TFTC: A Bitcoin Podcast - Rabbit Hole Recap: Week of 2019.03.11
Episode Date: March 14, 2019This week Marty and Matt are joined by Adam Ficsor (@nopara73), Founder of Wasabi Wallet, to discuss: - The current dust attack against Wasabi users - https://twitter.com/nopara73/status/1105779583410...946049 - CoinJoins - Privacy - Unchained Capital multisig vaults - Porn KYC in the UK - Drop in BTC transactions - Trezor vulnerabilities Thanks to this week's sponsor, Unchained Capital. Check out their new multisig vault solution today: https://www.unchained-capital.com/vaults/?utm_source=MartyBentNewsletter
Transcript
Discussion (0)
What is up, freaks? Welcome back to Tales from the Crypt. It's your boy, Marty Ben here on a Wednesday afternoon, a very special Wednesday afternoon. We've got a very special guest in the studio. Well, in the virtual studio today. Before I introduce our very special guest, gotta give a shout out to this week's sponsor. This episode is brought to you by Unchained Capital down there in Texas.
they eat steak they drill for oil and now they're setting up sitting around and figuring out the
best ways to secure your bitcoin it's a great state and a great company check out the multi-sig
vault platform that they just released on monday they did a presentation at the austin bitcoin
developers meetup you guys can go check it out i think there's a link on that meetup page
so you guys can enhance your security preserve your sovereignty unchained vaults are compatible
with Trezor and Ledger. You hold two or three keys on your own device. It's 100% cold storage.
Time to get your keys off the exchanges, freaks, if you're willing to take this responsibility into
your own hands. And if you're holding a bunch of Bitcoin with a single key, look into multi-sig.
We've been talking about this for a while in this podcast in particular. Multi-sig is definitely a
safer way. It's time to take security seriously. Learn more at unchained-capital.com slash vaults.
That's unchained-capital.com slash vault.
And if you create a vault, it's a special deal they're throwing in.
You'll get free access to the Bitcoin Standard Research Bulletin by Safedine for three months.
So you get three months of a free quality newsletter.
It's an incredible resource if you haven't read it.
Go create a vault today and fall further down the rabbit hole.
Freaks, I'd like to introduce you to a very special guest.
We've been talking about a product he's been building for weeks or months now.
Excuse me.
We have a special day dedicated to this product.
Today is that day.
It's Wasabi Wednesday.
I'd like to introduce you freaks to Adam Fisker, a.k.a. Nopara.
Adam, welcome to the podcast.
Hey, guys.
Thanks for having me.
Well, thanks for coming on, Matt.
This is a big week for you in particular.
I'm going to let you take it away from here.
It's been a long time coming.
Really happy to have you, Adam.
Thank you for reaching out and coming on.
We never do remote pods, particularly for Rabbit Hole,
So we, we made an exception for you because, uh, you're just doing really good work.
Thank you.
So you went to, went to check to, you went to their office, to Twitter office to check.
Oh no, I didn't.
But, uh, yeah, I went down, I, uh, I went to Twitter, see what's going on down there.
Uh, I was not able to, uh, to get past the Twitter security guards.
I was able to get past the, uh, the square security guards.
and sit down with Jack.
It was fun.
Apparently, he's a freak now.
He was tweeting about the podcast last night.
It was pretty cool.
Yeah, you could be listening to this pod right now.
Could be.
So try not to self-censor too much.
All right, we're going to...
But yeah, it's Wasabi Wednesday.
Wasabi, this is a topical news show.
Wasabi was in the news today.
You guys are experiencing a dust attack right now?
Is this...
What's going on with this?
We'll start with this
then jump into uh more particulars about wasabi after that all right jumping into the technicast
right away it's it's really interesting you know uh well first i tell you what is the dust attack
and then i tell you how it happened in wasabi because that's different in in a dust attack
just if i'm a blockchain analysis and i see someone that made a bitcoin transaction
like two years ago i sent him some money to that address two years ago and then i want to see
if he joins together that coin with it on his world address what i sent with with a new
transaction of keys and with that i can connect whether the two wallet clusters so this is the
dust attack knowing wasabi it did not happen of course because they were sending money to mixed
outputs right so they don't know who they were sending money to and i'm not quite sure what
they were trying to achieve with this so i think it's an experiment that they want to see what's
happening when when when this is you think when this is happening i'm i'm not sure what they
achieve with this or want to achieve uh it's a good question i can speculate but but but i can't
tell you what if it's effective or not yeah so so with dust attacks like usually involves a very
small amount because in traditional dust attacks it involves a very small amount because they're
They're hoping that your wallet doesn't have, not your, wallets in general doesn't have good coin control.
So it'll include that small little transaction, whatever, a small little UTXO in whatever transaction you do.
And in this case, it was, it was also a very small amount.
It's like three cents or something.
Now, the main, you were saying, you were saying online, it's a relatively, you know,
Wasabi automatically separates them out by UTXO.
