TFTC: A Bitcoin Podcast - Tales from the Crypt #80: Andrew Poelstra
Episode Date: June 18, 2019Join Marty as he sits down with Andrew Poelstra, Head of Research at Blockstream, to discuss Cryptography, how small of a field it is, how it's culture compares to Bitcoin's development culture, Tapro...ot, MuSig, MiniSketch, Schnorr signatures, and much much more. Checkout Andrew's work: https://github.com/apoelstra Follow Marty on Twitter: https://twitter.com/MartyBent Shoutout to this week's sponsor, Cash App. Head over to the App Store or Google Play Store, download cash.app and start #stackingsats today.
Transcript
Discussion (0)
Well, hey there, freaks. It's your boy Marty Bent here to introduce this week's sponsor
before our incredible conversation with Andrew Polstra from Blockstream. We talked about
really cool stuff. A lot of it went over my head because I'm an idiot, but I think you
guys are going to enjoy it. This week's episode of Tales from the Crypt is brought to you
by the Cash App. You freaks already know about it, but we also got some goddamn good news
this week. It looks like they're finally rolling out deposits on the app. So if you have Bitcoin
and you want to deposit on the Cash App,
it looks like they're rolling out that functionality.
I currently have the ability to do that.
You got to go through a little,
you got to share a little bit of information with them
and then they enable deposits.
So it looks like they're about to close the loop
on the Cash App.
And you guys know the Cash App's been
the number one finance app in the app stores
for the last two years with 15 million plus users.
They've also got the Boost program,
which allows you to go to merchants
and save and get money back.
you get a boost card you get to personalize it with your signature uh with a little bitcoin
symbol with the lightning bolt whatever you whatever floats your fancy whatever tickles
your fancy that's the correct term there um so yeah go to your local app store today
download the cash app again they're enabling uh bitcoin deposits on the app they're rolling that
out right now as we speak um as uh it seems that uh things are things again they're closing the
loop on the Cash App. I hope you freaks enjoy this episode of Andropulsia. I know I did.
I learned a lot about cryptography, Taproot, Bitcoin development, culture, and other things.
Enjoy.
What is up, freaks? Welcome back to Tales from the Crypt here in the Blockstream suite
for interview two of the day with the head of research from Blockstream, Andrew Polstra.
Andrew, welcome to the podcast.
Hey, thanks for having me.
Thanks for coming on.
I was listening to your most recent episode, podcast appearance, excuse me, on Noted with
Pierre Michael, two stand-up gentlemen in the Bitcoin world, learned a lot about Miniscript.
We're going to jump more into that in a little bit, but first, as is par for the course here
tales from the crypt what were you doing before you found bitcoin how did you find bitcoin and
why are you working on it now so i first found bitcoin in 2011 and at the time i was about
halfway through my mathematics degree at simon fraser university in burnaby canada and i first
heard this is kind of funny you just interviewed lawrence and he talked about finding bitcoin on
slash dot and it seemed like way too good to be true and so i also heard of bitcoin on slash dot
but unlike lawrence i did not have such a positive impression of it back in back in 2011 there was
a meme going around on reddit and on slash dot and other uh uninformed places that the way that
bitcoin worked is that you had these people grinding through all of these hashes until
they found like a very low hash and that part is true but then the story was that like bitcoin that
the hashes were the bitcoin somehow you were like selling these hashes and i thought that's that
doesn't make any sense sounds a bit stupid yeah i'm like you know i should go to this bitcoin
website and just copy all their hashes because this uh this sounds ridiculous but okay if they'll
pay me for these hashes i'll find a list of hashes and um so i went uh i wound up on i guess
bitcointalk.org and on irc i forget the exact sequence of steps that led me there and i wound
up hanging out with um with a lot of people who we now know as like giants in the bitcoin community
at the time in 2011 they were just you know normal people enthusiast yeah just enthusiast
um and i would go on irc and i'd say dumb things and greg maxwell was there and he'd he was always
on irc in those days like very very patiently answering questions for new people and getting
people up to speed um and i had shown up like many people in the era and many people still
like trying to prove that this whole thing was ridiculous
and it was never going to work.
But the more that I looked into it,
the more interesting it became.
And funnily, the more time I spent in the Bitcoin community,
it was so welcoming
and it was such a friendly place at the time
before any of the controversies that we've since lived through
that I just stopped going to Slashdot.
So Slashdot basically killed itself
with this anti-Bitcoin rhetoric,
as have so many giants.
uh so it seems like you stumbled into bitcoin like an opportune time towards the end of your
your studies and you it seems like this is your career now and how how does that feel to come
straight from college into into this world yeah i was extremely fortunate um as i was finishing my
my degree i had a year almost two years uh to sort of bum around in the bitcoin community tried to
compile bitcoin uh bitcoin core at the time was just called bitcoin it didn't have the the gui
that we have today it was using a toolkit called wx widgets which is not important what that is
except that it didn't compile for me i spent two years trying to compile the software and i couldn't
do it and then eventually i think cory or vlad or somebody added an option to disable the gui and
also replaced it with more modern toolkit toolkits that actually work um but by that time i i had
gotten into the habit of just compiling without the gui and i've never used the bitcoin core gui
even though I use the command line since then.
But when I finished my degree,
I went straight from SFU to the University of Texas at Austin,
where I was starting a PhD in mathematics.
