CD42: security focused bitcoin nodes with @nixbitcoinorg, @n1ckler, and @seardsalmon
EPISODE: 42
BLOCK: 707898
PRICE: 1577 sats per dollar
TOPICS: security focused bitcoin nodes
@nixbitcoinorg: https://twitter.com/nixbitcoinorg
@n1ckler: https://twitter.com/n1ckler
@seardsalmon: https://twitter.com/seardsalmon
streamed live every tuesday:
https://citadeldispatch.com
twitch: https://twitch.tv/citadeldispatch
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://anchor.fm/citadeldispatch
telegram: https://t.me/citadeldispatch
support the show: https://tippin.me/@odell
stream sats to the show: https://www.fountain.fm/
join the chat: http://citadel.chat/
53:23 - Nix Bitcoin is agnostic and supports various node implementations
58:30 - RTL package or module
01:00:28 - How to use Bitcoin
01:02:26 - Project culture at Next Bitcoin
01:58:03 - Next Bitcoin is for technical people
01:58:30 - Nix Bitcoin is a sandbox
02:00:07 - Graphical user interfaces for NextOS
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 8:13:45 PM
Duration: 9417.927
Channels: 1
1
00:00:00.080 --> 00:00:11.135
2
00:00:11.514 --> 00:00:12.335
I I mean,
3
00:00:12.875 --> 00:00:18.740
I I know that you you probably think that that Bitcoin is is here to stay. Do you think all of these,
4
00:00:19.599 --> 00:00:20.099
different,
5
00:00:21.359 --> 00:00:22.419
crypto assets
6
00:00:22.800 --> 00:00:27.064
are real and here to stay, or or is there something to be concerned with? And and do we
7
00:00:27.445 --> 00:00:34.345
need oversight so that that people aren't left holding the bag for some of these things, whether they do or not? I'm not not predicting one way or another.
8
00:00:35.480 --> 00:00:40.620
9
00:00:41.640 --> 00:00:44.059
The fact that Bitcoin is fully decentralized
10
00:00:44.600 --> 00:00:48.835
and that some of these others were issued by a person or an entity
11
00:00:49.295 --> 00:00:53.715
that kept a large block of the coin for themselves
12
00:00:54.050 --> 00:00:56.070
and then issued others to participate
13
00:00:56.690 --> 00:00:59.430
means they look more like a security than a commodity.
14
00:01:00.050 --> 00:01:02.150
Bitcoin is clearly a commodity.
15
00:01:02.485 --> 00:01:04.185
It is digital gold.
16
00:01:04.725 --> 00:01:08.104
So I do think that having a regulatory
17
00:01:08.645 --> 00:01:09.145
framework,
18
00:01:10.070 --> 00:01:12.009
within which this can
19
00:01:12.390 --> 00:01:15.929
exist and innovate, meaning this entire space
20
00:01:16.390 --> 00:01:17.609
of digital assets,
21
00:01:18.845 --> 00:01:20.705
but, that protects consumers
22
00:01:21.165 --> 00:01:23.985
at the same time is extremely valuable.
23
00:01:24.445 --> 00:01:27.425
And that's why we in the Financial Innovation Caucus,
24
00:01:28.100 --> 00:01:30.200
are, even as we speak, putting together,
25
00:01:30.659 --> 00:01:33.159
and reviewing the legislation we have crafted,
26
00:01:33.939 --> 00:01:34.439
to,
27
00:01:34.899 --> 00:01:36.679
address these and other issues.
28
00:01:37.645 --> 00:01:39.585
Bitcoin is the standard.
29
00:01:40.525 --> 00:01:41.585
Everything else,
30
00:01:42.285 --> 00:01:44.545
is has to be monitored differently,
31
00:01:45.360 --> 00:01:47.140
because they are created differently.
32
00:02:20.490 --> 00:02:25.710
33
00:02:26.675 --> 00:02:31.815
I know it's been a while since our last proper Bitcoin Tuesday, but I have not forgotten about y'all.
34
00:02:33.315 --> 00:02:40.110
We have a great conversation lined up for today, and, I have great conversations lined up for the next 4 weeks in a row.
35
00:02:40.890 --> 00:02:42.985
Bitcoin Tuesdays are coming back
36
00:02:43.545 --> 00:02:49.885
strong. Next week, we're gonna have Bitcoin q and a for a nice tight Bitcoin beginner focused conversation.
37
00:02:51.640 --> 00:02:54.220
Then we're gonna have raw avocado and waxwing
38
00:02:54.520 --> 00:02:57.100
on. Waxwing will be joining us for a second time.
39
00:02:57.400 --> 00:02:59.160
Then we're gonna have Eric Sirian on,
40
00:03:00.144 --> 00:03:03.045
with the Simple Bitcoin Wallet Maintainer and Fiat JAF,
41
00:03:03.665 --> 00:03:05.504
discuss, Fedimint and,
42
00:03:06.224 --> 00:03:07.765
Federated Lightning Wallets.
43
00:03:08.840 --> 00:03:11.020
Pretty excited about that with Tommy and Ecash.
44
00:03:12.120 --> 00:03:17.945
This is Sidelle Dispatch, the interactive live show about Bitcoin distributed systems privacy and open source software.
45
00:03:19.845 --> 00:03:26.640
Specifically, this is Citadel dispatch 40 2. We're gonna be focused on security focused Bitcoin nodes, specifically,
46
00:03:27.819 --> 00:03:28.640
Nick's Bitcoin,
47
00:03:29.315 --> 00:03:36.375
who's currently having some issues. So he is not with us right now, but he should be joining shortly, the lead maintainer of Nix Bitcoin.
48
00:03:38.060 --> 00:03:41.840
Shout out to the ride or dive freaks who continue to support the show,
49
00:03:42.460 --> 00:03:43.840
even though I've been traveling.
50
00:03:44.460 --> 00:03:45.760
You guys keep it
51
00:03:46.185 --> 00:03:47.805
ad free and sponsor free,
52
00:03:48.265 --> 00:03:50.925
so we can just focus on actionable Bitcoin discussion.
53
00:03:51.705 --> 00:03:54.685
The easiest way to support the show is to go to new podcast apps.com,
54
00:03:55.650 --> 00:03:58.390
pick a podcasting app, search Citadel dispatch,
55
00:03:58.850 --> 00:04:03.430
press the subscribe button, load it up with sats, and stream sats directly to my node.
56
00:04:04.050 --> 00:04:04.870
You can also,
57
00:04:05.925 --> 00:04:07.225
donate via paynim@cildispatch.com.
58
00:04:08.645 --> 00:04:11.065
My paynim's Odell, very easy to remember,
59
00:04:11.365 --> 00:04:15.710
or through tip and dot me, if you wanna just do a regular lightning payment.
60
00:04:17.050 --> 00:04:22.670
As you know, I appreciate you guys. You guys you guys make it what it is. Awesome. Nix Bitcoin just joined us
61
00:04:23.035 --> 00:04:25.215
just in time for me to finish up my intro.
62
00:04:25.835 --> 00:04:26.975
Today, we have,
63
00:04:27.835 --> 00:04:30.815
Jonas joining us, Nickler on Twitter.
64
00:04:32.190 --> 00:04:36.450
He works with Blockstream for research, and he's been a contributor to Nix Bitcoin.
65
00:04:37.070 --> 00:04:39.169
We have Vivek here, good friend,
66
00:04:39.695 --> 00:04:44.275
who helped set up this conversation. Always appreciate him. I just saw him in Austin.
67
00:04:45.055 --> 00:04:47.475
He is business development at Blockstream,
68
00:04:47.970 --> 00:04:51.350
and we have the lead maintainer of Nix Bitcoin himself,
69
00:04:53.490 --> 00:04:59.985
that goes by Nix Bitcoin Dev. So I'm just gonna be calling him Nix for the remainder of the show. How's it going, guys?
70
00:05:01.485 --> 00:05:02.625
Great. Great.
71
00:05:03.645 --> 00:05:04.865
72
00:05:05.565 --> 00:05:06.065
73
00:05:07.050 --> 00:05:07.550
74
00:05:08.890 --> 00:05:09.390
75
00:05:09.850 --> 00:05:10.590
you wanna
76
00:05:11.050 --> 00:05:14.350
you wanna say hi to the freaks? Let's see if your audio is horrible still.
77
00:05:16.355 --> 00:05:17.175
78
00:05:18.115 --> 00:05:19.975
Hi, freaks. Hi, everybody.
79
00:05:20.435 --> 00:05:21.955
80
00:05:23.150 --> 00:05:31.570
81
00:05:32.045 --> 00:05:33.585
complicated. I just
82
00:05:33.885 --> 00:05:36.305
figured it out how out on GrapheneOS.
83
00:05:37.005 --> 00:05:41.440
84
00:05:41.920 --> 00:05:43.780
So, I mean, we're gonna focus here
85
00:05:44.240 --> 00:05:46.900
to start with, we're gonna focus on NYX and NYX Bitcoin.
86
00:05:47.600 --> 00:05:52.125
And then the conversation is we're gonna take it, you know, we're gonna go wider with it.
87
00:05:52.585 --> 00:05:54.685
This will be a more technical conversation,
88
00:05:56.264 --> 00:06:00.200
but that's how we like it here on dispatch. Just a reminder that,
89
00:06:00.820 --> 00:06:11.395
this conversation builds on the conversation we had with Andrew Chow and Craig Raw on reproducible builds and building from software, which was still dispatch 37. So if you haven't listened to that, consider,
90
00:06:12.335 --> 00:06:15.155
listening to that after this live show. Don't leave us.
91
00:06:16.300 --> 00:06:24.080
So I think a a good place to start here is is what is Nix OS, and, you know, why should we care as Bitcoiners that it exists?
92
00:06:26.415 --> 00:06:28.115
93
00:06:28.415 --> 00:06:34.250
94
00:06:34.789 --> 00:06:41.050
that I know it's super confusing, but Nix Bitcoin Dev is not the lead maintainer of Nix Bitcoin.
95
00:06:42.875 --> 00:06:43.375
96
00:06:43.755 --> 00:06:46.975
97
00:06:48.555 --> 00:06:50.575
Brutal. I'm just saying this so the responsibilities
98
00:06:50.955 --> 00:07:01.175
99
00:07:01.795 --> 00:07:02.755
100
00:07:03.475 --> 00:07:05.895
101
00:07:06.355 --> 00:07:07.975
102
00:07:08.600 --> 00:07:09.979
NYX Bitcoin was actually
103
00:07:10.360 --> 00:07:17.580
how I started to really get into programming with Jonas back in the day, so I didn't have any better ideas. And
104
00:07:18.125 --> 00:07:21.025
I just picked the purpose built nickname, I guess.
105
00:07:21.645 --> 00:07:27.910
Also, back then, I was into samurai, and one of the devs there is samurai devs, so I just thought I'd go with
106
00:07:31.750 --> 00:07:37.450
107
00:07:39.795 --> 00:07:40.835
Perhaps it's
108
00:07:41.395 --> 00:07:42.055
I guess,
109
00:07:43.235 --> 00:07:46.375
it goes a bit too deep if we already start with NextOS.
110
00:07:46.849 --> 00:07:51.190
Perhaps we should first talk about Nix Bitcoin because if you use Nix
111
00:07:51.569 --> 00:07:52.069
Bitcoin
112
00:07:52.530 --> 00:07:53.030
in
113
00:07:53.490 --> 00:07:55.750
the way that is documented in the repository,
114
00:07:56.384 --> 00:07:59.604
you don't have to deal that much with NextOS.
115
00:07:59.905 --> 00:08:01.604
You earn all the benefits, but
116
00:08:03.460 --> 00:08:11.480
you don't have to to learn everything about NixOS. So Nix Bitcoin is a node project, you could call it. Perhaps,
117
00:08:12.285 --> 00:08:13.905
people know what that is from,
118
00:08:14.605 --> 00:08:15.105
raspiblitzes
119
00:08:16.365 --> 00:08:17.425
and Umbrell
120
00:08:17.725 --> 00:08:18.225
and,
121
00:08:19.085 --> 00:08:21.949
Noble and whatever else is there. And,
122
00:08:23.229 --> 00:08:24.610
I started this project,
123
00:08:25.069 --> 00:08:26.210
in November
124
00:08:26.669 --> 00:08:27.169
2018,
125
00:08:28.909 --> 00:08:30.930
because I guess as many people,
126
00:08:31.455 --> 00:08:34.915
I just set up too many Bitcoin notes in my life
127
00:08:35.615 --> 00:08:36.995
already at that point.
128
00:08:37.455 --> 00:08:42.580
And now I would at that time, I wanted to set up a new one just for lightning.
129
00:08:44.640 --> 00:08:47.300
And then I thought, man, there must be a more
130
00:08:47.625 --> 00:08:52.524
systematic way to do this. Like, how can we do this? We could write shell scripts or whatever,
131
00:08:52.985 --> 00:08:53.485
but
132
00:08:54.400 --> 00:08:58.500
I don't like this. I want I wanted to have a systematic way
133
00:08:58.960 --> 00:08:59.460
that's,
134
00:09:00.480 --> 00:09:01.860
also easily extensible
135
00:09:02.160 --> 00:09:04.955
in the future. And then I remembered my colleague,
136
00:09:05.975 --> 00:09:07.035
Russell O'Connor,
137
00:09:08.055 --> 00:09:10.795
who's working on simplicity at Blockstream.
138
00:09:11.380 --> 00:09:15.000
He gave a presentation at a a Blockstream off-site on NixOS.
139
00:09:16.260 --> 00:09:18.600
And, I thought, well, maybe NixOS
140
00:09:19.065 --> 00:09:21.565
is is a thing that we could build this on.
141
00:09:22.425 --> 00:09:26.365
And I started doing that mostly just published my own node configuration,
142
00:09:26.745 --> 00:09:27.245
basically.
143
00:09:30.079 --> 00:09:32.899
And, then Nick's Bitcoin dev started contributing,
144
00:09:33.279 --> 00:09:36.019
started running it on his note, and then
145
00:09:36.334 --> 00:09:45.235
more people started contributing. So we have, like, 3 regular contributors now, I would say, with with Eric Arstead and a couple of drive by contributors
146
00:09:46.690 --> 00:09:50.550
and a few users that even use that for for their infrastructure.
147
00:09:52.770 --> 00:09:55.785
Okay. So now to get to the question, what is NixOS?
148
00:09:57.845 --> 00:10:03.385
When I started this project, I said I I just shared my own configuration.
149
00:10:04.440 --> 00:10:07.900
What that means is that I basically I had this Nixo system,
150
00:10:08.440 --> 00:10:12.380
an operating system, and I was able to share this whole configuration
151
00:10:13.160 --> 00:10:15.375
in a GitHub repository
152
00:10:16.155 --> 00:10:17.935
so people could clone this repository
153
00:10:18.475 --> 00:10:18.975
and
154
00:10:19.915 --> 00:10:22.735
rebuild the exact same operating system
155
00:10:23.079 --> 00:10:24.139
that I was running.
156
00:10:24.839 --> 00:10:25.339
And
157
00:10:26.200 --> 00:10:29.339
this is the power of Nixos, basically,
158
00:10:31.265 --> 00:10:34.084
or or perhaps to to to go into this a bit more
159
00:10:34.865 --> 00:10:35.365
systematically,
160
00:10:39.080 --> 00:10:41.100
NixOS is a declarative
161
00:10:41.560 --> 00:10:42.620
operating system.
162
00:10:43.080 --> 00:10:43.580
K?
163
00:10:45.745 --> 00:10:50.004
Regularly I guess, regular users when they work with their operating system,
164
00:10:50.625 --> 00:10:53.524
either they have a MacBook or whatever.
165
00:10:53.880 --> 00:10:55.980
And if they want to change some setting,
166
00:10:56.839 --> 00:10:58.700
they go into their system,
167
00:10:59.560 --> 00:11:03.019
settings and change their setting and click apply,
168
00:11:03.555 --> 00:11:05.335
and then the setting is changed.
169
00:11:07.155 --> 00:11:11.655
Similarly, if you work on a server, you SSH into the server, you change your
170
00:11:12.170 --> 00:11:12.670
HTTPD
171
00:11:13.050 --> 00:11:13.550
configuration,
172
00:11:14.810 --> 00:11:16.509
and, restart the service,
173
00:11:16.810 --> 00:11:17.550
and then,
174
00:11:17.930 --> 00:11:18.430
your
175
00:11:18.970 --> 00:11:19.470
change
176
00:11:20.305 --> 00:11:21.125
takes effect.
177
00:11:22.465 --> 00:11:24.645
NextOS is different. In NextOS,
178
00:11:25.025 --> 00:11:29.045
you have a configuration file that specifies the whole system.
179
00:11:30.620 --> 00:11:31.120
It
180
00:11:31.899 --> 00:11:32.399
tells
181
00:11:32.700 --> 00:11:33.200
Nix
182
00:11:33.579 --> 00:11:41.745
OS how the system is supposed to look like in the end, and Nix OS is responsible for building the system. So you write the configuration file,
183
00:11:42.365 --> 00:11:43.585
and then you say
184
00:11:44.125 --> 00:11:48.385
okay. The the the command, sounds a bit weird, but it's called NixOS rebuild switch.
185
00:11:49.020 --> 00:11:53.840
And then your system, your operating system, will be built based on this configuration file.
186
00:11:54.620 --> 00:11:55.120
Yeah.
187
00:11:55.500 --> 00:11:57.040
So this is, like, the basic
188
00:11:57.665 --> 00:11:58.404
next stuff.
189
00:11:58.705 --> 00:12:00.325
It has a few other advantages.
190
00:12:00.785 --> 00:12:04.084
But, what next Bitcoin now adds is
191
00:12:04.600 --> 00:12:05.980
you have simple options
192
00:12:06.280 --> 00:12:06.780
for,
193
00:12:08.520 --> 00:12:12.460
Bitcoin related things. So in your configuration, you can say,
194
00:12:13.875 --> 00:12:16.215
bitcoin d dot enable equals true
195
00:12:17.635 --> 00:12:20.695
or bitcoin d dot port equals 8336
196
00:12:22.900 --> 00:12:25.800
or c lightning enable equals true and,
197
00:12:26.820 --> 00:12:29.400
a lot of other modules that that we maintain.
198
00:12:30.315 --> 00:12:30.815
And,
199
00:12:31.515 --> 00:12:38.975
you don't have to SSH into your system or whatever, download certain things. You only have to add this option.
200
00:12:39.790 --> 00:12:40.029
And,
201
00:12:41.870 --> 00:12:44.209
that way, you can you can build that system.
202
00:12:44.589 --> 00:12:49.175
203
00:12:49.575 --> 00:12:51.595
multiple nodes and services
204
00:12:51.975 --> 00:12:52.714
all in
205
00:12:53.175 --> 00:12:53.675
one,
206
00:12:54.535 --> 00:12:55.195
I guess,
207
00:12:55.735 --> 00:12:56.235
software?
208
00:12:57.350 --> 00:12:58.730
209
00:12:59.510 --> 00:13:01.769
yes, because it's also a text file.
210
00:13:02.709 --> 00:13:03.209
But
211
00:13:03.735 --> 00:13:06.475
if you've looked at a Bitcoin configuration file,
212
00:13:08.935 --> 00:13:12.635
it has a very simple structure. Right? It just says,
213
00:13:14.019 --> 00:13:15.480
prune equals 550
214
00:13:16.740 --> 00:13:18.279
or listen equals 1.
215
00:13:19.860 --> 00:13:22.040
But the configuration files
216
00:13:22.725 --> 00:13:23.464
in NextOS
217
00:13:23.765 --> 00:13:26.265
are written in the Nix language.
218
00:13:27.445 --> 00:13:30.185
So that means that you write your configuration
219
00:13:31.260 --> 00:13:32.880
in a programming language,
220
00:13:33.340 --> 00:13:34.800
which means that you have
221
00:13:35.420 --> 00:13:43.205
a lot of advantages in writing your configuration because you can write your configuration in a very powerful way. You can for example, you can define variables.
222
00:13:44.865 --> 00:13:47.205
Yeah. You can reuse code.
223
00:13:48.330 --> 00:13:48.990
You can
224
00:13:49.690 --> 00:13:54.750
you can do all these things. You have types, so you don't mess up ports with strings, etcetera.
225
00:13:55.735 --> 00:13:57.995
So that is really one of the main advantages,
226
00:13:58.695 --> 00:14:04.315
for me why why I think next Nixo is really is the systematic way to build infrastructure.
227
00:14:05.069 --> 00:14:08.769
228
00:14:09.310 --> 00:14:16.285
in the, configuration dot mix right now. It's all nicely documented. So most of what a new user would be doing
229
00:14:16.745 --> 00:14:17.245
is,
230
00:14:17.785 --> 00:14:27.730
commenting out single lines, just removing the hashtag sign from that line. So it's definitely on par with usability of a bitcoin.com
231
00:14:28.110 --> 00:14:30.209
file, if not even easier, I'd say.
232
00:14:30.775 --> 00:14:35.675
233
00:14:36.135 --> 00:14:39.575
functional programming language? Like, how does it differ from,
234
00:14:40.269 --> 00:14:43.570
object oriented programming? Like, what is, functional?
235
00:14:48.084 --> 00:14:50.985
236
00:14:51.365 --> 00:14:53.225
So you generally don't have
237
00:14:53.685 --> 00:14:55.704
variables that could change,
238
00:14:56.564 --> 00:14:57.464
their values.
239
00:14:59.290 --> 00:15:06.270
You basically just have constants. You have an input, and then you have functions operating on that input to produce an output.
240
00:15:06.775 --> 00:15:08.315
So in the case of,
241
00:15:08.855 --> 00:15:09.355
NextOS,
242
00:15:09.895 --> 00:15:14.475
your input is a configuration file. Your output is a running system.
243
00:15:18.520 --> 00:15:20.360
244
00:15:20.839 --> 00:15:22.220
because it's functional,
245
00:15:23.080 --> 00:15:28.195
it's re reproducible as well, and then every dependency also has a shawesome,
246
00:15:28.735 --> 00:15:29.555
and you can
247
00:15:30.175 --> 00:15:33.235
all rebuild the exact same packages. Is this correct?
248
00:15:34.120 --> 00:15:40.380
249
00:15:40.840 --> 00:15:42.780
I mean, the functional aspect
250
00:15:43.715 --> 00:15:45.975
mainly helps you deal with complexity
251
00:15:46.275 --> 00:15:53.170
because you're not going to write spaghetti code because you're not able to, basically. You can only write functions,
252
00:15:53.630 --> 00:15:54.930
which should be relatively,
253
00:15:55.870 --> 00:15:56.370
simple.
254
00:15:58.990 --> 00:16:01.810
But as you said, what Nix also provides you,
255
00:16:03.455 --> 00:16:06.815
k, perhaps it's a good time now to talk about,
256
00:16:07.135 --> 00:16:10.915
257
00:16:11.312 --> 00:16:16.629
258
00:16:17.009 --> 00:16:19.915
of all time because we have Eric Arstead
259
00:16:20.295 --> 00:16:23.995
in our team who goes through every pull request meticulously,
260
00:16:24.855 --> 00:16:26.395
fixes every point,
261
00:16:27.700 --> 00:16:28.200
refactors
262
00:16:28.580 --> 00:16:31.960
the whole code base at least monthly.
263
00:16:32.900 --> 00:16:33.400
So
264
00:16:34.005 --> 00:16:38.185
265
00:16:38.725 --> 00:16:39.125
266
00:16:40.165 --> 00:16:41.144
first of all,
267
00:16:41.605 --> 00:16:47.660
to the freaks, as always, I mean, feel free to put questions in the live chat. We will get to your questions.
268
00:16:48.840 --> 00:16:53.555
I will also probably be asking questions that you're thinking of without necessarily
269
00:16:53.935 --> 00:16:57.795
verbalizing them because a lot of this is over my head, and I'm learning as well,
270
00:16:58.175 --> 00:16:59.955
which are my favorite types of conversation.
271
00:17:01.390 --> 00:17:01.890
To
272
00:17:02.589 --> 00:17:08.610
to to start here, if if you're just an average freak and you're running let's say, you're running a Raspberry Pi blitz
273
00:17:09.195 --> 00:17:11.135
on a Raspberry Pi,
274
00:17:12.795 --> 00:17:16.735
and you want to you want to try nix Bitcoin out,
275
00:17:18.360 --> 00:17:29.034
It doesn't run on a Raspberry Pi. Correct? You need you need different hardware, and, like, how how does that start pro like, how does that let walk us through setting up your your Nix Bitcoin node.
276
00:17:29.654 --> 00:17:34.235
277
00:17:35.130 --> 00:17:38.110
Jonas' brother has it running on Raspberry Pi. Yeah.
278
00:17:38.809 --> 00:17:39.630
And, also,
279
00:17:40.730 --> 00:17:44.655
it's very easy to start working with Nix Bitcoin because of,
280
00:17:45.135 --> 00:17:51.955
the container and the M code that Eric in large part wrote, which allows you to basically start up
281
00:17:52.460 --> 00:17:58.000
a a Nix Bitcoin node on your own laptop to start playing with it. And once you wanna go
282
00:17:58.300 --> 00:18:00.320
build a 247 running node,
283
00:18:00.735 --> 00:18:01.475
you just get
284
00:18:02.255 --> 00:18:04.195
a off the shelf, stand alone,
285
00:18:04.815 --> 00:18:09.075
either single board computer or a real, you know, beefy server, and
286
00:18:09.490 --> 00:18:11.350
follow the install dotmd,
287
00:18:12.450 --> 00:18:16.950
and you should be running a Bitcoin node without any major issues.
288
00:18:20.985 --> 00:18:23.385
289
00:18:24.505 --> 00:18:28.720
the Nix Bitcoin tutorial would tell you to do essentially is
290
00:18:29.660 --> 00:18:35.440
to install Nix OS on your target platform, which could be Raspberry Pi, Intel NUC,
291
00:18:35.980 --> 00:18:36.480
or
292
00:18:36.845 --> 00:18:38.545
some people run it on an APUC
293
00:18:39.085 --> 00:18:41.165
4, I think it's called. And,
294
00:18:41.805 --> 00:18:46.929
we have a list of of hardware in the in the Readme. So, So basically you install NextOS there,
295
00:18:47.789 --> 00:18:50.610
and then you can, from your personal computer,
296
00:18:50.990 --> 00:18:53.250
you can deploy then the next Bitcoin
297
00:18:53.789 --> 00:18:54.289
system
298
00:18:54.894 --> 00:18:57.475
on this blank Nix OS,
299
00:18:57.934 --> 00:18:58.434
machine.