So you see the dust sitting there.
The issue is that it's currently showing that it's got a high anonymity set, right?
So the update should basically, you're going to basically not show that high anonymity set that doesn't exist.
And what are you going to do, hide it?
That's the plan?
Yeah, so, you know, it's blockchain analysis.
Wasabi has some built-in blockchain analysis heuristics, which are, of course, just emphasizes the difficulty with blockchain analysis because this dust attack tricked Wasabi's blockchain analysis tool.
What we did is simply we count the equal outputs of the transaction and that equal output, how many equal outputs you have, that's the anonymity set.
that's the basic heuristic now I could filter this out in the new release which
actually I released right now it's it's on github it's not on the website yet
but I could filter this out okay but the anonymity set cannot be higher than the
number of inputs which is going to be only one in this dust attack which is
which will happen right now but then the attacker could say okay but I will do
this dust attack in a way that i sent from like five different inputs inputs and and and so he
can play it out uh well fine play it out but uh i mean it's dust it's by definition uneconomical to
spend so that's one wasabi bug that it shows the wrong uh anonymity set well okay we fix it but
the other bug is that it's it's so small that it's uneconomical to spend so we are not going to show
it up uh from the next really it's just uh it's in your wallet but you're not gonna see it because
it's just too small that it it is more expensive to spend than not to spend it right so we're just
not going to show up the dust and so as a sort of adversarial thinker are you excited about this dust
attack at all or are you more stressed than excited yes i i am very excited because it's a
it's a mythical attack right it it never happened before so
So research papers were writing about it, but there were no concrete examples.
The closest thing I've seen is that Bitcoin mixers were dusting other Bitcoin addresses,
but that was not a dust attack.
I'm not sure what they were trying to achieve with that.
Probably some marketing stuff.
So this never happened really before.
And I have a feeling it was not blockchain analysis, actually.
You don't think it was blockchain analysis?
I don't think so.
So in Vostok, we are experiencing a host of attacks, different attacks.
for example we had a Twitter group both close thousands of bots were coming
into into was a big group and yeah I don't want to talk details yet because
I'm not sure, but all evidence, all clues points to a specific competition who, yeah,
so we will figure out eventually. I don't know. This is quite childish. I mean, the
The Dust attack was not that effective.
The Twitter bot attack was not that effective.
Anyway, maybe we will hire Chainalysis to figure out who are they.
How the tables have turned.
So you said Twitter group, but you meant Telegram group, right?
When we had in the Telegram, we just had thousands of bots entering the Telegram group.
Yes.
Um, yeah, I mean, these kinds of things are good, right? Because you, you wasabi needs to be able
for it to be a useful tool. It needs to be able to withstand all, all sorts of types of attacks,
right? It needs to work in an adversarial environment. Um, one of the things that's
interesting is that I, me and you had a back and forth online about, uh, best practices for using
wasabi and really if you want it to be as private as possible you should never combine any
transactions after you go through the wasabi process after you go through the coin join process
uh and you and you should really use wasabi as like a spending wallet right where it's
where it's the rather than like an intermediary wallet where you're going from you know a kyc
exchange through wasabi and then to like cold storage or a hardware wallet and if you used it
properly if you used it in that in that manner then the dusting would literally have zero effect
right because you're not combining any transactions to begin with so this mostly targeted people who
were combining after the coin joint yes this is another very interesting point that's a
So one systemic risk that I experienced, one systemic, actually only one systemic privacy issue there is with Wasabi, what I, what we figured out, which is how people, how some people use the wallet.
