CD34: mobile phone privacy with @sethforprivacy
EPISODE: 0.3.4
BLOCK: 695186
PRICE: 2194 sats per dollar
TOPICS: mobile phone privacy, iOS, calyxOS, grapheneOS, why privacy is important, open hardware, corporate surveillance, defcon, spending vs hodling, bitcoin vs monero tradeoffs
@sethforprivacy: https://twitter.com/sethforprivacy
streamed live every tuesday:
https://citadeldispatch.com
twitch: https://twitch.tv/citadeldispatch
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://anchor.fm/citadeldispatch
telegram: https://t.me/citadeldispatch
support the show: https://tippin.me/@odell
stream sats to the show: https://www.fountain.fm/
join the chat: http://citadel.chat/
00:00 - The overly broad definition of the word broker in the cryptocurrency bill
00:40 - The lack of understanding of cryptocurrency among senators
02:13 - Mobile phone privacy and the importance of personal privacy
50:50 - Comparison between Calix and Graphene privacy guarantees
51:50 - Difference between GrapheneOS and CalixOS in terms of app compatibility
52:16 - Micro g as a privacy-preserving alternative to Google Play Services
53:43 - Discussion on using Calix OS with or without Micro g
54:32 - The unique funding model of the Calix Foundation
58:16 - The importance of funding development costs in the FOSS ecosystem
01:00:30 - Choosing the right Google Pixel phone for Calix OS
01:04:46 - The benefits and risks of using Google Pixel devices with Calix OS
01:12:21 - Installing apps on Calix OS without Google Play Store
01:18:15 - Using Kallix OS and recommended apps
01:26:43 - The limitations and workarounds for certain apps on Kallix OS
01:39:39 - Threema's background service for message retrieval without Google Play services
01:40:08 - Reasons for not using Micro g
01:40:40 - Benefits of paying for privacy-focused apps
02:31:29 - Concerns with Bitcoin's base layer and privacy
02:32:26 - Challenges of pulling people into Bitcoin
02:33:08 - Focus on Monero as an easily approachable tool
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 8:12:32 PM
Duration: 10453.499
Channels: 1
1
00:00:00.240 --> 00:00:02.580
2
00:00:04.240 --> 00:00:06.899
Those who would have to collect information on cryptocurrency
3
00:00:08.055 --> 00:00:08.555
consumers
4
00:00:08.855 --> 00:00:13.594
and report this information to the IRS. It would force every single participant
5
00:00:13.975 --> 00:00:14.795
in the cryptocurrency
6
00:00:15.255 --> 00:00:15.755
structure
7
00:00:16.170 --> 00:00:17.950
to operate as a financial institution,
8
00:00:19.050 --> 00:00:24.990
which would mean they would have to provide consumer information to the IRS even if they don't have access to that information.
9
00:00:28.225 --> 00:00:30.805
This overly broad definition of the word broker
10
00:00:32.065 --> 00:00:34.245
will block rapid innovation in cryptocurrencies,
11
00:00:35.020 --> 00:00:38.400
and it will endanger the privacy of many Americans in cryptocurrencies.
12
00:00:39.100 --> 00:00:41.280
This is wrong. So I applaud
13
00:00:43.315 --> 00:00:44.695
my colleagues for Trump. Fortunately,
14
00:00:45.075 --> 00:00:51.495
because the senator from Vermont objected that incremental approach hasn't been adopted. So let's exercise a brief
15
00:00:52.050 --> 00:00:53.750
shining moment of common sense,
16
00:00:55.170 --> 00:00:56.309
and let's recognize
17
00:00:56.610 --> 00:01:02.645
if we've gathered all 100 senators in this chamber and ask them to stand up and articulate 2 sentences
18
00:01:03.185 --> 00:01:05.205
defining what in the hell a cryptocurrency
19
00:01:05.745 --> 00:01:06.245
is
20
00:01:07.900 --> 00:01:11.440
that you would not get greater than 5 who could answer that question.
21
00:01:14.220 --> 00:01:15.600
Given that reality,
22
00:01:17.685 --> 00:01:28.890
the barest exercise of prudence would say we shouldn't regulate something we don't yet understand. We should actually take the time to try to understand it. We should hold some hearings. We should consider the consequences.
23
00:01:29.270 --> 00:01:31.690
We shouldn't destroy people's lives and livelihoods
24
00:01:33.545 --> 00:01:34.845
from complete ignorance.
25
00:02:13.709 --> 00:02:19.170
26
00:02:19.695 --> 00:02:24.595
the interactive live show about Bitcoin distributed systems privacy and open source software.
27
00:02:25.375 --> 00:02:27.395
This is Citadel dispatch 34.
28
00:02:27.990 --> 00:02:30.330
Our focus is gonna be mobile phone privacy.
29
00:02:32.150 --> 00:02:37.130
I wanna do a quick shout out as I usually do to the ride or die freaks joining us
30
00:02:37.845 --> 00:02:39.064
via the live chat
31
00:02:39.685 --> 00:02:43.305
that it comes through on Twitter, Twitch, and YouTube.
32
00:02:43.685 --> 00:02:46.905
Appreciate you guys. You make this show unique and special.
33
00:02:47.870 --> 00:02:49.170
Also wanna shout out
34
00:02:49.470 --> 00:02:56.530
all the freaks who support the show. This show is a 100% audience funded with no ads or sponsors. It will always be the case,
35
00:02:57.165 --> 00:02:58.705
and you guys make that possible.
36
00:02:59.005 --> 00:03:04.385
The easiest way for you to do that is through podcasting 2.0 by going to new podcast apps.com,
37
00:03:05.420 --> 00:03:13.120
picking a podcasting 2.0 app, loading it up with Sats, searching for Citadel dispatch, and you can stream Sats directly to my node.
38
00:03:13.445 --> 00:03:18.665
It is appreciated, and it's pretty cool watching them stream in after the podcast feeds go up.
39
00:03:19.525 --> 00:03:22.800
You can also support the show at the website, sidildispatch.com.
40
00:03:24.060 --> 00:03:25.440
I have a pane m there.
41
00:03:25.900 --> 00:03:27.600
It's easy to remember. It's Odell.
42
00:03:28.620 --> 00:03:29.520
You can also
43
00:03:30.005 --> 00:03:31.145
support it through lightning@citildispatch.com
44
00:03:32.485 --> 00:03:36.345
using the tip and dot me link. So thank you, guys. I do appreciate it.
45
00:03:37.210 --> 00:03:40.430
To those freaks coming in through the audio feeds,
46
00:03:41.690 --> 00:03:44.990
that was senator Ted Cruz on the floor of congress
47
00:03:46.785 --> 00:03:48.004
talking about cryptocurrency.
48
00:03:49.025 --> 00:03:51.105
I don't think that we should take extra
49
00:03:52.305 --> 00:03:53.285
you know, I
50
00:03:54.690 --> 00:03:57.350
I I doubt his, you know, I doubt his motives,
51
00:03:57.810 --> 00:03:59.590
but, it is pretty interesting
52
00:04:00.610 --> 00:04:01.510
watching it
53
00:04:03.355 --> 00:04:11.855
be you know, we're everyone's noticing us now. We're we're we have the attention of regulators everywhere. We have the attention of senators and congressmen.
54
00:04:13.500 --> 00:04:15.920
A lot of what we've heard over the last
55
00:04:16.300 --> 00:04:18.080
week has been disappointing
56
00:04:18.700 --> 00:04:19.600
but expected.
57
00:04:20.700 --> 00:04:22.000
But at the same time,
58
00:04:22.475 --> 00:04:34.810
to hear Ted Cruz basically call out everyone for not having any idea what Bitcoin or cryptocurrency is is a bit of a breath of fresh air, and it is really crazy to see. So I'm glad we're gonna have that archived in the Citadel dispatch archives forever.
59
00:04:35.270 --> 00:04:36.810
With the archives being mentioned,
60
00:04:37.110 --> 00:04:38.330
once again, you can
61
00:04:38.825 --> 00:04:40.605
view all previous dispatches@cidildispatch.com.
62
00:04:42.585 --> 00:04:44.685
There's Bitcoin TV links there,
63
00:04:45.065 --> 00:04:48.125
which is our peer tube instance dedicated to Bitcoin content,
64
00:04:49.530 --> 00:04:50.910
hosted on our own servers,
65
00:04:51.930 --> 00:04:56.350
and, there's also links to the audio. And I think you can also search
66
00:04:56.725 --> 00:05:05.145
through all the transcripts too, which is actually a really useful feature. I don't think people realize it's there. It is algorithmic instead of, like, a human transcribing it. So
67
00:05:05.520 --> 00:05:10.419
there are a lot of errors, but it is nice that you can just search keywords through there. So keep that in mind.
68
00:05:11.120 --> 00:05:13.940
Anyway, guys, I'm really excited for our guest today.
69
00:05:14.365 --> 00:05:16.385
We have Seth for privacy here.
70
00:05:17.405 --> 00:05:23.345
He is the host of the Opt Out podcast, a very good podcast. We have, actually a lot of overlap with guests.
71
00:05:24.130 --> 00:05:31.350
He's he's had Catan on there. He's had Diverter on there recently. He had Max Tannahill on there, all previous guests
72
00:05:31.945 --> 00:05:34.445
of Cielo Dispatch and good friends of mine.
73
00:05:35.065 --> 00:05:37.725
The podcast is excellent. I highly recommend it.
74
00:05:38.720 --> 00:05:41.620
Also, me and Seth, we kinda go way back on Twitter.
75
00:05:42.080 --> 00:05:48.794
I think, Seth, I think we met at Bitcoin 2019, if I recall correctly. You introduced yourself. So welcome to dispatch.
76
00:05:50.055 --> 00:06:00.150
77
00:06:00.690 --> 00:06:09.655
and Bitcoin in general, drives home that idea of self sovereignty and taking back control, and mobile privacy is a huge part of that. So glad to be able to to to dive into it with you here.
78
00:06:10.675 --> 00:06:12.675
79
00:06:13.715 --> 00:06:14.294
I mean,
80
00:06:14.835 --> 00:06:16.694
mobile phone privacy is
81
00:06:18.020 --> 00:06:25.720
on the top of everyone's minds right now because of the recent iPhone announcement, Apple announcement. But before we jump in there,
82
00:06:27.205 --> 00:06:29.705
I mean, you've dedicated so much of your life,
83
00:06:30.645 --> 00:06:32.585
to privacy and personal privacy.
84
00:06:33.685 --> 00:06:39.150
Do you wanna tell the freaks why they should care about privacy, why they should care about their own privacy?
85
00:06:40.970 --> 00:06:44.430
86
00:06:44.754 --> 00:06:51.014
we can come back to, and a a lot of the like, one of the things that I enjoy about my podcast is I could just sat sit down with people
87
00:06:51.315 --> 00:07:00.670
and just hear a little bit more about, like, their personal privacy journey and what drove them to to see the need for privacy and to tar start taking steps to to take back their privacy. And,
88
00:07:02.455 --> 00:07:10.235
the big thing for me that jumps out is just the the simple idea, and it's a phrase people have probably heard, but just that the privacy is the ability to selectively
89
00:07:10.789 --> 00:07:13.050
selectively reveal oneself to the world.
90
00:07:13.990 --> 00:07:19.095
And just it's really a way for you to control the data about you, to control the
91
00:07:19.655 --> 00:07:28.225
the things that other people are able to see or not see. It's not about necessarily hiding things, not about necessarily hiding criminal activity or anything like that, but,
92
00:07:28.920 --> 00:07:31.720
it's really just about having that that control over your data,
93
00:07:32.440 --> 00:07:37.580
and I think a lot of times here, at least for me, I'm I'm in the West. I'm in the US, and
94
00:07:37.914 --> 00:07:44.095
people who grew up in areas that are a little bit better off or maybe have at least a a better facade of freedom,
95
00:07:45.360 --> 00:07:51.780
we can kind of get caught up in the idea that we we don't have anything to hide and that it doesn't really matter that all of our data's out there, that these
96
00:07:52.155 --> 00:08:01.190
these companies are just pulling in our data by troves. They're gathering information about where we go, who we visit, the apps that we use, how long we use those apps, where we click in the apps,
97
00:08:01.830 --> 00:08:06.730
that they're gathering data on all the people that we talk to, when we talk to them, what we talk to them about.
98
00:08:07.510 --> 00:08:12.525
That has been going on for years years. Mean, we've we've seen it with the government, with the NSA, and,
99
00:08:12.985 --> 00:08:20.789
now I think we're starting to take steps towards corporate surveillance being the bigger problem than governmental surveillance, at least in the in the west here. And,
100
00:08:21.569 --> 00:08:30.605
people that have at least the privileges that I've had growing up, I haven't felt the the harsh pressure of an authoritarian regime or the harsh pressure of,
101
00:08:31.065 --> 00:08:36.589
persecution of, like, myself or my family or my maybe a religious group or something like that.
102
00:08:37.449 --> 00:08:46.365
So I haven't seen the need that's, like, life or death. But a lot of people in the world have seen that, and they fight for that privacy, that that right to be able to decide what they reveal and to who.
103
00:08:47.065 --> 00:08:52.600
And I think that it's a responsibility for those of us who do have that freedom and and have access to those tools to
104
00:08:53.060 --> 00:08:56.680
to go ahead and jump in, focus on taking back our own personal privacy.
105
00:08:57.220 --> 00:09:14.140
And then as we go along that route, no one is too no one is too small or unknown or, maybe not technical. No one is is too far to be able to just write down the things that they do, share the that's the steps that they take towards privacy, and help pull other people into that journey over time.
106
00:09:15.995 --> 00:09:21.375
107
00:09:21.995 --> 00:09:26.490
First, you know, you said that corporate surveillance is becoming more of an issue.
108
00:09:27.750 --> 00:09:33.450
I seem I've noticed that it seems so intertwined now at this point. Right? It's like corporate surveillance
109
00:09:34.935 --> 00:09:35.835
is is almost
110
00:09:36.215 --> 00:09:39.675
it's an extension of state surveillance. And Mhmm.
111
00:09:40.455 --> 00:09:42.970
All that all that data that that these corporations
112
00:09:43.830 --> 00:09:46.490
are hoovering up oftentimes for their own
113
00:09:47.110 --> 00:09:48.010
profit motive,
114
00:09:48.790 --> 00:09:53.955
ends up in state hands. And even if you trust your government now, you don't really know,
115
00:09:55.215 --> 00:09:58.675
what the next government will be or what the next situation will be. Right?
116
00:10:02.130 --> 00:10:04.470
And then the other thing you mentioned was
117
00:10:04.850 --> 00:10:05.670
you evoked
118
00:10:07.685 --> 00:10:09.065
the cypherpunk manifesto,
119
00:10:10.725 --> 00:10:11.545
with privacy,
120
00:10:13.125 --> 00:10:15.144
with your comments on privacy, and
121
00:10:16.259 --> 00:10:17.320
there's a there's
122
00:10:18.019 --> 00:10:24.085
there's something interesting here with, you know, part part of part of that quote before the quote is that
123
00:10:24.565 --> 00:10:29.065
privacy is not secrecy. It's the ability to selectively reveal yourself to the world.
124
00:10:29.685 --> 00:10:30.185
And
125
00:10:30.565 --> 00:10:31.065
you,
126
00:10:32.160 --> 00:10:37.700
for better or worse, seem to have ended up in the same situation as me, where you're a public persona,
127
00:10:39.495 --> 00:10:42.155
a public person talking about privacy.
128
00:10:43.095 --> 00:10:49.600
How do you and I often get a lot of shit, like, oh, you know, you can't talk about privacy if
129
00:10:49.900 --> 00:10:53.600
if you're publicly talking about it. Like, obviously, you don't care about your privacy
130
00:10:54.965 --> 00:10:58.345
if if we we know what you look like, and we know who you are.
131
00:10:59.285 --> 00:11:03.920
You obviously don't take it that seriously. How do you circle that square? How do you,
132
00:11:06.540 --> 00:11:20.470
if if if when someone says to you, like, oh, you don't care about privacy because you're a public person talking about it, how how do you answer them? Yeah. Yeah. I'll I'll dive into the the first point you mentioned real quickly first. I accidentally didn't unmute. Wrong keyboard shortcut there.
133
00:11:21.250 --> 00:11:29.235
134
00:11:29.935 --> 00:11:32.195
the law and just social pressure
135
00:11:32.574 --> 00:11:35.954
onto these companies, they can get them to to do their work for them,
136
00:11:36.560 --> 00:11:41.779
and just take away the the need for them to do governmental surveillance or take away the need for them to do governmental censorship.
137
00:11:44.495 --> 00:11:49.714
But I think another reason why corporate surveillance is becoming so much of a problem is because it it pervades
138
00:11:50.574 --> 00:11:52.035
cross country lines.
139
00:11:52.490 --> 00:12:06.115
It's something that usually will follow you no matter if you move countries, no matter if you leave. It's usually something that very easily crosses borders. And sometimes governmental surveillance can cross borders. There's lots of agreements. There's 5 eyes and 13 eyes and
140
00:12:06.495 --> 00:12:15.630
different, groups of countries like that that do share data, but sharing data between governments is always tricky because they're trying to get the leg up on each other even when they're technically allies.
141
00:12:16.985 --> 00:12:17.805
But I think corporate surveillance
142
00:12:18.185 --> 00:12:25.485
has a lot more danger in that sense, and the services that we're using on the daily are normally things that were being sold as free.
143
00:12:26.250 --> 00:12:29.870
And the thing that they're selling us as a a service and taking our data.
144
00:12:30.649 --> 00:12:46.660
And so I think that's it can be a little bit sneakier than hearing that, like, the government surveilling you, and that can seem a little bit maybe conspiracy theorist or something to to think that the government's watching what you do. But we know that corporations are doing it. We've seen them do it time and time again, and it's only been growing as we've seen,
145
00:12:47.440 --> 00:12:52.965
monopolies around, specifically, like, social media is is one of the key areas. Social media and messaging apps.
146
00:12:53.445 --> 00:13:07.610
We've seen the monopolies around that shut down the smaller options. And then once they have control, they're able to really leverage that that surveillance and censorship, to sell your data and make themselves money or to censor and to push their own personal beliefs on the people that are using the platform.
147
00:13:09.375 --> 00:13:16.915
And as for the whole idea of kind of revealing more about your public personality or persona versus just using an m,
148
00:13:18.589 --> 00:13:21.810
I I definitely I go back and forth on this. I mean, as things get
149
00:13:22.589 --> 00:13:26.995
a little bit scarier here in the US over time, I I lean towards going to a NIM,
150
00:13:27.935 --> 00:13:32.115
but, obviously, I've built up this brand that is set for privacy,
151
00:13:32.495 --> 00:13:37.780
which it I definitely wanna keep this this following. It's a it's a great group of people. It's people that are passionate about privacy
152
00:13:38.400 --> 00:13:41.060
and have followed me through a lot of different steps that I've taken.
153
00:13:42.004 --> 00:13:45.865
But I think the key thing for me is I I think there is a lot of value
154
00:13:46.245 --> 00:13:47.144
in there being
155
00:13:48.004 --> 00:13:48.504
non
156
00:13:49.100 --> 00:13:56.860
pseudonym people that are willing to step up, willing to put a little bit more at risk, willing to put a little bit more on the line to become that,
157
00:13:57.665 --> 00:14:14.360
those people that can kind of draw in the less trustful people. I think a lot of people can be a little bit worried about pseudonyms or can feel like if someone has a NIM, they're not trustworthy. And, I don't think there's a reason for that. I think names are great that many people should probably use that instead of using the real name in almost every circle.
158
00:14:15.459 --> 00:14:16.339
But I think that
159
00:14:17.055 --> 00:14:24.895
I think it's useful for some people to just own at least part of their name or I mean, it it couldn't even be a fake name. Like, obviously, you don't know that my name is Seth, but,
160
00:14:26.200 --> 00:14:43.870
to own a little bit of that public persona, to own a a face and an image, and it helps to draw people in, especially kind of normies who maybe wouldn't be as comfortable with just jumping in and following all the things that a random NIM on the Internet says. So I think there's definitely value, but it is definitely it's extra risk,
161
00:14:44.650 --> 00:14:46.990
and it can complicate things as far as keeping
162
00:14:47.850 --> 00:14:53.925
keeping other aspects of life private if you do have any kind of linkage to your name, picture, that kind of thing.
163
00:14:55.345 --> 00:14:56.165
164
00:14:57.185 --> 00:14:59.045
100% cosign that message.
165
00:15:00.625 --> 00:15:01.925
Grapple with it daily.
166
00:15:02.880 --> 00:15:04.740
Do you have do you ever have any regrets
167
00:15:05.520 --> 00:15:06.180
with that?
168
00:15:08.800 --> 00:15:11.220
169
00:15:11.894 --> 00:15:14.154
that I was so open early on.
170
00:15:15.255 --> 00:15:24.150
Obviously, the things that I know and can remove, I've I've gone through and removed. But I, obviously, before I jumped into privacy, which was only very recent, I think a lot of people may just assume because
171
00:15:24.530 --> 00:15:26.630
the main thing I talk about is is privacy,
172
00:15:27.010 --> 00:15:34.055
both in the cryptocurrency space and just generally that that I'm someone who's, like, been thinking deeply about privacy for a decade or something. But
173
00:15:34.515 --> 00:15:37.895
it's really recent. I mean, really, I started caring more about it in
174
00:15:38.680 --> 00:15:45.579
2018, 2019. Probably even 2019, I think, would be when I started to really grapple with why personal privacy matters.
175
00:15:47.165 --> 00:15:51.565
And so I think before that, obviously, I was careless with social media and the things that I shared.
176
00:15:52.445 --> 00:15:58.180
So I think I think if you go into it knowing what you're doing, you you know that you're going to be sharing,
177
00:15:59.040 --> 00:16:10.355
at least a theoretically real name and a face that can be a little bit easier to to latch on to. I think just being careful, obviously, about how you how you use that because if there is a a link to real life, it could be
178
00:16:10.839 --> 00:16:14.460
can be more dangerous for you and can make tying things together a little bit easier.
179
00:16:15.880 --> 00:16:18.460
I don't say I have any regrets. Just that,
180
00:16:19.464 --> 00:16:27.005
yeah, I'm I'm glad that I did it. I think I will keep doing it, but it is definitely as things get tighter and tighter, it it's tempting to
181
00:16:27.649 --> 00:16:32.790
to become a pseudonym rather than sticking with any kind of semblance of in real life personality.
182
00:16:33.490 --> 00:16:35.350
183
00:16:36.755 --> 00:16:38.215
I don't know about you, but
184
00:16:39.795 --> 00:16:41.335
I exist on many nims.
185
00:16:43.630 --> 00:16:44.130
But,
186
00:16:45.310 --> 00:16:50.130
there there's there's definitely I can I can definitely relate with that path? I mean,
187
00:16:52.055 --> 00:16:57.035
with me, it happened a little bit earlier, but, you know, you kinda have, like, an moment where you realize
188
00:16:57.975 --> 00:17:02.720
I I think in today's world, most people, when they discover the importance of privacy,
189
00:17:03.260 --> 00:17:05.440
it's a it's a discovering of,
190
00:17:06.275 --> 00:17:07.095
oh, shit.
191
00:17:07.875 --> 00:17:08.375
I
192
00:17:08.755 --> 00:17:10.135
I'm completely exposed.
193
00:17:10.835 --> 00:17:16.030
And, that's when you start to realize why privacy why personal privacy really matters. Right?
194
00:17:17.210 --> 00:17:19.630
195
00:17:20.250 --> 00:17:24.350
having a real persona and pseudonyms is not something that
196
00:17:24.995 --> 00:17:27.735
that can't coexist. Like, those are definitely things that go together.
197
00:17:28.035 --> 00:17:34.375
I use pseudonyms as well for different platforms. I think everyone that I know who has chosen to reveal something about themselves on social media
198
00:17:34.850 --> 00:17:50.355
usually has other names that they go by and other things. And I think that's that's excellent. And, like, something I do is I use a tool like SimpleLogin to do email aliasing and the things that I use email aliases for. I'm obviously not using a a name with that kind of thing, so there's definitely power in pseudonyms.
199
00:17:50.760 --> 00:17:53.020
Like I said, I would recommend most people use pseudonyms,
200
00:17:53.880 --> 00:18:00.620
but I I do think that there's there's value in this. And outside of the the one persona that I think is valuable to have
201
00:18:01.115 --> 00:18:07.455
a more real persona attached to, which is my Twitter account and then obviously is the host of my podcast.
202
00:18:08.530 --> 00:18:15.650
Outside of that, I think pseudonyms are infinitely better. There's there's not really any comparison. You should avoid using, I think, real information wherever possible. But
203
00:18:17.605 --> 00:18:18.105
204
00:18:18.725 --> 00:18:20.424
Okay. So let's go back to,
205
00:18:20.965 --> 00:18:22.745
corporate surveillance. I mean,
206
00:18:23.205 --> 00:18:28.660
you made an interesting point there. Like, if if the government says they're reading all your emails,
207
00:18:30.160 --> 00:18:31.380
people tend to have
208
00:18:32.559 --> 00:18:39.385
a naturally revolting reaction to that. But if Google says they're doing it to serve you better ads and give you free email,
209
00:18:40.085 --> 00:18:40.905
people don't.
210
00:18:41.205 --> 00:18:51.280
If Facebook is tracking your location everywhere you go, people, for whatever reason, tend to have less of a reaction to that than if you found out your government was
211
00:18:51.684 --> 00:18:54.664
tracking your location everywhere you go. But at the end of the day,
212
00:18:55.365 --> 00:18:57.784
in both those scenarios, the end result
213
00:18:58.404 --> 00:19:00.904
ends up the same. Right? That data gets logged,
214
00:19:01.950 --> 00:19:06.610
and it can find the hands, whether that's in the government or it can find the hands of a malicious individual,
215
00:19:08.404 --> 00:19:14.265
get shared with all their partners. It's the same end result. But for whatever reason, people seem to be more,
216
00:19:15.284 --> 00:19:17.740
comfortable with sharing it with these corporations
217
00:19:18.360 --> 00:19:19.420
than they do,
218
00:19:21.880 --> 00:19:25.100
if if it's if it's explicit if it's explicit from
219
00:19:25.804 --> 00:19:26.845
a government actor.
220
00:19:28.524 --> 00:19:29.745
So recently,
221
00:19:30.845 --> 00:19:34.865
we had this news that Apple will be scanning photos,
222
00:19:35.870 --> 00:19:36.850
that are stored
223
00:19:38.990 --> 00:19:40.050
on a person's
224
00:19:40.350 --> 00:19:43.330
local device on their phone and on
225
00:19:43.715 --> 00:19:44.375
the cloud,
226
00:19:44.675 --> 00:19:46.855
the Icloud or whatever they wanna call it.
227
00:19:47.315 --> 00:19:48.935
The Icloud has never been,
228
00:19:50.355 --> 00:19:51.655
encrypted end to end,
229
00:19:52.250 --> 00:19:54.190
so they've always had that functionality
230
00:19:55.130 --> 00:19:55.630
capable.
231
00:19:57.130 --> 00:19:58.170
Right? We have,
232
00:19:58.570 --> 00:20:00.990
Bitcoin in the audience. His name is Bitcoin,
233
00:20:02.385 --> 00:20:04.885
Clarifying that they're scanning hashes of photos,
234
00:20:06.545 --> 00:20:10.885
to match them with whatever their blacklist of hashes is, which isn't transparent.
235
00:20:12.370 --> 00:20:15.510
But the end result is the same. They are scanning your device,
236
00:20:17.010 --> 00:20:21.685
and there's been a lot of pushback on that, but they're going ahead with it anyway.
237
00:20:22.465 --> 00:20:27.320
So, recently, there's been before that, I mean, Apple made a very big push to
238
00:20:28.500 --> 00:20:29.000
privacy,
239
00:20:29.700 --> 00:20:30.200
and
240
00:20:30.580 --> 00:20:31.720
a lot of their advertisements
241
00:20:32.179 --> 00:20:34.440
were about how if you want privacy,
242
00:20:34.740 --> 00:20:39.365
Apple is the product you wanna do, whether that's a computer or whether that's a phone.