300
00:19:03.679 --> 00:19:10.820
301
00:19:11.335 --> 00:19:17.995
302
00:19:18.480 --> 00:19:20.659
one of the examples, which would automatically
303
00:19:21.519 --> 00:19:26.899
run-in a VM or in a container. The only requirement there is that you have,
304
00:19:27.495 --> 00:19:29.675
the NIX package manager installed
305
00:19:30.215 --> 00:19:34.930
on, on this machine where you're running this. And perhaps I should mention that
306
00:19:35.310 --> 00:19:37.570
before you deploy Next Bitcoin,
307
00:19:38.350 --> 00:19:47.195
you go into the example folder, and there you have a configuration dot nix. And that's the example configuration dot nix, which has documentation
308
00:19:47.654 --> 00:19:50.394
and, like, has a lot of, options,
309
00:19:51.335 --> 00:19:52.315
commented out.
310
00:19:52.890 --> 00:19:55.150
So you can just remove the
311
00:19:56.090 --> 00:19:57.150
the pound symbol
312
00:19:57.610 --> 00:19:59.870
and, activate things like
313
00:20:00.235 --> 00:20:02.415
lightning c lightning or lnd,
314
00:20:04.155 --> 00:20:04.815
or whatever.
315
00:20:05.115 --> 00:20:06.415
316
00:20:06.875 --> 00:20:17.605
317
00:20:18.305 --> 00:20:18.805
organization.
318
00:20:19.105 --> 00:20:21.285
And the second repo there is nixbitcoin.org,
319
00:20:22.145 --> 00:20:26.085
which actually gives you the full server configuration of our own,
320
00:20:26.880 --> 00:20:28.500
internal project node,
321
00:20:29.759 --> 00:20:32.179
and that will give you a really nice,
322
00:20:33.679 --> 00:20:36.774
quick example of how a basic setup would look like.
323
00:20:39.715 --> 00:20:40.215
324
00:20:40.835 --> 00:20:42.695
Okay. So before we get deeper,
325
00:20:45.480 --> 00:20:50.220
I I'm running raspi blitz. Right? A lot of the freaks are running raspi blitz.
326
00:20:52.005 --> 00:20:52.985
The main advantages
327
00:20:53.525 --> 00:20:58.105
of switching to Nix Bitcoin, or at least testing it out and considering a switch,
328
00:20:58.885 --> 00:20:59.625
is that
329
00:21:01.060 --> 00:21:02.440
it is more transparent
330
00:21:02.900 --> 00:21:03.960
what you are running,
331
00:21:05.060 --> 00:21:05.560
and
332
00:21:06.500 --> 00:21:11.875
it is ideally a more secure setup all said and done. Would you agree with those two comments?
333
00:21:14.095 --> 00:21:22.720
334
00:21:24.725 --> 00:21:27.465
Yeah. So, I mean, I started off just,
335
00:21:27.845 --> 00:21:28.825
you know, in 2017,
336
00:21:29.205 --> 00:21:31.605
just like a lot of the freaks, a complete pleb.
337
00:21:32.005 --> 00:21:37.140
It it's only because of UASF, I finally ran a node, but it was pitiful because I didn't know how to verify
338
00:21:37.520 --> 00:21:43.054
my own transactions because, you know, I was still in the trying to decentralize the network mentality or whatever.
339
00:21:43.595 --> 00:21:45.934
For fast forward to 2018 where,
340
00:21:46.554 --> 00:21:50.520
you know, I was fortunate enough to attend Ellen Hackday,
341
00:21:51.540 --> 00:21:52.040
Rutsal,
342
00:21:53.140 --> 00:21:55.080
Jonas's younger brother, Constantine,
343
00:21:56.025 --> 00:21:57.245
Murch, Renee,
344
00:21:58.185 --> 00:21:58.585
and,
345
00:21:59.305 --> 00:22:01.165
Jeff, also, you know, FOMO.
346
00:22:01.465 --> 00:22:02.125
They were
347
00:22:02.425 --> 00:22:07.060
very kind to, like, have patience and explain to me how to run a raspy blitz,
348
00:22:07.440 --> 00:22:11.280
storing the seed, everything like that. And that's where I finally learned,
349
00:22:11.680 --> 00:22:16.705
simultaneously, this is around the time that, Pierre Richard put out his node launcher.
350
00:22:17.005 --> 00:22:18.385
So all this was fantastic.
351
00:22:19.404 --> 00:22:20.385
It's really cool.
352
00:22:20.910 --> 00:22:21.150
But,
353
00:22:21.790 --> 00:22:23.630
going forward, I wanted to,
354
00:22:23.950 --> 00:22:26.850
have a node just like Jonas mentioned that
355
00:22:27.390 --> 00:22:28.690
I don't have to,
356
00:22:29.630 --> 00:22:30.450
figure out,
357
00:22:30.865 --> 00:22:32.005
like, necessarily
358
00:22:32.865 --> 00:22:36.705
what broke if something did break in, my package manager.
359
00:22:37.425 --> 00:22:42.620
This recently happened to me as something as simple as, like, with Homebrew
360
00:22:43.000 --> 00:22:48.375
PIP and trying to get a Jupyter Notebook to work for a Jimmy Song's book on a MacBook.
361
00:22:48.835 --> 00:22:49.235
So,
362
00:22:49.715 --> 00:22:58.360
that that mentality kinda stuck with me where I want something that I figure out once that's a config file that I could kinda keep handy somewhere,
363
00:22:58.740 --> 00:23:01.320
and I could just, use that same config
364
00:23:01.780 --> 00:23:04.120
to almost rebuild the exact node.
365
00:23:04.684 --> 00:23:08.465
And, that's when, you know, Jonas helped me through this a bit more.
366
00:23:08.845 --> 00:23:10.544
And, it was intriguing because,
367
00:23:11.085 --> 00:23:11.985
there's also,
368
00:23:12.780 --> 00:23:15.600
quote, unquote, atomic rollbacks in this,
369
00:23:15.900 --> 00:23:20.560
where if something were to break, then I could just go back to the last build that worked.
370
00:23:20.894 --> 00:23:22.514
So for these certain reasons,
371
00:23:23.375 --> 00:23:29.075
I thought, you know, it was worth the steep learning curve to proceed down this path.
372
00:23:30.940 --> 00:23:31.500
373
00:23:32.780 --> 00:23:33.280
my
374
00:23:33.900 --> 00:23:34.960
note journey was
375
00:23:35.340 --> 00:23:38.460
pretty much the exact same, only that it was paired with my,
376
00:23:39.605 --> 00:23:42.985
paranoia, which made me use Deviant from the get go.
377
00:23:43.605 --> 00:23:52.425
But I always had a huge issue also with maintaining such a node because you constantly have to SSH in and and change things. And
378
00:23:52.850 --> 00:23:53.669
yeah. So
379
00:23:54.505 --> 00:23:57.085
at some point and I was always using Electrum,
380
00:23:58.265 --> 00:24:03.005
with it, and at some point, the Electrum server project went all b cache,
381
00:24:03.350 --> 00:24:10.090
and I decided to trash that node and start working with Jonas. And, my first thing was the Electrum Rust server.
382
00:24:11.245 --> 00:24:14.225
And from there we just kept on improving it and,
383
00:24:14.765 --> 00:24:18.865
from my side, I think I brought a lot of the security conscious
384
00:24:19.320 --> 00:24:22.220
thinking into it, and we have some security features
385
00:24:22.680 --> 00:24:31.725
right now and NEX Bitcoin will get into it probably in-depth later that I haven't seen anywhere else, and especially not with other Bitcoin nodes.
386
00:24:32.345 --> 00:24:33.965
So that's a major advantage.
387
00:24:36.620 --> 00:24:38.080
388
00:24:38.860 --> 00:24:43.680
everything is kind of moving in that trajectory. Right? Even with Bitcoin Core
389
00:24:44.215 --> 00:24:45.835
and, having bootstrappable
390
00:24:46.135 --> 00:24:47.655
builds as Carl Dong,
391
00:24:48.375 --> 00:24:55.560
has brought up with Geeks, you know, everyone's trying to figure out a much more methodical approach to these sort of things.
392
00:24:59.035 --> 00:24:59.355
But
393
00:25:00.075 --> 00:25:04.895
394
00:25:06.080 --> 00:25:11.380
I would say I'm on a similar journey, but I just haven't discovered NYX Bitcoin yet, so
395
00:25:11.760 --> 00:25:13.059
my journey stops there.
396
00:25:14.215 --> 00:25:19.815
397
00:25:20.135 --> 00:25:24.440
first of all, they're they want freedom and also they want their funds to stay secure.
398
00:25:24.740 --> 00:25:27.640
I think the learning curve is more than worth,
399
00:25:28.980 --> 00:25:30.120
taking up because,
400
00:25:30.885 --> 00:25:37.225
I can get into very in detail the advantages, but I've looked at some of the other code. And this is not to,
401
00:25:37.684 --> 00:25:39.705
talk badly about the other node projects.
402
00:25:40.309 --> 00:25:51.635
But I've I've looked at the code and none of the security features we we and the work we put in, I see in the other node. Plus it's more spaghetti code which always yields insecurity.
403
00:25:52.495 --> 00:25:55.075
So what Jonas also said with shell scripting,
404
00:25:55.855 --> 00:25:59.020
it and what you also said, Matt, about, you know,
405
00:25:59.320 --> 00:26:01.020
transparency and system configuration,
406
00:26:01.400 --> 00:26:11.955
I think that's already half of security there is knowing exactly what runs on your node and having just really what you absolutely need running there. No unnecessary
407
00:26:12.335 --> 00:26:13.475
ports, no unnecessary
408
00:26:13.775 --> 00:26:15.075
print servers whatsoever.
409
00:26:15.820 --> 00:26:30.135
And I think you can't get that with a shell script in the same way that you can with MixOS. I like to give the example that when I started working with Vivian, I tried to install de install every single package before I set up my Bitcoin node, which
410
00:26:30.675 --> 00:26:32.855
every single time broke the entire system.
411
00:26:33.360 --> 00:26:33.860
So
412
00:26:35.280 --> 00:26:37.780
I I can say from experience that Nix OS
413
00:26:38.480 --> 00:26:38.980
offers
414
00:26:39.280 --> 00:26:40.660
security conscious users
415
00:26:40.985 --> 00:26:45.804
something that no other node project does. Also privacy wise, we have everything,
416
00:26:46.904 --> 00:26:50.284
locked behind Tor on multiple levels on the
417
00:26:50.890 --> 00:26:54.350
individual application level, on the system d service level, and,
418
00:26:55.130 --> 00:27:07.340
even on a network namespace level. We'll get into that later. Sure. But from a privacy perspective also, you don't want some mistake to leak your personal information out to the world and
419
00:27:07.720 --> 00:27:09.580
this financial stuff is very sensitive,
420
00:27:10.600 --> 00:27:12.140
personal information. So
421
00:27:12.520 --> 00:27:16.655
I'm very I feel very safe with mixed Bitcoin because
422
00:27:17.195 --> 00:27:19.295
everything has multiple layers of security,
423
00:27:19.675 --> 00:27:23.295
which are all very transparently laid out and reviewed constantly.
424
00:27:23.950 --> 00:27:26.130
425
00:27:27.070 --> 00:27:28.370
historically speaking,
426
00:27:29.630 --> 00:27:30.930
Bitcoin node security
427
00:27:33.435 --> 00:27:36.795
was mostly focused on the privacy level, like you said,
428
00:27:37.595 --> 00:27:40.895
because when we use a traditional Bitcoin node,
429
00:27:41.195 --> 00:27:41.695
with
430
00:27:42.220 --> 00:27:45.840
on chain Bitcoin, your keys aren't held on the node.
431
00:27:47.260 --> 00:27:59.740
So you you have privacy risk, but if someone compromises your node, it's, you know, not the end of the world in terms of actually losing funds. But now that lightning is in play and we have these hot wallets with the growing amount of money in them,
432
00:28:00.380 --> 00:28:02.240
that are always connected to the Internet,
433
00:28:02.700 --> 00:28:05.840
you know, security has become way more important,
434
00:28:06.300 --> 00:28:10.935
from from my perspective and I assume from from most Bitcoiners' perspectives.
435
00:28:11.315 --> 00:28:17.415
And, also, on top of that, the fact that with Lightning, there's no really easy way to back up.
436
00:28:19.630 --> 00:28:20.450
You have
437
00:28:20.990 --> 00:28:24.290
this situation where reliability becomes really important,
438
00:28:24.670 --> 00:28:27.535
where where you you need to be able to count on your node.
439
00:28:28.095 --> 00:28:38.150
You wanna have as much uptime as possible, and you don't want anything to get corrupted or have any kind of issues in that regard. So I mean That's also a unique advantage of mixed Bitcoin
440
00:28:38.450 --> 00:28:39.670
441
00:28:40.130 --> 00:28:43.830
goes all the way down from a Raspberry Pi to a ZFS
442
00:28:44.450 --> 00:28:44.950
enabled,
443
00:28:46.485 --> 00:28:46.985
redundant
444
00:28:47.365 --> 00:28:49.625
power supply enterprise server.
445
00:28:50.165 --> 00:28:58.580
And the same review work we put into the Raspberry Pi and the same knowledge we get back from users of the Raspberry Pi goes into the enterprise,
446
00:28:59.360 --> 00:29:03.700
no, node and vice versa. And I think this having this approach,
447
00:29:04.975 --> 00:29:14.480
maximizes the improvements you make on the node and that's what it's really about. It's learning from mistakes and reviewing and having transparent code that you can fix easily and constantly.
448
00:29:15.820 --> 00:29:17.840
449
00:29:18.220 --> 00:29:20.160
important point. I think
450
00:29:21.185 --> 00:29:24.725
nix Bitcoin can only focus on security
451
00:29:26.545 --> 00:29:27.045
because,
452
00:29:28.700 --> 00:29:29.200
NixOS
453
00:29:29.900 --> 00:29:35.520
is the methodical way to set up a system. Because the the goal
454
00:29:36.295 --> 00:29:39.115
of next Bitcoin is to manage complexity,
455
00:29:39.575 --> 00:29:40.075
essentially.
456
00:29:40.615 --> 00:29:44.555
And if you add things up to a running system, it will get
457
00:29:45.190 --> 00:29:45.690
exponentially
458
00:29:45.990 --> 00:29:47.210
comp more complex
459
00:29:47.510 --> 00:29:48.330
very quickly.
460
00:29:49.029 --> 00:29:53.610
So how do you add security to such a system? You will have holes.
461
00:29:54.485 --> 00:29:54.985
You
462
00:29:55.445 --> 00:29:56.425
it's unavoidable.
463
00:29:57.205 --> 00:29:57.705
So
464
00:29:58.005 --> 00:30:00.905
what we really try to do is keep this
465
00:30:02.559 --> 00:30:05.299
as simple as possible, and we do that,
466
00:30:05.840 --> 00:30:08.179
which I tried to explain earlier
467
00:30:08.639 --> 00:30:09.139
by
468
00:30:09.825 --> 00:30:11.285
basically using the concepts
469
00:30:12.625 --> 00:30:13.365
of abstraction
470
00:30:13.745 --> 00:30:14.645
and reusability
471
00:30:15.105 --> 00:30:17.445
of code because you treat your infrastructure
472
00:30:18.340 --> 00:30:20.600
as code. You treat your server
473
00:30:20.900 --> 00:30:21.720
as code.
474
00:30:22.260 --> 00:30:22.500
And,
475
00:30:23.060 --> 00:30:25.400
because it is code, it can be reviewed
476
00:30:25.780 --> 00:30:27.160
on GitHub, for example.
477
00:30:27.855 --> 00:30:29.955
I think this is what because otherwise,
478
00:30:30.255 --> 00:30:33.155
we wouldn't be able to set up a such a sophisticated,
479
00:30:34.415 --> 00:30:36.355
system as Nix Bitcoin
480
00:30:36.655 --> 00:30:38.500
with the three spare time contributors,
481
00:30:39.120 --> 00:30:39.620
basically.
482
00:30:44.640 --> 00:30:45.140
483
00:30:46.355 --> 00:30:58.909
Nick's Bitcoin dev kept saying you guys have additional security features in place that aren't in place in other node projects, and I said we could talk about it later. I feel like now is a great time to talk about it. What do you guys think? Okay.
484
00:30:59.210 --> 00:31:00.669
485
00:31:02.125 --> 00:31:03.505
486
00:31:03.885 --> 00:31:04.545
I think
487
00:31:05.085 --> 00:31:09.485
the the thing that sold me even more on Nick's Bitcoin or Nick's OS was,
488
00:31:10.269 --> 00:31:13.570
the whole pseudo vulnerability that happened and how they,
489
00:31:14.029 --> 00:31:17.169
you know, they had duas. So they didn't necessarily
490
00:31:18.125 --> 00:31:19.745
go through that issue. I'd love to
491
00:31:20.205 --> 00:31:21.985
hear both of them elaborate on that.
492
00:31:22.765 --> 00:31:25.985
493
00:31:26.789 --> 00:31:28.250
First of all, Jonas,
494
00:31:29.270 --> 00:31:33.210
the reason why it took him such a long time to set up Bitcoin nodes,
495
00:31:33.915 --> 00:31:38.815
manually, I think, is because he always did it the right way, which means having one user per service,
496
00:31:39.195 --> 00:31:40.175
etcetera, etcetera.
497
00:31:41.390 --> 00:31:41.830
And,
498
00:31:42.270 --> 00:31:42.909
other mix
499
00:31:43.630 --> 00:31:47.730
other node projects don't have that. They run everything under one user, which makes it simple.
500
00:31:48.065 --> 00:31:50.965
But we don't do that, and we have every single
501
00:31:51.505 --> 00:31:52.005
service
502
00:31:52.945 --> 00:31:57.285
running under a different user with fine grained permissions between services
503
00:31:58.410 --> 00:32:01.790
when lightning loop needs to read certain things from LND,
504
00:32:02.970 --> 00:32:09.005
the service gets that permission but nothing more. So that's the very first step is using Linux properly.
505
00:32:09.625 --> 00:32:11.005
Then we go on to,
506
00:32:12.105 --> 00:32:13.325
system d which,
507
00:32:13.809 --> 00:32:18.149
you know, people have different opinions about it but in our use case, it made
508
00:32:18.769 --> 00:32:22.685
so many things easier that you have a long list of security features
509
00:32:23.165 --> 00:32:24.305
and even an
510
00:32:24.685 --> 00:32:28.065
tool, system d internal, which you can run over a service configuration.
511
00:32:28.605 --> 00:32:37.840
And it will tell you exactly what kind of hardening options still can enable, which are which ones are already enabled. And we just basically went through that list and turned on everything
512
00:32:38.300 --> 00:32:39.680
until something broke.
513
00:32:40.225 --> 00:32:43.365
And right now, that's the status we're still holding at, which is
514
00:32:44.065 --> 00:32:51.520
everything possible that system d offers in terms of hardening is enabled that goes from private route private temporary directories,
515
00:32:52.700 --> 00:32:53.200
firewalling
516
00:32:53.580 --> 00:32:54.880
on a service level,
517
00:32:56.745 --> 00:32:58.045
on and on. Just,
518
00:32:59.385 --> 00:33:00.445
privilege escalation
519
00:33:01.065 --> 00:33:03.085
protections which wouldn't exist.
520
00:33:06.090 --> 00:33:10.590
Normally, UNAS, probably can think of a lot, it's up around 30 or 40
521
00:33:10.890 --> 00:33:14.585
hardening settings. And then we go even further
522
00:33:14.965 --> 00:33:17.145
to the actual packages that are being used.
523
00:33:17.845 --> 00:33:22.380
Again, we have a extremely minimal foot footprint, whatever you enable in configuration.nix,
524
00:33:23.000 --> 00:33:26.220
only that and its dependencies are ever deployed to the node.
525
00:33:26.600 --> 00:33:27.100
And
526
00:33:27.400 --> 00:33:29.715
every package we maintain ourselves
527
00:33:30.495 --> 00:33:32.674
is GPG verified if possible,
528
00:33:33.135 --> 00:33:36.275
and, we're slowly bringing that into upstream as well,
529
00:33:37.545 --> 00:33:38.045
and,
530
00:33:38.880 --> 00:33:42.820
which is supply basically, taking care of supply chain vulnerabilities,
531
00:33:43.840 --> 00:33:47.540
but that's definitely the biggest construction site we still have.
532
00:33:48.045 --> 00:33:48.545
And,
533
00:33:50.125 --> 00:33:52.625
what else am I forgetting, Jonas, security wise?
534
00:33:53.245 --> 00:33:55.665
535
00:33:56.279 --> 00:33:58.840
I guess, atomic rollbacks are possible with,
536
00:34:00.200 --> 00:34:04.220
the way it's designed, essentially, with the next store versus the traditional, like,
537
00:34:04.794 --> 00:34:05.535
file system,
538
00:34:05.995 --> 00:34:07.215
hierarchical standard?
539
00:34:09.275 --> 00:34:12.095
540
00:34:14.650 --> 00:34:17.230
So what this rollback means is that,
541
00:34:18.090 --> 00:34:19.710
let's say you have your configuration.
542
00:34:20.535 --> 00:34:25.275
You make a change. You deploy it. You notice that your system doesn't work anymore.
543
00:34:27.175 --> 00:34:37.240
What can you do? Well, one thing is to just boot up. And in the boot screen of NextOS, just say, I don't wanna run the current revision. I want to,
544
00:34:37.640 --> 00:34:39.099
use an earlier deployment.
545
00:34:39.945 --> 00:34:42.445
And that way, you can make a rollback.
546
00:34:43.785 --> 00:34:45.085
How does that work?
547
00:34:46.940 --> 00:34:49.360
That goes into into the reproducibility
548
00:34:50.060 --> 00:34:54.000
aspect of, the Nix package manager and Nix OS,
549
00:34:54.620 --> 00:34:55.360
the system.
550
00:34:57.955 --> 00:34:58.695
And when
551
00:34:59.475 --> 00:35:01.735
when you read anything about reproducibility
552
00:35:03.660 --> 00:35:04.400
in the NextOS
553
00:35:04.780 --> 00:35:10.079
world, that's a different it's important to understand that that's a different definition of reproducibility
554
00:35:10.619 --> 00:35:12.240
that we usually use in Bitcoin.
555
00:35:14.115 --> 00:35:14.615
Reproducibility
556
00:35:15.474 --> 00:35:15.875
in,
557
00:35:17.315 --> 00:35:17.815
in,
558
00:35:18.355 --> 00:35:20.375
in the NICS world means that
559
00:35:21.234 --> 00:35:21.734
given
560
00:35:22.420 --> 00:35:31.400
some package, you know exactly what its dependencies are. You know the hash of the sources, let's say, the source code the hash of the source code itself
561
00:35:32.244 --> 00:35:33.065
and how,
562
00:35:33.925 --> 00:35:35.224
these various dependencies
563
00:35:35.525 --> 00:35:38.665
play together. That's all, like, everything is hashed, etcetera.
564
00:35:39.260 --> 00:35:43.040
Like, you could imagine, like, a big Merkle tree or something of of dependencies.
565
00:35:44.860 --> 00:35:47.920
But, that doesn't necessarily mean that the output
566
00:35:48.685 --> 00:35:57.105
is if if if I built the same package on 2 different system, that the output of this build, like a binary,
567
00:35:57.890 --> 00:36:00.310
has exactly the same bytes. Right?
568
00:36:01.010 --> 00:36:04.790
It has exactly the same dependency. It had its exactly the same source,
569
00:36:05.385 --> 00:36:09.964
but there may be differences on this system. For example, the current time or whatever
570
00:36:10.345 --> 00:36:11.165
that makes,
571
00:36:12.105 --> 00:36:14.204
the binary binaries different.
572
00:36:15.430 --> 00:36:19.609
There may be, like, a different byte at position x y z or or whatever.
573
00:36:21.190 --> 00:36:24.305
So that's, I think, important to understand. However,
574
00:36:25.245 --> 00:36:26.865
at least for the minimal
575
00:36:27.165 --> 00:36:28.225
NixOS system,
576
00:36:29.325 --> 00:36:30.065
the binaries
577
00:36:30.520 --> 00:36:37.820
are actually reproducible in the sense that we mean in in the Bitcoin world. So that that's, I think, also an important aspect.
578
00:36:38.555 --> 00:36:39.694
So this reproducibility
579
00:36:40.155 --> 00:36:42.335
allows you also to roll back because,
580
00:36:43.994 --> 00:36:45.214
packages have dependencies,
581
00:36:45.515 --> 00:36:47.615
but also your current system
582
00:36:47.950 --> 00:36:50.850
consists of packages which have dependencies. So you can just,
583
00:36:51.470 --> 00:36:54.130
store what your current system is. And
584
00:36:55.444 --> 00:36:58.184
if you go back to a previous system, you know exactly
585
00:36:59.365 --> 00:37:02.265
the packages that were used to build the system.
586
00:37:03.080 --> 00:37:05.420
And you don't when I say exactly,
587
00:37:06.040 --> 00:37:11.660
you don't I don't mean that you know the location where these things are. I mean, you know exactly the hash
588
00:37:12.165 --> 00:37:13.545
of this specific
589
00:37:13.925 --> 00:37:14.905
package. Right?
590
00:37:16.965 --> 00:37:17.405
And,
591
00:37:17.845 --> 00:37:20.760
so this gives you this kind of reproducibility
592
00:37:21.380 --> 00:37:26.280
aspect, which I think in the security context makes sense because that way,
593
00:37:26.580 --> 00:37:27.720
you know exactly
594
00:37:28.180 --> 00:37:29.765
what you are running on the
595
00:37:30.805 --> 00:37:36.744
system. You know exactly you you have one hash, and that's your system, basically. And from that hash, you know,
596
00:37:37.350 --> 00:37:37.850
exactly
597
00:37:38.630 --> 00:37:47.625
how your system is set up and what packages were used. So if some package is bad, you know, if you're running it, if if you're using it, and you know
598
00:37:48.005 --> 00:37:49.865
also, hopefully, how to get rid of it.
599
00:37:53.365 --> 00:37:54.265
600
00:37:54.880 --> 00:37:55.860
kind of reproducibility
601
00:37:56.240 --> 00:37:57.140
that Jonas
602
00:37:57.600 --> 00:37:58.100
mentioned
603
00:37:58.560 --> 00:37:59.700
allows us to,
604
00:38:00.880 --> 00:38:01.380
make
605
00:38:01.745 --> 00:38:05.045
very deep changes in the operating system,
606
00:38:06.065 --> 00:38:06.565
but
607
00:38:07.105 --> 00:38:08.085
and make them,
608
00:38:08.625 --> 00:38:12.490
make you able to roll back from them. So I like to use as an example
609
00:38:12.870 --> 00:38:14.650
something I think which is unique
610
00:38:15.030 --> 00:38:18.410
to nix bitcoin probably in all operating system
611
00:38:19.405 --> 00:38:21.984
configurations, which is something called network namespaces.
