TFTC: A Bitcoin Podcast - Rabbit Hole Recap: Week of 2019.03.11

Episode Date: March 14, 2019

This week Marty and Matt are joined by Adam Ficsor (@nopara73), Founder of Wasabi Wallet, to discuss: - The current dust attack against Wasabi users - https://twitter.com/nopara73/status/1105779583410...946049 - CoinJoins - Privacy - Unchained Capital multisig vaults - Porn KYC in the UK - Drop in BTC transactions - Trezor vulnerabilities Thanks to this week's sponsor, Unchained Capital. Check out their new multisig vault solution today: https://www.unchained-capital.com/vaults/?utm_source=MartyBentNewsletter

Transcript
Discussion (0)
Starting point is 00:00:00 What is up, freaks? Welcome back to Tales from the Crypt. It's your boy, Marty Ben here on a Wednesday afternoon, a very special Wednesday afternoon. We've got a very special guest in the studio. Well, in the virtual studio today. Before I introduce our very special guest, gotta give a shout out to this week's sponsor. This episode is brought to you by Unchained Capital down there in Texas. they eat steak they drill for oil and now they're setting up sitting around and figuring out the best ways to secure your bitcoin it's a great state and a great company check out the multi-sig vault platform that they just released on monday they did a presentation at the austin bitcoin developers meetup you guys can go check it out i think there's a link on that meetup page so you guys can enhance your security preserve your sovereignty unchained vaults are compatible with Trezor and Ledger. You hold two or three keys on your own device. It's 100% cold storage. Time to get your keys off the exchanges, freaks, if you're willing to take this responsibility into
Starting point is 00:00:55 your own hands. And if you're holding a bunch of Bitcoin with a single key, look into multi-sig. We've been talking about this for a while in this podcast in particular. Multi-sig is definitely a safer way. It's time to take security seriously. Learn more at unchained-capital.com slash vaults. That's unchained-capital.com slash vault. And if you create a vault, it's a special deal they're throwing in. You'll get free access to the Bitcoin Standard Research Bulletin by Safedine for three months. So you get three months of a free quality newsletter. It's an incredible resource if you haven't read it.
Starting point is 00:01:27 Go create a vault today and fall further down the rabbit hole. Freaks, I'd like to introduce you to a very special guest. We've been talking about a product he's been building for weeks or months now. Excuse me. We have a special day dedicated to this product. Today is that day. It's Wasabi Wednesday. I'd like to introduce you freaks to Adam Fisker, a.k.a. Nopara.
Starting point is 00:01:48 Adam, welcome to the podcast. Hey, guys. Thanks for having me. Well, thanks for coming on, Matt. This is a big week for you in particular. I'm going to let you take it away from here. It's been a long time coming. Really happy to have you, Adam.
Starting point is 00:02:01 Thank you for reaching out and coming on. We never do remote pods, particularly for Rabbit Hole, So we, we made an exception for you because, uh, you're just doing really good work. Thank you. So you went to, went to check to, you went to their office, to Twitter office to check. Oh no, I didn't. But, uh, yeah, I went down, I, uh, I went to Twitter, see what's going on down there. Uh, I was not able to, uh, to get past the Twitter security guards.
Starting point is 00:02:34 I was able to get past the, uh, the square security guards. and sit down with Jack. It was fun. Apparently, he's a freak now. He was tweeting about the podcast last night. It was pretty cool. Yeah, you could be listening to this pod right now. Could be.
Starting point is 00:02:49 So try not to self-censor too much. All right, we're going to... But yeah, it's Wasabi Wednesday. Wasabi, this is a topical news show. Wasabi was in the news today. You guys are experiencing a dust attack right now? Is this... What's going on with this?
Starting point is 00:03:05 We'll start with this then jump into uh more particulars about wasabi after that all right jumping into the technicast right away it's it's really interesting you know uh well first i tell you what is the dust attack and then i tell you how it happened in wasabi because that's different in in a dust attack just if i'm a blockchain analysis and i see someone that made a bitcoin transaction like two years ago i sent him some money to that address two years ago and then i want to see if he joins together that coin with it on his world address what i sent with with a new transaction of keys and with that i can connect whether the two wallet clusters so this is the
Starting point is 00:03:59 dust attack knowing wasabi it did not happen of course because they were sending money to mixed outputs right so they don't know who they were sending money to and i'm not quite sure what they were trying to achieve with this so i think it's an experiment that they want to see what's happening when when when this is you think when this is happening i'm i'm not sure what they achieve with this or want to achieve uh it's a good question i can speculate but but but i can't tell you what if it's effective or not yeah so so with dust attacks like usually involves a very small amount because in traditional dust attacks it involves a very small amount because they're They're hoping that your wallet doesn't have, not your, wallets in general doesn't have good coin control.
Starting point is 00:05:04 So it'll include that small little transaction, whatever, a small little UTXO in whatever transaction you do. And in this case, it was, it was also a very small amount. It's like three cents or something. Now, the main, you were saying, you were saying online, it's a relatively, you know, Wasabi automatically separates them out by UTXO. So you see the dust sitting there. The issue is that it's currently showing that it's got a high anonymity set, right? So the update should basically, you're going to basically not show that high anonymity set that doesn't exist.
