TFTC: A Bitcoin Podcast - #170: Chris Belcher
Episode Date: June 10, 2020Join Marty and Matt as they sit down with Chris Belcher, the developer behind JoinMarket and the first CoinSwap implementation, to discuss: - JoinMarket - Fidelity Bonds - Chain analysis heuristics - ...Chris' CoinSwap design - A "privacy threshold" - Why CoinSwaps are > CoinJoins - much more Follow Chris on Twitter Support Chris' work on a CoinSwap implementation here Shoutout to this week's sponsors. Cash App. Start #stackingsats today. Use the promo code: "stackingsats" to receive $10 and contribute $10 to OWLS Lacrosse when you download the app.
Transcript
Discussion (0)
What's up freaks, it's your boy Marty Bent here to introduce this episode of Tales from
the Crypt.
Matt and I had the immense pleasure of sitting down with Chris Belcher, the man behind Join
Market and the recent design implementation of Coinswap, which he is currently working
on and he is being supported by the Human Rights Foundation.
News just dropped a few minutes ago before recording this ad.
This news dropped after we recorded this episode, so we did not cover that.
in the episode but uh we did talk about dev funding towards the end and it is uh
very encouraging to see that the human rights foundation has stepped up and provided
chris with a grant to work on this coin swap implementation specifically so kudos to hrf
for putting the team on their back here this episode of tales from the crypt is brought to
by our good friends at the Cash App.
I hope you do many things.
I hope you stack sats, send sats, receive sats, sell sats,
if you so please.
On top of that, they're doing incredible things
on the banking front.
You can now use Cash App as your bank account.
It has an account number and a routing number.
You can start getting your paychecks direct deposited
into the Cash App, and it's becoming a neobank,
a new bank where you can uh send your paychecks there have them directly deposited start stacking
sats then also if you want to if you're if you're a stock picker out there seems to be a lot of
stock pickers out there these days stock market going crazy going mad and uh it's uh if you want
to do that cash app investing is letting you stack slivers of stocks okay you don't have to buy a
whole stock if uh your your favorite stock has become out of your reach to buy to purchase a
of that stock because of this crazy fed induced stock market bonanza you can buy as little as
one dollar via cash app investing because cash apps directly connected to your bank account or
like i described earlier it is your bank account there's no four to five day waiting periods you
can start investing today as always or before we get to the as always cash app investing is
a subsidiary of square remember sipc now as always when you download the app if you haven't done
done it yet if you're listening to this podcast you're in america you haven't done it yet
what the hell are you waiting for use the code stacking sats it's s-t-a-c-k-i-n-g-s-a-t-s
you're gonna get ten dollars upon sign up and then ten dollars gonna go to our great friends
at owls lacrosse in chicago doing incredible things uh in the west side and south side of
chicago building uh a lacrosse program to help instill leadership values and and teamwork into
the children of chicago owls lacrosse not owls lacrosse not that dirtbag owl owls
my uh my owl that sits outside my window he made a twitter account last night and so he's going to
be scoring these these owl calls from here on out so we'll see how i do uh download the cash app
enjoy this episode with chris belcher and congrats to chris for the grant from the hrf
huge uh huge huge news it's gonna make bitcoin better
you've had a dynamic where money's become freer than free
if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting
like safe haven i believe that in a world where central bankers are tripping over themselves to
devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean
that's part of the bull case for bitcoin if you're not paying attention you probably should be
what is up freaks welcome back to tales from the crypt it's your boy marty bent here
on a lovely tuesday afternoon uh despite all the madness going on in the world i'm very excited for
this conversation uh it's a privacy heavy conversation we're about to have this is a
topic that we talk a lot about here on tftc we've got matt odell with me the privacy
nut what's going on this is gonna be good i'm excited and and we're joined by chris belcher
who recently released a design implementation for a coin swap,
which is not a new idea, but the first implementation that's come to market.
And we're going to talk a lot about that.
Chris, thank you for joining us.
Hello there. Thanks for having me.
I really appreciate it.
You've taken some time to come talk about this.
We've talked about coin swap on this podcast last week after you dropped the implementation.
So I guess we should just dive right into it.
You and I have been talking since before this recording and have a little bit of structure laid out for this conversation, which isn't typical here on TFTC, but we're speaking to what I would deem somebody who's very knowledgeable in this space.
We're going to learn a lot about coin swaps.
So before we get into coin swaps, Chris, how did you get into Bitcoin and why are you focused on privacy?
uh well i've always liked coding and programming and uh cryptography i remember reading about pgp
and the crypto wars from ages and ages ago and uh it's actually kind of funny story when i was
quite young i used to be involved in uh there was an old video game i don't i think people still
play it called runescape and there was a thing where you could have in-game items and trade them
back then people trade for paypal and obviously that didn't work very well because we'll charge
back charge packs and you'd find out each other's real names and that kind of thing and um then when
i when i came across bitcoin i thought hey you know it's obvious it's really good for video
games right that's what it's for and then the more i got into it the more i read of how useful
it is for other reasons and uh i've always been interested in history so i thought yeah it would
be useful in you know the weiber republic in germany that kind of thing half money um yeah
I just went from there and I looked at what are the problems around Bitcoin and got interested in privacy and
Validation like the electron personal server is all about validation as well
Yeah, that's my story pretty much
Yeah, I mean, thank you for all the work that you've done to help
Improve personal validation and and privacy overall which join market specifically and now
coin swap at least your your implementation of a coin swap which you're still working on
correct yeah yeah it's in the design stages right now and so i guess let's let's help uh
the audience understand what a coin swap is when did the idea come to market and and how i guess
your design would work once once it's finally implemented so coin swap is i'll deal with those
things one by one a coin swap it's a privacy protocol so it's like like coin join but something
else uh the point of it is to improve privacy in bitcoin and fungibility and the way coin swaps
actually what they do is they break the transaction graph so you can imagine now when we look on the
blockchain and there's a transaction that spends uh money's going from address a to address b
coin swap can make it so that the coins like the actual ownership ends up on a totally different
address, address Z, address X, which is entirely unrelated.
And that's obviously really useful if you're using Coinswap,
but it's also useful for other people.
If there's some other user who's never even heard of Coinswap,
who just makes a normal transaction,
they'll have their privacy improved as well,
because anyone who wants to analyze the blockchain,
some kind of adversary, they'll always have to consider
that maybe they see this transaction, they think,
well, maybe a Coinswap happened.
So it will add a huge amount of doubt, I hope,
and will make their analysis much harder
and thereby improve privacy and fungibility.
So the way Coinswap is kind of...
What it works is there's two...
We've got Alice and Bob, like two entities,
and they swap coins with each other.
So Alice's coins end up with Bob,
and Bob's coins end up with Alice.
It's actually quite an old idea.
Like, it's from 2013.
It was invented by Greg Maxwell.
Around the same.
It was about a month or two after CoinJoin.
So what was the other thing you were saying?
Sorry, I forgot the rest of your question.
So how would your design work once implemented?
So coin swap, it's an old idea.
But it has loads of...
The original Greg Maxwell's design had loads of unsolved problems.
