TFTC: A Bitcoin Podcast - #280: A spooky Halloween special with our good friend @arbedout

Episode Date: October 30, 2021

Marty and Matt sit down with their good friend @arbedout to discuss: - Joining Unchained Capital - Writing a book - Has Lightning been attacked? - Is Tor reliable? - Is Bitcoin sufficiently robust wi...thout robust alternative transaction relay networks? - How are we going to transition from HTLCs to PTLCs - much more Follow @arbedout on Twitter Shoutout to our sponsors: Cash App Unchained Capital Braiins Compass Mining

Transcript
Discussion (0)
Starting point is 00:00:00 Sup freaks, it's your boy Marty Bent here to introduce this rip of Tales from the Crypt. Matt and I sat back down with our good friend Arbed Out for a holiday special. It's not a Christmas or New Year special this year. We decided to do a Halloween special. Since it's a Halloween special, we talked about a lot of spooky topics in Bitcoin. Maybe topics that people sort of avoid because it's like, if we ask these questions, are we going to find out things that we don't like? We talked about a lot of Bitcoin's problems.
Starting point is 00:00:28 or problems around Bitcoin that need to be solved. And I think it's going to be a very illuminating episode for a lot of you freaks. And I think it's a very important conversation to have. And I think you all will be, I don't know, some of you will be disappointed. I think some of you will be happy to learn that this one came with no alcohol.
Starting point is 00:00:47 We were sober ripping this one. And so therefore there were no naps taken during this. and it's a bit shorter than episodes of years past with our friend Arbedout, but I think the content is incredible. As always, he's a mensch, and I'm very happy that he is now working at a Bitcoin-only company in Unchained Capital. Disclaimer, they're a sponsor of the pod.
Starting point is 00:01:12 You're about to hear the ad read. But enjoy this, RIP Freaks. Share it. Let us know what you think. Don't get too spooked out as we head into Halloween. Okay. This rip was brought to you by our good friends at the motherfucking CASH APP. I don't have a voice.
Starting point is 00:01:30 I went to a wedding and lost my voice. CASH APP. CASH APP is making it easy to stack sats. Very easy. You can DCA into it. You can get paychecks direct deposited into the CASH APP. It's got its boost program. It's a beautiful app.
Starting point is 00:01:47 It really is. Beware of withdrawal limits and stuff like that. Make sure you get your sats off the app. But if you want to access sats, Cash App makes it very easy. You can set buy limits, or you can set, like, thresholds you want to buy. You want to buy, like, a little dip, and you want to set it and forget it and just wait for it to get there. Maybe it never will, but maybe it does.
Starting point is 00:02:05 It'll automatically fill your order. You can do that now on the Cash App. A little birdie told me there's some new wallet functionalities coming soon, too. Just be on the lookout for that. If you haven't downloaded the app, make sure you do so. Using the code STACKINGSATS, you're going to get $10. $10 is going to go to our good friends at Owls Lacrosse. that's owls lacrosse owls lacrosse this rip was also brought to you by our good friends at
Starting point is 00:02:29 unchained capital unchained capital is here to help you eliminate single points of failure in your custody model all right this personifies itself in their multi-sig vault which is a collaborative custody model where you engage with unchained two or three multi-sig signature you hold two keys Unchain holds one. You always have full control over your Bitcoin as long as you have the two keys that you are supposed to control. If you're ever in a pinch and you need Unchain to be there to be the second and the two or three, Multisig wallet or transaction, excuse me, they are there for you. They have a white glove concierge service. It's going to take you from zero to having a thousand cuck bucks worth of sats in the vault. They're going to have multiple video
Starting point is 00:03:10 conference calls with you. They're going to get you comfortable with Multisig, comfortable with vault they're going to get you hardware while it's going to get you comfortable with setting those up and securing and securing your your backups your seed phrases they're going to teach you how to back up your derivation pass for the multi-sig vault as well and then on top of that you're going to get 50 bucks off if you tell them the tftc sent you so go check it out on chain.com and check out everything they have going on beyond the vault product they've got an incredible suite of products. They just added an IRA service. They've got an incredible blog. They've got their lending desk. Go check it out, unchained.com. This group is also brought to you
Starting point is 00:03:49 by our good friends at Compass Mining. Compass Mining is here to get more individuals into the mining game. The way you do it, you go to compassmining.io, and you can go pick out an ASIC, buy that ASIC, and you have options there. Once you buy that ASIC, you can have it sent to your home, directly to your home. And Compass Mining has an at-home mining team, a support team there. the number one get you your miner send it to you and then number two walk you through the process of setting that miner up at your house or wherever you're you're plugging it in they're going to teach you the electrical infrastructure necessary to make sure that your your miner is working and actually functional they're going to teach you how to link into the miner's ip how to point
Starting point is 00:04:27 that hash rate at a mining pool and how to set up a wallet to receive the payouts from the mining pool it's a beautiful thing uh also if you don't want to do the at-home mining route and you're comfortable with hosting you can buy a miner via compass and then pick a hosting facility with competitive electricity rates they'll get that miner they'll send it to the hosting facility get it plugged in they'll start streaming sats to wallets of your choice go check all this out at compassmining.io last but not least this rip was brought to you by good friends at brains brains brains brains is here to help you stack more sats via your asics and they do that with the brains os plus auto tuning firmware which gets into your asic it finds different hashing chips
Starting point is 00:05:11 that have higher frequency and separates it from those it doesn't separate them but it focuses the electricity and the hashing on the higher frequency chips so that you can produce more hashes and therefore more sats for your asics if you have an asics that's compatible with brains os plus and you're not running it you're leaving sats on the table go to brains.com it's b-r-a-i-i-n-s dot com and check out which mining models are available to have brains downloaded on them. What's miners coming soon? That's 19 in private beta. I think it's getting rolled out as we speak as well. What else? If you point to your brains, your A6 running brains OS plus firmware at slush pool, you're going to get zero percent pool fees. It's nice little big there. You don't have to
Starting point is 00:05:55 point it at slush pool. You can point at any pool you want if you're running brains OS plus. But if you do you're going to get zero percent pool fees at slush pool they're looking to hire rust developers system admins and people have worked on hardware in the past incredible teams so go check all this out at brains.com b-r-a-i-i-n-s.com uh check out all their products check out check out slush pool check out brains os plus firmware check out their mining profitability calculators their their blogs are doing incredible things they're bitcoin only business and they're focused on making sure that miners have the best tools they possibly can to stack as many sats as possible It's a beautiful thing. Enjoy this, RIP freaks. Sorry, it's a little late.