And around that time, I discovered the IRC channel Bitcoin Wizards,
where all of these people were doing amateur cryptography,
like reading papers off the Eprint archive,
studying all these cool ideas that it hadn't occurred to me
i would have access to without doing a degree in cryptography so this had been something i'd
wanted to do for quite a while but i couldn't because i couldn't find anyone to supervise me
doing a crypto degree i was having trouble directing my studies to work cryptography so
i had been doing mathematical physics this is this cryptography sort of a very very niche
area of mathematics that very few people are in or it's not very very niche um but it is a fairly
it is a fairly small community um people who do academic cryptography um at least in the very
applied uh window of academic cryptography that bitcoin people are involved in so when i go to
academic crypto conferences uh they're conferences like real world crypto or financial crypto or
things like this that are not so much general cryptography it's not discussing applications
of encryption it's not discussing a lot of what people use cryptography for in the outside world
it's very much focused on signatures and zero knowledge proofs and the kind of things that
apply to bitcoin and financial technology and i always see like the same hundred people at all
of these conferences like it's really kind of a narrow community um having said that it's not so
niche that it would have been difficult to find somewhere where i could study cryptography but i
would have had to look and at the time that i started my degree i wasn't really looking so i
just sort of found myself unable to do it and when i started my degree i wasn't so into cryptography
that i was going to do anything to do it right i also wanted to study mathematics i also wanted
to study physics and that's what i wound up doing is it scary at all that uh there's uh you see the
hundred same people at these conferences about a technology that is very imperative to to the
future of humans i would argue so sometimes yes so this is getting better as more people come into
the bitcoin community and as information spreads out more widely but it certainly has been true
in the past and it is still true now to some extent that there's a fairly small community of
people who really understand this technology quite deeply and every so often an enormous
proportion of those people wind up in the same room or on the same plane or something like that
and in the early days this would seem to happen quite a bit and we kind of we both wisened up and
stopped riding the same planes all the time and also it's a much more open it's a much wider
community it's much easier to get into this stuff so it would be less of a i mean it wouldn't kill
bitcoin if like if something were to go wrong with one of these rooms full of a small set of people
that is uh it does like conferences like that even that not even cryptography specific bitcoin
specifically freaks me out when when bitcoiners aggregate uh or congregate excuse me in a very
very centralized location but uh it is something i had actually had this conversation a couple
weeks ago like like you see this in uh in countries like venezuela and zimbabwe that
have gone through hyperinflation and kicked out the smart people like how how quickly their
infrastructure goes to shit so thinking like yep we need we need to uh to grow more cryptographers
it seems to to limit that risk i mean it seems that way um like i agree with you in principle
but it seems like there are a lot of things in the world that works this way it's very interesting
and like historically this has gone wrong before for example all of the people involved in the
Apollo programs for NASA in the 60s and 70s retired since then in the 50 years since NASA
has sent anybody to the moon and the current like all of there's a lot of specialized engineering
knowledge related to how to do that which is effectively lost and is more or less being
rediscovered right now because there was a small community of people who knew what they were doing
and had all of this kind of tribal knowledge and that went away it wasn't passed on it stopped
being used it went away the maybe happier example would be all of the people qualified to do
nuclear physics in germany in the 1940s were all either sent out of the country or captured in some
way um and it became a very hostile place for intellectuals and academics and um as a result
germany faced a tremendous brain drain and despite fears during the war germany was actually never
anywhere near having a nuclear weapon because of exactly this kind of effect yeah they were all in
the manhattan project at that point yeah there are a lot of them came over to the manhattan project
um so so while it would be nice to have more cryptographers and not have such a situation
ultimately there are very many different fields that require this level of specialized knowledge
and only so many people in the world and people tend to specialize and congregate
and like if we had a hundred times as many cryptographers maybe we'd be taking away
people who know a whole lot about nuclear physics or about train switching or about
space programs or about any of the other things that require really detailed specialized knowledge
and it also may be that this is kind of a natural consequence of human communities not
communicating information so well once they get past a few hundred people like it could be that
when you have a larger community you don't get that intense density of focus knowledge it's not
socially scalable is that what you're trying to say yeah yeah i mean it just may be and i'm not
saying it's a good or bad thing i'm just saying like it may be that it's very difficult to scale
community in that way and that may be the reason why we see so many historical examples of exactly
this happening yeah what uh what are the personality types of the people in this
cryptography community so they vary or is there a very common theme among among uh your fellow
cryptographers i feel like there are some common themes um there's kind of so this is interesting
so so cryptography as a field has quite a bit of variance but the people who i'm willing to hang
around with they have much less variance um so for example there are a wide subset of cryptographers
who are doing cryptography for military applications and they have all these dod grants and they're off
at you know government agencies doing secret things they're not a lot to talk about and there
are other subsets of the cryptographic community who are like very um like militant pacifists or
however i mean maybe you know what i mean by that and um and they would never work for the government
and they would never accept these grants or anything.
And then there are people, and this is more of the Bitcoin kind of people,
people who would call themselves cypherpunks,
who are the ones trying to use cryptography to disrupt existing power structures.
And these people tend to have very strongly held opinions.
They tend to be very anti-patent.
They tend to be very anti-centralization, anti-surveillance, anti-censorship.
And they have this, a lot of the work that they do,
they do in order to affect change against those things that they don't like.
And so Bitcoin kind of came out of this community.
like this the term cypherpunk was i don't think it was coined by tim may but tim may in 1995 wrote
the cypherpunk manifesto and this was a manifesto of a small community of cryptographers both
professional and amateur cryptographers who had this small internet community mostly focused
around mailing lists and usenet and stuff and they would look at things like um like say the
Clipper chip was something proposed by the Clinton administration.
They wanted to put a chip in your computer to track everything, right?
Yeah, or in your TV to make sure you weren't watching bad content,
so that you could ensure that your children weren't watching bad content,
which was, I believe, the justification that was given to the public.
This eventually fell on its face, perhaps because of efforts by cyberpunks
taking political and other action,
or it may have just been technically infeasible.
one strange thing that causes things like this to work out better than you might expect given
human nature and given the incentive of that play is that i guess related to the situation we talked
about where there's very small groups of people who understand this stuff often when those small
groups of people have some sort of ideological bent and refuse to help with things if you're a
poorer nation state just trying to watch all of your people you may have a difficult time
finding anybody who's willing to help you anybody who's competent who's willing to help you do that
and uh and even you can find competent people the people who want to undermine you are more
competent and you wind up on the losing side of an arms race so you are you uh under the belief
that the most competent people are are fighting the good fight um that would be a very optimistic
thing for me to believe um but yes yeah i'm willing to say that it would
that would seem to be the case based on my experience in the bitcoin community
um but having said that i live in kind of a bubble in the bitcoin world right i mean that
right as i said like there are wide swaths of cryptographers who are doing also the military
applications and to be honest i don't have a good idea of what they do i don't like talking to them
i don't really care about their research i don't know what they're doing they could be miles ahead
of me and probably i wouldn't find out about that so while i do believe that the most confident
people are fighting the good fight i really don't have the evidence to say yeah so within
bitcoin in particular who are top tier cryptographers outside of yourself oh my goodness um
there are not too many to list but there are too many for me to list them all without forgetting
people. But the people who I work with closely, say, are Peter Willa, of course, and Gregory
Maxwell, and Jonas Nick, and Tim Roofing. And there's a guy, Yannick Sarin, who helped
us with Musig. He wrote the security proof for Musig. He works for INRIA in France. No,
that's not correct i forget um some agency like inria um there are many people i should be naming
um but i'm blanking here but those are the people who come to mind at the top of my head and how
like larry and i were talking about peer programming and stuff like that before how
are you guys bouncing ideas off each other stress testing and and are you doing that because i know
greg maxwell came out a couple months ago and said he he's only uh interacting in private with
people instead of in public more um so sidebarring ideas and stuff like that yeah that's a that's a
great question so in the early days of bitcoin wizards um when the bitcoin community and the
research community was much smaller um because they're like they're the whole group of
cryptographers like other groups of cryptographers who also do bitcoin stuff that i didn't just list
um there are folks at nyu there are folks at stanford there are folks uh there are some
people at Cornell, I guess. There are a bunch of research groups around the world who I interact
with sometimes. I meet them at conferences, but I don't do too much. I don't really collaborate
with them. We don't exchange ideas too much. There are people at Purdue as well, Pedro,
Marino, Sanchez. And so when the Bitcoin community was much smaller, we would talk a lot on IRC,
and we would just private message each other. Not even private message, we would just talk on the
Bitcoin Withers channel. And that was an effective way of communicating when there were only a couple
dozen people and there were only two or three who were talking at the same time and as things have
grown and as a lot of what we do has become politicized it becomes difficult to have
conversations in public or as publicly as we did before there's just a lot more friction and so we
find that the conversations that we're having in public are often things where we have to consciously
decide to have those conversations in public because we feel like they need to have public
input and oversight and stuff and this typically happens after we've already hashed out a lot of
our internal disagreements so the way that a lot of things happen in private or in practice is
there's some semi-private low volume irc channels uh that i'm not going to name but that you can
find if you type slash list and look at all 18 000 free note channels they'll be in there somewhere
um there are some small uh offshoot channels of bitcoin wizards where people discuss some
specific topics, such as Minisketch, which is a set reconciliation protocol that was
developed by Greg Maxwell and Peter Willa and Gleb Naumenko, among a couple of us.