So my design is basically solving these problems one by one.
like it the the title is this coin swap but there's loads of other building blocks in there
that are necessary to me to really make it work well so for example in the original coin swap
scheme you had alice and bob would swap just one coin so alice would give 10 bitcoins to bob and
bob would give 10 bitcoins to alice and that means if there's an adversary who knows alice's 10
bitcoins she can this adversary can search the blockchain for somewhere else where there's 10
bitcoins and they'd find bob's 10 bitcoins then it'll be easy okay so these 10 bitcoins went here
Bitcoin went back. So the amount would be a privacy leak. So my solution to that and
the design is to have multi-transaction coin swaps. And that would be where Alice gives
10 Bitcoins to Bob and Bob gives multiple coins back to Alice. So he gives her like
two Bitcoins, three Bitcoins and five Bitcoins. And those three together add up to 10. And
then if our adversary is searching the entire blockchain, he'll never find one coin which
is worth 10 bitcoins uh so that attack will be will be fixed um another problem in the in the
original design is there's only two of these parties so even though someone observing the
blockchain doesn't know where the coins went bob does like if you're alice you have to trust bob
though but they're not that they're not going to spy on you um so in my design that's solved by
routing coin swaps so alice would do a coin swap with bob and then bob will do a coin swap with
and not someone else Charlie and Charlie will do a coin swap with Dennis and then Dennis will do a coin swap back to Alice
and then Alice would have her coins made anonymous and
All three of those those other parties Bob Charlie and Dennis they'd have to collude
If they wanted to figure out where all the coins actually went
So rooted coin swap kind of spreads out the trust in that way
then
Another thing in the design is having a liquidity market. So that's just like in join market
where Alice would pay for the coin swaps actually to happen.
So for these, Bob and Charlie and so on,
they'll just hang around, they'll run a server all day,
and they'll say, you can coin swap with me
and return for a small fee, like a future social or something.
It's exactly the same way it works in join markets.
But instead of coin joins, you get coin swaps.
And the effect there, it means that if you're Alice,
if you have a wallet, you can do a coin swap whenever you want.
You just press a button, and the coin swap for your amount
It doesn't have to be 10 Bitcoin, 0. whatever, any amount you want. It just happens straight away.
The liquidity is always there because Alice is paying for it.
Another idea that's in the design is
the way coin swaps work is they have two of two multisigs and they
they would be a
bit more obvious on the blockchain. Like there are some two of two multisigs on the blockchain
but most people use single sig and there's a technology which didn't exist back in
2013 called multi-party ecdsa computation and that's a technique where you can you essentially
create a um a single signature like a single ecdsa signature but actually it's a multi-sig
so actually alice and bob hold one private key each and it acts like a multi-sig but when it's
actually mined into a block on the blockchain it looks just like a single sig and that would
massively improve the anonymity because there's like most people use single six and then these
Coinswap would just have a big anonymity set.
So yeah, those are the building blocks.
What were they?
The multi-transactions, the routing, liquidity markets,
and multi-party ECDSA computation.
And PaySwap, right?
I think that's what you called it.
Yeah, yeah, that's right.
I forgot about that.
So another thing is you can do a PaySwap,
a coin join into a Coinswap.
So Coinswaps break the transaction graph heuristics
and pay joins break the common input ownership heuristic.
So I don't know how, maybe I'll explain that for your listeners,
that a transaction graph is just that idea that if a coin goes from A to B,
then it actually went from A to B.
And yeah, coin swap would make the coin end up in Z.
And the common input ownership heuristic is this idea that
if there's a transaction on Bitcoin, it has multiple inputs,
then you, like an adversary, anyone analyzing the blockchain
usually assumes that all the inputs are in by the same person and this assumption is broken in coin
join in page or in any other kind of coin join uh so and those two assumptions are really important
for analysis and if we can break them then we gain a lot of privacy all right so diving more
into like the the actual function of how the swap works so you said alice and bob each have a private
key that controls the multi-sig how do they do the exchanging of the addresses that they're each
sending their coins to how does that work out uh so right so yeah so how coinswap actually
technically work it's it's not too far from lightning so if you understand lightning
how payment channels work then coinswap isn't too different so you have alice um has coins and she
sends them to a two of two multisig where alice and bob each hold one private key but before she
actually broadcasts the transaction she gets a refund she gets another transaction which spends
spends from the multisig and it gives the coins back to her but those coins have a they have a
smart contract they have conditions on them and that that smart contract is either the coins go
back to alice after some time like three days say or the coins will go to bob if bob reveals a hash
pre-image if he reveals a value x such that hash of x is equal to this thing in the transaction
and then Bob does has the same setup but mirrored so Bob will send his coins to a two for two
multisig and he has a similar contract where um after some time he'll get his money back or Alice
will get the money if she reveals a hash pre-image um so okay so what's happened there we're in a
situation where Alice and Bob both get their money back if they wait for a timeout or the other
person gets the money like the coins are swapped if they know the pre-image um so we're in that
situation now let's say the pre-image is revealed one of the say bob starts with and he reveals it
that means both parties will get their money back straight away they just reveal a pre-image and
they get it they don't have to trust anyone else it so you could say the money is basically in
their possession like the smart contract is filled what they do next because they want to save time
and they want to save minor fees instead of actually making the transaction they just give
private keys to each other. What happens then is Alice has her coins in a two-of-two multisig
where she has both the private keys and Bob has his coins in a two-of-two multisig where he has
both the private keys. So in that way we just have this situation where the coins are swapped
but there's no trust involved. Alice can't steal Bob's coins and Bob can't steal Alice's coins.
In the same way as Coinjoin. Coinjoin is also non-custodial, you can never
use your coins doing it if it's correctly
implemented
so by analogy of lightning
if you could understand this
that it's as if Alice opened the channel
with Bob and then pushed all her money
in the payment channel to Bob and then
they did a cooperative close to send the money
to Bob exactly at the same time
Bob opened the channel of Alice pushed
all his money in the channel to Alice and then they closed the channel
and they did this at the same
time so that they can't steal from each other
and so yeah i agree that's clear if this is no it's very clear this but one thing
to sort of really just like hone in on why this is uh a different solution to coin joining and
lightning in general like why would somebody create this setup instead of just like a lightning
channel yeah that's a great question and it's a big reason why it's been so long since 2013
why people realize this is useful.
So I think the biggest difference is
Coinswap is inherently on-chain.
If you want to pay someone with Lightning,
they have to actually use Lightning.
They have to give you a Lightning invoice.
But if you want to pay someone with a Coinswap transaction,
you just pay to a regular Bitcoin address.
So anyone who accepts Bitcoin today
on a Bitcoin address will accept Coinswap.
So it means once the software is written,
it can be adopted unilaterally.
So any, I don't know, an exchange
or some kind of any merchant who accepts Bitcoin,
they'll just take coin swaps with no,
there's no way they can censor it.
There's no way they could stop it in the way that they could.
They could, in theory, just say,
okay, we're not going to accept Lightning
because we think it's too private.
That won't be possible if coin swapped.
Another difference is that coin swap and Lightning
solve their liquidity issues in a different way.
So in Lightning, these channels are open for forever, essentially,
and they have uh there there's all kind of issues of inbound liquidity and channel rebalancing that
you can only send an amount of money that is actually that there's a valid route all the way
to the person you want to send to and that generally means it's limited to small amounts
but with coin swap it has this liquidity market that's like coin join where
alice pays coin swap fees straight away up front it means she could do any amount um because the
liquidity is always there like the liquidity will be paid for straight away um so the example i've
been using is in join market right now you can or anyone can create coin joins up to 200 bitcoins
like it's a ridiculously big value uh and it you know it costs a few thousand satoshis or something
uh and we can imagine we can expect the same thing you'll have with coin swap that people could
do any amount of do a coin swap for any bitcoin amount if they wanted
so that's another difference is that they deal with liquidity in a different way
Another difference is, oh, I forgot to mention it, in the design there's this idea of fidelity
bonds and that's a way of, that solves a few different problems, but one of the problems
it solves is Sybil attacks.
