CD16: bitcoin privacy and coinjoin with chris belcher and waxwing
EPISODE: 0.1.6
BLOCK: 678040
PRICE: 1719 sats per dollar
TOPICS: bitcoin privacy, coinjoin
chris belcher: https://twitter.com/chris_belcher_
streamed live every tuesday:
https://citadeldispatch.com
twitch: https://twitch.tv/citadeldispatch
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://anchor.fm/citadeldispatch
telegram: https://t.me/citadeldispatch
support the show: https://tippin.me/@odell
stream sats to the show: https://www.fountain.fm/
join the chat: http://citadel.chat/
00:03 - Goldman Sachs offering Bitcoin investment products to wealthy clients
03:04 - Bitcoin privacy and the importance of security
20:00 - PayJoin as a Bitcoin privacy solution
39:10 - The way Tor works nowadays and the hot wallet aspect
40:20 - Early days of Bitcoin and the interactivity of Lightning
41:03 - The impact of PayJoin on fees and the practicality of its usage
01:19:06 - Jack Miles gave a talk about it
01:19:23 - Facebook and Oculus
01:19:37 - Zuck's Facebook account got hacked
01:59:00 - CoinSwap and its advantages
02:00:57 - Comparison between CoinSwap and Lightning
02:11:07 - Visibility of privacy transactions
02:37:13 - Discussion about the limitations of using heuristics in analyzing broken transactions
02:38:50 - Opinions on Bisq and its importance as a project
02:46:45 - Opinions on Liquid and its use cases
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 4:34:04 PM
Duration: 11570.809
Channels: 1
1
00:00:00.240 --> 00:00:01.220
2
00:00:01.680 --> 00:00:04.180
Banking reporter, Houston. Goldman Sachs
3
00:00:04.799 --> 00:00:08.420
is getting close to offering Bitcoin investment products
4
00:00:09.025 --> 00:00:10.565
to its wealthy clients.
5
00:00:11.025 --> 00:00:11.525
Kewsan
6
00:00:12.705 --> 00:00:13.764
joins us now.
7
00:00:14.705 --> 00:00:19.310
Does Goldman know Bitcoin was, like, $4,000, like, 18 months ago, and now it's, like, 57,000?
8
00:00:19.850 --> 00:00:22.190
9
00:00:22.570 --> 00:00:23.070
view?
10
00:00:23.930 --> 00:00:25.289
11
00:00:25.850 --> 00:00:31.485
those dizzying charts that everybody has, is looking at and salivating over, that's one of the reasons why,
12
00:00:32.185 --> 00:00:36.285
Goldman and others are are getting into this. You know, they are in a client business.
13
00:00:36.590 --> 00:00:51.245
So when clients of Goldman Sachs or clients of Morgan Stanley, you know, call up their financial adviser and say, should I have an allocation to Bitcoin? Look look at what it's done. You know? Should I have a 1%, 2%, 3% allocation to this emerging asset class?
14
00:00:51.625 --> 00:01:00.690
You know, they've had to say, well, as as a firm, we can't really recommend that. Well, that changes, and that changes very, very soon. So as we report exclusively
15
00:01:01.789 --> 00:01:03.010
on, cbc.com,
16
00:01:03.550 --> 00:01:07.735
Goldman Sachs is is very close and in the second quarter will begin offering
17
00:01:08.195 --> 00:01:20.670
Bitcoin and other digital asset related investments to its private wealth management clients. This is the, this is sort of the Tony private bank of Goldman Sachs. You know, they really target people and endowments with at least 25,000,000
18
00:01:21.130 --> 00:01:22.430
in assets under management.
19
00:02:02.495 --> 00:02:05.795
20
00:02:06.340 --> 00:02:09.080
here for another episode of Citadel Dispatch,
21
00:02:09.460 --> 00:02:15.080
the interactive live show about Bitcoin distributed systems privacy and open source software.
22
00:02:15.885 --> 00:02:25.750
To those freaks joining us from our various audio streams, whether that's our 2 podcast feeds, our Sphinx tribe, or through the recent Breeze integration with podcasting 2 point
23
00:02:26.050 --> 00:02:31.270
o. That clip out in the beginning was our boy Joe Kernan from CNBC Squawk Box,
24
00:02:31.890 --> 00:02:33.190
who's currently running
25
00:02:33.585 --> 00:02:36.325
the largest, most popular Bitcoin entertainment
26
00:02:36.625 --> 00:02:37.925
show in the world.
27
00:02:38.945 --> 00:02:45.019
And he had a lot of fun trolling Goldman Sachs there with that with that massive announcement coming from them.
28
00:02:47.079 --> 00:02:50.805
Shout out to all the rider dive freaks that are joining us live in the comments.
29
00:02:51.385 --> 00:02:51.925
This is
30
00:02:53.825 --> 00:02:55.285
another earlier episode
31
00:02:56.720 --> 00:02:58.900
to to help our guests with time zones.
32
00:02:59.360 --> 00:03:07.125
So I hope you don't find it too early. I know some people preferred it. I know some people didn't. It is what it is. We will probably be switching between the 2,
33
00:03:07.665 --> 00:03:13.285
time slots, whether that's 1700 UTC, which is right now, or 21 100 UTC,
34
00:03:13.825 --> 00:03:15.445
which we've have done historically.
35
00:03:17.570 --> 00:03:22.150
I am fortunate enough to be joined here by Chris Belcher and Waxwing,
36
00:03:22.450 --> 00:03:23.750
the 2 lead maintainers
37
00:03:24.435 --> 00:03:25.254
of JoinMarket,
38
00:03:25.555 --> 00:03:29.655
the oldest and most reputable CoinJoin implementation in existence.
39
00:03:31.235 --> 00:03:35.280
And we are gonna have a great conversation focused on Bitcoin privacy,
40
00:03:36.700 --> 00:03:37.920
past, present, future,
41
00:03:38.940 --> 00:03:45.834
and and just the current state of all these tools. I think it's gonna be a very great follow-up discussion to last week's discussion we had with Open
42
00:03:46.135 --> 00:03:47.275
Arms and NoPara,
43
00:03:48.080 --> 00:03:51.380
and, obviously, plenty of previous discussions we've had on here.
44
00:03:55.095 --> 00:03:56.635
With with all that said,
45
00:03:57.095 --> 00:03:58.955
I'd like to welcome both of them.
46
00:03:59.495 --> 00:04:03.550
It seems like Chris is having some audio issues, so we will start with,
47
00:04:04.030 --> 00:04:04.530
Waxwing.
48
00:04:05.790 --> 00:04:07.090
How's it going, Waxwing?
49
00:04:08.030 --> 00:04:11.810
50
00:04:12.345 --> 00:04:13.325
51
00:04:14.825 --> 00:04:18.925
I I appreciate that. Me and the freaks have only been doing this for
52
00:04:19.705 --> 00:04:20.905
a couple months now. So
53
00:04:21.509 --> 00:04:24.169
54
00:04:24.710 --> 00:04:27.210
55
00:04:30.014 --> 00:04:32.675
So I think Chris can't hear us. Chris, can you hear us?
56
00:04:35.455 --> 00:04:35.955
Exactly.
57
00:04:37.320 --> 00:04:40.700
So we're gonna have him try and reset. And while we're doing that,
58
00:04:42.280 --> 00:04:45.180
I I guess, Waxwing, let's just start off with, you know,
59
00:04:45.935 --> 00:04:58.010
like, why why should the freaks care about using Bitcoin privately? Why should they care about Bitcoin privacy best practices? You know, why should they care about privacy in general? Why why are you so focused on this this aspect of Bitcoin?
60
00:05:00.550 --> 00:05:01.930
61
00:05:02.475 --> 00:05:04.015
I always prefer to
62
00:05:04.875 --> 00:05:07.615
answer that question more around security. Just thinking
63
00:05:07.915 --> 00:05:10.280
about average users are not, like,
64
00:05:10.820 --> 00:05:11.880
either or massive,
65
00:05:12.260 --> 00:05:18.115
you know, massively important people or whatever. Just you're just an ordinary user. It's to me, it's mostly about
66
00:05:18.435 --> 00:05:21.574
security. And you could there's there's different flavors of security. Right? There's
67
00:05:22.035 --> 00:05:28.480
the defense against someone literally coming at you violently with a with a hammer or whatever. And there's there's also just
68
00:05:29.260 --> 00:05:30.400
like, I don't really wanna
69
00:05:31.020 --> 00:05:35.920
when I pay someone for them to know where my my money came from, it could even be like business
70
00:05:36.544 --> 00:05:39.605
business intelligence. You know, you don't want your competitors to know
71
00:05:40.065 --> 00:05:49.419
what you're doing with your money. And, of course, the other thing about privacy is don't forget, it's it's kind of intertwined with with fungibility. People often use these two terms when they're
72
00:05:49.720 --> 00:05:50.220
advocating
73
00:05:51.000 --> 00:06:10.570
Bitcoin privacy, whether it be CoinJoin or other tech. They often say, oh, we we need Bitcoin to be fungible, and that's very true. And it's it's kind of it's not the same concept, but it's a very closely interrelated concept. So, you know, essentially, at the end of the day, money shouldn't have a memory. I think that's the simplest way to to express it. But the fact that the the way Bitcoin's designed is intrinsically
74
00:06:11.670 --> 00:06:15.210
kind of not like that, at least not at a surface level,
75
00:06:16.305 --> 00:06:18.485
it creates a need for us to really
76
00:06:19.105 --> 00:06:20.965
work on this stuff. Yeah.
77
00:06:21.345 --> 00:06:26.719
78
00:06:27.020 --> 00:06:28.560
like, a housewife's wall.
79
00:06:29.659 --> 00:06:31.599
Mhmm. Yeah. One of the inspirational quotes.
80
00:06:32.355 --> 00:06:36.375
81
00:06:36.915 --> 00:06:37.575
Oh, excellent.
82
00:06:38.755 --> 00:06:44.919
83
00:06:46.419 --> 00:06:47.620
especially in in,
84
00:06:48.740 --> 00:06:49.800
a show like this,
85
00:06:50.794 --> 00:06:55.775
discussions like this that we have on Citadel Dispatch that are that tend to to lean more technical.
86
00:06:56.555 --> 00:07:00.410
But today, I mean, I was the last 2 days, I've been called a FUDster,
87
00:07:01.110 --> 00:07:02.570
that I'm spreading FUD,
88
00:07:02.870 --> 00:07:05.290
for saying that people should be skeptical of their governments,
89
00:07:06.025 --> 00:07:15.940
and then not your keys, not your coins is a thing. Now now I'm being told that saying not your keys, not your coins is is FUD. So I think it's important that we keep coming back to the basics as we have new people join. So
90
00:07:17.280 --> 00:07:21.460
just in in your own words, why should people care about Bitcoin privacy best practices?
91
00:07:28.775 --> 00:07:31.194
We definitely lost him again. You might be muted.
92
00:07:35.940 --> 00:07:36.680
That's unfortunate.
93
00:07:38.715 --> 00:07:41.935
94
00:07:43.675 --> 00:07:44.175
95
00:07:45.115 --> 00:07:47.215
while we wait for him to come back again,
96
00:07:48.460 --> 00:07:49.759
where should we start?
97
00:07:51.580 --> 00:07:53.120
I wanna start with
98
00:07:53.819 --> 00:07:56.080
with your work on Join Market.
99
00:07:57.905 --> 00:07:58.725
You know, JoinMarket,
100
00:07:59.505 --> 00:08:01.764
when did the project start? 2015, I think?
101
00:08:03.104 --> 00:08:06.370
102
00:08:07.390 --> 00:08:12.930
and started writing, like, a a first version of the code, I think, in December of 2014. And so it's, like, December,
103
00:08:13.390 --> 00:08:22.365
January that time. Yeah. It was interestingly, it it coincides almost exactly with the the the bottom on the looking at the price chart here. I'm just thinking about the prices
104
00:08:23.110 --> 00:08:31.290
That that January 2015 was the the sub 200 plunge, if you remember. It was kind of a special time. Yeah. How can you forget?
105
00:08:32.055 --> 00:08:32.555
Indeed.
106
00:08:33.575 --> 00:08:39.995
Okay. Looks like Chris is gonna try and rejoin. That that would be a good idea, I think. We're doing it live, freaks. We're doing it live. That's what it's about.
107
00:08:40.580 --> 00:08:41.480
108
00:08:42.100 --> 00:08:43.960
it was a ridiculously
109
00:08:44.340 --> 00:08:47.320
brutal bear market as you so thoughtfully recounted.
110
00:08:49.295 --> 00:08:57.170
111
00:08:57.889 --> 00:09:08.145
sitting there. It was like, this is where the, this is where the rubber meets the road. That there there were, I'm sure there were several people who just gave up because it's just like, because don't forget, that was the end of a very long period
112
00:09:08.685 --> 00:09:15.870
of sort of comedown, you know, that we had so much may and people that forget this now because they all think about 2017, but we had a a ton of mainstream attention
113
00:09:16.569 --> 00:09:29.324
at the end of 2013 and especially the beginning of 2014 because, you know, after that spike, that's when everyone sort of caught on. And, indeed, often how it works is you get tons and tons of new users just flooding in post the spike, you know,
114
00:09:29.820 --> 00:09:36.715
because they they think, oh, this is this new thing. And they all came in, and they all just said, yeah. This is great. And then they just watched the price collapse for an entire year.
115
00:09:37.115 --> 00:09:38.575
It was absolutely brutal.
116
00:09:39.755 --> 00:09:53.400
Yeah. And I was I was sitting there thinking I I remember having more than one moment where I was thinking to myself, well, this is it. You know? I've just I'm am I gonna go down with this ship? You know, and I I I mean that in a kinda literal way because I'd given up my my job as a teacher a couple years earlier.
117
00:09:54.325 --> 00:09:57.705
And, I thought, you know, fuck it. Yeah. I am gonna go to coffee shop.
118
00:09:58.405 --> 00:10:00.745
119
00:10:01.380 --> 00:10:06.040
I was not stacking I was not stacking at the bottom of that bear market. Like, I I had
120
00:10:06.740 --> 00:10:11.285
I I had decided that I was gonna go down with the ship. I would go to 0 if I had to, but I
121
00:10:11.764 --> 00:10:14.665
I was did not have that much faith. I was losing the faith.
122
00:10:15.204 --> 00:10:19.020
123
00:10:19.500 --> 00:10:21.180
Okay. Because I'm trying to 2 of the most
124
00:10:23.420 --> 00:10:25.600
125
00:10:26.855 --> 00:10:34.475
developers on the show, and we've started it off with price talk in potential dispatch fashion. Chris, can you hear us now? Yeah.
126
00:10:35.175 --> 00:10:35.675
127
00:10:36.440 --> 00:10:38.220
Help Chris. Come back.
128
00:10:41.640 --> 00:10:43.100
He says he's back. Well,
129
00:10:44.765 --> 00:10:46.385
130
00:10:47.645 --> 00:10:50.225
Maybe try a different browser if you can hear us, Chris.
131
00:10:53.569 --> 00:10:54.069
So,
132
00:10:55.089 --> 00:10:56.769
Matt, losing faith. I,
133
00:10:57.490 --> 00:11:05.285
yeah. I'm telling you, the bit the Bitcoin price hit, like, 180 or something. And I was just I was a young kid, and I was, like, fuck. My dad was right. It's,
134
00:11:06.805 --> 00:11:08.985
it it was a bubble. It's all the tulips,
135
00:11:09.510 --> 00:11:09.990
and,
136
00:11:10.630 --> 00:11:17.545
and I I just I just had found solace in the fact that, you know, I wasn't gonna sell, so we're really gonna go to 0 or I was gonna be right.
137
00:11:18.024 --> 00:11:18.524
Yeah.
138
00:11:19.144 --> 00:11:22.845
But, it was definitely a very different bear market than than today's
139
00:11:23.305 --> 00:11:29.730
than than the one we had recently. But maybe maybe that's just because of experience. Maybe it's just because we I think so. Yeah. That last one.
140
00:11:30.269 --> 00:11:36.995
141
00:11:37.454 --> 00:11:44.035
142
00:11:44.380 --> 00:11:47.200
2015 was longer and most more painful
143
00:11:47.980 --> 00:11:53.420
than than this one. Like, this one, like, March was kind of brutal, but it was a quick brutal. Right? Like, it
144
00:11:54.605 --> 00:11:59.185
145
00:11:59.645 --> 00:12:00.145
to
146
00:12:00.685 --> 00:12:09.410
I don't know to know when when you decide when it started going up again. I don't know. But anyway, maybe not. It's just that my how it feels to me. Honestly, I think somebody hear me.
147
00:12:10.110 --> 00:12:13.010
148
00:12:13.944 --> 00:12:15.964
And just to check, is does this sound better?
