TFTC: A Bitcoin Podcast - #170: Chris Belcher

Episode Date: June 10, 2020

Join Marty and Matt as they sit down with Chris Belcher, the developer behind JoinMarket and the first CoinSwap implementation, to discuss: - JoinMarket - Fidelity Bonds - Chain analysis heuristics - ...Chris' CoinSwap design - A "privacy threshold" - Why CoinSwaps are > CoinJoins - much more Follow Chris on Twitter Support Chris' work on a CoinSwap implementation here Shoutout to this week's sponsors. Cash App. Start #stackingsats today. Use the promo code: "stackingsats" to receive $10 and contribute $10 to OWLS Lacrosse when you download the app.

Transcript
Discussion (0)
Starting point is 00:00:00 What's up freaks, it's your boy Marty Bent here to introduce this episode of Tales from the Crypt. Matt and I had the immense pleasure of sitting down with Chris Belcher, the man behind Join Market and the recent design implementation of Coinswap, which he is currently working on and he is being supported by the Human Rights Foundation. News just dropped a few minutes ago before recording this ad. This news dropped after we recorded this episode, so we did not cover that. in the episode but uh we did talk about dev funding towards the end and it is uh
Starting point is 00:00:35 very encouraging to see that the human rights foundation has stepped up and provided chris with a grant to work on this coin swap implementation specifically so kudos to hrf for putting the team on their back here this episode of tales from the crypt is brought to by our good friends at the Cash App. I hope you do many things. I hope you stack sats, send sats, receive sats, sell sats, if you so please. On top of that, they're doing incredible things
Starting point is 00:01:08 on the banking front. You can now use Cash App as your bank account. It has an account number and a routing number. You can start getting your paychecks direct deposited into the Cash App, and it's becoming a neobank, a new bank where you can uh send your paychecks there have them directly deposited start stacking sats then also if you want to if you're if you're a stock picker out there seems to be a lot of stock pickers out there these days stock market going crazy going mad and uh it's uh if you want
Starting point is 00:01:37 to do that cash app investing is letting you stack slivers of stocks okay you don't have to buy a whole stock if uh your your favorite stock has become out of your reach to buy to purchase a of that stock because of this crazy fed induced stock market bonanza you can buy as little as one dollar via cash app investing because cash apps directly connected to your bank account or like i described earlier it is your bank account there's no four to five day waiting periods you can start investing today as always or before we get to the as always cash app investing is a subsidiary of square remember sipc now as always when you download the app if you haven't done done it yet if you're listening to this podcast you're in america you haven't done it yet
Starting point is 00:02:20 what the hell are you waiting for use the code stacking sats it's s-t-a-c-k-i-n-g-s-a-t-s you're gonna get ten dollars upon sign up and then ten dollars gonna go to our great friends at owls lacrosse in chicago doing incredible things uh in the west side and south side of chicago building uh a lacrosse program to help instill leadership values and and teamwork into the children of chicago owls lacrosse not owls lacrosse not that dirtbag owl owls my uh my owl that sits outside my window he made a twitter account last night and so he's going to be scoring these these owl calls from here on out so we'll see how i do uh download the cash app enjoy this episode with chris belcher and congrats to chris for the grant from the hrf
Starting point is 00:03:12 huge uh huge huge news it's gonna make bitcoin better you've had a dynamic where money's become freer than free if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting like safe haven i believe that in a world where central bankers are tripping over themselves to devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean that's part of the bull case for bitcoin if you're not paying attention you probably should be what is up freaks welcome back to tales from the crypt it's your boy marty bent here on a lovely tuesday afternoon uh despite all the madness going on in the world i'm very excited for
Starting point is 00:04:07 this conversation uh it's a privacy heavy conversation we're about to have this is a topic that we talk a lot about here on tftc we've got matt odell with me the privacy nut what's going on this is gonna be good i'm excited and and we're joined by chris belcher who recently released a design implementation for a coin swap, which is not a new idea, but the first implementation that's come to market. And we're going to talk a lot about that. Chris, thank you for joining us. Hello there. Thanks for having me.
Starting point is 00:04:38 I really appreciate it. You've taken some time to come talk about this. We've talked about coin swap on this podcast last week after you dropped the implementation. So I guess we should just dive right into it. You and I have been talking since before this recording and have a little bit of structure laid out for this conversation, which isn't typical here on TFTC, but we're speaking to what I would deem somebody who's very knowledgeable in this space. We're going to learn a lot about coin swaps. So before we get into coin swaps, Chris, how did you get into Bitcoin and why are you focused on privacy? uh well i've always liked coding and programming and uh cryptography i remember reading about pgp
Starting point is 00:05:25 and the crypto wars from ages and ages ago and uh it's actually kind of funny story when i was quite young i used to be involved in uh there was an old video game i don't i think people still play it called runescape and there was a thing where you could have in-game items and trade them back then people trade for paypal and obviously that didn't work very well because we'll charge back charge packs and you'd find out each other's real names and that kind of thing and um then when i when i came across bitcoin i thought hey you know it's obvious it's really good for video games right that's what it's for and then the more i got into it the more i read of how useful it is for other reasons and uh i've always been interested in history so i thought yeah it would
Starting point is 00:06:04 be useful in you know the weiber republic in germany that kind of thing half money um yeah I just went from there and I looked at what are the problems around Bitcoin and got interested in privacy and Validation like the electron personal server is all about validation as well Yeah, that's my story pretty much Yeah, I mean, thank you for all the work that you've done to help Improve personal validation and and privacy overall which join market specifically and now coin swap at least your your implementation of a coin swap which you're still working on correct yeah yeah it's in the design stages right now and so i guess let's let's help uh
Starting point is 00:06:52 the audience understand what a coin swap is when did the idea come to market and and how i guess your design would work once once it's finally implemented so coin swap is i'll deal with those things one by one a coin swap it's a privacy protocol so it's like like coin join but something else uh the point of it is to improve privacy in bitcoin and fungibility and the way coin swaps actually what they do is they break the transaction graph so you can imagine now when we look on the blockchain and there's a transaction that spends uh money's going from address a to address b coin swap can make it so that the coins like the actual ownership ends up on a totally different address, address Z, address X, which is entirely unrelated.
Starting point is 00:07:37 And that's obviously really useful if you're using Coinswap, but it's also useful for other people. If there's some other user who's never even heard of Coinswap, who just makes a normal transaction, they'll have their privacy improved as well, because anyone who wants to analyze the blockchain, some kind of adversary, they'll always have to consider that maybe they see this transaction, they think,
Starting point is 00:07:55 well, maybe a Coinswap happened. So it will add a huge amount of doubt, I hope, and will make their analysis much harder and thereby improve privacy and fungibility. So the way Coinswap is kind of... What it works is there's two... We've got Alice and Bob, like two entities, and they swap coins with each other.
Starting point is 00:08:12 So Alice's coins end up with Bob, and Bob's coins end up with Alice. It's actually quite an old idea. Like, it's from 2013. It was invented by Greg Maxwell. Around the same. It was about a month or two after CoinJoin. So what was the other thing you were saying?