It was mostly those three, and they have a channel where they talk about things.
There's one where there's a whole bunch of discussion leading up to the Taproot bit proposal.
There were sort of five or six of us that were iterating on that.
and then in addition to that some conversations happen in like private communication and emails
and then irc messages and stuff and then a fair bit happens face to face we try to meet people
at conferences we try to meet each other um if we're just in the same city usually we'll call
each other um and so actually one one cool example of this actually is taproot taproot itself
the original idea for taproot was developed by greg maxwell and peter willa and myself
and we were at a diner in california in like you know within 100 miles of the san francisco bay
i'll say and and we were just getting breakfast and talking and and uh shooting the shit as we do
and taproot showed up kind of serendipitously what had happened was somebody had messaged greg
privately asking about a some more efficient script construction they had for somehow hiding
a time locked emergency um clause for their spending policy and i had also had basically
the same problem it may have been with larry uh working on blocks team green actually and greg
and i were talking about this thinking like if we had if we made a future version of bitcoin script
how could we hide these time locks?
Is there any way we can make the time locks take, like, zero space?
And we got it down to 32 bytes,
and then we were spitballing about this construction we knew about
that would let you hide stuff inside of an elliptic curve public key
with zero additional space.
And I thought, hey, what if we took the public keys
that we go through checksig,
and we had, like, an alternate checksig operator
that would, like, expand the public key
and pull out this hidden data
and then you could spin that script and stuff.
And Greg said, screw ChexSig.
What if that was the output, right?
Like what if we just put the public key in the output
and then by default you signed it?
And that was where Taproot came from
was just like a very quick exchange of ideas.
And this works.
So it was not only because we had a small set of people
who all knew each other very well
and we tend not to miscommunicate
and we can talk very quickly,
but also because we were all in person
And we were able to communicate very quickly.
And there's a lot of facial expressions.
You can read inflection and stuff like that.
Exactly.
That's why I do these interviews in person.
Yeah.
And it's just much easier to develop, at least to come up with ideas like that, at least the seeds of ideas.
And there is quite a bit of discussion that happens that way.
And I think all of us try to find our way to certain conferences throughout the year where we know that there will be other people in the Bitcoin crypto community.
Are these Bilderberg backdoor meetings to bastardize Bitcoin and backdoor the protocol?
So these are all very open conferences.
These are scaling Bitcoin.
There's a conference called SBC, the Stanford Blockchain Conference, that I believe is free.
There's the Real World Crypto Conference that was $100 one year and they sold out in five minutes.
And now it might be $250 or something.
so these are accessible conferences
that if you're interested in meeting people
and you're interested in getting into this space
you can certainly show up and listen to talks
and ask questions and meet people
and get
quite a bit of knowledge that way
and
I
what was I going to say
I had a follow up
to that comment that I've now
lost
I think the comment was going to be yeah we're definitely not sponsored by Bilderberg
or uh i'm kidding yeah no i i i swear on i'm kidding i'm kidding i'm kidding i get uh i get
a kick out of those conspiracy theories no i do as well i think they're a lot of fun and i try i
try to poke them when i can but you guys do a good job of uh satirically making fun of them
in videos i like the lizard the lizard uh the lizard uh mask that you guys have yeah yeah those
are a lot of fun we've got hats now that say blockstream spy and we get people to wear those
around town actually my favorite parody video that you guys made was the uh the time stamping
video in april fools uh sort of visualizing why it's stupid to to blockchain your supply chain
yep oh yeah i remember that that was fun it was fun um so let's jump into like taproot uh
bit excuse me bip taproot schnor we were discussing this between larry larry's recording
in this recording, I was sort of confused with BipTapRoot, what's included, and sort
of how all these things come together.
So the way I understand it, Schnorr is sort of the prerequisite that makes a lot of these
TapRoot, GraphRoot stuff work.
Is this a correct assumption?
Yeah, that's a reasonable way to put it.
So Schnorr is a crypto-primitive called the digital signature.
It's a replacement for ECDSA, which is also a digital signature.
And Schnorr signatures are basically the simplest possible digital signature.
They're like the most obvious.
If you're going to come up with a digital signature, you would come up with this.
They're incredibly obvious.
They're derivative of a bunch of other work that have been done.
Unfortunately, the U.S. Patent Office disagreed with the fact that it's obvious and derivative.
So they granted Schnorr a patent that lasted from 1990 until 2008.
which is why bitcoin uses ecdsa today so what we're doing is going back to the signatures that
we should have been using um that have a very simple algebraic structure and as a consequence
of that simple algebraic structure they're very extensible there are a lot of things that we can
do with snore signatures but ultimately snore itself is just a drop in replacement for ecdsa
it's kind of not very interesting by itself but what we can get so i guess let me list the things
the Taproot and Tapscript proposals that we are able to efficiently do or do it all because we
have Schnorr signatures as a primitive rather than being stuck using ECDSA. So Taproot itself,
as I mentioned, is this construction where you hide a script inside of a public key.