149
00:12:16.665 --> 00:12:20.285
150
00:12:20.620 --> 00:12:23.760
151
00:12:25.660 --> 00:12:33.135
So, Chris, Waxwing was telling everyone about how you believe that Bitcoin is designed pump forever. Do you want to elaborate on that at all?
152
00:12:37.755 --> 00:12:39.135
I think we lose them again.
153
00:12:39.900 --> 00:12:42.480
Oh. Do we lose you again? We could price talk.
154
00:12:43.900 --> 00:12:46.080
155
00:12:46.700 --> 00:12:56.255
156
00:12:57.699 --> 00:12:58.199
So,
157
00:12:58.899 --> 00:13:00.839
we've had joined market since 2015.
158
00:13:02.019 --> 00:13:02.519
Mhmm.
159
00:13:03.380 --> 00:13:08.154
Lot of time lot of time you guys have been working on it. Lot of time you guys have been using it.
160
00:13:09.415 --> 00:13:18.370
What lessons what lessons have you guys learned? What what, you know, what lessons have you learned? Thoughts on on the whole process of of maintaining this this implementation?
161
00:13:21.310 --> 00:13:30.745
162
00:13:32.520 --> 00:13:33.980
in terms of learning, like
163
00:13:35.399 --> 00:13:42.275
I mean, the thing about CoinJoin is this weird case where on the one hand, it seems like this super technical thing, and it is.
164
00:13:43.135 --> 00:13:47.955
On the other hand hear me? Oh, he's back again. Okay. Right. Sorry about that.
165
00:13:48.279 --> 00:13:49.100
No worries.
166
00:13:49.880 --> 00:13:55.740
167
00:13:56.600 --> 00:13:57.100
168
00:13:57.735 --> 00:13:59.275
169
00:14:00.455 --> 00:14:10.430
170
00:14:10.810 --> 00:14:20.154
that you'll just be completely wrong because markets and users, they they they have their own mind. So for example, right to the beginning of joint market, we had this this kind of operation.
171
00:14:20.455 --> 00:14:22.555
Those are scripts called the patient send payment.
172
00:14:22.860 --> 00:14:33.475
And the idea was that you could be a market maker, and then you could send the coin train it, but it it would be much cheaper because you wouldn't be paying fees. And I thought a lot of people use this, and it'll be a way to,
173
00:14:33.935 --> 00:14:41.820
have more payments merged into one transaction. And then it turned out that was basically never used. So the script was broken for about a year, and nobody even noticed.
174
00:14:43.320 --> 00:14:44.780
175
00:14:45.160 --> 00:14:51.695
176
00:14:52.395 --> 00:14:57.110
join market special? How does join market work? Let's explain the maker taker function, etcetera.
177
00:14:57.810 --> 00:14:59.570
178
00:15:00.370 --> 00:15:01.110
there is,
179
00:15:01.730 --> 00:15:05.030
obviously, Coin Joins require many people to come together in one transaction.
180
00:15:05.355 --> 00:15:14.735
And the way join markets works is that one of the one of the entities in a coin join can control things about it. They'll control the amount, and they'll control the time of when it actually happens.
181
00:15:15.050 --> 00:15:31.710
And for this privilege, they have to pay a small fee, and everyone else in the coin join is just waiting there. They wait. They have their computers always turned on, and they'll do coin joins. They basically have an advert that says, I'll do any amount of coin join at any time you want, and all I want is a fee, like a 100 associate or whatever it might be.
182
00:15:32.270 --> 00:15:37.170
Then the effects of that means if you're this taker, I. E. You take liquidity from the marketplace,
183
00:15:37.550 --> 00:15:42.014
then you can make a coin join for what whatever amount you want, whatever time you want.
184
00:15:43.355 --> 00:15:51.910
And the other people in the coin join, they'll just they'll go along with you. Like, they'll they'll earn their fee, and they don't know what the amount is. And that's the that's the unique thing that joint market does.
185
00:15:53.490 --> 00:15:55.090
186
00:15:56.024 --> 00:16:02.204
there's something to be said or highlighted about the idea of when trying to set up these systems to create a financial incentive
187
00:16:04.110 --> 00:16:09.570
to participants Yeah. To to act to act not necessarily in their best interest, but greedy. Right?
188
00:16:10.165 --> 00:16:14.745
189
00:16:15.125 --> 00:16:32.694
Right. And that was a little bit like JoinMarket, but it didn't have any fees. So people were there was also you could call them makers and takers, but the makers didn't make any money. They just they were just expected to sit there and do coin joints without, you know, leave their computer on all the time for no reason. And, of course, the problem was that there were no makers.
190
00:16:33.154 --> 00:16:37.600
191
00:16:38.399 --> 00:16:55.250
they called it a lobby server. And essentially, the idea was you wanna do a coin join, you make the intention, and you would be sitting on the lobby server waiting for actually, they were only doing 2 parties, so they would just wait for one other party to do a coin join. Yeah. Yeah. Did it ever actually fully launch? I think. Okay. Oh, yeah. Yeah. It was used quite a bit. Yeah.
192
00:16:56.110 --> 00:17:00.529
193
00:17:01.774 --> 00:17:19.105
194
00:17:19.885 --> 00:17:24.065
195
00:17:25.299 --> 00:17:29.640
I I guess if we're going down in history, right, we also had before that, we had, what, shared send,
196
00:17:30.100 --> 00:17:34.520
right, from blockchain dot info. No disclosure, no one should use a blockchain dot info anything,
197
00:17:35.405 --> 00:17:35.905
nowadays.
198
00:17:37.645 --> 00:17:53.375
199
00:17:53.995 --> 00:18:02.580
200
00:18:02.960 --> 00:18:10.825
It was kinda interesting. But, of course, it's not a cryptographically strong concept because, you know, individual payments might be trivially easy to find even if the
201
00:18:11.365 --> 00:18:23.160
202
00:18:23.780 --> 00:18:26.760
203
00:18:27.705 --> 00:18:31.965
204
00:18:32.664 --> 00:18:40.610
205
00:18:40.990 --> 00:18:44.210
sort of quietly knocked on their door and said, turn it off, and they said, okay.
206
00:18:44.795 --> 00:18:45.535
Because, you
207
00:18:45.835 --> 00:18:50.175
know, I I think it was used quite heavily in those early days. The UX was fantastic.
208
00:18:51.035 --> 00:18:52.095
209
00:18:53.419 --> 00:18:56.960
the other and then before that and still today, right,
210
00:18:57.740 --> 00:19:02.965
probably one of the most common and it's so funny because, like, in technical communities, we almost never talk
211
00:19:03.525 --> 00:19:12.789
about it. One of the most common Bitcoin privacy tools is this idea of a custodial of custodial mixer, where you send your coins in, and they send you someone else's coins.
212
00:19:13.970 --> 00:19:24.495
Yeah. You know, Silk Road had their own. Right? And then since then, there was a bunch of independent services that popped up, like, was it, like, Bitcoin Fog and, like, BitMxer and stuff.
213
00:19:24.955 --> 00:19:25.455
Yeah.
214
00:19:26.210 --> 00:19:29.110
And the concern there was always that they could be honeypots. Right?
215
00:19:29.570 --> 00:19:43.405
216
00:19:43.770 --> 00:19:45.710
217
00:19:46.730 --> 00:19:47.770
218
00:19:48.090 --> 00:19:58.825
219
00:20:00.350 --> 00:20:00.850
220
00:20:01.470 --> 00:20:08.450
Yeah. Creating creating this this market with makers and takers, this idea that you don't have to have a centralized entity involved at all,
221
00:20:09.885 --> 00:20:12.225
and that the whole thing is is p to p,
222
00:20:12.845 --> 00:20:16.385
with this financial incentive for people to provide 247 liquidity.
223
00:20:19.310 --> 00:20:19.810
Revolutionary.
224
00:20:20.670 --> 00:20:21.170
Right?
225
00:20:22.510 --> 00:20:23.330
What what
226
00:20:24.110 --> 00:20:24.610
what
227
00:20:25.470 --> 00:20:26.930
is it fair to say?
228
00:20:27.615 --> 00:20:28.515
I I think
229
00:20:28.975 --> 00:20:32.434
well, you tell me if it's unfair to say, but is it fair to say that
230
00:20:33.534 --> 00:20:34.914
that CoinJoin adoption
231
00:20:35.375 --> 00:20:36.515
JoinMarket adoption
232
00:20:37.490 --> 00:20:37.990
has
233
00:20:39.970 --> 00:20:40.610
not meet
234
00:20:41.090 --> 00:20:41.910
met your expectations
235
00:20:42.290 --> 00:20:45.590
of of what you had hoped, the amount of people, services,
236
00:20:46.050 --> 00:20:46.550
users
237
00:20:47.235 --> 00:20:48.615
would be using join market.
238
00:20:50.355 --> 00:20:55.095
239
00:20:55.395 --> 00:20:59.410
or wherever, I sometimes thought exchanges would do this. And the idea being that
240
00:20:59.870 --> 00:21:15.645
an exchange doesn't want its traders to be spied on. Like, if a trader sends those of coins in exchange, someone could front run them, like, you know, open a short position before they before the coins confirm. So I thought exchanges would use some kind of coin join or join market, and that never happens. Obviously, now we know,
241
00:21:16.390 --> 00:21:18.650
because the regulator stopped them. Right? So
242
00:21:19.030 --> 00:21:19.770
they went,
243
00:21:20.310 --> 00:21:21.510
they went through it for that reason.
244
00:21:22.710 --> 00:21:23.850
So, yeah, I guess
245
00:21:24.905 --> 00:21:28.605
it hasn't really met my expectation. Also, back then, I've just remembered now,
246
00:21:29.305 --> 00:21:36.679
back then, this was before the the block size debates, before people really like, the whole community really accepted the idea that minor fees were
247
00:21:37.140 --> 00:21:46.255
were like a big deal that you always had to plan for them. In fact, in the very first versions of joint market, the minor fee was a constant number. It was 10,000 satoshis, like, for every coin ring,
248
00:21:46.875 --> 00:21:50.020
just because fees were so cheap that every transaction would confirm.
249
00:21:51.040 --> 00:21:56.180
And then and because these because coin joints are bigger than regular transactions, then they they're a bit more expensive.
250
00:21:57.605 --> 00:22:04.745
So in that sense, that's maybe another reason why they haven't been as adopted as you might hope. It's not that every single transaction is a coin joint.
251
00:22:05.399 --> 00:22:06.139
252
00:22:06.519 --> 00:22:06.789
253
00:22:07.330 --> 00:22:09.419
traders that joins and they're expensive.
254
00:22:09.880 --> 00:22:13.500
255
00:22:14.274 --> 00:22:15.654
I've come to the
256
00:22:16.755 --> 00:22:18.375
the realization or
257
00:22:18.755 --> 00:22:20.855
the understanding with myself that I think
258
00:22:21.730 --> 00:22:24.789
using Bitcoin privately will always be the more expensive option.
259
00:22:25.490 --> 00:22:29.750
260
00:22:30.405 --> 00:22:36.345
and it's also cheaper. Like, the way we Wouldn't wouldn't custodial lightning be cheaper and less private?
261
00:22:38.000 --> 00:22:39.220
Oh, purely custodial
262
00:22:39.520 --> 00:22:56.500
PayPal would be even even cheaper as well. Just a completely centralized thing where Yeah. Yeah. Okay. You're right. But if you if you away all other trade offs, then the cheapest way of using it would be to have something that can censor you, that can steal your money, and that can spy on you. Well, I was thinking more from, like, on chain because because, yeah, layer
263
00:22:57.140 --> 00:23:05.275
264
00:23:05.895 --> 00:23:19.090
signature aggregation later, right, which is it's not even coming with Taproot, but let's say we get it later Cross input aggregation is not coming. Right. Signature aggregation and multi sig is coming, but that's Right. Right. Cross input signature aggregation. Yeah.
265
00:23:19.710 --> 00:23:20.530
If if
266
00:23:21.565 --> 00:23:27.585
even even when we get all that, on chain, the cheapest option in a high fee can sustained high fee environment
267
00:23:28.205 --> 00:23:28.705
is
268
00:23:29.370 --> 00:23:33.230
to combine all your UTXOs into a single UTXO and spend from that.
269
00:23:34.409 --> 00:23:41.024
270
00:23:41.804 --> 00:23:48.190
Suppose you want to use Bitcoins and you get censored, then your funds get stolen. Basically, they get frozen. You've lost a 100% of your money,
271
00:23:48.990 --> 00:24:04.135
if you put it in the custodial system. But if you then pay your own minor fees and use your own wallet that you control, you only lose 10% for minor fees. Right? So if you take into account censorship and having your funds frozen, then it might end up being more expensive to use a custodial solution.
272
00:24:05.000 --> 00:24:09.020
273
00:24:09.320 --> 00:24:13.340
A lot of the large education accounts and stuff on on Twitter and Reddit,
274
00:24:14.115 --> 00:24:16.215
we're we're and we're suggesting that people,
275
00:24:16.595 --> 00:24:20.855
you know, combine all their UTXOs into a single into a single output
276
00:24:21.260 --> 00:24:25.600
so that their fees going forward, their fee burden going forward would be the lowest possible.
277
00:24:26.780 --> 00:24:31.295
278
00:24:32.255 --> 00:24:36.355
the cheapest option would always be, non coin join because in the case
279
00:24:36.815 --> 00:24:38.115
of cross input aggregation,
280
00:24:39.390 --> 00:24:46.049
CoinJoin, you you at least save some of the the, so to speak, header bytes, the the the the constant overhead? It's a very small difference,
281
00:24:46.485 --> 00:24:58.400
but sort of philosophically, it's kind of critical. And I think one of the reasons that a lot of the, what you might call, Bitcoin gray beards have have been sort of not particularly enthusiastic about CoinJoin, but they're more enthusiastic about some future version of CoinJoin
282
00:24:58.700 --> 00:25:04.080
of the type that you just described involving Schnorr and cross and push signature aggregation because well,
283
00:25:04.605 --> 00:25:07.985
even if it's only 1¢ cheaper, if there's an economic incentive
284
00:25:08.605 --> 00:25:12.705
rather than just purely a privacy incentive, it encourages the crowd to come in.
285
00:25:14.799 --> 00:25:18.179
286
00:25:18.480 --> 00:25:51.530
287
00:25:52.950 --> 00:25:53.450
288
00:25:53.830 --> 00:25:55.610
289
00:25:56.535 --> 00:26:02.235
you're you're in a situation where to use Bitcoin privately, you have to make more on chain transactions than not.
290
00:26:02.615 --> 00:26:06.150
Today, that's definitely true. Yeah. Do we think that's gonna change going forward?
291
00:26:08.690 --> 00:26:10.310
292
00:26:10.690 --> 00:26:21.810
293
00:26:22.270 --> 00:26:30.654
as as not just a scalability technology, then it's clearly the case that it you you you're reducing on chain usage from using it rather than increasing.
294
00:26:31.115 --> 00:26:31.615
295
00:26:33.514 --> 00:26:38.014
296
00:26:38.340 --> 00:26:39.320
well built out.
297
00:26:40.100 --> 00:26:41.720
298
00:26:42.179 --> 00:26:51.575
so so, hopefully, we can get it cheaper than not using Bitcoin privately. But we all agree that for adoption, you know, the one of the main things is keeping costs down. Right?
299
00:26:51.955 --> 00:26:57.860
Yeah. Yeah. To get more people to use privacy. Another thing I was thinking, and I don't know if I'm just gonna throw us into a tangent, but fuck it.
300
00:26:59.780 --> 00:27:07.000
You know, today, I was arguing with people about all the the the newest hottest craze in Bitcoin land is these interest bearing accounts.
301
00:27:07.765 --> 00:27:15.544
Oh, yeah. Oh. And, you know, private Bitcoin users, Bitcoin users who care about their privacy, like, they can't get 6% interest,
302
00:27:16.929 --> 00:27:18.470
in a regulated custodian.
303
00:27:19.650 --> 00:27:20.950
So in a in a way,
304
00:27:21.730 --> 00:27:23.350
that kinda changes the
305
00:27:24.005 --> 00:27:24.505
mathematics,
306
00:27:25.045 --> 00:27:32.185
307
00:27:33.040 --> 00:27:55.090
you know, risk of the the the cost that we are the reason I personally am not using those kind of services today is mainly because I think it's very dangerous. So if somebody says they're gonna give me 6% per annum on Bitcoin that they take from me and holding their wallet, I'm gonna think very differently than than than the case of, you know, the fiat current fiat system where I just maybe hold some stock when I never really owned it in the first place.
