TFTC: A Bitcoin Podcast - #294: Gordian principles and the standardization of Bitcoin software with Christopher Allen & Wolf McNally
Episode Date: January 13, 2022Join Marty as he sits down with Christopher Allen and Wolf McNally to discuss Gordian principles and standardization of Bitcoin software. Follow Christopher on Twitter Follow Wolf on Twitter Check out... the Blockchain Commons Gordian Principles Gordian Seed Tool LifeHash Shoutout to our sponsors: Cash App Unchained Capital Braiins HodlHodl Bitcoin 2022 - use the code TFTC for 10% off
Transcript
Discussion (0)
What is up, freaks? It's your boy Marty Bent here to introduce this episode of Tales from the Crypt.
I had the immense pleasure of sitting now with Christopher Allen and Wolf McNally
from the Blockchain Commons Initiative, which is trying to create better standards
for Bitcoin software, particularly around wallet software
and how wallet providers should be
building their wallets to be interoperable with each other to eliminate
friction for users in the future. Fascinating conversation.
and it was an honor to have them on.
I mean, Christopher, I've been asking him to come on the podcast for years.
He finally reached out recently and said, hey, it's time.
I've got things to talk about.
So we talked about them.
We did a little demo here.
If you want to see the demo and you're listening to the audio format,
we did do a good job of describing what was going on in the demo.
But if you want to see it on a computer screen,
this is live on YouTube and Bitcoin TV as well.
So you can go check it out there.
if you want to see the seed tool
demo with Sparrow
Wallet. It's pretty cool. I do recommend
it.
Other than that, listen to it. There's some
great beards here teaching us some important
lessons of TFTC. It was brought
to you by our good friends at the motherfucking Cash App.
Don't know if you guys saw it.
You might not have it yet. I don't want to
tease you if you don't have
it yet, but Cash App enabled
Lightning Network payments this week. I got it.
I paid a Lightning Network invoice
using the Cash App. It worked flawlessly.
obviously tftc.io slash contribute tested it out there it works cash app it's the easiest way to
stack bitcoin or integrating bitcoin more into their their products not only that they're
integrating innovative bitcoin tools into their product suite as well lightning network being
the most recent so yes i have it now many of you don't you will have it i imagine in the future
It's going to be rolled out to everybody, I would imagine.
If not, then I'll have fun using the Lightning Network.
Well, you guys aren't, but I'm sure you will be able to.
If you haven't downloaded the Cash App yet,
make sure you use the code STACKINGSTATS.
It's S-T-A-C-K-I-N-G-S-A-T-S.
You're going to get $10.
$10 is going to go to our good friends at Owls Lacrosse.
That's Owls Lacrosse.
This room is also brought to you by our good friends at Unchained Capital.
Unchained Capital is here to help you eliminate single points of failure in your custody model.
Their vault product is the epitome of this ethos, the epitome, I can never use the right
word.
It is what really highlights their drive to eliminate single points of failure in your
security model.
Unchained is here to be a partner.
They're not some faceless company.
They're not some app.
They want to help you secure your generational wealth, not only for your life, but your children's
life, your grandchildren's life.
They want to be a partner in securing your Bitcoin.
If you haven't interacted with their vault product yet and you're thinking about it,
they have a white glove concierge service.
It's going to take you from zero to having a multisig vault set up to two or three multisig
where you hold two keys, Unchain holds one.
You always have control over your Bitcoin.
If you're ever in a pinch, Unchain is there for that second and two or three signature
quorum.
White glove concierge service comes with video conference calls.
They're going to get you hardware wallets.
They're going to get everything set up.
They're going to get you comfortable and they're going to dump a thousand cuck bucks worth
the sats into the vault after it's all set up.
Use the code
TFTC or just tell them that TFTC sent you.
I don't think it's a code. You just have to tell them, hey,
TFTC sent me. You'll get $50 off that package.
Which is a beautiful thing. Go check it out.
And everything else they have going on at Unchained
including the incredible content
they have. They're rolling out their IRA
product. It should be completely rolled out now
at this point. They have their
lending decks too if you want to use your
Bitcoin as collateral. But check all of it out
at Unchained.com.
This trip was also brought to you by good friends at Brains, Brains, Brains with two
I's, B-R-A-I-I-N-S.com is their website.
And if you go there, you're going to find a bunch of things.
Brains is the team behind Slush Pool.
There's a team behind Brains OS Plus auto-tuning firmware.
If you're running an ASIC that's compatible with Brains OS Plus firmware and you're not
running it, you're leaving sats on the table.
It's as simple as that.
Go to Brains.com.
check out the brains os plus page check out what miners are compatible of it if you have a miner
that's hashing it's compatible with brains download the firmware on if you're pointing
your hash at slash pool after downloading that firmware you're going to get zero percent pool
fees it's a beautiful thing they've also got insights.brains.com if you want to figure out
everything you need to know in the mining industry they have a one-stop shop at insights.brains.com
that'll give you mining profitability,
the cost to mine a Bitcoin,
network hash rate statistics,
difficulty pool statistics.
It's all there at insights.brains.com.
Shout out, Adam.
Adam.
Adam.
I'm sorry, Daniel.
I'm going to say Daniel.
I don't know why I said Adam.
I caught myself right away.
I'm sorry, Daniel.
It was a child of Daniel's mind
during the having of 2020.
This RIP was also brought to you.
Go to brains.com and check out all that.
This RIP was also brought to you by our good friends at HodlHodl.
HodlHodl is here to bring you guys a non-custodial,
no KYC, no AML lending platform.
You go to lend.hodlhodl.com there.
You'll be able to put your Bitcoin up as collateral
to get stable coin liquidity.
It's a beautiful thing because they're leveraging multisig as well.
So if you go to get a loan,
what you'll do is you'll create a two or three multisig.
You'll hold a key.
Your counterparty will hold a key
and HodlHodl will hold the third key.
You won't have control of the Bitcoin in that collateralized multi-sig wallet, that escrow wallet, for obvious reasons.
You don't want to put it in there and get stable coins and you run with the Bitcoin.
That just wouldn't work. It wouldn't be a viable product.
But you do have that one key, which gives you visibility into that wallet so that you know that your Bitcoin is not being rehypothecated.
So you're going to have peace of mind as you're paying back that stable coin loan.
If you pay it back plus the interest, you're going to get your stats back at the end of the day.
Alternatively, if you're a stablecoin guy or gal and you want to get some yield on your stablecoins that are just sitting there, you can put it up in this lending platform and lend it out to get your principal back plus interest.
So a little yield on that Bitcoin or that stablecoin.
Excuse me.
Go check all this out at lend.hodlhodl.com.
No KYC, no AML, non-custodo.
Beautiful thing.
Beautiful thing the HodlHodl team is doing.
last but not least, Bitcoin 2022 is the largest Bitcoin event in the world that takes place April
6th to 9th, 6th to 9th, 6th to 9th, 6th to 9th, nice, in Miami Beach, Florida. All four days will
be jam-packed with exclusive content, exciting announcements, and an incredible lineup of
Bitcoin speakers, artists, and leaders. Day one is Industry Day for entrepreneurs and
enterprising, excuse me, Bitcoiners who are looking to build a business or a career within
the ecosystem. Days two and three are general conference days featuring speakers like El
Salvador president, Nayib Bukele, CEOs like Michael Saylor, Elizabeth Stark, Jack Maulers,
Adam Back, and hundreds more. The conference caps off with the fourth day with the world's
first and largest Bitcoin music festival, Sound Money Fest, headlined by rapper and
fellow Bitcoiner Logic, featuring artists Kay Flay, MZero, Royal and the Serpent, Apache,
Asadi, and more. I know one of those. I'm getting old. Stay tuned for the upcoming lineup
announcement last year's conference sold out and this year's on pace to be three times larger so
make sure you grab your tickets before it's too late as is tradition we're going to be doing a
live rabbit hole recap at the conference matt and i will be so visit b.tc slash conference to learn
more ticket prices are going to increase on january 14th which is a little over 24 hours about
31 hours from the recording of this ad right now so use the code tftc before january 14th
you're going to get 10% off. If you use it after January 14th, you're still going to get 10% off.