Starting point is 00:05:46 And what are you going to do, hide it? That's the plan? Yeah, so, you know, it's blockchain analysis. Wasabi has some built-in blockchain analysis heuristics, which are, of course, just emphasizes the difficulty with blockchain analysis because this dust attack tricked Wasabi's blockchain analysis tool. What we did is simply we count the equal outputs of the transaction and that equal output, how many equal outputs you have, that's the anonymity set. that's the basic heuristic now I could filter this out in the new release which actually I released right now it's it's on github it's not on the website yet but I could filter this out okay but the anonymity set cannot be higher than the
Starting point is 00:06:37 number of inputs which is going to be only one in this dust attack which is which will happen right now but then the attacker could say okay but I will do this dust attack in a way that i sent from like five different inputs inputs and and and so he can play it out uh well fine play it out but uh i mean it's dust it's by definition uneconomical to spend so that's one wasabi bug that it shows the wrong uh anonymity set well okay we fix it but the other bug is that it's it's so small that it's uneconomical to spend so we are not going to show it up uh from the next really it's just uh it's in your wallet but you're not gonna see it because it's just too small that it it is more expensive to spend than not to spend it right so we're just
Starting point is 00:07:40 not going to show up the dust and so as a sort of adversarial thinker are you excited about this dust attack at all or are you more stressed than excited yes i i am very excited because it's a it's a mythical attack right it it never happened before so So research papers were writing about it, but there were no concrete examples. The closest thing I've seen is that Bitcoin mixers were dusting other Bitcoin addresses, but that was not a dust attack. I'm not sure what they were trying to achieve with that. Probably some marketing stuff.
Starting point is 00:08:26 So this never happened really before. And I have a feeling it was not blockchain analysis, actually. You don't think it was blockchain analysis? I don't think so. So in Vostok, we are experiencing a host of attacks, different attacks. for example we had a Twitter group both close thousands of bots were coming into into was a big group and yeah I don't want to talk details yet because I'm not sure, but all evidence, all clues points to a specific competition who, yeah,
Starting point is 00:09:28 so we will figure out eventually. I don't know. This is quite childish. I mean, the The Dust attack was not that effective. The Twitter bot attack was not that effective. Anyway, maybe we will hire Chainalysis to figure out who are they. How the tables have turned. So you said Twitter group, but you meant Telegram group, right? When we had in the Telegram, we just had thousands of bots entering the Telegram group. Yes.
Starting point is 00:10:01 Um, yeah, I mean, these kinds of things are good, right? Because you, you wasabi needs to be able for it to be a useful tool. It needs to be able to withstand all, all sorts of types of attacks, right? It needs to work in an adversarial environment. Um, one of the things that's interesting is that I, me and you had a back and forth online about, uh, best practices for using wasabi and really if you want it to be as private as possible you should never combine any transactions after you go through the wasabi process after you go through the coin join process uh and you and you should really use wasabi as like a spending wallet right where it's where it's the rather than like an intermediary wallet where you're going from you know a kyc
Starting point is 00:10:56 exchange through wasabi and then to like cold storage or a hardware wallet and if you used it properly if you used it in that in that manner then the dusting would literally have zero effect right because you're not combining any transactions to begin with so this mostly targeted people who were combining after the coin joint yes this is another very interesting point that's a So one systemic risk that I experienced, one systemic, actually only one systemic privacy issue there is with Wasabi, what I, what we figured out, which is how people, how some people use the wallet. from their hardware wallet they send it to wasabi and then they send it back to their hardware wallet of course how their hardware wallet is doing they send all their addresses back to their backend server so so so that's not idea
Starting point is 00:11:54 and in this dust attack dust attack that's is my speculation that as as I seen half of the people who has the dust were sending it out with zero link outfits so I think what they do is that they click select all private and they send back to their hardware well it's so it's like half of the people use it with hardware well that's a that's my speculation that's that's so if this is true then it kind of shows that they did not really expose more things with the dusts than they otherwise would because what I see is that they were always spending zero link outputs with dusts so you could assume you could go
Starting point is 00:12:55 into the blockchain and check it but i i don't want to spend on a block explorer all my day so you could assume that the mixed outputs corresponding with the dusts uh they were spending it together in fact they were just spending all their private points into their their hardware wallets which is just a bad practice until wasabi doesn't integrate hardware what uh this is this is happening but if if this was the case then that dust attack did not have any effect uh on helping blockchain analysis but yeah someone should look at look at it more truthfully more deeply because i'm not quite sure at this point it's it's it's interesting yeah because it doesn't really tell them anything new like they would know that you've linked those