from their hardware wallet they send it to wasabi and then they send it back to
their hardware wallet of course how their hardware wallet is doing they send
all their addresses back to their backend server so so so that's not idea
and in this dust attack dust attack that's is my speculation that as as I
seen half of the people who has the dust were sending it out with zero link
outfits so I think what they do is that they click select all private and they
send back to their hardware well it's so it's like half of the people use it with
hardware well that's a that's my speculation that's that's so if this is
true then it kind of shows that they did not really expose more things with the
dusts than they otherwise would because what I see is that they were
always spending zero link outputs with dusts so you could assume you could go
into the blockchain and check it but i i don't want to spend on a block explorer all my day
so you could assume that the mixed outputs corresponding with the dusts uh they were
spending it together in fact they were just spending all their private points into their
their hardware wallets which is just a bad practice until wasabi doesn't integrate hardware
what uh this is this is happening but if if this was the case then that dust attack did not have
any effect uh on helping blockchain analysis but yeah someone should look at look at it more
truthfully more deeply because i'm not quite sure at this point it's it's it's interesting
yeah because it doesn't really tell them anything new like they would know that you've linked those
six utxos or whatever that went through the coin journey process are probably the same person
combining right so even though it has that seventh seventh utxo in there that's the dust does it
really actually tell them it sounds redundant right yeah i kind of i'm you know maybe my ego
is getting like the best of me a little bit but i was getting a lot of shit for saying that people
you know you you lose privacy if you combine but you know if the alternative is is to not do it
uh you're probably better off going through wasabi anyway um and and i i when i saw this
attack i was like someone's just trying to teach me a lesson you know that you're gonna have 50
of the people are combining and and now we have like kind of proof that 50 of the people are
combining after the fact um but uh it's i think it's definitely like oh it's a it's a wake-up
call for people but my issue is is is privacy is such an issue with bitcoin to begin with um and i
think one of the best things wasabi is doing besides making coin join very user-friendly
is that it's really waking people up to how bad it really is right like none of these wallets have
good coin control like when people are using ledger live or using treasures web wallet um they
have they have zero control of which of which outputs are are which inputs are being selected
and and they're super vulnerable to dust attacks to begin with right and all sorts of blockchain
analytics so to me if the alternative is the person saying i don't want to end up with 100.1
new txos and possibly have a huge fee burden uh in the future so i'm not even going to use wasabi
like is there a situation here where i've like been trying to work it through my head is there
a situation here where using wasabi like hurts your privacy like there's i think it's always a
net benefit regardless like even if you combine like if you combine afterwards it's it's definitely
not as private as if you never combined but it's got to be a net benefit no yeah so so the one
one issue that can happen is the blacklist blacklisting right because coin joint transactions
can be seen from the blockchain so we just blacklist stuff those are coming from coin joints
which is which is just another mythical thing because it's not happening or what's being
blacklist that is like from darknet market to exchange that the transaction
if it goes through a mixer then they don't care about it anymore because they
they kind of lost the track they could steal the anonymized but then they have
to introduce more heuristics and more unreliability anyway so but they can
start blacklisting right it's if no one prevents them and what if they start
blacklisting mixing while then we we kind of failed building money i don't know go to work
for monero or something like that it's uh it's it's really it would be a really terrible situation
uh yeah well what i like to say is like i feel like if if if they start black you know if if
they if they say you can't send directly a coin join uh a utxo that was just coin join like
directly to coinbase or something um then then users start you know doing like a ricochet
situation where they do like four regular transactions after the coin join and then
they send it and if at that point they're still blacklisting like anything that has a history of
coin join in it like we're fucked like bitcoin is is like completely fucked at that point so i don't
i don't think it's like a real concern for people to be like i don't want to hold coins that have a
coin join history because if if that actually ever becomes a true concern then we have way bigger
problems well also what if it just lights a fire under everybody's ass to just be like fuck you
i'm gonna send my bitcoin to a coin join and it gets to like a tipping point where it's like all
right most of the coins are going join now what are you going to do about it just not let people
transact on bitcoin yeah i mean that's one of the reasons right one of the reasons why i think it's
important that we we get more people to use it um as quick as possible is to kind of like push the
hand like make it so that um it becomes untenable to do anything so this is probably a good segue
uh adam let's talk about like the growth of wasabi like how how how much liquidity you guys have
on wasabi how much that's been growing and how much that's been helping the anonymity set over
time a lot we are kind of tripling our user base every month and that's huge
huge growth in this beer market I am not sure what to expect we did not do any
active marketing only like when we got a when someone asked us to go for a
conference to speak or something like that then we went but we did not do any marketing so it's
just as organic as as it can get so yeah i'm kind of scared i mean it's so much money so much money
goes through it and i have to make sure everything is super stable and and ready for
for wasabi wednesday is this your uh is this your sastoshi uh don't kick the hornet's nest call
right now or i uh so so the the coordinator the coordinator fee address is a public address right
um so we can it's it's relatively transparent how how the growth is going right because you
can basically extrapolate based on how much fees you guys have gotten yeah which i think is pretty
cool no and that's like one thing i'm interested to see is like how because that's one thing we
talk about like matt expounds upon in particular is that privacy loves company so i'm a suit like
the increase in liquidity and amount of bitcoin being shuffled through wasabi is that allowing
you to sort of uh up the um the maximum like coin join that you can do the maximum amount of bitcoin
and you can sort of engage a CoinJoin with, right?
So it speeds up the process.
Yeah, exactly.
It speeds up the process.
It makes it more private,
and it just makes it way more useful of a tool,
like the more people you have using it.