That's the code TFTC. However, you'll be getting 10% off a higher price after the 14th. So go
check all this out and enjoy this episode with Christopher Allen and Wolf McNally. I certainly did.
You've had a dynamic where money's become freer than free.
if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting
like safe haven i believe that in a world where central bankers are tripping over themselves to
devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean
that's part of the bull case for bitcoin if you're not paying attention you probably should be
what is up freaks it's your boy marty bent here on a lovely wednesday afternoon finally
christopher allen uh we've been dming for years and you've been saying uh i'll come on the podcast
when when we actually have something to show uh and it seems like we're here we're sitting down
with christopher allen and wolf mcnally from the blockchain commons they're working on very
important standardization of bitcoin software and i'm very excited for today's conversation
thank you gentlemen for joining thank you thank you well uh again like i was saying before we
hit hit record here i think what you guys are working on the blockchain commons
specifically is very underappreciated in the space we've we've talked about in years past
in episodes of this podcast standardization of some parts of the bitcoin code so that you have
interoperability between different wallet softwares hardware wallets mobile walls desktop
wallets whatever it may be so that bitcoiners can just pick up tools and expect that they'll work
and be interoperable with other tools you guys have been applying and trying to bring this to
market at blockchain commons and it revolves around what you guys describe as gordian principles
i guess that's where i'd like to start today is the gordian principle model what what you're
applying it to and how it goes into the ethos of all the products that you guys are building
Great. So, yeah, my name is Christopher.
Christopher, it seems like you may have just did it.
There it is. Muted you. You're good.
My name is Christopher Allen, and I've been doing open infrastructure for a very long time.
I'm the co-author of the TLS 1.0 standard, which, of course, now is the world's dominant security protocol.
I did that in the 90s, and trillions of dollars of commerce are using it.
So this is an area that I'm passionate about, and with my entree into Bitcoin five years
ago, this has very much been on my mind of how do we create a strong foundation for all
of this um that can last for you know decades or even centuries so um i've taken a lot of you know
what and how uh uh things like tls evolved the community the ecosystem some of the best practices
there and the best practices from bitcoin i was uh a principal architect at blockstream i've been
involved with a number of different projects in the early days of Bitcoin. But I really felt like
there was the whole foundation was underserved, especially in the area of interoperability. So
we started working on that, what, two and a half, three years ago, seriously,
with different aspects of things, in particular, have been these Gordian projects. So
So as many people know, Bitcoin has been going through a lot of transitions right now with Taproot Schnorr and descriptors and multisig and all of that.
But we're also carrying with us a legacy of old styles, old designs of how these things work.
So how should the new ones work? How can they take advantage of these new technologies?
So, you know, we've really been focusing on these new Bitcoin architectures and, you know, what does it mean to have a secure foundation for the ecosystem as a whole?
So in doing that, we created something we call the Gordian Principles.
You know, the independence, privacy, resilience and openness is really what we're talking about.
Now, they all have, you know, deep, you know, underlying things.
You know, independence, you know, is everything from supporting user freedom, but also is kind of involuntary oversight, whether or not that's, you know, censorship resistance or some kind of coercion or whatever.
but also kind of the economic coercion that can happen in marketplaces and things of that nature.
How do we prevent that privacy?
There are other forms of coercion that happen because of strong identities and such.
So how can we enhance privacy and pseudo-anonymity?
So we have a variety of different projects associated with that.
resilience is an interesting one. You know, we definitely, security has this paradoxical
property of making you maybe less prone to certain kinds of attacks, but it also lowers
your resilience and makes you more fragile to other kinds of problems. So how do you balance
those? Because you really want resilience in both. So a lot of our work, for instance,
The Smart Custody book that we came out with two years ago and these projects are to try to cover this very interesting challenge of how do we decrease the likelihood of loss in general for regular people?
um and then finally uh openness um you know infrastructure uh open infrastructure means
that we really have to have a you know some common things so that if any of us uh fail move on
etc that we don't have uh you know an ecosystem uh problem where some major party loses hundreds
of millions or even a billion dollars because of mistakes and that will affect us all um uh so we
have to have a strong foundation, but we also need to avoid things like heartbleed. So one of the
things that was really sad for me is, you know, a dozen years after I finished SSL 1 and TLS 1,
and we were now moving on to 1.1 and whatever, you know, TLS became boring. We had one person
and supporting the number one open source project one quarter time.
And trillions of dollars of commerce were being used for it.
And a little bug creeped in.
And some people discovered it and shared it.
And, you know, it was probably actively used to steal keys and certificates and other different types of things for at least six months, if not longer,
before somebody discovered it.
I don't want to see that happen in the Bitcoin ecosystem
where it's a lot more dangerous.
So how do we support things for 15 years, 20 years, 50 years?
That is going to be best served not just by open source,
but also open development and open infrastructure,
which is a little bit more than just open source.
So those are the four principles.
When we look at any of our different tools, open source projects, et cetera, we've attempted to say, hey, this is what we do in independence.
This is what this particular tool offers as privacy.
This is what this tool offers in resilience.
This is what this tool offers in openness.
And share that with others.
And we're hoping that it's not just us because we're, well, we'll talk about that later about being a product company versus being a Schnelling point for the ecosystem.
But we're trying to encourage others to do the same.
Yeah.
I mean, you brought it up.
You mentioned it, especially with these open source protocols and more specifically this distributed system in Bitcoin.
How do you create a acceptable?
I don't even know if acceptable is the right word, but a tradeoff between security and usability that people are happy with and will bring more individuals who are not as tech savvy as your average early day Bitcoiner are to the Bitcoin protocol.
And so I guess another thing you mentioned there, not directly, but I think what you're trying to do with these standardizations that lead to interoperability is avoid potential tech debt that could be built up around Bitcoin development, particularly as it pertains to wallet software.
Exactly.
And that's, you know, an interesting challenge because sometimes, you know, early decisions are made.
Electrum, one of the first solid wallets outside of Bitcoin Core, made some decisions that they have to continue to support because they have a set of legacy users, which then makes it complicated for everybody else who wants to interoperate with them in the future or forces some architecture changes.
or sometimes what I call invisible architectures that, um, uh, you know, can cause long-term
problems. So, um, uh, you know, we have to address, you know, there's this interesting
problem with open infrastructure is how do you retire it? You know, how do you replace,
uh, the important bits and not leave people behind? Um, it's hard, especially again,
i'm trying to think in the terms of decades yeah decades maybe centuries who knows and and it's
crazy to think of this early on in bitcoin's history of the project 13 years in even though
we're 13 years in the decisions we make today are going to impact people decades from now and
do you think there you think there's enough weight on people i don't want to say consciousness but
Do you think people understand the gravity of the decisions that are being made today to the Bitcoin network that will affect people in the future?
I think we're doing an okay job at that at the Bitcoin consensus layer.
You know, I am one of the reasons why I am such a big supporter of Bitcoin is, you know, how the Bitcoin developers and adjacent developers like Lightning, et cetera, are thinking about security and how they're thinking about these types of things.
But that being said, Bitcoin Core is not a good wallet.
um so when we start you know talking about the broader um implications of bitcoin the broader
ecosystem that's where it gets complicated and we have centralities um or at least you know
almost duopolies um up until fairly recently um we have to address that yes and in your opinion
what is the best way to address this so let's get into like the gordian suite where
are you trying to create standards specifically obviously you have uh things around like how you
produce seeds how you secure those seeds qr codes something as simple as what some people would
think is simple in a qr code uh one thing one recent problem i ran into uh was trying to
recover a wallet using a seed phrase on a particular software that wasn't familiar
with the derivation path that i produced the the private key with and so there there was an issue
there like these pain points and those pain points are going to get worse um you know i i think one
of the lovely innovations um in bitcoin is how it handles keys which basically is it throws them
way um but early bitcoin um software basically just you know it randomly created every single
individual key separately and then it had a key management problem of lots and lots of keys and
and and all of that so uh you know bit 39 was invented to allow you to create these lists of
keys that had great security properties um that being said uh they weren't designed with multi-sig
in mind they weren't designed with uh various kinds of future proofing in mind last time i
looked um there were over 40 variations of single sig derivation paths in bitcoin between um uh you
know, different kinds of ways of doing accounts, uh, you know, bit 45 versus 74 versus, you
know, legacy Electrum, how changes handled, um, gap limits, um, et cetera, gap limits.
