Nov. 17, 2021

CD44: using secure random number generators to generate bitcoin keys with waxwing and @raw_avocado

CD44: using secure random number generators to generate bitcoin keys with waxwing and @raw_avocado
Citadel Dispatch
CD44: using secure random number generators to generate bitcoin keys with waxwing and @raw_avocado

EPISODE: 44

BLOCK: 710040

PRICE: 1647 sats per dollar

TOPICS: random number generators and why they are important when securing bitcoin, history of backdoors, compromises, and poor implementations, multisig tradeoffs, hardware wallet tradeoffs, mitigations to reduce your risk


@waxwing: https://x0f.org/@waxwing

@raw_avocado: https://twitter.com/raw_avocado

streamed live every tuesday:

https://citadeldispatch.com


twitch: https://twitch.tv/citadeldispatch​

bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos

podcast: https://anchor.fm/citadeldispatch​

telegram: https://t.me/citadeldispatch​


support the show: https://tippin.me/@odell

stream sats to the show: https://www.fountain.fm/

join the chat: http://citadel.chat/

00:00 - Introduction to the confusion about the Internet and email in the 1994 Today Show clip

06:11 - Importance of secure random number generation for Bitcoin

20:47 - Different sources of entropy for generating Bitcoin keys

27:53 - Debunking the myth of using physical dice for generating Bitcoin keys

33:29 - Discussion on the history of compromises and poor implementations of entropy sources

38:57 - Backdoors, compromises, and poor implementations in Bitcoin wallets

44:15 - Different methods of securing Bitcoin

01:06:12 - The importance of holding your own keys

01:19:08 - Discussion about the fragility of nonces and the potential for catastrophic failure

01:20:24 - The history of software failures related to nonce generation

01:21:47 - Introduction to deterministic nonces and their benefits

01:23:30 - Challenges with deterministic nonces in new protocols like Taproot

01:23:40 - Importance of being skeptical and practicing personal responsibility in Bitcoin

WEBVTT

NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 8:19:39 PM
Duration: 5841.998
Channels: 1

1
00:00:00.799 --> 00:00:05.859
Pass. I wasn't prepared to translate that as host doing that little t's. Oh, that's right. With the

2
00:00:06.319 --> 00:00:10.264
a and then the ring around it. At? See, that's what I said. Mhmm.

3
00:00:10.965 --> 00:00:21.289
Kaye said she thought it was about. Yeah. Oh. But I've never heard it Around. I've never heard it said. I've always seen the mark but never heard it said. And then it sounded stupid when I said it. Violence at NBC.

4
00:00:22.470 --> 00:00:27.244
I hate what happened to her about it in the lunchroom music. There it is. Violence at nbcgecom.

5
00:00:28.345 --> 00:00:28.664
I mean

6
00:00:29.945 --> 00:00:32.684
Well, Allison should know. What is Internet anyway?

7
00:00:33.950 --> 00:00:39.570
Internet is, that massive computer network. The one that's becoming really big now.

8
00:00:40.190 --> 00:01:26.420
What do you mean? That's big? Wait. How does one not what do you write to it like mail? No. A lot of people use it and communicate with I guess they can communicate with NBC writers and producers. Allison, can you explain what Internet is? No. She can't say anything in 10 seconds or less. Oh. Oh. Allison will be in the studio shortly. What is it? What does it mean? It's a giant computer network made up made up of, started with from Oh, I thought you were gonna tell us what this was. It's a computer billboard. It's it's not an it's it's it's a computer billboard, but it's not online. It's it's several, universities and everything all joined together. Right. And others can access it. Right. And it's getting bigger and bigger all. Just It came in really handy during the quake. A lot of people, that's how they were communicating out to tell family and loved ones they were okay because all the phone lines were down. I was telling Katie, you know, about don't need you don't need that you don't need a phone line to operate? No. No.

9
00:02:01.340 --> 00:02:06.720
Happy Bitcoin Tuesday, freaks. It's your boy, Matt Odell here for another Siddle Dispatch.

10
00:02:07.335 --> 00:02:08.875
That clip you just listened

11
00:02:09.335 --> 00:02:13.835
to was not a recent clip, if you couldn't tell. That was the Today Show in 1994.

12
00:02:14.295 --> 00:02:16.955
Katie Couric, Brian Gumbel, and Elizabeth Vargas,

13
00:02:17.400 --> 00:02:22.380
the anchors of the Today Show, completely confused about what the Internet and email was.

14
00:02:23.080 --> 00:02:25.100
There seems to be a little bit of confusion,

15
00:02:26.195 --> 00:02:31.415
with the cringe level of the mainstream media clips I play at the beginning of every sale of dispatch.

16
00:02:32.355 --> 00:02:34.935
The intention is for them to be a bit cringey.

17
00:02:35.300 --> 00:02:38.599
I expect them all to age about the same way that,

18
00:02:39.780 --> 00:02:46.385
that Today Show clip has aged since 1994, so it should be a pretty fun thing to go back and look at.

19
00:02:47.005 --> 00:02:52.545
CIL dispatch is the interactive live show about Bitcoin distributed systems privacy and open source software.

20
00:02:53.300 --> 00:03:01.560
Huge shout out to the rider dive freaks who continue to support the show and keep it ad free, sponsor free, and strictly focus on actionable Bitcoin discussion.

21
00:03:02.385 --> 00:03:04.165
The easiest way you can support the show

22
00:03:04.465 --> 00:03:07.045
is downloading a podcasting 2.0 app.

23
00:03:07.425 --> 00:03:08.485
My two favorites

24
00:03:10.180 --> 00:03:11.400
are fountain podcasts

25
00:03:12.420 --> 00:03:12.920
and

26
00:03:13.459 --> 00:03:13.959
Breeze.

27
00:03:14.340 --> 00:03:17.239
You can just load it up with Sats, search to dispatch,

28
00:03:17.915 --> 00:03:22.974
and then you can stream Sats directly to my lightning node. You can also support the show at sail dispatch.com,

29
00:03:24.715 --> 00:03:25.534
either through,

30
00:03:26.155 --> 00:03:27.534
Lightning on my Tippin

31
00:03:28.140 --> 00:03:28.640
account

32
00:03:29.819 --> 00:03:33.680
or through my pay name, which is Odell. Very easy to remember.

33
00:03:34.780 --> 00:03:41.665
Also, huge shout out to the rider dies who consistently come in for our live chat, which you can access on Twitter, Twitch, or YouTube.

34
00:03:42.444 --> 00:03:44.545
You guys make this show truly special,

35
00:03:45.220 --> 00:03:48.760
and unique, and, I couldn't do it without you. So thank you, guys.

36
00:03:49.220 --> 00:03:53.720
With all that said, I'm excited to introduce our guest for today's episode.

37
00:03:55.025 --> 00:03:58.485
We have return guest, Waxwing, coming in from El Salvador.

38
00:03:59.185 --> 00:04:01.525
He's one of the lead maintainers of

39
00:04:02.160 --> 00:04:03.540
the join market project,

40
00:04:04.400 --> 00:04:09.140
and I'm very happy that he's joining us again. And we have, raw avocado

41
00:04:09.760 --> 00:04:10.260
here,

42
00:04:10.560 --> 00:04:11.060
Alex.

43
00:04:12.685 --> 00:04:15.745
We will be discussing secure random number generators,

44
00:04:17.085 --> 00:04:20.305
why that is important when you're using Bitcoin and encryption,

45
00:04:21.140 --> 00:04:26.360
and what you can do to mitigate the risks associated with it. How's it going, guys?

46
00:04:27.220 --> 00:04:27.720
Good.

47
00:04:28.180 --> 00:04:29.720
Yo. What's happening, motherfuckers?

48
00:04:31.664 --> 00:04:32.965
That's what I meant. Yeah.

49
00:04:34.865 --> 00:04:36.004
I actually realized,

50
00:04:37.240 --> 00:04:39.180
I messed up the intro a tiny bit.

51
00:04:40.360 --> 00:04:43.260
For our freaks joining through our podcast streams,

52
00:04:43.960 --> 00:04:48.295
it's important for them to associate a voice to a name early on.

53
00:04:49.795 --> 00:04:52.535
So, Waxwing, why don't you say hi to everybody?

54
00:04:53.475 --> 00:04:58.760
Hi. This is Waxwing. I am in sunny El Salvador where there are 7 active volcanoes

55
00:04:59.220 --> 00:05:04.600
and military roaming the streets, and, Bitcoin is roaming the streets trying to pay for lightning.

56
00:05:05.245 --> 00:05:07.665
And it's all very surreal, and it's great.

57
00:05:08.125 --> 00:05:16.419
Are there really military on the streets? Well, I mean, if you if you walk around the city, you're gonna see men with very, very large guns. Quite a lot of them. Yeah.

58
00:05:16.800 --> 00:05:22.160
Wow. I guess they're taking it seriously. They don't want any Well, there was a bunch of murders a few days back, so you can't really

59
00:05:23.574 --> 00:05:26.955
Yeah. Well, stay safe out there. We don't want anything to happen to you.

60
00:05:27.574 --> 00:05:29.514
Alex, why don't you say hi to the freaks?

61
00:05:29.815 --> 00:05:40.914
Yo. Yo. What's happening, freaks? I mean, how can I beat that? What am I gotta say now? I mean, north I mean, north of UK. It's fucking foggy. Nothing is happening. A cow farted. That's the highlight of my day, you know.

62
00:05:41.294 --> 00:05:47.134
How can I beat what he's doing? Well, I think that's I don't even contribute to anything, by the way. I don't even contribute to anything. So

63
00:05:47.780 --> 00:05:53.479
You contribute to the the world's knowledge, Alex. You contribute greatly. Don't don't don't put yourself down.

64
00:05:55.205 --> 00:06:02.220
Well, I think I can speak for both me and Alex that we're very jealous, that waxwing is in El Salvador. I was sorry I couldn't make it work.

65
00:06:02.940 --> 00:06:07.280
So with all that said, I mean, I think a good spot for us to start here is,

66
00:06:08.700 --> 00:06:13.835
why is secure random generation important with respect to Bitcoin? Like, why should the freaks even care?

67
00:06:16.295 --> 00:06:20.235
I actually would go I would just start off, like, first of all, Bitcoin is a cryptocurrency.

68
00:06:20.935 --> 00:06:26.030
And And in case you probably didn't know this, if you're spending a lot of time on Twitter, but crypto stands for cryptography.

69
00:06:26.650 --> 00:06:31.784
And cryptography, most of the, most of the time has to do with secrets

70
00:06:32.245 --> 00:06:37.065
and sometimes authentication and other things. And the way these secrets are maintained

71
00:06:37.444 --> 00:06:37.944
and

72
00:06:38.805 --> 00:06:39.305
preserved

73
00:06:39.990 --> 00:06:40.890
is through

74
00:06:41.350 --> 00:06:44.170
mathematics that can't get inverted most of the ways,

75
00:06:45.030 --> 00:06:45.530
and,

76
00:06:45.910 --> 00:06:46.810
random numbers.

77
00:06:47.794 --> 00:06:51.574
So anything that uses communication uses cryptography, so

78
00:06:51.875 --> 00:06:55.815
it needs this random numbers. Now for Bitcoin, even more so considering that

79
00:06:56.460 --> 00:07:04.960
cryptography is what runs on it, it needs it. And it needs it in multiple places. It needs this when you generate your private keys, and it also needs this when you sign transactions.

80
00:07:05.835 --> 00:07:10.815
Because both of these operations, if if those random numbers aren't really run random,

81
00:07:11.675 --> 00:07:14.630
an adversary could possibly guess your keys. That's how I would

82
00:07:16.790 --> 00:07:18.410
ask this. Can you hear me?

83
00:07:19.190 --> 00:07:20.250
Yes. We can.

84
00:07:20.630 --> 00:07:25.455
Okay. It's those it connection's not great, so I'll be coming in and out. But I'm here

85
00:07:26.715 --> 00:07:27.215
now.

86
00:07:28.475 --> 00:07:37.039
Did you did you hear Alex just now? I saw the I saw I heard the end of it. He's describing what you need random numbers numbers for. So, I mean, basically,

87
00:07:37.500 --> 00:07:39.039
and correct me if I'm wrong,

88
00:07:39.740 --> 00:07:46.255
the process of generating private keys, whether that's for encryption or if that's for Bitcoin,

89
00:07:47.675 --> 00:07:54.210
involves a source of entropy to make them secure. And when we talk about entropy, we're talking about randomness, true randomness.

90
00:07:54.990 --> 00:07:57.970
Yeah. And if you don't have that true randomness,

91
00:07:59.504 --> 00:08:00.245
if your

92
00:08:00.944 --> 00:08:01.764
if your,

93
00:08:02.784 --> 00:08:04.324
entropy is compromised

94
00:08:04.705 --> 00:08:07.444
or poor, just not good randomness,

95
00:08:08.780 --> 00:08:17.440
that can be used against you to basically have someone else regenerate the same key as you and and compromise you. Right? Like, that's the

96
00:08:17.914 --> 00:08:22.175
the $1,000,000 question that almost every newcomer to Bitcoin asks

97
00:08:22.715 --> 00:08:23.215
is,

98
00:08:24.315 --> 00:08:25.775
you know, I just generated

99
00:08:26.250 --> 00:08:27.870
this Bitcoin key offline.

100
00:08:29.770 --> 00:08:32.430
How do I know that someone else isn't going to,

101
00:08:33.210 --> 00:08:36.595
generate the same key as me? Right? That's like I remember

102
00:08:37.375 --> 00:08:41.555
early on when I first started with Bitcoin, that was, like, the number one question people were asking.

103
00:08:42.415 --> 00:08:44.675
Yeah. It's a it's a natural source of

104
00:08:45.380 --> 00:08:55.035
uncertainty because it strikes at the very heart of the security of what you're doing, doesn't it? Yeah. And, I I do wanna mention there's a nuance with because I think Alex was saying you need it for both

105
00:08:55.415 --> 00:09:00.555
the the key the private keys and and the signing. And the signing operation still needs

106
00:09:00.990 --> 00:09:03.570
what you might call cryptographic randomness, but,

107
00:09:04.510 --> 00:09:11.705
there's a nuance where you can kind of get cryptographic randomness sort of secondhand where you can kind of seed what's called a

108
00:09:12.885 --> 00:09:19.750
a pseudo random number generator, but a a a generator that will generate, like an endless stream of random data from a starting seed,

109
00:09:21.089 --> 00:09:28.550
according to some complicated out which we might get into later, but but I'm just trying to say that the process of getting, like, so to speak, raw randomness

110
00:09:29.075 --> 00:09:44.820
from the environment, from your operating system, from something like that, that's one thing. And then there's a lot of actual of the random strings that you're using in cryptographic protocols are actually not coming directly from that. Because it's kind of hard to source masses of randomness. Right? So you might just have

111
00:09:55.310 --> 00:09:59.470
We lost you at the very end right after my what what were you saying there? You might have

112
00:10:02.345 --> 00:10:20.900
you I I'm not sure. I'm sorry. That this did did you get the point about that that you might Yes. See a random number generator, and it might produce a long string of randomness out of that. Oh, okay. It's it doesn't matter. It's not important. Please go on. But, I mean but there there's a key element here. Right? Is is so when you're

113
00:10:21.265 --> 00:10:23.285
so if if you are,

114
00:10:25.745 --> 00:10:26.565
let's say

115
00:10:27.025 --> 00:10:32.060
you're using Bitcoin Core. Right? You're using Bitcoin Core on your computer, and you create a new wallet.

116
00:10:34.440 --> 00:10:36.300
Where does that entropy come from?

117
00:10:37.584 --> 00:10:40.084
Right. So, Alex, do you wanna take that?

118
00:10:40.625 --> 00:10:45.980
Yeah. I I even made a a Twitter thread about this actually, about how Bitcoin Core specifically does this.

119
00:10:46.779 --> 00:10:52.800
Long so the thing is, like, there are multiple sources of entropies you can have. Right? And usually the more the better.