612
00:38:22.685 --> 00:38:23.825
Usually on Linux,
613
00:38:24.205 --> 00:38:27.105
you have a local host and every service running
614
00:38:27.640 --> 00:38:32.940
opens a port on local host and every other service can just talk to that. Sometimes services have authentication
615
00:38:33.240 --> 00:38:34.859
like macaroons or passwords,
616
00:38:35.240 --> 00:38:42.705
but sometimes you can also just call up the service and start talking to it. And we really didn't like that in nixed Bitcoin,
617
00:38:43.325 --> 00:38:45.185
so we invented something
618
00:38:45.565 --> 00:38:46.545
using standard,
619
00:38:47.750 --> 00:38:48.250
Linux
620
00:38:48.589 --> 00:38:49.089
kernel,
621
00:38:50.270 --> 00:38:52.690
functionality called network namespaces, which
622
00:38:53.069 --> 00:38:56.645
allows you to put every service into its own little box
623
00:38:57.225 --> 00:38:57.725
and,
624
00:38:58.385 --> 00:39:06.180
and fire and gives you very fine grain firewall control over which box is allowed to talk with which other box. So for example,
625
00:39:06.560 --> 00:39:07.060
your,
626
00:39:07.680 --> 00:39:13.475
ride the lightning or spark wallet won't be able to talk to Electrum running on the same system.
627
00:39:14.975 --> 00:39:18.835
And this is something that goes really deep into the operating system,
628
00:39:19.210 --> 00:39:21.070
but because everything is reproducible
629
00:39:21.770 --> 00:39:22.590
in the way
630
00:39:22.970 --> 00:39:23.870
Jonas Jonas explained,
631
00:39:24.570 --> 00:39:27.855
you can switch back and forth from that and one day when you
632
00:39:28.155 --> 00:39:39.840
want this extra complexity, you can have it enabled, and the next day when you feel comfortable with running in local host, with running everything in local host, you can go back to that. And these kinds of deep changes
633
00:39:40.300 --> 00:39:42.160
wouldn't be possible with shell scripts.
634
00:39:45.145 --> 00:39:49.005
635
00:39:49.305 --> 00:39:51.964
I don't know much about these other node projects.
636
00:39:52.510 --> 00:39:54.690
From my perspective, they could also have that.
637
00:39:55.390 --> 00:39:58.690
I just can talk about what what Nix Bitcoin is doing.
638
00:39:59.070 --> 00:40:03.424
And and perhaps to to rephrase this, what NixBitcoin dev said about,
639
00:40:03.904 --> 00:40:05.365
about the network namespaces
640
00:40:05.825 --> 00:40:08.565
and since we're also on the topic of security features.
641
00:40:10.750 --> 00:40:21.285
So what you can you use Next Bitcoin, you enable Bitcoin d, c lightning, and Spark wallet, let's say. And Spark wallet is like a front end for for CLitening.
642
00:40:22.545 --> 00:40:22.785
So
643
00:40:23.345 --> 00:40:27.605
and your threat model is kind of that Spark Wallet is compromised. Okay?
644
00:40:28.589 --> 00:40:32.369
That's a problem because Spark Wallet has access to your c lightning
645
00:40:33.150 --> 00:40:35.650
node. Right? So it can spend your coins.
646
00:40:36.030 --> 00:40:36.849
That's bad.
647
00:40:37.395 --> 00:40:37.895
But,
648
00:40:38.835 --> 00:40:42.695
also bad is if if Spark somehow is able to access
649
00:40:43.075 --> 00:40:44.980
your Bitcoin node as well.
650
00:40:45.380 --> 00:40:48.920
Like, let's say there's some kind of supply chain attack on,
651
00:40:49.380 --> 00:40:51.060
on Spark Wallet. It's not
652
00:40:52.155 --> 00:40:58.575
it it doesn't seem too unlikely that something like this happens, then you really don't want Spark Wallet to access your Bitcoin.
653
00:40:59.115 --> 00:41:01.615
You don't even want Spark Wallet to see,
654
00:41:02.540 --> 00:41:06.080
your transactions, your Bitcoin transactions. That will be a privacy leak.
655
00:41:06.619 --> 00:41:12.545
You also don't want Spark Wallet to even know that there is a Bitcoin d running on the system,
656
00:41:13.085 --> 00:41:15.265
and that's why we have this,
657
00:41:15.964 --> 00:41:16.464
NetNS
658
00:41:16.845 --> 00:41:21.089
feature. Net, what you could you can imagine that this is like a network
659
00:41:21.390 --> 00:41:23.890
on the Nix Bitcoin system itself.
660
00:41:24.349 --> 00:41:28.625
So you give each service a different IP address, and then we have a router
661
00:41:29.005 --> 00:41:29.905
and a firewall
662
00:41:30.285 --> 00:41:32.785
inside Nix Bitcoin that makes sure
663
00:41:33.220 --> 00:41:34.440
that only services
664
00:41:34.820 --> 00:41:50.940
that are supposed to talk to each other even see each other. Right? Because they cannot just ping any arbitrary IP address. They can only ping the IP addresses they're supposed to talk to. So CLightning has an IP address, Bitcoin has an IP address, and Spark Wallet can only
665
00:41:51.240 --> 00:41:52.860
ping and connect to,
666
00:41:53.640 --> 00:41:54.140
clightening.
667
00:41:55.640 --> 00:42:00.215
668
00:42:01.875 --> 00:42:04.935
protection from IP address leaks because,
669
00:42:05.635 --> 00:42:08.920
if you have a certain option enabled, which is enabled by default,
670
00:42:09.780 --> 00:42:16.200
services are only allowed to connect out of their network namespace out of their box to the Tor, Rooter.
671
00:42:16.665 --> 00:42:17.805
So all connections,
672
00:42:18.585 --> 00:42:20.205
you can be sure from that service
673
00:42:20.665 --> 00:42:24.125
will either go through Tor or not go to the Internet at all.
674
00:42:25.640 --> 00:42:27.740
675
00:42:28.760 --> 00:42:29.660
there's Tor,
676
00:42:30.040 --> 00:42:33.580
also a way through WireGuard, and then now, I2p recently?
677
00:42:34.975 --> 00:42:35.715
678
00:42:36.335 --> 00:42:40.515
is, Bitcoin specific, but what was amazing about the whole I2p,
679
00:42:41.615 --> 00:42:42.115
feature
680
00:42:42.415 --> 00:42:43.075
is that
681
00:42:43.510 --> 00:42:44.010
enabling,
682
00:42:44.870 --> 00:42:46.170
I2p with Bitcoin
683
00:42:46.710 --> 00:42:48.890
was a 4 line diff in our code,
684
00:42:49.510 --> 00:42:52.330
which is amazing if you think about it that you can enable
685
00:42:52.865 --> 00:42:53.685
such a complex
686
00:42:53.985 --> 00:42:54.805
feature with
687
00:42:55.425 --> 00:42:55.925
just
688
00:42:56.385 --> 00:43:02.405
a couple line differences. It was just services dot I two p dot enable, which pulled something from NextOS,
689
00:43:02.849 --> 00:43:09.670
and then the appropriate options in bitcon deed, and it was just able to start running immediately. And
690
00:43:10.905 --> 00:43:14.205
so that was something where I was again very happy that
691
00:43:14.585 --> 00:43:19.965
I was running Nix Bitcoin and that I'm developing on Nix Bitcoin because doing something like that on
692
00:43:20.580 --> 00:43:22.840
Deepgram or whatever else,
693
00:43:23.460 --> 00:43:27.320
would take much longer and be much more difficult to maintain.
694
00:43:29.954 --> 00:43:34.855
695
00:43:35.635 --> 00:43:39.470
Because of the way it's designed, do you feel that it would be easier to identify
696
00:43:40.170 --> 00:43:41.610
where it was and,
697
00:43:42.090 --> 00:43:45.070
you know, pinpoint it much faster than maybe
698
00:43:45.484 --> 00:43:46.785
the other, potential
699
00:43:47.964 --> 00:43:51.105
node boxes that are have taken more of a scripting approach.
700
00:43:53.279 --> 00:43:55.140
701
00:43:56.400 --> 00:43:57.059
is that,
702
00:43:57.760 --> 00:43:58.260
something,
703
00:43:58.880 --> 00:44:00.819
that is compromised won't necessarily
704
00:44:01.279 --> 00:44:04.805
compromise other things that it doesn't have access to already.
705
00:44:05.265 --> 00:44:05.765
So,
706
00:44:06.305 --> 00:44:08.725
in Jonas's example, a Spark wallet
707
00:44:09.105 --> 00:44:09.605
vulnerability,
708
00:44:10.465 --> 00:44:13.559
which is very likely because it runs on
709
00:44:13.940 --> 00:44:15.079
Node. Js,
710
00:44:16.819 --> 00:44:17.640
that wouldn't
711
00:44:17.940 --> 00:44:19.079
would never affect,
712
00:44:20.144 --> 00:44:25.684
Bitcoin d because it's so sectioned off on multiple levels, soaring from users
713
00:44:26.305 --> 00:44:37.430
to system d options and so on and so on. So I think maybe, Jonas, you can say more to what Matt said. But in my opinion, the biggest advantage is,
714
00:44:38.385 --> 00:44:42.484
basically, flames from one service won't catch all over immediately
715
00:44:42.945 --> 00:44:44.405
onto other services.
716
00:44:46.250 --> 00:44:47.470
717
00:44:47.850 --> 00:44:51.470
threat models that that we protect against. And
718
00:44:52.875 --> 00:44:54.895
one is that the package is compromised
719
00:44:55.195 --> 00:44:58.895
deep in your system. A library is compromised, and you might be
720
00:44:59.675 --> 00:45:00.175
since
721
00:45:00.960 --> 00:45:03.779
your whole system is pinned to certain dependencies,
722
00:45:04.160 --> 00:45:04.960
you know,
723
00:45:05.599 --> 00:45:07.299
if you are running this bad
724
00:45:07.839 --> 00:45:09.215
dependency or not.
725
00:45:10.335 --> 00:45:18.810
And there's also the thing where Spark, the service itself is is compromised in some way and now tries to break out and,
726
00:45:19.530 --> 00:45:21.310
really to damage to,
727
00:45:21.690 --> 00:45:24.270
the whole system in various ways.
728
00:45:26.250 --> 00:45:26.750
So
729
00:45:27.515 --> 00:45:32.895
perhaps another security feature, it's more trivial, but I wonder in in respi bullets,
730
00:45:33.835 --> 00:45:36.734
when I guess you also SSH into the system,
731
00:45:37.140 --> 00:45:37.960
Do you usually
732
00:45:38.340 --> 00:45:41.560
do you do that at as root, or how does that work?
733
00:45:47.215 --> 00:45:50.915
Question to Vivek or or Matt. Yeah. I I think so.
734
00:45:51.295 --> 00:45:52.275
735
00:45:54.020 --> 00:45:56.440
736
00:45:56.900 --> 00:45:57.400
we
737
00:45:57.860 --> 00:46:04.875
try to pay really good attention on having, like, a user that has restricted abilities
738
00:46:05.335 --> 00:46:08.555
but is still able to interact with all these services,
739
00:46:09.015 --> 00:46:13.500
although the services themselves are separated by running under different,
740
00:46:14.119 --> 00:46:24.214
Linux users. So that user is usually called the operator, and the operator can run all the important commands but is not root, for example. And this is, like, a simple,
741
00:46:25.474 --> 00:46:29.895
way, I guess, to to get quite a bit more security from your
742
00:46:30.250 --> 00:46:31.150
from your node.
743
00:46:32.730 --> 00:46:37.470
744
00:46:38.945 --> 00:46:41.125
is is really possible to maintain
745
00:46:41.745 --> 00:46:45.925
because of the way the ease of of the Nix OS approach.
746
00:46:46.465 --> 00:46:46.965
So,
747
00:46:50.510 --> 00:46:52.450
yeah, it's, it's something that,
748
00:46:53.310 --> 00:46:56.530
the the principle of least privilege, which is something a basic
749
00:46:56.975 --> 00:46:58.195
security tenant that
750
00:46:58.495 --> 00:47:03.235
everything should only have access to what it absolutely needs, every user, every program,
751
00:47:03.775 --> 00:47:06.035
is a nice theory, but people usually
752
00:47:06.339 --> 00:47:11.559
breaks down when people start having to maintain such a system and all of a sudden something breaks so they just
753
00:47:11.859 --> 00:47:15.880
disable the extra security feature and give more access than they need to.
754
00:47:16.245 --> 00:47:24.105
And with Mixed Bitcoin, we do the whole thing once. We do it properly, and every change that we make through the software gets run through our
755
00:47:24.405 --> 00:47:25.945
automated testing suite.
756
00:47:26.280 --> 00:47:26.780
And,
757
00:47:27.320 --> 00:47:29.180
and if there's any issue, we,
758
00:47:29.960 --> 00:47:39.285
we, the developers, fix it before it ever gets to the users, and we know that what is what we are testing is exactly what is gonna arrive at the user.
759
00:47:40.065 --> 00:47:40.565
So,
760
00:47:41.345 --> 00:47:43.125
we talk about security often
761
00:47:43.800 --> 00:47:47.099
in in an abstract way, but here it's very clear how
762
00:47:47.400 --> 00:47:47.900
the,
763
00:47:48.760 --> 00:47:50.859
the way NextOS works helps us
764
00:47:51.295 --> 00:47:55.635
to maintain and yeah. To create and maintain a secure system.
765
00:47:57.695 --> 00:48:03.940
766
00:48:04.240 --> 00:48:04.740
story?
767
00:48:05.040 --> 00:48:07.860
768
00:48:08.595 --> 00:48:13.894
So the pseudo duas story was something that was also personal to me because halfway through
769
00:48:14.434 --> 00:48:14.934
developing
770
00:48:15.690 --> 00:48:18.190
Nix Bitcoin, I stumbled upon OpenBSD,
771
00:48:18.490 --> 00:48:24.590
which is kind of the OG operating system for security conscious people, especially on servers.
772
00:48:25.025 --> 00:48:34.005
And I started to think about maybe this effort we put into developing the next Bitcoin is misplaced. Maybe we should do OpenBCD minus Bitcoin.
773
00:48:35.610 --> 00:48:43.470
But I quickly discovered that just because a system is relatively secure when you boot it up, doesn't mean it stays secure over time
774
00:48:43.915 --> 00:48:46.734
and doesn't mean that you can respond to security vulnerabilities
775
00:48:47.035 --> 00:48:47.535
quickly.
776
00:48:48.315 --> 00:48:52.815
And one of those security vulnerabilities that popped up was the sudo bug
777
00:48:53.420 --> 00:48:55.120
which first of all is because
778
00:48:55.420 --> 00:48:58.720
sudo is written in c and sudo is an extremely
779
00:48:59.100 --> 00:49:00.160
complex program,
780
00:49:01.285 --> 00:49:01.785
unnecessarily
781
00:49:02.165 --> 00:49:13.740
so. And it was only a question of time until such a terrible security vulnerability popped up, which basically allowed any user to gain root on the system where sudo was installed.
782
00:49:14.200 --> 00:49:14.700
So,
783
00:49:16.280 --> 00:49:18.345
from my background with OpenBSD,
784
00:49:18.645 --> 00:49:23.065
I knew that they do a couple things right, which is write really minimal,
785
00:49:24.325 --> 00:49:27.869
good programs. Like, for example, open SSH, which is in use
786
00:49:28.250 --> 00:49:28.750
everywhere
787
00:49:29.210 --> 00:49:30.030
in the industry
788
00:49:30.490 --> 00:49:32.990
and is the only thing I would feel comfortable,
789
00:49:34.125 --> 00:49:34.625
running
790
00:49:35.165 --> 00:49:41.265
Internet facing, which gives people access to my server because it's so well reviewed and so well secured.
791
00:49:42.570 --> 00:49:44.910
The same authors that wrote s s OpenSSH
792
00:49:45.530 --> 00:49:49.470
also wrote a tool called Duas, which has since been ported to Linux,
793
00:49:49.785 --> 00:49:52.445
and we decide as a project to, from now on,
794
00:49:53.305 --> 00:49:54.925
use Duas as our,
795
00:49:56.585 --> 00:50:01.110
tool to get have you allow users to gain root access when they need to.
796
00:50:01.650 --> 00:50:08.550
In our system, it's more used for root to become user, but that's going to into detail. The main
797
00:50:08.855 --> 00:50:09.914
point here is that
798
00:50:10.454 --> 00:50:13.835
Duas is is a much more minimal alternative to sudo,
799
00:50:14.214 --> 00:50:19.920
and changing that in Nix OS again because it's so transparent and it's
800
00:50:20.220 --> 00:50:24.080
it's code. It's not a abstract system where you input
801
00:50:25.225 --> 00:50:27.645
lines into a into a command line,
802
00:50:28.425 --> 00:50:37.630
every couple weeks, and you forget what you used to what you did before. It's a clearly laid out code which gets reviewed on GitHub by multiple people on every change.
803
00:50:38.330 --> 00:50:38.830
And,
804
00:50:39.770 --> 00:50:44.055
Duets making that switch was very simple, and we still, by the way,
805
00:50:44.675 --> 00:50:50.615
enable people to keep continue using sudo. It's just that we try to lean towards security in our default.
806
00:50:50.930 --> 00:50:51.430
So,
807
00:50:52.609 --> 00:50:58.230
808
00:50:59.915 --> 00:51:01.295
With Raspberry Pi Blitz,
809
00:51:02.395 --> 00:51:08.415
you use an admin user, but it has pseudo access, which to me, that means it's root. Right?
810
00:51:09.540 --> 00:51:11.240
811
00:51:13.460 --> 00:51:17.160
812
00:51:18.755 --> 00:51:19.734
Like, you type in
813
00:51:20.194 --> 00:51:20.994
you type in
814
00:51:21.714 --> 00:51:26.214
so, usually, when you're using Linux, right, and you wanna have root access, you type in sudo
815
00:51:26.540 --> 00:51:28.480
then whatever command you're gonna do.
816
00:51:29.099 --> 00:51:29.760
And then
817
00:51:30.140 --> 00:51:34.000
once you do that, it asks for a password, and then you have root access. Right?
818
00:51:34.535 --> 00:51:37.435
819
00:51:37.735 --> 00:51:39.015
versus the root, but,
820
00:51:39.575 --> 00:51:40.635
I don't know necessarily
821
00:51:41.175 --> 00:51:41.995
where their
822
00:51:42.580 --> 00:51:45.080
privileges end on whatever OS.
823
00:51:46.180 --> 00:51:47.320
824
00:51:47.620 --> 00:51:51.000
825
00:51:51.965 --> 00:51:53.905
user has no way of
826
00:51:54.365 --> 00:51:55.825
gaining new privileges.
827
00:51:56.685 --> 00:51:58.285
There he doesn't have access to,
828
00:51:59.460 --> 00:52:03.400
to do as in that way where he can go up to root. So
829
00:52:03.779 --> 00:52:07.079
I guess that's a slight difference, but I'm glad to hear that
830
00:52:07.525 --> 00:52:09.305
this security step is
831
00:52:09.925 --> 00:52:10.425
existent.
832
00:52:10.965 --> 00:52:11.465
Unlike
833
00:52:12.165 --> 00:52:19.650
Jonas, I'm not so diplomatic, and I I will say that something like Umbrell, for example, has terrible security practices.
834
00:52:20.270 --> 00:52:20.770
And,
835
00:52:21.630 --> 00:52:24.665
yeah. So I'm very happy to hear that GraphiteBlitz
836
00:52:25.045 --> 00:52:25.545
is
837
00:52:25.925 --> 00:52:26.325
is is,
838
00:52:26.805 --> 00:52:27.945
has that in place.
839
00:52:30.724 --> 00:52:44.015
840
00:52:45.035 --> 00:52:45.535
841
00:52:45.915 --> 00:52:49.295
842
00:52:49.595 --> 00:52:50.415
key auth.
843
00:52:51.200 --> 00:52:51.520
So,
844
00:52:52.080 --> 00:52:58.420
or offers it. But, any any person with, with half a brain should be using SSH key auth.
845
00:52:58.960 --> 00:53:00.260
Passwords are not
846
00:53:01.445 --> 00:53:01.945
not
847
00:53:04.565 --> 00:53:05.065
2021.
848
00:53:06.085 --> 00:53:06.585
Well,
849
00:53:07.205 --> 00:53:10.265
Matt, do you think, we could jump into maybe, like,
850
00:53:10.950 --> 00:53:13.369
cool features about Next Bitcoin? You know,
851
00:53:13.670 --> 00:53:15.130
they recently had a release.
852
00:53:15.430 --> 00:53:18.410
There's a bunch of stuff on there that I'm fascinated with.
853
00:53:19.305 --> 00:53:22.205
I think it's a good Yes. Let's rip it.
854
00:53:23.625 --> 00:53:24.585
Cool. Cool. So,
855
00:53:26.025 --> 00:53:32.150
I guess the stuff that intrigues me most about Nick's Bitcoin is that it's kind of agnostic.
856
00:53:33.410 --> 00:53:34.275
You know, there's
857
00:53:34.674 --> 00:53:37.494
a liquid node on there that you can enable through the module.
858
00:53:38.035 --> 00:53:41.015
You can have LND node. You can have a CLining node.
859
00:53:41.474 --> 00:53:43.095
There's pool on there.
860
00:53:43.510 --> 00:53:44.250
So I,
861
00:53:45.110 --> 00:53:47.450
you know, frankly, in these times where,
862
00:53:47.830 --> 00:53:50.090
there is, like, all sorts of
863
00:53:51.295 --> 00:53:52.435
protocol standardization,
864
00:53:54.895 --> 00:54:00.610
sharp elbows going on. I I find this as, like, the way forward in a sense.
865
00:54:01.490 --> 00:54:05.430
The other things that I'm fascinated with is, they also have JoinMarket,
866
00:54:06.210 --> 00:54:08.470
Elect RS, BTC pay server.
867
00:54:08.994 --> 00:54:11.734
So, I wanted to give Jonas and,
868
00:54:12.515 --> 00:54:16.515
Nix Bitcoin to have a chance to talk about maybe what they use or find,
869
00:54:16.914 --> 00:54:17.414
cool.
870
00:54:17.819 --> 00:54:19.359
And then, I think Satrinity
871
00:54:19.660 --> 00:54:22.799
had a question a while back about BTC pay server and,
872
00:54:23.500 --> 00:54:27.369
Ellen URL, which we can jump into afterwards. But, yeah, Jonas Definitely.
873
00:54:27.695 --> 00:54:28.595
874
00:54:29.695 --> 00:54:30.595
first of all,
875
00:54:30.895 --> 00:54:32.835
because you said c lightning and lnd
876
00:54:33.455 --> 00:54:35.315
and Nix Bitcoin being agnostic,
877
00:54:35.780 --> 00:54:36.520
I think
878
00:54:36.820 --> 00:54:43.640
nix Bitcoin is probably the only node project that allows you to run clighting and lnd at the same time easily.
879
00:54:44.020 --> 00:54:45.160
880
00:54:45.695 --> 00:54:49.155
just added that, but, yeah. Nyx is the 1st.
881
00:54:50.015 --> 00:54:54.355
882
00:54:57.100 --> 00:55:03.760
But for some of the development nodes, I actually have that running, which makes it easy because I have can test both on one node.
883
00:55:04.095 --> 00:55:04.595
But,
884
00:55:05.135 --> 00:55:10.914
you mentioned join market, and I like using that. And it's really difficult to maintain because it's Python
885
00:55:11.330 --> 00:55:17.430
code, and a lot of work goes into this joint market thing. So I hope I'm not the only user.
886
00:55:18.850 --> 00:55:19.330
But if
887
00:55:20.715 --> 00:55:23.455
888
00:55:23.995 --> 00:55:24.495
Yeah.
889
00:55:25.515 --> 00:55:26.735
890
00:55:27.810 --> 00:55:32.869
join market is something I like to use. I like to use c lightning and l and d.
891
00:55:33.810 --> 00:55:35.910
I haven't gotten into really the,
892
00:55:36.464 --> 00:55:36.964
lightning
893
00:55:37.265 --> 00:55:40.805
stuff like pool and loop, but I love this thing called CLboss,
894
00:55:41.505 --> 00:55:53.575
which Jonas turned us onto. It's the coolest thing ever. You have a CLightening node, you put funds on it to on it, you enable CL Boss and it has such complex logic that it just figures out,
895
00:55:54.535 --> 00:56:01.275
what are the best possible routes and channels for you, and just does with your funds. Really, everything automatically
896
00:56:01.575 --> 00:56:02.315
and tests
897
00:56:02.810 --> 00:56:03.550
stuff periodically,
898
00:56:04.810 --> 00:56:06.990
chain rebalances and even,
899
00:56:08.650 --> 00:56:09.950
eve, it even
900
00:56:11.454 --> 00:56:14.655
uses low low fee times to do a lot of these,
901
00:56:15.055 --> 00:56:16.035
on chain operations.
902
00:56:16.494 --> 00:56:22.010
So it's it's something like set and and forget and you always root. You always have a root.
903
00:56:22.310 --> 00:56:22.630
And,
904
00:56:23.270 --> 00:56:27.530
that's something I really like to use and on our Even sets your channel fees.
905
00:56:28.225 --> 00:56:29.045
Yeah. Exactly.
906
00:56:29.505 --> 00:56:30.485
It's so cool.
907
00:56:31.105 --> 00:56:36.805
908
00:56:37.150 --> 00:56:37.890
909
00:56:38.190 --> 00:56:42.830
910
00:56:43.869 --> 00:56:53.975
Francis from Bull Bitcoin, you know, he was a pessimist about lightning, then he got intrigued by it. Then he had some liquidity issues, and then he tweeted later about c l's CL boss fixing all of it. So,
911
00:56:55.000 --> 00:56:57.660
very bullish on this particular plug in.
912
00:56:57.960 --> 00:57:00.839
913
00:57:01.720 --> 00:57:04.380
and it it it somehow picks notes I like.
914
00:57:06.135 --> 00:57:07.995
It it, picks cool nodes.
915
00:57:08.295 --> 00:57:10.475
And, something else with nixbitcoinorg,
916
00:57:12.055 --> 00:57:14.395
because somebody mentioned BTC pay server,
917
00:57:15.160 --> 00:57:22.059
We have that running in a in a professional way. So if anybody wants to see how to deploy BTC pay server public facing
918
00:57:23.825 --> 00:57:26.885
and and have it really be very stable and reliable,
919
00:57:27.345 --> 00:57:28.805
go check out the next bitcoin.org
920
00:57:29.265 --> 00:57:29.765
repo.