Starting point is 00:13:53 six utxos or whatever that went through the coin journey process are probably the same person combining right so even though it has that seventh seventh utxo in there that's the dust does it really actually tell them it sounds redundant right yeah i kind of i'm you know maybe my ego is getting like the best of me a little bit but i was getting a lot of shit for saying that people you know you you lose privacy if you combine but you know if the alternative is is to not do it uh you're probably better off going through wasabi anyway um and and i i when i saw this attack i was like someone's just trying to teach me a lesson you know that you're gonna have 50 of the people are combining and and now we have like kind of proof that 50 of the people are
Starting point is 00:14:38 combining after the fact um but uh it's i think it's definitely like oh it's a it's a wake-up call for people but my issue is is is privacy is such an issue with bitcoin to begin with um and i think one of the best things wasabi is doing besides making coin join very user-friendly is that it's really waking people up to how bad it really is right like none of these wallets have good coin control like when people are using ledger live or using treasures web wallet um they have they have zero control of which of which outputs are are which inputs are being selected and and they're super vulnerable to dust attacks to begin with right and all sorts of blockchain analytics so to me if the alternative is the person saying i don't want to end up with 100.1
Starting point is 00:15:32 new txos and possibly have a huge fee burden uh in the future so i'm not even going to use wasabi like is there a situation here where i've like been trying to work it through my head is there a situation here where using wasabi like hurts your privacy like there's i think it's always a net benefit regardless like even if you combine like if you combine afterwards it's it's definitely not as private as if you never combined but it's got to be a net benefit no yeah so so the one one issue that can happen is the blacklist blacklisting right because coin joint transactions can be seen from the blockchain so we just blacklist stuff those are coming from coin joints which is which is just another mythical thing because it's not happening or what's being
Starting point is 00:16:26 blacklist that is like from darknet market to exchange that the transaction if it goes through a mixer then they don't care about it anymore because they they kind of lost the track they could steal the anonymized but then they have to introduce more heuristics and more unreliability anyway so but they can start blacklisting right it's if no one prevents them and what if they start blacklisting mixing while then we we kind of failed building money i don't know go to work for monero or something like that it's uh it's it's really it would be a really terrible situation uh yeah well what i like to say is like i feel like if if if they start black you know if if
Starting point is 00:17:14 they if they say you can't send directly a coin join uh a utxo that was just coin join like directly to coinbase or something um then then users start you know doing like a ricochet situation where they do like four regular transactions after the coin join and then they send it and if at that point they're still blacklisting like anything that has a history of coin join in it like we're fucked like bitcoin is is like completely fucked at that point so i don't i don't think it's like a real concern for people to be like i don't want to hold coins that have a coin join history because if if that actually ever becomes a true concern then we have way bigger problems well also what if it just lights a fire under everybody's ass to just be like fuck you
Starting point is 00:18:02 i'm gonna send my bitcoin to a coin join and it gets to like a tipping point where it's like all right most of the coins are going join now what are you going to do about it just not let people transact on bitcoin yeah i mean that's one of the reasons right one of the reasons why i think it's important that we we get more people to use it um as quick as possible is to kind of like push the hand like make it so that um it becomes untenable to do anything so this is probably a good segue uh adam let's talk about like the growth of wasabi like how how how much liquidity you guys have on wasabi how much that's been growing and how much that's been helping the anonymity set over time a lot we are kind of tripling our user base every month and that's huge
Starting point is 00:18:56 huge growth in this beer market I am not sure what to expect we did not do any active marketing only like when we got a when someone asked us to go for a conference to speak or something like that then we went but we did not do any marketing so it's just as organic as as it can get so yeah i'm kind of scared i mean it's so much money so much money goes through it and i have to make sure everything is super stable and and ready for for wasabi wednesday is this your uh is this your sastoshi uh don't kick the hornet's nest call right now or i uh so so the the coordinator the coordinator fee address is a public address right um so we can it's it's relatively transparent how how the growth is going right because you
Starting point is 00:20:02 can basically extrapolate based on how much fees you guys have gotten yeah which i think is pretty cool no and that's like one thing i'm interested to see is like how because that's one thing we talk about like matt expounds upon in particular is that privacy loves company so i'm a suit like the increase in liquidity and amount of bitcoin being shuffled through wasabi is that allowing you to sort of uh up the um the maximum like coin join that you can do the maximum amount of bitcoin and you can sort of engage a CoinJoin with, right? So it speeds up the process. Yeah, exactly.