120
00:10:53.180 --> 00:10:53.680
And

121
00:10:54.275 --> 00:10:56.295
good sources of entropy on your

122
00:10:56.835 --> 00:11:04.230
on your computer pretty much are things that are information that your computer does. For example, how does the disc move? Or,

123
00:11:04.690 --> 00:11:29.300
another thing would be, like, the timing interruptions between the disc or even the timing interruptions between your keyboard and your clicks. Right? Or how resources are used by your processor and your kernel and all this weird stuff. Right? Because these things, like, they they are still deterministic things, but it's very hard for someone to to measure them. So this would be, like, one type of of sources of entropy and you can call these, like, dynamic events.

124
00:11:29.765 --> 00:11:31.225
Another source of entropy

125
00:11:32.084 --> 00:11:38.980
could be your processor because all the modern processors that we have today, they have a built in,

126
00:11:40.400 --> 00:11:55.165
pseudo run they have a they have a thing built in that gives you random numbers. Right? And the way Bitcoin Core does it, it takes all it takes all the sources I've mentioned before. It takes also these things sort of process. It mixes them in a very interesting way.

127
00:11:56.570 --> 00:12:09.965
Mostly, it has to be using the the binary operation soar, and we can explain that what it is or whatever. But the the sore thing has very a very interesting magic property that if you so let's say I I have two sources of entropy. Right? And

128
00:12:10.820 --> 00:12:18.600
one of them is compromised. Like, it's it you literally, you know exactly what it is. And one of them is real entropy. Right? It's good. If you sort this thing together,

129
00:12:19.855 --> 00:12:48.310
this I'm just gonna end up with the the best entropy. So so sorry. What I'm trying to say is that this cannot bad entropy when you sort it with good entropy doesn't it doesn't cancel it out. So Bitcoin Core uses multiple sources like this, and it's a bit more complicated, by the way. You can check the thread if you want. They even draw it out. And you you jumble these things a lot of times, and you hash them together, and you sort them together, and that's how it gets. So that make sense. So to repeat, when whenever we say entropy in this in this conversation,

130
00:12:49.490 --> 00:12:51.190
you can the freaks can

131
00:12:51.535 --> 00:12:54.115
basically replace that with a source of randomness.

132
00:12:57.135 --> 00:13:06.940
The I I before we we're gonna dive very deep in this conversation. I wanna be very clear that you might get very scared or frightened from the conversation.

133
00:13:07.485 --> 00:13:08.865
You know, take a deep breath.

134
00:13:09.645 --> 00:13:15.265
Fortunately, we haven't had many compromises in this respect. We have had some, and we are gonna talk about that.

135
00:13:16.720 --> 00:13:23.780
But it's something that's very important in terms of actually using Bitcoin in a sovereign way and holding your own keys and making sure your keys are secure.

136
00:13:25.120 --> 00:13:25.620
So

137
00:13:26.004 --> 00:13:27.225
when we're talking about

138
00:13:27.605 --> 00:13:31.225
entropy, when we're talking about sources of entropy, the key is

139
00:13:31.925 --> 00:13:32.745
to have

140
00:13:33.270 --> 00:13:36.410
randomness that is distinct and unique,

141
00:13:37.270 --> 00:13:38.570
and can't be basically

142
00:13:40.645 --> 00:13:41.145
resimulated

143
00:13:41.685 --> 00:13:42.505
or recalculated

144
00:13:42.885 --> 00:13:45.545
on someone else's machine or device. Right?

145
00:13:46.165 --> 00:13:47.625
Yeah. Notice it's not just

146
00:13:48.149 --> 00:13:50.389
distinctness or uniqueness. Right? Because

147
00:13:50.870 --> 00:13:54.250
well, it's not just uniqueness. Because if I if I use the private key

148
00:13:55.269 --> 00:14:06.240
154, that's that's unique. Nobody else has done that, but that's because nobody else is stupid enough to do that. Right? So the the the point there is I'm trying to make is that, the concept of entropy is think of it like disorder.

149
00:14:06.940 --> 00:14:07.440
Like,

150
00:14:08.140 --> 00:14:16.634
one one measure I I won't sort of get into the technical details, but one one way of measuring the randomness of some string of data, you know, bytes on your

151
00:14:17.095 --> 00:14:19.255
list of, characters or bytes is,

152
00:14:20.180 --> 00:14:24.040
can you compress it? Right? Because if if I just write the character a

153
00:14:24.740 --> 00:14:26.930
a a a a 50

154
00:14:27.465 --> 00:14:30.045
times. It's a very long string, but it only

155
00:14:35.160 --> 00:14:35.660
was

156
00:14:36.920 --> 00:14:41.740
basic no entropy because I can take that whole string, and I can just express it as a

157
00:14:45.585 --> 00:14:50.405
times 50, which is a much, much shorter string algorithm that expresses that thing

158
00:14:50.759 --> 00:14:52.620
shorter than it originally was,

159
00:14:53.399 --> 00:14:58.620
then it didn't have perfect entropy or it didn't have entropy, if that makes any sense. So

160
00:14:58.944 --> 00:15:01.605
give it is it should be disorder. Oh, oops.

161
00:15:02.225 --> 00:15:02.944
Can you I'm

162
00:15:03.824 --> 00:15:09.300
I've lost you. Yeah. Right. So caught in and out there, but I I it's actually kinda the parts that didn't necessarily,

163
00:15:11.200 --> 00:15:12.180
lost any information.

164
00:15:12.800 --> 00:15:15.860
Sorry, Matt. You were gonna say something? I was gonna add something to what you said.

165
00:15:16.195 --> 00:15:17.654
No. Add. Go ahead.

166
00:15:17.955 --> 00:15:20.615
So, actually, the thing is, like Hello?

167
00:15:20.995 --> 00:15:23.735
So you have this let's see. Yeah. We can hear you now.

168
00:15:25.480 --> 00:15:43.325
Oh, I could also hear myself, I think. No. Yeah. We hear we you cut out a little bit, but it seems like it just lagged, and then we heard we heard what you wanted to say. Cool. Oh, you okay. To to the freaks, Waxwing's joining us from El Salvador, and he's on hotel Wi Fi. So we're gonna make this work because it's an important conversation.

169
00:15:44.050 --> 00:15:46.769
Yeah. Did you did you get this Alex, go on. What I was

170
00:15:47.649 --> 00:15:48.230
I'm sorry.

171
00:15:49.250 --> 00:15:50.389
Go ahead. Go ahead, Alex.

172
00:15:51.435 --> 00:16:26.959
Yeah. So so what so to reiterate what you said in case, so you will know what we heard, West Wing was saying if you have, the the string that has 50 a's, right, There's not that you can compress this a lot. There's not that much entropy. There is just a 50 times so you can write in a very short format. But, to to to bring a bit more home what he's trying to say. So let's say you have something. It's a program. It's a computer. Doesn't fucking matter what it is. It's something that whenever you press the button it just speeds out a lot of numbers. Right? Gibberish. Right? So then what would be good entropy? What would classify as good entropy? Well, there's 3 main characteristics of this. First of all, it's unpredictability.

173
00:16:27.945 --> 00:16:30.685
Okay? Meaning that if I have, like,

174
00:16:31.065 --> 00:16:42.060
2 of if I look at this, this thing, I can't predict what it's gonna do in the future Because I predict my private keys. I don't want Matt and and Waxwing and someone else to prove it my my private keys. So the first one is pre predictive unpredictability.

175
00:16:42.685 --> 00:16:45.585
The second property is gonna be uniform distribution.

176
00:16:45.965 --> 00:16:50.865
What does this mean? Yeah. It means that if we would take like these numbers and we would chart them out,

177
00:16:51.410 --> 00:16:52.930
they would literally look like,

178
00:16:53.410 --> 00:17:05.235
you know, when you have the television and there's like perfect noise in their static, it will literally look something like that. Like the the there's no pattern. There's nothing you can say about this. It's that's why it's random. It's complete gibberish. So there's unpredictability

179
00:17:05.615 --> 00:17:09.269
and uniformity. And then there's lack of patterns in the sequence.

180
00:17:09.570 --> 00:17:12.710
You don't wanna have any any patterns here. Now worth,

181
00:17:13.889 --> 00:17:14.870
noting here that

182
00:17:15.250 --> 00:17:16.549
free implies both.

183
00:17:17.125 --> 00:17:28.260
Right? Both 1 and 2. Because if you have lack of patterns, there's of course, there's gonna be uniform distribution is gonna be unpredictable. But one doesn't imply 2 because you can have something that's unpredictable, but it's not uniformly distributed.

184
00:17:28.800 --> 00:17:40.845
And 2 does not guarantee 1 because even if something is uniformly distributed, doesn't mean it's unpredictable. I know that it sounds a bit like concorded, but I think that would be the the simplest way I can compress, like, what would make good entropy.

185
00:17:41.705 --> 00:17:51.635
Mhmm. I hope that makes sense. It's Yeah. Yeah. There's there's also a thing about how you know, you said unpredictability. That's a very that's the difference between random numbers and cryptographically

186
00:17:52.095 --> 00:17:56.595
secure random numbers is, like, I could make a string of data that's completely random.

187
00:17:57.270 --> 00:18:26.635
Well, can you hear me? Yeah. Yeah. You're all good. Yeah. We hear you. We hear you. I I I can make a string of, I can make a stream of random numbers that that so the outside world looks totally random. But if somebody knows the algorithm that's used to generate the random numbers, then they might be able to predict the next sequence of numbers that comes after it. And it actually works backwards in time as well, which is kinda weird. What you should if you wanna make it cryptographically secure, it should also be a case that looking at the current stream of random numbers, I should not be able to go backwards in time and find out what was in the previous

188
00:18:27.015 --> 00:18:30.554
set of random numbers in this long stream. So that's that's that's,

189
00:18:31.270 --> 00:18:37.610
and I think that's part of what what Alex is saying. And that is his point about there not being a pattern is is probably the best overall,

190
00:18:38.870 --> 00:18:40.355
concept to remember. Yeah.

191
00:18:40.915 --> 00:18:50.840
Well, okay. Let's let's still mend this this point even more. So the thing is, like, when you hear the word entropy, this come like, the I I I like this how I think about it, by the way, so I don't feel like there's a rigorous

192
00:18:51.400 --> 00:18:58.059
But I think there's 3 types of entropy. First of all, there's the physical one, which that's where the word comes, and it expresses the second law of thermodynamics.

193
00:18:58.424 --> 00:19:03.625
And it has to do with molecular randomness. So you have a you have a so imagine you have a fart and the fart is comp

194
00:19:04.105 --> 00:19:13.190
composed of little tiny things. Right? And and those tiny things, like, go around it. There's a lot of, like, chaos. Right? You don't know what's happening there. Then there's the informational theoretical,

195
00:19:14.370 --> 00:19:20.855
context, which is what we described right now, which is something you can measure. And to measure this, Shannon invented this,

196
00:19:21.175 --> 00:19:29.730
unit to measure this because he was trying to measure information. So that's just what we described right now, which just says something theoretical about these things. But then there's the cryptographical

197
00:19:30.190 --> 00:19:47.360
context, which what is cryptography? Well, cryptography is just adversarial math, which means that we we we take what we just said, but we judge this from the perspective of how hard is for an adversary to to guess this. What do I mean? So all these things that I that we enumerated earlier, you can take the you know, pi.

198
00:19:47.715 --> 00:19:56.215
Pi is this this number that goes on forever. Right? And it doesn't repeat itself. So so if you if I would take, like, I don't know, the, we have calculated something around 60,000,000,000,000

199
00:19:56.755 --> 00:20:19.820
digits of powers. Something like that. I don't know. So if I would take like the 100th millions digits from now and I would give it to you guys, it would be like, oh, this looks random enough to me. Right? This is perfectly fine. You would they call these boxes. But it's not cryptographically secure because, well, it's the number pi. So what West Wing was saying, like, hey. I could realize this is pi and now I could see what your what is gonna what the other ones are gonna be and so on. I hope that makes sense.

200
00:20:20.520 --> 00:20:23.180
Yes. Important distinction. It's subtle, but it's really important.

201
00:20:25.144 --> 00:20:26.424
Yeah. No. That makes sense.

202
00:20:26.904 --> 00:20:28.205
So, I mean, I think

203
00:20:30.024 --> 00:20:31.865
I I I think it would be

204
00:20:32.490 --> 00:20:35.070
so so every every Bitcoin wallet,

205
00:20:35.610 --> 00:20:44.785
whether it's a software wallet, whether that's a wallet on your computer, something like Bitcoin Core or Sparrow Wallet, or if it's a hardware wallet, something like Coldcard

206
00:20:45.405 --> 00:20:46.625
or Seed Signer.

207
00:20:47.725 --> 00:20:49.184
The the key is

208
00:20:49.980 --> 00:20:51.600
when they're generating your keys

209
00:20:52.539 --> 00:21:00.655
is is that they're trying to have the secure randomness, the secure entropy when they're generating the keys. It's it's it's the most important thing they do.

210
00:21:01.515 --> 00:21:02.255
And they

211
00:21:03.035 --> 00:21:06.495
will source that from multiple different ways if they're

212
00:21:07.000 --> 00:21:15.740
if if they're a well designed wallet. Right? Because if you have one issue Can I just interrupt on that point? Can I just interrupt on that point? Yes. Interrupt me whenever you want, Waxwing.

213
00:21:16.044 --> 00:21:24.625
Alex explained that very beautifully at the beginning about how it's like looking into the operating system. It's looking at different things like the hard disk, the the CPU, and so on.

214
00:21:25.250 --> 00:21:30.230
Is it using are you are you talking about what comes out of dev view random?

215
00:21:30.610 --> 00:21:33.990
Am I right about that, Alex, on at least on Linux?

216
00:21:35.235 --> 00:21:41.415
Okay. You you know what? It would be really bigger if we'd have that picture. So the thing is, like, the so what is this random?

217
00:21:41.850 --> 00:21:43.129
The so when you have the Linux Linux,

218
00:21:45.289 --> 00:21:47.870
should should we go and explain this, or should I just answer the question?

219
00:21:48.490 --> 00:21:54.095
Or Explain. Go. Go for it. So so different so if you have a it's a in Linux, everything,

220
00:21:54.875 --> 00:21:55.775
is a file.

221
00:21:56.235 --> 00:22:00.520
And there's this the very special file which is you can access it as dashdevslash

222
00:22:01.380 --> 00:22:01.880
random.

223
00:22:02.260 --> 00:22:03.640
And, this file

224
00:22:04.340 --> 00:22:23.155
takes care of entropy. So, you know, the people who design Linux, they're like, hey. You know what, guys? We should, like, we should, like, create something in the kernel. And the kernel is, like, the the the the main thing there that that that generates random numbers because we need random numbers everywhere. Now the problem is that and this was invented in 1994, by the way.

225
00:22:23.955 --> 00:22:33.110
And the thing is, like, when they did computers were very different back then. And when they did this, they realized that and by the way, there weren't, like, random number generators on processors.

226
00:22:34.070 --> 00:22:37.670
They were like, we need to we need to find some sources that that,

227
00:22:38.150 --> 00:22:43.794
are are very easy to to use and don't depend on special hardware or whatever. So that's how they designed this thing. And,

228
00:22:44.735 --> 00:22:50.755
and then, so so so they they had this model where they have there's multiple source to do this. Now Bitcoin core,

229
00:22:51.400 --> 00:22:53.260
because it was designed pretty recently,

230
00:22:53.960 --> 00:22:59.740
it it does have multiple sources of entropy, but it's a bit more elegant in the way it mixes them up together.

231
00:23:00.065 --> 00:23:02.885
And I I hope I'm not saying something wrong, but,

232
00:23:03.345 --> 00:23:11.540
this would be called, this is like what, Fortuna would be this type of algorithms called. And this is like more modern ones, and it's also what BSD uses.

233
00:23:14.800 --> 00:23:16.820
Right. So it's okay. Go ahead. Yeah.

234
00:23:17.645 --> 00:23:19.105
Well, yeah, that that was it.

