.

1061
01:41:02.640 --> 01:41:05.220
Right. But they can just if they're a regulated entity,

1062
01:41:05.545 --> 01:41:07.965
if they're chain analysis and they're valued at $2,000,000,000

1063
01:41:08.744 --> 01:41:12.205
and their former chief counsel is now the head of FinCEN,

1064
01:41:12.850 --> 01:41:15.590
Like, they can just hedge that risk on CME

1065
01:41:16.449 --> 01:41:23.445
and just take out a short in Bitcoin equivalent amount, and then they have no they have no opportunity cost whatsoever, really.

1066
01:41:24.225 --> 01:41:25.925
Yeah. Fine. That Right?

1067
01:41:27.105 --> 01:41:39.295
So they'd pay interest on the the thing they're borrowing. You're right. So, yeah, those short positions have a cost of carry. Right. Right. They have they have a carry cost. But they're making up for it in their, like, 200,000, 400,000

1068
01:41:39.675 --> 01:41:43.135
fees that they're charging, all these exchange that that's their business.

1069
01:41:45.650 --> 01:41:49.910
Right? Right. So you're right. The kinda stepping back a second. This all this works if,

1070
01:41:51.490 --> 01:42:04.520
if people all this works in the sense that it costs a lot of money to attack it. So if the attacker does already have money, then it won't work. So you're right about that. It's the same with Bitcoin mining. If someone spends less of money on miners, then they can do a 51% attack.

1071
01:42:06.260 --> 01:42:08.280
Right. But with mining, it's a little bit different.

1072
01:42:09.220 --> 01:42:11.000
Because mining, you have, like,

1073
01:42:12.265 --> 01:42:19.805
with mining, you have, like, physical you have to get physical chips, which right now, by the way, there's a massive shortage, which is why we haven't seen

1074
01:42:20.210 --> 01:42:29.510
difficulty go up with price. Like, you can't get ASICs right now. And then you actually have to, like, plug them into to power. You know, you have to actually have power wherever you're located.

1075
01:42:31.925 --> 01:42:32.985
If buying a $100,000,000

1076
01:42:33.285 --> 01:42:35.305
worth of Bitcoin on the open market

1077
01:42:35.765 --> 01:42:37.685
and then staking it is not that

1078
01:42:38.650 --> 01:42:42.750
I mean, it's difficult for us, but it's it's not that difficult for a

1079
01:42:43.290 --> 01:42:46.270
a a company that's valued at $2,000,000,000 that just raised a $100,000,000,000,

1080
01:42:46.810 --> 01:42:47.949
like, 2 weeks ago.

1081
01:42:48.975 --> 01:42:56.515
My intuition about this is is is like I have 2 comments on it. I mean, it's first of all, it's, first of all, it's good analysis both from both of you. But but the

1082
01:42:57.290 --> 01:42:59.550
very glibly nowadays are talking about a $100,000,000

1083
01:42:59.850 --> 01:43:00.350
figure

1084
01:43:00.810 --> 01:43:07.755
because Right. The maybe when when when Chris first started writing a few Python to create joint marketing, we weren't thinking about a $100,000,000

1085
01:43:08.535 --> 01:43:09.755
attackers on our system.

1086
01:43:10.215 --> 01:43:15.035
And the second comment is, like, I have got this strong intuition, which may turn out to be totally wrong,

1087
01:43:15.390 --> 01:43:17.570
but the people who do this kind of an analytical

1088
01:43:18.510 --> 01:43:20.290
work are gonna be very

1089
01:43:21.390 --> 01:43:23.410
leery about committing engines

1090
01:43:23.775 --> 01:43:38.280
to these kind of sibling. It's I I it just says a little anecdote, and I don't think it's real, but it gives you a kind of flavor of it. That in late 2016, when we were experiencing this kind of a different kind of sibling attack, we might call it a snooping at some joint market where,

1091
01:43:39.060 --> 01:43:43.320
a bunch of people were coming along as as takers, not makers, coming along as takers,

1092
01:43:43.844 --> 01:43:45.145
starting the negotiation

1093
01:43:45.525 --> 01:43:50.905
of coin points and then stopping in order to try to collect UTXO information from makers. Right.

1094
01:43:51.330 --> 01:43:58.310
When when we implemented a defense against that, which basically consisted of a kind of a souped up commitment that forced

1095
01:43:58.875 --> 01:44:05.935
takers to, at some point in the negotiation, reveal their own and reveal that they'd never been used before for this kind of commitment.

1096
01:44:06.560 --> 01:44:14.180
It basically meant that if somebody wanted to continue doing that attack, they would have had to keep revealing new UTXOs to us, like in the 1,000.

1097
01:44:15.145 --> 01:44:28.580
And I I I I'm guessing that the the reason they stopped is not because it costs much, but because they just that's just not a thing you wanna do as an attack. Now maybe if you're chain analysts, you, a, are prepared to spend 100 of 1,000,000 of dollars on this, and, b, are prepared,

1098
01:44:29.040 --> 01:44:36.275
to reveal, like, on chain UTXOs to that you're doing this attack. But I suspect probably they're not prepared to do that. Just a suspicion.

1099
01:44:38.340 --> 01:44:43.000
Yeah. I I It might be right, but they they could turn around and they might do it. Like,

1100
01:44:43.940 --> 01:44:45.560
my kind of point of view is

1101
01:44:45.935 --> 01:44:51.635
you know, that old saying, if you want peace, prepare for war. But I'd imagine what to do in a in, like, the worst possible situation.

1102
01:44:52.335 --> 01:44:55.155
Right. We should assume worst case scenarios. Right?

1103
01:44:55.840 --> 01:44:56.340
Yeah.

1104
01:44:56.880 --> 01:45:10.535
But I I think there's a strong there's still a strong analogy between Bitcoin mining and how if you have a lot of money, you can attack Bitcoin and these Fidelity bonds where if you have a lot of money, you could attack joint markets. And if if your attacker just has loads of money, there's nothing really you can do.

1105
01:45:11.210 --> 01:45:16.110
I mean, I think at scale, we can defend against it just because, you know, Bitcoin will

1106
01:45:16.490 --> 01:45:19.310
increase in value so much, so they get cost prohibitive.

1107
01:45:20.795 --> 01:45:23.935
But in the short term, I mean, there's there's a massive advantage.

1108
01:45:24.395 --> 01:45:30.550
If if if there is a a chain in a a chain surveillance firm, it's important we call them what they are.

1109
01:45:31.329 --> 01:45:34.550
If there's a surveillance firm, a very competitive industry,

1110
01:45:35.010 --> 01:45:35.510
arguably,

1111
01:45:36.365 --> 01:45:37.345
the 2 industries

1112
01:45:37.725 --> 01:45:39.585
the 3 industries in Bitcoin

1113
01:45:40.045 --> 01:45:44.945
sub industries in Bitcoin that make the most money are the regulated exchanges, completely captured,

1114
01:45:45.540 --> 01:45:47.080
the chain surveillance companies,

1115
01:45:47.380 --> 01:45:51.160
completely captured by design. They capture people. And then,

1116
01:45:52.180 --> 01:45:54.200
and then these fucking lending services,

1117
01:45:54.915 --> 01:46:00.775
that are offering you 6% for custody of your coins, and and you're never gonna get those coins back out, presumably.

1118
01:46:02.034 --> 01:46:03.735
Those are the 3 most valuable

1119
01:46:04.370 --> 01:46:06.550
tranches in in Bitcoin land.

1120
01:46:07.170 --> 01:46:08.710
If if you're talking about,

1121
01:46:09.410 --> 01:46:13.510
I'm I'm a regulated institution or I'm the IRS or I'm the DEA

1122
01:46:14.035 --> 01:46:18.055
or I'm the CIA, and I'm trying to decide who I give the $15,000,000

1123
01:46:18.755 --> 01:46:19.735
contract to.

1124
01:46:21.330 --> 01:46:25.750
The firm the the surveillance firm that is unwinding joint market

1125
01:46:27.170 --> 01:46:30.630
compared to the firm that isn't unwinding joint market is way more valuable

1126
01:46:31.155 --> 01:46:32.055
from a subscription point of

1127
01:46:32.435 --> 01:46:32.935
view.

1128
01:46:34.355 --> 01:46:53.615
One interesting thing of that point is that if 2 firms at once try to attack joint market, then they stop each other from working. Right. So if you had an American firm and a Chinese firm both doing the civil attack, they they'll be half the the coin joint makers at every point. Right. Yeah. We wanna encourage as many of them to attack as possible. Yeah.

1129
01:46:54.155 --> 01:47:06.210
So America and China and Russia and North Korea or whatever, they all need to agree to, like, together do a similar attack, which might be possible, but it's also maybe that geographical arbitrage could also help us.

1130
01:47:06.865 --> 01:47:19.780
Notice how the kind of openness of this kind of system works in its favor here. The fact that we by design, we don't have any, like, identification of users, and we don't have any centrally controlling entities. So it's very amorphous.

1131
01:47:20.080 --> 01:47:20.820
I often

1132
01:47:21.335 --> 01:47:30.560
try to tell, like to tell people, which I have no idea if it's true or not, is, like, there could be another joint market trading trading pit out there that nobody knows about or that some people know about and I don't.

1133
01:47:31.680 --> 01:47:35.860
The the nature of open source software is kind of really helpful in this, and and and just

1134
01:47:36.160 --> 01:47:40.815
just generally using Tor and just not using it. But, of course, the flip point is exactly

1135
01:47:41.195 --> 01:47:45.670
why why we have so much difficulty in having to come up with very complicated or

1136
01:47:46.070 --> 01:47:46.570
sophisticated,

1137
01:47:47.110 --> 01:47:50.969
defenses against things like Sybil is for the same reason that we we explicitly

1138
01:47:51.590 --> 01:47:53.610
reject the concept entity in the system.

1139
01:48:00.015 --> 01:48:00.575
Yeah. Yeah.

1140
01:48:01.215 --> 01:48:01.715
So

1141
01:48:02.410 --> 01:48:05.290
that that was very awesome. That was a great discussion, guys.

1142
01:48:06.570 --> 01:48:10.430
I don't know if that discussion has happened publicly before. I don't think so.

1143
01:48:11.815 --> 01:48:13.675
Happened on IRC, I think.

1144
01:48:14.295 --> 01:48:18.615
So so yeah. IRC. All the good ones happened on IRC. So I Everything

1145
01:48:19.265 --> 01:48:19.700
see.

1146
01:48:20.980 --> 01:48:21.480
I,

1147
01:48:23.180 --> 01:48:27.320
I mean, the the reason I I I keep harping on it is because, specifically,

1148
01:48:28.215 --> 01:48:29.835
chain analysis has gotten

1149
01:48:30.615 --> 01:48:33.355
they've they the the company chain analysis,

1150
01:48:34.695 --> 01:48:37.035
the surveillance company chain analysis

1151
01:48:37.690 --> 01:48:38.430
has gotten,

1152
01:48:40.330 --> 01:48:49.575
is is by far the largest in the space. They're the elephant in the room, followed second, maybe I we we got 61 or 2 in the comments by Coinbase who has their own,

1153
01:48:50.355 --> 01:48:52.615
chain technology now, the chain surveillance

1154
01:48:53.075 --> 01:48:53.575
firm

1155
01:48:54.200 --> 01:48:56.540
within Coinbase, like their own tool

1156
01:48:56.840 --> 01:48:57.740
within Coinbase.

1157
01:48:58.120 --> 01:49:01.500
And and and, presumably, Coinbase itself is holding

1158
01:49:02.744 --> 01:49:03.645
over 15

1159
01:49:04.824 --> 01:49:05.324
1,500,000

1160
01:49:06.025 --> 01:49:06.505
Bitcoin,

1161
01:49:08.425 --> 01:49:10.525
because because we know they have

1162
01:49:10.869 --> 01:49:11.369
about

1163
01:49:11.670 --> 01:49:12.889
900 bit 900,000

1164
01:49:13.190 --> 01:49:14.730
Bitcoin of customer funds,

1165
01:49:15.349 --> 01:49:18.969
in proper Coinbase, and then Coinbase Custody at least has GBTC,

1166
01:49:20.455 --> 01:49:21.755
which is, like, another 800,

1167
01:49:22.535 --> 01:49:23.675
uh,000 coins.

1168
01:49:24.295 --> 01:49:26.715
So so we know that they're at least holding,

1169
01:49:27.510 --> 01:49:37.614
about 1a half and, like, the sailors of the world and stuff are all going to Coinbase Custody. So they they are holding a a ton of coins. They have a ton of users. They're going public. They have their own chain surveillance.

1170
01:49:37.994 --> 01:49:39.454
So it is kind of,

1171
01:49:41.994 --> 01:49:54.345
aggregating to single actors. Right? And and and as that happens, that centralization in the chain surveillance space, that hurts us, as you said. Like, I agree on that. Like, we we actually want it'd be better if we had multiple active attackers,

1172
01:49:55.445 --> 01:49:59.385
when you when you started to throw them all this up. But but all this said,

1173
01:50:01.679 --> 01:50:09.540
strictly, it's I think it's it's super important. We're we're an hour and 50 minutes in. I appreciate you guys' time. I think it's super important for us to to

1174
01:50:09.865 --> 01:50:12.365
to pull this back that if you're actively

1175
01:50:13.145 --> 01:50:18.190
trying to use CoinJoin, trying to use Bitcoin best practices, you're you're strictly in a better

1176
01:50:24.830 --> 01:50:26.050
sibling these things.

1177
01:50:27.355 --> 01:50:41.290
You're you're strictly better off, and you should you should use it. That's part of the solution, and it's very important that people use these things, but it's it's also very important that we openly discuss these concerns. These are the threat models. These are the the threats that we're trying to work against.

1178
01:50:42.070 --> 01:50:43.370
So with all that said,

1179
01:50:43.725 --> 01:50:47.825
where where are we going in the future? What what do we have to look forward to as Bitcoiners?

1180
01:50:50.125 --> 01:50:54.810
I think Chris We already talked about PayJoint. Coin swap at this point at this point at this point.

1181
01:50:56.949 --> 01:50:58.409
Let's talk about coin swap.

1182
01:50:59.270 --> 01:51:00.710
Okay. Yeah. So,

1183
01:51:01.885 --> 01:51:04.784
as as you may have seen, I've, I've released a version

1184
01:51:05.485 --> 01:51:07.824
of it that works on test net and chest.

1185
01:51:08.284 --> 01:51:17.910
And it doesn't have all the features, but it can do multi hop and multi transaction coin swaps. So they are you could think of that as like coin join, like an on chain privacy technology,

1186
01:51:18.265 --> 01:51:23.565
but it's it looks like a regular transaction kind of. Although right now has a multi sig. It has a 2 of 2 multi sig.

1187
01:51:23.945 --> 01:51:24.025
And,

1188
01:51:24.905 --> 01:51:27.180
you could someone could use that to mix their coins.

1189
01:51:27.820 --> 01:51:47.449
Now the reason I'm doing the reason I'm right now working on Fidelity bonds on joint market is partly to improve joint market, but also partly to kind of get used to the idea to have it sort of out there in the wild as an experiment of people actually using it to see if the Fidelity Bonds idea works and if there's anything that can be improved on it. And after that's done, then I'll go back to working on coin swap,

1190
01:51:47.989 --> 01:51:52.650
to make it to carry on work and get it towards so that it works on main net.