Starting point is 00:08:32 Sorry, I forgot the rest of your question. So how would your design work once implemented? So coin swap, it's an old idea. But it has loads of... The original Greg Maxwell's design had loads of unsolved problems. So my design is basically solving these problems one by one. like it the the title is this coin swap but there's loads of other building blocks in there that are necessary to me to really make it work well so for example in the original coin swap
Starting point is 00:09:04 scheme you had alice and bob would swap just one coin so alice would give 10 bitcoins to bob and bob would give 10 bitcoins to alice and that means if there's an adversary who knows alice's 10 bitcoins she can this adversary can search the blockchain for somewhere else where there's 10 bitcoins and they'd find bob's 10 bitcoins then it'll be easy okay so these 10 bitcoins went here Bitcoin went back. So the amount would be a privacy leak. So my solution to that and the design is to have multi-transaction coin swaps. And that would be where Alice gives 10 Bitcoins to Bob and Bob gives multiple coins back to Alice. So he gives her like two Bitcoins, three Bitcoins and five Bitcoins. And those three together add up to 10. And
Starting point is 00:09:46 then if our adversary is searching the entire blockchain, he'll never find one coin which is worth 10 bitcoins uh so that attack will be will be fixed um another problem in the in the original design is there's only two of these parties so even though someone observing the blockchain doesn't know where the coins went bob does like if you're alice you have to trust bob though but they're not that they're not going to spy on you um so in my design that's solved by routing coin swaps so alice would do a coin swap with bob and then bob will do a coin swap with and not someone else Charlie and Charlie will do a coin swap with Dennis and then Dennis will do a coin swap back to Alice and then Alice would have her coins made anonymous and
Starting point is 00:10:28 All three of those those other parties Bob Charlie and Dennis they'd have to collude If they wanted to figure out where all the coins actually went So rooted coin swap kind of spreads out the trust in that way then Another thing in the design is having a liquidity market. So that's just like in join market where Alice would pay for the coin swaps actually to happen. So for these, Bob and Charlie and so on, they'll just hang around, they'll run a server all day,
Starting point is 00:10:58 and they'll say, you can coin swap with me and return for a small fee, like a future social or something. It's exactly the same way it works in join markets. But instead of coin joins, you get coin swaps. And the effect there, it means that if you're Alice, if you have a wallet, you can do a coin swap whenever you want. You just press a button, and the coin swap for your amount It doesn't have to be 10 Bitcoin, 0. whatever, any amount you want. It just happens straight away.
Starting point is 00:11:19 The liquidity is always there because Alice is paying for it. Another idea that's in the design is the way coin swaps work is they have two of two multisigs and they they would be a bit more obvious on the blockchain. Like there are some two of two multisigs on the blockchain but most people use single sig and there's a technology which didn't exist back in 2013 called multi-party ecdsa computation and that's a technique where you can you essentially create a um a single signature like a single ecdsa signature but actually it's a multi-sig
Starting point is 00:11:55 so actually alice and bob hold one private key each and it acts like a multi-sig but when it's actually mined into a block on the blockchain it looks just like a single sig and that would massively improve the anonymity because there's like most people use single six and then these Coinswap would just have a big anonymity set. So yeah, those are the building blocks. What were they? The multi-transactions, the routing, liquidity markets, and multi-party ECDSA computation.
Starting point is 00:12:26 And PaySwap, right? I think that's what you called it. Yeah, yeah, that's right. I forgot about that. So another thing is you can do a PaySwap, a coin join into a Coinswap. So Coinswaps break the transaction graph heuristics and pay joins break the common input ownership heuristic.
Starting point is 00:12:47 So I don't know how, maybe I'll explain that for your listeners, that a transaction graph is just that idea that if a coin goes from A to B, then it actually went from A to B. And yeah, coin swap would make the coin end up in Z. And the common input ownership heuristic is this idea that if there's a transaction on Bitcoin, it has multiple inputs, then you, like an adversary, anyone analyzing the blockchain usually assumes that all the inputs are in by the same person and this assumption is broken in coin
Starting point is 00:13:14 join in page or in any other kind of coin join uh so and those two assumptions are really important for analysis and if we can break them then we gain a lot of privacy all right so diving more into like the the actual function of how the swap works so you said alice and bob each have a private key that controls the multi-sig how do they do the exchanging of the addresses that they're each sending their coins to how does that work out uh so right so yeah so how coinswap actually technically work it's it's not too far from lightning so if you understand lightning how payment channels work then coinswap isn't too different so you have alice um has coins and she sends them to a two of two multisig where alice and bob each hold one private key but before she
Starting point is 00:14:01 actually broadcasts the transaction she gets a refund she gets another transaction which spends spends from the multisig and it gives the coins back to her but those coins have a they have a smart contract they have conditions on them and that that smart contract is either the coins go back to alice after some time like three days say or the coins will go to bob if bob reveals a hash pre-image if he reveals a value x such that hash of x is equal to this thing in the transaction and then Bob does has the same setup but mirrored so Bob will send his coins to a two for two multisig and he has a similar contract where um after some time he'll get his money back or Alice will get the money if she reveals a hash pre-image um so okay so what's happened there we're in a
Starting point is 00:14:49 situation where Alice and Bob both get their money back if they wait for a timeout or the other person gets the money like the coins are swapped if they know the pre-image um so we're in that situation now let's say the pre-image is revealed one of the say bob starts with and he reveals it that means both parties will get their money back straight away they just reveal a pre-image and they get it they don't have to trust anyone else it so you could say the money is basically in their possession like the smart contract is filled what they do next because they want to save time and they want to save minor fees instead of actually making the transaction they just give private keys to each other. What happens then is Alice has her coins in a two-of-two multisig
Starting point is 00:15:29 where she has both the private keys and Bob has his coins in a two-of-two multisig where he has both the private keys. So in that way we just have this situation where the coins are swapped but there's no trust involved. Alice can't steal Bob's coins and Bob can't steal Alice's coins. In the same way as Coinjoin. Coinjoin is also non-custodial, you can never use your coins doing it if it's correctly implemented so by analogy of lightning if you could understand this
Starting point is 00:15:59 that it's as if Alice opened the channel with Bob and then pushed all her money in the payment channel to Bob and then they did a cooperative close to send the money to Bob exactly at the same time Bob opened the channel of Alice pushed all his money in the channel to Alice and then they closed the channel and they did this at the same
Starting point is 00:16:15 time so that they can't steal from each other and so yeah i agree that's clear if this is no it's very clear this but one thing to sort of really just like hone in on why this is uh a different solution to coin joining and lightning in general like why would somebody create this setup instead of just like a lightning channel yeah that's a great question and it's a big reason why it's been so long since 2013 why people realize this is useful. So I think the biggest difference is Coinswap is inherently on-chain.
Starting point is 00:16:53 If you want to pay someone with Lightning, they have to actually use Lightning. They have to give you a Lightning invoice. But if you want to pay someone with a Coinswap transaction, you just pay to a regular Bitcoin address. So anyone who accepts Bitcoin today on a Bitcoin address will accept Coinswap. So it means once the software is written,
Starting point is 00:17:09 it can be adopted unilaterally. So any, I don't know, an exchange or some kind of any merchant who accepts Bitcoin, they'll just take coin swaps with no, there's no way they can censor it. There's no way they could stop it in the way that they could. They could, in theory, just say, okay, we're not going to accept Lightning
Starting point is 00:17:27 because we think it's too private. That won't be possible if coin swapped. Another difference is that coin swap and Lightning solve their liquidity issues in a different way. So in Lightning, these channels are open for forever, essentially, and they have uh there there's all kind of issues of inbound liquidity and channel rebalancing that you can only send an amount of money that is actually that there's a valid route all the way to the person you want to send to and that generally means it's limited to small amounts
Starting point is 00:17:55 but with coin swap it has this liquidity market that's like coin join where alice pays coin swap fees straight away up front it means she could do any amount um because the liquidity is always there like the liquidity will be paid for straight away um so the example i've been using is in join market right now you can or anyone can create coin joins up to 200 bitcoins like it's a ridiculously big value uh and it you know it costs a few thousand satoshis or something uh and we can imagine we can expect the same thing you'll have with coin swap that people could do any amount of do a coin swap for any bitcoin amount if they wanted so that's another difference is that they deal with liquidity in a different way
Starting point is 00:18:35 Another difference is, oh, I forgot to mention it, in the design there's this idea of fidelity bonds and that's a way of, that solves a few different problems, but one of the problems it solves is Sybil attacks. So in join markets or in coin swap or in any kind of privacy solution, you could have an attack when an adversary makes lots lots of fake bots makes lots of fake other people who pretend they want to do pretend they want to improve their privacy but actually try and spy on everyone else and if if you're doing a coin during a coin swap and everyone else in your coin during is actually one person they can spy on you and fidelity bonds are a way to avoid this um where they
Starting point is 00:19:23 you can you can do the mathematics of it and it would actually cost like loads of money like like millions of dollars would have to be locked up for a Sibyl attack to be successful. And Coinswap would have, like, my design would use Fidelity bonds to make these Sibyl attacks very expensive, and Lightning, I mean, Lightning doesn't need to do this. It doesn't, you know, Lightning's purpose is to have these payments. Like, it's not aiming to solve Sibyl attacks,
Starting point is 00:19:48 but that's another difference between them. Basically, like, the Fidelity bond idea makes it so you have this in join market let's talk about join market in case of fidelity bonds because it exists already um you have these makers that are posting these open offers to to coin join your funds with um and it becomes cheaper for you to have all of your funds in a single maker instance than to spread it out right the way the math works out yeah that's right so these makers they they essentially have a message an announcement that says you can create a coin join with me up to this amount of bitcoins i have and it will only cost you i know 0.1 percent
Starting point is 00:20:30 whatever some number i'm just making up that um and that means anyone can create a coin join like for cheap they just pay for the liquidity but an attack there is that an adversary could make loads of these bots they can make 10 bots or 20 bots and they all say you can make a coin join with me for really cheap and if you're unlucky enough to choose one of those 10 bots to make your coin joins and all they make up everyone else in your coin join except for you then they can spy on you easily because they know the inputs and the outputs. And fidelity bonds, what they are is they're a way to provably sacrifice value. So what these makers would do is they'd send their Bitcoins to a time-locked address.