Starting point is 00:20:41 It speeds up the process. It makes it more private, and it just makes it way more useful of a tool, like the more people you have using it. The actual default anonymity set that Wasabi uses, you can change on a user level. um so you can up it and and lower it on user level it defaults at 51 um and then and then once but it defaults at 51 but you can basically just keep remixing to increase the
Starting point is 00:21:15 uh you can basically increase the anonymity set by remixing yeah but but obviously that's like more artificial you want more people to use it you want as many people to use as possible so so that you're you're hiding in a bigger crowd exactly um so adam how many how many bitcoin are on wasabi right now in total or have gone through that's what i'm trying to get is where are we on the website it says it says 17,000 Bitcoin but that's just a small part of it because these this only looks at the equal when join outputs right so how many bitcoins to it like you know hundreds of thousands and the interesting thing even with the change you know the change is not anonymized so
Starting point is 00:22:20 even with the change that's kind of anonymized because it cannot be the anonymized in a in a large scale because it just computationally so expensive to find all the all the combinations those are possibly in the change so if you look at only one input and one change output you then you can do it but if you're looking at all the coin joints it just takes a lot of computation so that's that's very interesting too so i have um so you guys have been iterating extremely well um just constant updates we've been seeing are there any big features on the horizon that you you might want to highlight whoo yeah at least we are releasing the daemon a mixing daemon so
Starting point is 00:23:20 what that means is that you can fire up your command line you can say wasabi mix wallet wallet name and it's going to mix for you without launching the GUI without launching the user interface. So that could come handy for some people. Other things, maybe it's worth mentioning the deterministic builds, which just means that people can reproduce the builds. So members of the community can verify that the binaries, those are built came from the same source code as it is on github so people of the community can verify that I am not not putting some virus or something into the the release binary so so that's that's that's an important thing to this
Starting point is 00:24:23 this just got released right now if you want uh something more interesting for the future that's there's a lot to do yeah i mean don't get me wrong i'm extremely excited regardless i those are both big big things and uh i just feel like every update it just it gets it gets more user friendly easier to use um one of the other things i wanted to bring up is what was what's the reasoning behind defaulting to the 51 default uh anonymity set um why not why not make that higher yes i so it was a long time ago i sent out emails to people like team roughing from coin shop uh ethan hayman who created tamba beat chris belcher adam gibson from join market and sent out emails that hey we have to do something we decide something on this
Starting point is 00:25:32 anonymity set so we what should we what should we consider uh acceptable because there is just no no research on it and and and decision has to be made and it looked like 50 seemed to be a rough consensus on it and yeah that's that's pretty much it uh why not increase it right now i think we should because actually remixing is very very more valuable than just mixing uh i don't know if you notice that but if you are looking at probability and not and not anonymity sets then it's going to be like if you mix once then the chances that your coin corresponds to your output is one per 50 right so two percent and if you mix again that same coin then it's exponential it becomes exponential in theory but in practice uh whatever but but this intuition can show us that remixing
Starting point is 00:26:45 is much more much better however i did not expect people remixing even once at the beginning so i i thought everyone's gonna just mix once and and be done with it but that's not what's happening and we learned a lot uh since since then so so the point is that if we elevate it to 100 then yeah that would be probably better but because that would incentivize remixing at least once but on the other hand it would be like people already have green shields right and then the green shields become not green, that might be annoying. That's that's a UX one on one, you cannot disrupt the users workflow like like eBay. The classical example is eBay, eBay
Starting point is 00:27:49 was yellow. They changed it to white, people were, oh my god, it cannot be white, yellow is so much better. So what did eBay have to do they wrote an algorithm that in one year changes the color just a little bit lighter just a little bit lighter and it eventually became white I never knew that that's hilarious I I do like that you can change your own default in the configuration file. I was thinking, you know, putting that in the GUI could be very useful to people so I don't have to, like, explain to them how to get to the configuration file. And also I was wondering, is there my first instinct is that to use your own custom
Starting point is 00:28:46 anonymity set does that that that has to help you you right because because it destroys another assumption right like if if if a bad actor is assuming that everyone's using 51 because that's the default then you know if you use even like 57 or something uh but then my other thought was Couldn't that make it even more trackable because you're the only guy using 57 anonymity set. Do you have any comment there? Is that we should put it in the UI Definitely just you know priorities In fact, we actually put in this release if you click file open config file That's that's how you will reach the config file, which is much better
Starting point is 00:29:37 but yes we should put it in the UI just just you know there are so many things to do and I don't think this is that important yet the other other thing is that the main problem with Bitcoin privacy is we don't have an adversary which so security for security metric to to mean something it should reflect the difficulty of an adversary overcoming this. But the issue is that right now blockchain analysis companies just don't care about mixing because 70% of all the darknet market users are just sending money directly to exchanges. So they just don't
Starting point is 00:30:23 care about mixes because they have such a low hanging, so much low hanging fluids that they don't even try to de-anonymize. So, yes, we have part-time choosing adversary, right? So we don't know if 50 or 100 and even the anonymity set metric is not that great because remixing is much more valuable, but that's not shown in the anonymity set metric because we should change to probability metric instead of anonymity set. And it gets really complicated really fast, especially without a real world adversary. So if you up it, it doesn't really matter if it's a unique or like a round number, right?