Starting point is 00:06:58 world of fiat currencies bitcoin is the victor i mean that's part of the bull case for bitcoin if you're not paying attention you probably should be probably should be i'll speak up for you old man appreciate it yeah i gotta get a hearing aid you're getting old i am getting old you're getting into bitcoin only jobs we're all getting old right don't age me i'm having fun getting old with you guys i gotta say that yeah cheers to that well old man bring that mic closer to you please you may not be able to hear me we want to make sure the freaks can hear you at least all right are we we're not recording yet are we no we're recording right now we've been recording for 27 seconds you've got to be kidding me let's fucking go all right then let's kick it off right
Starting point is 00:07:42 from the beginning sup freaks we are in my uh screened in porch in austin texas uh what time is it we're about 1400 15 hours away or yeah 15 hours ago we recorded a podcast at the unchained capital offices rabbit hole recap but uh this is a holiday special a spooky holiday special halloween special a halloween special um we're here with our doubt obviously if you didn't read uh the title of this podcast and what's today's date 22nd october 22nd so this will be released in nine days in nine days yes or maybe i might release it saturday the day before halloween we'll do it hollow's eve mischief night i like it night yes uh should we have a theme should we have like a spooky theme like what scares the shit out of you when it comes to bitcoin people thinking that
Starting point is 00:08:33 the etf is the same thing of bitcoin that's pretty spooky yeah it is very spooky shit coin it is it is worse than a shit coin we had this discussion last night like i would take wrapped btc over over this etf 100 yeah think of how perverse that is there's some subset of the population that is getting access to shares the btf the etf getting exposure to it and thinking that it has anything to do with bitcoin and the perverse thing is what's your what's the prize you win from the etf more fiat currency yeah a debasing cock buck right yeah oh and then people say like they use it as an excuse oh it's like an easy way to get into your ira but like you can use unchained capital right now easily and hold the actual keys and do the ira so i don't even think
Starting point is 00:09:21 that's a good fucking excuse no i mean again we said this last night uh i think people look like oh i had my 401k it's like not giving financial advice but i liquidated my 401k and just have been stacking sats uh since then i love it that was years ago i've also had never had a job that allowed me to contribute to a 401k in quite some time so um that's another aspect of it too maybe i'm a bit biased because of that but yeah i think uh it is spooky that the etf is going to swindle a lot of a lot of people out there i guess some people have like the way the company manages their 401k like the etf is the only way they can get exposure with their 401k right i think that's true yeah well some people have been using gbtc as well right right but gbtc
Starting point is 00:10:08 is even worse right yeah it is yeah it's like trading it i wonder what discount it will be at in eight days it's going to be an etf dude they're rolling it over oh goodness you know it's fine if you know what you're doing what you're doing is making a bet on the price of bitcoin that pays out in dollars which i guess i don't know it's the equivalent of playing fantasy football versus actually getting on the field for the eagles you know there's some sort of relationship there just don't think when you're playing fantasy football that you're the starting qb no you're completely divorced from the experience you derive none of the benefits from bitcoin you don't have permissionless money you don't have self-custody you're just if you're lucky getting a few more
Starting point is 00:10:48 dollars in your ira i'm not gonna tell you to go buy tesla instead but you should probably explain to yourself why you're not buying tesla instead but doesn't like there's a huge aspect of this market already i mean i don't even know if we could call them bitcoin users but that just like keep their bitcoin on kyc exchanges and then you know try and time the local tops and local bottoms and they're in the fiat mindset like that's got to be a huge part of our market share easily but that's preferable to the et like i'd rather people do that why is it preferable just in case they have an aha moment they realize oh maybe i should hold this they have the ability if the exchange allows withdrawals right yeah if it's something like robin hood which is trying to
Starting point is 00:11:29 apparently apparently they have a million people on their waiting list to be able to withdraw cryptocurrency i'm of two minds with this because on the one hand you can't help it those people are going to show up no matter what you know it's the same thing it's the third time we're doing this so i'm going to make another early internet analogy you know if everybody who needed to get access to the internet had to have the same user experience as the early days where you had to set up your own router and your own firewalls and know all the ins and outs of like ppp point to protocol and setting up a modem and all that the internet would never have achieved the critical mass that it's gotten to today some people need that you know just log in and click a button and
Starting point is 00:12:06 get shares that somebody else holds experience i understand that but on the other hand the more there are of them and the less there are of us there's a tension between you know the entire ecosystem sort of ends up catering to the people who are fine with custody so what does that look like are we going to have less vendors shipping us nodes how many different vendors are there that are shipping like raspberry pi knows there's noddle there's like pre-builds yeah noddle now umbrella is uh uh my node store on my node shipping pre-builds uh start nine shipping that's a pretty healthy ecosystem people that are enabling self-sovereignty healthy is like a strong word there it could be healthier sure but there's like no margins it's like a kill it's
Starting point is 00:12:53 like a yeah i think umbral ends up cannibalizing that because you know that's why umbral has such a restrictive license right because they're trying to make the app store the monetization and like the additional services like umbral has a very slick um encrypted lightning backups and like i don't think they charge for it yet but like they could easily get away with charging two dollars a month for that and they charge in sats and then you already have the wallet already up you pay with lightning and you just pay them right yeah so that's like the monetization model they're going for the actual hardware and you see a lot like um well you can download umbrella on any hardware you want it to right yeah exactly but and then and but they still get the app store
Starting point is 00:13:33 revenue in the future right that's that's like their monetization scheme and then the other one is like you have someone like noddle who like clearly it kind of seems to me that they're the consumer product the the node is almost like uh like to give back to the community it's like a pr kind of i mean pr is a bad word for it but it's it's like an it's like an image thing it's the brand it's it's it's their ethos it's a message like the noddle cloud which is like they're similar offering to like what voltage does is probably the money maker in the long term if they're going to be successful like i don't know and like we kind of see that in the computer market right like it's they all cannibalized
Starting point is 00:14:18 each other and then apple just came in at the high end and like cleans up the majority of the profits this brings a question to mind and i want to ask you both what you think of this because i'm still thinking it through what's the trust model you would have for sharing a node with someone else because when i think about this i think of like i wouldn't trust a random internet access point at you know a mcdonald's or whatever without going through vpn and making sure that a my information was uh protected by hdps and all that i would be concerned about sending my credentials to like log into my email over some untrusted network but i'd be fine doing it in my parents house because you know my parents are my web of trust what does that look like for bitcoin would you guys be fine
Starting point is 00:15:02 for example signing transactions and broadcasting them at each other's house at each other's nodes you know each other pretty well at this point is that personally i would be um i think matt would have a different answer to that betray him well light lightning is a little bit different trust model right but like if we're talking about like electrum servers yeah like i i think like even if it's just a nim that i'm like friendly with like i can use his like tor tor address for his electrum rust server and just hook it into sparrow or something and like that trust model is not the worst trust model in the world um obviously you don't want to just do that with like anybody but i mean it's like the uncle jim thing we talked about right yeah and in that model even if it's
Starting point is 00:15:44 a nim that you're trusting you've never met maybe they are malicious but like it's like if you're just going to connect and trust electrum servers you're essentially doing that already anyway so yeah it's just like distributed more right so it's you know maybe 10 people are using that Electrum server rather than 10,000. But then on Lightning, it's a whole different ballgame because if Marty's trusting my node,
Starting point is 00:16:09 not like my node, the company, but like my fucking node, and he's running his Lightning on there, I can do so many different things to steal his funds. With the Electrum server, it's more of a privacy thing. I mean, you can tell
Starting point is 00:16:25 him he didn't get a transaction that he got, but he can always just connect to another server and and c got that transaction my state history is on the lightning node and you control that right and your funds are yeah i think that's right yeah and i can just disconnect you and then fucking broadcast a bad state or whatever i can do all this different stuff even if i don't have access to your keys which is where they're like which i kind of feel like is where you were coming from a little bit there's these cloud node providers yeah um they're like technically non-custodial they don't have access to your keys everything's all the data is encrypted it's all
Starting point is 00:17:02 encrypted but you're running on their hardware um and there's all sorts of malicious things they could do but to me what it is is like a it's kind of like a regulatory arbitrage play because it's technically not custodial where they like fill the gap of where a noob might come in and have a small amount of funds on like custodial wallets right and the custodial wallets all have to implement kyc on a long enough time scale but maybe the cloud services don't i mean even in the cloud service model if they did fuck with their hardware like say they like turned your node off and you didn't have access you could always access your private keys and your state and your history and upload that on hardware that you and yourself would just be an inconvenience
Starting point is 00:17:46 temporarily correct i think i think if like a voltage or like a noddle cloud like wanted to take your money like they could take your money interesting maybe not maybe not the funds you have in the on-chain portion of the lightning wallet but almost definitely the funds on the they'd be able to take it or they would just be able to have you lose it to them they'd be able to drain it would they be able to drain it to themselves i mean i i i don't know enough about the technical specifics of each of these implementations but there's definitely a it's not it's trust minimized it's not like trustless there's uh i mean just think about like the early days like where every bitcoiner learned
Starting point is 00:18:35 that like if you're running an exchange you can't just like have the hot wallet on a server in some like vps somewhere oh this gets right to it the threat model idea because it ties into you know The question for those early exchanges is, when does the amount of funds in the hot wallet make sense to exit scam, right? Right. So for Voltage, I mean, does it make sense for them to try to screw you over for $50, $100? Depends on what their time preference is. If they realize that, you know, numbers are always going up and we're eventually going to take over the dollar sign for Satoshi's, then maybe. But probably in the short term, it makes more sense for them to operate a profitable business
Starting point is 00:19:12 and to play nicely with you and do their best to make sure that your $50 is... 100%. Same with the custodial wallets, right? But the custodial wallets have to implement KYC, while these services might not have to implement KYC. And I keep trying to make the distinction between Lightning and on-chain. Because for instance, you could use Voltage. You could spin up a BTC pay server super easily,
Starting point is 00:19:31 pay them $30 a month or whatever it is, run a beefsteak or something like that. grew that and all the funds could go directly to your hardware wallet like you'd have no funds on on the server even though you're running btc pacer on their server but lightning has this hot wallet requirement where it's got to always be online your funds always have to be hot you know the server's got to be running and that's where like all the risk comes in yeah i will note since you just gave me the opportunity for that matt corrales sent out a email to the lightning dev mailing list I think last night, you know, brainstorming ideas for how could two Lightning users manage payments between each other if one of them is offline.
Starting point is 00:20:12 Spoiler alert, even less trust minimized. It's still an extra layer of trust ends up being involved with LSPs. I'll leave it to you at home to Google the mailing post list. Matt Corallo, I think it's a mobile Lightning user. The routing node in the middle, right? Is that what it is? Yeah, that's the basic idea. It does a rendezvous and waits for the other.
Starting point is 00:20:35 And that routing node's online, but one of the peers isn't. A rendezvous and voice, I love this. Would that be a different... You're going to say trampoline routing too? Two of your two favorite buzzwords? Would that risk model be any different than a watchtower setup? Are you trusting that watchtower? Something similar, a third party in the mix
Starting point is 00:20:53 that is trying to make sure that the two peers play nice. The watchtower's less trust. Yeah. Because the Watchtower doesn't have access to funds. Right, I think the LSP. Yeah, because the LSP is acting as essentially a custodian. They're like keeping the ledger. Well, we're not going to use the word custodian.