The actual default anonymity set that Wasabi uses,
you can change on a user level.
um so you can up it and and lower it on user level it defaults at 51 um and then
and then once but it defaults at 51 but you can basically just keep remixing to increase the
uh you can basically increase the anonymity set by remixing yeah but but obviously
that's like more artificial you want more people to use it you want as many people to use as
possible so so that you're you're hiding in a bigger crowd exactly um so adam how many how
many bitcoin are on wasabi right now in total or have gone through that's what i'm trying to get
is where are we on the website it says it says 17,000 Bitcoin but that's just a
small part of it because these this only looks at the equal when join outputs
right so how many bitcoins to it like you know hundreds of thousands and the
interesting thing even with the change you know the change is not anonymized so
even with the change that's kind of anonymized because it cannot be the
anonymized in a in a large scale because it just computationally so expensive to
find all the all the combinations those are possibly in the change so if you
look at only one input and one change output you then you can do it but if you're looking at all
the coin joints it just takes a lot of computation so that's that's very interesting too
so i have um so you guys have been iterating extremely well um just constant updates we've
been seeing are there any big features on the horizon that you you might want
to highlight whoo yeah at least we are releasing the daemon a mixing daemon so
what that means is that you can fire up your command line you can say wasabi
mix wallet wallet name and it's going to mix for you without launching the GUI
without launching the user interface. So that could come handy for some people.
Other things, maybe it's worth mentioning the deterministic builds, which just means that
people can reproduce the builds. So members of the community can verify that the binaries,
those are built came from the same source code as it is on github so people
of the community can verify that I am not not putting some virus or something
into the the release binary so so that's that's that's an important thing to this
this just got released right now if you want uh something more interesting for the future that's
there's a lot to do yeah i mean don't get me wrong i'm extremely excited regardless
i those are both big big things and uh i just feel like every update it just it gets it gets
more user friendly easier to use um one of the other things i wanted to bring up is what was
what's the reasoning behind defaulting to the 51 default uh anonymity set um
why not why not make that higher yes i so it was a long time ago i sent out emails to people like
team roughing from coin shop uh ethan hayman who created tamba beat chris belcher adam gibson from
join market and sent out emails that hey we have to do something we decide something on this
anonymity set so we what should we what should we consider uh acceptable because there is just no
no research on it and and and decision has to be made and it looked like 50 seemed to be a rough
consensus on it and yeah that's that's pretty much it uh why not increase it right now i think we
should because actually remixing is very very more valuable than just mixing uh i don't know if you
notice that but if you are looking at probability and not and not anonymity sets then it's going to
be like if you mix once then the chances that your coin corresponds to your output is one per 50
right so two percent and if you mix again that same coin then it's exponential it becomes
exponential in theory but in practice uh whatever but but this intuition can show us that remixing
is much more much better however i did not expect people remixing even once at the beginning so i i
thought everyone's gonna just mix once and and be done with it but that's not what's happening
and we learned a lot uh since since then so so the point is that if we elevate it to 100 then
yeah that would be probably better but because that would incentivize remixing at least once
but on the other hand it would be like people already have green shields right and then the
green shields become not green, that might be annoying. That's
that's a UX one on one, you cannot disrupt the users
workflow like like eBay. The classical example is eBay, eBay
was yellow. They changed it to white, people were, oh my god,
it cannot be white, yellow is so much better. So what did eBay
have to do they wrote an algorithm that in one year changes the color just a
little bit lighter just a little bit lighter and it eventually became white I
never knew that that's hilarious I I do like that you can change your own
default in the configuration file. I was thinking, you know, putting that in the GUI could be
very useful to people so I don't have to, like, explain to them how to get to the configuration
file. And also I was wondering, is there my first instinct is that to use your own custom
anonymity set does that that that has to help you you right because because it destroys another
assumption right like if if if a bad actor is assuming that everyone's using 51 because that's
the default then you know if you use even like 57 or something uh but then my other thought was
Couldn't that make it even more trackable because you're the only guy using 57 anonymity set. Do you have any comment there?
Is that we should put it in the UI
Definitely just you know priorities
In fact, we actually put in this release if you click file open config file
That's that's how you will reach the config file, which is much better
but yes we should put it in the UI just just you know there are so many things
to do and I don't think this is that important yet the other other thing is
that the main problem with Bitcoin privacy is we don't have an adversary
which so security for security metric to to mean something it should reflect the
difficulty of an adversary overcoming this. But the issue
is that right now blockchain analysis companies just don't
care about mixing because 70% of all the darknet market users
are just sending money directly to exchanges. So they just don't
care about mixes because they have such a low hanging, so much
low hanging fluids that they don't even try to de-anonymize.
So, yes, we have part-time choosing adversary, right?
So we don't know if 50 or 100 and even the anonymity set metric is not that great
because remixing is much more valuable, but that's not shown in the anonymity set metric
because we should change to probability metric instead of anonymity set.
And it gets really complicated really fast, especially without a real world adversary.
So if you up it, it doesn't really matter if it's a unique or like a round number, right?
Like, so I'm saying like, is someone who uses like a 200 anonymity set significantly more
protected than someone who uses like a 205 anonymity set that maybe he's the only one
that's using 205 but a lot of people use 200 because it's a nice round number
yes so I am using 1000 on my on my server and server on my normal Bitcoin
well that's the time mixing through and I'm using 100 on the Bitcoin wallet that
my spending Bitcoin well that's I mean better yeah yeah actually I don't have
any idea, but those are what I've chosen for myself.