And the idea here is that since most coins are spent by somebody just creating a single signature,
we should privilege that mode of spending so your coins like you and i have bitcoin wallets
our coins have public keys associated to them right now those public keys are encoded on the
bitcoin blockchain in the form of a script a script that says here's a public key give me a
signature that validates with these public keys here we just make that implicit we just put the
public key there no script no anything and only if there is something other than a signature you need
to satisfy the the conditions of spending these coins do you need to reveal your script in taproot
and you reveal your script anybody can verify that the script was actually committed inside
of the public key but if you don't reveal it nobody can tell what the script was or even that
it was there and this would this is cool by itself but if that were the whole story it probably would
not get a lot of traction people would be very suspicious of this they say well maybe right now
people are using single keys for all their bitcoins but they could they shouldn't because
that's fragile and um it increases the risk of lossy keys or key corruption or whatever i like
the many things that increases the risk of so one thing that snore signatures get us which makes us
interesting again is that with snore you can very efficiently create multi-signatures and
threshold signatures that are that are themselves just snore signatures so you can think of this as
making a multi signature or you can think of this as jointly producing a
single signature. The idea here is that something like Blockstream Green where
we have a two of three multi signature or a two of three threshold signature, if
we had Schnorr signatures, rather than doing that the way we do today where you
have two signatures and you just put two signatures onto the blockchain, the
user of the green wallet and Blockstream would jointly produce a single signature
that hits the blockchain and because it's one signature you can spend it using taproot without
revealing any scripts so now we've extended the uh the things you can do with just a signature
from somebody sending their own coins to any kind of multi-signature or threshold signature
or more complicated policy related to signatures and this sort of this looks uh
this is when you're looking at it on the blockchain you can't really tell the difference
between anything and it sort of hides these functionalities in the script correct or not
in the script in the uh in the signature yeah exactly so you get a tremendous privacy and
fundability boost because there is no difference from a verifier's perspective um between a normal
like single signer signature and something more complicated that might have been created by
blockstream green or by bitgo or by casa or by liquid or by any of these things that are using
multi-signatures today they would all look the same and verify the same and that's a good segue
into a mini script something that you've been working on so you're working on something this
would work without taproot snoring any of this but it's something that would make uh the scripts
the unique scripts that something like bitgo makes that you guys make for liquid um and other stuff
sort of uh uh you're able to communicate across correct yep yep so in the same vein but in some
sense completely different yes yes the way that you today bitcoin script is actually very expressive
this is for some reason not very widely known the ethereum people showed up took this word
smart contract instead of memeing that smart contract meant something where you have this
incredible key value store of key value stores that nobody can possibly verify and you make sure
all of your transactions are updating a tremendous amount of state and doing so in a way that their
validity depends on what block they're in and what order they appear in so that every reorg is
catastrophic but bitcoin has always supported a form of smart contracting that doesn't have any
of those problems and we just don't call it smart contracts because in some sense it's kind of an
obvious idea um or you know actually i have no idea why we don't call it smart contracts because
in the early days like back when folks like nick sabo were around in the bitcoin community more
actively and more visibly we did use that term and bitcoin script was designed for smart contracting
purposes but here's here's what i think happened and and why we don't think of bitcoin as being a
smart contracting platform and uh and how miniscript intends to fix what i believe happened
so bitcoin does interesting contracts does things like multi-signatures and time locks and hash
primages and lightning htlcs and all of this crazy stuff using a special purpose language called
bitcoin script and bitcoin script was designed to be very easy to reason about it doesn't have
unbounded loops like ethereum does it doesn't have go-to so you can jump around randomly in
the script like ethereum does it has um and those two things are huge by themselves because if you
don't have either of those then in principle given a bitcoin script somebody could look at it they
could determine what the largest like how big a transaction might be that spends coins controlled
by that script they should be able to tell you how many signatures are needed all all these kind of
things but in practice this is actually very difficult to do it's possible to do quite
pathological things with bitcoin script meaning that general purpose analysis of scripts is
basically impossible like to the extent that it's possible it's useless because it will give you
such general answers about what a script is and does that you don't really learn anything about
it at all and the reason for this is just that bitcoin script has a whole pile of opcodes that
do weird things and we might talk later about the disabled opcodes believe it or not none of the
disable opcodes are problematic here it's the ones that are still there that do weird things
but um but to because of this problem people doing interesting things like green or liquid or bitco
who have scripts that do non-trivial things the implementers of those systems are forced to write
ad hoc code to produce these scripts to assemble signatures that satisfy those scripts to reason
about the fee market in the presence of those scripts,
trying to decide how large a transaction will be
that spends them to guarantee that the scripts
do what their creators expect them to.
Like BitGo acts as a countersigner.
They want to make sure that coins can't move
without their signature or, I guess, some time lock
I think they have in case they go down.
Similar for Blocksteam Green.
And the users should also be assured
that the coins can't move without their consent.
That's the most important thing.
and because bitcoin script is so difficult to reason about everybody has their own independent
code bases doing all of these things and there's a lot of human analysis and a lot of very specific
scripts that are done because humans need to vet everything and what mini script is is it's a
one way to look at it is a subset of bitcoin script where there is nothing confusing or
difficult to analyze and it supports signatures it supports hash pre-images it supports time locks
it supports any combination you can think of those so you can say like three of five signers or a
time lock and then two of three or a longer time lock and a hash pre-image has to be revealed and
a thing like whatever you can think of and combining these so now i think it's coming
together for me so some of these like bit go and liquid may have different parameters through which
that they come to these scripts
and you're just allowing,
like putting them all in one mini script
and letting them communicate across each other?
It's not quite that.
It's that they would have different mini scripts,
but they all would be mini scripts.
So the distinction between script and mini script
is that given a Bitcoin script,
you can't really say anything about it
without asking a human to look at it
and reason about what it's supposed to do
and then convince themselves
like it actually does what it's supposed to do but if you have a mini script a mini script is a
much more abstract thing it's like a tree of different combinations of signature requirements
and hash pre-images and stuff and so if you want to convince yourself that say you are a countersigner
to every branch of a mini script or at least every branch that doesn't have a time lock on it
that is very easy to do with mini script you just go through every branch of the script and you check
whether or not your key is on there you say like either my key is there or the time lock and maybe
the time lock has to be a certain length so you know people can't take your coins too quickly or
something like that um if you want to know what the time locks are it's very easy you just scan
through the miniscript looking for time locks um if you want to know and here's where things get
interesting if you want to know how large a witness for a miniscript might be that's an easy
question to answer you can just go through this we know the rules for encoding things on bitcoin
Miniscript supports complicated things
It supports if statements and branches and all sorts of stuff
Sometimes you have to add extra data beyond signatures
Maybe you have to push a 0 to take one branch
And a 1 to take the other or something like that
Because Miniscript is small and self-contained
We have libraries out there that know how to take a Miniscript
And just tell you how much it will cost to satisfy
And it can tell you the maximum cost, the minimum cost
The average cost and so on
It can tell you which public keys you need to give it signatures for
the library i have a library written in rust which will request signatures on a list of public keys
and you give it all the signatures that you have and it will tell you whether the script can be
satisfied with the signatures that you gave it if you gave it enough it will produce a satisfying
witness it will make the smallest satisfying witness so if you have like you need three or
five signatures and you give it all five it will choose the three smallest ones for example so
almost like an efficiency alarm so it's yeah it's uh it lets you do things more efficiently
and actually kind of amusingly i'm aware of two examples of people who using miniscript were able
to find more efficient scripts than the ones they had come up with by hand one of them was us with
liquid we were actually able to save two bytes in our liquid uh spending policy using miniscript
versus a scheme that we come up with.