Starting point is 00:21:15 Yeah. What did you say, quasi-custodian? A deliverer, a delivery man of the funds? It's like a quote-unquote non-custodial. Yeah. Fascinating stuff. Yeah, we're finding out a lot about, I think, how the term custodial can be sort of arbitrage,
Starting point is 00:21:32 for lack of a better way to put it, because there's someone who has custody of your funds and someone who can deprive you of access to your funds, and those aren't necessarily the same thing. Yeah, yeah. There's a lot of nuance to all this. Lots of impact here. The routing node could, in this situation,
Starting point is 00:21:48 I guess it's still an HTLC, so the routing node in the middle can't take the funds in the middle, I presume. yeah it just prevent them from moving along they could say you got paid when you didn't get paid or say you paid when you didn't pay and then presumably like the reason you're paying someone in an offline kind of mobile fashion is because you just like bought a coffee from them or something so then you just lost the coffee if that payment didn't actually go through yeah right like if you're the merchant you just sold a burger to someone and then you you go back online
Starting point is 00:22:19 you realize that the lsp you know fucked it up and and you didn't actually get your payment so So that ends up devolving to a reputation problem. As an LSP, you get to do that exactly once and then people don't trust you as an LSP, right? It kind of reminds me of the state chain model where the state chain coordinator can't steal your funds unless they collaborate with the other peer.
Starting point is 00:22:42 But in a really malicious exit camps situation, they are the other peer. So they're not collaborating with anyone. So they wait till there's a lot, a lot of usage. And then, I mean, in my offline thing, thing it doesn't make as much sense but like then they go out send their minions out to buy like a shit ton of meat and a shit ton of
Starting point is 00:22:59 like guns ammo like store value things bleach you know things that'll hold their things and then they just do one massive exit scam on it never heard bleach has a store value yeah the low income communities you can use food stamps or you can use not food stamps but whatever they call it EBT cards EBT's to
Starting point is 00:23:15 buy like Clorox and stuff and they have really good shelf life so that's like used as a as a means of an exchange i never i never realized that yeah fascinating tide is apparently the preferred unit of account in new york city yeah yeah give people if people have a need they find a way right and then um bringing it back to like the custodial thing and i don't want to get too far away from this lightning conversation that we're having is fascinating i think these oh before we get to what i was just about to get to uh have you guys seen like the ln i know you have
Starting point is 00:23:47 because we've talked about but like the ln url withdrawal function and the stuff that the cool stuff that's being implemented around that i think it was discussed last night at bit devs actually yeah yeah and it's like offline you can use like nfc touch payments you essentially like load up a lightning debit card if you will with certain amount of sad so you can then withdraw i don't know if it needs to be the exact amount that you're withdrawing from a particular invoice so you go to pay coffee you have to load up your ln ln url withdrawal wallet or whatever i don't even know nomenclature around it with the exact amount that you're about to pay um but i think that's an interesting i don't understand like what that really solves because the merchant is still
Starting point is 00:24:30 online so that they can actually verify that you're paying them so if if the person you're paying is able to be online like can't you just have like a wi-fi hotspot there and like your customer just connects to the wi-fi hotspot to pay you maybe i don't know that's why we're talking about this like that is it overkill to do l and url withdrawal in this in this instance is that what you're trying to say or it just doesn't make sense because you should if you're paying in person you should be able to access your lightning node and be comfortable paying because if you pay they don't give you the the goods you can just be like what the fuck like i've never come i mean like i feel like the bigger pain point is that if you're running a mobile wallet and i'm trying to
Starting point is 00:25:18 pay i'm trying to pay you fantasy dues for fantasy football and because it's a mobile wallet it's not an always on node so you're not necessarily online but you know i i wake up in the morning like oh shit i haven't paid marty and i just want to send you a payment but you're not online right but like when you're talking about like merchant things you know most people have cell phones most people are going to be using a cell phone mobile wallet already they're going to have internet connectivity at the point of payment when they open up their wallet it's going to connect to the network um and then on the receiver side where l and url is pretty cool is that you can print out like static qr codes which is also what i'm kind of hoping bolt 12 comes in to do if that actually
Starting point is 00:26:01 gets implemented but like you can like you can imagine like if you're like a like a shack in El Salvador, you can have just printed QR codes of all your menu items, and then the merchant doesn't necessarily have to have an online device ready to go. They still have to have the LNURL server running somewhere, though.
Starting point is 00:26:20 But I guess options are good, just to have as many options as possible. Yeah, I think LNURL and BALT 12 offers are complementary. We're going to have to have some both. They don't necessarily both cover every possible use case. Yeah, I mean, it just highlights how much needs to be figured out, how much
Starting point is 00:26:36 work needs to be done and how many unknown unknowns there are which many can see as spooky but it's also exciting and there's there's a lot to be done a lot to be figured out and if you're somebody who's looking to actually build things that are worthwhile useful and give you some some sense of meaning and purpose these are problems that need to be solved and i would consider working on if i had the uh the technical capabilities to actually do it talking about ln url i really like the combination of ln url auth deposit and withdraw or ln url pay i guess not deposit like so like ln markets which is like uh lightning only like bitmex type of site lnmarkets.co i believe yeah and you you like open it up you scan the qr code with your wallet to
Starting point is 00:27:29 sign in you don't have a username and password so it's tied to your wallet through lnurl auth and then you do lnurl pay by signing scanning another qr code to actually pay to deposit into it and you do your trades and then you use then you scan another qr code to withdraw back to your wallet like that seems like a very clean flow yeah i agree i agree i'm big on lnurl auth especially in a world where WorldCoin is being rolled out and they're going to want to use your iris as your authentication token. Technically retina.
Starting point is 00:28:02 Retina, whatever. Are we going to clown on WorldCoin for a bit? I feel like all of us have some WorldCoin content stored up in us. This is an episode about spooky things and I would consider WorldCoin that is forcing you to look into the orb to produce a private key is very spooky.
Starting point is 00:28:17 Do you think they'll still be talking about it in eight days? No. I think they might. It might be infuriating. You saw the cast of characters in that fundraising round in the pre-mine. A16Z, Coinbase, Multicoin, DCG. We were talking about BitClout for a while. A lot longer than you would expect a BitClout to last.
Starting point is 00:28:37 This seems like a stronger shitcoin than BitClout. BitClout was really fucking half-assed. These guys have orbs in different countries right now, and they're like paying part of the pre-mine to the orb operators to onboard people like it feels more like one coin ish or like uh like a salon or like a tron or something like that where like there's like uh the thing i don't get is if you're gonna do that like have orbs collecting like retina information all across like the third world why be half a supervillain i would go all out and get like a robe and like a snake hood go like oh gee i just throw be like this is who i am
Starting point is 00:29:15 they send you the robe right like here's your orb here's your robe here's your hat like and like so let's keep diving in like the orb it's fucking scary shit you scan your your retina and like they're trying to market this as a fair distribution so it's inherently not fair i assume the price is free floating so for it to be fair you'd have to have everybody scan the retina the exact same time and exchange rate right like you're getting ten dollars worth of world coin it's weird that it's the airdrops based it's just such a shit corner mentality right that the airdrop is denominated in dollars instead of world coin right like it should be like you got a thousand world coin or whatever the fucking amount is yeah yeah like so right off the bat
Starting point is 00:29:59 it's actually not a fair distribution like can people they have a pre-mine could you sybil like i guess i want to be a sybil attack but like on the road to us like what if you what if you go get your ten dollars with your right eye and then next week you go with your left eye scam both eyes oh they do okay and but retinas aren't perfect like you can have damage and stuff but it's only ten dollars so like hopefully like actually there was an eye doctor at bit devs yesterday and he came up to me afterwards we were talking and he was like he's like yeah you can like fuck around with the retinas and stuff but it's like it's expensive and it's dangerous to your eyes and you're only getting ten dollars of a shit coin yeah so that's the thing it's not worth very much
Starting point is 00:30:35 i don't know how much it costs to take a 4k resolution picture of someone's eyes from facebook and then print it out and then put it over a silicon prosthetic eye and scan that but we're about to find out if it costs more or less than ten dollars that's what it's that's a good point uh fucking world coin what are these people thinking matt had a great point yesterday during the recap everyone is forced to find out by themselves from first principles how distributed proof of work is the best means of exactly getting coins into people's hands you can try to come up with any sort of rube goldberg mechanism to like get around that but at the end of the day this is the best we have it was absolutely hilarious like i saw like the vcs
Starting point is 00:31:16 posting on twitter and they're like the issue is is uh you need a civil resistant mechanism for fair distribution and we spent months trying to develop the way and everything has pitfalls but we've discovered this orb this is completely oblivious they're like are you fucking kidding me It's been around for almost 13 years now. It's called Proof of Work using HashCashShot256. I wonder how it ends, whether it'll either be vulnerable to some sort of attack or even better, what I hope is that someone launches,
Starting point is 00:31:50 I don't know, what would be a good competitor name for the orb, the iris, whatever. Why do we trust these people to do this distribution when what's behind it is a cute little techno gimmick that gets around the problem of fairly distributed coins, why don't we just wait a few years for someone to come around for the next cute techno gimmick? The Orb 2 electric boogaloo.