So in join markets or in coin swap or in any kind of privacy solution, you could have an
attack when an adversary makes lots lots of fake bots makes lots of fake other people who pretend
they want to do pretend they want to improve their privacy but actually try and spy on everyone else
and if if you're doing a coin during a coin swap and everyone else in your coin during is actually
one person they can spy on you and fidelity bonds are a way to avoid this um where they
you can you can do the mathematics of it and it would actually cost like loads of money like
like millions of dollars would have to be locked up
for a Sibyl attack to be successful.
And Coinswap would have, like, my design would use Fidelity bonds
to make these Sibyl attacks very expensive,
and Lightning, I mean, Lightning doesn't need to do this.
It doesn't, you know, Lightning's purpose is to have these payments.
Like, it's not aiming to solve Sibyl attacks,
but that's another difference between them.
Basically, like, the Fidelity bond idea makes it so
you have this in join market let's talk about join market in case of fidelity bonds because
it exists already um you have these makers that are posting these open offers to to coin join
your funds with um and it becomes cheaper for you to have all of your funds in a single maker
instance than to spread it out right the way the math works out yeah that's right so these makers
they they essentially have a message an announcement that says you can create a coin
join with me up to this amount of bitcoins i have and it will only cost you i know 0.1 percent
whatever some number i'm just making up that um and that means anyone can create a coin join
like for cheap they just pay for the liquidity but an attack there is that an adversary could
make loads of these bots they can make 10 bots or 20 bots and they all say you can make a coin
join with me for really cheap and if you're unlucky enough to choose one of those 10 bots
to make your coin joins and all they make up everyone else in your coin join except for you
then they can spy on you easily because they know the inputs and the outputs.
And fidelity bonds, what they are is they're a way to provably sacrifice value.
So what these makers would do is they'd send their Bitcoins to a time-locked address.
Bitcoins would be, I don't know, say locked up for one year.
And the value of the fidelity bond goes as squared, so v squared.
So if the maker sacrifices 10 Bitcoins, their value will be 10 times 10, which is 100.
But if they sacrificed 20 bitcoins, it would be 20 times 20, which is 400, right?
So they have an incentive to lump all their coins that they want to sacrifice into one
bot.
And it means if someone wants to attack the system, if they want to create 10 bots, then
it will cost them much more because this effect of squaring, to make 10 bots, all of those
things will be reduced by a square factor.
Like, for example, if they had 10 bitcoins they want to sacrifice,
if they put it all into one bot,
their value would be 10 times 10, which is 100.
But if they split up those 10 bitcoins into 10 bots,
which had one bitcoin each,
the value would be 1 squared plus 1 squared plus 1 squared,
all the way to 10.
So the total value would be 10 instead of 100,
which means someone who's behaving honestly,
who just wants to earn money without spying on anyone else,
are going to have a huge advantage,
because their fidelity bond value is 100 bitcoins
and this Sybil attacker's fidelity bond value is only 10.
Yeah, that's the way the math works
to make fidelity bonds really expensive to do.
No, and it's beautiful too
because the way it disincentivizes Sybil attacks,
it also incentivizes long-term holders
to engage in fidelity bonds because...
Yeah, because they're not going to spend their coins anyway.
If they were just sitting in a hardware wallet doing nothing,
you may as well put it in this so there's lots of coins out there i i assume um to do this better
privacy arguably makes bitcoin as a network overall more more valuable too so yeah locking
yeah and you get money for doing it like you you don't have to risk your if you're like a hodler
you you don't have to risk your bitcoins you always have the private keys but you'd make a
small amount of coin join fees or coin swap fees just coming in like uh like for just for running
this server. It's a bit like in
Lightning routing. You get paid
to route other people's transactions.
That kind of thing. You get money for
not risking your Bitcoins,
which is nice. Another thing
that I should mention that Fidelity Bonds
solve is the old
coin swap design from 2013
had a DOS problem,
like an issue where Alice and Bob
what could happen is
Alice would send her coins
into the multisig and
Bob could just disappear if he
was trying to troll if he was trying to attack the system he could disappear and okay alice would get
her money back but she'd have to waste minor fees and she'd have to waste time uh and if bob if bob
could keep doing this like he could okay i disappeared once and then this time i really
really will do a coin swap bow i've disappeared again if he does that indefinitely it would just
make the system stop working and fidelity bonds are also a solution for this because
if suppose bob is this attacker if he has a he'll need a fidelity bond for alice to coin swap with
him but if he does disappear then alice would just refuse to coin swap with him again with that
fidelity bond and it would mean someone attacking the system in this way would also have to spend
lots of money so there's that problem of who goes first who actually puts their money into a multi
first um they'd be vulnerable to this attack and the fidelity bonds can solve that
so that is would that be more like a ddos attack yeah yeah exactly a dos attack denial of service
and if you notice in lightning they solve it in a different way that
what happens generally in lightning is people with wallets they open a channel
to someone like you might have a wallet on
your phone you open a channel to some merchant the merchant isn't
putting up any money normally they just accept your channel
and if you send money to them that's great but if not that's also fine
aren't wasted any money and that's also kind of why it can be
hard to get inbound liquidity because for you to get inbound liquidity
someone has to open a channel to you and put their own money in the channel
and if you disappeared like they could be thinking if this person disappears
i'm gonna i'm gonna just waste minor fees for nothing
um so that that comes into the liquidity thing as well but fidelity bonds and
liquidity work together in that way um
yeah but potentially enlightening i've seen on the mailing list there are a few
ideas for some maybe having some kind of liquidity
market so people can buy inbound liquidity um but i don't know i haven't been too much into this
so yeah oh so from my understanding of the spec i mean this seems like it's strictly better
than coin join and i'm trying to understand if i'm missing something here like if you're
successful with this coin swap implementation um would there be any reason for someone to use
join market or does does that does that usage just move over to coin swap yeah i think i hope
that it would move over to coin swap i don't um there's no as far as i can see it's better in
every way so the transactions are actually invisible the coin swap transactions look
like regular transactions and join market transactions are really obvious they have
all the equal amounts uh they also use much more block space like join market transactions one of
them is it's maybe about 10 times bigger than a regular transaction and also people don't do just
one you do coin joins it again and again and again so it costs loads of minor fees there's
yeah there's all kinds of advantages uh the only advantage to coin join uh that i can see is that
in coin swap it takes a little bit longer so you have to broadcast this transaction wait for it to
be confirmed and once it once it's confirmed that this contract is safe to do but with coin join you
don't have to wait for any confirmations you just talk to these other people doing a coin join with
and you create the conjuring and broadcast it and once it's confirmed that's that
so in that way coin join could be a bit faster however there is i was thinking about this like
imagining suppose you're a bitcoin user and you want to trade bitcoins real life in person for
cash a thing you could do with coin swap is you send your coins into a coin swap the contract
first before you actually meet anyone and once the the thing is confirmed you can go and meet
the person and you get the cash and then only then you make the next transaction like the
settlement transaction and you have to wait anything will be broadcast straight away and
once it's confirmed then the the cash is transferred so i think in practice it won't
actually be too this slowness thing won't be too much of a problem so and so let's dive into like
the on-chain heuristics that are
currently used to attempt
to de-anonymize people.
One thing we talk a lot about,
Matt and I are just
shooting the shit.
Is there
a threshold at which
a number of people coin
joining would provide a sufficient
amount of privacy
for the rest of the network just by
destroying heuristics
that chain surveillance companies use?
