TFTC: A Bitcoin Podcast - Tales from the Crypt #127: Andrew Chow

Episode Date: January 13, 2020

Join Marty and Matt as they sit down with Andrew Chow, Bitcoin Core Contributor and Engineer at Blockstream, to discuss: - How Andrew found bitcoin in high school - What life was like before the Parti...ally Signed Bitcoin Transactions (PSBT) standard - Why PSBT is important - Working on Bitcoin Core's Hardware Wallet Interface - CoinJoins - Coin selection - Hardware wallets - Video games - much more Follow Andrew on Twitter Follow Andrew on GitHub Shoutout to our sponsor: Cash App. Head over to the App Store or Google Play Store, download cash.app and start #stackingsats today. Use the promo code: "stackingsats" to receive $10 and contribute $10 to OWLS Lacrosse you download the app. Subscribe to our YouTube channel: tftc.tv Contribute to the show: https://tftc.io/contribute/

Transcript
Discussion (0)
Starting point is 00:00:00 well hey there freaks it's your boy marty bent here to introduce this week's episode i was joined by matt this week had the immense pleasure of sitting down with bitcoin core contributor andrew chow we talked a lot about partially signed bitcoin transactions coin joining coin selection video games a bunch of other stuff andrew is an incredibly talented and young mind young guns crushing it these days this was an incredible episode went for a while, I think we almost went two hours on this one
Starting point is 00:00:34 so I highly recommend you stick through it, we cover a lot, towards the end we talk about coin selection and dust it's a fascinating problem fascinating I wouldn't say problem maybe it's a problem in some people's
Starting point is 00:00:50 minds, what's the word I'm looking for here fascinating variable, we all have to to take into consideration so i i think you guys are going to like this one um again andrew's incredibly bright and doing some incredible things for you freaks that don't know he is the creator uh creator inventor i don't know he created the uh psbt standard which a lot of the wallets are now using to to build their um partially signed bitcoin transaction software so that they communicate between each other um we go through why this is important and how um it's been
Starting point is 00:01:27 accomplished up to this point and what what may be um uh enabled by this moving forward this episode of tales from the crypt is brought to you by the cash app you freaks already know all about them cash app is the simplest way to send and save money you already know they're letting you stack slivers of stonks now if you want to we're changing it from shares to stonks it's just too easy to say. The shares, it's too much to think. Stocks is just right on top of my mind, all right? Cash app investing is here. Unlike investing tools that only let you buy entire shares of stocks, cash app lets you instantly invest as little or as much as you want. This way, when your favorite company's stock is just a little too expensive, you can still own a piece
Starting point is 00:02:05 with as little as $1, okay? You can buy slivers of stocks now. You don't have to. The option is there i'm not saying go buy stocks on the cash app if you so please the option is there you can still stack sats send sats receive sats stack more sats on the app incredible bitcoin buying experience is still there as well um and because your cash app is directly connected to your bank account you don't have to wait four to five days sorry excuse me you don't have to wait i want porky to pig there on you guys you don't have to wait four to five days um for inbound transfers You can start investing today. Brokerage services are provided by Cash App Investing,
Starting point is 00:02:43 a subsidiary of Square, a member of SIPC. And as always, as always, use the code STACKINGSATS when you sign up. That's one word, S-T-A-C-K-I-N-G-S-A-T-S. You're going to get $10, and Cash App is going to send $10, a thousand pennies, to our good friends at Owl's Lacrosse. Yes. Download the Cash app from the App Store or Google Play Store today and enjoy this episode with Andrew Chow.
Starting point is 00:03:13 I know I certainly did. Okay. What is up, freaks? Welcome back to Tales from the Crypt. It's your boy Marty Bent here, fresh off a recording of rabbit hole recap we cut that one short because we have a very special guest i say we matt odell is with me matt what's up cheers guys we are sitting down with andrew chow engineer at blockstream and somebody i'm uh very excited to sit down and talk about talk
Starting point is 00:03:45 about talk with about partially signed bitcoin transactions a big topic on the podcast uh in the last couple of weeks but before we get into psbts andrew why don't you just give us a little intro to yourself how you got into bitcoin and what drew you to psbt in particular yeah so i'm andrew uh i work on bitcoin core and i'm engineer at blockstream uh i've been working on this since i was in high school like five years ago where that's where a couple friends of mine in high school introduced me to bitcoin uh because they knew i was interested in technology and stuff so you know i looked at it uh didn't have money to buy that much bitcoin and the technology was far more interesting so what is that 2014 what was the state of bitcoin like at that point i see
Starting point is 00:04:38 you're a moderator on bitcoin stack exchange and bitcointalk.org is that where you're getting information at that yeah so at that time uh i was really active on bitcoin talk uh i was i didn't get onto bitcoin stack exchange until fairly recently but on bitcoin talk um this is actually how i got into development i was hanging around in the development section and the tech support section and occasionally you get someone that comes in with like some weird issue that looks like it could be a bug and you know bitcoin's open source and i don't want to ask other people for help uh so i go digging through the source kind of like oh oh that's a bug and it looks like i can fix it so then that's how i got my first couple uh pull requests open just like people
Starting point is 00:05:23 report users do dumb things and they tell people about the issues they have and you can find bugs that way do you remember the first couple particular issues that you don't know i'm sure you can find you can definitely find them just looking through my contributions on github they're they're somewhere yeah deep in there a lot of a lot of contributions yeah that well before we get the psbt uh what's it like approaching bitcoin core and like making your first pull request were you nervous um um so i'd been on the irc channel for just listening and watching how things go uh i started like watching the meeting the irc meetings and generally asking a few questions talking to developers so by the time i got around to making a pull request uh it felt like it didn't
Starting point is 00:06:14 feel like a completely new thing to me although contributing was still new i think i had made a few issues just some other bugs i ran into also um but yeah it's the first time you do it is very daunting because like oh you're you're talking to peter walla and greg maxwell and these are important people and it's very scary well it seems like you've garnered their respect pretty quickly um so let's jump right into the way i found you was a presentation that you gave at the san francisco bit devs meetup i believe in the beginning of the summer that was in may so the actual presentation was in it was released in 2017 i think or 2018 something like that i think it was 2018 and uh there was an issue with the recording or something that it got delayed
Starting point is 00:07:09 for a while um before it got released yes so i i found it when it was eventually released i believe in may um but at the time he gave the presentation whether it was 2017 2018 uh it seemed like a a nebulous idea that had not been implemented yet and since the standard has been uh implemented and adopted by uh many hardware and software producers and um it seems that it's getting quick adoption so i guess the good best place to start is what was the problem before you could partially sign a bitcoin transaction before ppsbt um but now there's a standard that makes it easier correct so uh this actually started in 2017 that's when i wrote the first drafts of the standard um so in 2017 i was uh still in college and i had i was interning at blockstream over the summer
Starting point is 00:08:02 and while i was at blockstream um i got a hardware wallet and naturally being a core contributor working at a company that does a lot of things with core i wanted to use my hardware wallet with core but i couldn't uh so you know i did this normal like stop gap measure of run your own electrum server and use electrum but that's annoying and who's going to do that if they want Only hardcore people like me are going to run ElectrumX. It's a pain in the ass. Yes. Even for hardcore people.