Starting point is 00:31:15 Like, so I'm saying like, is someone who uses like a 200 anonymity set significantly more protected than someone who uses like a 205 anonymity set that maybe he's the only one that's using 205 but a lot of people use 200 because it's a nice round number yes so I am using 1000 on my on my server and server on my normal Bitcoin well that's the time mixing through and I'm using 100 on the Bitcoin wallet that my spending Bitcoin well that's I mean better yeah yeah actually I don't have any idea, but those are what I've chosen for myself. You saying that out loud, I'm using a thousand anonymity set, that doesn't hurt your privacy
Starting point is 00:32:08 at all, right? Oh no, that just makes the mixers extremely unlikely. I mean, they wouldn't think that someone is doing 1,000 anonymity sets. So it's just not even a reasonable assumption to do that someone is doing 100 anonymity sets. Yeah. So, I mean, if I'm using much more than normal people, then I'm just being more private. Not like it would matter again because we don't have an adversary, but that was my thinking process. of the problems with blockchain right is even if we don't have an adversary now we could presumably have an adversary in five years that uses the same data that's that is being recorded now right
Starting point is 00:33:02 because this data lives forever um so we have to be basically we have to be prepared for like future adversaries uh that might pop up and and and screw us over for things we did five years ago which yes which actually brings us to back to the point that when you send to ledger and you you send from ledger and send back to ledger well chances are ledger is not is not spying on you so So it's like confidentiality is such an old metric, old way of doing security, so much older than privacy. So when you do that, then you have confidentiality and chances are they are not sharing your data with anyone.
Starting point is 00:34:00 but it's better not to even give a chance of course but confidentiality is not as bad actually the banking system works that way and and my my my neighbor cannot figure out how much money i have in the bank okay he might can because i don't have anything i only have bitcoin but anyway go on when when when people ask me uh like what one of my biggest like what some of my biggest fears are for uh bitcoin uh specifically with bitcoin privacy one of my biggest fears is if if ledger was compromised because not only do they have all that all that utxo data they're linking all you know they're linking all your public keys to to you if if they are doing that um they also have tons of our addresses because people got them shipped directly to us so they can link the pub
Starting point is 00:34:54 key to the address to the physical home address to the name to the credit card if you bought it with a credit card yeah to an extent it is happening right now with the bloom filtering spv bullets like your bread wallet uh they can tell you exactly how much money you have in your bread wallet uh because the bloom filter collecting stuff is just so powerful uh that it's it's scary but they don't have your credit card data so that's not that bad I feel like that's the problem with all this is that right now privacy with Bitcoin
Starting point is 00:35:39 is way more of an art form than it is a science if you fuck up one little thing you have to think of all these little things that you have to constantly be aware of and vigilant of I think that's a good segue into the next question. Adam is like, what do you think, if anything, Bitcoin can add at the protocol level to make your job easier, to make not even your job easier, just to make privacy easier and more innate on the Bitcoin blockchain?
Starting point is 00:36:05 Are you looking for something like Schnorr, Mast, and Taproot, or are you sort of content with Wasabi-like privacy features? so they could add confidential transactions and make everything that I worked on so far obsolete that would be really nice snore is is okay such no confidential transactions and we could decentralize the coin joins more with with volume shuffle coin shuffle stuff that's that's the big vision right okay one one part of that vision is coin shuffle plus plus coin shuffle plus plus still needs a central server like possibly is this
Starting point is 00:37:00 exact same properties as wasabi just more decentralized still needs a central server but decentralization is a scale so the central server only is only a a bulletin board, which means the peers are just sending message to the server, where and read other peers messages, which is more decentralized, which is, which is quite nice. So this is one way making wasabi more decentralized. And other thing is the these amounts of we are always talking about, like, like you have to have equal outputs and equal this equal that anonymity set whatever this confidential
Starting point is 00:37:46 transactions would solve everything uh if it gets into bitcoin which is a huge if but i don't want to get into that uh for a moment confidential transactions blinds the amount so no one can see the amount and that's the it's the that's the huge cheat there uh in terms of designing privacy technologies and value shuffle which is built on coin shuffle plus plus is coin shuffle plus plus using confidential transactions now how can we make this as economical as normal people as normal transactions we introduce bullet proofs which makes confidential transactions smaller and linearly aggregatable which just means if we have like 100 people then the proof then the proof of the output it's not gonna matter anymore
Starting point is 00:38:52 because just people share the cost and the same with Schnorr Schnorr if you have a coin join and you aggregate your signatures it's not signatures then the input signatures become smaller then you're gonna get the signature so in a big coin join 100 people participates only uses one signature so people pay off their size on the Bitcoin network so that's gonna be great because now we are at the point that because of confidential transactions and bullet groups and snore uh bitcoin join would be even uh would cost even less than a normal bitcoin transaction which is just great of course we need confidential transactions for that which is just
Starting point is 00:39:45 there are a lot of issues with with that so i'm not very bullish at this point of time but who knows no one ever tried to to to define soft focusing into bitcoin with confidential transactions so so you you never know maybe we need some better crypto yeah no and if the last decade has taught us anything is that uh bitcoiners are very creative in ways in which they can figure out to implement these types of changes and like you said that's something that we touch on here rabbit hole whole recap in particular is if it gets to a point where like snore is implemented uh and bulletproofs are implemented and it just becomes a better you're more better incentivized to to join in a coin join transaction than a regular transaction like that is possibly the best way
Starting point is 00:40:38 to get get a private bitcoin is just make the incentive so it's it's inherently private yeah if it's cheaper more people use it and more people use it then then we have more privacy yeah okay so so we had a nice solid 40 minutes on uh wasabi uh shall we shall we move into like uh like a 20 minute quick round yeah let's do a quick round adam you're gonna uh we're gonna drag you into uh some topical stuff uh let's start out this week sponsor unchained cap unchained capital excuse me uh launched their vault service which which is bringing multi-sig solutions to the market, more multi-sig solutions, I would say.