1191
01:51:54.065 --> 01:51:55.045
Okay. So I think,

1192
01:51:55.745 --> 01:51:58.565
yeah, that that's, that's where I am at right now.

1193
01:51:59.105 --> 01:52:01.284
We have we have public final void,

1194
01:52:02.130 --> 01:52:03.750
talking about getting blacklisted

1195
01:52:04.290 --> 01:52:05.829
off of exchanges again,

1196
01:52:06.369 --> 01:52:07.349
on the chat,

1197
01:52:08.530 --> 01:52:11.750
and and disagreeing that you're better off using CoinJoin.

1198
01:52:12.215 --> 01:52:15.595
Look, if if you wanna, we said this earlier, but just to recap,

1199
01:52:15.975 --> 01:52:19.755
like, if if if you want to be a part of the surveillance economy,

1200
01:52:20.370 --> 01:52:23.270
by all means, you know, keep it in the same address,

1201
01:52:24.130 --> 01:52:25.190
maybe use custodial

1202
01:52:25.650 --> 01:52:31.885
custodian option. I don't fucking know. Like, if if you wanna practice all the best practices in terms of regulatory compliance,

1203
01:52:32.345 --> 01:52:38.270
by all means, proceed with that. But when we're talking strictly from a privacy point of view,

1204
01:52:38.810 --> 01:52:39.949
using these tools

1205
01:52:40.650 --> 01:52:44.670
are are net benefit. I mean, you shouldn't use them thinking that they're perfect.

1206
01:52:45.244 --> 01:52:54.864
I don't want you guys, like, making mistakes and assuming that you're completely anonymous. Like, that'd be horrible. I don't want that. But but strictly from a privacy point of view,

1207
01:52:55.310 --> 01:52:57.970
attempting to use these tools, using these tools is gonna

1208
01:52:59.950 --> 01:53:14.780
is is you're in a better privacy situation than if you don't do it otherwise. I mean, they're they're cataloging everything you do when you use these regulated institutions. They have they have your personal information. They have every financial transaction you're making. It's all getting recorded on a ledger that's gonna exist forever.

1209
01:53:15.320 --> 01:53:20.300
This ledger is gonna exist forever. It's all gonna be there. Even if you don't fuck things up now,

1210
01:53:20.680 --> 01:53:24.935
even if you don't realize you fucked things up now, that can come back to haunt you in 10 years.

1211
01:53:26.515 --> 01:53:27.495
Back to Coinswap.

1212
01:53:30.890 --> 01:53:32.030
Chris, Coinswap

1213
01:53:32.810 --> 01:53:33.310
is

1214
01:53:34.730 --> 01:53:38.909
is same concept as PayJoint in terms of being a steganographic,

1215
01:53:40.775 --> 01:53:42.395
strategy, right, to break heuristics.

1216
01:53:43.735 --> 01:53:47.675
Yeah. Yeah. That's the end of it. The the end of it, it would look just like a regular

1217
01:53:48.190 --> 01:53:51.090
transaction or more than one regular Bitcoin transactions.

1218
01:53:51.550 --> 01:53:55.410
So so both both the pro and con of using Coinswap

1219
01:53:55.870 --> 01:53:56.370
is

1220
01:53:58.315 --> 01:54:04.255
that on chain, the user the the anyone looking at the chain should not be able to know it's a Coinswap. Right?

1221
01:54:06.110 --> 01:54:07.730
Yeah. That's the that's the aim.

1222
01:54:09.230 --> 01:54:13.409
And then then the the if we steel man it, right, the negative is is

1223
01:54:14.625 --> 01:54:17.605
you might be accused of something that's not you you're doing.

1224
01:54:19.025 --> 01:54:21.125
That's right. But that's the same for pay join.

1225
01:54:21.440 --> 01:54:22.340
Like, you could,

1226
01:54:22.800 --> 01:54:32.655
you could have a pay you could accept pay joins and then someone pay joins you who got their coins from like, they stole them, you know, their their theft coins. And then people come to you

1227
01:54:33.115 --> 01:54:35.775
and say, oh, why do you have theft coins coming to have the

1228
01:54:36.155 --> 01:54:42.200
the the the theft coins were cospent with your money in this transaction. So why are you does does that mean you stole the money?

1229
01:54:43.140 --> 01:54:45.400
It's true that any kind of privacy technology

1230
01:54:45.700 --> 01:54:47.285
could bring heat on you,

1231
01:54:47.845 --> 01:54:49.625
and I don't know. People just

1232
01:54:50.485 --> 01:55:03.410
they'll have to deal with it. Like, in some countries, just using Bitcoin is against the law. Right. I mean, let let's talk like proper compliance pros. Right? Like, it doesn't have to be a theft transaction. Like, you could use Coinswap, and you can swap with someone who use CoinJoin,

1233
01:55:04.505 --> 01:55:08.605
Or or you can use PayJoint and they use CoinJoin, and it looks like you use CoinJoin.

1234
01:55:09.864 --> 01:55:11.085
Right? Yeah. Exactly.

1235
01:55:11.545 --> 01:55:16.030
Which is once again, like, if we go back, is a bullshit negative. Right?

1236
01:55:16.969 --> 01:55:19.469
Could could could we, I think long term

1237
01:55:20.250 --> 01:55:21.150
oh, go on.

1238
01:55:21.965 --> 01:55:23.824
I'm curious. I think long term,

1239
01:55:24.445 --> 01:55:28.784
the one possible outcome is that the KYC Bitcoin world and the kind of privacy,

1240
01:55:29.164 --> 01:55:34.920
self custody Bitcoin world split off and that it'll be that it won't be very common that coins go between them.

1241
01:55:35.460 --> 01:55:37.480
Do we think that's, like, happening right now?

1242
01:55:38.500 --> 01:55:41.565
I don't think it's gonna go like that. I mean but,

1243
01:55:43.545 --> 01:55:54.270
can I can I ask a question about CoinSoft? Because we've, like, started talking about it, and I I think they do. Yeah. Let yeah. Your listeners might might might want to hear more. Yeah. I was like you guys did an episode between you guys, and I just sat here at 5.

1244
01:55:55.290 --> 01:55:58.030
No. I just wanna say, like, so first of all,

1245
01:55:58.525 --> 01:56:08.270
maybe you could I'm gonna I'm gonna ask you a question in 2 parts, Chris, because I know you can answer them. The first question is, what is the basic idea of a coin swap? No no need to go into great detail, but what is the basic idea of

1246
01:56:10.270 --> 01:56:20.255
coin swap? And the second question is, how do you address in this concept that we've just talked about of it being secondographic, like, you couldn't tell it was a coin swap on chain, how do we address, like, the amounts of the two sides being equal?

1247
01:56:23.675 --> 01:56:28.180
Oh, right. Okay. So the the first thing of what a coin swap is, it's a way of,

1248
01:56:29.380 --> 01:56:30.280
it's a noncustodial

1249
01:56:30.580 --> 01:56:36.760
privacy protocol. So how it actually works is that if they say Alice and Bob or Alice, Bob, and Charlie,

1250
01:56:37.215 --> 01:56:37.715
they

1251
01:56:38.574 --> 01:56:42.275
send so Alice sends a coin to Bob, and then Bob will send

1252
01:56:44.530 --> 01:56:51.510
but a different actual Bitcoin, a different UTXO to Charlie, and Charlie will send, again, a different Bitcoin back to Alice.

1253
01:56:52.210 --> 01:56:55.375
So what's happening? The reason it's called the coin swap is they're actually paying Bitcoins.

1254
01:56:55.915 --> 01:57:00.920
So Alice's bought Alice's coin ends up in Bob. Bob's coins ends up in Charlie. Charlie's coin ends up on Alice.

1255
01:57:01.480 --> 01:57:01.960
And,

1256
01:57:02.360 --> 01:57:04.620
the the crucial point there is that it's noncustodial.

1257
01:57:05.160 --> 01:57:11.635
So it's a bit like CoinJoin in that. None of these users could actually lose money doing this because it uses Bitcoin smart contracts,

1258
01:57:12.415 --> 01:57:12.915
language.

1259
01:57:14.255 --> 01:57:23.460
And the reason that it improves privacy is because someone who's spying on Alice will think that Alice has sent, will think that, like, they won't realize that Bob now has the coin.

1260
01:57:24.160 --> 01:57:27.220
You're you're completely breaking the transaction graph.

1261
01:57:28.715 --> 01:57:29.215
Yeah.

1262
01:57:30.155 --> 01:57:33.075
And then the second question was how does it deal with the CoinJoin

1263
01:57:33.594 --> 01:57:34.895
amounts. It's almost a

1264
01:57:35.260 --> 01:57:39.680
almost a combination between CoinJoin and, like, the custodial mixers of the past. Right?

1265
01:57:40.860 --> 01:57:44.880
Or, like Yeah. So you could I I maybe that's a bad Like, the custodial mixers.

1266
01:57:46.015 --> 01:57:50.275
You could say it's a bit like the custodial mixers, except there's there'll be more than one of them,

1267
01:57:50.655 --> 01:57:53.075
and the custodial mixers can't steal your money.

1268
01:57:54.095 --> 01:57:54.595
Right.

1269
01:57:55.920 --> 01:58:00.820
Let's go here. Now the second question was how to deal with the equal amounts. Because, of course, if

1270
01:58:01.370 --> 01:58:01.870
sends

1271
01:58:02.215 --> 01:58:09.835
1.2 bitcoins, Hans has to send exactly 1.2 bitcoins or around that amount to Charlie and so on. And the way it deals with it is the multiple,

1272
01:58:10.695 --> 01:58:15.980
the multiple transactions. So Alice won't just send 1.2 bitcoins. She'll send maybe

1273
01:58:16.520 --> 01:58:19.260
2 or 3 transactions, and they will add up to 1.2.

1274
01:58:19.645 --> 01:58:22.945
So for example, she may send 0.5 plus 0.3

1275
01:58:23.405 --> 01:58:23.905
plus,

1276
01:58:24.525 --> 01:58:27.824
what's that leftover? 0.5 again. So it's 0.4.

1277
01:58:28.880 --> 01:58:32.980
You you get that there. And then and then Bob will send a different he'll also send 1.2,

1278
01:58:33.360 --> 01:58:37.300
but a different combination. So he'll send 0.1 plus 0.3 plus

1279
01:58:37.885 --> 01:58:38.545
1 point,

1280
01:58:39.005 --> 01:58:48.570
you know, you get you get the idea. And then for anyone who's looking on the blockchain, they'll never see the exact amount, 1.2 bitcoins. They'll only see these 0.5, 0.4, and so on.

1281
01:58:51.030 --> 01:58:51.530
Right.

1282
01:58:51.909 --> 01:59:00.165
And so you do you end up with a did you end up analyzing the kind of subset sum issue in the same way that I did with CoinJoin XT? I'm sure you remember that whole

1283
01:59:00.625 --> 01:59:02.510
spiel. Yes. Yeah. Yeah.

1284
01:59:03.370 --> 01:59:12.595
There is there is a I found a way you can this was, like, two and a half years ago at this point. If you remember, I actually messaged you on IRC and direct message way back then.

1285
01:59:14.015 --> 01:59:20.195
And what it was is that there is a way essentially that if you assume that each block has about 3,000 outputs,

1286
01:59:21.180 --> 01:59:27.680
then there is a way you can make the number of possible subset sums. Or the way I've worked it out is it doesn't work on subset sum, but on false positives.

1287
01:59:28.285 --> 01:59:45.400
So subset subsets which add up just by chance to be roughly close to your your total amount. And then you can make that up. It ends up the math ends up being that you can make that false positive rate be huge, like a 1,000,000 or 10,000,000 or something. Yeah. Well, this is very analogous to the discussion about nonequal sized

1288
01:59:46.185 --> 01:59:50.045
coin join inputs and outputs. Right? It's the same basic mathematical problem.

1289
01:59:51.304 --> 01:59:55.950
What I found was interesting recently in the analysis of the grid chain case, You remember the grid

1290
01:59:56.410 --> 02:00:00.270
chain case, you know, the whole thing where they they, this of early sea was, like,

1291
02:00:00.810 --> 02:00:02.405
finding where the coins went.

1292
02:00:03.364 --> 02:00:26.325
And some of the traces in his analysis was very interesting. I I found one particular transaction, and I thought, well, this is kind of interesting. I have these 4 inputs we know came from the same people. The rest of it, we can't quite, like, extricate, and I analyzed it. And I found that the subset problem was almost it was there were multiple, like, 5, 6, or more different solutions to the subset some problem on that particular coin joint specifically because

1293
02:00:27.310 --> 02:00:38.804
joint in those days, but to to a lesser extent now, has a quite unknown and quite large delta on each value because of the fees. And if the fees are unknown, you actually have quite a smearing out effect whereby

1294
02:00:39.265 --> 02:00:53.645
there are multiple reasonable solutions to who could have been the makers and who could have been the takers in the transaction. So here's an interesting thought. Yeah. If if we use and we get the the fees higher in join market, it will actually make the the privacy better because actually the fees will be larger and more smeared out.

1295
02:00:54.845 --> 02:00:56.865
That's a sorry. That was a nerdy joke.

1296
02:00:57.325 --> 02:00:58.945
I'm not too sure. And that also

1297
02:00:59.885 --> 02:01:05.910
that also applied the coin swap as well. The the adding up the the fees are included as well. There'll be a liquidity market.

1298
02:01:07.810 --> 02:01:33.065
Right. So some Right. One on someone on the chat has said, what's if you're with a FBI handler? And the reply to that so the general question is, what if Alice coin swaps with Bob and Bob is spying on her? The way that's solved is there'll be a rooted coin swap. So Alice will coin swap with Bob, and then she also organized a coin swap between Bob and Charlie. And if she wants, she can do between Charlie and Dennis, like, 3 you know, however many makers she wants. And the coin swap goes as a route through all those.

1299
02:01:33.605 --> 02:01:39.239
And and then in order to unmix her coin swap, all of those 3 or 4, however many makers would have to collude.

1300
02:01:39.619 --> 02:01:45.719
And then you it's it's essentially the same thing as in joint market. All the makers have to actually be the same person and colluding. Right.

1301
02:01:46.345 --> 02:01:48.285
Which is where the fidelity bonds come in.

1302
02:01:49.145 --> 02:01:55.645
Yeah. And then fidelity bonds would be helpful there as well. So that it's way more expensive for you to be multiple makers than a single maker.

1303
02:01:55.950 --> 02:01:56.850
Yep. Exactly.

1304
02:02:01.870 --> 02:02:05.570
Yeah. I mean, so that that that's I mean, that sounds fantastic.

1305
02:02:08.175 --> 02:02:08.995
And and

1306
02:02:09.695 --> 02:02:13.795
from your point of view, Chris, you think this completely deprecates CoinJoin?

1307
02:02:15.860 --> 02:02:26.265
Well, so, it may deprecate definitely only equal output coin joins. So pay join would still be used, I think. But what about join market? You think join market is completely

1308
02:02:28.165 --> 02:02:30.505
Well, the thing of join market join market say

1309
02:02:31.219 --> 02:02:36.739
the thing with joint market, it's a decentralized protocol, so nobody can shut it down, not even me. That's not what I'm saying. I'm not

1310
02:02:37.699 --> 02:02:50.020
It will live as long as people use it. And I So that's Yeah. I guess one day people decide that coin swap is more useful and they might swap over, but I think you're wrong with the market. I'm not asking you if you think that coin swaps

1311
02:02:50.480 --> 02:02:56.820
that that I I'm not asking you if you personally are gonna shut down joint market. That's the most ridiculous your most ridiculous

1312
02:02:57.815 --> 02:02:59.435
Okay. Idea ever.