235
00:23:22.605 --> 00:23:23.665
Okay. So

236
00:23:25.165 --> 00:23:25.665
so

237
00:23:26.280 --> 00:23:30.300
you we we now we now have chips that are designed

238
00:23:31.080 --> 00:23:31.580
purposely

239
00:23:32.120 --> 00:23:32.620
to

240
00:23:32.920 --> 00:23:33.420
create,

241
00:23:35.184 --> 00:23:40.404
you know, they they they claim to create secure random numbers.

242
00:23:40.784 --> 00:23:41.284
Right?

243
00:23:43.600 --> 00:23:45.300
And a lot of

244
00:23:48.000 --> 00:23:52.900
some some software and some hardware will just rely purely on those.

245
00:23:54.065 --> 00:23:59.205
Perfect example is, I believe, Ledger. Right? If you use, like, a Ledger hardware wallet,

246
00:23:59.825 --> 00:24:06.380
they have a chip on there, and they're deriving the entropy from that chip that's purpose built to derive entropy.

247
00:24:08.600 --> 00:24:09.660
Some wallets

248
00:24:10.295 --> 00:24:12.555
will give you the option to add additional

249
00:24:13.095 --> 00:24:13.595
environmental

250
00:24:13.975 --> 00:24:14.475
entropy.

251
00:24:15.655 --> 00:24:17.435
Stuff like dice rolls,

252
00:24:18.200 --> 00:24:18.700
pictures.

253
00:24:21.000 --> 00:24:25.500
You can either use that entropy specifically with Oz Waxwing. He'll be back in a second.

254
00:24:27.355 --> 00:24:29.775
Or you can combine that with other entropy.

255
00:24:30.955 --> 00:24:32.495
Am I correct in that

256
00:24:33.110 --> 00:24:33.610
explanation?

257
00:24:34.710 --> 00:24:35.929
You are very correct.

258
00:24:36.230 --> 00:24:38.070
That's how things work. But,

259
00:24:38.710 --> 00:24:39.850
I would so

260
00:24:40.549 --> 00:24:51.115
so the thing is, like, your wallet, it's like your instrument that you used to interact with a Bitcoin network. So it has to do all these things, and we already established. That's why we've been talking for past a minute. This is an important

261
00:24:52.730 --> 00:24:58.590
operation, so it takes care of this. And so most of the wallets by default take care of this. And you're very right. Most of the

262
00:25:00.165 --> 00:25:02.345
the hardware wallets are are built on, like,

263
00:25:02.725 --> 00:25:03.225
microcontrollers

264
00:25:03.525 --> 00:25:05.385
which are just from very dumb computers.

265
00:25:05.765 --> 00:25:10.930
And these very dumb computers have indeed a chip that's supposed to take care of random number generation they want it.

266
00:25:11.470 --> 00:25:14.770
Now the thing is that thing is that you have a problem of trust.

267
00:25:15.915 --> 00:25:21.455
And and in multiple ways. First of all, how do you know that these people are saying what they're doing?

268
00:25:21.915 --> 00:25:28.240
And how do you know that even if they're saying what they're doing when you get home, you actually got a device that's supposed to do this. So that's why some wallets,

269
00:25:28.700 --> 00:25:29.020
cold

270
00:25:33.705 --> 00:25:44.570
Oh, sorry. Is CallClare is a good example. They allow you to add your own interview. And another good example, which is my new, favorite project, I'm I'm a very big fanboy, is the seed signer that allows you to,

271
00:25:45.930 --> 00:25:58.165
that that allows you to, to even take pictures. Right? So so so the reason you would have the this, like, your, these personal sources of entropy, if we can call them, is just because you you wanna eliminate the possibility of of trusting

272
00:25:58.940 --> 00:26:03.120
anything. You know? Right. When you use something like Ledger, you're purely trusting

273
00:26:04.220 --> 00:26:05.039
that chip

274
00:26:05.745 --> 00:26:10.725
to generate your entropy for you. If you add environmental entropy, if you

275
00:26:11.105 --> 00:26:13.045
use SeedSigner, and you take a picture

276
00:26:13.720 --> 00:26:16.460
of something that's not on the Internet, you take a picture

277
00:26:16.840 --> 00:26:20.140
of anything, it can take randomness from that picture,

278
00:26:21.000 --> 00:26:22.299
and you know, like,

279
00:26:23.065 --> 00:26:26.845
someone wasn't in, like, your bedroom closet taking a picture of,

280
00:26:27.385 --> 00:26:29.005
you know, your shoes or something.

281
00:26:32.020 --> 00:26:32.520
Right?

282
00:26:35.059 --> 00:26:38.520
Or you can use something like cold card where they allow you to add dice,

283
00:26:39.435 --> 00:26:44.175
or use strictly dice. So cold card has, like, 2 methods. You can either add dice,

284
00:26:44.955 --> 00:26:47.055
you can use their chip plus dice,

285
00:26:47.500 --> 00:26:49.120
or you can just use dice.

286
00:26:50.700 --> 00:26:52.160
If you just use dice,

287
00:26:53.580 --> 00:26:54.160
I guess,

288
00:26:54.595 --> 00:27:00.775
there is a concern there when if you just use dice, there's a concern that maybe the dice aren't sufficiently random.

289
00:27:02.169 --> 00:27:07.389
That that's a myth. That that doesn't make that's just a stupid meme that people pass around. You can mathematically

290
00:27:07.850 --> 00:27:11.549
I believe, like, I'm proving in 5 minutes that that doesn't make any sense if you want

291
00:27:12.595 --> 00:27:14.375
about that not being random enough.

292
00:27:18.675 --> 00:27:20.535
Yo, Waxwing. Try and speak.

293
00:27:21.590 --> 00:27:22.090
Hello?

294
00:27:22.470 --> 00:27:26.410
Yeah. We can hear you. Oh, why is I must I selected interface thing. Right?

295
00:27:27.190 --> 00:27:30.570
No. I didn't actually wanna say anything. I was just it just had little buttons that I was muted.

296
00:27:31.154 --> 00:27:36.934
Yeah. Blackwing thought he was muted. I did mute you for a second. When you first joined, there was a little bit of an echo, and then I unmuted you.

297
00:27:37.554 --> 00:27:38.934
So it might have been my fault.

298
00:27:39.950 --> 00:27:45.250
So, I mean, I think what we use for here is let's go through, like, the history of

299
00:27:45.550 --> 00:27:46.850
backdoors, compromises,

300
00:27:47.150 --> 00:27:47.970
poor implementations

301
00:27:48.615 --> 00:27:49.115
of

302
00:27:49.975 --> 00:27:51.675
of entropy sources, randomness.

303
00:27:53.175 --> 00:27:56.155
And then after that, we can jump into, like, actionable,

304
00:27:57.190 --> 00:27:59.830
mitigations in way that ways that freaks can,

305
00:28:01.669 --> 00:28:03.690
you know, make sure that their keys are secure.

306
00:28:04.215 --> 00:28:15.900
Sure. Let's do that. But but someone asked here, like because so all so all this thing when people say that because you know that you need because you know DICE for better security of your Bitcoin private keys, that's that that's just that's not true.

307
00:28:16.280 --> 00:28:25.325
That's just a stupid meme. It's FUD. You don't need that. Even if and and I'll just call it casino dice? No. That's that's just dumb. That's people are But they're pretty awesome.

308
00:28:26.025 --> 00:28:31.245
I mean, sure. But I'll tell you why they don't. The thing is, like, imagine you have so a Bitcoin private key

309
00:28:32.410 --> 00:28:33.470
usually it's 256

310
00:28:33.850 --> 00:28:34.350
bits.

311
00:28:35.250 --> 00:28:37.150
But Have you bought casino dice?

312
00:28:37.690 --> 00:28:42.085
I've tested casino dice. They're pretty they're like they feel really nice in the hand.

313
00:28:42.544 --> 00:28:46.085
They chip very easily. You have to be careful not to roll them on hard surfaces.

314
00:28:46.769 --> 00:28:49.490
Why don't we make tungsten dice? That'd be cool, wouldn't it? That's that'd be

315
00:28:50.690 --> 00:28:52.549
Alex, have you tested tungsten dice?

316
00:28:52.850 --> 00:28:55.955
I have not tested. Fair enough. I was just trying to say that that

317
00:28:56.515 --> 00:28:57.575
the thing is that,

318
00:28:58.355 --> 00:29:00.615
from a from a you can definitely measure

319
00:29:01.394 --> 00:29:07.940
sorry. I'm trying to say, like, for Bitcoin private keys, if you have crooked dice, you still end up with a secure key. So you don't need

320
00:29:08.320 --> 00:29:10.900
physical dice. What if you, like, roll them enough times?

321
00:29:11.760 --> 00:29:32.934
Not even enough times. You do so the thing is, like so let's think about it. Let's say you have you say you use a 12 bit word, a 12 bit seed. Right? Which is a 128 bits. Right? Okay. 12 words seed. It's a 128 bits is what you meant to say. Yeah. Sorry. What what I said? 12 bits. You said 12 bits. You said 12 bit seed, which is Yeah. That's That's hardly insecure.

322
00:29:33.715 --> 00:29:34.695
It's pretty bad.

323
00:29:34.995 --> 00:29:41.320
Okay. So let's say you have that. Right? And let's say you have a a dice. Let's say you have a coin or a dice or it doesn't matter. Right? It really doesn't matter.

324
00:29:41.780 --> 00:29:42.580
That, like,

325
00:29:43.140 --> 00:29:52.245
30% of the time, it gives you bad beats. It it gives you the it gives you ones. Literally, it gives you ones all the time. Right? Yeah. So then

326
00:29:52.625 --> 00:30:00.950
so if you would have that, like, let's so 30% is like very like crazy. 30, 30 divided by a 100 times a 128, what is that?

327
00:30:01.410 --> 00:30:02.950
That's gonna be 34.

328
00:30:03.410 --> 00:30:04.470
So a 128

329
00:30:05.845 --> 00:30:06.665
minus 34

330
00:30:07.365 --> 00:30:08.424
it's not 34.

331
00:30:09.765 --> 00:30:12.825
I'm not good at math on air, so I'm not gonna attempt to help here.

332
00:30:13.140 --> 00:30:42.725
The the point is that through. 30 is about 8. So well, whatever. It's about 38, let's say. The the point is that even if you have a a a dice or whatever you want, that's 30% biased, which is a crazy bias to have, by the way, you would still end up with 94 bits of entropy. Yes. Exactly. Which is impossible for anyone to ever crack more than safe and whatever. So At some point that's meant to meet. But couldn't you have explain why this is not actually this argument is completely crap when it comes nonsense, but this argument is good when it comes to private keys. Yeah.

333
00:30:43.105 --> 00:30:48.565
But but couldn't you like, couldn't someone on Amazon sell you, like, dice that just, like, roll

334
00:30:48.990 --> 00:30:51.650
the same thing over and over again? Or, like,

335
00:30:52.030 --> 00:30:55.650
roll is that is that even a thing? Or is that just bullshit?

336
00:30:56.429 --> 00:30:56.929
Literally.

337
00:30:57.635 --> 00:30:59.335
What does this spice look like?

338
00:31:01.075 --> 00:31:03.655
Yeah. Fixed every single time that you roll it.

339
00:31:04.170 --> 00:31:17.305
Okay. Fair enough. Fair enough. Okay. Okay. You open the subject. Okay. So if you if you still wanna be paranoid, I mean, I have a fucking tinfoil head on. And if you wanna test your dice, you should use some salt water. Again, just if you want that's how the the a lot of, like,

340
00:31:18.245 --> 00:31:22.025
dice people. Or you can even buy a special machine. But easier, just get some salt water,

341
00:31:22.730 --> 00:31:27.950
and you put it there. And then you just, like, give it a so so the dice is gonna float. Right?

342
00:31:28.490 --> 00:31:37.165
Especially if it's because you know dice. And then you just, like, pop it just the tiniest bit. And it has to, like you're gonna see if it's, like, weighted in if it's, like, crooked,

343
00:31:37.865 --> 00:31:46.030
you can see it's gonna land on one face more than others. So that's how you can do that if you really want it. But it's you don't have to. Like it's useless. Like it practically

344
00:31:46.330 --> 00:31:50.695
it does it's just if you wanna be autistic. But if you roll the dice more times,

345
00:31:51.794 --> 00:31:53.015
that's better. Yeah.

346
00:31:54.515 --> 00:31:56.455
Right? The more you roll, the better.

347
00:31:57.120 --> 00:32:00.820
But the the well, I I don't know what that means because it's like, what is our algorithm

348
00:32:01.120 --> 00:32:03.299
for using the dice? Right? It's like Right.

349
00:32:03.679 --> 00:32:15.530
So let's say the easiest algorithm is like when you have an odd number, you put a 1. And when you have an even number, you put a 0. Right? Right. And you just scroll it 257 times. So it doesn't matter how much you. One roll gives you one bit.

350
00:32:16.150 --> 00:32:16.650
Right?

351
00:32:17.030 --> 00:32:22.090
Right. How does that make sense? That's obviously not the most efficient way to use the rolls, but whatever. I mean, I yeah.

352
00:32:23.175 --> 00:32:33.960
Anyway, what's the most what's the more efficient way to use the roles? Oh, because you're not capturing all of the entropy of the object itself. Right? The the the object has six possibilities. So it has what's that? Like, 2 and a half bits of entropy.

353
00:32:34.500 --> 00:32:39.080
So if you only take it, it's, like, odd or even. You're only taking one bit of the available entropy.

354
00:32:39.524 --> 00:32:52.980
Right? So that's why you'd need to roll it 256 or 7 or whatever times. Whereas if you Right. You're using it as, like, a coin flip instead of a dice roll. Exactly. So you might as well just use a coin. Exactly. And then then you'd be taking your coin into the salt water, and then it would sink, and you wonder what to do.

355
00:32:53.600 --> 00:32:58.080
But coins can be compromised. Right? Like, you could have a coin that only flips heads or

356
00:32:59.105 --> 00:33:16.690
but that would be obvious, I guess. Well, I I even have a solution for that if you can do it. Like, I have I literally have a hack for that. Like, you can I here is I will generate, and we can even I'll generate a private key with a coin? You can make as bad as you want, and I'll put a $1,000 there, and I bet no one can take it. I'm willing willing to do that.

357
00:33:17.184 --> 00:33:19.345
Okay. Well, we should do that after the show. But, anyway,

358
00:33:20.705 --> 00:33:22.565
we kinda skipped ahead. I

359
00:33:22.865 --> 00:33:24.725
I think we should talk about, like, the

360
00:33:25.025 --> 00:33:25.605
the history

361
00:33:26.120 --> 00:33:28.060
the history of compromises, basically.

362
00:33:29.400 --> 00:33:37.405
Yeah. It gives context, doesn't it? Because because it's easy to talk about theory, but if if we see practical reality, then then we might actually have a clue what to do. Yeah.

363
00:33:40.825 --> 00:33:42.044
Well, I don't know.

364
00:33:42.760 --> 00:33:44.060
Oh, sorry. You're gonna say?

365
00:33:45.560 --> 00:33:49.900
I mean, BTC pins has a question about pulling words out of a hat.

366
00:33:54.215 --> 00:33:57.595
My my original impulse was to wait until we got to mitigations,

367
00:33:58.620 --> 00:34:04.080
but we can talk about that right now because he mentioned it. So so you you take all the BIP 39 words.

368
00:34:04.620 --> 00:34:06.640
How many words are in that word list, Alex?

369
00:34:07.365 --> 00:34:18.950
I think 2,000 2048, something like that. Okay. So you spend all day cutting out all of those words into individual pieces of paper. You put them in a hat. You shake them up. You pull them out of the hat.

370
00:34:19.330 --> 00:34:20.790
What's wrong with doing that?

371
00:34:21.330 --> 00:34:23.905
Well, so here's the thing right now. So the question becomes, like,

372
00:34:24.865 --> 00:34:29.365
like, first of all, is there a mathematical way which we can measure this? Right?

373
00:34:29.985 --> 00:34:31.925
Is there anyone who ever, like, measure,

374
00:34:32.760 --> 00:34:36.300
how good is this as a mixing method? And there's this guy called Percy Diaconis.