You saying that out loud, I'm using a thousand anonymity set, that doesn't hurt your privacy
at all, right?
Oh no, that just makes the mixers extremely unlikely. I mean, they wouldn't think that
someone is doing 1,000 anonymity sets. So it's just not even a reasonable assumption
to do that someone is doing 100 anonymity sets. Yeah. So, I mean, if I'm using much
more than normal people, then I'm just being more private. Not like it would matter again
because we don't have an adversary, but that was my thinking process.
of the problems with blockchain right is even if we don't have an adversary now we could presumably
have an adversary in five years that uses the same data that's that is being recorded now right
because this data lives forever um so we have to be basically we have to be prepared for like future
adversaries uh that might pop up and and and screw us over for things we did five years ago
which yes which actually brings us to back to the point that when you send to ledger and you
you send from ledger and send back to ledger well chances are ledger is not is not spying on you so
So it's like confidentiality is such an old metric, old way of doing security, so much
older than privacy.
So when you do that, then you have confidentiality and chances are they are not sharing your
data with anyone.
but it's better not to even give a chance of course but confidentiality is not as bad actually
the banking system works that way and and my my my neighbor cannot figure out how much money i have
in the bank okay he might can because i don't have anything i only have bitcoin but anyway go on
when when when people ask me uh like what one of my biggest like what some of my biggest fears are
for uh bitcoin uh specifically with bitcoin privacy one of my biggest fears is if if ledger
was compromised because not only do they have all that all that utxo data they're linking all you
know they're linking all your public keys to to you if if they are doing that um they also have
tons of our addresses because people got them shipped directly to us so they can link the pub
key to the address to the physical home address to the name to the credit card if you bought it with
a credit card yeah to an extent it is happening right now with the bloom filtering spv bullets
like your bread wallet uh they can tell you exactly how much money you have in your bread
wallet uh because the bloom filter collecting stuff is just so powerful uh that it's it's scary
but they don't have your credit card data
so that's not that bad
I feel like that's the problem with all this
is that right now privacy with Bitcoin
is way more of an art form than it is a science
if you fuck up one little thing
you have to think of all these little things
that you have to constantly be aware of and vigilant of
I think that's a good segue into the next question.
Adam is like, what do you think, if anything, Bitcoin can add at the protocol level to make
your job easier, to make not even your job easier, just to make privacy easier and more
innate on the Bitcoin blockchain?
Are you looking for something like Schnorr, Mast, and Taproot, or are you sort of content
with Wasabi-like privacy features?
so they could add confidential transactions and make everything that I
worked on so far obsolete that would be really nice
snore is is okay such no confidential transactions and we could decentralize
the coin joins more with with volume shuffle coin shuffle stuff that's that's
the big vision right okay one one part of that vision is coin shuffle plus plus
coin shuffle plus plus still needs a central server like possibly is this
exact same properties as wasabi just more decentralized still needs a central
server but decentralization is a scale so the central server only is only a
a bulletin board, which means the peers are just sending
message to the server, where and read other peers messages, which
is more decentralized, which is, which is quite nice. So this is
one way making wasabi more decentralized. And other thing
is the these amounts of we are always talking about, like, like
you have to have equal outputs and equal this equal that anonymity set whatever this confidential
transactions would solve everything uh if it gets into bitcoin which is a huge if but i don't want
to get into that uh for a moment confidential transactions blinds the amount so no one can see
the amount and that's the it's the that's the huge cheat there uh in terms of designing privacy
technologies and value shuffle which is built on coin shuffle plus plus is coin shuffle plus plus
using confidential transactions now how can we make this as economical as normal people as normal
transactions we introduce bullet proofs which makes confidential transactions
smaller and linearly aggregatable which just means if we have like 100 people
then the proof then the proof of the output it's not gonna matter anymore
because just people share the cost and the same with Schnorr Schnorr if you
have a coin join and you aggregate your signatures it's not signatures then the
input signatures become smaller then you're gonna get the signature so in a
big coin join 100 people participates only uses one signature so people pay
off their size on the Bitcoin network so that's gonna be great because now we are
at the point that because of confidential transactions and bullet
groups and snore uh bitcoin join would be even uh would cost even less than a normal bitcoin
transaction which is just great of course we need confidential transactions for that which is just
there are a lot of issues with with that so i'm not very bullish at this point of time but who
knows no one ever tried to to to define soft focusing into bitcoin with confidential transactions
so so you you never know maybe we need some better crypto yeah no and if the last decade has taught
us anything is that uh bitcoiners are very creative in ways in which they can figure out to
implement these types of changes and like you said that's something that we touch on here rabbit hole
whole recap in particular is if it gets to a point where like snore is implemented uh and
bulletproofs are implemented and it just becomes a better you're more better incentivized to to
join in a coin join transaction than a regular transaction like that is possibly the best way
to get get a private bitcoin is just make the incentive so it's it's inherently private
yeah if it's cheaper more people use it and more people use it then
then we have more privacy yeah okay so so we had a nice solid 40 minutes on uh wasabi
uh shall we shall we move into like uh like a 20 minute quick round yeah let's do a quick round
adam you're gonna uh we're gonna drag you into uh some topical stuff uh let's start out this
week sponsor unchained cap unchained capital excuse me uh launched their vault service which
which is bringing multi-sig solutions to the market,
more multi-sig solutions, I would say.