1313
02:02:59.815 --> 02:03:03.995
I know you can't. What I'm what I'm saying is you believe personally

1314
02:03:04.855 --> 02:03:09.420
that me as a user or the freaks that are listening to the pod,

1315
02:03:10.199 --> 02:03:13.260
and I'm, and and and you're talking about best practices,

1316
02:03:13.800 --> 02:03:17.335
that they will have no use for for join market,

1317
02:03:18.595 --> 02:03:20.215
because coin swaps

1318
02:03:20.595 --> 02:03:21.415
are are

1319
02:03:22.035 --> 02:03:26.210
are better and obviate the need for for CoinJoin. Right?

1320
02:03:26.990 --> 02:03:32.370
Okay. I see. Yeah. So the word sorry. The word deprecate has a meaning in I know. I get what you mean now.

1321
02:03:33.215 --> 02:03:39.315
Yes. I think, in other words, do I think coin swap is better than joint market? Yes.

1322
02:03:40.250 --> 02:03:43.310
And the reason is that it's cheaper in minor fees and that it they're indistinguishable

1323
02:03:44.010 --> 02:03:46.989
so that it's you're hiding the fact that Coinswap is happening.

1324
02:03:49.715 --> 02:03:54.695
So you don't think you don't think that that Coinswap is a post mix tool?

1325
02:03:55.315 --> 02:03:59.175
You don't think Coinswap competes with PayJoin? You think Coinswap competes with CoinJoin?

1326
02:04:00.739 --> 02:04:05.079
Yes. Equal output coin join. I think so. What do you mean by post mix?

1327
02:04:06.395 --> 02:04:12.255
I mean I mean, you do coin join, and then after coin join, you do coin swap to break the transaction graph.

1328
02:04:13.820 --> 02:04:17.040
I suppose you could do that if you wanted, but then if you do it that way,

1329
02:04:18.060 --> 02:04:23.895
then it's obvious that you use the coin join, and also you'll spend more in minor fees. But but here's the thing.

1330
02:04:24.355 --> 02:04:24.855
So

1331
02:04:26.035 --> 02:04:28.675
this is where the frustration comes in. Right? It's because

1332
02:04:30.470 --> 02:04:33.450
so this show the whole point of this show is is

1333
02:04:34.790 --> 02:04:42.204
is that I wanted a a place where we can have actionable Bitcoin a place where we could discuss things with Bitcoiners,

1334
02:04:43.385 --> 02:04:47.565
amongst Bitcoiners with a live audience, where we could actually talk about things

1335
02:04:48.099 --> 02:04:54.599
that that a Bitcoiner could go and and and and and do tomorrow. Right? And and, like, actually make their situation better.

1336
02:04:56.005 --> 02:05:03.385
Rather than, like, pie in the sky cheerleader kind of ideas I'm not accusing you of this, by the way, but this is very common in the podcast space.

1337
02:05:03.960 --> 02:05:05.659
Where, like, Bitcoin fixes everything,

1338
02:05:06.120 --> 02:05:15.155
and there's, like, no trade offs. And and in 5 years, it's all gonna be perfect, but, like, you don't have to worry about it now. You just have to listen to the podcast and hear it's it's brought to you by these sponsors,

1339
02:05:15.455 --> 02:05:17.935
and in 5 years, like, it's all gonna work out. Yeah.

1340
02:05:18.335 --> 02:05:22.755
I wanted to show where, like, we could talk about real things and, like, people could do those things.

1341
02:05:24.559 --> 02:05:25.059
So

1342
02:05:25.360 --> 02:05:28.579
so so my my my concern is

1343
02:05:30.135 --> 02:05:31.915
is is that this idea

1344
02:05:32.455 --> 02:05:36.235
is is when we talk about in practice of people actually using Bitcoin,

1345
02:05:37.080 --> 02:05:41.020
the number one thing when you talk about privacy is coin control. Right?

1346
02:05:41.640 --> 02:05:43.820
Where did your UTXO's come from?

1347
02:05:44.360 --> 02:05:45.340
Labeling them,

1348
02:05:46.535 --> 02:05:50.795
knowing in 5 years when it comes time to actually spend them where they came from,

1349
02:05:51.815 --> 02:05:53.755
and and and choosing accordingly

1350
02:05:54.055 --> 02:05:55.195
based on that

1351
02:06:04.170 --> 02:06:04.670
and

1352
02:06:05.185 --> 02:06:19.180
and and and the user has to fucking deal with this, and there's, like, a major disconnect because, first of all, the majority of Bitcoiners just are never spending Bitcoin. So they're just putting it in cold storage. They're not even thinking about it. And then the privacy focused users are

1353
02:06:19.640 --> 02:06:26.375
in their own world where they're just boycotting KYC, and they're just they they just know how to use coin control and all these things.

1354
02:06:26.835 --> 02:06:30.934
So what's cool about CoinJoin for me, specifically, equal output CoinJoin,

1355
02:06:31.700 --> 02:06:33.239
is that it kind of resets

1356
02:06:34.660 --> 02:06:35.719
the coin control.

1357
02:06:36.340 --> 02:06:38.600
It kinda resets the history of the UTXO

1358
02:06:39.300 --> 02:06:41.320
in a in a very objective way.

1359
02:06:41.764 --> 02:06:42.985
Right? It's, like, almost

1360
02:06:44.085 --> 02:06:51.830
it doesn't matter if I I you you paid me 5 years ago. I don't remember it was you who paid me. I take that UTXO. I put it through CoinJoin,

1361
02:06:52.530 --> 02:06:58.230
and, like, I'm resetting that history. Like, I forgot I forgot what the label is. I'm resetting that history. It almost

1362
02:06:59.304 --> 02:07:00.605
reduces the need,

1363
02:07:00.985 --> 02:07:01.885
and I'm not

1364
02:07:02.425 --> 02:07:05.485
I'm trying to cover my bases with all the fucking

1365
02:07:06.025 --> 02:07:08.829
words, but, like, I'm not saying that coin control is

1366
02:07:09.130 --> 02:07:14.750
is unnecessary in that situation. I'm saying it reduces the reliance on prudent coin control and labeling

1367
02:07:15.195 --> 02:07:18.415
if you have this ability to almost reset the history of the transaction.

1368
02:07:19.195 --> 02:07:26.889
And in a situation where you're using Coinswap, it'd be really nice if I could reset the history of the transaction before I do my swap. Does that make sense?

1369
02:07:27.829 --> 02:07:34.145
Yeah. So if I understand right, you see the the fact that it's obvious that a coin join happened. You see it as a possible feature.

1370
02:07:34.844 --> 02:07:36.784
Right. Like, I'm resetting the history.

1371
02:07:37.680 --> 02:07:40.660
And then if so, you could say Coinswap does not have this feature.

1372
02:07:41.200 --> 02:07:41.700
Correct.

1373
02:07:42.640 --> 02:07:43.120
Right.

1374
02:07:43.680 --> 02:07:43.930
Probably

1375
02:07:44.955 --> 02:07:52.815
okay. You know? Okay. I understand that point of view. Probably what will happen then is people use both if people are interested in that, they'll use Coin CoinJoin and Coinswap,

1376
02:07:53.580 --> 02:07:54.800
like, depending on the situation.

1377
02:07:57.340 --> 02:08:02.375
Right. But I wanna automate that. Right? Like, I want the wallet to just automatically push it through CoinJoin

1378
02:08:02.675 --> 02:08:09.015
and then do a coin swap, and then maybe go into a a combined lightning opening, and then you pay.

1379
02:08:09.660 --> 02:08:14.320
Right? And you, like, put all that together, and I and and this goes back to my previous

1380
02:08:15.100 --> 02:08:16.000
topic that,

1381
02:08:16.545 --> 02:08:21.364
like, why the fuck are we hiding the fact that we care about privacy? Like, we don't do this with speech.

1382
02:08:21.665 --> 02:08:30.665
Like, everyone knows I'm using signal. The point is is that the encryption is supposed to stop people from being able to read the messages, not that they're supposed to not know that I'm using signal.

1383
02:08:32.185 --> 02:08:35.705
I think I think they're both they're both valid valid and correct,

1384
02:08:36.265 --> 02:08:49.765
perspectives to have at the same time. Even though they seem contradictory, they're they're not really contradictory because, like, when we use a steganographic technique, the advantage is that we we gain this huge anonymity set without needing to, like, coerce other people to do the same thing as us.

1385
02:08:50.645 --> 02:08:53.065
And with the the sort of public non steganographic

1386
02:08:53.445 --> 02:08:56.905
techniques, it has this advantage, as you say, that we are sort of

1387
02:08:57.860 --> 02:08:59.960
publicly asserting the right as well.

1388
02:09:00.900 --> 02:09:01.560
I think

1389
02:09:01.860 --> 02:09:03.160
at some level, the steganographic

1390
02:09:03.540 --> 02:09:05.000
approach is always fundamentally

1391
02:09:05.300 --> 02:09:06.280
better because

1392
02:09:06.845 --> 02:09:18.789
there's always this option of selective revelation. So you talk about something like confidential transactions where you're, you know, blinding amounts. You always have this auditability possibility where you could just have some key that allows you to actually

1393
02:09:19.090 --> 02:09:24.065
assert that this really was, x amount of Bitcoins. And the same with any other thing like coin swap. You could always

1394
02:09:24.545 --> 02:09:27.844
selectively reveal that you, you know, you engaged in a Coinswap.

1395
02:09:28.945 --> 02:09:36.450
So that's like, one of them is, to me, more powerful than the other, but it's it sometimes comes at a bit of a cost. Like, for example, with coin swaps, there's this kind of,

1396
02:09:37.810 --> 02:09:45.735
cross block what I like to call cross block interactivity property, which is a bit undesirable because you in order to enforce the smart contract, you have to consider the state

1397
02:09:46.114 --> 02:09:54.119
before and after, you know, blocks get confirmed, which introduces even if minor, it introduces an extra element of risk, which a coin joint doesn't have,

1398
02:09:54.980 --> 02:09:58.520
as well as the interactivity being more practically difficult, of course.

1399
02:09:59.764 --> 02:10:01.784
Like, can we go into that cross block?

1400
02:10:03.445 --> 02:10:07.385
Yeah. So that essentially means, you send coins into a multisig

1401
02:10:07.750 --> 02:10:11.849
when you're doing a coin swap, and then you have to wait a block or 2 to make sure there's no reorganization,

1402
02:10:12.389 --> 02:10:14.570
and then you complete the coin swap protocol.

1403
02:10:15.030 --> 02:10:20.355
And, the the fear there is that, for example, if there's a 51% attack or if

1404
02:10:20.815 --> 02:10:28.079
or something like that, if if you if your Internet cuts out, then you could lose money. It's it's quite similar to having lightning. You always need a watchtower,

1405
02:10:28.699 --> 02:10:34.225
if you're familiar with that. It's it's actually the same concept there. So does that added risk, which doesn't exist in a coin joint.

1406
02:10:35.025 --> 02:10:37.525
And then No one's running watch hours, by the way,

1407
02:10:38.225 --> 02:10:40.085
for whatever that's worth. Okay.

1408
02:10:41.105 --> 02:10:43.205
Very few. Very few. Few. Few.

1409
02:10:43.780 --> 02:10:47.640
Who watches the watches? The second thing about, waxing said about interactivity,

1410
02:10:48.340 --> 02:11:18.355
from my point of view, that doesn't make much of difference to the user. So that makes it a bit more difficult to implement. But the user will still come along and just press send on their on their application, and it will send. So it's a thing. It's a problem for developers, but for users, I think they won't notice. But it will it will create delay in the user experience. It won't create additional complexity for the user. As you say, it's more for the developer. Yeah. Right. But the user already has a delay because it takes 10 minutes for a block to appear or even longer if you pay a low fee. So the delay is big already. It doesn't matter. If you if you do it right if you do it right, a coin swap,

1411
02:11:18.870 --> 02:11:24.090
especially if you're paying someone else with a coin swap, if I'm paying Chris with a coin swap,

1412
02:11:26.475 --> 02:11:33.615
If if you do that if you do that in a a UX friendly way, that could actually be better that could be better UX than a regular Bitcoin payment.

1413
02:11:34.860 --> 02:11:37.360
I'm not too concerned about that aspect of

1414
02:11:38.300 --> 02:11:38.800
it.

1415
02:11:39.740 --> 02:11:50.305
Or what about what's the Yeah. Go on. Go ahead. What what about the comparison with with just just lightning? I mean, do you see, Chris, the main the the advantage of coin swap,

1416
02:11:51.085 --> 02:11:58.150
architecture over just a lightning architecture is that you can deal with larger amounts, or or is there other elements I'm not thinking about?

1417
02:11:58.530 --> 02:12:01.910
Yeah. There's that. There's larger amounts so that with lightning, it's inherently

1418
02:12:02.245 --> 02:12:09.705
limited by the channel capacity. And with Coinswap, you could do any amount that's in the in the liquidity order book. There's also the effect that with Coinswap,

1419
02:12:10.085 --> 02:12:21.265
you I call this unilateral adoption that you can pay anyone who has a Bitcoin address. Well, with Lightning, to pay someone with Lightning, they have to accept Lightning. You have to beg them a bit like with PayJoint to accept Lightning.

1420
02:12:21.805 --> 02:12:36.225
And then the 3rd kind of difference, there's actually a whole section where somewhere I wrote, what's the difference between coin swap and lightning? The 3rd difference is that coin swap has these fidelity bonds, and they can't really be added in lightning. So then the civil resistance of coin swap is is a lot higher.

1421
02:12:36.685 --> 02:12:41.345
Wait. Why can't But, yeah, you're you're a young Why can't they be added in lightning? Why can't you have a fidelity?

1422
02:12:43.159 --> 02:12:46.460
How how would it, like, think practically. If you want to open

1423
02:12:47.159 --> 02:13:04.120
a open a channel with someone, you you check the well, maybe there is a way. But Yeah. I don't know. If you want to imagine you open a channel, and then it says you'd rather I'd rather open it with this one because it has a high fidelity But but but that breaks up that you can sign a message and broadcast it with your public key of your node or something.

1424
02:13:05.460 --> 02:13:05.960
Right?

1425
02:13:06.340 --> 02:13:23.760
Yeah. This is the thing I'm asking is, would they make your route longer? Like, the person you're opening a channel to isn't necessarily the person you want to pay. Yeah. You know, most people Yeah. Open channels with Bitrefill or someone they pay very often. Yeah. Yeah. Yeah. The fact that I mean, Bitrefill, they're not regulated. Right? Like, they don't have to deal with KYC information.

1426
02:13:24.855 --> 02:13:26.875
They're not a centralizing factor at all.

1427
02:13:28.295 --> 02:13:30.555
I think I think they might be a little bit.

1428
02:13:33.150 --> 02:13:40.050
I'm I'm really a big fan there. I don't wanna say anything next to you. I love that refill. I'm just I'm just being a little bit of a dick about about lightning.

1429
02:13:41.950 --> 02:13:42.450
Yeah.

1430
02:13:43.265 --> 02:13:43.765
Yeah.