375
00:34:37.080 --> 00:34:42.605
He actually wrote papers on on on, how you can measure the efficiency of of,

376
00:34:43.165 --> 00:34:43.565
what's

377
00:34:43.965 --> 00:35:01.164
shuffling dice shuffle not shuffling, but mixing dice and mixing all those things. And he said that the best method to so if you have a deck of cards and what is the mathematical best method to mix it up is you have to do what I do in the casino. You put them face down on a on on a table or something, and then you you do this thing where like,

378
00:35:02.684 --> 00:35:09.410
that's not stroke, but you like, you know, you did that with them. You you move your hands around them. So you should do that. If you put them in a hat,

379
00:35:10.110 --> 00:35:16.645
I don't know what the shape of those things are and whatever. I don't know how that would work. So yeah. But this would be the the best way if you're asking. But

380
00:35:17.265 --> 00:35:23.045
come on, guys. I mean, nobody's gonna do that. I don't think you kind of implied it with the way you questioned it, man. And nobody's gonna cut out 2,000

381
00:35:23.345 --> 00:35:30.710
different people. Nobody's just trying to make an ass. See, but I think it the the it's a trivial point, but there's also a deeper point, isn't there, which is the

382
00:35:31.090 --> 00:35:31.590
practical

383
00:35:33.474 --> 00:35:41.555
inconvenience of a method is a huge factor, and it could lead to all kinds it could lead to you not doing it right, being sloppy, something could go wrong. Just, like, simpler is always

384
00:35:43.050 --> 00:35:43.869
Well, I

385
00:35:44.170 --> 00:35:45.150
mean, a 100%.

386
00:35:46.010 --> 00:35:50.830
So, like, I mean, I think this is a good bridging point to go into the history of compromises,

387
00:35:51.145 --> 00:35:54.845
because one of the main compromises I remember as a young Bitcoiner

388
00:35:55.385 --> 00:35:58.045
is before we had BIP 39. So BIP 39

389
00:35:58.460 --> 00:36:00.480
was the Bitcoin improvement proposal

390
00:36:01.019 --> 00:36:06.895
that implemented this standard that we all know as seed words. So if you're a new Bitcoiner, you just entered Bitcoin and

391
00:36:07.195 --> 00:36:16.339
there existed these seed words for backing up your wallet. These these 12 backup words or 24 backup words that you keep safe, You don't let anyone see,

392
00:36:17.359 --> 00:36:23.619
and and they restore your entire wallet for you. Those didn't always exist in Bitcoin. They were added after the fact as a standard.

393
00:36:24.195 --> 00:36:27.655
Now before they existed, we had something called brain wallets.

394
00:36:28.275 --> 00:36:34.349
And the idea of brain wallets was you would put a word phrase in that you decided on,

395
00:36:34.890 --> 00:36:35.390
and

396
00:36:35.690 --> 00:36:36.670
they would generate

397
00:36:37.130 --> 00:36:39.869
private keys for you based on that word phrase.

398
00:36:40.515 --> 00:36:43.575
And people, all the time, thought that they were being so clever

399
00:36:44.195 --> 00:36:47.015
Yep. With with what they were putting in there,

400
00:36:48.275 --> 00:36:57.730
but they they're there are people that out there that were just they were running GPUs, they were running computers, and they were just constantly trying all these different combinations.

401
00:36:58.855 --> 00:37:00.615
And, like, a perfect example was,

402
00:37:01.975 --> 00:37:05.515
like, poems or quotes. Like, people were using poems and quotes,

403
00:37:05.880 --> 00:37:06.859
and they were just

404
00:37:07.160 --> 00:37:07.660
generating

405
00:37:08.040 --> 00:37:16.785
people were able to generate the the private keys from those poems and quotes, and and they were just basically brute forcing it. They were just trying over and over different combinations

406
00:37:17.485 --> 00:37:19.105
of popular words and phrases

407
00:37:19.565 --> 00:37:24.705
and seeing if they could drain a wallet, if if it if it generated a real wallet that already existed.

408
00:37:26.680 --> 00:37:27.820
As as far as I remember,

409
00:37:28.120 --> 00:37:59.945
the people everyone was just, for some stupid reason, using the same algorithm where they would take the the text and hash it with, you know, Shar t 56. And and then so as you say, I mean, it it was quite remarkable even though we all understood that this was not very or we some of us understood this was not secure. It was remarkable. They were they literally took, like, the whole of Wikipedia a patch apparently. They they just they they were able to hash every possible combination of, you know, phrases and words and I mean, basically, obviously, not literally everything. Entire dictionaries and, like, they they cleaned it out, didn't they? There was basically, everyone

410
00:38:00.340 --> 00:38:03.960
who used any recognizable phrase got got taken like that.

411
00:38:05.060 --> 00:38:09.160
Yeah. That was pretty bad. And then also another thing is unlearn to learn,

412
00:38:09.565 --> 00:38:13.665
great name, by the way, is posting in the chat, the live chat via YouTube,

413
00:38:15.885 --> 00:38:19.025
is he makes it's a it's an important point to mention,

414
00:38:19.390 --> 00:38:21.329
is that when your wallet is

415
00:38:21.869 --> 00:38:22.609
is generating,

416
00:38:24.109 --> 00:38:28.210
your 24 word phrase, your seed phrase or 12 words,

417
00:38:28.615 --> 00:38:31.835
it's really the first 11 or the first 23

418
00:38:32.135 --> 00:38:33.355
is what it's generating.

419
00:38:33.895 --> 00:38:36.795
The last word is actually a checksum to make sure

420
00:38:37.590 --> 00:38:39.290
that all the other words are,

421
00:38:42.070 --> 00:38:44.330
valid, I guess, or, like, the order is valid.

422
00:38:46.745 --> 00:38:50.605
Yeah. But the thing is, like, most of the walls have a convention, and the first lexicographical

423
00:38:51.225 --> 00:38:54.125
valid one, if that's what he's talking about, is gonna be suggested.

424
00:38:54.650 --> 00:38:57.230
So But the last word's a checksum. Right?

425
00:38:57.609 --> 00:38:58.589
Yeah. Yeah. That's correct.

426
00:39:00.089 --> 00:39:02.510
So so if you're making them yourself,

427
00:39:03.655 --> 00:39:08.795
and we still need to get into the history of backdoors, compromises, and portal implementations, but if you're making one yourself,

428
00:39:09.975 --> 00:39:15.190
you basically have to if you want to comply with the standard and use it in

429
00:39:15.730 --> 00:39:20.390
all the mainstream wallets, you need to then use a separate tool to

430
00:39:21.155 --> 00:39:22.535
derive the checksum. Right?

431
00:39:24.595 --> 00:39:34.290
Oh, this was in the context of the yeah. If you do it yourself, yeah, you have to know. You should go yeah. That that's a good point then. Yeah. So, Alex, have you done that? Like, how do you how do you derive the checksum?

432
00:39:35.950 --> 00:39:38.690
I've done it on a lot of in a in a lot of ways.

433
00:39:39.555 --> 00:39:41.255
I personally just like,

434
00:39:42.115 --> 00:39:50.260
you know, I I like to have an offline computer and do it pretty much. Yeah. So but what what what do you is there a tool that you use to generate the checksum?

435
00:39:51.760 --> 00:39:53.625
I don't you the only time I myself. The only time I've

436
00:40:01.980 --> 00:40:04.559
So that's how I did it. But I think there's even,

437
00:40:05.579 --> 00:40:16.295
doesn't Coldcard have a Python script that you can use for that already or something like that? Or someone? Or even C Designer, I think, may have in the menu an option to do that. You just put all the words and they just spit it out for you.

438
00:40:16.595 --> 00:40:18.935
They give you the the last word for the checksum.

439
00:40:19.280 --> 00:40:20.099
I'm not a 100% sure,

440
00:40:21.119 --> 00:40:26.980
but some of what the wallets do that. Okay. Well, I'm not positive either. Waxwing, you have any idea?

441
00:40:28.435 --> 00:40:47.215
I I would say that the reason this caught me a little unaware is just because it it would never have occurred to me to to because I always thought the the algorithm and by the way, we we we talk about history. We should mention that that it was actually electron guys, Thomas Wirtland, who first came up with this idea before bit 39, and they implemented it. A slightly different algorithm

442
00:40:47.595 --> 00:40:51.695
with some rather interesting code that ended up being changed later. But,

443
00:40:51.995 --> 00:40:53.710
but yeah. But, I mean, that's not what you're that's not how it's

444
00:41:02.735 --> 00:41:04.595
that. It was never intended. And I think

445
00:41:05.055 --> 00:41:05.875
I personally

446
00:41:06.415 --> 00:41:25.005
I mean, I was I was sort of pooh poohing the the taking out of a hat based on practicality, but as a more fundamental point is you're not supposed to be coming up with a sequence of words yourself because that's dangerous to I mean, that's dangerously close to the old whole brain wallet thing again, isn't it? How many people might be tempted to come up with sequences of 12 or 24 words

447
00:41:25.545 --> 00:41:28.525
in this list that happen to make up a nice sentence. Right?

448
00:41:29.930 --> 00:41:41.135
So which is not what you're supposed to do. Right? It's a you you that's not how it's supposed to work. But, of course, cup taking out of a hat in theory is correct, except for, as you correctly point out, there's a check sum, which means you have to write one software anyway. So blah blah blah.

449
00:41:41.515 --> 00:41:45.935
Right. So, I mean, we have we have ride or die freak Younglurk in the comments,

450
00:41:46.609 --> 00:41:51.030
mentioning that seed signer will derive the checksum for you after you type,

451
00:41:51.490 --> 00:41:55.415
the first 11 or 23 words depending on what length seed phrase,

452
00:41:55.895 --> 00:41:56.635
you use.

453
00:41:57.175 --> 00:41:59.595
And the purpose there of that checksum is

454
00:41:59.975 --> 00:42:00.475
if

455
00:42:01.335 --> 00:42:02.315
if the checksum

456
00:42:02.615 --> 00:42:07.930
isn't valid, before you even try and restore a wallet in most good wallets, it will tell you,

457
00:42:08.470 --> 00:42:11.670
this seed phrase is not a valid seed phrase. And it's a

458
00:42:12.795 --> 00:42:15.535
it's just a way of it's it's just a,

459
00:42:17.115 --> 00:42:34.474
like a mistake check, a gut check to just tell you, you know, you fucked something up along the way. Now, the pass phrase, someone else is asking in the comments, the pass phrase is, yes, it's the 25th word or the 13th word, depending on how long your seed phrase is, and that is just completely from

460
00:42:34.934 --> 00:42:35.434
you.

461
00:42:35.734 --> 00:42:39.595
There's no randomness involved in that unless you wanna add randomness to that.

462
00:42:40.290 --> 00:42:41.570
And every seed

463
00:42:41.970 --> 00:42:44.230
every passphrase that you add, every

464
00:42:44.850 --> 00:42:48.630
every time you change that 25th word or that 13th word,

465
00:42:49.305 --> 00:42:51.165
you're gonna get a completely different wallet.

466
00:42:52.105 --> 00:42:58.605
So it will not show as invalid. Any any passphrase you put there will show up as a completely valid wallet,

467
00:42:59.330 --> 00:43:02.310
and there'll either be funds in it or there won't be funds in it.

468
00:43:03.010 --> 00:43:07.030
So as we've said many times on this show and on rabbit hole recap,

469
00:43:08.445 --> 00:43:25.599
it's it's a nice plausible deniability feature because you could have one pass raise that has some money in it, but another pass raise that has the majority of money in it, And you can go down that rabbit hole, you know, with 10 different wallets, you can go crazy on it. So that that's what that passphrase is there for. And what's nice about that passphrase

470
00:43:26.495 --> 00:43:32.675
is it just takes a little bit less trust. It it mitigates trust a little bit more from whatever wallet you're choosing

471
00:43:33.295 --> 00:43:33.795
because

472
00:43:34.290 --> 00:43:38.470
if for whatever reason, we're gonna we're about to go through the history of backdoor's compromises

473
00:43:38.930 --> 00:43:43.830
or implementations. If for whatever reason, that wallet is compromised and how they're generating

474
00:43:44.535 --> 00:43:46.475
your seed phrase, your private keys,

475
00:43:49.015 --> 00:43:57.780
they if someone wanted to take your funds, they still need to brute force your passphrase because you're providing that. The wallet isn't providing that.

476
00:43:58.560 --> 00:44:00.340
Okay. With all that said,

477
00:44:00.815 --> 00:44:14.190
we're 44 minutes in. Let's get into the history of different compromises. Alex, I think you I mean, your thread the reason one of the reasons you're on this show to begin with is you had a thread full of compromises. So you wanna start us off?

478
00:44:15.130 --> 00:44:17.470
Yeah. Okay. So the thing is, like,

479
00:44:18.255 --> 00:44:23.394
I the the way how that the trend started out is, like, I was listening to the city of dispatch and

480
00:44:23.775 --> 00:44:31.850
and Matt said that, you know, these are conspiracy theories that people try to compromise things. And I was like, oh, I have a lot of example where that's not the case. And,

481
00:44:32.285 --> 00:44:35.805
I I Yeah. Conspiracy theory was the wrong word, but, you know, when you do,

482
00:44:37.165 --> 00:44:39.744
when you do 400 hours of Bitcoin content,

483
00:44:40.204 --> 00:44:41.820
probably more than that, to be honest,

484
00:44:42.860 --> 00:44:49.920
You misspeak a lot. But, yeah, continue. I I was just being very autistic, of course. I mean, it was obvious what you're talking about. You know? But,

485
00:44:50.235 --> 00:44:54.715
I I I just wanted to to to write a thread because I spend so many times on this. But,

486
00:44:55.755 --> 00:44:56.735
the thing is

487
00:44:57.115 --> 00:44:58.815
that So the question becomes,

488
00:44:59.230 --> 00:45:06.049
do these things happen? Are these plausible? Right? Do we have to speculate? Well, I don't know if you guys should remember, but in 2,000 fourteen, Snowden

489
00:45:06.349 --> 00:45:09.565
leaked some documents. Right? And there's just one very specific document,

490
00:45:10.664 --> 00:45:12.924
that was that I got a lot of people's attention,

491
00:45:13.545 --> 00:45:19.300
and this is talking about the seed neck enabling project. And what this project does, it says very, very clear,

492
00:45:20.160 --> 00:45:24.420
like like, there's now nothing to interpret that they are putting constant effort

493
00:45:24.815 --> 00:45:25.055
to,

494
00:45:25.775 --> 00:45:37.580
well, let me read it from here. It says this, insert vulnerabilities into commercial encryption systems, IT systems, networks, and endpoint communication devices used by targets. Influence policies, standards, and specifications

495
00:45:37.880 --> 00:45:39.900
for commercial public key technologies.

496
00:45:40.435 --> 00:45:58.755
Complete enabling for blacked out companies, encryption chips, and virtual private networks, and web encryption devices. So it's just pretty much that they that they've done that. And never mind they've done it. They have a program that they spend, I don't know, it would like the budget of a few 100,000,000 or something per per year budget to do this. So that's the first example.

497
00:45:59.295 --> 00:46:10.720
I I have 2 more brief examples. Another example is there's this company called Crypto AG in 19 seventies, which is the be in Switzerland. Now, in the 19 7 in the 19 fifties, actually, that's when it was incorporated,

498
00:46:11.100 --> 00:46:18.275
cryptography looked very different. Everything was very analog, and there was no open sourceness of everything. So there was this one company in Switzerland

499
00:46:18.815 --> 00:46:19.714
when, people,

500
00:46:20.095 --> 00:46:27.830
were they were like, you know, Switzerland is neutral, so everyone buys their hardware from them. Well, the guy who who founded the company,

501
00:46:28.130 --> 00:46:31.515
he ended up being friends with a guy who actually was the chief cryptologist

502
00:46:32.215 --> 00:46:33.355
for, NSA.

503
00:46:33.895 --> 00:46:35.675
And from 1960

504
00:46:36.455 --> 00:46:36.955
until

505
00:46:37.575 --> 00:46:38.474
19 seventies,

506
00:46:38.910 --> 00:46:39.730
they backdoored,

507
00:46:40.830 --> 00:46:42.130
these things. So governments

508
00:46:42.510 --> 00:46:46.770
governments were paying money to get backdoor backdoor things. And here's where it gets even more crazy.