This is a pretty big announcement.
Like we said in the beginning of the episode,
you can engage with these multi-sig sort of schemes
with Ledger or Treasure.
Unchained will hold the third key in your two or three multi-sig.
You will have complete control of your coins at all time,
and you can sort of tap Unchained if you need them
to help you sign a message or something like that but 100 cold storage sovereign multi-sig solution
so my issue with the unchained cap multi-sig is that it requires a kyc check uh they take your
info and stuff and um the unchained team is fantastic like they say they're they're not
going to share this information and i completely believe that they have zero intention of doing it
but uh it is a it is could be a major privacy leak there um and it doesn't seem like
it has any regulatory requirement to do that because they don't actually have custody
yes they don't have custody so that's where i talked to drew and uh parker about this they
said that point in particular like they don't believe that any authorities could come and
subpoena information from them but so then why aren't they why are they doing the kyc in the
first place and my guess that they're doing the kyc is because they they want you to already be
through the kyc so that you can go right easily into their loan product uh okay yeah i can't speak
to that um but that sounds structurally right to me so i would say that uh and i think adam would
agree with me that is if you were going to use this product like you should probably go through
wasabi first i'm not sure i mean people people should not use wasabi just because it's cool
they should use when they realize that they actually need to reclaim their privacy right
otherwise it's just annoyance but when they they realize that it's oh if i don't use it it's a
problem then that's when they should but you don't think that if someone's using this multi-sig
if they're storing if they're storing coins with unchained capital and unchained capital has kyc
like if they go in there without if if they go in there without going through wasabi first
then they're just linking all their past transactions and potentially all their
their i mean the future transactions i guess don't really matter but they're they're linking
all their past transactions and like basically letting know uh the kyc service that they used
you know this is where i'm storing my coins you are right um i am not sold by them i i don't see
why i would use i don't see any situation where i would use their their things based on the
information i i know but uh there might be some some people who needs that i i i really don't know
yeah no i think this uh product in particular is probably best for like businesses and people
that are running businesses together that want to set up joint accounts uh with a third party
to help in a multi-sig facilitation i think this makes sense for them and there will be
products and companies that use bitcoin that are they're comfortable with this i would i would
argue and then people maybe family offices or trusts that that want the uh security of a third
party helping them in this custody solution it's a user-friendly play and also the i think there's
actually like a subset of clients that prefer that they do the kyc so they know who owns the
account yes yeah exactly and that's that's the thing it's like the thing we talked about block
last week it depends if it if it's in your risk appetite or not and this risk appetite being
your your risk for exposing your privacy uh and to who so if you are trying to hide all your utxos
and do not want people to know which utxos you own probably not the best product for you but
if you're uh in a business engagement and you need a multi-sig setup with your business partner
and you guys are okay with sharing your income and revenue streams
and being KYC'd on that platform,
it seems like a perfect setup for that type of environment.
Yeah, so should we – let's jump into – we're running short on time here.
Let's jump into the treasure vulnerabilities, I think.
Oh, I want to talk about porn.
Porn and KYC in the UK?
Yeah.
So the Brits are implementing KYC for porn.