Um, and it's gotten worse with multi-sig.
So if, you know, we are really focused on descriptor based wallets that use multi-sig,
And I'm, you know, very actively trying to encourage some parties to delete their single-sig capability from their wallets.
And, you know, if they're a tier-three new wallet company, do they really need to support legacy?
I'm not sure they do.
You know, and I've got some good designs for, you know, a two of three that we would like – we would love to see some wallet companies do that for self-sovereign wallets.
Multi-sig does not necessarily mean multiple people.
But anyhow, back to the key issue, there is state now that needs to be kept.
What we call an account map, it's called different names by the community,
but it's basically the multi-sig descriptor at minimum now also needs to be saved.
Now, fortunately, it's public keys that are in there,
But then that can potentially violate your privacy.
Other interesting problems, this is not one that I have a great solution for, is multisigs all largely are using the 48 derivation for the single key, which means the XPUB that you share, say, with CASA for some account, multisig account with somebody,
And the XPUB using that same Trezor ledger or whatever that you're using with, say, Unchained Capital is exactly the same XPUB, which gives them potentially an opportunity to go, oh, what other accounts are out there that this person uses?
Now, they need more information.
It's not super easy, but it is a weakness that we're reusing XPUBs even for privacy.
Um, so, you know, these are all the kinds of things that we're trying to identify at Blockchain Commons and see if we can, you know, have some low hanging fruit to address them or at least raise the issue enough to the community to kind of go, is there an emerging consensus that this needs to be solved?
So in that particular case, after talking with a lot of wallet developers and things of that nature, they're kind of like, yeah, we don't like it.
But, you know, it's not critical right now compared to other problems.
That's fine.
So we're not putting a lot of energy into solving it.
Interesting.
Wolf, would you have anything to add to that?
Things we should be aware of?
Why don't you introduce yourself a little bit first, too?
Yeah, sure.
I'm Wolf McNally.
Christopher and I met, I don't know, maybe 15 years ago now.
Christopher ran a series of iPhone slash iOS developer camps in Silicon Valley.
And I lived in Los Angeles at the time and attended several of those.
And Christopher and I got to know each other and became friends.
And when he started up this project, it was a good confluence of events.
It turns out I was available to work with him.
And I guess I'd become kind of a Blockchain Commons de facto lead researcher.
And so that basically involves, you know, working with Christopher to identify the issues that that wallet and blockchain developers are having and then figure out, you know, what we can best apply our talents to.
And then basically producing research papers and reference implementations and that the reference implementations can be take the form of libraries that you can link to or command line tools that you can run or apps.
Uh, and I've been an iOS developer as, you know, as I just mentioned, you know, for many
years.
So, um, uh, so basically, you know, I've been kind of capturing these ideas that we've had
as we've identified problems and then, um, produced a series of research papers and you
can check out our GitHub account, uh, where we have all of our research papers listed.
Everything we do is open source.
So, um, you know, from our command line tools like seed tool, which has a similar functionality
to the SeedTool app I'll be showing you,
which is a command line tool and key tool,
which drives keys and things like that.
Also command line to the various apps we've done.
I've been heavily involved with most of those,
although there have been some other major contributors as well
who've contributed other major apps or pieces of software
to Blockchain Commons.
And yeah, so that's a little bit about me.
Awesome.
um and so i guess you guys are talking to a lot of wallet developers and you're trying to build
uh early build tools to show hey this is the way you should do things and adopt this type
of standard what are the number one thing uh things that are coming top of mind to wallet
developers like because there's this weird thing too where you have the especially with the hardware
wallets you have the individual players who have a profitable business in the hardware side and
And one could argue there is an incentive to create a moat so that more people use their wallet.
How do you take that into consideration and then try to work within pain points on the software side as well?
I mean, I think our biggest ecosystem success has been our UR standards, in particular around PSBT.
So, PSBT is an incredibly useful format for having a partially signed transaction or a completely unsigned but assembled ready for other wallets to review and basically go, yes, I'm willing to participate in this and continue.
I'll sign my part and pass it on.
Um, well, it turns out there are a lot of gotchas because PSBTs, uh, you know, need to be moved from
one place to another. And there's information that may be associated with, uh, PSBTs, but aren't
actually in the PSBT itself. Uh, we have different kinds of wallets with different form factors.
um some people are fine with a usb or even worse a usbc cable between their uh their hardware uh
device and a computer others are going uh-huh no we don't want to do that um and you know so
they're at least trying to air gap it through uh little uh you know java cards uh sd cards that
have a Java capability. And then, of course, you know, the nirvana we're really kind of going for
is true air gaps. You know, let's not even have the devices communicate electronically directly.
That's not to say that QRs are perfect, but they have some, you know, clear advantages.
Then we run into this problem of, gosh, PSVTs can get to be really big. You know,
how do we deal with that? And we found some very, you know, nice sweet spots with, you know,
some interesting, you know, design challenges along the way, which Wolf can talk about,
that now there's half a dozen wallets that are supporting, you know, our Bear PSBT. And we now
have two services, Casa and Unchained Capital, that are doing it for transaction coordination,
where they don't have any of your keys at all.
So this is probably our biggest success.
Still a lot more to do.
It's still a pain to save keys.
There are definitely issues with state,
not just the account maps and descriptors that you might need to have,
but Lightning has some interesting problems with channels
and storing that information and other stuff
that we have made some progress on,
but we're looking for more wallet developers
to join the community so we can solve it together.
Yeah, PSPTs are a fascinating part of Bitcoin.
They're almost magical when you send a PSPT
for the first time.
I usually do it with, I've done it with cold card,
with the air-gapped way where you'd never,
we're technically air-gapped, I guess,
if you've never touched the internet,
but you construct the transaction on the device,
move the SD card to the computer,
or you construct it there, move it back, sign it,
then broadcast it from the computer.
It is an involved process.
And you mentioned QR codes are here to help,
and they're harder in some ways,
but a lot easier in others.
How do QR codes fit into all this,
particularly around the communication of the data size of the PSPT.
This, I think, would be a great segue to Wolf to demonstrate it can be even easier.
And we even have some new things that are emerging that make it even easier than what we're going to show you just now.
But let's talk about one of the easiest integrations, which is Sparrow Wallet and SeedTool.
sure yeah so um we basically you know as my conversations with christopher have gone on
we've identified kind of pain points in the developer community and so then i've basically
gone off and done the research uh written proposals uh we've kind of gotten gotten
reviewed by various people and then i've implemented the actual code for those um
One of the most successful ones has been what we call our Uniform Resource, or UR, proposal.
You've heard of URLs, Uniform Resource Locators.
They point to things on the Internet.
Our UR proposed standard is, you know, a number of people have adopted it now, so it's a de facto standard in some ways, is a self-contained resource.
So it's an actual string of letters, like a URL.
It begins with UR colon, just like URLs begin with URL colon, or HTTP colon, a scheme.
that is a scheme of U R colon, and then it includes data.
So it's completely self-contained and it's designed
in specifically to be efficient when transmitted as QR codes.
But QR codes have an inherent limitation
of about 4,000 bytes of data in one code.
And that's even pushing it because that's really dense
and screens, you know, obviously smaller screens
like on a hardware device might have trouble showing
such a dense QR code, cameras, especially like web
and cameras and so on might have a hard time reading
you can't really even approach that 4000 character limit um but partially signed
bitcoin transactions or psbts can be much greater than that because um the signed transaction itself
fights because it might have those in it each of those utxos um it might you i think you just
switched uh microphones i think your head yes we can hear you okay hello i can hear you i don't
think he can hear us can you hear me he can't hear us yes we can hear you but you can't hear us
i'm hearing i think you're hearing me but i'm not hearing you let me try to receive my audio here
sorry that's correct i was on a roll there too can you hear me now yes sir yes good sorry can
you hear us yeah so there we go yeah so so um partially signed bitcoin transactions can have
a lot of utxos in them that adds and then the signatures themselves add more and more to the
size of PSPT, you rapidly outgrow a practical size for a QR code. So we realized that our way
of transferring these things through an air gap between a QR code and a camera needed to be able
to provide like, say, a series of QR codes with the message broken up into fragments.