Starting point is 00:08:35 It's annoying. It takes a lot of disk space. And Electrum doesn't always do the best job of making sure information doesn't leak to the other servers. So when I was interning at Blockstream, I was just talking to Peter one day about how we could get hardware wallets into Bitcoin Core. and he pointed me to a few issues and we were talking and we eventually landed on well not eventually pretty quickly uh came up with basically we needed some software that does all the talking to the harbor wallet and some way to call out to and talk to that software well that software is what is now called hwi it's a project i've been working on a lot recently and the way to talk to
Starting point is 00:09:26 it is psbt so we just wanted one simple thing that contained all the transaction information that we could dump on a command line and send it to send to hwi or something else yeah so before hwi and psbt basically that babble between the different yeah software and hardware projects correct yeah so one of the main issues i had run into when i was uh working with core and the Electrum wallet was that Core and Electrum use like they have a they had a partially signed transaction format that wasn't well specified and was like half compatible with each other if you took the straight hex out of Core and gave it to Electrum it would reject it if you took it from Electrum you gave it to Core it would also reject it if you like spliced a few things in
Starting point is 00:10:21 and added a couple bytes here and there and removed some bytes here and there. You could get it to work. It's just annoying. This really became a problem actually when Bcash forked off. Why is that? Because I needed to move my coins.
Starting point is 00:10:40 And there's no way I'm running their software. So I had to modify Electrum's format to work with a bitcoin abc node so i could broadcast it and like track get the inputs and stuff yeah and why are partially signed transactions important or useful in the first place so well they contain all of the information you need to complete the transaction uh there's fields for the signature, for any scripts that you need, and fields for the UTXOs and the keys and their derivation paths. So since PSPT was initially designed with hardware wallets in mind, one of the things
Starting point is 00:11:28 that you need to do for a hardware wallet is to tell it the derivation path for the key to sign with. And so PSPT has a field for that. And since hardware wallets aren't connected to the blockchain, you also need to give it the UTXO so it knows how to sign because the UTXO is included in the, uh, signed data. And then a meat space.
Starting point is 00:11:48 Why would somebody want to conduct? And then, yeah. So construct a transaction in this fashion. Uh, PSPT, the, the other benefit is that it's one thing,
Starting point is 00:11:58 one string that you can copy and paste around. So, uh, you can move it to another, uh, you can create one on one software and then copy it to another one. And it should still work. if they both support it one of the issues that core had was it its transaction format didn't
Starting point is 00:12:16 contain all the necessary information that you needed to sign it you had to like pass in you have to pass in a json array of json objects which requires special escaping if you're using like bash it's just generally annoying to use uh and it was separate things and you have to know what you're doing so psbt puts it all together in one thing that for the normal user you don't really need to know what's inside of it it just has everything yeah it's got a standard that works so it's also it's also a well-defined standard why do you say that uh because none of the other transaction formats were well-defined or standards so what do you mean by well-defined like if you read the bit it tells you like exactly what where the bytes go and what you're supposed to put in
Starting point is 00:13:06 the psbt um i had to electrum had a similar ish thing where they were using keys uh electrum did everything based on keys which doesn't generalize well to scripts uh but that one i had a hard time figuring out how it worked and i had to like reverse engineer the source code to to figure that out uh but psbt you don't really have to do that it's specified in the bip um and if it isn't that's a bug and i'll fix it and before uh before this well-defined standard existed was the non-existence of this standard holding people back from building stuff like now that there is a standard what does this enable um well it enables our original goal of getting hardware walls to work with core that's that's at least one thing it does i'm not sure about i guess people have
Starting point is 00:14:01 been using it for other stuff um but those kind of like other things that you could use pspt with weren't necessarily on my radar when i designed it or some examples of that uh well a lot of people want to use it for multisig now which makes a lot of sense with multisig yeah i guess it does uh that was something I had thought of briefly, uh, before I went back to working on it for hardware wallets first. Um, I guess,
Starting point is 00:14:29 yeah, multi-sig is something that's mentioned in the bit. Yeah. That's something you can do. Cause, uh, shores provost just came out with the end key, right?
Starting point is 00:14:37 And that's, yeah, that uses PSP for multi-sig specifically. Correct. Yeah. Um, although now that people are using it for multi-sig or investigating using it for multi-sig,
Starting point is 00:14:49 there have been a few issues that came up like uh there's some privacy issues like you'll leak your derivation path if you care might be might be some important information might might not be it's not particularly private but uh you try you want to try to expose as little information as possible to your co-signers so you leak your derivation path if you don't drain the wallet when you move a UTXO and then somebody could use that to attack whatever's left? Well, with your derivation path,
Starting point is 00:15:26 you can, for one key, you get the derivation path where you can infer what the derivation paths of the other keys in your wallet are. After R, yeah. Right? We have a,
Starting point is 00:15:40 there's a way you can mask it, like just give half the derivation path, but that requires some the wallet software to be able to handle that yeah at least your wallet software yeah basically you're leaking the derivation path to anyone who sees the PSPT whether that's a cosigner if someone intercepts the PSPT or something yeah basically there is the this shouldn't happen risk of someone stealing your master private key by doing the whole unhardened thing with the child private key with the so you
Starting point is 00:16:21 can take the child private key with a parent public key and then recover the parent private key if you use unhardened bit 32 derivation that's a thing that can happen so you use an HD wallet you get a pub key then you make a private key from that yeah you make it you derive a child key if you for some reason give the child key to someone else which you really shouldn't do and they also get that parent x pub they can now derive the parent private key and now derive the rest of your child keys which is a problem but that's only for unhardened derivation the private key is the biggest problem right yeah yeah so uh and psbt you can include an x pub in it and the derivation
Starting point is 00:17:09 paths so if you had given one of your co-signers a private key for some reason and then you give them xpub for them to sign or you give them a psbd for them to sign they now get the xpub and they can check the derivation path to see if it's unhardened and now they can try to reverse out that that uh parent private key and that xpub by itself is the xpub by itself is perfectly safe except for privacy yeah except for privacy it could be a privacy it's just fascinating the uh the externalities you have to take into consideration when building this stuff like how how do you approach this with the security first mindset what uh what are you thinking first yeah so the the main thing though is uh this requires someone to give someone else
Starting point is 00:17:54 a private key which is something that you know everyone just says don't don't give people your private keys like why are your private keys going to someone else anyways so it's mostly uh i consider it to mostly be a non-issue uh but if someone has a use case for giving their private keys to someone they they should they need to consider it be aware be aware um so what uh what's i know you said there's use cases popping up that uh you didn't expect but what's what surprised you the most and what do you expect to happen moving forward like is it now that it's a standard are you are you moving on and working on something else or is the standard to be cleaned up and iterated on moving forward um the standard is still growing still changing i mean like the
Starting point is 00:18:45 base format is basically locked in because multiple software are using it now but uh people have been coming up with other fields to add other things that you want to consider so like the xpub thing was recently added because people wanted to be able to do change detection, which I had completely forgotten about when I wrote PSPT. But for a hardware wallet, they want to hide the change output because that confuses people. So they need some way to detect change. And that was specifically for multi-sigs, so they can use the XPUB to derive the change address and then check if any of the outputs use that um yeah the main use case i've seen so far has been a multi-sig i think there's been a proposal for
Starting point is 00:19:37 like some some commitment something there's a there's a pr for that somewhere and do uh any i haven't really thought about it i don't want to say looming but do any of the potential uh changes to bitcoin core in the future like it's snore signatures or taproot effect psbt in any way they all get new fields okay i guess i will need to rename the signature field to partial ecdsa signature because uh i told um i guess it's peter uh who's been working on taproot i told him that well we discussed it too that taproot should just get its own set of fields because it doesn't make sense to try to shoehorn them into the existing ones i mean we've got so many bytes available so it doesn't really matter if we just add a few few more fields for attack root okay and it's then
Starting point is 00:20:32 it's completely unambiguous as to what what everything is and there's no like guessing like is this signature a snore signature or an ecdsa signature yeah it's fascinating right because satoshi really didn't create these standards in the beginning and yeah you have all these uh uh disparate software projects building on top of bitcoin just building tools for themselves and uh it's one of the biggest worries that you create too much tech debt that it's hard to go back and you think this is catching this at this particular juncture of bitcoin's life cycle is important catching like creating a standard around this uh is imperative moving forward yeah i think could it have gotten to a point where we were too far gone it was
Starting point is 00:21:12 there's too much babble well i think that's unlikely or well i mean we're kind of already there to start with but like we're pulling it back in yeah it's like like we were already at a point where when i when i started working on psbt we had three different formats i knew of there was core electrum and armory actually had its own thing too because armory is specifically designed for the air gap model so they wrote their own standard and we had these three things but uh and then every hardware wallet manufacturer had their own thing in their apis it was already pretty confusing uh but having psbt is kind of bringing it all like everyone's shifting to using that so i don't think the timing really mattered uh it just happened to be convenient you had to