you have to register your passport or register your government id with them to view it yeah to
view porn the uh the british government is making a list of porn watchers so any of you any of our
british freaks out there uh the government's gonna know what you're fapping to going forward
so good luck to you i just think this is like a perfect example of internet privacy uh violations
and that they they start with these type of things that can get uh more widespread support
and then they start expanding their speech block you know like maybe you can't access
wasabi's website or something they're gonna go they're gonna go right for 4chan after porn i bet
you um do you have any opinion on this adam
i i think that i think the benefit is that there's going to be a whole group of young brits
that are going to learn what vpns are and how to use them yeah even with that being said don't
watch too much porn freaks it's bad for you it's bad for your mind but if you're going to watch
porn like use a vpn like even if your country doesn't like kyc you like you could always get
blackmailed for your porn habits at a later date this is true so you should at least you should
at least use a vpn learn about it yeah yeah i would recommend it at least um good luck to you
our british brethren looking to fap out there um do not register do not register for the porn kyc
just use a vpn um okay so let's move to the treasure vulnerabilities um yeah this was a
hot topic in the bent this week wrote about it two days in a row uh charles gilmette from ledger
he's their head security officer i believed went to the uh mit bitcoin expo over the weekend
and displayed a number of attacks that the ledger security team was able to successfully
engage with uh using trezor hardware devices i watched the presentation live and then uh
uh watched watched it a couple times after as well to me it seems like a lot of these
vulnerabilities were disclosed by the wallet.fail team um earlier or excuse me late last year
uh so this wasn't news to me it seems like all the uh attacks uh either need to be supply chain
which every hardware wallet is vulnerable to or physical attacks where the attacker has physical
access to your trezor for an extended period of time which is an assumption i've been i've been
working under the whole time i've owned a trezor is if somebody ever gets access to this they can
probably hack into it like eventually with enough time enough skill set yeah motivation i mean the
thing is like compared to a seed if they get the seed on a piece of paper then they automatically
have access to it if they get the trezor like at least they have to be like more sophisticated
um as far as the ledger ledger is less susceptible to supply chain attacks because they have that
proprietary secure chip um that that is authenticated when you connect it to the software
um but that has its own set of risks because it's not it's not a little risk right or something
it's not open source so you don't even know what's going on with the chip you're like you're
like trusting them to a degree um so they both have their own trade-offs and of course ledger
is gonna attack trezor for not having that chip right that's their bread and butter um adam do
you have a preference over when you if you recommend a hardware wallet to a i guess like
a normal user do you do you recommend a ledger versus a trezor or trezor versus a ledger
so first of all i'm traveling so i'm always under the assumption that all of my possession is going
to be stolen from me and they are from time to time so i never used the hardware wallet actually
before um but now i wasn't even paying attention but now i i realized that uh
that hardware wallet companies are so hostile to each other i was right oh my god i i i can't
believe they they don't it's like shitting in the baby pool and ruining it for everybody they're
just yeah it's like that's what i was talking about in a side channel this week it's like
All these hardware wallets attacking each other is just having people lose confidence in hardware wallets overall, right?
Yeah, and it's procrastination, right?
Because hardware wallets can be, all hardware wallets can be hacked if you have physical access to it.
But that's very rarely the case.
and by the time you hack them, he's going to just move the coins
because he noticed that his hardware wallet is missing.
Yeah, and that's what...
Oh, sorry for interrupting, but Trezor came out with their official response
and that's what they said.
Like 5% of Trezor users are afraid of physical attacks.
Like more people are worried about getting attacked via their computer
or something like that.
There's been no known attacks.
We've never had...
I don't think we've had any known...
I mean, there's been $5 wrench attacks.
Right. But I don't think we've ever had any known compromises.
Yeah.
And then the other thing is like, if you use a passphrase, you're a lot more secure
because even if they pull your seed. And then if you use multisig with both the hardware wallets,
then they both have to be compromised.
Exactly. At the same time.
Right. So what would be a real issue if they would be able to figure out how to hack it
remotely, which is unlikely.
that's the scariest when i would when i would say okay i wouldn't recommend this hardware
wallet to to anyone but on until that happens i i just don't mind but i i do agree with the
logic about the the traveling like when you travel you should never yeah don't put it in
put it in nature's pocket or just don't travel no just assume yeah just assume that when you
travel like every single piece of that you have with you can just be fucking violated and searched
and taken from you oh yes that's the other thing yeah especially if you come to america that's one
of the reasons we we agreed to the remote with you because i completely understand your uh
you're never coming you're not coming to america for a long time so we really had no alternative
of um next up this is an interesting one so uh there was a precipitous decline in the amount of
transactions on the bitcoin network since the last time we met here on rabbit hole recap
some people were trying to attribute that to uh the rolling blackouts in venezuela and
uh it would have been a cool story if uh if it was true if it was true but it's probably not
true it turns out vera block that uh project that is uh basically securing other blockchains by
hashing data into the bitcoin blockchain they ended their test net i believe march 8th or
something like that um and that was probably the main cause of the transaction downturn but
uh it's an interesting case study in i don't want to say ethical block space use or efficient block
space use but it looks like uh vera block they're going to turn back their they're going to turn
their main net on i believe friday in a couple days here so maybe we'll see transactions uh
begin to increase again but it does beg the question like is vera block like the new satoshi's
dice uh are they taking up too much space is it a worthwhile use case of the bitcoin blockchain
this is why this is why the the the weight limit exists this is why there's fee pressure you know
if they if they do it then they're just going to end up costing themselves a ton of money
and uh they'll price themselves out it'll eventually become either it'll become unviable
for them yeah otherwise if they had unlimited block size they could just block weight they
could just do whatever the hell they wanted yeah it's it's surprising they're not using bsv
it's not secure you don't see you don't secure other chains with an insecure chain so
what are you talking about man satoshi's vision don't even get me started
um what else do we have here uh oh the texas proposed bill this is a good one for adam
did you see this bill adam in texas i heard about it but you could refresh my memory
they basically they said that if in that the only currency it's a proposed bill they haven't
actually
passed it or anything, but
basically
for a digital currency to be
legal, you have to know who the sender is
when they send it to you.