It seems like, and with
equal inputs and coin joins it's pretty easy to pick them out on chain and it seems like the way
coin swap works just because it's 202 or 203 multi-sig it makes it much harder to follow
these heuristic that chain surveillance companies use because again you have to assume that it isn't
a coin swap so is this threshold for like proceed better privacy for the rest of the network
extremely low once coin swaps implemented yeah that's an interesting question like how much
percentage of people do you need using something like this to make all the heuristics stop working
and i can't imagine it's very high like suppose we said five percent that means one in every 20
it means one in every 20 transactions actually breaks the heuristic and that
seems like it could be enough but another thing we might need is that they need to be
these by the way this also applies to pay join uh like when people are pay joining with a merchant
that would also work but a thing that would need to be there is these transactions probably have
to be quite equal throughout the economy so you could imagine if i don't know if there's some
traders who only ever transact to exchanges and if they never use any of this tech and then there's
some other you know say people who do online gambling if they always use this tech then you
could you could imagine it will only break the heuristic in the gambling point of view and you
know the gambling sector of the economy and never in the exchanges so you'd probably want the entire
economy or loads of it to to use this technology and not just one part yeah i guess that's a good
segue into what would incentivize these exchanges to do so i know bull bitcoin is the only exchange
up in canada that i can think of that actually coin joins for their users um before sending
funds out is there any economic advantage to doing this for exchanges that would incentivize
Only if their customers demand it, I guess.
But they, I don't know if you saw,
there was a recent article just yesterday by Rusty Russell,
who was making the point that loads of these exchanges
just make their money from pumping shit coins,
like telling their customers to buy altcoins.
And then they're not so interested in privacy
or anything like that.
So for me, that seems kind of grim.
I don't think exchanges are really our,
they're not our friends.
It's just they're not,
they have other things to think about.
they're trying to make a profit or whatever so users if they're interested
I have to do it themselves and that then it's useful point up how it can be
adopted unilaterally but if you have a wallet which supports these coin swap
transactions you just send to an exchange and they don't have to change
anything they don't have to even know you're doing it update anything and it
just works in a way that it doesn't work with lightning with lightning the
exchange you make a lightning wallet probably will you know might the next has a lightning
wallet but it might take a while they might not do it and who knows yeah we saw uh we saw the
downfalls of these exchanges or one exchange particularly focusing on shit coins yesterday
when you have like a five percent pipe price pop and coinbase just completely uh yeah shuts down
because they can't handle it because they haven't fixed their exchange because they've
been focused on adding shit coins the other thing is i mean it's it'll be a lot more difficult for
exchanges to to flag deposits that are coin swap it appears than if they were with flagging
coin joins it's pretty obvious on chain yeah the equal amounts really give it away and yeah that's
definitely another advantage yeah because you wouldn't be able to know if somebody is sending
it from a coin swap or say a block stream green wallet all right because that's what yeah uses
202. the hope is that we because yeah because you're saying if block stream green uses multisig
but the hope is that these coin swap uh the the you know the solution it would use multi-party
computer ecdsa computation so nobody would even know that it's a multisig it'll just look like
a single sick and then nothing then as if you design it properly then nothing really would
to give it away that's the hope so how far along are you in actually writing out the code that'll
it'll make this implementation functional uh right now i'm kind of designing the exact details of how
the contracts should work and all the step by step of like first alice makes a connection to bob and
then asks bob for one of his public keys and then alice makes this transaction then they wait like
There's all of those steps which you have to kind of write
to make it work, and then I'll start coding.
Also, I've got a plan to do it in, I mean, maybe it'll happen,
maybe not, to do it in Rust, because it seems there's advantages
to that language, and so I've been learning a bit of Rust right now.
And one good thing about that is this would be nice if it was a library
that can be easily incorporated into other wallets.
So it's not like there's a whole wallet which is called
the Coinswap wallet.
It's just that any other wallet, Electrum or Dockstream Green, anything like that, they
could take a library, which would be compiled, which Rust can do, and then the user would
see a checkbox, and they'd turn on Coinswap or turn off Coinswap.
And once it's turned on, then the wallet pulls the library, and a Coinswap just happens.
And that would be great.
And then it would be really usable.
People just use the same wallets they already use.
Yeah, that would be huge.
and that's one topic of conversation we actually had last week
is the sort of standardization of these wallet softwares
across the industry.
That's something that's been a bit of a pain in the ass
up to this point is different wallet creators
using different software and being incompatible with each other.
So standardizing this out of the gate would be awesome.
Or even non-privacy things like seed phrases.
Excuse me?
even non-privacy things are not standardized across wallets like seed phrases the electrum
has a different seed phrase to hardware wallets or something like that yeah it's what a bitcoin
bitcoin recovery wall wallace recovery.com what's yeah that's right database of all of them
well you know that old joke of uh the great thing about standards is there's so many of them
right and especially when you start throwing in like the hardware wallets
compared to the software and paper wallets it's and then the lnd light wallet has a another seed
phrase which has a wallet birthday it's a nice feature but then no other wallet has it
i think ultimately the only thing the network enforces is that the transaction format will
be the same and everything else could change yeah um one thing we didn't touch on here
uh which i kind of just blurted out uh is is like wallet fingerprinting right so when we're
talking about stuff like pay swap and coin swap uh providing basically cover for other people's
transactions if their wallet is is very obvious in in these unique characteristics that allow you
to fingerprint that they're using a certain wallet then those transactions don't get any cover from
from these type of techniques right yeah that's right that they bitcoin transactions have a lot
of uh they have some data in them like there's end sequence numbers and whether rbf is enabled
or disabled or uh the end lock time like there's a there's a wiki page on it there's loads of things
that you can edit in a transaction and probably um it'll be something i do eventually for coin
swap is analyze a lot of wallets like electrum and blockstream green and all that things and
try and figure out exactly what they do i mean i didn't invent i think um i saw this in some
of a podcast i think but then you have these the coin swap wallets or any other wallets
say 10 of the time behaves intentionally like electrum and then 20 of the time behaves like
some other wallets and then 30 of the time behaves like bitcoin core um and then uh then that should
hopefully that that should be a way to work around this fingerprinting thing because that's also done
outside of bitcoin i've read it's done with browser fingerprinting you know browsers have
different things like whether javascript's enabled or disabled what your operating system is your
browser version your screen size uh and then i've heard of some idea for writing a privacy browser
which fakes those fakes those um those features but in a different way so it says like now i'm
going to pretend to be linux this version with this screen size and then a bit later it says
now i'll pretend to be mac with this version and this screen size so i do the same kind of thing
there's a lot of controversy with that with the tor browser right because the tor browser
tries to normalize all those things among all of their users
in terms of screen size is one of the big things.
But because they do that, it's easier to spot
when someone's using Tor browsers specifically.
Yeah, that's right.
But I think the thing with Tor is it's obvious if you're using Tor
because if you go through a Tor exit node,
then your IP address will be on the list of Tor exit nodes.
And if you're going to an Onion address,
then obviously you can only use Tor with those.
So Tor doesn't have the property that you can hide
that you're actually using Tor
in a way that Coinswap or Payjoin does.
So fascinating how many variables go into protecting privacy
on the internet with Bitcoin.
Every leak adds up.
Right.