308
00:27:55.885 --> 00:27:58.225
309
00:27:59.245 --> 00:28:03.665
Obviously, we all agree on that. Like, I would never use that service. I tell I tell
310
00:28:04.330 --> 00:28:11.929
my audience not to use to consider the risks, like, to actually appropriately assess the risk. People don't they're not able to they're
311
00:28:13.135 --> 00:28:32.554
I but but then I'm on Twitter, you know, and I I tell people not your keys, not your coins, and they're like, it's not Mt. Gox anymore. The industry has moved up. There's it's not like it's riskless to hold your own keys. More people will lose their money if they go self custody. Yes. This time is different. Yeah. And, like, that's fine. Like, I believe that everyone
312
00:28:33.255 --> 00:28:42.330
should be able to you know, options are good and people should do what they wanna do. I'm not trying to stop anyone from doing it, but the Bitcoin privacy conversation is one
313
00:28:43.510 --> 00:28:48.410
where 61 02 is in the comments. This is also the 61 02 show because he doesn't dox his voice.
314
00:28:48.915 --> 00:28:54.695
So he joins us in the live comments. He's telling me he wants he wants the freaks to be aware that those people aren't using Bitcoin. Yes.
315
00:28:55.155 --> 00:28:57.335
Yeah. We do ideologically agree 6102,
316
00:28:58.090 --> 00:28:58.850
but I just
317
00:28:59.290 --> 00:28:59.770
it's
318
00:29:00.250 --> 00:29:02.910
the the Bitcoin privacy discussion is one where
319
00:29:04.010 --> 00:29:05.150
we we need
320
00:29:05.695 --> 00:29:07.475
we need more people to care.
321
00:29:08.095 --> 00:29:13.475
Right? Because these tools aren't effective unless we have proper scale to them. Right?
322
00:29:13.950 --> 00:29:17.809
323
00:29:18.270 --> 00:29:24.425
You know, like, we we're always concerned about increasing the, anonymity set and trying to force people to use
324
00:29:24.805 --> 00:29:31.545
complicated privacy software or privacy software that's in any way inconvenient, as you correctly point out, is really problematic if you wanna increase your anonymity
325
00:29:32.005 --> 00:29:41.920
set like that. But then on the other hand, if we try to use steganographic tools, whether they be pay join or some variant of coin swap or even Lightning, because in the future, Lightning may well be steganographic on chain.
326
00:29:43.544 --> 00:29:53.720
Is everything okay? Oh, that's just the chat window. Yeah. So so He was a scammer, so I was I was blocking it. I got you. Yeah. So the thing about the steganographic is it flips that whole equation on its head. Right?
327
00:29:54.020 --> 00:30:02.025
Because, you you suddenly what you're trying to do is is hide in the crowd of people who aren't using your technology rather than hide in the crowd of people who are using your technology.
328
00:30:04.679 --> 00:30:13.019
329
00:30:13.480 --> 00:30:13.980
Yeah.
330
00:30:14.745 --> 00:30:16.605
331
00:30:17.225 --> 00:30:19.005
332
00:30:20.185 --> 00:30:22.185
Let's talk about something really interesting. I think this
333
00:30:22.910 --> 00:30:29.010
334
00:30:31.215 --> 00:30:31.715
High
335
00:30:32.015 --> 00:30:40.674
336
00:30:49.294 --> 00:30:50.995
337
00:30:53.455 --> 00:30:54.255
338
00:30:56.059 --> 00:31:00.960
and it's and so on the on the mobile wallet front, what we have, BlueWallet has already integrated it, I believe.
339
00:31:01.580 --> 00:31:03.040
340
00:31:03.385 --> 00:31:12.685
there's there's a list somewhere. I think on the Bitcoin Wiki, there's a more reliable list on on the bit. They join the option list. Yeah. Maybe we could pull up that link for some for guys to look at.
341
00:31:13.145 --> 00:31:14.830
342
00:31:15.530 --> 00:31:22.565
343
00:31:22.945 --> 00:31:23.445
implemented,
344
00:31:24.705 --> 00:31:25.605
sender side.
345
00:31:26.145 --> 00:31:29.685
But obviously, ideally yeah. Thanks, Chris. That's it. Ideally, we want
346
00:31:31.170 --> 00:31:32.710
sender and receiver side.
347
00:31:34.530 --> 00:31:49.095
So receiver, like, in join market, we've implemented it with a hidden service. So it basically will start off an ephemeral hidden service, and you can do this in the GUI or or on the command line. And it will give you a a bit 21 URI, and you can just copy it and send it to your center
348
00:31:49.554 --> 00:31:52.470
or QR code. Just scan it, and then you can,
349
00:31:53.509 --> 00:31:55.929
then you can send the page on over to. So
350
00:31:56.309 --> 00:31:57.450
it's cool, I think.
351
00:31:58.135 --> 00:32:08.070
352
00:32:08.690 --> 00:32:18.005
And that with those coin joins, it's about you as a user transacting with someone who might spy on you. For example, you'd you'd send a CoinJoin to an exchange, and you know the exchange will spy on you.
353
00:32:18.485 --> 00:32:24.919
But with PayJoin, it's a bit different. The way PayJoin works is it's a customer and a merchant together protect their privacy against
354
00:32:25.220 --> 00:32:25.960
other people.
355
00:32:26.340 --> 00:32:34.245
So it only works if you know the if you're a user and you know the merchant is not trying to spy on you. So probably what will happen, what I, you know, I predict,
356
00:32:35.025 --> 00:32:42.200
in the future, the people that adopt Pedro and you'll be merchants and, like, you know, businesses which are already somehow victims
357
00:32:42.659 --> 00:32:49.435
of of surveillance anyway. So that would be Bitcoin casinos or p to p exchanges or places like that or donation
358
00:32:49.975 --> 00:32:54.615
359
00:32:55.015 --> 00:32:56.955
360
00:32:57.279 --> 00:33:07.895
361
00:33:08.595 --> 00:33:21.240
362
00:33:22.260 --> 00:33:26.335
363
00:33:27.195 --> 00:33:33.295
364
00:33:33.730 --> 00:33:40.789
365
00:33:41.625 --> 00:33:47.005
366
00:33:47.865 --> 00:33:52.580
367
00:33:52.960 --> 00:33:59.264
No more than you. Not more not more than a regular payment. Yeah. Right. And then on chain, someone looking at it on chain,
368
00:33:59.884 --> 00:34:01.424
it breaks the common input
369
00:34:01.725 --> 00:34:33.885
370
00:34:34.185 --> 00:34:35.645
I mean, just generally speaking,
371
00:34:35.950 --> 00:34:40.610
like, there's a there's a particular heuristic that tends to get violated in pay joins. It doesn't have to be violated.
372
00:34:41.390 --> 00:34:43.250
And but the thing is that that heuristic
373
00:34:43.695 --> 00:34:50.435
can easily and quite often is violated by normal spending transactions anyway. So without delving too much into the details, just essentially,
374
00:34:51.060 --> 00:35:02.565
it's hard to know that it's a pay join. It may be almost impossible for an outsider to know that, and it's also easy for the outside observer to be totally misled and think that the payment amount is x x whereas actually it's x minus y.
375
00:35:03.105 --> 00:35:06.525
And so that so that observer to think that 2 inputs are,
376
00:35:06.944 --> 00:35:10.440
co owned when they're not actually co owned. I'm sure, Chris will will
377
00:35:10.839 --> 00:35:13.339
will remember as well as I do the funny examples of,
378
00:35:13.880 --> 00:35:14.940
what's it called, walletexplorer.com
379
00:35:15.720 --> 00:35:17.099
that used to, like, regularly
380
00:35:17.615 --> 00:35:18.735
mark all of our,
381
00:35:19.215 --> 00:35:23.395
joint market inputs as being coming from mount or connect connected to Mt. Cox
382
00:35:23.855 --> 00:35:28.780
because, even though they were absolutely unrelated, I'd never, like, connected with Mt. Gox whatsoever,
383
00:35:29.240 --> 00:35:30.860
because the joint market
384
00:35:31.160 --> 00:35:36.075
coin joints had been joined with, people who had interacted with Mt. Gox or,
385
00:35:36.795 --> 00:35:40.734
therefore, Wall Explorer thought thought I was, you know, a Mt. Gox user or something.
386
00:35:41.275 --> 00:35:46.940
387
00:35:47.559 --> 00:35:54.925
it it appears the software wallets that have integrated so far along this new standard is BTC pay server, join market, Wasabi Wallet.
388
00:35:55.225 --> 00:35:57.005
Wasabi is only for sending.
389
00:35:57.385 --> 00:36:00.285
Blue Wallet's only for sending. Sparrow's only for sending.
390
00:36:01.545 --> 00:36:03.805
Samurai has a has a separate
391
00:36:04.569 --> 00:36:08.270
pay join implementation that's not according to the standard that they call stowaway.
392
00:36:08.650 --> 00:36:11.069
Mhmm. And then you have Electrum listed as planned.
393
00:36:11.575 --> 00:36:16.955
Then hardware wallets, cold card's the only one who supports it because they're the only one that's Bitcoin only and actually gives a shit.
394
00:36:17.494 --> 00:36:18.395
Payment processors,
395
00:36:19.769 --> 00:36:26.349
BTC pay, because really that's the the main used payment processor. Now that's a huge huge bonus for us.
396
00:36:28.250 --> 00:36:39.030
So with all that said, let's Steelman PayJoins. What is the what are the negatives? What are the negatives of PayJoins? Why can't we just rely on PayJoins as a Bitcoin privacy all encompassing solution?
397
00:36:39.730 --> 00:36:41.830
398
00:36:42.130 --> 00:36:43.990
Okay. You you go, Chris. Yeah. And
399
00:36:45.235 --> 00:37:00.180
400
00:37:00.985 --> 00:37:11.260
which actually listeners should consider doing. If they transact with a Bitcoin casino or with something like that who they think could benefit, they should nudge them and say, look. I'm your customer. Can you adopt Pedro? And I think it'll be great.
401
00:37:12.040 --> 00:37:19.740
But the fact that you have to do this and the fact that a merchant can choose to not adopt it, like Coinbase is probably never gonna adopt it, means you could they can stop it in that way.
402
00:37:20.454 --> 00:37:22.474
Mhmm. So that would be a downside.
403
00:37:22.934 --> 00:37:27.915
404
00:37:28.400 --> 00:37:32.660
405
00:37:33.360 --> 00:37:37.700
I I was thinking on the more technical level. Chris' answer is very good, but my my answer was more
406
00:37:38.005 --> 00:37:48.349
the reason why this style of coin join wasn't sort of treated too seriously as an option back in the day, like, starting from 2013 when people started discussing it on Bitcoin talk.
407
00:37:49.050 --> 00:37:56.625
I think, because this is how I thought anyway, was the oh, that's kind of messy because you have to, like, actually, in real time, negotiate
408
00:37:57.325 --> 00:38:05.019
the, the payment transaction with the receiver, which is kinda related to what Chris actually just said because the receiver has to be involved. The receiver of the payment has to be involved.
409
00:38:05.720 --> 00:38:10.215
That's it's interactive specifically in the sense that you don't just send the payment like
410
00:38:10.695 --> 00:38:14.295
like the normal let's think about the normal payment workflow. You you you have some,
411
00:38:14.775 --> 00:38:15.275
merchant.
412
00:38:15.575 --> 00:38:19.035
They, you you negotiate an invoice. They send you an address,
413
00:38:19.570 --> 00:38:20.790
as in a Bitcoin address,
414
00:38:21.410 --> 00:38:26.070
and then it's entirely up to you to take your time and use your own wallet on your own machine
415
00:38:26.744 --> 00:38:36.720
and calculate the transaction, sign the transaction, and send the transaction. And the the merchant has to do absolutely nothing. They just wait until it arrives. Whereas here, we've got to have a process whereby
416
00:38:37.260 --> 00:38:41.599
the sender actually sends a network message to the to the merchant
417
00:38:41.900 --> 00:38:42.400
and
418
00:38:44.424 --> 00:38:51.724
do stuff and then send back another mess to the sender before the sender can finally send out this specific style of pay join payment.
419
00:38:52.250 --> 00:38:58.030
So there's it's it's not a big interaction, but any interaction at all is obviously like an order of magnitude worse than no interaction.
420
00:38:58.650 --> 00:39:06.585
So because of that, that's why, for example, in join market, I had to go through a whole load of, like, testing and and figuring out how to set up an ephemeral
421
00:39:06.965 --> 00:39:20.434
Tor onion service specifically for this payment, and it, you know, fires up. Thankfully, the way Tor works nowadays I mean, that's a tangent as well, I guess, Tor v 3. But thankful thankfully, the way Tor works nowadays, it's reasonably reliable and reasonably quick to just stop a hidden service,
422
00:39:20.895 --> 00:39:26.675
and then the sender can send a message and the receiver can send a message back. So that interactivity is clearly a big negative.
423
00:39:27.090 --> 00:39:37.255
The other big negative is the hot wallet aspect specifically for a merchant. So, again, thinking of the standard model of a merchant receiving payments, and this is how it's implemented by default in BDC pay server,
424
00:39:37.875 --> 00:39:45.095
is that you are gonna use something like an x pub, and it could be like an external x pub or it could be something that BC pay server has within its own software.
425
00:39:45.450 --> 00:39:59.615
Either way, it means that when a customer comes along and tries to make a payment, you simply farm out an address to them to pay to that address, and that's all you have to do. And you don't have to worry about whether the server or the infrastructure on which you put this BTC pay server instance is as secure
426
00:39:59.915 --> 00:40:04.174
because you you're not holding private keys. You're just holding xPubs, which can go to format addresses.
427
00:40:04.520 --> 00:40:13.980
428
00:40:14.505 --> 00:40:18.205
are held on on major cloud providers to have uptime. Right?
429
00:40:18.585 --> 00:40:19.965
And they don't control the hardware.
430
00:40:20.425 --> 00:40:21.645
Early days of Bitcoin.
431
00:40:22.400 --> 00:40:25.700
Remember early days of Bitcoin? It's like everyone's servers were getting hacked.
432
00:40:26.240 --> 00:40:33.095
433
00:40:33.555 --> 00:40:43.920
that's being talked about. But it's also the same thing happens for lightning. So the lightning need coins on a on a hot wallet, and it requires information being sent back and forth. Mhmm. And
434
00:40:44.775 --> 00:40:50.954
435
00:40:51.734 --> 00:40:52.315
436
00:40:54.420 --> 00:41:05.195
Yeah. Yeah. And in in practice, people aren't gonna like to I mean, it's it's the same thing of lightning. They don't do all this stuff themselves. They have software to do it, which they have to install and click. So I have a couple other steelmans.
437
00:41:06.055 --> 00:41:06.875
438
00:41:07.975 --> 00:41:13.220
higher fees. Pay join increases your fees. Right? Because you have more you're automatically adding an an
439
00:41:14.180 --> 00:41:18.440
from a fee perspective, an unnecessary input. Is that would we agree Well, it's it's a complex.
440
00:41:18.925 --> 00:41:24.385
441
00:41:25.005 --> 00:41:26.785
the on the merchant side,
442
00:41:27.160 --> 00:41:38.185
it could change the nature of the distribution of their UTXOs over time because I I when when I first wrote the page, I joined, like, blog post about this. I I I explained this concept of the snowball UTXO. Like,
443
00:41:38.485 --> 00:41:38.985
essentially,
444
00:41:39.605 --> 00:41:53.940
if a merchant just used page join as if as in every payment came in with a page join and they started off with 1 UTXO, then they'd be consuming 1 UTXO every time they receive a payment as well as receiving 1. So they'd have 1 UTXO that was just getting bigger and bigger and bigger, which is in dramatic contrast
445
00:41:54.335 --> 00:41:59.635
to the merchant who, let's say, sells a 1,000 widgets every day to a 1,000 distinct customers. But doesn't that add a heuristic?
446
00:42:00.895 --> 00:42:10.015
Yes. Exactly. Whatever was discussed at the blog post, like that's actually a heuristic. And, plus, also consider the practicality of whether whether this would ever be at the point where everyone was using it.
447
00:42:10.575 --> 00:42:24.350
And and I could have kind of finished off the blog post by saying, well, that's actually great because we don't need or even really want everyone using it. If even if just 10% of people used it and it was plausible that 10% of people were using it, the effect on blockchain analysis would be so detrimental.
448
00:42:25.930 --> 00:42:26.590
But anyway,
449
00:42:27.210 --> 00:42:28.575
absolutely, it could be a heuristic
450
00:42:29.135 --> 00:42:30.595
and so could some other things.
451
00:42:30.895 --> 00:42:33.714
452
00:42:34.494 --> 00:42:35.474
chain analysts
453
00:42:36.015 --> 00:42:38.355
to identify that a page join was happening.
454
00:42:39.060 --> 00:42:41.000
455
00:42:41.540 --> 00:42:42.120
not unambiguously.
456
00:42:42.660 --> 00:42:44.920
457
00:42:46.235 --> 00:42:57.580
just just to get it right. So the heuristic is the things that coins get joined together until they're bigger and bigger. But that can happen with in general usage as well. Like, people combine dust together or,
458
00:42:58.060 --> 00:43:02.540
I don't know. I haven't thought about it too much, but it's possible this heuristic happens in normalization.