509
00:46:47.184 --> 00:46:48.805
From in 19 seventies,

510
00:46:49.345 --> 00:46:53.125
the CIA and the BND, which is the equivalent for the Germans,

511
00:46:53.505 --> 00:46:55.845
they literally bought this company 5050,

512
00:46:56.800 --> 00:46:58.100
under some dummy companies.

513
00:46:58.560 --> 00:47:02.340
And they operated them like that until 2018 or something. So 2017.

514
00:47:03.040 --> 00:47:08.915
And they sold compromised hardware to governments around the world. Like, and by oh, and they were even profitable.

515
00:47:09.215 --> 00:47:12.035
Keep this in mind. Like, these companies even made money.

516
00:47:12.630 --> 00:47:16.089
So I don't know when these things happen and you see those things, it's like,

517
00:47:16.390 --> 00:47:25.585
it's kind of easy to realize that, hey, if they if they did it then for these things, like, there's there's a 100% chance something somewhere is gonna get targeted with Bitcoin also.

518
00:47:25.885 --> 00:47:26.045
So

519
00:47:29.750 --> 00:47:30.810
Yeah. So, I mean,

520
00:47:31.270 --> 00:47:31.770
obviously,

521
00:47:32.310 --> 00:47:33.770
before Bitcoin existed,

522
00:47:36.550 --> 00:47:37.050
there

523
00:47:37.974 --> 00:47:39.835
was a massive war on encryption.

524
00:47:41.815 --> 00:47:47.355
That war continues to this day. Like, the the so called crypto wars has not ended yet.

525
00:47:49.580 --> 00:47:51.440
We've won a lot of legal fights,

526
00:47:52.460 --> 00:47:53.680
in terms of protecting

527
00:47:54.380 --> 00:47:55.440
code as speech,

528
00:47:56.474 --> 00:48:00.575
but that war continues to this day. And the easiest way to compromise

529
00:48:01.755 --> 00:48:02.895
encryption standards

530
00:48:03.195 --> 00:48:03.435
or

531
00:48:04.850 --> 00:48:05.350
no.

532
00:48:05.650 --> 00:48:06.150
Compromise

533
00:48:06.530 --> 00:48:07.670
the use of encryption,

534
00:48:08.530 --> 00:48:09.030
communications,

535
00:48:09.650 --> 00:48:11.430
or compromise Bitcoin

536
00:48:11.730 --> 00:48:12.790
is through

537
00:48:13.895 --> 00:48:14.395
compromising

538
00:48:14.695 --> 00:48:17.435
the sources of entropy or randomness. Correct?

539
00:48:21.470 --> 00:48:24.690
Yeah. I mean, if you would wanna compromise on, then that would be

540
00:48:25.230 --> 00:48:30.290
that would be the best way to do it, because And this is why, like, something like Bitcoin Core

541
00:48:30.815 --> 00:48:31.715
doesn't use

542
00:48:33.055 --> 00:48:36.995
solely the chip in your computer that's designed for random number generation.

543
00:48:37.775 --> 00:48:38.275
WiFi.

544
00:48:39.455 --> 00:48:39.955
Correct.

545
00:48:44.789 --> 00:48:54.644
Sorry. Can you hear me, guys? Yeah. We can hear you. I heard you say Wi Fi as well. I yeah. Sorry about that. I just I had to find another place. I mean I mean, like, the business center is the only place I could find.

546
00:48:55.265 --> 00:48:57.045
I love it. I appreciate the dedication.

547
00:48:58.619 --> 00:49:01.200
Did you did you hear anything that Alex said?

548
00:49:01.500 --> 00:49:05.099
Well, I know he's talking about the crypto crypto r gay example and the,

549
00:49:05.985 --> 00:49:08.805
and the NSA generally. I mean, have you gotten to dual ECDRBG

550
00:49:09.185 --> 00:49:12.325
yet? Or but the thing is, these examples are, like, really interesting,

551
00:49:13.425 --> 00:49:17.300
generally, but it's, of course, the question is how much they apply to our particular

552
00:49:17.920 --> 00:49:21.375
threat model, of course. Do they not apply to our threat model threat model?

553
00:49:22.095 --> 00:49:33.060
Well, there's the sort of there's this whole concept in in, you know, amongst security researchers of the global passive adversary. You know, it's a really that it's a kind of a euphemism for the NSA really, or at least it was.

554
00:49:33.440 --> 00:49:37.940
Now this idea that somebody is basically to hoovering up all the data and trying to, like,

555
00:49:38.285 --> 00:49:40.464
get a tap into everything going on.

556
00:49:41.885 --> 00:49:46.305
I feel like that's quite a different thing from the problem of protecting secrets,

557
00:49:46.605 --> 00:49:48.710
like protecting credentials for specific,

558
00:49:50.050 --> 00:49:51.170
things like Bitcoin.

559
00:49:51.570 --> 00:49:59.255
It's not unrelated, of course. It's it's a very it's closely related concept, but it's not I'm not sure if it's exactly the same thing, really. Well, like, it's not like a crazy conspiracy

560
00:49:59.555 --> 00:50:00.055
to

561
00:50:01.395 --> 00:50:07.980
think and, like, I'm not trying to FUD them because they have a long track record of securing private keys. But,

562
00:50:10.060 --> 00:50:14.160
something like a ledger device that's used by tons of people,

563
00:50:15.180 --> 00:50:15.680
and

564
00:50:16.355 --> 00:50:18.454
its only source of entropy is,

565
00:50:18.994 --> 00:50:20.934
I'm pretty sure, a closed source chip.

566
00:50:21.234 --> 00:50:24.135
Right. So so can I take this opportunity while my WiFi,

567
00:50:24.595 --> 00:50:25.710
is working to,

568
00:50:26.510 --> 00:50:30.849
put put out a, like, put out my hot take? You know, my hot take about this topic, which

569
00:50:31.150 --> 00:50:31.890
is not,

570
00:50:32.670 --> 00:50:37.035
generally agreed by most experts in the field. But I I am quite

571
00:50:37.895 --> 00:50:40.315
against hardware wallets as a general,

572
00:50:41.640 --> 00:50:55.345
I'm specifically against them as being like the way. Like, it seems so common in the last couple of years for people to say to even like newbies, oh, yeah. Yeah. Take it off the exchanges and put it straight on the hardware wallet. Like, that's the right way. Like, that is the gold standard. That is the thing that every

573
00:50:55.645 --> 00:51:01.650
average Bitcoin user should be using. I'm not at all sure that's correct. I and my reason for saying it is specifically

574
00:51:02.750 --> 00:51:07.505
that it's obviously, it's related to what you just said, but it's but it's more just the general philosophical

575
00:51:07.805 --> 00:51:08.865
concept of

576
00:51:09.244 --> 00:51:11.345
of central points of failure

577
00:51:12.125 --> 00:51:25.385
that and and also a concept something like steganography. And and if people don't know what steganography is, it's the idea that there's one thing to hide, like using encryption or some other technology to hide some secret, but it's another thing to hide the fact that you're hiding.

578
00:51:25.845 --> 00:51:26.825
And I think that,

579
00:51:27.605 --> 00:51:28.565
the problem with,

580
00:51:28.965 --> 00:51:30.000
using a Trezor or

581
00:51:30.720 --> 00:51:34.980
using a Ledger, albeit I'm sure they're great devices and I've I've played around with them a little bit, is that

582
00:51:35.600 --> 00:51:46.394
you're not hiding that you're hiding, and everything is going through a very clear central point of failure. And if we're gonna worry about NSA as a as an adversary, for example, or or the Chinese or whatever it happens to be,

583
00:51:47.080 --> 00:51:53.100
that's that's an obvious one. I mean, I don't think that really quite works, but it it could in theory, there could be some

584
00:51:53.560 --> 00:52:01.085
very malicious, very powerful actor that could get into those supply chains. Whereas if you buy off the shelf hardware and you work with things that are more

585
00:52:01.385 --> 00:52:01.885
custom,

586
00:52:02.560 --> 00:52:19.510
it might make, a lot more sense in the sense sense that it has it's not exactly steganography. That's not quite right, but it's but nobody can if nobody can predict that the device you're using is gonna be used for that particular purpose, that's a huge step up. And that's why I advocate more the the, cold, the off offline,

587
00:52:20.130 --> 00:52:21.750
laptop kind of model myself.

588
00:52:22.050 --> 00:52:23.270
Well, I mean so

589
00:52:23.810 --> 00:52:26.150
the way I look at it, I mean, I I think,

590
00:52:27.575 --> 00:52:29.515
I mean, everything has trade offs. Right?

591
00:52:29.895 --> 00:52:30.395
And

592
00:52:30.855 --> 00:52:31.355
Yeah.

593
00:52:32.855 --> 00:52:34.395
You know, to me,

594
00:52:34.855 --> 00:52:36.680
hardware wallets are a middle ground,

595
00:52:37.800 --> 00:52:38.300
And

596
00:52:39.079 --> 00:52:42.940
most people will not go through the trouble of having an offline machine

597
00:52:44.119 --> 00:52:46.059
generating secure entropy themselves.

598
00:52:48.025 --> 00:52:51.725
They have a computer that maybe they've had for 5 or 6 years.

599
00:52:52.345 --> 00:52:56.445
They use it for playing games. They use it for searching porn. They they

600
00:52:56.809 --> 00:53:03.470
they have it, you know, their emails on it and stuff. Oh, we hope we hope we hope it's not Windows. Right? Yeah. Most of them are using Windows.

601
00:53:03.944 --> 00:53:04.684
That's just

602
00:53:05.625 --> 00:53:08.605
some of them are using Mac. Very few are using Linux.

603
00:53:08.905 --> 00:53:13.405
Even fewer are actually securing their Linux distro in a sufficient way.

604
00:53:14.570 --> 00:53:16.670
And a hardware wallet is a

605
00:53:17.530 --> 00:53:19.630
is a is a nice middle ground there,

606
00:53:20.570 --> 00:53:22.510
that is relatively easy to use.

607
00:53:22.825 --> 00:53:25.484
Now the earlier hardware wallets, things like

608
00:53:25.785 --> 00:53:26.285
Ledger

609
00:53:26.665 --> 00:53:27.385
and Trezor

610
00:53:28.105 --> 00:53:32.125
now Trezor has all open source components in it, Ledger doesn't.

611
00:53:32.770 --> 00:53:34.790
Both derive the entropy internally

612
00:53:35.730 --> 00:53:37.030
through their own processors.

613
00:53:38.690 --> 00:53:45.105
The newer generation of hardware wallets allow you to add additional entropy to them. Right. Right. Right. Things like cold card.

614
00:53:46.605 --> 00:53:47.105
The

615
00:53:47.805 --> 00:53:53.970
seed signer takes it to a step above that in in a lot of ways. It does not have a secure element, so it's

616
00:53:54.430 --> 00:53:55.070
it's less

617
00:53:58.545 --> 00:54:07.845
it it it doesn't have a secure element, but it wipes itself is its strategy. So you have to re upload the secret every time. They use a QR code method now to make that easier.

618
00:54:09.730 --> 00:54:17.830
But the c signer is completely off the shelf parts. It uses a raspi 0. You can just buy that in, you know, a Micro Center or something like that with cash.

619
00:54:19.255 --> 00:54:21.275
Are most people doing that? Probably not.

620
00:54:21.655 --> 00:54:31.420
But there it's it's all about trade off balances. And There is there is another model. I just wanna mention it, because it's something I haven't thought about for a long time. But one of the first things I tried was using Tails

621
00:54:32.359 --> 00:54:34.460
as a way of what I've done too.

622
00:54:34.845 --> 00:54:46.700
Yeah. Sort of a quasi second laptop, you know, but it's not really a laptop. It's just something that's completely in RAM, and you just stick it in. I stick it on a, like, a USB or whatever it was. And, you know, it isn't clearly quite as good, but,

623
00:54:47.000 --> 00:54:54.725
you know, you could imagine various virtual machine based models. You know, they they wouldn't stand up to an academic rigor like somebody would say, oh, look. This is still

624
00:54:55.025 --> 00:55:17.435
hooking up to the underlying operating system. They can still be hacked and blah blah blah. But it still has that nice property that it's you're doing see, like you just said that the the the hardware wallets are a middle ground, and I totally agree with you. And your point is entirely valid, but the keyword there is middle. Right? So middle is a bit like the word center, right, which is a bit like central point of failure, which is I think so the two things go together. The fact that it is easier to use

625
00:55:17.815 --> 00:55:21.360
attracts everyone to it. So and then you have this big kind of centralization,

626
00:55:22.060 --> 00:55:23.040
vector of attack.

627
00:55:24.060 --> 00:55:29.954
So before before Anyway. Before the cold card existed, before seed signer exist as a project,

628
00:55:30.255 --> 00:55:34.675
my main way of telling people to do cold storage was Tails. And, actually,

629
00:55:35.135 --> 00:55:42.180
that was before they even added Electrum. Now they have Electrum built into Tails. Correct. So you can have this Linux Distro Tails

630
00:55:42.560 --> 00:55:44.500
on a on a USB drive.

631
00:55:45.120 --> 00:55:50.635
You can boot it up, and as soon as you pull the USB drive out, it's designed to wipe everything.

632
00:55:51.095 --> 00:55:51.914
So theoretically,

633
00:55:52.214 --> 00:55:55.035
you could be using that with your regular computer,

634
00:55:55.590 --> 00:55:57.450
the computer you use every day. Now

635
00:55:57.990 --> 00:56:02.330
if we're if we're going down the rabbit hole, really, you should be using it with a

636
00:56:03.135 --> 00:56:18.150
computer that's always offline, that you don't use for anything else, and then just have the additional benefit of pulling out the tails drive. But it is pretty cool that they have Electrum built in. It does make it easier. You never have to you literally never have to connect it to the Internet. You can just securely generate a wallet,

637
00:56:19.194 --> 00:56:22.175
and then every time just keep in mind that every time you,

638
00:56:22.795 --> 00:56:26.655
relaunch tails, you're gonna have to put in put in your seed words again.

639
00:56:27.440 --> 00:56:36.545
Mhmm. I suppose another thing to meant oh, god. No. No. I'm just gonna start rambling. Who's No. No. Ramble. We we have you on here to ramble. We love your ramble. Was gonna say that another kind of

640
00:56:37.025 --> 00:56:38.724
meta level, recommendation, you know,

641
00:56:39.025 --> 00:56:39.924
we're talking about,

642
00:56:40.704 --> 00:56:41.204
recommendations

643
00:56:41.505 --> 00:56:51.510
is is is the idea of, like, a second opinion, isn't it? So there's multiple models where I mean, one one counterpoint I've heard from people who are, you know, experts in the field,

644
00:56:52.290 --> 00:56:58.875
who who say, you know, actually hardware is not so bad. They're they're often saying to me, yeah. They take my point about the supply chain,

645
00:56:59.255 --> 00:56:59.755
risk,

646
00:57:00.055 --> 00:57:17.965
but they say, well, that's why you use multisig. Of course, that's a more complex sophisticated model, so it kind of takes away partly from that selling point that hardware wallets have this ease of use, middle ground, you know, somebody can do do it pretty straightforwardly. But so it makes it a little bit more complicated, but it has that second opinion element where if you have 2 devices,

647
00:57:18.265 --> 00:57:23.700
you know, if one of them is compromised, the other one's gonna complain. And you can do you can mix and match. You can do that with,

648
00:57:24.079 --> 00:57:30.924
an offline device or or maybe a tel. You you know you know, the may maybe you have 2 different ways that you think are kind of probably secure,

649
00:57:31.385 --> 00:57:37.220
and you sort of try both of them and generate your your addresses from your your seed on on both of them, for example,

650
00:57:37.760 --> 00:57:38.580
as an idea?