Starting point is 00:32:12 Well, how does it even work, the distribution? So you scan your retina, right? And I assume people aren't walking up to the orb. I know too much about this. You scan your retina at an orb station, and the orb station is run by a local Ponzi operator, right? And so the local operator gets the orb. They probably pay something up front.
Starting point is 00:32:32 they do like an onboarding process to get the orb and then you they stand there and they they shill orb coin to you and then as soon as you you scan the retina then you open up like your mobile wallet your your world coin mobile wallet and then they send you your pre-mine they like register it to the hash of your retina and then they get a portion of the pre-mine as well so like they get a vig every time they onboard someone so they're incentivized to try and onboard as much of their community as possible evil hey get as many retinas as you can into this fucking database she hashed it into this blockchain this is an erc20 token so they didn't even have to like make a new wallet or anything it's just in like an ethereum address it's metamask gonna gonna start
Starting point is 00:33:17 enabling world coin it probably already supports it because it's an erc20 yeah that was the weirdest thing to me i had to follow this i don't know it's like if you're gonna go shit coin like go full shit coin like they don't even have their own chain of like centralized chain that they created yeah they have their own hashtag on twitter how do they not have their own chain it's weird they have like a symbol the world coin symbol behind it you can just buy them now yeah bitcoin was the only one that got it for free that was a funny thing i saw earlier today too like what's old is new again there has been a world coin before like somebody already thought of course there was like probably like a fair pow launch world coin back in 2013 there was
Starting point is 00:33:52 aurora coin remember aurora coin they dropped it on which country was that norway uh yeah yeah they didn't there i forget aurora coins you had to like show your id and you got a was it cyprus i want to say norway it wasn't cyprus it was one of the scandinavian scandinavian countries i think norway sounds i mean aurora coin you have the uh or what is it the uh what is the uh thing in the sky yeah something aurora man i hope it's not norway now because if i still remember that after eight years those brains have shit coin trauma gentlemen is it the aurora borealis is that that's what i was thinking of yep hit our scholarly matthew uh well see if i can hung over too so you can speaking about spooky and i what i wanted to
Starting point is 00:34:40 go to earlier before i got distracted by uh ellen url um going all the way back to the etf conversation in the beginning and the fact that these etfs specifically the physically settled ETFs are going to be amassing you would assume a considerable amount of Bitcoin and so you have that custodian the ETF fund whether it's the fund
Starting point is 00:35:04 itself which I doubt will happen or like a NYDIG or Coinbase custodying that much Bitcoin on their behalf is that spooky we always say it doesn't matter how much and this is something I've been thinking about recently because I had a lot of
Starting point is 00:35:19 noobs and alex berg actually hopped in a thread where somebody asked this uh asked me this question a few weeks ago and really like reminded me like brought me back to like the segway 2x and the fork wars yes these custodians will have um a lot of bitcoin they can't really change bitcoin consensus but like the whole con what i want to describe to freaks who may be newer is the the concept of an uh an economic full node like a full node that has a lot of bitcoin utx's moving through it like do they have more power than uh say somebody running a full node with a million sats on it i think i see where you're going with this you know there are some other uh alternative coins that have this idea of proof of stable coin issuance where a stable coin is issued as a
Starting point is 00:36:11 colored coin on top of the of their chain and so the correct version of the chain is whichever version that the stablecoin issuer decides the correct version of the chain they'll only honor claims on one chain so that prevents contentious forks so like on eth if it was like if usdc and tether decided that they wanted to on what on eth what's that if usdc and tether wanted to stay on one chain in a fork situation most of so-called defy is using them and then so that all the other projects will be basically compelled to continue on whatever chain they decide exactly and the problem with that is what you've just described is an alternative mechanism for reaching consensus i mean what's the point of having proof of work or even proof of stake or federation if you're
Starting point is 00:36:57 just going to leave the decision to decide what valid chain is right to paxos or bitfinex or whoever so this is sort of the equivalent like are we going to see etf issuers make the decision as to well this chain is not necessarily the valid chain but it's the chain that we associate with our ticker symbol and because there's so much money backing uh our ticker symbol and going through it we've got some alternative incentive besides proof of work to decide which chain is valid we kind of saw that with gbgc if i remember correctly like they weren't honoring bcash at first they were like we're on bitcoin chain and then ultimately i think they had to like pay out a dividend or something worth of coinbase had to do it too yeah they would no coinbase think
Starting point is 00:37:46 oh coinbase also they waited right before they supported because they were like december 7th because they were like segway 2xers they wanted segway 2x so they stayed and said be cash wasn't legitimate and then they started getting sued yeah so i think these like like i think like market participants will will like compel these if it's a big like if it's a big enough fork market market participants will compel these custodians to honor it through like traditional legal means self-custody people will be unaffected um but like even like we have there's so many shit like absolutely like bcash is a shit fork but there's like really shit forks like they like coinbase never on or like bitcoin diamond or like bitcoin gold or any of the other
Starting point is 00:38:34 ones um because they were just they never had any kind they were never legitimate at all it wasn't even close yeah they never had any kind of real market value i guess but wasn't there something legitimate because i'm not going to call bcash legitimate at all either wasn't there something around like bit 148 like if i remember correct again feels like ages ago like wasn't there like a thing is like not only do you have to run a bit 148 node to do the user activated soft fork or whether you're running bit 91 or bit 148 it was important to actually move bitcoin to those nodes as well to move utxos to say i'm moving value the economic nodes you're thinking about is like And usually it's exchanges is what people say.
Starting point is 00:39:17 Like their nodes are, they have a high amount of transactions. They're validating a lot of transactions. Like if you're just hodling, you know, your node isn't really, it's enforcing the rules for your savings, right? But you're not, I think the key takeaway that's really important here is, yeah, so you have the stable coin issue on a lot of these so-called, like smart contract type chains um which just seems to be adding on top and top and top um but the key thing with bitcoin is that having more coined does not give you more power over the
Starting point is 00:39:56 network and the big divide is going to be all these chains that are proof of stake because you can imagine a situation where there's like a black rock etf of ethereum after proof of stake and like the main validator is fucking black rock on your chain and then whatever they say is is is the way it goes and that's that's that's really scary like that's exactly what we're trying to get away from yeah yeah i think black rock has any world coin yet you think larry fink went to the orb so they they listed all the uh vc investors but they didn't uh list there's 70 the individual investors that they didn't list so we don't know who they are interesting interesting um yeah so there's no so yes i still probably doesn't i still want to lean into the economic
Starting point is 00:40:56 full node thing because i remember that being a huge topic i don't want to clarify it like for the freaks i think the fear was like if i remember correctly with the economic nodes the fear was like uh it was specifically with sega 2x rather than bcash because bcash never really had that kind of momentum um but the fear was like that coinbase was going to go segway 2x poloniex go segway 2x bitfinex go segway 2x and then you know you you you won't be able to to sell your original chain bitcoin you'll only be able to interact with the segway 2x chain on you know all the major economic nodes but to me that was always it was like a concern but it was like almost more of a theoretical concern because at the end of the day like i can use bitcoin without
Starting point is 00:41:43 one of these large exchanges and you know the whole point is like trusted third parties are security holes so like why um like i think it would be like a short-term damage type of situation rather than a like a long-term network kill yeah yeah i agree it's like there's these things there's so much to remember and like bitpay was big back then yeah we didn't have bcc pay server yet so So if BitPay and Coinbase Commerce both decide that they're going to go SegWit2x, remember BitPay sent out the letter getting ready for Bitcoin's big upgrade, right? And then all of a sudden all the merchants that, let's say you live full-time on Bitcoin and you're used to topping up your phone minutes with a BitPay-enabled processor,
Starting point is 00:42:27 then the only choice you have is to use whatever fork they push, right? Yeah, yeah. Spooky. very spooky yeah i think you think i think the network's sincerely more robust and resilient yeah i think that was a very good lesson learned at that particular juncture i think there has i mean the full node adoption um has considerably picked up since then i think it was a direct result of that we all had to go through that experience to realize just how important it was to be self-sovereign to run your own nodes to make sure that you're not relying on coinbase or Bitfinex or whoever to decide what the valid chain is.