459
00:43:02.940 --> 00:43:04.880
460
00:43:05.235 --> 00:43:06.535
right, a very common
461
00:43:06.835 --> 00:43:07.575
threat model
462
00:43:08.115 --> 00:43:15.980
for, like, a BTC pay server. Let's say I'm accepting donations. Right? I'm a I'm an activist. I'm I'm accepting donations. Obviously, I'm a I have a privacy focus.
463
00:43:16.360 --> 00:43:17.980
Of course, I'm gonna enable pay join.
464
00:43:19.720 --> 00:43:21.980
A common thread model there is for
465
00:43:22.840 --> 00:43:24.220
who's ever trying to,
466
00:43:25.305 --> 00:43:31.244
track you would send in an it would send in an input. Right? They would pay they would pay with PayJoint. They would see what's going on.
467
00:43:31.865 --> 00:43:32.365
Yep.
468
00:43:33.130 --> 00:43:35.309
Right? So it it'd be vulnerable to that.
469
00:43:36.569 --> 00:43:39.789
470
00:43:40.195 --> 00:43:41.015
471
00:43:41.395 --> 00:43:42.135
would know
472
00:43:42.755 --> 00:43:47.015
that every transaction that Snowball is involved with is most likely
473
00:43:47.395 --> 00:43:48.855
that that user
474
00:43:49.430 --> 00:44:03.525
475
00:44:04.145 --> 00:44:07.670
Right. But the attacker can't tell which is which. So the other one, which is the donation,
476
00:44:08.050 --> 00:44:10.710
like, the change of it would end up going somewhere else. And
477
00:44:11.170 --> 00:44:14.290
do you see that the two things would get merged, the the transaction drop? So
478
00:44:15.095 --> 00:44:22.394
okay. We like, if we back up a bit. So there's the activist who accepts pay joins, and he's getting many people giving him donations.
479
00:44:23.059 --> 00:44:25.559
And the attacker has also given him one small donation,
480
00:44:25.859 --> 00:44:32.645
and they can't tell whether these inputs that he sees belong to the activist or if they belong to other people giving donations to the activist.
481
00:44:34.165 --> 00:44:36.905
482
00:44:37.765 --> 00:44:45.890
But they might also get larger for the other people who donated as well. Right. So so you would actually be you're hoping that the donators are also snowballing.
483
00:44:46.510 --> 00:44:48.690
It couldn't be just BTC pay server
484
00:44:49.285 --> 00:44:56.984
as long as other the other wallets would need to be snowballing as well. I think what you're really where I'm lost. Combining. It just means combining inputs.
485
00:44:57.569 --> 00:45:08.305
Right. But the first time I heard about the Snowball was, specifically on the BTC pay server side as a way to incentivize merchants to use it. So I I in my head, I was just assuming that only the merchant side was using that
486
00:45:08.845 --> 00:45:09.345
model.
487
00:45:09.885 --> 00:45:10.385
Right?
488
00:45:11.405 --> 00:45:12.125
Okay. Anyway
489
00:45:12.829 --> 00:45:18.109
it's a complicated issue, but I think, okay. Go ahead. Yeah. But okay. So to continue this deal, man,
490
00:45:19.630 --> 00:45:22.609
491
00:45:22.975 --> 00:45:33.640
492
00:45:34.660 --> 00:45:39.240
but we we need it to hit a certain threshold to be effective. Right? So it's kinda like you need
493
00:45:39.700 --> 00:45:42.825
a you need, like, early ideological adopters, basically,
494
00:45:43.365 --> 00:45:49.545
which is not necessarily the end of the world. I mean, Bitcoin has kind of relied on early ideological adopters throughout its full history.
495
00:45:50.500 --> 00:45:51.640
The other thing is
496
00:45:52.980 --> 00:45:56.040
I feel like a high KYC environment kind of
497
00:45:56.500 --> 00:46:00.045
throws a wrench into our plans, you know. I I don't,
498
00:46:01.165 --> 00:46:02.145
if if
499
00:46:02.685 --> 00:46:06.145
let's use our let's use our BTC pay server as an example.
500
00:46:08.170 --> 00:46:11.950
We accept pay joins. We we have pay joins enabled on on
501
00:46:12.650 --> 00:46:14.430
Okay. On, BTC pay.
502
00:46:16.330 --> 00:46:21.135
503
00:46:21.595 --> 00:46:28.569
504
00:46:29.430 --> 00:46:34.395
in the spirit of free and open source software. So if you wanna support the show, feel free to send me some stats.
505
00:46:35.095 --> 00:46:39.195
But all that said, we have BTC pay server enabled with pay join,
506
00:46:39.690 --> 00:46:42.350
and we don't know when people pay with KYC or not.
507
00:46:42.890 --> 00:46:43.790
And and
508
00:46:44.330 --> 00:46:49.230
so so, like, KYC is, like, fucking insidious, and and I I I think there's, like, a big disconnect,
509
00:46:50.075 --> 00:46:52.815
in, like, the Bitcoin privacy community because
510
00:46:53.515 --> 00:46:55.454
we're hardliners about KYC
511
00:46:55.835 --> 00:47:01.529
versus the realities of the situation, which is, like, the overwhelming majority of participants are coming in via KYC,
512
00:47:02.390 --> 00:47:06.605
and though all those inputs are obviously bagged and tagged and put in databases
513
00:47:06.905 --> 00:47:08.845
and shared around and collated,
514
00:47:10.425 --> 00:47:17.250
and kinda break through that that veil. Right? Yeah. But that's a little bit unfair. And then the last thing is,
515
00:47:17.710 --> 00:47:18.210
like,
516
00:47:18.670 --> 00:47:21.010
is anyone really gonna be making on chain payments,
517
00:47:21.895 --> 00:47:28.955
Or, like, are we are we wasting our time a little bit with PayJoint when when most people are gonna pay with lightning at least, I think, in the near term?
518
00:47:29.819 --> 00:47:32.400
519
00:47:33.500 --> 00:47:42.305
520
00:47:42.925 --> 00:47:48.320
who's, like, Open Arms is, like, our perfect demo, right, of a of a pay join paying person.
521
00:47:49.820 --> 00:47:58.905
522
00:47:59.684 --> 00:48:02.585
523
00:48:02.940 --> 00:48:05.680
like you said, 10% paid join adoption. Mhmm.
524
00:48:06.540 --> 00:48:16.695
And if we have we're splitting up the privacy focused users because the privacy focused users, a lot of them are gonna go to Lightning. I know me personally, like, if I spend, I prefer to spend the Lightning. It's a better UX.
525
00:48:18.320 --> 00:48:22.020
526
00:48:22.320 --> 00:48:25.125
a downside of PayJoint, is that something else might be better?
527
00:48:28.965 --> 00:48:30.505
528
00:48:31.205 --> 00:48:33.705
I'm I'm coming from the educator perspective,
529
00:48:36.310 --> 00:48:43.210
where where I'm I'm But that's more I'm on the front lines with new users and stuff. Right? And I'm trying to increase adoption on these different
530
00:48:43.750 --> 00:48:44.250
tools,
531
00:48:44.954 --> 00:48:49.535
and so I'm just that that's the perspective I'm coming out, I guess, from this steel man of k join.
532
00:48:49.994 --> 00:49:07.395
533
00:49:07.775 --> 00:49:09.714
there is a value even if,
534
00:49:10.414 --> 00:49:16.700
it's maybe not as pure and as simple as people would like. There's gonna be a value in all kinds of coin joins because of that.
535
00:49:19.320 --> 00:49:25.035
Pay joins as as retail payments, well, then I you you your argument is more that
536
00:49:25.335 --> 00:49:37.500
Bitcoin itself is not ideal for retail payments, so, like, base low Bitcoin, and I kind of agree with that generally. But but But these are already getting pretty high. Yeah. As of today, it's still usable, but it tends to be only really valuable
537
00:49:38.174 --> 00:49:46.770
538
00:49:58.665 --> 00:50:01.965
Fucking create like, we take that for granted that we just assume
539
00:50:02.665 --> 00:50:04.045
that makes sense to people.
540
00:50:04.910 --> 00:50:05.410
541
00:50:06.990 --> 00:50:14.994
542
00:50:15.855 --> 00:50:17.634
I'm I'm not saying that's not the case.
543
00:50:18.015 --> 00:50:18.755
I'm saying
544
00:50:19.500 --> 00:50:22.079
to me, PayJoint seems more like
545
00:50:23.260 --> 00:50:31.145
and I I know Chris disagrees with me here, so I wanna dive into this. I think I think pay join seems like more of a post mix tool to me
546
00:50:32.085 --> 00:50:33.705
after, like, a coin join,
547
00:50:34.380 --> 00:50:35.039
and then
548
00:50:35.900 --> 00:50:40.480
and then Lightning also seems like a post mix tool to me. So I think I feel like pay join
549
00:50:40.859 --> 00:50:43.525
kind of competes with Lightning more than a coin join competes with Lightning.
550
00:50:54.150 --> 00:51:01.770
551
00:51:02.385 --> 00:51:06.645
which therefore can't be on lightning. So I don't know. You want to gamble,
552
00:51:07.185 --> 00:51:12.005
10,000 Bitcoins or something ridiculous, then you send it via k page you into a Bitcoin Casino.
553
00:51:12.529 --> 00:51:20.710
Okay. It's not very realistic, but that would be You're Arthur Hayes or something. Yeah. But I think Exactly. You know? I I think that's to me to me, you would the issue
554
00:51:21.115 --> 00:51:32.750
555
00:51:33.130 --> 00:51:34.270
this kind of opportunistic
556
00:51:34.650 --> 00:51:36.985
thing rather than some kind of rigid frame
557
00:51:37.465 --> 00:51:37.965
work.
558
00:51:39.065 --> 00:52:02.765
Like, one of the ways I've used join market open I I still do to some extent, but I tend to use Lightning more now is it it I've I've used it as like, oh, let me just make a retail payment. In the old days, it was via BitPay, but I don't use them anymore. But there's other, like, coin payments and what have you. And it was like, let's just do a coin join. And now I I'm not I have no pretense that in doing this specific coin join, I am somehow magically bit making this perfectly
559
00:52:03.510 --> 00:52:08.089
blockchain analysis resistant to, you know, constructed transaction. It's just not the case.
560
00:52:08.470 --> 00:52:15.645
But every single person that does this is is it's half a political and also half of just a kind of
561
00:52:16.265 --> 00:52:16.765
commonsensical
562
00:52:17.145 --> 00:52:20.445
thing to do is just to it's like fighting for fungibility.
563
00:52:21.240 --> 00:52:28.460
Every payment I make if I'm going to make a payment online, the first thing I'm gonna check is can I use PayJoint instead of just an ordinary payment or or join market,
564
00:52:29.775 --> 00:52:31.155
because I just feel like
565
00:52:31.535 --> 00:52:38.120
it's something that every every user and participant of the system could con could consider doing as as a way of just
566
00:52:39.320 --> 00:52:44.540
sort of not I don't fight the right way, but but just sort of asserting the right to fungibility?
567
00:52:44.920 --> 00:52:45.580
You know?
568
00:52:46.895 --> 00:53:00.130
569
00:53:00.430 --> 00:53:03.330
570
00:53:03.734 --> 00:53:07.595
ideological, is it? Right? Because when I when I make a coin joint payment instead of an ordinary payment,
571
00:53:08.695 --> 00:53:14.540
I'm creating something like a part of the permanent record of Bitcoin's transaction graph, which is either less,
572
00:53:15.320 --> 00:53:15.820
disentanglable
573
00:53:16.280 --> 00:53:17.020
or totally
574
00:53:17.480 --> 00:53:19.100
not not disentanglable,
575
00:53:19.560 --> 00:53:21.180
if that's I have too many in there.
576
00:53:21.720 --> 00:53:37.780
You know, so so so so my point is is is that we we're not just being altruistic if we sit in, like, slave all way and construct these incredibly complex collections instead of just making a payment. It's not just it's not just ideological altruistic. It's it's actually creating a
577
00:53:38.240 --> 00:53:45.954
it's like a you you live in a in a housing estate, and you all share a garden and, you know, you you look after the garden a little bit because, you know, both you and everyone else involved
578
00:53:47.535 --> 00:53:54.600
will will have a happier life because of it. Yeah. I mean, not just I agree. Yeah. It's something can be ideological and self interested.
579
00:53:55.220 --> 00:53:56.600
Yes. Exactly. Yeah.
580
00:53:56.900 --> 00:53:57.400
581
00:53:58.875 --> 00:54:21.924
582
00:54:22.865 --> 00:54:23.365
583
00:54:24.130 --> 00:54:25.270
so so so
584
00:54:26.130 --> 00:54:28.610
kind of tangential, let's unpack this a little bit,
585
00:54:28.930 --> 00:54:31.830
about talking about making a you're making a point,
586
00:54:32.395 --> 00:54:34.815
you mentioned. Making a making a
587
00:54:35.435 --> 00:54:40.015
standing your ground standing your ground and and making a visible protest,
588
00:54:40.630 --> 00:54:42.170
to the surveillance economy.
589
00:54:42.789 --> 00:54:44.569
Yeah. It's kind of weird to me
590
00:54:45.029 --> 00:54:45.529
that,
591
00:54:45.910 --> 00:54:47.690
you know, I've I've been a very,
592
00:54:49.825 --> 00:54:50.724
very active
593
00:54:51.345 --> 00:54:54.964
promoter of using CoinJoin and and using Bitcoin best practices,
594
00:54:55.744 --> 00:55:01.450
and I come up right against this whole, like, compliance culture in Bitcoin land, especially among,
595
00:55:03.510 --> 00:55:10.655
you know, for better or worse, you know, I'm a public figure. People know my face, you know, they they see me at these conferences and stuff.
596
00:55:11.275 --> 00:55:13.535
So I'm I'm literally butting heads,
597
00:55:14.635 --> 00:55:20.460
with with with these other public people that are are very compliance focused, regulation focused.
598
00:55:22.360 --> 00:55:25.545
And I got a lot of pushback about this idea of of
599
00:55:26.105 --> 00:55:27.885
trying to encourage increased CoinJoin adoption.
600
00:55:28.265 --> 00:55:30.845
And a lot of my arguments were even if
601
00:55:32.025 --> 00:55:34.444
certain CoinJoin implementations aren't perfect,
602
00:55:35.950 --> 00:55:52.015
because, honestly, like, if you're a privacy advocate and you're saying something's perfect, you're probably full of shit to begin with. But even if a user screws something up, the signaling mechanism of these coins going through coin joint and being visible on chain, I think, is super important. And we're we're seeing the ramifications of this
603
00:55:52.400 --> 00:55:54.100
with all these regulated services,
604
00:55:55.600 --> 00:56:03.355
flagging them and denying service and use of them and and, you know, we even have block file. I'll pull the graphic up again just because I have it saved in here.
605
00:56:03.895 --> 00:56:06.315
Going out of their way to specifically say
606
00:56:06.855 --> 00:56:07.355
that,
607
00:56:07.920 --> 00:56:13.700
and I think they use the word mixing instead of coin joint to insinuate more criminal intent, but that they don't accept,
608
00:56:15.040 --> 00:56:18.555
mixed funds. They don't accept anything that goes through, like, Bisk,
609
00:56:19.655 --> 00:56:22.955
peer to peer exchanges. They have this whole block list or whatever.
610
00:56:23.575 --> 00:56:25.115
So there's been, like, this weird
611
00:56:25.600 --> 00:56:26.100
element,
612
00:56:26.680 --> 00:56:27.180
and
613
00:56:27.760 --> 00:56:33.700
and and I I I love the idea of of these these demographic techniques as you said, like, things like PayJo and Coinswap
614
00:56:34.195 --> 00:56:38.695
that that are really it isn't visible on chain that they're being used and they break the heuristics.
615
00:56:39.075 --> 00:56:42.695
But this idea that, like, we should hide that we're using Bitcoin privately
616
00:56:45.230 --> 00:56:47.570
seems weird to me in a world where
617
00:56:48.030 --> 00:56:52.690
we've we've gone through the same exact argument and fight with with speech,
618
00:56:54.215 --> 00:57:01.835
and and encryption is obviously is very visible. Like, people know you're using encryption. The idea is that they can't see the message anyway.
619
00:57:03.400 --> 00:57:14.765
Right. Right? Like, what's the difference? Like, why should we be ashamed of using CoinJoin? The the fact that it's visible on chain isn't as big of a negative to me. I think it, like, falls right in line with with encryption. Does it not?
620
00:57:15.545 --> 00:57:21.244
621
00:57:22.010 --> 00:57:26.410
helps you get away with it in a way. So I don't know. BlockFi, they they try and block,
622
00:57:27.210 --> 00:57:33.714
they try and censor payments which are which are coin joints. And if you can if you can stop that from happening, then that's good. Right?