Transaction broadcasting, trying to delay that,
is one aspect.
the p2p network how you how your node connects and relays those transactions there's so many
variables that go into play and you've been around bitcoin for quite a while building software on top
of it and aiming towards creating better privacy how how's privacy evolved since you've been around
and do you think it's getting better do you think we're in a race against time absolutely getting
better like i remember when uh so you know we have this we have this kind of you know obvious thing
that to have really good privacy you basically have to use a full mode or you have to use
something which downloads every single block and then scans it on like locally to find your
addresses and and if you if you do it another way like with an electrum server or or something else
like that then uh then the server will figure out what your addresses are so this realization was
as far as i could tell completely unknown back when i started just no one even realized that's
a thing like people are thinking about coin joins or or or that kind of thing and there was um i
don't remember finding anywhere maybe there was somewhere
but I didn't see it that people were realizing that hold on
we need full nodes if you want to have privacy
so
just from that like that's just one example
of the huge progress I think we've made
in this few years
yeah so
are you confident
in the ability for Bitcoin
to provide sufficient fungibility and privacy
for all users in the future
because this is like are the
Monero stands
I'm in the business of
That's what I'm in the business of doing, but it's hard, you know, it's you
Whatever, you know, I'm sure people invent stuff
There's a thing right now that as far as I can tell there's no real way to have a lightweight private wallet synchronization
So we know wasabi wallet that uses those client-side block filters where there's these filters and then you only download the blocks that are related
To you, but that's actually not very lightweight. So if you did that
where Bitcoin Core has some code which does it and those filters for the whole
blockchain they add up to a huge amount of data like four gigabytes or five
gigabytes and that's not if you had a wallet we had to download four
gigabytes it's not really a lightweight wallet it's huge and the reason wasabi
gets around that is their filters only contain BESH32 addresses so the
filters are much smaller because those addresses are quite rare on the
blockchain but those filters wouldn't work for lightweight wallets if they had
all the kinds of addresses, DTSH addresses.
And we want to see batch 32 usage go up, too.
Yeah, exactly.
As usage goes up, those filters will get bigger, too.
So right now, there's no real solution for lightweight wallet sync.
But, you know, maybe one of the listeners can invent one, right?
It's all progress goes incrementally, doesn't it?
Yeah, no, that's one thing I say a lot.
Like, everybody wants this stuff out of the box right away.
It just doesn't happen that way.
especially the way bitcoin was designed at launch it's going to take time and luckily people like
you are focused on this and bringing software to market that that does make it better um that
gets us to a point where the should have used monero fans uh shut up at some point even monero
isn't that great like i sometimes rant a lot about this because there's like loads of privacy
problems with monero no i mean not loads but it's obviously better than bitcoin if it didn't have
of CoinJuin and stuff, but there's a thing you can do
with Monero if you make repeated transactions.
So Monero has those decoys, doesn't it?
It takes the decoy transaction inputs
and adds them to your transaction, makes a ring signature
so nobody can tell which are the real inputs.
So that's only if you take one transaction in isolation.
If you did 10 transactions, so if you had a Monero,
say someone accepting donations in Monero
and you made 10 donations to them,
you know 10 of their inputs.
And when they go to later spend them,
you have much more information.
Maybe easier if I drew it, but you can do an intersection.
You can figure out, because you have 10 or 20
or however many times you paid them,
you have much more information you can use
to take away their decoys.
That's to talk about it.
Maybe I can link it or something.
But it's interesting that even Monaro,
like Monaro is better, but there's still a tax you can do.
And the other thing you talk about is the scalability
is way, way lower.
so I've done a calculation
that if Monero was doing
the same amount of transactions that Bitcoin's doing today
then the full nodes would not be possible
to run on a regular desktop
it would just use too much CPU
so something like Monero is inherently limited
like yeah you'll get
better privacy but what's the point if
a thousand times less people use it
yeah and you expanded on this
topic with Stefan when you were on his podcast
recently
so go check that out
if you have freaks but
But one thing in relation to Coinswap that we haven't touched on yet,
a couple of things actually, is how does it affect,
like how expensive are the fees?
And if there's a lot of transactions, how does it affect fees?
And then moving forward, let's say something like Schnorr
and then Taproot gets implemented,
does this change the implementation at all?
No, that's a good question.
So the fees, so obviously it's a bit more expensive
than just doing a regular transaction
because they're as cheap as they can be.
They have a size.
But coin swaps would be much cheaper
for the same amount of privacy
than equal output coin joins.
So for example, in join market,
one coin join is about 10 times the size
of a regular transaction.
And users don't just do one coin join.
So the join market Tumblr script,
by default, there's about 10 coin joins.
And each of those transactions are huge.
So it's already using a huge amount of block space there.
And the privacy isn't even as good as what Coinswap,
how good Coinswap would be.
So if you work out on a per-privacy basis
how much minor fees you need to spend
to get a certain amount of privacy,
then Coinswap comes out ahead.
And another benefit of Coinswap
is because it's indistinguishable
from all the other transactions.
It means if you really want to cheap out one day
and just make a regular Bitcoin transaction,
your privacy will be improved anyway
because someone who was analyzing this would say,
hold on, maybe he's doing a coin swap.
Maybe he isn't. We don't know.
And that kind of externality,
that benefit doesn't happen with equal output coin joins.
So yes, overall, they'd improved efficiency
for minor fees and block space.
And as for Schnorr and Taproot...
Oh, sorry.
Sorry, carry on.
No, you continue.
I forgot about that part of the question.
So as for Schnorr and Taproot,
So there is a thing, so you can use Schnorr with MuSig to also make two of two multi-sigs
that look exactly like a single-sig, and there was an idea where we could use that instead
of multi-party computation, UCDSA, but in the beginning, there wouldn't actually be
much Schnorr being used out there.
So we know with Segwit, it's been three years since Segwit was adopted, and maybe 60% of
transactions use it.
I think I saw a statistic the other day.
And Segwit has a huge incentive to actually adopt it
because you get cheaper minor fees by adopting it
and still only 60% of people adopted it after three years.
And Schnorr doesn't have such an incentive.
If you use single-sig Segwit transactions
and you adopt Schnorr, then your minor fees cost the same.
There's no incentive to adopt it financially.
So in that way, you can expect adoption to be even slower.
and that means we'd be we may as well use multi-party you may as well use ecdsa for coin
swap for now and that that has a nice that has a benefit in that coin coin swap doesn't need any
soft forks to make it happen there's no way to stop it like you can't oppose the soft fork and
then that would stop coin swap somehow but it couldn't happen today yeah that's nice to know
So if people do adopt Schnorr in mass, it would be easy to just implement it with music.
Yeah, but realistically, I think it will take a while.
People who use multisig will probably adopt it first because they do have an incentive.
But if you're using single-sig, then there's no incentive.
Matt, did you have a question?
Oh, yeah.
So with CoinJoin right now, we have JoinMarket that does, where you have this maker-taker
model, you have this, it's a decentralized model.
And then we have these centralized coordinator models with Whirlpool and Wasabi.
And with those models, you don't have to worry as much about two things, the communication
channel between um the parties involved in the transaction and the the issue with fidelity
using fidelity bonds basically uh like the the civil attack protection using fidelity bonds
um and the denial of service in in a way right so do you do you expect and recently no power
made a comment uh the lead dev at wasabi made a comment in regards to he seemed confused about
the purpose of fidelity bonds to me um if do you do you envision that we'll see
these these decentralized coordinator projects pivot to a coin swap type of situation uh where
where they they run a centralized coordinator that that manages the coin swaps and in that
situation they there's no need for fidelity bonds right okay so um so the purpose of fidelity bonds
are useful when there's a decentralized system
where anyone can be a Sybil attacker.
So you could just have Chainalysis
or someone runs loads of bots to do a
Sybil attack. And
in a centralized system, that can't happen.
Chainalysis or any adversary, they cannot
become a Sybil attacker
on Wasabi's or Samurai's
coordinator. However,
because they're centralized, then Wasabi and
Samurai themselves can be the Sybil attacker.