Starting point is 00:43:06 And it doesn't need to be everyone, though. I hope as many people as possible are running their own nodes. It just needs to be enough to put the fear in the minds of anyone who would imagine themselves as being some sort of Bitcoin cartel that gets to unilaterally decide the fate of the chain. There'll be enough people transacting through their own nodes that you either have to make the choice
Starting point is 00:43:28 to obey the same rules as everyone else or you're on some different ghost chain that you have no idea what the freaks are running or if they're ever going to interact with your chin. Yeah, I guess the best chance a nefarious actor ever has of actually successfully waging that type of attack on the network in the future would come with a successful social attack, which Segwit2x was obviously very unsuccessful,
Starting point is 00:43:53 but maybe the CIA, the states, or something can try to do a better social attack at that level. surprised we haven't seen more you know fork style attacks uh in general maybe not necessarily against bitcoin but against like the low-hanging fruit shit coins um like i like i remember like early days of ethereum like i theorized that there'd be a market uh there'd be like a market for someone just forking eth clearing their state and either starting without a pre-mine or starting with the btc utxo set like the tip whatever the tip of like a clams drop or something like that no but not like clams was like there was a pre-mine there but like if you just completely
Starting point is 00:44:41 wiped it and there was no pre-mine you remove the pre-mine and you just put the um you put whatever the current state of bitcoin is at some block height like you pick a block height that was like two weeks ago and you say this is the ultimate ledger of truth is the bitcoin blockchain and now we're going to take ethereum smart contract functionality remove the pre-mine and put it with a fair ledger on top and then would it be long-term successful like probably not because bitcoiners don't want to use ethereum but like it would cause a ton of turmoil like if you shorted ethereum at the same time like people would start panicking if you're like a major eth holder maybe you'd swap into the new bitcoin eth or whatever and you could like rinse and repeat that on on
Starting point is 00:45:22 like all the shit coins and we haven't really seen that like we saw like half-assed attempts like bitcoin diamond like you said clams like they all had pre-mines and like they're doing like bitcoin private was like there was super dirty where they had like the fuck's that dude's name fast mine something ret yeah rec creating that damn armor dude wait yeah no i remember i remember all that rec creating yeah nick carter called him out coin metrics caught that inflation bug they like a pretty crazy inflation bug in bitcoin it was a feature yeah yeah uh yeah because they discovered it was like one of his prs that got merged that uh yeah that actually led to the inflation bug that's like the thing right it's like the cool part about bitcoin is that any
Starting point is 00:46:06 it's permissionless anyone can fork it if they want to now it doesn't mean it doesn't mean that it will be the dominant chain but like the three of us you know tomorrow before this episode drops we could we could fork bitcoin we could change the algo not do a pre-mine or anything and just release it out and be like you know this one has two minute blocks it's faster that's what litecoin is right no but litecoin didn't start with the bitcoin state no right and you could play all sorts of different games there with you know oh this is an asic resistant algo okay so now it's it's bitcoin without asics and just cause like a bunch of market turmoil by doing like a four it's like you know that's that's a very interesting concept to me and no one really
Starting point is 00:46:49 does we've never really seen that it's all like what do you think that is you think that people want just like the quick fix of a pre-mine you know yeah i don't really want to go through all that effort to like because again there's like a social aspect it's like a scammer versus like a nation state like if it was like a nation state attack that's a good way there's a nation state attack they get the benefit of just bitcoin possibly failing well i would praise that it's a scammer versus pro scammer right yeah scammer versus pro scammer or like even like a like a hedge fund like maybe it's just it's low-hanging fruit right like if they can just make the money out the pre-mine it's easier to do you don't have to worry about shorting something or trying to
Starting point is 00:47:24 monetize through another means um it's the scammer mindset it's it's all about time preference the scammers thinking about their immediate payoff and they've got bills to pay it's not free to get any of the stuff listed on coin market cap or on binance you have to actually pay the piper yeah it was like a big thing on polo and bitrex back in the day pay pay to get your coin listed i love when people talk about their shit coins and like organic community adoption like oh yeah did the community cut binance a million dollar check to go on the exchange cool uh binance binance dying is fd like i think sam tabasco ate their lunch yeah x is uh yeah you can't be half a scammer man you can't be they they're like 90 percent shit coins but you got to go like 110
Starting point is 00:48:07 percent listing lumber futures yeah like fake tesla stock you see spf's raise that he announced there's like a meme raise 420 million at 6.9 billion valentine it was 69 billion or 6.9 billion no it was it was 420 million 69 000 dollar raise so 420 69 raise and it was 69 investors see it's just as ridiculous as that is i prefer to like the whole we're building the future of france bullshit like nope we're memeing our friends in 420.69 yolo yeah trading doggie coins all right bro yeah and they uh he's paying what he donated 10 million to biden's administrator campaign but he's getting into all the sports he's got brady on sunday pumping ftx he's got the miami heat arena the block folio acquisition was a really good uh yeah play for retail you know
Starting point is 00:49:06 shit coin adoption yeah it's like they have they have a nice mobile app you know most people nowadays just they do everything on mobile that's what like so many of our super bitcoin geniuses don't realize like i had a like i'm this is very tangential but like i had a wax wing and belcher on dispatch to discuss bitcoin privacy and uh i said to waxwing um like what do you think about join market on mobile and he said if you care about bitcoin privacy you shouldn't use a phone and i was like dude like there's gonna be there's gonna be like six billion bitcoiners that are using mobile phones to interact with their bitcoin it's already inevitable where there's not there's no way you could stop that so you got to try and just lean into into the mobile world as much as
Starting point is 00:49:53 possible you have to most people don't have computers now they just have a phone yeah i mean anything where where bitcoin penetration is the strongest in terms of i like to use matt alborgs uh like his internet access and gdp index like the place like useful tulips right yeah like in nigeria venezuela argentina i think these people are all mobile maybe not argentina as much as venezuela and nigeria but like the people actually need bitcoin interacting with it like el salvador most people are using mobile like you you have to accept that fact and then design around it i hope this is the next thing that bitcoin actually fixes we actually what we've accomplished in the past four years of bitcoiners getting people to run their own nodes is not
Starting point is 00:50:43 something i've seen with any other peer-to-peer technology there are seed boxes for bit to iron sure and some people run torb readers but not nearly enough compared to like the population of people that benefit from those technologies bitcoiners run their own hardware the current mobile phone ecosystem is i understand wax wings uh reticence because it's just a dumpster fire i mean you've got your choice of like do you want to have your privacy violated by apple's app store or by Google Play. Yeah. And, like, all the chips and just...
Starting point is 00:51:11 Yeah, everything's proprietary. You have to... Yeah, it's all tied to your IMEI and your phone's billing information. There's a tremendous lift there to actually get from where we are now to privacy. I don't want to dox anyone, but I think someone we might know
Starting point is 00:51:25 has a setup where they've got a CalixOS on one phone and a Normie iOS phone, and they use the Normie iOS phone for their doxxed identity and their CalixOS pixel phone connects to it as a Wi-Fi hotspot, like, literally, that's NSA-level security.
Starting point is 00:51:42 You have two separate devices, you know? A computer over here and a computer over here. That's how they do it at the three-letter agencies. That might be what we have to start doing. Yeah, I mean, and that person's still getting owned. But, like, at least you're... The thing is, like, we can't let the perfect be better than the good, right?