243
00:20:41.505 --> 00:20:45.125
I I think before we jump into the, you know, privacy specifics,
244
00:20:45.980 --> 00:20:48.160
privacy specific OSes and phones,
245
00:20:49.580 --> 00:20:53.679
what is your what is your comment to someone who
246
00:20:54.425 --> 00:20:56.045
chooses iPhone or chooses
247
00:20:56.745 --> 00:20:59.325
Apple products for privacy? Why shouldn't they,
248
00:21:00.960 --> 00:21:03.780
why is that not a good option for someone seeking privacy?
249
00:21:05.200 --> 00:21:11.405
250
00:21:11.865 --> 00:21:12.765
I really think
251
00:21:13.145 --> 00:21:17.725
I'll start off with the positive. I do think that Apple is generally better than
252
00:21:18.580 --> 00:21:23.879
Android, specifically when we're talking mobile privacy. I think they've generally had better policies in place.
253
00:21:24.259 --> 00:21:30.835
They've generally been firmer about the requirements that they put out for apps in the App Store. They've had the recent really good push,
254
00:21:31.695 --> 00:21:40.980
about the the whole right to track idea where an app has to request if they can track you or not, and you get a very clear, do I wanna allow them to track me or not prompt.
255
00:21:42.080 --> 00:21:44.100
And we've seen lots and lots of people
256
00:21:45.375 --> 00:21:50.515
answer no to that, obviously. Because when you're presented with the with the clear question, you jump into,
257
00:21:51.455 --> 00:21:54.035
you jump to to no. You don't wanna share that data.
258
00:21:56.080 --> 00:22:02.660
But with this license this latest push, I mean, they've had kind of a big marketing thing going for a while now pushing privacy.
259
00:22:03.040 --> 00:22:04.975
And I think they've latched on to the
260
00:22:05.675 --> 00:22:08.475
the narrative that's been increasing lately, which is,
261
00:22:09.675 --> 00:22:11.775
that people are starting to wake up to privacy,
262
00:22:12.155 --> 00:22:15.440
and they they realize that's it's a great tool for marketing.
263
00:22:15.760 --> 00:22:18.659
If they can jump on a a trend, jump on a narrative,
264
00:22:19.200 --> 00:22:25.065
and jump on something that their competitors do poorly, which is Android. Android has generally been very poor for privacy,
265
00:22:26.405 --> 00:22:34.890
they realize they can make more money. So I'm not saying that everyone at Apple is necessarily malicious or using it just to make money. I think there there are probably people there who
266
00:22:35.429 --> 00:22:41.655
do legitimately care about privacy and think they're doing the right thing, and have built out, again, like I said, some some good privacy measures.
267
00:22:43.075 --> 00:22:48.710
I think at the end of the day, it's it's marketing. They wanna they wanna pull you in. They wanna get you using their devices,
268
00:22:49.650 --> 00:22:54.710
and get you under their ecosystem, which they've always made very hard to get out of, and they've always made it very
269
00:22:55.054 --> 00:22:59.154
holistic where you you need to get all of the different devices and things and accounts to
270
00:22:59.695 --> 00:23:00.754
to tie it all together.
271
00:23:02.095 --> 00:23:02.914
So I think
272
00:23:03.590 --> 00:23:12.570
iOS is generally alright for privacy. It has been very secure for a long time. That's one been one of its strengths, is that it is very secure against attacks. They they patch
273
00:23:12.965 --> 00:23:15.225
bugs and and vulnerabilities very quickly,
274
00:23:15.685 --> 00:23:20.185
and across the whole board of devices. You don't have to wait for different timings on
275
00:23:20.799 --> 00:23:22.960
on releases to patch those things, which is important.
276
00:23:24.320 --> 00:23:27.140
But it really to me, it's a it's a marketing push. And, I mean, this
277
00:23:27.520 --> 00:23:28.260
this latest
278
00:23:28.804 --> 00:23:35.065
this latest thing with photo scanning, it's a it's a tricky one because they chose to focus it on
279
00:23:36.220 --> 00:23:54.005
something that is that something that everyone should be against, which is child pornography. That was the focus of this this effort is to help to to shut that down, to shut down, rings around that and and sharing of of images. And, like, obviously, that's 100% a good thing. Like, no one no one would disagree with that,
280
00:23:55.140 --> 00:23:55.640
but
281
00:23:56.020 --> 00:23:56.520
that
282
00:23:56.820 --> 00:23:59.000
really job pornography, terrorism,
283
00:24:00.420 --> 00:24:05.015
have been 2 of the kind of boogeymen that get used for a lot of attacks on privacy and freedom.
284
00:24:06.615 --> 00:24:13.860
Again, not to say that those two things are not bad, but just to say that they are constantly used as a a fear inducing tool
285
00:24:14.640 --> 00:24:17.860
to push against privacy or to push against personal freedoms.
286
00:24:19.095 --> 00:24:24.395
And so that's what they that's what they chose to use this latest push for or to use for this latest push.
287
00:24:24.934 --> 00:24:27.275
And the the concept itself
288
00:24:27.610 --> 00:24:31.070
seems relatively harmless if you're just reading it at face value that they'll
289
00:24:31.530 --> 00:24:53.205
take caches of the images on your device. And for anyone who doesn't know, what what that means is that they'll take your image, they'll make a unique hash out of it that can only be that specific image. If a pixel is changed, the hash that's generated from that photo will change. So that's a it's a really specific thing with how hashes work. And, obviously, anybody who's familiar with Bitcoin or cryptocurrencies,
290
00:24:53.585 --> 00:24:58.885
hashes are very hashes and cryptography in general are very central to how cryptocurrencies work, but
291
00:25:00.430 --> 00:25:02.370
at least they do take that hash locally.
292
00:25:03.070 --> 00:25:07.970
But like you mentioned, Icloud is not end to end end encrypted. They've always had access to
293
00:25:08.434 --> 00:25:17.440
to Icloud photos and videos. I mean, we've had the, like, we had the big celebrity hack 4 or 5 years ago, and that was only possible because they got access to they got essentially admin
294
00:25:17.820 --> 00:25:18.800
access into Icloud
295
00:25:19.260 --> 00:25:24.035
and were able to just view people's pictures, videos because they're not encrypted. Apple has access to all of that.
296
00:25:24.755 --> 00:25:44.125
So they can still see the videos. They can still compare the hashes that they got off your device with the photos and videos that they have in Icloud. So they could still easily pull up the photo that actually attaches to that hash. It would be very straightforward to do that. And the other key thing here is it it's really important when you see people making steps towards,
297
00:25:45.385 --> 00:25:49.085
steps that seem focused on helping with security or helping with
298
00:25:49.680 --> 00:25:52.020
criminality or to help to kinda bring
299
00:25:52.320 --> 00:26:03.945
supposed good, try to think about how can this be misused in the future. And that shouldn't necessarily mean they'd never do anything for good now, obviously. If there's something that it's just a net positive to knock it out and we'll figure out how to work around it,
300
00:26:04.325 --> 00:26:05.044
great. But,
301
00:26:05.765 --> 00:26:06.825
like, here specifically,
302
00:26:07.600 --> 00:26:11.700
if this is just used to shut down child pornography and never anything else in the future,
303
00:26:12.080 --> 00:26:19.955
I think, generally, that's probably a good thing. That's not necessarily a huge loss, but the the issue here is you are putting 100% of your trust
304
00:26:20.335 --> 00:26:22.995
in Apple, in the people who work at Apple,
305
00:26:23.375 --> 00:26:27.800
and in Apple, the company, as never being pressured by someone else, like a government,
306
00:26:28.180 --> 00:26:33.465
to use that data against you or against a a minority or really anything,
307
00:26:34.405 --> 00:26:41.225
and you're trusting that the the data that they collect through these hashes and the the things that they can do with the videos and pictures that they have in Icloud,
308
00:26:42.789 --> 00:26:52.330
that they'll never start to target something other than child pornography. And that, I think, is one of the kickers that people have have been talking about, thankfully, on Twitter and other places,
309
00:26:53.414 --> 00:26:57.434
that this technology could very easily be used to try to target
310
00:26:58.375 --> 00:26:59.674
people of different
311
00:27:00.110 --> 00:27:03.010
ethnicities, people in different religious minorities, people,
312
00:27:03.710 --> 00:27:13.784
in specific countries, or people who are taking pictures of specific things. I mean, I'll take a very a very harmless example, but, say, you're a gun owner in the US. Right now, guns are legal. You can get them
313
00:27:14.664 --> 00:27:23.809
there's obviously restrictions around how and where and all that stuff, and we'll get into that. But you can buy a gun right now. You can buy ammo. You can you can shoot a gun. There's there's nothing illegal or harmful in that.
314
00:27:24.245 --> 00:27:30.024
But let's say in 5 years that the government decides that guns are illegal, we changed gun laws,
315
00:27:30.325 --> 00:27:41.220
now you have to either hand in all of your guns to the government. Maybe we'll give you, like, a $100 a gun or something to make you feel better about yourself. But you have to give it give all your guns. We're gonna take them away. You don't need them for your safety.
316
00:27:41.684 --> 00:27:43.465
Just let us take care of your safety.
317
00:27:44.325 --> 00:27:46.424
And they do that. They collect all the guns.
318
00:27:46.725 --> 00:27:48.985
Obviously, people who see the need for
319
00:27:49.550 --> 00:27:51.730
firearms as a deterrent to the government,
320
00:27:52.350 --> 00:28:01.505
some of them hold on to their guns. But what happens if you take a picture of that with your iPhone? You take a picture of a gun. Maybe you go out to the range. You're shooting with friends. You take a picture of of one of those guns.
321
00:28:02.205 --> 00:28:13.945
It uploads that hash. Maybe maybe even at this point, it will say that iCloud is entity encrypted, so they don't have access to the photo. But it uploads that hash, and they're able to compare with the data that they have and say, okay. This is a photo of a gun.
322
00:28:14.245 --> 00:28:29.690
And so they know this person said that they gave us all of their guns, but they're still taking pictures of guns. And now they go to start rounding they go to start round up people who still own guns when they supposedly give them all into the government, and that's, like, that's probably one of the most harmless potential ways that this could be used.
323
00:28:30.674 --> 00:28:31.395
Another more,
324
00:28:32.674 --> 00:28:35.015
harsh one could be something like what's happened with,
325
00:28:35.475 --> 00:28:39.360
multiple different religious minorities in China where they've used technology,
326
00:28:40.220 --> 00:28:48.165
surveillance. They've used a lot of kind of data analysis to figure out how to tell when a person is in a specific religious minority,
327
00:28:48.865 --> 00:28:56.510
even if they don't know it via an actual, like, specific fact. And they're able to use those different technologies that were supposedly put up for harmless reasons
328
00:28:57.049 --> 00:29:05.565
to track them as people, figure out who they are, and then deport them, kill them, put them in concentration camps. Like, that's obviously the the harsher end of things, but
329
00:29:05.945 --> 00:29:25.095
essentially what this means is Apple has access to your pictures and videos, which they always have, but now they're telling you upfront that they are performing analysis on those pictures to find specific things. And right now, you may be fine with the thing that they're finding, but down the line, what they're actually looking for could quickly change. They have no requirement to tell you that they've changed what they're targeting,
330
00:29:25.475 --> 00:29:30.580
and they can easily be pressured by governments, social pressure, etcetera. So I know that was a bit of
331
00:29:30.960 --> 00:29:33.779
332
00:29:34.159 --> 00:29:35.860
333
00:29:36.639 --> 00:29:40.085
334
00:29:40.545 --> 00:29:44.965
My audience always makes fun of me because I say nuance at least 5 times in every episode.
335
00:29:47.130 --> 00:29:47.870
You know,
336
00:29:48.890 --> 00:29:50.990
just to add on there, I mean, first of all,
337
00:29:51.930 --> 00:29:53.310
Apple on the surface,
338
00:29:54.385 --> 00:29:56.725
a lot of the privacy improvements they've made,
339
00:29:57.425 --> 00:29:58.245
seem outstanding,
340
00:29:59.345 --> 00:30:02.380
but it is closed source. There's no way for us to verify
341
00:30:02.680 --> 00:30:04.620
anything that they say they're doing,
342
00:30:04.920 --> 00:30:05.420
ourselves.
343
00:30:07.240 --> 00:30:10.934
And then on top of that, a perfect example, I think,
344
00:30:12.755 --> 00:30:15.815
of of what I expect this type of capability
345
00:30:16.195 --> 00:30:16.695
to
346
00:30:17.590 --> 00:30:19.530
evolve into in the near future
347
00:30:20.070 --> 00:30:26.809
is we've already seen Apple bend to the will of the Chinese government because it's such a valuable market to them.
348
00:30:28.865 --> 00:30:30.404
The the Icloud, for instance,
349
00:30:31.585 --> 00:30:35.684
Apple virtue signals about not giving government access,
350
00:30:36.680 --> 00:30:40.059
not accepting government requests from China for Icloud access.
351
00:30:40.760 --> 00:30:42.540
But what they did instead was,
352
00:30:43.320 --> 00:30:59.250
Icloud in China is co owned by a Chinese government entity, like a a so called private company that's really controlled by the Chinese government. So they don't even have to submit requests. They just have backdoor access to Icloud in China, and I could completely see,
353
00:30:59.870 --> 00:31:03.435
within the next few years this exact tool being used,
354
00:31:04.695 --> 00:31:11.530
to filter out to see if anyone has TNM and Square photos on their on their device. Like, that would not surprise me at all one bit.
355
00:31:12.650 --> 00:31:28.715
356
00:31:29.040 --> 00:31:30.900
capable and willing of pressuring
357
00:31:31.440 --> 00:31:35.815
large tech companies to do the things that they want? The US. We've seen that push with
358
00:31:36.455 --> 00:31:45.800
them specifically giving things giving links to posts that they don't want to see on Facebook to Facebook and saying you need to take care of this and using social pressure as a a tool to
359
00:31:46.360 --> 00:31:53.260
to get them to do that. So to think that they won't do something to pressure Apple into using this data against citizens
360
00:31:53.745 --> 00:32:11.380
in the future is very naive. And, honestly, it very well could be happening right now. And, again, there's no there's no requirement or responsibility that they have to tell you. Well, there's a responsibility, but there's no requirement that they have to tell you when and if, they've been compromised or if they're giving up that data or if they're using that data in a new way. So
361
00:32:11.735 --> 00:32:16.555
it's it's very important that people realize that that that can happen very, very quickly.
362
00:32:17.335 --> 00:32:21.355
363
00:32:22.040 --> 00:32:24.380
when we see these attacks on encryption
364
00:32:25.320 --> 00:32:25.820
and
365
00:32:27.640 --> 00:32:30.140
privacy in general is that the criminals
366
00:32:30.545 --> 00:32:33.525
tend to be the quickest to evolve. So,
367
00:32:35.265 --> 00:32:38.885
this new tactic might be effective in the beginning to get some criminals,
368
00:32:39.360 --> 00:32:40.659
but most of those criminals
369
00:32:40.960 --> 00:32:43.299
will move on to platforms that
370
00:32:43.600 --> 00:32:53.565
don't allow them to be spied on. And the end result is you don't actually catch many criminals from it, but instead you hurt law abiding citizens. You hurt honest people,
371
00:32:54.345 --> 00:32:58.550
who just want easy, accessible privacy, and instead, you take that away from them.
372
00:32:59.970 --> 00:33:06.385
373
00:33:06.845 --> 00:33:11.585
like, for instance, this note in revelations, which I'm sure people have heard of and probably talked about before.
374
00:33:12.980 --> 00:33:20.200
A a big part of that and a really huge part that stuck with me and has stuck around after learning more about what he revealed was that
375
00:33:21.465 --> 00:33:30.285
the the data that they were collecting, the things that they were doing I mean, we saw also a similar thing in the the CIA black sites where they were torturing prisoners to try to get information.
376
00:33:30.890 --> 00:33:34.510
These types of techniques, they rarely, if ever, yield
377
00:33:34.970 --> 00:33:38.910
actual crime prevention or actual catching of criminals.
378
00:33:39.405 --> 00:33:43.905
It's very rare that that happens. But once the government see that they can do this,
379
00:33:44.605 --> 00:34:00.355
they use something that they wanna track down or that they say they wanna track down to implement these things, and then they utilize the power that we give them because we say, like, yeah. I'm afraid of terrorists, or, yes. I wanna see child porn shut down, which, again, like, those are things, like, we all hopefully want.
380
00:34:00.895 --> 00:34:01.395
But
381
00:34:02.414 --> 00:34:06.674
when the government sees that they can use those those tools of of fear or
382
00:34:07.279 --> 00:34:08.260
feigned morality
383
00:34:08.560 --> 00:34:09.060
to
384
00:34:09.520 --> 00:34:14.099
to to get us to give over the power that we have over our data to them.
385
00:34:14.425 --> 00:34:16.605
They then leverage that to start to,
386
00:34:17.705 --> 00:34:21.645
to subtly oppress us or to censor information or to
387
00:34:21.960 --> 00:34:22.680
shut down,
388
00:34:23.080 --> 00:34:24.140
political minorities,
389
00:34:24.520 --> 00:34:26.540
to to shut down political dissidents.
390
00:34:26.920 --> 00:34:35.795
They start to use these things to keep consolidating power because that's what we've seen throughout all of history is governments love to consolidate power, consolidate power, consolidate power.
391
00:34:36.095 --> 00:34:39.635
So often these things are really about shutting down any kind of dissidents or
392
00:34:40.119 --> 00:34:46.140
any kind of resistance that they may have so they can keep consolidating power and increasing the the control that they have over people.
393
00:34:46.839 --> 00:34:47.420
394
00:34:49.595 --> 00:34:50.095
So
395
00:34:52.715 --> 00:34:54.415
and it's extremely frustrating
396
00:34:54.795 --> 00:34:57.535
that they they, like, pigeonhole us into
397
00:34:59.180 --> 00:35:01.599
it by by using criminals as the excuse
398
00:35:01.980 --> 00:35:06.640
when we obviously don't want criminal behavior to be happening, and we want, you know,
399
00:35:07.555 --> 00:35:09.895
we we we want people that hurt children
400
00:35:10.195 --> 00:35:14.615
to, you know, be behind bars, if not worse, for the rest of their lives.
401
00:35:16.040 --> 00:35:18.460
And they, like, intentionally pigeonhole you
402
00:35:19.080 --> 00:35:19.580
to
403
00:35:19.880 --> 00:35:25.500
to basically erode the ground you stand on when you're trying to defend personal privacy and personal freedom.
404
00:35:26.905 --> 00:35:30.045
You made an interesting point earlier, which I tend to agree with.
405
00:35:30.505 --> 00:35:33.724
So for most people when they're choosing a phone, they're choosing
406
00:35:34.490 --> 00:35:35.550
a stock iPhone,
407
00:35:36.330 --> 00:35:38.110
or they're choosing a stock Android.
408
00:35:39.450 --> 00:35:41.070
We spent the last
409
00:35:41.905 --> 00:35:45.525
20 minutes or so talking about the concerns over iPhone.
410
00:35:48.760 --> 00:35:57.740
You kind of mentioned in passing, and I I tend to agree with you, that that a stock Android experience is is probably strictly worse for your privacy.
411
00:35:58.905 --> 00:36:01.005
Would you you would agree with that. Right?
412
00:36:02.025 --> 00:36:06.765
413
00:36:07.180 --> 00:36:15.360
just privacy theater. It's it's a it's a marketing gimmick, but they have made some measurable steps that that increase the privacy of the users of iPhones.
414
00:36:15.885 --> 00:36:21.025
Whereas Android, I mean, as it's it's owned by Google. It's created by Google and run by them.
415
00:36:21.485 --> 00:36:28.990
And I think it's also important to to quickly note, Android is not necessarily just stock Android that comes on Google Pixel devices,
416
00:36:29.610 --> 00:36:32.430
but it's also Android that's reskinned and
417
00:36:32.975 --> 00:36:42.195
owned from the ground up by other companies who also have an interest in collecting data, like Samsung, like Huawei, like Xiaomi. There's lots of other vendors that sell Android phones,
418
00:36:42.500 --> 00:36:47.960
and each of them want a piece of the pie as far as your data is concerned as well, and each of those people have
419
00:36:48.339 --> 00:36:51.145
full control over the the operating systems that they build.
420
00:36:51.705 --> 00:36:55.005
So Android is a little harder to talk about because there are lots of different
421
00:36:55.945 --> 00:36:58.910
varieties. But at the core, Android is very much,
422
00:36:59.710 --> 00:37:01.569
very much centered on data collection,
423
00:37:02.109 --> 00:37:13.035
both for good or for evil. A lot of that is what makes it so easy to use and so helpful. I mean, like, Google Maps has been a really hard thing to not use because it's just so freaking effective. It's so good at what it does.
424
00:37:14.430 --> 00:37:24.375
And we'll we can talk about it later, but there there are ways to use Google Maps on Calix OS or, I'm not sure on Graphene, but on Calix OS at least. You definitely can use it on Graphene, but we will go into,
425
00:37:25.635 --> 00:37:32.920
426
00:37:33.619 --> 00:37:35.640
it's well worth it to pay, like, $200
427
00:37:36.180 --> 00:37:40.200
for a dedicated, like, Garmin GPS that isn't connected to the Internet.
428
00:37:41.325 --> 00:37:43.265
429
00:37:43.964 --> 00:37:45.984
I haven't made the jump yet. I've been using,
430
00:37:46.444 --> 00:37:48.224
I've been using Magic Earth mostly.
431
00:37:48.680 --> 00:37:54.300
But, yeah, I'll have I'll have to look into getting a a GPS itself. I've heard someone else mention that. I think it's a really good idea.
432
00:37:55.960 --> 00:38:01.315
433
00:38:02.175 --> 00:38:06.275
you have whatever the other vendors are on the phone as well,
434
00:38:07.599 --> 00:38:09.380
presumably spying on you,
435
00:38:10.079 --> 00:38:11.140
to different degrees.
436
00:38:12.319 --> 00:38:22.145
And like you said, oftentimes, it's like a convenience thing. Oh, here's an assistant that, knows what you're thinking about or knows what your next step is and knows when your restaurant appointments are,
437
00:38:22.845 --> 00:38:26.750
and it's sold to you as a convenience, which it undoubtedly is,
438
00:38:27.850 --> 00:38:34.350
but in so much of our lives, I feel like there's a there's a clear trade off between privacy and convenience.
439
00:38:37.224 --> 00:38:38.125
So enter
440
00:38:39.865 --> 00:38:41.005
privacy focused
441
00:38:42.265 --> 00:38:43.244
Android Forks,
442
00:38:45.000 --> 00:38:47.100
the 2 big ones being Kallix
443
00:38:48.040 --> 00:38:49.820
OS and Graphene.
444
00:38:54.515 --> 00:38:55.315
What is your
445
00:38:55.875 --> 00:38:59.715
I mean, one of the reasons I brought you on the show is because you had a great write up on
446
00:39:02.590 --> 00:39:04.690
I think the write up was between Kallix,
447
00:39:05.310 --> 00:39:08.770
Graphene, and Copperhead. Copperhead is basically a
448
00:39:09.605 --> 00:39:12.265
closed source, source viewable, but not open source,
449
00:39:12.645 --> 00:39:13.945
fork of Graphene
450
00:39:15.765 --> 00:39:23.010
and Kallix OS, and you ultimately chose Kallix OS. I've been running Kallix OS as my daily driver for, I think, 7 months now.
451
00:39:24.510 --> 00:39:26.450
My lady has been running it even longer.
452
00:39:27.795 --> 00:39:29.475
I absolutely love it. What
453
00:39:30.835 --> 00:39:31.335
why
454
00:39:32.515 --> 00:39:36.135
when you make when you when you advocate for someone to consider
455
00:39:36.750 --> 00:39:38.290
one of those solutions,
456
00:39:38.590 --> 00:39:39.490
what is your
457
00:39:39.950 --> 00:39:42.210
what is your framing? Why should they care?
458
00:39:44.244 --> 00:39:56.230
459
00:39:56.690 --> 00:40:02.825
and brought this up. And you you mentioned a lot of them before when you're talking about people that that we have in common for our podcast.
460
00:40:04.325 --> 00:40:05.225
But I think,
461
00:40:05.845 --> 00:40:08.105
like we were talking about, Android is very
462
00:40:08.405 --> 00:40:09.840
non privacy centric.
463
00:40:10.400 --> 00:40:14.020
It's very focused on data collection and, like you talked about, that convenience.
464
00:40:15.360 --> 00:40:19.620
I think what a lot of people don't realize is the convenience that they're offered by most of these applications
465
00:40:20.385 --> 00:40:31.480
is either at the cost of giving up your data and that's all the company wants, just collect your data and sell it, which is is certainly bad, but is oftentimes not necessarily the worst case use of data even though it is terrible.
466
00:40:32.740 --> 00:40:37.400
But another use case is to take your data and use it to train,
467
00:40:38.525 --> 00:40:44.705
AI, to train machine learning models, to to to actually keep putting that data back into the tools to make them better, which,
468
00:40:45.060 --> 00:40:58.465
again, there's nothing wrong with improving a tool using data. But, oftentimes, people are not aware that this data is being collected. They're not consenting to it. It's usually very unclear or impossible to know what data is actually being collected and what's done with it.
469
00:40:58.925 --> 00:41:05.490
So like you mentioned, the Google Assistant, which is a it's an amazing tool. It works so well. It has improved rapidly over the years.
470
00:41:06.430 --> 00:41:14.075
And what people don't realize is that the way that that tool is improved is that they record everything that you're saying and everyone else with an Android phone is saying.
471
00:41:14.615 --> 00:41:23.330
In theory, they only record snippets and upload them when you say the the keyword, which is usually okay, Google. And, hopefully, lots of people's phones got triggered, and they'll think about switching to
472
00:41:23.710 --> 00:41:25.650
switching to Kallix or Graphene today.
473
00:41:26.955 --> 00:41:32.895
But that that data that they're constantly collecting from you, they are using to improve the tools, which makes them more convenient,
474
00:41:33.275 --> 00:41:44.630
which then makes you, what, keep committing back to their services, keep giving them your data, and you fall into this loop of convenience that pulls you deeper and deeper into someone else controlling everything about your digital life.
475
00:41:45.955 --> 00:41:46.455
And
476
00:41:46.995 --> 00:41:57.520
the the good thing, though, about Android and the good thing about a lot of what Google has done is that, thankfully, they do generally follow the open source model. So a lot of the stuff that they create
477
00:41:58.060 --> 00:41:59.120
is open source,
478
00:42:00.625 --> 00:42:05.205
and Android is no exception. They created the Android project a long time ago. I think it was probably
479
00:42:06.865 --> 00:42:10.869
13 years ago now. Maybe it's been even before that that they created Android, but,
480
00:42:11.810 --> 00:42:19.394
Android itself as an operating system is open source. The Android that you actually get on your device is generally not open source and reproducible.
481
00:42:20.255 --> 00:42:28.000
Like on a Pixel device, there are lots of specific things that they build in and do not release the source for it because they want them to be unique features to Pixel devices.
482
00:42:29.040 --> 00:42:33.300
And then, obviously, like Samsung, Huawei, Xiaomi, all the different vendors of Android,
483
00:42:33.760 --> 00:42:42.515
they usually do not open source their specific twists on Android either. But the base of Android, which is specifically called the Android Open Source Project,
484
00:42:44.120 --> 00:42:45.820
is an open source operating system.
485
00:42:46.120 --> 00:42:53.395
Like Monero Lionx said in chat, Android is it's based on Linux, uses Linux kernel, uses a lot of things that are are core to Linux.
486
00:42:54.335 --> 00:43:00.920
And so that that open source base provides the opportunity for people to take the code and to make what they want out of it.