The other is a company called Arwen in the Boston area.
This is Sharon Goldberg and Ethan Hellman
and a few folks like that.
They're doing custody solutions.
Yeah, they're doing like a split custody crypto
to crypto exchange using sort of a custom
Bitcoin smart contract that's similar to a Lightning HDLC,
but it's different in a way that lets them support
Bitcoin Cash, which doesn't have Segwit
and therefore is vulnerable to malleability
attacks they've taken some some measures to prevent that and using miniscript they're able
to find a slightly more efficient script than the one that they had there but then also because
miniscript is so general it lets you like when you're when you're spending coins you can choose
you can find maybe a more efficient way of spending coins than you otherwise would
simply because you have a single library
that everybody can use to answer the same questions.
Because we, like Arwen and Blocksteam Green and Liquid
and BitGo and Kasa and everybody,
we all care about the same questions about our scripts.
We care about how large they are.
They care about how much they cost to satisfy.
We care about how do we satisfy them
if we have the right signatures.
How do we satisfy them if we have to use a time lock thing?
As far as I'm aware, there's no tooling out there
for using time lock emergency things.
i think there is in the lightning software but nobody else has it like in liquid today if um
the network goes down and we need to use the emergency uh alternate spending mechanism to
recover coins we're going to write software like when that day comes it's fine i mean like lawrence
was saying it's a weekend project it's not a big deal but it's silly it's silly that we have to do
that right but with miniscript minis the miniscript library can just do it for us so we got for free
that we no longer have that tool to write,
which is great.
Yeah, and this is,
I was talking with Lawrence about AB core decentralization
being ideal that we strive for.
It's like stuff like this
helps us become more decentralized
because it sort of tames the growth of the chain state,
or not the chain state,
the size of the chain, correct?
So Miniscript actually is probably bad
for the size of the chain state
because it's going to let people do more interesting things.
Although to the extent that Miniscript
is bad in that direction, Taproot will then recompress things and things will be even
smaller than they were. But what Miniscript gets us is a much wider variety of possibilities for
using Bitcoin and much more robust uses for Bitcoin. So let me give you an example that
affects me personally and many people that I know personally and also many institutions that I'm
aware of which are i have a non-zero number of bitcoins that i hold personally and those
bitcoins are stored on ordinary single signer segwit addresses associated to a single public
key which is derived deterministically from some master seed which is then split up and stored
securely in some collection of locations or something what i would like is that my coins
would be stored on some sort of multi-signature,
at least my long-term storage coins
that I don't spend very often.
I would like those to be stored
on some sort of multi-signature,
some redundant two of three.
I can spend them if I go to my cold storage thing
or maybe if I'm willing to call my parents
or my girlfriend or somebody to countersign,
then we can move them.
I would like there to be a lock-timed
alternate spending path
that would allow my coins to be recovered
in the case that I lose my keys
or I die or I disappear or something.
And right now, because there's no tooling for doing this whatsoever, I don't do this.
I have my coins on single key addresses.
My parents have a letter explaining how to recover them.
This letter involves them phoning multiple Bitcoin core developers at home and asking them for help.
Because I couldn't even give a reasonable workflow in this letter.
And part of this is because I wrote my own wallet with insane spending requirements.
but part of it is just that it's difficult to use bitcoin and i've wanted for a long time to
write some tools that will let you recover my coins that will let me do this and still be able
to spend my coins and still be able to recover them and stuff but the problem is this doesn't
help with recovery because if i write a tool on my personal github account my parents don't know
how to use that right um so i'm back to square one telling them oh call you know this bitcoin
core developer he looked at my tool once and he'll be able to figure it out so with miniscript
now i'll be able to do that because there will be just general mini script signing tools out there
and i'll be able to give like a few simple so this would be something where like if you don't
sign a message every n blocks release to this address or something like that yeah it would
be something like that yeah and i'd set n to be like six or twelve months i think the most you
can set in bitcoin script is 12 months i believe and i forget the exact reason i think it's a
back the number of blocks so is it use unix time to to derive that or is it going up block height
and a perceived uh guesstimated year length this is embarrassing for the the one in script i don't
know so that there are two mechanism for it by which you can do lock times like this um one is
to create a lock time transaction spending the coins normally that is just has something called
a lock time on it meaning the transaction is invalid until some time is up and for that one
If you give it a number less than some threshold, it's like 5 million or something like that,
then it's interpreted as a block height.
And if you give it a larger number, that's interpreted as a Unix timestamp.
And I wonder where the threshold is and if we're going to hit it soon.
I should take a look at that.
But the other way is to directly support this in Bitcoin script using an opcode called check sequence verify,
which is horribly named but it means check the the how old the coin is and for that i believe
you can only set a lot uh number of blocks and i further believe that there is a maximum number
of blocks you're allowed to set this in the consensus rules and it works out to roughly a
year so you cannot lock time things using this technique which is a bit more robust than having
a lock time transaction that you better not lose um but it limits you to doing one year yeah it's
So would you be able to set it up with a watch-only wallet app
that says 100 blocks before the time locks up?
You should probably sign a message,
and then it will just push it more into the future.
Is that how it works?
Yes.
So here's another benefit, or another specific benefit of Miniscript
that makes this kind of thing very easy.
So we actually have something similar today in Liquid.
The way that the liquid network works is that all the coins in the system are ultimately
custodied by an 11 of 15 threshold signature of the quorum of participants in the system.