Starting point is 00:52:00 Yeah, perfect can't be the enemy of the good, yeah. and like most of us are just gonna you just you can't put the nsa in your threat model yeah they've already they're already in snowden snowden basically made that very clear do this did we just find our way to the tour part of the discussion is that yeah it's another thing we wanted to talk about in the spooky topics tour being one of them it's gonna be the name of the episode spooky topics yeah it's this is a double entendre here in this particular uh part of the episode uh spooky spooks so on the the recap yesterday matt asked a salient question do you trust tor and we've been talking about it uh before the i didn't say trust like i said can we rely on can we rely on
Starting point is 00:52:44 tor that's a great way to put it um and what you touched on earlier what's your threat model is your threat model the nsa and nation state actors i think i think for lightning it it is like as a whole network rather than the individual so here's my way of working through for first principles i think we've heard other people make different arguments i'll try to make a new one that hopefully the freaks can follow and wrap their heads around okay you're worried about nation state actors and having them get in the way of your communications what do nation state actors use to play against other nation state actors when i don't know the pakistani isi or is going up against the russian kgb or india's is it our research warfare agency i think is their
Starting point is 00:53:30 intelligence agency do they rely on toward the spooks rely on tour they use dead drops and secure computer information facilities they go full offline well like putin uses like typewriters right he just doesn't even completely all network communications offline so if they're using a fundamentally different creative technology what hope do we have bringing the knife to a gunfight you know maybe we should be doing dead drops of open dimes so like we have but then does that just mean like lightning's a non-starter like we have right now there's basically as far as i'm concerned you have like two breeds of lightning nodes routing nodes you have that are both always online you have the like the doxed ones that are running on clear net on always on high performance
Starting point is 00:54:10 servers everyone knows where they are most of the time they're run by regulated businesses if they're not a regulated business yet they do enough lightning volume they'll become a regulated business and then you have the the onion side you have the tor nodes that are mostly run by like plebs we have pleb net and stuff like that they have a node in their house um it's they control the hardware themselves they're running it through tor lightning trust model so i they provide a check even if we have a lot of the volume going through the regulated clear net nodes they provide a check because some hops can go through the onion nodes and you always have that as an option you can go over there now imagine a scenario where where tor goes down for two weeks
Starting point is 00:54:55 and so the onion nodes all all lose access for two weeks and they have you know half the network half the lightning network goes down and all you have is the regulated side um that would do long-standing forget about if funds get lost or anything like that i don't i'm not even saying necessarily that funds get lost they just all lose access for two weeks and we had kind of a similar situation where tor was having ddos issues and i still to this day don't understand how tor is civil resistant at all like it seems like it's just super easy to ddos let alone like if the operators wanted to take it down so are you trying to get to like if this scenario happens you could use a process of elimination heuristic to sort of dock i would just say like half the nodes are off
Starting point is 00:55:40 the network and they're the important nodes to me right and like they're the private sovereign nodes they're all off the network um you've just basically turned off sovereign lightning and you only have corporate lightning left well does that do that would do just purely from a reputational damage kind of like adoption kind of you know lightning network is the future could substantially hurt lightning long term in terms of people like relying on and trusting it and that's because we put all this fucking trust on the sovereign side on tor itself well and this makes me think about again two questions that we touched on last night but i think they bear repeating and probably a bit further consideration explanation around like number one can you somehow incentivize
Starting point is 00:56:23 not only incentivize the running of exit nodes via the lightning network but decrease the potential for civil attacks by making them expensive by injecting a cost to routing them on Tor and then number two should we just grab tour all together and focus on building out something like a mesh network that could potentially be more robust so my two sets is that we're going for I've seen yeah I think we can't rely on any one technology I do think for the use case that you just outlined the idea that lightning is going to be resistant against a global passive nation-state adversary i don't think tor is resistant to a global passion passive
Starting point is 00:57:07 nation-state adversary so lightning through tor doesn't seem like it would be viable in that scenario so it's just not well but let me finish lightning is a overloaded term there's the lightning gossip network that you know you can spin up a lightning node now and find all your lightning peers and find routes to them everything and then there's payment channels i think the general idea that we're going to see is what we've seen oh god i always bring back everything to the internet so there's your private home internet and like you know your wi-fi access point you've got all your pcs and your devices that can talk to each other over here and then they connect to the outside world
Starting point is 00:57:48 i think we'll see a lightning topology if there's a need for it and maybe we're all just being you paranoid cranky old mountain men as vitalik would say you know just imagining things but i think there would be a need for community level nodes with payment channels in between each other and someone would say okay i'm gonna be the one who settles to the outside world i'll be the one who connects to the global lightning network and we have to worry about that guy's access that ends up looking not unlike a bank unfortunately it's like a bunch of small like almost like semi custodians yeah community because kind of like what bitcoin beach is yeah right where you have a custodial wallet that's backed by a multi-sig and then they're the ones connecting out to the
Starting point is 00:58:29 greater lightning network yeah so that's one way to do it another way is okay you said earlier offline beforehand that cjdns as an example and itp as an example are different methods of solving different problems cjdns for example has no anonymity but it's encrypted hop to hop right so you solve something different there itp different transport layer not quite the same network topology store not the same guarantees we're gonna need a little bit of everything at the end of the day it's going to be a game of whack-a-mole against a global uh passive nation state adversary they can print money so as long as they can do that they can throw as much manpower and as much uh resources as they can bring to bear against us so it's not
Starting point is 00:59:09 going to be any one thing there's no magic bullets i mean yeah i mean this was like something that was earlier like i thought was uh basically like consensus in the bitcoin community that the whole reason we're doing the layered scaling is because on-chain bitcoin the native protocol is as censorship resistant as possible it prioritizes that on the trade-off scale and then lightning can be more centralized a little bit less censorship resistant less state resistant but you have cheaper fees faster payments as a result yeah um but we've kind of lost that narrative now it's like in bitcoin land it's you know every payment's going to be lightning it's all going to be uh you know everything's going to be lightning network lightning's the
Starting point is 00:59:53 future and it's like a although right there will be a forcing function that makes what was old new again right something will happen and be like all right maybe yeah like tour going down for two yeah exactly uh but we just had to remember like again i think i don't know from a narrative perspective or just from like you said like since 2017 since the fork wars bitcoiners uh compared to other open source uh networks have have really put their money where their mouth is and actually spun up nodes to contribute to the network and stuff like that and i think maybe we do need a forcing function like a nation-state attack that takes down tor potentially lightning network that forces us to take it to another level building up mesh networks setting up satellites to bounce
Starting point is 01:00:37 transactions off off the atmosphere off the moon radio and radio go tennis yeah i think there's another interesting point that arbed out made that was uh like just at its core like payment channels um if if it's if it's just two parties that are having like a long-term payment relationship like that is that is pretty censorship resistant right like if if if the big one being like if like two exchanges have just a massive fat private channel yeah they're not even really connected to the greater lightning network i wouldn't even like that's not really even lightning to me um but they have this like internal ledger that settles on chain that is trust minimized and they're able to just constantly move that balance back and forth between them rather than going on chain
Starting point is 01:01:26 right yep or out to the greater lightning network right if you want to blow your mind instead of two exchanges two citadels exactly yeah yeah all right that's good i like that um you were talking about civil resistance earlier and that just what matt was talking about just brought to mind something to mind can we loop back on that yes yes sir you know how jonah market is trying to address civil resistance right now with fidelity bonds fidelity bonds i think that's a really interesting construct so the idea is you lock up a certain amount of bitcoin for a certain amount of time as a provable sacrifice and say how do you know i'm a scammer well here's my name and metadata or whatever and maybe it's embedded in op return of this transaction that says hey i've locked up
Starting point is 01:02:07 100 btc for however amount of time and you know my name is on this 100 btc so there's an implicit incentive to not try to screw you out of a certain amount of money because you know hey instead of screwing you out of 10 btc i could take my 100 btc and just have 100 btc right and like the key i think the key to the fidelity bond mechanism is if you if you lock up 100 bitcoin in one uh maker on um on join market you have a higher reputation score and you get selected more than if you split it as 10 makers with 10 Bitcoin in it. Because that's important, right? Because that's the Sybil, right?
Starting point is 01:02:49 So it has this really sleek way of incentivizing, I wouldn't say honest users, but incentivizing users who don't pretend they're many users. Right. So there's the Sybil resistance right there. What came to mind when we were talking about Tor is wouldn't it be great to have a Tor bridge node that advertised a fidelity bond,
Starting point is 01:03:12 and you could route to the ones that said, hey, I've locked up a certain amount of coins. Okay, well, I know a little about you. I know that you're unique in this way. You're not, you would need a lot of coins to be trying to fool me to be another bridge node. That could be a really clean improvement. And is it technically possible?
Starting point is 01:03:30 Can you inject a fidelity bond like that into a Tor? Just put like a hash commitment, right? Yeah, I'm going to see why not. You would need a unique ID that identifies the Tor bridge node, and you need some proof that exists on the Bitcoin blockchain and a mechanism to advertise to a peer which exists already.
Starting point is 01:03:46 The peers communicate in Tor. Did we just fix Tor? I think we just fixed Tor. It would definitely improve the situation because one of the things we constantly see is like a ton of nodes just flooding the network. Right.
Starting point is 01:03:57 And Tor is... I said wait, it's you too. It's all our doubt. Tor is such a shitcoin that their current technique for dealing with dealing with a bunch of malicious nodes joining the network
Starting point is 01:04:09 is they, like, have just, like, a centralized group that just decides which one's to ban. You're like, oh, this one just looks like it's a bad node. There's something similar like that in the Bitcoin, right? Like, there's a... Isn't there an IP blacklist at the seed... at the full node seeding level, right? Isn't there some sort of...
Starting point is 01:04:26 I think Mike Hearn tried to implement something like that to not great reviews. Yeah. There's a ban mechanism if you try to be naughty, but there's no, like, hard code blacklist. There's no list, okay. All right. Yeah.