Starting point is 00:41:22 This is a pretty big announcement. Like we said in the beginning of the episode, you can engage with these multi-sig sort of schemes with Ledger or Treasure. Unchained will hold the third key in your two or three multi-sig. You will have complete control of your coins at all time, and you can sort of tap Unchained if you need them to help you sign a message or something like that but 100 cold storage sovereign multi-sig solution
Starting point is 00:41:51 so my issue with the unchained cap multi-sig is that it requires a kyc check uh they take your info and stuff and um the unchained team is fantastic like they say they're they're not going to share this information and i completely believe that they have zero intention of doing it but uh it is a it is could be a major privacy leak there um and it doesn't seem like it has any regulatory requirement to do that because they don't actually have custody yes they don't have custody so that's where i talked to drew and uh parker about this they said that point in particular like they don't believe that any authorities could come and subpoena information from them but so then why aren't they why are they doing the kyc in the
Starting point is 00:42:36 first place and my guess that they're doing the kyc is because they they want you to already be through the kyc so that you can go right easily into their loan product uh okay yeah i can't speak to that um but that sounds structurally right to me so i would say that uh and i think adam would agree with me that is if you were going to use this product like you should probably go through wasabi first i'm not sure i mean people people should not use wasabi just because it's cool they should use when they realize that they actually need to reclaim their privacy right otherwise it's just annoyance but when they they realize that it's oh if i don't use it it's a problem then that's when they should but you don't think that if someone's using this multi-sig
Starting point is 00:43:31 if they're storing if they're storing coins with unchained capital and unchained capital has kyc like if they go in there without if if they go in there without going through wasabi first then they're just linking all their past transactions and potentially all their their i mean the future transactions i guess don't really matter but they're they're linking all their past transactions and like basically letting know uh the kyc service that they used you know this is where i'm storing my coins you are right um i am not sold by them i i don't see why i would use i don't see any situation where i would use their their things based on the information i i know but uh there might be some some people who needs that i i i really don't know
Starting point is 00:44:22 yeah no i think this uh product in particular is probably best for like businesses and people that are running businesses together that want to set up joint accounts uh with a third party to help in a multi-sig facilitation i think this makes sense for them and there will be products and companies that use bitcoin that are they're comfortable with this i would i would argue and then people maybe family offices or trusts that that want the uh security of a third party helping them in this custody solution it's a user-friendly play and also the i think there's actually like a subset of clients that prefer that they do the kyc so they know who owns the account yes yeah exactly and that's that's the thing it's like the thing we talked about block
Starting point is 00:45:15 last week it depends if it if it's in your risk appetite or not and this risk appetite being your your risk for exposing your privacy uh and to who so if you are trying to hide all your utxos and do not want people to know which utxos you own probably not the best product for you but if you're uh in a business engagement and you need a multi-sig setup with your business partner and you guys are okay with sharing your income and revenue streams and being KYC'd on that platform, it seems like a perfect setup for that type of environment. Yeah, so should we – let's jump into – we're running short on time here.
Starting point is 00:45:57 Let's jump into the treasure vulnerabilities, I think. Oh, I want to talk about porn. Porn and KYC in the UK? Yeah. So the Brits are implementing KYC for porn. you have to register your passport or register your government id with them to view it yeah to view porn the uh the british government is making a list of porn watchers so any of you any of our british freaks out there uh the government's gonna know what you're fapping to going forward
Starting point is 00:46:28 so good luck to you i just think this is like a perfect example of internet privacy uh violations and that they they start with these type of things that can get uh more widespread support and then they start expanding their speech block you know like maybe you can't access wasabi's website or something they're gonna go they're gonna go right for 4chan after porn i bet you um do you have any opinion on this adam i i think that i think the benefit is that there's going to be a whole group of young brits that are going to learn what vpns are and how to use them yeah even with that being said don't watch too much porn freaks it's bad for you it's bad for your mind but if you're going to watch
Starting point is 00:47:16 porn like use a vpn like even if your country doesn't like kyc you like you could always get blackmailed for your porn habits at a later date this is true so you should at least you should at least use a vpn learn about it yeah yeah i would recommend it at least um good luck to you our british brethren looking to fap out there um do not register do not register for the porn kyc just use a vpn um okay so let's move to the treasure vulnerabilities um yeah this was a hot topic in the bent this week wrote about it two days in a row uh charles gilmette from ledger he's their head security officer i believed went to the uh mit bitcoin expo over the weekend and displayed a number of attacks that the ledger security team was able to successfully
Starting point is 00:48:03 engage with uh using trezor hardware devices i watched the presentation live and then uh uh watched watched it a couple times after as well to me it seems like a lot of these vulnerabilities were disclosed by the wallet.fail team um earlier or excuse me late last year uh so this wasn't news to me it seems like all the uh attacks uh either need to be supply chain which every hardware wallet is vulnerable to or physical attacks where the attacker has physical access to your trezor for an extended period of time which is an assumption i've been i've been working under the whole time i've owned a trezor is if somebody ever gets access to this they can probably hack into it like eventually with enough time enough skill set yeah motivation i mean the