Starting point is 00:21:06 Bitcoins would be, I don't know, say locked up for one year. And the value of the fidelity bond goes as squared, so v squared. So if the maker sacrifices 10 Bitcoins, their value will be 10 times 10, which is 100. But if they sacrificed 20 bitcoins, it would be 20 times 20, which is 400, right? So they have an incentive to lump all their coins that they want to sacrifice into one bot. And it means if someone wants to attack the system, if they want to create 10 bots, then it will cost them much more because this effect of squaring, to make 10 bots, all of those
Starting point is 00:21:45 things will be reduced by a square factor. Like, for example, if they had 10 bitcoins they want to sacrifice, if they put it all into one bot, their value would be 10 times 10, which is 100. But if they split up those 10 bitcoins into 10 bots, which had one bitcoin each, the value would be 1 squared plus 1 squared plus 1 squared, all the way to 10.
Starting point is 00:22:06 So the total value would be 10 instead of 100, which means someone who's behaving honestly, who just wants to earn money without spying on anyone else, are going to have a huge advantage, because their fidelity bond value is 100 bitcoins and this Sybil attacker's fidelity bond value is only 10. Yeah, that's the way the math works to make fidelity bonds really expensive to do.
Starting point is 00:22:29 No, and it's beautiful too because the way it disincentivizes Sybil attacks, it also incentivizes long-term holders to engage in fidelity bonds because... Yeah, because they're not going to spend their coins anyway. If they were just sitting in a hardware wallet doing nothing, you may as well put it in this so there's lots of coins out there i i assume um to do this better privacy arguably makes bitcoin as a network overall more more valuable too so yeah locking
Starting point is 00:22:58 yeah and you get money for doing it like you you don't have to risk your if you're like a hodler you you don't have to risk your bitcoins you always have the private keys but you'd make a small amount of coin join fees or coin swap fees just coming in like uh like for just for running this server. It's a bit like in Lightning routing. You get paid to route other people's transactions. That kind of thing. You get money for not risking your Bitcoins,
Starting point is 00:23:23 which is nice. Another thing that I should mention that Fidelity Bonds solve is the old coin swap design from 2013 had a DOS problem, like an issue where Alice and Bob what could happen is Alice would send her coins
Starting point is 00:23:39 into the multisig and Bob could just disappear if he was trying to troll if he was trying to attack the system he could disappear and okay alice would get her money back but she'd have to waste minor fees and she'd have to waste time uh and if bob if bob could keep doing this like he could okay i disappeared once and then this time i really really will do a coin swap bow i've disappeared again if he does that indefinitely it would just make the system stop working and fidelity bonds are also a solution for this because if suppose bob is this attacker if he has a he'll need a fidelity bond for alice to coin swap with
Starting point is 00:24:12 him but if he does disappear then alice would just refuse to coin swap with him again with that fidelity bond and it would mean someone attacking the system in this way would also have to spend lots of money so there's that problem of who goes first who actually puts their money into a multi first um they'd be vulnerable to this attack and the fidelity bonds can solve that so that is would that be more like a ddos attack yeah yeah exactly a dos attack denial of service and if you notice in lightning they solve it in a different way that what happens generally in lightning is people with wallets they open a channel to someone like you might have a wallet on
Starting point is 00:24:51 your phone you open a channel to some merchant the merchant isn't putting up any money normally they just accept your channel and if you send money to them that's great but if not that's also fine aren't wasted any money and that's also kind of why it can be hard to get inbound liquidity because for you to get inbound liquidity someone has to open a channel to you and put their own money in the channel and if you disappeared like they could be thinking if this person disappears i'm gonna i'm gonna just waste minor fees for nothing
Starting point is 00:25:18 um so that that comes into the liquidity thing as well but fidelity bonds and liquidity work together in that way um yeah but potentially enlightening i've seen on the mailing list there are a few ideas for some maybe having some kind of liquidity market so people can buy inbound liquidity um but i don't know i haven't been too much into this so yeah oh so from my understanding of the spec i mean this seems like it's strictly better than coin join and i'm trying to understand if i'm missing something here like if you're successful with this coin swap implementation um would there be any reason for someone to use
Starting point is 00:26:00 join market or does does that does that usage just move over to coin swap yeah i think i hope that it would move over to coin swap i don't um there's no as far as i can see it's better in every way so the transactions are actually invisible the coin swap transactions look like regular transactions and join market transactions are really obvious they have all the equal amounts uh they also use much more block space like join market transactions one of them is it's maybe about 10 times bigger than a regular transaction and also people don't do just one you do coin joins it again and again and again so it costs loads of minor fees there's yeah there's all kinds of advantages uh the only advantage to coin join uh that i can see is that
Starting point is 00:26:43 in coin swap it takes a little bit longer so you have to broadcast this transaction wait for it to be confirmed and once it once it's confirmed that this contract is safe to do but with coin join you don't have to wait for any confirmations you just talk to these other people doing a coin join with and you create the conjuring and broadcast it and once it's confirmed that's that so in that way coin join could be a bit faster however there is i was thinking about this like imagining suppose you're a bitcoin user and you want to trade bitcoins real life in person for cash a thing you could do with coin swap is you send your coins into a coin swap the contract first before you actually meet anyone and once the the thing is confirmed you can go and meet
Starting point is 00:27:26 the person and you get the cash and then only then you make the next transaction like the settlement transaction and you have to wait anything will be broadcast straight away and once it's confirmed then the the cash is transferred so i think in practice it won't actually be too this slowness thing won't be too much of a problem so and so let's dive into like the on-chain heuristics that are currently used to attempt to de-anonymize people. One thing we talk a lot about,
Starting point is 00:27:56 Matt and I are just shooting the shit. Is there a threshold at which a number of people coin joining would provide a sufficient amount of privacy for the rest of the network just by
Starting point is 00:28:12 destroying heuristics that chain surveillance companies use? It seems like, and with equal inputs and coin joins it's pretty easy to pick them out on chain and it seems like the way coin swap works just because it's 202 or 203 multi-sig it makes it much harder to follow these heuristic that chain surveillance companies use because again you have to assume that it isn't a coin swap so is this threshold for like proceed better privacy for the rest of the network extremely low once coin swaps implemented yeah that's an interesting question like how much
Starting point is 00:28:50 percentage of people do you need using something like this to make all the heuristics stop working and i can't imagine it's very high like suppose we said five percent that means one in every 20 it means one in every 20 transactions actually breaks the heuristic and that seems like it could be enough but another thing we might need is that they need to be these by the way this also applies to pay join uh like when people are pay joining with a merchant that would also work but a thing that would need to be there is these transactions probably have to be quite equal throughout the economy so you could imagine if i don't know if there's some traders who only ever transact to exchanges and if they never use any of this tech and then there's
Starting point is 00:29:28 some other you know say people who do online gambling if they always use this tech then you could you could imagine it will only break the heuristic in the gambling point of view and you know the gambling sector of the economy and never in the exchanges so you'd probably want the entire economy or loads of it to to use this technology and not just one part yeah i guess that's a good segue into what would incentivize these exchanges to do so i know bull bitcoin is the only exchange up in canada that i can think of that actually coin joins for their users um before sending funds out is there any economic advantage to doing this for exchanges that would incentivize Only if their customers demand it, I guess.