Starting point is 00:22:09 find out that we needed it right or something yeah it's like such a big improvement that it's just like at any point it would have been helpful yeah and it's exactly and it's also one of those things like well why didn't someone bother to do this before it does turn out that someone did uh it's one of the very first bips bip 10 is specifies a format that is similar to psbt uh but it was withdrawn why was i don't know you know you can you can look it up it's uh it was written by the armory uh developer in 2012 i think so pretty early um and it doesn't quite do everything it's not as extendable as psbt but i think i find it's interesting that someone had the idea before but no one wanted to use it yeah timing maybe it was
Starting point is 00:23:00 I just had to wait for a Bitcoin to mature to the point that there were it there were competing well not standards but like multiple wallets and there was demand to each other yeah yeah and that and that's a crazy thing about Bitcoin core too because you have like a Russ Yanofsky commonly misunderstood as Ryan of sky but he's doing like some meticulous work to separate the node and the wallet GUI which is like a huge tech that that once that endeavor is is finished it seems like it gives you guys a core contributors a lot of open space to sort of work on more interesting stuff and I've been the other part the other stuff I'm working on for core is the descriptor wallets which is which is a prerequisite for having hardware wallet integration into core
Starting point is 00:23:57 and a big part of this has been to take all of the things in the wallet that are uh we basically call it script pub key management and put it into encapsulate that into its own object where if we want to change out what the script pub keys are and what's signing we just swap out that object so right now we have everything that currently exists we just call it legacy script pub key manager and it's copied all the wallet code into that for now but in uh an upcoming change is to introduce a descriptor script pub key manager which uses the output descriptors that peter designed uh that specify all the the script puppies that we're using in that wallet and then shores provost has the um has another change which introduces
Starting point is 00:24:56 the hardware wallet script pub key manager and that will deal with the hardware wallets out of shit so yeah this uh this change i'm making to encapsulate all the wallet stuff allows us to even further expand the wallet to do more and more things and more arbitrary things too yeah i saw you were talking about coin selection recently yeah coin selections is a completely different can of worms that no one wants to touch uh i don't know apparently i'm the expert on coin selection now because i'm the last person who really modified it it seems like this helpful but it's not it's not really related to um it seems like that would help now no not really oh it's uh because it doesn't deal with keys okay or script pub keys that makes sense right yeah so uh with our script
Starting point is 00:25:46 pub key manager thing the idea is that we have we have the script pub key manager that tells the wallet to watch for these script pub keys and the wallet will handle all the transactions and watching for those script pub keys and then when we want to sign a transaction it gets passed to the script pub key manager which does all the signing and whatever stuff behind the scenes to spit out a working transaction so that could be so like right now we we just have our bag of keys thing but later that'll be a hardware wallet it'll it'll be it'll just pass off that transaction to a hardware wallet and bitcoin core's wallet doesn't really need to know about that it's kind of a black box that's pretty awesome yeah so this lets us expand to do a whole lot more things
Starting point is 00:26:36 like we'll get the harbor wallet once we get descriptors uh and miniscript the wallet will now be able to do arbitrary scripts and you know whatever whatever we want it'll make multi-sigging core wallet so much easier because right now it's kind of a pain well this is is this a testament to the conservative nature of bitcoin core and working on these hard projects over a long period of time instead of trying to throw them all in at once and um i'm not sure i would call it conservative i think it's mostly developer laziness what do you mean by that well i dropped a ginormous pr to do the change and no one wanted to review it that's so uh is that is it that nobody wanted to review it or there weren't enough people to review it it looks scary and like
Starting point is 00:27:29 you have a billion other prs to review this one would take you at least like multiple weeks of dedicated time just to work through the commits in general and uh you know a large pr like that no one wants to review it you have to break it down into smaller chunks for people to smaller easily digestible pieces for people to go to go through and that takes a lot more time a lot more prs a lot more comments now and just slowly well takes time i think this is a perfect candidate for john newberry's pr review club maybe the month of february we can get on this john i think they've actually already covered the prs so you know i had the the one okay it was like 72 commits it was really big
Starting point is 00:28:14 um it got split into like seven prs uh and each one has been taking quite a while we're down to the last one finally for this for the split just to get the script pub key manager split we're down to the last pr then we'll get to descriptor wallets which is another 20 or so commits on top of that as uh as an engineer what's the hardest part of this mentally framing it before you write the code writing the code or reviewing um i think it's really the reviewing uh and the context switching So, you know, I write the code, open a PR, and then people have to go review it. Well, what am I going to do in the meantime? I'm going to go do something else.
Starting point is 00:28:54 Lately, I've been working on fixing up, working on the descriptor wallet itself, the descriptor wallet PR itself, or HWI or some block stream stuff or something else. But then someone makes a comment on my PR and I got to go fix it. But it's been, I don't know, three weeks since I last looked at it. i gotta go remember what what was i last doing here uh what was it supposed to do what was the reasoning for having this change that is completely uncommented and people keep getting hung up on should have commented um uh you know well you know that change was just to shut up a test or something like that and i don't remember the reason for it anymore how do you get how do you get in your flow do you have like a time of day where you get flow stayed is it uh um not really
Starting point is 00:29:43 although for some reason it always happens around 11 p.m so you have a time of day i like i'll just end up being like you know most of the day for some reason you know i work on some stuff but like nothing really like jumps out at me that i really gotta finish and then somehow at 11 p.m i always find something that's like all right i gotta finish this before i go to bed and then five hours later um it's uh very similar to how i write the bent i wait till 11 a.m it's supposed to be out at 9 a.m and then i'm like ah shit yeah two hours late already great work ethic yeah well yeah well i do have a full-time job too i am working i have um so so do you have any like suggestions of someone is you know aspiring to contribute to to bitcoin
Starting point is 00:30:31 core like how how best for them to dive into this like uh i think the best way is just to is really to start small and look at like simple things that uh you yourself want to fix like use bitcoin core yourself and find something that bothers you or something you don't like and try to fix it or change it and see how that goes yeah you got pissed off at uh at hardware wallet support and made something pretty big yeah there have been a bunch of um other i have some other wallet projects i've been working on that are just like i want this to be better and uh learning about how the wallet works so i can change it and make it better so like yeah so if you want to i think this goes for many open source projects it's use it yourself find something you don't like and
Starting point is 00:31:24 fix it yeah no it's uh and uh you can also go my way uh my the the way i got into it originally and that's just hang around where users are and see what they complain about and try to fix it yourself too is bitcoin talk still as lively today as it was when you first got in it's pretty lively it's a lot of junk um since i moderate some of the forums i do have to log in and like pay attention occasionally but i haven't really commented there in a while yeah i mean for you freaks that don't know bitcointalk.org was the place the forum to be back in the days where satoshi was talking outside the mailing list yeah there's a lot of historic threads that are really interesting you got the hodl the hodl meme satoshi you got hal finney in 2010 predicting
Starting point is 00:32:15 bitcoin banks yeah um you know dan larimer getting told off you have the epic forum redesign that's always two weeks yeah two weeks away how many bitcoin did they must raise no there was a beta about a year ago beta site isn't up anymore um but the software is called epoch talk and it is like actively being worked on if you want to take a look at it uh i haven't i just feel like that's such a bitcoin thing to do is like you want to redesign the forum so you just rewrite a whole new like forum stack instead of like borrowing from other people yeah there are things that themos wanted to have specifically that that are in bitcoin talk because he patched some php
Starting point is 00:33:10 to make it work but i guess he wanted it like as a feature itself yeah because php is back into a lot of cms's right yeah it's also not that great yeah it's uh there have been a lot of experience with drupal back in the day i understand that's not great bitcoin talk has has had many um many modifications to make it more secure yeah uh i don't remember what they are but i remember look in the list yeah because then somebody it wasn't bitcoin talk it was the gmx email somebody like yeah it expired and satoshi's username got to there have been yeah i think it was the emails that got taken over yeah uh yeah and then someone actually um someone actually got hal finney's account recently well really uh on bitcoin talk well i say recently i mean like
Starting point is 00:34:07 i guess it was nine months ago um started posting something and then it swiftly got locked down and banned what were they posting i don't even remember they're all it's all deleted they brought me back yeah uh but i know that i know when that happened um thamos or one of the other admins uh shut it down really quickly yeah i mean i would imagine yeah um that's actually one thing i hope twitter doesn't do now that they're shutting down all the inactive twitter accounts let people take old names they backtracked on that didn't they i don't i don't know i think it's i think it's europe only i don't know last night it was europe only and then they backtracked was my i don't know i just i just hope the running bitcoin tweet doesn't come down
Starting point is 00:34:52 that's a great tweet right i yeah i don't know about that yeah um all right switching topics here you i noticed you were talking about coin joins uh yeah the other week too let's talk about coin joins what are your thoughts on them what are the uh what are your thoughts on the um the products that exist that allow people to coin join today how they could be better how they're actually more importantly how they're they fall short and how they could be better yeah more importantly i want to talk about coin selection too so mix that in coin coins are great uh they're great for privacy um and they're uh a hard problem to coordinate i haven't really so the most i've most of coin joins that i've done have been um manual coin joins like me
Starting point is 00:35:44 uh find random people to coordinate a coin join together and that ends up being with me or whoever is coordinating it knowing everything which some people uh some people trust me uh i guess um and and so that's not really a problem but like this isn't something that you can do regularly it's kind of annoying it takes a lot of time and there's always there's always that guy that doesn't respond or yeah well that guy just doesn't respond um and i know that greg maxwell does does a lot of manual coin joins for around times. You just can't scale that.