Starting point is 01:04:38 so you can't misbehave too hard like the tour foundation like literally like sits down and decides which notes to ban yeah
Starting point is 01:04:44 it's not great CJDNS does that too there's like a list on github of like what valid notes are like great proof of github
Starting point is 01:04:51 not that I don't love grabbing scotch with you guys and not that the last one wasn't great but I've noticed an hour into this we fixed tour
Starting point is 01:04:58 and like two hours in the last one Matt was calling me a baron taking naps on my rug it's definitely been more productive
Starting point is 01:05:07 conversation midday rips uh drinking seltzer water are uh yeah are uh very good um this is our return to the jedi that was empire strikes back the second of the trilogy i'm glad you all made it through it i appreciate that i'm loving this conversation and like it feels like we're trying to be as efficient as possible but you have to catch a flight so we've got like another 30 minutes what else is there spooky that we can talk about are we done with tour now that we fixed it or is or anything because because you can apply this to it again like creating an economic incentive either not to be nefarious or to to prove that you're trustworthy um we could add fidelity bonds
Starting point is 01:05:46 to everything right yeah fidelity bonds would be cool lightning too yeah and i think we're fixing everything right now fidelity bonds on like electrum servers yeah uh because so let's describe it for the freaks who may be new to this why is a fidelity bond important right because you lock up funds for a certain amount of time and if you're a nefarious actor like you just have to hope that people would interact with that fidelity bond you can't go attack to attack way more people it'd be that much expense it'd be more expensive to do yeah you're increasing the cost of attack yeah the basic idea is you've shown that you know you've got a lot of money in one location that you're not going to move anywhere it is associated with some public information so you're saying to
Starting point is 01:06:27 everyone i could you know i could deprive you of your funds but if i were going to do that why don't i just unlock this and go yeah um now there's a couple of little gotchas there the big one is you have to make sure the fidelity bond itself is a civil you can't reuse fidelity bonds that would be the big uh giveaway so it has to be associated with something really unique which joint market does a good job of um i think there's also a privacy problem because the wallet and the coins and everything that are associated with value bond by definition you've tied it to some information that is public you can't be doing this out of your cold storage there's an interesting way to do this with tap
Starting point is 01:07:14 when i do that thing that i do after every rip that we do where i tweet about like all the stuff and all the references i'll tweet out the list there's a way to prove using taproot i think nickler and one c klr jonas right from blockstream yeah yeah he published a proof of concept of this where you can prove that you own a certain amount of uh utxos at a certain block height but not associate them with the history of uh yeah you just you can show the amount but not like what the actual address is yeah um that's nice yeah i'm trying to think how you would do That's a major benefit. Would you just have to use your own full node and have it count?
Starting point is 01:07:54 I'd have to turn on my phone and pull up the GitHub just to read it to you. We're trying to keep our phones in airplane mode to avoid the interference, so I can't do that right now, but I'll tweet it out. Yeah. Yeah, it's pretty neat. Talking about Taproot, now this is just a complete tangent. Marty had a good question yesterday that I didn't really think about. Like, to get the benefits of Taproot,
Starting point is 01:08:13 we're going to have to close all our Lightning channels and reopen them. Get the benefit of PTLCs. Yeah, the great migration. So, so that's, I mean, that's, that's fucked. We shouldn't be opening lightning channels right now, right? And it's happening exponentially right now. I'm sure there'll be a transition period and there, I'm sure there'll be hubs that rise up that accept incoming HTLC channels and
Starting point is 01:08:38 route outbound PTLCs to peers that you would like. You're not, you're still not going to get the benefits until you're native, but. Well, I think I mentioned it to you. I don't know if it was while we were recording or afterwards, but ryan gentry and i had a conversation last week and they've been talking about this at lightning labs and one of the i think the head engineers lighting labs can see a potential second system yeah syndrome problem trying to make this migration so really thinking through it and doing it in in a in a way that avoids that terrible fate which would be very spooky
Starting point is 01:09:11 is something that the engineers and community needs to figure out. There's like this meme, right? That's like, we're supposed to be opening up lightning channels for the inevitable fee increase. We're going to build reputation, long-running lightning nodes. It's a false meme, right? None of our lightning channels are going to really be around in five years. I mean, they can be around, but PTLCs are going to be better.
Starting point is 01:09:38 It's like, we want that better thing. but like especially if you want like routing fees and stuff like you gotta you gotta upgrade right yeah and if you actually want to scale lightning you make the argument too that you need ptlcs because that's what they were describing with aj's proposals that it really prevents you when you combine it with taproot from needing to store the whole channel state history on your node you can do that with much less data using taproot ptlcs so it makes the ability for people to run lightning that's significantly easier strong urge to close all my channels or at least a lot of them you close the you know the majority of them you leave some open
Starting point is 01:10:17 yeah well let's dive these are low let's dive into the potential solution you just described so people spin up hubs yeah i'm sure there'll be hub providers that you'll open up a channel to inbound and then outbound there'll be ptlc to someone else but that doesn't really get you the full benefit of ptlc is not hitting on the head you're gonna have to go native at some point yeah spooky you want to talk about spooky how about i was presenting at the hrf event teaching activists bitcoin privacy and like i get off stage and i walked to the back and stefan was like you did a great job did you see the lightning vulnerability and like i pull up the lightning vulnerability on my phone i'm like can i just lose all my lightning funds right now
Starting point is 01:10:59 like i didn't even and then i just went and got drunk and then the next morning like i woke up And I was like, oh, nice, I didn't lose all my money. But, like, that was pretty, I mean, to use your word, spooky. Yeah, yeah. There's a lot of spooky things. How is there not more funds lost on that? Like, I've upgraded since then. Hopefully the upgrade wasn't a vulnerability.
Starting point is 01:11:20 Maybe it highlights that the authorities aren't paying attention to this as much attention or attackers. Right? Maybe it's, yeah. Maybe, yeah, I don't know. What does it say? What does that say? maybe it wasn't practical at scale well to start it off the attacker needs to be
Starting point is 01:11:38 able to spin up a lightning node deposit funds into it there's already an opportunity cost there now unless he's going through tour remember it's public IP address right so I assume that that's part of the so do the tour okay so you're open a couple fat channels right they have to be a channel partner I mean why don't i just buy some shiba coin or fair enough yeah yeah we got uh we got young marty up from his nap how is he doing honey so i have an interesting question for you arbed out so we were at bit devs yesterday and one of the key aspects of bitcoin is that there's no auto update feature because the update itself
Starting point is 01:12:21 can be malicious right like if someone has the ability to auto update your client they can compromise you, give you an update that hurts you. That's malicious, right? So we don't have auto-updates. You have to update yourself. You should verify yourself. A lot of people run old clients. They're slow to update by design, and that's great.
Starting point is 01:12:40 That's one of the cool parts about Bitcoin. At PitDevs, Buck and Ben were like, if you see an update come out for Lightning, you should just update it immediately. Don't even read the release notes. You don't have to know what it is. you just got to update it immediately because it's like beta still and a hot wallet so is there an argument to be made which kind of spooky that was spooky to me what is there an argument to be
Starting point is 01:13:06 made that maybe for for some lightning users they should have auto updates enabled like should they just automatically like if a new lnd update happens there's just no automatically updates because they're not verifying it anyway well i would like to add more context that's before you fans are gonna they also mentioned the inflation cv bug of 2019 uh at the protocol level but with that it was miners right yeah well the point i'm trying to make with that particular cv they were like if you are after this version if you're between these versions you're going to want to update but if you're before you don't have to could you do that with lightning too like like if you're running lnd version x if you're between x and y you're going to want to upgrade but if
Starting point is 01:13:49 you're outside of that threshold before that you're good um is that possible because that was possible with the protocol this vulnerability affected all lnd versions okay there was no range okay right with the with the potential inflation bug it was introduced in like version 16 right and then it was found a couple versions later so there was a window yeah but my point is my point is lightning's a hot wallet there's all these different vulnerabilities we keep finding out about we had the one where it wasn't even checking the utxo commitments um for the vast majority of users like if this was a really bad vulnerability which it seems like it was like i just would have lost all my money while i was speaking on hrf right like the vast majority of users maybe
Starting point is 01:14:33 everything has trade-offs maybe auto updating on lightning makes more sense for them than doing manual updates to me whether you want to make that trade-off or not depends on how many how much funds you have at stake how many peers you have how long live your channels are it's one thing if you're just making a show off lightning payment for coffee for five dollars every few months to say hey i'm part of plebnet it's another thing if you're running lightning liquidity providers as a business if you want to take that approach of auto updating i'm very hesitant to recommend it to anyone but as an example i don't mind updating words with friends on my phone uh every having it set on auto update and i've got about 20 with the power-ups risked on there you
Starting point is 01:15:24 know but like i like i guess the better question is like should full node projects like um roll raspi blitz uh the ones that offer lightning should they offer an option to their users to enable auto updates for the lightning portion as default not as default okay not as if there were like should there be an option there because it doesn't none of them off the option because it's like even with just regular bitcoin wallets you shouldn't be have auto update it's always been the norm i think my noddle has an option to save encrypted backups to my lightning state to usb but it's hidden behind a scary message because it doesn't want to accidentally format my discs by getting the wrong USB.