But that has a problem too, which is that, you know, if you just show a chunk of the data,
you have to identify what's in the data, you have to identify, you know, and if you miss fragments,
because QR codes aren't always read properly,
and you show them the same QR codes over and over again,
you get to the point of diminishing returns
where you're missing that one QR code, but you keep missing it.
So we needed a better solution for that.
And there's another parallel issue,
which is that we want our standard to be able to support
all kinds of structured data, not just PSPTs, for instance.
You can put the raw bytes of a PSPT in a QR code, sure.
You can break them into fragments, sure.
But we want to be able to have all kinds of data,
like requests and responses so that one device can request a PSPT of a
certain kind and the other device can provide that.
So we can,
we want to go have kind of a networking between devices with air gaps using
requests and responses. We need ways of storing structured data.
So the UR standard supports all of that and supports kind of one of the most
highly efficient ways of encoding things in QR codes.
And so you can actually,
all the details are on our both our GitHub site where you can actually read
the papers. Our YouTube channel also has a, you know, a high level technical overview of a lot
of the technologies, including the ones I've been talking about. But the long and short of it is
you can stuff any amount of data you want into a UR and it will get broken up into an animated QR
code using what's called fountain codes, which are a way of avoiding that whole missed that one QR
code over and over again, because it kind of mixes the data between the whole block of data
into each QR code.
And it's actually, it makes it,
interestingly, more and more likely
you'll get all the data you need to finish the message
as you keep reading QR codes.
So, and you know, and again,
we have demos of this on the command line.
We have test vectors, the people who write it.
And we actually had,
I think we have six or seven various implementations
of the UR library, you know, Swift, Python,
I think somebody's done a Rust implementation,
the C, C++, and so on.
So all these are available for developers
to start using today.
So we've been developing a number of these technologies.
You know, another issue that we identified
was that you needed to be able to identify binary objects
at a glance.
Now humans are not very good, I mean,
at identifying binary objects at a glance.
A couple of bits could be off and you won't notice.
So we needed ways of rapidly doing that.
Now you might've seen like emoticons, you know,
which are basically these little icons that get generated.
I think you see them on Reddit and some other places
where your default account, unless you change your avatar,
has this little funny icon and it's yours.
Nobody else has one quite like it.
We came up with a rather innovative way of doing that
called Lifehash, and you can go to lifehash.info
and see a live demo of that running in your browser
using WebAssembly.
So this is also another thing that's totally open sourced.
And basically what we use it for
is to identify things like seeds, keys,
and other kinds of binary objects.
And we'll talk more about seeds in a moment.
So another issue is that, like Christopher was saying,
39 standard HD keys, hierarchical deterministic keys,
let you derive a whole bunch of keys from one master key.
But we realized that there's actually a step before that,
which is you have to generate the entropy
for the master key.
So the entropy is random numbers.
And that entropy itself is useful.
And so if you take it back one more step, you get what we call a seed.
And a seed is just cryptographically strong random numbers of some length, like at least 128 bits.
From that, you can derive master keys.
You can derive from that.
You can derive account keys.
From that, you can derive address keys.
And so there's a whole kind of chain of derivation that can happen that starts with seeds.
And so what we wanted is a way of managing seeds in kind of a very general way.
And so we came up with SeedTool, which is both a command line tool, which lets you derive seeds, ingest them, and transform them, and then also our iPhone app, which you can actually get in the iPhone app store today.
And you can also download the source code, compile it yourself, check it out if you're a developer, and that's what I'm going to demo.
So, we're trying to show, and SeedTools turns out to be a good showcase of a lot of the
technologies that we've been developing, including the animated QR codes, including another one
called SSKR, which is a way of splitting your seed up into a number of shares, which you
can hand out to people and have kind of a social key recovery system.
Christopher can talk a little bit more about that.
And, you know, basically let you, you know, spread out that data.
So if you ever lose it, you can recover it, like, say, you know, you might have three groups of friends, one for your professional associates, one for your personal, your friends, and one for your family.
And you can give out these nine shares, and you only have to get back two from two of those groups to actually recover your whole seed, whereas none of the people have enough in those groups, even if they collude, to recover your seed.
So SSKR is that technology, and that integrates with the UR stuff, and that's integrated into SeedTools.
So, you know, SeedTool is kind of like, you know, a great showcase of a lot of the stuff we've been working on.
Sounds like a Swiss army knife.
In a sense, yeah.
I mean, it's got one major goal, which is to manage your seeds in a secure way and to let you purpose them for various reasons.
To derive keys from them, to respond to requests for seeds or derive keys, things like that, to back up your seeds, to restore seeds, things like that.
So SeedTool is all about seeds.
But, and it's intended to interoperate with other hardware wallets or software wallets like Sparrow Wallet, which I'll be showing how to set up an account using SeedTool managing the seeds and Sparrow Wallet actually managing the account.
So, you know, so it's, I'd say it's a Swiss Army knife in the sense that it shows off a lot of the cool things we've been developing.
And one thing before we hop into the demo, just to make it clear to anybody listening at home or watching as well.
How would you describe the importance of entropy and how do you create entropy in SeedTool?
Because people don't realize this.
They'll just get a device that can spin up a private public key without editing entropy.
Yeah.
Do you want me to talk to that, Christopher?
Go ahead.
Yeah.
Yeah.
So, well, random numbers aren't, you know, there's a very funny Dilbert, which basically, you know, they're showing around the office and they're showing Dilbert to a desk and there's this monster sitting there saying,
one one or no nine nine nine nine nine nine this and the guy says this is a random number generator
and uh and bilbert says well how do you know they're really random and he says well you can
never tell so um the idea of creating quality random numbers is actually really hard most
computers use what they call pseudo random number generators uh which use a seed number you get from
somewhere and then generate a very deterministic sequence of numbers so um and many pseudo random
number generators have been shown to have both statistical flaws as well as ways that you can
manipulate the entropy that goes into them that make them unreliable or hackable. So cryptographically
strong random number generators are used by every wallet to create your key because you need a
random number to create your private key from which you get the public key. But some people
are suspicious of that too. And so they want to actually take control of the randomness themselves.
You want to create a truly random key, then you kind of got to do it yourself. You want to have
ultimate confidence in that. So some people choose to put coins or roll dice or draw numbers from
well-shuffled packs, draw cards from well-shuffled packs of cards. And those are actually
provably truly random. And so if you generate that entropy yourself, then you can generate
the seed from that entropy and a seed tool supports that as well. So you can actually
start with, you can either tell it to use the built-in cryptographically strong random number
generates, you just poof, create new seed. Or you can say, nope, I want to provide the entropy
myself. And you can show that, you know, the same entropy provides the same seed. So, but you
generally throw away the entropy, keep the seed, and then derive all your keys from that. But if
you generate the entropy yourself, you can have confidence that nobody tampered with it.
Also, another, you know, challenge here is that, you know, especially with hardware keys and things
of that nature are you really sure um that it's a random number um or that they've done the
derivations right to create the seed that you're using that there isn't some gamesmanship that
happens between the pseudo random number you know other entropy that's added in and whatever
ultimately to your um uh to the seed that you have so if you're really wanting to be super careful
I'm not saying, you know, the average Joe ought to, you know, needs to do this, but, you know, you can, you know, roll dice and there are some good techniques out there to get everything except the last word in a seed phrase and show that, you know, maybe on another device.
So this is LeathyKit, which uses yet another version of Seed Tool, where you can just put in the dice numbers by typing them into this keyboard.
And the result should be, at the end, the same exact seed as generated by the command line version, where you can look at the code and see, as well as the version that's on your iPhone.
So all three of those versions plus the hand version, all given the same dice, give exactly the same seed.
And you have some confidence that no games are being played at the lower levels.
And that's good.
And, you know, I wouldn't necessarily do all four of these and then use that dice.
But it would give me some confidence that now I can roll dice one last time and have the entropy that I want.
And one of the cool things about LeasyKit is you build it with off-the-shelf parts.
The case is 3D printed, and it uses Arduino, so you can review the code yourself.
You flash it, and you can have total confidence that you're basically controlling everything about that.
And it has no storage, so when you turn it off, it forgets.