Starting point is 00:36:25 It's just not scalable. How would you set up a manual coin join? Not what it docs your procedure or anything. I haven't done one in a while, but this would be for PSBD, by the way, so this is a lot more annoying. You would tell everyone to
Starting point is 00:36:41 send a TXID and VOUT. Also required them to know what that meant. And then I would use core to do create raw transaction make a transaction. They have to send txidv out couple addresses and the amounts that they want to those addresses and then If you're trying to avoid subset some analysis you have to say
Starting point is 00:37:09 One of these outputs has to be exactly. I don't know point one Bitcoin and And then everyone sends it to me and make the transaction. You have to send it back out to everyone else. And then they sign it and then I have to send it back to me and some, and I have to combine them all using some, we have a command for that. I think combine raw transaction,
Starting point is 00:37:33 merge some all together and then you can broadcast it, but requires a lot of back and forth requires people to know what a TX ID and a V out mean, uh requires them to know how to sign a raw transaction and requires them to also be online all the time and you have to trust each other and then they have to trust me to not to them all and you have to send it through secure channels so that yeah and then leak out then uh you know they'll pgp encrypt it or use signal or use like otr or something send it to me and then as very different it's really time consuming to do this manually so like we do have
Starting point is 00:38:15 some stuff that does it automatically now uh like what join market and wasabi they both do coin joins in the background and whirlpool samurai yeah samurai but well i haven't used them so i i don't have much to say about them i used join market back in the day uh like the very first few releases and the user experience is fine but i don't know how they what they really did in the background yeah is the i'm looking that much but the user experience is fine for you yeah i don't think that's really scalable yeah well and going back to you creating coin joins with individuals directly yeah is that there's something like uh adam gets some sticker make that easier because you could just broadcast uh well i haven't read it so i don't know all right um but i know that
Starting point is 00:39:08 pspd does make this a bit easier now uh we introduced a we i introduced a join pspds command that takes multiple pspds and makes them into a coin join cool so uh now if you want to do it manually you would say create a psp have your wallet create an unsigned pspd and just send that to me and then i'll use this command to join them all together so now it's slightly less like you don't have to know uh you don't have to know how to get your outputs and you don't have to know how to make a change address and all that yeah it's slightly easier but still still a bit time consuming well thank you for that um what are your what are your thoughts on coin join as the predominant fungibility solution going forward you think it's sufficient you think i think
Starting point is 00:39:58 well i mean confidential transactions would be nice but it's probably not going to happen uh i think coin joins would be sufficient if most like not not even most like the vast majority of people use them and but of course it's always there's still that problem of how are we coordinating coin joins and you know that's what everyone's been trying to solve that's how that's why wasabi does their charmian server thing join market does whatever they do uh we've had the pay join idea but i don't think anyone's really using that that's the maker is coordinating right so join market has makers but they don't know everything i think there's some way that they are able to mask uh information so that it's not uh so that one party doesn't necessarily know everything
Starting point is 00:40:53 but join market has had vulnerabilities where uh it's possible for people to find out what the inputs or who owns which inputs oh and they have constant improvements and stuff yeah well you mentioned pay join and that to me seems like the most makes the most sense right just make every transaction a yeah so pay join i was part of the group that came up with this which was to you would do a coin join with the person you're paying uh it's a nice idea but requires merchants to adopt it and i'm not confident on uh like say bit pay but btc pay helps here what about btc pay btc pay i mean yeah it'd be great uh and and i don't know if they do but yeah btc pay doing it and then but like a lot of businesses still use coinbase or bitpay to do their not us we're btc pay loyalist
Starting point is 00:41:48 here we're trying to make more people it's like pretty new it's pretty new that's why it's a game changer but it has no fees the market's going to choose btc pay right well see i'm a bit of a pessimist and i think that people are going to go with the easiest thing that they can do which is send a url to bitpay instead of firing up my own server running a node and figuring out how to configure this thing i'm a bit of a pessimist i'm gonna go with well it's good that you're the easiest the easiest option is just to have someone else do it but there's there's a middle ground there right where you could have like a thousand little bitpays that are all hosting btc pays right yeah you know like a btc pay as a service yeah i guess there's like
Starting point is 00:42:34 competitive market there at least they'd be more likely to implement something like pay join yeah but even then uh because it ends up being a custodial service yeah like you need to find something that's trustworthy and i wouldn't consider bitpay trustworthy but like they've been around long enough to show that they haven't really stolen or lost any bitcoin that it's not that i know of um but there was an instance so they're kind of trustworthy they did recently that's a pretty much incident there was there was a hong kong organization that had their account frozen oh yeah well that's a risk you run with any service like that yeah so that's actually brings up a good point like what is uh why are you in bitcoin why do you how do you
Starting point is 00:43:23 you're pessimistic about users uh running their own full nodes and accepting validating their on transactions, incoming transactions? What are you building? I'm pessimistic about businesses doing it because businesses also have bureaucracy and regulations to follow. Users,
Starting point is 00:43:43 I'm slightly more optimistic about them running their own full nodes, especially with people advocating for people to run their own full nodes and stuff. Are we all mountain men? Are we all crazy mountain men? Maybe. I don't know. But at least
Starting point is 00:43:58 like running your own full node is pretty easy as a as a user and you know it's your money that you're taking care of but as a business running your own full node and wallet well if you're a public company you've got shareholders to respond to and you have regulations to follow so maybe it's not as easy to run a full node and you also have to you have user data you might have to like hold on to this is what we're trying to get away from i say we just tftc if we ever grow into a unicorn we're bootstrapping with ptc pay and going up and that's why she actually says that time of the year we're doing our taxes and uh no shit taxes we uh we are the first year we had the business up so i had to report uh everything we received via ptc pay and again
Starting point is 00:44:45 the software makes everything really easy like um and yeah it is easy to comply like that like you can comply right um it just takes work it just does take work but it'll get easier i think yeah hopefully it'll get easier i'm hoping it'll get easier but the other thing with pay join is it requires interactivity right the the recipient requires yeah interactivity yeah pay join requires the recipient to be online if it's a merchant i'm they'll be it's a you expect them to be online because their website's still up um right right uh but like if it's another person they might not be online or it could just be like a donation address that someone's sending to then you can't do a pay join for that yeah but like pay joins a if wallets implemented it i think
Starting point is 00:45:37 that's a great way for coin joins to really take off more yeah btc pay listen yeah btc pay is going to implement it it's going to be a game changer uh you can put me on the record do it eventually core will do it eventually probably maybe yeah i make no promises when i say core will do it it will most likely be i will implement it into the world at some point after descriptor wallets and what hardware wallets and uh the other thing i was doing which was i don't even remember what it was anymore uh we were looking something with multi-wallet yeah we were lucky man what's it what's it like working at the protocol level like and working on this project do you um do you really feel like normal i'm not sure what
Starting point is 00:46:26 normal software engineering should feel like though it's just kind of just work to do like what what types of projects were you working on before bitcoin uh bitcoin was my first major well i think bitcoin was my first open source project i got into uh because i was in high school and you know not like i was going to do anything else and not like i was looking at anything else yeah you've never known a world without building on bitcoin damn that's weird all right do you uh i mean i had but like other open source projects that you look at are scary like i don't know have you ever looked at the linux kernel that's just that's scary i don't who wants to touch that no uh you were talking to somebody who's never looked at uh the linux