And they could do it in a much easier
way than is required in JoinMarket
because to do a Sybil attack in join market
you literally have to have 10 or 100 bots
but to do a Sybil attack in Wasabi
the Wasabi server just has
to exclude everyone else
except for you like I don't know maybe they
have a court order that says if this
transaction output does a coin
join then you have to exclude everyone else and just
have your own your own inputs
be that coin join and then
this court ordered transaction
I think they're doing a coin join but actually they've been
Sybil attacked and these
centralized coordinators can do that for free like there's nothing technically stopping them
right i mean it's not to say they're not useful but they but that's like you know that's the
trust model there's there's trade-offs like those benefits it even goes further than fidelity bonds
it won't help them uh because they it can't help them they only work it's only useful in a
decentralized setting as for whether they had a job sorry carry on i'm sorry i'm sorry i i'm just
very excited this is a great chat um i i just it even goes further than that because the sybil
resistance is the fee that's paid to the centralized coordinator so who's ever running
the centralized coordinator doesn't have to pay that fee so they don't even have to necessarily
exclude transactions uh they they could just sybil like crazy without ever really they just
pay minor fee yeah yeah um yeah that's right so they like you could say if there's 10 people who
want to do a coin join and in like the normal way in wasabi or samurai those 10 people make one coin
join but actually if if the coordinator symbol attacks all them then there'd actually be 10
coin joins with one person one like real person per coin join and everyone else being a simple
attacker and they learn all the same fees and they'd make the same money it's just the minor
fees would be a bit higher and as for if they do coin swap um i haven't really thought i've been
mostly interested in doing this in a decentralized setting because like i have the view that um to
to have real privacy you need censorship resistance because otherwise the sensor could
just censor you until you reveal your privacy relevant information so i haven't thought too
much about doing quantum in a centralized way i suspect it's not i'm not that interested really
but maybe maybe in future someone could figure out a way to do it right because there is a benefit to
to the Wasabi and Samurai way of doing things
is they have
an income. They can
hire developers and make a really nice wallet
that works really well and
has all the features.
There's some good things about centralization.
I don't want to completely disregard it.
But it is less
good at being private.
And the communication channel, right?
That is...
So with Coinswap,
is it going to use
irc based communication again like with joy market i know i've been um that's part of the design i've
been thinking probably the best way to do it is something similar to bisque where each maker makes
their own tour hidden service their own onion and then uh when a market taker comes along they
connect to each of these onions and download their fees their coin swap fees and other information
like the max Cointop size.
And then Tor is by default encrypted
and it's hidden where the actual service is.
I think that's the best way
because like JoinMarket today uses IRC
and it's not that good.
Like, let's be honest,
I made it right at the beginning
and it's not very,
I mean, it works,
but it's a bit centralized.
That's fascinating.
And before we get any further,
you are accepting donations
for this build out of your implementation, correct?
Yeah, that's right.
So it would be decentralized, and there's no way I or anyone else can collect fees to fund development.
And development happens by donations.
So I'll say the website I'm using now, which is bitcoinprivacy.me forward slash coinswap hyphen donations.
And there people can find Bitcoin addresses that go to me if they want to support this work financially.
And they can also review it technically if they're interested, if they have the skills.
but I'm trying to make it like an open source
like something like Linux or
Bitcoin Core itself where it can be
a community thing and it could exist
forever like if I ever lose
interest then hopefully it will still be there and people
can still use it to improve their privacy
but for now I'm committed to
making it a reality
Matt and I were admiring
your donation site
it's the best donation
site I've seen to date you hit refresh you get a new
you get a new address right away
very clean straightforward pgb signed yeah yeah that's the stop the way it actually works if
anyone like if anyone wants to make their own it's um i made many many bitcoin addresses from a
from my xpub and then signed them with my pgp key on my own on my own hard drive and then uploaded
them all to the server and then there's just a simple php script which uh goes to a new one
every time refresh is hit and then on my full node here in my home it just watches all those
addresses when a donation arrives i was thinking of using btc pay server but i honestly i thought
it would be more fun to do it myself i probably most people are better off using btc pay server
but i did it this way i'm sorry i probably contributed to your need to jump forward
a bunch of addresses because i was just hitting refresh that's okay there's a huge huge huge
amount of them because they don't take much disk space like each address is a few it's like 500
kilobytes no sorry 500 bytes including the signature so if you you know most of these
hosting things give you like gigabytes into gigabytes you can fill the whole thing up for
the addresses yeah they're basically infinite like you press f5 all you want there is you mentioned
btz pay and i was talking to someone about this the other day that no one really discusses it uh
And I also didn't really, I didn't think about it until this person brought it up because I was trying to get them to add BTC pay to their site.
And they're a very security conscious person.
There is a bit of a man in the middle risk there in terms of is the address shown actually controlled by the person you intend to donate to or pay?
That you do get around by doing the PGP signed, right?
Like I never really thought about it that way.
Yeah, that's true.
Although I think a lot of people using BTC pay-per-server,
they'll have HTTPS.
And as long as you trust that whole system,
which is more centralized than PGP,
but that should, in theory, stop a man in the middle of the attack.
I mean, that's how it works for when you buy things regularly,
like on Amazon.
They all rely on HTTPS for their security.
So in theory, it's okay, I guess.
and it's while we're on the topic of btc pay i think it's a great example of
an open source project that's garnered a lot of attention and and support from developers and
even grant support from from companies and individuals so hopefully something similar
will happen to your implementation yeah so are you are you looking for engineering help before
you launch it or will you sort of launch
it and then start accepting
PRs and
yeah I think I'd be I'm looking for
help in review that if
people look at the design and if they
see any attacks or anything like that they tell
me and then as soon as
I start writing code I'll
I have that idea of release early and release often
so I'll make the like the minimum you know
minimum minimum viable product that only works
on testnet and put that on github
and from there iterate and so hopefully
people if they're interested they can read
decode as early as possible.
It was the same with join market.
You can go back to years ago and find the very first testnet join market that worked.
Going through your GitHub here, I notice you have a fork of the user-activated
soft fork.
Were you maintaining a good implementation of that?
I think I added a company that said they would use a UASF full mode on their, you know, to accept Bitcoins.
I don't remember who.
I think it was someone who, like, Bitrefill back then.
They were quite new, and they were one of the people that did run UASF.
And then I think there was a Voltero that they trade gold for Bitcoin.
I've forgotten exactly.
It was a few years ago, but it was something like that.
I could probably look at the GitHub and find out who I did.
But no, I didn't run the site.
I just went to PR.
Yeah, that was an interesting time in Bitcoin.
Right.
Do you think we'll have as hard a time getting a soft fork implemented in the future?
Who knows?
It's really hard to say.
From one point of view, you could say that the victory with Segwit means that any other fights,
there'll be no point in happening because the other side know they're going to lose but from
the other side you could say well they still caused loads of drama and delayed segwit a bit
so they might try again anyway um but i think there's a lot back then a good thing about now
is many more enthusiasts are aware of how important full modes are and back in 2016 or so it was much
less well known as it took it took by education and telling the community and a lot more people
know about that and there's more there's better technology as well easier ways to connect your
wallet to your full node um so i think people will like because full nodes are so they're they
i don't i mean part of the measure of course but i feel like they're more common and they're more
aware there's more awareness how important they are then attacks which depend on their not being
full nodes will be less successful hopefully yeah it's been great to see the proliferation of
out of the box node hardware and better software uh things like raspi blitz yeah the noddle and
actually i'm interested to get your thoughts on the bitcoin wallet tracker that was released last
week you've you've worked a lot on electron personal server and that's been somewhat of
a pain in the ass for people who aren't as technically competent as others um this bitcoin
wallet tracker that was released last week that's an electron plug-in that lets you connect to your
full node what what are your thoughts on that like what are the trade-offs there and is it
materially better no it sounds great to me like there's no i haven't granted i haven't spent much
time um i haven't downloaded it or anything like that but uh share check and i talked a bit over
irc and twitter and it seems really great like they uh and the idea of having it as a plugin
is quite good um for me personally i always at least for the way i run it myself is i have a
little raspberry pi which has the electrum personal server on it and then my electrum connects to that
and i don't know how that would work if you so does bitcoin wallet tracker i don't know if any
of you have run it but does that mean you need the full mode on the same machine like this needs
to be on your laptop where your wallet is if it runs with a plugin well you can do both but either
way you can do both yeah it could be a drop in replacement for electrum personal server where
you run it on a dedicated device, or
you can
just run core on your machine
and BWT
and Electrum, and you're good.