487
00:43:01.320 --> 00:43:07.260
And one of the really great things that we can do with that is we can take the Android open source project base, AOS,
488
00:43:08.119 --> 00:43:08.619
and
489
00:43:09.185 --> 00:43:19.390
tear out all of the pieces that Google has baked in that feed them everyone's data. We can tear that out, and then we can also add in new features, new abilities, new applications
490
00:43:20.250 --> 00:43:28.755
that are either privacy preserving, so they're focused on, like, end to end encryption or on hiding behavior from certain apps or for VPNs,
491
00:43:29.454 --> 00:43:30.835
Tor, that kind of thing.
492
00:43:31.535 --> 00:43:35.940
Or we can add in new applications and features that are very specifically
493
00:43:36.640 --> 00:43:38.100
free and open source software.
494
00:43:39.680 --> 00:43:40.180
And
495
00:43:40.640 --> 00:43:47.944
there like you mentioned, there are 3 main projects that have take taken the base that is the Android open source project. All 3 of these come from the same base,
496
00:43:48.645 --> 00:43:51.625
and they've built up a privacy preserving
497
00:43:52.390 --> 00:43:53.530
version of Android
498
00:43:54.390 --> 00:43:55.130
that is,
499
00:43:55.750 --> 00:43:59.450
focused on maintaining your privacy, giving you control over what happens.
500
00:44:01.175 --> 00:44:08.475
At the very start, I'll just go ahead and say Copperhead OS is probably not a good choice for anyone who's listening to this. They are enterprise focused.
501
00:44:09.250 --> 00:44:26.375
There's been a lot of drama around them and around their founder and how he handles things, but I I will not recommend Copperhead OS. So we'll just go and toss that one aside for now. Just know that it's essentially Graphene OS. There's not much difference there. So if I'm talking about Graphene OS and for some reason you're interested in Copperhead OS, there's there's
502
00:44:26.950 --> 00:44:29.290
complete similarities there in almost every way.
503
00:44:31.030 --> 00:44:36.070
So the other two main containers that are left are Calix OS, which, like you mentioned, you're running.
504
00:44:36.390 --> 00:44:39.855
It's my favorite mobile operating system. It's what I use daily.
505
00:44:40.395 --> 00:44:48.110
And I think we we must have started using it right about the same time. I started in in January as well. So going on 7 months now of of Calix OS as a daily driver.
506
00:44:49.130 --> 00:44:52.110
And then GrapheneOS is the other main option, which
507
00:44:53.244 --> 00:44:59.105
kind of to I guess to sum up the differences between the 2, and like you mentioned, I have a good bit of this on my blog,
508
00:45:00.340 --> 00:45:07.000
But the main differences that I see between the 2 are that Calix OS, I think they've taken a very good approach,
509
00:45:07.460 --> 00:45:09.640
which is trying to bake in
510
00:45:10.325 --> 00:45:13.464
as much convenience as possible while preserving privacy.
511
00:45:14.805 --> 00:45:21.660
And they're not they're not doing that at the expense of large gaping privacy holes. Like, the defaults are very solid.
512
00:45:22.680 --> 00:45:25.580
They put in a lot of good apps that they include by default,
513
00:45:27.445 --> 00:45:33.705
but they've they've realized, I think and something that more and more privacy projects need to realize. They've realized that
514
00:45:34.325 --> 00:45:34.825
the
515
00:45:35.620 --> 00:45:42.280
the way to get people into using privacy preserving tools is if they are at least as good, if not better in certain ways
516
00:45:42.605 --> 00:45:49.744
as far as usability goes, than non privacy observing tools. So if you make something just impossible to use but perfectly private,
517
00:45:50.059 --> 00:45:55.279
guess what? No one uses it, and no one's privacy has improved. I feel like PGP is, like, the perfect example.
518
00:45:55.660 --> 00:45:57.455
Yeah. Yeah. It really is. It's
519
00:45:57.935 --> 00:46:01.955
a great tool that works well and still works well however many years later
520
00:46:02.335 --> 00:46:05.635
at the thing that it does, which is providing privacy, but it's
521
00:46:06.090 --> 00:46:08.110
god awful to use in almost every scenario.
522
00:46:08.490 --> 00:46:19.195
And I think there is a little bit of a shift to coming back to BGP, so there are some some good developments there that hopefully will be helpful. But, yeah, that's that's the perfect example of a tool that's existed forever
523
00:46:19.895 --> 00:46:23.675
that's been effective at what it says it does forever, but it's just
524
00:46:24.110 --> 00:46:26.270
basically impossible to use on a daily basis,
525
00:46:26.590 --> 00:46:31.570
or at least only for the very technically advanced and for the people who are willing to give up a lot of convenience.
526
00:46:33.605 --> 00:46:34.744
527
00:46:35.045 --> 00:46:39.305
I mean, I I'm aware that you used copperhead, but you never actually used Graphene. Right?
528
00:46:39.605 --> 00:46:43.349
No. No. I didn't. And So I I spent, like
529
00:46:43.970 --> 00:46:44.470
so
530
00:46:44.930 --> 00:46:46.230
7 months of Calix.
531
00:46:46.690 --> 00:46:55.845
The 3 months before that, I tried to use Graphene as my daily driver, and I was actually I was a pro this is very common with me. I was a prolific shill of Graphene,
532
00:46:57.960 --> 00:47:06.060
and I I created a guide that a lot of people have used. I think there's, like, over 10,000 hits on YouTube on how to install Graphene on your pixel device,
533
00:47:07.515 --> 00:47:11.775
and I saw that as a way of opting out at of the surveillance Panopticon.
534
00:47:13.595 --> 00:47:14.095
Everything
535
00:47:14.635 --> 00:47:17.349
has trade offs, and with Graphene,
536
00:47:17.730 --> 00:47:18.950
the trade off balance
537
00:47:19.730 --> 00:47:23.029
was extremely severe on the privacy security side.
538
00:47:25.425 --> 00:47:25.925
I
539
00:47:26.545 --> 00:47:32.725
could tell that a lot of effort and motivation went into hardening that OS as much as possible.
540
00:47:34.119 --> 00:47:41.579
But from my experience, what was happening was, and it almost happened to me, if I didn't find Kallix, is that people were switching to Graphene.
541
00:47:41.954 --> 00:47:44.375
They were having an absolute horrible time of it,
542
00:47:44.755 --> 00:47:46.135
their photos were horrible,
543
00:47:46.595 --> 00:47:49.734
their battery life wasn't great, the performance wasn't good,
544
00:47:50.330 --> 00:47:54.110
They couldn't use any apps that they any apps that they wanted to use,
545
00:47:55.850 --> 00:47:59.954
and then they were switching back to either stock Android or stock
546
00:48:00.414 --> 00:48:00.914
iPhone.
547
00:48:01.375 --> 00:48:02.434
But with Kallix,
548
00:48:03.934 --> 00:48:04.434
while
549
00:48:05.970 --> 00:48:17.885
they they they make a lot of interesting like, a lot of good steps towards being more privacy focused, and strictly the the number one thing both of these OSes do is they just completely rip out Google. There's no Google in the device.
550
00:48:21.260 --> 00:48:24.480
Is it's an enjoyable experience. Like, I actually
551
00:48:25.500 --> 00:48:31.355
I feel like I have a better phone than my peers that have iPhone or have the latest Samsung.
552
00:48:32.055 --> 00:48:34.635
My battery life's better. The photos are great.
553
00:48:35.175 --> 00:48:38.635
And then I also have these additional privacy and security benefits.
554
00:48:39.600 --> 00:48:40.740
So it to me,
555
00:48:41.280 --> 00:48:43.780
when you look at the trade off balance, it's
556
00:48:44.560 --> 00:48:45.940
it's if if
557
00:48:46.615 --> 00:48:49.435
if what you care about most is privacy and security,
558
00:48:50.375 --> 00:48:57.270
then, yes, choose Graphene. Maybe if you're using it as, like, a dedicated Bitcoin device and you're not using it as your daily driver, choose Graphene.
559
00:48:59.010 --> 00:49:04.765
The the install method for both are is relatively similar. It's actually way easier than you would expect.
560
00:49:05.704 --> 00:49:09.640
But when it comes down to, like, a daily driver that you want to have
561
00:49:09.960 --> 00:49:13.500
some convenient elements to it, you wanna have good battery life,
562
00:49:14.440 --> 00:49:18.940
you wanna be able to take the occasional photo and not have it just be potato quality.
563
00:49:21.435 --> 00:49:24.815
Kallax is just so much more accessible, so much more usable.
564
00:49:26.570 --> 00:49:30.590
565
00:49:31.130 --> 00:49:37.715
I switched to Kallax from Copperhead, which is, like I said, was very Graphene OS like, not exactly the same, but very similar.
566
00:49:39.055 --> 00:49:45.520
And the the core reason why I switched was that I wanted to use the phone as my daily driver. Like, I wanted it to be everything. Everything. I didn't
567
00:49:46.060 --> 00:49:58.545
wanna just be using that phone when I felt like I needed privacy and then have another phone for the things that I couldn't get to work on on my main phone. I wanted to be able to really dive into this idea of of protecting my personal privacy on mobile, which
568
00:49:59.165 --> 00:50:10.210
a lot of people, I think, don't realize that so much of our lives now happen on our mobile devices. Most people don't really use a laptop or computer that much for browsing, for interacting with people, for chatting.
569
00:50:11.464 --> 00:50:11.964
So
570
00:50:12.345 --> 00:50:24.320
preserving your privacy on your mobile device is, I think, often the most important step to take and the most kind of broad net that you can cast to to help to to preserve your privacy in key ways.
571
00:50:25.714 --> 00:50:29.494
But, yeah, like you said, CalixWorks just does a really good job of making things
572
00:50:30.435 --> 00:50:31.415
really usable.
573
00:50:31.875 --> 00:50:35.750
And I think, like, you you specifically called out that both strip out Google completely.
574
00:50:36.370 --> 00:50:41.590
So that is that's a lot of people, when they refer to these operating systems, they'll call them de googled Android.
575
00:50:41.975 --> 00:50:48.875
So for anyone who's heard that term and didn't know what that meant, that's that's kind of a blanket term for both Calix OS and Graphene OS.
576
00:50:50.990 --> 00:50:54.049
And I would say that they have very similar privacy guarantees
577
00:50:54.349 --> 00:50:55.809
between Calix and Graphene.
578
00:50:56.965 --> 00:51:00.425
The main caveat is that Kallix OS has this,
579
00:51:01.125 --> 00:51:06.070
kind of middleman layer that you can use for utilizing apps that rely on Google Play Services,
580
00:51:06.690 --> 00:51:09.670
which, really briefly, Google Play Services are kind of
581
00:51:10.425 --> 00:51:17.244
a core feature that almost every Android app utilizes for very important things like sending notifications,
582
00:51:17.545 --> 00:51:19.690
like querying for information, like,
583
00:51:20.250 --> 00:51:21.390
getting new messages
584
00:51:22.410 --> 00:51:28.755
and doing background processes. Google has done a good job of pulling people into their ecosystem and then pulling them into their very specific,
585
00:51:29.775 --> 00:51:36.115
applications. When people are building apps for Android, often they're building them in a way that makes the the application entirely reliant
586
00:51:36.720 --> 00:51:38.819
on Google servers to function properly.
587
00:51:40.000 --> 00:51:43.299
And so this is why you hear a lot if you hear people who have used GrapheneOS,
588
00:51:44.240 --> 00:51:46.045
you hear a lot that GrapheneOS,
589
00:51:46.345 --> 00:51:52.525
you can't run, like, any apps, that almost every app is broken or doesn't work. And the key reason behind that is not that GrapheneOS
590
00:51:52.825 --> 00:51:55.165
messed something up or did something wrong or
591
00:51:55.890 --> 00:52:05.424
something like that, but that most apps are designed to be used on a device that has Google Play services. And so a lot of those core features of every application are reliant on those those Google Play services.
592
00:52:06.365 --> 00:52:14.740
With GrapheneOS, there is no way to use Google Play services in in any fashion. So if the app relies on Google Play services, you're just you're stuck. There's nothing you can do.
593
00:52:16.080 --> 00:52:19.700
If you're on Kallax OS, however, you can use something called Micro g,
594
00:52:20.000 --> 00:52:22.180
which is a it's a privacy preserving
595
00:52:22.720 --> 00:52:23.220
anonymous
596
00:52:23.655 --> 00:52:27.355
wrapper for Google Play Services. It essentially integrates a lot of the
597
00:52:27.655 --> 00:52:31.595
a lot of the most important features that are part of the Google Play Services package
598
00:52:32.220 --> 00:52:40.799
into a free and open source middleman layer that you can use without having a Google account. So a Google account is not tied back to Google Play Services.
599
00:52:43.335 --> 00:52:50.475
Someone in the chat did say, and I saw someone mention it today, but I hadn't had time to do research, that Graphene launched something called Sandbox Google Play Services.
600
00:52:50.990 --> 00:52:55.710
I have not seen that, and I haven't dug into that. So, unfortunately, I can't speak to that today.
601
00:52:56.190 --> 00:53:00.609
If you can, Matt, feel free to to share about that. I I hadn't heard anything about that until
602
00:53:00.934 --> 00:53:02.214
literally right before going live.
603
00:53:03.654 --> 00:53:11.150
But those those micro g the micro g functionality in Calix OS is when it enables you to use almost every Android app without issues
604
00:53:11.530 --> 00:53:18.915
and still without having Google Telemetry, without having Google Tracking, without having a Google account tied to all of the data that's going through that.
605
00:53:19.615 --> 00:53:24.595
And it's very it's a it's a privacy preserving way to use Google Play Services. I still think if you're
606
00:53:25.010 --> 00:53:29.030
if you're very privacy conscious and you're willing to go through the hassle,
607
00:53:29.650 --> 00:53:34.230
installing without Micro g is is the ideal way for privacy,
608
00:53:34.855 --> 00:53:41.994
but it's not necessary for most people. A lot of people will benefit from just using Calix OS with micro g to make the transition a lot more smooth.
609
00:53:43.070 --> 00:53:44.930
610
00:53:45.230 --> 00:53:51.715
611
00:53:52.355 --> 00:53:54.775
612
00:53:55.475 --> 00:53:58.535
613
00:54:01.450 --> 00:54:07.710
614
00:54:09.050 --> 00:54:10.510
like, only Google Apps.
615
00:54:11.154 --> 00:54:16.994
But, like, a perfect example in the Bitcoin world is a wallet that I talk about a lot, Moon Wallet, m u u n,
616
00:54:17.795 --> 00:54:19.494
and they have Google Play Services
617
00:54:20.080 --> 00:54:22.980
requirements on that app. So you can't use it,
618
00:54:24.000 --> 00:54:29.060
unless you have micro g enabled. But if you have micro g enabled, it works relatively seamlessly,
619
00:54:30.765 --> 00:54:40.930
And there's other examples of that. I mean, I guess we could dive in a little bit deeper. I mean, in general, I think people should reduce the amount of apps they have on their device as just a simple rule of thumb.
620
00:54:42.190 --> 00:54:43.810
As for the sandboxed,
621
00:54:44.990 --> 00:54:47.215
Google Play services that Graphene added,
622
00:54:48.655 --> 00:54:49.395
I actually
623
00:54:49.775 --> 00:54:53.875
became, like, pretty close friends with with Daniel McKay of Graphene,
624
00:54:54.710 --> 00:54:58.410
He's very excited about this new feature. I have not tested it out myself.
625
00:54:59.510 --> 00:55:02.250
My understanding is it's less performant
626
00:55:03.035 --> 00:55:05.295
and is on, like, an app by app basis,
627
00:55:06.155 --> 00:55:07.215
than Kallix.
628
00:55:07.835 --> 00:55:09.295
But what's cool here is
629
00:55:09.810 --> 00:55:16.869
is competition is helping the customer. Right? And I I think a lot of it is the reason we see that feature getting added to Graphene,
630
00:55:18.115 --> 00:55:22.135
is because Kallix has Micro g support, and they see that a lot of users
631
00:55:22.755 --> 00:55:26.135
want to at least have some kind of limited Google Play services
632
00:55:27.869 --> 00:55:28.990
support, which is,
633
00:55:29.470 --> 00:55:30.930
just good to see in general,
634
00:55:31.710 --> 00:55:35.329
than just having a single project working on privacy stuff.
635
00:55:36.394 --> 00:55:40.335
Before we dive in deeper, I mean, I think one of the really cool parts of Kallix to me
636
00:55:40.635 --> 00:55:43.855
is that Kallix is actually maintained by a foundation
637
00:55:44.740 --> 00:55:46.359
called the Kallix Foundation
638
00:55:46.819 --> 00:55:49.960
that is just generally focused on privacy and freedom.
639
00:55:51.220 --> 00:55:53.400
To me, that's a very interesting model
640
00:55:53.835 --> 00:55:54.335
for
641
00:55:55.675 --> 00:55:59.455
funding development costs of a open source project.
642
00:56:00.234 --> 00:56:02.175
I'm a proud supporter of Kallix.
643
00:56:03.150 --> 00:56:06.050
I have been for a while even before I started running it.
644
00:56:07.310 --> 00:56:13.055
I just think that's a really, really cool concept, and anyone who does end up switching to Kallix and enjoys it,
645
00:56:13.615 --> 00:56:14.434
should consider,
646
00:56:14.974 --> 00:56:16.835
you know, supporting them as a member.
647
00:56:18.655 --> 00:56:22.835
648
00:56:23.520 --> 00:56:28.420
who is curious to go I think their website is I don't know if it's calyx.org or calyxinstitute.
649
00:56:28.720 --> 00:56:31.460
I'll have to look it up. But just dig into a little bit about
650
00:56:32.425 --> 00:56:39.980
Nick Merrill, the founder of the Kellogg's Institute and just the the things that he's done. He's gone through attempts to be silenced by the government and to
651
00:56:41.980 --> 00:56:57.484
to be forced to give up data, and so there's some there's some really interesting interviews out there with him and kind of why he became interested in it. But, yeah, they've got a very unique model of funding Calix OS development and the other services they provide, which they do not only do Calix OS. They have other things like a a free community VPN.
652
00:56:59.050 --> 00:57:02.030
But, yeah, they fund those things through the Kellogg's Institute. And,
653
00:57:02.410 --> 00:57:03.790
like Carrington 1859
654
00:57:04.090 --> 00:57:08.644
mentioned in chat, if you are in the US, you get some specific benefits if you're a member.
655
00:57:09.025 --> 00:57:11.765
In the past, they've done and I think they're still doing
656
00:57:12.144 --> 00:57:14.005
hot spots that you can use,
657
00:57:14.385 --> 00:57:17.880
for free for for for free once you get them. No monthly fee,
658
00:57:18.340 --> 00:57:18.820
and,
659
00:57:19.140 --> 00:57:26.015
you get unlimited data on these hotspots. And they actually work pretty well. I have one. Nice. Yeah. I've I've been waiting
660
00:57:26.315 --> 00:57:28.575
to be able to to fund them with Monero,
661
00:57:28.954 --> 00:57:37.280
to go ahead and dive in there, but I've been wanting to been wanting to support them for a while, and and I have have money ready. I've been trying to help them with that integration, but,
662
00:57:37.820 --> 00:57:39.920
they also recently started doing
663
00:57:40.700 --> 00:57:41.680
Pixel devices
664
00:57:42.005 --> 00:57:44.585
with Kallix OS as part of their membership
665
00:57:46.005 --> 00:57:46.505
benefits.
666
00:57:46.965 --> 00:57:50.345
So that's another way that people could get a Pixel device with Kallix OS
667
00:57:50.950 --> 00:58:01.015
for donating to the the foundation that's actually building Kallix OS, which I think is a it's a really unique model, and they've done really well funding themselves using these these different kind of benefits that they offer.
668
00:58:01.974 --> 00:58:06.315
And funding is a huge issue throughout the FOSS ecosystem. It's almost always a problem.
669
00:58:07.050 --> 00:58:10.750
So when you have someone who can who can really build a good model around funding
670
00:58:11.450 --> 00:58:15.310
the operating system development, I think that's a really important thing for people to consider.
671
00:58:16.965 --> 00:58:21.785
672
00:58:22.885 --> 00:58:27.730
you primarily you need a you need a Pixel phone. You need a Google Pixel phone.
673
00:58:29.070 --> 00:58:40.225
And part of that reason is because they have this this basically a known platform that they're developing for, but also it's because you're able to relock the bootloader afterwards.
674
00:58:41.160 --> 00:58:44.460
I saw, I think, Monero Lion mentioned Lineage OS,
675
00:58:45.000 --> 00:58:45.740
which is,
676
00:58:47.240 --> 00:58:47.740
basically
677
00:58:49.075 --> 00:58:50.214
the successor
678
00:58:50.515 --> 00:58:51.894
to Synergen mod,
679
00:58:52.434 --> 00:58:54.855
if if some of the freaks remember that,
680
00:58:55.555 --> 00:58:56.535
Android 4th.
681
00:58:56.914 --> 00:58:58.295
Yeah. The good old days.
682
00:58:58.670 --> 00:59:03.410
And Lineage is cool because you can run it on a lot of different devices.
683
00:59:04.110 --> 00:59:07.410
Unfortunately, you can't relock the bootloader. And what that means is,
684
00:59:08.065 --> 00:59:10.405
and you'd see this when you install on a Pixel,
685
00:59:12.305 --> 00:59:13.845
when it comes time to flash
686
00:59:14.145 --> 00:59:15.125
a new OS,
687
00:59:15.940 --> 00:59:22.119
basically, the device has a fail safe, and that fail safe is when you unlock the bootloader, it wipes the whole device.
688
00:59:23.665 --> 00:59:27.845
If you don't have your bootloader locked and someone gets physical access to your device,
689
00:59:28.224 --> 00:59:30.724
they can road run code on your device,
690
00:59:31.400 --> 00:59:37.820
without that fail safe activating and wiping. Before you even enter an encryption password or anything like that,
691
00:59:38.494 --> 00:59:41.555
they can run whatever code they want to run on the device,
692
00:59:42.015 --> 00:59:44.674
potentially compromising what you have on the phone.
693
00:59:45.770 --> 00:59:52.990
So that is the main concern in terms of using something like Lineage and one of the reasons why I like this combination of Pixel
694
00:59:54.744 --> 00:59:55.244
versus,
695
00:59:55.625 --> 00:59:56.285
you know, using
696
00:59:56.825 --> 00:59:59.644
a Pixel with with with Graphene or Calix.
697
01:00:00.105 --> 01:00:00.605
Now
698
01:00:01.360 --> 01:00:06.900
when we're talking about the pixels, you have basically the the big model for a while that people were talking about was 3 a.
699
01:00:07.840 --> 01:00:10.820
To me, I think that's, like, kind of obsolete hardware now.
700
01:00:11.385 --> 01:00:12.125
It will
701
01:00:12.585 --> 01:00:14.045
it's nearing end of life.
702
01:00:15.785 --> 01:00:18.045
I really like the 4 a. It's very cheap.
703
01:00:18.640 --> 01:00:20.819
I currently am running a Pixel 5,
704
01:00:21.359 --> 01:00:36.405
just because I wanted to ball out, and the experience is fantastic. So, basically, when it comes down to it, I say, you know, use a 4 a or a 5 depending on what your price range is. You can get the 4 a's for pretty cheap. I expect both of them to have discounts very soon because they just announced the Pixel 6.
705
01:00:37.920 --> 01:00:42.720
We have Crypto Grampy mentioning do not buy a Verizon one because the Verizon ones,
706
01:00:44.114 --> 01:00:47.734
can you can't unlock the bootloader. But if you just get an unlocked Pixel,
707
01:00:48.194 --> 01:00:53.494
ideally buying it with cash, that's one of the cool aspects of using general purpose hardware,
708
01:00:54.089 --> 01:00:55.550
because then you can just go into
709
01:00:56.089 --> 01:00:57.869
a store, a local store.
710
01:00:58.329 --> 01:01:04.995
Right now, you know, you can take advantage of wearing a mask while you do it, buy a pixel with with cash, and then you can,
711
01:01:05.935 --> 01:01:08.515
unlock the bootloader, install Kallix very straightforward.
712
01:01:10.420 --> 01:01:12.500
I believe Techlore has a guide up.
713
01:01:13.780 --> 01:01:16.369
I imagine he does. He could do it to a machine.
714
01:01:17.744 --> 01:01:21.285
But but I found it very easy to install. My lady installed it without,
715
01:01:21.585 --> 01:01:22.244
you know,
716
01:01:22.945 --> 01:01:27.680
having an issue whatsoever. So it's very accessible for people to install. Now, Seth,
717
01:01:28.619 --> 01:01:31.599
a common thing I hear, and I'm already seeing it in the comments,
718
01:01:32.060 --> 01:01:38.545
is how do we feel about the fact that we're using a Google device and trying to remove Google from the device?
719
01:01:39.645 --> 01:01:45.830
Should we be concerned about hardware backdoors or, know, lingering things that Google has running there?
720
01:01:47.090 --> 01:01:54.815
721
01:01:55.595 --> 01:01:58.339
It's definitely it's an odd concept to get your head around,
722
01:01:59.300 --> 01:02:01.160
but you you already did a really good job explaining
723
01:02:02.020 --> 01:02:14.445
the one of the core reasons why Pixel devices make such a good platform for this, and that that's kind of twofold that it's a platform that Google themselves develop against. So you know that you're going to have the longest term possible
724
01:02:15.030 --> 01:02:17.690
hardware support, which is especially in Android,
725
01:02:18.070 --> 01:02:26.005
some of the some of the drivers for the actual hardware of the phone are not open source. Actually, most of the drivers are not open source.
726
01:02:26.385 --> 01:02:30.005
So once Google or whoever makes the phone stops developing
727
01:02:31.250 --> 01:02:31.990
updates for
728
01:02:32.290 --> 01:02:42.714
it, you can't update the hardware drivers, which oftentimes restricts what versions of Android you can use in the future. So when you use a Pixel, you know that you're gonna have the the longest lifetime of the hardware
729
01:02:43.015 --> 01:02:43.515
support
730
01:02:44.055 --> 01:02:47.515
out of any Android phone, at least as far as far as I know.
731
01:02:48.270 --> 01:03:00.195
And you know that Google's putting the the development of Android against those Pixel devices first, so you're you're gonna get a better support experience because, again, this is these these operating systems, both Kallax and Graphene,
732
01:03:00.815 --> 01:03:20.424
are both pulling from the Android open source project, which is where Google is putting all of the changes and updates and improvements that they to Android, and they're making those improvements for the Pixel devices. So it's it's the the quickest way to have releases after Google puts out releases because they're able to pull for devices that are specifically built by Google, that there are factory images for from Google.
733
01:03:21.020 --> 01:03:25.280
It really simplifies that process and makes supporting devices long term much easier,
734
01:03:25.580 --> 01:03:29.360
which can be a a big problem for an operating system like Lineage,
735
01:03:30.045 --> 01:03:31.265
or in the past, Cyanogenmod
736
01:03:31.565 --> 01:03:32.065
because
737
01:03:32.765 --> 01:03:33.905
they rely on
738
01:03:34.525 --> 01:03:43.210
individual people just deciding to support devices long term. And, like I said, when the hardware drivers get too out of date, you can't install more recent versions of Android.
739
01:03:43.510 --> 01:03:44.630
So, like, I have an old,
740
01:03:45.030 --> 01:03:54.465
Nexus 5 x that I spun up, and and I installed Lineage on that because I just wanted something that I would run at home without Google Play services or anything like that as a a little easily mobile server.
741
01:03:55.830 --> 01:04:01.530
But the the most recent version of Android you can run on that device because of the hardware drivers is Android 8.1.
742
01:04:02.205 --> 01:04:13.730
So it's massively out of date as far as the the operating system itself. Thankfully, it still gets security patches, but I still I wouldn't wanna run that as my daily driver or sign into any accounts or using my SIM card, nothing like that.