Starting point is 00:47:11 kernel we just talked about i just bought the uh a book that has the bitcoin first version of the bitcoin source code in it um i will i will look through that but that's about as much code digging as i can do i mean i've i've read some of the linux kernel mailing list stuff and i was like this is way beyond me it's far scarier that's you're blowing my right you're way younger than me and you've contributed i mean thank you again like matt said like we're lucky to have you working on this stuff and you don't it's just like nothing to you it's crazy just bored into it i fucking love it bored into it yeah so like what like what what is your grand vision of bitcoin in the future like how what do you see in enabling or potentially enabling do you think
Starting point is 00:47:55 matt corallo came in here about a year and a half ago and said bitcoin has a five percent chance of succeeding um uh i don't know i don't think that far ahead no well like what do you how far ahead do you think just about a week needs needs to be up by next needs to be up uh next week and still up so do you find this more of just like an interesting uh intellectual engineering project or yeah that's that's mostly how i came into bitcoin it was just an interesting interesting to to work on and think about yeah uh as for like where it's going uh that's not something i really consider um i'm just mainly since i'm working on the wallet is just to make it make it easier to do more things uh make it easier to like do more multi-sigs or more
Starting point is 00:48:45 i guess you could do lightning scripts and htlcs and core after descriptor wallets shit uh just make it do uh let the user have more options yeah no it's great i mean this is the uh the common uh the common not verbatim response but paraphrase response i get from core developers you get like you're inherently uh drawn by the intellectual um from observation intellectual challenge and then you really don't think you like focus on the long-term success yeah that's probably yeah that's probably how a lot of the bitcoin core developers got into it anyways and it's just the mindset that keeps you going yeah and do you think that yeah do you think that's the exact right mindset to have when approaching with stuff um well kind of it's an open source
Starting point is 00:49:43 project and i feel like there shouldn't be that much of a huge grand vision that like the core project should be pushing for yeah that's a very like very valid and great point and so how as an engineer like looking at us twitter podcast or crazy bitcoin users like what is uh what do you think of the outside world non-engineering world um mostly boils down boils down to uh lull and then scroll that's that's about my interaction with twitter it's all noise you think it's all noise a lot of it's noise yeah yeah most of it is i would agree i contribute to it a lot too occasionally someone will say something wrong and then i go hey by the way you're wrong that's what twitter's for yeah yeah just dunking on people that's not a dunk that's a
Starting point is 00:50:44 correction it could be a dunk it depends on how you word it what do you what do you do outside of bitcoin uh i read books and i play video games what kind of books do you like uh usually sci-fi i'm reading the expanse the expanse novels i want to start that i've watched the show yeah i watched a show i'm like this is based on a book so i'm gonna read the books the show is great yeah there are nine books and i'm on like book four i fucking love sci-fi what's your favorite video game right now oh man um recently well i recently started playing the witcher and then but like one of my favorite games has been skyrim skyrim is that just is that like the hours and like expansive universe yeah so it's an uh it's an rpg and with dragons
Starting point is 00:51:38 you see you're talking to somebody who hasn't gamed in like five years yeah i'm big i'm big on video i know i know uh sats and games bitcoin and games it's gonna happen right oh man i kind of don't want it to really you don't want to okay well this comes from my uh the the gaming part of me of i dislike micro transactions fair and and what do you dislike about the incentivization behind the incentive the the incentives it produces and the um uh unfunness of the games it makes yeah i'm not a big gambler either like i don't like gambling like yeah so like having like the lightning network in games or having people been paying with sats and games i of it that's the whole uh micro transaction thing and i'm not a huge fan of that the reason
Starting point is 00:52:29 micro transactions and games right now fucking sucks is because it's all built around these like closed systems that are designed to give the publisher like a shit ton of money yeah and and it kind of creates like this play to pay to win environment a lot of times or or just it's just outright malicious because it's like skins or something like that yeah but if you actually use like real money like bitcoin um there's some situations there where you can develop like p2p games or something where you kill someone and you get a few sats and they lose a few sats that seems less um it seems like a whole different concept than like our current brew of microtransactions yeah but that also just mean i wouldn't want to play it because
Starting point is 00:53:12 then i'd be losing money unless you kill people right if you're good at it you could you know make a living out of it maybe make a living camping you know in a shooter game or something what do you do for a living oh i just sit by the spawns and counter-strike well what was what were the uh well then that that just produces unfun behavior right yeah exactly you got a good game the game needs to be structured well right it can't be a broken game i don't i'm just not a huge fan of the micro transactions in in any game like i i really i really just want to you know i pay once and i get the game and all its content that's fair and then i can just grind it for a few hundred hours do i need to get a system am i falling behind absolutely
Starting point is 00:53:52 very good answer i want to jump back into i like i really want to talk about coins okay all right coin selection coin selection what are your thoughts on it it's fucked right now it's pretty shitty wasabi's got coin selection electrum and then that's about it right well coin selection is a hard problem uh literally like i think it is uh it's a subset of the uh subset sum problem or something like uh fuck what's it called there's a computer science problem that is very similar to um coin selection uh where you have you have a bag of numbers and you want to choose the correct number of like the certain ones of them that meet meet meet this happens to me all the time don't worry meet a certain goal that that meet a certain goal like
Starting point is 00:54:48 so in bitcoin you're you have a bunch of utxos with some value and you are trying to meet the amount you're trying to send and this happens to be a hard problem i believe like computationally hard uh because there are so many possible combinations and and then you also have to decide what is quote unquote best how do you and how do you define best and the two big things are fees and privacy right yeah so you gotta you have to balance privacy fees now and fees in the future right so we have um there are a ton of different different strategies you know you've got your your first in first out or largest output or um uh the bitcoin core thing or the uh branch and bound algorithm and tons of other things but if you consider like largest first uh
Starting point is 00:55:47 sort them by order and you just pick the biggest one this definitely optimizes for lowest fees now right right you got one input and it becomes two outputs probably but what does that become in the future what are your fees going to be in the future well you've taken your biggest output you've cut in in half and now you cut that in half again and you kind of have and it just goes to dust well you've got a bunch of dust outputs and if say you haven't been receiving that much but you you're sending a lot or something uh you've got 50 dust outputs and now your fee now is humongous so your coin selection algorithm needs to balance for not just what your fee is going to be now but what is it going to be in the future how is
Starting point is 00:56:35 how are the utxos in your wallet going to change as you use this algorithm and this is a combination of the coin selection algorithm and maybe wallet ux of warning people hey maybe you should consolidate this dust or is that something that's untenable uh it's a bit of both i guess um consolidation hasn't been something i've been thinking that much about but because ideally you want your selection algorithm to realize that it's creating dust or well yeah to not require consolidation but that's hard to go up when fees go up right yeah and start consolidating yeah and and uh with coin selection you also have to consider well this output might not be dust now but in a couple months if the fee fee rate shoots up to like 100 satoshis per byte that might be
Starting point is 00:57:25 dust then and that was we found this out in 2017 yeah coinbase had like three million dollars where the dust they couldn't move or something like that a lot of people ran into dust problems when the fee rate shot up so like coin selection has been very difficult to find that balance uh the algorithm that bitcoin core uses now we call branch unbound which was developed by well designed by mark erhart also known as merch or yeah he's the main bitcoin stack exchange yes he's he's the bitcoin stack exchange um head honcho yes uh and he wrote uh his master's thesis designing this algorithm and analyzing it and other ones so it's actually it's like it's an actual scientific paper and it's a great read if you want to go learn about coin selection
Starting point is 00:58:16 algorithms and how they all suck um it's on his website somewhere uh and i've dropped the link The link's actually in the core source code, I think. Yeah. In our description of branch and bound. So branch and bound is, it does an exhaustive search of every possible combination of UTXOs, basically. So that is, this is also why it's considered hard. It's n factorial, right? n factorial number of possibilities which is which if you were to iterate