651
00:57:39.920 --> 00:57:41.060
Yeah. I mean, multisig

652
00:57:41.600 --> 00:57:42.420
is clearly

653
00:57:42.720 --> 00:57:43.220
a,

654
00:57:44.715 --> 00:57:48.015
mitigation of the trust issues that, you know,

655
00:57:48.715 --> 00:57:51.695
evolve around using a single hardware wallet fender.

656
00:57:52.440 --> 00:57:54.540
If you have something like a 3 of 5

657
00:57:55.160 --> 00:57:55.660
Yeah.

658
00:57:56.360 --> 00:57:59.580
And you have 5 different types of wallets there,

659
00:58:00.165 --> 00:58:03.385
You need 3 of them to be compromised for you to get compromised.

660
00:58:05.285 --> 00:58:08.185
I would say that's probably, like, the next level of middle ground.

661
00:58:08.740 --> 00:58:13.240
Right? And then you get and then you could even get into using multiple offline

662
00:58:14.100 --> 00:58:15.880
Mhmm. Computers that are dedicated,

663
00:58:16.575 --> 00:58:19.315
you know, to the purpose and then have them be in multisig.

664
00:58:20.095 --> 00:58:28.900
And I would say I mean, to I I think with multisig, you know, like, it's it's kind of it's like a relatively new niche within Bitcoin.

665
00:58:30.000 --> 00:58:33.859
Have people been doing it since, like, the armory days? And, you know,

666
00:58:34.684 --> 00:58:40.545
yes, like, people have been doing it for a while, but it's starting to really evolve. And I the ideal

667
00:58:41.325 --> 00:58:42.385
would be that,

668
00:58:42.930 --> 00:58:49.510
you know, in the relatively near future, in the next 5 years or so, it becomes even easier to use. And, I mean, you have you already have things

669
00:58:50.235 --> 00:58:55.615
like Casa and Unchained where they hold your hand, and they make it relatively easy to use multisig.

670
00:58:56.155 --> 00:59:01.350
Now you have a whole separate trade off there where you're trusting a third party completely with your privacy.

671
00:59:02.450 --> 00:59:06.630
And in Casa's case, I mean, it's it's a closed source wallet app,

672
00:59:07.785 --> 00:59:11.965
that also in a lot of situ I think in every situation holds one of your keys.

673
00:59:12.665 --> 00:59:13.885
So, I mean,

674
00:59:14.345 --> 00:59:16.125
that's a whole another trade off, but

675
00:59:17.049 --> 00:59:21.549
I feel like it's getting easier. Like, we're not we're not quite there yet, but it's

676
00:59:22.970 --> 00:59:23.789
it's relatively

677
00:59:24.089 --> 00:59:24.589
accessible.

678
00:59:25.015 --> 00:59:32.154
There's no doubt it's getting better. Yeah. Yeah. And if you talk about, like, 2 year even 2 years ago, I mean, it was a way it was a way worse situation

679
00:59:33.869 --> 00:59:35.250
in terms of using multisig.

680
00:59:35.630 --> 00:59:58.650
I feel like this is kinda like, this whole multisig thing is, like, you you think in your mind that you should have a girlfriend for each need you have. Once she cook for you, once she do this, once she do that. But then again, you have 10 girlfriend and, like, I mean, you have 10 you have 10 and you have 10 times more complexity. You know? And I think I think these companies did a good job. Fair enough. But I also feel there's, like, the people on Twitter who need something.

681
00:59:59.215 --> 01:00:04.115
Like, everyone needs to have an insight. Right? And I think that a lot of people always search for an insight, and I think,

682
01:00:04.655 --> 01:00:17.240
a lot of people think this is their insight. Multi 6 says everything. You know? But I don't think necessarily is obviously the best way to log in to 15. You know? I would I would say if you're a public Bitcoin figure, which I am,

683
01:00:19.625 --> 01:00:20.125
multisig

684
01:00:20.905 --> 01:00:25.645
adds an additional benefit that you can have your secrets geographically distributed.

685
01:00:27.210 --> 01:00:32.750
So if someone breaks into my house, not only do they have to deal with my guns, but they also have to deal with the fact

686
01:00:33.130 --> 01:00:33.630
that

687
01:00:34.595 --> 01:00:37.095
all my secrets aren't in this location.

688
01:00:37.395 --> 01:00:43.950
Right? And they they're gonna need to go and and get the secrets from those other locations and deal with that extra complexity,

689
01:00:44.810 --> 01:00:48.270
before they can steal your funds. So it's more than just mitigating

690
01:00:49.050 --> 01:00:53.525
the trust risk of whatever wallets you're using as the individual signers.

691
01:00:53.905 --> 01:00:58.645
I think that's perfectly valid for a case, by the way. But I'm I was I was trying to criticize

692
01:00:59.380 --> 01:01:12.275
as this being a social for everyone. Right? Then Right. I agree. Like, for for But I get it. You understand very well. And you you you you were like, hey. I have a very I have a very specific situation, and my security is specially catered to my situation.

693
01:01:12.734 --> 01:01:13.215
But I'm

694
01:01:13.855 --> 01:01:20.100
I guess my point was that maybe public figures on Twitter are more likely to be talking about it Sure. Because

695
01:01:20.640 --> 01:01:32.925
because it it suits their situation. Right? And people tend to get caught up. It's one of the things with this show that I'm I'm actively aware about, that I have to remember that everyone's not in my situation,

696
01:01:33.330 --> 01:01:35.590
and I I need to make sure that I have content,

697
01:01:36.210 --> 01:01:53.070
you know, for people in completely different threat models, completely different trade off balances that they're they're seeking, but a lot of people don't. Right? A lot of people just they're like, this is the best thing for me, so I'm just gonna keep talking about it. That that was my point. Can I can I, butt in and answer a question in the chat from Bill McFly?

698
01:01:53.370 --> 01:02:01.275
So he says, so memorizing so memorizing the seed is no good idea. Is is it not a good idea? He's asking. And, I think this is a a common and important question.

699
01:02:01.994 --> 01:02:02.895
So you have,

700
01:02:03.434 --> 01:02:09.520
you have a a set of words. And, obviously, the intention of bit 39 and and the former Electron version was that,

701
01:02:10.060 --> 01:02:12.080
you have something that's human readable

702
01:02:12.540 --> 01:02:14.880
and, at least in principle, human memorizable.

703
01:02:15.420 --> 01:02:21.184
And a lot of people will just immediately reject the idea. They'll say, oh, especially if it's 24. But even if it's 12 words, they'll say,

704
01:02:21.645 --> 01:02:26.865
well, you can't easily remember 12 words. That's a lot of words. That's a lot of lot of entropy to try to remember. But the thing is,

705
01:02:27.829 --> 01:02:29.770
the way the human brain works is

706
01:02:30.070 --> 01:02:45.675
the you know, I remember I vividly remember in school a absolutely terrible Latin teacher who insisted that we would memorize the entire chapter of Caesar's Gallic war before each each lesson, which is absolutely ridiculous, but I literally did it. I mean, because the human brain can do that. It can memorize an entire chapter of text.

707
01:02:46.850 --> 01:02:51.490
So memorizing 12 words is trivial as long as you use a simple mnemonic technique such as,

708
01:02:52.130 --> 01:03:01.325
embed those words into a story and have that story have some emotional resonance for you, and then just repeat it a few times, and you will find you're actually able to remember over a fairly fairly long period.

709
01:03:01.680 --> 01:03:22.290
Now you'll get the counterargument, and I certainly got this from people like Greg Maxwell back in the day. You should tell me, like, no. That's don't don't do that. Don't do that because your memory was very fallible. You cannot possibly just rely on your memory. It's a very bad idea. And, of course, he's got a very good point. So I think the the ultimate nuanced answer is, no. You don't just rely on your memory long term for your storage. You have some kind of physical storage.

710
01:03:22.590 --> 01:03:25.010
We can get into, like, how you do that. There's many ways.

711
01:03:25.315 --> 01:03:28.135
But it's also very convenient that you have this,

712
01:03:28.915 --> 01:03:30.775
option of memorizing memorizing,

713
01:03:31.075 --> 01:03:40.775
for example, when you're crossing borders. So I don't have to put anything on a piece of paper when I cross a border, let alone, carry a little device that looks like a calculator or whatever it is. Right? Right.

714
01:03:41.495 --> 01:03:50.235
So so I think there's a nuanced answer there. It's a very interesting Yeah. I mean, and if you're memorizing it to cross a border, you only need to memorize it for 24 hours or 48 hours.

715
01:03:51.400 --> 01:03:57.420
There's also a nuance there, like, if you have clues or something. But, like, I will I will speak from personal experience

716
01:03:57.720 --> 01:03:59.420
as a very paranoid person

717
01:04:01.075 --> 01:04:06.455
that I have right now. I have 4 encrypted drives that I do not know the password to

718
01:04:07.819 --> 01:04:17.405
because I thought I can memorize them, and I memorized them many times. There was many times I entered it until I couldn't enter it, you know. And I still have the drives because I'm like, one day it might come

719
01:04:18.125 --> 01:04:25.745
to me. And that's forgetting I haven't had any brain injuries or anything like that. Wait. Wait. Wait. Are there any private keys on those drives, or is it just information?

720
01:04:26.440 --> 01:04:28.620
You know, x wing, I'm not quite sure.

721
01:04:29.080 --> 01:04:43.235
You know, sure. But that's my point. My point in asking, although it's a bit of an in intrusion, my point in asking is that there's a certain incentive when there's there's money involved that you might have. There there's a there let me put it this way, Waxwing. There's a reason why I'm still holding the drives.

722
01:04:43.790 --> 01:04:44.290
Okay.

723
01:04:45.550 --> 01:04:58.405
I haven't thrown them out yet. I but I I have I really have no idea what's on those drives. So you had a virtual boating accident, basically. It's all all all of your yeah. It's still there. They're, you know, they're in my drawer. I just need to remember the password.

724
01:04:58.785 --> 01:04:59.845
Oh my gosh.

725
01:05:01.190 --> 01:05:04.650
But it happens. You know, you'll remember them until you don't. And

726
01:05:05.110 --> 01:05:06.330
if if if,

727
01:05:06.630 --> 01:05:16.375
you know, MVK says a very good, he has a very good line that that you should when you think about storing Bitcoin, like, you should be thinking 10 x the amount you're holding.

728
01:05:16.740 --> 01:05:18.520
And I would say that's even conservative.

729
01:05:18.900 --> 01:05:19.800
Right? Because,

730
01:05:22.100 --> 01:05:25.720
it's been way more than 10 x since I first entered the Bitcoin world.

731
01:05:26.295 --> 01:05:27.355
So you you know,

732
01:05:28.135 --> 01:05:33.835
it might not seem like that much. You're like, oh, I'm just setting it up. I don't need to write it down. I'll remember this.

733
01:05:34.210 --> 01:05:36.309
Of course. Yeah. It's it's it's

734
01:05:37.089 --> 01:05:45.735
it's more it's it's very likely that you will forget it. Some people will remember it until you forget it. So just, at the very least, have clues.

735
01:05:47.315 --> 01:05:49.575
When it comes to storing secrets safely,

736
01:05:51.315 --> 01:05:52.855
pen and paper is your friend.

737
01:05:54.090 --> 01:05:58.830
It's offline. Someone has to come into your home or office to to access it.

738
01:05:59.930 --> 01:06:05.065
Obviously, it's not fireproof or water proof. That's where, like, steel comes in, stamping steel, stuff like that.

739
01:06:05.365 --> 01:06:08.585
To go back to the history of backdoors compromises and poor implementations,

740
01:06:10.119 --> 01:06:12.140
one that I remember vividly

741
01:06:12.840 --> 01:06:17.900
Mhmm. Was the blockchain dot info wallet, which, by the way, still exists. Do not go to that website.

742
01:06:18.405 --> 01:06:21.865
Do not use their wallet. Do not use any of their software. They're also blockchain.com.

743
01:06:22.244 --> 01:06:25.464
Do not go to that website. Do not use their software. Disclaimer. Disclaimer.

744
01:06:26.789 --> 01:06:29.450
They had a compromise where they were using random.org

745
01:06:29.990 --> 01:06:32.410
as their source of entropy. Correct. Yeah.

746
01:06:32.710 --> 01:06:42.395
And it was serving a 404 error for a little bit, So all the wallets were derived from the 4 zero four error. Yeah. I think it was actually 403 redirect, but either way, it's the same. Okay.

747
01:06:42.775 --> 01:06:54.595
Either way, same reason why it's basically a fixed string, and they were just kinda hashing that and and and so it was everyone was but what's so catastrophic about that is I think that was private keys, not nonsense, right, in that that particular one. So it was actually

748
01:06:55.055 --> 01:07:01.450
was it? So they're actually Yeah. The one Max is referring to it was private keys. Yeah. Yeah. So does that mean that we're giving everyone the same address

749
01:07:02.710 --> 01:07:04.010
or the same seed anyway?

750
01:07:04.470 --> 01:07:10.234
I think they had did they have one other source of randomness, but it was, like, a bullshit derived source of randomness?

751
01:07:10.694 --> 01:07:25.890
At some point, they were even well, yeah. They were using random death of war, and that they didn't call anymore. But I don't think people were, like, people were in opening wallets, and they already had funds in them. It had it took an attacker. There was there was some nuance to it. Yeah. Yeah. There was definitely a bit, not simple. Yeah.

752
01:07:26.475 --> 01:07:35.855
And there was a around that same time, I think it went slightly earlier. It's less well remembered nowadays. There was a there was a bug where there was an actual weakness in the,

753
01:07:36.859 --> 01:07:37.340
secure random,

754
01:07:39.420 --> 01:07:40.880
library in Java.

755
01:07:41.500 --> 01:08:02.809
And and I think there were 2 or 3 wallets were hit by this where they were actually generating really insecure nonsense. Was the original shield back wallet compromised on that, I think? I think it might have been because it might have been Bitcoin j j s. Right? The the or the the Yeah. Yeah. It makes sense to me. It's just a bit unclear in my head, but because it was a long time ago. But that's the thing, Waxwing, is, like,

756
01:08:03.875 --> 01:08:04.855
like, I understand

757
01:08:06.275 --> 01:08:10.835
the concerns around, like, hardware wallets or whatever. But before, like, we enter the hardware wallet era

758
01:08:11.369 --> 01:08:13.869
Yeah. I mean, like, do you remember, like,

759
01:08:14.170 --> 01:08:25.375
on Bitcoin Talk and Reddit and stuff, like, it was just, you know, like, people, like, had logged me in on their computer. They just had, like, a virus on their computer something, and they were getting compromised. Like, forget entropy. I know the conversations around entropy.

760
01:08:26.074 --> 01:08:31.180
But, like, I it felt like every day you would just open Reddit, and it was just, like, someone got their wallet trained.

761
01:08:31.900 --> 01:08:32.400
Yeah.

762
01:08:33.100 --> 01:08:36.000
Yeah. Like, we've we've removed the low hanging fruit.

763
01:08:37.420 --> 01:08:37.920
Yeah.

764
01:08:38.355 --> 01:08:43.094
And now we can talk about now we can go deep about securing your Bitcoin because

765
01:08:43.635 --> 01:08:46.215
people aren't losing their shit every fucking day

766
01:08:46.560 --> 01:08:47.699
over some ridiculous

767
01:08:48.000 --> 01:08:49.380
compromise on their computer.

768
01:08:51.440 --> 01:08:52.579
I mean, yeah.

769
01:08:53.040 --> 01:08:54.099
It's still certainly,

770
01:08:54.985 --> 01:09:16.815
the the the problem I I mean, maybe I'm affected by having tried out hardware while it's in the early days of of that development where, you know, you would plug it in. It would say, like, oh, just just fire up our web app, and then it would, like, you know, and they do have it would be, like, more effectively, like, seeing all your transaction. So privacy disaster. And then it would be like, oh, just update the firmware, and there'd be another

771
01:09:17.275 --> 01:09:21.455
10 firmware. And they were just like, oh, are you joking? I just the more I think

772
01:09:21.755 --> 01:09:26.370
I mean, I actually went to the trouble of going to the Trezor offices in Prague to actually get my Trezor,

773
01:09:26.990 --> 01:09:30.990
in person playing for cash. So I'd I'd try to be like the good citizen like that. But,

774
01:09:31.824 --> 01:09:34.725
Of course, you did. But even so, I didn't

775
01:09:35.264 --> 01:09:35.764
really

776
01:09:36.304 --> 01:09:44.820
trust I just don't trust the model, but I do see the argument that it's Well, like, the good ones nowadays, like, don't you don't use, like, a prepackaged,

777
01:09:46.560 --> 01:09:47.060
software,

778
01:09:48.565 --> 01:09:50.665
you know, the firmware updates or

779
01:09:51.045 --> 01:10:02.440
at least there's there's PGP verification there. I mean, I guess, like, a hardware wallet, the beauty of it is you can have, like, a hard coded sign in key, and they can check it for you, but, you're trusting them to check it.