743
01:04:14.990 --> 01:04:18.609
And the other piece, like you mentioned, is that that security that you get from
744
01:04:19.185 --> 01:04:26.485
that ability to relock the bootloader and other security benefits that you get within the Pixel devices is because of a specific chip that Google designed
745
01:04:27.100 --> 01:04:27.500
for,
746
01:04:28.060 --> 01:04:29.020
secure compute.
747
01:04:29.420 --> 01:04:33.440
Sometimes these can be called secure enclaves or hardware security modules. But,
748
01:04:34.300 --> 01:04:41.945
essentially, it's it's something called a Titan M chip. And supposedly, they're releasing a new version of that chip on the Pixel 6, which will be interesting to see
749
01:04:42.245 --> 01:04:46.440
what that actually means for calyx and graphene or tools like that. But
750
01:04:47.240 --> 01:04:51.500
what that means is, like you mentioned, you can lock the bootloader again, which is what really transforms
751
01:04:51.800 --> 01:04:53.500
Kallax and Graphene from
752
01:04:54.645 --> 01:05:06.470
just kind of ROMs you can flash on your phone. We have to do with a lot of headache. You have to open yourself to a lot of, security risks. Like you mentioned, you can open yourself to attacks where you can get the maybe an an OTA update man in the middle. It gets installed.
753
01:05:06.849 --> 01:05:11.349
Then you don't have that fail safe that can double check the the signing keys and make sure the thing's legitimate.
754
01:05:12.444 --> 01:05:22.349
And you also open yourself to a lot of other hands on attacks that can't be done when the Titan M chip is involved because the the Titan M chip essentially protects a lot of essential data like,
755
01:05:22.890 --> 01:05:33.244
fingerprints and and other biometric data and things you do on your on your device. So there's some really key benefits there. And that that combination of not only de googling the operating system, but also still
756
01:05:33.704 --> 01:05:34.204
maintaining
757
01:05:34.665 --> 01:05:38.700
the, now, I would say, strong security guarantees of Android,
758
01:05:39.320 --> 01:05:43.900
without you're not having to compromise on that to get privacy, which is it's a really important combination.
759
01:05:45.135 --> 01:05:48.994
760
01:05:49.375 --> 01:05:51.234
but Google makes a strong
761
01:05:51.694 --> 01:05:53.075
attempt to open
762
01:05:53.640 --> 01:05:57.500
up the parts that are needed to interact with it so they can use it. I mean, I know,
763
01:05:58.200 --> 01:06:02.220
Samsung, for instance, has basically their own version of a secure chip,
764
01:06:03.675 --> 01:06:09.215
that these forks can't use, they can't interact with. So the fact that you have this chip there
765
01:06:10.930 --> 01:06:15.430
that these forks can use and can interact with in a relatively open manner
766
01:06:15.810 --> 01:06:17.109
is a massive boon,
767
01:06:17.490 --> 01:06:19.190
for us. I do worry,
768
01:06:20.615 --> 01:06:24.235
you kinda insinuated. I do worry. I I think the Pixel 6,
769
01:06:24.855 --> 01:06:29.115
they're going farther than that. I mean, previously, they've used qual Qualcomm hardware,
770
01:06:30.300 --> 01:06:36.640
for their devices. I think they're doing all the chips in house now, so I wonder if they do close it up.
771
01:06:37.414 --> 01:06:39.515
That is, like, an existential risk.
772
01:06:40.694 --> 01:06:42.154
What do you to to
773
01:06:42.775 --> 01:06:46.635
specifically, the question about, like, hardware backdoors, are you worried about
774
01:06:47.000 --> 01:06:48.220
Google having something
775
01:06:49.320 --> 01:06:52.380
running on their chips that we're not aware of?
776
01:06:53.320 --> 01:06:55.340
777
01:06:57.935 --> 01:07:02.035
I mean, this is one of those situations where a lot of times people
778
01:07:02.975 --> 01:07:03.475
let
779
01:07:04.000 --> 01:07:04.740
a potential
780
01:07:05.200 --> 01:07:05.700
risk
781
01:07:06.080 --> 01:07:08.900
get in the way of measurable steps towards privacy.
782
01:07:10.240 --> 01:07:21.445
And the risk of a hardware back is always present. That's present in essentially every piece of hardware you can purchase because open source hardware has not really taken off. It's not really a thing for most types of devices,
783
01:07:22.290 --> 01:07:24.630
and it is absolutely not a thing for mobile phones
784
01:07:25.090 --> 01:07:31.100
in any usable sense. I know there are some open source hardware phones that have been in the works for a long time now, but,
785
01:07:31.675 --> 01:07:34.575
they just haven't developed into something that I would ever recommend to someone.
786
01:07:35.275 --> 01:07:35.775
But
787
01:07:36.235 --> 01:07:39.855
because the hardware is closed source and because the hardware is proprietary,
788
01:07:40.600 --> 01:07:45.260
yes, there is not a way that you can easily verify that there's not some sort of hardware backdoor.
789
01:07:46.440 --> 01:08:02.460
And then, yeah, I I don't love that. But that that would be true of any device that you flash a privacy preserving version of Android on. If you took a random Samsung phone and did that, you would have the same problem. Samsung could have put in hardware backdoors. Samsung actually manufactures a lot of the
790
01:08:02.920 --> 01:08:11.955
the hardware that goes into Google phones. I mean, they they manufacture a lot of NAND chips that are used for storage. They manufacture a lot of screens. There are lots of places where they could have done something with the backdoor.
791
01:08:12.335 --> 01:08:14.734
And it's just it's one of those attack vectors that is
792
01:08:16.050 --> 01:08:20.710
it's there and it exists and it could always happen, but it is very rare.
793
01:08:21.090 --> 01:08:31.175
And you have to think about the effect they would have if something about a hardware backdoor came out that a company had done that. I mean, this is something that has happened in the past with, like, the NSA has been
794
01:08:31.555 --> 01:08:32.455
caught catching
795
01:08:32.915 --> 01:08:48.945
devices in transit, imp implementing hardware backdoors, and then passing them along. And later, we found out that some companies were complicit in this and okay with it, and that has a devastating effect effect on public opinion about that company. So there is a a social incentive that helps to keep companies honest.
796
01:08:50.125 --> 01:08:53.264
I also think there are so many other ways to collect data that
797
01:08:53.670 --> 01:08:55.130
Google knows that 99.9999%
798
01:08:56.390 --> 01:09:10.185
of the users of Google Pixel devices are just gonna be using their OS. So if they really wanted to do something malicious, it would be infinitely easier to just put something malicious in the code that they ship and not have to worry about putting in a hardware backdoor, and they could still do a lot of the same things.
799
01:09:11.090 --> 01:09:18.630
So I think, yes, it's an attack vector. It's something that's true of every piece of hardware that is proprietary, which is practically every piece of hardware,
800
01:09:19.170 --> 01:09:23.095
but it's something that it's it's very costly for a company to do.
801
01:09:23.555 --> 01:09:33.040
And if it is done, as far as I know, every instance of it being done is in an extremely targeted way. So it's to target very specific people or very specific organizations
802
01:09:33.739 --> 01:09:37.199
that are worth the risk of it being discovered that you put in a hardware backdoor.
803
01:09:37.605 --> 01:09:55.780
So, like, you as the random person listening to this, your threat model likely does not include Google targeting you and specifically finding a way to get a pixel in your hands that is hardware backdoored. And from everything we know about pixels, they are not hardware backdoored today. So it would have to be a a unique pixel device that's backdoored and sent to you.
804
01:09:56.995 --> 01:09:59.975
So I think the the actual real life risk is
805
01:10:00.595 --> 01:10:11.510
extremely minimal to non existent. If you do have a very advanced threat model where you're worried about a hardware backdoor targeting you, that's a different conversation. You probably need to find a way to use open source hardware,
806
01:10:12.315 --> 01:10:16.895
or make sure that you're getting a device that is known to be not backdoored or learning hardware engineering
807
01:10:17.355 --> 01:10:21.295
and, just kind of digging through the device and making sure that nothing's been changed. But,
808
01:10:22.380 --> 01:10:31.515
it's it's one of those things that I understand the hesitancy, but I think it's I think it's unnecessary. It shouldn't get in the way of you making practical steps towards mobile
809
01:10:32.055 --> 01:10:32.455
privacy.
810
01:10:32.935 --> 01:10:40.450
811
01:10:41.230 --> 01:10:43.890
And you can't let the perfect be the enemy of the good,
812
01:10:44.670 --> 01:10:45.570
or good enough.
813
01:10:46.255 --> 01:10:49.395
I, obviously, I think open hardware is the ideal,
814
01:10:50.494 --> 01:10:55.155
that we should strive for. Unfortunately, it's not really there yet. There are some
815
01:10:56.640 --> 01:10:57.700
projects working
816
01:10:58.640 --> 01:11:01.940
on open phones, more open privacy focused phones,
817
01:11:02.640 --> 01:11:10.005
including Purism and Fairphone and Pine Phone. Some of them have hardware switches on them so you can turn off Wi Fi, stuff like that.
818
01:11:10.625 --> 01:11:13.845
Unfortunately, they're just not really there yet. Some of them haven't shipped.
819
01:11:14.810 --> 01:11:17.070
They come very outdated to begin with,
820
01:11:17.449 --> 01:11:20.429
hardware wise. They're not very usable a lot of the time.
821
01:11:21.290 --> 01:11:22.670
Hopefully, that's just
822
01:11:23.685 --> 01:11:30.905
growing pains, and we see more open hardware in the future. I think in general, people should operate even if you're using a Kallax or a Graphene phone,
823
01:11:32.260 --> 01:11:35.880
or like on on desktop or laptop, you're using a Linux device.
824
01:11:36.659 --> 01:11:38.360
You should operate that all your
825
01:11:39.085 --> 01:11:43.105
all your electronics are compromised to begin with if it's a sophisticated hacker,
826
01:11:43.804 --> 01:11:45.105
a sophisticated attacker,
827
01:11:46.510 --> 01:11:47.730
to speak more clearly.
828
01:11:49.230 --> 01:11:51.650
And so you operate under that assumption.
829
01:11:52.590 --> 01:11:55.170
But in general, all things equal,
830
01:11:56.245 --> 01:12:01.145
you take a off the shelf Google Pixel device and you flash one of these,
831
01:12:02.405 --> 01:12:03.864
more privacy focused,
832
01:12:05.590 --> 01:12:09.130
open source forks, you you have better privacy,
833
01:12:10.230 --> 01:12:14.745
for mass collection from the low hanging fruit, than you would have otherwise.
834
01:12:16.005 --> 01:12:27.260
835
01:12:28.555 --> 01:12:35.135
And to my understanding, every Pixel device is unlockable except those that have been sold through Verizon. For some reason,
836
01:12:35.650 --> 01:12:39.190
Verizon has chosen to not allow their bootloaders to be unlocked.
837
01:12:39.810 --> 01:12:42.310
And really quick note, there's 2 types of unlocking devices.
838
01:12:42.765 --> 01:12:50.705
One that a lot of people think of is carrier unlocked, which just means that you can go take your phone from, like, Verizon to AT and T and use it there.
839
01:12:51.340 --> 01:12:57.840
And, thankfully, most phones nowadays can be carrier unlocked either right away or after, like, a 2 year contract ends or something like that.
840
01:12:58.535 --> 01:13:04.075
But the the key thing that matters for flashing, Kallax, or Graphene is that the bootloader is unlockable.
841
01:13:04.775 --> 01:13:11.070
And Google is good about that, but Verizon specifically, as a partner with Google, have chosen to not allow the bootloader to be unlocked.
842
01:13:11.449 --> 01:13:18.825
So if you get a Pixel device, make sure in every way possible that it is not a Verizon Pixel because you will not be able to bootloader unlock that.
843
01:13:19.285 --> 01:13:24.900
But every other carrier, AT and T, everyone else you can get it through. I mean, you you can get them straight from Google as well.
844
01:13:25.920 --> 01:13:31.139
There's not Google stores, so that's probably not the best privacy preserving way to do it, but it's it's doable. But,
845
01:13:31.905 --> 01:13:36.965
just make sure when you're using, like I I would definitely recommend buying these secondhand as well when you can,
846
01:13:37.425 --> 01:13:41.860
and using services, at least in the US. I don't know how worldwide this is, but swappa.comswappa.com
847
01:13:44.400 --> 01:13:46.740
are a really good secondhand phone market,
848
01:13:47.280 --> 01:13:51.204
and they constantly have pixels on there that are for sale. And they're very
849
01:13:51.985 --> 01:14:04.449
specific in you have to list the carrier properly. They check the IMEI when it's turned into the site to make sure that it's for the right carrier carrier and unlocked and everything like that. So you can make sure that you don't get a Verizon Pixel on there or if using Craigslist.
850
01:14:05.105 --> 01:14:09.025
I'm sure there are ways to inspect it to make sure that it's not a Verizon. I don't know them offhand,
851
01:14:10.625 --> 01:14:12.645
but I'm sure you could look that up to do that.
852
01:14:13.040 --> 01:14:16.100
853
01:14:16.800 --> 01:14:17.780
854
01:14:18.480 --> 01:14:22.945
I think I mean, cost specifically. If phones are just ridiculously overpriced these days,
855
01:14:24.145 --> 01:14:27.045
there's not a need for them to be as expensive as they are. And
856
01:14:27.425 --> 01:14:31.204
especially since, normally, when you're buying a device for calyx or graphene, you're buying
857
01:14:31.950 --> 01:14:38.850
a generation behind or the the lower end phone because you don't need all of the power because Kallax OS is so lightweight. It works
858
01:14:39.175 --> 01:14:42.875
incredibly well. Battery life is much better than normal Android, that kind of thing.
859
01:14:43.575 --> 01:14:48.315
But also just privacy. It's it's great to be able to especially if you can use something like Craigslist.
860
01:14:49.060 --> 01:14:54.520
You can meet someone. They don't know your name. Like you said, in this environment, you can wear a mask, sunglasses, and a hat.
861
01:14:55.300 --> 01:15:02.415
You can hand them cash. They hand you a phone. You make sure that's legitimate, and you walk away. And there's there's no record other than maybe an email,
862
01:15:03.780 --> 01:15:12.280
and hopefully you're using some other email or an email alias or something to do that. There's no record that you're the one that purchased that phone or that that IMEI is yours specifically.
863
01:15:12.765 --> 01:15:21.965
And if you take it home and you immediately flash Kallax or Graphene before doing anything else, there's no record that you were you used an account on there that's Google specific or anything like that. So,
864
01:15:23.010 --> 01:15:28.310
I think it's it's nice for both price. You're just saving money on a phone that's gonna work well even if it's a little bit older
865
01:15:28.770 --> 01:15:29.670
and privacy.
866
01:15:30.365 --> 01:15:34.305
867
01:15:34.765 --> 01:15:37.985
it's worth it for the premium to just buy it new and not
868
01:15:39.180 --> 01:15:42.880
have a potential malicious individual in between you and the device.
869
01:15:44.620 --> 01:15:54.235
870
01:15:54.855 --> 01:16:03.280
the person you find on Craigslist or whatever, being a government agent that's selling you a back to a pixel, like, it I mean, again, yeah, like I mentioned, it's possible
871
01:16:03.815 --> 01:16:07.835
unless you have a very specific threat model that fits that or you're a very high profile individual,
872
01:16:08.454 --> 01:16:09.195
that probably
873
01:16:09.735 --> 01:16:10.554
won't happen.
874
01:16:11.094 --> 01:16:19.110
And the other thing, you don't need to be worried about the malicious operating system because you're just gonna be flashing it with a a known, hopefully,
875
01:16:20.055 --> 01:16:25.035
verified version of Calix OS or Graphene. Right. Most malicious individuals would probably
876
01:16:25.735 --> 01:16:34.220
877
01:16:35.640 --> 01:16:37.475
They, you know, they tend to, like,
878
01:16:37.955 --> 01:16:39.415
just ship it with a predetermined
879
01:16:39.795 --> 01:16:40.855
seed already.
880
01:16:41.475 --> 01:16:44.775
So even if you just created a new seed, you'd be fine. But,
881
01:16:45.715 --> 01:16:47.255
in general, to me,
882
01:16:47.620 --> 01:16:50.280
one of the biggest advantages of something like Kallax
883
01:16:50.580 --> 01:16:51.640
over something
884
01:16:52.580 --> 01:16:55.800
like Purism I'm pretty sure Purism isn't shipping still,
885
01:16:56.125 --> 01:16:58.144
but over something like Purism is
886
01:16:59.005 --> 01:17:01.824
with Purism, you basically have to buy it online,
887
01:17:03.370 --> 01:17:08.270
and it's a direct privacy focused device. I love what Purism does on their laptops,
888
01:17:09.210 --> 01:17:12.830
but the same thing goes with the laptops. You know? You're buying a
889
01:17:13.245 --> 01:17:16.465
you're buying a device that is focused for privacy people.
890
01:17:17.085 --> 01:17:19.825
You're buying it online, so you have all these other
891
01:17:20.739 --> 01:17:26.039
threat models that you have to deal with, other all these gotchas that could happen because you're online.
892
01:17:26.579 --> 01:17:27.079
It's
893
01:17:27.835 --> 01:17:29.135
it's really fantastic
894
01:17:29.435 --> 01:17:33.215
with the Kallik setup that you can just go buy off the shelf hardware
895
01:17:35.270 --> 01:17:38.010
that is very common hardware with cash,
896
01:17:39.110 --> 01:17:43.050
and have a relatively private acquisition experience just from that.
897
01:17:43.830 --> 01:17:48.954
So, I mean, before we continue, I think we should dive into actually everyday usage of Kallix.
898
01:17:51.895 --> 01:17:53.994
I put your link in the video
899
01:17:54.500 --> 01:17:58.519
feed earlier, but to the people on audio, your blog is seth for privacy.com.
900
01:17:59.380 --> 01:18:03.145
You also have your podcast opt out, which is opt outpod.com.
901
01:18:03.605 --> 01:18:05.225
And on both, you have
902
01:18:05.765 --> 01:18:12.559
links to, like, different tools or, you know, resources to tools you like using on Calix. You wanna go into that a little bit?
903
01:18:15.900 --> 01:18:16.800
904
01:18:18.275 --> 01:18:27.780
Yeah. When I made the switch to Kallax OS, I wanted to be very specific about recording the things that I that I learned, recording the the app stores that I used,
905
01:18:28.420 --> 01:18:31.159
recording the apps that I found that that replaced some
906
01:18:31.539 --> 01:18:35.880
non open source or centralized alternatives as I kinda made the switch so that,
907
01:18:36.825 --> 01:18:53.700
honestly, just so that I would have a good resource that I could share with people. Because a lot of what I found is when I'm interacting with people regularly on Twitter, it can get really tiring to have to kinda dig up lists and find things and be like, oh, wait. What what app was I using? That kind of thing. So, oftentimes, it's just helpful for me to have these lists of things so I can easily share them and and share them as resources,
908
01:18:54.505 --> 01:19:01.165
But also just to help people who are trying to figure out, like, can I switch to Calix OS? Are there apps that'll meet the needs that I have that
909
01:19:01.470 --> 01:19:06.770
that don't rely on Google or don't rely on Google Play Services or maybe that are just not as
910
01:19:07.150 --> 01:19:08.405
as much of a
911
01:19:09.045 --> 01:19:10.025
kind of a data
912
01:19:10.405 --> 01:19:14.744
collection tool as some of the the kind of default services that people use.
913
01:19:15.590 --> 01:19:18.969
And so I I wrote out this blog post. Kinda it talks through
914
01:19:19.349 --> 01:19:23.610
my reasons for going with Kallix OS specifically, which we've talked a lot about today.
915
01:19:24.455 --> 01:19:30.795
It very briefly goes through how to install Calix itself, but like you mentioned, it's actually a lot easier than people realize.
916
01:19:31.120 --> 01:19:41.485
There's a really simple CLI flashing tool that does the vast majority of the work for you. It walks you through when to unlock the bootloader, when to lock it, what it's doing with each step. It it works really well.
917
01:19:42.765 --> 01:19:48.225
I am more tech savvy. I'm very familiar with CLI, but it took me, I think, like, 8 minutes
918
01:19:48.790 --> 01:19:49.290
from
919
01:19:49.670 --> 01:20:03.415
deciding to flash Kallix to flashing Kallix and to being up and running. Like, it it was it was incredibly quick, and it was not a complex process. And, like, I I would have been more familiar with the complex process and fine with it, but it was simpler than I expected for sure. And then
920
01:20:03.795 --> 01:20:17.625
Bitcoin q and a also has a really good installation guide for Kallax that's way more detailed than mine on how you actually do the process. So if you're if you're more worried about the installation, his guide is also linked for mine, and I'm sure you can throw it in the notes or something, Matt, as well. But,
921
01:20:18.165 --> 01:20:21.465
that's a good guide to just actually getting it installed.
922
01:20:22.885 --> 01:20:26.640
But one of the biggest things that people have to do continue really quickly,
923
01:20:27.260 --> 01:20:31.725
924
01:20:33.864 --> 01:20:34.685
Okay. Continue.
925
01:20:35.545 --> 01:20:37.725
926
01:20:39.620 --> 01:20:43.320
So the the biggest thing people have to wrap their heads around with switching to
927
01:20:43.700 --> 01:20:47.080
Kallax or Graphene is that you don't have the Google Play Store anymore.
928
01:20:47.955 --> 01:20:56.520
And that may seem like a small thing, but that means that all of the apps that you want to install on your phone, you have to find some other way, and that is a 100% a good thing.
929
01:20:56.920 --> 01:21:00.940
I know it is, again, giving up convenience for for privacy and security, but,
930
01:21:01.560 --> 01:21:06.385
it is worth it. So you won't have the Google Play Store. So the way that you can install apps is
931
01:21:06.845 --> 01:21:10.545
there's essentially 2 different ways. 1 is using a different app store,
932
01:21:11.780 --> 01:21:17.960
the the main one of which is something called F droid, which is a repository of only free and open source apps
933
01:21:18.285 --> 01:21:21.105
that F droid themselves build from source and verify.
934
01:21:21.885 --> 01:21:26.864
So it's an app store that is really, really good for that because everything you're gonna find in there is false, which is it's great.
935
01:21:27.440 --> 01:21:29.460
That's what I use for, like, 99.9%
936
01:21:30.480 --> 01:21:31.780
of the apps that I use.
937
01:21:33.200 --> 01:21:37.045
There's also a open source Google Play Store alternative
938
01:21:37.425 --> 01:21:40.245
that is able to pull in apps that are on the Google Play Store
939
01:21:40.705 --> 01:21:42.945
and help you to install them locally.
940
01:21:43.344 --> 01:21:44.645
And that works really well.
941
01:21:45.140 --> 01:21:46.040
I definitely
942
01:21:46.500 --> 01:21:48.840
advise, if at all possible, using F droid,
943
01:21:49.220 --> 01:21:52.760
just because it's good to switch to those FOSS apps anyways and support them,
944
01:21:53.220 --> 01:21:58.335
but also just that there's better security guarantees with using F droid than there are with Aurora store.
945
01:22:00.155 --> 01:22:03.935
You can also the second main way to install apps is to install the actual
946
01:22:04.640 --> 01:22:07.699
APKs is the the term, but the actual,
947
01:22:08.560 --> 01:22:11.380
application files for the application manually.
948
01:22:12.320 --> 01:22:12.820
But
949
01:22:13.495 --> 01:22:24.330
there's a lot of risk in doing that. Most people are not going to verify signatures or anything like that. It's very easy to get a malicious version of an app. So if you are going to install directly via the APK,
950
01:22:24.950 --> 01:22:29.210
make, like, a a 1000000 percent sure that you're going to the official website,
951
01:22:29.715 --> 01:22:38.935
that everything is legitimate. If there's a way to verify signatures, verify signatures because you're taking on a lot of risk manually side loading apps. Yeah. Learn how to verify signatures.
952
01:22:39.380 --> 01:22:41.159
953
01:22:41.699 --> 01:22:45.159
The freaks are very aware of that. I I try and
954
01:22:46.420 --> 01:22:47.639
phone that one home,
955
01:22:48.145 --> 01:22:49.925
as much as possible on dispatch.
956
01:22:51.025 --> 01:22:59.650
You know, when I first started using Kallax, they actually didn't even offer signatures of the Kallax image files, but then they started doing it after I asked them to.
957
01:23:00.350 --> 01:23:05.825
So that's fantastic. And the easiest way I have a lot of people ask me, how do I do that
958
01:23:06.445 --> 01:23:13.505
on my mobile phone? How do I do that on my Kallax device? What I like to do is I I actually will just verify it on my computer,
959
01:23:14.030 --> 01:23:17.650
and then I will side load it over to the device.
960
01:23:18.750 --> 01:23:21.730
I just find it more convenient. There are ways to verify,
961
01:23:22.110 --> 01:23:22.850
the signatures
962
01:23:25.355 --> 01:23:27.355
directly on the device. Bitcoin,
963
01:23:27.675 --> 01:23:30.015
Bitcoin q and a also has a bitcoiner.guide
964
01:23:30.635 --> 01:23:35.639
has a as a resource for verifying PGP signatures. Dude is just a absolute machine.
965
01:23:36.260 --> 01:23:40.760
I have had him on the show previously, and he will be on dispatch again in the future.
966
01:23:42.505 --> 01:23:44.125
The other thing you can do,
967
01:23:44.505 --> 01:23:46.205
which I think is extremely underrated,
968
01:23:47.385 --> 01:23:49.405
is you can run the web app version,
969
01:23:49.900 --> 01:23:52.240
which is, like, most popular apps
970
01:23:52.860 --> 01:23:55.120
tend to have a relatively responsive,
971
01:23:56.380 --> 01:23:57.360
browser version.
972
01:23:58.545 --> 01:24:00.965
Twitter, for instance, is that's how I use Twitter.
973
01:24:01.905 --> 01:24:04.805
I only use the web app. So you you just you open,
974
01:24:06.300 --> 01:24:09.120
whether you're using Chromium or a Brave Browser.
975
01:24:09.580 --> 01:24:12.240
I think Kallax defaults to Brave Browser now.
976
01:24:14.195 --> 01:24:15.895
You can just go to twitter.com,
977
01:24:16.275 --> 01:24:23.730
and you can sign in, and you have pretty much 99% of the features that you would have on the Twitter app without having a dedicated app.
978
01:24:24.690 --> 01:24:25.989
979
01:24:26.530 --> 01:24:27.989
that is I mean, it's a
980
01:24:28.450 --> 01:24:32.790
it's a different topic a little bit because it's not installing an application, but it is a 100%
981
01:24:33.175 --> 01:24:35.515
the best way to go in, like, almost every scenario.
982
01:24:35.975 --> 01:24:39.755
If you can use a web app, there are so many advantages. And like you mentioned,
983
01:24:40.135 --> 01:24:40.635
browsers
984
01:24:41.200 --> 01:24:46.900
on mobile make it really easy for you to kind of turn a web app into an application. It'll put an icon on your screen.