1431
02:13:44.865 --> 02:14:05.885
No. I mean, I think this is a very insightful conversation. Okay. I wanna I wanna I know I know we're gonna run out of time eventually. I wanna mention 2 other ideas. Although, probably, we should talk more about Coin Swap, but I just wanna mention 2 more ideas because I don't think these these get mentioned very often, and and they're both my idea. So I wanna mention them. So one of them is called coin join XT, and what I I like about coin join XT is imagine the idea of a coin join,

1432
02:14:06.345 --> 02:14:09.965
but still trying to make it kind of steganographic or maybe completely steganographic

1433
02:14:10.330 --> 02:14:11.950
by spreading the coin join

1434
02:14:12.330 --> 02:14:15.390
over multiple transactions instead of having 1 huge transaction.

1435
02:14:16.010 --> 02:14:20.585
And the great thing is that with Segwit, you can do that all in one single negotiation

1436
02:14:21.125 --> 02:14:22.824
without some massive, you know,

1437
02:14:24.005 --> 02:14:26.744
without some, massive interactive protocol.

1438
02:14:27.050 --> 02:14:31.550
Everyone can just get together just like they do now to arrange a coin join on join market or whatever.

1439
02:14:32.250 --> 02:14:40.125
And instead of just arranging one big transaction, they can arrange a graph of transactions that are all connected together, and each one of them could look like an ordinary payment.

1440
02:14:40.425 --> 02:14:50.350
Or if you like, it could look like a 3 party or 5 party coin joint. And you could build these whole this whole network of transactions all at once, and you can negotiate all the signatures up front because of SegWit's,

1441
02:14:51.370 --> 02:14:53.390
you know, malleability fix.

1442
02:14:53.995 --> 02:14:54.655
So, consequently,

1443
02:14:55.275 --> 02:15:00.014
we we we could negotiate that and then just have it so with careful, like,

1444
02:15:00.315 --> 02:15:26.110
arrangement of timeouts and stuff, time locks rather, We can have it so that any one party as long as any one party wants the whole thing to go through, the whole network of transactions to go through, then it will go through. And what I like about that is that it it it comes back to that beautiful steganographic property, meaning that coin joins could be, like, embedded in the blockchain in a way that they don't look like. And I know you you like everyone to be able to see it. And just for you, we could throw in a couple of, like, actually

1445
02:15:26.815 --> 02:15:32.594
public public coin joins into the graph, but, like, there'll be several other transactions around it that would actually be coin joins and nobody would know.

1446
02:15:33.935 --> 02:15:37.409
I like that idea, but I still haven't actually written any code. So so Chris

1447
02:15:38.290 --> 02:15:44.835
But this now that while while talking to you guys, I realized that some people actually want their their privacy transactions to be visible.

1448
02:15:45.375 --> 02:15:55.980
From that point of view, then this point during XT, which I I remember reading I mean, you told me about it. I read it, analyzed it, like, a few years ago. It it maybe makes a bit more sense because I originally didn't like it because I thought

1449
02:15:56.360 --> 02:15:58.620
coin swap was better because it can be invisible.

1450
02:15:59.815 --> 02:16:11.790
And there's actually a thing with coin swap that we're adding is it's if you have a a coin swap coin, like, you own a coin and it came from a coin swap, it's not possible for you to prove even if you wanted to that it came from coin swap.

1451
02:16:12.250 --> 02:16:16.085
So its history is completely like Ah, so you're saying it has has the deniability.

1452
02:16:17.585 --> 02:16:20.244
I'm wondering if you could have a version that is

1453
02:16:20.625 --> 02:16:31.165
to do with the way the lock is created that is actually oh, no. But even adapter signature coin swaps are actually, yeah, fundamentally deniable by design. That's very interesting point. I didn't didn't think about it. Yeah.

1454
02:16:31.645 --> 02:16:40.065
Yeah. Yeah. Fun and not even deniable that even if you want to do, you cannot prove it. So it's even more than deniable. Sorry. Yeah. The deniable is just gone. Yeah.

1455
02:16:40.720 --> 02:16:43.700
Yeah. The deniable. I know. Well, you'd call it like

1456
02:16:44.240 --> 02:16:47.061
a the knowledge is unprovable, maybe unprovable.

1457
02:16:47.645 --> 02:16:53.985
It's like OTR where, you know, given the transcript, anyone could have made the transcript. Yeah. So you just have no way of,

1458
02:16:54.605 --> 02:16:58.470
yeah, proving it. There is another term for it. I don't know what the term is. I can't remember.

1459
02:17:00.770 --> 02:17:03.189
Yeah. Interesting. Did points. Yeah. You're right.

1460
02:17:03.625 --> 02:17:07.545
We can look it up for later. Oh, yeah. Coin CoinJoin XT is a good,

1461
02:17:08.265 --> 02:17:19.900
it's a nice like, a kind of a fundamental privacy that's worth looking at. But but do you see in that in that way of doing things, it's optional. Like, you could go the the the route that you like, Chris, where it's absolutely

1462
02:17:20.440 --> 02:17:27.466
I know it wouldn't be perfect, and it wouldn't be as good as a coin swap, but it would you would have some contiguous subset of the entire chain of transactions,

1463
02:17:28.160 --> 02:17:34.580
which were actually all arranged by, let's say, 5 parties together. But each one of them just looks like an ordinary payment, has nothing.

1464
02:17:35.205 --> 02:17:44.825
There is a very important fly in fly in the ointment, which is multisig, which we should have talked about before with Coinswap. You see, the thing is when you make multisig today, it's very distinguishable as multisig.

1465
02:17:45.221 --> 02:17:48.601
And so in these CoinJoin XT graphs, you would have to have 1,

1466
02:17:49.141 --> 02:17:49.641
multisig,

1467
02:17:50.500 --> 02:17:51.221
co owned,

1468
02:17:51.700 --> 02:17:53.480
output at every at every step.

1469
02:17:54.075 --> 02:17:56.975
And so we really do need these multisigs to be indistinguishable

1470
02:17:57.595 --> 02:17:58.095
from

1471
02:17:58.715 --> 02:18:01.295
well, ECDSA. Yeah. No. You don't necessarily.

1472
02:18:02.720 --> 02:18:05.939
Yeah. E c d s a 2 p or 3 p or whatever.

1473
02:18:06.560 --> 02:18:26.590
You could have used that for because the plan is the plan for coin swap is to use that anyway, so you may as well use it for coin store and next eve too. Your your idea was that it might be better to use that even if Taproot's activated. Right? I seem to remember you saying that because it would inherit the because Taproot anonymity set of everything. Yeah? Yes. The tap the anonymity set is bigger.

1474
02:18:27.105 --> 02:18:32.645
Yeah. Yeah. Yeah. But I still wanna if if I don't mind, can we just come back to the point of why would people want their privacy

1475
02:18:33.186 --> 02:18:35.585
transactions to be visible? It just seems a bit like

1476
02:18:36.230 --> 02:18:48.245
I I don't understand that. I don't I don't know how how that Chris Chris, my argument my argument isn't that Yeah. That it it should be visible. I'm just saying, like, we shouldn't be ashamed if it is visible because

1477
02:18:48.705 --> 02:18:54.726
Right. That is privacy is like, seeking privacy historically has always been a visible task

1478
02:18:55.340 --> 02:19:02.960
that that you are actively seeking privacy. Like, you no no one hides that they're seeking privacy in every other situation. It's I don't know. I disagree.

1479
02:19:03.500 --> 02:19:04.160
I disagree.

1480
02:19:04.525 --> 02:19:05.426
Oh, no. Specifically

1481
02:19:05.886 --> 02:19:06.386
specifically

1482
02:19:07.006 --> 02:19:07.506
speech.

1483
02:19:08.125 --> 02:19:17.460
Specifically speech. When it comes to encryption, encryption is extremely obvious. It is obvious that we're using when when I speak to Chris on DM using PGP,

1484
02:19:18.080 --> 02:19:30.715
Jack Jack and everyone at Twitter knows that we're using encryption in our DMs. Yeah. But it's not always like that. Think about the activist in a despotic country. You know, this is this is where the steganography really comes in is that you do not want

1485
02:19:31.270 --> 02:19:37.450
your local government official to know that you're using GPG because he will come around your house with, you know, with the boys.

1486
02:19:40.395 --> 02:19:44.815
So that's the go on. In a free society in a so called free society

1487
02:19:45.355 --> 02:19:46.636
Yes. It is not

1488
02:19:47.115 --> 02:19:47.676
it shouldn't

1489
02:19:48.120 --> 02:19:49.020
we shouldn't just immediately

1490
02:19:49.960 --> 02:19:54.140
assume like, we shouldn't immediately assume the shame card.

1491
02:19:54.440 --> 02:19:57.985
Like, it's it's ridiculous that we should feel like we need to hide.

1492
02:19:58.545 --> 02:20:05.686
And and I'm saying this specifically as I mean, and and props to both of you guys. You guys have been very vocal, very public,

1493
02:20:06.290 --> 02:20:08.870
even though you have way better OPSEC than I do,

1494
02:20:09.810 --> 02:20:12.550
about Bitcoin privacy. And why is that the case?

1495
02:20:12.930 --> 02:20:24.045
Because you think it's important, and you think that you shouldn't be ashamed to care about it. Right? Yep. I think so. I do agree with you. I'm just saying that there's that other aspect, you know, like, in the more

1496
02:20:24.530 --> 02:20:29.430
the freedom fighter model, so to speak. That's the thing. If you're in a free society, why do you need Bitcoin?

1497
02:20:29.810 --> 02:20:32.310
Right? Bitcoin works best as a way of resisting

1498
02:20:32.905 --> 02:20:34.445
places where there's not much freedom.

1499
02:20:34.905 --> 02:20:58.306
Right. I mean, what I'm saying is it's a so called free society, and it it it it shows their hypocrisy. It every time every time, like, a a democratic government wants to ban encryption, it shows their hypocrisy. Yeah. Yeah. And and same with CoinJoint in my opinion. And and and I I would go back to this idea that coin control is a very difficult process, and this idea that we can

1500
02:20:58.760 --> 02:21:05.340
provably reset the history of a coin Mhmm. Is is a very valuable concept. If we can get

1501
02:21:06.016 --> 02:21:09.476
if if we can if we can get Western democracies at least

1502
02:21:10.095 --> 02:21:14.915
to agree that CoinJoin is a fundamental human right, that it's it is just

1503
02:21:15.760 --> 02:21:16.659
it's it's just

1504
02:21:17.359 --> 02:21:22.979
law abiding citizens trying to seek privacy best practices, send Bitcoin with privacy best practices.

1505
02:21:23.439 --> 02:21:29.115
That's a massive win. Right? Yeah. Do do do you see, Chris, our our our perspective is something like

1506
02:21:29.495 --> 02:21:31.035
by doing this thing publicly,

1507
02:21:31.814 --> 02:21:40.885
we at the very least, we force our opponents to show their cards as being, quite frankly, evil in their behavior. At the very least, we show that.

1508
02:21:41.285 --> 02:21:48.404
And I would say that's more than that. It's also it's, yeah, it's also like showing that fungibility is possible and and, like, making

1509
02:21:49.120 --> 02:21:52.900
putting fungibility in in people's face. Like, suppose somebody builds walletexplorer.com

1510
02:21:53.520 --> 02:21:55.860
today. I know that history has moved on.

1511
02:21:56.375 --> 02:21:59.435
And the only kind of technology people had ever used was, like,

1512
02:22:00.135 --> 02:22:18.665
you know, coin swaps and things. And nobody knew who was using coin swaps. They'd like you couldn't go up to someone and say, look. Look. Look at this wallet explorer. It's complete bullshit, and I can show you why it's bullshit. Because look on the graph, it's actually just a massive coin join, and they think they're all the same person, the while the explorer are stupid. But you couldn't really do that if we only ever used secondographic techniques

1513
02:22:19.260 --> 02:22:49.055
because, nobody would nobody would know anything, and everyone would sort of think they I don't know. Maybe that's not true, actually, but interesting to think. Yeah. You'd have to do it in a way that, I don't know, you take someone's coins from their own wallet, which they know belong to them. And then then you put it into Wallet Explorer, and they says, look. You actually this coin actually belongs to some guy over there. Can I just bring in something from the chat? So 6102 says, for coin swap to invalidate the heuristics, you need many users using it. For CoinJoin to validate the heuristics, you need just that one CoinJoin. But I think that's,

1514
02:22:50.175 --> 02:23:07.885
I think that's not right because you can have, this common input ownership heuristic. You could any any analyst could exclude coin joints because coin joints are detectable. They could say, I'm not gonna do the common input ownership heuristic on this particular transaction because I can see it's a coin joint. Well, that's not possible with coin swaps because you can't see them.

1515
02:23:09.065 --> 02:23:14.580
I thought that was a good point. That was worth saying. But so so, Chris, like, you care about protecting the privacy

1516
02:23:14.960 --> 02:23:17.220
of users who don't care about their own privacy,

1517
02:23:18.085 --> 02:23:22.505
And that's what Coinswap attempts to do. That that's one of the motivations. But they also,

1518
02:23:23.125 --> 02:23:33.150
doing building a system that way also helps massively people who do care about privacy. They have a much bigger anonymity set. Yeah. It's just making the bigger anonymity. But we do agree that, a stronger

1519
02:23:33.690 --> 02:23:35.150
heuristic than the common,

1520
02:23:36.155 --> 02:23:38.495
the common input ownership heuristic

1521
02:23:39.035 --> 02:23:43.216
is just, like, sending to a KYC exchange and, like, then they just have your KYC info.

1522
02:23:44.091 --> 02:23:45.631
Yeah. They have all your docs.

1523
02:23:46.330 --> 02:23:51.950
Like, you just send it to BlockFi to get your 6%. Like, it doesn't like, no one's gonna be, like, oh, that might be a coin swap.

1524
02:23:55.195 --> 02:24:06.551
Yeah. They wouldn't be able to detect. Well, this is why we the the discussion we've been, yeah, the that's why the discussion we've been having recently, I remember, on IRC is about blacklisting and whitelisting. Right? Because it seems like

1525
02:24:06.975 --> 02:24:07.555
the blacklisting

1526
02:24:07.935 --> 02:24:13.715
techniques that we're seeing being sort of thrown out there by exchanges like like a BlockFi example you showed earlier on

1527
02:24:14.311 --> 02:24:16.570
are obviously kind of broken ideas fundamentally

1528
02:24:17.190 --> 02:24:24.564
because there's always gonna be hops, and there's always, like, deniability and hops. So they're just gonna move more and more towards a world where they just say,

1529
02:24:25.185 --> 02:24:34.790
well, I want to see you know, you I wanna see you prove the origins of these coins before you even use them or something like that. It's a horrible thought, but I I I I that's how I see it going.

1530
02:24:35.490 --> 02:24:37.030
Yep. That could be an outcome.

1531
02:24:38.005 --> 02:24:48.640
You see this, question from Peter l Grant asking if there could be a maker taker model with Coinswap where the makers have to provably have performed a coin join beforehand?

1532
02:24:50.540 --> 02:24:57.895
In principle, that's possible. You could get the makers to send the transaction they're paying from, like, via the via the communication.

1533
02:24:59.715 --> 02:25:01.175
There could be, but I think,

1534
02:25:01.875 --> 02:25:03.255
yeah, there could be. Alright.