Starting point is 01:16:11 That's a good question. Should there just be a checkbox there that says auto-update Lightning? Yeah. I lean against, but if you hide it behind a modal saying, be sure you know what you're doing, all funds at risk,
Starting point is 01:16:23 danger, danger, Will Robinson, then at a certain point... But is that warning even accurate in that situation? Like, if you don't have the auto-update, if you're running the old L&D, your funds are at risk right now. Well, okay, here's the problem. This actually ties to a recent change made in Bitcoin Core.
Starting point is 01:16:38 We made the change from a single maintainer signing releases to multiple developers signing. It's so hard to verify it now. Right. You have to verify 14 signatures, and you can't find... I don't know where to find all the PGP keys. It's not all in the same area. Good. It should be hard.
Starting point is 01:16:55 I mean, what's the equivalent of that for Lightning? Are they all signed by a single maintainer with a GPGP key that you trust in your web of trust that you're checking? In this trust model, I feel like KetoMiner would be doing the verification if there's a noddle, right? And then his users under him
Starting point is 01:17:15 that were all running noddles are just trusting that he verified it and then pushed the auto-update. I like KetoMiner and he's a good guy, but I don't know about that. I'm telling you, there's a ton of node operators right now that still have not updated their nodes probably.
Starting point is 01:17:29 All their funds are at risk. Yeah, what does that say? that their funds are still at risk yet they have not been attacked. I guess it's just to say that again, Lightning Network's too small. It's a community of enthusiasts
Starting point is 01:17:43 who aren't trying to attack each other. Authorities saying, yeah, yeah, this just isn't worth it this time. It's not big enough. Laziness. Apathy. Questions of our day.
Starting point is 01:17:56 Not enough money to steal. Yeah. It takes a competent attacker to pull this off. It's not yet at the point where a script kitty can just press a button and get funds. Yeah. Like, most of the big nodes are probably updated.
Starting point is 01:18:09 Yeah. Yeah. Yeah, I'm just, like, wondering. Or, like, a node like y'all's or whatever, like, he probably updated it before the disclosure even went out. Yeah. With all this being said, like, this attack was discovered,
Starting point is 01:18:22 this vulnerability was discovered because you have, like, Antoine and Gleb actively, like, looking for and attacking the network. So we have white hats, if you will, looking for this stuff thank god we have them right thank god i mean just talk about something i think it was very underscored and underappreciated it was like the smart fuckers building this stuff like actually trying to attack it and that's a crazy like they're trying to attack it trying to find these pain points it is very spooky what we're talking
Starting point is 01:18:50 about some of you at home maybe like what the fuck is guys this even worth it i mean this was a vulnerability that was intentionally sought out. We didn't hear your opinion, Marty. I feel like the TFTC node is a perfect example. That BTC pay server we have,
Starting point is 01:19:11 would you check off the auto-update button after this vulnerability? I don't know. I'm against it. But it took a while for you to update it. Yeah. After you saw the disclosure, how long did it take you to update it? Two days.
Starting point is 01:19:26 yeah that's a long time in in disclosure land yeah yeah i think yeah against against auto update ah maybe i don't know because like again like that what if you auto update to an update that's has vulnerabilities in it that's like the whole that's the whole reason against auto update so you're just are you compounding risk there it's tough even like solving that problem like you waited two days and you just clicked update like you didn't even yeah yeah that's a good point maybe it's an unsolvable problem we're not definitely not going to solve it here right now because you have to go catch a flight yep i'm so glad that you we all managed to find time to do this for the third time uh right before i'm hopping on 100 percent it's not a three hour
Starting point is 01:20:15 drunk rep but i think it was a very good spooky rep just a pleasure to see you as always likewise it's a pleasure to see you both here in austin the bitcoin capital of the world i'm super excited for you to be working at Unchained Capital. Oh yeah, I guess I should. Yeah, that's what I was going to say.
Starting point is 01:20:28 Before you leave, what are you looking to accomplish at Unchained? Why did you join the team and what can we expect about your book that's going to come out at some point in the future?
Starting point is 01:20:37 At some point in the future. What I'm looking to accomplish at Unchained is to help Bitcoiners build products for Bitcoiners. We're building something that every Bitcoiner
Starting point is 01:20:46 is eventually going to need, I think, in some capacity, collaborative custody. At the end of the day, nobody wants to be a single point of failure. whether it's for your own cold storage
Starting point is 01:20:58 or whether you're Michael Saylor or Michael Strategy, you don't want to be in the position where you're the only person between you and Oblivion. Spreading out your trust between as many parties as possible is, I think, something that every Bitcoiner can benefit from. If you're a Bitcoiner looking to work with a bunch of passionate Bitcoiners at a Bitcoin-only startup,
Starting point is 01:21:21 please reach out to us at Unchained Capital. uh and i also announced yeah so i've been working on a book i guess i don't know i'd love to hear this yeah so i mean i've been tweeting about all this stuff for ages now and i realized if twitter.com goes down have you ever even written a medium post nope yeah i just ran for like 30 odd tweets in a thread i'm very excited to see a long form arbed out piece of literature so the basic idea is i was reading this book called the tyranny of email and it's making the case against email and it starts from you know the days of the pony express and even before then like the first like recorded mail services and it was an interesting book but it sort of made me
Starting point is 01:22:01 wonder what real relation does the united states post office have to you know mail back in the days of like cleopatra not much you're sort of stretching to make that story and then i started asking well what does bitcoin really have to do with fiat currency in the prehistory of money that crown has been covered brilliantly by a lot of people. Saifuddin's book is great. Nick Bhatia's book is great. Vijay Bhatia's book is great. I love all those.
Starting point is 01:22:28 That's the Bitcoin standard, layered money, and the bullish case for Bitcoin, respectively. But I thought it would be interesting to examine Bitcoin from the point of view of network protocols. So SMTP is the protocol that handles email. What can we learn from that? And how it was implemented
Starting point is 01:22:45 and how email competes with regular mail. Hell yeah. Yeah. so should we put a hard deadline on him to force him to write this book
Starting point is 01:22:54 oh man I think I have to have something what's the over under by the next time we do this by the next time we do this
Starting point is 01:23:02 oh yeah that doesn't allow us to create a DLC I want a DLC one year you think it's gonna take you longer than a year
Starting point is 01:23:10 are you gonna have me on for next Halloween are we doing that I like that we switch holidays yeah I would like to do yeah let's do Easter
Starting point is 01:23:16 next year that'll really speed up the book progress Oh, man, that's a bit early. Yeah, that was the joke there. Dude, I mean, we would love to rip with you whenever you want to fucking rip. Yeah.
Starting point is 01:23:26 See, I don't want to have to wait, like, a year to record again if we feel that there's something pertinent to talk about between now and our next recording, which could be sooner than a year. All right, let's just say Halloween next year. We'll do. Okay. We'll just do a year for the book,
Starting point is 01:23:43 but we won't use that as a... It won't necessarily be the next time we talk. All right, I appreciate that. I feel like such an honored guest, you guys. You gave me the 100th episode. You gave me the holiday special. And now I get the spooky Halloween. Such a privilege.
Starting point is 01:23:57 Well, we came up with the spooky theme, literally, 20 seconds after hitting record. I think it's very timely. And I thoroughly enjoy this conversation. Because, again, people like to knock on Bitcoiners. Like, oh, they're done. I think this episode particularly highlights the adversarial thinking approach that many Bitcoiners bring to this. There's not many people in the shitcoin world
Starting point is 01:24:21 having these conversations. Yeah. Great. Cheers to that. Well, I hope you have a safe flight. I'm more than ecstatic that you are with the Unchained team and that we were able to do this before you got out of here. Thank you.
Starting point is 01:24:33 Thank you for having me. And thank you especially to all the freaks who had to make it all the way through that nearly four-hour scotch-soaked shit show of a second rip that we did. I hope this one made up for it a little bit. Yeah, I apologize for that one, freaks. Yeah, we'll have to tease that,
Starting point is 01:24:46 Like, hey, this one was actually, Matt didn't fall asleep in this one. Yeah, Matt's a bear, by the way. It was the only time I've ever fallen asleep in an episode. Stay home, we'll take naps. Like a 45-minute nap right in the middle of the episode. You act like that's something to be proud of. We've done a lot of episodes, you know? Our other podcast is falling asleep.
Starting point is 01:25:07 We had so much steak. We had copious amounts of whiskey. And I think it was the first time I saw both of you since COVID happened. that was great i really got very excited yeah it was the first in person we had since covet started um and the price was like 17k and almost a year later we're sitting at like 60k and people are like oh my god bitcoin crashed yeah we were like we couldn't fathom 60 we couldn't fathom i was talking to our doubt before you came out here we couldn't fathom that our next show in a year because that one was at his apartment on the floor with no chairs um that
Starting point is 01:25:41 It was going to be on your screened-in studio porch in Austin, Texas. Yeah. What a fucking crazy year, man. Crazy year. Here we are. Cheers to that. Cheers, guys. Peace and love, freaks.
Starting point is 01:25:54 The key!

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.