985
01:24:47.200 --> 01:24:55.925
It'll be treated kind of like an app and how it's handled in the recents bar. There's a lot of advantages to doing that. And the I mean, the biggest one is you're not giving that
986
01:24:56.465 --> 01:25:01.890
website or that tool any access into your system past what the the browser allows, which is generally
987
01:25:02.430 --> 01:25:19.240
next to nothing. You're essentially running a sandbox version, not technically. So if you're technical out there, I know. But you're essentially running a sandbox version of the application that doesn't have control over the system data, over storage, doesn't have access to webcam or microphone unless you explicitly allow it. So it provides a lot better,
988
01:25:21.060 --> 01:25:22.680
potential privacy and security,
989
01:25:23.460 --> 01:25:29.965
guarantees than you would have if you're running the app itself, but it's kind of this it's a it's a greater topic of digital minimalism,
990
01:25:30.665 --> 01:25:34.845
which has a lot of crossover with privacy, but is a really important one. And just the idea that
991
01:25:35.790 --> 01:25:36.530
you really
992
01:25:37.070 --> 01:25:45.945
you really can cut down on the the the services that you use, the tools that you use, the applications you use. And as you actually do that and you kind of move more towards digital minimalism,
993
01:25:46.485 --> 01:25:47.785
less apps, less,
994
01:25:48.325 --> 01:25:57.170
accounts that you have, all of that, you actually gain better privacy just by being off of those things. So like you, I I only use Twitter through the the browser
995
01:25:57.505 --> 01:26:13.730
on my phone. I save it as an application on the home screen, so I can still just click straight into Twitter. And, yeah, it's not quite as nice as using the app. It's a little bit more annoying. Sometimes there's some issues and nuance, but most of the time, it works pretty darn well, and I don't ever have to worry about all of the telemetry and data collection that Twitter's
996
01:26:14.110 --> 01:26:17.735
trying to do through their app. But I can just use it straight through the browser.
997
01:26:19.155 --> 01:26:26.020
998
01:26:26.480 --> 01:26:29.940
Obviously, social media in general tends to be surveillance focused,
999
01:26:30.719 --> 01:26:32.420
reduce your social media usage.
1000
01:26:33.895 --> 01:26:35.515
Twitter is my weak spot,
1001
01:26:36.375 --> 01:26:39.355
but I I don't use any other social media besides Twitter.
1002
01:26:42.239 --> 01:26:49.620
What else do I have on the list? So Calix oh, so the the big the the the big gaping hole
1003
01:26:50.205 --> 01:26:53.505
that most users will see when they switch to something like Kallix
1004
01:26:54.045 --> 01:26:55.985
is going to be the banking apps,
1005
01:26:57.400 --> 01:27:01.080
whether that's directly for your bank or if it is a
1006
01:27:01.560 --> 01:27:06.620
one of these, like, new age banking apps, like a Cash App or a Venmo or something like that.
1007
01:27:07.915 --> 01:27:13.855
You tend to they first of all, they none of them provide APKs, so you can't get the direct download.
1008
01:27:14.969 --> 01:27:20.989
They're not free open source software, so you're not gonna get it on F droid. An Aurora store tends to not have them.
1009
01:27:21.965 --> 01:27:23.185
So that will be,
1010
01:27:23.885 --> 01:27:26.465
I think, for most people, will be the
1011
01:27:26.765 --> 01:27:27.425
the biggest
1012
01:27:29.239 --> 01:27:31.340
loss in terms of what they're used to.
1013
01:27:32.599 --> 01:27:33.099
Obviously,
1014
01:27:35.159 --> 01:27:41.065
whether you're in Bitcoin or Monero, that that is that is something that we're trying to obsolete anyway.
1015
01:27:43.605 --> 01:27:47.844
So, hopefully, it's just a short term pain. You can still, you know, maybe
1016
01:27:48.390 --> 01:27:52.730
if you really need to have that type of mobile banking experience,
1017
01:27:53.750 --> 01:27:57.530
you know, you have a a a separate, basically, like, KYC phone,
1018
01:27:58.034 --> 01:28:00.135
that you use for those types of things,
1019
01:28:00.835 --> 01:28:05.175
that is separate from your daily driver, and then it becomes a little bit less of a sacrifice.
1020
01:28:06.620 --> 01:28:08.320
Another big one is
1021
01:28:08.940 --> 01:28:10.880
if you're not running Micro g,
1022
01:28:11.820 --> 01:28:12.960
you lose access
1023
01:28:13.645 --> 01:28:16.145
to, like, the Ubers and the Lyfts of the world,
1024
01:28:16.925 --> 01:28:19.745
which is a a very big one that I've heard from people.
1025
01:28:22.050 --> 01:28:26.389
And this is where some of the nuance comes in about why I do like Micro g
1026
01:28:26.929 --> 01:28:27.670
is because
1027
01:28:28.585 --> 01:28:29.545
when I am in a
1028
01:28:31.065 --> 01:28:34.925
when I'm traveling and I'm in a town, like, when I was in Miami recently,
1029
01:28:36.260 --> 01:28:39.240
Uber is an extremely useful tool to have,
1030
01:28:39.860 --> 01:28:40.360
because
1031
01:28:41.700 --> 01:28:44.120
I don't have a car and drunk driving is bad anyway,
1032
01:28:44.824 --> 01:28:47.724
And I do have a little bit of an alcohol
1033
01:28:50.344 --> 01:28:50.844
consumption
1034
01:28:52.449 --> 01:28:54.130
1035
01:28:54.850 --> 01:28:56.770
pork pops this episode. So
1036
01:28:57.730 --> 01:29:02.175
1037
01:29:02.475 --> 01:29:05.755
a a a much better conversation if I consume beer instead.
1038
01:29:07.355 --> 01:29:07.855
The
1039
01:29:09.449 --> 01:29:17.310
the nice thing is you can use Uber with Micro g, and and best practice is probably to uninstall it when you're not using it.
1040
01:29:18.475 --> 01:29:20.975
But what's really cool about Kallax is it has
1041
01:29:22.075 --> 01:29:24.655
this built in firewall that comes with the phone,
1042
01:29:25.790 --> 01:29:37.085
And Graphene does not have this, and it's it is extremely useful for these types of quasi surveillance apps. As far as I'm concerned, Uber is a surveillance app. They're harvesting as much information from you as possible.
1043
01:29:38.985 --> 01:29:43.650
With Kallix, you can set in this firewall. You can you can literally choose,
1044
01:29:44.590 --> 01:29:49.330
which apps have background data access, which apps have Internet access, period.
1045
01:29:50.255 --> 01:29:53.715
And you can force an app to only connect if you have a VPN.
1046
01:29:54.415 --> 01:29:55.474
So you can install
1047
01:29:55.775 --> 01:29:58.594
you you can run a VPN on your phone,
1048
01:29:58.910 --> 01:30:01.890
and you can set it so Uber can never access
1049
01:30:02.270 --> 01:30:06.850
the Internet unless the VPN is running. So it's got a, like, a, basically, a foot gun
1050
01:30:07.284 --> 01:30:15.705
protection because a lot of people, what they'll do if they don't have that firewall feature is they'll intentionally make sure they're running a VPN whenever they do it. But, undoubtedly,
1051
01:30:16.130 --> 01:30:18.309
you're gonna make a mistake and you're gonna,
1052
01:30:20.050 --> 01:30:24.469
open the app without a VPN. So I think that firewall that they have built in is absolutely
1053
01:30:25.335 --> 01:30:26.715
fantastic. It's the coolest
1054
01:30:27.255 --> 01:30:33.495
1055
01:30:34.180 --> 01:30:36.840
something I I would do if I was running an app like that
1056
01:30:37.220 --> 01:30:55.500
is when I know I'm not using the app, like, at all, like, when I'm not traveling, especially apps like Uber, like Lyft, like, maybe if you fly a lot, maybe you have, like, the airplane or the airline specific app. When you you know you're not gonna need it until you travel next time, just go into the firewall, switch off network access, and that app has no ability to transmit anything.
1057
01:30:55.880 --> 01:31:10.620
So even if you open it in between on accident or if you don't open it and it has some background process that normally tries to collect data and send it off, it has no access at all until the next time you need it. Like, you're in the in the airport, you're ready to go ahead and get on, go ahead and give it Internet access, grab the boarding pass, you're done.
1058
01:31:11.900 --> 01:31:25.565
So that's I think that's a really important feature as well. And I actually never connected the dots that you could use that to make the app only available to connect to the VPN. I actually had thought about the the opposite way, so that was a really good point that you brought up. I hadn't hadn't thought about making that change.
1059
01:31:26.585 --> 01:31:28.605
And I would also mention with VPNs, generally,
1060
01:31:28.920 --> 01:31:32.380
Android in general is good about this. Kallax OS is no different, but,
1061
01:31:32.760 --> 01:31:47.680
Android has a really good feature. When you use a VPN and and you set it up, go into the VPN settings under, I think it's Network and Internet, in your general settings, and you can check Always on VPN, which will mean that the moment you have a network connection, your phone will try to connect to VPN
1062
01:31:48.460 --> 01:31:52.475
immediately without even do anything extra. And then, also, you can check block all connections without
1063
01:31:52.775 --> 01:31:57.195
VPN so that if for some reason your VPN's disconnected, your account dies, or,
1064
01:31:57.575 --> 01:32:02.810
there's some issue connecting to the VPN, your phone won't have network access until you reconnect to the VPN.
1065
01:32:03.510 --> 01:32:18.435
And that, especially, I found that can be really powerful when you're traveling and hopping on to different public Wi Fi because sometimes public Wi Fi providers will block known VPN providers or normal VPN ports, and so your VPN can't connect. And if you don't have that that,
1066
01:32:19.080 --> 01:32:20.219
toggle switched,
1067
01:32:20.600 --> 01:32:22.699
your phone will just connect without the VPN,
1068
01:32:23.000 --> 01:32:31.705
and then you could be leaking a lot of stuff that you don't want to. So those are some really important VPN controls. They're not specific to Kallix or Graphene, but I just think those are important pieces that some people don't see.
1069
01:32:32.165 --> 01:32:40.430
1070
01:32:40.810 --> 01:32:41.950
it's definitely lacking.
1071
01:32:43.825 --> 01:32:47.125
At least I've noticed that when I've tried to help friends install
1072
01:32:47.425 --> 01:32:48.885
VPNs on their iPhones.
1073
01:32:50.625 --> 01:32:52.805
To go back to this firewall, so
1074
01:32:54.199 --> 01:32:55.980
what's really cool so
1075
01:32:56.920 --> 01:32:57.580
I think
1076
01:32:58.040 --> 01:33:00.699
so I've never used Kallix without Micro g,
1077
01:33:02.845 --> 01:33:06.865
But a cool aspect of Micro g is that I can I side loaded
1078
01:33:07.245 --> 01:33:07.745
the
1079
01:33:09.325 --> 01:33:11.105
the the native Pixel
1080
01:33:12.880 --> 01:33:13.860
camera app?
1081
01:33:15.600 --> 01:33:16.100
And
1082
01:33:17.360 --> 01:33:18.180
because because
1083
01:33:18.640 --> 01:33:23.135
both for my Fiat job and just for life in general, I I tend
1084
01:33:23.675 --> 01:33:28.815
I've I've tend to really appreciate the convenience of having a high quality camera in my pocket.
1085
01:33:30.790 --> 01:33:36.090
And Google is known to basically, what they do is they take off the shelf hardware for their cameras,
1086
01:33:36.550 --> 01:33:37.610
the actual sensors,
1087
01:33:38.244 --> 01:33:40.105
but they do a lot of
1088
01:33:41.125 --> 01:33:45.625
software magic to try and make the photos as good as possible, and that's
1089
01:33:46.040 --> 01:33:48.460
only in the the Pixel camera app.
1090
01:33:49.000 --> 01:33:52.860
So I side load the Pixel camera app, and the camera app checks
1091
01:33:53.175 --> 01:33:56.795
if there's Google Play services. So it won't run without Google Play services,
1092
01:33:57.335 --> 01:33:59.435
but the micro g checks that box.
1093
01:33:59.735 --> 01:34:09.560
And because of the firewall, I can set it so the app never has any kind of network access even if the VPN is running. There's no network access at all if the software firewall is working as designed.
1094
01:34:10.125 --> 01:34:13.665
So it's a nice little trade off balance there where I get better photos,
1095
01:34:16.045 --> 01:34:19.345
without necessarily trusting that there's not, like, some,
1096
01:34:19.790 --> 01:34:23.330
you know, Google server back end that's getting hit by it.
1097
01:34:23.949 --> 01:34:28.370
And then the other big one that you hear a lot of Kallax proponents talk about
1098
01:34:29.065 --> 01:34:31.725
is, you know, the open source keyboards
1099
01:34:32.265 --> 01:34:32.765
tend
1100
01:34:33.545 --> 01:34:35.965
to be a lot worse than Google's keyboard.
1101
01:34:37.310 --> 01:34:39.090
I assume what do you use? Like, AnySoft?
1102
01:34:40.590 --> 01:34:43.570
1103
01:34:45.485 --> 01:34:51.745
I use OpenBoard. It's the one that I use. It's available on F droid. I've tried most of the ones that people recommend,
1104
01:34:52.180 --> 01:34:56.680
and they all have issues that make them kind of unusable for me. OpenBoard has been the best.
1105
01:34:57.860 --> 01:35:06.545
I'm assuming what you'll probably get to is that you can use other keyboards that would be collecting data and kill the data access. But You can literally use Google's keyboard. You can use Gboard,
1106
01:35:07.165 --> 01:35:08.705
1107
01:35:10.010 --> 01:35:10.510
I
1108
01:35:10.810 --> 01:35:13.949
mean, obviously, you're putting a lot of trust in that software firewall,
1109
01:35:15.449 --> 01:35:18.830
but it is a nice trade off balance because you get the full,
1110
01:35:19.475 --> 01:35:25.335
basically, Google keyboard experience where they've worked really hard on on making that a really fantastic keyboard,
1111
01:35:26.835 --> 01:35:27.335
without
1112
01:35:28.040 --> 01:35:28.780
that information
1113
01:35:29.400 --> 01:35:31.500
theoretically getting hitting their servers.
1114
01:35:32.760 --> 01:35:39.395
1115
01:35:40.094 --> 01:35:44.355
And I I have been able to find all of the banking apps that I have used in the past on Aurora.
1116
01:35:44.720 --> 01:35:49.220
I've uninstalled them all now because I realized I don't actually need any of them installed on my phone. But,
1117
01:35:50.480 --> 01:35:56.915
like, all of mine specifically were available at Aurora. I think someone mentioned in the chat that there was a way to kind of change how
1118
01:35:57.615 --> 01:35:59.715
Google sees your Aurora store
1119
01:36:00.640 --> 01:36:01.140
instance
1120
01:36:01.760 --> 01:36:04.400
to make it think that you're in a different location, which will,
1121
01:36:04.800 --> 01:36:10.415
give you access to the apps that you should have access to. I I haven't tried that, but there may be something there about,
1122
01:36:10.895 --> 01:36:17.395
playing around with Aurora store a bit. But for me in Aurora store, all the banking apps I've needed have been available and installed just fine. Oh, that's interesting.
1123
01:36:20.880 --> 01:36:21.940
1124
01:36:23.280 --> 01:36:27.680
general yeah. I a lot of the banking apps also block VPNs or they don't
1125
01:36:28.265 --> 01:36:34.445
they, like I don't know. They have issues with VPNs. In in general, the those are obviously going to be
1126
01:36:37.640 --> 01:36:39.100
anti anti privacy
1127
01:36:41.000 --> 01:36:41.500
apps.
1128
01:36:42.280 --> 01:36:49.455
1129
01:36:49.995 --> 01:37:00.100
The answer to a lot of that is just no. Like, a lot of the stuff you you get used to using, but there's just not really a reason to have it installed most of the time. And like you mentioned with websites, most of these
1130
01:37:00.525 --> 01:37:03.105
services have mobile websites that work pretty darn well.
1131
01:37:03.885 --> 01:37:10.420
And if you do need to install the app, maybe you can just do it for a short time if there's a specific thing you need to do, like upload a check or something. But
1132
01:37:10.720 --> 01:37:18.580
a lot of the time, you really just can kind of decide, I don't actually need this app, and get away with just the mobile website or just doing it on your computer when you're at your computer next.
1133
01:37:18.945 --> 01:37:27.125
1134
01:37:28.250 --> 01:37:31.310
So when you install Kallix, you will have that firewall,
1135
01:37:32.250 --> 01:37:33.790
there. It is not enabled.
1136
01:37:34.250 --> 01:37:37.495
You have to go in, and you can enable it on a per app basis,
1137
01:37:38.514 --> 01:37:45.090
whether you want to limit background access, limit all Internet connectivity, or force it to only use a VPN,
1138
01:37:46.190 --> 01:37:46.930
to access.
1139
01:37:49.710 --> 01:37:58.095
1140
01:37:58.635 --> 01:37:59.295
1141
01:37:59.740 --> 01:38:06.400
the live chat is my favorite part of dispatch, so feel free to just keep putting questions in there. Okay. Continue, Seth.
1142
01:38:06.915 --> 01:38:12.375
1143
01:38:12.755 --> 01:38:16.350
I don't think I will have quite as many people jumping in, but
1144
01:38:17.130 --> 01:38:17.870
we'll see.
1145
01:38:18.650 --> 01:38:23.710
So we'll we'll go and jump back. Manera Lion asked, what is the biggest downside of having Micro g on Calix?
1146
01:38:24.395 --> 01:38:29.135
I think this is a a good one to cover. I think I briefly mentioned a little bit about it before.
1147
01:38:29.915 --> 01:38:32.575
I'm not sure your thoughts around it, Matt. From my understanding,
1148
01:38:33.500 --> 01:38:36.400
it doesn't give Google a direct link between
1149
01:38:37.020 --> 01:38:38.400
your phone and you.
1150
01:38:39.020 --> 01:38:40.159
It doesn't tie
1151
01:38:41.804 --> 01:38:47.185
a device ID or a Google account to the things that you're running through Google Play Services.
1152
01:38:48.390 --> 01:38:52.489
So it's definitely better than just having regular Android and having Google Play Services.
1153
01:38:53.350 --> 01:39:03.755
In my mind, the the downsides are kind of twofold. One of them is that it enables you to keep using the services that have chosen to be reliant on Google Play services, which
1154
01:39:04.310 --> 01:39:17.474
personally, I like to I it it takes extra effort. It takes extra time. It takes getting used to, but I like to use and support apps that have taken the the step to not be relying on the Google Play Store or sorry. Google Play Services,
1155
01:39:18.494 --> 01:39:24.500
and there are a lot of apps that have baked in other ways to handle those things without Google Play Services, like,
1156
01:39:24.960 --> 01:39:29.780
for instance, 3 months. I started using 3 months recently for messaging. If you have Google Play Services,
1157
01:39:31.235 --> 01:39:36.375
notifications come in real time because, again, Google Play Services, one of the key things is that they handle push notifications
1158
01:39:36.835 --> 01:39:38.534
and they simplify it for app developers.
1159
01:39:39.120 --> 01:39:44.260
But Threema have put in the effort to build in a background service that if you don't have Google Play services,
1160
01:39:44.639 --> 01:39:49.185
it will regularly pull for messages, I think, anywhere between every 5 30 minutes,
1161
01:39:50.125 --> 01:39:54.865
which isn't quite as seamless as having instant push notifications. The moment someone sends a message,
1162
01:39:55.500 --> 01:40:01.360
missing a message for a max of 5 minutes. To me, it doesn't really matter. And if you have the app open, you're you get notifications instantly.
1163
01:40:02.985 --> 01:40:12.125
But that's an example of a good app that you could rely on Google Play services for, but you don't have to. And so, really, one of the reasons I chose not to use Micro g
1164
01:40:12.599 --> 01:40:17.980
is not necessarily that I see it as a major privacy risk. I really think for most people, it's probably fine.
1165
01:40:19.000 --> 01:40:24.245
It's not there's like I said, there's no direct ties between you and Google through it. It provides some anonymization,
1166
01:40:26.065 --> 01:40:28.405
but I wanted to force myself
1167
01:40:28.740 --> 01:40:33.400
to to go through the process of finding alternatives that did not reply that did not rely
1168
01:40:33.860 --> 01:40:35.880
on the services that Google provides.
1169
01:40:37.380 --> 01:40:37.880
And
1170
01:40:38.265 --> 01:40:51.060
that's what I did, and it was it was a little bit painful. But like I mentioned before, it really was not as bad as I expected to make that to make the switch to FOSS apps that actually cared about providing tools that could be used by those not using Google Play services. So
1171
01:40:51.440 --> 01:40:56.425
1172
01:40:57.605 --> 01:40:59.785
First of all, is awesome. I love.
1173
01:41:00.540 --> 01:41:02.480
That's how I invited you onto the show.
1174
01:41:03.580 --> 01:41:11.145
It costs money, and that's not a bad thing, people. That's what's cool. It's a my god. It's a free open source app, free as in freedom, that
1175
01:41:11.685 --> 01:41:18.745
that has a a paid model instead of harvesting your data, which is is very sustainable. And I I wouldn't be against other projects
1176
01:41:19.460 --> 01:41:20.280
offering similar,
1177
01:41:22.100 --> 01:41:27.640
1178
01:41:27.965 --> 01:41:29.265
use some post mixed stats,
1179
01:41:29.805 --> 01:41:35.905
go buy a a license that's $5. You're supporting the company who's building or not company, the organization who's building such a great tool. Like,
1180
01:41:36.220 --> 01:42:00.310
people need to use the concept that I am no longer paying in data, so I'm gonna pay in money to make sure that the people who are building the tools that I love can continue to build the tools that I love. Like, sorry. It's not a a high horse and a No. I agree. A little angry about, but I just I love seeing companies just willing or organizations willing to just say, hey. We want money for this because we're building a great tool, and people should be willing to pay for that. And and also to add there,
1181
01:42:01.445 --> 01:42:07.945
1182
01:42:08.560 --> 01:42:14.980
Another good app that handles without Google Play services and makes it a priority is Tutanota if you're using email,
1183
01:42:16.355 --> 01:42:21.494
which is a fantastic email provider, and and the app works really well without Google Play services.
1184
01:42:22.114 --> 01:42:26.770
I would just add on to the Micro g thing is there's 2 ways to use Micro g on Kallix.
1185
01:42:28.989 --> 01:42:29.889
Some apps,
1186
01:42:31.150 --> 01:42:34.130
you can use it to actually sign in to your Google account,
1187
01:42:35.055 --> 01:42:36.275
through Micro g.
1188
01:42:36.575 --> 01:42:37.555
I wholeheartedly
1189
01:42:38.015 --> 01:42:47.340
don't think anyone should do that. You should never use the Micro g component where you're signing in to your Google account. I I don't have a Google account attached to my device.
1190
01:42:47.800 --> 01:42:49.020
A lot of services
1191
01:42:49.960 --> 01:42:50.780
don't actually
1192
01:42:51.594 --> 01:43:00.495
need you to sign in to a Google account. They just need to know that there's a a Google Play Services, basically, capability on the device.
1193
01:43:01.710 --> 01:43:04.130
And those just will just work in the background,
1194
01:43:04.430 --> 01:43:04.930
and
1195
01:43:05.470 --> 01:43:10.585
and and you can you can get by on it. But I do I do agree with you that in general, even if you are running
1196
01:43:14.105 --> 01:43:19.245
Micro g, you should try and support services that go out of their way to not require Google Play services. And I I mentioned Moon earlier.
1197
01:43:19.570 --> 01:43:21.270
I know they're actively working,
1198
01:43:22.530 --> 01:43:25.270
to remove that requirement, so that that is good.
1199
01:43:26.130 --> 01:43:26.930
1200
01:43:27.395 --> 01:43:32.775
if it's a good project that just hasn't taken the step yet, which I think there definitely are many of those out there. I mean, like,
1201
01:43:33.155 --> 01:43:34.455
for example, ProtonMail,
1202
01:43:35.155 --> 01:43:43.130
which is a service that I use, their app does not work without Google Play services as far as notifications are concerned. So, like, I can't get email notifications through ProtonMail.
1203
01:43:44.310 --> 01:43:56.850
And they also don't publish onto F droid. And I do think that they're a good organization. I think they need to prioritize some some different things, and that would be F droid and not needing Google Play services as one of the big ones. But,
1204
01:43:57.390 --> 01:44:11.015
it also has pushed me towards services that do work without Google Play services. So I've, like, I've paid for c templar email because I know that I can get notifications using their app, and their app is available through F droid. So, again, we can show we can show our support
1205
01:44:11.460 --> 01:44:17.240
for organizations that are willing to put in the time and effort to to let us opt out of Google services
1206
01:44:17.860 --> 01:44:29.800
more easily by paying for their services, by showing our support publicly, by talking with people about why we use that app. And that can also be just really good competition to push the other organizations that are legitimately good, but maybe have different priorities
1207
01:44:30.180 --> 01:44:33.720
to start thinking more deeply about that before they start to lose market share.
1208
01:44:37.045 --> 01:44:37.545
1209
01:44:38.325 --> 01:44:40.505
You said you have some more questions written down?
1210
01:44:41.365 --> 01:44:49.840
1211
01:44:52.094 --> 01:45:01.790
This is one that I've been thinking about a lot. I I have to have an iPhone for work. The services that we use for work, I work in IT, and some of the stuff that we do has to
1212
01:45:02.650 --> 01:45:07.790
has to go on a device, and I don't want it touching my device, and they will give you an iPhone.
1213
01:45:08.285 --> 01:45:16.385
So I have a an iPhone for work, so I do have a private my regular personal Kallax OS phone, and then I have a non private iPhone that I use.
1214
01:45:18.280 --> 01:45:25.180
I would say there definitely is privacy risk. I mean, the main thing to to keep in mind is if you are carrying around that non private device with your private device everywhere,
1215
01:45:25.675 --> 01:45:31.375
you're likely giving away location. If there's, like, an assistant enabled, you could be giving away audio where you're at.
1216
01:45:31.835 --> 01:45:39.330
If you're taking pictures and videos, like we talked about earlier, Apple's gonna be digging through those looking for whatever they deem to be worth looking for at the moment.
1217
01:45:40.805 --> 01:45:43.705
So I definitely would say avoid it if you can.
1218
01:45:44.245 --> 01:45:47.145
But if you need the other device for some reason,
1219
01:45:47.900 --> 01:46:10.980
stick to a very minimal approach. So you can take, like, with my iPhone, the only things I have in there, like, the very required work apps and then a couple apps that I don't want on my main personal phone, but that I need sometimes. And so I'm able to keep them on there. I just keep them closed. I don't use them most of the time, but they're available if I have to. So just stick to that digital minimalism idea when when doing that is kinda my take, but any thoughts around that, Matt?
1220
01:46:12.905 --> 01:46:20.445
1221
01:46:23.490 --> 01:46:25.430
You know, there's there's additional
1222
01:46:26.210 --> 01:46:27.110
nuance here
1223
01:46:28.345 --> 01:46:30.925
with your carrier. So so, obviously,
1224
01:46:31.545 --> 01:46:34.045
whether or not you're using Kallix or iPhone
1225
01:46:34.985 --> 01:46:35.485
or
1226
01:46:35.980 --> 01:46:36.800
stock Android
1227
01:46:37.420 --> 01:46:39.280
or Samsung stock or whatever,
1228
01:46:39.820 --> 01:46:42.400
you should have that little toggle that says location
1229
01:46:42.860 --> 01:46:44.560
toggled off for 99%
1230
01:46:45.100 --> 01:46:51.105
of your time. If you absolutely need to use it, enable it when you're using it, and then disable it.
1231
01:46:51.965 --> 01:46:54.785
But that is specifically for GPS location.
1232
01:46:56.860 --> 01:47:02.540
There's also a method of tracking location that is done via carrier triangulate
1233
01:47:03.020 --> 01:47:03.520
triangulation,
1234
01:47:04.355 --> 01:47:05.095
which is
1235
01:47:06.995 --> 01:47:14.650
they take your your 3 closest towers, and they basically measure the distance from those 3 three towers. And you can imagine it kind of like
1236
01:47:15.030 --> 01:47:17.130
a Venn diagram, but with 3 circles.
1237
01:47:17.510 --> 01:47:21.690
And they're able to relatively closely pinpoint your location
1238
01:47:23.494 --> 01:47:28.954
based on that data alone without GPS. GPS will give them a very, very accurate location,
1239
01:47:29.660 --> 01:47:35.920
and might be harvested by apps that provide them to marketers, which then that data gets shared and leaked. And
1240
01:47:36.300 --> 01:47:44.215
sometimes I we've even seen the feds, they'll get around warrants because they'll just buy that data. But, also, they're especially among the major carriers,
1241
01:47:45.074 --> 01:47:48.055
the AT and T, the Verizons of the world, the T Mobiles,
1242
01:47:48.590 --> 01:47:50.770
they also monetize by selling
1243
01:47:51.150 --> 01:47:51.969
that triangulation
1244
01:47:52.350 --> 01:47:52.750
data.