Starting point is 00:30:10 But they, I don't know if you saw, there was a recent article just yesterday by Rusty Russell, who was making the point that loads of these exchanges just make their money from pumping shit coins, like telling their customers to buy altcoins. And then they're not so interested in privacy or anything like that. So for me, that seems kind of grim.
Starting point is 00:30:31 I don't think exchanges are really our, they're not our friends. It's just they're not, they have other things to think about. they're trying to make a profit or whatever so users if they're interested I have to do it themselves and that then it's useful point up how it can be adopted unilaterally but if you have a wallet which supports these coin swap transactions you just send to an exchange and they don't have to change
Starting point is 00:30:54 anything they don't have to even know you're doing it update anything and it just works in a way that it doesn't work with lightning with lightning the exchange you make a lightning wallet probably will you know might the next has a lightning wallet but it might take a while they might not do it and who knows yeah we saw uh we saw the downfalls of these exchanges or one exchange particularly focusing on shit coins yesterday when you have like a five percent pipe price pop and coinbase just completely uh yeah shuts down because they can't handle it because they haven't fixed their exchange because they've been focused on adding shit coins the other thing is i mean it's it'll be a lot more difficult for
Starting point is 00:31:40 exchanges to to flag deposits that are coin swap it appears than if they were with flagging coin joins it's pretty obvious on chain yeah the equal amounts really give it away and yeah that's definitely another advantage yeah because you wouldn't be able to know if somebody is sending it from a coin swap or say a block stream green wallet all right because that's what yeah uses 202. the hope is that we because yeah because you're saying if block stream green uses multisig but the hope is that these coin swap uh the the you know the solution it would use multi-party computer ecdsa computation so nobody would even know that it's a multisig it'll just look like a single sick and then nothing then as if you design it properly then nothing really would
Starting point is 00:32:26 to give it away that's the hope so how far along are you in actually writing out the code that'll it'll make this implementation functional uh right now i'm kind of designing the exact details of how the contracts should work and all the step by step of like first alice makes a connection to bob and then asks bob for one of his public keys and then alice makes this transaction then they wait like There's all of those steps which you have to kind of write to make it work, and then I'll start coding. Also, I've got a plan to do it in, I mean, maybe it'll happen, maybe not, to do it in Rust, because it seems there's advantages
Starting point is 00:33:08 to that language, and so I've been learning a bit of Rust right now. And one good thing about that is this would be nice if it was a library that can be easily incorporated into other wallets. So it's not like there's a whole wallet which is called the Coinswap wallet. It's just that any other wallet, Electrum or Dockstream Green, anything like that, they could take a library, which would be compiled, which Rust can do, and then the user would see a checkbox, and they'd turn on Coinswap or turn off Coinswap.
Starting point is 00:33:35 And once it's turned on, then the wallet pulls the library, and a Coinswap just happens. And that would be great. And then it would be really usable. People just use the same wallets they already use. Yeah, that would be huge. and that's one topic of conversation we actually had last week is the sort of standardization of these wallet softwares across the industry.
Starting point is 00:33:59 That's something that's been a bit of a pain in the ass up to this point is different wallet creators using different software and being incompatible with each other. So standardizing this out of the gate would be awesome. Or even non-privacy things like seed phrases. Excuse me? even non-privacy things are not standardized across wallets like seed phrases the electrum has a different seed phrase to hardware wallets or something like that yeah it's what a bitcoin
Starting point is 00:34:30 bitcoin recovery wall wallace recovery.com what's yeah that's right database of all of them well you know that old joke of uh the great thing about standards is there's so many of them right and especially when you start throwing in like the hardware wallets compared to the software and paper wallets it's and then the lnd light wallet has a another seed phrase which has a wallet birthday it's a nice feature but then no other wallet has it i think ultimately the only thing the network enforces is that the transaction format will be the same and everything else could change yeah um one thing we didn't touch on here uh which i kind of just blurted out uh is is like wallet fingerprinting right so when we're
Starting point is 00:35:14 talking about stuff like pay swap and coin swap uh providing basically cover for other people's transactions if their wallet is is very obvious in in these unique characteristics that allow you to fingerprint that they're using a certain wallet then those transactions don't get any cover from from these type of techniques right yeah that's right that they bitcoin transactions have a lot of uh they have some data in them like there's end sequence numbers and whether rbf is enabled or disabled or uh the end lock time like there's a there's a wiki page on it there's loads of things that you can edit in a transaction and probably um it'll be something i do eventually for coin swap is analyze a lot of wallets like electrum and blockstream green and all that things and
Starting point is 00:35:59 try and figure out exactly what they do i mean i didn't invent i think um i saw this in some of a podcast i think but then you have these the coin swap wallets or any other wallets say 10 of the time behaves intentionally like electrum and then 20 of the time behaves like some other wallets and then 30 of the time behaves like bitcoin core um and then uh then that should hopefully that that should be a way to work around this fingerprinting thing because that's also done outside of bitcoin i've read it's done with browser fingerprinting you know browsers have different things like whether javascript's enabled or disabled what your operating system is your browser version your screen size uh and then i've heard of some idea for writing a privacy browser
Starting point is 00:36:43 which fakes those fakes those um those features but in a different way so it says like now i'm going to pretend to be linux this version with this screen size and then a bit later it says now i'll pretend to be mac with this version and this screen size so i do the same kind of thing there's a lot of controversy with that with the tor browser right because the tor browser tries to normalize all those things among all of their users in terms of screen size is one of the big things. But because they do that, it's easier to spot when someone's using Tor browsers specifically.
Starting point is 00:37:17 Yeah, that's right. But I think the thing with Tor is it's obvious if you're using Tor because if you go through a Tor exit node, then your IP address will be on the list of Tor exit nodes. And if you're going to an Onion address, then obviously you can only use Tor with those. So Tor doesn't have the property that you can hide that you're actually using Tor
Starting point is 00:37:37 in a way that Coinswap or Payjoin does. So fascinating how many variables go into protecting privacy on the internet with Bitcoin. Every leak adds up. Right. Transaction broadcasting, trying to delay that, is one aspect. the p2p network how you how your node connects and relays those transactions there's so many
Starting point is 00:38:05 variables that go into play and you've been around bitcoin for quite a while building software on top of it and aiming towards creating better privacy how how's privacy evolved since you've been around and do you think it's getting better do you think we're in a race against time absolutely getting better like i remember when uh so you know we have this we have this kind of you know obvious thing that to have really good privacy you basically have to use a full mode or you have to use something which downloads every single block and then scans it on like locally to find your addresses and and if you if you do it another way like with an electrum server or or something else like that then uh then the server will figure out what your addresses are so this realization was
Starting point is 00:38:48 as far as i could tell completely unknown back when i started just no one even realized that's a thing like people are thinking about coin joins or or or that kind of thing and there was um i don't remember finding anywhere maybe there was somewhere but I didn't see it that people were realizing that hold on we need full nodes if you want to have privacy so just from that like that's just one example of the huge progress I think we've made
Starting point is 00:39:11 in this few years yeah so are you confident in the ability for Bitcoin to provide sufficient fungibility and privacy for all users in the future because this is like are the Monero stands
Starting point is 00:39:26 I'm in the business of That's what I'm in the business of doing, but it's hard, you know, it's you Whatever, you know, I'm sure people invent stuff There's a thing right now that as far as I can tell there's no real way to have a lightweight private wallet synchronization So we know wasabi wallet that uses those client-side block filters where there's these filters and then you only download the blocks that are related To you, but that's actually not very lightweight. So if you did that where Bitcoin Core has some code which does it and those filters for the whole blockchain they add up to a huge amount of data like four gigabytes or five
Starting point is 00:40:01 gigabytes and that's not if you had a wallet we had to download four gigabytes it's not really a lightweight wallet it's huge and the reason wasabi gets around that is their filters only contain BESH32 addresses so the filters are much smaller because those addresses are quite rare on the blockchain but those filters wouldn't work for lightweight wallets if they had all the kinds of addresses, DTSH addresses. And we want to see batch 32 usage go up, too. Yeah, exactly.