Starting point is 00:58:51 through every single one of them would be literally take forever and so what we did was so a merchant was basically you design design it as a tree of include this UTXO exclude this UTXO and like like that and by sorting them sorting UTXOs we can say if we include this and we're over and we like we're over our we have an upper limit because we're trying to do an exact match if we're over our target we can now ignore everything else that includes this UTXO which does mean we cut off tons of this tree which is quite called branch and bound because we're bounding it which makes the search time way faster so it's basically I mean it's kind of a tree yeah i was gonna just butcher it like a merkle tree with a bunch of
Starting point is 00:59:45 branches cut off yeah you can consider like a kind of like a boolean tree where every level is whether to include a utxo at that level a specific utxo so like you start with do i include the largest one or do i not then yes i included it or no i did not include it okay the second largest one i included the largest one and am i including the second one and so on so it becomes a tree and then you just cut off you start cutting off the branches where it doesn't make sense to keep including more because you've already gone past your limit yeah so one one input yeah if one uh i can't even try to explain that this requires a whiteboard yeah this doesn't include privacy at all privacy considerations at all right not at all you're so the privacy
Starting point is 01:00:36 so the privacy part comes in with if you want to um it's a common input heuristic right well the so privacy is when you get to it's the pre-processing step before the coin selection so you get to when you get to the algorithm you just say here's a bunch of numbers basically that's what you tell right but in your pre-processing you might combine uh you might say we're going to group all of these utxos and treat them like one so this is their number stuck together they're already linked so it doesn't matter to combine they're linked or they're the same one uh it's the same address so let's just call it as one when we give it to the coin selection people shouldn't be reusing addresses anyway yeah you shouldn't but it happens right
Starting point is 01:01:23 and then in core we have a we have a thing now that does that it'll group together uh there's an option you have to enable but you have all of your any reused addresses will be grouped together as one and so the so branch and bound algorithm will think of it as one utxo yeah it makes sense and the other thing that the one a privacy thing that um branch about does work with is a change so branch and bound is an exact match which means you don't make change ah everything that you do you you won't make something that's linkable because it all just goes to the merchant okay or fees there's so many goddamn things to think about coin selection well like best case scenario there's no fees but sometimes there's and there's no change right but
Starting point is 01:02:13 sometimes there's change yeah so if there is a combination so if branch and bound fails uh which happens fairly often because you can't always find a change uh no change solution uh we fall back to whatever bitcoin core was using previously which is some weird loop that does some random shuffling and some something else and no one can really describe it because it started as one thing and then just got patches slapped on top it's uh it works decently well um but it has this minor problem of not considering dust or rather not considering that something is dust so if you have dust it'll probably spend it yeah well dust is such a hard right because it's so contextual relative to whatever the fee market yeah point in time right yeah so with um such like a that's
Starting point is 01:03:12 So we've had Drew Bensal on in the past who created the concept of huddle waves and doing chain geology research to see when people are moving UTXOs and brought up the concept of a dust holiday, which intrigued me at first, but you can't really. It's never going to happen. Yeah, and miners would never go with it. There's no game theory there. Yeah. So with Branch Unbound, it's an exact match with a fuzzy fence. uh basically the idea is that this um this is one of the main innovations of it which was instead of we're choosing exactly this value it's we're choosing this value
Starting point is 01:03:51 plus some buffer that we're willing to discard as as fee even though all it'll just boost our fee rate so you don't get the change but we weren't we aren't going to get the change and the idea is that if we make a change we have the fee that we're going to pay to make it and the fee we have to pay to spend that change in the future so what if instead of dealing with that fee in the future after we made the change what if we just consider that as the excess that we are willing to waste and so that is our buffer just how much are we that's not even a waste it would be the premium you're willing to pay to avoid future headaches i mean it would it would basically be we're going to pay this now or we can we can pay this in the future or we can pay it now
Starting point is 01:04:38 and the benefit is that we won't make a change output the benefit is privacy you're doing the benefit is we get a bit more privacy and uh you have one less utxo to deal with yeah and you and potentially just don't have money that you can't use yeah yeah it's also it also ends up being fairly consolidatory uh in the simulations i've ran it does pretty okay pretty comparable to core in that uh it keeps the the number of utxos in your wallet like kind of down core the core wallet does consolidate a lot because it'll eat your dust outputs and spend them uh which means you're losing money but it happens um i have a bunch of simulation results that compare all of that compare branch and bound and core and uh it's interesting to see how
Starting point is 01:05:34 how they perform how long did these simulations track uh a little live action like uh well so you remember um back in 2012 2013 there was uh it was money pot there's a there's a gambling thing called money pot or uh what was that a long time ago there was this gambling site called money pot and the guy who ran it published all the uh deposits and withdrawals so that became our simulation data at least one chunk of our simulation was it like satoshi dice i don't remember what it is i just know it was it was a gambling site ran by ryan havar okay and uh he also ran bust a bit and they did the same you did the same thing there published the numbers so for all of uh our simulation data uh some of the simulations i've been using those okay and
Starting point is 01:06:37 then the rest of it i've just been choosing blocks by random in the blockchain and pulling out all their all the numbers from them oh so you can just use so it's like it's not even like randomly generated you can use bitcoin's current state yeah it's just like uh i'm gonna pick that block and go through every transaction and all the outputs they make uh randomly select whether they're going to be inputs or whether they're going to be deposits or withdrawals and that's those are my numbers fascinating i never thought it would be it also takes like six hours i thought you would have to create like your own like fake no that's too much work yeah fascinating so what what are the steps to making this coin join solution coin selection coin selection coin
Starting point is 01:07:26 coin selection i'm really glad we brought it brought back up coin selection this has been yeah it's been fascinating so you're working on it now testing it out um so branch amount has already merged it's been merged for a long time what we're what i've been working on is replacing the fallback so we fall back to core when we need to make change uh but in merch's thesis he suggested that we use just a simple random selection because apparently just randomly picking outputs does pretty well that's better somehow uh core kind of does that but like with more steps on top um it's not entirely random but just if you just randomly select outputs with a bit of uh bounds on like how small of a change you can make
Starting point is 01:08:13 uh it does apparently it does pretty well and the simulations have showed that the main the main problem has been when we do all this we're ignoring our dust outputs which means that if you compare the numbers direct the simulation numbers directly we have the mean number of utxos the average number of utxos in the wallet ends up being way higher when we do branch and bound with random selection fallback and that's almost entirely because we don't clean up the dust outputs that would make sense right yeah like as soon as i modified core to ignore dust outputs and like it's pretty close it still does a little bit a bit better so how would core how does it currently identify dust outputs basically there's takes a function that says is dust and it takes a v-ray but the v-ray
Starting point is 01:09:06 rate like is there dust right the fee rates well yeah there is the fee rate is like binance was binance or who just consolidated all their tether you like 546 sets yeah so yeah yeah dust has a really dumb definition this is this is a fun one so the original definition of dust was you take the minimum relay fee and the cost it would so however much how many satoshis it would cost to
Starting point is 01:09:41 spend an output at the minimum relay fee but one third of that was dust is the theory that you could wait longer I don't know what it was but originally it was like
Starting point is 01:09:56 the fee rate was the minimum relay fee which was set by your mempool but it's like how many blocks it's not how many blocks it's just based on what is oh like one sap per byte it's one sap per byte usually
Starting point is 01:10:08 but like what is the so the minimum relay fee depends on how full your mempool is so as soon as a mempool hits its limit
Starting point is 01:10:16 it starts popping up the min relay fee so it doesn't accept any more transactions so it's usually one sap per byte it'll go up
Starting point is 01:10:24 when your mempool hits 300 megabytes which is freaking huge no one really It's bigger than the chain state, or no, megabytes. Megabytes, yeah. Gigabytes.