1245
01:47:54.750 --> 01:47:56.690
And if I if I remember correctly,
1246
01:47:57.474 --> 01:47:58.295
that data,
1247
01:47:59.315 --> 01:48:02.695
they they when they sell it to to marketers, they they
1248
01:48:03.074 --> 01:48:05.655
they call it anonymized location data,
1249
01:48:05.980 --> 01:48:09.599
but there's no such thing as anonymized location data. Because if
1250
01:48:09.900 --> 01:48:11.360
if you're traveling between
1251
01:48:11.900 --> 01:48:16.824
your work and your home on a constant basis, then, obviously, you work at that place and
1252
01:48:17.685 --> 01:48:21.784
you live at that place. And we saw a case where I believe The New York Times
1253
01:48:22.489 --> 01:48:24.269
used so called anonymized
1254
01:48:25.369 --> 01:48:35.265
location data, and they basically tracked a secret service agent, and they were able to see where he lives. And that was because the location data basically showed him traveling around with the president and then going back home.
1255
01:48:36.445 --> 01:48:37.975
So if you're using a
1256
01:48:39.480 --> 01:48:41.739
if you have a second device, you're adding
1257
01:48:43.000 --> 01:48:49.074
you're you're adding that element of additional data that is being taken. So how do you reduce
1258
01:48:50.335 --> 01:48:55.554
that data from being taken from your your your privacy focused phone?
1259
01:48:56.060 --> 01:49:00.960
And in that case, the trade off becomes even greater in terms of convenience because
1260
01:49:01.500 --> 01:49:03.200
you basically end up in a situation
1261
01:49:03.660 --> 01:49:04.160
where
1262
01:49:04.574 --> 01:49:07.155
you have to basically get prepaid SIM cards.
1263
01:49:07.455 --> 01:49:09.635
Whether or not you pay with Bitcoin or you
1264
01:49:10.094 --> 01:49:16.010
or you pay with cash, you have to attempt to get prepaid SIM cards that are not attached to your identity.
1265
01:49:16.949 --> 01:49:17.690
And there's
1266
01:49:18.389 --> 01:49:26.285
there's a great service that works Kallix but not Graphene, because Graphene doesn't support esims, called silent dot link, which accepts Bitcoin,
1267
01:49:26.985 --> 01:49:35.120
and they'll give you an eSIM, which is instead of that little SIM card that you put in your device, which is how it the carrier recognizes it,
1268
01:49:35.755 --> 01:49:36.735
It gives you
1269
01:49:37.355 --> 01:49:41.054
a digital version that is super easy to load onto the device.
1270
01:49:42.770 --> 01:49:43.910
My boy, Ketamineer,
1271
01:49:44.690 --> 01:49:45.430
who has
1272
01:49:46.130 --> 01:49:48.950
a telco background, says that there's also
1273
01:49:49.965 --> 01:49:53.105
certain device data that gets transferred to your carrier.
1274
01:49:53.645 --> 01:49:54.145
So
1275
01:49:54.845 --> 01:49:56.945
rotating your SIMs isn't necessarily
1276
01:49:57.245 --> 01:49:57.745
enough
1277
01:49:59.210 --> 01:50:03.070
if you, you know, you switch between prepaid carriers, and
1278
01:50:03.530 --> 01:50:06.190
that data can also connect back to you.
1279
01:50:06.875 --> 01:50:08.975
But once again, as we went back earlier,
1280
01:50:09.995 --> 01:50:13.935
you know, you can't let perfect be the enemy of good, and you're
1281
01:50:14.720 --> 01:50:17.700
taking small steps to improve your privacy
1282
01:50:18.720 --> 01:50:23.700
surface or your your attack surface on the privacy side and mass collection of data
1283
01:50:24.305 --> 01:50:24.965
are tangibly
1284
01:50:25.265 --> 01:50:29.765
better for you. You you wanna just try and reduce that exposure as much as possible.
1285
01:50:31.025 --> 01:50:34.350
1286
01:50:34.810 --> 01:50:36.030
don't let talk about
1287
01:50:36.410 --> 01:50:37.550
cell tower triangulation
1288
01:50:37.930 --> 01:50:40.750
scare you out of making actionable steps towards privacy.
1289
01:50:41.130 --> 01:50:42.510
I mean, that it's definitely
1290
01:50:43.225 --> 01:50:54.320
that is a concern, and it's something you can't really get around. I mean, if your device is connected to cell signal, you your location is being triangulated. And that is either to collect the location or it's being used to help you
1291
01:50:54.780 --> 01:50:59.760
accurately and efficiently jump between cell towers for for getting good cell signals. So
1292
01:51:00.185 --> 01:51:03.725
that is unfortunately one of the things of having mobile data.
1293
01:51:04.505 --> 01:51:05.485
If you really
1294
01:51:05.864 --> 01:51:12.460
want to worry about that more, you could use airplane mode when you absolutely don't need mobile data, which probably not a bad idea at all.
1295
01:51:13.579 --> 01:51:17.840
Like you mentioned as well, there is a unique device identifier. It's called an I IMEI.
1296
01:51:18.645 --> 01:51:23.864
Probably heard people talk about it before, but that that unique identifier is new to is specific to your phone,
1297
01:51:24.645 --> 01:51:29.570
and no other. So even if you are swapping between carriers, that data could be
1298
01:51:30.030 --> 01:51:35.995
correlated between. But I think a a good thing to think about here and something we haven't really talked about too much today,
1299
01:51:36.295 --> 01:51:36.775
but,
1300
01:51:37.415 --> 01:51:43.275
you have to think about threat models. And most people's threat model and, like, my threat model is mostly,
1301
01:51:43.790 --> 01:52:07.170
it's getting a little different as we kinda see things shift in society. But, mostly, my threat model is I want to make sure that when companies and governments are just mass collecting data and seeing what interesting things they find, I don't show up or I don't easily stand out, and my data is not easily correlated across companies, across governments, that kind of thing. And for for people who have that type of threat model, which I really think is most people,
1302
01:52:08.110 --> 01:52:09.810
using something like Kallix OS
1303
01:52:10.435 --> 01:52:33.155
will get you most of the way there. And using some of these apps we've been talking about and tools we've been talking about, and you you probably don't need to worry about cell tower triangulation because that is gonna be very targeted. They're gonna need to say, like, hey. I wanna find out where Seth is. We don't have GPS because he doesn't use that. We don't have all of this data because he uses calyx, but we can use cell tower triangulation to try to track him down. And, like, that is a legitimate concern, but
1304
01:52:33.935 --> 01:52:39.760
I 1, that's a really hard thing to shut down, and 2, I don't think that I would be targeted in that way at the moment.
1305
01:52:40.700 --> 01:52:52.275
So that can be it can be a tricky one to get around, but definitely do not let perfect be the enemy of good. Like, take the steps. The more you're reducing that, the also, the more you're reducing the data that can be easily correlated between
1306
01:52:52.870 --> 01:53:02.409
your location and other things that you do. Like, if you're using private messaging apps, it's not gonna be easy for them to correlate the person that you're meeting up with and you being there at the same time,
1307
01:53:03.465 --> 01:53:12.045
at least not as easy. Or if you're not using social media and sharing where you're at each time, they may not even they may not go to the the lengths to dig into cell tower data
1308
01:53:12.370 --> 01:53:13.489
to find where you are.
1309
01:53:13.969 --> 01:53:19.110
So it it really you can protect yourself from Dragonet surveillance. And if you have a very targeted threat model,
1310
01:53:19.485 --> 01:53:24.864
you have other concerns, so that's a different conversation. But for most people, you don't really need to worry about that if we're honest.
1311
01:53:25.244 --> 01:53:36.630
But think about your threat model. Look up how to build a threat model. The EFF has a really great resource on that. Try to figure out what you're trying to protect, what you're trying to protect against, and what lengths you'll go to to do that,
1312
01:53:37.235 --> 01:53:41.414
and see if something like worrying about cell tower triangulation is is a concern of yours.
1313
01:53:42.195 --> 01:53:44.855
But there are there are some good carriers. You can also get
1314
01:53:45.270 --> 01:53:47.210
non, like, personally identifiable
1315
01:53:47.670 --> 01:53:56.915
SIM cards and data through. Mint Mobile is one that a lot of people talk about in the US. You can get prepaid Mint Mobile cards with cash without giving any personal information over.
1316
01:53:57.295 --> 01:54:05.450
And if you did buy your phone secondhand or if you bought it without giving away real name and address and everything, the IMEI for your phone is not tied to your identity
1317
01:54:05.910 --> 01:54:11.430
either. So it'd be it'd be much more difficult for them to correlate that the IMEI, which is yours, is connected to the,
1318
01:54:12.835 --> 01:54:17.735
Mint Mobile account, which is yours, when neither of those things have personally identifiable information attached.
1319
01:54:20.969 --> 01:54:25.550
1320
01:54:27.715 --> 01:54:30.935
in the hole that, oh, I'm just fucked regardless.
1321
01:54:31.635 --> 01:54:34.375
And I think it's really important to just constantly
1322
01:54:34.835 --> 01:54:35.335
reiterate
1323
01:54:35.980 --> 01:54:36.480
that
1324
01:54:39.980 --> 01:54:40.480
1325
01:54:41.020 --> 01:54:46.585
1326
01:54:47.125 --> 01:54:49.224
simple steps on a constant basis
1327
01:54:49.525 --> 01:54:50.824
to consistently improve
1328
01:54:51.125 --> 01:54:52.985
your privacy and and
1329
01:54:53.364 --> 01:54:56.730
and what your, like, your surface area is in terms of,
1330
01:54:57.510 --> 01:55:01.210
how much data you're leaking on a daily basis because most of us are
1331
01:55:02.045 --> 01:55:08.304
leaking a ton of data. Like, I, you know, I we get down in the weeds on the show, and then you do an opt out pod.
1332
01:55:09.820 --> 01:55:19.360
But simple things, you know, stop using Gmail. Stop you know, don't don't have an Alexa in your home that's just constantly running a microphone connected to the Internet.
1333
01:55:20.605 --> 01:55:21.905
Just simple steps,
1334
01:55:22.605 --> 01:55:23.905
to improve your privacy.
1335
01:55:24.685 --> 01:55:51.370
1336
01:55:51.785 --> 01:55:54.365
and I don't think personal privacy is impossible or unattainable,
1337
01:55:54.825 --> 01:55:59.965
I do not think that. But if somehow that turned out to be the case, that all the steps that I've taken have been pointless,
1338
01:56:00.800 --> 01:56:07.700
I wouldn't really care. I would be happy that I had done everything that I could. Like, that it wasn't because of my laziness or because of my,
1339
01:56:08.720 --> 01:56:09.460
poor choices
1340
01:56:09.760 --> 01:56:10.260
that
1341
01:56:10.645 --> 01:56:20.230
I suffered in the end or that something changed in the end, but that I would be one of the ones who stood up, who chose to fight, who chose to put in the time, and who chose to educate other people around me and try to pull them into it.
1342
01:56:20.790 --> 01:56:23.050
And I really think that that's a worst case scenario.
1343
01:56:23.350 --> 01:56:34.315
And I think the more realistic scenario is we're we're gonna keep pulling in more and more people. We're gonna make it difficult enough on them that they're gonna have to start changing the way they do things and not relying on people just willingly giving away troves of data.
1344
01:56:35.950 --> 01:56:40.130
1345
01:56:40.750 --> 01:56:44.930
that there was no such thing as an anonymized location data,
1346
01:56:46.665 --> 01:56:51.705
and that their carriers are tracking all this stuff and selling it to marketers, there'd be public outrage. And,
1347
01:56:52.610 --> 01:56:58.150
maybe, unfortunately, a lot of people will have to be burned in the in the meantime for that
1348
01:56:58.450 --> 01:57:00.950
to become more aware publicly aware.
1349
01:57:02.055 --> 01:57:08.315
But I I do have optimism that as people do get burned, there will be more public outcry and people will push,
1350
01:57:08.775 --> 01:57:10.715
for these things to not be so normalized.
1351
01:57:11.720 --> 01:57:15.100
We have a great question from Crypto Grampy in the audience,
1352
01:57:16.440 --> 01:57:21.705
asking, is there any benefit to blending in with some of this stuff? I hear this a lot. You know,
1353
01:57:23.045 --> 01:57:26.905
Calyxt is a privacy focused OS. Graphene's a privacy focused OS.
1354
01:57:27.349 --> 01:57:28.170
Are we putting,
1355
01:57:29.909 --> 01:57:32.250
a target on our backs, or or
1356
01:57:32.789 --> 01:57:34.329
or or basically
1357
01:57:35.954 --> 01:57:39.574
adding risk by seeking out privacy focused solutions?
1358
01:57:42.434 --> 01:57:44.054
1359
01:57:45.160 --> 01:57:51.100
It's one that I've started thinking about a bit more lately, but it's still kind of, I don't know, still kinda mulling over it.
1360
01:57:52.835 --> 01:57:53.495
I think
1361
01:57:54.114 --> 01:57:55.815
there certainly could be a benefit,
1362
01:57:58.355 --> 01:58:09.409
but I think the benefit that that could provide in almost all cases outweighs the risk of giving over data that just makes it easier for them to do what they wanna do. I mean, I definitely think they could use
1363
01:58:10.165 --> 01:58:23.150
like, our government could use a list of people who, for some reason, do not show up with KYC cell phone numbers and do not show up with Google accounts that are tied to their real identity and stuff like that and use that as a list to start targeting people.
1364
01:58:25.265 --> 01:58:29.365
But I think kind of 2 two responses to that. One of them is
1365
01:58:29.985 --> 01:58:36.230
if they do that, it's gonna be hard for them to actually collect the data that they need to make that realistic. So, yes, they have a list of
1366
01:58:36.770 --> 01:58:41.590
people or a a group of identities that they don't have an identity for that they need to go track down.
1367
01:58:42.475 --> 01:58:43.295
And so that's
1368
01:58:43.755 --> 01:58:47.455
complicated by the steps that you've taken. And the other answer would be,
1369
01:58:47.755 --> 01:58:51.375
I think a much better thing to do than blending in is increasing the
1370
01:58:51.740 --> 01:59:05.005
the crowd that you get to hide in. And the way that we do that is through education, through building better tools, through funding better tools, through, pulling in friends and family by regularly talking to them about the steps that we're taking towards personal privacy,
1371
01:59:05.465 --> 01:59:13.800
making it personal, making it about the the specific things that you see that they need or want out of maybe a mobile phone or an application and and crafting
1372
01:59:14.739 --> 01:59:18.840
the crafting the message that we have about privacy for them specifically. But,
1373
01:59:19.295 --> 01:59:26.995
really, the best way to not have to worry about blending in is to blend in with a crowd of people who are growing rapidly that care about personal privacy,
1374
01:59:27.340 --> 01:59:32.559
that are installing mobile operating systems like Kallax or Graphene, that are using tools like Bitcoin and Monero.
1375
01:59:32.860 --> 01:59:37.255
And the more people we're able to to bring into using those tools and using them effectively,
1376
01:59:38.034 --> 01:59:53.305
we end up blending into a crowd of people who are private. And those that crowd of people who are private all provide good privacy to each other because now there's less and less data between the whole group, and you're all using similar tools that are privacy preserving that they can't actually just collect data from simply or subpoena data from, and
1377
01:59:53.685 --> 01:59:56.025
you end up in a much better world that way,
1378
01:59:56.725 --> 02:00:05.020
I think, than if you try to blend in in some ways while keeping some things private. I also think it it would just be really difficult in real life to
1379
02:00:05.560 --> 02:00:06.700
blend in effectively
1380
02:00:07.160 --> 02:00:07.660
without
1381
02:00:08.565 --> 02:00:11.305
connecting the dots between your blended in personality
1382
02:00:11.685 --> 02:00:13.305
and your private personality,
1383
02:00:14.485 --> 02:00:18.025
especially, like, we were talking about the 2 phone idea. If if 2 phones,
1384
02:00:18.710 --> 02:00:21.530
let's say you're let's say you're using Kallax OS,
1385
02:00:22.310 --> 02:00:25.690
but you're not using a VPN when you're walking around,
1386
02:00:26.094 --> 02:00:31.395
and you're using some service that that IP address is logged. Maybe it's not logged in a a malicious way, but it's there,
1387
02:00:31.855 --> 02:00:36.650
and they're able to use or let's just forget the IP address, actually. Let's say you're they're using cell tower triangulation,
1388
02:00:37.350 --> 02:00:43.975
and maybe you didn't purchase your cell plan for your your Calix OS without giving up your identity,
1389
02:00:44.435 --> 02:00:45.575
and then they see
1390
02:00:45.955 --> 02:00:46.455
your
1391
02:00:47.155 --> 02:00:52.550
non private phone walking around. These two devices are always hand in hand. They're always together.
1392
02:00:53.250 --> 02:01:05.605
They're gonna be able to tie pieces of data together that maybe they're getting from Calix from your Calix OS install, maybe some things that you're doing on there, maybe you're still using the Twitter app rather than using the mobile app, and and some data is getting out of there that,
1393
02:01:06.065 --> 02:01:17.060
they can use to to do that. All all that's kind of, like, just conceptual, but just that idea that if you do try to kind of blend in halfway while opting out halfway, it can be really hard to keep those two lives separate. So it can be tricky.
1394
02:01:17.785 --> 02:01:21.165
1395
02:01:22.425 --> 02:01:25.325
in terms of of basically trying to
1396
02:01:26.300 --> 02:01:29.280
increase the anonymity set of these services,
1397
02:01:29.739 --> 02:01:31.920
increase the adoption and use of these services
1398
02:01:32.780 --> 02:01:36.025
so that you don't have that issue when you're using them.
1399
02:01:36.565 --> 02:01:44.989
I think I can speak for both of us. I I mean, that's why I do dispatch. That's why I'm so outspoken on Twitter. I think that's why you do opt out pod.
1400
02:01:45.690 --> 02:01:49.790
I think that's why we're doing this show right now. I mean, we need more people using Kallix
1401
02:01:51.945 --> 02:01:55.485
so that you don't have that that concern as much.
1402
02:01:56.025 --> 02:01:57.165
That is not just
1403
02:01:57.465 --> 02:01:59.325
necessarily a privacy tool.
1404
02:02:00.410 --> 02:02:05.290
It does give me better performance and better battery life than if I was running stock,
1405
02:02:05.610 --> 02:02:06.110
1406
02:02:07.635 --> 02:02:15.815
on my Pixel. Like, significantly better battery life. Like, Pixels have historically I've had a horrible battery life. But because this thing's not hitting Google all the time,
1407
02:02:16.900 --> 02:02:20.040
my battery life competes with, you know, brand new iPhones,
1408
02:02:20.820 --> 02:02:21.960
which is pretty unbelievable.
1409
02:02:22.420 --> 02:02:32.445
1410
02:02:32.900 --> 02:02:43.764
and it still had tons of battery, like 80% or something. And he had used it a good bit throughout that, but it really does help with battery life. And a perfect example of that is signal. In the beginning of signal usage,
1411
02:02:44.545 --> 02:02:45.364
1412
02:02:45.665 --> 02:02:47.925
if you were able to get a list of
1413
02:02:48.680 --> 02:02:50.460
phone numbers that were using signal,
1414
02:02:50.920 --> 02:02:55.180
you could pretty much assume that they were all privacy focused individuals.
1415
02:02:56.114 --> 02:02:57.974
But now it's starting to hit the mainstream
1416
02:02:58.275 --> 02:03:00.534
where, you know, my grandmother uses signal,
1417
02:03:01.474 --> 02:03:08.840
and her friends use signal. And and it does have features that are better than if you were just using a text message besides just privacy.
1418
02:03:09.220 --> 02:03:13.320
And we've seen success with it that and I think it's a very good example
1419
02:03:15.165 --> 02:03:23.905
of of, basically, what we wanna see with some of these privacy tools is is to them get some level of mainstream adoption so you don't have as much of that,
1420
02:03:26.040 --> 02:03:31.740
you know, that that risk of basically just you using it becomes suspicious. Not that it should be suspicious,
1421
02:03:32.175 --> 02:03:37.875
but, obviously, that that is going to be the case a lot of times when you're first starting, these types of projects.
1422
02:03:38.975 --> 02:03:41.875
We had Jack Sparrow in the chat ask
1423
02:03:42.320 --> 02:03:45.300
if he was to use Gmail on Kallix,
1424
02:03:46.080 --> 02:03:49.120
would he be better off using it in browser? Yes. Just in general
1425
02:03:49.865 --> 02:03:52.125
mean, you shouldn't use Gmail, but just in general,
1426
02:03:54.265 --> 02:03:57.965
using a browser based version is is strictly better.
1427
02:04:00.280 --> 02:04:03.500
And and if if you have to use it, that's how you should use it.
1428
02:04:04.119 --> 02:04:05.500
Seth, you mentioned Defcon.
1429
02:04:07.375 --> 02:04:10.114
You were there this weekend. How how was how was that?
1430
02:04:10.415 --> 02:04:13.875
Do you have any insight there? What was that experience like? I've never been.
1431
02:04:14.960 --> 02:04:17.300
1432
02:04:18.560 --> 02:04:19.060
They
1433
02:04:19.600 --> 02:04:23.280
changed a lot of things this year. I think they've kind of
1434
02:04:24.135 --> 02:04:31.220
I don't know. This might be a little divisive, but they bit the knee a little bit and forced people to provide personally identifiable information to get in.
1435
02:04:31.700 --> 02:04:36.920
They also did not make it clear that they accepted cash at the door, which has been like a Defcon thing forever,
1436
02:04:37.300 --> 02:04:38.600
and they instead did preregistration
1437
02:04:39.060 --> 02:04:40.120
via credit card.
1438
02:04:41.125 --> 02:04:44.665
So there were a lot of bad changes, but it was the 1st year I was able to go.
1439
02:04:46.565 --> 02:04:51.040
And there were a a there's a a large contingent of the Monera community going there,
1440
02:04:51.500 --> 02:04:55.200
which I've been wanting to get together with with a lot of those people for quite a while.
1441
02:04:56.055 --> 02:05:03.115
And, actually, the Monero people put on, along with the help of a couple other projects, but it was mostly driven by the Monero people, they put on a
1442
02:05:03.600 --> 02:05:10.820
cryptocurrency village, which normally there has been a Monero village itself in the previous years. But since this DevCon was much smaller,
1443
02:05:11.199 --> 02:05:13.345
they capped it to, like, a third of of the normal
1444
02:05:13.805 --> 02:05:16.065
size, and I'm not sure if they even hit that. So
1445
02:05:16.365 --> 02:05:18.525
it was a very different year for sure, but,
1446
02:05:19.325 --> 02:05:22.385
we were still able to put on that cryptocurrency village. I
1447
02:05:23.230 --> 02:05:26.449
may or may not have attended with or without a ticket,
1448
02:05:27.469 --> 02:05:29.170
and and actually helped out.
1449
02:05:29.925 --> 02:05:34.985
But we had the the cryptocurrency village there. It was it was cool to see a lot of people come in from
1450
02:05:35.365 --> 02:05:38.345
the DEFCON crowd that may or may not be familiar with cryptocurrency.
1451
02:05:40.660 --> 02:05:41.720
There was actually a much larger contingent than I expected
1452
02:05:42.420 --> 02:05:46.280
that didn't really know anything past, like, very basics about Bitcoin
1453
02:05:46.705 --> 02:05:49.125
and really just kinda the number go upside of Bitcoin.
1454
02:05:50.465 --> 02:05:53.285
There were a couple people that I talked to who had a a deeper understanding.
1455
02:05:53.950 --> 02:06:02.290
Obviously, my focus there was on Monero, but it was the cryptocurrency village. So I I try to just kinda be generic unless someone specifically asked about Monero stuff, but
1456
02:06:03.014 --> 02:06:08.875
had a lot of really good conversations, a lot of, obviously, privacy loving people. So there was there was good stuff around that.
1457
02:06:09.850 --> 02:06:16.190
We put on a few talks also, mostly focused on cryptocurrency privacy and some some research that's gone into
1458
02:06:16.650 --> 02:06:25.074
to scaling and privacy protocols from a a researcher who's, who has done research for Monero in the past and and is now doing research for other projects in addition to Monero.
1459
02:06:26.300 --> 02:06:32.320
But it it ended up being a good time. I mean, my focus was hanging out with Monero people, getting to know a little bit more of the the community,
1460
02:06:32.700 --> 02:06:34.460
getting a little a little closer to them, but,
1461
02:06:35.355 --> 02:06:44.495
I was able to to get into to DEFCON for a bit and and see it. I I didn't leave the cryptocurrency village, though. I didn't go to any of the other sections or talks or anything like that.
1462
02:06:44.900 --> 02:06:47.720
So I have a I had a very limited view of DEFCON, but,
1463
02:06:48.740 --> 02:06:54.815
the parts that I did see within the cryptocurrency village were were really good. It was it was a good time getting to to meet some of the people there. And,
1464
02:06:55.595 --> 02:07:02.199
honestly, just to show cryptocurrency and privacy to people, that's not something it really specifically Bitcoin and Monero to people,
1465
02:07:03.619 --> 02:07:12.125
and have those kind of face to face discussions with a lot of people who aren't as familiar with Bitcoin and Monero as the people that I regularly interact with on on Twitter or in chat rooms.
1466
02:07:13.065 --> 02:07:19.360
So definitely still good. Sad to see some of the changes that DEFCON has chosen to make to kinda bend to to social pressure,
1467
02:07:19.980 --> 02:07:21.440
and even to go way above
1468
02:07:22.619 --> 02:07:24.400
restrictions that are put in place, but,
1469
02:07:24.965 --> 02:07:33.864
that can be a that can be a discussion for another day. But, overall, a good time. Some awesome people, that came out from the Monero community. Many of them are also part of the Bitcoin community.
1470
02:07:34.590 --> 02:07:37.489
If you're active in Samurai Circle, some of the people there are active there.
1471
02:07:38.510 --> 02:07:42.205
There's a lot of crossover between privacy focused Bitcoiners
1472
02:07:42.824 --> 02:07:44.285
and Monero users.
1473
02:07:44.905 --> 02:07:48.844
So it was great to hang out with them, get to chat a little bit more, kinda,
1474
02:07:49.864 --> 02:07:51.470
yeah, just just a really good time.
1475
02:07:52.430 --> 02:07:54.190
1476
02:07:54.990 --> 02:08:01.170
since you mentioned it, I mean, I'm pretty sure they use COVID as the excuse for the additional information collection.
1477
02:08:02.335 --> 02:08:04.915
1478
02:08:05.535 --> 02:08:08.195
1479
02:08:10.040 --> 02:08:14.540
It's a troubling trend in general, but especially when you start seeing privacy focused
1480
02:08:17.215 --> 02:08:18.095
organizations and events,
1481
02:08:19.375 --> 02:08:21.235
kind of bend the knee to that.
1482
02:08:22.655 --> 02:08:24.595
It's not a good trend.
1483
02:08:24.940 --> 02:08:29.199
1484
02:08:29.579 --> 02:08:33.670
but it was, like, when things were much more restricted and locked down because of COVID and,
1485
02:08:34.655 --> 02:08:48.280
whatever you think about that, whatever, but for other people listening. But, things opened back up. Vaccine was out. Everybody was feeling fine, and then DEFCON did not reduce any of the restrictions even though they were way above CDC recommendations,
1486
02:08:48.580 --> 02:08:50.600
local requirements, anything like that.