Starting point is 00:48:49 thing is like compared to a seed if they get the seed on a piece of paper then they automatically have access to it if they get the trezor like at least they have to be like more sophisticated um as far as the ledger ledger is less susceptible to supply chain attacks because they have that proprietary secure chip um that that is authenticated when you connect it to the software um but that has its own set of risks because it's not it's not a little risk right or something it's not open source so you don't even know what's going on with the chip you're like you're like trusting them to a degree um so they both have their own trade-offs and of course ledger is gonna attack trezor for not having that chip right that's their bread and butter um adam do
Starting point is 00:49:32 you have a preference over when you if you recommend a hardware wallet to a i guess like a normal user do you do you recommend a ledger versus a trezor or trezor versus a ledger so first of all i'm traveling so i'm always under the assumption that all of my possession is going to be stolen from me and they are from time to time so i never used the hardware wallet actually before um but now i wasn't even paying attention but now i i realized that uh that hardware wallet companies are so hostile to each other i was right oh my god i i i can't believe they they don't it's like shitting in the baby pool and ruining it for everybody they're just yeah it's like that's what i was talking about in a side channel this week it's like
Starting point is 00:50:26 All these hardware wallets attacking each other is just having people lose confidence in hardware wallets overall, right? Yeah, and it's procrastination, right? Because hardware wallets can be, all hardware wallets can be hacked if you have physical access to it. But that's very rarely the case. and by the time you hack them, he's going to just move the coins because he noticed that his hardware wallet is missing. Yeah, and that's what... Oh, sorry for interrupting, but Trezor came out with their official response
Starting point is 00:51:03 and that's what they said. Like 5% of Trezor users are afraid of physical attacks. Like more people are worried about getting attacked via their computer or something like that. There's been no known attacks. We've never had... I don't think we've had any known... I mean, there's been $5 wrench attacks.
Starting point is 00:51:18 Right. But I don't think we've ever had any known compromises. Yeah. And then the other thing is like, if you use a passphrase, you're a lot more secure because even if they pull your seed. And then if you use multisig with both the hardware wallets, then they both have to be compromised. Exactly. At the same time. Right. So what would be a real issue if they would be able to figure out how to hack it remotely, which is unlikely.
Starting point is 00:51:46 that's the scariest when i would when i would say okay i wouldn't recommend this hardware wallet to to anyone but on until that happens i i just don't mind but i i do agree with the logic about the the traveling like when you travel you should never yeah don't put it in put it in nature's pocket or just don't travel no just assume yeah just assume that when you travel like every single piece of that you have with you can just be fucking violated and searched and taken from you oh yes that's the other thing yeah especially if you come to america that's one of the reasons we we agreed to the remote with you because i completely understand your uh you're never coming you're not coming to america for a long time so we really had no alternative
Starting point is 00:52:34 of um next up this is an interesting one so uh there was a precipitous decline in the amount of transactions on the bitcoin network since the last time we met here on rabbit hole recap some people were trying to attribute that to uh the rolling blackouts in venezuela and uh it would have been a cool story if uh if it was true if it was true but it's probably not true it turns out vera block that uh project that is uh basically securing other blockchains by hashing data into the bitcoin blockchain they ended their test net i believe march 8th or something like that um and that was probably the main cause of the transaction downturn but uh it's an interesting case study in i don't want to say ethical block space use or efficient block
Starting point is 00:53:23 space use but it looks like uh vera block they're going to turn back their they're going to turn their main net on i believe friday in a couple days here so maybe we'll see transactions uh begin to increase again but it does beg the question like is vera block like the new satoshi's dice uh are they taking up too much space is it a worthwhile use case of the bitcoin blockchain this is why this is why the the the weight limit exists this is why there's fee pressure you know if they if they do it then they're just going to end up costing themselves a ton of money and uh they'll price themselves out it'll eventually become either it'll become unviable for them yeah otherwise if they had unlimited block size they could just block weight they
Starting point is 00:54:07 could just do whatever the hell they wanted yeah it's it's surprising they're not using bsv it's not secure you don't see you don't secure other chains with an insecure chain so what are you talking about man satoshi's vision don't even get me started um what else do we have here uh oh the texas proposed bill this is a good one for adam did you see this bill adam in texas i heard about it but you could refresh my memory they basically they said that if in that the only currency it's a proposed bill they haven't actually passed it or anything, but
Starting point is 00:54:50 basically for a digital currency to be legal, you have to know who the sender is when they send it to you. Yeah, Texas is trying to dox all their users. I'm not even sure
Starting point is 00:55:06 how to react to that. I think laughing is the appropriate reaction. It's we are living in our own bubbles and they are living in their own bubbles and right bubble is going to pop first how does our bubble win that's it i mean that's the uh that's been part of like the overarching conversation of this podcast like the last three months is or last three episodes in particular is like the governments are just
Starting point is 00:55:38 like historically too slow to move against this stuff adam maybe this is like a good ending topic like do you you're on the front lines of building sort of technologies that overtly conflict with what these governments are trying to achieve so do you think governments do have the ability to move quick enough to stop the stuff that you're working on look look at it think about this question bitcoin is legal this is crazy can this be legal i mean this is going to destroy the largest power that governments have printing money this is this is this can't be legal this doesn't make sense right so based on this logic we might even have a future where privacy is by default
Starting point is 00:56:33 But, you know, it's not that crazy idea. No, I don't think it's that crazy. It still amazes me. It still amazes me that... Let's put our tinfoil hats on right now. What if the government wants us to adopt Bitcoin? That's why they're being so easy on us. Well, that's best case scenario.