Okay, that's great then.
It seems like the UX
around running a full node and connecting
to it and actually using it is getting
considerably better as well.
Yeah.
I should tell
Shashank, but it's good to know anyway,
that it would be good if
If Tor broadcasting was added, you know this feature
where when you click broadcast in Electrum,
then the server can broadcast your transaction over Tor
instead of using ClearNet, and that can be good for privacy
so your IP address isn't leaked with broadcasting.
Electrum personal server does this,
and it shouldn't be too hard to add to VWT.
Yeah, that's what's been encouraging
about the Node hardware.
It's been coming out, too.
it's just naturally been running through tor so hopefully stuff like that just makes that
just common practice out of the gate yeah yeah and that would be great
um what else are you excited about in the world of bitcoin or outside of bitcoin you've been
working on this for for quite some time you mentioned you're into gaming what else uh what
else piques your interest i haven't actually played games for a few years to be honest um
I mean, I know it's old news,
but Lightning is just generally exciting.
You can send a transaction basically instantly
and for low fees,
and I think that's really good, I guess.
I don't know what else.
I suppose I've been learning Rust,
and that's kind of exciting.
Yeah, Rust.
A lot of the devs I talk to,
just the way they explain it,
just like Rust is more powerful.
That's what BWT was made with, right?
Yeah, yeah, exactly.
Yeah, and um, it's more it's aimed to be a safe. It's aimed to have inherent
inherently safety features so
that it's impossible like the compiler won't allow you to do things like uh,
And I have a memory leak or free null pointers or things like things that happen
Things that you have to take care of in c plus plus and you don't in rust at least that's the idea
I haven't learned it properly yet
But it's a good thing to aim for
yeah it seems just from what i can tell it seems like a a really strong language that you want to
be building bitcoin software with at least should have implementations written in it yeah um what
are you guys interested in well uh i like to surf i write and talk and then uh outside of this i
surf we're very interested in lightning as well we fawn over i use lightning every day i've been
uh actually combining lightning and gaming the bitcoin uh bounty hunter game that allows you to
put ads in their game and pay for them via lightning that's been like one of the coolest
things that i've seen in the space recently so i've been i've been making sure our ads are
sufficiently uh funded on that game um that and then i'd like to focus on the adoption side too
and education side i think the education around bitcoin has gotten a lot better over the last
three years particularly and i'm very interested to see if if bitcoin begins getting more attention
in the mainstream how well um new users will sort of understand the technology and the software
available to them uh once they discover bitcoin and start using it for me i've kind of noticed
I might not be very good at the explaining to noobs because it seems like I spend a lot
of time on the technical details and then it's sometimes hard to dial that down when
you talk to people who are new to this stuff.
Like I've kind of noticed that with Coinsopper, I'm like, oh, you did this thing and it has
a hash time contract and then I guess people would be like, oh, what is that?
What's a hash?
Yeah, what's a hash?
Yeah.
I've experienced this too recently.
I've been going on more.
One thing I'm very interested in,
it would be remiss of me not to mention,
is I work for a company that we're mining as well,
and we're using wasted energy to mine Bitcoin,
particularly on oil and gas fields here in the United States.
And because of this,
we've been getting some attention in the oil and gas industry here.
So I've gone on a couple of oil and gas podcasts recently
and have had this experience where they're completely new to Bitcoin
and having to explain it to them
when I've been writing to an audience of Bitcoiners
and running this podcast with other Bitcoiners
really drives home, oh my gosh,
you do need to dumb down some of these concepts
and think about the beginner's road
to understanding Bitcoin.
It's a good thing for all of us to practice sometimes.
Yeah, no, it's not.
Yeah, I had that same experience there.
like explaining like how does mining work and i was like uh how much do you know about hash cash
shot 256 proof of work like trying to explain difficulty adjustments and i got like a little
off the rails but that's good like the the wasted energy because that energy is basically free isn't
it like you yeah zero costs so then you just need the a6 and you get free money yeah it's so the the
the ASICs and then the generators too actually consume the energy.
Right. Yeah. Yeah.
Because it doesn't come off as natural gas that you have to burn or
something.
Exactly. Yeah. So those, those are your,
what factor into your kilowatt per hour costs, but even,
even so you're able to get it down pretty low with these,
this wasted energy.
Yeah. Yeah.
What about you, Matt? What are you, what are you excited about right now?
outside of coin swaps well i mean i love bitcoin bitcoin is fascinating people are fascinating
love talking to people um i don't know privacy it's fucking massive i think
we've been very focused here on education uh we have a long way to go but i i do think it's really
cool um how many people are focused on education that are in scammers which is his is what the in
the past you know you you see people come in and they they go to youtube and they they buy the
courses on blockchain and stuff like that um and you just really hate to see it uh but now you know
you have like stefan lavera you have katan that works with him in ministry of nodes you have 6102
bitcoin there's like this whole sub-industry that's developing of a bitcoin education
that really seems to be focusing on on the right principles um in terms of privacy i i think we're
starting to it's you know i'm i'm fascinated by privacy not just on a bitcoin level um
and i just think it's it's we're starting to hit a critical mass here where people are realizing
People are realizing why it's important because their privacy is getting trampled on left and right.
Yeah, that's right.
Yeah, it'll be interesting.
I mean, another thing that's very interesting right now is the state of the world, geopolitics, China taking Hong Kong.
Obviously, we got some interesting things happening here in the United States.
like is bitcoin ready for uh not mass adoption but considerably more adoption in the face of
people maybe needing to turn to it um that's another thing that i'm very curious to see
like if if bitcoin does get a lot of attention soon like is the protocol ready to onboard a
bunch more people yeah that's right there's i don't know how well known this is but back in
2017 ish i was uh reading you know there's a reddit subreddit for the syrian civil war back
then it was a big thing it was aleppo and damascus and all that stuff and i came across a couple of
people who are actually trading bitcoin there because they it was for that it was because
there was huge inflation in um in syria and they were trying they were just you know dollar cost
averaging into bitcoin essentially and they had one of them mentioned this thing on reddit that
a great thing of bitcoin is you can if you end up being a refugee because there's war and if you
have to like go to turkey or something then you can take your bitcoins with you just memorize them
in your head um and like that that's kind of that's sort of what we're here for aren't we
we're helping people one of the use cases we're helping people store their wealth if they need to
you need to protect it from being seized yeah that was a real life example of it and there it was
i was kind of surprised because i was um thinking maybe they're gonna you know do you need this
explaining but they seem to just get it they're like you have a wallet and then you send it to
this person and they give you cash and it just works once you need it it's pretty obvious i feel
like yeah yeah yeah the hard part seems to be understanding what money is like you have this
thing called bitcoin and it's like money and once you understand that then in theory it's just
clicking buttons right you click send you click receive write down a seed phrase hopefully
it's crazy to see how how much utility bitcoin provides depending on your different use case
you just described syrian escaping to turkey keeping a seed phrase in their in their head
to escape um terrorist and a a dictatorship but then like i've talked with matt alborg who's doing
a lot of research on how people are using it in venezuela and argentina trying to escape hyper
inflation and using bitcoin as a rail to send money so that they can get dollars that's also
yeah um that's the beauty of bitcoin it's just this apolitical messaging system and if you can
download the software and interact with it you can participate and it doesn't know what you're
using it for or how you're using it or why you're using it just works that would be one one place
where privacy is important because if you're suppose you have this syrian guy and you want
across the border in Turkey, and they say,
aha, we see your mobile phone data.