Starting point is 00:40:27 As usage goes up, those filters will get bigger, too. So right now, there's no real solution for lightweight wallet sync. But, you know, maybe one of the listeners can invent one, right? It's all progress goes incrementally, doesn't it? Yeah, no, that's one thing I say a lot. Like, everybody wants this stuff out of the box right away. It just doesn't happen that way. especially the way bitcoin was designed at launch it's going to take time and luckily people like
Starting point is 00:40:54 you are focused on this and bringing software to market that that does make it better um that gets us to a point where the should have used monero fans uh shut up at some point even monero isn't that great like i sometimes rant a lot about this because there's like loads of privacy problems with monero no i mean not loads but it's obviously better than bitcoin if it didn't have of CoinJuin and stuff, but there's a thing you can do with Monero if you make repeated transactions. So Monero has those decoys, doesn't it? It takes the decoy transaction inputs
Starting point is 00:41:27 and adds them to your transaction, makes a ring signature so nobody can tell which are the real inputs. So that's only if you take one transaction in isolation. If you did 10 transactions, so if you had a Monero, say someone accepting donations in Monero and you made 10 donations to them, you know 10 of their inputs. And when they go to later spend them,
Starting point is 00:41:45 you have much more information. Maybe easier if I drew it, but you can do an intersection. You can figure out, because you have 10 or 20 or however many times you paid them, you have much more information you can use to take away their decoys. That's to talk about it. Maybe I can link it or something.
Starting point is 00:42:04 But it's interesting that even Monaro, like Monaro is better, but there's still a tax you can do. And the other thing you talk about is the scalability is way, way lower. so I've done a calculation that if Monero was doing the same amount of transactions that Bitcoin's doing today then the full nodes would not be possible
Starting point is 00:42:21 to run on a regular desktop it would just use too much CPU so something like Monero is inherently limited like yeah you'll get better privacy but what's the point if a thousand times less people use it yeah and you expanded on this topic with Stefan when you were on his podcast
Starting point is 00:42:37 recently so go check that out if you have freaks but But one thing in relation to Coinswap that we haven't touched on yet, a couple of things actually, is how does it affect, like how expensive are the fees? And if there's a lot of transactions, how does it affect fees? And then moving forward, let's say something like Schnorr
Starting point is 00:43:02 and then Taproot gets implemented, does this change the implementation at all? No, that's a good question. So the fees, so obviously it's a bit more expensive than just doing a regular transaction because they're as cheap as they can be. They have a size. But coin swaps would be much cheaper
Starting point is 00:43:19 for the same amount of privacy than equal output coin joins. So for example, in join market, one coin join is about 10 times the size of a regular transaction. And users don't just do one coin join. So the join market Tumblr script, by default, there's about 10 coin joins.
Starting point is 00:43:37 And each of those transactions are huge. So it's already using a huge amount of block space there. And the privacy isn't even as good as what Coinswap, how good Coinswap would be. So if you work out on a per-privacy basis how much minor fees you need to spend to get a certain amount of privacy, then Coinswap comes out ahead.
Starting point is 00:43:55 And another benefit of Coinswap is because it's indistinguishable from all the other transactions. It means if you really want to cheap out one day and just make a regular Bitcoin transaction, your privacy will be improved anyway because someone who was analyzing this would say, hold on, maybe he's doing a coin swap.
Starting point is 00:44:11 Maybe he isn't. We don't know. And that kind of externality, that benefit doesn't happen with equal output coin joins. So yes, overall, they'd improved efficiency for minor fees and block space. And as for Schnorr and Taproot... Oh, sorry. Sorry, carry on.
Starting point is 00:44:30 No, you continue. I forgot about that part of the question. So as for Schnorr and Taproot, So there is a thing, so you can use Schnorr with MuSig to also make two of two multi-sigs that look exactly like a single-sig, and there was an idea where we could use that instead of multi-party computation, UCDSA, but in the beginning, there wouldn't actually be much Schnorr being used out there. So we know with Segwit, it's been three years since Segwit was adopted, and maybe 60% of
Starting point is 00:45:01 transactions use it. I think I saw a statistic the other day. And Segwit has a huge incentive to actually adopt it because you get cheaper minor fees by adopting it and still only 60% of people adopted it after three years. And Schnorr doesn't have such an incentive. If you use single-sig Segwit transactions and you adopt Schnorr, then your minor fees cost the same.
Starting point is 00:45:22 There's no incentive to adopt it financially. So in that way, you can expect adoption to be even slower. and that means we'd be we may as well use multi-party you may as well use ecdsa for coin swap for now and that that has a nice that has a benefit in that coin coin swap doesn't need any soft forks to make it happen there's no way to stop it like you can't oppose the soft fork and then that would stop coin swap somehow but it couldn't happen today yeah that's nice to know So if people do adopt Schnorr in mass, it would be easy to just implement it with music. Yeah, but realistically, I think it will take a while.