623
00:57:34.734 --> 00:57:41.140
But I agree with you that with the thing, I really don't understand Bitcoin as you have that thing of we shouldn't use CoinJoin. We shouldn't use
624
00:57:41.839 --> 00:58:00.410
because even if they're only interested in it for number go up, do they really think that, say, central banks who want to print loads of money, are they just gonna allow people to just move into Bitcoin? Like, of course, they won't. They'll they'll want to spy on them. They'll want to do surveillance on them. So their whole the whole plan of number go up depends on having some kind of privacy because otherwise,
625
00:58:00.790 --> 00:58:06.155
people will take, you know, they'll take your money. They'll the number go up that you won't that you earned, they'll
626
00:58:06.535 --> 00:58:08.235
confiscate it, like, in the 6102.
627
00:58:09.575 --> 00:58:11.845
Yeah. It makes no sense to me. Order.
628
00:58:12.250 --> 00:58:17.710
Yeah. Like, the the number go up and sensitive resistance have to go together. You can't have one without the other.
629
00:58:19.290 --> 00:58:32.060
630
00:58:32.360 --> 00:58:33.980
all investors and shit in BlockFi.
631
00:58:34.280 --> 00:58:36.540
The thing is valued at, like, 2,000,000,000, $3,000,000,000
632
00:58:37.080 --> 00:58:38.700
right now. They wanna go public.
633
00:58:39.080 --> 00:58:40.220
They're offering Bitcoiners
634
00:58:40.845 --> 00:58:43.265
the ability to get 6% interest
635
00:58:43.644 --> 00:58:44.704
if they go custodial.
636
00:58:45.244 --> 00:58:46.625
They give them full KYC,
637
00:58:47.244 --> 00:58:48.865
and then on the withdrawal,
638
00:58:49.640 --> 00:58:57.740
they're not allowed to actively use Bitcoin privacy best practices. If they use active if they if they visibly use Bitcoin privacy best practices
639
00:58:58.215 --> 00:59:03.355
after they withdraw from BlockFi, not even the deposit, after they withdraw from BlockFi,
640
00:59:04.055 --> 00:59:05.675
then their account gets closed.
641
00:59:06.470 --> 00:59:10.730
That'd be like that'd be like me if I if I
642
00:59:11.110 --> 00:59:16.575
if when I withdrew money from the bank, I didn't, like, post my fucking receipt on social media,
643
00:59:17.035 --> 00:59:21.454
644
00:59:22.155 --> 00:59:24.174
We are not far away from that today
645
00:59:25.020 --> 00:59:26.240
with banks under each.
646
00:59:27.020 --> 00:59:27.760
But, yeah,
647
00:59:28.700 --> 00:59:30.080
how many hops? I'm curious.
648
00:59:30.700 --> 00:59:37.325
Well, that's the thing. No one can tell us. Right? Of course, they can't tell you. Right? Yeah. It's it's just like the legacy system. Right? It's like,
649
00:59:37.625 --> 00:59:40.925
you're not allowed to do money laundering or or or any of these other activities.
650
00:59:41.950 --> 00:59:45.089
So is this okay? And then they'll say, well, we can't tell you whether it's okay.
651
00:59:45.549 --> 01:00:04.700
So just deposit them deposit the money and then we'll figure out if it's okay afterwards. And we won't they they will block your account, and we won't tell you why it's blocked. It's the same bullshit, and it's gonna be the same bullshit every time. You just have to have some dignity and just say fuck fuck these people. Honestly, you're not really 6% isn't even that much. Right? I don't I don't know if if you can,
652
01:00:05.480 --> 01:00:06.140
653
01:00:07.615 --> 01:00:12.835
654
01:00:16.710 --> 01:00:28.245
Economic activity in the world that gives you 50% per year. So there's a golden number that you so there's a golden number that you're not gonna reveal at which you would invest in Blockfire. But if it's anywhere below or anywhere above that, you're not gonna invest in them.
655
01:00:29.345 --> 01:00:59.795
656
01:01:00.255 --> 01:01:07.715
657
01:01:08.040 --> 01:01:12.840
658
01:01:13.880 --> 01:01:29.450
659
01:01:30.630 --> 01:01:31.595
I think it's important that
660
01:01:32.135 --> 01:01:36.905
661
01:01:38.340 --> 01:01:41.080
662
01:01:41.620 --> 01:01:47.320
that I'm a rich Bitcoiner that's out of touch and that people need these interest payments to feed their family.
663
01:01:47.965 --> 01:01:52.385
And if I don't if if by me telling people that it's a risky investment,
664
01:01:52.685 --> 01:01:54.065
it's a risky move,
665
01:01:54.765 --> 01:01:59.540
that I'm I'm just completely heartless, and Dan Held liked that fucking comment.
666
01:02:00.480 --> 01:02:10.565
667
01:02:10.865 --> 01:02:13.045
Right? Not that much. If you have $6,000,000
668
01:02:13.585 --> 01:02:15.670
and you get 6% on that, then that's immediately
669
01:02:16.609 --> 01:02:22.070
$60,000, a huge amount. So 6% benefits rich people way more than it benefits poor people.
670
01:02:22.525 --> 01:02:26.945
671
01:02:27.885 --> 01:02:41.985
interest account on top of a volatile asset to feed your children if you're gonna try and lecture me on risk risk management. Like, that's fucking ridiculous, but that's all I digress. This is my my point was, do we do we all agree that this idea that regulated
672
01:02:42.285 --> 01:02:42.785
institutions
673
01:02:43.485 --> 01:02:45.745
might not accept your Bitcoin in the future
674
01:02:46.125 --> 01:02:46.945
is a bullshit
675
01:02:47.460 --> 01:02:57.595
that that's a bullshit reason to not care about Bitcoin privacy best practices, like, just opt out of those systems. That's what Bitcoin's about. Yeah. Yeah. I get it. I I I I'm I'm gonna just disagree just for the
676
01:02:58.395 --> 01:03:00.255
677
01:03:00.635 --> 01:03:08.810
I I I I don't think it's bullshit in a sense that, you know, people come people are in this space and come into this space with very, very different perspectives for all kinds of
678
01:03:09.110 --> 01:03:17.255
reasons. And, they might be a bit goosed, you know, like, what exactly they're doing. They they might be think that that they're dealing with Bitcoin or actually that they're dealing with, like,
679
01:03:17.635 --> 01:03:29.480
regulated instruments on top of Bitcoin effectively because they're really just playing around with money on exchanges, you know, and then they're just playing around with, you know, their their taxes and their accountants and just and their their their their brokerage accounts.
680
01:03:30.484 --> 01:03:33.704
But, you know, it's not completely stupid for people to think,
681
01:03:34.325 --> 01:03:51.904
you know what? I'm a stand up citizen and I abhor, and I am not gonna get involved in anything that even smells slightly of you know, they're very, like, risk averse people. You know? Okay. Fine. But but they should at least understand our point of view, that that that we actually believe in this as a as a as a different system, and we
682
01:03:52.345 --> 01:03:52.845
anyway
683
01:03:53.464 --> 01:03:56.125
684
01:03:56.920 --> 01:03:59.820
is is this is when we're talking about increasing
685
01:04:00.760 --> 01:04:05.580
the pool of of privacy focused Bitcoin users, right, to try and increase
686
01:04:06.545 --> 01:04:07.685
our own privacy.
687
01:04:09.905 --> 01:04:12.565
You're you're we're up against this
688
01:04:13.585 --> 01:04:16.800
this thought process, and I I'm telling you
689
01:04:17.340 --> 01:04:17.660
that
690
01:04:18.380 --> 01:04:27.405
and I'm curious what your guys' guys' opinion here is. I know exactly what's gonna come next. What's gonna come next, and I already see it happening amongst my peer group,
691
01:04:28.025 --> 01:04:28.525
is,
692
01:04:29.865 --> 01:04:35.869
we're gonna be sold this idea, and people are gonna, I'm gonna have them. They're all gonna attack me on Twitter about it.
693
01:04:36.250 --> 01:04:38.109
We're gonna be sold this idea that
694
01:04:38.810 --> 01:04:44.915
Bitcoin privacy best practice is to spend directly from a custodial wallet because BlockFi will protect my privacy,
695
01:04:45.935 --> 01:05:00.235
and the other person the transaction graph is completely broken, and I've done nothing wrong. And my government I can completely trust my government, and they'll protect those records. And if you look it up on on chain, you won't you won't be able to tell. And and why do I make this
696
01:05:00.775 --> 01:05:04.315
expectation? Why do I have this expectation? Why do I have this conclusion? Because
697
01:05:04.855 --> 01:05:10.300
I when people pay me in Bitcoin, I chain analysis them. Right? I look back,
698
01:05:10.600 --> 01:05:21.125
and I've called people multiple times sending me money directly from Cash App, directly from strike, and I say to them, I'm like, you sent me money directly from Cash App, for a poker game.
699
01:05:21.425 --> 01:05:30.890
You send me KYC funds directly, and you know who I am. And they're like, yeah, Matt. I didn't want you to fucking know how much Bitcoin I have, so I sent it from Cash App instead of doing it.
700
01:05:32.405 --> 01:05:46.730
Oh, I see. Right. Yeah. That's what's gonna happen. That's gonna be the next narrative. The next narrative is if you have nothing to hide, if you're not a criminal, you can just send from a custodial wallet, and you'll have perfect privacy. They're gonna say perfect privacy because they don't care about disclosing trade offs.
701
01:05:47.590 --> 01:05:48.230
702
01:05:48.710 --> 01:05:54.505
you can in that situation, they could send via lightning, then you would also not be able to tell how much money they have.
703
01:05:54.964 --> 01:06:03.990
704
01:06:04.530 --> 01:06:06.550
I have tons of respect for the developers.
705
01:06:06.895 --> 01:06:08.675
But as lightning stands right now,
706
01:06:09.295 --> 01:06:13.234
if they pay you from something like a strike or a bottle pay or something, that
707
01:06:13.935 --> 01:06:14.435
PubKey
708
01:06:15.280 --> 01:06:20.900
is is in a KYC database somewhere with the invoice, whatever you put in the invoice. So I actually had I'd
709
01:06:21.280 --> 01:06:21.780
I,
710
01:06:23.040 --> 01:06:23.540
I
711
01:06:23.895 --> 01:06:26.315
I did I did a poker game, and I was the bank,
712
01:06:27.175 --> 01:06:34.599
and I put in an invoice. I put in the invoice to keep track for my own Sovereign lightning note. I put in the invoice the guy's NIM,
713
01:06:35.700 --> 01:06:39.000
and poker. So it was his NIM plus poker. Right?
714
01:06:39.779 --> 01:06:48.655
And he paid me from strike. So strike now knows his NIM, knows we played poker, and knows my pubkey, and it's in their fucking database forever, presumably.
715
01:06:49.300 --> 01:06:50.040
No one knows,
716
01:06:50.340 --> 01:06:54.360
you know, what how what the retention is for these k y c services, but,
717
01:06:56.020 --> 01:07:07.020
718
01:07:08.380 --> 01:07:12.240
That would that would also not reveal how much money he had in his wallet.
719
01:07:13.500 --> 01:07:22.025
720
01:07:22.640 --> 01:07:29.539
Right. Right? Like, neither of us real like, there was no there's no from a UX point of view, I saw the invoice was paid. Right?
721
01:07:30.145 --> 01:07:33.745
I didn't I didn't even consider it. It wasn't even,
722
01:07:35.985 --> 01:07:38.405
I don't know. That's gonna become more common. Am I wrong?
723
01:07:39.589 --> 01:07:41.690
724
01:07:42.069 --> 01:07:46.970
there's people who people who for if it matters to someone, then they'll make the extra effort.
725
01:07:49.535 --> 01:07:54.975
726
01:07:55.375 --> 01:08:03.745
practical trade offs, including, you know, how they deal with regulators and banks and governments. I mean, they they always have done and they always will do and until there's some
727
01:08:04.145 --> 01:08:05.105
dramatic changes
728
01:08:05.665 --> 01:08:15.970
729
01:08:16.670 --> 01:08:18.030
that that you're targeting
730
01:08:18.965 --> 01:08:25.144
you you can't just we can't just target, like, OGs that care about we can't just target, like, the 1,000 OGs that care about privacy.
731
01:08:26.720 --> 01:08:34.580
732
01:08:35.040 --> 01:08:47.370
but but, you know, know, look at the he's doing it. He he's not just addressing the needs of a 1,000 OGs who are like cryptography experts. He's addressing he he is addressing people who are kind of couriers, people who like technology.
733
01:08:47.910 --> 01:08:50.330
They're playing around with things like Raspi, blitz,
734
01:08:50.790 --> 01:08:53.690
which I do as well, actually. I really like that device. It's really cool.
735
01:08:54.375 --> 01:08:59.015
But these are people who just like Bitcoin. I'm sure some of them are are relatively new.
736
01:08:59.895 --> 01:09:03.275
And, yeah, they are technically savvy much more than the average user,
737
01:09:04.290 --> 01:09:12.950
but they still like the fact that what he provides them is, like, this packaged version of join in box. They can just slap on their Like join in box. Plug in.
738
01:09:13.385 --> 01:09:19.165
Yeah. Join in box. They can just slap it into their already existing, you know, core node, lightning node, what what have you.
739
01:09:19.785 --> 01:09:27.070
Where am I going with this? Oh, yeah. The the point is, well, there's some truth, obviously, to your point, the how do we get all the masses involved?
740
01:09:28.250 --> 01:09:47.000
I have I've always been I've always had this attitude even from the early days that I always used to tell people Bitcoin is is swift, not Starbucks points, and you stop constantly, like, worrying about how you can get retail on board or whatever. Retailer always gonna do what retail do. Right? They're they're gonna use trusted third parties because that's just how people operate.
741
01:09:48.555 --> 01:09:54.655
They're all on the other hand, there are always gonna be those special people and not just people, but organizations as well. I mean,
742
01:09:55.355 --> 01:09:59.440
an example I like to give people even though it's totally fictitious is, like, the canonical
743
01:10:00.059 --> 01:10:02.719
Bitcoin user is probably a Nigerian trader
744
01:10:03.099 --> 01:10:04.960
who's sourcing products from Guangzhou.
745
01:10:05.335 --> 01:10:22.010
You know? In other words, it's not just it's not just like Joe Blogs on the street in London or or New York or whatever who's just playing around with his phone. I mean, talk to those people. There's nothing wrong with being that person. I'm just saying that isn't really what Bitcoin address is. I don't care what Satoshi wanted to use it for, vending payments or whatever, vending machines.
746
01:10:22.375 --> 01:10:24.715
The the truth is it's just not that kind of thing. It's
747
01:10:25.094 --> 01:10:28.155
much more like SWIFT. It's some very, very hard money.
748
01:10:28.855 --> 01:10:51.590
Right. It's almost financial plutonium. Like, remember people coming up to me when I was in Prague saying, no. Don't buy us in Bitcoin. I said, I I just say no. Don't buy Bitcoin. Fuck away from it. Because Right. Because, honestly, it's it's just not consumer product. Now lightning is a different story. If it gets polished enough, then maybe that's a different story. Right? I mean, in hindsight, they probably should have bought it. Right? Like, what was the price in price?
749
01:10:54.050 --> 01:10:55.190
It was near the 2017.
750
01:10:56.595 --> 01:11:15.155
It was it was like 5th 10, 15 k. Maybe they did. Yeah. Alright. I'll give it that. Literally any time in history, they should have brought me. And that's the point. They didn't deserve it unless they ignored my advice because they knew what the fuck they would do. They had their confidence in themselves to actually operate and own things like keys. That is not something ordinary people ever wanna deal with.
751
01:11:16.015 --> 01:11:17.635
I'm sorry. I know it sounds elitist,
752
01:11:18.495 --> 01:11:22.290
753
01:11:22.770 --> 01:11:24.150
I I was trying to be provocative,
754
01:11:24.530 --> 01:11:26.950
obviously. I didn't mean there's, like, a 1,000 OGs.
755
01:11:27.970 --> 01:11:31.910
I I I'm I'm not I'm not saying, like, I need grandma to use the privacy tools.
756
01:11:32.635 --> 01:11:45.889
I'm saying, like, this show this show why do I do this show? I do this show to increase the adoption of these kind of tools and these practices and spread this knowledge. Right? And I I I want people to pay it forward. Right? Like, I I I think it's it's interesting,
757
01:11:46.590 --> 01:11:50.449
where, like, a lot of people, like, I'm not competing with other podcasters.
758
01:11:51.045 --> 01:11:56.025
I would love if there's a 1,000,000 shows that cover the same exact topic. That's when we're winning.