Look, you've been using a Bitcoin wallet.
Hand it over, son.
You don't want to be in that situation.
And that is actually one thing I'm concerned about
with how there's no solution for lightweight wallet sync.
Like these wallets on people's smartphones,
they all connect to some server and tell them their addresses.
It's probably okay now.
I'm sure the Turkish border guards can't do this,
but in theory they could.
in theory they could have
something that scans
and figures out
the internet service provider and figures out what your
bitcoin addresses are
that will probably happen one day
if we're in early days and eventually the authorities
or anyone who wants to steal
your bitcoins will learn about this
so that should be something we should fix
but either way on smartphones people can
synchronize their wallets anonymously
and I don't think that exists now
would something like AB core help that?
yeah possibly
you could just have full nodes on a
smartphone
that could be one way, maybe smartphones
get powerful enough and
bandwidth gets cheap enough
and it could happen
but I think there's a long way, like you need a few
another few doublings of Moore's Law
at least for bandwidth to make that really
make that possible
It'll be interesting to see how that plays out
that's another thing
that I like to observe
is how people
extrapolate the current state of bitcoin and just technology in general and how how computers work
extrapolate that to the future and sort of discount potential
innovations and efficiencies that could happen um yeah a lot of linear thinking
yeah but the thing with bitcoin is the blockchain is linear like every block you generally get new
addresses that are mined into the blockchain and any wallets would have to synchronize them somehow
somehow figure out
these are my addresses that come from my seed trays
and I want to figure out if they have transactions on them
and how do I do that?
I don't know, we'll see.
I'm just kind of thinking out loud here.
I love that.
Do you have any thoughts on Lightning as a privacy tech?
Oh yeah, it's great.
This idea of not having your transaction on-chain
is basically a revolution.
All the things we talked about earlier,
the transaction graph and the common input ownership heuristic and things like address reuse
and change address detection they just don't exist in lightning there are no change addresses there
are no there are no uh you know multiple inputs into a transaction uh it's all off chain okay
there's other attacks but they just the fact that the the transactions aren't visible to everyone i
think is a huge help so yeah absolutely it's a great privacy tech somehow although it still
still has the thing that the channels
are on the blockchain, you could analyze
someone figured out your channel
because your Lightning Wallet also has to
message a third-party server
to figure out what your
channel UTXOs are, then someone
could analyze based on that.
We'll see how that goes.
The building blocks are there to solve it somehow.
Yeah, it shows
promise is kind of my perspective.
right especially on like the receiving side uh the privacy like it leaves a lot to be desired
on the privacy front if you're receiving lightning transactions yeah it depends a lot of the stuff
is with your threat model like you can i'm sometimes asked like if i do this will i be
private will i have enough privacy and then always the thing i answer is okay who you're
actually hiding from like if you're if you're hiding from some whatever turkish border guard
or someone who doesn't really there then you don't you know or just some looter then you won't
yeah probably have to try too hard but if you're hiding from i know the united states government
or something you have to try a lot harder and they because they the u.s government they have
the power to presumably we believe to look at every internet packet out there which i know
turkish border guard doesn't i think they just made a law here what what's that what does the
law say they're trying to make it a law where they can get access to to all of your internet data
they have indiscriminate rights to to check your messages on social media and all that stuff
yeah and the whole social media thing is a big privacy
really like amazing people give away all that information just for nothing
yeah that's that's another thing that sort of excites me about lightning this idea of ln url
If we were able to, instead of giving username and passwords to companies that they then store on their own databases, which are highly susceptible to getting hacked, you have an authorization flow from a node that you control and public keys within that node.
Your public key being signed by your private keys is basically authentication.
Yeah, so you use your private key as a login.
Yeah, that excites me as well.
sort of re-architecting that interaction between user and service provider on
the internet would be huge.
Yeah. Although I'm not sure. And yeah,
like it's good for privacy that you don't have usernames and passwords,
but there's still people like you go on Facebook and people upload pictures of
themselves, which can be,
can be sent to facial recognition algorithms and things like that.
And that,
that wouldn't change if people don't use passwords anymore if they use a
private key instead.
no we say it many times in this on this podcast we're all face fucked
yeah you're not doing it on social media there's so many cameras in the cities now that it's not
even well then maybe with the tracking devices in our pockets yeah that's right although maybe
one thing with the um with the pandemic is if more people wear face masks you must have heard
of that wearing face masks can help break facial recognition well in america we have this weird
phenomenon well at least before the rioting happened uh there was this weird phenomenon
where people were saying once face masks became basically mandatory at the state level uh it was
an act of defiance not to wear a face mask which i thought was a really interesting um psychological
experiment uh and i i said to marty i was like i wonder like if they mandated end-to-end encryption
if people would just send plain text messages
as like an act of defiance.
Right.
Right, yeah.
It's funny how
psychology is sometimes.
Right.
I mean,
and it's funny how that's an example
of like mass
hysteria coming into play.
It's been a topic too,
obviously with the riots.
People are being manipulated by the media
and the governments to act in certain ways
than they seem to be pretty easily manipulated these days.
Yeah.
What most people don't realize is in New York,
since the 1800s, it's been illegal to be with more than two people
with face masks on in public.
Really?
Yeah, so this is like the first real protest we've had,
in New York City at least, where you're legally allowed
and actually compelled to wear face masks to the protests.
It's an interesting thing to think about.
Why was that?
I suppose it was never enforced, this law.
It was enforced selectively, just like all the good laws are.
Yeah, just when you need an excuse.
Yeah, I've worn a face mask in New York City for 10 years.
Never got stopped once.
But I'm a white person and I wasn't doing specific things.
that they decided to enforce it on yeah you weren't getting stopped and frisked not once
um yeah there's so many so many things to think about but luckily luckily bitcoin exists i'd be
a lot more pessimistic if bitcoin didn't exist and luckily we have people like you chris working
to make this better and not only for yourself but for everybody and the work you're doing is
extremely important and i'm very happy you're doing and i'm very appreciative of of all the
effort that you put into this yeah thanks for saying so that's uh i hope you yeah i hope you
realize that people appreciate your work and it it's not does not go unnoticed very grateful
yeah thank you um i want to be respectful of your time we we blocked off an hour and a half here
coming to the end of that if you factor in our pre-conversation and what we've recorded already
is there any parting notes final thoughts you you want to leave the freaks before we wrap up here
well no i just for the coin swap thing that if you can review it technically uh then do that
that would be appreciated and if you um want to support me with a donation that would be
very helpful as well uh just those things really and you know think about how you think about your
privacy because it's a
like it helps everyone
should people
go to your github to help review
or they have to reach out personally
no it's on the actual design
the mailing list email
that's the design that has all the
building blocks
alright so go check that out
we will link to the gist
and your donation page
in the show notes again
Chris thank you for what you do
really appreciate you taking some time to come
explain this stuff too
anytime we should do this again
hopefully when you get closer to
actually releasing
a workable implementation we can
link up again and talk about
how it actually works and get people using it
yeah that sounds good
anything from you Matt
yes please we'd love to have you back
yeah sounds good
anytime
again have a good day
you as well that's all we got this week freaks
peace and love