921
00:57:30.145 --> 00:57:32.005
And, we have we have,
922
00:57:32.730 --> 00:57:41.735
Bitcoin enabled, we have Lightning enabled, and the coolest thing is we also have Liquid enabled. So you could make liquid payments to us,
923
00:57:42.115 --> 00:57:44.615
which so far one person has done, but
924
00:57:45.235 --> 00:57:46.535
I'm really into it.
925
00:57:48.195 --> 00:57:49.475
What else? I'll get the
926
00:57:50.195 --> 00:57:53.450
927
00:57:53.910 --> 00:57:54.410
928
00:57:57.430 --> 00:57:59.210
929
00:58:00.285 --> 00:58:02.785
930
00:58:06.125 --> 00:58:08.385
Spark Wallet, but I think that's on the way out
931
00:58:08.710 --> 00:58:11.590
because I'm maintained, and we're gonna
932
00:58:12.070 --> 00:58:12.710
today, we
933
00:58:13.270 --> 00:58:18.455
or today, I finished the Arrive the lightning module, which is gonna go through very intensive
934
00:58:21.655 --> 00:58:26.795
graphical user interface for making payments with either LND or c plus lightning
935
00:58:27.190 --> 00:58:28.970
and also managing your node.
936
00:58:29.750 --> 00:58:31.850
937
00:58:32.950 --> 00:58:36.230
package or module is going to be awesome because I remember,
938
00:58:37.385 --> 00:58:42.665
you guys didn't like gooey people, and, we were somewhat of peasants in your eyes. But,
939
00:58:43.065 --> 00:58:46.819
it's it's glad I'm I'm very glad to know that, we now.
940
00:58:47.680 --> 00:58:51.539
941
00:58:52.079 --> 00:59:00.255
$1,000 worth of Bitcoin on it. I'm sorry I still use the dollar as a unit of account. I know I'm not a great toxic maximalist,
942
00:59:00.795 --> 00:59:01.855
but still,
943
00:59:02.450 --> 00:59:09.750
so if you have a node with a couple $1,000 on it, I would feel comfortable to have a GUI. But once you start getting into the tens and 100 of 1,000,
944
00:59:10.210 --> 00:59:11.750
I would stick with,
945
00:59:12.275 --> 00:59:14.375
see lightning only or l and d only.
946
00:59:15.155 --> 00:59:16.214
947
00:59:16.595 --> 00:59:16.835
point.
948
00:59:17.395 --> 00:59:24.869
The question specifically that Sat Trinity asked were, are there plans for next Bitcoin to make it easy to expose a BTC pay server
949
00:59:25.250 --> 00:59:28.549
to the outside world to take advantage of the new lnurl
950
00:59:28.930 --> 00:59:30.505
slash lightning address functionality
951
00:59:31.285 --> 00:59:33.145
in a safe and secure way?
952
00:59:33.925 --> 00:59:34.244
953
00:59:35.845 --> 00:59:38.985
I don't know if it's so easy, but public facing again,
954
00:59:39.960 --> 00:59:41.080
usually we only work with,
955
00:59:42.680 --> 00:59:43.580
onion services,
956
00:59:44.200 --> 00:59:49.204
in the Nix Bitcoin repo itself and kind of say that if you wanna do anything more complex,
957
00:59:49.505 --> 01:00:02.680
we want you to know what you're doing and you should be doing that, as because Nix Bitcoin is super extensible, you should be extending that yourself. And if you want an example for how we extended NEX Bitcoin to work with Clearnet,
958
01:00:04.015 --> 01:00:04.335
and,
959
01:00:05.135 --> 01:00:07.475
Clearnet and Tor at the same time for nixbitcoin.org.
960
01:00:08.735 --> 01:00:09.795
Check out the nixbitcoin.orgrepo.
961
01:00:11.055 --> 01:00:13.235
And as far as Allan URL goes,
962
01:00:14.240 --> 01:00:16.500
we are working on that. Eric
963
01:00:17.760 --> 01:00:21.619
Arstead thinks that's a super cool feature, and I'm sure that'll be a very,
964
01:00:22.875 --> 01:00:23.915
thorough and,
965
01:00:25.035 --> 01:00:25.695
and good,
966
01:00:26.395 --> 01:00:28.494
PR coming up very soon.
967
01:00:28.875 --> 01:00:30.095
So, Jonas,
968
01:00:30.610 --> 01:00:33.270
I took up a lot of time about the features, but,
969
01:00:33.810 --> 01:00:37.190
I'm also interested to hear how you use your Bitcoin.
970
01:00:37.490 --> 01:00:39.190
971
01:00:40.615 --> 01:00:42.875
I'm also a fan of the CL boss.
972
01:00:44.295 --> 01:00:47.500
I think more people should look into it. It's also not
973
01:00:48.220 --> 01:00:56.640
it's also kind of extensible, and not many people are really looking at this right now, and is only updating it from time to time.
974
01:00:57.375 --> 01:00:57.875
So,
975
01:00:58.415 --> 01:01:01.155
I think there this could be improved quite a bit.
976
01:01:01.455 --> 01:01:03.635
977
01:01:04.590 --> 01:01:07.650
978
01:01:10.110 --> 01:01:11.490
So just because,
979
01:01:12.750 --> 01:01:13.250
as
980
01:01:13.705 --> 01:01:19.165
I need to answer this question so I don't forget, someone asked, how do you get a NYX white belt?
981
01:01:19.705 --> 01:01:23.619
And you usually get a white belt by showing up at the gym.
982
01:01:24.000 --> 01:01:27.059
So in this case, it would be to check out,
983
01:01:27.359 --> 01:01:28.819
the next Bitcoin repository
984
01:01:29.119 --> 01:01:29.655
and read
985
01:01:30.215 --> 01:01:33.035
what is there and perhaps also delve into the
986
01:01:33.335 --> 01:01:34.795
Nix OS documentation.
987
01:01:36.615 --> 01:01:39.100
988
01:01:40.060 --> 01:01:42.800
about I just wanna say something quickly about the
989
01:01:43.100 --> 01:01:44.880
project culture at Next Bitcoin,
990
01:01:45.660 --> 01:01:46.400
which is
991
01:01:46.780 --> 01:01:47.280
very
992
01:01:48.194 --> 01:01:51.174
software oriented in the terms of Cypherpunks
993
01:01:51.474 --> 01:01:52.214
right code.
994
01:01:52.674 --> 01:01:53.174
And,
995
01:01:54.674 --> 01:01:57.510
yeah, I I know that other projects have some kind of belt
996
01:01:58.070 --> 01:02:04.170
system and then and community managers and everything and we're you can rest assured that the 3
997
01:02:04.470 --> 01:02:05.370
spare time
998
01:02:05.750 --> 01:02:06.570
mixed Bitcoin
999
01:02:07.355 --> 01:02:12.735
developers waste all their time on on such stuff and focus all their time on improving
1000
01:02:13.115 --> 01:02:14.575
the software for your node.
1001
01:02:16.530 --> 01:02:20.549
1002
01:02:20.849 --> 01:02:21.730
communist, so,
1003
01:02:22.725 --> 01:02:25.305
very happy that I'm embraced in your community.
1004
01:02:26.485 --> 01:02:30.345
1005
01:02:31.330 --> 01:02:32.790
Some stronger, some
1006
01:02:33.170 --> 01:02:33.910
less strong,
1007
01:02:34.930 --> 01:02:42.855
but, we try to keep NEX Bitcoin or we do keep NEX Bitcoin. Also, the reason why I picked a NIM and a project specific NIM.
1008
01:02:43.875 --> 01:02:48.215
I and I think also the other developers are in this to write good code,
1009
01:02:48.660 --> 01:02:51.319
and good code automatically produces freedom,
1010
01:02:51.780 --> 01:02:52.440
I think.
1011
01:02:52.980 --> 01:02:55.079
At yeah. So we're
1012
01:02:55.540 --> 01:02:57.799
we're not in it to fight with anybody.
1013
01:02:58.645 --> 01:02:59.865
We're in it to make
1014
01:03:00.645 --> 01:03:03.225
good software, that a beautiful software,
1015
01:03:03.685 --> 01:03:05.065
non spaghetti software,
1016
01:03:05.700 --> 01:03:06.200
and,
1017
01:03:06.900 --> 01:03:09.000
we kind of keep our political opinions
1018
01:03:09.380 --> 01:03:10.120
to the
1019
01:03:10.500 --> 01:03:12.760
to other other parts of the world.
1020
01:03:13.540 --> 01:03:15.000
1021
01:03:16.005 --> 01:03:19.145
1022
01:03:19.765 --> 01:03:22.664
definitely no two x. We don't we also had
1023
01:03:22.964 --> 01:03:24.984
a a discussion, I remember Jonas,
1024
01:03:25.830 --> 01:03:26.570
when when
1025
01:03:27.350 --> 01:03:27.850
Taproot
1026
01:03:28.470 --> 01:03:33.450
stuff came up and we took a very clear line and decided a little bit for
1027
01:03:33.750 --> 01:03:34.330
our users,
1028
01:03:35.815 --> 01:03:39.674
I guess, something that we decide the defaults and we're definitely
1029
01:03:40.214 --> 01:03:41.595
we definitely take a
1030
01:03:42.775 --> 01:03:45.539
a block stream position on things. No yield
1031
01:03:46.319 --> 01:03:46.819
us.
1032
01:03:47.599 --> 01:03:53.380
1033
01:03:54.085 --> 01:03:56.185
pretty much all the other maintainers
1034
01:03:57.365 --> 01:03:59.865
all the other node project maintainers on
1035
01:04:00.165 --> 01:04:02.825
for, like, a roundtable discussion except for Umbrel,
1036
01:04:03.869 --> 01:04:05.650
who refused to participate. And,
1037
01:04:07.550 --> 01:04:10.050
you know, one of the main top that that was around,
1038
01:04:11.315 --> 01:04:15.015
when when the whole Tappr thing was going on with speedy trial and whatnot.
1039
01:04:16.995 --> 01:04:25.960
And so in the future, I mean, there could be a situation where we have, you know, contentious clients, where we have multiple clients, and, you know, Taproot was kind of obvious,
1040
01:04:26.980 --> 01:04:30.244
but where we have a situation where we have, you know, multiple
1041
01:04:30.545 --> 01:04:32.565
clients that are in contention with each other.
1042
01:04:32.945 --> 01:04:35.425
And these node projects, you know, are kinda going to
1043
01:04:36.560 --> 01:04:39.859
there's no clear answer there on how they will proceed,
1044
01:04:40.400 --> 01:04:45.460
in that type of situation. And people can say one thing or say the other, but, like, when push comes to shove,
1045
01:04:46.335 --> 01:04:55.850
we'll see how that all plays out. But am I correct in my understanding that with something like Nix Bitcoin, it would be easier for me to basically
1046
01:04:56.870 --> 01:04:59.450
choose which Bitcoin d client I'm running?
1047
01:05:03.404 --> 01:05:03.804
1048
01:05:04.204 --> 01:05:05.505
I'm not necessarily.
1049
01:05:05.884 --> 01:05:09.085
I I think that because it's it's kind of a
1050
01:05:10.090 --> 01:05:13.870
something where we take a lot of the technical complexity out of your hands,
1051
01:05:14.890 --> 01:05:16.190
we also make
1052
01:05:16.810 --> 01:05:19.470
decisions that we think are in the best interest.
1053
01:05:19.885 --> 01:05:24.545
But I think if something really contentious came up where we wouldn't see a clear,
1054
01:05:25.724 --> 01:05:26.944
clear answer,
1055
01:05:27.690 --> 01:05:30.510
where most of the time I think with Bitcoin because it's so
1056
01:05:31.130 --> 01:05:35.470
hard to make changes. If there are changes, they are only they're very clear,
1057
01:05:36.244 --> 01:05:37.065
for the better
1058
01:05:37.525 --> 01:05:40.665
or, only with pretty much only upsides.
1059
01:05:41.525 --> 01:05:42.025
But,
1060
01:05:43.650 --> 01:05:50.869
yeah, if there was something really contentious where you could fall on either side, I think we would make an easy option for people to choose. But,
1061
01:05:51.725 --> 01:05:56.945
going in the idea of us trying to protect our users and also ourselves because we use it ourselves,
1062
01:05:57.645 --> 01:06:06.810
we make sensible default decisions on a on a technical level. And also one quick thing about Deepak, I think you said you're a California communist. Who who said you're a Yes.
1063
01:06:07.145 --> 01:06:11.485
No. I think that's something also very important by us that we we
1064
01:06:12.665 --> 01:06:15.325
accept and love and accept everybody, I guess.
1065
01:06:16.320 --> 01:06:17.060
But definitely,
1066
01:06:17.600 --> 01:06:19.620
everybody's welcome and it's
1067
01:06:20.240 --> 01:06:22.500
about running good code and
1068
01:06:22.880 --> 01:06:25.300
and using Bitcoin the way it's supposed to be used,
1069
01:06:25.744 --> 01:06:27.125
on sovereign hardware,
1070
01:06:28.145 --> 01:06:30.805
privacy by default, security by default,
1071
01:06:31.185 --> 01:06:31.505
and,
1072
01:06:32.065 --> 01:06:32.965
not about
1073
01:06:33.760 --> 01:06:38.099
anything else. And then But am I am I wrong am I wrong in
1074
01:06:39.760 --> 01:06:46.935
1075
01:06:49.640 --> 01:06:57.740
1076
01:06:58.045 --> 01:07:07.860
some option. I mean, would make it optional to the user, but I don't probably other node projects would make similar choices and would make it easy for the user, whether that's,
1077
01:07:08.420 --> 01:07:11.080
like, changing a a config file or
1078
01:07:11.460 --> 01:07:17.720
1079
01:07:18.135 --> 01:07:23.835
California communist thing. You know, skills are what matters most, so I echo, Nick's Bitcoin dev sentiments.
1080
01:07:24.775 --> 01:07:28.350
It seems like specifically for this instance of Taproot
1081
01:07:28.730 --> 01:07:29.630
speedy trial,
1082
01:07:30.330 --> 01:07:31.070
Nix Bitcoin
1083
01:07:31.370 --> 01:07:32.350
is not
1084
01:07:33.610 --> 01:07:36.670
as, you know, inclined to take the lot true approach,
1085
01:07:37.295 --> 01:07:38.595
maybe rightfully so,
1086
01:07:39.215 --> 01:07:40.335
you know, given that,
1087
01:07:40.815 --> 01:07:42.435
UASF did reveal
1088
01:07:42.815 --> 01:07:45.235
that the nodes the full nodes
1089
01:07:45.670 --> 01:07:48.730
are, like, the validators in the network, and the miners are
1090
01:07:49.109 --> 01:07:52.490
kind of the appenders who need to follow the full nodes, say,
1091
01:07:52.815 --> 01:07:58.595
of course, you know, with contention of economic nodes and all the other variables thrown into the mix.
1092
01:07:59.215 --> 01:08:01.715
But with that said, there was no reason to
1093
01:08:03.380 --> 01:08:05.640
drive things to that right away.
1094
01:08:06.420 --> 01:08:07.240
If it was,
1095
01:08:08.020 --> 01:08:09.955
you know, contentious in that sense where
1096
01:08:10.595 --> 01:08:12.135
minors were adversarial,
1097
01:08:12.515 --> 01:08:15.895
then, of course, we can do it. But in this specific instance,
1098
01:08:17.370 --> 01:08:21.950
it didn't feel as if that was the right way to do things and further set precedent.
1099
01:08:22.730 --> 01:08:26.510
Not to say that's not a valid opinion. I do very much respect
1100
01:08:27.015 --> 01:08:31.594
Luke Dasher as well as others that would run the code and have expressed
1101
01:08:32.695 --> 01:08:35.034
that opinion like MBK. You know? So
1102
01:08:35.500 --> 01:08:37.260
I think it varies. And,
1103
01:08:37.820 --> 01:08:41.360
if it did come down to that contentious moment again like UASF,
1104
01:08:42.460 --> 01:08:44.284
I think, like, there would
1105
01:08:44.585 --> 01:08:45.644
be, like, multiple,
1106
01:08:46.985 --> 01:08:47.644
I guess,
1107
01:08:48.344 --> 01:08:48.844
configs
1108
01:08:49.304 --> 01:08:50.025
for this,
1109
01:08:50.744 --> 01:08:52.045
and maybe all the
1110
01:08:52.659 --> 01:08:56.119
distributions or node boxes of whatever client software.
1111
01:08:57.059 --> 01:09:02.445
1112
01:09:04.744 --> 01:09:05.244
first.
1113
01:09:05.784 --> 01:09:06.105
And,
1114
01:09:06.665 --> 01:09:08.284
we like to
1115
01:09:08.710 --> 01:09:14.170
do things easy and not, you know, go all the way all of a sudden. We're very
1116
01:09:14.790 --> 01:09:16.570
thoughtful in our decisions. Everything
1117
01:09:16.949 --> 01:09:26.075
in our code base has a lot of thought echoes into it. And, once we fix one thing, it stays like that for and we like it. It stays like that forever.
1118
01:09:26.500 --> 01:09:27.320
So we
1119
01:09:27.860 --> 01:09:32.519
are very careful using our code and also with these kinds of things. And,
1120
01:09:32.820 --> 01:09:38.975
so I think that gives a little bit of the background why we didn't choose to go with the radical approach
1121
01:09:39.595 --> 01:09:40.095
initially.
1122
01:09:44.429 --> 01:09:55.965
Another thing This is people's money. You know? It's it's people's Bitcoin, and once it's gone, it's never coming back. No. I mean, I I appreciate the conservative nature for sure. I think most Bitcoiners do.
1123
01:09:56.665 --> 01:09:59.005
1124
01:10:00.250 --> 01:10:01.469
Another another
1125
01:10:01.850 --> 01:10:04.989
line of of conversation that came from that conversation
1126
01:10:05.290 --> 01:10:05.790
was
1127
01:10:06.945 --> 01:10:11.125
the ability to, like, easily migrate between node projects. If,
1128
01:10:11.985 --> 01:10:21.409
let's say, you're running, an Umbral or a RAS pi blitz, and they decide to go a route that you don't want them to go and you want to easily migrate without closing out all your channels.
1129
01:10:22.349 --> 01:10:29.655
Is that something you guys have considered? Is it, like, how how how difficult is the migration process if if someone already has a
1130
01:10:32.350 --> 01:10:43.515
if they're already running Raspberry Pi Blitz and they have a bunch of channels open or vice versa, if they're they're running next Bitcoin and they have a bunch of channels open, and they wanna move to Raspi Bliss. Is that something that you guys have considered?
1131
01:10:44.775 --> 01:10:46.155
1132
01:10:46.855 --> 01:10:50.350
you know, more than even a NIX Bitcoin question, this is, I
1133
01:10:51.690 --> 01:10:53.950
guess, how easily can you,
1134
01:10:55.370 --> 01:11:00.135
port your channel DB and wallet dot dat and actually, like, the
1135
01:11:00.594 --> 01:11:04.855
the different derivation standards, like, the AZ with the birthday and other stuff.
1136
01:11:05.640 --> 01:11:09.580
Would you say that's fair, Jonas? And how does Nix Bitcoin
1137
01:11:10.520 --> 01:11:11.180
do this,
1138
01:11:11.560 --> 01:11:14.780
and maybe whether it's different or similar to others?
1139
01:11:16.625 --> 01:11:18.005
1140
01:11:18.385 --> 01:11:25.340
quite difficult to do in a general way. I know both who did this, who didn't lose their funds, but
1141
01:11:25.880 --> 01:11:29.020
I think there are many things that can go wrong. Just imagine that,
1142
01:11:30.255 --> 01:11:37.315
like, the the LND or c lightning versions are different on the next Bitcoin node you're porting to to the
1143
01:11:37.910 --> 01:11:46.330
to the node you're porting from, and somehow your data directory isn't compatible anymore, and it expects something else somewhere else. So I think that gets
1144
01:11:46.635 --> 01:11:49.215
difficult really quickly. I think it's a good question,
1145
01:11:50.395 --> 01:11:54.575
because could be expensive to close your channels to set up a a node.
1146
01:11:56.350 --> 01:12:03.090
I am in principle, if you had 2 Nix Bitcoin or NixOS based projects, I guess it would be simple to make this
1147
01:12:04.055 --> 01:12:05.835
switch because then you could do it,
1148
01:12:06.295 --> 01:12:07.355
basically programmatically
1149
01:12:07.815 --> 01:12:10.155
because you know what versions are running there.
1150
01:12:10.695 --> 01:12:13.435
But for, like to migrate from
1151
01:12:13.800 --> 01:12:14.780
a general
1152
01:12:15.559 --> 01:12:16.679
like, any kind of,
1153
01:12:18.520 --> 01:12:22.219
Bitcoin node, I guess, that requires some custom
1154
01:12:23.355 --> 01:12:23.855
thinking.
1155
01:12:25.675 --> 01:12:26.175
1156
01:12:27.435 --> 01:12:27.935
Jonas,
1157
01:12:28.715 --> 01:12:32.335
you just made a PR that I'm gonna review in the next
1158
01:12:32.679 --> 01:12:35.739
days of, of the backup plugin for CLightening.
1159
01:12:36.119 --> 01:12:39.179
Wouldn't you just be able to restore from your backups,
1160
01:12:40.525 --> 01:12:42.785
from 1 CLightening backup,
1161
01:12:43.325 --> 01:12:47.265
1 CLightening backup you made to your new next Bitcoin node or vice versa?
1162
01:12:49.660 --> 01:12:52.560
1163
01:12:53.020 --> 01:13:00.645
for this question. Are we talking, like, between implementations? Because that might be more of a lightning problem. Are we talking between, like, nodes?
1164
01:13:01.585 --> 01:13:02.485
And then also,
1165
01:13:03.744 --> 01:13:04.244
essentially,
1166
01:13:05.600 --> 01:13:08.740
don't wanna docs a person, but we did necessarily
1167
01:13:09.280 --> 01:13:10.020
see someone
1168
01:13:10.400 --> 01:13:12.340
who was able to migrate from
1169
01:13:13.095 --> 01:13:14.715
l and d recently, correct,
1170
01:13:15.095 --> 01:13:16.635
in our elements chat?
1171
01:13:21.500 --> 01:13:23.040
1172
01:13:26.139 --> 01:13:31.215
changing between different, lightning implementations, of course, that's that's not not our problem.
1173
01:13:32.155 --> 01:13:43.380
But, yeah, I guess it's too easy to lose funds. And to Nick's Bitcoin dev's question, we have this backup plugin. Actually, that's a good question. I'm not quite sure. What the backup plug in does, it simply writes down,
1174
01:13:44.079 --> 01:13:44.739
the SQL
1175
01:13:45.040 --> 01:13:48.345
statements that would usually go to your database,
1176
01:13:50.565 --> 01:13:56.400
and it writes this the simply the SQL statements into a file appended, and,
1177
01:13:57.040 --> 01:13:58.100
I'm not sure how
1178
01:13:59.760 --> 01:14:03.140
portable it is between versions, but that's a really good question.
1179
01:14:03.465 --> 01:14:06.764
1180
01:14:07.144 --> 01:14:07.625
because,
1181
01:14:07.945 --> 01:14:09.085
I have this dream.
1182
01:14:09.465 --> 01:14:10.925
I I I haven't articulated
1183
01:14:12.290 --> 01:14:14.470
in some private conversations, but
1184
01:14:14.850 --> 01:14:18.630
my kind of long term vision, which is just mine and
1185
01:14:19.090 --> 01:14:19.750
no one.
1186
01:14:20.515 --> 01:14:24.615
As Jonas pointed out in the very beginning, very clearly, I have not deleted
1187
01:14:26.115 --> 01:14:27.955
my payer, but my vision is to,
1188
01:14:29.000 --> 01:14:33.240
we have a couple things that we really need to get done, which is 1, ride the lightning and,
1189
01:14:34.040 --> 01:14:35.020
really good backups,
1190
01:14:35.480 --> 01:14:35.980
solutions,
1191
01:14:36.280 --> 01:14:38.300
and a couple of other things.
1192
01:14:38.975 --> 01:14:41.235
And after we finish those things, I wanna
1193
01:14:41.615 --> 01:14:42.355
make a,
1194
01:14:42.815 --> 01:14:43.635
v 0.1
1195
01:14:44.335 --> 01:14:47.635
or 1.0 whatever in our naming scheme release,
1196
01:14:48.050 --> 01:14:49.510
and from that point on,
1197
01:14:50.690 --> 01:14:52.790
just make functional improvements
1198
01:14:53.330 --> 01:14:53.830
or,
1199
01:14:54.450 --> 01:15:01.614
deprecate one feature in favor of another, but not keep expanding the complexity of of mixed Bitcoin adding new features,
1200
01:15:02.235 --> 01:15:03.695
but instead make that
1201
01:15:04.155 --> 01:15:04.655
more
1202
01:15:05.989 --> 01:15:08.809
part of secondary projects for people's
1203
01:15:09.429 --> 01:15:09.929
private,
1204
01:15:11.349 --> 01:15:14.090
big module extensions. But I kinda wanna
1205
01:15:14.685 --> 01:15:19.185
wanna finish make a finish line for next Bitcoin and start only making
1206
01:15:19.645 --> 01:15:31.610
improvements and and and functional and then and speed, secure all these kinds of underlying stuff, which which we pride ourselves in. I think we wanna get better and better in that.
1207
01:15:31.965 --> 01:15:32.465
And,
1208
01:15:33.005 --> 01:15:42.320
and backups is one thing that is, I think, a question for all of lightning, but specifically for us because we wanna be the most safe
1209
01:15:42.700 --> 01:15:49.760
and and conservative nodes for people and backup a good backup strategy is is an integral part of that. So,
1210
01:15:52.585 --> 01:15:56.764
I I wanna get into that in the coming that's part of that's one of the
1211
01:15:57.380 --> 01:16:04.600
most highest priority things that we wanna get done also for our own interest, not just because we think it's a good idea but I also
1212
01:16:05.085 --> 01:16:13.025
would appreciate have you know, having clarity about how safe my lightning funds are in case of hardware failure. And because that mentioned matrix
1213
01:16:13.550 --> 01:16:23.645
and l or element chat, I wanna give a quick plug that I think that Bitcoin users should slowly migrate onto matrix, which is shaping up to be a very robust
1214
01:16:24.265 --> 01:16:24.765
decentralized
1215
01:16:25.305 --> 01:16:26.765
federated chat solution.
1216
01:16:27.385 --> 01:16:33.320
And, I think this is more in the ethos of of Bitcoin than people using,
1217
01:16:34.040 --> 01:16:35.580
centralized things like
1218
01:16:36.040 --> 01:16:37.420
even Keybase or
1219
01:16:37.735 --> 01:16:46.955
whatever, which can all have a political lean, and and it's just a question a matter of time until people start getting banned, until people start getting shadow banned,
1220
01:16:47.270 --> 01:16:47.770
whatever.