And there is, after a month, I believe, what is 20, no, two weeks, so 2016 blocks, these
coins then become available for spending by an emergency policy, which are some cold keys
that are spread across the world.
and the idea is that if the network crashes if our hsms all catch fire at once or something like that
then we'll be able to recover the coins in the system by some alternate human mediated method
and today in and so the liquid network the functionaries who are supposed to control
the coins need to make sure that they move these coins every 2016 blocks otherwise
there will be an alternate spending path which should never be available while the network is
alive and the way that our existing code the deployed code does this is that it has a very
specific template that the coins should be controlled by it knows how to parse that template
and knows how to recognize functionary keys in that template it knows where to look for a lock
time it pulls out a couple bytes that represent a time parses those as an integer and it says okay
as long as it's not older than that number then i need to move the coins with miniscript this is
much much easier you take the script you run a function that looks like miniscript.parse
this script and now it's a miniscript so it used to it you're just representing uh the script as a
miniscript and then you say miniscripts list all the time locks that are available and the first
one will always be zero because well i guess if you had coins that you just couldn't move then
the first one would be maybe zero it will give you a second number and now our code that we haven't
deployed yet checks are there two numbers the bigger one is the expiry okay that's how simple
it is and this uh this is way more robust against changes and how we control uh the i don't know
what the spending policy looks like because they're no longer templating scripts and trying
to parse and doing all this ugly stuff and it's way easier to read you look at our source code
and you can just see what's going on so it's miniscript like a wrapper for these scripts or
so this is a cool thing so there are two ways to look at miniscript i i think of it as a
alternate language to bitcoin script for describing spending policies for bitcoins
but miniscript has an encoding that is in the form of bitcoin script okay so you can encode
and decode bitcoin script to miniscript and the encoded form when run by the bitcoin script
interpreter will have exactly the same semantics as the miniscript as described so you have some
policies it's kind of human readable right it's like this key and this key or this key kind of
thing and the semantics of that are exactly what i described right that is what semantics means
just like what what it does what the spending policy actually is and when you encode this as
bitcoin script it will look much more complicated it's going to look something like push this public
key call a checksig operator push the result to the alternate stack push this pub key call the
alt the checksig operator pull the other result from the stack run the boolean and op code push
the result of like like and the semantics of that are actually the same as just this key and this
key but you can see now that what i just said is very non-obvious that those are that those do the
same thing seems arduous yeah yeah it's arduous so with miniscript we have a set of predefined
script templates or script fragments that as far as we're aware express all of the most efficient
constructions for doing ands and ors and thresholds and stuff in bitcoin script and that we peter and
i and and a few other people who have gotten excited and read through our code have basically
vetted that all these fragments do exactly what we think in the ways that we think and now that
we've vetted those fragments that required a fair bit of human work um now we can just use
miniscripts and we can take a bitcoin script that's already on the network and just decode
it as a miniscript and then we don't have to worry about the script semantics because now
in a form that directly represents the semantics.
And you don't have to ask permission for that at all?
No.
And what's cool is this is so,
this is like way,
like on the spectrum of things that are permissionless,
like this is to the moon.
It's really cool.
So first of all, it's, I mean,
it's permissionless in the Bitcoin sense
of anybody can use it.
Anybody can do what they want.
It doesn't require any consensus changes
or consensus layer logic.
So anybody can use it with the existing Bitcoin system today.
and then because it is because it encodes to a subset of script even if peter and i go and
change the language as we define it i mean anybody can run whatever code but even if peter and i like
change the language 100 times and we're like oh now what we call miniscript is is this thing
chances are if you're doing something that's not really contrived our new version will still encode
what you were doing and you just keep on parsing your script as miniscript and don't worry about
what changed at the edges if we change to like allow shaw like ripemd instead of shaw we might
add that for example so it's backwards compatible as well it's very backwards compatible it's very
robust to changes in the underlying script and the reason for that is that we have to be able
to encode the bitcoin script and decode from bitcoin script and that doesn't change right
it's fascinating man how the hell did you get this smart
this is a question i have right now this is like it's blowing my mind like how so there's there's
a funny story about miniskip so all the intelligent stuff here is peter willa to be clear it's not me
all the efficient parsing and all that good stuff um actually it's funny as you're designing it
sometimes peter would put stuff in and i wouldn't know how to parse it and i say i reject that
change because i don't understand i don't know how to write the code for it and so it's deliberately
very simple to write a parser for it
because I didn't want to understand how
LAR1 parsers and stuff worked.
Keep it simple, stupid.
Exactly. And fortunately, we didn't have to sacrifice
efficiency anywhere to get that. We were worried
that we would, but it turned out everywhere where
something was difficult, there was an equivalent construction
that wasn't so difficult.
The story behind
how Miniscript started was
Carl Dong, who is
a Bitcoin developer who works at Chaincode
right now. TFTC alum, too. He's been on this podcast.
Oh, excellent.
Talking about Geeks Containers.
Yeah.
So Carl is one of the maintainers of the Rust Bitcoin project.
This is a library that does all sorts of Bitcoin transaction and block related things for Bitcoin.
And he wanted to add some support for multi-signatures.
And so he wrote some code and he wrote some unit tests.
It was all really solid stuff.
But he had templated a specific kind of multi-signature.
And I said, I don't want that in the library.
this is a general library and we're not going to use your special purpose like multi-signature
thing because that's like one specific thing you're doing is multi-signatures which to be
clear i was being irrational here i mean multi-signatures are very general but i was like
no that's too specific i was like what if i want to do a multi-signature and a hash pretty much
or something and carl said well what what the hell do you want me to do i'm not going to write
a general script analysis engine or something so that you don't have templates in your unit test
and um i said well okay let me think about this and so i happened to be in mountain view near
blockstream's office at the time so i was able to go locate peter woola and i said peter i need to
define a subset of script that will contain everything that i care about but doesn't have
but it's not just a fixed set of templates and he said oh that's funny because we need to do the
same thing in bitcoin core and so we both independently uh had the goal of creating such
of thing and so we got to work doing this we took out two or three whiteboards in the blockstream
office in mountain view and we spent like 40 hours just like laboriously going through every
possible bitcoin script construction we could think of and like counting opcodes and counting
bytes and reasoning about how much it would cost to satisfy them and in the end what we came up
with was miniscript and it was really um a combination of a lot of hard work and grinding
to get like the most efficient thing we could possibly do
that we are a little bit obsessive of.
And Peter knowing all sorts of computer science stuff
about what could be efficiently satisfied
and what could be efficiently reasoned about.
And like Peter was able to write a compiler
from an abstract,
like an even more human readable language in Miniscript
to Miniscript where it would choose the most optimal
of all the different Miniscript constructions or something.
So optimizing the optimizer?
Almost.
Almost, yeah.
So, well, the Miniscript optimizer,
what the Miniscript library that I wrote does,
it optimizes spending coins,
but it doesn't find the smallest Miniscript for you.
You still have to figure out,
you've got a few different ways to do ors,
you've got a few different ways to do ands,
you've got to choose the right one for your use case
that will be the smallest.