It has those little e-paper screen, which doesn't blank because it just remembers forever,
but nothing is secure on that screen once you go back to the home screen.
So it has no long-term storage and then definitely no network connection.
So everything you do on it, including rolling your dices, putting your number in, deriving your keys on, you know, never leaves the LeafyKit device.
So that's a pretty cool thing about that.
That's really cool.
I should also say SeedTool is designed, even though it's an iPhone app, you can run it on your regular connected iPhone, or you can like go out and get a little iPod touch.
You can install SeedTool on it, then turn off the network, and then it remains forever then a network non-connected device.
You can put it in your safe, keep your seeds in it, back up your seeds using SSKR among your friends and family, and have a lot of confidence that even if something happens to that iPod Touch that you might use to find high-value transactions using your seed, you're covered in a number of ways.
That's incredible, being able to use other hardware to basically just store the software.
i mean let's get into a demo for anybody watching at home uh wolf has a demo lined up for us uh just
to go through how this works and then um we can take yeah so i've got the uh the blockchain commons
research website up here uh and uh you know i just wanted to scroll through this these are the
research papers we've done a lot of them have my name on them there's a few people have been
collaborating with us as well um lisi kit and uh um gordian server and so on were created by other
guys uh and about i've been working with them but you know basically this is all open and available
for people to to look at news and that's uh github.com slash blockchain common slash research
um and so um you know the the specs for urs and so on are all there um let me uh
that away so i've got my iphone up here uh and that's the first thing we'll look at um
So I'm going to put that front and center here.
So I'm going to start with SeedTool.
And right now I'm actually down into a separate page here.
So basically SeedTool gives you a list of seeds.
You may never use more than two or three seeds,
but I've got a bunch of seeds I use to test with here.
And each seed, you notice that image, that colored image to the left of each seed,
that is a life hash.
And so, again, if you go to lifehash.info,
you'll see more information about the algorithm that's used to create those it's um it creates
kind of organic looking patterns that are very distinct so even if you change one little bit
of the input the entire image changes and they're also quite memorable um so um the when you drill
down into one of these seeds this is one one of our test vector seeds um you see more detail about
it and um one of the things you see uh in addition to the life hash is to the right of it you see the
little seed icon that says what this is this is a seed you see that little sequence of hex numbers
up there and that's in a way for example um you know christopher i early earlier he transmitted
this to me and you know he said you know is it f0b0b2c i said yes um rather than having to say
is it that purple thing that looks like a doily um so it's more more precise and then you can of
course give your own name to it um scrolling down you can see other things about this seed that
aren't sensitive, like its name, its creation date, any notes. And then there's this yellow
button called authenticate. And this is basically where you access the seed itself and do other
things with the derivations because seeds themselves are sensitive. You use them to derive
private keys and public and private addresses from those. So if I tap authenticate, then it's
going to ask for face ID. And that basically obviously means I'm the authorized user of this
phone. And then there's several different options. You can back up your seed. So there's a couple
different ways of doing that. You can back it up as SSK or multi-share, or you can back it up as
a UR colon crypto seed. Now, remember I mentioned that the UR thing lets you put data into a string
of characters that's designed to be displayed in the QR code, or even if it's too long, broken up
into multiple QR codes. So let's just say I want to back it up as UR crypto seed. So you see that
QR code. That can be scanned by anybody who has SeedTool or another tool that can read our URs.
And if this were too long, that QR code would automatically be animating. And I'll show you
an example of that in a little bit. But you can also print it. You can say print that, and then
you get an actual printout that not only has the QR code, but also has the actual hex value of the
seeds. ByteWords, ZenBit32Words, ByteWords are another technology we developed that gives you
four letter uh english words that represent one byte per word so that's another way of kind of
creating a mnemonic uh and then the other metadata about the seed so you can print that to your
printer you can also say share as you are crypto seed and you see that this one i can basically
copy this to the clipboard or whatever or whatever but you see that where it says uh
you are calling crypto seed that's the actual um text that would appear in the uh in the qr code
So that's one example of, of, you know, have a stack of our technology being used to do something. Another would be if I tap back and say backup as SS care multi.
Oh, we lost. I think we lost your mic, your connection again.
Well, it's going to get that back. This is fascinating.
So, yeah, I'll say a little bit, you know, while he's coming back, you know, I showed you LeethyKit.
So one of the big challenges for, you know, we want to serve the whole community.
This is a little tiny 200 by 200 display.
So when we designed the QR, we wanted it to be able to do animated QRs on this very slow processor with this very slow screen.
That only has 200, you know, by 200 black and white things.
It works.
And, yeah, it takes a little bit longer, but it's, you know, you can do some, you know, we did, I think we did, you know, like 100,000 character PSBT with it, and it worked.
Similarly, Wolf worked really hard to make sure that the life hashes, you know, which help you recognize things.
So I obviously printed this on a regular piece of paper, so there's no color there, but it's recognizably the same thing as the purple one.
So even though I don't even have necessarily the same display, it has a design for high contrast that lets you do things.
And we also don't want to lock people in. So we support, you know, all of the, you know, you know, good old fashioned BIP 39.
And and but sometimes the dates are really useful to know when it was created and the notes come along with it as well.
So I can say, hey, you know, this was only used with some obscure wallet that I don't use anymore, but I'm keeping it because it's got some dust on it.
Because I know I have some dust from when Bitcoin was, you know, $30 that all of a sudden, you know, I came back to an old wallet and it's saying, gosh, I've got 500 bucks there.
So, you know, you can save all those.
Let's see if Wolf's microphone's back.
Nope.
Can't hear you, Wolf.
Nope, no wallet.
it um nope okay so um uh i want to what time did you want to run till i've got plenty of time on
this end uh but one thing okay i mean sure so we'll let him work on that for a moment um you
know so you can kind of see what we're trying to do in general and uh uh you know in many ways
It's, you know, this is evolving as we go along.
So one of the challenges with PSVTs, I know you ran into this with Coldcard, is, you know,
how do I coordinate between the transaction coordinator on your computer, which because
it has to have all the inputs for your transaction, and the only way it can get it is from the
that. And then you have to get that onto your phone or onto your device in the case of a cold
card. But when you start talking about multi-sig and descriptor wallets, well, that means you might
need to get an XPUB from Casa. You might need to get another XPUB from your Trezor. And you want
another xpub from your wife um can you hear me now now we can so that becomes a challenge so
um our emerging stuff lets you hand you know make that part the whole setup before the psbt happens
a lot easier so we'll show crypto account in a second so go ahead yeah so yeah so i apologize
for that um if this keeps happening i'll switch i switch to a different microphone actually so
hopefully this one will uh not cut out on me um so uh yeah so we're talking about sskr and um
the actual uh as i mentioned before sskr breaks up your seed or whatever data you want into
chunks that can be distributed to various people and so you can say there's you know if you if i
have you know five people and i want to share that among five people then i can say okay three of
five. And you can see I have one group of five shares with a threshold of three. That means any
three of these five shares can reconstruct the key. So let's assume that's what I want to do.
I say next. And then basically you can either print the shares, you can share them all as
byte words, or you can share them as UR crypto SSKR. That's another kind of UR. Again, URs can
be used for any kind of data. And so for example, if I wanted to print them, then I get these coupons
that basically each have a QR code on them.
They have some byte words,
but they don't have the actual seed.
They just have a chunk of the seed,
a share of the seed.
There's actually two pages here
because there's five shares
and there's four per page.
So I can cut them up
and I can actually physically hand them
to other people.
And then when I get back three of these
from anybody I've given them to,
then I can use SeedTool to reconstruct them.
And so let's,
but I'm going to move forward
in terms of demonstration.
A seed tool has a scan function that lets you scan individual seeds or SSKRs or requests for seeds or derived keys.
There's actually a lot there.
So let's go back to the main seed.
And let's say I want to use Sparrow Wallet to have an account, but Sparrow Wallet is connected to the Internet.
And Sparrow Wallet is on my computer that's connected to the Internet.