Starting point is 01:10:36 I was thinking in gigabytes, my bad. So the min relay fee is one. The calculation was something like the fee to spend the output, but one third of that or something, or maybe it was three times. There was a three somewhere in there. Eventually, we got rid of this definition and replaced it with, we created a dust relay fee a separate variable uh anything and it was just at that dust relay fee the cost to spend the that output and that was the dust value for it and that dust relay fee to
Starting point is 01:11:13 make it compatible with the original definition was uh is three sats per byte so it makes the calculation so much easier yeah so the original way was you could have like millisats being dust or depending on what your relay fee was or uh i mean like you can still have those it's it was like i mean the the number boiled down to 546 sats yeah um but the and same with the new dust relay fee but it's a it's a straightforward calculation now so when we do our coin selection we just use the dust relay fee to determine if something is dust and then we might change the fee rate um like what if the fee rate dust really fee i think will also change depending on mempool i'm not sure uh but like for our coin selection stuff we have a long-term fee
Starting point is 01:12:11 rate okay which is like the thousand eight block prediction which is always one saprobite anyways I've seen it change like once are you worried about the fee market developing at all do you think about that not really I'll think about it when I do my coin selection stuff well I can't really avoid it
Starting point is 01:12:35 so so like right now if you want to do coin selection with privacy in mind you have to just manually coin select yeah pretty much no one really considers that much of privacy i guess with the coin selection that maybe wasabi does because
Starting point is 01:12:55 that's their point no wasabi wasabi just forces on the user but it forces on the user gives you manual coin selection and you have to decide samurai's plan is they're trying to do like a where they almost do like a localized chain analysis to try and determine what links are between the different utxos and select accordingly okay i don't know but like it's a super hard problem as a user as a user i personally like being forced to coin select like i like that wasabi forces you to label and select i'm actually fairly wary of user coin selection why because users will optimize for the wrong thing why do you say that um users will probably optimized for minimum fee and that's not what i've been optimizing for when you're not a normal
Starting point is 01:13:47 user i'm a user a lot of a lot of people just optimize for the minimum fee right right what do you think do you consider your change how large your changes especially when fees go up yeah people get greedy really quick yeah so but do you consider when you do a coin selection do you consider change like how big is your change output going to be yeah i don't yeah exactly yeah yeah so are you scolding me right now not really um but coin selection changing coin selection has an impact on the utxo set uh in general like uh this merch's first pr and maybe only pr to core was changing coin selection and it got reverted because if you looked at the utxo set there was a humongous spike when that version of core got released and because because it was just creating
Starting point is 01:14:39 more change it was making more dust it was reducing it was something something like you have way overshot the target so let's and we had we overshot it because we had included a bunch of extra utxos that were not needed at all so remove those so the change would be released get smaller and sometimes it would just be too small and be basically dust um this was in the 0.12 release uh where the in the 0.12 release if you look at the time it was released and you look at the utxo set size on like statoshi you will see that there's a pretty big spike and and that that means that it puts an additional burden on all everyone who runs it yeah it it burdens everyone who runs node
Starting point is 01:15:27 yeah so if every user did manual coin selection I think that they would optimize for the wrong thing and could cause a huge increase in UTXO growth
Starting point is 01:15:43 but then fees would probably rise and then it should calibrate that's the idea of a fee right it might consolidate but it might also just yeah like people might consolidate but they might just see it's dust and can't do anything with it right at that fee rate yeah so how uh what are your what are your your thoughts on the current uh chain state and its growth um it's pretty big you think it's too big uh i think we're pacing
Starting point is 01:16:13 well i think it's it's a bit larger than i would like it to be but i think everyone thinks that we've had a lot of performance improvements that make the sync time about the same so um you know the chain grows 20 larger but you've done a performance improvement of 20 well the time to sync hasn't changed and that's been happening a lot for the past few releases time hasn't really gone up but i don't think we can keep keep that up do things like assume utxo appeal to you assume UTXO is very useful for a fast
Starting point is 01:16:57 sync I think doing UTXO set commitments and assuming yeah I think that'd be good like there's a PR for that right yes yeah and then what was the other thing I was going to say it doesn't really bother me because I don't sync
Starting point is 01:17:15 a node that often my node is always synced because it's never off but for for new users uh having a faster sync like you assume you take so is i think it's fine yeah it makes sense to me as long as you're validating in the background yeah and i like the idea of having it uh you know here's the we're gonna start here but download everything from history so that we can check what uh what we started with yeah you can bury the checkpoints deep right yeah not checkpoints it's a bad word not verifying it anyway yeah and
Starting point is 01:17:53 i i think assume utxo would be similar to what we do for assume valid which is like it's not part of consensus it'll just be an extra thing that you can turn on yeah that's packaged with the software you can use pgb pgp key pgp see i'm telling you it's happening now use the keys and webs of trust too yeah to help cross verify and stuff like that yeah but trust yeah that's true good point um but are there any efficiencies outside of like assume utxs that you see helping to reduce chain like what schnorr signatures obviously would be huge for this or i don't think i don't think schnorr signatures will no change much because we don't have like signature aggregation yet i mean it'll be smaller uh blockchain won't grow as quickly i guess
Starting point is 01:18:45 with um with taproot and short signatures uh but that doesn't that doesn't really help what is current like the current state it won't change it won't improve anything that already exists it'll just make it better for the future yeah and so that's a process over so like i think the main problem is making what do we have now go by faster uh rather than in ibd yeah in ibd okay uh like we've had a ton of performance improvements um recent ones i've been seeing have been like changing around data structures that are to ones that are faster and more efficient uh which help so what is uh the one thing gleb and peter are working on is it early or early yeah that would help considerably with bandwidth correct um early
Starting point is 01:19:40 or is early the early is for transaction relay not for ibd so it wouldn't okay it wouldn't wouldn't change anything it's for nodes that are already fully fully downloaded i believe so yeah yeah okay interesting all right well we got bit devs to get to soon oh yeah a couple hours yeah it's a few hours um is there any any other pressing uh bitcoin topics that you want to talk about you want to talk about hardware wallets yeah let's do it what are your thoughts on hardware wallets what uh do you have a particular favorite uh they're all great and they all suck simultaneously what do you mean by this um as a user they're great as a developer holy crap they're all everyone does the same thing but slightly differently which makes
Starting point is 01:20:26 my job working on hwi much harder um like you know they all take a transaction they all sign it well how are you giving it that transaction uh trezor takes it in their own uh they use protobuff and you have to pack the transaction into a protobuff thing and you send it but that only works on trezor ledger has its own magic that i haven't looked at because uh that was implemented by greg sanders what's i don't know what the magic is do you have a personal uh i like the cold card okay because it's the easiest we're big cold card fans it's um and i i like how they used uh psbt with it too because like yeah the uh when they with the psbt stuff on the cold card you just there's just a thing that says upload psbt or just upload file
Starting point is 01:21:27 and that's all i have to do for the implementation in hwi it's just upload a psbt i don't even have to i don't even have to deserialize the thing well pass it to it this is i i created and sent my first psbt last week with wasabi and uh cold card and it was extremely easy it was i mean luckily we have matt here leading the citadel workshop uh to teach me and i did it on testnet a couple months ago but a couple weeks ago i took it upon myself to do it on the main net and it was extremely uh easy and it was a fun experience like moving the sd card from your air gapped wallet to your computer and then dropping the the transaction broadcasting it from wasabi it was like wow it was like another aha moment for me like that probably the biggest aha moment i've had since i first
Starting point is 01:22:18 recovered bitcoin from a seed phrase seriously yeah i like i like the cold card i like the ledger for a while until i found out how they install apps and update firmware um and then they like the other major players ledger likes trezor trezor's meh trezor has a trezor has limitations on what you can do um like my dad psbt soon they have a sd card slot on the on the treasure t what about what about uh solutions like justin moon's bitboy making your own hardware wallet from generalized hardware? Because I saw he did. That was PSBT
Starting point is 01:23:06 compatible too. Yeah, I think that's an interesting project to do that. But I'm not quite sure what it's trying to solve. What problem it's trying to solve. Like maybe a bit of a some of the trust stuff.