And Peter wrote a compiler that would find the right one.
You would just say,
I want this key and this key or this key,
and it would just grind through every possibility, basically,
and do so in quite an efficient way.
And then, actually, I wrote a compiler as well
in Rust to compete with him.
So he and I independently wrote compilers
for the same language.
And then because Peter had written a general tool
for creating sentences in any language,
he was able to produce the first 10 million miniscripts,
just programmatically generating them
with a tool that he already had lying around
that he was using for password generation or something.
And so he generated 10 million miniscripts
or 10 million of these abstract,
what we call the policy language.
And he and I both compiled all 10 million to Miniscript
and then compared every single one to check
we got the same results.
And they lined up?
They lined up.
And that's how we did a lot of our software testing.
Is that enough of a sample, you think?
Well, we didn't think so, no.
So after doing the first 10 million,
then we started generating random ones
that were enormous,
that had like 100 bits of entropy and stuff.
And we found when they got too complicated,
our compilers wouldn't finish in a reasonable amount of time they would take hours to run
but we did take a random sampling of quite very like deliberately random and enormous policies
and checked they were still compiled to something sane um i wrote some tooling um because i was
using this i was writing a production ready rust library for use in liquid i did a whole bunch of
tooling for actually producing valid transactions and stuff and i spent a while running random
scripts random mini scripts making sure that i could sign for them and that the resulting
signatures had a weight a transaction weight that was below what i had estimated that everything was
satisfiable that i thought was satisfiable and not satisfiable when i didn't think it was
and uh and just generally sanity checking against the actual final produced bitcoin transactions
so we actually have quite quite high assurance at least for the more commonly used part of
bitcoin script just using these random samples i just learned a lot in the last 52 minutes here
blowing my mind with it how do you keep all this in your head is because there's so many like
just here trying to like uh so you have many scripts taproot like all this stuff that you
can describe intently you you're working on music as well too right uh yeah i do yeah i am working
on musig and that and that will that taps into taproot and graphroot to help smart contracting
capabilities correct yep so musig is the the protocol that lets you jointly produce a schnor
signature so when you have a a multi-signature if you have a single signature that needs to be
produced by multiple people those people run the musig protocol off-chain and what comes out is a
single signature that you would use as taproot so do you like working on these different aspects
does it help you sort of uh stay motivated and and do you like jumping from the concept to concept
yeah it's uh it's very cool to have this kind of high level view of the system so actually um i
used to wonder about greg maxwell who knows everything about everything in bitcoin like
how could he possibly do this is he an alien um i can't answer that question but now that i am the
research director at blockstream since greg left um i have kind of a dirty little secret here which
is that other people are doing all of these things so like the active music development that's mostly
jonas nick and tim roofing and peter woola all the taproot stuff that's peter and jonas again
and aj towns and johnson lau uh the miniscript stuff actually was me and peter that's the one
thing that i really had a part in doing um and all of these people and many others send me messages
all the time saying like hey here's something i'm doing what do you think about it so i get this i
don't have to look to find out what's going on like people come to me with information that
they make an effort to make digestible by me that they try to make understandable
so i can pretend like i know all these things about all those million things but the truth
is that i have people kind of processing this information and doing all the heavy lifting and
stuff and i i kind of just have an executive summary of a lot of it that's like uh it's like
me just being a full node operator trying to understand what you guys are working on um
but no it is uh you're uh you're a fascinating person andrew it's um it's thank you it's uh
thank you i'm not as fascinating as you i don't think um but that's crazy like the
intense work that you're working on and it's for something greater than yourself bitcoin right so
are you uh let's talk about the mission of bitcoin like do you see it as imperative as we move into
the future yeah absolutely um so what bitcoin is for me is it's about economic sovereignty
it's about people's ability to interact with each other and to transact with each other
without worrying that their credit card company is going to censor them for interacting in the
wrong way without worrying that their bank is selling metadata to advertisers without worrying
that their merchant, who's an even bigger risk, is selling data to advertisers, without worrying
that their government will decide one day that they don't like certain activities that they're
doing, or certain people that they're donating to, or certain people who they're interacting with.
Right now, basically everywhere in the world, to a lesser or greater extent, people are restricted
in their economic activities in these ways. And with the advent of the internet,
this has gotten quite a bit worse because so much of the way that we transact with each other now
happens over the internet which until bitcoin basically requires you use a credit card you
have some company that's putting up um that's loaning you the money and your transactions are
basically just sending a request to them to process this transaction so they wind up having
tremendous amounts of data about what you're doing and how you're doing it and tremendous
amounts of power to prevent you from doing so or even to have a chilling effect to imply that if
you're doing bad things then they'll stop working with you and we see this happening a lot of u.s
banks if you receive money from coinbase they'll say you're using bitcoin stuff and they'll close
your accounts you see these kind of stories on our bitcoin all the time in other parts of the
world there are much more serious chilling effects happening for for things that really
if you want to have a free society it's imperative that people be able to do
and what bitcoin does is it undermines all of that censorship infrastructure all of that
surveillance infrastructure and it lets people just interact directly with each other directly
with merchants directly with whoever they want to interact with in a way that is very difficult
to censor and should be very difficult to surveil although it's really not right now a lot of what
i'm working on is making it harder to monitor this although right now unfortunately bitcoin
is very non-private and kind of a bad idea for people who need privacy no thank you for that
hard work do you think the legacy system has too much of a head start for bitcoin to to catch up
no no no um so the legacy system really is legacy so one of the benefits of working for a company
like Blockstream which deals a lot with or which talks a lot to players in traditional finance
often we get requests for advice or consulting or some sort of commentary is that I have a bit
of visibility into the way that large institutions do things today and the way that they view
Bitcoin and the way that they view this blockchain stuff and a lot of what big banks are doing is
like excel spreadsheets that they're emailing to each other and like really primitive things
and a lot of the uh blockchain not bitcoin hype we like to talk about how stupid that is because
like a blockchain without bitcoin is just the database like you guys surely you guys have
databases they don't have databases in a lot of cases in a lot of cases this is really just
trojanning uh like people within these companies are using the blockchain hype buzzword to like
trojan horse like 1980s technologies into these banks where they should have had it forever
because and the reason this happens is that large institutions are very hesitant to change
especially processes related to tremendous amounts of money and their existing processes
have a ton of human oversight and that's the way everything works there's just tons of human