Starting point is 00:46:05 People who use multisig will probably adopt it first because they do have an incentive. But if you're using single-sig, then there's no incentive. Matt, did you have a question? Oh, yeah. So with CoinJoin right now, we have JoinMarket that does, where you have this maker-taker model, you have this, it's a decentralized model. And then we have these centralized coordinator models with Whirlpool and Wasabi. And with those models, you don't have to worry as much about two things, the communication
Starting point is 00:46:46 channel between um the parties involved in the transaction and the the issue with fidelity using fidelity bonds basically uh like the the civil attack protection using fidelity bonds um and the denial of service in in a way right so do you do you expect and recently no power made a comment uh the lead dev at wasabi made a comment in regards to he seemed confused about the purpose of fidelity bonds to me um if do you do you envision that we'll see these these decentralized coordinator projects pivot to a coin swap type of situation uh where where they they run a centralized coordinator that that manages the coin swaps and in that situation they there's no need for fidelity bonds right okay so um so the purpose of fidelity bonds
Starting point is 00:47:43 are useful when there's a decentralized system where anyone can be a Sybil attacker. So you could just have Chainalysis or someone runs loads of bots to do a Sybil attack. And in a centralized system, that can't happen. Chainalysis or any adversary, they cannot become a Sybil attacker
Starting point is 00:47:59 on Wasabi's or Samurai's coordinator. However, because they're centralized, then Wasabi and Samurai themselves can be the Sybil attacker. And they could do it in a much easier way than is required in JoinMarket because to do a Sybil attack in join market you literally have to have 10 or 100 bots
Starting point is 00:48:16 but to do a Sybil attack in Wasabi the Wasabi server just has to exclude everyone else except for you like I don't know maybe they have a court order that says if this transaction output does a coin join then you have to exclude everyone else and just have your own your own inputs
Starting point is 00:48:32 be that coin join and then this court ordered transaction I think they're doing a coin join but actually they've been Sybil attacked and these centralized coordinators can do that for free like there's nothing technically stopping them right i mean it's not to say they're not useful but they but that's like you know that's the trust model there's there's trade-offs like those benefits it even goes further than fidelity bonds it won't help them uh because they it can't help them they only work it's only useful in a
Starting point is 00:49:00 decentralized setting as for whether they had a job sorry carry on i'm sorry i'm sorry i i'm just very excited this is a great chat um i i just it even goes further than that because the sybil resistance is the fee that's paid to the centralized coordinator so who's ever running the centralized coordinator doesn't have to pay that fee so they don't even have to necessarily exclude transactions uh they they could just sybil like crazy without ever really they just pay minor fee yeah yeah um yeah that's right so they like you could say if there's 10 people who want to do a coin join and in like the normal way in wasabi or samurai those 10 people make one coin join but actually if if the coordinator symbol attacks all them then there'd actually be 10
Starting point is 00:49:44 coin joins with one person one like real person per coin join and everyone else being a simple attacker and they learn all the same fees and they'd make the same money it's just the minor fees would be a bit higher and as for if they do coin swap um i haven't really thought i've been mostly interested in doing this in a decentralized setting because like i have the view that um to to have real privacy you need censorship resistance because otherwise the sensor could just censor you until you reveal your privacy relevant information so i haven't thought too much about doing quantum in a centralized way i suspect it's not i'm not that interested really but maybe maybe in future someone could figure out a way to do it right because there is a benefit to
Starting point is 00:50:25 to the Wasabi and Samurai way of doing things is they have an income. They can hire developers and make a really nice wallet that works really well and has all the features. There's some good things about centralization. I don't want to completely disregard it.
Starting point is 00:50:44 But it is less good at being private. And the communication channel, right? That is... So with Coinswap, is it going to use irc based communication again like with joy market i know i've been um that's part of the design i've been thinking probably the best way to do it is something similar to bisque where each maker makes
Starting point is 00:51:09 their own tour hidden service their own onion and then uh when a market taker comes along they connect to each of these onions and download their fees their coin swap fees and other information like the max Cointop size. And then Tor is by default encrypted and it's hidden where the actual service is. I think that's the best way because like JoinMarket today uses IRC and it's not that good.
Starting point is 00:51:33 Like, let's be honest, I made it right at the beginning and it's not very, I mean, it works, but it's a bit centralized. That's fascinating. And before we get any further, you are accepting donations
Starting point is 00:51:47 for this build out of your implementation, correct? Yeah, that's right. So it would be decentralized, and there's no way I or anyone else can collect fees to fund development. And development happens by donations. So I'll say the website I'm using now, which is bitcoinprivacy.me forward slash coinswap hyphen donations. And there people can find Bitcoin addresses that go to me if they want to support this work financially. And they can also review it technically if they're interested, if they have the skills. but I'm trying to make it like an open source
Starting point is 00:52:21 like something like Linux or Bitcoin Core itself where it can be a community thing and it could exist forever like if I ever lose interest then hopefully it will still be there and people can still use it to improve their privacy but for now I'm committed to making it a reality
Starting point is 00:52:36 Matt and I were admiring your donation site it's the best donation site I've seen to date you hit refresh you get a new you get a new address right away very clean straightforward pgb signed yeah yeah that's the stop the way it actually works if anyone like if anyone wants to make their own it's um i made many many bitcoin addresses from a from my xpub and then signed them with my pgp key on my own on my own hard drive and then uploaded
Starting point is 00:53:07 them all to the server and then there's just a simple php script which uh goes to a new one every time refresh is hit and then on my full node here in my home it just watches all those addresses when a donation arrives i was thinking of using btc pay server but i honestly i thought it would be more fun to do it myself i probably most people are better off using btc pay server but i did it this way i'm sorry i probably contributed to your need to jump forward a bunch of addresses because i was just hitting refresh that's okay there's a huge huge huge amount of them because they don't take much disk space like each address is a few it's like 500 kilobytes no sorry 500 bytes including the signature so if you you know most of these
Starting point is 00:53:52 hosting things give you like gigabytes into gigabytes you can fill the whole thing up for the addresses yeah they're basically infinite like you press f5 all you want there is you mentioned btz pay and i was talking to someone about this the other day that no one really discusses it uh And I also didn't really, I didn't think about it until this person brought it up because I was trying to get them to add BTC pay to their site. And they're a very security conscious person. There is a bit of a man in the middle risk there in terms of is the address shown actually controlled by the person you intend to donate to or pay? That you do get around by doing the PGP signed, right? Like I never really thought about it that way.
Starting point is 00:54:37 Yeah, that's true. Although I think a lot of people using BTC pay-per-server, they'll have HTTPS. And as long as you trust that whole system, which is more centralized than PGP, but that should, in theory, stop a man in the middle of the attack. I mean, that's how it works for when you buy things regularly, like on Amazon.
Starting point is 00:54:56 They all rely on HTTPS for their security. So in theory, it's okay, I guess. and it's while we're on the topic of btc pay i think it's a great example of an open source project that's garnered a lot of attention and and support from developers and even grant support from from companies and individuals so hopefully something similar will happen to your implementation yeah so are you are you looking for engineering help before you launch it or will you sort of launch it and then start accepting
Starting point is 00:55:34 PRs and yeah I think I'd be I'm looking for help in review that if people look at the design and if they see any attacks or anything like that they tell me and then as soon as I start writing code I'll I have that idea of release early and release often
Starting point is 00:55:50 so I'll make the like the minimum you know minimum minimum viable product that only works on testnet and put that on github and from there iterate and so hopefully people if they're interested they can read decode as early as possible. It was the same with join market. You can go back to years ago and find the very first testnet join market that worked.
Starting point is 00:56:11 Going through your GitHub here, I notice you have a fork of the user-activated soft fork. Were you maintaining a good implementation of that? I think I added a company that said they would use a UASF full mode on their, you know, to accept Bitcoins. I don't remember who. I think it was someone who, like, Bitrefill back then. They were quite new, and they were one of the people that did run UASF. And then I think there was a Voltero that they trade gold for Bitcoin.
Starting point is 00:56:50 I've forgotten exactly. It was a few years ago, but it was something like that. I could probably look at the GitHub and find out who I did. But no, I didn't run the site. I just went to PR. Yeah, that was an interesting time in Bitcoin. Right. Do you think we'll have as hard a time getting a soft fork implemented in the future?