1535
02:25:04.090 --> 02:25:08.350
And and then so, like things like this all, though. So you're you're you're the

1536
02:25:08.890 --> 02:25:18.726
the the dream of of Coinswap is that we get this fucking thing integrated into, like, every mobile wall every wallet, as many wallets as all the good wallets should have Coinswap implemented,

1537
02:25:19.431 --> 02:25:22.410
And then make every transaction a Coinswap.

1538
02:25:23.270 --> 02:25:26.070
As many transactions as possible. At least at least,

1539
02:25:26.605 --> 02:25:47.854
everyone who wants it can have it. There's no nuance here, Chris. Every transaction, every every transaction single one. Yes. No. But there's a really no. But there's a really important nuance, isn't there? Because, again, it's steganographic, which means it only has to be a smallish percentage to completely fuck up the blockchain analysis. I mean, that's a really important point that should be hammered home. Right. So what percentage? We're talking 10% you said earlier?

1540
02:25:48.234 --> 02:25:58.069
Yeah. We're all. Fantasy I've had is that it will be a checkbox that users do they want, like, a really private coin join, or do they want a regular transaction? They have a checkbox to prove which one they want, and then they press send and it happens.

1541
02:26:01.095 --> 02:26:05.574
Right. I mean, preferably I mean, it'd be nice if it was just the default, but

1542
02:26:06.260 --> 02:26:13.800
Yeah. It's hard for it to be the default. I if if you keep it in, like, a semi walled garden and you're fine with semi trusted third parties,

1543
02:26:14.945 --> 02:26:17.365
like I said, like, I think you could create a UX

1544
02:26:18.145 --> 02:26:18.645
where

1545
02:26:19.505 --> 02:26:23.045
where Coinswap could be an easier UX. I mean, I'm thinking, like,

1546
02:26:23.820 --> 02:26:27.680
let's pretend BlueWallet became super successful and they added usernames,

1547
02:26:29.020 --> 02:26:38.235
and I put in the username, and I just pay that username, and that person just has it on their phone, and just automatically, like, gets the push notification, and then connects and does the swap.

1548
02:26:39.735 --> 02:26:42.830
That could be an easier UX than scanning a QR code.

1549
02:26:43.530 --> 02:26:55.585
But they also means that you can only pay people with that method who are also using blue wallets. So you lose the whole worldwide permissionless part of Bitcoin. Right. But it's a it's we're talking trade offs. You know, it's convenience versus

1550
02:26:57.979 --> 02:27:15.024
Okay. So for that, you'd have to bother all your friends. You'd say, hey. Can you switch to blue one? Pay you using your name. And, Waxwing, where does where does where does Snicker fall into this? Yeah. So Snicker was a like, a it's kind of out of left field of all these other ideas, and I'm all that came out of was me thinking about

1551
02:27:15.400 --> 02:27:24.685
how could you possibly do CoinJoin in a way that didn't even involve, like, connecting to other users on a network? And it sounds kind of impossible because everyone has to sign a transaction. Right?

1552
02:27:25.244 --> 02:27:29.824
So all I could come up with is is this idea that what you could do is

1553
02:27:30.364 --> 02:27:35.860
basically kind of scan the blockchain, to put it crudely, and look for outputs obeying a certain pattern

1554
02:27:36.721 --> 02:27:37.221
and

1555
02:27:37.841 --> 02:27:44.145
infer that the outputs that the inputs corresponding to those outputs might be owned by the same party. They may or may not, of course.

1556
02:27:44.944 --> 02:27:54.085
And then you could kind of basically use the key in the input, the public the pub key in the input as an encryption key and send an encrypted proposed transaction

1557
02:27:55.090 --> 02:28:01.830
that included the output that I just mentioned and one of your own outputs both being spent together to make a a coin join.

1558
02:28:02.796 --> 02:28:11.296
So I wrote like a like a gist with a kind of proposed protocol for it. And, you know, a few people were somewhat interested and and sort of we looked into it a bit.

1559
02:28:11.750 --> 02:28:12.250
And,

1560
02:28:12.630 --> 02:28:19.645
at the end of the day, I don't think anyone's really taken up apart from me. And I do I I kind of literally mean me, not just not just join market, whatever.

1561
02:28:20.845 --> 02:28:32.920
But I have actually, like, written all the code, and you can actually do it in join market today, but I put heavy kind of warnings on it that you would only wanna be using this on Signet or some kind of, you know, test setup. You don't really wanna try and use this on Mainnet.

1562
02:28:33.620 --> 02:28:35.400
But it's all there. I mean, there's even like

1563
02:28:35.705 --> 02:28:39.005
a part well, it's funny that the well, the kind of

1564
02:28:39.465 --> 02:28:44.045
internal technicals of it are kind of interesting, but the really tricky point ends up being

1565
02:28:44.760 --> 02:29:06.540
the kind of broadcasting of the proposal. So you imagine you're sitting there looking at the the whole blockchain. You say, oh, this this output looks like it could be a good candidate for me to do a coin join with it. And so you make up the transaction, but then you have to put it somewhere for this other person who you've never met, don't know who they are, don't know what part of the planet they live on. How how are they gonna find that proposal? Right? Even if it's encrypted to them, so it's like secret. So that's good.

1566
02:29:07.000 --> 02:29:29.115
But they've gotta find that encrypted proposal. So I've what I've done is I've set up, like, a tool hidden service, and you can just post it to a simp it's got a simple SQLite DB on the back end, and you just you can just add your proposal there. And, and then wallets can just scan that list. And I've even added, like, a little proof of work. It's quite funny. I used, like, Adam Back's HashCash idea in in there so that people can't just send millions of proposals,

1567
02:29:30.215 --> 02:29:50.444
because they have to actually add some proof of work to them. And I guess the idea would be like a wallet would scan that automatically. Yeah. Exactly. Yeah. That's what Joy Joy Market can do that. Yeah. The biggest trade off being and I mean, this is how Joy Market used IRC for kind of a message board type of situation. But but the biggest trade off being that your public key needs to be exposed, which in

1568
02:29:50.900 --> 02:29:57.595
non Taproot times is you've you've already spent from that address. But but post Taproot, that could be extra useful.

1569
02:30:05.860 --> 02:30:07.480
Say you look at a joint market transaction

1570
02:30:07.940 --> 02:30:19.255
and you see the change output and you can figure out what the corresponding input is. There are ways what you can either guess or even completely know what the input corresponding to an output is. And since inputs publish pub keys

1571
02:30:19.635 --> 02:30:22.535
in their script sigs or or witnesses now, nowadays,

1572
02:30:23.390 --> 02:30:25.090
it didn't actually turn out to be a big limitation.

1573
02:30:25.470 --> 02:30:35.314
Joining with the reused address. Right? No. No. No. No. No. That's what I'm trying to say is that imagine you just did an order and repaying them. Right? Suppose you use 1 in suppose you use 1 input and you got one output and one change.

1574
02:30:35.935 --> 02:30:46.620
Then I, as the scanner, come along, look at either the output or the change, doesn't matter. And I know that and I don't know. Now that's the point is that you I've got a 5050 chance that the output or the change,

1575
02:30:47.240 --> 02:30:51.886
are the same owner as the input. So in that scenario, I could even just make 2 proposals.

1576
02:30:52.426 --> 02:30:55.085
1 in which I use the the the spending output

1577
02:30:55.466 --> 02:31:02.800
and the pub key of the input, and the other one in which I use the change output of the pub key of the input. And in in one of those two cases, I will be correct in my assumption

1578
02:31:03.340 --> 02:31:04.159
that the UTXO

1579
02:31:04.895 --> 02:31:15.930
is the same o has the same owner as the input had, and therefore, that public key will be owned by the same person who owns that UTXO, and therefore, they will be able to decrypt the proposal and sign and and broadcast transaction.

1580
02:31:16.630 --> 02:31:27.915
So you use you you don't use the reused address, but you use the reused pub key. Yeah. The the first proposal was based on the idea of reused address because therefore, you definitely know what the public key is. And as you say in Taproot,

1581
02:31:28.455 --> 02:31:33.490
as you say in Taproot, that removes that whole problem is entirely removed because you have the public key anyway. But yeah.

1582
02:31:33.870 --> 02:31:51.450
It's it's a detail, really. Yeah. That's a thing I think that, that's worth mentioning here, waxing mixed over. There's a cryptographic scheme where you can given a pop key, you can create another key pair from it that Oh, yeah. Yeah. Yeah. Yeah. This pop key will know, but you can calculate. So you can use this to not reuse addresses.

1583
02:31:52.470 --> 02:32:01.235
Yeah. So so the idea is is the the the the term is often used as tweak, t w e a k. I'm not quite sure why. It's just addition of cryptic. It looks like curve points.

1584
02:32:02.095 --> 02:32:04.755
Yeah. You just basically you take the original,

1585
02:32:06.630 --> 02:32:14.329
script pub key of the address and you just or the the the key corresponding. And, oh, sorry. The the key of the input, which you're using, that's the the key that you've, like,

1586
02:32:14.984 --> 02:32:29.870
connected to and said, right. I'm gonna use this for encryption. But you can also take that key and add a random number to it times, you know, the base point, and you get a new entirely new public key that only the recipient will know the private key of. Even though you were able to construct the public key of it,

1587
02:32:30.330 --> 02:32:35.535
as the sender, the recipient will be the only one who can, like, access it as a private key. Yeah.

1588
02:32:35.915 --> 02:32:37.535
It's kinda I I didn't wanna give

1589
02:32:37.995 --> 02:32:48.100
details, but, you know Yeah. Yeah. But it's a big, like like, at least for me, it was a big light bulb moment that it's a big thing that makes this whole team actually work. Yeah. As you yeah. It doesn't work without that for sure. Yeah.

1590
02:32:48.720 --> 02:33:12.925
Mhmm. Anyway, so how do how do we think that, like, snake rule will actually be used, or is this just a Well, what I like about something like this is that it almost it's it's one of those things you could just put put out there into the world and, like, people can find use in it or not. Right? Right. Because if, like, 10 people use it, it's, like, kind of a net benefit for everyone. Right? Well, there's that, but I just mean the fact that there's so little, like, interlocking or or dependency

1591
02:33:13.385 --> 02:33:14.445
between the participants.

1592
02:33:15.851 --> 02:33:16.431
Are the

1593
02:33:18.330 --> 02:33:24.270
you don't really need to do anything, to be honest, to, like, get people to use it. It's not like you don't have to coordinate a bunch of people together.

1594
02:33:24.686 --> 02:33:30.226
The only thing that people have to agree on is where there's where there's an an onion out there, an onion service

1595
02:33:30.686 --> 02:33:38.800
that can that's got a list that they can just query or or they can either add items to a query, and you can have multiple of those, and you can have make up your own one. I don't care.

1596
02:33:39.261 --> 02:33:43.745
I mean, I've written a a server. People can use that server if they want or just use their own server.

1597
02:33:45.085 --> 02:33:48.439
Do you see what I mean? It's like it's the whole point, it was try to disentangle

1598
02:33:48.740 --> 02:34:12.370
the the coordination of users. That was the whole thing to me. In a world where there were thousands or hundreds of thousands of people using it, which is ridiculous, but if in such a world, it will be really cool because you could actually use it to make payments because there'd be, like, a bunch of people out there. You could, like you what you can do is sweeten the pot by making just like in join market, an incentive where instead of just making an equal output coin join where both people get back exactly their coins,

1599
02:34:12.750 --> 02:34:18.595
you could make it so the receiver end actually gets a little bit more. And then there'll be tons of people out there scanning

1600
02:34:19.055 --> 02:34:20.095
to, like, make a

1601
02:34:20.975 --> 02:34:51.676
to to just for any snicker that, like, proposal that turns up, and it might be that you could send I would actively do that. Like, if I could actively Yeah. Easily scan to see if if if someone was trying to snicker with me, I would do it. Yeah. So there's there's a tool in there called snicker finder that actually, I should mention it because it also lets join market users using the minus j flag to the to the script. It allows them to just scan the chain for join market coin joins, but they can also use it to scan for snicker coin joins at the same time. And I assume you're not I assume you're not concerned about trademark infringement here.

1602
02:34:52.375 --> 02:34:57.355
I mean, what? You mean that yeah. That bee is candy. No. It needs an s on the end, right, for that.

1603
02:34:58.000 --> 02:35:02.820
It's not Snickers, freaks. It's important that that we we make it clear. It's just Snicker.

1604
02:35:03.200 --> 02:35:05.300
I just have a thought. So,

1605
02:35:05.855 --> 02:35:09.155
Waxwing, do you think it makes sense to combine the snicker noninteractivity

1606
02:35:09.535 --> 02:35:10.835
with CoinJoin XT?

1607
02:35:11.215 --> 02:35:14.755
So using snicker would actually produce these multi transaction

1608
02:35:15.681 --> 02:35:16.420
coin joints.

1609
02:35:16.960 --> 02:35:23.061
The thing about yeah. Possibly, yes. The benefit there would be Mhmm. Go on. The the advantages then in distinguishability.

1610
02:35:23.535 --> 02:35:25.715
It'll be a snicker that no one knows is a snicker.

1611
02:35:26.255 --> 02:35:27.155
Yeah. But I think,

1612
02:35:27.695 --> 02:35:39.851
I was gonna say is that the only limitation on snicker, it's a big limitation, is it's currently only 2 party. It can't really be more because you just want this one way flow. I I don't think you can make this one way flow with 3 or 4 or 5 parties.

1613
02:35:40.476 --> 02:35:46.016
But, given that limitation, you can see do a coin to an XT with just 2 people. 2 party. Yeah.

1614
02:35:48.590 --> 02:35:51.649
I don't see an obvious limit to a problem with,

1615
02:35:52.510 --> 02:35:54.770
I'd have to go back at the coin joint XT, like,

1616
02:35:55.149 --> 02:36:00.315
workflow because you have to multisign. No. I think you have no because you have to multisign every step of the graph.

1617
02:36:00.855 --> 02:36:02.875
So I don't think you can do it noninteractively.

1618
02:36:04.135 --> 02:36:06.950
Oh, I see. Yeah. Yeah. I'm not I'd have to go and check. You can

1619
02:36:07.511 --> 02:36:11.940
Multisign both and then oh, I don't know. It's tricky. I'm not going yeah.

1620
02:36:13.785 --> 02:36:20.125
Yeah. Because because Contrin XT is like one of those protocols very similar to lightning where the it's entirely based on that idea

1621
02:36:21.580 --> 02:36:22.880
that everyone signs

1622
02:36:23.420 --> 02:36:31.715
upfront by having, like, specific, like, anchor multisig outputs. So nothing will happen unless everyone agrees. You know? So that involves some interactivity.

1623
02:36:36.335 --> 02:36:37.395
Yeah. That's fine.

1624
02:36:39.930 --> 02:36:42.189
The this is fantastic so far.

1625
02:36:43.210 --> 02:36:45.710
I I I love the back and forth between you guys.

1626
02:36:46.354 --> 02:36:49.655
61 and 2 is getting blocked. I'm reading what he's saying.

1627
02:36:52.354 --> 02:36:53.415
Whereas with

1628
02:36:56.670 --> 02:37:00.450
yes. Yes. 61 to 2. I think I think we understand what you're saying.

1629
02:37:01.275 --> 02:37:02.976
Chris, correct me if I'm wrong.

1630
02:37:04.715 --> 02:37:06.655
61 to 2 is saying that,

1631
02:37:07.995 --> 02:37:12.760
with coin join, like, obviously, the heuristic is visibly broken with coin swap.