oversight everywhere which is cool but the result is a lot of inefficiency and a lot of resistance
to change and an inability to react to the kind of disruption that bitcoin is causing so
i wouldn't i mean i guess they have a head start in terms of market adoption
but they do not in terms of technology or in terms of expertise now that's the um that's one
thing that a lot of like especially in the vc world and the uh post.com bubble world is fintech
is a buzzword and fintech sort of markets itself as new technology when it's really better ux ui on
top of pre-existing technology where bitcoin is actually a new technology yeah exactly um
yeah that's exactly it so it's almost like
i mean the the way that most people in the financial space think about new technology
right it's not new technology so they're like in the last like two generations ago of new technology
is where they are so like bitcoin it's it's difficult for a lot of these players to even
comprehend bitcoin because of that because of that inferential gap these mental blockers people
the sunk i guess the sunk cost of just ingratiating yourself in that system is it's
is it uh is it a old dog can't learn new tricks or is it like head in the sand don't want to learn
the new tricks um i mean there are both of those but there's also um like because there's such a
distance between the way that people are used to dealing with money like it takes a lot of
outreach and education and it's difficult also for bitcoin people to make to bridge that gap
right it's difficult for us to understand how financial institutions are working today and to
even be able to speak their language to talk about why they might like bitcoin so there's a fun kind
of story i have i know we're well we're not out of time i've got time um i've got plenty of time
um a couple days ago my friend eric melzer at the magical crypto conference announced a project he's
been working on called the satoshi treasure hunt shout out to the dpr avengers our team on the
treasure is that right oh that's excellent ten percent of the proceeds go to uh the ross albrecht
and uh julian assange funds excellent i'm happy to hear that um and the way the satoshi treasure
hunt works is really so eric did a presentation about this at the magical crypto conference and
made a really important observation i think which is that the way this treasure hunt works where
he's taken private keys that store up to a million dollars of bitcoin he sharded them and he's
encoding shards everywhere and he had like multiple copies and all sorts of um crazy elaborate hiding
places this is literally impossible to do with any asset except for a cryptocurrency and i feel
like this is something that's very exciting and very tangible that demonstrates the counterintuitive
and novel properties of bitcoin to people who otherwise wouldn't see that that novelty
yeah it's like a real life ready player one it's incredible yeah and that's great
so he used uh shamir's secrets correct to break up the key and then he broke up the keys into
even more shards correct correct yeah yeah which is so like what he dropped on saturday was every
teammate on his every person on his team has a special business card and if you get all their
business cards you'll get one of the shards yeah yeah so i guess uh podcast listeners can't see it
but i just pulled one of these cards out that he machined with a friend of his in brooklyn a couple
days ago it's got the qr code that you can't really see it um this is the dopest business
card i've ever seen there is a trick to getting the qr code out of there if you try to peel that
paper is you're just going to ruin it yeah there's a a physical trick you can do um that i'm not
allowed to say eric told me not to tell people um and this is i guess this hadn't really occurred
to me until eric made this observation about how exciting that is um or how how tangible it is
to see something like this and how it makes tangible a lot of weird aspects of bitcoin
yeah because it's globally distributed you have teams the teams that are gathering have to be
globally distributed because you need people in physical areas to find the clues and so you need
people who are good hunters and then you need good cryptographers so people were basically
brute forcing yeah they would read read the html css of the first three shards and were able to
like brute force the the third or fourth key yeah um but that's the that's the problem they face
it's making it harder um over time he said he got a call from one of his quant buddies at like a
huge hedge fund is writing high frequency trading scripts and he's on the case now so trying to make
it harder for those types of minds is uh it's gonna be fun to watch yeah it will absolutely
be fun to watch and i really i hope that this will get a lot of traction in the public eye i
think it'll be a very good thing for bitcoin if we have a bigger price pump that uh that million
dollar price prize is gonna rise and uh yeah i guess it already has yeah i didn't even think
about that yeah we've had a hell of a week on the markets so yeah so yeah that's that million is
probably way above a million right not way above but above a million could be close to two yeah i
don't know yeah i should ask him that's that's like it's like the fomo like think about the
fomo of just like acquiring bitcoin but the fomo for this i guess around the time if the announcement
i'm not sure exactly how many bitcoin was around like 200 bitcoin 210 bitcoin or something like
that like as this race goes on if the price is going up it's going to get more intense yeah
more fomo so that's going to be fun to watch um we're an hour and five minutes in here 20 minutes
over my lot of time.
Thank you for indulging me.
Yeah, thank you.
I want to end it on,
get to know a little bit more
about the person in the last five minutes.
So you are into climbing.
We were talking about free solo before.
What about climbing interests you?
Does it help you get your mind away from this stuff?
Are you thinking about this stuff
while you're climbing?
Is it therapeutic?
No, it definitely helps me get my mind away.
So I was introduced to climbing, actually,
by Peter Todd,
who's well-known in the Bitcoin space.
I was visiting some folks
at the BHB lab in Milan,
where Peter used to spend quite a lot of time working.
I don't know if he does now.
They restructured a little bit,
and I'm not sure how his projects moved there.
But I wound up in Milan visiting some friends of mine,
Giacomo Lizzucco, who everyone on Twitter knows,
and Mir Limponi, and Peter Todd.
And we went to a climbing gym in Milan,
and I really got into it.
What I find that does help me,
so I can't think about Bitcoin.
When you're on the wall and if you screw up, then you fall,
there's very much a physical need to focus on what your body is doing
and how your body is positioned.
And it helps to be aware of something so physical and concrete
when you spend all of your time otherwise doing such incredible abstract things.
And I find it's very grounding and it's very meditative,
and I enjoy it for that reason.
You're reintroduced to your mortality?
Yes, yeah, that's good.
That's good to have that happen, I think.
No, it definitely is.
And I'm not going to ruin free solo for you,
but I think you're really going to like it.
Yeah, I should.
As I said, it's open on my Amazon page right now,
and I still have not clicked play.
All right, I'm going to let you get on with your day here.
Before we part, do you have a word of advice,
something you want to bring to the attention of the freaks out there,
or anything?
All right, so I have something very specific
that i want to say which is that shamir secret sharing is exactly the right tool for running
an enormous treasure hunt where somebody takes all the money it is not a substitute for multi
signatures that's all that's a very good point yeah that's uh that's an intuition when people
hear about samir secret sharing they think it's super cool i can split my bitcoins up amongst
multiple people but the point of secret sharing is that somebody reconstructs a whole key and
spends it so when if you're using it this way that's great for a treasure hunt but it's still
one key it's still one key exactly versus using a multi-signature whereas never one key is actually
an interactive protocol uh where multiple parties have to all contribute to the specific transaction
they're signing yeah so be aware of that freaks be aware yeah there we go that is my advice thank
you for that psa and thank you for joining us andrew so thank you pleasure man yeah for me as
well peace and love freaks