Starting point is 00:57:08 Who knows? It's really hard to say. From one point of view, you could say that the victory with Segwit means that any other fights, there'll be no point in happening because the other side know they're going to lose but from the other side you could say well they still caused loads of drama and delayed segwit a bit so they might try again anyway um but i think there's a lot back then a good thing about now is many more enthusiasts are aware of how important full modes are and back in 2016 or so it was much less well known as it took it took by education and telling the community and a lot more people
Starting point is 00:57:46 know about that and there's more there's better technology as well easier ways to connect your wallet to your full node um so i think people will like because full nodes are so they're they i don't i mean part of the measure of course but i feel like they're more common and they're more aware there's more awareness how important they are then attacks which depend on their not being full nodes will be less successful hopefully yeah it's been great to see the proliferation of out of the box node hardware and better software uh things like raspi blitz yeah the noddle and actually i'm interested to get your thoughts on the bitcoin wallet tracker that was released last week you've you've worked a lot on electron personal server and that's been somewhat of
Starting point is 00:58:29 a pain in the ass for people who aren't as technically competent as others um this bitcoin wallet tracker that was released last week that's an electron plug-in that lets you connect to your full node what what are your thoughts on that like what are the trade-offs there and is it materially better no it sounds great to me like there's no i haven't granted i haven't spent much time um i haven't downloaded it or anything like that but uh share check and i talked a bit over irc and twitter and it seems really great like they uh and the idea of having it as a plugin is quite good um for me personally i always at least for the way i run it myself is i have a little raspberry pi which has the electrum personal server on it and then my electrum connects to that
Starting point is 00:59:13 and i don't know how that would work if you so does bitcoin wallet tracker i don't know if any of you have run it but does that mean you need the full mode on the same machine like this needs to be on your laptop where your wallet is if it runs with a plugin well you can do both but either way you can do both yeah it could be a drop in replacement for electrum personal server where you run it on a dedicated device, or you can just run core on your machine and BWT
Starting point is 00:59:40 and Electrum, and you're good. Okay, that's great then. It seems like the UX around running a full node and connecting to it and actually using it is getting considerably better as well. Yeah. I should tell
Starting point is 00:59:59 Shashank, but it's good to know anyway, that it would be good if If Tor broadcasting was added, you know this feature where when you click broadcast in Electrum, then the server can broadcast your transaction over Tor instead of using ClearNet, and that can be good for privacy so your IP address isn't leaked with broadcasting. Electrum personal server does this,
Starting point is 01:00:19 and it shouldn't be too hard to add to VWT. Yeah, that's what's been encouraging about the Node hardware. It's been coming out, too. it's just naturally been running through tor so hopefully stuff like that just makes that just common practice out of the gate yeah yeah and that would be great um what else are you excited about in the world of bitcoin or outside of bitcoin you've been working on this for for quite some time you mentioned you're into gaming what else uh what
Starting point is 01:00:51 else piques your interest i haven't actually played games for a few years to be honest um I mean, I know it's old news, but Lightning is just generally exciting. You can send a transaction basically instantly and for low fees, and I think that's really good, I guess. I don't know what else. I suppose I've been learning Rust,
Starting point is 01:01:14 and that's kind of exciting. Yeah, Rust. A lot of the devs I talk to, just the way they explain it, just like Rust is more powerful. That's what BWT was made with, right? Yeah, yeah, exactly. Yeah, and um, it's more it's aimed to be a safe. It's aimed to have inherent
Starting point is 01:01:33 inherently safety features so that it's impossible like the compiler won't allow you to do things like uh, And I have a memory leak or free null pointers or things like things that happen Things that you have to take care of in c plus plus and you don't in rust at least that's the idea I haven't learned it properly yet But it's a good thing to aim for yeah it seems just from what i can tell it seems like a a really strong language that you want to be building bitcoin software with at least should have implementations written in it yeah um what
Starting point is 01:02:08 are you guys interested in well uh i like to surf i write and talk and then uh outside of this i surf we're very interested in lightning as well we fawn over i use lightning every day i've been uh actually combining lightning and gaming the bitcoin uh bounty hunter game that allows you to put ads in their game and pay for them via lightning that's been like one of the coolest things that i've seen in the space recently so i've been i've been making sure our ads are sufficiently uh funded on that game um that and then i'd like to focus on the adoption side too and education side i think the education around bitcoin has gotten a lot better over the last three years particularly and i'm very interested to see if if bitcoin begins getting more attention
Starting point is 01:03:03 in the mainstream how well um new users will sort of understand the technology and the software available to them uh once they discover bitcoin and start using it for me i've kind of noticed I might not be very good at the explaining to noobs because it seems like I spend a lot of time on the technical details and then it's sometimes hard to dial that down when you talk to people who are new to this stuff. Like I've kind of noticed that with Coinsopper, I'm like, oh, you did this thing and it has a hash time contract and then I guess people would be like, oh, what is that? What's a hash?
Starting point is 01:03:40 Yeah, what's a hash? Yeah. I've experienced this too recently. I've been going on more. One thing I'm very interested in, it would be remiss of me not to mention, is I work for a company that we're mining as well, and we're using wasted energy to mine Bitcoin,
Starting point is 01:03:57 particularly on oil and gas fields here in the United States. And because of this, we've been getting some attention in the oil and gas industry here. So I've gone on a couple of oil and gas podcasts recently and have had this experience where they're completely new to Bitcoin and having to explain it to them when I've been writing to an audience of Bitcoiners and running this podcast with other Bitcoiners
Starting point is 01:04:19 really drives home, oh my gosh, you do need to dumb down some of these concepts and think about the beginner's road to understanding Bitcoin. It's a good thing for all of us to practice sometimes. Yeah, no, it's not. Yeah, I had that same experience there. like explaining like how does mining work and i was like uh how much do you know about hash cash
Starting point is 01:04:46 shot 256 proof of work like trying to explain difficulty adjustments and i got like a little off the rails but that's good like the the wasted energy because that energy is basically free isn't it like you yeah zero costs so then you just need the a6 and you get free money yeah it's so the the the ASICs and then the generators too actually consume the energy. Right. Yeah. Yeah. Because it doesn't come off as natural gas that you have to burn or something. Exactly. Yeah. So those, those are your,
Starting point is 01:05:23 what factor into your kilowatt per hour costs, but even, even so you're able to get it down pretty low with these, this wasted energy. Yeah. Yeah. What about you, Matt? What are you, what are you excited about right now? outside of coin swaps well i mean i love bitcoin bitcoin is fascinating people are fascinating love talking to people um i don't know privacy it's fucking massive i think we've been very focused here on education uh we have a long way to go but i i do think it's really
Starting point is 01:06:02 cool um how many people are focused on education that are in scammers which is his is what the in the past you know you you see people come in and they they go to youtube and they they buy the courses on blockchain and stuff like that um and you just really hate to see it uh but now you know you have like stefan lavera you have katan that works with him in ministry of nodes you have 6102 bitcoin there's like this whole sub-industry that's developing of a bitcoin education that really seems to be focusing on on the right principles um in terms of privacy i i think we're starting to it's you know i'm i'm fascinated by privacy not just on a bitcoin level um and i just think it's it's we're starting to hit a critical mass here where people are realizing
Starting point is 01:06:56 People are realizing why it's important because their privacy is getting trampled on left and right. Yeah, that's right. Yeah, it'll be interesting. I mean, another thing that's very interesting right now is the state of the world, geopolitics, China taking Hong Kong. Obviously, we got some interesting things happening here in the United States. like is bitcoin ready for uh not mass adoption but considerably more adoption in the face of people maybe needing to turn to it um that's another thing that i'm very curious to see like if if bitcoin does get a lot of attention soon like is the protocol ready to onboard a
Starting point is 01:07:38 bunch more people yeah that's right there's i don't know how well known this is but back in 2017 ish i was uh reading you know there's a reddit subreddit for the syrian civil war back then it was a big thing it was aleppo and damascus and all that stuff and i came across a couple of people who are actually trading bitcoin there because they it was for that it was because there was huge inflation in um in syria and they were trying they were just you know dollar cost averaging into bitcoin essentially and they had one of them mentioned this thing on reddit that a great thing of bitcoin is you can if you end up being a refugee because there's war and if you have to like go to turkey or something then you can take your bitcoins with you just memorize them
Starting point is 01:08:19 in your head um and like that that's kind of that's sort of what we're here for aren't we we're helping people one of the use cases we're helping people store their wealth if they need to you need to protect it from being seized yeah that was a real life example of it and there it was i was kind of surprised because i was um thinking maybe they're gonna you know do you need this explaining but they seem to just get it they're like you have a wallet and then you send it to this person and they give you cash and it just works once you need it it's pretty obvious i feel like yeah yeah yeah the hard part seems to be understanding what money is like you have this thing called bitcoin and it's like money and once you understand that then in theory it's just
Starting point is 01:09:01 clicking buttons right you click send you click receive write down a seed phrase hopefully it's crazy to see how how much utility bitcoin provides depending on your different use case you just described syrian escaping to turkey keeping a seed phrase in their in their head to escape um terrorist and a a dictatorship but then like i've talked with matt alborg who's doing a lot of research on how people are using it in venezuela and argentina trying to escape hyper inflation and using bitcoin as a rail to send money so that they can get dollars that's also yeah um that's the beauty of bitcoin it's just this apolitical messaging system and if you can download the software and interact with it you can participate and it doesn't know what you're
Starting point is 01:09:51 using it for or how you're using it or why you're using it just works that would be one one place where privacy is important because if you're suppose you have this syrian guy and you want across the border in Turkey, and they say, aha, we see your mobile phone data. Look, you've been using a Bitcoin wallet. Hand it over, son. You don't want to be in that situation. And that is actually one thing I'm concerned about
Starting point is 01:10:13 with how there's no solution for lightweight wallet sync. Like these wallets on people's smartphones, they all connect to some server and tell them their addresses. It's probably okay now. I'm sure the Turkish border guards can't do this, but in theory they could. in theory they could have something that scans
Starting point is 01:10:32 and figures out the internet service provider and figures out what your bitcoin addresses are that will probably happen one day if we're in early days and eventually the authorities or anyone who wants to steal your bitcoins will learn about this so that should be something we should fix
Starting point is 01:10:48 but either way on smartphones people can synchronize their wallets anonymously and I don't think that exists now would something like AB core help that? yeah possibly you could just have full nodes on a smartphone that could be one way, maybe smartphones
Starting point is 01:11:04 get powerful enough and bandwidth gets cheap enough and it could happen but I think there's a long way, like you need a few another few doublings of Moore's Law at least for bandwidth to make that really make that possible It'll be interesting to see how that plays out
Starting point is 01:11:22 that's another thing that I like to observe is how people extrapolate the current state of bitcoin and just technology in general and how how computers work extrapolate that to the future and sort of discount potential innovations and efficiencies that could happen um yeah a lot of linear thinking yeah but the thing with bitcoin is the blockchain is linear like every block you generally get new addresses that are mined into the blockchain and any wallets would have to synchronize them somehow
Starting point is 01:11:56 somehow figure out these are my addresses that come from my seed trays and I want to figure out if they have transactions on them and how do I do that? I don't know, we'll see. I'm just kind of thinking out loud here. I love that. Do you have any thoughts on Lightning as a privacy tech?