1487
02:08:51.585 --> 02:08:54.885
And when I saw that, when they kind of reiterated their stance,
1488
02:08:55.265 --> 02:08:59.050
I reached out and and chatted with them to try to figure out if there was any
1489
02:09:01.610 --> 02:09:08.429
kind of workarounds there or anything I could do. And, essentially, their answer and this person wasn't necessarily speaking for all of Defcon, but I think it was a good window into
1490
02:09:09.355 --> 02:09:11.615
what has become of what used to be a countercultural
1491
02:09:12.155 --> 02:09:12.655
hacker
1492
02:09:13.035 --> 02:09:14.095
privacy focused,
1493
02:09:15.595 --> 02:09:23.440
conference. The the response I got from the person who worked for Defcon, and he was the person responding to me in my support case, was essentially that
1494
02:09:24.045 --> 02:09:35.600
because I don't have a reasonable expectation of privacy outside of the conference in Vegas because there's cameras everywhere, that kind of thing, that they have no problems with requesting personally identifiable information to get into the conference,
1495
02:09:36.540 --> 02:09:37.840
which I think is just
1496
02:09:38.665 --> 02:09:46.045
absolutely nuts and an awful response to hear from a a conference like that. And, again, that may that may not line up with the actual people who, like, are
1497
02:09:46.460 --> 02:09:50.320
creating and running the conference, but that was the official response that I got,
1498
02:09:50.699 --> 02:09:55.895
which was a little bit terrifying. I'm not I think I think took away a bit of my interest in going to future DevCons.
1499
02:09:56.915 --> 02:10:01.735
But regardless, there was still a big crowd there, so it was good to have a presence and good to have,
1500
02:10:02.310 --> 02:10:04.650
just some some good discussions throughout anyways.
1501
02:10:05.910 --> 02:10:07.930
1502
02:10:09.355 --> 02:10:15.775
it's a worrying trend. I do feel like I I wonder if it's just my bias showing, but I do feel like there's just
1503
02:10:18.440 --> 02:10:20.780
just an increasing trend of
1504
02:10:22.120 --> 02:10:23.580
anti privacy aggression,
1505
02:10:24.280 --> 02:10:27.705
around the world right now coming from a 1000000 different sources,
1506
02:10:29.605 --> 02:10:34.585
and it's more important than ever for people to stand up and say no and
1507
02:10:34.900 --> 02:10:40.440
and care about their privacy, care about their sovereignty, and help educate friends and family
1508
02:10:41.060 --> 02:10:42.200
the same, and
1509
02:10:43.495 --> 02:10:46.635
and and the the movement is more important than ever right now,
1510
02:10:47.255 --> 02:10:50.395
I think, but maybe I also will acknowledge
1511
02:10:50.740 --> 02:10:53.240
that it could partially be my own bias.
1512
02:10:54.260 --> 02:10:57.320
But it does definitely feel like a a worrying trend.
1513
02:10:58.805 --> 02:11:03.305
Seth, I mean, this has been an absolutely great conversation. I know you're tired from traveling.
1514
02:11:04.005 --> 02:11:07.705
We've been talking for over 2 hours now. I really appreciate your time.
1515
02:11:08.940 --> 02:11:12.480
Do you have anything that you wanna cover before we wrap this up?
1516
02:11:15.260 --> 02:11:17.520
1517
02:11:17.885 --> 02:11:19.585
major topics. I would just say,
1518
02:11:20.685 --> 02:11:26.430
like, I'm not I'm not making this about Calix OS or First Graphene OS, that kind of thing. I know there's a lot of issues
1519
02:11:26.969 --> 02:11:32.830
and just conflicts between them. I've had some run ins with the Graphene OS crowd that have been quite hostile, but
1520
02:11:33.645 --> 02:11:40.225
I think what I will just kinda say to sum up what you've been chatting about is definitely take the steps to to dig into mobile privacy.
1521
02:11:41.005 --> 02:11:42.145
Try out both
1522
02:11:42.890 --> 02:11:45.130
Kallix OS and Graphene OS if you have the time.
1523
02:11:45.850 --> 02:11:48.750
If you're focused on usability, jump into Kallix OS.
1524
02:11:49.050 --> 02:11:50.670
If you feel you have a
1525
02:11:51.370 --> 02:11:52.120
a more
1526
02:11:52.865 --> 02:11:56.565
aggressive threat model or a more, kind of high level threat model,
1527
02:11:57.105 --> 02:12:01.845
maybe go for GrapheneOS. It should be a little bit more secure in some ways.
1528
02:12:02.170 --> 02:12:05.310
Privacy is kind of they kinda trade blows there, but,
1529
02:12:06.090 --> 02:12:07.630
find the tool that works for you.
1530
02:12:08.010 --> 02:12:11.535
For me, that's Calix OS. Like Matt said, for him, that's Calix OS.
1531
02:12:12.015 --> 02:12:13.155
So, I mean, I
1532
02:12:14.175 --> 02:12:21.280
I definitely do personally show Calix OS, but Graphion OS can be a great tool too, no matter what drama is going out around that.
1533
02:12:23.840 --> 02:12:29.460
1534
02:12:29.985 --> 02:12:33.125
and it's very easy to switch between them. It's also,
1535
02:12:34.305 --> 02:12:52.965
Google is, I think, relatively unique in that they actually provide images for stock Android as well. So you can you can literally take your your Pixel device, you can flash Graphene on it, you could try it out, you can flash Kallax on it. And if you still disagree with both of us that it's a better experience,
1536
02:12:53.425 --> 02:12:55.925
even if privacy is not necessarily the concern,
1537
02:12:56.420 --> 02:12:57.860
you can then go and,
1538
02:12:58.980 --> 02:12:59.480
flash
1539
02:13:01.460 --> 02:13:03.735
flash stock Android onto it,
1540
02:13:04.295 --> 02:13:08.155
back onto it and go back into the Google universe so you don't have that issue.
1541
02:13:11.255 --> 02:13:15.590
We have we have Monero Lyon, bringing up the Monero question,
1542
02:13:16.690 --> 02:13:18.870
which is not a surprise given his name.
1543
02:13:21.785 --> 02:13:22.285
So
1544
02:13:22.905 --> 02:13:29.885
do we wanna have a brief discussion on our views of Monero? And, I guess he's he's specifically asking about usefulness.
1545
02:13:30.949 --> 02:13:36.730
I mean, I think we all know where you stand here. I mean, you you started as as pretty much
1546
02:13:38.635 --> 02:13:43.295
a fully focused Bitcoiner, and you seem to have moved on more towards Monero
1547
02:13:45.595 --> 02:13:47.695
due to the privacy focus of Monero.
1548
02:13:48.560 --> 02:13:50.260
I think I am often,
1549
02:13:51.280 --> 02:13:51.780
mischaracterized
1550
02:13:53.040 --> 02:13:54.660
in how I view Monero.
1551
02:13:55.895 --> 02:13:57.115
I've been very consistent
1552
02:13:57.495 --> 02:13:59.835
in that. I do believe that it is useful
1553
02:14:00.855 --> 02:14:01.355
if
1554
02:14:02.455 --> 02:14:05.219
if if you want transactional privacy today,
1555
02:14:06.239 --> 02:14:09.860
there's a lot less gotchas than if you're using Bitcoin.
1556
02:14:10.800 --> 02:14:11.460
I think
1557
02:14:12.595 --> 02:14:18.135
the tools around using Bitcoin privately have improved tremendously, and I expect them to continue to improve.
1558
02:14:20.435 --> 02:14:20.935
But
1559
02:14:22.470 --> 02:14:24.870
I I do not I I do not,
1560
02:14:25.750 --> 02:14:27.770
disagree that Monero is useful.
1561
02:14:30.145 --> 02:14:31.045
My belief,
1562
02:14:31.425 --> 02:14:32.325
though, is
1563
02:14:33.505 --> 02:14:34.805
that long term,
1564
02:14:37.265 --> 02:14:38.885
you will be better off holding
1565
02:14:40.460 --> 02:14:41.680
Bitcoin than Monero
1566
02:14:42.060 --> 02:14:43.120
in terms of,
1567
02:14:45.420 --> 02:14:47.680
purchasing power, in terms of how much
1568
02:14:50.574 --> 02:14:54.435
to in terms of holding your purchasing power and your purchasing power increasing
1569
02:14:54.980 --> 02:14:56.360
for your everyday expenses.
1570
02:14:57.460 --> 02:14:58.440
And I don't
1571
02:14:58.900 --> 02:14:59.639
I I
1572
02:15:01.219 --> 02:15:02.840
where I tend to disagree
1573
02:15:04.475 --> 02:15:04.975
with
1574
02:15:05.835 --> 02:15:06.895
people who think
1575
02:15:07.195 --> 02:15:08.815
that Monero is
1576
02:15:09.115 --> 02:15:10.735
strictly better than Bitcoin
1577
02:15:11.489 --> 02:15:13.909
is that it's kind of a
1578
02:15:15.250 --> 02:15:18.550
damned if you do, damned if you don't on the Monero side because
1579
02:15:19.514 --> 02:15:20.895
there's a strong focus
1580
02:15:21.755 --> 02:15:25.454
to make it easy to swap between Monero and Bitcoin.
1581
02:15:26.235 --> 02:15:28.094
And as long as that is the case,
1582
02:15:29.380 --> 02:15:32.840
there is no real incentive for someone to hold Monero
1583
02:15:33.220 --> 02:15:34.360
when they can just
1584
02:15:35.460 --> 02:15:36.360
switch into
1585
02:15:36.735 --> 02:15:38.275
Monero for short term,
1586
02:15:38.815 --> 02:15:39.315
transactional
1587
02:15:39.615 --> 02:15:40.115
privacy
1588
02:15:40.495 --> 02:15:44.035
and then swap back into Bitcoin for a long term hold?
1589
02:15:44.975 --> 02:15:45.375
Do you
1590
02:15:46.560 --> 02:15:49.140
what what is your thoughts on on my statement?
1591
02:15:51.360 --> 02:15:55.460
1592
02:15:56.545 --> 02:16:00.804
The way the way I look at it, I think, is a little bit different than a lot of people. I mean, I'm not
1593
02:16:01.744 --> 02:16:17.364
I'm not interested in the the number go up aspect. I'm not really I mean, I you I know you phrased it as purchasing power, which I think is a more a more nuanced and better way to phrase that idea of the price increasing over time versus Fiat, which is what is meant by purchasing power increasing,
1594
02:16:18.144 --> 02:16:20.625
at least in my eyes. If that's wrong, feel free to correct it. But
1595
02:16:21.160 --> 02:16:22.620
1596
02:16:23.080 --> 02:16:23.980
fuck Fiat,
1597
02:16:24.360 --> 02:16:27.980
but purchasing power between Bitcoin and Monero long term.
1598
02:16:29.985 --> 02:16:43.145
1599
02:16:43.625 --> 02:16:44.604
in price performance.
1600
02:16:45.465 --> 02:16:51.404
So if your if your only concern is price performance or if your main concern is price performance and store value,
1601
02:16:51.990 --> 02:16:55.290
I I think, obviously, Bitcoin has proven itself as that so far,
1602
02:16:55.670 --> 02:16:58.890
that it has worked well as that. The technology works well for
1603
02:16:59.505 --> 02:17:05.285
for that piece of cryptocurrency, and I do think store value is a a meaningful and useful,
1604
02:17:06.305 --> 02:17:08.484
use case for cryptocurrency in general.
1605
02:17:10.020 --> 02:17:12.680
I think where I differ a bit is that
1606
02:17:13.620 --> 02:17:15.400
I think that the world needs
1607
02:17:16.655 --> 02:17:20.035
a store of value much less than it needs a way to transact privately.
1608
02:17:20.976 --> 02:17:22.035
And I think that
1609
02:17:22.336 --> 02:17:29.440
Bitcoin can be used to transact privately. It's definitely doable. I've done it. I am really close to a ton of people in the samurai community.
1610
02:17:30.221 --> 02:17:34.305
I love what Samurai Wallet's doing. I think without them, there would be no hope for Bitcoin.
1611
02:17:34.765 --> 02:17:37.904
And I know that's a bold statement, but they're really kind of the last
1612
02:17:38.364 --> 02:17:45.310
the last bastion of privacy preserving crypto or, cypherpunk people who are are working on Bitcoin or or some of the few.
1613
02:17:47.390 --> 02:17:47.890
And,
1614
02:17:48.430 --> 02:17:52.210
yes, you you can use Bitcoin privately, but I think the caveat is
1615
02:17:52.515 --> 02:17:53.415
it is extremely
1616
02:17:53.795 --> 02:17:55.814
difficult in comparison to Monero.
1617
02:17:56.194 --> 02:17:59.814
Again, samurai wallet makes it possible, but not necessarily easy.
1618
02:18:01.000 --> 02:18:08.220
It is time consuming. It takes a lot longer to go through the mixing process with Bitcoin. You have to learn how to set it up. You have to learn how to mix.
1619
02:18:08.555 --> 02:18:17.915
Hopefully, you set up your own Dojo, which requires obviously setting up the Dojo and connecting to your own server and then maybe setting up the desktop GUI client to make sure that you're syncing all the time. And,
1620
02:18:19.020 --> 02:18:24.160
there's a lot that goes into preserving privacy on Bitcoin, and there are a lot of ways you can mess it up,
1621
02:18:24.780 --> 02:18:28.160
either pre, post mix, or obviously if you're not using Samurais
1622
02:18:28.686 --> 02:18:32.525
or some other privacy approach, but there's not too many great ones out there for Bitcoin.
1623
02:18:32.846 --> 02:18:38.226
If you're not using samurai, you're just you're shooting you're shooting yourself in the foot the whole time that you're using Bitcoin,
1624
02:18:38.740 --> 02:18:41.399
and you're making a clearly deterministically
1625
02:18:42.100 --> 02:18:42.600
traceable
1626
02:18:43.140 --> 02:18:45.399
footprint in a ledger that will last forever
1627
02:18:45.735 --> 02:18:49.835
and is readily available for data analysis by governments, companies, all of that.
1628
02:18:50.695 --> 02:18:55.516
So because my focus is more on a method of exchange, a way to transact value,
1629
02:18:56.120 --> 02:19:05.595
and more on something that is a replacement for cash. So we need digital cash, something that we can transact digitally with, but that carries over the the principles of cash, which are
1630
02:19:06.075 --> 02:19:07.854
essentially fungibility and privacy.
1631
02:19:09.435 --> 02:19:15.510
I I lean towards Monero, and I've chosen to focus my time in in learning and education,
1632
02:19:16.370 --> 02:19:17.109
and in,
1633
02:19:17.490 --> 02:19:18.390
just the
1634
02:19:19.250 --> 02:19:34.660
yeah. Really, the educational content that I put out is focused on Monero because I view it as an extremely approachable, extremely easy to use, and not perfect. The the UX is not perfect. Some of the wallets are better than others, of course, and, hopefully, user experience will continue to improve over time. But
1635
02:19:35.120 --> 02:19:38.340
anyone who uses Monero with any wallet that's available for Monero
1636
02:19:38.926 --> 02:19:45.186
gets very strong privacy guarantees, and they get that digital cash like feel where they they don't have to worry about fungibility.
1637
02:19:45.860 --> 02:19:48.680
They always know that the transactions that they make,
1638
02:19:49.620 --> 02:19:58.195
are being protected in both the sender's protected in each transaction, the receiver's protected in each transaction, and the amount is transact is protected in each transaction.
1639
02:19:58.735 --> 02:20:01.795
And since those things are enforced by the consensus layer,
1640
02:20:02.180 --> 02:20:16.505
there's no way for you to mess that up in those core ways. Obviously, there are some other issues that you could do, like if you're using a a KYC exchange, you go to your wallet once, and then you go to another KYC exchange. If those exchanges share information, they could link the transaction
1641
02:20:16.965 --> 02:20:20.665
back to you. But those are also KYC exchanges, which you shouldn't be touching.
1642
02:20:22.170 --> 02:20:25.630
1643
02:20:26.250 --> 02:20:37.495
1644
02:20:38.000 --> 02:20:43.620
the important distinction is that there is only one light wallet for Monero, and that's called MyMonero.
1645
02:20:44.720 --> 02:20:49.085
Every other mobile wallet, Cake Wallet, Monero Show, there are other ones like,
1646
02:20:49.705 --> 02:21:01.311
I can't remember what they are. They're not Monero specific. I won't focus on them. But, like, Monero Show and Cake Wallet, both of them just use remote nodes, which is it's an RPC connection just like if you were to use your own Bitcoin remote node.
1647
02:21:03.275 --> 02:21:05.535
So there's no leakage of,
1648
02:21:06.314 --> 02:21:10.015
so just just to break down Monero really quickly for anybody who's not aware.
1649
02:21:10.880 --> 02:21:15.300
So Monero, like I said, receiver, sender, and amount are protected in every transaction by default.
1650
02:21:16.000 --> 02:21:21.476
If you want to reveal that information, like, if you want to selectively reveal some information about a transaction
1651
02:21:22.175 --> 02:21:28.995
to a 3rd party, you can give them what's called a view key. And that view key lets them decrypt that information about,
1652
02:21:30.090 --> 02:21:41.625
about transactions that have been received to a specific address. So, like, if I wanted to, I could publish the view key for the donations that I receive via opt out pod so that people could see how much I've received in donations.
1653
02:21:42.165 --> 02:21:45.045
I think in a lot of situations, there's no reason to do that, but, like, if you're a
1654
02:21:45.780 --> 02:21:52.040
maybe a, an open source foundation and you wanna make it transparent how much money you're getting and what you're spending it on, or,
1655
02:21:52.420 --> 02:21:56.735
maybe you're a political candidate and you have to reveal donations, that kind of thing. It can be useful.
1656
02:21:57.755 --> 02:22:06.619
But the way that light wallets work, like my Monero, is that you hand them the view key to your wallet, and so they are able to decrypt that information about your transactions
1657
02:22:07.239 --> 02:22:17.686
so that they can do the actual syncing of the blockchain for you. They can look through the blockchain for all the transactions that correspond to your wallet and let you know about them without you having to
1658
02:22:18.100 --> 02:22:21.720
go to the node, request every block's data, and dig through yourself.
1659
02:22:22.260 --> 02:22:23.399
So you are offloading
1660
02:22:24.180 --> 02:22:26.340
quite large amounts of trust when you're using that.
1661
02:22:26.739 --> 02:22:29.945
You're still, at worst, as bad off as using Bitcoin.
1662
02:22:30.965 --> 02:22:32.425
You still do have some
1663
02:22:33.285 --> 02:22:52.615
some privacy provided there, but that is much less than just using a normal remote node. But, like, when I'm using I use Monerojo and Cake Wallet. When I'm using those, I'm connecting to my own node. Or even when I'm connecting to another node, I'm not revealing any information about the true spend in a transaction. I'm not revealing any information about amounts, and I'm not revealing who I'm sending that transaction to,
1664
02:22:53.510 --> 02:23:01.290
which is a really important point that that remote node privacy is much less of an issue in Monero because transactional privacy is so much stronger.
1665
02:23:02.975 --> 02:23:04.195
1666
02:23:06.335 --> 02:23:07.475
Before I respond,
1667
02:23:07.855 --> 02:23:12.250
we have Moe's bleb mentioning Bunny's open hardware phone.
1668
02:23:13.030 --> 02:23:22.465
Bunny is doing amazing work. I look forward to seeing what he has for us. We did not mention it on the show, so it should be mentioned. I'm very excited about it, but it's not out yet.
1669
02:23:25.300 --> 02:23:29.560
So I have, you know, Gitmo BTC mentioned StoreWealth and Bitcoin
1670
02:23:30.420 --> 02:23:31.399
and then spend
1671
02:23:32.100 --> 02:23:33.239
in in Monero
1672
02:23:33.619 --> 02:23:37.145
or Whirlpool where where Monero isn't accepted using CoinJoin.
1673
02:23:39.445 --> 02:23:40.185
To me
1674
02:23:41.045 --> 02:23:46.800
to me, that's the gotcha. The gotcha is and this is the case with pretty much
1675
02:23:48.380 --> 02:23:49.920
all Altcoins, but
1676
02:23:50.596 --> 02:23:53.415
most Altcoins do not have any kind of usability
1677
02:23:53.716 --> 02:23:54.615
or usability
1678
02:23:55.075 --> 02:24:03.601
advantage that Monero presents. Monero presents a short term to me transactional privacy advantage. I expect long term I hope long term
1679
02:24:04.061 --> 02:24:12.854
becomes easier to use Bitcoin privately, especially as people start to realize the need, especially as people start spending it more because a lot of people don't spend Bitcoin right now.
1680
02:24:15.040 --> 02:24:16.020
And when I when
1681
02:24:16.640 --> 02:24:17.700
I try and
1682
02:24:19.840 --> 02:24:21.620
conceptualize where we're going,
1683
02:24:24.266 --> 02:24:25.085
I just
1684
02:24:25.705 --> 02:24:26.525
all the
1685
02:24:27.145 --> 02:24:31.806
all the the privacy gains that you get in the short term spending
1686
02:24:33.301 --> 02:24:33.801
Monero
1687
02:24:34.820 --> 02:24:36.120
overspending Bitcoin,
1688
02:24:38.900 --> 02:24:42.681
as long as it's easily just easy to swap between the two chains,
1689
02:24:43.524 --> 02:24:46.984
a Bitcoin user has those available to them. They can use CoinJoin.
1690
02:24:47.444 --> 02:24:54.640
They can swap into Monero. They can spend with Monero. They can receive Monero donations and swap back into Bitcoin and hold it in Bitcoin.
1691
02:24:57.020 --> 02:24:58.399
And to me, that's
1692
02:24:59.915 --> 02:25:06.976
that's the ultimate gotcha. It means that, basically, XMR is like a utility token for a transactional privacy chain,
1693
02:25:09.700 --> 02:25:10.200
and
1694
02:25:10.660 --> 02:25:14.440
I value the project. I think it's very good work that's being done there,
1695
02:25:15.635 --> 02:25:17.415
and I think it's useful to Bitcoiners.
1696
02:25:19.234 --> 02:25:23.255
But long term, I just don't see the incentive to not hold your savings in Bitcoin
1697
02:25:23.950 --> 02:25:29.810
and just use Monero for short term transactional privacy until, hopefully, Bitcoin privacy gets better.
1698
02:25:30.910 --> 02:25:31.790
And this is not
1699
02:25:33.745 --> 02:25:35.185
this is where I get
1700
02:25:36.225 --> 02:25:37.524
there's a lot of
1701
02:25:39.185 --> 02:25:41.840
I butt heads with a lot of Monero people on this,
1702
02:25:43.120 --> 02:25:43.620
is
1703
02:25:44.880 --> 02:25:45.859
this is not
1704
02:25:46.399 --> 02:25:46.899
necessarily
1705
02:25:47.200 --> 02:25:48.020
my desire.
1706
02:25:48.640 --> 02:25:49.859
This is my expectation.
1707
02:25:50.320 --> 02:25:50.979
I think
1708
02:25:51.365 --> 02:25:59.145
the way the incentives are set up, I think the different properties of the 2 change where Bitcoin is much harder, much more difficult to change,
1709
02:26:00.350 --> 02:26:02.689
is is harder money to me.
1710
02:26:04.270 --> 02:26:05.970
On a characteristic level
1711
02:26:06.510 --> 02:26:08.689
means that, ultimately, it is
1712
02:26:09.016 --> 02:26:16.556
the better spot to keep your savings. And as a result, the purchasing power will always increase against Monero long term.
1713
02:26:18.030 --> 02:26:21.490
That is my expectation. That's the expectation I'm operating under.
1714
02:26:23.925 --> 02:26:30.585
1715
02:26:31.045 --> 02:26:32.665
as a checking account is
1716
02:26:33.110 --> 02:26:37.370
is another super common one. I I definitely I think that is a valid approach today,
1717
02:26:38.230 --> 02:26:41.930
based on the performance of Bitcoin and the the spendability of Monero.
1718
02:26:43.016 --> 02:26:45.035
We're seeing Monero acceptance
1719
02:26:45.815 --> 02:26:52.075
increase drastically. We've seen a ton more FOSS organizations start to accept it as donations and preferred as donations. We've seen,
1720
02:26:52.530 --> 02:27:06.524
a lot of companies start to accept it more. We've seen, like, coin cards accept Monero, so it's really easy to spend gift cards through there. So I think because the spendability of Monero is increasing, more places are accepting it. And because the Monero community is so focused on
1721
02:27:07.120 --> 02:27:09.620
spending Monero and not just HODLing, which
1722
02:27:10.000 --> 02:27:18.695
I'm not a fan of the whole HODL thing, I think that it it defeats a lot the purpose of cryptocurrencies even though it can be useful, so some people definitely can. But,
1723
02:27:20.035 --> 02:27:24.130
because Monero focuses on the idea of spending and using Monero,
1724
02:27:24.910 --> 02:27:33.494
I think merchant acceptance has been improving quickly. Donation acceptance has especially seen kind of the biggest gains, a ton of privacy focused projects, and people
1725
02:27:34.114 --> 02:27:39.015
accept donations either only in Monero or primarily in Monero in Monero, which is is great to see.
1726
02:27:39.641 --> 02:27:41.420
1727
02:27:41.880 --> 02:27:45.580
these things go hand in hand, and I butt heads on both sides
1728
02:27:46.040 --> 02:27:48.540
of the argument spending versus HODLing
1729
02:27:50.875 --> 02:27:55.535
because these networks for them to be truly distributed and censorship resistant,
1730
02:27:55.995 --> 02:28:00.069
they need a native token to pay the miners. That native token needs to have value.
1731
02:28:01.330 --> 02:28:05.430
Maybe in, like, a perfect theoretical sense, that value is just a stable value.
1732
02:28:06.370 --> 02:28:07.815
But it's that
1733
02:28:08.516 --> 02:28:09.016
that's
1734
02:28:10.436 --> 02:28:15.560
not really feasible without entering third party risk, having some kind of centralized peg.
1735
02:28:16.359 --> 02:28:19.020
So what happens is we have a free floating value.
1736
02:28:20.359 --> 02:28:20.859
And,
1737
02:28:21.960 --> 02:28:26.495
ultimately, better than that value going down would be that value going up over time
1738
02:28:26.955 --> 02:28:31.614
and the network becoming more secure as a result. And you being able to spend that value
1739
02:28:32.475 --> 02:28:35.811
needs that the token needs to have value to begin with. Right?
1740
02:28:37.150 --> 02:28:42.211
So I do think they kind of go hand in hand. I think people will have savings, and they'll have spend it. I
1741
02:28:42.671 --> 02:28:43.330
I think
1742
02:28:44.065 --> 02:28:45.925
good money, you should be able to
1743
02:28:47.265 --> 02:28:50.760
save and spend without permission. I will, however you wanna do it.
1744
02:28:52.840 --> 02:28:56.939
So so I do think that they I do think those two characteristics
1745
02:28:57.560 --> 02:29:01.565
go hand in hand, and there's really not that much nuance in that
1746
02:29:02.186 --> 02:29:04.205
in that discussion that happens. Like,
1747
02:29:05.705 --> 02:29:08.045
it gets very extreme, especially on Twitter,
1748
02:29:08.760 --> 02:29:09.580
where there's,
1749
02:29:10.040 --> 02:29:18.060
it's not really a good, platform for it. And then the other thing you mentioned was donations, and I I think, like, donations is, like, a perfect example here
1750
02:29:18.745 --> 02:29:24.285
where because Monero has stealth addresses where you're able to just post a a static string,
1751
02:29:25.065 --> 02:29:27.790
to receive donations or a static QR code
1752
02:29:28.190 --> 02:29:29.410
that interprets that string,
1753
02:29:30.270 --> 02:29:33.010
without revealing what donations you've received
1754
02:29:33.950 --> 02:29:47.520
and not having that issue, the same issue you have on Bitcoin where you don't wanna reuse an address because if if you have that static donation address in Bitcoin, you can just look it up on chain and see all the donations that come in and all the spends that go out.