1221
01:16:48.230 --> 01:16:48.730
So,
1222
01:16:49.510 --> 01:16:58.864
I think that quick thing just about matrix and our project is is pro matrix. We have a matrix server, which also interacts with IRC over libera.chat,
1223
01:17:00.045 --> 01:17:00.784
and we're
1224
01:17:01.085 --> 01:17:04.625
really I I feel very comfortable with this, and I think
1225
01:17:04.990 --> 01:17:07.090
every Bitcoiner should have his
1226
01:17:07.790 --> 01:17:09.570
own square, his own little
1227
01:17:10.670 --> 01:17:13.010
house in the digital realm, his own property.
1228
01:17:13.704 --> 01:17:17.965
Like, he has his money, he should also have property over his his, communications.
1229
01:17:18.664 --> 01:17:21.405
Just a side note, and we'll get back on topic.
1230
01:17:22.020 --> 01:17:30.039
1231
01:17:31.345 --> 01:17:35.525
With the channel DB, you know, the main issue is, like, the state
1232
01:17:35.825 --> 01:17:41.045
and, like, storing all those revocation points or the transactions. Right, Jonas?
1233
01:17:41.810 --> 01:17:42.869
Like, with the commitments,
1234
01:17:43.730 --> 01:17:45.270
does any plug out,
1235
01:17:46.050 --> 01:17:51.075
will that reduce the amount of state required and reduce, like, the channel DB size?
1236
01:17:53.955 --> 01:17:55.015
1237
01:17:55.715 --> 01:17:56.215
yes.
1238
01:17:56.835 --> 01:17:59.655
You should only have to store the latest state.
1239
01:18:00.780 --> 01:18:01.280
And
1240
01:18:02.140 --> 01:18:04.880
if you store an earlier state because you,
1241
01:18:06.700 --> 01:18:08.640
you have an older backup,
1242
01:18:09.375 --> 01:18:15.075
an updated backup, essentially, instead of losing your fund your funds, you should be able to recover
1243
01:18:15.615 --> 01:18:18.730
trustlessly kind of modular fees with your,
1244
01:18:19.210 --> 01:18:20.670
with your channel partner.
1245
01:18:23.450 --> 01:18:31.095
Awesome. But before we move away from this whole feature discussion, I want to answer a few questions from the chat. So,
1246
01:18:31.875 --> 01:18:34.615
let me find this. Radix rat asked
1247
01:18:35.199 --> 01:18:36.260
if there's
1248
01:18:36.880 --> 01:18:37.380
a
1249
01:18:38.960 --> 01:18:45.935
if I want a new version of Bitcoin Core that's not supported yet via the Nix Bitcoin update scripts, what should I do?
1250
01:18:46.875 --> 01:18:48.335
That's a good question.
1251
01:18:48.955 --> 01:18:53.215
So I can tell you that if I wanted to do that, that would take me
1252
01:18:53.980 --> 01:18:55.920
2 minutes or something to do that.
1253
01:18:56.220 --> 01:19:06.715
But for someone who hasn't worked with Nix, it would easily take a couple of hours. And the the reason is just that we have to be honest, the Nix and NixOS documentation
1254
01:19:07.735 --> 01:19:20.280
is really terrible, and it's a lot of custom things that need to be done. I could show you easily in 2 minutes how to do it if you show up in our matrix channel. For example, I guess it would be, the right answer to this question.
1255
01:19:21.605 --> 01:19:27.145
But, usually, we try to update relatively quickly. I think our Bitcoin d updates, they landed within,
1256
01:19:27.845 --> 01:19:30.970
2 weeks 1 or 2 weeks within the the release.
1257
01:19:32.070 --> 01:19:32.570
1258
01:19:32.870 --> 01:19:34.489
Something that also,
1259
01:19:34.870 --> 01:19:35.690
I think that,
1260
01:19:36.230 --> 01:19:39.370
on top of the security features and everything,
1261
01:19:40.265 --> 01:19:42.045
Mixed Bitcoin is one of the
1262
01:19:42.585 --> 01:19:45.645
node projects, I think, that updates the quickest,
1263
01:19:46.345 --> 01:19:50.910
and you don't have to wait on on on stuff with us. We usually have things
1264
01:19:51.450 --> 01:19:54.430
running in days or and or maximum one.
1265
01:19:55.450 --> 01:20:03.925
Crazy times, 2 weeks. But, usually, we're snappy with maintaining stuff, except join market, which usually takes a long time to figure out,
1266
01:20:04.625 --> 01:20:06.645
how to how to do it.
1267
01:20:07.219 --> 01:20:09.719
1268
01:20:10.420 --> 01:20:14.679
using NYX Bitcoin the way it's intended to be used should be relatively
1269
01:20:14.980 --> 01:20:15.480
straightforward
1270
01:20:16.020 --> 01:20:20.115
for a technical user who's familiar with command line.
1271
01:20:20.655 --> 01:20:21.155
But
1272
01:20:21.695 --> 01:20:24.515
if you want to do custom stuff, then it gets
1273
01:20:25.700 --> 01:20:26.520
quite difficult
1274
01:20:26.900 --> 01:20:28.920
quickly. And that's why we say
1275
01:20:29.300 --> 01:20:30.520
it's the lowest
1276
01:20:30.980 --> 01:20:31.880
time preference,
1277
01:20:32.580 --> 01:20:33.960
note project because
1278
01:20:34.725 --> 01:20:42.585
you it makes sense to invest into learning these things because then in the long run, you hopefully have, fewer problems.
1279
01:20:43.260 --> 01:20:47.920
1280
01:20:48.380 --> 01:20:53.895
new users or or not so technical people. I even read the dirty word Windows
1281
01:20:54.435 --> 01:20:57.495
and other things. So what do you think about
1282
01:20:58.035 --> 01:20:58.535
us
1283
01:20:59.475 --> 01:21:01.095
making Nix Bitcoin
1284
01:21:01.530 --> 01:21:04.430
plan friendly and lowering the bar of entry.
1285
01:21:04.810 --> 01:21:05.950
1286
01:21:06.410 --> 01:21:08.170
Yes. So, I mean,
1287
01:21:08.605 --> 01:21:12.145
I've been telling Jonas for a while that I'm going to build a tutorial.
1288
01:21:13.005 --> 01:21:13.405
You know,
1289
01:21:14.045 --> 01:21:18.065
Matt had, like, the PlevNet folks on before, Raj Winder and Pete.
1290
01:21:19.310 --> 01:21:23.890
Many others I've discussed with also, like, another guy named Richard, Miguel,
1291
01:21:24.350 --> 01:21:24.850
Rafael.
1292
01:21:25.230 --> 01:21:29.244
So they are interested in this, and, they are fairly technical.
1293
01:21:29.945 --> 01:21:31.005
So I think it's,
1294
01:21:31.385 --> 01:21:38.180
very much possible as long as there is, like, a good tutorial. So working on that with some Intel NUC hardware
1295
01:21:38.560 --> 01:21:40.100
that Jonas has suggested.
1296
01:21:40.960 --> 01:21:44.295
Specifically to the Windows question you mentioned, is from VidGamer
1297
01:21:44.595 --> 01:21:45.095
14.
1298
01:21:45.475 --> 01:21:54.500
He says the bar to entry seems extremely high. Like, can you even run this on a old Windows laptop? And to that, I say, you know, I have run Nix OS
1299
01:21:55.199 --> 01:21:57.920
on old MacBook Pro from 2010, and,
1300
01:21:58.635 --> 01:22:01.855
it worked. I got big Nix Bitcoin running as well.
1301
01:22:02.395 --> 01:22:03.535
I tried recently
1302
01:22:04.075 --> 01:22:04.975
on a 2017
1303
01:22:05.595 --> 01:22:06.495
Surface Pro,
1304
01:22:08.130 --> 01:22:08.630
The
1305
01:22:09.490 --> 01:22:15.590
the what's it called? The resolution was a little screwed up. But if I plugged in an HDMI, I was able to see upon another
1306
01:22:16.475 --> 01:22:16.975
monitor.
1307
01:22:17.915 --> 01:22:18.395
And,
1308
01:22:18.795 --> 01:22:19.695
I think it
1309
01:22:20.155 --> 01:22:26.810
for the most part, Nix does run pretty well on multiple things. But, the main issue I've encountered is
1310
01:22:27.270 --> 01:22:28.890
whether, you know, to use,
1311
01:22:29.670 --> 01:22:30.410
the UEFI
1312
01:22:31.350 --> 01:22:31.850
booting
1313
01:22:32.310 --> 01:22:32.710
or,
1314
01:22:33.715 --> 01:22:38.775
I guess, the legacy BIOS boot option, like, in the Nix OS install instructions.
1315
01:22:39.155 --> 01:22:46.750
But once again, like Jonas and Nix, Bitcoin Dev mentioned, just hop in the matrix and ask some questions, and, people are more than willing to help you.
1316
01:22:47.449 --> 01:22:56.364
1317
01:22:56.985 --> 01:23:00.364
what we, what we use for communication. I read 2
1318
01:23:00.909 --> 01:23:03.010
questions here that are related
1319
01:23:03.869 --> 01:23:04.849
from Setrinity
1320
01:23:05.150 --> 01:23:05.889
and SovereignHodler.
1321
01:23:07.310 --> 01:23:14.915
Can you talk more about the BTC pay server implementation and how you're exposing it to the outside world? Does Nix Bitcoin use Tor?
1322
01:23:15.455 --> 01:23:28.344
Great question. So first of all, Nix Bitcoin by default always uses Tor and only Tor. So if you are running on a home node and you wanna start up a BTC pay server, if you go into the config and,
1323
01:23:29.125 --> 01:23:31.704
uncomment the line BTC pay server enable,
1324
01:23:32.405 --> 01:23:36.184
what will happen is that on once you deploy that to a node,
1325
01:23:36.950 --> 01:23:42.490
it will set everything up and generate a Tor Onion service for your use.
1326
01:23:43.830 --> 01:23:45.930
Once you wanna leave the Tor world
1327
01:23:46.835 --> 01:23:47.335
and,
1328
01:23:48.195 --> 01:23:49.395
once you want to,
1329
01:23:49.875 --> 01:23:51.335
endanger your own privacy
1330
01:23:51.715 --> 01:23:54.375
and and start dealing with NAT and all those things,
1331
01:23:55.540 --> 01:23:57.160
you're kind of on your own,
1332
01:23:57.780 --> 01:23:59.080
which I think is something
1333
01:23:59.860 --> 01:24:01.960
we want to make a little bit difficult.
1334
01:24:02.824 --> 01:24:03.324
But,
1335
01:24:04.665 --> 01:24:07.005
I wouldn't recommend it for home use, especially,
1336
01:24:08.025 --> 01:24:10.445
exposing your IP address and dealing with NAT.
1337
01:24:10.920 --> 01:24:14.540
Usually better if you want to have a BTC pay server just for interacting
1338
01:24:15.160 --> 01:24:16.220
with people privately,
1339
01:24:16.680 --> 01:24:17.980
just to use for.
1340
01:24:18.465 --> 01:24:18.705
And,
1341
01:24:19.505 --> 01:24:27.200
if you wanna know then Sovereign Huddler, can you elaborate on public facing BTC pay? Does it expose your home IP? No.
1342
01:24:30.380 --> 01:24:36.560
Public facing with an onion service won't, and if you start, going out of that secure space,
1343
01:24:37.005 --> 01:24:38.225
like we did with nixbitcoin.org,
1344
01:24:39.645 --> 01:24:43.425
it does expose your IP, obviously, because you're using ClearNet.
1345
01:24:44.180 --> 01:24:44.420
And,
1346
01:24:46.260 --> 01:24:46.739
that's,
1347
01:24:47.140 --> 01:24:51.719
1348
01:24:52.155 --> 01:24:54.175
support that Raspberry Blitz has integrated?
1349
01:24:55.195 --> 01:24:56.735
1350
01:24:57.275 --> 01:24:57.915
of it
1351
01:24:58.395 --> 01:25:05.590
its name, but I never how does it, make it clear that IP? The name is, like, pretty self explanatory.
1352
01:25:07.090 --> 01:25:13.785
1353
01:25:14.165 --> 01:25:16.105
and you wanna run on your own hardware,
1354
01:25:18.260 --> 01:25:30.074
doing Onion only, doing Tor only is kind of a nonstarter. Like, all your customers need to, you know, open up Tor Browser and and go to your onion link. They can't Depends what kind of merchant you are.
1355
01:25:31.014 --> 01:25:35.920
That's true. It depend it depends on the type of merchant you are. But if you're just like a a standard,
1356
01:25:37.100 --> 01:25:40.540
I'm selling coffee. Yeah. You're selling coffee and,
1357
01:25:40.860 --> 01:25:43.680
you you you you wanna use BTC pay server,
1358
01:25:44.285 --> 01:25:49.025
it's it's pretty much a nonstarter to do Tor only. But the other issue is that if you're
1359
01:25:49.485 --> 01:25:52.065
if you're running it at home, you're running out of your office,
1360
01:25:52.730 --> 01:25:54.670
exposing your IP to the whole world,
1361
01:25:55.130 --> 01:25:57.870
is obviously horrible for your privacy and security.
1362
01:25:58.410 --> 01:25:58.910
So
1363
01:25:59.290 --> 01:26:05.585
they're they have this IP to Tor service integrated where you pay them SATs, and it basically does a tunnel
1364
01:26:05.885 --> 01:26:06.945
through Tor
1365
01:26:07.405 --> 01:26:10.625
to a VPS that they run, and then
1366
01:26:11.100 --> 01:26:13.179
they provide you, like, a clear net,
1367
01:26:14.219 --> 01:26:14.719
IP.
1368
01:26:15.659 --> 01:26:23.375
So you can That sounds a little centralized to me. Yeah. It's extremely centralized, and it's not very reliable, to be honest, but it's a cool feature.
1369
01:26:24.635 --> 01:26:32.639
I've kind of come to the conclusion, and I'm curious of your opinion is, like, if if you're a merchant in that kind of situation I mean, the perfect example is,
1370
01:26:33.739 --> 01:26:38.715
my other podcast, rabbit hole recap, where we accept donations via BTC pay server,
1371
01:26:39.815 --> 01:26:47.830
is to just run a dedicated BTC pay server instance on some server somewhere that's, you know, virtual private server, and you just,
1372
01:26:49.970 --> 01:26:54.630
you just expose that IP address, and you keep it contained, and you just have a separate node for yourself.
1373
01:26:55.275 --> 01:26:58.975
1374
01:27:00.075 --> 01:27:00.475
or,
1375
01:27:01.675 --> 01:27:06.360
in at how we did it there, and that gives you a pretty straightforward way to also,
1376
01:27:07.220 --> 01:27:11.960
expose BTC pay server publicly and also safely, because what we did
1377
01:27:12.275 --> 01:27:12.915
with our,
1378
01:27:13.315 --> 01:27:15.015
with our next bitcoin.org
1379
01:27:15.635 --> 01:27:17.975
is that in nginx, in the web server,
1380
01:27:18.595 --> 01:27:21.680
we, disallow access to a lot of
1381
01:27:22.240 --> 01:27:23.620
the admin API
1382
01:27:24.400 --> 01:27:27.380
and API admin stuff that people don't need
1383
01:27:27.840 --> 01:27:28.340
publicly,
1384
01:27:28.805 --> 01:27:31.945
which I think is a mistake in BTC pay server kind of that,
1385
01:27:32.485 --> 01:27:33.865
the same way you
1386
01:27:34.565 --> 01:27:36.905
administrate the node is also the way you
1387
01:27:37.300 --> 01:27:43.720
access it as a customer. I we have certain issues with v t c pay server, but not to get into it.
1388
01:27:45.745 --> 01:27:51.605
We we block all that stuff, so I think it's really worthwhile to take a look there. But probably
1389
01:27:51.905 --> 01:27:54.645
something we we should make easier in the future.
1390
01:27:55.250 --> 01:27:58.390
But as far as how I would do it if I was a merchant,
1391
01:27:58.770 --> 01:27:59.510
trying to,
1392
01:28:00.690 --> 01:28:02.630
expose not expose my
1393
01:28:02.935 --> 01:28:03.435
public
1394
01:28:03.815 --> 01:28:04.614
IP address,
1395
01:28:05.014 --> 01:28:06.795
but at the same time,
1396
01:28:07.255 --> 01:28:10.155
be available over Clearnet with, high reliability
1397
01:28:11.320 --> 01:28:12.780
is I would use WireGuard,
1398
01:28:14.280 --> 01:28:16.460
to run a very simple
1399
01:28:17.000 --> 01:28:19.980
public VPS server or something that really
1400
01:28:20.355 --> 01:28:21.095
only takes,
1401
01:28:21.635 --> 01:28:25.175
you know, a couple 1 CPU core and maybe 1
1402
01:28:25.715 --> 01:28:30.520
a half a gigabyte of memory to have a a public facing WireGuard server
1403
01:28:31.140 --> 01:28:35.640
that tunnels from from that public IP address to your local machine.
1404
01:28:36.455 --> 01:28:38.955
But, I think that that's something that's,
1405
01:28:40.935 --> 01:28:41.435
yeah,
1406
01:28:41.815 --> 01:28:44.630
that's that's something that isn't isn't straightforward
1407
01:28:45.250 --> 01:28:47.909
as just setting an option and it makes Bitcoin.
1408
01:28:48.449 --> 01:28:48.949
So,
1409
01:28:50.290 --> 01:28:53.190
Jonas, do you think that's something that in the project's
1410
01:28:53.665 --> 01:28:55.684
future to to make easier, or
1411
01:28:56.145 --> 01:28:58.405
1412
01:29:00.704 --> 01:29:01.605
To be honest,
1413
01:29:02.860 --> 01:29:07.520
it should not be too difficult to set this up yourself. I've
1414
01:29:08.060 --> 01:29:14.925
done that a couple of times. There probably ways for Nix Bitcoin to make this simpler for you
1415
01:29:15.225 --> 01:29:15.885
to use.
1416
01:29:17.305 --> 01:29:19.805
Perhaps one thing to mention is that
1417
01:29:21.230 --> 01:29:23.889
if you you you can use NextOS on one machine
1418
01:29:24.429 --> 01:29:27.090
and deploy your configuration to 1 machine,
1419
01:29:27.985 --> 01:29:30.725
But you could also run your whole infrastructure,
1420
01:29:32.145 --> 01:29:42.929
on NextOS, which means that you have one configuration file per server, and you can deploy them all with one command. And they can interact with each other's share, their variables,
1421
01:29:43.550 --> 01:29:44.050
etcetera.
1422
01:29:45.735 --> 01:29:51.275
And once you're doing that, you're definitely not a pleb anymore. So if pleb means anything,
1423
01:29:52.200 --> 01:29:59.660
you're not a pleb anymore. So I I thought about this a lot today. Like, if if you're doing that, you're not a pleb.
1424
01:30:00.425 --> 01:30:02.285
So people should be aware of that.
1425
01:30:02.665 --> 01:30:04.525
1426
01:30:05.465 --> 01:30:06.285
1427
01:30:09.640 --> 01:30:17.980
But, Jonas, how would you go about it? Would you be would you put the BTC pay server on a VPS and have it connect to your Bitcoin node over
1428
01:30:18.545 --> 01:30:22.165
over Wireguard, or would you put the BTC pay server
1429
01:30:22.945 --> 01:30:29.130
on the on the on your own hardware and then just put the public facing Wireguard server on the VPS?
1430
01:30:31.110 --> 01:30:32.650
1431
01:30:33.165 --> 01:30:37.985
on on your situation and how powerful your VPS is. For example,
1432
01:30:38.685 --> 01:30:51.065
sometimes these VPSs that you can get privately are pretty underpowered. So perhaps you don't want you only want to run BTC pay server there, especially if it should be performed. So it all depends, and this is really
1433
01:30:52.425 --> 01:30:52.985
like, when
1434
01:30:53.625 --> 01:30:56.765
if we want to add support for it in next Bitcoin,
1435
01:30:57.260 --> 01:31:01.840
then the question is exactly in what way because people are different and have different,
1436
01:31:02.700 --> 01:31:03.200
requirements.
1437
01:31:03.740 --> 01:31:09.364
And that's why it makes sense to learn how to use NextOS because then you can build these systems,
1438
01:31:09.985 --> 01:31:16.239
by yourself relatively easily. But I think something like IP two Tor is is pretty elegant solution to this problem.
1439
01:31:16.540 --> 01:31:27.824
1440
01:31:28.605 --> 01:31:31.025
thinks about a very specific kind of user
1441
01:31:31.480 --> 01:31:35.260
and makes it easy for that guy. So,
1442
01:31:36.520 --> 01:31:41.100
it thinks about a user who has a b who has a Raspberry Pi 4
1443
01:31:41.625 --> 01:31:46.445
with this and this amount of gigabytes and this and this kind of HD or SSD,
1444
01:31:47.224 --> 01:31:52.190
and who's running it at home and wants to do things that somebody at home does.
1445
01:31:52.730 --> 01:31:56.750
But what makes Bitcoin takes more the root is that we give a basic
1446
01:31:57.130 --> 01:31:58.270
kind of function
1447
01:31:59.055 --> 01:31:59.795
and then and,
1448
01:32:00.815 --> 01:32:05.075
some some really streamlined stuff. And once you wanna do something
1449
01:32:05.455 --> 01:32:05.955
more,
1450
01:32:06.600 --> 01:32:11.420
you start extending it yourself, which is much easier than you think probably.
1451
01:32:12.119 --> 01:32:12.520
And,
1452
01:32:13.480 --> 01:32:17.655
and and once more people start using it and sharing their configurations
1453
01:32:18.035 --> 01:32:19.575
and and writing tutorials,
1454
01:32:20.835 --> 01:32:27.260
it will become as easy as just following a tutorial for your use case. I'm not sure if those are things that we should really,
1455
01:32:28.940 --> 01:32:33.035
determine for people in Nix Bitcoin because Nix Bitcoin tries to take the
1456
01:32:33.335 --> 01:32:34.475
agnostic approach
1457
01:32:34.935 --> 01:32:36.395
and not presume
1458
01:32:36.695 --> 01:32:38.395
a way you're using it.
1459
01:32:39.940 --> 01:32:40.660
1460
01:32:41.780 --> 01:32:50.574
just, just one aspect of that. I'd be in favor of removing features from NixBidco and actually Make it as simple as possible but
1461
01:32:51.034 --> 01:32:51.534
extensible.
1462
01:32:52.235 --> 01:33:05.619
So, that's one of the things that we're investing quite a bit of time on. How can we make NEX Bitcoin extensible? So we have one core NEX Bitcoin system that perhaps has Bitcoin d and perhaps the Lightning implementation
1463
01:33:06.000 --> 01:33:10.175
and sidechains or whatever has a module for,
1464
01:33:11.195 --> 01:33:12.815
having a Tor interface
1465
01:33:13.195 --> 01:33:14.735
and the password interface.
1466
01:33:16.100 --> 01:33:22.840
But everything else would be kind of separate repositories that can be that can have a separate governance
1467
01:33:23.455 --> 01:33:25.795
and would be able to easily integrate
1468
01:33:26.175 --> 01:33:26.735
with this,
1469
01:33:27.295 --> 01:33:27.775
NIX,
1470
01:33:28.574 --> 01:33:29.315
with the,
1471
01:33:29.775 --> 01:33:30.675
like, upstream
1472
01:33:31.054 --> 01:33:33.140
NIX Bitcoin system.
1473
01:33:34.240 --> 01:33:36.660
1474
01:33:37.120 --> 01:33:40.260
once we reach that certain point where we have more features,
1475
01:33:41.975 --> 01:33:45.034
these couple features that we've laid out that we need, like,
1476
01:33:45.655 --> 01:33:48.235
a graphical node manager and other stuff,
1477
01:33:48.570 --> 01:33:55.390
we're not gonna keep on adding to the next Bitcoin, but we're gonna start chiseling away at it and making it more
1478
01:33:56.054 --> 01:33:56.554
robust.
1479
01:33:57.014 --> 01:33:57.514
And,
1480
01:33:58.695 --> 01:33:59.195
and,
1481
01:33:59.815 --> 01:34:00.315
yeah.
1482
01:34:01.255 --> 01:34:13.380
1483
01:34:15.345 --> 01:34:19.365
I don't I'm not sure if I I'm not going to dox him who's doing that anyway.
1484
01:34:20.065 --> 01:34:25.890
So it's already possible, but it's just not very ergonomic at the moment and not documented at all.
1485
01:34:29.205 --> 01:34:32.505
1486
01:34:33.285 --> 01:34:40.080
putting reposting it again because I'm reading through questions now, and I'm not sure what really got answered in the context. So
1487
01:34:40.380 --> 01:34:41.440
somebody's still listening
1488
01:34:43.100 --> 01:34:45.600
and then hasn't had their question properly answered.
1489
01:34:46.324 --> 01:34:46.824
Please,
1490
01:34:47.445 --> 01:34:51.625
write it again maybe if you can because I think when someone's Yeah.
1491
01:34:52.005 --> 01:34:52.324
1492
01:34:53.170 --> 01:34:57.730
I I saw it wasn't a question, but Winsome Hacks was saying, you know, my
1493
01:34:59.090 --> 01:35:01.510
he was commenting on my question, which was
1494
01:35:02.235 --> 01:35:07.534
was the twofold question, which was migration and the ability to choose which Bitcoin version you run.
1495
01:35:08.235 --> 01:35:09.534
And he was saying,
1496
01:35:10.050 --> 01:35:12.870
I think rightfully so, that it's important that we have standardization
1497
01:35:13.170 --> 01:35:15.350
and and these things are easier to use,
1498
01:35:15.890 --> 01:35:17.830
rather than focusing on edge cases.
1499
01:35:18.530 --> 01:35:19.510
The reason I
1500
01:35:20.215 --> 01:35:21.675
brought it up is because
1501
01:35:22.135 --> 01:35:22.795
to me,
1502
01:35:23.574 --> 01:35:33.179
to my monkey brain over here, you know, I see we never had, like, these node projects before. Right? Like, this is like a relatively new phenomenon. If you've been in Bitcoin for a while,
1503
01:35:33.480 --> 01:35:36.380
we used to just, you know, run Bitcoin d or run Bitcoin Core.
1504
01:35:37.255 --> 01:35:40.315
Now you have all these, like, managed node projects. And
1505
01:35:40.615 --> 01:35:44.155
one of the things, like, Umbrel has been making noise about lately is is,
1506
01:35:45.200 --> 01:35:48.100
you know, whether the validity of their claim is correct or not,
1507
01:35:48.560 --> 01:35:56.295
they're taking credit for a lot of the growth in lightning and a lot of the growth in node count and saying that it's it's their users that are running these nodes.