Yeah, Texas
is trying to dox
all their users.
I'm not even sure
how to react to that.
I think
laughing is the appropriate reaction.
It's
we are living in our own bubbles and they are living in their own bubbles and
right bubble is going to pop first how does our bubble win that's it i mean that's the uh
that's been part of like the overarching conversation of this podcast like the last
three months is or last three episodes in particular is like the governments are just
like historically too slow to move against this stuff adam maybe this is like a good ending topic
like do you you're on the front lines of building sort of technologies that
overtly conflict with what these governments are trying to achieve so do you think governments
do have the ability to move quick enough to stop the stuff that you're working on
look look at it think about this question bitcoin is legal this is crazy
can this be legal i mean this is going to destroy the largest power that governments have
printing money this is this is this can't be legal this doesn't make sense right so
based on this logic we might even have a future where privacy is by default
But, you know, it's not that crazy idea.
No, I don't think it's that crazy.
It still amazes me.
It still amazes me that...
Let's put our tinfoil hats on right now.
What if the government wants us to adopt Bitcoin?
That's why they're being so easy on us.
Well, that's best case scenario.
Like if the government is Satoshi, then...
Is it though?
Then we've already won.
You know, the future is bright.
we just have a lot of work to do that's right and that's why i'm ecstatic that we're able to
get you on this week adam you're you're an individual in my mind that's doing an immense
amount of work to to number one to show people that this vision's viable and this mission's
worthwhile and then number two you're actually producing uh good products that people are using
and helping out the community at large so i just want to thank you for for joining us for this hour
and all the work that you've done at Wasabi.
Yeah, thank you, guys.
Yeah, we have an insane amount of respect for you
and everything that you and your team have done.
I've been waiting for a user-friendly privacy wallet
since the dark wallet days of 2013, 2014,
where Amir and Cody were telling us
all these great things were going to happen with dark wallet,
and it's just never really materialized so it's um i i think that even if we don't
you know there's a there's a lot of improvements to to be desired uh on a protocol level but even
if we even if we don't hit those we have like a like this base minimum privacy tool we can use
is an absolutely huge, huge step forward.
Yeah, I wouldn't say it's base minimum.
I would say we cover privacy well.
There is really nothing to do about privacy anymore.
That wouldn't be procrastination.
It's just we have to make it more convenient, easier to use,
and faster and cheaper, and that's all.
This is what it all comes down to.
it's like privacy privacy is not an issue anymore privacy is solved you just have to make it not
bloat the blockchain and maybe a bit more decentralized things like that so yeah that's
my thinking i mean my my two issues i think that are like the is like the well one is like a low
hanging fruit um you know which is it makes sense that's not a priority but uh but people have been
talking about like hardware wallet integration like obviously obviously you can't um do do
live mixing with with hardware wallet because you need to be able to sign the transactions
it needs to be a hot wallet but if if we we need better ways of interacting with our hardware
wallets easily and um wasabi seems like a natural fit because it's got such good coin control it's
got tor built in it can use your your bitcoin full node uh like out of the box um so that that
that'll be i think would be a a pretty big a huge improvement and then the other the the main issue
i have with a at least in a pre-snore world uh with a coin join implementation is that if fees
do go up it could become it could become quite quite the issue which is one of the reasons why
I think it's important that people use it now
while fees are cheap, yeah.
Hurry up before Veriblock tears on their mind then.
Yes, one small thing I want to say that
it is possible to do hardware wallet Bitcoin join.
Now it is clear for me that it is possible.
It just work has to be done on the hardware wallet sign
for auto signing and basically the same script ability
needed that's needed for lightning network uh anyway i just wanted to mention this so what would
you you would like pre-sign for like a certain amount of days or something like a certain number
of transactions you would pre-sign something to that effect the most basic idea is that you tell
the hardware wallet that sign every transaction until ten dollar leaves the wallet and after that
don't sign any transaction right so it's going to mix and the attacker can only get 10 out of it
so yeah that's possible that's awesome i'll agree your heads up i think that's a perfect place to
end it this week we're at an hour adam again thank you for joining us and all the work you've done
um i don't know if you have a parting note or a parting message for the freaks out there but
this is your time yeah thanks thanks a lot guys my message would be that use
hardware wallets based on color color right it really doesn't matter if the
hardware wallet is well-known then don't don't don't be afraid of
scaremongering color is the most important thing if you like pink then it
should be pink i like that uh bedazzle your hardware wallet freaks that's the uh that's
the parting note and uh we we've we've shilled wasabi a ton of times on the pod but it's
wasabi wallet.io um it's available on on linux on mac on windows very easy to to install and use
and and you should at least check it out with some some small amounts of bitcoin and play around
with it and get you get your feet wet get your feet wet freaks and thank you again adam and uh
that's it for this week yeah peace and love freaks cheers bye