It possibly has security vulnerabilities or whatever.
i want to keep my seeds from which my private keys are derived um absolutely offline and so
let's say i have an ipod touch my iphone will stand in for that right now where i have for my
seeds um and let's say i'm going to use uh this one uh uh the dark purple aqua love seed uh which
again is just um it's a sequence of random numbers but it's a unique sequence that i've generated
and so i'm going to tell i want to authenticate and then i'm going to say derive a key
now i can either derive a cosigner private key which is again a standard from blockchain commons
of how to do multi-sig cosigners but i'm going to go to the other key derivations in this case
and this is a fairly involved page here but starts but it's a workflow it starts with the
c at the top you get a certain parameters and then you can see there's the private hd key that's
been generated uh there's the public hd key and below that an address and so you can just use
that address and and receive receive it there but you can say whether you want this asset to be
a bitcoin address or an ethereum address if you do an ethereum then you can see it's switched
over to ethereum's style of uh of identifying accounts or uh or private keys um let's say i
want a bitcoin main net and you can derive you know cosigner paths uh or segwit paths or you
can enter your own custom paths um so i'm going to keep it on master key and i'm going to go down
here where it says secondary derivation now i can either generate the public key which you see is
what's being what's below the public hd key or i can set it for an output descriptor uh bitcoin
output descriptors are a way of describing a uh a range of uh of uh of ways to derive uh other
public keys or there's the account descriptor which is a whole bundle of output descriptors
And so an account descriptor, in this case, you give it an account number.
And then the last step below is it says, here's your account descriptor.
And it's a long UR.
So in this case, I'm going to show it as a QR code.
And you can see that it's now an animating QR code.
This is a longer QR code that's been broken up into chunks.
It contains a bundle of output descriptors.
And this is something that other wallet developers can write code using our open source implementations to read.
So I'm going to use Sparrow Wallet here.
Sparrow Wallet, developed by Cray Raw, is one of the first to support our technologies.
So I've got no accounts right now.
So I'm going to tell it I want to create a new wallet.
And I'm going to call it Arcane Commons.
I'm going to create that wallet.
And now it's going to say that it currently doesn't have an actual key.
It needs a public key because, remember, the public key is going to be on my laptop.
There's going to be no private keys on my laptop.
So I'm going to say I want to connect an AirGap hardware wallet.
And now Sparrow supports a number of different ones.
And if this were in light mode, then you should see our logo better, but C-Tool is one of them.
um and uh i just put in dark mode before the podcast and now i've now i should suggest to
craig that he should make these stand out better um so anyway so uh seed um sparrow wall helpfully
gives you details about how to derive these now i just did this uh on c2 you can still you can
still see it's animating back there and like i said this is a fountain code i can actually pick
up anywhere within the sequence and you can dip into the fountain and pick up from the stream
and read the whole thing so I'm gonna say I want to scan it and let's see here
okay so this is using my webcam so I'm gonna hold this up
another other yeah there we go yeah other left right backwards
there you see that progress bar so it read several the qr codes starting anywhere and now as you can
see it has an x pub here and that was derived from the seed and it picked which one it wanted
it wanted a uh a witness public key hash coming from a seed tool and so this is that how it
derived that key and how the wallets to use that key so now when I say apply I
can just have no password on this one now basically I have an account here's
the transactions now if there were any actual transactions on this it would go
out that you know sparrow wallet because it's connected to the internet would go
out and do them now when since I don't have any transactions on this I'm not
going to carry through and do a PSP T but then what you do is you would
construct a partially signed Bitcoin transaction from the balances, from the UTXOs on this account,
then you would transmit a, a PSBT back to C tool that would then recognize, oh, it's asking for
the seed that I already have. So I'm going to sign that PSBT and send back the signed PSBT back
to Sparrow wallet. And then Sparrow wallet can put that onto the network. So, you know, it's,
it's, there's basically kind of a conversation between your online hot wallet, which only has
public keys and ctool which uh only has the seeds and can derive private keys on on on demand
but does so in a highly secure way would sparrow even be a hot wallet in this case or would it be
a watch only wallet that this is a watch only yeah yeah it'd be considered a watch only wallet
yeah so it's but again they're different scenarios i mean part of what we're trying to figure you
know we are with smart custody and some of our efforts trying to uh make it easier for people
to consider what is the right scenarios for things.
So you could have one key on your Mac,
one key on your phone,
and one key in an SSKR among your friends
in a two of three multisig.
So that means that there's no single points of failure.
Your Mac could die.
You lose your iCloud account or whatever.
Well, you can go to your friends and your phone
and still recover it.
um you uh can uh you know you know you're you're not all nine of your friends abandon you
uh you can still recover uh your your iphone can die you can still recover so that's back
to those gordian principles of resilience um and but the workflow is exactly the same i need to
give you uh a uh an x pub and there are also shortcuts so like this is a a special uh shortcut
um so if i if you use seed tool where's the camera if you use seed cool tool with this
this is a request that says please give me an x pub and if um uh you know if uh wolf scanned that
it would basically say hey somebody's asking for an x pub um do you want to give them an x pub and
if you do which seed do you want to give it and you choose and it will streamline the whole process
of setting up the accounts and all that kind of stuff so that's uh when you later on you receive
a psb needed to be signed it says oh yes i have the seed do you want me to sign the utxos of this
psbt that i know how to sign so it's entirely within the user's control and it seems like a
much better user experience particularly with the qr codes because now i'm thinking like i just spun
up a btc pay server and took an xpub from a hardware wallet and copy pasted it into the btc
pay server interface where i now what you just described and what you just demoed wolf would be
much easier if btc pay servers just like let me scan a qr code i just held up yeah an xpub from
exactly and that's and it gets even that's more secure too right switching btc pay to a multi-sig
i want this year's donations to blockchain commons on btc pay to go to a multi-sig account um that
has greater resilience and you know single points of failure etc and it's kind of hard to set up a
multi-sig with btc pay i mean it's doable um but all i would have to do with uh with uh the qr
thing is it would basically say, here's what I need to do a multisig. And, you know, it would
present the first QR code in a request and it would go through the different things. And I would do my
different wallets. I'd do my foundation devices and I'd do my, you know, Sparrow or Blue Wallet
or, you know, whatever else out there is there for my multisigs. And then at some point, BTC pay
says hey i have everything i need i'm ready to start um being your uh uh your invoices
because i have all the xpubs i need yeah it's crazy again like i said in the beginning of the
episode before we started recording i mean what you guys are building is very much underappreciated
in the space right now i don't think people particularly i don't call them laymen but
you're non-technical bitcoiner uh he's just a casual listener probably doesn't understand how
important these types of tools are well obviously we're we're working with primarily wallet
developers and and you know people who are working you know more core towards bitcoin
technologies but we want this to trickle down to all the end users you know right now like i say
if you're using sparrow wallet today you can use seed tool to keep your seeds and and and sparrow
wallet doesn't have to manage anything private so but you know there's no reason why people can't
create seed managers uh you know cold wallets things like that that use all of our technologies
to do the same thing and add their own secret sauce
because everything we're doing is open source.
And we're hoping that while developers and so on
will see that what we're doing is valuable
and support the blockchain commons
because we're a non-profit
and we're basically trying to create a better world together
and there's still plenty of room to compete.
Well, number one, thank you for building all this
and doing it the right way.
And number two, I think, like we said earlier,
again, we need to avoid as much potential tech debt
as possible so getting as many wallet providers or wallet software developers on these standards
as quickly as possible is just going to make scaling much easier and make loss of bitcoin or
like the thought because that's a lot of a lot of people think they lose bitcoin they just don't
understand that they're interacting with the wallet software doesn't know how to find their
derivation path they probably haven't lost it just can't find the derivation path where where it's
hidden. And we are trying to work on those two things. The project that Wolf has been working
on this week is called Gordian Recovery, which specifically is designed to go through the 40 plus
different common paths and gap limits and things of that nature to see, gosh, is there anything
out there for you? And again, since we're an ecosystem organization, I don't want to compete
with Sparrow or any of the others.
But if we can create kind of a universal process
of discovery to allow you to recover,
that's useful for the whole ecosystem.
And then you can recover it with your foundation devices
or you can recover it with any of the other people
that are supporting the standards.
And we think that's important.
And then obviously we need to carry this to Lightning.
Lightning has some additional challenges, state channels and things of that nature are kind of hard to do with hardware wallets.
There's some interesting new approaches for that.
And then, of course, we have to keep current.