Starting point is 01:23:24 It's like supply chain. Supply chain. And you mix it into a multi-sig setup so then some of the trade-offs that you get for like not having a secure element or whatever it can um like i mean i'm i'm i wouldn't be and okay same with trezor i wouldn't be convinced that it prevent uh protect against someone stealing the device yeah but like well bitboy was stateless is it yeah intentionally okay yeah like uh trezor i wouldn't be i'm not convinced that it would protect against someone stealing it uh it definitely won't it definitely won't yeah i know ledger ledger i'm more convinced that it will it'll be fine if someone steals it but then you
Starting point is 01:24:01 have different supply chain but then you have like you have the ledger trade-offs yeah um and and the ledger the issues that ledgers have uh cold card same thing but i haven't looked at their hardware that closely so do you have that do you have like an ideal vision of what a hardware wallet should be and should do in your mind or um not really i guess i'm thinking the hardware wallet i want is a cold card in the form factor of a ledger that's about it you don't like the calculator i don't like the calculator i dig the calculator you just want to be a usb stick i think it's too big really yeah i thought it was gonna be so much bigger and before i got one like in the pictures it looks way bigger so i've always considered it really small because it beat my expectations
Starting point is 01:24:49 oh okay i maybe it's just because i was used to using ledger at that time yeah um the ledger's tiny yeah the ledger is really small that's why i like it yeah uh the i i like the cold card i guess um also cold card does not have shit coins definitely that's the that's the that's one of the better parts of it one of the best parts of it i think what are your thoughts on shit coins yeah the uh especially in hwi uh we've had i've had so many problems trying to get uh firmware built for the devices for testing um and they all get hung up on like shit coins like my build will stall on like something something ethereum like i don't care why are you building it just adds more complexity yeah this makes it more annoying to deal with
Starting point is 01:25:41 looks like trezor is realizing that right and they're offering a bitcoin only product now and i think i need to fix hwi to build the bitcoin only firmware for that because i never got around to it and we um for our testing setup okay yeah so they all thankfully now they all have a simulator uh you start a simulator and then you can do all the same things to it but it's just over a different interface and that's how we test hwi uh but the simulator needs to be built from source basically okay um ah fuck what the hell was i just gonna go into i have something uh all right go for it i'm gonna remember what i was saying um would you agree that if people are expecting schnor in 2020 they're going to be disappointed
Starting point is 01:26:30 probably yeah it's so much people were throwing that around today i'm thinking that schnor it's it's just because of like what everyone has what snort by itself is capable like the uh signature aggregation stuff and all that stuff that people thought it would do are just not going to be there right because they're not done yet implementation yeah because it's like requires other changes requires large changes or it's just not it's not done or we're not confident in its safety but even base snore we probably won't even snore i think well it's just gonna be underwhelming it's just so we might get in 2020 but it's gonna be underwhelming yeah uh i know this is past your week outlook so a little bit past it andrew i think we might get
Starting point is 01:27:23 it in 2020 by the end of the year like the second week of december are you gonna prove i'm i i would put a a less than 50 chance on december 31st um i dig it the bip number is coming soon i think are you going to propose the activation uh process no everyone's too scared to propose the activation process no no you can't propose activation until the the details have been proposed you gotta wait for peter to propose like bip schnor bip tap root first like get get the number assigned then we can go deal with activation yeah so right right bit taproot its current form is just a warm-up until it gets a number um it's just a draft just a draft okay which means it can change at any moment uh and you should definitely not implement anything based on
Starting point is 01:28:14 it yeah and then because alex leishman was telling me that the taproot review found some versioning problems or something like that yeah the taproot review has taproot review club has been finding coming up uh finding some questions and issues that should be answered or things that should be changed i haven't really i haven't participated in them so i'm not up uh up to date on the details but i know like it's actively being the bips actively being changed based on comments from review yeah which is good it means that people care yeah no it was actually interesting to see how this review process came to be. I think AJ Towns
Starting point is 01:28:54 did the bull by his horns. Bull by its horns it seems and a lot what was it like 215 people signed up? I don't know how many people participated. I thought about signing up but I was feeling lazy and I didn't know
Starting point is 01:29:10 I didn't want to review more things. No more laziness Andrew. You haven't done enough yet. You're young. No I'm kidding. You're not working nights and weekends in your 20s, and you're not going to be successful. Yeah, definitely.
Starting point is 01:29:28 You always got to be working for those dev incentives, man. What are the dev incentives? What drives you to work on this? Absolutely nothing. Well, this has been fascinating. Thank you for responding to my DM. Thanks for reaching out. It's been interesting.
Starting point is 01:29:47 It always is. It always is. matt do you have any uh anything you want to end on in particular i'm just really thank you for everything you do i'm just really glad i got to be a part of this conversation and i'm really glad we jumped back into coin selection i thought that was fantastic yeah and andrew do you have a parting note for the freaks out there uh no you should follow me on twitter but i don't tweet anything so maybe you shouldn't follow him on twitch you can follow me on twitch and i won't stream for another your last stream was december 5th i checked a couple weeks yeah december 5th that was
Starting point is 01:30:21 uh that was a month ago oh okay i thought about streaming yesterday but it was only a thought all right we need to turn those thoughts into action moving forward i thought the twitch thing was super cool that's how i discovered you it was the twitch streaming i i've yeah i got that feedback a lot of people like it but it's hard to uh stream when you have nothing to stream well twitch is a big audience too in a date with bitcoin information so you're doing your part yeah when you do show up what's your let's show your twitter account how are they going to follow you all of my social stuff is achow101 a-c-h-o-w-1-0-1 literally everywhere online including in games so if you run into me in a game
Starting point is 01:31:05 you can say hi and i'll try to destroy you it's the perfect place to end it andrew thank you for your time thanks for having me peace and love freaks

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.