759
01:11:57.205 --> 01:11:59.465
But, like, we have we have,
760
01:12:00.440 --> 01:12:04.780
you know, over over 20,000 people are gonna listen to this to this discussion.
761
01:12:06.200 --> 01:12:07.420
Out of those people,
762
01:12:08.335 --> 01:12:08.835
maybe
763
01:12:09.535 --> 01:12:11.635
5,000 of them have used the tools,
764
01:12:13.375 --> 01:12:15.475
and actively use the tools. Right?
765
01:12:16.660 --> 01:12:21.160
I'm talking about getting that number up by a magnitude of 10:10 x. Right?
766
01:12:21.620 --> 01:12:31.055
Let's get that number up to 50,000 people worldwide that are that care about these tools and are using these tools. And when we talk about that, when we talk about Yeah. You're right. Crossing that chasm,
767
01:12:32.860 --> 01:12:39.599
this is what we're up against. Right? We're up against the UX of the custodial regulated products. We're up against the the
768
01:12:40.935 --> 01:12:44.155
the incentives that those products are offering their users. Right?
769
01:12:45.415 --> 01:12:58.920
770
01:12:59.685 --> 01:13:08.850
they're not somewhere in London, New York, and they had so someone like, in Nigeria, you mentioned the example of Nigeria. That country has a 100,000,000 population. Right? It's a third of America. So
771
01:13:09.150 --> 01:13:09.810
they actually,
772
01:13:10.750 --> 01:13:27.900
the I think Alex Gladstein put it in another way. Bitcoin is for the other 5,000,000,000 people in the world, the people who don't have good and in fact, I can point out they actually can't use BlockFi because BlockFi only accepts customers from certain places in the world. So I question. It it could be argued. It's actually not elitism. It's the opposite. It's for more Mhmm.
773
01:13:28.360 --> 01:13:34.775
There's the old cliche of Bitcoin helping people in third world countries, but you could argue it's that. People have to hold their own coins because there's nothing else.
774
01:13:35.955 --> 01:13:39.895
775
01:13:40.360 --> 01:13:40.860
accessibility.
776
01:13:41.320 --> 01:13:41.820
777
01:13:43.240 --> 01:13:53.745
778
01:13:55.005 --> 01:14:01.159
client available. It's it's hard to run a a VPS in general nowadays on a major cloud provider without KYC.
779
01:14:02.340 --> 01:14:17.360
780
01:14:18.140 --> 01:14:21.520
yeah. Or maybe it's that. I don't remember. They they use essentially completely custodial
781
01:14:22.145 --> 01:14:26.085
versions of the tools. So it's like you you talk about the traders in Nigeria,
782
01:14:26.385 --> 01:14:45.805
that they they're constrained bandwidth wise. They're constrained cost wise. They're constrained regulatory wise, and they don't have a a solid basis of a lot of Bitcoin developers in the local area. I mean, good old Tim McMo's there, but most sadly, anybody else there who knows anything about Bitcoin. Right? So so the the the essentially, what's gonna end up happening is they go into these custodial,
783
01:14:46.265 --> 01:14:46.765
systems.
784
01:14:47.250 --> 01:14:50.869
So, unfortunately, while I agree with your point, Chris, I suspect in practice,
785
01:14:52.050 --> 01:14:56.065
while 3rd world is where Bitcoin is kind of the most useful in some
786
01:14:56.365 --> 01:14:57.825
ways, it isn't actually,
787
01:14:58.525 --> 01:15:05.969
788
01:15:06.270 --> 01:15:07.890
but Bitcoin Beach in El Salvador,
789
01:15:08.910 --> 01:15:15.285
is is fostering this this grassroots lightning community, and they do have their own wallet. Mhmm. You were correct,
790
01:15:15.825 --> 01:15:17.445
that that is custodial,
791
01:15:18.305 --> 01:15:21.605
but it's kinda cool because it's it's locally custodial.
792
01:15:22.080 --> 01:15:32.395
Right? So, like, it's, like, the local El Salvador Bitcorders are running this custodial wallet that doesn't comply with US regulations and is completely interoperable with the wider Lightning Network.
793
01:15:32.775 --> 01:15:37.680
Maybe that is gonna be something that we see scale out. You know? That kinda makes sense to me.
794
01:15:38.080 --> 01:15:39.380
795
01:15:40.480 --> 01:15:42.980
796
01:15:43.280 --> 01:15:47.060
if if if if a user and strike just so strike,
797
01:15:47.705 --> 01:15:52.845
just opened up in El Salvador, they just have bit now now they have business in El Salvador because Jack Mahler's
798
01:15:53.385 --> 01:15:57.290
fucking boss, man. Like, he flew down to El Salvador, one of the highest
799
01:15:57.930 --> 01:15:58.430
crime
800
01:15:58.970 --> 01:16:05.895
crime rates in the world. Him and Myles Suter of Cash Apps down there, both my boys are are in at Bitcoin Beach right now.
801
01:16:06.935 --> 01:16:11.115
And Wow. And strike launched in El Salvador with no banking relationship.
802
01:16:11.975 --> 01:16:18.900
And and the reason why they were able to do that is because the overwhelming amount of transactions coming from are coming from the United States
803
01:16:19.599 --> 01:16:20.099
as
804
01:16:20.400 --> 01:16:20.900
as,
805
01:16:22.755 --> 01:16:23.655
goddamn it.
806
01:16:24.275 --> 01:16:27.415
What what's the the word when you're sending money abroad,
807
01:16:29.610 --> 01:16:30.110
808
01:16:30.810 --> 01:16:42.385
809
01:16:43.085 --> 01:16:43.905
El Salvador.
810
01:16:44.525 --> 01:16:51.830
And and you and you know you know they're part of Bitcoin Beach's pilot program or whatever, but you don't know who the individual user is.
811
01:16:53.170 --> 01:16:55.875
They have their own in on an onset, basically. Right?
812
01:16:57.395 --> 01:17:03.895
813
01:17:04.640 --> 01:17:05.140
like,
814
01:17:05.440 --> 01:17:15.845
a a a card payment or a or a fee let's say a fee payment to strike, and then it gets sent over lightning to the El Salvador. Your debit card you hook up your debit card or
815
01:17:16.305 --> 01:17:19.685
816
01:17:20.890 --> 01:17:21.390
and
817
01:17:22.170 --> 01:17:23.150
you you
818
01:17:23.450 --> 01:17:26.990
it's k it's considered KYC lite because what he did was
819
01:17:27.465 --> 01:17:29.325
he had a he has a partnership
820
01:17:29.945 --> 01:17:30.685
that basically
821
01:17:31.225 --> 01:17:36.525
allows you to put in your phone number, and if the KYC infos already exists, you don't have to reenter it.
822
01:17:37.530 --> 01:17:41.790
So so you still have full KYC, but at least friction wise, it's reduced.
823
01:17:42.890 --> 01:17:45.790
And then you actually never see Bitcoin. So
824
01:17:46.225 --> 01:17:53.364
you can just scan any lightning invoice, and he'll automatically do the conversion in the behind the scenes, and the receiver receives Bitcoin.
825
01:17:53.740 --> 01:17:59.520
And the reason it's set up that way is it provides him regulatory cover because he never has to
826
01:17:59.900 --> 01:18:01.040
custody Bitcoin,
827
01:18:02.605 --> 01:18:09.345
And Yeah. It provides the user Right. A a a a pro tax way of spending Bitcoin
828
01:18:09.760 --> 01:18:24.945
because the users never actually buying Bitcoin and then spending the Bitcoin and incurring capital gains. They're just Right. They're they're just processing this transaction in the background and using Bitcoin as the rails. The receiver receives Bitcoin. So it's it's become very, very popular among
829
01:18:26.390 --> 01:18:27.930
mainstream Bitcoin Twitter,
830
01:18:29.830 --> 01:18:30.630
but it's,
831
01:18:31.670 --> 01:18:39.875
That's why I haven't heard of it. But it leaves yeah. So waxwing to the freaks to the freaks that are aware, waxwing's the first guest on the show
832
01:18:40.495 --> 01:18:45.860
who really truly cares about privacy and and and boycotts and boycotts Twitter.
833
01:18:46.240 --> 01:18:50.100
We have a bunch of freaks that are listening to this through Twitter. I'm sorry. So,
834
01:18:50.800 --> 01:18:52.580
props to you for doing that, waxwing.
835
01:18:53.315 --> 01:18:54.614
You can find them on Mastodon.
836
01:18:56.835 --> 01:19:00.535
But, yeah, is that it's an interesting dynamic that is that is has
837
01:19:01.155 --> 01:19:02.695
exist that exists now,
838
01:19:04.020 --> 01:19:11.480
839
01:19:12.005 --> 01:19:18.105
army. I think you you came a few sent you to our v army top. Yes. And it was kind of interesting to me. My eyes started to hurt.
840
01:19:18.565 --> 01:19:39.641
841
01:19:40.044 --> 01:19:44.075
the the Facebook accidentally got hacked for 533,000,000 users' accounts
842
01:19:44.635 --> 01:19:48.415
information, and they they use that to realize that Zuck is using signal,
843
01:19:48.795 --> 01:19:51.615
which is hilarious. Oh, that's cool. On WhatsApp.
844
01:19:53.980 --> 01:19:54.800
845
01:19:55.900 --> 01:19:56.880
846
01:19:57.739 --> 01:20:03.285
it's it's the the strike phenomenon is is very interesting, and it that's
847
01:20:03.905 --> 01:20:04.405
that's
848
01:20:05.185 --> 01:20:14.220
it's a it's an awesome product. It's really pushing it's pushing the tears, but this that's kind of where I come from when I say that that's what we're up against. Because you're you're trying to convince the user
849
01:20:14.760 --> 01:20:18.940
to to spend Bitcoin privately rather than using a service like that
850
01:20:19.525 --> 01:20:20.345
a lot of times.
851
01:20:20.965 --> 01:20:41.825
852
01:20:43.085 --> 01:20:44.465
853
01:20:45.699 --> 01:20:50.328
854
01:20:51.219 --> 01:20:51.880
the name?
855
01:20:52.865 --> 01:20:55.285
856
01:20:55.825 --> 01:21:08.380
857
01:21:09.160 --> 01:21:23.610
858
01:21:24.870 --> 01:21:26.570
and you never have to sell your Bitcoin.
859
01:21:28.575 --> 01:21:32.835
860
01:21:34.335 --> 01:21:38.610
861
01:21:39.390 --> 01:21:39.890
Right?
862
01:21:40.990 --> 01:21:47.974
But that's what we're up like like, you're competing when you're talking about increasing from 5 1,000 to 50,000 users.
863
01:21:48.755 --> 01:21:52.375
Right? You're you're competing against that, like, that those concepts.
864
01:21:54.114 --> 01:21:55.335
Do we agree on that?
865
01:21:57.140 --> 01:21:58.280
Well I agree. Yeah.
866
01:22:00.660 --> 01:22:02.660
867
01:22:03.140 --> 01:22:04.600
868
01:22:05.014 --> 01:22:11.675
869
01:22:12.119 --> 01:22:21.260
870
01:22:21.639 --> 01:22:22.765
you it should all be regulated
871
01:22:23.225 --> 01:22:25.645
and forget about privacy. Yeah. He's He has crazy.
872
01:22:25.945 --> 01:22:27.565
873
01:22:27.865 --> 01:22:32.240
I have you ever come close to getting a 1,000 retweets on something?
874
01:22:33.100 --> 01:22:37.600
That's crazy. That's that that's this is consensus opinion. Look at this.
875
01:22:39.644 --> 01:22:40.125
876
01:22:41.405 --> 01:22:46.144
Well, maybe it's bots. You never know. This is not smart. Oh, wait.
877
01:22:46.490 --> 01:22:48.910
878
01:22:49.450 --> 01:22:56.110
I wanna qualify. Is this the ideal mobile wallet? Well, I don't know. Maybe he's right because the ideal wallet certainly isn't on a mobile phone.
879
01:22:57.195 --> 01:22:59.215
880
01:23:00.395 --> 01:23:06.720
881
01:23:07.580 --> 01:23:10.800
882
01:23:11.580 --> 01:23:22.915
883
01:23:23.230 --> 01:23:24.989
And it will I'm sure it will be at least
884
01:23:25.710 --> 01:23:31.650
I'm sure it will you know, I the the the positive outcome is that there's a lot of usage of semi custodial
885
01:23:32.205 --> 01:23:33.985
Bitcoin like the example you give from
886
01:23:34.285 --> 01:23:36.785
which I think is a really interesting and cool example.
887
01:23:37.805 --> 01:23:47.559
And it's gonna be on phones because phones are the devices that those people have, and it's gonna be something which respects stream bandwidth limitations because bandwidth is very expensive in those places
888
01:23:48.179 --> 01:23:48.760
and unreliable.
889
01:23:49.765 --> 01:23:59.520
So we just gotta face up to the reality there. You know? It's all very nice to think of satellites and stuff, and it's all cool, but and there will be some nodes. But god, I remember back in the early days when you used to look on the,
890
01:23:59.980 --> 01:24:04.320
the maps of, like, where all the nodes were in the world. You'd look at Africa, and there'd be, like, 2 nodes
891
01:24:04.625 --> 01:24:05.925
on the entire continent.
892
01:24:06.864 --> 01:24:11.364
It's just it's just terrible, really, but I don't think it's gonna get much better, at least not quickly.
893
01:24:12.940 --> 01:24:14.240
Sorry. I'm I'm woofing.
894
01:24:14.780 --> 01:24:17.820
895
01:24:18.220 --> 01:24:20.720
We haven't even talked about coin swaps yet.
896
01:24:23.085 --> 01:24:27.105
I I just before before we move on, I just want to,
897
01:24:30.660 --> 01:24:32.360
on on on a on a bigger sense,
898
01:24:32.660 --> 01:24:37.400
what do you guys think? Like, do you feel a sense of urgency in terms of Bitcoin privacy?
899
01:24:38.065 --> 01:24:40.465
Do we have all the time in the world or should we
900
01:24:40.945 --> 01:24:43.445
is it is it important that people care right now?
901
01:24:43.824 --> 01:24:47.105
902
01:24:47.730 --> 01:24:50.390
for example, more services which block coin joins.
903
01:24:52.449 --> 01:25:02.915
Yeah. I think it's so every yeah. The more the more this goes on, the more information the the surveillance people get. And the KYC is just going farther and farther. Right? It's just like
904
01:25:04.440 --> 01:25:05.100
905
01:25:08.200 --> 01:25:08.700
Okay.
906
01:25:09.960 --> 01:25:13.325
So so we kind of talked about current Bitcoin privacy.
907
01:25:15.385 --> 01:25:20.850
Let's move on let's move on to the future. Let's let's oh, oh, no. No. No. We're not moving to the future. Sorry, freaks.
908
01:25:22.830 --> 01:25:26.370
Last last discussion we had on civil dispatch last week,
909
01:25:27.535 --> 01:25:29.795
there was some confusion about civil attacks.
910
01:25:32.335 --> 01:25:32.835
Arguably,
911
01:25:33.215 --> 01:25:34.835
civil attacks are
912
01:25:35.440 --> 01:25:36.980
the number one threat model
913
01:25:38.240 --> 01:25:40.980
for users that are trying to use Bitcoin more privately.
914
01:25:41.840 --> 01:25:45.755
Do you guys want to explain I guess, we'll start with Chris. You wanna explain,
915
01:25:46.135 --> 01:25:48.715
like, what what a Sybil attack is?
916
01:25:50.580 --> 01:25:53.719
Maybe we'll talk about Fidelity Bonds really quick. Are you talking about
917
01:25:54.260 --> 01:25:59.400
918
01:26:00.014 --> 01:26:12.970
now with with joint markets, anyone can be a maker. They just put Bitcoins in a in a bot in the wallet and then start it up and it'll become a maker. And a civil attack would be when there's an adversary who create the 10 or 20 or 50 bots,
919
01:26:13.510 --> 01:26:17.690
and has all of them on into the order book, and they all create coin joints. And
920
01:26:18.005 --> 01:26:22.264
if a you if a user is unlucky, they'll coin join, but only with these Sybil users,
921
01:26:22.724 --> 01:26:24.264
only with these Sybil makers.
922
01:26:24.645 --> 01:26:26.985
And then they would get a coin join, but
923
01:26:27.320 --> 01:26:31.420
because all the all the other all the other people in the coin join would actually be the same person,
924
01:26:32.200 --> 01:26:33.900
their coin join could be easily unmixed.
925
01:26:35.160 --> 01:26:36.140
Now the way,
926
01:26:36.635 --> 01:26:45.000
so that's called a Sybil attack because it comes from it comes from that there was someone who had, like, a mental disorder where she had multiple personalities, and she was called Sybil. Her name was Sybil.
927
01:26:45.380 --> 01:26:47.159
928
01:26:47.460 --> 01:26:48.199
929
01:26:48.500 --> 01:26:49.560
Johnson. I don't know.