Starting point is 00:56:49 Like if the government is Satoshi, then... Is it though? Then we've already won. You know, the future is bright. we just have a lot of work to do that's right and that's why i'm ecstatic that we're able to get you on this week adam you're you're an individual in my mind that's doing an immense amount of work to to number one to show people that this vision's viable and this mission's worthwhile and then number two you're actually producing uh good products that people are using
Starting point is 00:57:25 and helping out the community at large so i just want to thank you for for joining us for this hour and all the work that you've done at Wasabi. Yeah, thank you, guys. Yeah, we have an insane amount of respect for you and everything that you and your team have done. I've been waiting for a user-friendly privacy wallet since the dark wallet days of 2013, 2014, where Amir and Cody were telling us
Starting point is 00:57:56 all these great things were going to happen with dark wallet, and it's just never really materialized so it's um i i think that even if we don't you know there's a there's a lot of improvements to to be desired uh on a protocol level but even if we even if we don't hit those we have like a like this base minimum privacy tool we can use is an absolutely huge, huge step forward. Yeah, I wouldn't say it's base minimum. I would say we cover privacy well. There is really nothing to do about privacy anymore.
Starting point is 00:58:36 That wouldn't be procrastination. It's just we have to make it more convenient, easier to use, and faster and cheaper, and that's all. This is what it all comes down to. it's like privacy privacy is not an issue anymore privacy is solved you just have to make it not bloat the blockchain and maybe a bit more decentralized things like that so yeah that's my thinking i mean my my two issues i think that are like the is like the well one is like a low hanging fruit um you know which is it makes sense that's not a priority but uh but people have been
Starting point is 00:59:19 talking about like hardware wallet integration like obviously obviously you can't um do do live mixing with with hardware wallet because you need to be able to sign the transactions it needs to be a hot wallet but if if we we need better ways of interacting with our hardware wallets easily and um wasabi seems like a natural fit because it's got such good coin control it's got tor built in it can use your your bitcoin full node uh like out of the box um so that that that'll be i think would be a a pretty big a huge improvement and then the other the the main issue i have with a at least in a pre-snore world uh with a coin join implementation is that if fees do go up it could become it could become quite quite the issue which is one of the reasons why
Starting point is 01:00:09 I think it's important that people use it now while fees are cheap, yeah. Hurry up before Veriblock tears on their mind then. Yes, one small thing I want to say that it is possible to do hardware wallet Bitcoin join. Now it is clear for me that it is possible. It just work has to be done on the hardware wallet sign for auto signing and basically the same script ability
Starting point is 01:00:38 needed that's needed for lightning network uh anyway i just wanted to mention this so what would you you would like pre-sign for like a certain amount of days or something like a certain number of transactions you would pre-sign something to that effect the most basic idea is that you tell the hardware wallet that sign every transaction until ten dollar leaves the wallet and after that don't sign any transaction right so it's going to mix and the attacker can only get 10 out of it so yeah that's possible that's awesome i'll agree your heads up i think that's a perfect place to end it this week we're at an hour adam again thank you for joining us and all the work you've done um i don't know if you have a parting note or a parting message for the freaks out there but
Starting point is 01:01:31 this is your time yeah thanks thanks a lot guys my message would be that use hardware wallets based on color color right it really doesn't matter if the hardware wallet is well-known then don't don't don't be afraid of scaremongering color is the most important thing if you like pink then it should be pink i like that uh bedazzle your hardware wallet freaks that's the uh that's the parting note and uh we we've we've shilled wasabi a ton of times on the pod but it's wasabi wallet.io um it's available on on linux on mac on windows very easy to to install and use and and you should at least check it out with some some small amounts of bitcoin and play around
Starting point is 01:02:25 with it and get you get your feet wet get your feet wet freaks and thank you again adam and uh that's it for this week yeah peace and love freaks cheers bye

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.