780
01:10:04.685 --> 01:10:07.025
They're they add additional sources of entropy.

781
01:10:07.805 --> 01:10:14.490
You're using you can use your own node with it instead of using the centralized node that's is tracking all your balances and your transactions.

782
01:10:16.630 --> 01:10:19.130
So if we if we try and summarize, like, the historical

783
01:10:19.725 --> 01:10:26.945
aspects apart from the whole NSA thing, which is that the the the I think the reason Alex focused Apart from the elephant in the room. Yeah. Well, apart I think the reason,

784
01:10:27.429 --> 01:10:40.614
Alex focused on that is because it illustrates the point that people say, oh, don't be conspiracy theorists, whereas in fact, the conspiracies are real. Right. Right. You know, I think that is a very important point to to bear in mind. But in terms of, like, Bitcoin, it's been mostly like

785
01:10:41.554 --> 01:10:42.614
software flaws.

786
01:10:43.720 --> 01:10:46.780
It's user error in terms of generating keys,

787
01:10:47.320 --> 01:11:16.245
and I think the software errors tend to be more about generating nonces. And the reason for that is you have to generate a nonce every time you do a transaction, whereas a key is a one time thing. So it's easier. It's more an isolated thing to get that right. Okay. Maybe block channel info was so terrible. They actually screwed that up as well. But Maybe now it's a it's a good moment to actually start explaining this because maybe a lot of people don't even know this is a thing where, like, what I mean. If you start, you start the whole nonce conversation. Wait. Wait. Before we get there before we get there, I wanna make it completely clear.

788
01:11:16.705 --> 01:11:28.409
I wanna make it completely clear to the freaks. We have 20 minutes left in this conversation. I just wanna make it completely clear to the freaks who are scared shitless right now. There's a lot of you out there. I know you're you're a little bit scared from this conversation.

789
01:11:29.255 --> 01:11:29.755
That

790
01:11:30.775 --> 01:11:33.435
strictly speaking, if you hold your own keys,

791
01:11:34.215 --> 01:11:37.275
ideally use your own node, but if you hold your own keys

792
01:11:37.840 --> 01:11:39.699
in any of the major hardware wallets,

793
01:11:40.320 --> 01:11:41.780
you're still better off

794
01:11:42.159 --> 01:11:42.480
than if

795
01:11:44.079 --> 01:11:45.219
all else equal.

796
01:11:45.679 --> 01:11:51.324
I I don't like speaking absolutes. You're still better off than keeping it in custodial regulated exchange,

797
01:11:51.864 --> 01:11:54.284
custodial wallet. We have MZ

798
01:11:54.660 --> 01:12:01.640
fucking legend in the comments right now talking about Mt. Gox. Like good point. Like, we have in the history of Bitcoin,

799
01:12:02.155 --> 01:12:06.655
if you hold your Bitcoin with the custodian, not your keys, not your coins, we say this a 1000000 times,

800
01:12:07.035 --> 01:12:13.320
it it can it can get frozen, it can get stolen, you can lose it, the exchange go bankrupt.

801
01:12:14.020 --> 01:12:19.640
Like, there's there's a lot of ways you can lose your coin if you're holding it on an exchange. So the first step

802
01:12:20.335 --> 01:12:21.875
before you get into all this

803
01:12:22.815 --> 01:12:30.570
rabbit hole, you you you gotta hold your own keys, and don't get don't get too frightened from this conversation. Okay. Alex, continue.

804
01:12:33.430 --> 01:12:46.380
Yeah. So we were talking initially about the whole random numbers things. Right? And it's like all we said here pretty much was that, hey. It's pretty obvious and I think everyone knows even if they're a novice that you need those words to be random, and we stress this enough.

805
01:12:46.760 --> 01:12:49.900
Now the thing is that the way Bitcoin works,

806
01:12:50.920 --> 01:13:07.705
is that you have these Bitcoins laying around on that's not technically accurate, but go with me. You have these Bitcoin laying around on on the blockchain. Right? And you need to provide a signature to say, hey. I actually could This is a proof that Like you sign in Chegg that I have this Bitcoins and I'm gonna move them somewhere else.

807
01:13:08.265 --> 01:13:13.085
The way this signature works mathematically because it just works like that,

808
01:13:13.545 --> 01:13:46.895
you need some a bit of randomness for this also. And, you well, probably some of you are gonna think right now, well, we just got a new signature scheme with like Taproot and whatever is nor. So what we're gonna talk is valid for both of them. This specific aspect that we're gonna talk about Yep. Yep. Doesn't change anything. So it's valid for both of them. Anyway, so the thing is that you what the signature pretty much does in a very dumb way, you just think you also use your private key. You jumble a lot with some other with this randomness and some other things. And then when someone looks at this on the blockchain, other nodes, they're gonna be like, this is a valid signature.

809
01:13:47.755 --> 01:13:49.135
And the thing is that

810
01:13:49.790 --> 01:13:57.650
signatures are made to function in this way and they shouldn't leak your private key. That's why you use that random you know, that's randomness to mix it together so you don't leak it.

811
01:13:58.054 --> 01:14:01.195
And turns out there's, like, these very clever attacks

812
01:14:01.895 --> 01:14:09.390
that actually if you have so I was I was actually, made a really big case earlier that, hey, if you have a crooked dice

813
01:14:09.690 --> 01:14:18.105
and 30% of the dice is Right. Like, 40% of the inter piece. But, like, you're still guiding up with a with a private key. It so happens that with the nonces,

814
01:14:18.565 --> 01:14:25.210
like, if you have even one single bit, I'm repeating this, one single bit of biased entropy there,

815
01:14:25.590 --> 01:14:27.290
someone could look at your,

816
01:14:28.230 --> 01:14:29.850
at your signatures on the blockchain

817
01:14:30.390 --> 01:14:30.890
and

818
01:14:31.625 --> 01:14:38.925
they could steal your they could guess your private keys, which is pretty crazy. It's like it sounds like it's impossible when you think about it. Maybe Adam wants to

819
01:14:39.400 --> 01:14:53.965
explain how this has happened. And there's actually a few variants on this attack, not just the one with a bit, but that one is the most, Yeah. I guess, scary. So yeah. So I think I think going back to first of all, let's get the word clear. So nonce is a word that's short for number used once.

820
01:14:54.520 --> 01:15:22.605
And what is this number used once? What is the purpose of it in the context of a signature? Well, the purpose of it is simply blinding. Very crude understanding of it is when you're signing with your private key, you're kind of multiplying the message by the private key very crudely. You're just taking the message and just imagine it in your head. I'm just gonna multiply it by the private key. Now if you pass that across to somebody as a signature, it would be horribly insecure because they would just divide out the message and they get your private key. So the purpose of this nonce is to add a blinding

821
01:15:23.065 --> 01:15:31.450
number just like, I could give you the number if I have the number 13 and it's a secret, but if I add 17 to it, you're you're just gonna see, like,

822
01:15:32.170 --> 01:15:49.840
what is that? 40, 30. You're gonna see 30, and you're not gonna know the original secret 13. Could be precisely because you don't know what that random blinding addition was that I did that 17. If you knew it was 17, then, of course, you could take it away and get the 13. So the purpose of a nonce in a signature scheme is specifically

823
01:15:50.540 --> 01:15:51.360
to blind

824
01:15:51.820 --> 01:15:56.815
the the output signature while still having that property that you're binding the the private key to the message.

825
01:15:57.515 --> 01:16:15.514
And it's obvious from that description that I can't well, it maybe isn't obvious, but it should be clear if you think about it from that description that if I tried to use the same nonce twice so I signed 2 different messages with the same private key. But if I then use the same nonce twice, then by simple subtraction, I'd get rid of the nonce, so I'd be back to the situation

826
01:16:15.815 --> 01:16:21.355
where I can just trivially ex extract your private key from the signature by by taking away the messages.

827
01:16:22.360 --> 01:16:29.260
If you work out the algebra, that's how it works. And, like, the saying twice is like a simplification, but if you do it, like, 15, 20,

828
01:16:29.585 --> 01:16:45.810
100 times, it becomes easier. No. No. That that in that particular case, it's not a simplification because because the most basic nons reuse here. Specific. Yeah. So the most, yeah, so the most basic example of of a of a nonce failure, so to speak, is if you simply reuse the same nonce twice in different messages.

829
01:16:46.255 --> 01:16:56.080
Then it is the case because you've only used it you've only you've got 2 equations there, and you can subtract out the nonce from the two equations and get the private key. And just to add very quickly here before we move on,

830
01:16:56.720 --> 01:17:05.220
there were a lot of well, by a lot of, I mean, probably a few hundred cases of when this happened. And there are a few people who, like, did some research and there's some papers there,

831
01:17:05.875 --> 01:17:14.135
and they found this. And that is true. They were more like because these are implementation errors pretty much. Right? And these were happening more in the early days

832
01:17:14.435 --> 01:17:15.270
more than now.

833
01:17:15.750 --> 01:17:20.090
Yeah. Yeah. So so that's the most basic So how do you know the nonce is being reused?

834
01:17:20.630 --> 01:17:40.125
Right. Well, it's very simple. When when you publish a signature on the chain, you're publishing 2 pieces of data. One is the actual signature, which is a a number, a scalar number in in the field, and the other the other one is an actual elliptic curve point like a public key. So what you actually if you actually look at a signature like an easy to say signal on chain, unfortunately, it has, like, weird extra formatting. But you probably already

835
01:17:40.845 --> 01:17:42.465
know that public keys are like 3 or

836
01:17:42.925 --> 01:17:43.425
2.

837
01:17:44.205 --> 01:17:51.410
Right? It's actually a pub just like your public key for your for your private key. This this nonce point, we could call it, is the corresponding

838
01:17:51.950 --> 01:18:28.210
elliptical point to the to the nonce scalar, the the the nonce secret. So just like your private key is not exposed by giving someone the public key, they can't they can't reverse it and find it. Similarly, when we publish the nonce point on chain, you can't reverse it back to the original nonce from the public the public point nonce, the nonce point, however you wanna say it. So if if but if you just reuse the same nonce, just like if you reuse the same private key, you'll get the same public key. Right? If you reuse the same nonce, you'll get the same nonce point. So somebody so what these people did in the early days was they set up automated programs looking on chain or or in the mempool anyway

839
01:18:28.590 --> 01:18:40.085
for transactions that were using the same r value, which is the public nonce point as had previously been used. Soon as they saw that, they could just subtract the 2 signatures and immediately get the private key. So it was it is visible on chain.

840
01:18:40.465 --> 01:18:44.165
Yeah. The Yeah. But do you see the subtlety is that you're it doesn't reveal the actual

841
01:18:44.470 --> 01:19:00.145
nonce secret value itself. It reveals the public key corresponding to it. So it reveals that it's been reused, but not exactly what it is. Exactly the same way as if I gave you the the public you know, it's the same private key even. Like, anyway, you get the point. So that's the most basic example.

842
01:19:00.685 --> 01:19:07.730
Yeah. Go ahead. No. No. No. I was gonna say that that actually MZ brought up something, but I think you're gonna explain maybe then we should address the question.

843
01:19:08.270 --> 01:19:15.625
Yeah. I think before we before we do the that's a very important thing to discuss. Before we discuss that, let's just quickly I just wanna expand one little detail on,

844
01:19:16.005 --> 01:19:27.515
like, Alex gave you the bombshell. Right? The bombshell is that the nonces have this horrible fragility to them, which is that even if you have slight biases, 1 bit, 2 bits, 3 bits maybe,

845
01:19:27.975 --> 01:19:29.915
in a nonce, that can

846
01:19:30.215 --> 01:19:45.344
lead to, this catastrophic failure where you actually get the private key just from the nonces even though the nonces are only a tiny bit biased. And but I just wanted to just qualify that. Very important qualification to that is that that attack, I mean, it's generally called the, LLL, it's,

847
01:19:47.324 --> 01:20:06.815
hidden number problem is is how it's described or also a lattice based attack is another way to describe it. But this attack only works with lots of signatures. And when I say lots, it could be anything from, like, 20 to 30. Well, if it's a really extreme bias, you might only need 10 signatures. But if it's like a normal, like a few bits or 10 bits, you might need, like, 30, 40, 50 signatures. So, luckily,

848
01:20:07.370 --> 01:20:12.030
even if somebody's got a very slightly bad nonce generator that is random,

849
01:20:13.210 --> 01:20:15.150
if you only use the same key once,

850
01:20:15.465 --> 01:20:32.920
then it kind of, by luck, doesn't matter. Right? So that's a detail, but it's an important detail. Now MZ is making a very important point, which is everything we're describing about generating. That's not how it works. And part of the reason it doesn't work like that is because in history, there were a number of software failures leading to one very famous example was

851
01:20:33.380 --> 01:20:36.885
somebody we all know and love, Ryan x Charles, managed to put,

852
01:20:37.605 --> 01:20:45.350
this wonderful piece of code in in one library or another that some wallets were using that actually generated nonce of 64 bits instead of 256 bits.

853
01:20:45.730 --> 01:20:51.270
So that's not like a 1 or 2. That's 1 or 2 bits. That's like 3 quarters of the bits rule zeros.

854
01:20:51.975 --> 01:20:59.675
So as a consequence, and this was found by in the paper, biased nonsense by Henning Henninger et al. Oh, that's a great name for the paper.

855
01:21:00.280 --> 01:21:04.920
Yeah. Bias nonsense. Yeah. You can look it up. It was funny because when when she published it,

856
01:21:06.120 --> 01:21:12.955
I was on I was on our IC with with Greg Maxwell, and I we were looking at at a typical Greg Maxwell. It's like you're like, oh, yeah.

857
01:21:13.595 --> 01:21:32.675
And it and it it I think it took him about 1 hour to figure out it was this one particular commit by Ryan x Charles. He found out which wallet it was because they were saying in the paper, we don't know which wallet generated these, but we found all these and they were all insecure and all the money was lost. And, of course, it wasn't the academics that stole the money. It was some somebody else had automated programs running looking for this kind of thing.

858
01:21:33.660 --> 01:21:37.520
That's a name I haven't heard in a while. I remember when he used to be a hero to me

859
01:21:37.900 --> 01:21:44.675
before he completely lost his shit. Oh, yes. So we yeah. Those videos. Yeah. That's kinda interesting. Yeah. That is that is something.

860
01:21:45.215 --> 01:21:45.715
Anyway,

861
01:21:46.335 --> 01:21:56.179
so what's going on? Yeah. So deterministic nonces. Now this is where it gets interesting. What you can do is because it's difficult to do this right in software and because nonces are fragile, how about let's get clever

862
01:21:56.719 --> 01:21:59.139
and let's refer back to something we said earlier

863
01:21:59.520 --> 01:22:10.045
in the the discussion, which was the idea of a pseudo random number generator. So instead of just thinking of a a fixed amount of a random number, think of something that generates a stream of random bytes.

864
01:22:11.290 --> 01:22:15.630
And what we can do is create, this pseudo random number generator based on 2,

865
01:22:16.090 --> 01:22:26.315
like, bits of secret data. The private well, not one of them secret. The private key and the transaction message. And what we can do is go through a bunch of hashing, basically. That's what it's called RFC 6979,

866
01:22:26.695 --> 01:22:28.395
and we can output a nonce,

867
01:22:29.020 --> 01:23:00.665
which and this would be the the actual secret nonce. The output nonce would be a function of both the message and the private key. So nobody who doesn't know the private key can regenerate the nonce. But the cool thing is it means that this same nonce will be generated every time you have the same message and same private key, and it also guarantees that every time you have a different message with the same private key, you'll get a different nonce. And that's the property that's absolutely critical. You never want to have the same nonce on the same private key with a different message because that's when you're repeating the nonce and you lose all your money.