930
01:26:50.020 --> 01:26:53.425
Right. Now the way the thing I'm I'm working on right now is
931
01:26:54.224 --> 01:26:54.625
a thing
932
01:26:55.344 --> 01:26:57.684
the idea is called Fidelity Bonds, which is where
933
01:26:58.304 --> 01:27:09.080
in joint markets and in in Coins Swap later, you'd have makers would also have the option of putting coins into a time locked address. For example, they could lock up their coins for 1 year or 6 months or something,
934
01:27:09.485 --> 01:27:13.264
and that's kind of like a sacrifice. You can you can precisely work it out mathematically
935
01:27:13.565 --> 01:27:25.460
how much they've sacrificed in value to lock up coins for a year or 2 years. And then takers, joint market takers, would be programmed to preferentially choose makers which have a more valuable fidelity bond.
936
01:27:26.640 --> 01:27:27.140
So
937
01:27:27.665 --> 01:27:32.804
the effect of that would mean if someone then wants to do a Sybil attack, they have to sacrifice much more value.
938
01:27:33.665 --> 01:27:38.910
I've done the I've I've got some calculations on this that if if kind of the honest order book sacrifices
939
01:27:39.370 --> 01:27:45.565
1 Bitcoin worth of value, then a similar attack would have to sacrifice about 60 Bitcoins worth of value to to
940
01:27:45.945 --> 01:27:50.445
941
01:27:50.985 --> 01:27:54.940
the with with with the Sybil attack is is is where
942
01:27:55.720 --> 01:28:04.885
the the goal when in privacy focused Bitcoin is is to be amongst a crowd. A Sybil attack in its most extreme form is that the whole crowd is a single attacker.
943
01:28:05.264 --> 01:28:17.260
So if if we're talking about fighting Sybil attacks, the plan should be to make it so that an attacker has to spend more than an a so called honest actor, someone acting in good faith. And with Fidelity Bonds
944
01:28:17.715 --> 01:28:20.455
945
01:28:21.155 --> 01:28:29.699
made the same joke that I was gonna make that they they sacrificed 6% a year. Right? Right. Of course. It's it's important to remember that the civil attacker is sacrificing 6%
946
01:28:30.160 --> 01:28:40.824
947
01:28:41.910 --> 01:28:42.410
But
948
01:28:42.950 --> 01:28:51.370
the the the the idea with Fidelity bonds is if you spread out your Bitcoin among multiple maker positions,
949
01:28:51.895 --> 01:28:56.395
that's gonna cost you significantly more money than if you just do one large maker position.
950
01:28:56.775 --> 01:28:57.275
Right?
951
01:28:59.560 --> 01:29:00.300
952
01:29:02.200 --> 01:29:05.260
And coming back to the the 6% per year idea,
953
01:29:05.640 --> 01:29:07.580
you could think of this as a way to
954
01:29:07.915 --> 01:29:13.455
earn income from your Bitcoins without I mean, join market already has this. You can earn an income from your Bitcoins without
955
01:29:13.755 --> 01:29:22.440
having without having to give up your Bitcoins. So they stay in your wallet, and you don't have to give up any KYC information, and you earn money from them. But you're on Hot Wallet. Because, like, from the
956
01:29:23.355 --> 01:29:36.140
yeah. And from the point of view of someone who's doing this, like an investor, you could call it, in a way, it competes with the BlockFi thing. So the thing that the effect that Fidelity Bonds would have is they'll make the joint market system more capital intensive.
957
01:29:36.600 --> 01:29:45.135
Like, it would require more Bitcoins to be involved. And from, like, from financial principles, you could expect that then the yields that the interest people could earn would go upwards.
958
01:29:46.450 --> 01:30:02.035
959
01:30:02.810 --> 01:30:04.170
960
01:30:05.130 --> 01:30:12.784
I mean, that's definitely true, but never forget that there is, like, a a kind of edge case because the at the very larger sizes, that isn't really as
961
01:30:13.165 --> 01:30:27.250
962
01:30:28.565 --> 01:30:33.385
Yeah. Generally, you know. Like, would we would we agree that, like, the the the biggest
963
01:30:33.764 --> 01:30:41.670
the biggest example that adoption of join market is unfortunately lower than what we were hoping for is that the fees are still pretty low.
964
01:30:42.290 --> 01:31:17.500
965
01:31:18.360 --> 01:31:22.645
966
01:31:23.745 --> 01:31:29.205
good enough. It's easy enough to use for someone who is is savvy enough to try and be a maker,
967
01:31:29.670 --> 01:31:30.170
but
968
01:31:30.550 --> 01:31:32.810
but could use work on the taker side
969
01:31:33.270 --> 01:31:46.485
to get, like, more, you know, mainstream users in. But on the maker's side, like, they have an incentive to just figure it out and and Yes. And then just to go back to my previous provocative example, like, you only really need, like, the a1000
970
01:31:47.040 --> 01:31:50.179
dedicated ideological OGs on the maker side,
971
01:31:50.960 --> 01:32:00.445
and and they can figure out the US. On the taker side, we we kinda need taker adoption to go up and then the and the fees should go up at that point. But but wait. I think there's a danger here
972
01:32:00.745 --> 01:32:05.070
973
01:32:05.630 --> 01:32:12.210
The way I try to explain this in the past is that that there's many, many costs and benefits to add in to the to the system. So
974
01:32:12.565 --> 01:32:13.605
on the on the,
975
01:32:15.045 --> 01:32:15.864
maker side,
976
01:32:16.244 --> 01:32:21.945
there are benefits such as the the passivity means you don't have to make decisions. The fact that you,
977
01:32:23.190 --> 01:32:24.250
you you get,
978
01:32:24.710 --> 01:32:25.210
privacy
979
01:32:25.510 --> 01:32:35.545
while you don't spend Bitcoin network transaction fees, which are which are usually the larger by far of the 2 components of fee is the is the Bitcoin network transaction fee.
980
01:32:35.845 --> 01:32:48.220
So the unusual thing you know, like, if you came at the joy market from the point of view of something like Wasabi, you you understand that or at least the first anyway. Yeah. The the taker's, like, bearing that entire cost and distributed among all the participants.
981
01:32:49.165 --> 01:32:55.585
So there's several, I mean, advantages the taker gets such as being able to choose an exact size. Go go ahead.
982
01:32:56.230 --> 01:32:59.750
983
01:33:01.030 --> 01:33:06.495
a taker and joy market is considerably cheaper than Wasabi. Everything out everything equal. Wasabi's
984
01:33:07.275 --> 01:33:10.255
Wasabi's coin joint fee is dramatically high.
985
01:33:11.275 --> 01:33:11.675
It's like
986
01:33:12.960 --> 01:33:16.980
like, it it you you save a ton of money if you're a taker in your market. Yeah.
987
01:33:17.840 --> 01:33:22.175
But even the network fee, the network fee is a 100 inputs or whatever. Sorry. Continue.
988
01:33:23.835 --> 01:33:55.220
989
01:33:55.895 --> 01:34:03.275
Another advantage you get, which if you compare it to, like, other CoinJoin implementations is you could do any size, including very large sum principle.
990
01:34:03.910 --> 01:34:10.475
So there's a lot and the and, of course, the biggest, maybe the most crucial advantage that the taker gets is that you're supposed at least, assuming there's no bug,
991
01:34:10.875 --> 01:34:18.575
it's supposed to be the case that you don't reveal any information about your inputs and outputs to the other participants in the whereas the maker doesn't get that advantage.
992
01:34:19.920 --> 01:34:24.500
So there's all these advantages. On the other side, it has the advantage of, well, I'm not paying any network transaction fee,
993
01:34:24.800 --> 01:34:27.220
and I can just leave it runnatively and,
994
01:34:27.695 --> 01:34:44.380
a couple of other things I can't remember. But but the point is that there's many different, like, components of cost and benefit to play in. And the fact that it works out the most of the time, we're talking about, like, tens to hundreds of sats for coin joint fee. Only if you'd go to larger sizes does that price get significantly larger.
995
01:34:45.005 --> 01:34:52.065
It's just it's just the result of all these, like, difficult to measure factors. And I I totally agree, by the way. None none of this is to disagree with what Chris just,
996
01:34:52.605 --> 01:34:53.824
expounded on fidelity
997
01:34:54.210 --> 01:34:55.590
bonds as it would add
998
01:34:56.050 --> 01:34:59.030
a much stronger anti civil effect, which means that,
999
01:35:00.130 --> 01:35:06.905
most likely or almost certainly, the prices will go up because the quality of what's being offered is gonna be is gonna be higher.
1000
01:35:07.365 --> 01:35:08.345
But I would also
1001
01:35:08.805 --> 01:35:13.980
mention because I I wanted to mention this because I think it earlier podcast is that when we had this bug recently,
1002
01:35:15.080 --> 01:35:21.260
well, we could talk about the bug if you like. But but the thing is We could talk about that. But Okay. We'll we'll talk about it in a minute. But I just wanna say that,
1003
01:35:22.365 --> 01:35:27.345
people do have 1 and you specifically, I think, perhaps have forgotten a rather, important,
1004
01:35:27.725 --> 01:35:34.240
change that was made to join market as a system about, I don't know, 2 years ago. I can't remember exactly when, which is that the,
1005
01:35:35.420 --> 01:35:39.675
it's slightly less it's significantly, I would say, less syllable than it used to be
1006
01:35:39.994 --> 01:35:41.215
in as much as,
1007
01:35:42.554 --> 01:35:43.934
you don't have the situation
1008
01:35:44.235 --> 01:35:53.360
where somebody can simply of the lowest possible fee and just almost automatically get chosen. Because it was kind of sort of like that in the early days where there was another exponential.
1009
01:35:54.220 --> 01:35:59.520
Well, it was it was kind of an exponential distribution giving too much weight to the very lowest fees.
1010
01:35:59.885 --> 01:36:05.105
And all that we changed was we made it so that without going to huge amount of detail, we made it so that,
1011
01:36:05.565 --> 01:36:10.280
when a taker comes along, he doesn't just aim for the very lowest fees possible, but he aims for
1012
01:36:10.580 --> 01:36:26.469
1013
01:36:27.170 --> 01:36:31.750
the reason I bring this up, first of all, is that, I mean, people should do their own research.
1014
01:36:32.445 --> 01:36:41.550
Fucking people say that too much in this space. People should listen to the the the last conversation we had with No Power and Open Arms. But No Power just, like,
1015
01:36:42.730 --> 01:36:47.395
is extremely frustrating when you start talking about sibling. Right? Because because it
1016
01:36:47.935 --> 01:36:50.035
when we're talking about actively seeking
1017
01:36:50.495 --> 01:36:54.835
privacy when using Bitcoin, we're talking about very well funded actors,
1018
01:36:55.720 --> 01:36:57.900
that are very secretive in what they do.
1019
01:36:58.200 --> 01:37:04.540
And I'm talking about the chain analysis of the world. I'm talking about the Elliptics of the world, and I know their founders listen to this show.
1020
01:37:06.555 --> 01:37:07.615
Elliptic, especially,
1021
01:37:08.475 --> 01:37:10.015
like, Tom, I know you're listening.
1022
01:37:11.035 --> 01:37:17.100
I appreciate that you're you're very upfront with what you do, to a degree, but everything is very secretive.
1023
01:37:17.640 --> 01:37:24.205
And if we're talking about them and we're talking about threat modeling them in an active an attempt to actively
1024
01:37:24.745 --> 01:37:26.205
seek privacy in Bitcoin,
1025
01:37:26.985 --> 01:37:29.645
the threat model is is that they're gonna try
1026
01:37:30.260 --> 01:37:30.920
and flood
1027
01:37:31.619 --> 01:37:42.465
our usage. Right? And in in joint market in joint market, we're talking about them being multiple makers. Right? They're gonna be multiple makers, and they're gonna offer very low prices.
1028
01:37:43.005 --> 01:37:49.489
Mhmm. Right? And they're gonna try and be as in as many of of your make arounds as possible. Do we agree on that?
1029
01:37:50.909 --> 01:38:04.815
I don't know if we agree that it actually is happening, but it certainly No. I'm not saying it's happening. We don't know what's happening. That's the crazy part. Right? Yeah. Is that we're talking publicly, but they're not talking publicly about this shit. So we don't know if it's happening or not. But the if they were to attack joint market
1030
01:38:05.170 --> 01:38:07.750
from a Sybil scenario, that's how they would do it. Right?
1031
01:38:08.849 --> 01:38:15.844
Yeah. They would do it on the maker side. Yeah. Right. And that's what Fidelity Bonds is trying to solve is, like, is is is so that it becomes
1032
01:38:16.545 --> 01:38:18.965
way more expensive for them to be multiple makers
1033
01:38:19.905 --> 01:38:23.284
Yeah. Yes. Than than be a single maker. Right?
1034
01:38:25.320 --> 01:38:29.820
But Yep. But if they're a regulated entity like chain analysis,
1035
01:38:31.094 --> 01:38:32.074
can't they just
1036
01:38:33.415 --> 01:38:34.395
can't they just
1037
01:38:34.855 --> 01:38:40.670
reduce that that fidelity bond risk? The idea is that that you have such a large Fidelity Bond
1038
01:38:40.970 --> 01:38:44.670
that you have this massive price risk. Right? You have to lock up Bitcoin,
1039
01:38:44.970 --> 01:38:48.030
which is nice because first of all That's not right.
1040
01:38:48.955 --> 01:38:53.775
1041
01:38:54.395 --> 01:38:58.540
in the maths of it is that, the the value of your fidelity bond is
1042
01:38:58.840 --> 01:39:06.415
the amount of Bitcoins you have squared. So for 5 Bitcoins, it would be 5 times 5 is is 25. If you have 6, it's 6 and 636.
1043
01:39:06.795 --> 01:39:10.975
And that means people are trying to to lump up their Bitcoins into 1 bot.
1044
01:39:12.449 --> 01:39:29.705
Right. But Right. There probably is a risk where it doesn't come into the analysis of it. Like, you know, you can analyze proof of work to see how it works. Right. But you're I mean The way this thing there's a there's a strong incentive for someone to lump up their Bitcoins into 1 bot rather than if they spread it out over many different bots, then they have a disadvantage, a strong disadvantage.
1045
01:39:30.110 --> 01:39:37.570
But if I recall correctly if they if Chainalysis is doing this, they would they would have to it ends up working out. They'd have to own, like, a $100,000,000
1046
01:39:38.110 --> 01:39:40.355
worth of Bitcoins or something. Right. Right. So
1047
01:39:40.895 --> 01:39:43.395
1048
01:39:44.255 --> 01:39:49.090
They can just borrow they can just borrow on BlockFi. Right? That that's what I'm saying. Right? But that's exactly what I'm saying.
1049
01:39:49.710 --> 01:39:54.369
Can they just can't they just if they're a regulated entity, they don't care about privacy.
1050
01:39:54.909 --> 01:39:57.969
They can borrow this shit. They can hedge it with shorts.
1051
01:39:58.335 --> 01:40:05.635
They can do all these different things. Right? And and and and the cool part about Fidelity Bonds is that it's not a hot wallet, which is awesome.
1052
01:40:06.500 --> 01:40:07.000
Yeah.
1053
01:40:07.700 --> 01:40:09.800
Right? I'm I'm correct on that. I recall correctly.
1054
01:40:10.420 --> 01:40:21.875
Yeah. Which is awesome. So you don't have hot wallet risk. So, really, what you have is capital risk. Right? You have you have to you have to own this much Bitcoin and Bitcoin's a volatile asset, which is kinda nice
1055
01:40:22.210 --> 01:40:30.550
in terms of a trade off if you're a Bitcoiner, which is the same trade but it's the same trade off it's it's on a high level, it's the same trade off as
1056
01:40:30.905 --> 01:40:33.005
trying to actively surveil lightning.
1057
01:40:33.385 --> 01:40:39.645
In that, they have to force number go up if they try and they have to, like, literally buy Bitcoin and own Bitcoin.
1058
01:40:40.790 --> 01:40:55.295
1059
01:40:55.755 --> 01:40:56.255
investment.
1060
01:40:57.680 --> 01:41:02.340
That's the that's how you work out things in financing. It's called the cost of capital.
1061
01:41:02.640 --> 01:41:05.220
1062
01:41:05.545 --> 01:41:07.965
if they're chain analysis and they're valued at $2,000,000,000
1063
01:41:08.744 --> 01:41:12.205
and their former chief counsel is now the head of FinCEN,
1064
01:41:12.850 --> 01:41:15.590
Like, they can just hedge that risk on CME
1065
01:41:16.449 --> 01:41:23.445
and just take out a short in Bitcoin equivalent amount, and then they have no they have no opportunity cost whatsoever, really.