1755
02:29:48.460 --> 02:29:52.000
Monero's had that advantage over Bitcoin for a long time, but now
1756
02:29:52.335 --> 02:29:53.795
we're starting to see,
1757
02:29:55.375 --> 02:29:56.975
we have a have a have a new,
1758
02:29:58.575 --> 02:30:01.955
lightning invoice format that is being rolled out right now, bolt 12,
1759
02:30:02.471 --> 02:30:04.650
which attempts to provide a
1760
02:30:05.110 --> 02:30:06.330
privacy preserving
1761
02:30:06.631 --> 02:30:07.131
static,
1762
02:30:08.391 --> 02:30:12.756
either text string or QR code that gives you similar functionality to
1763
02:30:13.855 --> 02:30:14.915
Monero donations.
1764
02:30:16.256 --> 02:30:19.315
And that's a trend I expect to continue. So to me,
1765
02:30:22.370 --> 02:30:23.250
you know, I I
1766
02:30:25.250 --> 02:30:29.375
the the the long term value prop of Monero, I
1767
02:30:29.855 --> 02:30:33.635
see eroding, but, you know, I don't pretend to know everything. I'm not gonna
1768
02:30:34.415 --> 02:30:42.090
1769
02:30:42.630 --> 02:30:51.735
Bitcoin has done great things. Without Bitcoin, Monero would not be here. Without people working on Bitcoin, many of the technologies that are fundamental to Monero would not be here.
1770
02:30:52.676 --> 02:30:54.695
And Bitcoin just being the
1771
02:30:55.311 --> 02:31:07.755
being the the lead, the alpha in the in the cryptocurrency space takes a lot of the heat away from an arrow and lets us just focus on building and not have to worry about a lot of the other issues. So, like, I don't want people to come away with us thinking, like, I hate Bitcoin. I I just
1772
02:31:08.314 --> 02:31:13.455
the the the big things for me and I'll I'll I'll comment on the the l n thing in just a second. But,
1773
02:31:14.340 --> 02:31:16.600
the big things for me are that
1774
02:31:17.220 --> 02:31:31.835
Monero is easily spendable for anybody in a private manner. I I don't I don't question that Bitcoin is spendable privately by people like yourself or people who are using Ceramic Wallet today or who understand those concepts. My concern with Bitcoin is that we
1775
02:31:32.910 --> 02:31:36.050
we don't improve the base layer. We don't provide better privacy.
1776
02:31:36.430 --> 02:31:48.055
And also coupled with that, that Lightning Network doesn't take off or it doesn't provide the privacy that people thought it would at first, which again is what happened with Bitcoin. The people thought it was private and then found out that there were too many issues, and then it didn't proceed.
1777
02:31:49.340 --> 02:31:54.000
And then, obviously, Lightning inherits some privacy issues from the base layer, but that's a whole another topic.
1778
02:31:54.780 --> 02:31:58.080
But my my concern is that we pull people more into Bitcoin,
1779
02:31:58.555 --> 02:32:05.375
and they don't know how to use the tools. And there's only like, right now, there's only 1, in my opinion, privacy preserving wallet implementation.
1780
02:32:05.800 --> 02:32:09.740
If that wallet gets shut down or if the samurai devs die or if the samurai devs leave,
1781
02:32:10.280 --> 02:32:12.060
Bitcoin is in a really bad place,
1782
02:32:12.439 --> 02:32:15.886
and that requires the servers that they're running to coordinate Whirlpool.
1783
02:32:16.266 --> 02:32:23.580
So if that stuff gets compromised, that could be really problematic, and that's not something that there's any real other great tool to jump into. But we have joined market.
1784
02:32:24.520 --> 02:32:28.380
The usability is not great. But Yeah. I mean, I I know it's there, but
1785
02:32:29.000 --> 02:32:37.365
greater problems of pulling people in to actually who can actually functionally use it, and it has the core problem of post mix spending is really difficult.
1786
02:32:38.386 --> 02:32:42.006
But it it really comes back to, like, why I focus on Monero is because
1787
02:32:42.530 --> 02:32:49.350
I want if I'm gonna focus on building a tool, and this is different than, like, the tools that I educate people about through opt out pod or through my blog.
1788
02:32:49.686 --> 02:33:01.840
Those are not tools that I'm building and pouring time into. They're they're tools, many of them, that I donate to or that I help out with, like, bug requests and feature requests that I see are necessary. But the reason I focus on Monero is because I see that
1789
02:33:02.221 --> 02:33:15.870
it's a tool that practically anyone can get into and use, and they don't have to be technically savvy. They don't have to be wealthy to pay fees. They don't have to to have access to a a node that they can run so that they can preserve their
1790
02:33:23.955 --> 02:33:29.015
and not just one that I could use. I could use Bitcoin privately today, and it would be fine for me.
1791
02:33:29.635 --> 02:33:41.780
I mean, I I prefer to use Monero. It's much easier. I I prefer the the ease of mind that I have when using it, but I I have the technical skills. I have the money. I can afford the fees. I can afford the time investment to to use Whirlpool and spend funds.
1792
02:33:42.165 --> 02:33:48.265
But I choose to focus on Monero because I want to I want to build a tool that's more easily approachable for other people.
1793
02:33:49.811 --> 02:33:51.990
Any comment on that before I say a couple more things?
1794
02:33:53.090 --> 02:33:57.590
1795
02:33:59.734 --> 02:34:01.194
I I love your
1796
02:34:01.734 --> 02:34:06.555
your your your your extremely motivated, and I I think you're fighting the good fight.
1797
02:34:08.220 --> 02:34:12.960
And I, you know, I re likewise, I'm I'm glad that we have both Monero and Bitcoin.
1798
02:34:16.035 --> 02:34:21.335
I I guess I mean, like, I've I view Monero as a tool of receiving and sending Bitcoin, basically.
1799
02:34:22.820 --> 02:34:27.620
1800
02:34:28.500 --> 02:34:33.925
in many ways, a more complete tool than Lightning, at least today, as a second layer for Bitcoin.
1801
02:34:35.025 --> 02:34:41.649
And I am really glad that that's a possibility, and I love that the Monera community funded and is building atomic swaps that
1802
02:34:42.270 --> 02:34:44.609
really, the atomic swaps that we're building benefit
1803
02:34:45.229 --> 02:34:54.555
Bitcoiners. They don't really benefit Monero people, because if we're gonna be the ones on the other side of that, if we're gonna be market making for atomic swaps, we're gonna be gonna we're gonna be getting tainted UTXOs,
1804
02:34:55.654 --> 02:35:02.770
toxic change. We're gonna getting all we're gonna be getting all that fun stuff and have to deal with mixing it or finding ways to sell it or trade it, or,
1805
02:35:03.550 --> 02:35:04.765
there's gonna be a lot of
1806
02:35:13.250 --> 02:35:24.814
people to be able to use Monero when and how they want. If you wanna use Bitcoin for savings and you wanna use Monero for for spending, that's awesome. I'm glad that that that that possibility exists. And, like, I think that's probably the most
1807
02:35:25.354 --> 02:35:25.854
coherent
1808
02:35:26.395 --> 02:35:26.895
approach
1809
02:35:27.354 --> 02:35:28.975
that I see Bitcoiners take,
1810
02:35:30.230 --> 02:35:35.130
just at least acknowledging that Monero is an extremely effective tool for spending money.
1811
02:35:36.630 --> 02:35:38.490
But I also think the
1812
02:35:39.085 --> 02:35:42.785
the one with Bitcoin as a store of value long term is a tricky one because
1813
02:35:43.325 --> 02:35:45.025
a store value really depends on
1814
02:35:45.405 --> 02:35:53.380
really 2 things. It could be one of 2 things, but generally 2 things, which are network effect, that remains the the main thing that's being used to store value.
1815
02:35:54.000 --> 02:35:54.500
And,
1816
02:35:54.915 --> 02:35:55.415
generally,
1817
02:35:55.795 --> 02:36:01.734
value increases as people use something and keep increasing the price by needing to buy back in and keep using it.
1818
02:36:02.350 --> 02:36:06.530
A method of exchange generally leads to price stability, which can also help as a store of value
1819
02:36:06.910 --> 02:36:14.774
because if the price is stable and slowly rising rather than rapidly increasing and rapidly declining, it's a much more attractive store value for more people.
1820
02:36:15.395 --> 02:36:25.430
And since Monero does so well at method of exchange, the argument could be made that that would lead to price stability and a good store value long term. Like I said, my my focus is not on price. I haven't
1821
02:36:25.825 --> 02:36:34.405
looked at charts and compared and seen how these things specifically affect coins. I'm not really as concerned with that, but there are lots of other arguments around that.
1822
02:36:35.061 --> 02:36:39.801
1823
02:36:40.980 --> 02:36:45.205
like, not Fiat price. I'm talking about the 2 between the 2. But,
1824
02:36:45.845 --> 02:36:53.145
1825
02:36:54.190 --> 02:37:05.795
a massive market between Bitcoin and Monero. It's that people are buying buying Bitcoin with fiat, pumping the price, and Monero is not as purchased because it's restricted because people hate privacy, so it's not on as many exchanges.
1826
02:37:06.495 --> 02:37:12.400
So I don't I don't I mean, I I agree that specifically, XMR versus BTC price is your focus, but, I mean, that
1827
02:37:14.960 --> 02:37:24.255
is at the core, that's still fiat price. But, yeah, so far, I mean, like, I'll I'll just be quite honest. If I had held Bitcoin and not hold Monero, I would've and I don't hold Monero. I use Monero. But if I had only
1828
02:37:24.875 --> 02:37:36.740
bought and held or used Bitcoin and not touched Monero, I would have a lot more money today. Do I regret it? No? I'm glad that I got into Monero and that I was I've dedicated the time and effort to to building up that tool and educating people. But,
1829
02:37:37.125 --> 02:37:44.665
yes, I mean, price has not been kind to Monero, especially since I got into it, which is either unfortunate or maybe I caused something. I don't know.
1830
02:37:45.845 --> 02:37:46.190
But
1831
02:37:46.671 --> 02:37:52.450
but, I mean, yes, I would have been better off price wise, but I think that Monero is a much more approachable tool that I I wanna get people into.
1832
02:37:53.555 --> 02:37:57.494
You also mentioned something about network security relying on price increases.
1833
02:37:59.234 --> 02:38:01.395
That that one is something that a lot of people
1834
02:38:02.130 --> 02:38:06.950
I don't know. I go back and forth on that one. I agree that price increase can drive network security,
1835
02:38:07.569 --> 02:38:15.205
but when something has a rapidly changing price, it can also hurt network security. But the the main thing to me is, what is the technological approach that's taken
1836
02:38:15.585 --> 02:38:18.325
with Bitcoin versus Monero for long term network security?
1837
02:38:19.580 --> 02:38:24.320
And the one of the reasons that I like Monero is that the approach has been taken that we don't want to rely
1838
02:38:25.020 --> 02:38:26.000
solely on
1839
02:38:26.380 --> 02:38:32.845
fees long term to to support network security. We wanna make sure that there's at least some base stable layer
1840
02:38:33.385 --> 02:38:37.880
of block reward that miners can trust will happen no matter what's happening with fees at the moment.
1841
02:38:38.420 --> 02:38:42.855
And so for those who are new to Monero, that's called the tail emission. Essentially, what that means is that
1842
02:38:43.415 --> 02:38:45.756
Monero has a a set supply.
1843
02:38:46.136 --> 02:38:50.636
And then after that set supply, which I think May 2022 is when this will happen,
1844
02:38:50.970 --> 02:39:00.029
it'll switch to something called a tail emission, and that tail emission will be that there will be point 6 XMR per block or point 3 XMR per minute depending on how you how you wanna look at it,
1845
02:39:00.335 --> 02:39:01.234
emitted forever.
1846
02:39:01.935 --> 02:39:06.595
And I know to to Bitcoiners with your 21,000,000 cap out there, that's a terrifying concept,
1847
02:39:07.614 --> 02:39:11.150
but it's really important to realize that it's it's what's called asymptotically
1848
02:39:11.530 --> 02:39:12.590
approaching 0%.
1849
02:39:13.130 --> 02:39:15.150
So because it's a fixed amount of Monero,
1850
02:39:15.690 --> 02:39:20.895
when it's compared to the total amount of Monero, the percent of inflation is constantly approaching 0%.
1851
02:39:21.915 --> 02:39:31.770
And it's also already a lower inflation percentage than Bitcoin and gold. And, again, that percentage will continue to decrease. So it's it's a very small inflation that is known, that is predictable,
1852
02:39:32.311 --> 02:39:36.075
but that provides a base level of network security to what happens with fees.
1853
02:39:36.556 --> 02:39:39.295
And that is definitely a concern for Bitcoin long term if
1854
02:39:39.675 --> 02:39:43.436
when there are less Bitcoin per block in the block subsidy or if there are
1855
02:39:44.580 --> 02:39:50.360
when there is no Bitcoin given out in the blocks of the block world. Well, there'll never be no Bitcoin given out.
1856
02:39:51.380 --> 02:39:54.155
1857
02:39:54.615 --> 02:40:04.830
1858
02:40:05.370 --> 02:40:08.200
1859
02:40:20.171 --> 02:40:25.950
the concern in terms of supply with with the tail emission on Monero is less so than the fact
1860
02:40:26.570 --> 02:40:27.070
that
1861
02:40:29.555 --> 02:40:30.774
for better or worse,
1862
02:40:31.955 --> 02:40:33.255
Monero is
1863
02:40:34.595 --> 02:40:37.095
is easier to change, and and Monero
1864
02:40:37.721 --> 02:40:40.461
stakeholders have taken advantage of that to adapt quickly.
1865
02:40:41.721 --> 02:40:50.604
But as a result, it means that any guarantees you have in terms of what the protocol says it's going to be, are reduced because
1866
02:40:51.305 --> 02:40:52.845
you don't you don't know if,
1867
02:40:53.785 --> 02:40:56.685
it'll change out from under you. So, like, even,
1868
02:41:01.560 --> 02:41:02.380
you know, like,
1869
02:41:02.840 --> 02:41:04.140
something that's that's
1870
02:41:04.465 --> 02:41:10.085
a if if you if you take an altcoin that has let's say that they're actually holding a 21,000,000,
1871
02:41:11.825 --> 02:41:12.725
supply cap,
1872
02:41:13.461 --> 02:41:21.961
in the protocol now. That supply cap promise is significantly weaker than Bitcoin's because Bitcoin has shown that it's extremely hard to change,
1873
02:41:24.055 --> 02:41:26.314
So you have a a much stronger guarantee
1874
02:41:27.255 --> 02:41:27.755
that
1875
02:41:28.375 --> 02:41:33.710
that that that will be held, and it won't be changed in the future out from underneath you.
1876
02:41:34.490 --> 02:41:36.510
1877
02:41:36.811 --> 02:41:39.470
points I'd like to make in response to that. I mean, one is
1878
02:41:40.716 --> 02:41:44.895
I don't think that it's valid to really be concerned about the supply changing in Monero.
1879
02:41:45.835 --> 02:41:46.976
Just like in Bitcoin,
1880
02:41:47.410 --> 02:42:04.695
the supply is purely social consensus. If social consensus changed in Bitcoin enough that the supply wanted to be changed, it would be changed. It's it's just code. I mean, it's not gonna change. But I know. Yeah. I know. I I agree. I don't think that Bitcoin's never gonna make any large base layer changes in the future, and supply is something that is obviously
1881
02:42:05.290 --> 02:42:12.350
that's, like, the number one narrative for Bitcoin. So I I don't I don't see that changing. So I'm not saying that. I'm just saying it is social consensus.
1882
02:42:12.890 --> 02:42:20.694
And thankfully for Bitcoin, at least as far as number go up, the supply is fixed. Social consensus is that the supply will stay fixed.
1883
02:42:21.190 --> 02:42:25.590
It's not gonna fork in any real changes anyways, so that's not really a concern there at all.
1884
02:42:26.470 --> 02:42:36.475
But it's also not a concern in Monero because it's, again, social consensus. If if people were to want to change the supply, it would have the same impact it would have on Monero, which would be to destroy trust and
1885
02:42:36.854 --> 02:42:37.835
destroy the fundamental
1886
02:42:38.250 --> 02:42:44.830
guarantees that have been existent since the Genesis block in Monero. So, I mean, that's it's never that's never gonna happen either,
1887
02:42:45.186 --> 02:42:51.125
and it's not like Monero is small. Monero is a very large community and a very large project compared to most altcoins.
1888
02:42:51.585 --> 02:42:54.645
But, yes, in comparison to Bitcoin, it is it is a much smaller
1889
02:42:55.190 --> 02:42:55.690
community.
1890
02:42:57.670 --> 02:43:06.465
The other key part though is that this unwillingness to change in Bitcoin, which is good for things like supply cap, is also very bad for things like
1891
02:43:08.045 --> 02:43:09.664
increasing the base layer's
1892
02:43:09.965 --> 02:43:10.465
privacy.
1893
02:43:10.820 --> 02:43:16.760
I mean, this is something we've seen. There have been many proposed approaches to increase the privacy of the Bitcoin base layer,
1894
02:43:17.141 --> 02:43:21.475
many of which have gone on to be included in Monero and and used regularly with great success.
1895
02:43:22.015 --> 02:43:24.755
But those changes have been denied simply because people
1896
02:43:25.455 --> 02:43:28.274
either do not wanna sacrifice the narrative of the
1897
02:43:29.229 --> 02:43:32.850
back of the back of the napkin math on looking at
1898
02:43:33.310 --> 02:43:38.515
the total outputs to calculate the supply of Bitcoin versus trusting in some some cryptography
1899
02:43:38.815 --> 02:43:39.475
for that,
1900
02:43:40.415 --> 02:43:42.355
or it has it has
1901
02:43:43.695 --> 02:43:57.095
just not been implemented because people didn't want to take the risk of implementing a serious change into the Bitcoin base layer. So there is the I mean, the the niceness of Bitcoin being hard to change also has serious side effects in that Bitcoin's layer 1 privacy will probably never improve,
1902
02:43:57.955 --> 02:44:16.195
or at least it doesn't seem like it will improve noticeably. Hopefully, it will. Again, many of these things I'm saying about Bitcoin, I've said this many times before on Twitter and other places, but the best thing for the world would be for Bitcoiners to wake up to the need for privacy, to wake up the for the need for the the spendability of Bitcoin to be improved, the fungibility to be improved,
1903
02:44:16.815 --> 02:44:33.185
and to make the necessary changes to the base layer to make that happen. I would love that. If we had no need for a Monero in the world, that would be freaking awesome. I would be so happy. So, like, don't take what I'm saying as something where, like, I want Monero to beat Bitcoin or anything like that. I would much rather Bitcoin just evolve into what the world needs, in my opinion,
1904
02:44:34.045 --> 02:44:39.024
rather than needing a Monero. But but because I see that as unlikely, that's why I
1905
02:44:39.430 --> 02:44:41.369
why I focus on, on Monero.
1906
02:44:41.989 --> 02:44:43.770
1907
02:44:44.790 --> 02:44:46.330
trade offs like everything else.
1908
02:44:48.715 --> 02:44:52.415
Look. I I appreciate I I appreciate you having,
1909
02:44:53.115 --> 02:44:55.135
this discussion with me on air.
1910
02:44:55.979 --> 02:44:58.560
I hope the freaks appreciate it. I mean, regardless,
1911
02:44:58.860 --> 02:44:59.520
I think
1912
02:45:02.595 --> 02:45:04.515
before the Monero topic came up,
1913
02:45:05.074 --> 02:45:06.135
we had a very,
1914
02:45:06.994 --> 02:45:08.774
very important discussion
1915
02:45:09.154 --> 02:45:09.654
on
1916
02:45:10.729 --> 02:45:18.895
mobile phone privacy. So I know the freaks will find that extremely helpful, but I also hope they found it helpful our discussion on Monero and Bitcoin,
1917
02:45:19.995 --> 02:45:23.135
and the different trade offs that both projects are making.
1918
02:45:26.710 --> 02:45:36.170
Yeah. And I just wanna reiterate that I, you know, I respect you, and I'm I'm really glad you came on the show. I I I respect what you're doing with opt out pod. I think it's one of the best podcasts in the space.
1919
02:45:36.735 --> 02:45:41.555
I don't want Bitcoiners that are listening here to get discouraged from listening to opt out because,
1920
02:45:42.975 --> 02:45:44.915
Monero really isn't the main focus.
1921
02:45:45.979 --> 02:45:47.600
Privacy and sovereignty is,
1922
02:45:48.460 --> 02:45:54.995
and it's it's a fantastic show. So I really do appreciate the work you've done there. It's not even it's not even cryptocurrency
1923
02:45:55.615 --> 02:46:02.675
1924
02:46:03.050 --> 02:46:13.885
a Monero only podcast or anything like that. That is not the focus. It is much more similar to the earlier discussion we had for the first couple hours that that focused on Kallix and using different tools to opt out.
1925
02:46:14.265 --> 02:46:14.765
1926
02:46:15.225 --> 02:46:20.365
And I expect insecure bit corners to come at me probably for this last segment.
1927
02:46:21.100 --> 02:46:25.840
I will reiterate to them that open discussion of these very important topics
1928
02:46:26.460 --> 02:46:30.615
is good for everybody and that as soon as we stop having open discussion,
1929
02:46:33.155 --> 02:46:40.190
that's when things start to degrade and things get a lot worse. So it's extremely important that we have open discussion on on all of these topics,
1930
02:46:40.811 --> 02:46:45.550
and that's one of the reasons why I started dispatch. That's one of the reasons why there's no ads or sponsors.
1931
02:46:46.565 --> 02:46:48.425
It's completely funded by the audience.
1932
02:46:50.725 --> 02:46:51.945
Buy us for us.
1933
02:46:53.045 --> 02:46:53.545
Seth,
1934
02:46:54.370 --> 02:46:57.830
really enjoyed this conversation. You have any final thoughts before we wrap up?
1935
02:46:58.530 --> 02:47:08.325
1936
02:47:09.045 --> 02:47:19.935
And I'm sure you're gonna take a lot of flack for it. But but like you said, I I think that it's hopefully, I didn't come off as too aggressive or abrasive specifically about Monero. I get fired up about that. But if anyone is just
1937
02:47:20.494 --> 02:47:22.114
surely anti Monero,
1938
02:47:22.415 --> 02:47:25.475
listen to the rest of this this dispatch. It's been a great conversation.
1939
02:47:26.814 --> 02:47:39.945
And I just I know you you took some some risk in social circles having me on, but I I think that this this concept of kind of pushing the boundaries of just Bitcoin privacy into more general privacy journey
1940
02:47:40.405 --> 02:47:56.035
is so vital. And I really hope that more Bitcoiners they they fall down the Bitcoin rabbit hole, they fall down the Bitcoin privacy rabbit hole, and then they fall down the the general privacy rabbit hole because it's it's really I mean, that's that's the way I have gone through. I'm I'm here because of Bitcoin,
1941
02:47:56.575 --> 02:47:57.556
Privacy Maximalist.
1942
02:47:58.096 --> 02:48:08.950
That's why I'm I'm into the tools that I am. That's much of why I created a podcast. That's much of why I created a blog. So I'm I'm really grateful for for you, for the content you're putting out, and just
1943
02:48:09.275 --> 02:48:19.060
just grateful to to be able to come on, to chat, to have some really good, I think, meaningful discussions about mobile privacy that that really can they can change things for the better on a on a large
1944
02:48:19.540 --> 02:48:32.346
scale. It is very much about personal privacy, but with all of us opting out of the the tools that that the government and the corporations are trying to use to surveil us and pulling others along with us, we I think can have a a really
1945
02:48:32.726 --> 02:48:34.745
major impact on the world for good.
1946
02:48:35.046 --> 02:48:37.226
So I hope that more people take the time to
1947
02:48:37.640 --> 02:48:45.145
to learn about those tools, to to gain more knowledge and understanding, and to just pull pull their friends and family and pull, their online communities in,
1948
02:48:46.104 --> 02:48:50.364
really try to be the one pulling pulling people down the privacy rabbit hole and
1949
02:48:50.744 --> 02:49:03.380
and, making a change in the world that way. So, yeah, really grateful for this time. I love what you're doing with with dispatch, all the educational content you've done in the past. You are one of my absolute favorite Bitcoiners, and, yeah, just had a great time chatting, Matt.
1950
02:49:03.955 --> 02:49:05.734
1951
02:49:09.314 --> 02:49:16.460
I'm I'm I'm glad I'm glad to have you have you on our side in this fight. It's it's the most important thing as far as I'm concerned, and,
1952
02:49:17.739 --> 02:49:21.155
yeah, just just thank thank you for joining, and thank you for everything you do.
1953
02:49:21.955 --> 02:49:27.575
Big thanks to the freaks who joined us in the live chat, to the freaks who support the show and keep us going.
1954
02:49:28.436 --> 02:49:32.120
And thanks for everyone for listening. Appreciate you all. Thanks, Seth.
1955
02:49:33.699 --> 02:49:34.600
1956
02:49:40.385 --> 02:49:41.445
1957
02:49:43.425 --> 02:49:44.405
I guess I had
1958
02:49:44.945 --> 02:49:46.165
to go to that place
1959
02:49:46.790 --> 02:49:48.090
to get to this one.
1960
02:49:49.029 --> 02:49:49.930
Now some of
1961
02:49:50.310 --> 02:49:51.930
you might still be in that place
1962
02:49:53.350 --> 02:49:54.285
if you're trying to get
1963
02:49:55.645 --> 02:49:56.865
out, just follow me.
1964
02:49:58.045 --> 02:49:58.785
I can too.
1965
02:49:59.245 --> 02:50:20.490
You can try and read my lyrics off, but it's capable for all I am. But you won't take this thing off these words before I say them. Because ain't no way I'm gonna let you stop me from causing them. When I say them, I do something, I do it. I don't give a damn what you think. I'm doing this for me. So fuck the world, feed it beans, it's gas stuff. If you think it's stopping me, I'm a be what I set out to be. Without a title, I'm tired of bleeding. All those who look down on
1966
02:50:37.450 --> 02:50:46.190
for Christmas. His gift is a curse. Forget that earth has got the urge to pull his dick from the dirt and fuck the whole universe. I'm not afraid, I'm not afraid
1967
02:50:46.650 --> 02:50:47.115
to take a stand, take a
1968
02:51:05.895 --> 02:51:27.650
Okay. Take away your senses and shit and cut the crap. I shouldn't have to rhyme these words in the rhythm for you to know it's a rap. You said you was king, you lied through your teeth. For that, fuck your feelings. Instead of getting crowned, you're getting capped into the bands. I never let you down to get them back. I promise to never go back on that promise. In fact, let's be honest, at last we last see the was aired. Perhaps our random accents
1969
02:51:44.940 --> 02:51:53.615
fucking black cloud still follows me around but it's time to exercise these demons. These motherfuckers are doing jumping jacks. I'm not afraid. I'm not afraid to
1970
02:52:21.830 --> 02:52:29.085
breaking out of this cave. I'm standing up. I'm a face my demon. I'm manning up. I'm a hold
1971
02:52:35.725 --> 02:52:40.900
It was my decision to get clean. I did it for me. Admittedly, I probably did it subliminally
1972
02:52:41.440 --> 02:53:01.840
for you. So I could come back a brand new me you helped seen me through. And don't realize what you did, because believe me you, hopping through the wringer, but taking too little to the middle finger. I think I got a tear in my eye, I feel like the king of my world. Haters can make like bees when those fingers end up ripe gay. No more beef fingers, no more drama from now. I wanna promise to focus solely on handling
1973
02:53:57.185 --> 02:53:58.245
1974
02:53:58.705 --> 02:54:00.725
Thanks again for joining another dispatch.
1975
02:54:01.104 --> 02:54:06.500
Looking forward to our HR this week on Thursday, and I'll see you next Bitcoin Tuesday
1976
02:54:07.040 --> 02:54:08.420
for another great dispatch.
1977
02:54:09.040 --> 02:54:11.220
Cheers. Stay humble. Stack stats.