1632
02:37:13.940 --> 02:37:27.960
They don't know if it happens, so they have no way to factor it in. Mhmm. The the I I I I think we've made that clear. Right? I think so. Yeah. But my my point there was that because it's visibly broken. Someone who's using the the heuristic,

1633
02:37:28.580 --> 02:37:30.680
an analyst can exclude those transact

1634
02:37:31.220 --> 02:37:47.530
so it Right. Will be visibly broken, and then that makes it not broken, If you see what I mean when they exclude it, Chris. I love when they I love when they say I love when they say just, like, Altcoin join Altcoin joins illicit behavior because our fucking tools cannot unwind it, and that's fantastic to me. Yeah.

1635
02:37:48.150 --> 02:37:49.210
Okay. Fine.

1636
02:37:49.830 --> 02:37:58.325
So I have I have, I mean, look look, I I think it's important that we flex on these people. We can't let, like, the compliance bros just think, like, they can run this shit.

1637
02:37:58.944 --> 02:38:00.885
The whole point of Bitcoin is

1638
02:38:01.890 --> 02:38:03.750
is is civil disobedience.

1639
02:38:04.290 --> 02:38:05.270
Right? And,

1640
02:38:05.650 --> 02:38:08.311
you know, I might co host on rabbit hole recap,

1641
02:38:08.785 --> 02:38:20.061
who he's, like, fucking livid at fat for every week and shit, and they listen to the podcast. That's great. But let's put that liveness on chain, you know, like, let's let's make it clear to them on chain forever,

1642
02:38:21.000 --> 02:38:23.740
that we disagree. I wanna see the percentage of

1643
02:38:24.520 --> 02:38:32.205
of equal output coin joints go up. I don't wanna I don't wanna see it sit at 2% or 3% of the chain. I wanna see it go to fucking 45%

1644
02:38:32.585 --> 02:38:39.311
of the chain. I want I want these guys to be, like I want them to go into a meeting and be, like, we have no idea what the fuck is going on.

1645
02:38:40.410 --> 02:38:44.830
And and and it's visible. It's obvious. Like, let's fucking do it.

1646
02:38:45.936 --> 02:38:47.476
So I have 2 more questions,

1647
02:38:49.136 --> 02:38:54.310
that are I think are really important. First of all, I'm curious on your guys' opinions of bisque.

1648
02:38:54.710 --> 02:39:02.329
The people that are watching the video right now, bisque is pumping. We're almost at 63 k. That's the bottom that's the bottom price.

1649
02:39:02.705 --> 02:39:04.645
The top price is the evil empire.

1650
02:39:05.104 --> 02:39:06.245
The most liquid

1651
02:39:06.945 --> 02:39:09.285
spot exchange in the world for Bitcoin

1652
02:39:09.641 --> 02:39:19.145
is Coinbase Pro, and they're about to go public. They have a surveillance company, and they're fucking evil. They're trading at 58 k. Bisc is trading almost at 63 k.

1653
02:39:19.524 --> 02:39:26.630
What is what is your opinion on Bisc? Do you think Bisc can scale? Do you think Bisc is an important project? Do you have any critical views here?

1654
02:39:29.830 --> 02:39:31.189
Do you wanna go Well, I I

1655
02:39:31.910 --> 02:39:38.516
sure. Yeah. I I was I was around. I don't think Chris was as well when when Manfred first came up with this whole Bittsquare thing, and,

1656
02:39:39.395 --> 02:39:42.455
he was very enthusiastic. And I think it's really good that we

1657
02:39:42.835 --> 02:39:44.275
have those kind of,

1658
02:39:46.610 --> 02:39:47.591
like, in principle

1659
02:39:47.971 --> 02:39:51.511
that that those things that exist that are peer to peer, of course,

1660
02:39:52.051 --> 02:39:57.465
it's always gonna struggle at at the fear, like, edge because it's at the fiat edge.

1661
02:39:58.085 --> 02:39:59.545
And I'm I'm presumably,

1662
02:40:00.005 --> 02:40:04.660
it's people often say, oh, there isn't enough liquidity. Well, I mean, people have trouble,

1663
02:40:05.200 --> 02:40:13.061
doing any more than, I guess, small amounts of trade on such platforms because, you know, you're moving money into and out of bank accounts. And

1664
02:40:13.586 --> 02:40:18.546
it's all about the bank accounts, ultimately. Everything else is fine. I mean, I've used the software myself. I think it's,

1665
02:40:19.586 --> 02:40:22.950
I mean, it's obviously evolved over the years, and I think it's got a lot better.

1666
02:40:24.770 --> 02:40:32.204
I think it's I think it's good, but I'm I'm not surprised the the volume's alone. Let's just say that It's because of the oh, the fear volume specifically are low. Yeah.

1667
02:40:33.225 --> 02:40:38.680
I mean, if we look at the volume, I mean, the volume is, like, there there's been point there's been 30,000,000

1668
02:40:39.060 --> 02:40:40.680
sats traded on

1669
02:40:41.780 --> 02:40:44.920
on BISK today in the USD market,

1670
02:40:46.905 --> 02:40:50.345
and there's been over 5,000 Bitcoin traded on,

1671
02:40:51.065 --> 02:40:54.330
on Coinbase today. Yeah. So we're not even close.

1672
02:40:54.970 --> 02:40:57.710
The the the fee outside is the concern, obviously.

1673
02:40:58.250 --> 02:41:02.350
To be fair to them, it's not really a comparable figure. Right? Because one of them is an internal database

1674
02:41:02.726 --> 02:41:04.645
transfers going on, you know, between,

1675
02:41:04.966 --> 02:41:06.186
users, or the other one

1676
02:41:06.565 --> 02:41:17.319
is transfers into and out of bank accounts. Right? I mean, I mean, it's still obviously ridiculously huge difference, but I'm just saying it's not actually directly Right. I mean I mean, on on on that note on that note, let's just quickly

1677
02:41:17.779 --> 02:41:19.635
let's just quickly remind everyone

1678
02:41:19.955 --> 02:41:20.455
why,

1679
02:41:21.154 --> 02:41:25.415
like, why we're in this space in the first place. Let's go. Yeah. To you, Bisc.

1680
02:41:27.311 --> 02:41:29.650
There are many places to buy Bitcoin.

1681
02:41:30.270 --> 02:41:32.290
They collect your personal information

1682
02:41:33.230 --> 02:41:35.011
and jeopardize your privacy.

1683
02:41:36.476 --> 02:41:39.215
K y c is the illicit activity.

1684
02:41:41.115 --> 02:41:42.495
This is open source.

1685
02:41:42.875 --> 02:41:44.990
It does not collect user data.

1686
02:41:45.450 --> 02:41:47.230
You keep your private keys,

1687
02:41:47.770 --> 02:41:53.285
create or take offers to trade peer to peer, and keep your Bitcoin private and secure.

1688
02:42:00.250 --> 02:42:00.750
Cool.

1689
02:42:01.289 --> 02:42:05.310
This is civil dispatch. We only do mid rolls for open source projects.

1690
02:42:06.855 --> 02:42:09.195
Wait. So just someone understand why is

1691
02:42:10.295 --> 02:42:14.235
why is this Bitcoin's more expensive? Are people paying for

1692
02:42:14.740 --> 02:42:15.800
privacy, for example?

1693
02:42:16.819 --> 02:42:17.319
Question.

1694
02:42:18.340 --> 02:42:19.319
Does someone know?

1695
02:42:20.100 --> 02:42:27.385
I mean, I I I think it's just a liquid. It's just very there's very little liquidity. It goes up and down dramatically in both directions.

1696
02:42:28.645 --> 02:42:31.705
So it's so sometimes It does sometimes trade at a discount.

1697
02:42:32.070 --> 02:42:42.055
It would we've I mean, for the last 3 hours of this show, we've been trading at both the discount and the premium. If we go back and forth, it's just Oh, I see. So it's just a very wide market. Yeah.

1698
02:42:42.774 --> 02:42:43.755
Oh, okay. Yeah.

1699
02:42:45.255 --> 02:42:49.354
Just to all the bisque freaks out there, like, if you want to create

1700
02:42:49.680 --> 02:42:50.420
bisque video content,

1701
02:42:50.960 --> 02:42:53.220
like, I will fucking put it on the show.

1702
02:42:54.079 --> 02:42:57.915
So if yeah. That was great. That was from Pedro who That was good. Yeah. Free.

1703
02:42:59.115 --> 02:43:02.655
It's good. I mean, we we put it in, like, every every two episodes,

1704
02:43:03.035 --> 02:43:05.215
the freaks get hit with that mid roll. So,

1705
02:43:06.800 --> 02:43:08.500
and obviously, they pay us nothing.

1706
02:43:09.120 --> 02:43:14.735
I think people should use Bisq, but I I do agree that like, look, bank accounts are at the end of the day

1707
02:43:15.136 --> 02:43:16.436
always gonna be an issue.

1708
02:43:16.895 --> 02:43:19.395
You you're never gonna be able to decentralize bank accounts,

1709
02:43:20.255 --> 02:43:26.641
and it it it is what it is. Like, always cash will be best, but I expect that cash is going to,

1710
02:43:28.700 --> 02:43:33.975
cash is already getting phased out. Yeah. Whether that's peers who who who care about convenience

1711
02:43:34.595 --> 02:43:37.015
or whether that's governments that care about surveillance,

1712
02:43:38.120 --> 02:43:41.420
Cash is getting phased out, but obviously, cash is king,

1713
02:43:42.040 --> 02:43:44.220
when it comes to buying Bitcoin.

1714
02:43:47.355 --> 02:43:52.095
I think Yeah. This and and I'm saying this from a point of view,

1715
02:43:52.715 --> 02:43:54.655
I'm a massive supporter of this,

1716
02:43:56.250 --> 02:43:57.630
and I fucking love Wiz,

1717
02:43:58.890 --> 02:44:01.310
who's one of the the lead maintainers of Bisc.

1718
02:44:04.170 --> 02:44:04.670
But

1719
02:44:07.625 --> 02:44:08.846
it it's it's,

1720
02:44:09.226 --> 02:44:12.445
you know, it it it is what it is. The the

1721
02:44:12.860 --> 02:44:18.160
it is our last gap, but, the the the fiat side is always gonna be more difficult.

1722
02:44:19.020 --> 02:44:19.580
So I have

1723
02:44:20.255 --> 02:44:26.035
I mean, Chris, you have an opinion on Bisc? We heard Waxwing's opinion on Bisc. You have an opinion on Bisc? Yeah. It's just

1724
02:44:26.654 --> 02:44:32.760
basically the same as Waxwing's. Like, great projects, and I wish it the best. And, hopefully, its volume will go up. And,

1725
02:44:33.560 --> 02:44:46.655
there is actually a point. The thing of Coinbase and these centralized exchanges, you probably have people on them who are actually day trading. Like, they buy and sell many times in the same day. And I don't know if that happens with Bisk, so that might make the the volume Oh, 100%. A 100%

1726
02:44:47.155 --> 02:44:55.716
centralized exchanges. But, dude, it's it's a difference between 5,000 Bitcoin. Okay? So so even even if it's You're right. You're right. We're not even close. But,

1727
02:44:56.436 --> 02:45:01.655
61 and 2 mentioned postal money order in the United States is the most private way of doing it.

1728
02:45:02.750 --> 02:45:05.729
I wonder 61 to 2 if you dox yourself a little bit there.

1729
02:45:06.590 --> 02:45:07.090
But,

1730
02:45:07.790 --> 02:45:09.570
that is the best way in America.

1731
02:45:12.105 --> 02:45:12.925
Bisque is,

1732
02:45:14.345 --> 02:45:15.965
yeah, Bisque is fantastic.

1733
02:45:16.425 --> 02:45:17.965
My biggest issue with Bisque,

1734
02:45:19.145 --> 02:45:34.436
is is that it is very obvious on change. So I want people to realize, like, if you transact with Bisk, like, if you look at that on chain, that's there forever that you bought Bitcoin through Bisk. So, obviously, after after you receive Bitcoin from Bisq, you should put it into join market

1735
02:45:34.895 --> 02:45:36.370
and and CoinJoin it.

1736
02:45:36.930 --> 02:45:39.110
And then everyone will know you coin joined it,

1737
02:45:39.730 --> 02:45:40.470
as well.

1738
02:45:41.570 --> 02:45:44.070
But at least we flex on we flex on the haters.

1739
02:45:45.516 --> 02:45:59.040
To keep in mind here, that doesn't change anything for BlockFi. BlockFi is going to block you whether or not you use Bisq or whether or not you use CoinJoin. So no one gives a shit there, so at least your trust you're, like, protecting yourself against your counterparty.

1740
02:46:00.859 --> 02:46:03.200
And people who are against Bitcoin privacy

1741
02:46:03.775 --> 02:46:07.155
probably have never received Bitcoin in exchange for goods and services.

1742
02:46:08.016 --> 02:46:10.355
I mean, I got paid in Bitcoin the other day.

1743
02:46:11.510 --> 02:46:14.170
Like, I don't want I don't I don't want,

1744
02:46:14.630 --> 02:46:16.569
the company that paid me in Bitcoin,

1745
02:46:17.510 --> 02:46:21.136
to know my future transactions. Of course, I'm gonna fucking put it through CoinJoin.

1746
02:46:21.676 --> 02:46:23.615
Like, this is a very Yeah.

1747
02:46:23.995 --> 02:46:31.149
The the the these questions that we receive are from people who are not actually using Bitcoin on a day to day basis.

1748
02:46:32.810 --> 02:46:38.109
So I have 2 more questions for you guys before we wrap this up, and before I give you your final thoughts.

1749
02:46:40.095 --> 02:46:42.515
Do you have do you guys have opinions on Liquid?

1750
02:46:45.695 --> 02:46:46.195
Chris?

1751
02:46:48.680 --> 02:46:49.640
So liquid is,

1752
02:46:51.960 --> 02:47:03.935
I'd I'd suppose it's good. I've never used it myself, and I suppose it's okay. There's a I suppose the reason I've never used it, there's the custodial aspects, which isn't the point that it's useful for traders. And then if you're exchanging between many exchanges,

1753
02:47:04.270 --> 02:47:06.851
you can do that right No. That's bullshit. With small privacy.

1754
02:47:07.311 --> 02:47:11.230
That's bullshit. I don't know. I I I told them I told them

1755
02:47:13.255 --> 02:47:19.515
I I it that that's just poor marketing. I mean, lightning lightning is gonna dominate between exchanges.

1756
02:47:20.591 --> 02:47:24.290
Like, large private channels between exchanges are gonna dominate.

1757
02:47:25.630 --> 02:47:28.290
They can market however they fucking they want to market,

1758
02:47:29.194 --> 02:47:29.694
but,

1759
02:47:30.955 --> 02:47:39.000
but but but private lightning private lightning channels are gonna dominate there. It makes more sense. Like, why are you gonna trust the federation when you could do a private lightning channel,

1760
02:47:39.780 --> 02:47:55.360
and get all the benefits without any kind of you don't you don't have that custodial risk. You don't have to deal with the federation. You don't have to deal with the regular regulatory risk. You just have to deal with the other exchange that you have the private lightning channel with, and and and public lightning could fail,

1761
02:47:55.900 --> 02:47:57.360
but but private lightning

1762
02:47:57.979 --> 02:47:59.920
still makes a 100% sense.