1508
01:35:57.395 --> 01:35:58.535
So in my mind,
1509
01:35:59.315 --> 01:36:00.855
I immediately go to
1510
01:36:01.460 --> 01:36:04.199
this theoretical situation in the future where
1511
01:36:04.900 --> 01:36:08.040
whatever the leading node project is decides to,
1512
01:36:08.895 --> 01:36:09.635
you know,
1513
01:36:10.415 --> 01:36:13.074
push their users towards some kind of contentious,
1514
01:36:15.215 --> 01:36:22.230
version of Bitcoin. So so I'm, like, I think that's, like, a real fear. Like, I think that's something that could happen in the future, and I'd prefer
1515
01:36:23.010 --> 01:36:26.950
if I'd prefer if we weren't trying to figure it out, you know, as it was going down.
1516
01:36:27.315 --> 01:36:32.534
1517
01:36:32.915 --> 01:36:34.490
or deja vu of
1518
01:36:35.290 --> 01:36:35.870
of BitPay
1519
01:36:36.250 --> 01:36:41.790
and, like Yeah. Just, you know. And I think this problem will always be there, where,
1520
01:36:42.205 --> 01:36:53.520
you know, the noob users will come in to, like, whatever, like a MyNode or an Umbrel, and then they'll brag about adding, like, onboarding 9 of 10 nodes of, like, the last year.
1521
01:36:53.900 --> 01:36:58.025
But, I think it's our duty to make sure, like, they go further down the funnel. Right? Like,
1522
01:36:58.585 --> 01:37:01.165
maybe, like, they just get pissed off because, like,
1523
01:37:01.625 --> 01:37:03.885
their channel state just keeps crashing,
1524
01:37:04.505 --> 01:37:06.525
and then they're it just corrupts.
1525
01:37:06.985 --> 01:37:08.010
Other things, like,
1526
01:37:08.489 --> 01:37:08.989
maybe,
1527
01:37:09.610 --> 01:37:12.670
they get jacked because there's just too much attack surface.
1528
01:37:13.449 --> 01:37:14.829
You know, things like that. Like,
1529
01:37:15.655 --> 01:37:20.614
I think no matter what, it'll be whack a mole with whatever is, at the top of that funnel, and,
1530
01:37:21.175 --> 01:37:22.155
it's pretty fucked.
1531
01:37:23.014 --> 01:37:24.074
1532
01:37:24.470 --> 01:37:25.130
also with
1533
01:37:25.590 --> 01:37:29.690
with Node projects, now that you're add adding that layer layer of abstraction,
1534
01:37:30.310 --> 01:37:31.610
you also have to
1535
01:37:31.975 --> 01:37:34.635
kind of find who you align with philosophically.
1536
01:37:35.415 --> 01:37:39.435
And I I'm somewhat skeptical that Nix Bitcoin is gonna become
1537
01:37:39.815 --> 01:37:40.475
by itself,
1538
01:37:40.950 --> 01:37:45.130
Nix Bitcoin is gonna become the go to Bitcoin node for everybody,
1539
01:37:45.430 --> 01:37:46.730
maybe as an underlying,
1540
01:37:49.644 --> 01:37:53.344
as an underlying structure for a more user focused,
1541
01:37:54.284 --> 01:37:55.425
more user friendly,
1542
01:37:56.204 --> 01:38:01.989
thing built on top. But by itself, I don't think I don't see Mixed Bitcoin going that route of being the
1543
01:38:02.290 --> 01:38:02.790
mainstream,
1544
01:38:04.130 --> 01:38:07.555
node project, I guess. But it's something for people who,
1545
01:38:08.415 --> 01:38:11.395
align with our philosophy of of of conservatism,
1546
01:38:11.855 --> 01:38:13.075
stability, security,
1547
01:38:13.880 --> 01:38:16.780
and and taking things into your own hand a little bit,
1548
01:38:17.720 --> 01:38:18.780
technically, also.
1549
01:38:19.720 --> 01:38:20.460
To to,
1550
01:38:21.465 --> 01:38:25.325
to, be be sovereign in that way, which I think is is
1551
01:38:25.945 --> 01:38:29.245
you don't have the option as as the somebody who wants to
1552
01:38:29.770 --> 01:38:30.989
remain sovereign,
1553
01:38:32.010 --> 01:38:36.670
digitally of of being a techno. You need to increase your skills over time
1554
01:38:37.055 --> 01:38:40.195
to because the other side is also increasing their skills
1555
01:38:40.574 --> 01:38:43.074
and and and building a a more
1556
01:38:43.855 --> 01:38:44.574
and more,
1557
01:38:45.055 --> 01:38:46.740
elaborate net of control
1558
01:38:47.080 --> 01:38:47.580
over,
1559
01:38:48.240 --> 01:38:48.740
over,
1560
01:38:49.760 --> 01:38:52.500
you know, companies and and and what whatever.
1561
01:38:52.880 --> 01:38:53.520
And and,
1562
01:38:54.495 --> 01:38:54.995
so
1563
01:38:55.615 --> 01:39:05.730
when you really wanna be sovereign, you need to also kind of understand the technological side. And and if you align with our philosophy of conservatism and security first, then,
1564
01:39:06.510 --> 01:39:11.785
it's it's worth investing the effort. And probably it's not gonna be everybody, but that we're gonna be that
1565
01:39:12.245 --> 01:39:14.585
that per that role in the market.
1566
01:39:14.885 --> 01:39:15.545
1567
01:39:16.565 --> 01:39:22.270
I guess not to beat a dead horse, but just reframe my perspective a little bit. I tend to agree with you that,
1568
01:39:23.050 --> 01:39:26.570
and with Vivek that, you know, next Bitcoin will be,
1569
01:39:29.135 --> 01:39:35.235
and and should be, I think rightfully so, geared to more technical users, who are farther down the funnel.
1570
01:39:36.495 --> 01:39:38.195
I guess my perspective is
1571
01:39:40.820 --> 01:39:46.840
and maybe this is just like a maybe this isn't even on the dev side. Maybe this is more on, like, a tutorial side.
1572
01:39:47.455 --> 01:39:53.474
But to make it easier for people to migrate from these top of the funnel node projects
1573
01:39:54.255 --> 01:39:55.614
down to Nix Bitcoin,
1574
01:39:56.740 --> 01:39:57.240
because,
1575
01:39:58.260 --> 01:40:05.895
you know, right now I mean, I I have pie on my face from earlier in this year when I was calling for a sustained high fee market, and as you can see from mempool.space
1576
01:40:06.275 --> 01:40:09.975
being streamed by now, it's just fees have been fucking low as hell. But
1577
01:40:10.595 --> 01:40:22.190
in a sustained high fee environment, all of a sudden, all those lightning channels you have open become real frictions, you know, sticking points where people, you know, might not like the direction a node project's going,
1578
01:40:23.344 --> 01:40:29.284
but they're hesitant to move because they have to close and then open. So each channel is is 2 on chain transactions.
1579
01:40:31.310 --> 01:40:32.210
So it's just
1580
01:40:33.070 --> 01:40:35.810
you know, I I I think it's just something to consider
1581
01:40:36.910 --> 01:40:38.530
making it easier for
1582
01:40:39.265 --> 01:40:43.284
someone who's already on one of the other node projects to migrate over to Nix.
1583
01:40:43.745 --> 01:40:44.324
But maybe
1584
01:40:44.625 --> 01:40:45.125
Yeah.
1585
01:40:45.585 --> 01:40:49.150
1586
01:40:50.250 --> 01:40:55.470
I I think start 9 is well positioned to be probably, like, the
1587
01:40:56.475 --> 01:40:56.975
most,
1588
01:40:57.355 --> 01:40:57.855
compelling
1589
01:40:58.155 --> 01:40:59.695
top of the funnel solution
1590
01:41:00.315 --> 01:41:01.775
that, you know, has
1591
01:41:02.235 --> 01:41:04.335
a multitude of these sort of offerings.
1592
01:41:05.050 --> 01:41:07.150
Ideally, they have some other competitors,
1593
01:41:08.250 --> 01:41:10.750
that are a bit more respectable, not just Umbrel.
1594
01:41:11.690 --> 01:41:16.255
And then with that then said, you highlighted on a great point of vendor lock in,
1595
01:41:16.875 --> 01:41:21.535
not only between, like, the node boxes, but maybe between the lightning implementations
1596
01:41:21.915 --> 01:41:23.055
themselves. You know?
1597
01:41:24.030 --> 01:41:26.050
And I don't necessarily know if, like,
1598
01:41:27.469 --> 01:41:30.050
we fix that. You know, it's more of, like, on
1599
01:41:31.265 --> 01:41:32.245
a on a standardized
1600
01:41:32.785 --> 01:41:33.285
standardization
1601
01:41:33.825 --> 01:41:40.245
or, like, a a spec level type of thing that needs to be ironed out about, like, the the backups and
1602
01:41:40.580 --> 01:41:44.920
channel DB, you know, like, it it, it gets hairy really fast.
1603
01:41:47.915 --> 01:41:50.015
1604
01:41:50.395 --> 01:41:51.215
would be nice.
1605
01:41:52.235 --> 01:41:52.735
Absolutely.
1606
01:41:53.355 --> 01:42:03.910
I don't exactly see the lock in problem. It would be a problem if it was a problem. But, for example, in respi blitz, if they would make decisions you don't agree with,
1607
01:42:04.325 --> 01:42:07.465
You at least if it's, like, a simple thing using Bitcoin
1608
01:42:07.925 --> 01:42:14.360
core version x versus version y, someone could fork it, and, hopefully, you'd be able to intercept
1609
01:42:14.740 --> 01:42:15.960
the update process
1610
01:42:16.500 --> 01:42:18.920
and, basically point to this forked
1611
01:42:19.300 --> 01:42:28.205
repository instead of the original one. At least with Nix Bitcoin, that would be possible. And it should be possible because, otherwise, you're not in control of your money.
1612
01:42:29.850 --> 01:42:36.110
1613
01:42:36.705 --> 01:42:38.485
have diverging opinions about
1614
01:42:38.865 --> 01:42:41.045
open source and, like, FOSS,
1615
01:42:41.345 --> 01:42:44.485
1616
01:42:44.830 --> 01:42:46.530
that open that
1617
01:42:47.070 --> 01:42:50.929
that free software isn't just something that you throw around
1618
01:42:51.310 --> 01:42:56.885
because it's a cool marketing term, but it's a a way of of thinking about the world.
1619
01:42:57.345 --> 01:43:02.805
That your computer is your property, an extension of your brain and your and you.
1620
01:43:03.600 --> 01:43:04.100
And,
1621
01:43:04.880 --> 01:43:07.300
and free software means being in control of
1622
01:43:07.600 --> 01:43:08.340
that. And,
1623
01:43:09.119 --> 01:43:13.364
Nix Bitcoin takes the maximum approach on that, and we're MIT licensed.
1624
01:43:14.465 --> 01:43:20.005
Somebody also, I think I read in the chat that it needs to be a business and and businesses are,
1625
01:43:20.520 --> 01:43:25.660
Mixed Bitcoin is, first and foremost, a free software project that people develop in their free time.
1626
01:43:26.600 --> 01:43:27.420
People who
1627
01:43:27.975 --> 01:43:33.514
have don't have economic interests except that they wanna have a great node that works really well.
1628
01:43:33.975 --> 01:43:38.710
And there's a place in the market for that too. There isn't just place in the market for glossy,
1629
01:43:40.290 --> 01:43:40.790
glossy,
1630
01:43:41.330 --> 01:43:43.030
quote, unquote, open source
1631
01:43:43.489 --> 01:43:48.835
source available notes. There's also place in the market for a hardcore MIT project,
1632
01:43:49.534 --> 01:43:50.034
hobbyist,
1633
01:43:51.054 --> 01:43:52.114
made with love,
1634
01:43:52.494 --> 01:43:53.315
made carefully,
1635
01:43:53.960 --> 01:43:56.780
made for your own use project, and that's Nix Bitcoin.
1636
01:43:57.159 --> 01:44:01.239
1637
01:44:02.345 --> 01:44:09.245
this is, like, priceless. You know? It's it's not to say, like, this needs a business or whatever. Like, literally, Avionna Snyk, one of the Taproot
1638
01:44:09.640 --> 01:44:13.740
BIP authors working on this as, like, his pet project.
1639
01:44:14.360 --> 01:44:16.380
So, you know, it's something
1640
01:44:16.760 --> 01:44:21.155
1641
01:44:21.695 --> 01:44:27.074
one of the most knowledgeable first people in the world on the inner workings of NYX,
1642
01:44:27.430 --> 01:44:29.530
reviewing every PR meticulously.
1643
01:44:30.390 --> 01:44:33.210
And, also, not to toot my own horn, but
1644
01:44:33.590 --> 01:44:38.114
I'm more on the paranoid side of things as Jonas would probably confirm.
1645
01:44:38.575 --> 01:44:41.475
And, I'm also looking at things, and
1646
01:44:41.935 --> 01:44:44.195
and everything is always open for review.
1647
01:44:45.060 --> 01:44:45.460
And,
1648
01:44:46.340 --> 01:44:50.760
there's some very technical people using it. Again, not to talk to anybody,
1649
01:44:51.220 --> 01:44:56.975
but there's, there's people who know what they're doing who are using NICK's Bitcoin and also looking at code changes.
1650
01:44:57.675 --> 01:45:03.455
So, I think those are things that are a little that are really, as you said, priceless and
1651
01:45:04.460 --> 01:45:05.920
not a business case.
1652
01:45:06.860 --> 01:45:07.680
1653
01:45:08.460 --> 01:45:12.400
I had a flash of autism again. You know, when we linked up, we were talking about
1654
01:45:13.635 --> 01:45:14.135
PTLCs
1655
01:45:14.595 --> 01:45:17.255
and, I guess, Taproot in a sense of, like,
1656
01:45:18.115 --> 01:45:20.855
do channels need to close, or how are they updated?
1657
01:45:22.180 --> 01:45:23.239
We have Jonas
1658
01:45:23.540 --> 01:45:25.460
on here with us too. So,
1659
01:45:27.300 --> 01:45:32.945
1660
01:45:38.045 --> 01:45:38.785
1661
01:45:42.460 --> 01:45:43.020
You will have to
1662
01:45:45.900 --> 01:45:49.605
I mean, you won't get the benefits of music, for example, immediately,
1663
01:45:51.265 --> 01:46:00.950
because your channel's already open. Right? So if you want to close it, you always have to provide 2 signatures to close it. So I guess that's But, PTLC should be separate from that.
1664
01:46:01.890 --> 01:46:02.870
1665
01:46:03.570 --> 01:46:12.055
you you can have, like, the output updated in the existing channel. Right? But, to take advantage of maybe the updates to bolt 7 and 23,
1666
01:46:12.995 --> 01:46:15.415
that's when you need to close it and reopen?
1667
01:46:19.040 --> 01:46:20.740
1668
01:46:25.885 --> 01:46:26.385
1669
01:46:26.685 --> 01:46:27.805
I'm a simple pleb.
1670
01:46:28.685 --> 01:46:30.864
This is this is the impression I was under.
1671
01:46:32.045 --> 01:46:33.265
1672
01:46:33.760 --> 01:46:36.820
for updating to music or for updating to pOTLCs?
1673
01:46:37.840 --> 01:46:38.340
1674
01:46:38.719 --> 01:46:40.420
like, I guess, p t l c's,
1675
01:46:41.199 --> 01:46:41.699
maybe,
1676
01:46:42.080 --> 01:46:43.219
a taproot address,
1677
01:46:45.074 --> 01:46:47.655
music ideally, like, you know, whatever is, like,
1678
01:46:48.435 --> 01:46:52.775
1679
01:46:53.380 --> 01:46:58.199
for our grandchildren. Right? Like, you you wanna have long lasting channels that are
1680
01:46:58.579 --> 01:46:59.480
there for
1681
01:47:00.099 --> 01:47:00.599
years
1682
01:47:00.980 --> 01:47:02.840
and have reputation and whatnot.
1683
01:47:03.435 --> 01:47:06.335
But is that is that just a meme? Like, are we gonna be constantly
1684
01:47:08.235 --> 01:47:11.215
closing our channels, opening them up for whatever
1685
01:47:11.840 --> 01:47:13.460
new goodies we have in line?
1686
01:47:15.520 --> 01:47:23.455
1687
01:47:24.074 --> 01:47:26.574
I'm not really a deep part of the technical
1688
01:47:27.275 --> 01:47:29.775
light lightning community. They would like to
1689
01:47:30.210 --> 01:47:31.890
start with upgrading to,
1690
01:47:32.850 --> 01:47:33.350
music
1691
01:47:33.730 --> 01:47:34.230
first,
1692
01:47:34.690 --> 01:47:44.875
which would mean that instead of having 2 public keys and 2 signatures on the chain for an open and close of a channel, you would only have one public key and one signature.
1693
01:47:46.670 --> 01:47:49.330
But for doing that, of course,
1694
01:47:49.710 --> 01:47:53.090
since the public key is in the channel opening,
1695
01:47:53.550 --> 01:47:55.250
you would have to close and reopen.
1696
01:47:55.835 --> 01:48:05.809
But, perhaps doing that can be deferred to your grandchildren, so you will always have this open channel. I think for if you want to upgrade to l 2, you would have to make another,
1697
01:48:08.210 --> 01:48:11.190
Bitcoin transaction that doesn't have to be a closing transaction, but at least another Bitcoin transaction.
1698
01:48:11.730 --> 01:48:12.995
On Bitcoin transaction.
1699
01:48:17.535 --> 01:48:21.950
1700
01:48:22.730 --> 01:48:23.230
PTLC
1701
01:48:24.250 --> 01:48:25.290
conversation is,
1702
01:48:26.090 --> 01:48:28.430
is that a as a conclusion?
1703
01:48:30.385 --> 01:48:35.844
1704
01:48:36.304 --> 01:48:39.800
1705
01:48:40.100 --> 01:48:47.885
says, I suppose the question then is, who do you see using it? There are many more people not using it and using it and want to migrate.
1706
01:48:48.585 --> 01:48:49.085
So
1707
01:48:49.545 --> 01:48:50.045
right
1708
01:48:50.505 --> 01:48:52.204
now, I really see the technical
1709
01:48:52.585 --> 01:48:53.085
users
1710
01:48:54.025 --> 01:48:55.565
who are focused on mix
1711
01:48:56.050 --> 01:48:57.350
using it at the moment.
1712
01:48:58.370 --> 01:48:58.870
And
1713
01:48:59.970 --> 01:49:05.375
I think that because we're so focused on on improving stuff right now, I don't think
1714
01:49:06.255 --> 01:49:08.195
we even have the time of doing tutorials.
1715
01:49:09.055 --> 01:49:11.955
And and so if if anybody who listening
1716
01:49:12.415 --> 01:49:12.915
is
1717
01:49:13.360 --> 01:49:16.100
a good project, always needs somebody who's into documentation
1718
01:49:17.040 --> 01:49:19.460
and and somebody who's who's
1719
01:49:20.560 --> 01:49:22.020
making videos and
1720
01:49:22.495 --> 01:49:23.315
and, and
1721
01:49:24.175 --> 01:49:26.755
and showing people how to migrate and all this stuff. So
1722
01:49:27.135 --> 01:49:30.835
I think our project would very much benefit from you if you're like that.
1723
01:49:32.180 --> 01:49:37.400
But until that really happens and gets and gets easier, I really see
1724
01:49:38.100 --> 01:49:38.600
the
1725
01:49:39.505 --> 01:49:42.165
technical people using it or people within companies
1726
01:49:42.625 --> 01:49:44.565
who want a good basis to build on,
1727
01:49:45.345 --> 01:49:45.845
just
1728
01:49:46.225 --> 01:49:48.885
using Nix Bitcoin as as their starting point.
1729
01:49:52.220 --> 01:49:53.840
Another question that I saw
1730
01:49:54.540 --> 01:50:02.585
1731
01:50:03.305 --> 01:50:05.885
we should do with NYX Bitcoin because
1732
01:50:06.510 --> 01:50:07.010
perhaps,
1733
01:50:07.470 --> 01:50:09.090
there was this impression earlier
1734
01:50:09.390 --> 01:50:12.690
that we are kind of building Nix Bitcoin for some
1735
01:50:13.150 --> 01:50:13.650
ideal
1736
01:50:14.275 --> 01:50:17.575
Bitcoin user, but that's not the case, at least not for me.
1737
01:50:18.035 --> 01:50:23.175
Whatever I do, I do mostly for myself. I do stuff that I want to use myself. So
1738
01:50:23.660 --> 01:50:24.880
sometimes it's difficult
1739
01:50:25.260 --> 01:50:25.580
to,
1740
01:50:26.380 --> 01:50:27.040
to know
1741
01:50:27.420 --> 01:50:31.875
what is currently on vogue in in the Bitcoin world, like whatever,
1742
01:50:32.494 --> 01:50:34.034
lightning node manager
1743
01:50:34.335 --> 01:50:39.220
or something like that. So I'm always happy to get suggestions in in that area.
1744
01:50:39.840 --> 01:50:51.005
1745
01:50:53.065 --> 01:50:58.750
And and that's we share all of the knowledge. We share the use cases, and the more people who
1746
01:50:59.610 --> 01:51:03.150
put in the effort to get into next Bitcoin, the better it's gonna become.
1747
01:51:03.465 --> 01:51:08.605
And another thing that I really wanna get into with Nix Bitcoin is is exploring the different
1748
01:51:09.144 --> 01:51:14.159
ways that Nix OS has, or in the Nix OS community of verifying
1749
01:51:14.540 --> 01:51:15.040
packages
1750
01:51:15.580 --> 01:51:16.800
in in the way that
1751
01:51:17.420 --> 01:51:17.920
reproducibility
1752
01:51:18.380 --> 01:51:20.159
is understood in the Bitcoin world.
1753
01:51:21.264 --> 01:51:26.724
I think we that's something we really need to do, Jonas. And we talked about originally, there was something
1754
01:51:27.184 --> 01:51:28.804
trustics that came up
1755
01:51:29.110 --> 01:51:32.730
that build basically, packages get built on on a decentralized
1756
01:51:33.030 --> 01:51:39.995
network of of servers controlled by different people, and then hashes gets of the final binaries get compared,
1757
01:51:40.455 --> 01:51:42.395
and then only the ones where
1758
01:51:42.695 --> 01:51:49.790
they truly are the same for everybody get get put into the system for users to download from. And
1759
01:51:51.130 --> 01:51:52.270
we really need to
1760
01:51:53.050 --> 01:51:54.590
exploit more the
1761
01:51:54.955 --> 01:51:55.455
reproducibility
1762
01:51:55.994 --> 01:51:59.135
in the sense Bitcoin nature of of Nix OS.
1763
01:52:00.715 --> 01:52:06.400
1764
01:52:06.860 --> 01:52:13.335
like, you do a next Bitcoin upgrade and perhaps your Bitcoin d version upgrades, and usually you would go to the
1765
01:52:13.735 --> 01:52:17.355
Nexo as as cash and download the new,
1766
01:52:17.895 --> 01:52:19.114
Bitcoin d version.
1767
01:52:20.775 --> 01:52:24.890
But that's, of course, a problem if you do that, and the cash
1768
01:52:25.350 --> 01:52:30.969
that is maintained by the Nixo as people is compromised and would, provide a
1769
01:52:31.974 --> 01:52:33.275
backdoor to Bitcoin
1770
01:52:33.815 --> 01:52:39.914
deal. So, what we're actually suggesting in the tutorial is to build everything yourself.
1771
01:52:40.820 --> 01:52:44.360
So then when you do a next Bitcoin upgrade,
1772
01:52:46.099 --> 01:52:53.485
it actually takes a while for me on my system. Usually, it depends sometimes half a day or so. But, during that time,
1773
01:52:54.025 --> 01:52:54.685
the whole
1774
01:52:55.385 --> 01:52:58.364
system, everything that changed is rebuilt
1775
01:52:59.090 --> 01:53:03.429
from source. And I think that's also a really great, security feature.
1776
01:53:04.449 --> 01:53:07.030
1777
01:53:07.335 --> 01:53:10.395
I have is, is in my network and build server
1778
01:53:10.695 --> 01:53:14.475
where every every NixOS computer every NixOS machine,
1779
01:53:15.820 --> 01:53:23.600
running in my network put hands off all the intensive build tasks to the to the, build server, which has
1780
01:53:23.915 --> 01:53:32.895
a lot of cores, high memory. It's obviously not something that everybody can use. But if you're going the maximum security way, you wanna build everything from source and don't wanna wait half a day,
1781
01:53:33.240 --> 01:53:35.100
that's something we should look into.
1782
01:53:45.365 --> 01:53:54.960
Jonas, that was just I quickly Jake, continue, please. I just quickly wanted to so not everybody thinks that it's the only option is wedding half a day. You have the option of
1783
01:53:55.420 --> 01:54:04.074
1784
01:54:04.614 --> 01:54:06.635
1785
01:54:10.650 --> 01:54:11.950
1786
01:54:12.810 --> 01:54:21.295
so there are at least 3 three points on non Nix Bitcoin that I would like to to make before we go on to this other nerd discussion.
1787
01:54:22.075 --> 01:54:23.035
So one is that,
1788
01:54:23.755 --> 01:54:26.875
a security feature that we haven't mentioned yet are,
1789
01:54:28.460 --> 01:54:29.280
which I think
1790
01:54:29.659 --> 01:54:30.239
are underappreciated
1791
01:54:31.020 --> 01:54:32.719
are, Bitcoin d,
1792
01:54:33.260 --> 01:54:33.760
RPC
1793
01:54:34.380 --> 01:54:35.280
white lists.
1794
01:54:36.165 --> 01:54:38.345
So what that is, that's a list
1795
01:54:38.805 --> 01:54:39.864
that a bitcoindrpcuser,
1796
01:54:42.725 --> 01:54:47.460
is allowed to it's a list of RPC commands that a Bitcoin DRPC
1797
01:54:48.080 --> 01:54:49.860
user is allowed to make.
1798
01:54:51.585 --> 01:54:53.525
So you could have a public,
1799
01:54:53.985 --> 01:54:56.645
Bitcoin RPC user, which we're doing in,
1800
01:54:57.345 --> 01:54:58.165
NYX Bitcoin,
1801
01:54:58.465 --> 01:55:00.005
and that public user
1802
01:55:01.140 --> 01:55:04.920
only has read access to your Bitcoin d note.
1803
01:55:05.540 --> 01:55:10.360
So the white list would say, yeah, you can you can, read blocks
1804
01:55:11.205 --> 01:55:12.085
or you can,
1805
01:55:14.005 --> 01:55:18.425
check what the chain tip is or you can see the peers, but you cannot
1806
01:55:18.725 --> 01:55:19.945
use send to address
1807
01:55:20.310 --> 01:55:24.329
or you cannot interact with the wallet at all because the RPC command
1808
01:55:24.630 --> 01:55:25.290
is not,
1809
01:55:26.070 --> 01:55:27.449
allowed to be used.