868
01:23:01.365 --> 01:23:08.210
So RFC 6979 has become absolutely standard across all wallets used in Bitcoin since about, I don't know, 2015, 2016.

869
01:23:08.750 --> 01:23:13.810
Nobody uses anything else. But there is a little, like, fly in the ointment, which is when these new, like, music

870
01:23:14.195 --> 01:23:20.615
music type, protocols get developed. We can no longer do that for more reason. Which we just added functionality for?

871
01:23:21.800 --> 01:23:31.265
Yeah. It's Taproot. Yeah. But Taproot Music isn't really in anything. Yeah. Music isn't really in anything. Yeah. It's not even in LipSect p, but but it's kind of, like, coming very quickly. So, yeah.

872
01:23:31.965 --> 01:23:41.580
So so right now, probably, you know, they're like, the people on the chat are like, okay. That was some very interesting boring fucking technical detail. Why do I fucking care? Well, I was only

873
01:23:42.140 --> 01:23:48.960
Mzs. Yeah. You're right, Mzs. That's why I was the long version of, like, what was what you're saying. No. No. But but I I I'm gonna steal man that.

874
01:23:49.324 --> 01:24:08.695
Okay. So so so you're thinking like this isn't okay. That's interesting thing, but you already said it's fixed. So why the fuck would I care? Right? Well, now here's the problem right now. So let's say you get your hard reward. Right? Which is, you know, it's a Bitcoin hard reward. Yeah. And, you you say, I I generated my so I I've done my my job. I generated with my own dice. Right?

875
01:24:09.235 --> 01:24:20.920
But now you have to still make transactions. And now here's comes the question. And I know this again also very esoteric attacks, so keep that in mind. So don't get scared, but it could happen. Well, if someone intercepts your hardware wallet,

876
01:24:21.380 --> 01:25:01.835
they could do specifically bug your random number generator in a way where it affects your nonsense. Right? So right now you don't know you don't sorry. When when it's creating a transaction, you don't know where it's getting this this nonsense for. You know? And and then this becomes also a different problem because so what if we have the standard? How do you know the wallet is using it? Exactly. Can I just can I just reemphasize that for my other people? People are not gonna necessarily think of it. But everything I just described is great, but you don't know if a hardware wallet is doing it. You cannot know when you look at a nonce whether it was generated by RFC 6979 or whether it was generated by dice rolls or whether it's completely, like, evil generates. You know. Yeah. Well, like, is there is there, like,

877
01:25:02.695 --> 01:25:09.500
a a time reputation kind of thing that involves this thing? I mean, people have been using some of these hardware wallets for years. Oh,

878
01:25:10.760 --> 01:25:19.315
So regarding this thing that I just said, Stefanik's Nityev, I think that's how I pronounce your name, the guy who Niggirievs. Nigirev, I think is Nigirev. The guy the guy who

879
01:25:19.915 --> 01:25:21.515
pronounced name. He's awesome.

880
01:25:22.215 --> 01:25:30.199
He he he yeah. He's just great. The he actually wrote about this thing, had a blog post, and he even they even try to standardize this

881
01:25:30.579 --> 01:25:48.659
a bit, and had some some posts or whatever. So and there are there are a few ways to, like, solve this problem, by the way. Even this one, you can still solve it. Maybe Adam can describe it a bit more. Can I ex expand a bit on this? Because I'm I'm running out, and I wanna talk explain. So the the concept here might be I mean, you talked about time. That's an important concept is,

882
01:25:49.765 --> 01:25:55.945
you can get really sneaky with this. One thing you could do as an attacker is if you had control of the nonce generation function,

883
01:25:56.405 --> 01:25:58.745
instead of just having it spit out a key immediately,

884
01:25:59.120 --> 01:26:01.700
you could have it spit out a couple of bits

885
01:26:02.160 --> 01:26:08.500
of the secret data, let's say, the master secret for your bit 32 tree. Right? It could spit out a couple of bits every

886
01:26:09.175 --> 01:26:46.465
every transaction or maybe just one bit every 10th transaction, and it could be, like, over, like, 3 years. He slowly but surely gets gets your key. Once you're well you know, you've spent a couple of months thinking, well, I'm not sure about this hallway. Well, like, oh, yeah. It seems to be working fine. I've done a few transactions. Now do a few bigger ones. Now do a few bigger ones. And he's waited, like, a year, and then eventually, he's got your whole key and you're you're dead. Right? So so just you have to think, like, really fiendishly, like, these adversaries. So how do we protect against this? It's a very nontrivial problem. There's a there's a post on the Bitcoin dev mailing list, I think, by Peter Willer, who went through several different ways you could try to address this problem. And it's a very weird problem because the whole concept of the hardware wallet

887
01:26:46.765 --> 01:26:49.585
is that the, you don't trust the,

888
01:26:50.285 --> 01:27:11.400
the hot computer, let's say, yeah, the online computer, and you're trusting the the the offline computer, which is the hardware wallet. But in this attack, we have to flip it around, and we have to say, okay. I'm gonna assume that the hardware wallet is is is an anniversary. Right? So how do we so so how do we deal with this? Well well, the the general concept is just like you said before with a cold card, you take some randomness

889
01:27:11.860 --> 01:27:12.760
and you actually

890
01:27:13.300 --> 01:27:25.725
sort of feed it into the nonce, add it into the randomness that the hardware wallet is generating, whether it be RFC 6979 or anything else. But you add your own little element of randomness into it to make sure that overall that nonce is in fact random.

891
01:27:26.960 --> 01:27:36.735
So it's things like there's a concept concept called sign to contract, and it's basically the idea that you take the hardware while it's nonce, and you kind of add You tweak that point with a hash

892
01:27:37.114 --> 01:27:41.534
of some data that you fed in. And then you have to have a protocol that sort of,

893
01:27:41.915 --> 01:27:49.170
how to say, verifies from the the the the software wallet side, verifies that the actual procedure was followed honestly.

894
01:27:50.110 --> 01:28:00.015
And I think I would recommend people read a post by Blockstream on on Blockstream's mediums. It's like anti exfil, they call it. Anti dash exfil because it's against

895
01:28:00.610 --> 01:28:01.110
exfiltration

896
01:28:01.970 --> 01:28:06.870
of the secret via the nonce. So the nonce is like a side channel if the people who know about that concept.

897
01:28:07.730 --> 01:28:20.870
But, yeah, it's it's pretty advanced up, but that is that is an example of a problem that you can kind of solve. But the interesting point is if you read the whole blog post, at the end, they point out that there's a fundamental sense in which you can never totally solve it. Because what can happen is if the attacker,

898
01:28:21.730 --> 01:28:35.469
sees that the output from this honest protocol to produce a properly honest nonce, if it produces a kind of nonce that they don't want, they can just abort the protocol and say, oh, sorry. There was an error. We can't sign sign that. So they point out in the blog post

899
01:28:35.849 --> 01:28:48.565
that even if you get really, really clever, you still have to take an approach of saying, you still have to be paranoid. Like, if if the thing stops working or maybe it's maybe it's, an adversary. You know? Well, it's a personal responsibility thing. You should just always be paranoid.

900
01:28:50.840 --> 01:28:55.340
But, Alex, when was the last time an attack like this happened, an a non space attack?

901
01:28:56.055 --> 01:29:13.455
Well, the the thing is, like, we kind of, like, made them very general, but you have to like, these nonce attacks are very specific. Like, even, like, Adam was saying, like, there's the whatever problem. There's even, like, specific attacks of the hidden number problem. Right? Yeah. That's true. Yes. So so so it depends which one do you mean.

902
01:29:13.915 --> 01:29:18.000
But that's but can I just say that's why you should read biased nonsense by by

903
01:29:18.320 --> 01:29:25.780
Henninger, et al? Because it's it's effectively a review, and it doesn't even restrict itself to Bitcoin. It also covers Ethereum and LOL Ripple.

904
01:29:26.115 --> 01:29:35.170
And it actually shows, like, over that they because they basically scanned the whole blockchains looking for weak nonces. And they found that they part of their summary is, like, we found, like, $24

905
01:29:35.630 --> 01:29:39.410
worth of Bitcoin is still exposed and, like, $12 of Ethereum. So, essentially,

906
01:29:39.950 --> 01:29:40.690
all the

907
01:29:41.015 --> 01:29:47.515
the other examples, which they found quite a lot over several years, had already been taken. So be people had programs running continuously,

908
01:29:48.750 --> 01:29:54.510
and some of the most obvious examples were like the ones I mentioned before. Secure random in Java had a a weakness in its,

909
01:29:55.325 --> 01:30:24.880
it's supposedly cryptographically secure random number generator, which wasn't actually cryptographically secure, which meant that once somebody has seen enough data, they could predict what the next values would be, and they could use that to extract the nonce. Oh, okay. That wasn't exactly nonce reuse, but there were I think there were a lot of examples. This is something you can trivially check by just scanning of people literally just reusing nonsense due due to a software bug or just due to being stupid. I don't know exactly. But it's it has happened quite a lot. I mean, relatively, I don't mean, like, 1,000,000, but, you know, it has happened.

910
01:30:25.579 --> 01:30:31.315
You know, the idea was, like, don't worry about this, but if you were having a coverage of, like, what could go bad with entropy,

911
01:30:31.615 --> 01:30:34.995
this is what could go bad with entropy. And okay. So how could you,

912
01:30:35.375 --> 01:30:46.510
one way to limit this? Well, in order for someone to deploy this attack, they have to target your device. So get this hardware. Right? I I don't know. Don't get, but this would be a way to mitigate it pretty much.

913
01:30:47.850 --> 01:30:48.350
So,

914
01:30:48.965 --> 01:30:49.465
guys,

915
01:30:49.925 --> 01:30:52.425
this has been an absolutely fantastic conversation.

916
01:30:53.045 --> 01:30:54.345
We have a hard stop,

917
01:30:54.725 --> 01:30:56.505
that we've Yeah. Gone past.

918
01:30:57.240 --> 01:30:59.420
No. It's it's okay. I'm I'm yeah. That's good.

919
01:30:59.800 --> 01:31:07.695
You're good? You're good to continue, Wax? Well, I mean, I'm good I'm good to finish is what I meant. Oh, yeah. Yeah. We're gonna wrap up. It's been a great it's been a great conversation.

920
01:31:08.395 --> 01:31:12.050
I appreciate both your time. Let's let's end it with some final thoughts.

921
01:31:12.530 --> 01:31:14.469
Alex, first to you. Final thoughts.

922
01:31:15.809 --> 01:31:16.710
Final thoughts.

923
01:31:17.090 --> 01:31:17.809
I don't know.

924
01:31:18.690 --> 01:31:28.655
I don't know what to say. I guess you should just start being a bit more skeptical. That's what I would say about all these things and all this this common knowledge that you have that that you get from people because

925
01:31:29.170 --> 01:31:31.590
I don't know. That's the whole point of Bitcoin. That's

926
01:31:32.050 --> 01:31:33.350
that's what I would say.

927
01:31:34.130 --> 01:31:36.870
Waxwing. Thank you, Alex. Waxwing, final thoughts.

928
01:31:37.655 --> 01:31:38.295
Yeah. Well, just,

929
01:31:39.575 --> 01:31:40.395
be suspicious

930
01:31:41.815 --> 01:31:44.075
of third parties, like central parties.

931
01:31:44.695 --> 01:31:49.950
Be as because, you know, everything in our in our culture encourages us as consumers to just, like,

932
01:31:50.570 --> 01:32:00.784
do the easy thing, but but, you know, have a bit of gumption and and do the do the hard thing. There we go. But, yes, thank you, waxwing. Yeah. Everyone, practice some personal responsibility.

933
01:32:02.284 --> 01:32:06.599
Don't go for the most convenient answer, and, constantly continue learning.

934
01:32:06.980 --> 01:32:12.599
I wanna thank all the rider die freaks who joined us in, the live chat for this conversation.

935
01:32:13.219 --> 01:32:13.540
Very

936
01:32:14.585 --> 01:32:25.820
you you guys make this show special. Thank you to all the Rider Die Freaks that continue to support the show and keep it ad free and sponsor free. And a huge thank you to both Alex and Waxwing for joining us.

937
01:32:26.920 --> 01:32:31.100
It's it's been an absolute pleasure. I hope you guys come on again soon. And,

938
01:32:31.805 --> 01:32:36.065
Waxwing, thank you for coming on for your second time. You're you're fucking killing it. Enjoy El Salvador.

939
01:32:39.060 --> 01:32:50.875
Yeah. Thanks for thanks for having us on, Matt. And I I really appreciate, again, you just, straight away after you saw the thread, you were like, Astro, let's talk about this. So thanks for That's what that's what this show is about. That's why I do it. So thank you both. Cheers.

940
01:32:51.574 --> 01:32:52.074
Cheers.

941
01:33:15.670 --> 01:33:21.945
Looking out the window, hear the ice cream truck tearing through the couch, cushions, tryna

942
01:33:22.324 --> 01:33:33.170
scrounge up. But, Buck, you know, I'm runnin' to get to him, but, oh, he rolls away, because I gotta stay cool on a hot summer day. I've got

943
01:33:33.790 --> 01:33:34.530
3 quarters

944
01:33:35.790 --> 01:33:37.570
and two dimes. I've got

945
01:33:38.030 --> 01:33:38.425
4

946
01:35:03.760 --> 01:35:08.145
Hours yearly living life carefree, not a worry in the world from a bill or girl.

947
01:35:08.525 --> 01:35:10.945
Homework was the main concern, and with 99¢

948
01:35:11.245 --> 01:35:14.130
I had money to burn. Looking for a block party or barbeque,

949
01:35:14.610 --> 01:35:16.389
Who said ballin' out was impossible?

950
01:35:16.770 --> 01:35:23.125
And I could do things that was hard to do, a quarter water plus chips and a Charleston juice. It was water, kid, like Evian.

951
01:35:23.425 --> 01:35:25.285
Looking for a girl like a move, Evian.

952
01:35:25.825 --> 01:35:38.610
In the vein of Christina Mille Young, but with more Echelon and some pink jellies on. Now, not some average missus, someone I could play run, catch, and kiss with. Back then, kid, please believe this. Only thing me and Eli would need is.

953
01:35:39.070 --> 01:35:39.570
Three

954
01:35:39.895 --> 01:35:40.395
quarters

955
01:35:40.775 --> 01:35:43.114
and no. 2 dimes I got. Okay.

956
01:35:43.415 --> 01:35:48.010
Open pieces. Come on. Oh, man. I'm walking in the street

957
01:36:34.645 --> 01:36:35.705
Love you, freaks.

958
01:36:36.165 --> 01:36:38.905
Thank you for joining me for another dispatch.

959
01:36:39.830 --> 01:36:42.730
I will see you on Rabbit Hole Recap on Thursday,

960
01:36:43.110 --> 01:36:46.170
and another civil dispatch on Tuesday for another

961
01:36:46.550 --> 01:36:50.625
Bitcoin Tuesday. We have a great lineup next week. We have Eric Sirion,

962
01:36:51.325 --> 01:36:54.465
the lead maintainer of Simple Bitcoin Wallet as well.

963
01:36:54.845 --> 01:36:56.145
That's not Eric Sirion.

964
01:36:56.780 --> 01:37:00.800
And Fiat Jaffe, and we're gonna be discussing Chaumian Mints on Lightning.

965
01:37:01.100 --> 01:37:02.719
This idea that you can have

966
01:37:03.100 --> 01:37:10.625
a privacy preserving, trust minimized custodial wallet that has easy UX and can interact with the rest of the Lightning Network.

967
01:37:12.960 --> 01:37:20.020
It could be a very special conversation. I am looking forward to it. I love you all. Stay humble. Stack stats. Cheers.