1066
01:41:24.225 --> 01:41:25.925
1067
01:41:27.105 --> 01:41:39.295
So they'd pay interest on the the thing they're borrowing. You're right. So, yeah, those short positions have a cost of carry. Right. Right. They have they have a carry cost. But they're making up for it in their, like, 200,000, 400,000
1068
01:41:39.675 --> 01:41:43.135
1069
01:41:45.650 --> 01:41:49.910
1070
01:41:51.490 --> 01:42:04.520
if people all this works in the sense that it costs a lot of money to attack it. So if the attacker does already have money, then it won't work. So you're right about that. It's the same with Bitcoin mining. If someone spends less of money on miners, then they can do a 51% attack.
1071
01:42:06.260 --> 01:42:08.280
1072
01:42:09.220 --> 01:42:11.000
Because mining, you have, like,
1073
01:42:12.265 --> 01:42:19.805
with mining, you have, like, physical you have to get physical chips, which right now, by the way, there's a massive shortage, which is why we haven't seen
1074
01:42:20.210 --> 01:42:29.510
difficulty go up with price. Like, you can't get ASICs right now. And then you actually have to, like, plug them into to power. You know, you have to actually have power wherever you're located.
1075
01:42:31.925 --> 01:42:32.985
If buying a $100,000,000
1076
01:42:33.285 --> 01:42:35.305
worth of Bitcoin on the open market
1077
01:42:35.765 --> 01:42:37.685
and then staking it is not that
1078
01:42:38.650 --> 01:42:42.750
I mean, it's difficult for us, but it's it's not that difficult for a
1079
01:42:43.290 --> 01:42:46.270
a a company that's valued at $2,000,000,000 that just raised a $100,000,000,000,
1080
01:42:46.810 --> 01:42:47.949
like, 2 weeks ago.
1081
01:42:48.975 --> 01:42:56.515
1082
01:42:57.290 --> 01:42:59.550
very glibly nowadays are talking about a $100,000,000
1083
01:42:59.850 --> 01:43:00.350
figure
1084
01:43:00.810 --> 01:43:07.755
because Right. The maybe when when when Chris first started writing a few Python to create joint marketing, we weren't thinking about a $100,000,000
1085
01:43:08.535 --> 01:43:09.755
attackers on our system.
1086
01:43:10.215 --> 01:43:15.035
And the second comment is, like, I have got this strong intuition, which may turn out to be totally wrong,
1087
01:43:15.390 --> 01:43:17.570
but the people who do this kind of an analytical
1088
01:43:18.510 --> 01:43:20.290
work are gonna be very
1089
01:43:21.390 --> 01:43:23.410
leery about committing engines
1090
01:43:23.775 --> 01:43:38.280
to these kind of sibling. It's I I it just says a little anecdote, and I don't think it's real, but it gives you a kind of flavor of it. That in late 2016, when we were experiencing this kind of a different kind of sibling attack, we might call it a snooping at some joint market where,
1091
01:43:39.060 --> 01:43:43.320
a bunch of people were coming along as as takers, not makers, coming along as takers,
1092
01:43:43.844 --> 01:43:45.145
starting the negotiation
1093
01:43:45.525 --> 01:43:50.905
of coin points and then stopping in order to try to collect UTXO information from makers. Right.
1094
01:43:51.330 --> 01:43:58.310
When when we implemented a defense against that, which basically consisted of a kind of a souped up commitment that forced
1095
01:43:58.875 --> 01:44:05.935
takers to, at some point in the negotiation, reveal their own and reveal that they'd never been used before for this kind of commitment.
1096
01:44:06.560 --> 01:44:14.180
It basically meant that if somebody wanted to continue doing that attack, they would have had to keep revealing new UTXOs to us, like in the 1,000.
1097
01:44:15.145 --> 01:44:28.580
And I I I I'm guessing that the the reason they stopped is not because it costs much, but because they just that's just not a thing you wanna do as an attack. Now maybe if you're chain analysts, you, a, are prepared to spend 100 of 1,000,000 of dollars on this, and, b, are prepared,
1098
01:44:29.040 --> 01:44:36.275
to reveal, like, on chain UTXOs to that you're doing this attack. But I suspect probably they're not prepared to do that. Just a suspicion.
1099
01:44:38.340 --> 01:44:43.000
1100
01:44:43.940 --> 01:44:45.560
my kind of point of view is
1101
01:44:45.935 --> 01:44:51.635
you know, that old saying, if you want peace, prepare for war. But I'd imagine what to do in a in, like, the worst possible situation.
1102
01:44:52.335 --> 01:44:55.155
1103
01:44:55.840 --> 01:44:56.340
1104
01:44:56.880 --> 01:45:10.535
But I I think there's a strong there's still a strong analogy between Bitcoin mining and how if you have a lot of money, you can attack Bitcoin and these Fidelity bonds where if you have a lot of money, you could attack joint markets. And if if your attacker just has loads of money, there's nothing really you can do.
1105
01:45:11.210 --> 01:45:16.110
1106
01:45:16.490 --> 01:45:19.310
increase in value so much, so they get cost prohibitive.
1107
01:45:20.795 --> 01:45:23.935
But in the short term, I mean, there's there's a massive advantage.
1108
01:45:24.395 --> 01:45:30.550
If if if there is a a chain in a a chain surveillance firm, it's important we call them what they are.
1109
01:45:31.329 --> 01:45:34.550
If there's a surveillance firm, a very competitive industry,
1110
01:45:35.010 --> 01:45:35.510
arguably,
1111
01:45:36.365 --> 01:45:37.345
the 2 industries
1112
01:45:37.725 --> 01:45:39.585
the 3 industries in Bitcoin
1113
01:45:40.045 --> 01:45:44.945
sub industries in Bitcoin that make the most money are the regulated exchanges, completely captured,
1114
01:45:45.540 --> 01:45:47.080
the chain surveillance companies,
1115
01:45:47.380 --> 01:45:51.160
completely captured by design. They capture people. And then,
1116
01:45:52.180 --> 01:45:54.200
and then these fucking lending services,
1117
01:45:54.915 --> 01:46:00.775
that are offering you 6% for custody of your coins, and and you're never gonna get those coins back out, presumably.
1118
01:46:02.034 --> 01:46:03.735
Those are the 3 most valuable
1119
01:46:04.370 --> 01:46:06.550
tranches in in Bitcoin land.
1120
01:46:07.170 --> 01:46:08.710
If if you're talking about,
1121
01:46:09.410 --> 01:46:13.510
I'm I'm a regulated institution or I'm the IRS or I'm the DEA
1122
01:46:14.035 --> 01:46:18.055
or I'm the CIA, and I'm trying to decide who I give the $15,000,000
1123
01:46:18.755 --> 01:46:19.735
contract to.
1124
01:46:21.330 --> 01:46:25.750
The firm the the surveillance firm that is unwinding joint market
1125
01:46:27.170 --> 01:46:30.630
compared to the firm that isn't unwinding joint market is way more valuable
1126
01:46:31.155 --> 01:46:32.055
from a subscription point of
1127
01:46:32.435 --> 01:46:32.935
view.
1128
01:46:34.355 --> 01:46:53.615
1129
01:46:54.155 --> 01:47:06.210
So America and China and Russia and North Korea or whatever, they all need to agree to, like, together do a similar attack, which might be possible, but it's also maybe that geographical arbitrage could also help us.
1130
01:47:06.865 --> 01:47:19.780
1131
01:47:20.080 --> 01:47:20.820
I often
1132
01:47:21.335 --> 01:47:30.560
try to tell, like to tell people, which I have no idea if it's true or not, is, like, there could be another joint market trading trading pit out there that nobody knows about or that some people know about and I don't.
1133
01:47:31.680 --> 01:47:35.860
The the nature of open source software is kind of really helpful in this, and and and just
1134
01:47:36.160 --> 01:47:40.815
just generally using Tor and just not using it. But, of course, the flip point is exactly
1135
01:47:41.195 --> 01:47:45.670
why why we have so much difficulty in having to come up with very complicated or
1136
01:47:46.070 --> 01:47:46.570
sophisticated,
1137
01:47:47.110 --> 01:47:50.969
defenses against things like Sybil is for the same reason that we we explicitly
1138
01:47:51.590 --> 01:47:53.610
reject the concept entity in the system.
1139
01:48:00.015 --> 01:48:00.575
1140
01:48:01.215 --> 01:48:01.715
So
1141
01:48:02.410 --> 01:48:05.290
that that was very awesome. That was a great discussion, guys.
1142
01:48:06.570 --> 01:48:10.430
I don't know if that discussion has happened publicly before. I don't think so.
1143
01:48:11.815 --> 01:48:13.675
1144
01:48:14.295 --> 01:48:18.615
1145
01:48:19.265 --> 01:48:19.700
see.
1146
01:48:20.980 --> 01:48:21.480
I,
1147
01:48:23.180 --> 01:48:27.320
I mean, the the reason I I I keep harping on it is because, specifically,
1148
01:48:28.215 --> 01:48:29.835
chain analysis has gotten
1149
01:48:30.615 --> 01:48:33.355
they've they the the company chain analysis,
1150
01:48:34.695 --> 01:48:37.035
the surveillance company chain analysis
1151
01:48:37.690 --> 01:48:38.430
has gotten,
1152
01:48:40.330 --> 01:48:49.575
is is by far the largest in the space. They're the elephant in the room, followed second, maybe I we we got 61 or 2 in the comments by Coinbase who has their own,
1153
01:48:50.355 --> 01:48:52.615
chain technology now, the chain surveillance
1154
01:48:53.075 --> 01:48:53.575
firm
1155
01:48:54.200 --> 01:48:56.540
within Coinbase, like their own tool
1156
01:48:56.840 --> 01:48:57.740
within Coinbase.
1157
01:48:58.120 --> 01:49:01.500
And and and, presumably, Coinbase itself is holding
1158
01:49:02.744 --> 01:49:03.645
over 15
1159
01:49:04.824 --> 01:49:05.324
1,500,000
1160
01:49:06.025 --> 01:49:06.505
Bitcoin,
1161
01:49:08.425 --> 01:49:10.525
because because we know they have
1162
01:49:10.869 --> 01:49:11.369
about
1163
01:49:11.670 --> 01:49:12.889
900 bit 900,000
1164
01:49:13.190 --> 01:49:14.730
Bitcoin of customer funds,
1165
01:49:15.349 --> 01:49:18.969
in proper Coinbase, and then Coinbase Custody at least has GBTC,
1166
01:49:20.455 --> 01:49:21.755
which is, like, another 800,
1167
01:49:22.535 --> 01:49:23.675
uh,000 coins.
1168
01:49:24.295 --> 01:49:26.715
So so we know that they're at least holding,
1169
01:49:27.510 --> 01:49:37.614
about 1a half and, like, the sailors of the world and stuff are all going to Coinbase Custody. So they they are holding a a ton of coins. They have a ton of users. They're going public. They have their own chain surveillance.
1170
01:49:37.994 --> 01:49:39.454
So it is kind of,
1171
01:49:41.994 --> 01:49:54.345
aggregating to single actors. Right? And and and as that happens, that centralization in the chain surveillance space, that hurts us, as you said. Like, I agree on that. Like, we we actually want it'd be better if we had multiple active attackers,
1172
01:49:55.445 --> 01:49:59.385
when you when you started to throw them all this up. But but all this said,
1173
01:50:01.679 --> 01:50:09.540
strictly, it's I think it's it's super important. We're we're an hour and 50 minutes in. I appreciate you guys' time. I think it's super important for us to to
1174
01:50:09.865 --> 01:50:12.365
to pull this back that if you're actively
1175
01:50:13.145 --> 01:50:18.190
trying to use CoinJoin, trying to use Bitcoin best practices, you're you're strictly in a better
1176
01:50:24.830 --> 01:50:26.050
sibling these things.
1177
01:50:27.355 --> 01:50:41.290
You're you're strictly better off, and you should you should use it. That's part of the solution, and it's very important that people use these things, but it's it's also very important that we openly discuss these concerns. These are the threat models. These are the the threats that we're trying to work against.
1178
01:50:42.070 --> 01:50:43.370
So with all that said,
1179
01:50:43.725 --> 01:50:47.825
where where are we going in the future? What what do we have to look forward to as Bitcoiners?
1180
01:50:50.125 --> 01:50:54.810
1181
01:50:56.949 --> 01:50:58.409
1182
01:50:59.270 --> 01:51:00.710
1183
01:51:01.885 --> 01:51:04.784
as as you may have seen, I've, I've released a version
1184
01:51:05.485 --> 01:51:07.824
of it that works on test net and chest.
1185
01:51:08.284 --> 01:51:17.910
And it doesn't have all the features, but it can do multi hop and multi transaction coin swaps. So they are you could think of that as like coin join, like an on chain privacy technology,
1186
01:51:18.265 --> 01:51:23.565
but it's it looks like a regular transaction kind of. Although right now has a multi sig. It has a 2 of 2 multi sig.
1187
01:51:23.945 --> 01:51:24.025
And,
1188
01:51:24.905 --> 01:51:27.180
you could someone could use that to mix their coins.
1189
01:51:27.820 --> 01:51:47.449
Now the reason I'm doing the reason I'm right now working on Fidelity bonds on joint market is partly to improve joint market, but also partly to kind of get used to the idea to have it sort of out there in the wild as an experiment of people actually using it to see if the Fidelity Bonds idea works and if there's anything that can be improved on it. And after that's done, then I'll go back to working on coin swap,
1190
01:51:47.989 --> 01:51:52.650
to make it to carry on work and get it towards so that it works on main net.
1191
01:51:54.065 --> 01:51:55.045
Okay. So I think,
1192
01:51:55.745 --> 01:51:58.565
yeah, that that's, that's where I am at right now.
1193
01:51:59.105 --> 01:52:01.284
1194
01:52:02.130 --> 01:52:03.750
talking about getting blacklisted
1195
01:52:04.290 --> 01:52:05.829
off of exchanges again,
1196
01:52:06.369 --> 01:52:07.349
on the chat,
1197
01:52:08.530 --> 01:52:11.750
and and disagreeing that you're better off using CoinJoin.
1198
01:52:12.215 --> 01:52:15.595
Look, if if you wanna, we said this earlier, but just to recap,
1199
01:52:15.975 --> 01:52:19.755
like, if if if you want to be a part of the surveillance economy,
1200
01:52:20.370 --> 01:52:23.270
by all means, you know, keep it in the same address,
1201
01:52:24.130 --> 01:52:25.190
maybe use custodial
1202
01:52:25.650 --> 01:52:31.885
custodian option. I don't fucking know. Like, if if you wanna practice all the best practices in terms of regulatory compliance,
1203
01:52:32.345 --> 01:52:38.270
by all means, proceed with that. But when we're talking strictly from a privacy point of view,
1204
01:52:38.810 --> 01:52:39.949
using these tools
1205
01:52:40.650 --> 01:52:44.670
are are net benefit. I mean, you shouldn't use them thinking that they're perfect.
1206
01:52:45.244 --> 01:52:54.864
I don't want you guys, like, making mistakes and assuming that you're completely anonymous. Like, that'd be horrible. I don't want that. But but strictly from a privacy point of view,
1207
01:52:55.310 --> 01:52:57.970
attempting to use these tools, using these tools is gonna
1208
01:52:59.950 --> 01:53:14.780
is is you're in a better privacy situation than if you don't do it otherwise. I mean, they're they're cataloging everything you do when you use these regulated institutions. They have they have your personal information. They have every financial transaction you're making. It's all getting recorded on a ledger that's gonna exist forever.
1209
01:53:15.320 --> 01:53:20.300
This ledger is gonna exist forever. It's all gonna be there. Even if you don't fuck things up now,
1210
01:53:20.680 --> 01:53:24.935
even if you don't realize you fucked things up now, that can come back to haunt you in 10 years.
1211
01:53:26.515 --> 01:53:27.495
Back to Coinswap.
1212
01:53:30.890 --> 01:53:32.030
Chris, Coinswap
1213
01:53:32.810 --> 01:53:33.310
is
1214
01:53:34.730 --> 01:53:38.909
is same concept as PayJoint in terms of being a steganographic,
1215
01:53:40.775 --> 01:53:42.395
strategy, right, to break heuristics.
1216
01:53:43.735 --> 01:53:47.675
1217
01:53:48.190 --> 01:53:51.090
transaction or more than one regular Bitcoin transactions.
1218
01:53:51.550 --> 01:53:55.410
1219
01:53:55.870 --> 01:53:56.370
is
1220
01:53:58.315 --> 01:54:04.255
that on chain, the user the the anyone looking at the chain should not be able to know it's a Coinswap. Right?
1221
01:54:06.110 --> 01:54:07.730
1222
01:54:09.230 --> 01:54:13.409
1223
01:54:14.625 --> 01:54:17.605
you might be accused of something that's not you you're doing.
1224
01:54:19.025 --> 01:54:21.125