1810
01:55:28.175 --> 01:55:31.635
And, where is this useful? For example, it's useful,
1811
01:55:33.295 --> 01:55:40.620
if c lightning is compromised because usually, c lightning has full access has RPC access to to Bitcoin d.
1812
01:55:41.239 --> 01:55:43.820
So it a compromised c lightning
1813
01:55:44.325 --> 01:55:45.225
could, easily,
1814
01:55:46.325 --> 01:55:47.065
just spend
1815
01:55:47.445 --> 01:55:54.570
all the coins in the Bitcoin wallet as well, which is something that, of course, you want to prevent. But if you use these, white lists,
1816
01:55:55.670 --> 01:55:59.770
which we do by default in in Bitcoin, then even a compromise c lightning
1817
01:56:00.305 --> 01:56:04.324
cannot steal your coins on Bitcoin d because it uses
1818
01:56:04.625 --> 01:56:06.085
these, white lists.
1819
01:56:11.960 --> 01:56:19.975
So everyone who's maintain who's running their own, Bitcoin node should think about this and integrate it or switch to next Bitcoin to make use of,
1820
01:56:20.614 --> 01:56:21.995
Bitcoin DRPC wireless?
1821
01:56:22.695 --> 01:56:24.955
1822
01:56:26.150 --> 01:56:30.730
So, for BTC pace and for example, we don't just give it the admin macaroons.
1823
01:56:31.190 --> 01:56:34.250
We make a custom macaroons that only includes
1824
01:56:34.935 --> 01:56:35.175
the,
1825
01:56:35.815 --> 01:56:37.114
permissions that,
1826
01:56:37.815 --> 01:56:39.355
BTS and pay silver absolutely
1827
01:56:39.974 --> 01:56:41.355
needs for LND.
1828
01:56:46.460 --> 01:56:48.160
1829
01:56:48.700 --> 01:56:49.520
second one
1830
01:56:49.975 --> 01:56:53.595
is that we have a relatively comprehensive test framework.
1831
01:56:54.135 --> 01:56:56.235
So that means that if you open a PR,
1832
01:56:56.535 --> 01:56:56.935
then,
1833
01:56:57.530 --> 01:57:00.910
basically, a next Bitcoin will be spun up on a VM,
1834
01:57:01.290 --> 01:57:02.670
and it will be checked,
1835
01:57:03.050 --> 01:57:06.350
whether all the services are running and whether they can interact
1836
01:57:07.025 --> 01:57:14.325
with each other. And this is really useful. It's also basically a feature of, NextOS. I mean, other people can reproduce it,
1837
01:57:15.030 --> 01:57:19.770
but it works quite well. And as a result, we have relatively frequent releases
1838
01:57:20.230 --> 01:57:24.755
because we don't really when we do updates, we don't have to do manual testing,
1839
01:57:25.535 --> 01:57:31.155
really, perhaps a bit. But, if these tests are running, then we know basically that we can,
1840
01:57:31.535 --> 01:57:32.035
release,
1841
01:57:32.970 --> 01:57:36.830
the software. That's really nice. And also what this test framework
1842
01:57:37.130 --> 01:57:39.070
allows you to do is,
1843
01:57:40.170 --> 01:57:40.910
to have
1844
01:57:41.705 --> 01:57:42.205
a
1845
01:57:42.665 --> 01:57:43.965
set up so it's okay.
1846
01:57:44.344 --> 01:57:47.965
It says this. Some of our back reports are scripts.
1847
01:57:49.280 --> 01:57:55.460
They are scripts that's built in Nix Bitcoin system and try to reproduce this bug.
1848
01:57:56.160 --> 01:57:56.400
And,
1849
01:57:57.505 --> 01:58:07.125
that works similar to the VM examples that we mentioned earlier. So you run the script. It can be just a few lines, sometimes 5, 6 lines,
1850
01:58:08.260 --> 01:58:10.280
and this will spin up a VM
1851
01:58:10.820 --> 01:58:19.205
and, with all the next Bitcoin services, and we'll try to do something weird that will exercise this bug. And this is a really nice feature,
1852
01:58:20.785 --> 01:58:24.965
because it allows you to quickly figure out what the problem is and how to solve it.
1853
01:58:27.090 --> 01:58:27.910
1854
01:58:30.930 --> 01:58:31.430
1855
01:58:32.705 --> 01:58:36.325
I think another point that next Bitcoin dev made earlier
1856
01:58:36.945 --> 01:58:37.765
was that,
1857
01:58:39.265 --> 01:58:40.085
next Bitcoin
1858
01:58:40.385 --> 01:58:40.885
is
1859
01:58:41.630 --> 01:58:42.930
for technical people,
1860
01:58:43.310 --> 01:58:45.570
but Nix Bitcoin is also a sandbox.
1861
01:58:46.670 --> 01:58:47.890
Nix Bitcoin is
1862
01:58:48.670 --> 01:58:49.170
modules,
1863
01:58:49.535 --> 01:58:50.355
Nixos modules.
1864
01:58:50.735 --> 01:58:55.315
And if you use the tutorial to set it up, you will use our preset
1865
01:58:55.855 --> 01:58:56.255
to,
1866
01:58:57.890 --> 01:58:59.989
which basically says how these services
1867
01:59:00.610 --> 01:59:07.425
interact with each other. We call this preset secure node, by the way, because it does all the Tor by default
1868
01:59:07.885 --> 01:59:08.785
stuff, etcetera.
1869
01:59:09.245 --> 01:59:21.105
But you don't have to use it that way. You can use it in any way you like if you understand NextOS. But what I think follows from that is that anyone since Next is also composable,
1870
01:59:21.645 --> 01:59:27.085
anyone could try to build something more user friendly on top. I mean, if you
1871
01:59:28.480 --> 01:59:31.860
let's let's say a graphical user interface, for example.
1872
01:59:32.320 --> 01:59:32.820
So,
1873
01:59:33.280 --> 01:59:46.195
we have a user interface, but it's command line based. I think it's pretty good. It has versioning. It will tell you if you if there are incompatible changes in a new version, it will tell you what to do in such a case.
1874
01:59:46.640 --> 01:59:47.360
But it's,
1875
01:59:48.080 --> 01:59:51.940
just a command line interface. Other people may prefer graphical user interfaces.
1876
01:59:52.400 --> 01:59:53.300
And I think
1877
01:59:53.815 --> 01:59:54.315
because
1878
01:59:54.615 --> 01:59:56.235
NextOS is so composable,
1879
01:59:56.695 --> 02:00:03.500
it's relatively easy, if you know something about NextOS, to build stuff on top that's more user friendly.
1880
02:00:07.400 --> 02:00:09.580
1881
02:00:10.385 --> 02:00:12.705
about you guys are never gonna implement graph,
1882
02:00:13.105 --> 02:00:14.325
GUIs yourself. Right?
1883
02:00:14.785 --> 02:00:17.775
1884
02:00:19.220 --> 02:00:23.400
1885
02:00:23.780 --> 02:00:24.280
and,
1886
02:00:27.514 --> 02:00:29.295
you know, your brother mentioned something,
1887
02:00:30.074 --> 02:00:33.775
some time ago about it was the next GUI thing, but
1888
02:00:34.240 --> 02:00:36.420
I also like the command line interface.
1889
02:00:37.200 --> 02:00:42.980
So I don't know. I'm I'm not I wouldn't be bullish on that. Yeah. I mean, Raspberry Blitz made the same decision.
1890
02:00:43.885 --> 02:00:45.025
Yeah. Great.
1891
02:00:45.325 --> 02:00:51.265
They they're much better than everything I'm hearing here. This is really good stuff about Raspberry Pi Blitz.
1892
02:00:51.960 --> 02:00:53.340
1893
02:00:53.960 --> 02:00:57.420
and, Ronin Dojo. But, man, I was gonna say these guys are,
1894
02:00:58.440 --> 02:01:09.600
1895
02:01:10.080 --> 02:01:15.860
1896
02:01:16.960 --> 02:01:19.380
Electron, which sucks, or,
1897
02:01:20.545 --> 02:01:21.364
Node, which
1898
02:01:22.145 --> 02:01:23.205
JS, which has
1899
02:01:23.585 --> 02:01:32.840
you know, we used to think that supply chain attacks are in theory and never happened, but now we know they do happen, and they happen almost exclusively through NPM and the Node.
1900
02:01:33.300 --> 02:01:33.800
Js,
1901
02:01:35.060 --> 02:01:35.560
ecosystem.
1902
02:01:35.940 --> 02:01:36.440
So
1903
02:01:37.445 --> 02:01:41.864
GUI thing to me, at least to be a huge problem. And also on,
1904
02:01:42.565 --> 02:01:46.264
on Linux, as long as you're not using Wayland, which is the newest,
1905
02:01:47.830 --> 02:01:48.570
kind of
1906
02:01:48.950 --> 02:01:49.450
graphical,
1907
02:01:50.310 --> 02:01:55.130
driver behind the scenes. If you do X Server, which is the standard on pretty much everything,
1908
02:01:55.935 --> 02:01:59.315
you have to know that each one of your GUIs can see
1909
02:02:00.015 --> 02:02:07.030
all other GUIs and can read all keystrokes from all other GUIs. So that's maybe something that reflects badly on Linux in general,
1910
02:02:07.489 --> 02:02:09.349
but that's the way it works and,
1911
02:02:10.050 --> 02:02:10.869
it's a terrible
1912
02:02:11.815 --> 02:02:16.875
thing. It's it's a huge security hole, and the only way to get around that,
1913
02:02:17.495 --> 02:02:22.530
while staying in the Linux world is by using Wayland, which is really good and,
1914
02:02:23.389 --> 02:02:26.290
is already being used, I think, in Fedora and Linux
1915
02:02:26.909 --> 02:02:28.929
Mint. I'm not sure, but definitely in Fedora.
1916
02:02:29.855 --> 02:02:31.875
Or using something like cubes OS,
1917
02:02:32.335 --> 02:02:36.595
which goes the extreme route of running everything in its own virtual machine.
1918
02:02:37.820 --> 02:02:38.320
But,
1919
02:02:39.580 --> 02:02:44.560
yeah, it's it's gooeys bring a lot of problems. They're not just good.
1920
02:02:45.100 --> 02:02:46.720
If you want a hardcore security
1921
02:02:47.985 --> 02:02:48.485
node,
1922
02:02:48.785 --> 02:02:49.925
privacy node,
1923
02:02:50.625 --> 02:02:54.725
probably it's a good decision to stay away from GUIs in general.
1924
02:02:56.030 --> 02:02:56.429
And,
1925
02:02:56.830 --> 02:03:00.210
one off the topic thing I want to say before Jonas
1926
02:03:00.670 --> 02:03:01.570
makes his
1927
02:03:01.950 --> 02:03:02.770
third point,
1928
02:03:03.715 --> 02:03:04.375
right, about
1929
02:03:05.235 --> 02:03:06.055
next Bitcoin
1930
02:03:06.595 --> 02:03:07.415
is that
1931
02:03:07.955 --> 02:03:08.275
privacy
1932
02:03:09.395 --> 02:03:10.855
I tried to say this often,
1933
02:03:11.170 --> 02:03:14.389
and I also wanna say it here is that privacy is not something dark.
1934
02:03:14.929 --> 02:03:15.429
Privacy
1935
02:03:15.810 --> 02:03:23.605
is not something illicit or criminal. Privacy is the basic way that the world used to work and should return to working that
1936
02:03:24.065 --> 02:03:26.405
a human being has control over
1937
02:03:27.184 --> 02:03:31.660
who he exposes private information to and to what degree and
1938
02:03:32.200 --> 02:03:34.940
and and for how long and, you know, just
1939
02:03:35.240 --> 02:03:44.025
really the individual being in control and and they the way it works now with with regulation and all these things are toothless,
1940
02:03:44.725 --> 02:03:46.025
and we're moving
1941
02:03:46.420 --> 02:03:53.159
into a world that's that's not the way it's supposed to work. And privacy is not the issue. Privacy is actually
1942
02:03:53.954 --> 02:04:13.020
the the most important thing that we're losing and it's not it's not, you know, something that usually in the marketing things, privacy is portrayed as some, you know, somebody with dark goggles and a hoodie, and it's not that. It's and and bit makes Bitcoin is not a target project because we use Tor and privacy.
1943
02:04:13.385 --> 02:04:24.290
It's a very bright project, so a positive project that we give the user control over who he exposes information to, and we always make the decision towards privacy,
1944
02:04:25.309 --> 02:04:26.210
for the user,
1945
02:04:27.469 --> 02:04:30.130
and and he needs to invest effort to
1946
02:04:30.515 --> 02:04:32.215
leave that secure space.
1947
02:04:32.915 --> 02:04:37.975
And and I think that's how it's supposed to be. If you wanna start risking stuff,
1948
02:04:39.120 --> 02:04:42.820
you should have the technical knowledge of how it works. But by default,
1949
02:04:43.280 --> 02:04:45.540
we wanna protect you as much as we can.
1950
02:04:46.375 --> 02:04:48.155
So, Jonas, please continue.
1951
02:04:48.614 --> 02:04:54.474
Just this is something important that I wanna say on every report that I have.
1952
02:04:55.090 --> 02:04:57.650
1953
02:04:58.530 --> 02:05:01.349
I'm kind of a broken record on the show about it. So,
1954
02:05:02.105 --> 02:05:04.045
but the freaks can always use another reminder.
1955
02:05:06.505 --> 02:05:07.005
1956
02:05:07.945 --> 02:05:16.639
I actually made my 3 points already. The only thing left on my list is, like, what what to do, where where to start if you want to use the next Bitcoin now.
1957
02:05:20.255 --> 02:05:25.155
Should should I go on with that? Or do we have more discussion topics? Where to start?
1958
02:05:25.630 --> 02:05:26.130
1959
02:05:26.670 --> 02:05:28.610
1960
02:05:29.070 --> 02:05:38.245
1961
02:05:38.885 --> 02:05:40.025
Libera. It's
1962
02:05:41.125 --> 02:05:42.265
pound Nix
1963
02:05:42.860 --> 02:05:43.600
dash Bitcoin,
1964
02:05:44.380 --> 02:05:48.400
1965
02:05:49.100 --> 02:05:49.600
1966
02:05:51.270 --> 02:05:51.770
Then
1967
02:05:52.765 --> 02:05:56.864
we have this tutorial. So if you go on to GitHub /
1968
02:05:57.245 --> 02:05:57.745
GitHub.com/fortdashnix/
1969
02:06:00.960 --> 02:06:01.460
nixdashbitcoin,
1970
02:06:03.120 --> 02:06:08.420
then, you will find a read me, and there's a get started section, and that brings you to a tutorial,
1971
02:06:08.725 --> 02:06:12.665
kind of discuss what it what it does. But that should be a good start and should
1972
02:06:13.045 --> 02:06:13.545
basically
1973
02:06:14.085 --> 02:06:17.990
work if you have a target system. If you don't have a target system,
1974
02:06:18.530 --> 02:06:22.630
then you can just run the examples. We also discussed this this earlier.
1975
02:06:23.010 --> 02:06:26.795
As long as you have the next package manager, that should be also easily
1976
02:06:27.735 --> 02:06:30.715
installable, I guess, with regular package managers,
1977
02:06:31.015 --> 02:06:32.235
depends on your distro.
1978
02:06:32.870 --> 02:06:34.010
But these examples,
1979
02:06:35.670 --> 02:06:40.385
they worked on macOS at one point, but I don't think they work anymore, unfortunately.
1980
02:06:41.085 --> 02:06:43.264
So for that, you would need a a Linux
1981
02:06:44.364 --> 02:06:44.864
machine.
1982
02:06:49.540 --> 02:06:56.040
What else? I think those those are the the most most important points how to get started if you want to use Next Bitcoin.
1983
02:06:59.864 --> 02:07:00.765
Yeah. Nixbitcon.org,
1984
02:07:01.545 --> 02:07:04.125
that's also another repository in the Fortnix
1985
02:07:05.640 --> 02:07:06.140
organization.
1986
02:07:07.640 --> 02:07:14.300
And there, you basically have a good example of how you could set up a system, for example, with a public BTC pay server,
1987
02:07:15.364 --> 02:07:15.864
etcetera.
1988
02:07:16.645 --> 02:07:17.145
And,
1989
02:07:17.764 --> 02:07:25.550
yeah, lastly, if you would just want to learn more about NYX, I'm not sure if I've, mentioned earlier, they are also the so called nicks pills,
1990
02:07:26.330 --> 02:07:28.489
and, this is a tutorial that,
1991
02:07:29.130 --> 02:07:30.110
basically explains
1992
02:07:30.994 --> 02:07:33.655
all the advantages of NIX and also gives you an introduction
1993
02:07:34.195 --> 02:07:34.695
into,
1994
02:07:35.554 --> 02:07:37.895
NIX as a programming language.
1995
02:07:39.150 --> 02:07:44.690
1996
02:07:45.630 --> 02:07:47.570
I I went at it, I think, also,
1997
02:07:48.565 --> 02:07:54.105
like, other people using Nix Bitcoin, who I know of, from the hacker side where I just
1998
02:07:54.885 --> 02:07:57.465
used it until I figured out how to use it.
1999
02:07:57.870 --> 02:07:58.350
And,
2000
02:07:58.830 --> 02:08:01.730
that's also if you're more that kind, then
2001
02:08:02.190 --> 02:08:07.165
I I and also another person that I know who uses NixBitcoin can give testimony
2002
02:08:07.545 --> 02:08:09.324
that that also works. So,
2003
02:08:09.864 --> 02:08:18.310
you don't have to have a background in computer science to to with the right attitude, get get, you know, get this thing running.
2004
02:08:19.730 --> 02:08:22.150
2005
02:08:22.485 --> 02:08:22.985
Absolutely.
2006
02:08:25.845 --> 02:08:26.745
2007
02:08:27.365 --> 02:08:28.585
2008
02:08:29.820 --> 02:08:32.320
2009
02:08:34.139 --> 02:08:34.800
2010
02:08:36.059 --> 02:08:39.784
2011
02:08:40.085 --> 02:08:44.184
2012
02:08:45.045 --> 02:08:47.385
with its own language and everything, and,
2013
02:08:48.290 --> 02:08:49.750
yeah, I'll just get that.
2014
02:08:50.530 --> 02:08:52.390
2015
02:08:52.850 --> 02:08:57.885
They, like, call them, like, planets, stars, and universes. And imagine if DNS
2016
02:08:58.344 --> 02:09:00.684
2017
02:09:00.985 --> 02:09:03.005
and they also had, like, a language
2018
02:09:03.625 --> 02:09:03.864
to,
2019
02:09:05.200 --> 02:09:06.500
essentially provision,
2020
02:09:07.120 --> 02:09:12.020
2021
02:09:13.554 --> 02:09:16.215
My pure Bitcoin head has never heard of this.
2022
02:09:17.795 --> 02:09:21.655
2023
02:09:22.940 --> 02:09:30.880
to this tiny little mention of it, and, they're all gonna flood our mentions now. Next Bitcoin is gonna get this this is like the
2024
02:09:31.295 --> 02:09:39.075
2025
02:09:41.120 --> 02:09:44.420
2026
02:09:45.520 --> 02:09:50.420
Because somebody opened a PR, and they they can't I mean, something called squeak mode,
2027
02:09:51.094 --> 02:09:55.994
which doesn't have a description in its repo, and I have no idea what it does.
2028
02:09:56.375 --> 02:09:58.954
If anybody knows what it is, please tell us.
2029
02:10:01.530 --> 02:10:03.630
No. You ever you ever figured that out?
2030
02:10:04.969 --> 02:10:07.310
2031
02:10:07.855 --> 02:10:09.875
But the PR gets updated.
2032
02:10:10.335 --> 02:10:12.755
2033
02:10:13.454 --> 02:10:13.954
At,
2034
02:10:14.335 --> 02:10:27.585
2035
02:10:28.364 --> 02:10:32.465
2036
02:10:32.845 --> 02:10:33.720
I'll figure it out.
2037
02:10:37.640 --> 02:10:47.074
I guess, is this the time where now I can just, like, Yeah. Just you want you want your autism to run wild? Or Yes. You wanna wrap it up? Wait a sec. Wait a sec.
2038
02:10:48.735 --> 02:10:49.554
Go ahead.
2039
02:10:49.980 --> 02:10:50.560
2040
02:10:51.260 --> 02:10:56.160
2041
02:10:56.825 --> 02:11:01.885
2042
02:11:02.345 --> 02:11:04.525
2043
02:11:05.050 --> 02:11:06.750
Just trying my best out here.
2044
02:11:07.690 --> 02:11:10.970
I'll tell you, this conversation has been fantastic. I've learned a lot. So
2045
02:11:11.530 --> 02:11:13.630
and I look forward to trying Nick's out.
2046
02:11:15.135 --> 02:11:17.955
2047
02:11:18.574 --> 02:11:21.554
being really cool and also Erbit.
2048
02:11:22.010 --> 02:11:27.790
I I'm kind of curious now. I wanna take a look at it, see if I if I can grok it.
2049
02:11:31.045 --> 02:11:35.385
2050
02:11:38.060 --> 02:11:42.480
2051
02:11:43.500 --> 02:11:44.240
just like
2052
02:11:45.275 --> 02:11:48.875
I I reminisced to the bear market times of 2018, and,
2053
02:11:49.835 --> 02:11:50.895
you guys, TFTC,
2054
02:11:51.675 --> 02:11:52.575
Stefan Lavera,
2055
02:11:52.955 --> 02:11:57.020
Block Digest pretty much got me through. Everything else was kinda shit corny. So,
2056
02:11:57.960 --> 02:11:59.579
it's amazing to see what,
2057
02:12:00.039 --> 02:12:00.539
these,
2058
02:12:01.079 --> 02:12:01.805
quote, unquote,
2059
02:12:02.445 --> 02:12:05.745
podcasts have blossomed to be as, like, communities now.
2060
02:12:07.725 --> 02:12:09.185
2061
02:12:10.890 --> 02:12:16.350
2062
02:12:17.264 --> 02:12:18.485
So, Jonas,
2063
02:12:19.505 --> 02:12:24.324
because, you know, you're into this Taproot stuff and, you happen to be one of these BIP authors,
2064
02:12:25.600 --> 02:12:35.220
I'm curious, you know, what's up with signatures these days? You know, I'll be in the DMs with Shinobi once in a while. They'll be floating some other random ring signature stuff.
2065
02:12:35.585 --> 02:12:38.565
I watched some half aggregation stuff that you posted
2066
02:12:38.945 --> 02:12:43.745
that may be used for, gossip, and then also music could be used for gossip. So,
2067
02:12:44.890 --> 02:12:48.190
we'd love to dive deep into the signature
2068
02:12:48.650 --> 02:12:49.550
rabbit hole
2069
02:12:50.170 --> 02:12:51.310
and, potentially
2070
02:12:52.315 --> 02:12:53.295
end at, like,
2071
02:12:54.075 --> 02:12:56.255
where threshold is at these days.
2072
02:12:57.835 --> 02:12:59.935
2073
02:13:00.475 --> 02:13:00.975
conversation.
2074
02:13:03.849 --> 02:13:06.030
Okay. Where are signatures these days?
2075
02:13:06.809 --> 02:13:12.525
According to my best estimate, Taproot will activate sometime November 14th.
2076
02:13:13.545 --> 02:13:18.890
So from then on, we will have, Schnorr signatures on Bitcoin main chain, which will be
2077
02:13:19.850 --> 02:13:20.670
really nice.
2078
02:13:22.010 --> 02:13:25.390
Will be interesting to see how people are going to use it.
2079
02:13:26.494 --> 02:13:29.315
Right now, I spend a lot of my time trying to,
2080
02:13:30.094 --> 02:13:31.474
make music usable.
2081
02:13:32.175 --> 02:13:34.815
I talked a bit early about about it, which,
2082
02:13:35.400 --> 02:13:36.860
basically, what it does is,
2083
02:13:37.320 --> 02:13:39.500
if you had previous if you have a multisig,
2084
02:13:41.159 --> 02:13:43.500
let's say a 2 of 2 in the lightning case,
2085
02:13:44.205 --> 02:13:49.185
then right now, you would have to write both public keys. And then if you close the channel,
2086
02:13:49.485 --> 02:13:53.630
both signatures on chain, which is both bad for privacy,
2087
02:13:54.090 --> 02:13:57.230
and, also, it costs more money using lightning,
2088
02:13:57.929 --> 02:13:58.670
that way
2089
02:13:59.050 --> 02:14:08.575
compared to having just a single public key and a single signature, which is what, music would allow you to do. And this is what I hinted at earlier that
2090
02:14:09.410 --> 02:14:13.890
the Lightning people are really interested in making this upgrade once,
2091
02:14:14.370 --> 02:14:14.870
Taproot
2092
02:14:15.330 --> 02:14:15.830
is,
2093
02:14:16.985 --> 02:14:20.204
or has landed on main chain. But, of course, this all needs to
2094
02:14:20.665 --> 02:14:23.945
be spec'd out how exactly this is going to look like. So,
2095
02:14:24.870 --> 02:14:28.010
the lightning people need to do that. But before they can do that,
2096
02:14:29.270 --> 02:14:31.610
we also need to, write a specification
2097
02:14:31.910 --> 02:14:37.905
how exactly music should look like. Like, how to how do the various signers interact to actually
2098
02:14:38.285 --> 02:14:41.985
aggregate their public keys and signatures into a single
2099
02:14:43.219 --> 02:14:46.120
signature. So I'm working on that. Implementing this,
2100
02:14:46.739 --> 02:14:50.199
in Libsec p z Libsec p z k p right now,
2101
02:14:50.905 --> 02:14:54.844
which is a a fork of Libsec p, the the library that Bitcoin Core
2102
02:14:55.224 --> 02:14:55.724
uses,
2103
02:14:57.145 --> 02:14:59.485
and also trying to to spec it out.
2104
02:15:00.690 --> 02:15:04.949
And there are also, like, regular wallet authors who would like to use music.
2105
02:15:06.130 --> 02:15:07.110
There are some
2106
02:15:07.489 --> 02:15:08.790
like having this.
2107
02:15:11.315 --> 02:15:11.975
Some wallets,
2108
02:15:12.515 --> 02:15:19.540
wallets provide multisync functionality, and they want to use music as well because they see as it as a big advantage for their users,
2109
02:15:20.160 --> 02:15:30.555
if they have to pay less fees. And, also, if it isn't immediately obvious on chain that someone is using a multisig wallet, which I think is a really big benefit of these things.
2110
02:15:31.735 --> 02:15:33.975
So that's in the music world. But,
2111
02:15:37.020 --> 02:15:40.480
there are many different things that we we also want to do.