There's Taproot and Schnorr and all that.
Yeah, and on top of that, there's new technologies that can probably be implemented into the standard tree building.
I think, one, I couldn't stop thinking about the cold card I know is working on
and Blue Wallet already has enabled to a certain extent as NFC capabilities.
Is that something that excites you guys or that you would stay away from
from a security perspective?
I have a mixed thing there.
I think it is something that we're going to need to support.
You know, if I'm got, you know, 5,000, 10,000,
I mean, it'd be different for everybody.
You know, somebody in India will have a very different, you know, number for that.
The convenience of NFC is amazing.
The still doesn't solve the multi-sig problem.
It just it makes the single signature problem easier, makes, you know, this back and forth that that Wolf and I were just demonstrating easier.
So, yeah, let's do it for there.
If that key on that NFC doesn't have total custody of your funds, it's just a participant in a larger multi-sig and the threat model against it, and you know exactly what it is, I might put more money on it.
But, you know, if I'm trying to save money for my children and my grandchildren and I am hodling for, you know, I never plan to sell for a decade or more.
No, I'm going to use something that doesn't use an NFC chip, which is, you know, could be potentially supply chain compromised and other different things of that nature.
So it's all about thinking about threats.
And, you know, we have a book free called Smart Custody.
You can go to smartcustody.com and download the old version.
You go to GitHub, you can see some new chapters that we're going to be adding to it for SmartCustody 2.0.
But, you know, how do we explain this to regular people is hard.
You know, so I wouldn't say we have a whole chapter on how do you do a threat model.
And, you know, my basic argument is, you know, don't do this unless you've got a significant amount of money of your net worth in Bitcoin.
And if you do, you know, spend a couple of hours to do the exercise we have you walk through.
And but if we can figure out how to make that easier and avoid some of those things, create some common scenarios that everybody can use, help you understand how to make choices, whether or not you're a brand new user who, you know, doesn't know how to make decisions or whether or not, you know, you're Avanti Bank.
another one of our patrons who is, you know, potentially, you know, storing billions of
dollars worth of funds, you know, as they grow. So, you know, those are very different threat
models. We want to be able to help make that easier. Thank you again for doing that because
it's imperative. And so that's what I wonder as we're having the discussion, like, is you think
there needs to be pressure put on wallet developers from bitcoin users to i don't want to say get in
line but to work towards the standards that you guys are working towards like what like i guess
to steel man what would a wallet provide if you use a wallet if you yeah if you use a wallet and
you think that you've seen some technologies here or you go to our youtube channel watch our
technology overview if you think your wallet ought to support these things well there's nothing
stopping people it's all it's all open source but if they feel like well this isn't quite right
there's something that is missing from this or that we need to add we'd like to integrate with
this well you know we're available to work with wallet developers to expand the technologies in
the directions that benefit the whole community uh and you know and so that's that's what we're
here for and you know so yeah i mean i would say you know i wouldn't put in this in terms of putting
pressure on them but you know ask for what you want uh and if you know if more interoperability
more support for air gap standards we're also working on uh tour gap standards where thing
where communication takes place over the uh the tour the onion router network uh for you know
even though it's connected through the internet it's much more secure and much more private um
so we're going to be doing products that projects that use that as well we already have some uh and
you know these things are all about the resilience of the community and the privacy of the community
So if you want that, ask for it and tell people that we exist and that, you know, that we can help.
Yeah, that's what I hope.
And we deserve the support, you know, and it's, you know, some of these companies are making, you know, millions and millions of dollars.
You know, especially if we talk about the tier one wallets, you know, say, hey, you know, support these, you know,
these types of things, not just in your code, but you've got the money, support them financially,
because, you know, we want these standards to be around 10 years from now. If somebody,
you know, basically says, gosh, there's this weird little trick you can do here that we didn't
anticipate, you know, we need to be able to fix it fast and deploy it to the whole ecosystem in
the same way that, you know, we were able to do in the early days of SSL when there were lots of
people supporting uh tls but then after 15 years you know it was down to one quarter time of one
person we don't want to get to that point we need to create a base that can last for decades well
i'm happy you brought the tls ssl experience up chris because that's what i wanted to sort of end
the conversation i was like what are the lessons learned from that uh open protocol project that
you worked on for quite some time obviously you've mentioned in fact it's been nickel it's at the
point where you someone argue that it's completely neglected which you don't want to see especially
if there's trillions of dollars of value flowing through it to a certain extent uh
what did what did you see during those projects that you want to avoid in bitcoin at all cost
is bitcoin doing well we could probably do a whole podcast on that um
And, you know, some of the early things are, I personally was shocked that it, so TLS 1.3, which came out in 2018, end of 2018, was almost 20 years after, if it had been out one more month later, it would have been 20 years after I finished TLS 1.0.
I never thought it would take so long. And realistically, TLS 1.3 really was TLS 2.0 or SSL 4.0. I don't know. You know, the numbers kind of get confusing after time.
Um, uh, but you know, there was, there's no pressure to, um, uh, there isn't sufficient
pressure to upgrade. So something I've encouraged, uh, other standards, I'm one of the coauthors now
of the decentralized identifier standard that W3C is getting close to finalizing on and verifiable
credentials and things of that nature is things like expiration dates. So yeah, maybe somebody
will use a cipher suite that is expired um but you know if uh you know uh some investor or somebody
else comes along and says hey you just lost uh you know a billion dollars of your stock value
because you know you're supporting things that were expired you know you know they can protect
their um uh their wealth that way so um uh you know for irresponsible uh stuff i mean i mean
It's hard. I'm sure that Tim Dirks at Google, who was my co-author of TLS 1.0, would have a different position there, but I think that the arguments are sound, that we can do better.
Another element that I think is real interesting is although decentralization, as we know it today as a term of art in our industry, we would say that TLS is centralized, right?
You know, it depends on certificates.
Certificates then depend on a route of trust.
But you have to recognize back then, we were trying to decentralize against a monopoly of Microsoft.
A lot of what my job as a standards leader was to say, hey, Microsoft, you've got to not be one ring rule them all.
You need to cooperate with the rest of us.
And we were able to eventually force them to participate in the commons so that we could all work together.
And that was a form of decentralization.
But centralization always creeps back in.
I mean, when SSL and TLS were first deployed, we thought, oh, well, there are lots of CAs, you know, and there's nothing that stops the Internet from having multiple DNS routes.
A lot of these different types of things were allowed, you know, for, you know, maybe not truly decentralized, but distributed choices.
But then over time, you know, VeriSign acquired a lot of the secondary CAs.
Then ultimately the browser companies discovered, oh, gosh, you know, the users don't need to decide what CA to use.
We're going to decide for them.
And so centralization creeped back in.
I believe that centralization can creep back into Bitcoin, Ethereum, into all of these different protocols.
because I honestly do not believe there's such a thing as perfect decentralization.
It may be – I can't prove it, but it may be impossible
because some parts of decentralization conflict with other rubrics of decentralization.
So we have to balance those.
We have to be able to allow people to make some choices there
to be able to make good decisions in the future.
i think one of the ways we see uh centralization creeping to bitcoin correct me if i'm wrong
christopher is like the mining pools that become dominant and things like that and so
when they gain a certain amount of hashing power they they basically are a kind of centralized
uh authority at that point um and so we try to you know the community tries to balance that out
does that sound right yeah and but it's other things i mean you know so mining pools and
obvious you know we can you know uh we're blockchain commons is not involved in kind
of a lot of the mining conversations, um, uh, for different reasons. Uh, it's not a place where we
can make a difference, but, you know, if we were all using, uh, you know, Ledger and Ledger clones,
um, you know, we would not, uh, have much innovation. Um, and, you know, when Ledger
decided, I mean, I'm sorry, picking on Ledger, they have sponsored watching common stuff in the
that in the past, but they're the biggest player out there. You know, over time there can become
incentives for, you know, Ledger to start throwing its weight around, you know, oh no, we don't want
Taproot or we don't want, you know, whatever the next latest thing is. And then it doesn't happen.
And so that's another form of centrality is, you know, lock-in, being locked into old choices.
So we want to allow for innovation, but we have to be cautious because, you know, in the end, it's the consumer sometimes pays the price for innovation.