Starting point is 01:12:15 Oh yeah, it's great. This idea of not having your transaction on-chain is basically a revolution. All the things we talked about earlier, the transaction graph and the common input ownership heuristic and things like address reuse and change address detection they just don't exist in lightning there are no change addresses there are no there are no uh you know multiple inputs into a transaction uh it's all off chain okay there's other attacks but they just the fact that the the transactions aren't visible to everyone i
Starting point is 01:12:44 think is a huge help so yeah absolutely it's a great privacy tech somehow although it still still has the thing that the channels are on the blockchain, you could analyze someone figured out your channel because your Lightning Wallet also has to message a third-party server to figure out what your channel UTXOs are, then someone
Starting point is 01:13:05 could analyze based on that. We'll see how that goes. The building blocks are there to solve it somehow. Yeah, it shows promise is kind of my perspective. right especially on like the receiving side uh the privacy like it leaves a lot to be desired on the privacy front if you're receiving lightning transactions yeah it depends a lot of the stuff is with your threat model like you can i'm sometimes asked like if i do this will i be
Starting point is 01:13:39 private will i have enough privacy and then always the thing i answer is okay who you're actually hiding from like if you're if you're hiding from some whatever turkish border guard or someone who doesn't really there then you don't you know or just some looter then you won't yeah probably have to try too hard but if you're hiding from i know the united states government or something you have to try a lot harder and they because they the u.s government they have the power to presumably we believe to look at every internet packet out there which i know turkish border guard doesn't i think they just made a law here what what's that what does the law say they're trying to make it a law where they can get access to to all of your internet data
Starting point is 01:14:21 they have indiscriminate rights to to check your messages on social media and all that stuff yeah and the whole social media thing is a big privacy really like amazing people give away all that information just for nothing yeah that's that's another thing that sort of excites me about lightning this idea of ln url If we were able to, instead of giving username and passwords to companies that they then store on their own databases, which are highly susceptible to getting hacked, you have an authorization flow from a node that you control and public keys within that node. Your public key being signed by your private keys is basically authentication. Yeah, so you use your private key as a login. Yeah, that excites me as well.
Starting point is 01:15:14 sort of re-architecting that interaction between user and service provider on the internet would be huge. Yeah. Although I'm not sure. And yeah, like it's good for privacy that you don't have usernames and passwords, but there's still people like you go on Facebook and people upload pictures of themselves, which can be, can be sent to facial recognition algorithms and things like that. And that,
Starting point is 01:15:37 that wouldn't change if people don't use passwords anymore if they use a private key instead. no we say it many times in this on this podcast we're all face fucked yeah you're not doing it on social media there's so many cameras in the cities now that it's not even well then maybe with the tracking devices in our pockets yeah that's right although maybe one thing with the um with the pandemic is if more people wear face masks you must have heard of that wearing face masks can help break facial recognition well in america we have this weird phenomenon well at least before the rioting happened uh there was this weird phenomenon
Starting point is 01:16:15 where people were saying once face masks became basically mandatory at the state level uh it was an act of defiance not to wear a face mask which i thought was a really interesting um psychological experiment uh and i i said to marty i was like i wonder like if they mandated end-to-end encryption if people would just send plain text messages as like an act of defiance. Right. Right, yeah. It's funny how
Starting point is 01:16:46 psychology is sometimes. Right. I mean, and it's funny how that's an example of like mass hysteria coming into play. It's been a topic too, obviously with the riots.
Starting point is 01:17:01 People are being manipulated by the media and the governments to act in certain ways than they seem to be pretty easily manipulated these days. Yeah. What most people don't realize is in New York, since the 1800s, it's been illegal to be with more than two people with face masks on in public. Really?
Starting point is 01:17:23 Yeah, so this is like the first real protest we've had, in New York City at least, where you're legally allowed and actually compelled to wear face masks to the protests. It's an interesting thing to think about. Why was that? I suppose it was never enforced, this law. It was enforced selectively, just like all the good laws are. Yeah, just when you need an excuse.
Starting point is 01:17:50 Yeah, I've worn a face mask in New York City for 10 years. Never got stopped once. But I'm a white person and I wasn't doing specific things. that they decided to enforce it on yeah you weren't getting stopped and frisked not once um yeah there's so many so many things to think about but luckily luckily bitcoin exists i'd be a lot more pessimistic if bitcoin didn't exist and luckily we have people like you chris working to make this better and not only for yourself but for everybody and the work you're doing is extremely important and i'm very happy you're doing and i'm very appreciative of of all the
Starting point is 01:18:34 effort that you put into this yeah thanks for saying so that's uh i hope you yeah i hope you realize that people appreciate your work and it it's not does not go unnoticed very grateful yeah thank you um i want to be respectful of your time we we blocked off an hour and a half here coming to the end of that if you factor in our pre-conversation and what we've recorded already is there any parting notes final thoughts you you want to leave the freaks before we wrap up here well no i just for the coin swap thing that if you can review it technically uh then do that that would be appreciated and if you um want to support me with a donation that would be very helpful as well uh just those things really and you know think about how you think about your
Starting point is 01:19:24 privacy because it's a like it helps everyone should people go to your github to help review or they have to reach out personally no it's on the actual design the mailing list email that's the design that has all the
Starting point is 01:19:40 building blocks alright so go check that out we will link to the gist and your donation page in the show notes again Chris thank you for what you do really appreciate you taking some time to come explain this stuff too
Starting point is 01:19:56 anytime we should do this again hopefully when you get closer to actually releasing a workable implementation we can link up again and talk about how it actually works and get people using it yeah that sounds good anything from you Matt
Starting point is 01:20:14 yes please we'd love to have you back yeah sounds good anytime again have a good day you as well that's all we got this week freaks peace and love

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.