2112
02:15:40.940 --> 02:15:41.099
So,
2113
02:15:42.860 --> 02:15:44.480
you mentioned ring signatures.
2114
02:15:45.475 --> 02:15:46.375
So interestingly,
2115
02:15:46.675 --> 02:15:46.915
in,
2116
02:15:49.555 --> 02:15:50.535
in SegWitv0,
2117
02:15:51.875 --> 02:15:52.695
our current,
2118
02:15:53.235 --> 02:15:54.135
most recent
2119
02:15:55.290 --> 02:15:57.630
address format. In order to spend it,
2120
02:15:58.090 --> 02:15:58.650
you need,
2121
02:15:59.290 --> 02:16:01.230
to reveal the public key
2122
02:16:01.875 --> 02:16:04.375
because in the output of this coin
2123
02:16:04.994 --> 02:16:07.815
or of this u UTXO, there's only is is
2124
02:16:08.275 --> 02:16:10.695
a hash of the public key. Right?
2125
02:16:12.110 --> 02:16:16.690
So that will change in Taproot where the, public key,
2126
02:16:18.510 --> 02:16:20.530
is barely written or is
2127
02:16:21.025 --> 02:16:22.885
is written into the output,
2128
02:16:23.585 --> 02:16:24.565
of this coin.
2129
02:16:25.585 --> 02:16:27.525
So that means there's no hashing involved.
2130
02:16:29.560 --> 02:16:32.061
And this makes it simple to,
2131
02:16:33.240 --> 02:16:36.220
create ring signatures over the UTX OSAT.
2132
02:16:37.436 --> 02:16:39.535
So how does that work? What does it mean?
2133
02:16:40.235 --> 02:16:42.415
What you can do, for example, is,
2134
02:16:43.195 --> 02:16:45.136
let's say you have the UTX offset
2135
02:16:45.650 --> 02:16:48.070
and you just filter the ones that are using
2136
02:16:48.450 --> 02:16:48.950
Taproot.
2137
02:16:49.490 --> 02:16:53.670
And then you look at the public keys, which is now possible because they're not hashed anymore.
2138
02:16:55.175 --> 02:16:57.995
You have then you end up with a list of public keys,
2139
02:16:58.375 --> 02:17:02.555
and then you can create a ring. If one of the public keys is yours,
2140
02:17:03.160 --> 02:17:05.500
then you can you can create a ring signature.
2141
02:17:06.760 --> 02:17:07.900
And the ring signature,
2142
02:17:09.320 --> 02:17:13.506
over these public keys will prove that you own one of these public keys.
2143
02:17:14.525 --> 02:17:17.105
One of them, but you don't reveal which one.
2144
02:17:18.766 --> 02:17:19.266
And
2145
02:17:20.851 --> 02:17:22.550
this could be interesting
2146
02:17:22.851 --> 02:17:23.750
in various
2147
02:17:24.290 --> 02:17:25.510
spam prevention,
2148
02:17:27.410 --> 02:17:27.910
schemes,
2149
02:17:29.515 --> 02:17:33.694
because you don't have to reveal exactly which coin you own
2150
02:17:34.635 --> 02:17:35.135
anymore.
2151
02:17:36.475 --> 02:17:37.455
So for example,
2152
02:17:38.780 --> 02:17:42.960
there were some discussions on joint market fidelity bonds where
2153
02:17:44.140 --> 02:17:49.795
you don't say exactly which output you own, but you say, I own this output.
2154
02:17:51.216 --> 02:17:53.855
I own one of these outputs, but you don't say,
2155
02:17:55.120 --> 02:17:55.620
specifically
2156
02:17:56.080 --> 02:17:59.380
which one you own. And that's something that's
2157
02:18:00.320 --> 02:18:00.820
possible
2158
02:18:01.600 --> 02:18:04.795
with Taproot. It was possible before, but, basically, computationally
2159
02:18:05.175 --> 02:18:07.835
and complexity wise, relatively infeasible.
2160
02:18:08.454 --> 02:18:13.850
So I think that's that's an interesting, research area to see how how that could,
2161
02:18:14.790 --> 02:18:22.975
improve the privacy of these fidelity bonds because these fidelity bonds, they are also suggested in suggested in the lightning world quite a bit.
2162
02:18:23.915 --> 02:18:36.641
2163
02:18:39.046 --> 02:18:42.426
this is what's, like, commonly referred to as, like, liquidity
2164
02:18:42.886 --> 02:18:45.065
pools or whatever. Right? Like, if you can,
2165
02:18:45.445 --> 02:18:48.346
prove that you own part of that Fidelity bond.
2166
02:18:49.949 --> 02:18:53.090
2167
02:18:54.510 --> 02:18:56.210
Perhaps perhaps, liquidity
2168
02:18:56.590 --> 02:18:57.489
something liquidity,
2169
02:18:57.875 --> 02:18:58.775
but not pool.
2170
02:19:01.075 --> 02:19:02.375
2171
02:19:02.755 --> 02:19:06.055
mixing 2 concepts. But, They are liquidity ads.
2172
02:19:06.740 --> 02:19:10.920
2173
02:19:12.500 --> 02:19:13.800
2174
02:19:14.686 --> 02:19:20.546
because you're pooling you could still pool capital in a sense of, like, how he was mentioning the Fidelity bond,
2175
02:19:21.780 --> 02:19:23.880
where you just have one of the keys. Right?
2176
02:19:24.260 --> 02:19:24.760
2177
02:19:25.620 --> 02:19:30.200
So this isn't something that would happen on on chain. It's totally off chain.
2178
02:19:32.715 --> 02:19:39.790
I mean, basically, Monero is kind of similar, but there, it's really on chain where you prove that you own one of these,
2179
02:19:40.190 --> 02:19:48.690
input coins, but you don't reveal which one, and you do that with a ring signature. But here, it would be just off chain to prove that you own some,
2180
02:19:49.275 --> 02:19:51.135
coin without revealing which one.
2181
02:19:53.995 --> 02:19:55.035
Okay. And,
2182
02:19:57.330 --> 02:19:59.270
another topic that you mentioned
2183
02:19:59.650 --> 02:20:00.870
was aggregation.
2184
02:20:01.970 --> 02:20:02.470
Yes.
2185
02:20:03.010 --> 02:20:04.710
2186
02:20:06.305 --> 02:20:07.265
2187
02:20:08.625 --> 02:20:12.085
as I said, I'm not that deep into the technical
2188
02:20:13.420 --> 02:20:14.399
lightning community.
2189
02:20:15.100 --> 02:20:15.500
But,
2190
02:20:16.140 --> 02:20:17.340
it seems that,
2191
02:20:17.899 --> 02:20:18.399
one
2192
02:20:19.420 --> 02:20:21.920
kind of problem is that in the gossip network,
2193
02:20:22.795 --> 02:20:25.375
your channel announcements are relatively large,
2194
02:20:26.234 --> 02:20:28.654
and that's because the channel announcements
2195
02:20:29.274 --> 02:20:32.255
contain multiple signatures, multiple public keys
2196
02:20:32.590 --> 02:20:34.290
in order to prove, for example,
2197
02:20:35.069 --> 02:20:44.995
that you own a coin on chain to make this resistant this message resistant against spam because you don't want anyone to just send any message because that would,
2198
02:20:45.615 --> 02:20:56.340
bring down the gossip network very quickly. So you're only supposed to send a message if you can prove that you have a coin on chain, and that's basically your your spam prevention,
2199
02:20:57.359 --> 02:20:57.859
method.
2200
02:20:58.720 --> 02:21:02.235
Now the current channel announcements, they are relatively big.
2201
02:21:03.175 --> 02:21:08.075
The question is, how can you reduce the size of these? And,
2202
02:21:09.711 --> 02:21:10.931
one thing that they
2203
02:21:11.631 --> 02:21:13.811
include is, for example, they include,
2204
02:21:15.150 --> 02:21:17.330
the public keys of both nodes
2205
02:21:18.115 --> 02:21:23.415
that open the channel and also signatures from both nodes. So you could use this music technique
2206
02:21:23.875 --> 02:21:25.730
I mentioned earlier to make,
2207
02:21:26.170 --> 02:21:28.430
both public keys into one public key
2208
02:21:28.810 --> 02:21:31.630
and also both signatures into one signature.
2209
02:21:33.355 --> 02:21:36.735
And, that way, you already save a lot of space,
2210
02:21:37.195 --> 02:21:38.735
but you can go further.
2211
02:21:41.040 --> 02:21:42.260
So music is
2212
02:21:42.640 --> 02:21:47.300
essentially a way to have multiple parties sign the same message,
2213
02:21:48.306 --> 02:21:50.245
but there's also the concept of
2214
02:21:50.625 --> 02:21:55.766
signature aggregation. And when we talk about that, we usually mean there are multiple people
2215
02:21:56.181 --> 02:21:57.960
signing a different message.
2216
02:21:59.301 --> 02:22:00.990
So what could happen is that,
2217
02:22:03.796 --> 02:22:06.375
each of these channel there are channel announcements,
2218
02:22:06.756 --> 02:22:10.535
gossiped, and, each of these channel announcements has a signature.
2219
02:22:11.235 --> 02:22:11.315
But
2220
02:22:12.360 --> 02:22:15.420
and this signature signs the channel announcement itself.
2221
02:22:16.120 --> 02:22:16.520
But,
2222
02:22:17.240 --> 02:22:20.460
what if you could have a batch of channel announcements,
2223
02:22:21.895 --> 02:22:26.555
each having a signature, and aggregate these signatures together into
2224
02:22:27.015 --> 02:22:28.235
a smaller signature?
2225
02:22:29.290 --> 02:22:33.470
And that's something that would be possible with a concept of, half aggregation,
2226
02:22:35.370 --> 02:22:37.550
because half aggregation doesn't need
2227
02:22:38.016 --> 02:22:41.635
cooperation with the signers. So you can take a bunch of signatures
2228
02:22:42.096 --> 02:22:45.795
and just aggregate them into 1 half aggregated signature.
2229
02:22:46.200 --> 02:22:49.900
It's, it's half as big as the individual signatures
2230
02:22:50.520 --> 02:22:51.020
combined,
2231
02:22:52.450 --> 02:22:52.950
and
2232
02:22:53.295 --> 02:22:58.114
this would already give you quite a lot. You could go even further than that using full aggregation.
2233
02:22:59.935 --> 02:23:05.979
And this is only on the Lightning gossip network. So perhaps one day, this could also be used
2234
02:23:07.240 --> 02:23:08.460
on the Bitcoin
2235
02:23:09.400 --> 02:23:10.540
consensus layer
2236
02:23:10.955 --> 02:23:12.895
to reduce the size of transactions
2237
02:23:13.515 --> 02:23:15.935
where you have one signature per transaction
2238
02:23:16.475 --> 02:23:19.535
as opposed to one signature per input.
2239
02:23:21.239 --> 02:23:21.979
2240
02:23:23.000 --> 02:23:26.619
am I mixing concepts up, or is that a cross signature input aggregation?
2241
02:23:27.615 --> 02:23:30.115
2242
02:23:30.575 --> 02:23:31.235
C cell.
2243
02:23:33.775 --> 02:23:36.995
2244
02:23:38.859 --> 02:23:40.960
2245
02:23:42.620 --> 02:23:44.240
because now it makes
2246
02:23:44.596 --> 02:23:45.096
sense
2247
02:23:45.476 --> 02:23:50.296
to create larger transactions and pool your inputs with other people,
2248
02:23:51.315 --> 02:23:51.815
because
2249
02:23:52.275 --> 02:23:53.336
then you
2250
02:23:54.740 --> 02:24:00.040
on like, if you imagine an infinitely large coin join, then your cost,
2251
02:24:00.420 --> 02:24:02.439
your fee that you pay for the signature
2252
02:24:02.820 --> 02:24:04.200
is essentially 0
2253
02:24:05.285 --> 02:24:09.145
because you don't have a signature anymore. It's aggregated into everyone else's,
2254
02:24:09.925 --> 02:24:10.425
signature.
2255
02:24:11.205 --> 02:24:11.705
But,
2256
02:24:12.660 --> 02:24:15.960
actually, the advantage that you get is
2257
02:24:16.500 --> 02:24:19.881
not that big. So that's something that,
2258
02:24:21.476 --> 02:24:25.655
that will be would be interesting to see in a world where we have signature aggregation
2259
02:24:26.035 --> 02:24:27.175
because the signature
2260
02:24:27.555 --> 02:24:30.295
is relatively large. Right? It's 64 bytes,
2261
02:24:30.730 --> 02:24:35.470
but it's also already in the witness. Right? So it's also 64 witness units
2262
02:24:36.010 --> 02:24:36.750
weight units.
2263
02:24:38.345 --> 02:24:38.845
So,
2264
02:24:39.305 --> 02:24:51.189
in terms of weight units, your gain isn't that big in terms of bytes. Okay. Your transaction will get smaller. But in terms of weight units, I think in the infinite coin join example, you would get you would get, like,
2265
02:24:51.830 --> 02:24:52.330
18%
2266
02:24:52.790 --> 02:24:53.290
reduction
2267
02:24:53.910 --> 02:24:55.805
in weight for an average
2268
02:24:56.345 --> 02:24:56.845
transaction.
2269
02:24:57.145 --> 02:25:01.165
And weight would also translate into fees, so an 18% reduction in fees.
2270
02:25:01.625 --> 02:25:03.245
2271
02:25:04.141 --> 02:25:04.881
make people,
2272
02:25:05.900 --> 02:25:07.360
want to do this,
2273
02:25:08.381 --> 02:25:12.721
as, like, a de facto or default versus doing it the other way,
2274
02:25:14.056 --> 02:25:20.476
in a sense where you opt into a CoinJoin. You'd essentially be of the mindset to opt out for some reason.
2275
02:25:21.150 --> 02:25:28.610
2276
02:25:29.715 --> 02:25:37.495
2277
02:25:37.890 --> 02:25:50.405
what ex I mean, in terms of usability, right, it takes longer to create a coinjoin, for example, because people need to interact and need to send these, signatures around. That's the downside. So the question is, like, is the upside worth it?
2278
02:25:51.985 --> 02:25:56.930
But, yeah, it's also it just gives you a good reason to co and join because now it's not just
2279
02:25:57.390 --> 02:26:04.455
the, how do we call them earlier, the dark people anymore with the hoodies because now it's everyone. We just want to save, dark
2280
02:26:04.915 --> 02:26:14.320
2281
02:26:15.500 --> 02:26:26.535
2282
02:26:27.235 --> 02:26:35.800
Pierre Richard, and, an actual watch streamer called Johnny Dilley. And he goes into this in-depth, essentially, where the holy grail is,
2283
02:26:36.500 --> 02:26:37.620
you know, some sort of,
2284
02:26:38.340 --> 02:26:44.465
batching in a sense where every channel open or channel close is also a coin joined because it's,
2285
02:26:45.325 --> 02:26:46.545
economically incentivized.
2286
02:26:49.700 --> 02:26:55.720
2287
02:26:56.420 --> 02:26:57.400
that as well.
2288
02:26:57.745 --> 02:26:58.245
And,
2289
02:26:58.625 --> 02:27:03.604
even better is every channel, lightning channel open, should be a coin join
2290
02:27:04.600 --> 02:27:14.565
in in the ideal world where you have multiple channels, dual funding channels, and whatever. And if that's cheaper than not doing that, then that's that's even better. But, I mean,
2291
02:27:15.105 --> 02:27:20.965
even in terms of bytes, like, for for the network, it gets you a lot. It's like a 40% reduction
2292
02:27:21.520 --> 02:27:24.660
in the just size of transaction in in bytes.
2293
02:27:25.360 --> 02:27:27.540
So, that's our already a huge thing.
2294
02:27:29.065 --> 02:27:30.525
2295
02:27:31.785 --> 02:27:32.845
What a good show.
2296
02:27:33.625 --> 02:27:37.885
Yeah. Yeah. I mean, we had we had, Johnny Dilley on
2297
02:27:39.159 --> 02:27:46.140
TFTC as well. That was an in person rip in New York. That was a fucking fire rip. Oh, yeah. That that was really good. That too.
2298
02:27:49.515 --> 02:27:51.215
So, I mean, guys, this has been
2299
02:27:51.675 --> 02:27:55.695
a absolutely fantastic conversation. We are hitting the 2 and a half hour mark.
2300
02:27:56.990 --> 02:27:59.250
You think we should just wrap up with some final thoughts?
2301
02:28:00.910 --> 02:28:02.610
2302
02:28:03.070 --> 02:28:03.971
getting late for,
2303
02:28:05.274 --> 02:28:06.175
the other 2.
2304
02:28:06.555 --> 02:28:10.095
2305
02:28:11.435 --> 02:28:15.820
2306
02:28:16.301 --> 02:28:17.601
writing about Telegram.
2307
02:28:18.301 --> 02:28:21.440
I think this is a chance to make a bigger point that,
2308
02:28:22.805 --> 02:28:26.904
next Bitcoin is the node for the digitally sovereign,
2309
02:28:28.325 --> 02:28:31.580
people who wanna have full control up down to the hardware,
2310
02:28:32.439 --> 02:28:36.140
and also wanna have an overview over how it works technically,
2311
02:28:38.359 --> 02:28:42.205
while at the same time not having to become expert system administrators
2312
02:28:43.065 --> 02:28:44.765
to have extremely secure,
2313
02:28:45.705 --> 02:28:46.205
configuration.
2314
02:28:47.225 --> 02:28:47.725
So,
2315
02:28:48.480 --> 02:28:50.660
with that in mind, it's it's also
2316
02:28:51.040 --> 02:28:53.600
probably right now not not for,
2317
02:28:54.480 --> 02:28:57.220
the super noobish people, but,
2318
02:28:58.006 --> 02:29:02.105
I hope that once we once we get the
2319
02:29:03.125 --> 02:29:03.625
project
2320
02:29:04.085 --> 02:29:05.945
to a certain finish line,
2321
02:29:06.320 --> 02:29:12.180
we can start or it's probably gonna be me because Jonas and, Eric are
2322
02:29:12.480 --> 02:29:14.020
more on the technical side,
2323
02:29:14.480 --> 02:29:15.300
start making
2324
02:29:16.635 --> 02:29:17.455
more documentation
2325
02:29:17.995 --> 02:29:18.975
for migration
2326
02:29:19.915 --> 02:29:20.975
and just in general,
2327
02:29:21.515 --> 02:29:23.695
different use cases and how to do it.
2328
02:29:24.181 --> 02:29:24.681
And,
2329
02:29:25.460 --> 02:29:30.280
yeah, we're building on a on a good foundation, on a good technical foundation right now.
2330
02:29:30.660 --> 02:29:31.141
And,
2331
02:29:31.815 --> 02:29:37.995
rather than doing it vice versa, rather than getting users involved and then trying to improve the technical foundation.
2332
02:29:40.351 --> 02:29:42.450
2333
02:29:43.391 --> 02:29:44.610
Vivek, final thoughts.
2334
02:29:47.785 --> 02:29:48.505
2335
02:29:49.305 --> 02:29:50.045
I guess
2336
02:29:50.585 --> 02:29:51.085
nobody's
2337
02:29:51.545 --> 02:29:52.045
untouchable.
2338
02:29:52.425 --> 02:29:53.645
No plan is foolproof.
2339
02:29:54.345 --> 02:29:55.965
Software will break.
2340
02:29:56.770 --> 02:30:00.550
That's why we strive for FOSS. That's why we strive for agnostic
2341
02:30:00.930 --> 02:30:01.430
implementation.
2342
02:30:02.770 --> 02:30:05.190
You know, anything that we're interested in,
2343
02:30:06.215 --> 02:30:09.034
That's why I was drawn towards Nick's Bitcoin.
2344
02:30:09.734 --> 02:30:10.715
I will be,
2345
02:30:11.975 --> 02:30:15.095
not only releasing the tutorial for this after,
2346
02:30:15.860 --> 02:30:17.460
you know, submitting it with,
2347
02:30:18.181 --> 02:30:19.400
Jonas, Nick for
2348
02:30:19.780 --> 02:30:26.346
making sure I'm doing everything properly. I'll also be speaking about it at tabconf later this week. But, just really
2349
02:30:26.886 --> 02:30:27.386
find,
2350
02:30:27.766 --> 02:30:34.506
a FOSS project or something in this community that interests you and see if there's one way you can some way you can contribute to it
2351
02:30:35.000 --> 02:30:35.479
and,
2352
02:30:35.880 --> 02:30:39.579
just try to build I think I've heard Nick's Bitcoin say this before.
2353
02:30:40.359 --> 02:30:41.899
Cyberpunks write code.
2354
02:30:42.655 --> 02:30:47.055
Twitter's fun, but, someone's actually gotta roll up their sleeves and,
2355
02:30:47.854 --> 02:30:52.580
walk the walk. So much love to everyone that does sit and walks the walk.
2356
02:30:53.040 --> 02:30:55.780
2357
02:30:56.480 --> 02:30:57.540
2358
02:30:58.555 --> 02:30:59.455
2359
02:31:00.314 --> 02:31:01.614
Jonas, final thoughts.
2360
02:31:03.354 --> 02:31:06.895
2361
02:31:07.880 --> 02:31:08.780
It's a great
2362
02:31:09.160 --> 02:31:09.980
side project.
2363
02:31:11.160 --> 02:31:13.101
The lows are very low too.
2364
02:31:13.641 --> 02:31:15.980
I would still recommend to,
2365
02:31:17.385 --> 02:31:23.885
would generally recommend to have a look at NextOS. I think it is a game changer in many ways. If you've
2366
02:31:24.760 --> 02:31:29.979
if you stepped over a certain point, you don't wanna get back into regular Linux or regular
2367
02:31:30.439 --> 02:31:31.580
system administration.
2368
02:31:32.199 --> 02:31:37.725
The community is the general Next OS community is really large and also great.
2369
02:31:39.705 --> 02:31:48.280
I'm going to continue doing this because I'm going to continue running a Bitcoin node, and somehow it needs to be, managed. And that's going to continue
2370
02:31:48.820 --> 02:31:50.280
to be through Bitcoin.
2371
02:31:50.660 --> 02:31:52.120
If people want to join,
2372
02:31:53.716 --> 02:31:57.415
this project will be really cool to see you on GitHub or Matrix.
2373
02:31:58.436 --> 02:31:59.895
2374
02:32:00.851 --> 02:32:05.030
I wanna thank the Rider Die Freaks for being in the live chat
2375
02:32:05.410 --> 02:32:07.431
and hanging in here with us and
2376
02:32:08.426 --> 02:32:17.405
being a part of the show. You guys are what make it unique, and I wanna thank all of you who choose to support the show and keep it ad free and sponsor free so we can focus on actionable Bitcoin discussion.
2377
02:32:18.090 --> 02:32:21.710
It is truly special. As I said it in the beginning of the episode,
2378
02:32:22.250 --> 02:32:26.430
I know I've been traveling, and our Bitcoin Tuesday schedule has been in flux,
2379
02:32:27.605 --> 02:32:33.306
But we're going hard into the winter months, so expect a lot of more great discussions
2380
02:32:34.070 --> 02:32:35.530
on our Bitcoin Tuesdays.
2381
02:32:36.311 --> 02:32:37.270
I wanna thank,
2382
02:32:37.830 --> 02:32:46.216
our guests, Nix Bitcoin Dev, Vivek, and Jonas for joining us. I really do appreciate all the work you guys do in the space. I hope you come back on,
2383
02:32:46.835 --> 02:32:47.655
in the future,
2384
02:32:48.490 --> 02:32:51.550
not only to follow-up on this project, but also for future,
2385
02:32:52.410 --> 02:32:53.470
autistic discussion.
2386
02:32:54.170 --> 02:32:56.425
Looking forward to that, and just thank you, guys.
2387
02:32:57.705 --> 02:32:59.885
2388
02:33:00.265 --> 02:33:02.125
2389
02:33:05.305 --> 02:33:07.391
2390
02:33:08.250 --> 02:33:15.165
Oh, oh my god. Bitch, I won the game. Y'all just come and take it from the side. I'm like, oh, god. Oh, oh my god.
2391
02:33:15.565 --> 02:33:19.425
Everything I do, you know I do it for the squad. I'm like, oh, god.
2392
02:33:19.965 --> 02:33:23.680
Oh, oh my god. Bitch, I won the game. Y'all just commentate from the
2393
02:33:34.225 --> 02:33:36.645
So I gave them this right here, now go get bloody
2394
02:33:37.265 --> 02:33:39.685
Check my last album, all y'all know I'm running
2395
02:33:40.145 --> 02:33:45.550
Flipping script just because I couldn't fucking stun it, this this this this this the type of shit my life was all about,
2396
02:33:46.250 --> 02:33:51.115
check the forms unless you know I'm falling down, they say Logic, you too humble boy just let it
2397
02:34:24.115 --> 02:34:32.055
I'm like, oh god. Oh. Oh my god. Everything I do, you know I do it for the squad. I'm like, oh god. Oh.
2398
02:34:32.355 --> 02:34:37.359
Oh my god. Bitch, I run the game. Y'all just time to take from the side. I'm like, oh god.
2399
02:34:37.899 --> 02:34:47.330
Oh. Oh my god. Everything I do, you know I do it for the squad. I'm like, hold on. Let me bring it back. Everybody know I'm bringing a fax. And it went around. I got it like that. Because I put everything
2400
02:35:32.275 --> 02:35:37.415
Oh, my god. Bitch, I won the game. Y'all just commentate from the side. I'm like, oh, god.
2401
02:35:37.795 --> 02:35:39.320
Oh. Oh, my god.
2402
02:35:39.641 --> 02:35:44.860
Everything I do, you know I do a do a fool. I know. I know. I know.
2403
02:35:45.240 --> 02:35:45.740
I
2404
02:35:46.120 --> 02:35:49.020
know. I know. I know. I know. I know. It's been a hell of a ride.
2405
02:36:19.390 --> 02:36:23.970
2406
02:36:24.590 --> 02:36:27.090
for the first Bitcoin infused music festival,
2407
02:36:27.605 --> 02:36:28.905
April 6th through 9th.
2408
02:36:29.766 --> 02:36:31.945
Ticket prices go up tomorrow.
2409
02:36:33.285 --> 02:36:39.640
You get a $100 off if you buy with Bitcoin. You get an additional 21% off if you use code open source.
2410
02:36:40.020 --> 02:36:44.805
I do not make any money from that code. That was not an ad read. I am helping them organize it.
2411
02:36:45.685 --> 02:36:49.465
Love you all, freaks. We'll be back for Bitcoin Tuesday next week,
2412
02:36:49.925 --> 02:36:54.345
with Bitcoin q and a, and I'll see you all for rabbit hole recap on Thursday.
2413
02:36:54.932 --> 02:36:56.312
Stay humble, Stack Sats.