So like one of the things when we were talking earlier about talking to your wallet vendors about supporting some of these different things, you know, Blockchain Commons has limited resources, you know, a couple of different engineers, number of volunteers, etc.
So we have to prioritize things. I prioritize things when two wallet companies want it. So when somebody comes to me, as has happened recently, going, gosh, we've really got to solve this problem in the silicon level where we would like to have elliptic curve done on the chip rather than in code on a secondary less secure chip.
um uh you know if i've got two companies that are interested in that problem um then that's
something that sort of triggers okay let's maybe do some research on this let's you know identify
the use cases where are the low-hanging fruit you know who else might we partner with or whatever
but my the signal that i need is that two companies want it um so like with the psbt uh
You know, Kobo Vault, which no longer is actively supporting, you know, another company's taken over their product.
And Blue Wallet, basically, they ran fast and implemented our very first preliminary version of our PSBT stuff way before we expected it to.
But that was a signal from the marketplace that interoperability was desirable.
And so we put a lot more effort into PSVTs and finalizing it.
And the versions that you see today are, you know, because more than one company are involved.
Yeah.
It's a fun space to play in.
Big problems to solve.
There's obviously on the wallet side too.
there's unfortunately or for some reason or another ego tends to pop into uh the conversation
and again like i think what you guys are working on is deeply underappreciated and i think getting
these standards out there as quickly as possible because if we what we assume is going to happen
in terms of bitcoin adoption is going to continue to go up is what i assume that we're assuming
you're going to have not only individuals getting bitcoin but people building on bitcoin
And being able to quickly create, not necessarily quickly, but create a standardization across certain processes that make it so people aren't just building on things that are never going to be able to be interacted with is massive.
And it does seem like you guys aren't getting enough shine.
And so, like, how can we, as a TFTC community, like, help you guys get more attention and more funding and more conversations going throughout the user's world?
One of the easiest ways is if you have a Bitcoin account, I mean, excuse me, a GitHub account, is support us through GitHub.
You know, a $20 a month patronage makes a difference for us.
Um, so, uh, we're at the point now where I can hire, you know, a half an engineer, um, uh, FTEs
off of our GitHub revenues. Um, obviously we accept Bitcoin through BTC pay. Uh, you know,
we've received grants from, uh, human rights foundation and others. So, and, you know,
encourage these organizations to still do so. Um, but also, you know, you can volunteer, let's say,
You know, I mean, one of my challenges, I'm the executive director and principal architect, which means I'm spending far too much time, you know, coordinating, trying to get grants, talking to different people, writing, you know, various people, you know, volunteer to be in, you know, to work with us on these types of things.
Or if you're a coder or a writer, help us write better documentation.
One of our very successful projects this year was to translate our Bitcoin course to Spanish and Portuguese.
I would love to see an Italian version of the course.
Some of our other material, even if you're not kind of at the level of doing Bitcoin Core command line stuff,
You know, we have other documents that could be translated or be updated or made easier and more accessible to people.
So there's a lot of volunteer opportunities as well.
Get on it, freaks.
Doing very important work here.
I guess before we wrap up here, we've been deep into the technical details of the project and what you guys have been working on within it.
But what are your views for Bitcoin's future?
Are you optimistic that it will succeed and continue to succeed?
do you think it's an imperative how and why are you working on what you guys are doing
outside of creating standards so other people can play nicely together
um well you know uh obviously i like to it's not really a brag because it's also kind of a shame
because you know the first bitcoin ever purchased were for under 10 cents on mount gox way back when
if i'd never sold any i'd be set for life but i did so i'm not actually lived off of bitcoin for
year while working on a startup idea that didn't really take off. But what I have left, I'm holding
on to. And I've always believed that the future of Bitcoin is bright. I deeply believe that it's
a world-changing technology. And I'm really honored that Christopher asked me to work with
him on Blockchain Commons because it's benefiting everybody in helping that technology change the
world yeah for me what i think probably one of the biggest things is um obviously you know i have
some bitcoin from my work at blockstream and and other stuff but blockchain commons uh largely
is a bitcoin organization in that we pay everybody with bitcoin um you know as much as possible
you know we don't want fiat um i mean yeah i you know github is easy and convenient for those
people want to do 20 a month or whatever um you know i would love to be able to have be able to
have something like that for uh for bitcoin in the future um but because of that you know the
fact that bitcoin's down right now or up or whatever you know it has an impact on us but
Not nearly as much. I mean, basically about as much Bitcoin went in this year as went out.
So we're I consider and we have new technologies and new capabilities.
I can I figure that's a win. I don't care as much about the up and down.
And I would say, you know, when I you can find an old video of me talking about introducing Bitcoin or whatever from 2015 or 2014.
And I'm kind of going, oh, you know, it's kind of stable right now at 30, you know, and, you know, I'm just not thinking about Bitcoin and, you know, versus fiat.
Bitcoin is Bitcoin. It's the way we're going to be transacting and interacting with people around the world.
And at some point, you know, obviously not this year, you know, we may no longer even be referring to a fiat value.
I will pay X Bitcoin an hour for the professional, you know, cryptographic protocol engineering work that we do.
So that's the future.
It's pretty bullish. I'm very excited to hear it because I usually have developers working on the nitty gritty and they're some of the most bearish people I've ever met because they know how things like tech debt and trying to make all this interoperable. So I'm very happy to see that you guys are optimistic about the future of the protocol.
on again thank you for all the work that you guys do it's underappreciated and it's very high
leverage in terms of making it so future bitcoin users not only bitcoin users today but some that
haven't even been born yet are able to leverage software that can work interoperably which is
imperative if if you actually want to scale this thing to the masses yeah well thank you for having
us. And
when we have
the next major release of something, we'll be
glad to demo it. Or if you've got some specific
thing you want us to look at, I'll let us know.
Yeah. No, I'd love to have you guys back on.
If you're ever in Austin, please
let me know. I'd love to meet up in person.
You've got to get out to a BitDevs meetup
in Austin.
I've been to a couple, so we'll have to
do it again. Oh, hell yeah.
All right. Where can we find you guys?
Where can we find out more information about
the Bitcoin Commons?
Yeah, blockchaincommons.com is our main website. Obviously, we're a developer organization, so most of our work is on GitHub, Blockchain Commons. And there's six links at the top that have our most important projects there.
um you can go to smart custody.com to get uh the book which still i i still think it's you know if
you're you know kind of a intro ledger class um single sig user still i think has the the safest
uh process for doing a single sig uh for bitcoin cold storage uh so that's a free book uh smart
custody.com and then if you want to you know uh you know play around with life hash life hash.info
uh we didn't talk about torgap um but we're also you know very uh uh active in trying to figure
out how to leverage uh the privacy tech those privacy technologies so we have something called
spot bit so spot bit.info is a decentralized it's more distributed than decentralized we want it to
be this decentralized price server for bitcoin so it basically looks at you know uh you know 50 plus
uh different price uh servers and volumes around the world and allows you to either use our data
or you it's an open source thing you can go put it on a five dollar vps somewhere and you can
decide how you want to price bitcoin versus around the world uh wolf and you got to sit through tor
Yeah.
So, yeah, so our Gordian recovery tool that I'm working on now, which will also be an iPhone app, will use Spotbit to get prices.
So you'll be able to, for example, report on the historical prices that you acquired Bitcoin at for your tax records, things like that, as well as recover and possibly even sweep accounts eventually.
Although, again, it's an online tool, so it doesn't have to handle any private keys.
you can have it you know for example you will to put a bit 39 that you don't know what's on it
and it'll find all the things that might be there on the account it'll create a psbt you can send
that over to c2 over signing send it back and sweep that account to something else so the idea
is there's a very clear separation of interest if you're doing a tax return or whatever and you need
you know like information for capital gains you will use spotbit through tor to get pricing on
those things so you can document your transactions. So, you know, that's again, very clear separation
concerns and upholding the Gordian principles at every step.
Hell yeah. Freaks, if you're listening, go check all this out. We're going to link
to as much of this as we can in the show notes. And just want to thank you again,
Christopher and Wolf for the work that you're doing, for coming on. Can't wait to do it again.
Very excited to see what you guys produce going forward.
Thank you.
alright that's all we got this week freaks
peace and love