1763
02:48:00.300 --> 02:48:21.285
Mhmm. I mean, there is there is there is a counterargument, but there is a counterargument. I remember Adam Back sort of saying this a few times. It's like, well, you did the sort of capacity issues with channels. I I tend to bring you Blackpink. But tends to be rude. Sense for p2p. That makes more sense for p2p. Like, I don't need capacity. I shouldn't have to to have inbound capacity to receive a payment from you p2p,

1764
02:48:21.824 --> 02:48:24.324
but an exchange can fucking have Bitfinex

1765
02:48:24.625 --> 02:49:00.930
give them fucking inbound if they need to receive a payment. But, you know, I mean, if there's, like, 10 exchanges and they all wanna have, you know, a 100 millions worth of the ability to move a 100,000,000 between them at any one moment, then then it tends to, like, magnify the amount of capacity you need to have. No. But they could root. Right? You don't have to have a 100,000,000 of each one. They could have a, like, 2 or 3 channels then route by them. Yeah. But Yeah. And you still need and and and liquid doesn't solve that. You still need to have the equivalent amount of liquid Bitcoin ready to go. Yeah. And then you're storing it in a fucking custodial federation instead instead of just you and like, if I'm bidstamped

1766
02:49:01.310 --> 02:49:02.770
and I need to send $2,000,000

1767
02:49:03.470 --> 02:49:05.090
quickly to Bitfinex,

1768
02:49:05.545 --> 02:49:09.245
like, I'm gonna have a trusted relationship with them. We're gonna have a private lightning channel.

1769
02:49:10.984 --> 02:49:15.005
I mean, I'm I'm I'm big believer in this general concept of Yeah. It makes sense.

1770
02:49:15.530 --> 02:49:19.070
Not yeah. But then liquid liquid makes more sense to me

1771
02:49:19.690 --> 02:49:20.250
as, like,

1772
02:49:21.050 --> 02:49:30.635
we have confidential transactions on it, and and p to p, I don't need to have inbound. It's like socialized inbound. It's like as long as you're in the system, you have inbound.

1773
02:49:32.160 --> 02:49:32.660
Right?

1774
02:49:33.040 --> 02:49:33.540
Well,

1775
02:49:34.880 --> 02:49:45.596
it does I don't I don't think ordinary users are gonna find much of a use case for it. I mean, in theory, yeah, it could be like a good privacy tool, but they already have, like, Altcoins that do something similar. I don't know.

1776
02:49:45.976 --> 02:49:46.476
Maybe.

1777
02:49:46.870 --> 02:49:50.330
I I I never really thought about it too hard. It never really struck me

1778
02:49:50.790 --> 02:49:57.965
as something I personally wanna investigate. I do like the elements project, and I do I do like all the tech that they've pushed forward in that in that realm.

1779
02:49:58.285 --> 02:50:12.080
But the the the the product itself, yeah, maybe it's just mainly aimed at businesses, and and it's not so interesting to us. But it shouldn't be. That's my point, Waxwing. Like, I use You're using the opposite. Right? Yeah. You're using the opposite. No. No. So so so if if I'm withdrawing from an exchange, right,

1780
02:50:12.605 --> 02:50:18.386
and I withdraw through lightning, they know my pub key, and they can white list me. Like, they could be, like,

1781
02:50:18.766 --> 02:50:23.020
send me a and and and companies are doing this. Send me a,

1782
02:50:23.880 --> 02:50:27.820
you know, a 100 sat transaction to prove that you own the lightning node.

1783
02:50:28.295 --> 02:50:32.154
And now I have your public key registered, and then I'll withdraw it to lightning.

1784
02:50:32.455 --> 02:50:42.149
And then I have I have inbound capacity restraints. Like, I don't know, Like, what? I gotta loop out, do all this bullshit that, like, Bosworth tells me I have to do. I'm gonna, like, fucking go to, like,

1785
02:50:42.689 --> 02:50:51.364
because I gotta go to liquidity market and, like, go pay 10% or whatever to our boy, Anthony, who's in the comments, and, like, get my inbound liquidity. With liquid,

1786
02:50:51.840 --> 02:50:52.659
I could withdraw

1787
02:50:53.040 --> 02:50:53.540
everything

1788
02:50:54.319 --> 02:50:55.540
to multiple,

1789
02:50:57.520 --> 02:51:02.125
you know, liquid addresses. With confidential transactions, it doesn't show up on the liquid chain,

1790
02:51:03.244 --> 02:51:05.104
and then I could swap out

1791
02:51:05.725 --> 02:51:06.864
to proper Bitcoin

1792
02:51:07.165 --> 02:51:08.225
or proper Lightning

1793
02:51:09.200 --> 02:51:15.540
after the fact. Like, there's there's major privacy improvements if I could withdraw via Liquid. If I withdraw via Lightning,

1794
02:51:16.845 --> 02:51:19.024
I don't really get any privacy improvements.

1795
02:51:20.285 --> 02:51:22.225
There there's a there's a use case

1796
02:51:22.845 --> 02:51:23.665
for p2p.

1797
02:51:24.285 --> 02:51:26.305
There's a use case for the average user

1798
02:51:26.740 --> 02:51:29.560
on liquid that is not being addressed, really.

1799
02:51:30.580 --> 02:51:32.040
I see what you mean. Yeah.

1800
02:51:32.660 --> 02:51:39.455
And, also, it would cost possibly cost less than minor fees because it's a side chain. So it's Sure. Basically free transfers.

1801
02:51:40.475 --> 02:51:41.775
Yeah. That might make sense.

1802
02:51:42.235 --> 02:51:54.305
Right? Like, I I would love. I I would do my dollar cost average. If I if I have my auto stacking or like, this is what I'm talking about. Like, you guys are, like, you're on a whole different level. If I'm doing my auto stacking through

1803
02:51:55.085 --> 02:51:57.585
through fucking liquid, that'd be fucking fantastic.

1804
02:51:58.125 --> 02:52:07.320
I do my auto stacking through liquid and I swap out when I wanna swap out in a private way, and then that's from a different provider. Maybe that provider is from Singapore or something.

1805
02:52:08.181 --> 02:52:11.400
It disconnects it disconnects me from that KYC record.

1806
02:52:14.965 --> 02:52:18.460
I'm not sure where that makes sense. The problem is no one uses it.

1807
02:52:19.260 --> 02:52:21.840
I'm not pretending that liquid isn't garbage.

1808
02:52:22.860 --> 02:52:27.760
It is fucking a mess right now, but if if people used it, it could be useful.

1809
02:52:29.005 --> 02:52:44.270
It's true of a lot of things, isn't it? Yeah. It's like with with many things, you have to bother the other person to also use it, like, pay join and everything and stuff. Well, anyway, Freaks, you should go try Liquid. Go go try it out. SideSwap go download the SideSwap app and just, like, not sponsored.

1810
02:52:44.686 --> 02:52:45.426
It's on,

1811
02:52:45.966 --> 02:52:51.745
it's on Green Wallet, isn't it? I've got that one. Maybe I could have a quick look at it. Yeah. Green Wallet Green Wallet has liquid

1812
02:52:52.150 --> 02:52:53.670
built into it. Come on. And,

1813
02:52:54.390 --> 02:52:57.930
they have aqua on iPhone. There's also the actual full mode.

1814
02:52:58.925 --> 02:53:02.545
And there's also the full mode, and you can Yeah. Chris. Chris, no one's gonna use that.

1815
02:53:03.885 --> 02:53:09.350
No one's running a full liquid. Okay? I'm not I'm not I'm not trying to I'm not trying to broadcast,

1816
02:53:10.290 --> 02:53:12.390
It's probably really easy. Fairy tales.

1817
02:53:13.729 --> 02:53:21.335
You just 61 and 2 fine. Yeah. 61 and 2 is in the comments. 61 to 2 actually runs an elements node. He he says that people should peg in.

1818
02:53:21.955 --> 02:53:29.720
That just that just reminded me. The very first time I I I literally, in my entire life, have never used Bitcoin QT, but I did run Elements QT once.

1819
02:53:30.260 --> 02:53:31.880
It's nice. It's very clean.

1820
02:53:32.500 --> 02:53:43.340
Probably is now. When I did it, it was it was just pretty basic. But yeah. 60102. We know it's trivial. He's ask he's mentioning that it's trivial to run your own Yeah. I can That's the cool part. That's the cool part.

1821
02:53:44.060 --> 02:53:49.280
I just don't think the majority of people are gonna use it. I don't think that matters. But, yes, I do agree that it is trivial.

1822
02:53:51.055 --> 02:53:53.234
The last thing I wanted to bring up was

1823
02:53:55.614 --> 02:53:56.914
so we do have,

1824
02:53:58.200 --> 02:54:01.260
we have so far, we have 2 coinjoin implementations

1825
02:54:01.561 --> 02:54:03.500
that involve a centralized coordinator.

1826
02:54:05.945 --> 02:54:07.485
I know there's a lot of controversy

1827
02:54:08.105 --> 02:54:09.965
about those 2 implementations.

1828
02:54:11.385 --> 02:54:17.190
I'm not really trying to dive into the controversy, but if you guys wanna dive into it, I'm happy to dive into it.

1829
02:54:18.530 --> 02:54:20.551
Really, what I wanted to bring up was

1830
02:54:21.090 --> 02:54:24.471
the cool part about join market is it doesn't need a centralized coordinator.

1831
02:54:25.055 --> 02:54:25.875
But if regulators

1832
02:54:27.135 --> 02:54:30.114
don't care about centralized coordinators and they just

1833
02:54:30.734 --> 02:54:31.954
allow that to happen,

1834
02:54:32.420 --> 02:54:36.500
Do you would do you guys revise your thesis there? Like, do you think

1835
02:54:36.979 --> 02:54:38.359
if we can get the advantages

1836
02:54:38.660 --> 02:54:40.760
of a blinded centralized coordinator

1837
02:54:41.485 --> 02:54:44.545
that uses Tor, so doesn't really know that much information,

1838
02:54:45.165 --> 02:54:46.625
but might be regulatory,

1839
02:54:49.245 --> 02:54:50.625
liable for things.

1840
02:54:52.700 --> 02:55:00.845
Is there use there? Like, is there an advantage there to use the tools that we have available to us if regulators aren't going to attack them?

1841
02:55:02.205 --> 02:55:10.465
I suppose the advantage is because it's centralized, they can have an income from the CoinJoints and that could Right. That means they can pay programmers to make the product really nice.

1842
02:55:11.150 --> 02:55:17.570
And they're making a lot of money. Like, that's always the thing of close source and This is not hypothetical, Chris. Yeah. Yeah. Exactly. Like, they're making a lot of money.

1843
02:55:17.950 --> 02:55:18.450
Yeah.

1844
02:55:19.555 --> 02:55:20.295
Yeah. Yeah.

1845
02:55:21.475 --> 02:55:30.850
Well, they I don't think I think regulators will eventually, like, focus on them because it's such a it's such a centralized choke point. Why wouldn't you? And so the stroke of a pen, you can force them to

1846
02:55:31.229 --> 02:55:33.310
do stuff. And, also, you know, they,

1847
02:55:34.189 --> 02:55:38.290
these these coordinators, as we said before, they can do a civil attack. So they can,

1848
02:55:38.865 --> 02:55:42.564
for example, the regulator could say, watch for this UTXO. And if it gets,

1849
02:55:43.425 --> 02:55:58.655
if it gets proposed for a coin join, then you have to add your own inputs Oh, 100%. Attack and find out or Well, I've been I've been very clear to the freaks. I've been very clear to the freaks, and I think that it should be we should repeat it right now since especially since you mentioned it,

1850
02:55:59.035 --> 02:56:00.255
is that these

1851
02:56:00.635 --> 02:56:01.135
centralized

1852
02:56:01.761 --> 02:56:04.900
coordinated coin joins, whether that's with Sabi or Samurais,

1853
02:56:06.160 --> 02:56:09.381
do not provide protection from the coordinator itself,

1854
02:56:10.325 --> 02:56:16.665
because the civil protection is the coin joint fee, and that is paid to the coordinator. So the coordinator is paying it to themselves.

1855
02:56:17.020 --> 02:56:22.801
Yeah. And with Sabi, it's even worse because they actually make more money if they Sybil.

1856
02:56:24.575 --> 02:56:31.795
Right. But but I that that is not mentioned enough. We we mention all the time on this show. I think it's a very important concept to mention.

1857
02:56:32.200 --> 02:56:38.460
But when you combine that with this idea, like, the custodial mixers, right, that were very popular and

1858
02:56:38.920 --> 02:56:41.180
arguably very effective if they weren't

1859
02:56:42.074 --> 02:56:42.574
honeypots.

1860
02:56:44.715 --> 02:56:46.415
It's it's not the worst scenario.

1861
02:56:47.435 --> 02:56:48.895
Am I wrong in that regard?

1862
02:56:49.780 --> 02:56:54.840
Yeah. I mean, if it works and if you if your enemy isn't these regulators, then it's fine.

1863
02:56:57.354 --> 02:56:58.654
I mean, Gladstein

1864
02:56:59.035 --> 02:56:59.535
argues,

1865
02:57:00.075 --> 02:57:02.654
and I disagree with him, and he's my boy.

1866
02:57:03.115 --> 02:57:06.175
But I disagree with him because we can disagree with our boys publicly,

1867
02:57:07.070 --> 02:57:09.310
that if you're not, like as as

1868
02:57:09.870 --> 02:57:12.609
he's fine with Bitcoin privacy that is

1869
02:57:13.470 --> 02:57:15.890
in the threat model that trust the US government.

1870
02:57:16.255 --> 02:57:18.435
Right? And I I'm not cool with that,

1871
02:57:18.895 --> 02:57:20.274
but he's fine with that.

1872
02:57:21.375 --> 02:57:34.500
And I kinda feel like coordinated coin joints kinda fall somewhere in that that regard. Right? Yeah. Like, you're kinda I guess everyone chooses their own threat model in a sense. So if you're cool with the gov the US government, I suppose you could use those.

1873
02:57:35.655 --> 02:57:41.275
But you're like, the status quo is that everyone is just destroying themselves on chain.

1874
02:57:42.300 --> 02:57:42.800
Yeah.

1875
02:57:43.340 --> 02:57:43.840
Right?

1876
02:57:44.300 --> 02:57:55.795
So it's like any improvement is an improvement. Like, even if even if it requires a honeypot, like, fine. Like, okay, they got you. But they already got everyone else. Like, what what it Yeah.

1877
02:57:56.734 --> 02:58:03.080
Yeah. For sure. I I'd never tell people to not use wasabi or samurai. Like, if it's better it's better than nothing. Right.

1878
02:58:06.420 --> 02:58:08.120
Laxwing, you got opinion here?

1879
02:58:10.575 --> 02:58:13.795
Not not hugely. I mean, yeah.

1880
02:58:14.335 --> 02:58:16.675
I think, they're definitely viable models,

1881
02:58:16.990 --> 02:58:22.030
and I do like the fact I'm very I'm very, happy with the fact that you've honed in on the,

1882
02:58:23.630 --> 02:58:37.240
the weakness of the model with the was with regard to the incentive in civil, but it is a fairly minor I'm not saying it's theoretical. It's an actual weakness, but it's It's a massive weakness. Yeah. It is real, but I

1883
02:58:37.780 --> 02:58:43.800
in practice, these systems I mean, a a nice thing to remember, of course, is something like Wasabi and I think also Samurais

1884
02:58:44.945 --> 02:58:51.926
are open source, and it's not like we're totally tied to 1 provider like we are with these centralized exchanges. Right? They are actual software

1885
02:58:52.390 --> 02:58:57.290
Right. That we run. So if people if so if something goes wrong, people can swap to another one.

1886
02:58:58.149 --> 02:59:00.810
Presumably, we can have, like, an anonymous coordinator

1887
02:59:01.815 --> 02:59:05.595
that just, like, builds reputation based on, like, a web of trust.

1888
02:59:06.455 --> 02:59:07.175
And and

1889
02:59:07.655 --> 02:59:14.750
we could. Yep. And you kinda end up you you end up in a similar trust model as custodial mixers, to be quite honest.

1890
02:59:15.210 --> 02:59:20.085
Mhmm. But you end up in a situation where maybe regulators won't push

1891
02:59:20.705 --> 02:59:23.605
where where where custodial mixers is obvious

1892
02:59:24.280 --> 02:59:41.699
that a regulator is gonna fucking attack that. Right? But let's not forget, there is such a thing as coin shuffle plus plus. Right? I mean, there is no coin shuffle generally. Just the idea of, it is possible to build it in perfectly peer to peer, without coordinator and without anyone knowing anyone else's linkages,

1893
02:59:42.640 --> 02:59:53.305
implementation. It's So this is what Decred is using. Right? Yeah. I believe they did implement. I don't know whether with the plus plus or without, but I think they did implement one of that, Tim Ruffing's,

1894
02:59:53.925 --> 03:00:01.300
paper. It's a very excellent paper. I recommend people to read it. It's a very good idea. But Decred, like, they cheat a little bit because they have they have

1895
03:00:01.920 --> 03:00:03.460
the they have the proof of stake,

1896
03:00:03.840 --> 03:00:07.115
ticket system. So they have this, like, delayed time

1897
03:00:07.655 --> 03:00:09.756
proof of stake system that they're using

1898
03:00:10.375 --> 03:00:11.115
to incentivize

1899
03:00:11.575 --> 03:00:12.075
CoinJoin.

1900
03:00:12.860 --> 03:00:27.275
And and and the delayed time is very important in terms of civil resistance. But using it as a locking up funds. Yeah. They're using it as civil resistance. Yeah. But you actually get paid you actually get paid you you make money if you coin join in in Decred. And and

1901
03:00:28.040 --> 03:00:36.225
and I do I do remember when To be clear to be clear to the freaks that are listening, I believe every single asset is trending to 0 in terms of Bit

1902
03:00:36.705 --> 03:00:43.045
Bitcoin, including the Chrysler building and including Decred. I'm talking about every single asset, Apple stock, everything.

1903
03:00:44.869 --> 03:00:53.505
But with Decred, it's very interesting because they implemented this. They have a financial incentive. You make money if you coin join, and we're actually watching

1904
03:00:54.125 --> 03:01:00.145
we're watching that chain go dark. Like, we're watching the whole chain go into coin join, which is very cool.

1905
03:01:00.480 --> 03:01:10.055
Interesting. I didn't I didn't even know. I I remember the thing about them doing the project, but I was like like that Altcoin Dash, if you remember, where But Dash is garbage. Dash is like different story.

1906
03:01:10.435 --> 03:01:14.055
Yeah. Dash is like very shitcoin. Right? Like, that's like super scam.

1907
03:01:14.755 --> 03:01:17.495
Decred is also shitcoin, but it's it's

1908
03:01:18.551 --> 03:01:19.211
less scammy

1909
03:01:19.591 --> 03:01:23.450
in in in in that the actual there's actually an incentive.

1910
03:01:24.391 --> 03:01:26.891
There's actually an incentive that they've designed,

1911
03:01:27.795 --> 03:01:29.815
with their proof of stake, whatever,

1912
03:01:31.635 --> 03:01:40.250
that is that is providing an incentive to CoinJoin. Right? Like, you make money Coin Joining, and the whole chain is is is basically going dark right now.

1913
03:01:40.870 --> 03:01:42.890
Right? There there the whole chain is going CoinJoin.

1914
03:01:43.510 --> 03:01:44.890
Right? Like, so, like, you're

1915
03:01:45.436 --> 03:01:50.095
watching you're watching a higher and higher percentage of transactions go coinjoin because they make money.

1916
03:01:52.635 --> 03:01:56.200
I'm gonna I'm gonna read a little bit about their, I've just found their link

1917
03:01:56.740 --> 03:02:01.480
about their How is that different to join market where you can make money being a maker?

1918
03:02:03.695 --> 03:02:05.556
They make significantly more money.

1919
03:02:07.135 --> 03:02:07.635
Right.

1920
03:02:08.016 --> 03:02:08.516
Right.

1921
03:02:09.061 --> 03:02:17.801
But but the I think the more important well, okay. Maybe that is the more important thing. But the the other important thing is that they're using that coin shuffle plus plus protocol, that

1922
03:02:18.665 --> 03:02:30.910
really does kind of finally square off the rough edges of the the other implementations, I think, at least in theory, because it it doesn't it is it can be implemented purely peer to peer without, without a coordinator,

1923
03:02:31.851 --> 03:02:34.671
and it's still perfectly private, at least, you know, theoretically.

1924
03:02:38.305 --> 03:02:45.660
Yeah. I mean, I mean, it's the same concept as Joy Market. That was the cool part about Joy Market to me, right, Was that you can make money providing privacy.

1925
03:02:46.520 --> 03:02:49.420
Mhmm. You we just can't make enough money yet.

1926
03:02:49.721 --> 03:02:53.020
Like, how do we how do we make more money, Chris? Like,

1927
03:02:53.864 --> 03:02:56.585
like, you don't make it you don't make enough money off of it. And

1928
03:02:57.545 --> 03:02:59.965
Good. Bitcoin is just so greedy. Right? It's like,

1929
03:03:00.320 --> 03:03:02.020
of stuff like Yeah. 10,000%.

1930
03:03:02.641 --> 03:03:06.740
I mean, I see it as I go. Can I make more? Everyone loves money from nothing.

1931
03:03:08.320 --> 03:03:08.820
Yeah.

1932
03:03:10.085 --> 03:03:12.905
Well, maybe commodity bonds will improve the yield.

1933
03:03:13.685 --> 03:03:16.025
I appreciate both of you. Yeah. Continue.

1934
03:03:17.561 --> 03:03:21.101
Go ahead. Yeah. Yeah. No. I've got a team on time for the yield. That's all.

1935
03:03:22.680 --> 03:03:23.180
I

1936
03:03:23.865 --> 03:03:24.345
I,

1937
03:03:24.905 --> 03:03:26.524
I appreciate both of you joining.

1938
03:03:27.145 --> 03:03:29.645
We went we've gone 3 hours. So,

1939
03:03:30.024 --> 03:03:31.725
you know, I know time is money.

1940
03:03:33.210 --> 03:03:34.270
Apparently not.

1941
03:03:35.050 --> 03:03:47.854
No. It is. It is. And I appreciate you guys. We're we're this is a charitable deduction. You can just you can report this on your taxes as a charitable deduction for 3 hours worth of your time. They're demanding 6% in the chat now. So

1942
03:03:48.910 --> 03:03:53.330
They want they want their 6%. Yeah. You're never gonna get your 6%, guys.

1943
03:03:53.870 --> 03:04:00.814
That it doesn't matter if you shit coin. You will never get it. Yeah. It's not a huge risk. You can get 6% by gambling.

1944
03:04:04.395 --> 03:04:05.614
Gambling on BlockFi.

1945
03:04:07.310 --> 03:04:10.290
I I do do you guys agree with me that

1946
03:04:11.470 --> 03:04:13.729
we we get all this shit from

1947
03:04:14.495 --> 03:04:15.235
the ridiculous

1948
03:04:17.854 --> 03:04:25.510
this this idea like, we're privacy advocates in a world where we expect Bitcoin to succeed. Right? So the goal should be

1949
03:04:25.891 --> 03:04:27.510
that Bitcoin is going

1950
03:04:27.971 --> 03:04:37.035
to fucking absorb everything around us. And if Bitcoin absorbs everything around us, then we should focus on trying to improve the privacy of Bitcoin.

1951
03:04:37.735 --> 03:04:38.555
Yeah. Right?

1952
03:04:38.855 --> 03:04:39.675
Yeah. Sure.

1953
03:04:40.215 --> 03:05:00.375
No. I'm I'm saying from, like, from the perspective of shit corners. Right? Like, where the shit coins kinda came up just now. So, like, from the perspective of shit coins is, like, we're not gonna focus on a fucking privacy focused shit coin because because no one's gonna fucking use that shit. So there's no value to to us focusing on it. No. But it's still interesting to look at the the, like, the technologies they've chosen. Oh, 100%.

1954
03:05:00.800 --> 03:05:07.620
100%. We should look at everything they fucking do, and we should adopt the best of everything they do. And then, like, that that should not be debatable.

1955
03:05:08.885 --> 03:05:13.225
But, like, why don't I tell people go use privacy coin?

1956
03:05:13.685 --> 03:05:14.185
Right?

1957
03:05:15.101 --> 03:05:16.960
It's because that's counterintuitive.

1958
03:05:17.500 --> 03:05:18.801
They're already in Bitcoin.

1959
03:05:19.500 --> 03:05:21.280
They're already going to be in Bitcoin.

1960
03:05:24.175 --> 03:05:25.074
Do we agree?

1961
03:05:25.774 --> 03:05:35.761
I think they're wrong. Mainly, it's about, like, network usage, anonymity set, and and and also some security issues as well because a lot of the time, they trade things off to get these security,

1962
03:05:36.301 --> 03:05:42.025
like, achievements. So these privacy achievements, they trade off security, I mean. Sorry. Right. Yeah. It's always it's usually

1963
03:05:42.405 --> 03:05:43.945
a security trade off.

1964
03:05:46.726 --> 03:05:52.710
Okay. Well, with all that said, appreciate you both. All the work you've done. You guys are fucking legends.

1965
03:05:54.529 --> 03:05:55.670
Thank you for joining,

1966
03:05:56.210 --> 03:06:00.284
this discussion. I hope you come on again in the future. The whole point of dispatch

1967
03:06:01.064 --> 03:06:06.284
is that we're gonna it's like it's supposed to be like a global classroom, this idea that we all learn together

1968
03:06:06.740 --> 03:06:11.400
and that I'm gonna bring you guys back. Like, I wanna bring you guys back year after year after year.

1969
03:06:11.940 --> 03:06:13.480
So I hope you guys come back.

1970
03:06:14.500 --> 03:06:18.904
I appreciate all the work you've done. Yeah. You guys have any last statements here,

1971
03:06:19.765 --> 03:06:21.864
before we conclude this

1972
03:06:22.725 --> 03:06:23.225
discussion?

1973
03:06:25.380 --> 03:06:30.520
No. I think that's everything. Thanks for the kind words and for having us on. Yeah. Happy to know. Chris.

1974
03:06:31.540 --> 03:06:32.359
Yeah. Thanks.

1975
03:06:33.835 --> 03:06:39.136
Final words. No. I'm just really tired. We've been talking for 3 and a half hours nearly.

1976
03:06:39.915 --> 03:06:43.690
That's my final words. Thanks a lot for having us on. It was, you know, a very difficult conversation.

1977
03:06:44.311 --> 03:06:48.545
This is a really professional setup you've got here. I really like it. Yeah. Well, I appreciate that.

1978
03:06:49.265 --> 03:06:56.645
Most of it is thanks to a centralized company that is probably going to go into surveillance capitalism. So I will have to switch.

1979
03:06:57.729 --> 03:07:03.189
But thank you both for all the work you've done. Thank you for joining us. Thank you to the right guys. Mumble.

1980
03:07:03.729 --> 03:07:04.229
What?

1981
03:07:04.575 --> 03:07:08.995
Have you ever used Mumble? You know, the voice chat. Yeah. Mumble's good. Mumble's good.

1982
03:07:10.495 --> 03:07:16.920
It can't compete with this. Like, the live chat is so cool that we have the ride or die guys just in here participating.

1983
03:07:18.660 --> 03:07:24.065
Okay. I I think it keeps us honest. You know, it, like, creates the don't trust, verify kind of situation

1984
03:07:24.846 --> 03:07:26.625
Yeah. Where where,

1985
03:07:27.420 --> 03:07:30.000
you know, you can't accuse me of

1986
03:07:30.301 --> 03:07:33.280
of spending the last 40 hours on SIPL dispatch

1987
03:07:34.275 --> 03:07:49.551
selling FUD when you can just respond in here and just I'll let you just fucking broadcast it out to everyone who's watching. Like, they'll see what you say. You can call me you can say that I'm a fucking liar, and you can just put it in the fucking live chat, and it'll it'll it'll post it.

1988
03:07:50.465 --> 03:07:51.925
And I don't think it's a coincidence

1989
03:07:52.465 --> 03:07:56.165
that none of the other shows have the fucking live chat broadcast.

1990
03:07:56.625 --> 03:07:59.445
Right? Because they're not comfortable enough with it.

1991
03:08:01.140 --> 03:08:03.080
So mobile's dope. It's open source,

1992
03:08:03.860 --> 03:08:07.800
but but but the the closed source shit is always good, dude. It's, like, fantastic.

1993
03:08:08.445 --> 03:08:10.065
So I appreciate you guys time helps.

1994
03:08:10.525 --> 03:08:15.585
It's great. It's great. And we got the price, and we got our names, and we got all this fucking shit. It's good.

1995
03:08:17.990 --> 03:08:19.930
But I appreciate you both coming on.

1996
03:08:20.870 --> 03:08:22.090
Everyone should go,

1997
03:08:22.870 --> 03:08:33.165
try join market. They should try joining box, OpenOMS. You guys remember OpenOMS from last week with Joininbox? Go try that shit. Care about your privacy, please. It's important.

1998
03:08:35.010 --> 03:08:36.790
Follow Chris on Twitter.

1999
03:08:37.810 --> 03:08:40.630
It's under dash, Chris Belcher, under dash.

2000
03:08:41.785 --> 03:08:44.845
Waxwing is not on Twitter. You're gonna have to go find him on Mastodon.

2001
03:08:45.226 --> 03:08:47.405
And if you find him, you deserve it.

2002
03:08:48.800 --> 03:08:55.845
Go to IRC. Let go of these things, and and just care about your privacy. I love you both. Thank you for joining us. I appreciate all your work.

2003
03:08:56.564 --> 03:08:59.465
Shout out to all the freaks. Thank you, guys. Appreciate you all.

2004
03:08:59.925 --> 03:09:01.385
Thanks. Okay. Bye.

2005
03:09:03.045 --> 03:09:04.270
Bye. I'm waiting.

2006
03:09:05.450 --> 03:09:05.950
Oh.

2007
03:12:30.985 --> 03:12:31.885
Love you, freaks.

2008
03:12:32.345 --> 03:12:36.125
Thank you for joining us. Bitcoin privacy is fucking important.

2009
03:12:36.665 --> 03:12:38.925
Don't let the compliance bros tell you otherwise.

2010
03:12:39.410 --> 03:12:43.190
We'll see you Thursday for rabbit hole recap. We'll see you next Tuesday,

2011
03:12:44.130 --> 03:12:49.394
for the for the next little dispatch. Appreciate you all. Stay humble. Stack stats.